Payment methods, terminal devices, servers, systems, and media
A dual verification method using an SDK and host program with security and user verification improves the security of electronic payments by ensuring both entities agree on the legitimacy of transactions, addressing the increased security risks with multiple entities in the settlement process.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-08
- Publication Date
- 2026-03-26
AI Technical Summary
The increasing number of entities involved in the settlement process, such as application programs and SDKs, increases security risks in electronic payment systems.
Implementing a dual verification process using both an SDK and a host program, where security verification is performed by a security control system, followed by user verification if the security verification is successful, ensuring both entities agree on the legitimacy of the transaction.
Enhances the security of electronic payments by ensuring bidirectional verification between the SDK and host program owners, reducing the risk of unauthorized transactions.
Smart Images

Figure 0007836409000001 
Figure 0007836409000002 
Figure 0007836409000003
Abstract
Description
Technical Field
[0001] [Cross - reference to Related Applications] This application claims priority based on a Chinese patent application filed with the Chinese Patent Office on March 10, 2022, with an application number of 202210238575.1 and an invention title of "Settlement Method, Terminal Device, Server, System and Medium", and incorporates all of its disclosures herein.
[0002] The present invention relates to the field of data processing, and particularly to a settlement method, a terminal device, a server, a system and a medium.
Background Art
[0003] With the development of settlement technology, the application of electronic settlement is becoming increasingly widespread. Users can make payments through terminals. Application programs and software development kits (SDKs) are installed on terminal devices. It is also possible to integrate the SDK into the application program to jointly implement settlement.
[0004] In the settlement process in a terminal device, two entities, namely an application program and an SDK, are involved. As the number of entities involved in the settlement process increases, the security risks of settlement also increase. Therefore, there is an urgent need for a settlement method that can improve security.
Summary of the Invention
Problems to be Solved by the Invention
[0005] Embodiments of the present invention provide a settlement method, a terminal device, a server, a system and a medium that can improve the security of settlement.
Means for Solving the Problems
[0006] In a first embodiment, a settlement method applied to a software development kit (SDK) server provided by an embodiment of the present invention includes the steps of: sending a security verification request message to a security control system in response to a received settlement request message; receiving security verification result information sent by the security control system; sending a first notification message to the SDK in a terminal device if the security verification result information indicates that the security verification has been passed; and initiating a payment request and completing the payment if the user verification result information indicates that the user verification has been passed, wherein the security verification request message includes security verification information for instructing the security control system to perform security verification of the settlement corresponding to the settlement request message based on the security verification information; the terminal device has an SDK and a host program; the first notification message is used to instruct the SDK to display a user verification page to the host program and prompt the user to enter first user verification input information; and the first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
[0007] In a second embodiment, an example of the present invention provides a payment method applicable to a terminal device. The terminal device comprises a software development kit (SDK) and a host program, and the method includes the steps of: obtaining a first notification message sent by an SDK server via the SDK; in response to the first notification message, notifying the host program via the SDK to display a user verification page to prompt the user to enter first user verification input information; feeding back the first user verification input information to a host program server via the host program; and, if the user verification result information to the SDK server indicates that user verification has passed, sending the user verification result information obtained from the host program server via the host program to the SDK server via the SDK in order to initiate a payment request and complete the payment, wherein the first notification message is sent by the SDK server based on security verification result information indicating that security verification has passed, the security verification result information is obtained by a security control system performing security verification on a payment corresponding to a payment request message based on security verification information in a security verification request message, the security verification request message is sent by the SDK server in response to a received payment request message, and the first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
[0008] In a third embodiment, an embodiment of the present invention provides a settlement method applicable to a host program server. The method includes the steps of: receiving first user verification input information fed back by a terminal device via a host program; performing user verification based on the first user verification input information and obtaining user verification result information; and transmitting the user verification result information to a host program in the terminal device and transmitting the user verification result information to an SDK via the host program, thereby causing the SDK to transmit the user verification result information to an SDK server, and if the user verification result information indicates that user verification has been passed, the SDK server initiates a payment request and completes the payment. The terminal device comprises a software development kit (SDK) and a host program. The first user verification input information is obtained by the SDK in response to a first notification message instructing the host program to display a user verification page. The first notification message is transmitted by the SDK server based on security verification result information indicating that security verification has been passed. The security verification result information is obtained by a security control system performing security verification on a settlement corresponding to a settlement request message based on security verification information in a security verification request message. The security verification request message is transmitted by the SDK server in response to a received settlement request message.
[0009] In a fourth embodiment, an embodiment of the present invention provides an SDK server. The SDK server includes a transmit module configured to send a security verification request message to a security control system in response to an received payment request message, and a receive module configured to receive security verification result information sent by the security control system, wherein the security verification request message includes security verification information for instructing the security control system to perform security verification of the payment corresponding to the payment request message based on the security verification information, and the transmit module is further configured to send a first notification message to the SDK in a terminal device if the security verification result information indicates that the security verification has passed, the terminal device having the SDK and a host program, the first notification message is used to instruct the host program to display a user verification page and prompt the user to enter first user verification input information, the first user verification input information is used by the host program server to perform user verification and obtain user verification result information, and the transmit module is further configured to initiate a payment request and complete the payment if the user verification result information indicates that the user verification has passed.
[0010] In a fifth embodiment, an embodiment of the present invention provides a terminal device. The terminal device includes a software development kit (SDK) and a host program, the terminal device comprising: a receiving module configured to receive a first notification message sent by an SDK server via the SDK; a display module configured to notify the host program via the SDK in response to the first notification message to display a user verification page to prompt the user to enter first user verification input information; and a transmitting module configured to feed back the first user verification input information to a host program server via the host program, the first notification message being sent by the SDK server based on security verification result information indicating that security verification has been passed, and security verification The result information is obtained when the security control system performs security verification on the payment corresponding to the payment request message based on the security verification information in the security verification request message. The security verification request message is sent by the SDK server in response to the received payment request message. The first user verification input information is used by the host program server to perform user verification and obtain user verification result information. The sending module is further configured to send the user verification result information obtained from the host program server via the host program to the SDK server via the SDK in order to initiate the payment request and complete the payment, if the user verification result information indicates to the SDK server that the user verification has passed.
[0011] In a sixth embodiment, the host program server provided by an embodiment of the present invention includes: a receiving module configured to receive first user verification input information fed back by a terminal device via a host program; a verification module configured to perform user verification based on the first user verification input information and obtain user verification result information; and a transmitting module configured to transmit the user verification result information to a host program in the terminal device, transmit the user verification result information to the SDK via the host program, so that the SDK transmits the user verification result information to the SDK server, and if the user verification result information indicates that the user verification has passed, the SDK server initiates a payment request and completes the payment. The terminal device includes a software development kit (SDK) and a host program, the first user verification input information is obtained by the SDK in response to a first notification message instructing the host program to display a user verification page, the first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed, the security verification result information is obtained by a security control system performing security verification on a payment corresponding to a payment request message based on security verification information in a security verification request message, and the security verification request message is sent by the SDK server in response to a received payment request message.
[0012] In a seventh embodiment, the SDK server provided by an embodiment of the present invention includes a processor and a memory for storing computer program instructions, wherein when the processor executes a computer program instruction, the settlement method of the first embodiment is executed.
[0013] In the eighth embodiment, the terminal device provided by the embodiment of the present invention includes a processor and a memory for storing computer program instructions, wherein when the processor executes a computer program instruction, the settlement method of the second embodiment is executed.
[0014] In the ninth embodiment, the host program server provided by an embodiment of the present invention includes a processor and a memory for storing computer program instructions, wherein when the processor executes a computer program instruction, the settlement method of the third embodiment is executed.
[0015] In a tenth embodiment, the payment system provided by an embodiment of the present invention includes an SDK server according to a seventh embodiment, a terminal device according to an eighth embodiment, and a host program server according to a ninth embodiment.
[0016] In an eleventh embodiment, an embodiment of the present invention provides a computer-readable storage medium storing computer program instructions, wherein when the computer program instructions are executed by a processor, the settlement method of the first embodiment, the settlement method of the second embodiment, or the settlement method of the third embodiment is executed. [Effects of the Invention]
[0017] Embodiments of the present invention provide a payment method, terminal device, server, system, and medium. The SDK server responds to a payment request message and sends a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of security verification, the SDK server sends a message to the SDK on the terminal device instructing the SDK to notify the host program to display a user verification page, thereby causing the SDK to trigger the host program to proactively initiate user verification and complete the user ID security requested by the host program owner. The payment process enables bidirectional verification between the SDK owner and the host program owner, improving the security of the payment. [Brief explanation of the drawing]
[0018] [Figure 1]It is a schematic diagram showing an example of an application scenario of the settlement method provided by an embodiment of the present invention. [Figure 2] It is a flowchart of one embodiment of the settlement method provided by the first aspect of the present invention. [Figure 3] It is a flowchart of another embodiment of the settlement method provided by the first aspect of the present invention. [Figure 4] It is a flowchart of another embodiment of the settlement method provided by the first aspect of the present invention. [Figure 5] It is a flowchart of yet another embodiment of the settlement method provided by the first aspect of the present invention. [Figure 6] It is a flowchart of yet another embodiment of the settlement method provided by the first aspect of the present invention. [Figure 7] It is a flowchart of one embodiment of the settlement method provided by the second aspect of the present invention. [Figure 8] It is a flowchart of another embodiment of the settlement method provided by the second aspect of the present invention. [Figure 9] It is a flowchart of another embodiment of the settlement method provided by the second aspect of the present invention. [Figure 10] It is a flowchart of yet another embodiment of the settlement method provided by the second aspect of the present invention. [Figure 11] It is a flowchart of yet another embodiment of the settlement method provided by the second aspect of the present invention. [Figure 12] It is a flowchart of one embodiment of the settlement method provided by the third aspect of the present invention. [Figure 13] It is a flowchart of another embodiment of the settlement method provided by the third aspect of the present invention. [Figure 14] It is a flowchart showing an example of the settlement process provided by an embodiment of the present invention. [Figure 15] It is a flowchart showing another example of the settlement process provided by an embodiment of the present invention. [Figure 16]This flowchart shows another example of a settlement process provided by embodiments of the present invention. [Figure 17] This is a schematic diagram of one embodiment of an SDK server provided according to a fourth aspect of the present invention. [Figure 18] This is a schematic diagram of one embodiment of a terminal device provided according to the fifth aspect. [Figure 19] This is a schematic diagram of one embodiment of a host program server provided by the sixth aspect. [Figure 20] This is a schematic diagram of one embodiment of an SDK server provided according to a seventh aspect of the present invention. [Modes for carrying out the invention]
[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention are briefly described below, but those skilled in the art can obtain other accompanying drawings based on these drawings without requiring any creative effort.
[0020] While various aspects of the present invention, their features, and exemplary embodiments are described in detail below, the present invention will be described in further detail with reference to the accompanying drawings and specific embodiments in order to further clarify the object, technical solution, and advantages of the present invention. It should be understood that the specific embodiments described herein are for illustrative purposes only and not to limit their applications. Those skilled in the art will see that the present invention can be carried out without some of these specific details. The following description of embodiments is intended to provide a better understanding of the present invention simply by illustrating its examples.
