Payment systems, terminals, and electronic payment programs

JP2026147413AActive Publication Date: 2026-09-17NTT DOCOMO INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025035281
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2026-09-17
Estimated Expiration
2045-03-06

AI Technical Summary

Benefits of technology

【0009】 本発明によれば、従来の技術と比較して、電子決済プログラムの起動からコード画像の表示までの期間が短くなる可能性が高くなる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026147413000001_ABST
    Figure 2026147413000001_ABST
Patent Text Reader

Abstract

Reduce the waiting time from launching the electronic payment program to displaying the code image. [Solution] A terminal device 1[q] that can communicate with a payment device 3 includes an information acquisition unit 112 that acquires an online token KX[q] from the payment device 3 when the terminal device 1[q] can communicate with the payment device 3, and a display control unit 114 that, when the information acquisition unit 112 acquires an online token KX[q], displays an online code image GX[q] based on the online token KX[q] on the display device 13 of the terminal device 1[q]. The display control unit 114, when the electronic payment program PG-T is started, displays an offline code image GY[q] based on an offline token KY[q] stored in the storage device 12 of the terminal device 1[q] on the display device 13, regardless of the communication status of the terminal device 1[q].
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a payment system, a terminal, and an electronic payment program. [Background Art]

[0002] Technologies related to electronic payment have become widespread, in which a terminal device such as a smartphone (which is an example of a "terminal") displays a code image based on a token supplied from a payment device, and the displayed code image is read by a store terminal such as a POS terminal installed in a store or the like to complete the payment. For example, Patent Document 1 discloses a technology related to two types of electronic payment: online electronic payment, which is executed by displaying an online code image (an example of a "first code image") on a terminal device based on an online token (an example of a "first token") supplied from a payment device when the terminal device and the payment device can communicate with each other; and offline electronic payment, which is executed by displaying an offline code image (an example of a "second code image") on the terminal device based on an offline token (an example of a "second token") that has been supplied in advance from the payment device and stored in the terminal device when communication between the terminal device and the payment device is difficult. [Prior Art Documents] [Patent Documents]

[0003] [Patent Document 1] Japanese Patent No. 7391263 [Summary of the Invention] [Problem to be Solved by the Invention]

[0004] In conventional technology, after the electronic payment program installed on the terminal device is launched, the payment device supplies an online token to the terminal device in response to a request for an online token sent from the terminal device to the payment device. Therefore, with conventional technology, even when the terminal device and the payment device can communicate, there may be a delay between the launch of the electronic payment program and the supply of the online token. Furthermore, with conventional technology, when communication between the terminal device and the payment device is difficult, there may be a delay in the terminal device detecting the communication status after the launch of the electronic payment program. In these cases, the waiting time from the launch of the electronic payment program to the display of the code image becomes long, which may be inconvenient for the terminal device user.

[0005] This invention has been made in view of the circumstances described above, and one of its objectives is to provide a technology that can significantly reduce the waiting time from the launch of an electronic payment program to the display of a code image compared to conventional technologies. [Means for solving the problem]

[0006] To solve the above problems, the electronic payment program according to the present invention is an electronic payment program installed in a terminal capable of communicating with a payment device, wherein the processor of the terminal functions as an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device, and a display control unit that, when the acquisition unit acquires the first token, causes a first code image based on the first token to be displayed on the display device of the terminal, and the display control unit, when the electronic payment program is started, causes a second code image based on a second token stored in the storage device of the terminal to be displayed on the display device, regardless of the communication status of the terminal.

[0007] Furthermore, the terminal according to the present invention is a terminal capable of communicating with a payment device, comprising: an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device; and a display control unit that, when the acquisition unit acquires the first token, causes a first code image based on the first token to be displayed on the display device of the terminal, wherein the display control unit, when an electronic payment program installed on the terminal is activated, causes a second code image based on a second token stored in the terminal's storage device to be displayed on the display device, regardless of the terminal's communication status.

[0008] Furthermore, the payment system according to the present invention is a payment system comprising a payment device and a terminal capable of communicating with the payment device, wherein the terminal comprises an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device, and a display control unit that, when the acquisition unit acquires the first token, causes a first code image based on the first token to be displayed on the display device of the terminal, and the display control unit, when an electronic payment program installed on the terminal is activated, causes a second code image based on a second token stored in the storage device of the terminal to be displayed on the display device, regardless of the communication status of the terminal. [Effects of the Invention]

[0009] According to the present invention, there is a high probability that the time from the launch of the electronic payment program to the display of the code image will be shortened compared to conventional technology. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing an example of the configuration of an electronic payment system Sys according to an embodiment of the present invention. [Figure 2] This is a block diagram showing an example of the configuration of terminal device 1[q]. [Figure 3] This is a block diagram showing an example of the configuration of payment device 3. [Figure 4] This is a sequence chart illustrating an example of the operation of the electronic payment system Sys. [Figure 5] It is an explanatory diagram showing an example of token response information DSW[q]. [Figure 6] It is an explanatory diagram showing an example of token response information DSW[q]. [Figure 7] It is a flow chart showing an example of the operation of the electronic payment system Sys. [Figure 8] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 9] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 10] It is a schematic diagram showing an example of an offline code image display screen GGY. [Figure 11] It is a schematic diagram showing an example of a payment method selection screen GGS. [Figure 12] It is a schematic diagram showing an example of an online code image display screen GGX. [Figure 13] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 14] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 15] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 16] It is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 17] It is a sequence chart showing an example of the operation of the electronic payment system according to the reference example. [Figure 18] It is a schematic diagram showing an example of the data structure of a payment code CC[q]. [Figure 19] It is a flow chart showing an example of the operation of the terminal device 1[q]. [Figure 20] It is a flow chart showing an example of the operation of the terminal device 1[q]. [Figure 21] It is a flow chart showing an example of the operation of the terminal device 1[q]. [Figure 22]It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 23] It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 24] It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 25] It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 26] It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 27] It is a flowchart illustrating an example of an operation of terminal device 1[q]. [Figure 28] It is a flowchart illustrating an example of an operation of payment device 3. [Figure 29] It is a flowchart illustrating an example of an operation of payment device 3. [Figure 30] It is a flowchart illustrating an example of an operation of payment device 3. [Figure 31] It is a flowchart illustrating an example of an operation of payment device 3. [Figure 32] It is a flowchart illustrating an example of an operation of payment device 3. [Figure 33] It is a flowchart illustrating an example of an operation of an electronic payment system Sys according to Modification 3 of the present invention. [Figure 34] It is a sequence chart illustrating an example of an operation of an electronic payment system Sys according to Modification 3 of the present invention. [Figure 35] It is a sequence chart illustrating an example of an operation of an electronic payment system Sys according to Modification 3 of the present invention. [Figure 36] It is a flowchart illustrating an example of an operation of an electronic payment system Sys according to Modification 4 of the present invention. [Figure 37] It is a sequence chart illustrating an example of an operation of an electronic payment system Sys according to Modification 4 of the present invention. [Figure 38] It is a flowchart illustrating an example of an operation of an electronic payment system Sys according to Modification 5 of the present invention. [Figure 39]It is a sequence chart showing an example of the operation of the electronic payment system Sys according to Modification 6 of the present invention. [Figure 40] It is a sequence chart showing an example of the operation of the electronic payment system Sys according to Modification 9 of the present invention. Description of Embodiments

[0011] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. In each of the drawings, the dimensions and scale of each part are appropriately different from the actual ones. Further, since the embodiments described below are preferred specific examples of the present invention, various technically preferable limitations are attached thereto. However, the scope of the present invention is not limited to these embodiments unless there is a description that specifically limits the present invention in the following explanation.

[0012] <A. Embodiment> Hereinafter, an embodiment of the present invention will be described.

[0013] <A.1. Overview of Electronic Payment System Sys> An overview of the electronic payment system Sys will be described with reference to FIGS. 1 to 3.

[0014] FIG. 1 is a block diagram showing an example of the configuration of the electronic payment system Sys.

[0015] As shown in FIG. 1, the electronic payment system Sys includes a payment device 3, a store device 5 communicable with the payment device 3 via a network NW, and one or more terminal devices 1 communicable with the payment device 3 via the network NW, and provides services related to electronic payment to a user U of the terminal device 1.

[0016] In this embodiment, as an example, we assume that the electronic payment system Sys has multiple terminal devices 1. Specifically, in this embodiment, we assume that the electronic payment system Sys has Q terminal devices 1. Here, the value Q is a natural number satisfying "Q≧2". Furthermore, below, the q-th terminal device 1 among the Q terminal devices 1 provided by the electronic payment system Sys will be referred to as terminal device 1[q]. Here, the variable q is a natural number satisfying "1≦q≦Q". Furthermore, below, the user U who uses terminal device 1[q] will be referred to as user U[q].

[0017] Terminal device 1[q] (an example of a "terminal") is, for example, a mobile device such as a smartphone or tablet, and is carried by user U[q]. In this embodiment, the electronic payment program PG-T is installed on terminal device 1[q]. By executing the electronic payment program PG-T, terminal device 1[q] launches an electronic payment application (hereinafter sometimes referred to as the "payment app"). When user U[q] of terminal device 1[q] receives a service at a store where the store device 5 is installed, they can pay for the service by electronic payment by using the payment app running on terminal device 1[q] to display a code image GG based on the token KK obtained from the payment device 3 on terminal device 1[q].

[0018] Hereinafter, the code image GG displayed on terminal device 1[q] will be referred to as code image GG[q]. Code image GG[q] is, for example, a barcode or a two-dimensional code. In this embodiment, as an example, we assume that code image GG[q] is a barcode. Furthermore, hereafter, the token KK supplied from payment device 3 to terminal device 1[q] will be referred to as token KK[q].

[0019] In this embodiment, it is assumed that the store where the store device 5 is installed is a physical store located in the real world, i.e., a real store. Furthermore, in this embodiment, it is assumed that the services provided at the store are the sale of goods or the provision of services. In other words, in this embodiment, when a user U[q] of terminal device 1[q] receives goods or services at the store where the store device 5 is installed, the user U[q] can pay for such goods or services electronically.

[0020] Store device 5 is, for example, a POS (Point of Sales) register. Store device 5 reads the code image GG[q] displayed on terminal device 1[q] when user U[q] of terminal device 1[q] pays for services provided by the store via electronic payment. Next, store device 5 generates payment information DP[q] by adding store payment information DF[q] to the payment code CC[q] which is the value indicated by the read code image GG[q], and supplies the generated payment information DP[q] to payment device 3. Here, store payment information DF[q] is, for example, information that includes store identification information to uniquely identify the store that provided services to user U[q], the payment amount that user U[q] should pay as consideration for the services provided to user U[q], and the payment date and time, which is the date and time when the payment is made.

[0021] When payment device 3 receives payment information DP[q] from store device 5, it executes payment processing based on said payment information DP[q]. Here, payment processing is the process of confirming payment from user U[q] of terminal device 1[q] to the store as consideration for the service received from the store.

[0022] Furthermore, in this embodiment, as an example, we assume that the payment device 3 manages the usage fees for terminal device 1[q] by user U[q]. Here, the usage fees for terminal device 1[q] include, for example, the purchase price of terminal device 1[q] and communication charges incurred when terminal device 1[q] communicates. In this embodiment, for example, on the payment date of each month, the payment device 3 deducts the usage fees for terminal device 1[q] from the bank account of user U[q] that has been registered with the payment device 3 in advance. In the following, the usage fees for terminal device 1[q] may be referred to as "telephone charges". Furthermore, in this embodiment, as an example, we assume that the payment device 3 manages the electronic money of user U[q] that is available at terminal device 1[q]. In this embodiment, we assume that the electronic money managed by the payment device 3 is so-called prepaid electronic money, and that user U[q] can use electronic money equivalent to the amount charged by pre-charging the electronic money. However, the present invention is not limited to this embodiment. The electronic money managed by the payment device 3 may also be so-called postpaid electronic money that can be used within a predetermined upper limit. Furthermore, in this embodiment, as an example, we assume that the payment device 3 manages the credit cards that user U[q] can use for electronic payments in the electronic payment system Sys. In this embodiment, we assume that the payment device 3 is able to communicate with a credit card server operated by a credit card company, and that user U[q] can make payments using the credit card issued by the credit card company.

[0023] In this embodiment, the payment device 3 can perform the payment processing corresponding to user U[q] of terminal device 1[q] using the payment method selected by user U[q] from among three types of payment methods: telephone bill combined payment, prepaid balance payment, and credit card payment. Here, combined telephone bill payment is a payment method in which the usage fee for terminal device 1[q] is added to the payment method and the user U[q] pays the store. Prepaid balance payment is a payment method in which the user U[q] pays the store using the electronic money managed by payment device 3. Credit card payment is a payment method in which the user U[q] pays the store using the user U[q]'s credit card.

[0024] Furthermore, in this embodiment, as described above, the payment device 3 issues tokens KK[q] in response to a request from terminal device 1[q] and supplies the issued tokens KK[q] to terminal device 1[q].

[0025] The following describes an example of the operation of the electronic payment system Sys (hereinafter sometimes referred to as "online electronic payment") when the terminal device 1[q] and the payment device 3 are able to communicate, and the electronic payment system Sys according to this embodiment provides electronic payment services to user U[q] of terminal device 1[q]. First, when user U[q] of terminal device 1[q] receives a service at a store where store device 5 is installed and pays for the service via online electronic payment, user U[q] operates terminal device 1[q] to launch the payment application on terminal device 1[q]. Next, when the payment application is launched, terminal device 1[q] requests token KK[q] from payment device 3. Next, payment device 3 supplies token KK[q] to terminal device 1[q] in response to the request from terminal device 1[q]. Next, terminal device 1[q] generates a payment code CC[q] based on the token KK[q] supplied by payment device 3 and displays a code image GG[q] representing the payment code CC[q]. Next, the store device 5 reads the code image GG[q] displayed on the terminal device 1[q] to generate payment information DP[q], which includes the payment code CC[q] indicated by the code image GG[q] and the store payment information DF[q], and supplies this payment information DP[q] to the payment device 3. Next, the payment device 3 executes the payment process based on the payment information DP[q] supplied from the store device 5, thereby confirming the payment from user U[q] to the store.

[0026] In the online electronic payment described above, the payment device 3 issues a token KK[q] in response to a request from the terminal device 1[q]. Therefore, online electronic payment can only be performed when the terminal device 1[q] and the payment device 3 can communicate, and cannot be performed when communication between the terminal device 1[q] and the payment device 3 is difficult. Accordingly, in the case where communication between the terminal device 1[q] and the payment device 3 is difficult, the electronic payment system Sys according to this embodiment performs payment processing using payment information DP[q] generated based on the token KK[q] stored in the terminal device 1[q].

[0027] The following describes an example of the operation of the electronic payment system Sys according to this embodiment when communication between terminal device 1[q] and payment device 3 is difficult, and the electronic payment system Sys provides electronic payment services to user U[q] of terminal device 1[q] (hereinafter sometimes referred to as "offline electronic payment"). First, when user U[q] of terminal device 1[q] receives a service at a store where store device 5 is installed and pays for the service via offline electronic payment, user U[q] operates terminal device 1[q] to launch the payment application on terminal device 1[q]. Next, when the payment application is launched, terminal device 1[q] generates a payment code CC[q] based on token KK[q] stored in terminal device 1[q] and displays a code image GG[q] representing the payment code CC[q]. Next, store device 5 reads the code image GG[q] displayed on terminal device 1[q] and generates payment information DP[q] including the payment code CC[q] indicated by the code image GG[q] and store payment information DF[q], and supplies this payment information DP[q] to payment device 3. Next, payment device 3 executes the payment process based on the payment information DP[q] supplied by store device 5, thereby confirming the payment from user U[q] to the store.

[0028] As described above, the electronic payment system Sys according to this embodiment can perform two types of electronic payments: online electronic payment when terminal device 1[q] and payment device 3 can communicate, and offline electronic payment when terminal device 1[q] and payment device 3 cannot communicate. Therefore, compared to an embodiment where only online electronic payment is possible, it can improve the convenience of the user U[q] of terminal device 1[q].

[0029] In the following, a token KK[q] acquired by terminal device 1 from payment device 3 in online electronic payment, which is used to generate payment code CC[q], will be referred to as online token KX[q] (an example of a "first token"), and a token KK[q] stored in terminal device 1[q] in offline electronic payment, which is used to generate payment code CC[q], will be referred to as offline token KY[q] (an example of a "second token"). Furthermore, in the following, the payment code CC[q] generated by terminal device 1[q] from online token KX[q] in online electronic payments may be referred to as the online payment code CX[q], and the payment code CC[q] generated by terminal device 1[q] from offline token KY[q] in offline electronic payments may be referred to as the offline payment code CY[q]. Furthermore, in the following, in online electronic payments, the code image GG[q] displayed by terminal device 1[q] based on the online payment code CX[q] will be referred to as the online code image GX[q] (an example of the "first code image"), and in offline electronic payments, the code image GG[q] displayed by terminal device 1[q] based on the offline payment code CY[q] will be referred to as the offline code image GY[q] (an example of the "second code image"). Furthermore, in the following, the payment processing performed by payment device 3 in online electronic payments may be referred to as online payment processing, and the payment processing performed by payment device 3 in offline electronic payments may be referred to as offline payment processing.

[0030] In this embodiment, even when user U[q] of terminal device 1[q] makes payment via online electronic payment, if terminal device 1[q] stores offline token KY[q], terminal device 1[q] generates an offline payment code CY[q] based on the offline token KY[q] stored in terminal device 1[q] before displaying the online code image GX[q] based on the online token KX[q] supplied from payment device 3 after the payment application is launched, and displays the offline code image GY[q] representing the said offline payment code CY[q]. Therefore, in this embodiment, if it takes time from the launch of the payment application to the display of the online code image GX[q], and it takes a long time to make a payment via online electronic payment, the offline code image GY[q] is displayed after the launch of the payment application and before the display of the online code image GX[q], thus enabling a quick payment via offline electronic payment.

[0031] Figure 2 is a block diagram showing an example of the configuration of terminal device 1[q].

[0032] As shown in Figure 2, the terminal device 1[q] comprises a control device 11, a storage device 12, a display device 13, an input device 14, a communication device 15, and a bus 100 that connects these devices to each other.

[0033] The storage device 12 is a recording medium that can be read by the control device 11. The storage device 12 is configured to include, for example, volatile memory such as RAM (Random Access Memory) that functions as a work area for the control device 11, and non-volatile memory such as EEPROM (Electrically Erasable Programmable Read-Only Memory) that stores various information, and stores user identification information DID[q], acquired offline token information KYY[q], offline blockage information DHY, business operator identification token KZ, token response information DSW[q], setting information DS, and electronic payment program PG-T.

[0034] The user identification information DID[q] is identification information used to uniquely identify user U[q] of terminal device 1[q] from among the Q users U[1] to U[Q] managed by payment device 3.

[0035] The acquired offline token information KYY[q] is information containing one or more offline tokens KY[q] acquired by terminal device 1[q] from payment device 3. In this embodiment, it is assumed that terminal device 1[q] has acquired offline tokens KY[q] M times from payment device 3 during the period from when the payment application was first launched (initial launch) on terminal device 1[q] to the present. Here, the value M is a natural number satisfying "M≧1". Below, the offline token KY[q] acquired by terminal device 1[q] from payment device 3 on the mth time will be referred to as offline token KY[q][m]. Here, the variable m is a natural number satisfying "1≦m≦M".

[0036] In this embodiment, it is assumed that the acquired offline token information KYY[q] comprises M records that correspond one-to-one with the M offline tokens KY[q][1] to KY[q][M] acquired by the terminal device 1[q] from the payment device 3. Of the M records contained in the acquired offline token information KYY[q], the m-th record includes the offline token KY[q][m], the offline token validity period information DTY[q][m], and the cryptographic key KS[q][m].

[0037] Here, the offline token validity period information DTY[q][m] represents the period during which the offline token KY[q][m] can be used in offline electronic payments, i.e., the validity period of the offline token KY[q][m], which is the offline token validity period TY[q][m]. In this embodiment, it is assumed that the offline token validity period TY[q][m] is a period that starts from the time of creation of the offline token KY[q][m] and ends at a time that has elapsed from the time of creation of the offline token KY[q][m] by the offline token validity period TSY. Here, in this embodiment, as an example, it is assumed that the offline token validity period TSY is set to "1 week". In other words, in this embodiment, as an example, it is assumed that the validity period of the offline token KY[q] is 1 week.

[0038] Furthermore, the encryption key KS[q][m] is information used to generate the offline payment code CY[q] in offline electronic payments.

[0039] Thus, in this embodiment, it is assumed that the acquired offline token information KYY[q] includes M offline tokens KY[q][1] to KY[q][M] acquired by the terminal device 1[q] from the payment device 3. However, the present invention is not limited to this embodiment. The acquired offline token information KYY[q] only needs to include at least the last acquired offline token KY[q][M] among the M offline tokens KY[q][1] to KY[q][M] acquired by the terminal device 1[q] from the payment device 3. For example, terminal device 1[q] may delete expired offline tokens KY[q][m] (specifically, offline tokens KY[q][m] whose expiration date has arrived, as indicated by the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m]) from the M offline tokens KY[q][1] to KY[q][M] acquired from payment device 3. Specifically, terminal device 1[q] may delete offline tokens KY[q][m] (specifically, expired offline tokens KY[q]) from acquired offline token information KYY[q] if the expiration date of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] included in acquired offline token information KYY[q] stored in storage device 12 is in the past time (i.e., expired). In this case, acquired offline token information KYY[q] will only include offline tokens KY[q] that are still within their validity period. Furthermore, for example, terminal device 1[q] may delete offline tokens KY[q][1] to KY[q][M-1] from the M offline tokens KY[q][1] to KY[q][M] acquired from payment device 3, except for the last acquired offline token KY[q][M]. Specifically, terminal device 1[q] may delete previously acquired offline tokens KY[q][M-1] when it acquires the latest offline token KY[q][M] from payment device 3. In this case, the acquired offline token information KYY[q] will contain only the latest offline token KY[q][M].

