Payment method, device, equipment, storage medium and computer program product

By encrypting payment information at the user terminal and re-encrypting with the proxy key, the problem of payment information leakage in the aggregate payment platform is solved, and the high-security transmission of payment information is achieved.

CN120181849APending Publication Date: 2025-06-20TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311757965.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing aggregation payment platform is difficult to avoid the leakage and excessive use of payment information during the payment process, affecting user privacy and security.

Method used

The payment information including the digital asset account is obtained through the user terminal, and the payment information is encrypted using the user's public key, and a proxy key is generated for re-encryption, ensuring that the payment information is only transmitted between the user terminal and the institutional server, and avoiding the intermediate proxy server from obtaining plain text payment information.

Benefits of technology

It effectively avoids the leakage of payment information, improves the security of the payment process, and ensures the protection of user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120181849A_ABST
    Figure CN120181849A_ABST
Patent Text Reader

Abstract

The invention relates to a payment method and device, computer equipment, a storage medium and a computer program product. The method comprises the following steps: in response to a trigger operation of asset deduction based on payment information, obtaining encrypted information obtained by encrypting the payment information by using a user public key, obtaining an account registration mechanism identifier corresponding to the digital asset account, acquiring a proxy key generated by using the user public key and an institution public key corresponding to the account registration institution identifier; and sending the encrypted information, the account registration institution identifier and the proxy key to a proxy server to indicate the proxy server to encrypt the encrypted information by using the proxy key, and forwarding the obtained new encrypted information to an institution server corresponding to the account registration institution identifier, and after the payment information is obtained, performing asset deduction on the digital asset account based on the payment information. Therefore, the payment security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a payment method, apparatus, computer device, storage medium, and computer program product. Background Art

[0002] With the development of network technology, online payment technology has become increasingly popular. Different third-party payment methods have emerged, providing users with more payment options and improving the convenience of the payment process for users. However, for merchants, multiple third-party payment methods will increase their operation complexity and costs. For example, merchants need to connect to the payment channels of various third-party payment methods respectively.

[0003] To this end, aggregation payment platforms have emerged on the market. They integrate various third-party payment methods on their own platforms, providing aggregated network payment for e-commerce online and aggregated mobile payment for physical merchants offline. However, aggregation payment platforms can obtain the plaintext information (such as payment account information, etc.) during the user payment process. Therefore, how to avoid the leakage and overuse of relevant information during the above payment process, and ensure the privacy and security of payment information to protect the rights and interests and privacy of users is an urgent problem to be solved. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a payment method, apparatus, computer device, computer-readable storage medium, and computer program product that can improve payment security.

[0005] This application provides a payment method. The method includes:

[0006] Obtain payment information, where the payment information includes a digital asset account;

[0007] In response to a trigger operation for asset deduction based on the payment information, obtain encrypted information obtained by encrypting the payment information using the user's public key, obtain the account registration institution identifier corresponding to the digital asset account, and obtain a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier;

[0008] Send the encrypted information, the account registration institution identifier, and the proxy key to a proxy server, instructing the proxy server to encrypt the encrypted information using the proxy key, and after obtaining new encrypted information, forward the new encrypted information to the institution server corresponding to the account registration institution identifier, instructing the institution server to decrypt the new encrypted information using the institution private key, obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

[0009] The present application provides a payment system. The system includes a user terminal, a proxy server, and an institution server;

[0010] The user terminal is configured to obtain payment information, where the payment information includes a digital asset account. In response to a trigger operation for asset deduction based on the payment information, it obtains encrypted information obtained by encrypting the payment information using the user's public key, obtains the account registration institution identifier corresponding to the digital asset account, obtains a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier, and sends the encrypted information, the account registration institution identifier, and the proxy key to the proxy server;

[0011] The proxy server is configured to receive the encrypted information, the account registration institution identifier, and the proxy key, and use the proxy key to encrypt the encrypted information. After obtaining new encrypted information, it forwards the new encrypted information to the institution server corresponding to the account registration institution identifier;

[0012] The institution server is configured to receive the new encrypted information, decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

[0013] The present application also provides a payment device. The device includes:

[0014] A payment information acquisition module, configured to obtain payment information, where the payment information includes a digital asset account;

[0015] A proxy key acquisition module, configured to, in response to a trigger operation for asset deduction based on the payment information, obtain encrypted information obtained by encrypting the payment information using the user's public key, obtain the account registration institution identifier corresponding to the digital asset account, and obtain a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier;

[0016] A sending module, configured to send the encrypted information, the account registration institution identifier, and the proxy key to the proxy server, so as to instruct the proxy server to use the proxy key to encrypt the encrypted information. After obtaining new encrypted information, it forwards the new encrypted information to the institution server corresponding to the account registration institution identifier, so as to instruct the institution server to decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

[0017] In some embodiments, the payment information acquisition module is configured to, after collecting the payment code provided by a merchant, display a payment interface, where the payment interface includes payment method options corresponding to multiple different payment methods; in response to the selection of the digital asset account payment method option, display multiple digital asset accounts of the user; and in response to the selection of a target digital asset account from the multiple digital asset accounts, generate payment information according to the target digital asset account.

[0018] In some embodiments, the payment information acquisition module is configured to obtain a digital asset account for paying a target order; obtain order information of the target order, where the order information at least includes an order number, product information, and the amount to be paid; according to the order information, display an independent encryption option interface, where the independent encryption option interface at least includes encryption options corresponding to the order number, product information, and the amount to be paid; obtain a selection operation on the encryption option corresponding to the amount to be paid in the independent encryption option interface, and generate payment information according to the digital asset account and the amount to be paid.

[0019] In some embodiments, the device further includes an encryption module, where the encryption module is configured to obtain a user public key, where the user public key is generated by using a random number generated by a random generation program, and the user public key corresponds to the digital asset account; and encrypt the payment information by using the user public key to obtain encrypted information.

[0020] In some embodiments, the device further includes a storage module, where the storage module is configured to register a digital asset account with an institutional server; after successful registration, obtain an institutional public key from the institutional server; store the account registration institution identifier corresponding to the digital asset account in correspondence with the institutional public key; generate a proxy key according to the user public key and the institutional public key; and store the account registration institution identifier in correspondence with the proxy key.

[0021] In some embodiments, the storage module is configured to, in response to a trigger operation for asset deduction based on the payment information, obtain a common parameter shared between the user terminal and the institutional server corresponding to the account registration institution, and generate a proxy key according to the user public key, the institutional public key, and the common parameter.

[0022] In some embodiments, the common parameter is a static common parameter, and the static common parameter is the account registration institution identifier; the storage module is configured to generate a proxy key according to the user public key, the institutional public key, and the account registration institution identifier.

[0023] In some embodiments, the common parameter is a dynamic common parameter, and the dynamic common parameter is a random verification code; the storage module is configured to generate a random verification code in response to a trigger operation for asset deduction based on the payment information; the storage module is configured to generate an agent key according to the user public key, the institution public key, and the random verification code.

[0024] In some embodiments, the sending module is further configured to use the institution private key to decrypt the new encrypted information to obtain decrypted information; if it is verified that the new encrypted information has not been tampered with, the decrypted information is determined as the payment information.

[0025] In some embodiments, the new encrypted information is formed by combining a first intermediate ciphertext, a third intermediate ciphertext, a fourth intermediate ciphertext, and a second intermediate ciphertext; the sending module is further configured to extract the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information; decrypt according to the institution private key, the common parameter, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain decrypted information.

[0026] In some embodiments, the device further includes a verification module, which is configured to extract the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information; calculate a hash value through hash calculation according to the first intermediate ciphertext, the decrypted information, and the extracted third intermediate ciphertext; if the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0027] The present application also provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the above payment method are implemented.

[0028] The present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the steps of the above payment method are implemented.

[0029] The present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the above payment method are implemented.

[0030] The above payment method, device, computer equipment, storage medium and computer program product obtain payment information including a digital asset account through a user terminal. In this way, once a trigger operation for asset deduction based on the payment information is responded to, first, based on the obtained payment information, the encrypted information obtained by encrypting the payment information using the user public key can be directly determined. This encrypted information can ensure that the subsequent proxy server cannot obtain the plaintext payment information, avoiding the leakage of payment information. Second, based on the digital asset account, the corresponding account registration institution identifier can be quickly determined. Thus, the corresponding proxy key can be directly generated using the user public key and the institution public key corresponding to the account registration institution identifier. After sending the encrypted information, the account registration institution identifier and the proxy key to the proxy server, the proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institution server can decrypt by itself. During the process of the proxy server encrypting again, the payment information will not be exposed to the proxy server, ensuring the security of the payment information. Subsequently, after the proxy server forwards the new encrypted information to the institution server corresponding to the account registration institution identifier, the institution server can use the institution private key to decrypt the new encrypted information by itself to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, during the entire payment process, only the user terminal and the institution server know the payment information, effectively avoiding the leakage of payment information and improving the security of payment.

[0031] This application provides a payment method. The method includes:

[0032] Receiving encrypted information, an account registration institution identifier, and a proxy key sent by a user terminal, where the encrypted information is obtained by encrypting payment information using a user public key, the payment information includes a digital asset account, the account registration institution identifier is an identifier of an account registration institution for registering the digital asset account, and the proxy key is generated using the user public key and the institution public key corresponding to the account registration institution identifier;

[0033] Using the proxy key to encrypt the encrypted information, after obtaining new encrypted information, forwarding the new encrypted information to the institution server corresponding to the account registration institution identifier to instruct the institution server to decrypt the new encrypted information using an institution private key, and after obtaining the payment information, performing asset deduction on the digital asset account based on the payment information.