[0021] With the advancement of payment technology, the application of electronic payments is becoming increasingly widespread. Users can make payments via terminal devices. While these terminal devices are equipped with payment application programs, their functionality is limited. To make payment functionality more comprehensive, an SDK can be configured in the terminal device. The SDK is integrated into the application program and can perform payments together with the application program. In this scenario, the payment process on the terminal device involves two entities: the application program (hereinafter abbreviated as "application") and the SDK. As the number of entities involved in the payment process increases, so does the security risk of payments. Therefore, there is an urgent need for payment methods that can improve security.
[0022] Embodiments of the present invention provide a payment method, terminal device, server, system, and medium that perform dual verification primarily using an SDK and a host program, and can complete payment only if both the SDK-based verification and the host program-based verification are passed. Verification using both the SDK and the host program ensures the security of SDK-related and host program-related interactions, thereby improving the security of the entire payment process.
[0023] The payment method provided in the present invention is mainly applied to payment scenarios including a terminal device, an SDK backend system, a host program backend system, and a security control system. Figure 1 is a schematic diagram showing an example of an application scenario of the payment method provided by an embodiment of the present invention. As shown in Figure 1, the terminal device 11 can communicate and interact with the SDK backend system 12 and the host program backend system 13, respectively, and the SDK backend system 12 can also communicate and interact with the host program backend system 13 and the security control system 14, respectively.
[0024] The terminal device 11 comprises a host program and an SDK. The payment function of the terminal device 11 requires the host program to call the SDK and execute them together. The SDK of the terminal device 11 can interact with the host program. The SDK of the terminal device 11 can communicate and interact with the SDK backend system 12, and the host program of the terminal device 11 can communicate and interact with the host program backend system 13. The terminal device 11 is a device used by a user to make payments, and specifically includes, but is not limited to, mobile phones, tablet computers, computers, smart wearable devices, etc.
[0025] The SDK backend system 12 is the backend system for the SDK and may include multiple SDK servers. The types and number of SDK servers within the SDK backend system 12 are not limited here. During the payment process, the terminal device 11 transmits payment-related information to the SDK backend system 12 via the SDK. The SDK backend system 12 can also pre-store the account information and personal information of the user (payer) making the payment.
[0026] In some embodiments, the SDK backend system 12 may include an SDK backend subsystem and a payment code subsystem. The SDK backend subsystem and the payment code subsystem can communicate and interact with each other. The SDK backend subsystem can also communicate and interact with the SDK of the terminal device 11, and the payment code subsystem can communicate and interact with the host program backend system. The payment code subsystem can store information related to the payment code and manage and verify the payment code. The payment code may include a collection code, a payment code, etc., and the payment code may specifically be a QR code® or other form of graphic code, but is not limited to these.
[0027] The host program backend system 13 is the backend system for the host program and may include multiple host program servers. The types and number of host program servers within the host program backend system 13 are not limited herein. During the settlement process, the terminal device 11 interacts with the host program backend system 13 via the host program. The host program backend system 13 can also communicate and interact with the SDK backend system 12.
[0028] The security control system 14 is configured to perform security verification of payments and may include multiple electronic devices. The types and number of electronic devices in the security control system 14 are not limited herein. The security control system 14 can communicate and interact with the SDK backend system 12. If the SDK backend system 12 includes an SDK backend subsystem and a payment code subsystem, the security control system 14 can communicate and interact with the SDK backend subsystem of the SDK backend system 12.
[0029] In some embodiments, information transmission between the SDK in the terminal device 11 and the host program is encrypted; that is, the information exchanged between the SDK in the terminal device 11 and the host program is encrypted. The SDK and the host program each store the encryption algorithm and decryption algorithm necessary for encryption and decryption, respectively. The encryption algorithm and decryption algorithm in the SDK and the host program can be configured according to the application environment, requirements, etc. For example, the encryption algorithm and decryption algorithm in the SDK and the host program may include, but are not limited to, the SM2 algorithm, the SM4 algorithm, the Data Encryption Standard (DES), and the RSA (Rivest-Shamir-Adleman) algorithm. The keys required for the encryption algorithm and decryption algorithm in the SDK may be stored and managed by the SDK backend system 12. In other words, the encryption and decryption keys in the SDK may be stored on the SDK server in the SDK backend system 12. The SDK can interact with the SDK backend system 12 to perform encryption and decryption. The keys required for the encryption and decryption algorithms within the host program may be stored and managed by the host program backend system 13; in other words, the encryption and decryption keys within the host program are stored on the host program server within the host program backend system 13. The host program interacts with the host program backend system 13 to perform encryption and decryption. Encryption transmission between the SDK and the host program prevents information transmitted between the SDK and the host program from being easily stolen, thus ensuring the security of communication between the SDK and the host program.
[0030] In some embodiments, the SDK within the terminal device 11 has a security domain, and information within the SDK is stored in the security domain. The security domain is an encrypted data storage space and may be enforced by hardware and software such as a Secure Element (SE) and / or a Trusted Execution Environment (TEE). The SDK may manage permissions within the security domain, such as by dividing it into data that cannot be publicly read and data that only the host program has read permission for.
[0031] The payment method, terminal device, server, system, and medium in this invention will be described in order below.
[0032] A first aspect of the present invention provides a payment method applicable to an SDK server. That is, the payment method can be executed by the SDK server. Figure 2 is a flowchart of an embodiment of the payment method according to the first aspect of the present invention. As shown in Figure 2, the payment method may include steps S201 to S204.
[0033] In step S201, in response to the received payment request message, a security verification request message is sent to the security control system.
[0034] A payment request message is used to initiate a payment. A payment request message may be sent to the SDK server by the SDK in the terminal device, or it may be sent to the SDK server by the payment-receiving device. If the SDK backend system includes an SDK backend subsystem and a payment code subsystem, the payment-receiving device may initiate a payment to the SDK server in the payment code subsystem. The SDK server in the payment code subsystem sends a payment request message to the SDK server in the SDK backend subsystem. A payment request message includes order information, terminal device information, and payment information. Order information includes, but is not limited to, the order identifier, order initiator, order details, order amount, order time, and other information related to the order. Terminal device information includes, but is not limited to, information related to the terminal device making this payment, such as its geographical location and device identifier. Payment information includes, but is not limited to, payment payer information, payment recipient information, payment amount, payment time, and other payment-related information. Payment recipient information may include the merchant name, merchant account, and other information, while payment payer information may include, but is not limited to, the payer account, payer payment card information, payer ID, and other information.
[0035] A security verification request message contains security verification information. The security verification request message is used to instruct the security control system to perform security verification of the payment corresponding to the payment request message, based on the security verification information. The security verification information may include at least some of the information sent to the SDK server by the SDK in the terminal device. The security verification information may include, but is not limited to, payment payer information pre-stored on the SDK server and indicated by the payment request message. For example, the security verification information may include one or more of the following: payment card number, payer's login account, mobile phone number associated with the payer's login account, mobile phone number associated with the payment card, terminal device identifier, terminal device geographical location, payment amount, payment time, payment card, and payment card history. The security verification information may also include, but is not limited to, other information that can be used for security verification.
[0036] In some cases, if a security verification request message includes a payment card number, that payment card number may be the default payment card number provided by the SDK in the terminal device. If the user switches the default payment card on the terminal device, i.e., if the default payment card number changes, the SDK sends a message containing the new default payment card number to the SDK server, which is triggered to resend a security verification request message containing the new default payment card number to the security control system. That is, if the user switches the default payment card on the payment details page displayed on the terminal device, the SDK server resends a security verification request message containing the switched default payment card number to the security control system.
[0037] The security control system receives a security verification request message and performs a security verification based on the security verification information contained in the security verification request message. The security verification can verify the legality of the payment and the security of the login status of the payment terminal device. Specifically, it can determine whether the security verification passes by checking whether the security verification information meets predetermined security criteria. The security criteria can be set according to specific application scenarios, needs, etc., and are not limited to these. For example, the security verification information may include the terminal device identifier for the current payment and the payment card's past settlement information. The payment card's past settlement information may include the payment card's terminal device identifier in the history of payments. If the terminal device identifier for the current payment and the payment card's terminal device identifier in the history of payments match, the security verification passes; otherwise, the security verification fails. As another example, the security verification information may include the geographical location of the terminal device used for the current payment, the payment time, and the payment card's past settlement information, while the payment card's past settlement information may include the geographical location and payment time of the terminal device used for the most recent payment by the payment card. If the time difference between the payment time of the latest payment on the payment card and the payment time of the current payment is less than a preset time, and the distance between the geographical location of the terminal device for the latest payment on the payment card and the location of the terminal device for the current payment is greater than a preset distance, the security verification will fail; otherwise, the security verification will pass. As another example, security verification information includes the mobile phone number associated with the payer's login account and the mobile phone number associated with the payment card. If the mobile phone number associated with the payer's login account matches the mobile phone number associated with the payment card, the security verification will pass; otherwise, the security verification will fail.
[0038] In some cases, security verification may fail if the security risk is very high, such as insufficient account balance or fraudulent payment. Security verification may pass if the security risk is moderate or low, and if the security of the payment can be verified by subsequent user verification. For example, security verification information may include the terminal device identifier for the current payment and the payment card's past payment information. The payment card's past payment information includes the payment card's terminal device identifier for past payments. Because users may change their terminal devices, even if the terminal device identifier for the current payment does not match the terminal device identifier for the payment card's past payments, the security verification may be considered to have passed, and subsequent processing may use user verification to determine whether the user is making the payment using a terminal device they have replaced. As another example, security verification information may include the payment amount for the current payment and the payer's account balance, and security verification may pass if the payment amount for the current payment is less than or equal to the payer's account balance, and fail otherwise.
[0039] In some examples, when the SDK receives a payment request message and detects that the currently logged-in user account is not associated with a payment card, it sends card binding prompt information to prompt the user to perform the card binding process and bind the payment card. After the payment card is bound, the SDK sends a security verification request message to the security control system.
[0040] In step S202, the security verification result information transmitted by the security control system is received.
[0041] The security control system can perform security verification based on security verification information and obtain security verification result information for the current payment, i.e., the payment indicated by the payment request message. The security verification result information is used to indicate whether the security verification was passed or not. If the security verification result information indicates that the security verification was not passed, the SDK server can send an instruction message to the SDK on the terminal device, causing the SDK to issue a pop-up message to temporarily suspend the payment.
[0042] In some cases, after the SDK server receives security verification result information indicating that it has passed security verification, the SDK on the terminal device can call a pre-configured inquiry interface to send payment information such as payer information, order information such as order number, and any other possible information related to the current payment to the SDK server. The SDK server can further supplement other order information related to the current payment (such as seller number) and other payment information related to the payment, and synchronize the payment information and order information with the host program server to achieve synchronization of information regarding the current payment between the SDK server and the host program server.
