TWM601410U - System for completing account application by scanning code to verify identity - Google Patents

System for completing account application by scanning code to verify identity Download PDF

Info

Publication number
TWM601410U
TWM601410U TW109207964U TW109207964U TWM601410U TW M601410 U TWM601410 U TW M601410U TW 109207964 U TW109207964 U TW 109207964U TW 109207964 U TW109207964 U TW 109207964U TW M601410 U TWM601410 U TW M601410U
Authority
TW
Taiwan
Prior art keywords
data
verification
certificate
server
digital
Prior art date
Application number
TW109207964U
Other languages
Chinese (zh)
Inventor
許宏維
林舒婉
郭彥宏
王國河
Original Assignee
國泰世華商業銀行股份有限公司
臺灣網路認證股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 國泰世華商業銀行股份有限公司, 臺灣網路認證股份有限公司 filed Critical 國泰世華商業銀行股份有限公司
Priority to TW109207964U priority Critical patent/TWM601410U/en
Publication of TWM601410U publication Critical patent/TWM601410U/en

Links

Images

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一種掃碼驗身以完成帳戶申請之系統,其透過由自動櫃員機透過行動裝置取得待驗資料,並在待驗資料通過數銀伺服器的確認後,透過憑證載具取得簽章資料,數銀伺服器在簽章資料通過驗證伺服器的驗證後,依據行動裝置所傳送的申請資料進行對應之帳戶申請作業之技術手段,可以改用自動櫃員機完成開戶之身分確認,並達成讓開戶者自由選擇方便的時間與地點完成身分確認的技術功效。A system that scans the code to complete the account application. It obtains the data to be verified through the mobile device from the ATM, and obtains the signature data through the certificate carrier after the data to be verified is confirmed by the digital bank server. After the signature data is verified by the verification server, the server uses the application data sent by the mobile device to carry out the corresponding technical means of account application. It can use the ATM to complete the identity confirmation of the account opening, and the account holder can choose freely Convenient time and place to complete the technical effect of identity verification.

Description

掃碼驗身以完成帳戶申請之系統Scan the QR code to complete the account application system

一種數位帳戶遠端申請系統裝置,特別係指一種掃碼驗身以完成帳戶申請之系統裝置。A remote application system device for a digital account, in particular, a system device that scans a code to complete the account application.

銀行是提供支付、存款、儲蓄、貸款、電匯等業務的金融機構。要使用銀行所提供的業務,通常需要先在銀行開戶。Banks are financial institutions that provide services such as payments, deposits, savings, loans, and wire transfers. To use the services provided by the bank, you usually need to open an account with the bank first.

目前雖然可以透過網路銀行或行動銀行在線上開設數位帳戶,但這樣的開戶方式依身分確認之方式不同,所開設的數位帳戶的等級亦有不同,也就是等級較低之數位帳戶與經過較完整身分確認而開設的數位帳戶相比有諸多限制,例如,部分交易無法執行或交易時可動用的金額較低等。若要開設具有較完整功能的數位帳戶,仍然與開設一般帳戶相同,需要臨櫃由銀行的服務人員檢視開戶者所提供的開戶資料,藉以判斷是否允許開戶者開戶。Although it is currently possible to open a digital account online through Internet banking or mobile banking, the method of opening such an account depends on the method of identity verification, and the level of the digital account opened is also different. Compared with the digital accounts opened for full identity verification, there are many restrictions, for example, some transactions cannot be executed or the amount that can be used during the transaction is lower. If you want to open a digital account with more complete functions, it is still the same as opening a general account. The bank's service staff must check the account opening information provided by the account holder at the counter to determine whether the account holder is allowed to open the account.

為了要讓透過網路銀行或行動銀行在線上開戶的開戶者不需要在臨櫃進行身分確認,目前也可以在線上開戶過程中讓開戶者上傳證件影本或證件影像,藉以提供銀行的服務人員判斷是否允許開戶者開戶。但這樣的開戶流程便需要等待銀行服務人員審核,無法即時為開戶者開戶。為了解決這樣的問題,也有銀行提供開戶者使用自然人憑證等數位憑證(digital certificate)在線上開戶過程中進行身分檢核。然而,自然人憑證需要透過讀卡機讀取,但並非所有的開戶者都擁有讀卡機可以使用,且即使開戶者擁有讀卡機也常會因為讀卡機所連接之客戶裝置中作業系統的系統環境或於作業系統中執行之應用程式或瀏覽器的原則(policy)造成無法存取讀卡機或無法透過讀卡機取得數位憑證的情況,造成開戶者的不便與困擾。In order to allow account holders who open online accounts through online banking or mobile banking to not need to confirm their identity at the counter, at present, account holders can also upload ID copies or ID images during the online account opening process, so as to provide bank service personnel to judge Whether to allow account holders to open an account. However, such an account opening process needs to wait for bank service personnel to review, and it is impossible to open an account for the account holder immediately. In order to solve this problem, some banks also provide account holders to use digital certificates such as natural person certificates to conduct identity verification during the online account opening process. However, natural person certificates need to be read through a card reader, but not all account holders have a card reader to use, and even if the account holder has a card reader, it is often due to the operating system of the client device connected to the card reader The environment or the policy of the application or browser running in the operating system causes the situation that the card reader cannot be accessed or the digital certificate cannot be obtained through the card reader, causing inconvenience and trouble for the account holder.

綜上所述,可知先前技術中長期以來一直存在目前各種線上開戶方式都可能導致開戶者無法完成即時帳戶申請的問題,因此有必要提出改進的技術手段,來解決此一問題。In summary, it can be seen that there has been a long-standing problem in the prior art that various online account opening methods may cause account holders to fail to complete instant account applications. Therefore, it is necessary to propose improved technical means to solve this problem.

有鑒於先前技術存在目前各種線上開戶方式都可能導致開戶者無法即時完成帳戶申請的問題,本創作遂揭露一種掃碼驗身以完成帳戶申請之系統,其中:In view of the fact that various online account opening methods in the prior art may cause the account opener to be unable to complete the account application in real time, this creation reveals a system for scanning the code to complete the account application, including:

本創作所揭露之掃碼驗身以完成帳戶申請之系統,至少包含:數銀伺服器;行動裝置,用以產生並傳送申請資料至數銀伺服器,及用以接收數銀伺服器產生之驗證序號,並依據驗證序號產生相對應之編碼資料;自動櫃員機,用以透過行動裝置取得編碼資料並解碼編碼資料為待驗資料,及用以傳送待驗資料至數銀伺服器,使數銀伺服器比對待驗資料與驗證序號是否相同,並判斷數銀伺服器傳回之比對結果表示待驗資料通過確認後,連接憑證載具並透過憑證載具取得簽章資料;驗證伺服器,用以驗證自動櫃員機所傳送之簽章資料,並傳送相對應之驗證結果至數銀伺服器,使數銀伺服器判斷簽章資料通過驗證伺服器驗證後,依據申請資料進行對應之帳戶申請作業。The system for scanning the code to complete the account application disclosed in this creation at least includes: a digital bank server; a mobile device for generating and sending application data to the digital bank server, and for receiving the data generated by the digital bank server Verify the serial number, and generate corresponding coded data based on the verified serial number; the ATM is used to obtain coded data through mobile devices and decode the coded data into pending data, and to send the pending data to the DDB server to enable DDB The server compares the data to be verified with the verification serial number, and determines whether the comparison result returned by the digital bank server indicates that the data to be verified is confirmed, and then connects to the certificate carrier and obtains the signature data through the certificate carrier; the verification server, Used to verify the signature data sent by the ATM, and send the corresponding verification result to the digital bank server, so that the digital bank server will determine that the signature data has passed the verification server verification, and then perform the corresponding account application based on the application data .

本創作本創作所揭露之系統如上,與先前技術之間的差異在於本創作由自動櫃員機透過行動裝置取得待驗資料,並在待驗資料通過數銀伺服器的確認後,透過憑證載具取得簽章資料,數銀伺服器在簽章資料通過驗證伺服器的驗證後,依據行動裝置所傳送的申請資料進行對應之帳戶申請作業,藉以解決先前技術所存在的問題,並可以達成讓開戶者自由選擇方便的時間與地點完成帳戶申請的技術功效。The system disclosed in this creation is as above. The difference between this creation and the previous technology is that this creation is obtained by the ATM through the mobile device to obtain the pending data, and after the pending data is confirmed by the digital bank server, it is obtained through the certificate carrier Signature data. After the signature data is verified by the verification server, the Digital Bank server performs the corresponding account application based on the application data sent by the mobile device, so as to solve the problems of the previous technology and achieve the account opening Free to choose a convenient time and place to complete the technical function of the account application.

以下將配合圖式及實施例來詳細說明本創作之特徵與實施方式,內容足以使任何熟習相關技藝者能夠輕易地充分理解本創作解決技術問題所應用的技術手段並據以實施,藉此實現本創作可達成的功效。The following will describe in detail the features and implementation of this creation in conjunction with the drawings and embodiments. The content is sufficient to enable anyone familiar with relevant skills to easily and fully understand the technical means used in this creation to solve technical problems and implement them accordingly. The achievable effect of this creation.

本創作可以讓使用者(開戶者)先使用行動裝置連線到數銀伺服器填寫申請資料後,再使用憑證載具至自動櫃員機完成帳戶申請作業。其中,本創作所提之帳戶申請作業,例如開戶或帳戶升級等,但本創作並不以此為限。This creation allows the user (account opener) to use a mobile device to connect to the digital bank server to fill in the application information, and then use the certificate carrier to the ATM to complete the account application. Among them, the account application tasks mentioned in this creation, such as account opening or account upgrade, etc., but this creation is not limited to this.

