TW538357B - Authorization method and system for electronic commerce financial transaction - Google Patents

Authorization method and system for electronic commerce financial transaction Download PDF

Info

Publication number
TW538357B
TW538357B TW90126353A TW90126353A TW538357B TW 538357 B TW538357 B TW 538357B TW 90126353 A TW90126353 A TW 90126353A TW 90126353 A TW90126353 A TW 90126353A TW 538357 B TW538357 B TW 538357B
Authority
TW
Taiwan
Prior art keywords
card
transaction
bank
transfer
cardholder
Prior art date
Application number
TW90126353A
Other languages
Chinese (zh)
Inventor
Wei-Bin Lee
Cheng-Kuo Zheng
Original Assignee
Univ Feng Chia
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Univ Feng Chia filed Critical Univ Feng Chia
Priority to TW90126353A priority Critical patent/TW538357B/en
Application granted granted Critical
Publication of TW538357B publication Critical patent/TW538357B/en

Links

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

The present invention relates to an authorization method and system for electronic commerce financial transaction. A card holder fills out an order on a web-page and presses a paying key. A network store generates a transaction code and a message abstract value for being transmitted to the java applet, and downloads the java sign applet for reading the card information of the card holder to produce a card issuing bank key. The key is pressed to open an account-transfer web-page, and the transaction code and message abstract value are transmitted to the account-transfer web-page. The ID number and the account number and password of the card holder in the card issuing bank are entered to the account-transfer web-page. The card issuing bank certifies the card information of the card holder. If the ID number and password are correct, the transaction code, message abstract value and account-transfer data are transmitted to the remittee bank. After the remittee bank successfully performs a certification, the card-issuing bank is notified of the message of receiving an account-transfer request, and the transaction code of completing the account-transfer is transmitted to the network store. The card issuing bank notifies the card holder of completing account-transfer and the card balance via the web-page. The network store notifies the card holder of a successful transaction via the web-page.

Description

538357538357

子商務金 下訂單, 產生交易 按下付款 易碼則透 行帳號, 行,持卡 輸入身份 業流程完 商店已收 額,則告 卡人,藉 融交易授權方法與系 並以SSL方式傳送至 碼與訊息摘要值,並 鍵後,將下載金資 過1 applet傳送給網 applet使用SSL方式 人在網路銀行的網頁 證字號、發卡銀行認 成,而若收款銀行接 到該筆父易金額,網 知持卡人完成交易, 以達到兼具安全性與 本發明係有關於一種電 統,其係挤卡人在網路網頁 網/路商店,網路商店依訂單 傳送到j a v a a p p 1 e t;當持卡 中心簽署過的applet,而交 路銀行。持卡人選擇付款銀 將父易資料傳送至該網路銀 上確定該資料正確無誤,就 證帳號、密碼,再依FED I作 華父易後,將即時告知網路 路商店知已收到該筆交易金 並產生父易成功碼傳送給持 便利性及降低成本之目的者 隨著網路發達,網際網路已為我們生活帶來許多便 利’ 2統的商業交易方式,也延伸至網際網路成為電子商 務,· w而電子商務最重要的就是便利性及安全性。 在足兩者找到平衡點,是大家一直努力的方向。 口 按目前電子商務的安全交易機制多以VisaMastei^apd 兩大發卡組織推廣的SET(Secure ElectronicThe sub-business gold places an order, generates a transaction and presses the payment e-code to pass through the account. OK, the card holder enters the identity industry process and the store has received the amount, then the cardholder is informed of the transaction authorization method and system and sends it to the SSL. Code and message summary value, and then press the key to send the downloaded applet over 1 applet to the online applet. The SSL certificate is used by the online bank identification number of the online bank and the issuing bank. If the receiving bank receives the The amount of money, the net know cardholder completes the transaction to achieve both security and the present invention relates to an electrical system, which squeezes cardholders in the online webpage / road shop, and the online shop sends the order to javaapp 1 et ; When the card center signed the applet, and Bank of Communications. The cardholder selects the payment bank to send the parent data to the online bank and confirms that the information is correct. After verifying the account number and password, and then using FED I as the parent, it will immediately inform the online store that it has received the information. The transaction gold and the generation of a parent-friendly success code are transmitted to those who want convenience and reduce costs. With the development of the Internet, the Internet has brought many conveniences to our lives. 2 unified business transaction methods have also been extended to the Internet Road becomes e-commerce, and the most important thing for e-commerce is convenience and security. Finding a balance between the two is the direction that everyone has been working hard for. According to the current secure transaction mechanism of e-commerce, most of the SET (Secure Electronic) promoted by VisaMastei ^ apd

