Digital currency transaction method and terminal
Patent Information
- Application Number
- CN202311865278.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2043-12-29
AI Technical Summary
[0049] One embodiment of the above invention has the following advantages or beneficial effects: In this embodiment, the near-field communication controller in the smart terminal determines whether the receiving target is a host-based card emulation application or a security unit based on the payment application selection instruction and the system activation state of the smart terminal, providing users with a flexible payment experience. After verifying the payment application identifier, the receiving target generates response information and returns it to the receiving terminal. After verifying the response information, the receiving terminal sends a transaction instruction to the receiving target. The receiving target generates transaction ciphertext and returns it to the receiving terminal. The receiving terminal sends the transaction ciphertext to the digital currency back-end system, and the digital currency back-end system executes the digital currency transaction according to the type of transaction ciphertext. In this embodiment, by having a host-based card emulation application communicate with the security unit through a card-machine channel or internal interface, and using the security functions of the security unit to generate transaction ciphertext, the security of digital currency transactions is improved.
Smart Images

Figure CN117974133B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a digital currency transaction method, terminal, electronic device, and computer-readable medium. Background Technology
[0002] With the widespread adoption of smart devices and the rapid development of mobile payment, mobile payment based on smart devices is gaining increasing popularity. Security and convenience remain the focus of mobile payment technology. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a digital currency transaction method based on a smart terminal, which ensures both security and ease of use. Specifically, the smart terminal is equipped with a near-field communication controller, a security unit, and a host-based card emulation application. The method includes the following steps:
[0004] The near-field communication controller acquires the payment application selection instruction sent by the acceptance terminal, which includes a payment application identifier;
[0005] In response to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier stored in the near-field communication controller, the near-field communication controller determines the receiving target of the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal. The receiving target is a security unit or a host-based card emulation application and security unit.
[0006] The near-field communication controller sends the payment application selection instruction to the receiving target, which then processes the digital currency transaction.
[0007] In some embodiments of this application, receiving a target for digital currency transaction processing includes:
[0008] The system generates selection response information based on the payment application's selection instruction and sends the selection response information to the acceptance terminal via the near-field communication controller.
[0009] The near-field communication controller receives transaction instructions sent by the receiving terminal and sends the transaction instructions to the receiving target. The transaction instructions are generated by the receiving terminal after verifying and selecting the response information.
[0010] The receiving target generates a transaction ciphertext according to the transaction instruction and sends the transaction ciphertext to the receiving terminal through the near-field communication controller. This enables the receiving terminal to send the transaction ciphertext to the digital currency back-end system. After verifying the transaction ciphertext, the digital currency back-end system executes the digital currency transaction corresponding to the transaction ciphertext type and sends the transaction result to the receiving terminal.
[0011] In some embodiments of the present invention, when the receiving target is a host-based card emulation application and security unit, the near-field communication controller sends a payment application selection instruction to the receiving target. The receiving target generates selection response information according to the payment application selection instruction and sends the selection response information to the acceptance terminal through the near-field communication controller, including:
[0012] The near-field communication controller sends a payment application selection instruction to the host-based card emulation application, so that the host-based card emulation application forwards the payment application selection instruction to the security unit. The security unit generates selection response information according to the payment application selection instruction and sends the selection response information to the host-based card emulation application, so that the host-based card emulation application sends the selection response information to the acceptance terminal through the near-field communication controller.
[0013] The near-field communication controller receives transaction instructions sent by the receiving terminal and sends the transaction instructions to the receiving target, including:
[0014] The near-field communication controller acquires the transaction instruction sent by the acceptance terminal, sends the transaction instruction to the host-based card emulation application, the host-based card emulation application performs identity verification according to the transaction instruction, and sends the verified transaction instruction to the security unit.
[0015] The receiving target generates ciphertext based on the transaction instruction and sends the ciphertext to the receiving terminal via the near-field communication controller, including:
[0016] The security unit generates transaction ciphertext based on the transaction instruction, marks the type of transaction ciphertext based on the identity verification result, and sends the transaction ciphertext to the host-based card emulation application, so that the host-based card emulation application can send the transaction ciphertext to the acceptance terminal through the near field communication controller.
[0017] In some embodiments of the present invention, when the receiving target is a security unit, the near-field communication controller sends a payment application selection instruction to the receiving target. The receiving target generates selection response information according to the payment application selection instruction and sends the selection response information to the acceptance terminal through the near-field communication controller, including:
[0018] The near-field communication controller sends a payment application selection instruction to the security unit. The security unit generates selection response information based on the payment application selection instruction and sends the selection response information to the near-field communication controller, so that the near-field communication controller can send the selection response information to the acceptance terminal.
[0019] The near-field communication controller receives transaction instructions sent by the receiving terminal and sends the transaction instructions to the receiving target, including:
[0020] The near-field communication controller acquires the transaction instructions sent by the receiving terminal and sends the transaction instructions to the security unit;
[0021] The receiving target generates ciphertext based on the transaction instruction and sends the ciphertext to the receiving terminal via the near-field communication controller, including:
[0022] The security unit generates ciphertext based on the transaction instruction, marks the type of the ciphertext as unverified, and sends the ciphertext to the near-field communication controller, so that the near-field communication controller can send the ciphertext to the receiving terminal.
[0023] In some embodiments of the present invention, the host-based card emulation application performs identity verification according to the transaction instruction and sends the verified transaction instruction to the security unit, including:
[0024] The verification of transaction instructions by host-based card emulation applications requires identity verification processing, which verifies the identity information entered by the user.
[0025] Upon successful verification of identity information, an identity verification flag is added to the transaction instruction, and the transaction instruction is sent to the security unit.
[0026] The security unit marks the type of the transaction ciphertext based on the authentication result, including:
[0027] The security unit marks the type of the transaction ciphertext as verified based on the verified tag.
[0028] In some embodiments of the present invention, the host-based card emulation application performs identity verification based on the transaction instruction and sends the verified transaction instruction to the security unit, further comprising:
[0029] In response to the failure of identity verification, a transaction failure message is sent to the acceptance terminal through the near-field communication controller, so that the acceptance terminal terminates the transaction.
[0030] In some embodiments of the present invention, the host-based card emulation application performs identity verification according to the transaction instruction and sends the verified transaction instruction to the security unit, including:
[0031] Host-based card emulation applications do not require identity verification for transaction instructions. Instead, an unverified flag is added to the transaction instruction before it is sent to the security unit.
