TWI651677B - Log-in method for network bank account and netwok bank system apply log-in method thereof - Google Patents

Log-in method for network bank account and netwok bank system apply log-in method thereof Download PDF

Info

Publication number
TWI651677B
TWI651677B TW106115012A TW106115012A TWI651677B TW I651677 B TWI651677 B TW I651677B TW 106115012 A TW106115012 A TW 106115012A TW 106115012 A TW106115012 A TW 106115012A TW I651677 B TWI651677 B TW I651677B
Authority
TW
Taiwan
Prior art keywords
account
server
online banking
center server
authorization
Prior art date
Application number
TW106115012A
Other languages
Chinese (zh)
Other versions
TW201843636A (en
Inventor
吳冠青
傅芊芊
王淳佑
Original Assignee
臺灣銀行股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 臺灣銀行股份有限公司 filed Critical 臺灣銀行股份有限公司
Priority to TW106115012A priority Critical patent/TWI651677B/en
Publication of TW201843636A publication Critical patent/TW201843636A/en
Application granted granted Critical
Publication of TWI651677B publication Critical patent/TWI651677B/en

Links

Abstract

本發明揭露一種網路銀行帳戶的登入方法,應用於一網路銀行系統。網路銀行系統包括一帳戶管理伺服器及一帳務中心伺服器。帳戶管理伺服器透過網路與一使用端裝置及一憑證管理中心伺服器連接。登入方法包括下列步驟:帳戶管理伺服器自使用端裝置接收一登入帳戶請求;帳戶管理伺服器傳送一查核帳戶請求至帳務中心伺服器;帳務中心伺服器查核使用端裝置所對應之一授權憑證的狀態;帳務中心伺服器傳送一失效狀態資訊至帳戶管理伺服器;以及帳戶管理伺服器傳送失效狀態資訊及一刪除授權憑證指令至使用端裝置。The invention discloses a method for logging in an online banking account, which is applied to an online banking system. The online banking system includes an account management server and a billing center server. The account management server is connected to a user device and a credential management center server through the network. The login method includes the following steps: the account management server receives a login account request from the user device; the account management server transmits a check account request to the account center server; and the account center server checks the authorization of the one of the use device The status of the voucher; the account center server transmits a failure status message to the account management server; and the account management server transmits the failure status information and a delete authorization voucher command to the use device.

Description

網路銀行帳戶的登入方法及應用該登入方法之網路銀行系統Online banking account login method and online banking system using the login method

本發明係關於一種網路金融方法及系統,特別是關於一種網路銀行帳戶的登入方法及應用該登入方法之網路銀行系統。 The present invention relates to an internet financial method and system, and more particularly to an online banking account login method and an online banking system using the login method.

通訊及網路相關產業的高度發展,亦帶動電子商務的蓬勃發展,而消費者對於金融業務電子化的需求日益升高。金融業針對此種需求推出網路銀行,由商業銀行等金融機構透過網路向其使用者提供各種金融服務。近年來,更因智慧型手機之性能的提升,進一步提出應用在智慧型手機或平板電腦等電子裝置的行動銀行。使用者可藉由操作智慧型手機或平板電腦下載網路銀行的應用程式(Application,App),以進行轉帳、查帳、繳費、匯款等金融交易。 The high development of communications and network-related industries has also led to the booming of e-commerce, and consumers are increasingly demanding the electronic business of financial services. The financial industry has launched online banking for such needs, and financial institutions such as commercial banks provide various financial services to their users through the Internet. In recent years, due to the improvement of the performance of smart phones, mobile banking has been further proposed for use in electronic devices such as smart phones or tablet computers. Users can download online banking applications (Application, App) by operating a smart phone or tablet to conduct financial transactions such as transfer, audit, payment, and remittance.

藉由網路進行金融交易時,最重視的便是交易安全。關於使用者身分認證的技術,目前主要是使用授權憑證來進行使用者的身分認證。具體而言,授權憑證是由具公信力之第三認證中心,本說明書中稱為憑證管理中心伺服器,於檢核使用者身分後核發,以表示持有者所具有的身分及能力。又,核發的授權憑證同時儲存於憑證管理中心伺服器及使用者所操作的智慧型手機或平板電腦等電子裝置,以下以使用端裝置稱之。 When making financial transactions over the Internet, the most important thing is the security of the transaction. Regarding the technology of user identity authentication, it is currently mainly used to authorize credentials for user identity authentication. Specifically, the authorization certificate is issued by a credible third certification center, which is referred to as a credential management center server in this specification, and is issued after checking the identity of the user to indicate the identity and ability of the holder. Moreover, the issued authorization certificate is simultaneously stored in the credential management center server and the electronic device such as a smart phone or a tablet computer operated by the user, and is referred to as a use device.

當使用者所操作的使用端裝置遺失時,則可能有其他人(非使用者)操作該使用端裝置,以連線至網路銀行系統進行金融交易,此將嚴重影響交易安全。目前的做法是在使用者通報掛失後,由網路銀行系統傳送掛失的訊息至憑證管理中心伺服器,以註銷儲存於憑證管理中心伺服器的授權憑證。然而,使用端裝置所儲存的授權憑證仍存在,故有遭暴力破解的風險,影響交易安全甚鉅。因此,亟需一種網路銀行帳戶的登入方法,於使用者通報遺失使用端裝置後,若有非使用者試圖連線該網路銀行帳戶之虞,即可刪除使用端裝置所儲存的授權憑證,以避免遭暴力破解。 When the user device operated by the user is lost, there may be other people (non-users) operating the user device to connect to the online banking system for financial transactions, which will seriously affect transaction security. The current practice is to send the lost message to the credential management center server by the online banking system after the user reports the loss, to cancel the authorization credential stored in the credential management center server. However, the authorization credentials stored by the end device still exist, so there is a risk of being violently cracked, which affects the security of the transaction. Therefore, there is a need for an online banking account login method. After the user reports that the user device is lost, if a non-user attempts to connect to the online banking account, the authorization certificate stored by the user device can be deleted. To avoid being hacked by violence.

本發明之主要目的係在提供一種網路銀行帳戶的登入方法及應用該登入方法之網路銀行系統,藉由網路銀行系統接收登入帳戶請求時,可先查核使用端裝置所對應之授權憑證的狀態,若為失效狀態,則傳送失效狀態資訊及刪除授權憑證指令至使用端裝置,以解決習知使用端裝置遺失後,無法刪除使用端裝置所儲存之授權憑證的問題。 The main purpose of the present invention is to provide an online banking account login method and an online banking system using the login method. When the online banking system receives the login account request, the authorization certificate corresponding to the user device can be checked first. If the status is invalid, the failure status information is sent and the authorization credential command is deleted to the user device to solve the problem that the authorization certificate stored by the user device cannot be deleted after the known user device is lost.

為達成上述之目的,本發明提供一種網路銀行帳戶的登入方法,應用於一網路銀行系統,其包括一帳戶管理伺服器及一帳務中心伺服器。帳戶管理伺服器透過網路與一使用端裝置及一憑證管理中心伺服器連接。登入方法包括下列步驟:帳戶管理伺服器自使用端裝置接收一登入帳戶請求;帳戶管理伺服器傳送一查核帳戶請求至帳務中心伺服器;帳務中心伺服器查核使用端裝置所對應之一授權憑證的狀態;帳務中心伺服器傳送一失效狀態資訊至帳戶管理伺服器;以及帳戶管理伺服器傳送失效狀態資訊及一刪除授權憑證指令至使用端裝置。 To achieve the above objective, the present invention provides a method for logging in an online banking account, which is applied to an online banking system including an account management server and a billing center server. The account management server is connected to a user device and a credential management center server through the network. The login method includes the following steps: the account management server receives a login account request from the user device; the account management server transmits a check account request to the account center server; and the account center server checks the authorization of the one of the use device The status of the voucher; the account center server transmits a failure status message to the account management server; and the account management server transmits the failure status information and a delete authorization voucher command to the use device.

