Payment Methods and Systems for Central Bank Digital Currencies

The HSM and TEE-based method secures offline CBDC transactions by verifying and recording payments, preventing double spending and ensuring transaction integrity, with synchronization upon reconnection.

JP7754582B2Active Publication Date: 2025-10-15LINE PLUS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2021151948
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-11-03
Filing Date
2021-09-17
Publication Date
2025-10-15
Estimated Expiration
2041-09-17

AI Technical Summary

Technical Problem

Existing payment systems for central bank digital currencies (CBDC) fail to prevent double payments and process transactions in offline situations where user terminals cannot connect to a server via a network.

Method used

A payment method utilizing a Hardware Security Module (HSM) and Trusted Execution Environment (TEE) to securely process transactions offline, involving nonce value transmission, signature verification, and recording transaction information in a secure area, with certificate authentication and synchronization upon reconnection.

Benefits of technology

Prevents double spending and enables secure offline payments using CBDC, ensuring transaction integrity and synchronization with the ledger upon reconnection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007754582000001
    Figure 0007754582000001
  • Figure 0007754582000002
    Figure 0007754582000002
  • Figure 0007754582000003
    Figure 0007754582000003
Patent Text Reader

Abstract

To provide a payment method and system that process payment using Central Bank Digital Currency (CBDC) while preventing double payment even in an offline situation.SOLUTION: A computer device includes a security area, a HSM (Hardware Security Module), and a processor. A payment method includes the stages of: transmitting a nonce value from a terminal of a last user who receives remittance by short-range communication in an offline situation; signing a remittance transaction containing first final transaction information recorded in the security area, the transmitted nonce value, and a hash value of a security value with a private key of the HSM and transmitting it to the terminal; transmitting an original of the security value to the terminal when a verification success message is received from the terminal; and recording second final transaction information by the remittance transaction and a latest balance of an electronic wallet in the security area.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The following description relates to settlement methods and systems for central bank digital currencies. [Background technology]

[0002] A central bank digital currency (CBDC) is an electronic form of currency issued by a central bank. CBDC implementation methods are classified into a single ledger method (account method), in which the central bank or a bank stores and manages CBDC accounts and related transaction information, and a distributed ledger method, in which multiple transaction participants manage the same transaction records. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Korean Patent No. 10-1862637 Summary of the Invention [Problem to be solved by the invention]

[0004] To provide a payment method and system that can prevent double payments and process payments using central bank digital currency (CBDC) even in offline situations (situations where a user's terminal device cannot connect to a server via a network). [Means for solving the problem]

[0005] a step of transmitting, by the at least one processor, a remittance transaction including first final transaction information recorded in the secure area, the transmitted nonce value, and a hash value of a security value, using a private key of the HSM, and transmitting the remittance transaction to the terminal; a step of transmitting, by the at least one processor, an original text of the security value to the terminal when a verification success message is received from the terminal; and a step of recording, by the at least one processor, second final transaction information and the latest balance of an electronic wallet resulting from the remittance transaction in the secure area.

[0006] A payment method for a computer device, the computer device comprising: a first security domain, an HSM (Hardware Security Module), a HSM (HSM Module) and at least one processor, the payment method comprising: transmitting, by the at least one processor, a nonce value to a terminal of an end user who sends remittance in an offline state via near field communication; receiving, by the at least one processor, a remittance transaction signed with a private key of the HSM of the terminal from the terminal (the remittance transaction includes first final transaction information recorded in a second secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value); verifying, by the at least one processor, a signature of the received remittance transaction; verifying, by the at least one processor, a nonce value included in the received remittance transaction; transmitting, by the at least one processor, a verification success message to the terminal if the signature verification and the verification of the nonce value are successful; recording, by the at least one processor, the received remittance transaction and the second final transaction in the first secure area; and receiving, by the at least one processor, an original of the security value that the terminal transmits in response to receiving the verification success message.

[0007] A computer program is provided that is recorded on a computer-readable recording medium and that, when combined with a computer device, causes the computer device to execute the method.

[0008] Provided is a computer device comprising: at least one processor implemented to execute computer-readable instructions; a secure area; and an HSM (Hardware Security Module), wherein the at least one processor receives a nonce value from a terminal of an end user receiving remittance via short-range communication in an offline state; signs a remittance transaction including first final transaction information recorded in the secure area, the transmitted nonce value, and a hash value of a security value using a private key of the HSM, and transmits the signed transaction to the terminal; and, upon receiving a verification success message from the terminal, transmits the original text of the security value to the terminal, and records second final transaction information and the latest balance of an electronic wallet resulting from the remittance transaction in the secure area.

