WO2007009373A1 - Procede et systeme de paiement securise dans un reseau et un serveur d'acheminement - Google Patents

Procede et systeme de paiement securise dans un reseau et un serveur d'acheminement Download PDF

Info

Publication number
WO2007009373A1
WO2007009373A1 PCT/CN2006/001739 CN2006001739W WO2007009373A1 WO 2007009373 A1 WO2007009373 A1 WO 2007009373A1 CN 2006001739 W CN2006001739 W CN 2006001739W WO 2007009373 A1 WO2007009373 A1 WO 2007009373A1
Authority
WO
WIPO (PCT)
Prior art keywords
cardholder
security
subsystem
information
transaction
Prior art date
Application number
PCT/CN2006/001739
Other languages
English (en)
French (fr)
Inventor
Rui Guo
Jianming Kang
Jiachu Yang
Xufeng Lv
Original Assignee
China Unionpay
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay filed Critical China Unionpay
Priority to EP06761474A priority Critical patent/EP1906583A4/en
Priority to US11/994,365 priority patent/US20080228655A1/en
Publication of WO2007009373A1 publication Critical patent/WO2007009373A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/10Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
    • G06Q20/108Remote banking, e.g. home banking
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/12Payment architectures specially adapted for electronic shopping systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/102Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measure for e-commerce

Definitions

  • the present invention relates to the field of network data processing, and more particularly to an online secure payment system for online payment.
  • FIG. 1 is a schematic diagram of a structure of an online secure payment system commonly used in the prior art. It includes a cardholder terminal 11, a merchant website 12, and an acquiring subsystem 13.
  • the cardholder terminal 11 is connected to the merchant website 12 via the Internet
  • the merchant website 12 is connected to the acquiring subsystem 13 via the Internet or a dedicated line.
  • the acquiring subsystem 13 includes at least a communication server, an application server, and a database server.
  • the communication server is used to establish a connection with the merchant website 12 of each merchant, and perform security detection on the received data packets.
  • the application server is configured to process various data of the received various merchant websites 12, and modify the information in the database server according to the processing result, and return the processing result to the merchant server 12, and the database server saves the receipt. Corresponding information for each account in system 13.
  • This online secure payment system is suitable for secure payment in the case where the card issuer and the acquirer are the same financial institution.
  • the payment process is as follows: First, the cardholder logs into the merchant website 12, selects the product, confirms the order submission, and then, the merchant website 12 sends the order information, the transaction information and the like to the card issuing subsystem 13 of the card issuing institution.
  • the card issuing subsystem 13 receives the data such as the card number and the password input by the user, and after the security authentication of the cardholder identity authentication and the merchant identity authentication is passed, the debit payment processing is performed, and after the deduction is completed, the merchant performs the delivery.
  • payment can be made through another payment system. Please refer to FIG.
  • FIG. 2 which is a schematic structural diagram of another payment system according to the present invention. It includes a cardholder terminal 11, a merchant website 12, and a number of card issuing subsystems 14.
  • the cardholder terminal 11 is connected to the merchant website 12 via the Internet, and the merchant website 12 also connects a number of card issuing subsystems 14 via the Internet.
  • the merchant website 12 stores routing information of each card issuing subsystem 14 connected to the merchant website 12, and establishes a correspondence between the BI code of the card number and the routing information of the card issuing subsystem 14.
  • the payment process is as follows: First, the cardholder logs in to the merchant website 12, selects the product, confirms the order submission, and then, the merchant website 12 establishes an interaction with the cardholder terminal 11, and asks the cardholder to input the card number, and then, the merchant website 12 according to the
  • the BIN code of the card number finds the routing information of the card issuing institution corresponding to the card number, and sends the cardholder information and the order information to the card issuing subsystem 14 to perform the debit processing.
  • VISA has proposed another online payment system and online payment process.
  • Figure 3 is a schematic diagram of the structure of the online payment system proposed by VISA. It includes a cardholder terminal 11, a merchant website 12, an acquiring subsystem 13, a routing server 15 provided by VISA, and a card issuing subsystem 14.
  • the routing server 15 can be connected to the acquiring subsystem 13, the issuing subsystem 14 and the merchant website 12 via the Internet.
  • An MPI software provided by the acquiring subsystem 13 is set up on the merchant website 12.
  • the cardholder logs into the merchant website 12, selects the product, confirms the order submission, and then, the merchant website uses the MPI software to send the cardholder information to the routing server 15, and then the routing server 15 finds the corresponding card issuing institution according to the card number, and returns the card issuing. Routing information of the subsystem 14 to the merchant website 12; subsequently, the card issuing subsystem 14 authenticates the identity of the cardholder, The special network returns the authentication result to the cardholder terminal 11 and the merchant website 12. When the authentication result is the certification pass, the traditional card issuance system deducts the payment before the cardholder is shipped.
  • the above discloses three different system architectures established in order to complete secure internet payment transactions in the transaction modes employed by the three existing banks. Since each system can only satisfy one transaction mode, if the transaction mode set by the card issuing bank of the user is different from the transaction mode established by one of the above systems, the user cannot use the bank card to complete the security on the system. Online payment, resulting in a lot of secure online payment data processing process can not be completed successfully.
  • the object of the present invention is to provide an online secure payment system for establishing a unified platform for online payment, thereby solving the technical problems of existing online transaction process confusion and resource waste.
  • the present invention discloses an online secure payment system, including a cardholder terminal, a merchant website, an acquiring subsystem, a card issuing subsystem, and a routing unit connected to the acquiring subsystem and the card issuing subsystem, wherein:
  • the routing unit includes: a storage module, configured to store a transaction mode used by each card issuing subsystem and a routing information and a processing flow corresponding to each "" BIN BIN; and a processing module configured to receive according to the receiving subsystem
  • the card number determines the transaction mode corresponding to the card issuing subsystem, and processes according to the corresponding processing flow.
  • the online secure payment system further includes a security plug-in connected to the acquiring subsystem or disposed in the acquiring subsystem; the security plug-in is used to establish data interaction between the merchant website, the cardholder terminal, and the routing unit. : interaction with the cardholder terminal, obtained Cardholder's card number information, interaction with the routing unit, to obtain routing information or corresponding processing flow.
  • the online secure payment system further includes a security authentication and authorization unit, connected to the card issuance subsystem, or disposed in the card issuance subsystem; the security authentication and authorization unit includes at least an authentication subunit and a notification subunit, and the authenticator The unit is used for identity authentication of the cardholder; the notification subunit: the security authentication authorization unit forms the online transaction result of the cardholder's identity authentication result and the card issuing subsystem's deduction processing result to the cardholder terminal through the Internet.
  • the routing unit saves routing information of each security authentication and authorization unit corresponding to the card issuing subsystem that adopts the direct authentication and authorization mode.
  • the online secure payment system further includes a cardholder security control unit, configured to establish interaction with the cardholder terminal, and receive the cardholder to input security information indicating the identity of the cardholder.
  • the routing unit stores routing information of each cardholder security control unit corresponding to the card issuing subsystem authenticated by the cardholder security control unit.
  • the online secure payment system further includes a cardholder security interaction unit, and the cardholder security interaction unit is connected to the cardholder security control unit, and is configured to send the authentication information to the cardholder terminal through the agreed channel. And receiving the authentication information entered by the cardholder and authenticating the information.
  • the cardholder security control unit, the routing unit, and the cardholder security interaction unit may be set on a server.
  • the security plug-in comprises the following units: a verification merchant unit: used for authenticating a merchant that initiates an order transaction request; an interaction control unit: for controlling a merchant website, a cardholder terminal, a routing unit, a security authentication authorization Data exchange between the unit and the cardholder security control unit; data storage unit: for storing data including merchant information; and authentication and transmission unit: for performing secure authentication on the received data packet and the transmitted data packet.
  • a verification merchant unit used for authenticating a merchant that initiates an order transaction request
  • an interaction control unit for controlling a merchant website, a cardholder terminal, a routing unit, a security authentication authorization Data exchange between the unit and the cardholder security control unit
  • data storage unit for storing data including merchant information
  • authentication and transmission unit for performing secure authentication on the received data packet and the transmitted data packet.
  • the invention also discloses a routing server, comprising the following components:
  • Storage unit used to store the transaction mode adopted by each card issuing subsystem and the routing information and processing flow corresponding to each card number BIN;
  • Direct authentication and authorization mode processing unit when the card issuing subsystem corresponding to the card number adopts a direct authentication and authorization mode, returning a route of the security authentication and authorization unit corresponding to the card number ⁇ ;
  • Cardholder security control unit authentication mode processing unit when the card issuing subsystem corresponding to the card number adopts the cardholder security control unit authentication mode, returning routing information of the cardholder security control unit;
  • the acquiring subsystem self-processing mode processing unit when the card issuing subsystem corresponding to the card number adopts the acquiring subsystem self-processing mode, notifying the processing mode to the corresponding acquiring subsystem.
  • the invention also provides an online secure payment method, comprising: an acquiring subsystem acquiring a transaction request and a cardholder card number information; the routing unit determining a transaction mode corresponding to the card issuing subsystem according to the card number, and performing information processing according to the corresponding processing flow
  • the acquiring subsystem or the card issuing subsystem completes the transaction settlement and returns the result information.
  • the routing unit notifies the corresponding acquiring subsystem; the acquiring subsystem completes the transaction settlement and returns the result information.
  • the routing unit returns routing information of the cardholder security control unit; the cardholder security control unit establishes with the cardholder terminal Interacting, receiving cardholder input security information characterizing cardholder identity; completion of transaction settlement after card issuing subsystem authentication, returning result letter, if the card issuing subsystem corresponding to the card number adopts direct authentication and authorization mode, the routing unit returns the card number The routing information of the corresponding security authentication and authorization unit; after the card issuance subsystem is authenticated, the transaction settlement is completed, and the result information is returned.
  • the invention also provides another online secure payment method, the method comprising:
  • the security plug-in forwards the card number and the order information to the routing unit; the routing unit determines whether the cardholder security control unit is used for authentication according to the card number input by the cardholder.
  • the authentication method if yes, sending the routing information of the corresponding cardholder security control unit to the security plug-in; the security plug-in sends the card number and the cardholder information to the cardholder security control unit;
  • the card security control unit establishes an interaction with the cardholder, receives the cardholder inputting the security information of the identity of the cardholder, and sends the security information to the security plugin;
  • the security plug-in combines the security information and the order information into the transaction request message, and sends the information to the corresponding card issuing subsystem through the inter-row switching center or according to the routing information provided by the routing unit;
  • the interaction between the card security control unit and the cardholder is completed by the following steps: bl: The cardholder security control unit sends the card number to the cardholder security interaction unit, and the cardholder security interaction unit controls the card holder safely. The unit returns to the interface input requirements;
  • B2 the cardholder security interaction unit sends the authentication information to the cardholder through the agreed channel
  • b3 the cardholder security control unit receives the input information, and sends the input information to the cardholder security interaction unit;
  • the cardholder security interaction unit authenticates the input information and sends the authenticated information to the cardholder security control unit.
  • the security plug-in guides the cardholder to establish an SSL secure channel authenticated by the cardholder security control unit, checks the validity of the cardholder certificate and establishes a channel for providing secure transmission of data; after the validity of the certificate is recognized, the cardholder
  • the security control unit displays the cardholder input information through the browser of the cardholder terminal, and obtains the DN of the certificate and the card number input by the cardholder through the SSL server module, and verifies whether the certificate and the card number are validly bound, and if valid, The information entered by the cardholder is sent to the security plugin, otherwise the invalidation result is transmitted to the security plugin.
  • the invention also discloses an online secure payment method, characterized in that the method comprises the following steps:
  • the cardholder terminal submits an order to the merchant website
  • the merchant website initiates a transaction request to the acquiring subsystem;
  • the acquiring subsystem establishes an interaction with the cardholder terminal, and obtains the card number information input by the cardholder;
  • the acquiring subsystem sends the card number information and the transaction information to the routing unit;
  • the routing unit sends the card number information and transaction information to the security certification authority corresponding to the card issuer;
  • the security certification authority unit authenticates the cardholder
  • the card issuing subsystem sends the deduction processing result and the authentication result to the acquiring subsystem;
  • the acquiring subsystem notifies the merchant.
  • the method further comprises: the security authentication authorization unit determining whether the cardholder has been registered, and returning the registration result to the routing unit; the routing unit assigning a transaction identifier to the payment Code, and assign the registration result and identification code to the acquiring subsystem; if the registration result is that the cardholder has been registered, the acquiring subsystem sends the card number information, the order information and the service identification code to the security authentication authority unit, requesting the authentication card people.
  • the transaction result information is sent to the acquiring subsystem by the following steps: the card issuing subsystem sends an online transaction result notification to the inter-bank switching center, where the online transaction result includes a unique transaction identification code; when the issuance subsystem is within a preset time Respond to the online transaction result and re-issue the online transaction result notification within a limited number of times; after receiving the online transaction result, the inter-bank exchange center returns a response message and sends the online transaction result to the corresponding acquiring subsystem; The online transaction result response is not received within the preset time, and the online transaction result notification is re-issued to the acquiring subsystem within a limited number of times.