Transation)(2. 6· 10)機制和Netseape 所提出的 SSL (Secure Socket Lay er)(1.3.18)協定為主要交易方式 ’兩者各有其優缺點。 二 其中’ SE丁購物付款之交易流程(請配合參看第一圖所 示),係持卡人(10)取得電子錢包,持卡人的電子錢包軟 538357 五、發明說明(2) 體自動與牲& ^ & 店(11)的试查1商店(11)的SET軟體溝通,_認網路商 卡銀行聯繫,^銀/的往來㈣,持卡人必須先與其發 子證給發卡銀兀成註冊程序,認證令心(13)CA便提供電 (10) ,當交易卡”電子證書給其持卡人 :(:=商店⑴)與持卡人⑴ 決定么= = = 1)進行講物對話,當持卡人⑽ 購單與網路商店;ί 會將訂 持要使用的支付卡片,在持卡人(1°)訂講時, 上Ϊ卡人(52會自動地把相關的證書寄出,軟體會附 -I: 付款說明。寄給特約網路商店⑴),全部 :卄丰:公開鑰匙加密技術’特約網路商店(11)無法看見 =卡片的貢料,惟有特約網路商店⑴)的收單銀行可以 解雄;一旦購貨單與付款資料安全送達,特約網路商店 (11) 的收單銀行會要求持卡人(10)的發卡銀行授權。正如 同現一般的特約網路商店請款方式,授權後,特約網路商 店(11)就會向持卡人(10)確認交易,清算與清償也就是像 現在一般的付款與交易過程來完成;按SET的基本構想是 將交易中的金流,物流資訊徹底分開,其安全核心技術有 二,分別是達成資料私密的加解密技術(Cryt〇graphy)、 維護資料完整的數位簽章(Digital Signature)及使交易 資訊無可否認的f子認證機制(Certificate),利用此三 項安全核心來保障持卡人與網路商店在網路交易進行中雙 ·, 'Transation (2.6.10) mechanism and the SSL (Secure Socket Layer) (1.3.18) agreement proposed by Netseape as the main transaction methods ’Both have their advantages and disadvantages. Second, the transaction process of SE payment for shopping (please refer to the first figure), is that the cardholder (10) obtains the electronic wallet, and the cardholder's electronic wallet is soft 538357 V. Description of the invention (2) Animal & ^ & Test of store (11) 1 SET software communication of store (11), _recognize online merchant card bank contact, ^ bank / contacts, cardholder must first issue a sub-certificate with the card issuer Yinwu completed the registration process. The certification authority (13) CA will provide electricity (10). When the transaction card "electronic certificate" is given to its cardholder: (: = shop⑴) and cardholder⑴ decide? = = = 1) Have a talk with the lecturer, when the cardholder ⑽ purchase order and online store; ί will subscribe to the payment card to be used, and when the cardholder (1 °) subscribes, the cardholder (52 will automatically The relevant certificate will be sent, and the software will be accompanied by -I: payment instructions. It will be sent to the special online store ⑴), all: 卄 Feng: public key encryption technology 'special online store (11) cannot be seen = card tribute, only Special online store ⑴) Acquiring bank can dissolve the hero; once the purchase order and payment information are safely delivered, the special online store (11) 's A single bank will require the card-issuing bank's card-issuing bank to authorize it. Just like the current special online store request payment method, after authorization, the special online store (11) will confirm the transaction with the card holder (10). Liquidation and settlement are like the current payment and transaction process. According to the basic idea of SET, the gold flow and logistics information in the transaction are completely separated. There are two core security technologies: encryption and decryption technology to achieve data privacy. (Cryt〇graphy), a digital signature that maintains complete data, and a f-certificate that makes transaction information undeniable. Use these three security cores to protect cardholders and online stores on the Internet. Road transactions in double ...

第5頁 538357 五、發明綱⑶ '" —— 方的權利;也由於需保障其交易過程中的安全性,所以在 SET電子商務機制中。持卡人、網路商店、銀行都必須取 得認證中心(Certificate Authority,簡稱CA)認證,此 外’構成SET’軟體規格的四個要素為持卡人的「錢包」軟 體、特約商店軟體、支付閘門伺服器軟體、認證授權軟 體,雖然SET三項安全核心為電子商務提供高安全性,然 而卻因各環節皆必須取得CA認證以及引入SET軟體規格'的 四個要素所產生高複雜性、高成本與低利性等因素,導致 於SET的推廣不易;顯然,SET有個便利性、高成本而導致 市場接受度不高的缺失。 而SSL·購物付款之交易流程,請配合參看第二圖所 示,係持卡人(20)進入可提供SSL的購物網頁,在“03網 頁’能保證資料傳輸過程的安全,倘若有人從中擷取,所 看到的均是毫無意義的亂碼,持卡人(2〇)委託網路商店 (2 1 )做卡片授權。持卡人(2 〇 )輸入欲購買之商品資訊及卡 片相關資料,請網路商店(21)代為授權,網路商店(21) 卡等資料傳至付款銀行⑵ (21)通知持卡人(20)授權結果,完成交易,網路商店(21) 根據其授權結果來完成交易,並告知持卡人(2〇)其授權交 易結果,貨品送出後,網路商店(21)將向信用卡中心(22) 明放,按SSL係藉由通路的加密,提供完整的隱私。 因為資料可經過公開的通路安全的傳送,因此&當持卡人與 可信賴的網路商店往來時,SSL可提供充分的安全性;SSL 電子商務系統是由CA去做網路商店認證,使網路商店成Page 5 538357 V. Outline of the invention ⑶ "" —— the right of the party; also because it needs to guarantee the security in the transaction process, it is in the SET e-commerce mechanism. Cardholders, online stores, and banks must all obtain Certificate Authority (CA) certification. In addition, the four elements that constitute the SET software specification are cardholder's "wallet" software, special store software, and payment gates. Server software, certification and authorization software. Although the three security cores of SET provide high security for e-commerce, they have high complexity and high costs due to the need to obtain CA certification in each link and the introduction of the four elements of SET software specifications. Factors such as low profitability have made it difficult to promote SET. Obviously, SET has a lack of convenience and high cost, resulting in a lack of market acceptance. For the transaction flow of SSL · shopping payment, please refer to the second picture. The cardholder (20) enters the shopping page that can provide SSL. The "03 page" can ensure the security of the data transmission process. The cardholder (20) entrusts the online store (21) to authorize the card. The cardholder (20) enters the product information and card-related information to be purchased , Please ask the online store (21) to authorize it. The online store (21) card and other information should be transferred to the payment bank. (21) Notify the cardholder (20) of the authorization result and complete the transaction. The online store (21) according to its authorization The result is to complete the transaction, and inform the cardholder (20) of the authorization transaction result. After the goods are delivered, the online store (21) will be exposed to the credit card center (22). According to the SSL system, it will provide complete integrity through the channel encryption. Because the data can be transmitted securely through open channels, & when cardholders communicate with trusted online stores, SSL can provide sufficient security; SSL e-commerce systems are networked by the CA Store certification

