TWI521450B - A payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction - Google Patents

A payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction Download PDF

Info

Publication number
TWI521450B
TWI521450B TW100110480A TW100110480A TWI521450B TW I521450 B TWI521450 B TW I521450B TW 100110480 A TW100110480 A TW 100110480A TW 100110480 A TW100110480 A TW 100110480A TW I521450 B TWI521450 B TW I521450B
Authority
TW
Taiwan
Prior art keywords
payment
terminal
card
memory
pos terminal
Prior art date
Application number
TW100110480A
Other languages
Chinese (zh)
Other versions
TW201205477A (en
Inventor
米羅斯拉夫 佛羅瑞克
米歇爾 馬沙瑞克
大衛 艾倫 里費爾麥契
Original Assignee
Smk股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Smk股份有限公司 filed Critical Smk股份有限公司
Publication of TW201205477A publication Critical patent/TW201205477A/en
Application granted granted Critical
Publication of TWI521450B publication Critical patent/TWI521450B/en

Links

Landscapes

  • Cash Registers Or Receiving Machines (AREA)
  • Telephone Function (AREA)

Description

使用如行動電話之行動通信裝置之付費終端及直接帳單付費處理方法Pay terminal using mobile communication device such as mobile phone and direct bill payment processing method

解決方案指一種定位在一行動通信裝置(諸如一行動電話)中之付費終端。為實現付費處理程序,該終端甚至可透過其自身的主要為NPC類型之通信元件進行通信。本發明亦描述一種使用一無接觸傳輸鏈路之直接帳單付費之方法。A solution refers to a paying terminal that is positioned in a mobile communication device, such as a mobile phone. To implement the payment processing program, the terminal can even communicate via its own communication component, primarily of the NPC type. The present invention also describes a method of direct bill payment using a contactless transmission link.

已知永久定位在商辦大樓中之付費終端(POS(銷售點)終端)。POS終端以將錢自購買者之帳戶轉帳至商店業者之帳戶在一協議系統中有安全保護的方式運作。至今,通過POS終端之付費係作為一種付費之特徵,其中收款者具有一POS終端且付費消費者使用一對應卡作為一付費裝置。在第一階段中,運行卡持有者之一檢查、檢驗,此處理程序應受高度安全保護且應在雙方(商家及付費消費者)之合理努力下實現。隨後,運行付費金額自動記入至商店業者之帳戶之一處理程序。起初,僅配備有一磁條之卡用於運行付費終端應用程式。然而,關於技術限制,因為磁條可經複製或隨簡單技術裝置之使用而改變,所以具有載入資料之磁條呈現一安全風險。讀取來自磁條之內部資料係低技術的。It is known to permanently locate a pay terminal (POS (point of sale) terminal) in a commercial building. The POS terminal operates in a manner that is secure in a protocol system by transferring money from the purchaser's account to the store operator's account. To date, payment through a POS terminal has been a feature of payment, in which a payee has a POS terminal and a paying consumer uses a corresponding card as a payment device. In the first phase, one of the operating card holders checks and verifies that the process should be highly secure and should be implemented with reasonable efforts of both parties (merchants and paying consumers). Subsequently, the running payment amount is automatically credited to one of the store's account handlers. Initially, only cards with a magnetic strip were used to run the paid terminal application. However, with regard to technical limitations, magnetic strips with loaded data present a security risk because the magnetic strips can be replicated or changed with the use of simple technical devices. Reading internal data from magnetic strips is low-tech.

因此,在90年代下半期發卡業者歐洲國際萬事達卡(MasterCard)與VISA間做出使用定位在付費卡上之微型晶片關於創建EMV標準之一協議。EMV(Europay MasterCard Visa)標準為確保全球互通性之目介於付費卡晶片與POS終端之間的互動。微型晶片之使用能夠保護定位在微型晶片上之資料,以此方式使得在沒有一PIN情況下不可能自外部存取該等資料。甚至在沒有與處理者總部線上連接情況下,在卡上使用晶片亦能夠實現卡持有者檢驗(Cardholder Verification)。雖然磁條代表被動資料載體,但卡上之晶片基本上係具有其自身的計算容量、具有記憶體之有安全保護部分且具有一資料加密單元之一小型電腦。不管提到的當前POS終端之技術特性,發現在POS終端之內側中之欺騙性調整及操縱之情況下或在將一中間鏈路插入至讀取裝置之情況下,可揭示來自該卡之資料及PIN碼。此通常在受操作人員之不足控制情況下或在其他欺騙方式之情況下不知道具有POS終端之商店所有者時發生。Therefore, in the second half of the 1990s, the card issuer, MasterCard, and VISA made an agreement to create an EMV standard using a microchip positioned on a pay card. The EMV (Europay MasterCard Visa) standard ensures that the interoperability of global interoperability is between the payment card chip and the POS terminal. The use of microchips can protect the data located on the microchip in such a way that it is not possible to access the data from outside without a PIN. Even if there is no online connection to the processor's headquarters, cardholder verification (Cardholder Verification) can be achieved by using the wafer on the card. Although the magnetic stripe represents a passive data carrier, the wafer on the card is basically a small computer having its own computational capacity, a secure portion with memory and a data encryption unit. Regardless of the technical characteristics of the current POS terminal mentioned, it is found that in the case of fraudulent adjustment and manipulation in the inner side of the POS terminal or in the case of inserting an intermediate link into the reading device, the data from the card can be revealed And PIN code. This usually occurs when the store owner of the POS terminal is not known, under the control of the operator's lack of control or in the case of other deceptive methods.

然而直到現在,並未已知能夠將行動電話轉換成此種類付費終端之此等技術工具,該等技術工具可由付費消費者所有且可具有整個業務關係(付款卡發行業者、處理總部、銀行、商家)之個別參與者需要的安全性。However, until now, there has been no known technical tool capable of converting a mobile phone into a pay-type terminal of this type, which can be owned by a paying consumer and can have an entire business relationship (pay card issuer, processing headquarters, bank, The security required by individual participants of the business).

根據CN101351819專利之解決方案指示使用一行動電話作為一POS終端之可能性;然而,其並未處理系統之個別基本元件之特定組織。許多解決方案(諸如根據專利CN101339685、CN101329801、US2008270246(A1)、SI22595(A)、US2008059375之解決方案)描述行動電話參與直接帳單付費,儘管在電話中不直接有獨立的POS終端。或者,如其在US20077241180(A1)檔案中,有一行動電話與一靜態POS終端互動之解決方案。The solution according to CN101351819 indicates the possibility of using a mobile phone as a POS terminal; however, it does not deal with the specific organization of the individual basic elements of the system. Many solutions, such as the solution according to the patents CN101339685, CN101329801, US2008270246 (A1), SI22595(A), US2008059375, describe mobile phones participating in direct bill payment, although there are no separate POS terminals directly in the phone. Or, as in its US20077241180 (A1) file, there is a solution for a mobile phone to interact with a static POS terminal.

對於此一技術解決方案有一要求,即使在網際網路付費或在一般商店外部實現的其他付費(例如,下載行動業者處儲存的程式之付費)之情況下,該技術解決方案將具有EMV付費應用程式之高安全性且將嚴格以EMV標準之形式產生最終付費密碼。此等種類的解決方案目前並不是已知的,或者由於可能透露或誤用在(例如)通過網際網路自付費消費者之付費卡至商家之POS終端或虛擬POS終端之資料傳輸期間之通信或者NFC或GPRS通信,該等解決方案具有以上事實中存在的安全風險。若一般商店中之POS終端與付費卡間之初始靠近接觸加長至通過網際網路環境之通信,則接著安全風險增加。There is a requirement for this technical solution that the technology solution will have an EMV paid application even if the Internet pays or other payments made outside the general store (for example, downloading a program stored at the operator) The program is highly secure and will generate the final paid password strictly in the form of EMV standards. These types of solutions are currently not known, or may be disclosed or misused, for example, during the transmission of data from a pay-per-click consumer's payment card to the merchant's POS terminal or virtual POS terminal, or NFC or GPRS communication, these solutions have the security risks inherent in the above facts. If the initial proximity between the POS terminal and the pay card in the general store is lengthened to communicate through the Internet environment, then the security risk increases.

提到的缺點很大程度上由使用一行動通信裝置(諸如,一行動電話)之一付費終端消除,其中該付費終端含有一記憶體、一介面及微控制器。該微控制器鏈接至該記憶體且透過一介面亦鏈接至該行動通信裝置之電路。該付費終端包含具有一POS付費終端應用程式之一單元且亦包含儲存在該記憶體之有安全保護部分中之一付費終端之組態資料單元。本發明之精髓在於付費終端連同有關組態資料可儲存在一可抽換式記憶體卡上之事實,該可抽換式記憶體卡以此方式經調整使得可將其插入於行動通信裝置之用於額外硬體的插槽中,該插槽用於增加超越該行動通信裝置之基礎功能之功能。The disadvantages mentioned are largely eliminated by the use of a payment terminal such as a mobile communication device, such as a mobile telephone, which contains a memory, an interface and a microcontroller. The microcontroller is linked to the memory and is also linked to the circuitry of the mobile communication device via an interface. The payment terminal includes a configuration data unit having a unit of a POS payment terminal application and also including a payment terminal stored in one of the security portions of the memory. The essence of the invention lies in the fact that the payment terminal can be stored on a removable memory card together with the relevant configuration data, the removable memory card being adjusted in such a way that it can be inserted into the mobile communication device. In a slot for additional hardware, this slot is used to add functionality beyond the basic functionality of the mobile communication device.