[0009] a first secure area and an HSM (Hardware Security Module), the at least one processor being implemented to execute computer-readable instructions, transmitting a nonce value to a terminal of an end user who sends remittances by short-range communication in an offline state, receiving a remittance transaction signed with a private key of the HSM of the terminal from the terminal (the remittance transaction includes first final transaction information recorded in a second secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value), verifying a signature of the received remittance transaction and verifying the nonce value included in the received remittance transaction, and if the signature verification and the verification of the nonce value are successful, transmitting a verification success message to the terminal, recording the received remittance transaction and the second final transaction in the first secure area, and receiving an original of the security value that the terminal sends in response to receiving the verification success message. [Effects of the Invention]

[0010] Even in offline situations (when the user's device cannot connect to the server via the network), double spending can be prevented and payments can be processed using Central Bank Digital Currency (CBDC). [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 illustrates an example of a network environment in accordance with an embodiment of the present invention. [Figure 2] FIG. 1 is a block diagram illustrating an example of a computing device according to an embodiment of the present invention. [Figure 3] 2 is a diagram illustrating an example of the internal configuration of an end user terminal according to an embodiment of the present invention. [Figure 4] 1 is a flowchart illustrating an example method for making an online payment in accordance with one embodiment of the present invention. [Figure 5] 1 is a flowchart illustrating an example of an offline payment method in accordance with an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0012] <Summary of the Invention> a step of transmitting, by the at least one processor, a remittance transaction including first final transaction information recorded in the secure area, the transmitted nonce value, and a hash value of a security value, using a private key of the HSM, and transmitting the remittance transaction to the terminal; a step of transmitting, by the at least one processor, an original text of the security value to the terminal when a verification success message is received from the terminal; and a step of recording, by the at least one processor, second final transaction information and the latest balance of an electronic wallet resulting from the remittance transaction in the secure area.

[0013] According to one aspect, the security domain may be characterized as including a Trusted Execution Environment (TEE) security domain or a White-Box Cryptographic (WBC) security domain.

[0014] According to another aspect, in response to the offline state changing to an online state, the terminal may transmit the original text of the remittance transaction and the security value to a CBDC ledger, thereby synchronizing the transaction that occurred in the offline state.

[0015] According to another aspect, the payment method may further include exchanging a certificate with the terminal by the at least one processor to authenticate the terminal.

[0016] According to another aspect, the certificate may be issued to include device-specific information of the device to which the certificate is issued, public information of the HSM included in the device, issuing authority information, and a validity period, and may be recorded in a secure area included in the device.

[0017] According to another aspect, the terminal may process signature verification of the remittance transaction using public information of the HSM included in a certificate of the computing device.

[0018] According to another aspect, the step of signing the remittance transaction using the private key of the HSM and transmitting the signed transaction to the terminal may further include transmitting public information of the HSM to the terminal, and the terminal may process signature verification of the remittance transaction using the public information of the HSM.

[0019] A payment method for a computer device, the computer device comprising: a first security domain, an HSM (Hardware Security Module), a HSM (HSM Module) and at least one processor, the payment method comprising: transmitting, by the at least one processor, a nonce value to a terminal of an end user who sends remittance in an offline state via near field communication; receiving, by the at least one processor, a remittance transaction signed with a private key of the HSM of the terminal from the terminal (the remittance transaction includes first final transaction information recorded in a second secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value); verifying, by the at least one processor, a signature of the received remittance transaction; verifying, by the at least one processor, a nonce value included in the received remittance transaction; transmitting, by the at least one processor, a verification success message to the terminal if the signature verification and the verification of the nonce value are successful; recording, by the at least one processor, the received remittance transaction and the second final transaction in the first secure area; and receiving, by the at least one processor, an original of the security value that the terminal transmits in response to receiving the verification success message.

[0020] According to one aspect, each of the first security domain and the second security domain may include a Trusted Execution Environment (TEE) security domain or a White-Box Cryptographic (WBC) security domain.

[0021] According to another aspect, the payment method may further include, in response to the offline status changing to an online status, transmitting, by the at least one processor, the original text of the remittance transaction and the security value recorded in the first secure domain to a CBDC ledger to synchronize a transaction that occurred in the offline status.

[0022] According to another aspect, the payment method may further include exchanging a certificate with the terminal device and authenticating the terminal device by the at least one processor.

[0023] According to another aspect, the certificate may be issued to include device-specific information of the device to which the certificate is issued, public information of the HSM included in the device, issuing authority information, and a validity period, and may be recorded in a secure area included in the device.

[0024] According to another aspect, the step of verifying the signature may be characterized by verifying the signature of the remittance transaction using public information of the HSM, the issuing authority information, and the validity period included in the terminal.

[0025] According to yet another aspect, the step of receiving the signed remittance transaction may further receive public information of an HSM included in the terminal from the terminal, and the step of verifying the signature may be characterized by verifying the signature of the remittance transaction using the received public information of the HSM.

[0026] A computer program is provided that is recorded on a computer-readable recording medium and that, when combined with a computer device, causes the computer device to execute the method.

[0027] A computer-readable recording medium is provided, on which a program for causing a computer device to execute the method is recorded.