第6頁 538357 五、發明說明⑷ — —- 為可信賴的商店;由於SSL成本低於SET,且對持卡人而言 =需安裝電子錢包等的考量,造成目前SSL全球使用率上 高;然而在SSL交易過程中,持卡人是透過網路商店 ,行信用卡授權交易,因此網路商店將擁有持卡人的個人 f料及信用卡資料,一旦駭客入侵該網路商店竊取持卡人 貝料,將造成重大損失;這樣的事情正不斷地發生,不少 头名、、罔站雖稱線上父易機制安全絕對無慮,卻仍遭駭客 入侵:竊走用戶的資料,如:唱片公司⑸“油^ ^^^網 站、叔遊網站Travelocity和全球最大線上零售網站亞 ίΪ:網2Bibi〇find等,因此儘管業者不斷強調線上交 、^度安全性,但以一般使用ss[做為線上交易的機 :m的安全性仍對網路商店及持卡人構威嚴重威 ,^為SSL只關注在網路上傳輸時的安全性;此外,我 3 :ΐ要求所有網路商店花大成本來保護自己的網站。 力研究疋與SSL的缺失,本發明人等乃積極努 也改盖兮I'/曰 終於發展出具有SE 丁及SSL的優點, 明統的缺點,以做為SET和ssl的平衡點之本發 月%子商務金融交易授權方法與系統。 持卡人目的’在於提供-種不讓網路商店取得 商店建置成本,麵者身 為芙礎,以兼具較佳安全性與便利性,利用現有機制 收到該訂單後產生交具真fa丁早再按下付款鍵,網路商店 父易碼與訊息摘要值,並傳送到j a v aPage 6 538357 V. Description of the invention ⑷ — —- is a trusted store; because the cost of SSL is lower than SET, and for cardholders = considerations such as the need to install an electronic wallet, the current global usage of SSL is high; However, in the SSL transaction process, the cardholder authorizes the transaction through the online store. Therefore, the online store will have the personal information and credit card information of the cardholder. Once a hacker invades the online store, the cardholder will be able to steal the cardholder's account. It is expected that major losses will be caused; such things are happening constantly. Although many top names, and stations have called the online parent-exchange mechanism safe and secure, they are still hacked: users ’data is stolen, such as: record companies ⑸ “You ^ ^ ^ ^ website, Shuyou website Travelocity and the world ’s largest online retail website Asia Ϊ 网: 2Bibi〇find, etc., so despite the industry ’s continuous emphasis on online safety, safety, but generally use ss [as an online Transaction machine: The security of m is still a serious threat to online stores and cardholders. ^ SSL is only concerned about the security of transmission on the Internet. In addition, I 3: I require all online stores to spend a lot of cost Lai Bao My own website. Researching the lack of SSL, the inventors, etc. have been actively working on it. I've finally developed the advantages of SE and SSL, and the shortcomings of Tongtong as SET and SSL. The balance point of this month is the method and system for authorizing commercial financial transactions. The purpose of the cardholder is to provide a way to prevent online stores from obtaining store construction costs. Convenience, using the existing mechanism to receive the order and generate a real payment, and then press the payment key, the online store parent code and message summary value, and send it to java

538357 五、發明說明(5) ^ ^ ' —538357 V. Description of the invention (5) ^ ^ '—

Applet ; f持卡人按下付款鍵時,會下載java “叩 applet並f買取持卡人電腦内的檔案的卡片資料,並產生該一 卡片的發卡銀行之按鍵,按下該發卡銀行按鍵後,Java s/gn applet'開啟該發卡銀行的轉帳網頁,並將交易碼及 Λ心摘要值傳送到該轉帳網頁,持卡人在轉帳網頁上輸入 持卡人的身份字號及發卡銀行認證帳號與密碼;發卡銀行 收到f卡人卡片資料、持卡人身份字號與帳號、密碼、交 易、,息摘要值,並確認持卡人卡片資料;持卡人身份字 號與密碼正確無誤,則將交易碼、訊息摘要值和轉帳資料 傳送心款銀行,收款銀行依據交易碼驗證訊息 1無=,則接党該筆轉帳,並接受轉悵請求的訊息告知發 銀灯,且將已完成轉帳的交易碼傳送到網路商店,_ ,:S:接受轉帳請求的訊息*;透過網頁告知持卡人 行3=目前卡片的餘額,、網路商店收到來自收款銀 仃已凡,,帳的交易碼後,透過網頁即時告知持卡人 土:::易碼與訊息摘要值不相符,則不 清求’並告知發卡銀行,發卡銀行再告 功之訊息。 了下入轉帳不成 為便於、貴審查委員深入了解本發明之技術手 作目的與達成功效。自附以實施詳細說明如后。 :發:之電子商務金融交易授權方法流程:請配人夂 看第一圖所不,係使持卡人(3〇)先 口 ς :::擇:商4Γ,並填寫收貨人相關 人姓名聯絡方式。寄送地址)後,持卡人(3〇)按下付款Applet; When the cardholder presses the payment button, the java "叩 applet" will be downloaded to buy the card information in the file on the cardholder's computer, and the key of the card issuing bank will be generated. After pressing the button of the card issuing bank, , Java s / gn applet 'opens the transfer webpage of the card-issuing bank, and transmits the transaction code and Λ heart summary value to the transfer webpage. The cardholder enters the cardholder's identity number and the issuing bank's authentication account number and Password; the card-issuing bank receives the f cardholder card information, cardholder identification number and account number, password, transaction, and digest value, and confirms the cardholder card information; if the cardholder identification number and password are correct, the transaction Code, message summary value, and transfer information to the sending bank, and the receiving bank verifies that the message 1 is not available according to the transaction code, then the party receives the transfer, and accepts the transfer request message to inform the issuing bank of the light, and the transfer has been completed. The transaction code is sent to the online store, _ ,: S: A message to accept the transfer request *; inform the cardholder via the webpage 3 = the current card balance, and the online store has received the payment from the bank, After the transaction code is issued, the cardholder will be notified immediately via the webpage ::: The easy code does not match the value of the message summary, so please do n’t know clearly and tell the card-issuing bank, and the card-issuing bank will report the success. Your reviewing committee has a thorough understanding of the technical purpose of the present invention and its effectiveness. It is attached with a detailed description of the implementation as follows.: Issue: The flow of authorization methods for electronic commerce financial transactions: Please assign someone to see what is not in the first picture. After making the cardholder (30) first greet ::: select: business 4Γ, and fill in the contact information of the person in charge of the consignee. The mailing address), the cardholder (30) presses the payment

