[go: up one dir, main page]

CN110969434B - Payment method, server, terminal and system - Google Patents

Payment method, server, terminal and system Download PDF

Info

Publication number
CN110969434B
CN110969434B CN201911204994.8A CN201911204994A CN110969434B CN 110969434 B CN110969434 B CN 110969434B CN 201911204994 A CN201911204994 A CN 201911204994A CN 110969434 B CN110969434 B CN 110969434B
Authority
CN
China
Prior art keywords
payment
information
terminal
authentication information
dynamic authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201911204994.8A
Other languages
Chinese (zh)
Other versions
CN110969434A (en
Inventor
徐若宸
上官昕阳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Priority to CN201911204994.8A priority Critical patent/CN110969434B/en
Publication of CN110969434A publication Critical patent/CN110969434A/en
Application granted granted Critical
Publication of CN110969434B publication Critical patent/CN110969434B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/085Payment architectures involving remote charge determination or related payment systems

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • Finance (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

The embodiment of the application discloses a payment method, a server, a terminal and a system, wherein the method comprises the following steps: the payment server receives a payment request sent by a payment terminal, wherein the payment request comprises payment information generated by the payment terminal based on a payment credential displayed by the payment terminal; the payment server sends a security authentication request to the payment terminal to instruct the payment terminal to display first dynamic authentication information; the payment server receives feedback information sent by the payment terminal, and carries out security authentication on the payment terminal according to the first dynamic authentication information and second dynamic authentication information acquired by the payment terminal based on the first dynamic authentication information, wherein the feedback information is included in the feedback information, and if the authentication is passed, payment transaction is carried out according to the payment information. According to the embodiment of the application, the malicious collection operation of the malicious collection terminal can be effectively avoided, and the safety of mobile payment is improved.

Description

支付方法、服务器、终端及系统Payment method, server, terminal and system

技术领域Technical Field

本申请涉及移动支付技术领域,尤其涉及一种支付方法、服务器、终端及系统。The present application relates to the field of mobile payment technology, and in particular to a payment method, server, terminal and system.

背景技术Background technique

随着互联网技术的飞速发展,移动支付在生活中广泛普及。当前的移动支付过程通常是用户将其支付终端中的支付码(如二维码或条形码等)展示给商家的收款终端,商家的收款终端通过扫描该支付码即可直接完成收款。然而由于支付环境复杂多变,周围还可能存在其他的恶意收款设备,如他人恶意隐藏的摄像头等,该恶意收款设备也可扫描用户的支付终端所展示的付款码并进行非法扣款操作,因此,存在安全性差,容易给用户造成财产损失等问题。With the rapid development of Internet technology, mobile payment has become widely popular in life. The current mobile payment process is usually that the user shows the payment code (such as a QR code or barcode, etc.) in his payment terminal to the merchant's payment terminal, and the merchant's payment terminal can directly complete the payment by scanning the payment code. However, due to the complex and changeable payment environment, there may be other malicious payment devices around, such as malicious hidden cameras, etc. The malicious payment device can also scan the payment code displayed by the user's payment terminal and perform illegal deduction operations. Therefore, there are problems such as poor security and easy to cause property losses to users.

发明内容Summary of the invention

本申请实施例提供一种支付方法、服务器、终端及系统,以解决现有技术中移动支付的安全性差,容易给用户造成财产损失等问题。The embodiments of the present application provide a payment method, a server, a terminal and a system to solve the problems of poor security of mobile payment in the prior art and easy to cause property loss to users.

为解决上述技术问题,本申请实施例是这样实现的:To solve the above technical problems, the embodiments of the present application are implemented as follows:

第一方面,本申请实施例提供了一种支付方法,应用于支付服务器,包括:In a first aspect, an embodiment of the present application provides a payment method, applied to a payment server, comprising:

接收收款终端发送的支付请求,其中,所述支付请求包括所述收款终端基于支付终端展示的支付凭证所生成的支付信息;Receiving a payment request sent by a payment terminal, wherein the payment request includes payment information generated by the payment terminal based on a payment voucher displayed by the payment terminal;

向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息;Sending a security authentication request to the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information;

接收所述收款终端发送的反馈信息,其中,所述反馈信息包括所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;Receiving feedback information sent by the payment terminal, wherein the feedback information includes second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information;

根据所述第一动态认证信息和所述第二动态认证信息,对所述支付终端进行安全认证;Performing security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information;

若认证通过,则根据所述支付信息进行支付交易。If the authentication is successful, the payment transaction is performed according to the payment information.

第二方面,本申请实施例提供了一种支付方法,应用于支付终端,包括:In a second aspect, an embodiment of the present application provides a payment method, applied to a payment terminal, comprising:

响应于用户的支付操作,展示支付凭证,以使收款终端基于所述支付凭证生成支付信息,并根据所述支付信息向支付服务器发送支付请求;In response to the user's payment operation, display the payment voucher so that the payment terminal generates payment information based on the payment voucher and sends a payment request to the payment server according to the payment information;

接收所述支付服务器发送的安全认证请求;Receiving a security authentication request sent by the payment server;

根据所述安全认证请求,展示第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器,使所述支付服务器根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端进行安全认证。According to the security authentication request, the first dynamic authentication information is displayed so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information.

第三方面,本申请实施例提供了一种支付服务器,包括:In a third aspect, an embodiment of the present application provides a payment server, including:

接收模块,用于接收收款终端发送的支付请求,其中,所述支付请求包括所述收款终端基于支付终端展示的支付凭证所生成的支付信息;A receiving module, configured to receive a payment request sent by a payment terminal, wherein the payment request includes payment information generated by the payment terminal based on a payment voucher displayed by the payment terminal;

发送模块,用于向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息;A sending module, configured to send a security authentication request to the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information;

所述接收模块,还用于接收所述收款设备发送的反馈信息,其中,所述反馈信息包括所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;The receiving module is further used to receive feedback information sent by the payment receiving device, wherein the feedback information includes second dynamic authentication information collected by the payment receiving terminal based on the first dynamic authentication information;

认证模块,用于根据所述第一动态认证信息和所述第二动态认证信息,对所述支付终端进行安全认证;an authentication module, configured to perform security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information;

处理模块,用于在所述认证模块认证通过时,根据所述支付信息进行支付交易。The processing module is used to perform a payment transaction according to the payment information when the authentication module passes the authentication.

第四方面,本申请实施例提供了一种支付终端,包括:In a fourth aspect, an embodiment of the present application provides a payment terminal, including:

展示模块,用于响应于用户的支付操作,展示支付凭证,以使收款终端基于所述支付凭证生成支付信息,并根据所述支付信息发送支付请求给支付服务器;A display module, used to display the payment voucher in response to the user's payment operation, so that the payment terminal generates payment information based on the payment voucher and sends a payment request to the payment server according to the payment information;

接收模块,用于接收所述支付服务器发送的安全认证请求;A receiving module, used for receiving a security authentication request sent by the payment server;

所述展示模块,还用于根据所述安全认证请求,展示第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集的第二动态认证信息发送给所述支付服务器,使所述支付服务器根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端进行安全认证。The display module is also used to display the first dynamic authentication information according to the security authentication request, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information.

第五方面,本申请实施例提供了一种支付系统,包括:支付终端、收款终端和后台支付服务器;In a fifth aspect, an embodiment of the present application provides a payment system, including: a payment terminal, a payment terminal and a backend payment server;

所述支付终端,用于响应于用户的支付操作,展示支付凭证;以及,接收所述支付服务器发送的安全认证请求,根据所述安全认证请求,展示第一动态认证信息;The payment terminal is configured to display a payment voucher in response to a payment operation of a user; and receive a security authentication request sent by the payment server, and display first dynamic authentication information according to the security authentication request;

所述收款终端,用于基于所述支付凭证生成支付信息,根据所述支付信息向所述支付服务器发送支付请求;以及,将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器;The payment terminal is configured to generate payment information based on the payment voucher, send a payment request to the payment server according to the payment information; and send second dynamic authentication information collected based on the first dynamic authentication information to the payment server;

所述支付服务器,用于接收所述收款终端发送的支付请求,向所述支付终端发送安全认证请求;以及,根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端进行安全认证,若认证通过,则根据所述支付信息进行支付交易。The payment server is used to receive the payment request sent by the payment terminal, send a security authentication request to the payment terminal; and perform security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information. If the authentication is successful, a payment transaction is performed according to the payment information.

第六方面,本申请实施例提供一种支付服务器,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现上述实施例提供的应用于支付服务器的支付方法的步骤。In a sixth aspect, an embodiment of the present application provides a payment server, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the steps of the payment method applied to the payment server provided in the above embodiment are implemented.

第七方面,本申请实施例提供一种支付终端,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现上述实施例提供的应用于支付终端的支付方法的步骤。In the seventh aspect, an embodiment of the present application provides a payment terminal, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the payment method applied to the payment terminal provided in the above embodiment.

第八方面,本申请实施例提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述实施例提供的应用于支付服务器的支付方法的步骤。In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the payment method applied to the payment server provided in the above embodiment are implemented.

第九方面,本申请实施例提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述实施例提供的应用于支付终端的支付方法的步骤。In a ninth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the payment method applied to the payment terminal provided in the above embodiment are implemented.

本申请实施例中,支付服务器接收到收款终端发送的支付请求时,通过向支付终端发送安全认证请求,以指示支付终端展示第一动态认证信息;以及,接收收款终端发送的反馈信息,根据反馈信息包括的收款终端基于支付终端展示的第一动态认证信息所采集到的第二动态认证信息,对支付终端进行安全认证;并在认证通过时执行支付交易,而非直接进行支付交易,有效的避免了恶意收款终端执行恶意收款操作现象的发生,从而确保了用户的财产安全,提升了移动支付的安全性。In an embodiment of the present application, when the payment server receives a payment request sent by a payment terminal, it sends a security authentication request to the payment terminal to instruct the payment terminal to display first dynamic authentication information; and, receives feedback information sent by the payment terminal, and performs security authentication on the payment terminal according to the second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information displayed by the payment terminal, which is included in the feedback information; and executes the payment transaction when the authentication is passed, rather than directly performing the payment transaction, effectively avoiding the occurrence of malicious payment terminals performing malicious payment operations, thereby ensuring the property safety of users and improving the security of mobile payments.

附图说明BRIEF DESCRIPTION OF THE DRAWINGS

为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请中记载的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

图1为本申请一个实施例提供的一种支付方法的应用场景示意图;FIG1 is a schematic diagram of an application scenario of a payment method provided by an embodiment of the present application;

图2为本申请一个实施例提供的一种应用于支付服务器的支付方法的流程示意图;FIG2 is a schematic diagram of a flow chart of a payment method applied to a payment server provided by an embodiment of the present application;

图3为本申请一个实施例提供的另一种应用于支付服务器的支付方法的流程示意图;FIG3 is a flow chart of another payment method applied to a payment server provided by an embodiment of the present application;

图4为本申请一个实施例提供的又一种应用于支付服务器的支付方法的流程示意图;FIG4 is a flow chart of another payment method applied to a payment server provided by an embodiment of the present application;

图5为本申请一个实施例提供的一种应用于支付终端的支付方法的流程示意图;FIG5 is a schematic diagram of a flow chart of a payment method applied to a payment terminal provided by an embodiment of the present application;

图6为本申请一个实施例提供的另一种应用于支付终端的支付方法的流程示意图;FIG6 is a flow chart of another payment method applied to a payment terminal provided by an embodiment of the present application;

图7为本申请一个实施例提供的一种支付服务器的结构示意图;FIG7 is a schematic diagram of the structure of a payment server provided by an embodiment of the present application;

图8为本申请一个实施例提供的一种支付终端的结构示意图;FIG8 is a schematic diagram of the structure of a payment terminal provided by an embodiment of the present application;

图9为本申请一个实施例提供的一种支付系统的结构示意图;FIG9 is a schematic diagram of the structure of a payment system provided by an embodiment of the present application;

图10为本申请一个实施例提供的另一种支付终端的结构示意图。FIG. 10 is a schematic diagram of the structure of another payment terminal provided in an embodiment of the present application.