[0034] This application provides a payment device. The device includes:

[0035] A receiving module, configured to receive the encrypted information, the account registration institution identifier, and the proxy key sent by the user terminal, where the encrypted information is obtained by encrypting payment information using the user's public key, the payment information includes a digital asset account, the account registration institution identifier is the identifier of the account registration institution for registering the digital asset account, and the proxy key is generated using the user's public key and the institutional public key corresponding to the account registration institution identifier;

[0036] A forwarding module, configured to encrypt the encrypted information using the proxy key, and after obtaining new encrypted information, forward the new encrypted information to the institutional server corresponding to the account registration institution identifier, so as to instruct the institutional server to decrypt the new encrypted information using the institutional private key, and after obtaining the payment information, perform asset deduction on the digital asset account based on the payment information.

[0037] This application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above payment method are implemented.

[0038] This application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above payment method are implemented.

[0039] This application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the above payment method are implemented.

[0040] The above payment method, device, computer device, storage medium, and computer program product receive the encrypted information, account registration institution identifier, and proxy key sent by the user terminal, making it impossible for the proxy server to decrypt the encrypted information, and thus the proxy server cannot obtain the plaintext payment information. Among them, the encrypted information is obtained by the user terminal encrypting the payment information using the user's public key, which can ensure that the proxy server does not know the payment information to avoid the leakage of payment information. Moreover, after the user terminal obtains the payment information including the digital asset account, it can directly determine the identifier of the account registration institution corresponding to the digital asset account, and this account registration institution identifier is the identifier of the account registration institution used to register the digital asset account. Subsequently, the user terminal can directly generate the corresponding proxy key using the user's public key and the institutional public key corresponding to the account registration institution identifier. The proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institutional server can decrypt by itself. After the proxy server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier, the institutional server can use the institutional private key to decrypt the new encrypted information by itself to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, during the entire payment process, the payment information is only known to the user terminal and the institutional server, effectively avoiding the leakage of payment information and improving the security of payment. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 It is an application environment diagram of the payment method in one embodiment;

[0042] Figure 2 It is an application environment diagram of the payment method in another embodiment;

[0043] Figure 3 It is a schematic flowchart of the payment method in one embodiment;

[0044] Figure 4 It is a schematic flowchart of the payment information generation step in one embodiment;

[0045] Figure 5 It is a schematic flowchart of the payment method in another embodiment;

[0046] Figure 6 It is a payment timing diagram in one embodiment;

[0047] Figure 7 It is a structural block diagram of a payment system in one embodiment;

[0048] Figure 8 It is a structural block diagram of a payment device in one embodiment;

[0049] Figure 9It is a structural block diagram of a payment device in another embodiment;

[0050] Figure 10 It is an internal structure diagram of a computer device in one embodiment. Detailed implementation manners

[0051] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0052] In the related art, after determining the payment information, the user terminal needs to use an aggregation payment platform (also called an agency platform) to forward the payment information to the account registration institution, so as to ensure that the institutional platform of the account registration institution completes the deduction based on the payment information. Among them, the information obtained by the aggregation payment platform can be the plaintext payment information or the encrypted information obtained by the user terminal encrypting the payment information with the user's private key. Since the user's public key is public, no matter what information the aggregation payment platform obtains, it can know the payment information. Therefore, in the whole payment process, the payment information is easily exposed in the aggregation payment platform, which is extremely likely to lead to the leakage and overuse of the payment information, and the privacy and security of the payment information cannot be ensured.

[0053] In the payment method provided in the embodiment of the present application, the user terminal obtains the payment information including the digital asset account. In this way, once a trigger operation for asset deduction based on the payment information is responded to, first, the encrypted information obtained by encrypting the payment information with the user's public key can be directly determined based on the obtained payment information. This encrypted information can ensure that the subsequent proxy server cannot obtain the plaintext payment information and avoid the leakage of the payment information. Secondly, based on the digital asset account, the corresponding account registration institution identifier can be quickly determined. Thus, the corresponding proxy key can be directly generated by using the user's public key and the institutional public key corresponding to the account registration institution identifier. After sending the encrypted information, the account registration institution identifier and the proxy key to the proxy server, the proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institutional server can decrypt by itself. During the process of the proxy server encrypting again, the payment information will not be exposed to the proxy server, ensuring the security of the payment information. Subsequently, after the proxy server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier, the institutional server can use the institutional private key to decrypt the new encrypted information by itself to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, in the whole payment process, the payment information is only known to the user terminal and the institutional server, effectively avoiding the leakage of the payment information and improving the security of the payment.

[0054] The payment method provided by the embodiments of this application can be applied to an application environment as Figure 1 shown. Among them, the user terminal 102 communicates with the proxy server 104 through the network, and the proxy server 104 communicates with the institutional server 106 through the network. The data storage system A can store the data that the proxy server 104 needs to process. The data storage system A can be integrated on the proxy server 104, or can be placed on the cloud or other servers. The data storage system B can store the data that the institutional server 106 needs to process. The data storage system B can be integrated on the institutional server 106, or can be placed on the cloud or other servers.

[0055] In some embodiments, the user terminal 102 obtains payment information, where the payment information includes a digital asset account; in response to a trigger operation for asset deduction based on the payment information, the user terminal 102 obtains encrypted information obtained by encrypting the payment information using the user's public key, the user terminal 102 obtains the account registration institution identifier corresponding to the digital asset account, and the user terminal 102 obtains a proxy key generated using the user's public key and the institutional public key corresponding to the account registration institution identifier; the user terminal 102 sends the encrypted information, the account registration institution identifier, and the proxy key to the proxy server 104, so as to instruct the proxy server 104 to encrypt the encrypted information using the proxy key, and after obtaining new encrypted information, the proxy server 104 forwards the new encrypted information to the institutional server 106 corresponding to the account registration institution identifier, so as to instruct the institutional server 106 to decrypt the new encrypted information using the institutional private key, and after obtaining the payment information, perform asset deduction on the digital asset account based on the payment information.

[0056] Among them, the user terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, etc. The proxy server 104 and the institutional server 106 are two different servers. The server can be an independent physical server, or can be a server cluster or distributed system composed of multiple physical servers, or can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0057] In some other instances, such as Figure 2As shown in the figure, it is an application environment diagram of a payment method in another embodiment. During the payment process, a third-party payment platform is also involved. The third-party payment platform is deployed on the payment server 206. Among them, the user terminal 202 communicates with the proxy server 204 through the network, the proxy server 204 communicates with the payment server 206 through the network, and the payment server 206 communicates with the institutional server 208 through the network.

[0058] After the user terminal 202 obtains the payment information including the digital asset account, in response to the trigger operation for asset deduction based on the payment information, the user terminal 202 obtains the encrypted information obtained by encrypting the payment information with the user's public key, the user terminal 202 obtains the account registration institution identifier corresponding to the digital asset account, and the user terminal 202 obtains the proxy key generated by using the user's public key and the institutional public key corresponding to the account registration institution identifier; the user terminal 202 sends the corresponding user terminal identifier, encrypted information, account registration institution identifier, and proxy key to the proxy server 204. The proxy server 204 encrypts the encrypted information with the proxy key to obtain new encrypted information. The proxy server 204 forwards the new encrypted information and the account registration institution identifier to the payment server 206. The payment server 206 forwards the new encrypted information to the institutional server 208 corresponding to the account registration institution identifier. After the institutional server 208 decrypts the new encrypted information with the institutional private key to obtain the payment information, it performs asset deduction on the digital asset account based on the payment information. After completing the deduction operation, the institutional server 208 returns the payment result to the payment server 206. The payment server 206 forwards the payment result to the proxy server 204. The proxy server 204 returns the payment result to the user terminal 202 corresponding to the user terminal identifier.

[0059] Thus, in Figure 2 the indicated communication link, during the entire payment process, the proxy server 204 and the payment server 206 at the intermediate nodes cannot obtain the plaintext payment information, ensuring the privacy and security of the payment information.

[0060] In one embodiment, as Figure 3 shown, a payment method is provided. Taking the user terminal 102 in Figure 1 as an example for illustration, it includes the following steps:

[0061] Step S302, obtain payment information, where the payment information includes a digital asset account.

[0062] Among them, the payment information is the information used for asset deduction. The payment information includes the digital asset account as the payer. In the embodiments of the present application, to ensure payment security, the payment information is the information to be encrypted. The digital asset account is the account of digital assets. Digital assets can be understood as electronic cash for electronic payment. The digital asset account can be understood as a cash wallet. Exemplarily, in addition to including the digital asset account as the payer, the payment information may further include the digital asset account as the payee, the payable amount, the order validity period, the order identifier, the order information, the product information, etc.

[0063] Optionally, when the user terminal performs online payment, determine the digital asset account for online payment, and based on this digital asset account, determine the payment information.

[0064] Exemplarily, the user terminal activates the target application. The target application is an application with a payment function. For example, a payment application, or an instant messaging application. The user terminal uses the target application to perform online payment, and determines the digital asset account for online payment from at least one digital asset account associated with the target application.

[0065] Exemplarily, when performing online payment, the user terminal responds to the selection operation of the digital asset account, and determines the selected digital asset account as the digital asset account for online payment. For example, after detecting the initiation of online payment, the user terminal selects the digital asset account with the largest balance according to the balances of each digital asset account as the digital asset account for online payment.

