An electronic evidence method and system for transaction security

By injecting payment requests as evidence identifiers into transaction data, generating digital digests, and constructing trusted evidence data packages, the problem of the disconnect between evidence data and transactions in existing electronic evidence preservation technologies is solved. This achieves the integrity and non-repudiation of evidence data, thereby improving the security and credibility of commercial transactions.

CN121860633BActive Publication Date: 2026-05-05FUJIAN JUNNUO SCI & TECH ACHIEVEMENTS TRANSFORMATION SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FUJIAN JUNNUO SCI & TECH ACHIEVEMENTS TRANSFORMATION SERVICE CO LTD
Filing Date
2026-03-18
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing electronic evidence storage technology is independent of the payment business process, resulting in the disconnect between the stored evidence data and the transaction. It lacks standardized and structured encapsulation, making it difficult to form an evidence chain that runs through the entire transaction. Furthermore, the evidence storage results are insufficient in terms of time reliability and content integrity verification, and cannot be directly used for transaction dispute resolution and judicial evidence.

Method used

The payment request is injected into the transaction data as a notarization identifier. A digital digest is generated through hash operation to construct a trusted notarization data package. The notarization identifier is used as the main framework to associate index information and generate a digital notarization certificate, ensuring that the notarized content is bound to the user's identity.

Benefits of technology

It ensures the integrity and non-repudiation of the stored evidence, enhances the security and credibility of commercial transactions, simplifies the evidence presentation process in transaction disputes, and improves the automation level of the evidence storage process and the consistency of evidence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121860633B_ABST
    Figure CN121860633B_ABST
Patent Text Reader

Abstract

This invention relates to the field of electronic payment technology, and discloses a method and system for electronic evidence preservation for transaction security. The method includes: injecting a payment request as an evidence preservation identifier into the transaction data of a payment gateway to generate evidence-preserving transaction data; extracting key elements of the transaction and binding them with the user's payment identity credentials to form a structured evidence preservation instruction; performing a hash operation on the evidence-preserving payload of the instruction to obtain a digital digest; constructing a trusted evidence preservation data packet by combining a timestamp and the digital digest; generating an evidence preservation completion receipt by associating index information with the evidence preservation identifier as the main body; and digitally signing the receipt to finally obtain a digital evidence preservation certificate. This invention can enhance the evidentiary effect of electronic evidence preservation for transaction security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic payment technology, and in particular to an electronic evidence storage method and system for transaction security. Background Technology

[0002] In the field of transaction security, existing electronic evidence preservation technologies often operate independently of the payment business process, resulting in a disconnect between evidence preservation and the actual fund transaction. This separation makes it difficult to achieve native and accurate binding of preserved data with specific payment requests, transaction details, and user identities. The resulting evidence records are insufficient in terms of completeness and relevance, and cannot form a consistent chain of evidence throughout the entire transaction.

[0003] Furthermore, the evidence generated by existing methods is often fragmented, lacking a standardized, structured encapsulation mechanism, and suffers from procedural gaps in verifying temporal reliability, content integrity, and ultimately issuing legally valid electronic certificates. This makes it difficult to directly and efficiently use the evidence for transaction dispute resolution, auditing, or judicial evidence, reducing its practical value and reliability as a core trust infrastructure in commercial activities. Summary of the Invention

[0004] This invention provides a method and system for electronic evidence preservation for transaction security, the main purpose of which is to solve the problem of insufficient evidentiary value when electronic evidence is used for transaction security.

[0005] To achieve the above objectives, the present invention provides an electronic evidence storage method for transaction security, comprising:

[0006] The payment request is injected as a notarization identifier into the transaction data of the payment gateway to obtain the notarized transaction data of the payment gateway.

[0007] The key elements in the transaction data are used as evidence and bound to the user's payment identity credential in the payment request to obtain the structured evidence storage instruction of the payment gateway.

[0008] A hash operation is performed on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway;

[0009] Based on the timestamp of the structured evidence storage instruction and the digital digest, a trusted evidence storage data packet for the payment gateway is constructed;

[0010] Using the evidence storage identifier as the main framework, and associating it with the evidence storage index information of the trusted evidence storage data packet, the evidence storage completion receipt of the payment gateway is obtained.

[0011] The receipt for completion of evidence storage is digitally signed to obtain the digital evidence storage certificate of the payment gateway.

[0012] In a preferred embodiment, injecting the payment request as a notarized identifier into the transaction data of the payment gateway to obtain the notarized transaction data of the payment gateway includes:

[0013] Receive the payment request generated by the payment gateway based on the user's operation;

[0014] The transaction serial number in the payment request is concatenated with the payment gateway identifier in string order to obtain the evidence storage identifier of the payment gateway.

[0015] The evidence storage identifier is inserted as a new field into the message header of the transaction data to obtain the evidence storage transaction data of the payment gateway.

[0016] In a preferred embodiment, the step of binding key elements in the transaction data as evidence with the user payment identity credential of the payment request to obtain the structured evidence storage instruction of the payment gateway includes:

[0017] The transaction amount, payee account information, and product description information in the transaction data are used as key elements of the payment gateway.

[0018] The user payment token in the payment request is used as the user payment identity credential of the payment gateway.

[0019] A continuous storage block is allocated within the evidence storage buffer of the payment gateway, and the continuous storage block is divided into an element set storage area and a voucher storage area.

[0020] The key elements are written into the element set storage area, and the user's payment identity certificate is written into the certificate storage area to obtain the structured evidence storage instruction of the payment gateway.

[0021] In a preferred embodiment, the step of performing a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway includes:

[0022] Starting from the beginning address of the contiguous storage block, the key elements and the user payment token are reassembled into a byte stream to obtain the evidence storage payload of the payment gateway;

[0023] A one-way hash calculation is performed on the evidence storage payload, and the calculated fixed-length hash value is used as the digital digest of the payment gateway.

[0024] In a preferred embodiment, constructing the trusted evidence storage data packet for the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest includes:

[0025] Extract the timestamp from the process log of the structured evidence storage instructions;

[0026] Based on the timestamp, the digital digest, and the link field of the evidence identifier, the data packet structure of the payment gateway is created;

[0027] The timestamp, the digital digest, and the reference address pointing to the evidence storage identifier are respectively filled into the corresponding fields of the data packet structure to obtain the trusted evidence storage data packet of the payment gateway.

