Contactless payment methods and systems, electronic devices and storage media
By verifying the consistency of identity and timestamps between the terminal and the gate, the security deficiencies in the contactless payment process are resolved, achieving higher security and reliability while avoiding hardware cost and universality issues.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 深圳市深圳通有限公司
- Filing Date
- 2026-01-06
- Publication Date
- 2026-05-05
AI Technical Summary
Existing contactless payment methods have security deficiencies during the interaction between the terminal and the gate, especially in terms of information security risks at the level of trusted device identity verification. They are difficult to achieve two-way trusted verification, and have high hardware costs, poor versatility, and poor deployment flexibility.
By obtaining the terminal identification information and the first key, the gate signature verification and timestamp consistency verification are performed, including signature verification, time digest operation and data consistency verification, to ensure the two-way identity and timestamp consistency between the terminal and the gate, and reduce the risk of impersonation by counterfeit devices and replay attacks.
It improves the security of the contactless payment process, reduces the risk of counterfeit devices impersonating others and replay attacks, and enhances the security and reliability of the payment process.
Smart Images

Figure CN121482882B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of public transportation technology, and in particular to a contactless payment method and system, electronic device and storage medium. Background Technology
[0002] In the field of public transportation technology, users typically need to actively hold a terminal device equipped with a virtual transit card close to the gate at both the entrance and exit points to complete the payment via short-range wireless communication. However, this payment method has its limitations, such as the virtual transit card requiring a real-time internet connection to be displayed, and the need for users to actively operate the terminal device.
[0003] Currently, smart gates can proactively discover and connect to nearby terminal devices, and these devices can automatically respond and invoke the payment module. For this type of terminal device, the smart gate and the terminal device can automatically sense and establish a communication connection, allowing users to complete seamless payments without manual intervention. It should be understood that this method of establishing a communication connection is not natively supported on Android or iOS devices due to ecosystem isolation and permission restrictions.
[0004] It is worth noting that this method of establishing communication connections still has information security risks at the level of device identity verification. For example, it may be susceptible to man-in-the-middle attacks or spoofed gate attacks, thereby reducing the security of the contactless payment process. Therefore, how to further improve the security of the contactless payment process while achieving it is an urgent problem to be solved in the industry. Summary of the Invention
[0005] The main objective of this application is to propose a contactless payment method and system, electronic device and storage medium, which aims to improve the security of the contactless payment process.
[0006] To achieve the above objectives, a first aspect of this application proposes a contactless payment method applied to a target terminal device, the method comprising:
[0007] Obtain the terminal identification information and the first key;
[0008] Receive gate signature information from the target gate and verify the gate signature information to obtain signature verification result information;
[0009] In response to the signature verification result information satisfying the preset signature verification pass condition, the terminal mark timestamp is determined, and a digest operation is performed on the preset time window and the terminal mark timestamp according to the first key symbol to obtain time digest data;
[0010] The time summary data and the terminal identification information are sent to the target gate so that the target gate generates a gate mark timestamp and performs data consistency verification based on the time summary data, the terminal identification information and the gate mark timestamp to obtain consistency verification result information.
[0011] In response to the consistency verification result information satisfying the preset consistency verification pass condition, the billing information is received from the target gate, and contactless payment is performed based on the billing information.
[0012] In some embodiments, the step of performing a digest operation on a preset time window and the terminal-marked timestamp based on the first key symbol to obtain time digest data includes:
[0013] The time stamp of the terminal is time-quantized according to a preset time window to obtain a time counting factor;
[0014] The time count factor is hashed based on the first key symbol to obtain the time digest data.
[0015] In some embodiments, the step of performing a hash operation on the time counter factor based on the first key symbol to obtain the time digest data includes:
[0016] The time counter factor is hashed based on the first key symbol to obtain candidate digest data;
[0017] The candidate summary data is truncated to obtain truncated summary data;
[0018] The extracted summary data is processed by format conversion to obtain the time summary data.
[0019] In some embodiments, the step of performing a hash operation on the time counter factor based on the first key symbol to obtain the time digest data includes:
[0020] The time counting factor is subjected to modulo operation to obtain the time modulo value;
[0021] A second key is obtained by generating a key based on the time modulus and the first key symbol.
[0022] The time counting factor is hashed using the second key to obtain the time digest data.
[0023] In some embodiments, the step of verifying the signature information of the gate to obtain signature verification result information includes:
[0024] The signature information of the gate is verified to obtain the signature verification result information.
[0025] The signature status of the gate signature information is verified to obtain the status verification result information;
[0026] The signature validity period of the gate signature information is verified to obtain the validity period verification result information;
[0027] The signature verification result information is determined based on the trusted verification result information, the status verification result information, and the validity period verification result information.
[0028] To achieve the above objectives, a second aspect of this application proposes another contactless payment method applied to a target turnstile, the method comprising:
[0029] The gate signature information is sent to the target terminal device so that the target terminal device can verify the gate signature information and obtain the signature verification result information.
[0030] In response to the signature verification result information satisfying the preset signature verification pass condition, time digest data and terminal identification information are received from the target terminal device; wherein, the time digest data is generated by the target terminal device after performing a digest operation on the preset time window and the terminal mark timestamp according to the first key symbol, the first key symbol and the terminal identification information are obtained by the target terminal device, and the terminal mark timestamp is generated by the target terminal device;
[0031] Determine the gate marking timestamp, and perform data consistency verification based on the time summary data, the terminal identification information, and the gate marking timestamp to obtain consistency verification result information;
[0032] In response to the consistency verification result information satisfying the preset consistency verification pass condition, the billing information is sent to the target terminal device so that the target terminal device can make contactless payment based on the billing information.
