Point-of-sale order-receiving transaction system and point-of-sale order-receiving transaction method
By integrating a SIM card as a security element into the POS terminal, combined with a near-field communication module and a back-end terminal encryption module, the compatibility issues between different devices are resolved, achieving highly secure and stable mobile payment transactions while reducing development costs.
Patent Information
- Application Number
- CN202510984353.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-10-31
AI Technical Summary
In existing technologies, when mobile devices are used as POS terminals, differences in the implementation of the Secure Element (SE) lead to compatibility issues for acquiring software on different terminals, resulting in high development costs and difficulty in achieving stable operation.
By using a user identification module (SIM card) as a security element, integrating a near-field communication module and acquiring software, an acquiring platform with local awareness and remote collaboration capabilities is built. This enables unified management and encrypted processing of transaction data. Security decisions are made through the encryption and security authentication modules of the back-end terminal, reducing reliance on dedicated security hardware.
It improves the universality and scalability of the trading system across different devices, enhances the stability and security of the trading process, reduces the adaptation burden on terminal manufacturers, and improves the real-time performance and reliability of transactions.
Smart Images

Figure CN120875874A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a point-of-sale (POS) payment system and a point-of-sale (POS) payment method. Background Technology
[0002] With the development of mobile payment technology, point-of-sale (POS) terminals have become the medium connecting consumers, merchants, and financial institutions. Whether in traditional retail scenarios or emerging mobile payment scenarios, POS terminals provide a secure and convenient infrastructure for offline payments by enabling rapid acceptance and settlement of bank cards at the point of purchase. POS terminals are gradually evolving towards intelligence and mobility. In particular, the POS model that combines mobile terminals such as smartphones with acquiring software provides a low-cost and highly flexible transaction method.
[0003] In existing technologies, mobile devices, acting as POS terminals, typically use a built-in Secure Element (SE) and Near Field Communication (NFC) module to read and process bank card information. During a transaction, the merchant terminal's acquiring application first reads the user's bank card information via NFC, then uses the device's SE to locally encrypt the data. The encrypted transaction data, along with the transaction request information, is sent to the back-end acquiring system. The back-end system then uses appropriate encryption verification and security checks to determine whether to complete the transaction.
[0004] However, different manufacturers' devices differ in their SE (Search Engine) implementations, making it difficult for acquiring software to run stably on all terminals. This causes compatibility issues between the acquiring software and the SE, leading to high development costs for acquiring software adapted to different terminal models. Therefore, there is an urgent need for a point-of-sale (POS) acquiring transaction system to solve the technical problem of poor device compatibility in existing technologies. Summary of the Invention
[0005] This application provides a point-of-sale (POS) payment system and a POS payment method to improve the universality and scalability of POS payments across different devices.
[0006] In a first aspect, embodiments of this application provide a point-of-sale (POS) payment system, including: a merchant terminal and a back-end terminal;
[0007] The merchant terminal is connected to the back-end terminal, and the merchant terminal is equipped with a near-field communication module.
[0008] The merchant terminal is equipped with acquiring software and a user identification module.
[0009] The back-end terminal includes a back-end management server, an encryption module, a foreign card acquiring transaction module, a point-of-sale terminal module, and a security authentication module;
[0010] The foreign card acquiring transaction module is connected to the downstream transaction card channel data; the point of sale terminal module is connected to the foreign card acquiring transaction module data; the point of sale terminal module is connected to the encryption module data; the security authentication module is connected to the encryption module data; the encryption module transmits encrypted information between the acquiring software and the user identification module; and the back-end management server is connected to the merchant terminal data through the acquiring software.
[0011] Secondly, embodiments of this application provide a point-of-sale (POS) payment method applied to merchant terminals, the method comprising:
[0012] In response to the device binding operation performed by the acquiring user between the acquiring software and the back-end terminal, the point of sale terminal function is activated.
[0013] The system reads the foreign card information to be traded through the near-field communication module, and reads the software operating environment information and the transaction verification information to be verified by the user identification module through the acquiring software.
[0014] The user identification module encrypts the foreign card information to be transacted, the transaction verification information, and the software operating environment information to obtain secure encrypted transaction information.
[0015] In response to a transaction initiated by an acquiring user in the acquiring software, a transaction request message is generated.
[0016] The transaction request information and transaction security encryption information are sent to the backend terminal, so that the backend terminal can make security decisions based on the transaction security encryption information through the encryption module and security authentication module, obtain the transaction security detection result, and when the security detection result is detected as normal, perform the transaction operation according to the transaction request information to obtain the transaction result;
[0017] Receive the transaction result sent by the back-end terminal through the encryption module and complete the transaction.
[0018] Thirdly, embodiments of this application provide a point-of-sale (POS) payment transaction method, applied to a back-end terminal, the method comprising:
[0019] The merchant terminal responds to the device binding operation performed by the acquiring user through the acquiring software and activates the point of sale terminal function.
[0020] The system receives transaction request information and transaction security encryption information sent by the merchant terminal. The transaction request information is generated by the merchant terminal in response to a transaction operation initiated by the acquiring user in the acquiring software. The transaction security encryption information is obtained by the merchant terminal encrypting the foreign card information to be traded, the transaction verification information, and the software operating environment information through the user identification module. The foreign card information to be traded is read by the merchant terminal through the near-field communication module. The transaction verification information is read by the merchant terminal from the user identification module through the acquiring software. The software operating environment information is collected in real-time by the merchant terminal through the acquiring software.
[0021] The encryption module decrypts the encrypted transaction security information, and the security authentication module performs security decision processing based on the decrypted encrypted transaction security information to obtain the transaction security detection result.
[0022] When the security check result indicates that the transaction is normal, the transaction operation is performed according to the transaction request information, and the transaction result is obtained;
[0023] The transaction result is sent to the merchant's terminal via an encryption module to complete the transaction.
[0024] Fourthly, embodiments of this application provide a point-of-sale (POS) payment processing device, which is applied to a merchant terminal and includes:
[0025] The first processing module is used to respond to the device binding operation between the acquiring user and the back-end terminal through the acquiring software and to activate the point of sale terminal function.
[0026] The first acquisition module is used to read the foreign card information to be traded through the near-field communication module, and to read the software operating environment information and the transaction verification information of the user identification module through the acquiring software;
[0027] The second acquisition module is used to encrypt the foreign card information to be traded, the transaction verification information and the software operating environment information through the user identification module to obtain transaction security encrypted information.
[0028] The request generation module is used to generate transaction request information in response to transaction operations initiated by acquiring users in the acquiring software.
[0029] The transaction request module is used to send transaction request information and transaction security encryption information to the backend terminal, so that the backend terminal can make security decisions based on the transaction security encryption information through the encryption module and security authentication module, obtain the transaction security detection result, and when the security detection result is detected as normal, perform the transaction operation according to the transaction request information to obtain the transaction result.
[0030] The result receiving module is used to receive the transaction results sent by the back-end terminal through the encryption module and complete the transaction.
[0031] Fifthly, embodiments of this application provide a point-of-sale (POS) payment processing device, which is applied to a back-end terminal and includes:
[0032] The second processing module is used to respond to the device binding operation performed by the acquiring user through the acquiring software and activate the point of sale terminal function in response to the merchant terminal.
[0033] The information receiving module is used to receive transaction request information and transaction security encryption information sent by the merchant terminal. The transaction request information is generated by the merchant terminal in response to a transaction operation initiated by the acquiring user in the acquiring software. The transaction security encryption information is obtained by the merchant terminal encrypting the foreign card information to be traded, the transaction verification information, and the software operating environment information through the user identification module. The foreign card information to be traded is read by the merchant terminal through the near-field communication module. The transaction verification information is read by the merchant terminal from the user identification module through the acquiring software. The software operating environment information is collected in real time by the merchant terminal through the acquiring software.
[0034] The transaction detection module is used to decrypt the encrypted transaction security information through the encryption module, and to make security decisions based on the decrypted encrypted transaction security information through the security authentication module, so as to obtain the transaction security detection result.