本創作所提之數銀伺服器包含但不限於網路銀行伺服器或行動銀行伺服器等透過網路提供服務的計算設備;本創作所提之憑證載具為可以儲存數位憑證(digital certificate)並可以執行如晶片作業系統(Chip Operating System, COS)以加密資料及/或對資料簽章等能夠管理與使用數位憑證的硬體裝置,例如晶片卡(IC卡)等,但本創作並不以此為限;本創作所提之自動櫃員機包含但不限於自動提款機(Automated Teller Machine, ATM)或自動存款機(Cash Deposit Machine, CDM)等提供一種或多種銀行業務之服務的自動化設備。The digital bank server mentioned in this creation includes, but is not limited to, online banking servers or mobile banking servers and other computing devices that provide services over the Internet; the certificate carrier mentioned in this creation can store digital certificates It can also execute hardware devices that can manage and use digital certificates such as Chip Operating System (COS) to encrypt data and/or sign data, such as chip cards (IC cards), but this creation does not Limited to this; the automated teller machines mentioned in this creation include but are not limited to automated devices such as Automated Teller Machine (ATM) or Automated Deposit Machine (Cash Deposit Machine, CDM) that provide one or more banking services .

本創作所提之計算設備包含但不限於一個或多個處理器、一條或多條記憶體模組、以及連接不同硬體元件(包括記憶體模組和處理器)的匯流排等硬體元件。透過所包含之多個硬體元件,計算設備可以載入並執行作業系統,使作業系統在計算設備上運行,也可以執行軟體或程式。另外,計算設備也包含一個外殼,上述之各個硬體元件設置於外殼內。The computing devices mentioned in this creation include but are not limited to one or more processors, one or more memory modules, and hardware components such as buses connecting different hardware components (including memory modules and processors) . Through the included multiple hardware components, the computing device can load and execute the operating system, make the operating system run on the computing device, and can also execute software or programs. In addition, the computing device also includes a housing, and the above-mentioned hardware components are arranged in the housing.

本創作所提之計算設備的匯流排可以包含一種或多個類型,例如包含資料匯流排(data bus)、位址匯流排(address bus)、控制匯流排(control bus)、擴充功能匯流排(expansion bus)、及/或局域匯流排(local bus)等類型的匯流排。計算設備的匯流排包括但不限於的工業標準架構(Industry Standard Architecture, ISA)匯流排、周邊元件互連(Peripheral Component Interconnect, PCI)匯流排、視頻電子標準協會(Video Electronics Standards Association, VESA)局域匯流排、以及串列的通用序列匯流排(Universal Serial Bus, USB)、快速周邊元件互連(PCI Express, PCI-E/PCIe)匯流排等。The bus of the computing device mentioned in this creation can include one or more types, for example, including data bus, address bus, control bus, and extended function bus ( expansion bus), and/or local bus (local bus). The bus bars of computing devices include but are not limited to the Industry Standard Architecture (ISA) bus, Peripheral Component Interconnect (PCI) bus, and the Video Electronics Standards Association (VESA) Bureau Domain bus, serial universal serial bus (Universal Serial Bus, USB), fast peripheral component interconnection (PCI Express, PCI-E/PCIe) bus, etc.

本創作所提之計算設備的處理器與匯流排耦接。處理器包含暫存器(Register)組或暫存器空間,暫存器組或暫存器空間可以完全的被設置在處理晶片上,或全部或部分被設置在處理晶片外並經由專用電氣連接及/或經由匯流排耦接至處理器。處理器可為處理單元、微處理器或任何合適的處理元件。若計算設備為多處理器設備,也就是計算設備包含多個處理器,則計算設備所包含的處理器都相同或類似,且透過匯流排耦接與通訊。處理器可以解釋一個電腦指令或一連串的多個電腦指令以進行特定的運算或操作,例如,數學運算、邏輯運算、資料比對、複製/移動資料等,藉以驅動計算設備中的其他硬體元件或運行作業系統或執行各種程式及/或模組。The processor of the computing device mentioned in this creation is coupled with the bus. The processor contains a register group or register space. The register group or register space can be completely set on the processing chip, or all or part of it can be set outside the processing chip and connected via a dedicated electrical connection And/or coupled to the processor via the bus. The processor may be a processing unit, a microprocessor, or any suitable processing element. If the computing device is a multi-processor device, that is, the computing device includes multiple processors, the processors included in the computing device are all the same or similar, and they are coupled and communicated through a bus. The processor can interpret a computer instruction or a series of multiple computer instructions to perform specific operations or operations, such as mathematical operations, logical operations, data comparison, copy/move data, etc., to drive other hardware components in the computing device Or run the operating system or execute various programs and/or modules.

計算設備中通常也包含一個或多個晶片組(Chipset)。計算設備的處理器可以與晶片組耦接或透過匯流排與晶片組電性連接。晶片組是由一個或多個積體電路(Integrated Circuit, IC)組成,包含記憶體控制器以及周邊輸出入(I/O)控制器等,也就是說,記憶體控制器以及周邊輸出入控制器可以包含在一個積體電路內,也可以使用兩個或更多的積體電路實現。晶片組通常提供了輸出入和記憶體管理功能、以及提供多個通用及/或專用暫存器、計時器等,其中,上述之通用及/或專用暫存器與計時器可以讓耦接或電性連接至晶片組的一個或多個處理器存取或使用。Computing equipment usually also contains one or more chipsets (Chipset). The processor of the computing device can be coupled to the chipset or electrically connected to the chipset through a bus. The chipset is composed of one or more integrated circuits (Integrated Circuit, IC), including memory controller and peripheral input/output (I/O) controller, that is, memory controller and peripheral input/output control The device can be included in one integrated circuit, or it can be implemented using two or more integrated circuits. Chipsets usually provide I/O and memory management functions, as well as multiple general and/or dedicated registers, timers, etc., among which the above-mentioned general and/or dedicated registers and timers can be coupled or One or more processors electrically connected to the chipset are accessed or used.

計算設備的處理器也可以透過記憶體控制器存取安裝於計算設備上的記憶體模組和大容量儲存區中的資料。上述之記憶體模組包含任何類型的揮發性記憶體(volatile memory)及/或非揮發性(non-volatile memory, NVRAM)記憶體,例如靜態隨機存取記憶體(Static Random Access Memory, SRAM)、動態隨機存取記憶體(Dynamic Random Access Memory, DRAM)、唯讀記憶體(Read-Only Memory, ROM)、快閃記憶體(Flash memory)等。上述之大容量儲存區可以包含任何類型的儲存裝置或儲存媒體,例如,硬碟機、光碟(optical disc)、隨身碟(flash drive)、記憶卡(memory card)、固態硬碟(Solid State Disk, SSD)、或任何其他儲存裝置等。也就是說,記憶體控制器可以存取靜態隨機存取記憶體、動態隨機存取記憶體、快閃記憶體、硬碟機、固態硬碟中的資料。The processor of the computing device can also access the data in the memory module and the mass storage area installed on the computing device through the memory controller. The above-mentioned memory modules include any type of volatile memory (volatile memory) and/or non-volatile memory (NVRAM), such as static random access memory (SRAM) , Dynamic Random Access Memory (DRAM), Read-Only Memory (ROM), Flash memory, etc. The above-mentioned mass storage area can include any type of storage device or storage medium, such as hard disk drives, optical discs, flash drives, memory cards, and solid state disks. , SSD), or any other storage device, etc. In other words, the memory controller can access data in static random access memory, dynamic random access memory, flash memory, hard disk drives, and solid state drives.

計算設備的處理器也可以透過周邊輸出入控制器經由周邊輸出入匯流排與周邊輸出裝置、周邊輸入裝置、通訊介面、及GPS接收器等周邊裝置或介面連接並通訊。周邊輸入裝置可以是任何類型的輸入裝置,例如鍵盤、滑鼠、軌跡球、觸控板、搖桿等,周邊輸出裝置可以是任何類型的輸出裝置,例如顯示器、印表機等,周邊輸入裝置與周邊輸出裝置也可以是同一裝置,例如觸控螢幕等。通訊介面可以包含無線通訊介面及/或有線通訊介面,無線通訊介面可以包含支援無線區域網路(如Wi-Fi、Zigbee等)、藍牙、紅外線、近場通訊(Near-field communication, NFC)、3G/4G/5G等行動通訊網路(蜂巢式網路)或其他無線資料傳輸協定的介面,有線通訊介面可為乙太網路裝置、DSL數據機、纜線(Cable)數據機、非同步傳輸模式(Asynchronous Transfer Mode, ATM)裝置、或光纖通訊介面及/或元件等。處理器可以週期性地輪詢(polling)各種周邊裝置與介面,使得計算設備能夠透過各種周邊裝置與介面進行資料的輸入與輸出,也能夠與具有上面描述之硬體元件的另一個計算設備進行通訊。The processor of the computing device can also connect and communicate with peripheral output devices, peripheral input devices, communication interfaces, and GPS receivers and other peripheral devices or interfaces through peripheral I/O controllers via peripheral I/O buses. The peripheral input device can be any type of input device, such as a keyboard, mouse, trackball, touchpad, joystick, etc., the peripheral output device can be any type of output device, such as a display, a printer, etc., a peripheral input device It can also be the same device as the peripheral output device, such as a touch screen. The communication interface can include a wireless communication interface and/or a wired communication interface. The wireless communication interface can include support for wireless local area networks (such as Wi-Fi, Zigbee, etc.), Bluetooth, infrared, and near-field communication (NFC), 3G/4G/5G and other mobile communication network (cellular network) or other wireless data transmission protocol interface, wired communication interface can be Ethernet device, DSL modem, cable modem, asynchronous transmission Mode (Asynchronous Transfer Mode, ATM) devices, or optical fiber communication interfaces and/or components, etc. The processor can periodically poll various peripheral devices and interfaces, so that the computing device can input and output data through various peripheral devices and interfaces, and can also communicate with another computing device with the hardware components described above. communication.