  • the online secure payment method further includes:
  • the inter-bank switching center performs the clearing step according to the transaction identification code in a preset period: the inter-bank switching center aggregates all the online transaction result notifications in the preset time period and sends them to the corresponding acquiring subsystem;
  • the acquiring subsystem sends the unsuccessful online transaction result notification to the corresponding merchant website.
  • the transaction result information is sent to the acquiring subsystem by the following steps: the card issuing subsystem combines the authentication result and the deduction processing result into an online transaction result and sends the result to the cardholder terminal through the Internet, and the online transaction result further includes the transaction identification code;
  • the card terminal transmits the online transaction result to the acquiring subsystem via the Internet.
  • the invention also provides an online secure payment method, the method comprising the following steps:
  • the cardholder terminal submits an order to the merchant's website
  • the acquiring subsystem establishes an interaction with the cardholder terminal, and obtains the card number information input by the cardholder;
  • the acquiring subsystem sends the card number information and the transaction information to the routing unit;
  • the routing unit sends the card number information and the transaction information to the security authentication and authorization unit corresponding to the card issuing institution;
  • the security certification authority unit authenticates the cardholder
  • the card issuance subsystem After the certification is passed, the card issuance subsystem performs deduction processing and returns the transaction result;
  • the consumption determination request is sent to the card issuing subsystem through the inter-exchange switching center or the routing unit;
  • the card issuing subsystem After receiving the consumption determination request, the card issuing subsystem searches for the corresponding database, and after finding the corresponding debit processing, returns the acceptance information to the acquiring subsystem.
  • the present invention has the following advantages:
  • the present invention provides a platform for banks currently adopting different transaction modes to perform transaction processing on the platform, thereby solving the technical defects of the existing online transaction process confusion and resource waste. Moreover, the present invention provides security by providing a security plug-in on the acquirer to interact with the cardholder, obtain the card number information.
  • the invention provides an online secure payment system and method, which can synthesize the authentication process and the deduction process into a payment process, which not only improves the processing speed of payment, but also improves the utilization rate of online resources.
  • the most important thing is that the card issuer actively forwards the transaction result to the acquirer through the exchange center, adopts the existing proprietary network, takes less time, and has fewer abnormal conditions, effectively reducing the occurrence of unilateral accounts, thereby improving the situation.
  • Transaction success rate is provided cardholders and merchants with information on whether the transaction was successful, rather than information on whether the authentication was passed.
  • the transaction success information obtained by the merchant from the acquiring institution can be used as the basis for delivery.
  • the card issuing institution can transmit the success information of the transaction to the merchant, thereby improving the achievability of the online transaction.
  • the invention can set a unified online security control subsystem, so it is possible to provide a unified transaction interface for the user.
  • the transaction is added to the inter-bank exchange subsystem regardless of the structure of the card issuance subsystem.
  • the bank can use this method to make online payment, which improves the scope of application of the present invention; and, the present invention passes
  • the API (Security Plug-in) directly establishes interaction with the cardholder, obtains the card number information, avoids obtaining the card number of the cardholder through the uneven merchant, and further improves the security of the online payment.
  • FIG. 1 is a schematic structural diagram of an online payment system provided by the prior art
  • FIG. 2 is a schematic structural diagram of another online payment system provided by the prior art
  • FIG. 3 is another online payment system provided by VISA.
  • FIG. 4 is a schematic structural diagram of an online secure payment system of the present invention
  • Figure 5 is a flow chart of the online secure payment method of the present invention.
  • FIG. 6 is a flow chart of another online secure payment method provided by the present invention
  • FIG. 7 is a schematic structural diagram of an improved online payment system of an online payment system provided by the existing VISA company
  • Figure 8 is a schematic diagram showing the structure of an online secure payment system improved by the banking system provided by UnionPay;
  • FIG. 9 is a schematic flow chart of an online secure payment method provided by the present invention.
  • FIG. 10 is a schematic diagram showing an example of a flow of an online secure payment method provided by the present invention.
  • FIG. 11 is a schematic diagram of another online secure payment process provided by the present invention.
  • the present invention provides a platform for making current The transaction mode can all be run on the secure payment platform provided by the present invention.
  • the acquiring institution's own processing mode the online banking center authentication mode (cardholder security control unit authentication mode)
  • the card issuing institution direct authentication and authorization mode the card issuing institution direct authentication and authorization mode.
  • the secure payment system provided by the present invention enables the above three transaction modes or other transaction modes that appear in the future to operate on the platform.
  • FIG. 4 is a schematic diagram showing the structure of an online secure payment system provided by the present invention.
  • the online secure payment system provided by the invention can provide three transaction modes: an acquirer self-processing mode, an online banking center authentication mode (cardholder security control unit authentication mode), and a card issuing institution direct authentication and authorization mode. It includes: a cardholder terminal 21, a merchant website 22, an acquiring subsystem 23, an inter-bank switching system 24, a card issuing subsystem 26, a routing unit 25, an online security control subsystem, and a secure authentication authority unit 30. among them:
  • the cardholder terminal 21, connected to the merchant website 22, is used to establish a connection between the cardholder and the merchant. They are usually connected via the Internet, for example: an internet browser on the cardholder terminal logs in to the merchant website, selects the product, and submits the order.
  • the inter-row switching system 24 is connected to each of the card issuing subsystem 26 and the acquiring sub-system 23 by a dedicated line for establishing a connection between the card issuing mechanism and the acquiring institution. Clearing can be done for each transaction and each acquirer and issuer. Inter-bank switching center 24 can use China UnionPay's inter-row switching system.
  • the security authentication and authorization unit 30 is configured to set a security authentication and authorization unit in each card issuing institution, and the notification subunit combines the identity authentication result of the cardholder and the card processing result of the card issuing subsystem to form an online transaction result. Sent to the cardholder terminal via the Internet;
  • the routing unit 25 stores the transaction mode adopted by each card issuing institution and the routing information and processing flow corresponding to each BIN, and determines the transaction mode adopted by the corresponding card issuing institution according to the received card number, and processes according to the processing flow.
  • a card issuance subsystem 26 configured to perform debit processing according to an order
  • Online Security Control Subsystem Establishes an interaction with the cardholder and receives the cardholder's input of security information that characterizes the cardholder.
  • the routing unit 25 stores the correspondence between the BIN code and the card issuer, and stores the transaction mode adopted by each card issuer, the routing information or the processing flow corresponding to the card issuer.
  • the card issuing authority corresponding to the card number adopts the direct authentication and authorization mode
  • the correspondence between the BIN and the routing information of the security authentication and authorization unit 30 is saved, and when the card issuing institution adopts the acquiring mechanism of the acquiring institution, the method returns to the acquiring institution to process the self-processing
  • the instruction returns the routing information of the cardholder security control unit when the card issuer corresponding to the card number adopts the cardholder security control unit authentication mode.
  • Routing unit 25 can be programmed according to a particular supported transaction mode. Routing unit 25 is typically provided by a collaboration mechanism, which can be a routing subsystem or a server or server.
  • the online security control subsystem includes a cardholder security control unit 27 for receiving security information identifying the identity of the cardholder.
  • the security information that characterizes the cardholder identity such as the card number and the corresponding password
  • the security of the security information is directly linked to the merchant website of the entire online payment service, and the legality of the merchant website cannot be confirmed and its security is not high.
  • the characteristics of the entire online payment service are relatively low. If the receiving cardholder enters the security information (such as the card number and the corresponding password) indicating the identity of the person to be placed in each card issuing subsystem 26, since each card issuing subsystem 26 needs to be set to complete the card receiving the card holder to input the security information.
  • the human security certification unit is therefore difficult to implement and has a high investment.
  • the present invention can only set up an online security control subsystem to complete the headaches of all card issuers: Establish an interactive interface to securely receive security information entered by the cardholder.
  • the applicant China UnionPay established an online security authentication subsystem, and all card issuers can use the online security authentication subsystem to obtain the security information input by the cardholder, which greatly improves the security of the entire online payment process.
  • the card issuer end there is no need to establish a cardholder security authentication unit, which reduces a large amount of repetitive investment.
  • the present invention can also provide a cardholder security interaction unit 28 in the existing online security control subsystem, and the cardholder security interaction unit 28 is connected to the cardholder security control unit 27, Used to make online payment password information After the channel is sent to the cardholder, the cardholder security control unit 27 receives the password information input by the cardholder and authenticates the information.
  • the cardholder security interaction unit 28 sends the generated dynamic password to the cardholder through a pre-agreed channel, and the cardholder receives the dynamic password.
  • the cardholder security control unit 27 sends the input information to the cardholder security interaction unit 28 for authentication, for example, inputting the dynamic password in the information and transmitting it to the user through other channels.
  • the passwords are the same, if yes, the authentication is passed, otherwise the authentication fails.
  • the number of times of input can also be set.
  • the validity period of the dynamic password can also be set.
  • the cardholder terminal 21 connects to various merchant websites 22 via the Internet, and many merchant websites 22 are connected to an acquiring subsystem 23 via the Internet or a dedicated line.
  • the present invention provides a corresponding security plug-in 29 for each acquiring institution.
  • the security plug-in 29 can be directly connected to the corresponding acquiring subsystem 23 or directly in the acquiring subsystem 23.
  • direct interaction with the cardholder terminal 21 can be established through the security plug-in 29.
  • the acquiring subsystem 23 establishes a connection with the inter-row switching center 24 via a dedicated line, and the security plug-in 29 can establish a connection with the routing unit 25 via the private line or via the Internet.
  • Each card issuing subsystem 26 is connected to the inter-bank switching center 24 through a dedicated line.
  • a security authentication authority unit 30 is correspondingly disposed in each card issuing institution.
  • the security certification authority unit 30 may be directly developed by the card issuing institution, or may be entrusted by the card issuing institution to be developed by other companies, and disposed outside the card issuing subsystem 26, and directly connected to the card issuing subsystem 26.
  • the security authentication authority unit 30 corresponding to each card issuing institution can be connected to the routing unit 25 via a dedicated line or via the Internet.
  • Each security plug-in 29, routing unit 25, each secure authentication authority unit 30 may be a node on the Internet, directly connected to each cardholder terminal 21 via the Internet.
  • the security plug-in 29 can be a programmed server or can be programmed on an application server within the original billing subsystem.
  • the security plugin can contain the following units: Verified Merchant Unit: Used to authenticate the merchant that initiated the order transaction request. After the merchants of the acquiring institution register, the merchant information of the merchant is saved in the data storage unit. Each merchant has a unique merchant identifier (such as a merchant name or an IP number corresponding to the merchant website). When the merchant initiates an order transaction request, the verification merchant unit performs merchant identity authentication according to the merchant information of the data storage unit.
  • Interactive control unit Used to control data interaction with the merchant website, cardholder terminal, routing unit, cardholder security control unit, and security authentication authority unit.
  • the interaction control unit saves the routing information of the interaction objects (the merchant website, the cardholder terminal, the routing unit, the security authentication authority), and the interaction triggering process. For example, after the merchant identity authentication is passed, the routing information of the cardholder terminal is obtained from the transaction request sent by the merchant, the interaction with the cardholder is established, and the card number information of the cardholder is obtained; the card number information of the cardholder and corresponding The transaction information is sent to the routing unit, obtaining the authentication type of the transaction and the routing information of the corresponding security authentication authority, and the transaction identification code; when receiving the transaction processing result, returning to the merchant website, and the like.
  • Data storage unit used to store data, used to store business information and security plug-ins
  • Authentication and transmission unit used to securely authenticate received packets and transmitted packets. Every time data interaction with other devices requires strict security controls. For example, before the sender sends a transaction to the receiver, the digital certificate is used to authenticate the two parties. After the authentication is successful, the symmetric key of the encrypted transaction data is negotiated, and the sender encrypts the data transaction data to the receiver using the symmetric key. After the receiver decrypts using the symmetric key, the response data is encrypted by the symmetric key and then returned.
  • the security plug-in 29 can be used as a sender or a receiver.
  • the authentication and transmission unit is mainly responsible for security control during data interaction.
  • the cardholder security control unit 27 When the cardholder security control unit 27 receives the authentication success message, the security information (such as a password) input by the user is sent to the security plug-in 29. When the cardholder security control unit 27 receives the authentication failure message, the authentication may fail. The message is sent directly to the security plugin 29, and the security plugin 29 can be subsequently processed (eg, returning to the merchant: the identity of the user needs further confirmation, etc.).
  • a preferred security plug-in 29 has been described above, of course, Those skilled in the art can also implement in other feasible ways as long as the corresponding functions can be completed.
  • the verification merchant unit and the authentication and transmission unit included in the preferred security plug-in 29 described above can be used to improve and secure security in data transmission.
  • the security plug-in 29 can typically be placed on an acquiring subsystem developed by an acquirer.
  • the cardholder security control unit 27, the routing unit 25, and the cardholder security interaction unit 28 can be set up on a server.
