Digital currency payment method and system based on multi-dimensional proof framework
The digital currency payment method using a multidimensional proof framework leverages near-field communication and biometric identification technologies to generate tamper-proof spatiotemporal and identity proofs, solving the security and compliance issues of existing payment models, improving the security and compliance of offline payments, and providing irrefutable electronic evidence and compliance review.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TAIEN IND (SHENZHEN) CO LTD
- Filing Date
- 2026-01-16
- Publication Date
- 2026-05-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing digital currency payment models have serious technical defects and security risks in terms of identity verification, transaction compliance, risk control, and judicial evidence collection. In particular, in offline peer-to-peer payment scenarios, it is difficult to effectively verify the true identities of the two parties in the transaction, compliance review is lagging behind, there is a lack of records of user intent, and physical presence verification is lacking, which makes it difficult to resolve disputes and collect evidence for regulators.
The digital currency payment method based on a multidimensional proof framework verifies the transaction location and time through near-field communication, and combines biometric identification and compliance verification to generate spatiotemporal proof, identity proof, and proof of transaction intent and asset compliance, ensuring the physical presence and legality of the payment process, and storing the evidence on the blockchain.
It enhances the security and compliance of digital currency payments, blocks remote fraud and illegal activities, provides non-repudiable electronic authorization certificates, meets anti-money laundering and regulatory requirements, and ensures the auditability and privacy protection of transactions.
Smart Images

Figure CN122048355A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain payment technology, and in particular to a digital currency payment method and system based on a multidimensional proof framework. Background Technology
[0002] In recent years, with the widespread application of digital currencies, payment methods based on convenient methods such as QR codes have become increasingly popular. However, digital currency payments, especially in offline peer-to-peer payment scenarios, have exposed serious technical defects and security risks in areas such as identity verification, transaction compliance, risk control, and judicial evidence collection, becoming a significant bottleneck restricting the healthy development of the industry. Therefore, there is an urgent need for an innovative technical method and system capable of constructing a multi-dimensional verifiable proof framework, upgrading the digital currency payment process from a simple "asset transfer" to a comprehensive, real-time, and auditable "fact verification," thereby fundamentally improving the security and compliance level of digital currency payments. Summary of the Invention
[0003] This application provides a digital currency payment method and system based on a multidimensional proof framework, which can improve the security and compliance level of digital currency payments.
[0004] To address the above problems, this application provides the following technical solution: In a first aspect, this application provides a digital currency payment method based on a multidimensional proof framework, the method comprising: After the user terminal establishes a near-field communication link with the terminal, it verifies the location and time of the transaction between the user terminal and the terminal based on the near-field communication link, and generates a spacetime proof after the verification is successful. The user terminal compares the user's current biometric information collected by the terminal with the locally pre-stored biometric template, and generates a verification result certificate after a successful comparison. It then uses a private key to digitally sign the verification result certificate and generates an identity certificate after a successful signature. The biometric template is associated with and bound to the user's verified KYC identity information. During the transaction, after the user confirms the transaction information and payment asset information, the server is triggered to verify the compliance of the payment assets. After the verification is passed, the user authorizes the transaction and generates a certificate of transaction intent and asset compliance.
[0005] As one possible implementation, determining the location and time of the transaction between the user terminal and the terminal based on the near-field communication link includes: The terminal broadcasts terminal information via the near-field communication link. The terminal information includes: terminal location information, terminal current timestamp, and merchant identifier. After the user terminal hears the broadcast, it generates response information and sends the response information to the terminal. The response information includes the wallet identifier in the user terminal and the current timestamp of the user terminal. After determining that the time difference between the current timestamp of the terminal and the current timestamp of the user terminal is less than a preset threshold, the user terminal generates a spatiotemporal proof; wherein, the spatiotemporal proof includes the terminal information, the response information and the time difference.
[0006] As one possible implementation, the biometric information is palmprint information. Before the user terminal compares the user's current biometric information collected by the terminal with the biometric template, the method further includes: After receiving the palm print and palm vein images entered by the user, the biometric identification device uses a feature extraction algorithm to extract features from the palm print and palm vein images to obtain a biometric template. The biometric identification device transmits the biometric template to the user terminal for local encrypted storage and associates and binds the biometric template with the user's verified KYC identity information.
[0007] As one possible implementation, the identity verification is output in the form of a zero-knowledge proof, which indicates that the legitimate user who has been confirmed to control the asset account is present at this moment and agrees to make the payment.
