IP Library Granted Patent US 12700002
Granted Patent B2
US 12700002 · App. 18/845,693 · Granted Aug 4, 2026

Payment method, terminal devices, servers, systems and medium

Inventors: Yu Wang (Shanghai, CN); Zhuo Chen (Shanghai, CN); He Huang (Shanghai, CN); Zhimin Xie (Shanghai, CN); Xinyuan Xu (Shanghai, CN); Zhangyuan Ye (Shanghai, CN); Yongsheng Huang (Shanghai, CN); Jien Zhou (Shanghai, CN); Wei Li (Shanghai, CN); Xi Shen (Shanghai, CN); Zhixiong Tang (Shanghai, CN)
Assignee: CHINA UNIONPAY CO., LTD.
G06Q20/4014G06Q20/3829G06Q20/407
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12700002
App. No.
18/845,693
Granted
Aug 4, 2026
Kind
B2
Abstract

A payment includes: in response to a received payment request message, sending a security verification request message to a security control system, the security verification request message is used to instruct the security control system to perform security verification according to security verification information; receiving security verification result information sent by the security control system; when the security verification result information indicates that the security verification is passed, sending a first notification message to the SDK, the first notification message instructs the SDK to notify the host program to display a user verification page to prompt the user to enter the first user verification input information, the first user verification input information is used for the host program server to perform user verification to obtain user verification result information; when the user verification result information indicates that the user verification is passed, initiating a payment request to complete the payment.

Claims (93)

1 . A payment method, comprising:

in a payment process, generating, by a software development kit (SDK) server, an order identifier in response to an order request message sent by a merchant system;

sending, by the SDK server, an order feedback message to the merchant system, and sending, by the merchant system, an SDK call request message to an SDK in a terminal device, wherein the order feedback message and the SDK call request message include the order identifier;

in response to a first order query message sent by the SDK of the terminal device, sending, by the SDK server, a first query feedback message to the SDK, wherein the first query feedback message includes order information corresponding to the order identifier;

transmitting, by the SDK on the terminal device, a payment request message after the SDK receives the first query feedback message;

sending, by the SDK server in response to the payment request message, a security verification request message to a security control system, wherein the payment request message includes the order information, and the security verification request message includes security verification information for instructing a security control system to perform a first security verification initiated by the SDK;

performing, by the security control system, the first security verification for a payment corresponding to the payment request message according to the security verification information;

receiving, by the SDK server, security verification result information sent by the security control system;

in response to that the security verification result information indicates that the security verification is passed, sending, by the SDK server, a first notification message to the SDK in the terminal device, wherein the terminal device has the SDK and a host program;

notifying, based on the first notification message by the SDK on the terminal device, to notify the host program to display a user verification page to prompt a user to enter first user verification input information;

transmitting, by the host program on the terminal device, the first user verification input information to a host program server;

performing, by the host program server based on the first user verification input information sent by the host program, a second security verification on user identity initiated by the host program to obtain user verification result information;

receiving, by the SDK server, from the host program server, the user verification result information; and

in response to that the user verification result information indicates that the user verification is passed, initiating a payment request to complete the payment process, wherein two security verifications are completed in the payment process, the first security verification is required by an owner of the SDK, and the second security verification is required by an owner of the host program, to improve a security of the payment process.

2 . The method according to claim 1 , wherein, after receiving the security verification result information sent by the security control system, the method further comprises:

in response to that the security verification result information indicates that the security verification is passed, sending a user verification method request message to the host program server, wherein the user verification method request message includes one or more of order information corresponding to the payment indicated by the payment request message, terminal device information and payment information;

receiving a user verification method feedback message sent by the host program server, where the user verification method feedback message includes verification operation information;

in response to that the verification operation information includes a payment refusal mark, sending a second notification message to the SDK, and issuing, based on the second notification message by the SDK on the terminal device, a payment refusal prompt message; and

in response to that the verification operation information includes a password-free payment sign, sending a third notification message to the SDK, and sending, based on the third notification message by the SDK on the terminal device, a password-free payment prompt message.

