CA2894482C - Method and apparatus for the transfer of a money amount by using a two-dimension image code - Google Patents

Method and apparatus for the transfer of a money amount by using a two-dimension image code Download PDF

Info

Publication number
CA2894482C
CA2894482C CA2894482A CA2894482A CA2894482C CA 2894482 C CA2894482 C CA 2894482C CA 2894482 A CA2894482 A CA 2894482A CA 2894482 A CA2894482 A CA 2894482A CA 2894482 C CA2894482 C CA 2894482C
Authority
CA
Canada
Prior art keywords
payment
smartphone
party
authorization
reception
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CA2894482A
Other languages
French (fr)
Other versions
CA2894482A1 (en
Inventor
Marco Cavaterra
Cosmo DI TUCCI
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Publication of CA2894482A1 publication Critical patent/CA2894482A1/en
Application granted granted Critical
Publication of CA2894482C publication Critical patent/CA2894482C/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/10Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models
    • G06Q20/223Payment schemes or models based on the use of peer-to-peer networks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/325Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
    • G06Q20/3255Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks using mobile network messaging services for payment, e.g. SMS
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3274Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3276Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being read by the M-device
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07GREGISTERING THE RECEIPT OF CASH, VALUABLES, OR TOKENS
    • G07G1/00Cash registers
    • G07G1/0036Checkout procedures
    • G07G1/0045Checkout procedures with a code reader for reading of an identifying code of the article to be registered, e.g. barcode reader or radio-frequency identity [RFID] reader
    • G07G1/0081Checkout procedures with a code reader for reading of an identifying code of the article to be registered, e.g. barcode reader or radio-frequency identity [RFID] reader the reader being a portable scanner or data reader

Abstract

The present disclosure concerns a method for transferring a manly amount by using a two-dimension image code. It provides that the registration of the transfer parties affected by a managing entity generates a two-dimension image code containing registration and security data. Moreover, the request of the recipient party to the paying party of the money amount occurs by a two-dimension image code generated on the display of a mobile phone of the recipient party; the payment order of the paying party to the managing entity to pay said money amount comprises the capture of the two-dimension image code from the display of the recipient party and be sending to the managing party of an encrypted SMS message including the data contained in the two-dimension image code, the reception of the encrypted the SMS message by a central server of the managing party, which forwards or not the request of authorization of payment of the money amount. A relevant system is also disclosed. The image code is in some embodiments a QR code (Quick Response code). Both mobile phones can execute the functions of buyer and seller.

