Digital currency transaction method and system, device, apparatus, and storage medium

By setting up a secure and isolated execution environment and core key data processing in mobile devices, the information security problem in digital currency transactions where mobile devices are used as acceptance terminals is solved, and the secure transmission and verification of transaction information is realized, ensuring the reliability and integrity of transactions.

WO2026026626A1PCT designated stage Publication Date: 2026-02-05THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/110051
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2025-07-23
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing technologies lack effective solutions for using mobile devices as acceptance terminals for digital currency transactions, and there is a lack of security guarantees for transaction information.

Method used

The system employs a first and second execution environment set up in the mobile device. The first execution environment is a conventional environment, and the second execution environment is a trusted execution environment or a secure element. The digital currency acquiring application and the trusted application run in their respective environments. The transaction information is encrypted and integrity-processed using core key data and transmitted to the digital currency back-end system for verification and decryption through a secure channel.

Benefits of technology

It ensures the security and integrity of transaction information during digital currency transactions using mobile devices as acceptance terminals, prevents sensitive data from being stolen by malicious software, and provides more reliable transaction execution protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025110051_05022026_PF_FP_ABST
    Figure CN2025110051_05022026_PF_FP_ABST
Patent Text Reader

Abstract

A mobile device for a digital currency transaction, a digital currency transaction method and system, an electronic apparatus, and a storage medium. The mobile device, as an acceptance terminal, comprises: a digital currency acquiring application executable in a first execution environment and a digital currency trusted application executable in a second execution environment. The digital currency acquiring application is configured to initiate a digital currency acquiring transaction to a payment terminal to obtain digital currency payment information or code information of an offline payment code returned by the payment terminal. The digital currency trusted application is configured to execute encryption and integrity processing of digital currency transaction information by using core key data stored in the second execution environment, and to send the processed digital currency transaction information to a digital currency backend system, such that the digital currency backend system executes the digital currency acquiring transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Digital currency transaction method, device, apparatus, system and storage medium

[0001] The present application claims priority to the Chinese patent application No. 202411047969.4, filed on July 31, 2024, and entitled "Mobile device for digital currency transaction and digital currency transaction method", the whole content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present disclosure relates to the technical field of digital currency, and in particular to a mobile device for digital currency transaction, a digital currency transaction method and system, an electronic device and a storage medium. BACKGROUND

[0003] In recent years, with the widespread use and rapid growth of mobile devices, mobile devices (such as mobile phones) can also be used as receiving terminals (such as Point of sales terminal, POS) to provide convenient collection services for merchants. However, there is no effective implementation scheme for the new scene application of using mobile phones as receiving terminals for digital currency collection transactions. SUMMARY

[0004] Therefore, the present disclosure provides a mobile device for digital currency transaction, a digital currency transaction method and system, an electronic device and a storage medium to realize an effective digital currency transaction mode when the mobile device is used as a receiving terminal, and ensure the security of the digital currency transaction information transmitted to the digital currency background system.

[0005] In a first aspect, at least one embodiment of the present disclosure provides a mobile device for digital currency transaction, the mobile device being used as a receiving terminal, comprising: a digital currency collection application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, the second execution environment being securely isolated from the first execution environment; the digital currency collection application is configured to initiate a digital currency collection transaction to a payment end to obtain digital currency payment information or code information of an offline payment code returned by the payment end, and transmit the digital currency payment information or the code information of the offline payment code to the digital currency trusted application; the digital currency trusted application is configured to perform encryption and integrity processing on digital currency transaction information by using core key data stored in the second execution environment, and send the processed digital currency transaction information to a digital currency background system through the digital currency collection application, so that the digital currency background system verifies and decrypts the processed digital currency transaction information to perform the digital currency collection transaction; wherein the digital currency transaction information comprises the digital currency payment information or the code information of the offline payment code; the core key data comprises an encryption key and an integrity key with a validity period.

[0006] In a second aspect, at least one embodiment of the present disclosure provides a mobile device for digital currency transaction, the mobile device serving as a receiving terminal, comprising a digital currency acquirer application executable in a first execution environment; the digital currency acquirer application is configured to perform the following operations: sending a key application request to a digital currency background system at each time of initiating a digital currency acquirer transaction, and receiving core key data through a secure channel between the digital currency background system and the mobile device, wherein the core key data comprises an encryption key and an integrity key; performing encryption and integrity processing of digital currency transaction information by using the core key data, and sending the processed digital currency transaction information to the digital currency background system, so that the digital currency background system verifies and decrypts the processed digital currency transaction information to perform the digital currency acquirer transaction; wherein the digital currency transaction information comprises digital currency payment information returned by a payment terminal or code information of an offline payment code.

[0007] In a third aspect, at least one embodiment of the present disclosure provides a digital currency background system, comprising: a key generation module configured to randomly generate core key data, and store the core key data in association with user data corresponding to the mobile device, wherein the core key data comprises an encryption key and an integrity key; a communication module configured to establish a secure channel with the mobile device; and a business management module configured to verify and decrypt processed digital currency transaction information sent by the mobile device based on the core key data stored in association with the user data corresponding to the mobile device, to perform a digital currency acquirer transaction.

[0008] In a fourth aspect, at least one embodiment of the present disclosure provides a digital currency transaction system, comprising: a mobile device according to at least one embodiment of the present disclosure, and a digital currency background system according to at least one embodiment of the present disclosure.

[0009] In a fifth aspect, at least one embodiment of the present disclosure provides a mobile device-based digital currency transaction method, the mobile device serving as a receiving terminal, including a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, the second execution environment being securely isolated from the first execution environment, the method comprising: the digital currency acquirer application initiating a digital currency acquirer transaction with a payment terminal to obtain digital currency payment information returned by the payment terminal or code information of an offline payment code, and transmitting the digital currency payment information or the code information of the offline payment code to the digital currency trusted application; the digital currency trusted application performing encryption and integrity processing on digital currency transaction information using core key data stored in the second execution environment, and sending the processed digital currency transaction information to a digital currency back-end system through the digital currency acquirer application, so that the digital currency back-end system verifies and decrypts the processed digital currency transaction information to perform the digital currency acquirer transaction; wherein the digital currency transaction information includes the digital currency payment information or the code information of the offline payment code; and the core key data includes an encryption key and an integrity key with a validity period.

[0010] In a sixth aspect, at least one embodiment of the present disclosure provides a mobile device-based digital currency transaction method, the mobile device serving as a receiving terminal, including a digital currency acquirer application executable in a first execution environment; the digital currency acquirer application performing the following operations: at each time of initiating a digital currency acquirer transaction, sending a key application request to a digital currency back-end system, and receiving core key data through a secure channel between the digital currency back-end system and the mobile device, wherein the core key data includes an encryption key and an integrity key; performing encryption and integrity processing on digital currency transaction information using the core key data, and sending the processed digital currency transaction information to the digital currency back-end system, so that the digital currency back-end system verifies and decrypts the processed digital currency transaction information to perform the digital currency acquirer transaction; wherein the digital currency transaction information includes digital currency payment information returned by a payment terminal or code information of an offline payment code.

[0011] In a seventh aspect, at least one embodiment of the present disclosure provides an electronic device, including: one or more processors; a memory storing one or more computer programs; wherein when the one or more computer programs are executed, the one or more processors implement the digital currency transaction method provided by at least one embodiment of the present disclosure.

[0012] In an eighth aspect, at least one embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer-executable instructions, wherein when the computer-executable instructions are executed by one or more processors, the digital currency transaction method provided by at least one embodiment of the present disclosure is implemented.