[0028] In a preferred embodiment, creating the data packet structure of the payment gateway based on the link fields of the timestamp, the digital digest, and the evidence identifier includes:

[0029] Initialize the time record field based on the timestamp, and convert the timestamp into a standard time string format and write it into the time record field;

[0030] Allocate a data fingerprint configuration space for the digital digest, and load the digital digest into the data fingerprint configuration space in the form of a binary large object;

[0031] Allocate storage space for the link field of the evidence storage identifier, and write a reference pointer pointing to the storage location of the evidence storage identifier in the evidence storage buffer of the payment gateway into the storage space;

[0032] The timestamp, the digital digest, and the evidence identifier are organized in the order of their declarations to form the data packet structure of the payment gateway.

[0033] In a preferred embodiment, the step of obtaining the evidence storage completion receipt from the payment gateway by associating the evidence storage identifier as the main framework with the evidence storage index information of the trusted evidence storage data packet includes:

[0034] The timestamp field and digital digest field in the trusted evidence storage data packet are used as the core evidence storage index information of the payment gateway;

[0035] Calculate the logical association strength value between the information entries in the core evidence storage index information and the evidence storage identifier;

[0036] Using the evidence storage identifier as the root node and the core evidence storage index information as the leaf nodes, and sorting the leaf nodes according to the logical association strength value, the tree index structure of the payment gateway and the corresponding storage path are obtained.

[0037] The list of storage paths is integrated to obtain the evidence storage completion receipt of the payment gateway.

[0038] In a preferred embodiment, the formula for calculating the logical association strength value includes:

[0039]

[0040] in, The logical association strength value, For time-related weighting coefficients, The time sensitivity coefficient, For the timestamp, The time base is the time reference in the evidence storage identifier. Content-related weights, The evidence storage identifier is... For the digital digest, The reference hash value in the evidence storage identifier. The number of binary bits in the digital digest.

[0041] In a preferred embodiment, the step of digitally signing the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway includes:

[0042] The complete data of the evidence storage completion receipt is encrypted using the private key of the payment gateway to obtain the original signature data of the payment gateway.

[0043] The original signature data is appended to the end of the evidence storage completion receipt to obtain the signature file to be encapsulated by the payment gateway;

[0044] The public key certificate identifier of the payment gateway is merged with the signature file to be packaged to obtain the transaction certificate of the payment gateway;

[0045] The transaction certificate is encoded according to the standard electronic signature data format to obtain the digital evidence certificate of the payment gateway.

[0046] To address the above problems, the present invention also provides an electronic evidence storage system for transaction security, the system comprising:

[0047] The evidence storage transaction module injects the payment request as an evidence storage identifier into the transaction data of the payment gateway to obtain the evidence storage transaction data of the payment gateway.

[0048] The evidence storage structure module takes the key elements in the transaction data as evidence storage content and binds them with the user payment identity certificate of the payment request to obtain the structured evidence storage instruction of the payment gateway.

[0049] The digital digest module performs a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway;

[0050] The evidence storage data packet module constructs a trusted evidence storage data packet for the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest.

[0051] The evidence storage receipt module uses the evidence storage identifier as the main framework, associates it with the evidence storage index information of the trusted evidence storage data packet, and obtains the evidence storage completion receipt from the payment gateway.

[0052] The digital evidence storage module digitally signs the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway.

[0053] Compared with the prior art, the present invention has the following beneficial effects:

[0054] 1. This electronic evidence preservation method ensures that each transaction has a unique and traceable evidence anchor by injecting payment requests as evidence identifiers into transaction data, thus establishing a complete evidence preservation chain at the starting point of a commercial transaction. By structurally binding key transaction elements with user payment identity credentials and calculating digital digests, this method generates an immutable data fingerprint, integrating transaction content and identity information into the evidence preservation process, significantly improving the integrity and non-repudiation of the evidence data. Constructing trusted evidence preservation data packages and evidence preservation completion receipts further integrates elements such as timestamps and index information, forming self-contained and verifiable evidence units, enhancing the automation level of the evidence preservation process and the consistency of the evidence.

[0055] 2. This technology directly enhances the security and credibility of commercial transactions, providing payment gateways with legally valid digital evidence. Through digital signatures and standardized encoding, the evidence possesses verifiable authenticity and authority, simplifying the evidence-gathering process in transaction disputes and reducing compliance costs. Overall, this method improves the efficiency and reliability of transaction evidence preservation, supporting the core need for rapid and secure evidence preservation in commercial activities. Attached Figure Description

[0056] Figure 1 This is a flowchart illustrating an electronic evidence preservation method for transaction security provided in an embodiment of the present invention.

[0057] Figure 2 This is a functional block diagram of an electronic evidence storage system for transaction security provided in an embodiment of the present invention;

[0058] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0059] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0060] This application provides an electronic evidence preservation method for transaction security. The executing entity of the electronic evidence preservation method for transaction security includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application embodiment: a server, a terminal, etc. In other words, the electronic evidence preservation method for transaction security can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0061] Reference Figure 1 The diagram shown is a flowchart illustrating an electronic evidence preservation method for transaction security provided in an embodiment of the present invention. In this embodiment, the electronic evidence preservation method for transaction security includes:

[0062] In this embodiment of the invention, the step of injecting the payment request as a notarized identifier into the transaction data of the payment gateway to obtain the notarized transaction data of the payment gateway is specifically used for:

[0063] Receive the payment request generated by the payment gateway based on the user's operation;

[0064] The transaction serial number in the payment request is concatenated with the payment gateway identifier in string order to obtain the evidence storage identifier of the payment gateway.

[0065] The evidence storage identifier is inserted as a new field into the message header of the transaction data to obtain the evidence storage transaction data of the payment gateway.

[0066] Specifically, the payment gateway receives payment requests triggered by user operations through its interface. These payment requests are generated after the user completes the payment information and confirms the payment on the payment interface. The payment request includes the transaction serial number, transaction amount, payee information, and user payment token.

[0067] Specifically, the transaction serial number field is extracted from the message body of the payment request. This field is a unique sequence number assigned by the payment gateway when generating the payment request. At the same time, the payment gateway identifier is read from the system configuration of the payment gateway. This identifier is a unique identification code of the payment gateway in the system. The transaction serial number and the payment gateway identifier are treated as strings.

[0068] Specifically, the evidence storage identifier is added as a new field to the message header of the transaction data. The transaction data is a complete message of the payment request. A new field is inserted after the existing fields in the message header. The field name is set to "evidence storage identifier" and the field value is set to the concatenated evidence storage identifier string.