[0033] In some embodiments, before sending the gate signature information to the target terminal device, the method further includes:
[0034] The target terminal device is subjected to distance detection to obtain the measured distance value;
[0035] When the measured distance value is less than or equal to a preset distance threshold, the gate signature information is sent to the target terminal device.
[0036] To achieve the above objectives, a third aspect of this application proposes a contactless payment system applied to a target terminal device, the system comprising:
[0037] The data acquisition unit is used to acquire terminal identification information and the first key symbol;
[0038] The signature verification unit is used to receive gate signature information from the target gate, and to perform signature verification on the gate signature information to obtain signature verification result information;
[0039] The digest operation unit is used to determine the terminal mark timestamp in response to the signature verification result information satisfying the preset verification pass condition, and to perform digest operation processing on the preset time window and the terminal mark timestamp according to the first key symbol to obtain time digest data;
[0040] The data sending unit is used to send the time summary data and the terminal identification information to the target gate, so that the target gate generates a gate mark timestamp, and performs data consistency verification based on the time summary data, the terminal identification information and the gate mark timestamp to obtain consistency verification result information;
[0041] The contactless payment unit is used to receive billing information from the target gate in response to the consistency verification result information meeting the preset consistency verification pass conditions, and to perform contactless payment based on the billing information.
[0042] To achieve the above objectives, a fourth aspect of the present application provides an electronic device, the electronic device including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the methods described in the first and second aspects.
[0043] To achieve the above objectives, a fifth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods described in the first and second aspects.
[0044] The contactless payment method, system, electronic device, and storage medium proposed in this application are applied to a target terminal device. They acquire terminal identification information and a first key symbol; then receive gate signature information from the target gate and verify the signature information to obtain a signature verification result; next, in response to the signature verification result satisfying a preset signature verification pass condition, a terminal-marked timestamp is determined, and a digest operation is performed on a preset time window and the terminal-marked timestamp based on the first key symbol to obtain time digest data; further, the time digest data and terminal identification information are sent to the target gate, causing the target gate to generate a gate-marked timestamp, and data consistency verification is performed based on the time digest data, terminal identification information, and gate-marked timestamp to obtain a consistency verification result; finally, in response to the consistency verification result satisfying a preset consistency verification pass condition, billing information is received from the target gate, and contactless payment is performed based on the billing information. In this way, two-way identity and timestamp consistency verification between the terminal and the gate can be achieved, reducing the risk of impersonation by counterfeit devices and replay attacks, thus improving the security of the contactless payment process. Attached Figure Description
[0045] Figure 1 This is a flowchart of a contactless payment method provided in an embodiment of this application;
[0046] Figure 2 yes Figure 1 A flowchart of step S103 in the process;
[0047] Figure 3 yes Figure 2 A flowchart of step S202 in the process;
[0048] Figure 4 yes Figure 2 Another flowchart of step S202 in the process;
[0049] Figure 5 yes Figure 1 A flowchart of step S102 in the process;
[0050] Figure 6 This is another flowchart of the contactless payment method provided in the embodiments of this application;
[0051] Figure 7 yes Figure 6 A flowchart of the steps preceding step S601;
[0052] Figure 8 This is a flowchart illustrating a specific implementation of the contactless payment method provided in this application.
[0053] Figure 9 This is a schematic diagram of the structure of the contactless payment system provided in the embodiments of this application;
[0054] Figure 10 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0056] It should be noted that although functional modules are divided in the system diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0058] First, let's analyze some of the terms used in this application:
[0059] Terminal device: refers to a portable electronic device with near-field communication capability. For example, a terminal device can be a user's mobile phone or a smart wearable watch, and there is no specific limitation.
[0060] A turnstile (or turnstile) is a channel control device deployed at the entrances and exits of subways or buses, which issues billing instructions via wireless communication. It should be noted that the turnstile in this application can actively discover and connect to nearby terminal devices, and the terminal devices can automatically respond and invoke the payment module for contactless payment. For example, both the turnstile and the terminal devices can be equipped with the HarmonyOS system, utilizing its distributed soft bus device virtualization capabilities and seamless discovery and connection functions. Relying on HarmonyOS's more controllable and stable permission management mechanism (i.e., "background keep-alive" and "interfaceless authorization"), after the user's initial authorization, subsequent operations do not require further confirmation via pop-up windows, thus achieving contactless payment. It should be understood that this method of establishing communication connections is currently not natively supported in Android or iOS system terminal devices due to ecosystem isolation and permission restrictions.
[0061] Seamless payment refers to the process where, when a user takes a vehicle, the terminal device deducts the fare using a pre-stored payment voucher without requiring any additional user interaction.