3 . The method according to claim 2 , wherein sending the first notification message to the SDK in the terminal device comprises:

in response to that the verification operation information includes a user verification method identifier, sending the first notification message to the SDK, wherein the first notification message includes the user verification method identifier; and

notifying, based on the first notification message by the SDK, the host program to display a user verification page that matches the user verification method identifier, and to prompt the user to input first user verification input information that matches the user verification method identifier.

4 . The method according to claim 3 , wherein the security verification result information includes a target host program identifier, and the target host program identifier includes a host program identifier for the payment corresponding to the payment request message,

wherein, before sending the first notification message to the SDK in the terminal device, the method further includes:

according to the target host program identifier and a pre-set first corresponding relationship, determining a target user verification caller corresponding to the target host program identifier, wherein the first corresponding relationship includes a relationship between host program identifiers and user verification callers; and

wherein sending the first notification message to the SDK in the terminal device includes:

in response to that a target user verifies that a caller is the host program, sending the first notification message to the SDK.

5 . The method according to claim 4 , wherein, after determining the target user verification caller corresponding to the target host program identifier based on the target host program identifier and the pre-set first corresponding relationship, the method further comprises:

in response to that the target user verification caller is the SDK, sending a fourth notification message to the SDK,

displaying, based on the fourth notification message by the SDK, a user verification page to prompt the user to enter second user verification input information, and

performing, based on the second user verification input information by the SDK server, the user verification to obtain the user verification result information.

6 . The method according to claim 1 , wherein initiating a payment request comprises:

in response to that the user verification result information satisfies consistency verification standards, initiating the payment request.

7 . The method according to claim 6 , wherein the consistency verification standards include that first user verification result information is consistent with second user verification result information, wherein the first user verification result information is user verification result information transmitted to the SDK by the host program server through the host program, and the second user verification result information is user verification result information obtained from the host program server.

8 . The method according to claim 1 , wherein the SDK server stores a key used to encrypt and decrypt information interacted between the SDK and the host program.

9 . The method according to claim 1 , wherein the order request message includes specified payer identity information, and the method further comprises:

in response to that the specified payer identity information is inconsistent with payer identity information of the payment indicated by the payment request message, sending a payment suspension notification message to the SDK, and

issuing, by the SDK, a payment prompt message.

10 . The method according to claim 1 , wherein, before sending a security verification request message to the security control system in response to the received payment request message, the method further comprises:

receiving a second order query message sent by the SDK of the terminal device, wherein the second order query message includes first code information obtained by scanning a payment code of the terminal device; and

sending a second query feedback message to the SDK, wherein the second query feedback message includes order information corresponding to the first code information.

11 . The method according to claim 1 , wherein, before sending a security verification request message to the security control system in response to the received payment request message, the method further comprises:

in response to a received payment code application message, sending a payment code feedback message to the SDK, wherein the payment code application message is sent by the SDK, and the payment code feedback message includes a payment code,

wherein the payment request message is generated by a payment acceptance device based on a scanning of the payment code.

12 . A payment system, comprising:

a software development kit (SDK) server comprising at least one first memory and at least one first processor coupled to the at least one first memory;

a terminal device having a SDK and a host program;

a security control system; and

a host program server comprising at least one second memory and at least one second processor coupled to the at least one second memory,

wherein the at least one first processor of the SDK server is configured to perform:

in a payment process, generating an order identifier in response to an order request message sent by a merchant system;

sending an order feedback message to the merchant system, so that the merchant system sends an SDK call request message to an SDK in a terminal device, wherein the order feedback message and the SDK call request message include the order identifier;

in response to a first order query message sent by the SDK of the terminal device, sending a first query feedback message to the SDK, wherein the first query feedback message includes order information corresponding to the order identifier;

the SDK on the terminal device is configured to transmit a payment request message after receiving the first query feedback message;

the at least one first processor of the SDK server is further configured to perform:

in response to the payment request message transmitted by the SDK, sending a security verification request message to a security control system, wherein the payment request message includes the order information, and the security verification request message includes security verification information for instructing a security control system to perform a first security verification initiated by the SDK;

the security control system is configured to perform the first security verification for a payment corresponding to the payment request message according to the security verification information;

the at least one first processor of the SDK server is further configured to perform:

receiving security verification result information sent by the security control system; and

in response to that the security verification result information indicates that the security verification is passed, sending a first notification message to the SDK in the terminal device;

the SDK on the terminal device is further configured to notify, based on the first notification message, the host program to display a user verification page to prompt a user to enter first user verification input information;

the host program on the terminal device is configured to transmit the first user verification input information to the host program server;

the at least one second processor of the host program server is configured to perform, based on the first user verification input information sent by the host program, a second security verification on user identity initiated by the host program to obtain user verification result information; and

the at least one first processor of the SDK server is further configured to perform:

receiving from the host program server, the user verification result information; and

in response to that the user verification result information indicates that the user verification is passed, initiating a payment request to complete the payment process,

wherein two security verifications are completed in the payment process, the first security verification is required by an owner of the SDK, and the second security verification is required by an owner of the host program, to improve a security of the payment process.

13 . The payment system according to claim 12 , wherein the at least one first processor of the SDK server is further configured to perform: after receiving the security verification result information sent by the security control system,

in response to that the security verification result information indicates that the security verification is passed, sending a user verification method request message to the host program server, wherein the user verification method request message includes one or more of order information corresponding to the payment indicated by the payment request message, terminal device information and payment information;

receiving a user verification method feedback message sent by the host program server, where the user verification method feedback message includes verification operation information;

in response to that the verification operation information includes a payment refusal mark, sending a second notification message to the SDK; and

in response to that the verification operation information includes a password-free payment sign, sending a third notification message to the SDK;

wherein the SDK on the terminal device is further configured to:

issue, based on the second notification message, a payment refusal prompt message; and

send, based on the third notification message, a password-free payment prompt message.

14 . The payment system according to claim 13 , wherein sending the first notification message to the SDK in the terminal device comprises:

in response to that the verification operation information includes a user verification method identifier, sending the first notification message to the SDK, where the first notification message includes the user verification method identifier; and

the SDK on the terminal device is further configured to notify the host program to display a user verification page that matches the user verification method identifier, to prompt the user to input first user verification input information that matches the user verification method identifier.

15 . The payment system according to claim 14 , wherein the security verification result information includes a target host program identifier, and the target host program identifier includes a host program identifier for the payment corresponding to the payment request message,

wherein, before sending the first notification message to the SDK in the terminal device, the at least one first processor of the SDK server is further configured to perform:

according to the target host program identifier and a pre-set first corresponding relationship, determining a target user verification caller corresponding to the target host program identifier, wherein the first corresponding relationship includes a relationship between host program identifiers and user verification callers; and

wherein sending the first notification message to the SDK in the terminal device includes: in response to that a target user verifies that a caller is the host program, sending the first notification message to the SDK.

16 . The payment system according to claim 15 , wherein, after determining the target user verification caller corresponding to the target host program identifier based on the target host program identifier and the pre-set first corresponding relationship, the at least one first processor of the SDK server is further configured to perform:

in response to that the target user verification caller is the SDK, sending a fourth notification message to the SDK,

the SDK on the terminal device is further configured to display, based on the fourth notification message, a user verification page to prompt the user to enter second user verification input information, and

the at least one first processor of the SDK server is further configured to perform, based on the second user verification input information, the user verification to obtain the user verification result information.

17 . The payment system according to claim 12 , wherein initiating a payment request comprises:

in response to that the user verification result information satisfies consistency verification standards, initiating the payment request.

18 . The payment system according to claim 17 , wherein the consistency verification standards include that first user verification result information is consistent with second user verification result information, wherein the first user verification result information is user verification result information transmitted to the SDK by the host program server through the host program, and the second user verification result information is user verification result information obtained from the host program server.

19 . The payment system according to claim 12 , wherein the SDK server stores a key used to encrypt and decrypt information interacted between the SDK and the host program.

20 . The payment system according to claim 12 , wherein the order request message includes specified payer identity information, and the at least one first processor of the SDK server is further configured to perform:

in response to that the specified payer identity information is inconsistent with payer identity information of the payment indicated by the payment request message, sending a payment suspension notification message to the SDK, and

the SDK on the terminal device is configured to issue a payment prompt message.