Payment system, terminal, and electronic payment program

By acquiring an online token and displaying an offline token-based code image upon launching, the system addresses long waiting times in conventional payment systems, ensuring quicker payment processing.

JP7723856B1Active Publication Date: 2025-08-14NTT DOCOMO INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025035281
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-08-14
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

Conventional electronic payment systems experience long waiting times from launching the payment program to displaying the code image due to the need for online token supply and communication status checks, which can be inconvenient for users.

Method used

The system acquires an online token when communication is possible and displays an offline token-based code image immediately upon launching the payment program, regardless of communication status, using a terminal device with an acquisition unit and display control unit.

Benefits of technology

This approach significantly reduces the time from launching the payment program to displaying the code image, enhancing user convenience by allowing immediate offline payment processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007723856000001_ABST
    Figure 0007723856000001_ABST
Patent Text Reader

Abstract

To shorten the waiting time from the start of an electronic payment program to the display of a code image. [Solution] A terminal device 1[q] capable of communicating with a payment device 3 includes an information acquisition unit 112 that acquires an online token KX[q] from the payment device 3 when the terminal device 1[q] is capable of communicating with the payment device 3, and a display control unit 114 that, when the information acquisition unit 112 acquires the online token KX[q], causes an online code image GX[q] based on the online token KX[q] to be displayed on a display device 13 of the terminal device 1[q]. When an electronic payment program PG-T is launched, the display control unit 114 causes the display device 13 to display an offline code image GY[q] based on the offline token KY[q] stored in a storage device 12 of the terminal device 1[q], regardless of the communication status of the terminal device 1[q].
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a payment system, a terminal, and an electronic payment program. [Background technology]

[0002] Technologies relating to electronic payments are becoming widespread, in which a terminal device (an example of a "terminal") such as a smartphone displays a code image based on a token supplied from a payment device, and the displayed code image is read by a store terminal such as a POS terminal installed in a store, etc. For example, Patent Document 1 discloses two types of technologies relating to electronic payments: online electronic payments that are executed by displaying an online code image (an example of a "first code image") on the terminal device based on an online token (an example of a "first token") supplied from the payment device when the terminal device and the payment device can communicate with each other; and offline electronic payments that are executed by displaying an offline code image (an example of a "second code image") on the terminal device based on an offline token (an example of a "second token") supplied in advance from the payment device and stored in the terminal device when communication between the terminal device and the payment device is difficult. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7391263 Summary of the Invention [Problem to be solved by the invention]

[0004] In conventional technology, after an electronic payment program installed on a terminal device is launched, the payment device supplies the terminal device with an online token in response to a request for an online token sent from the terminal device to the payment device. Therefore, according to conventional technology, even if the terminal device and the payment device can communicate with each other, it may take some time for the online token to be supplied after the electronic payment program is launched. Furthermore, according to conventional technology, if communication between the terminal device and the payment device is difficult, it may take some time for the terminal device to detect the communication status after the electronic payment program is launched. In these cases, the waiting time from the launch of the electronic payment program to the display of the code image is long, which may be inconvenient for the user of the terminal device.

[0005] The present invention was made in consideration of the above-mentioned circumstances, and one of the problems to be solved is to provide a technology that can increase the likelihood of shortening the waiting time from the launch of an electronic payment program to the display of a code image, compared to conventional technology. [Means for solving the problem]

[0006] In order to solve the above problems, the electronic payment program of the present invention is an electronic payment program installed on a terminal capable of communicating with a payment device, and causes the processor of the terminal to function as an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device, and a display control unit that, when the acquisition unit acquires the first token, displays a first code image based on the first token on a display device of the terminal, and is characterized in that, when the electronic payment program is launched, the display device displays a second code image based on a second token stored in a memory device of the terminal, regardless of the communication status of the terminal.

[0007] Furthermore, the terminal according to the present invention is a terminal capable of communicating with a payment device, and comprises an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device, and a display control unit that, when the acquisition unit acquires the first token, displays a first code image based on the first token on a display device of the terminal, wherein the display control unit, when an electronic payment program installed on the terminal is launched, displays a second code image based on a second token stored in a memory device of the terminal on the display device, regardless of the communication status of the terminal.

[0008] In addition, the payment system of the present invention is a payment system comprising a payment device and a terminal capable of communicating with the payment device, wherein the terminal comprises an acquisition unit that acquires a first token from the payment device when the terminal is capable of communicating with the payment device, and a display control unit that, when the acquisition unit acquires the first token, displays a first code image based on the first token on a display device of the terminal, and is characterized in that, when an electronic payment program installed on the terminal is launched, the display control unit displays a second code image based on a second token stored in a memory device of the terminal on the display device, regardless of the communication status of the terminal. [Effects of the Invention]

[0009] According to the present invention, it is highly likely that the period from the start of the electronic payment program to the display of the code image will be shorter than in the prior art. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a block diagram showing an example of the configuration of an electronic payment system Sys according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of a terminal device 1[q]. [Figure 3] FIG. 2 is a block diagram showing an example of the configuration of the payment device 3. [Figure 4] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 5] FIG. 10 is an explanatory diagram illustrating an example of token response information DSW[q]. [Figure 6] FIG. 10 is an explanatory diagram illustrating an example of token response information DSW[q]. [Figure 7] 10 is a flowchart showing an example of the operation of the electronic payment system Sys. [Figure 8] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 9] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 10] FIG. 10 is a schematic diagram showing an example of an offline code image display screen GGY. [Figure 11] FIG. 10 is a schematic diagram showing an example of a payment method selection screen GGS. [Figure 12] FIG. 10 is a schematic diagram showing an example of an online code image display screen GGX. [Figure 13] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 14] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 15] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 16] 1 is a sequence chart showing an example of the operation of the electronic payment system Sys. [Figure 17] 10 is a sequence chart showing an example of the operation of the electronic payment system according to the reference example. [Figure 18] FIG. 10 is a schematic diagram showing an example of the data configuration of a payment code CC[q]. [Figure 19] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 20] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 21] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 22]10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 23] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 24] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 25] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 26] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 27] 10 is a flowchart showing an example of the operation of the terminal device 1[q]. [Figure 28] 10 is a flowchart showing an example of the operation of the payment device 3. [Figure 29] 10 is a flowchart showing an example of the operation of the payment device 3. [Figure 30] 10 is a flowchart showing an example of the operation of the payment device 3. [Figure 31] 10 is a flowchart showing an example of the operation of the payment device 3. [Figure 32] 10 is a flowchart showing an example of the operation of the payment device 3. [Figure 33] 10 is a flowchart showing an example of the operation of the electronic payment system Sys according to the third modification of the present invention. [Figure 34] 10 is a sequence chart showing an example of the operation of the electronic payment system Sys according to the third modification of the present invention. [Figure 35] 10 is a sequence chart showing an example of the operation of the electronic payment system Sys according to the third modification of the present invention. [Figure 36] 10 is a flowchart showing an example of the operation of the electronic payment system Sys according to the fourth modification of the present invention. [Figure 37] 10 is a sequence chart showing an example of the operation of the electronic payment system Sys according to the fourth modification of the present invention. [Figure 38] 10 is a flowchart showing an example of the operation of the electronic payment system Sys according to the fifth modification of the present invention. [Figure 39]It is a sequence chart showing an example of the operation of the electronic payment system Sys according to Modification 6 of the present invention. [Figure 40] It is a sequence chart showing an example of the operation of the electronic payment system Sys according to Modification 9 of the present invention.

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. In each figure, the dimensions and scales of each part are appropriately different from the actual ones. Further, the embodiments described below are preferred specific examples of the present invention, and thus various technically preferable limitations are imposed. However, the scope of the present invention is not limited to these embodiments unless there is a description to particularly limit the present invention in the following description.

[0012] <A. Embodiment> Hereinafter, an embodiment of the present invention will be described.

[0013] <A.1. Overview of the Electronic Payment System Sys> While referring to FIGS. 1 to 3, an overview of the electronic payment system Sys will be described.

[0014] FIG. 1 is a block diagram showing an example of the configuration of the electronic payment system Sys.

[0015] As shown in FIG. 1, the electronic payment system Sys includes a payment device 3, a store device 5 that can communicate with the payment device 3 via a network NW, and one or more terminal devices 1 that can communicate with the payment device 3 via the network NW, and provides services related to electronic payment to the user U of the terminal device 1.

[0016] In this embodiment, as an example, it is assumed that the electronic payment system Sys includes multiple terminal devices 1. Specifically, in this embodiment, it is assumed that the electronic payment system Sys includes Q terminal devices 1. Here, the value Q is a natural number that satisfies "Q≧2". In addition, hereinafter, the qth terminal device 1 among the Q terminal devices 1 included in the electronic payment system Sys will be referred to as terminal device 1[q]. Here, the variable q is a natural number that satisfies "1≦q≦Q". In addition, in the following, a user U who uses terminal device 1[q] will be referred to as user U[q].

[0017] The terminal device 1[q] (an example of a "terminal") is, for example, a mobile terminal such as a smartphone or tablet terminal, and is carried by the user U[q]. In this embodiment, an electronic payment program PG-T is installed in the terminal device 1[q]. The terminal device 1[q] executes the electronic payment program PG-T to launch an electronic payment application (hereinafter, may be referred to as a "payment app"). When the user U[q] of the terminal device 1[q] receives a service at a store where the in-store device 5 is installed, the user U[q] of the terminal device 1[q] can pay for the service by electronic payment by using the payment app running on the terminal device 1[q] to display on the terminal device 1[q] a code image GG based on the token KK acquired from the payment device 3.

[0018] Hereinafter, the code image GG displayed on the terminal device 1[q] will be referred to as the code image GG[q]. The code image GG[q] is, for example, a barcode or a two-dimensional code. In this embodiment, as an example, it is assumed that the code image GG[q] is a barcode. Also, below, the token KK supplied from the payment device 3 to the terminal device 1[q] will be referred to as the token KK[q].

[0019] In this embodiment, it is assumed that the store where the in-store device 5 is installed is a physical store existing in real space, i.e., a brick-and-mortar store. Also, in this embodiment, it is assumed that the service provided at the store is the sale of goods or the provision of services. That is, in this embodiment, when a user U[q] of a terminal device 1[q] receives goods or services at a store where the in-store device 5 is installed, the user U[q] can pay for the goods or services by electronic payment.

[0020] The in-store device 5 is, for example, a point-of-sale (POS) cash register. When a user U[q] of a terminal device 1[q] electronically pays for a service provided by a store, the in-store device 5 reads a code image GG[q] displayed on the terminal device 1[q]. The in-store device 5 then generates payment information DP[q] by adding store payment information DF[q] to a payment code CC[q], which is a value indicated by the read code image GG[q], and provides the generated payment information DP[q] to the payment device 3. Here, the store payment information DF[q] includes, for example, store identification information for uniquely identifying the store that provided the service to the user U[q], the payment amount to be paid by the user U[q] as payment for the service provided to the user U[q], and the payment date and time, which is the date and time when the payment is made.

[0021] The payment device 3 executes payment processing based on the payment information DP[q] when it receives payment information DP[q] from the in-store device 5. Here, the payment processing is a process for confirming payment from the user U[q] of the terminal device 1[q] to the store as consideration for a service provided by the store when the user U[q] of the terminal device 1[q] receives the service from the store.

[0022] In this embodiment, as an example, it is assumed that the payment device 3 manages the usage fee for the terminal device 1[q] by the user U[q]. Here, the usage fee for the terminal device 1[q] includes, for example, the purchase price of the terminal device 1[q] and communication fees incurred when the terminal device 1[q] communicates. In this embodiment, the payment device 3 debits the usage fee for the terminal device 1[q] from the bank account of the user U[q] registered in advance with the payment device 3, for example, on the payment date of each month. Note that, hereinafter, the usage fee for the terminal device 1[q] may be referred to as "telephone fee." In addition, in this embodiment, as an example, it is assumed that the payment device 3 manages electronic money of a user U[q] that can be used at a terminal device 1[q]. In this embodiment, it is assumed that the electronic money managed by the payment device 3 is so-called prepaid electronic money, and that the user U[q] can use electronic money equivalent to the amount charged by charging the electronic money in advance. However, the present invention is not limited to this aspect. The electronic money managed by the payment device 3 may also be so-called postpaid electronic money that can be used up to a predetermined upper limit. In addition, in this embodiment, as an example, it is assumed that the payment apparatus 3 manages credit cards that user U[q] can use for electronic payments in the electronic payment system Sys. In this embodiment, it is assumed that the payment apparatus 3 can communicate with a credit card server operated by a credit card company, and that user U[q] can make payments using a credit card issued by the credit card company.

[0023] In this embodiment, the payment device 3 can perform payment processing for user U[q] of terminal device 1[q] using a payment method selected by user U[q] from three payment methods: combined telephone bill payment, prepaid balance payment, and credit card payment. Here, the telephone bill combined payment is a payment method in which the user U[q] pays the store by adding the telephone bill to the usage fee of the terminal device 1[q]. Also, the prepaid balance payment is a payment method in which the user U[q] pays the store using the electronic money of the user U[q] managed by the settlement device 3. Also, the credit card payment is a payment method in which the user U[q] pays the store using the credit card of the user U[q].

[0024] Furthermore, in this embodiment, as described above, the settlement device 3 pays out the token KK[q] in response to a request from the terminal device 1[q], and supplies the paid-out token KK[q] to the terminal device 1[q].

[0025] Below, we will explain an example of the operation of the electronic payment system Sys (hereinafter sometimes referred to as ``online electronic payment'') when the terminal device 1[q] and the payment device 3 are able to communicate and the electronic payment system Sys of this embodiment provides electronic payment services to the user U[q] of the terminal device 1[q]. First, when a user U[q] of terminal device 1[q] receives a service at a store where in-store device 5 is installed and pays for the service through online electronic payment, user U[q] operates terminal device 1[q] to launch a payment app on terminal device 1[q]. Next, when the payment app is launched, terminal device 1[q] requests a token KK[q] from the payment device 3. Next, in response to the request from terminal device 1[q], payment device 3 provides the token KK[q] to terminal device 1[q]. Next, terminal device 1[q] generates a payment code CC[q] based on the token KK[q] provided by the payment device 3, and displays a code image GG[q] representing the payment code CC[q]. Next, the in-store device 5 reads the code image GG[q] displayed on the terminal device 1[q] to generate payment information DP[q] including the payment code CC[q] indicated by the code image GG[q] and the store payment information DF[q], and supplies the payment information DP[q] to the payment device 3. Next, the payment device 3 executes a payment process based on the payment information DP[q] supplied from the in-store device 5, thereby finalizing the payment from the user U[q] to the store.

[0026] In the above-described online electronic payment, the payment device 3 issues a token KK[q] in response to a request from the terminal device 1[q]. Therefore, online electronic payment can be performed when the terminal device 1[q] and the payment device 3 can communicate with each other, but cannot be performed when communication between the terminal device 1[q] and the payment device 3 is difficult. Therefore, when communication between the terminal device 1[q] and the payment device 3 is difficult, the electronic payment system Sys according to this embodiment performs payment processing using payment information DP[q] generated based on the token KK[q] stored in the terminal device 1[q].

[0027] Below, we will explain an example of the operation of the electronic payment system Sys (hereinafter sometimes referred to as "offline electronic payment") when communication between the terminal device 1[q] and the payment device 3 is difficult and the electronic payment system Sys of this embodiment provides electronic payment services to the user U[q] of the terminal device 1[q]. First, when a user U[q] of a terminal device 1[q] receives a service at a store where a store device 5 is installed and pays for the service through offline electronic payment, the user U[q] operates the terminal device 1[q] to launch a payment app on the terminal device 1[q]. Next, when the payment app is launched, the terminal device 1[q] generates a payment code CC[q] based on the token KK[q] stored in the terminal device 1[q] and displays a code image GG[q] representing the payment code CC[q]. Next, the store device 5 reads the code image GG[q] displayed on the terminal device 1[q] to generate payment information DP[q] including the payment code CC[q] indicated by the code image GG[q] and store payment information DF[q], and provides the payment information DP[q] to the payment device 3. Next, the payment device 3 executes a payment process based on the payment information DP[q] provided by the store device 5, thereby finalizing the payment from the user U[q] to the store.

[0028] As described above, the electronic payment system Sys of this embodiment can perform two types of electronic payments: online electronic payment when the terminal device 1[q] and the payment device 3 can communicate, and offline electronic payment when communication between the terminal device 1[q] and the payment device 3 is difficult. Therefore, compared to a system in which only online electronic payment is possible, it can improve convenience for the user U[q] of the terminal device 1[q].

[0029] In the following, the token KK[q] that the terminal device 1 obtains from the payment device 3 in online electronic payment and that is used to generate the payment code CC[q] may be referred to as the online token KX[q] (an example of a "first token"), and the token KK[q] that is stored in the terminal device 1[q] in offline electronic payment and that is used to generate the payment code CC[q] may be referred to as the offline token KY[q] (an example of a "second token"). In addition, in the following, in online electronic payments, the payment code CC[q] generated by terminal device 1[q] from online token KX[q] may be referred to as online payment code CX[q], and in offline electronic payments, the payment code CC[q] generated by terminal device 1[q] from offline token KY[q] may be referred to as offline payment code CY[q]. In addition, in the following, in online electronic payments, the code image GG[q] displayed by the terminal device 1[q] based on the online payment code CX[q] may be referred to as the online code image GX[q] (an example of a "first code image"), and in offline electronic payments, the code image GG[q] displayed by the terminal device 1[q] based on the offline payment code CY[q] may be referred to as the offline code image GY[q] (an example of a "second code image"). In the following, the payment process executed by the payment device 3 in online electronic payment may be referred to as online payment process, and the payment process executed by the payment device 3 in offline electronic payment may be referred to as offline payment process.

[0030] In this embodiment, even when user U[q] of terminal device 1[q] pays by online electronic payment, if terminal device 1[q] stores offline token KY[q], after launching the payment app, terminal device 1[q] generates offline payment code CY[q] based on the offline token KY[q] stored in terminal device 1[q] and displays offline code image GY[q] representing the offline payment code CY[q], prior to displaying online code image GX[q] based on online token KX[q] supplied from payment device 3. Therefore, in this embodiment, even if it takes time from launching the payment app to displaying online code image GX[q], and therefore a long time is required before payment by online electronic payment, since offline code image GY[q] is displayed after launching the payment app and before displaying online code image GX[q], payment by offline electronic payment can be made quickly.

[0031] FIG. 2 is a block diagram showing an example of the configuration of the terminal device 1[q].

[0032] As shown in FIG. 2, the terminal device 1[q] includes a control device 11, a storage device 12, a display device 13, an input device 14, a communication device 15, and a bus 100 that interconnects these devices.

[0033] The storage device 12 is a recording medium readable by the control device 11. The storage device 12 includes, for example, a volatile memory such as a RAM (Random Access Memory) that functions as a work area for the control device 11, and a non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read-Only Memory) that stores various information, and stores user identification information DID[q], acquired offline token information KYY[q], offline blockage information DHY, a business operator identification token KZ, token response information DSW[q], setting information DS, and an electronic payment program PG-T.

[0034] The user identification information DID[q] is identification information for uniquely identifying the user U[q] of the terminal device 1[q] from among the Q users U[1] to U[Q] managed by the payment device 3.

[0035] The acquired offline token information KYY[q] is information including one or more offline tokens KY[q] acquired by the terminal device 1[q] from the payment device 3. In this embodiment, it is assumed that the terminal device 1[q] has acquired offline tokens KY[q] M times from the payment device 3 during the period from when the payment app was first launched (initial launch) on the terminal device 1[q] to the present. Here, the value M is a natural number that satisfies "M≧1". In the following, the offline token KY[q] acquired m times from the payment device 3, out of the M offline tokens KY[q] acquired by the terminal device 1[q] from the payment device 3, is referred to as offline token KY[q][m]. Here, the variable m is a natural number that satisfies "1≦m≦M".

[0036] In this embodiment, it is assumed that the acquired offline token information KYY[q] includes M records that correspond one-to-one to the M offline tokens KY[q][1] to KY[q][M] that the terminal device 1[q] acquired from the payment device 3. Of the M records included in the acquired offline token information KYY[q], the m-th record includes the offline token KY[q][m], offline token validity period information DTY[q][m], and an encryption key KS[q][m].

[0037] Here, the offline token validity period information DTY[q][m] indicates the period during which the offline token KY[q][m] can be used in offline electronic payments, i.e., the offline token validity period TY[q][m], which is the validity period of the offline token KY[q][m]. In this embodiment, it is assumed that the offline token validity period TY[q][m] is a period that starts from the time the offline token KY[q][m] is generated and ends when the offline token validity period TSY has elapsed since the time the offline token KY[q][m] was generated. Here, in this embodiment, as an example, it is assumed that the offline token validity period TSY is set to "one week." That is, in this embodiment, as an example, it is assumed that the validity period of the offline token KY[q] is one week.

[0038] The encryption key KS[q][m] is information used to generate the offline payment code CY[q] in offline electronic payment.

[0039] As described above, in this embodiment, it is assumed that the acquired offline token information KYY[q] includes M offline tokens KY[q][1] to KY[q][M] that the terminal device 1[q] has acquired from the payment device 3. However, the present invention is not limited to this aspect. The acquired offline token information KYY[q] only needs to include at least the offline token KY[q][M] that was acquired last among the M offline tokens KY[q][1] to KY[q][M] that the terminal device 1[q] has acquired from the payment device 3. For example, the terminal device 1[q] may delete an expired offline token KY[q][m] (specifically, an offline token KY[q][m] for which the end of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] has arrived) from among the M offline tokens KY[q][1] to KY[q][M] acquired from the payment apparatus 3. Specifically, if the end of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] included in the acquired offline token information KYY[q] stored in the storage device 12 is earlier than the current time (i.e., the offline token has expired), the terminal device 1[q] may delete from the acquired offline token information KYY[q] the offline token KY[q][m] corresponding to the offline token validity period TY[q][m] indicating the expiration (i.e., the expired offline token KY[q]). In this case, the acquired offline token information KYY[q] will include only offline tokens KY[q] that are within their expiration dates. Furthermore, for example, the terminal device 1[q] may delete offline tokens KY[q][1] to KY[q][M-1] other than the most recently acquired offline token KY[q][M] from among the M offline tokens KY[q][1] to KY[q][M] acquired from the payment device 3. Specifically, upon acquiring the latest offline token KY[q][M] from the payment device 3, the terminal device 1[q] may delete the offline token KY[q][M-1] acquired previously. In this case, the acquired offline token information KYY[q] will include only the latest offline token KY[q][M].