[0035] The transaction result generation module is used to perform transaction operations based on the transaction request information and obtain the transaction result when the security detection result indicates that the transaction is normal.
[0036] The transaction result sending module is used to send the transaction result to the merchant terminal through an encryption module to complete the transaction.
[0037] Sixthly, embodiments of this application provide an electronic device, including: a memory and a processor;
[0038] The memory stores the instructions that the computer executes;
[0039] The processor executes computer execution instructions stored in memory, causing the processor to perform any of the point-of-sale acquiring transaction methods described in the second or third aspect above.
[0040] In a seventh aspect, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement any of the point-of-sale (POS) acquiring transaction methods described in the second or third aspect above.
[0041] Eighthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements any one of the point-of-sale (POS) acquiring transaction methods described in the second or third aspect above.
[0042] This application provides a point-of-sale (POS) acquiring transaction system and method. By integrating a near-field communication module, acquiring software, and a user identification module into the merchant terminal, a hardware-software integrated acquiring platform with local sensing and remote collaboration capabilities is constructed. This enables unified management and local collection of user identity, device information, and transaction data during the acquiring process, enhancing the real-time performance and integrity of transaction interactions. Through the integration of a backend management server, encryption module, foreign card acquiring transaction module, POS terminal module, and security authentication module in the backend terminal, a well-defined and secure backend processing architecture for acquiring business is constructed, enabling rapid implementation of tasks such as transaction authentication, key encryption / decryption, and cross-system business integration. The system uses the user identification module as the security key carrier and combines it with the encryption module to complete local encryption and remote decryption, ensuring that information remains encrypted during transmission and enhancing overall communication security. The user identification module in this system is based on a SIM card, which is cross-platform and highly compatible. It solves the terminal adaptation problem caused by differences in interfaces and drivers in traditional hardware SEs, enhances the universality and scalability of the transaction link across different devices, and achieves the effect of improving the stability, security and reliability of the transaction process. Attached Figure Description
[0043] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0044] Figure 1 A schematic diagram of the point-of-sale acquiring transaction system provided in this application;
[0045] Figure 2 A flowchart illustrating the point-of-sale (POS) payment method provided in this application embodiment. Figure 1 ;
[0046] Figure 3 A flowchart illustrating the point-of-sale (POS) payment method provided in this application embodiment. Figure 2 ;
[0047] Figure 4 This is a schematic diagram of the interactive process for activating the point-of-sale terminal function provided in an embodiment of this application;
[0048] Figure 5 A schematic diagram of the interaction process of the transaction process provided in the embodiments of this application;
[0049] Figure 6 Schematic diagram of the point-of-sale acquiring transaction device provided in the embodiments of this application Figure 1 ;
[0050] Figure 7Schematic diagram of the point-of-sale acquiring transaction device provided in the embodiments of this application Figure 2 ;
[0051] Figure 8 A schematic diagram of the structure of the electronic device provided in this application.
[0052] Figure label:
[0053] 1-Transaction system; 11-Merchant terminal; 12-Back-end terminal; 111-Near-field communication module; 112-Acquiring software; 113-User identification module; 121-Back-end management server; 122-Encryption module; 123-Foreign card acquiring transaction module; 124-Point of sale terminal module; 125-Security authentication module.
[0054] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0055] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0056] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0057] First, let me explain the terms used in this application:
[0058] Derived Unique Key Per Transaction (DUKPT) is a symmetric encryption key management mechanism that dynamically derives a unique key for each transaction, used only for that specific transaction. In DUKPT, each terminal device is loaded with an Initial PIN Encryption Key (IPEK) upon initialization. This key is generated from the master key and the terminal's unique identifier (i.e., Key Serial Number, KSN). During the actual transaction, the terminal device uses its own IPEK and current KSN to generate a working key for the current transaction using a pre-defined key derivation algorithm. This working key is only used in the current transaction and is discarded after the transaction is completed; it will not be used for any subsequent transactions. Because the key derivation process is reproducible, the backend system can generate a corresponding working key using the same algorithm based on the terminal's uploaded KSN and registered IPEK, which is then used to decrypt transaction data.
[0059] The unique mapping identifier of a SIM card is a data identifier that is pre-set or dynamically generated within the SIM card and can uniquely identify the SIM card instance. It is usually stored in a secure element inside the SIM card in a secure and encrypted manner. This identifier is usually strongly bound to the physical or logical identity of the SIM card and has the characteristics of being uncopyable and untamperable.
[0060] Existing point-of-sale (POS) payment systems largely rely on pre-installed secure elements or trusted execution environments (TEEs) within mobile devices to handle data encryption and key management. In this architecture, the acquiring application needs to access the SE through interfaces provided by the device manufacturer via the operating system to read and encrypt bank card information. However, inconsistencies in the integration of secure elements, interface protocols, and system access control among device manufacturers result in poor compatibility of the acquiring software across different device models, making overall stability difficult to guarantee. Furthermore, on some terminals, SE access may be restricted or key leakage may occur, posing security risks.
[0061] The point-of-sale (POS) acquiring transaction system and method provided in this application, by using a Subscriber Identity Module (SIM) as a security element in the merchant terminal, achieves localized processing of key generation, storage, and encryption operations, constructing a trusted execution environment. This eliminates dependence on equipment manufacturer (SE) hardware, improving the system's versatility and security. Furthermore, combined with the near-field communication module and acquiring software in the merchant terminal, it provides a more compatible and secure implementation scheme for POS terminal transaction systems in mobile payment environments.
[0062] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0063] Figure 1 A schematic diagram of the point-of-sale acquiring transaction system provided in this application is shown below. Figure 1 As shown, the transaction system 1 includes a merchant terminal 11 and a back-end terminal 12; wherein the merchant terminal 11 and the back-end terminal 12 are communicatively connected. That is, the merchant terminal 11 and the back-end terminal 12 realize data interaction through a communication link, thus constructing a business closed loop from transaction initiation, identity verification, encryption processing to security decision-making and transaction execution.
[0064] Merchant terminal 11 is equipped with a near-field communication module 111, typically a mobile phone or tablet terminal with near-field communication capabilities. It features an NFC module for reading bank card information from contactless payment media (such as chip bank cards or NFC mobile devices), supporting both contact and contactless reading methods, and ensuring the accuracy and low latency of transaction data during the data collection phase. Merchant terminal 11 also includes acquiring software 112 and a user identification module 113. The acquiring software 112 serves as the interface between the user and the backend terminal 12, and its functions include merchant login, device authentication, card information collection, transaction information encapsulation, and message uploading. The user identification module 113 (i.e., a SIM card or eSIM) stores unique mapping identifiers, authentication keys, identity credentials, and dynamic tokens. It also locally encrypts data involved in transaction request information (such as device fingerprints, operating environment information, and card information), ensuring terminal-side key security and tamper-proof capabilities.
[0065] The back-end terminal 12 includes a back-end management server 121, an encryption module 122, a foreign card acquiring transaction module 123, a point-of-sale terminal module 124, and a security authentication module 125. These modules collaborate through a secure link. The foreign card acquiring transaction module 123 is connected to downstream transaction card channels; the point-of-sale terminal module 124 is connected to the foreign card acquiring transaction module 123; the point-of-sale terminal module 124 is connected to the encryption module 122; the security authentication module 125 is connected to the encryption module 122; the encryption module 122 transmits encrypted information between the acquiring software 112 and the user identification module 113; and the back-end management server 121 is connected to the merchant terminal 11 through the acquiring software 112.