[0066] Optionally, the user terminal obtains the encryption items involved in the encryption protocol based on the pre-set encryption protocol. The user terminal obtains the information corresponding to the encryption items, and generates payment information based on the information corresponding to the encryption items and the digital asset account for online payment. The payment information includes the information corresponding to the encryption items. Among them, the encryption protocol defines the encryption items that can be encrypted together with the digital asset account. The encryption protocol contains at least one encryption item. The encryption item is an item related to the order, such as the amount to be paid, the order generation time, the product involved in the order, etc. The user terminal obtains the payable amount, payment time, and payment product corresponding to the online payment involved based on the encryption protocol, and generates payment information based on at least one of the payable amount, payment time, payment product, and the digital asset account for online payment.

[0067] Step S304, in response to the trigger operation for asset deduction based on the payment information, obtain the encrypted information obtained by encrypting the payment information with the user's public key, obtain the account registration institution identifier corresponding to the digital asset account, and obtain the proxy key generated by using the user's public key and the institutional public key corresponding to the account registration institution identifier.

[0068] Among them, asset deduction refers to the process of deducting a preset amount of digital assets from one digital asset account to another. The triggering operation refers to the operation that triggers the asset deduction, and its specific forms include but are not limited to touch operation, cursor operation, button operation, voice operation or biometric recognition operation.

[0069] In some embodiments, the user public key is the public key corresponding to the user. Different users (i.e., different accounts) have different corresponding key pairs, and the key pair includes a paired public key and private key. For example, User 1 can log in to his own account A on the user terminal. After the identity verification is passed, the user terminal logging in to account A can obtain the user public key of this User 1. Another example is that the user public key is the public key corresponding to the user terminal, and one user terminal corresponds to one user public key. For multiple different accounts allowed to log in to the user terminal, these accounts can share the user public key corresponding to the user terminal. For example, in some scenarios, due to security or system restrictions, only payment is allowed on a specific user terminal. Therefore, for multiple different accounts belonging to the same collective and having the permission to use the user terminal, after logging in to the user terminal, they can all obtain the user public key corresponding to the user terminal and use this user public key for payment.

[0070] The encrypted information refers to the encrypted information, which is obtained by encrypting the payment information using the user public key. Optionally, the encryption entity can be the user terminal or other devices. For example, other devices encrypt the payment information using the user public key to obtain the encrypted information, and then send the encrypted information to the user terminal.

[0071] The account registration institution identifier is used to mark the account registration institution. The account registration institution is the digital asset operation institution that registers digital asset accounts. The digital asset operation institution provides users with services for the circulation and exchange of digital assets. Usually, a user can register a digital asset account with a certain digital asset operation institution. The institution public key refers to the public key of the account registration institution. The proxy key is the key for the server to perform secondary encryption. In the payment scenario, the server can be the server deploying the aggregated payment platform (application). The user terminal can generate a proxy key based on the user public key and the institution public key of the account registration institution. It can be seen that for the same user, for the digital asset accounts registered by the user in different account registration institutions, the user terminal will generate different proxy keys. For example, there are 2 digital asset accounts bound to the user terminal logged in by User 1. Digital asset account 1 is registered with account registration institution 1, and digital asset account 2 is registered with account registration institution 2. For digital asset account 1, based on user public key 1 and institution public key 1 of account registration institution 1, proxy key 1 is generated. For digital asset account 2, based on user public key 1 and institution public key 2 of account registration institution 2, proxy key 2 is generated.

[0072] Optionally, in response to a confirmation operation on payment information, the user terminal obtains encrypted information of the payment information and queries the account registration institution identifier corresponding to the digital asset account. The user terminal obtains the institutional public key corresponding to the queried account registration institution identifier from the list of institutional public keys stored locally, and obtains the user public key and the proxy key corresponding to the institutional public key. The list of institutional public keys contains at least one institutional public key, and each of the included institutional public keys is the institutional public key corresponding to the digital asset account associated with the user terminal.

[0073] Exemplarily, after the user terminal activates the target application and obtains the input payment information through the target application, the user terminal obtains the user public key. In response to a trigger operation on the confirmation payment control in the target application, the user terminal encrypts the payment information using the user public key to obtain encrypted information, queries the account registration institution identifier corresponding to the digital asset account in the payment information, obtains the institutional public key corresponding to the account registration institution identifier, and generates a proxy key using the user public key and the institutional public key. That is, after the asset deduction is confirmed, the encrypted information and the proxy key are generated. In this way, in the case where the user temporarily cancels the payment or changes the digital asset account, the encrypted information will not be regenerated repeatedly, and the proxy key will not be generated multiple times, ensuring the payment efficiency.

[0074] Step S306: Send the encrypted information, the account registration institution identifier, and the proxy key to the proxy server, instructing the proxy server to encrypt the encrypted information using the proxy key to obtain new encrypted information, and then forward the new encrypted information to the institutional server corresponding to the account registration institution identifier, instructing the institutional server to decrypt the new encrypted information using the institutional private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

[0075] Among them, the proxy server can be an integrated payment platform that aggregates multiple payment methods. The server corresponding to the above-mentioned target application can be regarded as a payment server.

[0076] The institutional server is a server different from the proxy server. The institutional server refers to the server corresponding to the account registration institution, which is used to store the data of the account registration institution and execute the business of the account registration institution, etc. Different account registration institutions correspond to different institutional servers.

[0077] The new encrypted information is different from the above-mentioned encrypted information. The above-mentioned encrypted information is encrypted using the user public key, and neither the proxy server nor the institutional server can decrypt it. The new encrypted information is encrypted using the user public key and the proxy key corresponding to the institutional public key. The proxy server cannot decrypt it, and it supports the institutional server to decrypt the new encrypted information using its own institutional private key.

[0078] Optionally, the user terminal sends the encrypted information, the account registration institution identifier, and the proxy key to the proxy server. The proxy server uses the received proxy key to re-encrypt the received encrypted information to obtain new encrypted information. The proxy server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier, and the institutional server uses its own institutional private key to decrypt the received new encrypted information to obtain payment information and parse the payment information. If the payment information includes a digital asset account, the institutional server performs asset deduction based on the parsed digital asset account.

[0079] Exemplarily, when the user terminal obtains the payment information, it also obtains merchant information, and sends the user terminal identifier, the above-mentioned encrypted information, the account registration institution identifier, the proxy key, and the merchant information to the proxy server. The proxy server queries the merchant digital asset account according to the merchant information, and uses the proxy key to re-encrypt the received encrypted information to obtain new encrypted information.

[0080] At this time, payment can be made through the following two payment methods:

[0081] The first method: The proxy server sends the merchant digital asset account and the new encrypted information to the institutional server where the account registration institution identifier is located. The institutional server uses its own institutional key to decrypt the new encrypted information to obtain payment information, parses the payment information to obtain the digital asset account and the amount to be paid, and deducts the digital asset of the amount to be paid from the parsed digital asset account to the merchant digital asset account.

[0082] The second method: The proxy server sends the new encrypted information to the institutional server where the account registration institution identifier is located. The institutional server uses its own institutional key to decrypt the new encrypted information to obtain payment information, parses the payment information to obtain the digital asset account and the amount to be paid. The institutional server deducts the digital asset of the amount to be paid from the obtained digital asset account to the digital asset account of the payment server, and returns a payment success result to the proxy server. The proxy server sends a request containing the merchant digital asset account to the payment server. After obtaining the request, the payment server deducts the digital asset of the amount to be paid from the digital asset account of the payment server to the merchant digital asset account..

[0083] In the above payment method, payment information including a digital asset account is obtained through a user terminal. In this way, once a trigger operation for asset deduction based on the payment information is responded to, first, based on the obtained payment information, the encrypted information obtained by encrypting the payment information using the user's public key can be directly determined. This encrypted information can ensure that the subsequent proxy server cannot obtain the plaintext payment information, avoiding the leakage of payment information. Second, based on the digital asset account, the corresponding account registration institution identifier can be quickly determined. Thus, the corresponding proxy key can be directly generated using the user's public key and the institutional public key corresponding to the account registration institution identifier. After sending the encrypted information, the account registration institution identifier, and the proxy key to the proxy server, the proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institutional server can decrypt by itself. During the process of the proxy server encrypting again, the payment information is not exposed to the proxy server, ensuring the security of the payment information. Subsequently, after the proxy server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier, the institutional server can use its institutional private key to decrypt the new encrypted information by itself to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, during the entire payment process, the payment information is only known to the user terminal and the institutional server, effectively avoiding the leakage of payment information and improving the security of payment.

[0084] In some embodiments, obtaining payment information includes: after collecting the payment code provided by the merchant, displaying a payment interface, where the payment interface includes payment method options corresponding to various different payment methods; in response to the selection of the digital asset account payment method option, displaying multiple digital asset accounts of the user; and in response to the selection of a target digital asset account among the multiple digital asset accounts, generating payment information according to the target digital asset account.

[0085] Among them, the payment code is a graphic code for online payment, which supports selecting one payment method from various different payment methods for payment, and this image code contains merchant information. The payment method refers to the method of online payment. The digital asset account payment method refers to the payment method of deducting digital assets using a digital asset account. The payment method also includes non-digital asset account payment methods, that is, payment methods that do not use a digital asset account for deduction.

[0086] Optionally, when the user account logs in to the target application on the user terminal, scan the payment code through the target application to display the payment interface, which includes a payment method selection area. The payment method selection area includes payment method options corresponding to multiple different payment methods. In response to the selection operation for the digital asset account payment method in the payment method selection area, multiple digital asset accounts associated with the user account are displayed in the payment method selection area. In response to the selection operation of selecting the target digital asset from multiple digital asset accounts, payment information is generated based on the target digital asset.