[0008] As one possible implementation, after the user confirms the transaction information and payment asset information, the process includes: The terminal generates a transaction summary based on the transaction information and sends the transaction summary to the user terminal. The transaction information includes merchant ID, store ID, currency, amount, and timestamp. The user terminal parses the transaction summary and then displays the transaction information. After receiving confirmation of the transaction information from the user, the client receives confirmation of the payment asset information from the user, wherein the payment asset information includes: the blockchain network and the type of payment token.
[0009] As one possible implementation, the server performs compliance verification on the transaction assets, including: After confirming the transaction information, the user sends a transaction risk assessment request to the server. Upon receiving the transaction risk assessment request, the server invokes the risk assessment engine to perform a real-time risk assessment of the user's assets.
[0010] As one possible implementation, the invocation of the risk assessment engine to perform real-time risk assessment of the user's assets includes: The risk assessment engine is invoked to perform a KYT risk assessment on the historical behavior of the payment address in the user terminal and the historical flow path of the payment token.
[0011] As one possible implementation, the triggering server performs compliance verification on the payment assets, and after successful verification, the user terminal authorizes the transaction, including: After the server verifies the compliance of the payment assets, the user initiates password payment authorization verification or biometric payment authorization verification, and uses a private key to sign the transaction data, generating a transaction signature, and broadcasts the transaction signature to the target blockchain network.
[0012] As one possible implementation, after the user authorizes the transaction, the method further includes: The spatiotemporal proof, the identity proof, and the transaction intention and asset compliance proof are cryptographically bound to generate a transaction evidence chain, and the transaction evidence chain or the feature value of the transaction evidence chain is stored in the evidence storage layer of the blockchain.
[0013] In a second aspect of this application, a digital currency payment system based on a multidimensional proof framework is provided, the system comprising: a user terminal, a terminal, and a server. The user terminal is used to establish a near-field communication link with the terminal, verify the location and time of the transaction between the user terminal and the terminal based on the near-field communication link, and generate a spacetime proof after the verification is successful. The user terminal is used to compare the user's current biometric information collected by the terminal with the biometric template pre-stored locally, and generate a verification result certificate after successful comparison. The verification result certificate is digitally signed using a private key, and an identity certificate is generated after successful signing. The biometric template is associated with and bound to the user's verified KYC identity information. The user terminal is also used to trigger the server to perform compliance verification of the payment assets after confirming the transaction information and payment asset information during the transaction process. After the verification is passed, the user terminal authorizes the transaction and generates a transaction intention and asset compliance certificate.
[0014] The beneficial effects of the technical solutions provided in this application include at least the following: This application provides a digital currency payment method based on a multidimensional proof framework. After the user establishes a near-field communication link with the terminal, the location and time of the transaction between the user and the terminal are verified based on the near-field communication link, and a spatiotemporal proof is generated after successful verification. The user compares the user's current biometric information collected by the terminal with the locally pre-stored biometric template, and generates a verification result certificate after successful comparison. The verification result certificate is digitally signed using a private key, and an identity certificate is generated after successful signing. The biometric template is associated with the user's verified KYC identity information. During the transaction, after the user confirms the transaction information and payment asset information, the server is triggered to perform compliance verification of the payment assets. After successful verification, the user authorizes the transaction and generates a transaction intention and asset compliance certificate.
[0015] The digital currency payment method based on a multidimensional proof framework provided in this application sets up a double physical barrier. First, the transaction must verify that the payer and the receiving terminal are in the same location via near-field communication (such as Bluetooth), preventing attackers in different locations from initiating payments remotely. Second, the payment must be authorized by the user in person through on-site verification using biometrics (such as palm print). These two barriers work together to completely block illegal activities such as remote fraud and money laundering through remote account control at both physical and biometric levels, firmly locking digital currency payments into real-world "face-to-face" scenarios.
[0016] Meanwhile, this application features a clear user intent confirmation process. Before payment, the user's client will clearly display complete transaction details (such as merchant and amount), and the user must actively click to confirm. Afterward, the user digitally signs this specific transaction using their private key. This signature, linked to the transaction details, constitutes a legally valid and non-repudiable electronic authorization certificate. Subsequently, the user cannot dispute the transaction based on "accidental click" or "unauthorized action," effectively protecting the merchant's rights and significantly reducing disputes.
[0017] Secondly, this application moves compliance checks (KYC / KYT) forward to before the transaction occurs. After the user confirms payment but before the transaction is actually recorded on the blockchain, the system automatically checks the risk score of the sending address and traces the origin history of the payment assets in real time. The results of these compliance checks are directly packaged into the transaction's "proof of intent and compliance" as a key component. Therefore, each successfully completed transaction comes with a standardized "compliance health check report," which regulatory agencies can directly access and verify, meeting regulatory requirements such as Anti-Money Laundering (AML) and "travel rules."
