A method and system for user privacy protection in public transportation payment
By using anonymous QR code account technology to generate anonymously assembled message data and utilizing the CL signature algorithm, the problem of insufficient user privacy protection in the public transportation payment system is solved, realizing user identity privacy protection and system security, and preventing overdraft risks.
Patent Information
- Application Number
- CN202511552984.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-29
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-10-29
AI Technical Summary
The existing public transportation payment system lacks adequate protection of user privacy, user identity information is easily tracked, data is easily leaked due to centralized storage, and there is a lack of technical safeguards, resulting in a high risk of data leakage.
Anonymous QR code account technology is used to generate and parse anonymously assembled message data through the ride code APP, user terminal and privacy protection backend, generate anonymous wallet account, complete anonymous QR code payment, and use CL signature algorithm to ensure account security and non-forgeability.
Protect user privacy, prevent payment transactions from revealing specific identities, prevent account duplication and forgery, ensure system security and payment process compatibility, and prevent overdraft risks.
Smart Images

Figure CN121032490B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security protection technology, and more specifically to a method and system for protecting user privacy in public transportation payments. Background Technology
[0002] Currently, with the development of electronic payment technology, public transportation payment systems are gradually introducing contactless payment methods such as QR code scanning and NFC card swiping, replacing traditional cash payment methods.
[0003] However, currently, public transport QR code payments generally rely on a real-name account system. Users need to bind their mobile phone number, ID card, and other information, with the mobile payment platform completing identity verification and the server handling transaction processing and data recording. While these public transport payment models are relatively simple in terms of functionality and operational management, they present problems in terms of user privacy protection. First, all payment behaviors are strongly linked to the user's real identity, allowing the platform to fully track and create precise travel profiles involving highly sensitive data such as location, time, frequency, and trajectory. Second, the system architecture is highly centralized, with user identity information and travel trajectories stored centrally. The consequences of internal data leaks or hacker attacks would be severe. Third, currently, public transport data needs to be provided to multiple government agencies for various aspects of social governance; in the future, it may also be used as a data resource for authorized use or trading. However, the lack of technical measures to protect user privacy makes data leakage risks difficult to control.
[0004] Therefore, how to provide a user privacy protection method for public transportation payment that can solve the above problems is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, the present invention provides a method and system for protecting user privacy in public transportation payments, ensuring that the payment behavior of normal users does not reveal the user's specific identity.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] A method for protecting user privacy in public transportation payments, based on a transit code app, user terminal, privacy protection backend, and code platform, includes:
[0008] Users send a request to apply for an anonymous QR code account to the ride code APP through the user terminal. The user terminal generates corresponding anonymous assembled message data and sends the anonymous assembled message data to the privacy protection backend for parsing.
[0009] The privacy protection backend receives and parses the anonymous assembled message data, generates backend response data based on the parsing result, generates corresponding privacy protection backend response data based on the backend response data, and sends the privacy protection backend response data to the ride code APP. The ride code APP requests and completes the activation of the anonymous QR code account from the code platform.
[0010] Users can click the "QR code recharge" function in the ride code APP, and at the same time query the user's anonymous account information through the user terminal. Based on the query and verification results, a corresponding anonymous wallet account is generated, and the recharge transaction is completed.
[0011] Users interact with the privacy protection backend and code platform using anonymous wallet accounts to complete anonymous QR code payment for public transportation.
[0012] Preferred options also include:
[0013] Users can use the ride code app to query and verify the transaction records of anonymous QR code accounts, and also to track abnormal anonymous QR code accounts and perform data backup and recovery functions.
[0014] Preferably, the specific process for activating an anonymous QR code account includes:
[0015] Users apply for an anonymous QR code account through the user terminal to the ride code APP. The ride code APP determines whether the user has activated the anonymous QR code account service.
[0016] If the user has not activated the service, the user's personal identification information will be collected, and corresponding user certificate secret parameters will be generated based on the user's personal identification information.
[0017] Based on the user certificate secret parameters, a corresponding certificate parameter knowledge hiding structure, a first knowledge commitment item, a first challenge value, and a first response set are constructed. The certificate parameter knowledge hiding structure, the first knowledge commitment item, the first challenge value, and the first response set are then used to generate corresponding initial anonymous assembled message data, which is sent to the privacy protection backend through the user terminal.
[0018] The privacy protection backend parses and reconstructs the initial anonymous assembled message data, recalculates the second challenge value, and compares the second challenge value with the first challenge value;
[0019] When the second challenge value is the same as the first challenge value, the CL signature algorithm is used to generate a CL signature result for the user certificate secret parameter.
[0020] The privacy protection backend constructs a privacy structure for subsequent tracking, generates a unique user ID corresponding to the privacy structure, and stores the correspondence between the user ID and the privacy structure;
[0021] The privacy protection backend sends the user ID and CL signature result to the user terminal to form a message response data. The user terminal parses and verifies the message response data and sends the verification result to the ride code APP.
[0022] The ride code app requests the anonymous QR code account activation service from the code platform.
[0023] Preferably, the specific process for completing the activation of an anonymous QR code account also includes:
[0024] The user terminal parses the message response data and verifies the signature result using the CL signature result and the user certificate secret parameters;
[0025] When the verification is successful, the client uses the CL signature result and the user certificate secret parameter to generate an anonymous certificate and saves the anonymous certificate locally. At the same time, the client returns the user ID to the ride code APP.
[0026] The ride code APP assembles an anonymous QR code account opening notification message and uses the assembled anonymous QR code account opening notification message to request the QR code activation service from the code platform;
[0027] The code platform parses the anonymous QR code account opening notification message to determine whether the anonymous QR code account opening notification message is for an anonymous QR code account;
[0028] When the code platform determines that the account is anonymous, it searches the database for an activation record based on the user ID.