[0066] In this embodiment, the backend management server 121 is mainly used to handle the business initialization process such as merchant registration, account login, permission issuance, and device binding. It maintains a connection with the merchant terminal 11 through the acquiring software 112 to complete the interaction and synchronization of user information and status. The encryption module 122 establishes an encrypted information transmission channel with the acquiring software 112 and the user identification module 113. The encryption module 122 receives the transaction security encryption information returned by the merchant terminal 11, parses the key and decrypts the transaction data through a synchronous derivation mechanism, and provides plaintext input for subsequent transaction decisions and execution. The security authentication module 125 is used to verify whether the transaction source meets the requirements and whether the operating environment is secure. It usually combines the device fingerprint, the unique mapping identifier of the user identification module 113 and the identity identifier of the currently logged-in user to perform multi-factor consistency judgment, and analyzes in real time whether there is any risky behavior in the terminal, and decides whether to allow the transaction based on the result. The foreign card acquiring transaction module 123 is used to connect the transaction request to the downstream bank card clearing channel and receive the authorization result from the bank or payment network to form the fund clearing path of the transaction link. Specifically, the foreign card acquiring transaction module 123 is used to connect to multi-channel payment platforms, including bank card clearing institutions and third-party payment networks. Its main task is to complete the specific fund clearing operation under the premise that the transaction request is legal and has been authenticated. The point-of-sale terminal module 124 communicates with the encryption module 122 and the foreign card acquiring transaction module 123. It is used to call subsequent transaction processes according to the judgment result given by the security authentication module 125, and feed back the final transaction result to the encryption module 122 to ensure the integrity of data transmission and the closed loop of the link.
[0067] In summary, by integrating a SIM card with Secure Element (SE) capabilities into the merchant terminal 11 as the user identification module 113, and establishing an end-to-end encrypted channel between this module and the encryption module 122 in the backend terminal 12, local encryption and secure transmission of transaction-related information are achieved, ensuring the security of data processing on the terminal side. This user identification module 113, based on the SE in the SIM card, possesses cross-platform attributes and good hardware versatility, effectively solving compatibility issues caused by interface differences and driver inconsistencies between traditional hardware SEs on different devices. By centrally deploying the encryption system, key protection system, and transaction authentication logic within the SE in the SIM card, the system can be quickly deployed and maintain consistent security capabilities on various models and manufacturers of mobile terminals, improving the compatibility and scalability of the transaction system 1 on the terminal side. Furthermore, this solution reduces the acquiring device's dependence on dedicated security hardware, alleviates the adaptation burden on terminal manufacturers, and provides flexible support for subsequent software iterations and vulnerability patching, thus achieving the technical effect of enhancing the system's cross-platform adaptability while ensuring high security.
[0068] Figure 2A flowchart illustrating the point-of-sale (POS) payment method provided in this application embodiment. Figure 1 Applied to merchant terminals, the methods include:
[0069] S21, responding to the device binding operation performed by the acquiring user between the acquiring software and the back-end terminal, activates the point of sale terminal function.
[0070] In this embodiment, device binding and function activation are initiated by the acquiring user on the merchant terminal through the acquiring software, establishing a communication relationship with the backend terminal to complete the registration, identification, and function activation of the merchant terminal. The acquiring software acts as a communication bridge between the merchant terminal and the backend terminal, responding to the acquiring user's binding request and coordinating with multiple information sources to collect data, which is then sent to the backend terminal via the communication link for subsequent binding processing. Upon receiving the device binding request, the backend terminal establishes an association between the merchant terminal and the user's identity based on the information uploaded by the acquiring software. Through the interaction between the acquiring user and the backend terminal, the merchant terminal's identity is confirmed, and its registration process in the point-of-sale acquiring system is completed, thus officially enabling the point-of-sale terminal's functions.
[0071] S22 reads the foreign card information to be traded through the near-field communication module, and reads the software operating environment information and the transaction verification information to be verified by the user identification module through the acquiring software.
[0072] In this embodiment, the reading of foreign card information is performed by the near-field communication module. This module uses a sensing method based on a contactless communication protocol to read data from the bank card or other payment card in close proximity after a transaction request is initiated. This data includes structured information identifying the payment account, whose source is unforgeable, and serves as evidence to establish the correspondence between the cardholder and the transaction. Software operating environment information is collected locally in real time by the acquiring software. The acquiring software calls the underlying interfaces of the terminal operating system or embedded security detection components to obtain relevant information such as the current device status and debugging configuration. This information reflects the credibility of the current transaction execution environment and serves as input for subsequent transaction security strategy decisions. Transaction verification information originates from the user identification module. The acquiring software obtains pre-configured or dynamically generated authentication-related data from this module through a preset data interaction mechanism. This data includes information related to the user's identity or session link, used for subsequent consistency judgment and key synchronization operations in the encryption module or authentication process. The user identification module, as a controlled information source, ensures the integrity and credibility of this data source. This embodiment achieves comprehensive data construction in the transaction preparation stage by aggregating information from three sources: payment medium, operating environment, and user identity. This provides support for subsequent execution data encryption, identity authentication, and transaction decisions. Through the effective combination of multi-source data, joint identification of the transaction source, execution carrier, and terminal status is achieved, enhancing the security closed-loop capability of the entire transaction chain.
[0073] S23, through the user identification module, encrypts the foreign card information to be traded, the transaction verification information, and the software operating environment information to obtain transaction security encrypted information.
[0074] In this embodiment, the merchant terminal has completed the acquisition of the required encrypted data, including the foreign card information to be transacted read from the near-field communication module, the operating environment information collected by the acquiring software, and the transaction verification information to be read from the user identification module by the acquiring software. This data covers the payment medium itself, the terminal's operating status, and the authentication context. To prevent leakage, tampering, or replay of this information during transmission, encryption must be performed locally immediately after data generation, ensuring that the encryption key is generated and used only within controlled hardware to prevent key leakage or falling into an untrusted environment. The encryption operation is implemented through the user identification module, which has local encryption capabilities and a key management mechanism. When called by the acquiring software, the data to be encrypted is passed through a preset instruction channel (e.g., a dedicated secure interface or a controlled command set), and a transaction-level key for encryption is generated internally within the module. For example, the key is dynamically derived based on internal counting parameters, device identifier, and authentication status, and is used only for the current transaction during the key's lifecycle. The data encryption process is completed internally within the module; the merchant terminal cannot directly access the key or intermediate data, ensuring that the key remains physically isolated at all times.
[0075] After encryption, the user identification module outputs the encrypted result as encrypted information. This transaction security encryption information encapsulates encrypted content including the foreign card information to be transacted, the transaction verification information, and the operating environment information, possessing the characteristics of structural integrity, data trustworthiness, and traceable data source. The acquiring software uses this encrypted information as one of the fields in the transaction message for subsequent transmission, without processing the plaintext data, effectively reducing the problem of data exposure on the terminal side. This embodiment achieves encrypted isolation of transaction data and pre-encryption of the link by completing local encryption processing of data in the user identification module, ensuring tamper-proof and strong correlation characteristics during subsequent transmission, authentication, and authorization processes.
[0076] S24, in response to the transaction operation initiated by the acquiring user in the acquiring software, generates transaction request information.
[0077] In this embodiment, when an acquiring user initiates a transaction in the acquiring software, the merchant terminal generates transaction request information based on this operation. This transaction request information serves as a trigger signal for the transaction process, primarily carrying parameters related to the transaction intent, such as transaction amount, transaction time, transaction type, merchant identifier, and terminal identifier. This indicates that the user is conducting a transaction and is used by the backend terminal for subsequent identification and processing. It is important to emphasize that the transaction request information does not contain encrypted data; its purpose is to clearly define the basic business parameters and execution instructions of the transaction, ensuring the initiation of the subsequent transaction process. This method is applicable to various acquiring terminal platforms, and the generation of basic request instructions can be completed without the involvement of additional security hardware, ensuring that the transaction maintains good platform adaptability and processing flexibility even under high security requirements.
[0078] S25, the transaction request information and transaction security encryption information are sent to the back-end terminal, so that the back-end terminal can make security decisions based on the transaction security encryption information through the encryption module and security authentication module, obtain the transaction security detection result, and when the security detection result is detected as normal, perform the transaction operation according to the transaction request information to obtain the transaction result.