Description

METHOD AND APPARATUS FOR THE TRANSFER OF A MONEY
AMOUNT BY USING A TWO-DIMENSION IMAGE CODE
[0001]
FIELD
[0002] Most of the transactions of goods or services occur today by means of bank transfers performed in the bank or "remotely" or by electronic commerce, as well as by devices called POS (Point Of Sale).
100031 As it is known, the POS is a device utilized in the shops, which allows to accept payments by means of credit cards, debit cards and prepaid cards. The devices connected with the elaboration centre of a bank or banks group offering the service, so that the relevant debit on the current account of the enabled subject and the credit on the seller current account are authorized. In the operations with the POS, debit or credit cards can undergo data interceptions and therefore cloning; besides, there are passages from hand to hand which imply that the seller gains knowledge of the personal details of the buyer.
[00041 Japan patent application number JP 2002109421A tries to overcome this drawbacks by providing a money transfer method and relevant system which provide the use of a cellular phone.
[0005] In an embodiment of the method according to the above-mentioned Japan patent application, the POS is a two-dimension code identifying a money amount to be paid on a terminal screen; the mobile phone of the buyer captures, using its camera, the product code from the POS and sends a payment request to the transfer terminal of the bank. The transfer terminal of the bank sends the required bank transfer to the POS and to the mobile phone together with information that the bank transfer has been effected. One understands that with the transfer method and system according to. the above-mentioned patent application, the need of having at disposal an electric network and a fixed telephone network can disappear if one uses the so-called POS GSM/GPRS, which integrate the functions of a POS with those of the mobile phone and is used mainly by shopkeepers who have a necessity to move such as taxi drivers, street vendors or by those who are reached by a telephone line; however, there remains the need of a POS and the use of debit or credit cards, with all the relevant drawbacks.
100061 Owing to the fact that transfer system according to the Japan patent application requires that the money recipient party is provided with a POS, it does not allow to private subjects without a POS to carry out a sale and a corresponding purchase of a good or service. Otherwise, the paying party should be provided with a credit or debit card.
[0007] Document US2008222048 describes a payment system wherein there are information fluxes between three parties of the transaction: the seller (with his POS), the buyer (with his mobile phone), and a server of the payment system (bank or similar). The seller, when he has to carry out a transaction for selling one or more products, requires, by POS, a bar code to the payment system managed by the server. The server sends the bar code to the POS of the seller. At this point, the seller prints and provides it to the buyer, who captures the bar code by a mobile device and sends, by SMS, to the same server. An information exchange begins to verify the identity of the buyer. Once such an identity is verified, the server sends to the seller a notification of effected payment, with which the seller can close the sale and deliver the goods and purchase receipt. This method has the drawback that it needs the use of the POS and occupies the server with many information exchanges, what can be critical in some periods in the year because of the enormous amount of required transactions.
3 OBJECT
100081 An object of the present disclosure is to allow the transfer of a money amount by using a two dimension image code, the transfer having characteristics of efficiency, security and privacy compliancy that cannot be reached with the prior art.
100091 In particular, an object of the present disclosure is to allow the transfer of a money amount between two persons, wherein the seller, i.e.
the one that should be paid, does not have a POS at its disposal.
Moreover, an object of the present invention is to allow the transfer of a money amount between two persons, wherein the buyer does not have a credit or debit card.
SUMMARY
100101 The above-mentioned objects are substantially achieved by the present disclosure that in a first aspect provides a method for transferring a money amount by using a two-dimension image code between a paying party provided with a payment device and a recipient party provided with a reception payment device, comprising:
A. Registration of both paying party and recipient party at a money transfer managing entity on a server, which provides for the management and verification of the paying party and recipient party and is responsible of the authorization to the transfer of money amounts and their payment;
B. Request of the recipient party to the paying party of a money amount, executed between the reception payment device and the payment device;
C. order from the paying party to the money transfer managing entity to pay said money amount to the recipient party, after the insertion of a authorization PIN in the payment device and information communication from the payment device to the server;
D. authorization to the payment from the transfer managing entity to
4 the recipient party, with information communication from the server to the reception payment device;
E. payment of said money amount to the recipient party and sending of a confirmation information of effected money amount transfer to the payment device and reception payment device concerning the effected payment of the money amount, or possible writing off or cancellation of an already effected payment operation;
The method being characterized in that said payment device and said reception payment device are mobile phones, and in that:
- in step B, the recipient party generates a two-dimension image code on the display of the reception payment mobile phone;
¨ in step B, the payment mobile phone of the paying party captures the two-dimension image code from the display of the recipient party mobile phone;
- in step C, the paying party sends to the server via the payment mobile phone an encrypted authorization SMS message, the encrypted authorization SMS message including data contained in the two-dimension image code, comprising the indication of said money amount, - in step D, the server receives said encrypted authorization SMS
message and authorizes or not the payment of the money amount, the recipient party mobile phone of the recipient party restricting itself in step B to the visualization of said two-dimension code, without sending any relevant information to the money transfer managing entity.
[0011] According to an aspect of the invention, in case of authorization to the payment in step D, the server sends a confirmation of effected payment by means of two confirmation SMS, one directed to the payment mobile phone and the other one directed to the reception payment mobile phone.
