Unionpay electronic payment method and payment data query system
Dynamic tokens are generated through dynamic identity verification and multi-factor biometric authentication, and the transaction data is encrypted and processed in combination with encryption algorithms and quantum key distribution technology, solving the problems of vulnerability to attacks and complex data query in existing electronic payment technology, and achieving high-security transaction data processing and multi-dimensional index query.
Patent Information
- Application Number
- CN202510254237.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing electronic payment technology has problems such as vulnerability to attacks in the transaction process, data loss and the security of transaction data cannot be guaranteed, and transaction data query is complex and can only be queried according to time.
Through dynamic identity verification, multi-factor biometric authentication is used to generate dynamic tokens, and the transaction data is encrypted and processed in combination with SM4 algorithm and quantum key distribution technology to achieve secure processing of transaction information. At the same time, an intelligent risk control interception and hierarchical authorization mechanism is adopted to improve transaction security, and multi-dimensional indexing and data query is realized through the classification index engine and privacy protection module, improving the security and query efficiency of transaction data.
It improves the security of the transaction process and data, and realizes the query of indexing transaction data in various ways, ensuring the immutability of transaction data and the security of query.
Smart Images

Figure CN120197211A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electronic payment, and more specifically, particularly relates to a UnionPay electronic payment method. At the same time, the present invention also relates to a payment data query system. Background Art
[0002] "UnionPay Online Payment" is a bank card online transaction transfer and settlement platform built to meet the online payment needs of all parties. It is also the first integrated and comprehensive online payment platform with financial-level pre-authorization guarantee transaction functions and fully supports all types of UnionPay cards.
[0003] UnionPay Online Payment is a bank card online transaction transfer and settlement platform jointly built by UnionPay and various commercial banks.
[0004] With the rapid development of fintech, electronic payment has become a core part of modern financial infrastructure. As a bank card association, UnionPay's electronic payment system undertakes key functions such as cross-bank transaction settlement and cross-border payment. The current mainstream electronic payment technology mainly adopts the following architecture:
[0005] Traditional four-party model: A chain processing system of cardholder → merchant → acquirer → issuer, and transactions need to be forwarded through multiple heterogeneous systems. The typical delay reaches 200 - 500ms, and there are the following inherent problems:
[0006] Asynchronous transaction fragmentation: Authorization, clearing, and settlement belong to different batch processes, resulting in poor visibility of the fund status;
[0007] Data island effect: Each participating party adopts independent data storage specifications. For example, the issuer uses a DB2 time series database, and the acquirer uses an Oracle cluster, resulting in complex ETL conversion for joint queries;
[0008] Security verification mechanism: Commonly adopted under the current PCIDSS 4.0 standard:
[0009] Two-factor authentication: SMS verification code + payment password;
[0010] Tokenization technology: PAN replacement token generation algorithm.
[0011] However, there are some problems in the existing technology: It is vulnerable to attacks during the transaction process, resulting in data loss, and it cannot guarantee the security of transaction data. Also, during the query process of transaction data, the query is relatively complex and can only be queried according to time. Therefore, we propose a UnionPay electronic payment method and a payment data query system. Summary of the Invention
[0012] In view of the problems existing in the prior art, the purpose of the present invention is to provide a UnionPay electronic payment method and a payment data query system, which realize the encryption processing of transaction information through dynamic identity verification, and combine bank authorization, and have a variety of indexing methods for transaction data query, and high security, so as to improve the security of the transaction process and data, and can realize indexing transaction data in multiple ways.
[0013] To achieve the above object, the present invention provides the following technical solutions: A UnionPay electronic payment method, comprising the following steps:
[0014] The user initiates a payment request: The user initiates a payment request through the Internet, mobile terminal or POS machine channel;
[0015] Dynamic verification of user identity: When making a payment, a dynamic token is generated through multi-factor biometric authentication;
[0016] Transaction encryption processing: The SM4 algorithm is used to encrypt transaction data, and a dynamic key is generated in combination with the quantum key distribution technology; and the transaction hash value is uploaded to the chain in real time to ensure that the transaction cannot be tampered with;
[0017] Payment gateway processing: The UnionPay payment gateway is responsible for processing all payment requests, verifying the user's payment account information, transaction amount, merchant information, and sending the payment request to the user's bank through the UnionPay network for authorization;
[0018] Bank authorization: The bank will authorize according to the balance and transaction information of the user's account to confirm whether the user makes a payment. After the bank confirms the authorization, it sends a response to the UnionPay payment gateway to return the transaction status;
[0019] Transaction confirmation and fund settlement: After receiving the bank authorization confirmation, the payment gateway initiates a fund settlement process to transfer the amount from the user's account to the merchant's account;
[0020] Payment completion notification: The UnionPay payment system sends a payment success notification to the user and the merchant, including the transaction number, transaction amount, and payment method information;
[0021] Intelligent risk control interception: The AI anomaly detection model is used to intercept abnormal transaction information, and a hierarchical authorization mechanism is adopted to realize the security protection of the user's transaction information.
