CN103326994B - Method for processing business and system - Google Patents

Method for processing business and system Download PDF

Info

Publication number
CN103326994B
CN103326994B CN201210076929.3A CN201210076929A CN103326994B CN 103326994 B CN103326994 B CN 103326994B CN 201210076929 A CN201210076929 A CN 201210076929A CN 103326994 B CN103326994 B CN 103326994B
Authority
CN
China
Prior art keywords
card number
plaintext
index
business
entity
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201210076929.3A
Other languages
Chinese (zh)
Other versions
CN103326994A (en
Inventor
朱晓峰
周兴江
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Advanced New Technologies Co Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Priority to CN201210076929.3A priority Critical patent/CN103326994B/en
Publication of CN103326994A publication Critical patent/CN103326994A/en
Application granted granted Critical
Publication of CN103326994B publication Critical patent/CN103326994B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

This application discloses a kind of method for processing business and system, wherein, this method includes:Receive the plaintext card number for asking processing business;The plaintext card number is converted into index card number, wherein, the index card number corresponds uniquely to the plaintext card number;The index card number being converted to is sent to the entity for handling the business, for making the entity according to the index card number processing business.Present application addresses the technical problem of the security that can not ensure user's processing business caused in correlation technique due to the real card number information of leakage, the security of Network processing is improved.

