Information processing device, information processing method, and information processing program

The information processing system generates and displays a code image on a widget using stored token information, addressing the time and network dependency of existing code settlement methods, enabling immediate and secure payments directly from a widget without app launch.

JP7838138B1Active Publication Date: 2026-03-31NTT DOCOMO INC
View PDF 21 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing code settlement methods, such as QR Code-based CPM, require launching a settlement application, which is time-consuming and network-dependent, especially in offline conditions.

Method used

An information processing apparatus and method that generates and displays a code image on a widget without launching the settlement application, using pre-acquired token information stored as non-volatile data, enabling immediate settlement regardless of network status, and updates the code image at predetermined intervals using a time-synchronized one-time token.

Benefits of technology

Enables immediate and secure code payments without requiring a network connection, preventing unauthorized use through token expiration and theft, and enhancing user convenience by allowing payments directly from a widget without app launch.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007838138000001_ABST
    Figure 0007838138000001_ABST
Patent Text Reader

Abstract

This invention provides an information processing device, method, and program that enable immediate payment in CPM-based code payments, regardless of network conditions, without requiring the launch of a payment application. [Solution] The user terminal 10, which is an information processing device, comprises a display unit 11, a storage unit 12, and a control unit 13. The acquisition unit 133 of the control unit acquires token information, the storage unit stores the acquired token information, the code image generation unit 135 of the control unit generates a code image based on the token information stored in the storage unit, and the display control unit 136 of the control unit displays the code image on a widget displayed on the display unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information processing method, and an information processing program.

Background Art

[0002] Currently, code settlement using codes such as QR Code (registered trademark) has become widespread (for example, Patent Document 1).

[0003] When a user performs code settlement in the CPM (Consumer Presented Mode) method, the user needs to start a settlement application on their user terminal and display a settlement barcode on the display unit of the user terminal, which takes time both for offline settlement and normal online settlement.

Prior Art Documents

Patent Documents

[0004] [[ID=?]]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In view of the above background, an object of the present invention is to provide an information processing apparatus and the like that enable immediate settlement without starting a settlement application regardless of the network state in CPM method code settlement.

Means for Solving the Problems

[0006] The information processing apparatus of the present invention includes a display unit, an acquisition unit that acquires token information, a storage unit that stores the acquired token information, a code image generation unit that generates a code image based on the token information stored in the storage unit, and a display control unit that displays the code image on a widget displayed on the display unit.

[0007] The present invention relates to an information processing method performed by a computer of an information processing device used by a user, comprising the steps of: acquiring token information; storing the acquired token information; generating a code image based on the stored token information; and displaying the code image on a widget displayed on the display unit of the information processing device.

[0008] The information processing program of the present invention is an information processing program that is pre-installed on an information processing device used by a user, and causes the information processing device to function as: an acquisition unit that acquires token information; a storage unit that stores the acquired token information; a code image generation unit that generates a code image based on the token information stored in the storage unit; and a display control unit that displays the code image on a widget displayed on the display unit. [Effects of the Invention]

[0009] According to the present invention, in CPM-based code payment, payment can be made immediately regardless of the network status, without having to launch a payment application. [Brief explanation of the drawing]

[0010] [Figure 1] Figure 1 is a block diagram of the payment processing system S according to this embodiment. [Figure 2] Figure 2 is an operation sequence diagram of the payment processing system S according to this embodiment, showing the operation sequence until payment is completed. [Figure 3] Figure 3 shows an example of the hardware configuration of the user terminal 10 according to this embodiment. [Figure 4] Figure 4 shows an example of the hardware configuration of the payment server 20 according to this embodiment. [Figure 5] Figure 5 is a diagram showing the functional configuration of the user terminal 10 according to this embodiment. [Figure 6]Figure 6(a) shows an example of a code image CI displayed on the widget WG shown on the display unit 11. Figure 6(b) shows an example where the payment method change button B1, point redemption switch button B2, and app launch button B3 are displayed on the widget WG. Figure 6(c) shows an example where payment completion information F1 is displayed on the widget WG. [Figure 7] Figure 7 shows an example of displaying a code image CI on the widget WG shown on the display unit 11 when biometric authentication by the biometric authentication execution unit 137 is successful. [Figure 8] Figure 8 shows the functional configuration of the payment server 20 according to this embodiment. [Figure 9] Figure 9 shows an example of a token information database (DBt). [Figure 10] Figure 10 is a flowchart showing an example of the operations performed by the user terminal 10 of the payment processing system S according to this embodiment. [Figure 11] Figure 11 is a flowchart showing an example of the operations performed by the payment server 20 of the payment processing system S according to this embodiment. [Modes for carrying out the invention]

[0011] The payment processing system according to this embodiment will be described below with reference to the drawings. Note that the following description is merely an example of a preferred embodiment and is not intended to limit the invention as described in the claims. Furthermore, the same parts are denoted by the same reference numerals in each of the following embodiments, and redundant descriptions are omitted.

[0012] [Overview of Payment Processing System S] Figure 1 is a block diagram of the payment processing system S according to this embodiment. In Figure 1, the payment processing system S executes processing related to code payment. In this embodiment, the CPM (Consumer Presented Mode) method is used as the code payment method. The payment code used as a code image in CPM code payment (hereinafter sometimes simply referred to as "CPM payment") may be a one-dimensional barcode or a two-dimensional barcode.

[0013] The payment processing system S comprises a user terminal 10, a payment server 20, and a store terminal 30. The user terminal 10 is an information processing device used by the user, such as a smartphone, tablet, or personal computer. The payment server 20 is an information processing device that provides content usable in code payments using the user's user terminal 10, and is implemented by, for example, a server device or a cloud system. For example, the payment server 20 issues token information to the user's user terminal 10 to generate a payment code and performs payment processing.