[0069] Furthermore, the system components of the payment gateway parse the user's operation and encapsulate the user's input data into a standard payment request format. This format includes a message header and a message body. The message header contains the protocol version and request type, and the message body contains transaction details. The processing unit of the payment gateway verifies the validity of the user's operation to ensure that the payment request comes from a legitimate user operation. Then, the receiving module of the payment gateway stores the payment request in a temporary buffer for subsequent processing.

[0070] Furthermore, the transaction serial number is concatenated first, followed by the payment gateway identifier. The concatenation operation is implemented through a string concatenation function, which joins the two strings end to end to form a new string. The concatenated new string is the payment gateway's evidence storage identifier, which is used to uniquely identify the evidence storage of this transaction.

[0071] Furthermore, the insertion operation is achieved by modifying the message structure, expanding the original message header, adding storage space for new fields, and writing the evidence storage identifier into this space. The modified transaction data message is the evidence storage transaction data of the payment gateway, which contains the evidence storage identifier for subsequent evidence storage processing.

[0072] In summary, by proactively injecting a unique and traceable evidence identifier at the beginning of the payment transaction process, a solid anchor is established for the entire subsequent electronic evidence preservation process. The payment gateway, receiving payment requests generated based on user actions, ensures that the evidence preservation behavior is directly linked to the genuine commercial transaction intent, giving the evidence data a real business context.

[0073] In summary, by concatenating the transaction serial number and the payment gateway identifier in a fixed order to generate a notarized identifier, this method creates a key string with dual uniqueness. This string contains both the transaction sequence information within the payment system and the identity information of the gateway that processed the transaction, thus forming a unique key index globally that can be directly associated with a specific transaction and a specific transaction processor.

[0074] In summary, inserting the generated evidence identifier as a new field into the header of the original transaction data to obtain evidence-stored transaction data places the evidence identifier in a prominent and priority position in data transmission without changing the original transaction data payload. This ensures that the identifier can be preferentially identified and extracted in all subsequent transaction data processing and transmission stages. This provides an accurate and error-free index source and data association foundation for the subsequent structured evidence storage, digital digest generation, and construction of trusted evidence data packets for the payment gateway, thus ensuring the integrity and consistency of the electronic evidence storage chain from the very beginning of the process.

[0075] In this embodiment of the invention, when the key elements in the transaction data are used as evidence storage content and bound to the user payment identity credential of the payment request to obtain the structured evidence storage instruction of the payment gateway, it is specifically used for:

[0076] The transaction amount, payee account information, and product description information in the transaction data are used as key elements of the payment gateway.

[0077] The user payment token in the payment request is used as the user payment identity credential of the payment gateway.

[0078] The payment gateway allocates a continuous storage block within its evidence storage buffer, and divides the continuous storage block into an element set storage area and a voucher storage area.

[0079] The key elements are written into the element set storage area, and the user's payment identity certificate is written into the certificate storage area to obtain the structured evidence storage instruction of the payment gateway.

[0080] Specifically, transaction data messages follow the standard format of the payment industry. The payment gateway has a built-in message parser that reads the identifiers and length information of each field in the message. The transaction amount field is usually identified as "transaction amount" or its corresponding numeric code, and exists in the message as a numeric string. The payment gateway uses a string-to-numeric conversion function to convert it into an internal numeric format, such as a decimal number.

[0081] Specifically, the payment request is initiated by the user through the client application and includes a user payment token as an authentication credential. The user payment token is a digital token issued by an authentication server to identify the user session and authorize payment operations. The payment gateway first verifies the validity of the user payment token by checking the token's signature using public key verification to ensure the token has not been tampered with, and by checking the expiration timestamp in the token to ensure that the token is within its validity period.

[0082] Specifically, the payment gateway calls a memory allocation function to request a contiguous block of memory in the evidence storage buffer, called a contiguous storage block. The evidence storage buffer is a reserved area in memory specifically for processing evidence storage data to avoid conflicts with other processes. The payment gateway determines the size of the contiguous storage block based on key elements and the estimated amount of data for the user's payment identity credentials.

[0083] Specifically, the key elements include transaction amount, payee account information, and product description information. The transaction amount is converted to an 8-byte binary representation using double-precision floating-point format. The payee account information is encoded as an ASCII string and terminated with a null character. The product description information is encoded as a UTF-8 byte sequence. The payment gateway writes these byte streams sequentially to the starting address of the element set storage area and uses a memory write function to ensure accurate data storage.

[0084] Furthermore, the payee account information field is identified as "payee account," containing the payee's bank account number or e-wallet address. The payment gateway directly extracts the string value of this field without modification. The product description information field is identified as "product description," which is text information. The payment gateway extracts its original text content and ensures consistent encoding, such as converting it to UTF-8 encoding. The payment gateway combines these three fields into a data structure called the key element. The key element, as a data set, is stored in a memory variable or object for subsequent evidence storage processing.

[0085] Furthermore, upon successful verification, the payment gateway stores the user's payment token as a user payment identity credential. This credential is a string or binary data representing the user's identity information, used in the evidence storage to bind the user's identity and ensure that the evidence is associated with a specific user. The payment gateway stores the user payment identity credential in memory, ready for subsequent binding operations. As part of the structured evidence storage instructions, the user payment identity credential enhances the security and traceability of the evidence storage.

[0086] Furthermore, the payment gateway logically divides the contiguous storage block into two parts: an element set storage area and a voucher storage area. The element set storage area occupies the first byte starting from the beginning address of the contiguous storage block, while the voucher storage area occupies the last 64 bytes. This division is achieved by setting memory pointers: the pointer for the element set storage area points to the beginning address, and the pointer for the voucher storage area points to the beginning address plus the address of the following bytes. In this way, the contiguous storage block is organized into two clearly defined regions, each with fixed boundaries, facilitating data writing and reading, and providing a storage framework for constructing structured evidence storage instructions.

[0087] Furthermore, if the user's payment identity credential is a JSON Web token, it is directly written as a string occupying 64 bytes, and the payment gateway writes it to the starting address of the credential storage area. After writing, the contiguous storage block contains the key elements and complete data of the user's payment identity credential. This data block is called a structured evidence storage instruction, which is an in-memory data structure containing all the key content of the evidence storage and user identity information, ready for subsequent processing such as hash operations. The structured evidence storage instruction, as a data object inside the payment gateway, represents the complete state of the evidence storage instruction and is used to generate a digital digest.

[0088] In summary, by explicitly extracting the transaction amount, payee account information, and product description information from the transaction data as key elements, the evidence accurately covers the core commercial attributes and performance details of the transaction. This ensures that any data summary or voucher generated subsequently can fully and unambiguously represent the substantive content of the transaction, effectively preventing the problem of insufficient evidence validity due to missing or ambiguous information.