解決方案之精髓係以下組態:POS終端之整個處理程序核心可定位在插入於行動通信裝置中之一可抽換式記憶體卡上,同時最有可能的使用存在於該可抽換式記憶體卡插入至行動電話之共同記憶體插槽中。所有內部付費POS終端應用程式之運行可在插入於行動通信裝置中之該可抽換式記憶體卡上實現。可利用付費處理者總部發現通信處理程序中之例外,在該等付費處理者總部中可使用行動通信裝置自身的通信頻道(SMS(短訊息服務)、GPRS通用封包無線電服務)。行動通信裝置之顯示工具可用於顯示付費應用程式之運行。The essence of the solution is the following configuration: the entire processing program core of the POS terminal can be positioned on one of the removable memory cards inserted in the mobile communication device, and the most likely use exists in the removable memory. The body card is inserted into the common memory slot of the mobile phone. The operation of all internal paid POS terminal applications can be implemented on the removable memory card inserted in the mobile communication device. An exception to the communication handler can be discovered by the payment processor headquarters, and the mobile communication device's own communication channel (SMS (Short Message Service), GPRS General Packet Radio Service) can be used in the payment processor headquarters. A display device for the mobile communication device can be used to display the operation of the paid application.

POS終端之處理核心僅傳送至行動電話中之補充記憶體卡中帶來出人意料的技術優點,但其亦造成載入來自付費卡之資料之困難,此係因為行動電話不具有晶片讀卡器。於是當前解決方案之重要特徵在於:甚至在相同硬體設備上(即,在該可抽換式記憶體卡上)可放置有使用者之一付費卡或甚至若干付費卡。以此方式技術上可確保除了具有用於付費終端之資料的該記憶體之該有安全保護部分之外,該可抽換式記憶體卡亦含有具有付費卡資料之記憶體之一分開有安全保護部分。The processing core of the POS terminal is only transmitted to the supplementary memory card in the mobile phone, which brings unexpected technical advantages, but it also causes difficulty in loading data from the pay card because the mobile phone does not have a chip card reader. An important feature of the current solution is that even one of the user's payment cards or even a number of payment cards can be placed on the same hardware device (i.e., on the removable memory card). In this way, it is technically ensured that in addition to the security-protected portion of the memory having the data for the payment terminal, the removable memory card also contains one of the memory devices having the payment card data. Protection section.

在付費應用程式之運行期間,將該可抽換式記憶體卡插入於該行動通信裝置之用於額外硬體之插槽中,該插槽用於增加超越該行動通信裝置之基礎功能之功能。然而並不排除,該插槽將主要係可自該行動通信裝置(諸如,一行動電話)外部存取的最常使用的插槽。有關插槽經設計用於此技術設備,沒有該插槽,該行動通信裝置可滿足其之基本功能。因此考慮中的該插槽並不直接影響資料及/或聲音在業者之網路中之傳輸;事實係該插槽不同於用於SIM(用戶識別模組)卡之介面。該記憶體卡(其係本發明之一重要元件)不具有SIM卡之功能。考慮中的該解決方案中描述的該可抽換式記憶體卡並不取決於行動電話之SIM卡且可被移除或插入於該行動電話中而不干擾該電話之常規功能之任一者。Inserting the removable memory card into a slot for the additional hardware of the mobile communication device during operation of the payment application, the slot for adding functionality beyond the basic functions of the mobile communication device . However, it is not excluded that the slot will be primarily the most commonly used slot accessible externally from the mobile communication device, such as a mobile telephone. The slot is designed for this technical device, without the slot, the mobile communication device can fulfill its basic functions. Therefore, the slot under consideration does not directly affect the transmission of the data and/or voice practitioner's network; in fact, the slot is different from the interface for the SIM (Subscriber Identity Module) card. The memory card, which is an important component of the present invention, does not have the function of a SIM card. The removable memory card described in the solution under consideration does not depend on the SIM card of the mobile phone and can be removed or inserted into the mobile phone without interfering with any of the conventional functions of the phone. .

若付費卡與POS終端間之通信變窄至在運行應用程式期間插入於行動電話中之一硬體裝置內之資料傳輸,則不可能由共同構件監測且誤用此通信。實現付費之後,自該可抽換式記憶體卡發送關於所實現付費之加密資訊。由以EMV標準之形式的充足安全性區分此資訊。在共同組態中,該行動通信裝置可係一行動電話,該行動電話可確保作為與付費處理總部通信之外部功能用於在該可抽換式記憶體卡上運行付費應用程式。該行動電話亦將確保該可抽換式記憶體卡之供電。If the communication between the payment card and the POS terminal is narrowed to the data transmission inserted in one of the hardware devices in the mobile phone during the running of the application, it is impossible to monitor and misuse the communication by the common component. After the payment is realized, the encrypted information about the realized payment is sent from the removable memory card. This information is differentiated by sufficient security in the form of EMV standards. In a common configuration, the mobile communication device can be a mobile phone that ensures that an external function for communicating with the payment processing headquarters is used to run a paid application on the removable memory card. The mobile phone will also ensure the power of the removable memory card.

該可抽換式記憶體卡甚至可包括主要為EMV類型的具有一付費應用程式之一付費卡單元。根據EMV標準,此種類的付費卡單元將包括硬體及軟體工具用於確保與晶片具有的功能類似的功能。此單元之介面可係不同的,此係因為該單元不被設計為在通常類型的讀取器中讀取,但該單元將與可抽換式記憶體卡載體穩固地、不可卸離地連接。The removable memory card may even include a pay card unit having a paid application primarily of the EMV type. According to the EMV standard, this type of payment card unit will include hardware and software tools to ensure functionality similar to that of the wafer. The interface of this unit can be different because the unit is not designed to be read in a conventional type of reader, but the unit will be firmly and detachably connected to the removable memory card carrier. .

將POS付費終端及付費卡放置在一個而且不可分的硬體設備中直到現在毫無意義,此係因為該等終端被實體放置在商家處而其等通常由銀行、付費處理者等等所有。透過當前解決方案,使用者可實現租賃付費終端,且在此情況下,可能將付費終端及付費卡放置在一硬體設備中。從組態身份觀點來看,終端將保持由一特定銀行或處理機構擁有,此係因為銀行或處理機構直到現在通常具有放置在商家處之該等終端。因為付費卡與POS終端間之通信將透過可抽換式記憶體卡之硬體中的控制器、微控制器運行且給定付費裝置之微型大小,所以接著本質上,自外部非法讀取此通信在技術上將係不能實行的。Placing POS pay terminals and payment cards in one and inseparable hardware devices until now is meaningless because the terminals are physically placed at the merchant and are typically owned by banks, payment processors, and the like. With the current solution, the user can implement a rental payment terminal, and in this case, the payment terminal and the payment card may be placed in a hardware device. From a configuration identity point of view, the terminal will remain owned by a particular bank or processing organization, as the bank or processing organization up to now typically has such terminals placed at the merchant. Because the communication between the payment card and the POS terminal will be run through the controller and microcontroller in the hardware of the removable memory card and given the micro size of the payment device, then essentially, this is illegally read from the outside. Communication will not be technically feasible.

該POS付費終端之專用資料(正如加密密鑰及識別資料)必須儲存在該記憶體之該有安全保護部分中,較佳儲存在所謂安全元件(Secure Element)中。該安全元件特徵在於特定硬體特性且經受對應憑證,多虧此憑證,參與部件樂於相信其之專用資料在此一記憶體裝置中。此等POS付費終端之資料必須與對付費卡資料之存取嚴格分開,反之亦然。出於此原因,至少兩個獨立分開的有安全保護記憶體域可係在該可抽換式記憶體卡上。此等域可係(例如)一安全元件之分開部分之形式。The dedicated material of the POS paying terminal (such as the encryption key and the identification data) must be stored in the secured portion of the memory, preferably in a so-called Secure Element. The secure element is characterized by specific hardware characteristics and is subject to corresponding credentials, and thanks to this credential, the participating components are happy to believe that their proprietary material is in the memory device. The information of these POS paying terminals must be strictly separated from the access to the paid card data and vice versa. For this reason, at least two independently separated secured memory domains can be attached to the removable memory card. Such fields may be in the form of, for example, separate portions of a secure element.

