Transaction verification method, device, equipment and system based on user terminal POS

By embedding a secure element (eSE) in the user terminal POS, using encrypted computation applications and keys for encryption, and combining the binding relationship between the merchant terminal number and the device serial number, the adaptability limitation of user terminal POS transaction verification is solved, and secure and universal transaction verification is achieved.

CN119762060BActive Publication Date: 2025-10-21CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411814123.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-10-21
Estimated Expiration
2044-12-10

AI Technical Summary

Technical Problem

In existing technologies, transaction verification methods based on user terminal POS have significant limitations due to the different TEE operating systems and chip models used by terminal equipment manufacturers, which leads to deep involvement in the adaptation process and affects the universality of transaction verification.

Method used

By embedding a secure element (eSE) in the user terminal POS, encryption is performed using ciphertext computation applications and keys, and transaction verification is achieved by combining the binding relationship between the merchant terminal number and the device serial number.

Benefits of technology

It improves the universality of transaction verification for user terminal POS, ensures the security of applications, keys and device serial numbers, meets the basic requirements of "1 terminal, 1 hardware serial number and 1 merchant", and realizes secure transaction verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119762060B_ABST
    Figure CN119762060B_ABST
Patent Text Reader

Abstract

The application discloses a transaction verification method, device, equipment and system based on a user terminal POS. The method comprises the following steps: after a payment account information is acquired by a collecting application, acquiring a chip identifier of an eSE and transaction information; calling a ciphertext calculation application, encrypting the chip identifier and the transaction information by using a chip identifier key to obtain first verification data, and encrypting a device serial number and the payment account information by using a device serial number key to obtain second verification data; determining verification data according to the first verification data, the second verification data and the device serial number; sending the transaction information and the verification data to a transaction verification system via a transaction system platform, so that the transaction verification platform verifies the first verification data based on a binding relationship and the transaction information under the condition that a binding relationship between a merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data. According to the embodiment of the application, the universality of transaction verification of the user terminal POS can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of transaction verification technology, and in particular relates to a transaction verification method, device, equipment and system based on a user terminal POS. Background Art

[0002] With the popularization of mobile payment technology and the increasing demand of consumers for convenient payment, Point of Sale (POS) terminals can be combined with user terminals such as mobile phones and tablets to use user terminals as POS machines, further improving the convenience of payment.

[0003] In order to ensure transaction security, it is often necessary to verify the transaction on the user terminal POS. Currently, the user terminal POS usually implements transaction verification based on the Trusted Execution Environment (TEE) in the user terminal.

[0004] However, as terminal equipment manufacturers are equipped with different TEE operating systems and chip models, terminal equipment manufacturers need to deeply intervene in the adaptation process of user terminal POS, resulting in limitations in the transaction verification method for user terminal POS based on the TEE mode. Summary of the Invention

[0005] The embodiments of the present application provide a transaction verification method, apparatus, device, system, computer-readable storage medium, and computer program product based on a user terminal POS, which can improve the universality of transaction verification for the user terminal POS.

[0006] In a first aspect, an embodiment of the present application provides a transaction verification method based on a user terminal POS, which is applied to a user terminal having an embedded secure element (eSE) and an acquiring application. The secure area of ​​the eSE includes a ciphertext calculation application, a chip identification key, a device serial number key, and the device serial number of the user terminal.

[0007] The method comprises:

[0008] When the acquiring application obtains the payment account information used to pay the transaction order, obtaining the chip identifier of the eSE and the transaction information of the transaction order, wherein the acquiring application has a merchant terminal number entered therein, and the transaction information includes the merchant terminal number;

[0009] calling the ciphertext calculation application and encrypting the chip identification and the transaction information using the chip identification key to obtain first verification data; the chip identification key and the ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information;

[0010] calling the ciphertext calculation application to encrypt the device serial number and the payment account information using the device serial number key to obtain second verification data, wherein the device serial number and the device serial number key are assigned to the user terminal by the transaction verification platform upon determining a one-to-one correspondence between the merchant terminal number and the chip identifier before the acquiring application obtains the payment account information;

[0011] determining verification data based on the first verification data, the second verification data, and the device serial number;

[0012] The transaction information and the verification data are sent to the transaction verification system via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and the transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

[0013] In a second aspect, an embodiment of the present application provides a transaction verification method based on a user terminal POS, which is applied to a transaction verification platform. The method includes:

[0014] Receive a transaction verification request sent by the transaction system platform, the transaction verification request including transaction information and verification data. The transaction information and verification data are obtained and sent to the transaction system platform by the user terminal when the user terminal obtains the payment account information used to pay the transaction order. The transaction information includes the merchant terminal number, and the verification data includes first verification data, second verification data, and the device serial number of the user terminal; the first verification data is obtained by encrypting the chip identifier of the eSE in the user terminal and the transaction information using the chip identifier key; the second verification data is obtained by encrypting the device serial number and the payment account information using the device serial number key;

[0015] In response to the transaction verification request, if a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform, determining a target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship;

[0016] Obtaining a target chip identification key corresponding to the target chip identification stored in the transaction verification platform;

[0017] Encrypting the target chip identification and the transaction information using the target chip identification key to obtain target first verification data;

[0018] In a case where the target first verification data is identical to the first verification data, verification pass information corresponding to the first verification data is sent to the trading system platform, so that the trading system platform verifies the second verification data.

[0019] In a third aspect, an embodiment of the present application provides a transaction verification device based on a user terminal POS, which is applied to a user terminal having an embedded secure element (eSE) and an acquiring application. The secure area of ​​the eSE includes a ciphertext calculation application, a chip identification key, a device serial number key, and the device serial number of the user terminal.

[0020] The device comprises:

[0021] a first acquisition module, configured to acquire, when the acquiring application acquires payment account information used to pay for a transaction order, the chip identifier of the eSE and transaction information of the transaction order, wherein the acquiring application has a merchant terminal number entered therein, and the transaction information includes the merchant terminal number;

[0022] a first encryption module, configured to call the ciphertext calculation application and encrypt the chip identification and the transaction information using the chip identification key to obtain first verification data; the chip identification key and the ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information;

[0023] The first encryption module is further configured to call the ciphertext calculation application to encrypt the device serial number and the payment account information using the device serial number key to obtain second verification data, wherein the device serial number and the device serial number key are assigned to the user terminal by the transaction verification platform upon determining a one-to-one correspondence between the merchant terminal number and the chip identifier before the acquiring application obtains the payment account information;

[0024] a first determining module, configured to determine verification data based on the first verification data, the second verification data, and the device serial number;

[0025] The first sending module is used to send the transaction information and the verification data to the transaction verification system via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and the transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

[0026] In a fourth aspect, an embodiment of the present application provides a transaction verification device based on a user terminal POS, which is applied to a transaction verification platform, and the device includes:

[0027] a second receiving module, configured to receive a transaction verification request sent by a transaction system platform, the transaction verification request including transaction information and verification data, the transaction information and verification data being obtained and sent to the transaction system platform by a user terminal upon obtaining payment account information used to pay for a transaction order, the transaction information including a merchant terminal number, the verification data including first verification data, second verification data, and a device serial number of the user terminal; the first verification data being obtained by encrypting the chip identifier of the eSE in the user terminal and the transaction information using a chip identifier key; the second verification data being obtained by encrypting the device serial number and the payment account information using a device serial number key;

[0028] a second determining module, configured to, in response to the transaction verification request, determine, based on a binding relationship between the merchant terminal number and the device serial number stored in the transaction verification platform, a target chip identifier corresponding to the merchant terminal number and the device serial number, stored in the transaction verification platform;

[0029] A second acquisition module is used to acquire a target chip identification key corresponding to the target chip identification stored in the transaction verification platform;

[0030] a second encryption module, configured to encrypt the target chip identification and the transaction information using the target chip identification key to obtain target first verification data;

[0031] The second sending module is used to send verification pass information corresponding to the first verification data to the trading system platform when the target first verification data is the same as the first verification data, so that the trading system platform verifies the second verification data.

[0032] In a fifth aspect, an embodiment of the present application provides an electronic device, the device comprising: a processor and a memory storing computer program instructions;

[0033] When the processor executes the computer program instructions, the method in any possible implementation method of the first aspect or the second aspect is implemented.

[0034] In a sixth aspect, an embodiment of the present application provides a transaction verification system based on a user terminal POS, comprising:

[0035] A user terminal, configured to execute any one of the possible implementation methods of the first aspect above;

[0036] The transaction verification platform is communicatively connected to the user terminal and is used to execute the method in any possible implementation method of the second aspect above.

[0037] In the seventh aspect, an embodiment of the present application provides a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are executed by a processor, they implement any possible implementation method in the first or second aspect above.

[0038] In an eighth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes a method in any possible implementation method of the first aspect or the second aspect mentioned above.

[0039] This embodiment of the present application assigns a device serial number to the user terminal by ensuring, before the acquiring application obtains payment account information, that the merchant terminal number entered into the acquiring application corresponds to the chip identifier of the user terminal's eSE. This achieves a one-to-one correspondence between the user terminal, device serial number, and merchant terminal number, meeting the basic transaction verification requirement of "one terminal, one hardware serial number, one authorized merchant." The user terminal obtains the ciphertext calculation application, chip identifier key, device serial number, and device serial number key from the transaction verification platform and stores them in the user terminal's eSE chip, ensuring the security of the application, key, and device serial number, providing security for transaction verification. By calling a ciphertext calculation application when the acquiring application obtains the payment account information used to pay for the transaction order, using the chip identification key to encrypt the chip identification and transaction information to obtain the first verification data; using the device serial number key to encrypt the device serial number and payment account information to obtain the second verification data; determining the verification data based on the first verification data, the second verification data and the device serial number; and sending the transaction information and verification data to the transaction verification platform via the transaction system platform, so that the transaction verification platform can verify the first verification data, and the transaction system platform can verify the second verification data, thereby realizing transaction verification of the user terminal POS. In this way, since the user terminal with POS function usually has an eSE chip, the embodiment of the present application can improve the universality of transaction verification of the user terminal POS. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0041] Figure 1This is a schematic diagram of the structure of a transaction verification system based on a user terminal POS provided in an embodiment of the present application;

[0042] Figure 2 This is a flowchart of a transaction verification method based on a user terminal POS, which is applied to a user terminal and provided in an embodiment of the present application;

[0043] Figure 3 This is a flow chart of updating an initial master key using a master key provided in an embodiment of the present application;

[0044] Figure 4 This is a flowchart of a request to establish a one-to-one correspondence between a chip identifier, a merchant terminal number, and a device serial number, provided by an embodiment of the present application;

[0045] Figure 5 This is a flowchart of a transaction verification method based on a user terminal POS and applied to a transaction verification platform provided in an embodiment of the present application;

[0046] Figure 6 This is a schematic diagram of a device initialization process provided by an embodiment of the present application;

[0047] Figure 7 This is a flow chart of a transaction verification process provided by an embodiment of the present application;

[0048] Figure 8 This is a schematic diagram of the structure of a transaction verification device based on a user terminal POS and applied to a user terminal, provided in an embodiment of the present application;

[0049] Figure 9 This is a schematic diagram of the structure of a transaction verification device based on a user terminal POS and applied to a transaction verification platform provided in an embodiment of the present application;

[0050] Figure 10 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0052] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0053] In addition, the acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0054] Currently, user terminal POS typically implements transaction verification based on the Trusted Execution Environment (TEE) within the user terminal. However, as terminal device manufacturers adopt different TEE operating systems and chip models, terminal device manufacturers need to be deeply involved in the user terminal POS adaptation process, resulting in limitations in the TEE-based POS transaction verification method.

