Offline authentication type payment terminal

The offline authentication payment terminal verifies one-time passwords using a secret key and timer signals, addressing authentication challenges and replay attacks, ensuring secure and efficient operations with external devices.

JP7851554B1Active Publication Date: 2026-04-27SHIFT CO LTD(JP)
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SHIFT CO LTD(JP)
Filing Date
2025-10-24
Publication Date
2026-04-27

AI Technical Summary

Technical Problem

Existing payment terminals, such as vending machines, face challenges in performing authentication when communication with servers is impossible or fails, and are vulnerable to replay attacks due to the reuse of one-time passwords.

Method used

An offline authentication type payment terminal that verifies one-time passwords without relying on a server or communication lines, using a control unit to decrypt authentication codes with a secret key, generates passwords based on a clock unit, and supports both timer and communication signals for output to external devices.

Benefits of technology

Enables stable authentication independent of communication environments, prevents password reuse, and enhances security and operability by displaying code validity, ensuring connectivity with various devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007851554000001_ABST
    Figure 0007851554000001_ABST
Patent Text Reader

Abstract

The present invention provides an offline authentication type payment terminal that can verify one-time passwords independently of servers and communication lines, and can also prevent the reuse of previously used one-time passwords. [Solution] The offline authentication type payment terminal 1 comprises a control unit 10, a terminal information storage unit 11, a secret key storage unit 12, a storage means 29, a server connection information display unit 13, and an authentication code input unit 14 for inputting an authentication code transmitted from the server 40. The control unit decrypts the authentication code input via the authentication code input unit based on the secret key stored in the secret key storage unit, verifies whether the information obtained by the decryption is identical to the information generated based on the secret key, and outputs a drive signal or the like to an external device if the verification is successful. This enables secure cashless payment without requiring a network connection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a payment terminal that performs authentication using a one-time password (TOTP) in an offline environment, and more particularly to an offline authentication type payment terminal that is connected to and used with an external device such as a vending machine.

Background Art

[0002] Conventionally, in a payment terminal such as a vending machine, a method of performing authentication online via a server has been widely used. In such a method, the one-time password and identification information entered by the user are transmitted to the server, and authentication is performed by comparing them with the one-time password and authentication information generated on the server side.

[0003] However, there is a problem that when there is an environment where communication with the server is impossible or a communication failure occurs, authentication processing cannot be performed and the user cannot use the payment service. There is also a problem that it is difficult to take sufficient countermeasures against a replay attack in which a previously used authentication code is reused.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In view of the above problems, an object of the present invention is to provide a payment terminal that can verify a one-time password with a single terminal without depending on a server or a communication line, and can further prevent the reuse of a one-time password used in the past. Another object is to make it possible to flexibly connect to various devices by supporting both a timer control signal and a communication signal as an output method to an external device, thereby enhancing user convenience and operation efficiency. [Means for solving the problem]

[0006] In view of the above problems, the present invention has the following configuration. That is, An offline authentication type payment terminal, It comprises a control unit, a terminal information storage unit, a secret key storage unit, a storage means, a display unit for displaying server connection information, and an input unit for inputting an authentication code sent from the server. The control unit decrypts the authentication code input via the input unit based on the secret key stored in the secret key storage unit, and verifies whether the information obtained by the decryption is identical to the information generated based on the secret key stored in the secret key storage unit. An offline authentication type payment terminal characterized by being configured to output a drive signal or a sales authorization signal to an external device when the aforementioned verification is successful.

[0007] Furthermore, the present invention has the following configuration: The above-described offline authentication type payment terminal is characterized by comprising a clock unit, wherein the control unit generates a one-time password using time information obtained from the clock unit, and verifies whether the generated one-time password matches the one-time password obtained by decrypting the input authentication code.

