Key management method, mobile device for digital currency transaction, apparatus, system, and storage medium

By setting up a secure and isolated execution environment and a secure channel management core key in mobile devices, the data security issue when mobile devices are used as acceptance terminals for digital currency transactions is solved, enabling secure data encryption and automatic updates, thereby improving the security and success rate of transactions.

WO2026026622A1PCT designated stage Publication Date: 2026-02-05THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/110040
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2025-07-23
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

There is a lack of effective solutions in the current technology to protect the data security when mobile devices are used as acceptance terminals for digital currency transactions.

Method used

By setting up first and second execution environments in a mobile device, the first execution environment is a rich execution environment (REE) and the second execution environment is a trusted execution environment (TEE) or a secure element (SE), and storing core key data in the second execution environment, the keys are transmitted and managed using a secure channel to ensure data security and integrity.

Benefits of technology

It achieves data security encryption and protection when mobile devices are used as acceptance terminals for digital currency transactions, ensuring the security of sensitive data during transmission and storage, reducing the risk of key cracking, and supporting automatic updates, thereby improving the success rate of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025110040_05022026_PF_FP_ABST
    Figure CN2025110040_05022026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a key management method, a mobile device for a digital currency transaction, an apparatus, a system, and a storage medium. The mobile device serves as an acceptance terminal, and comprises a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, and the second execution environment is securely isolated from the first execution environment. The digital currency acquirer application is configured to send a key application request to a digital currency background system, receive core key data by means of a secure channel between the digital currency background system and the mobile device, and when it is detected that the mobile device has the second execution environment and the executable digital currency trusted application is installed in the second execution environment, send the core key data to the digital currency trusted application. The digital currency trusted application is configured to receive the core key data sent by the digital currency acquirer application and store the core key data in the second execution environment.
Need to check novelty before this filing date? Find Prior Art

Description

Key management methods, digital currency transaction mobile devices, apparatus and systems, storage media

[0001] This application claims priority to Chinese Patent Application No. 202411046676.4, filed on July 31, 2024, entitled "Mobile Device for Digital Currency Transactions and Key Management Method", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure relates to the field of digital currency technology, and in particular to a key management method, a digital currency transaction mobile device, apparatus and system, and a storage medium. Background Technology

[0003] In recent years, with the widespread use and rapid growth of mobile devices, mobile devices (such as mobile phones) can serve as payment terminals (such as point-of-sale terminals, POS machines) to provide merchants with convenient payment services. However, for the new application scenario of using mobile phones as payment terminals for digital currency payment transactions, no effective implementation plan has yet been provided. Summary of the Invention

[0004] In view of this, embodiments of the present disclosure provide a key management method, a digital currency transaction mobile device, an apparatus and system, and a storage medium to achieve key management based on mobile devices and to securely encrypt sensitive data (such as core encrypted data) that protects digital currency transaction information.

[0005] In a first aspect, at least one embodiment of this disclosure provides a mobile device for digital currency transactions. The mobile device serves as an acceptance terminal and includes a digital currency acquiring application executable in a first execution environment and a trusted digital currency application executable in a second execution environment, wherein the second execution environment is securely isolated from the first execution environment. The digital currency acquiring application is configured to: send a key request to a digital currency back-end system and receive core key data through a secure channel between the digital currency back-end system and the mobile device; and, upon detecting that the mobile device has a second execution environment and that a trusted digital currency application is installed in the second execution environment, send the core key data to the trusted digital currency application. The trusted digital currency application is configured to: receive the core key data sent by the digital currency acquiring application and store the core key data in the second execution environment, wherein the core key data is randomly generated by the digital currency back-end system in response to the key request and includes an encryption key and an integrity key with an expiration date.

[0006] Secondly, at least one embodiment of this disclosure provides a mobile device for digital currency transactions. The mobile device serves as an acceptance terminal and includes a digital currency acquiring application executable in a first execution environment. The digital currency acquiring application is configured to perform the following operations when it is detected that the mobile device does not have a second execution environment: upon initiating a digital currency acquiring transaction, it sends a key request to the digital currency backend system, receives core key data through a secure channel between the digital currency backend system and the mobile device, and stores the core key data in a secure area of ​​the first execution environment. The second execution environment is securely isolated from the first execution environment, and the core key data is randomly generated by the digital currency backend system in response to the key request and includes an encryption key and an integrity key.

[0007] Thirdly, at least one embodiment of this disclosure provides a digital currency back-end system, including: a key generation module configured to: randomly generate core key data and store it in association with user data corresponding to a mobile device, the core key data including an encryption key and an integrity key with an expiration date; a communication module configured to establish a secure channel between the communication module and the mobile device; and a business management module configured to: respond to a key request sent by the mobile device, control the key generation module to randomly generate core key data and send it to the mobile device through the secure channel.

[0008] Fourthly, at least one embodiment of this disclosure provides a digital currency trading system, including: a mobile device provided according to at least one embodiment of this disclosure, and a digital currency back-end system provided according to at least one embodiment of this disclosure.

[0009] Fifthly, at least one embodiment of this disclosure provides a key management method based on a mobile device. The mobile device serves as an acceptance terminal for digital currency transactions and includes a digital currency acquiring application executable in a first execution environment and a trusted digital currency application executable in a second execution environment. The second execution environment is securely isolated from the first execution environment. The method includes: the digital currency acquiring application sending a key request to a digital currency back-end system and receiving core key data through a secure channel between the digital currency back-end system and the mobile device; and, upon detecting that the mobile device has a second execution environment and that a trusted digital currency application is installed in the second execution environment, sending the core key data to the trusted digital currency application; and the trusted digital currency application receiving the core key data transmitted by the digital currency acquiring application and storing the core key data in the second execution environment. The core key data is randomly generated by the digital currency back-end system in response to the key request and includes an encryption key and an integrity key with an expiration date.

[0010] In a sixth aspect, at least one embodiment of this disclosure provides a key management method based on a mobile device, wherein the mobile device serves as an acceptance terminal for digital currency transactions and includes a digital currency acquiring application executable in a first execution environment. The method includes: when the digital currency acquiring application detects that the mobile device does not have a second execution environment, it performs the following operations: each time a digital currency acquiring transaction is initiated, it sends a key application request to the digital currency backend system, receives core key data through a secure channel between the digital currency backend system and the mobile device, and stores the core key data in a secure area of ​​the first execution environment, wherein the second execution environment is securely isolated from the first execution environment, and the core key data is randomly generated by the digital currency backend system in response to the key application request and includes an encryption key and an integrity key.

[0011] In a seventh aspect, at least one embodiment of the present disclosure provides an electronic device comprising: one or more processors; and a memory configured to store one or more computer programs; wherein the one or more computer programs are executed such that the one or more processors implement the method provided by at least one embodiment of the present disclosure.

[0012] Eighthly, at least one embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions, when executed by one or more processors, implement the method provided by at least one embodiment of the present disclosure.

[0013] The mobile device-based key management scheme of this disclosure provides an effective way to securely encrypt sensitive data (such as core encrypted data) protecting digital currency transaction information in scenarios where mobile devices are used as acceptance terminals. Attached Figure Description

[0014] To more clearly illustrate the technical solutions of the prior art and the embodiments of this disclosure, the accompanying drawings used in the description of the prior art and the embodiments of this disclosure will be briefly introduced below. Of course, the accompanying drawings described below with reference to the embodiments of this disclosure are only a part of the embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort, and the obtained other drawings also fall within the protection scope of this disclosure. Clearly, the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure.