[0029] Read the configuration records related to the anonymous QR code account, set the code type field value, and insert the record into the database table. After the code platform operation is successful, assemble the activation success message and return the result to the APP; otherwise, return the activation failure message.
[0030] Preferably, the specific process of generating the corresponding anonymous wallet account based on the query-proof result and completing the recharge transaction includes:
[0031] Verify whether a user has a current anonymous wallet account by querying locally on the user's device.
[0032] If it does not exist, the current anonymous wallet account is set to zero, and the first challenge random number is requested from the privacy protection backend through the user client. The first knowledge commitment structure set is constructed using the anonymous certificate, and then the first knowledge commitment item set is constructed using the first knowledge commitment structure set and the user certificate secret parameter.
[0033] The user client uses the current anonymous wallet account, the first challenge random number, the first knowledge commitment structure set, the user certificate secret parameters, and the first knowledge commitment item set to construct the first knowledge signature challenge value and the second response set, and sends the first knowledge signature challenge value and the second response set to the privacy protection backend;
[0034] The privacy protection backend compares the first challenge random number with the first knowledge signature challenge value. If they are the same, the privacy protection backend uses the CL signature algorithm to sign the user certificate secret parameter, establishes the relationship between the user and the current anonymous wallet account, and sends the signature result back to the user to generate the anonymous wallet account.
[0035] Preferably, the specific process of determining whether to generate a corresponding anonymous wallet account based on the query-proof results also includes:
[0036] If a current anonymous wallet account exists, the user can choose to establish a new anonymous wallet account linked to the current anonymous wallet account using a zero-knowledge method, complete the account transfer, and set the status of the original anonymous wallet account to canceled.
[0037] Preferably, the specific process for providing anonymous QR code top-up services to anonymous wallet accounts includes:
[0038] When a current anonymous wallet account exists, the user can choose to transfer the balance of the current anonymous wallet account to a new anonymous wallet account;
[0039] The client verifies the legitimacy of the current anonymous wallet account and requests a second challenge random number from the privacy protection backend. It then constructs a second knowledge commitment structure set using the anonymous certificate, and constructs a second knowledge commitment item set using the second knowledge commitment structure set and the user certificate secret parameters. Finally, it constructs a second knowledge signature challenge value and a third response set using the second challenge random number, the second knowledge commitment structure set, the user certificate secret parameters, and the second knowledge commitment item set. This generates a first authentication sequence number and a first non-standard zero-knowledge proof response data. The client then sends a message consisting of the second challenge random number, the first authentication sequence number, the first non-standard zero-knowledge proof response data, the second knowledge commitment structure set, the second knowledge commitment item set, the signature result, and the third response set to the privacy protection backend.
[0040] The privacy protection backend parses the message data and performs a duplicate check on the first authentication sequence number. If it is not duplicated, the privacy protection backend parses and reconstructs the second challenge random number to obtain the corresponding third challenge random number.
[0041] Determine if the second challenge random number is the same as the third challenge random number. If they are the same, use the CL signature algorithm to sign the user certificate secret parameter. Privacy protection background query - prove anonymous wallet account record;
[0042] The fourth challenge value is generated using the anonymous wallet account query-proof result, and the anonymous wallet account query-proof result, the fourth challenge value, and the user certificate secret parameters are combined to form a third response privacy set.
[0043] The privacy protection backend uses a third-party response privacy collection request to complete the recharge service.
[0044] Preferably, the specific processing steps for completing anonymous QR code payment for public transportation include:
[0045] When a user clicks the QR code display function in the ride code APP, the ride code APP will determine whether there are any incomplete recharge transactions.
[0046] If no user requests a fifth challenge random number from the privacy protection backend, the third knowledge commitment structure set is constructed using an anonymous certificate, the third knowledge commitment item set is constructed using the third knowledge commitment structure set and the user certificate secret parameters, the third knowledge signature challenge value and the fourth response set are constructed using the fifth challenge random number, the third knowledge commitment structure set, the user certificate secret parameters and the third knowledge commitment item set, and the second authentication sequence number and the second non-standard zero-knowledge proof response data are generated.
[0047] Finally, the user sends a message consisting of the fifth challenge random number, the second authentication serial number, the second non-standard zero-knowledge proof response data, the third knowledge commitment structure set, the third knowledge commitment item set, and the fourth response set to the privacy protection backend to request the QR code authentication service.
[0048] The privacy protection backend parses the message data and performs a duplicate check on the second authentication serial number. If the second authentication serial number is found to have been used, the user's behavior is in violation and the violation tracking process is triggered. Otherwise, the privacy protection backend reconstructs the fourth response set to obtain the sixth challenge random number. If the fifth challenge random number is consistent with the sixth challenge random number, the privacy protection backend obtains the corresponding anonymous wallet account.
[0049] The privacy protection backend stores anonymous wallet account query records and inserts authentication records into the authentication record table of the privacy protection backend. It uses the CL signature algorithm to sign the third knowledge commitment item set and the anonymous wallet account, and sends the message data composed of the signature result and the second authentication sequence number to the user terminal.
[0050] The client parses the received message data and verifies the signature result using the signature result, the user certificate secret parameters, and the anonymous wallet account. When the verification is successful, the client updates and saves the original anonymous certificate using the signature result and sends the second authentication serial number, the verification result, and the payment account corresponding to the anonymous wallet account to the ride code APP.
[0051] The ride code APP assembles an anonymous code request message {sequence, acctype, bizid}, which consists of the second authentication serial number, account type, and merchant number, respectively. At the same time, it uses the anonymous QR code request message to request anonymous code data from the code platform.