具体实施方式Detailed ways

为了使本技术领域的人员更好地理解本申请中的技术方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。In order to enable those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.

附图1为本申请实施例提供的一种支付方法的应用场景示意图,如图1所示,场景包括:支付终端、收款终端和支付服务器;其中,支付终端可以为手机、平板电脑、台式计算机、便携笔记本式计算机等;收款终端具有扫描功能;支付服务器可以为独立的服务器,还可以为服务器集群等;支付终端和收款终端均通过无线网络与支付服务器进行通讯连接。Figure 1 is a schematic diagram of an application scenario of a payment method provided in an embodiment of the present application. As shown in Figure 1, the scenario includes: a payment terminal, a payment terminal and a payment server; wherein the payment terminal can be a mobile phone, a tablet computer, a desktop computer, a portable notebook computer, etc.; the payment terminal has a scanning function; the payment server can be an independent server or a server cluster, etc.; the payment terminal and the payment terminal are both connected to the payment server through a wireless network.

具体的,支付终端响应于用户的支付操作,展示支付凭证;收款终端扫描该支付凭证得到用户的支付相关信息,根据得到的支付相关信息和自身的终端标识生成支付信息,并根据该支付信息发送支付请求给支付服务器;支付服务器接收收款终端发送的支付请求,并向支付终端发送安全认证请求;支付终端根据接收的安全认证请求,展示第一动态认证信息;收款终端将基于第一动态认证信息所采集到的第二动态认证信息发送给支付服务器;支付服务器根据第一动态认证信息和第二动态认证信息对支付终端进行安全认证,并在认证通过时,根据支付请求包括的支付信息进行支付交易。由此,在支付服务器接收到收款终端发送的支付请求时,通过向支付终端发送安全认证请求以使支付终端展示第一动态认证信息,从而基于第一动态认证信息以及收款终端所采集到的第二动态认证信息对支付终端进行安全认证,并在认证通过时执行支付交易,而非直接进行支付交易,有效的避免了恶意收款终端执行恶意收款操作现象的发生,从而确保了用户的财产安全,提升了移动支付的安全性。Specifically, the payment terminal displays the payment voucher in response to the user's payment operation; the payment terminal scans the payment voucher to obtain the user's payment related information, generates payment information according to the obtained payment related information and its own terminal identification, and sends a payment request to the payment server according to the payment information; the payment server receives the payment request sent by the payment terminal and sends a security authentication request to the payment terminal; the payment terminal displays the first dynamic authentication information according to the received security authentication request; the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server; the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information, and performs a payment transaction according to the payment information included in the payment request when the authentication is passed. Therefore, when the payment server receives the payment request sent by the payment terminal, by sending a security authentication request to the payment terminal so that the payment terminal displays the first dynamic authentication information, the payment terminal is securely authenticated based on the first dynamic authentication information and the second dynamic authentication information collected by the payment terminal, and the payment transaction is executed when the authentication is passed, rather than directly performing the payment transaction, which effectively avoids the occurrence of malicious payment terminals performing malicious payment collection operations, thereby ensuring the property safety of users and improving the security of mobile payments.

基于上述应用场景架构,本申请一个实施例提供了一种支付方法,应用于图1所示应用场景中的支付服务器;图2为本申请一个实施例提供的一种应用于支付服务器的支付方法的流程示意图,参见图2,该方法包括如下步骤:Based on the above application scenario architecture, an embodiment of the present application provides a payment method, which is applied to the payment server in the application scenario shown in FIG1 ; FIG2 is a flow chart of a payment method applied to the payment server provided by an embodiment of the present application. Referring to FIG2 , the method includes the following steps:

步骤102,接收收款终端发送的支付请求,其中,支付请求包括收款终端基于支付终端展示的支付凭证所生成的支付信息;Step 102, receiving a payment request sent by a payment terminal, wherein the payment request includes payment information generated by the payment terminal based on a payment voucher displayed by the payment terminal;

具体而言,当用户需要为其所购买的商品、或者对其所享受的服务支付费用时,操作其支付终端所安装的具有支付功能的应用以进行费用支付,例如用户点击其支付终端所安装的具有支付功能的应用中的“付款”控件,以使支付终端展示支付凭证,其中,支付凭证如二维码、条形码等;支付终端响应于用户的操作,展示支付凭证;用户将其支付终端所展示的支付凭证提供给商户的收款终端,如将支付凭证对准收款终端的摄像头;收款终端从支付终端所展示的支付凭证中获取用户的支付相关信息,如支付金额、支付账户、支付终端的设备标识等信息;并根据获取的支付相关信息、收款终端的终端标识等生成支付信息,根据支付信息发送支付请求给支付服务器;支付服务器接收收款终端发送的支付请求。Specifically, when a user needs to pay for the goods he purchased or the services he enjoys, he operates the application with payment function installed on his payment terminal to make payment. For example, the user clicks the "Payment" control in the application with payment function installed on his payment terminal to make the payment terminal display the payment voucher, where the payment voucher is such as a QR code, barcode, etc.; the payment terminal displays the payment voucher in response to the user's operation; the user provides the payment voucher displayed by his payment terminal to the merchant's payment terminal, such as pointing the payment voucher at the camera of the payment terminal; the payment terminal obtains the user's payment-related information from the payment voucher displayed by the payment terminal, such as the payment amount, payment account, device identification of the payment terminal, etc.; and generates payment information based on the obtained payment-related information, the terminal identification of the payment terminal, etc., and sends a payment request to the payment server based on the payment information; the payment server receives the payment request sent by the payment terminal.

步骤104,向支付终端发送安全认证请求;其中,安全认证请求用于指示支付终端展示第一动态认证信息;Step 104, sending a security authentication request to the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information;

考虑到用户所在的环境中可能存在恶意收款终端,如他人恶意隐藏的摄像头等,该恶意收款终端可能获取用户的支付终端所展示的支付凭证而进行恶意收款操作,从而为用户造成经济损失;基于此,为提升支付安全,本申请实施例中,在支付服务器接收到收款终端发送的支付请求时,向支付终端发送安全认证请求,以使支付终端展示第一动态认证信息,并基于该第一动态认证信息对支付终端进行安全认证。Taking into account that there may be malicious payment terminals in the user's environment, such as cameras maliciously hidden by others, the malicious payment terminal may obtain the payment credentials displayed by the user's payment terminal and perform malicious payment operations, thereby causing economic losses to the user; based on this, in order to improve payment security, in an embodiment of the present application, when the payment server receives a payment request sent by the payment terminal, it sends a security authentication request to the payment terminal, so that the payment terminal displays the first dynamic authentication information, and performs security authentication on the payment terminal based on the first dynamic authentication information.

可选地,安全认证请求包括第一预设时长的视频,或者固定排序方式的数张图片,或者连续的变换指令等。Optionally, the security authentication request includes a video of a first preset length, or a plurality of pictures in a fixed order, or continuous transformation instructions, etc.

作为一个示例,安全认证请求包括第一预设时长的视频,对应的,第一动态认证信息包括该第一预设时长的视频,步骤104包括:支付服务器随机生成第一预设时长的视频,根据生成的第一预设时长的视频和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求;或者,支付服务器在指定的多个第一预设时长的视频中随机选取一个视频,并根据选取的视频和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求;或者,支付服务器在指定的第三预设时长的视频中,随机截取第一预设时长的视频,并根据截取的视频和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求;其中,第三预设时长大于第一预设时长。As an example, the security authentication request includes a video of a first preset length, and correspondingly, the first dynamic authentication information includes the video of the first preset length. Step 104 includes: the payment server randomly generates a video of the first preset length, and sends a security authentication request to the corresponding payment terminal based on the generated video of the first preset length and the terminal identifier of the payment terminal included in the payment information; or, the payment server randomly selects a video from a plurality of specified videos of the first preset length, and sends a security authentication request to the corresponding payment terminal based on the selected video and the terminal identifier of the payment terminal included in the payment information; or, the payment server randomly intercepts a video of the first preset length from a specified video of a third preset length, and sends a security authentication request to the corresponding payment terminal based on the intercepted video and the terminal identifier of the payment terminal included in the payment information; wherein the third preset length is greater than the first preset length.

作为另一示例,安全认证请求包括固定排序方式的数张图片,对应的,第一动态认证信息包括该固定排序方式的数张图片,步骤104包括:支付服务器随机生成数张图片,按照第一预设排序方式对该数张图片进行排序,并根据排序后的数张图片和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求;或者,支付服务器从指定的图片库中随机选取数张图片,按照第一预设排序方式对该数张图片进行排序,并根据排序后的数张图片和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求,其中,图片库中包括大量图片;或者,支付服务器从指定的多组图片中,随机选取一组图片,并根据选择的一组图片和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求,其中,每组图片中包括固定排序方式的数张图片。As another example, the security authentication request includes several pictures in a fixed sorting manner, and correspondingly, the first dynamic authentication information includes several pictures in the fixed sorting manner. Step 104 includes: the payment server randomly generates several pictures, sorts the pictures according to a first preset sorting manner, and sends a security authentication request to the corresponding payment terminal based on the sorted pictures and the terminal identification of the payment terminal included in the payment information; or, the payment server randomly selects several pictures from a specified picture library, sorts the pictures according to a first preset sorting manner, and sends a security authentication request to the corresponding payment terminal based on the sorted pictures and the terminal identification of the payment terminal included in the payment information, wherein the picture library includes a large number of pictures; or, the payment server randomly selects a group of pictures from a specified plurality of groups of pictures, and sends a security authentication request to the corresponding payment terminal based on the selected group of pictures and the terminal identification of the payment terminal included in the payment information, wherein each group of pictures includes several pictures in a fixed sorting manner.

作为另一示例,安全认证请求包括连续的变换指令,对应的,第一动态认证信息包括根据该变换指令对支付凭证进行变化而得的信息,例如根据变换指令对支付凭证进行连续的旋转、重新合成等变换;步骤104包括:支付服务器从指定的指令库中随机选取预设数量的变换指令,根据第二预设排序方式对选取的变换指令排序得到连续的变换指令,并根据连续的变换指令和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求;或者,支付服务器从指定的多组指令中,随机选取一组指令,并根据选取的一组指令和支付信息所包括的支付终端的终端标识,向对应的支付终端发送安全认证请求,其中,每组指令中包括连续的多个指令。As another example, the security authentication request includes continuous transformation instructions, and correspondingly, the first dynamic authentication information includes information obtained by changing the payment credential according to the transformation instruction, such as continuously rotating, resynthesizing, and other transformations of the payment credential according to the transformation instruction; step 104 includes: the payment server randomly selects a preset number of transformation instructions from a specified instruction library, sorts the selected transformation instructions according to a second preset sorting method to obtain continuous transformation instructions, and sends a security authentication request to the corresponding payment terminal based on the continuous transformation instructions and the terminal identification of the payment terminal included in the payment information; or, the payment server randomly selects a group of instructions from a specified plurality of groups of instructions, and sends a security authentication request to the corresponding payment terminal based on the selected group of instructions and the terminal identification of the payment terminal included in the payment information, wherein each group of instructions includes a plurality of continuous instructions.