[0089] In summary, using the user's payment token directly as the user's payment identity credential in the payment request leverages readily available, securely authenticated tokens within the payment system to establish a strong link between user identity and transaction behavior. This avoids the overhead and delays associated with additional identity verification, while ensuring the authority and consistency of identity information. It also provides a responsibility binding mechanism for stored data that can be directly traced back to specific users.

[0090] In summary, allocating contiguous storage blocks within the payment gateway's evidence storage buffer and dividing it into an element set storage area and a voucher storage area provides two types of critical data with physically adjacent and logically isolated pre-defined storage spaces. This pre-divided contiguous block layout not only eliminates the impact of memory fragmentation and ensures efficient data storage and retrieval, but more importantly, it creates a deterministic memory structure prerequisite for processing the two as a whole (such as byte stream reassembly for hash calculation).

[0091] In summary, by writing key elements and user payment identity credentials into their respective storage areas, structured evidence storage instructions are obtained. This operation produces a data set with a uniform format and clear boundaries. These structured evidence storage instructions serve as standard inputs for all subsequent processing flows, such as calculating digital digests and constructing data packets, greatly simplifying data processing logic and improving the maintainability and reliability of the entire evidence storage system.

[0092] In this embodiment of the invention, when performing a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway, it is specifically used for:

[0093] Starting from the beginning address of the contiguous storage block, the key elements and the user payment token are reassembled into a byte stream to obtain the evidence storage payload of the payment gateway;

[0094] A one-way hash calculation is performed on the evidence storage payload, and the calculated fixed-length hash value is used as the digital digest of the payment gateway.

[0095] Specifically, the system first reads the byte sequences of key elements already written in the element set storage area, such as transaction amount, payee account information, and product description information. Then, it reads the byte sequence of user payment token already written in the adjacent voucher storage area, and the system creates a new buffer.

[0096] Specifically, the obtained evidence storage payload byte stream is input to a preset one-way hash calculation function for processing. This function performs a series of irreversible transformation operations on the input byte stream. First, the byte stream is divided into several fixed-size data blocks. Bitwise operations and logical functions are performed on the first data block to generate an intermediate state value. Then, each subsequent data block is mixed and compressed with the previous intermediate state value in turn to update the intermediate state value.

[0097] Furthermore, the byte sequence of the read key elements is used as the leading part, and the byte sequence of the user's payment token is used as the following part. The bytes are spliced ​​and combined in the buffer in strict order to form a single and coherent byte stream. This newly generated byte stream, which contains complete key elements and user credential information, is named by the system as the evidence storage payload of the payment gateway.

[0098] Furthermore, after all data blocks have been processed, the final intermediate state value is formatted and transformed into a fixed-length, unique sequence of hexadecimal characters. This final fixed-length hash value is extracted by the system and identified as the digital digest of the payment gateway, which represents the digital fingerprint of the original evidence payload.

[0099] In summary, leveraging the physical characteristics of contiguous memory storage ensures the atomicity and sequential consistency of data reading. By sequentially reading the contents of the element set storage area and the credential storage area from a predetermined starting address and reassembling them into a single byte stream, this method forcibly integrates discrete key business elements and user identity credentials into an inseparable whole at the data level. This deterministic byte sequence generation method eliminates the risk of inconsistent subsequent summary calculation results due to inconsistent data splicing order or format, providing a reliable data foundation for generating unique and reproducible evidentiary payloads, directly serving the core need to accurately reconstruct and verify the original transaction content in commercial transaction disputes.

[0100] In summary, by leveraging the properties of cryptographic hash functions, a fixed-length, highly collision-resistant digital fingerprint, or digital digest, is generated for the evidence-preserving payload produced in the previous step. This computation process is irreversible, meaning that the original transaction details cannot be deduced from the digest, thus protecting commercially sensitive information. Furthermore, any minor modification to the input data will cause significant and unpredictable changes to the generated digest value. The resulting digital digest, as a unique and compact representation of the transaction data packet, greatly facilitates efficient verification of the transaction data integrity. It provides a crucial and tamper-proof technological foundation for constructing a "trustworthy evidence-preserving data packet" and ultimately a legally valid "digital evidence certificate," fundamentally guaranteeing the credibility and probative value of electronic evidence in secure transaction scenarios.

[0101] In this embodiment of the invention, when constructing the trusted evidence storage data packet of the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest, it is specifically used for:

[0102] Extract the timestamp from the process log of the structured evidence storage instructions;

[0103] Based on the timestamp, the digital digest, and the link field of the evidence identifier, the data packet structure of the payment gateway is created;

[0104] The timestamp, the digital digest, and the reference address pointing to the evidence storage identifier are respectively filled into the corresponding fields of the data packet structure to obtain the trusted evidence storage data packet of the payment gateway.

[0105] Specifically, the system parses the auxiliary log file of the structured evidence storage instruction, namely the process log, identifies and locates the field that records the time when the evidence storage operation occurs through the predefined log format, and reads the raw string data representing the time information from the field.

[0106] Specifically, the system initializes a new structured data object as a container for the data packet structure. This container predefines three independent field areas, which are used to hold the timestamp field, the digital digest field, and the link field, respectively.

[0107] Specifically, the system performs a data filling operation, writing the extracted timestamp string into the timestamp field of the data packet structure, and writing the complete binary sequence of the previously calculated digital digest into the digital digest field of the data packet structure.

[0108] Furthermore, the string data is converted into a year-month-day-hour-minute-second format conforming to the Coordinated Universal Time standard, and this formatted time string is officially named the timestamp extracted from the process log.

[0109] Furthermore, the creation process includes allocating a date and time type storage location for the timestamp field, a fixed-length binary data storage location for the digital digest field, and a storage location for storing a memory address pointer for the link field. This link field is explicitly specified to associate the evidence identifier. The resulting structured data object with three fields and a clear logical relationship is called the payment gateway's data packet structure.

[0110] Furthermore, the specific physical memory address of the evidence storage identifier in the system's evidence storage buffer is obtained simultaneously. This reference address is converted into a pointer and written into the link field of the data packet structure. After all the specified fields are assigned values, the data packet structure, which contains the timestamp, digital digest, and the reference address of the evidence storage identifier, is finally confirmed by the system as a trusted evidence storage data packet of the payment gateway.