為達成上述之目的,本發明另提供一種網路銀行系統,用以執行一網路銀行帳戶的登入方法。網路銀行系統透過網路與一使用端裝置及 一憑證管理中心伺服器連接。網路銀行系統包括一帳戶管理伺服器以及一帳務中心伺服器。帳戶管理伺服器透過網路與使用端裝置及憑證管理中心伺服器連接。帳戶管理伺服器包括一登入作業模組,登入作業模組自使用端裝置接收一登入帳戶請求,並傳送一查核帳戶請求。帳務中心伺服器與帳戶管理伺服器電性連接,接收查核帳戶請求。帳務中心伺服器包括一查核模組,其查核使用端裝置所對應之一授權憑證的狀態,並傳送一失效狀態資訊至帳戶管理伺服器。帳戶管理伺服器傳送失效狀態資訊及一刪除授權憑證指令至使用端裝置。 To achieve the above object, the present invention further provides an online banking system for performing an online banking account login method. Internet banking system through a network and a user device and A credential management center server connection. The online banking system includes an account management server and a billing center server. The account management server is connected to the client device and the credential management center server through the network. The account management server includes a login operation module, and the login operation module receives a login account request from the user device and transmits a check account request. The account center server is electrically connected to the account management server and receives the check account request. The account center server includes a check module that checks the status of one of the authorization credentials corresponding to the user device and transmits a failure status message to the account management server. The account management server transmits the invalidation status information and a delete authorization credential command to the use device.

在本發明之一實施例中,帳戶管理伺服器自使用端裝置接收一登入帳戶請求的步驟之前,更包括下列步驟:帳戶管理伺服器自使用端裝置接收一裝置遺失資料,並傳送至帳務中心伺服器;以及帳務中心伺服器依據裝置遺失資料,變更使用端裝置對應之授權憑證至一失效狀態。 In an embodiment of the present invention, before the step of the account management server receiving a login account request from the user device, the method further includes the following steps: the account management server receives a device lost data from the user device, and transmits the data to the account. The central server; and the accounting center server change the authorization certificate corresponding to the user device to a failure state according to the lost data of the device.

在本發明之一實施例中,帳戶管理伺服器更包括一掛失作業模組,其自使用端裝置接收一裝置遺失資料,並傳送至帳務中心伺服器。 In an embodiment of the present invention, the account management server further includes a report loss module, which receives a device lost data from the user device and transmits the data to the account center server.

在本發明之一實施例中,帳務中心伺服器包括一狀態變更模組,其接收裝置遺失資料,並依據裝置遺失資料變更使用端裝置對應之授權憑證至一失效狀態。 In an embodiment of the present invention, the account center server includes a state change module, and the receiving device loses the data, and changes the authorization certificate corresponding to the user device to a failure state according to the device lost data.

在本發明之一實施例中,登入方法更包括下列步驟:使用端裝置接收失效狀態資訊後,執行刪除授權憑證指令,以刪除儲存於使用端裝置之一授權憑證。 In an embodiment of the present invention, the login method further includes the following steps: after receiving the failure status information by using the end device, executing the delete authorization credential instruction to delete the authorization credential stored in one of the user devices.

在本發明之一實施例中,帳戶管理伺服器接收失效狀態資訊的步驟之後,更包括下列步驟:傳送一註銷授權憑證請求至憑證管理中心伺服器。 In an embodiment of the present invention, after the step of receiving the invalidation status information by the account management server, the method further includes the step of: transmitting a logout authorization credential request to the credential management center server.

在本發明之一實施例中,掛失作業模組傳送一註銷授權憑證請求至憑證管理中心伺服器。 In one embodiment of the invention, the report loss module transmits a logout authorization credential request to the credential management center server.

在本發明之一實施例中,帳務中心伺服器係將使用端裝置對應之該授權憑證自一使用中狀態變更為失效狀態。 In an embodiment of the present invention, the accounting center server changes the authorization credential corresponding to the end device to an invalid state from an in-use state.

在本發明之一實施例中,狀態變更模組將使用端裝置對應之授權憑證自一使用中狀態變更為失效狀態。 In an embodiment of the present invention, the state change module changes the authorization credential corresponding to the end device to an invalid state from an in-use state.

在本發明之一實施例中,網路銀行系統更包括一客服中心伺服器,帳戶管理伺服器自客服中心伺服器接收裝置遺失資料。 In an embodiment of the present invention, the online banking system further includes a customer service center server, and the account management server receives the lost data from the customer service center server.

在本發明之一實施例中,網路銀行系統更包括一客服中心伺服器,接收一裝置遺失訊息後,再傳送裝置遺失資料至帳戶管理伺服器。 In an embodiment of the present invention, the online banking system further includes a customer service center server, and after receiving a device lost message, the transmitting device loses the data to the account management server.

在本發明之一實施例中,帳戶管理伺服器自另一使用端裝置接收裝置遺失資料。 In one embodiment of the invention, the account management server receives device lost data from another consumer device.

承上所述,依據本發明之網路銀行帳戶的登入方法及應用該登入方法之網路銀行系統,藉由網路銀行系統接收登入帳戶請求時,可先查核使用端裝置所對應之授權憑證的狀態,若為失效狀態,則傳送失效狀態資訊及刪除授權憑證指令至使用端裝置,以避免使用端裝置遺失後,其內部之授權憑證遭暴力破解,進而可提升網路銀行的交易安全。 According to the above, the online banking account login method and the online banking system using the login method can first check the authorization certificate corresponding to the user device when receiving the login account request through the online banking system. If the status is invalid, the failure status information is transmitted and the authorization credential command is deleted to the user device to prevent the internal authorization certificate from being violently cracked after the use device is lost, thereby improving the security of the online banking transaction.

1‧‧‧網路銀行系統 1‧‧‧Internet Banking System

10‧‧‧帳戶管理伺服器 10‧‧‧Account Management Server

11‧‧‧傳輸模組 11‧‧‧Transmission module

12‧‧‧記憶模組 12‧‧‧Memory Module

13‧‧‧登入作業模組 13‧‧‧ Login Operation Module

14‧‧‧掛失作業模組 14‧‧‧Reporting Loss Module

20‧‧‧帳務中心伺服器 20‧‧‧Accounting Center Server

21‧‧‧傳輸模組 21‧‧‧Transmission module

22‧‧‧記憶模組 22‧‧‧Memory Module

23‧‧‧查核模組 23‧‧‧Check module

24‧‧‧狀態變更模組 24‧‧‧State Change Module

30‧‧‧客服中心伺服器 30‧‧‧Customer Service Server

80、80a、…、80n‧‧‧使用端裝置 80, 80a, ..., 80n‧‧‧ use end device

81‧‧‧授權憑證 81‧‧‧Authorization certificate

90‧‧‧憑證管理中心伺服器 90‧‧‧Voucher Management Center Server

91‧‧‧授權憑證 91‧‧‧Authorization certificate

S10~S284‧‧‧步驟 S10~S284‧‧‧Steps

圖1A為本發明之網路銀行帳戶系統之一實施例的使用環境示意圖。 FIG. 1A is a schematic diagram of a usage environment of an embodiment of an online banking account system of the present invention.