[0013] The mobile device-based digital currency transaction solution of the embodiments of the present disclosure proposes an effective digital currency transaction method in the scenario that the mobile device is used as a receiving terminal, and ensures the security of the digital currency transaction information transmitted to the digital currency background system. BRIEF DESCRIPTION OF DRAWINGS

[0014] In order to more clearly illustrate the technical solutions of the prior art and the embodiments of the present disclosure, the drawings needed to be used in the description of the prior art and the embodiments of the present disclosure will be briefly introduced below. Of course, the following description of the drawings of the embodiments of the present disclosure is only a part of the embodiments of the present disclosure, and those skilled in the art can obtain other drawings according to the provided drawings without creative labor, and the obtained drawings also belong to the protection scope of the present disclosure. Obviously, the drawings described below only relate to some embodiments of the present disclosure, not limit the present disclosure.

[0015] FIG. 1 shows a block diagram of a digital currency transaction system according to an embodiment of the present disclosure;

[0016] FIG. 2A shows a block diagram of an exemplary mobile device (receiving terminal) according to an embodiment of the present disclosure;

[0017] FIG. 2B shows a block diagram of another exemplary mobile device (receiving terminal) according to an embodiment of the present disclosure;

[0018] FIG. 3 shows a block diagram of an exemplary digital currency background system according to an embodiment of the present disclosure;

[0019] FIG. 4A shows a flowchart of a mobile device-based key data management method according to an embodiment of the present disclosure;

[0020] FIG. 4B shows a flowchart of a mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0021] FIG. 5A shows a flowchart of an exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0022] FIG. 5B shows a flowchart of another exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure;

[0023] FIG. 6 shows a schematic diagram of an electronic device according to an embodiment of the present disclosure;

[0024] FIG. 7 shows a schematic diagram of a non-transitory computer-readable storage medium according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0025] In order to make the objects, technical solutions and advantages of the embodiments of the present disclosure clearer, the following will be used in conjunction with the accompanying drawings of the embodiments of the present disclosure to clearly and completely describe the technical solutions of the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure. Based on the described embodiments of the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative effort belong to the scope of protection of the present disclosure.

[0026] Unless otherwise defined, technical terms or scientific terms used herein should be understood as having the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. Unless otherwise defined, the terms "first", "second" and similar terms used in the present disclosure do not denote any order, quantity or importance, but are used to distinguish different components. Similarly, the terms "include" or "contain" and the like mean that the elements or objects before the terms encompass the elements or objects listed after the terms and their equivalents, and do not exclude other elements or objects. The terms "connected" or "connected" and the like are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to represent relative positional relationships, and when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0027] Note that the examples to be introduced next are only specific examples and are not as a limitation on the embodiments of the present disclosure, which must be specific shapes, hardware, connection relationships, operations, values, conditions, data, sequences, etc. shown and described. Those skilled in the art can use the concept of the present disclosure to construct more embodiments not mentioned in the present specification by reading the present specification.

[0028] The terms used in the present disclosure are those general terms currently widely used in the art in consideration of the functions related to the present disclosure, but these terms can vary according to the intent of a person of ordinary skill in the art, precedents, or new technology in the art. In addition, specific terms can be selected by the applicant, and in this case, the detailed meaning thereof will be described in the detailed description of the present disclosure. Therefore, the terms used in the specification should not be understood as simple names, but based on the meaning of the terms and the overall description of the present disclosure.

[0029] Flowcharts are used in the present disclosure to illustrate the operations performed by the system according to the embodiments of the present disclosure. It should be understood that the preceding or following operations are not necessarily performed in sequence. On the contrary, various steps can be processed in reverse order or simultaneously as needed. Meanwhile, other operations can be added to these processes, or one or more steps of operations can be removed from these processes.

[0030] First, the abbreviations and related terms involved in the present disclosure are defined and explained.

[0031] Mobile device: The field of application of mobile devices is very broad and mainly includes devices related to communication technology. Specifically, it includes any electronic device that a user can conveniently carry or operate, which can also provide remote communication capabilities with a network. A mobile communication terminal can communicate using a mobile phone (wireless) network, a wireless data network (e.g., 3G, 4G, 5G or similar networks), Wi-Fi, Bluetooth, Bluetooth Low Energy (BLE), Wi-Max, or any other communication medium that can provide access to a network such as the Internet or a private network. Examples of mobile communication terminals include mobile phones (also known as cell phone terminals), tablet computers, netbooks, laptop computers, wearable devices (e.g., smartwatches), etc. A mobile communication terminal can include any suitable hardware and software for performing such functions, and can also include multiple devices or components.

[0032] Secure Element (SE): Can include an on-chip computer or microprocessor. The secure element can perform cryptographic operations and can be embedded in a package with one or more physical security measures. In some embodiments, the secure element can include a component that can securely perform functions. The secure element can be a memory that securely stores data, such that its access is protected. An example of a secure element is a Universal Integrated Circuit Card (UICC) or a hardware security module (HSM), which is a physical computing device that can protect and manage cryptographic keys for authentication and provide cryptographic processing functions.

[0033] Trusted Execution Environment (TEE): Can include a secure area for processing data. The trusted execution environment can be a software stack stored on read-only memory (ROM). The trusted execution environment software stack can include one or more trusted applications (TAs) that implement the functionality of a particular application within a trusted application environment.

[0034] Digital currency acquirer application (referred to as acquirer App): used to initiate a collection request, obtain payment information from the payer side through NFC or scan the offline payment code to obtain the code information of the offline payment code, and prompt the collection result. It is also used to manage the SE card application or TEE TA application for collection and its related core key data, and is responsible for daily check-in to update the key.

[0035] Digital currency acquirer card application (referred to as acquirer card application): installed in the SE, associated with the acquirer App for use, mainly used for the application of storing core key data.

[0036] It should be noted that in the technical solutions of the present disclosure, the collection, collection, updating, analysis, processing, use, transmission, storage, etc. of user personal information involved in the technical solutions comply with relevant laws and regulations, are used for legal purposes, and do not violate public order and good customs. Necessary measures are taken for user personal information to prevent illegal access to user personal information data, and to maintain user personal information security, network security and national security.

[0037] At present, the receiving terminal generally uses a POS machine to perform the collection service. With the rapid development of mobile devices (such as mobile phones), it is increasingly becoming a demand to use mobile devices as receiving terminals, which provides a new application scenario. However, the related art does not provide an effective solution to this new scenario.

[0038] To solve the above problems, the embodiments of the present disclosure provide a relatively effective scheme for using a mobile device as a receiving terminal to perform a digital currency collection transaction. Moreover, the scheme realizes data security protection when the mobile device transmits digital currency transaction information. Further, by securely storing and automatically updating the key that guarantees the security of the digital currency transaction information, the scheme further provides better support for digital currency collection transactions.

[0039] The embodiments of the present disclosure and some examples thereof will be described in detail below with reference to the accompanying drawings.

[0040] FIG. 1 shows a block diagram of a digital currency transaction system 100 based on a mobile device according to an embodiment of the present disclosure. As shown in FIG. 1, the transaction system 100 mainly includes a payment device (payment end) 102, a mobile device 104 as a receiving terminal, and a digital currency background system (which can be referred to as a "background system" for short) 108.

[0041] For example, the payment device 102 may, for example, be a hard wallet or a mobile device (such as a mobile phone) with payment function, and can communicate with the receiving terminal 104 through a non-contact mode (NFC payment mode) to complete digital currency payment, or can complete payment by displaying an offline payment code (scan code payment mode) for the receiving terminal 104 to scan the code. The payment device 102 can transmit digital currency payment information in the Application Protocol Data Unit (APDU) format through NFC near field communication according to user selection, or can transmit digital currency payment information including offline payment code information through a scan code mode.