  • the present invention also constructs a routing server based on the transaction patterns already set by existing banks, including the following components:
  • Storage unit used to store the transaction mode adopted by each card issuing subsystem and the routing information and processing flow corresponding to each card number BIN;
  • a direct authentication and authorization mode processing unit when the card issuing subsystem corresponding to the card number adopts a direct authentication and authorization mode, returning routing information of the security authentication and authorization unit corresponding to the card number;
  • Cardholder security control unit authentication mode processing unit when the card issuing subsystem corresponding to the card number adopts the cardholder security control unit authentication mode, returning routing information of the cardholder security control unit;
  • the acquiring subsystem self-processing mode processing unit when the card issuing subsystem corresponding to the card number uses the acquiring subsystem self-processing mode, notifying the processing mode to the corresponding acquiring subsystem.
  • the above routing server is connected with the acquiring subsystem and the card issuing subsystem, so that the transaction processing of each bank can be satisfied, and the convenience of the user to use the bank card for online secure payment is improved.
  • the following describes the secure payment process based on a publicly available secure payment system.
  • the cardholder terminal submits an order to the merchant's website
  • the security plug-in establishes an interaction with the cardholder terminal to obtain the card number information input by the cardholder;
  • the security plug-in sends the card number information and the transaction information to the routing unit, and the routing unit determines the transaction mode adopted by the card issuing institution according to the card number. If the acquiring mechanism adopts the self-processing mode, the process A is performed, for example, the cardholder security control unit is adopted. Authentication mode, then proceed Process B. If the card issuer directly authenticates the authorization mode, proceed to process C.
  • A1 the routing unit determines, by the card number, that the transaction belongs to the acquiring institution self-processing mode, and notifies the security plug-in;
  • A2 The security plug-in sends the card number and order information to the acquiring subsystem;
  • A3 The acquiring sub-unit processes the subsequent process by itself: After the authentication and authorization deduction are processed, the cardholder and the merchant are notified.
  • the routing unit determines, according to the card number input by the cardholder, whether the authentication mode is performed by the cardholder security control unit, and if yes, sends the routing information of the corresponding cardholder security control unit to the security plug-in;
  • B2 The security plug-in first sends the card number information to the cardholder security control unit;
  • B3 The security plug-in sends the card number and the cardholder information to the cardholder security control unit:
  • the cardholder security control unit sends the card number to the card holder
  • the cardholder security interaction unit the cardholder security interaction unit returns the interface input request to the cardholder security control unit;
  • the cardholder security interaction unit sends the authentication information to the cardholder through the agreed channel;
  • the cardholder security control unit receives the input Information, and the input information is sent to the cardholder security interaction unit;
  • the cardholder security interaction unit authenticates the input information, and sends the authentication information to the cardholder security control unit;
  • the security plug-in combines the security information and the order information into the transaction request message, and sends the message to the corresponding card issuing subsystem through the inter-bank transaction subsystem;
  • the routing unit sends the card number information and the transaction information to the security authentication and authorization unit corresponding to the card issuing institution;
  • C2 the security certification authority unit authenticates the cardholder
  • C3 After the certification is passed, the card issuing subsystem performs deduction processing;
  • C4 when the acquiring subsystem does not receive the online transaction result within the preset time, sending a consumption determination notification to the inter-bank switching center, and the online exchange result is sent back to the cardholder terminal by the security authentication authorization unit through the Internet, and then The cardholder terminal sends back to the acquiring subsystem;
  • the card issuing subsystem searches for the corresponding database after receiving the consumption determination notification of the inter-row switching center, and returns the acceptance information to the acquiring sub-system after the corresponding debit processing is found, so as to notify the merchant.
  • the C4 - C5 step is replaced by the following steps:
  • the card issuing subsystem sends the deduction processing result and the authentication result to the acquiring subsystem through the inter-row switching center;
  • the acquiring subsystem notifies the merchant.
  • FIG. 5 is a flowchart of an authentication method provided by the invention.
  • the method includes: S110: when the merchant website receives the cardholder's order information, establishing an interaction between the cardholder and the security plug-in, the security plug-in receiving the card number input by the cardholder and requiring payment of the transaction amount;
  • the cardholder logs into the merchant's website through the Internet browser installed on the personal terminal, selects the product and submits the order and submits it.
  • the merchant website redirects the card holder's webpage to the security plug-in and transmits the order information to the security plug-in.
  • the cardholder establishes interaction with the cardholder according to the obtained cardholder webpage, and receives the cardholder input card number information.
  • S120 The security plug-in sends the card number and cardholder information to the cardholder security control unit;
  • the card security control unit establishes an interaction with the cardholder, receives the cardholder inputting the security information of the identity of the cardholder, and sends the security information to the security plugin;
  • S140 The security plug-in combines the security information and the order information into the transaction request message, and sends the information to the corresponding card issuing subsystem through the inter-bank transaction subsystem;
  • the present invention passes a cardholder Security information and orders are sent to the card issuer (usually a bank) via an interbank exchange subsystem for authentication and authorization debit processing. All card issuers that use the online security control subsystem for authentication may obtain the cardholder's security information securely through the above methods, and do not need to establish a cardholder security authentication unit in the card issuance subsystem.
  • the online security control subsystem can not only provide personalized services: it can establish a corresponding user interface according to the requirements of each card issuer, and send the corresponding information input by the cardholder to the corresponding card issuer; and the online security control subsystem can also provide A unified user interface makes it easy for cardholders to enter.
  • step S110 and step S120 the method further includes:
  • the security plug-in forwards the card number and order information to the routing unit to query the routing information.
  • a2 The routing unit determines whether the card is authenticated by the cardholder security control unit according to the card number entered by the cardholder. If yes, it will correspond. The routing information of the cardholder security control unit is sent to the security plug-in. Otherwise, the card number does not support the authentication mode or other authentication mode information is sent back to the security plug-in.
  • A3 The security plug-in first sends the card number information to the cardholder security control unit, and queries whether the cardholder needs to participate in the interaction with the cardholder security control unit;
  • A4 The cardholder security control unit returns the query result
  • step S130 further includes: M: the cardholder security control unit sends the card number to the cardholder security interaction unit, and the cardholder security interaction unit returns the interface input request to the cardholder security control unit; b2: the cardholder secure interaction The unit sends the authentication information to the cardholder through the agreed channel; b3: the cardholder security control unit receives the input information, and sends the input information to the cardholder security interaction unit; b4: cardholder security interaction unit certification office Enter the information and send the authentication information to the cardholder security control unit.
  • the security plug-in can also perform merchant authentication by means of the merchant database of the acquiring subsystem: authentication of the merchant identity and authentication of the merchant authority.
  • the security plugin] is established by the cardholder and authenticated by the cardholder security control unit.
  • SSL secure channel verifying the validity of the cardholder certificate and establishing a channel for providing secure transmission of data;
  • the cardholder security control unit displays the cardholder input information through the browser of the cardholder terminal, and obtains the DN of the certificate and the card number input by the cardholder through the SSL server module, and verifies the certificate and Whether the card number is a valid binding, if it is valid, the information input by the cardholder is sent to the security plug-in, otherwise the invalid result is transmitted to the security plug-in.
  • the present invention provides an online secure payment method (refer to FIG. 6), including: S210: A cardholder security control unit set by a collaboration center establishes interaction with a cardholder, and receives cardholder input to characterize the cardholder identity. Safety information;
  • S220 Send the security information and transaction information to a card issuing subsystem
  • the card issuing subsystem completes the identity verification of the cardholder according to the security information, performs deduction processing according to the authentication result, and finally returns the authentication result and the deduction processing result.
  • the authentication process and the deduction process are combined into a payment process, which not only improves the processing speed of payment, but also improves the utilization rate of online resources.
  • the card issuer's security control unit provided by the Collaboration Center, collects different information from different card issuers and can also obtain a certificate.
  • the structure of the improved online payment system in the existing online payment system provided by VISA. It includes a cardholder terminal 31, a merchant website 32, an acquirer subsystem 33, a routing server 34, a card issuance subsystem 35, and a cardholder security control unit 36.
  • the cardholder terminal 31, the merchant website 32, the acquiring subsystem 33, the routing server 34, the card issuing subsystem 35 and the cardholder security control unit 36 may be nodes of the Internet, establishing data communication via the Internet.
  • the cardholder security control unit 36 can be developed by a collaboration agency such as VISA to establish interaction with the cardholder to obtain security information and establish interaction with the merchant website 32 or the acquirer subsystem 33 and to perform certificate authentication.
  • the cardholder terminal 31 initiates a transaction request to the merchant website 32, the transaction request
  • the request includes at least pre-purchased goods and corresponding fees, cardholder terminal information, etc.; then, the merchant website 32 sends the IP address information of the cardholder terminal 31 to the cardholder security control unit 36;
  • the cardholder security control unit 36 establishes interaction with the cardholder, obtains security information, and performs certificate authentication;
  • the cardholder security control unit 36 can return the certificate authentication result and the security information to the merchant website, and can return to the acquiring subsystem 33 in consideration of security factors; subsequently, the merchant website 32 sends the security information and the transaction information to the routing server. 34, sent to the corresponding card issuance subsystem 35, or similarly considering security factors, the merchant website 32 sends the transaction information to the acquiring subsystem 33, and the acquiring subsystem 33 sends the security information and transaction information to the routing server 34, which is routed to the routing server 34. Send to the corresponding card issuing subsystem 35;
  • the card issuing subsystem 35 performs authentication and debit processing, and returns the result so that the merchant website 32 and the cardholder terminal 31 obtain the authentication result and the deduction processing result.
  • FIG. 8 It is a schematic diagram of the structure of the online security payment system improved by the banking system provided by UnionPay. It includes a cardholder terminal 41, a merchant website 42, an acquiring subsystem 43, an interbank switching center 44, a card issuing subsystem 45, and a cardholder security authentication unit 46.
  • the cardholder security control unit 36 can be developed by a collaboration institution such as UnionPay to establish interaction with the cardholder to obtain security information and establish interaction with the merchant website 42 or the acquiring sub-system 43 and to perform certificate authentication.
  • the cardholder terminal 41 initiates a transaction request to the merchant website 42, the transaction request including at least the pre-purchased item and the corresponding fee, the cardholder terminal information, etc.; then, the merchant website 42 will hold the card holder terminal 41 IP address information and the like are sent to the cardholder security control unit 46 through the acquiring subsystem 43;
  • the cardholder security control unit 46 establishes interaction with the cardholder, obtains security information, returns the security information to the acquiring subsystem, and the acquiring subsystem sends the security information and transaction information to the inter-bank switching center, the inter-bank switching center.
  • the security information and the transaction information are developed to the corresponding card issuing subsystem, and the card issuing subsystem performs corresponding identity authentication and deduction Process and return its certification results and debit processing results.
  • the cardholder security authentication unit can be replaced by the above-disclosed online security authentication subsystem. All card issuers can use the online security authentication subsystem to obtain the security information entered by the cardholder, which greatly improves the security of the entire online payment process. Moreover, at the card issuer end, there is no need to establish a cardholder security authentication unit, which reduces a large amount of repeated investment.
  • the present invention also provides an online secure payment method based on the aforementioned online secure payment system. Please refer to FIG. 9, which is a flowchart of the online secure payment method of the present invention. The method includes the following steps:
  • S110 The cardholder terminal submits an order to the merchant website
  • S120 The merchant website initiates a transaction request to the acquiring subsystem
  • the acquiring subsystem establishes an interaction with the cardholder terminal, and obtains card number information input by the cardholder;
  • S140 the acquiring subsystem sends the card number information and the transaction information to the routing unit;
  • S150 if the card issuing institution corresponding to the card number adopts the card issuing authority direct authentication and authorization mode, the routing unit sends the card number information and the transaction information to the card issuing institution Corresponding security certification authority unit;
  • S160 The security certification authority unit authenticates the cardholder
  • S190 The security plugin of the acquiring subsystem notifies the merchant.
  • an online payment mode that can be implemented is provided. Moreover, for the cardholder, it is not only the authentication information that the authentication identity is successful, but the transaction processing result of whether the transaction is successful. Most importantly, the present invention enables the online payment mode provided by the present invention to have both security and shortcut functions by virtue of the security and shortcut functions of the existing financial system.
  • FIG. 10 is a specific flowchart of the online secure payment method of the present invention. It includes the following steps: 1- The cardholder terminal connects to the merchant website via the Internet, the cardholder selects the merchandise, and confirms the order submission;
  • the merchant website redirects the cardholder webpage to the security plugin and transmits the order information and transaction information to the security plugin;
  • 3- Security plug-in displays the card to the cardholder, allowing the cardholder to enter the card number, and the cardholder clicks to submit;
  • the security plug-in sends the card number, transaction type and other information to the routing unit to query the routing information
  • the routing unit judges that the transaction adopts the direct authentication and authorization mode of the card issuer according to the card number of the cardholder, and generates a unique identifier id (transaction identification code) of the transaction, and sends the card number, the transaction type, the transaction unique identifier id and the like to the transaction.