從最佳化付費終端應用程式中之處理程序觀點來看,若該可抽換式記憶體卡具有兩個獨立的硬體安全元件係有利的(但非必要)。此等安全元件可係兩個一致晶片之形式,該等晶片可獨立放置在該可抽換式記憶體卡之印刷電路上。接著第一安全元件可意欲用於儲存POS終端或分別儲存不同POS終端之資料。第二安全元件將意欲用於儲存該付費卡之資料或各種付費卡之資料。所以當前解決方案能夠將若干業者之POS終端及一使用者之若干付費卡(即以個人名字發行的各種銀行之付費卡)放置於一硬體裝置。因為從存取觀點來看,此等組態及付費資料(屬於不同公司)必須分開予以定位,所以該等安全元件將被劃分成若干獨立的域、部分。若使用兩個安全元件,則接著甚至在安全元件將不具有多重任務之情況下,能夠使該等安全元件互相進行通信且運行兩個應用程式。使用兩個或若干安全元件增加可用的總記憶體容量,以此方式可直接在該等安全元件上運行該付費POS終端應用程式。在具有一個安全元件之組態中,將更適宜於使用另一最便宜但不安全的記憶體,該付費POS終端應用程式將被載入至該記憶體中且將在付費處理程序期間在該記憶體上運行該付費POS終端應用程式。From the point of view of the processor in the optimized pay-per-view application, it is advantageous (but not necessary) for the removable memory card to have two separate hardware security elements. These security elements can be in the form of two identical wafers that can be placed independently on the printed circuit of the removable memory card. The first secure element can then be used to store POS terminals or separately store data for different POS terminals. The second secure element will be intended to store information about the payment card or various payment cards. Therefore, the current solution can place a POS terminal of a certain industry and a number of payment cards of a user (ie, payment cards of various banks issued under a personal name) on a hardware device. Since these configurations and paid materials (belonging to different companies) must be located separately from an access point of view, these secure elements will be divided into separate domains and parts. If two secure elements are used, then even if the secure elements will not have multiple tasks, the secure elements can be made to communicate with one another and run two applications. The use of two or more secure elements increases the total memory capacity available, in such a way that the paid POS terminal application can be run directly on the secure elements. In a configuration with one secure element, it would be more appropriate to use another, inexpensive but unsafe memory that will be loaded into the memory and will be in the payment process The paid POS terminal application runs on the memory.

除了含有共同記憶體自身之外,該記憶體卡可持有具有安全記憶體的呈一晶片形式之一安全元件,具有終端之組態資料之一單元儲存在該安全記憶體中。此單元用於安全儲存該終端需要指派其自己的身份之資料。原則上,此等大多數係對具有有關資料之終端屬於何人之資料判定。In addition to containing the common memory itself, the memory card can hold a security element in the form of a wafer with secure memory in which one of the configuration data of the terminal is stored. This unit is used to securely store the information that the terminal needs to assign its own identity. In principle, most of these decisions are made as to who owns the terminal with the relevant information.

該安全元件與微控制器連接。術語微控制器甚至可意指控制器或呈控制器形式之一些變窄的硬體。可以一種方式定位該微控制器,其中劃分該微控制器之功能,例如,在另一晶片中將控制器部分與計算部分劃分開。為了能夠運行該付費POS終端應用程式,該微控制器亦可連接至該記憶體卡之記憶體,該記憶體中儲存有具有付費POS終端應用程式之單元。此應用程式可特別係一EMV應用程式之形式。該微控制器讀取來自各別單元之該付費POS終端應用程式,藉由此其變成一所謂通用POS終端。其係一通用POS付費終端,雖然此刻仍是無差異的。為了使該POS付費終端變成與一些特定銀行、特定機構相關聯,必須自智慧卡晶片中之所選單元下載終端組態資料。The secure element is connected to the microcontroller. The term microcontroller may even mean a controller or some narrowed hardware in the form of a controller. The microcontroller can be located in a manner in which the functionality of the microcontroller is divided, for example, dividing the controller portion from the computing portion in another wafer. In order to be able to run the paid POS terminal application, the microcontroller can also be connected to the memory of the memory card, which stores a unit with a paid POS terminal application. This application can be in the form of an EMV application. The microcontroller reads the paid POS terminal application from the respective unit whereby it becomes a so-called universal POS terminal. It is a general-purpose POS payment terminal, although it is still indistinguishable at the moment. In order for the POS paying terminal to become associated with a particular bank or institution, the terminal configuration material must be downloaded from the selected unit in the smart card chip.

此組態能夠將可實現付費POS終端操作之一經組態且經調適的記憶體卡插入於一共同行動電話中,該行動電話具有用於記憶體擴充之一插槽。This configuration enables the configuration and adaptation of a memory card that implements one of the paid POS terminal operations to be inserted into a common mobile phone having a slot for memory expansion.

該付費卡單元將與具有終端組態資料之單元分開定位在該記憶體之一有安全保護部分中,較佳在一特定晶片中之安全元件之獨立域上。至於該記憶體卡之適宜結構且相對於具有SD插槽之行動通信裝置之高滲透,該卡適宜於係SD類型或miniSD或microSD卡或甚至可能係M2(微型記憶體棒(Memory Stick Micro))。接著朝向行動通信裝置之電路的記憶體卡之介面將係SD或M2類型的介面。該微控制器可連接至該卡之介面,如由SD卡協會(技術委員會SD卡協會)定義的規定中闡述。The pay card unit will be located separately from the unit having the terminal configuration data in a secured portion of the memory, preferably on a separate domain of the secure elements in a particular wafer. As for the appropriate structure of the memory card and high penetration with respect to the mobile communication device having the SD slot, the card is suitable for an SD type or miniSD or microSD card or even a M2 (Memory Stick Micro) ). The interface to the memory card of the circuit of the mobile communication device will then be an SD or M2 type interface. The microcontroller can be connected to the card interface as set forth in the regulations defined by the SD Card Association (Technical Committee SD Card Association).

為了達到充足資料滲透性,若該付費卡具有至少一個兩導體式資料匯流排或更好一個四導體式資料匯流排可係適宜的。該卡較佳具有小於24毫米之最大參數及小於14毫米之第二最大參數。In order to achieve sufficient data permeability, it may be appropriate if the payment card has at least one two-conductor data bus or a better four-conductor data bus. The card preferably has a maximum parameter of less than 24 mm and a second maximum parameter of less than 14 mm.

該微控制器可配備有較佳為EEPROM類型的不可刪除內部記憶體。為了實現一充足安全層級,該微控制器亦可含有一開機載入器單元用於控制載入的POS付費應用程式之未經授權的介入。該開機載入器可定位在微控制器處理器記憶體之唯讀部分中且其在終端之各自重設之後運行。該開機載入器功能係用以控制作業系統或應用程式是否由任何未經授權的介入改變。每次重設之後,該開機載入器根據程式之外部快閃記憶體之內容計算雜湊值(數位簽章),該外部快閃記憶體中儲存有該作業系統及該等應用程式。接著該開機載入器比較結果與該EEPROM內部記憶體中儲存的值。若資料相等,則接著該開機載入器將管理權留給該作業系統。否則,該開機載入器遞減不成功嘗試之計數器且接著停止。若該計數器達到0,不可能再啟動該微控制器。在該記憶體中,可儲存有一作業系統(作為經定址區域之一開始及一結束),同時該記憶體之容量之雜湊值(數位簽章)在第一次作業系統及應用程式儲存期間儲存在該微控制器中。以後,不可能再改變此資料。The microcontroller can be equipped with non-deletable internal memory, preferably of the EEPROM type. In order to achieve a sufficient level of security, the microcontroller can also include a boot loader unit for controlling unauthorized intervention of the loaded POS payment application. The boot loader can be located in the read-only portion of the microcontroller processor memory and it runs after each reset of the terminal. The boot loader function is used to control whether the operating system or application is altered by any unauthorized intervention. After each reset, the boot loader calculates a hash value (digital signature) based on the contents of the external flash memory of the program, and the external flash memory stores the operating system and the applications. The boot loader then compares the result with the value stored in the internal memory of the EEPROM. If the data is equal, then the boot loader leaves management rights to the operating system. Otherwise, the boot loader decrements the counter of the unsuccessful attempt and then stops. If the counter reaches zero, it is not possible to start the microcontroller again. In the memory, an operating system (starting and ending as one of the addressed areas) can be stored, and the hash value (digital signature) of the memory capacity is stored during the first operating system and application storage. In the microcontroller. In the future, it is impossible to change this information.

在共同版本中,該微控制器可具有32位元微處理器結構。In a common version, the microcontroller can have a 32-bit microprocessor structure.

可由此一組態明顯增加終端之效用,其中該付費終端可具有其自己的通信頻道,即,原則上該通信頻道獨立於行動裝置之通信路徑。此組態版本之特徵將在於含有一無接觸通信元件之記憶體卡,該無接觸通信元件連接至安全元件及/或一微控制器。若該記憶體卡上直接定位有一天線且若該天線連接至無接觸通信元件,則係較佳的。以此方式,將實現該終端之功能獨立性。該無接觸通信元件可配備有周圍電磁場之一偵測,由於該偵測,將僅在需要連接時啟動該無接觸通信元件之電路,此將造成終端之能量需求降低。可由該電磁場且可透過有關記憶體卡之介面由行動電話之電力供應器供電給該終端。該無接觸通信裝置可鏈接至該安全元件上之所有單元,惟加密單元例外,該加密單元僅透過微控制器存取以降低未授權的碼破壞之風險。相對於現有的通信類型之分佈,該通信元件較佳係根據ISO14443標準之NFC類型。The utility of the terminal can be significantly increased by this configuration, wherein the paying terminal can have its own communication channel, ie in principle the communication channel is independent of the communication path of the mobile device. This configuration version will feature a memory card containing a contactless communication component that is coupled to the security component and/or a microcontroller. It is preferred if the antenna is directly positioned on the memory card and if the antenna is connected to a contactless communication component. In this way, the functional independence of the terminal will be achieved. The contactless communication component can be equipped with one of the surrounding electromagnetic fields. Due to the detection, the circuit of the contactless communication component will be activated only when a connection is required, which will result in a reduction in the energy requirements of the terminal. The terminal can be powered by the electromagnetic field of the mobile phone through the electromagnetic field and through the interface of the memory card. The contactless communication device can be linked to all of the units on the secure element, except for the encryption unit, which is only accessed by the microcontroller to reduce the risk of unauthorized code corruption. The communication element is preferably of the NFC type according to the ISO 14443 standard with respect to the distribution of existing communication types.