[0111] In this embodiment of the invention, when creating the data packet structure of the payment gateway based on the link field of the timestamp, the digital digest, and the evidence identifier, it is specifically used for:

[0112] Initialize the time record field based on the timestamp, and convert the timestamp into a standard time string format and write it into the time record field;

[0113] Allocate a data fingerprint configuration space for the digital digest, and load the digital digest into the data fingerprint configuration space in the form of a binary large object;

[0114] Allocate storage space for the link field of the evidence storage identifier, and write a reference pointer pointing to the storage location of the evidence storage identifier in the evidence storage buffer of the payment gateway into the storage space;

[0115] The timestamp, the digital digest, and the evidence identifier are organized in the order of their declarations to form the data packet structure of the payment gateway.

[0116] Specifically, a field is created in memory specifically for storing time information; this field is defined as a time record field. The system reads the raw timestamp data, which is typically a long integer or a string in a specific format.

[0117] Specifically, the system prepares a storage area for digital digests by allocating a contiguous, fixed-size storage space in the memory heap. The size of this space is determined by the output length of the hash algorithm used. For example, for an algorithm that outputs a 256-bit digest, 32 bytes of space are allocated. This allocated storage space is named the data fingerprint configuration space.

[0118] Specifically, the system allocates the necessary storage resources for the link of the evidence identifier. In the memory layout of the data packet structure, a field is reserved specifically for storing address references. This field is called the storage space of the link field, and its size is consistent with the pointer length of the system architecture.

[0119] Specifically, the system ultimately assembles the data packet structure by creating a new structure instance. This structure has three predefined member variables, corresponding to the timestamp, digital digest, and evidence identifier, respectively. The system then fills in the data in the order specified in the structure declaration.

[0120] Furthermore, by calling the time formatting function, the time is parsed into components of year, month, day, hour, minute, second, and millisecond. Then, these components are recombined into a new string according to a predefined format. Finally, this standardized time string is written into the storage space of the allocated time record field, completing the initialization and data writing of the time record field.

[0121] Furthermore, the system loads the calculated digital digest, i.e., the fixed-length hash value, into its original binary form, i.e., a byte array. Specifically, each byte of the hash value is copied sequentially from the most significant bit to the least significant bit to the corresponding byte address in the data fingerprint configuration space, so that the digital digest is stored in the data fingerprint configuration space in its complete binary form, thus completing the loading of the digital digest in the form of a binary large object.

[0122] Furthermore, the actual physical storage location of the evidence storage identifier is obtained by querying the memory management table of the payment gateway's evidence storage buffer to find the starting memory address of the evidence storage identifier string or data structure in the buffer, and converting this address value into a pointer that can be referenced by the program. Finally, the system stores the value of this reference pointer into the storage space previously allocated for the link field through a memory write operation, thereby establishing a clear link to the storage location of the evidence storage identifier.

[0123] Furthermore, firstly, the standard time string, which has been formatted and stored in the time record field, is assigned to the timestamp member of the structure; then, the complete byte array of the binary large object, i.e., the digital digest, stored in the data fingerprint configuration space, is assigned to the digital digest member of the structure; finally, the reference pointer read from the link field storage space, which points to the evidence identifier, is assigned to the evidence identifier member of the structure; after all three members have been assigned, this well-structured data set containing the timestamp, digital digest, and evidence identifier reference is finally constructed into the data packet structure of the payment gateway.

[0124] In summary, this provides an objective, authoritative, and irrefutable proof of the time point for the entire evidence preservation process. By extracting the timestamp from the system's automatically generated process logs, rather than relying on potentially tampered client-side times, the reliability and neutrality of the timestamp source are ensured. As a key time element in transaction evidence preservation, this timestamp provides a credible basis for subsequently determining the order of transactions, verifying the timeliness of evidence preservation, and defining the time window for liability in commercial disputes, thus meeting the core need for transaction time authentication in commercial activities.

[0125] In summary, a standardized data structure framework, namely the data packet structure, was designed and instantiated specifically for encapsulating the core elements of evidence preservation. This framework defines the timestamp representing temporal credibility, the digital digest representing the integrity of the transaction content, and the link field for the evidence preservation identifier used to associate with the original transaction as fixed components of the data packet. This structured design organizes the originally scattered key evidence preservation elements into a logically clear and well-defined whole, laying the foundation for generating standardized evidence preservation data packets that are easy for automated system processing and verification, thus improving the standardization and interoperability of commercial evidence preservation data management.

[0126] In summary, the entered timestamp provides a time anchor, the entered digital digest provides a content fingerprint, and the entered reference address pointing to the evidence identifier establishes an index relationship between the data packet and the original transaction request. The resulting trusted evidence data packet integrates three key elements of trust: time, content, and index, forming an independent and robust unit of evidence. It can be used alone to quickly verify the existence and integrity of a transaction, providing direct data support for payment gateways to issue highly credible transaction credentials in business processes.

[0127] In this embodiment of the invention, when obtaining the evidence storage completion receipt from the payment gateway by associating the evidence storage identifier as the main framework with the evidence storage index information of the trusted evidence storage data packet, it is specifically used for:

[0128] The timestamp field and digital digest field in the trusted evidence storage data packet are used as the core evidence storage index information of the payment gateway;

[0129] Calculate the logical association strength value between the information entries in the core evidence storage index information and the evidence storage identifier;

[0130] Using the evidence storage identifier as the root node and the core evidence storage index information as the leaf nodes, and sorting the leaf nodes according to the logical association strength value, the tree index structure of the payment gateway and the corresponding storage path are obtained.

[0131] The list of storage paths is integrated to obtain the evidence storage completion receipt of the payment gateway.

[0132] Specifically, the system reads the internal structure of the completed trusted evidence storage data packet. First, it locates the specific area in the data packet that stores time information, namely the timestamp field, and extracts the standardized time string recorded therein. Then, it locates the specific area that stores the data fingerprint, namely the digital digest field, and extracts the complete binary hash value stored therein.

[0133] Specifically, the system initiates the association strength calculation process, performing association degree measurement with the evidence identifier for each information entry in the core evidence index information, namely the timestamp entry and the digital digest entry; for the timestamp entry, the calculation process involves parsing the time base information encoded in the evidence identifier string, comparing the current timestamp with the time base, calculating the absolute time difference between the two, and converting the time difference into a normalized strength component.

[0134] Specifically, the system constructs a tree-shaped index model based on the data; the system creates a tree-shaped data structure in memory and designates the evidence identification string as the unique root node of the data structure; subsequently, the timestamp entries and digital digest entries in the core evidence index information are created as two independent leaf nodes respectively.