[0040] Furthermore, in this embodiment, it is assumed that the acquired offline token information KYY[q] includes M offline token validity period information DTY[q][1]~DTY[q][M] and M cryptographic keys KS[q][1]~KS[q][M]. However, the present invention is not limited to this embodiment. The acquired offline token information KYY[q] only needs to include at least the offline token validity period information DTY[q][M] corresponding to the last acquired offline token KY[q][M] among the M offline token validity period information DTY[q][1]~DTY[q][M] and the cryptographic key KS[q][M] corresponding to the last acquired offline token KY[q][M] among the M cryptographic keys KS[q][1]~KS[q][M]. For example, terminal device 1[q] may delete the encryption key KS[q][m] corresponding to the expired offline token KY[q][m] from the M encryption keys KS[q][1] to KS[q][M] acquired from payment device 3 (specifically, the encryption key KS[q][m] corresponding to the offline token KY[q][m] whose offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] has reached its end). Specifically, terminal device 1[q] may delete the encryption key KS[q][m] corresponding to the expired offline token KY[q][m] from acquired offline token information KYY[q] stored in storage device 12 if the end of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] is in the past time (i.e., the offline token KY[q][m] has expired). In this case, the acquired offline token information KYY[q] will only include the cryptographic key KS[q] corresponding to the offline token KY[q] that is still within its validity period. Furthermore, for example, terminal device 1[q] may delete all encryption keys KS[q][1] to KS[q][M-1] from the M encryption keys KS[q][1] to KS[q][M] obtained from payment device 3, except for the last encryption key KS[q][M] obtained. Specifically, terminal device 1[q] may delete previously obtained encryption keys KS[q][M-1] when it obtains the latest encryption key KS[q][M] from payment device 3. In this case, the acquired offline token information KYY[q] will contain only the latest encryption key KS[q][M].

[0041] The offline blocking information DHY is information used in offline electronic payment to determine whether or not to display the offline code image GY[q] on the terminal device 1[q]. Specifically, the offline blocking information DHY indicates whether or not the payment device 3 is capable of performing offline payment processing. More specifically, the offline blocking information DHY may indicate whether or not the functions of the payment device 3 for performing offline payment processing are operating without being blocked.

[0042] The business identification token KZ includes business identification information DKZ, which identifies the payment service provider that manages payment device 3.

[0043] The token response information DSW[q] indicates the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q].

[0044] The online token response waiting time TSWX[q] is the length of the online token response waiting period TWX[q]. In this embodiment, the online token response waiting period TWX[q] is the waiting period of terminal device 1[q] from the time terminal device 1[q] requests online token KX[q] from payment device 3 until online token KX[q] is supplied to terminal device 1[q]. However, the present invention is not limited to this embodiment. The online token response waiting period TWX[q] may also be the waiting period of terminal device 1[q] from the time the payment application is launched on terminal device 1[q] until online token KX[q] is supplied to terminal device 1[q]. In this embodiment, terminal device 1[q] waits for the supply of online token KX[q] from payment device 3 during the online token response waiting period TWX[q]. Then, at the time the online token response waiting period TWX[q] ends, terminal device 1[q] stops waiting for the supply of online token KX[q] from payment device 3. In this embodiment, we assume that the online token response waiting time TSWX[q] is determined based on the performance of the terminal device 1[q].

[0045] The offline token response waiting time TSWY[q] is the length of the offline token response waiting period TWY[q]. The offline token response waiting period TWY[q] is the waiting period of terminal device 1[q] from the time terminal device 1[q] requests the offline token KY[q] from payment device 3 until the offline token KY[q] is supplied to terminal device 1[q]. However, the present invention is not limited to this embodiment. The offline token response waiting period TWY[q] may also be the waiting period of terminal device 1[q] from the time the payment application is launched on terminal device 1[q] until the offline token KY[q] is supplied to terminal device 1[q]. In this embodiment, terminal device 1[q] waits for the supply of the offline token KY[q] from payment device 3 during the offline token response waiting period TWY[q]. Then, when the offline token response waiting period TWY[q] ends, terminal device 1[q] stops waiting for the supply of the offline token KY[q] from payment device 3. In this embodiment, we assume that the offline token response waiting time TSWY[q] is determined based on the performance of the terminal device 1[q].

[0046] The configuration information DS includes online token validity information DSX, offline token validity information DSY, and update time information DSC.

[0047] The online token validity information DSX indicates the duration (hereinafter referred to as "online token validity time TSX") of the period during which the online token KX[q] can be used in online electronic payments (hereinafter referred to as "online token validity period TX[q]"). In this embodiment, as an example, we assume that the online token validity time TSX is set to "5 minutes". However, the present invention is not limited to this embodiment. The online token validity time TSX may be longer than the online token response waiting time TSWX[q]. In this embodiment, the online token validity period TX[q] is a period that starts from the time of creation of the online token KX[q] and ends at a time that has elapsed from the time of creation of the online token KX[q] by the online token validity time TSX.

[0048] The offline token validity information DSY indicates the offline token validity period TSY. As described above, the offline token validity period TSY is the length of the offline token validity period TY[q][m] during which the offline token KY[q][m] can be used in offline electronic payments. Also, as described above, in this embodiment, as an example, we assume that the offline token validity period TSY is set to "1 week". However, the present invention is not limited to this embodiment. The offline token validity period TSY only needs to be longer than the online token validity period TSX.

[0049] The update time information DSC is information indicating the update unit time TC. Here, the update unit time TC is the update cycle of the terminal time value AG based on the terminal time TG, which is the current time managed by terminal device 1[q]. In this embodiment, as an example, we assume that the update unit time TC is set to "1 minute". Also, in this embodiment, as an example, we assume that the terminal time value AG is a value obtained by expressing the terminal time TG in the order of "minutes". For example, in this embodiment, if the terminal time TG is "18:25:37", the terminal time value AG may be "1825", obtained by removing "37 seconds" from the terminal time TG. However, the present invention is not limited to such embodiments. The update unit time TC may be shorter than the offline token validity period TSY. Also, the update unit time TC may be shorter than the online token validity period TSX.

[0050] The control device 11 is configured to include a processor. The processor provided in the control device 11 is configured to include, for example, one or more CPUs (Central Processing Units). However, the processor provided in the control device 11 may be configured to include hardware such as a GPU (Graphics Processing Unit), DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), PLD (Programmable Logic Device), FPGA (Field Programmable Gate Array), etc., in addition to one or more CPUs, or in place of some or all of one or more CPUs. The processor provided in the control device 11 executes the electronic payment program PG-T stored in the storage device 12 and operates according to the electronic payment program PG-T, thereby functioning as an information transmission unit 111, an information acquisition unit 112, a code generation unit 113, a display control unit 114, and a communication status determination unit 115.

[0051] During the online token response waiting period TWX[q], the information transmission unit 111 transmits an online token request RX to the settlement device 3 requesting the online token KX[q]. The online token request RX may include, for example, information indicating that the online token KX is requested and user identification information DID[q]. Furthermore, during the offline token response waiting period TWY[q], the information transmission unit 111 transmits an offline token request RY to the settlement device 3 requesting the offline token KY[q]. The offline token request RY may include, for example, information indicating that the offline token KY is requested and user identification information DID[q]. The information transmission unit 111 also transmits terminal information DTM[q], which will be described later, to the settlement device 3. Furthermore, the information transmission unit 111 transmits an online blockage information request BX to the settlement device 3 requesting the online blockage information DHX and an offline blockage information request BY to the settlement device 3 requesting the offline blockage information DHY. Here, online blocking information DHX is information used to determine whether or not to display the online code image GX[q] on terminal device 1[q] in online electronic payment. Specifically, online blocking information DHX is information indicating whether or not payment device 3 is capable of executing online payment processing. More specifically, online blocking information DHX may be information indicating whether or not the functions of payment device 3 for executing online payment processing are operating without being blocked. In the following, online blocking information DHX and offline blocking information DHY may be collectively referred to as blocking information DH.

[0052] The information acquisition unit 112 is an example of an "acquisition unit" and acquires online token KX[q], offline token KY[q], online blockage information DHX, offline blockage information DHY, token response information DSW[q], business operator identification token KZ, and setting information DS supplied from the payment device 3 in response to a request from the terminal device 1[q]. The information acquisition unit 112 also acquires the offline token KY[q] stored in the storage device 12.

[0053] The code generation unit 113 generates an online payment code CX[q] based on the online token KX[q] acquired by the information acquisition unit 112. The code generation unit 113 also generates an offline payment code CY[q] based on the offline token KY[q] acquired by the information acquisition unit 112 and stored in the storage device 12.

[0054] In online electronic payments, the display control unit 114 causes the display device 13 to display an online code image GX[q] based on the online payment code CX[q] generated by the code generation unit 113. In offline electronic payments, the display control unit 114 causes the display device 13 to display an offline code image GY[q] based on the offline payment code CY[q] generated by the code generation unit 113.

[0055] The communication status determination unit 115 determines whether the communication status of terminal device 1[q] is online or not. Specifically, the communication status determination unit 115 may, for example, use the communication status monitoring function of terminal device 1[q] provided by the operating system of terminal device 1[q] to determine whether the communication status of terminal device 1[q] is online or not. Here, "the communication status of terminal device 1[q] is online" means, for example, that terminal device 1[q] is in a state where it can communicate with an external device located outside of terminal device 1[q], or that when terminal device 1[q] is performing wireless communication, the radio wave strength related to the wireless communication is above a predetermined strength.

[0056] The display device 13 is hardware for displaying various types of information. The display device 13 can employ various display panels, such as a liquid crystal display panel or an organic EL display panel. In this embodiment, the display device 13 displays various images, such as an online code image GX[q] and an offline code image GY[q], under the control of the display control unit 114.

[0057] The input device 14 is hardware for receiving operations from user U[q] of terminal device 1[q]. The input device 14 can be, for example, a keyboard, mouse, microphone, switch, button, sensor, or a combination of these devices. The display device 13 and the input device 14 may be configured as a single unit. In this case, for example, a touch panel may be used as both the display device 13 and the input device 14.

[0058] The communication device 15 is hardware for communicating with an external device located outside the terminal device 1[q] via the network NW. In this embodiment, the information transmission unit 111 transmits various information to the payment device 3 via the communication device 15. The information acquisition unit 112 acquires various information from the payment device 3 via the communication device 15.

[0059] Figure 3 is a block diagram showing an example of the configuration of the payment device 3.

[0060] As shown in Figure 3, the payment device 3 comprises a control device 31, a storage device 32, a communication device 35, and a bus 300 that connects these devices to each other.

[0061] The storage device 32 is a recording medium that can be read by the control device 31. The storage device 32 is configured to include, for example, a volatile memory such as RAM that functions as a work area for the control device 31, and a non-volatile memory such as EEPROM that stores various information, and stores user management information DU, online token payout information DKX, offline token payout information DKY, business operator identification information DKZ, terminal-specific token response information DW, settlement management information DKP, setting information DS, and control program PG-S.

[0062] The user management information DU has Q records that correspond one-to-one with Q users U[1] to U[Q] managed by the payment device 3. Each record of the user management information DU includes, in addition to the user identification information DID[q] described above, electronic money balance information DPR[q], telephone charge information DTL[q], credit card information DCR[q], points information DPT[q], and user payment information DSH[q].

[0063] Electronic money balance information DPR[q] is information that shows the balance of electronic money held by user U[q]. The telephone charge information DTL[q] is information indicating the telephone charges that user U[q] should pay (i.e., the usage fee for terminal device 1[q]). Credit card information DCR[q] is information about a credit card owned by user U[q] that user U[q] has registered with payment device 3 via terminal device 1[q]. Specifically, credit card information DCR[q] indicates, for example, the card number, expiration date, etc., of the credit card owned by user U[q]. The point information DPT[q] is information regarding points awarded by the payment device 3 to user U[q]. In this embodiment, it is assumed that when the payment device 3 awards points to user U[q], user U[q] becomes able to use electronic money equivalent to the amount of points awarded. User payment information DSH[q] is information indicating the payment method selected by user U[q].

[0064] Online token payout information DKX has one or more records that correspond one-to-one with one or more online tokens KX issued by settlement device 3. Each record of online token payout information DKX includes the online token KX[q] issued by settlement device 3, the user identification information DID[q] of user U[q] corresponding to the terminal device 1[q] to which the online token KX[q] was issued, and information indicating the online token validity period TX[q] corresponding to the online token KX[q] (hereinafter referred to as "online token validity period information DTX[q]").

[0065] Furthermore, the settlement device 3 may delete one or more records in the online token payout information DKX for which the end date of the online token validity period TX[q] indicated by the online token validity period information DTX[q] has arrived. Specifically, if the end date of the online token validity period TX[q] indicated by the online token validity period information DTX[q] is in the past time (i.e., the token has expired), the settlement device 3 may delete the online token KX[q] corresponding to the online token validity period information DTX[q] (i.e., the expired online token KX[q]) from among the one or more online tokens KX included in the online token payout information DKX. Furthermore, if the payment device 3 has issued multiple online tokens KX[q] in the online token payout information DKX corresponding to user U[q], it may delete all records from among the multiple records corresponding to the multiple online tokens KX[q] except for the record corresponding to the most recently issued online token KX[q].

[0066] The offline token issuance information DKY has one or more records that correspond one-to-one with one or more offline tokens KY issued by the payment device 3. Each record of the offline token issuance information DKY includes the offline token KY[q] issued by the payment device 3, the cryptographic key KS[q] issued by the payment device 3 in accordance with the offline token KY[q], the user identification information DID[q] of user U[q] corresponding to the terminal device 1[q] to which the offline token KY[q] was issued, and the offline token validity period information DTY[q][m] indicating the offline token validity period TY[q][m] corresponding to the offline token KY[q].

[0067] Furthermore, the payment device 3 may delete one or more records in the offline token payout information DKY for which the end of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] has arrived. Specifically, if the end of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] is in the past time (i.e., the token has expired), the payment device 3 may delete the offline token KY[q][m] corresponding to the offline token validity period information DTY[q][m] (i.e., the expired offline token KY[q][m]) from among the one or more offline token KYs included in the offline token payout information DKY, and may also delete the cryptographic key KS[q][m] corresponding to the offline token validity period information DTY[q][m] (i.e., the expired cryptographic key KS[q][m]) from among the multiple cryptographic keys KS included in the offline token payout information DKY. Furthermore, in the offline token payout information DKY, the payment device 3 may delete records from the M records corresponding to the M offline tokens KY[q][1] to KY[q][M] that were issued in accordance with user U[q], except for the record corresponding to the most recent offline token KY[q][M]. In other words, in the offline token payout information DKY, the payment device 3 may delete offline tokens KY[q] from the M offline tokens KY[q][1] to KY[q][M] that were issued in accordance with user U[q], except for the last offline token KY[q][M]. Also, in the offline token payout information DKY, the payment device 3 may delete encryption keys KS[q] from the M encryption keys KS[q][1] to KS[q][M] that were issued in accordance with user U[q], except for the last encryption key KS[q][M].

[0068] The token response information DW for each terminal includes Q token response information DSW[1] to DSW[Q] that correspond one-to-one to the Q terminal devices 1[1] to 1[Q] provided by the electronic payment system Sys. As described above, the token response information DSW[q] issued in relation to terminal device 1[q] indicates the online token response waiting time TSWX[q] which defines the length of the online token response waiting period TWX[q], and the offline token response waiting time TSWY[q] which defines the length of the offline token response waiting period TWY[q].

[0069] The payment management information DKP has one or more records that correspond one-to-one with one or more electronic payments performed in the electronic payment system Sys. Each record in the payment management information DKP contains payment information DP[q] corresponding to each electronic payment.

[0070] The control device 31 is configured to include a processor. The processor provided in the control device 31 is configured to include, for example, one or more CPUs. However, the processor provided in the control device 31 may be configured to include hardware such as a GPU, DSP, ASIC, PLD, FPGA, etc., in addition to one or more CPUs, or in place of some or all of the one or more CPUs. The processor provided in the control device 31 executes a control program PG-S stored in the storage device 32 and operates according to the control program PG-S, thereby functioning as an information supply unit 311, an information receiving unit 312, and a settlement processing unit 313.

[0071] The information supply unit 311 supplies the online token KX[q], online blocking information DHX, offline token KY[q], offline blocking information DHY, token response information DSW[q], operator identification token KZ, and setting information DS to the terminal device 1[q] in response to a request from the terminal device 1[q].

[0072] The information receiving unit 312 receives terminal information DTM[q], online token request RX, online blockage information request BX, offline token request RY, and offline blockage information request BY from the terminal device 1[q]. The information receiving unit 312 also receives payment information DP[q] from the store device 5.

[0073] The settlement processing unit 313 executes settlement processing based on the settlement information DP[q]. Specifically, in online electronic payments, the settlement processing unit 313 executes online settlement processing based on the settlement information DP[q], and in offline electronic payments, it executes offline settlement processing based on the settlement information DP[q].

[0074] The communication device 35 is hardware for communicating with external devices such as the terminal device 1[q] and the store device 5 existing outside the payment device 3 via the network NW. In the present embodiment, the information supply unit 311 supplies various types of information to the terminal device 1[q] via the communication device 35. Further, the information reception unit 312 acquires various types of information from the terminal device 1[q] and the store device 5 via the communication device 35.

[0075] <A.2. Operation of Electronic Payment System Sys> Hereinafter, an outline of the operation of the electronic payment system Sys will be described with reference to FIGS. 4 to 17.

[0076] <A.2.1. Operation of Electronic Payment System Sys when the Payment Application is Launched for the First Time> FIG. 4 is a sequence chart showing an example of the operation of the electronic payment system Sys when the payment application in the terminal device 1[q] is launched for the first time.

[0077] As shown in FIG. 4, the control device 11 of the terminal device 1[q] launches the payment application by executing the electronic payment program PG-T based on the operation of the user U[q] (S1). Note that in the sequence chart shown in FIG. 4, a case is assumed where the launch of the payment application on the terminal device 1[q] is a first launch. For example, the control device 11 of the terminal device 1[q] may determine whether or not the launch of the payment application on the terminal device 1[q] is the first launch by referring to a launch history (not shown) of the payment application stored in the storage device 12 or the like.

[0078] Next, the electronic payment system Sys executes a first launch process (S0).

[0079] Specifically, the communication state determination unit 115 of the terminal device 1[q] determines whether or not the communication state of the terminal device 1[q] is an online state in the first launch process (S01). Note that in the sequence chart shown in FIG. 4, a case is assumed where the communication state of the terminal device 1[q] is an online state.

[0080] Next, the information transmission unit 111 of the terminal device 1[q] transmits terminal information DTM[q] to the payment device 3 during the initial startup process (S02). Here, terminal information DTM[q] is information regarding the performance of the terminal device 1[q]. In this embodiment, as an example, it is assumed that terminal information DTM[q] indicates the memory capacity α of the terminal device 1[q]. Here, memory capacity α is the capacity of volatile memory such as RAM among the storage device 12 of the terminal device 1[q].

[0081] Next, in the initial startup process, the control device 31 of the payment device 3 supplies token response information DSW[q] to the terminal device 1[q] as a response to the terminal information DTM[q] supplied from the terminal device 1[q] in step S02 (S03). Specifically, in step S03, the information receiving unit 312 of the payment device 3 acquires terminal information DTM[q] supplied from terminal device 1[q]. Next, the control device 31 of the payment device 3 generates token response information DSW[q] based on the terminal information DTM[q]. Then, the information supply unit 311 of the payment device 3 supplies the generated token response information DSW[q] to terminal device 1[q].

[0082] Figure 5 is an explanatory diagram illustrating an example of the relationship between terminal information DTM[q] and token response information DSW[q].

[0083] As shown in Figure 5, in this embodiment, in step S03, the control device 31 determines the online token response waiting time TSWX[q] to the value TKX1 if the memory capacity α indicated by the terminal information DTM[q] is greater than or equal to the threshold α0, and determines the online token response waiting time TSWX[q] to the value TKX2, which is greater than the value TKX1, if the memory capacity α indicated by the terminal information DTM[q] is less than the threshold α0. In this embodiment, as an example, it is assumed that the value TKX1 is "5 seconds" and the value TKX2 is "10 seconds".

[0084] Furthermore, in this embodiment, in step S03, the control device 31 determines the offline token response waiting time TSWY[q] to the value TKY1 if the memory capacity α indicated by the terminal information DTM[q] is greater than or equal to the threshold α0, and determines the offline token response waiting time TSWY[q] to the value TKY2, which is greater than the value TKY1, if the memory capacity α indicated by the terminal information DTM[q] is less than the threshold α0. In this embodiment, it is assumed that the value TKY1 is smaller than the value TKX1, and the value TKY2 is smaller than the value TKX2. Specifically, in this embodiment, as an example, it is assumed that the value TKY1 is "3 seconds" and the value TKY2 is "6 seconds".

[0085] In this embodiment, as an example, we assume that terminal information DTM[q] indicates the memory capacity α of terminal device 1[q], but the present invention is not limited to this embodiment. Terminal information DTM[q] may indicate anything other than the memory capacity α, as long as it is information related to the performance of terminal device 1[q]. For example, terminal information DTM[q] may indicate the model name of terminal device 1[q], or the model number of terminal device 1[q], or it may indicate the type of processor that terminal device 1[q] has.

[0086] Figure 6 is an explanatory diagram illustrating another example of the relationship between terminal information DTM[q] and token response information DSW[q].

[0087] In the example shown in Figure 6, we assume that the terminal information DTM[q] represents the memory capacity α of the storage device 12 of the terminal device 1[q], as well as the processing speed β of the control device 11 of the terminal device 1[q]. Here, the processing speed β is the processing speed of the processor, such as a CPU, provided in the control device 11 of the terminal device 1[q].

[0088] In the example shown in Figure 6, the control device 31 determines the online token response waiting time TSWX[q] to the value TKX11 when the memory capacity α indicated by terminal information DTM[q] is greater than or equal to threshold α0 and the processing speed β indicated by terminal information DTM[q] is greater than or equal to threshold β0, and when the memory capacity α indicated by terminal information DTM[q] is greater than or equal to threshold α0 and the processing speed β indicated by terminal information DTM[q] is less than threshold β0, it determines the online token response waiting time TSWX[q] to the value T If KX12 is determined, and the memory capacity α indicated by terminal information DTM[q] is less than threshold α0, and the processing speed β indicated by terminal information DTM[q] is greater than or equal to threshold β0, then the online token response waiting time TSWX[q] is determined to be value TKX21. If the memory capacity α indicated by terminal information DTM[q] is less than threshold α0, and the processing speed β indicated by terminal information DTM[q] is less than threshold β0, then the online token response waiting time TSWX[q] is determined to be value TKX22. Here, value TKX12 is greater than value TKX11, value TKX21 is greater than value TKX11, and value TKX22 is greater than value TKX21. Specifically, in the example shown in Figure 6, we assume that the value TKX11 is "5 seconds", the value TKX12 is "8 seconds", the value TKX21 is "10 seconds", and the value TKX22 is "15 seconds".