圖1B為圖1A所示之網路銀行帳戶系統之一實施例的示意圖。 FIG. 1B is a schematic diagram of an embodiment of the online banking account system shown in FIG. 1A.

圖2A及圖2B為本發明之網路銀行帳戶的登入方法之一實施例的流程步驟圖。 2A and 2B are flow diagrams showing an embodiment of an online banking account login method according to an embodiment of the present invention.

圖3為使用端裝置所執行網路銀行帳戶的登入方法的步驟流程圖。 FIG. 3 is a flow chart showing the steps of the online banking account login method performed by the terminal device.

為能讓 貴審查委員能更瞭解本發明之技術內容,特舉較佳具體實施例說明如下。 In order to enable the reviewing committee to better understand the technical contents of the present invention, the preferred embodiments are described below.

首先,由於金融機構須處理大量的帳務資料,故通常具有專用於處理帳務資料的核心帳務伺服器,並另外具有前置作業伺服器。前置作業伺服器與其他伺服器及使用端裝置連繫,作為資料傳輸的平台,並可處理與帳務無關的一般作業,例如網路銀行帳戶的登入、問題排除等,而與帳務相關的訊息則傳送至核心帳務伺服器,由核心帳務伺服器處理。 First, because financial institutions have to deal with a large amount of accounting data, they usually have a core accounting server dedicated to processing accounting data, and additionally have a pre-job server. The pre-service server is connected to other servers and user devices as a platform for data transmission, and can handle general operations unrelated to accounting, such as online banking account login, problem elimination, etc., and related to accounting. The message is sent to the core accounting server and processed by the core accounting server.

本實施例之網路銀行系統1亦包括二個伺服器,一帳戶管理伺服器10及一帳務中心伺服器20,如圖1A所示,圖1A為本發明之網路銀行帳戶系統之一實施例的使用環境示意圖。其中,帳戶管理伺服器10作為前置作業伺服器,主要用於傳輸資料的平台,而帳務中心伺服器20作為核心帳務伺服器,專用於處理與金流相關的作業。又,帳戶管理伺服器10與帳務中心伺服器20相互電性連接,以下先說明其硬體架構。 The online banking system 1 of the present embodiment also includes two servers, an account management server 10 and a billing center server 20, as shown in FIG. 1A, and FIG. 1A is one of the online banking account systems of the present invention. A schematic diagram of the use environment of the embodiment. Among them, the account management server 10 is used as a pre-work server, and is mainly used for a platform for transmitting data, and the account center server 20 serves as a core accounting server for processing jobs related to the golden stream. Further, the account management server 10 and the account center server 20 are electrically connected to each other, and the hardware structure thereof will be described below.

圖1B為圖1A所示之網路銀行帳戶系統之一實施例的示意圖,請同時參考圖1A及圖1B所示。具體而言,本實施例之帳戶管理伺服器10包括傳輸模組11、記憶模組12、登入作業模組13、及掛失作業模組14。同樣的,帳務中心伺服器20亦包括傳輸模組21、記憶模組22、查核模組23、狀態變更模組24。 FIG. 1B is a schematic diagram of an embodiment of the online banking account system shown in FIG. 1A. Please refer to FIG. 1A and FIG. 1B simultaneously. Specifically, the account management server 10 of the embodiment includes a transmission module 11, a memory module 12, a login operation module 13, and a loss reporting module 14. Similarly, the accounting center server 20 also includes a transmission module 21, a memory module 22, a verification module 23, and a state change module 24.

需注意的是,上述各個模組除可配置為硬體裝置、軟體程式、韌體或其組合外,亦可藉電路迴路或其他適當型式配置;並且,各個模組除可以單獨之型式配置外,亦可以結合之型式配置。一個較佳實施例是各模組皆為軟體程式儲存於記憶體上,藉由網路銀行系統1中的一處理器(圖未示)執行各模組以達成本發明之功能。此外,本實施方式僅例示本發明之較佳實施例,為避免贅述,並未詳加記載所有可能的變化組合。然而,本領域之通常知識者應可理解,上述各模組或元件未必皆為必要。且為實 施本發明,亦可能包含其他較細節之習知模組或元件。各模組或元件皆可能視需求加以省略或修改,且任兩模組間未必不存在其他模組或元件。 It should be noted that, in addition to being configurable as a hardware device, a software program, a firmware, or a combination thereof, each of the above modules may also be configured by a circuit loop or other suitable type; and, in addition, each module may be configured in a separate type. It can also be combined with the type configuration. In a preferred embodiment, each module is stored in a software program on a memory, and each module is executed by a processor (not shown) in the online banking system 1 to achieve the functions of the present invention. In addition, the present embodiment is merely illustrative of preferred embodiments of the present invention, and in order to avoid redundancy, all possible combinations of variations are not described in detail. However, those of ordinary skill in the art will appreciate that the various modules or components described above are not necessarily required. And be true The invention may also include other conventional modules or components of more detail. Each module or component may be omitted or modified as needed, and no other modules or components may exist between any two modules.

帳戶管理伺服器10與帳務中心伺服器20藉由傳輸模組11、21相互連接,以進行資料傳輸。除了網路銀行系統1內部的資料傳輸以外,帳戶管理伺服器10亦可透過網路與使用端裝置80、80a、…、80n及憑證管理中心伺服器90連接。需說明的是,帳戶管理伺服器10可與多台使用端裝置80、80a、…、80n連接,以下先以一台使用端裝置80為例說明。 The account management server 10 and the account center server 20 are connected to each other by the transmission modules 11, 21 for data transmission. In addition to the data transfer within the online banking system 1, the account management server 10 can also be connected to the client devices 80, 80a, ..., 80n and the credential management center server 90 via the network. It should be noted that the account management server 10 can be connected to a plurality of user devices 80, 80a, ..., 80n. The following uses a user device 80 as an example for description.

換言之,帳戶管理伺服器10藉由傳輸模組11與使用端裝置80及憑證管理中心伺服器90進行資料傳輸。而帳戶管理伺服器10與帳務中心伺服器20、使用端裝置80及憑證管理中心伺服器90間的資料傳輸的方式是依據彼此相互配合的硬體架構不同而有不同,具體來說可以透過符合例如乙太網絡、3G、Wi-Fi或4G LTE等傳輸資料技術實現。較佳的,帳戶管理伺服器10可透過虛擬私人網路(Virtual Private Network,VPN)與帳務中心伺服器20及憑證管理中心伺服器90連接。 In other words, the account management server 10 performs data transmission by the transmission module 11 with the user terminal device 80 and the voucher management center server 90. The manner of data transmission between the account management server 10 and the account center server 20, the user terminal device 80, and the voucher management center server 90 is different according to the hardware architecture of each other, specifically, It is compatible with transmission data technologies such as Ethernet, 3G, Wi-Fi or 4G LTE. Preferably, the account management server 10 can be connected to the account center server 20 and the credential management center server 90 via a virtual private network (VPN).