Description

Method for processing business and system
Technical field
The application is related to data processing field, in particular to a kind of method for processing business and system.
Background technology
By the end of the year 2010, domestic credit card issued volume reaches 2.3 hundred million, and credit card at home gradually come by popularization.Letter Facility is provided the user in line with fast and easily criterion with card, but at the same time the potential safety hazard of credit card information also emerges Come.The Third-party payment company of existing internet, is much faced with credit card information that user submitted in webpage in many places It is scattered, these information include:Credit card plaintext card number, cvv2 are (behind Card Verification Value 2, credit card 3 identifying codes), the sensitive information such as validDate (credit card effective period), once a leak occurs, meaning to bring to user Economic loss.
As shown in figure 1, during processing business, it (or is letter that credit card user, which sends and carries credit card number, With card plaintext card number) service request, operation system receives and identifies the service request from user;Then, operation system is led to Often directly carry out processing business using the credit card number carried in service request, for example, being put down using credit card number and third party Platform is interacted.
For example, when user is traded on shopping website, the user is submitted for payment transaction to Website server The credit card number is sent to the server where the 3rd payment platform by the credit card number of expense, the Website server.Together When, during payment, in addition it is also necessary to which user provides the information related to credit card number, for example, password that user is set etc..
However, with the development of network technology, Website server is carried out using credit card number with the 3rd payment platform In interactive process, it is easy to by third party's malicious attack, so as to obtain above-mentioned credit card number.Due to the credit card number It is the true card number (or being credit card plaintext card number) for the credit card that user uses, therefore, third party may be by getting The true card number certain economic loss is caused to the user, it is impossible to ensure the security of user's processing business.
From the foregoing, it will be observed that in the prior art, the security of user's processing business can not be ensured in business procession.
The content of the invention
The main purpose of the application is to provide a kind of method for processing business and system, at least to solve because leakage is true Card number information and the technical problem of the security that can not ensure user's processing business that causes.
According to the one side of the application there is provided a kind of method for processing business, it includes:Receive for asking processing industry The plaintext card number of business;Plaintext card number is converted into index card number, wherein, index card number corresponds uniquely to plaintext card number;It will turn The index card number got in return is sent to the entity of processing business, for making entity according to index card number processing business.
It is preferred that, the step of plaintext card number is converted into index card number includes:Obtain the portion numbers in plaintext card number, obtain Current date when taking portion numbers and the sequence number for unique mark plaintext card number;By portion numbers, current date with And sequence number builds and obtains indexing card number.
It is preferred that, portion numbers, current date and sequence number are built to the step of obtaining index card number to be included:By part Second in Part I number, current date, sequence number and portion numbers in number in addition to Part I number Branch code is built in order to be obtained indexing card number.
It is preferred that, when plaintext card number is converted into index card number, in addition to:Perform and be converted into plaintext card number to index card number Entity storage index card number and plaintext card number is encrypted obtained encryption card number.
It is preferred that, the step of receiving for asking the plaintext card number of processing business includes:The entity of processing business, which is received, to be used In the plaintext card number of request processing business;Plaintext card number is sent to plaintext card number being converted into index card by the entity of processing business Number entity.
It is preferred that, the step of receiving for asking the plaintext card number of processing business includes:The entity for receiving plaintext card number will Plaintext card number is sent to the entity that plaintext card number is converted into indexing to card number;The index card number being converted to is sent to processing industry The step of entity of business, includes:Plaintext card number is converted into indexing the entity of card number will index card number by receiving plaintext card number Entity is sent to the entity of processing business.
It is preferred that, the step of receiving for asking the plaintext card number of processing business includes:The entity for receiving plaintext card number will Plaintext card number is sent to the entity that plaintext card number is converted into indexing to card number;The index card number being converted to is sent to processing industry The step of entity of business, includes:Index card number is sent to the reality of processing business by the entity that plaintext card number is converted into index card number Body.
It is preferred that, plaintext card number includes:The plaintext card number of credit card.
According to the another aspect of the application there is provided a kind of transaction processing system, it includes:The business processing communicated Device and card number processing unit, wherein, card number processing unit is used for the plaintext card number for being used to ask processing business that will be received It is converted into indexing card number, wherein, index card number corresponds uniquely to plaintext card number;The index card number being converted to is sent to industry Business processing unit;Business processing device is used for according to index card number processing business.
It is preferred that, card number processing unit includes:Acquiring unit, for obtaining the portion numbers in plaintext card number, acquisition unit Current date during branch code and the sequence number for unique mark plaintext card number;Construction unit, for by portion numbers, when Preceding date and sequence number, which are built, to be obtained indexing card number.
It is preferred that, card number processing unit also includes:Memory cell, for storing index card number and being carried out to plaintext card number Encrypt obtained encryption card number.
It is preferred that, business processing device is additionally operable to receive plaintext card number, and plaintext card number is sent into card number processing unit.
It is preferred that, transaction processing system also includes:Reception device, sends for receiving plaintext card number, and by plaintext card number Give card number processing unit.
It is preferred that, reception device is additionally operable to receive the index card number from card number processing unit, and index card number is sent To business processing device.
By the technical scheme of the application, following beneficial effect can be reached:In this application, by the plaintext card received Number it is indexed conversion, generation index card number, wherein, it is unique that this index card number, which corresponds to plaintext card number, and to index card Number it is encrypted, in business procession, is interacted using the index card number after encryption.So, even in interactive mistake Card number information is got by third party's malice in journey, third party also can not obtain real card according to acquired index card number Number information (i.e. plaintext card number), so that solving can not ensure that user handles industry due to what is leaked real card number information and cause The technical problem of the security of business, improves the security of Network processing.