  • the security certification authority unit queries the cardholder for registration, and returns the result;
  • the routing unit passes the cardholder registration result and the transaction unique identifier id returned by the security authentication and authorization unit to the corresponding security plug-in; if the returned result is that the cardholder is not registered, the process ends;
  • the security certification authority establishes a connection with the cardholder terminal, facing the cardholder, allowing the cardholder to input relevant information and authenticate the cardholder;
  • the security certification authority transmits the transaction information (including the transaction unique identifier id) to the card issuing subsystem corresponding to the unit, and causes the card issuing subsystem to perform the chargeback processing;
  • the security certification authority unit notifies the cardholder of the authentication result and the transaction result via the Internet
  • the 12-issuing subsystem sends the transaction result, such as debit, to the inter-bank exchange center in the form of a consumption confirmation notice;
  • the card issuing subsystem can obtain enough information from the SAA to form a notification message. At the same time, for notifications using the store-and-forward and retransmission mechanism, within a limited number of times, if not received In response to the notification, the card issuing subsystem must resend the notification.
  • the serial number of the resend notification is the same as the transaction unique identifier id, which is described in detail later.
  • the 16-acquisition subsystem notifies the merchant after receiving the transaction result.
  • the card issuing subsystem sends an online transaction result notification to the inter-bank exchange center, and the online transaction result includes a unique transaction identification code; when the card issuing subsystem does not receive the response of the online transaction result within the preset time, re-issues the online within a limited number of times Transaction result notification; after receiving the online transaction result, the inter-bank exchange center returns a response message and sends the online transaction result to the corresponding acquiring subsystem; when the inter-bank switching center does not receive the response of the online transaction result within the preset time, it is limited Re-issue the online transaction result notification to the acquiring subsystem within the number of times.
  • the message carries the transaction unique identifier id generated by the routing unit, so that the acquiring institution can determine the transaction by the card number + the merchant code + the transaction unique identifier id, and further Notify the merchant of the transaction results.
  • the online transaction result notification transaction may be repeated within a limited number of times, but the serial number + transaction unique identifier id does not change.
  • the inter-bank exchange center After the inter-bank exchange center receives the online transaction result notification transaction, if the identification transaction is a duplicate notification transaction, the response sent to the card issuer indicates that the notification is repeated.
  • the switching system notifies the transaction of the online transaction result to the acquiring institution, and if no response is received, the retransmission is repeated within a limited number of times until the response is received.
  • the online transaction result notification transaction uses the store-and-forward mechanism at the initiator to ensure that the receiver can receive it correctly. Initiating notification transactions through the proprietary network of the inter-bank switching center ensures that the acquiring institution can receive the transaction results accurately and in a timely manner, effectively reducing the situation of unilateral accounts.
  • the online transaction result notification transaction is initiated by the issuer, and is received by the acquirer. Receive, but the transaction is similar to consumer transactions, there are follow-up transactions such as cancellation.
  • the originator of the subsequent transaction is the same as the traditional transaction.
  • the inter-bank switching center performs the clearing step in a preset period: the inter-bank switching center sends a summary of all the online transaction result notifications in the preset time period to the corresponding acquiring subsystem; the acquiring subsystem notifies the unreceived online transaction result notification to the Corresponding merchant website.
  • the inter-bank exchange center will conduct liquidation based on the online transaction result notification transaction.
  • the inter-bank exchange center successfully receives the online transaction result notification and cannot forward it to the acquirer, the online transaction result notification will still participate in the liquidation.
  • the inter-bank exchange center will clear the transaction according to the notification transaction.
  • the inter-bank exchange center aggregates all the notification transactions of the day into a file and sends it to the acquirer, so that the acquirer can find the transaction that has not received the notification according to the document, and reissue the notice to the merchant.
  • the online transaction result notification transaction is initiated by the card issuer and received by the acquirer via the exchange system.
  • the online transaction results notify the transaction error processing as well as the existing consumption result notification.
  • the document can be a merchant delivery notice or a cardholder receipt receipt when the order is placed.
  • the acquirer is responsible for obtaining relevant documents and providing them to the card issuer to assist the card issuer in determining whether the merchants are shipped.
  • the reason for the refund can be that the merchant has not shipped the goods, but it cannot be the cardholder certification.
  • the invention provides an online secure payment method, which comprises: after the card issuing subsystem performs cardholder identity authentication, performs deduction processing according to the authentication result, and returns the cardholder identity authentication result and the deduction processing result through the acquiring subsystem.
  • an online secure payment method which comprises: after the card issuing subsystem performs cardholder identity authentication, performs deduction processing according to the authentication result, and returns the cardholder identity authentication result and the deduction processing result through the acquiring subsystem.
  • the payment process is as follows: First, the cardholder logs in to the merchant's website, selects the product, confirms the order submission, and then the merchant website sends the cardholder information.
  • the routing server finds the corresponding card issuing institution according to the card number, and returns the routing information of the card issuing institution subsystem to the merchant website; subsequently, the merchant website sends the cardholder information and the debit information to the card issuing subsystem, and then issues the card.
  • the subsystem first authenticates the cardholder's identity, then performs debit processing according to the result of the authentication, and returns the debit processing result and the authentication result to the cardholder terminal and the merchant website through the Internet, and obtains the acquiring subsystem through the routing server.
  • the routing information returns the deduction processing result and the authentication result to the acquiring subsystem, and the acquiring subsystem notifies the merchant.
  • the card issuing subsystem can set a transaction code for each transaction, and the acquiring subsystem and the merchant website can judge whether the return processing result and the authentication result returned this time have been received according to the transaction code.
  • the cardholder When using an existing payment system consisting of an inter-bank exchange center, first, the cardholder logs into the merchant website, selects the merchandise, confirms the order submission, and then, the merchant website connects to the acquiring subsystem, and obtains the routing information of the card issuing subsystem through the routing unit. Sending the cardholder information and transaction information to the card issuing subsystem, the card issuing subsystem first establishes interaction with the cardholder, performs cardholder identity authentication, and performs debit processing according to the authentication result, and then the cardholder is The identity authentication result and the debit processing result are sent to the acquiring subsystem through the inter-bank switching center to notify the merchant.
  • the routing unit can set a transaction code for each transaction, and the acquiring subsystem and the merchant website can judge whether the deduction processing result and the authentication result returned this time have been received according to the transaction code.
  • the invention also provides an online secure payment method. Still referring to FIG. 9, it can also be a flowchart of the online secure payment method of the present embodiment. The method includes the following steps:
  • S110 The cardholder terminal submits an order to the merchant website
  • S120 The merchant website initiates a transaction request to the acquiring subsystem
  • the acquiring subsystem establishes an interaction with the cardholder terminal, and obtains card number information input by the cardholder;
  • S140 The acquiring subsystem sends the card number information and the transaction information to the routing unit;
  • S150 If the card issuer corresponding to the card number adopts the card issuer direct authentication and authorization mode, the routing unit sends the card number information and the transaction information to the security certification authority corresponding to the card issuer;
  • S160 The security certification authority unit authenticates the cardholder
  • the card issuing subsystem searches for the corresponding database after receiving the consumption determination notification of the inter-row switching center, and returns the acceptance information to the acquiring sub-system after the corresponding debit processing is found, so as to notify the merchant.
  • an online payment mode that can be implemented is provided. Moreover, for the cardholder, it is not only the authentication information that the authentication identity is successful, but the transaction processing result of whether the transaction is successful. From the perspective of data interaction process, during an online transaction process, the payment process can be completed by accessing the card issuance subsystem to improve resource utilization. Moreover, the present invention also improves the security of the payment process by issuing a consumption determination request to the card issuing subsystem through the inter-bank switching center through the receivable subsystem.
  • FIG. 10 a specific flowchart of the online secure payment method of this embodiment may be used. It includes the following steps:
  • the cardholder logs into the merchant website through an internet browser, selects the product, and confirms the order submission;
  • the merchant website redirects the cardholder webpage to the security plug-in, and transmits the order information and transaction information to the security plug-in;
  • 3- Security plug-in displays the card to the cardholder, allowing the cardholder to enter the card number, and the cardholder clicks to submit;
  • the security plug-in sends the card number, the transaction type and other information to the routing unit to query the routing information;
  • the routing unit judges that it belongs to the security authentication and authorization unit mode according to the card number of the cardholder, and generates a unique identifier id of the transaction, and sends the card number, the transaction type, the transaction unique identifier id and the like to the corresponding security authentication and authorization unit, and the security certification.
  • the authorization unit queries whether the cardholder is registered, and the security certification authority returns the result;
  • the routing unit passes the security authentication authorization unit return result and the transaction unique identifier id to the security plugin; if the returned result is that the cardholder is not registered, the process ends;
  • the security certification authority unit is for the cardholder, allowing the cardholder to input relevant information and certify the cardholder;
  • the security certification authority transmits the transaction information (including the transaction unique identifier id) to the card issuing system, and causes the card issuing system to perform related accounting processing;
  • the security certification authority sends the authentication result, the accounting result and other information to the security plug-in through the cardholder's browser;
  • the security plug-in receives relevant information and passes the information required by the acquiring system to the acquiring system;
  • the security plug-in does not receive the information sent back by the security authentication and authorization unit, the relevant information is still transmitted to the acquiring system, so that the acquiring system can initiate the corresponding confirmation transaction. This is to ensure that the security authentication and authorization unit has been processed in the event of instability in the network environment, and that the transaction cannot be successfully delivered to the security plug-in.
  • the 13-acquisition system groups the relevant information according to the transaction type according to the transaction type, and initiates a corresponding confirmation transaction;
  • the 14-inter-bank switching system forwards the transaction request message to the card issuance system
  • the card issuance system searches the account system, confirms whether the relevant account processing has been done, and decides whether or not to convert the transaction processing result to the inter-bank exchange system;
  • the 16-interline exchange system returns the transaction processing result to the acquiring system;
  • the 17-acquisition system notifies the merchant after receiving the transaction result.
  • the receipt subsystem sends a confirmation transaction request
  • the message carries the transaction unique identifier id generated by the routing unit, and the card issuing subsystem can determine a transaction by using the card number + the acquirer code + the merchant code + the transaction unique identifier id,
  • a confirmation transaction is received, a transaction is located and it has been confirmed whether the relevant transaction has been processed.
  • the confirmation transaction may be repeated, but it must be indicated as a duplicate transaction in the confirmation transaction.
  • the exchange system After the inter-bank exchange receives the confirmation request, if the identified transaction is a duplicate confirmation transaction, the exchange system first looks for the original transaction. If the original transaction is accepted, it does not need to forward the direct response to the acquiring subsystem to the card issuing subsystem. If the original transaction is rejected, there is no need to forward to the issuing subsystem to directly reject the receipt subsystem. If the original transaction does not answer, the duplicate confirmation transaction is forwarded to the card issuing subsystem.
  • the card issuing subsystem When the card issuing subsystem receives the duplicate confirmation transaction, it first looks for the original transaction, and if it does not find the original transaction, it is treated as a new transaction. If the original transaction is found and has been processed, there is no need to repeat it and the response can be given directly.
  • the card issuer may have debited before receiving the consumer confirmation transaction, it is only confirmed by the acquirer through the consumer confirmation transaction, so the consumer confirmation transaction cannot trigger the correction.
  • a consumer confirmation transaction is similar to a consumer transaction, with subsequent transactions such as cancellation. Subsequent transactions such as cancellations need to match the consumer confirmation transaction.
  • the line exchange center will perform liquidation based on the consumer confirmation transaction.
  • the exchange system successfully receives a response from the card issuer for the consumer confirmation transaction and cannot forward it to the acquirer, the consumer confirmation transaction is still involved in the liquidation, and the acquirer processes it through the correction.
  • the acquirer can repeatedly initiate a consumer confirmation transaction. If the exchange system receives multiple transactions, it will only liquidate one.
  • the exchange system aggregates all confirmed transactions on the day into documents, including accepted and unconfirmed, and is sent to the acquiring institution and the issuing institution respectively.
  • Card issuer Find the account system if the debit has not been accepted, the relevant processing, reduce the chance of wrong accounting.
  • the acquiring institution searches according to the documents, and if some confirmed transactions have not received the response, the result is notified to the merchant in time.
  • the acquiring institution needs to send additional online transaction documents, forward it to the card issuer through the exchange system, and let the card issuer make relevant Accounting treatment, further reducing the situation of unilateral accounts.
  • the document can be a merchant delivery notice or a cardholder receipt receipt when the order is placed.
  • the acquirer is responsible for obtaining relevant documents and providing them to the card issuer to assist the card issuer in determining whether the merchants are shipped.
  • the reason for the chargeback may be that the merchant has not delivered the goods, but it cannot be a cardholder certification.
  • the method includes the following steps:
  • the card issuing subsystem searches the database of the subsystem, and after finding the corresponding debit processing, returns the acceptance information to the acquiring subsystem to notify the merchant website. Specifically, after receiving the confirmed transaction, the card issuing subsystem searches whether the corresponding account has been subjected to the corresponding debit processing, and if so, gives an acceptance response, otherwise a rejection response is given; the acquiring sub-system notifies the merchant of the result.