該付費終端可具有在該安全元件中之更多個別單元,該等個別單元具有來自不同獨立終端的組態資料。此等組態資料將儲存在該安全元件之分開域中。此技術解決方案將能夠啟動該付費終端進入屬於不同付費處理者之一終端。此能力將取決於使用者之選擇或取決於其他命令。以此方式,一記憶體卡可歸類且運行若干獨立付費終端之順序功能。此組態將係有利的,尤其當考慮描述的該付費終端之行動性及其與一特定商家之獨立性時或當較佳具有選擇之可能性及付費終端之身份及所有者時。The paying terminal may have more individual units in the secure element, the individual units having configuration data from different independent terminals. These configuration data will be stored in separate domains of the secure element. This technical solution will enable the paying terminal to enter a terminal belonging to one of the different pay processors. This ability will depend on the user's choice or on other commands. In this way, a memory card can be categorized and run the sequential functions of several independent paying terminals. This configuration would be advantageous, especially when considering the described mobility of the paying terminal and its independence from a particular merchant or when there is a better likelihood of selection and the identity and owner of the paying terminal.

該付費終端亦可藉由在該安全元件中具有若干獨立單元而含有若干付費卡,該等獨立單元持有具有其等之各別付費應用程式之獨立付費卡。所以該付費終端不僅可係一多重付費終端而且可係一多重卡。隨著一使用者擁有的卡數目日益增加,此解決方案將產生此等付費構件之舒適且安全的結合之空間至插入於一行動電話之一記憶體卡中。The paying terminal may also include a number of paying cards by having a number of separate units in the secure element, the independent units holding independent payment cards having their respective paying applications. Therefore, the paying terminal can be not only a multi-paying terminal but also a multi-card. As the number of cards owned by a user increases, this solution will create a comfortable and secure combination of such payment components to be inserted into one of the memory cards of a mobile phone.

該記憶體卡之記憶體(較佳呈一快閃記憶體之形式)可具有其之有安全保護空間之至少一部分。在此情況下,一付費POS終端應用程式單元可儲存至此記憶體中。此單元甚至可直接定位在該微處理器中或該等安全元件中,但在一些電路板架構中,當考慮記憶體區域之需要大小時,此種類的解決方案可能不充分靈活。然而,將需要逐漸更新該付費POS終端應用程式,可由下載的管理單元實行的活動儲存在該記憶體中。該記憶體卡可配備有用於資料流程管理之記憶體控制器處理單元。若在一記憶體卡與一行動電話間有透過網站介面進行通信之任何需要,則一網站伺服器單元可包含在該記憶體卡中。The memory card memory (preferably in the form of a flash memory) can have at least a portion of its security space. In this case, a paid POS terminal application unit can be stored in this memory. This unit may even be located directly in the microprocessor or in such secure elements, but in some board architectures, this type of solution may not be sufficiently flexible when considering the required size of the memory area. However, it will be necessary to gradually update the paid POS terminal application, and the activities that can be performed by the downloaded management unit are stored in the memory. The memory card can be equipped with a memory controller processing unit for data flow management. If there is any need for communication between the memory card and a mobile phone through the website interface, a web server unit can be included in the memory card.

根據當前描述,該終端之效用將藉由擴充其之非金融特徵之功能而增加。該記憶體卡之現有元件、獨立安全元件域、無接觸通信元件及加密單元可用於控制外部裝置(例如,遙控器)、至門禁閘之電子鑰等等。在此情況下,通過該微控制器經初始化之一非金融應用程式單元可在該安全元件中或在管控智慧卡晶片中。According to the current description, the utility of the terminal will be increased by expanding the functionality of its non-financial features. The existing components of the memory card, the independent secure element domain, the contactless communication component, and the encryption unit can be used to control an external device (eg, a remote control), an electronic key to a gatekeeper, and the like. In this case, one of the non-financial application units initialized by the microcontroller can be in the secure element or in the managed smart card chip.

在根據此解決方案之組態中,具有付費終端功能之該記憶體卡甚至可進一步履行行動通信裝置之擴充記憶體之功能。在未受保護的部分中,該記憶體可具有用於使用者之可自由存取資料(如圖像、音樂檔案及類似物)之區域。當查看該行動通信裝置時,此部分係直接可見的。在該記憶體中,對於對使用者隱藏之資料,可有系統資料作為付費處理結果及類似物之記錄。In the configuration according to this solution, the memory card with the payment terminal function can even further fulfill the function of the extended memory of the mobile communication device. In the unprotected portion, the memory can have an area for the user to freely access data such as images, music files, and the like. This portion is directly visible when viewing the mobile communication device. In this memory, for data hidden from the user, system data can be recorded as a result of payment processing and the like.

為在標準商店中付費之目的,該系統可補充付費POS終端應用程式啟動器;該啟動器可係呈一簡單硬體元件之形式或者其可係收銀機之一部分。該啟動器可具有付費值產生單元。商家通過該啟動器鍵入需要的付費金額。此金額亦可產生為自該收銀機輸出的最終購買金額。該啟動器附接至一通信元件或完全配備有該通信元件,該通信元件與該可抽換式記憶體卡上之該通信元件相容或與該行動通信裝置之短距離通信元件相容。For payment purposes in a standard store, the system may complement the pay-as-you-go POS terminal application launcher; the launcher may be in the form of a simple hardware component or it may be part of a cash register. The initiator may have a payment value generating unit. The merchant types the required payment amount through the launcher. This amount can also be generated as the final purchase amount output from the cash register. The actuator is attached to or fully equipped with a communication component that is compatible with the communication component on the removable memory card or with the short-range communication component of the mobile communication device.

根據本發明,使用一行動通信裝置之直接帳單付費方式係基於以下事實:付費POS終端應用程式可在插入於行動電話之用於額外硬體的插槽中之可抽換式記憶體卡上運行且該付費卡應用程式亦可在相同硬體裝置上運行。直到現在已知的該付費POS終端應用程式之運行特徵在於:在實現付費期間,該付費卡暫時連接至POS終端。根據當前解決方案,該付費卡穩固連接至付費終端且因此該POS終端與該付費卡間之通信可通過該付費卡之電路直接運行。自此技術解決方案使各種新付費應用程式程序可能性湧現,且原則上該付費POS終端應用程式之結果可係現今使用的格式(EMV付費密碼(cryptogram))。In accordance with the present invention, a direct bill payment method using a mobile communication device is based on the fact that a paid POS terminal application can be inserted on a removable memory card in a slot for a mobile phone for additional hardware. Run and the pay card application can also run on the same hardware device. The operating feature of the paid POS terminal application known until now is that the payment card is temporarily connected to the POS terminal during the implementation of the payment. According to the current solution, the payment card is securely connected to the paying terminal and thus the communication between the POS terminal and the pay card can be run directly through the circuit of the pay card. Since then, the technical solution has made it possible for various new paid application programs to emerge, and in principle the result of the paid POS terminal application can be in the format used today (EMV cryptogram).

在可能程序版本之一者中,該付費POS終端應用程式可被載入至該記憶體卡中之該微控制器中,且隨後自對應安全元件載入所選終端之身份之組態資料。重要特徵亦在於將來自安全元件之付費卡資料載入至操作為付費終端之該微控制器之可能性,所以自由該付費POS終端應用程式為其之運行而使用的相同種類的硬體設備載入該資料。若該安全元件具有充足計算容量,則該付費POS終端應用程式可直接在該安全元件中運行。此將在使用兩個安全元件之情況下發生,一安全元件用於付費終端,另一安全元件用於付費卡。甚至在此組態中,該付費POS終端應用程式可產生為用於所有付費終端之身份之一無差異、共同者;且僅在選擇該付費終端之後,將來自該安全元件之對應獨立域之識別資料載入至該付費POS終端應用程式中。使用具有已經插入組態資料之獨立付費POS終端應用程式之版本亦未被刪除。In one of the possible program versions, the paid POS terminal application can be loaded into the microcontroller in the memory card and subsequently loaded with the configuration data of the identity of the selected terminal from the corresponding secure element. An important feature is also the possibility of loading the payment card data from the secure element into the microcontroller operating as a payment terminal, so free of the same kind of hardware device used by the paying POS terminal application for its operation. Enter the information. If the secure element has sufficient computing capacity, the pay POS terminal application can run directly in the secure element. This will happen with the use of two secure elements, one for the paying terminal and the other for the pay card. Even in this configuration, the pay-as-you-go POS terminal application can be generated as one of the identities for all paying terminals, with no difference, commonality; and only after selecting the paying terminal, will be from the corresponding independent domain of the secure element The identification data is loaded into the paid POS terminal application. The version using the stand-alone POS terminal application with the configuration data already inserted has also not been deleted.

為增加安全層級,該開機載入器在運行該付費POS終端應用程式自身之前運行該付費POS終端應用程式中之變化控制係較佳的。將透過該行動通信裝置之一輸入裝置(主要為鍵盤)管理該付費POS終端應用程式。To increase the security level, it is preferred that the boot loader run the change control system in the paid POS terminal application before running the pay POS terminal application itself. The paid POS terminal application will be managed by an input device (mainly a keyboard) of the mobile communication device.

圖1至圖6中詳細闡述該解決方案。This solution is illustrated in detail in Figures 1 to 6.