[0052] The code platform parses the anonymous code request message, determines whether the ride code type is anonymous based on the account type in the message, and if so, the code platform looks up the corresponding anonymous wallet account ID in the authentication record table based on the second authentication serial number, saves the anonymous code QR code request record and the application response message, and returns it to the ride code APP.
[0053] The ride code app assembles a QR code based on the QR code data message. The user displays the anonymous code to the in-vehicle mobile POS machine, which verifies the platform signature and data legality in the QR code. If the verification is successful, the scan payment is valid.
[0054] This invention also provides a system for protecting user privacy in public transportation payments, based on a transit code app, a user terminal, and a privacy protection backend, including:
[0055] The sending module is used for users to send a request to apply for an anonymous QR code account to the ride code APP through the user terminal, generate corresponding anonymous assembled message data on the user terminal, and send the anonymous assembled message data to the privacy protection backend for parsing;
[0056] The activation module is used to receive and parse the anonymous assembled message data in the privacy protection backend, generate backend response data based on the parsing result, generate corresponding privacy protection backend response data based on the backend response data, and send the privacy protection backend response data to the ride code APP. The ride code APP requests and completes the activation of the anonymous QR code account from the code platform.
[0057] The query-proof module is used by users to click the "QR code recharge" function in the ride code APP, and at the same time query-proof the user's anonymous account information through the user terminal, and generate the corresponding anonymous wallet account based on the query-proof results;
[0058] The processing module is used to generate an anonymous wallet account after the user uses the anonymous QR code account and recharge request to generate the corresponding message response privacy set, and to complete the anonymous QR code recharge service. It is also used by the user to complete the anonymous QR code payment transaction by using the anonymous wallet account, QR code display request, and displaying the QR code to the vehicle-mounted mobile POS machine.
[0059] As can be seen from the above technical solution, compared with the prior art, the present invention discloses a method and system for protecting user privacy in public transportation payment, which has the following beneficial effects:
[0060] 1. Protect user privacy and ensure that the payment behavior of normal users does not reveal the user's specific identity; users can choose the non-linkability of their recharge behavior, that is, there is an implicit link between the anonymous wallet account of the same user and the unique registered account that can be proven with zero knowledge, and multiple anonymous wallet accounts can be chosen not to be associated with each other;
[0061] 2. When a user illegally copies another person's identity to make a payment, their identity can be deanonymized to ensure compliance with the management requirements of public transport cards.
[0062] 3. System security: User-registered anonymous accounts and wallet accounts cannot be forged or copied, and account balances cannot be falsified, ensuring that user-registered accounts and wallet accounts are not misused; ensuring that delayed settlements can be deducted, and ensuring the balance of system accounts.
[0063] 4. The QR code payment process, architecture, and hardware requirements of this invention are compatible with the current real-name payment system. Account copying and use will automatically cancel its anonymity attribute. Unlike electronic cash payment methods, accounts cannot be linked, which not only ensures user privacy but also effectively prevents overdraft risks caused by bus screenshot payments and delayed settlement in one-way communication, limited communication volume, and distributed offline payment scenarios. Attached Figure Description
[0064] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0065] Figure 1 This invention provides an overall flowchart of a user privacy protection method for public transportation payments.
[0066] Figure 2 This is a schematic diagram of the anonymous QR code account service activation process provided in an embodiment of the present invention;
[0067] Figure 3 This is a schematic diagram of the anonymous QR code account recharge process provided in an embodiment of the present invention;
[0068] Figure 4 This is a schematic diagram of the anonymous QR code account scanning payment process provided in an embodiment of the present invention;
[0069] Figure 5 This is a schematic diagram of the anonymous QR code account transaction record query-proof process provided in an embodiment of the present invention;
[0070] Figure 6This is a schematic diagram illustrating anonymous QR code account violation tracking provided in an embodiment of the present invention;
[0071] Figure 7 This is a schematic diagram of the anonymous QR code account backup business process provided in an embodiment of the present invention;
[0072] Figure 8 This is a schematic diagram of the anonymous QR code account recovery process provided in an embodiment of the present invention;
[0073] Figure 9 This invention provides a structural principle block diagram of a system for protecting user privacy in public transportation payments. Detailed Implementation
[0074] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0075] See Figure 1 As shown, this embodiment of the invention provides a user privacy protection method for public transportation payments, implemented based on a transit code APP, a user terminal, a privacy protection backend, and a code platform, including:
[0076] Users send a request to apply for an anonymous QR code account to the ride code APP through the user terminal. The user terminal generates corresponding anonymous assembled message data and sends the anonymous assembled message data to the privacy protection backend for parsing.
[0077] The privacy protection backend receives and parses the anonymous assembled message data, generates backend response data based on the parsing result, generates corresponding privacy protection backend response data based on the backend response data, and sends the privacy protection backend response data to the ride code APP. The ride code APP requests and completes the activation of the anonymous QR code account from the code platform.
[0078] Users can click the "QR code recharge" function in the ride code APP, and at the same time query-proof the user's anonymous account information through the user terminal, and generate the corresponding anonymous wallet account based on the query-proof results;
[0079] Users interact with the privacy protection backend and code platform using anonymous wallet accounts to complete anonymous QR code payment for public transportation.
[0080] In one specific embodiment, it also includes:
[0081] Users can use the ride code app to query and verify the transaction records of anonymous QR code accounts, and also to track abnormal anonymous QR code accounts and perform data backup and recovery functions.
[0082] In one specific embodiment, see Figure 2 As shown, the specific process for opening an anonymous QR code account includes:
[0083] Users apply for an anonymous QR code account through the user terminal to the ride code APP. The ride code APP determines whether the user has activated the anonymous QR code account service.
[0084] If the user has not activated the service, the user's personal identification information will be collected, and the corresponding user certificate secret parameter θ will be generated based on the user's personal identification information.