[0015] Figure 1 shows a block diagram of a digital currency trading system according to an embodiment of the present disclosure;

[0016] Figure 2A shows a block diagram of an exemplary mobile device (acceptance terminal) according to an embodiment of the present disclosure;

[0017] Figure 2B shows a block diagram of another exemplary mobile device (acceptance terminal) according to an embodiment of the present disclosure;

[0018] Figure 3 shows a block diagram of an exemplary digital currency back-end system according to an embodiment of the present disclosure;

[0019] Figure 4A shows a flowchart of a key data management method based on a mobile device according to an embodiment of the present disclosure;

[0020] Figure 4B shows a flowchart of a mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0021] Figure 5A shows a flowchart of an exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0022] Figure 5B shows a flowchart of another exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0023] Figure 6 shows a schematic diagram of an electronic device according to an embodiment of the present disclosure;

[0024] Figure 7 illustrates a schematic diagram of a computer-readable medium according to an embodiment of the present disclosure. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.

[0026] Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms “first,” “second,” and similar terms used in this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, terms such as “comprising” or “including” mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as “connected” or “linked” are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as “upper,” “lower,” “left,” and “right” are used only to indicate relative positional relationships, which may change accordingly when the absolute position of the described objects changes.

[0027] Note that the examples described below are merely specific examples and are not intended to limit the embodiments of this disclosure to the specific shapes, hardware, connections, operations, values, conditions, data, sequences, etc., shown and described. Those skilled in the art can utilize the concepts of this disclosure to construct further embodiments not mentioned herein by reading this specification.

[0028] The terminology used in this disclosure is that which is currently widely used in the art in consideration of the functionality of this disclosure; however, these terms may vary depending on the intent, precedent, or new technology of those skilled in the art. Furthermore, specific terms may be chosen by the applicant, and in such cases, their detailed meanings will be described in the detailed description of this disclosure. Therefore, the terminology used in this specification should not be construed as simple names, but rather based on the meaning of the terms and the overall description of this disclosure.

[0029] This disclosure uses flowcharts to illustrate the operations performed by a system according to embodiments of this disclosure. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, various steps can be processed in reverse order or simultaneously, as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0030] First, the abbreviations and related terms involved in this disclosure are defined and explained.

[0031] Mobile devices: Mobile devices have a wide range of applications, primarily including devices involving communication technologies. Specifically, this includes any electronic device that a user can easily carry or operate, which can also provide remote communication capabilities with networks. Mobile communication terminals can communicate using mobile phone (wireless) networks, wireless data networks (e.g., 3G, 4G, 5G, or similar networks), Wi-Fi, Bluetooth, Bluetooth Low Energy (BLE), Wi-Max, or any other communication medium that provides access to networks such as the Internet or private networks. Examples of mobile communication terminals include mobile phones (also called mobile terminals), tablet computers, netbooks, laptops, wearable devices (e.g., smartwatches), etc. Mobile communication terminals can include any suitable hardware and software for performing such functions, and may also include multiple devices or components.

[0032] Secure Element (SE): May include an on-chip computer or microprocessor. A secure element can perform cryptographic operations and may be embedded in a package with one or more physical security measures. In some embodiments, a secure element may include components capable of securely performing functions. A secure element may be a memory that securely stores data, making its access protected. Examples of secure elements are Universal Integrated Circuit Cards (UICCs) or Hardware Security Modules (HSMs), which are physical computing devices that protect and manage cryptographic keys used for authentication and provide cryptographic processing functions.

[0033] A Trusted Execution Environment (TEE) may include a secure area for processing data. The TEE may be a software stack stored on read-only memory (ROM). The TEE software stack may include one or more trusted applications (TAs) that implement the functionality of a specific application within a trusted application environment.

[0034] Digital currency acquiring application (referred to as acquiring App): It is used to initiate payment requests, obtain payment information from the payment side via NFC or obtain offline payment code information by scanning code and prompt the payment result. It is also used to manage the SE card application or TEE TA application for payment collection and its related core key data, and is responsible for daily check-in to update the key.

[0035] Digital currency acquiring card application (referred to as acquiring card application): Installed in SE, it is used in conjunction with the acquiring app and is mainly used to store core key data.

[0036] It should be noted that the collection, gathering, updating, analysis, processing, use, transmission, and storage of user personal information involved in this disclosed technical solution all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.

[0037] Currently, POS machines are generally used as payment terminals for acquiring transactions. However, with the rapid development of mobile devices (such as smartphones), using mobile devices as payment terminals is becoming increasingly necessary, providing a new application scenario. Nevertheless, relevant technologies do not offer effective solutions for this new scenario.

[0038] To address the aforementioned issues, this disclosure provides a relatively effective solution for using mobile devices as acceptance terminals to execute digital currency acquiring transactions. Furthermore, this solution achieves data security protection for mobile devices when transmitting digital currency transaction information. Moreover, by securely storing and automatically updating the keys that ensure the security of digital currency transaction information, better support is provided for digital currency acquiring transactions.

[0039] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.

[0040] Figure 1 shows a block diagram of a mobile device-based digital currency transaction system 100 according to an embodiment of the present disclosure. As shown in Figure 1, the transaction system 100 mainly includes a payment device (payment terminal) 102, a mobile device 104 as an acceptance terminal, and a digital currency back-end system (hereinafter referred to as "back-end system") 108.

[0041] For example, payment device 102 can be a hardware wallet or a mobile device with payment functionality (such as a mobile phone). It can complete digital currency payments by communicating with the acceptance terminal 104 via contactless means (NFC payment mode) or by displaying an offline payment code (QR code payment mode) for the acceptance terminal 104 to scan and complete the payment. Depending on the user's choice, payment device 102 can transmit digital currency payment information conforming to the Application Protocol Data Unit (APDU) format via NFC near-field communication or transmit digital currency payment information including offline payment code information via QR code scanning.

[0042] For example, in some embodiments of this disclosure, the payment device 102 can calculate and generate the offline payment code required for the QR code payment mode based on a key factor, challenge factor, event factor, calculation factor, and current time factor (base time of the hard wallet or current time of the mobile phone) used to generate the offline payment code. The challenge factor can be a random number, the event factor can be wallet account information, and the calculation factor is set separately for different operating institutions (digital currency back-end systems). For example, the offline payment code can include any image or symbol generated in an offline scenario that can be read by an electronic device and parsed and manipulated by the mobile device 104. Some examples include barcodes, quick response (QR) codes, military-grade UID codes, and any other suitable codes. In one example, the code information of the offline payment code can include a string consisting of a check digit and a user index, used to display to the receiving terminal for scanning when the user pays with digital currency. Moreover, the offline payment code is preferably a dynamic offline QR code or barcode, which can be dynamically updated according to a set time during the transaction to protect fund security. When transmitted to the backend system 108, the code information of the offline payment code can be used as part of the payment information to enable the backend system 108 to perform security verification of the payment information.