[0028] Provided is a computer device comprising: at least one processor implemented to execute computer-readable instructions; a secure area; and an HSM (Hardware Security Module), wherein the at least one processor receives a nonce value from a terminal of an end user receiving remittance via short-range communication in an offline state; signs a remittance transaction including first final transaction information recorded in the secure area, the transmitted nonce value, and a hash value of a security value using a private key of the HSM, and transmits the signed transaction to the terminal; and, upon receiving a verification success message from the terminal, transmits the original text of the security value to the terminal, and records second final transaction information and the latest balance of an electronic wallet resulting from the remittance transaction in the secure area.

[0029] a first secure area and an HSM (Hardware Security Module), the at least one processor being implemented to execute computer-readable instructions, transmitting a nonce value to a terminal of an end user who sends remittances by short-range communication in an offline state, receiving a remittance transaction signed with a private key of the HSM of the terminal from the terminal (the remittance transaction includes first final transaction information recorded in a second secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value), verifying a signature of the received remittance transaction and verifying the nonce value included in the received remittance transaction, and if the signature verification and the verification of the nonce value are successful, transmitting a verification success message to the terminal, recording the received remittance transaction and the second final transaction in the first secure area, and receiving an original of the security value that the terminal sends in response to receiving the verification success message.

[0030] <Details of the Invention> Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings.

[0031] The payment system according to an embodiment of the present invention may be implemented by at least one computer device. In this case, a computer program according to an embodiment of the present invention may be installed and executed in the computer device, and the computer device may execute the payment method according to an embodiment of the present invention under the control of the executed computer program. The computer program may be recorded on a computer-readable recording medium in combination with the computer device to cause the computer to execute the payment method.

[0032] FIG. 1 is a diagram showing an example of a network environment in one embodiment of the present invention. The network environment in FIG. 1 shows an example including multiple electronic devices 110, 120, 130, and 140, multiple servers 150 and 160, and a network 170. FIG. 1 is merely an example for explaining the invention, and the number of electronic devices and the number of servers are not limited to those shown in FIG. 1. Furthermore, the network environment in FIG. 1 is merely an example of an environment applicable to this embodiment, and environments applicable to this embodiment are not limited to the network environment in FIG. 1.

[0033] The electronic devices 110, 120, 130, and 140 may be fixed or mobile terminals implemented by computers. Examples of the electronic devices 110, 120, 130, and 140 include smartphones, mobile phones, navigation systems, personal computers (PCs), notebook PCs, digital broadcasting terminals, personal digital assistants (PDAs), portable multimedia players (PMPs), and tablets. While FIG. 1 illustrates a smartphone as an example of the electronic device 110, in embodiments of the present invention, the electronic device 110 may represent one of a variety of physical computer devices capable of communicating with the other electronic devices 120, 130, and 140 and / or the servers 150 and 160 via the network 170 using a substantially wireless or wired communication method.

[0034] The communication method is not limited, and may include not only communication methods using communication networks (for example, a mobile communication network, a wired Internet, a wireless Internet, and a broadcast network) that can be included in network 170, but also short-range wireless communication between devices. For example, network 170 may include any one or more of networks such as a personal area network (PAN), a local area network (LAN), a campus area network (CAN), a metropolitan area network (MAN), a wide area network (WAN), a broadband network (BBN), and the Internet. Furthermore, network 170 may include any one or more of network topologies including, but not limited to, a bus network, a star network, a ring network, a mesh network, a star-bus network, a tree or hierarchical network, etc.

[0035] Each of the servers 150, 160 may be realized by one or more computer devices that communicate with multiple electronic devices 110, 120, 130, 140 via the network 170 to provide instructions, code, files, content, services, etc. For example, the server 150 may be a system that provides services (such as a payment service, a virtual exchange service, a risk monitoring service, an instant messaging service, a gaming service, a group calling service (or an audio conferencing service), a messaging service, an email service, a social networking service, a map service, a translation service, a financial service, a search service, a content provision service, etc.) to multiple electronic devices 110, 120, 130, 140 connected via the network 170.

[0036] 2 is a block diagram showing an example of a computer device according to an embodiment of the present invention. Each of the electronic devices 110, 120, 130, and 140 and each of the servers 150 and 160 described above may be realized by a computer device 200 shown in FIG.

[0037] As shown in FIG. 2 , such a computer device 200 may include a memory 210, a processor 220, a communication interface 230, and an input / output interface 240. The memory 210 is a computer-readable storage medium and may include random access memory (RAM), read-only memory (ROM), and a persistent mass storage device such as a disk drive. The persistent mass storage device such as a ROM or a disk drive may be included in the computer device 200 as a separate persistent storage device distinct from the memory 210. The memory 210 may also store an operating system and at least one program code. Such software components may be loaded into the memory 210 from a computer-readable storage medium separate from the memory 210. Such separate computer-readable storage medium may include a computer-readable storage medium such as a floppy drive, a disk, a tape, a DVD / CD-ROM drive, or a memory card. In another embodiment, the software components may be loaded into the memory 210 through a communication interface 230, which is not a computer-readable storage medium. For example, the software components may be loaded into the memory 210 of the computer device 200 based on a computer program installed by a file received over the network 170 .