需要指出的是,上述第一预设排序方式、第二预设排序方式、第一预设时长、第三预设时长、预设数量等均可在实际应用中根据需要自行设定;其中,第一预设排序方式与第二预设排序方式可以相同也可以不同,例如,均为根据选取顺序进行排序等。It should be pointed out that the above-mentioned first preset sorting method, second preset sorting method, first preset duration, third preset duration, preset quantity, etc. can all be set according to needs in actual applications; among them, the first preset sorting method and the second preset sorting method can be the same or different, for example, both are sorted according to the selection order, etc.

进一步的,为了避免因用户没有及时的将支付终端所展示的第一动态认证信息提供给收款终端,而导致认证失败,如图3所示,本说明书一个实施例中,步骤104包括:Further, in order to avoid authentication failure due to the user not providing the first dynamic authentication information displayed by the payment terminal to the payment terminal in a timely manner, as shown in FIG3 , in one embodiment of this specification, step 104 includes:

步骤104-2,向支付终端发送安全认证提示信息,以使支付终端提示用户进行安全认证;Step 104-2, sending security authentication prompt information to the payment terminal, so that the payment terminal prompts the user to perform security authentication;

步骤104-4,若接收到支付终端发送的提示完毕信息,则向支付终端发送安全认证请求;其中,安全认证请求用于指示支付终端展示第一动态认证信息。Step 104 - 4 , if the prompt completion information sent by the payment terminal is received, a security authentication request is sent to the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information.

通过预先向支付终端发送安全认证提示信息,使得支付终端能够对用户进行提示,以确保用户及时的将支付终端的展示界面展示给收款终端,确保安全认证的顺利进行。By sending security authentication prompt information to the payment terminal in advance, the payment terminal can prompt the user to ensure that the user displays the display interface of the payment terminal to the payment terminal in time to ensure the smooth progress of security authentication.

步骤106,接收收款终端发送的反馈信息,其中,反馈信息包括收款终端基于第一动态认证信息所采集到的第二动态认证信息;Step 106, receiving feedback information sent by the payment terminal, wherein the feedback information includes second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information;

具体而言,当支付终端接收到支付服务器发送的安全认证请求时,根据安全认证请求展示第一动态认证信息,收款终端基于支付终端所展示的第一动态认证信息采集第二动态认证信息,并根据采集到的第二动态认证信息发送反馈信息给支付服务器,支付服务器接收收款终端发送的反馈信息;其中,反馈信息还可以包括收款终端的终端标识等信息。Specifically, when the payment terminal receives a security authentication request sent by the payment server, it displays the first dynamic authentication information according to the security authentication request, the payment terminal collects the second dynamic authentication information based on the first dynamic authentication information displayed by the payment terminal, and sends feedback information to the payment server based on the collected second dynamic authentication information, and the payment server receives the feedback information sent by the payment terminal; wherein the feedback information may also include information such as the terminal identification of the payment terminal.

步骤108,根据第一动态认证信息和第二动态认证信息,对支付终端进行安全认证;Step 108, performing security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information;

为了使支付服务器对各支付请求进行有效区分,从而对对应的支付终端进行安全认证,进而进行准确的支付交易,如图4所示,步骤104之后还包括:In order to enable the payment server to effectively distinguish each payment request, thereby performing security authentication on the corresponding payment terminal and then performing an accurate payment transaction, as shown in FIG. 4 , after step 104, the following steps are further included:

步骤105,将第一动态认证信息或者第一动态认证信息的索引信息与支付信息关联保存;Step 105, the first dynamic authentication information or the index information of the first dynamic authentication information is associated with the payment information and saved;

可选地,当安全认证请求包括第一预设时长的视频时,支付服务器向支付终端发送安全认证请求之后,将该第一预设时长的视频作为第一动态认证信息,将第一动态认证信息与支付信息关联保存;或者,将随机选择的视频的预设索引信息与支付信息关联保存。当安全认证请求包括固定排序方式的数张图片时,支付服务器向支付终端发送安全认证请求之后,将该固定排序方式的数张图片作为第一动态认证信息,将第一动态认证信息与支付信息关联保存;或者,按照该数张图片的排序方式对预设的该数张图片的索引信息排序,并将排序后的索引信息与支付信息关联保存;或者,将选取的一组图片的预设的索引信息与支付信息关联保存。当安全认证请求包括连续的变换指令时,支付服务器向支付终端发送安全认证请求之后,根据该连续的变换指令依次对支付信息中的支付凭证进行变换得到第一动态认证信息,将得到的第一动态认证信息与支付信息关联保存;或者,将该连续的变换指令作为第一动态认证信息的索引信息,将索引信息与支付信息关联保存。Optionally, when the security authentication request includes a video of a first preset duration, after the payment server sends the security authentication request to the payment terminal, the video of the first preset duration is used as the first dynamic authentication information, and the first dynamic authentication information is associated with the payment information and saved; or, the preset index information of the randomly selected video is associated with the payment information and saved. When the security authentication request includes several pictures in a fixed sorting method, after the payment server sends the security authentication request to the payment terminal, the several pictures in the fixed sorting method are used as the first dynamic authentication information, and the first dynamic authentication information is associated with the payment information and saved; or, the preset index information of the several pictures is sorted according to the sorting method of the several pictures, and the sorted index information is associated with the payment information and saved; or, the preset index information of a selected group of pictures is associated with the payment information and saved. When the security authentication request includes continuous transformation instructions, after the payment server sends the security authentication request to the payment terminal, the payment credentials in the payment information are transformed in sequence according to the continuous transformation instructions to obtain first dynamic authentication information, and the obtained first dynamic authentication information is associated with the payment information and saved; or, the continuous transformation instructions are used as index information of the first dynamic authentication information, and the index information is associated with the payment information and saved.

与步骤105对应的,如图4所示,步骤108包括:Corresponding to step 105, as shown in FIG4 , step 108 includes:

步骤108-2,根据反馈信息包括的收款终端的终端标识,确定关联的第一动态认证信息;Step 108-2, determining the associated first dynamic authentication information according to the terminal identification of the payment terminal included in the feedback information;

可选地,根据反馈信息包括的收款终端的终端标识,查询关联保存的第一动态认证信息;或者,根据反馈信息包括的收款终端的终端标识,查询关联保存的索引信息,根据查询到的索引信息,获取对应的第一动态认证信息。Optionally, according to the terminal identification of the payment terminal included in the feedback information, the associated saved first dynamic authentication information is queried; or, according to the terminal identification of the payment terminal included in the feedback information, the associated saved index information is queried, and the corresponding first dynamic authentication information is obtained according to the queried index information.

步骤108-4,根据确定的第一动态认证信息和接收的第二动态认证信息,对支付终端进行安全认证。Step 108 - 4 , performing security authentication on the payment terminal according to the determined first dynamic authentication information and the received second dynamic authentication information.

进一步的,考虑到由于支付终端根据安全认证请求展示第一动态认证信息的速度较快,当用户没有及时的将支付终端所展示的第一动态信息提供给收款终端时,收款终端很可能没有采集到第一帧视频或者第一张图片,从而导致后续安全认证失败;基于此,本申请实施例中,支付终端在接收到安全认证请求时,在第二预设时长内重复的展示第一动态认证,以确保收款终端能够采集到至少一个完整的第一动态认证信息;其中,第二预设时长大于第一预设时长,其在实际应用中可以根据需要自行设定,确保能够多次的展示第一动态认证信息即可。与之对应的,若安全认证请求包括第一动态认证信息,第一动态认证信息包括第一预设时长的视频或固定排序方式的数张图片等,则步骤108进一步包括:Furthermore, considering that the payment terminal displays the first dynamic authentication information at a high speed according to the security authentication request, when the user fails to provide the first dynamic information displayed by the payment terminal to the payment terminal in a timely manner, the payment terminal is likely to fail to collect the first frame of video or the first picture, thereby causing the subsequent security authentication to fail; based on this, in the embodiment of the present application, upon receiving the security authentication request, the payment terminal repeatedly displays the first dynamic authentication within the second preset time length to ensure that the payment terminal can collect at least one complete first dynamic authentication information; wherein, the second preset time length is greater than the first preset time length, and it can be set as needed in actual applications to ensure that the first dynamic authentication information can be displayed multiple times. Correspondingly, if the security authentication request includes the first dynamic authentication information, and the first dynamic authentication information includes a video of the first preset time length or a number of pictures in a fixed order, etc., then step 108 further includes:

确定第二动态认证信息中是否包括第一动态认证信息,若是,则确定认证通过;若否,则确定认证未通过。Determine whether the second dynamic authentication information includes the first dynamic authentication information, and if so, determine that the authentication is successful; if not, determine that the authentication is not successful.

例如,第一动态认证信息包括3张图片,为便于描述,按照排序方式依次将该3张图片分别记为图片1、图片2、图片3,即第一动态认证信息为“图片1-图片2-图片3”;第二动态认证信息所包括的图片顺序为“图片1-图片2-图片3-图片1-图片2”,第二动态认证信息中包括第一动态认证信息,确定认证通过;又如,第二动态认证信息所包括的图片顺序为“图片2-图片3-图片1-图片2-图片3”,第二动态认证信息中包括第一动态认证信息,确定认证通过。For example, the first dynamic authentication information includes three pictures. For the convenience of description, the three pictures are recorded as Picture 1, Picture 2, and Picture 3 in order according to the sorting method, that is, the first dynamic authentication information is "Picture 1-Picture 2-Picture 3"; the order of pictures included in the second dynamic authentication information is "Picture 1-Picture 2-Picture 3-Picture 1-Picture 2", and the second dynamic authentication information includes the first dynamic authentication information, determining that the authentication is successful; for another example, the order of pictures included in the second dynamic authentication information is "Picture 2-Picture 3-Picture 1-Picture 2-Picture 3", and the second dynamic authentication information includes the first dynamic authentication information, determining that the authentication is successful.

进一步的,若安全认证请求包括连续的变换指令,则步骤108包括:Furthermore, if the security authentication request includes continuous transformation instructions, step 108 includes:

确定第二动态认证信息中是否包括变换指令所对应的第一动态认证信息,若是,则确定认证通过;若否,则确定认证未通过。It is determined whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction. If so, it is determined that the authentication is passed; if not, it is determined that the authentication is not passed.

由此,基于第一动态认证信息和第二动态认证信息对支付终端进行安全认证,有效的避免了恶意收款终端进行恶意收款操作现象的发生,确保了用户的财产安全,提升了移动支付的安全性。Therefore, the payment terminal is securely authenticated based on the first dynamic authentication information and the second dynamic authentication information, which effectively avoids the occurrence of malicious payment terminal performing malicious payment operations, ensures the property safety of the user, and improves the security of mobile payment.

步骤110,若认证通过,则根据支付信息进行支付交易。Step 110: If the authentication is successful, the payment transaction is performed according to the payment information.

具体的,若认证通过,则从支付信息中获取支付金额、支付账户和收款账户;根据获取的支付金额、支付账户和收款账户,进行支付交易;以在支付账户中扣除支付金额对应的钱款,并在收款账户中增加支付金额对应的钱款。Specifically, if the authentication is passed, the payment amount, payment account and receiving account are obtained from the payment information; the payment transaction is performed based on the obtained payment amount, payment account and receiving account; the money corresponding to the payment amount is deducted from the payment account, and the money corresponding to the payment amount is added to the receiving account.