[0043] In some examples, if the SDK backend system includes an SDK backend subsystem and a payment code subsystem, after the SDK server in the SDK backend subsystem receives security verification result information indicating that it has passed security verification, the SDK server in the SDK backend subsystem can call a pre-configured query interface to send payment information, such as payer information for the current payment, and order information, such as the order number, to the SDK server in the payment code subsystem. The SDK server in the payment code subsystem can further supplement this with other order information, such as the merchant number for the current payment, and other payment information related to the payment, and synchronize the payment information and order information with the host program server, thereby achieving synchronization of information regarding the current payment between the SDK server in the SDK backend system and the host program server.
[0044] In step S203, if the security verification result information indicates that the security verification has been passed, a first notification message is sent to the SDK in the terminal device.
[0045] If the security validation result information indicates that the security validation has passed, the host program owner's user validation process may be executed. The first notification message is used to instruct the SDK to display the user validation page by notifying the host program to prompt the user to enter the first user validation input information. The first user validation input information is used by the host program server to perform user validation and obtain the user validation result information.
[0046] In response to the first notification message, the SDK in the terminal device may send a message to the host program instructing it to display a user verification page. In response to this message, the host program causes the terminal device to display a user verification page. The user verification page includes a password input area, a verification code input area, a biological feature collection area, etc. The method of user verification is not limited here. The information entered by the user on the user verification page is the first user verification input information. The host program may send the first user verification input information to the host program server. The host program server may perform user verification based on the received first user verification input information and obtain user verification result information. User verification is used to verify the identity of the user. Passing user verification means that the user performing the payment operation is a legitimate user. For example, if the first user verification input information is a password, the host program server verifies whether the first user verification input information matches the password registered by the user with the host program server. If the first user authentication input information matches the password registered by the user with the host program server, user authentication is successful; otherwise, user authentication fails. As another example, the first user authentication input information is a facial image, and the host program server verifies whether the first user authentication input information and the facial image pre-stored by the user on the host program server belong to the same user. If the first user authentication input information and the facial image pre-stored by the user on the host program server belong to the same user, user authentication is successful; otherwise, user authentication fails.
[0047] User validation result information is used to indicate whether user validation has been passed. The host program server can feed back user validation result information to the host program and the SDK server, respectively. The host program also sends the user validation result to the SDK so that both the SDK owner and the host program owner can know whether user validation has been passed.
[0048] In some cases, when a host program displays a user verification page, the SDK can add event tracking capabilities associated with the action of displaying the user verification page to facilitate subsequent analysis and troubleshooting of the host program's execution of the process of displaying the user verification page.
[0049] In step S204, if the user verification result information indicates that user verification has been passed, the payment request is initiated and the payment is completed.
[0050] The user verification result information indicates that the user has passed verification, that user ID security is highly secure, and that the payment request can be initiated to the payer's account management system and the payment can be successfully processed. If the user verification result information indicates that the user has not passed verification, the payment may be suspended.
[0051] In some embodiments, because user verification results information may be stolen or tampered with during transmission, consistency verification criteria may be used to verify the security of user verification results information in transmission to further ensure payment security. If the user verification results information meets the consistency verification criteria, the payment request is initiated. Consistency verification criteria are used to determine whether the user verification results information is secure and valid during the transmission process. If the user verification results information meets the consistency verification criteria, this means that the user verification results information is secure and valid during the transmission process. The payment request is initiated to the payer's account management system, and the payment may be successfully processed. Alternatively, the SDK server may send the request to the payer's account management system via the host program server. The payer's account management system initiates the payment request and successfully processes the payment. If the user verification results information does not meet the consistency verification criteria, i.e., if the user verification results information is not secure and valid during the transmission process, the payment may be suspended.
[0052] In some examples, consistency verification criteria include ensuring that the first user verification result information matches the second user verification result information, where the first user verification result information is the user verification result information that the host program server sends to the SDK via the host program, and the second user verification result information is the user verification result information obtained from the host program server. If the first user verification result information matches the second user verification result information, it means that the user verification result information is secure and valid during the transmission process. If the first user verification result information does not match the second user verification result information, it means that the user verification result information is not secure and valid during transmission.
[0053] If the payment is successful, the SDK server may obtain payment result information indicating whether the payment was successful. The SDK server sends the payment result information to the SDK, the seller system, etc., and displays the payment success result to the user, seller, etc.
[0054] In the above payment process, since it takes some time for user verification results, payment, and settlement results to be transmitted after user verification, the terminal device will not immediately display the payment completion page. In this case, the SDK may control the terminal device to display a payment progress indicator, such as an image containing the text "Loading," and stop displaying the payment progress indicator when the terminal device displays the payment completion page.
[0055] In an embodiment of the present invention, the SDK server responds to a payment request message by sending a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of the security verification, the SDK server sends a message to the SDK on the terminal device instructing the SDK to notify the host program to display the user verification page, thereby causing the SDK to trigger the host program to proactively initiate user verification and complete the user ID security requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0056] In some cases, when the SDK server initiates a payment request to the payer's account management system via the host program server, the SDK server may provide the SDK owner's first payment policy information. This first payment policy information may include the SDK owner's promotional information, payment activity information, etc., and can be used to calculate the payment amount indicated by the payment request message. The host program server may provide the host program owner's second payment policy information. This second payment policy information may include the host program owner's promotional information, payment activity information, etc., and can be used to calculate the payment amount indicated by the payment request message.
[0057] In some embodiments, after receiving a payment request message, the SDK server may either query the host program server directly for payment policy information, such as promotional information and payment activity information, or query the host program server via the payment policy system.
[0058] In the above embodiment, the information exchanged between the SDK and the host program is encrypted, and the SDK needs to encrypt and decrypt the information. Accordingly, the SDK server stores keys used to encrypt and decrypt the information exchanged between the SDK and the host program.
[0059] In some embodiments, the SDK server requests a user verification mode from the host program server, and the host program server sends feedback to the SDK so that the SDK can perform the corresponding operation. Figure 3 is a flowchart of another embodiment of the settlement method provided by the first aspect of the present invention. The difference between Figure 3 and Figure 2 is that the settlement method shown in Figure 3 also includes steps S205-S208, and step S203 in Figure 2 may be specifically modified into step S2031 in Figure 3.
[0060] In step S205, if the security verification result information indicates that the security verification has passed, a user verification mode request message is sent to the host program server.
[0061] The user verification mode request message is used to request user verification mode from the host program server and may include one or more order information, terminal device information, and payment information corresponding to the payment indicated by the payment request message. Specific details of the order information, terminal device information, and payment information are described in the relevant descriptions of the above embodiments and are not repeated here.
[0062] The host program server may determine verification operation information based on the information in the user verification mode request message. The verification operation information is used to indicate whether or not to perform user verification and the mode of user verification. The host program server stores criteria for determining whether or not to perform user verification and the mode of user verification, and can determine whether or not to perform user verification and the mode of user verification based on whether the information in the user verification mode request message satisfies the reference criteria. The criteria can be set according to the payment scenario, needs, etc., and are not limited to these. For example, the user verification mode request message includes payment information, and the payment information includes the payment amount. The criteria may include the correspondence between the range of the payment amount and whether or not to perform user verification and the user verification mode. For example, the criteria may include: if the payment amount is less than 100 yuan, user verification is not required; if the payment amount is between 100 yuan and 500 yuan, user verification is required; and the user verification mode is password verification, etc. If the payment amount is between 500 yuan and 1,000 yuan, user verification is required, and the user verification mode is verification code verification. If the payment amount exceeds 1,000 yuan, user verification is required, and the user verification mode is biological characteristic verification. As another example, the user verification mode request message may include order information and payment information. The order information includes the order identifier and the user account that placed the order, and the payment information includes the payer's login account. The criteria for determination are: if the account of the user that placed the order does not match the payer's login account, user verification is required, and the user verification mode is biological characteristic verification. If the user account that placed the order matches the payer's login account, user verification is required, and the user verification mode includes password verification.
[0063] After determining the verification operation information, the host program server can send a user verification mode feedback message to the SDK server. The user verification mode feedback message contains the verification operation information.
[0064] In step S206, the user verification mode feedback message sent by the host program server is received.
[0065] In step S207, if the verification operation information contains a payment rejection mark, a second notification message is sent to the SDK.
[0066] The payment rejection mark indicates that user verification is not required and the payment has been stopped. In response to the user verification mode feedback message, the SDK server sends a second notification message to the SDK in the terminal device. The second notification message is used to instruct the SDK to issue payment rejection prompt information. In response to the second notification message, the SDK may issue prompt information that prompts the user that there is a payment risk. In the example, the user verification mode feedback message may also include the reason for payment rejection. Accordingly, the second notification message may also include the reason for payment rejection. The prompt information sent by the SDK in response to the second notification message may include the reason for payment rejection. The terminal device may display the reason for payment rejection to notify the user. Reasons for payment rejection may include SDK malfunctions, host program server malfunctions, and other reasons indicating that user verification mode has failed.
[0067] In step S208, if the verification operation information includes a password-free payment signature, a third notification message is sent to the SDK.
[0068] A password-free payment signature indicates that user verification is not required and the payment process can proceed. In response to the user verification mode feedback message, the SDK server sends a third notification message to the SDK on the terminal device. The third notification message is used to instruct the SDK to issue password-free payment prompt information. The password-free payment prompt information may inform the user that the payment is a password-free payment.
[0069] In step S2031, if the verification operation information includes a user verification mode identifier and the security verification result information indicates that the security verification has been passed, a first notification message is sent to the SDK.
[0070] The first notification message is: User verification mode Includes an identifier. User Verification mode The identifier is used to indicate the user verification mode. The first notification message is used by the user Verification mode To prompt the user to enter first user verification input information that matches the identifier, Verification mode This is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier. In other words, the SDK responds to the first notification message to the user Verification mode The host program sends an instruction message containing an identifier, and the host program then processes the user Verification mode User Verification mode The user verification page corresponding to the user verification mode indicated by the identifier is displayed. In response to this, the first user verification input information entered by the user is also displayed. Verification mode Corresponds to the user verification mode indicated by the identifier.
[0071] For example, if the user verification mode is identified as 01, the user verification mode is password verification, the user verification page displayed by the host program is a password verification page, and the first user verification input information that the user must enter is a password. If the user verification mode is identified as 10, the user verification mode is verification code verification, the user verification page displayed by the host program is a verification code verification page, and the first user verification input information that the user must enter is a verification code. If the user verification mode is identified as 11, the user verification mode is biological feature verification, the user verification page displayed by the host program is a biological feature verification page, and the first user verification input information that the user must enter is a biological feature.
[0072] In some embodiments, payment request messages, security verification request messages, and security verification result information may include a target host program identifier. The target host program identifier may include the host program identifier for the payment corresponding to the payment request message; in other words, the target host program identifier may indicate the payment-related host program corresponding to the payment request message.
[0073] The SDK server includes a pre-configured first correspondence. This first correspondence includes the relationship between the host program identifier and the user verification caller. The host program identifier is used to identify the host program. The user verification caller is used to indicate the entity that displays the user verification page. The user verification caller includes the SDK or host program within the terminal device. After receiving security verification result information, the SDK server can determine the target user verification caller corresponding to the target host program identifier based on the target host program identifier and the first correspondence. The target user verification caller is the user verification caller corresponding to the target host program identifier in the first correspondence.