[0085] Construct the corresponding certificate parameter knowledge hiding structure J1, J2=cst(θ) based on the user certificate secret parameter θ, and the first knowledge commitment term d. J1 ,d J2 =ckc(θ), first challenge value c, first response set S=ccr(d J1 ,d J2, θ), and hide the certificate parameter knowledge structure J1,J2=cst(θ), and the first knowledge commitment item d J1 ,d J2 =ckc(θ), first challenge value c, first response set S=ccr(d J1 ,d J2, θ) Generate the corresponding initial anonymous assembled message data, and send it through the user terminal to the privacy protection backend;
[0086] The privacy-protected backend parses and reconstructs the initial anonymously assembled message data, and recalculates the second challenge value. And compare the second challenge value with the first challenge value;
[0087] When the second challenge value When the first challenge value c is the same, the CL signature algorithm is used to generate a CL signature result for the user certificate secret parameter. ;
[0088] The privacy protection backend constructs a privacy structure for subsequent tracking, generates a unique user ID corresponding to the privacy structure, and stores the correspondence between the user ID and the privacy structure;
[0089] The privacy protection backend will store the user ID and CL signature result. The message response data J=csst(J1,ε) is sent to the user terminal. The user terminal parses and verifies the message response data and sends the verification result to the ride code APP.
[0090] The ride code app requests the anonymous QR code account activation service from the code platform.
[0091] In one specific embodiment, the specific process for activating an anonymous QR code account further includes:
[0092] The user terminal parses the message response data and verifies the signature result using the CL signature result and the user certificate secret parameter θ.
[0093] When the verification is successful, the client uses the CL signature result and the user certificate secret parameter θ to generate an anonymous certificate ancert=gen(ε,θ), and saves the anonymous certificate ancert=gen(ε,θ) locally. At the same time, the client returns the user ID to the ride code APP.
[0094] The ride code APP assembles an anonymous QR code account opening message and uses the assembled anonymous QR code account opening message to request the QR code activation service from the code platform. The message includes the following main fields {userid,acctype,unionopen,subcardtype,apparea,biz_id}, which are, in order, userid, account type (fixed value N), joint activation status (fixed value N), subcard type (fixed value 00), area code (fixed value FF), and merchant number.
[0095] The platform parses the anonymous QR code account opening notification message and determines whether the anonymous QR code account opening notification message is for an anonymous QR code account. The determination is based on the account type field acctype in the message to determine whether the transit code type is an anonymous QR code account. If acctype=N, the anonymous QR code account opening process is executed; otherwise, the normal transit cloud card opening process is executed.
[0096] When the code platform determines that a QR code account is anonymous, it searches the database for an activation record based on the user ID.
[0097] Read the configuration records related to the anonymous QR code account, set the code type field value, and insert the record into the database table. After the code platform operation is successful, assemble the activation success message and return the result to the APP; otherwise, return the activation failure message.
[0098] Specifically, the anonymous QR code account activation process also includes the following steps:
[0099] 1. The code platform checks the database to see if a record exists based on the user ID;
[0100] 2. Read the configuration records related to the anonymous QR code account, set the code type field value to N, and insert the record into the database table;
[0101] 3. After the code platform operation is successful, it will assemble a successful activation message and return to the APP; otherwise, it will return an activation failure message.
[0102] In one specific embodiment, see Figure 3 As shown, the specific process for providing anonymous QR code recharge service includes:
[0103] Users can click the "Anonymous QR Code Account Top-up" function in the ride code APP, select the top-up amount and top-up method, and then execute the deduction process; otherwise, the deduction process will be executed again.
[0104] In one specific embodiment, the process of providing anonymous QR code top-up service to anonymous wallet accounts includes:
[0105] When a current anonymous wallet account exists, the user's account balance will be transferred to the new anonymous wallet account.
[0106] The user verifies the legitimacy of the current anonymous wallet account and requests a second challenge random number from the privacy protection backend. It then constructs a second knowledge commitment structure set using the anonymous certificate, followed by a second knowledge commitment item set using the second knowledge commitment structure set and the user certificate secret parameter θ. Finally, it constructs a second knowledge signature challenge value and a third response set using the second challenge random number, the second knowledge commitment structure set, the user certificate secret parameter θ, and the second knowledge commitment item set, generating the first authentication sequence number SN= f ( The user client sends a message consisting of a second challenge random number, a first authentication sequence number, the first non-standard zero-knowledge proof response data, a second knowledge commitment structure set, a second knowledge commitment item set, a signature result, and a third response set to the privacy protection backend. The calculation of R uses a non-exponential pseudo-random function (i.e., the exponent of SN) instead of the knowledge commitment random number. f ( ) is a provable pseudo-random function;
[0107] The privacy protection backend parses the message data and performs a duplicate check on the first authentication sequence number. If it is not duplicated, the privacy protection backend parses and reconstructs the second challenge random number to obtain the corresponding third challenge random number. If the SN is found to be an already used authentication sequence number, the user's behavior is in violation, and the violation tracking process is triggered.
[0108] Determine if the second challenge random number is the same as the third challenge random number. If they are the same, use the CL signature algorithm to sign the user certificate secret parameter θ. Privacy protection background query - prove anonymous wallet account record;
[0109] The fourth challenge value is generated using the anonymous wallet account query-proof result, and the anonymous wallet account query-proof result, the fourth challenge value, and the user certificate secret parameter θ are combined to form the third response privacy set;
[0110] The privacy protection backend uses a third-party response privacy collection request to complete the recharge service.