[0032] The security unit marks the type of the transaction ciphertext based on the authentication result, including:
[0033] The security unit marks the type of the transaction ciphertext as unverified based on the unverified tag.
[0034] In some embodiments of the present invention, the near-field communication controller determines the target for receiving the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal, including:
[0035] If the system activation status of the smart terminal is not activated and the payment application corresponding to the payment application identifier is installed in the security unit, the target of receiving the payment application selection instruction is determined to be the security unit.
[0036] In response to the system activation status of the smart terminal being activated, the target of receiving the payment application selection instruction is determined to be the host-based card emulation application and security unit.
[0037] In some embodiments of the present invention, the security element generates selection response information based on the payment application selection instruction, including:
[0038] In response to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier of the payment application installed in the security unit, the security unit calls the payment application corresponding to the payment application identifier to generate selection response information.
[0039] In some embodiments of the present invention, the security element generates transaction ciphertext according to the transaction instruction, including:
[0040] The security unit invokes the payment application corresponding to the payment application identifier and generates ciphertext based on the transaction instructions.
[0041] Another aspect of this invention provides a digital currency trading terminal, including a near-field communication controller, a security unit, and a host-based card emulation application device, wherein...
[0042] The near-field communication controller is configured to acquire a payment application selection instruction sent by the acceptance terminal, the payment application selection instruction including a payment application identifier;
[0043] The near-field communication controller is configured to respond to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier stored in the near-field communication controller, and to determine the receiving target of the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal. The receiving target is a security element or a host-based card emulation application and security element.
[0044] The near-field communication controller is configured to send a payment application selection instruction to the receiving target, and the receiving target is configured to generate selection response information according to the payment application selection instruction and send the selection response information to the acceptance terminal through the near-field communication controller;
[0045] The near-field communication controller is configured to receive transaction instructions sent by the receiving terminal and send transaction instructions to the receiving target. The transaction instructions are generated by the receiving terminal after verifying and selecting response information.
[0046] The receiving target is configured to generate transaction ciphertext according to the transaction instruction and send the transaction ciphertext to the receiving terminal through the near-field communication controller, so that the receiving terminal sends the transaction ciphertext to the digital currency back-end system. After verifying the transaction ciphertext, the digital currency back-end system executes the digital currency transaction corresponding to the transaction ciphertext type and sends the transaction result to the receiving terminal.
[0047] According to another aspect of the present invention, an electronic device is provided, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the digital currency transaction method provided in the embodiments of the present invention.
[0048] According to another aspect of the present invention, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the digital currency transaction method provided in the embodiments of the present invention.
[0049] One embodiment of the above invention has the following advantages or beneficial effects: In this embodiment, the near-field communication controller in the smart terminal determines whether the receiving target is a host-based card emulation application or a security unit based on the payment application selection instruction and the system activation state of the smart terminal, providing users with a flexible payment experience. After verifying the payment application identifier, the receiving target generates response information and returns it to the receiving terminal. After verifying the response information, the receiving terminal sends a transaction instruction to the receiving target. The receiving target generates transaction ciphertext and returns it to the receiving terminal. The receiving terminal sends the transaction ciphertext to the digital currency back-end system, and the digital currency back-end system executes the digital currency transaction according to the type of transaction ciphertext. In this embodiment, by having a host-based card emulation application communicate with the security unit through a card-machine channel or internal interface, and using the security functions of the security unit to generate transaction ciphertext, the security of digital currency transactions is improved.
[0050] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description
[0051] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:
[0052] Figure 1 This is a schematic diagram of the overall architecture of a digital currency trading system according to some embodiments of the present invention;
[0053] Figure 2 This is a flowchart illustrating a digital currency transaction method according to some embodiments of the present invention;
[0054] Figure 3 This is a schematic diagram of the process for determining the receiving target in a digital currency transaction method according to some embodiments of the present invention;
[0055] Figure 4 This is a schematic diagram of the identity verification process in a digital currency transaction method according to some embodiments of the present invention;
[0056] Figure 5 This is a schematic diagram of the overall architecture of a digital currency trading system according to other embodiments of the present invention;
[0057] Figure 6 This is a schematic diagram of the process of performing identity verification transactions using a digital currency transaction method according to some embodiments of the present invention;
[0058] Figure 7 This is a schematic diagram of the process of performing a contactless payment transaction in an activated state using a digital currency transaction method according to some embodiments of the present invention;
[0059] Figure 8 This is a schematic diagram of the process of performing a seamless payment transaction in an inactive state using a digital currency transaction method according to some embodiments of the present invention;
[0060] Figure 9 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;
[0061] Figure 10 This is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present invention. Detailed Implementation
[0062] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0063] It should be noted that the technical solutions disclosed in this invention, regarding the collection, updating, analysis, processing, use, transmission, and storage of user personal information, all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.
[0064] It should be noted that the collection, use, storage, sharing and transfer of user personal information involved in the technical solution of the present invention all comply with the provisions of relevant laws and regulations, and require notification to users and obtaining their consent or authorization. When applicable, user personal information is subjected to de-identification and / or anonymization and / or encryption technical processing.
[0065] In this embodiment of the invention, "NFC" refers to Near Field Communication technology; "POS" refers to a terminal with transaction function; "AID" refers to an application identifier; "HCE" refers to host-based card emulation, where HCE on a smart terminal can interact with the user, such as for identity verification and user authorization; "SE" refers to a security unit or security chip, including forms such as SWP-SIM (Single-Wire Connection Protocol SIM card), SWP-SD (Single-Wire Connection Protocol memory card), and eSE (embedded security unit); and "APDU" refers to an application protocol data unit.
[0066] like Figure 1 As shown, this embodiment of the invention provides a digital currency trading system 100 based on a smart terminal, including a smart terminal 110, an acceptance terminal 120, and a digital currency back-end system 130. The smart terminal 110 includes a host-based card emulation application (HCE application) 111, a near-field communication controller (NFC controller) 112, and a security element (SE) 113. Among them, HCE application 111 is a client app for digital currency that uses HCE service and is installed on smart terminal 110. It provides users with a UI interface, verifies user identity, and obtains user authorization for transactions. The AID registered in NFC controller 112 is consistent with the AID of wallet application in SE113. NFC controller 112 is a module on smart terminal that provides NFC function. It is responsible for receiving and sending contactless communication data, registering and distributing AID routing tables. SE113 is a security unit on the terminal, including forms such as SWP-SIM, SWP-SD, and eSE. It has a user wallet application installed (uniquely identified by AID), stores wallet keys and user personal data, and is responsible for securely encrypting transaction data to generate transaction ciphertext. Acceptance terminal 120 is a payment receiving device that supports NFC card reader mode communication, including merchant POS, personal POS and other acceptance devices. Digital currency back-end system 130 is a back-end system that supports digital currency mobile payment function, including back-end systems of payment and collection operation institutions, central bank interconnection systems and other back-end systems, supporting digital currency transactions within the institution and across institutions.