[0042] For example, in some embodiments of the present disclosure, the payment device 102 is capable of calculating an offline payment code to be displayed for generating a payment code in a scan code payment mode according to a key factor, a challenge factor, an event factor, an operation factor and a current time factor (a reference time of the hard wallet or a current time of the mobile phone). The challenge factor can be a random number, the event factor can be wallet account information, and the operation factor is set for different operation agencies (digital currency background system). For example, the offline payment code can include any image or symbol generated in an offline scenario that can be read by an electronic device for the mobile device 104 to parse and manipulate. Some examples include bar codes, quick response (QR) codes, military specification UID codes, and any other suitable codes. In one example, the code information of the offline payment code can include a string composed of a check code and a user index, which is used to display a scan code to a receiving terminal when a user makes a digital currency payment. Moreover, the offline payment code is preferably a dynamic offline QR code or bar code, which can be dynamically updated according to a set time during the transaction to protect the safety of the funds. When transmitted to the background system 108, the code information of the offline payment code can be part or all of the payment information, which is used to implement the security check of the payment information by the background system 108.

[0043] For example, in some embodiments of the present disclosure, the payment device 102 is configured to generate an offline payment code by performing the following operations: encrypting the challenge factor, the time factor and the event factor using the key factor to obtain a check code; calculating the check code and the operation factor to obtain a digest value, and calculating the digest value and the event factor to obtain a user index; and obtaining a string of the offline payment code based on the user index and the check code as code information of the offline payment code. For example, a symmetric encryption algorithm can be used to encrypt the check code, and a digest algorithm can be used to calculate the digest value. The digest algorithm includes various existing algorithms, such as the MAC algorithm and the SM3 algorithm.

[0044] For example, in some embodiments of the present disclosure, the mobile device 104 provides a first execution environment and a second execution environment that is securely isolated from the first execution environment. The first execution environment runs a main operating system, and the first execution environment is an environment for running regular applications on the mobile device 104, such as a rich execution environment (REE). The second execution environment is securely isolated from the first execution environment, and data exchange between the two environments is limited. The second execution environment can be, for example, a trusted execution environment (TEE) or a secure element (SE). Sensitive data such as keys can be securely stored in the second execution environment without the risk of being leaked to the first execution environment, and even if the mobile device 104 is infected with malicious software, third parties cannot steal data stored in the second execution environment.

[0045] In one example, the first execution environment has an executable digital currency acquirer application (a kind of client application), and the second execution environment has an executable digital currency trusted application (executes specific acquirer functions, used in pairs with the digital currency acquirer application, for example, can be a digital currency acquirer card application in the SE or a digital currency acquirer TA application in the TEE). Specifically, in the mobile device 104, the data processing related to the digital currency acquirer transaction is mainly the digital currency acquirer application running in the REE and the digital currency trusted application running in the second execution environment. The digital currency acquirer application can interact with the digital currency trusted application through the operating system in the second execution environment (such as the trusted operating system TOS or the chip operating system COS), thereby providing user-oriented functions. This mode separates the critical security operations (executed in the digital currency trusted application) from the user interface (provided in the digital currency acquirer application), which can ensure the security and integrity of the data.

[0046] For example, the digital currency acquirer application displays the user interface during the digital currency acquirer transaction through the display screen of the mobile device 104, which mainly displays the guidance of the acquirer operation on the user interface and performs the corresponding operation according to the user's trigger to complete the digital currency acquirer transaction. Moreover, when the mobile device 104 is connected to the digital currency system, the user can also complete the registration of the merchant information and the mobile device information through the user registration interface presented by the digital currency acquirer application, so as to enable the merchant holding the mobile device 104 to have the right to perform the digital currency acquirer.

[0047] For example, in some embodiments of the present disclosure, if the second execution environment is a secure element, the digital currency trusted application is a digital currency acquirer card application, which is managed by the acquirer App and is mainly used for storing related core key data and performing encryption and integrity processing on transaction information, and its running relies on the chip operating system COS in the secure element. Unlike the digital currency acquirer application, the digital currency acquirer card application generally does not have a user interface for users; if the second execution environment is a trusted execution environment TEE, the digital currency trusted application is a digital currency acquirer TA application, which can perform operations similar to those executable by the digital currency acquirer card application. In the following specific description, the embodiments of the present disclosure will take the secure element as the second execution environment and the digital currency acquirer card application running in the secure element as an example to illustrate the method flow involved.

[0048] FIG. 2A shows a block diagram of an exemplary mobile device 104 according to an embodiment of the present disclosure. As shown in FIG. 2A, the mobile device 104 includes a digital currency acquirer application 1041 running in the REE, a secure element 104A (an example of the second executable environment) having a data storage area (not shown) and a digital currency acquirer card application 1043, and a communication module 1045.

[0049] For example, in some embodiments of the present disclosure, the digital currency acquirer application 1041 is configured to initiate a digital currency acquirer transaction to the payment end (the payment device 102 shown in FIG. 1) to obtain digital currency payment information or code information of an offline payment code returned by the payment end, in the case that the mobile device 104 is detected to have a second execution environment (such as the SE 104A in this example), and a digital currency trusted application (such as the acquirer card application 1043 in this example) is installed in the SE 104A. For example, the digital currency acquirer application 1041 displays pre-acquired amount information in a user interface, and after receiving a triggering operation of the user, obtains digital currency payment information in APDU instruction format through NFC communication with the payment device 102 in a non-interactive consumption manner, i.e., a “tap and go” manner, or opens a sensor (such as a camera and / or a visual sensor) of the mobile device 104 to scan an offline payment code shown by reference numeral 102A in FIG. 1 to obtain code information of the offline payment code. The specific obtaining manner is not limited in the present disclosure.

[0050] For example, in some embodiments of the present disclosure, the digital currency acquirer card application 1043 is configured to perform encryption and integrity processing on digital currency transaction information by using core key data stored in a data storage area of a second execution environment, such as the secure element 104A, and send the processed digital currency transaction information to the digital currency back-end system 108 through the digital currency acquirer application 1041, so that the digital currency back-end system 108 verifies and decrypts the processed digital currency transaction information to perform a digital currency acquirer transaction. The core key data is a key received from the digital currency back-end system 108 and stored in the second execution environment through a secure channel between the digital currency back-end system 108 and the mobile device 104 in advance, and the core key data includes an encryption key and an integrity key with a validity period.

[0051] In this example, the digital currency transaction information at least includes digital currency payment information or code information of an offline payment code. In addition, it can also include device information, merchant information, order information, etc. These information can be dynamically acquired by the mobile device 104 from the local, such as querying device information including device type, device ID, merchant information and order information of this acquirer transaction from the corresponding storage area through the digital currency acquirer application 1041.

[0052] Specifically, the encryption key is mainly to ensure the confidentiality of the transmitted data in the process of digital currency transaction, and the integrity key is mainly to ensure the integrity and reliability of the transmitted data in the process of digital currency transaction. When the digital currency acquirer card application 1043 receives the digital currency transaction information sent by the digital currency acquirer application 1041, the preset key algorithm (for example, a symmetric key algorithm) is used to perform encryption operation on the digital currency transaction information by using the encryption key to obtain transaction information ciphertext, and then the digest algorithm and the integrity key (for example, the MAC key) are used to perform integrity calculation on the transaction information ciphertext to obtain a digest value (for example, the MAC value), and the transaction information ciphertext and the digest value are sent to the background system 108 as the processed digital currency transaction information for processing. The digest algorithm includes various existing algorithms, such as the MAC algorithm and the SM3 algorithm.