[0111] For details, see Figure 4 As shown, the specific process of anonymous QR code account scanning payment includes:
[0112] When a user clicks the "QR code display" function in the ride code APP, the ride code APP will query and verify the recharge status. If there are any incomplete recharges, the user will be directed to the anonymous QR code account recharge service.
[0113] After the recharge is completed, the client requests a challenge random number to randomize the challenge c in the knowledge signature, making it unpredictable. At the same time, the client uses an anonymous certificate to construct a knowledge commitment structure set and a knowledge commitment item set, and generates an authentication sequence number SN and a non-standard zero-knowledge proof response R.
[0114] Users construct a set of challenges and responses for knowledge signatures using anonymous wallet account B, challenge random numbers, a set of knowledge commitment structures, a set of secret parameters, and a set of knowledge commitment items on the user's end.
[0115] The user client sends a message to the privacy protection backend requesting QR code authentication service, consisting of the current anonymous wallet account B, the challenge random number, the authentication serial number SN, the non-standard zero-knowledge proof response R, the knowledge commitment structure set, the knowledge commitment item set, the knowledge signature challenge, and the knowledge signature response set.
[0116] The ride code APP performs a duplicate check on the authentication serial number SN. If the SN is found to be a used authentication serial number, the user's behavior is considered to be in violation, triggering the violation tracking process. Otherwise, the commitment value is reconstructed and the challenge value is recalculated. This is because the number of authentication serial numbers SN is limited.
[0117] If the two are the same, it means that the knowledge signature is valid. Use the current anonymous wallet account B to query the proof database record, get the accountid corresponding to B, and insert the authentication record into the authentication record table. The corresponding relationship is {B, accountid, SN, R, c, sequence}, where sequence is a unique authentication sequence number starting with NM, which is generated by trigger plus sequence. A new sequence will be generated each time the request code is authenticated.
[0118] The secret parameter is signed using the CL signature algorithm, and the CL signature result and sequence are assembled into a message response and sent to the user terminal.
[0119] The client parses the data responded by the privacy protection backend, uses the signature result, local secret parameters and the current anonymous wallet account B to verify the signature result. If the verification result is correct, the signature and the original anonymous certificate are used to update and save the data locally, and the authentication result and payment account sequence are returned to the APP.
[0120] The ride code APP determines the status based on the query-proof results. If there is an error, it will prompt the user with an error message. Otherwise, the ride code APP will assemble an anonymous QR code account request message, which includes the following main fields {squence, acctype, bizid}, which are the authentication serial number, account type (fixed value N), and merchant number, respectively.
[0121] The ride code app parses the anonymous QR code account request message and determines whether the ride code type is an anonymous QR code account based on the Acctype field in the message. If acctype=N, the anonymous QR code account request process is executed; otherwise, the normal request process is executed. The specific process of the anonymous QR code account request process includes:
[0122] The system searches for the corresponding accountid in the authentication record table based on the sequence. If no record is found, authentication fails, and an error message is returned. Otherwise, it queries the anonymous wallet account of the verified user based on the accountid to check if a corresponding anonymous wallet account opening record exists. If no record exists, an error message is returned; otherwise, the anonymous QR code account request code record is saved.
[0123] The assembly of the QR code data request response message mainly includes the following fields {qrcode, time}, and is returned to the ride code APP. The ride code APP assembles the QR code based on the QR code data message.
[0124] Users present their anonymous QR code accounts to the in-vehicle mobile POS machine. The in-vehicle mobile POS machine verifies the platform signature and data legitimacy in the QR code. If the verification is successful, the scan payment is valid. The in-vehicle mobile POS machine periodically sends the locally generated anonymous QR code account transaction data to the clearing server for clearing.
[0125] See Figure 5 As shown, the specific process of querying and verifying transaction records of anonymous QR code accounts includes:
[0126] When a user clicks the "Transaction Inquiry - Proof" function in the ride code APP, the user's client requests a challenge random number from the privacy protection backend, and uses an anonymous certificate to construct a knowledge commitment structure set, a knowledge commitment item set, an authentication serial number SN, and a non-standard zero-knowledge proof response R;
[0127] The user client uses the current anonymous wallet account B, a challenge random number, a set of knowledge commitment structures, a set of secret parameters, and a set of knowledge commitment items to construct a challenge and response set for a knowledge signature. This message is then sent to the privacy protection backend to request the transaction record query-proof authentication service.
[0128] The app parses the request message and performs a duplicate check on the authentication sequence number (SN). If the SN is found to be a previously used authentication sequence number, the user's behavior is considered a violation, triggering the violation tracking process. Otherwise, the commitment value is reconstructed and the challenge value is recalculated. If the two are the same, the knowledge signature is considered valid.
[0129] Use the current anonymous wallet account B to query the database record, obtain the accountid corresponding to B, sign the secret parameter using the CL signature algorithm, and assemble the CL signature result and accountid into a message response to the App;
[0130] The app determines the status based on the query-proof result. If an error is found, the app displays an error message to the user. The app assembles an anonymous QR code account transaction record query-proof message, including the following main fields {accountid, acctype, bizid}, and uses the anonymous QR code account transaction record query-proof message to request an anonymous QR code account transaction record query-proof from the code platform. The query-proof process for anonymous QR code account transaction records is the same as the aforementioned process.
[0131] In a specific embodiment, the process of determining whether to generate a corresponding anonymous wallet account based on the query-proof result includes:
[0132] Verify whether the user's current anonymous wallet account B exists by querying locally on the user's client.