  • the routing server can perform the consumption confirmation.
  • the cardholder logs into the merchant website and selects The goods, confirm the order submission, and then, the merchant website sends the cardholder information to the routing server, and then the routing server finds the corresponding card issuing institution according to the card number, and returns the routing information of the card issuing institution subsystem to the merchant website; subsequently, the merchant website will hold The card information and the debit information are sent to the card issuing subsystem.
  • the card issuing subsystem first authenticates the cardholder's identity, and then performs debit processing according to the result of the authentication, and returns the deduction processing result and the authentication result to the Internet through the Internet. Card terminal and merchant website.
  • the inquiry request may be directly sent to the card issuing subsystem.
  • the merchant website may issue a query request to the acquiring subsystem, and the query request includes at least the card number, the transaction identifier and the like.
  • the acquiring subsystem obtains the routing information of the card issuing subsystem through the routing server, and establishes interaction with the card issuing subsystem: sending the consumption confirmation request to the card issuing subsystem and the card issuing subsystem returning the acceptance information.
  • the acquiring subsystem can also establish data interaction between the issuing subsystem and the acquiring subsystem through the existing inter-bank switching center provided by UnionPay: sending the consumption confirmation request to the issuing subsystem and the issuing subsystem to return the acceptance information.
  • UnionPay's inter-bank exchange center is currently a relatively mature technology, it can fully utilize the current inter-bank exchange center for online payment and subsequent online determination.
  • the inter-bank switching center performs the clearing step according to the confirmed transaction within the preset period: the inter-bank switching center aggregates all unaccepted confirmation transactions within the preset time period and sends them to the card issuing subsystem, and the card issuing subsystem confirms all the unaccepted The transaction is checked for comparison.
  • the present invention mainly provides an online payment platform, so that banks currently using different transaction modes perform transaction processing on the platform, thereby solving the existing online transaction process.
  • Technical deficiencies in confusion and waste of resources are for illustrative purposes only and are not intended to limit the invention.

Description

网上安全支付系统和方法、 以及路由服务器 技术领域
本发明涉及网络数据处理领域,尤其涉及有关于网上支付的网上 安全支付系统。
背景技术
随着网絡技术的发展, 特别是因特网的普及, 网络已成为很多人 生活和工作中一个不可获缺的部分。人们不仅可以利用因特网浏宽新 闻、 发布消息、 接听音乐, 而且可以进行网络购物。 基于电子商务不 断的增长, 网上支付的安全性不仅是交易双方需要关注的问题, 同时 还是金融系统特别重视的一个问题。
请参阅图 1 , 其为现有技术中常见的一种网上安全支付系统的结 构示意图。 它包括持卡人终端 11、商户网站 12、收单子系统 13。其中, 持卡人终端 11通过因特网连接商户网站 12,商户网站 12通过因特网或 专线连接至收单子系统 13。 收单子系统 13至少包括通信服务器、应用 服务器及数据库服务器。通信服务器用以建立与各家商户的商户网站 12连接, 并对接收的数据包进行安全检测。应用服务器用于对接收到 的各种商户网站 12的各种数据进行处理,并根据处理的结果修改数据 库服务器中的信息, 并将处理结果返回至商户服务器 12, 而数据库服 务器保存着本收单子系统 13中每一账号的相应信息。
这种网上安全支付系统适用于发卡机构与收单机构是同一家金 融机构的情况下的安全支付。 其支付流程如下所示: 首先, 持卡人登 录商户网站 12, 选取商品, 确认订单提交, 然后, 商户网站 12将订单 信息、 交易信息等数据发送至发卡机构的发卡子系统 13。发卡子系统 13接收用户输入的卡号及密码等数据, 经过持卡人身份认证、 商户的 身份认证等安全认证通过后, 才进行扣款处理, 扣款完成后, 商户才 进行发货。 当发卡机构和收单机构不在同一家时,可以通过另一种支付系统 进行支付。请参阅图 2, 其为本发明的另一种支付系統的结构示意图。 它包括持卡人终端 11、 商户网站 12、 若干发卡子系统 14。 持卡人终端 11与商户网站 12通过因特网连接,商户网站 12也通过因特网连接若干 家发卡子系统 14。商户网站 12中保存着每个与所述商户网站 12连接的 发卡子系统 14的路由信息, 并且建立卡号的 BI 码与发卡子系统 14的 路由信息的对应关系。
其支付流程为: 首先持卡人登录商户网站 12, 选取商品, 确认订 单提交, 然后, 商户网站 12建立与持卡人终端 11的交互, 要求持卡人 输入卡号, 随后, 商户网站 12根据其卡号的 BIN码找到所述卡号的发 卡机构对应主机的路由信息,将持卡人信息及订单信息发送至发卡子 系统 14, 进行扣款处理。
上述支付系统及支付流程存在很多问题, 首先: 网上支付的安全 性低, 由于因特网上的商户网站的数量多, 而目前却缺少有利机制约 束商户, 商户网站可以直接获得持卡人的卡号信息, 由此造成对持卡 人的财产安全带来很大隐患。 其次, 正是缺少有利机制约束商户, 而 使得很多发卡机构不愿直接建立与商户网站的连接: 告知卡号 BIN码 与发卡机构的对应关系, 告知发卡机构主机的路由信息, 由此导致持 卡人能够进行付款消费的 艮行卡的种类受到极大限制。
为此, VISA公司提出了又一种网上支付系统和网上支付流程。 请参阅图 3, 其为 VISA公司提出的网上支付系统的结构示意图。 它包 括持卡人终端 11、 商户网站 12、 收单子系统 13、 由 VISA公司提供的 路由服务器 15及发卡子系统 14。 其中, 路由服务器 15可以通过因特网 分别连接收单子系统 13、发卡子系统 14和商户网站 12。在商户网站 12 上设置一由收单子系统 13提供的 MPI软件。
首先,持卡人登录商户网站 12,选取商品,确认订单提交, 然后, 商户网站利用 MPI软件将持卡人信息发送至路由服务器 15 , 随后, 路 由服务器 15根据卡号找到对应的发卡机构,返回发卡子系统 14的路由 信息至商户网站 12; 随后, 发卡子系统 14认证持卡人的身份, 通过因 特网将认证结果返回至持卡人终端 11和商户网站 12。当认证结果为认 证通过时, 经传统的发卡系统扣款处理, 才向持卡人进行发货。
以上公开了在三种现有银行采用的交易模式下,为了完成安全网 上支付而建立的三种不同的系统架构。由于各个系统仅仅能满足一种 交易方式, 如果用户使用的银行卡的发卡行设置的交易模式, 与上述 某个系统确立的交易方式不同,则用户就无法使用该银行卡在该系统 上完成安全网上支付,导致很多的安全网上支付的数据处理流程无法 顺利完成。
以上公开仅为现有银行采用的几种较为常见的网上支付的交易 模式, 事实上, 银行采用网上支付的交易模式并不仅仅是上述公开的 几种, 而银行业发展至今, 国内已有几十家银行, 很多建立网上支付 业务的银行采用的交易模式是不同的,由此导致整个网上银行交易的 混乱以及存在网上安全性不高的缺陷。 并且, 网上银行业务是未来业 务发展的一个方向, 为此, 很多家银行设置若干不同的交易模式或者 有设置不同交易模式的计划, 进而存在资源浪费的缺陷。
发明内容
本发明的目的在于提供一种网上安全支付系统,以便建立网上支 付的一个统一平台,进而解决现有网上交易流程混乱以及资源浪费的 技术问题。
为解决上述问题, 本发明公开了一种网上安全支付系统, 包括持 卡人终端、 商户网站、 收单子系统、 发卡子系统, 还包括与收单子系 统和发卡子系统连接的路由单元, 其中:
所述路由单元, 包括: 存储模块, 用以保存各发卡子系统所采用 的交易模式以及每一"" ^号 BIN对应的路由信息及处理流程; 处理模 块,用以根据从收单子系统接收的卡号确定对应发卡子系统采用的交 易模式, 按照相应处理流程进行处理。
优选的, 所述的网上安全支付系统, 还包括安全插件, 与收单子 系统相连, 或者设置在收单子系统内; 所述安全插件用以建立商户网 站、 持卡人终端、 路由单元的数据交互: 与持卡人终端的交互, 获得 持卡人的卡号信息, 与路由单元的交互, 获得路由信息或对应的处理 流程。
优选的, 所述的网上安全支付系统, 还包括安全认证授权单元, 与发卡子系统相连, 或者设置在发卡子系统内; 所述安全认证授权单 元至少包含认证子单元和通知子单元,认证子单元用于对持卡人进行 身份认证; 通知子单元: 将安全认证授权单元对持卡人的身份认证结 果和发卡子系统的扣款处理结果组成网上交易结果通过因特网发送 至持卡人终端。优选的, 所述路由单元保存每个采用直接认证授权模 式的发卡子系统对应的安全认证授权单元的路由信息。
优选的,所述的网上安全支付系统,还包括持卡人安全控制单元, 用于建立与持卡人终端的交互,接收持卡人输入表征持卡人身份的安 全信息。所述路由单元保存每个釆用持卡人安全控制单元认证的发卡 子系统对应的持卡人安全控制单元的路由信息。优选的, 所述的网上 安全支付系统, 还包括持卡人安全互动单元, 所述持卡人安全互动单 元连接持卡人安全控制单元,用于将认证信息经约定渠道发送至持卡 人终端, 以及接收持卡人输入的认证信息, 并对所述信息进行认证。