又,本實施例之帳戶管理伺服器10可提供網路銀行帳戶的操作介面,以供使用端裝置80連線操作,以進行申請網路銀行帳戶,並取得由憑證管理中心伺服器90所核發的授權憑證。為求說明清楚明瞭,圖1A及實施方式係將儲存於使用端裝置80的授權憑證81給予標號81,而儲存於憑證管理中心伺服器90的授權憑證91給予標號91。使用端裝置80取得授權憑證81後,使用者U即可操作使用端裝置80以進行轉帳、查帳、繳費、匯款等金融交易。其中,使用端裝置80即為使用者U所操作的電子裝置,其可以為智慧型手機、平板電腦(PAD)、個人電腦等具有執行電腦軟體之電子裝置,本發明並不限制,本實施例係以智慧型手機為例說明。 Moreover, the account management server 10 of the present embodiment can provide an operation interface of the online bank account for the user device 80 to operate in connection to apply for an online bank account and obtain the certificate issued by the certificate management center server 90. Authorization credentials. For clarity of explanation, FIG. 1A and the embodiment give the authorization certificate 81 stored in the use terminal device 80 to the reference numeral 81, and the authorization certificate 91 stored in the voucher management center server 90 is given the reference numeral 91. After the authorization device 81 is obtained by using the terminal device 80, the user U can operate the user device 80 to perform financial transactions such as transfer, audit, payment, and remittance. The user device U is an electronic device operated by the user U, and may be an electronic device that executes a computer software, such as a smart phone, a tablet computer (PAD), a personal computer, etc., which is not limited by the present invention. Take a smart phone as an example.

本實施例之網路銀行帳戶的登入方法(以下簡稱為登入方法)應用於網路銀行系統1及使用端裝置80。。圖2A及圖2B為本發明之網路銀行帳戶的登入方法之一實施例的流程步驟圖。需說明的是,本實施例之登入方法係為解決使用端裝置80遺失後,可能遭暴力破解授權憑證81的問題。因此,圖2A為使用者U通報使用端裝置80遺失時,本實施例之登入方法的執行步驟流程圖,而圖2B則為操作遺失的使用端裝置80登入網路銀行帳戶時,本實施例之登入方法的執行步驟流程圖。以下請先同時參考圖1A、圖1B及圖2A所示,以瞭解本發明。 The login method of the online bank account of the present embodiment (hereinafter referred to as the login method) is applied to the online banking system 1 and the usage device 80. . 2A and 2B are flow diagrams showing an embodiment of an online banking account login method according to an embodiment of the present invention. It should be noted that the login method in this embodiment is to solve the problem that the authorization device 81 may be violently cracked after the use device 80 is lost. Therefore, FIG. 2A is a flow chart of the execution steps of the login method of the embodiment when the user U notifies the user device 80 that the user device 80 is lost, and FIG. 2B is the embodiment for the operation of the lost user device 80 to log in to the online bank account. A flow chart of the execution steps of the login method. Please refer to FIG. 1A, FIG. 1B and FIG. 2A for the purpose of understanding the present invention.

步驟S10:客服中心伺服器30接收一裝置遺失訊息。 Step S10: The call center server 30 receives a device lost message.

網路銀行系統1更包括一客服中心伺服器30,當使用端裝置80遺失後,使用者U通常會直接撥打電話至客服中心,圖1A係以虛線表示,由客服人員協助掛失。進言之,當客服人員接到掛失的電話後,再確認使用者U的身分後,可於客服中心的電腦輸入使用端裝置80遺失的訊息,客服中心伺服器30即可接收一裝置遺失訊息。 The online banking system 1 further includes a customer service center server 30. When the user terminal 80 is lost, the user U usually directly calls the customer service center. FIG. 1A is indicated by a dotted line, and the customer service personnel assists in reporting the loss. In other words, when the customer service personnel receives the lost call and then confirms the identity of the user U, the user can enter the missing message from the user terminal 80 on the computer of the customer service center, and the service center server 30 can receive a device lost message.

步驟S11:客服中心伺服器30依據裝置遺失訊息,產生一裝置遺失資料,並傳送至帳戶管理伺服器10。 Step S11: The customer service center server 30 generates a device lost data according to the device lost message, and transmits it to the account management server 10.

客服中心伺服器30接收裝置遺失訊息後,並可依據該裝置遺失訊息產生一裝置遺失資料,其包含遺失之使用端裝置80的代碼或其所儲存之授權憑證81的號碼。接著,客服中心伺服器30可將裝置遺失資料傳送至帳戶管理伺服器10。 After receiving the device lost message, the customer service center server 30 may generate a device lost data according to the device lost message, which includes the code of the lost user device 80 or the number of the authorization certificate 81 stored therein. Next, the call center server 30 can transmit the device lost data to the account management server 10.

步驟S12:帳戶管理伺服器10接收裝置遺失資料。 Step S12: The account management server 10 receives the device lost data.

在本實施例中,使用者U是透過客服中心通知使用端裝置80遺失的訊息,故帳戶管理伺服器10的傳輸模組11可自客服中心伺服器30接收裝置遺失資料。 In this embodiment, the user U notifies the user terminal 80 of the lost message through the customer service center, so the transmission module 11 of the account management server 10 can receive the device lost data from the customer service center server 30.

在其他實施例中,使用者U亦可藉由其他具有身分驗證設備的電子裝置,例如使用端裝置80a,傳送裝置遺失資料至帳戶管理伺服器10。換言之,帳戶管理伺服器10的傳輸模組11亦可自另一使用端裝置80a接收裝置遺失資料,本發明並不限制。帳戶管理伺服器10確認使用端裝置80a的身分後,亦即,確認裝置遺失資料的真實性後,即可執行後續的步驟。 In other embodiments, the user U may also lose the data to the account management server 10 by using another electronic device having the identity verification device, for example, using the terminal device 80a. In other words, the transmission module 11 of the account management server 10 can also receive the lost data from the other device 80a, which is not limited by the present invention. After the account management server 10 confirms the identity of the user terminal 80a, that is, after confirming the authenticity of the lost device, the subsequent steps can be performed.

步驟S13:帳戶管理伺服器10傳送裝置遺失資料至帳務中心伺服器20。 Step S13: The account management server 10 transmits the lost data to the account center server 20.

傳輸模組11接收裝置遺失資料後,將其傳送至掛失作業模組14。如前述,裝置遺失資料包含遺失之使用端裝置80的代碼或其所儲存之授權憑證81的號碼,故掛失作業模組14可得知使用端裝置80所對應的網路銀行帳戶,較佳的,可註記掛失的紀錄。又,掛失作業模組14可再透過傳輸模組11,將裝置遺失資料傳送至帳務中心伺服器20。 After receiving the lost data, the transmission module 11 transmits the data to the loss reporting module 14. As described above, the device lost data includes the code of the lost user device 80 or the number of the authorization certificate 81 stored therein, so that the report loss module 14 can know the online bank account corresponding to the user device 80, preferably. Can record the loss report. Moreover, the lost operation module 14 can transmit the device lost data to the account center server 20 through the transmission module 11.

步驟S14:帳務中心伺服器20依據裝置遺失資料更新對應之授權憑證至一失效狀態。 Step S14: The account center server 20 updates the corresponding authorization certificate to a failure state according to the device lost data.

由帳務中心伺服器20的傳輸模組21接收裝置遺失資料,並傳送至狀態變更模組24。接著,狀態變更模組24依據裝置遺失資料,亦即,利用使用端裝置80的代碼或其所儲存之授權憑證81的號碼的資訊,自記憶模組22中搜尋使用端裝置80所對應之授權憑證81,並將其變更至一失效狀態。 The device lost data is received by the transmission module 21 of the accounting center server 20 and transmitted to the state change module 24. Then, the state change module 24 searches the memory module 22 for the authorization corresponding to the user device 80 according to the device lost data, that is, the code of the user device 80 or the information of the number of the authorization certificate 81 stored therein. Document 81 and change it to a failed state.