为了使用户和商户知晓支付结果,步骤110之后,还包括:分别向收款终端和支付终端发送支付结果。In order to let the user and the merchant know the payment result, after step 110, the process further includes: sending the payment result to the payment terminal and the payment terminal respectively.

本申请实施例提供的应用于支付服务器的支付方法中,在支付服务器接收到收款终端发送的支付请求时,通过向支付终端发送安全认证请求,以指示支付终端展示第一动态认证信息;以及,接收收款终端发送的反馈信息,根据反馈信息包括的收款终端基于支付终端展示的第一动态认证信息所采集到的第二动态认证信息,对支付终端进行安全认证;并在认证通过时执行支付交易,而非直接进行支付交易,有效的避免了恶意收款终端执行恶意收款操作现象的发生,从而确保了用户的财产安全,提升了移动支付的安全性。In the payment method applied to the payment server provided in the embodiment of the present application, when the payment server receives a payment request sent by the payment terminal, it sends a security authentication request to the payment terminal to instruct the payment terminal to display first dynamic authentication information; and receives feedback information sent by the payment terminal, and performs security authentication on the payment terminal according to the second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information displayed by the payment terminal included in the feedback information; and executes the payment transaction when the authentication is passed instead of directly performing the payment transaction, which effectively avoids the occurrence of malicious payment terminals performing malicious payment collection operations, thereby ensuring the property safety of users and improving the security of mobile payments.

对应上述图2至图4描述的支付方法,本申请一个实施例还提供另一种支付方法,应用于图1所示应用场景中的支付终端;图5为本申请一个实施例提供的一种应用于支付终端的支付方法的流程示意图,参见图5,该方法包括如下步骤:Corresponding to the payment method described in Figures 2 to 4 above, an embodiment of the present application also provides another payment method, which is applied to the payment terminal in the application scenario shown in Figure 1; Figure 5 is a flow chart of a payment method applied to a payment terminal provided by an embodiment of the present application. Referring to Figure 5, the method includes the following steps:

步骤202,响应于用户的支付操作,展示支付凭证,以使收款终端基于支付凭证生成支付信息,并根据支付信息向支付服务器发送支付请求;Step 202, in response to the user's payment operation, display the payment voucher so that the payment terminal generates payment information based on the payment voucher and sends a payment request to the payment server according to the payment information;

具体而言,当用户需要为其所购买的商品、或者对其所享受的服务支付费用时,操作其支付终端所安装的具有支付功能的应用以进行费用支付,例如用户点击其支付终端所安装的具有支付功能的应用中的“付款”控件,以使支付终端展示支付凭证,其中,支付凭证如二维码、条形码等,支付凭证包括支付账户、支付金额、支付终端的终端标识等信息;支付终端响应于用户的支付操作,展示支付凭证。Specifically, when a user needs to pay for the goods he purchased or the services he enjoys, he operates the application with payment function installed on his payment terminal to make payment. For example, the user clicks the "Payment" control in the application with payment function installed on his payment terminal to make the payment terminal display the payment voucher, where the payment voucher is such as a QR code, barcode, etc., and the payment voucher includes information such as the payment account, payment amount, and terminal identification of the payment terminal; the payment terminal displays the payment voucher in response to the user's payment operation.

步骤204,接收支付服务器发送的安全认证请求;Step 204, receiving a security authentication request sent by the payment server;

为了避免恶意收款终端进行恶意收款操作,本申请实施例中支付服务器接收到收款终端发送的支付请求时,根据支付信息所包括的支付终端的终端标识向对应的支付终端发送安全认证请求,以对支付终端进行安全认证。In order to prevent malicious payment terminals from performing malicious payment operations, in an embodiment of the present application, when the payment server receives a payment request sent by the payment terminal, it sends a security authentication request to the corresponding payment terminal based on the terminal identifier of the payment terminal included in the payment information to perform security authentication on the payment terminal.

可选地,安全认证请求包括支付终端的终端标识,对应的,步骤204之后还包括:Optionally, the security authentication request includes a terminal identification of the payment terminal. Accordingly, after step 204, the following steps are further included:

确定安全认证请求包括的支付终端的终端标识与自身的终端标识是否一致,若一致,则执行步骤206;若不一致则发送认证失败信息给支付服务器,以使支付服务器发送支付失败的支付结果给收款终端。Determine whether the terminal identification of the payment terminal included in the security authentication request is consistent with its own terminal identification. If they are consistent, execute step 206; if they are inconsistent, send authentication failure information to the payment server, so that the payment server sends the payment result of payment failure to the payment terminal.

步骤206,根据安全认证请求,展示第一动态认证信息,以使收款终端将基于第一动态认证信息所采集到的第二动态认证信息发送给支付服务器,使支付服务器根据第一动态认证信息和第二动态认证信息对支付终端进行安全认证。Step 206, based on the security authentication request, the first dynamic authentication information is displayed, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal based on the first dynamic authentication information and the second dynamic authentication information.

可选地,步骤206中根据安全认证请求,展示第一动态认证信息,包括:Optionally, in step 206, displaying the first dynamic authentication information according to the security authentication request includes:

步骤206-2,从安全认证请求中获取第一动态认证信息,其中,第一动态认证信息包括第一预设时长的视频或固定排序方式的数张图片;Step 206-2, obtaining first dynamic authentication information from the security authentication request, wherein the first dynamic authentication information includes a video of a first preset duration or a plurality of pictures in a fixed order;

步骤206-4,在第二预设时长内重复的展示获取的第一预设时长的视频或固定排序方式的数张图片;其中,第二预设时长大于第一预设时长。Step 206-4, repeatedly displaying the obtained video of the first preset duration or the plurality of pictures in a fixed order within a second preset duration; wherein the second preset duration is greater than the first preset duration.

具体的,在第二预设时长内重复的展示获取的第一预设时长的视频;或者,根据获取的图片的排序方式,在第二预设时长内重复的依次展示各图片;例如,获取的固定排序方式的数张图片依次为图片1、图片2、图片3,则在第二预设时长内依次展示图片1、图片2、图片3、图片1、图片2等。Specifically, the acquired video of the first preset duration is repeatedly displayed within the second preset duration; or, according to the sorting method of the acquired pictures, each picture is repeatedly displayed in sequence within the second preset duration; for example, the acquired pictures in a fixed sorting method are picture 1, picture 2, picture 3, then picture 1, picture 2, picture 3, picture 1, picture 2, etc. are displayed in sequence within the second preset duration.

可选地,步骤206中根据安全认证请求,展示第一动态认证信息,包括:Optionally, in step 206, displaying the first dynamic authentication information according to the security authentication request includes:

步骤206-2`,从安全认证请求中获取连续的变换指令;Step 206-2, obtaining continuous transformation instructions from the security authentication request;

步骤206-4`,根据获取的变换指令对支付凭证进行变换,得到第一动态认证信息;Step 206-4, transforming the payment credential according to the acquired transformation instruction to obtain first dynamic authentication information;

具体的,按照连续的变换指令中各指令的先后顺序,依次根据各变换指令对支付凭证进行变换,得到第一动态认证信息;例如,获取的连续的变换指令依次为指令1、指令2、指令3,则依次根据指令1、指令2、指令3对支付凭证进行变换,如根据变换指令对支付凭证进行旋转、翻转、重新合成等变换。Specifically, according to the sequence of each instruction in the continuous transformation instructions, the payment credential is transformed in accordance with each transformation instruction in sequence to obtain the first dynamic authentication information; for example, the continuous transformation instructions obtained are instruction 1, instruction 2, and instruction 3 in sequence, then the payment credential is transformed in accordance with instruction 1, instruction 2, and instruction 3 in sequence, such as rotating, flipping, resynthesizing, etc. the payment credential according to the transformation instructions.

步骤206-6`,在第二预设时长内重复的展示第一动态认证信息。Step 206-6', repeatedly displaying the first dynamic authentication information within a second preset time period.

支付终端通过在第二预设时长内,根据安全认证请求重复的展示第一动态认证信息,以确保收款设备能够采集到至少一个完整的第一动态认证信息,从而确保安全认证操作的顺利进行,进而顺利完成支付。The payment terminal repeatedly displays the first dynamic authentication information according to the security authentication request within the second preset time period to ensure that the payment device can collect at least one complete first dynamic authentication information, thereby ensuring the smooth progress of the security authentication operation and successfully completing the payment.

进一步的,为了避免由于用户没有及时的将支付终端所展示的第一动态认证信息提供的收款终端,而导致安全认证失败,如图6所示,本申请一个实施例中,步骤204之前还包括:Further, in order to avoid the security authentication failure caused by the user not providing the first dynamic authentication information displayed by the payment terminal to the payment terminal in time, as shown in FIG6 , in one embodiment of the present application, before step 204, the following is further included:

步骤203-2,接收支付服务器发送的安全认证提示信息;Step 203-2, receiving security authentication prompt information sent by the payment server;

步骤203-4,按照第一预设提示方式提示用户进行安全认证;Step 203-4, prompting the user to perform security authentication according to the first preset prompting method;

其中,第一预设提示方式如震动提示、声音提示等,其可在实际应用中根据需要自行设定。Among them, the first preset prompt mode, such as vibration prompt, sound prompt, etc., can be set according to needs in actual application.

步骤203-6,向支付服务器发送提示完毕信息,以使支付服务器对支付终端进行安全认证。Step 203-6, sending a prompt completion message to the payment server so that the payment server can perform security authentication on the payment terminal.

由此,通过提示用户进行安全认证,使得用户能够及时的将支付终端的展示界面展示给收款设备,使收款设备采集到完整的认证信息,确保安全认证的顺利进行。Therefore, by prompting the user to perform security authentication, the user can promptly display the display interface of the payment terminal to the payment device, so that the payment device can collect complete authentication information, ensuring the smooth progress of security authentication.

为了使用户知晓支付结构,支付服务器在进行支付交易之后,还向支付终端发送支付结果,对应的,步骤206之后,还包括:In order to make the user aware of the payment structure, the payment server further sends the payment result to the payment terminal after the payment transaction. Correspondingly, after step 206, the following steps are also included:

步骤208,接收支付服务器发送的支付结果;Step 208, receiving the payment result sent by the payment server;

步骤210,按照第二预设方式提示用户认证完毕,并根据支付结果,展示支付成功信息或支付失败信息。Step 210, prompting the user that authentication is complete in accordance with the second preset method, and displaying payment success information or payment failure information according to the payment result.

其中,第二预设方式与前述第一预设方式可以相同,也可以不同;本实施例中,通过提示用户认证完毕,能够避免用户因不知是否认证结束而长时间的将支付终端的展示界面展示给收款终端,有利于提升用户体验。Among them, the second preset method can be the same as or different from the aforementioned first preset method; in this embodiment, by prompting the user that the authentication is completed, it can avoid the user from showing the display interface of the payment terminal to the payment terminal for a long time because he does not know whether the authentication is completed, which is conducive to improving the user experience.

本申请实施例提供的应用于支付终端的支付方法中,支付终端基于支付服务器发送的安全认证请求展示第一动态认证信息,以使收款终端将基于第一动态认证信息所采集到的第二动态认证信息发送给支付服务器,从而使支付服务器根据第一动态认证信息和第二动态认证信息对支付终端进行安全认证,并在认证通过后进行支付交易。可见,通过本申请实施例,能够有效的避免恶意收款终端执行恶意收款的行为,从而确保了用户的财产安全,提升了移动支付的安全性。In the payment method applied to the payment terminal provided in the embodiment of the present application, the payment terminal displays the first dynamic authentication information based on the security authentication request sent by the payment server, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information, and performs the payment transaction after the authentication is passed. It can be seen that through the embodiment of the present application, malicious payment terminals can be effectively prevented from performing malicious payment collection behaviors, thereby ensuring the property safety of users and improving the security of mobile payments.