[0087] In this embodiment, by collecting the payment code provided by the merchant, the payment interface is displayed, and the payment interface includes payment method options corresponding to multiple different payment methods. Thus, multiple payment methods are provided for the user, improving the payment convenience. In response to the selection of the digital asset account payment method option, it is determined to use the digital asset account for payment, and multiple digital asset accounts of the user are displayed. In response to the selection of the target digital asset account among multiple digital asset accounts, corresponding payment information is automatically generated based on the target digital asset account. Subsequently, based on the payment information including the target digital asset account, the deduction of digital assets can be performed, realizing the payment of digital assets.

[0088] In some embodiments, as Figure 4 shown, it is a schematic flowchart of the payment information generation step in an embodiment. Obtaining payment information includes:

[0089] Step S402, obtain the digital asset account for paying the target order.

[0090] Among them, the target order is the order to be paid, and the digital asset account is the account used to pay the target order.

[0091] Exemplarily, in an online interaction scenario, the user terminal displays the payment interface for the target order, and the payment interface includes the digital asset account method option. In response to the selection operation for the digital asset account method option, multiple digital asset accounts of the user are displayed on the payment interface. In response to the selection operation of selecting one digital asset account from multiple digital asset accounts, the selected digital asset account is determined as the digital asset account for paying the target order.

[0092] Step S404, obtain the order information of the target order, and the order information includes at least the order number, commodity information, and the amount to be paid.

[0093] Among them, the order information includes the commodity information (i.e., product information) of at least one commodity, and the commodity information includes at least the commodity type, commodity quantity, and commodity unit price.

[0094] Exemplarily, in response to a confirmation operation for interacting with at least one commodity, the user terminal obtains the commodity information of at least one commodity, calculates the payable amount corresponding to at least one commodity, generates an order number corresponding to the confirmation operation, and the user terminal determines the order information of the target order based on the commodity information, payable amount, and order number of at least one commodity.

[0095] Step S406: According to the order information, display an independent encryption option interface, which at least includes encryption options corresponding to the order number, commodity information, and payable amount.

[0096] Among them, the independent encryption option interface is for the user to independently select the options that need to be encrypted. In this embodiment, in addition to the payment information that needs to be encrypted, the user can choose to encrypt some or all of the order information according to their own wishes.

[0097] Exemplarily, after the user terminal determines the order information, the user terminal identifies the information items in the order information, determines the identified information items as encryption options related to the order information, and displays an independent encryption option interface that shows the encryption options related to the order information. The information items can be the order number, commodity information, payable amount, etc.

[0098] In another example, the encryption options can be pre-set when downloading the client. That is, when the user installs the client, the user selects at least one encryption option that needs to be encrypted. Thus, each time when interacting with the client, after determining the digital asset account for paying the target order, the pre-set at least one encryption option is automatically obtained. The user terminal generates payment information according to the at least one encryption option and the digital asset account, so that the user does not need to re-select the encryption options every time they place an order.

[0099] Step S408: Obtain the selection operation of the encryption option corresponding to the payable amount in the independent encryption option interface, and generate payment information according to the digital asset account and the payable amount.

[0100] Of course, in another example, after executing step S406, it further includes: in response to the selection operation of at least one encryption option in the independent encryption option interface, the user terminal obtains the selected at least one encryption option, and generates payment information according to the selected at least one encryption option and the digital asset account. In this way, through the encryption items independently selected by the user, the user's consumption habits can be effectively prevented from being leaked, ensuring the privacy and security of the user.

[0101] In this embodiment, after obtaining the digital asset account for paying the target order, the order information of the target order is further obtained. The order information at least includes the order number, commodity information, and the payable amount. According to the order information, an independent encryption option interface is displayed, and the independent encryption option interface at least includes the encryption options corresponding to the order number, commodity information, and the payable amount. That is, based on the encryption options, the user can independently select the information that does not want to be collected by the aggregated payment platform, improving the user experience. At this time, the selection operation of the encryption option corresponding to the payable amount in the independent encryption option interface is obtained, and payment information is generated according to the digital asset account and the payable amount. In this way, not only the user's digital asset account is effectively protected, but also the payable amount for each payment can be prevented from being leaked, protecting the user's privacy and security.

[0102] In some embodiments, after obtaining the payment information, the method further includes: obtaining the user public key, where the user public key is generated by a random number generated by a random generation program, and the user public key corresponds to the digital asset account; encrypting the payment information with the user public key to obtain encrypted information.

[0103] Among them, the random number refers to a digital sequence with randomness, and the random number generation program is a program for generating random numbers. For each user account, if a digital asset account is associated, the digital asset account corresponds to the corresponding user public key. If multiple digital asset accounts are associated, the user public key can correspond to multiple digital asset accounts, without limitation.

[0104] Optionally, when the user account logs in to the user terminal, the user terminal obtains the user public key from other devices and stores it locally, and the user public key is generated by other devices. Of course, the user public key can also be generated by the user terminal.

[0105] After obtaining the user public key, the user terminal encrypts the plaintext payment information with the user public key to obtain encrypted information.

[0106] Taking the example of the user terminal generating the user public key, the user terminal obtains the pre-set elliptic curve, obtains the coordinates of the base point on the elliptic curve, randomly generates a random number by the random generation program, and multiplies the random number by the abscissa and ordinate of the base point respectively to obtain the coordinates of another point, and the coordinates of the another point are the user public key, and the random number is the corresponding user private key.

[0107] In this embodiment, after the user terminal obtains the payment information, it continues to obtain the user public key. The user public key is generated using a random number generated by a random generation program, ensuring the randomness of the encrypted information. The user public key corresponds to the digital asset account. Then, the payment information is encrypted using the user public key to obtain the encrypted information. In this way, the proxy server cannot decrypt the encrypted information, ensuring the security of the payment information during the payment process.

[0108] In some embodiments, the method further includes: registering a digital asset account with the institution server; after successful registration, obtaining the institution public key from the institution server; storing the account registration institution identifier corresponding to the digital asset account in correspondence with the institution public key; generating a proxy key according to the user public key and the institution public key; and storing the account registration institution identifier in correspondence with the proxy key.

[0109] Optionally, during the process of registering a digital asset account with the institution server, after the user terminal determines successful registration, it obtains the institution public key from the institution server and stores the account registration institution identifier corresponding to the digital asset account in correspondence with the institution public key. After the user terminal determines the digital asset account for payment, it obtains the account registration institution identifier corresponding to the digital asset account and obtains the institution public key corresponding to the account registration institution identifier from local storage. The user terminal generates a proxy key according to the user public key and the institution public key and stores the account registration institution identifier in correspondence with the proxy key.

[0110] In some embodiments, generating a proxy key according to the user public key and the institution public key includes: in response to a trigger operation for asset deduction based on the payment information, obtaining a common parameter shared between the user terminal and the institution server corresponding to the account registration institution, and generating a proxy key according to the user public key, the institution public key, and the common parameter.

[0111] The common parameter refers to a parameter shared between the user terminal and the institution server corresponding to the account registration institution. Exemplarily, the common parameter can be the user terminal identifier, or the account registration institution identifier, or the institution server identifier, and is not specifically limited. Exemplarily, the user terminal sends a key generation request for generating a proxy key to the corresponding institution server, and the institution server, in response to the key generation request, randomly generates a parameter and sends the parameter to the user terminal, and the parameter is the common parameter.

[0112] Optionally, in response to a triggering operation for asset deduction based on payment information, the user terminal obtains the common parameters corresponding to the institutional server corresponding to the account registration institution of the user terminal, obtains the random number used in the process of generating the user public key, and uses a key derivation function to generate a first intermediate key based on the random number and the user public key, and performs a hash calculation on the common parameters to obtain a hash value. The user terminal generates a second intermediate key based on the hash value, the account registration institution identifier, and the random number according to the key derivation function, and generates a proxy key based on the first intermediate key and the second intermediate key.

[0113] Exemplarily, after determining the first intermediate key and the second intermediate key, an exclusive OR operation is performed on the first intermediate key and the second intermediate key to obtain a proxy key.

[0114] Thus, after responding to the triggering operation for asset deduction based on payment information, it is confirmed that asset deduction is performed using the digital asset account in the payment information. At this time, the common parameters shared between the user terminal and the institutional server corresponding to the account registration institution are obtained, and a proxy key is generated based on the user public key, the institutional public key, and the common parameters. Since this proxy key cannot decrypt the encrypted information, the subsequent proxy server cannot decrypt the encrypted information when obtaining the encrypted information, improving the security of the payment.

[0115] In this embodiment, first, a digital asset account is registered with the institutional server. After successful registration, the institutional public key is obtained from the institutional server. At this time, the account registration institution identifier corresponding to the digital asset account is stored corresponding to the institutional public key, so that the user terminal can directly query the institutional public key corresponding to the digital asset account quickly according to the corresponding storage relationship. Then, a proxy key is generated based on the user public key and the institutional public key. Finally, by storing the account registration institution identifier corresponding to the proxy key, it is convenient to send the corresponding proxy key to the proxy server subsequently. The proxy server generates new encrypted information that the corresponding institutional server can decrypt itself based on the proxy key, ensuring the security of the payment information.

[0116] In some embodiments, the common parameter is a static common parameter, and the static common parameter is the account registration institution identifier; generating a proxy key based on the user public key, the institutional public key, and the common parameter includes: generating a proxy key based on the user public key, the institutional public key, and the account registration institution identifier.