Brief description of the drawings
Accompanying drawing described herein is used for providing further understanding of the present application, constitutes the part of the application, this Shen Schematic description and description please is used to explain the application, does not constitute the improper restriction to the application.In the accompanying drawings:
Fig. 1 is the schematic diagram of the method for processing business according to correlation technique;
Fig. 2 is the transaction processing system structural representation according to the embodiment of the present application;
Fig. 3 is a kind of preferred structured flowchart of the transaction processing system according to the embodiment of the present application;
Fig. 4 is another preferred structured flowchart of the transaction processing system according to the embodiment of the present application;
Fig. 5 is a kind of preferred flow chart of the method for processing business according to the embodiment of the present application;
Fig. 6 is a kind of schematic diagram of Third-party payment platform data storage according to the embodiment of the present application;
Fig. 7 is according to a kind of preferred of the method for processing business based on Web Service patterns of the embodiment of the present application Structural representation;
Fig. 8 is a kind of preferred structural representation of the method for processing business based on Ajax patterns according to the embodiment of the present application Figure;
Fig. 9 is shown according to a kind of preferred structure of the method for processing business based on Proxy patterns of the embodiment of the present application It is intended to.
Embodiment
Describe the application in detail below with reference to accompanying drawing and in conjunction with the embodiments.It should be noted that not conflicting In the case of, the feature in embodiment and embodiment in the application can be mutually combined.
Before the further detail below of description present embodiments, it will be described with reference to Figure 2 and can be used for realizing this Shen The suitable counting system structure of one of principle please.In the following description, except as otherwise noted, otherwise will refer to by one or The action and the symbol of operation that multiple computers are performed represent to describe present embodiments.As such, it will be understood that sometimes Being referred to as this kind of action and operation of computer execution includes the processing unit of computer to representing data with structured form The manipulation of electric signal.It is safeguarded on this manipulation transforms data or position in the accumulator system of computer, this is with this The mode that the technical staff in field understands reconfigures or changed the operation of computer.The data structure for safeguarding data is that have The physical location of the memory of particular community defined in the form of data.Although however, this Shen described in above-mentioned context Please, but its being not intended to limit property, as understood by those skilled in the art, action described below and operation Each side can also be realized with hardware.
Accompanying drawing is turned to, wherein identical reference number refers to identical element, and the principle of the application is shown in a conjunction Realized in suitable computing environment.Describe based on described embodiments herein, and be not considered as on herein not below The alternative embodiment that is expressly recited and limit the application.
Fig. 2 shows the schematic diagram of an example computer architecture available for these equipment.For the mesh of description , the architecture painted is only an example of proper environment, and not use scope or the function proposition to the application are any Limitation.The computing system should not be also construed to have any dependence or demand to any component shown in Fig. 2 or its combination.
The principle of the application can use other universal or special calculating or communication environment or configure to operate.Suitable for this Well-known computing system, environment and the example of configuration of application include but is not limited to, personal computer, server, many places Manage device system, the system based on microprocessor, minicomputer, mainframe computer and the distribution including any said system or equipment Formula computing environment.
In its most basic configuration, the transaction processing system 200 in Fig. 2 at least includes:The server 202 of one website And one or more clients 204.Server 202 can include but is not limited to Micro-processor MCV or PLD FPGA etc. processing unit, the storage device for data storage and the transmitting device with client communication;Client 204 can With including:Micro-processor MCV, the transmitting device with server communication, the display device with user mutual.In this specification and power In sharp claim, " transaction processing system " can also be defined as being able to carry out software, firmware or microcode realizing appointing for function The combination of what nextport hardware component NextPort or nextport hardware component NextPort.Transaction processing system 200 can even is that it is distributed, to realize distributed work( Energy.
As used in this application, term " module ", " component " or " unit " can refer to holds on transaction processing system 200 Capable software object or routine.Different components described herein, module, unit, engine and service can be implemented as in business The object or process of (for example, being used as single thread) are performed in processing system 200.Although system and method described herein Preferably realized with software, but the realization of the combination of hardware or software and hardware is also that may and be contemplated.
Embodiment 1
Fig. 3 is a kind of preferred structure chart of the transaction processing system according to the application preferred embodiment, it is preferred that this reality The transaction processing system applied in example is located in server 202 or client 204.
It is preferred that, the transaction processing system shown in Fig. 3 includes:Business processing device 302 and the card number processing communicated Device 304, wherein, card number processing unit 304 is used to the plaintext card number of the request processing business received being converted into index card Number, wherein, index card number corresponds uniquely to plaintext card number;Card number processing unit 304 sends the index card number being converted to To business processing device 302;Business processing device 302 is used for according to index card number processing business.
In above-mentioned preferred embodiment, the plaintext card number received is indexed conversion, generation indexes card number, its In, it is unique that this index card number, which corresponds to plaintext card number, and index card number is encrypted, and in business procession, is made Interacted with the index card number after encryption.So, card number information is got by third party's malice during interaction, Third party can not also obtain real card number information (i.e. plaintext card number) according to acquired index card number, thus solve by In the technical problem for the security that can not ensure user's processing business for leaking real card number information and causing, network is improved The security of business processing.
The application is also improved above-mentioned card number processing unit 404, to reach that generation is uniquely right with plaintext card number The index card number technique effect answered.To achieve these goals, specifically, as shown in figure 4, in above-mentioned preferred embodiment, Card number processing unit 404 includes:Acquiring unit 4042 and construction unit 4044.During index card number is built, obtain single Member 4042 obtain plaintext card number in portion numbers, fetching portion number when current date and for unique mark in plain text block Number sequence number;Then, construction unit 4044 obtains acquiring unit 4042 portion numbers, current date and sequence number structure Build and obtain indexing card number.Pass through the improvement to above-mentioned card number processing unit 404 so that the index card number of generation includes plaintext card number In portion numbers, fetching portion number when current date and plaintext card number unique corresponding sequence number, so as to ensure The index card number of generation is uniquely corresponding with plaintext card number.