[0089] Furthermore, in the example shown in Figure 6, the control device 31 determines the offline token response waiting time TSWY[q] to the value TKY11 when the memory capacity α indicated by terminal information DTM[q] is greater than or equal to threshold α0 and the processing speed β indicated by terminal information DTM[q] is greater than or equal to threshold β0, and when the memory capacity α indicated by terminal information DTM[q] is greater than or equal to threshold α0 and the processing speed β indicated by terminal information DTM[q] is less than threshold β0, the offline token response waiting time TSWY[q] is The value TKY12 is determined, and if the memory capacity α indicated by terminal information DTM[q] is less than threshold α0, and the processing speed β indicated by terminal information DTM[q] is greater than or equal to threshold β0, the offline token response waiting time TSWY[q] is determined to be value TKY21, and if the memory capacity α indicated by terminal information DTM[q] is less than threshold α0, and the processing speed β indicated by terminal information DTM[q] is less than threshold β0, the offline token response waiting time TSWY[q] is determined to be value TKY22. Here, value TKY12 is greater than value TKY11, value TKY21 is greater than value TKY11, and value TKY22 is greater than value TKY21. Furthermore, in the example shown in Figure 6, we assume that the value TKY11 is smaller than the value TKX11, the value TKY12 is smaller than the value TKX12, the value TKY21 is smaller than the value TKX21, and the value TKY22 is smaller than the value TKX22. Specifically, in the example shown in Figure 6, we assume that the value TKY11 is "3 seconds", the value TKY12 is "5 seconds", the value TKY21 is "6 seconds", and the value TKY22 is "9 seconds".

[0090] Return to the explanation in Figure 4. As shown in Figure 4, in the initial startup process, the information supply unit 311 of the payment device 3 supplies a business identification token KZ to the terminal device 1[q] in step S02 as a response to the terminal information DTM[q] supplied from the terminal device 1[q] (S04). Specifically, in step S04, the information supply unit 311 first generates a business identification token KZ based on the business identification information DKZ stored in the storage device 32. Then, the information supply unit 311 supplies the generated business identification token KZ to the terminal device 1[q].

[0091] Furthermore, in the initial startup process, the information supply unit 311 of the payment device 3 supplies setting information DS to the terminal device 1[q] in step S02 as a response to the terminal information DTM[q] supplied from the terminal device 1[q] (S05). Specifically, in step S05, the information supply unit 311 first acquires the setting information DS stored in the storage device 32. Then, the information supply unit 311 supplies the acquired setting information DS to the terminal device 1[q].

[0092] In this embodiment, as an example, in steps S03 to S05, the payment device 3 transmits token response information DSW[q] to the terminal device 1[q], then transmits the business operator identification token KZ, and then transmits the configuration information DS. However, the present invention is not limited to this embodiment. The order in which the payment device 3 transmits the token response information DSW[q], the business operator identification token KZ, and the configuration information DS to the terminal device 1[q] is arbitrary. For example, the payment device 3 may transmit the token response information DSW[q], the business operator identification token KZ, and the configuration information DS to the terminal device 1[q] simultaneously (for example, in the same message).

[0093] Next, in the initial startup process, the information acquisition unit 112 of the terminal device 1[q] acquires the token response information DSW[q] supplied from the payment device 3 in step S03, the business operator identification token KZ supplied from the payment device 3 in step S04, and the setting information DS supplied from the payment device 3 in step S05, and stores the acquired token response information DSW[q], business operator identification token KZ, and setting information DS in the storage device 12 (S06).

[0094] Next, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 during the initial startup process (S07).

[0095] Then, in the initial startup process, the control device 31 of the payment device 3 supplies the offline token KY[q] and the encryption key KS[q] to the terminal device 1[q] in response to the offline token request RY supplied from the terminal device 1[q] in step S07 (S08). Specifically, in step S08, the control device 31 first generates the offline token KY[q] and the encryption key KS[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated offline token KY[q] and encryption key KS[q] to the terminal device 1[q].

[0096] Next, in the initial startup process, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] supplied from the payment device 3 in step S08, and stores the acquired offline token KY[q] and encryption key KS[q] in the storage device 12 (S09). Note that the offline token KY[q] and encryption key KS[q] that the information acquisition unit 112 stores in the storage device 12 in step S09 are the information acquired for the first time and are the latest information. In other words, in step S09, the information acquisition unit 112 stores the offline token KY[q][1] (=offline token KY[q][M]) and encryption key KS[q][1] (=encryption key KS[q][M]) in the storage device 12.

[0097] <A.2.2. Operation of electronic payment system Sys in normal scenarios> Hereinafter, an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys executes online electronic payment will be described with reference to FIGS. 7 to 12. Here, the "normal operation of the electronic payment system Sys" refers to the operation of the electronic payment system Sys when the electronic payment system Sys executes electronic payment, where the terminal device 1[q] can obtain the offline token KY[q] from the storage device 12 and the terminal device 1[q] can obtain the online token KX[q] from the payment device 3.

[0098] FIG. 7 is a flowchart showing an example of an overview of the normal operation of the electronic payment system Sys when the electronic payment system Sys executes online electronic payment. The flowchart shown in FIG. 7 starts when the user U[q] of the terminal device 1[q] performs an operation to activate the payment application. In addition, in the flowchart shown in FIG. 7, it is assumed that the activation of the payment application on the terminal device 1[q] is the second or subsequent activation.

[0099] As shown in FIG. 7, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] executes the electronic payment program PG-T based on the operation of the user U[q], thereby activating the payment application (S1).

[0100] Next, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] executes offline code image display processing (S2). Here, the offline code image display processing is processing in which, after the payment application is activated on the terminal device 1[q] and before the online code image GX[q] is displayed, the offline payment code CY[q] is generated based on the offline token KY[q][M] stored in the storage device 12 of the terminal device 1[q], and the offline code image GY[q] representing the generated offline payment code CY[q] is caused to be displayed on the display device 13.

[0101] Next, the electronic payment system Sys executes payment-related processing (S3). Here, payment-related processing includes the process of supplying payment information DP[q] from the store device 5 to the payment device 3, the process of determining the validity of the token KK[q] contained in the payment information DP[q] supplied from the store device 5 in the payment device 3, and the payment processing executed in the payment device 3 based on the payment information DP[q] whose validity has been confirmed.

[0102] Next, the electronic payment system Sys executes the online code image display process (S4). Here, the online code image display process includes the process by which terminal device 1[q] obtains an online token KX[q] from payment device 3, the process by which terminal device 1[q] generates an online payment code CX[q] based on the obtained online token KX[q], and the process of displaying the online code image GX[q] representing the generated online payment code CX[q] on the display device 13.

[0103] Next, the electronic payment system Sys executes the offline token acquisition process (S5). Here, the offline token acquisition process is the process by which terminal device 1[q] acquires the offline token KY[q] from payment device 3.

[0104] Figures 8 and 9 are sequence charts showing an example of the normal operation of the electronic payment system Sys when it performs online electronic payments. Below, we will explain the details of the processes in steps S1 to S5 described in the flowchart of Figure 7, referring to Figures 8 and 9.

[0105] As shown in Figure 8, in the electronic payment system Sys, the control device 11 of terminal device 1[q] launches the payment application (S1) by executing the electronic payment program PG-T based on the operation of user U[q].

[0106] Next, the electronic payment system Sys performs the offline code image display process described above (S2).

[0107] More specifically, in the offline code image display process of the terminal device 1[q], the information acquisition unit 112 of the terminal device 1[q] first determines whether the offline token KY[q][M] stored in the storage device 12 is a valid offline token KY (S21). Specifically, in step S21, the information acquisition unit 112 determines whether the storage device 12 stores one or more offline tokens KY[q][1] to KY[q][M], and whether the latest offline token KY[q][M] among the one or more offline tokens KY[q][m] is an offline token KY that is within its validity period. For example, in step S21, the information acquisition unit 112 may determine whether the end of the offline token validity period TY[q][M] corresponding to the offline token KY[q][M] is a time later than the current time. Note that the sequence charts shown in Figures 8 and 9 assume that the offline token KY[q][M] stored in the storage device 12 is valid.

[0108] Next, in the offline code image display process of step S2, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q][M] and the encryption key KS[q][M] from the storage device 12 (S22).

[0109] Next, in the offline code image display process of step S2, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on the offline token KY[q][M] and the encryption key KS[q][M] obtained in step S22 (S23).

[0110] Subsequently, in the offline code image display processing of step S2, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display an offline code image display screen GGY including the offline code image GY[q] based on the offline payment code CY[q] generated in step S23 (S24).

[0111] Then, the offline code image GY[q] displayed on the display device 13 of terminal device 1[q] is held up to the barcode reader installed in store device 5 by the user U[q] of terminal device 1[q]. In this case, store device 5 executes the process of reading the offline code image GY[q] displayed on the display device 13 of terminal device 1[q] (S25).

[0112] Figure 10 is a schematic diagram showing an example of an offline code image display screen GGY containing the offline code image GY[q].

[0113] As shown in Figure 10, the offline code image display screen GGY comprises an offline code image GY[q], a payment method display area A1, and a point usage selection button B1.

[0114] As described above, the offline code image GY[q] is a barcode representing the offline payment code CY[q]. In this embodiment, as an example, it is assumed that the two-dimensional code representing the offline payment code CY[q] is also displayed as the offline code image GY[q] on the offline code image display screen GGY.

[0115] The point usage selection button B1 is a button used in offline electronic payment to select whether or not to use points awarded to user U[q]. Although not shown in the sequence charts in Figures 8 and 9, in this embodiment, as an example, it is assumed that when user U[q] changes whether or not to use points using the point usage selection button B1 on the offline code image display screen GGY, the change is notified from terminal device 1[q] to payment device 3.

[0116] The payment method display area A1 displays the payment method used by user U[q] when U[q] uses electronic payment in the electronic payment system Sys. Specifically, the display control unit 114 displays the payment method of user U[q] in the payment method display area A1 based on the user payment information DSH[q]. Although not shown in the sequence charts in Figures 8 and 9, in this embodiment, as an example, it is assumed that the user payment information DSH[q] is stored in the storage device 12 of the terminal device 1[q]. However, the present invention is not limited to this embodiment. For example, the payment device 3 may supply the user payment information DSH[q] to the terminal device 1[q] in response to a request from the terminal device 1[q]. The payment method for user U[q] displayed in payment method display area A1 can be changed in the payment method selection screen GGS, which is described below.

[0117] Figure 11 is a schematic diagram showing an example of the payment method selection screen in GGS.

[0118] As shown in Figure 11, the payment method selection screen GGS includes three radio buttons RB, including radio button RB1 for selecting telephone bill payment as a payment method in electronic payment, radio button RB2 for selecting prepaid balance payment as a payment method in electronic payment, and radio button RB3 for selecting credit card payment as a payment method in electronic payment, a confirmation button BS1 for confirming the payment method in electronic payment, and a credit registration button BS2 for displaying a screen (not shown) for registering credit card information DCR[q] on the display device 13. User U[q] can select the payment method corresponding to the selected radio button RB as the payment method for user U[q] when electronic payment is performed in the electronic payment system Sys by selecting one of the three radio buttons RB on the payment method selection screen GGS and pressing the confirmation button BS1.

[0119] Return to the explanation in Figure 8. As shown in Figure 8, the electronic payment system Sys executes the payment-related processing described above (S3).

[0120] More specifically, in the payment-related processing of step S3, the store device 5 generates store payment information DF[q] (store identification information, payment amount, payment date and time) based on the services provided by the store where the store device 5 is installed to user U[q], and generates payment information DP[q] which includes the generated store payment information DF[q] and the offline payment code CY[q] indicated by the offline code image GY[q] read from terminal device 1[q] in step S25 (S31). Furthermore, if the code image GG[q] read by the store device 5 before the start of step S3 is an online code image GX[q], the store device 5 generates payment information DP[q] in step S31, which includes the online payment code CX[q] indicated by the online code image GX[q] and the store payment information DF[q].

[0121] Next, in the payment-related processing of step S3, the store device 5 transmits the payment information DP[q] generated in step S31 to the payment device 3 (S32).

[0122] Next, in the payment-related processing of step S3, the payment processing unit 313 of the payment device 3 determines the validity of the offline token KY[q] contained in the offline payment code CY[q] based on the offline payment code CY[q] contained in the payment information DP[q] supplied from the store device 5 in step S32 (S33). Specifically, in step S33, the payment processing unit 313 determines whether the offline token KY[q] contained in the payment information DP[q] supplied from the store device 5 in step S32 is stored in the storage device 32 and whether the offline token KY[q] is within its validity period. For example, in step S33, the payment processing unit 313 may determine whether the end of the offline token validity period TY[q] corresponding to the offline token KY[q] is a time later than the current time. Note that the sequence charts shown in Figures 8 and 9 assume that the offline token KY[q] is valid. Furthermore, if the token KK[q] included in the payment information DP[q] supplied from the store device 5 in step S32 is the online token KX[q], the store device 5 will determine the validity of the online token KX[q] in step S33.

[0123] Subsequently, the settlement processing unit 313 of the settlement device 3 executes the settlement process in the settlement-related processing of step S3 (S34). Then, the information supply unit 311 of the payment device 3 transmits a register charge response to the store device 5 indicating the result of the payment processing in step S34 (S35).

[0124] Subsequently, as shown in Figure 9, the electronic payment system Sys executes the online code image display process described above (S4).

[0125] More specifically, the communication status determination unit 115 of terminal device 1[q] determines whether the communication status of terminal device 1[q] is online or not during the online code image display process in step S4 (S41). Note that the sequence charts shown in Figures 8 and 9 assume that the communication status of terminal device 1[q] is online.

[0126] Next, the information transmission unit 111 of the terminal device 1[q] transmits an online blockage information request BX to the payment device 3 during the online code image display process in step S4 (S42). Here, the online blockage information request BX is a message requesting online blockage information DHX.

[0127] Next, in the online code image display processing of the payment device 3, the control device 31 supplies online blocking information DHX to the terminal device 1[q] in response to the online blocking information request BX supplied from the terminal device 1[q] in step S42 (S43). Specifically, in step S43, the control device 31 first determines whether or not the online payment processing in the payment device 3 can be executed, and generates online blocking information DHX indicating the result of that determination. Then, the information supply unit 311 of the control device 31 supplies the generated online blocking information DHX to the terminal device 1[q].

[0128] Next, in the online code image display process of step S4, the information transmission unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S44). Here, the online token request RX is a message requesting the online token KX[q].

[0129] Then, in the online code image display processing of step S4, the control device 31 of the payment device 3 supplies the online token KX[q] to the terminal device 1[q] in response to the online token request RX supplied from the terminal device 1[q] in step S44 (S45). Specifically, in step S45, the control device 31 first generates the online token KX[q] and the online token validity period information DTX[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated online token KX[q] to the terminal device 1[q].

[0130] In this embodiment, as an example, the case in which terminal device 1[q] transmits an online blockage information request BX to payment device 3 in step S42, and then transmits an online token request RX to payment device 3 in step S44, has been described as an example, but the present invention is not limited to this embodiment. Terminal device 1[q] may transmit an online blockage information request BX to payment device 3 after transmitting an online token request RX to payment device 3. Alternatively, terminal device 1[q] may transmit an online token request RX and an online blockage information request BX to payment device 3 simultaneously (for example, in the same message).

[0131] Next, in the online code image display process of step S4, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of online payment processing in the payment device 3 is blocked or not based on the online blockage information DHX acquired by the information acquisition unit 112 in step S43 (S46). Note that the sequence charts shown in Figures 8 and 9 assume that the execution function of online payment processing in the payment device 3 is not blocked, that is, that the payment device 3 is capable of executing online payment processing. Hereafter, the state in which the execution function of online payment processing in the payment device 3 is blocked may be referred to as "online blocked state". Also, hereafter, the state in which the execution function of offline payment processing in the payment device 3 is blocked may be referred to as "offline blocked state".

[0132] Next, in the online code image display processing of step S4, the code generation unit 113 of the terminal device 1[q] generates an online payment code CX[q] based on the online token KX[q] acquired by the information acquisition unit 112 in step S45 (S47). Specifically, in step S47, the code generation unit 113 generates an online payment code CX[q] that includes the online token KX[q].

[0133] Subsequently, in the online code image display processing of step S4, the display control unit 114 of the terminal device 1[q] generates display information for displaying the online code image GX[q] representing the online payment code CX[q] based on the online payment code CX[q] generated by the code generation unit 113 in step S47, and causes the display device 13 to display the online code image display screen GGX including the online code image GX[q] based on the generated display information (S48).

[0134] In this embodiment, if the display control unit 114 displays the offline code image GY[q] on the display device 13 of the terminal device 1[q] in step S24, it maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the online code image GX[q] is displayed on the display device 13 of the terminal device 1[q] in step S48.

[0135] Then, the store device 5 uses a barcode reader or the like installed in the store device 5 to read the online code image GX[q] displayed on the display device 13 of the terminal device 1[q] (S49).

[0136] Figure 12 is a schematic diagram showing an example of the GGX online code image display screen.

[0137] As shown in Figure 12, the online code image display screen GGX comprises an online code image GX[q], a payment method display area A2, and a point usage selection button B2.

[0138] As described above, the online code image GX[q] is a barcode representing the online payment code CX[q]. However, the present invention is not limited to this embodiment. The online code image GX[q] may be, for example, a two-dimensional code representing the online payment code CX[q]. In the payment method display area A2, similar to the payment method display area A1, the payment method used by user U[q] when using electronic payment in the electronic payment system Sys is displayed. The Point Usage Selection Button B2, like the Point Usage Selection Button B1, is a button that displays the current selection status of user U[q] regarding whether or not to use the points awarded to user U[q] in online electronic payments.

[0139] Return to the explanation in Figure 9. As shown in Figure 9, the electronic payment system Sys executes the offline token acquisition process described above (S5).

[0140] Next, in the offline token acquisition process of step S5, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S51). Here, the offline token request RY is a message requesting the offline token KY[q].

[0141] Then, in the offline token acquisition process of step S5, the control device 31 of the payment device 3 supplies the offline token KY[q] and the encryption key KS[q] to the terminal device 1[q] as a response to the offline token request RY supplied from the terminal device 1[q] in step S51 (S52). Specifically, in step S52, the control device 31 first generates the offline token KY[q], the encryption key KS[q], and the offline token validity period information DTY[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated offline token KY[q] and encryption key KS[q] to the terminal device 1[q].

[0142] Next, in the offline token acquisition process of step S5, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] supplied from the payment device 3 in step S52, and stores the acquired offline token KY[q] and encryption key KS[q] in the storage device 12 (S53). Note that since the acquisition of the offline token KY[q] in step S53 is the Mth acquisition (latest acquisition), the information acquisition unit 112 adds the acquired offline token information KYY[q] as offline token KY[q][M], and adds the encryption key KS[q] acquired in step S53 as encryption key KS[q][M] to the acquired offline token information KYY[q].

[0143] As described above, when online electronic payment is performed, the terminal device 1[q] according to the present embodiment causes the display device 13 to display the offline code image GY[q] during the period from after the payment application is activated to before the online code image GX[q] is displayed on the display device 13. Therefore, according to the present embodiment, compared to a mode in which the offline code image GY[q] is not displayed after the payment application is activated, the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service can be shortened.

[0144] In addition, when online electronic payment is performed, the terminal device 1[q] according to the present embodiment causes the display device 13 to display the offline code image GY[q] regardless of the communication state of the terminal device 1[q] before executing the processing of step S41 in which the communication state of the terminal device 1[q] is checked. Therefore, according to the present embodiment, compared to a mode in which the offline code image GY[q] is displayed after checking the communication state of the terminal device 1[q] after the payment application is activated, the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service can be shortened.

[0145] <A.2.3. Operation of Electronic Payment System Sys Outside Normal Operation> Hereinafter, an example of the operation of the electronic payment system Sys outside the normal operation when the electronic payment system Sys executes electronic payment will be described with reference to FIGS. 13 to 16.

[0146] FIG. 13 is a sequence chart showing an example of the operation of the electronic payment system Sys outside the normal operation when the electronic payment system Sys executes electronic payment. Note that in FIG. 13, it is assumed that the electronic payment system Sys cannot perform normal operation because a valid offline token KY is not stored in the storage device 12.

[0147] As shown in FIG. 13, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] activates the payment application (S1).

[0148] Next, the electronic payment system Sys performs the offline code image display process (S2).

[0149] Specifically, in the offline code image display process of step S2, the information acquisition unit 112 of the terminal device 1[q] determines whether the offline token KY[q][M] stored in the storage device 12 is a valid offline token KY (S21). In Figure 13, as described above, we assume that no valid offline token KY is stored in the storage device 12. Then, in the offline code image display processing of step S2, if the result of the determination in step S21 is negative, that is, if no valid offline token KY is stored in the storage device 12, the information acquisition unit 112 of the terminal device 1[q] displays a waiting screen (S26) and then terminates the offline code image display processing of step S2. Here, the waiting screen (not shown) is a screen that informs user U[q] that terminal device 1[q] is scheduled to acquire online token KX[q], but has not yet acquired online token KX[q], and that it is waiting for terminal device 1[q] to acquire online token KX[q]. In this embodiment, an example is described in which terminal device 1[q] displays a waiting screen and then terminates the offline code image display processing when the result of the determination in step S21 is negative, but the present invention is not limited to this embodiment. If the result of the determination in step S21 is negative, terminal device 1[q] may terminate the offline code image display process without displaying a waiting screen.

[0150] Next, the electronic payment system Sys executes the online code image display process (S4) described above. Specifically, as the online code image display process in step S4, the electronic payment system Sys executes the processes described in steps S41 to S49. As a result, the display control unit 114 of the terminal device 1[q] displays the online code image GX[q] on the display device 13 (S48).