[0074] If the target user verification caller is the host program, the SDK server sends a first notification message to the SDK. If the target user verification caller is the SDK, the SDK server sends a fourth notification message to the SDK. The fourth notification message is used to instruct the SDK to display a user verification page and prompt the user to enter second user verification input information. The second user verification input information is used by the SDK server to perform user verification and obtain user verification result information. The SDK in the terminal device can directly display the user verification page in response to the fourth notification message. Accordingly, user verification is performed by the SDK server. The SDK in the terminal device can send second user verification input information to the SDK server. The SDK server performs user verification based on the second user verification input information and obtains user verification result information. For specific details of user verification, please refer to the relevant description of user verification performed by the host program server in the above embodiment, and will not repeat it here.
[0075] By establishing the first correspondence, the setting of the primary user verification in terminal devices can be made more flexible and selective.
[0076] In some embodiments, payment is initiated by the dealer system or by a dealer program installed on the terminal device. Order-related information must be communicated between the dealer system and the SDK, and between the SDK and the SDK server, before the SDK server receives the payment request message. Figure 4 is a flowchart of another embodiment of the payment method provided by the first aspect of the present invention. The difference between Figure 4 and Figure 2 is that the payment method shown in Figure 4 may also include steps S209-S211.
[0077] In step S209, an order identifier is generated in response to an order request message sent by the dealer system.
[0078] After a user creates and places an order, the reseller system may send an order request message to the SDK server, requesting an identifier that can identify the order, i.e., an order identifier. The order identifier generated by the SDK server is specifically the order's serial number.
[0079] In step S210, an order feedback message is sent to the dealer system so that the dealer system can attempt to send an SDK call request message to the SDK.
[0080] The SDK server may generate an order feedback message. This order feedback message includes an order identifier. The SDK server sends this order feedback message to the dealer system, which also includes the order identifier. After receiving the order feedback message, the dealer system may send an SDK invocation request message to the SDK on the terminal device. This SDK invocation request message includes the order identifier. The SDK invocation request message is used to request that the SDK on the terminal device be invoked. During the initialization process, the SDK on the terminal device may collect information such as the geographical location of the terminal device and the terminal device identifier.
[0081] In step S211, in response to the first order inquiry message sent by the SDK, a first inquiry feedback message is sent to the SDK.
[0082] The SDK sends a first order inquiry message to the SDK server, attempting to query the order information corresponding to the order identifier via the order identifier. The first order inquiry message includes the order identifier. After the SDK server finds the order message corresponding to the order identifier, it feeds back the order message corresponding to the order identifier to the SDK via a first inquiry feedback message. The first inquiry feedback message includes the order information corresponding to the order identifier. After receiving the first inquiry feedback message, the SDK sends a payment request message to the SDK server.
[0083] In some embodiments, the vendor may specify a particular payer for payment, and the order request message includes the specified payer identification information; that is, the specific payer is specified through the order request message. The payment request message sent from the SDK to the SDK server includes payment payer identification information, such as the user's login account. If the specified payer identification information does not match the payment payer identification information shown in the payment request message, the SDK server sends a payment suspension notification message to the SDK, and the SDK issues payment prompt information. The payment prompt information may notify the user to switch user login accounts and try paying again. The payment prompt information may also prompt the user for the reason why the user payment was suspended. For example, the payment prompt information may include words displayed on the terminal device such as "Payment cannot be made temporarily because the login account information does not match the information specified by the vendor."
[0084] In some embodiments, payment may be initiated by a user who scans another person's payment code using a terminal device. Before the SDK server receives the payment request message, the SDK and the SDK server must interact with each other regarding order-related information. Figure 5 is a flowchart of yet another embodiment of the payment method provided by the first aspect of the present invention. The difference between Figure 5 and Figure 2 is that the payment method shown in Figure 5 may also include steps S212 and S213.
[0085] In step S212, the terminal device receives a second order inquiry message sent by the SDK.
[0086] The terminal device scans the collection code to obtain first code information. The first code information is the code information read from the collection code. The terminal device's SDK sends a second order inquiry message to the SDK server. The second order inquiry message is used to request the SDK server to query the order message corresponding to the first code information. The second order inquiry message contains the first code information obtained by the terminal device scanning the collection code.
[0087] In step S213, a second query feedback message is sent to the SDK.
[0088] The SDK server searches for order information corresponding to the first code information based on the first code information. After finding the order information corresponding to the first code information, the SDK server generates a second query feedback message and sends the second query feedback message to the SDK. The second query feedback message contains the order information corresponding to the first code information.
[0089] After receiving the second inquiry feedback message, the SDK can determine the payment amount based on the user's input, generate a payment request message, and send the payment request message to the SDK server. After receiving the payment request message, the SDK server can determine whether the payment card indicated in the payment request message is available, and if the payment card is available, it can send a security verification request message to the security control system.
[0090] In some embodiments, the payment may be initiated by a user who displays a payment code using a terminal device and another user who scans the payment code using a payment acceptance terminal. Before the SDK server receives the payment request message, the SDK may request a payment code from the SDK server. Figure 6 is a flowchart of yet another embodiment of the payment method provided by the first aspect of the present invention. The difference between Figure 6 and Figure 2 is that the payment method shown in Figure 6 may also include step S214.
[0091] In step S214, in response to the received payment code request message, a payment code feedback message is sent to the SDK.
[0092] The payment code request message is sent by the SDK. Specifically, the SDK on the terminal device sends the payment code request message to the SDK server, which is used to request a payment code from the SDK server. The SDK server assigns a payment code to the payment code request message and feeds the payment code back to the SDK via a payment code feedback message. The payment code feedback message contains the payment code.
[0093] In some examples, the SDK backend system includes an SDK backend subsystem and a payment code subsystem. The SDK can send a payment code request message to the SDK server in the SDK backend subsystem. The SDK server in the SDK backend subsystem forwards the payment code request message to the SDK server in the payment code subsystem. The SDK server in the payment code subsystem assigns a payment code to the payment code request message and sends a payment code feedback message to the SDK server in the SDK backend subsystem. The SDK server in the SDK backend subsystem forwards the payment code feedback message to the SDK.
[0094] The payment request message is generated by the payment receiving device based on the scanned payment code. After receiving the payment code feedback message, the SDK can display the payment code when making a payment. The payment receiving device scans the payment code and obtains second code information. This second code information is the code information read from the payment code. The payment receiving device generates a payment request message based on the second code information and sends the payment request message to the SDK server.
[0095] A second aspect of the present invention provides a payment method applicable to a terminal device. That is, the payment method can be performed by the terminal device. The terminal device includes an SDK and a host program. Figure 7 is a flowchart of one embodiment of the payment method provided by the second aspect of the present invention. As shown in Figure 7, the payment method may include steps S301 to S304.
[0096] In step S301, the first notification message sent by the SDK server via the SDK is retrieved.
[0097] The first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed. The security verification result information is obtained when the security control system performs security verification on the payment corresponding to the payment request message based on the security verification information in the security verification request message. The security verification request message is sent by the SDK server in response to the received payment request message.
[0098] In step S302, in response to the first notification message, the SDK notifies the host program to display a user verification page to prompt the user to enter the first user verification input information.
[0099] In step S303, the first user verification input information is fed back to the host program server via the host program.
[0100] The first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
[0101] In step S304, the user verification result information obtained from the host program server via the host program is sent to the SDK server via the SDK. If the user verification result information indicates that the user verification has passed, the SDK server initiates a payment request and allows the payment to be completed.
[0102] In some implementations, user validation results are also used so that the SDK server can attempt to initiate a payment request if the user validation results meet consistency validation criteria.
[0103] In some examples, consistency verification criteria include: the first user verification result information matches the second user verification result information; the first user verification result information is the user verification result information that the host program server sends to the SDK via the host program; and the second user verification result information is the user verification result information obtained from the host program server.
[0104] For specific details of steps S301 to S304 described above, please refer to the related explanations in the above embodiment, as they will not be explained again here.
[0105] In this embodiment of the present invention, the SDK server responds to a payment request message by sending a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of security verification, the SDK in the terminal device receives a message instructing the SDK to notify the host program, sent by the SDK server, to display the user verification page. The SDK responds to this message by triggering the host program to proactively initiate user verification in order to complete the user ID security verification requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0106] In some embodiments, the SDK server requests a user verification mode from the host program server, and the SDK can receive feedback from the host program server via the SDK server and perform the corresponding operation. Figure 8 is a flowchart of another embodiment of the settlement method provided by a second aspect of the present invention. The difference between Figure 8 and Figure 7 is that the settlement method shown in Figure 8 may also include steps S305 and S306.
[0107] In step S305, in response to the second notification message received by the SDK, rejection prompt information is sent via the SDK.
[0108] The second notification message is sent by the SDK server if the verification operation information contains a payment rejection mark.
[0109] In step S306, the SDK responds to the third notification message it receives by sending passwordless payment prompt information via the SDK.
[0110] A third notification message is sent by the SDK server if the verification operation information includes a password-free payment signature.
[0111] The user verification mode feedback message contains verification operation information. The user verification mode feedback message is sent by the host server in response to the user verification mode request message. The user verification mode request message is sent by the SDK server to the host program server if it indicates that the security verification has been passed. The user verification mode request message contains one or more of the order information, terminal device information, and payment information corresponding to the payment indicated in the payment request message.
[0112] In some embodiments, the first notification message is , check Certificate operation information but user Verification mode If an identifier is included, it is sent by the SDK server. The first notification message includes user verification. mode Includes identifier, and user verification mode The identifier is user Verification mode To prompt the user to enter first user verification input information that matches the identifier, Verification modeThis is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier.
[0113] For specific details of steps S305 and S306 described above, please refer to the relevant explanations in the above embodiment, as they will not be explained again here.
[0114] In some embodiments, the security verification result information includes a target host program identifier. The target host program identifier includes the host program identifier of the payment corresponding to the payment request message. The first notification message is ,Ta - Sent by the SDK server when the GetUserVerification caller is the host program. The TargetUserVerification caller is a user verification caller that matches the TargetHostProgramIdentifier in the First Correspondence, where the TargetHostProgramIdentifier contains the hostProgramIdentifier of the payment corresponding to the payment request message. The First Correspondence includes the relationship between the hostProgramIdentifier and the UserVerification caller.
[0115] In some embodiments, if the target user verification caller is the SDK, the terminal device receives a fourth notification message sent by the SDK server via the SDK. The fourth notification message is sent by the SDK server if the target user verification caller is the SDK. In response to the fourth notification message, the terminal device attempts to invoke the SDK to display the user verification page and prompt the user to enter second user verification input information. The terminal device feeds back the second user verification input information to the SDK server via the SDK. The second user verification input information is used by the SDK server to perform user verification and obtain user verification result information.
[0116] In some embodiments, payment is initiated by the dealer system or by a dealer program installed on the terminal device. Before the SDK server receives the payment request message, there needs to be interaction between the dealer system and the SDK, and between the SDKs themselves, regarding order-related information. Figure 9 is a flowchart of another embodiment of the payment method provided by a second aspect of the present invention. The difference between Figure 9 and Figure 7 is that the payment method shown in Figure 9 may also include steps S307-S309.