[0079] In this embodiment, the acquiring software sends the constructed transaction request information and transaction security encryption information to the back-end terminal. The encryption and security authentication modules built into the back-end terminal perform data parsing and transaction security analysis to determine whether the transaction can be allowed to execute. If security conditions are met, subsequent transaction operations are completed, and the final transaction result is output. Specifically, firstly, the acquiring software uniformly encapsulates the transaction request information and transaction security encryption information and sends it to the back-end terminal through a preset secure communication protocol. This communication process can employ encrypted transmission protocols such as Transport Layer Security (TLS) to ensure the confidentiality and integrity of information during network transmission. The transaction request information includes the user-initiated transaction instruction, timestamp, user identification, device identification, and other auxiliary parameters. The transaction security encryption information is composed of the encryption processing results of the user identification module based on the foreign card information to be transacted, the transaction verification information, and the software operating environment information. For example, it includes dynamically generated key derivation results (such as KSN), environmental feature digests, and device fingerprints.
[0080] After receiving the above information, the backend terminal first decrypts the encrypted transaction information using the encryption module, extracting the original data or encrypted digest. This decryption process is generally based on a symmetric encryption algorithm (such as AES) or a transaction key derived from the DUKPT algorithm, ensuring the uniqueness and consistency of the restored ciphertext data. The decrypted data is then subjected to multi-dimensional verification by the security authentication module. This module can embed a rule matching engine, device identification algorithm, and environmental behavior model to comprehensively analyze whether there are security issues in the current transaction, such as device changes, abnormal logins, or tampering with the operating environment. Through the collaborative processing of the encryption module and the security authentication module, a transaction security detection result is generated. If the detection result indicates that no abnormalities were found in the transaction behavior, that is, the security authentication module determines that the current transaction source is trustworthy and the operating environment is normal, the backend terminal triggers the downstream transaction link according to the transaction request information, calling the point-of-sale terminal module and the foreign card acquiring transaction module to complete the bank card channel connection, transaction authorization, and deduction processing, ultimately obtaining the transaction result. This embodiment realizes a closed-loop security link between the terminal and the backend, ensuring that each transaction undergoes a dual authentication mechanism of local and remote authentication, completing the actual transaction instruction execution while fully guaranteeing transaction security. By introducing end-side key control and back-end behavior recognition mechanisms, the protection capabilities against complex scenarios such as environmental anomalies have been improved, enhancing the credibility and stability of the entire point-of-sale transaction.
[0081] S26: Receive the transaction result sent by the back-end terminal through the encryption module and complete the transaction.
[0082] In this embodiment, by parsing and responding to the transaction result information returned by the backend terminal, the merchant terminal can update the transaction status in a timely manner and complete the local result display, ensuring the continuity of user experience and system interaction. The merchant terminal receives the transaction results through the acquiring software and processes them accordingly: if the transaction is successful, the acquiring software will display a success interface and can link the printing module or electronic receipt system to generate a user voucher; if the transaction fails, it will display the reason for the failure and prompt the user with optional remedial measures or retry paths. At the same time, the transaction results can also be synchronously written to the local transaction log for subsequent reconciliation, auditing, or user inquiries. This embodiment completes the transaction closed loop on the merchant terminal side by receiving and processing the transaction results, ensuring that users can know the transaction status in real time on the terminal side, improving the overall responsiveness and traceability of acquiring.
[0083] In one embodiment, the activation of the point-of-sale terminal function in step S21 above is implemented as follows. Based on the above embodiment, it includes:
[0084] S211, reads the unique mapping identifier of the acquiring user identification module through the acquiring software;
[0085] S212, in response to the account login operation performed by the acquiring user in the acquiring software, generate login request information;
[0086] S213, the login request information is sent to the back-end terminal through the acquiring software, so that the back-end terminal can complete the login through the back-end management server according to the login request information and output the acquiring user information;
[0087] S214, Receive acquiring user information sent by the back-end terminal;
[0088] S215 collects multi-dimensional information about the device through the acquiring software and sends the multi-dimensional information to the back-end terminal so that the back-end terminal can generate a device fingerprint based on the multi-dimensional information.
[0089] S216, Receive the device fingerprint sent by the backend terminal and store the device fingerprint in the user identification module;
[0090] S217: The acquiring software sends the point-of-sale terminal activation request information, device fingerprint, unique mapping identifier, and acquiring user information to the back-end terminal, so that the back-end terminal can perform binding operations through the point-of-sale terminal module and activate the point-of-sale terminal function.
[0091] In this embodiment, data interaction is established between the acquiring software and the user identification module to read the unique mapping identifier stored in the user identification module. This unique mapping identifier is unique data pre-installed in the user identification module (i.e., the SIM card) and is used to identify the one-to-one correspondence between the device and the user during the binding process. Direct reading ensures the accuracy and immutability of the mapping identifier, providing a foundation for subsequent identity binding. Subsequently, when the acquiring user logs in, the acquiring software responds by generating login request information. This login request information includes login credentials and device identification information and is sent to the backend terminal. Upon receiving the request, the backend terminal performs identity verification and login processing via the backend management server, thereby outputting the corresponding acquiring user information. This processing achieves server-side verification of user identity and synchronizes the authenticated user information to the frontend device, providing basic user identity data for subsequent binding processes.
[0092] After acquiring user information, the acquiring software collects multi-dimensional information about the device, including parameters such as device model, operating system version, hardware characteristics, geographical location, and network environment, and sends this information to the backend terminal. Based on the received device characteristic data, the backend terminal executes a device fingerprint generation algorithm to uniquely identify the device and generate a device fingerprint. The generated device fingerprint is sent to the merchant terminal and stored in the user identification module by the acquiring software, thus forming a hardware binding credential on the local device and improving the security and traceability of terminal identification. Finally, the acquiring software sends the point-of-sale terminal activation request information, device fingerprint, unique mapping identifier, and acquiring user information to the backend terminal. The backend terminal cross-verifies the above information through the point-of-sale terminal module to complete the binding operation and activate the point-of-sale terminal function. This embodiment integrates user identity, device characteristics, and the unique identifier of the SIM card to achieve terminal-user binding, ensuring the authenticity and stability of the acquiring transaction source.
[0093] In one specific embodiment, the generation of device fingerprints is described exemplarily. The acquiring software collects multi-dimensional information from the terminal device, including but not limited to hardware configuration parameters (e.g., processor model, memory capacity, storage device identifier, etc.), network parameters (e.g., MAC address, IP address, base station information, network type, etc.), and raw readings from various sensors on the device (e.g., accelerometer, gyroscope, ambient light sensor, etc.). The collected raw multi-dimensional data undergoes preprocessing operations, such as unified format conversion, outlier filtering, and timestamp standardization, to form a standardized multi-dimensional data structure.
[0094] Subsequently, key features are extracted from information across various dimensions. For example, unique identifier fields are extracted from hardware parameters, data sources with high stability are extracted from network information, and representative change curves or static state features are extracted from sensor data. These extracted features will serve as input for subsequent hash operations. Based on analytical indicators such as stability, non-forgeability, and heterogeneity of each feature, different weight values are assigned, and all features are fused using a weighted calculation method to generate a preliminary feature vector.
[0095] Feature vectors are hashed to generate encoded vectors, ensuring consistency and tamper resistance. Finally, based on a pre-defined device fingerprint generation algorithm, such as a machine learning strategy, the encoded vectors are structured to output a unique and stable device fingerprint. This device fingerprint serves not only as an identifier for the terminal but also provides accurate authentication in subsequent stages such as transaction source verification, login binding, and transaction security identification. By constructing a device fingerprint process based on multi-dimensional input, weighted fusion, and hash calculation, the security of terminal device identification is improved, and the false recognition rate is reduced.
[0096] In one embodiment, the reading of the unique mapping identifier in step S211 above will be further explained. Based on the above embodiment, it includes:
[0097] S2111, in response to the data interaction operation of the acquiring user in the acquiring software, generates identification request information;
[0098] S2112, the acquiring software sends the identifier request information to the user identification module to read the unique mapping identifier of the user identification module.