[0043] For example, in some embodiments of this disclosure, payment device 102 is configured to generate an offline payment code by performing the following operations: encrypting a challenge factor, a time factor, and an event factor using a key factor to obtain a verification code; calculating a digest value using the verification code and an operation factor, and calculating a user index using the digest value and the event factor; and obtaining a string of offline payment code based on the user index and the verification code, which serves as the code information of the offline payment code. For example, a symmetric encryption algorithm can be used to encrypt the verification code, and the digest value can be calculated using a digest algorithm, such as various existing algorithms, including the MAC algorithm and the SM3 algorithm.

[0044] For example, in some embodiments of this disclosure, the mobile device 104 provides a first execution environment and a second execution environment securely isolated from the first execution environment. The first execution environment runs the main operating system and is an environment for running regular applications on the mobile device 104, such as a Rich Execution Environment (REE). The second execution environment is securely isolated from the first execution environment, and data interaction between the two environments is restricted. The second execution environment may be, for example, a Trusted Execution Environment (TEE) or a Secure Element (SE). Sensitive data, such as keys, can be securely stored in the second execution environment without the security risk of being disclosed to the first execution environment. Even if the mobile device 104 is infected with malware, third parties cannot steal the data stored in the second execution environment.

[0045] In one example, a first execution environment contains an executable digital currency acquiring application (a client application), and a second execution environment contains an executable trusted digital currency application (performing specific acquiring functions and used in conjunction with the digital currency acquiring application, such as a digital currency acquiring card application in the SE or a digital currency acquiring TA application in the TEE). Specifically, in the mobile device 104, the data processing typically involved in digital currency acquiring transactions mainly consists of the digital currency acquiring application running in the REE and the trusted digital currency application running in the second execution environment. The digital currency acquiring application can interact with the trusted digital currency application through the operating system (such as a trusted operating system TOS or a chip operating system COS) in the second execution environment, thereby providing user-facing functionality. This model separates critical security operations (performed in the trusted digital currency application) from the user interface (provided in the digital currency acquiring application), ensuring data security and integrity.

[0046] For example, the digital currency acquiring application displays a user interface on the screen of mobile device 104 during a digital currency acquiring transaction. This interface primarily provides guidance on the acquiring operation and executes corresponding actions based on user triggers to complete the digital currency acquiring transaction. Furthermore, when connecting mobile device 104 to the digital currency system, the user registration interface presented by the digital currency acquiring application allows users to register their merchant information and mobile device information, thus granting the merchant holding mobile device 104 the right to perform digital currency acquiring.

[0047] For example, in some embodiments of this disclosure, if the second execution environment is a secure element, the trusted digital currency application is a digital currency acquiring card application. This digital currency acquiring card application is managed by the acquiring app and is mainly used to store relevant core key data and to encrypt and ensure the integrity of transaction information. Its operation relies on the chip operating system (COS) within the secure element, unlike the digital currency acquiring application, which generally does not have a user-facing interface. If the second execution environment is a trusted execution environment (TEE), the trusted digital currency application is a digital currency acquiring TA application, which can perform similar operations as the digital currency acquiring card application. In the following detailed description, the embodiments of this disclosure will use a secure element as the second execution environment and a digital currency acquiring card application running within the secure element as an example to illustrate the relevant method flow.

[0048] Figure 2A shows a block diagram of an exemplary mobile device 104 according to an embodiment of the present disclosure. As shown in Figure 2A, the mobile device 104 includes a digital currency acquiring application 1041 running in an REE, a secure element 104A (an example of a second executable environment) having a data storage area (not shown) and a digital currency acquiring card application 1043, and a communication module 1045.

[0049] For example, in some embodiments of this disclosure, the digital currency acquiring application 1041 is configured to initiate a digital currency acquiring transaction with the payment terminal (payment device 102 shown in FIG1) to obtain digital currency payment information or offline payment code information returned by the payment terminal when it detects that the mobile device 104 has a second execution environment (such as SE 104A in this example) and a trusted digital currency application (such as acquiring card application 1043 in this example) is installed in SE 104A. For example, the digital currency acquiring application 1041 displays the amount information of the pre-acquisition on the user interface, and after receiving the user's trigger operation, it obtains digital currency payment information in APDU instruction format through NFC communication with the payment device 102 by using contactless consumption, i.e., "tap-to-pay", or it activates the sensor (such as camera and / or vision sensor) of the mobile device 104 to scan the offline payment code shown as 102A in FIG1 to obtain the payment code information. The specific acquisition method is not limited in this disclosure.

[0050] For example, in some embodiments of this disclosure, the digital currency acquiring card application 1043 is configured to perform encryption and integrity processing on digital currency transaction information using core key data stored in the data storage area of ​​a second execution environment, such as the secure element 104A. The processed digital currency transaction information is then sent to the digital currency back-end system 108 via the digital currency acquiring application 1041, so that the digital currency back-end system 108 verifies and decrypts the processed digital currency transaction information to execute the digital currency acquiring transaction. The core key data is a key pre-received from the digital currency back-end system 108 and stored in the second execution environment through a secure channel between the digital currency back-end system 108 and the mobile device 104, and includes an encryption key and an integrity key with an expiration date.

[0051] In this example, the digital currency transaction information includes at least digital currency payment information or offline payment code information. Additionally, it may include device information, merchant information, order information, etc. This information can be dynamically obtained locally by the mobile device 104, for example, by querying the corresponding storage area through the digital currency acquiring application 1041, including device information such as device type and device ID, merchant information, and order information for this acquiring transaction.

[0052] Specifically, the encryption key primarily ensures the confidentiality of transmitted data during digital currency transactions, while the integrity key primarily ensures the integrity and reliability of transmitted data. When the digital currency acquiring card application 1043 receives digital currency transaction information sent by the digital currency acquiring application 1041, it uses a preset key algorithm (e.g., a symmetric key algorithm) to encrypt the digital currency transaction information using the encryption key to obtain ciphertext. Then, it uses a digest algorithm and an integrity key (e.g., a MAC key) to perform integrity calculations on the ciphertext to obtain a digest value (e.g., a MAC value). The ciphertext and digest value are then sent as the processed digital currency transaction information to the backend system 108 for further processing. Digest algorithms include various existing algorithms, such as the MAC algorithm and the SM3 algorithm.

[0053] Furthermore, by setting a key validity period, such as 24 hours, the risk of key cracking can be reduced without leading to frequent key replacements and high management costs. Correspondingly, the mobile device 104, acting as the acceptance terminal, also needs to automatically update the key before it expires. Based on the above, in some embodiments of this disclosure, the digital currency acquiring application 1041 also responds to a data update synchronization command by sending an update command for the core key data to the digital currency backend system 108. This "data update synchronization command" can be triggered by the merchant before using the mobile acceptance terminal for digital currency acquiring transactions, or it can be automatically triggered internally by the acceptance terminal system according to a set time. The "set time" should ideally be consistent with the key validity period. For example, if the key validity period is 24 hours, then every 24 hours, i.e., daily, the user or system triggers the mobile device 104 to "check in" to the digital currency backend system 108, sending an update command for the core key data to obtain new core key data.