[0040] Furthermore, in this embodiment, it is assumed that the acquired offline token information KYY[q] includes M pieces of offline token validity period information DTY[q][1] to DTY[q][M] and M encryption keys KS[q][1] to KS[q][M]. However, the present invention is not limited to this aspect. The acquired offline token information KYY[q] only needs to include at least the offline token validity period information DTY[q][M] corresponding to the offline token KY[q][M] that was acquired last among the M pieces of offline token validity period information DTY[q][1] to DTY[q][M], and the encryption key KS[q][M] corresponding to the offline token KY[q][M] that was acquired last among the M encryption keys KS[q][1] to KS[q][M]. For example, the terminal device 1[q] may delete the encryption key KS[q][m] corresponding to the expired offline token KY[q][m] (specifically, the encryption key KS[q][m] corresponding to the offline token KY[q][m] for which the end point of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] has arrived) from among the M encryption keys KS[q][1] to KS[q][M] acquired from the payment apparatus 3. Specifically, if the end point of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] included in the acquired offline token information KYY[q] stored in the storage device 12 is a time in the past (i.e., if the offline token KY[q][m] has expired), the terminal device 1[q] may delete the encryption key KS[q][m] corresponding to the expired offline token KY[q][m] from the acquired offline token information KYY[q]. In this case, the acquired offline token information KYY[q] includes only the encryption key KS[q] corresponding to the offline token KY[q] that is within the expiration date. Furthermore, for example, the terminal device 1[q] may delete the encryption keys KS[q][1] to KS[q][M-1] other than the most recently acquired encryption key KS[q][M] from among the M encryption keys KS[q][1] to KS[q][M] acquired from the payment device 3. Specifically, upon acquiring the latest encryption key KS[q][M] from the payment device 3, the terminal device 1[q] may delete the encryption key KS[q][M-1] acquired previously. In this case, the acquired offline token information KYY[q] will include only the latest encryption key KS[q][M].

[0041] The offline blockage information DHY is information used to determine whether or not to display the offline code image GY[q] on the terminal device 1[q] in offline electronic payment. Specifically, the offline blockage information DHY is information indicating whether or not the payment device 3 is capable of executing offline payment processing. More specifically, the offline blockage information DHY may be information indicating whether or not the function of the payment device 3 for executing offline payment processing is operating without being blocked.

[0042] The business identification token KZ includes business identification information DKZ that identifies the payment business that manages the payment device 3.

[0043] The token response information DSW[q] indicates an online token response waiting time TSWX[q] and an offline token response waiting time TSWY[q].

[0044] The online token response waiting time TSWX[q] is the time length of the online token response waiting period TWX[q]. In this embodiment, the online token response waiting period TWX[q] is a waiting period for the terminal device 1[q] from when the terminal device 1[q] requests the online token KX[q] from the payment apparatus 3 until the online token KX[q] is provided to the terminal device 1[q]. However, the present invention is not limited to this aspect. The online token response waiting period TWX[q] may also be a waiting period for the terminal device 1[q] from when the payment app is launched in the terminal device 1[q] until the online token KX[q] is provided to the terminal device 1[q]. In this embodiment, the terminal device 1[q] waits for the online token KX[q] to be provided from the payment apparatus 3 during the online token response waiting period TWX[q]. Then, when the online token response waiting period TWX[q] ends, the terminal device 1[q] stops waiting for the online token KX[q] to be provided from the payment apparatus 3. In this embodiment, it is assumed that the online token response waiting time TSWX[q] is determined based on the performance of the terminal device 1[q].

[0045] The offline token response waiting time TSWY[q] is the time length of the offline token response waiting period TWY[q]. The offline token response waiting period TWY[q] is a waiting period for the terminal device 1[q] from when the terminal device 1[q] requests the offline token KY[q] from the payment apparatus 3 until the offline token KY[q] is provided to the terminal device 1[q]. However, the present invention is not limited to this aspect. The offline token response waiting period TWY[q] may also be a waiting period for the terminal device 1[q] from when the payment app is launched on the terminal device 1[q] until the offline token KY[q] is provided to the terminal device 1[q]. In this embodiment, the terminal device 1[q] waits for the supply of the offline token KY[q] from the payment apparatus 3 during the offline token response waiting period TWY[q]. Then, the terminal device 1[q] stops waiting for the supply of the offline token KY[q] from the payment apparatus 3 when the offline token response waiting period TWY[q] ends. In this embodiment, it is assumed that the offline token response waiting time TSWY[q] is determined based on the performance of the terminal device 1[q].

[0046] The setting information DS includes online token validity information DSX, offline token validity information DSY, and update time information DSC.

[0047] The online token validity information DSX indicates the length of time (hereinafter referred to as the "online token validity time TSX") during which the online token KX[q] can be used for online electronic payments (hereinafter referred to as the "online token validity time TX[q]"). In this embodiment, as an example, it is assumed that the online token validity time TSX is set to "5 minutes." However, the present invention is not limited to this aspect. The online token validity time TSX may be longer than the online token response waiting time TSWX[q]. Furthermore, in this embodiment, the online token validity period TX[q] is a period that starts from the time of generation of the online token KX[q] and ends when the online token validity time TSX has elapsed since the generation of the online token KX[q].

[0048] The offline token validity information DSY indicates the offline token validity time TSY. As described above, the offline token validity time TSY is the length of time of the offline token validity period TY[q][m] during which the offline token KY[q][m] can be used for offline electronic payments. Also, as described above, in this embodiment, as an example, it is assumed that the offline token validity time TSY is set to "one week." However, the present invention is not limited to this aspect. The offline token validity time TSY may be any time longer than the online token validity time TSX.

[0049] The update time information DSC is information indicating the update unit time TC. Here, the update unit time TC is the update cycle of the terminal time value AG based on the terminal time TG, which is the current time managed by the terminal device 1[q]. In this embodiment, as an example, it is assumed that the update unit time TC is set to "1 minute." Also, in this embodiment, as an example, it is assumed that the terminal time value AG is a value representing the terminal time TG in the order of "minutes." For example, in this embodiment, if the terminal time TG is "18:25:37," the terminal time value AG may be "1825," which is obtained by deleting "37 seconds" from the terminal time TG. However, the present invention is not limited to this aspect. The update unit time TC may be shorter than the offline token validity time TSY. Also, the update unit time TC may be shorter than the online token validity time TSX.

[0050] The control device 11 includes a processor. The processor provided in the control device 11 includes, for example, one or more central processing units (CPUs). However, the processor provided in the control device 11 may include hardware such as a graphics processing unit (GPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA) in addition to or in place of some or all of the one or more CPUs. The processor provided in the control device 11 executes an electronic payment program PG-T stored in the storage device 12 and operates in accordance with the electronic payment program PG-T, thereby functioning as an information transmission unit 111, an information acquisition unit 112, a code generation unit 113, a display control unit 114, and a communication status determination unit 115.

[0051] The information transmitting unit 111 transmits an online token request RX requesting an online token KX[q] to the payment apparatus 3 during an online token response waiting period TWX[q]. The online token request RX may include, for example, information requesting an online token KX and user identification information DID[q]. Furthermore, the information transmitting unit 111 transmits an offline token request RY requesting an offline token KY[q] to the payment apparatus 3 during an offline token response waiting period TWY[q]. The offline token request RY may include, for example, information requesting an offline token KY and user identification information DID[q]. Furthermore, the information transmitting unit 111 transmits terminal information DTM[q], which will be described later, to the payment apparatus 3. Furthermore, the information transmitting unit 111 transmits, to the payment apparatus 3, an online blockage information request BX requesting online blockage information DHX and an offline blockage information request BY requesting offline blockage information DHY. Here, the online blockage information DHX is information used to determine whether or not to display the online code image GX[q] on the terminal device 1[q] in online electronic payment. Specifically, the online blockage information DHX is information indicating whether or not the payment device 3 is capable of executing online payment processing. More specifically, the online blockage information DHX may be information indicating whether or not the function of the payment device 3 for executing online payment processing is operating without being blocked. Note that, hereinafter, the online blockage information DHX and the offline blockage information DHY may be collectively referred to as blockage information DH.

[0052] The information acquisition unit 112 is an example of an "acquisition unit" and acquires the online token KX[q], offline token KY[q], online blockage information DHX, offline blockage information DHY, token response information DSW[q], business operator identification token KZ, and setting information DS, which are supplied from the payment device 3 in response to a request from the terminal device 1[q]. The information acquisition unit 112 also acquires the offline token KY[q] stored in the storage device 12.

[0053] The code generation unit 113 generates an online payment code CX[q] based on the online token KX[q] acquired by the information acquisition unit 112. The code generation unit 113 also generates an offline payment code CY[q] based on the offline token KY[q] acquired by the information acquisition unit 112 and stored in the storage device 12.

[0054] In online electronic payments, the display control unit 114 causes the display device 13 to display an online code image GX[q] based on the online payment code CX[q] generated by the code generation unit 113. In offline electronic payments, the display control unit 114 causes the display device 13 to display an offline code image GY[q] based on the offline payment code CY[q] generated by the code generation unit 113.

[0055] The communication status determination unit 115 determines whether the communication status of the terminal device 1[q] is online. Specifically, the communication status determination unit 115 may determine whether the communication status of the terminal device 1[q] is online, for example, by using a communication status monitoring function of the terminal device 1[q] by the operating system of the terminal device 1[q]. Here, "the communication status of the terminal device 1[q] is online" may mean, for example, that the terminal device 1[q] is in a state where it can communicate with an external device located outside the terminal device 1[q], or that when the terminal device 1[q] performs wireless communication, the radio wave intensity related to the wireless communication is equal to or greater than a predetermined intensity.

[0056] The display device 13 is hardware for displaying various types of information. As the display device 13, various display panels such as a liquid crystal display panel and an organic EL display panel can be adopted. In this embodiment, the display device 13 displays various images such as an online code image GX[q] and an offline code image GY[q] under the control of the display control unit 114.

[0057] The input device 14 is hardware for receiving operations from a user U[q] of the terminal device 1[q]. The input device 14 may be, for example, a keyboard, a mouse, a microphone, a switch, a button, a sensor, or a combination of these devices. The display device 13 and the input device 14 may be configured as an integrated unit. In this case, the display device 13 and the input device 14 may be, for example, a touch panel.

[0058] The communication device 15 is hardware for communicating with an external device located outside the terminal device 1[q] via the network NW. In this embodiment, the information sending unit 111 sends various information to the payment device 3 via the communication device 15. The information acquiring unit 112 acquires various information from the payment device 3 via the communication device 15.

[0059] FIG. 3 is a block diagram showing an example of the configuration of the payment device 3. As shown in FIG.

[0060] As shown in FIG. 3, the payment device 3 includes a control device 31, a storage device 32, a communication device 35, and a bus 300 that interconnects these devices.

[0061] The storage device 32 is a recording medium readable by the control device 31. The storage device 32 is configured to include, for example, a volatile memory such as a RAM that functions as a work area for the control device 31, and a non-volatile memory such as an EEPROM that stores various information, and stores user management information DU, online token payout information DKX, offline token payout information DKY, business operator identification information DKZ, per-terminal token response information DW, payment management information DKP, setting information DS, and a control program PG-S.

[0062] The user management information DU has Q records that correspond one-to-one to the Q users U[1] to U[Q] managed by the payment device 3. Each record of the user management information DU includes, in addition to the above-mentioned user identification information DID[q], electronic money balance information DPR[q], telephone charge information DTL[q], credit card information DCR[q], point information DPT[q], and user payment information DSH[q].

[0063] The electronic money balance information DPR[q] is information indicating the balance of electronic money held by the user U[q]. The telephone charge information DTL[q] is information indicating the telephone charge to be paid by the user U[q] (that is, the usage charge for the terminal device 1[q]). The credit card information DCR[q] is information about a credit card owned by the user U[q] and registered by the user U[q] in the payment device 3 via the terminal device 1[q]. Specifically, the credit card information DCR[q] indicates, for example, the card number, expiration date, etc. of the credit card owned by the user U[q]. The point information DPT[q] is information about points granted to the user U[q] by the payment apparatus 3. In this embodiment, it is assumed that the payment apparatus 3 grants points to the user U[q], and the user U[q] can use electronic money in an amount equivalent to the granted points. The user payment information DSH[q] is information indicating the payment method selected by the user U[q].

[0064] The online token payout information DKX has one or more records that correspond one-to-one to one or more online tokens KX paid out by the payment device 3. Each record of the online token payout information DKX includes the online token KX[q] paid out by the payment device 3, the user identification information DID[q] of the user U[q] corresponding to the terminal device 1[q] to which the online token KX[q] is paid out, and information indicating the online token validity period TX[q] corresponding to the online token KX[q] (hereinafter referred to as "online token validity period information DTX[q]").

[0065] The settlement device 3 may delete a record of which the end point of the online token validity period TX[q] indicated by the online token validity period information DTX[q] has arrived, from among one or more records contained in the online token payout information DKX. Specifically, if the end point of the online token validity period TX[q] indicated by the online token validity period information DTX[q] is a time earlier than the current time (i.e., if the validity period has expired), the settlement device 3 may delete the online token KX[q] (i.e., the expired online token KX[q]) corresponding to the online token validity period information DTX[q] from among one or more online tokens KX included in the online token payout information DKX. In addition, when the payment device 3 issues multiple online tokens KX[q] corresponding to user U[q] in the online token payout information DKX, it may delete all of the records corresponding to the multiple online tokens KX[q] except for the record corresponding to the most recent online token KX[q] that was last paid out.

[0066] The offline token issuance information DKY has one or more records that correspond one-to-one to one or more offline tokens KY issued by the payment apparatus 3. Each record of the offline token issuance information DKY includes an offline token KY[q] issued by the payment apparatus 3, an encryption key KS[q] issued by the payment apparatus 3 in correspondence with the offline token KY[q], user identification information DID[q] of a user U[q] corresponding to the terminal apparatus 1[q] to which the offline token KY[q] is issued, and offline token validity period information DTY[q][m] indicating the offline token validity period TY[q][m] corresponding to the offline token KY[q].

[0067] Furthermore, the payment apparatus 3 may delete a record for which the end point of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] has arrived, from among one or more records held by the offline token issuance information DKY. Specifically, if the end point of the offline token validity period TY[q][m] indicated by the offline token validity period information DTY[q][m] is earlier than the current time (in other words, if the validity period has expired), the payment apparatus 3 may delete the offline token KY[q][m] corresponding to the offline token validity period information DTY[q][m] from among one or more offline tokens KY included in the offline token issuance information DKY (in other words, the expired offline token KY[q][m]), and may also delete the encryption key KS[q][m] corresponding to the offline token validity period information DTY[q][m] from among the multiple encryption keys KS included in the offline token issuance information DKY (in other words, the expired encryption key KS[q][m]). Furthermore, the payment apparatus 3 may delete, in the offline token issuance information DKY, from among the M records corresponding to the M offline tokens KY[q][1] to KY[q][M] issued to correspond to user U[q], records other than the record corresponding to the latest offline token KY[q][M]. In other words, the payment apparatus 3 may delete, in the offline token issuance information DKY, from among the M offline tokens KY[q][1] to KY[q][M] issued to correspond to user U[q], offline token KY[q] other than the last issued offline token KY[q][M]. Furthermore, the payment apparatus 3 may delete, in the offline token issuance information DKY, from among the M encryption keys KS[q][1] to KS[q][M] issued to correspond to user U[q], encryption key KS[q] other than the last issued encryption key KS[q][M].

[0068] The per-terminal token response information DW includes Q pieces of token response information DSW[1] to DSW[Q] that correspond one-to-one to the Q terminal devices 1[1] to 1[Q] provided in the electronic payment system Sys. As described above, the token response information DSW[q] issued corresponding to the terminal device 1[q] indicates an online token response waiting time TSWX[q] that specifies the time length of the online token response waiting period TWX[q], and an offline token response waiting time TSWY[q] that specifies the time length of the offline token response waiting period TWY[q].

[0069] The payment management information DKP has one or more records that correspond one-to-one to one or more electronic payments executed in the electronic payment system Sys. Each record of the payment management information DKP contains payment information DP[q] corresponding to each electronic payment.

[0070] The control device 31 is configured to include a processor. The processor provided in the control device 31 is configured to include, for example, one or more CPUs. However, the processor provided in the control device 31 may be configured to include hardware such as a GPU, DSP, ASIC, PLD, FPGA, etc. in addition to the one or more CPUs, or in place of some or all of the one or more CPUs. The processor provided in the control device 31 executes a control program PG-S stored in the storage device 32 and operates in accordance with the control program PG-S, thereby functioning as an information supply unit 311, an information acceptance unit 312, and a payment processing unit 313.

[0071] In response to a request from terminal device 1[q], the information supply unit 311 supplies online token KX[q], online blocking information DHX, offline token KY[q], offline blocking information DHY, token response information DSW[q], operator identification token KZ, and setting information DS to terminal device 1[q].

[0072] The information receiving unit 312 receives terminal information DTM[q], an online token request RX, an online blockage information request BX, an offline token request RY, and an offline blockage information request BY from the terminal device 1[q]. The information receiving unit 312 also receives payment information DP[q] from the in-store device 5.

[0073] The payment processing unit 313 executes payment processing based on the payment information DP[q]. Specifically, in online electronic payments, the payment processing unit 313 executes online payment processing based on the payment information DP[q], and in offline electronic payments, the payment processing unit 313 executes offline payment processing based on the payment information DP[q].

[0074] The communication device 35 is hardware for communicating with external devices such as the terminal device 1[q] and the store device 5 that exist outside the settlement device 3 via the network NW. In the present embodiment, the information supply unit 311 supplies various information to the terminal device 1[q] via the communication device 35. Further, the information reception unit 312 acquires various information from the terminal device 1[q] and the store device 5 via the communication device 35.

[0075] <A.2. Operations of the Electronic Payment System Sys> Hereinafter, the outline of the operation of the electronic payment system Sys will be described while referring to FIGS. 4 to 17.

[0076] <A.2.1. Operations of the Electronic Payment System Sys When the Payment Application is Launched for the First Time> FIG. 4 is a sequence chart showing an example of the operation of the electronic payment system Sys when the payment application in the terminal device 1[q] is launched for the first time.

[0077] As shown in FIG. 4, the control device 11 of the terminal device 1[q] launches the payment application by executing the electronic payment program PG-T based on the operation of the user U[q] (S1). In the sequence chart shown in FIG. 4, it is assumed that the launch of the payment application in the terminal device 1[q] is the first launch. For example, the control device 11 of the terminal device 1[q] may refer to the launch history (not shown) of the payment application stored in the storage device 12 to determine whether the launch of the payment application in the terminal device 1[q] is the first launch.

[0078] Next, the electronic payment system Sys executes the first launch process (S0).

[0079] Specifically, the communication state determination unit 115 of the terminal device 1[q] determines whether the communication state of the terminal device 1[q] is an online state in the first launch process (S01). In the sequence chart shown in FIG. 4, it is assumed that the communication state of the terminal device 1[q] is an online state.

[0080] Next, the information transmission unit 111 of the terminal device 1[q] transmits terminal information DTM[q] to the payment device 3 in the initial startup process (S02). Here, the terminal information DTM[q] is information related to the performance of the terminal device 1[q]. Note that in this embodiment, as an example, it is assumed that the terminal information DTM[q] indicates the memory capacity α of the terminal device 1[q]. Here, the memory capacity α is the capacity of a volatile memory such as a RAM in the storage device 12 of the terminal device 1[q].

[0081] Next, in the initial startup process, the control device 31 of the payment device 3 supplies token response information DSW[q] to the terminal device 1[q] in response to the terminal information DTM[q] supplied from the terminal device 1[q] in step S02 (S03). Specifically, in step S03, the information receiving unit 312 of the payment device 3 acquires terminal information DTM[q] provided from the terminal device 1[q]. Next, the control device 31 of the payment device 3 generates token response information DSW[q] based on the terminal information DTM[q]. Then, the information providing unit 311 of the payment device 3 provides the generated token response information DSW[q] to the terminal device 1[q].

[0082] FIG. 5 is an explanatory diagram illustrating an example of the relationship between terminal information DTM[q] and token response information DSW[q].

[0083] 5, in this embodiment, in step S03, if the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold value α0, the control device 31 determines the online token response waiting time TSWX[q] to be a value TKX1, and if the memory capacity α indicated by the terminal information DTM[q] is less than the threshold value α0, the control device 31 determines the online token response waiting time TSWX[q] to be a value TKX2 greater than the value TKX1. Note that in this embodiment, as an example, it is assumed that the value TKX1 is "5 seconds" and the value TKX2 is "10 seconds."

[0084] Furthermore, in this embodiment, in step S03, if the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold value α0, the control device 31 determines the offline token response waiting time TSWY[q] to be a value TKY1, and if the memory capacity α indicated by the terminal information DTM[q] is less than the threshold value α0, the control device 31 determines the offline token response waiting time TSWY[q] to be a value TKY2 greater than the value TKY1. Note that this embodiment assumes a case where the value TKY1 is smaller than the value TKX1, and the value TKY2 is smaller than the value TKX2. Specifically, this embodiment assumes, as an example, a case where the value TKY1 is "3 seconds" and the value TKY2 is "6 seconds."

[0085] In this embodiment, as an example, it is assumed that the terminal information DTM[q] indicates the memory capacity α of the terminal device 1[q], but the present invention is not limited to this aspect. The terminal information DTM[q] may indicate something other than the memory capacity α as long as it is information related to the performance of the terminal device 1[q]. For example, the terminal information DTM[q] may be information indicating the model name of the terminal device 1[q], information indicating the model number of the terminal device 1[q], or information indicating the type of processor that the terminal device 1[q] has.

[0086] FIG. 6 is an explanatory diagram illustrating another example of the relationship between the terminal information DTM[q] and the token response information DSW[q].

[0087] 6, it is assumed that the terminal information DTM[q] indicates the memory capacity α of the storage device 12 of the terminal device 1[q] as well as the processing speed β of the control device 11 of the terminal device 1[q]. Here, the processing speed β is the processing speed of a processor such as a CPU provided in the control device 11 of the terminal device 1[q].