[0038] Processor 220 may be configured to process computer program instructions by performing basic arithmetic, logic, and input / output operations. The instructions may be provided to processor 220 by memory 210 or by communication interface 230. For example, processor 220 may be configured to execute instructions received according to program code stored in a storage device such as memory 210.

[0039] The communication interface 230 may provide a function for the computer device 200 to communicate with other devices (e.g., the above-mentioned storage device) via the network 170. For example, requests, instructions, data, files, etc. generated by the processor 220 of the computer device 200 in accordance with program code stored in a storage device such as the memory 210 may be transmitted to other devices via the network 170 under the control of the communication interface 230. Conversely, signals, instructions, data, files, etc. from other devices may be received by the computer device 200 via the communication interface 230 of the computer device 200 via the network 170. The signals, instructions, data, etc. received via the communication module 230 may be transmitted to the processor 220 or the memory 210, and files, etc. may be recorded on a storage medium (e.g., the above-mentioned permanent storage device) that the computer device 200 may further include.

[0040] The input / output interface 240 may be a means for interfacing with the input / output device(s) 250. For example, the input device may include a device such as a microphone, keyboard, or mouse, and the output device may include a device such as a display or speaker. As another example, the input / output interface 240 may be a means for interfacing with a device that integrates input and output functions into one, such as a touchscreen. At least one of the input / output devices 250 may be configured as a single device together with the computer device 200. For example, like a smartphone, the touchscreen, microphone, speaker, etc. may be implemented in a form that is included in the computer device 200.

[0041] Also, in other embodiments, computing device 200 may include fewer or more components than those shown in Figure 2. However, most prior art components need not be explicitly shown in the figures. For example, computing device 200 may be implemented to include at least some of the input / output devices 250 described above, and may further include other components such as a transceiver, a database, etc.

[0042] To process payments using Central Bank Digital Currency (CBDC), end-user terminals must constantly communicate with the server to update ledger information. Furthermore, payments between end-users must be made even in offline situations, such as when the end-user terminal cannot connect to the network. In this case, double payments must not occur, and end-users must be authenticated.

[0043] FIG. 3 illustrates an example of the internal configuration of an end-user terminal according to an embodiment of the present invention. According to this embodiment, the first end-user terminal 310 and the second end-user terminal 320 process payments while communicating with the server 330. In offline situations, offline payments between the end-user terminals (the first end-user terminal 310 and the second end-user terminal 320) may be processed through communication between them. After this, when communication with the server 330 resumes, the end-user terminal may synchronize the offline payment details with the server 330 through communication with the server 330. The server 330 may be a server device of a service provider that processes payments using CBDC between the CBDC platform and end-user terminals. Hereinafter, the term "server," as used without any particular limitation in this specification, may refer to a server of a service provider.

[0044] To prevent duplicate payments in offline payments, the first end user terminal 310 may include a P2P communication module 311, a Hardware Security Module (HSM) 312, and a Trusted Execution Environment (TEE) security area 313, as shown in Fig. 3. The second end user terminal 320 may also have the same or similar internal configuration as the first end user terminal 310. The first end user terminal 310 and the second end user terminal 320 may be realized by the computer device 200 described with reference to Fig. 2. In the embodiment of Fig. 3, components that are not essential for offline payments are omitted.

[0045] The P2P communication module 311 may include a communication module for short-range communication such as Bluetooth (registered trademark) or NFC (Near Field Communication). In order to enable payments between end users even in a situation where users cannot communicate with the server 330 via a network (for example, an offline situation such as a temporary network failure or a failure caused by a disaster), communication must be established at least between the end users' terminals (for example, the first end user terminal 310 and the second end user terminal 320 in FIG. 3), and therefore the P2P communication module 311 is required.

[0046] The HSM 312 may include a module for managing and protecting a private key that cannot be physically copied or extracted. Unlike the typical method of storing a private key, such as an encryption key, in a memory or the like in an encryption API, the HSM 312 may utilize a method of sending data encrypted or decrypted to the HSM 312 and receiving the result value. Therefore, the private key is managed internally and is not leaked to the outside, and the encryption calculation itself is performed within the HSM 312, so that the private key can essentially be prevented from leaking. For example, the computer device 200 of FIG. 2 may further include a physical device for such an HSM 312.

[0047] The TEE security domain 313 may provide a hardware-independent security domain and provide security functions such as application program integrity and data confidentiality in a secure execution environment. As an example, the processor 220 included in the computer device 200 of FIG. 2 may include a TEE function for providing the TEE security domain 313.

[0048] Also, depending on the embodiment, software technology may replace the hardware-based TEE secure domain 313. For example, White-Box Cryptographic (WBC) is a software technology that can securely store data and prevent the stored data from being exposed even if an encryption algorithm is executed on an untrusted device.

[0049] It will be readily apparent that the security domain of the TEE infrastructure described below may be expanded to a "security domain" including either a hardware security domain or a software security domain.

[0050] Bluetooth and NFC for short-range communication, HSM and TEE for security are well-known technologies, so detailed explanations of these will be omitted.

[0051] In order to process payments offline, the payment method according to this embodiment is assumed to satisfy the following conditions (1) to (5).

[0052] (1) Each end user terminal (for example, the first end user terminal 310 and the second end user terminal 320) may be an HSM device that holds a unique private key. In other words, no two or more end user terminals hold the same private key.

[0053] (2) The latest information signed by the final user terminal may be recorded in the TEE, and the signature may be processed using the information recorded in the TEE each time a signature is made. For example, the latest information signed by the first final user terminal 310 may be recorded in the TEE secure area 313, and the first final user terminal 310 may process the next signature using the signed latest information recorded in the TEE secure area 313.

[0054] (3) Information about the final balance synchronized with the server 330 is recorded in the TEE. For example, the first final user terminal 310 may record information about the final balance synchronized through communication with the server 330 in the TEE secure area 313.

[0055] (4) The electronic wallet of a user who has completed KYC (Know Your Customer) authentication can be used. Depending on the embodiment, KYC authentication may be selectively processed so that foreigners can also use it. If an electronic wallet that has not undergone KYC authentication is permitted as usable, restrictions such as a limit on the maximum amount that can be used for payment may be applied to the electronic wallet.

[0056] (5) A PKI (Public Key Infrastructure)-based certificate is issued by a Certification Authority (CA) to a unique device using an HSM, e.g., HSM 312. The certificate may be recorded in the TEE (e.g., TEE secure domain 313) to prevent duplicate issuance of the certificate. The certificate information may include device-specific information, public information of the HSM, issuing authority information, and a validity period. For example, the device-specific information may include information that can uniquely identify the end-user terminal, and the public information may include information (e.g., a public key) that is made public in correspondence with the private key recorded in the HSM.

[0057] In the embodiment of Figure 3 described above, an embodiment has been described in which the first final user terminal 310 includes all of the P2P communication module 311, HSM 312, and TEE security area 313, but it may also be realized in a form in which a device supporting a TEE (e.g., a smartphone) is combined with a smart HSM (e.g., Ledger Nano, Trezor, YubiKey, etc.), or in a form in which a device supporting a network (e.g., a POS (Point of Sales) or smartphone, etc.) is combined with a device having a TEE and an HSM (e.g., an HSM card with a secure storage device).

[0058] In the case of smartphones, portable chargers and battery charging equipment can be purchased at low cost, making it easy to prepare for power outages. Separately developed end-user terminals can also be prepared for power outages by incorporating a built-in battery that can be charged via micro USB or USB Type-C, allowing them to be charged with portable chargers or batteries. Furthermore, if the end-user terminal is developed as a small card-type device, it must be designed to allow for replaceable batteries and long-term use with low power consumption.

[0059] Meanwhile, when receiving the issuance of an end-user terminal (for example, the first end-user terminal 310 or the second end-user terminal 320) or when setting up the use of an end-user terminal that the user owns, an authentication process such as KYC authentication and / or ID / password authentication from an intermediary company (for example, other financial institutions other than the central bank) may be carried out.

[0060] Furthermore, a certificate may be issued to the end-user terminal after the authentication is completed. As described above, the certificate may include a signature including device-specific information, public information of the HSM, issuing authority information, and a validity period. The validity period may be used to periodically reissue the certificate and to maintain the latest information.

[0061] In addition, when a user uses the end user terminal, device user authentication may be processed by biometric authentication such as a password, fingerprint, iris, face recognition, etc. For example, a payment program installed and executed in the end user terminal may control the end user terminal so that when a user attempts to make a payment using the end user terminal, the end user terminal first authenticates the user through device user authentication.

[0062] When connecting online or when authenticating between users offline, information used when receiving authentication from the CA, such as device-specific information, HSM public information, issuing authority information, validity period, etc., may be sent to the server or the final user terminal of another user along with the certificate, and authentication may be performed on the user's final user terminal.

[0063] FIG. 4 is a flowchart illustrating an example of an online payment method according to an embodiment of the present invention. The online payment method according to this embodiment may be performed by a computer device 200 that implements an end-user terminal. In this case, the processor 220 of the computer device 200 may be implemented to execute control instructions according to operating system code and at least one computer program code stored in the memory 210. Here, the processor 220 may control the computer device 200 to perform steps 410 to 470 of the method of FIG. 4 according to the control instructions provided by the code stored in the computer device 200.

[0064] In step 410, the computer 200 may transmit to the service provider server the certificate issued to the computer 200 and information used in receiving authentication from the CA, such as the device specific information of the computer 200, the public information of the HSM, the issuing authority information, the validity period, etc. In this case, the service provider server may authenticate the computer 200 as an end user terminal using the transmitted certificate and information used in receiving authentication from the CA, such as the device specific information, the public information of the HSM, the issuing authority information, the validity period, etc.

[0065] In step 420, the computer device 200 may inquire about the latest balance and last transaction information (sequence number) of the user's electronic wallet via the server.