[0053] In addition, by setting the validity period of the key, for example, 24 hours, the risk of key cracking can be reduced, and frequent key replacement and high management cost can be avoided. Correspondingly, the mobile device 104 as the receiving terminal also needs to automatically update the key before the key expires. Based on the above, in some embodiments of the present disclosure, the digital currency acquirer application 1041 also sends an update instruction for updating the core key data to the digital currency background system 108 in response to a data update synchronization instruction. The "data update synchronization instruction" here can be triggered and generated by the merchant before using the mobile receiving terminal to perform digital currency acquirer transaction, or can be automatically triggered by the receiving terminal system according to the set time. Here, the "set time" is consistent with the key validity period as much as possible, for example, if the key validity period is 24 hours, the user or the system triggers the mobile device 104 to "check in" to the digital currency background system 108 every 24 hours, that is, every day, and sends an update instruction for the core key data to obtain new core key data.

[0054] Moreover, since the business and other communications and the like need to ensure the validity of the business-related data such as the communication certificate, other keys and the like used by them according to actual needs, the digital currency acquirer application 1041 also sends a synchronization instruction for synchronizing the business-related data to the digital currency background system 108 in response to the data update synchronization instruction. The two instructions (the update instruction for the core key data and the synchronization instruction for the business-related data) can be sent to the background system 108 at the same time, or can be sent at different time periods, and the embodiments of the present disclosure do not limit this.

[0055] Accordingly, in some embodiments of the present disclosure, the digital currency acquirer card application 1043 is further configured to replace the core key data and the business-related data stored in the second execution environment with the new core key data and the business-related data transmitted by the digital currency acquirer application 1041. In this way, the validity of the core key data can be ensured, the success rate of the background system 108 in checking and decrypting the processed transaction information can be improved, and thus the transaction can be better executed. In addition, the update of the business-related data can also ensure the synchronization with the data on the background side. Just like the daily update of the core key data, the update of the business-related data such as the key used for business and other communications can ensure the freshness and validity of the data, and thus ensure the successful execution of the transaction.

[0056] For the first installation of the digital currency acquirer application, the digital currency acquirer application detects whether the mobile device has the second execution environment, and further detects whether the digital currency trusted application is installed in the environment if the second execution environment exists. In one example, whether the digital currency trusted application is installed can be determined by accessing whether the collection application identifier exists in the second environment. If the collection application identifier exists, it is determined that the second environment has installed, for example, the SE acquirer card application or the TA application of the TEE.

[0057] Further, in some embodiments of the present disclosure, the digital currency acquirer application 1041 is further configured to, in the case where it is detected that the mobile device 104 has the second execution environment but does not have the digital currency trusted application, send a download request for the digital currency trusted application to the digital currency background system 108, then receive the installation file of the digital currency trusted application sent by the digital currency background system 108 through the secure channel, and install it into the second execution environment. The background system 108 has the digital currency acquirer card application for the secure element or the digital currency acquirer TA application for the TEE environment, and the background system 108 sends the installation file of the corresponding version to the mobile device 104 according to the information of the download request. The download request includes the download, installation, personalization instruction of the SE acquirer card application or the download, personalization instruction of the TA file.

[0058] In one example, if the digital currency acquirer application 1041 detects that the current mobile device includes both a secure element and a TEE, considering that the secure element is a separate hardware component, it provides hardware-level security isolation, so that sensitive data is physically isolated, which can more effectively reduce security risks compared to the TEE environment, and thus the secure element is preferred as the second execution environment for executing digital currency transactions. Then, the download request sent by the digital currency acquirer application 1041 to the background system 108 also indicates the intention to install the acquirer card application corresponding to the secure element.

[0059] After the digital currency trusted application is installed to the secure element for the first time, the digital currency acquirer application 1041 and the digital currency trusted application still cannot cooperate to perform a digital currency acquirer transaction, and the core key data used in the transaction process needs to be applied to protect the confidentiality and integrity of the transmitted data.

[0060] Based on the above, for example, in some embodiments of the present disclosure, the digital currency acquirer application 1041 is further configured to send a key application request to the digital currency back-end system 108, receive the core key data randomly generated and sent by the digital currency back-end system 108 in response to the key application request through a secure channel between the digital currency back-end system 108 and the mobile device 104; the digital currency acquirer card application 1043 is further configured to receive the core key data transmitted by the digital currency acquirer application 1041 and store it into the second execution environment. The key application request is used to request to download the encryption key and the integrity protection key. After receiving the core key data, the digital currency acquirer card application 1043 stores it into the data storage area of the secure element 104A, for example.

[0061] The communication module 1045 is mainly connected with the payment device 102 and the digital currency back-end system 108, and the communication method it follows can be Bluetooth, near-field NFC radio frequency, WIFI, UWB, and mobile network, etc. In some examples, the communication module 1045 establishes a secure channel with the communication module 108D of the digital currency back-end system 108, through which the key factor, challenge factor, event factor, and operation factor for generating the offline payment code, and the core key data for protecting the confidentiality and integrity of the transmitted information in the digital currency acquirer process sent by the back-end system 108 are received.

[0062] It should be noted that the "secure channel" can be a network channel between two entities (such as the back-end and the mobile communication terminal), which can allow the two entities to communicate with each other through the secure channel without being eavesdropped by a third entity or being disguised by a third entity as one of the two intended entities participating in the secure communication. The establishment of a secure channel can securely transmit sensitive information between two entities.

[0063] In some examples, the "secure channel" between the digital currency back-end system 108 and the mobile device 104 (communication module 1045) will perform integrity protection processing on the sensitive information to be transmitted during transmission. For example, the digital currency back-end system 108 and the mobile device 104 will save the keys for encrypting and decrypting the transmitted sensitive information, and use the same encryption algorithm for encryption to prevent being stolen by a third party.

[0064] For example, messages between the acceptance terminal 104 and the back-end system 108 can be sent over a communication network using a secure communication protocol such as, but not limited to, File Transfer Protocol (FTP), HyperText Transfer Protocol (HTTP), HyperText Transfer Protocol Secure (HTTPS), and the like. The communication network can include any one and / or combination of the following: a direct interconnection, the Internet, a Local Area Network (LAN), a Metropolitan Area Network (MAN), a secure custom connection, a Wide Area Network (WAN), a wireless network, and the like.

[0065] In consideration of the case where the mobile device does not include a second execution environment such as an SE or TEE, in other embodiments of the present disclosure, another mobile device for digital currency transaction is also provided.

[0066] FIG. 2B shows a block diagram of another exemplary mobile device (acceptance terminal) according to an embodiment of the present disclosure. The mobile device 104 includes a digital currency acquirer application 1041 running in a REE, a memory 1047 with a key storage area 1048, and a communication module 1045.

[0067] In this figure, the mobile device 104 does not have an SE or TEE environment that is securely isolated from the REE, but the key storage area 1048 may, for example, be a secure area that is separately partitioned from the memory 1047 and has a certain security, and the secure area is logically isolated from other areas and is mainly used to store core key data. For example, the secure area has an encryption function to encrypt sensitive data, and even if the content is obtained by a third party, the ciphertext of the sensitive data cannot be decrypted.

[0068] For example, in at least one embodiment of the present disclosure, the digital currency acquirer application 1041 is configured to, in the case where it is detected that the mobile device 104 does not have a second execution environment, perform the following operations: send a key application request to the back-end system 108 each time a digital currency acquirer transaction is initiated, and receive core key data through a secure channel between the back-end system 108 and the mobile device 104; perform encryption and integrity processing of digital currency transaction information using the core key data, and send the processed digital currency transaction information to the back-end system 108, so that the back-end system 108 verifies and decrypts the processed digital currency transaction information to perform the digital currency acquirer transaction.