[0135] Specifically, the established tree-like index structure is traversed to collect all storage paths from the root node (the evidence identifier) ​​to each leaf node (the timestamp entry and the digital digest entry).

[0136] Furthermore, the system combines the two core identifier data elements extracted from the trusted evidence storage data packet—the timestamp string and the digital digest binary value—to define and name them together as the core evidence storage index information of the payment gateway.

[0137] Furthermore, for digital digest entries, the calculation process involves parsing a pre-stored reference hash value from the evidence identifier, comparing the binary sequence of the current digital digest with the binary sequence of the reference hash value bit by bit, counting the number of identical bits, and converting the statistical result into a normalized strength component. Finally, the system weights and fuses the two strength components calculated for the timestamp and digital digest respectively according to a preset fixed ratio to generate a single value that represents the overall degree of correlation. This value is defined as the logical correlation strength value between the information entry and the evidence identifier.

[0138] Furthermore, based on the previously calculated logical association strength value corresponding to each leaf node, the system sorts all leaf nodes in descending order, links the leaf node with the highest association strength value as the first child node of the root node, and links the leaf node with the second highest association strength value as the second child node of the root node, thus forming a tree-like index structure with a clear hierarchy and order. At the same time, based on the actual organization of this tree structure on the storage medium, the system records the sequence of nodes required to access each leaf node from the root node, and this node access sequence is defined as the storage path corresponding to that leaf node.

[0139] Furthermore, the text descriptions or logical addresses of these storage paths are arranged according to the order of the leaf nodes in the tree to form an ordered list of paths. Finally, the system encapsulates this list of paths into a structured data object, which is then generated and identified as the payment gateway's proof of storage completion receipt.

[0140] In summary, by extracting the timestamp from the system's automatically generated process logs, rather than relying on potentially tampered client timestamps, the reliability and neutrality of the timestamp source are ensured. As a key time element for transaction evidence preservation, this timestamp provides a credible basis for subsequently determining the order of transactions, verifying the timeliness of evidence preservation, and defining the time window for liability in commercial disputes, thus meeting the core need for transaction time authentication in commercial activities.

[0141] In summary, a standardized data structure framework, namely the data packet structure, was designed and instantiated specifically for encapsulating the core elements of evidence preservation. This framework defines the timestamp representing temporal credibility, the digital digest representing the integrity of the transaction content, and the link field for the evidence preservation identifier used to associate with the original transaction as fixed components of the data packet. This structured design organizes the originally scattered key evidence preservation elements into a logically clear and well-defined whole, laying the foundation for generating standardized evidence preservation data packets that are easy for automated system processing and verification, thus improving the standardization and interoperability of commercial evidence preservation data management.

[0142] In summary, the standardized framework described above has been fully implemented, generating a self-contained and self-verifying complete evidence package. The entered timestamp provides a time anchor, the entered digital digest provides a content fingerprint, and the entered reference address pointing to the evidence storage identifier establishes an index relationship between the data package and the original transaction request. The resulting trusted evidence storage data package integrates the three trusted elements of time, content, and index, forming an independent and robust evidence unit. It can be used alone to quickly verify the existence and integrity of a transaction, providing direct data support for payment gateways to issue highly credible transaction credentials in business processes.

[0143] In this embodiment of the invention, the formula for calculating the logical association strength value is specifically used for:

[0144]

[0145] in, The logical association strength value, For time-related weighting coefficients, The time sensitivity coefficient, For the timestamp, The time base is the time reference in the evidence storage identifier. Content-related weights, The evidence storage identifier is... For the digital digest, The reference hash value in the evidence storage identifier. The number of binary bits in the digital digest.

[0146] Specifically, the sources of each parameter in the formula for calculating the logical association strength value are as follows: the timestamp comes directly from the time string extracted and standardized from the process log of the structured evidence storage instructions; the time base comes from the time component encoded in the evidence storage identifier string; the digital digest comes from the fixed-length hash value obtained after performing a one-way hash calculation on the evidence storage payload; the reference hash value comes from the hash component encoded in the evidence storage identifier string; the number of binary bits in the digital digest is fixedly determined by the output length of the hash algorithm used; the time association weight coefficient and the time sensitivity coefficient are fixed values ​​preset by the system to adjust the degree of influence of the time part; the content association weight is a fixed value preset by the system to adjust the degree of influence of the content part; and the evidence storage identifier is a string previously generated by concatenating the transaction serial number and the payment gateway identifier.

[0147] Furthermore, the significance of this formula lies in evaluating the logical correlation between the core evidence index information and the evidence identifier through quantitative calculation. Specifically, the time correlation part is calculated first by multiplying the square of the difference between the timestamp and the time base by the time sensitivity coefficient, then subtracting the product by one, and finally multiplying by the time correlation weight coefficient to obtain the time contribution value. Then, the content correlation part is calculated by comparing the binary sequence of the digital digest and the reference hash value bit by bit, counting the number of identical bits and dividing by the total number of binary bits in the digital digest to obtain the matching ratio, then subtracting the ratio by one, and finally multiplying by the content correlation weight to obtain the content contribution value. Finally, the time contribution value and the content contribution value are added together to obtain the logical correlation strength value.

[0148] In general, the trend of the formula shows the variation of the logical association strength value. When the difference between the timestamp and the time base increases, the value of the time association part decreases, thus reducing the overall strength value. When the matching degree between the digital digest and the reference hash value decreases, the value of the content association part decreases, thus reducing the overall strength value. Conversely, when the timestamp and the time base are consistent and the digital digest and the reference hash value are perfectly matched, both the time association part and the content association part reach their maximum values, making the logical association strength value the highest.

[0149] In this embodiment of the invention, when digitally signing the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway, it is specifically used for:

[0150] The complete data of the evidence storage completion receipt is encrypted using the private key of the payment gateway to obtain the original signature data of the payment gateway.

[0151] The original signature data is appended to the end of the evidence storage completion receipt to obtain the signature file to be encapsulated by the payment gateway;

[0152] The public key certificate identifier of the payment gateway is merged with the signature file to be packaged to obtain the transaction certificate of the payment gateway;

[0153] The transaction certificate is encoded according to the standard electronic signature data format to obtain the digital evidence certificate of the payment gateway.

[0154] Specifically, the security module of the payment gateway loads its stored private key, which is the secret part of an asymmetric encryption algorithm. The system converts the data of the certificate of deposit completion receipt into a binary byte sequence, and then uses the private key to perform encryption operations on the byte sequence.