[0054] Furthermore, since business and other communications require the validity of business-related data such as communication certificates and other keys based on actual needs, the digital currency acquiring application 1041 also sends a synchronization instruction for synchronizing business-related data to the digital currency backend system 108 in response to the data update synchronization instruction. These two instructions (the core key data update instruction and the synchronization instruction for synchronizing business-related data) can be sent to the backend system 108 simultaneously or in different time periods; this embodiment does not limit this.

[0055] Accordingly, in some embodiments of this disclosure, the digital currency acquiring card application 1043 is further configured to replace the core key data and business-related data already stored in the second execution environment with new core key data and business-related data transmitted by the digital currency acquiring application 1041. This ensures the validity of the core key data, improves the success rate of the backend system 108 in verifying and decrypting processed transaction information, and thus ensures better transaction execution. Updates to business-related data also ensure synchronization with backend data. Just as the core key data is updated daily, updating business-related data such as keys used for business and other communications ensures data freshness and validity, thereby guaranteeing successful transaction execution.

[0056] For the first installation of a digital currency acquiring application, the application checks whether the mobile device has a second execution environment. If a second execution environment is detected, it further checks whether a trusted digital currency application is installed in that environment. In one example, the installation of a trusted digital currency application can be determined by checking whether the second environment contains a payment application identifier. If the payment application identifier is present, it is determined that the second environment has installed applications such as an SE acquiring card application or a TEE TA application.

[0057] Furthermore, in some embodiments of this disclosure, the digital currency acquiring application 1041 is also configured to, upon detecting that the mobile device 104 has a second execution environment but has not installed a trusted digital currency application, send a download request for the trusted digital currency application to the digital currency backend system 108, then receive the installation file of the trusted digital currency application sent by the digital currency backend system 108 through a secure channel, and install it into the second execution environment. The backend system 108 has a digital currency acquiring card application for a secure element or a digital currency acquiring TA application for a TEE environment. Based on the information in the download request, the backend system 108 sends the corresponding version of the installation file to the mobile device 104. The download request includes instructions to download, install, or personalize the SE acquiring card application or the TA file sent to the backend system 108.

[0058] In one example, if the cryptocurrency acquiring application 1041 detects that the current mobile device includes both a secure element and a TEE (Transaction Execution Environment), considering that the secure element is an independent hardware component that provides hardware-level security isolation, physically isolating sensitive data and more effectively reducing security risks compared to a TEE environment, the secure element is preferentially selected as the secondary execution environment for executing cryptocurrency transactions. Therefore, the download request sent by the cryptocurrency acquiring application 1041 to the backend system 108 will also indicate the intention to install the acquiring card application corresponding to the secure element.

[0059] After the initial installation of the trusted digital currency application into the secure element, the digital currency acquiring application 1041 and the trusted digital currency application are still unable to cooperate in executing digital currency acquiring transactions. It is necessary to apply for the core key data used in the transaction process to protect the confidentiality and integrity of the transmitted data.

[0060] Based on the above, for example, in some embodiments of this disclosure, the digital currency acquiring application 1041 is further configured to send a key request to the digital currency back-end system 108, and receive core key data randomly generated and sent in response to the key request from the digital currency back-end system 108 through a secure channel between the digital currency back-end system 108 and the mobile device 104; the digital currency acquiring card application 1043 is further configured to receive the core key data transmitted by the digital currency acquiring application 1041 and store it in a second execution environment. The key request is used to request the download of encryption keys and integrity protection keys. After receiving the core key data, the digital currency acquiring card application 1043 stores it in a data storage area, such as that of a secure element 104A.

[0061] The communication module 1045 primarily communicates with the payment device 102 and the digital currency back-end system 108. The communication methods it follows can include Bluetooth, NFC, Wi-Fi, UWB, and mobile networks. In some examples, the communication module 1045 establishes a secure channel with the communication module 108D of the digital currency back-end system 108. Through this secure channel, it receives key factors, challenge factors, event factors, and computation factors sent by the back-end system 108 for generating offline payment codes, as well as core key data that protects the confidentiality and integrity of transmitted information during the digital currency acquiring process.

[0062] It should be noted that a "secure channel" can be a network channel between two entities (such as a backend and a mobile communication terminal). It allows the two entities to communicate with each other securely without being eavesdropped on by a third entity or impersonated by a third entity as one of the two intended entities participating in the secure communication. Establishing a secure channel enables the secure transmission of sensitive information between two entities.

[0063] In some examples, the "secure channel" between the digital currency back-end system 108 and the mobile device 104 (communication module 1045) performs integrity protection processing on the sensitive information to be transmitted. For example, both the digital currency back-end system 108 and the mobile device 104 store the keys for encrypting and decrypting the transmitted sensitive information and use the same encryption algorithm to encrypt it, preventing it from being stolen by third parties.

[0064] For example, messages between the receiving terminal 104 and the backend system 108 can be sent over a communication network using a secure communication protocol, such as, but not limited to, File Transfer Protocol (FTP), Hypertext Transfer Protocol (HTTP), and Secure Hypertext Transfer Protocol (HTTPS). The communication network can include any one and / or a combination of the following: direct interconnection, the Internet, a local area network (LAN), a metropolitan area network (MAN), a secure custom connection, a wide area network (WAN), a wireless network, etc.

[0065] Considering that mobile devices may also have a second execution environment that does not include, for example, an SE or TEE, other embodiments of this disclosure also provide another mobile device for digital currency transactions.

[0066] Figure 2B shows a block diagram of another exemplary mobile device (acceptance terminal) according to an embodiment of the present disclosure. The mobile device 104 includes a digital currency acquiring application 1041 running in REE, a memory 1047 having a key storage area 1048, and a communication module 1045.

[0067] In this diagram, the mobile device 104 does not have a SE or TEE environment that is securely isolated from, for example, the REE. However, the key storage area 1048 can be a secure area with a certain level of security, separately partitioned from the memory 1047, making this secure area logically isolated from other areas. It is mainly used to store core key data. For example, this secure area has encryption functions to encrypt sensitive data, so even if a third party obtains its contents, they will not be able to decrypt the ciphertext of the sensitive data.

[0068] For example, in at least one embodiment of this disclosure, the digital currency acquiring application 1041 is configured to perform the following operations when it detects that the mobile device 104 does not have a second execution environment: each time a digital currency acquiring transaction is initiated, a key application request is sent to the backend system 108, and core key data is received through a secure channel between the backend system 108 and the mobile device 104; the core key data is used to perform encryption and integrity processing on the digital currency transaction information, and the processed digital currency transaction information is sent to the backend system 108 so that the backend system 108 can verify and decrypt the processed digital currency transaction information to execute the digital currency acquiring transaction.

[0069] In one example, the digital currency acquiring application 1041 can combine payment information or offline payment code information obtained from the payment side with locally obtained device information, merchant information, and order information to form digital currency transaction information. It then uses a preset key algorithm (e.g., a symmetric key algorithm) to encrypt the digital currency transaction information using an encryption key to obtain ciphertext. Next, it uses a digest algorithm and an integrity key (e.g., a MAC key) to perform integrity calculations on the ciphertext to obtain a digest value (e.g., a MAC value). Finally, it sends the ciphertext and digest value as the processed digital currency transaction information to the backend system 108 for further processing. Digest algorithms include various existing algorithms, such as the MAC algorithm and the SM3 algorithm.