[0055] In order to solve the problems of the prior art, the invention of this application is as follows:

[0056] In combination with the usage scenario of the user terminal POS, when the user terminal serves as a payment device to accept transactions with payment cards or the user terminal's own electronic wallet, it is often necessary to use the user terminal's Near Field Communication (NFC) capability to read the payment account information corresponding to the payment card or the user terminal's own electronic wallet. If the user terminal has NFC capability, it often has an embedded secure element (eSE). Based on the premise that the manufacturer of the user terminal can openly read the eSE's Card Production Lifecycle (CPLC) information and the ability to use the secure area of ​​the eSE chip, the embodiment of the present application provides a method for performing transaction verification on the user terminal POS based on eSE, which can improve the universality of transaction verification on the user terminal POS.

[0057] Thus, to solve the problems of the prior art, the embodiments of the present application provide a transaction verification method, apparatus, device, system, computer-readable storage medium, and computer program product based on a user terminal POS. The transaction verification method based on a user terminal POS can be applied to scenarios where a user terminal POS is used as a payment device to perform transaction verification when accepting transactions.

[0058] The following is an introduction to the transaction verification system based on the user terminal POS provided in the embodiment of the present application.

[0059] Figure 1 FIG1 shows a schematic diagram of a transaction verification system based on a user terminal POS provided in an embodiment of the present application. Figure 1 As shown, the transaction verification system based on the user terminal POS provided in the embodiment of the present application includes a user terminal 11 with POS function, a transaction system platform 12 and a transaction verification platform 13. Among them, the user terminal 11, the transaction system platform 12 and the transaction verification platform 13 can be communicatively connected. In addition, the user terminal 11 can have an eSE 111 and an acquiring application 112. A ciphertext calculation application 1111 can be installed in the security area of ​​the eSE 111. In addition, the master key, chip identification key, device serial number key and the device serial number of the user terminal 11 can be stored in the security area of ​​the eSE. Among them, the ciphertext calculation application 1111 can be used to perform ciphertext calculation based on a key (such as a chip identification key and a device serial number key). The master key can be used to encrypt working keys such as the chip identification key and the device serial number key. The chip identification key can be used to encrypt the chip identification of the eSE. The device serial number key can be used to encrypt the device serial number.

[0060] The transaction verification system based on the user terminal POS can be used to initialize the user terminal 11 and perform transaction verification when collecting payment using the user terminal POS.

[0061] As an example, during the device initialization process, the user terminal 11 may request the master key, chip identification key, and ciphertext calculation application 1111 from the transaction verification platform 13 and store them in the secure area of ​​the eSE 111. In addition, the merchant terminal number may be entered into the acquiring application 112. The user terminal 11 may also send a device binding request including the merchant terminal number and the chip identification of the eSE 111 to the transaction verification platform 13 to request the transaction verification platform 13 to establish a binding relationship between the merchant terminal number and the chip identification. After determining the one-to-one correspondence between the merchant terminal number and the chip identification, the transaction verification platform 13 may establish a binding relationship between the merchant terminal number and the chip identification and assign a device serial number to the binding relationship to obtain a one-to-one correspondence between the merchant terminal number, the chip identification, and the device serial number. The transaction verification platform 13 may also generate a device serial number key and return the device serial number to the user terminal 11. The user terminal 11 device may store the device serial number and the device serial number key in the secure area of ​​the eSE 111.

[0062] In addition, during the transaction process, if the acquiring application 112 obtains the payment account information used to pay the transaction order, the user terminal 11 can call the ciphertext calculation application 1111 to encrypt the transaction information of the transaction order and the chip identification of the eSE 111 using the chip identification key to obtain first verification data; encrypt the payment account information and the device serial number using the device serial number key to obtain second verification data; determine the verification data based on the first verification data, the second verification data, and the device serial number; and send the transaction information and verification data to the transaction system platform 12. The transaction system platform 12 can verify the second verification data and call the transaction verification platform 13 to verify the binding relationship between the merchant terminal number and the device serial number and the first verification data, and complete the transaction if the binding relationship, the first verification data, and the second verification data are all verified.

[0063] Since user terminals with POS functions usually have an eSE chip, the transaction verification system based on the user terminal POS in the embodiment of the present application can improve the universality of transaction verification for the user terminal POS.

[0064] The following is an introduction to the transaction verification method based on the user terminal POS and applied to the user terminal provided in the embodiment of the present application.

[0065] Figure 2 The flowchart of a transaction verification method based on a user terminal POS provided in an embodiment of the present application is shown. The transaction verification method based on a user terminal POS can be executed by a processor in the user terminal. Figure 2As shown, the transaction verification method based on the user terminal POS provided in the embodiment of the present application includes the following steps:

[0066] S210. When the acquiring application obtains the payment account information used to pay the transaction order, obtain the eSE chip identifier and transaction information of the transaction order. The acquiring application has the merchant terminal number entered, and the transaction information includes the merchant terminal number.

[0067] S220: Invoke a ciphertext calculation application to encrypt the chip identifier and transaction information using the chip identifier key to obtain first verification data; the chip identifier key and ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information;

[0068] S230. Invoke a ciphertext calculation application to encrypt the device serial number and payment account information using the device serial number key to obtain second verification data. The device serial number and device serial number key are assigned to the user terminal by the transaction verification platform after confirming a one-to-one correspondence between the merchant terminal number and the chip identifier, before the acquiring application obtains the payment account information.

[0069] S240, determining verification data according to the first verification data, the second verification data, and the device serial number;

[0070] S250. Send transaction information and verification data to the transaction verification system via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

[0071] This embodiment of the present application assigns a device serial number to the user terminal by ensuring, before the acquiring application obtains payment account information, that the merchant terminal number entered into the acquiring application corresponds to the chip identifier of the user terminal's eSE. This achieves a one-to-one correspondence between the user terminal, device serial number, and merchant terminal number, meeting the basic transaction verification requirement of "one terminal, one hardware serial number, one authorized merchant." The user terminal obtains the ciphertext calculation application, chip identifier key, device serial number, and device serial number key from the transaction verification platform and stores them in the user terminal's eSE chip, ensuring the security of the application, key, and device serial number, providing security for transaction verification. By calling a ciphertext calculation application when the acquiring application obtains the payment account information used to pay for the transaction order, using the chip identification key to encrypt the chip identification and transaction information to obtain the first verification data; using the device serial number key to encrypt the device serial number and payment account information to obtain the second verification data; determining the verification data based on the first verification data, the second verification data and the device serial number; and sending the transaction information and verification data to the transaction verification platform via the transaction system platform, so that the transaction verification platform can verify the first verification data, and the transaction system platform can verify the second verification data, thereby realizing transaction verification of the user terminal POS. In this way, since the user terminal with POS function usually has an eSE chip, the embodiment of the present application can improve the universality of transaction verification of the user terminal POS.

[0072] The specific implementation methods of the above steps are introduced below.

[0073] In some embodiments, in S210, a user terminal with POS functionality may be installed with an acquiring application. The acquiring application may correspond to a unique application identifier (AID), which may be mutually agreed upon by the user terminal manufacturer and the transaction verification platform. Furthermore, the acquiring application may include a merchant terminal number.

[0074] When a user pays for a transaction using resources in their payment account, the acquiring application can obtain the payment account information used to pay for the transaction. This payment account information can include the account information for the payment account associated with the e-wallet and the account information for the payment card. If the user pays using a payment card, the payment account information may include the card number. Payment cards can include bank cards, membership cards, and transportation cards. Additionally, the eSE chip identifier can be the eSE's CPLC information. Transaction information may include the merchant terminal number, order number, transaction time, and transaction amount.

[0075] As an example, when a user pays with a bank card, the acquiring application can read the CPLC information and collect transaction information such as the merchant terminal number, order number, transaction time, and transaction amount after completing the card reading operation.

[0076] In some embodiments, in S220, after obtaining the chip identifier and transaction information, the acquiring application may transmit the chip identifier and transaction information to a cryptographic calculation interface of a cryptographic calculation application running on the eSE, perform cryptographic calculations through the cryptographic calculation application, and return the cryptographic information to the acquiring application. The cryptographic calculation application may be an applet.

[0077] As an example, the acquiring application can call the ciphertext calculation application to encrypt the chip identification and transaction information using the chip identification key to obtain the first verification data. In other words, the first verification data can include the ciphertext information of the chip identification and transaction information.

[0078] In some embodiments, the above S220 may specifically include:

[0079] Call the ciphertext calculation application to perform digest calculation on the chip identifier and transaction information to obtain the digest information;

[0080] The digest information is encrypted using the chip identification key to obtain first verification data.

[0081] Here, calculating a digest of the chip identifier and transaction information may specifically include: first concatenating the chip identifier and transaction information in a fixed format to obtain a first string; then using a hash algorithm to calculate a digest of the first string to obtain digest information; and then symmetrically encrypting the digest information using the chip identifier key to obtain the first verification data.

[0082] In some embodiments, in S230, after obtaining the payment account information, the acquiring application may also pass the payment account information to the ciphertext calculation interface of the ciphertext calculation application running on the eSE, perform ciphertext calculation through the ciphertext calculation application, and return the ciphertext information to the acquiring application.

[0083] As an example, the acquiring application can call a ciphertext calculation application to encrypt the device serial number and payment account information using the device serial number key to obtain the second verification data. That is, the second verification data can include the ciphertext information of the device serial number and payment account information. The device serial number can be read by the ciphertext calculation application from the secure area.

[0084] When a user pays with a bank card, the device serial number key can be used to encrypt the device serial number and the bank card number to obtain the second verification data. The encrypted bank card number can be the full card number or a partial card number (e.g., the last six digits), without limitation.

[0085] In some embodiments, the above S230 may specifically include:

[0086] Call the ciphertext calculation application to concatenate the device serial number and payment account information to obtain the target serial number;

[0087] The target serial number is encrypted using the device serial number key to obtain second verification data.

[0088] Here, after receiving the payment account information sent by the acquiring application, the ciphertext calculation application can read the device serial number from the secure area, concatenate the device serial number and the payment account information to obtain the target serial number, and use the existing rules to encrypt the target serial number using the device serial number key to obtain the second verification data.

[0089] In some embodiments, in S240, the acquiring application may determine the verification data based on the first verification data, the second verification data, and the device serial number. That is, the verification data may include the first verification data, the second verification data, and the device serial number.

