Data processing method, system, device, apparatus, medium and computer product

By generating digital identity credentials that integrate user personal identity, payment account, and payment device identity, and using blockchain technology for end-to-end verification and storage, the problem of leakage and tampering of payment transaction data during transmission is solved, achieving higher security and resource efficiency.

CN119515382BActive Publication Date: 2025-10-21CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411515503.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-28
Publication Date
2025-10-21
Estimated Expiration
2044-10-28

AI Technical Summary

Technical Problem

In the field of electronic payments, payment transaction data is easily leaked and tampered with during transmission, and existing technologies cannot guarantee data security throughout the entire process.

Method used

By generating digital identity credentials that integrate the user's personal identity, payment account, and payment device identity as proof of the user's willingness to pay, anonymization and desensitization are achieved. Blockchain technology is used for end-to-end verification and storage to ensure the security of data transmission.

Benefits of technology

It improves the security of payment transaction data, reduces the risk of data leakage and tampering, and reduces the investment in encryption resources for transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119515382B_ABST
    Figure CN119515382B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method, system, device, equipment, medium and computer product. The application belongs to the technical field of data processing. The method comprises the following steps: determining an identity credential set according to identity information of a user carried in a credential application request initiated by a payment application system, wherein the identity credential set comprises a user identity credential used for representing a personal identity of the user, an account identity credential used for representing a payment account of the user, and a device identity credential used for representing a payment device of the user; and determining a digital identity credential used for proving a digital identity of the user in an electronic payment service and reflecting a payment intention of the user based on the identity credential set. In this way, the integrated digital identity credential integrating the personal identity of the user, the payment account of the user and the multiple attributes of the payment device of the user is realized, the user transaction data is anonymized and desensitized, the possibility of leaking the user transaction data is removed from the source, and the security of the user transaction data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of data processing technology, and in particular relates to a data processing method, system, device, equipment, medium and computer product. Background Art

[0002] In the field of electronic payments, payment transaction authorization relies on the verification of the payment account and user identity by the account issuer. Specifically, it must confirm that the payment transaction is initiated by a genuine user, in accordance with the user's genuine payment intention, and using a real and valid payment account.

[0003] In related technologies, user transaction data, such as payment account data and user identity data, typically needs to be transferred between multiple payment processing terminals, such as the merchant terminal and the resource transfer terminal. However, preventing data leakage risks relies on the protection capabilities of each processing terminal, making it difficult to ensure data security throughout the entire payment transaction process. Data leakage is prone to occur during data transmission, reducing the security of user transaction data. Summary of the Invention

[0004] The embodiments of the present application provide a data processing method, system, device, equipment, medium and computer product, which can solve the problem in related technologies that user transaction data is easily leaked and tampered with, thereby reducing the security of transaction data.

[0005] In a first aspect, an embodiment of the present application provides a data processing method, applied to a payment switching system, comprising:

[0006] Receive a credential application request from the payment application system, which carries the user's identity information;

[0007] Determine the user's identity credential set based on the identity information. The identity credential set includes user identity credentials, account identity credentials, and device identity credentials. The user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device.

[0008] Based on the user identity credential, account identity credential and device identity credential, a digital identity credential is determined. The digital identity credential is a credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay.

[0009] In a second aspect, an embodiment of the present application provides a data processing device, which is applied to a payment switching system. The device may include:

[0010] A receiving module is used to receive a credential application request initiated by a payment application system, the credential application request carrying the user's identity information;

[0011] A determination module, configured to determine a user's identity credential set based on the identity information, the identity credential set including a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device;

[0012] The determination module is also used to determine the digital identity credential based on the user identity credential, the account identity credential and the device identity credential. The digital identity credential is a credential used to prove the user's digital identity in the electronic payment business and reflect the user's willingness to pay.

[0013] In a third aspect, an embodiment of the present application provides a data processing system, including a payment application system and a payment switching system; wherein,

[0014] The payment application system is used to initiate a credential application request, which carries the user's identity information;

[0015] The payment switching system is used to determine the user's identity credential set based on the identity information. The identity credential set includes user identity credentials, account identity credentials, and device identity credentials. The user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device;

[0016] The payment switching system is also used to determine digital identity credentials based on user identity credentials, account identity credentials and device identity credentials. Digital identity credentials are credentials used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay.

[0017] In a fourth aspect, an embodiment of the present application provides a computer device, the computer device comprising: a processor and a memory storing computer program instructions;

[0018] When the processor executes the computer program instructions, the data processing method shown in the first aspect is implemented.

[0019] In a fifth aspect, an embodiment of the present application provides a computer storage medium having computer program instructions stored thereon, which, when executed by a processor, implements the data processing method shown in the first aspect.

[0020] In a sixth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the data processing method shown in the first aspect.

[0021] In a seventh aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the data processing method shown in the first aspect.

[0022] The data processing method, system, apparatus, equipment, medium and computer product of the embodiments of the present application determine the user's identity credential set through the user's identity information carried in the credential application request initiated by the payment application system, and the identity credential set includes a user identity credential, an account identity credential and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; then, based on the user identity credential, the account identity credential and the device identity credential, a digital identity credential is determined, and the digital identity credential is a credential used to prove the user's digital identity in the electronic payment business and reflect the user's willingness to pay. In this way, a hybrid digital identity credential that integrates multiple attributes of the user's personal identity, user payment account and user payment device is established, and an integrated credential of personal identity, device identity and account identity is established. It can be used as a credential to prove the user's true payment intention from multiple dimensions when the electronic payment transaction occurs, and the user's transaction data is anonymized and desensitized, eliminating the possibility of leakage of user transaction data during the electronic payment transaction process from the source, avoiding the situation where user transaction data is easily leaked and tampered with, improving the security of transaction data, and reducing the transmission encryption, storage encryption and other resources invested by each processing end to protect user transaction data. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 A schematic diagram of the structure of a data processing system provided in an embodiment of the present application;

[0025] Figure 2 A schematic diagram of the structure of a digital identity credential generation system provided by an embodiment of the present application;

[0026] Figure 3 A schematic diagram of the structure of digital identity credential storage and transmission in a data processing system provided in an embodiment of the present application;

[0027] Figure 4 A schematic diagram of the structure of digital identity credential transmission in a data processing system provided in an embodiment of the present application;

[0028] Figure 5 A schematic diagram of the structure of a digital identity credential verification system provided in an embodiment of the present application;

[0029] Figure 6 A flowchart of a data processing method provided in an embodiment of the present application;

[0030] Figure 7 is a structural diagram of a data processing device provided by an embodiment of the present application;

[0031] Figure 8 It is a structural diagram of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0032] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0033] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0034] The acquisition, storage, use, and processing of data (including but not limited to the features and information herein) in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0035] In the field of electronic payments, the authorization of a payment transaction relies on the account issuer's verification of the payment account and user identity. This verification requires confirmation that the payment transaction is initiated by a genuine user, in accordance with the user's genuine payment intention, and using a valid payment account. In traditional payment processes, upon receiving a payment transaction, the account issuer verifies user transaction data, including payment account data and user identity data. During this process, payment account data and user identity data are transmitted in plain text between multiple payment processing terminals, such as the merchant terminal and the resource transfer terminal. However, preventing data leakage risks relies on the protection capabilities of each processing terminal, making it difficult to guarantee data security throughout the entire payment transaction process. Data leakage is prone to occur during data transmission, compromising the security of user transaction data.

[0036] Specifically, the current electronic payment transaction authentication model generally requires that the accepting merchant or accepting institution provide an information collection entrance on its own page. With the user's authorization, the information collection portal collects the user's payment account data, user identity data and other user transaction data, transmits it to the transfer institution through the backend system, and then forwards it to the account issuer. After receiving the payment transaction, the account issuer verifies the payment account data, user identity data and other user transaction data. Therefore, the account issuer needs to obtain user authorization from the accepting merchant or accepting institution every time a payment event occurs, directly collect payment account data and user identity data, and transmit them in the payment network. On the one hand, the user is required to repeatedly provide payment account data, user identity data and user transaction data when a payment event occurs, which affects the convenience of payment; on the other hand, the collection, transmission, storage and use of user transaction data depends on the protection capabilities of each processing node to prevent data leakage risks, making it difficult to ensure security throughout the process.

[0037] Furthermore, the current verification of payment account data by the account issuer can be achieved by verifying account data submitted by the user when initiating payment, such as financial institution account, payment account number, or authentication data such as payment password, SMS verification code, biometric data, etc. These data are directly collected by the accepting merchant or acceptance institution and transmitted to the account issuer through the transfer institution. The verification of user identity is entirely carried out by the account issuer based on the retained information. This method relies on the information retained by the account issuer. If there are anomalies in the retained information, the user identity cannot be verified. Although the account issuer can call the verification service of the identity information management authority to perform secondary verification of the payment account data, this will increase the processing of accessing the verification service during the transaction, which will extend the transaction processing chain and reduce the processing efficiency of the payment transaction.

[0038] Furthermore, the verification of user identity by the account issuer usually involves the following methods: first, the user identity data obtained during the transaction is compared with the identity data retained when the user opened the account. If they match, the verification is deemed successful. Second, the account issuer transmits the user identity data obtained during the transaction to the identity data management authority for secondary verification of the identity data. The verification is considered successful only when the verification is confirmed by the identity data management authority. However, the user's authorization to use payment account data and user identity data in each electronic payment transaction reflects the user's approval of the current payment behavior, agreement to use a fixed account for payment, and agreement to use the user's user identity data in this payment. However, each authorization for a transaction requires the user to provide relevant information, which is prone to the risk of information being misused. The acceptance agency, transfer agency, and account issuer retain records of the information provided by the user in the transaction log, which is prone to the risk of information leakage.

[0039] In order to solve the above technical problems, the embodiments of the present application provide a data processing system, method, apparatus, computer equipment and storage medium.

[0040] Based on this, the following will be combined with the Figures 1 to 8 , describes in detail the data processing system, method, apparatus, computer equipment and storage medium of the embodiments of the present application. It should be noted that these embodiments are not intended to limit the scope of disclosure of the present application.

[0041] First, in order to better illustrate the contents of the embodiments of the present application, the following are respectively combined with Figures 1 to 5 According to the process of generating, storing, transmitting and verifying digital identity credentials, a data processing system provided in an embodiment of the present application is described as follows.

[0042] In some embodiments of the present application, for the generation of digital identity credentials, the data processing system may include a payment application system 101, a payment acceptance system 102, and a payment switching system 103. The payment application system 101 may be an electronic device of the user, and the electronic device may be a mobile phone, tablet computer, laptop computer, PDA, vehicle-mounted electronic device, or other device with a payment function. The payment acceptance system 102 may be a payment collection device of the merchant, and the payment collection device may be a point of sales (POS), a barcode scanning cash register, a mobile phone, a tablet computer, or other device with a payment collection function. The payment switching system 103 is a server or cloud server that is connected to the payment application system 101 and the payment acceptance system 102 and generates digital identity credentials.

[0043] Specifically, the payment application system 101 is used to initiate a credential application request, which carries the user's identity information.

[0044] The payment acceptance system 102 is used to send the credential application request initiated by the payment application system 101 to the payment switching system 103 .

[0045] The payment switching system 103 is configured to receive a credential application request from the payment acceptance system 102 and determine the user's identity credential set based on the identity information in the credential application request. The identity credential set includes a user identity credential, an account identity credential, and a device identity credential. The user identity credential represents the user's personal identity, the account identity credential represents the user's payment account, and the device identity credential represents the user's payment device. The payment switching system is also configured to determine a digital identity credential based on the user identity credential, the account identity credential, and the device identity credential. The digital identity credential is a credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay.

[0046] In this embodiment, the identity credential set in the embodiment of the present application includes three identity credentials, namely user identity credentials, account identity credentials and device identity credentials. Based on this, the payment transfer system needs to interact with the identity authentication system, the account issuer system and the payment device management system respectively to obtain the corresponding identity credentials. Figure 2 A detailed description of the process of determining the identity credentials in the identity credential set is provided.

[0047] like Figure 2 As shown, in the embodiment of generating digital identity credentials, the data processing system 10 includes the following Figure 1 In addition to the system shown, it may also include an identity authentication system 201 , an account issuer system 202 and a payment device manager system 203 .

[0048] The identity authentication system 201 may be the system of an identity authentication institution used to verify a user's personal identity. The account issuer system 202 is the issuer of the user's payment account. For example, if the user's payment account is a bank card account, the account issuer system 202 may be the system of the financial institution that issued the bank card. For another example, if the user's payment account is a mobile payment account, the account issuer system 202 may be the system of the mobile payment institution to which the mobile payment account belongs. The payment device manager system 203 may be the system of the device manufacturer's server for the device corresponding to the payment application system 101.

[0049] In some embodiments of the present application, the data processing system further includes an identity authentication system 201. This system can generate a user identity credential to verify the user's identity. Specifically, the payment switching system 103 is configured to send a first request to the identity authentication system, the first request carrying identity information. Identity authentication system 201 verifies the identity information and, if the identity information passes verification, digitally signs the identity information to obtain a user identity credential corresponding to the identity information. The user identity credential is then sent to the payment switching system 103.

[0050] For example, Figure 2 As shown, the process of issuing and obtaining a user identity credential may include the payment application system 101 transmitting collected identity information, such as bank card passwords, social media communication numbers, user names, and identification document numbers, to the payment transfer system 103 via the acceptance institution system 102. Identity authentication is then performed between the payment transfer system 103 and the identity authentication system 201. Specifically, the identity authentication system 201 receives the identity information sent by the payment transfer system 103 and verifies the identity information using the credential service capabilities established by the identity authentication system 201 based on blockchain technology. If the identity information passes verification, the identity information, such as the identification document number, can be digitally signed using the system certificate of the identity authentication system 201 to obtain an identity credential identification code. In this case, the identity credential identification code can be used as the user identity credential.

[0051] In other embodiments of the present application, an account identity credential may be generated by the account issuer system 202 to verify the association between the user and the user's legitimate user payment account. Based on this, the data processing system also includes the account issuer system 202.

[0052] Based on this, the payment switching system 103 is also used to obtain the user's user personal certificate based on the identity information; digitally sign the identity information and the user identity certificate through the user personal certificate to obtain the first signature data; and send a second request to the account issuer system 202, the second request carrying the first signature data. The account issuer system 202 is used to verify the first association relationship between the identity information and the user's user payment account based on the first signature data, and when the first association relationship is verified, digitally sign the identity information and the user payment account to obtain the account identity certificate; and send the account identity certificate to the payment switching system 103. Here, the user personal certificate in the embodiment of the present application can be a digital certificate used to verify personal identity, which is usually issued by an authoritative third-party organization, such as a certificate authority (CA), and can contain the user's public key, issuer information, validity period and other data to ensure the authenticity and security of the user's identity when conducting online transactions or accessing protected resources.

[0053] For example, Figure 2 As shown, the process of issuing and obtaining an account identity credential may include: the payment switching system 103 obtaining a user personal certificate based on the identity information, and digitally signing the identity information and the user identity credential using the user personal certificate to obtain first signature data, thereby notifying the account issuer system 202 of the authenticity of the identity information and the user identity credential. The account issuer system 202 is then configured to verify, based on the first signature data and the association between the preset identity information and the user payment account established by the account issuer system 202, the first association between the identity information in the first signature data and the user's payment account. If the first association is verified, the system certificate of the account issuer system 202 is used to digitally sign the identity information and the user payment account to obtain the account identity credential, and then send the account identity credential to the payment switching system 103.

[0054] In other embodiments of the present application, the data processing system also includes a payment device management system 203, and the credential application request also carries device information of the user payment device used by the user, such as device identification, device physical address, and other information used to identify the user payment device.

[0055] Based on this, the payment switching system 103 is further configured to obtain the user's personal certificate based on the identity information; digitally sign the identity information, device information, and user identity credential using the user's personal certificate to obtain a second signature data; and send a third request to the payment device system, the third request carrying the second signature data. The payment device management system 303 is configured to verify the second association between the identity information and the device information based on the second signature data, and if the second association is verified, digitally sign the identity information and device information to obtain a device identity credential; and send the device identity credential to the payment device system.

[0056] For example, we can still refer to Figure 2 The process of obtaining the device identity credential may include the following: the credential application request initiated by the payment application system 101 may also include device information of the user's payment device. In this case, the payment switching system 103 may digitally sign the identity information, user identity credential, and device information using the user's personal certificate to obtain second signature data, thereby notifying the payment device management system 303 of the authenticity of the identity information and user identity credential. The second signature data is then sent to the payment device management system 303. Based on the second signature data, the payment device management system 303 may verify the second association between the identity information in the second signature data and the user's payment device using the association established by the payment device management system 303 (or using the device management capabilities established by the payment device management system 303 based on blockchain technology). If the second association is verified, the identity information and device information are digitally signed using the system certificate of the payment device management system 303 to obtain the device identity credential, which is then sent to the payment switching system 103.

[0057] Therefore, the digital identity credential provided in the embodiment of the present application is a fusion digital identity credential that integrates multiple attributes such as the user's personal identity, payment account, and payment device. It can be used as a credential to prove the user's true willingness to pay from multiple dimensions when the electronic payment transaction occurs. This changes the current payment scenario where the user's true intention can only be reflected by verifying the verification elements associated with the payment account entered by the user. For each system in the transaction chain, such as the payment application system 101, the payment acceptance system 102, the payment transfer system 103, and the account issuer system 202, if the digital identity credential is accepted, the digital identity credential can be used as a basis for identifying the user and judging whether the payment behavior is in line with the user's wishes. This method can be used as a supplement to the existing account verification element verification method, or as a replacement for the existing verification method.

[0058] In other embodiments of the present application, Figure 3 As shown, for the custody of digital identity credentials, the data processing system may further include a credential custodian system 301 for storing and verifying digital identity credentials. Here, credential custodian system 301 may be a server in the payment switching system 103 for storing and verifying digital identity credentials, or a server or system of a neutral third party for storing and verifying digital identity credentials, such as a credential custody service established based on blockchain technology.

[0059] Based on this, the data processing system provided in the embodiment of the present application also includes a credential depository system 301; wherein, the payment switching system 103 is also used to send a fourth request to the credential depository system, and the fourth request carries the user identity credential, the account identity credential, and the device identity credential. The credential depository system 301 is used to verify the third association relationship between the user identity credential, the account identity credential, and the device identity credential based on the fourth request, and generate a credential depository certificate if the third association relationship is verified successfully; and send the credential depository certificate to the credential depository system. The payment switching system 103 is also used to digitally sign the user identity credential, the account identity credential, and the device identity credential through the credential depository certificate and the user's personal certificate to obtain a digital identity credential.

[0060] For example, after the payment switching system 103 obtains the user identity credential, account identity credential, and device identity credential, it sends the three types of identity credential to the credential depository system 301. The credential depository system 301 can associate the user identity credential with the designated user based on its pre-stored user identity credential identification code and verify the authenticity of the credential by verifying the digital signatures of the identity authentication system 201, the account issuer system 202, and the payment device management system 203. If the identity credential verification by the three parties passes, the credential depository system can send the credential depository certificate to the credential depository system. In this way, the payment switching system 103 can digitally sign the user identity credential, account identity credential, and device identity credential using the user's personal certificate and the credential depository certificate to obtain a digital identity credential. This digital identity credential can be sent to the payment application system 101 for storage on the user device corresponding to the payment application system 101, such as in the user device's security chip and / or payment application. Furthermore, this digital identity credential can also be stored in the credential depository system 301 for subsequent verification.

[0061] Therefore, this application is a privately proposed digital identity credential security authentication method, which can integrate the digital signature authentication of various information systems, namely the identity authentication system 201, the account issuer system 202, and the payment device management system 203. It can achieve traceability of the entire digital signature authentication process and tamper-proofing of the entire data transmission process. It has high security, availability and non-repudiation, and changes the current payment scenario where transaction evidence can only be obtained by querying transaction details at each transaction processing node, effectively reducing the cost of restoring abnormal situations in the payment scenario.

[0062] Here, it should be noted that in addition to sending the digital identity credentials to the credential custodian system 301, in order to improve the verification efficiency of the credential custodian system 301, the payment transfer system 103 can also send the processing information of determining the identity credential set and the public key of the digital signature of the target system to the credential custodian system 301. In this way, the credential custodian system 30 can retain relevant information on the blockchain through the data storage capability established by the credential custodian system 301 based on blockchain technology, for use in subsequent verification services.

[0063] Therefore, the digital identity credential security authentication method proposed in the embodiments of this application can achieve evidence storage through secure technical means. In the event of a dispute in an electronic payment transaction, each system can obtain the corresponding digital identity credential through the entry query of the credential depository system 301 as evidence to resolve the transaction dispute. By using digital identity credentials that are more easily recognized by all parties and retained on a neutral third party (or blockchain), the trust issues of each system in other transaction participants are effectively resolved.

[0064] In some further embodiments of the present application, the present invention is directed to a process of delivering digital identity credentials.

[0065] In the embodiment of the present application, when the payment application system 101 initiates a payment request, the digital identity certificate can be read from the security chip and / or payment application of the user device where the payment application system 101 is located according to the user's authorization permission, and the digital identity certificate can be sent to various systems on the transaction processing path through the payment request along with the transaction order, such as the payment acceptance system 102, the payment transfer system 103, the account issuer system 202 and the certificate depository system 301. These systems can obtain and use the digital identity certificate in the payment request or transaction order. Figure 4 As shown, the payment application system 101 can generate a payment request based on the digital identity credential and transaction order. During the transaction processing, each system obtains the digital identity credential from the payment request and uses the information contained therein as needed. Each system can verify the digital identity credential as needed, using the credential verification service provided by the credential depository system.

[0066] In some further embodiments of the present application, the present invention provides credential verification for digital identity credentials.

[0067] In the embodiment of the present application, each party involved in the electronic payment transaction, such as Figure 5 As shown, the payment acceptance system 102 , the payment switching system 103 and the account issuer system 202 can all perform voucher verification by calling the voucher verification capability provided by the voucher depository system 301 .

[0068] like Figure 5 As shown, the credential depository system 301 is also used to store the digital identity credentials carried in the second instruction, the processing information for determining the identity credential set, and the public keys of the digital signatures of multiple processing systems based on the second instruction sent by the payment switching system. When the payment application system initiates a payment request, it receives a verification request sent by the target system, the payment request carries the transaction order and the target credential, and the target credential includes the digital identity credential; based on the verification request, it verifies the target credential with the digital identity credential, the processing information for determining the identity credential set, and the public keys of the digital signatures of multiple processing systems, wherein the target system includes at least one of the following: the payment acceptance system that accepts the payment request, the payment switching system, and the account issuer system for settling the transaction order; if the target credential is verified, a verification pass message is sent to the target system.

[0069] For example, the target system, a party participating in an electronic payment transaction, initiates a credential verification request using the credential verification capability provided by the credential depository system 301. The credential depository system 301 verifies the digital identity credential and, if the verification is successful, sends a verification success message to the target system.

[0070] The digital identity credential security authentication method proposed in this application embodiment uses a trusted identity credential that circulates throughout the entire business process, confining the authentication process to a specific business role. Other roles in the business chain can directly use the digital identity credential without repeated verification. This changes the situation in which each transaction processing node in the payment scenario needs to collect user identity information and send it to the identity authentication source agency for verification. Instead, it achieves one-time verification and multiple uses, effectively reducing the overall cost of identity authentication in the payment transaction chain.

[0071] In summary, the embodiments of the present application provide a digital identity credential that is anonymized, desensitized, verifiable, transferable, and multi-party authenticated, which replaces the current mode of transmitting and verifying original, plaintext payment account data and user identity data. It can ensure the data security of the entire payment transaction process, avoid data leakage that is prone to occur during the early transmission of transaction data from the source, improve the security of user transaction data, and reduce the cost of transmission encryption, storage encryption and other resources invested by various systems to protect user transaction data.

[0072] Then, combine the following Figure 6 A data processing method provided in an embodiment of the present application is described as follows.

[0073] Figure 6 A flowchart of a data processing method provided in an embodiment of the present application.

[0074] like Figure 6 As shown, the data processing method can be applied to Figures 1 to 5 Based on the payment switching system shown in , the data processing method may specifically include the following steps:

[0075] Step 610: Receive a credential application request initiated by the payment application system, which carries the user's identity information; Step 620: Determine the user's identity credential set based on the identity information, which includes a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; Step 630: Determine a digital identity credential based on the user identity credential, the account identity credential, and the device identity credential, which is a credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay.

[0076] Therefore, the embodiment of the present application integrates a fusion digital identity credential including multiple attributes of the user's personal identity, user payment account and user payment device, and establishes an integrated credential of personal identity, device identity and account identity. It can be used as a credential to prove the user's true payment intention from multiple dimensions when the electronic payment transaction occurs, and realizes the anonymization and desensitization of user transaction data, thereby eliminating the possibility of leakage of user transaction data during the electronic payment transaction process from the source, avoiding the situation where user transaction data is easily leaked and tampered with, improving the security of transaction data, and reducing the transmission encryption, storage encryption and other resources invested by each data processing end to protect user transaction data.

[0077] The above steps are described in detail below.

[0078] In step 610, in some embodiments of the present application, the payment switching system may receive a credential request initiated by the payment application system and forwarded by the payment acceptance system. The credential request carries the user's identity information. In embodiments of the present application, the identity information may include, but is not limited to, the user's personal information, such as bank card passwords, social media contact numbers, usernames, and identification card numbers.

[0079] Regarding step 620, the identity credential set in the embodiment of the present application includes three identity credentials, namely, user identity credentials, account identity credentials and device identity credentials. Based on this, the steps of how to determine different identity credentials are explained separately below.

[0080] In some embodiments of the present application, the user identity credentials may be determined through the following steps 6201 and 6202. Based on this, the step 620 may specifically include steps 6201 and 6202.

[0081] Step 6201: Send a first request to the identity authentication system. The first request carries identity information. The first request is used to request the identity authentication system to verify the identity information and generate a user identity credential corresponding to the identity information if the identity information passes the verification. The user identity credential is the data obtained after the identity authentication system digitally signs the identity information.

[0082] Step 6202: Receive user identity credentials sent by the identity authentication system.

[0083] For example, the identity authentication system may send identity information to the identity authentication system for authentication. Specifically, the identity authentication system receives the identity information sent by the payment switching system and verifies the identity information using the credential service capabilities established by the identity authentication system based on blockchain technology. If the identity information is verified, the identity information, such as the identity card number, can be digitally signed using the identity authentication system's system certificate to obtain an identity credential identification code. In this case, the identity credential identification code can be used as the user's identity credential.

[0084] In some other embodiments of the present application, the account identity credentials may be determined through the following steps 6203 and 6206. Based on this, step 620 may specifically include steps 6203 and 6206.

[0085] Step 6203: Obtain the user's personal certificate based on the identity information.

[0086] Step 6204: Digitally sign the identity information and user identity credentials using the user's personal certificate to obtain first signature data.

[0087] Step 6205: Send a second request to the account issuer system. The second request carries the first signature data. The second request is used to request the account issuer system to verify the first association between the identity information and the user's payment account based on the first signature data, and generate an account identity credential if the first association is verified. The account identity credential is data obtained after the account issuer system digitally signs the identity information and the user payment account.

[0088] Step 6206: Receive the account identity credentials sent by the identity authentication system.

[0089] Exemplarily, the payment switching system can obtain the user's personal certificate based on the identity information, and digitally sign the identity information and user identity credential through the user's personal certificate to obtain the first signature data, so as to inform the account issuer system of the authenticity of its identity information and user identity credential. In this way, the account issuer system can verify the first association relationship between the identity information in the first signature data and the user's payment account based on the first signature data and the association relationship between the preset identity information and the user's payment account. When the first association relationship is verified, the system certificate of the universal account issuer system is used to digitally sign the identity information and the user's payment account to obtain the account identity credential, so as to send the account identity credential to the payment switching system, thereby obtaining the account identity credential.

[0090] In some other embodiments of the present application, the device identity credential can be determined through the following steps 6207 and 6210. Based on this, the credential application request also carries the device information of the user payment device used by the user. The step 620 can specifically include steps 6207 and 6210.

[0091] Step 6207: Obtain the user's personal certificate based on the identity information.

[0092] Step 6208: Digitally sign the identity information, device information, and user identity credentials using the user's personal certificate to obtain second signature data.

[0093] Step 6209: Send a third request to the payment device system. The third request carries the second signature data. The third request is used to request the payment device system to verify the second association between the identity information and the device information based on the second signature data, and generate a device identity credential if the second association is verified. The device identity credential is the data obtained after the payment device system performs a data signature on the identity information and the device information.

[0094] Step 6210: Receive the device identity certificate sent by the payment device system.

[0095] For example, the credential application request initiated by the payment application system may also carry the device information of the user's payment device. In this case, the payment switching system may digitally sign the identity information, user identity credential, and device information using the user's personal certificate to obtain second signature data, thereby informing the payment device management system of the authenticity of the identity information and user identity credential, i.e., sending the second signature data to the payment device management system. In this way, the payment device management system can verify the second association between the identity information in the second signature data and the user's payment device based on the second signature data and the preset association between the identity information and the user's payment device (or, using the device management capabilities established by the payment device management system based on blockchain technology). In this way, if the second association is verified, the identity information and device information are digitally signed using the system certificate of the payment device management system to send the account identity credential to the payment switching system, thereby obtaining the device identity credential.

[0096] Therefore, during the payment preparation stages such as user registration, real-name authentication, and account binding, while verifying the user's real-name identity, an identity credential representing the user's personal identity is obtained, and the account identity credential is obtained from the account issuer's system. For payment scenarios involving personal payment devices, the device identity credential is obtained from the device system, thereby establishing a digital identity credential that integrates personal identity, device identity, and account identity. As a credential from multiple sources, this digital identity credential can be deposited with a neutral third party, or blockchain technology can be used to put the credential on the chain, further reducing the risk of tampering when using a single-source credential. It should be noted that identity information includes the user's ID number, and the user identity credential includes an identity credential identification code generated based on the user's ID number; the account identity credential includes an identity credential identification code generated based on the user's ID number and the user's payment account number; and the device identity credential includes an identity credential identification code generated based on the user's ID number and the device identification number of the user's payment device.

[0097] Regarding step 630, in some embodiments of the present application, step 630 may specifically include steps 6301 to 6303.

[0098] Step 6301: Send a fourth request to the credential custodian system. The fourth request carries the user identity credential, the account identity credential, and the device identity credential. The fourth request is used to request the credential custodian system to verify the third association relationship among the user identity credential, the account identity credential, and the device identity credential, and generate a credential custodian certificate when the third association relationship verification is successful.

[0099] Step 6302: Receive the credential depository certificate sent by the credential depository system.

[0100] Step 6303: Digitally sign the user identity certificate, account identity certificate, and device identity certificate using the certificate custodian certificate and the user's personal certificate to obtain a digital identity certificate.

[0101] For example, after the payment switching system obtains the user identity credential, account identity credential, and device identity credential, it sends the three types of identity credential to the credential custodian system. The credential custodian system then associates the user identity credential with the designated user based on its pre-stored user identity credential identification code. The credential custodian system verifies the authenticity of the digital signatures generated by the identity authentication system, the account issuer system, and the payment device management system. If the identity credential verification by the three parties passes, the credential custodian certificate is sent to the credential custodian system. In this way, the payment switching system 103 can digitally sign the user identity credential, account identity credential, and device identity credential using the user's personal certificate and the credential custodian certificate to obtain a digital identity credential.

[0102] Furthermore, the above-mentioned step 6303 may specifically include steps 63031 to 63033.

[0103] Step 63031: According to the preset business type, the business credential data corresponding to the preset business type is extracted from the user identity credential, the account identity credential and the device identity credential respectively.

[0104] Step 63032: Perform data fusion on the preset business credential data corresponding to the business type extracted from the user identity credential, the account identity credential, and the device identity credential to obtain a fused credential file.

[0105] Step 63033: Digitally sign the integrated credential file using the credential custodian certificate and the user's personal certificate to obtain a digital identity credential.

[0106] For example, business credential data corresponding to the preset business type can be extracted from the user identity credential, account identity credential, and device identity credential according to the preset business type, thereby fusing them into a digital identity credential. Specifically, according to the preset business type, business credential data corresponding to the preset business type is extracted respectively, such as attributes that can confirm the user identity, payment account, and the relationship between the payment device, and attributes that determine the authenticity of the user's authorization to use the current device and the account initiating the payment, etc. Then, these data can be fused to obtain a fused credential file, and the fused credential file can be digitally signed using the credential custodian certificate and the user's personal certificate to obtain a digital identity credential, forming a digital identity credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay.

[0107] In addition, in some embodiments of the present application, after step 630, the data processing method may further include step 6401, sending a first instruction to the payment application system, the first instruction carrying the digital identity credential, the first instruction being used to instruct the payment application system to store the digital identity credential, and to use the digital identity credential as a credential for proving the user's digital identity in the electronic payment business and reflecting the user's willingness to pay when the payment device initiates a payment request.

[0108] And, in some other embodiments of the present application, after step 630, the data processing method may further include step 6402, sending a second instruction to the credential custodian system, the second instruction carrying the digital identity credential, processing information for determining the identity credential set, and the public key of the digital signature of the target system, the second instruction being used to instruct the credential custodian system to store the digital identity credential, and verifying the data related to the identity credential set based on the processing information and the public key when the payment device initiates a payment request, wherein the target system includes at least one of the following: a payment acceptance system for accepting payment requests, a payment transfer system, and an account issuer system for settling transaction orders carried in payment requests.

[0109] As a result, the voucher custodian system provides voucher information storage and query services. Each system can verify the voucher as needed during or after a payment. This allows for real-time authorization verification of payment transactions during the payment process and for investigations and evidence collection after the payment occurs, such as in the event of payment disputes, risks, or regulatory audits. The voucher's validity is guaranteed by the voucher custodian system.

[0110] Based on this, in the transaction stage, after step 630, the data processing method may further include steps 6501 to 6503, as shown below.

[0111] Step 6501: Receive a payment request initiated by the payment application system. The payment request carries a transaction order and a target credential. The target credential includes a digital identity credential or a business feature credential. The business feature credential is data obtained by digitally signing the business features related to the transaction order extracted from the digital identity credential. The business feature credential is used to prove the user's digital identity in the business related to the transaction order and is a credential reflecting the user's willingness to pay.

[0112] Step 6502: Send a verification request to the credential depository system. The verification request carries the target credential. The verification request is used to request the credential depository system to verify the target credential and generate verification pass information if the target credential is verified successfully.

[0113] Therefore, after obtaining a digital identity certificate, it can be used as the basis for identifying the user's identity and payment intention. If the compliance of the digital identity certificate itself needs to be verified, it can be carried out through the verification service provided by the certificate custodian system, effectively reducing the difficulty of achieving mutual recognition among multiple business parties.

[0114] Step 6503: Upon receiving the verification information sent by the credential depository system, a resource transfer request is sent to the account issuer system corresponding to the user payment account based on the user payment account in the transaction order. The resource transfer request carries the target credential and the transaction order. The resource transfer request is used to request the account issuer system to verify the target credential through the credential depository system, and settle the transaction order if the target credential is verified.

[0115] Therefore, during the actual payment stage of the user, the digital identity certificate is delivered to each participant in the payment business according to the actual needs of the payment scenario. During the certificate delivery process, the integrity and authenticity of the digital identity certificate are guaranteed, reducing the risk of the digital identity certificate being tampered with by any party.

[0116] The present application also provides a data processing device, specifically in combination with Figure 7 Provide detailed explanation.

[0117] Figure 7 It is a structural diagram of a data processing device provided by an embodiment of the present application.

[0118] In some embodiments of the present application, Figure 7 The data processing device shown can be set in the payment switching system provided in the embodiment of the present application.

[0119] like Figure 7 As shown, the data processing device 70 may specifically include:

[0120] Receiving module 701, used to receive a credential application request initiated by the payment application system, the credential application request carrying the user's identity information;

[0121] Determination module 702, configured to determine a user's identity credential set based on the identity information, the identity credential set including a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device;

[0122] The determination module 702 is also used to determine the digital identity credential based on the user identity credential, the account identity credential and the device identity credential. The digital identity credential is a credential used to prove the user's digital identity in the electronic payment business and reflect the user's willingness to pay.

[0123] The data processing device 70 in the embodiment of the present application is described in detail below.

[0124] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include a sending module; wherein,

[0125] a sending module, configured to send a first request to the identity authentication system, the first request carrying identity information, the first request being used to request the identity authentication system to verify the identity information, and to generate a user identity credential corresponding to the identity information if the identity information is verified, the user identity credential being data obtained by the identity authentication system digitally signing the identity information;

[0126] The receiving module 701 may also be configured to receive user identity credentials sent by an identity authentication system.

[0127] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include an acquisition module, a processing module and a sending module; wherein,

[0128] The acquisition module is used to obtain the user's personal certificate based on the identity information;

[0129] A processing module, configured to digitally sign the identity information and the user identity credential using the user's personal certificate to obtain first signature data;

[0130] a sending module, configured to send a second request to the account issuer system, the second request carrying the first signature data, the second request being used to request the account issuer system to verify the first association between the identity information and the user's payment account based on the first signature data, and to generate an account identity credential if the first association is verified. The account identity credential is data obtained by digitally signing the identity information and the user's payment account by the account issuer system;

[0131] The receiving module 701 can also be used to receive the account identity certificate sent by the identity authentication system

[0132] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include an acquisition module, a processing module and a sending module; wherein,

[0133] An acquisition module, configured to acquire the user's personal certificate based on the identity information when the credential application request also carries device information of the user's payment device;

[0134] A processing module, configured to digitally sign the identity information, device information, and user identity credentials using a user personal certificate to obtain second signature data;

[0135] a sending module, configured to send a third request to the payment device system, the third request carrying the second signature data, the third request being used to request the payment device system to verify the second association between the identity information and the device information based on the second signature data, and to generate a device identity credential if the second association is verified, the device identity credential being data obtained by the payment device system performing a digital signature on the identity information and the device information;

[0136] The receiving module 701 may also be used to receive a device identity certificate sent by the payment device system.

[0137] In some embodiments of the present application, the identity information includes a user identification document number, and the user identity credential includes an identity credential identification code generated based on the user identification document number;

[0138] The account identity credential includes an identity credential identification code generated based on the user's identity document number and the user's user payment account number;

[0139] The device identity credential includes an identity credential identification code generated based on the user's identity document number and the device identification number of the user payment device used by the user.

[0140] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include a sending module and a processing module; wherein,

[0141] a sending module, configured to send a fourth request to the credential depository system, the fourth request carrying the user identity credential, the account identity credential, and the device identity credential, the fourth request being used to request the credential depository system to verify a third association among the user identity credential, the account identity credential, and the device identity credential, and to generate a credential depository certificate when the third association is verified successfully;

[0142] The receiving module 701 may also be used to receive the credential depository certificate sent by the credential depository system;

[0143] The processing module is used to digitally sign the user identity certificate, account identity certificate and device identity certificate through the certificate depository certificate and the user's personal certificate to obtain a digital identity certificate.

[0144] In some embodiments of the present application, the processing module may be specifically configured to extract, according to the preset business type, business credential data corresponding to the preset business type from the user identity credential, the account identity credential, and the device identity credential;

[0145] Performing data fusion on preset business credential data corresponding to the business type extracted from the user identity credential, the account identity credential, and the device identity credential to obtain a fused credential file;

[0146] The fusion certificate file is digitally signed using the certificate custodian certificate and the user's personal certificate to obtain a digital identity certificate.

[0147] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include a sending module; wherein,

[0148] A first instruction is sent to the payment application system, the first instruction carrying the digital identity credential, and the first instruction is used to instruct the payment application system to store the digital identity credential and use the digital identity credential as a credential for proving the user's digital identity in the electronic payment business and reflecting the user's willingness to pay when the payment device initiates a payment request.

[0149] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include a sending module; wherein,

[0150] A second instruction is sent to the credential depository system, the second instruction carrying the digital identity credential, processing information for determining the identity credential set, and the public key of the digital signature of the target system. The second instruction is used to instruct the credential depository system to store the digital identity credential and verify the data related to the identity credential set based on the processing information and the public key when the payment device initiates a payment request. The target system includes at least one of the following: a payment acceptance system that accepts payment requests, a payment transfer system, and an account issuer system for settling transaction orders carried in payment requests.

[0151] In some embodiments of the present application, the data processing device 70 in the embodiment of the present application may further include a sending module; wherein,

[0152] The receiving module 701 is further configured to receive a payment request initiated by the payment application system. The payment request carries a transaction order and a target credential. The target credential includes a digital identity credential or a business feature credential. The business feature credential is data obtained by digitally signing business features related to the transaction order extracted from the digital identity credential. The business feature credential is used to prove the user's digital identity in the business related to the transaction order and to reflect the user's willingness to pay.

[0153] A sending module is used to send a verification request to the credential depository system. The verification request carries the target credential and is used to request the credential depository system to verify the target credential. If the target credential is verified successfully, a verification pass message is generated.

[0154] The sending module is also used to, upon receiving the verification information sent by the credential custodian system, send a resource transfer request to the account issuer system corresponding to the user payment account based on the user payment account in the transaction order. The resource transfer request carries the target credential and the transaction order. The resource transfer request is used to request the account issuer system to verify the target credential through the credential custodian system, and settle the transaction order if the target credential is verified.

[0155] Therefore, the data processing device of the embodiment of the present application can determine the user's identity credential set through the user's identity information carried in the credential application request initiated by the payment application system, and the identity credential set includes user identity credentials, account identity credentials and device identity credentials, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; then, based on the user identity credential, account identity credential and device identity credential, a digital identity credential is determined, and the digital identity credential is a credential used to prove the user's digital identity in the electronic payment business and reflect the user's willingness to pay. In this way, a hybrid digital identity credential that integrates multiple attributes of the user's personal identity, user payment account and user payment device is established, and an integrated credential of personal identity, device identity and account identity is established. It can be used as a credential to prove the user's true payment intention from multiple dimensions when the electronic payment transaction occurs, and the user's transaction data is anonymized and desensitized, eliminating the possibility of leakage of user transaction data during the electronic payment transaction process from the source, avoiding the situation where user transaction data is easily leaked and tampered with, improving the security of transaction data, and reducing the transmission encryption, storage encryption and other resources invested by each processing end to protect user transaction data.

[0156] Based on the same inventive concept, the present application also provides a computer device. Figure 8 Provide detailed explanation.

[0157] Figure 8 It is a structural diagram of a computer device provided in one embodiment of the present application.

[0158] like Figure 8 As shown, the computer device may include at least one of the following involved in the embodiments of this application: an electronic device corresponding to the payment application system, a server corresponding to the payment switching system, a server corresponding to the identity authentication system, a server corresponding to the account issuer system, a server corresponding to the payment device management system, a server corresponding to the credential depository system, and an electronic device or server corresponding to the payment acceptance system. The computer device may include a processor 801 and a memory 802 storing computer program instructions.

[0159] Specifically, the processor 801 may include a central processing unit (CPU), or an application specific integrated circuit (ASTC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0160] The memory 802 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 802 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 802 may include a removable or non-removable (or fixed) medium. Where appropriate, the memory 802 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 802 is a non-volatile solid-state memory. In a specific embodiment, the memory 802 includes a solid-state memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or a flash memory, or a combination of two or more of these.

[0161] The processor 801 implements any one of the data processing methods in the above embodiments by reading and executing computer program instructions stored in the memory 802 .

[0162] In one example, the computer device may further include a communication interface 803 and a bus 810. Figure 8 As shown, the processor 801, the memory 802, and the communication interface 803 are connected via a bus 810 and communicate with each other.

[0163] The communication interface 803 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0164] Bus 810 comprises hardware, software or both, and the parts of flow control device are coupled to each other.For example, and not limitation, bus can comprise accelerated graphics port (AGP) or other graphics bus, enhanced industry standard system (ETSA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard system (TSA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel system (MCA) bus, peripheral component interconnection (PCT) bus, PCT-Express (PCT-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more above these combination.In suitable case, bus 810 can comprise one or more buses.Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.

[0165] The data processing device can execute the data processing method in the embodiment of the present application, thereby realizing the combination Figures 1 to 8 Described data processing method and device.

[0166] In addition, in conjunction with the data processing methods in the above embodiments, embodiments of the present application may provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any one of the data processing methods in the above embodiments is implemented.

[0167] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0168] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in unit, a function card or the like. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0169] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0170] The above is only a specific implementation method of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited to this. Any technician familiar with this technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the scope of protection of this application.

Claims

1. A data processing method, characterized in that: Applied to payment switching systems, including: Receive a credential application request initiated by the payment application system, wherein the credential application request carries the user's identity information; Determine, based on the identity information, a set of identity credentials for the user, the set of identity credentials including a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; The user identity credential, the account identity credential and the device identity credential are digitally signed by the credential custodian certificate and the user's personal certificate to obtain a digital identity credential. The digital identity credential is a credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay. The credential custodian certificate is provided by the credential custodian system.

2. The method according to claim 1, characterized in that Determining the user's identity credential set based on the identity information includes: Sending a first request to an identity authentication system, the first request carrying the identity information, the first request being used to request the identity authentication system to verify the identity information and, if the identity information passes verification, to generate a user identity credential corresponding to the identity information, the user identity credential being data obtained by the identity authentication system digitally signing the identity information; Receive the user identity certificate sent by the identity authentication system.

3. The method according to claim 2, characterized in that Determining the user's identity credential set based on the identity information includes: Obtaining the user's personal certificate based on the identity information; Digitally signing the identity information and the user identity credential using the user personal certificate to obtain first signature data; Sending a second request to the account issuer system, the second request carrying the first signature data, the second request being used to request the account issuer system to verify the first association between the identity information and the user's payment account based on the first signature data, and generating the account identity credential if the first association is verified. The account identity credential is data obtained by the account issuer system digitally signing the identity information and the user payment account; Receive the account identity credential sent by the identity authentication system.

4. The method according to claim 2, characterized in that The credential application request also carries device information of a user payment device used by the user; and determining the user's identity credential set based on the identity information includes: Obtaining the user's personal certificate based on the identity information; Digitally signing the identity information, the device information, and the user identity credential using the user personal certificate to obtain second signature data; Sending a third request to the payment device system, the third request carrying the second signature data, the third request being used to request the payment device system to verify the second association between the identity information and the device information based on the second signature data, and generating the device identity credential if the second association is verified, the device identity credential being data obtained by the payment device system performing a digital signature on the identity information and the device information; Receive the device identity credential sent by the payment device system.

5. The method according to any one of claims 1 to 4, characterized in that The identity information includes the user's identity document number, and the user identity credential includes an identity credential identification code generated based on the user's identity document number; The account identity credential includes an identity credential identification code generated based on the user's identity document number and the user's payment account number; The device identity credential includes an identity credential identification code generated based on the user identity document number and the device identification number of the user payment device used by the user.

6. The method according to claim 1, characterized in that The method further comprises: Sending a fourth request to the credential depository system, the fourth request carrying the user identity credential, the account identity credential, and the device identity credential, the fourth request being used to request the credential depository system to verify a third association among the user identity credential, the account identity credential, and the device identity credential, and generating a credential depository certificate when the third association is verified successfully; Receive the credential depository certificate sent by the credential depository system.

7. The method according to claim 6, characterized in that The digitally signing the user identity credential, the account identity credential, and the device identity credential using the credential depository certificate and the user's personal certificate to obtain the digital identity credential includes: According to the preset business type, extracting business credential data corresponding to the preset business type from the user identity credential, the account identity credential, and the device identity credential respectively; fusing preset service credential data corresponding to the service type extracted from the user identity credential, the account identity credential, and the device identity credential to obtain a fused credential file; The fusion certificate file is digitally signed by the certificate depository certificate and the user's personal certificate to obtain the digital identity certificate.

8. The method according to claim 1, characterized in that The method further comprises: A first instruction is sent to the payment application system, where the first instruction carries the digital identity credential. The first instruction is used to instruct the payment application system to store the digital identity credential and use the digital identity credential as a credential to prove the user's digital identity in the electronic payment business and to reflect the user's willingness to pay when the payment device initiates a payment request.

9. The method according to claim 1, characterized in that The method further comprises: A second instruction is sent to the credential depository system, wherein the second instruction carries the digital identity credential, processing information for determining the identity credential set, and the public key of the digital signature of the target system. The second instruction is used to instruct the credential depository system to store the digital identity credential and verify the data related to the identity credential set based on the processing information and the public key when the payment device initiates a payment request, wherein the target system includes at least one of the following: a payment acceptance system that accepts the payment request, the payment transfer system, and an account issuer system for settling the transaction order carried in the payment request.

10. The method according to claim 1 or 9, characterized in that The method further comprises: Receive a payment request initiated by the payment application system, the payment request carrying a transaction order and a target credential, the target credential including the digital identity credential or the business feature credential, the business feature credential being data obtained by digitally signing a business feature related to the transaction order extracted from the digital identity credential, the business feature credential being used to prove the user's digital identity in the business related to the transaction order and reflecting the user's willingness to pay; Sending a verification request to the credential depository system, the verification request carrying the target credential, the verification request being used to request the credential depository system to verify the target credential, and generating verification pass information if the target credential is verified successfully; Upon receiving the verification pass information sent by the credential depository system, a resource transfer request is sent to the account issuer system corresponding to the user payment account based on the user payment account in the transaction order. The resource transfer request carries the target credential and the transaction order. The resource transfer request is used to request the account issuer system to verify the target credential through the credential depository system, and settle the transaction order if the target credential is verified.

11. A data processing system, characterized in that: Including payment application system and payment transfer system; among them, The payment application system is used to initiate a credential application request, wherein the credential application request carries the user's identity information; The payment switching system is configured to determine a user's identity credential set based on the identity information, wherein the identity credential set includes a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; The payment switching system is also used to digitally sign the user identity certificate, the account identity certificate and the device identity certificate through the certificate custodian certificate and the user's personal certificate to obtain a digital identity certificate. The digital identity certificate is a certificate used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay. The certificate custodian certificate is provided by the certificate custodian system.

12. The system according to claim 11, wherein: The data processing system also includes an identity authentication system; wherein, The payment switching system is specifically configured to send a first request to the identity authentication system, where the first request carries the identity information; The identity authentication system is used to verify the identity information and, if the identity information passes the verification, digitally sign the identity information to obtain a user identity certificate corresponding to the identity information; and send the user identity certificate to the payment switching system.

13. The system according to claim 12, wherein: The data processing system also includes an account issuer system; wherein, The payment switching system is further configured to obtain a user personal certificate of the user based on the identity information; digitally sign the identity information and the user identity credential using the user personal certificate to obtain first signature data; and send a second request to the account issuer system, the second request carrying the first signature data; The account issuer system is used to verify the first association relationship between the identity information and the user's user payment account based on the first signature data, and if the first association relationship is verified, digitally sign the identity information and the user payment account to obtain the account identity certificate; and send the account identity certificate to the payment switching system.

14. The system according to claim 12, wherein: The credential application request also carries device information of the user's payment device, and the data processing system also includes a payment device management system; wherein, The payment switching system is further configured to obtain a user personal certificate of the user based on the identity information; digitally sign the identity information, the device information, and the user identity credential using the user personal certificate to obtain second signature data; and send a third request to the payment device system, the third request carrying the second signature data. The payment device management system is used to verify the second association relationship between the identity information and the device information based on the second signature data, and if the second association relationship is verified, perform a data signature on the identity information and the device information to obtain the device identity certificate; and send the device identity certificate to the payment device system.

15. The system according to claim 11, wherein: The data processing system also includes a voucher depository system; wherein, The payment switching system is further configured to send a fourth request to the credential depository system, wherein the fourth request carries the user identity credential, the account identity credential, and the device identity credential; The credential custodian system is configured to verify, based on the fourth request, a third association relationship among the user identity credential, the account identity credential, and the device identity credential, and generate a credential custodian certificate if the third association relationship is verified successfully; and send the credential custodian certificate to the credential custodian system.

16. The system according to claim 15, wherein the credential depository system is further configured to, based on a second instruction sent by the payment switching system, store the digital identity credential carried in the second instruction, information on a process for determining the identity credential set, and public keys of digital signatures of multiple processing systems; When the payment application system initiates a payment request, receiving a verification request sent by the target system, the payment request carries a transaction order and a target credential, the target credential including the digital identity credential; Based on the verification request, verifying the target credentials using the digital identity credentials, information about the process of determining the identity credential set, and public keys of digital signatures of multiple processing systems, wherein the target systems include at least one of the following: a payment acceptance system that accepts the payment request, the payment switching system, and an account issuer system used to settle the transaction order; When the target credential passes the verification, a verification pass message is sent to the target system.

17. A data processing device, applied to a payment switching system, comprising: A receiving module, configured to receive a credential application request initiated by a payment application system, wherein the credential application request carries the user's identity information; a determination module, configured to determine a user's identity credential set based on the identity information, the identity credential set comprising a user identity credential, an account identity credential, and a device identity credential, wherein the user identity credential is a credential used to represent the user's personal identity, the account identity credential is a credential used to represent the user's payment account, and the device identity credential is a credential used to represent the user's payment device; The determination module is further configured to digitally sign the user identity credential, the account identity credential, and the device identity credential using the credential custodian certificate and the user's personal certificate to obtain a digital identity credential. The digital identity credential is a credential used to prove the user's digital identity in electronic payment services and reflect the user's willingness to pay. The credential custodian certificate is provided by the credential custodian system.

18. A computer device, comprising: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the steps of the data processing method according to any one of claims 1 to 10 are implemented.

19. A storage medium having computer program instructions stored thereon, wherein the computer program instructions, when executed by a processor, implement the steps of the data processing method according to any one of claims 1 to 10.

20. A computer program product, characterized in that The program product is stored in a storage medium, and is executed by at least one processor to implement the steps of the data processing method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Digital payment processing method, device, equipment, system and medium

    CN115760082A

  • Code scanning method, electronic equipment, system and medium

    CN116485381A