538357 五、發明說明(6)538357 V. Description of the invention (6)

鍵,網路商店(32)收到該筆訂單。便產生該筆交易的交易 碼,並將該交易碼使用MAC(Message authentication Code) key產生出一組訊息摘要值’網路商店(31)再將交 易碼及訊息摘要值傳送到java applet ·,且當持卡人(3 0) 按下付款鍵後,也會下載來自金資中心(32 )(FEDI) (BANK NET)的java sign applet ,而java sign applet 將自動讀 取持卡人(30)電腦内的檔案,取得檔案内的卡片資料,而 依據其卡片資料產生該卡片的發卡銀行之按鍵,按―下該發 卡銀行按鍵,java sign applet 將開啟發卡銀行的轉帳 網頁,java sign applet也將交易碼及訊息摘要值傳送 到該發卡銀行的轉帳網頁,同時持卡人(3〇)在轉帳網頁上 祭看該筆交易資料是否無誤,若正蜂無誤,則輸入持卡人 (3 0 )在該發卡銀行所設定的身份字號與帳號密碼(丨^ & password) 持卡人身份 摘要值,發 身份字號與 訊息摘要值 (34)依據交 誤,則接受 銀行,且將 卡銀行收到 人(30)已完 來自收款銀 ,發卡銀行收到資料為持卡人(3 〇 )卡片資料、 字號、發卡銀行認證帳號與密碼、交易、訊章、 ^銀行確認持卡人(30)卡片資料.、持卡人(°3(^ 密碼是否正確’如果正確無誤,則將交易碼、 和轉帳資料傳送到收款銀行(34),收款銀行 易碼去驗證訊息摘要值是否正確,若正確盔 帳’並將接受轉帳請求的訊息告知發卡 已:易碼傳送到網路商店⑶),發 已接文轉帳請求的訊息後, 成轉帳及目前卡片的铨=透過、、罔f。知持卡 Λ 的餘額’網路商店(3 1 )收到 已完成轉帳的交易碼後,透過網頁即時 538357 五、發明說明(7) 告知持卡人(30)交易成功,若交易石馬與訊息摘要值不相 付土則不接受該筆轉帳請求,並告知發卡銀行,發卡銀行 再二知持卡人(30)轉帳不成功之訊息,同時收款銀行亦會 將父易不成功的訊息傳送到網路商店,網路商店透過網頁 告知持卡人『交易不成功』訊息。 其中,java sign applet依據持卡人卡片資料可產 生數個付款銀行(33)之按鍵,讓持卡人自由選擇欲使用轉 帳之付款銀行(33)。 再者,本發明電子商務金融交易授權系統,係包含 有·· 於吹*丨傳輸工具,jaVa Slgn appl et,讓網路商店用來傳 輸—貝料給發卡銀行;讓持卡人用來傳輸資料給發卡銀行; 戶資i接收處理系、统,設於銀行,用以接收交易資料與用 -發送處理系統’設於網路商店,用以發送交易資 料, 一傳輸網路,用以傳輸發送或接收交易資料與用戶資 料, 用戶,用以進行父易之使用工且 其中,用戶端可為一瀏覽網頁之工具 以下為本發明具體應用的過程: 本發明電子商務金融系統Press and the online store (32) receives the order. Generate the transaction code of the transaction, and use the MAC (Message authentication Code) key to generate a set of message digest values for the transaction code. The online store (31) then sends the transaction code and message digest value to the java applet. And when the cardholder (3 0) presses the payment key, the java sign applet from the financial center (32) (FEDI) (BANK NET) will also be downloaded, and the java sign applet will automatically read the cardholder (30 ) The file in the computer to get the card information in the file, and generate the key of the issuing bank of the card based on its card information, press ―press the key of the issuing bank, the java sign applet will open the transfer page of the issuing bank, and the java sign applet also Send the transaction code and message summary value to the card transfer bank's transfer web page, and at the same time, the cardholder (30) will check whether the transaction information is correct on the transfer page. If the transaction is correct, enter the cardholder (3 0 ) The identity number and account password (丨 ^ & password) of the card issuer set the cardholder ’s identity summary value, and the identity number and message summary value (34) are based on the mistake, the bank will be accepted, and The recipient of the bank (30) has completed the payment from the receiving bank, and the information received by the card-issuing bank is the cardholder's (30) card information, font size, card-issuing bank authentication account number and password, transaction, stamp, and bank confirmation cardholder (30) Card information. Cardholder (° 3 (^ Is the password correct? If it is correct, send the transaction code and transfer information to the beneficiary bank (34), and the beneficiary bank's e-code to verify the message summary value Is it correct? If the helmet account is correct, and inform the card issuer of the message of accepting the transfer request: E-code is sent to the online store (3). After the message of the transfer request is sent, the transfer and the current card will be sent.罔 f. Know the balance of the card Λ '. The online store (3 1) received the transaction code of the completed transfer, and then real-time via the webpage 538357. 5. Description of the invention (7) Inform the cardholder (30) that the transaction was successful. If Shima does not pay the sum of the message summary, the transfer request will not be accepted, and the card issuer will be informed that the card issuer will know the cardholder's (30) message that the transfer was unsuccessful. Success message sent to the web Road stores, online stores inform the cardholder of the "successful transaction" message through the webpage. Among them, the java sign applet can generate several keys of the payment bank (33) based on the cardholder card information, allowing the cardholder to freely choose which to use The payment bank for transfer (33). Furthermore, the e-commerce financial transaction authorization system of the present invention includes a ... transfer tool, jaVa Slgn appl. ; Let cardholders use it to transmit data to the card-issuing bank; Account asset receiving and processing system and system are set up at the bank to receive transaction data and the use-send processing system is set up at online stores to send transaction data, A transmission network for transmitting or receiving transaction data and user data. The user is used for the use of the parent. Among them, the client can be a tool for browsing the web. The following is a specific application process of the present invention: The present invention E-commerce financial system