[0090] In some embodiments, in S250, after determining the verification data, the acquiring application may send the transaction information and verification data collected during the transaction to the acquiring system platform. The acquiring system platform includes a backend server of the acquiring application. The acquiring system platform may forward the transaction information and verification data to the transaction system platform. The transaction system platform may call the transaction verification platform to verify the binding relationship between the merchant terminal number and the device serial number and the first verification data. If both the binding relationship and the first verification data are verified successfully, the transaction system platform may verify the second verification data and complete the transaction if the second verification data is verified successfully.

[0091] As an example, the transaction verification platform may store the binding relationship between the merchant terminal number, the device serial number, and the chip identifier. After receiving the transaction information and verification data, the transaction system platform may request the transaction verification platform to verify the binding relationship between the merchant terminal number and the device serial number and the first verification data. Specifically, if the transaction verification platform stores the binding relationship between the merchant terminal number and the device serial number, it can be determined that the binding relationship verification is successful, and based on the binding relationship, the chip identifier corresponding to the merchant terminal number and the device serial number is determined, the chip identifier key corresponding to the chip identifier is queried, and the transaction information and the chip identifier are encrypted based on the chip identifier key to obtain the target first verification data. If the target first verification data and the first verification data are the same, it can be determined that the first verification data verification is successful, and the verification pass information corresponding to the first verification data is sent to the transaction system platform.

[0092] It should be noted that in the embodiment of the present application, what the user terminal sends to the transaction verification platform through the acquiring system platform and the transaction system platform is the device serial number, not the chip ID. This can protect the chip ID from being used only within the user terminal and the transaction verification platform, and not being output to the acquiring system platform and the transaction system platform, thereby ensuring the security of the chip ID.

[0093] In addition, the transaction information may also include payment account information, and the transaction system platform may store a device serial number key. This device serial number key is the same as the device serial number key stored in the user terminal. After receiving the verification pass information, the transaction system platform can use the device serial number key stored in the transaction system platform to encrypt the device serial number and payment account information to obtain the target second verification data. If the target second verification data and the second verification data are identical, the second verification data can be determined to have been verified, and the transaction is completed.

[0094] It should be noted that if any one of the binding relationship, the first verification data, or the second verification data fails to be verified, the transaction is deemed to be at risk of being tampered with and the transaction is stopped.

[0095] On this basis, to implement transaction verification for the user terminal POS, in some embodiments, a device initialization phase may be included before S210 described above. This device initialization phase may include the user terminal requesting the transaction verification platform to obtain the chip identification key, ciphertext calculation application, device serial number, and device serial number key, and storing them in a secure area. Furthermore, this initialization phase may also include the user terminal requesting the transaction verification platform to establish a binding relationship between the merchant terminal number, device serial number, and chip identification.

[0096] It should be noted that working keys such as the chip identification key and device serial number may be at risk of being tampered with during transmission between the user terminal and the transaction verification platform. Therefore, to ensure the security of the working key, and thereby the accuracy of the first and second verification data subsequently encrypted using the working key, and thus the accuracy of transaction verification, in some embodiments, before the user terminal requests information such as the chip identification key, ciphertext calculation application, device serial number, and device serial number key from the transaction verification platform, it may also first request a master key from the transaction verification platform. This master key is then used to encrypt the working key in subsequent processes, ensuring the security of the working key. The master key may also be stored in the secure area of ​​the eSE.

[0097] Based on this, in order to ensure the security of the working key, in some embodiments, before the above S210, the method may further include:

[0098] Obtain the chip identifier of the eSE in the user terminal (such as CPLC information) and the application identifier of the acquiring application;

[0099] Generate a master key acquisition request based on the chip ID and application ID;

[0100] Send a master key acquisition request to the transaction verification platform.

[0101] After receiving a master key acquisition request, the transaction verification platform can respond to the master key acquisition request by generating a master key based on the chip identifier and application identifier, and return the master key to the user terminal. A specific method for generating the master key based on the chip identifier and application identifier can be to use the chip identifier and application identifier as key diversification factors, and then utilize a root key to diversify the key diversification factors based on a key diversification algorithm to obtain the master key. The root key can be a symmetric key agreed upon offline between the user terminal manufacturer and the transaction verification platform, and the key diversification algorithm can be an algorithm agreed upon offline between the user terminal manufacturer and the transaction verification platform for generating the master key.

[0102] After receiving the master key, the user terminal may store the master key in a secure area.

[0103] In the above example, the user terminal that sends the master key acquisition request and the user terminal that agrees on the root key with the transaction verification platform may be different. Therefore, in order to enable the transaction verification platform to verify the identity of the user terminal and issue the master key if the user terminal passes the identity authentication, thereby ensuring the success of subsequent transaction verification, in some embodiments, when the initial master key is stored in the secure area, such as Figure 3 As shown, before the above S210, the method may further include:

[0104] S310: Obtain the chip identifier of the eSE and the application identifier of the acquiring application;

[0105] S320: Generate a key update request based on the chip identifier, application identifier, and initial master key;

[0106] S330: Send a key update request to the transaction verification platform, so that the transaction verification platform verifies the initial master key and generates a master key based on the chip identifier and the application identifier if the initial master key verification passes.

[0107] S340: Receive the master key fed back by the transaction verification platform in response to the key update request;

[0108] S350: Use the master key to update the initial master key stored in the security area.

[0109] Here, the key update request can be used to request the transaction verification platform to generate a master key. Furthermore, the initial master key can include the user terminal's identity information. That is, the transaction verification platform can identify the user terminal based on the initial master key. Once the transaction verification platform verifies the initial master key and confirms the user terminal's identity, it can generate a master key based on the chip ID and application ID and return the master key to the user terminal.

[0110] This application sends an initial master key including the identity information of the user terminal to the transaction verification platform, so that the transaction verification platform can identify the identity of the user terminal based on the initial master key, and issue the master key if the user terminal's identity authentication is passed, thereby ensuring the success of subsequent transaction verification.

[0111] In addition, as described above, the user terminal manufacturer and the transaction verification platform may agree offline on a symmetric key as a root key and a key dispersion algorithm for generating a master key. Therefore, to enable the transaction verification platform to verify the identity of the user terminal using the initial master key, in some embodiments, before step S320, the method may further include:

[0112] Determine the key dispersion factor based on the chip identifier and the application identifier;

[0113] Using the root key, the key dispersion factor is dispersed based on the key dispersion algorithm to obtain the initial master key;

[0114] Store the initial master key in a secure area.

[0115] Here, the user terminal can generate the initial master key in the same manner as the transaction verification platform generates the master key. Since the root key and key diversification algorithm are agreed upon between the user terminal manufacturer and the transaction verification platform, if the key diversification factors are the same, the initial master key generated by the user terminal and the master key generated by the transaction verification platform can be the same.

[0116] On this basis, if the master key generated by the transaction verification platform based on the chip identifier and application identifier is the same as the initial master key sent by the user terminal, it can be determined that the initial master key verification has passed, and then it can be determined that the identity authentication of the user terminal has passed, so that the transaction verification platform can verify the identity of the user terminal through the initial master key.

[0117] In addition, the embodiment of the present application sends the initial master key to the transaction verification platform through the user terminal, and receives the master key sent by the transaction verification platform, so as to realize the online agreement of the master key.

[0118] In addition, there is a risk that the initial master key and the master key may be tampered with during transmission between the user terminal and the transaction verification platform. Therefore, to ensure the security of the initial master key, in some embodiments, the key update request generated based on the chip identifier, application identifier, and initial master key may specifically include:

[0119] The initial master key is encrypted using the root key to obtain the ciphertext information of the initial master key;

[0120] Generate a key update request based on the chip identification, application identification and encrypted information of the initial master key.

[0121] The embodiment of the present application generates a key update request based on the ciphertext information of the chip identification, application identification and initial master key. That is, during the information transmission process between the user terminal and the transaction verification platform, the security of the initial master key is guaranteed by transmitting the ciphertext information of the initial master key instead of the initial master key.

[0122] On this basis, in response to the key update request, the transaction verification platform can first use the root key to decrypt the ciphertext of the initial master key to obtain the initial master key, then verify the initial master key, and generate the master key if the initial master key verification passes.

[0123] To ensure the security of the master key, after generating the master key, the transaction verification platform can also use the initial master key to encrypt the master key, obtain the ciphertext information of the master key, and return the ciphertext information of the master key to the user terminal. Specifically, the transaction verification platform can generate a master key update instruction based on the ciphertext information of the master key, and return the master key update instruction to the user terminal, instructing the user terminal to update the initial master key in the secure area to the master key. The master key update instruction can be an Application Protocol Data Unit (APDU) instruction. APDU defines the format and rules for data transmitted during the interaction.

[0124] Based on this, in order to ensure the security of the master key, in some embodiments, the master key received from the transaction verification platform in response to the key update request may specifically include:

[0125] The transaction verification platform receives ciphertext information of the master key fed back in response to the key update request, where the ciphertext information of the master key is obtained by encrypting the master key using the initial master key on the transaction verification platform.

[0126] Based on this, the above-mentioned master key is used to update the initial master key stored in the secure area to include:

[0127] Use the initial master key to decrypt the ciphertext of the master key to obtain the master key;

[0128] The master key is used to update the initial master key stored in the secure area.

[0129] If the ciphertext information of the master key is assembled into a master key update instruction, after receiving the master key update instruction, the user terminal can respond to the master key update instruction, call the system interface to decrypt the ciphertext information of the master key, obtain the master key, and complete the master key update operation in the security area of ​​​​the eSE.

[0130] The embodiment of the present application can ensure the security of the master key by transmitting the ciphertext information of the master key instead of the master key during the information transmission process between the user terminal and the transaction verification platform.

[0131] Based on this, in order to implement verification of the first verification data through the transaction verification platform, in some embodiments, after obtaining the chip identifier of the eSE and the application identifier of the acquiring application, the method may further include:

[0132] Sending a chip identification key acquisition request to the transaction verification platform, so that the transaction verification platform generates a chip identification key, and encrypts the chip identification key with the master key to obtain ciphertext information of the chip identification key;

[0133] Receiving the ciphertext information of the chip identification key fed back by the transaction verification platform in response to the chip identification key acquisition request;

[0134] Decrypt the ciphertext of the chip identification key using the master key to obtain the chip identification key;

[0135] Store the chip identification key in a secure area.

[0136] Here, before the user terminal is officially activated, after the acquiring application obtains the chip identifier, it can send a chip identifier key acquisition request to the transaction verification platform. After receiving the chip identifier key acquisition request, the transaction verification platform can generate a chip identifier key for encrypting the chip identifier and encrypt the chip identifier key using the master key to obtain the ciphertext information of the chip identifier key. The transaction verification platform can also generate a key receive instruction for receiving the chip identifier key based on the ciphertext information of the chip identifier key and send the key receive instruction to the user terminal. The key receive instruction can specifically be an APDU instruction.

[0137] After receiving the key receiving instruction, the user terminal may first use the master key to decrypt the ciphertext information of the chip identification key to obtain the chip identification key, and then store the chip identification key in the secure area.