以下先以「第1圖」本創作所提之掃碼驗身以完成帳戶申請之架構圖來說明本創作的系統運作。如「第1圖」所示,本創作之系統含有行動裝置110、自動櫃員機120、憑證載具130、驗證伺服器150、數銀伺服器170,及可附加的身分確認伺服器160、中繼伺服器190。其中,行動裝置110、自動櫃員機120、驗證伺服器150、身分確認伺服器160、數銀伺服器170及中繼伺服器190為計算設備。The following first uses the scan code mentioned in the creation of "Picture 1" to complete the structure diagram of the account application to illustrate the system operation of this creation. As shown in "Figure 1", the system of this creation includes a mobile device 110, an ATM 120, a certificate carrier 130, an authentication server 150, a digital bank server 170, and an additional identity verification server 160, relay Server 190. Among them, the mobile device 110, the automated teller machine 120, the verification server 150, the identity verification server 160, the digital bank server 170, and the relay server 190 are computing devices.

行動裝置110可以透過無線網路與數銀伺服器170連接,並可以傳送資料或訊號給數銀伺服器170,也可以接收數銀伺服器170所傳送的資料或訊號。本創作所提之無線網路包含行動通訊網路(蜂巢式網路)或無線區域網路等。The mobile device 110 can be connected to the digital bank server 170 via a wireless network, and can send data or signals to the digital bank server 170, and can also receive data or signals sent by the digital bank server 170. The wireless network mentioned in this creation includes mobile communication network (cellular network) or wireless local area network.

行動裝置110負責產生申請資料。一般而言,行動裝置110可以提供資料輸入介面給使用者輸入申請資料。在本創作中,申請資料包含但不限於使用者的姓名、識別資料、性別、生日、住址、通訊資料等,其中,使用者的識別資料通常為身分證號、護照號碼或簽證號碼等與客戶具有一對一關係的資料,但本創作並不以此為限;使用者的通訊資料包含但不限於手機號碼、電子郵件帳號、即時通訊帳號等能夠與客戶連絡的資料。在部分的實施例中,申請資料也可以包含使用者持有之身分證件的證件影像。其中,使用者的身分證件通常是身分證、駕照、健保卡等具有開戶者之面部影像的證件。The mobile device 110 is responsible for generating application data. Generally speaking, the mobile device 110 can provide a data input interface for the user to input application data. In this creation, the application information includes but is not limited to the user’s name, identification data, gender, birthday, address, communication data, etc., among which the user’s identification data is usually the ID number, passport number or visa number, etc. and the customer Data with a one-to-one relationship, but this creation is not limited to this; the user’s communication data includes, but is not limited to, mobile phone numbers, email accounts, instant messaging accounts, and other data that can be connected to customers. In some embodiments, the application data may also include a certificate image of an identity certificate held by the user. Among them, the user's identity document is usually an identity card, a driver's license, a health insurance card, and other documents that have the facial image of the account holder.

行動裝置110也負責將所產生的申請資料傳送給數銀伺服器170,並負責接收數銀伺服器170所傳回的驗證序號。行動裝置110也負責產生與所接收到之驗證序號相對應的編碼資料。行動裝置110所產生的編碼資料通常是QR code等二維條碼,但本創作並不以此為限,例如,編碼資料也可以是一維條碼或一組由一定數量之文字、字母、數字、符號任意排列而成的字符串。The mobile device 110 is also responsible for sending the generated application data to the digital bank server 170 and is responsible for receiving the verification serial number returned by the digital bank server 170. The mobile device 110 is also responsible for generating coded data corresponding to the received verification serial number. The coded data generated by the mobile device 110 is usually a two-dimensional bar code such as QR code, but this creation is not limited to this. For example, the coded data can also be a one-dimensional bar code or a set of characters, letters, numbers, and numbers. A string of arbitrary arrangement of symbols.

自動櫃員機120可以透過有線網路或無線網路與驗證伺服器150及數銀伺服器170連接,並可以傳送資料或訊號給驗證伺服器150或數銀伺服器170,也可以接收驗證伺服器150或數銀伺服器170所傳送的資料或訊號。本創作所提之有線網路例如乙太網路或光纖網路等,但本創作並不以此為限。The ATM 120 can be connected to the verification server 150 and the digital bank server 170 via a wired or wireless network, and can send data or signals to the verification server 150 or the digital bank server 170, and can also receive the verification server 150 Or the data or signal sent by the digital bank server 170. The wired network mentioned in this creation is such as Ethernet or optical fiber network, but this creation is not limited to this.

自動櫃員機120也可以提供使用者介面給使用者輸入使用者的識別資料。The automated teller machine 120 may also provide a user interface for the user to input user identification data.

自動櫃員機120負責透過行動裝置110取得編碼資料。一般而言,自動櫃員機120中可以設置掃描裝置(圖中未示),藉以透過掃描裝置掃描行動裝置110所顯示的編碼資料來取得編碼資料,但本創作並不以此為限,例如,自動櫃員機120中也可以設置近端通訊裝置(圖中未示),並透過近端通訊裝置接收行動裝置110所傳送之編碼資料來取得編碼資料。其中,近端通訊裝置可以是近場通訊裝置, 也可以是使用藍牙或紅外線等無線通訊裝置,本創作並沒有特別的限制。The automated teller machine 120 is responsible for obtaining coded data through the mobile device 110. Generally speaking, a scanning device (not shown in the figure) can be installed in the ATM 120 to obtain the coded data by scanning the coded data displayed by the mobile device 110 through the scanning device, but this creation is not limited to this, for example, automatic The teller machine 120 can also be provided with a near-end communication device (not shown in the figure), and the encoded data transmitted by the mobile device 110 can be received through the near-end communication device to obtain the encoded data. Among them, the near-end communication device may be a near-field communication device, or a wireless communication device such as Bluetooth or infrared, and there is no special restriction on this creation.

自動櫃員機120也負責將所取得的編碼資料解碼為待驗資料,並負責將解碼產生之待驗資料傳送至數銀伺服器170。在部分的實施例中,自動櫃員機120也可以將使用者的識別資料與待驗資料一併傳送給數銀伺服器170。The automated teller machine 120 is also responsible for decoding the obtained encoded data into data to be verified, and is responsible for transmitting the data to be verified generated by the decoding to the digital bank server 170. In some embodiments, the automated teller machine 120 may also send the user's identification data and the data to be verified to the digital bank server 170 together.

自動櫃員機120也負責接收數銀伺服器170所傳送之比對結果,並負責在判斷所接收到之比對結果是否表示待驗資料通過確認。自動櫃員機120也負責在判斷比對結果表示待驗資料通過確認時,連接憑證載具130。一般而言,自動櫃員機120上可以設置憑證載具130的連接介面,如晶片卡插槽、記憶卡插槽、USB插槽等,使得憑證載具130可以透過相對應的連接介面與自動櫃員機120連接。舉例來說,當憑證載具130為晶片卡時,連接介面可以是晶片卡插槽。The automated teller machine 120 is also responsible for receiving the comparison result sent by the digital bank server 170, and is responsible for determining whether the received comparison result indicates that the data to be inspected has passed the confirmation. The automated teller machine 120 is also responsible for connecting to the credential carrier 130 when it is judged that the comparison result indicates that the data to be checked is confirmed. Generally speaking, the automatic teller machine 120 can be provided with a connection interface for the certificate carrier 130, such as a chip card slot, a memory card slot, a USB slot, etc., so that the certificate carrier 130 can communicate with the automatic teller machine 120 through a corresponding connection interface. connection. For example, when the credential carrier 130 is a chip card, the connection interface may be a chip card slot.

自動櫃員機120也負責透過憑證載具130取得簽章資料。在本創作中,簽章資料可以包含目標資料及憑證載具130對目標資料簽章所產生的簽章值,在部分的實施例中,簽章資料也可以包含目標資料及/或憑證載具130所儲存的數位憑證。一般而言,目標資料可以包含自動櫃員機120所產生之欲透過驗證伺服器150傳送給數銀伺服器170的資料,例如客戶識別資料或隨機產生之特定長度的資料等,但本創作並不以此為限。The automated teller machine 120 is also responsible for obtaining signature data through the credential carrier 130. In this creation, the signature data may include the target data and the signature value generated by the certificate carrier 130 to sign the target data. In some embodiments, the signature data may also include the target data and/or the certificate carrier. 130 stored digital certificates. Generally speaking, the target data can include data generated by the ATM 120 to be sent to the digital bank server 170 through the verification server 150, such as customer identification data or randomly generated data of a specific length, but this creation does not This is limited.