實例1Example 1

在此實例中,描述利用根據圖3之兩個獨立安全元件31、32之解決方案。使用分開硬體安全元件31、32簡化憑證要求,由付費系統之個別參與者(發卡者、結算中心業者)在儲存機密資料於該等安全元件3、31、32上時設定該等憑證要求。在此實例中,該等安全元件31、32之每一者亦被劃分為獨立域,該等獨立域可被提供至不同發卡業者且至POS終端之組態資料之不同所有者。該等安全元件31、32係呈電路板上之獨立晶片之形式,該等安全元件在該電路板上與履行微控制器12之角色之控制器連接。該等安全元件31、32朝向該控制器12之介面係ISO 7816。可抽換式記憶體卡1係呈microSD卡之形式。ASIC(專用積體電路)晶片與該微控制器12連接,該ASIC晶片經設定用以執行NFC平台通信處理程序且藉由做到此,該ASIC晶片履行通信元件13之功能。直接定位在該可抽換式記憶體卡之本體1上之天線21根據專利所有人之不同專利申請經設計且以使能NFC通信之方式連接至該ASIC晶片,NFC通信獨立域行動電話4之其他硬體。該可抽換式記憶體卡1亦含有(例如)具有2GB容量之一共同快閃記憶體2。使用者不能自行動電話之介面4存取該記憶體2之一部分20;該記憶體之此部分用於所實現付費記錄之存檔。該記憶體2之剩餘部分用於音樂、圖像及類似物之共同儲存,多虧該共同儲存,整個記憶體卡1對使用者顯現為一共同記憶體媒體。藉由將POS終端及付費卡放置在一可抽換式記憶體卡1上,經設計用以擴充記憶體容量之該行動電話4之插槽之初始功能不會消失。In this example, a solution using two independent security elements 31, 32 according to Fig. 3 is described. The use of separate hardware security elements 31, 32 simplifies the credential requirements that are set by individual participants (issuers, clearinghouse operators) of the payment system when storing confidential information on the secure elements 3, 31, 32. In this example, each of the secure elements 31, 32 is also divided into separate domains that can be provided to different issuers and to different owners of the configuration data of the POS terminal. The security elements 31, 32 are in the form of separate chips on a circuit board on which the security elements are coupled to a controller that performs the role of the microcontroller 12. The interfaces of the security elements 31, 32 towards the controller 12 are ISO 7816. The removable memory card 1 is in the form of a microSD card. An ASIC (Dedicated Integrated Circuit) chip is coupled to the microcontroller 12, which is configured to execute an NFC platform communication processing program and by doing so, the ASIC chip performs the functions of the communication element 13. The antenna 21 directly positioned on the body 1 of the removable memory card is designed according to a patent application of the patent owner and is connected to the ASIC chip in a manner enabling NFC communication, the NFC communication independent domain mobile phone 4 Other hardware. The removable memory card 1 also contains, for example, a common flash memory 2 having a capacity of 2 GB. The user cannot access a portion 20 of the memory 2 from the interface 4 of the mobile phone; this portion of the memory is used for archiving of the paid records. The remainder of the memory 2 is used for the common storage of music, images and the like, and thanks to the common storage, the entire memory card 1 appears to the user as a common memory medium. By placing the POS terminal and the payment card on a removable memory card 1, the initial function of the slot of the mobile phone 4 designed to expand the memory capacity does not disappear.

付費可以兩個不同種類運行。例如,如圖6中展示,該行動電話4之使用者判定他想要在一網際網路商店中買呈電子形式之一地圖。在此情況下,該網際網路商店之業者可係該行動電話4生產者。根據描述的技術解決方案生產的該microSD記憶體卡1被插入於可自該行動電話4之外部存取的橫向插槽中。該安全元件31上儲存有屬於若干人(其等間甚至有網際網路商店之業者)之POS終端組態資料6。選擇購買的項目之後,將對應金額之付費要求自該網際網路商店發送至該行動電話4。使用者按壓該電話配備有之付費按鈕。在另一付費實例中,可由該行動電話4之顯示器上顯示的軟體按鈕啟動付費選擇。將發動該付費POS應用程式之要求發送至介面11。該付費POS終端應用程式以與其在一標準POS付費終端與付費卡間之一關係中之運行方式相同的方式在該記憶體卡1上運行,該付費卡被插入於POS終端之讀取器中。該行動電話4之顯示器用於管理付費之運行。使用者根據他想要付所需金額而選擇該付費卡。啟動所選付費卡之對應單元7中之應用程式之後,亦可由對應卡之發行者之風險管理之預設定規則管理付費之運行。取決於此,將有必要或不必要鍵入該付費之卡通行密碼(password)。Payment can be run in two different categories. For example, as shown in Figure 6, the user of the mobile phone 4 determines that he wants to buy a map in electronic form in an internet store. In this case, the operator of the internet store can be the producer of the mobile phone 4. The microSD memory card 1 produced according to the described technical solution is inserted into a lateral slot accessible from the outside of the mobile phone 4. The secure element 31 stores POS terminal configuration data 6 belonging to a number of people (and even among those of the Internet shop). After selecting the purchased item, a payment request for the corresponding amount is sent from the internet store to the mobile phone 4. The user presses the phone with a pay button. In another payment example, the payment selection can be initiated by a software button displayed on the display of the mobile phone 4. The request to launch the paid POS application is sent to interface 11. The pay POS terminal application runs on the memory card 1 in the same manner as it operates in a relationship between a standard POS pay terminal and a pay card, the pay card being inserted into the reader of the POS terminal . The display of the mobile phone 4 is used to manage the operation of the payment. The user selects the payment card based on the amount he wants to pay. After launching the application in the corresponding unit 7 of the selected payment card, the payment operation can also be managed by the pre-set rules of the risk management of the issuer of the corresponding card. Depending on this, it will be necessary or unnecessary to type in the paid cartoon line password.

結束該付費POS終端應用程式之後,由軟體斷開該POS付費終端與該付費卡間之連接且通過網際網路商店中待處理的GPRS頻道發送所得付費密碼。網際網路商店接收且解密付費檔案之後,估計該付費且在一肯定結果情況下,經付費的項目(在此實例中為該地圖)被發送至該行動電話4。After ending the paid POS terminal application, the software disconnects the POS payment terminal from the payment card and transmits the generated payment password through the GPRS channel to be processed in the Internet store. After the internet store receives and decrypts the paid profile, the payment is estimated and, in the case of a positive result, the paid item (in this example, the map) is sent to the mobile phone 4.

實例2Example 2

此實例中描述在形狀及參數上相當於一標準microSD卡之microSD類型的該可抽換式付費卡1平台上之付費終端。如圖1中,該付費卡1具有呈32位元微處理器之形式之一微控制器12,該微處理器在多任務作業系統8(此實例中係Linux)上進行操作。一快閃記憶體2、安全元件3及SD介面11連接至該微控制器12。微控制器12含有一內部EEPROM記憶體10及開機載入器9,該開機載入器9控制載入的付費POS終端應用程式中之未授權的介入。A pay terminal on the removable pay card 1 platform of the microSD type equivalent to a standard microSD card in shape and parameters is described in this example. As in Figure 1, the payment card 1 has a microcontroller 12 in the form of a 32-bit microprocessor operating on a multitasking operating system 8 (Linux in this example). A flash memory 2, a secure element 3 and an SD interface 11 are connected to the microcontroller 12. Microcontroller 12 includes an internal EEPROM memory 10 and a boot loader 9 that controls unauthorized intervention in the loaded pay POS terminal application.

該快閃記憶體2被劃分為有安全保護部分及未受保護部分。在未受保護部分中有用於自由存取且可見的使用者資料之一空間15及用於隱藏系統檔案(尤其由付費終端處理的付費處理之記錄)之一空間20。在該記憶體卡之該有安全保護部分中,有持有作業系統(此實例中係Linux)之一單元8及儲存有一付費POS終端應用程式(在此情況下係一EMV類型的應用程式)之首要的付費POS終端應用程式單元5。在此實例中,在該記憶體2之該有安全保護部分中,亦有用於該記憶體卡1上之儲存及軟體更新管理之下載管理單元19。若有必要載入/升級智慧卡晶片3中之應用程式,則接著將該應用程式之二進位資料載入至該快閃記憶體2之未受保護部分中,例如至儲存有對使用者隱藏之資料之該空間20中之系統資料單元。該下載管理單元19週期性檢查該系統資料單元中是否有應載入至該安全元件3中之任何新檔案。若有,則接著運行一各別安裝。The flash memory 2 is divided into a protected portion and an unprotected portion. In the unprotected portion there is a space 15 for free access and visible user data and a space 20 for hiding system files (especially records of payment processing processed by the paying terminal). In the security part of the memory card, there is a unit 8 holding the operating system (Linux in this example) and a paid POS terminal application (in this case, an EMV type application) The premier paid POS terminal application unit 5. In this example, in the secured portion of the memory 2, there is also a download management unit 19 for storage and software update management on the memory card 1. If it is necessary to load/upgrade the application in the smart card chip 3, then the application binary data is loaded into the unprotected portion of the flash memory 2, for example, until the storage is hidden from the user. The system data unit in the space 20 of the data. The download management unit 19 periodically checks whether there are any new files in the system data unit that should be loaded into the secure element 3. If so, then run a separate installation.