[0133] If it does not exist, set B to zero for the current anonymous wallet account, and request a first challenge random number from the privacy protection backend via the user client. The first challenge random number is used to randomize the challenge c in the knowledge signature to make it unpredictable. The first knowledge commitment structure set is constructed using the anonymous certificate ancert. Then, the first knowledge commitment item set is constructed using the first knowledge commitment structure set and the user certificate secret parameter θ. ;
[0134] The user client uses the current anonymous wallet account, the first challenge random number challenge, the first knowledge commitment structure set, the user certificate secret parameter θ, and the first knowledge commitment item set to construct the first knowledge signature challenge value and the second response set. The first knowledge signature challenge value and the second response set are sent to the privacy protection backend.
[0135] The privacy protection backend compares the first challenge random number challenge with the first knowledge signature challenge value. If the two are the same, the privacy protection backend uses the CL signature algorithm to sign the user certificate secret parameter θ, establishes the relationship between the user and the current anonymous wallet account, and sends the signature result back to the user to generate the anonymous wallet account.
[0136] In one specific embodiment, the process of determining whether a corresponding anonymous wallet account needs to be generated based on the query-proof result further includes:
[0137] If a current anonymous wallet account exists, a new anonymous wallet account is established and associated with the current anonymous wallet account using zero-knowledge methods to complete the account transfer, and the status of the original anonymous wallet account is set to canceled.
[0138] For details, see Figure 6 As shown, the specific process of anonymous QR code account violation tracking includes:
[0139] When performing authentication for recharge, QR code payment, or record query-proof business, the user terminal generates a knowledge signature and knowledge commitment, calculates the authentication sequence number SN and a non-standard zero-knowledge proof response R, assembles the message, and sends it to the privacy protection backend.
[0140] The privacy protection backend queries and verifies the authentication records in the user's current wallet based on the SN sent by the user. If the SN does not exist, the authentication is stored in the database (storing the SN and the corresponding R). Otherwise, if the user violates the rules—for example, by copying and using someone else's account—the privacy protection backend can lock the offending user's anonymous wallet account B (suspending all its functions).
[0141] Copying another person's account deprives the payment process of uniqueness, thus making the challenge-response equations for the knowledge proof constructed from user parameters solvable. The privacy protection backend recalculates the equations based on the non-standard zero-knowledge proof challenge responses from the two authentication records.
[0142] The corresponding user ID is retrieved based on the calculation and returned to the back-end management platform.
[0143] The system retrieves the user's real-name information based on their user ID, thus deanonymizing the account. The user is then notified that their account is locked.
[0144] See Figures 7-8 As shown, the specific steps for backing up and restoring anonymous QR code accounts include:
[0145] The ride code app obtains the user's mobile phone number and certificate encryption password and sends them to the user's device.
[0146] The client executes the authentication process and reads the locally stored anonymous certificate ancert;
[0147] The user terminal uses the mobile phone number msisdn and the password pw to generate a symmetric encryption key, and uses the SM4 national cryptographic algorithm to symmetrically encrypt the anonymous certificate ancert.
[0148] The user assembles the backup message, the ride code APP parses and saves the backup, and stores the correspondence between the mobile phone number msisdn and the chiper.
[0149] The ride code app assembles a response message and sends it to the user's device. The user's device then returns a backup status to the app.
[0150] The specific process for restoring services to anonymous QR code accounts:
[0151] The ride code APP obtains the user's mobile phone number and certificate encryption password, and transmits the mobile phone number msisdn and password pw to the user's terminal;
[0152] The user-side assembles a recovery request message, the main field of which is the mobile phone number (MSID).
[0153] The privacy protection backend parses the request message, locates the corresponding encrypted anonymous certificate chiper based on the phone number, sets the backup record to unavailable, and assembles and restores the response message.
[0154] The user client uses the mobile phone number msisdn and password pw to generate a symmetric encryption key, and uses the SM4 national cryptographic algorithm to symmetrically decrypt the anonymous certificate ancert. The user client saves the anonymous certificate ancert to the local machine and returns the recovery status to the ride code APP. The ride code APP displays that the account has been restored to a usable status.
[0155] Specifically, the process of completing the recharge service also includes:
[0156] The ride code APP determines the status based on the query-proof results. If there is an error, it will prompt the user with an error message. Otherwise, the ride code APP assembles an anonymous QR code account recharge message, which includes the following main fields {acctype, accountB1, accountB}, which are the account type (fixed value N), the original wallet account of the anonymous QR code account, and the new wallet account of the anonymous QR code account, respectively.
[0157] The ride code app uses an anonymous QR code account recharge message to request anonymous QR code account recharge service from the platform.
[0158] The platform parses the anonymous QR code account recharge message and determines whether the ride code type is an anonymous QR code account based on the account type field Acctype in the message. If acctype=N, the anonymous QR code account recharge process is executed; otherwise, the cloud card recharge process is executed.
[0159] The platform checks if the original anonymous wallet account value is 0. If the result is yes, it inserts an account record into the user's anonymous wallet account table, with the balance equal to the recharge amount, and establishes a mapping between the current anonymous wallet account B, its corresponding accountid, and its balance. If the result is 1, it searches the user's anonymous wallet account table, finding the original account record and registering its balance. It then inserts a new record into the user's anonymous wallet account table, including the current anonymous wallet account B and its corresponding accountid, with the account balance equal to the recharge amount plus the original anonymous wallet account's balance, and sets the original anonymous wallet's status to "cancelled."
[0160] The platform saves the recharge record, assembles the relevant status information message, and returns it to the ride code APP.
[0161] See Figure 9 As shown, this embodiment of the invention also provides a system for protecting user privacy in public transportation payments using any of the above embodiments, implemented based on a transit code APP, a user terminal, and a privacy protection backend, including:
[0162] The sending module is used for users to send a request to apply for an anonymous QR code account to the ride code APP through the user terminal, generate corresponding anonymous assembled message data on the user terminal, and send the anonymous assembled message data to the privacy protection backend for parsing;
[0163] The activation module is used to receive and parse the anonymous assembled message data in the privacy protection backend, generate backend response data based on the parsing result, generate corresponding privacy protection backend response data based on the backend response data, and send the privacy protection backend response data to the ride code APP. The ride code APP requests and completes the activation of the anonymous QR code account from the code platform.