一般而言,自動櫃員機120可以取得憑證密碼,並可以執行預先儲存或安裝之憑證載具130的驅動程式以驅動憑證載具130,藉以在憑證載具130被驅動後,將所取得的憑證密碼及目標資料傳送到憑證載具130,並接收憑證載具130所傳回的簽章資料。其中,自動櫃員機120可以顯示密碼輸入介面給使用者輸入憑證密碼來取得憑證密碼。另外,在部分的實施例中,自動櫃員機120也可以預先安裝安控元件,並可以執行安控元件,藉以透過安控元件將憑證密碼及目標資料傳送給憑證載具130,及透過安控元件接收憑證載具130所傳回的簽章資料。但自動櫃員機120透過憑證載具130取得簽章資料的方式並不以上述為限。Generally speaking, the ATM 120 can obtain the certificate password, and can execute the pre-stored or installed driver of the certificate carrier 130 to drive the certificate carrier 130, so that after the certificate carrier 130 is driven, the obtained certificate password And the target data are sent to the certificate carrier 130, and the signature data returned by the certificate carrier 130 is received. Among them, the automated teller machine 120 may display a password input interface for the user to input the certificate password to obtain the certificate password. In addition, in some embodiments, the ATM 120 can also be pre-installed with security components, and can execute the security components, so as to transmit the certificate password and target data to the certificate carrier 130 through the security components, and through the security components Receive the signature data returned by the certificate carrier 130. However, the manner in which the automated teller machine 120 obtains the signature data through the certificate carrier 130 is not limited to the above.

自動櫃員機120也負責將簽章資料傳送給驗證伺服器150。在部分的實施例中,自動櫃員機120也可以將識別資料及簽章資料一同傳送給驗證伺服器150。The automated teller machine 120 is also responsible for sending the signature data to the verification server 150. In some embodiments, the automated teller machine 120 may also send the identification data and the signature data to the verification server 150 together.

自動櫃員機120還可以接收數銀伺服器170所傳送的作業處理結果或提示訊息,或可以接收驗證伺服器150所傳送的驗證結果,並可以顯示所接收到的作業處理結果/提示訊息/驗證結果。甚至,自動櫃員機120也可以依據作業處理結果/提示訊息/驗證結果播放相對應的聲音或影像。The ATM 120 can also receive the processing result or prompt message sent by the digital bank server 170, or can receive the verification result sent by the verification server 150, and can display the received processing result/prompt message/verification result . Furthermore, the ATM 120 can also play corresponding sounds or images according to the operation processing result/prompt message/verification result.

憑證載具130負責儲存私鑰(private key)及數位憑證。其中,私鑰通常為憑證載具130的持有者所擁有;數位憑證包含與憑證載具130所儲存之私鑰對應的公鑰(public key)及憑證序號。The certificate carrier 130 is responsible for storing a private key (private key) and a digital certificate. The private key is usually owned by the holder of the certificate carrier 130; the digital certificate includes a public key corresponding to the private key stored in the certificate carrier 130 and a certificate serial number.

憑證載具130可以使用所儲存之私鑰加密目標資料或對目標資料簽章。憑證載具130在對目標資料簽章後,可以產生簽章資料,並可以將所產生的簽章資料傳回自動櫃員機120。一般而言,憑證載具130所儲存的私鑰經過加密,但本創作並不以為限。憑證載具130可以接收自動櫃員機120所傳送的憑證密碼,並使用所取得的憑證密碼解密所儲存的私鑰。The certificate carrier 130 can use the stored private key to encrypt or sign the target data. After the certificate carrier 130 signs the target data, it can generate signature data, and can transmit the generated signature data back to the ATM 120. Generally speaking, the private key stored in the certificate carrier 130 is encrypted, but this creation is not limited. The certificate carrier 130 can receive the certificate password sent by the automated teller machine 120 and use the obtained certificate password to decrypt the stored private key.

驗證伺服器150可以透過有線或無線網路與自動櫃員機120、數銀伺服器170及身分確認伺服器160連接,並可以接收自動櫃員機120、數銀伺服器170及/或身分確認伺服器160所傳送的資料或訊號,也可以傳送資料或訊號給自動櫃員機120、數銀伺服器170及/或身分確認伺服器160。The authentication server 150 can be connected to the ATM 120, the digital bank server 170, and the identity verification server 160 through a wired or wireless network, and can receive the automatic teller machine 120, the digital bank server 170 and/or the identity verification server 160. The transmitted data or signal may also be transmitted to the automated teller machine 120, the digital bank server 170 and/or the identity verification server 160.

驗證伺服器150負責接收自動櫃員機120所傳送的簽章資料,並負責驗證所接收到的簽章資料以產生相對應之驗證結果,及負責將所產生之驗證結果傳送到數銀伺服器170(及自動櫃員機120)。一般而言,驗證伺服器150可以如習知驗證簽章的方式,由簽章資料所包含的數位憑證中取得使用者的公鑰,並使用使用者的公鑰與簽章資料所包含的目標資料驗證簽章資料以產生驗證結果。當簽章資料通過驗證時,驗證伺服器150所產生的驗證結果可以包含簽章資料中的目標資料,但本創作並不以此為限。The verification server 150 is responsible for receiving the signature data sent by the ATM 120, and is responsible for verifying the received signature data to generate the corresponding verification result, and is responsible for sending the generated verification result to the digital bank server 170 ( And automatic teller machine 120). Generally speaking, the verification server 150 can obtain the user's public key from the digital certificate contained in the signature data in a conventional way of verifying the signature, and use the user's public key and the target contained in the signature data. Data verification signature data to generate verification results. When the signature data passes the verification, the verification result generated by the verification server 150 may include the target data in the signature data, but this creation is not limited to this.

驗證伺服器150也可以接收自動櫃員機120所傳送的識別資料。在部分的實施例中,驗證伺服器150可以由所接收到之簽章資料包含的數位憑證中讀出憑證序號,並可以產生包含所接收之識別資料及所讀出之憑證序號的憑證確認資料,也可以將所產生的憑證確認資料傳送給身分確認伺服器160。The verification server 150 can also receive the identification data sent by the automated teller machine 120. In some embodiments, the verification server 150 can read the certificate serial number from the digital certificate included in the received signature data, and can generate the certificate confirmation data including the received identification data and the read certificate serial number , The generated certificate confirmation data can also be sent to the identity confirmation server 160.

驗證伺服器150也可以接收身分確認伺服器160所傳送的身分確認結果,並可以在所接收到之簽章資料通過驗證伺服器150自身的驗證且所接收到之身分確認結果表示所產生之憑證確認資料通過身分確認伺服器160的驗證時,才產生表示簽章資料通過驗證的驗證結果,反之,若簽章資料沒有通過驗證伺服器150的驗證,或身分確認結果表示憑證確認資料沒有通過身分確認伺服器160的驗證時,驗證伺服器150可以產生表示簽章資料沒有通過驗證的驗證結果。The verification server 150 can also receive the identity verification result sent by the identity verification server 160, and can verify the received signature data by the verification server 150 itself and the received identity verification result represents the generated certificate Only when the verification data passes the verification of the identity verification server 160, a verification result indicating that the signature data has passed the verification is generated. On the contrary, if the signature data does not pass the verification of the verification server 150, or the identity verification result indicates that the certificate verification data does not pass the identity When verifying the verification by the server 160, the verification server 150 may generate a verification result indicating that the signature data has not passed the verification.

身分確認伺服器160可以透過有線或無線網路與驗證伺服器150連接,並可以接收驗證伺服器150所傳送的資料或訊號,也可以傳送資料或訊號給驗證伺服器150。The identity verification server 160 can be connected to the verification server 150 via a wired or wireless network, and can receive data or signals sent by the verification server 150, and can also send data or signals to the verification server 150.

身分確認伺服器160可以接收驗證伺服器150所傳送的憑證確認資料,並可以由設置於身分確認伺服器160的儲存媒體(圖中未示)或與身分確認伺服器160連接之外部儲存裝置(圖中未示)讀出與憑證確認資料中之憑證序號相對應之數位憑證的相關資料。身分確認伺服器160所讀出之數位憑證的相關資料包含憑證擁有者的識別資料。The identity verification server 160 can receive the credential verification data sent by the verification server 150, and it can be configured from a storage medium (not shown in the figure) or an external storage device connected to the identity verification server 160 ( (Not shown in the picture) Read out the relevant data of the digital voucher corresponding to the voucher serial number in the voucher confirmation data. The relevant data of the digital certificate read by the identity verification server 160 includes the identification data of the certificate owner.

身分確認伺服器160也可以判斷所讀出之數位憑證的相關資料所包含之憑證擁有者的識別資料是否與憑證確認資料中的識別資料相符,並產生相對應的身分確認結果,也就是產生表示憑證確認資料中之識別資料是否與憑證確認資料中的數位憑證關聯的身分確認結果,及將所產生的身分確認結果傳回驗證伺服器150。若憑證擁有者之識別資料與憑證確認資料中的識別資料相同,則身分確認伺服器160可以確認憑證確認資料與驗證伺服器150所接收到之簽章資料中的數位憑證的擁有者相符,也就是確認憑證確認資料中之識別資料與憑證確認資料中的數位憑證關聯,反之,若憑證擁有者之識別資料與憑證確認資料中的識別資料不同或不相符,則身分確認伺服器160可以判斷憑證確認資料與數位憑證之擁有者不符,即確認憑證確認資料中之識別資料與憑證確認資料中的數位憑證沒有關聯。The identity verification server 160 can also determine whether the identification data of the certificate owner contained in the relevant data of the digital certificate read out is consistent with the identification data in the certificate confirmation data, and generate a corresponding identity confirmation result, that is, a representation Whether the identification data in the certificate confirmation data is associated with the identity confirmation result of the digital certificate in the certificate confirmation data, and the generated identity confirmation result is returned to the authentication server 150. If the identification data of the certificate owner is the same as the identification data in the certificate confirmation data, the identity verification server 160 can confirm that the certificate confirmation data matches the owner of the digital certificate in the signature data received by the verification server 150. It is to confirm that the identification data in the certificate confirmation data is associated with the digital certificate in the certificate confirmation data. On the contrary, if the identification data of the certificate owner is different or inconsistent with the identification data in the certificate confirmation data, the identity confirmation server 160 can determine the certificate The confirmation data does not match the owner of the digital certificate, that is, the identification data in the certificate confirmation data is not related to the digital certificate in the certificate confirmation data.