在該記憶體2之該有安全保護部分中,亦有用於管理儲存在該安全元件3中之應用程式(惟EMV付費應用程式除外)的SCWS網站伺服器單元。在該微控制器12中,有儲存有作業系統(作為經定址區域之一開始及一結束)之一記憶體空間。該記憶體之容量之雜湊值(數位簽章)在第一作業系統及應用程式儲存期間儲存在該微控制器12中。以後,不可能再改變此資料,其確保對禁止軟體改變之保護。In the secure portion of the memory 2, there is also a SCWS web server unit for managing applications stored in the secure element 3 (except for the EMV paid application). In the microcontroller 12, there is stored a memory space in which the operating system (as one of the addressed regions begins and ends). The hash value (digital signature) of the memory capacity is stored in the microcontroller 12 during storage of the first operating system and application. In the future, it is impossible to change this information, which ensures protection against software changes.

在該智慧卡晶片3之該安全元件中產生若干個別域。在此文件中,該等域有用於持有屬於三個不同付費處理者的三個獨立終端之三個組態資料單元6。該安全元件之兩部分含有具有EMV類型的各別付費應用程式之兩個獨立付費卡7。此處給出的實例因此描述一種解決方案,其能夠使使用者在三個終端處用兩個不同付費卡付費,而該等終端之每一者屬於一不同付費處理者。舉例而言,此等付費處理者之一者可係一行動電話網路業者,該業者將其之電信服務連接至直接帳單付費處理處理服務。在該安全元件上,亦有RSA加密單元14。A number of individual fields are created in the secure element of the smart card chip 3. In this document, the fields have three configuration data units 6 for holding three independent terminals belonging to three different payment processors. The two parts of the secure element contain two separate pay cards 7 with separate paid applications of the EMV type. The example given here thus describes a solution that enables a user to pay with two different payment cards at three terminals, each of which belongs to a different payment processor. For example, one of these payment processors can be a mobile phone network operator who connects their telecommunications services to a direct bill payment processing service. On the secure element, there is also an RSA encryption unit 14.

該記憶體卡1亦具有分別放置在該記憶體卡1內之其自己的NFC無接觸通信元件13與該天線21。此組態能夠在不具有NFC晶片之一共同電話與滿足ISO14443標準之有關讀取器間產生NFC通信連接。The memory card 1 also has its own NFC contactless communication element 13 and the antenna 21 placed in the memory card 1, respectively. This configuration enables an NFC communication connection between a common telephone that does not have an NFC chip and a related reader that satisfies the ISO 14443 standard.

在該安全元件3中,亦有非金融應用程式單元16,其在此實例中經組態以操作為用於打門之電子無接觸鑰。Also within the secure element 3 is a non-financial application unit 16, which in this example is configured to operate as an electronic contactless key for door knocking.

該快閃記憶體2之控制器17係在該記憶體2之該有安全保護部分中且該控制器管理該行動電話與該記憶體卡1上之該快閃記憶體2間之資料傳送。該快閃記憶體2之控制器17單位化檢視資料或寫至該記憶體2之該有安全保護部分之可能性且亦單位化檢視該記憶體2之該未受保護部分之可能性,系統資料單元(准許讀取及寫入)定位在該未受保護部分中。The controller 17 of the flash memory 2 is in the secured portion of the memory 2 and the controller manages the transfer of data between the mobile phone and the flash memory 2 on the memory card 1. The controller of the flash memory 2 unitizes the possibility of viewing the data or writing to the protected portion of the memory 2 and also systematically viewing the unprotected portion of the memory 2, the system The data unit (allowing read and write) is located in the unprotected portion.

該付費POS終端應用程式在插入於該行動通信裝置之用於額外硬體的插槽4中之該可抽換式記憶體卡1上運行。該付費POS終端應用程式被載入至該記憶體卡1中之該微控制器12中且隨後自該安全元件3載入所選終端之身份的組態資料。將所選付費卡資料自該安全元件3載入至操作為一付費終端之該微控制器12中。載入哪一付費卡資料取決於使用者之選擇。The pay-as-you-go terminal application runs on the removable memory card 1 inserted in the slot 4 of the mobile communication device for additional hardware. The paid POS terminal application is loaded into the microcontroller 12 in the memory card 1 and subsequently loaded with configuration information of the identity of the selected terminal from the secure element 3. The selected payment card data is loaded from the secure element 3 into the microcontroller 12 operating as a pay terminal. Which payment card information to load depends on the user's choice.

在開始該付費POS終端應用程式自身之前,該開機載入器9運行該付費POS終端應用程式之一改變控制。使用該行動通信裝置4之鍵盤及顯示器管理該付費POS終端應用程式。該行動電話具有一圖形GUI介面(圖形使用者介面),該GUI讓使用者、記憶體卡1及主機處理器之間能夠進行通信。該電話中亦有推送(push)SMS技術。該付費POS終端應用程式係使用該microSD記憶體卡1上之付費應用程式使能線上付費及離線付費之一SD微控制器應用程式12。當「卡存在」時實現付費,其高度增加安全性(用密碼簽章處理)且在每一處理期間,ATC計數器遞增1,此意謂著不可能產生無限次處理以便得到一些密鑰。用戶端透過安裝在其自己的電話中之一GUI應用程式管理該付費POS終端應用程式。在此實例中,該付費POS終端應用程式連同該微控制器12形成一通用POS終端。在一不同組態中,可由付費POS終端應用程式連同一計算元件形成該通用POS終端,該計算元件直接在具有該安全元件之晶片中。隨後,連同組態參數,其等形成嵌入式POS終端(EMBEDDED POS TERMINAL):Terminal_type 1x=屬於一金融機構之終端,2x=屬於一商家之一終端,3x=屬於卡持有者之一終端(卡持有者終端)。該終端之組態資料單元6含有終端之ID號碼、PDOL資料(處理選項資料物件列表)、終端風險管理、離線批次檔案格式、主機上之SMS選通器、主機上之IP位址、簽章離線處理之代碼。付費可係離線或線上的。可透過SMS訊息或透過GPRS實現與付費處理者之通信。The boot loader 9 runs one of the paid POS terminal applications to change control before starting the pay POS terminal application itself. The paid POS terminal application is managed using the keyboard and display of the mobile communication device 4. The mobile phone has a graphical GUI interface (graphical user interface) that enables communication between the user, the memory card 1 and the host processor. There are also push SMS technologies in the phone. The pay-as-you-go POS terminal application enables the SD microcontroller application 12, one of online payment and offline payment, using the payment application on the microSD memory card 1. Payment is implemented when the "card exists", which increases security (with a cryptographic signature) and the ATC counter is incremented by one during each processing, which means that it is not possible to generate an infinite number of processing in order to get some keys. The client manages the paid POS terminal application through one of the GUI applications installed on its own phone. In this example, the pay POS terminal application, along with the microcontroller 12, forms a general purpose POS terminal. In a different configuration, the universal POS terminal can be formed by a paid POS terminal application connected to the same computing component directly in the wafer having the secure component. Subsequently, together with the configuration parameters, they form an embedded POS terminal (EMBEDDED POS TERMINAL): Terminal_type 1x = terminal belonging to a financial institution, 2x = one terminal belonging to a merchant, 3x = one terminal belonging to the card holder ( Card holder terminal). The configuration data unit 6 of the terminal contains the terminal ID number, PDOL data (processing option data item list), terminal risk management, offline batch file format, SMS strobe on the host, IP address on the host, and signing Chapter offline processing code. Payment can be offline or online. Communication with payment processors can be achieved via SMS messages or via GPRS.

real 例3Example 3

此實例中描述一種可抽換式記憶體卡1,其僅含有用於實現付費必要的一最小組。圖4中展示該可抽換式記憶體卡1之結構。此種類的可抽換式記憶體卡經設計僅用預買入金額的錢作為一預付付費卡出售且意欲(例如)出售給來自使用不同貨幣之一國家之旅遊者。該可抽換式記憶體卡1含有根據microSD格式之具有接觸件之一介面11。在該可抽換式記憶體卡1之塑膠本體中有兩個安全元件31、32。在第一安全元件31中有由預付卡系統之業者產生的POS終端之組態資料。在第二安全元件32中有一次性付費卡(one-time payment card)之資料。連同該可抽換式記憶體卡1,商業套件亦含有具有一剪輯欄位(scrap field)之一紙張輸送器(paper carrier),該剪輯欄位中有用於管理對該付費卡之存取之一對應PIN碼。當由商家持有的一共同POS終端連接至付費消費者之付費卡時,該記憶體卡1執行所有操作。該行動電話4之設施用於顯示及通信。In this example, a removable memory card 1 is described which contains only a minimum set necessary to effect payment. The structure of the removable memory card 1 is shown in FIG. This type of removable memory card is designed to be sold only as a prepaid card with a pre-purchased amount and is intended, for example, to be sold to a traveler from a country using a different currency. The removable memory card 1 contains an interface 11 having contacts in accordance with the microSD format. There are two security elements 31, 32 in the plastic body of the removable memory card 1. In the first secure element 31 there is configuration information of the POS terminal generated by the manufacturer of the prepaid card system. There is a one-time payment card in the second secure element 32. In conjunction with the removable memory card 1, the business kit also includes a paper carrier having a scrap field for managing access to the pay card. A corresponding PIN code. The memory card 1 performs all operations when a common POS terminal held by the merchant is connected to the paying card of the paying consumer. The facility of the mobile phone 4 is used for display and communication.