对应上述图2至图4描述的支付方法,基于相同的技术构思,本申请实施例还提供一种支付服务器,如图7所示,支付服务器300包括:Corresponding to the payment method described in FIGS. 2 to 4 above, based on the same technical concept, the embodiment of the present application further provides a payment server, as shown in FIG. 7 , the payment server 300 includes:

接收模块301,用于接收收款终端发送的支付请求,其中,所述支付请求包括所述收款终端基于支付终端展示的支付凭证所生成的支付信息;The receiving module 301 is used to receive a payment request sent by a payment terminal, wherein the payment request includes payment information generated by the payment terminal based on the payment voucher displayed by the payment terminal;

发送模块302,用于向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息;A sending module 302, configured to send a security authentication request to the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information;

所述接收模块301,还用于接收所述收款设备发送的反馈信息,其中,所述反馈信息包括所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;The receiving module 301 is further configured to receive feedback information sent by the payment receiving device, wherein the feedback information includes second dynamic authentication information collected by the payment receiving terminal based on the first dynamic authentication information;

认证模块303,用于根据所述第一动态认证信息和所述第二动态认证信息,对所述支付终端进行安全认证;An authentication module 303, configured to perform security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information;

处理模块304,用于在所述认证模块认证通过时,根据所述支付信息进行支付交易。The processing module 304 is used to perform a payment transaction according to the payment information when the authentication module passes the authentication.

可选的,所述支付信息包括所述收款终端的终端标识,所述反馈信息还包括所述收款终端的终端标识;所述支付服务器还包括:保存模块;Optionally, the payment information includes a terminal identifier of the payment terminal, and the feedback information also includes a terminal identifier of the payment terminal; the payment server further includes: a storage module;

所述保存模块,用于将所述第一动态认证信息或者所述第一动态认证信息的索引信息与所述支付信息关联保存;The storage module is used to associate and store the first dynamic authentication information or the index information of the first dynamic authentication information with the payment information;

对应的,所述认证模块303,用于根据所述反馈信息包括的所述收款终端的终端标识,确定关联的第一动态认证信息;以及,Correspondingly, the authentication module 303 is used to determine the associated first dynamic authentication information according to the terminal identification of the payment terminal included in the feedback information; and

根据确定的第一动态认证信息和接收的所述第二动态认证信息,对所述支付终端进行安全认证。Perform security authentication on the payment terminal according to the determined first dynamic authentication information and the received second dynamic authentication information.

可选地,所述安全认证请求包括所述第一动态认证信息,所述第一动态认证信息包括第一预设时长的视频或固定排序方式的数张图片;Optionally, the security authentication request includes the first dynamic authentication information, and the first dynamic authentication information includes a video of a first preset duration or a plurality of pictures in a fixed order;

所述认证模块303,用于确定所述第二动态认证信息中是否包括所述第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过。The authentication module 303 is used to determine whether the second dynamic authentication information includes the first dynamic authentication information; if so, determine that the authentication is successful; if not, determine that the authentication is not successful.

可选地,所述安全认证请求包括连续的变换指令;Optionally, the security authentication request includes continuous transformation instructions;

所述认证模块303,用于确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过。The authentication module 303 is used to determine whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, it is determined that the authentication is passed; if not, it is determined that the authentication is not passed.

可选地,所述发送模块302,具体用于向所述支付终端发送安全认证提示信息,以使所述支付终端提示用户进行安全认证;以及,Optionally, the sending module 302 is specifically configured to send security authentication prompt information to the payment terminal, so that the payment terminal prompts the user to perform security authentication; and

若接收到所述支付终端发送的提示完毕信息,则向所述支付终端发送安全认证请求。If the prompt completion information sent by the payment terminal is received, a security authentication request is sent to the payment terminal.

可选地,所述处理模块304,从所述支付信息中获取支付金额、支付账户和收款账户;以及,Optionally, the processing module 304 obtains the payment amount, the payment account and the receiving account from the payment information; and

根据所述支付金额、所述支付账户和所述收款账户,进行支付交易。A payment transaction is performed based on the payment amount, the payment account and the receiving account.

可选地,所述发送模块302,还用于在所述处理模块304根据所述支付信息进行支付交易之后,分别向所述收款终端和所述支付终端发送支付结果。Optionally, the sending module 302 is further configured to send payment results to the payment terminal and the payment terminal respectively after the processing module 304 performs a payment transaction according to the payment information.

本申请实施例提供的支付服务器,在接收到收款终端发送的支付请求时,向支付终端发送安全认证请求,以指示支付终端展示第一动态认证信息;以及,接收收款终端发送的反馈信息,根据反馈信息包括的收款终端基于支付终端展示的第一动态认证信息所采集到的第二动态认证信息,对支付终端进行安全认证;并在认证通过时执行支付交易,而非直接进行支付交易,有效的避免了恶意收款终端执行恶意收款操作现象的发生,确保了用户的财产安全,提升了移动支付的安全性。The payment server provided in the embodiment of the present application, when receiving a payment request sent by a payment terminal, sends a security authentication request to the payment terminal to instruct the payment terminal to display first dynamic authentication information; and, receives feedback information sent by the payment terminal, and performs security authentication on the payment terminal according to the second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information displayed by the payment terminal included in the feedback information; and executes the payment transaction when the authentication is passed, rather than directly performing the payment transaction, effectively avoiding the occurrence of malicious payment terminals performing malicious payment operations, ensuring the property safety of users, and improving the security of mobile payments.

本申请实施例提供的支付服务器能够实现图2至图4的方法实施例中支付服务器实现的各个过程,为避免重复,这里不再赘述。而且,应当注意的是,本申请的支付服务器的各个部件中,根据其要实现的功能而对其中的部件进行了逻辑划分,但是,本申请不受限于此,可以根据需要对各个部件进行重新划分或组合。The payment server provided in the embodiment of the present application can implement the various processes implemented by the payment server in the method embodiments of Figures 2 to 4. To avoid repetition, they are not described here. In addition, it should be noted that the various components of the payment server of the present application are logically divided according to the functions to be implemented, but the present application is not limited thereto, and the various components can be re-divided or combined as needed.

进一步的,本申请实施例还提供一种支付服务器,包括处理器、存储器及存储在存储器上并可在处理器上运行的计算机程序,该计算机程序被处理器执行时实现上述应用于支付服务器的支付方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。Furthermore, an embodiment of the present application also provides a payment server, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned payment method embodiment applied to the payment server are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

另外,本申请实施例还提供一种计算机可读存储介质,计算机可读存储介质上存储计算机程序,该计算机程序被处理器执行时实现上述应用于支付服务器的支付方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。In addition, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned payment method embodiment applied to the payment server are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

进一步的,对应上述图5和图6描述的支付方法,基于相同的技术构思,本申请实施例还提供一种支付终端,如图8所示,支付终端400包括:Further, corresponding to the payment method described in FIG. 5 and FIG. 6 , based on the same technical concept, the embodiment of the present application further provides a payment terminal, as shown in FIG. 8 , where the payment terminal 400 includes:

展示模块401,用于响应于用户的支付操作,展示支付凭证,以使收款终端基于所述支付凭证生成支付信息,并根据所述支付信息向支付服务器发送支付请求;A display module 401 is used to display the payment voucher in response to the user's payment operation, so that the payment terminal generates payment information based on the payment voucher and sends a payment request to the payment server according to the payment information;

接收模块402,用于接收所述支付服务器发送的安全认证请求;Receiving module 402, used to receive the security authentication request sent by the payment server;

展示模块401,还用于根据所述安全认证请求,展示第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器,使所述支付服务器根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端进行安全认证。The display module 401 is also used to display the first dynamic authentication information according to the security authentication request, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information.

可选地,所述展示模块401,从所述安全认证信息中获取第一动态认证信息,所述第一动态认证信息包括第一预设时长的视频或固定排序方式的数张图片;以及,Optionally, the display module 401 obtains first dynamic authentication information from the security authentication information, where the first dynamic authentication information includes a video of a first preset duration or a plurality of pictures in a fixed order; and

在第二预设时长内重复的展示获取的所述第一预设时长的视频或固定排序方式的数张图片;其中,所述第二预设时长大于所述第一预设时长。Repeatedly display the video of the first preset duration or several pictures in a fixed order obtained within a second preset duration; wherein the second preset duration is greater than the first preset duration.

可选的,所述展示模块401,从所述安全认证信息中获取连续的变换指令;以及,Optionally, the display module 401 obtains continuous transformation instructions from the security authentication information; and

根据所述变换指令对所述支付凭证进行变换,得到第一动态认证信息;transforming the payment credential according to the transformation instruction to obtain first dynamic authentication information;

在第二预设时长内重复的展示得到的所述第一动态认证信息。The first dynamic authentication information obtained is repeatedly displayed within a second preset time period.

可选地,支付终端还包括:第一提示模块和发送模块;Optionally, the payment terminal further includes: a first prompting module and a sending module;

对应的,所述接收模块402,在接收所述支付服务器发送的安全认证请求之前,还接收所述支付服务器发送的安全认证提示信息;Correspondingly, the receiving module 402, before receiving the security authentication request sent by the payment server, also receives security authentication prompt information sent by the payment server;

所述第一提示模块,按照第一预设提示方式提示用户进行安全认证;The first prompt module prompts the user to perform security authentication according to a first preset prompt method;

所述发送模块,向所述支付服务器发送提示完毕信息,以使所述支付服务器对所述支付终端进行安全认证。The sending module sends prompt completion information to the payment server, so that the payment server performs security authentication on the payment terminal.

可选地,支付终端还包括:第二提示模块;Optionally, the payment terminal further includes: a second prompt module;

所述接收模块402,还用于在展示模块401展示第一动态认证信息之后,接收所述支付服务器发送的支付结果;The receiving module 402 is further configured to receive a payment result sent by the payment server after the display module 401 displays the first dynamic authentication information;

所述第二提示模块,在所述接收模块402接收到支付结果时,按照第二预设方式提示用户认证完毕;The second prompting module prompts the user that the authentication is complete in a second preset manner when the receiving module 402 receives the payment result;

所述展示模块401,还根据所述支付结果,展示支付成功信息或支付失败信息The display module 401 also displays payment success information or payment failure information according to the payment result.

本申请实施例提供的支付终端,基于支付服务器发送的安全认证请求展示第一动态认证信息,以使收款终端将基于第一动态认证信息所采集到的第二动态认证信息发送给支付服务器,从而使支付服务器根据第一动态认证信息和第二动态认证信息对支付终端进行安全认证,并在认证通过后进行支付交易。可见,通过本申请实施例,能够有效的避免恶意收款终端执行恶意收款现象的发生,确保了用户的财产安全,提升了移动支付的安全性。The payment terminal provided in the embodiment of the present application displays the first dynamic authentication information based on the security authentication request sent by the payment server, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information, and performs the payment transaction after the authentication is passed. It can be seen that through the embodiment of the present application, the occurrence of malicious payment terminals executing malicious payment collection can be effectively avoided, the property safety of users is ensured, and the security of mobile payment is improved.