[0151] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing of step S3, the electronic payment system Sys executes the processing described in steps S31 to S35. Subsequently, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown in the diagram). Specifically, as the offline token acquisition process in step S5, the electronic payment system Sys executes the processes described in steps S51 to S53 above.

[0152] Thus, according to this embodiment, even if the electronic payment system Sys is unable to perform normal operations due to the storage device 12 not having a valid offline token KY stored, the online code image GX[q] can be displayed on the display device 13 of the terminal device 1[q] based on the online token KX[q] acquired from the payment device 3. Therefore, according to this embodiment, even if the storage device 12 does not have a valid offline token KY stored, the user U[q] of the terminal device 1[q] can receive electronic payment services.

[0153] Figure 14 is a sequence chart showing an example of an operation of the electronic payment system Sys other than the normal operation when the electronic payment system Sys performs an electronic payment. In Figure 14, we assume a case where the electronic payment system Sys cannot perform the normal operation due to the communication status of terminal device 1[q] being offline.

[0154] As shown in Figure 14, in the electronic payment system Sys, the control device 11 of terminal device 1[q] starts the payment application (S1).

[0155] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, as the offline code image display process in step S2, the electronic payment system Sys executes the processes described in steps S21 to S25. As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24).

[0156] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing of step S3, the electronic payment system Sys executes the processing described in steps S31 to S35 (some parts are omitted from the diagram).

[0157] Subsequently, the electronic payment system Sys performs the online code image display process (S4). Specifically, the communication status determination unit 115 of terminal device 1[q] determines whether the communication status of terminal device 1[q] is online or not during the online code image display process in step S4 (S41). In Figure 14, as described above, we assume that the communication status of terminal device 1[q] is offline. Then, if the result of the determination in step S41 is negative, that is, if the communication status of terminal device 1[q] is offline, the control device 11 of terminal device 1[q] terminates the online code image display process in step S4.

[0158] Next, the electronic payment system Sys performs the offline code image display process (S2). Specifically, in the offline code image display process of step S2, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 by executing the process of step S24 described above. More specifically, after the payment application is launched, the display control unit 114 first displays the offline code image GY[q] on the display device 13 by the process of step S24, and then maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the process of step S4 is executed and the process of step S2 is executed again.

[0159] Thus, according to this embodiment, even if the electronic payment system Sys is unable to perform normal operations due to the communication state of terminal device 1[q] being offline, the offline code image GY[q] can be displayed on the display device 13 of terminal device 1[q] based on the offline token KY[q][M] obtained from the storage device 12. Therefore, according to this embodiment, even if the communication state of terminal device 1[q] is offline, user U[q] of terminal device 1[q] can receive electronic payment services.

[0160] Figure 15 is a sequence chart showing an example of an operation of the electronic payment system Sys other than the normal operation when the electronic payment system Sys performs an electronic payment. In Figure 15, we assume a case where the electronic payment system Sys cannot perform normal operation due to the payment device 3 being in an online blocked state.

[0161] As shown in Figure 15, in the electronic payment system Sys, the control device 11 of terminal device 1[q] starts the payment application (S1).

[0162] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, as the offline code image display process in step S2, the electronic payment system Sys executes the processes described in steps S21 to S25 (some parts are not shown). As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24).

[0163] Subsequently, the electronic payment system Sys performs the online code image display process (S4). Specifically, as the online code image display process in step S4, the electronic payment system Sys performs the processes described in steps S41 to S46 above. Of these, the code generation unit 113 of terminal device 1[q] determines in step S46 whether the execution function of the online payment processing in payment device 3 is blocked, based on the online blockage information DHX acquired by the information acquisition unit 112 in step S43. In Figure 15, as described above, it is assumed that payment device 3 is in an online blockage state. Then, if the result of the determination in step S46 is affirmative, that is, if payment device 3 is in an online blockage state, the control device 11 of terminal device 1[q] terminates the online code image display processing in step S4.

[0164] Next, the electronic payment system Sys performs the offline code image display process (S2). Specifically, in the offline code image display process of step S2, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 by executing the process of step S24 described above. More specifically, after the payment application is launched, the display control unit 114 first displays the offline code image GY[q] on the display device 13 by the process of step S24, and then maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the process of step S4 is executed and the process of step S2 is executed again.

[0165] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing of step S3, the electronic payment system Sys executes the processing described in steps S31 to S35 (some parts are omitted from the diagram). Subsequently, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown in the diagram). Specifically, as the offline token acquisition process in step S5, the electronic payment system Sys executes the processes described in steps S51 to S53 above.

[0166] Thus, according to this embodiment, even if the electronic payment system Sys is unable to perform normal operations due to the payment device 3 being in an online blocked state, the offline code image GY[q] can be displayed on the display device 13 of the terminal device 1[q] based on the offline token KY[q][M] acquired from the storage device 12. Therefore, according to this embodiment, even if the payment device 3 is in an online blocked state, the user U[q] of the terminal device 1[q] can receive electronic payment services.

[0167] Figure 16 is a sequence chart showing an example of an operation of the electronic payment system Sys other than the normal operation when the electronic payment system Sys performs an electronic payment. In Figure 16, we assume a case where the electronic payment system Sys cannot perform the normal operation because terminal device 1[q] is unable to obtain the online token KX[q] from payment device 3.

[0168] As shown in Figure 16, in the electronic payment system Sys, the control device 11 of terminal device 1[q] starts the payment application (S1).

[0169] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, as the offline code image display process in step S2, the electronic payment system Sys executes the processes described in steps S21 to S25 (some parts are not shown). As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24).

[0170] Subsequently, the electronic payment system Sys performs the online code image display process (S4). Specifically, as the online code image display process in step S4, the electronic payment system Sys first performs the processes described in steps S41, S42, and S44 above. Then, in the online code image display processing of the terminal device 1[q], the information acquisition unit 112 determines whether or not the online token KX[q] was supplied from the payment device 3 before the online token response waiting period TWX[q] ends (S91). In Figure 16, as described above, it is assumed that in step S44, the terminal device 1[q] sends an online token request RX to the payment device 3, but there is no response from the payment device 3 to the online token request RX, and the terminal device 1[q] cannot obtain the online token KX[q] from the payment device 3. Then, if the result of the determination in step S91 is negative, that is, if the online token KX[q] is not supplied during the online token response waiting period TWX[q], the control device 11 of the terminal device 1[q] terminates the online code image display processing of step S4.

[0171] Next, the electronic payment system Sys performs the offline code image display process (S2). Specifically, the display control unit 114 of the terminal device 1[q] executes the process of step S24 described above in the offline code image display process of step S2, thereby causing the display device 13 to display the offline code image GY[q]. More specifically, after activating the payment application and first causing the display device 13 to display the offline code image GY[q] through the process of step S24, the display control unit 114 maintains the offline code image GY[q] displayed on the display device 13 until the process of step S4 is executed and the process of step S2 is executed again.

[0172] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing in step S3, the electronic payment system Sys executes the processing of steps S31 to S35 described above (part of which is not shown in the figure). Thereafter, the electronic payment system Sys executes the offline token acquisition processing (S5) described above (not shown in the figure). Specifically, as the offline token acquisition processing in step S5, the electronic payment system Sys executes the processing of steps S51 to S53 described above.

[0173] As described above, according to the present embodiment, even when the electronic payment system Sys cannot perform normal operation because the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3, the offline code image GY[q] can be caused to be displayed on the display device 13 of the terminal device 1[q] based on the offline token KY[q][M] acquired from the storage device 12. Therefore, according to the present embodiment, even when the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3, the user U[q] of the terminal device 1[q] can still receive the electronic payment service provision.

[0174] <A.2.4. Operation of Electronic Payment System According to Reference Example> Hereinafter, in order to clarify the effects of the present embodiment, the electronic payment system according to the reference example will be described.

[0175] Figure 17 is a sequence chart showing an example of the operation of the electronic payment system according to the reference example when it performs online electronic payment. The electronic payment system according to the reference example also comprises a terminal device 1[q], a payment device 3, and a store device 5, similar to the electronic payment system Sys according to this embodiment.

[0176] As shown in Figure 17, when the electronic payment system according to the example performs online electronic payment, terminal device 1[q] of the electronic payment system according to the example launches the payment application (S1). Next, the electronic payment system according to the example performs the online code image display process described above (S4). Specifically, the electronic payment system according to the example performs the processes described in steps S41 to S49 as the online code image display process in step S4. As a result, the display control unit 114 of the terminal device 1[q] provided in the electronic payment system according to the example causes the display device 13 to display the online code image GX[q] (S48). Next, the electronic payment system in the example executes the payment-related processing described above (S3). Subsequently, the electronic payment system in the example executes the offline token acquisition process described above (S5).

[0177] Thus, according to the electronic payment system in the example, the code image GG[q] is not displayed on the display device 13 of the terminal device 1[q] during the period from the start of the payment application until the online code image GX[q] is displayed on the display device 13 of the terminal device 1[q]. Furthermore, according to the electronic payment system in the example, the processing in steps S41 to S47 must be executed during the period from the start of the payment application until the online code image GX[q] is displayed on the display device 13 of the terminal device 1[q]. For this reason, the period from the start of the payment application until the online code image GX[q] is displayed becomes longer in the electronic payment system in the example. In other words, the waiting time for user U[q] of terminal device 1[q] to receive the electronic payment service becomes longer in the electronic payment system in the example.

[0178] In contrast, according to the electronic payment system Sys according to the present embodiment, when online electronic payment is performed, after the payment application is started, an offline code image GY[q] is displayed on the display device 13 during the period until the online code image GX[q] is displayed on the display device 13. Therefore, according to the present embodiment, compared with the electronic payment system according to the reference example, the waiting time until the user U[q] of the terminal device 1[q] receives the provision of the electronic payment service can be shortened.

[0179] <A.2.5.Summary of Operations of Electronic Payment System Sys> As described above, in the present embodiment, when online electronic payment is performed in the electronic payment system Sys, the terminal device 1[q] displays an offline code image GY[q] on the display device 13 during the period after the payment application is started and before the online code image GX[q] is displayed on the display device 13. Therefore, according to the present embodiment, compared with a mode in which the offline code image GY[q] is not displayed after the payment application is started, the waiting time after the user U[q] of the terminal device 1[q] starts the payment application until receiving the provision of the electronic payment service can be shortened.

[0180] Further, in the present embodiment, the electronic payment system Sys executes offline electronic payment when online electronic payment is difficult, such as when the communication state of the terminal device 1[q] is an offline state, when the terminal device 1[q] fails to acquire the online token KX[q] from the payment device 3, and when the payment device 3 is in an online blocked state. Therefore, for example, compared with a mode in which an electronic payment system can only perform online electronic payment, when the user U[q] of the terminal device 1[q] receives a service provision at a store where the store device 5 is installed, the possibility that the user pays the consideration for the service via electronic payment can be increased. Accordingly, according to the present embodiment, a reduction in convenience related to payment for the user U[q] who has received a service provision at the store where the store device 5 is installed can be suppressed.

[0181] Furthermore, in this embodiment, when the payment application is launched on terminal device 1[q] (see step S1) and electronic payment is executed, terminal device 1[q] acquires an online token KX[q] from payment device 3 (see step S45) and also acquires an offline token KY[q] (see step S52). That is, in this embodiment, terminal device 1[q] acquires the offline token KY[q] from payment device 3 at the time when terminal device 1[q] and payment device 3 communicate regarding electronic payment. Therefore, according to this embodiment, it is possible to reduce the number of processes other than electronic payment on terminal device 1[q] compared to a configuration in which terminal device 1[q] acquires the offline token KY[q] from payment device 3 at a time unrelated to the timing of electronic payment, such as a predetermined timing. As a result, according to this embodiment, it is possible to reduce the complexity of scheduling processes on terminal device 1[q] compared to a configuration in which terminal device 1[q] acquires the offline token KY[q] from payment device 3 at a time unrelated to the timing of electronic payment.

[0182] Furthermore, in this embodiment, the terminal device 1[q] stores the offline token KY[q] acquired from the payment device 3 in the storage device 12 at the time the electronic payment is made. Therefore, according to this embodiment, if online electronic payment is difficult due to communication failure or the like, the possibility that offline electronic payment will also become difficult to execute can be reduced.

[0183] Furthermore, in this embodiment, terminal device 1[q] displays the online code image GX[q] on the display device 13 when the online blockage information DHX indicates that the payment device 3 is not in an online blockage state. In other words, in this embodiment, terminal device 1[q] suppresses the display of the online code image GX[q] on the display device 13 when the online blockage information DHX indicates that the payment device 3 is in an online blockage state. In other words, according to this embodiment, the display of the online code image GX[q] on terminal device 1[q] can be suppressed when it is difficult to perform online electronic payment. For this reason, according to this embodiment, the effort required of user U[q] to display the online code image GX[q] can be reduced compared to, for example, an embodiment in which the online code image GX[q] is displayed without considering the online blockage information DHX.

[0184] Furthermore, in this embodiment, the length of the online token response waiting period TWX[q], which is the time for the terminal device 1[q] to wait for the supply of online tokens KX[q] from the payment device 3, i.e., the online token response waiting time TSWX[q], is determined based on the performance of the terminal device 1[q]. In other words, in this embodiment, the online token response waiting time TSWX[q] is adjusted according to the performance of the terminal device 1[q]. Therefore, according to this embodiment, compared to the embodiment in which the length of the online token response waiting period TWX[q] is fixed, the probability that the terminal device 1[q] can acquire online tokens KX[q] can be increased even when the terminal device 1[q] has low performance. In other words, according to this embodiment, compared to the embodiment in which the length of the online token response waiting period TWX[q] is fixed, the probability that an online electronic payment will be executed in which the online code image GX[q] is displayed in the terminal device 1[q] can be increased.

[0185] In this embodiment, the configuration information DS is provided from the payment device 3 to the terminal device 1[q] when the payment application is first launched on the terminal device 1[q], but the present invention is not limited to this embodiment. For example, the payment device 3 may provide the modified configuration information DS to the terminal device 1[q] when the configuration information DS is changed. Specifically, if the configuration information DS is changed and a payment application launch notification (not shown) indicating that the payment application has been launched on the terminal device 1[q] is provided to the payment device 3 from the terminal device 1[q], the payment device 3 may provide the modified configuration information DS to the terminal device 1[q] as a response to the payment application launch notification. Alternatively, the payment device 3 may provide the configuration information DS to the terminal device 1[q] regardless of whether the configuration information DS has been changed, for example, when a payment application launch notification is provided to the payment device 3 from the terminal device 1[q].

[0186] Furthermore, in this embodiment, an example has been given in which the business identification token KZ is supplied from the payment device 3 to the terminal device 1[q] when the payment application is first launched on the terminal device 1[q]. However, the present invention is not limited to this embodiment. For example, if the business identification information DKZ is changed, the payment device 3 may supply the terminal device 1[q] with a business identification token KZ indicating the changed business identification information DKZ. Specifically, if the business identification information DKZ is changed and the terminal device 1[q] supplies the payment device 3 with a business identification token KZ based on the changed business identification information DKZ as a response to the payment application launch notification. In this case, the frequency with which the terminal device 1[q] acquires the business identification token KZ will be lower than the frequency with which it acquires the online token KX[q]. Also, in this case, the frequency with which the terminal device 1[q] acquires the business identification token KZ will be lower than the frequency with which it acquires the offline token KY[q]. Furthermore, the payment device 3 may, for example, supply the business identification token KZ to terminal device 1[q] when a payment application launch notification is supplied to the payment device 3 from terminal device 1[q], regardless of whether or not the business identification information DKZ has been changed.

[0187] Further, in the present embodiment, an example is illustrated in which when the payment application is first activated on the terminal device 1[q], the token response information DSW[q] is supplied from the payment device 3 to the terminal device 1[q], but the present invention is not limited to such an embodiment. For example, when the token response information DSW[q] is changed, the payment device 3 may supply the changed token response information DSW[q] to the terminal device 1[q]. Specifically, when the token response information DSW[q] is changed and a payment application activation notification is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the changed token response information DSW[q] to the terminal device 1[q] as a response to the payment application activation notification. Further, for example, when a payment application activation notification is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the token response information DSW[q] to the terminal device 1[q] regardless of whether the token response information DSW[q] has been changed or not.

[0188] <A.3.Outline of Payment Code CC[q]> Hereinafter, an outline of the payment code CC[q] (the online payment code CX[q] and the offline payment code CY[q]) will be described with reference to FIG. 18.

[0189] FIG. 18 is a diagram showing an example of the data structure of the online payment code CX[q] and the offline payment code CY[q].

[0190] As shown in FIG. 18, the online payment code CX[q] includes an operator identification token KZ, an online token KX[q], an allocation value VJ, and a code type value VV. Further, the offline payment code CY[q] includes an operator identification token KZ, an offline token KY[q], a time encryption code TT[q][n], an allocation value VJ, and a code type value VV.

[0191] The operator identification token KZ is LZ-digit data composed of LZ code values VZ[1] to VZ[LZ]. Here, the value LZ is a natural number satisfying "LZ≧2". In addition, in the present embodiment, it is assumed that each code value VZ is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VZ may be 1-digit data composed of 1-digit alphanumeric characters (a 1-digit number or one alphabet).

[0192] The online token KX[q] is LX-digit data composed of LX code values VX[1] to VX[LX]. Here, the value LX is a natural number satisfying "LX≧4". In addition, in the present embodiment, it is assumed that each code value VX is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VX may be 1-digit data composed of 1-digit alphanumeric characters (a 1-digit number or one alphabet).

[0193] The offline token KY[q] is LY-digit data composed of LY code values VY[1] to VY[LY]. Here, the value LY is a natural number satisfying "LY≧2" and "LY<LX". In addition, in the present embodiment, it is assumed that each code value VY is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VY may be 1-digit data composed of 1-digit alphanumeric characters (a 1-digit number or one alphabet).

[0194] The time-cryptographic code TT[q] is LT-digit data composed of LT code values ​​VT[1] to VT[LT]. Here, the value LT is a natural number satisfying "LT≧2" and "LT+LY=LX". That is, in this embodiment, the sum of the number of digits LY of the offline token KY[q] and the number of digits LT of the time-cryptographic code TT[q][n] is equal to the number of digits LX of the online token KX[q]. Also in this embodiment, it is assumed that each code value VT is a single-digit data composed of a single digit (0 to 9). However, the code value VT may also be a single-digit data composed of a single alphanumeric character (a single digit or a single letter).

[0195] The allocated value VJ is a single-digit data consisting of a single digit (0-9). However, the allocated value VJ may be a 1-bit value, a number with two or more digits, or a 1-digit or more alphanumeric string.

[0196] The code type value VV is a single-digit data consisting of a single number (0-9). However, the code type value VV may be a 1-bit value, a number with two or more digits, or a 1 or more alphanumeric string. The code type value VV is set to a value that indicates the type of payment code CC[q]. Specifically, if payment code CC[q] is an online payment code CX[q], the code type value VV is set to a value that indicates payment code CC[q] is an online payment code CX[q], for example, "1". Hereafter, the value that indicates payment code CC[q] is an online payment code CX[q] will be referred to as the "online code value". Also, if payment code CC[q] is an offline payment code CY[q], the code type value VV is set to a value that indicates payment code CC[q] is an offline payment code CY[q], for example, "2". Hereafter, the value that indicates payment code CC[q] is an offline payment code CY[q] will be referred to as the "offline code value".

[0197] The following describes the process by which the code generation unit 113 generates the payment code CC[q] (hereinafter referred to as the "code generation process"). In the following, the process by which the code generation unit 113 generates the online payment code CX[q] will be referred to as the "online code generation process". Also, in the following, the process by which the code generation unit 113 generates the offline payment code CY[q] will be referred to as the "offline code generation process".

[0198] In the online code generation process, the code generation unit 113 sets an online code value (for example, "1") to the code type value VV. Then, the code generation unit 113 generates an online payment code CX[q] by arranging the business identification token KZ stored in the storage device 12, the online token KX[q] acquired by the information acquisition unit 112 from the payment device 3, the redemption value VJ, and the code type value VV in a predetermined order.

[0199] In the offline code generation process, the code generation unit 113 generates a terminal time value AG based on the terminal time TG managed by the terminal device 1[q]. Specifically, the code generation unit 113 generates the terminal time value AG by removing the part representing "seconds" from the terminal time TG and leaving the parts representing "minutes" and "hours". Next, in the offline code generation process, the code generation unit 113 generates a time-encrypted code TT[q] by encrypting the terminal time value AG using the encryption key KS[q][M] corresponding to the last acquired offline token KY[q][M] from among the M encryption keys KS[q][1] to KS[q][M] stored in the storage device 12. In other words, in this embodiment, it is assumed that the time-encrypted code TT[q] is the value obtained by encrypting the terminal time value AG using the encryption key KS[q][M]. Furthermore, in the offline code generation process, the code generation unit 113 sets an offline code value (for example, "2") to the code type value VV. Then, in the offline code generation process, the code generation unit 113 generates the offline payment code CY[q] by arranging the business identification token KZ stored in the storage device 12, the offline token KY[q] acquired by the information acquisition unit 112 from the payment device 3, the time encryption code TT[q] generated by the code generation unit 113, the allocation value VJ, and the code type value VV in a predetermined order. In this embodiment, it is assumed that the number of digits in the online payment code CX[q] and the number of digits in the offline payment code CY[q] are equal.

[0200] As described above, in this embodiment, the code generation unit 113 updates the terminal time value AG at a period of update unit time TC. Specifically, in this embodiment, the code generation unit 113 updates the terminal time value AG every minute. When the terminal time value AG is updated, the code generation unit 113 updates the time encryption code TT[q] with the value obtained by encrypting the updated terminal time value AG with the encryption key KS[q][M], and updates the offline payment code CY[q] with the updated time encryption code TT[q]. Specifically, the updated offline payment code CY[q] is generated by arranging the business operator identification token KZ, the offline token KY[q], the updated time encryption code TT[q], the allocation value VJ, and the code type value VV in a predetermined order.

[0201] In the following, a time-cryptographic code TT[q] that has undergone (n+1) updates may be referred to as time-cryptographic code TT[q][n]. That is, a time-cryptographic code TT[q] that has never been updated may be referred to as time-cryptographic code TT[q][1], and a time-cryptographic code TT[q] that has undergone one update may be referred to as time-cryptographic code TT[q][2]. Here, the variable n is a natural number satisfying "1 ≤ n".