[0022] Preferably in the present invention, the multi-factor biometric authentication includes fingerprint recognition and liveness detection, and fingerprint recognition and liveness detection are fused to generate a dynamic token;
[0023] The steps of the fingerprint recognition are as follows:
[0024] The fingerprint texture is captured through a sensor, or a 3D fingerprint model is constructed;
[0025] Extract minutiae of fingerprints through Gabor filters, including bifurcation points and endpoints, to form a feature template;
[0026] Matching algorithm: Use the improved FingerCode algorithm to calculate the similarity between the fingerprint to be tested and the template. The calculation formula is as follows:
[0027]
[0028] Among them, FV represents the template feature vector, FV2 represents the feature vector of the fingerprint to be tested, ∑|FV1 - FV2| represents the sum of the absolute values of the feature differences, which represents the cumulative difference between the template feature vector and the feature vector of the fingerprint to be tested in all dimensions. Max_Diff represents the maximum possible difference, which is used to normalize the difference sum so that the matching degree falls within the interval [0, 1]. K represents the ratio of fingerprint recognition, and the similarity threshold is set to ≥85%.
[0029] Preferably in the present invention, the method for detecting liveness includes a dynamic detection method or a static detection method;
[0030] The dynamic detection method includes micro - motion analysis and physiological signal detection;
[0031] Micro - motion analysis: Require the user to perform actions such as blinking and shaking the head, verify liveness through continuous frame analysis, or use the optical flow method to calculate the facial motion vector. The vector distribution of non - live videos is abnormal;
[0032] Physiological signal detection: Capture the change of facial blood flow through a camera to detect the heart rate; or analyze the pupil contraction speed and amplitude after being stimulated by a flash;
[0033] The static detection method includes texture analysis and 3D structured light;
[0034] The texture analysis extracts the micro - texture features on the skin surface and uses the LBP algorithm for comparison; or project hundreds of thousands of infrared dot matrices to construct a facial depth map to identify the difference between a flat photo and a three - dimensional human face;
[0035] The multi - modal fusion scheme is used to fuse the scores calculated by multiple liveness detections;
[0036] The calculation formula for confidence - weighted decision - making is as follows:
[0037] L = 0.4·S motion +0.3·S rPPG +0.3·S 3D ,
[0038] Among them, S motion represents the dynamic action score, analyzing the micro - motions completed by the user according to the instructions; SrPPG Expressed as a heart rate signal score, capturing facial blood flow changes through a camera, calculating the heart rate and signal stability; S 3D Expressed as a three-dimensional structure score, obtaining facial depth information using structured light or ToF sensors, verifying three-dimensional features, L represents the total score of liveness detection. If the total score ≥ 0.7, it is determined to be a live body, otherwise it is rejected.
[0039] Preferably in the present invention, the multi-factor biometric authentication uses cross-comparison to perform computational processing on fingerprint recognition and liveness detection, that is, the fingerprint matching degree ≥ 85% and the liveness score ≥ 0.7, generating a dynamic token. If any condition is not met, secondary verification is triggered and voiceprint recognition is required;
[0040] The generation calculation of the dynamic token is as follows:
[0041] Time window division:
[0042] Discretize the current timestamp T at a fixed interval:
[0043]
[0044] Among them, T0 represents the initial time, and the time window is default 30 seconds, T step Represents the time factor;
[0045] HMAC hash operation:
[0046] Use the key K to perform HMAC-SHA1 operation on the time factor T step To generate a 20-byte hash value;
[0047] H = HMAC_SHA1(K, T step )
[0048] Among them, H represents the hash byte, and HMAC_SHA1 represents the HMAC-SHA1 operation function;
[0049] Extract the dynamic offset:
[0050] Take the lower 4 bits of the last byte of the hash value as the offset offset, and intercept 4 bytes from the offset position:
[0051] offset = H[-1] & 0x0F Dynamic code = (H[offset] & 0x7F) << 24 | H[offset + 1] << 16 | H[offset + 2] << 8 | H[offset + 3],
[0052] Modulo truncation:
[0053] Convert the dynamic code to a decimal number with a specified number of digits: OTP = dynamic code mod 10 6 .
[0054] Preferably in the present invention, the calculation of the SM4 algorithm is as follows:
[0055] Input a 128-bit transaction plaintext block X = (X0, X1, X2, X3), each word being 32 bits;
[0056] In each round, for X i+1 , X i+2 , X i+3 and the round key rk i perform processing:
[0057]
[0058] The composite permutation function T: includes S-box substitution and linear transformation L;
[0059] S-box: A non-linear permutation table with 8-bit input and output;
[0060] Linear transformation L: Perform circular shift and exclusive OR on a 32-bit word;
[0061] After 32 rounds of iteration, the ciphertext Y = (X 35 , X 34 , X 33 , X 32 ) is output.
[0062] Preferably in the present invention, the calculation of the quantum key distribution technology for generating a dynamic key is as follows:
[0063] Key generation: Alice randomly selects the X basis or the Y basis, prepares a quantum state according to the random bit stream, and then Bob performs polarization detection on the received photons according to the measurement basis. Alice and Bob publicly compare the basis selection sequences through a classical channel, and retain the bits with consistent bases as the original key material;
[0064] Dynamic key generation: A unique key is generated for each session, and the key generated by QKD is used as the session key for SM4 / AES, which is refreshed periodically;
[0065] Mathematical security proof: Based on the quantum no-cloning theorem and the quantum mechanical uncertainty principle, any eavesdropping behavior will introduce QBER > 11%, which can be detected by the legitimate party;
[0066] Key rate formula:
[0067]
[0068] where h(x) = -x log2 x - (1 - x) log2 (1 - x), leakEC It is denoted as the amount of error correction process information leakage, QBER is denoted as the calculated bit error rate, and R is denoted as the dynamic key.