本申请实施例提供的支付终端能够实现图5至图6的方法实施例中支付终端实现的各个过程,为避免重复,这里不再赘述。而且,应当注意的是,本申请的支付终端的各个部件中,根据其要实现的功能而对其中的部件进行了逻辑划分,但是,本申请不受限于此,可以根据需要对各个部件进行重新划分或组合。The payment terminal provided in the embodiment of the present application can implement the various processes implemented by the payment terminal in the method embodiments of Figures 5 to 6, and will not be described here to avoid repetition. In addition, it should be noted that among the various components of the payment terminal of the present application, the components are logically divided according to the functions to be implemented, but the present application is not limited thereto, and the various components can be re-divided or combined as needed.

对应上述描述的支付方法,基于相同的技术构思,本申请实施例还提供一种支付系统,如图9所示,支付系统500包括:支付终端501、收款终端502和后台支付服务器503;Corresponding to the payment method described above, based on the same technical concept, the embodiment of the present application also provides a payment system, as shown in FIG9 , the payment system 500 includes: a payment terminal 501, a payment terminal 502 and a backend payment server 503;

所述支付终端501,用于响应于用户的支付操作,展示支付凭证;以及,接收所述支付服务器503发送的安全认证请求,根据所述安全认证请求,展示第一动态认证信息;The payment terminal 501 is used to display the payment voucher in response to the user's payment operation; and receive the security authentication request sent by the payment server 503, and display the first dynamic authentication information according to the security authentication request;

所述收款终端502,用于从所述支付凭证中获取支付信息,根据所述支付信息向所述支付服务器503发送支付请求;以及,将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器503;The payment terminal 502 is used to obtain payment information from the payment voucher, send a payment request to the payment server 503 according to the payment information; and send the second dynamic authentication information collected based on the first dynamic authentication information to the payment server 503;

所述支付服务器503,用于接收所述收款终端502发送的支付请求,向所述支付终端501发送安全认证请求;以及,根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端501进行安全认证,若认证通过,则根据所述支付信息进行支付交易。The payment server 503 is used to receive the payment request sent by the payment terminal 502, send a security authentication request to the payment terminal 501; and perform security authentication on the payment terminal 501 according to the first dynamic authentication information and the second dynamic authentication information. If the authentication is successful, a payment transaction is performed according to the payment information.

可选地,所述收款终端502,从所述支付凭证中获取所述用户的支付相关信息,根据所述支付相关信息和所述收款终端502的终端标识生成支付信息;Optionally, the payment terminal 502 obtains payment related information of the user from the payment voucher, and generates payment information according to the payment related information and the terminal identification of the payment terminal 502;

可选地,所述收款终端502,向支付服务器503发送反馈信息,所述反馈信息包括基于所述第一动态认证信息所采集到的第二动态认证信息和所述收款终端502的终端标识。Optionally, the payment terminal 502 sends feedback information to the payment server 503 , where the feedback information includes the second dynamic authentication information collected based on the first dynamic authentication information and the terminal identification of the payment terminal 502 .

本申请实施例提供的支付系统,在支付服务器接收到收款终端发送的支付请求时,通过向支付终端发送安全认证请求,以指示支付终端展示第一动态认证信息;以及,接收收款终端发送的反馈信息,根据反馈信息包括的收款终端基于支付终端展示的第一动态认证信息所采集到的第二动态认证信息,对支付终端进行安全认证;并在认证通过时执行支付交易,而非直接进行支付交易,有效的避免了恶意收款终端执行恶意收款操作现象的发生,确保了用户的财产安全,提升了移动支付的安全性。The payment system provided in the embodiment of the present application, when the payment server receives a payment request sent by the payment terminal, sends a security authentication request to the payment terminal to instruct the payment terminal to display first dynamic authentication information; and receives feedback information sent by the payment terminal, and performs security authentication on the payment terminal according to the second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information displayed by the payment terminal included in the feedback information; and executes the payment transaction when the authentication is passed, instead of directly performing the payment transaction, which effectively avoids the occurrence of malicious payment terminals performing malicious payment collection operations, ensures the property safety of users, and improves the security of mobile payments.

需要说明的是,本申请中关于支付系统的实施例与本申请中关于支付方法的实施例基于同一发明构思,因此该实施例的具体实施可以参见前述支付方法的实施,重复之处不再赘述。It should be noted that the embodiment of the payment system in the present application and the embodiment of the payment method in the present application are based on the same inventive concept, so the specific implementation of this embodiment can refer to the implementation of the aforementioned payment method, and the repeated parts will not be repeated.

图10为实现本申请各个实施例的一种支付终端的硬件结构示意图。FIG. 10 is a schematic diagram of the hardware structure of a payment terminal for implementing various embodiments of the present application.

如图10所示,支付终端600包括但不限于:射频单元601、网络模块602、音频输出单元603、输入单元604、传感器605、显示单元606、用户输入单元607、接口单元608、存储器609、处理器610、以及电源611等部件。本领域技术人员可以理解,图10中示出的支付终端的结构并不构成对支付终端的限定,支付终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。在本发明实施例中,支付终端包括但不限于手机、平板电脑、笔记本电脑、掌上电脑、车载终端、可穿戴设备、以及计步器等。As shown in FIG10 , the payment terminal 600 includes but is not limited to: a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609, a processor 610, and a power supply 611. It can be understood by those skilled in the art that the structure of the payment terminal shown in FIG10 does not constitute a limitation on the payment terminal, and the payment terminal may include more or fewer components than shown, or combine certain components, or arrange components differently. In an embodiment of the present invention, the payment terminal includes but is not limited to a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted terminal, a wearable device, and a pedometer.

其中,处理器610,用于响应于用户的支付操作,展示支付凭证,以使收款终端从所述支付凭证中获取支付信息,并根据所述支付信息向支付服务器发送支付请求;接收所述支付服务器发送的安全认证请求;根据所述安全认证请求,展示第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器,使所述支付服务器根据所述第一动态认证信息和所述第二动态认证信息对所述支付终端进行安全认证。Among them, the processor 610 is used to display the payment voucher in response to the user's payment operation, so that the payment terminal obtains payment information from the payment voucher and sends a payment request to the payment server according to the payment information; receives a security authentication request sent by the payment server; and displays the first dynamic authentication information according to the security authentication request, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server performs security authentication on the payment terminal according to the first dynamic authentication information and the second dynamic authentication information.

基于此,能够有效的避免恶意收款终端执行恶意收款的行为,避免了用户的财产损失,提升了移动支付的安全性。Based on this, malicious payment terminals can be effectively prevented from executing malicious payment collection behaviors, thus avoiding property losses of users and improving the security of mobile payments.

应理解的是,本申请实施例中,射频单元601可用于收发信息或通话过程中,信号的接收和发送,具体的,将来自基站的下行数据接收后,给处理器610处理;另外,将上行的数据发送给基站。通常,射频单元601包括但不限于天线、至少一个放大器、收发信机、耦合器、低噪声放大器、双工器等。此外,射频单元601还可以通过无线通信系统与网络和其他设备通信。It should be understood that in the embodiment of the present application, the radio frequency unit 601 can be used for receiving and sending signals during information transmission or calls. Specifically, after receiving downlink data from the base station, it is sent to the processor 610 for processing; in addition, uplink data is sent to the base station. Generally, the radio frequency unit 601 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc. In addition, the radio frequency unit 601 can also communicate with the network and other devices through a wireless communication system.

支付终端通过网络模块602为用户提供了无线的宽带互联网访问,如帮助用户收发电子邮件、浏览网页和访问流式媒体等。The payment terminal provides users with wireless broadband Internet access through the network module 602, such as helping users to send and receive emails, browse web pages, and access streaming media.

音频输出单元603可以将射频单元601或网络模块602接收的或者在存储器609中存储的音频数据转换成音频信号并且输出为声音。而且,音频输出单元603还可以提供与支付终端600执行的特定功能相关的音频输出(例如,呼叫信号接收声音、消息接收声音等等)。音频输出单元603包括扬声器、蜂鸣器以及受话器等。The audio output unit 603 can convert the audio data received by the RF unit 601 or the network module 602 or stored in the memory 609 into an audio signal and output it as sound. Moreover, the audio output unit 603 can also provide audio output related to a specific function performed by the payment terminal 600 (e.g., a call signal reception sound, a message reception sound, etc.). The audio output unit 603 includes a speaker, a buzzer, a receiver, etc.

输入单元604用于接收音频或视频信号。输入单元604可以包括图形处理器(Graphics Processing Unit,GPU)6041和麦克风6042,图形处理器6041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。处理后的图像帧可以显示在显示单元606上。经图形处理器6041处理后的图像帧可以存储在存储器609(或其它存储介质)中或者经由射频单元601或网络模块602进行发送。麦克风6042可以接收声音,并且能够将这样的声音处理为音频数据。处理后的音频数据可以在电话通话模式的情况下转换为可经由射频单元601发送到移动通信基站的格式输出。The input unit 604 is used to receive audio or video signals. The input unit 604 may include a graphics processor (GPU) 6041 and a microphone 6042, and the graphics processor 6041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The processed image frame can be displayed on the display unit 606. The image frame processed by the graphics processor 6041 can be stored in the memory 609 (or other storage medium) or sent via the radio frequency unit 601 or the network module 602. The microphone 6042 can receive sound and can process such sound into audio data. The processed audio data can be converted into a format output that can be sent to a mobile communication base station via the radio frequency unit 601 in the case of a telephone call mode.

支付终端600还包括至少一种传感器605,比如光传感器、运动传感器以及其他传感器。具体地,光传感器包括环境光传感器及接近传感器,其中,环境光传感器可根据环境光线的明暗来调节显示面板6061的亮度,接近传感器可在支付终端600移动到耳边时,关闭显示面板6061和/或背光。作为运动传感器的一种,加速计传感器可检测各个方向上(一般为三轴)加速度的大小,静止时可检测出重力的大小及方向,可用于识别支付终端姿态(比如横竖屏切换、相关游戏、磁力计姿态校准)、振动识别相关功能(比如计步器、敲击)等;传感器605还可以包括指纹传感器、压力传感器、虹膜传感器、分子传感器、陀螺仪、气压计、湿度计、温度计、红外线传感器等,在此不再赘述。The payment terminal 600 also includes at least one sensor 605, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel 6061 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 6061 and/or the backlight when the payment terminal 600 is moved to the ear. As a kind of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in each direction (generally three axes), and can detect the magnitude and direction of gravity when stationary, which can be used to identify the posture of the payment terminal (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; the sensor 605 can also include a fingerprint sensor, a pressure sensor, an iris sensor, a molecular sensor, a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, etc., which will not be repeated here.

显示单元606用于显示由用户输入的信息或提供给用户的信息。显示单元606可包括显示面板6061,可以采用液晶显示器(Liquid Crystal Display,LCD)、有机发光二极管(Organic Light-Emitting Diode,OLED)等形式来配置显示面板6061。The display unit 606 is used to display information input by the user or information provided to the user. The display unit 606 may include a display panel 6061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

用户输入单元607可用于接收输入的数字或字符信息,以及产生与支付终端的用户设置以及功能控制有关的键信号输入。具体地,用户输入单元607包括触控面板6071以及其他输入设备6072。触控面板6071,也称为触摸屏,可收集用户在其上或附近的触摸操作(比如用户使用手指、触笔等任何适合的物体或附件在触控面板6071上或在触控面板6071附近的操作)。触控面板6071可包括触摸检测装置和触摸控制器两个部分。其中,触摸检测装置检测用户的触摸方位,并检测触摸操作带来的信号,将信号传送给触摸控制器;触摸控制器从触摸检测装置上接收触摸信息,并将它转换成触点坐标,再送给处理器610,接收处理器610发来的命令并加以执行。此外,可以采用电阻式、电容式、红外线以及表面声波等多种类型实现触控面板6071。除了触控面板6071,用户输入单元607还可以包括其他输入设备6072。具体地,其他输入设备6072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。The user input unit 607 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the payment terminal. Specifically, the user input unit 607 includes a touch panel 6071 and other input devices 6072. The touch panel 6071, also known as a touch screen, can collect the user's touch operation on or near it (such as the user's operation on the touch panel 6071 or near the touch panel 6071 using any suitable object or accessory such as a finger, stylus, etc.). The touch panel 6071 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch orientation, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into the contact point coordinates, and then sends it to the processor 610, receives the command sent by the processor 610 and executes it. In addition, the touch panel 6071 can be implemented in various types such as resistive, capacitive, infrared and surface acoustic waves. In addition to the touch panel 6071, the user input unit 607 may also include other input devices 6072. Specifically, other input devices 6072 may include but are not limited to a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.