具體而言,記憶模組22儲存各個授權憑證的狀態,例如,當使用端裝置80取得授權憑證81後,記憶模組22即可儲存「授權憑證81為使用中狀態」的資訊;當狀態變更模組24接收到裝置遺失資料後,即可更新記憶模組22所儲存的資料,變更為「授權憑證81為失效狀態」的資 訊。簡言之,狀態變更模組24接收裝置遺失資料後,可依據裝置遺失資料變更使用端裝置80所對應之授權憑證81至一失效狀態。 Specifically, the memory module 22 stores the status of each authorization credential. For example, after the end device 80 obtains the authorization credential 81, the memory module 22 can store the information that the authorization credential 81 is in use state; After receiving the lost data of the device, the module 24 can update the data stored in the memory module 22 and change it to "the authorization certificate 81 is in a failed state". News. In short, after the state change module 24 receives the lost data, the state change module 24 can change the authorization credential 81 corresponding to the user device 80 to a failure state according to the device lost data.

又,一般係透過不同的旗標表示特定的狀態,例如授權憑證81具有「使用中旗標」代表其為「使用中狀態」;若具有「失效旗標」代表其為「失效狀態」。因此,當狀態變更模組24接收到裝置遺失資料後,於記憶模組22搜尋使用端裝置80所對應之授權憑證81,並將「使用中旗標」變更為「失效旗標」。 Moreover, a specific state is generally indicated by a different flag. For example, the authorization credential 81 has an "in-use flag" to represent it as "in-use state"; if it has a "failed flag", it represents a "failed state". Therefore, when the state change module 24 receives the lost data of the device, the memory module 22 searches for the authorization credential 81 corresponding to the user device 80, and changes the "in-use flag" to the "failed flag".

在其他實施例中,若使用者U後續找到使用端裝置80,可參照前述方法(透過客服中心伺服器30、或其他具有身分驗證設備的電子裝置)通知取消掛失,狀態變更模組24即可將授權憑證81從失效狀態變更回使用中狀態。 In other embodiments, if the user U subsequently finds the user device 80, the method can be used to notify the cancellation of the loss by referring to the foregoing method (through the customer service center server 30 or other electronic device having the identity verification device), and the state change module 24 can The authorization credential 81 is changed from the failed state back to the in-use state.

然而,在使用端裝置80掛失後,若仍有使用端裝置80連線至帳戶管理伺服器10,則執行後續步驟(步驟S20之後),請同時參考圖1A、圖1B及圖2B所示。 However, after the end device 80 is reported to be lost, if the user device 80 is still connected to the account management server 10, the subsequent steps are performed (after step S20), please refer to FIG. 1A, FIG. 1B and FIG. 2B simultaneously.

步驟S20:使用端裝置80傳送一登入帳戶請求至帳戶管理伺服器10。 Step S20: The use terminal device 80 transmits a login account request to the account management server 10.

當使用者U操作使用端裝置80以登入網路銀行帳戶時,使用端裝置80傳送登入帳戶請求至帳戶管理伺服器10,此為登入網路銀行帳戶的一般操作。然而,在使用端裝置80掛失後,若仍有使用端裝置80連線至帳戶管理伺服器10,試圖登入網路銀行帳戶的情形,此極可能是其他人(非使用者)操作使用端裝置80。為避免他人試圖以不法的方式取得授權憑證81,可藉由後續步驟,禁止已掛失的使用端裝置80登入網路銀行帳戶。 When the user U operates the use device 80 to log in to the online bank account, the use terminal device 80 transmits a login account request to the account management server 10, which is a general operation for logging into the online bank account. However, after the end device 80 is reported to be lost, if the user device 80 is still connected to the account management server 10 and attempts to log in to the online bank account, it is highly probable that other people (non-users) operate the user device. 80. In order to prevent others from attempting to obtain the authorization credential 81 in an unlawful manner, the lost-end user device 80 can be prohibited from logging into the online banking account by the subsequent steps.

步驟S21:帳戶管理伺服器10接收登入帳戶請求。 Step S21: The account management server 10 receives the login account request.

帳戶管理伺服器10的傳輸模組11自使用端裝置80接收一登入帳戶請求後,再傳送至登入作業模組13,以執行登入作業。需再次說明的是,使用端裝置80已掛失。 The transmission module 11 of the account management server 10 receives a login account request from the user device 80 and transmits it to the login operation module 13 to perform the login operation. It should be noted again that the use of the end device 80 has been reported to be lost.

步驟S22:帳戶管理伺服器10傳送一查核帳戶請求至帳務中心伺服器。 Step S22: The account management server 10 transmits a check account request to the account center server.

在本實施例中,登入作業模組13接收登入帳戶請求後,並不會直接讓對應之裝置(使用端裝置80)直接與網路銀行系統1連線,而是先傳送一查核帳戶請求至帳務中心伺服器20。換言之,本實施例之登入作業模組13接收登入帳戶請求後,可先產生查核帳戶請求,其包含連線請求登入之使用端裝置80的代碼或其所儲存之授權憑證81的號碼的資訊。同樣的,登入作業模組13透過傳輸模組11將查核帳戶請求傳送至帳務中心伺服器20。 In this embodiment, after the login operation module 13 receives the login account request, it does not directly connect the corresponding device (the use device 80) to the online banking system 1, but first transmits a check account request to Accounting Center Server 20. In other words, after receiving the login account request, the login operation module 13 of the present embodiment may first generate a verification account request, which includes information of the code of the user device 80 that is connected to request the login or the number of the authorization certificate 81 stored therein. Similarly, the login operation module 13 transmits the verification account request to the account center server 20 via the transmission module 11.

步驟S23:帳務中心伺服器20查核使用端裝置80所對應之授權憑證的狀態。 Step S23: The account center server 20 checks the status of the authorization credential corresponding to the user device 80.

在本實施例中,帳務中心伺服器20透過傳輸模組21接收查核帳戶請求後,並傳送至查核模組23,由查核模組23查核使用端裝置80所對應之一授權憑證的狀態。具體而言,查核模組23可由查核帳戶請求得知連線請求登入之使用端裝置80的代碼、或請求登入之裝置(使用端裝置80)所儲存之授權憑證81號碼。接著,查核模組23即可於記憶模組22查詢使用端裝置80所對應之授權憑證81的狀態,本實施例係為失效狀態。 In this embodiment, the account center server 20 receives the check account request through the transmission module 21, and transmits it to the checking module 23, and the checking module 23 checks the status of one of the authorization credentials corresponding to the user device 80. Specifically, the verification module 23 can request the verification account to request the code of the user device 80 that the connection request to log in, or the authorization certificate 81 number stored by the device (the use device 80) that requests the login. Then, the checking module 23 can query the memory module 22 for the status of the authorization credential 81 corresponding to the user device 80. This embodiment is a failure state.

具體而言,由於本實施例之使用端裝置80為已掛失的裝置,並於步驟S14中(圖2B),授權憑證81已變更至失效狀態。因此,步驟S23中,查核模組23於記憶模組22可查詢到使用端裝置80所對應之授權憑 證81為失效狀態。若是由同的旗標表示特定的狀態者,則可由「失效旗標」判斷其為失效狀態。 Specifically, since the user terminal device 80 of the present embodiment is a device that has been reported to be lost, and in step S14 (FIG. 2B), the authorization certificate 81 has been changed to the invalid state. Therefore, in step S23, the checking module 23 can query the memory module 22 for the authorization corresponding to the user device 80. Certificate 81 is in a failed state. If the same flag indicates a specific state, it can be judged as a failure state by the "failure flag".

步驟S24:帳務中心伺服器20傳送一失效狀態資訊至帳戶管理伺服器10。 Step S24: The account center server 20 transmits a failure status message to the account management server 10.

查核模組23於步驟S23得知使用端裝置80所對應之授權憑證81為失效狀態,接著,查核模組23可再透過傳輸模組21傳送一失效狀態資訊至帳戶管理伺服器10。 The verification module 23 knows in step S23 that the authorization credential 81 corresponding to the user device 80 is in a failed state. Then, the verification module 23 can transmit a failure status information to the account management server 10 through the transmission module 21.