[0066] In step 430, the computer device 200 may record the latest balance and last transaction information in the TEE. As described above, the hardware-based TEE-based security domain may be replaced by software technology such as the WBC.

[0067] At step 440, the computing device 200 may receive remittance information. As an example, the computing device 200 may receive input from the user of the remittance amount and recipient information.

[0068] At step 450, the computing device 200 may sign the final transaction information and the remittance information using the HSM. For example, the final transaction information and the remittance information may be signed using a private key contained in the HSM.

[0069] In step 460, the computer device 200 may send the signed information to the server. The server may process the payment by transferring the remittance amount to the recipient's electronic wallet according to the sent information and deducting the remittance amount from the user's electronic wallet.

[0070] In step 470, the computer device 200 may check the processing result. At this time, the computer device 200 may record the latest balance of the electronic wallet and the last transaction information in the TEE once the processing is completed.

[0071] 5 is a flowchart illustrating an example of an offline payment method according to an embodiment of the present invention. This embodiment describes an example in which, when communication between a service user and a server is not possible, an end user terminal a 510 of an end user A that sends money and an end user terminal b 520 of an end user B that receives money process payment through P2P communication (hereinafter referred to as short-range communication) using a short-range network. First, the end user terminal a 510 and the end user terminal b 520 may exchange certificates through short-range communication to confirm that they are authenticated devices. Each of the end user terminal a 510 and the end user terminal b 520 may be implemented by a computer device 200, and may include a TEE secure domain and an HSM.

[0072] In step 531, the end user terminal b 520 may transmit a nonce value for the transaction to the end user terminal a 510. The nonce value may be a randomly generated value.

[0073] In step 532, the end user terminal a 510 may send a remittance transaction including final transaction information 1, a nonce value, and a hash value of a specific security value to the end user terminal b 520. Here, the final transaction information 1 may include a sequence number recorded in the TEE, and the specific security value may be a randomly generated value. In this case, the remittance transaction may be signed with the private key of the HSM and sent to the end user terminal b 520 together with the public key as public information of the HSM. In some embodiments, the end user terminal b 520 may obtain the public key as public information of the HSM from the certificate of the end user terminal a 510, without the end user terminal a 510 needing to send the public key as public information of the HSM to the end user terminal b 520.

[0074] In step 533, the final user terminal b 520 may verify the received remittance transaction and nonce value. For example, the final user terminal b 520 may process signature verification for the received remittance transaction using a public key and may check whether the nonce value included in the remittance transaction is the same as the nonce value transmitted in step 531. If the signature verification for the received remittance transaction fails, if the received nonce value differs from the nonce value transmitted in step 531, or if a previously processed nonce value is received, the final user terminal b 520 may send a failure message to the final user terminal a 510. In addition, the final user terminal b 520 may record the received remittance transaction together with final transaction information 2. Here, the final transaction information 2 may be information about the current transaction, different from the final transaction information 1.

[0075] In step 534, the final user terminal b 520 may transmit a verification result to the final user terminal a 510. For example, the final user terminal b 520 may transmit a verification success message or a verification failure message to the final user terminal a 510.

[0076] In step 535, if the verification result is successful, the final user terminal a 510 may transmit the original security value of the remittance transaction to the final user terminal b 520. If the final user terminal b 520 does not receive a successful verification message from the final user terminal a 510 within a certain time, the transaction may be canceled. In this case, the original security value is not transmitted to the final user terminal b 520.

[0077] In step 536, the final user terminal a 510 may record the final transaction information 2 and the latest balance in the TEE. The latest balance may be the latest balance of the final user A's electronic wallet.

[0078] After this, when communication resumes, the final user terminal b 520 may transmit the remittance transaction and the original text of the security value received from the final user terminal a 510 to the CBDC ledger and sequentially synchronize transactions that occurred offline from the final user terminal a 510 to the final user terminal b 520 with the ledger. If the original text of the security value is not transmitted to the final user terminal b 520 in step 535, synchronization with the ledger may fail, and the transaction may essentially be canceled. Because the final transaction information must be updated by this transaction, final transaction information 2 may be information about the current transaction, unlike final transaction information 1. Depending on the embodiment, the final transaction information 2 recorded in the TEE of the final user terminal a 510 in step 536 and the final transaction information 2 recorded in the TEE of the final user terminal b 520 in step 533 may differ in at least some content.

[0079] Depending on the embodiment, the following constraints (a) to (c) may apply.

[0080] (a) Transaction amounts received offline cannot be used unless they are synchronized with the CBDC ledger service online.

[0081] (b) The amount of money that can be used at the end user terminal may be limited.

[0082] (c) At least one of the following may be set: a limit on the amount of money that can be used offline, the number of transactions, and the valid time period during which transactions can be performed offline, and transactions may be restricted if the limit, number of transactions, or time period is exceeded.