[0088] In the example shown in FIG. 6, when the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is equal to or greater than the threshold β0, the control device 31 determines the online token response waiting time TSWX[q] to be a value TKX11, and when the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is less than the threshold β0, the control device 31 determines the online token response waiting time TSWX[q] to be a value T When the memory capacity α indicated by the terminal information DTM[q] is less than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is equal to or greater than the threshold β0, the online token response waiting time TSWX[q] is determined to be TKX21. When the memory capacity α indicated by the terminal information DTM[q] is less than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is less than the threshold β0, the online token response waiting time TSWX[q] is determined to be TKX22. Here, the value TKX12 is greater than the value TKX11, the value TKX21 is greater than the value TKX11, and the value TKX22 is greater than the value TKX21. Specifically, in the example shown in FIG. 6, it is assumed that the value TKX11 is "5 seconds", the value TKX12 is "8 seconds", the value TKX21 is "10 seconds", and the value TKX22 is "15 seconds".

[0089] Furthermore, in the example shown in FIG. 6, when the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is equal to or greater than the threshold β0, the control device 31 determines the offline token response waiting time TSWY[q] to be TKY11, and when the memory capacity α indicated by the terminal information DTM[q] is equal to or greater than the threshold α0 and the processing speed β indicated by the terminal information DTM[q] is less than the threshold β0, the control device 31 determines the offline token response waiting time TSWY[q] to be The offline token response waiting time TSWY[q] is determined to be the value TKY12, and when the memory capacity α indicated by the terminal information DTM[q] is less than the threshold value α0 and the processing speed β indicated by the terminal information DTM[q] is equal to or greater than the threshold value β0, the offline token response waiting time TSWY[q] is determined to be the value TKY21, and when the memory capacity α indicated by the terminal information DTM[q] is less than the threshold value α0 and the processing speed β indicated by the terminal information DTM[q] is less than the threshold value β0, the offline token response waiting time TSWY[q] is determined to be the value TKY22. Here, the value TKY12 is greater than the value TKY11, the value TKY21 is greater than the value TKY11, and the value TKY22 is greater than the value TKY21. 6, it is assumed that the value TKY11 is smaller than the value TKX11, the value TKY12 is smaller than the value TKX12, the value TKY21 is smaller than the value TKX21, and the value TKY22 is smaller than the value TKX22. Specifically, it is assumed that the value TKY11 is "3 seconds," the value TKY12 is "5 seconds," the value TKY21 is "6 seconds," and the value TKY22 is "9 seconds."

[0090] Returning to the explanation in Figure 4. 4, in the initial startup process, the information supply unit 311 of the payment device 3 supplies a business operator identification token KZ to the terminal device 1[q] in response to the terminal information DTM[q] supplied from the terminal device 1[q] in step S02 (S04). Specifically, in step S04, the information supply unit 311 first generates a business operator identification token KZ based on the business operator identification information DKZ stored in the storage device 32. Then, the information supply unit 311 supplies the generated business operator identification token KZ to the terminal device 1[q].

[0091] Furthermore, in the initial startup process, the information supply unit 311 of the payment apparatus 3 supplies setting information DS to the terminal apparatus 1[q] as a response to the terminal information DTM[q] supplied from the terminal apparatus 1[q] in step S02 (S05). Specifically, in step S05, the information supply unit 311 first acquires the setting information DS stored in the storage device 32. Then, the information supply unit 311 supplies the acquired setting information DS to the terminal apparatus 1[q].

[0092] In the present embodiment, as an example, in steps S03 to S05, the payment device 3 transmits the token response information DSW[q] to the terminal device 1[q], then transmits the carrier identification token KZ, and then transmits the setting information DS. However, the present invention is not limited to this example. The order in which the token response information DSW[q], carrier identification token KZ, and setting information DS are transmitted from the payment device 3 to the terminal device 1[q] is arbitrary. For example, the payment device 3 may transmit the token response information DSW[q], carrier identification token KZ, and setting information DS to the terminal device 1[q] simultaneously (for example, in the same message).

[0093] Next, in the initial startup process, the information acquisition unit 112 of the terminal device 1[q] acquires the token response information DSW[q] supplied from the payment device 3 in step S03, the operator identification token KZ supplied from the payment device 3 in step S04, and the setting information DS supplied from the payment device 3 in step S05, and stores the acquired token response information DSW[q], operator identification token KZ, and setting information DS in the memory device 12 (S06).

[0094] Next, the information transmitting unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 in the initial startup process (S07).

[0095] Then, in the initial startup process, the control device 31 of the payment device 3 supplies the terminal device 1[q] with an offline token KY[q] and an encryption key KS[q] in response to the offline token request RY supplied from the terminal device 1[q] in step S07 (S08). Specifically, in step S08, the control device 31 first generates an offline token KY[q] and an encryption key KS[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated offline token KY[q] and encryption key KS[q] to the terminal device 1[q].

[0096] Next, in the initial startup process, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] supplied from the payment device 3 in step S08, and stores the acquired offline token KY[q] and encryption key KS[q] in the storage device 12 (S09). Note that in step S09, the offline token KY[q] and encryption key KS[q] that the information acquisition unit 112 stores in the storage device 12 are the information acquired for the first time and are the latest information. That is, in step S09, the information acquisition unit 112 stores the offline token KY[q][1] (= offline token KY[q][M]) and encryption key KS[q][1] (= encryption key KS[q][M]) in the storage device 12.

[0097] <A.2.2. Operation of the Electronic Payment System Sys in the Normal System> Hereinafter, referring to FIGS. 7 to 12, an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys performs online electronic payment will be described. Here, the "normal operation of the electronic payment system Sys" means the operation of the electronic payment system Sys when the electronic payment system Sys performs electronic payment, and the terminal device 1[q] can obtain the offline token KY[q] from the storage device 12, and the terminal device 1[q] can obtain the online token KX[q] from the payment device 3.

[0098] FIG. 7 is a flowchart showing an example of the outline of the normal operation of the electronic payment system Sys when the electronic payment system Sys performs online electronic payment. The flowchart shown in FIG. 7 starts when the user U[q] of the terminal device 1[q] performs an operation to start the payment application. Also, in the flowchart shown in FIG. 7, it is assumed that the start of the payment application in the terminal device 1[q] is the second or later start.

[0099] As shown in FIG. 7, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] starts the payment application by executing the electronic payment program PG-T based on the operation of the user U[q] (S1).

[0100] Next, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] executes an offline code image display process (S2). Here, the offline code image display process is a process in which, in the terminal device 1[q], after the payment application is started and before the online code image GX[q] is displayed, an offline payment code CY[q] is generated based on the offline token KY[q][M] stored in the storage device 12 of the terminal device 1[q], and an offline code image GY[q] representing the generated offline payment code CY[q] is displayed on the display device 13.

[0101] Next, the electronic payment system Sys executes a payment-related process (S3). Here, the payment-related process includes a process of supplying payment information DP[q] from the in-store device 5 to the payment device 3, a process of determining the validity of the token KK[q] included in the payment information DP[q] supplied from the in-store device 5 in the payment device 3, and a payment process executed in the payment device 3 based on the payment information DP[q] whose validity has been confirmed.

[0102] Next, the electronic payment system Sys executes an online code image display process (S4). Here, the online code image display process includes a process in which the terminal device 1[q] acquires an online token KX[q] from the payment device 3, a process in which the terminal device 1[q] generates an online payment code CX[q] based on the acquired online token KX[q], and a process in which the display device 13 displays an online code image GX[q] representing the generated online payment code CX[q].

[0103] Next, the electronic payment system Sys executes an offline token acquisition process (S5). Here, the offline token acquisition process is a process in which the terminal device 1[q] acquires an offline token KY[q] from the payment device 3.

[0104] 8 and 9 are sequence charts showing an example of normal operation of the electronic payment system Sys when the electronic payment system Sys executes online electronic payment. Below, the processing of steps S1 to S5 explained in the flowchart of FIG. 7 will be explained in detail with reference to FIGS. 8 and 9.

[0105] As shown in FIG. 8, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] executes the electronic payment program PG-T based on the operation of the user U[q], thereby launching the payment application (S1).

[0106] Next, the electronic payment system Sys executes the offline code image display process described above (S2).

[0107] More specifically, in the offline code image display process of step S2, the information acquisition unit 112 of the terminal device 1[q] first determines whether the offline token KY[q][M] stored in the storage device 12 is a valid offline token KY (S21). Specifically, in step S21, the information acquisition unit 112 determines whether the storage device 12 stores one or more offline tokens KY[q][1] to KY[q][M] and whether the latest offline token KY[q][M] among the one or more offline tokens KY[q][m] is an offline token KY within its expiration date. For example, in step S21, the information acquisition unit 112 may determine whether the end point of the offline token validity period TY[q][M] corresponding to the offline token KY[q][M] is later than the current time. Note that the sequence charts shown in FIGS. 8 and 9 assume that the offline token KY[q][M] stored in the storage device 12 is valid.

[0108] Next, in the offline code image display process of step S2, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q][M] and the encryption key KS[q][M] from the storage device 12 (S22).

[0109] Next, in the offline code image display process of step S2, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on the offline token KY[q][M] and the encryption key KS[q][M] acquired in step S22 (S23).

[0110] Then, in the offline code image display process of step S2, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display an offline code image display screen GGY including the offline code image GY[q] based on the offline payment code CY[q] generated in step S23 (S24).

[0111] Then, the user U[q] of the terminal device 1[q] holds the offline code image GY[q] displayed on the display device 13 of the terminal device 1[q] over the barcode reader provided in the in-store device 5. In this case, the in-store device 5 executes a process to read the offline code image GY[q] displayed on the display device 13 of the terminal device 1[q] (S25).

[0112] FIG. 10 is a schematic diagram showing an example of the offline code image display screen GGY including the offline code image GY[q].

[0113] As shown in FIG. 10, the offline code image display screen GGY includes an offline code image GY[q], a payment method display area A1, and a point use selection button B1.

[0114] As described above, the offline code image GY[q] is a barcode for representing the offline payment code CY[q]. In this embodiment, as an example, it is assumed that a two-dimensional code for representing the offline payment code CY[q] is also displayed as the offline code image GY[q] on the offline code image display screen GGY.

[0115] The point use selection button B1 is a button for selecting whether or not to use points granted to the user U[q] in offline electronic payment. Although not shown in the sequence charts in Figures 8 and 9, in this embodiment, as an example, it is assumed that when the user U[q] changes whether or not to use points using the point use selection button B1 on the offline code image display screen GGY, the change is notified from the terminal device 1[q] to the payment device 3.

[0116] The payment method display area A1 displays the payment method of user U[q] when user U[q] uses electronic payment in the electronic payment system Sys. Specifically, the display control unit 114 displays the payment method of user U[q] in the payment method display area A1 based on the user payment information DSH[q]. Note that, although not shown in the sequence charts shown in FIGS. 8 and 9, this embodiment assumes, as an example, that the user payment information DSH[q] is stored in the storage device 12 of terminal device 1[q]. However, the present invention is not limited to this configuration. For example, the payment device 3 may provide the user payment information DSH[q] to terminal device 1[q] in response to a request from terminal device 1[q]. The payment method of user U[q] displayed in the payment method display area A1 can be changed on the payment method selection screen GGS, which will be described below.

[0117] FIG. 11 is a schematic diagram showing an example of the payment method selection screen GGS.

[0118] 11, the payment method selection screen GGS has three radio buttons RB including a radio button RB1 for selecting combined telephone bill payment as the payment method for electronic payment, a radio button RB2 for selecting prepaid balance payment as the payment method for electronic payment, and a radio button RB3 for selecting credit card payment as the payment method for electronic payment, a decision button BS1 for determining the payment method for electronic payment, and a credit registration button BS2 for displaying a screen (not shown) for registering credit card information DCR[q] on the display device 13. By selecting any one of the three radio buttons RB on the payment method selection screen GGS and then pressing the decision button BS1, the user U[q] can select the payment method corresponding to the selected radio button RB as the payment method for user U[q] when electronic payment is executed in the electronic payment system Sys.

[0119] Returning to the explanation of FIG. As shown in FIG. 8, the electronic payment system Sys executes the payment-related processing described above (S3).

[0120] More specifically, in the payment-related processing of step S3, the in-store device 5 generates store payment information DF[q] (store identification information, payment amount, payment date and time) based on the service content provided to user U[q] by the store where the in-store device 5 is installed, and generates payment information DP[q] (S31) that includes the generated store payment information DF[q] and the offline payment code CY[q] indicated by the offline code image GY[q] read from terminal device 1[q] in step S25. If the code image GG[q] read by the store device 5 before the start of step S3 is an online code image GX[q], the store device 5 generates payment information DP[q] in step S31, which includes the online payment code CX[q] indicated by the online code image GX[q] and store payment information DF[q].

[0121] Next, in the payment-related process of step S3, the in-store device 5 transmits the payment information DP[q] generated in step S31 to the payment device 3 (S32).

[0122] Next, in the payment-related processing of step S3, the payment processing unit 313 of the payment device 3 determines the validity of the offline token KY[q] included in the offline payment code CY[q] based on the offline payment code CY[q] included in the payment information DP[q] provided from the in-store device 5 in step S32 (S33). Specifically, in step S33, the payment processing unit 313 determines whether the offline token KY[q] included in the payment information DP[q] provided from the in-store device 5 in step S32 is stored in the storage device 32 and whether the offline token KY[q] is within its expiration date. For example, in step S33, the payment processing unit 313 may determine whether the end point of the offline token validity period TY[q] corresponding to the offline token KY[q] is later than the current time. Note that the sequence charts shown in FIGS. 8 and 9 assume that the offline token KY[q] is valid. If the token KK[q] included in the payment information DP[q] supplied from the in-store device 5 in step S32 is the online token KX[q], the in-store device 5 determines the validity of the online token KX[q] in step S33.

[0123] Thereafter, the payment processing unit 313 of the payment device 3 executes the payment process in the payment-related process of step S3 (S34). Then, the information supply unit 311 of the settlement device 3 transmits a register charge response indicating the result of the settlement process in step S34 to the in-store device 5 (S35).

[0124] Thereafter, as shown in FIG. 9, the electronic payment system Sys executes the above-mentioned online code image display process (S4).

[0125] More specifically, in the online code image display process of step S4, the communication status determination unit 115 of the terminal device 1[q] determines whether the communication status of the terminal device 1[q] is online (S41). Note that the sequence charts shown in Figures 8 and 9 assume that the communication status of the terminal device 1[q] is online.

[0126] Next, in the online code image display process of step S4, the information transmission unit 111 of the terminal device 1[q] transmits an online blockage information request BX to the payment device 3 (S42). Here, the online blockage information request BX is a message requesting online blockage information DHX.

[0127] Next, in the online code image display process of step S4, the control device 31 of the payment device 3 supplies online blockage information DHX to the terminal device 1[q] as a response to the online blockage information request BX supplied from the terminal device 1[q] in step S42 (S43). Specifically, in step S43, the control device 31 first determines whether the online payment process in the payment device 3 can be executed, and generates online blockage information DHX indicating the result of the determination. Then, the information supply unit 311 of the control device 31 supplies the generated online blockage information DHX to the terminal device 1[q].

[0128] Next, the information transmission unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 in the online code image display process of step S4 (S44). Here, the online token request RX is a message requesting the online token KX[q].

[0129] Then, in the online code image display process of step S4, the control device 31 of the payment device 3 supplies the online token KX[q] to the terminal device 1[q] as a response to the online token request RX supplied from the terminal device 1[q] in step S44 (S45). Specifically, in step S45, the control device 31 first generates the online token KX[q] and online token validity period information DTX[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated online token KX[q] to the terminal device 1[q].

[0130] In the present embodiment, as an example, the case has been described in which the terminal device 1[q] transmits an online blockage information request BX to the payment device 3 in step S42, and then transmits an online token request RX to the payment device 3 in step S44, but the present invention is not limited to this form. The terminal device 1[q] may transmit an online blockage information request BX to the payment device 3 after transmitting an online token request RX to the payment device 3. Furthermore, the terminal device 1[q] may transmit the online token request RX and the online blockage information request BX to the payment device 3 simultaneously (for example, in the same message).

[0131] Next, in the online code image display process of step S4, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of the online payment process in the payment device 3 is in a blocked state, based on the online blockage information DHX acquired by the information acquisition unit 112 in step S43 (S46). Note that the sequence charts shown in FIGS. 8 and 9 assume that the execution function of the online payment process in the payment device 3 is not in a blocked state, that is, that the payment device 3 is able to execute the online payment process. Hereinafter, the state in which the execution function of the online payment process in the payment device 3 is in a blocked state may be referred to as an "online blocked state." Also, below, the state in which the execution function of the offline payment process in the payment device 3 is in a blocked state may be referred to as an "offline blocked state."

[0132] Next, in the online code image display process of step S4, the code generation unit 113 of the terminal device 1[q] generates an online payment code CX[q] based on the online token KX[q] acquired by the information acquisition unit 112 in step S45 (S47). Specifically, in step S47, the code generation unit 113 generates an online payment code CX[q] including the online token KX[q].

[0133] Thereafter, in the online code image display processing of step S4, the display control unit 114 of the terminal device 1[q] generates display information for displaying the online code image GX[q] representing the online payment code CX[q] based on the online payment code CX[q] generated by the code generation unit 113 in step S47, and causes the display device 13 to display the online code image display screen GGX including the online code image GX[q] based on the generated display information (S48).

[0134] In this embodiment, when the display control unit 114 displays the offline code image GY[q] on the display device 13 of the terminal device 1[q] in step S24, the display control unit 114 maintains the offline code image GY[q] displayed on the display device 13 until the display device 13 of the terminal device 1[q] displays the online code image GX[q] in step S48.

[0135] Then, the in-store device 5 performs a process of reading the online code image GX[q] displayed on the display device 13 of the terminal device 1[q] using a barcode reader or the like provided in the in-store device 5 (S49).

[0136] FIG. 12 is a schematic diagram showing an example of the online code image display screen GGX.

[0137] As shown in FIG. 12, the online code image display screen GGX includes an online code image GX[q], a payment method display area A2, and a point use selection button B2.

[0138] As described above, the online code image GX[q] is a barcode representing the online payment code CX[q]. However, the present invention is not limited to this. The online code image GX[q] may be, for example, a two-dimensional code representing the online payment code CX[q]. In the payment method display area A2, similar to the payment method display area A1, the payment method of the user U[q] when the user U[q] uses electronic payment in the electronic payment system Sys is displayed. Like the point use selection button B1, the point use selection button B2 is a button for displaying the current selection status of user U[q] as to whether or not to use the points granted to user U[q] in online electronic payment.

[0139] Returning to the explanation of Figure 9. As shown in FIG. 9, the electronic payment system Sys executes the offline token acquisition process described above (S5).

[0140] Next, in the offline token acquisition process of step S5, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S51). Here, the offline token request RY is a message requesting an offline token KY[q].

[0141] Then, in the offline token acquisition process of step S5, the control device 31 of the payment device 3 supplies the terminal device 1[q] with an offline token KY[q] and an encryption key KS[q] in response to the offline token request RY supplied from the terminal device 1[q] in step S51 (S52). Specifically, in step S52, the control device 31 first generates the offline token KY[q], encryption key KS[q], and offline token validity period information DTY[q] corresponding to the user U[q] of the terminal device 1[q]. Then, the information supply unit 311 of the control device 31 supplies the generated offline token KY[q] and encryption key KS[q] to the terminal device 1[q].

[0142] Next, in the offline token acquisition process of step S5, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] supplied from the payment device 3 in step S52, and stores the acquired offline token KY[q] and encryption key KS[q] in the storage device 12 (S53). Note that since the acquisition of the offline token KY[q] in step S53 is the Mth acquisition (latest acquisition), the information acquisition unit 112 adds the offline token KY[q] acquired in step S53 to the acquired offline token information KYY[q] as the offline token KY[q][M], and adds the encryption key KS[q] acquired in step S53 to the acquired offline token information KYY[q] as the encryption key KS[q][M].

[0143] As described above, when online electronic payment is executed, the terminal device 1[q] according to this embodiment causes the display device 13 to display the offline code image GY[q] during the period from the activation of the payment application until the online code image GX[q] is displayed on the display device 13. Therefore, according to this embodiment, compared with the mode in which the offline code image GY[q] is not displayed after the activation of the payment application, the waiting time for the user U[q] of the terminal device 1[q] to receive the service provision of electronic payment can be shortened.

[0144] Also, when online electronic payment is executed, the terminal device 1[q] according to this embodiment causes the display device 13 to display the offline code image GY[q] regardless of the communication state of the terminal device 1[q] before the execution of the process of step S41 for checking the communication state of the terminal device 1[q]. Therefore, according to this embodiment, compared with the mode in which the offline code image GY[q] is displayed after checking the communication state of the terminal device 1[q] after the activation of the payment application, the waiting time for the user U[q] of the terminal device 1[q] to receive the service provision of electronic payment can be shortened.

[0145] <A.2.3. Operation of the Electronic Payment System Sys Other than the Normal System> Hereinafter, an example of the operation of the electronic payment system Sys other than the normal system when the electronic payment system Sys executes electronic payment will be described while referring to FIGS. 13 to 16.

[0146] FIG. 13 is a sequence chart showing an example of the operation of the electronic payment system Sys other than the normal system when the electronic payment system Sys executes electronic payment. In FIG. 13, it is assumed that the electronic payment system Sys cannot execute the normal operation because the valid offline token KY is not stored in the storage device 12.

[0147] As shown in FIG. 13, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] activates the payment application (S1).

[0148] Next, the electronic payment system Sys executes offline code image display processing (S2).

[0149] Specifically, in the offline code image display process of step S2, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token KY[q][M] stored in the storage device 12 is a valid offline token KY (S21). Note that, as described above, Fig. 13 assumes the case where a valid offline token KY is not stored in the storage device 12. Then, in the offline code image display process of step S2, if the result of the determination in step S21 is negative, i.e., if a valid offline token KY is not stored in the storage device 12, the information acquisition unit 112 of the terminal device 1[q] displays a standby screen (S26) and terminates the offline code image display process of step S2. Here, the standby screen (not shown) is a screen for informing the user U[q] that the terminal device 1[q] is scheduled to acquire the online token KX[q] but has not yet acquired the online token KX[q] and to wait for the terminal device 1[q] to acquire the online token KX[q]. Note that, in the present embodiment, an example is described in which the terminal device 1[q] displays a standby screen and terminates the offline code image display process when the result of the determination in step S21 is negative, but the present invention is not limited to such an example. If the result of the determination in step S21 is negative, the terminal device 1[q] may end the offline code image display process without displaying the standby screen.

[0150] Next, the electronic payment system Sys executes the online code image display process (S4) described above. Specifically, the electronic payment system Sys executes the processes of steps S41 to S49 described above as the online code image display process of step S4. As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the online code image GX[q] (S48).