进一步的,触控面板6071可覆盖在显示面板6061上,当触控面板6071检测到在其上或附近的触摸操作后,传送给处理器610以确定触摸事件的类型,随后处理器610根据触摸事件的类型在显示面板6061上提供相应的视觉输出。虽然在图9中,触控面板6071与显示面板6061是作为两个独立的部件来实现支付终端的输入和输出功能,但是在某些实施例中,可以将触控面板6071与显示面板6061集成而实现支付终端的输入和输出功能,具体此处不做限定。Furthermore, the touch panel 6071 may be covered on the display panel 6061. When the touch panel 6071 detects a touch operation on or near it, it is transmitted to the processor 610 to determine the type of the touch event, and then the processor 610 provides a corresponding visual output on the display panel 6061 according to the type of the touch event. Although in FIG9 , the touch panel 6071 and the display panel 6061 are used as two independent components to implement the input and output functions of the payment terminal, in some embodiments, the touch panel 6071 and the display panel 6061 may be integrated to implement the input and output functions of the payment terminal, which is not limited here.

接口单元608为外部装置与支付终端600连接的接口。例如,外部装置可以包括有线或无线头戴式耳机端口、外部电源(或电池充电器)端口、有线或无线数据端口、存储卡端口、用于连接具有识别模块的装置的端口、音频输入/输出(I/O)端口、视频I/O端口、耳机端口等等。接口单元608可以用于接收来自外部装置的输入(例如,数据信息、电力等等)并且将接收到的输入传输到支付终端600内的一个或多个元件或者可以用于在支付终端600和外部装置之间传输数据。The interface unit 608 is an interface for connecting an external device to the payment terminal 600. For example, the external device may include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device with an identification module, an audio input/output (I/O) port, a video I/O port, a headphone port, etc. The interface unit 608 may be used to receive input (e.g., data information, power, etc.) from an external device and transmit the received input to one or more elements in the payment terminal 600 or may be used to transmit data between the payment terminal 600 and an external device.

存储器609可用于存储软件程序以及各种数据。存储器609可主要包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的应用程序(比如声音播放功能、图像播放功能等)等;存储数据区可存储根据手机的使用所创建的数据(比如音频数据、电话本等)等。此外,存储器609可以包括高速随机存取存储器,还可以包括非易失性存储器,例如至少一个磁盘存储器件、闪存器件、或其他易失性固态存储器件。The memory 609 can be used to store software programs and various data. The memory 609 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory 609 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

处理器610是支付终端的控制中心,利用各种接口和线路连接整个支付终端的各个部分,通过运行或执行存储在存储器609内的软件程序和/或模块,以及调用存储在存储器609内的数据,执行支付终端的各种功能和处理数据,从而对支付终端进行整体监控。处理器610可包括一个或多个处理单元;优选的,处理器610可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序等,调制解调处理器主要处理无线通信。可以理解的是,上述调制解调处理器也可以不集成到处理器610中。The processor 610 is the control center of the payment terminal. It uses various interfaces and lines to connect various parts of the entire payment terminal. It executes various functions of the payment terminal and processes data by running or executing software programs and/or modules stored in the memory 609, and calling data stored in the memory 609, so as to monitor the payment terminal as a whole. The processor 610 may include one or more processing units; preferably, the processor 610 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 610.

支付终端600还可以包括给各个部件供电的电源611(比如电池),优选的,电源611可以通过电源管理系统与处理器610逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。The payment terminal 600 may also include a power supply 611 (such as a battery) for supplying power to various components. Preferably, the power supply 611 may be logically connected to the processor 610 via a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system.

另外,支付终端600包括一些未示出的功能模块,在此不再赘述。In addition, the payment terminal 600 includes some functional modules not shown, which will not be described in detail here.

优选的,本发明实施例还提供一种支付终端,包括处理器610,存储器609,存储在存储器609上并可在所述处理器610上运行的计算机程序,该计算机程序被处理器610执行时实现上述应用于支付终端的方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。Preferably, an embodiment of the present invention further provides a payment terminal, comprising a processor 610, a memory 609, and a computer program stored in the memory 609 and executable on the processor 610. When the computer program is executed by the processor 610, each process of the above-mentioned method embodiment applied to the payment terminal is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be described here.

本申请实施例还提供一种计算机可读存储介质,计算机可读存储介质上存储有计算机程序,该计算机程序被处理器执行时实现上述应用于支付终端的支付方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,简称ROM)、随机存取存储器(Random AccessMemory,简称RAM)、磁碟或者光盘等。The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, each process of the payment method embodiment applied to the payment terminal is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。The present invention is described with reference to the flowchart and/or block diagram of the method, device (system), and computer program product according to the embodiment of the present invention. It should be understood that each process and/or box in the flowchart and/or block diagram, as well as the combination of the process and/or box in the flowchart and/or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.

这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.

这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.

在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。In a typical configuration, a computing device includes one or more processors (CPU), input/output interfaces, network interfaces, and memory.

内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and/or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

本领域技术人员应明白,本申请的实施例可提供为方法、系统或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

以上所述仅为本申请的实施例而已,并不用于限制本申请。对于本领域技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本申请的权利要求范围之内。The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims (11)