[0202] As described above, in the present embodiment, the offline payment code CY[q] includes, in addition to the offline token KY[q] updated every offline token valid period TSY (for example, one week), a time encryption code TT[q] updated every update unit time TC (for example, one minute), which is a shorter period than the offline token valid period TSY. That is, in the present embodiment, the offline payment code CY[q] is updated every update unit time TC, which is the update cycle of the time encryption code TT[q]. Therefore, according to the present embodiment, the security risk caused by the leakage of the offline payment code CY[q] can be reduced compared with a configuration in which the offline payment code CY[q] does not include the time encryption code TT[q].

[0203] Further, in the present embodiment, the offline payment code CY[q] includes, in addition to the offline token KY[q], an operator identification token KZ obtained at a timing different from that of the offline token KY[q]. Therefore, according to the present embodiment, the security risk caused by the leakage of the offline payment code CY[q] can be reduced compared with a configuration in which the offline payment code CY[q] does not include the operator identification token KZ. Similarly, in the present embodiment, the online payment code CX[q] includes, in addition to the online token KX[q], an operator identification token KZ obtained at a timing different from that of the online token KX[q]. Therefore, according to the present embodiment, the security risk caused by the leakage of the online payment code CX[q] can be reduced compared with a configuration in which the online payment code CX[q] does not include the operator identification token KZ.

[0204] <A.4. Operation of Terminal Device 1[q]> Hereinafter, an outline of the operation of the terminal device 1[q] when electronic payment is performed will be described with reference to FIG. 19 to FIG. 27.

[0205] Figures 19 to 27 are flowcharts illustrating an example of the operation of terminal device 1[q] when electronic payment is performed in the electronic payment system Sys. Note that the flowcharts shown in Figures 19 to 27 are initiated when user U[q] of terminal device 1[q] launches the payment application.

[0206] As shown in Figure 19, when user U[q] of terminal device 1[q] performs an operation to launch the payment application, the control device 11 of terminal device 1[q] launches the payment application (S101). Note that the process in step S101 corresponds to the process in step S1 described above. Next, the control device 11 of terminal device 1[q] determines whether the activation of the payment application in terminal device 1[q] is the first activation of the payment application in terminal device 1[q] (S103). If the result of the determination in step S103 is negative, that is, if the startup of the payment application on terminal device 1[q] is the second or later startup, the control device 11 of terminal device 1[q] proceeds to step S201.

[0207] If the result of the determination in step S103 is positive, that is, if the startup of the payment application on terminal device 1[q] is the first startup, the control device 11 of terminal device 1[q] determines whether the communication status of terminal device 1[q] is online (S105) and waits until the communication status of terminal device 1[q] becomes online (S105:Y). The processing in step S105 corresponds to the processing in step S01 described above. In addition, if terminal device 1[q] remains offline for a predetermined time or longer (S105:N), the display control unit 114 of terminal device 1[q] may, for example, display an error screen on the display device 13.

[0208] If the result of the determination in step S105 is positive, that is, if the communication status of terminal device 1[q] is online, the control device 11 of terminal device 1[q] identifies the memory capacity α of terminal device 1[q] and generates terminal information DTM[q] indicating the identified memory capacity α (S107). Next, the information transmission unit 111 of the terminal device 1[q] transmits the terminal information DTM[q] generated in step S107 to the payment device 3 (S109). Note that the processing in step S109 corresponds to the processing in step S02 described above. Next, the control device 11 of terminal device 1[q] determines whether or not there is a response from payment device 3 (S111), and waits until there is a response from payment device 3 (S111:Y). In step S111, if the state of no response from payment device 3 (S111:N) continues for a predetermined time or longer, the display control unit 114 of terminal device 1[q] may, for example, display an error screen on the display device 13.

[0209] If the result of the determination in step S111 is positive, that is, if there is a response from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the token response information DSW[q] supplied from the payment device 3 (S113). Furthermore, if the result of the determination in step S111 is positive, the information acquisition unit 112 of the terminal device 1[q] acquires the business operator identification token KZ supplied from the payment device 3 (S115). Furthermore, if the result of the determination in step S111 is positive, the information acquisition unit 112 of the terminal device 1[q] acquires the setting information DS supplied from the payment device 3 (S117). Then, the information acquisition unit 112 of the terminal device 1[q] stores the token response information DSW[q] acquired in step S113, the business operator identification token KZ acquired in step S115, and the setting information DS acquired in step S117 in the storage device 12 (S119), and proceeds to step S121. The processing in step S119 corresponds to the processing in step S06 described above.

[0210] As shown in Figure 20, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S121). Note that the processing in step S121 corresponds to the processing in step S07 described above.

[0211] Then, the information acquisition unit 112 of terminal device 1[q] determines whether or not the offline token KY[q] and encryption key KS[q] have been supplied from the payment device 3 as a response to the offline token request RY (S123), and waits until the online token KX[q] and encryption key KS[q] are supplied (S123:Y). If, even after the offline token response waiting period TWY[q], which is started when the offline token request RY is sent, has ended, the information acquisition unit 112 of terminal device 1[q] still has not supplied the online token KX[q] and encryption key KS[q] from the payment device 3 (S123:N), it may, for example, display an error screen on the display device 13.

[0212] Next, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and the cryptographic key KS[q] supplied from the payment device 3 in step S123 (S125).

[0213] Then, the information acquisition unit 112 of the terminal device 1[q] stores the offline token KY[q] and encryption key KS[q] acquired in step S125 in the storage device 12 (S127). Specifically, in step S127, the information acquisition unit 112 adds the offline token KY[q] acquired in step S125 as the latest offline token KY[q][M] to the acquired offline token information KYY[q], and also adds the encryption key KS[q] acquired in step S125 as the latest encryption key KS[q][M] to the acquired offline token information KYY[q]. Note that the processing in step S127 corresponds to the processing in step S09 described above. After that, the control device 11 of the terminal device 1[q] completes the processing shown in the flowcharts in Figures 19 to 27.

[0214] As shown in Figure 21, if the result of the determination in step S103 is negative, that is, if the payment application in terminal device 1[q] is being launched for the second time or later, the information acquisition unit 112 of terminal device 1[q] determines whether or not a valid offline token KY[q][M] is stored in the storage device 12 of terminal device 1[q] (S201). Note that the processing in step S201 corresponds to the processing in step S21 described above. If the result of the determination in step S201 is negative, that is, if no valid offline token KY[q][M] is stored in the memory device 12 of terminal device 1[q], the control device 11 of terminal device 1[q] proceeds to step S301.

[0215] If the result of the determination in step S201 is positive, that is, if a valid offline token KY[q][M] is stored in the storage device 12 of terminal device 1[q], the information acquisition unit 112 of terminal device 1[q] acquires the offline token KY[q][M] and the encryption key KS[q][M] from the storage device 12 (S203). Note that the processing in step S203 corresponds to the processing in step S22 described above.

[0216] Next, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on the offline token KY[q][M] and the encryption key KS[q][M] obtained in step S203 (S205). Note that the processing in step S205 corresponds to the processing in step S23 described above.

[0217] Next, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display an offline code image display screen GGY including the offline code image GY[q] based on the offline payment code CY[q] generated in step S205 (S207). Note that the processing in step S207 corresponds to the processing in step S24 described above.

[0218] Then, the control device 11 of the terminal device 1[q] determines whether or not user U[q] has performed an operation to terminate the payment application (hereinafter referred to as the "termination operation") using the input device 14 (S209). If the result of the determination in step S209 is positive, that is, if the termination operation is performed, the control device 11 of terminal device 1[q] proceeds to step S501. If the result of the determination in step S209 is negative, that is, if the termination operation has not been performed, the control device 11 of terminal device 1[q] proceeds to step S301.

[0219] As shown in Figure 22, if the result of the determination in step S201 is negative, that is, if no valid offline token KY[q][M] is stored in the storage device 12 of terminal device 1[q], or if the result of the determination in step S209 is negative, that is, if no termination operation is performed after the offline code image GY[q] is displayed on the display device 13, the communication status determination unit 115 of terminal device 1[q] determines whether the communication status of terminal device 1[q] is online or not (S301). Note that the processing in step S301 corresponds to the processing in step S41 described above.

[0220] If the result of the determination in step S301 is negative, that is, if the communication state of terminal device 1[q] is offline, the control device 11 of terminal device 1[q] proceeds to step S407. If the result of the determination in step S301 is positive, that is, if the communication status of terminal device 1[q] is online, the information transmission unit 111 of terminal device 1[q] transmits an online blockage information request BX to the payment device 3 (S303). The processing in step S303 corresponds to the processing in step S42 described above.

[0221] Next, the information acquisition unit 112 of the terminal device 1[q] determines whether or not online block information DHX has been supplied from the payment device 3 as a response to the online block information request BX (S305). If the result of the determination in step S305 is negative, that is, if online blocking information DHX is not supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S309. If the result of the determination in step S305 is positive, that is, if online blockage information DHX is supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the online blockage information DHX (S307).

[0222] Next, the information transmission unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S309). Note that the processing in step S309 corresponds to the processing in step S44 described above.

[0223] Next, the information acquisition unit 112 of the terminal device 1[q] determines whether or not an online token KX[q] has been supplied from the payment device 3 as a response to the online token request RX (S311). If the result of the determination in step S311 is positive, that is, if the online token KX[q] is supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the online token KX[q] (S313) and proceeds to step S317. If the result of the determination in step S311 is negative, that is, if the online token KX[q] is not supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] determines whether the online token response waiting period TWX[q] has ended (S315). In the flowcharts of Figures 19 to 27, as an example, it is assumed that the online token response waiting period TWX[q] is a period that starts from the time the information transmission unit 111 transmits the online token request RX in step S309.

[0224] If the result of the determination in step S315 is negative, that is, if the online token response waiting period TWX[q] has not ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S309. If the result of the determination in step S315 is positive, that is, if the online token response waiting period TWX[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S317.

[0225] Next, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of the online payment processing in the payment device 3 is not in a blocked state (S317), based on the online blockage information DHX acquired by the information acquisition unit 112 in step S307. Specifically, the code generation unit 113 determines whether the following conditions are met: the information acquisition unit 112 acquired the online blockage information DHX in step S307, and the online blockage information DHX indicates that the payment device 3 is not in an online blockage state. The processing in step S317 corresponds to the processing in step S46 described above.

[0226] If the result of the determination in step S317 is negative, that is, if the information acquisition unit 112 did not acquire the online blockage information DHX in step S307, or if the online blockage information DHX indicates that the payment device 3 is in an online blockage state, the control device 11 of the terminal device 1[q] proceeds to step S401.

[0227] If the result of the determination in step S317 is affirmative, that is, if the conditions are met such that the information acquisition unit 112 acquired online blockage information DHX in step S307 and the online blockage information DHX indicates that the settlement device 3 is not in an online blockage state, then the control device 11 of the terminal device 1[q] determines whether or not the information acquisition unit 112 acquired online token KX[q] in step S313 (S319).

[0228] If the result of the determination in step S319 is positive, that is, if the information acquisition unit 112 acquired the online token KX[q] in step S313, the control device 11 of the terminal device 1[q] proceeds to step S321. If the result of the determination in step S319 is negative, that is, if the information acquisition unit 112 did not acquire the online token KX[q] in step S313, the control device 11 of the terminal device 1[q] proceeds to step S401.

[0229] As shown in Figure 23, if the result of the determination in step S319 is positive, that is, if the information acquisition unit 112 acquires the online token KX[q] in step S313, the code generation unit 113 of the terminal device 1[q] executes the online code generation process and generates the online payment code CX[q] based on the online token KX[q] (S321). Note that the process in step S321 corresponds to the process in step S47 described above.

[0230] Then, the display control unit 114 of the terminal device 1[q] generates display information for displaying the online code image GX[q] which represents the online payment code CX[q], and based on this display information, causes the display device 13 to display the online code image display screen GGX which includes the online code image GX[q] (S323). Note that the processing in step S323 corresponds to the processing in step S48 described above.

[0231] Next, the control device 11 of the terminal device 1[q] determines whether or not user U[q] has performed a termination operation using the input device 14 (S325). If the result of the determination in step S325 is positive, that is, if the termination operation is performed, the control device 11 of terminal device 1[q] proceeds to step S501. If the result of the determination in step S325 is negative, that is, if the termination operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether or not an online code image update trigger has arrived (S327). Here, an online code image update trigger is an event in which the online code image GX[q] displayed on the display device 13 is updated.

[0232] In this embodiment, it is assumed that an online code image update trigger occurs when one or more of the three update conditions J1, namely the online token time condition J11, the online code image display condition J12, and the online code image operation condition J13, are met. Here, the online token time condition J11 is the condition that a time equivalent to the online token validity period TSX (5 minutes in this embodiment) has elapsed since the online code image GX[q] was displayed on the display device 13. The online code image display condition J12 is the condition that the online code image display screen GGX containing the online code image GX[q] transitions from background display to foreground display on the display device 13. The online code image operation condition J13 is the condition that a pull-down operation is performed while the online code image display screen GGX containing the online code image GX[q] is displayed on the display device 13.

[0233] If the result of the determination in step S327 is negative, that is, if the trigger for updating the online code image has not arrived, the control device 11 of the terminal device 1[q] returns to step S323 and continues to display the online code image GX[q] on the display device 13. If the result of the determination in step S327 is positive, that is, if an online code image update trigger has arrived, the information transmission unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S329).

[0234] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not an online token KX[q] has been supplied from the settlement device 3 as a response to the online token request RX related to step S329 (S331). If the result of the determination in step S331 is positive, that is, if an online token KX[q] is supplied from the payment device 3, the control device 11 of the terminal device 1[q] acquires the online token KX[q] (S333) and proceeds to step S321, in which step S321 updates the online code image GX[q] by generating an online payment code CX[q] based on the online token KX[q] acquired in step S333.

[0235] If the result of the determination in step S331 is negative, that is, if the online token KX[q] has not been supplied from the settlement device 3, it is determined whether or not the online token response waiting period TWX[q] has ended (S335). If the result of the determination in step S335 is negative, that is, if the online token response waiting period TWX[q] has not ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S329, and the information transmission unit 111 repeats the transmission of the online token request RX. If the result of the determination in step S335 is positive, that is, if the online token response waiting period TWX[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S407.

[0236] As shown in Figure 24, if the result of the determination in step S317 is negative, or if the result of the determination in step S319 is negative, the information transmission unit 111 of the terminal device 1[q] sends an offline blockage information request BY to the payment device 3 (S401).

[0237] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not offline blockage information DHY has been supplied from the settlement device 3 as a response to the offline blockage information request BY related to step S401 (S403). If the result of the determination in step S403 is affirmative, that is, when the offline block information DHY is supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal apparatus 1[q] acquires the offline block information DHY (S405), and proceeds the process to step S407. If the result of the determination in step S403 is negative, that is, when the offline block information DHY is not supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal apparatus 1[q] proceeds the process to step S407.

[0238] Next, the code generation unit 113 of the terminal apparatus 1[q] determines whether or not the offline payment code CY[q] has already been generated in step S205 (S407). If the result of the determination in step S407 is affirmative, that is, when the offline payment code CY[q] has already been generated, the code generation unit 113 of the terminal apparatus 1[q] proceeds the process to step S433. If the result of the determination in step S407 is negative, that is, when the offline payment code CY[q] has not been generated yet, the information transmission unit 111 of the terminal apparatus 1[q] transmits an offline token request RY to the payment apparatus 3 (S409).

[0239] Then, the information acquisition unit 112 of the terminal apparatus 1[q] determines whether or not an offline token KY[q] and an encryption key KS[q] have been supplied from the payment apparatus 3 as a response to the offline token request RY according to step S409 (S411).

[0240] If the result of the determination in step S411 is affirmative, that is, when the offline token KY[q] and the encryption key KS[q] are supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal apparatus 1[q] acquires the offline token KY[q] and the encryption key KS[q] (S413). Next, the information acquisition unit 112 of the terminal apparatus 1[q] causes the storage device 12 to store the offline token KY[q] and the encryption key KS[q] acquired in step S413 (S415), and proceeds the process to step S419.

[0241] If the result of the determination in step S411 is negative, that is, if the offline token KY[q] and encryption key KS[q] are not supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] determines whether the offline token response waiting period TWY[q] has ended (S417). In the flowcharts of Figures 19 to 27, as an example, it is assumed that the offline token response waiting period TWY[q] is a period starting from the time the information transmission unit 111 sends the offline token request RY in step S409. If the result of the determination in step S417 is negative, that is, if the offline token response waiting period TWY[q] has not ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S409. If the result of the determination in step S417 is positive, that is, if the offline token response waiting period TWY[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S419.

[0242] Next, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of the offline payment processing in the payment device 3 is not in a blocked state based on the offline blockage information DHY acquired by the information acquisition unit 112 in step S405 (S419). Specifically, the code generation unit 113 determines whether the following conditions are met: the information acquisition unit 112 acquired the offline blockage information DHY in step S405, and the offline blockage information DHY indicates that the payment device 3 is not in an offline blockage state.

[0243] If the result of the determination in step S419 is negative, that is, if the information acquisition unit 112 did not acquire the offline blockage information DHY in step S405, or if the offline blockage information DHY indicates that the payment device 3 is in an offline blockage state, the control device 11 of the terminal device 1[q] proceeds to step S451.

[0244] If the result of the determination in step S419 is affirmative, that is, if the conditions are met such that the information acquisition unit 112 acquired offline blockage information DHY in step S405 and the offline blockage information DHY indicates that the settlement device 3 is not in an offline blockage state, then the control device 11 of the terminal device 1[q] determines whether or not a valid offline token KY[q][M] is stored in the storage device 12 of the terminal device 1[q] (S421).

[0245] If the result of the determination in step S421 is positive, that is, if a valid offline token KY[q][M] is stored in the memory device 12, the control device 11 of the terminal device 1[q] proceeds to step S431. If the result of the determination in step S421 is negative, that is, if no valid offline token KY[q][M] is stored in the storage device 12, the control device 11 of the terminal device 1[q] proceeds to step S451.

[0246] As shown in Figure 25, if the result of the determination in step S421 is positive, the code generation unit 113 of the terminal device 1[q] executes offline code generation processing and generates an offline payment code CY[q] based on the offline token KY[q][M] and the cryptographic key KS[q][M] (S431).

[0247] Then, the display control unit 114 of the terminal device 1[q] generates display information for displaying an offline code image GY[q] that represents the online payment code CX[q], and based on this display information, causes the display device 13 to display an offline code image display screen GGY that includes the offline code image GY[q] (S433).

[0248] Next, the control device 11 of the terminal device 1[q] determines whether or not user U[q] has performed a termination operation using the input device 14 (S435). If the result of the determination in step S435 is positive, that is, if the termination operation is performed, the control device 11 of terminal device 1[q] proceeds to step S501. If the result of the determination in step S435 is negative, that is, if the termination operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether or not an offline code image update trigger has arrived (S437). Here, an offline code image update trigger is an event in which the offline code image GY[q] displayed on the display device 13 is updated.

[0249] In this embodiment, it is assumed that an offline code image update trigger occurs when one or more of the two update conditions J2, namely the offline code image display condition J22 and the offline code image operation condition J23, are met. Here, the offline code image display condition J22 is the condition that the offline code image display screen GGY containing the offline code image GY[q] transitions from background display to foreground display on the display device 13. The offline code image operation condition J23 is the condition that a pull-down operation is performed while the offline code image display screen GGY containing the offline code image GY[q] is displayed on the display device 13.

[0250] If the result of the determination in step S437 is positive, that is, if an opportunity for offline code image update has arrived, the control device 11 of terminal device 1[q] proceeds to step S301. If the result of the determination in step S437 is negative, that is, if an offline code image update trigger has not occurred, the code generation unit 113 of the terminal device 1[q] determines whether or not an update trigger for the time encryption code TT[q] has occurred due to the updating of the terminal time value AG (S439). If the result of the determination in step S439 is negative, that is, if the opportunity to update the time encryption code TT[q] has not arrived, the control device 11 of the terminal device 1[q] returns to step S433 and continues to display the offline code image GY[q] on the display device 13.

[0251] If the result of the determination in step S439 is positive, that is, if the terminal time value AG is updated and an opportunity to update the time encryption code TT[q] has arrived, the code generation unit 113 of the terminal device 1[q] updates the time encryption code TT[q] by encrypting the updated terminal time value AG with the encryption key KS[q][M] (S441).

[0252] Then, the code generation unit 113 of the terminal device 1[q] updates the offline payment code CY[q] with the updated time encryption code TT[q] (S443), and proceeds to step S433, causing the display device 13 to display the updated offline code image GY[q]. Specifically, in step S443, the code generation unit 113 generates the updated offline payment code CY[q] by arranging the business identification token KZ stored in the storage device 12, the latest offline token KY[q][M] stored in the storage device 12, the updated time encryption code TT[q], the payment value VJ, and the code type value VV in a predetermined order.

[0253] As shown in Figure 26, if the result of the determination in step S419 is negative, or if the result of the determination in step S421 is negative, and the offline code generation process is difficult, the display device 13 is shown an online payment waiting screen (not shown) which notifies the user U[q] that it is waiting for the execution of online electronic payment (S451). Note that the process in step S451 may be omitted.

[0254] Then, the information transmitting unit 111 of the terminal device 1[q] determines whether or not communication can be established between the terminal device 1[q] and the payment device 3 (S453). Then, the information transmitting unit 111 waits until communication becomes available between the terminal device 1[q] and the payment device 3.

[0255] When communication becomes available between the terminal device 1[q] and the payment device 3 (S453: Y), the information transmitting unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S455). Then, if there is no response to the online token request RX from the payment device 3 (S457: N), the control device 11 of the terminal device 1[q] returns the process to step S455 to retransmit the online token request. On the other hand, when the information acquiring unit 112 of the terminal device 1[q] receives the online token KX[q] transmitted from the payment device 3 as a response to the online token request RX (S457: Y), the information acquiring unit 112 acquires the online token KX[q] (S459).

[0256] Next, the code generating unit 113 of the terminal device 1[q] executes an online code generation process using the online token KX[q] acquired in step S459, and generates an online payment code CX[q] (S461).

[0257] Then, the display control unit 114 of the terminal device 1[q] uses the online payment code CX[q] generated in step S461 to generate display information for displaying an online code image GX[q] representing the online payment code CX[q], and causes the display device 13 to display the online code image GX[q] based on the display information (S463).