[0018] Furthermore, this application generates a "spatiotemporal proof" for each transaction, bound to precise physical coordinates and a timestamp. In the event of a legal dispute, this proof can serve as crucial electronic evidence, clearly demonstrating the exact geographical location and time of the transaction, thus solving the problem of determining whether a user made a payment face-to-face in the jurisdiction where the transaction took place. Combined with blockchain-based evidence storage, this evidence possesses integrity and immutability, and can be directly submitted to judicial or arbitration institutions for admissibility.
[0019] Furthermore, this application adheres to the principles of "data minimization" and "privacy first" in its architecture. The most sensitive user biometric templates and detailed KYC data are encrypted and stored only in a secure area on the user's local device, never uploaded to a centralized server. Only cryptographic hashes or zero-knowledge proofs of various types of information are uploaded to the blockchain at the stages requiring evidence preservation and auditing. This means that, without infringing on user privacy, auditors or regulatory agencies can still verify that "the correct process has been executed" and "critical data has not been tampered with," perfectly balancing personal privacy protection with the necessary auditability requirements of the financial system. Attached Figure Description
[0020] Figure 1 A flowchart of a digital currency payment method based on a multidimensional proof framework is provided for embodiments of this application; Figure 2 This is a structural diagram of a digital currency payment system based on a multidimensional proof framework, provided as an embodiment of this application. Detailed Implementation
[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0022] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of embodiments of this disclosure, unless otherwise stated, "a plurality of" means two or more.
[0023] In addition, the use of “based on” or “according to” implies openness and inclusivity, because processes, steps, calculations or other actions “based on” or “according to” one or more conditions or values can in practice be based on additional conditions or values beyond those conditions.
[0024] In recent years, with the widespread application of digital currencies, payment methods based on convenient methods such as QR codes have become increasingly popular. However, in addition to their convenience, they also harbor serious security and compliance flaws, which are mainly reflected in the following five aspects.
[0025] Anonymity and the Risk of Remote Fraud: Existing models struggle to effectively verify the true identities of both parties in a transaction. QR codes can be easily copied, screenshotted, and disseminated remotely through any channel, creating opportunities for criminals. They can remotely trick or coerce victims into scanning QR codes to make payments, thereby committing anonymous fraud or cross-border money laundering, while the system cannot distinguish whether it is a legitimate face-to-face transaction or a remotely controlled illegal transfer.
[0026] The delayed and reactive nature of compliance reviews: Existing Know Your Transaction (KYT) risk control measures typically analyze and issue warnings only after a transaction has been settled on the blockchain. This retrospective approach leads to significant delays in regulatory action. When a transaction is found to involve illicit funds or illegal addresses, the funds have often already been transferred multiple times, leaving only "one-size-fits-all" remedial measures such as freezing the recipient's account. This causes problems for innocent merchants and normal financial activities, creating a "compliance freeze dilemma."
[0027] Lack of proof of transaction intent makes dispute resolution difficult: The system lacks an instantaneous recording and solidification mechanism for users' clear payment intentions. When users later initiate disputes (refusals to pay) on the grounds of "misoperation" or "unauthorized operation," the payer, payee, and regulatory agency all lack objective and irrefutable technical evidence to determine the true situation at the time, making disputes difficult to arbitrate and causing losses to merchants.
[0028] The lack of physical "presence" verification and ambiguous jurisdiction: Purely digital transactions cannot prove whether the payer and the receiving terminal were in the same physical space at the time. This makes it impossible to determine the transaction location (jurisdiction). A payment might be initiated remotely by a user in country A and sent to a merchant in country B, triggering cross-border regulatory arbitrage and complex jurisdictional disputes.
[0029] Non-standardized audit data makes regulatory evidence collection difficult: Regulatory agencies struggle to directly obtain structurally consistent, complete, and readily verifiable transaction records from existing payment systems. Data is scattered across different wallet providers, exchanges, and merchant systems, with varying formats. Audits require manual retrieval and verification across platforms, resulting in high costs, low efficiency, and difficulty in achieving effective monitoring.