[0062] The widespread application of contactless payment methods has provided technical support for rapid passage and settlement in the field of public transportation technology, effectively improving payment efficiency and reducing queuing time. However, existing contactless payment methods still have insufficient security issues during the interaction between the terminal and the gate. For example, related technologies typically use gates equipped with the HarmonyOS system to automatically connect with terminal devices, thereby directly realizing contactless payment. However, this method of establishing a communication connection still has information security risks at the device identity trust verification level, making it difficult to perform two-way trust verification between the two parties, thus reducing the security of contactless payment. Alternatively, related technologies can also achieve contactless payment by additionally equipping the gate and terminal devices with a specific UWB chip. However, although this method can perform two-way trust verification between the two parties through the chip, the chip increases hardware costs and maintenance workload, and it also requires the user's terminal device to be equipped with the chip, reducing the versatility and deployment flexibility of the solution. Based on this, embodiments of this application provide a contactless payment method and system, electronic device, and storage medium, aiming to achieve contactless payment while further improving the security of the contactless payment process.
[0063] The contactless payment method provided in this application relates to the field of public transportation technology. The contactless payment method provided in this application can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the contactless payment method, but is not limited to the above forms.
[0064] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0065] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirects to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0066] Figure 1 This is an optional flowchart of the contactless payment method provided in the embodiments of this application. Figure 1 The method described above is applied to the target terminal device, and the method may include, but is not limited to, steps S101 to S105:
[0067] Step S101: Obtain terminal identification information and first key symbol;
[0068] Step S102: Receive the gate signature information from the target gate, and verify the gate signature information to obtain the signature verification result information;
[0069] Step S103: In response to the signature verification result information satisfying the preset signature verification pass condition, determine the terminal mark timestamp, and perform digest operation processing on the preset time window and the terminal mark timestamp according to the first key to obtain time digest data;
[0070] Step S104: Send the time summary data and terminal identification information to the target gate so that the target gate generates a gate mark timestamp and performs data consistency verification based on the time summary data, terminal identification information and gate mark timestamp to obtain consistency verification result information;
[0071] Step S105: In response to the consistency verification result information meeting the preset consistency verification pass conditions, receive billing information from the target gate and make contactless payment based on the billing information.
[0072] Steps S101 to S105, as illustrated in this embodiment, are applied to a target terminal device. The device acquires terminal identification information and a first key symbol; then, it receives gate signature information from the target gate and verifies the signature information to obtain a signature verification result. Next, in response to the signature verification result satisfying a preset signature verification pass condition, it determines a terminal-marked timestamp and performs a digest operation on a preset time window and the terminal-marked timestamp based on the first key symbol to obtain time digest data. Furthermore, it sends the time digest data and terminal identification information to the target gate, enabling the target gate to generate a gate-marked timestamp. Based on the time digest data, terminal identification information, and gate-marked timestamp, it performs data consistency verification to obtain a consistency verification result. Finally, in response to the consistency verification result satisfying a preset consistency verification pass condition, it receives billing information from the target gate and performs contactless payment based on the billing information. This enables two-way identity and timestamp consistency verification between the terminal and the gate, reducing the risk of impersonation by counterfeit devices and replay attacks. Therefore, this application can improve the security of the contactless payment process.
[0073] In step S101 of some embodiments, the target terminal device may refer to the terminal device performing the contactless payment interaction. For example, the target terminal device may be a mobile phone or a smart wearable watch, and there is no specific limitation. The terminal identification information may refer to the encoded information allocated by the cloud server to the target terminal device for identifying the identity of the target terminal device. For example, the terminal identification information may be "zhongduan0001" or "zhongduanA001", and there is no specific limitation. The first key symbol may refer to the key allocated by the cloud server to the target terminal device for subsequent digest operation processing. For example, the first key symbol may be "Key_zhongduan123" or "Key_zhongduan23ab", and there is no specific limitation.
[0074] In step S102 of some embodiments, the target gate can refer to a channel control device that interacts with the target terminal device for contactless payment. For example, the target gate can be a subway station gate or a bus stop gate, and the specific designation is not limited. It should be noted that in the embodiments of this application, the target gate and the target terminal device can automatically sense each other and establish a communication connection, allowing the user to complete contactless payment without active operation. The gate signature information can refer to the credential information jointly generated based on the device identifier, preset key, and signature data of the target gate. For example, the gate signature information can be generated by concatenating the device identifier, preset key, and signature data according to predetermined rules through a cloud server when the target gate is manufactured or deployed; or, the gate signature information can also be generated by performing an XOR operation on the device identifier, preset key, and signature data through a cloud server when the target gate is manufactured or deployed. It is understood that the generation method of the gate signature information can be adjusted according to actual needs, and the gate signature information is pre-stored in the target gate.
[0075] It should be noted that the device identifier can refer to the device number pre-assigned to the target gate at the factory or during deployment. For example, the device identifier can be "zhajiA001" or "zhaji0001", without specific limitations. The pre-set key can refer to a key pre-assigned to the target gate at the factory or during deployment. For example, the pre-set key can be "Key_zhajiABC" or "Key_zhajiAbc", without specific limitations. The signature data can refer to the signature value pre-assigned to the target gate at the factory or during deployment. For example, the signature data can be "Sign_zhaji123" or "Sign_zhaji456", without specific limitations.
[0076] Signature verification refers to the data processing procedure of validating the legitimacy of signature information on a turnstile and outputting a quantitative result. The signature verification result information refers to the information obtained after signature verification, used to determine whether the turnstile's identity is trustworthy. For example, the signature verification result information can be "0" or "1", where "0" indicates verification failure and "1" indicates verification success; or, the signature verification result information can be "FALSE" or "TRUE", where "FALSE" indicates verification failure and "TRUE" indicates verification success. It is understood that the specific values and meanings of the signature verification result information can be adjusted according to actual needs.