[0099] In this embodiment, in response to data interaction operations performed by the acquiring user in the acquiring software, such as login, activation, or settings operations, an identification request message for requesting a device identifier is generated. This identification request message characterizes the current terminal state and the user's interaction intent, and serves as the trigger condition for invoking the user identification module, ensuring that the initiation of the read operation has a clear business context. Subsequently, the acquiring software establishes a secure communication channel with the locally deployed user identification module based on the identification request message and sends the request message to the user identification module. The user identification module, which can be a SIM card or eSIM, parses and confirms the validity of the request after receiving the identification request message, and then extracts a unique mapping identifier pre-bound to the current device or user from its internal storage. This achieves secure reading of the locally unique mapping identifier, ensuring the independence and trustworthiness of identity recognition. This mapping identifier can be used as a marker of device identity in binding, authentication, and transaction processes, improving overall security.
[0100] For example, the acquiring software opens a channel and reads the unique mapping identifier of the SIM card after the APDU (Application Protocol Data Unit) passes the AC rule verification. Upon receiving a user's operation request, the acquiring software first constructs an APDU instruction and sends it to the user identification module through the communication interface between the terminal and the SIM card. This APDU instruction carries request information for accessing a specified secure application within the SIM card, used to obtain the unique mapping identifier. Upon receiving the instruction, the SIM card performs a security verification of the access request based on its internally configured Access Control (AC) rules. AC rules determine whether the current request has permission to access specific data elements; verification criteria may include parameters such as the type of access instruction, the caller's identity, the execution context, and the access mode (e.g., read or write). After passing the AC rule verification, the user identification module allows the access operation and opens a predefined secure channel. This secure channel can be a logical channel or an encrypted channel after key negotiation, depending on the SIM card's SE (Security Entity) configuration and security level. The acquiring software then sends a read request to the channel, and the user identification module responds and returns a unique mapping identifier stored internally.
[0101] In one embodiment, based on the above embodiments, it further includes:
[0102] S27 visualizes the transaction results so that acquiring users can view them.
[0103] In this embodiment, to enhance user interaction and transaction transparency, the transaction results returned by the backend terminal are visualized. Specifically, after receiving the transaction result, the acquiring software first parses the result data for format and semantic judgment, identifying core fields including but not limited to transaction status, transaction amount, transaction time, transaction object identifier, and transaction reference number. Subsequently, the acquiring software presents the transaction results in a graphical and structured manner on the user interface according to a preset interface template and interaction logic. For example, a successful transaction will display a green "Transaction Successful" message, along with the corresponding amount and time; a failed or abnormal transaction will display a red message indicating the reason for the failure, while guiding the user to re-initiate the operation or contact customer service for assistance. The visualized interface also allows users to click to view transaction details, copy the transaction number, or download the transaction receipt, improving ease of use. In summary, by visualizing the transaction results, acquiring users can intuitively obtain the current transaction status and specific details, enhancing the controllability and trustworthiness of the transaction process, helping to reduce operational misunderstandings, and also building a more efficient and user-friendly interaction system.
[0104] Figure 3A flowchart illustrating the point-of-sale (POS) payment method provided in this application embodiment. Figure 2 Applied to the back-end terminal, based on the above embodiments, the transaction method includes:
[0105] S31, in response to the acquiring user's device binding operation through the acquiring software, activates the point of sale terminal function.
[0106] In this embodiment, the backend terminal includes multiple functional modules, such as a backend management server, a point-of-sale (POS) terminal module, an encryption module, and a security authentication module, enabling it to perform identity verification, data processing, and function control on merchant terminals. When an acquiring user initiates a device binding operation through the acquiring software on the merchant terminal, the backend terminal receives the binding request information sent from the merchant terminal and performs identity verification to ensure that the binding operation originates from a trusted terminal. After initial verification, the backend terminal calls the binding management program through the POS terminal module to establish a one-to-one mapping relationship between the merchant terminal and the acquiring user account in the server database and updates the current terminal status to "activated." Through the binding operation between the backend terminal and the merchant terminal, the activation of the POS terminal function is completed.
[0107] S32 receives transaction request information and transaction security encryption information sent by the merchant terminal;
[0108] Specifically, the transaction request information is generated by the merchant terminal in response to the transaction operation initiated by the acquiring user in the acquiring software; the transaction security encryption information is obtained by the merchant terminal through the user identification module encrypting the foreign card information to be transacted, the transaction verification information, and the software operating environment information; the foreign card information to be transacted is read by the merchant terminal through the near-field communication module; the transaction verification information is read by the merchant terminal from the user identification module through the acquiring software; and the software operating environment information is collected in real time by the merchant terminal through the acquiring software.
[0109] In this embodiment, the merchant terminal receives transaction request information and transaction security encryption information. The transaction request information typically includes core transaction parameters such as transaction amount, transaction type, merchant identifier, and transaction timestamp. Simultaneously, to ensure the legality and credibility of the transaction's source, the merchant terminal also encrypts multiple data points through a user identification module to generate transaction security encryption information. Specifically, the foreign card information to be transacted is read by a near-field communication module (such as NFC) in the merchant terminal. This module supports near-field communication protocols such as ISO / IEC 14443, enabling secure interaction with external payment cards with RFID capabilities, such as UnionPay cards and credit cards. The transaction verification information is read internally by the acquiring software in the merchant terminal via the user identification module interface to verify the consistency between the device identity and the user identity. The software operating environment information is collected in real-time by the acquiring software to determine whether the current transaction environment is under control and trustworthy. This embodiment ensures that the back-end terminal obtains comprehensive input data before transaction execution by receiving data transmitted from the merchant terminal, and strengthens the authenticity and integrity of the data source through encryption mechanisms, establishing a reliable input foundation for subsequent security authentication and transaction execution.
[0110] S33 decrypts the encrypted transaction security information through the encryption module, and performs security decision processing based on the decrypted encrypted transaction security information through the security authentication module to obtain the transaction security detection result.
[0111] In this embodiment, the encryption module decrypts the transaction security encryption information. This transaction security encryption information is generated by the merchant terminal through the user identification module and contains data from multiple dimensions, such as the foreign card information to be transacted, the transaction verification information, and the software operating environment information. To ensure data confidentiality and tamper resistance during transmission, the encryption module typically uses a symmetric key algorithm (such as AES) or a key derivation algorithm under a two-way authentication mechanism (such as DUKPT) to securely decrypt the ciphertext. Subsequently, the decrypted plaintext data is submitted to the security authentication module for security decision processing. The security authentication module comprehensively analyzes factors such as device identity consistency and transaction environment trustworthiness to determine the security of the transaction. This embodiment, through the collaborative processing of the encryption module and the security authentication module, achieves reliable restoration and dynamic security judgment of transaction data in the background, improving the ability to detect and intercept abnormal behavior and abnormal terminal access.
[0112] S34, when the security check result indicates that the transaction is normal, perform the transaction operation according to the transaction request information and obtain the transaction result.
[0113] In this embodiment, after the security authentication module decrypts the encrypted transaction information and performs a security check, if the detection result indicates that the transaction is "normal," the transaction execution phase begins, i.e., the formal point-of-sale (POS) acquiring transaction operation is initiated to generate the final transaction result. After confirming that the transaction source is trustworthy, the device is in normal condition, and the environment has not been tampered with, the backend terminal can initiate transaction instructions to downstream transaction card channels through the POS terminal module or in collaboration with the foreign card acquiring transaction module. This process typically uses an integrated transaction interface protocol to encapsulate and transmit the transaction command format.