數銀伺服器170可以透過有線或無線網路與行動裝置110、自動櫃員機120、驗證伺服器150連接,並可以接收行動裝置110、自動櫃員機120及/或驗證伺服器150所傳送的資料或訊號,也可以傳送資料或訊號給行動裝置110、自動櫃員機120及/或驗證伺服器150。The digital bank server 170 can be connected to the mobile device 110, the automated teller machine 120, and the verification server 150 via a wired or wireless network, and can receive data or signals sent by the mobile device 110, the automated teller machine 120 and/or the verification server 150 , It is also possible to send data or signals to the mobile device 110, the automated teller machine 120 and/or the verification server 150.

數銀伺服器170負責接收行動裝置110所傳送之申請資料,並負責產生與所接收到之申請資料對應的驗證序號。數銀伺服器170可以使用流水號產生驗證序號,也可以對申請資料進行特定運算以產生驗證序號,本創作並沒有特別的限制。上述之特定運算例如雜湊(Hash)運算、或由申請資料中抽取出特定位置的字元進行組合等,但本創作並不以此為限。The digital bank server 170 is responsible for receiving the application data sent by the mobile device 110, and is responsible for generating a verification serial number corresponding to the received application data. The digital silver server 170 can use the serial number to generate the verification serial number, and can also perform specific operations on the application materials to generate the verification serial number. There is no special restriction on this creation. The above-mentioned specific operations such as hash operations, or combinations of characters in specific positions extracted from the application materials, but this creation is not limited to this.

數銀伺服器170也負責接收自動櫃員機120所傳送的待驗資料,並負責比對接收到的待驗資料是否與所產生的驗證序號相同,及負責將所產生之比對待驗資料與驗證序號是否相同的比對結果傳送給自動櫃員機120。其中,數銀伺服器170可以接收自動櫃員機120連同待驗資料一起傳送之識別資料,並依據所接收到之識別資料讀取驗證序號,藉以比對待驗資料與驗證序號是否相同。The digital bank server 170 is also responsible for receiving the pending data sent by the ATM 120, and is responsible for comparing the received pending data with the generated verification serial number, and is responsible for comparing the generated pending data with the verification serial number Whether the comparison result is the same is transmitted to the automated teller machine 120. Wherein, the digital bank server 170 can receive the identification data sent by the ATM 120 together with the data to be inspected, and read the verification serial number according to the received identification data to compare whether the data to be inspected and the verification serial number are the same.

數銀伺服器170也負責接收驗證伺服器150所傳送的驗證結果,並負責判斷所接收到的驗證結果表示簽章資料通過驗證後,依據行動裝置110所傳送之申請資料進行對應的帳戶申請作業。數銀伺服器170也可以將帳戶申請作業的作業處理結果傳送給自動櫃員機120。其中,作業處理結果可以表示帳戶申請作業成功完成或表示帳戶申請作業無法完成,作業處理結果也可以包含帳戶申請作業無法完成的原因,但本創作並不以此為限。The digital bank server 170 is also responsible for receiving the verification result sent by the verification server 150, and is responsible for judging that the received verification result indicates that after the signature data has been verified, it performs the corresponding account application based on the application data sent by the mobile device 110 . The digital bank server 170 may also transmit the operation processing result of the account application operation to the automated teller machine 120. The job processing result may indicate that the account application job was successfully completed or that the account application job could not be completed. The job processing result may also include the reason why the account application job could not be completed, but this creation is not limited to this.

另外,為了安全性、管理性、擴充性及/或其他考量因素,本創作還可以包含中繼伺服器190。中繼伺服器190可以透過有線或無線網路與自動櫃員機120、驗證伺服器150與數銀伺服器170連接,使得自動櫃員機120、驗證伺服器150與數銀伺服器170所發出的資料或訊號可以透過中繼伺服器190轉送,例如,中繼伺服器190可以接收自動櫃員機120所傳送的待驗資料並將所接收到的待驗資料傳送給數銀伺服器170,也可以接收數銀伺服器170所傳送的比對結果並將所接收到的比對結果傳送至自動櫃員機120,也可以接收自動櫃員機120所傳送的簽章資料並將所接收到的簽章資料傳送至驗證伺服器150,也可以接收驗證伺服器150所傳送的驗證結果並將所接收到的驗證結果傳送給數銀伺服器170(及自動櫃員機120),也可以接收數銀伺服器170所產生的作業處理結果並將作業處理結果傳送至自動櫃員機120等。In addition, for security, management, scalability, and/or other considerations, the creation may also include a relay server 190. The relay server 190 can be connected to the ATM 120, the verification server 150, and the digital bank server 170 through a wired or wireless network, so that the ATM 120, the verification server 150, and the digital bank server 170 can send data or signals It can be forwarded through the relay server 190. For example, the relay server 190 can receive the pending data sent by the ATM 120 and send the received pending data to the digital bank server 170, or it can receive the digital bank server. The comparison result sent by the server 170 and the received comparison result are sent to the automatic teller machine 120, and it can also receive the signature data sent by the automatic teller machine 120 and send the received signature data to the verification server 150 , It can also receive the verification result sent by the verification server 150 and send the received verification result to the digital bank server 170 (and the automated teller machine 120), or receive the operation processing result generated by the digital bank server 170 and The job processing result is transmitted to the automated teller machine 120, etc.

需要特別說明的是,若本創作中包含中繼伺服器190,則自動櫃員機120可以包含電文閘道器(圖中未示),電文閘道器可以將自動櫃員機120欲傳送的資料轉換為電文後再傳送給中繼伺服器190,中繼伺服器190可以將所接收到的電文還原為自動櫃員機120欲傳送的資料後,在轉送到目的地,也就是驗證伺服器150或數銀伺服器170;中繼伺服器190也可以將驗證伺服器150或數銀伺服器170傳送給自動櫃員機120的電文轉換為電文後再傳送給自動櫃員機120,自動櫃員機120可以在接收到電文後將所接收到的電文還原為驗證伺服器150或數銀伺服器170所發出的資料。It should be noted that if the creation includes a relay server 190, the ATM 120 can include a text gateway (not shown in the figure), and the text gateway can convert the data to be sent by the ATM 120 into a text Then send it to the relay server 190. The relay server 190 can restore the received message to the data to be sent by the ATM 120, and then forward it to the destination, which is the verification server 150 or the digital bank server. 170; the relay server 190 can also convert the telegram sent by the verification server 150 or the digital bank server 170 to the ATM 120 into a telegram and then send it to the ATM 120. The ATM 120 can receive the telegram after receiving the telegram. The received message is restored to the data sent by the verification server 150 or the digital bank server 170.

接著以一個實施例來解說本創作的運作過程,並請參照「第2A圖」本創作所提之掃碼驗身以完成帳戶申請之流程圖。在本實施例中,假設行動裝置110為手機,且自動櫃員機120、驗證伺服器150及數銀伺服器170間是透過中繼伺服器190傳送資料或訊號,但本創作並不以此為限。Next, an example is used to explain the operation process of this creation, and please refer to "Figure 2A" for the scan code mentioned in this creation to complete the flow chart of account application. In this embodiment, it is assumed that the mobile device 110 is a mobile phone, and the ATM 120, the verification server 150, and the digital bank server 170 transmit data or signals through the relay server 190, but this creation is not limited to this .

首先,使用者可以操作行動裝置110連線到數銀伺服器170,使得行動裝置110可以產生申請資料並可以將所產生的申請資料傳送給數銀伺服器170(步驟210)。在本實施例中,假設使用者可以操作行動裝置110執行行動銀行應用程式,行動銀行應用程式在被執行後,使用者可以在行動銀行應用程式的初始畫面中選擇「開戶」的功能或可以在行動銀行應用程式的帳戶設定介面中選擇「升級」的功能,之後,行動銀行應用程式可以提供的申請資料輸入介面,使用者可以在申請資料輸入介面中輸入申請資料,使得行動裝置110取得申請資料。First, the user can operate the mobile device 110 to connect to the digital bank server 170, so that the mobile device 110 can generate application data and send the generated application data to the digital bank server 170 (step 210). In this embodiment, it is assumed that the user can operate the mobile device 110 to execute the mobile banking application. After the mobile banking application is executed, the user can select the "account opening" function in the initial screen of the mobile banking application or Select the "upgrade" function in the account setting interface of the mobile banking application. After that, the application data input interface provided by the mobile banking application. The user can enter application data in the application data input interface so that the mobile device 110 can obtain the application data .