It is preferred that, portion numbers, current date and sequence number are built and obtained by construction unit 4044 by following steps Index card number:Part I number will be removed in Part I number, current date, sequence number and portion numbers in portion numbers Part II number outside code is built in order to be obtained indexing card number.
The application is also improved above-mentioned card number processing unit 404, to reach that storage user credit card was merchandised The technique effect of relevant information in journey.To achieve these goals, specifically, as shown in figure 4, each is preferred in the application On the basis of embodiment, by increasing memory cell 4046 in card number processing unit 404, the memory cell 4046 is used to store Index card number and plaintext card number is encrypted obtained encryption card number.Certainly, the rope that said memory cells 4046 are stored It is a kind of example to draw card number and encryption card number, and the application is not limited only to this, for example, it is also possible to store credit card effective period etc.. By being improved above-mentioned card number processing unit 404, increased memory cell 4046 can store the transaction of user credit card The record of details, makes the convenient relevant information to credit card of Third-party payment platform be checked and be managed collectively.
In addition, the application is also improved above-mentioned business processing device 402, specifically, in the application, each is preferred Embodiment on the basis of, business processing device 402 be additionally operable to receive plaintext card number, and by plaintext card number be sent to card number processing Device 404.In the present embodiment, business processing device 402 receives plaintext card number, and plaintext card number then is sent into card number processing Device 404;The plaintext card number is converted into indexing card number, then will by card number processing unit 404 after it will receive plaintext card number The index card number being converted to is sent to business processing device 402, business processing device 402 according to the index card number received at Reason business.Pass through the improvement carried out to above-mentioned business processing device 402 so that business processing device 402 can and directly with card Number processing unit 404 is interacted, so as to complete the biography of index card number in the case where not needing other third party devices It is defeated, improve the efficiency of index card number interaction.
The application is also improved transaction processing system, at reaching card number processing unit 404 without business Manage the technique effect that device 402 receives plaintext card number.To achieve these goals, specifically, as shown in figure 4, each in the application On the basis of individual preferred embodiment, transaction processing system also includes:Reception device 406, for receiving plaintext card number, and will be bright Literary card number is sent to card number processing unit 404.By the improvement carried out to above-mentioned transaction processing system, it can reach that card number is handled Device 404 receives the effect of plaintext card number without business processing device 402 so that transaction processing system can apply to send The plaintext card number of request first passes through the pattern that card number processing unit 404 carries out conversion process.
The application is also improved reception device 406, to reach that reception device 406 can be by the rope being converted to Draw card number and be sent to the technique effect that business processing device 402 is handled.To achieve these goals, specifically, such as Fig. 4 institutes Show, on the basis of the application each preferred embodiment, reception device 406, which is additionally operable to receive, comes from card number processing unit 404 Index card number, and by index card number be sent to business processing device 402.By the improvement carried out to above-mentioned reception device 406, The index card number being converted to can be sent to business processing device 402 and be handled by reception device 406, transaction processing system The plaintext card number that can apply to send request first passes through the progress conversion process of card number processing unit 404, re-sends at business Manage the pattern that device 402 carries out business processing.
Embodiment 2
On the basis of the transaction processing system shown in Fig. 2-Fig. 4, present invention also provides a kind of method of business processing. As shown in figure 5, the method for the business processing includes:
S502, receives the plaintext card number for asking processing business;
S504, plaintext card number is converted into index card number, wherein, index card number corresponds uniquely to plaintext card number;
S506, the index card number being converted to is sent to the entity of processing business, for making entity according to index card number Processing business.
In above-mentioned preferred embodiment, the plaintext card number received is indexed conversion, generation indexes card number, its In, it is unique that this index card number, which corresponds to plaintext card number, and index card number is encrypted, and in business procession, is made Interacted with the index card number after encryption.So, card number information is got by third party's malice during interaction, Third party can not also obtain real card number information (i.e. plaintext card number) according to acquired index card number, thus solve by In the technical problem for the security that can not ensure user's processing business for leaking real card number information and causing, network is improved The security of business processing.
The application is also improved plaintext card number index translation step to above-mentioned, to reach generation with blocking in plain text The technique effect of number unique corresponding index card number.To achieve these goals, specifically, in the base of above-mentioned preferred embodiment On plinth, the step of plaintext card number is converted into index card number includes:Obtain plaintext card number in portion numbers, fetching portion number when Current date and sequence number for unique mark plaintext card number;Portion numbers, current date and sequence number are built Obtain indexing card number.Pass through the current date and use when the portion numbers in the plaintext card number to acquisition, fetching portion number The plaintext card number got is indexed encryption in the sequence number of unique mark plaintext card number so that the index card number bag of generation Unique corresponding sequence of current date and plaintext card number when portion numbers in card number containing plaintext, fetching portion number Number, so as to ensure that the index card number of generation is uniquely corresponding with plaintext card number.
The application is also improved portion numbers, current date and sequence number index translation step to above-mentioned, The technique effect that index card number is uniquely determined with plaintext card number is further limited to reach.To achieve these goals, specifically Ground, on the basis of each preferred embodiment, by Part I number, current date, the sequence number in above-mentioned portion numbers And the Part II number in portion numbers in addition to Part I number builds obtain indexing card number in order.By to portion Branch code, current date and sequence number index translation step are improved, further ensure the index card number of generation with The only one-to-one correspondence of plaintext card number.