[0114] The specific process of a transaction includes: verifying the merchant's account status and balance, executing the fund deduction operation, initiating a transaction authorization request to the issuing bank or payment network, and recording the transaction serial number, authorization code, and fund status upon receiving a response. For transactions using overseas card channels, additional processing logic such as currency conversion and cross-border checks may also be involved. After successfully completing the fund processing, a transaction result structure is generated, including information such as transaction amount, transaction time, transaction status, reference number, and authorization code. Through the linkage control of security authentication results, it is ensured that only normal and valid transaction requests are processed and responded to, improving the stability, security, and reliable execution capability of the entire point-of-sale acquiring system in a financial transaction environment.
[0115] S35 sends the transaction result to the merchant's terminal via an encryption module to complete the transaction.
[0116] In this embodiment, after the transaction operation is completed and the transaction result is generated, the backend terminal needs to send the transaction result back to the merchant terminal to complete the closed-loop process of the point-of-sale (POS) acquiring transaction. To ensure the data security and integrity of the transaction result during transmission, the process uses an encryption module to process the transaction result before sending it to the merchant terminal, thereby achieving a secure and reliable result transmission mechanism. The encryption module can encrypt the transaction result based on a symmetric encryption mechanism (such as AES) or a key derivation mechanism (such as DUKPT). The encrypted transaction result is output by the encryption module and sent to the merchant terminal through an encrypted communication channel established with the acquiring software. This embodiment improves the overall credibility and protection capability of the POS acquiring transaction system by setting the encryption module as the channel for transmitting transaction results.
[0117] In one embodiment, the activation of the point-of-sale terminal function in step S31 above will be further described below. Based on the above embodiment, it includes:
[0118] S311, Receive login request information sent by the merchant terminal through the acquiring software, wherein the login request information is generated by the merchant terminal in response to the account login operation performed by the acquiring user in the acquiring software;
[0119] S312 completes the login process based on the login request information through the backend management server and reads the acquiring user information;
[0120] S313 sends the acquiring user information to the merchant terminal;
[0121] S314, Receive device multi-dimensional information sent by the merchant terminal, wherein the device multi-dimensional information is collected by the merchant terminal through the acquiring software;
[0122] S315 generates a device fingerprint based on multi-dimensional device information and sends the device fingerprint to the merchant terminal so that the merchant terminal can store the device fingerprint in the user identification module;
[0123] S316, receives activation request information, device fingerprint, unique mapping identifier and acquiring user information sent by the merchant terminal through the acquiring software; wherein, the unique mapping identifier is read by the merchant terminal from the acquiring user identification module through the acquiring software;
[0124] S317, bind the point of sale terminal module to enable point of sale terminal function.
[0125] In this embodiment, the backend terminal receives a login request from the merchant terminal via the acquiring software. This login request is generated by the merchant terminal in response to the acquiring user's account login operation on the acquiring software, and typically includes the username, password, verification code, and terminal device identification information entered by the acquiring user. Upon receiving the login request, the backend management server verifies the acquiring user's identity based on a pre-stored user authentication mechanism (e.g., username-password verification, two-factor authentication), and retrieves the acquiring user information bound to the currently logged-in account from the user information database, such as user ID, role, and permission level. Subsequently, the backend management server sends the acquiring user information back to the merchant terminal via the acquiring software for subsequent device binding operations. The backend terminal receives multi-dimensional device information sent by the merchant terminal via the acquiring software. This multi-dimensional information includes, but is not limited to, the device hardware serial number, operating system version, installed application list, SIM card information, and network environment parameters (such as IP address and base station ID). This information is obtained by the acquiring software and reflects the device's operating status and usage environment.
[0126] The backend terminal performs feature extraction and algorithm modeling on multi-dimensional device information, such as calculating the device fingerprint using a hash algorithm. Once generated, the device fingerprint is sent from the backend terminal to the merchant terminal, which then calls the user identification module (e.g., SIM card) interface to write the fingerprint into it, ensuring that the device fingerprint exists in trusted hardware as a binding credential for user identity and device environment in subsequent transactions. Next, the backend terminal also needs to receive activation request information, device fingerprint, unique mapping identifier, and acquiring user information sent by the merchant terminal through the acquiring software. The unique mapping identifier is read by the merchant terminal from the user identification module through the acquiring software. After completing the above information collection, the backend terminal calls the point-of-sale (POS) terminal module to perform device binding, establishing a binding relationship between the acquiring user, merchant terminal, device fingerprint, and user identification module. Upon successful binding, the POS terminal function is activated, allowing subsequent foreign card transactions. Through this binding process, closed-loop management is achieved from user authentication, device environment collection, fingerprint generation, and binding request response. By constructing a device identity trust mechanism based on multi-source information, the point-of-sale acquiring system has improved its ability to identify abnormal terminal access and account misuse, effectively enhancing the security and overall credibility of the transaction process.
[0127] In one specific embodiment, the transaction security encryption information also includes the device fingerprint; the acquiring user information includes the identity identifier of the currently logged-in user.
[0128] In this embodiment, to further enhance the integrity of transaction data and the consistency of device and user identity binding, the transaction security encryption information includes not only the foreign card information to be transacted, transaction verification information, and software operating environment information, but also the device fingerprint. The device fingerprint is an identifier generated by the backend terminal based on multi-dimensional device information collected by the merchant terminal; this identifier reflects the uniqueness of the terminal device. Incorporating the device fingerprint into the transaction security encryption information ensures that each transaction is bound to a unique device state, thereby effectively preventing issues such as abnormal terminal duplication or abnormal transactions.
[0129] Meanwhile, the acquiring user information involved in the transaction process also includes the identity identifier of the currently logged-in user. This identity identifier is the user ID or its encrypted form generated and returned to the merchant terminal by the back-end terminal after completing user login verification, used to indicate the legitimate user initiating the transaction. By embedding the currently logged-in user's identity identifier into the transaction-related data, the back-end terminal can determine whether there is any abnormal device, user replacement, or abnormal login during security authentication by combining the correspondence between the device fingerprint, unique mapping identifier, and user identity identifier. By introducing device fingerprint and user identity identifier into the encrypted transaction information, joint verification of user identity and device environment is achieved, enhancing the uniqueness and traceability of the transaction source, effectively preventing abnormal terminals or unauthorized users from triggering transaction operations, and improving the security decision-making accuracy and anti-attack capability of the point-of-sale acquiring transaction system.
[0130] Accordingly, the transaction security detection results obtained in S33 include:
[0131] S331 uses the security authentication module to detect whether a transaction source change has occurred based on the device fingerprint, unique mapping identifier, and the identity identifier of the currently logged-in user, and obtains the transaction source change result.
[0132] S332, through the security authentication module, performs transaction environment detection based on the acquiring software's operating environment information, and obtains the environment detection results;
[0133] S333, when the transaction source change result is detected as unchanged and the environment detection result is normal, the transaction is normal as the transaction security detection result;
[0134] S334, when the transaction source change result is detected as changed and / or the environment detection result is abnormal, the transaction abnormality is obtained as the transaction security detection result.
[0135] In this embodiment, a multi-parameter-based security decision-making mechanism is established to ensure the authenticity of transactions and the consistency of their sources. First, the security authentication module comprehensively compares and analyzes the device fingerprint, unique mapping identifier, and currently logged-in user identity identifier contained in the transaction's encrypted security information to determine if the transaction source has changed. By verifying the historical binding relationship between these three pieces of information and the consistency with the currently uploaded data, it can be determined whether the transaction originated from the authorized original device and the correct user, thus indicating a change in the transaction source. Second, to detect the stability and credibility of the current transaction environment, the security authentication module also analyzes the acquiring software's operating environment information. This operating environment information includes, but is not limited to, parameters such as operating system version, application signature, debugging status, and emulator identifier, to determine whether the current transaction is executed in a trusted terminal environment, thereby outputting the environment detection result.