[0069] Preferably in the present invention, the AI anomaly detection model is modeled through the user behavior baseline, and the user behavior baseline includes geographical location, consumption habits, device fingerprint and behavior sequence;
[0070] Anomaly detection is achieved through multi-dimensional weighted deviation, and the calculation is as follows:
[0071]
[0072] Among them, n represents the total number of behavior baselines, i represents the sequence of behavior baselines, and x i is denoted as the behavior baseline, and μ i is denoted as the historical mean of the behavior baseline, and σ i is denoted as the historical standard deviation of the behavior baseline, and w is denoted as the weight value of the behavior baseline;
[0073] Interception condition: If the deviation > 80%, the risk control rule is triggered.
[0074] Preferably in the present invention, the trigger condition steps of the hierarchical authorization mechanism are as follows:
[0075] Set the single-transaction amount threshold. If the amount exceeds the set threshold and the deviation > 60%, then multi-signature is triggered;
[0076] The multi-signature conducts transactions through fingerprint, face biometric recognition and dynamic token, and the user private key signs the transaction hash;
[0077] The bank side conducts secondary evaluation through the AI model and determines the transaction information through manual review. The bank HSM authorizes the transaction using the dedicated key;
[0078] The transaction hash and double signature are written into the consortium chain to achieve blockchain evidence storage and ensure immutability.
[0079] A payment data query system includes a transaction query module, a payment status query module, a refund query module, a report module, a storage module, a classification index engine and a privacy protection module;
[0080] The transaction query module is used to query specific payment transaction records; and the query content includes transaction number, transaction amount, transaction status and payment method;
[0081] The payment status query module is used to query the current status of the payment transaction, including whether it has been paid, whether the payment is successful. If the payment fails, query the reason for failure;
[0082] The refund query module is used to allow users to view the refund progress and status through the refund query module if they need to apply for a refund after payment is completed;
[0083] The report module is used to generate payment transaction reports, including daily transaction data summary, revenue statistics, and refund situations;
[0084] The storage module uses a time-series database. The time-series database uses InfluxDB to store transaction records, supports millisecond-level timestamp indexing, and enables fast querying by time range;
[0085] The classification index engine constructs a multi-dimensional index based on Elasticsearch and performs multi-dimensional queries by time, transaction status, and transaction amount;
[0086] The privacy protection module is used to encrypt user data locally and upload the aggregated analysis results to the cloud to avoid leakage of raw data and display data with user permission grading.
[0087] Preferably in the present invention, the local encryption calculation of the privacy protection module is as follows:
[0088] The BLS short signature technology is used for local encryption processing. In the BLS short signature technology, the bilinear mapping is e: G1×G2=G T , where G1, G2, G T are multiplicative groups, the generator is P, and a hash function is selected The private key is sk and the public key is pk;
[0089] The user data is set as data, and the private key sk is used to calculate the signature Sign=h(data) sk , where h represents the hash algorithm, and the user data data sends the signature information and the original data information s=data||Sign to the blockchain;
[0090] The types of user data are set as G={G1,G2,…,G n}, G i ∈G;
[0091] The types of user data include transaction number, transaction amount, transaction status, and payment method;
[0092] The same type of data is denoted as C-data={C1-data,C2-data,…,C n -data}, C i -data∈C-data; The blockchain uses the private key sk to calculate the signature Sign=h(s,G,C_data) for s, G, and C_data sk, and send the signature and related data Msg = sign||G||C_data to the blockchain layer.
[0093] Technical effects and advantages of the present invention:
[0094] Through the integration of biometric authentication, quantum encryption, intelligent risk control, and privacy computing, etc., the present invention constructs a leading electronic payment infrastructure with high security of transaction data. The payment requests initiated by users are recognized through dynamic identity verification. After the payment requests are recognized, the payment requests are securely processed through transaction encryption to improve the security of payment requests. And through payment risk control interception, abnormal transaction information is intercepted and processed to prevent abnormal transactions from causing losses to users;
[0095] That is, a dynamic token is generated through multi-factor biometric authentication, and fingerprint recognition and liveness detection are integrated to determine that the payment request is initiated by the user himself, improving security. And after dynamic identity verification, a dynamic key is generated through the SM4 algorithm and quantum key distribution technology to facilitate the encryption of transaction information, improve the security of transaction information, prevent transaction information from being attacked, and upload the transaction hash value to the blockchain to prevent transaction information from being tampered with;
[0096] And through intelligent risk control interception, abnormal transaction information is processed. Abnormal transaction information is intercepted through an AI abnormal detection model, and a hierarchical authorization mechanism is adopted to achieve security protection for users' transaction information, which can effectively prevent the generation of abnormal transaction information. And for transactions with a large amount, multiple signature processing is triggered, and the transaction is authorized through a private key;
[0097] And through a classification index engine for multi-dimensional indexing, the query of transaction data can be indexed according to multiple indexes. And the privacy protection module is used to encrypt user data locally and upload the aggregated analysis results to the cloud to avoid the leakage of original data. And user permissions are graded to display data, which can ensure the security of transaction data.