[0012] According to an aspect of the invention, the registration of step A of the paying party and the recipient party on the server of the money transfer managing entity includes the generation by the server of relevant unique codes called user-ID and assigned to the same paying party and recipient party, the definition of personal details data, account data, payment modes and payment limits, the type of user account, Le. prepaid or credit card, the request of a ID-SMS utilized for validating the
5 authorization SMS during the authorization to the payment, definition of an alteration code to generate an authorization PIN and an alteration method used to encrypt a protection key for the PIN, generation of a random key to protect the PIN, and definition of a data structure of the two-dimension image code of step B
[0013] According to an aspect of the invention, step D includes the identification of the user who accesses the service on the basis of the information given in step B.
[0014] According to an aspect of the invention, the writing off or cancellation of the last effected transaction occurs upon request of the paying party by the generation of a QR-code provided to the recipient party, which confirms the writing off or cancellation by authorization PIN, and wherein the two confirmation SMS confirm the effected writing off, guaranteeing to both parties the execution of the operation and the subsequent the restoration of the previous situation in the respective accounts.
[0015] According to an aspect of the invention, the two-dimension image code generated on the display of the reception payment mobile contains the user-ID retrieved from a "personal details" archive as well as information retrieved from an "operations" archive residing on the reception payment mobile phone.
[0016] According to an aspect of the invention, the two-dimension image code presented by the reception party mobile phone and captured by the payment mobile phone, provides as guarantee of the privacy the only user-ID of the recipient party, an operation number, the money amount, the payment mobile phone number.
[0017] According to an aspect of the invention, the payment mobile phone visualizes on the display the transaction money amount and requests the
6 typing of the authorization PIN, extracts from a "personal details" archive the user-ID= of the paying party, extracts from a "keys" archive the encryption key for the authorization PIN, encrypts the authorization PIN, composes an authorization SMS message and sends it to the server.
[0018] According to an aspect of the invention, the only payment mobile phone receives a SMS of refusal to effect the payment in case of a wrong PIN, blocked user profile, exceeding of an expense limit, funds shortage, lack of authorization from a bank and/or credit card system.
[0019] According to an aspect of the invention, the two-dimension image code is a QR code, "Quick response code".
[0020] According to an aspect of the invention, the payment of the money amount by remote transactions is possible, i.e. when the payment mobile phone is far away from the reception payment mobile phone, and wherein the paying party activates the transaction unilaterally by choosing among the receipt parties in a list, or by typing the mobile telephone number or the ID of the recipient party, the money amount to be credited, the payment reason and the authorization PIN.
[0021] According to another, further aspect of the invention, it is provided a system for transferring a money amount between a paying party and a recipient party by using ,a two-dimension image code, wherein a payment device of the paying party and a reception payment device of the recipient party are provided, as well as a server of money transfer managing entity, wherein:
- said payment device and reception payment device are mobile phones both provided with a display and at least a camera, - on the reception payment mobile phone a recipient party software module is installed, which is set up to create a two-dimension bar code;
- on the payment mobile phone a paying party software module is installed, which is set up to analyze said two-dimension image code and to send to said server a SMS for authorization to payment of the money amount;
7 - on the server of the money transfer managing entity there is:
o a managing software module which allows registration and management of new users, blocking and unblocking of transaction service, management of security parameters values and encryption keys, and manages a payment authorizing step, as well as a module managing the reception and sending of SMS, by means of a connection to a SMS forward device;
o a module managing the information exchange with gateways of a bank and/or credit card system;
said paying party software module, said recipient party software module and said managing software module being set up to execute the steps of the method according to an aspect of the invention.
[0022]
According to an aspect of the invention, said paying party software module and said recipient party software module are present on both reception payment mobile phone and payment mobile phone, making both mobiles phones adapted to execute the role of paying party or recipient party indifferently.
[0022a] According to one aspect of the present invention, there is provided a method for transferring a money amount, by using a two-dimensional image code, between a paying party provided with a payment smartphone and a recipient party provided with a reception payment smartphone, wherein a recipient party program module and a paying party program module are installed on the payment smartphone and the reception payment smartphone, and wherein the method comprises: A.
registration of both the paying party and the recipient party at a money transfer managing entity on a server, which provides for the management and verification of the paying party and the recipient party and is responsible for the authorization of the transfer of money amounts and their payment; B. request of the recipient party to the paying party of a money amount, executed between the reception payment smartphone and the payment smartphone, wherein in step B: (i) the reception 7a payment smartphone generates, without communicating with the server, the two-dimensional image code and visually displays the two-dimensional image code on a display of the reception payment smartphone; (ii) the reception payment smartphone provides only a visualization of the two-dimensional image code to the payment smartphone; (iii) the payment smartphone captures, by said paying party program module installed on said payment smartphone, the two-dimensional image code from the display of the reception payment smartphone; C. order from the paying party to the money transfer managing entity to pay said money amount to the recipient party, after the insertion of an authorization PIN in the payment smartphone and information communication from the payment smartphone to the server, wherein the payment smartphone sends, to the server, an encrypted authorization SMS message, the encrypted authorization SMS message including data contained in the two-dimensional image code, the data comprising the indication of the money amount; D.