[0117] Among them, the static common parameter is an inherent parameter, that is, when using the same digital asset account for multiple payments, the common parameter for each payment is the same, and the proxy key generated each time is the same. Therefore, when the user account logs in to the user terminal, after the user account first uses the digital asset account 1 for asset deduction, where the digital asset account 1 corresponds to the account registration institution identifier 1, at this time, the user terminal stores the generated proxy key 1, the user account, and the account registration institution identifier 1 correspondingly. When the user account uses the digital asset account 1 again, it directly obtains the corresponding proxy key 1 from the pre-stored information without regenerating it.

[0118] In some other embodiments, when the user account logs in to the user terminal, the static common parameter can also be the user account.

[0119] After determining the static common parameter, the steps of obtaining the random number used in the process of generating the user public key in the above embodiments can be returned to continue execution. After executing to the first intermediate key generation step, a hash calculation is performed on the account registration institution identifier to obtain the corresponding hash value. The user terminal generates a second intermediate key according to the key derivation function based on the hash value, the account registration institution identifier, and the random number, and generates a proxy key according to the first intermediate key and the second intermediate key.

[0120] In this embodiment, when the common parameter is a static parameter and the static common parameter is the account registration institution identifier, a proxy key is generated according to the user public key, the institution public key, and the account registration institution identifier. In this way, when using the same digital asset account again later, there is no need to generate the proxy key again, which improves the payment efficiency. Moreover, the proxy key can generate new encrypted information that can be self-decrypted by the corresponding institution server, ensuring the security of payment information.

[0121] In some embodiments, the common parameter is a dynamic common parameter, and the dynamic common parameter is a random verification code; obtaining the common parameter shared between the user terminal and the institution server corresponding to the account registration institution includes: generating a random verification code in response to a trigger operation for asset deduction based on payment information.

[0122] Among them, the dynamic common parameter refers to a parameter that changes dynamically, and the random verification code refers to a randomly generated string. Each time a payment is made, a random verification code will be randomly generated. For example, it is randomly generated using a random number generation program.

[0123] Exemplarily, in response to a triggering operation for asset deduction based on payment information, the user terminal generates a random verification code and sends it to the institutional server corresponding to the digital asset account. In some other examples, in response to a triggering operation for asset deduction based on payment information, the user terminal sends a key generation request for generating a proxy key to the corresponding institutional server. In response to the key generation request, the institutional server uses a random number generator program to randomly generate a random number, and uses this random number as the random verification code, or sends verification code information to the user terminal, where the verification code information includes a verification code randomly generated by the institutional server.

[0124] In some embodiments, generating a proxy key based on the user public key, the institutional public key, and the common parameters includes: generating a proxy key based on the user public key, the institutional public key, and the random verification code.

[0125] After determining that the public key parameter is the random verification code, the steps of obtaining the random number used in the process of generating the user public key in the above embodiments can be returned and continued to be executed. After executing to the first intermediate key generation step, a hash calculation is performed on the random verification code to obtain the corresponding hash value. The user terminal generates a second intermediate key according to the key derivation function, based on the hash value, the account registration institution identifier, and the random number, and generates a proxy key according to the first intermediate key and the second intermediate key.

[0126] Thus, in each payment process, a corresponding random verification code is dynamically generated, which improves the randomness of the generated proxy key, and further ensures the security of payment information.

[0127] In this embodiment, when the common parameter is a dynamic common parameter and the dynamic common parameter is the random verification code, once a triggering operation for asset deduction based on payment information is responded to, a random verification code is randomly generated. In this way, based on the randomly generated random verification code, the randomness of the proxy key is ensured, and further, the security of payment information is ensured.

[0128] In some embodiments, decrypting the new encrypted information using the institutional private key to obtain the payment information includes: decrypting the new encrypted information using the institutional private key to obtain the decrypted information; if it is verified that the new encrypted information has not been tampered with, the decrypted information is determined as the payment information.

[0129] It should be noted that the encrypted information includes four parts, namely the first encrypted ciphertext, the second encrypted ciphertext, the third encrypted ciphertext, and the fourth encrypted ciphertext. Among them, the first encrypted ciphertext is used to verify whether the public key and the private key match, that is, whether the public key and the private key belong to the same key pair, thereby ensuring the security and correctness of encryption. For example, it is used to verify whether the institutional public key and the institutional private key match. The second encrypted ciphertext is used to store payment information. The third encrypted ciphertext and the fourth encrypted ciphertext are used to verify whether the new encrypted information has been tampered with.

[0130] The generation steps of the new encrypted information include: the proxy server encrypts the second encrypted ciphertext using the proxy key pair to obtain the second intermediate ciphertext, and takes the first encrypted ciphertext as the first intermediate ciphertext, the third encrypted ciphertext as the third intermediate ciphertext, and the fourth encrypted ciphertext as the fourth intermediate ciphertext. Thus, the proxy server sequentially splices the first intermediate ciphertext, the third intermediate ciphertext, the fourth intermediate ciphertext, and the second intermediate ciphertext to obtain the new encrypted information.

[0131] Exemplarily, the institutional server extracts the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information, and uses the first intermediate ciphertext to verify whether the institutional public key and the institutional private key match. If they match, the decryption information is obtained based on the first intermediate ciphertext and the second intermediate ciphertext. The institutional server extracts the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information. If the institutional server verifies that the new encrypted information has not been tampered with based on the third intermediate ciphertext and the fourth intermediate ciphertext, the decryption information is determined as the payment information. If the institutional server verifies that the new encrypted information has been tampered with based on the third intermediate ciphertext and the fourth intermediate ciphertext, it returns a payment failure result to the proxy server, and the proxy server forwards the payment result failure to the user terminal.

[0132] In this embodiment, after obtaining the new encrypted information, the institutional server can directly decrypt the new encrypted information using the institutional private key to obtain the decryption information. Further, after verifying that the new encrypted information has not been tampered with, the decryption information is determined as the payment information, and asset deduction is performed based on the payment information, ensuring the legality and accuracy of the payment.

[0133] In some embodiments, the new encrypted information is formed by splicing the first intermediate ciphertext, the third intermediate ciphertext, the fourth intermediate ciphertext, and the second intermediate ciphertext; decrypting the new encrypted information using the institutional private key to obtain the decryption information includes: extracting the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information; decrypting according to the institutional private key, the common parameters, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain the decryption information.

[0134] Optionally, the institution server extracts the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information. When it is verified that the institution public key and the institution private key match using the first intermediate ciphertext, the institution server uses a key derivation function to determine a derived result based on the first intermediate ciphertext, the institution private key, and the public key parameter, and obtains the decrypted information according to the derived result and the second intermediate ciphertext.

[0135] Exemplarily, the steps for determining the derived result include: The institution server calculates the first product of the first intermediate ciphertext and the institution private key, calculates the hash value of the common parameter, calculates the second product between the first product and the hash value, and inputs the second product into the key derivation function to obtain the derived result.

[0136] The steps for determining the decrypted information include: The institution server performs an exclusive OR operation on the derived result and the second intermediate ciphertext to obtain the decrypted information.

[0137] In this embodiment, since the new ciphertext information is composed of the first intermediate ciphertext, the third intermediate ciphertext, the fourth intermediate ciphertext, and the second intermediate ciphertext, thus, the first intermediate ciphertext and the second intermediate ciphertext can be extracted from the new encrypted information. However, the decrypted information is obtained by decrypting according to the institution private key, the common parameter, the extracted first intermediate ciphertext, and the second intermediate ciphertext. That is to say, the institution server can decrypt by itself based on the institution private key, improving the decryption efficiency.

[0138] In some embodiments, the method further includes: extracting the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information; obtaining a hash value through hash calculation according to the first intermediate ciphertext, the decrypted information, and the extracted third intermediate ciphertext; if the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0139] Exemplarily, after obtaining the decrypted information, the institution server sequentially concatenates the first intermediate ciphertext, the decrypted information, and the third intermediate ciphertext to obtain a concatenated ciphertext. The institution server calculates the hash value of the concatenated ciphertext. If the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0140] In this embodiment, the third intermediate ciphertext and the fourth intermediate ciphertext are extracted from the new encrypted information. Then, based on the first intermediate ciphertext, the decryption information, and the extracted third intermediate ciphertext, a hash value is obtained through hash calculation. By comparing the hash value with the fourth intermediate ciphertext, it is possible to effectively identify whether the new encrypted information has been tampered with. If the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with. Thus, the effectiveness of the payment process is ensured.

[0141] In one embodiment, a payment method is provided. Taking the application of this method to the user terminal 102 as an example, it includes: obtaining the amount to be paid; in response to a trigger operation for asset deduction based on the amount to be paid using the digital asset account, obtaining the encrypted account obtained by encrypting the digital asset account using the user's public key, obtaining the account registration institution identifier corresponding to the digital asset account, and obtaining the proxy key generated using the user's public key and the institutional public key corresponding to the account registration institution identifier; sending the amount to be paid, the encrypted account, the account registration institution identifier, and the proxy key to the proxy server to instruct the proxy server to encrypt the encrypted account using the proxy key, and after obtaining the new encrypted account, forwarding the new encrypted account and the amount to be paid to the institutional server corresponding to the account registration institution identifier to instruct the institutional server to decrypt the new encrypted account using the institutional private key, and after obtaining the digital asset account, performing asset deduction on the digital asset account based on the amount to be paid.

[0142] Among them, the steps for obtaining the encrypted account, the steps for obtaining the new encrypted account, and the steps for decrypting the new encrypted account in this embodiment can respectively refer to the steps for obtaining the encrypted information, the steps for obtaining the new encrypted information, and the steps for decrypting the new encrypted information in the previous text.