[0098] Through the following detailed description of the exemplary embodiments of the present invention with reference to the accompanying drawings, other features and advantages of the present invention will become clear. BRIEF DESCRIPTION OF THE DRAWINGS
[0099] Figure 1 is a schematic flowchart of the UnionPay electronic payment method provided by the present invention;
[0100] Figure 2 is a schematic structural diagram of the payment data query system provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0101] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below in conjunction with specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.
[0102] As Figure 1 shown, a UnionPay electronic payment method provided by an embodiment of the present invention includes the following steps:
[0103] User initiates a payment request: The user initiates a payment request through the Internet, mobile device or POS machine channel;
[0104] Dynamic verification of user identity: When making a payment, a dynamic token is generated through multi-factor biometric authentication;
[0105] Transaction encryption processing: The SM4 algorithm is used to encrypt transaction data, and a dynamic key is generated in combination with the quantum key distribution technology; and the transaction hash value is uploaded to the blockchain in real time to ensure that the transaction cannot be tampered with;
[0106] Payment gateway processing: The UnionPay payment gateway is responsible for processing all payment requests, verifying the user's payment account information, transaction amount, and merchant information, and sending the payment request to the user's bank through the UnionPay network for authorization;
[0107] Bank authorization: The bank will authorize according to the balance and transaction information of the user's account to confirm whether the user makes a payment. After the bank confirms the authorization, it sends a response to the UnionPay payment gateway to return the transaction status;
[0108] Transaction confirmation and fund settlement: After receiving the bank authorization confirmation, the payment gateway initiates the fund settlement process to transfer the amount from the user's account to the merchant's account;
[0109] Payment completion notification: The UnionPay payment system sends a payment success notification to the user and the merchant, including the transaction number, transaction amount, and payment method information;
[0110] Intelligent risk control interception: An AI anomaly detection model is used to intercept abnormal transaction information, and a hierarchical authorization mechanism is adopted to protect the user's transaction information.
[0111] In this embodiment, preferably, the multi-factor biometric authentication includes fingerprint recognition and liveness detection, and fingerprint recognition and liveness detection are fused to generate a dynamic token;
[0112] The steps of the fingerprint recognition are as follows:
[0113] Capture fingerprint texture through a sensor or construct a 3D fingerprint model;
[0114] Extract minutiae of the fingerprint through a Gabor filter, including bifurcation points and endpoints, to form a feature template;
[0115] Matching algorithm: Use an improved FingerCode algorithm to calculate the similarity between the fingerprint to be measured and the template. The calculation formula is as follows:
[0116]
[0117] Among them, FV represents the template feature vector, FV2 represents the feature vector of the fingerprint to be measured, ∑|FV1 - FV2| represents the sum of the absolute values of the feature differences, representing the cumulative difference between the template feature vector and the feature vector of the fingerprint to be measured in all dimensions, Max_Diff represents the maximum possible difference, which is used to normalize the difference sum to make the matching degree fall within the range of [0, 1], K represents the ratio of fingerprint recognition, and the similarity threshold is set to ≥85%;
[0118] It should be noted that by extracting the minutiae of the fingerprint through a Gabor filter to form a feature template, and through the improved FingerCode algorithm, the similarity between the details of the fingerprint and the template can be effectively improved, and the fingerprint recognition accuracy is effectively improved.
[0119] In this embodiment, preferably, the method for detecting liveness includes a dynamic detection method or a static detection method;
[0120] The dynamic detection method includes micro-motion analysis and physiological signal detection;
[0121] Micro-motion analysis: Require the user to perform actions such as blinking and shaking the head, verify liveness through continuous frame analysis, or use the optical flow method to calculate the facial motion vector. The vector distribution of non-live videos is abnormal;
[0122] Physiological signal detection: Capture the change of facial blood flow through a camera to detect the heart rate; or analyze the pupil contraction speed and amplitude after being stimulated by a flash;
[0123] The static detection method includes texture analysis and 3D structured light;
[0124] The texture analysis extracts the micro-texture features of the skin surface and compares them using the LBP algorithm; or project tens of thousands of infrared dots to construct a facial depth map to identify the difference between a flat photo and a three-dimensional human face;
[0125] The multi-modal fusion scheme is used to fuse the scores calculated by multiple liveness detections;
[0126] The calculation formula for confidence-weighted decision-making is as follows:
[0127] L = 0.4·S motion + 0.3·S rPPG + 0.3·S 3D ,
[0128] where S motion represents the dynamic action score, analyzing the micro-actions completed by the user according to the instructions; S rPPG represents the heart rate signal score, capturing the facial blood flow changes through a camera, calculating the heart rate and signal stability; S 3D represents the three-dimensional structure score, using structured light or ToF sensors to obtain facial depth information and verify the stereo features. L represents the total score of liveness detection. If the total score ≥ 0.7, it is determined as a live body, otherwise it is rejected;
[0129] It should be noted that the liveness information of the user is obtained through the dynamic detection method or static detection of liveness detection, and the scores calculated by multiple liveness detections are fused through a multi-modal fusion scheme, so as to effectively obtain the score information of liveness detection, and analyze and process it through confidence weighted decision-making, and generate and determine information of dynamic tokens by combining the similarity threshold of fingerprints and the total score of liveness detection, which is convenient for determining the transaction request.