[0077] It should be noted that the cloud server in this embodiment can pre-allocate device identifiers, preset keys, and signature data for the target gate and back them up. The target terminal device can then verify the gate signature information by having the cloud server recalculate a reference value using the same generation method as the gate signature information, and compare this reference value with the received gate signature information. Alternatively, the cloud server can decrypt the gate signature information using the same preset key as the target gate, and then compare the decrypted device identifier, preset key, and signature data with the backed-up data. The specific implementation method of signature verification can be adjusted according to actual needs.
[0078] In step S103 of some embodiments, the preset signature verification pass condition may refer to pre-selected information used to indicate the trustworthiness of the gate's identity. For example, if the signature verification result information is "0" or "1", then the preset signature verification pass condition is "1"; or, if the signature verification result information is "FALSE" or "TRUE", then the preset signature verification pass condition is "TRUE". If the signature verification result information meets the preset signature verification pass condition, that is, the signature verification result information is the same as the preset signature verification pass condition, then the terminal timestamp is determined. The terminal timestamp may refer to the time information recorded on the terminal side used to mark the current moment. For example, if the current time is XXXX year XX month XX day 10:00:00, the terminal marker timestamp can be a Unix timestamp, that is, the number of seconds from a specific time to XXXX year XX month XX day 10:00:00, which can be represented as "1698393600"; or, if the current time is XXXX year XX month XX day 16:00:00, the terminal marker timestamp can also be "XXXXXXXX160000", without any specific limitation. The preset time window can refer to the length of a pre-selected time interval. For example, the preset time window can be "30 seconds" or "40 seconds", without any specific limitation. Digest processing can refer to the process of performing a hash operation on the preset time window and the terminal marker timestamp using a specific hash algorithm based on the first key. The time digest data can refer to the hash value obtained after digest processing, used for subsequent consistency verification. For example, time digest data can be obtained by first normalizing the terminal's timestamp through a preset time window, and then hashing the normalized time quantization data using a key-based hash message authentication code (HMAC-SHA1) algorithm based on the first key. Alternatively, time digest data can also be obtained by hashing the normalized time quantization data using a cryptographic hash algorithm (SM3). Understandably, the time digest data generation method can be adjusted according to actual needs.
[0079] It should be noted that if the signature verification result does not meet the preset signature verification pass conditions, that is, the signature verification result is different from the preset signature verification pass conditions, it means that the gate identity has not passed the trusted verification. The target terminal device will terminate the subsequent contactless payment process and can choose to discard the received gate signature information. The cloud server can record the abnormal event and report it.
[0080] In step S104 of some embodiments, after sending the time summary data and terminal identification information to the target gate, the target gate can generate a gate-marked timestamp. The gate-marked timestamp can refer to time information recorded on the gate side to mark the current moment. It should be noted that the generation principle of the gate-marked timestamp is the same as that of the terminal-marked timestamp. Then, the target gate can perform data consistency verification based on the gate-marked timestamp, the received terminal identification information, and the time summary data to obtain consistency verification result information. The data consistency verification can refer to the data processing process of performing a digest operation on the gate-marked timestamp using the same digest operation processing method as the target terminal device, generating time summary data on the gate side, comparing it with the received time summary data, and outputting a quantization result. For example, data consistency verification can be achieved by the target gate obtaining a first key symbol and a preset time window corresponding to the target terminal device from the cloud server based on the terminal identification information. Then, the preset time window and the terminal are timestamped according to the first key symbol, and the same digest operation is performed on the target terminal device to obtain the time digest data on the gate side. This data is then compared with the received time digest data. Alternatively, data consistency verification can also be achieved by the target gate sending the gate-marked timestamp, the received terminal identification information, and the time digest data to the cloud server. The cloud server then obtains a first key symbol and a preset time window corresponding to the target terminal device based on the terminal identification information. The preset time window and the terminal are timestamped according to the first key symbol, and the same digest operation is performed on the target terminal device to obtain the time digest data on the gate side. This data is then compared with the received time digest data.
[0081] It should be noted that the gate marker timestamp and terminal marker timestamp in this embodiment are obtained independently from both ends, resulting in a slight clock offset due to communication delay. Therefore, this embodiment aligns the two timestamps to the same preset time window and normalizes them before generating the time summary data. This ensures that as long as the difference falls within the window range, the normalized time values are the same, and the calculated time summary data will remain consistent, thus guaranteeing the effectiveness of subsequent consistency verification.
[0082] Consistency verification result information refers to information obtained after data consistency verification, used to indicate whether the time summary data at both ends of the target terminal device and the target gate are consistent. For example, consistency verification result information can be "0xFF" or "0x00", where "0x00" indicates data inconsistency and "0xFF" indicates data consistency; or, consistency verification result information can be "F" or "T", where "F" indicates data consistency and "T" indicates data inconsistency. It is understood that the specific values and meanings of consistency verification result information can be adjusted according to actual needs.