[0008] Furthermore, the present invention has the following configuration. A payment method for an external device that sells goods or services, comprising a server, a mobile terminal, and an offline authentication type payment terminal, wherein the mobile terminal is used to access the server based on server connection information specific to the external device, so that the server displays the goods or services sold by the external device in a selectable format on the mobile terminal, the server displays information on the mobile terminal to confirm whether or not to make a payment based on the selection of the goods or services, the server performs a payment process if it is selected to make the payment, generates an authentication code corresponding to the payment, and displays the authentication code on the mobile terminal, and when the authentication code is entered into the input section of the payment terminal, the payment terminal verifies whether or not the entered authentication code is information generated based on a secret key stored in the payment terminal, and outputs a drive signal or a sales permission signal to the external device if the authentication code is information generated based on a secret key stored in the payment terminal. [Effects of the Invention]

[0009] According to this invention, one-time password verification can be performed on a terminal alone, even in environments where servers or communication lines are unavailable. Therefore, stable authentication that does not depend on the communication environment is possible. Furthermore, by storing previously used one-time passwords in a storage device and eliminating their reuse, replay attacks can be effectively prevented. In addition, the remaining time display unit can show the user the validity period of the code, improving operability and security. Moreover, the output configuration that supports both timer control signals and communication signals ensures connectivity with a variety of external devices, thereby improving practicality and expandability. [Brief explanation of the drawing]

[0010] [Figure 1] This is a hardware configuration diagram of the payment terminal and payment system according to the present invention. [Figure 2] Overview diagram of a payment system using an offline authentication payment terminal. [Figure 3]Processing flow of a payment system using an offline authentication payment terminal [Figure 4] This is an explanatory diagram showing an example of a server connection information display unit. [Figure 5] This is an explanatory diagram illustrating an example of the authentication code input section and authentication code display section shown on a payment terminal. [Figure 6] This is an explanatory diagram illustrating examples of images displayed on a mobile device. Figure 6(a) shows an example of the screen for selecting the product or service to purchase, Figure 6(b) shows an example of the screen for paying for the purchased product or service, and Figure 6(c) shows an example of the display of the authentication code sent by the server. [Modes for carrying out the invention]

[0011] The following describes the offline authentication type payment terminal (hereinafter referred to as "payment terminal") 1 and the payment system using the payment terminal 1 according to the present invention. The payment terminal 1 of the present invention enables payment authentication based on an authentication code generated by the server 40, even in environments without communication capabilities, and allows control of external devices 30. Figure 1 shows a hardware configuration diagram of the payment terminal 1 and the payment system.

[0012] As shown in Figure 1, the payment terminal 1 is composed of a control unit 10, a terminal information storage unit 11, a secret key storage unit 12, a server connection information display unit 13, an authentication code input unit 14, an authentication code display unit 16, a clock unit 17, a power input unit 18, a signal output unit 22, a communication unit 24, a setting means 26, a display unit 28, a storage means 29, and the like.

[0013] The control unit 10 is an arithmetic processing unit mainly consisting of a microcontroller or CPU that comprehensively controls the overall operation of the payment terminal 1, and performs data control between each means, encryption processing, output control, and error detection. The control unit 10 refers to the time data supplied from the clock unit 17 and the basic secret key, which is the secret key stored in the secret key holding unit 12, and verifies the authenticity of the authentication code provided by the server 40. The authentication code is generated based on the secret key, and this includes cases where it is generated by the secret key itself, as well as cases where it is generated by information generated using the secret key.

[0014] In the embodiment described later, the authenticity of the authentication code is determined by comparing it with a TOTP (Time-based One Time Password), which is a one-time password generated using a private key (basic secret key) and payment information obfuscated by the current time, to see if they match. However, the method for generating comparison information for authenticity verification using a private key (basic secret key) is not limited to the method described after generating the TOTP. That is, both the payment terminal 1 and the server 40 are made to hold the same concealed information, and based on that information, both the payment terminal 1 and the server 40 perform the same calculation process, and if the results are the same, it is determined to be authentic. There are various variables and calculation methods that can be used to generate comparison information based on a private key, so it goes without saying that it is not limited to the method described in this embodiment.