[0130] In this embodiment, preferably, the multi-factor biometric authentication uses cross-comparison to perform calculation processing on fingerprint recognition and liveness detection, that is, the fingerprint matching degree ≥ 85% and the liveness score ≥ 0.7, and a dynamic token is generated. If any condition is not met, secondary verification is triggered and voiceprint recognition is required;
[0131] The generation calculation of the dynamic token is as follows:
[0132] Time window division:
[0133] The current timestamp T is discretized at a fixed interval:
[0134]
[0135] where T0 represents the initial time, and the time window is default 30 seconds, and T step represents the time factor;
[0136] HMAC hash operation:
[0137] Use the key K to perform HMAC-SHA1 operation on the time factor T step to generate a 20-byte hash value;
[0138] H = HMAC_SHA1(K, T step )
[0139] Wherein, H represents the hash byte, and HMAC_SHA1 represents the HMAC-SHA1 operation function;
[0140] Extract the dynamic offset:
[0141] Take the lower 4 bits of the last byte of the hash value as the offset offset, and intercept 4 bytes from the offset position:
[0142] offset = H[-1] & 0x0F
[0143] Dynamic code = (H[offset] & 0x7F) << 24 | H[offset + 1] << 16 | H[offset + 2] << 8 | H[offset + 3],
[0144] Modulo truncation:
[0145] Convert the dynamic code to a decimal number with a specified number of digits: OTP = dynamic code mod 10 6 ;
[0146] It should be noted that by cross-comparing to perform computational processing on fingerprint recognition and liveness detection, a dynamic token can be effectively generated. And the dynamic token is processed by time discretization, and combined with the key K for HMAC-SHA1 operation. Then, through the dynamic offset and modulo stages, a dynamic code is generated, and the generation index of the dynamic token is that the fingerprint matching degree ≥ 85% and the liveness score ≥ 0.7. If any condition is not met, secondary verification is triggered, and voiceprint recognition is required to facilitate improving the security of transactions.
[0147] In this embodiment, preferably, the calculation of the SM4 algorithm is as follows:
[0148] Input the 128-bit transaction plaintext block X = (X0, X1, X2, X3), 32 bits per word;
[0149] In each round, process X i+1 , X i+2 , X i+3 and the round key rk i for processing:
[0150]
[0151] The composite permutation function T: includes S-box substitution and linear transformation L;
[0152] S-box: a non-linear permutation table with 8-bit input and output;
[0153] Linear transformation L: perform circular shift and exclusive OR on 32-bit words;
[0154] After 32 rounds of iteration, output the ciphertext Y = (X35 ,X 34 ,X 33 ,X 32 );
[0155] It should be noted that by implementing the SM4 algorithm to encrypt transaction data, ciphertext can be effectively generated, facilitating the encryption of transaction data, achieving millisecond-level key updates, and effectively preventing key leakage.
[0156] In this embodiment, preferably, the calculation of generating dynamic keys by the quantum key distribution technology is as follows:
[0157] Key generation: At the Alice end, randomly select the X basis or Y basis, prepare a quantum state according to the random bit stream, and then at the Bob end, perform polarization detection on the received photons according to the measurement basis. Alice and Bob publicly compare the basis selection sequences through the classical channel and retain the bits with consistent bases as the original key material;
[0158] Dynamic key generation: Generate a unique key for each session. The key generated by QKD is used as the session key for SM4 / AES and is refreshed periodically;
[0159] Mathematical security proof: Based on the quantum no-cloning theorem and the quantum mechanics uncertainty principle, any eavesdropping behavior will introduce QBER > 11%, which can be detected by the legitimate party;
[0160] Key rate formula:
[0161]
[0162] where h(x) = -x log2x - (1 - x) log2(1 - x), leak EC represents the amount of information leakage during the error correction process, QBER represents the computational bit error rate, and R represents the dynamic key;
[0163] It should be noted that the quantum key distribution technology publicly compares the basis selection sequences through the classical channels of Alice and Bob, retains the bits with consistent bases as the original key material, generates a unique key for each session, uses the key generated by QKD as the session key for SM4 / AES, and refreshes it periodically, which can effectively prevent key loss, improve key security, and enable the legitimate party to detect any eavesdropping behavior, improving the security of transaction data.
[0164] In this embodiment, preferably, the AI anomaly detection model is modeled based on the user behavior baseline, and the user behavior baseline includes geographical location, consumption habits, device fingerprint, and behavior sequence;
[0165] Anomaly detection is achieved through multi-dimensional weighted deviation, and the calculation is as follows:
[0166]
[0167] Among them, n represents the total number of behavior baselines, i represents the sequence of behavior baselines, xi represents the behavior baseline, and μ i represents the historical mean of the behavior baseline, and σ i represents the historical standard deviation of the behavior baseline, and w represents the weight value of the behavior baseline;
[0168] Interception condition: If the deviation degree > 80%, the risk control rule is triggered;
[0169] It should be noted that through the AI anomaly detection model, the user behavior baseline is modeled, enabling the model to identify the transaction process based on geographical location, consumption habits, device fingerprint, and behavior sequence, and realizing anomaly detection through multi-dimensional weighted deviation. When the detected deviation degree > 80%, the risk control rule is triggered, which can effectively protect the security of transactions and prevent the occurrence of abnormal transactions.