[0083] According to this embodiment, all transactions of an electronic wallet linked to an HSM are processed by the end user terminal including the corresponding HSM. For example, since the private key of an HSM cannot be copied, all transactions of the linked electronic wallet are guaranteed to be processed by the end user terminal including the corresponding HSM. Furthermore, since electronic wallet authentication verifies that the device-specific information recorded in the certificate is the same as the public information of the HSM, the electronic wallet cannot be used on other devices. Furthermore, according to this embodiment, completed transactions cannot be forcibly modified because they are recorded in the TEE. In this case, since transactions are only performed by one end user terminal, the latest information is always recorded in the TEE. Therefore, double spending can be prevented.

[0084] Furthermore, in this embodiment, a security area based on a TEE configured in hardware is described, but such a TEE may be replaced by software technology such as WBC.

[0085] As such, according to an embodiment of the present invention, even in an offline situation (a situation in which a user's terminal cannot connect to a server via a network), double spending can be prevented and payments can be processed using Central Bank Digital Currency (CBDC).

[0086] The above-described systems or devices may be realized using hardware components or a combination of hardware and software components. For example, the devices and components described in the embodiments may be realized using one or more general-purpose or special-purpose computers, such as a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit (PLU), a microprocessor, or various devices capable of executing and responding to instructions. The processing device may execute an operating system (OS) and one or more software applications running on the OS. The processing device may also access, store, manipulate, process, and generate data in response to the execution of software. For ease of understanding, a single processing device may be described. However, those skilled in the art will understand that a processing device may include multiple processing elements and / or multiple types of processing elements. For example, a processing device may include multiple processors or one processor and one controller. Other processing configurations, such as parallel processors, are also possible.

[0087] Software may include computer programs, codes, instructions, or a combination of one or more of these, and may configure a processing device to operate as desired or may independently or collectively instruct the processing device. The software and / or data may be embodied in any type of machine, component, physical device, virtual device, computer storage medium, or device to be interpreted by the processing device or to provide instructions or data to the processing device. The software may be distributed and stored and executed in a distributed manner across computer systems connected by a network. The software and data may be stored on one or more computer-readable recording media.

[0088] Methods according to embodiments may be implemented in the form of program instructions executable by various computer means and recorded on a computer-readable medium. The computer-readable medium may include program instructions, data files, data structures, and the like, alone or in combination. The medium may continuously store a computer-executable program or temporarily store it for execution or download. Furthermore, the medium may be a variety of recording or storage means, including a single or multiple hardware devices, and is not limited to media directly connected to a computer system but may also be distributed over a network. Examples of media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; ROM, RAM, flash memory, and the like, configured to store program instructions. Other examples of media include recording media or storage media managed by application stores, other software distribution sites, servers, and the like. Examples of program instructions include not only machine language code, such as that generated by a compiler, but also high-level language code executed by a computer using an interpreter or the like.

[0089] Although the embodiments have been described above based on limited examples and drawings, those skilled in the art will appreciate that various modifications and variations may be made from the above description. For example, the described techniques may be performed in an order different from that described, and / or the described system, structure, device, circuit, or other element may be coupled or combined in a manner different from that described, or may be substituted or replaced by other elements or equivalents, and still achieve suitable results.

[0090] Therefore, different embodiments are within the scope of the appended claims, provided that they are equivalent to the claims. [Explanation of symbols]

[0091] 310: First final user terminal 311: P2P communication module 312:HSM 313:TEE security area 320: Second final user terminal 330: Server

Claims

1. 1. A payment method for a computer device, comprising: the computing device includes a first Trusted Execution Environment (TEE) security domain, a first Hardware Security Module (HSM), and at least one processor; the computer device communicates with a terminal of an end user receiving remittance via near field communication in an offline situation; the end user terminal includes a second TEE security domain and a second HSM; The payment method is receiving a nonce value from the end user's terminal by the at least one processor; signing a remittance transaction including first final transaction information recorded in the first TEE secure area, the transmitted nonce value, and a hash value of a security value using a private key of the first HSM and transmitting the signed transaction to the terminal; transmitting the original of the security value to the terminal when the at least one processor completes a signature verification process for the remittance transaction and a verification process for the identity of the nonce value in the terminal and receives a verification success message from the terminal; and recording second final transaction information and the latest balance of the electronic wallet according to the remittance transaction in the first TEE secure area by the at least one processor; A payment method comprising:

2. 2. The payment method of claim 1, wherein the transaction that occurred in the offline state is synchronized by transmitting the original text of the remittance transaction and the security value from the terminal to the CBDC ledger in response to the offline state changing to an online state.

3. The payment method is authenticating the terminal by exchanging a certificate with the terminal, by the at least one processor; The payment method according to claim 1 or 2, further comprising:

4. The certificate is issued to include device-specific information of the device to which the certificate is issued, public information of the HSM included in the device, issuing authority information, and a validity period, and is recorded in a secure area included in the device. The payment method according to claim 3 .

5. In the terminal, signature verification of the remittance transaction is processed using the public information of the HSM included in the certificate of the computer device. The payment method according to claim 4 .