[0138] In the embodiment of the present application, the user terminal requests the chip identification key from the transaction verification platform, so that the user terminal can subsequently use the chip identification key to encrypt the chip identification and transaction information to obtain the first verification data, and the transaction verification platform can verify the first verification data based on the chip identification key, chip identification and transaction information.

[0139] In addition, in order to enable the user terminal to generate the first verification data and the second verification data, in some embodiments, after obtaining the chip identifier of the eSE and the application identifier of the acquiring application, the method may further include:

[0140] Send an application acquisition request to the transaction verification platform. The application acquisition request is used to request the ciphertext calculation application.

[0141] Receiving an installation package of the ciphertext calculation application fed back by the transaction verification platform in response to the application acquisition request;

[0142] Install the encrypted computing application in the secure zone based on the installation package.

[0143] Here, before the user terminal is officially activated, after the acquiring application obtains the chip identifier, it can send an application acquisition request to the transaction verification platform. After receiving the application acquisition request, the transaction verification platform can obtain the installation package of the ciphertext calculation application, assemble the installation package and installation steps into application installation instructions, and send the application installation instructions to the user terminal. The application installation instructions can specifically be APDU instructions.

[0144] After receiving the application installation instruction, the user terminal can complete the installation of the ciphertext computing application in the secure area of ​​the eSE based on the installation package.

[0145] In the embodiment of the present application, by installing a ciphertext calculation application in a secure area, the ciphertext calculation application can be called to calculate the first verification data and the second verification data.

[0146] Furthermore, to conserve communication resources, in some embodiments, before the user terminal is officially activated, after the acquiring application obtains the chip identifier, it may send a target acquisition request to the transaction verification platform. This target acquisition request may include a chip identifier key acquisition request and an application acquisition request. Upon receiving the target acquisition request, the transaction verification platform may generate a key acquisition instruction and an application installation instruction in response to the target acquisition request, and then batch-distribute these instructions to the user terminal.

[0147] In addition, in order to meet the basic requirement of "1 terminal 1 hardware serial number 1 authorized merchant" for transaction verification and further improve the accuracy of transaction verification, in some embodiments, such as Figure 4 As shown, before the above S210, the following steps may also be included:

[0148] S410: Obtain the merchant terminal number and eSE chip identifier entered in the acquiring application;

[0149] S420: Generate a device binding request based on the merchant terminal number and the chip identifier, where the device binding request is used to request establishment of a binding relationship between the merchant terminal number and the chip identifier;

[0150] S430. Sending a device binding request to the transaction verification platform, so that the transaction verification platform establishes a binding relationship between the merchant terminal number and the chip identifier when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number, assigns a device serial number and a device serial number key corresponding to the device serial number to the binding relationship, and encrypts the device serial number key using the master key to obtain ciphertext information of the device serial number key.

[0151] S440: Receive the encrypted information of the device serial number and the device serial number key fed back by the transaction verification platform in response to the device binding request;

[0152] S450, using the master key in the secure area to decrypt the encrypted information of the device serial number to obtain the device serial number key;

[0153] S460: Store the device serial number and the device serial number key in a secure area.

[0154] Here, before the user terminal is officially activated, after the acquiring application obtains the chip identifier, it can also read the merchant terminal number entered in the acquiring application, generate a device binding request based on the merchant terminal number and chip identifier, and send the device binding request to the transaction verification platform.

[0155] After receiving the device binding request, the transaction verification platform can, on the one hand, query the transaction verification platform's database to see whether there is a merchant terminal number bound to the chip identifier; on the other hand, it can query the transaction verification platform's database to see whether there is a chip identifier bound to the merchant terminal number. If there is no binding record for both the chip identifier and the merchant terminal number in the device binding request, a binding relationship between the chip identifier and the merchant terminal number can be established to ensure a one-to-one correspondence between the chip identifier and the merchant terminal number. Afterwards, the transaction verification platform can also assign a device serial number and its corresponding device serial number key to the above binding relationship to obtain a one-to-one correspondence between the chip identifier, the merchant terminal number, and the device serial number. Among them, the device serial number key can be used to encrypt the device serial number. In addition, in order to ensure the security of the device serial number key, after generating the device serial number key, the transaction verification platform can also use the master key to encrypt the device serial number key to obtain the ciphertext information of the device serial number key.

[0156] The transaction verification platform may assemble the encrypted information of the device serial number and the device serial number key into a device information receiving instruction and send the device information receiving instruction to the user terminal. Specifically, the device information receiving instruction may be an APDU instruction. Furthermore, the transaction verification platform may also send the encrypted information of the device serial number key to the transaction system platform, so that the transaction system platform can verify the second verification data based on the device serial number key.

[0157] After receiving the device information receiving instruction, the user terminal may store the device serial number and the device serial number key in the secure area in response to the device information receiving instruction.

[0158] The embodiment of the present application establishes a binding relationship between the merchant terminal number and the chip identifier through the transaction verification platform when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number, and allocates a device serial number and a device serial number for the binding relationship, thereby ensuring a one-to-one correspondence between the chip identifier, the merchant terminal number and the device serial number, and meeting the basic requirement for transaction verification of "1 terminal 1 hardware serial number 1 authorized merchant".

[0159] In addition, the device serial number and device serial number key are sent to the user terminal through the transaction verification platform, so that the user terminal can use the device serial number key to encrypt the device serial number and payment account information to obtain the second verification data. Compared with generating the second verification data on the transaction verification platform, it can ensure the verification effect of the user terminal.

[0160] In addition, eSE has an initial security area. During the initialization of the user terminal, the user terminal manufacturer's interface can be called first to create a security area corresponding to the transaction verification business in the above-mentioned initial security area, and the ciphertext calculation application is installed in the security area corresponding to the transaction verification business, and the master key, chip identification key, device serial number and device serial number key are stored in the security area corresponding to the transaction verification business.

[0161] In addition, the communication process between the user terminal and the transaction verification platform in the embodiment of the present application can be specifically implemented through the communication between the acquiring application and the transaction verification platform.

[0162] The following is an introduction to the transaction verification method based on the user terminal POS and applied to the transaction verification platform provided in the embodiment of the present application.

[0163] Figure 5 The flowchart of a transaction verification method based on a user terminal POS provided in an embodiment of the present application is shown. The transaction verification method based on a user terminal POS can be executed by a processor and / or server in the transaction verification platform. Figure 5 As shown, the transaction verification method based on the user terminal POS provided in the embodiment of the present application includes steps S510-S550.

[0164] S510, receiving a transaction verification request sent by the transaction system platform, the transaction verification request including transaction information and verification data, the transaction information and verification data being obtained and sent to the transaction system platform by the user terminal when the user terminal obtains the payment account information used to pay the transaction order, the transaction information including the merchant terminal number, the verification data including the first verification data, the second verification data and the device serial number of the user terminal; the first verification data is obtained by encrypting the chip identification of the eSE in the user terminal and the transaction information using the chip identification key; the second verification data is obtained by encrypting the device serial number and the payment account information using the device serial number key.

[0165] Here, after determining the verification data, the acquiring application in the user terminal can send the transaction information and verification data collected during the transaction to the acquiring system platform. The acquiring system platform includes the acquiring application's backend server. The acquiring system platform can forward the transaction information and verification data to the trading system platform. The trading system platform can generate a transaction verification request based on the transaction information and verification data, and send the transaction verification request to the transaction verification platform, requesting the transaction verification platform to verify the binding relationship between the merchant terminal number and the device serial number identifier, as well as the first verification data.

[0166] S520, in response to the transaction verification request, if a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform, determine the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship.

[0167] The transaction verification platform may store the binding relationship between the merchant terminal number, the device serial number, and the chip identifier. After receiving a transaction verification request, the transaction system platform may respond to the transaction verification request by first verifying the binding relationship between the device serial number and the merchant terminal number in the transaction information. If the transaction verification platform stores the binding relationship between the merchant terminal number and the device serial number, it may be determined that the binding relationship verification has passed. Based on the binding relationship, the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform is determined. The target chip identifier may be used to verify the first verification data.

[0168] S530: Acquire a target chip identification key corresponding to the target chip identification stored in the transaction verification platform.

[0169] S540: Encrypt the target chip identification and transaction information using the target chip identification key to obtain target first verification data.

[0170] The transaction verification platform uses the same encryption method as the user terminal. It first concatenates the target chip ID and transaction information in a fixed format to generate a second string. It then uses a hash algorithm to calculate a digest of the second string to generate the digest information. This digest information is then symmetrically encrypted using the target chip ID key to generate the target first verification data.

[0171] S550: When the target first verification data is identical to the first verification data, verification pass information corresponding to the first verification data is sent to the trading system platform, so that the trading system platform verifies the second verification data.

[0172] Here, if the target chip identification and the chip identification are the same, the target chip identification key and the chip identification key are the same, and the transaction information collected by the user terminal and the transaction information received by the transaction verification platform are the same, then the target first verification data is the same as the first verification data.

[0173] As an example, after obtaining the target first verification data, the transaction verification platform can compare the target first verification data with the first verification data. If the comparison is consistent, it can be determined that the first verification data has been verified and the verification pass information can be sent to the transaction system platform so that the transaction system platform can continue to complete the subsequent process. If the target first verification data is inconsistent with the first verification data, it can be determined that the transaction information collected by the user terminal and the transaction information received by the transaction verification platform are different, or the target chip identification key is different from the chip identification key, or the target chip identification is different from the chip identification. Therefore, it is considered that there is a risk of tampering with the transaction, and the transaction system platform is notified to suspend the transaction process.

[0174] In addition, other steps of the method in the embodiment of the present application can be found in the above Figure 2 The description of the embodiments shown will not be repeated here.

[0175] The embodiment of the present application, when receiving the transaction information and verification data sent by the user terminal via the transaction system platform, first determines whether there is a binding relationship between the merchant terminal number and the device serial number stored, so as to verify whether the user terminal meets the basic requirements of "1 terminal 1 hardware serial number 1 authorized merchant" for transaction verification. By determining the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship when the verification is passed; obtaining the target chip identifier key corresponding to the target chip identifier stored in the transaction verification platform; using the target chip identifier key to encrypt the target chip identifier and the transaction information to obtain the target first verification data, it is possible to verify the first verification data based on the consistency between the target first verification data and the first verification data. In addition, by sending the verification pass information corresponding to the first verification data to the transaction system platform when the first verification data is verified, the transaction system platform can verify the second verification data, thereby realizing transaction verification of the user terminal POS. In this way, since user terminals with POS functions usually have eSE chips, the embodiment of the present application can improve the universality of transaction verification of user terminal POS.

[0176] On the basis of the above embodiment, in order to improve the security of the transaction, in some embodiments, the above S520 may specifically include:

[0177] In response to the transaction verification request, obtaining the sending time of the transaction verification request and the system time of the transaction verification platform;

[0178] When the time interval between the sending time and the system time is less than the preset time interval, and the transaction verification platform stores a binding relationship between the merchant terminal number and the device serial number, the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform is determined according to the binding relationship.