[0067] The system 100 in this embodiment of the invention includes pre-transaction setup and transaction process in its operation flow.
[0068] The setup process before a transaction is as follows: The user sets up the NFC function on the smart terminal 110, sets the default application to the HCE application, and sets the default SE to the security unit with the wallet application installed. This only needs to be set once and does not need to be set before each transaction.
[0069] The transaction process consists of two phases: the initialization process and the transaction processing process.
[0070] The first stage is the transaction initialization process, which is described in detail below.
[0071] The first step is for the terminal 120 to use NFC reader mode to send an APDU command to select an AID, where the AID in the command is the wallet application AID.
[0072] The second step is route selection: The user brings the smart terminal 110 close to the receiving terminal 120. The NFC controller 112 receives the selection command, selects the APDU command receiving target according to the AID routing table, and transmits the command. The routing rules are set as follows:
[0073] 1) If the smart terminal system is active and meets the user authentication and authorization conditions, the receiving target is HCE application 111. Subsequently, the HCE application will send instructions to the wallet application in SE113.
[0074] 2) If the smart terminal system is inactive, to meet the user's pre-authorized contactless payment requirements, the receiving target is the wallet application in SE113.
[0075] Third, the NFC controller 112 transmits the selection instruction response data returned by the wallet application in SE113 to the acceptance terminal 120.
[0076] The second stage is the transaction processing process, which is described in detail below.
[0077] In the first step, the receiving terminal 120 continues to send transaction instructions. After receiving the transaction instructions, the NFC controller 112 transmits them according to the receiving target determined in the second step of the first stage. Depending on the receiving target, the second or third step described below is executed. In this embodiment of the invention, the transaction instructions include information such as the transaction amount and the recipient's wallet identifier.
[0078] The second step is that if the NFC controller 112 routes to HCE application 111, HCE application 111 checks whether user authentication is required based on business rules (such as whether it is password-free payment) and performs the following branch processing.
[0079] 1. If user verification is not required (e.g., when the transaction amount is less than the limit for password-free payment), the HCE application 111 will directly transmit the transaction instruction to the wallet application in the SE113. The wallet application will generate the transaction ciphertext and return it to the receiving terminal 120 via the HCE application 111 and the NFC controller 112 to continue the fourth step of the transaction processing.
[0080] 2. If user verification is required (e.g., when the transaction amount exceeds the password-free payment limit, or when password-free payment is not enabled), HCE application 111 calls the system interaction interface to pop up a window to verify the user's identity and obtain user authorization, proceeding to different branches depending on success or failure:
[0081] a) If the transaction fails, the NFC controller 112 returns a transaction rejection message to the accepting terminal 120.
[0082] b) If successful, the transaction instruction is appended with the user's verified identity mark and transmitted to the wallet application in SE113 through the card channel. The wallet application returns the user's verified transaction ciphertext, which is then returned to the receiving terminal via HCE application 111 and NFC controller 112 to continue the fourth step of the transaction processing.
[0083] Third, if the NFC controller 112's routing target is the wallet application in SE113, it transmits the transaction instruction to the wallet application in SE113 via a contactless channel. The wallet application returns the user's transaction ciphertext, which is then returned to the receiving terminal 120 via the NFC controller 112, and the fourth step of the transaction processing continues.
[0084] In this embodiment of the invention, the plaintext corresponding to the ciphertext of the transaction includes information such as the transaction amount, the type of ciphertext of the transaction, the payer's wallet identifier, and the payee's wallet identifier.
[0085] Fourth, the receiving terminal 120 receives the transaction response. If the response is a rejection, the transaction is terminated; otherwise, the encrypted transaction is transmitted to the digital currency back-end system 130.
[0086] Fifth, the digital currency back-end system 130 implements different limit management and risk control based on the type of transaction encryption to ensure transaction security. For example, the digital currency back-end system 130 verifies whether the transaction encryption has been verified before it is generated. If it has not been verified and the transaction amount exceeds the limit for password-free payments, the transaction fails.
[0087] In this embodiment of the invention, the digital currency back-end system 130 also conducts digital currency transactions based on the payer's wallet identifier, the payee's wallet identifier, and the transaction amount in the transaction ciphertext. When the operating institutions of the wallets corresponding to the payer's wallet identifier and the payee's wallet identifier belong to the same wallet operating institution, a transaction within the same institution is conducted; when the operating institutions of the wallets corresponding to the payer's wallet identifier and the payee's wallet identifier do not belong to the same wallet operating institution, a transaction request is sent through the interconnection platform to conduct a cross-institutional transaction.
[0088] In the digital currency transaction of this embodiment of the invention, the parent wallet account bound to the payer wallet identifier can be obtained by querying the payer wallet identifier, and the digital currency corresponding to the transaction amount can be deducted from the parent wallet account, and the corresponding digital currency can be added to the corresponding payee wallet.
[0089] In this embodiment of the invention, transactions with verified user identities have a higher level of security and are suitable for large transactions (such as large purchases in shopping malls and supermarkets), while transactions without verified user identities are suitable for small and fast transactions (such as small-amount scenarios like buses, subways, and convenience stores).
[0090] The system in this embodiment of the invention sets different transaction processes for different transaction scenarios, which can not only meet the security requirements, but also provide users with a convenient and easy transaction experience.
[0091] like Figure 2 As shown, this embodiment of the invention also provides a digital currency transaction method applied to a smart terminal. The smart terminal includes a near-field communication controller, a security unit, and a host-based card emulation application. The method includes:
[0092] S210: The near-field communication controller acquires the payment application selection instruction sent by the acceptance terminal. The payment application selection instruction includes a payment application identifier. The acceptance terminal sends the payment application selection instruction to the near-field communication unit via card emulation. The payment application selection instruction includes the payment application identifier (AID).
[0093] S220: The near-field communication controller responds to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier stored in the near-field communication controller, and determines the receiving target of the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal. The receiving target is a security unit or a host-based card emulation application and security unit.
[0094] The operation of the near-field communication controller in this embodiment of the invention includes the step of the near-field communication controller making a judgment.