[0030] A core paradigm shift: Traditional encrypted payment systems primarily focus on ensuring the reliable completion of the "value transfer" process (i.e., whether the transaction actually occurred). This invention, however, addresses a more fundamental problem—verifying the authenticity and credibility of the "facts" supporting the transaction. Therefore, we innovatively propose a multi-dimensional proof framework based on Proof of Who, Proof of What, and Proof of When & Where. This framework aims to simultaneously generate a set of independently verifiable and tamper-proof "fact certificates" for every cryptocurrency payment, thereby driving a fundamental technological leap in the field from a single "value transfer" to credible "fact verification."
[0031] This application provides a digital currency payment method based on a multidimensional proof framework, such as... Figure 1 As shown, the method includes the following steps: Step 101: After the user terminal establishes a near-field communication link with the terminal, it verifies the location and time of the transaction between the user terminal and the terminal based on the near-field communication link, and generates a spacetime proof after the verification is successful.
[0032] The user terminal can be a user's mobile phone, specifically a wallet app on the user's phone. The terminal includes devices such as POS terminals, computer web interfaces, and cash registers; this application does not specifically limit this. Near-field communication includes Bluetooth communication or a short-range physical connection established based on NFC.
[0033] When the payment process is initiated, the user's device (such as a mobile wallet) first establishes a short-range physical connection with the merchant's terminal (POS machine) via Bluetooth (BLE) or Near Field Communication (NFC). Both parties instantly exchange and compare their recorded precise geographical locations and high-precision timestamps through this link. By calculating the difference between the two timestamps, if the difference is within a very short permission window (e.g., less than 1 second), it is determined that the user and the terminal are in the same physical space and time are synchronized, and the verification is successful. Subsequently, the system generates a cryptographic hash value as a spatiotemporal proof. This proof immutably records the precise geographical location and time of the transaction, providing crucial electronic evidence for possible subsequent legal proceedings.
[0034] Step 102: The user terminal compares the user's current biometric information collected by the terminal with the locally pre-stored biometric template, and generates a verification result certificate after successful comparison. The user terminal uses a private key to digitally sign the verification result certificate, and generates an identity certificate after successful signing. The biometric template is associated with and bound to the user's verified KYC identity information.
[0035] After confirming physical presence, identity verification is performed. The user must provide real-time biometric data (such as a palm print) on the terminal. The terminal encrypts and transmits this biometric information to the user's device, which compares it with a biometric template pre-stored in a local secure environment (such as a security chip) that is linked to the user's KYC (Know Your Customer) legal identity. If the comparison is successful, a "biometric verification passed" verification result credential is generated. The user's device then uses the private key controlling the payment assets to digitally sign the credential. This signing action cryptographically proves that "the individual who has passed biometric verification at this moment" is indeed "the legitimate controller of the current payment assets," thus generating irrefutable proof of identity and ownership.
[0036] Step 103: During the transaction process, after the user confirms the transaction information and payment asset information, the server is triggered to perform compliance verification on the payment assets. After the verification is passed, the user authorizes the transaction and generates a transaction intention and asset compliance certificate.
[0037] The server-side is a back-end processing system operated by a professional payment service provider (which may be a licensed payment institution, fintech company, or exchange). It is responsible for receiving, verifying, and processing payment requests from user wallets and completing the final clearing and settlement on behalf of the merchant.
[0038] Based on the successful verification in steps 101 and 102, the user can clearly view and confirm the specific information of this transaction (such as amount, payee) and details of the assets to be paid on their device. After user confirmation, the system does not immediately broadcast the transaction, but first triggers a compliance pre-review process. The server (compliance gateway) traces the source of the payment assets on-chain and assesses their risks. Only after the assets are verified to be "clean" and compliant is the user authorized to use their private key to finally sign the complete transaction information and complete the payment authorization. Finally, the user confirmation certificate, transaction signature, and compliance review results are packaged to generate proof of transaction intent and asset compliance.
[0039] The above three steps constitute a progressive trust chain: it first ensures that the transaction is a genuine act of the buyer and seller physically present; then it proves that the operator is the legitimate owner of the asset; and finally it ensures that the owner authorized the payment with full knowledge and on the premise that the asset is from a compliant source. This transforms post-event risk tracing into pre-event risk interception and fact solidification, fundamentally improving the security and compliance of digital currency payments.
[0040] Optionally, determining the location and time of the transaction between the user terminal and the terminal based on the near-field communication link includes: The terminal broadcasts terminal information via the near-field communication link. The terminal information includes: terminal location information, terminal current timestamp, and merchant identifier. After the user terminal hears the broadcast, it generates response information and sends the response information to the terminal. The response information includes the wallet identifier in the user terminal and the current timestamp of the user terminal. After determining that the time difference between the current timestamp of the terminal and the current timestamp of the user terminal is less than a preset threshold, the user terminal generates a spatiotemporal proof; wherein, the spatiotemporal proof includes the terminal information, the response information and the time difference.