步驟S25:帳戶管理伺服器10接收失效狀態資訊。 Step S25: The account management server 10 receives the failure status information.

本實施例之傳輸模組11接收失效狀態資訊後,再傳送至登入作業模組13。登入作業模組13接收失效狀態資訊,得知連線請求登入之使用端裝置80的授權憑證為失效狀態,即可執行步驟S26及步驟S27。 The transmission module 11 of this embodiment receives the failure status information and transmits it to the login operation module 13. The login operation module 13 receives the failure status information, and knows that the authorization certificate of the user device 80 that the connection request is logged in is in a invalid state, and step S26 and step S27 can be performed.

另需說明的是,在其他實施例中,若連線請求登入之使用端裝置的授權憑證為使用中狀態,則直接將使用中狀態資訊傳送至使用端裝置,且保持連線,令使用者U可操作使用端裝置(非掛失)登入網路銀行帳戶。 It should be noted that, in other embodiments, if the authorization credential of the user device that is requested to log in to the connection is in the in-use state, the in-use status information is directly transmitted to the user device, and the connection is kept, so that the user U can operate the end device (not lost) to log in to the online bank account.

步驟S26:帳戶管理伺服器10傳送一註銷授權憑證請求至憑證管理中心伺服器90。 Step S26: The account management server 10 transmits a logout authorization credential request to the credential management center server 90.

登入作業模組13接收失效狀態資訊後,即可產生一註銷授權憑證請求,並透過傳輸模組11將註銷授權憑證請求傳送至憑證管理中心伺服器90,以請求憑證管理中心伺服器90將其所儲存之授權憑證91註銷。憑證管理中心伺服器90註銷授權憑證91後,進而令使用端裝置80亦無法利用其所儲存的授權憑證81連線登入網路銀行帳戶。 After the login operation module 13 receives the failure status information, a logout authorization credential request can be generated, and the logout authorization credential request is transmitted to the credential management center server 90 through the transmission module 11 to request the credential management center server 90 to The stored authorization certificate 91 is cancelled. After the voucher management center server 90 cancels the authorization voucher 91, the user device 80 is also unable to log in to the online bank account by using the stored authorization voucher 81.

換言之,使用端裝置80於通報掛失,且憑證管理中心伺服器90自帳戶管理伺服器10接收註銷授權憑證請求,並註銷對應之授權憑證91後,使用端裝置80亦無法再利用授權憑證81連線登入網路銀行帳戶。亦即,使用端裝置80於通報掛失後的連線行為皆失效。 In other words, after the end device 80 is used to report the loss, and the voucher management center server 90 receives the logout authorization credential request from the account management server 10, and cancels the corresponding authorization credential 91, the use device 80 can no longer use the authorization credential 81. Log in to your online banking account. That is, the connection behavior of the end device 80 after the notification of the loss is invalid.

另外,帳戶管理伺服器10除了傳送註銷授權憑證請求至憑證管理中心伺服器90(步驟S26),亦可將失效狀態資訊傳送至使用端裝置80(步驟S27)。本發明並未限制步驟S26及步驟S27的先後順序,亦可同時作動,僅為方便說明,而先說明步驟S26。 Further, the account management server 10 can transmit the failure status information to the use side device 80 in addition to transmitting the logout authorization voucher request to the voucher management center server 90 (step S26) (step S27). The present invention does not limit the sequence of steps S26 and S27, and can also be operated at the same time. For convenience of explanation, step S26 will be described first.

步驟S27:帳戶管理伺服器10傳送失效狀態資訊及一刪除授權憑證指令至使用端裝置80。 Step S27: The account management server 10 transmits the invalidation status information and a delete authorization credential command to the user device 80.

登入作業模組13於步驟S25接收失效狀態資訊後,更可進一步透過傳輸模組11將失效狀態資訊傳送至連線請求登入且已掛失的使用端裝置80。此外,帳務中心伺服器20亦傳送刪除授權憑證指令至使用端裝置80。 After the login operation module 13 receives the failure status information in step S25, the failure status information can be further transmitted to the use terminal device 80 that has requested the login and has been reported to be lost through the transmission module 11. In addition, the billing center server 20 also transmits a delete authorization credential command to the consumer device 80.

需說明的是,失效狀態資訊與刪除授權憑證指令可同時或不同時傳送至使用端裝置80,本發明並未特別限制。以同時傳送為例,登入作業模組13接收失效狀態資訊後,可將失效狀態資訊與刪除授權憑證指令同時傳送至使用端裝置80。以不同時傳送為例,使用端裝置80連線帳戶管理伺服器10並下載網路銀行的應用程式(App),其應用程式即包含刪除授權憑證指令。換言之,帳戶管理伺服器10在使用端裝置80下載應用程式時,先傳送刪除授權憑證指令至使用端裝置80,並將刪除授權憑證指令儲存於使用端裝置80。在使用端裝置80掛失後,再傳送失效狀態資訊至使用端裝置80,並於使用端裝置80執行步驟S28。 It should be noted that the failure status information and the deletion authorization certificate instruction may be transmitted to the user device 80 at the same time or at different times, and the present invention is not particularly limited. Taking the simultaneous transmission as an example, after the login operation module 13 receives the failure status information, the failure status information and the deletion authorization certificate instruction can be simultaneously transmitted to the user device 80. Taking the different time transfer as an example, the end device 80 is used to connect the account management server 10 and download the online banking application (App), and the application includes the delete authorization credential command. In other words, when the application device 80 downloads the application, the account management server 10 first transmits the delete authorization credential command to the user device 80, and stores the delete authorization credential command to the user device 80. After the use of the end device 80 is reported to be lost, the failure status information is transmitted to the use end device 80, and the use device 80 performs step S28.

步驟S28:使用端裝置80接收失效狀態資訊後,執行刪除授權憑證指令。 Step S28: After receiving the failure status information by using the end device 80, executing the delete authorization credential instruction.

不論使用端裝置80是同時接收失效狀態資訊與刪除授權憑證指令,或是使用端裝置80於下載網路銀行的應用程式時,即先接收刪除授權憑證指令,皆是在使用端裝置80接收失效狀態資訊後,使執行刪除授權憑證指令,以刪除儲存於使用端裝置80之授權憑證81。因此,在使用 端裝置80掛失後,仍有以使用端裝置80傳送登入帳戶請求至帳戶管理伺服器10(步驟S20),試圖登入網路銀行帳戶的情形時,本實施例之網路銀行系統1即可透過執行步驟S21~S25及S27,促使使用端裝置80刪除儲存於使用端裝置80之授權憑證81。因此,可避免有心人士撿取使用端裝置80後,試圖以暴力破解的方式取得授權憑證81,進而可提升網路銀行的交易安全。 Regardless of whether the user device 80 receives the failure status information and deletes the authorization credential command at the same time, or uses the end device 80 to download the online banking application, the instruction to delete the authorization credential is received first, and the receiving device 80 receives the invalidation. After the status information, the delete authorization credential command is executed to delete the authorization credential 81 stored in the user device 80. Therefore, in use After the end device 80 is reported to be lost, the online banking system 1 of the present embodiment can still be transmitted when the user device 80 transmits the login account request to the account management server 10 (step S20) to attempt to log in to the online banking account. Steps S21 to S25 and S27 are executed to prompt the user terminal device 80 to delete the authorization credential 81 stored in the user device 80. Therefore, it is possible to prevent the interested person from obtaining the authorization device 81 by violently cracking after using the terminal device 80, thereby improving the security of the online banking transaction.