[0083] In step S105 of some embodiments, the preset consistency verification pass condition may refer to pre-selected information used to indicate data consistency. For example, if the consistency verification result information can be "0xFF" or "0x00", then the preset consistency verification pass condition is "0xFF"; or, if the consistency verification result information can be "F" or "T", then the preset consistency verification pass condition is "F". If the consistency verification result information meets the preset consistency verification pass condition, that is, the consistency verification result information is the same as the preset consistency verification pass condition, billing information is received from the target gate, and contactless payment is performed according to the billing information. The billing information may refer to data generated by the target gate that describes the cost of this passage. It should be noted that if the application scenario of the contactless payment method in this embodiment is when a user passes through a subway gate, the user's target terminal device needs to complete a signature verification and data consistency verification when entering or exiting the subway gate, i.e., two-way authentication between the gate and the terminal. In this case, the billing information is the fare for the section between entering and exiting the station. Alternatively, if the application scenario of the contactless payment method in this embodiment is when a user passes through a bus gate, the user's target terminal device only needs to complete a signature verification and data consistency verification once when boarding the bus. In this case, the billing information is the fare for a single ride. It should be noted that the method of generating billing information in this solution can be adjusted according to the application scenario.
[0084] Please see Figure 2 In some embodiments, step S103, which involves performing a digest operation on the preset time window and the terminal marker timestamp based on the first key symbol to obtain time digest data, may include, but is not limited to, steps S201 to S202:
[0085] Step S201: Perform time quantization processing on the terminal-marked timestamp according to the preset time window to obtain the time counting factor;
[0086] Step S202: Perform a hash operation on the time counting factor based on the first key symbol to obtain time digest data.
[0087] In step S201 of some embodiments, time quantization processing can refer to the process of normalizing the terminal-marked timestamp according to a preset time window. The time count factor can refer to the value obtained after time quantization processing, used for subsequent hash operations. For example, the calculation principle of the time count factor can be as follows:
[0088]
[0089] in, It is a time counting factor; It is a terminal-marked timestamp; It is a preset time window; " is the division symbol.
[0090] In step S202 of some embodiments, the hash operation processing can refer to the process of performing a hash operation on the time count factor based on the first key symbol using a specific hash algorithm. The time digest data can refer to the hash value obtained after the hash operation processing, which is used for subsequent consistency verification.
[0091] Please see Figure 3 In some embodiments, step S202 may include, but is not limited to, steps S301 to S303:
[0092] Step S301: Perform a hash operation on the time counting factor based on the first key symbol to obtain candidate digest data;
[0093] Step S302: Perform data truncation processing on the candidate abstract data to obtain truncated abstract data;
[0094] Step S303: Perform format conversion processing on the extracted summary data to obtain time summary data.
[0095] In steps S301 to S302 of some embodiments, the candidate digest data may refer to the original hash value obtained after performing a full hash operation on the time count factor using the first key as the key. Data truncation processing may refer to the process of selecting a bit sequence of a specified length or position from the candidate digest data. Truncation digest data may refer to the short hash value obtained after data truncation processing, used for subsequent format conversion. For example, if the candidate digest data is a hexadecimal string "3a7f9c2b5e8d", then the last four bytes of the hexadecimal string "5e8d" can be truncated as the truncated digest data; or, if the candidate digest data is a binary bitstream "1011101011", then the last six bytes of the binary bitstream "101011" can be truncated as the truncated digest data. It is understood that the implementation of the data truncation processing can be adjusted according to actual needs.
[0096] In step S303 of some embodiments, the format conversion process can refer to the process of converting the internal encoding form of the truncated digest data into another preset encoding form. The time digest data can refer to the hash value obtained after the format conversion process, used for subsequent consistency verification. For example, if the truncated digest data is a hexadecimal string "5e8d", it can be converted to the decimal value "24205" as the time digest data; or, if the truncated digest data is a binary string "101011", it can be converted to the octal value "53" as the time digest data. It should be noted that the method of generating the time digest data can be adjusted according to actual needs.
[0097] Understandably, in this embodiment, the time count factor is first hashed based on the first key symbol to obtain candidate digest data. Then, the candidate digest data is truncated to obtain truncated digest data. Finally, the truncated digest data undergoes format conversion to obtain the time digest data. This approach hides the original hash, reduces the possibility of time digest data forgery, improves the security of the consistency verification process, and ultimately enhances the security of the entire seamless payment process.
[0098] Please see Figure 4 In some embodiments, step S202 may include, but is not limited to, steps S401 to S403:
[0099] Step S401: Perform modulo operation on the time counting factor to obtain the time modulo value;
[0100] Step S402: Generate a second key based on the time modulus and the first key symbol;
[0101] Step S403: Perform a hash operation on the time counting factor according to the second key to obtain time digest data.
[0102] In steps S401 to S403 of some embodiments, the modulo operation processing can refer to the process of taking a preset modulus remainder from the time count factor. The preset modulus remainder can refer to a pre-selected positive integer modulus. The time modulus value can refer to the remainder value obtained after the modulo operation processing and used in key generation. For example, if the time count factor is 202 and the preset modulus is 64, then the time modulus value is 10. It is understood that the generation method of the time modulus value can be adjusted according to actual needs. The second key can refer to a key obtained by generating a key using a specific key generation algorithm based on the time modulus value and the first key symbol. For example, the second key can be derived using a hash-based key derivation function (HKDF) algorithm with the time modulus value and the first key symbol as input; or, the second key can also be obtained by using a hash-based message authentication code (HMAC) algorithm with the time modulus value and the first key symbol as key material. It is understood that the generation method of the second key can be adjusted according to actual needs. Time summary data can refer to the hash value obtained by performing a hash operation on the time counting factor based on the second key, which is used for consistency verification with the target gate.