[0117] In step S307, an SDK call request message is received via the SDK, which is generated by the seller system in response to the order feedback message.
[0118] Order feedback messages and SDK invocation request messages include an order identifier. The order identifier is generated by the SDK server in response to an order request message sent by the reseller system.
[0119] In step S308, in response to the SDK call request message, a first order inquiry message is sent to the SDK server via the SDK.
[0120] In step S309, the first inquiry feedback message, which was sent from the SDK server in response to the first order inquiry message, is received via the SDK.
[0121] The first inquiry feedback message contains order information corresponding to the order identifier.
[0122] In some embodiments, the order request message includes specified payer identification information. In response to a payment suspension notification message received via the SDK, the terminal device can send payment prompt information via the SDK. The payment suspension notification message is sent by the SDK server when the specified payer identification information does not match the payment N payer identification information indicated in the payment request message.
[0123] The specific details of steps S307 to S309 described above will not be explained again here, as please refer to the related explanations in the above embodiment.
[0124] In some embodiments, payment may be initiated by a user who scans another person's payment code using a terminal device. Before the SDK server receives the payment request message, the SDK and the SDK server must interact with each other regarding order-related information. Figure 10 is a flowchart of yet another embodiment of the payment method provided by a second aspect of the present invention. The difference between Figure 10 and Figure 7 is that the payment method shown in Figure 10 may also include steps S310 to S312.
[0125] In step 310, you scan the payment code to obtain the first code information.
[0126] In step 311, a second order inquiry message is sent to the SDK server via the SDK.
[0127] The second order inquiry message contains the code information from the first order.
[0128] In step 312, a second query feedback message is received, which was sent by the SDK server via the SDK.
[0129] The second inquiry feedback message contains the corresponding order information, including the code information from the first inquiry.
[0130] The specific details of steps S310 to S312 described above will not be explained again here, as they should be referred to in the related explanations of the above embodiment.
[0131] In some embodiments, payment includes a payment initiated by a user displaying a payment code using a terminal device, and a payment initiated by another user scanning a payment code using a payment acceptance terminal. Before the SDK server receives a payment request message, the SDK may request a payment code from the SDK server. Figure 11 is a flowchart of yet another embodiment of the payment method provided by a second aspect of the present invention. The difference between Figure 11 and Figure 7 is that the payment method shown in Figure 11 may also include steps S313 through S315.
[0132] In step S313, a payment code request message is sent to the SDK server via the SDK.
[0133] In step S314, the payment code feedback message sent by the SDK server via the SDK is received.
[0134] The payment code feedback message includes the payment code.
[0135] Step S315 displays the payment code.
[0136] The payment code is scanned by the payment acceptance device and used to generate a payment request message.
[0137] For specific details of steps S313 to S315 described above, please refer to the related explanations in the above embodiment, as they will not be explained again here.
[0138] A third aspect of the present invention provides a settlement method applicable to a host program server. That is, the settlement method can be executed by the host program server. Figure 12 is a flowchart of one embodiment of the settlement method provided by the third aspect of the present invention. As shown in Figure 12, the settlement method may include steps S401 to S403.
[0139] In step S401, the terminal device receives first user verification input information that has been fed back via the host program.
[0140] The first user verification input information is obtained after the SDK notifies the host program to display the user verification page in response to the first notification message. The first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed. The security verification result information is used by the security control system to process the payment request message based on the security verification information in the security verification request message. The security verification request message is sent by the SDK server in response to the received payment request message.
[0141] In step S402, user verification is performed based on the first user verification input information, and user verification result information is obtained.
[0142] In step S403, the SDK sends user verification result information to the SDK server. If the user verification result information indicates that the user verification has passed, the SDK server sends the user verification result information to the host program in the terminal device, and the host program then sends the user verification result information to the SDK.
[0143] In some embodiments, after performing step S403, the host program server sends user verification result information to the SDK server, indicating that the user verification has passed. If the user verification result information meets the consistency verification criteria, the SDK server can initiate a payment request and complete the payment.
[0144] In some examples, consistency verification criteria include ensuring that the first user verification result information matches the second user verification result information. The first user verification result information is the user verification result information that the host program server sends to the SDK via the host program, and the second user verification result information is the user verification result information obtained from the host program server.
[0145] The specific details of steps S401 to S403 described above will not be explained again here, as please refer to the related explanations in the above embodiment.
[0146] In an embodiment of the present invention, the SDK server responds to a payment request message and sends a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of the security verification, the SDK server sends a message to the SDK on the terminal device instructing the SDK to notify the host program to display the user verification page, enabling the SDK to trigger the host program to proactively initiate user verification. The terminal device can receive first user verification input information entered by the user and send the first user verification input information to the host program server. The host program server can then complete the user ID security verification requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0147] In the above embodiment, the host program server stores keys for encrypting and decrypting information exchanged between the host program and the SDK. For specific details, please refer to the relevant explanations in the above embodiment; they will not be repeated here.
[0148] In some embodiments, the host program server can accept requests from the SDK server and provide the SDK server with a user verification mode. The SDK can receive feedback from the host program server via the SDK server and perform corresponding operations. Figure 13 is a flowchart of another embodiment of the settlement method provided by a third aspect of the present invention. The difference between Figure 13 and Figure 12 is that the settlement method shown in Figure 13 may also include steps S404 and S405.
[0149] In step S404, if the security verification result indicates that the security verification has been passed, the system receives a user verification mode request message sent by the SDK server.
[0150] A user verification mode request message includes one or more of the following: order information, terminal device information, and payment information, corresponding to the payment indicated in the payment request message.
[0151] In step S405, a user verification mode feedback message is sent to the SDK server based on the user verification mode request message.
[0152] User verification mode feedback messages include verification operation information.
[0153] If the verification operation information contains a payment rejection mark, the SDK server sends a second notification message to the SDK. The second notification message is used to instruct the SDK to issue a payment rejection prompt. If the verification operation information contains a passwordless payment signature, the SDK server sends a third notification message to the SDK. The third notification message is used to instruct the SDK to issue a passwordless payment prompt.
[0154] In some embodiments, the first notification message is , check Certificate operation information but user Verification mode If an identifier is included, it is sent by the SDK server. The first notification message includes user verification. mode Includes identifier, and user verification mode The identifier is user Verification mode To prompt the user to enter first user verification input information that matches the identifier, Verification mode This is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier.
[0155] The specific details of steps S404 and S405 described above will not be repeated here, as they should be referred to in the related explanations of the above embodiment.
[0156] In some examples, the security verification results information includes a target host program identifier. The target host program identifier includes the host program identifier for the payment corresponding to the payment request message. The first notification message is ,Ta - Sent by the SDK server when the GetUserVerification caller is the host program. The TargetUserVerification caller is the user verification caller that matches the TargetHostProgram identifier in the First Correspondence. The TargetHostProgram identifier contains the hostProgram identifier of the payment corresponding to the payment request message. The First Correspondence contains the relationship between the hostProgram identifier and the UserVerification caller.
[0157] To simplify the explanation, we will use three scenarios as examples to illustrate the interaction of the payment process between terminals, systems, and servers: payment initiated by a dealer program installed in the dealer system or terminal device; payment initiated by a terminal device scanning another person's collection code; and payment initiated by a payment receiving terminal scanning a payment code.
[0158] In this example, payment is initiated by the retail system or through a retail program installed on the terminal device. Figure 14 is a flowchart of an example of a payment process provided by an embodiment of the present invention. The terminal device includes an SDK and a host program. As shown in Figure 14, the payment process includes steps S501 to S522.
[0159] In step S501, after the user places an order, the seller system sends an order request message to the SDK server.
[0160] In step S502, the SDK server responds to the order request message and sends an order feedback message to the dealer system. The order feedback message may include an order identifier generated by the SDK server.
[0161] In step S503, the dealer system sends an SDK call request message to the SDK in the terminal device.
[0162] In step S504, the SDK collects terminal device information.
[0163] In step S505, the SDK sends the first order inquiry message to the SDK server.
[0164] In step S506, the SDK server feeds back the first query feedback message to the SDK.
[0165] In step S507, the SDK sends a payment request message to the SDK server.
[0166] In step S508, the SDK server sends a security verification request message to the security control system.
[0167] In step S509, the security control system performs security verification on the payment indicated by the payment request message.
[0168] In step S510, the security control system feeds back security verification result information to the SDK server.
[0169] In step S511, if the security verification result information indicates that the security verification has passed, the SDK server sends a user verification mode request message to the host program server.
[0170] In step S512, the host program server responds to the user verification mode request message and sends a user verification mode feedback message to the SDK server. The user verification mode feedback message contains the user verification mode It contains an identifier.
[0171] In step S513, the SDK server sends a first notification message to the SDK. The first notification message contains user verification mode It contains an identifier.
[0172] In step S514, the SDK sends a user verification mode identifier to the host program.
[0173] In step S515, the host program is triggered, and the user Verification mode A user verification page matching the identifier will be displayed.
[0174] In step S516, the host program receives first user verification input information entered by the user and sends the first user verification input information to the host program server.
[0175] In step S517, user verification is performed based on the user verification input information of the host program server 1, and user verification result information is obtained.
[0176] In step S518, the SDK server obtains user validation result information from the host program server. For the sake of explanation, the user validation result information that the SDK server obtains directly from the host server will be referred to as the second user validation result information.
[0177] In step S519, the host program server sends user verification result information to the host program.
[0178] In step S520, the host program feeds user verification result information back to the SDK.
[0179] In step S521, the SDK feeds back user validation results information to the SDK server. For the sake of explanation, the user validation results information obtained by the SDK server from the SDK will be referred to as the first user validation results information.
[0180] In step S522, if the first user verification result information and the second user verification result information match, the SDK server initiates a payment request and completes the payment.
[0181] The specific details of steps S501 to S522 described above will not be repeated here, as they should be viewed in the related explanations of the above embodiment.
[0182] In this example, payment is initiated by the terminal device scanning another person's collection code. Figure 15 is a flowchart of another example of a payment process provided by an embodiment of the present invention. The terminal device includes an SDK and a host program. As shown in Figure 15, the payment process includes steps S601 to S621.
[0183] In step S601, the terminal device scans the collection code to obtain the first code information, and the SDK sends a second order inquiry message to the SDK server. The second order inquiry message contains the first code information.
[0184] In step S602, the SDK server sends a second query feedback message to the SDK.
[0185] In step S603, the SDK receives user input and determines the payment amount.
[0186] In step S604, the SDK sends a payment request message to the SDK server.
[0187] In step S605, the SDK server determines whether there are any available payment cards.
[0188] In step S606, if there is an available payment card, the SDK server sends a security verification request message to the security control system.
[0189] In step S607, the security control system performs security verification on the payment indicated by the payment request message.
[0190] In step S608, the security control system feeds back security verification result information to the SDK server.
[0191] In step S609, if the security verification result information indicates that the security verification has passed, the SDK server sends a user verification mode request message to the host program server.
[0192] In step S610, the host program server responds to the user verification mode request message and sends a user verification mode feedback message to the SDK server. The user verification mode feedback message contains the user verification mode It contains an identifier.