Payment Gateway是商店與金 演的角色如以下所敘: 之準備: 融銀行的溝通橋樑,其所扮Payment Gateway is the role of the store and the show as described below: Preparation: The communication bridge of the financial bank

538357 五、發明說明(8) 透過Internet接收商店的付款/請款等Electr〇nic Commerce(EC)需求訊息。 將商店的EC需求訊息轉換為現行交易格式is〇8583, 透過通訊介面傳送給金融銀行主機,並接受回應。 將銀行主機回應轉換為EC回應訊息,透過匕忟^以回 傳給商店。 W e b B a s e系統之方法: 由於要解決SET系統中持卡人需安裝電子錢包的問 題’所以我們採用W e b B a s e的方式,以及利用簽署認證 的Java applet來達到此目標;我們的方法是當持卡人 進行交易時,下載並執行金資中心提供的簽署java applet,網路商店透過applet與網路銀行傳輸資料,並且 提供持卡人選擇要轉帳的銀行。 達到W e b B a s e此目標的詳細步驟如下: 持卡人先在網路商店網頁訂單上選擇好商品資料,並填寫 收貨人相關資料(例如收貨人姓名、聯絡方式、寄送地址) 後,持卡人再按下付款鍵,網路商店收到訂單,便產生該 筆交易的父易碼’並將交易碼使用MAC(Message Authentication Code) Key 產生出一組訊息摘要值,網 路商店再將交易碼及訊息摘要值傳送到j a v a a p p 1 e t ;且 當持卡人按下付款鍵後,會下載來自金資中心的簽署 applet,網路商店使用收款銀行所給的MAC(Message Authentication Code)Key,來保證資料完整性;applet 去讀取持卡人存放在硬碟内的只含銀行帳號的文字檔,根538357 V. Description of the invention (8) Receiving payments / requests from stores via the Internet for Electronic Commerce (EC) demand messages. The EC demand message of the store is converted into the current transaction format is 08583, which is transmitted to the host of the financial bank through the communication interface, and the response is accepted. The host response of the bank is converted into an EC response message, which is sent back to the store via dagger ^. The method of the Web Base system: To solve the problem of cardholders who need to install an electronic wallet in the SET system, we use the Web Base method and use a signed Java applet to achieve this goal; our method is When the cardholder makes a transaction, download and execute the signed java applet provided by the financial center, the online store transmits data to the online bank through the applet, and provides the cardholder to choose the bank to transfer money. The detailed steps to achieve this goal are as follows: The cardholder first selects the product information on the order on the online store webpage, and fills in the relevant information of the consignee (such as the consignee's name, contact information, and delivery address). , The cardholder presses the payment key again, the online store receives the order, and generates the parent easy code of the transaction, and uses the MAC (Message Authentication Code) Key to generate a set of message summary values. The online store Then send the transaction code and message summary value to javaapp 1 et; and when the cardholder presses the payment key, it will download the signed applet from the financial center, and the online store uses the MAC (Message Authentication Code) given by the beneficiary bank. ) Key to ensure data integrity; the applet reads the text file containing only the bank account number stored by the cardholder in the hard disk, and

538357 五、發明說明(9) 據銀行帳號,app 1 et則把交 頁,並自動將帳號輸入進去 料,持卡人只需確認其資料 及帳號密碼;等候轉帳結果 行’收款銀行驗證MAC Key 絕該筆交易’若正確,則接 轉帳結果告知持卡人。 易資料送至該網路銀行轉帳網 ’網路銀行將顯示所收到的資 疋否正確,再輸入身分證字號 ’付放銀行將資料轉至收款銀 是否正確,若不正確,則拒 受該筆交易,同時付款銀行將 以下為本發明詳細交易授權流程(請再配合參看第 圖所示): 持卡人(30)在網路商店(31)網頁選擇商品資料並填寫 收貨人貪料(收貨人姓名、聯絡方式寄送地址等),將資料 使用SSL方式傳送資料至網路商店(31 );網路商店(3 1)收 到訂單後,產生『交易碼』,並將『交易碼』加MAC,當 持卡人按下付款鍵後,將下載金資中心(32 )簽署過的 applet,而『交易碼』則透過此apPiet傳送給網路銀 行,持卡人在applet上選擇好付款銀行(33)帳號後, applet使用SSL方式將交易資料傳至該發卡銀行;持卡人 在發卡銀行的網頁上確定該資料正確無誤後,就輸入身分 證字號及帳號密碼,發卡銀行將收到的資料傳送到 Payment Gateway,Payment Gateway 將資料轉換成在銀 行網路中,做為電子資料交換的特定格式後,傳至付款銀 行(33)主機,付款銀行(33)主機將該筆交易資料透過金資 中心(32)傳至收款銀行(34)進行『轉帳請求』;收款銀行 (34)認證該筆加MAC的『交易瑪』是否正確,如果正確無538357 V. Description of the invention (9) According to the bank account number, app 1 et submits the page and automatically enters the account number. Cardholders only need to confirm their information and account password; wait for the result of the transfer. The Key must never make a transaction. 'If the transaction is correct, the transfer result is notified to the cardholder. Send the data to the online bank transfer network. The online bank will display whether the received funds are correct, and then enter the identity card number. The payment bank is correct to transfer the data to the receiving bank. If it is not correct, it will be rejected. After receiving the transaction, the paying bank will provide the detailed transaction authorization process of the present invention (please refer to the figure below): Cardholder (30) selects the product information on the web store (31) webpage and fills in the consignee Greedy (consignee name, contact address, etc.), send the data to the online store using SSL (31); after receiving the order, the online store (31) generates a "transaction code", and Add the "transaction code" to the MAC. When the cardholder presses the payment button, the applet signed by the Financial Center (32) will be downloaded, and the "transaction code" will be sent to the online bank through this apPiet. After selecting the payment bank (33) account number on the applet, the applet uses SSL to transfer the transaction information to the card issuing bank; after the cardholder confirms that the information is correct on the card issuing bank's page, he enters his ID number and account password. Card issuing silver Send the received data to the Payment Gateway. The Payment Gateway converts the data into a specific format for electronic data exchange in the bank network, and then sends it to the host of the payment bank (33). The host of the payment bank (33) sends the data The transaction information is transmitted to the beneficiary bank (34) through the fund center (32) to perform a "transfer request"; the beneficiary bank (34) verifies that the transaction MAC with the MAC is correct.