[0103] Understandably, this embodiment first performs a modulo operation on the time counting factor to obtain a time modulus value. Then, it generates a second key based on the time modulus value and a first key symbol. Finally, it performs a hash operation on the time counting factor based on the second key to obtain time digest data. This allows for the dynamic generation of a new key based on the time modulus value and the first key symbol, followed by hash operations using the new key. This reduces the possibility of time digest data being forged due to key leakage, improves the security of the consistency verification process, and ultimately enhances the security of the entire contactless payment process.
[0104] Please see Figure 5 In some embodiments, step S102 may also include, but is not limited to, steps S501 to S504:
[0105] Step S501: Perform signature trust verification on the gate signature information to obtain trust verification result information;
[0106] Step S502: Verify the signature status of the gate signature information to obtain the status verification result information;
[0107] Step S503: Verify the validity period of the gate signature information to obtain the validity period verification result information;
[0108] Step S504: Determine the signature verification result information based on the trusted verification result information, the status verification result information, and the validity period verification result information.
[0109] In step S501 of some embodiments, the gate signature information may refer to credential information jointly generated based on the device identifier, preset key, and signature data of the target gate. It is understood that the gate signature information may be pre-generated by a cloud server and stored in both the cloud server and the target gate. Signature trust verification may refer to the process of verifying the legitimacy of the signature data in the gate signature information to confirm whether it has been tampered with. Trust verification result information may refer to information obtained after signature trust verification, used to indicate whether the signature data is trustworthy. Trust verification result information includes trust verification passed and trust verification failed, which can be indicated by different quantification values. For example, the trust verification result information can be determined by sending the received gate signature information to the cloud server using the target terminal device, comparing the signature data in the gate signature information stored in the cloud server with the signature data in the received gate signature information; or, the trust verification result information can also be determined on the target terminal device. It is understood that the method of determining the trust verification result information can be adjusted according to actual needs.
[0110] In step S502 of some embodiments, signature status verification may refer to the process of checking the status of the device identifier in the gate signature information to confirm whether it is included in a specific list or register. Status verification result information may refer to information obtained after signature status verification, used to indicate whether the device identifier's status is normal. Status verification result information includes status verification passed and status verification failed, which can be indicated by different quantified values. For example, status verification result information can be obtained by the target terminal device sending the received gate signature information to a cloud server, obtaining the device identifier in the received gate signature information through the cloud server, and then determining whether it is included in a specific list or register; alternatively, status verification result information can also be determined on the target terminal device. It is understood that the method for determining status verification result information can be adjusted according to actual needs.
[0111] In step S503 of some embodiments, signature validity period verification can refer to the process of checking the validity period of the signature data in the gate signature information to confirm whether it is within the valid time range. Validity period verification result information can refer to information obtained after signature validity period verification, used to indicate whether the signature is within its validity period. Validity period verification result information includes validity period verification passed and validity period verification failed, which can be indicated by different quantitative values. For example, the validity period verification result information can be obtained by the target terminal device sending the received gate signature information to a cloud server, obtaining the validity period information indicated by the received gate signature information through the cloud server, and comparing it with the current system time; alternatively, the validity period verification result information can also be determined on the target terminal device. It is understood that the method for determining the validity period verification result information can be adjusted according to actual needs.
[0112] In step S504 of some embodiments, the signature verification result information may refer to the conclusion information determined comprehensively based on the trusted verification result information, the status verification result information, and the validity period verification result information. For example, if the trusted verification result information, the status verification result information, and the validity period verification result information all indicate that the verification has passed, then the signature verification result information can be determined to be verified, i.e., the gate's identity is determined to be legitimate; or, if the trusted verification result information, the status verification result information, and the validity period verification result information indicate that the verification has failed, then the signature verification result information can be determined to be verified, i.e., the gate's identity is determined to be illegitimate.
[0113] It is understood that the embodiments of this application perform signature trust verification, signature status verification, and signature validity period verification on the gate signature information, and then comprehensively determine the signature verification result based on the obtained trust verification result, status verification result, and validity period verification result. In this way, multi-dimensional trust verification of the target gate identity can be achieved, reducing the risk of gate forgery, replay attacks, and expired credentials passing through, thereby improving the security of the contactless payment process.
[0114] Figure 6 This is another optional flowchart of the contactless payment method provided in the embodiments of this application. Figure 6 The method described above is applied to the target gate, and the method may include, but is not limited to, steps S601 to S604:
[0115] Step S601: Send the gate signature information to the target terminal device so that the target terminal device can verify the gate signature information and obtain the signature verification result information.
[0116] Step S602: In response to the signature verification result information meeting the preset signature verification pass conditions, receive time digest data and terminal identification information from the target terminal device;
[0117] Step S603: Determine the gate marking timestamp, and perform data consistency verification based on time summary data, terminal identification information and gate marking timestamp to obtain consistency verification result information;
[0118] Step S604: In response to the consistency verification result information meeting the preset consistency verification pass conditions, the billing information is sent to the target terminal device so that the target terminal device can make contactless payment based on the billing information.