[0164] The query-proof module is used by users to click the "QR code recharge" function in the ride code APP, and at the same time query-proof the user's anonymous account information through the user terminal, and generate the corresponding anonymous wallet account based on the query-proof results;
[0165] The processing module is used to generate an anonymous wallet account after the user uses the anonymous QR code account and recharge request to generate the corresponding message response privacy set, and to complete the anonymous QR code recharge service. It is also used by the user to complete the anonymous QR code payment transaction by using the anonymous wallet account, QR code display request, and displaying the QR code to the vehicle-mounted mobile POS machine.
[0166] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.
[0167] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for protecting user privacy in public transportation payment, based on a ride code APP, a user terminal, a privacy protection background and a code platform, characterized in that, The application comprises the following steps: The user sends an application for an anonymous two-dimensional code account to the ride code APP through the user terminal, and the corresponding anonymous assembly message data is generated on the user terminal and sent to the privacy protection background for analysis; The privacy protection background receives and analyzes the anonymous assembly message data, generates background response data according to the analysis result, generates corresponding privacy protection background response data according to the background response data, and sends the privacy protection background response data to the ride code APP, and the ride code APP requests and completes the opening of the anonymous two-dimensional code account, the specific process comprising: The user applies for an anonymous two-dimensional code account through the user terminal, and the ride code APP judges whether the user has opened the anonymous two-dimensional code account service; If the user has not opened it, the user's personal identification information is collected, and the corresponding user certificate secret parameter is generated according to the user's personal identification information; The corresponding certificate parameter knowledge hiding structure, the first knowledge commitment item, the first challenge value, and the first response set are constructed according to the user certificate secret parameter, and the certificate parameter knowledge hiding structure, the first knowledge commitment item, the first challenge value, and the first response set are generated into the initial anonymous assembly message data, which is sent to the privacy protection background through the user terminal; The privacy protection background analyzes and reconstructs the initial anonymous assembly message data, and re-computes the second challenge value, and compares the second challenge value with the first challenge value; When the second challenge value is the same as the first challenge value, the CL signature algorithm is used to generate the CL signature result of the user certificate secret parameter; The privacy protection background constructs a privacy structure for subsequent tracking, generates a user ID uniquely corresponding to the privacy structure, and stores the corresponding relationship between the user ID and the privacy structure; The privacy protection background sends the user ID and the CL signature result to the user terminal, and the user terminal analyzes and verifies the message response data, and sends the verification result to the ride code APP; The ride code APP requests the opening of the anonymous two-dimensional code account service from the code platform; The user clicks the "two-dimensional code recharge" function in the ride code APP, and queries the user anonymous account information through the user terminal, generates the corresponding anonymous wallet account according to the query-proof result, and completes the recharge business, the specific process comprising: Querying whether the current anonymous wallet account exists through the user terminal; If it does not exist, set the current anonymous wallet account to zero, request a first challenge random number from the privacy protection background through the user terminal, construct a first knowledge commitment structure set using the anonymous certificate, and then construct a first knowledge commitment item set using the first knowledge commitment structure set and the user certificate secret parameter; The user terminal constructs a first knowledge signature challenge value and a second response set using the current anonymous wallet account, the first challenge random number, the first knowledge commitment structure set, the user certificate secret parameter, and the first knowledge commitment item set, and sends the first knowledge signature challenge value and the second response set to the privacy protection background; The privacy protection background compares the first challenge random number with the first knowledge signature challenge value. If the two are the same, the privacy protection background uses the CL signature algorithm to sign the user certificate secret parameter, establishes the relationship between the user and the current anonymous wallet account, and responds the signature result to the user end to generate the anonymous wallet account. The user uses the anonymous wallet account to interact with the privacy protection background and the code platform to complete the anonymous code scanning and bus payment business.
2. The method for user privacy protection in public transportation payment according to claim 1, characterized in that, Further comprising: The user queries and proves the anonymous two-dimensional code account transaction record through the bus code APP, and can also realize the abnormal anonymous two-dimensional code account tracking business and the data backup and recovery function.
3. The method for user privacy protection in public transportation payment according to claim 1, characterized in that, The specific processing process for completing the opening of the anonymous two-dimensional code account further comprises: The user end analyzes the message response data, uses the CL signature result to verify the signature result of the user certificate secret parameter; When the verification is passed, the user end generates an anonymous certificate using the CL signature result and the user certificate secret parameter, saves the anonymous certificate locally, and returns the user ID to the bus code APP; The bus code APP assembles the anonymous two-dimensional code account opening message and requests the two-dimensional code opening service from the code platform using the assembled anonymous two-dimensional code account opening message; The code platform analyzes the anonymous two-dimensional code account opening message and determines whether the anonymous two-dimensional code account opening message is an anonymous two-dimensional code account; When the code platform determines that it is an anonymous two-dimensional code account, the code platform searches the database for an opening record according to the user ID, reads the anonymous two-dimensional code account related configuration record, sets the code type field value, and inserts a record in the database table. After the code platform operation is successful, the opening success message is assembled and the result is returned to the APP. Otherwise, the opening failure message is returned.
4. The method for user privacy protection in public transportation payment according to claim 1, characterized in that, The specific processing process for determining whether to generate the corresponding anonymous wallet account according to the query and proof result further comprises: If there is a current anonymous wallet account, the association between the new anonymous wallet account and the current anonymous wallet account is established through a zero-knowledge method, the account transfer is completed, and the state of the original anonymous wallet account is set to be cancelled.