[0095] In this embodiment of the invention, different receiving targets are determined based on the payment application selection instruction and the system activation state of the smart terminal, enabling digital currency transactions to meet the diverse needs of users and providing a technical foundation for the expansion of digital currency scenarios. When the receiving target is a security unit, transaction-related instructions can be processed quickly, providing users with a fast payment experience. When the receiving target is a host-based card emulation application (HCE) and a security unit, HCE can be used to verify and process transaction-related instructions, thereby improving transaction security.
[0096] This application embodiment can provide users with convenient payment methods while also offering more secure payment options. Users can choose the receiving target and payment method based on their payment needs and scenarios. For example, when a user needs convenient payment without identity verification, they can quickly conduct cryptocurrency transactions. Transaction-related instructions are directly transmitted to the SE for processing, making the transaction fast. When a user needs secure payment, their identity needs to be verified. Transaction-related instructions are transmitted to the SE via HCE. If the transaction conditions meet the identity verification requirements, the user can verify their identity through the HCE service. Only after successful identity verification can the cryptocurrency transaction be completed, improving transaction security and preventing fraudulent transactions.
[0097] In this embodiment of the invention, the near-field communication controller generally stores an AID routing table. The near-field communication controller determines whether the payment application selection instruction should be processed by the near-field communication controller based on the AID in the payment application selection instruction. If the AID in the application selection instruction is consistent with the AID in the stored AID routing table, it is determined that the near-field communication controller should process it. Then, the receiving target is determined based on the system activation status of the smart terminal.
[0098] For example, if the AID routing table in the near-field communication controller is {AID: F001002003, target: eSE; AID: F001002002, target: SIM card}, and the receiving terminal sends a selected AID of F001002001, the near-field communication controller cannot determine the receiving target according to the AID routing table and returns a failure. If the receiving terminal sends a selected AID of F001002003, the near-field communication controller determines the target as eSE and further judges the system activation status to determine the receiving target of the response command.
[0099] In some embodiments of the present invention, such as Figure 3 As shown, the near-field communication controller determines the target for receiving the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal, including:
[0100] S221: In response to the smart terminal's system activation state being inactive and the payment application corresponding to the payment application identifier being installed in the security unit, the target for receiving the payment application selection instruction is determined to be the security unit.
[0101] S222: In response to the system activation state of the smart terminal being activated, determine that the target of receiving the payment application selection instruction is the host-based card emulation application and security unit.
[0102] This invention allows for the determination of the instruction receiving target based on the activation state of the smart terminal, ensuring transaction flexibility. In this invention, the system is inactive when the smart terminal screen is off and activated when the screen is on. This invention provides users with convenient payment options while also offering more secure payment methods. Users can select the receiving target and payment method based on their payment needs and scenarios. For example, for convenient payments without verification, users can conduct cryptocurrency transactions while the smart terminal screen is off, resulting in quick transactions. For secure payments requiring identity verification, users can activate the smart terminal system. After activation, transaction-related instructions are transmitted to the SE via HCE. If the transaction conditions meet the verification requirements, the user can verify their identity through the HCE service. Only after successful verification can the transaction be completed, enhancing transaction security.
[0103] In this embodiment of the invention, after the near-field communication controller determines the receiving target, the subsequent digital currency transaction processing is performed by the receiving target. In some embodiments of the invention, the receiving target's digital currency transaction processing includes responding to the payment application selection instruction and processing subsequent transaction instructions, generating transaction ciphertext, and sending the transaction ciphertext to the receiving terminal to complete the digital currency transaction.
[0104] S230: The near-field communication controller sends the payment application selection instruction to the receiving target. The receiving target generates selection response information according to the payment application selection instruction and sends the selection response information to the acceptance terminal through the near-field communication controller.
[0105] In this embodiment of the invention, the near-field communication controller sends instructions to different subjects for execution according to different receiving targets, which is flexible.
[0106] In some embodiments of the present invention, when the receiving target is a host-based card emulation application and a security unit, the near-field communication controller sends a payment application selection instruction to the host-based card emulation application, so that the host-based card emulation application forwards the payment application selection instruction to the security unit. The security unit generates selection response information according to the payment application selection instruction and sends the selection response information to the host-based card emulation application, so that the host-based card emulation application sends the selection response information to the acceptance terminal through the near-field communication controller.
[0107] In some embodiments of the present invention, when the receiving target is a security unit, the near-field communication controller sends a payment application selection instruction to the security unit. The security unit generates selection response information according to the payment application selection instruction and sends the selection response information to the near-field communication controller, so that the near-field communication controller sends the selection response information to the acceptance terminal.
[0108] In some embodiments of the present invention, different payment applications can be installed in the security unit, and the target payment application to be invoked can be determined based on the AID. Specifically, the security unit generates selection response information based on the payment application selection instruction, including:
[0109] In response to the payment application identifier in the payment application selection instruction matching the payment application identifier of the payment application installed in the security unit, the security unit calls the payment application corresponding to the payment application identifier to generate selection response information. The operation responded to by the security unit in this embodiment includes a judgment step.
[0110] For example, the security unit contains a digital currency payment application (corresponding AID: F001002003), a bank A account payment application (corresponding AID: F001002007), and a bank B account payment reference (corresponding AID: F001002008). When the AID in the payment application selection instruction is F001002003, the security unit determines that the AID in the payment application selection instruction matches the AID of the digital currency payment application installed in the security unit. The security unit then calls the digital currency payment application to generate selection response information, which includes a successful response message. When the AID in the payment application selection instruction is F001002009, the security unit determines that the AID in the payment application selection instruction does not match the AID of any application installed in the security unit. The security unit then generates a failed response message.
[0111] S240: The near-field communication controller receives the transaction instruction sent by the receiving terminal and sends the transaction instruction to the receiving target. The transaction instruction is generated by the receiving terminal after verifying and selecting response information. In this embodiment of the invention, the transaction instruction includes information such as the transaction amount and the recipient's wallet identifier.
[0112] In this embodiment of the invention, if the receiving terminal verifies the response information as successful, it sends a transaction instruction; if the response information is unsuccessful, the receiving terminal terminates the transaction.
[0113] In this embodiment of the invention, the transmission path for the response instruction is consistent with the transmission instruction for the transaction instruction, thus ensuring the integrity of the transaction.
[0114] In some embodiments of the present invention, when the receiving target is a host-based card emulation application and a security unit, the near-field communication controller obtains the transaction instruction sent by the receiving terminal, sends the transaction instruction to the host-based card emulation application, the host-based card emulation application performs identity verification processing according to the transaction instruction, and sends the verified transaction instruction to the security unit.