[0119] In steps S601 to S604 of some embodiments, during the contactless payment process, the target gate first sends its signature information to the target terminal device so that the target terminal device can verify the signature information and obtain a signature verification result. If the signature verification result indicates that the gate's identity is untrustworthy, the signature verification fails, and the target terminal device terminates subsequent interactions, does not send any data to the gate, and may choose to discard the received gate signature information or record an abnormal event. If the signature verification result indicates that the gate's identity is trustworthy, the signature verification passes, and the target terminal device immediately determines the terminal-marked timestamp and performs a digest operation on the preset time window and the timestamp according to the first key symbol to generate time digest data. The time digest data and terminal identification information are then sent to the target gate. After receiving the time digest data and terminal identification information, the target gate immediately determines the gate-marked timestamp and performs the same digest operation as the target terminal device to obtain time digest data on the gate side. By comparing the time digest data on the gate side with the received time digest data, a consistency verification result is generated. If the consistency verification results are inconsistent, the gate will terminate the transaction and will not send billing information; if the consistency verification results are consistent, the gate will generate billing information and send it to the target terminal device, which will then complete the contactless payment.
[0120] Please see Figure 7 In some embodiments, steps S701 to S702 may be included before step S601:
[0121] Step S701: Perform distance detection on the target terminal device to obtain the measured distance value;
[0122] Step S702: When the measured distance value is less than or equal to the preset distance threshold, the gate signature information is sent to the target terminal device.
[0123] In steps S701 to S702 of some embodiments, distance detection can refer to the process of measuring the relative distance between the target terminal device and the target gate. The measured distance value can refer to the numerical value obtained after distance detection, used to characterize the distance between the target terminal device and the gate. The preset distance threshold can refer to a pre-selected upper limit of distance used to trigger the transmission of signature information. When the measured distance value is less than or equal to the preset distance threshold, it means that the distance between the target terminal device and the target gate meets the triggering condition, and the operation of sending the gate signature information to the target terminal device can be performed; when the measured distance value is greater than the preset distance threshold, it means that the distance does not meet the triggering condition, and the transmission operation is not performed.
[0124] It is understood that, in this embodiment of the application, before sending the gate signature information to the target terminal device, a distance detection is performed on the target terminal device to obtain a measured distance value. If the measured distance value is less than or equal to a preset distance threshold, the gate signature information is then sent to the target terminal device. In this way, identity interaction can be initiated only when the user approaches the valid area of the gate, reducing the risk of long-distance interception, replay attacks, and man-in-the-middle attacks. Therefore, this application can improve the security of the contactless payment process.
[0125] Please see Figure 8 This application also provides a flowchart of a contactless payment method, which includes: First, the target terminal device obtains terminal identification information and a first key symbol assigned to it from a cloud server, and also receives gate signature information stored in the target gate from the target gate. Then, the target terminal device sends the received gate signature information to the cloud server to verify the received gate signature information using the gate signature information backed up by the cloud server, obtains the signature verification result information, and then sends the obtained signature verification result information back to the target terminal device; if the target terminal device determines that the information indicated by the signature verification result information is valid for the gate identity, it generates a terminal mark timestamp, and then performs digest operation processing on a preset time window and the terminal mark timestamp according to the first key symbol to obtain time digest data. Furthermore, the time digest data and terminal identification information are sent to the target gate, enabling the target gate to generate a gate-marked timestamp. Then, based on the terminal identification information, the first key assigned to the target terminal device is retrieved from the cloud server. Using the same digest operation processing method as the target terminal device, time digest data on the gate side is generated based on the gate-marked timestamp, a preset time window, and the first key. The received time digest data is then compared with the time digest data on the gate side to verify data consistency, obtaining a consistency verification result, which is returned to the target terminal device. Finally, if the consistency verification result indicates successful verification, the target terminal device is considered secure, thus completing the two-way authentication between the target terminal device and the target gate. At this point, the target terminal device can receive calculated billing information from the target gate for seamless payment. It is understood that the contactless payment method in this application first verifies the identity and legitimacy of the target gate through the target terminal device, and then sends the time summary data dynamically generated by the target terminal device to the target gate so that the target gate can verify the identity and legitimacy of the target terminal device. This enables two-way authentication between the target terminal device and the target gate during the contactless payment process, reduces the risk of man-in-the-middle attacks or spoofed gate attacks, and thus improves the security of the contactless payment process.
[0126] Please see Figure 9This application also provides a contactless payment system applied to a target terminal device, which can realize the above-mentioned contactless payment method. The system includes:
[0127] The data acquisition unit 901 is used to acquire terminal identification information and the first key symbol;
[0128] The signature verification unit 902 is used to receive the gate signature information from the target gate, and to perform signature verification on the gate signature information to obtain the signature verification result information;
[0129] The digest operation unit 903 is used to determine the terminal mark timestamp in response to the signature verification result information meeting the preset verification pass conditions, and to perform digest operation processing on the preset time window and the terminal mark timestamp according to the first key to obtain time digest data;
[0130] The data sending unit 904 is used to send time summary data and terminal identification information to the target gate so that the target gate generates a gate mark timestamp and performs data consistency verification based on the time summary data, terminal identification information and gate mark timestamp to obtain consistency verification result information;
[0131] The contactless payment unit 905 is used to receive billing information from the target gate in response to the consistency verification result information meeting the preset consistency verification pass conditions, and to perform contactless payment based on the billing information.
[0132] The specific implementation of this contactless payment system is basically the same as the specific implementation of the contactless payment method described above, and will not be repeated here.