authorization of the payment from the transfer managing entity to the recipient party, with information communication from the server to the reception payment smartphone, wherein step D includes the server receiving the encrypted authorization SMS message and determining whether to authorize the payment of the money amount; E. payment of said money amount to the recipient party and sending of a confirmation information of effected money amount transfer to the payment smartphone and reception payment smartphone concerning the effected payment of the money amount, or possible writing off or cancellation of an already effected payment operation.
[0022b] According to another aspect of the present invention, there is provided a system for transferring a money amount between a paying party and a recipient party by using a two-dimensional image code, wherein a payment smartphone of the paying party and a reception payment smartphone of the recipient party are provided, as well as a server of a money transfer managing entity, wherein: said payment smartphone and said reception payment smartphone are both provided with a display and at least a camera; on the reception payment smartphone a recipient party software module is installed, which is set up to create the two-dimensional image 7b code; on the payment smartphone a paying party software module is installed, which is set up to analyze said two-dimensional image code and to send to said server a SMS for authorization of payment of the money amount; on the server of the money transfer managing entity there is: a managing software module which allows registration and management of new users, blocking and unblocking of transaction service, management of security parameters values and encryption keys, and manages a payment authorizing step, as well as a module managing the reception and sending of SMS, by means of a connection to a SMS forward device; a module managing the information exchange with gateways of a bank and/or credit card system; said paying party software module, said recipient party software module and said managing software module being set up to execute the steps of the method as described herein.
BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Further technical features and effects of the present disclosure will appear in greater detail in the following description, which is given by way of illustration and not by way of limitation, of aspects of the above method and system for transferring a money amount by using a two-dimension image code, with reference to enclose drawings, wherein:
[0024] Fig. 1 is a schematic diagram of the components of the system for the transfer of a money amount according to an aspect of present disclosure;
[0025] Fig. 2 is a block diagram of the user registration step in the method according to an aspect of the present disclosure;
[0026] Fig. 3 is a block diagram of the transfer of a money amount between users in the method according to an aspect of the present
8 PCT/IT2012/000386 disclosure;
[0027] Fig. 4 is a block diagram of the user registration step in the mobile phone in the method according to an aspect of the present disclosure;
[0028] Fig. 5 is a block diagram of the selling step in the mobile phone of the recipient party in the method according to an aspect of the present disclosure; and [0029] Fig. 6 is a block diagram of the buying step in the mobile phone of the paying party in the method according to one aspect of the present disclosure;
[0030] Fig. 7(a) and Fig. 7(b) show respectively figure 3 of US2008222048 and a diagram of an aspect of the present disclosure.
[0031] In the figures, equal or similar reference numbers have be used to indicate equal or similar parts.
DETAILED DESCRIPTION
[00321 The method for the transfer of a money amount by using a two-dimension image code that allows two mobile phones to perform a selling/buying transaction or a fund transfer, in any place covered by a mobile telephone service, between accounts registered at a managing authority. The two mobile phones are registered on a control server wherein a suitable software module is installed; on the two mobile phones a modular software application has been installed beforehand, which is described in the following. The two mobile phones can perform indifferently and alternatively the selling or buying function, so that there will be a recipient party and a paying party; and therefore, the two mobile phones have the same module program application installed thereon. The privacy is guaranteed by the only use of a user unique identifier, that cannot traced back to the personal data of the user itself. To carry out the service, the use of further, additional software and hardware resources is .. provided, which are already in the market and described in the following.
[0033] Making reference to Fig. 1, which is a schematic view of the
9 components for the system for the transfer of a money amount according to the present disclosure, it is indicated by 1 a computer or any other device that can be used for the web surfing and is provided with a display, such as a laptop, notebook, handheld computer, tablet computer, a smartphone.
10034] With reference 2 a central server is indicated, which is placed at the managing entity end, the managing entity managing user accounts and in general the money transfers. On the central server 2, a suitable software application is installed, as described in the following. In the World Wide Web indicated by reference 5, a SMS Gateway 8 is provided, which allows the reception and transmission of a SMS. Alternatively to SMS Gateway 8, a SMS transmitter/receiver can be provided, i.e. a hardware device that can be connected to the central server 2. To execute the method according to present disclosure, a mobile telephone network indicated by reference 9 is needed, wherein mobile phones provided with video camera or even a simple camera operate, as the one indicated generically with =
reference 4 in Fig. I. On the two mobile phones, a software application is installed which is described in the following and allows the access to the companies of the credit cards by a credit card Gateway 6, a further software interfacing the bank system by a bank system Gateway 7, and the World Wide' Web 5. Still in Fig. 1, with reference 3 is indicated a 2-dimension image code, in the particular case a QR code (Quick Response Code).
100351 The software applications developed exactly for the execution of the method according to the present disclosure are substantially:
[0036] A central module residing on the central server 2, which allows the registration and the users management, as well as blocking and unblocking of the service, management of the security parameters and encryption keys, and the authorization steps;
[0037] A SMS module residing on the central server 2, which manages the reception and transmission of necessary SMS messages through mobile telephone network 9, by means of information exchange with the SMS

transmission module or SMS Gateway 8;
100381 A mobile module residing on the mobile phone 4, which allows the capture and management of the two-dimension image code, utilized in the registration, selling and buying steps, which allows moreover the 5 encryption and decryption of private data and the management of the SMS;
[0039] A bank module, residing on the central server 2, which manages the information exchange with the credit card Gateway 6 and, respectively, with the bank system Gateway 7.
10 100401 The central module comprises a part dedicated to the management and verification of the user and a part relevant to the authorization step for the purchase or found transfer. The central module comprises also a SMS
management module, that interfaces with at least a modem for the sending of SMS, and a bank module which manages the transaction according to the paying party request.
[0041] One makes now reference to Fig. 2, which is a block diagram of the user registration step in the method according to the present disclosure.
The request coming from computer 1 or other user device, which registered itself to the service, reaches the management central server 2 through the World Wide Web 5. It comprises the following steps:
- generation of a unique code called user-ID;
- definition of the in personal data;
- definition of the account data and payment modes;
- definition of the limit of the single transaction;
- user account type (prepaid or credit card);
- main mobile telephone number associated with the service;
- request of an ID-SMS use for validating the SMS during the authorization step;
- request of an alteration code and an alteration method chosen by the user, which will be used to create the PIN of the payment transactions (authorization PIN) or of funds transfer and to encrypt the PIN encryption key;
11 - providing a further PIN utilized exclusively during the installation of the application on the mobile phone;
- generation of a random key to protect the PIN;
- definition of the two-dimension image code 3 containing the registration data.
[0042] Briefly, the central server 2 registers the new user and generates a key to encrypt the PIN for payment transaction, by a two-dimension image code 3. Alternatively, the data will be downloaded on the mobile phone together with the application, comprised in a security archive exactly utilized for their installation.
10043] The data are typed in a secure web environment, and the two:
dimension image code 3 is sent through the World Wide Web 5 again to the user and to the screen of his computer 1, in order that it can be captured directly by the video camera or camera of the mobile phone 4 of the (other) user. The application, i.e. the mobile phone software module on the mobile phone 4 of the user, decrypts and registers the received data.
The data cannot be intercepted since the not visible. Once the image is captured, the keying of the code and alteration method on the mobile phone is requested; in such a way, the user who has input the information on the central server 2 is only able to acquire them correctly on the mobile phone. By using the mode with security archive, a further numerical code will be provided that can be used only one time and will allow the activation of the application.
100441 The user, by connecting to the webpage of server, can decide autonomously, for as many times as he wishes, to block and unblock the account and the relevant profile, to change the security codes and the entered data. He can moreover look through the balance of his account and the list of the carried-out operations.
[0045] With reference to Fig. 3, which is a block diagram of the operation of money amount transfer between users according to the present disclosure, the authorization step during the sale or purchase step, or generically the step of transferring a money amount between two users is
12 illustrated.
[0046] With .reference 41, the mobile phone of a first user, cellular or recipient party is indicated, whilst with 42 to mobile phone of a second user, buying or paying party is indicated.
[0047] The seller sets the purchase price on his mobile phone 41 and by means of his mobile software module generates the two-dimensional image code containing his identifier and the amount that is visualized on the display of the mobile phone 41.
100481 The buyer captures the two-dimension image code by the camera of his mobile phone 42, whereon the same mobile software module is installed. The money amount of the transaction is visualized and the authorization PIN needed for the authorization is required. In the mode with security archive, the verification of the authorization PIN provides that the authorization PIN travels within the SMS sent by the buyer, the data are all encrypted of course. An encrypted SMS is then sent from the mobile phone 42 through the mobile telephone network 9.
[0049] The central server 2 receives the request by SMS from the mobile phone 42, decrypts the SMS and forwards the authorization request to the bank Gateway 7 or credit card Gateway 6, depending on the gateway specified by the user during the registration step, or it authorizes locally if the account type is a prepaid account.
100501 More in detail, by verification of the format of the received data, the software on the central server 2 accesses the user archive. If the profile is blocked, it denies the service; otherwise the software module on the client side retrieves the security parameter values, and decrypts and verifies the authorization PIN (if the remote verification is provided).
[0051] In case of negative issue of the authorization PIN verification, it sends a SMS through the SMS module. The SMS contains the caption "wrong PIN" and at the third attempt, it blocks the account.
100521 In case of a positive issue of the authorization PIN verification, in presence of prepaid account, the software on the central server 2 verifies the expense limit and the availability of the account, and authorizes or not
13 the payment on the basis of the carried-out controls.
[0053] In case of positive issue of the authorization PIN verification, in presence of an account that is external or associated to a credit or debit card, it forwards the request through the bank module to the Gateway 7 of the bank system that carries out the payment, receives the response and sends a positive or negative SMS on the basis of the received response.
[0054] The transactions are univocally and progressively numbered and stored, as well as verifications are carried out; possible anomalies trigger the temporarily block of the service.
.. [0055] Once the operation is carried out, the central server 2 sends two SMS, one to the mobile phone 41 of the seller and the other one to the mobile phone 42 of the buyer, for confirming or denying the transaction.
[0056] With the same modes of the authorization step, the writing off or the cancellation of the last carried-out operation is provided. The initiative starts always from the buyer which produces a suitable bar code and is confirmed by the seller by means of the authorization PIN and the sending of an encrypted SMS. The arrival of the two SMS indicating the effected writing off guarantees to both parties the execution of the operation and the subsequent restoration of the previous situation on both accounts.
[0057] It is provided the reception of a service block/restoration SMS, on the remote initiative of the client.
100581 The SMS module acquires from SMS reception device (the above-mentioned at least a modem, for example) or from the Gateway 8 the incoming messages and writes them in a "requests" archive, reads from "responses" archive the outgoing messages and forwards them to be SMS sending device (the above-mentioned at least a modem, for example) or to the Gateway 8.
[0059] The bank module receives from the Gateway 7 of the bank system the top-up orders, normally bank transfer orders, in the prepaid user .. account, forwards the authorization requests in case of an account associated to credit or debit cards to the gateway 6 of the credit card companies or bank system, receives the authorizations or refusals to the
14 service execution.
[0060] Making now reference to Fig. 4, which illustrates the registration data acquisition step for the user registration to the service, as contained in the QR-code, and Fig. 5 and 6, which illustrate the sale operation in the mobile phone of the recipient party and, respectively, the operation of purchase in the mobile phone of the paying party are shown according to another aspect of the method according to the present disclosure.
[0061] For the user registration, the user acquires on the display 10 of the mobile phone 41 or 42 the two-dimension image code 3 from the software to module of the central server 2. The registration is carried out, wherein the alteration number (arbitrarily chosen by the user) and the alteration method (that the user chooses in a web page dedicated to the registration to the service) are decrypted and saved in a "personal details" archive 14 and a "keys" archive 15.
[0062] The mobile phone 41 (Fig. 5) of the seller requires in block 17 the typing of the money amount that he should receive, generates the image code containing the user-ID retrieved from the "personal details" archive 14, besides some information that characterize the transaction and are retrieved from a "operations" archive 16 and prepares in the sale block 12 the image prepared on the display 10 of the mobile phone 41.
[0063] The mobile phone 42 of the buyer, by means of video camera or camera, captures the image visualized on the mobile phone 41 of the seller, extracts from it the user-ID of the seller, the operation number and the money amount (charge), visualizes on the display the charge of the operation and requires the typing of the authorization PIN in purchase block 13, extracts from the "personal details" archive 14 the user-ID of the buyer, extracts from the "keys" archive 15 the decryption key of the authorization PIN. In the mode with security archive, the verification of the authorization PIN is carried out on the mobile phone, otherwise it is encrypted and sent with the SMS of authorization request. Then, it composes the SMS message and sends it to the central service 2.
[0064] Both the mobile phones 41 and 42 receive in any case a SMS that = WO

confirms or refuses the required operation.
[0065] The only buyer mobile phone 42 receives a SMS in the following cases: wrong PIN, blocked profile, blocked account, exceeding of the expense limit, fund shortage, absence of authorization by the bank system 5 and credit card systems.
[0066] In case of wrong PIN, a new typing is requested, for a total of three attempts, with subsequent sending of a new SMS. At the end of the three attempts, there is a blocking of the user workability in the central server.
[0067] With the same modes of the authorization step, the writing off or 10 cancellation of the last carried-out operation is provided, the initiative starts always from the buyer, who produces a suitable bar code and is confirmed by the seller by PIN and a SMS to the server. The reception by the two mobile phones of the two SMS of effected writing off guarantees to both parties the execution of the operation and the subsequent restoration
15 of the preceding situation on the accounts of both ones.
[0068] Both the mobile phones can, by using a provided function, send a SMS to block or unblock the service. They can moreover interrogate the transactions archive and know the balance or delays of the effected operations, both for purchases and sales.
[0069] In an aspect of the disclosure, it is possible the function of remote payment. It will be activated in one-sided way by the paying party, by choosing among the recipient parties in a list, or by typing the telephone number or the ID of the recipient party, the charge to be credited, the reason for payment and the PIN. The sending of the request SMS and the notification of the operation (always by SMS) will occur according to the modes already described for the other embodiments.
100701 One understands technical effects of the present disclosure. Once two users are registered at a money transfer managing entity, a transfer can occur between one user and another one, which utilizes the mobile telephone network, a mobile phone provided with video camera or camera and the use of a two-dimension image code. Even if in the foregoing and in the drawings a QR code is cited and shown, another type of two-PCT/1T2012/000,386 =
16 dimension image code can be used alternatively. The transmission of this code containing all the data for a secure transaction is sufficient to make it possible, without the availability of a POS of the recipient party and without the presentation of a credit card of the paying party.
[0071] This new system composed by a server engine and two mobile phones, leads to dematerialization of the POS, which represented a constraint for the utilization of the credit cards.
[0072] By this new system/method, the POS and the cards can be completely substituted and each customer can, with an only device, carry out the functions of POS (sale) and card (purchase). Moreover, the payment tool is in the hands of the paying party (buyer), whilst with the credit card the seller has the payment tool (the same credit card) for the payment itself.
[0073] All this would have never been possible with the POS and credit cards, since these are systems that are not designed to allow a different use.
[0074] By the present system money transactions ever occurs, however the today's barriers and constraints disappear, which oblige two entities (seller and buyer) to have POS and card close to each other to effect an electronic money transaction.
[0075] It is therefore clear that it is easy for the customer to own a card, whilst it is more difficult to have a POS. This is the reason for which one frequently uses cash money, for goods and/or services purchases.
[0076] Since the mobile phone use used by all persons for other aims, this new system is well suited to substitute both POS and card for each customer. All this is not possible in the prior art, wherein the system is composed by a POS, a mobile phone and a payment engine. In the prior art, credit cards, debit cards, current accounts have been dematerialized and regrouped in an only device (mobile phone), however the presence of the POS remains still a constraint for the whole system in the prior art.
[0077] In the prior art, a rigidity of the system remains, because each actor of the process (buyer and seller) can play an only role in the transaction.