It is preferred that, in the transfer process of above-mentioned index card number, the part number in the middle of plaintext card number is substituted for a string Unique sequence number, sequence number can use the sequence number of credit card information table, for example, the sequence number used in credit card information table For 1~4845788, be then currently used in the Serial No. 4845789 of generation index card number, here, credit card information table can with but The table for the storage sequence number that the system of being not limited to is pre-established.It is preferred that, credit card plaintext card number, which can be taken, only retains 4 digits after preceding 5+ The mode of word, allows card user itself to recognize currently used credit number.Ultimately generate the formula of index card number:Preceding 5 Plaintext card number+yyyyMMdd (current date)+sequence number (7)+rear 4 plaintext card number, for example:Plaintext card number: 6225512145641234, index card number:622552011072248457891234.After being changed by plaintext card number, final To the index card number of 24, the index card number is globally unique in the credit card information table that the system is stored.Obviously, this is preferred Embodiment can with but be not limited to this.
The application is also improved above-mentioned index card number switch process, and user credit card can be stored to reach The technique effect of information.To achieve these goals, specifically, on the basis of above-mentioned preferred embodiment, performing will in plain text Card number is converted into indexing the entity storage index card number of card number and plaintext card number is encrypted obtained encryption card number.Pass through Above-mentioned index translation step is improved, increases store function, the 3rd payment platform is preserved user credit card The record for details of merchandising.
It is preferred that, Fig. 6 shows a kind of schematic diagram of Third-party payment platform data storage, and plaintext card number is converted into by execution The entity division of card number is indexed for security domain and non-secure domains two parts, wherein, can only be by performing in plain text in non-secure domains Card number is converted into indexing the entity storage original credit card information of card number, and takes the index card number after index;In security domain System can exchange corresponding credit card information for by indexing card number.By the improvement to above preferred embodiment, it can reach The information that storage for the service selection of different credits card needs, makes Third-party payment platform is convenient to be carried out to credit card Unified management.
It is preferred that, during credit card information is stored, following credit card information can be stored:The unique ID of credit card Number, via plaintext card number handle after generate index card number, via plaintext card number encrypt and generate content, Cvv2 information, card Term of validity information on piece, the time being currently generated (being accurate to millisecond) and current information last renewal time etc..Specifically Ground, the credit card information of storage may refer to shown in following table:
Field name Description
ID The Unique ID of credit card, is that stepping increases certainly with 1
Credit card indexes card number The index card number generated after being handled via plaintext card number
Credit card encrypts card number The content encrypted via plaintext card number
Credit card CVV2 Cvv2 information
Credit card effective period (ValidDate) Validdate information on card
The generation time Current information generates the time, is accurate to millisecond, yyyyMMdd hhmmss
Renewal time The current information final updating time
It is preferred that, only plaintext card number is carried out being converted to index card number completing and complete to add plaintext card number The above-mentioned credit card information of storage is just carried out after close operation, if above-mentioned conversion operation and cryptographic operation failure, without storage. Obviously, this preferred embodiment can with but be not limited to this.
For the particularity of the demand that meets miscellaneous service scene, the application provides a variety of patterns for business processing, It is described in detail below in conjunction with accompanying drawing.
(1) Web Service patterns
Fig. 7 shows a kind of business processing scene of Web Service patterns, and under the scene, user passes through client The request of initiation first passes through transaction processing system reception, and transaction processing system is (for example, the business processing dress shown in Fig. 3 and Fig. 4 Put) the plaintext card number of reception is carried out by information encryption storage system (e.g., the card number processing unit shown in Fig. 3 and Fig. 4) again Index translation, then plaintext card number by information encryption storage system by the index card number being converted to send transaction processing system Carry out business processing.
To achieve these goals, the application to above-mentioned reception plaintext card number the step of improved, to reach place The entity of reason business can receive plaintext card number, and be sent to the technique effect that plaintext card number is converted into indexing the entity of card number. Specifically, on the basis of above-mentioned preferred embodiment, the step of receiving for asking the plaintext card number of processing business includes:Place The entity of reason business receives the plaintext card number for asking processing business;Plaintext card number is sent to by the entity of processing business will be bright Literary card number is converted into indexing the entity of card number.The step of by above-mentioned reception plaintext card number, is improved so that processing industry The entity that the entity of business and can directly be converted into indexing card number with plaintext card number is interacted, so as to need not be other The transmission of index card number is completed in the case of third party entity, the efficiency of index card number interaction is improved.
Below based on the business processing scene shown in Fig. 7, the method for processing business in this preferred embodiment is described, it includes Following steps:
S702, user submits credit card related information to be handled to transaction processing system by client;
S704, transaction processing system carries plaintext card number is sent to credit card information encryption storage system in convert requests System;
S706, credit card information encryption storage system responds above-mentioned convert requests and carries out plaintext card number to be converted to index Card number, then returns to transaction processing system by index card number.It is preferred that, the process of above-mentioned conversion can use above-described embodiment In the method mentioned, will not be repeated here;It is preferred that, credit card information encryption storage system stores above-mentioned plaintext card number, index The information such as card number;
S708, transaction processing system carries out business processing according to index card number, and result is returned to user.
In the above-described embodiments, transaction processing system can and directly be handed over credit card information encryption storage system Mutually, so as to the transmission of the completion index card number in the case where not needing other third party devices, improve index card number and hand over Mutual efficiency.
(2) Ajax patterns
Fig. 8 shows a kind of business processing scene based on Ajax patterns, and under the scene, user is sent by client When submitting cleartext information request, first pass through js initiations ajax and call credit card information to encrypt storage system (for example, Fig. 3 and Fig. 4 institutes The card number processing unit shown), to carry out the index translation operation to plaintext card number;Then, credit card information encryption storage system The index card number being converted to is sent to transaction processing system (for example, shown in Fig. 3 and Fig. 4 by system by the credit card information page Business processing device) carry out business processing.