5. The method for user privacy protection in public transportation payment according to claim 4, characterized in that, The specific process of the anonymous wallet account for the anonymous code scanning and recharging service comprises: When there is a current anonymous wallet account, the user end transfers the balance of the current anonymous wallet account to a new anonymous wallet account; The user end verifies the legality of the current anonymous wallet account, requests a second challenge random number from the privacy protection background, constructs a second knowledge commitment structure set using the anonymous certificate, constructs a second knowledge commitment item set using the second knowledge commitment structure set and the user certificate secret parameter, constructs a second knowledge signature challenge value and a third response set using the second challenge random number, the second knowledge commitment structure set, the user certificate secret parameter, and the second knowledge commitment item set, generates a first authentication serial number and a first non-standard zero-knowledge proof response data, and finally sends the second challenge random number, the first authentication serial number, the first non-standard zero-knowledge proof response data, the second knowledge commitment structure set, the second knowledge commitment item set, the signature result, and the third response set to the privacy protection background. The privacy protection background analyzes the message data, repeatedly checks the first authentication serial number, and if the first authentication serial number is not repeated, the privacy protection background analyzes and reconstructs the second challenge random number to obtain the corresponding third challenge random number; It is judged whether the second challenge random number and the third challenge random number are consistent, if consistent, the CL signature algorithm is used to sign the user certificate secret parameter, and the privacy protection background queries the anonymous wallet account record; The fourth challenge value is generated by using the anonymous wallet account query-proof result, and the anonymous wallet account query-proof result, the fourth challenge value, and the user certificate secret parameter form a third response privacy set; The privacy protection background requests to complete the recharge service by using the third response privacy set.
6. The method for user privacy protection in public transportation payment according to claim 5, characterized in that, The specific processing process of completing the anonymous code scanning bus payment business includes: The user clicks the two-dimensional code display function in the bus code APP, and the bus code APP judges whether there is an unfinished recharge service; If there is no user end to request the fifth challenge random number from the privacy protection background, a third knowledge commitment structure set is constructed using the anonymous certificate, a third knowledge commitment structure set is constructed using the anonymous certificate, a third knowledge commitment item set is constructed using the third knowledge commitment structure set and the user certificate secret parameter, a third knowledge signature challenge value and a fourth response set are constructed using the fifth challenge random number, the third knowledge commitment structure set, the user certificate secret parameter and the third knowledge commitment item set, a second authentication serial number and a second non-standard zero-knowledge proof response data are generated; Finally, the user end sends the fifth challenge random number, the second authentication serial number, the second non-standard zero-knowledge proof response data, the third knowledge commitment structure set, the third knowledge commitment item set, and the fourth response set to the privacy protection background to request a code scanning authentication service; The privacy protection background analyzes the message data, repeatedly checks the second authentication serial number, and if the second authentication serial number is not repeated, the privacy protection background analyzes and reconstructs the second challenge random number to obtain the corresponding third challenge random number; The privacy protection background stores the anonymous wallet account query record, and inserts an authentication record in the authentication record table of the privacy protection background, signs the third knowledge commitment item set and the anonymous wallet account using the CL signature algorithm, and sends the signature result and the second authentication serial number to the user end as message data; The user end analyzes the received message data, uses the signature result, the user certificate secret parameter, and the anonymous wallet account to verify the signature result, and when the verification is passed, the user end updates and saves the original anonymous certificate using the signature result, and sends the second authentication serial number, the verification result, and the payment account corresponding to the anonymous wallet account to the bus code APP; The bus code APP assembles an anonymous code request message {sequence, acctype, bizid}, which is the second authentication serial number, the account type, and the merchant number in sequence, and requests anonymous code data from the code platform using the anonymous two-dimensional code request message. The code platform analyzes the anonymous code request message, judges whether the ride code type is an anonymous code according to the account type in the message, if yes, the code platform finds the corresponding anonymous wallet account ID in the authentication record table according to the second authentication serial number, saves the anonymous code two-dimensional code request record and the application response message and returns to the ride code APP; The ride code APP assembles the two-dimensional code according to the two-dimensional code data message, the user shows the anonymous code to the vehicle mobile POS machine, the vehicle mobile POS machine verifies the code platform signature and data legality in the two-dimensional code, and if the verification is passed, the code scanning payment is valid.
7. A system for protecting user privacy in public transportation payment using the method of any one of claims 1-6, based on a ride code APP, a user terminal and a privacy protection background. Comprise: The sending module is used for sending an application anonymous two-dimensional code account request to the ride code APP through a user terminal, generating corresponding anonymous assembly message data on the user terminal and sending the anonymous assembly message data to the privacy protection background for analysis; The opening module is used for receiving and analyzing the anonymous assembly message data by the privacy protection background, generating background response data according to the analysis result, generating corresponding privacy protection background response data according to the background response data, and sending the privacy protection background response data to the ride code APP, and the ride code APP requests and completes the opening of the anonymous two-dimensional code account to the code platform; The query-proof module is used for clicking the "two-dimensional code recharge" function in the ride code APP, querying and proving the user anonymous account information through the user terminal, and generating the corresponding anonymous wallet account according to the query-proof result; The processing module is used for generating the anonymous wallet account by the user using the anonymous two-dimensional code account and the recharge request to generate the corresponding message response privacy set, and completing the anonymous code scanning recharge service; and is used for completing the anonymous code scanning payment business by the user using the anonymous wallet account, the two-dimensional code display code request and showing the two-dimensional code to the vehicle mobile POS machine.
Citation Information
Patent Citations
Double-blind privacy protection method and system in compact electronic cash scheme
CN115170103A
Two-dimensional code generation method and system for realizing user anonymity and clone behavior detection
CN115471940A