[0155] Specifically, a new buffer area is allocated in memory. The system first copies the original byte data of the proof completion receipt from beginning to end to the beginning of the buffer. Then, the system obtains the byte sequence of the original signature data and appends the sequence directly to the copied receipt data.

[0156] Specifically, the system retrieves the unique identifier of the public key certificate from the payment gateway's certificate management system. This identifier is a hash value of the certificate serial number or subject key identifier. The system then creates a new composite data structure containing two main parts: the first part is the public key certificate identifier stored in plaintext or encoded form, and the second part is the complete byte data of the signature file to be encapsulated.

[0157] Specifically, the system encodes the transaction voucher according to the standard electronic signature data format to generate a digital evidence certificate. The system follows the predefined standard electronic signature data format specification to first parse the data of the transaction voucher and map it to the various fields of the standard format, such as putting the signature data into the signature field and the certificate identifier into the certificate information field.

[0158] Furthermore, the encryption process involves dividing the data into blocks and performing mathematical transformations using a private key, such as performing modular exponentiation and padding operations, to generate corresponding encrypted data blocks. Finally, all the encrypted data blocks are combined in sequence into a complete ciphertext sequence, which is defined as the original signature data of the payment gateway.

[0159] Furthermore, it is ensured that there are no gaps or separators between the two parts of data, thus forming a single, longer byte sequence. This newly formed byte sequence contains both the original receipt content and its digital signature, which is the signature file to be packaged by the payment gateway.

[0160] Furthermore, the system writes the public key certificate identifier into the header field of the data structure, and then continuously writes the byte stream of the signature file to be encapsulated into the subsequent fields, making the two logically related and physically continuous. This data set containing the certificate identifier and the signature file is recognized by the system as the transaction credential of the payment gateway.

[0161] Furthermore, appropriate encoding rules are then applied, such as using encoding for serialization or text conversion, to ensure that the data meets the format requirements and can be transmitted across systems. Finally, a fully encoded, self-contained data packet is output, which is the digital proof of the payment gateway.

[0162] In summary, the payment gateway uses its unique private key for encryption. This process not only encrypts and protects the data but, more importantly, generates original signature data that is identity-bound and unforgeable. This signature data is the sole cryptographic proof that the payment gateway acknowledges and is responsible for the content of the "proof of evidence completion receipt" (i.e., the core evidence list containing the proof of evidence index path). It provides an undeniable technical foundation for subsequent verification of data integrity and the issuer's identity, directly serving the need for liability determination in commercial activities.

[0163] In summary, a simple tail appending method ensures a direct and explicit link between the signature and the original receipt data, forming a self-contained signature file to be encapsulated. This structure allows any verification of the file to be completed within the same data unit, i.e., extracting the original receipt data and verifying the tail signature using the corresponding public key. This greatly simplifies the verification process, improves the efficiency and reliability of evidence processing, and prepares the ground for generating standardized credentials that are easy to distribute and store.

[0164] In summary, the public key certificate identifier indicates the location or unique identifier of the public key certificate issued by a trusted third party required for signature verification. Combining it with the signature file makes the generated transaction credential a "self-illustrating" evidence package. Any verifier can use this identifier to obtain the correct public key to verify the authenticity of the signature, thus confirming that the transaction credential was indeed issued by the claimed payment gateway and has not been tampered with. This solves the critical question of "which public key to use" in digital signature verification, enhancing the convenience and reliability of credentials during cross-system exchange and verification.

[0165] In summary, it transforms transaction credentials into a final electronic document with broad compatibility and legal recognition through standardized coding. Using industry- or legally recognized standard formats for coding ensures that the digital evidence credential can be correctly parsed and processed by various judicial evidence collection systems, verification tools, or business partner systems. The resulting digital evidence credential integrates a signed core evidence index, verifiable issuer identity information, and a standard encapsulation format, becoming a final electronic document with a complete chain of evidence and legal validity that can be directly used in litigation, auditing, or dispute mediation.

[0166] Compared with the prior art, the present invention has the following beneficial effects:

[0167] 1. This electronic evidence preservation method ensures that each transaction has a unique and traceable evidence anchor by injecting payment requests as evidence identifiers into transaction data, thus establishing a complete evidence preservation chain at the starting point of a commercial transaction. By structurally binding key transaction elements with user payment identity credentials and calculating digital digests, this method generates an immutable data fingerprint, integrating transaction content and identity information into the evidence preservation process, significantly improving the integrity and non-repudiation of the evidence data. Constructing trusted evidence preservation data packages and evidence preservation completion receipts further integrates elements such as timestamps and index information, forming self-contained and verifiable evidence units, enhancing the automation level of the evidence preservation process and the consistency of the evidence.

[0168] 2. This technology directly enhances the security and credibility of commercial transactions, providing payment gateways with legally valid digital evidence. Through digital signatures and standardized encoding, the evidence possesses verifiable authenticity and authority, simplifying the evidence-gathering process in transaction disputes and reducing compliance costs. Overall, this method improves the efficiency and reliability of transaction evidence preservation, supporting the core need for rapid and secure evidence preservation in commercial activities.

[0169] like Figure 2 The diagram shown is a functional block diagram of an electronic evidence storage system for transaction security provided in an embodiment of the present invention.

[0170] The electronic evidence storage system 100 for transaction security described in this invention can be installed in an electronic device. Depending on the functions implemented, the electronic evidence storage system 100 for transaction security may include an evidence storage transaction module 101, an evidence storage structure module 102, a digital digest module 103, an evidence storage data packet module 104, an evidence storage receipt module 105, and a digital evidence storage module 106. The module described in this invention can also be referred to as a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, and which are stored in the memory of the electronic device.

[0171] In this embodiment, the functions of each module / unit are as follows:

[0172] The evidence storage transaction module injects the payment request as an evidence storage identifier into the transaction data of the payment gateway to obtain the evidence storage transaction data of the payment gateway.

[0173] The evidence storage structure module takes the key elements in the transaction data as evidence storage content and binds them with the user payment identity certificate of the payment request to obtain the structured evidence storage instruction of the payment gateway.

[0174] The digital digest module performs a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway;

[0175] The evidence storage data packet module constructs a trusted evidence storage data packet for the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest.

[0176] The evidence storage receipt module uses the evidence storage identifier as the main framework, associates it with the evidence storage index information of the trusted evidence storage data packet, and obtains the evidence storage completion receipt from the payment gateway.

[0177] The digital evidence storage module digitally signs the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway.