538357 五、發明說明(10) 誤,則接受該筆交易,如果是铒筑 透過金資中心(32)傳送『轉帳^應,蛉巨^該筆交易,並 機;付款銀行(33)主機將『轉帳;:,:::行(33)主 Gateway,Payment Gateway 收『^』傳运⑺ Pay-nt 甘功上 J轉帳回應』,轉換成 imr:卡,)轉帳結果;若收款銀丄)接 父易後,將即時地告知網路商店(31 店(31)得知已收到該筆交易,則告知持卡 (3 ί元成,並產生『交易成功碼』傳送給持卡人 碑杏^貝 寄送;持卡人(3〇)可以使用『交易成功 碼』查洵交易送貨情形。 化商務不像傳統交易方式那般交易過程透明 易僂ίΐί因網路交易過程複雜,所以預防與解決每個交 n過程可能發生的錯誤,是必須且重要的;本 行網路進行轉帳1以每筆交易情形都會記錄在 款銀行,因此該記錄可為持卡人與網路商店提供 接1士 t性丄此外透過網路商店和收款銀行簽章機制,可 I明70整性,由於系統傳輸過程是建置在s S L·上, 也保證交易的私密性;此外,本系統強迫apput讀 取磁碟資料,所以間接利用sandb〇x來匡住惡意 jplet —因此只有簽署的applet可順利讀取帳號,所以 二二確定此applet的可靠性,並防止類似之前有人架設 又國商銀網站,取得持卡人帳號和密瑪的事件發生。 =此,依上述之本發明並配合參看附件—所示,我們可以 歸納本發明具有以下幾點特色:538357 V. The description of the invention (10) is incorrect, then the transaction is accepted. If it is set up, the bank transfers the "transfer ^ response, 蛉 giant ^ the transaction, and the machine is parallel; the payment bank (33) host will "Transfer;:, ::: Line (33) The main Gateway, Payment Gateway receives the" ^ "transfer ⑺ Pay-nt Gan Gong on J transfer response" and converts it into an imr: card, the transfer result; if the payment is received ) After picking up the parent, it will immediately inform the online store (31 stores (31) that it has received the transaction, then notify the cardholder (3 Yuan Yuan), and generate a "transaction success code" to send to the cardholder tablet Send by apricot; cardholder (30) can use "transaction success code" to check the transaction delivery situation. Chemical commerce is not as transparent and traditional as the traditional transaction method. Because the online transaction process is complicated, so It is necessary and important to prevent and resolve possible errors in each payment process; the bank's online transfer1 will be recorded in the bank with each transaction situation, so this record can be provided to cardholders and online stores 11 士 t 性 In addition, through the online shop and receiving bank signature mechanism, you can The integrity of the system is 70. Since the system transmission process is built on s SL ·, the privacy of the transaction is also guaranteed. In addition, the system forces apput to read the disk data, so sandb〇x is used to indirectly host the malicious jplet — Therefore, only the signed applet can read the account number smoothly, so confirm the reliability of this applet, and prevent similar incidents such as someone setting up the ICBC website and obtaining the cardholder account and Mi Ma. = This, according to the above With reference to the appendix of the present invention, as shown, we can summarize the following features of the present invention:

538357 五、發明說明(11) " ---—-- 1.FSEC可提供沒有信用卡之持卡人使用金融卡進行 電子商務的服務。 2 ·持卡人可靈活運用各銀行的個人帳戶,做即時付次 或是後付款的方式,做理想且有效率的理財。 开 3 ·不受作業系統影響。 4·持卡人不需安裝電子錢包。 5 ·持卡人卡片資料不會被網路商店知道。 ^ 6·持卡人由銀行來實行認證,比目前SSL·付款機制, 父由網路商店以會員認證方式,提供更嚴謹的認證方式。 7·使用簽署過的aPPiet代替電子錢包,因此若有版 本更新,僅需由發行機構更換即可。 8·可用於即時募款、證券交易(不限定銀行付款)等, :SL用於電子商務的功能涵蓋進去,並提供更嚴謹的安 全性’且提高其便利性。 9.由於本發明是以SSL為基礎,所以在網路交易過程 中’可能發生的法律、交易等問題,其解決的方式與目 解決方式一樣。 ^ $上所述’如何利用科技創造更舒適便利的生活環境 疋大家的理想與目標,希望將來能塑造一個無須攜帶現金 或卡片’甚至不需要這些設備就能進行交易的環境,持卡 ^不需安裝電子錢包軟體;本發明取SET及SSL的優點且有 ^改善兩系統的缺點,其所具體界定於申請專利範圍之技 術内容’實已符合電子商務發明專利要件,爰依法具文提 出申睛’僅請鈞局依法核予專利,以維護本申請人合法538357 V. Description of Invention (11) " ------ 1. FSEC can provide cardholders without credit cards to use financial cards for e-commerce services. 2 · Cardholders can flexibly use the personal accounts of banks to make immediate or post-payment methods to make ideal and efficient financial management. On 3 • Not affected by the operating system. 4. Cardholders do not need to install an electronic wallet. 5 · Cardholder card information will not be known to online stores. ^ 6. The cardholder is authenticated by the bank. Compared with the current SSL · payment mechanism, the online store provides a more rigorous authentication method by the member authentication method. 7. Use signed aPPiet instead of e-wallet, so if there is a version update, it only needs to be replaced by the issuer. 8. It can be used for real-time fundraising, securities transactions (without restrictions on bank payments), etc.: SL's functions for e-commerce are covered and provide more rigorous security ’and improve its convenience. 9. Since the present invention is based on SSL, the legal and transactional issues that may occur during the network transaction process are solved in the same way as the objective solution. ^ "How to use technology to create a more comfortable and convenient living environment 疋 Everyone's ideals and goals, I hope that in the future, we can create an environment where transactions can be carried out without carrying cash or cards", even without these devices. Card holders ^ No Electronic wallet software needs to be installed; the present invention takes the advantages of SET and SSL and has the disadvantages of improving both systems. The technical content specifically defined in the scope of the patent application 'actually meets the e-commerce invention patent requirements. Eyes only, please ask the Bureau to grant patents in accordance with the law in order to maintain the legality of the applicant

第14頁 538357 五、發明說明(12) 之權益。Page 14 538357 V. Rights of Invention Statement (12).

第15頁 538357 圖式簡單說明 (一) 圖式部分 第一圖係習知SET交易授權關係架構示意圖。 / 第二圖係習知SSL交易授權關係架構示意圖。 第三圖係本發明交易授權架構示意圖。 附件一係本發明與SET、SSL之比較表。 (二) 圖號部分: (1 0 ) ( 2 0 ) ( 3 0 )持卡人 (1 1) ( 21) ( 3 1)網路銀行 (22)信用卡中心 ( 2 3 )( 33 )付款銀行 - (3 2 )金資中心 (3 4 )收款銀行Page 15 538357 Schematic description (1) Schematic part The first diagram is a schematic diagram of the known SET transaction authorization relationship structure. / The second diagram is a schematic diagram of a conventional SSL transaction authorization relationship architecture. The third diagram is a schematic diagram of the transaction authorization architecture of the present invention. Attachment 1 is a comparison table between the present invention, SET and SSL. (2) Part of drawing number: (1 0) (2 0) (3 0) Cardholder (1 1) (21) (3 1) Online Banking (22) Credit Card Center (2 3) (33) Payment Bank -(3 2) Funding Center (3 4) Receiving Bank

第16頁Page 16

Claims (1)