[0041] The preset threshold can be 1 second or less. After the user sends a response (or the terminal receives a response), it calculates the time difference between the terminal's current timestamp and the user's current timestamp. If the time difference is less than the threshold, it is determined that the user and terminal are highly synchronized in time and space, meeting the characteristic of "physical co-occurrence," and the verification passes. After successful verification, the terminal information, response information, and calculated time difference are cryptographically hashed to generate a unique and tamper-proof spatiotemporal proof. This proof mathematically locks down the location, time, and participants of a specific interaction.
[0042] Thus, this application utilizes the communication constraints of the physical world to build trust. The short-range nature of near-field communication limits the physical scope of the interaction, while strict verification of the time difference prevents any attempt to forge "presence" through relay or delay attacks. Such forgery attempts would cause the time difference to exceed the threshold due to the additional delay caused by signal transmission, thus being identified and rejected by the system.
[0043] Optionally, the biometric information is palmprint information. Before the user terminal compares the user's current biometric information collected by the terminal with the biometric template, the method further includes: After receiving the palm print and palm vein images entered by the user, the biometric identification device uses a feature extraction algorithm to extract features from the palm print and palm vein images to obtain a biometric template. The biometric identification device transmits the biometric template to the user terminal for local encrypted storage and associates and binds the biometric template with the user's verified KYC identity information.
[0044] Among them, biometric identification devices can be terminals, such as POS machines.
[0045] During user registration or initial authorization, a dedicated biometric identification device guides users to input their palm information. This device doesn't simply store the raw image; instead, it uses a locally integrated feature extraction algorithm to jointly process and analyze the acquired palm print and palm vein images, extracting deep biometric features that uniquely identify the user and are irreversible. The algorithm then encodes these features to generate a highly abstract biometric template that cannot be reconstructed from the original image. This template is transmitted to the user's device via an encrypted channel.
[0046] After receiving the encrypted biometric template, the user's device stores it encrypted in a local hardware security area (such as a security chip or trusted execution environment). Then, a crucial binding operation is performed: this biometric template is logically associated and bound locally with the user's rigorously verified KYC (Know Your Customer) identity information. This means that, in a cryptographic sense, the biometric template represents a specific, legally authenticated identity.
[0047] During real-time comparisons of subsequent transactions, the user terminal uses this pre-securely stored and identity-bound biometric template. By comparing it with the current biometric information generated from palm print / vein information collected in real time by the terminal, the verification of "whether the operator is the bound KYC person" can be completed with high confidence.
[0048] Optionally, the identity verification is output in the form of a zero-knowledge proof, which indicates that the legitimate user controlling the asset account has been confirmed to be present at this moment and has agreed to make the payment.
[0049] This application outputs identity verification in the form of zero-knowledge proof. In this way, the verification party (such as merchants, acquiring institutions, and regulatory nodes) can only confirm the truthfulness of the statement that "a qualified legitimate user has completed the authorization", but cannot obtain the user's specific identity information at all, thus protecting the user's privacy and identity.
[0050] Optionally, after the user confirms the transaction information and payment asset information, the process includes: The terminal generates a transaction summary based on the transaction information and sends the transaction summary to the user terminal. The transaction information includes merchant ID, store ID, currency, amount, and timestamp. The user terminal parses the transaction summary and displays the transaction information. After receiving confirmation from the user regarding the transaction information, the user terminal receives confirmation from the user regarding the payment asset information, wherein the payment asset information includes: blockchain network and payment token type.
[0051] The aforementioned payment process breaks down a single payment into two stages: confirmation of "transaction information" and confirmation of "payment asset information," ensuring that users review every key aspect of the transaction. This dual confirmation mechanism significantly reduces the risk of erroneous payments due to haste or misunderstanding. Each confirmation step (click event, record selection) generates a local log, which, combined with the subsequent digital signature, forms a complete chain of proof of user intent, providing irrefutable electronic evidence in case of potential disputes.
[0052] Optionally, the server performs compliance verification on the transaction assets, including: After confirming the transaction information, the user sends a transaction risk assessment request to the server. Upon receiving the transaction risk assessment request, the server invokes the risk assessment engine to perform a real-time risk assessment of the user's assets.
[0053] Specifically, the step of calling the risk assessment engine to perform real-time risk assessment on the user's assets includes: calling the risk assessment engine to perform KYT risk assessment on the historical behavior of the payment address in the user's terminal and the historical flow path of the payment token.