[0070] Since the mobile device 104 requests core key data from the backend system 108 before each digital currency acquiring transaction, it does not need to automatically update the core key data as shown in Figure 2A, and an expiration date is not required. Furthermore, considering that business-related data such as communication certificates and other keys required for business and other communications also need to be valid, the digital currency acquiring application 1041 is also configured to send a synchronization instruction to the digital currency backend system 108 to synchronize business-related data in response to a data update synchronization request, receive new business-related data sent by the digital currency backend system 108, and replace the business-related data already stored in the first execution environment.

[0071] Furthermore, in one example, the digital currency acquiring application 1041 can send different key request requests to the backend system 108 for cases with and without a SE, requesting core key data with and without an expiration date. For example, the key request request may include an identifier.

[0072] In this embodiment, the digital currency back-end system 108 is a back-end system supporting digital currency transaction functions. It may include a payment and receipt operation institution's back-end server and an interconnection platform, supporting digital currency transactions within the institution and across institutions. The digital currency back-end system 108 may be conventional in terms of hardware, but it may be controlled by software to cause it to perform the operations described below. For example, the digital currency back-end system 108 may be composed of server computer hardware, the specifics of which will not be elaborated further.

[0073] In most cases, the digital currency back-end system 108 may include a receiving institution back-end and a paying institution back-end. Both can process digital currency transactions within their respective institutions and generate transaction execution result information after the mobile communication terminal 104 is connected to the network, returning it to the mobile device 104 for user confirmation. To facilitate information exchange among multiple operating institutions, in this embodiment of the disclosure, the digital currency back-end system 108 also includes an interconnection system or server that communicates with the systems or servers corresponding to each operating institution.

[0074] For example, in this embodiment of the disclosure, when conducting a digital currency transaction based on the payer's institution identifier, the payee's institution identifier, and the transaction amount in the transaction information (payment information), if the operating institutions corresponding to the payer's institution identifier and the payee's institution identifier belong to the same operating institution, a transaction within this institution is conducted; if the operating institutions corresponding to the payer's institution identifier and the payee's institution identifier do not belong to the same operating institution, a transaction request is sent through the interconnection platform to conduct a cross-institutional transaction.

[0075] Figure 3 shows a block diagram of an exemplary digital currency back-end system according to an embodiment of the present disclosure. Since the digital currency back-end system is either an acquiring institution back-end or a payment institution back-end, the functional modules comprising the digital currency back-end system will be described below with reference to Figure 3.

[0076] As shown in Figure 3, the digital currency back-end system 108 includes a key generation module 108A, a business management module 108C, and a communication module 108D.

[0077] The key generation module 108A is configured to randomly generate core key data and stores it in association with user data (such as account information of a digital currency wallet ID) corresponding to the mobile device 104. The core key data has an expiration date. In one example, the key generation module 108A can use a suitable random number generator and algorithm to generate a key of a set key length. The calculated key is used as the encryption key for encrypting digital currency transaction information during digital currency transactions, or as the integrity key for integrity calculations, thereby ensuring the confidentiality and integrity of data transmission. After generating the core key data, the key generation module 108A stores the user wallet ID and the core key data accordingly.

[0078] The communication module 108D is configured to establish a secure channel between itself and the mobile device 104. For details regarding the "secure channel," please refer to the preceding content; it will not be repeated here.

[0079] The business management module 108C is configured to respond to a key request sent by the mobile device 104, control the key generation module 108A to randomly generate core key data, and send the core key data to the mobile device 104 through a secure channel; and, based on the core key data stored in association with the user data corresponding to the mobile device, verify and decrypt the processed digital currency transaction information sent by the mobile device 104 to execute digital currency acquiring transactions.

[0080] For example, in at least one embodiment of this disclosure, the business management module 108C uses the same verification algorithm as the mobile device 104, such as MAC value calculation. It calculates the MAC value of the information other than the MAC value in the processed digital currency transaction information sent by the mobile device 104, and then compares the calculated MAC value with the MAC value in the processed transaction information. If they match, the verification passes. Then, it queries the corresponding core key data based on the user data to decrypt the encrypted information and obtain the transaction information, such as digital currency payment information (or payment code information), device information, merchant information, and order information. Based on this information, it performs subsequent acquiring processing and applies for deduction from the digital currency account.

[0081] For example, if the transaction information also includes the code information of an offline payment code, in at least one embodiment of this disclosure, the business management module 108C is further configured to verify the code information of the offline payment code through the following steps: parsing the code information of the offline payment code to determine the user index and verification code; calculating a digest value by combining the verification code with local operation factors, and calculating an event factor by combining the digest value with the user index; querying the corresponding user data according to the event factor, and determining the key factor and challenge factor corresponding to the user data using the mapping relationship; encrypting the challenge factor, time factor, and event factor using the key factor to obtain the verification code; comparing the calculated verification code with the verification code in the offline payment code, and performing digital currency transaction processing after the comparison is successful. Afterwards, a successful transaction result is returned to the acceptance terminal 104.

[0082] It is easy to understand that if the mobile device 104 and the payment device 102 obtain transaction information through NFC communication, and the code information of the offline payment code mentioned above is not included, then the back-end system 108 only needs to perform MAC verification and decryption operations on the transaction information containing APDU instructions, and execute the digital currency acquiring transaction according to the decrypted transaction information, and apply for deduction from the corresponding digital currency account.

[0083] For example, in at least one embodiment of this disclosure, the business management module 108C, in response to an update instruction sent by the mobile device 104 to update the core key data, sends the updated core key data to the mobile device 104 through a secure channel to replace the core key data already stored in the mobile device 104; and in response to a synchronization instruction sent by the mobile device 104 to synchronize business-related data, sends the synchronized business-related data to the mobile device 104 through a secure channel to replace the business-related data already stored in the mobile device 104. As mentioned above, the core key data has an expiration date, and the mobile device 104 needs to update the core key data at a set time to prevent transaction failure due to key expiration. After receiving the key update instruction sent by the mobile device 104, the backend 108 controls the key generation module 108A to regenerate new core key data, stores the new core key data and the corresponding user data locally, and simultaneously sends the new core key data to the mobile device 104.

[0084] For example, in at least one embodiment of this disclosure, the business management module 108C is configured to send the installation file of the digital currency trusted application to the mobile device 104 via a secure channel in response to a download request for the digital currency trusted application sent by the mobile device 104. After the digital currency acquiring application is installed on the mobile device 104, if it is detected that the current secure element or TEE does not have the digital currency trusted application (e.g., acquiring card application or TA application) installed, a download request needs to be sent to the backend system 108. The backend system 108 sends the corresponding installation file to the corresponding mobile device 104 based on the information in the download request to complete the installation of the digital currency card application or TA application.

[0085] For example, in at least one embodiment of this disclosure, the business management module 108C is further configured to determine whether the current digital currency transaction is a password-free transaction or a small-amount transaction based on the digital currency transaction data. Specifically, the business management module 108C can determine whether the payment terminal wallet defaults to password-free transactions or small-amount transactions (or limit transactions) based on the wallet identifier of the payment terminal in the digital currency transaction data. If it does, the corresponding transaction processing is executed; otherwise, the transaction execution result is returned to the receiving terminal 104 as failed. This allows for transaction risk control.