在數銀伺服器170接收到行動裝置110所傳送的申請資料後,數銀伺服器170可以產生與所接收到之申請資料對應的驗證序號,並將所產生的驗證序號傳送到行動裝置110(步驟221),及可以儲存所接收到的申請資料與驗證序號。在本實施例中,假設數銀伺服器170可以在儲存申請資料與驗證序號時,將申請資料中所包含之使用者的識別資料作為申請資料與驗證序號的索引。After the digital bank server 170 receives the application data sent by the mobile device 110, the digital bank server 170 can generate a verification serial number corresponding to the received application data, and send the generated verification serial number to the mobile device 110 ( Step 221), and can store the received application data and verification serial number. In this embodiment, it is assumed that the digital bank server 170 can use the user identification data included in the application data as an index of the application data and the verification serial number when storing the application data and the verification serial number.

在行動裝置110接收到數銀伺服器170所傳回的驗證序號後,可以產生與所接收到之驗證序號對應的編碼資料(步驟225)。在本實施例中,假設行動裝置110是由行動銀行應用程式接收驗證序號並產生包含驗證序號的QR code。After the mobile device 110 receives the verification serial number returned by the digital bank server 170, it can generate encoded data corresponding to the received verification serial number (step 225). In this embodiment, it is assumed that the mobile device 110 receives the verification serial number from the mobile banking application and generates a QR code containing the verification serial number.

在行動裝置110產生編碼資料(步驟225)後,自動櫃員機120可以透過行動裝置110取得編碼資料,並解碼編碼資料為待驗資料(步驟230)。在本實施例中,使用者在抵達自動櫃員機120後,可以操作行動裝置110執行行動銀行應用程式,使得行動銀行應用程式顯示所產生的QR code(或使用者也可以操作行動裝置110顯示包含行動銀行應用程式所產生之QR code的影像),使用者也可以操作自動櫃員機120,若自動櫃員機120之操作介面310如「第3A圖」所示,使用者可以選擇左下角之「身分驗證」的功能選項311,使得自動櫃員機120可以顯示如「第3B圖」之輸入介面330以提供使用者輸入身分證字號(識別資料),並可以透過自身所包含的條碼掃描裝置掃描行動裝置110所顯示的QR code以取得編碼資料。After the mobile device 110 generates the coded data (step 225), the automated teller machine 120 can obtain the coded data through the mobile device 110, and decode the coded data into the pending data (step 230). In this embodiment, after arriving at the ATM 120, the user can operate the mobile device 110 to execute the mobile banking application, so that the mobile banking application displays the generated QR code (or the user can also operate the mobile device 110 to display the mobile banking application The QR code image generated by the banking application), the user can also operate the ATM 120. If the operation interface 310 of the ATM 120 is as shown in "Figure 3A", the user can select the "Identity Verification" in the lower left corner The function option 311 enables the ATM 120 to display the input interface 330 as shown in "Figure 3B" to provide the user to enter the ID number (identification data), and to scan the display of the mobile device 110 through the barcode scanning device included in it QR code to obtain coding data.

在自動櫃員機120取得待驗資料後,可以將待驗資料傳送給數銀伺服器170。在本實施例中,假設自動櫃員機120可以使用所包含的電文閘道器(圖中未示)透過中繼伺服器190將識別資料及待驗資料傳送給數銀伺服器170。After the automated teller machine 120 obtains the data to be inspected, the data to be inspected can be sent to the digital bank server 170. In this embodiment, it is assumed that the automated teller machine 120 can use the included text gateway (not shown in the figure) to transmit the identification data and the pending data to the digital bank server 170 through the relay server 190.

數銀伺服器170在接收到自動櫃員機120所傳送的識別資料與待驗資料後,可以比對所接收到的待驗資料是否與先前所產生之驗證序號相同,並將比對所產生之相對應的比對結果傳回自動櫃員機120(步驟250)。在本實施例中,假設數銀伺服器170可以依據所接收到的識別資料讀出先前所產生的驗證序號,進而比對所接收到的待驗資料與所讀出的驗證序號以產生相對應的比對結果,並透過中繼伺服器190將比對結果傳回自動櫃員機120。After receiving the identification data and the data to be verified from the ATM 120, the digital bank server 170 can compare whether the received data to be verified is the same as the previously generated verification serial number, and compare the generated phases. The corresponding comparison result is transmitted back to the ATM 120 (step 250). In this embodiment, it is assumed that the digital silver server 170 can read the previously generated verification serial number based on the received identification data, and then compare the received data to be verified with the read verification serial number to generate a corresponding The result of the comparison is sent back to the ATM 120 through the relay server 190.

自動櫃員機120在接收到數銀伺服器170所傳送的比對結果後,可以判斷所接收到的比對結果是否表示所取得的待驗資料通過數銀伺服器170的確認。若否,則自動櫃員機120可以顯示相對應之錯誤訊息。After the automated teller machine 120 receives the comparison result sent by the digital bank server 170, it can determine whether the received comparison result indicates that the obtained data to be checked is confirmed by the digital bank server 170. If not, the ATM 120 can display the corresponding error message.

若自動櫃員機120所接收到的比對結果表示所取得的待驗資料通過數銀伺服器170的確認,則自動櫃員機120可以提示使用者連接憑證載具130及自動櫃員機120,並透過所連接的憑證載具130取得簽章資料(步驟260),及將透過憑證載具130取得之簽章資料傳送給驗證伺服器150。在本實施例中,假設如「第2B圖」之流程所示,若使用者所持有的憑證載具130為實體的自然人憑證,則自動櫃員機120可以執行已預先安裝之自然人憑證的驅動程式及顯示插入自然人憑證的提示訊息,並可以在使用者將自然人憑證插入自動櫃員機120的晶片卡插槽而連接憑證載具130及自動櫃員機120(步驟262)後,顯示憑證密碼的密碼輸入介面,及可以在使用者於密碼輸入介面中輸入憑證密碼後取得憑證密碼,並可以透過預先安裝於自動櫃員機120內的安控元件傳送目標資料及所取得的憑證密碼給憑證載具130(步驟263),使得憑證載具130可以使用自動櫃員機120所提供的憑證密碼解密所儲存的私鑰,並可以使用解密所得的私鑰對自動櫃員機120所傳送的目標資料簽章以產生簽章資料(步驟265)後,將簽章資料傳回自動櫃員機120,使自動櫃員機120可以透過安控元件接收憑證載具130所產生的簽章資料(步驟267),並可以透過中繼伺服器190將使用者所輸入之識別資料及憑證載具130所產生的簽章資料傳送給驗證伺服器150(步驟268)。If the comparison result received by the automated teller machine 120 indicates that the acquired data for inspection is confirmed by the digital bank server 170, the automated teller machine 120 can prompt the user to connect the certificate carrier 130 and the automated teller machine 120, and use the connected The certificate carrier 130 obtains the signature data (step 260), and sends the signature data obtained through the certificate carrier 130 to the verification server 150. In this embodiment, it is assumed that as shown in the process shown in "Figure 2B", if the certificate carrier 130 held by the user is a physical natural person certificate, the automated teller machine 120 can execute the driver of the pre-installed natural person certificate And display the prompt message for inserting the natural person certificate. After the user inserts the natural person certificate into the chip card slot of the ATM 120 and connects the certificate carrier 130 and the ATM 120 (step 262), the password input interface of the certificate password can be displayed. And the certificate password can be obtained after the user enters the certificate password in the password input interface, and the target data and the obtained certificate password can be sent to the certificate carrier 130 through the security control component pre-installed in the ATM 120 (step 263) , So that the certificate carrier 130 can use the certificate password provided by the ATM 120 to decrypt the stored private key, and use the decrypted private key to sign the target data sent by the ATM 120 to generate signature data (step 265 ), the signature data is sent back to the ATM 120, so that the ATM 120 can receive the signature data generated by the credential carrier 130 through the security component (step 267), and can send the user's signature data through the relay server 190 The input identification data and the signature data generated by the certificate carrier 130 are sent to the verification server 150 (step 268).

在驗證伺服器150接收到自動櫃員機120所傳送的識別資料及簽章資料後,可以驗證所接收到的簽章資料以產生相對應的驗證結果,並可以將所產生的驗證結果傳回數銀伺服器170(步驟270)。在本實施例中,假設驗證伺服器150可以由簽章資料中之數位憑證中讀出憑證序號,並可以依據憑證序號取得對應之公鑰,及可以使用所取得之公鑰驗證簽章資料以產生相對應的驗證結果,也就是產生簽章資料是否通過驗證的驗證結果,驗證伺服器150並可以透過中繼伺服器190將所產生的驗證結果傳送到數銀伺服器170,也可以透過中繼伺服器190將驗證結果傳送到自動櫃員機120顯示。After the verification server 150 receives the identification data and the signature data sent by the ATM 120, it can verify the received signature data to generate a corresponding verification result, and can send the generated verification result back to the digital bank Server 170 (step 270). In this embodiment, it is assumed that the verification server 150 can read the certificate serial number from the digital certificate in the signature data, and can obtain the corresponding public key according to the certificate serial number, and can use the obtained public key to verify the signature data. Generate a corresponding verification result, that is, whether the signature data is verified. The verification server 150 can also send the generated verification result to the digital bank server 170 through the relay server 190, or through the middle The server 190 then transmits the verification result to the automated teller machine 120 for display.