[0193] In step S611, the SDK server sends a first notification message to the SDK. The first notification message contains user verification mode It contains an identifier.
[0194] In step S612, the SDK sends a user verification mode identifier to the host program.
[0195] In step S613, the host program is triggered, and the user Verification mode A user verification page matching the identifier will be displayed.
[0196] In step S614, the host program receives first user verification input information entered by the user and sends the first user verification input information to the host program server.
[0197] In step S615, user verification is performed based on the user verification input information of the host program server 1, and user verification result information is obtained.
[0198] In step S616, the SDK server obtains user validation result information from the host program server. For the sake of explanation, the user validation result information that the SDK server obtains directly from the host server is referred to as the second user validation result information.
[0199] In step S617, the host program server sends user verification result information to the host program.
[0200] In step S618, the host program feeds user verification result information back to the SDK.
[0201] In step S619, the SDK feeds back user validation results to the SDK server. For the sake of explanation, the user validation results obtained by the SDK server from the SDK are referred to as the first user validation results.
[0202] In step S620, if the first user verification result information and the second user verification result information match, the SDK server initiates a payment request to the host program server.
[0203] In step S621, the host program server initiates a payment request to the payer's account management system and completes the payment.
[0204] The specific details of steps S601 to S621 described above will not be repeated here, as they should be referred to in the related explanations of the above embodiment.
[0205] In this example, payment is initiated when a payment acceptance terminal scans a payment code displayed on the terminal device. The terminal device includes an SDK and a host program. Here, we take an example of an SDK backend system that includes an SDK backend subsystem and a payment code subsystem. For convenience of explanation, the SDK server in the SDK backend subsystem is referred to as the first SDK server, and the SDK server in the payment code subsystem is referred to as the second SDK server. Figure 16 is a flowchart showing another example of a payment process provided by an embodiment of the present invention. As shown in Figure 16, the payment process may include steps S701 to S723.
[0206] In step S701, the SDK in the terminal device sends a payment code request message to the second SDK server via the first SDK server.
[0207] In step S702, the second SDK server assigns a payment code and sends a payment code feedback message to the SDK via the first SDK server. The payment code feedback message contains the payment code.
[0208] In step S703, the payment acceptance terminal scans the payment code displayed on the terminal device, obtains second code information, and sends a payment request message to the second SDK server.
[0209] In step S704, the second SDK server sends a payment policy inquiry message to the host program server via the payment policy system.
[0210] In step S705, the host program server feeds back payment policy information to the second SDK server via the payment policy system.
[0211] In step S706, the second SDK server sends an additional processing request message to the first SDK server. The additional processing request message contains payment policy information.
[0212] In step S707, the first SDK server sends a security verification request message to the security control system.
[0213] In step S708, the security control system performs security verification on the payment indicated by the payment request message.
[0214] In step S709, the security control system feeds back the security verification result information to the first SDK server.
[0215] In step S710, the first SDK server synchronizes payment information, order information, and other information with the host program server via the second SDK server.
[0216] In step S711, the first SDK server sends a user verification mode request message to the host program server via the second SDK server.
[0217] In step S712, the host program server sends a user verification mode feedback message to the first SDK server via the second SDK server. The user verification mode feedback message contains user verification mode It contains an identifier.
[0218] In step S713, the first SDK server sends a first notification message to the SDK. The first notification message contains user verification mode It contains an identifier.
[0219] In step S714, the SDK sends a user verification mode identifier to the host program.
[0220] In step S715, the host program is triggered, and the user Verification mode A user verification page matching the identifier will be displayed.
[0221] In step S716, the host program receives first user verification input information entered by the user and sends the first user verification input information to the host program server.
[0222] In step S717, user verification is performed based on the user verification input information of the host program server 1, and user verification result information is obtained.
[0223] In step S718, the first SDK server obtains user validation result information from the host program server via the second SDK server. For the sake of explanation, the user validation result information obtained by the SDK server from the host server via the second SDK server will be referred to as the second user validation result information.
[0224] In step S719, the host program server sends user verification result information to the host program.
[0225] In step S720, the host program feeds user verification result information back to the SDK.
[0226] In step S721, the SDK feeds back the user verification result information to the first SDK server. For the sake of explanation, the user verification result information obtained by the first SDK server from the SDK is referred to as the first user verification result information. If the owner of the host program and the owner of the payment card are the same, proceed to step S724; otherwise, proceed to step S725.
[0227] In step S722, if the first user verification result information and the second user verification result information match, the first SDK server initiates a payment request to the payer's account management system via the second SDK server and the host program server to complete the payment.
[0228] In step S723, if the first user verification result information and the second user verification result information match, the first SDK server initiates a payment request to the payer's account management system via the second SDK server and completes the payment.
[0229] Prior to steps S722 and S723 above, if the payment uses payment policy information, the second SDK server can also interact with the payment policy system to comply with the payment policy information.
[0230] The specific details of steps S701 to S723 described above will not be repeated here, as they should be viewed in the related explanations of the above embodiment.
[0231] A fourth aspect of the present invention provides an SDK server. Figure 17 is a schematic diagram of one embodiment of the SDK server provided according to the fourth aspect of the present invention. As shown in Figure 17, the SDK server 800 may include a transmitting module 801 and a receiving module 802.
[0232] The transmission module 801 is configured to send a security verification request message to the security control system in response to a received payment request message.
[0233] The security verification request message includes security verification information to instruct the security control system to perform security verification of the payment corresponding to the payment request message, based on the security verification information.
[0234] The receiving module 802 may be configured to receive security verification result information transmitted by the security control system.
[0235] The transmission module 801 can also be configured to send a first notification message to the SDK in the terminal device if the security verification result information indicates that the security verification has been passed.
[0236] The terminal device includes an SDK and a host program. A first notification message is used to instruct the SDK to notify the host program and display a user verification page in order to prompt the user to enter first user verification input information. The first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
[0237] The transmission module 801 can also be configured to initiate a payment request and complete the payment if the user verification result information indicates that user verification has been passed.
[0238] In some embodiments, the transmission module 801 may also be configured to initiate a payment request if the user verification result information meets the consistency verification criteria.
[0239] In some examples, consistency verification criteria include ensuring that the first user verification result matches the second user verification result.
[0240] The first user verification result information is the user verification result information that the host program server sends to the SDK via the host program. The second user verification result information is the user verification result information obtained from the host program server.
[0241] In an embodiment of the present invention, the SDK server responds to a payment request message by sending a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of the security verification, the SDK server sends a message to the SDK on the terminal device instructing the SDK to notify the host program to display the user verification page, thereby causing the SDK to trigger the host program to proactively initiate user verification and complete the user ID security requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0242] In some examples, the SDK server stores keys used to encrypt and decrypt information exchanged between the SDK and the host program.
[0243] In some embodiments, the transmission module 801 may be configured to send a user verification mode request message to the host program server if the security verification result information indicates that the security verification has passed.
[0244] A user verification mode request message includes one or more of the following: order information, terminal device information, and payment information, corresponding to the payment indicated in the payment request message.
[0245] The receiving module 802 can also be configured to receive user verification mode feedback messages sent by the host program server.
[0246] User verification mode feedback messages include verification operation information.
[0247] The transmitting module 801 can also be configured to send a second notification message to the SDK if the verification operation information contains a payment rejection mark.
[0248] The second notification message is used to instruct the SDK to issue a payment rejection prompt.
[0249] The receiving module 802 can also be configured to send a third notification message to the SDK if the verification operation information includes a password-free payment signature.
[0250] The third notification message is used to instruct the SDK to issue a passwordless payment prompt.
[0251] In some embodiments, the transmission module 801 transmits verification operation information. but user Verification mode If an identifier is included, it is configured to send a first notification message to the SDK.
[0252] The first notification message is: User verification mode Includes identifier, and user verification mode The identifier is user Verification mode To prompt the user to enter first user verification input information that matches the identifier, Verification mode This is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier.
[0253] In some embodiments, the SDK server may further include a query module.
[0254] The query module determines the target user verification caller corresponding to the target host program identifier based on the target host program identifier and a pre-configured first correspondence.
[0255] The first correspondence includes the relationship between the host program identifier and the user-validated caller.
[0256] The sending module 801 can be configured to send a first notification message to the SDK if the target user verification caller is the host program.
[0257] In some embodiments, the sending module 801 may also be configured to send a fourth notification message to the SDK if the target user verification caller is the SDK.
[0258] The fourth notification message is used to instruct the SDK to display a user verification page and prompt the user to enter second user verification input information. The second user verification input information is used by the SDK server to perform user verification and retrieve user verification result information.
[0259] In some embodiments, the SDK server 800 may further include an order identifier generation module.
[0260] The order identifier generation module may be configured to generate order identifiers in response to order request messages sent by the dealer system.
[0261] The transmitting module 801 can also send order feedback messages to the dealer system so that the dealer system can send an SDK call request message to the SDK.
[0262] Order feedback messages and SDK call request messages include an order identifier.
[0263] The transmitting module 801 can also send a first inquiry feedback message to the SDK in response to a first order inquiry message sent by the SDK.
[0264] The first query feedback message includes order information corresponding to the order identifier.
[0265] In some embodiments, the order request message includes specified payer identification information.
[0266] If the specified payer identification information in the sending module 801 does not match the payer identification information of the settlement indicated by the settlement request message, the sending module 801 sends a settlement stop notification message to the SDK to cause the SDK to issue settlement prompt information.
[0267] In some embodiments, the receiving module 802 is further configured to receive a second order query message sent by the SDK of the terminal device.
[0268] The second order query message includes first code information obtained by scanning a collection code by the terminal device.
[0269] The sending module 801 is further configured to send a second query feedback message to the SDK.
[0270] The second query feedback message includes order information corresponding to the inclusion of the first code information.
[0271] In some embodiments, the sending module 801 can also be configured to send a payment code feedback message to the SDK in response to the received payment code application message.
[0272] The payment code application message is sent by the SDK. The payment code feedback message includes a payment code. Accordingly, the settlement request message is generated based on the settlement code scanned by the payment acceptance device.
[0273] A fifth aspect of the present invention provides a terminal device, which includes an SDK and a host program. Figure 18 is a schematic diagram of one embodiment of the terminal device provided by the fifth aspect. As shown in Figure 18, the terminal device 900 includes a receiving module 901, a display module 902, and a transmitting module 903.
[0274] The receiving module 901 is configured to receive a first notification message sent by the SDK server via the SDK.
[0275] The first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed. The security verification result information is obtained when the security control system performs security verification on the payment corresponding to the payment request message based on the security verification information in the security verification request message. The security verification request message is sent by the SDK server in response to the received payment request message.
[0276] The display module 902 may be configured to respond to a first notification message by notifying the host program via the SDK to display a user verification page to prompt the user to enter first user verification input information.
[0277] The transmission module 903 may be configured to feed back first user validation input information to the host program server via the host program.
[0278] The first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
[0279] The transmission module 903 sends user verification result information obtained from the host program server via the host program to the SDK server via the SDK. If the user verification result information indicates that user verification has passed, the SDK server initiates a payment request and allows the payment to be completed.
[0280] In some embodiments, the user verification result information is also used to enable the SDK server to initiate a payment request if it meets the consistency verification criteria.