To achieve these goals, the application is improved to above-mentioned reception and the step of sending plaintext card number, can be with Reach and plaintext card number is converted into indexing the entity of card number without the technique effect of the entity reception plaintext card number of processing business. Specifically, on the basis of above-mentioned preferred embodiment, the step of receiving for asking the plaintext card number of processing business includes:Connect Plaintext card number is sent to the entity that plaintext card number is converted into indexing to card number by the entity for receiving plaintext card number., will under this scene The step of index card number being converted to is sent to the entity of processing business includes:Plaintext card number is converted into indexing to the reality of card number Body is sent to the entity of processing business by card number is indexed by receiving the entity of plaintext card number.By bright to above-mentioned reception and transmission The improvement that the step of literary card number is carried out, can be converted into indexing the entity of card number without processing business by plaintext card number Entity receives plaintext card number so that the plaintext card number that method for processing business can apply to send request is first passed through plaintext card number It is converted into indexing the pattern of the entity progress conversion process of card number.
Below based on the business processing scene shown in Fig. 8, the method for processing business in this preferred embodiment is described, it includes Following steps:
S802, user fills in credit card number information by client, and submits request to the credit card information page;
S804, receives and submits the credit card information page of request to call credit card information encryption storage by js initiations ajax System, it is preferred that js calls credit card information to encrypt the ajax addresss of service that storage system is provided by xmlHttp, such as: http://xxx.xxx.com/ajaxService.do;
S806, credit card information encryption storage system, which is indexed, to be changed and stores, and the index card number after storage is returned Give the credit card information page;It is preferred that, the process of above-mentioned conversion can use the method mentioned in above-described embodiment, herein no longer Repeat;It is preferred that, credit card information encryption storage system stores the information such as above-mentioned plaintext card number, index card number;
S808, the credit card information page replaces original plaintext card number using index card number, and index card number is submitted to Transaction processing system is handled;
Result is returned to client by S810, transaction processing system.
In the above-described embodiments, transaction processing system can support more complicated js invocation patterns, initiate to call using js, directly Connect and the system is submitted to by the page of operation system, it is to avoid it is hidden safely that the possibility brought after plaintext card number is taken in operation system rear end Suffer from;And other systems without force depend on the system, access, fast.
(3) Proxy patterns
Fig. 9 shows a kind of business processing scene based on Proxy patterns, under the scene, user by client to When the credit card information page submits service request, the credit card information page receives the plaintext card number of user, then passes through credit card Information encryption storage system (for example, card number processing unit shown in Fig. 3 and Fig. 4) is indexed to plaintext card number is converted to rope Draw card number, then will index card number and be sent to operation system progress business processing (for example, the business processing shown in Fig. 3 and Fig. 4 is filled Put).
To achieve these goals, the application is also improved to above-mentioned reception and the step of sending plaintext card number, with Just reach that the entity for being converted into indexing card number by plaintext card number is imitated without the technology of the entity reception plaintext card number of processing business Really.Specifically, on the basis of above-mentioned preferred embodiment, the step of receiving for asking the plaintext card number of processing business is wrapped Include:The plaintext card number received is sent to the entity that plaintext card number is converted into indexing to card number by the entity for receiving plaintext card number; The step of index card number being converted to is sent into the entity of processing business includes:Plaintext card number is converted into index card number Entity is sent to the entity of processing business by card number is indexed.What the step of by above-mentioned reception and transmission plaintext card number was carried out changes Enter, can reach that plaintext card number is converted into indexing the entity of card number without the effect of the entity reception plaintext card number of processing business Really so that the plaintext card number that the application method for processing business can apply to send request first passes through plaintext card number and is converted into index The entity of card number carries out the pattern of conversion process.
Below based on the business processing scene shown in Fig. 9, the method for processing business in this preferred embodiment is described, it includes Following steps:
S902, user submits service request by client to the credit card information page;
S904, receives and submits the credit card information page of request to call credit card information encryption storage system by post/get System, wherein, credit card information encrypts storage system and is converted to rope to submitting the plaintext card number of the credit card come up to be indexed Draw card number and store;
S906, credit card information encryption storage system is blocked in plain text with the credit card obtained in index card number replacement originally requested content Number being sent to operation system is handled, it is preferred that credit card information encryption storage system will index card number together with other specification Operation system is transmitted to by http/post modes together;It is preferred that, other specification includes request parameters and cookies believes Breath, it is clear that the application preferred embodiment can with but be not limited to this;
S908, transaction processing system returns to credit card letter using index card number processing business, and by the result handled Encryption for information storage system;
The result that transaction processing system is handled is returned to client by S910, credit card information encryption storage system.
In above preferred embodiment, transaction processing system is middle-agent's mode based on page request, it is possible to achieve Some can not use the business processing of complicated js front end page, the page such as wap.In addition, by the business processing of the application The above-mentioned pattern of system access, is that can be achieved without big transformation.
It is preferred that, in each above-mentioned embodiment, plaintext card number includes:The plaintext card number of credit card, this is that one kind is shown Example, the application is not limited to that, for example, plaintext card number can also include:The others such as plaintext card number of bank card are used for net The data that upper information is exchanged.So so that the application can apply to different scenes, the flexibility of application is increased.
Obviously, those skilled in the art should be understood that each module or each step of above-mentioned the application can be with general Computing device realize that they can be concentrated on single computing device, or be distributed in multiple computing devices and constituted Network on, alternatively, the program code that they can be can perform with computing device be realized, it is thus possible to they are stored Performed in the storage device by computing device, and in some cases, can be shown to be performed different from order herein The step of going out or describe, they are either fabricated to each integrated circuit modules respectively or by multiple modules in them or Step is fabricated to single integrated circuit module to realize.So, the application is not restricted to any specific hardware and software combination.
The preferred embodiment of the application is the foregoing is only, the application is not limited to, for the skill of this area For art personnel, the application can have various modifications and variations.It is all within spirit herein and principle, made any repair Change, equivalent substitution, improvement etc., should be included within the protection domain of the application.