若在本實施例中還包含身分確認伺服器160,則驗證伺服器150也可以在簽章資料通過驗證後,將所接收到的識別資料及所讀出之憑證序號傳送至身分確認伺服器160,使得身分確認伺服器160可以判斷驗證伺服器150所接收到之簽章資料所包含的數位憑證是否為憑證載具130之持有者所擁有,也就是由身分確認伺服器160判斷所接收到之識別資料與所接收到之憑證序號是否相關聯以產生相對應之身分確認結果,並可以將身分確認結果傳回驗證伺服器150,驗證伺服器150可以在所接收到之身分確認結果表示識別資料與憑證序號相關聯時才產生表示簽章資料通過驗證的驗證結果;但若驗證伺服器150判斷身分確認結果表示識別資料與憑證序號沒有關聯,則驗證伺服器150可以產生表示簽章資料沒有通過驗證的驗證結果。之後,驗證伺服器150可以透過中繼伺服器190將所產生的驗證結果傳送至數銀伺服器170(及自動櫃員機120)。If the identity verification server 160 is also included in this embodiment, the verification server 150 can also send the received identification data and the read certificate serial number to the identity verification server 160 after the signature data is verified. , So that the identity verification server 160 can determine whether the digital certificate contained in the signature data received by the verification server 150 is owned by the holder of the certificate carrier 130, that is, the identity verification server 160 determines the received Is the identification data associated with the received certificate serial number to generate the corresponding identity verification result, and the identity verification result can be sent back to the verification server 150, and the verification server 150 can indicate the identity in the received identity verification result When the data is associated with the certificate serial number, the verification result indicating that the signature data has passed the verification is generated; but if the verification server 150 determines that the identity verification result indicates that the identification data is not associated with the certificate serial number, the verification server 150 can generate a verification result indicating that the signature data is not. The verification result that passed the verification. After that, the verification server 150 may send the generated verification result to the digital bank server 170 (and the ATM 120) through the relay server 190.

在數銀伺服器170接收到驗證伺服器150所傳送之驗證結果後,數銀伺服器170可以依據驗證結果判斷自動櫃員機120所取得的簽章資料是否通過驗證伺服器150的驗證。若否,則數銀伺服器170可以透過中繼伺服器190將表示簽章資料驗證失敗的提示訊息傳送給自動櫃員機120顯示。After the digital bank server 170 receives the verification result sent by the verification server 150, the digital bank server 170 can determine whether the signature data obtained by the ATM 120 is verified by the verification server 150 according to the verification result. If not, the digital bank server 170 may send a prompt message indicating that the verification of the signature data has failed to the ATM 120 for display through the relay server 190.

而若驗證結果表示自動櫃員機120所取得的簽章資料通過驗證伺服器150驗證,則數銀伺服器170可以儲存驗證結果,並依據接收自行動裝置110的申請資料進行對應之帳戶申請作業(步驟290)。在本實施例中,也就是開戶或帳戶升級作業,並可以將作業處理結果透過中繼伺服器190傳送至自動櫃員機120,使得自動櫃員機120顯示作業處理結果。If the verification result indicates that the signature data obtained by the ATM 120 has been verified by the verification server 150, the DDB server 170 can store the verification result and perform the corresponding account application operation based on the application data received from the mobile device 110 (step 290). In this embodiment, it is an account opening or account upgrade operation, and the operation processing result can be transmitted to the ATM 120 through the relay server 190, so that the ATM 120 displays the operation processing result.

如此,透過本創作,使用者便可以先透過行動裝置填寫申請資料後,再使用行動裝置及憑證載具至自動櫃員機進行身分確認,藉以完成需要臨櫃的帳戶申請作業。In this way, through this creation, the user can first fill in the application information through the mobile device, and then use the mobile device and the certificate carrier to confirm the identity of the ATM, so as to complete the account application that requires the counter.

綜上所述,可知本創作與先前技術之間的差異在於具有由自動櫃員機透過行動裝置取得待驗資料,並在待驗資料通過數銀伺服器的確認後,透過憑證載具取得簽章資料,數銀伺服器在簽章資料通過驗證伺服器的驗證後,依據行動裝置所傳送的申請資料進行對應之帳戶申請作業之技術手段,藉由此一技術手段可以來解決先前技術所存在目前各種線上開戶方式都可能導致開戶者無法即時完成開戶申請的問題,進而達成讓開戶者自由選擇方便的時間與地點完成帳戶申請的技術功效。In summary, it can be seen that the difference between this creation and the prior art is that the automated teller machine obtains the data to be verified through the mobile device, and after the data to be verified is confirmed by the digital bank server, the signature data is obtained through the certificate carrier , After the signature data is verified by the verification server, the digital bank server performs the corresponding technical means of account application based on the application data sent by the mobile device. This technical means can solve the current various existing technologies. Online account opening methods may lead to the problem that the account opener cannot complete the account application immediately, thereby achieving the technical effect of allowing the account opener to freely choose a convenient time and place to complete the account application.

再者,本創作之掃碼驗身以完成帳戶申請之系統,可以硬體、軟體或硬體與軟體之組合等方式實現。Furthermore, the system for completing the account application by scanning the code in this creation can be implemented in hardware, software, or a combination of hardware and software.

雖然本創作所揭露之實施方式如上,惟所述之內容並非用以直接限定本創作之專利保護範圍。任何本創作所屬技術領域中具有通常知識者,在不脫離本創作所揭露之精神和範圍的前提下,對本創作之實施的形式上及細節上作些許之更動潤飾,均屬於本創作之專利保護範圍。本創作之專利保護範圍,仍須以所附之申請專利範圍所界定者為準。Although the implementation of this creation is disclosed as above, the content described is not used to directly limit the scope of patent protection of this creation. Any person with ordinary knowledge in the technical field to which this creation belongs, without departing from the spirit and scope of this creation, makes some changes in the form and details of the implementation of this creation, all belong to the patent protection of this creation range. The scope of patent protection for this creation shall still be subject to the scope of the attached patent application.

110:行動裝置 120:自動櫃員機 130:憑證載具 150:驗證伺服器 160:身分確認伺服器 170:數銀伺服器 190:中繼伺服器 310:操作介面 311:功能選項 330:輸入介面 步驟210:行動裝置產生並傳送申請資料至數銀伺服器 步驟221:數銀伺服器產生驗證序號並傳回行動裝置 步驟225:行動裝置依據驗證序號產生相對應之編碼資料 步驟230:自動櫃員機透過行動裝置取得編碼資料,並解碼編碼資料為待驗資料 步驟250:數銀伺服器比對自動櫃員機傳送之待驗資料是否與驗證序號相同,並將相對應之比對結果傳回自動櫃員機 步驟260:自動櫃員機判斷比對結果表示待驗資料通過確認後,連接憑證載具,並透過憑證載具取得簽章資料 步驟262:自動櫃員機連接憑證載具 步驟263:自動櫃員機取得憑證密碼,並透過安控元件傳送憑證密碼至憑證載具 步驟265:憑證載具使用憑證密碼取得數位憑證,並使用數位憑證產生簽章資料 步驟267:自動櫃員機透過安控元件接收憑證載具傳回之簽章資料 步驟268:自動櫃員機傳送簽章資料至驗證伺服器 步驟270:驗證伺服器驗證自動櫃員機傳送之簽章資料,並傳送相對應之驗證結果至數銀伺服器 步驟290:數銀伺服器判斷簽章資料通過驗證伺服器驗證後,依據申請資料進行對應之帳戶申請作業 110: mobile device 120: ATM 130: certificate carrier 150: verify server 160: Identity Confirmation Server 170: Digital Bank Server 190: Relay server 310: Operation interface 311: Function options 330: Input interface Step 210: The mobile device generates and sends the application data to the digital bank server Step 221: The digital bank server generates a verification serial number and sends it back to the mobile device Step 225: The mobile device generates corresponding coded data based on the verification serial number Step 230: The ATM obtains the coded data through the mobile device, and decodes the coded data into data to be verified Step 250: The digital bank server compares whether the data to be verified sent by the ATM is the same as the verification serial number, and sends the corresponding comparison result back to the ATM Step 260: The ATM judges that the comparison result indicates that the data to be verified is confirmed, connect to the certificate carrier, and obtain the signature data through the certificate carrier Step 262: Connect the voucher carrier to the ATM Step 263: The ATM obtains the certificate password and sends the certificate password to the certificate carrier through the security control component Step 265: The certificate carrier uses the certificate password to obtain a digital certificate, and uses the digital certificate to generate signature data Step 267: The ATM receives the signature data returned by the certificate carrier through the security control component Step 268: The ATM sends the signature data to the verification server Step 270: The verification server verifies the signature data sent by the ATM, and sends the corresponding verification result to the digital bank server Step 290: After the digital bank server determines that the signature data is verified by the verification server, it performs the corresponding account application based on the application data

第1圖為本創作所提之掃碼驗身以完成帳戶申請之架構圖。 第2A圖為本創作所提之掃碼驗身以完成帳戶申請之流程圖。 第2B圖為本創作所提之自動櫃員機透過憑證載具取得簽章資料之流程圖。 第3A圖為本創作實施例所提之功能選擇介面示意圖。 第3B圖為本創作實施例所提之資料輸入介面示意圖。 The first picture is the structure diagram of the scan code mentioned in the creation to complete the account application. Figure 2A is the flow chart for completing the account application by scanning the code mentioned in the creation. Figure 2B is the flow chart of the creation of the ATM to obtain signature data through the voucher carrier. Figure 3A is a schematic diagram of the function selection interface mentioned in the creative embodiment. Figure 3B is a schematic diagram of the data input interface mentioned in the creation embodiment.