[0281] In some examples, consistency verification criteria include ensuring that the first user verification result information matches the second user verification result information. The first user verification result information is the user verification result information that the host program server sends to the SDK via the host program. The second user verification result information is the user verification result information obtained from the host program server.
[0282] In this embodiment of the present invention, the SDK server responds to a payment request message by sending a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of security verification, the SDK in the terminal device receives a message instructing the SDK to notify the host program, sent by the SDK server, to display the user verification page. The SDK responds to this message by triggering the host program to proactively initiate user verification in order to complete the user ID security verification requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0283] In some cases, the SDK has a security domain, and the information within the SDK is stored in the security domain.
[0284] The information exchanged between the SDK and the host program is encrypted. The encryption and decryption keys within the SDK are stored on the SDK server. The encryption and decryption keys within the host program are stored on the host program server.
[0285] In some embodiments, the display module 902 may also be configured to send rejection prompt information via the SDK in response to a second notification message received by the SDK.
[0286] The second notification message is sent by the SDK server if the verification operation information contains a payment rejection mark.
[0287] The display module 902 can also be configured to send passwordless payment prompt information via the SDK in response to a third notification message received by the SDK.
[0288] A third notification message is sent by the SDK server if the verification operation information includes a password-free payment signature.
[0289] Here, the user verification mode feedback message contains verification operation information. The user verification mode feedback message is sent by the host server in response to the user verification mode request message. The user verification mode request message is sent by the SDK server to the host program server if it indicates that the security verification has been passed. The user verification mode request message contains one or more of the order information, terminal device information, and payment information corresponding to the payment indicated by the payment request message.
[0290] In some embodiments, the first notification message is , checkProof operation information but User Verification mode If it contains an identifier, it is sent by the SDK server. The first notification message contains user verification mode An identifier is included, and the user verification mode The identifier is for the user Verification mode To prompt the user to enter the first user verification input information that matches the identifier, the user Verification mode It is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier.
[0291] In some embodiments, the security verification result information includes a target host program identifier. The target host program identifier includes a host program identifier for settlement corresponding to the settlement request message. The first notification message is ,Ta - Sent by the SDK server when the target user verification caller is the host program. The target user verification caller is a user verification caller that matches the target host program identifier in the first correspondence relationship. The target host program identifier includes a host program identifier for settlement corresponding to the settlement request message. The first correspondence relationship includes the relationship between the host program identifier and the user verification caller.
[0292] In some embodiments, the receiving module 901 may be configured to obtain the fourth notification message sent by the SDK server via the SDK. The fourth notification message is sent by the SDK server when the target user verification caller is the SDK.
[0293] The display module 902 is configured to call the SDK to display a user verification page in response to the fourth notification message and attempt to prompt the user to enter the second user verification input information.
[0294] The transmission module 903 can also be configured to feed back second user validation input information to the SDK server via the SDK.
[0295] The second user validation input information is used by the SDK server to perform user validation and retrieve user validation result information.
[0296] In some embodiments, the receiving module 901 may also be configured to receive SDK call request messages via the SDK.
[0297] The SDK invocation request message is generated by the seller system in response to the order feedback message. Both the order feedback message and the SDK invocation request message contain an order identifier. The order identifier is generated by the SDK server in response to the order request message sent by the seller system.
[0298] The transmitting module 903 can also be configured to send a first order inquiry message to the SDK server via the SDK in response to an SDK call request message.
[0299] The receiving module 901 can also be configured to receive the first inquiry feedback message sent from the SDK server in response to the first order inquiry message via the SDK.
[0300] The first inquiry feedback message contains order information corresponding to the order identifier.
[0301] In some embodiments, the order request message includes specified payer identification information.
[0302] The display module 902 can also be configured to issue payment prompt information via the SDK in response to a payment suspension notification message received via the SDK.
[0303] A payment suspension notification message is sent by the SDK server when the specified payer identification information does not match the payment N payer identification information indicated in the payment request message.
[0304] In some embodiments, the terminal device 900 may further include a scan module.
[0305] The scanning module is configured to scan the payment code and obtain the first code information.
[0306] The sending module 903 can also be configured to send a second order inquiry message to the SDK server via the SDK.
[0307] The second order inquiry message contains the code information from the first order.
[0308] The receiving module 901 can also be configured to receive a second query feedback message sent by the SDK server via the SDK.
[0309] The second inquiry feedback message contains the corresponding order information, including the code information from the first inquiry.
[0310] In some embodiments, the sending module 903 may also be configured to send payment code request messages to the SDK server via the SDK.
[0311] The receiving module 901 can also be configured to receive payment code feedback messages sent by the SDK server via the SDK. The payment code feedback message contains a payment code.
[0312] The display module 902 can also be configured to display the payment code.
[0313] The payment code is scanned by the payment acceptance device and used to generate a payment request message.
[0314] A sixth aspect of the present invention provides a host program server. Figure 19 is a schematic diagram of one embodiment of the host program server provided by the sixth aspect. As shown in Figure 19, the host program server 1000 includes a receiving module 1001, a verification module 1002, and a transmitting module 1003.
[0315] The receiving module 1001 is configured to receive first user verification input information that has been fed back by the terminal device via the host program.
[0316] The terminal device includes a software development kit (SDK) and a host program. The first user verification input information is obtained after the SDK notifies the host program to display the user verification page in response to the first notification message. The first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed. The security verification result information is used by the security control system to process the payment request message based on the security verification information in the security verification request message. The security verification request message is sent by the SDK server in response to the received payment request message.
[0317] The verification module 1002 is configured to perform user verification based on the first user verification input information and to obtain user verification result information.
[0318] The transmission module 1003 is configured to send user verification result information to a host program in the terminal device, and then to send the user verification result information to the SDK via the host program. The SDK then sends the user verification result information to the SDK server, and if the user verification result information indicates that the user verification has passed, the SDK server initiates a payment request and completes the payment.
[0319] In some embodiments, the sending module 1003 indicates that the user verification result information has passed user verification by sending it to the SDK server. If the user verification result information meets the consistency verification criteria, the SDK server can initiate a payment request and complete the payment.
[0320] In some examples, consistency verification criteria include ensuring that the first user verification result matches the second user verification result.
[0321] The first user verification result information is the user verification result information that the host program server sends to the SDK via the host program. The second user verification result information is the user verification result information obtained from the host program server.
[0322] In an embodiment of the present invention, the SDK server responds to a payment request message and sends a security verification request message to the security control system, requesting the security control system to perform security verification for the current payment, thereby completing the security verification requested by the SDK owner. Upon successful completion of the security verification, the SDK server sends a message to the SDK on the terminal device instructing the SDK to notify the host program to display the user verification page, enabling the SDK to trigger the host program to proactively initiate user verification. The terminal device can receive first user verification input information entered by the user and send the first user verification input information to the host program server. The host program server can then complete the user ID security verification requested by the host program owner. In the payment process, bidirectional verification between the SDK owner and the host program owner is achieved, improving the security of the payment and satisfying the security management needs of both parties.
[0323] In some examples, the host program server stores keys used to encrypt and decrypt information exchanged between the host program and the SDK.
[0324] In some embodiments, the receiving module 1001 may be configured to receive a user verification mode request message sent by the SDK server if it indicates that the security verification has been passed.
[0325] A user verification mode request message includes one or more of the following: order information, terminal device information, and payment information, corresponding to the payment indicated in the payment request message.
[0326] The transmission module 1003 may be configured to send a user verification mode feedback message to the SDK server based on the user verification mode request message.
[0327] User verification mode feedback messages include verification operation information.
[0328] If the verification operation information contains a payment rejection mark, the SDK server sends a second notification message to the SDK. The second notification message is used to instruct the SDK to issue a payment rejection prompt. If the verification operation information contains a passwordless payment signature, the SDK server sends a third notification message to the SDK. The third notification message is used to instruct the SDK to issue a passwordless payment prompt.
[0329] In some embodiments, the first notification message is , check Certificate operation information but user Verification mode If an identifier is included, it is sent by the SDK server. The first notification message includes user verification. mode Includes identifier, and user verification mode The identifier is user Verification mode To prompt the user to enter first user verification input information that matches the identifier, Verification mode This is used to instruct the SDK to notify the host program to display a user verification page that matches the identifier.
[0330] In some embodiments, the security verification results information includes a target host program identifier. The target host program identifier includes the host program identifier for the payment corresponding to the payment request message.
[0331] The first notification message is ,Ta- Sent by the SDK server when the GetUserVerification caller is the host program. The TargetUserVerification caller is the user verification caller that matches the TargetHostProgram identifier in the First Correspondence. The TargetHostProgram identifier contains the hostProgram identifier of the payment corresponding to the payment request message. The First Correspondence contains the relationship between the hostProgram identifier and the UserVerification caller.
[0332] A seventh aspect of the present invention provides an SDK server. Figure 20 is a schematic diagram of one embodiment of the SDK server provided by the seventh aspect of the present invention. As shown in Figure 20, the SDK server 1100 includes a memory 1101, a processor 1102, and a computer program stored in the memory 1101 and executable on the processor 1102.
[0333] In some examples, the processor 1102 may include a central processing unit (CPU) or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of embodiments of the present invention.
[0334] The memory 1101 may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. In general, the memory includes one or more tangible (non-temporary) computer-readable storage media (e.g., memory devices) encoded with software that includes computer executable instructions, and when such software is executed (e.g., by one or more processors), it can perform the operations described with reference to the settlement method of the first embodiment of the present invention.
[0335] The processor 1102 reads the executable program code stored in the memory 1101, executes the computer program corresponding to that executable program code, and realizes the settlement method in the embodiment of the first aspect described above.
[0336] In some examples, the SDK server 1100 may also include a communication interface 1103 and a bus 1104. Here, as shown in Figure 20, the memory 1101, processor 1102, and communication interface 1103 are connected via the bus 1104 and communicate with each other.
[0337] In embodiments of the present invention, the communication interface 1103 is primarily used to facilitate communication between modules, devices, units, and / or equipment. Input devices and / or output devices may be accessed via the communication interface 1103.
[0338] Bus 1104 includes hardware, software, or both that interconnect the components of SDK Server 1100. Examples, but not limited to, include Accelerated Graphics Port (AGP) or other graphics buses, Enhanced Industry Standard Architecture (EISA) buses, Front Side Bus (FSB), Hyper Transport (HT) interconnects, Industry Standard Architecture (ISA) buses, unlimited bandwidth interconnects, Low pin count (LPC) buses, memory buses, Micro Channel Architecture (MCA) buses, Peripheral Component Interconnect (PCI) buses, PCI-Express (PCI-E) buses, Serial Advanced Technology Attachment (SATA) buses, Video Electronics Standards Association Local Bus (VLB) buses, or other appropriate buses, or a combination of two or more of these. If necessary, bus 1104 may include one or more buses. While embodiments of the present invention describe and illustrate specific buses, the present invention can accommodate any suitable bus or interconnection.