[0170] In this embodiment, preferably, the trigger condition steps of the hierarchical authorization mechanism are as follows:
[0171] Set the threshold of the single transaction amount. If the amount exceeds the set threshold and the deviation degree > 60%, multiple signatures are triggered;
[0172] The multiple signatures conduct transactions through fingerprint, face biometric recognition, and dynamic token, and the user's private key signs the transaction hash;
[0173] The bank end conducts a secondary evaluation through the AI model and determines the transaction information through manual review. The bank HSM authorizes the transaction using a dedicated key;
[0174] The transaction hash and dual signature are written into the consortium chain to achieve blockchain evidence storage and ensure immutability;
[0175] It should be noted that for transaction information with a large transaction amount, multiple signatures are triggered through the set threshold and deviation degree, and combined with the analysis and processing of the bank end, a dedicated key is used for transaction authorization to improve the security of transactions, prevent the occurrence of abnormal transactions, and upload the transaction information to the cross-chain to prevent the transaction information from being tampered with and improve security.
[0176] Reference Figure 2 , a payment data query system, including a transaction query module, a payment status query module, a refund query module, a report module, a storage module, a classification index engine, and a privacy protection module;
[0177] The transaction query module is used to query specific payment transaction records; and the query content includes transaction number, transaction amount, transaction status, and payment method;
[0178] The payment status query module is used to query the current status of payment transactions, including whether the payment has been made, whether the payment is successful, and if the payment fails, query the reason for failure;
[0179] The refund query module is used to, after the payment is completed, if the user needs to apply for a refund, view the refund progress and refund status through the refund query module;
[0180] The report module is used to generate payment transaction reports, including summary of daily transaction data, revenue statistics, and refund situations;
[0181] The storage module uses a time series database. The time series database uses InfluxDB to store transaction records, supports millisecond-level timestamp indexing, and enables fast query by time range;
[0182] The classification index engine constructs a multi-dimensional index based on Elasticsearch and performs multi-dimensional queries by time, transaction status, and transaction amount;
[0183] The privacy protection module is used to encrypt user data locally and upload the aggregated analysis results to the cloud to avoid leakage of original data and display data with user permission grading.
[0184] In this embodiment, preferably, the calculation of local encryption by the privacy protection module is as follows:
[0185] Use the BLS short signature technology for local encryption processing. In the BLS short signature technology, the bilinear mapping is e: G1×G2 = G T , where G1, G2, G T are multiplicative groups, the generator is P, and a hash function is selected The private key is sk and the public key is pk;
[0186] Set the user data as data, and use the private key sk to calculate the signature Sign = h(data) sk , where h represents the hash algorithm, and the user data data sends the signature information and the original information of the data s = data||Sign to the blockchain;
[0187] Set the types of user data as G = {G1, G2,..., G n}, G i ∈ G;
[0188] The types of user data include transaction number, transaction amount, transaction status, and payment method;
[0189] The same type of data is denoted as C-data = {C1-data, C2-data, …, C n -data}, C i -data ∈ C-data; The blockchain uses the private key sk to calculate the signature Sign = h(s, G, C_data) for s, G, and C_data sk and sends the signature and related data Msg = sign||G||C_data to the blockchain layer;
[0190] It should be noted that the privacy protection module is used to protect the security of the queried transaction information, prevent the queried transaction information from being attacked, and improve the security of the user's transaction information.
[0191] The specific operation process of the present invention: for realizing electronic payment:
[0192] The user initiates a payment request: The user initiates a payment request through the Internet, mobile terminal or POS machine channel;
[0193] The user identity dynamic verification: When making a payment, a dynamic token is generated through multi-factor biometric authentication;
[0194] The transaction encryption process: The SM4 algorithm is used to encrypt the transaction data, and a dynamic key is generated in combination with the quantum key distribution technology; and the transaction hash value is uploaded to the chain in real time to ensure that the transaction cannot be tampered with;
[0195] The payment gateway processing: The UnionPay payment gateway is responsible for processing all payment requests, verifying the user's payment account information, transaction amount, and merchant information, and sending the payment request to the user's bank through the UnionPay network for authorization;
[0196] The bank authorization: The bank will authorize according to the balance and transaction information of the user's account to confirm whether the user makes a payment. After the bank confirms the authorization, it sends a response to the UnionPay payment gateway to return the transaction status;
[0197] The transaction confirmation and fund settlement: After receiving the bank authorization confirmation, the payment gateway initiates the fund settlement process to transfer the amount from the user's account to the merchant's account;
[0198] The payment completion notification: The UnionPay payment system sends a payment success notification to the user and the merchant, including the transaction number, transaction amount, and payment method information;
[0199] The intelligent risk control interception: The AI anomaly detection model is used to intercept abnormal transaction information, and a hierarchical authorization mechanism is adopted to realize the security protection of the user's transaction information;
[0200] For realizing the query of transaction information;
[0201] The transaction query module is used to query specific payment transaction records; and the query content includes transaction number, transaction amount, transaction status, and payment method;
[0202] The payment status query module is used to query the current status of payment transactions, including whether the payment has been made, whether the payment is successful, and if the payment fails, to query the reason for failure;
[0203] The refund query module is used to, after the payment is completed, if the user needs to apply for a refund, view the refund progress and refund status through the refund query module;
[0204] The report module is used to generate payment transaction reports, including daily transaction data summary, revenue statistics, and refund situations;
[0205] The storage module uses a time series database. The time series database uses InfluxDB to store transaction records, supports millisecond-level timestamp indexing, and enables fast query by time range;
[0206] The classification index engine constructs a multi-dimensional index based on Elasticsearch and performs multi-dimensional queries by time, transaction status, and transaction amount;
[0207] The privacy protection module is used to encrypt user data locally and upload the aggregated analysis results to the cloud to avoid the leakage of raw data and display data with user permission grading.