[0086] Figure 4A shows a flowchart of a key data management method based on a mobile device according to an embodiment of the present disclosure. The various steps of an application in a mobile device performing this method will now be described with reference to Figure 4A.

[0087] First, in step S400, the digital currency acquiring application 1041 detects whether the current mobile device has a second execution environment, such as TEE / SE, and whether a trusted digital currency application is installed in the second execution environment. If the detection shows that the second execution environment exists, the operation process of steps S402 and S404 is executed. If the detection shows that the second execution environment does not exist, the operation process of steps S4021 and S4023 is executed.

[0088] In step S402, the digital currency acquiring application 1041 sends a key application request to the digital currency back-end system 108, receives core key data through the secure channel between the digital currency back-end system 108 and the mobile device 104, and sends the core key data to the trusted digital currency application.

[0089] In step S404, the trusted digital currency application receives the core key data transmitted by the digital currency acquiring application 1041 and stores it in the second execution environment.

[0090] For example, in some embodiments of this disclosure, the method can also automatically update core key data and business-related data. In response to a data update synchronization command, the digital currency acquiring application 1041 sends an update command to update the core key data and a synchronization command to synchronize business-related data to the backend system 108, and receives new core key data and business-related data sent by the digital currency backend system 108 through a secure channel in response to the update and synchronization commands. The trusted digital currency application replaces the core key data and business-related data already stored in the second execution environment with the new core key data and business-related data transmitted by the digital currency acquiring application 1041.

[0091] In step S4021, when the digital currency acquiring application 1041 detects that the mobile device does not have a second execution environment, it sends a key application request to the digital currency back-end system every time it initiates a digital currency acquiring transaction, and receives core key data through the secure channel between the digital currency back-end system and the mobile device.

[0092] In step S4023, the digital currency acquiring application 1041 stores the core key data in the secure area of ​​the first execution environment.

[0093] For example, in some embodiments of this disclosure, the method can also automatically update business-related data. In response to a data update synchronization command, the digital currency acquiring application 1041 sends a synchronization command to the backend system 108 to synchronize business-related data, receives new business-related data from the backend system 108, and replaces the business-related data already stored in the first execution environment.

[0094] Figure 4B shows a schematic flowchart of a transaction method based on a digital currency hard wallet according to an embodiment of the present disclosure. The various steps of the method will now be described with reference to Figure 4B.

[0095] First, in step S400, the digital currency acquiring application 1041 detects whether the current mobile device has a second execution environment, such as TEE / SE, and whether a trusted digital currency application is installed in the second execution environment. If the detection shows that it exists, steps S401, S403 and S405 are executed; otherwise, steps S4011, S4013 and S405 are executed.

[0096] In step S401, when it is detected that the mobile device 104 has a second execution environment and a trusted digital currency application (e.g., acquiring card application 1043) is installed in the second execution environment, the digital currency acquiring application 1041 initiates a digital currency acquiring transaction to the payment terminal to obtain the digital currency payment information or offline payment code information returned by the payment terminal, and transmits it to the trusted digital currency application.

[0097] In step S403, the trusted digital currency application uses the core key data stored in the second execution environment (e.g., security element 104A) to perform encryption and integrity processing on the digital currency transaction information, and sends the processed digital currency transaction information to the digital currency back-end system 108 through the digital currency acquiring application 1041.

[0098] In step S405, the digital currency back-end system 108 verifies and decrypts the processed digital currency transaction information to execute the digital currency acquiring transaction.

[0099] For example, in some embodiments of this disclosure, if it is detected that the mobile device 104 has a second execution environment but has not installed a trusted digital currency application, the digital currency acquiring application 1041 sends a download request for the trusted digital currency application to the digital currency back-end system 108, receives the installation file of the trusted digital currency application sent by the digital currency back-end system 108 through a secure channel, and installs it into the second execution environment.

[0100] For example, in some embodiments of this disclosure, the digital currency acquiring application 1041 also sends a key application request to the digital currency back-end system 108 and receives core key data sent by the digital currency back-end system 108 through a secure channel in response to the key application request; the digital currency trusted application receives the core key data transmitted by the digital currency acquiring application 1041 and stores it in the second execution environment.

[0101] In step S4011, each time a digital currency acquiring transaction is initiated, the digital currency acquiring application 1041 sends a key application request to the digital currency back-end system and receives core key data through a secure channel between the digital currency back-end system and the mobile device.

[0102] In step S4013, the digital currency acquiring application 1041 uses the core key data to perform encryption and integrity processing on the digital currency transaction information, sends the processed digital currency transaction information to the digital currency back-end system, and then executes step S405.

[0103] In addition, when the mobile device does not have a second execution environment, the digital currency acquiring application 1041 can apply for core key data from the digital currency back-end system and store it in the secure area of ​​the first execution environment. Then, the core key data in the secure area can be used to encrypt and perform integrity calculations on the transaction information.

[0104] The embodiments of the methods shown in Figures 4A and 4B are basically similar to the embodiments of the aforementioned mobile device-based digital currency trading system, so they will not be repeated here. For relevant details, please refer to the description in the system embodiment section.

[0105] Figure 5A illustrates a flowchart of an exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure. The method mainly describes how the digital currency acquiring APP 1041 in the mobile device and the digital currency trusted application 1043 in the secure element / TEE, such as the acquiring card application (SE card application) of the secure element or the acquiring card TA (TEE TA application) in the TEE, store core key data, how to use the core key data to conduct digital currency transactions, and how to update the core key data.

[0106] First, when a merchant wants to use a mobile device as a receiving terminal for digital currency transactions, they must first download the digital currency receiving app and install it on the mobile device 104. Then, they can register the merchant information and mobile device information through the receiving app and connect to the digital currency system.

[0107] Next, the digital currency acquiring app 1041 determines whether the mobile device 104 has SE or TEE capabilities. If it does, when the mobile device 104 activates its acquiring function, the digital currency acquiring app 1041 requests the backend system 108 to download the SE card application to the security element SE of the mobile device 104. If the mobile device has TEE capabilities, when it activates its acquiring function, the digital currency acquiring app requests the digital currency acquiring TA application to the TEE of the mobile device 104 from the digital currency backend system 108. When both SE and TEE capabilities are present, SE capability is prioritized.

[0108] After installing the SE card application or the TEE's TA application, the digital currency acquiring app 1041 requests the core key data of the mobile device from the digital currency backend system 108. The backend system 108 then sends the core key data to the digital currency acquiring app 1041 on the mobile device through a secure channel. The digital currency acquiring app 1041 then transmits the core key data to the SE card application or the TEE's TA application for storage in the SE or TEE. The digital currency backend system 108 randomly generates core key data each time it is requested, and the validity period does not exceed 24 hours. If SE or TEE capabilities are not available, the digital currency acquiring app 1041 stores the received core key data in a secure area of ​​the REE environment. Alternatively, the core key data can be retrieved as needed without prior storage.

[0109] In addition, mobile devices 104 with SE or TEE capabilities need to check in daily to update the core key data and other business-related data synchronization. The backend system 108 sends the updated core key data and business-related data to mobile device 104, and the SE card application or the TEE's TA application stores the new core key data and business-related data. For mobile devices without SE / TEE capabilities, they only need to check in daily to the backend system 108 to obtain the business-related data to be synchronized and store it in the first execution environment.