實例4Example 4

在此實例中,系統補充該付費POS終端應用程式啟動器22。該啟動器22可係呈具有NFC通信元件之一單用裝置之形式。在此實例中,該啟動器連接至收銀機26之輸出端,該收銀機26將發送關於總共需要的付費之資訊至輸出端。該啟動器22產生含有付費值、商家帳戶之資訊及要求命令之一檔案。該啟動器22通過通信元件24發送此檔案至應用於此之該行動電話4。此檔案在該記憶體卡1上之接收造成該付費POS終端應用程式之發動。此解決方案能夠使用使用者之該行動電話4之付費終端用於在不具有其自己的POS終端之一般商店中之直接帳單付費。In this example, the system supplements the paid POS terminal application launcher 22. The actuator 22 can be in the form of a single device having one of the NFC communication elements. In this example, the initiator is coupled to the output of the cash register 26, which will send information about the total required payment to the output. The launcher 22 generates an archive containing the payment value, the merchant account information, and the request command. The initiator 22 transmits this file to the mobile phone 4 applied thereto via the communication component 24. The receipt of this file on the memory card 1 causes the payment POS terminal application to be launched. This solution enables the use of the paying terminal of the mobile phone 4 of the user for direct bill payment in a general store that does not have its own POS terminal.

商業適用性Commercial applicability

商業適用性顯而易見。利用本發明,可能產業上且重複製造並使用實施至記憶體卡中之付費終端,一記憶體卡中具有一或多個付費卡。Commercial applicability is obvious. With the present invention, it is possible to industrially and repeatedly manufacture and use a payment terminal implemented in a memory card having one or more payment cards in one memory card.

1...記憶體卡1. . . Memory card

2...記憶體2. . . Memory

3...安全元件3. . . Safety element

4...行動通信裝置4. . . Mobile communication device

5...付費POS終端應用程式5. . . Paid POS terminal application

6...終端之組態資料單元6. . . Terminal configuration data unit

7...付費卡單元7. . . Payment card unit

8...作業系統單元8. . . Operating system unit

9...開機載入器單元9. . . Boot loader unit

10...內部微控制器記憶體10. . . Internal microcontroller memory

11...介面11. . . interface

12...微控制器12. . . Microcontroller

13...通信元件13. . . Communication component

14...加密單元14. . . Encryption unit

15...可自由存取的使用者之資料空間15. . . Freely accessible user data space

16...非金融應用程式單元16. . . Non-financial application unit

17...快閃記憶體控制器17. . . Flash memory controller

18...網站伺服器單元18. . . Website server unit

19...下載管理單元19. . . Download snap-in

20...隱藏的資料空間20. . . Hidden data space

21...天線twenty one. . . antenna

22...啟動器twenty two. . . Launcher

23...收款者之電腦twenty three. . . Payee computer

24...啟動器之通信元件twenty four. . . Starter communication component

25...付費處理總部25. . . Paid processing headquarters

26...收銀機26. . . cashier

31...POS終端之安全元件31. . . POS terminal security element

32...付費卡之安全元件32. . . Secure element for payment card

圖1係記憶體卡之個別元件與顯示的記憶體卡上之個別元件間之連接與一劃分的安全元件之一方塊圖,該安全元件上有來自付費POS終端(亦來自若干付費卡)之有安全保護資料。1 is a block diagram of a connection between an individual component of a memory card and an individual component on a memory card being displayed, and a partitioned security component having a paid POS terminal (also from a number of payment cards) Have security information.

圖2展示一種解決方案,該解決方案中有在網際網路商店中付費期間或在對自行動網路下載的檔案付費期間具有一記憶體卡之一行動電話。Figure 2 shows a solution in which there is a mobile phone with one memory card during payment in the internet store or during payment for files downloaded from the mobile network.

圖3係具有兩個獨立安全元件且具有直接定位在記憶體卡上之通信元件(正如天線)之microSD類型的可抽換式記憶體卡。Figure 3 is a microSD type removable memory card with two separate security elements and a communication element (just like an antenna) positioned directly on the memory card.

圖4係在具有兩個安全元件之選項中具有一簡化架構之一預付可抽換式記憶體卡。Figure 4 is a prepaid removable memory card with a simplified architecture among the options with two secure elements.

圖5係在可抽換式記憶體卡上運行同時為行動網路中提供的檔案付費之付費應用程式內之任務之連續。Figure 5 is a continuation of the tasks within a paid application running on a removable memory card while paying for the files provided in the mobile network.

圖6係具有付費啟動器之一解決方案,其中啟動器實踐中經定位永久接著實體商店中之收銀機。Figure 6 is a solution with a paid launcher in which the launcher practice is positioned to permanently follow the cash register in the physical store.

1...記憶體卡1. . . Memory card

2...記憶體2. . . Memory

3...安全元件3. . . Safety element

5...付費POS終端應用程式5. . . Paid POS terminal application

6...終端之組態資料單元6. . . Terminal configuration data unit

7...付費卡單元7. . . Payment card unit

8...作業系統單元8. . . Operating system unit

9...開機載入器單元9. . . Boot loader unit

10...內部微控制器記憶體10. . . Internal microcontroller memory

11...介面11. . . interface

12...微控制器12. . . Microcontroller

13...通信元件13. . . Communication component

14...加密單元14. . . Encryption unit

15...可自由存取的使用者之資料空間15. . . Freely accessible user data space

16...非金融應用程式單元16. . . Non-financial application unit

17...快閃記憶體控制器17. . . Flash memory controller

18...網站伺服器單元18. . . Website server unit

19...下載管理單元19. . . Download snap-in

20...隱藏的資料空間20. . . Hidden data space

Claims (23)