[0115] For large transactions or transactions requiring identity verification, this invention can utilize a host-based card emulation application to perform identity verification, ensuring transaction security. The identity verification principles of the host-based card emulation application in this invention can be set by the user. A limit can be set for password-free transactions. When the transaction amount is less than the limit, the host-based card emulation application determines that identity verification is not required and sends the transaction instruction to the security unit for processing. When the transaction amount is greater than the limit, the host-based card emulation application determines that identity verification is required. The host-based card emulation application accepts user-input identity verification information through an interactive interface, such as a payment password, mobile verification code, or fingerprint verification result. After successful verification, the host-based card emulation application adds an "identified" marker to the transaction instruction, and the security unit subsequently performs corresponding processing based on the "identified" marker.
[0116] In some embodiments of the present invention, such as Figure 4 As shown, the host-based card emulation application performs identity verification based on the transaction instruction and sends the verified transaction instruction to the security unit, including:
[0117] S241: The host-based card emulation application needs to verify the transaction instructions and perform identity verification processing to verify the identity information entered by the user.
[0118] S242: In response to successful identity verification, add an identity verification flag to the transaction instruction and send the transaction instruction to the security unit.
[0119] S243: In response to the failure of identity verification, a transaction failure message is sent to the acceptance terminal through the near-field communication controller so that the acceptance terminal terminates the transaction.
[0120] S244: Host-based card emulation applications verify transaction instructions without requiring identity verification. An unverified flag is added to the transaction instruction, and the transaction instruction is sent to the security unit.
[0121] The host-based card emulation application in this embodiment of the invention responds to operations including a judgment step.
[0122] In this embodiment of the invention, the host-based card emulation application verifies identity according to business rules or user-defined rules to ensure transaction security. When identity verification fails, a transaction failure message is returned to the receiving terminal.
[0123] In some embodiments of the present invention, when the receiving target is a security unit, the near-field communication controller receives a transaction instruction sent by the receiving terminal and sends the transaction instruction to the receiving target, including: the near-field communication controller acquiring the transaction instruction sent by the receiving terminal and sending the transaction instruction to the security unit.
[0124] In some embodiments of the present invention, when the receiving target is a security unit, the near-field communication controller sends a transaction instruction to the security unit according to the AID routing table, and the security unit processes the transaction instruction.
[0125] S250: The receiving target generates ciphertext according to the transaction instruction and sends the ciphertext to the receiving terminal through the near-field communication controller. This causes the receiving terminal to send the ciphertext to the digital currency backend system. After verifying the ciphertext, the digital currency backend system executes the digital currency transaction corresponding to the ciphertext type and sends the transaction result to the receiving terminal. In this embodiment of the invention, the plaintext corresponding to the ciphertext includes information such as the transaction amount, ciphertext type, payer's wallet identifier, and payee's wallet identifier.
[0126] In some embodiments of the present invention, when the receiving target is a host-based card emulation application and a security unit, the receiving target generates transaction ciphertext according to the transaction instruction and sends the transaction ciphertext to the receiving terminal through a near-field communication controller, including:
[0127] The security unit generates transaction ciphertext based on the transaction instruction, marks the type of transaction ciphertext based on the identity verification result, and sends the transaction ciphertext to the host-based card emulation application, so that the host-based card emulation application can send the transaction ciphertext to the acceptance terminal through the near field communication controller.
[0128] In some embodiments of the present invention, when the receiving target is a secure unit, the receiving target generates a transaction ciphertext according to the transaction instruction and sends the transaction ciphertext to the receiving terminal through the near-field communication controller, including:
[0129] The security unit generates ciphertext based on the transaction instruction, marks the type of the ciphertext as unverified, and sends the ciphertext to the near-field communication controller, so that the near-field communication controller can send the ciphertext to the receiving terminal.
[0130] In some embodiments of the present invention, when the security unit generates transaction ciphertext, it can also set the type of transaction ciphertext according to the identity verification mark in the transaction instruction.
[0131] In some embodiments of the present invention, the security unit marks the type of the encrypted transaction as verified based on the verified mark. The security unit also marks the type of the encrypted transaction as unverified based on the unverified mark. In these embodiments, the digital currency backend system executes digital currency transactions according to the type of the encrypted transaction. For example, when the transaction amount exceeds a limit, verification is required, but if the corresponding encrypted transaction type is unverified, the transaction fails, or the system prompts the user to input additional verification information to verify the user's identity. When the transaction amount is less than a limit, the digital currency backend system verifies that the encrypted transaction is unverified and then pays digital currency to the recipient's wallet based on the payer's wallet identifier in the encrypted transaction.
[0132] In some embodiments of the present invention, multiple payment applications are installed in the security unit. To ensure the accuracy of transactions, the security unit determines the target payment application based on the payment application identifier (AID) and processes the transaction instructions. Specifically, the security unit generates ciphertext based on the transaction instructions, including: the security unit calls the payment application corresponding to the payment application identifier and generates ciphertext based on the transaction instructions.
[0133] In some scenarios of the present invention, the digital currency back-end system includes the system or server of the operating institution corresponding to the payer's wallet and the system or server of the operating institution corresponding to the payee's wallet. In order to facilitate information exchange among multiple operating institutions, in some embodiments, the digital currency back-end system also includes an interconnection system or server that is connected to the system or server corresponding to each operating institution. In some transaction scenarios, the payee's wallet and the payer's wallet belong to the same cryptocurrency operator. In this case, the cryptocurrency transaction takes place on the same operator's server, and the transfer of cryptocurrency occurs within the operator's server or system. In other scenarios, if the payee's wallet and the payer's wallet do not belong to the same operator, the transaction occurs between the payee's operator's server or system, the payer's operator's server or system, and an interconnected server or system. For example, after the receiving terminal sends the encrypted transaction to the payee's operator's server or system, it identifies the operator corresponding to the payer's wallet based on the payer's wallet identifier. Then, it sends the transaction request to the operator corresponding to the payer's wallet through the interconnected system or server. The operator's server or system deducts the cryptocurrency corresponding to the transaction amount from the payer's wallet, while the payee's operator adds the cryptocurrency corresponding to the transaction amount to the payee's wallet. In some embodiments of the present invention, the payer wallet identifier can be associated with a parent wallet account. When deducting digital currency, it can be deducted from the parent wallet account. The operator of the payer wallet can identify the parent wallet account through the associated identifier of the payer wallet to make the deduction.
[0134] The digital currency transaction method in this embodiment of the invention can implement different levels of security verification mechanisms for different transaction needs and transaction business rules. It can provide both password-free fast payment methods and payment methods with secure identity verification mechanisms. The transaction process is short, which can ensure security and provide users with a convenient and fast experience.
[0135] The digital currency transaction method in this embodiment of the invention will be described below from the perspectives of user identity verification transaction process, seamless payment transaction process in active state, and seamless payment transaction process in inactive state.
[0136] like Figure 5As shown, in some embodiments of the present invention, the digital currency transaction method runs on system 600 in the figure. HCE application 611 is a client App that supports digital currency and uses HCE service installed on smart terminal 610. It provides a UI interaction interface for users, checks whether user verification is required, verifies user identity, and obtains user authorization for the transaction. The AID registered in the NFC controller is the AID of the SE wallet application.
[0137] The NFC controller 612 is a module on the smart terminal 610 that provides NFC functionality and is responsible for receiving and sending contactless communication data, registering and distributing AID routing tables.
[0138] SE613 is a security unit on the 610 smart terminal, including forms such as SWP-SIM, SWP-SD, and eSE. It has a user wallet application installed (uniquely identified by AID), stores wallet keys and user personal data, and is responsible for securely encrypting transaction data to generate transaction ciphertext.
[0139] The 620 payment terminal is a payment device that supports NFC card reader mode communication, including merchant POS, personal POS and other payment devices.
[0140] The Digital Currency Back-End System 630 is a back-end system that supports digital currency mobile payment functions. It includes back-end systems such as the payment and collection operation institution's back-end system and the central bank's interconnection system, and supports digital currency transactions within the institution and across institutions.
[0141] like Figure 6 As shown, in some embodiments of the present invention, the digital currency transaction method, when performing user identity verification transactions, is divided into a transaction initialization process and a transaction processing process. The specific steps are as follows.
[0142] The first stage is the transaction initialization process:
[0143] S310: The terminal uses NFC reader mode to send a command to select an AID, which is the wallet application AID.
[0144] S320: When the user brings the smart terminal close to the receiving terminal, the NFC controller receives the selection instruction. Based on the AID routing table and the activation status of the smart terminal system, it selects the APDU instruction receiving target as the HCE application and transmits the selection instruction to the HCE application (the HCE application has a UI interface, and its execution condition requires the smart terminal system to be in an active state).
[0145] S330: The HCE application passes the selection command to the wallet application in the SE and obtains the returned selection response, which is then passed to the NFC controller.
[0146] S340: The NFC controller transmits the received selection instruction response data to the receiving terminal.
[0147] The second stage is the transaction processing process:
[0148] S350: The receiving terminal continues to send transaction instructions. After receiving the transaction instructions, the NFC controller transmits them to the HCE application according to the receiving target determined during the transaction initialization process.
[0149] S360: The HCE application checks business rules, determines that user authentication is required, calls the smart terminal system UI interface, pops up a window to verify the user's identity and obtain user authorization, and proceeds to different branches depending on the success or failure:
[0150] a) If the transaction fails, the NFC controller sends a transaction failure message to the receiving terminal.
[0151] b) If successful, the transaction instruction is appended with the user's verified token and passed to the wallet application in the SE. The wallet application returns the user's verified transaction ciphertext, which is then returned to the receiving terminal via the HCE application and the NFC controller.
[0152] S370: The receiving terminal receives a transaction response. If the transaction fails, the transaction is terminated; otherwise, the encrypted transaction is transmitted to the digital currency back-end system.
[0153] S380: The digital currency back-end system performs different limit management and risk control based on the type of transaction encryption, and returns the transaction result to the receiving terminal.
[0154] This invention ensures transaction security by requiring user verification before conducting transactions.
[0155] like Figure 7 As shown, in some embodiments of the present invention, the digital currency transaction method, when performing a contactless payment transaction in the active state, is divided into a transaction initialization process and a transaction processing process. The specific steps are as follows.
[0156] The first stage is the transaction initialization process:
[0157] S410: The receiving terminal uses NFC reader mode and sends a command to select an AID, which is the wallet application AID.
[0158] S420: When the user brings the smart terminal close to the receiving terminal, the NFC controller receives the selection instruction. Based on the AID routing table and the activation status of the smart terminal system, it selects the APDU instruction receiving target as the HCE application and transmits the selection instruction to the HCE application (the HCE application has a UI interface, and its execution requires the smart terminal system to be in an active state).
[0159] S430: The HCE application passes the selection command to the wallet application in the SE and obtains the returned selection response, which is then passed to the NFC controller.
[0160] S440: The NFC controller transmits the received selection instruction response data to the receiving terminal.
[0161] The second stage is the transaction processing process:
[0162] S450: The receiving terminal continues to send transaction instructions. After receiving the transaction instructions, the NFC controller transmits them to the HCE application according to the receiving target determined during the transaction initialization process.
[0163] S460: The HCE application checks the business rules and determines that user verification is not required. It then directly transmits the transaction instruction to the wallet application in the SE. The wallet application returns the ciphertext of the transaction, which is then sent back to the receiving terminal via the HCE application and the NFC controller.
[0164] S470: The receiving terminal receives a transaction response. If the transaction fails, the transaction is terminated; otherwise, the encrypted transaction is transmitted to the digital currency back-end system.
[0165] S480: The digital currency back-end system performs different limit management and risk control based on the type of transaction encryption, and returns the transaction result to the receiving terminal.
[0166] According to the business rules, the present invention eliminates the need for identity verification after verifying the transaction instruction, thus achieving contactless payment and making transactions convenient.
[0167] like Figure 8 As shown, in some embodiments of the present invention, the digital currency transaction method for conducting contactless payment transactions in an inactive state is divided into a transaction initialization process and a transaction processing process. The specific steps are as follows.
[0168] The first stage is the transaction initialization process:
[0169] S510: The receiving terminal uses NFC reader mode and sends a command to select an AID, which is the wallet application AID.
[0170] S520: When a user brings their smart terminal close to the receiving terminal, the NFC controller receives the selection instruction. Based on the AID routing table and the inactive state of the smart terminal system, it selects the wallet application in the SE as the target for receiving the APDU instruction and transmits the selection instruction to the SE.
[0171] S530: The wallet application in the SE processes the selection command and returns a selection response to the NFC controller.
[0172] S540: The NFC controller transmits the selection instruction response data returned by the wallet application to the receiving terminal.