[0143] In this embodiment, after obtaining the payable amount, in response to a trigger operation for asset deduction based on the payable amount using the digital asset account, an encrypted account obtained by encrypting the digital asset account with the user's public key is acquired, so that the proxy server cannot obtain the plaintext digital asset account, ensuring the security of the digital asset account. Then, the account registration institution identifier corresponding to the digital asset account is obtained, and a proxy key generated using the user's public key and the institutional public key corresponding to the account registration institution identifier is obtained; the payable amount, the encrypted account, the account registration institution identifier, and the proxy key are sent to the proxy server. The proxy server does not know the digital asset account to avoid the leakage of the digital asset account. Moreover, the proxy server encrypts the encrypted account with the proxy key to obtain a new encrypted account, and then forwards the new encrypted account and the payable amount to the institutional server corresponding to the account registration institution identifier. In this way, the institutional server decrypts the new encrypted account by itself using the institutional private key to obtain the digital asset account. Finally, asset deduction is performed on the digital asset account based on the payable amount. Therefore, during the entire payment process, the digital asset account is only known to the user terminal and the institutional server, effectively avoiding the leakage of the digital asset account and improving the security of the payment.

[0144] In one embodiment, as Figure 5 shown, a payment method is provided. Taking the method applied to Figure 1 the proxy server 104 as an example, it includes the following steps:

[0145] Step S502: Receive the encrypted information, the account registration institution identifier, and the proxy key sent by the user terminal. The encrypted information is obtained by encrypting the payment information with the user's public key. The payment information includes the digital asset account. The account registration institution identifier is the identifier of the account registration institution used to register the digital asset account, and the proxy key is generated using the user's public key and the institutional public key corresponding to the account registration institution identifier.

[0146] Optionally, the payment information acquisition step includes: after the user terminal collects the payment code provided by the merchant, a payment interface is displayed. The payment interface includes payment method options corresponding to various different payment methods; in response to the selection of the digital asset account payment method option, multiple digital asset accounts of the user are displayed; in response to the selection of the target digital asset account among the multiple digital asset accounts, payment information is generated according to the target digital asset account.

[0147] Optionally, the payment information acquisition step includes: the user terminal acquires a digital asset account for paying the target order; acquires the order information of the target order, where the order information at least includes an order number, product information, and the amount to be paid; the user terminal displays an independent encryption option interface according to the order information, and the independent encryption option interface at least includes encryption options corresponding to the order number, product information, and the amount to be paid; the user terminal acquires a selection operation for the encryption option corresponding to the amount to be paid in the independent encryption option interface, and generates payment information according to the digital asset account and the amount to be paid.

[0148] Optionally, the encryption information acquisition step includes: the user terminal acquires a user public key, where the user public key is generated by a random number generated by a random generation program, and the user public key corresponds to the digital asset account; the user terminal encrypts the payment information using the user public key to obtain encrypted information.

[0149] Optionally, the proxy key acquisition step includes: the user terminal registers a digital asset account with the institutional server; after successful registration, acquires the institutional public key from the institutional server; stores the account registration institution identifier corresponding to the digital asset account in correspondence with the institutional public key; the user terminal generates a proxy key according to the user public key and the institutional public key; stores the account registration institution identifier in correspondence with the proxy key.

[0150] Exemplarily, the step of generating a proxy key according to the user public key and the institutional public key includes: in response to a trigger operation for asset deduction based on the payment information, the user terminal acquires a common parameter shared between the user terminal and the institutional server corresponding to the account registration institution, and generates a proxy key according to the user public key, the institutional public key, and the common parameter.

[0151] For example, the common parameter is a static common parameter, and the static common parameter is the account registration institution identifier; the user terminal generates a proxy key according to the user public key, the institutional public key, and the account registration institution identifier.

[0152] Another example is that the common parameter is a dynamic common parameter, and the dynamic common parameter is a random verification code. In response to a trigger operation for asset deduction based on the payment information, the user terminal generates a random verification code and sends it to the institutional server, and generates a proxy key according to the user public key, the institutional public key, and the random verification code.

[0153] Step S504, after encrypting the encrypted information using the proxy key to obtain new encrypted information, forward the new encrypted information to the institutional server corresponding to the account registration institution identifier, so as to instruct the institutional server to decrypt the new encrypted information using the institutional private key, obtain the payment information, and perform asset deduction on the digital asset account based on the payment information.

[0154] Optionally, the proxy server encrypts the second encrypted ciphertext in the encrypted information using the proxy key to obtain a second intermediate ciphertext. The proxy server uses the first encrypted ciphertext as the first intermediate ciphertext, the third encrypted ciphertext as the third intermediate ciphertext, and the fourth encrypted ciphertext as the fourth intermediate ciphertext. Thus, the proxy server sequentially splices the first intermediate ciphertext, the third intermediate ciphertext, the fourth intermediate ciphertext, and the second intermediate ciphertext to obtain new encrypted information.

[0155] Optionally, the steps for the institution server to obtain the payment information include: the institution server decrypts the new encrypted information using the institution private key to obtain decrypted information; if it is verified that the new encrypted information has not been tampered with, the decrypted information is determined as the payment information.

[0156] Exemplarily, the institution server extracts the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information; the institution server decrypts according to the institution private key, the common parameters, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain decrypted information.

[0157] Extract the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information; calculate the hash value through hash calculation based on the first intermediate ciphertext, the decrypted information, and the extracted third intermediate ciphertext; if the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0158] In the above payment method, by receiving the encrypted information, the account registration institution identifier, and the proxy key sent by the user terminal, the proxy server cannot decrypt the encrypted information, and thus the proxy server cannot obtain the plaintext payment information. Among them, the encrypted information is encrypted by the user terminal using the user public key, which can ensure that the proxy server does not know the payment information to avoid the leakage of payment information. Moreover, after the user terminal obtains the payment information including the digital asset account, it can directly determine the identifier of the account registration institution corresponding to the digital asset account, and this account registration institution identifier is the identifier of the account registration institution used to register the digital asset account. Subsequently, the user terminal can directly generate the corresponding proxy key using the user public key and the institution public key corresponding to the account registration institution identifier. The proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institution server can decrypt by itself. After the proxy server forwards the new encrypted information to the institution server corresponding to the account registration institution identifier, the institution server can decrypt the new encrypted information by itself using the institution private key to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, during the entire payment process, only the user terminal and the institution server know the payment information, effectively avoiding the leakage of payment information and improving the security of payment.

[0159] The present application also provides an application scenario, which applies the above payment method. Specifically, the application of the payment method in this application scenario is as follows: In an online payment scenario, in the e-commerce client of the user terminal, log in to the e-merchant client with a target account. The e-merchant client supports aggregated payment and deploys multiple payment methods, including a digital asset account payment method. After responding to the selection operation of the digital asset account payment method, determine the digital asset account for payment and determine the payment information based on the digital asset account. During this process, to ensure that the payment information is not leaked, the payment method provided in the embodiments of the present application can be used to deduct digital assets. Specifically, the user terminal obtains payment information, and the payment information includes a digital asset account; in response to the trigger operation for asset deduction based on the payment information, the user terminal obtains the encrypted information obtained by encrypting the payment information with the user's public key, obtains the account registration institution identifier corresponding to the digital asset account, and the user terminal obtains the proxy key user terminal generated by using the user's public key and the institutional public key corresponding to the account registration institution identifier; send the encrypted information, the account registration institution identifier, and the proxy key to the proxy server. The proxy server encrypts the encrypted information with the proxy key, and after obtaining the new encrypted information, forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier. The institutional server decrypts the new encrypted information with the institutional private key, obtains the payment information, and then deducts the digital assets from the digital asset account based on the payment information.

[0160] Of course, it is not limited to this. The payment method provided by the present application can also be applied in other application scenarios. For example, in an offline payment scenario, when the user pays in a physical store, the physical store provides a payment code for aggregated payment. At this time, when the user terminal logs in to the user account, the user terminal obtains the payment information by scanning the payment code. At this time, the safe and convenient asset deduction can also be realized through the payment method of the embodiments of the present application.

[0161] The above application scenarios are only illustrative descriptions. It can be understood that the application of the payment method provided by the embodiments of the present application is not limited to the above scenarios.

[0162] In a specific embodiment, this embodiment involves a process of multi-party interaction, such as Figure 6 shown, which is a payment timing diagram in an embodiment. Combining the foregoing Figure 2The application scenarios are described, specifically involving user terminals, proxy servers, payment servers, and institutional servers. It should be noted that the target application is configured in the user terminal, and the target application can be a payment application. The corresponding payment server is the server corresponding to the payment application. The proxy server is configured with an aggregated payment application that aggregates multiple payment methods. The institutional server is the server corresponding to the account registration institution. The proxy server, payment server, and institutional server are all different servers. The specific steps are as follows:

[0163] Step S601: The user terminal obtains payment information including the target digital asset account.

[0164] Optionally, when the user terminal logs in with the target account, the user terminal initiates the target payment for payment. After collecting the payment code provided by the merchant, a payment interface is displayed. The payment interface includes payment method options corresponding to multiple different payment methods. In response to the selection of the digital asset account payment method option, multiple digital asset accounts of the user are displayed. In response to the selection of the target digital asset account among the multiple digital asset accounts, payment information is generated based on the target digital asset account.

[0165] Optionally, after the user terminal launches the e-commerce client, in response to the confirmation operation for at least one item, the target order is determined. The user terminal obtains the digital asset account used to pay the target order; obtains the order information of the target order, and the order information at least includes the order number, item information, and the amount to be paid; according to the order information, an independent encryption option interface is displayed, and the independent encryption option interface at least includes encryption options corresponding to the order number, item information, and the amount to be paid; obtains the selection operation of the encryption option corresponding to the amount to be paid in the independent encryption option interface, and generates payment information based on the digital asset account and the amount to be paid.