[0339] An eighth aspect of the present invention provides a terminal device. The terminal device may include memory, a processor, and a computer program stored in memory and executable on the processor. For the types and relationships of memory and processor, see the above-described description of memory and processor in the SDK server. The difference from the above-described SDK server is that, once the software in memory is executed, it is operable to perform the operations described with reference to the settlement method in the embodiment of the second aspect of the present invention. Furthermore, by reading the executable program code stored in memory, the processor is configured to execute the computer program corresponding to the executable program code and to perform the settlement method in the embodiment of the second aspect. In some examples, the terminal device may also include a communication interface and a bus. The memory, processor, and communication interface are connected via the bus and can communicate with each other. The communication connections between the memory, processor, communication interface, and bus can be seen by referring to the communication connections between memory, processor, communication interface, and bus in the SDK server shown in Figure 20, which will not be repeated here.
[0340] A ninth aspect of the present invention provides a host program server. The host program server may include memory, a processor, and a computer program stored in memory and executable on the processor. For the types and relationships of memory and processor, see the above-described descriptions of memory and processor in the SDK server. The difference from the above-described SDK server is that, once the software in memory is executed, it is operable to perform the operations described with reference to the settlement method in the embodiment of the third aspect of the present invention. Furthermore, the processor is configured to execute a computer program corresponding to the executable program code and to perform the settlement method in the embodiment of the third aspect. In some examples, the host program server may also include a communication interface and a bus. The memory, processor, and communication interface are connected via the bus and can communicate with each other. The communication connections between the memory, processor, communication interface, and bus can be seen in the communication connections between memory, processor, communication interface, and bus in the SDK server shown in Figure 20, which are not repeated here.
[0341] A tenth aspect of the present invention provides a payment system. This payment system may include the SDK server, terminal device, and host program server described in the above embodiment. Details of the SDK server, terminal device, and host program server are described in the relevant descriptions of the above embodiment and will not be repeated here.
[0342] An eleventh aspect of the present invention also provides a computer-readable storage medium. Computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are executed by a processor, the settlement method of the first aspect, the settlement method of the second aspect, and / or the settlement method of the third aspect in the above embodiment can be implemented, achieving similar technical effects. To avoid redundancy, details will not be described again here. Here, the computer-readable storage medium includes, but is not limited to, a non-temporary computer-readable storage medium, such as read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0343] Embodiments of the present invention may also provide a computer program product in which instructions within the computer program product are executed by the processors of the SDK server, terminal device, and host program server, and the SDK server, terminal device, and host program server execute the settlement method of the first embodiment, the settlement method of the second embodiment, or the settlement method of the third embodiment.
[0344] Each embodiment described herein is explained step-by-step, and it should be noted that each embodiment can be referenced to others for differences and similarities. Each embodiment highlights its differences from others. Details of the SDK server embodiment, user terminal embodiment, device embodiment, system embodiment, and computer-readable storage medium embodiment are described in the description of the method embodiment. The present invention is not limited to the specific steps and structures described above and shown in the drawings. Those skilled in the art will understand the spirit of the invention and can make various changes, modifications, additions, and alter the order of the steps. Also, for the sake of brevity, a detailed description of known method technology is omitted here.
[0345] Aspects of the present invention have been described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block in the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to generate a machine that can be implemented by executing the instructions via the processor of the computer or other programmable data processing device. Thus, these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes in the flowcharts and / or block diagrams. Such a processor may be, but is not limited to, a general-purpose processor, a dedicated processor, a dedicated application processor, or a field-programmable logic circuit. It will also be understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware or software that performs a specified function or operation. It will also be understood that they can be implemented by a combination of dedicated hardware and computer instructions.
[0346] Those skilled in the art will understand that the embodiments described above are illustrative and not restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Those skilled in the art will be able to understand and implement other modified embodiments of the disclosed embodiments based on a review of the drawings, specification, and scope of the patent message. In the claims, the term “including” is not exclusive of other means or steps; the quantifier “one” is not exclusive of plural; and the terms “first” and “second” are used to indicate names, not a specific order. No reference numeral in the claims should be construed as limiting the scope. The functionality of some parts described within the scope of the patent message can be implemented by a single hardware or software module. The appearance of certain technical features in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.
Claims
1. A payment method applicable to a Software Development Kit (SDK) server, The steps include sending a security verification request message to the security control system in response to a received payment request message, The steps include receiving security verification result information transmitted by the security control system, If the security verification result indicates that the information security verification has been passed, the first step is to send a notification message to the SDK in the terminal device. If the user verification result information indicates that user verification has passed, the steps to initiate a payment request and complete the payment are as follows: Includes, The security verification request message includes security verification information and is used to instruct the security control system to perform security verification of the payment corresponding to the payment request message based on the security verification information. A payment method comprising a terminal device having an SDK and a host program, wherein the first notification message is used to notify the host program and instruct the SDK to display a user verification page in order to prompt the user to input first user verification input information, and the first user verification input information is used by the host program server to perform user verification and obtain user verification result information.
2. After receiving the security verification result information transmitted by the security control system, If the security verification result indicates that the information security verification has been passed, the user verification mode request message is sent to the host program server. The steps include receiving a user verification mode feedback message containing verification operation information sent by the host program server, If the verification operation information includes a payment rejection mark, the second notification message is sent to the SDK. If the verification operation information includes a password-free payment signature, the third notification message is sent to the SDK. Includes, The user verification mode request message includes one or more of the order information, terminal device information, and payment information corresponding to the payment indicated by the payment request message. The second notification message is used to instruct the SDK to issue payment rejection prompt information. The settlement method according to claim 1, wherein the third notification message is used to instruct the SDK to issue passwordless payment prompt information.
3. The step of sending a first notification message to the SDK in the terminal device is: If the verification operation information includes a user verification mode identifier, the step includes sending the first notification message to the SDK. The settlement method according to claim 2, wherein the first notification message includes the user verification mode identifier and is used to notify the host program and instruct the SDK to display a user verification page matching the user verification mode identifier in order to prompt the user to enter the first user verification input information matching the user verification mode identifier.
4. The security verification result information includes a target host program identifier, and the target host program identifier includes the host program identifier for the payment corresponding to the payment request message. Before sending the first notification message to the SDK in the terminal device, The step further includes determining a target user verification caller corresponding to the target host program identifier based on the target host program identifier and a pre-configured first correspondence, wherein the first correspondence includes the relationship between the host program identifier and the user verification caller. The step of sending a first notification message to the SDK in the terminal device is: The settlement method according to claim 1, further comprising the step of sending the first notification message to the SDK if the target user verification caller is the host program.
5. Based on the target host program identifier and the pre-configured first correspondence, after determining the target user verification caller corresponding to the target host program identifier, If the target user verification caller is the SDK, the further step includes sending a fourth notification message to the SDK. The settlement method according to claim 4, wherein the fourth notification message is used to instruct the SDK to display a user verification page in order to prompt the user to enter second user verification input information, and the second user verification input information is used by the SDK server to perform user verification and obtain user verification result information.
6. The step of initiating the payment request is: The settlement method according to claim 1, further comprising the step of initiating a payment request if the user verification result information satisfies the consistency verification criteria.
7. The aforementioned consistency verification criteria are: The settlement method according to claim 6, comprising: first user verification result information matching second user verification result information; first user verification result information being user verification result information transmitted from the host program server to the SDK via the host program; and second user verification result information being user verification result information obtained from the host program server.
8. The settlement method according to claim 1, wherein the SDK server stores keys used to encrypt and decrypt information exchanged between the SDK and the host program.
9. In response to the received payment request message, before sending a security verification request message to the security control system, A step of generating an order identifier in response to an order request message sent by the dealer system, The steps include sending an order feedback message to the dealer system and causing the dealer system to send an SDK call request message to the SDK, The steps include sending a first inquiry feedback message to the SDK in response to a first order inquiry message sent by the SDK, Includes, The order feedback message and the SDK call request message include the order identifier. The settlement method according to claim 1, wherein the first inquiry feedback message includes order information corresponding to the order identifier.
10. The aforementioned order request message includes the specified payer identification information. The aforementioned method, The settlement method according to claim 9, further comprising the step of the SDK sending a settlement suspension notification message in order to cause the SDK to issue settlement prompt information if the specified payer identification information does not match the payer identification information for settlement indicated by the settlement request message.
11. In response to the received payment request message, before sending a security verification request message to the security control system, The steps include receiving a second order inquiry message transmitted by the SDK of the terminal device, The steps include sending a second inquiry feedback message to the SDK, The second order inquiry message includes the first code information obtained by scanning the collection code by the terminal device. The settlement method according to claim 1, wherein the second inquiry feedback message includes order information corresponding to the first code information.
12. In response to the received payment request message, before sending a security verification request message to the security control system, The further step includes sending a payment code feedback message to the SDK in response to a received payment code request message, The payment code request message is sent by the SDK, and the payment code feedback message includes the payment code. The payment method according to claim 1, wherein the payment request message is generated by a payment receiving device based on the scanned payment code.
13. A payment method applicable to a terminal device, The terminal device includes a software development kit (SDK) and a host program. The aforementioned method, The steps include: obtaining a first notification message sent by the SDK server via the SDK; In response to the first notification message, the host program is instructed via the SDK to display a user verification page and prompt the user to enter first user verification input information. The steps include feeding back the first user verification input information to the host program server via the host program, The steps include: sending user verification result information obtained from the host program server via the host program to the SDK server via the SDK, and if the SDK server indicates that the user verification result information has passed user verification, initiating a payment request and attempting to complete the payment; Includes, The first notification message is transmitted by the SDK server based on security verification result information indicating that the security verification has been passed, the security verification result information is obtained by the security control system performing a security verification on the payment corresponding to the payment request message based on the security verification information in the security verification request message, and the security verification request message is transmitted by the SDK server in response to the received payment request message. The first user verification input information is used by the host program server to perform user verification and obtain the user verification result information, and is a payment method.
14. A payment method applied to the host program server, The steps include receiving first user verification input information fed back via a host program by a terminal device, The steps include: performing user verification based on the first user verification input information and obtaining user verification result information; The steps include: transmitting the user verification result information to the host program in the terminal device, transmitting the user verification result information to the SDK via the host program, causing the SDK to transmit the user verification result information to the SDK server, and if the user verification result information indicates that the user verification has passed, the SDK server initiates a payment request and attempts to complete the payment; Includes, The terminal device comprises a software development kit (SDK) and a host program, the first user verification input information is obtained after the SDK notifies the host program to display a user verification page in response to a first notification message, the first notification message is sent by the SDK server based on security verification result information indicating that security verification has been passed, the security verification result information is obtained by a security control system performing security verification on a payment corresponding to a payment request message based on security verification information in a security verification request message, and the security verification request message is sent by the SDK server in response to a received payment request message, the payment method.
15. A computer-readable storage medium, A computer-readable storage medium in which computer program instructions are stored, and when the computer program instructions are executed by a processor, the settlement method according to any one of claims 1 to 14 is realized.
Citation Information
Patent Citations
Credit card check system, method for checking availability of settlement by credit card, and computer program
JP2005275459A
Electronic settlement apparatus and electronic settlement method
JP2009289063A
Portable terminal utilization transaction system and method
JP2015087832A
Advertisement processing device and program
JP2017102754A
Server and communication device
JP2020057392A