[0208] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A UnionPay electronic payment method, characterized in that: The steps include: User-initiated payment request: The user initiates a payment request through the Internet, mobile terminal or POS machine channel; Dynamic user identity verification: When making a payment, a dynamic token is generated through multi-factor biometric authentication; Transaction encryption processing: SM4 algorithm is used to encrypt transaction data, and dynamic keys are generated in combination with quantum key distribution technology; and the transaction hash value is uploaded to the chain in real time to ensure that the transaction cannot be tampered with; Payment gateway processing: UnionPay payment gateway is responsible for processing all payment requests, verifying the user's payment account information, transaction amount, merchant information, and sending the payment request to the user's bank for authorization through the UnionPay network; Bank authorization: The bank will authorize based on the balance and transaction information of the user's account to confirm whether the user makes the payment. After confirming the authorization, the bank will send a response to the UnionPay payment gateway and return the transaction status; Transaction confirmation and fund settlement: After receiving the bank's authorization confirmation, the payment gateway initiates the fund settlement process and transfers the amount from the user account to the merchant account; Payment completion notification: The UnionPay payment system sends a payment success notification to the user and the merchant, including the transaction number, transaction amount, and payment method information; Intelligent risk control interception: Abnormal transaction information can be intercepted through AI anomaly detection model, and a hierarchical authorization mechanism can be adopted to achieve security protection of users' transaction information.
2. A UnionPay electronic payment method according to claim 1, characterized in that: The multi-factor biometric authentication includes fingerprint recognition and liveness detection, and the fingerprint recognition and liveness detection are integrated to generate a dynamic token; The steps of fingerprint identification are as follows: Capture fingerprint texture or build 3D fingerprint model through the sensor; The fingerprint minutiae, including bifurcation points and endpoints, are extracted through Gabor filters to form a feature template; Matching algorithm: Use the improved FingerCode algorithm to calculate the similarity between the fingerprint to be tested and the template. The calculation formula is as follows: Among them, FV represents the template feature vector, FV2 represents the feature vector of the fingerprint to be tested, ∑|FV1-FV2| represents the sum of the absolute values of the feature differences, which represents the cumulative difference between the template feature vector and the feature vector of the fingerprint to be tested in all dimensions, Max_Diff represents the maximum possible difference, which is used to normalize the difference sum so that the matching degree falls in the [0, 1] interval, K represents the proportion of fingerprint recognition, and the similarity threshold is set to ≥85%.
3. A UnionPay electronic payment method according to claim 2, characterized in that: The method of liveness detection includes a dynamic detection method or a static detection method; The dynamic detection method includes micro-motion analysis and physiological signal detection; Micro-motion analysis: users are asked to blink or shake their heads to verify liveness through continuous frame analysis, or the facial motion vector is calculated using the optical flow method. The vector distribution of non-live videos is abnormal. Physiological signal detection: Capture facial blood flow changes and detect heart rate through a camera; or analyze pupil contraction speed and amplitude after stimulation with a flash light; The static detection method includes texture analysis and 3D structured light; The texture analysis extracts micro-texture features of the skin surface and compares them using the LBP algorithm; or projects tens of thousands of infrared dots to construct a facial depth map and identify the difference between a flat photo and a three-dimensional face; The multimodal fusion scheme is used to fuse the scores calculated by multiple living body detection; The confidence-weighted decision formula is as follows: L=0.4·S motion +0.3·S rPPG +0.3·S 3D , Among them, S motion It is expressed as a dynamic action score, which analyzes the micro-actions completed by the user according to the instructions; S rPPG It is expressed as the heart rate signal score, which uses a camera to capture facial blood flow changes and calculate heart rate and signal stability; S 3D It is expressed as a three-dimensional structure score. It uses structured light or ToF sensors to obtain facial depth information and verify three-dimensional features. L is the total score of liveness detection. If the total score is ≥ 0.7, it is judged as live, otherwise it is rejected.
4. A UnionPay electronic payment method according to claim 3, characterized in that: The multi-factor biometric authentication uses cross-comparison to calculate and process fingerprint recognition and liveness detection, that is, the fingerprint matching degree is ≥85% and the liveness score is ≥0.7, and a dynamic token is generated. If any of the conditions is not met, secondary verification is triggered and voiceprint recognition is required; The generation calculation of the dynamic token is as follows: Time window division: Discretize the current timestamp T into fixed intervals: Among them, T0 represents the initial time, and the time window defaults to 30 seconds, T step Expressed as a time factor; HMAC hashing: Use the key K to calculate the time factor T step Perform HMAC-SHA1 operation to generate a 20-byte hash value; H=HMAC_SHA1(K,T step ), Among them, H represents the hash byte, and HMAC_SHA1 represents the HMAC-SHA1 operation function; Extract dynamic offset: Take the lower 4 bits of the last byte of the hash value as the offset, and intercept 4 bytes from the offset: ofset=H[-1]&0x0F Dynamic code = (H[σffser]&0x7F)<<24|H[offset+1]<<16|H[ofset+2]<<8|H[offset+3], Modulo truncation: Convert the dynamic code to a decimal number with a specified number of digits: OTP = dynamic code mod 10 6 .