优选的, 所述持卡人安全控制单元、路由单元、持卡人安全互动 单元可设置一服务器上。
优选的, 所述安全插件包含以下单元: 验证商户单元: 用于对发 起订单交易请求的商户进行身份认证; 交互控制单元: 用于控制与商 户网站、 持卡人终端、 路由单元、 安全认证授权单元、 持卡人安全控 制单元的数据交互; 数据存储单元: 用于存储包括商户信息的数据; 认证和传输单元:用于对接收到的数据包和发送的数据包进行安全认 证。
本发明还公开了一种路由服务器, 包括以下部件:
存储单元:用于保存各发卡子系统所采用的交易模式以及每一卡 号 BIN对应的路由信息及处理流程;
直接认证授权模式处理单元: 当所述卡号对应的发卡子系统采用 直接认证授权模式,则返回所述卡号对应的安全认证授权单元的路由 Ίσ·息;
持卡人安全控制单元认证模式处理单元: 当所述卡号对应的发卡 子系统采用持卡人安全控制单元认证模式,则返回所述持卡人安全控 制单元的路由信息;
收单子系统自行处理模式处理单元: 当所述卡号对应的发卡子系 统采用收单子系统自行处理模式 ,则将所述处理模式通知对应的收单 子系统。
本发明还提供了一种网上安全支付方法, 包括: 收单子系统获取 交易请求和持卡人卡号信息;路由单元根据所述卡号确定对应发卡子 系统采用的交易模式, 按照相应处理流程进行信息处理; 收单子系统 或者发卡子系统完成交易结算, 返回结果信息。
其中,
如果所述卡号对应的发卡子系统采用收单子系统自行处理模式, 则路由单元通知对应的收单子系统; 收单子系统完成交易结算, 返回 结果信息。
如果所述卡号对应的发卡子系统采用持卡人安全控制单元认证 模式, 则路由单元返回所述持卡人安全控制单元的路由信息; 所述持 卡人安全控制单元建立与持卡人终端的交互,接收持卡人输入表征持 卡人身份的安全信息; 发卡子系统认证后完成交易结算, 返回结果信 如果所述卡号对应的发卡子系统采用直接认证授权模式,则路由 单元返回所述卡号对应的安全认证授权单元的路由信息;发卡子系统 认证后完成交易结算, 返回结果信息。
本发明还提供了另一种网上安全支付方法, 所述方法包括:
( 1 ) 当商户网站接收到持卡人的订单信息时, 建立持卡人与安 全插件的交互,所述安全插件接收持卡人输入的需要支付交易额的卡 号;
( 2 )安全插件将卡号、 订单信息转发至路由单元; 路由单元根 据持卡人输入的卡号,判断是否是采用持卡人安全控制单元进行认证 W
的认证方式, 若是, 将对应的持卡人安全控制单元的路由信息发送至 安全插件;安全插件将所述卡号及持卡人信息发送至持卡人安全控制 单元;
( 3 )持卡安全控制单元与持卡人建立交互, 接收持卡人输入表 征持卡人身份的安全信息, 并将所述安全信息发送至安全插件;
( 4 )安全插件将所述安全信息及订单信息组入交易请求报文, 通过跨行交换中心或者根据路由单元提供的路由信息发送至对应的 发卡子系统;
( 5 )发卡子系统对其进行身份认证和授权扣款处理后 , 返回处 理结果。
优选的, 通过以下步骤完成持卡安全控制单元与持卡人的交互: bl: 持卡人安全控制单元将卡号发送至持卡人安全互动单元,持 卡人安全互动单元向持卡人安全控制单元返回界面输入要求;
b2: 持卡人安全互动单元经约定渠道将认证信息发送至持卡人; b3: 持卡人安全控制单元接收输入信息, 并将所述输入信息发送 至持卡人安全互动单元;
b4: 持卡人安全互动单元认证所述输入信息, 并将认证后的信息 发送至持卡人安全控制单元。
优选的,安全插件引导持卡人建立与持卡人安全控制单元认证的 SSL安全通道,检验持卡人证书的有效性并建立提供安全传输数据的 通道; 证书有效性被认可后, 持卡人安全控制单元通过持卡人终端的 浏览器显示需要持卡人输入信息, 并通过 SSL服务器模块获得证书 的 DN和持卡人输入的卡号, 验证该证书和卡号是否是有效绑定, 若 是有效, 则将持卡人输入的信息发送至安全插件, 否则将验证无效结 果传送至安全插件。
本发明还公开了一种网上安全支付方法, 其特征在于, 该方法包 括以下步骤:
(1)持卡人终端向商户网站提交订单;
(2)商户网站向收单子系统发起交易请求; (3)收单子系统与持卡人终端建立交互, 获得持卡人输入的卡号 信息;
(4)收单子系统将卡号信息和交易信息发送至路由单元;
(5)若所述卡号对应的发卡机构釆用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
(6)安全认证授权单元认证所述持卡人;
(7)认证通过后, 发卡子系统进行扣款处理;
(8)发卡子系统将扣款处理结果和认证结果发送至收单子系统;
(9)收单子系统通知商户。
优选的, 步骤(5 )和步骤(6 )之间还包括: 安全认证授权单元 判断所述持卡人是否已注册, 并将注册结果返回至路由单元; 路由单 元给本次支付分配一交易标识码,并将注册结果和标识码分配至收单 子系统; 若注册结果为持卡人已注册, 则收单子系统将卡号信息、 订 单信息和业务标识码发送至安全认证授权单元, 请求认证持卡人。
优选的, 通过以下步骤将交易结果信息发送至收单子系统: 发卡子系统发送网上交易结果通知至跨行交换中心,所述网上交 易结果中包含唯一交易标识码; 当发卡子系统在预设时间内未收到网 上交易结果的应答, 在限定次数内重新发出网上交易结果通知; 跨行 交换中心接收到网上交易结果后, 返回应答消息, 并向对应的收单子 系统发送网上交易结果; 当跨行交换中心在预设时间内未收到网上交 易结果的应答,在限定次数内重新发出网上交易结果通知至收单子系 统。
优选的, 所述的网上安全支付方法, 还包括:
跨行交换中心在预设周期内按照交易标识码进行清算步骤:跨行 交换中心将预设时间周期内所有的网上交易结果通知汇总后发送至 对应的收单子系统;
收单子系统将未收到的网上交易结果通知发送至对应的商户网 站。 优选的, 通过以下步驟将交易结果信息发送至收单子系统: 发卡子系统将认证结果和扣款处理结果组成网上交易结果通过 因特网发送至持卡人终端, 网上交易结果还包括交易标识码; 持卡人 终端通过因特网将所述网上交易结果发送至收单子系统。
本发明还提供了一种网上安全支付方法, 该方法包括以下步骤:
(1) 持卡人终端向商户网站提交订单;
(2)商户网站向收单子系统发起交易请求;
(3)收单子系统与持卡人终端建立交互, 获得持卡人输入的卡号 信息;
(4)收单子系统将卡号信息和交易信息发送至路由单元;
(5)若所述卡号对应的发卡机构采用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
(6)安全认证授权单元认证所述持卡人;
(7)认证通过后, 发卡子系统进行扣款处理, 并返回交易结果;
(8) 当收单子系统在预设时间内未收到网上交易结果,则通过跨 行交换中心或者路由单元向发卡子系统发送消费确定请求;
(9) 发卡子系统接收到消费确定请求后查找对应的数据库,当查 找到经过对应的扣款处理后 , 返回承兌信息至收单子系统。
与现有技术相比, 本发明具有以下优点:
本发明提供了一个平台,使得目前采用不同交易模式的银行都可 以在该平台上进行交易处理,以此解决现有网上交易流程混乱以及资 源浪费的技术缺陷。 并且, 本发明通过收单机构上设置安全插件, 来 进行与持卡人的交互, 获得卡号信息, 提供了安全性。
本发明提供了一种能够实现的网上安全支付系统及方法,将认证 过程和扣款过程合成一个支付流程, 不仅提高了支付的处理速度, 而 且也提高了网上资源的利用率。 最重要的是, 由发卡机构主动将交易 结果通过交换中心转发给收单机构, 采用现有的专有网络, 耗时少, 异常情况少,有效地减少单边账的情况发生,进而提高了交易成功率。 并且, 本发明给持卡人和商户提供的是交易是否成功的信息, 而不是 认证是否通过的信息。 商户从收单机构得到的交易成功信息, 可以作 为发货依据。 另外, 通过本发明的方法, 发卡机构能够将交易是否成 功信息发送至商户, 提高了网上交易的可实现性。
本发明可以设置统一的网上安全控制子系统,因此为用户提供统 一的交易界面成为可能,对于发卡机构而言, 每次交易不管其设置的 发卡子系统的结构如何,在现行加入跨行交换子系统的银行都能利用 此方法进行网上支付, 提高了本发明适用的范围; 并且, 本发明通过
API (安全插件)直接建立与持卡人的交互, 获得卡号信息, 避免通 过良莠不齐的商户来获得持卡人的卡号,进一步网上支付的提高了安 全性。
附图说明 图 1为现有技术提供的一种网上支付系统的结构示意图; 图 2为现有技术提供的另一种网上支付系统的结构示意图; 图 3为 VISA提供的又一种网上支付系统的结构示意图; 图 4是本发明的网上安全支付系统的结构示意图;
图 5是本发明网上安全支付方法的流程图;
图 6是本发明提供的另一种网上安全支付方法的流程图; 图 7是现有的 VISA公司提供的网上支付系统改良后的网上支付 系统结构示意图;
图 8 是由银联提供的银行系统进行改良完成的网上安全支付系 统的结构示意图;
图 9是本发明提供的一种网上安全支付方法的流程示意图; 图 10是本发明提供的一种网上安全支付方法的流程示例示意 图;
图 11是本发明提供的另一种网上安全支付流程示意图。
具体实施方式 以下结合附图, 具体说明本发明。
基于现有繁多的交易模式,本发明提供了一个平台,使得目前的 交易模式都能够在本发明提供的安全支付平台上运行。 目前的交易模 式主要有三种: 收单机构自行处理模式、 网银中心认证模式(持卡人 安全控制单元认证模式)、 发卡机构直接认证授权模式。 当然, 随着 电子交易的发展, 也许会出现越来越多的交易模式, 本发明提供的安 全支付系统能够使得上述三种交易模式或将来出现的其他交易模式 都能够在该平台上进行运行。
请参阅图 4, 其为本发明提供的网上安全支付系统的结构实例示 意图。 本发明提供的网上安全支付系统能够提供三种交易模式: 收单 机构自行处理模式、 网银中心认证模式(持卡人安全控制单元认证模 式)、 发卡机构直接认证授权模式。 它包括: 持卡人终端 21、 商户网 站 22、 收单子系统 23、 跨行交换系统 24、 发卡子系统 26、 路由单元 25、 网上安全控制子系统和安全认证授权单元 30。 其中:
持卡人终端 21 , 连接商户网站 22, 用于建立持卡人和商户的连 接, 它们通常通过互联网连接, 比如: 持卡人终端上互联网浏览器登 录至商户网站, 选取商品, 进行订单提交。
商户网站 22, 连接收单机构。
跨行交换系统 24, 通过专线连接至每一发卡子系统 26与收单子 系统 23 , 用以建立发卡机构和收单机构的连接。 能对每一交易和各 个收单机构和发卡机构进行清算。 跨行交换中心 24可以采用中国银 联的跨行交换系统。
安全认证授权单元 30, 在每个发卡机构内设置一安全认证授权 单元,所述通知子单元将安全认证授权单元对持卡人的身份认证结果 和发卡子系统的扣款处理结果组成网上交易结果通过因特网发送至 持卡人终端;
路由单元 25,保存各家发卡机构所采用的交易模式以及每一 BIN 对应的路由信息及处理流程,用以根据接收的卡号确定对应发卡机构 采用的交易模式, 按照所述处理流程进行处理。
发卡子系统 26, 用于根据订单进行扣款处理; 网上安全控制子系统: 与持卡人建立交互,接收持卡人输入表征 本持卡人身份的安全信息。
路由单元 25保存卡号 BIN码和发卡机构对应关系, 保存每一发 卡机构采用的交易模式, 所述发卡机构对应的路由信息或处理流程。 当所述卡号对应的发卡机构采用直接认证授权模式时, 保存 BIN和 安全认证授权单元 30的路由信息的对应关系, 当所述发卡机构采用 收单机构自行处理模式时, 返回收单机构自行处理的指示, 当所述卡 号对应的发卡机构采用持卡人安全控制单元认证模式时,返回持卡人 安全控制单元的路由信息。 路由单元 25可以根据具体支持的交易模 式进行编程设置。 路由单元 25通常由协作机构提供, 它可以是一具 有路由功能的服务子系统或服务器。
网上安全控制子系统包括持卡人安全控制单元 27, 用于接收表 征持卡人身份的安全信息。 目前表征持卡人身份的安全信息: 如卡号 及对应密码,这种安全信息的安全性直接联系到整个网上支付业务的 商户网站来获得,由于商户网站的合法性无法确认以及其安全性不高 的特点, 导致整个网上支付业务的安全性都较低。 若将接收持卡人输 入表征持人身份的安全信息(如卡号及对应密码)放置在各个发卡子 系统 26时,由于各个发卡子系统 26都需要设置完成接收持卡人输入 安全信息的持卡人安全认证单元, 因此实现难度大、 投资高。 而本发 明仅可以设置一个网上安全控制子系统,完成所有发卡机构比较头痛 之事: 建立交互界面, 安全接收持卡人输入的安全信息。 比如, 本申 请人中国银联建立一个网上安全认证子系统,所有发卡机构即可利用 该网上安全认证子系统得到持卡人输入的安全信息,大大提高了整个 网上支付过程的安全性。 并且, 在发卡机构端, 无需各自建立持卡人 安全认证单元, 減少了大量的重复投资。
为了提高网上支付的安全性,本发明还可以在现有的网上安全控 制子系统中设置一持卡人安全互动单元 28, 所述持卡人安全互动单 元 28连接持卡人安全控制单元 27, 用于将网上支付密码信息经约定 渠道发送至持卡人后, 通过持卡人安全控制单元 27接收持卡人输入 的密码信息, 并对所述信息进行认证。