[0178] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0179] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0180] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0181] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0182] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for electronic evidence storage for transaction security, characterized in that, The method includes: The payment request is injected as a notarized identifier into the transaction data of the payment gateway to obtain the notarized transaction data of the payment gateway, including: Receive the payment request generated by the payment gateway based on the user's operation; The transaction serial number in the payment request is concatenated with the payment gateway identifier in string order to obtain the evidence storage identifier of the payment gateway. The evidence storage identifier is inserted as a new field into the message header of the transaction data to obtain the evidence storage transaction data of the payment gateway; The key elements in the transaction data are used as evidence and bound to the user's payment identity credential in the payment request to obtain the structured evidence storage instruction of the payment gateway. A hash operation is performed on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway; Based on the timestamp of the structured evidence storage instruction and the digital digest, a trusted evidence storage data packet for the payment gateway is constructed; Using the evidence storage identifier as the main framework, and associating it with the evidence storage index information of the trusted evidence storage data packet, the evidence storage completion receipt of the payment gateway is obtained. The receipt for completion of evidence storage is digitally signed to obtain the digital evidence storage certificate of the payment gateway.

2. The electronic evidence storage method for transaction security as described in claim 1, characterized in that, The step of binding key elements in the transaction data as evidence with the user's payment identity credentials in the payment request to obtain the structured evidence storage instructions from the payment gateway includes: The transaction amount, payee account information, and product description information in the transaction data are used as key elements of the payment gateway. The user payment token in the payment request is used as the user payment identity credential of the payment gateway. A continuous storage block is allocated within the evidence storage buffer of the payment gateway, and the continuous storage block is divided into an element set storage area and a voucher storage area. The key elements are written into the element set storage area, and the user's payment identity certificate is written into the certificate storage area to obtain the structured evidence storage instruction of the payment gateway.

3. The electronic evidence preservation method for transaction security as described in claim 2, characterized in that, The step of performing a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway includes: Starting from the beginning address of the contiguous storage block, the key elements and the user payment token are reassembled into a byte stream to obtain the evidence storage payload of the payment gateway; A one-way hash calculation is performed on the evidence storage payload, and the calculated fixed-length hash value is used as the digital digest of the payment gateway.

4. The electronic evidence preservation method for transaction security as described in claim 1, characterized in that, The process of constructing a trusted evidence storage data packet for the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest includes: Extract the timestamp from the process log of the structured evidence storage instructions; Based on the timestamp, the digital digest, and the link field of the evidence identifier, the data packet structure of the payment gateway is created; The timestamp, the digital digest, and the reference address pointing to the evidence storage identifier are respectively filled into the corresponding fields of the data packet structure to obtain the trusted evidence storage data packet of the payment gateway.

5. The electronic evidence preservation method for transaction security as described in claim 4, characterized in that, The method of creating the data packet structure of the payment gateway based on the link field of the timestamp, the digital digest, and the evidence identifier includes: Initialize the time record field based on the timestamp, and convert the timestamp into a standard time string format and write it into the time record field; Allocate a data fingerprint configuration space for the digital digest, and load the digital digest into the data fingerprint configuration space in the form of a binary large object; Allocate storage space for the link field of the evidence storage identifier, and write a reference pointer pointing to the storage location of the evidence storage identifier in the evidence storage buffer of the payment gateway into the storage space; The timestamp, the digital digest, and the evidence identifier are organized in the order of their declarations to form the data packet structure of the payment gateway.

6. The electronic evidence storage method for transaction security as described in claim 1, characterized in that, The process of obtaining the evidence storage completion receipt from the payment gateway, using the evidence storage identifier as the main framework and associating it with the evidence storage index information of the trusted evidence storage data packet, includes: The timestamp field and digital digest field in the trusted evidence storage data packet are used as the core evidence storage index information of the payment gateway; Calculate the logical association strength value between the information entries in the core evidence storage index information and the evidence storage identifier; Using the evidence storage identifier as the root node and the core evidence storage index information as the leaf nodes, and sorting the leaf nodes according to the logical association strength value, the tree index structure of the payment gateway and the corresponding storage path are obtained. The list of storage paths is integrated to obtain the evidence storage completion receipt of the payment gateway.

7. The electronic evidence preservation method for transaction security as described in claim 6, characterized in that, The formula for calculating the logical association strength value includes: in, The logical association strength value, For time-related weighting coefficients, The time sensitivity coefficient, For the timestamp, The time base is the time reference in the evidence storage identifier. Content-related weights, The evidence storage identifier is... For the digital digest, The reference hash value in the evidence storage identifier. The number of binary bits in the digital digest.

8. The electronic evidence storage method for transaction security as described in claim 1, characterized in that, The step of digitally signing the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway includes: The complete data of the evidence storage completion receipt is encrypted using the private key of the payment gateway to obtain the original signature data of the payment gateway. The original signature data is appended to the end of the evidence storage completion receipt to obtain the signature file to be encapsulated by the payment gateway; The public key certificate identifier of the payment gateway is merged with the signature file to be packaged to obtain the transaction certificate of the payment gateway; The transaction certificate is encoded according to the standard electronic signature data format to obtain the digital evidence certificate of the payment gateway.

9. An electronic evidence storage system for transaction security, used to implement the electronic evidence storage method for transaction security as described in any one of claims 1-8, characterized in that, The system includes: The evidence storage transaction module injects the payment request as an evidence storage identifier into the transaction data of the payment gateway to obtain the evidence storage transaction data of the payment gateway, including: Receive the payment request generated by the payment gateway based on the user's operation; The transaction serial number in the payment request is concatenated with the payment gateway identifier in string order to obtain the evidence storage identifier of the payment gateway. The evidence storage identifier is inserted as a new field into the message header of the transaction data to obtain the evidence storage transaction data of the payment gateway; The evidence storage structure module takes the key elements in the transaction data as evidence storage content and binds them with the user payment identity certificate of the payment request to obtain the structured evidence storage instruction of the payment gateway. The digital digest module performs a hash operation on the evidence storage payload in the structured evidence storage instruction to obtain the digital digest of the payment gateway; The evidence storage data packet module constructs a trusted evidence storage data packet for the payment gateway based on the timestamp of the structured evidence storage instruction and the digital digest. The evidence storage receipt module uses the evidence storage identifier as the main framework, associates it with the evidence storage index information of the trusted evidence storage data packet, and obtains the evidence storage completion receipt from the payment gateway. The digital evidence storage module digitally signs the evidence storage completion receipt to obtain the digital evidence storage certificate of the payment gateway.

Citation Information

Patent Citations

  • Two-dimensional code identification method based on digital signatures and timestamps

    CN105095728A

  • A block chain-based data storage method

    CN109766724A