538357538357 1 · 一種電子商務金融交易授權方法,其係持卡人 在網路商店網頁訂單上選擇好商品資料,並填寫收貨人相 關資料(例如收貨人姓名、聯絡方式、寄送地址)後,持卡 人再按下付款鍵,網路商店收到該訂單,便產生該筆交易 的交易碼,並將將交易碼使用MAC(Message 又 Authentication Code)Key產生出一組訊息摘要值,網路 商店再將交易碼及訊息摘要值傳送到java sign applet 將自動讀取持卡人電腦内的檔案,取得檔案内的卡片資 料,而依據其卡片資料產生該卡片的發卡銀行之按鍵,、按 下該發卡銀行按鍵後,java sign applet將開啟該發卡 銀行的轉帳網頁,java sign appl et也將交易碼及訊息 摘要值傳送到該發卡銀行的轉帳網頁,同時持卡人在轉“帳 網頁上察看該筆交易資料是否無誤,若正確無誤,則輸二 持:人在該發卡銀行所設的身份字號、發卡銀行認證帳號 與密碼(i d & p a s s w 〇 r d );發卡銀行收到資斜給技丰λ上 片資料、持卡人身份字號與密碼、交易、訊 卡銀打確認持卡人卡片資料、持卡人分份字號與密碼是否 正確,如果正確無誤,則將交易碼、訊息摘要值和轉帳資 料傳送到收款銀行’收款銀行依據交易碼去驗證訊息摘要 值疋否正確’若正確無誤,則接受該葦轉帳,並將接受轉 帳請請求的訊息告知發卡銀行,且將已完成轉帳的交易碼 傳送到網路商店,發卡銀行收到以接受轉帳請求的訊息 後’透過網頁告知持卡人已完成轉帳及目前卡片的餘額, 網路商店收到來自收款銀行已完成轉帳的交易碼後,'透過1 · An e-commerce financial transaction authorization method, where the cardholder selects the product information on the order on the online store webpage and fills in the relevant information of the consignee (such as the consignee's name, contact information, and delivery address). When the cardholder presses the payment key again, the online store receives the order, generates a transaction code for the transaction, and uses the MAC (Message and Authentication Code) Key to generate a set of message summary values. The store will then send the transaction code and message summary value to the java sign applet, which will automatically read the file in the cardholder's computer to obtain the card information in the file, and then generate the key of the card-issuing bank of the card based on its card information. After the card-issuing bank presses the button, the java sign applet will open the transfer page of the card-issuing bank, and the java sign applet will also send the transaction code and message summary value to the transfer page of the card-issuing bank. At the same time, the cardholder will check on the transfer account page Whether the transaction information is correct. If it is correct, lose the second holder: the identity number set by the issuing bank, the verification account of the issuing bank and Code (id & passw 〇rd); card issuing bank received the information from Gongfeng λ uploading information, cardholder identification number and password, transaction, information card silver card confirmation cardholder card information, cardholder share Whether the font size and password are correct. If they are correct, send the transaction code, message summary value, and transfer information to the beneficiary bank. 'The beneficiary bank verifies the message summary value based on the transaction code. Is it correct?' If it is correct, accept the reed. Transfer the funds, and inform the card-issuing bank of the message that the request for the transfer is accepted, and send the transaction code of the completed transfer to the online store. After the card-issuing bank receives the message to accept the transfer request, 'the cardholder is notified via the webpage that the transfer has been completed and The current card balance, after receiving the transaction code from the beneficiary bank that the bank has completed the transfer, >38357 /、'申請專利範圍 網頁即時止知 相符,則;功,*交易碼與訊息摘要值不 行再告知持卡人轉帳以,並告知發卡銀行,發卡銀 、 人轉帳不成功之訊息。 如申凊專利範圍第1項所述之電 授權方法;其中,h · 包千商務金融父易 、甲 Java S1gn applet依據格士人丰ΰ二欠 料可產生數個付款銀行按、 貝 轉帳之付款銀行。 建a持卡人自由選擇欲使用 3 . -種電子商務金融交易授權系統,其係包含有: 一傳輸工具,java sign applet,讓網路商店用來傳 輸資料給毛卡銀行;亦讓持卡人用來傳輸資料給發卡銀 行 -接收處理系統 戶資料; 一發送處理系統 設於銀行’用以接收交易資料與用 設於網路商店,用以發送交易資 料; 一傳輸網路,用以傳輸發送或接收交易資料與用戶資 料; 一用戶端,用以進行交易之使用工具。> 38357 / 、 'Patent application scope webpage real-time notification matches, then; function, * transaction code and message summary value are not available, then inform the cardholder to transfer funds, and inform the card-issuing bank that the card-issuing bank and the person did not transfer successfully. The power authorization method described in item 1 of the scope of patent application; among which, h · Baoqian Business Finance, Fangyi, and Java S1gn applet can generate several payment bank deposits and credit transfers according to Geshi Renfeng's second debt. Payment bank. A cardholder is free to choose to use 3. A kind of electronic commerce financial transaction authorization system, which includes: a transmission tool, java sign applet, which is used by online stores to transmit data to hair card banks; also allows cardholders A person is used to transmit data to the card-issuing bank-receiving processing system; a sending processing system is set up at the bank 'to receive transaction data and is set up at an online store to send transaction data; a transmission network is used to transmit data Send or receive transaction and user information; a client, a tool used to conduct transactions. 4·如申請專利範圍第3項所述之電子商務金融交易授權 系統;其中,用戶端可為一瀏覽網頁之工具。4. The electronic commerce financial transaction authorization system as described in item 3 of the scope of patent application; wherein the client can be a tool for browsing the web.
TW90126353A 2001-10-23 2001-10-23 Authorization method and system for electronic commerce financial transaction TW538357B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW90126353A TW538357B (en) 2001-10-23 2001-10-23 Authorization method and system for electronic commerce financial transaction

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW90126353A TW538357B (en) 2001-10-23 2001-10-23 Authorization method and system for electronic commerce financial transaction

Publications (1)

Publication Number Publication Date
TW538357B true TW538357B (en) 2003-06-21

Family

ID=29546782

Family Applications (1)

Application Number Title Priority Date Filing Date
TW90126353A TW538357B (en) 2001-10-23 2001-10-23 Authorization method and system for electronic commerce financial transaction

Country Status (1)

Country Link
TW (1) TW538357B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110050285A (en) * 2016-07-13 2019-07-23 李成元 Utilize the card payment authorization method and system of the mobile terminal of the holder of mobile phone fiscard

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110050285A (en) * 2016-07-13 2019-07-23 李成元 Utilize the card payment authorization method and system of the mobile terminal of the holder of mobile phone fiscard

Similar Documents

Publication Publication Date Title
US11645640B2 (en) Authentication and payment system and method using mobile communication terminal
US11398910B2 (en) Token provisioning utilizing a secure authentication system
US11256789B2 (en) Recurring token transactions
US20190356489A1 (en) Method and system for access token processing
RU2520392C2 (en) Electronic payment system and payment authorisation method
CN101354770B (en) Use the system and method that five side's protocol realization bank cards pay
RU2438172C2 (en) Method and system for performing two-factor authentication in mail order and telephone order transactions
US7757945B2 (en) Method for electronic payment
CN110612546A (en) Digital asset account management
CN111343233A (en) Digital currency payment method and device based on storage and mobile terminal
US20080257952A1 (en) System and Method for Conducting Commercial Transactions
US20110103586A1 (en) System, Method and Device To Authenticate Relationships By Electronic Means
CN105590214A (en) Payment method and payment system based on virtual card
WO2001050429A1 (en) Smartcard internet authorization system
CA2686280A1 (en) Method and system for payment authorization and card presentation using pre-issued identities
AU2006277397A1 (en) Electronic settlement system, method therefor, settlement server used therein, communication terminal, and program
TW201419185A (en) Mobile device, payment transaction system and payment transaction method
JP2019525645A (en) Cryptographic authentication and tokenized transactions
TW202127340A (en) Registration and payment methods and devices for cross-region offline payment
TWM577549U (en) Virtual wallet account payment system
CN112970234B (en) Account assertion
SK500202011A3 (en) Method of cashless transfer money from person to person through mobile phone
TW538357B (en) Authorization method and system for electronic commerce financial transaction
KR20080079714A (en) A system and method of certifying cardholder using mobile phone
TW201917647A (en) Virtual wallet account payment method in which a virtual account is opened in an offshore financial institution by using an account of an on-shore financial institution for fund transfer through a business account established in the offshore financial institution

Legal Events

Date Code Title Description
GD4A Issue of patent certificate for granted invention patent
MM4A Annulment or lapse of patent due to non-payment of fees