[0110] Next, when mobile device 104 initiates a digital currency acquiring transaction with the payment side, it receives NFC payment information or offline payment code information returned by the payment side. This information is then combined with locally acquired device information, merchant information, and order information to form transaction information. The SE card application or TEE's TA application uses the stored core key data to encrypt and ensure the integrity of the transaction information, and sends the processed transaction information to the digital currency backend system 108. The digital currency backend system 108 performs integrity verification; if the verification passes, the transaction information is decrypted, and the deduction process is completed. For mobile devices without SE / TEE capabilities, the digital currency acquiring app 1041 uses the core key data requested from the backend system 108 to encrypt and ensure the integrity of the transaction information.

[0111] Figure 5B illustrates a flowchart of another exemplary mobile device-based digital currency transaction method according to an embodiment of this disclosure. The method primarily describes how a digital currency acquiring app 1041 on a mobile device performs digital currency transactions using core key data dynamically retrieved from the background each time an acquiring transaction is executed.

[0112] First, during each acquiring transaction, the digital currency acquiring app 1041 determines whether the mobile device 104 has SE or TEE capabilities or a secure area for storing core key data under an REE environment. If it does, the digital currency acquiring app 1041 further determines whether the core key data has been stored in these areas. If not, it requests the core key data from the backend system 108.

[0113] Next, the digital currency acquiring app 1041 uses the dynamically retrieved core key data to encrypt and process the transaction information for integrity. The processed transaction information is then sent to the digital currency backend system 108. The digital currency backend system 108 performs integrity verification. If the verification passes, the transaction information is decrypted, and the deduction process is completed. The transaction information includes NFC payment information or offline payment code information returned by the payment side, as well as device information, merchant information, and order information.

[0114] It should be noted that the above application scenarios are merely exemplary in order to describe one or more aspects of this disclosure in specific scenarios. However, these aspects are not essential, and various modifications can be made to the application scenario. The embodiments of this disclosure are not limited.

[0115] It should be noted that the above application scenarios are merely exemplary in order to describe one or more aspects of this disclosure in specific scenarios. However, these aspects are not essential, and various modifications can be made to the application scenario. The embodiments of this disclosure are not limited.

[0116] At least some embodiments of this disclosure also provide an electronic device. FIG6 shows a schematic diagram of an electronic device 600 according to an embodiment of the present disclosure.

[0117] As shown in Figure 6, the electronic device 600 includes one or more processors 610 and a memory 620. The memory 620 includes one or more computer program modules 621. The one or more computer program modules 621 are stored in the memory 620 and configured to be executed by the processor 610. These computer program modules 621 include instructions for performing methods and additional aspects thereof according to at least one embodiment of the present disclosure. When executed by the processor 610, they can perform one or more steps of the methods and additional aspects thereof according to at least one embodiment of the present disclosure. The memory 620 and the processor 610 can be interconnected via a bus system and / or other forms of connection mechanisms (not shown). For example, the bus may be a Peripheral Component Interconnect Standard (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus may be divided into an address bus, a data bus, a control bus, etc.

[0118] For example, processor 610 may be a central processing unit (CPU), a digital signal processor (DSP), or other processing unit with data processing and / or program execution capabilities, such as a field-programmable gate array (FPGA). Processor 610 may be a general-purpose processor or a special-purpose processor, capable of controlling other components in electronic device 600 to perform desired functions.

[0119] Exemplarily, memory 620 may include any combination of one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, flash memory, etc. One or more computer program modules 621 may be stored on the computer-readable storage medium, and processor 610 may run one or more computer program modules 621 to implement various functions of electronic device 600. The computer program modules include multiple computer-executable instructions. Various application programs and various data, as well as various data used and / or generated by the application programs, may also be stored in the computer-readable storage medium.

[0120] For example, electronic device 600 may also include input devices such as touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, and gyroscopes; output devices such as liquid crystal displays, speakers, and vibrators; storage devices such as magnetic tapes and hard disks (HDDs or SDDs); and communication devices such as network interface cards like LAN cards and modems. The communication devices allow electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data and perform communication processing via networks such as the Internet. A drive is connected to the I / O interface as needed. Removable storage media, such as disks, optical disks, magneto-optical disks, and semiconductor memories, are installed on the drive as needed so that computer programs read from them can be installed into the storage device as required.

[0121] For example, the electronic device 600 may further include a peripheral interface (not shown in the figure). This peripheral interface can be various types of interfaces, such as a USB interface, a Lightning interface, etc. The communication device can communicate wirelessly with networks and other devices, such as the Internet, intranets and / or wireless networks such as cellular telephone networks, wireless local area networks (LANs) and / or metropolitan area networks (MANs). Wireless communication can use any of a variety of communication standards, protocols, and technologies, including but not limited to Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (e.g., based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.

[0122] The electronic device 600 may be, for example, a system-on-a-chip (SOC) or a device including the SOC. For instance, it can be any device such as a mobile phone, tablet computer, laptop computer, e-reader, game console, television, digital photo frame, navigator, home appliance, communication base station, industrial controller, server, etc., or any combination of data processing devices and hardware. The embodiments of this disclosure do not limit this. The specific functions and technical effects of the electronic device 600 can be found in the description above of the digital currency transaction method and its additional aspects according to at least one embodiment of this disclosure, and will not be repeated here.

[0123] Figure 7 shows a schematic diagram of a computer-readable medium 700 according to an embodiment of the present disclosure.

[0124] As shown in Figure 7, a computer-readable medium 700 stores computer instructions 710, which, when executed by a processor, perform one or more steps of the method and its additional aspects as described above.

[0125] For example, when the program code is read by a computer, the computer can execute the program code stored in the computer storage medium to perform one or more steps of the method and its additional aspects according to at least one embodiment of the present disclosure.

[0126] For example, the computer-readable medium may include a memory card of a smartphone, a storage component of a tablet computer, a hard disk of a personal computer, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), flash memory, and other computer-readable media or any combination thereof.

[0127] At least some of the embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other.

[0128] It should be noted that, in this document, relational terms such as "first," "second," etc., are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0129] The following points should be noted regarding this disclosure:

[0130] (1) The accompanying drawings of the embodiments of this disclosure only involve the structures mentioned in the embodiments of this disclosure. Other structures can be referred to the general design.

[0131] (2) Where there is no conflict, the embodiments of this disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.

[0132] The above description is merely an exemplary embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure, which is determined by the appended claims.