即: 当持卡人与持卡人安全控制单元 27建立交互时, 持卡人安 全互动单元 28 通过预先约定的渠道将产生的动态密码发送至持卡 人, 持卡人接收到该动态密码后输入持卡人安全控制单元 27提供的 输入界面, 持卡人安全控制单元 27将输入信息发送至持卡人安全互 动单元 28进行认证, 比如, 输入信息中动态密码与通过其它渠道发 送给用户的密码是否相同, 若是, 则表明认证通过, 否则认证没有通 过。 当然, 为了避免用户不小心写错密码, 也可以设置输入的次数。 为了保证认证的可靠性, 也可以设置动态密码的有效期。
持卡人终端 21通过因特网连接各个商户网站 22, 很多商户网站 22通过因特网或专线连接至一收单子系统 23。为了收单子系统 23的 安全, 本发明给每个收单机构设置一对应的安全插件 29。 安全插件 29可以直接与对应的收单子系统 23连接, 也可以直接设置在收单子 系统 23内。 并且, 通过安全插件 29可以建立与持卡人终端 21的直 接交互。 收单子系统 23通过专线与跨行交换中心 24建立连接, 而安 全插件 29可以通过专线也可以通过因特网与路由单元 25建立连接。 每一发卡子系统 26通过专线连接至跨行交换中心 24, 当发卡机构采 用发卡机构直接认证授权模式,在每一发卡机构对应设置一安全认证 授权单元 30。 安全认证授权单元 30可以由发卡机构直接开发, 也可 以由发卡机构委托其他公司开发, 设置在发卡子系统 26外, 直接与 发卡子系统 26连接。每一发卡机构对应的安全认证授权单元 30可以 通过专线或通过因特网连接至路由单元 25。 每一安全插件 29、 路由 单元 25、 每一安全认证授权单元 30可以是因特网上的一节点, 通过 因特网直接与各个持卡人终端 21进行连接。
安全插件 29可以是一经过编程的服务器, 也可以在原有收单子 系统内的应用服务器上进行编程处理。 安全插件可以包含以下单元: 验证商户单元: 用于对发起订单交易请求的商户进行身份认证。 收单机构下属的商户注册后,将本商户的商户信息保存在数据存储单 元。每一商户有一唯一商户标识(比如商户名、或商户网站对应的 IP 号), 当商户发起订单交易请求时, 验证商户单元根据数据存储单元 的商户信息进行商户身份认证。
交互控制单元: 用于控制与商户网站、 持卡人终端、 路由单元、 持卡人安全控制单元、安全认证授权单元的数据交互。 交互控制单元 保存该些交互对象(商户网站、 持卡人终端、 路由单元、 安全认证授 权单元)的路由信息, 及交互触发流程。 比如, 当商户身份认证通过 后, 从商户发送的交易请求中获得持卡人终端的路由信息, 建立与持 卡人的交互, 获得持卡人的卡号信息; 将持卡人的卡号信息及相应的 本次交易信息发送至路由单元,获得交易的认证类型及对应的安全认 证授权单元的路由信息, 以及交易识別码; 当接收到交易处理结果返 回至商户网站等等。
数据存储单元: 用于存储数据, 用于存储商户信息及安全插件
29在交易过程中必要的数据: 如每一次交易的交易识别码。
认证和传输单元:用于对接收到的数据包和发送的数据包进行安 全认证。每一次和其他设备进行数据交互, 都需要进行严格的安全控 制。 比如, 发送方向接收方提出交易处理之前, 先用数字证书进行双 方的身份认证, 认证成功后, 协商加密交易数据的对称密钥, 发送方 使用对称密钥对数据交易数据加密发送至接收方,接收方使用对称密 钥解密后, 将响应数据通过对称密钥加密后再返回。 安全插件 29即 可以做为发送方, 也可以做为接收方, 认证和传输单元主要负责数据 交互过程中的安全控制。
当持卡人安全控制单元 27接收到认证成功消息时, 将用户输入 的安全信息 (如密码)发送至安全插件 29, 当持卡人安全控制单元 27接收到认证失败消息时, 可以将认证失败消息直接发送至安全插 件 29, 安全插件 29即可采用后续的处理(如返回至商户: 此用户的 身份需要进一步确认等)。
上面对一种优选的安全插件 29的内部结构进行了描述, 当然, 本领域技术人员还可以采用其他可行的方式实现,只要能够完成相应 功能即可。 上述优选的安全插件 29中包括的验证商户单元和认证和 传输单元, 可以用来提高和保证数据传输中的安全性。
安全插件 29通常可设置在由收单机构开发的收单子系统上。 而 所述持卡人安全控制单元 27、 路由单元 25、 持卡人安全互动单元 28 可设置一服务器上。
本发明还基于现有银行已经设置的交易模式构造了一种路由服 务器, 包括以下部件:
存储单元:用于保存各发卡子系统所采用的交易模式以及每一卡 号 BIN对应的路由信息及处理流程;
直接认证授权模式处理单元: 当所述卡号对应的发卡子系统采用 直接认证授权模式,则返回所述卡号对应的安全认证授权单元的路由 信息;
持卡人安全控制单元认证模式处理单元: 当所述卡号对应的发卡 子系统采用持卡人安全控制单元认证模式,则返回所述持卡人安全控 制单元的路由信息;
收单子系统自行处理模式处理单元: 当所述卡号对应的发卡子系 统釆用收单子系统自行处理模式,则将所述处理模式通知对应的收单 子系统。
上述路由服务器与收单子系统和发卡子系统相连,即可满足各个 银行的交易处理, 提高用户使用银行卡进行网上安全支付的便利性。
以下基于公开的安全支付系统, 叙述安全支付流程。
( 1 )持卡人终端向商户网站提交订单;
( 2 ) 商户网站向安全插件发起交易请求;
( 3 )安全插件与持卡人终端建立交互, 获得持卡人输入的卡号 信息;
( 4 )安全插件将卡号信息和交易信息发送至路由单元, 路由单 元根据卡号确定发卡机构采用的交易模式,如采用收单机构自行处理 模式, 则进行过程 A, 如采用持卡人安全控制单元认证模式, 则进行 过程 B、 若采用发卡机构直接认证授权模式, 则进行过程 C。
过程 A
A1 : 路由单元通过卡号判断所述交易属于收单机构自行处理模 式, 则通知所述安全插件;
A2: 安全插件将所述卡号和订单信息发送至收单子系统; A3: 收单子单元自行处理后续流程: 认证和授权扣款处理后, 通知持卡人和商户。
过程 B
B1 : 路由单元根据持卡人输入的卡号, 判断是否是采用持卡人 安全控制单元进行认证的认证方式, 若是, 将对应的持卡人安全控制 单元的路由信息发送至安全插件;
B2:安全插件先将卡号信息发送至持卡人安全控制单元; B3: 安全插件将所述卡号及持卡人信息发送至持卡人安全控制 单元: 持卡人安全控制单元将卡号发送至持卡人安全互动单元, 持卡 人安全互动单元向持卡人安全控制单元返回界面输入要求;持卡人安 全互动单元经约定渠道将认证信息发送至持卡人;持卡人安全控制单 元接收输入信息, 并将所述输入信息发送至持卡人安全互动单元; 持 卡人安全互动单元认证所述输入信息,并将认证信息发送至持卡人安 全控制单元;
B4: 安全插件将所述安全信息及订单信息组入交易请求报文, 通过跨行交易子系统发送至对应的发卡子系统;
B5: 发卡子系统对其进行身份认证和授权扣款处理后, 返回处 理结果。
过程 C
C1 若所述卡号对应的发卡机构采用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
C2: 安全认证授权单元认证所述持卡人;
C3: 认证通过后, 发卡子系统进行扣款处理; C4: 当收单子系统在预设时间内未收到网上交易结果, 则向跨 行交换中心发送消费确定通知,所述网上交换结果是由安全认证授权 单元通过因特网回送至持卡人终端,再由持卡人终端送回至收单子系 统;
C5:发卡子系统接收跨行交换中心的消费确定通知后查找对应的 数据库, 当查找到经过对应的扣款处理后,返回承兌信息至收单子系 统, 以便通知商户。
C4 - C5步驟或由以下步骤代替: 发卡子系统将扣款处理结果和 认证结果通过跨行交换中心发送至收单子系统;
(5)收单子系统通知商户。
基于前述公开的网上安全认证系统, 本发明提供了一种认证方 法。 请参阅图 5, 其为发明提供的一种认证方法的流程图。 它包括: S110: 当商户网站接收到持卡人的订单信息时, 建立持卡人与安 全插件的交互 ,所述安全插件接收持卡人输入的需要支付交易额的卡 号;
持卡人通过安装在个人终端上互联网浏览器登陆商户网站,选择 商品并确认订单后将其提交, 商户网站将持卡人网页转向安全插件, 同时给安全插件传输订单信息。持卡人根据得到的持卡人网页建立与 持卡人的交互, 接收持卡人输入卡号信息。
S120:安全插件将所述卡号及持卡人信息发送至持卡人安全控制 单元;
S130: 持卡安全控制单元与持卡人建立交互,接收持卡人输入表 征持卡人身份的安全信息, 并将所述安全信息发送至安全插件;
S140: 安全插件将所述安全信息及订单信息组入交易请求报文, 通过跨行交易子系统发送至对应的发卡子系统;
S150:发卡子系统对其进行身份认证和授权扣款处理后,返回处 理结果。
这是本发明提供的一种安全支付方法。本发明通过一个持卡人安 安全信息和订单通过跨行交换子系统发送至发卡机构 (通常是银行 ) 进行认证和授权扣款处理。所有采用网上安全控制子系统进行认证的 发卡机构都可能通过上述方法安全得到持卡人的安全信息,不需要在 发卡子系统建立持卡人安全认证单元。网上安全控制子系统不仅可以 提供个性化的服务: 可以根据各个发卡机构的要求建立相应用户界 面, 并将持卡人输入的相应信息发送至对应的发卡机构; 而且网上安 全控制子系统也可以提供统一的用户界面, 便于持卡人方便输入。
但是,若将所有交易不管三七二十一都发给持卡人安全控制单元 进行处理, 会给持卡人安全控制单元带来很大的处理负担。 为此, 在 步骤 S110和步骤 S120之间还包括:
al:安全插件将卡号、 订单信息转发至路由单元, 查询路由信息; a2:路由单元根据持卡人输入的卡号, 判断是否是采用持卡人安 全控制单元进行认证的认证方式, 若是, 将对应的持卡人安全控制单 元的路由信息发送至安全插件, 否则, 将此卡号不支持这种认证方式 或者其他认证方式的信息发回至安全插件。
a3:安全插件先将卡号信息发送至持卡人安全控制单元, 查询所 述持卡人是否需要参予与持卡人安全控制单元的交互;
a4:持卡人安全控制单元返回查询结果;
a5:当安全插件得到的查询结果为 "是", 进行步骤 S120。 j 步骤 S130还包括: M:持卡人安全控制单元将卡号发送至持卡人 安全互动单元,持卡人安全互动单元向持卡人安全控制单元返回界面 输入要求; b2:持卡人安全互动单元经约定渠道将认证信息发送至持 卡人; b3:持卡人安全控制单元接收输入信息, 并将所述输入信息发 送至持卡人安全互动单元; b4:持卡人安全互动单元认证所述输入信 息, 并将认证信息发送至持卡人安全控制单元。 通过上述的步骤, 预 先对网上支付的持卡人进行身份认证, 由此提高网上交易的安全性。
还是为了提供安全性,安全插件还可以借助收单子系统的商户数 据库, 进行商户认证: 商户身份的认证及商户权限的认证。
并且, 安全插件 ]导持卡人建立与持卡人安全控制单元认证的 SSL安全通道,检验持卡人证书的有效性并建立提供安全传输数据的 通道;
证书有效性被认可后 ,持卡人安全控制单元通过持卡人终端的浏 览器显示需要持卡人输入信息, 并通过 SSL服务器模块获得证书的 DN和持卡人输入的卡号, 验证该证书和卡号是否是有效绑定, 若是 有效, 则将持卡人输入的信息发送至安全插件, 否则将验证无效结果 传送至安全插件。
本发明提供了一种网上安全支付方法(请参阅图 6 ), 包括: S210:由协作中心设置的持卡人安全控制单元建立与持卡人的交 互, 接收持卡人输入表征持卡人身份的安全信息;
S220: 将所述安全信息和交易信息发送至发卡子系统;
S230:发卡子系统根据所述安全信息完成对持卡人的身份认证, 并根据认证结果进行扣款处理, 最后返回认证结果和扣款处理结果。
通过上述方法, 将认证过程和扣款过程合成一个支付流程, 不仅 提高了支付的处理速度, 而且也提高了网上资源的利用率。 由协作中 心提供的持卡人安全控制单元不同的发卡机构收集不同的信息,也可 以马 证证书。
以下在 VISA公司提供的网上支付系统的基础上进行改良, 以及 在现有由银联提供的银行系统进行改良为例,说明本发明的网上支付 流程。
请参阅图 7, 在现有的 VISA公司提供的网上支付系统改良后的 网上支付系统结构示意图。 它包括持卡人终端 31、 商户网站 32、 收 单子系统 33、路由服务器 34、发卡子系统 35和持卡人安全控制单元 36。 持卡人终端 31、 商户网站 32、 收单子系统 33、 路由服务器 34、 发卡子系统 35和持卡人安全控制单元 36可以是因特网的节点,通过 因特网建立数据通讯。 持卡人安全控制单元 36可以由 VISA等协作 机构开发的,用于建立与持卡人的交互莰得安全信息和建立与商户网 站 32或收单子系统 33的交互以及进行证书认证。
首先,持卡人终端 31向商户网站 32发起交易请求, 所述交易请 求中至少包含预购买的商品及对应的费用、 持卡人终端信息等; 然后, 商户网站 32将持卡人终端 31的 IP地址信息等发送至持 卡人安全控制单元 36;
随后, 持卡人安全控制单元 36建立与持卡人的交互, 获得安全 信息, 并进行证书认证;