[0069] In one example, the digital currency acquirer application 1041 can form digital currency transaction information from the payment information or offline payment code information obtained from the payment side and the device information, merchant information, and order information obtained locally, perform an encryption operation on the digital currency transaction information using a preset key algorithm (such as a symmetric key algorithm) using an encryption key to obtain transaction information ciphertext, perform an integrity calculation on the transaction information ciphertext using a digest algorithm and an integrity key (such as a MAC key) to obtain a digest value (such as a MAC value), and send the transaction information ciphertext and the digest value as processed digital currency transaction information to the back-end system 108 for processing. The digest algorithm includes various existing algorithms, such as the MAC algorithm and the SM3 algorithm.

[0070] Since the mobile device 104 applies for core key data from the back-end system 108 before initiating a digital currency acquirer transaction each time, it is not necessary to automatically update the core key data as in the mobile device shown in FIG. 2A, and the validity period can also not be set. In addition, considering that similar communication certificates, other keys, and other business-related data required for business and other communications also need to be guaranteed to be valid, the digital currency acquirer application 1041 is also configured to, in response to a data update synchronization request, send a synchronization instruction to synchronize business-related data to the digital currency back-end system 108, receive new business-related data sent by the digital currency back-end system 108, and replace the business-related data stored in the first execution environment.

[0071] In addition, in one example, the digital currency acquirer application 1041 can distinguish between the cases of having an SE and not having an SE and send different key application requests to the back-end system 108 to request core key data with a validity period and core key data without a validity period. For example, the key application request sent can carry an identifier.

[0072] In the embodiments of the present disclosure, the digital currency back-end system 108 is a back-end system that supports digital currency transaction functions and can include a payment and collection operation agency back-end server and an interconnection platform, supporting in-house and cross-agency digital currency transactions. The digital currency back-end system 108 can be conventional in terms of hardware, but can be controlled by software to facilitate its operation as described below. For example, the digital currency back-end system 108 can be composed of server computer hardware, which is not described in detail.

[0073] In most cases, the digital currency background system 108 can include a payee institution background and a payer institution background, which can both process digital currency transactions within the institution and generate transaction execution result information after the mobile communication terminal 104 is connected to return to the mobile device 104 for user confirmation. In order to facilitate information exchange between multiple operating institutions, in the embodiment of the present disclosure, the digital currency background system 108 further includes an interconnection system or server corresponding to the system or server of each operating institution.

[0074] For example, in the embodiment of the present disclosure, when the payer institution identifier, the payee institution identifier and the transaction amount in the transaction information (payment information) are used to conduct a digital currency transaction, when the operating institutions corresponding to the payer institution identifier and the payee institution identifier belong to the same operating institution, the transaction is conducted in the institution; when the operating institutions corresponding to the payer institution identifier and the payee institution identifier do not belong to the same operating institution, the transaction request is sent through the interconnection platform, and the cross-institution transaction is conducted.

[0075] FIG. 3 shows a block diagram of an exemplary digital currency background system according to an embodiment of the present disclosure. For the digital currency background system being one of the payee institution background and the payer institution background, the functions of each group of modules of the digital currency background system are described below with reference to FIG. 3.

[0076] As shown in FIG. 3, the digital currency background system 108 includes a key generation module 108A, a business management module 108C and a communication module 108D.

[0077] The key generation module 108A is configured to randomly generate core key data, and store the core key data in association with the user data (such as the account information of the digital currency wallet ID) corresponding to the mobile device 104. The core key data has a validity period. In one example, the key generation module 108A can use a suitable random number generator and algorithm to generate a key with a specified key length. The calculated key is used as an encryption key for encrypting digital currency transaction information during a digital currency transaction, or as an integrity key for integrity calculation, thereby ensuring the confidentiality and integrity of data transmission. After generating the core key data, the key generation module 108A stores the user wallet ID and the core key data correspondingly.

[0078] The communication module 108D is configured to establish a secure channel with the mobile device 104. For details of the "secure channel", please refer to the foregoing description, which will not be repeated here.

[0079] The business management module 108C is configured to, in response to the key application request sent by the mobile device 104, control the key generation module 108A to randomly generate core key data, and send the core key data to the mobile device 104 through a secure channel; and based on the core key data stored in association with the user data corresponding to the mobile device, verify and decrypt the processed digital currency transaction information sent by the mobile device 104 to perform a digital currency acquirer transaction.

[0080] For example, in at least one embodiment of the present disclosure, the business management module 108C uses the same verification algorithm as the mobile device 104, such as MAC value calculation, to perform MAC value calculation on the information in the processed digital currency transaction information sent by the mobile device 104 except for the MAC value, and then compares the calculated MAC value with the MAC value in the processed transaction information. If they are consistent, the verification is passed, and then the encrypted information is decrypted according to the corresponding core key data queried based on the user data to obtain the transaction information, such as digital currency payment information (or code information of the payment code), device information, merchant information and order information, based on which subsequent acquirer processing is performed to apply for deduction from the digital currency account.

[0081] For example, if the code information of the offline payment code is also included in the transaction information, in at least one embodiment of the present disclosure, the business management module 108C is further configured to verify the code information of the offline payment code by the following steps: parsing the code information of the offline payment code to determine the user index and the verification code; calculating the digest value from the verification code and the local operation factor, and calculating the event factor from the digest value and the user index; querying the corresponding user data according to the event factor, and determining the key factor and the challenge factor corresponding to the user data using the mapping relationship; encrypting the challenge factor, the time factor and the event factor using the key factor to obtain the verification code; comparing the calculated verification code with the verification code in the offline payment code, and performing digital currency transaction processing after the comparison is passed. Then, the execution result of the transaction success is returned to the receiving terminal 104.

[0082] It is easy to understand that if the mobile device 104 and the payment device 102 obtain the transaction information through NFC communication, the code information of the offline payment code is not included, and then the background system 108 only needs to perform MAC verification and decryption operation on the transaction information containing APDU instruction, and perform digital currency acquirer transaction according to the decrypted transaction information to apply for deduction from the corresponding digital currency account.

[0083] For example, in at least one embodiment of the present disclosure, the business management module 108C sends the updated core key data to the mobile device 104 through a secure channel to replace the core key data stored in the mobile device 104 in response to the update instruction for updating the core key data sent by the mobile device 104, and sends the synchronized business-related data to the mobile device 104 through a secure channel to replace the business-related data stored in the mobile device 104 in response to the synchronization instruction for synchronizing the business-related data sent by the mobile device 104. As described above, the core key data has a validity period, and the mobile device 104 needs to update the core key data at a set time to prevent transaction failure due to key invalidation. After receiving the key update instruction sent by the mobile device 104, the background 108 controls the key generation module 108A to regenerate new core key data, and stores the new core key data and the corresponding user data locally, while sending the new core key data to the mobile device 104.

[0084] For example, in at least one embodiment of the present disclosure, the business management module 108C is configured to send the installation file of the digital currency trusted application to the mobile device 104 through a secure channel in response to the download request for the digital currency trusted application sent by the mobile device 104. After the mobile device 104 installs the digital currency acquirer application, it is detected that the current secure element or TEE does not install the digital currency trusted application (such as acquirer card application or TA application), and a download request needs to be sent to the background system 108. The background system 108 sends the corresponding installation file to the corresponding mobile device 104 according to the information of the download request to complete the installation of the digital currency card application or TA application.

[0085] For example, in at least one embodiment of the present disclosure, the business management module 108C is further configured to determine whether the current digital currency transaction belongs to a password-free transaction or a small-amount transaction according to the digital currency transaction data. Specifically, the business management module 108C can determine whether the payment end wallet defaults a password-free transaction or a small-amount transaction (or a limited-amount transaction) according to the wallet identifier of the payment end in the digital currency transaction data, and if so, execute the corresponding transaction processing, otherwise return the result of transaction execution failure of the receiving terminal 104. In this way, transaction risk control can be performed.