[0136] Ultimately, the security authentication module combines the results of the two tests mentioned above for a final judgment. If the transaction source change result is unchanged and the environment detection result is normal, the transaction is deemed secure, and a "transaction normal" security detection result is output. Conversely, if the transaction source change result is detected as changed or the environment detection result is abnormal, the transaction is considered problematic, and a "transaction abnormal" security detection result is output. In summary, by jointly comparing device identity, user identity, and software operating environment, a dual security verification mechanism for the transaction source and execution environment is implemented. This enhances the defense capabilities against abnormal device access, identity impersonation, and tampering during the transaction process, ensuring the reliability and attack resistance of the acquiring transaction system in real-world commercial scenarios.
[0137] Next, in step S35, the transaction result is sent to the merchant terminal via the encryption module, including:
[0138] S351, the transaction result is sent from the point-of-sale terminal module to the encryption module;
[0139] S352 sends the transaction results to the merchant's terminal via an encryption module.
[0140] In this embodiment, the point-of-sale (POS) terminal module, as the functional unit responsible for executing and generating specific transactions, encapsulates the processed transaction results and sends them to the encryption module. The transaction results here may include information such as the transaction success or failure status code, transaction amount, response timestamp, and transaction serial number, forming a complete transaction response dataset. Upon receiving the transaction results from the POS terminal module, the encryption module immediately encrypts them. This encryption operation is based on a built-in key management mechanism and encryption protocol specifications, and can use symmetric key algorithms or algorithms based on dynamic key derivation mechanisms (such as DUKPT) to ensure that the transaction results are not tampered with or leaked during network transmission.
[0141] After encryption, the encryption module sends the encrypted transaction result back to the merchant terminal through a secure communication channel established with the merchant terminal. Upon receiving the transaction result, the merchant terminal can use its internal decryption interface (usually accessed by the acquiring software using the decryption capabilities of the user identification module) to reconstruct the plaintext transaction result and perform subsequent operations based on the result, such as displaying the interface, printing a receipt, or updating the local account status. This embodiment achieves logical decoupling of transaction execution and secure transmission by defining the functional division between the point-of-sale terminal module and the encryption module, ensuring clear responsibilities for system modules. Simultaneously, by introducing encryption during the transaction result return process, the confidentiality and integrity of the data are strengthened, effectively reducing the risk of unauthorized access to information by man-in-the-middle attacks during transmission, further enhancing the overall security level of the acquiring transaction.
[0142] In another embodiment, the method further includes: interrupting the transaction with the merchant terminal when a security check result indicates an abnormal transaction.
[0143] In this embodiment, if the detected transaction security check result indicates an anomaly, an interruption mechanism is immediately implemented to terminate the transaction process with the merchant terminal. Specifically, this transaction anomaly may be caused by various abnormal factors, including but not limited to inconsistencies between the device fingerprint and the unique mapping identifier, abnormal identity of the currently logged-in user, and deviations of transaction environment parameters from preset security thresholds. Upon detecting any of the above abnormal factors, it is determined that the transaction source is untrustworthy or the transaction environment is out of control. Therefore, the point-of-sale terminal module in the backend terminal immediately sends an instruction to interrupt the transaction to the encryption module. The encryption module then returns a control signal or status code marked "abnormal termination" to the merchant terminal. This signal can be recognized by the acquiring software in the merchant terminal and triggers an abnormal prompt process on the terminal interface, such as displaying error information, recording an abnormal log, and suspending subsequent transaction requests. By rapidly responding to abnormal results, the ability to identify dynamic anomalies and handle emergencies is enhanced, improving the prevention and control level and security of acquiring transactions.
[0144] Figure 4 This is a schematic diagram illustrating the interactive process for activating the point-of-sale (POS) terminal function as provided in this embodiment. Here, the overall activation process is outlined, serving only as a simple example. In this embodiment, the merchant terminal is a mobile device (such as a mobile phone) with payment acquiring software installed and an integrated SIM card. The backend system includes a security authentication module, a backend management server, and a POS terminal module. Specifically, it includes:
[0145] 1. The acquiring software sends a mapping identifier request to the SIM card;
[0146] 2. The SIM card returns the mapping identifier to the acquiring software;
[0147] 3. The acquiring software initiates a merchant login request to the backend management server;
[0148] 4. The backend management server returns the merchant's identity identifier (such as merchant ID) to the acquiring software;
[0149] 5. The acquiring software collects multi-dimensional device information from merchant terminals;
[0150] 6. The acquiring software requests the generation of device fingerprints from the back-end management server and submits the collected device information.
[0151] 7. The backend management server performs weighted and hashed processing to generate device fingerprints and returns the fingerprints to the merchant's terminal;
[0152] 8. The acquiring software stores the device's fingerprint on the SIM card, completing the local binding of the fingerprint with the terminal;
[0153] 9. The acquiring software sends an activation request to the point-of-sale terminal module. The request includes the device fingerprint, mapping identifier, and merchant ID.
[0154] 10. The point-of-sale terminal module completes registration and binding, and returns the binding result to the acquiring software.
[0155] Figure 5 This is a schematic diagram of the interaction flow of the transaction process provided in the embodiments of this application. Here, the transaction process is outlined as a whole, and is only a simple example. Specifically, it includes:
[0156] 1. The acquiring software sends a request to the SIM card to obtain the KSN, token, and unique mapping identifier;
[0157] 2. The SIM card returns the encrypted KSN, token, and unique mapping identifier.
[0158] 3. The acquiring software requests transaction security encryption information from the SIM card;
[0159] 4. The SIM card returns encrypted security information for DUKPT transactions;
[0160] 5. The acquiring software sends the ciphertext of the transaction to the encryption module;
[0161] 6. The encryption module decrypts the ciphertext;
[0162] 7. The encryption module sends the decrypted token, device fingerprint, SIM unique mapping identifier, etc. to the security authentication module;
[0163] 8. The security authentication module performs a check and returns the result to the encryption module to indicate whether the check was successful.
[0164] 9. The encryption module initiates a transaction request to the point-of-sale terminal module;
[0165] 10. The point-of-sale terminal module returns the transaction result to the encryption module;
[0166] 11. The encryption module returns the transaction results to the acquiring software.
[0167] Figure 6 Schematic diagram of the point-of-sale acquiring transaction device provided in the embodiments of this application Figure 1 The point-of-sale (POS) acquiring device 6 is used in merchant terminals and includes:
[0168] The first processing module 61 is used to respond to the device binding operation between the acquiring user and the back-end terminal through the acquiring software and to activate the point of sale terminal function.
[0169] The first acquisition module 62 is used to read the foreign card information to be traded through the near-field communication module, and to read the software operating environment information and the transaction verification information of the user identification module through the acquiring software;
[0170] The second acquisition module 63 is used to encrypt the foreign card information to be traded, the transaction verification information and the software operating environment information through the user identification module to obtain transaction security encrypted information.
[0171] The request generation module 64 is used to generate transaction request information in response to the transaction operation initiated by the acquiring user in the acquiring software.
[0172] The transaction request module 65 is used to send transaction request information and transaction security encryption information to the back-end terminal, so that the back-end terminal can make security decisions based on the transaction security encryption information through the encryption module and security authentication module, obtain the transaction security detection result, and when the security detection result is detected as normal, perform the transaction operation according to the transaction request information to obtain the transaction result.
[0173] The result receiving module 66 is used to receive the transaction result sent by the back-end terminal through the encryption module and complete the transaction.
[0174] Figure 7 Schematic diagram of the point-of-sale acquiring transaction device provided in the embodiments of this application Figure 2 The point-of-sale (POS) acquiring device 7 is used in the back-end terminal and includes:
[0175] The second processing module 71 is used to respond to the device binding operation performed by the acquiring user through the acquiring software and activate the point of sale terminal function.
[0176] The information receiving module 72 is used to receive transaction request information and transaction security encryption information sent by the merchant terminal. The transaction request information is generated by the merchant terminal in response to a transaction operation initiated by the acquiring user in the acquiring software. The transaction security encryption information is obtained by the merchant terminal encrypting the foreign card information to be traded, the transaction verification information, and the software operating environment information through the user identification module. The foreign card information to be traded is read by the merchant terminal through the near-field communication module. The transaction verification information is read by the merchant terminal from the user identification module through the acquiring software. The software operating environment information is collected in real time by the merchant terminal through the acquiring software.