[0054] The aforementioned KYT risk assessment of the historical behavior of payment addresses in the user terminal utilizes the openness and immutability of blockchain data. By analyzing all past fund flow records of the address (such as counterparties, frequency, amount, related services, etc.), and applying risk control models and risk databases, it determines whether the address may be involved in illegal financial activities such as money laundering, fraud, and terrorist financing. Based on this, a dynamic risk score or label is generated, providing a key compliance decision-making basis for whether to allow the transaction.
[0055] The aforementioned risk assessment of the historical flow path of the payment token involves tracing the historical origin of the specific token (identified by its unique identifier on the blockchain) that the user intends to pay. The risk assessment engine traces the complete flow path of the token from its withdrawal from a centralized exchange. It assesses whether each historical transfer involves suspicious intermediary addresses, stolen funds, addresses associated with hacking attacks, or compliance blacklists. This ensures the "clean origin" of the token and prevents illicit funds from flowing into the payment system. Once the risk assessment engine determines that the risk is too high, the server will immediately return a rejection instruction to the user, and the transaction will be proactively blocked by the system, preventing illegal funds from contaminating the merchant's account and subsequent complex judicial freezing procedures.
[0056] Optionally, the triggering server performs compliance verification on the payment assets, and after the verification is passed, the user terminal authorizes the transaction, including: after the server performs compliance verification on the payment assets, the user terminal initiates password payment authorization verification or biometric recognition payment authorization verification, and uses a private key to sign the transaction data, generates a transaction signature, and broadcasts the transaction signature to the target blockchain network.
[0057] During the above process, after receiving the "compliance verification passed" instruction from the server, the user's client will not automatically complete the payment. To ensure that the final authorization is given by the user, the user needs to provide final confirmation through at least one of the following methods.
[0058] The first method: Password payment authorization verification. Users need to enter a pre-set payment password or gesture password. The second method: Biometric recognition payment authorization verification. During this transaction session, a quick biometric verification (such as Face ID, fingerprint, or palm print secondary confirmation) is performed again. This step aims to ensure that the operator is the same person from transaction confirmation to the final delivery, preventing unauthorized operation.
[0059] After the final authorization verification is passed, the user's security module (such as a security chip) will be allowed to access the user's asset control private key to digitally sign the complete transaction data (such as the receiving address, amount, chain ID, nonce, etc.) containing all details of the transaction, thereby generating a transaction signature. This signature is the final and irrefutable legal and technical authorization certificate for the user to transfer their assets. Subsequently, the user will broadcast this signed transaction data to its target blockchain network (such as Ethereum, Tron, etc.) and wait for network node confirmation and final settlement.
[0060] Optionally, after the user authorizes the transaction, the method further includes: cryptographically binding the spatiotemporal proof, the identity proof, and the transaction intention and asset compliance proof to generate a transaction evidence chain, and storing the transaction evidence chain or the feature value of the transaction evidence chain in the evidence storage layer of the blockchain.
[0061] In other words, after the user completes the transaction authorization and broadcasts the transaction to the blockchain network, the system does not end its work. Instead, it executes a crucial evidence solidification and preservation step. The three proof documents generated during this transaction are: a spatiotemporal proof (evidence recording the precise geographical location and time of the transaction); an identity proof (evidence proving the operator is the legal owner of the asset and has passed identity verification); and a proof of transaction intent and asset compliance (evidence containing the user's explicit authorization record and the results of real-time asset compliance review). These three proof documents are bound together using cryptographic hash operations or Merkle trees to generate a unique, global "transaction evidence chain." This operation ensures the integrity and relevance of the three types of evidence—any minor change to a single proof will cause unpredictable changes to the characteristic values of the entire evidence chain.
[0062] Subsequently, the system writes the complete chain of transaction evidence or its cryptographic features (such as the root hash of the entire chain of evidence), along with the basic identifier of the transaction (such as the transaction ID), into a designated, immutable blockchain storage layer. This provides a unified and standardized query entry point for regulatory audits. Regulatory agencies do not need to retrieve logs from different systems separately; they can simply query the storage chain using the transaction ID to obtain all compliance and factual fingerprints of the transaction and, based on this, request relevant parties to provide the original data for verification.