[0179] Here, the system time of the transaction verification platform may be the time when the transaction verification platform receives the transaction verification request. The preset time interval may be a pre-set time interval used to verify whether the transaction has been tampered with. If there is a significant gap between the time the transaction verification request is sent by the transaction system platform and the time it is received, the transaction verification request may have been tampered with or replayed during the sending process, resulting in an abnormal response being returned to the transaction system platform. If the time interval between the sending time and the system time is less than the preset time interval, subsequent transaction verification can proceed.

[0180] The embodiment of the present application determines whether a transaction verification request has an anti-replay risk based on the sending time of the transaction verification request and the system time of the transaction verification platform, thereby reducing the risk of the first verification data being tampered with during the transaction process and improving the security of the transaction.

[0181] Based on this, in order to further improve the security of transactions, in some embodiments, when the time interval between the sending time and the system time is less than the preset time interval, and the transaction verification platform stores a binding relationship between the merchant terminal number and the device serial number, determining the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform based on the binding relationship may specifically include:

[0182] When the time interval between the sending time and the system time is less than the preset time interval, calculating a first hash value of the first verification data;

[0183] When the first hash value does not exist in the cache of the transaction verification platform and the transaction verification platform stores a binding relationship between the merchant terminal number and the device serial number, the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform is determined according to the binding relationship.

[0184] Here, the transaction verification platform's cache (e.g., a Redis cache) may contain a hash value of the first verification data. If the first hash value exists in the transaction verification platform's cache, the first verification data may be at risk of being replayed, and an exception response may be returned to the transaction system platform, halting the transaction. If the first hash value does not exist in the transaction verification platform's cache, the subsequent transaction verification process can continue.

[0185] The embodiment of the present application can reduce the risk of the first verification data being tampered with during the transaction process by performing an anti-replay check on the first verification data, thereby further improving transaction security.

[0186] Based on this, in order to implement anti-replay check on the first verification data, in some embodiments, the above S550 may specifically include:

[0187] When the target first verification data is identical to the first verification data, calculating a second hash value of the first verification data;

[0188] caching the second Hash value until the cache duration of the second Hash value reaches a preset cache duration;

[0189] Send verification pass information corresponding to the first verification data to the transaction system platform.

[0190] Here, if the first verification data is verified, the second hash value of the first verification data can be cached in a cache (such as a Redis cache), and a preset cache duration of the key corresponding to the second hash value can be set. The preset cache duration can indicate the expiration time of the second hash value. The preset cache duration can be, for example, 5 minutes. If the cache duration of the second hash value reaches the preset cache duration, the second hash value can be deleted from the cache.

[0191] By caching the second Hash value until the cache duration of the second Hash value reaches the preset cache duration, an anti-replay check can be performed on the first verification data based on the second Hash value.

[0192] Furthermore, as described above, to implement transaction verification for the user terminal POS, in some embodiments, a device initialization phase may be included before S210. This device initialization phase may include the user terminal requesting the transaction verification platform to obtain the chip identification key, ciphertext calculation application, device serial number, and device serial number key, and storing them in a secure area. Furthermore, the initialization phase may also include the user terminal requesting the transaction verification platform to establish a binding relationship between the merchant terminal number, device serial number, and chip identification.

[0193] That is, before the above S510, the transaction verification counter can respond to the request of the user terminal and send information such as the chip identification key, ciphertext calculation application, device serial number and device serial number key to the user terminal, and establish a binding relationship between the merchant terminal number, device serial number and chip identification.

[0194] It should be noted that there may be a risk of tampering with working keys such as chip identification keys and device serial numbers during the transmission process between the user terminal and the transaction verification platform. Therefore, in order to ensure the security of the working keys, and then ensure the accuracy of the first verification data and second verification data subsequently encrypted using the working keys, and ensure the accuracy of transaction verification, in some embodiments, before the user terminal requests information such as the chip identification key, ciphertext calculation application, device serial number and device serial number key from the transaction verification platform, it can also first request a master key from the transaction verification platform, so as to use the master key to encrypt the working key in the subsequent process to ensure the security of the working key.

[0195] Based on this, in order to ensure the security of the working key, in some embodiments, before the above S510, the following steps may also be included:

[0196] Receiving a key update request sent by a user terminal, where the key update request is generated by the user terminal based on the chip identifier, the application identifier, and the initial master key stored in the secure area;

[0197] In response to the key update request, the chip identifier and the application identifier are encrypted using the root key to obtain a target initial master key;

[0198] If the target initial master key and the initial master key are the same, the target initial master key is determined as the master key;

[0199] Send the master key to the user terminal.

[0200] To ensure the security of the initial master key, in some embodiments, the key update request may include the encrypted information of the initial master key. The encrypted information of the initial master key is obtained by encrypting the initial master key using the root key by the user terminal. Therefore, if the target initial master key is the same as the initial master key, before determining the target initial master key as the master key, the method may further include:

[0201] Use the root key to decrypt the ciphertext of the initial master key to obtain the initial master key;

[0202] Determine whether the target initial master key is the same as the initial master key.

[0203] Based on this, in order to ensure the security of the master key, in some embodiments, sending the master key to the user terminal may specifically include:

[0204] The master key is encrypted using the initial master key to obtain the ciphertext information of the master key;

[0205] Send the encrypted information of the master key to the user terminal.

[0206] Furthermore, in order to implement verification of the first verification data through the transaction verification platform, in some embodiments, after determining the target initial master key as the master key, the method may further include:

[0207] Receiving a chip identification key acquisition request sent by a user terminal;

[0208] generating a chip identification key in response to a chip identification key acquisition request;

[0209] The chip identification key is encrypted using the master key to obtain the ciphertext information of the chip identification key;

[0210] Send the encrypted information of the chip identification key to the user terminal.

[0211] In order to enable the user terminal to generate the first verification data and the second verification data, in some embodiments, after determining the target initial master key as the master key, the method may further include:

[0212] Receive an application acquisition request sent by a user terminal, where the application acquisition request is used to request acquisition of a ciphertext calculation application;

[0213] Responding to the application acquisition request, obtaining an installation package of the ciphertext calculation application;

[0214] Send the installation package to the user terminal.

[0215] In order to meet the basic transaction verification requirement of "1 terminal 1 hardware serial number 1 authorized merchant" and further improve the accuracy of transaction verification, in some embodiments, after determining the target initial master key as the master key, the method may further include:

[0216] Receive a device binding request sent by a user terminal, where the device binding request is used to request establishment of a binding relationship between a merchant terminal number and a chip identifier;

[0217] In response to the device binding request, if there is no binding relationship between the merchant terminal number and any chip identifier, and if there is no binding relationship between the chip identifier and any merchant terminal number, establishing a binding relationship between the merchant terminal number and the chip identifier;

[0218] Assign a device serial number and a device serial number key corresponding to the device serial number to the binding relationship;

[0219] Use the master key to encrypt the device serial number key to obtain the ciphertext information of the device serial number key;

[0220] Send the encrypted information of the device serial number and the device serial number key to the user terminal.

[0221] The steps of the method in the embodiment of the present application can be found in the relevant description of the embodiment shown on the user terminal side above, and will not be elaborated here.

[0222] In order to better describe the entire solution, based on the above embodiments, the transaction verification method provided in the embodiment of the present application and applied to the transaction verification system based on the user terminal POS is introduced.

[0223] As mentioned above, the transaction verification system based on the user terminal POS can be used to initialize the user terminal device and perform transaction verification when using the user terminal POS to collect payments. Among them, taking the key calculation application as Applet, the chip key as CPLC information, and the chip identification key as the CPLC working key as an example, the device initialization realizes the remote key distribution and device binding check functions, which mainly include the eSE security area master key generation process, Applet and CPLC working key distribution, and device binding. In addition, taking the user using a bank card to pay as an example, in the transaction process, in addition to the basic collection of transaction information, the CPLC working key and device serial number key stored in the eSE security area will also be used to calculate the device ciphertext (including the first verification data and the second verification data), and the device ciphertext verification and ciphertext anti-replay mechanism will be used during the transaction process to realize device control verification. The transaction process can include two parts: front-end information collection and back-end transaction verification.

[0224] like Figure 6 As shown, a schematic diagram of a device initialization process provided in an embodiment of the present application may include the following steps:

[0225] S61. Enter the merchant terminal number into the acquiring application of the user terminal;

[0226] S62. The user terminal reads the CPLC information of the eSE, creates a security area corresponding to the transaction verification service in the eSE, generates an initial master key, and stores it in the security area.

[0227] S63. The user terminal applies to the transaction verification platform for updating the initial master key.

[0228] S64. The transaction verification platform verifies the initial master key and generates a master key if the verification passes.

[0229] S65. The transaction verification platform returns the master key to the user terminal.

[0230] S66. The user terminal updates the initial master key using the master key.

[0231] S67: The user terminal requests the transaction verification platform to issue the Applet and CPLC working key.

[0232] S68. The transaction verification platform generates a CPLC working key and obtains the Applet installation package;

[0233] S69. The transaction verification platform issues the CPLC working key and Applet installation package;

[0234] S610: The user terminal installs the Applet in the secure area and stores the CPLC working key.

[0235] S611. The user terminal applies to the transaction verification platform for device binding based on the user terminal number and CPLC information.

[0236] S612: The transaction verification platform checks the binding relationship between the user terminal number and the CPLC information;

[0237] S613. After confirming that the user terminal number and the CPLC information correspond one to one, the transaction verification platform establishes a binding relationship between the user terminal number and the CPLC information, and allocates a device serial number and a device serial number key for the binding relationship.

[0238] S614. The transaction verification platform sends the device serial number and device serial number key to the user terminal.

[0239] S615. The user terminal stores the device serial number and the device serial number key in a secure area.

[0240] In the embodiments of the present application, a user terminal with POS functionality collects the eSE's CPLC information as a unique device identifier. Based on the CPLC information, the transaction verification platform generates a secure zone master key, CPLC working key, device serial number, and device serial number key, and distributes these keys to the secure zone of the device's eSE. This enables remote distribution of device key data and operating parameters. Because the device key data and operating parameters are distributed remotely, compared to the offline input of master keys and device serial number keys in traditional POS systems, user operations can be simplified and device initialization efficiency improved.

[0241] like Figure 7 As shown, a flowchart of a transaction verification process provided by an embodiment of the present application may include the following steps:

[0242] S71. The user terminal reads the card through the acquiring application and obtains transaction information.

[0243] S72. The user terminal uses the acquiring application to call the applet to calculate the first verification data and the second verification data, and read the device serial number;

[0244] S73. The user terminal sends the transaction information and verification data to the acquiring system platform through the acquiring application, where the verification data includes the first verification data, the second verification data, and the device serial number.

[0245] S74. The acquiring system platform sends transaction information and verification data to the trading system platform;

[0246] S75. The transaction system platform sends a transaction verification request to the transaction verification platform. The transaction verification request may include transaction information and verification data. The transaction verification request may be used to request the transaction verification platform to verify the device information of the user terminal.

[0247] S76. The transaction verification platform performs an anti-replay check on the first verification data.