[0014] The store terminal 30 is an information processing device used by businesses that provide goods, services, or other transaction items to users, such as POS (Point-of-Sales) terminals. The payment server 20 can communicate with the user terminal 10 and the store terminal 30 via a network (not shown). The network includes, for example, the internet, LAN (Local Area Network), wireless base stations, and provider equipment. Note that the payment processing system S shown in Figure 1 may include multiple user terminals 10, multiple payment servers 20, and multiple store terminals 30.

[0015] The user terminal 10 has a payment application installed that provides a terminal-side code payment service compatible with the CPM method. By launching the payment application on the user terminal 10, the user can use the user terminal 10 to pay for goods and services (hereinafter sometimes simply referred to as "goods") using the CPM code payment method.

[0016] The store terminal 30 is installed with a settlement application on the store side that supports the CPM method. By starting the settlement application on the store terminal 30, the store side can execute code settlement using the CPM method using the store terminal 30.

[0017] Hereinafter, with reference to FIG. 2, the flow until the settlement is completed for the CPM method code settlement using the user terminal 10 according to the present embodiment will be described. The CPM method is a method in which a settlement code such as a two-dimensional barcode is displayed on the user terminal 10, and settlement is performed according to the reading of the settlement code on the store side.

[0018] FIG. 2 is an operation sequence diagram until the settlement of the settlement processing system S according to the present embodiment is completed. In the settlement processing system S according to the present embodiment, a code image for code settlement is displayed on a widget displayed on the display unit of the user terminal 10. Since the code image is generated based on token information, which is non-volatile information stored in advance in the storage unit of the user terminal 10, it can be used regardless of the network state. Further, since the code image is displayed on the widget, the user does not need to start a settlement application when performing code settlement and can perform settlement immediately.

[0019] First, in step S1, the user starts a settlement application (hereinafter, may be simply referred to as a "code settlement application") that provides a code settlement service installed on his / her user terminal 10.

[0020] In step S2, when the code payment app is launched, the user terminal 10 sends a request to the payment server 20 for the issuance of offline token information to generate an offline code image, along with the user's user ID. The offline state is a communication state in which the user terminal 10's communication volume is less than the set communication volume. Therefore, the offline state also includes the state in which the user terminal 10 is not connected to the network. The user ID is identification information used to identify the user.

[0021] In step S3, when the payment server 20 receives a request from the user terminal 10 for the issuance of token information for offline status and a user ID, it generates the token information and a private key corresponding to the token information.

[0022] In step S4, the payment server 20 stores the offline token information generated in step S3 and the secret key corresponding to the token information in the token information database DBt (see Figure 9), associating them with the user ID received from the user terminal 10.

[0023] In step S5, the payment server 20 sends the token information and private key generated in step S3 to the user terminal 10.

[0024] In step S6, the user terminal 10 stores the received token information and secret key in its storage unit as non-volatile information.

[0025] In step S7, the user terminal 10 generates an offline code image (hereinafter sometimes simply referred to as "code image for widget") for display on the widget shown on the display unit, based on the stored token information.

[0026] As will be explained in more detail later, the code image for the widget may be generated based on token information and a time-synchronous one-time token that is generated (updated) at predetermined time intervals (for example, at regular intervals such as every minute). The time-synchronous one-time token is a TOTP (Time-based One-Time Password) and is generated using a private key. As a result, the code image for the widget is generated each time the one-time token is generated (updated) at predetermined time intervals, and therefore the code image for the widget is also updated at predetermined time intervals.

[0027] In step S8, the user terminal 10 displays the widget code image generated in step S7 on the widget displayed on the user terminal 10's display. The user then presents the widget code image to the store clerk. If the widget code image is updated at predetermined time intervals due to the one-time talk being updated at predetermined time intervals, the widget code image displayed on the widget will also be updated and displayed at predetermined time intervals. The processes in steps S7 and S8 are executed regardless of the running status of the code payment app. That is, the user terminal 10 generates the widget code image and displays it on the user terminal 10's display even when the code payment app is not running.

[0028] In step S9, the store employee operates the reader on the store terminal 30, which reads the widget code image displayed on the widget on the display unit of the user terminal 10.

[0029] In step S10, the store terminal 30 identifies the price of the product based on the product ID entered by the store clerk via the operation unit or the product ID read from the barcode attached to the product by the reader, and calculates the payment amount.

[0030] In step S11, the store terminal 30 sends a payment request to the payment server 20, which includes payment information including the payment amount calculated in step S10, the store ID, and the token information and one-time token contained in the code image read in step S9. The store ID is identification information used to identify the store.

[0031] In step S12, the settlement server 20 retrieves the private key corresponding to the received token information from the token information database DBt using the received token information as the key.

[0032] In step S13, the settlement server 20 generates a one-time token using the secret key retrieved in step S12, and uses the generated one-time token and the one-time token included in the settlement request to verify the validity of the code image read in step S9. Details of the process for verifying the validity of the code image will be described later.

[0033] In step S14, the payment server 20 executes the payment process if it confirms that the code image is valid. Specifically, if the payment server 20 confirms that the code image is valid by matching the one-time token generated in step S13 with the one-time token included in the payment request, it executes a payment process to deduct the payment amount from the account of the user corresponding to the user ID associated with the token information, and also executes a process to deposit the store's account, which is identified by the store ID included in the payment request, into the store's account.

[0034] In step S15, the payment server 20 sends payment completion information to the store terminal 30, indicating that the payment has been completed.

[0035] In step S16, when the store terminal 30 receives payment completion information from the payment server 20, it displays the payment completion information on its display unit and notifies the store clerk that the payment has been completed.

[0036] In step S17, the payment server 20 sends payment completion information to the user terminal 10 indicating that the payment has been completed.

[0037] In step S18, if the user terminal 10 is online, the user terminal 10 receives payment completion information from the payment server 20, displays the payment completion information on the widget of the display unit, and notifies the user that the payment has been completed. An online state is a state in which the communication volume of the user terminal 10 is greater than the set communication volume.