110:行動裝置 110: mobile device

120:自動櫃員機 120: ATM

130:憑證載具 130: certificate carrier

150:驗證伺服器 150: verify server

160:身分確認伺服器 160: Identity Confirmation Server

170:數銀伺服器 170: Digital Bank Server

190:中繼伺服器 190: Relay server

Claims (10)

一種掃碼驗身以完成帳戶申請之系統,該系統至少包含: 一數銀伺服器; 一行動裝置,用以產生並傳送一申請資料至該數銀伺服器,及用以接收該數銀伺服器產生之一驗證序號,並依據該驗證序號產生相對應之一編碼資料; 一自動櫃員機,用以透過該行動裝置取得該編碼資料並解碼該編碼資料為一待驗資料,及用以傳送該待驗資料至該數銀伺服器,使該數銀伺服器比對該待驗資料與該驗證序號是否相同,並判斷該數銀伺服器傳回之一比對結果表示該待驗資料通過確認後,連接一憑證載具並透過該憑證載具取得一簽章資料;及 一驗證伺服器,用以驗證該自動櫃員機所傳送之該簽章資料,並傳送相對應之一驗證結果至該數銀伺服器,使該數銀伺服器判斷該簽章資料通過該驗證伺服器驗證後,依據該申請資料進行對應之帳戶申請作業。 A system for scanning the code to complete the account application. The system includes at least: One-digit silver server; A mobile device for generating and transmitting an application data to the digital bank server, and for receiving a verification serial number generated by the digital bank server, and generating a corresponding code data according to the verification serial number; An automated teller machine for obtaining the coded data through the mobile device and decoding the coded data into a pending data, and for transmitting the pending data to the digital bank server so that the digital bank server compares the pending data Whether the verification data is the same as the verification serial number, and determining whether the data bank server returns a comparison result indicating that the data to be verified is confirmed, connect to a certificate carrier and obtain a signature data through the certificate carrier; and A verification server for verifying the signature data sent by the ATM, and sending a corresponding verification result to the digital bank server, so that the digital bank server determines that the signature data passes the verification server After verification, perform the corresponding account application operations based on the application materials. 如請求項1所述之掃碼驗身以完成帳戶申請之系統,其中該自動櫃員機是掃描該行動裝置所顯示之該編碼資料或接收該行動裝置所傳送之該編碼資料以取得該編碼資料。The system for completing account application by scanning code for body check as described in claim 1, wherein the automated teller machine scans the coded data displayed by the mobile device or receives the coded data transmitted by the mobile device to obtain the coded data. 如請求項1所述之掃碼驗身以完成帳戶申請之系統,其中該數銀伺服器更用以依據自動櫃員機所取得之一識別資料讀取驗證序號,藉以比對該待驗資料與該驗證序號是否相同。For example, the system for scanning the code to complete the account application as described in claim 1, wherein the digital bank server is used to read the verification serial number based on an identification data obtained by an ATM, so as to compare the data to be verified with the Verify that the serial numbers are the same. 如請求項1所述之掃碼驗身以完成帳戶申請之系統,其中該自動櫃員機是取得一憑證密碼並透過一安控元件傳送該憑證密碼至該憑證載具,使該憑證載具使用該憑證密碼取得一數位憑證並使用該數位憑證產生一簽章資料,及透過該安控元件接收該憑證載具傳回之該簽章資料。For example, the system for completing account application by scanning code for body check described in claim 1, wherein the ATM obtains a certificate password and transmits the certificate password to the certificate carrier through a security control component, so that the certificate carrier can use the certificate The certificate password obtains a digital certificate and uses the digital certificate to generate a signature data, and receives the signature data returned by the certificate carrier through the security control component. 如請求項4所述之掃碼驗身以完成帳戶申請之系統,其中該系統更包含一身分確認伺服器,用以接收該驗證伺服器所傳送之一識別資料,並確認該數位憑證與該識別資料關聯。The system for completing account application by scanning a code for body verification as described in claim 4, wherein the system further includes an identity verification server for receiving an identification data sent by the verification server, and confirming the digital certificate and the Identify data associations. 如請求項5所述之掃碼驗身以完成帳戶申請之系統,其中該身分確認伺服器更用以接收該驗證伺服器由該自動櫃員機所轉送之一憑證確認資料,並依據該憑證確認資料中之憑證序號讀取一相關資料,及判斷該相關資料所包含之憑證擁有者的識別資料是否與憑證確認資料中之該識別資料相符以產生表示該識別資料是否與該數位憑證關聯之身分確認結果。The system for completing account application by scanning code for body verification as described in request item 5, wherein the identity verification server is further used to receive a certificate confirmation data forwarded by the verification server from the ATM, and confirm the data according to the certificate The certificate serial number in reads a related data, and determines whether the identification data of the certificate owner contained in the related data matches the identification data in the certificate confirmation data to generate an identity confirmation indicating whether the identification data is associated with the digital certificate result. 如請求項6所述之掃碼驗身以完成帳戶申請之系統,其中該驗證伺服器更用以依據該身分確認伺服器所產生之身分確認結果產生該驗證結果。The system for completing account application by scanning a code for body verification as described in claim 6, wherein the verification server is further used to generate the verification result based on the identity verification result generated by the identity verification server. 如請求項1所述之掃碼驗身以完成帳戶申請之系統,其中該自動櫃員機更用以接收該數銀伺服器所產生之一作業處理結果或接該該數銀伺服器或該驗證伺服器所產生之一提示訊息,並用以顯示該作業處理結果及該提示訊息。The system for completing account application by scanning the code for physical examination as described in claim 1, wherein the ATM is further used to receive a processing result generated by the digital bank server or to connect to the digital bank server or the verification server A prompt message generated by the device and used to display the processing result of the operation and the prompt message. 如請求項8所述之掃碼驗身以完成帳戶申請之系統,其中該自動櫃員機更用以於顯示該作業處理結果或該提示訊息時,播放相對應之聲音或影像。For example, the system for scanning the body to complete the account application described in claim 8, wherein the automated teller machine is further used to play the corresponding sound or video when displaying the processing result of the operation or the prompt message. 如請求項8所述之掃碼驗身以完成帳戶申請之系統,其中該數銀伺服器是以特定運算產生該驗證序號。The system for completing account application by scanning the code for body verification as described in claim 8, wherein the digital bank server generates the verification serial number by a specific operation.
TW109207964U 2020-06-23 2020-06-23 System for completing account application by scanning code to verify identity TWM601410U (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW109207964U TWM601410U (en) 2020-06-23 2020-06-23 System for completing account application by scanning code to verify identity

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW109207964U TWM601410U (en) 2020-06-23 2020-06-23 System for completing account application by scanning code to verify identity

Publications (1)

Publication Number Publication Date
TWM601410U true TWM601410U (en) 2020-09-11

Family

ID=73644590

Family Applications (1)

Application Number Title Priority Date Filing Date
TW109207964U TWM601410U (en) 2020-06-23 2020-06-23 System for completing account application by scanning code to verify identity

Country Status (1)

Country Link
TW (1) TWM601410U (en)

Similar Documents

Publication Publication Date Title
TWM601411U (en) System for digital account application by using ATM to obtain authentication
US20180034811A1 (en) Method and System for Authenticating a User with Service Providers Using a Universal One Time Password
TWM592134U (en) System for verifying identity for opening an account using a vehicle in an ATM
US20140074713A1 (en) Obtaining User Input From A Remote User to Authorize a Transaction
EP2854087A1 (en) Method for processing a payment
TWI644276B (en) System for opening account and applying mobile banking account online and method thereof
BRPI0718899A2 (en) SYSTEMS AND METHODS TO ENABLE A FINANCIAL TRANSACTION BETWEEN A POTENTIAL TRADER AND A RECIPIENT AND TO VERIFY DATA FROM A NEGOTIATOR BEFORE THE NEGOTIATOR CONDUCT A RECIPIENT TO A POINT-TO-TO-POINT DEVICE DEVICE TO CONDUCT SECURE FINANCIAL TRANSACTIONS
TWM539668U (en) System for opening account online and applying for mobile banking
WO2012104872A1 (en) E-cheque based transaction system and method
JP5981507B2 (en) How to process payments
TWI792010B (en) System for using automation machine to scan barcode and verify identity for applying account and method thereof
TWM601410U (en) System for completing account application by scanning code to verify identity
TWI724638B (en) System for using carrier to verity identity in machine for opening account and method thereof
TWM620550U (en) System for verifying identity on different devices by verifying valid certificates
TWM618726U (en) System for verifying identity on different devices based on certificates and verification data
TWM609003U (en) System for transferring to client end to continue operation after confirming the identity on the public equipment
KR102140708B1 (en) Method and server for providing financial service
TWI774011B (en) System for getting certification through automation machine for applying account and method thereof
TWM603573U (en) System generating authorization content during identity verification before transaction
TWI729535B (en) System for using financial account to confirm identity and method thereof
TWI790495B (en) System for driving smart card by third-party device for identity verification and method thereof
TWI803907B (en) System for confirming identity on different devices by verifying valid certification and method thereof
TWI784339B (en) System for changing to client to continue operations after confirming identity on public device and method thereof
TWI807219B (en) System for performing identification based on comparing photo stored in chip and real-time live photo and method thereof
JP6994209B1 (en) Authentication system and authentication method