[0248] S77. The transaction verification platform performs a device binding relationship check (i.e., checks whether a binding relationship between the merchant terminal number and the device serial number is stored);

[0249] S78. The transaction verification platform verifies and performs anti-replay processing on the first verification data (i.e., caches the second hash value corresponding to the first verification data);

[0250] S79. The transaction verification platform sends the device verification result (including the verification result of anti-replay check, binding relationship, and first verification data) to the transaction system platform.

[0251] S710: The trading system platform verifies the second verification data;

[0252] S711. The transaction system platform returns a transaction response to the acquiring system platform.

[0253] S712. The acquiring system platform returns a transaction response to the acquiring application in the user terminal.

[0254] The front-end application (i.e., acquiring application) designed in the embodiment of the present application is responsible for calling the Applet in the eSE security area, using CPLC information and transaction element information to participate in the calculation process of the first verification data and the second verification data. The back-end system verifies the transaction information and transaction equipment through the ciphertext verification mechanism, and reduces the risk of device information being tampered with during the transaction process through the device ciphertext anti-replay mechanism.

[0255] The embodiment of the present application uses a transaction verification and mechanism that combines the front-end and back-end, relies on CPLC information as device identification, and uses a master key mechanism and a transaction information participation verification mechanism to achieve management and control of device binding and enhanced verification of device transactions during the transaction process, thereby realizing the control of "1 terminal 1 hardware serial number 1 authorized merchant".

[0256] Based on the user terminal POS-based transaction verification method provided in the above embodiment, this application also provides a specific implementation of a user terminal POS-based transaction verification device applied to a user terminal. The user terminal includes an embedded secure element (eSE) and an acquiring application, and the eSE's secure area includes a ciphertext calculation application, a chip identification key, a device serial number key, and the user terminal's device serial number.

[0257] See the following examples.

[0258] like Figure 8As shown, the transaction verification device 800 based on the user terminal POS provided in the embodiment of the present application includes the following modules:

[0259] A first acquisition module 810 is configured to acquire the chip identifier of the eSE and transaction information of the transaction order when the acquiring application acquires the payment account information used to pay the transaction order. The acquiring application has a merchant terminal number entered therein, and the transaction information includes the merchant terminal number.

[0260] A first encryption module 820 is configured to invoke a ciphertext calculation application to encrypt the chip identification and transaction information using the chip identification key to obtain first verification data. The chip identification key and ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information.

[0261] The first encryption module 820 is further configured to call a ciphertext calculation application to encrypt the device serial number and payment account information using a device serial number key to obtain second verification data. The device serial number and device serial number key are assigned to the user terminal by the transaction verification platform after confirming a one-to-one correspondence between the merchant terminal number and the chip identifier, before the acquiring application obtains the payment account information.

[0262] A first determination module 830 is configured to determine the verification data based on the first verification data, the second verification data, and the device serial number;

[0263] The first sending module 840 is used to send transaction information and verification data to the transaction verification system via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

[0264] The transaction verification device 800 based on the user terminal POS is described in detail below:

[0265] In some embodiments, the first encryption module 820 may specifically include:

[0266] The first calculation submodule is used to call the ciphertext calculation application to perform digest calculation on the chip identifier and transaction information to obtain digest information;

[0267] The first encryption submodule is configured to encrypt the summary information using the chip identification key to obtain first verification data.

[0268] In some embodiments, the first encryption module 820 may specifically include:

[0269] The splicing submodule is used to call the ciphertext calculation application to splice the device serial number and payment account information to obtain the target serial number;

[0270] The first encryption submodule is further configured to encrypt the target serial number using the device serial number key to obtain a second verification.

[0271] In some embodiments, an initial master key is stored in the secure area. Based on this, the first acquisition module 810 is further configured to obtain the chip identifier of the eSE and the application identifier of the acquiring application before obtaining the chip identifier of the eSE and the transaction information of the transaction order when the acquiring application obtains the payment account information used to pay the transaction order;

[0272] The transaction verification device 800 based on the user terminal POS may further include:

[0273] A first generating module, configured to generate a key update request based on the chip identifier, the application identifier, and the initial master key;

[0274] The first sending module 840 is further configured to send a key update request to the transaction verification platform, so that the transaction verification platform verifies the initial master key and generates a master key based on the chip identifier and the application identifier if the initial master key verification passes;

[0275] A first receiving module is configured to receive a master key fed back by the transaction verification platform in response to a key update request;

[0276] The update module is used to update the initial master key stored in the security area using the master key.

[0277] In some embodiments, the first determining module 830 is further configured to determine a key dispersion factor based on the chip identification and the application identification before generating a key update request based on the chip identification, the application identification, and the initial master key;

[0278] The transaction verification device 800 based on the user terminal POS may further include:

[0279] A key dispersion module is used to disperse the key dispersion factors using the root key based on the key dispersion algorithm to obtain an initial master key;

[0280] The storage module is used to store the initial master key in a secure area.

[0281] In some embodiments, the first generating module may specifically include:

[0282] The first encryption submodule is further configured to encrypt the initial master key using the root key to obtain ciphertext information of the initial master key;

[0283] The first generating submodule is used to generate a key update request based on the chip identifier, the application identifier and the encrypted information of the initial master key.

[0284] In some embodiments, the first receiving module may specifically include:

[0285] The receiving submodule is used to receive the ciphertext information of the master key fed back by the transaction verification platform in response to the key update request. The ciphertext information of the master key is obtained by encrypting the master key using the initial master key by the transaction verification platform.

[0286] Based on this, the update module may specifically include:

[0287] The decryption submodule is used to decrypt the ciphertext information of the master key using the initial master key to obtain the master key;

[0288] The update submodule is used to update the initial master key stored in the security area using the master key.

[0289] In some embodiments, the first sending module 840 is further configured to, after obtaining the chip identification of the eSE and the application identification of the acquiring application, send a chip identification key acquisition request to the transaction verification platform, so that the transaction verification platform generates a chip identification key, and encrypt the chip identification key using the master key to obtain ciphertext information of the chip identification key.

[0290] The first receiving module is further configured to receive the ciphertext information of the chip identification key fed back by the transaction verification platform in response to the chip identification key acquisition request;

[0291] The transaction verification device 800 based on the user terminal POS may further include:

[0292] A first decryption module is used to decrypt the ciphertext information of the chip identification key using the master key to obtain the chip identification key;

[0293] The storage module is also used to store the chip identification key in a secure area.

[0294] In some embodiments, the first sending module 840 is further configured to, after obtaining the chip identifier of the eSE and the application identifier of the acquiring application, send an application acquisition request to the transaction verification platform, where the application acquisition request is used to request the acquisition of the ciphertext calculation application;

[0295] The first receiving module is further configured to receive an installation package of the ciphertext calculation application fed back by the transaction verification platform in response to the application acquisition request;

[0296] The transaction verification device 800 based on the user terminal POS may further include:

[0297] The installation module is used to install the ciphertext computing application in the secure area based on the installation package.

[0298] In some embodiments, the first obtaining module 810 is further configured to obtain the merchant terminal number and the eSE chip identifier entered in the acquiring application before obtaining the eSE chip identifier and the transaction information of the transaction order when the acquiring application obtains the payment account information used to pay the transaction order;

[0299] The first generating module is further configured to generate a device binding request based on the merchant terminal number and the chip identifier, wherein the device binding request is configured to request establishment of a binding relationship between the merchant terminal number and the chip identifier;

[0300] The first sending module 840 is further configured to send a device binding request to the transaction verification platform, so that the transaction verification platform establishes a binding relationship between the merchant terminal number and the chip identifier when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number, assigns a device serial number and a device serial number key corresponding to the device serial number to the binding relationship, and encrypts the device serial number key using the master key to obtain ciphertext information of the device serial number key.

[0301] The first receiving module is further configured to receive the encrypted information of the device serial number and the device serial number key fed back by the transaction verification platform in response to the device binding request;

[0302] The first decryption module is further configured to decrypt the encrypted information of the device serial number using the master key in the secure area to obtain the device serial number key;

[0303] The storage module is further configured to store the device serial number and the device serial number key in a secure area.

[0304] This embodiment of the present application assigns a device serial number to the user terminal by ensuring, before the acquiring application obtains payment account information, that the merchant terminal number entered into the acquiring application corresponds to the chip identifier of the user terminal's eSE. This achieves a one-to-one correspondence between the user terminal, device serial number, and merchant terminal number, meeting the basic transaction verification requirement of "one terminal, one hardware serial number, one authorized merchant." The user terminal obtains the ciphertext calculation application, chip identifier key, device serial number, and device serial number key from the transaction verification platform and stores them in the user terminal's eSE chip, ensuring the security of the application, key, and device serial number, providing security for transaction verification. By calling a ciphertext calculation application when the acquiring application obtains the payment account information used to pay for the transaction order, using the chip identification key to encrypt the chip identification and transaction information to obtain the first verification data; using the device serial number key to encrypt the device serial number and payment account information to obtain the second verification data; determining the verification data based on the first verification data, the second verification data and the device serial number; and sending the transaction information and verification data to the transaction verification platform via the transaction system platform, so that the transaction verification platform can verify the first verification data, and the transaction system platform can verify the second verification data, thereby realizing transaction verification of the user terminal POS. In this way, since the user terminal with POS function usually has an eSE chip, the embodiment of the present application can improve the universality of transaction verification of the user terminal POS.

[0305] Based on the transaction verification method based on a user terminal POS and applied to a transaction verification platform provided in the above embodiment, this application also provides a specific implementation of a transaction verification device based on a user terminal POS and applied to a transaction verification platform. Please refer to the following embodiment.

[0306] like Figure 9 As shown, the transaction verification device 900 based on the user terminal POS provided in the embodiment of the present application includes the following modules:

[0307] The second receiving module 910 is configured to receive transaction information and verification data sent by the user terminal via the transaction system platform. The transaction information and verification data are obtained by the user terminal when the payment account information used to pay the transaction order is obtained. The transaction information includes the merchant terminal number, and the verification data includes the first verification data, the second verification data, and the device serial number of the user terminal. The first verification data is obtained by encrypting the chip identifier of the eSE in the user terminal and the transaction information using the chip identifier key; the second verification data is obtained by encrypting the device serial number and the payment account information using the device serial number key.

[0308] A second determination module 920 is configured to, in response to the transaction verification request, determine a target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform based on the binding relationship if a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform;

[0309] The second acquisition module 930 is used to obtain the target chip identification key corresponding to the target chip identification stored in the transaction verification platform;

[0310] The second encryption module 940 is used to encrypt the target chip identification and transaction information using the target chip identification key to obtain the target first verification data;

[0311] The second sending module 950 is configured to send verification pass information corresponding to the first verification data to the trading system platform when the target first verification data is identical to the first verification data, so that the trading system platform verifies the second verification data.

[0312] The transaction verification device 900 based on the user terminal POS is described in detail below.