[0015] The encryption / TOTP verification unit 10a is an encryption function unit located within the control unit 10. Based on the TOTP algorithm, it verifies the latter six digits of the input 10-digit authentication code. It regenerates the TOTP using the time information and secret key obtained from the clock unit 17 and determines whether it matches the input code. The HMAC-SHA method is used to generate the TOTP, and authentication is successful if a match is found within a fixed slot interval (e.g., 60 seconds).

[0016] After the authentication is established by the encryption / TOTP verification unit 10a, the settlement number verification and replay prevention unit 10b extracts the product number and settlement number decrypted from the first four digits of the authentication code, and collates them with the used number data held in the storage means 29. If the same settlement number has been registered in the past, it is determined as reuse and the authentication is invalidated. Thereby, double settlement can be surely prevented without going through communication.

[0017] The output control unit 10c is a functional unit that controls the generation and output time of a drive signal for operating the external device 30 after the authentication is established. Depending on the mode set by the setting means 26, it executes either a communication mode in which a digital communication signal (such as the JVMA protocol) is sent via the communication unit 24 or a timer mode in which a power-on signal is output via the signal output unit 22 for a certain period of time. The output control unit 10c transmits remaining time information to the display unit 28 during operation to present the operation status to the user. Note that, as will be described later, it is also possible to specially design the settlement terminal 1 according to the specifications of the external device 30. In that case, the setting means 26 such as a DIP switch for setting the specifications for the external device 30 can be made unnecessary.

[0018] The terminal information holding unit 11 is a non-volatile storage area for holding the unique information of the settlement terminal 1, and is electrically connected to the control unit 10. At least a unique terminal ID number for identifying the unique settlement terminal is recorded in the holding unit Also, if necessary, corresponding terminal information (installation location, model type, manufacturing number, etc.) registered in the server 40, reference management information (key identification code or cryptographic hash) of the secret key basic secret key used for TOTP generation / verification, etc. are also recorded. The terminal ID recorded in the terminal information holding unit 11 is embedded in a QR code (registered trademark of Denso Wave Incorporated) displayed on the server connection information display unit 13. Also, when performing TOTP verification, the control unit 10 calls the basic secret key stored in the secret key holding unit 12 and executes cryptographic operations. With this configuration, it is possible to associate the terminal information managed on the server 40 side with the information inside the payment terminal 1, and it is possible to prevent unauthorized verification of the authentication code by a counterfeit terminal.

[0019] The secret key holding unit 12 is a security area for securely storing the basic secret key used for TOTP generation and authentication code verification. This holding unit 12 is composed of a secure element, a hardware cryptographic module, or a dedicated non-volatile memory connected to the control unit 10, and is structured such that reading from the outside is impossible or extremely difficult. The basic secret key assigned uniquely to the terminal is stored in the secret key holding unit 12, and the same basic secret key is also stored in the server 40. When performing TOTP verification, the control unit 10 refers to this key based on the time data from the clock unit 17 and generates TOTP by HMAC operation. The generation result is compared with the TOTP part in the 10-digit code input from the authentication code input unit 14, and authentication is established when they match exactly. Also, the basic secret key itself is encrypted so that it cannot be accessed from outside the internal program, and it is designed so that the key information does not disappear even during firmware update or power reset.

[0020] The server connection information display unit 13 is a display unit that presents the connection information for the user's mobile terminal 50 to access the server 40. As the display format, a two-dimensional image code such as a QR code or an NFC tag is used. The display information includes the terminal ID or encrypted URL parameters, and when the mobile terminal 50 reads this, it transitions to the payment screen on the server 40. The display information may be fixed or dynamic, and may be configured to be periodically updated by the control unit 10.

[0021] The authentication code input unit 14 is an input device for the user to enter a 10-digit authentication code displayed on the screen of the mobile terminal 50. It is equipped with a numeric keypad (0-9) and "ENT (Confirm)" and "CLR (Cancel)" keys, and transmits the input signal to the control unit 10. After the 10 digits have been entered, the TOTP verification process begins. If there is an input error, it can be initialized with the "CLR" key, and if there is no input for a certain period of time, it will automatically return to the standby state.