6. The step of signing the remittance transaction with the private key of the first HSM and transmitting the signed transaction to the terminal includes: Further transmitting the public information of the first HSM to the terminal; The terminal processes the signature verification of the remittance transaction using the public information of the first HSM. The payment method according to any one of claims 1 to 5,

7. 1. A payment method for a computer device, comprising: the computing device includes a first Trusted Execution Environment (TEE) security domain, a first Hardware Security Module (HSM), and at least one processor; The computer device communicates with a terminal of a final user who sends money via near field communication in an offline situation; the end user terminal includes a second TEE security domain and a second HSM; The payment method is transmitting a nonce value to the end user's terminal by the at least one processor; receiving, by the at least one processor, from the terminal, a remittance transaction signed by a private key of a second HSM of the terminal, the remittance transaction including first final transaction information recorded in a second TEE secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value; performing, by the at least one processor, a signature verification process for the received remittance transaction; performing, by the at least one processor, a verification process for the identity of a nonce value included in the received remittance transaction; transmitting a verification success message to the terminal when the signature verification and the identity of the nonce value are successfully verified by the at least one processor; recording, by the at least one processor, the received remittance transaction and second final transaction information according to the remittance transaction in the first TEE secure area; and receiving, by the at least one processor, an original of the security value transmitted by the terminal in response to receiving the verification success message; A payment method comprising:

8. To synchronize transactions that occurred in the offline situation in response to the offline situation changing to an online situation, the payment method includes: transmitting, by the at least one processor, the original text of the remittance transaction and the security value recorded in the first TEE secure domain to a CBDC ledger. The payment method of claim 7 further comprising:

9. The payment method is authenticating the terminal by exchanging a certificate with the terminal, by the at least one processor; The payment method according to claim 7 or 8, further comprising:

10. The certificate is issued to include device-specific information of the device to which the certificate is issued, public information of the HSM included in the device, issuing authority information, and a validity period, and is recorded in a secure area included in the device. The payment method according to claim 9 .

11. The step of performing the signature verification process includes: and verifying the remittance transaction by using the public information, the issuing authority information, and the validity period of the second HSM included in the terminal. The payment method according to claim 10,

12. receiving the signed remittance transaction, Further receiving public information of the second HSM contained in the terminal from the terminal; The step of verifying the signature includes: and verifying the signature of the remittance transaction using the public information of the received second HSM. The payment method according to any one of claims 7 to 11,

13. A computer program for causing a computer device to execute the method according to any one of claims 1 to 6.

14. A computer-readable recording medium having recorded thereon a computer program for causing a computer device to execute the method according to any one of claims 1 to 6.

15. at least one processor implemented to execute computer-readable instructions; a first Trusted Execution Environment (TEE) security domain; and 1st HSM (Hardware Security Module) Including, the computer device communicates with a terminal of an end user receiving remittance via near field communication in an offline situation; the end user terminal includes a second TEE security domain and a second HSM; by the at least one processor A nonce value is transmitted from the terminal of the end user, a remittance transaction including the first final transaction information recorded in the first TEE secure area, the transmitted nonce value, and a hash value of a security value, signed with a private key of the first HSM, and transmitted to the terminal; When the terminal completes a signature verification process for the remittance transaction and a verification process for the identity of the nonce value and receives a verification success message from the terminal, the original security value is transmitted to the terminal; recording second final transaction information and the latest balance of the electronic wallet resulting from the remittance transaction in the first TEE secure area; A computer device comprising:

16. In response to the change from the offline state to the online state, the original text of the remittance transaction and the security value is sent from the terminal to the CBDC ledger, thereby synchronizing the transaction that occurred in the offline state.

16. The computer device of claim 15.

17. A computer device comprising: at least one processor implemented to execute computer readable instructions; a first Trusted Execution Environment (TEE) security domain; and 1st HSM (Hardware Security Module) Including, The computer device communicates with a terminal of a final user who sends money via near field communication in an offline situation; the end user terminal includes a second TEE security domain and a second HSM; by the at least one processor transmitting a nonce value to the terminal of the end user; receiving from the terminal a remittance transaction signed by a private key of a second HSM of the terminal, the remittance transaction including first final transaction information recorded in a second TEE secure area of ​​the terminal, the transmitted nonce value, and a hash value of a security value; performing a signature verification process for the received remittance transaction; Verifying the identity of the nonce value included in the received remittance transaction; If the signature verification and the verification of the identity of the nonce value are successful, a verification success message is sent to the terminal; recording the received remittance transaction and second final transaction information according to the remittance transaction in the first TEE secure area; receiving an original of the security value transmitted by the terminal in response to receiving the verification success message; A computer device comprising:

18. by the at least one processor and synchronizing transactions that occurred in the offline situation in response to the offline situation changing to an online situation. Transmitting the original text of the remittance transaction and the security value recorded in the first TEE secure domain to the CBDC ledger.

18. The computer device of claim 17.

Citation Information

Patent Citations

  • Digital money system

    KR101862637B1