[0313] In some embodiments, the second determining module 920 may specifically include:

[0314] An acquisition submodule, configured to respond to a transaction verification request and obtain the sending time of the transaction verification request and the system time of the transaction verification platform;

[0315] The determination submodule is used to determine the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship when the time interval between the sending time and the system time is less than the preset time interval and the binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform.

[0316] In some embodiments, the determination submodule may specifically include:

[0317] a second calculation submodule, configured to calculate a first hash value of the first verification data when the time interval between the sending time and the system time is less than a preset time interval;

[0318] The determination submodule is used to determine the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship when the first hash value does not exist in the cache of the transaction verification platform and the binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform.

[0319] In some embodiments, the second sending module 950 may specifically include:

[0320] The second calculation submodule is further configured to calculate a second hash value of the first verification data when the target first verification data is the same as the first verification data;

[0321] a cache submodule, configured to cache the second hash value until a cache duration of the second hash value reaches a preset cache duration;

[0322] The sending submodule is used to send verification pass information corresponding to the first verification data to the trading system platform.

[0323] In some embodiments, the second acquisition module 930 is further configured to receive a key update request sent by the user terminal before receiving the transaction verification request sent by the transaction system platform, where the key update request is generated by the user terminal based on the chip identifier, the application identifier, and the initial master key stored in the secure area;

[0324] The second encryption module 940 is further configured to, in response to a key update request, encrypt the chip identifier and the application identifier using the root key to obtain a target initial master key;

[0325] The second determining module 920 is further configured to determine the target initial master key as the master key when the target initial master key and the initial master key are the same;

[0326] The second sending module 950 is configured to send the master key to the user terminal.

[0327] In some embodiments, the key update request includes the ciphertext of the initial master key, which is obtained by encrypting the initial master key using the root key at the user terminal. Based on this, the transaction verification device 900 based on the user terminal POS may further include:

[0328] a decryption module for, when the target initial master key and the initial master key are identical, decrypting the ciphertext of the initial master key using the root key to obtain the initial master key before determining the target initial master key as the master key;

[0329] The second determining module 920 is further configured to determine whether the target initial master key is the same as the initial master key.

[0330] In some embodiments, the second sending module 950 may specifically include:

[0331] The second encryption submodule is used to encrypt the master key using the initial master key to obtain ciphertext information of the master key;

[0332] The sending submodule is further used to send the ciphertext information of the master key to the user terminal.

[0333] In some embodiments, the second receiving module 910 is further configured to receive a chip identification key acquisition request sent by a user terminal after determining the target initial master key as the master key;

[0334] The transaction verification device 900 based on the user terminal POS may further include:

[0335] A second generating module, configured to generate a chip identification key in response to a chip identification key acquisition request;

[0336] The second encryption module 940 is further configured to encrypt the chip identification key using the master key to obtain ciphertext information of the chip identification key;

[0337] The second sending module 950 is further configured to send the ciphertext information of the chip identification key to the user terminal.

[0338] In some embodiments, the second receiving module 910 is further configured to receive an application acquisition request sent by a user terminal after determining the target initial master key as the master key, the application acquisition request being used to request acquisition of a ciphertext calculation application;

[0339] The second acquisition module 930 is further configured to obtain an installation package of the ciphertext calculation application in response to the application acquisition request;

[0340] The second sending module 950 is further configured to send the installation package to the user terminal.

[0341] In some embodiments, the second receiving module 910 is further configured to receive a device binding request sent by a user terminal after determining the target initial master key as the master key, the device binding request being used to request establishment of a binding relationship between the merchant terminal number and the chip identifier;

[0342] The transaction verification device 900 based on the user terminal POS may further include:

[0343] an establishing module for establishing, in response to a device binding request, a binding relationship between the merchant terminal number and the chip identifier when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number;

[0344] An allocation module, configured to allocate a device serial number and a device serial number key corresponding to the device serial number for the binding relationship;

[0345] The second encryption module 940 is further configured to encrypt the device serial number key using the master key to obtain ciphertext information of the device serial number key;

[0346] The second sending module 950 is further configured to send the encrypted information of the device serial number and the device serial number key to the user terminal.

[0347] The embodiment of the present application, when receiving the transaction information and verification data sent by the user terminal via the transaction system platform, first determines whether there is a binding relationship between the merchant terminal number and the device serial number stored, so as to verify whether the user terminal meets the basic requirements of "1 terminal 1 hardware serial number 1 authorized merchant" for transaction verification. By determining the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship when the verification is passed; obtaining the target chip identifier key corresponding to the target chip identifier stored in the transaction verification platform; using the target chip identifier key to encrypt the target chip identifier and the transaction information to obtain the target first verification data, it is possible to verify the first verification data based on the consistency between the target first verification data and the first verification data. In addition, by sending the verification pass information corresponding to the first verification data to the transaction system platform when the first verification data is verified, the transaction system platform can verify the second verification data, thereby realizing transaction verification of the user terminal POS. In this way, since user terminals with POS functions usually have eSE chips, the embodiment of the present application can improve the universality of transaction verification of user terminal POS.

[0348] Based on the transaction verification method based on the user terminal POS provided in the above embodiment, the embodiment of the present application also provides a specific implementation of the electronic device. Figure 10 A schematic diagram of an electronic device 1000 provided in an embodiment of the present application is shown.

[0349] The electronic device 1000 may include a processor 1010 and a memory 1020 storing computer program instructions.

[0350] Specifically, the processor 1010 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0351] The memory 1020 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 1020 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 1020 may include removable or non-removable (or fixed) media. Where appropriate, the memory 1020 may be internal or external to the electronic device 1000. In a particular embodiment, the memory 1020 is a non-volatile solid-state memory.

[0352] The memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to the first aspect of the present application.

[0353] The processor 1010 reads and executes computer program instructions stored in the memory 1020 to implement any one of the transaction verification methods based on the user terminal POS in the above embodiments.

[0354] In one example, the electronic device 1000 may further include a communication interface 1030 and a bus 1040. Figure 10 As shown, the processor 1010, the memory 1020, and the communication interface 1030 are connected via a bus 1040 and communicate with each other.

[0355] The communication interface 1030 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0356] Bus 1040 includes hardware, software or both, couples the parts of electronic equipment to each other.For example, and not limitation, bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 1040 may include one or more buses. Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.

[0357] Illustratively, the electronic device 1000 may be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA).

[0358] The electronic device can execute the transaction verification method based on the user terminal POS in the embodiment of the present application, thereby realizing the combination of Figures 1 to 9 The present invention describes a transaction verification method and device based on a user terminal POS.

[0359] In addition, in conjunction with the user terminal POS-based transaction verification method in the above-mentioned embodiment, the present application also provides a user terminal POS-based transaction verification system. This user terminal POS-based transaction verification system may include the user terminal, transaction verification platform, and transaction system platform in the above-mentioned embodiment. The user terminal can execute the user terminal POS-based transaction verification method applied to the user terminal in the above-mentioned embodiment. The transaction verification platform can execute the user terminal POS-based transaction verification method applied to the transaction verification platform in the above-mentioned embodiment. For details, please refer to the relevant descriptions in the above-mentioned embodiments. Since the same technical effects can be achieved, they will not be repeated here to avoid repetition.

[0360] In addition, in conjunction with the transaction verification method based on a user terminal POS in the above embodiments, embodiments of the present application may provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the transaction verification methods based on a user terminal POS in the above embodiments is implemented.

[0361] In conjunction with the transaction verification method based on a user terminal POS in the above embodiments, the present application can provide a computer program product for implementation. When the instructions in the computer program product are executed by a processor of an electronic device, any one of the transaction verification methods based on a user terminal POS in the above embodiments is implemented.

[0362] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0363] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0364] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0365] Aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. This processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be implemented by the dedicated hardware that performs the specified function or action, or can be implemented by the combination of dedicated hardware and computer instructions.

[0366] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A transaction verification method based on a user terminal POS, characterized in that: Applied to a user terminal, the user terminal having an embedded secure element (eSE) and an acquiring application, wherein the secure area of ​​the eSE includes a ciphertext calculation application, a chip identification key, a device serial number key, and the device serial number of the user terminal; The method comprises: When the acquiring application obtains the payment account information used to pay the transaction order, obtaining the chip identifier of the eSE and the transaction information of the transaction order, wherein the acquiring application has a merchant terminal number entered therein, and the transaction information includes the merchant terminal number; calling the ciphertext calculation application and encrypting the chip identification and the transaction information using the chip identification key to obtain first verification data; the chip identification key and the ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information; calling the ciphertext calculation application to encrypt the device serial number and the payment account information using the device serial number key to obtain second verification data, wherein the device serial number and the device serial number key are assigned to the user terminal by the transaction verification platform upon determining a one-to-one correspondence between the merchant terminal number and the chip identifier before the acquiring application obtains the payment account information; determining verification data based on the first verification data, the second verification data, and the device serial number; The transaction information and the verification data are sent to the transaction verification platform via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and the transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

2. The method according to claim 1, characterized in that The calling of the ciphertext computing application and encrypting the chip identification and the transaction information using the chip identification key to obtain first verification data includes: Calling the ciphertext calculation application to perform digest calculation on the chip identifier and the transaction information to obtain digest information; The digest information is encrypted using the chip identification key to obtain the first verification data.

3. The method according to claim 1, characterized in that The calling of the ciphertext calculation application and encrypting the device serial number and the payment account information using the device serial number key to obtain second verification data includes: Calling the ciphertext calculation application to concatenate the device serial number and the payment account information to obtain a target serial number; The target serial number is encrypted using the device serial number key to obtain the second verification.

4. The method according to claim 1, wherein The security area stores an initial master key. When the acquiring application obtains payment account information for paying a transaction order, before obtaining the chip identifier of the eSE and transaction information of the transaction order, the method further includes: Obtaining the chip identifier of the eSE and the application identifier of the acquiring application; Generate a key update request based on the chip identifier, the application identifier and the initial master key; Sending the key update request to the transaction verification platform, so that the transaction verification platform verifies the initial master key, and if the initial master key passes the verification, generating a master key based on the chip identifier and the application identifier; receiving the master key fed back by the transaction verification platform in response to the key update request; The initial master key stored in the secure area is updated using the master key.

5. The method according to claim 4, characterized in that Before generating a key update request based on the chip identifier, the application identifier, and the initial master key, the method further includes: determining a key dispersion factor according to the chip identifier and the application identifier; Using the root key, the key dispersion factor is subjected to key dispersion based on a key dispersion algorithm to obtain the initial master key; The initial master key is stored in the secure area.

6. The method according to claim 4 or 5, characterized in that The generating a key update request based on the chip identifier, the application identifier, and the initial master key includes: Encrypting the initial master key using the root key to obtain ciphertext information of the initial master key; The key update request is generated based on the chip identifier, the application identifier, and the encrypted information of the initial master key.

7. The method according to claim 4 or 5, characterized in that The receiving the master key fed back by the transaction verification platform in response to the key update request includes: receiving ciphertext information of the master key fed back by the transaction verification platform in response to the key update request, where the ciphertext information of the master key is obtained by the transaction verification platform encrypting the master key using the initial master key; The updating of the initial master key stored in the security area by using the master key includes: Decrypting the ciphertext of the master key using the initial master key to obtain the master key; The initial master key stored in the secure area is updated using the master key.