Claims (10)

1. a kind of method for processing business, it is characterised in that including:
Receive the plaintext card number for asking processing business;
The plaintext card number is converted into index card number, wherein, the index card number corresponds uniquely to the plaintext card number;
The index card number being converted to is sent to the entity for handling the business, for making the entity according to the index card Number processing business;
The step of plaintext card number is converted into index card number includes:
Current date when obtaining portion numbers in the plaintext card number, obtaining the portion numbers and for unique mark The sequence number of the plaintext card number;
The portion numbers, the current date and the sequence number are built and obtain the index card number;
When the plaintext card number is converted into index card number, in addition to:
Perform and the plaintext card number is converted into indexing the entity storage index card number of card number and to the plaintext card number Obtained encryption card number is encrypted;
Wherein, perform and the plaintext card number be converted into indexing the entity division of card number for security domain and non-secure domains two parts, Wherein, original credit can only be stored by performing the entity for being converted into indexing card number by the plaintext card number in the non-secure domains Card information, and take the index card number after index;System in the security domain exchanges corresponding letter for by the index card number Use card information.
2. according to the method described in claim 1, it is characterised in that by the portion numbers, the current date and described Sequence number, which builds the step of obtaining the index card number, to be included:
By in the Part I number in the portion numbers, the current date, the sequence number and the portion numbers Part II number in addition to the Part I number is built in order obtains the index card number.
3. according to the method described in claim 1, it is characterised in that the step of receiving the plaintext card number for asking processing business Including:
The entity for handling the business receives plaintext card number for asking processing business;
The plaintext card number is sent to the entity that the plaintext card number is converted into indexing to card number by the entity for handling the business.
4. according to the method described in claim 1, it is characterised in that
The step of receiving for asking the plaintext card number of processing business includes:The entity of the plaintext card number is received by the plaintext Card number is sent to the entity that the plaintext card number is converted into indexing to card number;
The step of index card number being converted to is sent into the entity for handling the business includes:By plaintext card number conversion The index card number is sent to by the entity for receiving the plaintext card number into the entity for indexing card number and handles the industry The entity of business.
5. according to the method described in claim 1, it is characterised in that
The step of receiving for asking the plaintext card number of processing business includes:The entity of the plaintext card number is received by the plaintext Card number is sent to the entity that the plaintext card number is converted into indexing to card number;
The step of index card number being converted to is sent into the entity for handling the business includes:By plaintext card number conversion The index card number is sent to the entity for handling the business into the entity for indexing card number.
6. according to the method described in claim 1, it is characterised in that the plaintext card number includes:The plaintext card number of credit card.
7. a kind of transaction processing system, it is characterised in that including:The business processing device and card number processing unit communicated, Wherein,
The plaintext card number for being used to ask processing business that the card number processing unit is used to receive is converted into index card number, its In, the index card number corresponds uniquely to the plaintext card number;The index card number being converted to is sent at the business Manage device;
The business processing device is used to handle the business according to the index card number;
The card number processing unit includes:
Acquiring unit, for obtain the portion numbers in the plaintext card number, obtain the portion numbers when current date with And the sequence number for plaintext card number described in unique mark;
Construction unit, the index card is obtained for the portion numbers, the current date and the sequence number to be built Number;
The card number processing unit also includes:
Memory cell, for storing the index card number and obtained encryption card number being encrypted to the plaintext card number;
Wherein, perform and the plaintext card number be converted into indexing the entity division of card number for security domain and non-secure domains two parts, Wherein, original credit can only be stored by performing the entity for being converted into indexing card number by the plaintext card number in the non-secure domains Card information, and take the index card number after index;System in the security domain exchanges corresponding letter for by the index card number Use card information.
8. system according to claim 7, it is characterised in that the business processing device is additionally operable to receive the plaintext card Number, and the plaintext card number is sent to the card number processing unit.
9. system according to claim 7, it is characterised in that also include:Reception device, for receiving the plaintext card Number, and the plaintext card number is sent to the card number processing unit.
10. system according to claim 9, it is characterised in that the reception device, which is additionally operable to receive, comes from the card number The index card number of processing unit, and the index card number is sent to the business processing device.
CN201210076929.3A 2012-03-21 2012-03-21 Method for processing business and system Active CN103326994B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210076929.3A CN103326994B (en) 2012-03-21 2012-03-21 Method for processing business and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210076929.3A CN103326994B (en) 2012-03-21 2012-03-21 Method for processing business and system