[0063] This application also provides a digital currency payment system based on a multidimensional proof framework, such as... Figure 2 As shown, the system includes: a user terminal 10, a terminal 20, and a server terminal 30; The user terminal 10 is used to establish a near-field communication link with the terminal 20, verify the location and time of the transaction between the user terminal 10 and the terminal 20 based on the near-field communication link, and generate a spacetime proof after the verification is successful. The user terminal 10 is used to compare the user's current biometric information collected by the terminal 20 with the biometric template pre-stored locally, and generate a verification result certificate after successful comparison. The verification result certificate is digitally signed using a private key, and an identity certificate is generated after successful signing. The biometric template is associated with and bound to the user's verified KYC identity information. The user terminal 10 is also used to trigger the server terminal 30 to perform compliance verification on the payment assets after confirming the transaction information and payment asset information during the transaction process. After the verification is passed, the user terminal 10 authorizes the transaction and generates a transaction intention and asset compliance certificate.
[0064] In one embodiment, the terminal 20 is specifically used to: broadcast terminal 20 information through the near-field communication link, the terminal 20 information including: terminal 20 location information, terminal 20 current timestamp, and merchant identifier; The user terminal 10 is specifically used to: generate response information after listening to the broadcast, and send the response information to the terminal 20. The response information includes the wallet identifier in the user terminal 10 and the current timestamp of the user terminal 10. The user terminal 10 is specifically used to: generate a spatiotemporal proof after determining that the time difference between the current timestamp of the terminal 20 and the current timestamp of the user terminal 10 is less than a preset threshold; wherein the spatiotemporal proof includes the terminal 20 information, the response information and the time difference.
[0065] In one embodiment, the biometric information is palmprint information, and the user terminal 10 is specifically used to: before comparing the user's current biometric information collected by the terminal 20 with the biometric template, the method further includes: A biometric identification device is used to receive palm print and palm vein images entered by a user, and then use a feature extraction algorithm to extract features from the palm print and palm vein images to obtain a biometric template. The biometric identification device is also used to transmit the biometric template to the user terminal 10 for local encrypted storage, and to associate and bind the biometric template with the user's verified KYC identity information.
[0066] In one implementation, the identity verification is output in the form of a zero-knowledge proof, which indicates that the legitimate user who has been confirmed to control the asset account is present at this moment and agrees to make the payment.
[0067] In one embodiment, the terminal 20 is specifically used to: generate a transaction summary based on the transaction information, and send the transaction summary to the user terminal 10, wherein the transaction information includes merchant ID, store ID, currency, amount, and timestamp; The user terminal 10 is specifically used to: parse the transaction summary and then display the transaction information; The user terminal 10 is specifically used to: receive confirmation information from the user regarding the transaction information, and then receive confirmation from the user regarding the payment asset information, wherein the payment asset information includes: the blockchain network and the type of payment token.
[0068] In one embodiment, the user terminal 10 is specifically used to: send a transaction risk assessment request to the server terminal 30 after confirming the transaction information; The server 30 is specifically used to: after receiving a transaction risk assessment request, call the risk assessment engine to perform a real-time risk assessment on the assets of the user terminal 10.
[0069] In one embodiment, the server 30 is specifically used to: invoke the risk assessment engine to perform KYT risk assessment on the historical behavior of the payment address in the user terminal and the historical flow path of the payment token.
[0070] In one embodiment, the server 30 is specifically used to: after the server 30 passes the compliance verification of the payment asset; The user terminal 10 is specifically used for: initiating password payment authorization verification or biometric recognition payment authorization verification, and using a private key to sign the transaction data, generating a transaction signature, and broadcasting the transaction signature to the target blockchain network.
[0071] In one embodiment, the user terminal 10 is further configured to: cryptographically bind the spatiotemporal proof, the identity proof, and the transaction intention and asset compliance proof to generate a transaction evidence chain, and store the transaction evidence chain or the feature value of the transaction evidence chain in the evidence storage layer of the blockchain.
[0072] The digital currency payment system based on a multidimensional proof framework provided in this application can execute the aforementioned digital currency payment method based on a multidimensional proof framework. Its implementation principle and technical effects are similar, and will not be repeated here. Specific limitations regarding the digital currency payment system based on a multidimensional proof framework can be found in the limitations of the digital currency payment method based on a multidimensional proof framework described above, and will not be repeated here.
[0073] In another embodiment of this application, a computer-readable storage medium is also provided, on which a computer program is stored, wherein when the computer program is executed by a processor, the steps of the digital currency payment method based on a multidimensional proof framework as described in the embodiments of this application are implemented.
[0074] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When these computer instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks (SSDs)).