[0133] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned contactless payment method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0134] Please see Figure 10 , Figure 10 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes:
[0135] The processor 1001 can be implemented using a general-purpose central processing unit (CPU), microprocessor, application specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0136] The memory 1002 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 1002 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1002 and is called and executed by the processor 1001 to execute the contactless payment method of the embodiments of this application.
[0137] Input / output interface 1003 is used to implement information input and output;
[0138] The communication interface 1004 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0139] Bus 1005 transmits information between various components of the device (e.g., processor 1001, memory 1002, input / output interface 1003, and communication interface 1004);
[0140] The processor 1001, memory 1002, input / output interface 1003 and communication interface 1004 are connected to each other within the device via bus 1005.
[0141] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described contactless payment method.
[0142] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0143] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0144] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0145] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0146] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0147] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0148] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0149] In the embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or units may be electrical, mechanical, or other forms.
[0150] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0151] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0152] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0153] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. A contactless payment method, characterized in that, Applied to a target terminal device, the method includes: Obtain the terminal identification information and the first key; Receive gate signature information from the target gate and verify the gate signature information to obtain signature verification result information; In response to the signature verification result information satisfying the preset signature verification pass condition, the terminal mark timestamp is determined, the terminal mark timestamp is time quantized according to the preset time window to obtain the time count factor, and the time count factor is hashed according to the first key to obtain the time digest data; The time summary data and the terminal identification information are sent to the target gate so that the target gate generates a gate mark timestamp and performs data consistency verification based on the time summary data, the terminal identification information and the gate mark timestamp to obtain consistency verification result information. In response to the consistency verification result information satisfying the preset consistency verification pass condition, the billing information is received from the target gate, and contactless payment is performed based on the billing information.
2. The method according to claim 1, characterized in that, The step of performing a hash operation on the time counter factor based on the first key symbol to obtain the time digest data includes: The time counter factor is hashed based on the first key symbol to obtain candidate digest data; The candidate summary data is truncated to obtain truncated summary data; The extracted summary data is processed by format conversion to obtain the time summary data.
3. The method according to claim 1, characterized in that, The step of performing a hash operation on the time counter factor based on the first key symbol to obtain the time digest data includes: The time counting factor is subjected to modulo operation to obtain the time modulo value; A second key is obtained by generating a key based on the time modulus and the first key symbol. The time counting factor is hashed using the second key to obtain the time digest data.
4. The method according to claim 1, characterized in that, The signature verification of the gate signature information to obtain signature verification result information includes: The signature information of the gate is verified to obtain the signature verification result information. The signature status of the gate signature information is verified to obtain the status verification result information; The signature validity period of the gate signature information is verified to obtain the validity period verification result information; The signature verification result information is determined based on the trusted verification result information, the status verification result information, and the validity period verification result information.
5. A contactless payment method, characterized in that, Applied to a target turnstile, the method includes: The gate signature information is sent to the target terminal device so that the target terminal device can verify the gate signature information and obtain the signature verification result information. In response to the signature verification result information satisfying the preset signature verification pass condition, time digest data and terminal identification information are received from the target terminal device; wherein, the time digest data is generated by the target terminal device by performing time quantization processing on the terminal-marked timestamp according to a preset time window to obtain a time count factor, and then performing a hash operation on the time count factor according to a first key symbol, wherein the first key symbol and the terminal identification information are obtained by the target terminal device, and the terminal-marked timestamp is generated by the target terminal device; Determine the gate marking timestamp, and perform data consistency verification based on the time summary data, the terminal identification information, and the gate marking timestamp to obtain consistency verification result information; In response to the consistency verification result information satisfying the preset consistency verification pass condition, the billing information is sent to the target terminal device so that the target terminal device can make contactless payment based on the billing information.
6. The method according to claim 5, characterized in that, Before sending the gate signature information to the target terminal device, the method further includes: The target terminal device is subjected to distance detection to obtain the measured distance value; When the measured distance value is less than or equal to a preset distance threshold, the gate signature information is sent to the target terminal device.
7. A contactless payment system, characterized in that, The system, applied to a target terminal device, includes: The data acquisition unit is used to acquire terminal identification information and the first key symbol; The signature verification unit is used to receive gate signature information from the target gate, and to perform signature verification on the gate signature information to obtain signature verification result information; The digest operation unit is configured to, in response to the signature verification result information satisfying the preset verification pass condition, determine the terminal mark timestamp, perform time quantization processing on the terminal mark timestamp according to the preset time window to obtain a time count factor, and perform hash operation processing on the time count factor according to the first key symbol to obtain time digest data; The data sending unit is used to send the time summary data and the terminal identification information to the target gate, so that the target gate generates a gate mark timestamp, and performs data consistency verification based on the time summary data, the terminal identification information and the gate mark timestamp to obtain consistency verification result information; The contactless payment unit is used to receive billing information from the target gate in response to the consistency verification result information meeting the preset consistency verification pass conditions, and to perform contactless payment based on the billing information.
8. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the contactless payment method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the contactless payment method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Rail transit charging method, device, equipment, storage medium and product
CN120071457A
Identity authentication and key negotiation method, gateway equipment and terminal
CN121173585A
Non-screen POS machine data acquisition method and system based on NFC and WeChat applet, POS machine and storage medium
CN121213067A