[0258] Next, the control device 11 of the terminal device 1[q] determines whether or not the user U[q] has performed an end operation using the input device 14 (S465). If the result of the determination in step S465 is affirmative, that is, when an end operation has been performed, the control device 11 of the terminal device 1[q] advances the process to step S501. If the result of the determination in step S465 is negative, that is, if the termination operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether or not an online code image update trigger has arrived (S467).

[0259] If the result of the determination in step S467 is negative, that is, if an online code image update opportunity has not occurred, the control device 11 returns to step S463 and continues to display the online code image GX[q] on the display device 13. If the result of the determination in step S467 is positive, that is, if an online code image update trigger has arrived, the information transmission unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S469).

[0260] Then, if the control device 11 of terminal device 1[q] does not receive a response from the payment device 3 to the online token request RX related to step S469 (S471:N), it proceeds to step S451. On the other hand, if the control device 11 of terminal device 1[q] receives the online token KX[q] transmitted from the payment device 3 as a response to the online token request RX related to step S469 (S471:Y), it acquires the online token KX[q] (S473) and proceeds to step S461, thereby generating an online payment code CX[q] based on the online token KX[q] acquired in step S473 and updating the online code image GX[q].

[0261] As shown in Figure 27, if the result of the determination in step S209 is positive, if the result of the determination in step S325 is positive, if the result of the determination in step S435 is positive, or if the result of the determination in step S465 is positive, that is, if the termination operation is performed, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S501). Note that the processing in step S501 corresponds to the processing in step S51 described above.

[0262] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token KY[q] and the cryptographic key KS[q] have been supplied from the settlement device 3 as a response to the offline token request RY related to step S501 (S503).

[0263] If the result of the determination in step S503 is positive, that is, if the offline token KY[q] and encryption key KS[q] are supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] (S505). Next, the information acquisition unit 112 of the terminal device 1[q] stores the offline token KY[q] and encryption key KS[q] acquired in step S505 in the storage device 12 (S507), and completes the process shown in the flowcharts of Figures 19 to 27. Note that the process in step S507 corresponds to the process in step S53 described above.

[0264] If the result of the determination in step S503 is negative, that is, if the offline token KY[q] and encryption key KS[q] are not supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] determines whether the offline token response waiting period TWY[q] has ended (S509). Here, in the flowcharts of Figures 19 to 27, as an example, it is assumed that the offline token response waiting period TWY[q] related to step S509 is the period starting from the time the information transmission unit 111 sent the offline token request RY in step S501. If the result of the determination in step S509 is negative, that is, if the offline token response waiting period TWY[q] has not ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S501. If the result of the determination in step S509 is positive, that is, if the offline token response waiting period TWY[q] has ended, the control device 11 of the terminal device 1[q] terminates the process shown in the flowcharts of Figures 19 to 27.

[0265] As described above, according to the present embodiment, when online electronic payment is difficult, such as in the case of an online blocked state (S317: N) and when acquisition of the online token KX[q] has failed (S319: N), offline electronic payment is executed (see S401 to S433). Therefore, for example, compared with a mode in which the electronic payment system can only execute online electronic payment, when the user U[q] of the terminal device 1[q] receives a service provision at a store where the store device 5 is installed, the possibility that the user will pay the consideration for the service via electronic payment can be increased.

[0266] Further, according to the present embodiment, when an offline code image update timing arrives (S437: Y) in a state where an offline code image GY[q] is being displayed (see step S433), an attempt to acquire the online token KX[q] is made again (see steps S301 to S313). Therefore, according to the present embodiment, when online electronic payment is temporarily difficult and offline electronic payment is being executed, a return to online electronic payment becomes possible.

[0267] Further, according to the present embodiment, when offline code generation processing is difficult, such as in the case of an offline blocked state (S419: N) and when there is no valid offline token KY[q] in the storage device 12 (S421: N), a re-acquisition of the online token KX[q] is attempted (see steps S455 to S463). Therefore, compared with a mode that does not attempt to acquire the online token KX[q] when offline code generation processing is difficult, that is, a mode that abandons execution of the code generation processing when offline code generation processing is difficult, when the user U[q] of the terminal device 1[q] receives a service provision at a store where the store device 5 is installed, the possibility that the user will pay the consideration for the service via electronic payment can be increased.

[0268] <A.5. Operation of Payment Device 3> Hereinafter, an outline of the operation of the payment device 3 when electronic payment is executed will be described with reference to FIGS. 28 to 32.

[0269] Figure 28 is a flowchart illustrating an example of the operation of payment device 3 when the token response information supply process is performed in payment device 3. Here, the token response information supply process is a process in which, when electronic payment is performed in the electronic payment system Sys, payment device 3 supplies various information such as token response information DSW[q] to terminal device 1[q] in accordance with the terminal information DTM[q] from terminal device 1[q].

[0270] As shown in Figure 28, when terminal information DTM[q] is transmitted from terminal device 1[q], the information receiving unit 312 of the payment device 3 receives the terminal information DTM[q] (S601).

[0271] Next, the control device 31 of the payment device 3 determines the online token response waiting time TSWX[q] based on the terminal information DTM[q] (S603). Furthermore, the control device 31 of the payment device 3 determines the offline token response waiting time TSWY[q] based on the terminal information DTM[q] (S605). Then, the control device 31 of the payment device 3 generates token response information DSW[q] which indicates the online token response waiting time TSWX[q] determined in step S603 and the offline token response waiting time TSWY[q] determined in step S605 (S607).

[0272] Next, the control device 31 of the payment device 3 updates the terminal-specific token response information DW by adding the token response information DSW[q] generated in step S607 to the terminal-specific token response information DW (S609). Furthermore, the information supply unit 311 of the payment device 3 supplies the token response information DSW[q] generated in step S607 to the terminal device 1[q] (S611). Furthermore, the information supply unit 311 of the payment device 3 supplies the business identification token KZ, which is generated based on the business identification information DKZ stored in the storage device 32, to the terminal device 1[q] (S613). Furthermore, the information supply unit 311 of the payment device 3 supplies the setting information DS stored in the storage device 32 to the terminal device 1[q] (S615), and terminates the token response information supply process.

[0273] Figure 29 is a flowchart illustrating an example of the operation of payment device 3 when online token generation processing is performed in payment device 3. Here, online token generation processing is the process of generating online tokens KX[q] in response to online token requests RX from terminal device 1[q] when electronic payment is performed in the electronic payment system Sys.

[0274] As shown in Figure 29, when an online token request RX is transmitted from the terminal device 1[q], the information receiving unit 312 of the payment device 3 receives the online token request RX (S701).

[0275] Next, the control device 31 of the payment device 3 generates an online token KX[q] (S703). Furthermore, the control device 31 of the payment device 3 determines the online token validity period TX[q] (S705). Specifically, in step S705, the control device 31 determines the online token validity period TX[q] as a period that starts from the time of creation of the online token KX[q] and ends at a time that has elapsed from the time of creation of the online token KX[q] by the online token validity period TSX (for example, 5 minutes).

[0276] Then, the control device 31 of the payment device 3 updates the online token payout information DKX (S707). Specifically, in step S707, the control device 31 adds a new record to the online token payout information DKX, and stores in the new record the user identification information DID[q] corresponding to user U[q] of terminal device 1[q], the online token KX[q] generated in step S703, and the online token validity period TX[q] determined in step S705.

[0277] Then, the information supply unit 311 of the payment device 3 supplies the online token KX[q] generated in step S703 to the terminal device 1[q] (S709), and terminates the online token generation process.

[0278] Figure 30 is a flowchart illustrating an example of the operation of payment device 3 when offline token generation processing is performed in payment device 3. Here, offline token generation processing is the process of generating offline tokens KY[q] in response to offline token requests RY from terminal device 1[q] when electronic payment is performed in the electronic payment system Sys.

[0279] As shown in Figure 30, when an offline token request RY is transmitted from the terminal device 1[q], the information receiving unit 312 of the payment device 3 receives the offline token request RY (S721).

[0280] Next, the control device 31 of the payment device 3 generates an offline token KY[q] (S723). Furthermore, the control device 31 of the payment device 3 determines the offline token validity period TY[q] (S725). Specifically, in step S725, the control device 31 determines the offline token validity period TY[q] as a period that starts from the time of generation of the offline token KY[q] and ends at the time when the offline token validity period TSY (for example, one week) has elapsed from the time of generation of the offline token KY[q]. Furthermore, the control device 31 of the payment device 3 generates the cryptographic key KS[q] (S727).

[0281] Then, the control device 31 of the payment device 3 updates the offline token payout information DKY (S729). Specifically, in step S729, the control device 31 adds a new record to the offline token payout information DKY, and stores in the new record the user identification information DID[q] corresponding to user U[q] of terminal device 1[q], the offline token KY[q] generated in step S723, the offline token validity period TY[q] determined in step S725, and the encryption key KS[q] generated in step S727.

[0282] Then, the information supply unit 311 of the payment device 3 supplies the offline token KY[q] generated in step S723 and the encryption key KS[q] generated in step S727 to the terminal device 1[q] (S731), and terminates the offline token generation process.

[0283] Figures 31 and 32 are flowcharts illustrating an example of the operation of the payment device 3 when payment-related processing is performed in the payment device 3. Here, payment-related processing includes the process of determining the validity of token KK[q] in the payment device 3 and the payment processing performed by the payment device 3. The payment device 3 starts payment-related processing when payment information DP[q] is supplied from the store device 5.

[0284] As shown in Figure 31, when payment information DP[q] is transmitted from the store device 5 to the information receiving unit 312 of the payment device 3, the information receiving unit 312 receives the payment information DP[q] (S741).

[0285] Next, the settlement processing unit 313 of the settlement device 3 extracts the code type value VV from the settlement code CC[q] included in the settlement information DP[q] received in step S741 (S743). Then, the settlement processing unit 313 of the settlement device 3 determines whether the code type value VV extracted in step S743 represents an online code value (S745). That is, in step S745, the settlement processing unit 313 determines whether the settlement code CC[q] included in the settlement information DP[q] received in step S741 is an online settlement code CX[q].

[0286] If the result of the determination in step S745 is negative, that is, if the payment code CC[q] included in the payment information DP[q] is the offline payment code CY[q], the payment processing unit 313 of the payment device 3 proceeds to step S761. If the result of the determination in step S745 is positive, that is, if the payment code CC[q] included in the payment information DP[q] is the online payment code CX[q], the payment processing unit 313 of the payment device 3 extracts the online token KX[q] from the online payment code CX[q] included in the payment information DP[q] received in step S741 (S747).

[0287] Next, the settlement processing unit 313 of the settlement device 3 determines whether the online token KX[q] extracted in step S747 exists in the online token payout information DKX (S749). If the result of the determination in step S749 is negative, that is, if the online token KX[q] extracted in step S747 does not exist in the online token payout information DKX, the settlement processing unit 313 of the settlement device 3 proceeds to step S757.

[0288] If the result of the determination in step S749 is positive, that is, if the online token KX[q] extracted in step S747 exists in the online token withdrawal information DKX, the settlement processing unit 313 of the settlement device 3 refers to the online token withdrawal information DKX and determines whether the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 is a period that includes the current time (S751). If the result of the determination in step S751 is negative, that is, if the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 does not include the current time, the settlement processing unit 313 of the settlement device 3 proceeds to step S757.

[0289] If the result of the determination in step S751 is positive, that is, if the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 includes the current time, the settlement processing unit 313 of the settlement device 3 executes online settlement processing (S753) and confirms the payment from user U[q] corresponding to the online token KX[q] extracted in step S747 to the store where the store device 5 that sent the settlement information DP[q] in step S741 is located. Then, the information supply unit 311 of the payment device 3 sends a register charge response (S755) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, notifying that the payment from user U[q] based on the payment information DP[q] has been confirmed, and terminates the payment-related processing.

[0290] On the other hand, if the result of the determination in step S749 is negative, and if the result of the determination in step S751 is negative, the information supply unit 311 of the payment device 3 sends a notification (S757) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, informing the store that the payment from user U[q] based on the payment information DP[q] has failed, and terminates the payment-related processing.

[0291] As shown in Figure 32, if the result of the determination in step S745 is negative, that is, if the payment code CC[q] included in the payment information DP[q] is the offline payment code CY[q], the payment processing unit 313 of the payment device 3 extracts the offline token KY[q] from the offline payment code CY[q] included in the payment information DP[q] received in step S741 (S761).

[0292] Next, the settlement processing unit 313 of the settlement device 3 determines whether the offline token KY[q] extracted in step S761 exists in the offline token payout information DKY (S763). If the result of the determination in step S763 is negative, that is, if the offline token KY[q] extracted in step S761 does not exist in the offline token payout information DKY, the settlement processing unit 313 of the settlement device 3 proceeds to step S781.

[0293] If the result of the determination in step S763 is positive, that is, if the offline token KY[q] extracted in step S761 exists in the offline token payout information DKY, the settlement processing unit 313 of the settlement device 3 refers to the offline token payout information DKY and determines whether the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 is a period that includes the current time (S765). If the result of the determination in step S765 is negative, that is, if the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 does not include the current time, the settlement processing unit 313 of the settlement device 3 proceeds to step S781.

[0294] If the result of the determination in step S765 is affirmative, that is, if the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 includes the current time, the settlement processing unit 313 of the settlement device 3 determines whether the same offline token KY[q] included in the settlement information DP[q] received in step S741 was supplied during the period from a time twice the update unit time TC past the time the settlement information DP[q] was received in step S741 (for example, 2 minutes before the present) to the time the settlement information DP[q] was received in step S741 (hereinafter sometimes referred to as the "same token prohibition period") (S767). If the result of the determination in step S767 is positive, that is, if the same offline token KY[q] as the offline token KY[q] included in the settlement information DP[q] received in step S741 was received during the same token prohibition period, the settlement processing unit 313 of the settlement device 3 proceeds to step S781.

[0295] If the result of the determination in step S767 is negative, that is, if no offline token KY[q] identical to the offline token KY[q] included in the settlement information DP[q] received in step S741 has been received during the same token prohibition period, the settlement processing unit 313 of the settlement device 3 extracts the time encryption code TT[q] from the offline settlement code CY[q] included in the settlement information DP[q] received in step S741 (S769).

[0296] Furthermore, the settlement processing unit 313 of the settlement device 3 identifies the cryptographic key KS[q] corresponding to the offline token KY[q] extracted in step S761 by referring to the offline token payout information DKY (S771).

[0297] Next, the settlement processing unit 313 of the settlement device 3 encrypts the server time value AM, the future time value AMf, and the past time value AMp using the encryption key KS[q] identified in step S771 (S773).

[0298] Here, the server time value AM is a value based on the server time TM, which is the current time managed by the payment device 3, and is updated at intervals of the update unit time TC. Specifically, in this embodiment, as an example, we assume that the server time value AM is a value obtained by expressing the server time TM in the order of minutes. For example, in this embodiment, if the server time TM is "18:25:37", the server time value AM may be "1825", obtained by removing "37 seconds" from the server time TM. Therefore, if the server time TM and the terminal time TG are the same time, the server time value AM will be the same value as the terminal time value AG. However, in reality, there may be some error between the server time TM and the terminal time TG. In this case, the server time value AM and the terminal time value AG may be different values. Furthermore, the future time value AMf is a value based on a time that is one update unit time TC in the future of the server time TM. Specifically, in this embodiment, as an example, we assume that the future time value AMf is a value expressed in the order of minutes that is one update unit time TC (for example, 1 minute) in the future of the server time TM. For example, if the server time TM is "18:25:37", the future time value AMf may be "1826", which is obtained by removing "37 seconds" from "18:26:37", a time that is one minute in the future of the server time TM. Furthermore, the past time value AMp is a value based on a time that is one update unit time TC earlier than the server time TM. Specifically, in this embodiment, as an example, we assume that the past time value AMp is a value expressed in the order of minutes that is one update unit time TC (for example, 1 minute) earlier than the server time TM. For example, if the server time TM is "18:25:37", the past time value AMp may be "1824", which is obtained by removing "37 seconds" from "18:24:37", a time that is one minute earlier than the server time TM.

[0299] In the following, the value obtained by encrypting the server time value AM with the encryption key KS[q] will be referred to as the server time encryption code CM, the value obtained by encrypting the future time value AMf with the encryption key KS[q] will be referred to as the future time encryption code CMf, and the value obtained by encrypting the past time value AMp with the encryption key KS[q] will be referred to as the past time encryption code CMp. Furthermore, in the following, the server time encryption code CM, the future time encryption code CMf, and the past time encryption code CMp may be collectively referred to as the time encryption code CMM. That is, in step S773, the settlement processing unit 313 generates three time encryption codes CMM: the server time encryption code CM obtained by encrypting the server time value AM with the encryption key KS[q], the future time encryption code CMf obtained by encrypting the future time value AMf with the encryption key KS[q], and the past time encryption code CMp obtained by encrypting the past time value AMp with the encryption key KS[q].

[0300] Next, the settlement processing unit 313 of the settlement device 3 determines whether any of the three time encryption codes CMM generated in step S773 matches the time encryption code TT[q] extracted in step S769 (S775).

[0301] If the result of the determination in step S775 is positive, that is, if the time encryption code CMM generated in step S773 matches the time encryption code TT[q] extracted in step S769, the settlement processing unit 313 of the settlement device 3 executes offline settlement processing (S777) and confirms the payment from user U[q] corresponding to the offline token KY[q] extracted in step S761 to the store where the store device 5 that sent the settlement information DP[q] in step S741 is located. Then, the information supply unit 311 of the payment device 3 sends a register charge response (S779) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, notifying that the payment from user U[q] based on the payment information DP[q] has been confirmed, and terminates the payment-related processing.

[0302] On the other hand, if the result of the determination in step S763 is negative, if the result of the determination in step S765 is negative, if the result of the determination in step S767 is positive, and if the result of the determination in step S775 is negative, the information supply unit 311 of the payment device 3 sends a notification (S781) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, indicating that the payment from user U[q] based on the payment information DP[q] has failed, and terminates the payment-related processing.

[0303] As described above, in this embodiment, the payment device 3 is capable of performing two types of payment processing: online payment processing and offline payment processing. Therefore, compared to, for example, an embodiment in which the payment device 3 is capable of performing only online payment processing, the convenience of the user U[q] using electronic payment can be improved.

[0304] Furthermore, in this embodiment, if two or more pieces of payment information DP[q] containing the same offline token KY[q] are supplied during a token prohibition period having a duration twice the update unit time TC, the payment device 3 restricts offline payment processing based on the payment information DP[q] supplied from the second time onward. Therefore, according to this embodiment, it is possible to restrict fraudulent payments using the offline token KY[q], and security risks in the event of leakage of the offline token KY[q] can be reduced.

[0305] Furthermore, in the present embodiment, in the payment-related processing, the payment device 3 verifies the validity of the temporal encryption code TT[q] included in the offline payment code CY[q] using a future time value AMf and a past time value AMp in addition to the server time value AM. Therefore, according to the present embodiment, even if an error occurs between the terminal time TG managed by the terminal device 1[q] and the server time TM managed by the payment device 3, the user U[q] of the terminal device 1[q] can still use offline electronic payment. Accordingly, according to the present embodiment, for example, compared to a mode in which the validity of the temporal encryption code TT[q] is verified based only on the server time value AM in payment-related processing, it is possible to increase the possibility that the user U[q] can use electronic payment, and improve the convenience for the user U[q] who uses electronic payment.

[0306] <B.Modifications> Each of the above embodiments can be modified in various ways. Specific modification modes are exemplified below. Any two or more modes arbitrarily selected from the following examples can be appropriately combined within a range that does not contradict each other. Note that, in the modifications exemplified below, for elements whose actions and functions are equivalent to those of the embodiments, the reference numerals used in the above description are reused, and detailed description of each is omitted as appropriate.

[0307] <B.1.Modification 1> In the above-described embodiment, a mode in which the electronic payment system Sys starts the online code image display process of step S4 after executing the offline code image display process of step S2 has been described as an example, but the present invention is not limited to such a mode. The electronic payment system Sys may start part or all of the processes of steps S41 to S49 included in the online code image display process of step S4 before the completion of part or all of the processes of steps S21 to S25 included in the offline code image display process of step S2.

[0308] Specifically, terminal device 1[q] may start part of the processing among steps S41 to S48 included in the online code image display processing of step S4 after the timing at which at least part of the processing among steps S21 to S24 included in the offline code image display processing of step S2 is started and before part of the processing among steps S21 to S24 is completed. For example, terminal device 1[q] may start the processing of step S41 included in the online code image display processing of step S4 after the timing at which the processing of step S24 included in the offline code image display processing of step S2 is started and before the processing of step S24 is completed. Further, for example, terminal device 1[q] may execute the offline code image display processing of step S2 and the online code image display processing of step S4 as parallel processing.

[0309] <B.2. Modified Example 2> In the above-described embodiment and Modified Example 1, a mode in which the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] are determined based on terminal information DTM[q] is described as an example, but the present invention is not limited to such a mode. The online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be determined without being based on the terminal information DTM[q]. Specifically, the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be determined without considering the performance of the terminal device 1[q].

[0310] For example, the online token response waiting time TSWX[q] may be a predetermined fixed value. Further, for example, the offline token response waiting time TSWY[q] may also be a predetermined fixed value. In this case, token response information DSW[q] indicating the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be pre-stored in the storage device 12 of the terminal device 1[q].

[0311] <B.3.Modification 3> In the above-described embodiment and modifications 1 and 2, an aspect in which offline code image display processing is executed after the payment application is started without considering whether the payment device 3 is in an offline blocked state is described as an example; however, the present invention is not limited to such an aspect. The terminal device 1[q] may confirm whether or not the payment device 3 is in an offline blocked state after starting the payment application, and execute the offline code image display processing only when the payment device 3 is not in the offline blocked state.

[0312] FIG. 33 is a flowchart showing an example of an outline of a normal operation of an electronic payment system Sys according to the present modification when the electronic payment system Sys executes online electronic payment. The electronic payment system Sys according to the present modification has the same configuration as the electronic payment system Sys according to the embodiment.

[0313] As shown in FIG. 33, in the present modification, the control device 11 of the terminal device 1[q] activates a payment application by executing the electronic payment program PG-T based on an operation of a user U[q] (S1).