[0022] The authentication code display unit 16 consists of a 7-segment LED, liquid crystal display module, electronic paper, etc., connected to the control unit 10, and displays the user the authentication code input, authentication result, and operating status. It displays "OK" upon successful authentication after input and "ERR" upon failure. In maintenance mode, it can also display the terminal ID and internal time correction value.

[0023] The clock unit 17 consists of a real-time clock (RTC) and a coin cell battery, and maintains accurate time even when the terminal's power is cut off. The clock unit 17 outputs time data to the control unit 10, which is used as the reference time during TOTP verification. The control unit 10 corrects drift by comparing it with past successful settlement times, suppressing time errors during long-term use.

[0024] The power input section 18 receives power from an external device 30 or a common power supply and supplies a stabilized voltage to each component within the terminal. The input voltage is compatible with DC 5 to 24V and is equipped with an overvoltage protection, noise filter, and reverse connection prevention circuit. In addition, a coin battery is built into the clock section 17 to maintain the RTC, and the time information is retained even when the main power is turned off.

[0025] The signal output unit 22 is a circuit unit that generates an electrical output to operate the external device 30 based on a command from the control unit 10. Its configuration includes relays, MOSFET switches, optical isolators, etc., and it outputs a voltage signal depending on whether it is in communication mode or timer mode. In timer mode, it holds the voltage for the energizing time specified by the setting means 26, controlling the operation of the external device 30.

[0026] The communication unit 24 is an interface for digital communication between the control unit 10 and the signal output unit 22 and the external device 30, and supports JVMA communication, pulse communication, or serial communication (UART, RS-485, etc.). It transmits product selection commands, etc., according to the output commands of the control unit 10 and monitors the status after receiving a response from the external device 30. Communication with the external device 30 is conducted via either a wired or wireless connection. Furthermore, when the payment terminal 1 is integrated into the external device 30, it is connected directly to the communication terminal on the external device 30, or via a wiring cable.

[0027] The setting means 26 is a setting interface for specifying the output mode, operating time, signal level, etc., of the payment terminal 1. It consists of multiple DIP switches, rotary switches, or jumper setting terminals, and allows selection of communication type, timer type, or simple output type. The setting value is read by the control unit 10 when the power is turned on and applied as the operating condition of the output control unit 10c. Furthermore, if the device is specifically designed to match the specifications of the external device 30, setting means 26 such as DIP switches are unnecessary and do not need to be provided.

[0028] The display unit 28 is a display that visually shows the remaining operating time to the user while the external device 30 is in operation. It uses a 7-segment LED or liquid crystal display to show countdown information transmitted from the control unit 10. It can also display blinking when there are 5 seconds or less remaining, or automatically turn off when operation is complete. In maintenance mode, it can also be used to display diagnostic codes and error codes. Furthermore, the display unit 28 does not need to be provided separately; it can be used in conjunction with the authentication code display unit 16.

[0029] The storage means 29 consists of non-volatile memory (EEPROM or flash memory) and stores payment history, time correction data, and operation setting information. The control unit 10 records the decrypted payment number after authentication is successful and prevents replays by verifying it in subsequent transactions. The data is retained even after the power is turned off.

[0030] External devices 30 are devices that provide goods or services based on control signals from the payment terminal 1. These include vending machines, car wash machines, massage chairs, coin laundry machines, etc. In the case of pulse input type devices, the signal output unit 22 simulates a coin insertion signal to drive the device, and in the case of timer type devices, operation is performed by controlling the power supply for a certain period of time. In the case of communication-enabled devices, commands are sent and received via the communication unit 24.

[0031] Server 40 receives access from the mobile terminal 50, displays product information corresponding to the terminal ID, processes payment, and generates a TOTP authentication code. Server 40 maintains a basic secret key for each terminal and generates a TOTP upon completion of payment, sending a 10-digit authentication code to the mobile terminal 50. To prevent reuse, the TOTP and payment number are managed by the server for a certain period of time.