Claims

1. A mobile device for digital currency transaction, comprising: a digital currency acquirer application executable in a first execution environment, configured to send a key application request to a digital currency back-end system, receive core key data through a secure channel between the digital currency back-end system and the mobile device, and send the core key data to a digital currency trusted application installed in a second execution environment of the mobile device upon detecting that the mobile device is equipped with the second execution environment; and the digital currency trusted application executable in the second execution environment, configured to receive the core key data sent by the digital currency acquirer application, and store the core key data in the second execution environment, wherein the mobile device serves as a receiving terminal, the second execution environment is securely isolated from the first execution environment, the core key data is randomly generated by the digital currency back-end system in response to the key application request, and includes an encryption key and an integrity key with a valid period. 2.The mobile device of claim 1, wherein the digital currency acquirer application is further configured to send an update instruction to update the core key data and a synchronization instruction to synchronize business-related data to the digital currency back-end system in response to a data update synchronization instruction, and receive new core key data and business-related data sent by the digital currency back-end system through the secure channel; and the digital currency trusted application is further configured to replace the core key data and business-related data stored in the second execution environment with the new core key data and business-related data transmitted by the digital currency acquirer application. 3.The mobile device of claim 2, wherein the digital currency acquirer application is further configured to initiate a digital currency acquirer transaction to a payment terminal to obtain digital currency payment information or code information of an offline payment code, and transmit to the digital currency trusted application; and the digital currency trusted application is configured to perform encryption and integrity processing on digital currency transaction information using the core key data stored in the second execution environment, and send the processed digital currency transaction information to the digital currency back-end system through the digital currency acquirer application, so that the digital currency back-end system verifies and decrypts the processed digital currency transaction information to perform a digital currency acquirer transaction, wherein the digital currency transaction information includes the digital currency payment information or the code information of the offline payment code. 4.The mobile device of claim 1, wherein the digital currency acquirer application is further configured to send a download request for the digital currency trusted application to the digital currency back-end system upon detecting that the mobile device is equipped with the second execution environment but does not have the digital currency trusted application installed, receive an installation file of the digital currency trusted application sent by the digital currency back-end system through the secure channel, and install the digital currency trusted application to the second execution environment. ​ 5.The mobile device of any one of claims 1-4, wherein, the second execution environment is a trusted execution environment or a secure element. 6.A mobile device for digital currency transaction, the mobile device serving as a receiving terminal, comprising a digital currency acquirer application executable in a first execution environment; the digital currency acquirer application is configured to, in case that the mobile device is detected not to have a second execution environment, perform the following operations: sending a key application request to a digital currency background system each time a digital currency acquirer transaction is initiated, receiving core key data through a secure channel between the digital currency background system and the mobile device, and storing the core key data to a secure area of the first execution environment; wherein the second execution environment is securely isolated from the first execution environment, the core key data is randomly generated by the digital currency background system in response to the key application request, and comprises an encryption key and an integrity key. 7.The mobile device of claim 6, wherein, the digital currency acquirer application is further configured to, in response to a data update synchronization request, send a synchronization instruction of synchronizing business related data to the digital currency background system, receive new business related data sent by the digital currency background system, and replace the business related data stored in the first execution environment with the new business related data sent by the digital currency background system. 8.The mobile device of claim 6, wherein, the digital currency acquirer application is further configured to initiate a digital currency acquirer transaction to a payment end to obtain digital currency payment information or code information of an offline payment code, perform encryption and integrity processing of digital currency transaction information by using the core key data stored to the secure area, and send the processed digital currency transaction information to the digital currency background system through the digital currency acquirer application, so that the digital currency background system verifies and decrypts the processed digital currency transaction information to perform a digital currency acquirer transaction, wherein the digital currency transaction information comprises the digital currency payment information or the code information of the offline payment code. 9.A digital currency background system, comprising: a key generation module configured to randomly generate core key data, and store the core key data in association with user data corresponding to a mobile device, the core key data comprising an encryption key and an integrity key with a validity period; a communication module configured to establish a secure channel with the mobile device; and a business management module configured to, in response to a key application request sent by the mobile device, control the key generation module to randomly generate core key data, and send the core key data to the mobile device through the secure channel. 10.The digital currency background system of claim 9, wherein, ​ The service management module is configured to: in response to an update instruction for updating the core key data sent by the mobile device, send updated core key data to the mobile device through the secure channel to replace the core key data stored in the mobile device; and in response to a synchronization instruction for synchronizing service-related data sent by the mobile device, send synchronized service-related data to the mobile device through the secure channel to replace the service-related data stored in the mobile device.

11. The digital currency background system of claim 9, wherein, The service management module is configured to: in response to a download request for a digital currency trusted application sent by the mobile device, send an installation file of the digital currency trusted application to the mobile device through the secure channel.

12. The digital currency background system of claim 9, wherein, The service management module is further configured to: receive processed digital currency transaction information sent by the mobile device, and based on core key data associated with user data corresponding to the mobile device, verify and decrypt the digital currency transaction information to perform a digital currency acquirer transaction, wherein the digital currency transaction information includes digital currency payment information or code information of an offline payment code.

13. A digital currency transaction system, comprising: The mobile device of any one of claims 1-8, and The digital currency background system of any one of claims 9-12.

14. A mobile device based key management method, the mobile device serving as a point of acceptance terminal for a digital currency transaction, comprising a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, the second execution environment being securely isolated from the first execution environment, wherein, The method comprises: The digital currency acquirer application sends a key application request to a digital currency background system, and receives core key data through a secure channel between the digital currency background system and the mobile device, and in a case where the mobile device is detected to have a second execution environment and an executable digital currency trusted application is installed in the second execution environment, sends the core key data to the digital currency trusted application; and The digital currency trusted application receives the core key data transmitted by the digital currency acquirer application, and stores the core key data in the second execution environment, Wherein the core key data is randomly generated by the digital currency background system in response to the key application request, and includes an encryption key and an integrity key with a validity period.

15. The method of claim 14, wherein, The digital currency acquirer application sends an update instruction for updating the core key data and a synchronization instruction for synchronizing service-related data to the digital currency background system in response to a data update synchronization instruction, and receives new core key data and service-related data sent by the digital currency background system through the secure channel; And The digital currency trusted application replaces the core key data and the service-related data stored in the second execution environment with the new core key data and the service-related data transmitted by the digital currency acquirer application. 16.A method for key management based on a mobile device, the mobile device serving as a terminal for receiving a digital currency transaction, comprising a digital currency acquirer application executable in a first execution environment, the method comprising: in response to detecting that the mobile device does not have a second execution environment, the digital currency acquirer application performs the following operations: at each time a digital currency acquirer transaction is initiated, sending a key application request to a digital currency back-end system, receiving core key data through a secure channel between the digital currency back-end system and the mobile device, and storing the core key data in a secure area of the first execution environment, wherein the second execution environment is securely isolated from the first execution environment, the core key data is randomly generated by the digital currency back-end system in response to the key application request, and comprises an encryption key and an integrity key. 17.The method of claim 16, wherein in response to a data update synchronization instruction, the digital currency acquirer application sends a synchronization instruction to the digital currency back-end system to synchronize business-related data, receives new business-related data sent by the digital currency back-end system, and replaces the business-related data already stored in the first execution environment with the new business-related data sent by the digital currency back-end system. 18.An electronic device comprising: one or more processors; and a memory for storing one or more computer programs, when the one or more computer programs are executed, causing the one or more processors to implement the method of any one of claims 14-17.

19. A non-transitory computer-readable storage medium storing computer- executable instructions, wherein, the computer executable instructions, when executed by one or more processors, implement the method of any one of claims 14-17.

Citation Information

Patent Citations

  • Mobile intelligent terminal acquirer system and method suitable for bank cards and business cards

    CN103793815A

  • Intelligent POS terminal main key updating system and updating method

    CN104954123A

  • Systems and methods for end-to-end key management

    CN109564607B

  • Blockchain application security credit granting and signing system based on terminal equipment

    CN111181960A

  • Digital currency double-offline transaction method based on security unit and trusted execution environment

    CN114841684A