[0314] Next, the control device 11 of the terminal device 1[q] executes offline blockage determination processing (S8). Here, the offline blockage determination processing is processing for determining whether or not the payment device 3 is in an offline blocked state. In the flowchart shown in FIG. 33, it is assumed that the payment device 3 is not in the offline blocked state.

[0315] Subsequently, the control device 11 of terminal device 1[q] executes the offline code image display process (S2). However, if the control device 11 of terminal device 1[q] determines in the offline blockage determination process of step S8 that the payment device 3 is in an offline blockage state, it omits the offline code image display process of step S2. Furthermore, if the electronic payment system Sys determines in the offline blockage determination process of step S8 that the payment device 3 is in an offline blockage state, it executes the payment-related processing of step S3 after executing the online code image display process of step S4.

[0316] Next, the electronic payment system Sys executes payment-related processing (S3). Subsequently, the electronic payment system Sys performs the online code image display process (S4). Then, the electronic payment system Sys executes the offline token acquisition process (S5).

[0317] Figures 34 and 35 are sequence charts showing an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys according to this modified example performs online electronic payment.

[0318] As shown in Figure 34, in this modified example, the control device 11 of terminal device 1[q] in the electronic payment system Sys starts the payment application (S1).

[0319] Next, the electronic payment system Sys performs the offline blockage determination process (S8).

[0320] Specifically, in the offline blockage determination process of step S8, the communication status determination unit 115 of terminal device 1[q] first determines whether the communication status of terminal device 1[q] is online (S81). Note that the sequence charts shown in Figures 34 and 35 assume that the communication status of terminal device 1[q] is online. If, in step S81, the determination result is that the communication status of terminal device 1[q] is offline, the control device 11 of terminal device 1[q] terminates the offline blockage determination process of step S8. Next, in the offline blockage determination process of step S8, the information transmission unit 111 of terminal device 1[q] transmits an offline blockage information request BY to the payment device 3 (S82). Next, in the offline blockage determination process of step S8, the control device 31 of the payment device 3 supplies offline blockage information DHY to the terminal device 1[q] in response to the offline blockage information request BY supplied from the terminal device 1[q] in step S82 (S83). Specifically, in step S83, the control device 31 first determines whether or not the offline payment process in the payment device 3 can be executed, and generates offline blockage information DHY indicating the result of that determination. Then, the information supply unit 311 of the control device 31 supplies the generated offline blockage information DHY to the terminal device 1[q]. After that, the information acquisition unit 112 of the terminal device 1[q] acquires the offline blockage information DHY supplied from the payment device 3. Next, in the offline blockage determination process of step S8, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of offline payment processing in the payment device 3 is blocked or not based on the offline blockage information DHY acquired by the information acquisition unit 112 in step S83 (S84). Note that the sequence charts shown in Figures 34 and 35 assume that the execution function of offline payment processing in the payment device 3 is not blocked, that is, that the payment device 3 is capable of performing offline payment processing.

[0321] Next, the electronic payment system Sys executes the offline code image display process (S2). Specifically, as the offline code image display process in step S2, the electronic payment system Sys executes the processes described in steps S21 to S25 above. As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24). As described above, the control device 11 of the terminal device 1[q] executes the offline code image display process in step S2 only if the result obtained in step S84 is that the payment device 3 is not in an offline blocked state. If the result obtained is that the payment device 3 is in an offline blocked state, the offline code image display process in step S2 is omitted.

[0322] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing of step S3, the electronic payment system Sys executes the processing described in steps S31 to S35.

[0323] As shown in Figure 35, the electronic payment system Sys executes the online code image display process (S4) described above. Specifically, as the online code image display process in step S4, the electronic payment system Sys executes the processes described in steps S42 to S49.

[0324] Next, the electronic payment system Sys executes the offline token acquisition process (S5) described above. Specifically, as the offline token acquisition process in step S5, the electronic payment system Sys executes the processes described in steps S51 to S53 above.

[0325] As described above, in the present modification, the terminal device 1[q] displays the offline code image GY[q] on the display device 13 when the offline blockage information DHY indicates that the payment device 3 is not in an offline blockage state. That is, in the present modification, the terminal device 1[q] suppresses the display of the offline code image GY[q] on the display device 13 by restricting the execution of the offline code image display processing when the offline blockage information DHY indicates that the payment device 3 is in an offline blockage state. In other words, according to the present modification, the display of the offline code image GY[q] on the terminal device 1[q] is suppressed when execution of offline electronic payment is difficult. Therefore, according to the present modification, for example, the time and effort of the user U[q] related to displaying the offline code image GY[q] can be reduced compared to a mode in which the offline code image GY[q] is displayed without considering the offline blockage information DHY.

[0326] <B.4.Modification 4> In the above-described embodiment and Modifications 1 and 2, a mode in which offline code image display processing is executed after activation of a payment application without considering whether the payment device 3 is in an offline blockage state has been exemplified and described, but the present invention is not limited to such a mode. The terminal device 1[q] may confirm whether or not the payment device 3 is in an offline blockage state by executing offline blockage determination processing after activation of the payment application and after executing offline code image display processing.

[0327] FIG. 36 is a flowchart illustrating an example of an outline of a normal operation of an electronic payment system Sys according to the present modification when the electronic payment system Sys executes online electronic payment. Note that the electronic payment system Sys according to the present modification has the same configuration as the electronic payment system Sys according to the embodiment.

[0328] As shown in FIG. 36, in the present modification, the control device 11 of the terminal device 1[q] activates a payment application by executing an electronic payment program PG-T based on an operation of the user U[q] (S1).

[0329] Subsequently, the control device 11 of terminal device 1[q] executes offline code image display processing (S2). As a result, terminal device 1[q] displays the offline code image GY[q] on the display device 13.

[0330] Subsequently, the control device 11 of terminal device 1[q] executes an offline blockage determination process (S8). Note that the flowchart shown in Figure 33 assumes that the payment device 3 is not in an offline blockage state. Furthermore, if the control device 11 of terminal device 1[q] determines in the offline blockage determination process of step S8 that the payment device 3 is in an offline blockage state, it interrupts the display of the offline code image GY[q] on the display device 13. Also, if the electronic payment system Sys determines in the offline blockage determination process of step S8 that the payment device 3 is in an offline blockage state, it executes the payment-related processing of step S3 after executing the online code image display processing of step S4.

[0331] Next, the electronic payment system Sys executes payment-related processing (S3). Subsequently, the electronic payment system Sys performs the online code image display process (S4). Then, the electronic payment system Sys executes the offline token acquisition process (S5).

[0332] Figure 37 is a sequence chart showing an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys according to this modified example performs online electronic payment.

[0333] As shown in Figure 37, in this modified example, the control device 11 of terminal device 1[q] in the electronic payment system Sys starts the payment application (S1).

[0334] Next, the electronic payment system Sys performs offline code image display processing (S2). Specifically, as the offline code image display processing in step S2, the electronic payment system Sys performs the processes described in steps S21 to S25 above. As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24).

[0335] Next, the electronic payment system Sys performs an offline blockage determination process (S8). Specifically, as the offline blockage determination process in step S8, the electronic payment system Sys performs the processes described in steps S81 to S84 above. Note that the sequence chart shown in Figure 37 assumes that the offline payment processing execution function in the payment device 3 is not in a blocked state, that is, that the payment device 3 is capable of performing offline payment processing. However, if the display control unit 114 of the terminal device 1[q] determines in the offline blockage determination process of step S8 that the payment device 3 is in an offline blockage state, it interrupts the display of the offline code image GY[q] on the display device 13.

[0336] Next, the electronic payment system Sys executes the payment-related processing (S3) described above. Specifically, as the payment-related processing of step S3, the electronic payment system Sys executes the processing described in steps S31 to S35. Then, the electronic payment system Sys executes the online code image display process (S4) described above (not shown). Specifically, as the online code image display process of step S4, the electronic payment system Sys executes the processes of steps S42 to S49 described above. Subsequently, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown in the diagram). Specifically, as the offline token acquisition process in step S5, the electronic payment system Sys executes the processes described in steps S51 to S53 above.

[0337] As described above, in this modified example, the terminal device 1[q] executes offline blockage determination processing after offline code image display processing. That is, in this modified example, after the terminal device 1[q] executes offline code image display processing and displays the offline code image GY[q] on the display device 13, if the offline blockage information DHY indicates that the payment device 3 is in an offline blockage state, the terminal device 1[q] interrupts the display of the offline code image GY[q] on the display device 13. Therefore, according to this modified example, for example, the effort of the user U[q] related to the display of the offline code image GY[q] can be reduced compared to a mode in which the offline blockage determination processing is not executed after the offline code image display processing.

[0338] <B.5.Modified Example 5> In the above-described embodiment and modified examples 1 to 4, a mode has been described as an example in which the electronic payment system Sys starts the offline token acquisition processing of step S5 after executing the offline code image display processing of step S4, but the present invention is not limited to such a mode. The electronic payment system Sys may start part or all of the offline code image display processing of step S4 after starting part or all of the offline token acquisition processing of step S5.

[0339] FIG. 38 is a flowchart illustrating an example of an outline of a normal operation of the electronic payment system Sys when the electronic payment system Sys according to the present modified example executes online electronic payment. Note that the electronic payment system Sys according to the present modified example has the same configuration as the electronic payment system Sys according to the embodiment.

[0340] As shown in FIG. 38, in the present modified example, the control device 11 of the terminal device 1[q] activates a payment application by executing an electronic payment program PG-T based on an operation of the user U[q] (S1). Thereafter, the control device 11 of the terminal device 1[q] executes offline code image display processing (S2). Accordingly, the terminal device 1[q] displays the offline code image GY[q] on the display device 13. Next, the electronic payment system Sys executes payment-related processing (S3). Next, the electronic payment system Sys executes offline token acquisition processing (S5). Thereafter, the electronic payment system Sys executes online code image display processing (S4).

[0341] As described above, in this modification, before displaying the online code image GX[q] through the online code image display processing, the terminal device 1[q] executes acquisition of the offline token KY[q] and the encryption key KS[q] through the offline token acquisition processing. Therefore, according to this modification, compared to an aspect in which the offline token KY[q] and the encryption key KS[q] are acquired after displaying the online code image GX[q], the terminal device 1[q] can acquire the offline token KY[q] and the encryption key KS[q] more reliably. Thereby, according to this modification, compared to the aspect in which the offline token KY[q] and the encryption key KS[q] are acquired after displaying the online code image GX[q], it is possible to increase the possibility of displaying the offline code image GY[q] based on the valid offline token KY[q] in the offline code image display processing executed by the terminal device 1[q], and to increase the possibility that the offline electronic payment is executed by the user U[q] of the terminal device 1[q].

[0342] <B.6.Modification 6> In the above-described embodiment and modifications 1 to 5, an example is described where the terminal device 1[q] acquires the online token KX[q] and the offline token KY[q] at different timings during electronic payment, but the present invention is not limited to such an aspect. The terminal device 1[q] may acquire the online token KX[q] and the offline token KY[q] simultaneously during electronic payment.

[0343] FIG. 39 is a sequence chart showing an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys according to this modification executes online electronic payment.

[0344] Although not shown in Figure 39, in this modified example, the electronic payment system Sys launches the payment application (S1), then performs offline code image display processing (S2), then performs payment-related processing (S3), and then performs online code image display processing (S4).

[0345] As shown in Figure 39, the communication status determination unit 115 of terminal device 1[q] determines whether the communication status of terminal device 1[q] is online or not during the online code image display process in step S4 (S41). Note that the sequence chart shown in Figure 39 assumes that the communication status of terminal device 1[q] is online. Next, the information transmission unit 111 of the terminal device 1[q] transmits a block information request BXY in the online code image display process of step S4 (S92). Here, the block information request BXY is a message requesting online block information DHX and offline block information DHY. Next, in the online code image display processing of step S4, the control device 31 of the payment device 3 supplies online block information DHX and offline block information DHY to the terminal device 1[q] as a response to the block information request BXY supplied from the terminal device 1[q] in step S92 (S93). Next, the information transmission unit 111 of the terminal device 1[q] transmits a token request RXY to the payment device 3 during the online code image display process in step S4 (S94). Here, the token request RXY is a message requesting the online token KX[q], the offline token KY[q], and the encryption key KS[q]. Then, in the online code image display processing of step S4, the control device 31 of the payment device 3 supplies the online token KX[q], the offline token KY[q], and the cryptographic key KS[q] to the terminal device 1[q] as a response to the token request RXY supplied from the terminal device 1[q] in step S94 (S95). Next, in the online code image display processing of step S4, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and the encryption key KS[q] supplied from the payment device 3 in step S95, and causes the storage device 12 to store the acquired offline token KY[q] and encryption key KS[q] (S53). Next, the control device 11 of the terminal device 1[q] executes the processing of steps S46 to S48 described above as the online code image display processing of step S4. Thereafter, the electronic payment system Sys executes offline token acquisition processing (S5).

[0346] According to this modification, at the timing when electronic payment is performed, the offline token KY[q] is acquired from the payment device 3 and the offline token KY[q] is stored in the storage device 12. Therefore, according to the present embodiment, when online electronic payment is difficult due to communication failure or the like, it is possible to reduce the possibility that even offline electronic payment becomes difficult to execute.

[0347] <B.7.Modification 7> In the above-described embodiment and modifications 1 to 3, a mode has been described as an example in which the online token valid time TSX, the offline token valid time TSY, and the update unit time TC are notified from the payment device 3 as the setting information DS. However, the present invention is not limited to such a mode. Part or all of the online token valid time TSX, the offline token valid time TSY, and the update unit time TC may be stored as fixed values in the storage device 12 of the terminal device 1[q].

[0348] <B.8.Modification 8> In the above-described embodiment and modifications 1 to 7, a case where the blocking information DH is information indicating whether or not the payment device 3 can execute payment processing has been described as an example. However, the present invention is not limited to such a mode. The blocking information DH may be information indicating whether or not the payment device 3 can execute payment processing by each payment method.

[0349] Specifically, in this modified example, the online blockage information DHX includes online combined payment blockage information DHX1, which indicates whether online payment processing by combined telephone bill payment is possible; online balance payment blockage information DHX2, which indicates whether online payment processing by prepaid balance payment is possible; and online card payment blockage information DHX3, which indicates whether online payment processing by credit card payment is possible. Here, online combined payment blockage information DHX1 may be information indicating whether the function of the payment device 3 for executing online payment processing by combined telephone bill payment is operating without blockage. Online balance payment blockage information DHX2 may be information indicating whether the function of the payment device 3 for executing online payment processing by prepaid balance payment is operating without blockage. Online card payment blockage information DHX3 may be information indicating whether the function of the payment device 3 for executing online payment processing by credit card payment is operating without blockage. In the following, online combined payment blockage information DHX1, online balance payment blockage information DHX2, and online card payment blockage information DHX3 may be collectively referred to as individual online blockage information DHX0. Furthermore, in this modified example, the offline blockage information DHY includes offline combined payment blockage information DHY1, which indicates whether offline payment processing by telephone bill combined payment is possible; offline balance payment blockage information DHY2, which indicates whether offline payment processing by prepaid balance payment is possible; and offline card payment blockage information DHY3, which indicates whether offline payment processing by credit card payment is possible. Here, offline combined payment blockage information DHY1 may be information indicating whether the function of the payment device 3 for executing offline payment processing by telephone bill combined payment is operating without blockage. Also, offline balance payment blockage information DHY2 may be information indicating whether the function of the payment device 3 for executing offline payment processing by prepaid balance payment is operating without blockage. Also, offline card payment blockage information DHY3 may be information indicating whether the function of the payment device 3 for executing offline payment processing by credit card payment is operating without blockage. In the following, offline combined payment blockage information DHY1, offline balance payment blockage information DHY2, and offline card payment blockage information DHY3 may be collectively referred to as individual offline blockage information DHY0.

[0350] In this modified example, the payment device 3 may, in response to the online blockage information request BX from the terminal device 1[q], supply to the terminal device 1[q] the individual online blockage information DHX0, which is one of the three individual online blockage information DHX0 included in the online blockage information DHX, that corresponds to the payment method selected by the user U[q] of the terminal device 1[q]. Furthermore, in this modified example, the payment device 3 may, in response to the offline blockage information request BY from the terminal device 1[q], supply to the terminal device 1[q] the individual offline blockage information DHY0 from the three individual offline blockage information DHY0 included in the offline blockage information DHY that corresponds to the payment method selected by the user U[q] of the terminal device 1[q]. Furthermore, in this modified example, the payment device 3 may, in response to the offline blockage information request BY from the terminal device 1[q], supply to the terminal device 1[q] the three individual offline blockage information DHY0 included in the offline blockage information DHY.

[0351] Furthermore, in the embodiments and modifications 1 to 7 described above, the payment device 3 is shown as supplying the terminal device 1[q] with an online token KX[q] common to multiple payment methods and an offline token KY[q] common to multiple payment methods, regardless of the payment method selected by the user U[q] of the terminal device 1[q]. However, the present invention is not limited to such embodiments. For example, the payment device 3 may supply the terminal device 1[q] with one or more offline tokens KY[q] that correspond one-to-one with one or more payment methods that the user U[q] of the terminal device 1[q] can select.

[0352] Specifically, in this modified example, in response to an offline token request RY from terminal device 1[q], payment device 3 supplies terminal device 1[q] with: an offline token KY1[q] for combined payment, which is an offline token KY[q] corresponding to combined telephone bill payment; an offline token KY2[q] for balance payment, which is an offline token KY[q] corresponding to prepaid balance payment; and an offline token KY3[q] for card payment, which is an offline token KY[q] corresponding to credit card payment. In the following, the offline token KY1[q] for combined payment, the offline token KY2[q] for balance payment, and the offline token KY3[q] for card payment may be collectively referred to as individual offline token KY0[q]. That is, in this modified example, in response to an offline token request RY from terminal device 1[q], payment device 3 supplies terminal device 1[q] with three individual offline tokens KY0[q] that correspond one-to-one with the three payment methods that user U[q] of terminal device 1[q] can select.

[0353] In this modified example, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on an individual offline token KY0[q] corresponding to the payment method selected by user U[q] of the terminal device 1[q]. Specifically, in this modified example, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on an offline token KY1[q] for combined payment when the payment method selected by user U[q] of the terminal device 1[q] is combined telephone bill payment, generates an offline payment code CY[q] based on an offline token KY2[q] for balance payment when the payment method selected by user U[q] of the terminal device 1[q] is prepaid balance payment, and generates an offline payment code CY[q] based on an offline token KY3[q] for card payment when the payment method selected by user U[q] of the terminal device 1[q] is credit card payment.

[0354] Furthermore, in this modified example, the display control unit 114 of the terminal device 1[q] determines whether or not to display the offline code image GY[q] based on the individual offline token KY0[q] corresponding to the payment method selected by user U[q] of the terminal device 1[q] to the display device 13, based on the individual offline block information DHY0 corresponding to the payment method selected by user U[q] of the terminal device 1[q]. Specifically, in this modified example, if the payment method selected by user U[q] of terminal device 1[q] is telephone bill combined payment, the presence or absence of the offline code image GY[q] based on the combined payment offline token KY1[q] is determined based on the offline combined payment blockage information DHY1. If the payment method selected by user U[q] of terminal device 1[q] is prepaid balance payment, the presence or absence of the offline code image GY[q] based on the balance payment offline token KY2[q] is determined based on the offline balance payment blockage information DHY2. If the payment method selected by user U[q] of terminal device 1[q] is credit card payment, the presence or absence of the offline code image GY[q] based on the card payment offline token KY3[q] is determined based on the offline card payment blockage information DHY3.

[0355] Note that in this modification, the settlement device 3 may supply three online tokens KX[q] to the terminal device 1[q], the three online tokens KX[q] being in one-to-one correspondence with the three types of payment methods selectable by the user U[q] of the terminal device 1[q]. Further, in this modification, the settlement device 3 may, from among the three online tokens KX[q] that are in one-to-one correspondence with the three types of payment methods selectable by the user U[q] of the terminal device 1[q], supply, to the terminal device 1[q], one online token KX[q] corresponding to the one payment method selected by the user U[q] of the terminal device 1[q].

[0356] As described above, according to this modification, whether to display the offline code image GY[q] can be finely controlled in accordance with the blockage status for each payment method selected by the user U[q] of the terminal device 1[q], and therefore compared with aspects that do not take payment methods into consideration, it is possible to reduce the effort of the user U[q] and improve the convenience of the user U[q].

[0357] <B.9.Modification 9> In the above-described embodiment and modifications 1 to 8, an aspect is exemplified in which the terminal device 1[q] can display an offline code image GY[q] based on the offline token KY[q][M] stored in the storage device 12, and the terminal device 1[q] can display an online code image GX[q] based on the online token KX[q] supplied from the settlement device 3. However, the present invention is not limited to such an aspect. For example, based on the status of the user U[q] of the terminal device 1[q], the display function of the online code image GX[q] in the terminal device 1[q] and the display function of the offline code image GY[q] in the terminal device 1[q] may be restricted.

[0358] FIG. 40 is a sequence chart showing an example of the operation of the electronic settlement system Sys according to this modification when the electronic settlement system Sys executes online electronic settlement.

[0359] As shown in Figure 40, in this modified example, the control device 11 of terminal device 1[q] in the electronic payment system Sys starts the payment application (S1).

[0360] Next, the electronic payment system Sys performs offline code image display processing (S2). Specifically, as the offline code image display processing in step S2, the electronic payment system Sys performs the processes described in steps S21 to S25 above (some parts are not shown). As a result, the display control unit 114 of the terminal device 1[q] displays the offline code image GY[q] on the display device 13 (S24).

[0361] Next, the electronic payment system Sys performs the processes described in steps S41 to S43 during the online code image display process (S4). Subsequently, terminal device 1[q] sends an online token request RX to payment device 3 (S44).

[0362] Next, in the online code image display process, the payment device 3 determines the validity of user U[q] corresponding to user identification information DID[q] included in the online token request RX, based on the online token request RX obtained in step S43 (SA1). Here, "validity of user U[q]" is a concept that includes "validity of user U[q]'s ability to pay" and "validity of user U[q]'s identity verification." Of these, "User U[q]'s ability to pay" refers to, for example, the ability of User U[q] to pay in order to receive electronic payment services from the electronic payment system Sys. For example, if User U[q] has the ability to pay in order to receive electronic payment services from the electronic payment system Sys, User U[q]'s ability to pay may be considered valid. On the other hand, for example, if User U[q] has defaulted on payments multiple times in the past for electronic payment services provided by the electronic payment system Sys, User U[q]'s ability to pay may be considered invalid. Furthermore, "validity of user U[q]'s identity authentication" means, for example, that there is no possibility of impersonation of user U[q], and that user U[q] himself is operating terminal device 1[q] to receive electronic payment services. For example, if user U[q] contacts the administrator of the electronic payment system Sys requesting the suspension of electronic payment services because terminal device 1[q] has been lost, user U[q]'s identity authentication may be deemed invalid. Also, for example, if user U[q] contacts the administrator of the electronic payment system Sys requesting the suspension of electronic payment services because authentication information managed by user U[q] has been leaked, user U[q]'s identity authentication may be deemed invalid. Note that the example shown in Figure 40 assumes that user U[q] is not valid.

[0363] In step SA1, if the payment device 3 determines that user U[q] is invalid, it sends an online token rejection notice ZX to terminal device 1[q] (SA2). Here, the online token rejection notice ZX is a notification from the payment device 3 to terminal device 1[q] that it is rejecting the supply of online token KX[q]. The online token rejection notice ZX may also include a notification that user U[q] is invalid.

[0364] If terminal device 1[q] receives an online token rejection notification ZX from payment device 3, it executes code image blocking processing (SB). Specifically, terminal device 1[q] performs online code image blocking processing (SB1) in the code image blocking processing. Here, online code image blocking processing is the process of blocking the display function of the online code image GX[q] in the payment application. Furthermore, terminal device 1[q] performs offline code image blocking processing (SB2) during code image blocking processing. Here, offline code image blocking processing is the process of blocking the display function of the offline code image GY[q] in the payment application. Then, in the code image blocking process, the terminal device 1[q] changes the offline code image GY[q] displayed on the display device 13 in step S24 to a non-display state (SB3).

[0365] As described above, according to this modification, when the validity related to the solvency of the user U[q] has been lost, or when the validity related to the personal authentication of the user U[q] has been lost, that is, when the validity of the user U[q] has been lost, the terminal device 1[q] blocks the display function of the code image GG[q] in the payment application of the terminal device 1[q]. Therefore, according to this modification, it is possible to prevent a situation where a service related to electronic payment is illegally used by using the terminal device 1[q].

[0366] <C. Supplementary Notes> Aspects related to the above embodiment and modifications are supplementary described below. To facilitate understanding of each aspect, reference numerals from the drawings are added to the description below, but this is not intended to limit the present invention to the illustrated aspects.

[0367] <Supplementary Note 1> The electronic payment program PG-T according to Supplementary Note 1 is an electronic payment program PG-T installed in a terminal device 1[q] capable of communicating with a payment device 3, which causes a processor of the terminal device 1[q] to function as: an information acquisition unit 112 that acquires an online token KX[q] from the payment device 3 when the terminal device 1[q] can communicate with the payment device 3; and a display control unit 114 that causes the display device 13 of the terminal device 1[q] to display an online code image GX[q] based on the online token KX[q] when the information acquisition unit 112 acquires the online token KX[q], wherein the display control unit 114 causes the display device 13 to display an offline code image GY[q] based on an offline token KY[q] stored in a storage device 12 of the terminal device 1[q] regardless of the communication state of the terminal device 1[q] when the electronic payment program PG-T is started.

[0368] According to Appendix 1, after the electronic payment program PG-T is launched, the offline code image GY[q] based on the offline token KY[q] is displayed regardless of the communication status of the terminal device 1[q]. Therefore, according to Appendix 1, compared to a configuration in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched, it is possible to shorten the waiting time for user U[q] of terminal device 1[q] to receive the electronic payment service. As a result, according to Appendix 1, the convenience for user U[q] can be improved compared to a configuration in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched.

[0369] <Note 2> The electronic payment program PG-T relating to Appendix 2 is the electronic payment program PG-T described in Appendix 1, characterized in that, after the electronic payment program PG-T is started, when the information acquisition unit 112 acquires an online token KX[q], the display control unit 114 switches the image to be displayed on the display device 13 from the offline code image GY[q] to the online code image GX[q] based on the online token KX[q] acquired by the information acquisition unit 112.

[0370] According to Appendix 2, in terminal device 1[q], the offline code image GY[q] is displayed from the time the electronic payment program PG-T is launched until the online token KX[q] is acquired. Therefore, according to Appendix 2, compared to the configuration in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched, it is possible to shorten the waiting time for user U[q] of terminal device 1[q] to receive the electronic payment service. As a result, according to Appendix 2, the convenience for user U[q] can be improved compared to the configuration in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched.

[0371] <Note 3> The electronic payment program PG-T relating to Appendix 3 is the electronic payment program PG-T described in Appendix 1 or Appendix 2, characterized in that the processor of the terminal device 1[q] is further configured to function as a communication status determination unit 115 for determining the communication status of the terminal device 1[q], and the display control unit 114 displays the offline code image GY[q] on the display device 13 after the electronic payment program PG-T is started and before the communication status determination unit 115 outputs the result of determining the communication status of the terminal device 1[q].

[0372] According to Appendix 3, in terminal device 1[q], the display control unit 114 prioritizes displaying the offline code image GY[q] over the communication status determination by the communication status determination unit 115. Therefore, according to Appendix 3, compared to a configuration in terminal device 1[q] where the communication status determination is prioritized over the display of the offline code image GY[q], it becomes possible to shorten the waiting time for user U[q] of terminal device 1[q] to receive electronic payment services.

[0373] <Note 4> The electronic payment program PG-T relating to Appendix 4 is the electronic payment program PG-T described in Appendix 1 to Appendix 3, characterized in that the information acquisition unit 112 acquires offline blockage information DHY indicating whether or not an offline payment process can be executed in the payment device 3 based on the offline code image GY[q] when communication between the terminal device 1[q] and the payment device 3 is difficult, after the electronic payment program PG-T has been started and before the display control unit 114 displays the offline code image GY[q] on the display device 13.

[0374] According to Appendix 4, when the payment device 3 is in an offline blocked state and it is difficult to perform offline payment processing, the terminal device 1[q] performs a process to acquire offline blocked information DHY indicating that the payment device 3 is in an offline blocked state, prior to the process of displaying the offline code image GY[q] on the display device 13. Therefore, according to Appendix 4, when the payment device 3 is in an offline blocked state, the display of the offline code image GY[q] can be suppressed in the terminal device 1[q]. As a result, according to Appendix 4, the load on the user U[q] that would occur due to the process of displaying the offline code image GY[q] in the terminal device 1[q] despite the payment device 3 being unable to perform offline payment processing can be suppressed in advance.

[0375] <Note 5> The electronic payment program PG-T relating to Appendix 5 is the electronic payment program PG-T described in Appendix 1 to Appendix 3, characterized in that the information acquisition unit 112 acquires offline blockage information DHY indicating whether or not an offline payment process can be executed in the payment device 3 based on the offline code image GY[q] when communication between the terminal device 1[q] and the payment device 3 is difficult, after the electronic payment program PG-T has been started and the display control unit 114 has displayed the offline code image GY[q] on the display device 13.

[0376] According to Appendix 5, when the payment device 3 is in an offline blocked state and it is difficult to perform offline payment processing, the terminal device 1[q] performs a process to display the offline code image GY[q] on the display device 13, followed by a process to acquire offline blocked information DHY indicating that the payment device 3 is in an offline blocked state. Therefore, according to Appendix 5, when the payment device 3 is in an offline blocked state, it is possible to suppress the continued display of the offline code image GY[q] on the terminal device 1[q]. As a result, according to Appendix 5, it is possible to suppress the load on the user U[q] that would otherwise be generated by the continued display of the offline code image GY[q] on the terminal device 1[q] despite the payment device 3 being unable to perform offline payment processing.

[0377] <Note 6> The electronic payment program PG-T relating to Appendix 6 is the electronic payment program PG-T described in Appendix 1 to Appendix 5, characterized in that the information acquisition unit 112 acquires the offline token KY[q] from the payment device 3 during the period from when the electronic payment program PG-T is started until the electronic payment program PG-T is terminated, and stores the acquired offline token KY[q] in the storage device 12.

[0378] According to Appendix 6, in order to acquire both the online token KX[q] and the offline token KY[q] during the period in which the electronic payment program PG-T is activated, it is possible to reliably acquire both the online token KX[q] and the offline token KY[q] in the manner in which only one of the two tokens, KK[q], is acquired during that period.

[0379] <Note 7> The electronic payment program PG-T relating to Appendix 7 is the electronic payment program PG-T described in Appendix 1 to Appendix 6, characterized in that, after the electronic payment program PG-T is started, when the information acquisition unit 112 acquires an online token KX[q], the display control unit 114 switches the image to be displayed on the display device 13 from the offline code image GY[q] to the online code image GX[q] based on the online token KX[q] acquired by the information acquisition unit 112, and after the display control unit 114 displays the online code image GX[q] on the display device 13, until the electronic payment program PG-T is terminated, the information acquisition unit 112 acquires an offline token KY[q] from the payment device 3 and stores the acquired offline token KY[q] in the storage device 12.

[0380] According to Appendix 7, since terminal device 1[q] acquires offline token KY[q] after displaying online code image GX[q], it is possible to reduce the possibility of delay in displaying online code image GX[q] compared to the configuration in which terminal device 1[q] acquires offline token KY[q] before displaying online code image GX[q].

[0381] <Note 8> The electronic payment program PG-T relating to Appendix 8 is the electronic payment program PG-T described in Appendix 1 to Appendix 7, wherein the offline token KY[q] has an offline token validity period TY[q] set as the validity period of the offline token KY[q], and the display control unit 114 displays the offline code image GY[q] based on the offline token KY[q] on the display device 13 if the offline token KY[q] within the offline token validity period TY[q] is stored in the storage device 12, and does not display the offline code image GY[q] on the display device 13 if the offline token KY[q] within the offline token validity period TY[q] is not stored in the storage device 12.

[0382] According to Appendix 8, since it is possible to prevent offline electronic payments from being executed using expired offline tokens KY[q], the security level of offline electronic payments can be increased compared to a configuration in which offline tokens KY[q] do not have an expiration date.

[0383] <Note 9> The electronic payment program PG-T relating to Appendix 9 is the electronic payment program PG-T described in Appendix 1 to Appendix 8, characterized in that, when the storage device 12 stores a plurality of offline tokens KY[q][1] to KY[q][M], the display control unit 114 causes the display device 13 to display the offline code image GY[q] based on the offline token KY[q][M] that the information acquisition unit 112 last acquired from the payment device 3 among the plurality of offline tokens KY[q][1] to KY[q][M].

[0384] According to Appendix 9, since the latest offline token KY[q][M] is used to execute the offline electronic payment, the security level of the offline electronic payment can be increased compared to the case in which the older offline token KY[q][M-1] is used to execute the offline electronic payment.

[0385] <Note 10> The electronic payment program PG-T relating to Appendix 10 is the electronic payment program PG-T described in Appendix 1 to Appendix 9, characterized in that the online token KX[q] is a token KK[q] used in the payment device 3 to decide whether to perform payment processing corresponding to user U[q] of terminal device 1[q] when terminal device 1[q] and payment device 3 can communicate, and the offline token KY[q] is a token KK[q] used in the payment device 3 to decide whether to perform payment processing corresponding to user U[q] of terminal device 1[q] when communication between terminal device 1[q] and payment device 3 is difficult.

[0386] According to Appendix 10, electronic payment can be performed not only when terminal device 1[q] and payment device 3 can communicate, but also when communication between terminal device 1[q] and payment device 3 is difficult. Therefore, a decrease in convenience for user U[q] of terminal device 1[q] due to communication failure can be suppressed.

[0387] <Note 11> The electronic payment program PG-T relating to Appendix 11 is the electronic payment program PG-T described in Appendix 1 to Appendix 10, characterized in that the display control unit 114 uses the encryption key KS[q] stored in the storage device 12 to encrypt the terminal time value AG based on the terminal time TG of the terminal device 1[q], and the offline token KY[q] to display the offline code image GY[q] on the display device 13.

[0388] According to Appendix 11, since the offline code image GY[q] is displayed using the time-cryptographic code TT[q] in addition to the offline token KY[q], the security level of offline electronic payments can be increased compared to the method of displaying the offline code image GY[q] without using the time-cryptographic code TT[q].

[0389] <Note 12> The electronic payment program PG-T relating to Appendix 12 is the electronic payment program PG-T described in Appendix 1 to Appendix 11, characterized in that the display control unit 114 changes the offline code image GY[q] displayed on the display device 13 of the terminal device 1[q] to a hidden state when the information acquisition unit 112 acquires an online token rejection notification ZX from the payment device 3. In Appendix 12, the online token rejection notification ZX is an example of a "specific notification concerning the terminal user".

[0390] According to Supplementary Note 12, when the user U[q] is in a specific state, such as when the validity of the solvency of the user U[q] has expired, or when the validity of the personal authentication of the user U[q] has expired, the display function of the code image GG[q] in the payment application of the terminal device 1[q] is disabled. Therefore, the occurrence of a situation where a service related to electronic payment is illegally used by using the terminal device 1[q] can be prevented.

[0391] <D.Other matters> (1) In the above-described embodiment (including modified examples; the same applies hereinafter), ROM and RAM are exemplified as the storage device 12 and the storage device 32, but the storage device may be a flexible disk, a magneto-optical disk (for example, a compact disc, a digital versatile disc, a Blu-ray (registered trademark) disc), a smart card, a flash memory device (for example, a card, a stick, a key drive), a CD-ROM (Compact Disc-ROM), a register, a removable disk, a hard disk, a floppy (registered trademark) disk, a magnetic strip, a database, a server, or another suitable storage medium. In addition, the program may be transmitted from a network via a telecommunication line. Further, the program may be transmitted from the communication network NET via a telecommunication line.

[0392] (2) In the above-described embodiment, the information, signals, and the like described may be represented using any of various different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips and the like that may be referred to throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or photons, or any combination of these.

[0393] (3) In the above-described embodiment, input / output information and the like may be stored in a specific location (for example, a memory), or may be managed using a management table. The input / output information and the like can be overwritten, updated, or additionally recorded. The output information and the like may be deleted. The input information and the like may be transmitted to another device.

[0394] (4) In the embodiments described above, the determination may be made by a value represented using 1 bit (0 or 1), by a boolean value (true or false), or by a numerical comparison (for example, a comparison with a predetermined value).

[0395] (5) The processing procedures, sequences, flowcharts, etc., exemplified in the embodiments described above may be rearranged in order, as long as they do not contradict each other. For example, the methods described in this disclosure present various step elements using an exemplary order and are not limited to the specific order presented.

[0396] (6) Each function illustrated in Figures 2 and 3 is implemented by any combination of at least one of hardware and software. Furthermore, the method of implementing each function block is not particularly limited. That is, each function block may be implemented using one device that is physically or logically coupled, or it may be implemented using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wired or wireless connections). A function block may also be implemented by combining the one or more devices with software.

[0397] (7) The programs illustrated in the embodiments described above should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., whether they are called software, firmware, middleware, microcode, hardware description languages ​​or by other names.

[0398] Furthermore, software, instructions, information, etc., may be transmitted and received via a transmission medium. For example, if software is transmitted from a website, server, or other remote source using at least one of wired technology (such as coaxial cable, fiber optic cable, twisted pair, or digital subscriber line (DSL)) and wireless technology (such as infrared or microwave), then at least one of these wired and wireless technologies is included in the definition of a transmission medium.

[0399] (8) In each of the above-mentioned forms, the terms “system” and “network” shall be used interchangeably.

[0400] (9) The information, parameters, etc. described in this disclosure may be expressed using absolute values, relative values ​​from a given value, or other corresponding information.

[0401] (10) In the embodiments described above, the terminal device 1[q] may be a mobile station (MS). A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or several other appropriate terms. In this disclosure, terms such as “mobile station,” “user terminal,” “user equipment (UE),” and “terminal” may be used interchangeably.

[0402] (11) In the embodiments described above, the terms “connected,” “coupled,” or any variation thereof, mean any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are “connected” or “coupled” with each other. The coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination thereof. For example, “connection” may be reinterpreted as “access.” As used in this disclosure, two elements may be considered to be “connected” or “coupled” with each other using at least one of one or more wires, cables and printed electrical connections, and, in some non-limiting and non-exclusive examples, electromagnetic energy having wavelengths in the radio frequency domain, microwave domain and optical (both visible and invisible) domain.

[0403] (12) In the embodiments described above, the phrase “based on” does not mean “based solely on” unless otherwise specified. In other words, the phrase “based on” means both “based solely on” and “based at least on.”

[0404] (13) The terms “determining” and “determining” as used in this disclosure may encompass a wide variety of actions. “Determining” may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiry (e.g., searching in a table, database or other data structure), and ascertaining. “Determining” may also include, for example, receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, and accessing (e.g., accessing data in memory). Furthermore, "judgment" and "decision" can include considering something as having been "judged" or "decided" after resolving, selecting, choosing, establishing, comparing, etc. In other words, "judgment" and "decision" can include considering something as having been "judged" or "decided" after some action. Also, "judgment (decision)" can be reinterpreted as "assuming," "expecting," or "considering."

[0405] (14) Where the terms “include,” “including,” and variations thereof are used in the embodiments described above, these terms are intended to be inclusive, as is the term “comprising.” Furthermore, the term “or” as used in this disclosure is not intended to be exclusive OR.

[0406] (15) In the present disclosure, if articles are added by translation, such as a, an, and the in English, the present disclosure may include the fact that the noun following these articles is plural.

[0407] (16) In this disclosure, the term “A and B are different” may mean “A and B are different from each other.” The term may also mean “A and B are each different from C.” Terms such as “separate” and “combine” may be interpreted in the same way as “different.”

[0408] (17) Each aspect / embodiment described herein may be used individually, in combination, or switched between as needed in practice. Furthermore, notification of certain information (e.g., notification that "X is") is not limited to explicit notification, but may also be implicit (e.g., by not providing such notification).

[0409] Although the present disclosure has been described in detail above, it will be clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the intent and scope of the present disclosure as defined by the claims. Accordingly, the descriptions in the present disclosure are illustrative and not restrictive in any way. [Explanation of Symbols]

[0410] 1[q]...Terminal device, 3...Payment device, 5...Store device, 11...Control device, 12...Storage device, 13...Display device, 14...Input device, 15...Communication device, 31...Control device, 32...Storage device, 35...Communication device, 111...Information transmission unit, 112...Information acquisition unit, 113...Code generation unit, 114...Display control unit, 115...Communication status determination unit, 311...Information supply unit, 312...Information reception unit, 313...Payment processing unit.

Claims

1. An electronic payment program installed on a terminal capable of communicating with a payment device, The processor of the aforementioned terminal is When the terminal is able to communicate with the payment device, the acquisition unit acquires a first token from the payment device, When the acquisition unit acquires the first token, the display control unit causes the terminal's display device to display a first code image based on the first token. and make it work The display control unit, When the aforementioned electronic payment program is activated, regardless of the communication status of the terminal, The second code image based on the second token stored in the terminal's storage device is displayed on the display device. An electronic payment program characterized by the following features.

2. The display control unit, If the acquisition unit acquires the first token after the electronic payment program has been activated, The image to be displayed on the display device is switched from the second code image to the first code image based on the first token acquired by the acquisition unit. The electronic payment program according to claim 1, characterized in that...

3. The processor of the aforementioned terminal is The aforementioned terminal is further configured to function as a communication status determination unit for determining the communication status of the terminal. The display control unit, After the electronic payment program is started, and before the communication status determination unit outputs the result of determining the communication status of the terminal, The second code image is displayed on the display device. The electronic payment program according to claim 1, characterized in that...

4. The acquisition unit is, After the electronic payment program is started, and before the display control unit causes the second code image to be displayed on the display device, When communication between the terminal and the payment device is difficult, the payment device acquires offline blockage information indicating whether or not it can perform the offline payment process based on the second code image. The electronic payment program according to claim 1, characterized in that...

5. The acquisition unit is, After the electronic payment program has been activated and the display control unit has displayed the second code image on the display device, When communication between the terminal and the payment device is difficult, the payment device acquires offline blockage information indicating whether or not it can perform the offline payment process based on the second code image. The electronic payment program according to claim 1, characterized in that...

6. The acquisition unit is, During the period from when the electronic payment program is started until when the electronic payment program is terminated, The second token is obtained from the payment device, and the obtained second token is stored in the storage device. The electronic payment program according to claim 1, characterized in that...

7. The display control unit, If the acquisition unit acquires the first token after the electronic payment program has been activated, The image to be displayed on the display device is switched from the second code image to the first code image based on the first token acquired by the acquisition unit. The acquisition unit is, After the display control unit displays the first code image on the display device, during the period until the electronic payment program is terminated, The second token is obtained from the payment device, and the obtained second token is stored in the storage device. The electronic payment program according to claim 1, characterized in that...

8. The display control unit, When the acquisition unit acquires a specific notification regarding the user of the terminal from the payment device, The second code image displayed on the terminal's display device is changed to a hidden state. The electronic payment program according to claim 1, characterized in that...

9. A terminal capable of communicating with a payment device, When the terminal is able to communicate with the payment device, the acquisition unit acquires a first token from the payment device, When the acquisition unit acquires the first token, the display control unit causes the terminal's display device to display a first code image based on the first token. Equipped with, The display control unit, When the electronic payment program installed on the terminal is launched, regardless of the terminal's communication status, The second code image based on the second token stored in the terminal's storage device is displayed on the display device. A terminal characterized by the following features.

10. A payment system comprising a payment device and a terminal capable of communicating with the payment device, The aforementioned terminal is When the terminal is able to communicate with the payment device, the acquisition unit acquires a first token from the payment device, When the acquisition unit acquires the first token, the display control unit causes the terminal's display device to display a first code image based on the first token. Equipped with, The display control unit, When the electronic payment program installed on the terminal is launched, regardless of the terminal's communication status, The second code image based on the second token stored in the terminal's storage device is displayed on the display device. A payment system characterized by the following features.

Citation Information

Patent Citations

  • Payment server, payment control method, and program

    JP7391263B1