Publications (2)

Publication Number Publication Date
CN103326994A CN103326994A (en) 2013-09-25
CN103326994B true CN103326994B (en) 2017-09-01

Family

ID=49195528

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210076929.3A Active CN103326994B (en) 2012-03-21 2012-03-21 Method for processing business and system

Country Status (1)

Country Link
CN (1) CN103326994B (en)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105825371A (en) * 2015-01-07 2016-08-03 阿里巴巴集团控股有限公司 Method and device for processing service
CN106779705B (en) * 2016-12-08 2021-06-01 上海众人网络安全技术有限公司 Dynamic payment method and system
CN108090768A (en) * 2017-11-14 2018-05-29 阿里巴巴集团控股有限公司 The method and device that a kind of business performs
CN108829650B (en) * 2018-06-01 2022-08-23 腾讯科技(北京)有限公司 Card number generation method, device, server and storage medium
CN111461728B (en) * 2020-03-31 2023-03-10 支付宝(杭州)信息技术有限公司 Risk identification method, device and system

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1028401A3 (en) * 1999-02-12 2003-06-25 Citibank, N.A. Method and system for performing a bankcard transaction
GB0010422D0 (en) * 2000-04-28 2000-06-14 Cast Technologies Limited Payment apparatus and method
US7853782B1 (en) * 2004-04-14 2010-12-14 Sprint Spectrum L.P. Secure intermediation system and method

Also Published As

Publication number Publication date
CN103326994A (en) 2013-09-25

Similar Documents

Publication Publication Date Title
CN103326994B (en) Method for processing business and system
CN104767613B (en) Signature verification method, apparatus and system
CN105556891B (en) Method, system and the storage medium of session token are sent by passive client
CN106713508B (en) A kind of data access method and system based on Cloud Server
CN103488922B (en) A kind of method and apparatus for providing identifying code
CN109067541A (en) Data verification method and device, electronic equipment based on block chain
US20110191591A1 (en) Transmitting Information Using Virtual Input Layout
CN108701309A (en) A kind of distributed user profile authentication system for security of e-commerce transactions
CN109063016A (en) Block chain data storage method, device, electronic equipment, storage medium
CN105373927A (en) Coupon code generation method of electronic coupon, device and server
CN105072108B (en) Transmission method, the apparatus and system of user information
CN109345417A (en) The on-line examination method and terminal device of the business personnel of identity-based certification
CN104994064A (en) Authorization authentication method and system based on client end plug-in
CN108418790A (en) Business tracking method, device, terminal device and storage medium
CN102710621B (en) A kind of user authentication method and system
CN105978855A (en) System and method for protecting personal information security in real-name system
CN108718323A (en) A kind of identity identifying method and system
CN110247857A (en) Current-limiting method and device
CN104158797A (en) Word and indentifying password integrated user login authentication implementation method
CN110536118A (en) A kind of data capture method, device and computer storage medium
CN107196898A (en) Account logon method, page display method, client and server
CN106899937B (en) The home service range of secret protection inquires outsourcing method
CN109284452A (en) The online methods of exhibiting of electronic protocol, device, electronic equipment, storage medium
CN110020235A (en) Web browser threedimensional model localization method, device, medium and electronic equipment
CN115643090A (en) Longitudinal federal analysis method, device, equipment and medium based on privacy retrieval

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
REG Reference to a national code

Ref country code: HK

Ref legal event code: DE

Ref document number: 1185738

Country of ref document: HK

GR01 Patent grant
GR01 Patent grant
REG Reference to a national code

Ref country code: HK

Ref legal event code: GR

Ref document number: 1185738

Country of ref document: HK

TR01 Transfer of patent right

Effective date of registration: 20191211

Address after: P.O. Box 31119, grand exhibition hall, hibiscus street, 802 West Bay Road, Grand Cayman, Cayman Islands

Patentee after: Innovative advanced technology Co., Ltd

Address before: A four-storey 847 mailbox in Grand Cayman Capital Building, British Cayman Islands

Patentee before: Alibaba Group Holding Co., Ltd.

TR01 Transfer of patent right