[0086] FIG. 4A shows a flowchart of a mobile device-based key data management method according to an embodiment of the present disclosure. The following describes the steps of the method executed by the application in the mobile device with reference to FIG. 4A.

[0087] Firstly, in step S400, the digital currency acquirer application 1041 detects whether the current mobile device has a second execution environment such as a TEE / SE and installs a digital currency trusted application in the second execution environment, and if the detection is positive, the operation procedures of steps S402 and S404 are performed, and if the detection is negative, the operation procedures of steps S4021 and S4023 are performed.

[0088] In step S402, the digital currency acquirer application 1041 sends a key application request to the digital currency background system 108 and receives core key data through a secure channel between the digital currency background system 108 and the mobile device 104, and sends the core key data to the digital currency trusted application.

[0089] In step S404, the digital currency trusted application receives the core key data transmitted by the digital currency acquirer application 1041 and stores it in the second execution environment.

[0090] For example, in some embodiments of the present disclosure, the method can also automatically update the core key data and the business-related data. The digital currency acquirer application 1041 sends an update instruction for updating the core key data and a synchronization instruction for synchronizing the business-related data to the background system 108 in response to a data update synchronization instruction, receives new core key data and business-related data sent by the digital currency background system 108 through a secure channel in response to the update instruction and the synchronization instruction, and the digital currency trusted application replaces the core key data and the business-related data stored in the second execution environment with the new core key data and the business-related data transmitted by the digital currency acquirer application 1041.

[0091] In step S4021, the digital currency acquirer application 1041 sends a key application request to the digital currency background system in each time of initiating a digital currency acquirer transaction in the case of detecting that the mobile device does not have a second execution environment, and receives core key data through a secure channel between the digital currency background system and the mobile device.

[0092] In step S4023, the digital currency acquirer application 1041 stores the core key data in the secure area of the first execution environment.

[0093] For example, in some embodiments of the present disclosure, the method can also automatically update the business-related data. The digital currency acquirer application 1041 sends a synchronization instruction for synchronizing the business-related data to the background system 108 in response to a data update synchronization instruction, receives new business-related data sent by the background system 108, and replaces the business-related data stored in the first execution environment.

[0094] FIG. 4B shows a flowchart of a transaction method based on a digital currency hard wallet according to an embodiment of the present disclosure. The various steps of the method are explained below with reference to FIG. 4B.

[0095] Firstly, in step S400, the digital currency acquirer application 1041 detects whether the current mobile device has a second execution environment such as a TEE / SE and whether a digital currency trusted application is installed in the second execution environment. If the detection is positive, the steps of steps S401, S403 and S405 are performed, otherwise the steps of steps S4011, S4013 and S405 are performed.

[0096] In step S401, in the case where it is detected that the mobile device 104 has a second execution environment and a digital currency trusted application such as an acquirer card application 1043 is installed in the second execution environment, the digital currency acquirer application 1041 initiates a digital currency acquirer transaction to the payment end to obtain digital currency payment information or code information of an offline payment code returned by the payment end and transmits to the digital currency trusted application.

[0097] In step S403, the digital currency trusted application performs encryption and integrity processing of the digital currency transaction information using core key data stored in the second execution environment such as the secure element 104A, and transmits the processed digital currency transaction information to the digital currency backend system 108 through the digital currency acquirer application 1041.

[0098] In step S405, the digital currency backend system 108 verifies and decrypts the processed digital currency transaction information to perform a digital currency acquirer transaction.

[0099] For example, in some embodiments of the present disclosure, in the case where it is detected that the mobile device 104 has a second execution environment but no digital currency trusted application is installed, the digital currency acquirer application 1041 sends a download request for a digital currency trusted application to the digital currency backend system 108, receives an installation file of the digital currency trusted application sent by the digital currency backend system 108 through a secure channel, and installs it into the second execution environment.

[0100] For example, in some embodiments of the present disclosure, the digital currency acquirer application 1041 also sends a key application request to the digital currency backend system 108 and receives core key data sent by the digital currency backend system 108 in response to the key application request through a secure channel; the digital currency trusted application receives the core key data transmitted by the digital currency acquirer application 1041 and stores it into the second execution environment.

[0101] In step S4011, the digital currency acquirer application 1041 sends a key application request to the digital currency background system each time a digital currency acquirer transaction is initiated, and receives core key data through a secure channel between the digital currency background system and the mobile device.

[0102] In step S4013, the digital currency acquirer application 1041 performs encryption and integrity processing of the digital currency transaction information using the core key data, sends the processed digital currency transaction information to the digital currency background system, and then performs step S405.

[0103] In addition, the digital currency acquirer application 1041 can also apply for core key data from the digital currency background system and store it in the secure area of the first execution environment when the mobile device does not have a second execution environment, and then use the core key data in the secure area to encrypt and integrity calculate the transaction information.

[0104] The embodiments of the methods shown in FIGS. 4A and 4B are basically similar to the contents of the previously described embodiments of the mobile device-based digital currency transaction system, and therefore will not be described here again. For relevant parts, please refer to the description in the system embodiment part.

[0105] FIG. 5A shows a flowchart of an exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure, which mainly describes how the digital currency acquirer APP 1041 in the mobile device and the digital currency trusted application 1043 in the secure element / TEE, such as the acquirer card application (SE card application for short) of the secure element or the acquirer card TA (TEE TA for short) application in the TEE, store core key data, use the core key data for digital currency transactions, and update the core key data.

[0106] First, when a merchant wants to use a mobile device as a receiving terminal for digital currency acquirer transactions, the merchant downloads a digital currency acquirer App and installs it in the mobile device 104, and then registers the merchant information and mobile device information through the acquirer App to access the digital currency system.

[0107] Next, the digital currency acquirer App 1041 determines whether the mobile device 104 has SE or TEE capabilities. If the mobile device 104 has SE capabilities, the digital currency acquirer APP 1041 applies to the background system 108 to download an SE card application to the secure element SE of the mobile device 104 when the acquirer function is enabled. If the mobile device 104 has TEE capabilities, the digital currency acquirer APP 1041 applies to the digital currency background system 108 to download a digital currency acquirer TA application to the TEE of the mobile device 104 when the acquirer function is enabled. When both SE and TEE capabilities are available, the SE capability is preferred.

[0108] After the SE card application or the TA application of the TEE is installed, the digital currency acquirer App 1041 triggers the core key data of the mobile device to be applied to the digital currency background 108, and the background system 108 transmits the core key data to the digital currency acquirer App 1041 of the mobile device through a secure channel, and then the digital currency acquirer App 1041 transmits the core key data to the SE card application or the TA application of the TEE to store the core key data in the SE or TEE. The digital currency background system 108 randomly generates the core key data each time according to the request, and the validity period is not more than 24 hours. If there is no SE or TEE capability, the digital currency acquirer App 1041 stores the received core key data in the secure area of the REE environment, and can also be used as needed, without pre-storing.

[0109] In addition, the mobile device 104 with SE or TEE capability needs to sign in daily to update the synchronization of the core key data and other business related data, and the background system 108 transmits the updated core key data and business related data to the mobile device 104, and the SE card application or the TA application of the TEE stores the new core key data and business related data. For the mobile device without SE / TEE capability, it only needs to sign in to the background system 108 daily to obtain the business related data to be synchronized, and store it in the first execution environment.