[0177] The transaction detection module 73 is used to decrypt the transaction security encryption information through the encryption module, and to perform security decision processing based on the decrypted transaction security encryption information through the security authentication module to obtain the transaction security detection result;
[0178] The result generation module 74 is used to perform transaction operations based on the transaction request information and obtain the transaction result when the security detection result is detected as normal.
[0179] The result sending module 75 is used to send the transaction result to the merchant terminal through the encryption module to complete the transaction.
[0180] The point-of-sale (POS) acquiring device provided in this embodiment can execute the methods provided in the corresponding method embodiments described above. Its implementation principle and technical effects are similar, and will not be elaborated here.
[0181] Figure 8 A schematic diagram of the structure of the electronic device provided in this application. Figure 8 As shown, the electronic device 8 provided in this embodiment includes at least one processor 81 and a memory 82. Optionally, the electronic device 8 further includes a communication component 83. The processor 81, memory 82, and communication component 83 are connected via a bus 84.
[0182] In a specific implementation, at least one processor 81 executes computer execution instructions stored in memory 82, causing at least one processor 81 to perform the above-described method.
[0183] The specific implementation process of processor 81 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0184] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0185] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0186] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0187] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0188] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0189] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0190] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0191] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0192] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0193] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A point-of-sale (POS) payment system, characterized in that, include: Merchant terminals and back-end terminals; The merchant terminal is communicatively connected to the back-end terminal, and the merchant terminal is equipped with a near-field communication module. The merchant terminal is equipped with acquiring software and a user identification module. The back-end terminal includes a back-end management server, an encryption module, a foreign card acquiring transaction module, a point-of-sale terminal module, and a security authentication module. The foreign card acquiring transaction module is connected to the downstream transaction card channel data, the point of sale terminal module is connected to the foreign card acquiring transaction module data, the point of sale terminal module is connected to the encryption module data, the security authentication module is connected to the encryption module data, the encryption module transmits encrypted information between the acquiring software and the user identification module, and the back-end management server is connected to the merchant terminal data through the acquiring software.
2. A point-of-sale (POS) payment method, characterized in that, Applied to the merchant terminal as described in claim 1, the method includes: In response to the device binding operation performed by the acquiring user between the acquiring software and the back-end terminal, the point of sale terminal function is activated. The system reads the foreign card information to be traded through the near-field communication module, and reads the software operating environment information and the transaction verification information to be verified by the user identification module through the acquiring software. The user identification module encrypts the foreign card information to be traded, the transaction verification information, and the software operating environment information to obtain transaction security encrypted information. In response to a transaction operation initiated by the acquiring user in the acquiring software, a transaction request information is generated; The transaction request information and the transaction security encryption information are sent to the backend terminal, so that the backend terminal can perform security decision processing based on the transaction security encryption information through the encryption module and the security authentication module to obtain the transaction security detection result. When the security detection result is detected as normal, the transaction operation is performed based on the transaction request information to obtain the transaction result. The system receives the transaction result sent by the backend terminal through the encryption module and completes the transaction.
3. The method according to claim 2, characterized in that, The response to the device binding operation performed by the acquiring user between the acquiring software and the back-end terminal to activate the point-of-sale terminal function includes: The unique mapping identifier of the acquiring user identification module is read through the acquiring software; In response to the acquiring user's account login operation in the acquiring software, a login request information is generated; The login request information is sent to the back-end terminal through the acquiring software, so that the back-end terminal can complete the login through the back-end management server according to the login request information and output the acquiring user information; Receive the acquiring user information sent by the backend terminal; The acquiring software collects multi-dimensional information about the device and sends the multi-dimensional information to the back-end terminal, so that the back-end terminal can generate a device fingerprint based on the multi-dimensional information. Receive the device fingerprint sent by the backend terminal and store the device fingerprint in the user identification module; The acquiring software sends the point-of-sale terminal activation request information, the device fingerprint, the unique mapping identifier, and the acquiring user information to the back-end terminal, so that the back-end terminal can perform a binding operation through the point-of-sale terminal module and activate the point-of-sale terminal function.
4. The method according to claim 3, characterized in that, The step of reading the unique mapping identifier of the acquiring user identification module through the acquiring software includes: In response to the data interaction operations of the acquiring user in the acquiring software, an identification request information is generated; The acquiring software sends the identification request information to the user identification module to read the unique mapping identifier of the user identification module.
5. The method according to any one of claims 2 to 4, characterized in that, Also includes: The transaction results are visualized so that the acquiring user can view them.
6. A point-of-sale (POS) payment method, characterized in that, Applied to the backend terminal as described in claim 1, the method includes: The merchant terminal responds to the device binding operation performed by the acquiring user through the acquiring software and activates the point of sale terminal function. Receive transaction request information and transaction security encryption information sent by the merchant terminal; The transaction request information is generated by the merchant terminal in response to a transaction operation initiated by the acquiring user in the acquiring software. The transaction security encryption information is obtained by the merchant terminal through the encryption of the foreign card information to be transacted, the transaction verification information and the software operating environment information by the user identification module. The foreign card information to be traded is read by the merchant terminal through the near-field communication module; The transaction verification information is read by the merchant terminal from the user identification module through the acquiring software; The software operating environment information is collected in real time by the merchant terminal through the acquiring software; The transaction security encryption information is decrypted by the encryption module, and the security authentication module performs security decision processing based on the decrypted transaction security encryption information to obtain the transaction security detection result. When the security check result indicates that the transaction is normal, the transaction operation is performed according to the transaction request information to obtain the transaction result; The transaction result is sent to the merchant terminal via the encryption module to complete the transaction.
7. The method according to claim 6, characterized in that, The process of activating the point-of-sale terminal function in response to the device binding operation performed by the acquiring user through the acquiring software on the merchant terminal includes: The merchant terminal receives a login request information sent through the acquiring software, wherein the login request information is generated by the merchant terminal in response to the account login operation performed by the acquiring user in the acquiring software. The backend management server completes the login process based on the login request information and reads the acquiring user information. Send the acquiring user information to the merchant terminal; Receive device multi-dimensional information sent by the merchant terminal, wherein the device multi-dimensional information is collected by the merchant terminal through the acquiring software; Based on the multi-dimensional information of the device, a device fingerprint is generated and sent to the merchant terminal so that the merchant terminal stores the device fingerprint in the user identification module. Receive the activation request information, device fingerprint, unique mapping identifier and acquiring user information sent by the merchant terminal through the acquiring software; The unique mapping identifier is read by the merchant terminal from the acquiring user identification module through the acquiring software; Bind the device through the point-of-sale terminal module to activate the point-of-sale terminal function.
8. The method according to claim 6, characterized in that, The transaction security encryption information also includes the device fingerprint; the acquiring user information includes the identity identifier of the currently logged-in user; Accordingly, the security authentication module performs security decision processing based on the decrypted transaction security encryption information to obtain the transaction security detection result, including: The security authentication module detects whether a transaction source change has occurred based on the device fingerprint, unique mapping identifier, and the identity identifier of the currently logged-in user, and obtains the transaction source change result. The security authentication module performs transaction environment detection based on the acquiring software's operating environment information to obtain the environment detection result. When the transaction source change result is detected as unchanged and the environment detection result is normal, then the transaction is considered normal as the transaction security detection result. When the transaction source change result is detected as changed and / or the environment detection result is abnormal, the transaction abnormality is obtained as the transaction security detection result.
9. The method according to claim 6, characterized in that, Sending the transaction result to the merchant terminal via the encryption module includes: The transaction result is sent from the point-of-sale terminal module to the encryption module; The transaction result is sent to the merchant terminal via the encryption module.
10. The method according to any one of claims 6 to 9, characterized in that, Also includes: If the security check result indicates an abnormal transaction, the transaction with the merchant terminal will be interrupted.