[0166] Before obtaining the payment information, the steps also include: registering the digital asset account with the institutional server; after successful registration, the user terminal obtains the institutional public key from the institutional server and stores the account registration institution identifier corresponding to the digital asset account in correspondence with the institutional public key.

[0167] Step S602: The user terminal encrypts the payment information using the user's public key to obtain encrypted information.

[0168] Exemplarily, the user terminal obtains the user's public key, which is generated by a random number generated by a random generation program. The user's public key corresponds to the digital asset account; the payment information is encrypted using the user's public key to obtain encrypted information.

[0169] Step S603: The user terminal obtains the account registration institution identifier corresponding to the target digital asset account, and generates a corresponding proxy key based on the institutional public key corresponding to the account registration institution identifier and the user's public key.

[0170] Exemplarily, in response to a trigger operation for asset deduction based on payment information, common parameters shared between the user terminal and the institutional server corresponding to the account registration institution are obtained. The common parameters can be one of static common parameters and dynamic common parameters. The static common parameter is the account registration institution identifier, and the dynamic common parameter is a random verification code. If the common parameter is a static common parameter and is the account registration institution identifier, the user terminal generates a proxy key according to the user public key, the institutional public key, and the account registration institution identifier. If the common parameter is a dynamic common parameter and is a dynamic verification code, the user terminal generates a proxy key according to the user public key, the institutional public key, and the random verification code. Among them, before generating the proxy key, in response to the trigger operation for asset deduction based on payment information, a random verification code is generated.

[0171] Exemplarily, after the user terminal generates the proxy key, the account registration institution identifier and the proxy key are stored in a corresponding manner.

[0172] Step S604: The user terminal sends the encrypted information, the proxy key, and the account registration institution identifier to the proxy server.

[0173] Exemplarily, the user terminal simultaneously sends the user terminal identifier, the encrypted information, the proxy key, the account registration institution identifier, and the payment server identifier corresponding to the payment application to the proxy server.

[0174] Step S605: The proxy server re-encrypts the encrypted information with the proxy key to obtain new encrypted information.

[0175] Step S606: The proxy server forwards the new encrypted information and the account registration institution identifier to the payment server corresponding to the payment server identifier.

[0176] Step S607: The payment server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier.

[0177] Step S608: The institutional server decrypts the new encrypted information with the institutional private key to obtain the payment information.

[0178] Exemplarily, the new encrypted information is formed by splicing the first intermediate ciphertext, the third intermediate ciphertext, the fourth intermediate ciphertext, and the second intermediate ciphertext. Thus, the institutional server extracts the first intermediate ciphertext, the second intermediate ciphertext, the third intermediate ciphertext, and the fourth intermediate ciphertext from the new encrypted information. The institutional server decrypts according to the institutional private key, the common parameters, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain the decrypted information.

[0179] The institutional server calculates a hash value through hash calculation based on the first intermediate ciphertext, the decryption information, and the extracted third intermediate ciphertext. If the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with. If the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0180] If it is verified that the new encrypted information has not been tampered with, the decryption information is determined as the payment information.

[0181] Step S609: The institutional server performs asset deduction on the digital asset account based on the payment information.

[0182] Step S610: The institutional server returns the payment result to the payment server.

[0183] Step S611: The institutional server forwards the payment result to the proxy server.

[0184] Step S612: The proxy server forwards the payment result to the user terminal corresponding to the user terminal identifier.

[0185] In this embodiment, the payment information including the digital asset account is obtained through the user terminal. In this way, once a trigger operation for asset deduction based on the payment information is responded to, first, based on the obtained payment information, the encrypted information obtained by encrypting the payment information using the user's public key can be directly determined. This encrypted information can ensure that the subsequent proxy server cannot obtain the plaintext payment information and avoid the leakage of payment information. Second, based on the digital asset account, the corresponding account registration institution identifier can be quickly determined. Therefore, the corresponding proxy key can be directly generated using the user's public key and the institutional public key corresponding to the account registration institution identifier. After sending the encrypted information, the account registration institution identifier, and the proxy key to the proxy server, the proxy server directly uses the proxy key to encrypt the encrypted information again to obtain new encrypted information that the institutional server can decrypt by itself. During the process of the proxy server encrypting again, the payment information will not be exposed to the proxy server, ensuring the security of the payment information. Subsequently, after the proxy server forwards the new encrypted information to the institutional server corresponding to the account registration institution identifier, the institutional server can use its institutional private key to decrypt the new encrypted information by itself to obtain the payment information. Finally, asset deduction is performed on the digital asset account based on the payment information. Therefore, during the entire payment process, only the user terminal and the institutional server know the payment information, effectively avoiding the leakage of payment information and improving the security of payment.

[0186] In one embodiment, as Figure 7 shown, a payment system 700 is provided. The payment system includes a user terminal 702, a proxy server 704, and an institutional server 706;

[0187] The user terminal 702 is configured to obtain payment information, where the payment information includes a digital asset account. In response to a trigger operation for asset deduction based on the payment information, it obtains encrypted information obtained by encrypting the payment information using the user's public key, obtains the account registration institution identifier corresponding to the digital asset account, obtains a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier, and sends the encrypted information, the account registration institution identifier, and the proxy key to the proxy server;

[0188] The proxy server 704 is configured to receive the encrypted information, the account registration institution identifier, and the proxy key, encrypt the encrypted information using the proxy key to obtain new encrypted information, and then forward the new encrypted information to the institution server corresponding to the account registration institution identifier;

[0189] The institution server 706 is configured to receive the new encrypted information, decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

[0190] For the interaction process among the user terminal 702, the proxy server 704, and the institution server 706 in the above payment system 700, refer to the previous description.

[0191] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0192] Based on the same inventive concept, an embodiment of the present application further provides a payment device for implementing the above-mentioned payment method. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following payment devices can refer to the limitations on the payment method in the above text, and will not be repeated here.

[0193] In one embodiment, as Figure 8 shown, a payment device 800 is provided, including: a payment information acquisition module 802, a proxy key acquisition module 804, and a sending module 806, where:

[0194] A payment information acquisition module 802, configured to acquire payment information, where the payment information includes a digital asset account;

[0195] A proxy key acquisition module 804, configured to, in response to a trigger operation for asset deduction based on the payment information, acquire encrypted information obtained by encrypting the payment information using a user public key, acquire an account registration institution identifier corresponding to the digital asset account, and acquire a proxy key generated using the user public key and an institution public key corresponding to the account registration institution identifier;

[0196] A sending module 806, configured to send the encrypted information, the account registration institution identifier, and the proxy key to a proxy server, so as to instruct the proxy server to encrypt the encrypted information using the proxy key, and after obtaining new encrypted information, forward the new encrypted information to an institution server corresponding to the account registration institution identifier, so as to instruct the institution server to decrypt the new encrypted information using an institution private key, and after obtaining the payment information, perform asset deduction on the digital asset account based on the payment information.

[0197] In some embodiments, the payment information acquisition module 802 is configured to, after collecting a payment code provided by a merchant, display a payment interface, where the payment interface includes payment method options corresponding to multiple different payment methods; in response to a selection of the payment method option for the digital asset account, display multiple digital asset accounts of the user; and in response to a selection of a target digital asset account from the multiple digital asset accounts, generate payment information according to the target digital asset account.

[0198] In some embodiments, the payment information acquisition module 802 is configured to acquire a digital asset account for paying a target order; acquire order information of the target order, where the order information at least includes an order number, product information, and an amount to be paid; according to the order information, display an independent encryption option interface, where the independent encryption option interface at least includes encryption options corresponding to the order number, product information, and the amount to be paid; acquire a selection operation for the encryption option corresponding to the amount to be paid in the independent encryption option interface, and generate payment information according to the digital asset account and the amount to be paid.

[0199] In some embodiments, the apparatus further includes an encryption module, configured to acquire a user public key, where the user public key is generated using a random number generated by a random generation program, and the user public key corresponds to the digital asset account; and encrypt the payment information using the user public key to obtain encrypted information.

[0200] In some embodiments, the device further includes a storage module. The storage module is configured to register a digital asset account with an institutional server; after successful registration, obtain the institutional public key from the institutional server; store the account registration institution identifier corresponding to the digital asset account in correspondence with the institutional public key; generate a proxy key according to the user public key and the institutional public key; and store the account registration institution identifier in correspondence with the proxy key.

[0201] In some embodiments, the storage module is configured to, in response to a trigger operation for asset deduction based on payment information, obtain a common parameter shared between the user terminal and the institutional server corresponding to the account registration institution, and generate a proxy key according to the user public key, the institutional public key, and the common parameter.

[0202] In some embodiments, the common parameter is a static common parameter, and the static common parameter is the account registration institution identifier; the storage module is configured to generate a proxy key according to the user public key, the institutional public key, and the account registration institution identifier.

[0203] In some embodiments, the common parameter is a dynamic common parameter, and the dynamic common parameter is a random verification code; the storage module is configured to, in response to a trigger operation for asset deduction based on payment information, generate a random verification code; and the storage module is configured to generate a proxy key according to the user public key, the institutional public key, and the random verification code.

[0204] In some embodiments, the sending module 806 is further configured to decrypt the new encrypted information using the institutional private key to obtain decrypted information; if it is verified that the new encrypted information has not been tampered with, determine the decrypted information as payment information.

[0205] In some embodiments, the new encrypted information is formed by splicing a first intermediate ciphertext, a third intermediate ciphertext, a fourth intermediate ciphertext, and a second intermediate ciphertext; the sending module 806 is further configured to extract the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information; and decrypt according to the institutional private key, the common parameter, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain decrypted information.