[0110] Then, when the mobile device 104 initiates a digital currency acquirer transaction to the payment side, the NFC payment information or offline payment code information returned by the payment side is received, and then the information is combined with the locally obtained device information, merchant information and order information to form transaction information. The SE card application or the TA application of the TEE uses the stored core key data to encrypt and integrity process the transaction information, and transmits the processed transaction information to the digital currency background system 108. The digital currency background system 108 integrity checks, checks through decryption, and then completes the deduction processing. For the mobile device without SE or TEE capability, the digital currency acquirer App 1041 uses the core key data applied to the background system 108 to encrypt and integrity process the transaction information.

[0111] FIG. 5B shows a flowchart of another exemplary mobile device-based digital currency transaction method according to an embodiment of the present disclosure. The method mainly describes how the digital currency acquirer App 1041 in the mobile device uses the core key data dynamically pulled from the background to perform a digital currency transaction each time the acquirer transaction is performed.

[0112] First, at each time of performing the acquirer transaction, the digital currency acquirer App 1041 judges whether the mobile device 104 has SE or TEE capability or a secure area for storing core key data in the REE environment, if yes, the digital currency acquirer App 1041 further judges whether the area has stored the core key data, if not, the core key data is applied to the background system 108.

[0113] Next, the digital currency acquirer App 1041 uses the core key data obtained by dynamic pulling to encrypt and integrity process the transaction information, and sends the processed transaction information to the digital currency background system 108. The digital currency background system 108 integrity checks, checks through decryption of the transaction information, and then completes the deduction processing. Among them, the transaction information includes the NFC payment information or offline payment code information returned by the payment side, as well as device information, merchant information and order information and other information.

[0114] It should be noted that the above application scenario is only exemplary, so as to describe one or more aspects of the present disclosure in a specific scenario, but these aspects are not necessarily required, and various modifications can be made to the application scenario, and the embodiments of the present disclosure are not limited.

[0115] At least some embodiments of the present disclosure also provide an electronic device. FIG. 6 shows a schematic diagram of an electronic device 600 according to an embodiment of the present disclosure.

[0116] As shown in FIG. 6, the electronic device 600 includes one or more processors 610 and a memory 620. The memory 620 includes one or more computer program modules 621. The one or more computer program modules 621 are stored in the memory 620 and configured to be executed by the processor 610, and the one or more computer program modules 621 include instructions for executing the method according to at least one embodiment of the present disclosure and its additional aspects, which are executed by the processor 610, and can execute one or more steps of the method according to at least one embodiment of the present disclosure and its additional aspects. The memory 620 and the processor 610 can be interconnected by a bus system and / or other forms of connection mechanism (not shown). For example, the bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0117] The processor 610 may, for example, be a central processing unit (CPU), a digital signal processor (DSP), or other form of processing unit having data processing and / or program execution capabilities, such as a field-programmable gate array (FPGA), etc. The processor 610 may be a general purpose processor or a special purpose processor, and can control other components in the electronic device 600 to perform desired functions.

[0118] The memory 620 may, for example, include any combination of one or more computer program products. The computer program product may include various forms of computer-readable storage media having computer-readable program instructions stored therein. The computer-readable storage media may, for example, include volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM), cache memory, etc. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, erasable programmable ROM (EPROM), compact disk ROM (CD-ROM), USB memory, flash memory, etc. One or more computer program modules 621 may be stored on the computer-readable storage media. The processor 610 may execute the one or more computer program modules 621 to implement various functions of the electronic device 600. The computer program modules include a plurality of computer-executable instructions. Various application programs and various data used and / or generated by the application programs, etc. may also be stored in the computer-readable storage media.

[0119] The electronic device 600 may, for example, further include an input device such as a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device such as a liquid crystal display, a speaker, a vibrator, etc.; a storage device such as a magnetic tape, a hard disk (HDD or SDD), etc.; and a communication device such as a LAN card, a modem, etc. The communication device may allow the electronic device 600 to perform wireless or wired communication with other devices to exchange data, perform communication processing via a network such as the Internet. A driver is connected to the I / O interface as needed. A removable storage medium such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the driver as needed, so that a computer program read out from the removable storage medium is installed in the storage device as needed.

[0120] For example, the electronic device 600 can further include a peripheral interface (not shown in the figure) and the like. The peripheral interface can be various types of interfaces, such as a USB interface, a lighting interface, and the like. The communication device can communicate with networks and other devices through wireless communication, such as the Internet, an intranet, and / or a wireless network such as a cellular telephone network, a wireless local area network (LAN), and / or a metropolitan area network (MAN). The wireless communication can use any of a plurality of communication standards, protocols, and technologies, including but not limited to Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (such as based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for e-mail, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.

[0121] The electronic device 600 may, for example, be a system on chip (SOC) or a device including the SOC, such as a mobile phone, a tablet computer, a notebook computer, an e-book, a game console, a television, a digital photo frame, a navigator, a household appliance, a communication base station, an industrial controller, a server, or any device, and can be any data processing apparatus and combination of hardware, without limitation. The specific functions and technical effects of the electronic device 600 can be referred to the description of the method for digital currency transaction and additional aspects thereof according to at least one embodiment of the present disclosure above, and will not be repeated here.

[0122] FIG. 7 shows a schematic diagram of a non-transitory computer-readable storage medium 700 according to an embodiment of the present disclosure.

[0123] As shown in FIG. 7, the non-transitory computer-readable storage medium 700 stores computer-executable instructions 710 that, when executed by a processor, perform one or more steps of the method and additional aspects thereof as described above.

[0124] For example, when the program code is read by a computer, the computer can execute the program code stored in the computer storage medium to perform one or more steps of the method and additional aspects thereof according to at least one embodiment of the present disclosure.

[0125] Exemplarily, the computer readable storage medium can include a memory card of a smart phone, a memory component of a tablet computer, a hard disk of a personal computer, a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM), a compact disc read only memory (CD-ROM), a flash memory, and other computer readable medium or any combination thereof.

[0126] At least some embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments, and the same or similar parts between embodiments can be referred to each other.

[0127] It should be noted that, in this document, the relationship terms such as first, second and the like are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. The terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also further includes other elements not explicitly listed or further includes elements inherent to such process, method, article or device. Without more limitations, the elements defined by the statement "include" do not exclude the presence of other same elements in the process, method, article or device including the elements.

[0128] For the present disclosure, the following points also need to be explained:

[0129] (1) The drawings of the embodiments of the present disclosure only involve the structures involved in the embodiments of the present disclosure, and other structures can refer to the general design.

[0130] (2) In the case of no conflict, the embodiments of the present disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.

[0131] The above is only an exemplary embodiment of the present disclosure, and is not used to limit the protection scope of the present disclosure, and the protection scope of the present disclosure is determined by the appended claims.

Claims

1. A mobile device for digital currency transactions, comprising: The digital currency acquiring application executable in the first execution environment is configured to: initiate a digital currency acquiring transaction to the payment terminal to obtain digital currency payment information or offline payment code information returned by the payment terminal, and transmit the digital currency payment information or the offline payment code information to the trusted digital currency application. and The trusted digital currency application executable in the second execution environment is configured to: perform encryption and integrity processing of digital currency transaction information using core key data stored in the second execution environment, and send the processed digital currency transaction information to the digital currency back-end system through the digital currency acquiring application, so that the digital currency back-end system can verify and decrypt the processed digital currency transaction information to execute the digital currency acquiring transaction; The mobile device serves as the receiving terminal, the second execution environment is securely isolated from the first execution environment, the digital currency transaction information includes the digital currency payment information or the code information of the offline payment code, and the core key data includes an encryption key and an integrity key with a validity period.

2. The mobile device according to claim 1, wherein, The digital currency acquiring application is further configured to: when it detects that the mobile device has a second execution environment but the trusted digital currency application is not installed, send a download request for the trusted digital currency application to the digital currency backend system, receive the installation file of the trusted digital currency application sent by the digital currency backend system through the secure channel, and install the trusted digital currency application to the second execution environment.