[0038] In Figure 1, the processes from step S1 to step S6 are performed when the user terminal 10 is online. Since the user terminal 10 stores token information for the offline state in step S6, the processes from step S7 to step S17 can be executed regardless of whether the user terminal 10 is online or offline, and regardless of the network state. The process in step S18 is a process that can be executed when the user terminal 10 is online. When the payment completion information is sent from the payment server 20 to the user terminal 10 in step S17, if the user terminal 10 is offline, the payment completion information cannot be received, and therefore the payment completion information is not displayed in the widget on the display unit of the user terminal 10. When the user terminal 10 returns from the offline state to the online state, the payment completion information may be obtained and displayed in the widget on the display unit.

[0039] As described above, the payment processing system S operates so that a code image generated based on the offline token information stored as non-volatile information in the user terminal 10 is displayed in the widget on the display unit. Therefore, in CPM-based code payments, the user only needs to show the code image displayed in the widget to the store clerk, and can make a payment immediately regardless of the network status, without having to launch a code payment app.

[0040] Furthermore, the code image displayed in the widget is generated (updated) at predetermined time intervals using a time-synchronized one-time token. Therefore, each time a one-time token is generated, a new code image is displayed on the user terminal 10's display. This prevents unauthorized use through duplication or theft of the code image, thereby enhancing security.

[0041] In this embodiment, the transmission of the request to issue token information for offline status in step S2 is triggered by the launch of the code payment application (step S1), but the trigger is not limited to this. The request to issue token information for offline status may be sent automatically at a predetermined timing. For example, the request to issue token information may be sent automatically at a predetermined time once a day or once every few days. Alternatively, a button (icon) for sending a request to issue token information for offline status may be placed on the home screen of the code payment application, and the user may obtain the token information by tapping the button. Furthermore, multiple token information entries may be obtained and stored in the user terminal 10. When the number of stored token information entries falls below a predetermined number, new token information may be obtained.

[0042] The following describes the detailed configuration of the user terminal 10 and the payment server 20.

[0043] Figure 3 shows an example of the hardware configuration of the user terminal 10 according to this embodiment. The user terminal 10 is connected to the payment server 20 in a communicative manner. The user terminal 10 is a computer such as a smartphone, mobile phone, tablet, or wearable device.

[0044] The user terminal 10 is physically configured as a computer including a processor 101, memory 102, storage 103, communication device 104, input device 105, output device 106, timing device 107, and a bus connecting them. Each of these devices operates on power supplied from a battery (not shown). In the following description, the term "device" can be read as a circuit, device, unit, etc. The hardware configuration of the user terminal 10 may include one or more of the devices shown in Figure 3, or it may be configured with some devices omitted. Alternatively, multiple devices with different enclosures may be connected via communication to constitute the user terminal 10.

[0045] Each function in the user terminal 10 is realized by loading predetermined software (programs) onto hardware such as the processor 101 and memory 102, which allows the processor 101 to perform calculations, control communication by the communication device 104, and control at least one of the reading and writing of data in the memory 102 and storage 103.

[0046] The processor 101 controls the entire computer, for example, by running the operating system. The processor 101 may consist of a central processing unit (CPU) that includes interfaces with peripheral devices, control units, arithmetic units, registers, etc. Alternatively, a baseband signal processing unit or a call processing unit may be implemented by the processor 101.

[0047] The processor 101 reads programs (program code), software modules, data, etc., from at least one of the storage 103 and the communication device 104 into the memory 102 and executes various processes accordingly. The program used is one that causes the computer to execute at least a part of the operations described later. Functional blocks of the user terminal 10 are stored in the memory 102 and may be implemented by control programs that run on the processor 101. Various processes may be executed by one processor 101, or they may be executed simultaneously or sequentially by two or more processors 101. The processor 101 may be implemented by one or more chips. The program may also be transmitted to the user terminal 10 via a telecommunications line.

[0048] Memory 102 is a computer-readable recording medium and may consist of at least one of the following: ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), RAM (Random Access Memory), etc. Memory 102 may also be called a register, cache, main memory, etc. Memory 102 can store executable programs (program code), software modules, etc., for carrying out the method according to this embodiment.

[0049] The storage 103 is a computer-readable recording medium and may consist of at least one of the following: an optical disc such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disc, a digital multipurpose disc, a Blu-ray® disc), a smart card, flash memory (e.g., a card, a stick, a key drive), a floppy® disk, a magnetic strip, etc. The storage 103 may also be called an auxiliary storage device.

[0050] The communication device 104 is hardware (transceiver / receiver device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as a network device, network controller, network card, communication module, etc. The communication device 104 enables communication with the payment server 20. The communication device 104 may be configured to include, for example, a high-frequency switch, duplexer, filter, frequency synthesizer, etc., in order to implement at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, the transmit / receive antenna, amplifier section, transmit / receive section, transmission path interface, etc., may be implemented by the communication device 104. The transmit / receive section may be implemented with physically or logically separated transmitting and receiving sections.

[0051] The input device 105 is an input device that accepts input from an external source (e.g., a key, microphone, camera, switch, button, sensor, etc.). The output device 106 is an output device that outputs to an external source (e.g., a display, speaker, LED lamp, etc.). The input device 105 and the output device 106 may be configured as an integrated unit (e.g., a touch panel).

[0052] The timing device 107 is a device that acquires the current time. The time to be acquired may be the system time of the user terminal 10, or it may be the absolute time provided by a time server or the like. In this embodiment, the timing device 107 acquires UNIX® time expressed as the number of seconds elapsed since January 1, 1970, 00:00:00.

[0053] Each device, such as the processor 101 and memory 102, is connected by a bus for communicating information. The bus may be configured using a single bus, or different buses may be used for each device.

[0054] The user terminal 10 may be configured with hardware such as a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), or an FPGA (Field Programmable Gate Array), and some or all of the functional blocks may be implemented by such hardware. For example, the processor 101 may be implemented using at least one of these hardware components.

[0055] Figure 4 shows an example of the hardware configuration of the payment server 20 according to this embodiment. The payment server 20 is an information processing device implemented by, for example, a server device or a cloud system. Physically, the payment server 20 is configured as a computer device including a processor 201, memory 202, storage 203, communication device 204, input device 205, output device 206, timing device 207, and a bus connecting these. The processor 201, memory 202, storage 203, communication device 204, input device 205, output device 206, and timing device 207 are the same hardware as the processor 101, memory 102, storage 103, communication device 104, input device 105, output device 106, and timing device 107 of the user terminal 10, so their description is omitted.

[0056] [Functional configuration of user terminal 10] Next, the functional configuration of the user terminal 10 according to this embodiment will be described. Figure 5 is a diagram showing the functional configuration of the user terminal 10. The user terminal 10 has a display unit 11, a storage unit 12, and a control unit 13.

[0057] The display unit 11 is, for example, a display that shows various kinds of information, and is an example of the output device 106 shown in Figure 3. The display unit 11 displays various images based on the control of the display control unit 136. For example, the display unit 11 displays a code image generated by the code image generation unit 135 based on the control of the display control unit 136. The display unit 11 also displays a code display image on which the code image is displayed based on the control of the display control unit 136.

[0058] The storage unit 12 stores various types of data. For example, the storage unit 12 stores the program executed by the control unit 13. The storage unit 12 stores a program (a code payment application according to this embodiment) that causes the control unit 13 to function as an operation reception unit 131, an issuance request transmission unit 132, an acquisition unit 133, a one-time token generation unit 134, a code image generation unit 135, a display control unit 136, and a biometric authentication execution unit 137. The storage unit 12 also stores token information, a private key, and a code image for payment generated based on the token information received from the payment server 20. The storage unit 12 may also store a code display image on which the code image is displayed.

[0059] In this embodiment, the user uses the widget function of the application that serves as the OS (Operating System) of the user terminal 10, which is stored in the memory unit 12, to place the widget of the code payment application according to this embodiment on at least one of the home screen or lock screen.

[0060] The control unit 13 functions as an operation reception unit 131, an issuance request transmission unit 132, an acquisition unit 133, a one-time token generation unit 134, a code image generation unit 135, a display control unit 136, and a biometric authentication execution unit 137 by executing (or launching) the code payment application stored in the storage unit 12.

[0061] The operation reception unit 131 identifies the user's operation based on signals input from an operation unit, such as a touch panel provided on the surface of the display unit 11. If the identified operation is an operation for requesting the issuance of offline token information to generate an offline code image, the operation reception unit 131 notifies the issuance request transmission unit 132 of the operation. For example, if the identified operation is a startup operation to launch a code payment application (an example of an operation for requesting the issuance of offline token information), the operation reception unit 131 notifies the issuance request transmission unit 142 of the operation.

[0062] The issuance request transmission unit 132 sends to the payment server 20, via the communication device 104, a request to issue offline token information for generating an offline code image, along with the user's user ID. The issuance request transmission unit 132 also sends to the payment server 20, via the communication device 104, a request to issue online token information for generating an online code image, along with the user's user ID.

[0063] The acquisition unit 133 acquires offline token information and a private key corresponding to the token information, which are transmitted from the payment server 20. The acquisition unit 133 stores the acquired token information and private key as non-volatile information in the storage unit 12. The acquisition unit 133 may also acquire online token information transmitted from the payment server 20.

[0064] The one-time token generation unit 134 generates a time-synchronous one-time token at predetermined time intervals (for example, every minute) using the secret key acquired by the acquisition unit 133. A time-synchronous one-time token is, for example, TOTP (Time-based One-Time Password). Specifically, the one-time token generation unit 134 generates a one-time token using the secret key and the UNIX time acquired by the timing device 107. The one-time token generation unit 134 can generate (update) the one-time token at predetermined time intervals (for example, every minute) by converting the UNIX time into blocks of predetermined time units (for example, every minute).

[0065] The code image generation unit 135 generates a code image for display on the display unit 11 based on token information transmitted from the payment server 20. The code image generation unit 135 generates an offline code image for display on the display unit 11 based on offline token information stored as non-volatile information in the storage unit 12. The code image generation unit 135 generates an online code image for display on the display unit 11 based on online token information transmitted from the payment server 20. The code image generation unit 135 may also generate a code display image on which the code image is displayed.

[0066] Here, we will explain the data structure of token information used when generating code images.

[0067] First, we will explain the data structure of the online token information used when generating the code image. This token information includes information indicating the business code, which is a prefix value. This information indicating the business code can be obtained, for example, from the payment server 20 when acquiring the online token information.

[0068] Furthermore, the online token information used when generating the code image includes information indicating whether or not points will be used for payment via code payment.

[0069] It also includes online token information for generating the code image, and information indicating whether the payment is made online or offline.

[0070] Furthermore, the online token information used when generating the code image includes online status token information transmitted from the payment server 20 in response to an issuance request from the user.

[0071] Next, we will describe the data structure of the offline token information used when generating the code image. This token information includes information indicating the business code, which is a prefix value. This information indicating the business code can be obtained from the payment server 20, for example, when launching the code payment application to obtain the offline token information.

[0072] Furthermore, the offline token information used when generating the code image includes information indicating whether or not points will be used for payment via code payment, and information indicating whether the payment is made online or offline.

[0073] Furthermore, the offline token information used when generating the code image includes offline token information transmitted from the payment server 20 in response to an issuance request when the code payment application is launched, and a one-time token (TOTP) generated using the private key corresponding to the token information.

[0074] The offline token information sent from the payment server 20 in response to an issuance request when the code payment app is launched is a random number and is fixed information for a predetermined period (for example, a fixed period such as one week). In other words, the offline token information is valid only for a predetermined period from the date of issuance. After the predetermined period has elapsed from the date of issuance, the offline token information, along with the corresponding private key, is deleted by the payment server 20. By making the offline token information valid only for a predetermined period (for example, one week from the date of issuance), after the predetermined period has elapsed, it becomes impossible to make payments using code images generated based on that token information. This prevents unauthorized use through duplication or theft of the token information itself, thereby enhancing security. As described above, a one-time token is information that is updated and its value is changed at predetermined time intervals (for example, every minute).

[0075] The display control unit 136 causes the image generated by the code image generation unit 135 to be displayed on the display unit 11. The display control unit 136 causes the image generated by the code image generation unit 135 to be displayed on a widget displayed on the display unit 11. The display control unit 136 causes the code image or code display image generated by the code image generation unit 125 to be displayed on the display unit 11. The display control unit 136 causes the code image or code display image generated by the code image generation unit 125 to be displayed on a widget displayed on the display unit 11.

[0076] The one-time token is updated at predetermined time intervals by the one-time token generation unit 134. Therefore, each time a one-time token is generated, the code image generation unit 135 generates a code image based on the offline token information stored in the storage unit 12 and the generated one-time token. The display control unit 136 then displays the generated code image on the widget displayed on the display unit 11. In other words, each time a new one-time token is generated, a code image is generated using the newly generated one-time token, and the newly generated code image is displayed on the widget.

[0077] Figure 6(a) shows an example of a code image CI displayed in a widget WG on the display unit 11. In Figure 6(a), two code image CIs, including a one-dimensional barcode and a two-dimensional barcode, are displayed in the widget WG of the home screen shown on the display unit 11.

[0078] In this way, the offline code image CI generated based on the offline token information, which is non-volatile information stored in the memory unit 12, is displayed in the widget WG. As a result, in CPM payments, users can make payments immediately without launching a code payment app, regardless of the network status.

[0079] Furthermore, since the time-synchronized one-time token is updated at predetermined time intervals, the code image CI changes and is displayed in the widget WG each time the one-time token is updated. This prevents unauthorized use through duplication or theft of the code image CI, thereby enhancing security.

[0080] Furthermore, as shown in Figure 6(a), it is preferable to display the code image CI in the home screen widget WG. By displaying the code image CI in the home screen widget WG, compared to displaying the code image CI in the lock screen widget WG, the user must bypass the screen lock security (e.g., PIN number, password, fingerprint authentication, facial recognition, etc.) that is normally set on the lock screen. Therefore, displaying the code image CI in the home screen widget WG can further enhance security.

[0081] Furthermore, as shown in Figure 6(a), the code image CI may always be displayed in the widget WG. When the code image CI is always displayed in the widget WG, users can make payments immediately in CPM payments without having to launch the code payment app.

[0082] The display control unit 136 may display at least one of the following on the widget WG: a payment method change button B1 for changing the payment method, or a point redemption switch button B2 for switching whether or not to use points for payment. The display control unit 136 may also display an app launch button B3 on the widget WG for launching a code payment app. Figure 6(b) shows an example in which the payment method change button B1, the point redemption switch button B2, and the app launch button B3 are displayed on the widget WG.

[0083] By displaying a payment method change button B1 and a point redemption toggle button B2 on the widget WG, users can change their payment method or switch whether or not to use points for payment in CPM payments, regardless of network conditions, without having to launch the code payment app. This improves user convenience in CPM payments where a code image CI is displayed on the widget WG for payment processing.

[0084] Furthermore, when the communication status of the user terminal 10 is online, and the code payment application is launched via the application launch button B3, the acquisition unit 133 may acquire online token information, and the code image generation unit 135 may generate an online code image based on the online token information.

[0085] This allows users to launch the code payment app via the app launch button B3, and also allows them to select so-called regular code payment from the widget WG where the code image CI is displayed, thereby improving user convenience.

[0086] Furthermore, if the communication status of the user terminal 10 is online and payment is made using the offline code image CI displayed on the widget WG, the acquisition unit 133 may acquire payment information related to the payment from the payment server 20, and the display control unit 136 may display payment completion information F1 based on the payment information on the widget WG.

[0087] Figure 6(c) shows an example where payment completion information F1 is displayed on the widget WG when payment is made using the offline code image CI displayed on the widget WG, while the communication status of the user terminal 10 is online.

[0088] Thus, when a payment is made using the code image CI displayed on the widget WG, if the communication status of the user terminal 10 is online, payment completion information F1 related to that payment is displayed on the widget WG. This allows the user to confirm that the payment has been made properly via the widget WG, thereby improving user convenience in CPM payments where payment is made by displaying the code image CI on the widget WG.

[0089] Returning to Figure 5, the biometric authentication execution unit 137 performs biometric authentication of the user. Biometric authentication is a method of authentication that uses biometric information such as fingerprints or iris scans. The storage unit 12 stores pre-registered biometric information such as the user's fingerprint pattern or iris pattern. The biometric authentication execution unit 137 compares the stored biometric information with the biometric information acquired by a biosensor, which is an example of an input device. If the two match, the biometric authentication is successful (authentication OK). The display control unit 136 displays a code image on the widget displayed on the display unit 11 when the biometric authentication by the biometric authentication execution unit 137 is successful. The display control unit 136 does not display a code image on the widget displayed on the display unit 11 when the biometric authentication by the biometric authentication execution unit 137 fails (authentication NG).

[0090] Figure 7 shows an example of displaying a code image CI on the widget WG shown on the display unit 11 when biometric authentication by the biometric authentication execution unit 137 is successful. When displaying the code image CI on the widget WG when biometric authentication is successful, the code image CI is not displayed on the widget WG until biometric authentication is successful, as shown in the left diagram of Figure 7. Instead, information F2 is displayed on the widget WG indicating that the code image CI will be displayed when tapped. The user performs biometric authentication by the biometric authentication execution unit 137 by tapping the widget WG. The middle diagram of Figure 7 is an example of screen F3 displayed on the display unit 11 during biometric authentication. When biometric authentication is successful, the screen transitions to the screen shown on the right side of Figure 7, where the code image CI is displayed on the widget WG.

[0091] In this way, by preventing the code image CI from being displayed in the widget WG unless the user successfully performs biometric authentication, security can be further enhanced because only the user themselves can display the code image CI in the widget WG.

[0092] If the token information has expired, a message indicating that the code image CI cannot be displayed may be shown, along with a button to retrieve the token information. When the user taps this button, if the user terminal 10 is online, the token information is retrieved, a code image CI is generated based on the token information, and displayed on the widget WG.

[0093] [Functional Configuration of Payment Server 20] Figure 8 shows the functional configuration of the payment server 20 according to this embodiment. The payment server 20 includes a storage unit 21 and a control unit 22.

[0094] The storage unit 21 stores various types of data. For example, the storage unit 21 stores programs that the control unit 22 executes. The storage unit 21 stores programs that cause the control unit 22 to function as the issuance request acquisition unit 221, the token information generation unit 222, the token information transmission unit 223, the settlement request acquisition unit 224, the validity verification unit 225, and the settlement processing unit 226.

[0095] Furthermore, the storage unit 21 includes a token information database DBt. The settlement server 20 stores token information for the offline state and the secret key corresponding to said token information in the token information database DBt, associated with the user ID. The settlement server 20 may also store token information for the online state in the token information database DBt, associated with the user ID.

[0096] Figure 9 shows an example of a token information database DBt. As shown in Figure 9, the token information database DBt stores issued offline token information and the corresponding private key, associated with the user ID of the user who requested the issuance of the token information. The token information database DBt may also store issued online token information, associated with the user ID of the user who requested the issuance of the token information.

[0097] The control unit 22 functions as an issuance request acquisition unit 221, a token information generation unit 222, a token information transmission unit 223, a settlement request acquisition unit 224, a validity verification unit 225, and a settlement processing unit 226 by executing a program stored in the storage unit 21.

[0098] The token issuance request acquisition unit 221 acquires (receives) the user ID of the user who owns the user terminal 10 and the token information issuance request from the user terminal 10.

[0099] When the token information generation unit 222 receives a request to issue token information, it generates token information and stores it in the token information database DBt in association with the user ID. If the received token information is for an offline state, the token information generation unit 222 generates offline token information and a corresponding secret key, and stores the token information and the corresponding secret key in the token information database DBt in association with the user ID. If the received token information is for an online state, the token information generation unit 222 generates online token information and stores it in the token information database DBt in association with the user ID.

[0100] The token information transmission unit 223 transmits the generated offline token information and the corresponding private key to the user terminal 10 that made the issuance request. The token information transmission unit 223 also transmits the generated online token information to the user terminal 10 that made the issuance request.

[0101] The payment request acquisition unit 224 acquires (receives) a payment request from the store terminal 30 that has read the code image displayed by the user terminal 10. This request includes a store ID that identifies the store, payment information such as the payment amount at the user's store, and token information and a one-time token contained in the read code image.

[0102] The validity verification unit 225 retrieves a secret key corresponding to the token information from the token information database DBt using the offline token information included in the received payment request as the key. The validity verification unit 225 generates a one-time token using the retrieved secret key and verifies the validity of the code image using the generated one-time token and the one-time token included in the payment request. Specifically, the validity verification unit 225 generates three one-time tokens for the current time t minutes, (t+1) minutes, and (t-1) minutes, respectively, using the retrieved secret key. The validity verification unit 225 then checks whether any of the three one-time tokens corresponding to the time t minutes, (t+1) minutes, and (t-1) minutes matches the one-time token included in the payment request. If there is a one-time token among the three one-time tokens corresponding to the time t minutes, (t+1) minutes, and (t-1) minutes that matches the one-time token included in the payment request, the validity verification unit 225 determines that the code image is valid and proceeds to the payment process.

[0103] The payment processing unit 226 executes the payment process if it confirms that the code image is valid. Specifically, the payment processing unit 226 executes a payment process to deduct the payment amount from the user's account corresponding to the user ID associated with the token information, and also executes a process to deposit the store's payment amount into the store's account identified by the store ID included in the payment request. Then, when the payment is made, the payment processing unit 226 sends payment completion information regarding the payment to the user terminal 10.

[0104] [Operation Flow] Figure 10 is a flowchart showing an example of the operations performed by the user terminal 10 of the payment processing system S according to this embodiment.

[0105] First, in step S111, the issuance request transmission unit 132 of the user terminal 10 sends a request to issue token information for offline status and the user's user ID to the payment server 20. For example, by launching the code payment application installed on the user terminal 10, the issuance request transmission unit 132 sends the issuance request to the payment server 20.

[0106] In step S112, the acquisition unit 133 of the user terminal 10 acquires the token information generated by the payment server 20 and the secret key corresponding to the token information, and stores them as non-volatile information in the storage unit 12. The processes from steps S111 to S112 are executed when the communication status of the user terminal 10 is online.

[0107] In step S113, the one-time token generation unit 134 of the user terminal 10 generates a time-synchronized one-time token at predetermined time intervals (for example, every minute) using the secret key acquired by the acquisition unit 133, and the code image generation unit 135 generates an offline code image (code image for the widget) to be displayed on the widget shown on the display unit 11, based on the stored token information and the generated one-time token.

[0108] In step S114, the biometric authentication execution unit 137 of the user terminal 10 performs biometric authentication. If biometric authentication is successful (authentication OK), the flow proceeds to step S115. If biometric authentication fails (authentication NG), the flow returns to step S114.

[0109] In step S115, the display control unit 136 of the user terminal 10 displays the generated widget code image on the widget displayed on the display unit 11. When the user presents the widget code image to a store employee, the reader of the store terminal 30 reads the widget code image. The store terminal 30 then sends a payment request to the payment server 20.

[0110] Note that the processes from step S113 to step S115 can be executed whether the user terminal 10 is online or offline.

[0111] If the communication status of the user terminal 10 is online, the flow proceeds to step S116. In step S116, the acquisition unit 133 acquires payment completion information from the payment server 20.

[0112] If the communication status of the user terminal 10 is online, the flow proceeds to step S117. In step S117, the display control unit 136 displays the acquired payment completion information on the widget of the display unit 11.

[0113] Figure 11 is a flowchart showing an example of the operations performed by the payment server 20 of the payment processing system S according to this embodiment.

[0114] First, in step S121, the payment server 20's issuance request acquisition unit 221 acquires (receives) a request from the user terminal 10 for the issuance of token information for offline status and the user ID.

[0115] In step S122, the token information generation unit 222 of the payment server 20 generates the acquired token information and a secret key corresponding to the token information.

[0116] In step S123, the token information generation unit 222 of the payment server 20 stores the acquired token information and the corresponding secret key in the token information database DBt, associating them with the acquired user ID.

[0117] In step S124, the token information transmission unit 223 of the payment server 20 transmits the generated token information and private key to the user terminal 10.

[0118] In step S125, the payment request acquisition unit 224 of the payment server 20 acquires (receives) a payment request from the store terminal 30, which includes payment information including the payment amount, the store ID, and token information and a one-time token contained in the code image read by the reader of the store terminal 30.

[0119] In step S126, the validity verification unit 225 of the settlement server 20 retrieves the secret key corresponding to the acquired token information from the token information database DBt using the acquired token information as a key.

[0120] In step S127, the validity verification unit 225 of the payment server 20 generates a one-time token using the retrieved private key, and uses the generated one-time token and the one-time token included in the payment request to verify the validity of the code image read at the store. If the code image is valid (OK), the flow proceeds to step S128. If the code image is not valid (NG), the flow returns to step S127.

[0121] In step S128, the payment processing unit 226 of the payment server 20 executes the payment process if it confirms that the code image is valid.

[0122] In step S129, the payment processing unit 226 of the payment server 20 sends payment completion information to the store terminal 30 indicating that the payment has been completed.

[0123] In step S130, the payment processing unit 226 of the payment server 20 sends payment completion information to the user terminal 10 indicating that the payment has been completed.

[0124] As described above, in the user terminal 10 according to this embodiment, a code image generated based on token information, which is non-volatile information stored in the storage unit 12, is displayed in the widget. Therefore, in CPM payments, users can make payments immediately without launching a code payment application, regardless of the network status. Furthermore, since the code image displayed in the widget is generated at predetermined time intervals using a time-synchronized one-time token, a new code image is displayed in the widget of the display unit each time a one-time token is generated. This prevents unauthorized use through duplication or theft of code images, thereby enhancing security.

[0125] [Other embodiments] Although the payment processing system S of the present invention has been described above with reference to this embodiment, the payment processing system S of the present invention is not limited to the above embodiment. Various modifications to the configuration and details of the present invention can be made, as can be understood by those skilled in the art within the technical scope of the present invention. Furthermore, any system or device that combines the different features included in each embodiment is also within the technical scope of the present invention.

[0126] Furthermore, the present invention may be applied to a system composed of multiple devices or to a single device. Moreover, the present invention is also applicable when an information processing program that realizes the functions of each embodiment is supplied to a system or device and executed by a built-in processor. To realize the functions of the present invention on a computer, a program installed on a computer, a medium storing the program, a server that downloads the program, and a processor that executes the program are all included in the technical scope of the present invention. In particular, at least a non-transitory computer-readable medium storing a program that causes a computer to execute the processing steps included in each of the embodiments described above is included in the technical scope of the present invention.

[0127] The following additional notes are provided regarding the embodiments described above.

[0128] [Note 1] Information processing equipment, Display unit and A unit for obtaining token information, A storage unit that stores the acquired token information, A code image generation unit generates a code image based on the token information stored in the storage unit, The widget displayed on the display unit includes a display control unit that displays the code image, It is equipped with.

[0129] With the above configuration, a code image generated based on the token information stored in the token storage unit is displayed in the widget, allowing users to make payments immediately in CPM payments, regardless of network conditions, without having to launch a code payment app.

[0130] [Note 2] The information processing device described in Appendix 1 further comprises a one-time token generation unit that generates time-synchronized one-time tokens at regular time intervals. Each time the aforementioned one-time token is generated, The code image generation unit generates the code image based on the token information stored in the storage unit and the generated one-time token. The display control unit displays the generated code image on the widget.

[0131] With the above configuration, the code image displayed in the widget is generated at regular time intervals using a time-synchronized one-time token. Therefore, each time a one-time token is generated, a new code image is displayed in the display area. This prevents unauthorized use through duplication or theft of code images, thereby enhancing security.

[0132] [Note 3] In the information processing device described in Appendix 1 or 2, the token information is valid only for a certain period of time.

[0133] With the above configuration, the token information is valid only for a certain period (for example, one week from issuance). After this period, it becomes impossible to make payments using code images generated based on that token information. Therefore, it is possible to prevent fraudulent use through duplication or theft of the token information itself, thereby enhancing security.

[0134] [Note 4] In any of the information processing devices described in Appendix 1 to 3, the widget is a widget on the home screen.

[0135] With the above configuration, the code image can be displayed as a widget on the home screen. Compared to displaying the code image as a widget on the lock screen, displaying the code image as a widget on the home screen provides a higher level of security because the user must bypass the screen lock security set on the lock screen (e.g., PIN number, password, fingerprint authentication, facial recognition, etc.).

[0136] [Note 5] Any of the information processing devices described in Appendix 1 to 4, It further includes a biometric authentication execution unit that performs biometric authentication of the user, The display control unit displays the code image on the widget when the biometric authentication is successful.

[0137] With the above configuration, users must successfully complete biometric authentication in order to display the code image in the widget. This ensures that only the user themselves can display the code image in the widget, thus enhancing security.

[0138] [Note 6] In any of the information processing devices described in Appendix 1 to 5, The display control unit displays at least one of the following on the widget: a payment method change button for changing the payment method, and a point redemption switch button for switching whether or not to use points for payment.

[0139] With the above configuration, users can change their payment method or switch whether or not to use points for payment in CPM payments, regardless of network conditions, without having to launch a code payment app. This improves user convenience in CPM payments, where a code image is displayed on a widget for payment processing.

[0140] [Note 7] In any of the information processing devices described in Appendix 1 to 6, The display control unit displays an app launch button on the widget for launching a code payment app that provides a code payment service. In a first communication state where the communication volume of the information processing device is greater than the set communication volume, if the code payment application is launched via the application launch button, The acquisition unit acquires the token information for the first communication state, The code image generation unit generates a code image based on the token information for the first communication state.

[0141] With the above configuration, an app launch button is displayed on the widget, allowing users to launch the code payment app that provides the code payment service via this button. This also allows users to select so-called regular code payment from the widget displaying the code image, thereby improving user convenience.

[0142] [Note 8] In any of the information processing devices described in Appendix 1 to 7, In a first communication state where the communication volume of the information processing device is greater than the set communication volume, if a payment is made using the code image displayed on the widget, The acquisition unit acquires settlement information relating to the settlement, The display control unit displays payment completion information based on the payment information on the widget.

[0143] With the above configuration, when a payment is made using the code image displayed on the widget, if the communication status of the information processing device (user terminal) is the first communication status (e.g., online), payment completion information for that payment will be displayed on the widget. This allows the user to confirm that the payment has been made properly via the widget, improving user convenience in CPMM payments where payment is made by displaying a code image on the widget.

[0144] [Note 9] Information processing methods are An information processing method performed by a computer of an information processing device used by a user, Steps to obtain token information, The steps include storing the acquired token information, The steps include generating a code image based on the stored token information, The steps include: displaying the code image on a widget displayed on the display unit of the information processing device; It is equipped with.

[0145] This configuration produces the same effects as the information processing device described in Appendix 1.

[0146] [Note 10] Information processing programs are An information processing program that is pre-installed on an information processing device used by a user, wherein the information processing device is A unit for obtaining token information, A storage unit that stores the acquired token information, A code image generation unit generates a code image based on the token information stored in the storage unit, The display control unit that displays the code image on a widget on the display unit of the information processing device, To make it function as such.

[0147] This configuration produces the same effects as the information processing device described in Appendix 1. [Explanation of Symbols]

[0148] 10. User terminal (information processing device) 13 Control Unit 131 Operation Reception Section 132 Issuance Request Transmission Unit 133 Acquisition Department 134 One-Time Token Generation Unit 135 Code Image Generation Unit 136 Display Control Unit 137 Biometric Authentication Execution Unit 11 Display section 12 Storage section 20 Payment Server 22 Control Unit 221 Issuance Request Acquisition Department 222 Token Information Generation Unit 223 Token Information Transmission Unit 224 Payment Request Acquisition Unit 225 Effectiveness Verification Section 226 Payment Processing Unit 21 Memory section DBt Token Information Database 30 store terminals

Claims

1. Display unit and An acquisition unit that acquires token information and a secret key associated with said token information, A storage unit that stores the acquired token information and the private key, A one-time token generation unit that generates time-synchronized one-time tokens at regular time intervals using the aforementioned secret key, Each time the one-time token is generated, a code image generation unit generates a code image based on the token information stored in the storage unit and the generated one-time token. Each time the one-time token is generated, the display control unit displays the generated code image on a widget displayed on the display unit, An information processing device equipped with the following features.

2. The information processing apparatus according to claim 1, wherein the token information is information that is valid only for a certain period of time.

3. The information processing apparatus according to claim 1, wherein the widget is a widget on the home screen.

4. It further includes a biometric authentication execution unit that performs biometric authentication of the user, The information processing apparatus according to claim 1, wherein the display control unit displays the code image on the widget when the biometric authentication is successful.

5. The information processing apparatus according to claim 1, wherein the display control unit displays at least one of the following on the widget: a payment method change button for changing the payment method, and a point redemption switch button for switching whether or not to use points for payment.

6. The display control unit displays an app launch button on the widget for launching a code payment app that provides a code payment service. In a first communication state where the amount of communication of the information processing device is greater than the set amount of communication, if the code payment application is launched via the application launch button, The acquisition unit acquires the token information for the first communication state, The information processing apparatus according to claim 1, wherein the code image generation unit generates a code image based on the token information for the first communication state.

7. In a first communication state where the communication volume of the information processing device is greater than the set communication volume, if a payment is made using the code image displayed on the widget, The acquisition unit acquires settlement information relating to the settlement, The information processing apparatus according to claim 1, wherein the display control unit displays payment completion information based on the payment information on the widget.

8. An information processing method performed by a computer of an information processing device used by a user, A step of obtaining token information and a private key associated with said token information, A step of storing the acquired token information and the private key, The steps include generating a time-synchronized one-time token at regular time intervals using the aforementioned private key, Each time the aforementioned one-time token is generated, a code image is generated based on the stored token information and the generated one-time token. Each time the one-time token is generated, the generated code image is displayed on a widget on the display unit of the information processing device. An information processing method comprising:

9. An information processing program that is pre-installed on an information processing device used by a user, wherein the information processing device is An acquisition unit that acquires token information and a secret key associated with said token information, A storage unit that stores the acquired token information and the private key, A one-time token generation unit that generates time-synchronized one-time tokens at regular time intervals using the aforementioned secret key, Each time the one-time token is generated, a code image generation unit generates a code image based on the token information stored in the storage unit and the generated one-time token. Each time the one-time token is generated, the display control unit displays the generated code image on a widget displayed on the display unit of the information processing device, An information processing program that functions as such.

Citation Information

Patent Citations

  • Method and system for authenticating transaction request from device

    JP2019012538A

  • Payment information processing method, apparatus, and user device

    JP2019526088A

  • Two-dimensional code settlement system for laundry store

    JP2021002240A

  • Information processing method, program, and terminal

    JP2021057073A

  • User terminal, store terminal, transaction management system, transaction management method, and transaction management program

    JP2022115651A