一種使用如一行動電話之一行動通信裝置之付費終端,其中該付費終端含有一記憶體、一介面(11)及微控制器(12),同時該微控制器(12)與該記憶體及該介面(11)連接,POS終端亦含有具有付費終端應用程式之單元(5)且甚至亦含有具有該記憶體(3、31、32)之有安全保護部分中的付費終端之組態資料之單元(6),該付費終端之特徵在於:該付費終端連同該付費終端之對應組態資料係定位在一可抽換式記憶體卡(1)上,該可抽換式記憶體卡以此方式經調整使得可將其插入於一額外硬體插槽中,該插槽用於增加超越該行動通信裝置(4)之基礎功能之功能,該可抽換式記憶體卡(1)含有具有該POS終端之組態資料單元(6)之一有安全保護記憶體(3、31)且亦含有具有付費卡單元(7)之一有安全保護記憶體(3、32),其中該付費卡單元(7)與該POS終端之組態資料係分開予以定位,該等有安全保護記憶體(3、31、32)鏈接至該微控制器(12)且該微控制器(12)鏈接至該介面(11)用於連接至該行動通信裝置(4)之電路。 A payment terminal using a mobile communication device such as a mobile phone, wherein the payment terminal includes a memory, an interface (11) and a microcontroller (12), and the microcontroller (12) and the memory and the The interface (11) is connected, and the POS terminal also includes a unit (5) having a payment terminal application and even a unit having configuration data of the payment terminal in the security protection portion of the memory (3, 31, 32). (6) The pay terminal is characterized in that the corresponding configuration data of the paying terminal together with the paying terminal is located on a removable memory card (1), and the removable memory card is in this manner Adjusted so that it can be inserted into an additional hardware slot that is used to add functionality beyond the basic functions of the mobile communication device (4), the removable memory card (1) containing One of the configuration data units (6) of the POS terminal has a security memory (3, 31) and also has a security card (3, 32) having a payment card unit (7), wherein the payment card unit (7) Positioning separately from the configuration data of the POS terminal, which is safe Memory protection (3,31,32) linked to the microcontroller (12) and the microcontroller (12) linked to the interface (11) for connection to the mobile communication device (4) of the circuit. 如請求項1之付費終端,其特徵在於:產生用於該付費終端之組態資料單元(6)且用於該付費卡單元(7)之該等有安全保護記憶體作為一安全元件(3)之獨立域。 The payment terminal of claim 1, characterized in that: the configuration data unit (6) for the payment terminal is generated and the security protected memory for the payment card unit (7) is used as a security element (3) Independent domain. 如請求項1之付費終端,其特徵在於:藉由該安全元件(3)而形成用於儲存付費終端之組態資料之該有安全保護記憶體,該安全元件(3)係與具有該付費卡單元(7)之獨 立安全元件(32)分開的硬體。 The payment terminal of claim 1, characterized in that the secure storage device for storing configuration data of the payment terminal is formed by the security element (3), and the security element (3) is associated with the payment Card unit (7) alone Separate hardware of the security element (32). 如請求項1至3之任一項之付費終端,其特徵在於:該記憶體卡(1)係SD類型或miniSD或microSD卡或M2類型且該介面(11)係SD類型或M2類型。 A pay terminal according to any one of claims 1 to 3, characterized in that the memory card (1) is of the SD type or miniSD or microSD card or M2 type and the interface (11) is of the SD type or the M2 type. 如請求項1至4之任一項之付費終端,其特徵在於:該記憶體卡(1)具有至少兩個導體(較佳四個導體)資料匯流排。 A pay terminal according to any one of claims 1 to 4, characterized in that the memory card (1) has at least two conductors (preferably four conductors) data bus. 如請求項1至5之任一項之付費終端,其特徵在於:該記憶體卡(1)之最大尺寸參數小於24毫米且第二最大尺寸參數小於14毫米。 A pay terminal according to any one of claims 1 to 5, characterized in that the memory card (1) has a maximum size parameter of less than 24 mm and a second maximum size parameter of less than 14 mm. 如請求項1至6之任一項之付費終端,其特徵在於:該微控制器(12)含有一不可刪除內部記憶體(10)(較佳為EEPROM類型),該微控制器(12)亦含有一開機載入器單元(9),該開機載入器單元用於載入的付費POS終端應用程式中之未經授權的介入控制。 A payment terminal according to any one of claims 1 to 6, characterized in that the microcontroller (12) comprises a non-deletable internal memory (10) (preferably of the EEPROM type), the microcontroller (12) There is also a boot loader unit (9) for unauthorized intervention control in the loaded pay POS terminal application. 如請求項1至7之任一項之付費終端,其特徵在於:該記憶體卡(1)配備有一無接觸通信元件(13),該無接觸通信元件連接至該安全元件(3、31、32)及/或該微控制器(12)。 A payment terminal according to any one of claims 1 to 7, characterized in that the memory card (1) is provided with a contactless communication element (13) to which the contactless communication element is connected (3, 31, 32) and / or the microcontroller (12). 如請求項8之付費終端,其特徵在於:該記憶體卡(1)上有一天線(21),該天線連接至一無接觸通信元件(13)。 A pay terminal as claimed in claim 8, characterized in that the memory card (1) has an antenna (21) connected to a contactless communication element (13). 如請求項1至9之任一項之付費終端,其特徵在於:該安全元件(3、31)中有具有來自不同的獨立終端的組態資料之至少兩個單元(6)。 A pay terminal according to any one of claims 1 to 9, characterized in that the secure element (3, 31) has at least two units (6) having configuration data from different independent terminals. 如請求項1至10之任一項之付費終端,其特徵在於:該安全元件(3、32)中有持有較佳為EMV標準的具有對應付費應用程式之獨立付費卡之至少兩個單元(7)。 The payment terminal of any one of claims 1 to 10, characterized in that the security element (3, 32) has at least two units of independent payment cards having a corresponding payment application, preferably having an EMV standard. (7). 如請求項1至11之任一項之付費終端,其特徵在於:較佳為快閃類型之該記憶體(2)具有其之有安全保護空間之至少一部分,在此有安全保護區域中將儲存有該付費POS終端應用程式(5)。 The payment terminal according to any one of claims 1 to 11, characterized in that the memory (2), which is preferably of the flash type, has at least a part of its security protection space, and in this security protection area The paid POS terminal application (5) is stored. 如請求項1至12之任一項之付費終端,其特徵在於:該記憶體(2)中有一記憶體控制單元(17)、一下載管理單元(19)及較佳亦有一網站伺服器單元(18)。 The payment terminal of any one of claims 1 to 12, characterized in that the memory (2) has a memory control unit (17), a download management unit (19) and preferably a website server unit. (18). 如請求項1至13之任一項之付費終端,其特徵在於:該安全元件(3、31、32)中有一非金融應用程式單元(16)。 A pay terminal according to any one of claims 1 to 13, characterized in that the secure element (3, 31, 32) has a non-financial application unit (16). 如請求項8至14之任一項之付費終端,其特徵在於:該無接觸通信元件(13)係滿足ISO14443標準之NFC類型。 A pay terminal according to any one of claims 8 to 14, characterized in that the contactless communication element (13) is of the NFC type which satisfies the ISO 14443 standard. 如請求項1至15之任一項之付費終端,其特徵在於:該記憶體(2)之未受保護部分中具有對使用者隱藏之一空間(20)資料及使用者自由存取資料之一空間(15)。 The payment terminal according to any one of claims 1 to 15, characterized in that the unprotected portion of the memory (2) has a space (20) hidden from the user and the user freely accesses the data. A space (15). 如請求項1至16之任一項之付費終端,其特徵在於:該付費終端亦包括定位在商店中之該付費POS終端應用程式之啟動器(22)且含有產生付費值之一單元;該啟動器(22)配備有通信元件(24),該通信元件(24)與該可抽換式記憶體卡(1)上之該通信元件(13)相容或與該行動通信裝置(4)之短距離通信元件相容。 The payment terminal of any one of claims 1 to 16, wherein the payment terminal further comprises an initiator (22) of the paid POS terminal application located in the store and having a unit for generating a payment value; The starter (22) is equipped with a communication component (24) that is compatible with the communication component (13) on the removable memory card (1) or with the mobile communication device (4) The short-range communication components are compatible. 一種直接帳單付費處理方法,其使用一行動通信裝置(較 佳一行動電話)且運行主要為EMV類型的付費POS終端應用程式,該方法之特徵在於:該付費POS終端應用程式在插入於該行動通信裝置(4)之用於額外硬體的插槽中之一可抽換式記憶體卡(1)上運行,同時與該付費卡之通信在該可抽換式記憶體卡(1)之電路內運行。 A direct bill payment processing method using a mobile communication device a mobile phone POS terminal and running an EMV type paid POS terminal application, the method is characterized in that the paid POS terminal application is inserted in a slot for the additional hardware of the mobile communication device (4) One of the removable memory cards (1) operates while communication with the payment card operates within the circuit of the removable memory card (1). 如請求項18之直接帳單付費處理方法,其特徵在於:該付費POS終端應用程式將載入至定位在該記憶體卡(1)中之該微控制器(12)中,且隨後自該安全元件(3、31)載入所選終端之身份之組態資料。 The direct bill payment processing method of claim 18, characterized in that the pay POS terminal application is loaded into the microcontroller (12) located in the memory card (1), and then from the The secure element (3, 31) loads the configuration data of the identity of the selected terminal. 如請求項18或19之直接帳單付費處理方法,其特徵在於:將關於所選付費卡之資料自該安全元件(3、32)載入至操作為一付費終端之該微控制器(12)中。 A direct bill payment processing method according to claim 18 or 19, characterized in that data relating to the selected payment card is loaded from the secure element (3, 32) to the microcontroller operating as a pay terminal (12) )in. 如請求項18至20之任一項之直接帳單付費處理方法,其特徵在於:在啟動該POS終端期間或之前,該開機載入器單元(9)運行該付費POS終端應用程式中之改變控制。 A direct bill payment processing method according to any one of claims 18 to 20, characterized in that the boot loader unit (9) runs a change in the paid POS terminal application during or before the activation of the POS terminal control. 如請求項18至21之任一項之直接帳單付費處理方法,其特徵在於:透過該行動通信裝置(4)之一輸入裝置(主要為一鍵盤)管理該付費POS終端應用程式。 The direct bill payment processing method according to any one of claims 18 to 21, characterized in that the paid POS terminal application is managed by an input device (mainly a keyboard) of the mobile communication device (4). 如請求項18至22之任一項之直接帳單付費處理方法,其特徵在於:將關於要求的付費金額之資料自分開之啟動器(22)插入於該付費POS終端應用程式中,該啟動器(22)透過無接觸通信頻道連同啟動命令發送關於該要求付費之該資料。 The direct bill payment processing method according to any one of claims 18 to 22, characterized in that: the information about the required payment amount is inserted into the paid POS terminal application from the separate initiator (22), the startup The device (22) transmits the information about the payment for the request through the contactless communication channel along with the start command.
TW100110480A 2010-03-27 2011-03-25 A payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction TWI521450B (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
SK50009-2010A SK500092010A3 (en) 2010-03-27 2010-03-27 Payment terminal using mobile communication devices, particularly mobile phone, method for cashless payment

Publications (2)

Publication Number Publication Date
TW201205477A TW201205477A (en) 2012-02-01
TWI521450B true TWI521450B (en) 2016-02-11

Family

ID=45035316

Family Applications (1)

Application Number Title Priority Date Filing Date
TW100110480A TWI521450B (en) 2010-03-27 2011-03-25 A payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction

Country Status (3)

Country Link
AR (1) AR080412A1 (en)
SK (1) SK500092010A3 (en)
TW (1) TWI521450B (en)

Also Published As

Publication number Publication date
SK500092010A3 (en) 2011-12-05
AR080412A1 (en) 2012-04-04
TW201205477A (en) 2012-02-01

Similar Documents

Publication Publication Date Title
US8583493B2 (en) Payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction
US9965762B2 (en) Combicard transaction method and system having an application parameter update mechanism
US11657384B2 (en) Apparatus and method for emulating transactional infrastructure with a digital transaction processing unit (DTPU)
RU2639690C2 (en) Method, device and secure element for implementation of secure financial transaction in device
CA2776438C (en) Mobile payment application architecture
TWI437502B (en) Systems, methods, and computer program products for supporting multiple applications and multiple instances of the same application on a wireless smart device
US7516884B2 (en) Method and system for private information exchange in smart card commerce
US20120284194A1 (en) Secure card-based transactions using mobile phones or other mobile devices
US20190392427A1 (en) Digital transaction system and method with a virtual companion card
WO2013112839A1 (en) Portable e-wallet and universal card
AU2022291440A1 (en) Digital transaction apparatus and method
TW201737169A (en) System and method for updating firmware
TW201801018A (en) System and method for secure transacting
TWI521450B (en) A payment terminal using a mobile communication device, such as a mobile phone; a method of direct debit payment transaction
TWI837075B (en) Apparatus and method for emulating transactional infrastructure with a digital transaction processing unit (dtpu)
TWI819998B (en) Apparatus and method for directly communicating with a digital transaction processing unit (dtpu)
SK322009A3 (en) Payment terminal using mobile communication device, especially mobile phone, cashless payment method

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees