Method and system for enterprise to pay through bank
[ technical field ] A method for producing a semiconductor device
The invention relates to a method and a system for paying by an enterprise through a bank.
[ background of the invention ]
The enterprise security certificate is a high-level security tool for transacting online banking business provided by a bank for enterprise customers, and specifically comprises a common card certificate, a bank card certificate, a gold card certificate, a USBKey certificate and a disk certificate.
At present, a method for paying by an enterprise through a bank is as follows: before the enterprise system (such as financial software) sends each payment request to the bank system, firstly, workers of each relevant approval post are required to carry out approval and signature according to a specified flow, and after the approval is finished, the approved payment request and the enterprise security certificate are sent to the bank system; after receiving the payment request and the enterprise security certificate, the bank verifies the enterprise certificate, and if the enterprise certificate is correct, the payment request of the enterprise is met. If the enterprise security certificate of the enterprise is stolen in the network, the transaction of the bank account can be stolen. Therefore, the above method is relatively unsafe. In addition, according to the method, the approval process and the post signature information of the internal payment of the enterprise are not protected externally.
[ summary of the invention ]
The technical problem to be solved by the invention is to provide a method for paying by an enterprise through a bank, which has relatively high safety and can externally protect the approval process and the post signature information of the enterprise.
The technical problem is solved by the following technical scheme:
a method for enterprise payment through bank is characterized in that the method comprises an enterprise system sending step and a bank system verifying step; wherein,
the enterprise system sending step specifically comprises:
101) recording a payment request, and setting a corresponding standard table, wherein the standard table records the signature sequence (namely the approval process) of a plurality of approval positions and a plurality of signature information corresponding to the plurality of approval positions;
102) sending the set standard table to a bank system;
103) receiving the operation of signing by using the respective signing certificate of the plurality of approval stations, and generating a log table, wherein the log table records the signing sequence of the plurality of approval stations and the signing information of the plurality of approval stations in the operation process;
104) receiving input of a payment request sent to a bank system, and verifying whether a signature sequence and signature information in a standard table are respectively consistent with a signature sequence and signature information in a log table; if the payment request is consistent with the enterprise security certificate, the payment request, the enterprise security certificate and the log table are sent to the bank system together; if not, the payment request, the enterprise security certificate and the log table are not sent to the bank system;
the bank system verification step specifically comprises:
201) receiving the standard table sent by the enterprise system in the step 102);
202) receiving the payment request, the enterprise security certificate and the log table sent by the enterprise system in the step 104);
203) verifying the received enterprise security certificate, if the verification is wrong, the payment request sent by the enterprise system is not satisfied, and if the verification is correct, turning to the step 204);
204) whether the signature sequence and the signature information in the verification standard table are respectively consistent with the signature sequence and the signature information in the log table is verified; and if the payment requests are consistent, the payment requests sent by the enterprise system are satisfied, and if the payment requests are not consistent, the payment requests sent by the enterprise system are not satisfied.
Further scheme is that the method also comprises a first enterprise informing step: informing the enterprise user of the processing result of step 104).
The further scheme is that the method further comprises a bank first feedback step: and feeding back the processing result of the bank system verification step to the enterprise system.
Further proposal is that the method also comprises a second enterprise informing step: and receiving the processing result fed back by the bank system in the bank feedback step, and informing the enterprise user.
According to the scheme, the method provided by the invention not only verifies the enterprise security certificate of the enterprise in the payment request process, but also verifies the post signature and sequence of each post in the payment request approval process in the enterprise, so that more verification links are added, and the payment security is improved; in addition, the method not only protects the identity of the enterprise, but also simultaneously protects the inside and the outside of each post in the enterprise and the approval process of the enterprise.
The invention also provides a system for realizing the method, which is used for paying by an enterprise through a bank and comprises an enterprise system and a bank system;
wherein, enterprise system includes the transmitting device, and the transmitting device includes:
the enterprise setting module is used for recording the payment request and setting a corresponding standard table, and the standard table records the signature sequence of the plurality of approval positions and a plurality of signature information corresponding to the plurality of approval positions;
the sending module is used for sending the set standard table to the bank system;
the recording module is used for receiving the signature operation of the plurality of approval stations by using respective signature certificates and generating a log table, and the log table records the signature sequence of the plurality of approval stations and the signature information of the plurality of approval stations in the operation process;
the enterprise verification module is used for receiving input of a payment request sent to the bank system, and verifying whether the signature sequence and the signature information in the standard table are respectively consistent with the signature sequence and the signature information in the log table; if the payment request is consistent with the enterprise security certificate, the payment request, the enterprise security certificate and the log table are sent to the bank system together; if not, the payment request, the enterprise security certificate and the log table are not sent to the bank system, and the user is informed;
the bank system includes a verification device, the verification device including:
the first receiving module is used for receiving the standard table sent by the sending module of the enterprise system;
the second receiving module is used for receiving the payment request, the enterprise security certificate and the log table which are sent by the enterprise verification module of the enterprise system;
the first bank verification module is used for verifying the received enterprise security certificate, if the verification is wrong, the payment request sent by the enterprise system is not satisfied, and if the verification is correct, the second bank verification module is informed;
the second bank verification module is used for verifying whether the signature sequence and the signature information in the standard table are respectively consistent with the signature sequence and the signature information in the log table after receiving the notification of the first bank verification module; and if the payment requests are consistent, the payment requests sent by the enterprise system are satisfied, and if the payment requests are not consistent, the payment requests sent by the enterprise system are terminated.
The enterprise system further comprises a first informing device for informing the enterprise user of the processing result of the enterprise authentication module.
The further scheme is that the bank system further comprises a feedback device for feeding back the processing result of the verification device to the enterprise system.
Further, the enterprise system further includes a second notification device: and receiving the processing result fed back by the feedback device in the bank system and informing the enterprise user.
[ description of the drawings ]
FIG. 1 is a schematic diagram of the system of the present invention.
[ detailed description ] embodiments
The invention provides a method for paying by an enterprise through a bank, which comprises an enterprise system sending step and a bank system verifying step; wherein,
the enterprise system sending step specifically comprises:
101) recording a payment request, and setting a corresponding standard table, wherein the standard table records the signature sequence of a plurality of approval positions and a plurality of signature information corresponding to the plurality of approval positions;
102) sending the set standard table to a bank system;
103) receiving the operation of signing by using the respective signing certificate of the plurality of approval stations, and generating a log table, wherein the log table records the signing sequence of the plurality of approval stations and the signing information of the plurality of approval stations in the operation process;
104) receiving input of a payment request sent to a bank system, and verifying whether a signature sequence and signature information in a standard table are respectively consistent with a signature sequence and signature information in a log table; if the payment request is consistent with the enterprise security certificate, the payment request, the enterprise security certificate and the log table are sent to the bank system together; if not, the payment request, the enterprise security certificate and the log table are not sent to the bank system;
105) informing the user of the result of the step 104), namely informing the user whether the payment request, the enterprise security certificate and the log sheet are sent to the bank system together;
the bank system verification step specifically comprises:
201) receiving the standard table sent by the enterprise system in the step 102);
202) receiving the payment request, the enterprise security certificate and the log table sent by the enterprise system in the step 104);
203) verifying the received enterprise security certificate, if the verification is wrong, the payment request sent by the enterprise system is not satisfied, and if the verification is correct, turning to the step 204);
204) whether the signature sequence and the signature information in the verification standard table are respectively consistent with the signature sequence and the signature information in the log table is verified; and if the payment requests are consistent, the payment requests sent by the enterprise system are satisfied, and if the payment requests are not consistent, the payment requests sent by the enterprise system are not satisfied.
In order to facilitate the use of the user, the method further comprises a first informing step of the enterprise system: informing the enterprise user of the processing result of step 104).
Also for the convenience of users, the method also comprises a first feedback step of the bank: feeding back the processing result of the bank system verification step to the enterprise system; and a second informing step of the enterprise system: and receiving the processing result fed back by the bank system in the bank feedback step, and informing the enterprise user.
As shown in fig. 1, the embodiment further provides a system for an enterprise to pay by a bank, where the system includes an enterprise system and a bank system;
wherein, enterprise system includes the transmitting device, and the transmitting device includes:
the enterprise setting module is used for recording the payment request and setting a corresponding standard table, and the standard table records the signature sequence of the plurality of approval positions and a plurality of signature information corresponding to the plurality of approval positions;
the sending module is used for sending the set standard table to the bank system;
the recording module is used for receiving the signature operation of the plurality of approval stations by using respective signature certificates and generating a log table, and the log table records the signature sequence of the plurality of approval stations and the signature information of the plurality of approval stations in the operation process;
the enterprise verification module is used for receiving input of a payment request sent to the bank system, and verifying whether the signature sequence and the signature information in the standard table are respectively consistent with the signature sequence and the signature information in the log table; if the payment request is consistent with the enterprise security certificate, the payment request, the enterprise security certificate and the log table are sent to the bank system together; if not, the payment request, the enterprise security certificate and the log table are not sent to the bank system, and the user is informed;
the bank system includes a verification device, the verification device including:
the first receiving module is used for receiving the standard table sent by the sending module of the enterprise system;
the second receiving module is used for receiving the payment request, the enterprise security certificate and the log table which are sent by the enterprise verification module of the enterprise system;
the first bank verification module is used for verifying the received enterprise security certificate, if the verification is wrong, the payment request sent by the enterprise system is not satisfied, and if the verification is correct, the second bank verification module is informed;
the second bank verification module is used for verifying whether the signature sequence and the signature information in the standard table are respectively consistent with the signature sequence and the signature information in the log table after receiving the notification of the first bank verification module; and if the payment requests are consistent, the payment requests sent by the enterprise system are satisfied, and if the payment requests are not consistent, the payment requests sent by the enterprise system are terminated.
In order to facilitate the use of the enterprise system, the enterprise system further comprises a first informing device for informing the enterprise user of the processing result of the enterprise authentication module.
The bank system also comprises a feedback device for feeding back the processing result of the verification device to the enterprise system; the enterprise system further comprises a second notification means: and receiving the processing result fed back by the feedback device in the bank system and informing the enterprise user.
The application of the invention is described below in an operational example:
assuming that a certain enterprise pays 100 thousands of the bank accounts to the account of a certain client through a bank system, firstly, a payment request is recorded in the enterprise system, and a standard table of the payment is set, wherein a plurality of approval posts arranged in sequence are recorded in the standard table: the method comprises the following steps that an accounting post, a master post and a cashier post are also recorded, and corresponding signature information of three approval posts of the accounting post, the master post and the cashier post is respectively Lisomewhat, Wansomewhat and Zhang somewhat; the enterprise system sends the standard table to the bank system; in the enterprise, the examining and approving personnel at the examining and approving stations examine and approve and sign by using the corresponding signature certificates in the enterprise system in sequence; in the process of the approval, the enterprise system generates a log table, and the log table records the signature sequence of a plurality of approval positions and the signature information of the plurality of approval positions in the operation process; finally, the cashier inputs and receives the input of a payment request (paying 100 thousands of the bank accounts to the account of a certain client) sent to the bank system to the enterprise system, and the enterprise system verifies whether the signature sequence and the signature information in the standard table are respectively consistent with the signature sequence and the signature information in the log table; if the payment request is consistent with the enterprise security certificate, the payment request, the enterprise security certificate and the log table are sent to the bank system together; if not, the payment request, the enterprise security certificate and the log table are not sent to the bank system; the enterprise system informs the user of the processing result;
the bank system receives the standard table, the payment request, the enterprise security certificate and the log table which are sent by the enterprise system; firstly, the bank system verifies the received enterprise security certificate, if the verification is wrong, the payment request sent by the enterprise system is not satisfied, if the verification is correct, whether the signature sequence and the signature information in the verification standard table are respectively consistent with the signature sequence and the signature information of the log table, if so, the payment request sent by the enterprise system is satisfied, and if not, the payment request sent by the enterprise system is not satisfied;
the bank system feeds back the processing result to the enterprise system, and the enterprise system receives the feedback result and informs the enterprise user.
The present invention is not limited to the above-described embodiments, and simple substitutions based on the above-described embodiments, which are not inventive, should fall within the scope of the present disclosure.