[0151] Next, the electronic payment system Sys executes the above-mentioned payment-related process (S3). Specifically, the electronic payment system Sys executes the above-mentioned steps S31 to S35 as the payment-related process of step S3. Thereafter, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown). Specifically, the electronic payment system Sys executes the processes of steps S51 to S53 described above as the offline token acquisition process of step S5.

[0152] Thus, according to this embodiment, even if the electronic payment system Sys cannot perform normal operation because a valid offline token KY is not stored in the storage device 12, the online code image GX[q] can be displayed on the display device 13 of the terminal device 1[q] based on the online token KX[q] acquired from the payment device 3. Therefore, according to this embodiment, even if a valid offline token KY is not stored in the storage device 12, the user U[q] of the terminal device 1[q] can receive electronic payment services.

[0153] Fig. 14 is a sequence chart showing an example of non-normal operation of the electronic payment system Sys when the electronic payment system Sys executes an electronic payment. In Fig. 14, it is assumed that the electronic payment system Sys cannot execute normal operation because the communication state of the terminal device 1[q] is offline.

[0154] As shown in FIG. 14, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] starts up the payment application (S1).

[0155] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, the electronic payment system Sys executes the processes of steps S21 to S25 described above as the offline code image display process of step S2. As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24).

[0156] Next, the electronic payment system Sys executes the above-mentioned payment-related process (S3). Specifically, the electronic payment system Sys executes the above-mentioned processes of steps S31 to S35 as the payment-related process of step S3 (some of which are not shown).

[0157] Thereafter, the electronic payment system Sys executes an online code image display process (S4). Specifically, in the online code image display process of step S4, the communication state determination unit 115 of the terminal device 1[q] determines whether the communication state of the terminal device 1[q] is online (S41). Note that, as described above, in Fig. 14, it is assumed that the communication state of the terminal device 1[q] is offline. Then, if the result of the determination in step S41 is negative, that is, if the communication state of the terminal device 1[q] is offline, the control device 11 of the terminal device 1[q] ends the online code image display process of step S4.

[0158] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the display control unit 114 of the terminal device 1[q] executes the processing of step S24 described above in the offline code image display processing of step S2, thereby causing the display device 13 to display the offline code image GY[q]. More specifically, after the payment app is launched, the display control unit 114 first causes the display device 13 to display the offline code image GY[q] by the processing of step S24, and then maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the processing of step S4 is executed and the processing of step S2 is executed again.

[0159] Thus, according to this embodiment, even if the electronic payment system Sys cannot perform normal operations because the communication state of the terminal device 1[q] is offline, the offline code image GY[q] can be displayed on the display device 13 of the terminal device 1[q] based on the offline token KY[q][M] obtained from the storage device 12. Therefore, according to this embodiment, even if the communication state of the terminal device 1[q] is offline, the user U[q] of the terminal device 1[q] can receive electronic payment services.

[0160] Fig. 15 is a sequence chart showing an example of non-normal operation of the electronic payment system Sys when the electronic payment system Sys executes electronic payment. Note that Fig. 15 assumes that the electronic payment system Sys cannot execute normal operation due to the payment device 3 being in an online blocked state.

[0161] As shown in FIG. 15, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] starts up the payment application (S1).

[0162] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, the electronic payment system Sys executes the processes of steps S21 to S25 described above as the offline code image display process of step S2 (some parts are not shown). As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24).

[0163] Thereafter, the electronic payment system Sys executes the online code image display process (S4). Specifically, the electronic payment system Sys executes the processes of steps S41 to S46 described above as the online code image display process of step S4. In step S46, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of the online payment process in the payment device 3 is in a blocked state, based on the online blockage information DHX acquired by the information acquisition unit 112 in step S43. Note that, as described above, FIG. 15 assumes that the payment device 3 is in an online blocked state. Then, if the result of the determination in step S46 is positive, that is, if the payment device 3 is in an online blocked state, the control device 11 of the terminal device 1[q] ends the online code image display process in step S4.

[0164] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the display control unit 114 of the terminal device 1[q] executes the processing of step S24 described above in the offline code image display processing of step S2, thereby causing the display device 13 to display the offline code image GY[q]. More specifically, after the payment app is launched, the display control unit 114 first causes the display device 13 to display the offline code image GY[q] by the processing of step S24, and then maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the processing of step S4 is executed and the processing of step S2 is executed again.

[0165] Next, the electronic payment system Sys executes the above-mentioned payment-related processing (S3). Specifically, the electronic payment system Sys executes the processing of steps S31 to S35 described above as the payment-related processing of step S3 (some of which are not shown). Thereafter, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown). Specifically, the electronic payment system Sys executes the processes of steps S51 to S53 described above as the offline token acquisition process of step S5.

[0166] Thus, according to this embodiment, even if the electronic payment system Sys cannot perform normal operations due to the payment device 3 being in an online blocked state, the offline code image GY[q] can be displayed on the display device 13 of the terminal device 1[q] based on the offline token KY[q][M] obtained from the storage device 12. Therefore, according to this embodiment, even if the payment device 3 is in an online blocked state, the user U[q] of the terminal device 1[q] can receive electronic payment services.

[0167] Fig. 16 is a sequence chart showing an example of non-normal operation of the electronic payment system Sys when the electronic payment system Sys executes electronic payment. In Fig. 16, it is assumed that the electronic payment system Sys cannot execute normal operation because the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3.

[0168] As shown in FIG. 16, in the electronic payment system Sys, the control device 11 of the terminal device 1[q] starts up the payment application (S1).

[0169] Next, the electronic payment system Sys executes the offline code image display process (S2) described above. Specifically, the electronic payment system Sys executes the processes of steps S21 to S25 described above as the offline code image display process of step S2 (some parts are not shown). As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24).

[0170] Thereafter, the electronic payment system Sys executes the online code image display process (S4). Specifically, as the online code image display process of step S4, the electronic payment system Sys first executes the processes of steps S41, S42, and S44 described above. Then, in the online code image display process of step S4, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the online token KX[q] has been supplied from the payment device 3 before the online token response waiting period TWX[q] ends (S91). Note that, as described above, in FIG. 16, it is assumed that, in step S44, the terminal device 1[q] transmits an online token request RX to the payment device 3, but there is no response from the payment device 3 to the online token request RX, and the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3. Then, if the result of the determination in step S91 is negative, that is, if the online token KX[q] has not been supplied during the online token response waiting period TWX[q], the control device 11 of the terminal device 1[q] terminates the online code image display process of step S4.

[0171] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] by executing the process of step S24 in the offline code image display process of step S2. More specifically, after the settlement application is launched, the display control unit 114 first causes the display device 13 to display the offline code image GY[q] by the process of step S24, and then maintains the state in which the offline code image GY[q] is displayed on the display device 13 until the process of step S4 is executed and the process of step S2 is executed again.

[0172] Next, the electronic payment system Sys executes the above-described payment-related process (S3). Specifically, as the payment-related process of step S3, the electronic payment system Sys executes the processes of steps S31 to S35 described above (some are omitted in the figure). Thereafter, the electronic payment system Sys executes the above-described offline token acquisition process (S5) (omitted in the figure). Specifically, as the offline token acquisition process of step S5, the electronic payment system Sys executes the processes of steps S51 to S53 described above.

[0173] Thus, according to the present embodiment, even when the electronic payment system Sys cannot execute the normal operation because the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3, the offline code image GY[q] can be displayed on the display device 13 of the terminal device 1[q] based on the offline token KY[q][M] acquired from the storage device 12. Therefore, according to the present embodiment, even when the terminal device 1[q] cannot acquire the online token KX[q] from the payment device 3, the user U[q] of the terminal device 1[q] can receive the provision of the electronic payment service.

[0174] <Operation of the Electronic Payment System According to Reference Example A.2.4> Hereinafter, in order to clarify the effects of the present embodiment, an electronic payment system according to a reference example will be described.

[0175] 17 is a sequence chart showing an example of the operation of the electronic payment system according to the reference example when the electronic payment system according to the reference example performs online electronic payment. Note that, like the electronic payment system Sys according to this embodiment, the electronic payment system according to the reference example also includes a terminal device 1[q], a payment device 3, and a store device 5.

[0176] As shown in FIG. 17, when the electronic payment system according to the reference example executes online electronic payment, the terminal device 1[q] in the electronic payment system according to the reference example starts up a payment application (S1). Next, the electronic payment system according to the reference example executes the online code image display process described above (S4). Specifically, the electronic payment system according to the reference example executes the processes of steps S41 to S49 described above as the online code image display process of step S4. As a result, the display control unit 114 of the terminal device 1[q] provided in the electronic payment system according to the reference example causes the display device 13 to display the online code image GX[q] (S48). Next, the electronic payment system according to the reference example executes the payment-related processing described above (S3). Thereafter, the electronic payment system according to the reference example executes the offline token acquisition process described above (S5).

[0177] Thus, in the electronic payment system according to the reference example, during the period from when the payment app is launched until when the online code image GX[q] is displayed on the display device 13 of the terminal device 1[q], the code image GG[q] is not displayed on the display device 13. Furthermore, in the electronic payment system according to the reference example, during the period from when the payment app is launched until when the online code image GX[q] is displayed on the display device 13 of the terminal device 1[q], the processing of steps S41 to S47 must be executed. Therefore, in the electronic payment system according to the reference example, the period from when the payment app is launched until when the online code image GX[q] is displayed is long. In other words, in the electronic payment system according to the reference example, the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service is long.

[0178] In contrast, according to the electronic payment system Sys according to the present embodiment, when an online electronic payment is executed, after the payment application is launched, the offline code image GY[q] is displayed on the display device 13 during the period until the online code image GX[q] is displayed on the display device 13. Therefore, according to the present embodiment, compared with the electronic payment system according to the reference example, the waiting time for the user U[q] of the terminal device 1[q] to receive the service provision of the electronic payment can be shortened.

[0179] <Summary of the operation of the electronic payment system Sys> As described above, in the present embodiment, when an online electronic payment is executed in the electronic payment system Sys, after the payment application is launched, the offline code image GY[q] is displayed on the display device 13 during the period until the online code image GX[q] is displayed on the display device 13. Therefore, according to the present embodiment, compared with the mode in which the offline code image GY[q] is not displayed after the payment application is launched, the waiting time for the user U[q] of the terminal device 1[q] to receive the service provision of the electronic payment after launching the payment application can be shortened.

[0180] Further, in the present embodiment, the electronic payment system Sys executes an offline electronic payment when it is difficult to perform an online electronic payment, such as when the communication state of the terminal device 1[q] is in an offline state, when the terminal device 1[q] fails to obtain the online token KX[q] from the payment device 3, and when the payment device 3 is in an online congestion state. Therefore, for example, compared with the mode in which the electronic payment system can only execute an online electronic payment, when the user U[q] of the terminal device 1[q] receives a service at a store where the store device 5 is installed, the possibility of paying the price of the service by electronic payment can be increased. Thereby, according to the present embodiment, it is possible to reduce the decrease in convenience related to the payment of the user U[q] who has received the service at the store where the store device 5 is installed.

[0181] Furthermore, in this embodiment, when the payment app is launched on the terminal device 1[q] (see step S1) and electronic payment is executed, the terminal device 1[q] acquires the online token KX[q] (see step S45) and also acquires the offline token KY[q] (see step S52) from the payment device 3. That is, in this embodiment, the terminal device 1[q] acquires the offline token KY[q] from the payment device 3 when the terminal device 1[q] and the payment device 3 communicate with each other for electronic payment. Therefore, according to this embodiment, it is possible to reduce the number of processes other than electronic payment in the terminal device 1[q] compared to a case where the terminal device 1[q] acquires the offline token KY[q] from the payment device 3 at a timing unrelated to the timing of electronic payment, such as a predetermined timing. As a result, according to this embodiment, it is possible to reduce the complexity of scheduling processes in the terminal device 1[q] compared to a case where the terminal device 1[q] acquires the offline token KY[q] from the payment device 3 at a timing unrelated to the timing of electronic payment.

[0182] Furthermore, in this embodiment, when electronic payment is made, the terminal device 1[q] stores the offline token KY[q] acquired from the payment device 3 in the storage device 12. Therefore, according to this embodiment, when online electronic payment is difficult due to poor communication or the like, it is possible to reduce the possibility that offline electronic payment will also become difficult to perform.

[0183] Furthermore, in this embodiment, the terminal device 1[q] displays the online code image GX[q] on the display device 13 when the online blockage information DHX indicates that the payment device 3 is not in an online blockage state. That is, in this embodiment, the terminal device 1[q] suppresses the display of the online code image GX[q] on the display device 13 when the online blockage information DHX indicates that the payment device 3 is in an online blockage state. In other words, according to this embodiment, the display of the online code image GX[q] on the terminal device 1[q] can be suppressed when it is difficult to perform online electronic payment. Therefore, according to this embodiment, the effort required by the user U[q] to display the online code image GX[q] can be reduced compared to, for example, an embodiment in which the online code image GX[q] is displayed without considering the online blockage information DHX.

[0184] Furthermore, in this embodiment, the length of the online token response waiting period TWX[q] during which the terminal device 1[q] waits for the supply of the online token KX[q] from the payment device 3, i.e., the online token response waiting time TSWX[q], is determined based on the performance of the terminal device 1[q]. That is, in this embodiment, the online token response waiting time TSWX[q] is adjusted according to the performance of the terminal device 1[q]. Therefore, according to this embodiment, compared to an embodiment in which the length of the online token response waiting period TWX[q] is fixed, even when the terminal device 1[q] has low performance, the terminal device 1[q] is more likely to be able to acquire the online token KX[q]. That is, according to this embodiment, compared to an embodiment in which the length of the online token response waiting period TWX[q] is fixed, the terminal device 1[q] is more likely to be able to execute an online electronic payment that displays the online code image GX[q] on the terminal device 1[q].

[0185] In the present embodiment, the payment device 3 supplies the setting information DS to the terminal device 1[q] when the payment app is first launched on the terminal device 1[q]. However, the present invention is not limited to this. For example, when the setting information DS is changed, the payment device 3 may supply the changed setting information DS to the terminal device 1[q]. Specifically, when the setting information DS is changed and a payment app launch notification (not shown) indicating that the payment app has been launched on the terminal device 1[q] is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the changed setting information DS to the terminal device 1[q] in response to the payment app launch notification. Furthermore, when a payment app launch notification is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the setting information DS to the terminal device 1[q] regardless of whether the setting information DS has been changed.

[0186] Furthermore, in the present embodiment, an example has been described in which the payment device 3 provides the terminal device 1[q] with a carrier identification token KZ when the payment app is first launched on the terminal device 1[q]. However, the present invention is not limited to this example. For example, if the carrier identification information DKZ is changed, the payment device 3 may provide the terminal device 1[q] with a carrier identification token KZ indicating the changed carrier identification information DKZ. Specifically, if the carrier identification information DKZ is changed and the terminal device 1[q] provides the payment device 3 with a payment app launch notification, the payment device 3 may provide the terminal device 1[q] with a carrier identification token KZ based on the changed carrier identification information DKZ in response to the payment app launch notification. In this case, the terminal device 1[q] acquires the carrier identification token KZ less frequently than the online token KX[q]. In this case, the terminal device 1[q] acquires the carrier identification token KZ less frequently than the offline token KY[q]. In addition, for example, when a payment app launch notification is supplied from terminal device 1[q] to payment device 3, payment device 3 may supply a business operator identification token KZ to terminal device 1[q] regardless of whether the business operator identification information DKZ has changed.

[0187] In addition, in this embodiment, an example is given of a mode in which token response information DSW[q] is supplied from the payment device 3 to the terminal device 1[q] when the payment application is first launched in the terminal device 1[q]. However, the present invention is not limited to such a mode. For example, the payment device 3 may supply the terminal device 1[q] with the changed token response information DSW[q] when the token response information DSW[q] is changed. Specifically, when the token response information DSW[q] is changed and a payment application launch notification is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the terminal device 1[q] with the changed token response information DSW[q] as a response to the payment application launch notification. Further, for example, when a payment application launch notification is supplied from the terminal device 1[q] to the payment device 3, the payment device 3 may supply the terminal device 1[q] with the token response information DSW[q] regardless of whether the token response information DSW[q] has been changed.

[0188] <A.3. Outline of the payment code CC[q]> Hereinafter, the outline of the payment code CC[q] (online payment code CX[q] and offline payment code CY[q]) will be described with reference to FIG. 18.

[0189] FIG. 18 is a diagram showing an example of the data configuration of the online payment code CX[q] and the offline payment code CY[q].

[0190] As shown in FIG. 18, the online payment code CX[q] includes a merchant identification token KZ, an online token KX[q], an appropriation value VJ, and a code type value VV. The offline payment code CY[q] includes a merchant identification token KZ, an offline token KY[q], a time encryption code TT[q][n], an appropriation value VJ, and a code type value VV.

[0191] The operator identification token KZ is LZ-digit data composed of LZ code values VZ[1] to VZ[LZ]. Here, the value LZ is a natural number satisfying "LZ ≥ 2". Also, in this embodiment, it is assumed that each code value VZ is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VZ may be 1-digit data composed of a 1-digit alphanumeric character (a 1-digit number or one alphabet).

[0192] The online token KX[q] is LX-digit data composed of LX code values VX[1] to VX[LX]. Here, the value LX is a natural number satisfying "LX ≥ 4". Also, in this embodiment, it is assumed that each code value VX is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VX may be 1-digit data composed of a 1-digit alphanumeric character (a 1-digit number or one alphabet).

[0193] The offline token KY[q] is LY-digit data composed of LY code values VY[1] to VY[LY]. Here, the value LY is a natural number satisfying "LY ≥ 2" and "LY < LX". Also, in this embodiment, it is assumed that each code value VY is 1-digit data composed of a 1-digit number (0 to 9). However, the code value VY may be 1-digit data composed of a 1-digit alphanumeric character (a 1-digit number or one alphabet).

[0194] The time encryption code TT[q] is LT-digit data consisting of LT code values VT[1] to VT[LT]. Here, the value LT is a natural number that satisfies "LT≧2" and "LT+LY=LX." That is, in this embodiment, the sum of the number of digits LY of the offline token KY[q] and the number of digits LT of the time encryption code TT[q][n] is equal to the number of digits LX of the online token KX[q]. Also, in this embodiment, it is assumed that each code value VT is one-digit data consisting of one digit number (0 to 9). However, the code value VT may also be one-digit data consisting of one alphanumeric character (one digit number or one alphabet).

[0195] The allocation value VJ is one-digit data consisting of a single-digit number (0 to 9). However, the allocation value VJ may be a one-bit value, a number of two or more digits, or an alphanumeric character of one or more digits.

[0196] The code type value VV is one-digit data consisting of a single digit (0-9). However, the code type value VV may be a one-bit value, a number of two or more digits, or an alphanumeric character of one or more digits. A value indicating the type of payment code CC[q] is set in the code type value VV. Specifically, if the payment code CC[q] is an online payment code CX[q], a value indicating that the payment code CC[q] is the online payment code CX[q], such as "1," is set in the code type value VV. Hereinafter, a value indicating that the payment code CC[q] is the online payment code CX[q] is referred to as the "online code value." Furthermore, if the payment code CC[q] is an offline payment code CY[q], a value indicating that the payment code CC[q] is the offline payment code CY[q], such as "2," is set in the code type value VV. Hereinafter, a value indicating that the payment code CC[q] is the offline payment code CY[q] is referred to as the "offline code value."

[0197] The following describes the process by which the code generation unit 113 generates a payment code CC[q] (hereinafter referred to as the "code generation process"). Note that, hereinafter, the process by the code generation unit 113 to generate an online payment code CX[q] is referred to as the "online code generation process." Also, hereinafter, the process by the code generation unit 113 to generate an offline payment code CY[q] is referred to as the "offline code generation process."

[0198] In the online code generation process, the code generation unit 113 sets an online code value (for example, "1") for the code type value VV. Then, the code generation unit 113 generates an online payment code CX[q] by arranging, in a predetermined order, the business identification token KZ stored in the storage device 12, the online token KX[q] acquired by the information acquisition unit 112 from the payment device 3, the allocation value VJ, and the code type value VV.

[0199] In the offline code generation process, the code generation unit 113 generates a terminal time value AG based on the terminal time TG managed by the terminal device 1[q]. Specifically, the code generation unit 113 deletes the portion representing "seconds" from the terminal time TG and leaves the portions representing "minutes" and "hours" to generate the terminal time value AG. Next, in the offline code generation process, the code generation unit 113 generates a time encryption code TT[q] by encrypting the terminal time value AG using the encryption key KS[q][M] corresponding to the offline token KY[q][M] that was last acquired among the M encryption keys KS[q][1] to KS[q][M] stored in the storage device 12. That is, in this embodiment, it is assumed that the time encryption code TT[q] is a value obtained by encrypting the terminal time value AG using the encryption key KS[q][M]. Furthermore, in the offline code generation process, the code generation unit 113 sets an offline code value (for example, "2") for the code type value VV. Then, in the offline code generation process, the code generation unit 113 generates the offline payment code CY[q] by arranging in a predetermined order the business identification token KZ stored in the storage device 12, the offline token KY[q] acquired by the information acquisition unit 112 from the payment device 3, the time encryption code TT[q] generated by the code generation unit 113, the allocation value VJ, and the code type value VV. In this embodiment, it is assumed that the number of digits of the online payment code CX[q] is equal to the number of digits of the offline payment code CY[q].

[0200] As described above, in this embodiment, the code generation unit 113 updates the terminal time value AG at a period of the update unit time TC. Specifically, in this embodiment, the code generation unit 113 updates the terminal time value AG every minute. When the terminal time value AG is updated, the code generation unit 113 updates the time encryption code TT[q] with a value obtained by encrypting the updated terminal time value AG with the encryption key KS[q][M], and updates the offline payment code CY[q] with the updated time encryption code TT[q]. Specifically, the updated offline payment code CY[q] is generated by arranging the business identification token KZ, the offline token KY[q], the updated time encryption code TT[q], the allocation value VJ, and the code type value VV in a predetermined order.

[0201] Hereinafter, among the time encryption codes TT[q], the time encryption code TT[q] that has been updated (n+1) times may be referred to as the time encryption code TT[q][n]. That is, hereinafter, the time encryption code TT[q] that has never been updated may be referred to as the time encryption code TT[q][1], and the time encryption code TT[q] that has been updated once may be referred to as the time encryption code TT[q][2]. Here, the variable n is a natural number that satisfies "1≦n".

[0202] Thus, in this embodiment, the offline settlement code CY[q] includes, in addition to the offline token KY[q] that is updated every offline token valid time TSY (for example, one week), a time encryption code TT[q] that is updated every update unit time TC (for example, one minute), which is a time shorter than the offline token valid time TSY. That is, in this embodiment, the offline settlement code CY[q] is updated every update unit time TC, which is the update period of the time encryption code TT[q]. Therefore, according to this embodiment, compared with the mode in which the offline settlement code CY[q] is configured without including the time encryption code TT[q], the security risk associated with the leakage of the offline settlement code CY[q] can be reduced.

[0203] Also, in this embodiment, the offline settlement code CY[q] includes, in addition to the offline token KY[q], a merchant identification token KZ obtained at a timing different from that of the offline token KY[q]. Therefore, according to this embodiment, compared with the mode in which the offline settlement code CY[q] is configured without including the merchant identification token KZ, the security risk associated with the leakage of the offline settlement code CY[q] can be reduced. Similarly, in this embodiment, the online settlement code CX[q] includes, in addition to the online token KX[q], a merchant identification token KZ obtained at a timing different from that of the online token KX[q]. Therefore, according to this embodiment, compared with the mode in which the online settlement code CX[q] is configured without including the merchant identification token KZ, the security risk associated with the leakage of the online settlement code CX[q] can be reduced.

[0204] <A.4. Operation of Terminal Device 1[q]> Hereinafter, referring to FIGS. 19 to 27, an outline of the operation of the terminal device 1[q] when electronic settlement is executed will be described.

[0205] 19 to 27 are flowcharts showing an example of the operation of the terminal device 1[q] when electronic payment is executed in the electronic payment system Sys. The flowcharts shown in Fig. 19 to 27 start when a user U[q] of the terminal device 1[q] launches a payment app.

[0206] 19, when a user U[q] of a terminal device 1[q] performs an operation to launch a payment application, the control device 11 of the terminal device 1[q] launches the payment application (S101). The process of step S101 corresponds to the process of step S1 described above. Next, the control device 11 of the terminal device 1[q] determines whether the activation of the payment app on the terminal device 1[q] is the first activation of the payment app on the terminal device 1[q] (S103). If the result of the determination in step S103 is negative, that is, if the activation of the payment application in terminal device 1[q] is the second or subsequent activation, control device 11 of terminal device 1[q] proceeds to step S201.

[0207] If the result of the determination in step S103 is positive, i.e., if the launch of the payment app on the terminal device 1[q] is the first launch, the control device 11 of the terminal device 1[q] determines whether the communication state of the terminal device 1[q] is online (S105) and waits until the communication state of the terminal device 1[q] becomes online (S105: Y). The processing of step S105 corresponds to the processing of step S01 described above. Note that, if the terminal device 1[q] maintains the offline state (S105: N) for a predetermined time or more in step S105, the display control unit 114 of the terminal device 1[q] may, for example, display an error screen on the display device 13.

[0208] If the result of the judgment in step S105 is positive, that is, if the communication status of the terminal device 1[q] is online, the control device 11 of the terminal device 1[q] identifies the memory capacity α of the terminal device 1[q] and generates terminal information DTM[q] indicating the identified memory capacity α (S107). Next, the information transmitting unit 111 of the terminal device 1[q] transmits the terminal information DTM[q] generated in step S107 to the settlement device 3 (S109). Note that the process of step S109 corresponds to the process of step S02 described above. Next, the control device 11 of the terminal device 1[q] determines whether or not there is a response from the payment device 3 (S111), and waits until there is a response from the payment device 3 (S111: Y). Note that, in step S111, if there is no response from the payment device 3 (S111: N) continues for a predetermined time or longer, the display control unit 114 of the terminal device 1[q] may, for example, cause the display device 13 to display an error screen.

[0209] If the result of the judgment in step S111 is positive, that is, if there is a response from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the token response information DSW[q] supplied from the payment device 3 (S113). If the result of the determination in step S111 is positive, the information acquisition unit 112 of the terminal device 1[q] acquires the business identification token KZ supplied from the payment device 3 (S115). If the result of the determination in step S111 is positive, the information acquisition unit 112 of the terminal device 1[q] acquires the setting information DS supplied from the payment device 3 (S117). Then, the information acquisition unit 112 of the terminal device 1[q] stores the token response information DSW[q] acquired in step S113, the carrier identification token KZ acquired in step S115, and the setting information DS acquired in step S117 in the storage device 12 (S119), and proceeds to step S121. The process of step S119 corresponds to the process of step S06 described above.

[0210] 20, the information transmitting unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S121). The process of step S121 corresponds to the process of step S07 described above.

[0211] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token KY[q] and the encryption key KS[q] have been supplied from the payment apparatus 3 in response to the offline token request RY (S123), and waits until the online token KX[q] and the encryption key KS[q] are supplied (S123:Y). Note that, if the state in which the online token KX[q] and the encryption key KS[q] are not supplied from the payment apparatus 3 (S123:N) continues even after the end of the offline token response waiting period TWY[q] that starts when the offline token request RY is sent, the information acquisition unit 112 of the terminal device 1[q] may, for example, display an error screen on the display device 13.

[0212] Next, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and encryption key KS[q] supplied from the settlement device 3 in step S123 (S125).

[0213] Then, the information acquisition unit 112 of the terminal device 1[q] stores the offline token KY[q] and encryption key KS[q] acquired in step S125 in the storage device 12 (S127). Specifically, in step S127, the information acquisition unit 112 adds the offline token KY[q] acquired in step S125 to the acquired offline token information KYY[q] as the latest offline token KY[q][M], and also adds the encryption key KS[q] acquired in step S125 to the acquired offline token information KYY[q] as the latest encryption key KS[q][M]. Note that the processing of step S127 corresponds to the processing of step S09 described above. Thereafter, the control device 11 of the terminal device 1[q] ends the processing shown in the flowcharts of FIGS. 19 to 27.

[0214] 21, if the result of the determination in step S103 is negative, that is, if the launch of the payment app on terminal device 1[q] is the second or subsequent launch, the information acquisition unit 112 of terminal device 1[q] determines whether a valid offline token KY[q][M] is stored in the storage device 12 of terminal device 1[q] (S201). The process of step S201 corresponds to the process of step S21 described above. If the result of the judgment in step S201 is negative, that is, if a valid offline token KY[q][M] is not stored in the memory device 12 of the terminal device 1[q], the control device 11 of the terminal device 1[q] proceeds to step S301.

[0215] If the result of the determination in step S201 is positive, that is, if a valid offline token KY[q][M] is stored in the storage device 12 of the terminal device 1[q], the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q][M] and the encryption key KS[q][M] from the storage device 12 (S203). The processing of step S203 corresponds to the processing of step S22 described above.

[0216] Next, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on the offline token KY[q][M] and the encryption key KS[q][M] acquired in step S203 (S205). The process of step S205 corresponds to the process of step S23 described above.

[0217] Next, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display an offline code image display screen GGY including the offline code image GY[q] based on the offline payment code CY[q] generated in step S205 (S207). The process of step S207 corresponds to the process of step S24 described above.

[0218] Then, the control device 11 of the terminal device 1[q] determines whether the user U[q] has performed an operation to terminate the payment application (hereinafter referred to as the "termination operation") using the input device 14 (S209). If the result of the determination in step S209 is positive, that is, if an end operation has been performed, the control device 11 of the terminal device 1[q] advances the process to step S501. If the result of the determination in step S209 is negative, that is, if the termination operation has not been performed, the control device 11 of the terminal device 1[q] advances the process to step S301.

[0219] 22, if the result of the determination in step S201 is negative, i.e., if a valid offline token KY[q][M] is not stored in the storage device 12 of the terminal device 1[q], or if the result of the determination in step S209 is negative, i.e., if an end operation has not been performed after the offline code image GY[q] is displayed on the display device 13, the communication status determination unit 115 of the terminal device 1[q] determines whether the communication status of the terminal device 1[q] is online (S301). The processing in step S301 corresponds to the processing in step S41 described above.

[0220] If the result of the determination in step S301 is negative, that is, if the communication state of the terminal device 1[q] is offline, the control device 11 of the terminal device 1[q] advances the process to step S407. If the result of the determination in step S301 is positive, that is, if the communication state of the terminal device 1[q] is online, the information sending unit 111 of the terminal device 1[q] sends an online blockage information request BX to the payment device 3 (S303). The process of step S303 corresponds to the process of step S42 described above.

[0221] Next, the information acquisition unit 112 of the terminal device 1[q] determines whether or not online blockage information DHX has been supplied from the settlement device 3 in response to the online blockage information request BX (S305). If the result of the determination in step S305 is negative, that is, if the online blockage information DHX is not supplied from the settlement apparatus 3, the information acquisition unit 112 of the terminal apparatus 1[q] advances the process to step S309. If the result of the determination in step S305 is positive, that is, if the online blockage information DHX is supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the online blockage information DHX (S307).

[0222] Next, the information transmitting unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S309). The process of step S309 corresponds to the process of step S44 described above.

[0223] Next, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the online token KX[q] has been provided from the settlement apparatus 3 in response to the online token request RX (S311). If the result of the judgment in step S311 is positive, i.e., if the online token KX[q] is supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the online token KX[q] (S313) and proceeds to step S317. If the result of the determination in step S311 is negative, that is, if the online token KX[q] is not supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the online token response waiting period TWX[q] has ended (S315). Note that, in the flowcharts of Figures 19 to 27, as an example, it is assumed that the online token response waiting period TWX[q] is a period starting from the time when the information transmission unit 111 transmits the online token request RX in step S309.

[0224] If the result of the determination in step S315 is negative, that is, if the online token response waiting period TWX[q] has not expired, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S309. If the result of the determination in step S315 is positive, that is, if the online token response waiting period TWX[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S317.

[0225] Next, the code generation unit 113 of the terminal device 1[q] determines whether or not the execution function of the online payment process in the payment apparatus 3 is in a blocked state, based on the online blockage information DHX acquired by the information acquisition unit 112 in step S307 (S317). Specifically, the code generation unit 113 determines whether or not the following conditions are satisfied: the information acquisition unit 112 has acquired the online blockage information DHX in step S307, and the online blockage information DHX indicates that the payment apparatus 3 is not in an online blockage state. The processing of step S317 corresponds to the processing of step S46 described above.

[0226] If the result of the judgment in step S317 is negative, that is, if the information acquisition unit 112 has not acquired the online blockage information DHX in step S307, or if the online blockage information DHX indicates that the payment device 3 is in an online blockage state, the control device 11 of the terminal device 1[q] proceeds to step S401.

[0227] If the result of the judgment in step S317 is positive, that is, if the condition that the information acquisition unit 112 has acquired the online blockage information DHX in step S307 and the online blockage information DHX indicates that the payment device 3 is not in an online blockage state is satisfied, the control device 11 of the terminal device 1[q] judges whether the information acquisition unit 112 has acquired the online token KX[q] in step S313 (S319).

[0228] If the result of the determination in step S319 is positive, that is, if the information acquisition unit 112 acquires the online token KX[q] in step S313, the control device 11 of the terminal device 1[q] advances the process to step S321. If the result of the determination in step S319 is negative, that is, if the information acquisition unit 112 has not acquired the online token KX[q] in step S313, the control device 11 of the terminal device 1[q] proceeds to step S401.

[0229] 23, if the result of the determination in step S319 is positive, that is, if the information acquisition unit 112 acquires the online token KX[q] in step S313, the code generation unit 113 of the terminal device 1[q] executes an online code generation process to generate an online payment code CX[q] based on the online token KX[q] (S321). The process of step S321 corresponds to the process of step S47 described above.

[0230] Then, the display control unit 114 of the terminal device 1[q] generates display information for displaying the online code image GX[q] indicating the online payment code CX[q], and causes the display device 13 to display the online code image display screen GGX including the online code image GX[q] based on the display information (S323). The processing of step S323 corresponds to the processing of step S48 described above.

[0231] Next, the control device 11 of the terminal device 1[q] determines whether or not the user U[q] has performed a termination operation using the input device 14 (S325). If the result of the determination in step S325 is positive, that is, if an end operation has been performed, the control device 11 of the terminal device 1[q] advances the process to step S501. If the result of the determination in step S325 is negative, i.e., if the termination operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether an opportunity to update the online code image has arrived (S327). Here, the opportunity to update the online code image is an opportunity to update the online code image GX[q] displayed on the display device 13.

[0232] In this embodiment, it is assumed that an opportunity to update an online code image is deemed to have arrived when one or more of the three update conditions J1, namely, the online token time condition J11, the online code image display condition J12, and the online code image operation condition J13, are met. Here, the online token time condition J11 is a condition that a time equivalent to the online token validity time TSX (five minutes in this embodiment) has elapsed since the online code image GX[q] was displayed on the display device 13. The online code image display condition J12 is a condition that an online code image display screen GGX including the online code image GX[q] transitions from background display to foreground display on the display device 13. The online code image operation condition J13 is a condition that a pull-down operation is performed while the online code image display screen GGX including the online code image GX[q] is displayed on the display device 13.

[0233] If the result of the judgment in step S327 is negative, i.e., if the opportunity to update the online code image has not arrived, the control device 11 of the terminal device 1[q] returns the processing to step S323 and continues to display the online code image GX[q] on the display device 13. If the result of the determination in step S327 is positive, that is, if the opportunity to update the online code image has arrived, the information sending unit 111 of the terminal device 1[q] sends an online token request RX to the payment device 3 (S329).

[0234] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the online token KX[q] has been provided from the payment apparatus 3 in response to the online token request RX in step S329 (S331). If the result of the judgment in step S331 is positive, i.e., if an online token KX[q] is supplied from the payment device 3, the control device 11 of the terminal device 1[q] acquires the online token KX[q] (S333) and proceeds to step S321, where it updates the online code image GX[q] by generating an online payment code CX[q] based on the online token KX[q] acquired in step S333.

[0235] If the result of the determination in step S331 is negative, that is, if the online token KX[q] has not been supplied from the settlement apparatus 3, it is determined whether or not the online token response waiting period TWX[q] has ended (S335). If the result of the judgment in step S335 is negative, i.e., if the online token response waiting period TWX[q] has not ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S329, thereby repeating the transmission of the online token request RX by the information transmission unit 111. If the result of the determination in step S335 is positive, that is, if the online token response waiting period TWX[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S407.

[0236] As shown in FIG. 24, if the result of the judgment in step S317 is negative, or if the result of the judgment in step S319 is negative, the information sending unit 111 of the terminal device 1[q] sends an offline blockage information request BY to the payment device 3 (S401).

[0237] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not offline blockage information DHY has been provided from the payment device 3 in response to the offline blockage information request BY in step S401 (S403). If the result of the judgment in step S403 is positive, that is, if offline blockage information DHY is supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the offline blockage information DHY (S405) and proceeds to step S407. If the result of the determination in step S403 is negative, that is, if the offline blockage information DHY is not provided from the settlement apparatus 3, the information acquisition unit 112 of the terminal apparatus 1[q] advances the process to step S407.

[0238] Next, the code generation unit 113 of the terminal device 1[q] determines whether or not the offline payment code CY[q] has already been generated in step S205 (S407). If the result of the determination in step S407 is positive, that is, if the offline payment code CY[q] has already been generated, the code generation unit 113 of the terminal device 1[q] proceeds to step S433. If the result of the determination in step S407 is negative, that is, if the offline payment code CY[q] has not been generated, the information transmitting unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S409).

[0239] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token KY[q] and the encryption key KS[q] have been provided by the payment device 3 in response to the offline token request RY in step S409 (S411).

[0240] If the result of the judgment in step S411 is positive, that is, if the offline token KY[q] and the encryption key KS[q] are supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and the encryption key KS[q] (S413). Next, the information acquisition unit 112 of the terminal device 1[q] stores the offline token KY[q] and encryption key KS[q] acquired in step S413 in the storage device 12 (S415), and the process proceeds to step S419.

[0241] If the result of the determination in step S411 is negative, that is, if the offline token KY[q] and the encryption key KS[q] have not been supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token response waiting period TWY[q] has ended (S417). Note that, in the flowcharts of Figures 19 to 27, as an example, it is assumed that the offline token response waiting period TWY[q] is a period starting from the time when the offline token request RY is transmitted by the information transmission unit 111 in step S409. If the result of the determination in step S417 is negative, that is, if the offline token response waiting period TWY[q] has not expired, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S409. If the result of the determination in step S417 is positive, that is, if the offline token response waiting period TWY[q] has ended, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S419.

[0242] Next, the code generation unit 113 of the terminal device 1[q] determines whether or not the execution function of offline payment processing in the payment apparatus 3 is in a blocked state, based on the offline blockage information DHY acquired by the information acquisition unit 112 in step S405 (S419). Specifically, the code generation unit 113 determines whether or not the following conditions are satisfied: the information acquisition unit 112 has acquired the offline blockage information DHY in step S405, and the offline blockage information DHY indicates that the payment apparatus 3 is not in an offline blocked state.

[0243] If the result of the judgment in step S419 is negative, that is, if the information acquisition unit 112 has not acquired the offline blockage information DHY in step S405, or if the offline blockage information DHY indicates that the payment device 3 is in an offline blockage state, the control device 11 of the terminal device 1[q] proceeds to step S451.

[0244] If the result of the judgment in step S419 is positive, that is, if the condition that the information acquisition unit 112 has acquired offline blockage information DHY in step S405 and the offline blockage information DHY indicates that the payment device 3 is not in an offline blockage state is satisfied, the control device 11 of the terminal device 1[q] judges whether a valid offline token KY[q][M] is stored in the memory device 12 of the terminal device 1[q] (S421).

[0245] If the result of the determination in step S421 is positive, that is, if a valid offline token KY[q][M] is stored in the storage device 12, the control device 11 of the terminal device 1[q] proceeds to step S431. If the result of the determination in step S421 is negative, that is, if a valid offline token KY[q][M] is not stored in the storage device 12, the control device 11 of the terminal device 1[q] advances the process to step S451.

[0246] As shown in Figure 25, if the result of the judgment in step S421 is positive, the code generation unit 113 of the terminal device 1[q] executes an offline code generation process and generates an offline payment code CY[q] based on the offline token KY[q][M] and the encryption key KS[q][M] (S431).

[0247] Then, the display control unit 114 of the terminal device 1[q] generates display information for displaying the offline code image GY[q] indicating the online payment code CX[q], and based on the display information, causes the display device 13 to display the offline code image display screen GGY including the offline code image GY[q] (S433).

[0248] Next, the control device 11 of the terminal device 1[q] determines whether or not the user U[q] has performed a termination operation using the input device 14 (S435). If the result of the determination in step S435 is positive, that is, if an end operation has been performed, the control device 11 of the terminal device 1[q] advances the process to step S501. If the result of the determination in step S435 is negative, that is, if the termination operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether or not an opportunity to update the offline code image has arrived (S437). Here, the opportunity to update the offline code image is an opportunity to update the offline code image GY[q] displayed on the display device 13.

[0249] In this embodiment, it is assumed that the opportunity to update the offline code image is deemed to have arrived when at least one of two update conditions J2, the offline code image display condition J22 and the offline code image operation condition J23, is met. Here, the offline code image display condition J22 is a condition that the offline code image display screen GGY including the offline code image GY[q] transitions from background display to foreground display on the display device 13. The offline code image operation condition J23 is a condition that a pull-down operation is performed while the offline code image display screen GGY including the offline code image GY[q] is displayed on the display device 13.

[0250] If the result of the determination in step S437 is positive, that is, if an opportunity to update the offline code image has arrived, the control device 11 of the terminal device 1[q] advances the process to step S301. If the result of the judgment in step S437 is negative, i.e., if the opportunity to update the offline code image has not arrived, the code generation unit 113 of the terminal device 1[q] judges whether the opportunity to update the time encryption code TT[q] due to the update of the terminal time value AG has arrived (S439). If the result of the judgment in step S439 is negative, i.e., if the opportunity to update the time encryption code TT[q] has not arrived, the control device 11 of the terminal device 1[q] returns the processing to step S433 and continues displaying the offline code image GY[q] on the display device 13.

[0251] If the result of the judgment in step S439 is positive, that is, if the terminal time value AG is updated and the opportunity to update the time encryption code TT[q] has arrived, the code generation unit 113 of the terminal device 1[q] updates the time encryption code TT[q] by encrypting the updated terminal time value AG with the encryption key KS[q][M] (S441).

[0252] Then, the code generation unit 113 of the terminal device 1[q] updates the offline payment code CY[q] with the updated time encryption code TT[q] (S443), and proceeds to step S433 to display the updated offline code image GY[q] on the display device 13. Specifically, in step S443, the code generation unit 113 generates the updated offline payment code CY[q] by arranging, in a predetermined order, the business identification token KZ stored in the storage device 12, the latest offline token KY[q][M] stored in the storage device 12, the updated time encryption code TT[q], the allocation value VJ, and the code type value VV.

[0253] 26, if the result of the determination in step S419 is negative, or if the result of the determination in step S421 is negative and offline code generation processing is difficult, the display device 13 is caused to display an online payment standby screen (not shown), which is a screen that notifies the user U[q] that the execution of online electronic payment is waiting (S451). Note that the processing of step S451 may be omitted.

[0254] Then, the information transmission unit 111 of the terminal device 1[q] determines whether or not the terminal device 1[q] and the payment device 3 can communicate with each other (S453). Then, the information transmission unit 111 waits until the terminal device 1[q] and the payment device 3 can communicate with each other.

[0255] When the terminal device 1[q] and the payment device 3 become able to communicate with each other (S453: Y), the information transmitting unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S455). Then, if there is no response to the online token request RX from the payment device 3 (S457: N), the control device 11 of the terminal device 1[q] returns the process to step S455 and resends the online token request. On the other hand, if the information acquisition unit 112 of the terminal device 1[q] receives the online token KX[q] sent from the payment device 3 as a response to the online token request RX (S457: Y), it acquires the online token KX[q] (S459).

[0256] Next, the code generation unit 113 of the terminal device 1[q] executes online code generation processing using the online token KX[q] acquired in step S459, and generates an online payment code CX[q] (S461).

[0257] Then, the display control unit 114 of the terminal device 1[q] uses the online payment code CX[q] generated in step S461 to generate display information for displaying an online code image GX[q] indicating the online payment code CX[q], and causes the display device 13 to display the online code image GX[q] based on the display information (S463).

[0258] Next, the control device 11 of the terminal device 1[q] determines whether or not the user U[q] has performed a termination operation using the input device 14 (S465). If the result of the determination in step S465 is positive, that is, if an end operation has been performed, the control device 11 of the terminal device 1[q] advances the process to step S501. If the result of the determination in step S465 is negative, that is, if the end operation has not been performed, the code generation unit 113 of the terminal device 1[q] determines whether or not an opportunity to update the online code image has arrived (S467).