=
17 Such a constraint can be removed only if the customer moves, bringing with himself mobile phone and POS; all this appears unlikely.
[0078] From the above concepts, one understands the importance of the present disclosure with respect to what is available on the market till today.
[0079] Indeed, making reference to figures 7(a) and 7(b), one observes the difference of the system of above-mentioned US2008222048. In the case of the present disclosure, the seller communicates only with the buyer; the latter is the only one that sends data to the central server. In such a way, the overload of the server is avoided, because for each transaction and only message is sent to the server, instead of the two messages of US2008222048, with the additional advantage to be able to use a mobile phone instead of the POS.
[0080] Form the above concepts, one understands the importance of the present disclosure with respect to what is today available on the market.
[0081] A number of embodiments of the disclosure have been described.
Nevertheless, it will be understood that various modifications can be made without departing from the spirit and scope of the present disclosure.
Accordingly, other embodiments are within the scope of the following claims.

Claims (13)

CLAIMS:
1. A
method for transferring a money amount, by using a two-dimensional image code, between a paying party provided with a payment smartphone and a recipient party provided with a reception payment smartphone, wherein a recipient party program module and a paying party program module are installed on the payment smartphone and the reception payment smartphone, and wherein the method comprises:
A. registration of both the paying party and the recipient party at a money transfer managing entity on a server, which provides for the management and verification of the paying party and the recipient party and is responsible for the authorization of the transfer of money amounts and their payment;
B. request of the recipient party to the paying party of a money amount, executed between the reception payment smartphone and the payment smartphone, wherein in step B:
(i) the reception payment smartphone generates, without communicating with the server, the two-dimensional image code and visually displays the two-dimensional image code on a display of the reception payment smartphone;
(ii) the reception payment smartphone provides only a visualization of the two-dimensional image code to the payment smartphone;
(iii) the payment smartphone captures, by said paying party program module installed on said payment smartphone, the two-dimensional image code from the display of the reception payment smartphone;
C. order from the paying party to the money transfer managing entity to pay said money amount to the recipient party, after the insertion of an authorization PIN in the payment smartphone and information communication from the payment smartphone to the server, wherein the payment smartphone sends, to the server, an encrypted authorization SMS message, the encrypted authorization SMS message including data contained in the two-dimensional image code, the data comprising the indication of the money amount;
D. authorization of the payment from the transfer managing entity to the recipient party, with information communication from the server to the reception payment smartphone, wherein step D includes the server receiving the encrypted authorization SMS message and determining whether to authorize the payment of the money amount;
E. payment of said money amount to the recipient party and sending of a confirmation information of effected money amount transfer to the payment smartphone and reception payment smartphone concerning the effected payment of the money amount, or possible writing off or cancellation of an already effected payment operation.
2. The method according to claim 1, wherein upon authorization of the payment in step D, the server sends a confirmation of effected payment by means of two confirmation SMS messages, one directed to the payment smartphone and the other one directed to the reception payment smartphone.
3. The method according to claim 1, wherein the registration of step A of the paying party and the recipient party on the server of the money transfer managing entity includes generation, by the server, of relevant unique codes called user-ID and assigned to the same paying party and recipient party, the definition of personal details data, account data, payment modes and payment limits, the type of user account, which is prepaid or credit card, the request of a ID-SMS utilized for validating the authorization SMS during the authorization of the payment, definition of an alteration code to generate an authorization PIN and an alteration method used to encrypt a protection key for the PIN, generation of a random key to protect the PIN, and definition of a data structure of the two-dimensional image code of step B.
4. The method according to claim 1, wherein step D includes the identification of the user who accesses the service on the basis of the information given in step B.
5. The method according to claim 2, wherein the writing off or cancellation of the last effected transaction occurs upon request of the paying party by the generation of a QR-code provided by the server to the recipient party, which confirms the writing off or cancellation by authorization PIN, and wherein the two confirmation SMS
messages confirm the effected writing off, guaranteeing to both parties the execution of the operation and the subsequent restoration of the previous situation in the respective accounts.
6. The method according to claim 1, wherein the two-dimensional image code generated on the display of the reception payment smartphone contains a user-ID
retrieved from a "personal details" archive as well as information retrieved from an "operations" archive residing on the reception payment smartphone.
7. The method according to claim 1, wherein the two-dimensional image code visually displayed by the reception payment smartphone and captured by the payment smartphone, provides as guarantee of privacy the only user-ID of the recipient party, an operation number, the money amount, and the reception payment smartphone number.
8. The method according to claim 7, wherein the payment smartphone visualizes on the display the transaction money amount and requests the typing of the authorization PIN, extracts from a "personal details" archive the user-ID
of the paying party, extracts from a "keys" archive the encryption key for the authorization PIN, encrypts the authorization PIN, composes an authorization SMS message and sends it to the server.
9. The method according to claim 1, wherein only the payment smartphone receives a SMS of refusal to effect the payment in case of a wrong PIN, blocked user profile, exceeding of an expense limit, funds shortage, lack of authorization from a bank and/or credit card system.
10. The method according to claim 1, wherein the two-dimensional image code is a Quick Response (QR) code.
11. The method according to claim 1, wherein the payment of the money amount by remote transactions is possible, when the payment smartphone is far away from the reception payment smartphone, and wherein the paying party activates the transaction unilaterally by choosing among the recipient parties in a list, or by typing the smartphone number or the ID of the recipient party, the money amount to be credited, the payment reason and the authorization PIN.
12. A system for transferring a money amount between a paying party and a recipient party by using a two-dimensional image code, wherein a payment smartphone of the paying party and a reception payment smartphone of the recipient party are provided, as well as a server of a money transfer managing entity, wherein:
said payment smartphone and said reception payment smartphone are both provided with a display and at least a camera;
on the reception payment smartphone a recipient party software module is installed, which is set up to create the two-dimensional image code;
on the payment smartphone a paying party software module is installed, which is set up to analyze said two-dimensional image code and to send to said server a SMS for authorization of payment of the money amount;
on the server of the money transfer managing entity there is:
a managing software module which allows registration and management of new users, blocking and unblocking of transaction service, management of security parameters values and encryption keys, and manages a payment authorizing step, as well as a module managing the reception and sending of SMS, by means of a connection to a SMS forward device;
a module managing the information exchange with gateways of a bank and/or credit card system;
said paying party software module, said recipient party software module and said managing software module being set up to execute the steps of the method according to claim 1.
13. The system according to claim 12, wherein said paying party software module and said recipient party software module are present on both the reception payment smartphone and the payment smartphone, making both the reception payment smartphone and the payment smartphone adapted to execute the role of paying party or recipient party indifferently.
CA2894482A 2012-12-19 2012-12-19 Method and apparatus for the transfer of a money amount by using a two-dimension image code Active CA2894482C (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/IT2012/000386 WO2014097328A1 (en) 2012-12-19 2012-12-19 Method and apparatus for the transfer of a money amount by using a two-dimension image code