總的來說,登入方法之步驟S20及步驟S28為使用端裝置80所執行的步驟,而使用端裝置80所執行之登入方法的應用程式如圖3所示。亦即,圖3為使用端裝置所執行網路銀行帳戶的登入方法的步驟流程圖,以下搭配圖3作進一步的說明。 In general, steps S20 and S28 of the login method are the steps performed by the end device 80, and the application using the login method executed by the end device 80 is as shown in FIG. That is, FIG. 3 is a flow chart showing the steps of the online bank account login method performed by the terminal device, which will be further described below with reference to FIG. 3.

首先,使用端裝置80亦傳送登入帳戶請求至帳戶管理伺服器20(步驟S20),以連線請求登入網路銀行帳戶,而步驟S28又可分為四個子步驟(步驟S281~S284),說明如下。 First, the user device 80 also transmits a login account request to the account management server 20 (step S20), and requests to log in to the online bank account by connecting, and step S28 can be further divided into four sub-steps (steps S281-S284), indicating as follows.

使用端裝置80自帳戶管理伺服器20接收授權憑證狀態資訊(步驟S281),再判斷授權憑證狀態資訊是否失效狀態(步驟S282)。具體而言,其中授權憑證狀態資訊包括失效狀態資訊、使用中狀態資訊(可參考前述步驟S14之內容)。若授權憑證狀態資訊為失效狀態資訊,則表示使用端裝置80已掛失,而有授權憑證81有被盜取之風險,進而執行步驟S283,以執行刪除授權憑證指令,並刪除儲存於使用端裝置80之授權憑證81。在其他實施例中,若授權憑證狀態資訊為使用中狀態資訊,表示請求登入的使用端裝置為正常使用狀態,而可執行步驟S284,續行登入網路銀行帳戶。 The use terminal device 80 receives the authorization voucher status information from the account management server 20 (step S281), and then determines whether the authorization voucher status information is invalid (step S282). Specifically, the authorization credential status information includes invalid status information and in-use status information (refer to the foregoing step S14). If the authorization credential status information is the invalid status information, it indicates that the use end device 80 has reported the loss, and the authorized credential 81 has the risk of being stolen, and then proceeds to step S283 to execute the delete authorization credential command, and deletes the stored on the use end device. 80 authorization certificate 81. In other embodiments, if the authorization credential status information is the in-use status information, the user device requesting the login is in a normal use state, and step S284 may be performed to continue to log in to the online banking account.

另外,由於本實施例之登入方法,在使用端裝置80掛失後,係透過傳送註銷授權憑證請求至憑證管理中心伺服器90(步驟S26),及傳送失效狀態資訊及刪除授權憑證指令至使用端裝置80(步驟S27),以避 免有心人士撿取使用端裝置80後,試圖以暴力破解的方式取得授權憑證81。因此,使用者U從新取得新的使用端裝置後,可再重新下載網路銀行的應用程式,並透過操作新的使用端裝置取得身分認證後,憑證管理中心伺服器90可移除註銷,恢復授權憑證91的權限,而帳務中心伺服器20的查核模組23,亦可將授權憑證81的狀態自「失效狀態」變更為「重新開啟狀態」,以利新的使用端裝置開通及使用。 In addition, due to the login method of this embodiment, after the use device 80 is reported to be lost, the request is sent to the voucher management center server 90 by transmitting the logout authorization credential (step S26), and the invalidation status information and the deletion authorization credential command are transmitted to the use end. Device 80 (step S27), to avoid After the use of the device 80 is avoided, the intent-free person attempts to obtain the authorization certificate 81 by means of brute force. Therefore, after the user U newly acquires a new user device, the user can re-download the online banking application, and after obtaining the identity authentication by operating the new user device, the voucher management center server 90 can be deleted and restored. The authority of the authorization certificate 91, and the verification module 23 of the account center server 20 can also change the status of the authorization certificate 81 from "invalid state" to "re-open state" to facilitate the opening and use of the new user device. .

綜上所述,依據本發明之網路銀行帳戶的登入方法及應用該登入方法之網路銀行系統,藉由網路銀行系統接收登入帳戶請求時,可先查核使用端裝置所對應之授權憑證的狀態,若為失效狀態,則傳送失效狀態資訊及刪除授權憑證指令至使用端裝置,以避免使用端裝置遺失後,其內部之授權憑證遭暴力破解,進而可提升網路銀行的交易安全。 In summary, the online banking account login method and the online banking system using the login method according to the present invention can first check the authorization certificate corresponding to the user device when receiving the login account request through the online banking system. If the status is invalid, the failure status information is transmitted and the authorization credential command is deleted to the user device to prevent the internal authorization certificate from being violently cracked after the use device is lost, thereby improving the security of the online banking transaction.

需注意的是,上述僅為實施例,而非限制於實施例。譬如此不脫離本發明基本架構者,皆應為本專利所主張之權利範圍,而應以專利申請範圍為準。 It should be noted that the above is only an embodiment, and is not limited to the embodiment. Therefore, those who do not depart from the basic structure of the present invention should be bound by the scope of the patent, and the scope of the patent application shall prevail.

Claims (9)