[0259] If the result of the determination in step S467 is negative, that is, if the opportunity to update the online code image has not arrived, the control device 11 returns the process to step S463 and causes the display device 13 to continue displaying the online code image GX[q]. If the result of the determination in step S467 is positive, that is, if the opportunity to update the online code image has arrived, the information transmitting unit 111 of the terminal device 1[q] transmits an online token request RX to the payment device 3 (S469).

[0260] Then, if there is no response to the online token request RX in step S469 from the payment apparatus 3 (S471: N), the control device 11 of the terminal device 1[q] proceeds to step S451. On the other hand, if the control device 11 of the terminal device 1[q] receives the online token KX[q] transmitted from the payment apparatus 3 as a response to the online token request RX in step S469 (S471: Y), it acquires the online token KX[q] (S473) and proceeds to step S461, thereby generating an online payment code CX[q] based on the online token KX[q] acquired in step S473 and updating the online code image GX[q].

[0261] 27, if the result of the determination in step S209 is positive, if the result of the determination in step S325 is positive, if the result of the determination in step S435 is positive, or if the result of the determination in step S465 is positive, that is, if a termination operation is performed, the information transmission unit 111 of the terminal device 1[q] transmits an offline token request RY to the payment device 3 (S501). The processing in step S501 corresponds to the processing in step S51 described above.

[0262] Then, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token KY[q] and the encryption key KS[q] have been provided by the payment device 3 in response to the offline token request RY in step S501 (S503).

[0263] If the result of the judgment in step S503 is positive, that is, if the offline token KY[q] and the encryption key KS[q] are supplied from the payment device 3, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and the encryption key KS[q] (S505). Next, the information acquisition unit 112 of the terminal device 1[q] stores the offline token KY[q] and encryption key KS[q] acquired in step S505 in the storage device 12 (S507), and ends the processing shown in the flowcharts of Figures 19 to 27. The processing of step S507 corresponds to the processing of step S53 described above.

[0264] If the result of the determination in step S503 is negative, that is, if the offline token KY[q] and the encryption key KS[q] have not been supplied from the payment apparatus 3, the information acquisition unit 112 of the terminal device 1[q] determines whether or not the offline token response waiting period TWY[q] has ended (S509). Here, in the flowcharts of Figures 19 to 27, as an example, it is assumed that the offline token response waiting period TWY[q] in step S509 is a period starting from the time when the offline token request RY is transmitted by the information transmission unit 111 in step S501. If the result of the determination in step S509 is negative, that is, if the offline token response waiting period TWY[q] has not expired, the information acquisition unit 112 of the terminal device 1[q] proceeds to step S501. If the result of the determination in step S509 is positive, that is, if the offline token response waiting period TWY[q] has ended, the control device 11 of the terminal device 1[q] ends the processing shown in the flowcharts of FIGS.

[0265] Thus, according to this embodiment, when in an online blocked state (S317: N), or when the acquisition of the online token KX[q] fails (S319: N), etc., when online electronic settlement is difficult, offline electronic settlement is executed (see S401 to S433). Therefore, for example, compared with a mode in which the electronic settlement system can only execute online electronic settlement, when the user U[q] of the terminal device 1[q] receives a service in a store where the store device 5 is installed, the possibility of paying the price of the service by electronic settlement can be increased.

[0266] Also, according to this embodiment, when an opportunity to update the offline code image arrives (S437: Y) while the offline code image GY[q] is being displayed (see step S433), the acquisition of the online token KX[q] is attempted again (see steps S301 to S313). Therefore, according to this embodiment, when online electronic settlement is primarily difficult and offline electronic settlement is being executed, it is possible to return to online electronic settlement.

[0267] Also, according to this embodiment, when in an offline blocked state (S419: N), or when there is no valid offline token KY[q] in the storage device 12 (S421: N), etc., when it is difficult to perform the offline code generation process, an attempt is made to acquire the online token KX[q] again (see steps S455 to S463). Therefore, compared with a mode in which the acquisition of the online token KX[q] is not attempted when the offline code generation process is difficult, that is, a mode in which the execution of the code generation process is abandoned when the offline code generation process is difficult, when the user U[q] of the terminal device 1[q] receives a service in a store where the store device 5 is installed, the possibility of paying the price of the service by electronic settlement can be increased.

[0268] <A.5. Operation of the Settlement Device 3> Hereinafter, referring to FIGS. 28 to 32, an outline of the operation of the settlement device 3 when electronic settlement is executed will be described.

[0269] 28 is a flowchart showing an example of the operation of the payment device 3 when a token response information supply process is executed in the payment device 3. Here, the token response information supply process is a process of supplying various information such as token response information DSW[q] from the payment device 3 to the terminal device 1[q] in response to terminal information DTM[q] from the terminal device 1[q] when electronic payment is executed in the electronic payment system Sys.

[0270] As shown in FIG. 28, when terminal information DTM[q] is transmitted from terminal device 1[q], the information receiving unit 312 of the settlement apparatus 3 receives the terminal information DTM[q] (S601).

[0271] Next, the control device 31 of the settlement device 3 determines the online token response waiting time TSWX[q] based on the terminal information DTM[q] (S603). Furthermore, the control device 31 of the settlement device 3 determines the offline token response waiting time TSWY[q] based on the terminal information DTM[q] (S605). Then, the control device 31 of the payment device 3 generates token response information DSW[q] indicating the online token response waiting time TSWX[q] determined in step S603 and the offline token response waiting time TSWY[q] determined in step S605 (S607).

[0272] Next, the control device 31 of the settlement device 3 adds the token response information DSW[q] generated in step S607 to the token response information DW for each terminal, thereby updating the token response information DW for each terminal (S609). Furthermore, the information supply unit 311 of the settlement apparatus 3 supplies the token response information DSW[q] generated in step S607 to the terminal apparatus 1[q] (S611). Furthermore, the information supply unit 311 of the settlement device 3 supplies the business identification token KZ generated based on the business identification information DKZ stored in the storage device 32 to the terminal device 1[q] (S613). Furthermore, the information supply unit 311 of the settlement apparatus 3 supplies the setting information DS stored in the storage device 32 to the terminal apparatus 1[q] (S615), and ends the token response information supply process.

[0273] 29 is a flowchart showing an example of the operation of the payment apparatus 3 when the online token generation process is executed in the payment apparatus 3. Here, the online token generation process is a process of generating an online token KX[q] in response to an online token request RX from the terminal device 1[q] when electronic payment is executed in the electronic payment system Sys.

[0274] As shown in FIG. 29, when an online token request RX is transmitted from the terminal device 1[q], the information receiving unit 312 of the payment apparatus 3 receives the online token request RX (S701).

[0275] Next, the control device 31 of the settlement device 3 generates an online token KX[q] (S703). Furthermore, the control device 31 of the payment device 3 determines the online token validity period TX[q] (S705). Specifically, in step S705, the control device 31 determines the online token validity period TX[q] as a period starting from the time when the online token KX[q] is generated and ending from the time when the online token KX[q] is generated, the time when the online token validity period TSX (for example, 5 minutes) has elapsed.

[0276] Then, the control device 31 of the settlement device 3 updates the online token payout information DKX (S707). Specifically, in step S707, the control device 31 adds a new record to the online token payout information DKX, and stores in the new record the user identification information DID[q] corresponding to the user U[q] of the terminal device 1[q], the online token KX[q] generated in step S703, and the online token validity period TX[q] determined in step S705.

[0277] Then, the information supply unit 311 of the settlement apparatus 3 supplies the online token KX[q] generated in step S703 to the terminal apparatus 1[q] (S709), and ends the online token generation process.

[0278] 30 is a flowchart showing an example of the operation of the payment device 3 when the offline token generation process is executed in the payment device 3. Here, the offline token generation process is a process of generating an offline token KY[q] in response to an offline token request RY from the terminal device 1[q] when electronic payment is executed in the electronic payment system Sys.

[0279] As shown in FIG. 30, when an offline token request RY is transmitted from the terminal device 1[q], the information accepting unit 312 of the settlement apparatus 3 accepts the offline token request RY (S721).

[0280] Next, the control device 31 of the settlement device 3 generates an offline token KY[q] (S723). Furthermore, the control device 31 of the payment device 3 determines the offline token validity period TY[q] (S725). Specifically, in step S725, the control device 31 determines the offline token validity period TY[q] as a period starting from the time when the offline token KY[q] is generated and ending from the time when the offline token KY[q] is generated, when the offline token validity period TSY (for example, one week) has elapsed. Furthermore, the control device 31 of the settlement device 3 generates an encryption key KS[q] (S727).

[0281] Then, the control device 31 of the payment device 3 updates the offline token payout information DKY (S729). Specifically, in step S729, the control device 31 adds a new record to the offline token payout information DKY, and stores in the new record the user identification information DID[q] corresponding to the user U[q] of the terminal device 1[q], the offline token KY[q] generated in step S723, the offline token validity period TY[q] decided in step S725, and the encryption key KS[q] generated in step S727.

[0282] Then, the information supply unit 311 of the payment device 3 supplies the offline token KY[q] generated in step S723 and the encryption key KS[q] generated in step S727 to the terminal device 1[q] (S731), and terminates the offline token generation process.

[0283] 31 and 32 are flowcharts showing an example of the operation of the payment device 3 when payment-related processing is executed in the payment device 3. Here, the payment-related processing includes processing for determining the validity of the token KK[q] in the payment device 3 and payment processing executed by the payment device 3. When payment information DP[q] is supplied from the store device 5, the payment device 3 starts the payment-related processing.

[0284] As shown in FIG. 31, when the payment information DP[q] is transmitted from the in-store device 5, the information receiving unit 312 of the payment apparatus 3 receives the payment information DP[q] (S741).

[0285] Next, the payment processing unit 313 of the payment apparatus 3 extracts the code type value VV from the payment code CC[q] included in the payment information DP[q] accepted in step S741 (S743). Then, the payment processing unit 313 of the payment device 3 determines whether the code type value VV extracted in step S743 indicates an online code value (S745). That is, in step S745, the payment processing unit 313 determines whether the payment code CC[q] included in the payment information DP[q] accepted in step S741 is an online payment code CX[q].

[0286] If the result of the determination in step S745 is negative, that is, if the payment code CC[q] included in the payment information DP[q] is the offline payment code CY[q], the payment processing unit 313 of the payment device 3 proceeds to step S761. If the result of the judgment in step S745 is positive, that is, if the payment code CC[q] included in the payment information DP[q] is the online payment code CX[q], the payment processing unit 313 of the payment device 3 extracts the online token KX[q] from the online payment code CX[q] included in the payment information DP[q] accepted in step S741 (S747).

[0287] Next, the settlement processing unit 313 of the settlement apparatus 3 determines whether or not the online token KX[q] extracted in step S747 exists in the online token payout information DKX (S749). If the result of the determination in step S749 is negative, that is, if the online token KX[q] extracted in step S747 does not exist in the online token payout information DKX, the settlement processing unit 313 of the settlement apparatus 3 proceeds to step S757.

[0288] If the result of the judgment in step S749 is positive, that is, if the online token KX[q] extracted in step S747 is present in the online token payout information DKX, the payment processing unit 313 of the payment device 3 determines whether the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 is a period that includes the current time by referring to the online token payout information DKX (S751). If the result of the judgment in step S751 is negative, that is, if the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 does not include the current time, the payment processing unit 313 of the payment device 3 proceeds to step S757.

[0289] If the result of the judgment in step S751 is positive, that is, if the online token validity period TX[q] corresponding to the online token KX[q] extracted in step S747 includes the current time, the payment processing unit 313 of the payment device 3 executes online payment processing (S753) and confirms the payment from the user U[q] corresponding to the online token KX[q] extracted in step S747 to the store where the store device 5 that sent the payment information DP[q] in step S741 is located. Then, the information supply unit 311 of the payment device 3 sends a cash register billing response (S755) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, which is a notification that the payment from user U[q] based on the payment information DP[q] has been confirmed, and terminates the payment-related processing.

[0290] On the other hand, if the result of the judgment in step S749 is negative, or if the result of the judgment in step S751 is negative, the information supply unit 311 of the payment device 3 sends a notification to the store where the store device 5 that sent the payment information DP[q] in step S741 is located that the payment from user U[q] based on the payment information DP[q] has failed (S757), and terminates the payment-related processing.

[0291] As shown in Figure 32, if the result of the judgment in step S745 is negative, that is, if the payment code CC[q] included in the payment information DP[q] is the offline payment code CY[q], the payment processing unit 313 of the payment device 3 extracts the offline token KY[q] from the offline payment code CY[q] included in the payment information DP[q] accepted in step S741 (S761).

[0292] Next, the settlement processing unit 313 of the settlement apparatus 3 determines whether or not the offline token KY[q] extracted in step S761 exists in the offline token payout information DKY (S763). If the result of the determination in step S763 is negative, that is, if the offline token KY[q] extracted in step S761 does not exist in the offline token payout information DKY, the settlement processing unit 313 of the settlement apparatus 3 proceeds to step S781.

[0293] If the result of the judgment in step S763 is positive, that is, if the offline token KY[q] extracted in step S761 is present in the offline token issuance information DKY, the payment processing unit 313 of the payment device 3 determines whether the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 is a period that includes the current time by referring to the offline token issuance information DKY (S765). If the result of the judgment in step S765 is negative, that is, if the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 does not include the current time, the payment processing unit 313 of the payment device 3 proceeds to step S781.

[0294] If the result of the judgment in step S765 is positive, that is, if the offline token validity period TY[q] corresponding to the offline token KY[q] extracted in step S761 includes the current time, the payment processing unit 313 of the payment device 3 judges whether or not an offline token KY[q] identical to the offline token KY[q] included in the payment information DP[q] accepted in step S741 has been supplied during the period from a time twice the update unit time TC in the past (for example, two minutes before the present) to the time when the payment information DP[q] was accepted in step S741 (hereinafter sometimes referred to as the "same token prohibited period") (S767). If the result of the judgment in step S767 is positive, that is, if an offline token KY[q] identical to the offline token KY[q] included in the payment information DP[q] accepted in step S741 has been accepted during the same token prohibition period, the payment processing unit 313 of the payment device 3 proceeds to step S781.

[0295] If the result of the judgment in step S767 is negative, that is, if an offline token KY[q] identical to the offline token KY[q] included in the payment information DP[q] accepted in step S741 has not been accepted during the same token prohibition period, the payment processing unit 313 of the payment device 3 extracts the time encryption code TT[q] from the offline payment code CY[q] included in the payment information DP[q] accepted in step S741 (S769).

[0296] Furthermore, the payment processing unit 313 of the payment apparatus 3 refers to the offline token payout information DKY to identify the encryption key KS[q] corresponding to the offline token KY[q] extracted in step S761 (S771).

[0297] Next, the payment processing unit 313 of the payment apparatus 3 encrypts the server time value AM, the future time value AMf, and the past time value AMp using the encryption key KS[q] identified in step S771 (S773).

[0298] Here, the server time value AM is a value based on the server time TM, which is the current time managed by the payment apparatus 3, and is a value that is updated periodically at the update unit time TC. Specifically, in this embodiment, as an example, it is assumed that the server time value AM is a value that expresses the server time TM in the order of minutes. For example, in this embodiment, if the server time TM is "18:25:37," the server time value AM may be "1825," which is obtained by deleting "37 seconds" from the server time TM. Therefore, if the server time TM and the terminal time TG are the same time, the server time value AM will have the same value as the terminal time value AG. However, in reality, there may be a slight difference between the server time TM and the terminal time TG. In this case, the server time value AM and the terminal time value AG may have different values. Furthermore, the future time value AMf is a value based on a time that is an update unit time TC in the future than the server time TM. Specifically, in this embodiment, as an example, it is assumed that the future time value AMf is a value that represents a time that is an update unit time TC (e.g., one minute) in the future than the server time TM in the order of minutes. For example, if the server time TM is "18:25:37," the future time value AMf may be "1826," which is "18:26:37," a time that is one minute in the future than the server time TM, with "37 seconds" deleted. Furthermore, the past time value AMp is a value based on a time that is an update unit time TC in the past than the server time TM. Specifically, in this embodiment, as an example, it is assumed that the past time value AMp is a value that represents a time that is an update unit time TC (e.g., one minute) in the past than the server time TM, in the order of minutes. For example, if the server time TM is "18:25:37," the past time value AMp may be "1824," which is "18:24:37," a time that is one minute in the past than the server time TM, with "37 seconds" deleted.

[0299] In the following, the value obtained by encrypting the server time value AM with the encryption key KS[q] will be referred to as the server time encryption code CM, the value obtained by encrypting the future time value AMf with the encryption key KS[q] will be referred to as the future time encryption code CMf, and the value obtained by encrypting the past time value AMp with the encryption key KS[q] will be referred to as the past time encryption code CMp. In the following, the server time encryption code CM, the future time encryption code CMf, and the past time encryption code CMp may be collectively referred to as the time encryption code CMM. In other words, in step S773, the payment processing unit 313 generates three time encryption codes CMM: the server time encryption code CM obtained by encrypting the server time value AM with the encryption key KS[q], the future time encryption code CMf obtained by encrypting the future time value AMf with the encryption key KS[q], and the past time encryption code CMp obtained by encrypting the past time value AMp with the encryption key KS[q].

[0300] Next, the payment processing unit 313 of the payment device 3 determines whether any of the three time encryption codes CMM generated in step S773 matches the time encryption code TT[q] extracted in step S769 (S775).

[0301] If the result of the judgment in step S775 is positive, that is, if the time encryption code CMM generated in step S773 matches the time encryption code TT[q] extracted in step S769, the payment processing unit 313 of the payment device 3 executes offline payment processing (S777) and confirms the payment from the user U[q] corresponding to the offline token KY[q] extracted in step S761 to the store where the store device 5 that sent the payment information DP[q] in step S741 is located. Then, the information supply unit 311 of the payment device 3 sends a cash register billing response (S779) to the store where the store device 5 that sent the payment information DP[q] in step S741 is located, which is a notification that the payment from user U[q] based on the payment information DP[q] has been confirmed, and terminates the payment-related processing.

[0302] On the other hand, if the result of the judgment in step S763 is negative, if the result of the judgment in step S765 is negative, if the result of the judgment in step S767 is positive, or if the result of the judgment in step S775 is negative, the information supply unit 311 of the payment device 3 sends a notification to the store where the store device 5 that sent the payment information DP[q] in step S741 is located that the payment from user U[q] based on the payment information DP[q] has failed (S781), and terminates the payment-related processing.

[0303] As described above, in this embodiment, the payment device 3 can perform two types of payment processing: online payment processing and offline payment processing. Therefore, compared to, for example, an embodiment in which the payment device 3 can perform only online payment processing, the convenience of the user U[q] who uses electronic payment can be improved.

[0304] Furthermore, in this embodiment, if two or more pieces of payment information DP[q] including the same offline token KY[q] are supplied during a same-token prohibition period having a time length twice the update unit time TC, the payment device 3 restricts offline payment processing based on the payment information DP[q] supplied the second time onwards. Therefore, according to this embodiment, it is possible to restrict fraudulent payments using the offline token KY[q], thereby reducing security risks in the event that the offline token KY[q] is leaked, for example.

[0305] Also, in this embodiment, the settlement device 3 verifies the validity of the time encryption code TT[q] included in the offline settlement code CY[q] using the future time value AMf and the past time value AMp in addition to the server time value AM in settlement-related processing. Therefore, according to this embodiment, even if there is an error between the terminal time TG managed by the terminal device 1[q] and the server time TM managed by the settlement device 3, the user U[q] of the terminal device 1[q] can use offline electronic settlement. Thereby, according to this embodiment, for example, in settlement-related processing, compared with the mode of verifying the validity of the time encryption code TT[q] based only on the server time value AM, the possibility that the user U[q] can use electronic settlement can be improved, and the convenience of the user U[q] using electronic settlement can be improved.

[0306] <B. Variation Example> Each of the above embodiments can be variously modified. Specific modification modes are exemplified below. Two or more modes arbitrarily selected from the following examples can be appropriately combined within a range where they do not conflict with each other. In the variation examples exemplified below, for elements whose operations and functions are equivalent to those of the embodiment, the reference numerals referred to in the above description are used, and the detailed description of each is appropriately omitted.

[0307] <B.1. Variation Example 1> In the above-described embodiment, the electronic settlement system Sys has been exemplified and described in the mode of starting the online code image display process of step S4 after executing the offline code image display process of step S2. However, the present invention is not limited to such a mode. The electronic settlement system Sys may start some or all of the processes of steps S41 to S49 included in the online code image display process of step S4 before the end of some or all of the processes of steps S21 to S25 included in the offline code image display process of step S2.

[0308] Specifically, after the timing when at least a part of the processes of steps S21 to S24 included in the offline code image display process in step S2 starts, and before a part of the processes of steps S21 to S24 ends, a part of the processes of steps S41 to S48 included in the online code image display process in step S4 may be started. For example, the terminal device 1[q] may start the process of step S41 included in the online code image display process in step S4 after the timing when the process of step S24 included in the offline code image display process in step S2 starts and before the process of step S24 ends. Further, for example, the terminal device 1[q] may perform the offline code image display process in step S2 and the online code image display process in step S4 as parallel processes.

[0309] <B.2. Modified Example 2> In the above-described embodiment and modified example 1, the mode in which the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] are determined based on the terminal information DTM[q] has been exemplified and described. However, the present invention is not limited to such a mode. The online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be determined without being based on the terminal information DTM[q]. Specifically, the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be determined without considering the performance of the terminal device 1[q].

[0310] For example, the online token response waiting time TSWX[q] may be a predetermined fixed value. Further, for example, the offline token response waiting time TSWY[q] may also be a predetermined fixed value. In this case, the token response information DSW[q] indicating the online token response waiting time TSWX[q] and the offline token response waiting time TSWY[q] may be stored in advance in the storage device 12 of the terminal device 1[q].

[0311] <B.3. Variant Example 3> In the above-described embodiments and Variant Examples 1 and 2, an aspect in which the offline code image display process is executed after the settlement application is started without considering whether the settlement device 3 is in an offline blocked state has been exemplified and described. However, the present invention is not limited to such an aspect. The terminal device 1[q] may confirm whether the settlement device 3 is in an offline blocked state after the settlement application is started, and execute the offline code image display process only when the settlement device 3 is not in an offline blocked state.

[0312] FIG. 33 is a flowchart showing an example of an overview of the normal operation of the electronic settlement system Sys when the electronic settlement system Sys according to this variant example executes online electronic settlement. It is assumed that the electronic settlement system Sys according to this variant example has the same configuration as the electronic settlement system Sys according to the embodiment.

[0313] As shown in FIG. 33, in this variant example, the control device 11 of the terminal device 1[q] starts the settlement application by executing the electronic settlement program PG-T based on the operation of the user U[q] (S1).

[0314] Next, the control device 11 of the terminal device 1[q] executes an offline block determination process (S8). Here, the offline block determination process is a process for determining whether the settlement device 3 is in an offline blocked state. In the flowchart shown in FIG. 33, a case where the settlement device 3 is not in an offline blocked state is assumed.

[0315] Thereafter, the control device 11 of the terminal device 1[q] executes offline code image display processing (S2). Note that if the offline blockage determination processing of step S8 determines that the payment device 3 is in an offline blocked state, the control device 11 of the terminal device 1[q] omits the offline code image display processing of step S2. Also, if the offline blockage determination processing of step S8 determines that the payment device 3 is in an offline blocked state, the electronic payment system Sys executes the online code image display processing of step S4 and then executes the payment-related processing of step S3.

[0316] Next, the electronic payment system Sys executes payment-related processing (S3). Thereafter, the electronic payment system Sys executes an online code image display process (S4). Then, the electronic payment system Sys executes offline token acquisition processing (S5).

[0317] 34 and 35 are sequence charts showing an example of normal operation of the electronic payment system Sys according to this modification when the electronic payment system Sys executes online electronic payment.

[0318] As shown in FIG. 34, in this modification, the control device 11 of the terminal device 1[q] in the electronic payment system Sys starts up the payment application (S1).

[0319] Next, the electronic payment system Sys executes offline blockage determination processing (S8).

[0320] Specifically, in the offline blockage determination process of step S8, the communication status determination unit 115 of the terminal device 1[q] first determines whether the communication status of the terminal device 1[q] is online (S81). Note that the sequence charts shown in Figures 34 and 35 assume that the communication status of the terminal device 1[q] is online. Furthermore, if the determination result in step S81 indicates that the communication status of the terminal device 1[q] is offline, the control device 11 of the terminal device 1[q] terminates the offline blockage determination process of step S8. Next, the information transmitter 111 of the terminal device 1[q] transmits an offline blockage information request BY to the settlement device 3 in the offline blockage determination process of step S8 (S82). Next, in the offline blockage determination process of step S8, the control device 31 of the payment device 3 supplies offline blockage information DHY to the terminal device 1[q] in response to the offline blockage information request BY supplied from the terminal device 1[q] in step S82 (S83). Specifically, in step S83, the control device 31 first determines whether the offline payment process in the payment device 3 can be executed, and generates offline blockage information DHY indicating the result of the determination. Then, the information supply unit 311 of the control device 31 supplies the generated offline blockage information DHY to the terminal device 1[q]. Thereafter, the information acquisition unit 112 of the terminal device 1[q] acquires the offline blockage information DHY supplied from the payment device 3. Next, in the offline blockage determination process of step S8, the code generation unit 113 of the terminal device 1[q] determines whether the execution function of offline payment processing in the payment device 3 is in a blocked state based on the offline blockage information DHY acquired by the information acquisition unit 112 in step S83 (S84). Note that the sequence charts shown in Figures 34 and 35 assume that the execution function of offline payment processing in the payment device 3 is not in a blocked state, that is, that the payment device 3 is able to execute offline payment processing.

[0321] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the electronic payment system Sys executes the processing of steps S21 to S25 described above as the offline code image display processing of step S2. As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24). As described above, the control device 11 of the terminal device 1[q] executes the offline code image display processing of step S2 only if the result obtained in step S84 is that the payment device 3 is not in an offline blocked state, and omits the offline code image display processing of step S2 if the result obtained is that the payment device 3 is in an offline blocked state.

[0322] Next, the electronic payment system Sys executes the above-mentioned payment-related process (S3). Specifically, the electronic payment system Sys executes the above-mentioned steps S31 to S35 as the payment-related process of step S3.

[0323] As shown in Figure 35, the electronic payment system Sys executes the above-mentioned online code image display process (S4). Specifically, the electronic payment system Sys executes the processes of steps S42 to S49 as the online code image display process of step S4.

[0324] Next, the electronic payment system Sys executes the offline token acquisition process (S5) described above. Specifically, the electronic payment system Sys executes the processes of steps S51 to S53 described above as the offline token acquisition process of step S5.

[0325] As described above, in this modification example, when the offline block information DHY indicates that the settlement device 3 is not in the offline blocked state, the terminal device 1[q] displays the offline code image GY[q] on the display device 13. That is, in this modification example, when the offline block information DHY indicates that the settlement device 3 is in the offline blocked state, the terminal device 1[q] suppresses the display of the offline code image GY[q] on the display device 13 by restricting the execution of the offline code image display process. That is, according to this modification example, when it is difficult to execute offline electronic settlement, the display of the offline code image GY[q] on the terminal device 1[q] is suppressed. Therefore, according to this modification example, for example, compared with a mode in which the offline code image GY[q] is displayed without considering the offline block information DHY, the labor of the user U[q] related to the display of the offline code image GY[q] can be reduced.

[0326] <B.4. Modification Example 4> In the above-described embodiments and modification examples 1 and 2, an example has been described in which the offline code image display process is executed after the settlement application is started without considering whether the settlement device 3 is in the offline blocked state, but the present invention is not limited to such a mode. After the settlement application is started and after the offline code image display process is executed, the terminal device 1[q] may execute an offline block determination process to confirm whether the settlement device 3 is in the offline blocked state.

[0327] FIG. 36 is a flowchart showing an example of an outline of the normal operation of the electronic settlement system Sys when the electronic settlement system Sys according to this modification example executes online electronic settlement. Note that the electronic settlement system Sys according to this modification example has the same configuration as the electronic settlement system Sys according to the embodiment.

[0328] As shown in FIG. 36, in this modification example, the control device 11 of the terminal device 1[q] starts the settlement application by executing the electronic settlement program PG-T based on the operation of the user U[q] (S1).

[0329] Thereafter, the control device 11 of the terminal device 1[q] executes offline code image display processing (S2), whereby the terminal device 1[q] displays the offline code image GY[q] on the display device 13.

[0330] Thereafter, the control device 11 of the terminal device 1[q] executes offline blockage determination processing (S8). Note that the flowchart shown in FIG. 33 assumes that the payment device 3 is not in an offline blockage state. Furthermore, if the offline blockage determination processing of step S8 determines that the payment device 3 is in an offline blockage state, the control device 11 of the terminal device 1[q] suspends the display of the offline code image GY[q] on the display device 13. Furthermore, if the offline blockage determination processing of step S8 determines that the payment device 3 is in an offline blockage state, the electronic payment system Sys executes the payment-related processing of step S3 after executing the online code image display processing of step S4.

[0331] Next, the electronic payment system Sys executes payment-related processing (S3). Thereafter, the electronic payment system Sys executes an online code image display process (S4). Then, the electronic payment system Sys executes offline token acquisition processing (S5).

[0332] FIG. 37 is a sequence chart showing an example of normal operation of the electronic payment system Sys according to this modification when the electronic payment system Sys executes online electronic payment.

[0333] As shown in FIG. 37, in this modification, the control device 11 of the terminal device 1[q] in the electronic payment system Sys starts up the payment application (S1).

[0334] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the electronic payment system Sys executes the processing of steps S21 to S25 described above as the offline code image display processing of step S2. As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24).

[0335] Next, the electronic payment system Sys executes offline blockage determination processing (S8). Specifically, the electronic payment system Sys executes the processing of steps S81 to S84 described above as the offline blockage determination processing of step S8. Note that the sequence chart shown in FIG. 37 assumes that the offline payment processing execution function of the payment device 3 is not in a blocked state, that is, that the payment device 3 is able to execute offline payment processing. However, if the offline blockage determination processing of step S8 results in the payment device 3 being in an offline blockage state, the display control unit 114 of the terminal device 1[q] suspends the display of the offline code image GY[q] on the display device 13.

[0336] Next, the electronic payment system Sys executes the above-mentioned payment-related process (S3). Specifically, the electronic payment system Sys executes the above-mentioned steps S31 to S35 as the payment-related process of step S3. Then, the electronic payment system Sys executes the above-mentioned online code image display process (S4) (not shown). Specifically, the electronic payment system Sys executes the above-mentioned processes of steps S42 to S49 as the online code image display process of step S4. Thereafter, the electronic payment system Sys executes the offline token acquisition process (S5) described above (not shown). Specifically, the electronic payment system Sys executes the processes of steps S51 to S53 described above as the offline token acquisition process of step S5.

[0337] Thus, in this modification example, the terminal device 1[q] executes an offline occlusion determination process after the offline code image display process. That is, in this modification example, after the terminal device 1[q] executes the offline code image display process and displays the offline code image GY[q] on the display device 13, when the offline occlusion information DHY indicates that the settlement device 3 is in an offline occlusion state, the display of the offline code image GY[q] on the display device 13 is interrupted. Therefore, according to this modification example, for example, compared with a mode in which the offline occlusion determination process is not executed after the offline code image display process, the labor of the user U[q] related to the display of the offline code image GY[q] can be reduced.

[0338] <B.5. Modification Example 5> In the above-described embodiments and modification examples 1 to 4, the electronic payment system Sys has been illustrated and described by taking as an example a mode in which, after executing the offline code image display process in step S4, the offline token acquisition process in step S5 is started. However, the present invention is not limited to such a mode. The electronic payment system Sys may start part or all of the processes of the offline code image display process in step S4 after starting part or all of the processes of the offline token acquisition process in step S5.

[0339] FIG. 38 is a flowchart showing an example of an outline of the normal operation of the electronic payment system Sys when the electronic payment system Sys according to this modification example executes online electronic payment. Note that the electronic payment system Sys according to this modification example is assumed to have the same configuration as the electronic payment system Sys according to the embodiment.

[0340] As shown in FIG. 38, in this modification example, the control device 11 of the terminal device 1[q] starts the payment application by executing the electronic payment program PG-T based on the operation of the user U[q] (S1). Thereafter, the control device 11 of the terminal device 1[q] executes an offline code image display process (S2). As a result, the terminal device 1[q] displays the offline code image GY[q] on the display device 13. Next, the electronic payment system Sys executes payment-related processing (S3). Next, the electronic payment system Sys executes offline token acquisition processing (S5). Thereafter, the electronic payment system Sys executes online code image display processing (S4).

[0341] As described above, in this modified example, the terminal device 1[q] executes acquisition of the offline token KY[q] and the encryption key KS[q] by offline token acquisition processing before display of the online code image GX[q] by online code image display processing. For this reason, according to this modified example, compared with the mode of acquiring the offline token KY[q] and the encryption key KS[q] after display of the online code image GX[q], the terminal device 1[q] can acquire the offline token KY[q] and the encryption key KS[q] more reliably. Thereby, according to this modified example, compared with the mode of acquiring the offline token KY[q] and the encryption key KS[q] after display of the online code image GX[q], the possibility of displaying the offline code image GY[q] based on the valid offline token KY[q] in the offline code image display processing executed by the terminal device 1[q] can be increased, and the possibility of execution of offline electronic payment by the user U[q] of the terminal device 1[q] can be increased.

[0342] <B.6. Modified Example 6> In the above-described embodiments and Modified Examples 1 to 5, the mode in which the terminal device 1[q] executes acquisition of the online token KX[q] and acquisition of the offline token KY[q] at different timings during electronic payment has been exemplified and described, but the present invention is not limited to such a mode. The terminal device 1[q] may acquire the online token KX[q] and the offline token KY[q] simultaneously during electronic payment.

[0343] FIG. 39 is a sequence chart showing an example of the normal operation of the electronic payment system Sys when the electronic payment system Sys according to this modified example executes online electronic payment.

[0344] Although not shown in Figure 39, in this modified example, the electronic payment system Sys launches the payment app (S1), then executes offline code image display processing (S2), executes payment-related processing (S3), and then executes online code image display processing (S4).

[0345] 39, the communication status determination unit 115 of the terminal device 1[q] determines whether the communication status of the terminal device 1[q] is online in the online code image display process of step S4 (S41). Note that the sequence chart shown in FIG. 39 assumes that the communication status of the terminal device 1[q] is online. Next, the information transmission unit 111 of the terminal device 1[q] transmits a blockage information request BXY in the online code image display process of step S4 (S92). Here, the blockage information request BXY is a telegram requesting the online blockage information DHX and the offline blockage information DHY. Next, in the online code image display processing of step S4, the control device 31 of the payment device 3 supplies online blockage information DHX and offline blockage information DHY to the terminal device 1[q] in response to the blockage information request BXY supplied from the terminal device 1[q] in step S92 (S93). Next, the information transmission unit 111 of the terminal device 1[q] transmits a token request RXY to the payment device 3 in the online code image display process of step S4 (S94). Here, the token request RXY is a message requesting the online token KX[q], offline token KY[q], and encryption key KS[q]. Then, in the online code image display processing of step S4, the control device 31 of the payment device 3 supplies the online token KX[q], offline token KY[q], and encryption key KS[q] to the terminal device 1[q] in response to the token request RXY supplied from the terminal device 1[q] in step S94 (S95). Next, in the online code image display process of step S4, the information acquisition unit 112 of the terminal device 1[q] acquires the offline token KY[q] and the encryption key KS[q] supplied from the payment device 3 in step S95, and stores the acquired offline token KY[q] and encryption key KS[q] in the storage device 12 (S53). Next, as the online code image display process of step S4, the control device 11 of the terminal device 1[q] executes the processes of steps S46 to S48 described above. Thereafter, the electronic payment system Sys executes an offline token acquisition process (S5).

[0346] According to this modification example, at the timing of performing electronic payment, the offline token KY[q] is acquired from the payment device 3 and the offline token KY[q] is stored in the storage device 12. Therefore, according to this embodiment, when it is difficult to perform online electronic payment due to a communication failure or the like, it is possible to reduce the possibility that even offline electronic payment becomes difficult to execute.

[0347] <B.7. Modification Example 7> In the above-described embodiments and modification examples 1 to 3, the mode in which the online token valid time TSX, the offline token valid time TSY, and the update unit time TC are notified from the payment device 3 as the setting information DS has been illustrated and described. However, the present invention is not limited to such a mode. Part or all of the online token valid time TSX, the offline token valid time TSY, and the update unit time TC may be stored as fixed values in the storage device 12 of the terminal device 1[q].

[0348] <B.8. Modification Example 8> In the above-described embodiments and modification examples 1 to 7, the case where the congestion information DH is information indicating whether the payment device 3 can execute the payment process has been illustrated and described. However, the present invention is not limited to such a mode. The congestion information DH may be information indicating whether the payment device ۳ can execute the payment process by each payment method.

[0349] Specifically, in this modification, the online blockage information DHX includes online combined payment blockage information DHX1 indicating whether online payment processing by telephone bill combined payment is executable, online balance payment blockage information DHX2 indicating whether online payment processing by prepaid balance payment is executable, and online card payment blockage information DHX3 indicating whether online payment processing by credit card payment is executable. Here, the online combined payment blockage information DHX1 may be information indicating whether the functions of the payment device 3 for executing online payment processing by telephone bill combined payment are operating without being blocked. Furthermore, the online balance payment blockage information DHX2 may be information indicating whether the functions of the payment device 3 for executing online payment processing by prepaid balance payment are operating without being blocked. Furthermore, the online card payment blockage information DHX3 may be information indicating whether the functions of the payment device 3 for executing online payment processing by credit card payment are operating without being blocked. Note that, hereinafter, the online combined payment blockage information DHX1, the online balance payment blockage information DHX2, and the online card payment blockage information DHX3 may be collectively referred to as individual online blockage information DHX0. In this modification, the offline blockage information DHY includes offline combined payment blockage information DHY1 indicating whether offline payment processing using telephone bill combined payment is possible, offline balance payment blockage information DHY2 indicating whether offline payment processing using prepaid balance payment is possible, and offline card payment blockage information DHY3 indicating whether offline payment processing using credit card payment is possible. Here, the offline combined payment blockage information DHY1 may be information indicating whether the functions of the payment device 3 for executing offline payment processing using telephone bill combined payment are operating without being blocked. Furthermore, the offline balance payment blockage information DHY2 may be information indicating whether the functions of the payment device 3 for executing offline payment processing using prepaid balance payment are operating without being blocked. Furthermore, the offline card payment blockage information DHY3 may be information indicating whether the functions of the payment device 3 for executing offline payment processing using credit card payment are operating without being blocked. Note that, hereinafter, the offline combined payment blockage information DHY1, the offline balance payment blockage information DHY2, and the offline card payment blockage information DHY3 may be collectively referred to as individual offline blockage information DHY0.

[0350] In this modified example, in response to an online blockage information request BX from terminal device 1[q], payment device 3 may supply terminal device 1[q] with the individual online blockage information DHX0 corresponding to the payment method selected by user U[q] of terminal device 1[q], out of the three individual online blockage information DHX0 contained in the online blockage information DHX. Furthermore, in this modification, in response to an offline blockage information request BY from the terminal device 1[q], the payment device 3 may supply to the terminal device 1[q] the individual offline blockage information DHY0 corresponding to the payment method selected by the user U[q] of the terminal device 1[q], out of the three individual offline blockage information DHY0 included in the offline blockage information DHY. Furthermore, in this modification, in response to an offline blockage information request BY from the terminal device 1[q], the payment device 3 may supply to the terminal device 1[q] the three individual offline blockage information DHY0 included in the offline blockage information DHY.

[0351] Furthermore, in the above-described embodiment and variations 1 to 7, an example has been described in which the payment device 3 supplies the terminal device 1[q] with an online token KX[q] common to multiple payment methods and an offline token KY[q] common to multiple payment methods, regardless of the payment method selected by the user U[q] of the terminal device 1[q], but the present invention is not limited to such an example. For example, the payment device 3 may supply the terminal device 1[q] with one or more offline tokens KY[q] that correspond one-to-one to one or more payment methods selectable by the user U[q] of the terminal device 1[q].

[0352] Specifically, in this modification, in response to an offline token request RY from the terminal device 1[q], the payment apparatus 3 supplies the terminal device 1[q] with a combined payment offline token KY1[q], which is an offline token KY[q] corresponding to combined telephone bill payment, a balance payment offline token KY2[q], which is an offline token KY[q] corresponding to prepaid balance payment, and a card payment offline token KY3[q], which is an offline token KY[q] corresponding to credit card payment. Note that, hereinafter, the combined payment offline token KY1[q], the balance payment offline token KY2[q], and the card payment offline token KY3[q] may be collectively referred to as individual offline token KY0[q]. In other words, in this modification, in response to an offline token request RY from the terminal device 1[q], the payment apparatus 3 supplies the terminal device 1[q] with three individual offline tokens KY0[q], which correspond one-to-one to the three payment methods selectable by the user U[q] of the terminal device 1[q].

[0353] In this modification, the code generation unit 113 of the terminal device 1[q] generates an offline payment code CY[q] based on an individual offline token KY0[q] corresponding to the payment method selected by the user U[q] of the terminal device 1[q]. Specifically, in this modification, the code generation unit 113 of the terminal device 1[q] generates the offline payment code CY[q] based on the offline token KY1[q] for combined payment when the payment method selected by the user U[q] of the terminal device 1[q] is combined payment for telephone charges, generates the offline payment code CY[q] based on the offline token KY2[q] for balance payment when the payment method selected by the user U[q] of the terminal device 1[q] is prepaid balance payment, and generates the offline payment code CY[q] based on the offline token KY3[q] for card payment when the payment method selected by the user U[q] of the terminal device 1[q] is credit card payment.

[0354] In addition, in this modified example, the display control unit 114 of the terminal device 1[q] determines whether or not to display on the display device 13 an offline code image GY[q] based on the individual offline token KY0[q] corresponding to the payment method selected by the user U[q] of the terminal device 1[q], based on the individual offline blockage information DHY0 corresponding to the payment method selected by the user U[q] of the terminal device 1[q]. Specifically, in this modified example, if the payment method selected by user U[q] of terminal device 1[q] is combined telephone bill payment, it is determined based on the offline combined payment blocking information DHY1 whether or not to display the offline code image GY[q] based on the offline token KY1[q] for combined payment; if the payment method selected by user U[q] of terminal device 1[q] is prepaid balance payment, it is determined based on the offline balance payment blocking information DHY2 whether or not to display the offline code image GY[q] based on the offline token KY2[q] for balance payment; and if the payment method selected by user U[q] of terminal device 1[q] is credit card payment, it is determined based on the offline card payment blocking information DHY3 whether or not to display the offline code image GY[q] based on the offline token KY3[q] for card payment.

[0355] In addition, in this modified example, the settlement device 3 may supply three online tokens KX[q] to the terminal device 1[q], which correspond one-to-one to three types of payment methods that can be selected by the user U[q] of the terminal device 1[q]. Further, in this modified example, the settlement device 3 may supply one online token KX[q] to the terminal device 1[q], which corresponds to one payment method selected by the user U[q] of the terminal device 1[q] among the three online tokens KX[q] that correspond one-to-one to the three types of payment methods that can be selected by the user U[q] of the terminal device 1[q].

[0356] As described above, according to this modified example, since the display presence or absence of the offline code image GY[q] can be finely controlled according to the blockage situation for each payment method selected by the user U[q] of the terminal device 1[q], it is possible to reduce the labor of the user U[q] and improve the convenience of the user U[q] as compared with a mode that does not consider the payment method.

[0357] <B.9. Modified Example 9> In the above-described embodiments and Modified Examples 1 to 8, an example of an aspect in which the terminal device 1[q] can display the offline code image GY[q] based on the offline token KY[q][M] stored in the storage device 12, and the terminal device 1[q] can display the online code image GX[q] based on the offline token KY[q] supplied from the settlement device 3 has been illustrated. However, the present invention is not limited to such an aspect. For example, based on the state of the user U[q] of the terminal device l[q], the display function of the online code image GX[q] and the display function of the offline code image GY[q] in the terminal device 1[q] may be restricted.

[0358] FIG. 40 is a sequence chart showing an example of the operation of the electronic settlement system Sys when the electronic settlement system Sys according to this modified example performs online electronic settlement.

[0359] As shown in FIG. 40, in this modification, the control device 11 of the terminal device 1[q] in the electronic payment system Sys starts up the payment application (S1).

[0360] Next, the electronic payment system Sys executes offline code image display processing (S2). Specifically, the electronic payment system Sys executes the processing of steps S21 to S25 described above (some parts are omitted from the illustration) as the offline code image display processing of step S2. As a result, the display control unit 114 of the terminal device 1[q] causes the display device 13 to display the offline code image GY[q] (S24).

[0361] Next, the electronic payment system Sys executes the above-mentioned steps S41 to S43 in the online code image display process (S4). After that, the terminal device 1[q] transmits an online token request RX to the payment device 3 (S44).

[0362] Next, in the online code image display process, the payment device 3 determines the validity of the user U[q] corresponding to the user identification information DID[q] included in the online token request RX based on the online token request RX acquired in step S43 (SA1). Here, "validity of user U[q]" is a concept that includes "validity related to user U[q]'s ability to pay" and "validity related to user U[q]'s personal authentication." Among these, "user U[q]'s ability to pay" refers to, for example, the ability to pay required for user U[q] to receive electronic payment services from electronic payment system Sys. For example, if user U[q] has the ability to pay required for receiving electronic payment services from electronic payment system Sys, user U[q]'s ability to pay may be deemed valid. Also, for example, if user U[q] has been in arrears multiple times in the past for electronic payment services provided by electronic payment system Sys, user U[q]'s ability to pay may be deemed invalid. Furthermore, "validity of user U[q]'s identity authentication" means, for example, that there is no possibility of impersonation of user U[q], and user U[q] himself / herself operates terminal device 1[q] to receive electronic payment services. For example, if user U[q] contacts the administrator of electronic payment system Sys to request that electronic payment services be stopped because he / she has lost terminal device 1[q], user U[q]'s identity authentication may be deemed invalid. Also, for example, if user U[q] contacts the administrator of electronic payment system Sys to request that electronic payment services be stopped because authentication information managed by user U[q] has been leaked, user U[q]'s identity authentication may be deemed invalid. In the example shown in FIG. 40, it is assumed that the user U[q] is not valid.

[0363] If the determination result in step SA1 is that the validity of user U[q] is "not valid," the payment device 3 transmits an online token rejection notice ZX to the terminal device 1[q] (SA2). Here, the online token rejection notice ZX is a notice from the payment device 3 to the terminal device 1[q] that the supply of the online token KX[q] is rejected. Note that the online token rejection notice ZX may include a notice that the validity of user U[q] is "not valid."

[0364] When the terminal device 1[q] receives the online token rejection notification ZX from the settlement device 3, it executes the code image blocking process (SB). Specifically, the terminal device 1[q] executes online code image blocking processing in the code image blocking processing (SB1). Here, the online code image blocking processing is processing to block the display function of the online code image GX[q] in the payment application. Furthermore, the terminal device 1[q] executes offline code image blocking processing in the code image blocking processing (SB2). Here, the offline code image blocking processing is processing for blocking the display function of the offline code image GY[q] in the payment application. Then, in the code image occlusion process, the terminal device 1[q] changes the offline code image GY[q] displayed on the display device 13 in step S24 to a non-display state (SB3).

[0365] As described above, according to this modification example, when the validity related to the payment ability of the user U[q] is lost, or when the validity related to the authentication of the user U[q] is lost, etc., when the validity of the user U[q] is lost, the terminal device 1[q] blocks the display function of the code image GG[q] in the payment application of the terminal device 1[q]. Therefore, according to this modification example, it is possible to prevent the situation where a service related to electronic payment is illegally used using the terminal device 1[q].

[0366] <C. Supplementary Note> Aspects related to the above embodiments and modification examples are appended below. For ease of understanding of each aspect, hereinafter, the description will be given with reference numerals of the drawings appended, but the present invention is not intended to be limited to the illustrated aspects.

[0367] <Supplementary Note 1> The electronic payment program PG-T according to Supplementary Note 1 is an electronic payment program PG-T installed in the terminal device 1[q] that can communicate with the payment device 3. When the terminal device 1[q] can communicate with the payment device 3, the processor of the terminal device 1[q] functions as an information acquisition unit 112 that acquires the online token KX[q] from the payment device 3, and when the information acquisition unit 112 acquires the online token KX[q], it functions as a display control unit 114 that displays the online code image GX[q] based on the online token KX[q] on the display device 13 of the terminal device 1[q]. The display control unit 114 displays the offline code image GY[q] based on the offline token KY[q] stored in the storage device 12 of the terminal device 1[q] on the display device 13 regardless of the communication state of the terminal device 1[q] when the electronic payment program PG-T is activated. This is the feature.

[0368] According to Supplementary Note 1, after the electronic payment program PG-T is launched, an offline code image GY[q] based on the offline token KY[q] is displayed regardless of the communication state of the terminal device 1[q]. Therefore, according to Supplementary Note 1, it is possible to shorten the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service, compared to an embodiment in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched. As a result, according to Supplementary Note 1, it is possible to improve the convenience for the user U[q], compared to an embodiment in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched.

[0369] <Appendix 2> The electronic payment program PG-T according to Appendix 2 is the electronic payment program PG-T described in Appendix 1, characterized in that after the electronic payment program PG-T is launched, when the information acquisition unit 112 acquires an online token KX[q], the display control unit 114 switches the image to be displayed on the display device 13 from the offline code image GY[q] to an online code image GX[q] based on the online token KX[q] acquired by the information acquisition unit 112.

[0370] According to Supplementary Note 2, after the electronic payment program PG-T is launched on the terminal device 1[q], the offline code image GY[q] is displayed until the online token KX[q] is acquired. Therefore, according to Supplementary Note 2, it is possible to shorten the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service, compared to an embodiment in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched. As a result, according to Supplementary Note 2, it is possible to improve the convenience for the user U[q], compared to an embodiment in which the offline code image GY[q] is not displayed after the electronic payment program PG-T is launched.

[0371] <Appendix 3> The electronic payment program PG-T according to Appendix 3 is the electronic payment program PG-T described in Appendix 1 or Appendix 2, characterized in that it further causes the processor of the terminal device 1[q] to function as a communication status determination unit 115 that determines the communication status of the terminal device 1[q], and the display control unit 114 causes the display device 13 to display an offline code image GY[q] after the electronic payment program PG-T is launched and before the communication status determination unit 115 outputs the determination result of the communication status of the terminal device 1[q].

[0372] According to Supplementary Note 3, in the terminal device 1[q], the display control unit 114 has priority over the communication status determination unit 115 in displaying the offline code image GY[q]. Therefore, according to Supplementary Note 3, it is possible to shorten the waiting time until the user U[q] of the terminal device 1[q] receives the electronic payment service, compared to an aspect in which the terminal device 1[q] has priority over the communication status determination unit 115 in displaying the offline code image GY[q].

[0373] <Appendix 4> The electronic payment program PG-T according to Appendix 4 is the electronic payment program PG-T described in Appendix 1 to Appendix 3, characterized in that after the electronic payment program PG-T is launched, the information acquisition unit 112 acquires offline blockage information DHY indicating whether or not the offline payment processing executed in the payment device 3 based on the offline code image GY[q] can be executed when communication between the terminal device 1[q] and the payment device 3 is difficult, before the display control unit 114 displays the offline code image GY[q] on the display device 13.

[0374] According to Supplementary Note 4, when the payment apparatus 3 is in an offline blocked state and it is difficult to execute the offline payment process, the terminal device 1[q] executes a process of acquiring offline blockage information DHY indicating that the payment apparatus 3 is in an offline blocked state prior to a process of displaying the offline code image GY[q] on the display device 13. Therefore, according to Supplementary Note 4, when the payment apparatus 3 is in an offline blocked state, it is possible to prevent the offline code image GY[q] from being displayed on the terminal device 1[q]. As a result, according to Supplementary Note 4, it is possible to prevent in advance the burden on the user U[q] that would be caused by the terminal device 1[q] executing a process of displaying the offline code image GY[q] even though it is difficult to execute the offline payment process on the payment apparatus 3.

[0375] <Appendix 5> The electronic payment program PG-T according to Appendix 5 is the electronic payment program PG-T described in Appendix 1 to Appendix 3, and is characterized in that the information acquisition unit 112 acquires offline blockage information DHY indicating whether or not the offline payment processing executed based on the offline code image GY[q] in the payment device 3 can be executed when communication between the terminal device 1[q] and the payment device 3 is difficult after the electronic payment program PG-T is started and the display control unit 114 displays the offline code image GY[q] on the display device 13.

[0376] According to Supplementary Note 5, when the payment apparatus 3 is in an offline blocked state and it is difficult to execute the offline payment process, the terminal device 1[q] executes a process of displaying the offline code image GY[q] on the display device 13, and then executes a process of acquiring offline blockage information DHY indicating that the payment apparatus 3 is in an offline blocked state. Therefore, according to Supplementary Note 5, when the payment apparatus 3 is in an offline blocked state, it is possible to prevent the terminal device 1[q] from continuing to display the offline code image GY[q]. As a result, according to Supplementary Note 5, it is possible to prevent the burden on the user U[q] that would be caused by the terminal device 1[q] continuing to display the offline code image GY[q] even though it is difficult to execute the offline payment process in the payment apparatus 3.

[0377] <Appendix 6> The electronic payment program PG-T according to Appendix 6 is the electronic payment program PG-T described in Appendix 1 to Appendix 5, characterized in that the information acquisition unit 112 acquires an offline token KY[q] from the payment device 3 during the period from when the electronic payment program PG-T is launched until when the electronic payment program PG-T is terminated, and stores the acquired offline token KY[q] in the memory device 12.

[0378] According to Appendix 6, during the period in which the electronic payment program PG-T is running, both the online token KX[q] and the offline token KY[q], i.e., the token KK[q], are obtained. Therefore, compared to the mode in which only one of the online token KX[q] and the offline token KY[q], the token KK[q], i.e., the token KK[q], can be obtained reliably during that period.

[0379] <Appendix 7> The electronic payment program PG-T according to Appendix 7 is the electronic payment program PG-T described in Appendix 1 to Appendix 6, characterized in that after the electronic payment program PG-T is launched, when the information acquisition unit 112 acquires an online token KX[q], the display control unit 114 switches the image to be displayed on the display device 13 from the offline code image GY[q] to an online code image GX[q] based on the online token KX[q] acquired by the information acquisition unit 112, and the information acquisition unit 112 acquires an offline token KY[q] from the payment device 3 during the period from when the display control unit 114 displays the online code image GX[q] on the display device 13 until the electronic payment program PG-T is terminated, and stores the acquired offline token KY[q] in the memory device 12.

[0380] According to Appendix 7, the terminal device 1[q] acquires the offline token KY[q] after displaying the online code image GX[q], thereby reducing the possibility of delay in displaying the online code image GX[q] compared to a case where the terminal device 1[q] acquires the offline token KY[q] before displaying the online code image GX[q].

[0381] <Appendix 8> The electronic payment program PG-T according to Appendix 8 is the electronic payment program PG-T described in Appendix 1 to Appendix 7, characterized in that the offline token KY[q] has an offline token validity period TY[q] set therein, which is the validity period of the offline token KY[q], and the display control unit 114, when an offline token KY[q] within the offline token validity period TY[q] is stored in the storage device 12, displays an offline code image GY[q] based on the offline token KY[q] on the display device 13, and when an offline token KY[q] within the offline token validity period TY[q] is not stored in the storage device 12, does not display the offline code image GY[q] on the display device 13.

[0382] According to Appendix 8, it is possible to prevent offline electronic payments from being made using an expired offline token KY[q], thereby increasing the security level of offline electronic payments compared to when the offline token KY[q] does not have an expiration date.

[0383] <Appendix 9> The electronic payment program PG-T according to Appendix 9 is the electronic payment program PG-T described in Appendix 1 to Appendix 8, and is characterized in that, when the memory device 12 stores multiple offline tokens KY[q][1] to KY[q][M], the display control unit 114 causes the display device 13 to display an offline code image GY[q] based on the offline token KY[q][M] that the information acquisition unit 112 last acquired from the payment device 3 out of the multiple offline tokens KY[q][1] to KY[q][M].

[0384] According to Appendix 9, offline electronic payments are made using the latest offline token KY[q][M], which increases the security level of offline electronic payments compared to when offline electronic payments are made using a non-latest offline token KY[q][M-1].

[0385] <Appendix 10> The electronic payment program PG-T according to Appendix 10 is the electronic payment program PG-T described in Appendix 1 to Appendix 9, characterized in that the online token KX[q] is a token KK[q] used in the payment device 3 to decide whether to carry out payment processing corresponding to user U[q] of terminal device 1[q] when communication between terminal device 1[q] and payment device 3 is possible, and the offline token KY[q] is a token KK[q] used in the payment device 3 to decide whether to carry out payment processing corresponding to user U[q] of terminal device 1[q] when communication between terminal device 1[q] and payment device 3 is difficult.

[0386] According to Appendix 10, electronic payment can be performed not only when the terminal device 1[q] and the payment device 3 can communicate with each other, but also when communication between the terminal device 1[q] and the payment device 3 is difficult, thereby preventing a decrease in convenience for the user U[q] of the terminal device 1[q] due to poor communication.

[0387] <Appendix 11> The electronic payment program PG-T according to Appendix 11 is the electronic payment program PG-T described in Appendix 1 to Appendix 10, characterized in that the display control unit 114 displays an offline code image GY[q] on the display device 13 based on a time encryption code TT[q] obtained by encrypting a terminal time value AG based on the terminal time TG of the terminal device 1[q] using an encryption key KS[q] stored in the memory device 12, and an offline token KY[q].

[0388] According to Appendix 11, in addition to the offline token KY[q], the offline code image GY[q] is displayed using the time encryption code TT[q], thereby increasing the security level of offline electronic payments compared to a mode in which the offline code image GY[q] is displayed without using the time encryption code TT[q].

[0389] <Appendix 12> The electronic payment program PG-T according to Supplementary Note 12 is the electronic payment program PG-T described in Supplementary Note 1 to Supplementary Note 11, characterized in that the display control unit 114 changes the offline code image GY[q] displayed on the display device 13 of the terminal device 1[q] to a hidden state when the information acquisition unit 112 acquires an online token rejection notification ZX from the payment device 3. Note that in Supplementary Note 12, the online token rejection notification ZX is an example of a "specific notification regarding the user of the terminal."

[0390] According to Supplementary Note 12, when the validity regarding the payment ability of user U[q] is lost, or when the validity regarding the authentication of user U[q] is lost, etc., when user U[q] is in a specific state, the display function of the code image GG[q] in the payment application of the terminal device 1[q] is blocked. For this reason, it is possible to prevent the occurrence of a situation where a service related to electronic payment is illegally used using the terminal device 1[q].

[0391] <D. Others> (1) In the above-described embodiments (including modifications. The same applies hereinafter), the storage device 12 and the storage device 32 were exemplified as ROM and RAM, but flexible disks, magneto-optical disks (e.g., compact disks, digital versatile disks, Blu-ray (registered trademark) disks), smart cards, flash memory devices (e.g., cards, sticks, key drives), CD-ROM (Compact Disc-ROM), registers, removable disks, hard disks, floppy (registered trademark) disks, magnetic strips, databases, servers, and other appropriate storage media. Also, the program may be transmitted from a network via a telecommunication line. Also, the program may be transmitted from the communication network NET via a telecommunication line.

[0392] (2) In the above-described embodiments, the information, signals, etc. described may be represented using any of various different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0393] (3) In the above-described embodiments, the input / output information, etc. may be stored in a specific location (e.g., memory), or may be managed using a management table. The input / output information, etc. may be overwritten, updated, or appended. The output information, etc. may be deleted. The input information, etc. may be transmitted to other devices.

[0394] (4) In the above-described embodiment, the determination may be made by a value (0 or 1) represented using one bit, by a Boolean value (true or false), or by a comparison of numerical values (e.g., comparison with a predetermined value).

[0395] (5) The order of the process procedures, sequences, flowcharts, etc. illustrated in the above-described embodiments may be rearranged unless inconsistent. For example, the methods described in this disclosure present elements of various steps using an example order, and are not limited to the particular order presented.

[0396] (6) Each function illustrated in Figures 2 and 3 is realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, by wire, wirelessly, etc.) and these multiple devices. A functional block may also be realized by combining software with the single device or the multiple devices.

[0397] (7) The programs exemplified in the above-described embodiments should be broadly construed to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., regardless of whether they are called software, firmware, middleware, microcode, hardware description language, or by other names.

[0398] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.

[0399] (8) In each of the foregoing embodiments, the terms "system" and "network" are used interchangeably.

[0400] (9) The information, parameters, etc. described in this disclosure may be expressed using absolute values, relative values from a predetermined value, or corresponding other information.

[0401] (10) In the above-described embodiments, the terminal device 1[q] may be a mobile station (MS). Those skilled in the art may also refer to a mobile station as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other appropriate term. In this disclosure, the terms "mobile station," "user terminal," "user equipment (UE)," "terminal," etc. may be used interchangeably.

[0402] (11) In the above-described embodiments, the terms "connected," "coupled," or any variations thereof refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using at least one of one or more wires, cables, and printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.

[0403] (12) In the above embodiments, the phrase "based on" does not mean "based only on," unless otherwise specified. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0404] (13) As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching in a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like. Furthermore, "judgment" and "decision" can include regarding resolving, selecting, choosing, establishing, comparing, etc. as having been "judged" or "decided." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Furthermore, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.

[0405] (14) In the above embodiments, when "include," "including," and variations thereof are used, these terms are intended to be inclusive, similar to the term "comprising." Furthermore, the term "or" as used in this disclosure is not intended to be an exclusive or.

[0406] (15) In this disclosure, where articles are added by translation, such as a, an, and the in English, this disclosure may include that the nouns following these articles are plural.

[0407] (16) In this disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "combined" may also be interpreted in the same way as "different."

[0408] (17) Each aspect / embodiment described in this disclosure may be used alone, in combination, or switched depending on the implementation. Notification of predetermined information (e.g., notification that "X is true") is not limited to explicit notification, but may be implicit (e.g., not notifying the predetermined information).

[0409] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is for illustrative purposes only and does not have any limiting meaning on the present disclosure. [Explanation of symbols]

[0410] 1[q]...terminal device, 3...payment device, 5...store device, 11...control device, 12...storage device, 13...display device, 14...input device, 15...communication device, 31...control device, 32...storage device, 35...communication device, 111...information transmission unit, 112...information acquisition unit, 113...code generation unit, 114...display control unit, 115...communication status determination unit, 311...information supply unit, 312...information reception unit, 313...payment processing unit.

Claims

1. An electronic payment program installed on a terminal capable of communicating with a payment device, a processor of the terminal, an acquisition unit that acquires a first token from the payment device when the terminal is able to communicate with the payment device; a display control unit that, when the acquisition unit acquires the first token, displays, on a display device of the terminal, a first code image showing a first code including the first token, the first code image being used in online electronic payment when the terminal and the payment device are capable of communicating with each other; and make it work, The display control unit When the electronic payment program is started, regardless of the communication status of the terminal, displaying on the display device a second code image showing a second code including a second token stored in a storage device of the terminal, the second code image being used for offline electronic payment when communication between the terminal and the payment device is difficult; When the acquiring unit acquires the first token after the electronic payment program is started, switching the image to be displayed on the display device from the second code image to the first code image based on the first token acquired by the acquisition unit; An electronic payment program comprising:

2. a processor of the terminal, further functioning as a communication status determination unit that determines the communication status of the terminal; The display control unit After the electronic payment program is started, and before the communication status determination unit outputs the determination result of the communication status of the terminal, displaying the second code image on the display device; 2. The electronic payment program according to claim 1.

3. The acquisition unit After the electronic payment program is started, and before the display control unit causes the display device to display the second code image, When communication between the terminal and the payment device is difficult, offline blockage information indicating whether or not offline payment processing to be executed based on the second code image in the payment device is executable is acquired.

2. The electronic payment program according to claim 1.

4. The acquisition unit After the electronic payment program is started and the display control unit displays the second code image on the display device, When communication between the terminal and the payment device is difficult, offline blockage information indicating whether or not offline payment processing to be executed based on the second code image in the payment device is executable is acquired.

2. The electronic payment program according to claim 1.

5. The acquisition unit During the period from when the electronic payment program is started until when the electronic payment program is terminated, acquiring the second token from the payment device and storing the acquired second token in the storage device; 2. The electronic payment program according to claim 1.

6. The display control unit When the acquiring unit acquires the first token after the electronic payment program is started, switching an image to be displayed on the display device from the second code image to the first code image based on the first token acquired by the acquisition unit; The acquisition unit During a period from when the display control unit displays the first code image on the display device until when the electronic payment program is terminated, acquiring the second token from the payment device and storing the acquired second token in the storage device; 2. The electronic payment program according to claim 1.

7. The display control unit When the acquisition unit acquires a specific notification regarding the user of the terminal from the payment device, changing the second code image displayed on the display device of the terminal to a hidden state; 2. The electronic payment program according to claim 1.

8. A terminal capable of communicating with a payment device, an acquisition unit that acquires a first token from the payment device when the terminal is able to communicate with the payment device; a display control unit that, when the acquisition unit acquires the first token, displays, on a display device of the terminal, a first code image showing a first code including the first token, the first code image being used in online electronic payment when the terminal and the payment device are capable of communicating with each other; Equipped with The display control unit When the electronic payment program installed on the terminal is started, regardless of the communication status of the terminal, displaying on the display device a second code image showing a second code including a second token stored in a storage device of the terminal, the second code image being used for offline electronic payment when communication between the terminal and the payment device is difficult; When the acquiring unit acquires the first token after the electronic payment program is started, switching the image to be displayed on the display device from the second code image to the first code image based on the first token acquired by the acquisition unit; A terminal characterized by:

9. A payment system comprising a payment device and a terminal capable of communicating with the payment device, The terminal an acquisition unit that acquires a first token from the payment device when the terminal is able to communicate with the payment device; a display control unit that, when the acquisition unit acquires the first token, displays, on a display device of the terminal, a first code image showing a first code including the first token, the first code image being used in online electronic payment when the terminal and the payment device are capable of communicating with each other; Equipped with The display control unit When the electronic payment program installed on the terminal is started, regardless of the communication status of the terminal, displaying on the display device a second code image showing a second code including a second token stored in a storage device of the terminal, the second code image being used for offline electronic payment when communication between the terminal and the payment device is difficult; When the acquiring unit acquires the first token after the electronic payment program is started, switching the image to be displayed on the display device from the second code image to the first code image based on the first token acquired by the acquisition unit; A payment system characterized by:

Citation Information

Patent Citations

  • Information processing method, program, and terminal

    JP2021021992A

  • Application program, payment control method, payment server, program, and payment system

    JP2024165498A

  • Application program, electronic payment method, and terminal device

    JP7620155B1

  • Payment server, payment control method, and program

    JP7391263B1

  • JPP7620155B