[0206] In some embodiments, the device further includes a verification module. The verification module is configured to extract the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information; calculate a hash value through hash calculation according to the first intermediate ciphertext, the decrypted information, and the extracted third intermediate ciphertext; if the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; if the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

[0207] Based on the same inventive concept, an embodiment of this application also provides a payment device for implementing the payment method involved above. The implementation solutions for solving problems provided by this device are similar to those recorded in the above method. Therefore, the specific limitations in one or more of the following payment device embodiments can refer to the limitations on the payment method in the above text and will not be elaborated here.

[0208] In one embodiment, as Figure 9 shown, a payment device 900 is provided, including: a receiving module 902 and a forwarding module 904, where:

[0209] The receiving module 902 is configured to receive the encrypted information, the account registration institution identifier, and the proxy key sent by the user terminal. The encrypted information is obtained by encrypting the payment information using the user public key. The payment information includes a digital asset account. The account registration institution identifier is the identifier of the account registration institution for registering the digital asset account. The proxy key is generated using the user public key and the institutional public key corresponding to the account registration institution identifier;

[0210] The forwarding module 904 is configured to encrypt the encrypted information using the proxy key, and after obtaining the new encrypted information, forward the new encrypted information to the institutional server corresponding to the account registration institution identifier, so as to instruct the institutional server to decrypt the new encrypted information using the institutional private key, and after obtaining the payment information, perform asset deduction on the digital asset account based on the payment information.

[0211] Each module in the above payment devices can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.

[0212] In one embodiment, a computer device is provided. This computer device can be a server or a terminal, and its internal structure diagram can be as Figure 10As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it realizes the above various payment methods.

[0213] Those skilled in the art can understand that Figure 10 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0214] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are realized.

[0215] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are realized.

[0216] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are realized.

[0217] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0218] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0219] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0220] The above-described embodiments only represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. A payment method, characterized in that, The method includes: Obtaining payment information, where the payment information includes a digital asset account; In response to a trigger operation for asset deduction based on the payment information, obtaining encrypted information obtained by encrypting the payment information using the user's public key, obtaining the account registration institution identifier corresponding to the digital asset account, and obtaining a proxy key generated using the user's public key and the institutional public key corresponding to the account registration institution identifier; Sending the encrypted information, the account registration institution identifier, and the proxy key to a proxy server to instruct the proxy server to encrypt the encrypted information using the proxy key, and after obtaining new encrypted information, forwarding the new encrypted information to the institutional server corresponding to the account registration institution identifier to instruct the institutional server to decrypt the new encrypted information using the institutional private key, and after obtaining the payment information, performing asset deduction on the digital asset account based on the payment information.

2. The method according to claim 1, characterized in that, The obtaining of the payment information includes: After collecting the payment code provided by the merchant, displaying a payment interface, where the payment interface includes payment method options corresponding to multiple different payment methods; In response to the selection of the digital asset account payment method option, displaying multiple digital asset accounts of the user; In response to the selection of a target digital asset account among the multiple digital asset accounts, generating payment information based on the target digital asset account.

3. The method according to claim 1, characterized in that, The obtaining of the payment information includes: Obtaining a digital asset account for paying a target order; Obtaining order information of the target order, where the order information at least includes an order number, product information, and the amount to be paid; According to the order information, displaying an independent encryption option interface, where the independent encryption option interface at least includes encryption options corresponding to the order number, product information, and the amount to be paid; Obtaining a selection operation on the encryption option corresponding to the amount to be paid in the independent encryption option interface, and generating payment information based on the digital asset account and the amount to be paid.

4. The method according to claim 1, characterized in that, After obtaining the payment information, the method further includes: Obtaining the user's public key, where the user's public key is generated using a random number generated by a random generation program, and the user's public key corresponds to the digital asset account; Encrypting the payment information using the user's public key to obtain encrypted information.

5. The method according to claim 1, characterized in that, The method further includes: Registering a digital asset account with an institutional server; After successful registration, obtaining the institutional public key from the institutional server; Correspondingly storing the account registration institution identifier corresponding to the digital asset account and the institutional public key; Generating a proxy key according to the user's public key and the institutional public key; Correspondingly storing the account registration institution identifier and the proxy key.

6. The method according to claim 5, characterized in that, The generating of the proxy key according to the user's public key and the institutional public key includes: In response to a trigger operation for asset deduction based on the payment information, obtaining a common parameter shared between the user terminal and the institutional server corresponding to the account registration institution, and generating a proxy key according to the user's public key, the institutional public key, and the common parameter.

7. The method according to claim 6, characterized in that, The common parameter is a static common parameter, and the static common parameter is the account registration institution identifier; generating a proxy key according to the user public key, the institution public key, and the common parameter includes: Generating a proxy key according to the user public key, the institution public key, and the account registration institution identifier.

8. The method according to claim 6, characterized in that, The common parameter is a dynamic common parameter, and the dynamic common parameter is a random verification code; obtaining the common parameter shared between the user terminal and the institution server corresponding to the account registration institution includes: Generating a random verification code in response to a trigger operation for asset deduction based on the payment information; The generating a proxy key according to the user public key, the institution public key, and the common parameter includes: Generating a proxy key according to the user public key, the institution public key, and the random verification code.

9. The method according to claim 1, characterized in that, The decrypting the new encrypted information using the institution private key to obtain the payment information includes: Decrypting the new encrypted information using the institution private key to obtain decrypted information; If it is verified that the new encrypted information has not been tampered with, determining the decrypted information as the payment information.

10. The method according to claim 9, wherein, The new encrypted information is formed by splicing a first intermediate ciphertext, a third intermediate ciphertext, a fourth intermediate ciphertext, and a second intermediate ciphertext; The decrypting the new encrypted information using the institution private key to obtain decrypted information includes: Extracting the first intermediate ciphertext and the second intermediate ciphertext from the new encrypted information; Performing decryption according to the institution private key, the common parameter, the extracted first intermediate ciphertext, and the second intermediate ciphertext to obtain decrypted information.

11. The method according to claim 10, wherein, The method further includes: Extracting the third intermediate ciphertext and the fourth intermediate ciphertext from the new encrypted information; calculating a hash value through hash calculation according to the first intermediate ciphertext, the decrypted information, and the extracted third intermediate ciphertext; If the hash value is equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has not been tampered with; If the hash value is not equal to the extracted fourth intermediate ciphertext, it is verified that the new encrypted information has been tampered with.

12. A payment method, wherein, The method includes: Receiving an encrypted information, an account registration institution identifier, and a proxy key sent by a user terminal, where the encrypted information is obtained by encrypting payment information using a user public key, the payment information includes a digital asset account, the account registration institution identifier is an identifier of an account registration institution for registering the digital asset account, and the proxy key is generated using the user public key and the institution public key corresponding to the account registration institution identifier; After encrypting the encrypted information using the proxy key to obtain new encrypted information, forwarding the new encrypted information to the institution server corresponding to the account registration institution identifier, so as to instruct the institution server to decrypt the new encrypted information using the institution private key to obtain the payment information, and then performing asset deduction on the digital asset account based on the payment information.

13. A payment system, wherein, The system includes a user terminal, a proxy server, and an institution server; The user terminal is configured to obtain payment information, where the payment information includes a digital asset account. In response to a trigger operation for asset deduction based on the payment information, it obtains encrypted information obtained by encrypting the payment information using the user's public key, obtains the account registration institution identifier corresponding to the digital asset account, obtains a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier, and sends the encrypted information, the account registration institution identifier, and the proxy key to the proxy server; The proxy server is configured to receive the encrypted information, the account registration institution identifier, and the proxy key, and use the proxy key to encrypt the encrypted information. After obtaining new encrypted information, it forwards the new encrypted information to the institution server corresponding to the account registration institution identifier; The institution server is configured to receive the new encrypted information, decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

14. A payment device, wherein, The device includes: A payment information acquisition module, configured to obtain payment information, where the payment information includes a digital asset account; A proxy key acquisition module, configured to, in response to a trigger operation for asset deduction based on the payment information, obtain encrypted information obtained by encrypting the payment information using the user's public key, obtain the account registration institution identifier corresponding to the digital asset account, and obtain a proxy key generated using the user's public key and the institution public key corresponding to the account registration institution identifier; A sending module, configured to send the encrypted information, the account registration institution identifier, and the proxy key to the proxy server, so as to instruct the proxy server to use the proxy key to encrypt the encrypted information. After obtaining new encrypted information, it forwards the new encrypted information to the institution server corresponding to the account registration institution identifier, so as to instruct the institution server to decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

15. A payment device, wherein, The device includes: A receiving module, configured to receive the encrypted information, the account registration institution identifier, and the proxy key sent by the user terminal. The encrypted information is obtained by encrypting the payment information using the user's public key. The payment information includes a digital asset account. The account registration institution identifier is the identifier of the account registration institution for registering the digital asset account. The proxy key is generated using the user's public key and the institution public key corresponding to the account registration institution identifier; A forwarding module, configured to use the proxy key to encrypt the encrypted information. After obtaining new encrypted information, it forwards the new encrypted information to the institution server corresponding to the account registration institution identifier, so as to instruct the institution server to decrypt the new encrypted information using the institution private key to obtain the payment information, and then perform asset deduction on the digital asset account based on the payment information.

16. A computer device, comprising a memory and a processor, wherein the memory stores a computer program, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 12 are implemented.

17. A computer-readable storage medium, on which a computer program is stored, wherein, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.

18. A computer program product, comprising a computer program, wherein, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.