[0173] The second stage is the transaction processing process:
[0174] S550: The receiving terminal continues to send transaction instructions. After receiving the transaction instructions, the NFC controller transmits them to the SE according to the receiving target determined in step three.
[0175] S560: The wallet application in the SE returns the encrypted transaction information, which is then sent back to the receiving terminal via the NFC controller.
[0176] S570: The receiving terminal receives the encrypted transaction and transmits it to the digital currency back-end system.
[0177] S580: The digital currency back-end system manages different limits and controls risks based on the type of encrypted transaction, and returns the transaction results to the receiving terminal.
[0178] The digital currency transaction method in this embodiment of the invention supports seamless payment when the user terminal is not activated, making transactions convenient.
[0179] Figure 9 An exemplary system architecture 900 is shown that can be applied to the digital currency transaction method or digital currency transaction implementation apparatus of the present invention.
[0180] like Figure 9 As shown, system architecture 900 may include terminal devices 901, 902, and 903, network 904, and server 905. Network 904 is used as a medium to provide a communication link between terminal devices 901, 902, and 903 and server 905. Network 904 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.
[0181] Users can use terminal devices 901, 902, and 903 to interact with server 905 via network 904 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 901, 902, and 903, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0182] Terminal devices 901, 902, and 903 can be various electronic devices with displays that support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0183] Server 905 can be a server providing various services, such as a backend management server supporting shopping websites browsed by users using terminal devices 901, 902, and 903 (for example only). The backend management server can analyze and process data such as received product information query requests, and feed back the processing results (such as target push information, product information - for example only) to the terminal devices.
[0184] It should be noted that the digital currency transaction method provided in this embodiment of the invention is generally executed by server 905, and correspondingly, the digital currency transaction implementation device is generally set in server 905.
[0185] It should be understood that Figure 9 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0186] The following is for reference. Figure 10 It shows a schematic diagram of the structure of a computer system 1000 suitable for implementing terminal devices or servers of the present invention. The methods or apparatus for implementing the methods in the embodiments of the present invention can be implemented on the computer system 1000. Figure 10 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.
[0187] like Figure 10 As shown, the computer system 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage section 1008 into a random access memory (RAM) 1003. The RAM 1003 also stores various programs and data required for the operation of the system 1000. The CPU 1001, ROM 1002, and RAM 1003 are interconnected via a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.
[0188] The following components are connected to I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to I / O interface 1005 as needed. A removable medium 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 1010 as needed so that computer programs read from it can be installed into storage section 1008 as needed.
[0189] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1009, and / or installed from removable medium 1011. When the computer program is executed by central processing unit (CPU) 1001, it performs the functions defined in the system of this invention.
[0190] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0191] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0192] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a sending unit (or "module"), an acquisition unit, a determining unit, and a first processing unit. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a sending unit can also be described as "a unit that sends an image acquisition request to a connected server."
[0193] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to control a near-field communication controller to acquire a payment application selection instruction sent by a receiving terminal, the payment application selection instruction including a payment application identifier; control the near-field communication controller to respond to the payment application identifier in the payment application selection instruction matching the payment application identifier stored in the near-field communication controller; the near-field communication controller, based on the payment application selection instruction and the system activation state of the smart terminal, determines the receiving target of the payment application selection instruction, the receiving target being a security element or a host-based card emulation application and security element; and controls the near-field communication controller to select the payment application... The system sends a selection instruction to the receiving target, which generates a selection response based on the payment application's selection instruction and sends the selection response to the receiving terminal via the near-field communication controller. The system then controls the near-field communication controller to receive the transaction instruction from the receiving terminal and send it to the receiving target. This transaction instruction is generated by the receiving terminal after verifying the selection response. Finally, the system controls the receiving target to generate ciphertext based on the transaction instruction and sends the ciphertext to the receiving terminal via the near-field communication controller. This enables the receiving terminal to send the ciphertext to the digital currency backend system. The digital currency backend system verifies the ciphertext, executes the digital currency transaction corresponding to the ciphertext type, and sends the transaction result to the receiving terminal.
[0194] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A digital currency transaction method, characterized in that, Applied to a smart terminal, the smart terminal is equipped with a near-field communication controller, a security unit, and a host-based card emulation application. The method includes: The near-field communication controller acquires a payment application selection instruction sent by the acceptance terminal, the payment application selection instruction including a payment application identifier; The near-field communication controller responds to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier stored in the near-field communication controller, and determines the receiving target of the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal. The receiving target is the security unit or a host-based card emulation application and the security unit. The near-field communication controller sends the payment application selection instruction to the receiving target, and the receiving target performs digital currency transaction processing; wherein... The near-field communication controller determines the target for receiving the payment application selection instruction based on the payment application selection instruction and the system activation state of the smart terminal, including: In response to the smart terminal's system activation state being inactive and the payment application corresponding to the payment application identifier being installed in the security unit, the target of receiving the payment application selection instruction is determined to be the security unit. In response to the system activation status of the smart terminal being activated, the target of receiving the payment application selection instruction is determined to be a host-based card emulation application and security unit. The near-field communication controller sends the payment application selection instruction to the receiving target, and the receiving target performs digital currency transaction processing, including: The near-field communication controller sends the payment application selection instruction to the receiving target, and the receiving target generates selection response information according to the payment application selection instruction, and sends the selection response information to the acceptance terminal through the near-field communication controller; The near-field communication controller receives a transaction instruction sent by the receiving terminal and sends the transaction instruction to the receiving target, wherein the transaction instruction is generated by the receiving terminal after verifying the selection response information; The receiving target generates ciphertext according to the transaction instruction and sends the ciphertext to the receiving terminal via the near-field communication controller. The receiving terminal then sends the ciphertext to the digital currency backend system. After verifying the ciphertext, the digital currency backend system executes a digital currency transaction corresponding to the ciphertext type and sends the transaction result to the receiving terminal. When the receiving target is a host-based card emulation application and the security unit, the near-field communication controller sends the payment application selection instruction to the receiving target. The receiving target generates selection response information according to the payment application selection instruction and sends the selection response information to the acceptance terminal through the near-field communication controller, including: The near-field communication controller sends the payment application selection instruction to the host-based card emulation application, so that the host-based card emulation application forwards the payment application selection instruction to the security unit. The security unit generates selection response information according to the payment application selection instruction and sends the selection response information to the host-based card emulation application, so that the host-based card emulation application sends the selection response information to the acceptance terminal through the near-field communication controller. The near-field communication controller receives a transaction instruction sent by the receiving terminal and sends the transaction instruction to the receiving target, including: The near-field communication controller acquires the transaction instruction sent by the acceptance terminal and sends the transaction instruction to the host-based card emulation application. The host-based card emulation application performs identity verification processing according to the transaction instruction and sends the verified transaction instruction to the security unit. The host-based card emulation application verifies that the transaction instruction requires identity verification processing and verifies the identity verification information input by the user. In response to the successful verification of the identity information, an identity verification mark is added to the transaction instruction. The receiving target generates transaction ciphertext according to the transaction instruction and sends the transaction ciphertext to the receiving terminal through the near-field communication controller, including: The security unit generates ciphertext according to the transaction instruction, marks the type of the ciphertext according to the authentication processing result, and sends the ciphertext to the host-based card emulation application, so that the host-based card emulation application sends the ciphertext to the acceptance terminal through the near-field communication controller. The security unit marks the type of the ciphertext as authenticated according to the authenticated mark.