Publications (2)

Publication Number Publication Date
CA2894482A1 CA2894482A1 (en) 2014-06-26
CA2894482C true CA2894482C (en) 2020-12-29

Family

ID=47741221

Family Applications (1)

Application Number Title Priority Date Filing Date
CA2894482A Active CA2894482C (en) 2012-12-19 2012-12-19 Method and apparatus for the transfer of a money amount by using a two-dimension image code

Country Status (3)

Country Link
AU (2) AU2012397548A1 (en)
CA (1) CA2894482C (en)
WO (1) WO2014097328A1 (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105279469A (en) * 2015-09-15 2016-01-27 重庆智韬信息技术中心 Two-dimension code oriented authorization method
CN106790051A (en) * 2016-12-19 2017-05-31 杭州信雅达数码科技有限公司 A kind of Mobile banking's security protocol based on MB connections
CN108269088A (en) * 2018-01-25 2018-07-10 信利光电股份有限公司 A kind of method of mobile payment and mobile payment device
CN113194419B (en) * 2021-04-30 2022-04-22 中国银行股份有限公司 User locking method and system based on 5G message and face recognition

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002109421A (en) 2000-09-28 2002-04-12 Denso Corp Payment method and payment system using portable terminal
US20070244811A1 (en) * 2006-03-30 2007-10-18 Obopay Inc. Mobile Client Application for Mobile Payments
US8935187B2 (en) 2007-03-07 2015-01-13 Playspan, Inc. Distributed payment system and method
JP2008225832A (en) * 2007-03-13 2008-09-25 Oki Electric Ind Co Ltd Electronic money issue system, electronic money issue method, electronic money issue management system, electronic money issue management method, apparatus for outputting identification number for electronic money issue, and method for outputting identification number for electronic money issue
EP2073160A1 (en) * 2007-12-18 2009-06-24 Kienzle Argo Taxi International GmbH Transmission of encoded information from a terminal to a central server via a mobile device by way of a multidimensional barcode
EP2088548A1 (en) * 2008-02-11 2009-08-12 Accenture Global Services GmbH Point of sale payment method
EP2128809A1 (en) * 2008-05-30 2009-12-02 Luc Stals Server device for controlling a transaction, first entity and second entity
BRPI0805406A2 (en) * 2008-12-23 2010-05-25 Infoserver S A authentication system by sending 2d images
SG185750A1 (en) * 2010-05-25 2013-01-30 Paycash Labs Ag Method for producing a transaction signal
ITRM20110391A1 (en) * 2011-07-22 2013-01-23 Marco Cavaterra METHOD AND EQUIPMENT FOR THE TRANSFER OF A MONEY MONEY WITH THE USE OF A TWO-DIMENSIONAL IMAGE CODE

Also Published As

Publication number Publication date
AU2019226138A1 (en) 2019-09-26
WO2014097328A1 (en) 2014-06-26
AU2019226138B2 (en) 2021-01-07
CA2894482A1 (en) 2014-06-26
AU2012397548A1 (en) 2015-06-11
WO2014097328A8 (en) 2014-07-17

Similar Documents

Publication Publication Date Title
US9552577B2 (en) Method and apparatus for the transfer of a money amount by using a two dimension image code
AU2019226138B2 (en) Method and apparatus for the transfer of a money amount by using a two-dimension image code
CN104838399B (en) Remote transaction is authenticated using mobile device
US7231372B1 (en) Method and system for paying for goods or services
WO2016164648A1 (en) Methods and systems for using a mobile device to effect a secure electronic transaction
US20100223187A1 (en) System and method for electronic payment, and server, communication terminal and program therefor
CN105308898B (en) For executing system, the method and apparatus of password authentification
CN101697220A (en) Systems and methods for secure pin-based transactions
US10713679B1 (en) Offline payment processing
KR101136509B1 (en) Wireless terminal payment system using payer's pre permission and method thereof
GB2496595A (en) Smart phone payment application using two-dimensional barcodes
KR20160064061A (en) Payment system and payment method, additional service, url-nfc payable card and server
KR20070097874A (en) Service system for instant payment utilizing a wireless telecommunication device
JP2011044151A (en) Method and system for safe payment by portable terminal
KR20060093575A (en) Method for settling using a portable phone
KR101439136B1 (en) Payment channel management system
KR20080009242A (en) Service system for instant payment utilizing a wireless telecommunication device
US20180183805A1 (en) System and method of authorization of simple, sequential and parallel requests with means of authorization through previously defined parameters
KR101511194B1 (en) METHOD AND SYSTEM OF MANAGING PAYMENT CHANNEL AND Recording Medium
KR101344465B1 (en) System and method for trading gift certificates
KR20020006189A (en) Method and system for notifying transaction and billing process using a card
KR20180047244A (en) Method for Simple Payment Using Virtual ARS Number
KR20000072682A (en) System and method for issuing and paymenting virtual card based on certification
KR20150105160A (en) Method and apparatus for check before trading for providing electronic payment and banking service using smart device and secure element
KR101548200B1 (en) charge-type electronic commerce methods using the mobile-push

Legal Events

Date Code Title Description
EEER Examination request

Effective date: 20171212