8. The method according to claim 4, characterized in that After obtaining the chip identifier of the eSE and the application identifier of the acquiring application, the method further includes: Sending a chip identification key acquisition request to the transaction verification platform, so that the transaction verification platform generates a chip identification key, and encrypting the chip identification key with the master key to obtain ciphertext information of the chip identification key; receiving the ciphertext information of the chip identification key fed back by the transaction verification platform in response to the chip identification key acquisition request; Decrypting the ciphertext information of the chip identification key using the master key to obtain the chip identification key; The chip identification key is stored in the secure area.

9. The method according to claim 4 or 8, characterized in that After obtaining the chip identifier of the eSE and the application identifier of the acquiring application, the method further includes: Sending an application acquisition request to the transaction verification platform, wherein the application acquisition request is used to request acquisition of a ciphertext calculation application; Receiving the installation package of the ciphertext calculation application fed back by the transaction verification platform in response to the application acquisition request; The ciphertext computing application is installed in the secure area based on the installation package.

10. The method according to claim 4 or 5, characterized in that When the acquiring application obtains the payment account information used to pay the transaction order, before obtaining the chip identifier of the eSE and the transaction information of the transaction order, the method further includes: Obtain the merchant terminal number entered in the acquiring application and the chip identifier of the eSE; generating a device binding request based on the merchant terminal number and the chip identifier, wherein the device binding request is used to request establishment of a binding relationship between the merchant terminal number and the chip identifier; Sending a device binding request to the transaction verification platform, so that the transaction verification platform establishes a binding relationship between the merchant terminal number and the chip identifier when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number, assigns a device serial number and a device serial number key corresponding to the device serial number to the binding relationship, and encrypts the device serial number key using the master key to obtain ciphertext information of the device serial number key; receiving the encrypted information of the device serial number and the device serial number key fed back by the transaction verification platform in response to the device binding request; Decrypting the encrypted information of the device serial number using the master key in the secure area to obtain the device serial number key; The device serial number and the device serial number key are stored in the secure area.

11. A transaction verification method based on a user terminal POS, characterized in that: Applied to a transaction verification platform, the method includes: Receive a transaction verification request sent by a transaction system platform, the transaction verification request including transaction information and verification data, the transaction information and verification data being obtained and sent to the transaction system platform by the user terminal when the user terminal obtains payment account information used to pay the transaction order, the transaction information including the merchant terminal number, and the verification data including first verification data, second verification data, and a device serial number of the user terminal; the first verification data being obtained by encrypting the chip identifier of the eSE in the user terminal and the transaction information using a chip identifier key; the second verification data being obtained by encrypting the device serial number and the payment account information using a device serial number key, the device serial number and the device serial number key being allocated to the user terminal by the transaction verification platform when determining a one-to-one correspondence between the merchant terminal number and the chip identifier; In response to the transaction verification request, if a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform, determining a target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform according to the binding relationship; Obtaining a target chip identification key corresponding to the target chip identification stored in the transaction verification platform; Encrypting the target chip identification and the transaction information using the target chip identification key to obtain target first verification data; In a case where the target first verification data is identical to the first verification data, verification pass information corresponding to the first verification data is sent to the trading system platform, so that the trading system platform verifies the second verification data.

12. The method according to claim 11, characterized in that In response to the transaction verification request, if a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform, determining, based on the binding relationship, a target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform, includes: In response to the transaction verification request, obtaining the sending time of the transaction verification request and the system time of the transaction verification platform; When the time interval between the sending time and the system time is less than the preset time interval and the transaction verification platform stores a binding relationship between the merchant terminal number and the device serial number, the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform is determined according to the binding relationship.

13. The method according to claim 12, characterized in that The step of determining, when the time interval between the sending time and the system time is less than a preset time interval and a binding relationship between the merchant terminal number and the device serial number is stored in the transaction verification platform, based on the binding relationship, a target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform, includes: When the time interval between the sending time and the system time is less than a preset time interval, calculating a first hash value of the first verification data; When the first hash value does not exist in the cache of the transaction verification platform and the transaction verification platform stores a binding relationship between the merchant terminal number and the device serial number, the target chip identifier corresponding to the merchant terminal number and the device serial number stored in the transaction verification platform is determined based on the binding relationship.

14. The method according to any one of claims 11 to 13, characterized in that: When the target first verification data is identical to the first verification data, sending verification pass information corresponding to the first verification data to the trading system platform includes: When the target first verification data is identical to the first verification data, calculating a second hash value of the first verification data; caching the second Hash value until the cache duration of the second Hash value reaches a preset cache duration; Sending verification pass information corresponding to the first verification data to the transaction system platform.

15. The method according to claim 11, characterized in that Before receiving the transaction verification request sent by the transaction system platform, the method further includes: receiving a key update request sent by the user terminal, where the key update request is generated by the user terminal based on the chip identifier, the application identifier of the acquiring application, and the initial master key stored in the secure area of ​​the user terminal; In response to the key update request, encrypting the chip identifier and the application identifier using a root key to obtain a target initial master key; If the target initial master key and the initial master key are the same, determining the target initial master key as the master key; Sending the master key to the user terminal.

16. The method according to claim 15, characterized in that The key update request includes ciphertext information of the initial master key, where the ciphertext information of the initial master key is obtained by the user terminal encrypting the initial master key using the root key; When the target initial master key and the initial master key are identical, before determining the target initial master key as the master key, the method further includes: Decrypting the ciphertext of the initial master key using the root key to obtain the initial master key; It is determined whether the target initial master key is the same as the initial master key.

17. The method according to claim 15 or 16, characterized in that The sending the master key to the user terminal includes: Encrypting the master key using the initial master key to obtain ciphertext information of the master key; Send the encrypted information of the master key to the user terminal.

18. The method according to claim 15, characterized in that After determining the target initial master key as the master key, the method further includes: Receiving a chip identification key acquisition request sent by the user terminal; generating a chip identification key in response to the chip identification key acquisition request; Encrypting the chip identification key using the master key to obtain ciphertext information of the chip identification key; Sending the encrypted information of the chip identification key to the user terminal.

19. The method according to claim 15 or 18, characterized in that After determining the target initial master key as the master key, the method further includes: receiving an application acquisition request sent by the user terminal, wherein the application acquisition request is used to request acquisition of a ciphertext calculation application; In response to the application acquisition request, obtaining an installation package of the ciphertext computing application; Send the installation package to the user terminal.

20. The method according to claim 15 or 16, characterized in that After determining the target initial master key as the master key, the method further includes: receiving a device binding request sent by the user terminal, wherein the device binding request is used to request establishment of a binding relationship between the merchant terminal number and the chip identifier; In response to the device binding request, when there is no binding relationship between the merchant terminal number and any chip identifier, and when there is no binding relationship between the chip identifier and any merchant terminal number, establishing a binding relationship between the merchant terminal number and the chip identifier; Allocating a device serial number and a device serial number key corresponding to the device serial number to the binding relationship; Encrypting the device serial number key using the master key to obtain ciphertext information of the device serial number key; Sending the encrypted information of the device serial number and the device serial number key to the user terminal.

21. A transaction verification device based on a user terminal POS, characterized in that: Applied to a user terminal, the user terminal having an embedded secure element (eSE) and an acquiring application, wherein the secure area of ​​the eSE includes a ciphertext calculation application, a chip identification key, a device serial number key, and the device serial number of the user terminal; The device comprises: a first acquisition module, configured to acquire, when the acquiring application acquires payment account information used to pay for a transaction order, the chip identifier of the eSE and transaction information of the transaction order, wherein the acquiring application has a merchant terminal number entered therein, and the transaction information includes the merchant terminal number; a first encryption module, configured to call the ciphertext calculation application and encrypt the chip identification and the transaction information using the chip identification key to obtain first verification data; the chip identification key and the ciphertext calculation application are requested by the user terminal from the transaction verification platform before the acquiring application obtains the payment account information; The first encryption module is further configured to call the ciphertext calculation application to encrypt the device serial number and the payment account information using the device serial number key to obtain second verification data, wherein the device serial number and the device serial number key are assigned to the user terminal by the transaction verification platform upon determining a one-to-one correspondence between the merchant terminal number and the chip identifier before the acquiring application obtains the payment account information; a first determining module, configured to determine verification data based on the first verification data, the second verification data, and the device serial number; The first sending module is used to send the transaction information and the verification data to the transaction verification platform via the transaction system platform, so that the transaction verification platform verifies the first verification data based on the binding relationship and the transaction information when the binding relationship between the merchant terminal number and the device serial number is stored, and the transaction system platform verifies the second verification data.

22. A transaction verification device based on a user terminal POS, characterized in that: Applied to a transaction verification platform, the device comprises: a second receiving module, configured to receive a transaction verification request sent by a transaction system platform, the transaction verification request including transaction information and verification data, the transaction information and verification data being obtained and sent to the transaction system platform by the user terminal upon obtaining payment account information used to pay for the transaction order, the transaction information including the merchant terminal number, the verification data including first verification data, second verification data, and a device serial number of the user terminal; the first verification data being obtained by encrypting the chip identifier of the eSE in the user terminal and the transaction information using a chip identifier key; the second verification data being obtained by encrypting the device serial number and the payment account information using a device serial number key, the device serial number and the device serial number key being allocated to the user terminal by the transaction verification platform upon determining a one-to-one correspondence between the merchant terminal number and the chip identifier; a second determining module, configured to, in response to the transaction verification request, determine, based on a binding relationship between the merchant terminal number and the device serial number stored in the transaction verification platform, a target chip identifier corresponding to the merchant terminal number and the device serial number, stored in the transaction verification platform; A second acquisition module is used to acquire a target chip identification key corresponding to the target chip identification stored in the transaction verification platform; a second encryption module, configured to encrypt the target chip identification and the transaction information using the target chip identification key to obtain target first verification data; The second sending module is used to send verification pass information corresponding to the first verification data to the trading system platform when the target first verification data is the same as the first verification data, so that the trading system platform verifies the second verification data.

23. An electronic device, characterized in that: The electronic device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the transaction verification method based on the user terminal POS is implemented as described in any one of claims 1-10 or 11-20.

24. A transaction verification system based on a user terminal POS, characterized in that: include: A user terminal, configured to execute the transaction verification method based on a user terminal POS according to any one of claims 1 to 10; A transaction verification platform, in communication with the user terminal, is configured to execute the transaction verification method based on the user terminal POS as described in any one of claims 11 to 20.

25. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processor, the transaction verification method based on the user terminal POS as described in any one of claims 1-10 or 11-20 is implemented.

26. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the transaction verification method based on the user terminal POS as described in any one of claims 1-10 or 11-20.

Citation Information

Patent Citations

  • Method, system and equipment for distributing secret key between server and terminal equipment

    CN116886317A

  • Payment method, device, equipment and system based on POS (Point Of Sale) of user terminal and medium

    CN118521301A