3. The mobile device according to claim 2, wherein, The digital currency acquiring application is further configured to: send a key request to the digital currency back-end system, and receive core key data randomly generated and sent in response to the key request from the digital currency back-end system via a secure channel between the digital currency back-end system and the mobile device; and The trusted application for digital currency is further configured to: receive core key data transmitted by the digital currency acquiring application, and store the core key data in the second execution environment.

4. The mobile device according to claim 1, wherein, The digital currency acquiring application is further configured to: in response to a data update synchronization instruction, send an update instruction to update the core key data and a synchronization instruction to synchronize business-related data to the digital currency back-end system, and receive new core key data and business-related data sent by the digital currency back-end system through the secure channel; and The trusted application for digital currency is further configured to replace the core key data and business-related data already stored in the second execution environment with new core key data and business-related data transmitted by the digital currency acquiring application.

5. The mobile device according to any one of claims 1 to 4, wherein, The second execution environment is a trusted execution environment or a secure element.

6. A mobile device for digital currency transactions, the mobile device serving as an acceptance terminal, including a digital currency acquiring application executable in a first execution environment; The digital currency acquiring application is configured to perform the following operations: Each time a digital currency acquiring transaction is initiated, a key request is sent to the digital currency backend system, and core key data is received through a secure channel between the digital currency backend system and the mobile device. The core key data includes encryption keys and integrity keys; The core key data is used to perform encryption and integrity processing on digital currency transaction information, and the processed digital currency transaction information is sent to the digital currency back-end system so that the digital currency back-end system can verify and decrypt the processed digital currency transaction information to execute digital currency acquiring transactions. The digital currency transaction information includes digital currency payment information returned by the payment terminal or code information of offline payment codes.

7. The mobile device according to claim 6, wherein, The digital currency acquiring application is further configured to: in response to a data update synchronization request, send a synchronization instruction to the digital currency back-end system to synchronize business-related data, receive new business-related data sent by the digital currency back-end system, and replace the business-related data already stored in the first execution environment with the new business-related data sent by the digital currency back-end system.

8. A digital currency back-end system, comprising: The key generation module is configured to randomly generate core key data and store it in association with the user data corresponding to the mobile device. The core key data includes an encryption key and an integrity key. The communication module is configured to: establish a secure channel with the mobile device; The business management module is configured to: verify and decrypt the processed digital currency transaction information sent by the mobile device in order to execute digital currency acquiring transactions based on the core key data stored in association with the user data corresponding to the mobile device.

9. The digital currency back-end system according to claim 8, wherein, The business management module is further configured to: respond to a key request sent by the mobile device, control the key generation module to randomly generate core key data, and send the core key data to the mobile device through the secure channel.

10. The digital currency back-end system according to claim 8, wherein, The business management module is also configured to: in response to an update instruction sent by the mobile device to update the core key data, send the updated core key data to the mobile device through the secure channel to replace the core key data already stored in the mobile device; In response to a synchronization command sent by the mobile device to synchronize service-related data, the synchronized service-related data is sent to the mobile device through the secure channel to replace the service-related data already stored on the mobile device.

11. The digital currency back-end system according to claim 8, wherein, The business management module is also configured to: in response to a download request for a trusted digital currency application sent by the mobile device, send the installation file of the trusted digital currency application to the mobile device through the secure channel.

12. A digital currency trading system, comprising: The mobile device as described in any one of claims 1-7, and The digital currency back-end system as described in any one of claims 8-11.

13. A digital currency transaction method based on a mobile device, wherein the mobile device serves as an accepting terminal, the mobile device includes a digital currency acquiring application executable in a first execution environment and a trusted digital currency application executable in a second execution environment, the second execution environment being securely isolated from the first execution environment. The method includes: The digital currency acquiring application initiates a digital currency acquiring transaction to the payment terminal to obtain digital currency payment information or offline payment code information returned by the payment terminal, and transmits the digital currency payment information or offline payment code information to the trusted digital currency application. The trusted digital currency application uses the core key data stored in the second execution environment to perform encryption and integrity processing on digital currency transaction information, and sends the processed digital currency transaction information to the digital currency back-end system through the digital currency acquiring application, so that the digital currency back-end system can verify and decrypt the processed digital currency transaction information to execute the digital currency acquiring transaction. The digital currency transaction information includes the digital currency payment information or the code information of the offline payment code; the core key data includes an encryption key and an integrity key with a validity period.

14. The method according to claim 13, wherein, Also includes: If the mobile device is found to have a second execution environment but the trusted digital currency application is not installed, the digital currency acquiring application sends a download request for the trusted digital currency application to the digital currency back-end system, receives the installation file of the trusted digital currency application sent by the digital currency back-end system through the secure channel, and installs the trusted digital currency application to the second execution environment.

15. The method according to claim 13, wherein, The digital currency acquiring application also sends a key application request to the digital currency back-end system, and receives core key data randomly generated and sent in response to the key application request from the digital currency back-end system through a secure channel between the digital currency back-end system and the mobile device. and The trusted digital currency application receives the core key data transmitted by the digital currency acquiring application and stores the core key data in the second execution environment.

16. The method according to claim 13, wherein, In response to the data update and synchronization command, the digital currency acquiring application sends an update command to update the core key data and a synchronization command to synchronize business-related data to the digital currency back-end system, and receives new core key data and business-related data sent by the digital currency back-end system through the secure channel in response to the update command and the synchronization command. and The trusted digital currency application replaces the core key data and business-related data already stored in the second execution environment with new core key data and business-related data transmitted by the digital currency acquiring application.

17. The method according to any one of claims 13 to 16, wherein, The second execution environment is a trusted execution environment or a secure element.

18. A digital currency transaction method based on a mobile device, wherein the mobile device serves as an accepting terminal and includes a digital currency acquiring application executable in a first execution environment; The digital currency acquiring application performs the following operations: Each time a digital currency acquiring transaction is initiated, a key request is sent to the digital currency backend system, and core key data is received through a secure channel between the digital currency backend system and the mobile device. The core key data includes encryption keys and integrity keys; and The core key data is used to perform encryption and integrity processing on digital currency transaction information, and the processed digital currency transaction information is sent to the digital currency back-end system so that the digital currency back-end system can verify and decrypt the processed digital currency transaction information to execute digital currency acquiring transactions. The digital currency transaction information includes digital currency payment information returned by the payment terminal or code information of offline payment codes.

19. The method according to claim 18, wherein, In response to a data update synchronization request, the digital currency acquiring application sends a synchronization instruction to the digital currency back-end system to synchronize business-related data, receives new business-related data sent by the digital currency back-end system, and replaces the business-related data already stored in the first execution environment with the new business-related data sent by the digital currency back-end system.

20. An electronic device comprising: One or more processors; and Memory, used to store one or more computer programs. When the one or more computer programs are executed, the one or more processors implement the method as described in any one of claims 13 to 19.

21. A non-transitory computer-readable storage medium storing computer-executable instructions, wherein, When the computer-executable instructions are executed by one or more processors, they implement the method as described in any one of claims 13 to 19.

Citation Information

Patent Citations

  • Method for authenticating point of sail (POS) file and method for maintaining authentication certificate

    CN102064939A

  • Mobile intelligent terminal acquirer system and method suitable for bank cards and business cards

    CN103793815A

  • POS terminal master key distribution method and POS terminal master key distribution device

    CN110048831A

  • Digital currency payment method and device

    CN114186995A

  • Digital currency POS terminal and implementation method of digital currency hardware wallet

    CN116415936A