一種網路銀行帳戶的登入方法,應用於一網路銀行系統,其包括一帳戶管理伺服器及一帳務中心伺服器,該帳戶管理伺服器透過網路與一使用端裝置及一憑證管理中心伺服器連接,該登入方法包括下列步驟:該帳戶管理伺服器自另一使用端裝置接收一裝置遺失資料,並傳送至該帳務中心伺服器;該帳務中心伺服器依據該裝置遺失資料,變更該使用端裝置對應之該授權憑證至一失效狀態;該帳戶管理伺服器自該使用端裝置接收一登入帳戶請求;該帳戶管理伺服器傳送一查核帳戶請求至該帳務中心伺服器;該帳務中心伺服器查核該使用端裝置所對應之一授權憑證的狀態;該帳務中心伺服器傳送一失效狀態資訊至該帳戶管理伺服器;以及該帳戶管理伺服器傳送該失效狀態資訊及一刪除授權憑證指令至該使用端裝置。 An online banking account login method is applied to an online banking system, which includes an account management server and a billing center server, the account management server through the network and a user device and a credential management center The server is connected. The login method includes the following steps: the account management server receives a device lost data from another user device and transmits the lost data to the account center server; the account center server loses data according to the device. Changing the authorization credential corresponding to the user device to a failed state; the account management server receives a login account request from the user device; the account management server transmits a check account request to the account center server; The account center server checks the status of one of the authorization credentials corresponding to the user device; the account center server transmits a failure status message to the account management server; and the account management server transmits the failure status information and a The authorization credential command is deleted to the user device. 如申請專利範圍第1項所述之網路銀行帳戶的登入方法,更包括下列步驟:該使用端裝置接收該失效狀態資訊後,執行該刪除授權憑證指令,以刪除儲存於該使用端裝置之一授權憑證。 The method for logging in an online banking account as described in claim 1 further includes the following steps: after receiving the invalidation status information, the using device performs the delete authorization credential instruction to delete the device stored in the user device. An authorization credential. 如申請專利範圍第1項所述之網路銀行帳戶的登入方法,其中該帳戶管理伺服器接收該失效狀態資訊的步驟之後,更包括下列步驟:傳送一註銷授權憑證請求至該憑證管理中心伺服器。 The method for logging in an online banking account according to claim 1, wherein the step of the account management server receiving the invalidation status information further comprises the step of: transmitting a cancellation authorization certificate request to the credential management center servo Device. 如申請專利範圍第1項所述之網路銀行帳戶的登入方法,其中該網路銀行系統更包括一客服中心伺服器,該帳戶管理伺服器自該客服中心伺服器接收該裝置遺失資料。 The method for logging in an online banking account according to claim 1, wherein the online banking system further comprises a customer service center server, and the account management server receives the lost data of the device from the customer service center server. 如申請專利範圍第1項所述之網路銀行帳戶的登入方法,其中該帳務中心伺服器係將該使用端裝置對應之該授權憑證自一使用中狀態變更為該失效狀態。 The method for logging in to an online banking account according to claim 1, wherein the accounting center server changes the authorization credential corresponding to the user device from an in-use state to the invalid state. 一種網路銀行系統,用以執行一網路銀行帳戶的登入方法,該網路銀行系統透過網路與一使用端裝置及一憑證管理中心伺服器連接,該網路銀行系統包括:一帳戶管理伺服器,透過網路與該使用端裝置及該憑證管理中心伺服器連接,該帳戶管理伺服器包括一掛失作業模組及一登入作業模組,該掛失作業模組自另一使用端裝置接收一裝置遺失資料,並傳送至該帳務中心伺服器,該登入作業模組自該使用端裝置接收一登入帳戶請求,並傳送一查核帳戶請求;以及一帳務中心伺服器,與該帳戶管理伺服器電性連接,接收該查核帳戶請求,該帳務中心伺服器包括一狀態變更模組及一查核模組,該狀態變更模組接收該裝置遺失資料,並依據該裝置遺失資料變更該使用端裝置對應之該授權憑證至一失效狀態,該查核模組查核該使用端裝置所對應之一授權憑證的狀態,並傳送一失效狀態資訊至該帳戶管理伺服器,該帳戶管理伺服器傳送該失效狀態資訊及一刪除授權憑證指令至該使用端裝置。 An online banking system for performing an online banking account login method, the online banking system is connected to a user terminal device and a credential management center server through a network, the online banking system comprising: an account management system The server is connected to the user device and the credential management center server through a network, and the account management server includes a report loss operation module and a login operation module, and the report loss operation module is received from another use end device. A device loses the data and transmits it to the account center server, the login operation module receives a login account request from the user device, and transmits a check account request; and a account center server, and the account management The server is electrically connected, and receives the check account request, the account center server includes a state change module and a check module, and the state change module receives the lost data of the device, and changes the use according to the lost data of the device. The authorization device corresponds to the authorization certificate to a failure state, and the verification module checks the authorization certificate corresponding to the one of the use device State, and sends a failure status information to the account management server, the management server transmits the account status information, and a failure to delete command to the authorization ticket end use device. 如申請專利範圍第6項所述之網路銀行系統,其中該狀態變更模組將該使用端裝置對應之該授權憑證自一使用中狀態變更為該失效狀態。 The online banking system of claim 6, wherein the state change module changes the authorization credential corresponding to the user device from an in-use state to the invalid state. 如申請專利範圍第6項所述之網路銀行系統,其中該帳戶管理伺服器的該掛失作業模組傳送一註銷授權憑證請求至該憑證管理中心伺服器。 The online banking system of claim 6, wherein the loss management module of the account management server transmits a logout authorization credential request to the credential management center server. 如申請專利範圍第6項所述之網路銀行系統,更包括: 一客服中心伺服器,自該另一使用端裝置接收該裝置遺失訊息後,再傳送該裝置遺失資料至該帳戶管理伺服器。For example, the online banking system described in claim 6 of the patent scope further includes: A customer service center server receives the lost information of the device from the other user terminal device, and then transmits the device lost data to the account management server.
TW106115012A 2017-05-05 2017-05-05 Log-in method for network bank account and netwok bank system apply log-in method thereof TWI651677B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW106115012A TWI651677B (en) 2017-05-05 2017-05-05 Log-in method for network bank account and netwok bank system apply log-in method thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW106115012A TWI651677B (en) 2017-05-05 2017-05-05 Log-in method for network bank account and netwok bank system apply log-in method thereof

Publications (2)

Publication Number Publication Date
TW201843636A TW201843636A (en) 2018-12-16
TWI651677B true TWI651677B (en) 2019-02-21

Family

ID=65431096

Family Applications (1)

Application Number Title Priority Date Filing Date
TW106115012A TWI651677B (en) 2017-05-05 2017-05-05 Log-in method for network bank account and netwok bank system apply log-in method thereof

Country Status (1)

Country Link
TW (1) TWI651677B (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW200943898A (en) * 2006-08-22 2009-10-16 Interdigital Tech Corp Method and apparatus for providing trusted single sing-on access to applications and internet-based services
CN102598577A (en) * 2009-10-23 2012-07-18 微软公司 Authentication using cloud authentication
CN103501292A (en) * 2013-09-24 2014-01-08 长沙裕邦软件开发有限公司 Method and system for achieving data safety protection by using standby mobile phone
TW201428535A (en) * 2012-11-21 2014-07-16 Apple Inc Policy-based techniques for managing access control
CN104009850A (en) * 2014-06-09 2014-08-27 中国联合网络通信集团有限公司 User identity authentication method and system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW200943898A (en) * 2006-08-22 2009-10-16 Interdigital Tech Corp Method and apparatus for providing trusted single sing-on access to applications and internet-based services
CN102598577A (en) * 2009-10-23 2012-07-18 微软公司 Authentication using cloud authentication
TW201428535A (en) * 2012-11-21 2014-07-16 Apple Inc Policy-based techniques for managing access control
CN103501292A (en) * 2013-09-24 2014-01-08 长沙裕邦软件开发有限公司 Method and system for achieving data safety protection by using standby mobile phone
CN104009850A (en) * 2014-06-09 2014-08-27 中国联合网络通信集团有限公司 User identity authentication method and system

Also Published As

Publication number Publication date
TW201843636A (en) 2018-12-16

Similar Documents

Publication Publication Date Title
US11270314B2 (en) Systems and methods for providing notifications to devices
US10936078B2 (en) Account management services for load balancers
US11122028B2 (en) Control method for authentication/authorization server, resource server, and authentication/authorization system
US10673866B2 (en) Cross-account role management
US20200153831A1 (en) Refresh token for credential renewal
US11019068B2 (en) Quorum-based access management
EP3090525B1 (en) System and method for biometric protocol standards
US10116448B2 (en) Transaction authorization method and system
US9053306B2 (en) Authentication system, authentication server, service providing server, authentication method, and computer-readable recording medium
US9083702B2 (en) System and method for providing internal services to external enterprises
US20210136063A1 (en) Systems and methods for identifying suspicious logins
CN111314340B (en) Authentication method and authentication platform
US9584506B2 (en) Server apparatus, information processing method, program, and storage medium
US10484433B2 (en) Virtual communication endpoint services
CN105229987A (en) The initiatively mobile authentication of associating
JP6572750B2 (en) Authentication control program, authentication control device, and authentication control method
US10757089B1 (en) Mobile phone client application authentication through media access gateway (MAG)
JP2018502394A (en) Computer-readable storage medium for legacy integration and method and system for using the same
CN110069909A (en) It is a kind of to exempt from the close method and device for logging in third party system
US10257263B1 (en) Secure remote execution of infrastructure management
TWI651677B (en) Log-in method for network bank account and netwok bank system apply log-in method thereof
TWM547708U (en) Netwok bank system
RU2673018C2 (en) Systems and methods of managing communication endpoints
CN109684818A (en) A kind of server log method for the cross-terminal formula for preventing owner's login password from revealing
US9231930B1 (en) Virtual endpoints for request authentication