[0032] The mobile terminal 50 is a communication terminal used by users to access the server 40, select products, and make payments. It connects to the server 40 by reading the QR code on the server connection information display unit 13, and displays an authentication code generated by the server 40 on the screen after payment is completed. The user completes offline authentication by entering this authentication code into the authentication code input unit 14 of the payment terminal 1. The mobile terminal 50 can be a general communication device such as a smartphone or tablet.

[0033] Figure 2 is a schematic diagram showing the overall configuration of the offline authentication type payment system according to the present invention. As shown in the figure, the system consists of an offline authentication type payment terminal 1, a server 40, a mobile terminal 50, and external equipment 30. The offline authentication type payment terminal 1, the server 40, and the external equipment 30 do not communicate directly with each other, but rather indirectly exchange authentication information through the operation of the mobile terminal 50 by the user.

[0034] Since payment terminal 1 does not have network communication capabilities, it is connected to external device 30 via wired or serial communication and does not communicate with server 40. Instead, communication with the server is performed via the user's mobile terminal 50, and payment terminal 1 completes authentication and operation control in an offline state.

[0035] Server 40 is a payment management server built on the internet and is accessed from mobile terminals 50. Server 40 maintains a payment terminal information table, a product information table, and a payment history table. When a user reads the QR code (server connection information display unit 13) on the external device 30 using their mobile terminal 50, the server 40 reads the terminal's configuration information based on the terminal ID and sends the product selection screen to the mobile terminal 50. After product selection and payment are completed, the server 40 generates a TOTP using the terminal's unique basic secret key and time information, and based on this generates a 10-digit authentication code which is then sent to the mobile terminal 50.

[0036] The mobile terminal 50 is a smartphone or tablet with communication capabilities for users to make payments. The mobile terminal 50 accesses the server 40 by reading the QR code displayed on the server connection information display unit 13 of the external device 30 and displays the product list received from the server 40 (see Figure 6(a)). The user selects a product and makes a payment (see Figure 6(b)). Once the payment is complete, a 10-digit authentication code generated by the server 40 is displayed on the screen of the mobile terminal 50 (see Figure 6(c)). The user manually enters this code into the authentication code input section 14 of the payment terminal 1. The mobile terminal 50 is solely a device for communication with the server 40 and does not communicate directly with the payment terminal 1.

[0037] External devices 30 are various service devices that operate in response to control signals from the payment terminal 1. Specifically, examples include vending machines, coin laundries, car washes, and massage chairs. Instead of conventional coin insertion signals or prepaid card signals, external devices 30 receive control signals sent from the payment terminal 1 and start predetermined operations. Based on the authentication results obtained via the server 40 and the mobile terminal 50, the payment terminal 1 sends an operation start signal to the external devices 30, thereby completing offline payments without using communication.

[0038] Thus, in this system, by interposing a mobile terminal 50 between the server 40 and the payment terminal 1, payment information can be securely transmitted via human operation. Since server 40 processes payments online and payment terminal 1 performs authentication offline, reliable transactions are possible even without a network connection. Furthermore, since payment terminal 1 does not communicate directly with the server, the risk of unauthorized access from external sources can be minimized.

[0039] According to the configuration shown in Figure 2, the server 40 functions as the "central core for payment and TOTP generation," the mobile terminal 50 as the "communication and user interface," the payment terminal 1 as the "authentication and control output execution device," and the external device 30 as the "product and service provision device." This allows for stable cashless payments that are not dependent on the communication environment, compared to conventional online integrated payment systems.

[0040] [Payment Processing System Flow] The following describes an example of a payment processing system using payment terminal 1. Figure 3 is an explanatory diagram illustrating the flow of the payment processing system using payment terminal 1. As an example, we will explain the process from connecting a payment terminal 1 to an external device 30 configured as a vending machine, to the server 40 processing the payment on the external device 30, and then to the purchase of goods or services on the external device 30.

[0041] As an example, a QR code constituting server connection information is displayed on the casing of the external device 30 as a server connection information display unit 13. NFC may be used as an alternative to the QR code, as long as the connection information for connecting to the server 40 can be obtained by the mobile terminal owned by the person making the payment. Furthermore, although the server connection information display unit 13 is provided on the external device 30 in this example, it is also possible to provide the server connection information display unit 13 on the payment terminal 1, and the placement can be appropriately determined depending on the payment target. In addition to a printed 2D image code, the server connection information display unit 13 may also display an image generated by the control unit 10 on the display. In this case, the displayed information may be fixed or dynamic, and may be configured to be periodically updated by the control unit 10. In addition to being built into the external device 30, the payment terminal 1 may also be installed outside the external device 30 and connected to the external device 30 by wire or wireless connection.

[0042] The following describes each step S1 to S16 shown in Figure 3. [Step S1: Read the QR code] The user reads the QR code displayed on the server connection information display unit 13 of the external device 30 using the camera of the mobile terminal 50. Figure 4 shows an example of the display on the server connection information display unit 13, which is provided as printed information on the front of the casing of the external device 30. In this example, the logos of available payment services are displayed along with the instruction, "Please take a picture of the QR code and make a payment with your smartphone. Please enter the 10-digit number displayed at the end of the payment process." The QR code has the terminal ID of the payment terminal 1 and the URL to connect to the server 40 embedded in it, and the mobile terminal 50 automatically accesses the payment web page of the server 40. As a result, the server 40 obtains the registration information of the terminal based on the terminal ID and identifies a list of products that can be sold from the product database.

[0043] [Step S2: Display the product list] Server 40 transmits a product list and price information corresponding to the terminal ID to the mobile terminal 50, and displays the product list on the screen of the mobile terminal 50. Figure 6(a) is an example screen for selecting products or services provided by the external device 30, where, for example, multiple usage courses (10 minutes to 100 minutes) and their respective fees are displayed in a list format. The user selects the desired course and performs the "purchase" operation. This product list includes product number, price, description, etc., and the user can select the desired product. Product data is managed on the server 40 side and can have different settings for each payment terminal.

[0044] [Step S3: Product Selection and Payment] When a user selects a product on their mobile device 50, the server 40 receives the selection information and executes the electronic payment process (credit card, electronic money, or wallet payment, etc.). Figure 6(b) shows an example of a confirmation screen just before payment, displaying the selected product name and price, as well as the payment service to be used (credit card, electronic money, or wallet payment, etc.). When the user touches the "Purchase" button, the server 40 executes the payment, and once the payment is complete, a response screen is displayed on the mobile device 50. [Step S4: Generate 4-digit payment information] If the payment is successfully completed, server 40 generates a unique 4-digit payment information (1-digit product number + 3-digit payment number) for the transaction and temporarily records it.

[0045] [Step S5: Obfuscation of payment information] Server 40 obfuscates the generated 4-digit payment information by performing an XOR operation using the terminal-specific basic secret key registered in the terminal information storage unit 11, the same basic secret key stored in Server 40, and the current time. This obfuscation process protects the transaction information so that even if it is read by a third party, the original content cannot be identified. The obfuscated 4-digit information is used as part of the subsequent TOTP generation process.

[0046] [Step S6: Creating a secret key for TOTP generation] Server 40 combines obfuscated 4-digit payment information with a terminal-specific basic secret key to generate a secret key for TOTP generation. This secret key is input into the TOTP generation algorithm (compliant with RFC6238) and used as an encryption key to generate a transaction-specific 6-digit TOTP.

[0047] [Step S7: TOTP generation] Server 40 generates a TOTP using the above generation key and the current time. The generated TOTP is a 6-digit numerical code that changes at regular intervals (e.g., every 60 seconds). This TOTP is compared with the TOTP regenerated on the payment terminal 1 side, allowing its authenticity to be verified without communication.

[0048] [Step S8: Generate and display a 10-digit code] Server 40 concatenates the obfuscated 4-digit payment information with the generated 6-digit TOTP to generate a 10-digit authentication code. This 10-digit code is displayed on the screen of the user's mobile terminal 50, and the user enters it into the payment terminal 1. Figure 6(c) shows an example of the display of a 10-digit authentication code generated by the server 40 after payment is completed and sent to the mobile terminal 50. The screen displays the generated authentication code (e.g., "1684284794") along with instructions regarding the validity period, such as "The number will be updated in 55 seconds" and "Please enter this into the terminal within 1 hour after payment." This authentication code is updated at regular intervals based on a time-synchronous TOTP, and authentication is established by comparing it with the TOTP regenerated by the payment terminal 1 using the same algorithm. This configuration allows authentication information to be transmitted offline without using a communication line, enabling rapid payment processing while maintaining security.

[0049] Next, we will describe the processing performed by the payment terminal 1 after the series of payment processing in server 40. [Step S9: Enter the 10-digit code] The user enters the 10-digit authentication code (4 obfuscated digits + 6 TOTP digits) displayed on the mobile terminal 50 into the authentication code input section 14 of the payment terminal 1. The control unit 10 transfers the entered data to the encryption / TOTP verification unit 10a. During input, the authentication code display unit 16 displays a digit mask, and after the 10 digits have been entered, the TOTP verification process begins.

[0050] [Step S10: Creating a secret key for TOTP generation] The control unit 10 of the payment terminal 1 extracts the first four digits from the 10-digit authentication code entered via the authentication code input unit 14. The extracted four-digit obfuscated payment information is combined with the terminal-specific basic secret key stored in the secret key holding unit 12 to reconstruct a secret key for TOTP generation. Since this generation process is performed using the same algorithm (XOR concatenation or HMAC synthesis) as the procedure used on server 40, it becomes possible to reproduce matching TOTPs within the same time slot.

[0051] [Step S11: TOTP Verification] The encryption / TOTP verification unit 10a of the control unit 10 refers to the current time output from the clock unit 17 and regenerates the TOTP using the TOTP generation secret key. The generated 6-digit TOTP is compared with the last 6 digits of the authentication code entered by the user, and if they match, authentication is determined to be successful. If they do not match, "ERR (Error)" is displayed on the authentication code display unit 16, and the system returns to the re-input waiting state. In this verification process, by setting the time deviation tolerance to one slot before or after (for example, 60 seconds before or after), authentication failure due to errors in the clock unit 17 can be prevented. The slot is the same as the update cycle shown in Figure 6(c), and in this embodiment, it is set to 60 seconds.

[0052] [Step S12: Decrypting payment information] If TOTP verification is successful, the control unit 10 performs a decryption process on the first four digits of the input code. That is, using the terminal-specific secret key stored in the private key holding unit 12 and the current time data from the clock unit 17, the original four-digit payment information is restored by applying the same XOR operation used during obfuscation in reverse. [Step S13: Obtain the product number and payment number] The decryption results include a product number (1 digit) and a payment number (3 digits), and the control unit 10 temporarily stores these in its internal memory.

[0053] [Step S14: Check whether the payment number is unused or not] The settlement number verification and replay prevention unit 10b of the control unit 10 verifies the decrypted settlement number (3 digits) against the past settlement history stored in the storage means 29. If the same number is already registered, it determines that the same authentication code has been reused (replay), invalidates the authentication, and displays a message such as "This settlement number has already been used." [Step S15: Generation of control signal] If the number is unused, the four-digit payment information is newly registered in the storage means 29 and used for verification in subsequent transactions, thereby ensuring that it is not reused. This makes it possible to guarantee the uniqueness of transactions independently without communication.

[0054] [Step S16: Send a signal corresponding to the product number to the connected device] If the replay prevention determination is successful, the output control unit 10c of the control unit 10 generates a control signal to be sent to the external device 30 based on the product number obtained from the decoding result. If the product number corresponds to a specific setting, the signal format is determined according to the output mode (communication type, timer type, or other simple output type) selected by the setting means 26. As mentioned above, it is also possible to design a dedicated program according to the external device 30, in which case selection by the setting means 26 is unnecessary. In the communication type, JVMA protocol or serial communication data is sent via the communication unit 24, and in the timer type, power is supplied for a set time via the signal output unit 22. It is also possible to transmit certain signals to unlock electronic locks, etc.

[0055] After the external device 30 has finished operating, the control unit 10 stops the signal output and performs the set stop process. The control unit 10 appends the transaction result (settlement number, execution time, operation result) to the storage means 29 and initializes the internal state of the terminal. After that, the settlement terminal 1 returns to the initial standby screen and prepares for the next settlement transaction. Through this series of processes, the payment terminal 1 can integrate payment completion, control output, and history management without communication, enabling highly reliable payment operations even in an offline environment. [Explanation of symbols]

[0056] 1 Payment terminal 10 Control Unit 10a Cryptography / TOTP Verification Department 10b Payment number verification and replay prevention unit 10c Output control unit 11 Terminal information storage unit 12 Private key holding unit 13. Server connection information display section 14. Authentication code input section 16 Authentication code display section 17 Clock Department 18 Power Input Section 22 Signal output section 24 Communications Department 26 Setting means 28 Display section 29 Memory means 30 External equipment 40 servers 50 Mobile devices

Claims

1. An offline authentication type payment terminal, The system comprises a control unit, a terminal information storage unit, a private key storage unit, a storage means for storing past payment history, a display unit for displaying server connection information, and an input unit for the user to input an authentication code containing payment information transmitted from the server. The control unit, Based on the encryption key generated by combining the obfuscated payment information contained in the authentication code input via the input unit and the terminal-specific secret key stored in the private key holding unit, a TOTP (Time Token Time) is generated with the current time encrypted, and it is verified that the generated TOTP is identical to the TOTP contained in the authentication code. If the above verification is successful, the payment number contained in the information obtained by decrypting the obfuscated payment information contained in the authentication code based on the terminal-specific secret key and the current time information is compared with the past payment history stored in the storage means, and if the same payment number is registered, it is determined to be a reuse and the authentication is invalidated. An offline authentication type payment terminal characterized by being configured to output a drive signal or a sales authorization signal to an external device if the same payment number is not registered.

2. A payment method for an external device that sells goods or services, Using a server, mobile terminals, and offline authentication type payment terminals, By using the aforementioned mobile terminal to access the server based on server connection information specific to the external device, the server displays the products or services sold on the external device in a selectable format on the mobile terminal. When a product or service is selected, the server displays information on the mobile terminal to confirm whether or not to make a payment based on that selection. The server performs the payment process if it is selected to perform the payment. The server generates an authentication code that includes payment information corresponding to the payment, which has been obfuscated based on the basic secret key stored by the server and the current time, and TOTP, which encrypts the current time using an encryption key generated by combining the obfuscated payment information and the basic secret key, and displays the authentication code on the mobile terminal. The aforementioned payment terminal is When the authentication code is entered into the input section of the payment terminal, the terminal generates an encrypted TOTP (Time-to-Time Pass) based on an encryption key generated by combining the obfuscated payment information contained in the entered authentication code with a terminal-specific secret key that is identical to the basic secret key stored in the payment terminal, and the current time is encrypted. If the TOTP generated by the payment terminal is the same as the TOTP included in the authentication code, the obfuscated payment information included in the authentication code is restored based on the terminal's unique secret key and the current time information held by the payment terminal to obtain the payment information. An offline authentication type payment method characterized by outputting a drive signal or a sales authorization signal to an external device if the payment number included in the payment information is not a previously used payment number stored by the payment terminal.

Citation Information

Patent Citations

  • Service receiving system

    JP2002140756A

  • Cashless automatic selling method and system

    JP2004070883A

  • Article purchase method, article purchase system, and article purchase program and recording medium

    JP2005141754A

  • Management system based on distributed non-connection one-time password authentication

    JP2005190447A

  • Anti-replay system and method

    JP2019513250A