5. A UnionPay electronic payment method according to claim 1, characterized in that: The calculation of the SM4 algorithm is as follows: Input 128-bit transaction plaintext group X = (X0, X1, X2, X3), 32 bits per word; Each round of X i+1 ,X i+2 ,X i+3 and round key rk i To process: Synthetic permutation function T: includes S-box replacement and linear transformation L; S-box: nonlinear permutation table with 8-bit input and output; Linear transformation L: cyclic shift and XOR of 32-bit words; After 32 rounds of iterations, the output ciphertext Y=(X 35 ,X 34 ,X 33 ,X 32 ).
6. A UnionPay electronic payment method according to claim 1, characterized in that: The calculation of the dynamic key generated by the quantum key distribution technology is as follows: Key generation: Alice randomly selects the X basis or Y basis, prepares the quantum state according to the random bit stream, and then Bob performs polarization detection on the received photons according to the measurement basis. Alice and Bob publicly compare the basis selection sequences through the classical channel and retain the bits with the same basis as the original key material. Dynamic key generation: A unique key is generated for each session. The key generated by QKD is used as the session key of SM4 / AES and is refreshed periodically. Mathematical security proof: Based on the quantum non-cloning theorem and the uncertainty principle of quantum mechanics, any eavesdropping behavior will introduce QBER>11% and be detected by the legitimate party; Key rate formula: Where, h(x) = -xlog2x-(1-x)log2(1-x), leak EC It represents the information leakage in the error correction process, QBER represents the calculated bit error rate, and R represents the dynamic key.
7. A UnionPay electronic payment method according to claim 1, characterized in that: The AI anomaly detection model is modeled by a user behavior baseline, and the user behavior baseline includes geographic location, consumption habits, device fingerprints, and behavior sequences; Anomaly detection is achieved through multi-dimensional weighted deviation, and the calculation is as follows: Where n represents the total number of behavioral baselines, i represents the sequence of behavioral baselines, and x i Denoted as the behavioral baseline, μ i Expressed as the historical mean of the behavioral baseline, σ i It is represented as the historical standard deviation of the behavior baseline, and w is represented as the weight value of the behavior baseline; Interception condition: If the deviation is >80%, the risk control rule will be triggered.
8. A UnionPay electronic payment method according to claim 1, characterized in that: The triggering conditions of the hierarchical authorization mechanism are as follows: Set a single transaction amount threshold. If the amount exceeds the set threshold and the deviation is greater than 60%, multi-signature is triggered. Multi-signature transactions are carried out through fingerprint, facial biometrics and dynamic tokens, and the user's private key signs the transaction hash; The bank uses an AI model for secondary evaluation and manual review to confirm transaction information, and the bank's HSM uses a dedicated key to authorize the transaction; The transaction hash and dual signatures are written into the alliance chain to realize blockchain evidence storage and ensure that it cannot be tampered with.
9. A payment data query system, characterized in that: It includes transaction query module, payment status query module, refund query module, report module, storage module, classification index engine and privacy protection module; The transaction query module is used to query specific payment transaction records; and the query content includes transaction number, transaction amount, transaction status and payment method; The payment status query module is used to query the current status of the payment transaction, including whether the payment has been made, whether the payment is successful, and if the payment fails, query the reason for the failure; The refund inquiry module is used to check the refund progress and status of the refund if the user needs to apply for a refund after the payment is completed; The report module is used to generate payment transaction reports, including daily transaction data summary, income statistics and refund status; The storage module uses a time series database, which uses InfluxDB to store transaction records and supports millisecond-level timestamp indexing to achieve fast query by time range. The classification index engine uses multi-dimensional indexes built on Elasticsearch, and can query by time, transaction status, and transaction amount. The privacy protection module is used to encrypt user data locally and upload aggregated analysis results to the cloud to prevent leakage of original data, and to display data in a hierarchical manner according to user permissions.
10. A payment data query system according to claim 9, characterized in that: The privacy protection module performs the following calculations when performing local encryption: The BLS short signature technology is used for local encryption processing. The bilinear mapping in the BLS short signature technology is e:G1×G2=G T , where G1, G2, G T is a multiplication group, the generator is P, and the hash function is selected The private key is sk and the public key is pk; The user data is set to data, and the private key sk is used to calculate the signature of the data Sign = h(data) sk , where h represents the hash algorithm, the user data data blockchain sends the signature information and the original information of the data s = data||Sign; The types of user data are G = {G1, G2, ..., G n },G i ∈G; The types of user data include transaction number, transaction amount, transaction status and payment method; The same type of data is recorded as C-data = {C1-data, C2-data, ..., C n -data},C i -data∈C-data; blockchain uses private key sk to calculate signature Sign=h(s,G,C_data) for s,G,C_data sk , and send the signature and related data Msg=sign||G||C_data to the blockchain layer.
Citation Information
Patent Citations
Dynamic password authentication method and device
CN103441856A
Bitcoin burglary prevention method based on multi-signature
CN109255609A
Multi-factor user identity dynamic authentication system and method thereof
CN116167025A
Method and system for preventing attack by combining face video with living body
CN117746488A
Full-scene intelligent payment system based on Internet medical platform
CN118863877A
Cited By
Fund position management system-oriented payment authorization method and system, and storage medium
CN121032508A
Payment authorization method, system and storage medium for a funding position management system
CN121032508B