[0075] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0076] The above embodiments merely illustrate several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A digital currency payment method based on a multidimensional proof framework, characterized in that, The method includes: After the user terminal establishes a near-field communication link with the terminal, it verifies the location and time of the transaction between the user terminal and the terminal based on the near-field communication link, and generates a spacetime proof after the verification is successful. The user terminal compares the user's current biometric information collected by the terminal with the locally pre-stored biometric template, and generates a verification result certificate after a successful comparison. It then uses a private key to digitally sign the verification result certificate and generates an identity certificate after a successful signature. The biometric template is associated with and bound to the user's verified KYC identity information. During the transaction, after the user confirms the transaction information and payment asset information, the server is triggered to verify the compliance of the payment assets. After the verification is passed, the user authorizes the transaction and generates a certificate of transaction intent and asset compliance.
2. The method according to claim 1, characterized in that, Determining the location and time of a transaction between the user terminal and the terminal based on the near-field communication link includes: The terminal broadcasts terminal information via the near-field communication link. The terminal information includes: terminal location information, terminal current timestamp, and merchant identifier. After the user terminal hears the broadcast, it generates response information and sends the response information to the terminal. The response information includes the wallet identifier in the user terminal and the current timestamp of the user terminal. After determining that the time difference between the current timestamp of the terminal and the current timestamp of the user terminal is less than a preset threshold, the user terminal generates a spatiotemporal proof; wherein, the spatiotemporal proof includes the terminal information, the response information and the time difference.
3. The method according to claim 1, characterized in that, The biometric information is palmprint information. Before the user terminal compares the user's current biometric information collected by the terminal with the biometric template, the method further includes: After receiving the palm print and palm vein images entered by the user, the biometric identification device uses a feature extraction algorithm to extract features from the palm print and palm vein images to obtain a biometric template. The biometric identification device transmits the biometric template to the user terminal for local encrypted storage and associates and binds the biometric template with the user's verified KYC identity information.
4. The method according to claim 1, characterized in that, The identity verification is output in the form of a zero-knowledge proof, which indicates that the legitimate user who has been confirmed to control the asset account is present at this moment and agrees to make the payment.
5. The method according to claim 1, characterized in that, The process of confirming transaction information and payment asset information on the user's end includes: The terminal generates a transaction summary based on the transaction information and sends the transaction summary to the user terminal. The transaction information includes merchant ID, store ID, currency, amount, and timestamp. The user terminal parses the transaction summary and then displays the transaction information. After receiving confirmation of the transaction information from the user, the client receives confirmation of the payment asset information from the user, wherein the payment asset information includes: the blockchain network and the type of payment token.
6. The method according to claim 5, characterized in that, The server performs compliance verification on the transaction assets, including: After confirming the transaction information, the user sends a transaction risk assessment request to the server. Upon receiving the transaction risk assessment request, the server invokes the risk assessment engine to perform a real-time risk assessment of the user's assets.
7. The method according to claim 6, characterized in that, The process of calling the risk assessment engine to perform real-time risk assessment on the user's assets includes: The risk assessment engine is invoked to perform a KYT risk assessment on the historical behavior of the payment address in the user terminal and the historical flow path of the payment token.
8. The method according to claim 1, characterized in that, The triggering server performs compliance verification on the payment assets, and after successful verification, the user terminal authorizes the transaction, including: After the server verifies the compliance of the payment assets, the user initiates password payment authorization verification or biometric payment authorization verification, and uses a private key to sign the transaction data, generating a transaction signature, and broadcasts the transaction signature to the target blockchain network.
9. The method according to claim 1, characterized in that, After the user authorizes the transaction, the method further includes: The spatiotemporal proof, the identity proof, and the transaction intention and asset compliance proof are cryptographically bound to generate a transaction evidence chain, and the transaction evidence chain or the feature value of the transaction evidence chain is stored in the evidence storage layer of the blockchain.
10. A digital currency payment system based on a multidimensional proof framework, characterized in that, The system includes: a user terminal, a terminal, and a server. The user terminal is used to establish a near-field communication link with the terminal, verify the location and time of the transaction between the user terminal and the terminal based on the near-field communication link, and generate a spacetime proof after the verification is successful. The user terminal is used to compare the user's current biometric information collected by the terminal with the biometric template pre-stored locally, and generate a verification result certificate after successful comparison. The verification result certificate is digitally signed using a private key, and an identity certificate is generated after successful signing. The biometric template is associated with and bound to the user's verified KYC identity information. The user terminal is also used to trigger the server to perform compliance verification of the payment assets after confirming the transaction information and payment asset information during the transaction process. After the verification is passed, the user terminal authorizes the transaction and generates a transaction intention and asset compliance certificate.