2. The method according to claim 1, characterized in that, When the receiving target is the security unit, the near-field communication controller sends the payment application selection instruction to the receiving target. The receiving target generates selection response information according to the payment application selection instruction and sends the selection response information to the acceptance terminal through the near-field communication controller, including: The near-field communication controller sends the payment application selection instruction to the security unit. The security unit generates selection response information based on the payment application selection instruction and sends the selection response information to the near-field communication controller, so that the near-field communication controller sends the selection response information to the acceptance terminal. The near-field communication controller receives a transaction instruction sent by the receiving terminal and sends the transaction instruction to the receiving target, including: The near-field communication controller acquires the transaction instruction sent by the receiving terminal and sends the transaction instruction to the security unit; The receiving target generates transaction ciphertext according to the transaction instruction and sends the transaction ciphertext to the receiving terminal through the near-field communication controller, including: The security unit generates ciphertext according to the transaction instruction, marks the type of the ciphertext as unverified, and sends the ciphertext to the near-field communication controller, so that the near-field communication controller sends the ciphertext to the receiving terminal.
3. The method according to claim 1, characterized in that, The host-based card emulation application performs identity verification based on the transaction instruction and sends the verified transaction instruction to the security unit, further comprising: In response to the failure of the identity verification, a transaction failure message is sent to the acceptance terminal through the near-field communication controller, so that the acceptance terminal terminates the transaction.
4. The method according to claim 1, characterized in that, The host-based card emulation application performs identity verification based on the transaction instruction and sends the verified transaction instruction to the security unit, including: The host-based card emulation application verifies that the transaction instruction does not require identity verification, adds an unverified flag to the transaction instruction, and sends the transaction instruction to the security unit. The security unit marks the type of the transaction ciphertext based on the authentication result, including: The security unit marks the type of the ciphertext as unverified based on the unverified tag.
5. The method according to claim 1 or 2, characterized in that, The security unit generates selection response information based on the payment application selection instruction, including: In response to the fact that the payment application identifier in the payment application selection instruction is consistent with the payment application identifier of the payment application installed in the security unit, the security unit calls the payment application corresponding to the payment application identifier to generate the selection response information.
6. The method according to claim 1 or 2, characterized in that, The security unit generates transaction ciphertext according to the transaction instruction, including: The security unit invokes the payment application corresponding to the payment application identifier and generates transaction ciphertext according to the transaction instruction.
7. A digital currency trading terminal, characterized in that, It includes a near-field communication controller, a security unit, and a host-based card emulation application device, wherein, The near-field communication controller is configured to acquire a payment application selection instruction sent by the acceptance terminal, the payment application selection instruction including a payment application identifier; The near-field communication controller is configured to respond to the payment application identifier in the payment application selection instruction being consistent with the payment application identifier stored in the near-field communication controller, and to determine the receiving target of the payment application selection instruction based on the payment application selection instruction and the system activation state of the digital currency transaction terminal, wherein the receiving target is the security unit or a host-based card emulation application and the security unit; The near-field communication controller is configured to send the payment application selection instruction to the receiving target, which is configured to perform digital currency transaction processing. The near-field communication controller is further configured to, in response to the system activation state of the digital currency trading terminal being inactive and the payment application corresponding to the payment application identifier being installed in the security unit, determine that the receiving target of the payment application selection instruction is the security unit; and in response to the system activation state of the digital currency trading terminal being activated, determine that the receiving target of the payment application selection instruction is the host-based card emulation application and the security unit. The near-field communication controller is further configured to: send the payment application selection instruction to the receiving target; the receiving target generates selection response information based on the payment application selection instruction and sends the selection response information to the acceptance terminal via the near-field communication controller; receive a transaction instruction sent by the acceptance terminal and send the transaction instruction to the receiving target, wherein the transaction instruction is generated by the acceptance terminal after verifying the selection response information; enable the receiving target to generate transaction ciphertext based on the transaction instruction and send the transaction ciphertext to the acceptance terminal via the near-field communication controller; enable the acceptance terminal to send the transaction ciphertext to the digital currency back-end system, and the digital currency back-end system verifies the... After the transaction is encrypted, a digital currency transaction corresponding to the transaction encryption type is executed, and the transaction result is sent to the receiving terminal; wherein, when the receiving target is a host-based card emulation application and the security unit, the near-field communication controller is further configured to send the payment application selection instruction to the host-based card emulation application, so that the host-based card emulation application forwards the payment application selection instruction to the security unit, the security unit generates selection response information according to the payment application selection instruction, and sends the selection response information to the host-based card emulation application, so that the host-based card emulation application sends the selection response information to the receiving terminal through the near-field communication controller; The near-field communication controller is further configured to acquire a transaction instruction sent by the acceptance terminal, send the transaction instruction to the host-based card emulation application, the host-based card emulation application perform identity verification processing according to the transaction instruction, and send the verified transaction instruction to the security unit. The host-based card emulation application verifies that the transaction instruction requires identity verification and verifies the identity verification information input by the user. In response to successful identity verification, an identity verification mark is added to the transaction instruction. The security unit is further configured to generate transaction ciphertext according to the transaction instruction, mark the type of the transaction ciphertext according to the authentication processing result, and send the transaction ciphertext to the host-based card emulation application, so that the host-based card emulation application sends the transaction ciphertext to the acceptance terminal through the near-field communication controller, wherein the security unit marks the type of the transaction ciphertext as authenticated according to the authenticated mark.
8. An electronic device, characterized in that, include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to perform the method as described in any one of claims 1-6.
9. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-6.
Citation Information
Patent Citations
Payment method payment device
CN106600272A
A data processing method and related apparatus
CN109076428B