1.一种支付方法,应用于支付服务器,其特征在于,包括:1. A payment method, applied to a payment server, comprising: 接收收款终端发送的支付请求,其中,所述支付请求包括所述收款终端基于支付终端展示的支付凭证所生成的支付信息;所述支付信息包括所述支付终端的终端标识和所述收款终端的终端标识;Receiving a payment request sent by a payment terminal, wherein the payment request includes payment information generated by the payment terminal based on a payment voucher displayed by the payment terminal; the payment information includes a terminal identifier of the payment terminal and a terminal identifier of the payment terminal; 根据所述支付终端的终端标识,向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息,所述安全认证请求包括所述第一动态认证信息,所述安全认证请求包括连续的变换指令,所述第一动态认证信息包括根据所述变换指令对所述支付凭证进行变化而得的信息;Sending a security authentication request to the payment terminal according to the terminal identification of the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display first dynamic authentication information, the security authentication request includes the first dynamic authentication information, the security authentication request includes continuous transformation instructions, and the first dynamic authentication information includes information obtained by changing the payment credential according to the transformation instruction; 将所述第一动态认证信息或者所述第一动态认证信息的索引信息与所述支付信息关联保存;Associating and saving the first dynamic authentication information or the index information of the first dynamic authentication information with the payment information; 接收所述收款终端发送的反馈信息,其中,所述反馈信息包括所述收款终端的终端标识,和所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;receiving feedback information sent by the payment terminal, wherein the feedback information includes a terminal identifier of the payment terminal and second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information; 确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过;其中,所述第一动态认证信息为根据所述反馈信息包括的所述收款终端的终端标识,确定的关联的第一动态认证信息;Determine whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, determine that the authentication is passed; if not, determine that the authentication is not passed; wherein the first dynamic authentication information is the associated first dynamic authentication information determined according to the terminal identifier of the payment terminal included in the feedback information; 若认证通过,则根据所述支付信息进行支付交易。If the authentication is successful, the payment transaction is performed according to the payment information. 2.根据权利要求1所述的方法,其特征在于,所述向所述支付终端发送安全认证请求,包括:2. The method according to claim 1, characterized in that the sending of a security authentication request to the payment terminal comprises: 向所述支付终端发送安全认证提示信息,以使所述支付终端提示用户进行安全认证;Sending security authentication prompt information to the payment terminal so that the payment terminal prompts the user to perform security authentication; 若接收到所述支付终端发送的提示完毕信息,则向所述支付终端发送安全认证请求。If the prompt completion information sent by the payment terminal is received, a security authentication request is sent to the payment terminal. 3.一种支付方法,应用于支付终端,其特征在于,包括:3. A payment method, applied to a payment terminal, comprising: 响应于用户的支付操作,展示支付凭证,以使收款终端基于所述支付凭证生成支付信息,并根据所述支付信息向支付服务器发送支付请求;所述支付信息包括所述支付终端的终端标识;In response to a user's payment operation, displaying a payment voucher so that the payment terminal generates payment information based on the payment voucher and sends a payment request to a payment server according to the payment information; the payment information includes a terminal identifier of the payment terminal; 接收所述支付服务器发送的安全认证请求,所述安全认证请求包括第一动态认证信息,所述安全认证请求包括连续的变换指令;所述第一动态认证信息包括根据所述变换指令对所述支付凭证进行变化而得的信息;receiving a security authentication request sent by the payment server, the security authentication request including first dynamic authentication information, the security authentication request including continuous transformation instructions; the first dynamic authentication information including information obtained by changing the payment credential according to the transformation instruction; 从所述安全认证请求中获取连续的变换指令;根据所述变换指令对所述支付凭证进行变换,得到第一动态认证信息;在第二预设时长内重复的展示所述第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器,使所述支付服务器确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过。Obtain continuous transformation instructions from the security authentication request; transform the payment credential according to the transformation instruction to obtain first dynamic authentication information; repeatedly display the first dynamic authentication information within a second preset time period, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server determines whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, determine that the authentication is passed; if not, determine that the authentication is not passed. 4.根据权利要求3所述的方法,其特征在于,所述接收所述支付服务器发送的安全认证请求之前,还包括:4. The method according to claim 3, characterized in that before receiving the security authentication request sent by the payment server, it also includes: 接收所述支付服务器发送的安全认证提示信息;Receiving security authentication prompt information sent by the payment server; 按照第一预设提示方式提示用户进行安全认证;Prompt the user to perform security authentication according to a first preset prompting method; 向所述支付服务器发送提示完毕信息,以使所述支付服务器对所述支付终端进行安全认证。Sending a prompt completion message to the payment server so that the payment server performs security authentication on the payment terminal. 5.一种支付服务器,其特征在于,包括:5. A payment server, comprising: 接收模块,用于接收收款终端发送的支付请求,其中,所述支付请求包括所述收款终端基于支付终端展示的支付凭证所生成的支付信息;所述支付信息包括所述支付终端的终端标识和所述收款终端的终端标识;A receiving module, configured to receive a payment request sent by a payment receiving terminal, wherein the payment request includes payment information generated by the payment receiving terminal based on the payment voucher displayed by the payment terminal; the payment information includes a terminal identifier of the payment terminal and a terminal identifier of the payment receiving terminal; 发送模块,用于根据所述支付终端的终端标识,向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息,所述安全认证请求包括所述第一动态认证信息,所述安全认证请求包括连续的变换指令,所述第一动态认证信息包括根据所述变换指令对所述支付凭证进行变化而得的信息;a sending module, configured to send a security authentication request to the payment terminal according to the terminal identification of the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display first dynamic authentication information, the security authentication request includes the first dynamic authentication information, the security authentication request includes continuous transformation instructions, and the first dynamic authentication information includes information obtained by changing the payment credential according to the transformation instruction; 保存模块,用于将所述第一动态认证信息或者所述第一动态认证信息的索引信息与所述支付信息关联保存;A saving module, used to associate and save the first dynamic authentication information or the index information of the first dynamic authentication information with the payment information; 所述接收模块,还用于接收所述收款终端发送的反馈信息,其中,所述反馈信息包括所述收款终端的终端标识,和所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;The receiving module is further used to receive feedback information sent by the payment terminal, wherein the feedback information includes a terminal identifier of the payment terminal and second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information; 认证模块,用于确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过;其中,所述第一动态认证信息为根据所述反馈信息包括的所述收款终端的终端标识,确定的关联的第一动态认证信息;an authentication module, used to determine whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, determining that the authentication is passed; if not, determining that the authentication is not passed; wherein the first dynamic authentication information is the associated first dynamic authentication information determined according to the terminal identification of the payment terminal included in the feedback information; 处理模块,用于在所述认证模块认证通过时,根据所述支付信息进行支付交易。The processing module is used to perform a payment transaction according to the payment information when the authentication module passes the authentication. 6.一种支付终端,其特征在于,包括:6. A payment terminal, comprising: 展示模块,用于响应于用户的支付操作,展示支付凭证,以使收款终端基于所述支付凭证生成支付信息,并根据所述支付信息发送支付请求给支付服务器;所述支付信息包括所述支付终端的终端标识和所述收款终端的终端标识;a display module, configured to display the payment voucher in response to the user's payment operation, so that the payment terminal generates payment information based on the payment voucher and sends a payment request to the payment server according to the payment information; the payment information includes the terminal identification of the payment terminal and the terminal identification of the payment terminal; 接收模块,用于接收所述支付服务器发送的安全认证请求,所述安全认证请求包括第一动态认证信息,所述安全认证请求包括连续的变换指令;所述第一动态认证信息包括根据所述变换指令对所述支付凭证进行变化而得的信息;A receiving module, configured to receive a security authentication request sent by the payment server, wherein the security authentication request includes first dynamic authentication information, and the security authentication request includes continuous transformation instructions; the first dynamic authentication information includes information obtained by changing the payment credential according to the transformation instruction; 所述展示模块,还用于根据所述安全认证请求,展示第一动态认证信息,以使所述收款终端将基于所述第一动态认证信息所采集的第二动态认证信息发送给所述支付服务器,使所述支付服务器确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过;The display module is further used to display the first dynamic authentication information according to the security authentication request, so that the payment terminal sends the second dynamic authentication information collected based on the first dynamic authentication information to the payment server, so that the payment server determines whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, it is determined that the authentication is passed; if not, it is determined that the authentication is not passed; 在根据所述安全认证请求,展示第一动态认证信息的过程中,所述展示模块,用于从所述安全认证请求中获取连续的变换指令;根据所述变换指令对所述支付凭证进行变换,得到第一动态认证信息;在第二预设时长内重复的展示所述第一动态认证信息。In the process of displaying the first dynamic authentication information according to the security authentication request, the display module is used to obtain continuous transformation instructions from the security authentication request; transform the payment credential according to the transformation instruction to obtain the first dynamic authentication information; and repeatedly display the first dynamic authentication information within a second preset time period. 7.一种支付系统,其特征在于,包括:支付终端、收款终端和支付服务器;7. A payment system, characterized by comprising: a payment terminal, a payment terminal and a payment server; 所述支付终端,用于响应于用户的支付操作,展示支付凭证;以及,接收所述支付服务器发送的安全认证请求,从所述安全认证请求中获取连续的变换指令;根据所述变换指令对所述支付凭证进行变换,得到第一动态认证信息;在第二预设时长内重复的展示所述第一动态认证信息;The payment terminal is configured to display the payment voucher in response to the user's payment operation; and receive a security authentication request sent by the payment server, and obtain a continuous transformation instruction from the security authentication request; transform the payment voucher according to the transformation instruction to obtain first dynamic authentication information; and repeatedly display the first dynamic authentication information within a second preset time period; 所述收款终端,用于基于所述支付凭证生成支付信息,根据所述支付信息向所述支付服务器发送支付请求;以及,将基于所述第一动态认证信息所采集到的第二动态认证信息发送给所述支付服务器;所述支付信息包括所述支付终端的终端标识和所述收款终端的终端标识;The payment terminal is used to generate payment information based on the payment voucher, send a payment request to the payment server according to the payment information; and send the second dynamic authentication information collected based on the first dynamic authentication information to the payment server; the payment information includes the terminal identification of the payment terminal and the terminal identification of the payment terminal; 所述支付服务器,用于接收所述收款终端发送的支付请求,根据所述支付终端的终端标识,向所述支付终端发送安全认证请求;其中,所述安全认证请求用于指示所述支付终端展示第一动态认证信息,所述安全认证请求包括所述第一动态认证信息,所述安全认证请求包括连续的变换指令;所述第一动态认证信息包括根据所述变换指令对所述支付凭证进行变化而得的信息;将所述第一动态认证信息或者所述第一动态认证信息的索引信息与所述支付信息关联保存;接收所述收款终端发送的反馈信息,其中,所述反馈信息包括所述收款终端的终端标识,和所述收款终端基于所述第一动态认证信息所采集到的第二动态认证信息;确定所述第二动态认证信息中是否包括所述变换指令所对应的第一动态认证信息;若是,则确定认证通过;若否,则确定认证未通过;其中,所述第一动态认证信息为根据所述反馈信息包括的所述收款终端的终端标识,确定的关联的第一动态认证信息;若认证通过,则根据所述支付信息进行支付交易。The payment server is used to receive the payment request sent by the payment terminal, and send a security authentication request to the payment terminal according to the terminal identification of the payment terminal; wherein the security authentication request is used to instruct the payment terminal to display the first dynamic authentication information, the security authentication request includes the first dynamic authentication information, and the security authentication request includes continuous transformation instructions; the first dynamic authentication information includes information obtained by changing the payment credential according to the transformation instruction; the first dynamic authentication information or the index information of the first dynamic authentication information is associated with the payment information and saved; receiving feedback information sent by the payment terminal, wherein the feedback information includes the terminal identification of the payment terminal and the second dynamic authentication information collected by the payment terminal based on the first dynamic authentication information; determining whether the second dynamic authentication information includes the first dynamic authentication information corresponding to the transformation instruction; if so, determining that the authentication is passed; if not, determining that the authentication is not passed; wherein the first dynamic authentication information is the associated first dynamic authentication information determined according to the terminal identification of the payment terminal included in the feedback information; if the authentication is passed, performing a payment transaction according to the payment information. 8.一种支付服务器,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求1至2中任一项所述的支付方法的步骤。8. A payment server, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the steps of the payment method according to any one of claims 1 to 2 when executed by the processor. 9.一种支付终端,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求3-4任一项所述的支付方法的步骤。9. A payment terminal, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the steps of the payment method according to any one of claims 3 to 4 when executed by the processor. 10.一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现如权利要求1至2中任一项所述的支付方法的步骤。10. A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the payment method according to any one of claims 1 to 2 are implemented. 11.一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现如权利要求3至4中任一项所述的支付方法的步骤。11. A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the payment method according to any one of claims 3 to 4 are implemented.
CN201911204994.8A 2019-11-29 2019-11-29 Payment method, server, terminal and system Active CN110969434B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201911204994.8A CN110969434B (en) 2019-11-29 2019-11-29 Payment method, server, terminal and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201911204994.8A CN110969434B (en) 2019-11-29 2019-11-29 Payment method, server, terminal and system

Publications (2)

Publication Number Publication Date
CN110969434A CN110969434A (en) 2020-04-07
CN110969434B true CN110969434B (en) 2024-06-25

Family

ID=70032514

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201911204994.8A Active CN110969434B (en) 2019-11-29 2019-11-29 Payment method, server, terminal and system

Country Status (1)

Country Link
CN (1) CN110969434B (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111784345B (en) * 2020-07-21 2022-06-14 支付宝(杭州)信息技术有限公司 Payment processing method, device, equipment and system
CN113592503B (en) * 2021-07-30 2025-02-14 中国工商银行股份有限公司 Unified payment authentication transaction method, server and system
CN114693293A (en) * 2022-03-25 2022-07-01 中国银联股份有限公司 Scanned payment method executed in intelligent device and scanned payment device
CN114997858B (en) * 2022-06-20 2025-08-15 中国银联股份有限公司 Payment method, device, equipment and computer readable storage medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105930765A (en) * 2016-02-29 2016-09-07 中国银联股份有限公司 Payment method and device
CN107330696A (en) * 2016-04-29 2017-11-07 宇龙计算机通信科技(深圳)有限公司 A kind of method of payment, device, terminal and the system of utilization speech recognition technology

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107967602A (en) * 2011-03-04 2018-04-27 维萨国际服务协会 Ability to pay is bound to the safety element of computer
CN107194689B (en) * 2017-06-16 2024-05-03 河南晟宇信息技术有限公司 Mobile phone payment system and method based on near field magnetic communication and proximity relation detection
CN107705128A (en) * 2017-09-05 2018-02-16 深圳支点电子智能科技有限公司 A kind of payment verification method and system
CN108898206A (en) * 2018-06-11 2018-11-27 上海掌门科技有限公司 A kind of method and barcode scanning safe checking method generating gathering code

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105930765A (en) * 2016-02-29 2016-09-07 中国银联股份有限公司 Payment method and device
CN107330696A (en) * 2016-04-29 2017-11-07 宇龙计算机通信科技(深圳)有限公司 A kind of method of payment, device, terminal and the system of utilization speech recognition technology

Also Published As

Publication number Publication date
CN110969434A (en) 2020-04-07

Similar Documents

Publication Publication Date Title
US9703971B2 (en) Sensitive operation verification method, terminal device, server, and verification system
CN110969434B (en) Payment method, server, terminal and system
CN106651522B (en) Information interaction method and device
US10762542B2 (en) Item transfer apparatus, system and method
CN110674662B (en) Scanning method and terminal equipment
WO2019174541A1 (en) Operation method for mobile terminal and mobile terminal
CN111274842B (en) Coded image recognition method and electronic device
CN108629579B (en) Payment method and mobile terminal
CN110069407B (en) Function test method and device for application program
CN111600931A (en) Information sharing method and electronic device
CN110162241A (en) A kind of message treatment method and terminal
WO2021083091A1 (en) Screenshot capturing method and terminal device
CN108901020A (en) Method, mobile terminal and the server of network insertion
CN111124706A (en) Application sharing method and electronic device
CN109242512A (en) A method, device and equipment for processing authenticity information of parts based on blockchain
CN110189123A (en) Payment privilege method and mobile terminal
CN110191426A (en) A method and terminal for information sharing
CN107948278B (en) Information transmission method, terminal equipment and system
CN111405043B (en) Information processing method and device and electronic equipment
CN108768838A (en) One kind putting out screen information sharing method, transmitting terminal and receiving terminal
CN110287719B (en) File encryption method and mobile terminal
CN108287745A (en) A kind of display methods and terminal device at the interfaces WebApp
CN108121546A (en) A kind of information processing method and mobile terminal
CN110703967A (en) A method for processing a short message and a terminal device thereof
CN109067979B (en) Prompting method and mobile terminal

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
TG01 Patent term adjustment
TG01 Patent term adjustment