随后, 持卡人安全控制单元 36可以将证书认证结果和安全信息 返回至商户网站, 考虑到安全因素, 可以返回至收单子系统 33; 随后,商户网站 32将安全信息和交易信息发送至路由服务器 34, 发送至对应的发卡子系统 35, 或者同样考虑安全因素, 商户网站 32 将交易信息发送至收单子系统 33 , 收单子系统 33将安全信息和交易 信息发送至路由服务器 34, 由路由服务器 34发送至对应的发卡子系 统 35;
最后, 发卡子系统 35进行认证和扣款处理, 并把结果返回, 以 便商户网站 32和持卡人终端 31获得认证结果和扣款处理结果。
在现有由银联提供的银行系统进行改良完成的网上安全支付系 统。 请参阅图 8, 其为由银联提供的银行系统进行改良完成的网上安 全支付系统的结构示意图。 它包括持卡人终端 41、 商户网站 42、 收 单子系统 43、跨行交换中心 44、发卡子系统 45及持卡人安全认证单 元 46。 持卡人安全控制单元 36可以由银联等协作机构开发的, 用于 建立与持卡人的交互获得安全信息和建立与商户网站 42或收单子系 统 43的交互以及进行证书认证。
首先,持卡人终端 41向商户网站 42发起交易请求, 所述交易请 求中至少包含预购买的商品及对应的费用、 持卡人终端信息等; 然后, 商户网站 42将持卡人终端 41的 IP地址信息等通过收单 子系统 43发送至持卡人安全控制单元 46;
持卡人安全控制单元 46建立与持卡人的交互, 获得安全信息, 将所述安全信息返回至收单子系统,收单子系统将所述安全信息和交 易信息发送至跨行交换中心,跨行交换中心将所述安全信息和交易信 息发达至对应的发卡子系统,发卡子系统进行相应的身份认证和扣款 处理, 并返回其认证结果和扣款处理结果。
为了达到更佳的认证效果,持卡人安全认证单元可以由上述公开 的网上安全认证子系统替代。所有发卡机构即可利用该网上安全认证 子系统得到持卡人输入的安全信息,大大提高了整个网上支付过程的 安全性。 并且, 在发卡机构端, 无需各自建立持卡人安全认证单元, 減少了大量的重复投资。
基于前述公开的网上安全支付系统,本发明还提供了一种网上安 全支付方法。请参阅图 9,其为本发明的网上安全支付方法的流程图。 该方法包括以下步骤:
S110: 持卡人终端向商户网站提交订单;
S120: 商户网站向收单子系统发起交易请求;
S130: 收单子系统与持卡人终端建立交互,获得持卡人输入的卡 号信息;
S 140: 收单子系统将卡号信息和交易信息发送至路由单元; S150:若所述卡号对应的发卡机构采用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
S160: 安全认证授权单元认证所述持卡人;
S170: 认证通过后, 发卡子系统进行扣款处理;
S180:发卡子系统将扣款处理结果和认证结果通过跨行交换中心 发送至收单子系统;
S190: 收单子系统的安全插件通知商户。
通过上述步骤, 提供了一种能够实现的网上支付模式。 并且, 对 于持卡人而言, 得到的不仅仅是认证身份是否成功的认证信息, 而是 交易是否成功的交易处理结果。 最重要的是, 本发明借助现有金融系 统的安全和快捷功能,使得本发明提供的网上支付模式同样具有安全 和快捷功能。
请参阅图 10, 其为本发明网上安全支付方法的一具体流程图。 它包括以下步驟: 1-持卡人终端通过互联网连接至商户网站, 持卡人选取商品, 并 确认订单提交;
2-商户网站将持卡人网页转向到安全插件, 同时给安全插件传输 订单信息和交易信息;
3-安全插件给持卡人显示页面, 让持卡人输入卡号, 持卡人点击 提交;
4-安全插件将卡号、 交易类型等信息发送给路由单元, 查询路由 信息;
5-路由单元根据持卡人所输卡号判断本次交易采用发卡机构直 接认证授权模式, 则产生交易的唯一标识 id (交易识别码), 将卡号、 交易类型、交易唯一标识 id等信息发往相应的安全认证授权单元, 安 全认证授权单元查询持卡人是否注册, 并返回结果;
6-路由单元将安全认证和授权单元返回的持卡人注册结果和交 易唯一标识 id传递给对应的安全插件; 如果返回的结果是持卡人未 注册, 那么流程结束;
7-安全插件通过持卡人的浏览器, 将持卡人的卡号、 订单、 商户 信息、 交易唯一标识 id等信息发送给安全认证授权单元, 让安全认 证授权单元认证持卡人;
8-安全认证授权单元收到相关信息;
9-安全认证授权单元与持卡人终端建立连接, 面向持卡人, 让持 卡人输入相关信息 , 认证持卡人;
10-安全认证授权单元将交易信息 (包括交易唯一标识 id )传递 给本单元对应的发卡子系统, 让发卡子系统进行扣款处理;
11-安全认证授权单元将认证结果、 交易结果通过因特网通知持 卡人;
12-发卡子系统将是否扣账等交易结果通过消费确认通知的形式 发送给跨行交换中心;
发卡子系统可以从 SAA获得足够的信息组成通知报文。 同时, 对于通知采用存储转发和重发机制, 在限定的次数内, 如果没有收到 通知的应答,发卡子系统必须重发通知。 重发通知的流水号和交易唯 一标识 id相同, 这在后续后详细介绍。
13 -跨行交换中心给出应答;
14-跨行交换中心将通知转送收单子系统;
15-收单子系统给出应答;
16-收单子系统收到交易结果后通知商户。
交易转接部分处理说明
发卡子系统发送网上交易结果通知至跨行交换中心,所述网上交 易结果中包含唯一交易标识码; 当发卡子系统在预设时间内未收到网 上交易结果的应答, 在限定次数内重新发出网上交易结果通知; 跨行交换中心接收到网上交易结果后, 返回应答消息, 并向对应 的收单子系统发送网上交易结果; 当跨行交换中心在预设时间内未收 到网上交易结果的应答,在限定次数内重新发出网上交易结果通知至 收单子系统。
比如 ··
发卡子系统发送网上交易结果通知给跨行交换中心时,报文中携 带由路由单元产生的交易唯一标识 id, 以便收单机构可以通过卡号 + 商户代码 +交易唯一标识 id来确定该笔交易,进而通知商户交易结果。
当发卡子系统在限定的时间内没有收到通知交易的应答时,在限 定的次数内, 可以重复发起网上交易结果通知交易, 但流水号 +交易 唯一标识 id不变。
跨行交换中心收到网上交易结果通知交易后,若识别交易为重复 通知交易, 则发送给发卡机构的应答中表明通知重复。 交换系统将网 上交易结果通知交易向收单机构转发, 若没有收到应答, 则在限定的 次数内, 不停重发, 直至收到应答为止。
网上交易结果通知交易在发起方采用存储转发机制,确保接收方 能够正确接收。 通过跨行交换中心的专有网络发起通知交易, 确保收 单机构能够准确、 及时地接收到交易结果, 有效减少单边账的情形。
网上交易结果通知交易虽然是从发卡机构发起, 由收单机构接 收, 但交易类似于消费交易, 存在撤销等后续交易。 后续交易的发起 方接收方和传统交易相同。
撤销等后续交易需匹配网上交易结果通知交易。
清算说明
跨行交换中心在预设周期内进行清算步驟:跨行交换中心将预设 时间周期内所有的网上交易结果通知汇总发送至对应的收单子系统; 收单子系统将未收到的网上交易结果通知发达至对应的商户网站。 跨行交换中心以网上交易结果通知交易为准进行清算。
若跨行交换中心成功接收网上交易结果通知, 而无法向收单机 构转发, 网上交易结果通知仍然参与清算。
由于网上交易结果通知交易采用存储转发机制, 可以重复发起, 但是仅清算一次。
若是收单机构没有收到网上交易结果通知交易, 曰终, 跨行交 换中心才艮据通知交易进行清算。跨行交换中心将当日所有的通知交易 汇总成文件发送给收单机构,让收单机构根据文件查找未收到通知的 交易, 补发通知给商户。
差错处理说明
网上交易结果通知交易由发卡机构发起, 经交换系统, 由收单 机构接收。 网上交易结果通知交易差错处理同现有的消费结果通知。 由于网上交易的特殊性, 在调单时, 单据可以是商户发货通知单, 或 是持卡人收货接收单。 收单机构有责任获取相关单据提供给发卡机 构, 以协助发卡机构确定商户是否发货。发卡机构针对网上交易结果 通知交易发起退单时, 退单原因可以是商户未发货, 但是不能是持卡 人认证等问题。
本发明提供了一种网上安全支付方法, 包括,发卡子系统进行持 卡人身份认证后, 根据认证结果进行扣款处理, 并将持卡人身份认证 结果和扣款处理结果通过收单子系统返回至商户网站。 比如: 采用 VISA公司提供的网上安全支付系统进行网上安全支 付时,其支付流程如下所示: 首先,持卡人登录商户网站,选取商品, 确认订单提交, 然后, 商户网站将持卡人信息发送至路由服务器, 随 后, 路由服务器根据卡号找到对应的发卡机构, 返回发卡机构子系统 的路由信息至商户网站; 随后, 商户网站将持卡人信息及扣款信息发 送至发卡子系统, 然后, 发卡子系统先认证持卡人的身份, 然后根据 认证的结果进行扣款处理,并将扣款处理结果和认证结果通过因特网 返回至持卡人终端和商户网站,以及通过路由服务器获得收单子系统 的路由信息, 将扣款处理结果和认证结果返回至收单子系统, 由收单 子系统通知商户。发卡子系统可以给每一次交易设置一交易码, 收单 子系统及商户网站可以根据交易码判断这一次返回的扣款处理结果 和认证结果是否已接收到。
采用现有的由跨行交换中心组成的支付系统时, 首先,持卡人登 录商户网站, 选取商品, 确认订单提交, 然后, 商户网站连接至收单 子系统, 通过路由单元获得发卡子系统的路由信息, 将所述持卡人信 息和交易信息发送至发卡子系统, 发卡子系统先建立与持卡人的交 互, 进行持卡人身份认证, 并根据认证结果进行扣款处理, 随后将持 卡人身份认证结果和扣款处理结果通过跨行交换中心发送至收单子 系统, 以便通知至商户。 路由单元可以给每一次交易设置一交易码, 收单子系统及商户网站可以根据交易码判断这一次返回的扣款处理 结果和认证结果是否已接收到。
本发明还提供了一种网上安全支付方法。 仍然参照图 9, 其也可 以为本实施例的网上安全支付方法的流程图。 该方法包括以下步驟:
S110: 持卡人终端向商户网站提交订单;
S120: 商户网站向收单子系统发起交易请求;
S130: 收单子系统与持卡人终端建立交互, 获得持卡人输入的卡 号信息;
S140: 收单子系统将卡号信息和交易信息发送至路由单元; S 150:若所述卡号对应的发卡机构采用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
S160: 安全认证授权单元认证所述持卡人;
S170: 认证通过后, 发卡子系统进行扣款处理;
S180: 当收单子系统在预设时间内未收到网上交易结果, 则向跨 行交换中心发送消费确定通知,所述网上交换结果是由安全认证授权 单元通过因特网回送至持卡人终端,再由持卡人终端送回至收单子系 统;
S 190:发卡子系统接收跨行交换中心的消费确定通知后查找对应 的数据库, 当查找到经过对应的扣款处理后, 返回承兌信息至收单子 系统, 以便通知商户。
通过上述步骤, 提供了一种能够实现的网上支付模式。 并且, 对 于持卡人而言, 得到的不仅仅是认证身份是否成功的认证信息, 而是 交易是否成功的交易处理结果。从数据交互过程来看, 一次网上交易 过程中, 可以通过访问一次发卡子系统完成支付过程,提高资源利用 率。 并且, 本发明还通过可以收单子系统通过跨行交换中心向发卡子 系统发出消费确定请求, 提高了支付过程的安全。
仍然可以参照图 10 ,可以为本实施例网上安全支付方法的一具体 流程图。 它包括以下步骤:
1-持卡人通过互联网浏览器登陆商户网站, 选取商品, 并确认订 单提交;
2-商户网站将持卡人网页转向到安全插件, 同时给安全插件传输 订单信息、 交易信息;
3-安全插件给持卡人显示页面, 让持卡人输入卡号, 持卡人点击 提交;
4-安全插件将卡号、 交易类型等信息发送给路由单元, 查询路由 信息; 5-路由单元根据持卡人所输卡号判断属于安全认证授权单元模 式, 则产生交易的唯一标识 id, 将卡号、 交易类型、 交易唯一标识 id 等信息发往相应的安全认证授权单元 , 安全认证授权单元查询持卡 人是否注册, 安全认证授权单元返回结果;
6-路由单元将安全认证授权单元返回结果和交易唯一标识 id传递 给安全插件; 如果返回的结果是持卡人未注册, 那么流程结束;
7-安全插件通过持卡人的浏览器, 将持卡人的卡号、 订单、 商户 信息、 交易唯一标识 id等信息发送给安全认证授权单元, 让安全认证 授权单元认证持卡人;
8-安全认证授权单元收到相关信息;
9-安全认证授权单元面向持卡人, 让持卡人输入相关信息, 并认 证持卡人;
10-安全认证授权单元将交易信息(包括交易唯一标识 id )传递给 发卡系统, 让发卡系统做相关账务处理;
11-安全认证授权单元将认证结果、 账务处理结果等信息通过持 卡人的浏览器传递给安全插件;
12-安全插件收到相关信息, 并且将收单系统所需信息传递给收 单系统;
如果安全插件超时没有收到安全认证授权单元发回的信息,仍将 相关信息传递给收单系统, 让收单系统能发起相应的确认交易。这是 为了确保在网络环境不稳定等因素下,安全认证授权单元已作相关处 理, 而无法巴结果及时地传递给安全插件时, 能够通过交换系统这个 渠道确认交易是否成功。
13-收单系统根据交易类型将相关信息按要求组包, 发起对应的 确认交易;
14-跨行交换系统将交易请求报文转送发卡系统;
15-发卡系统查找账户系统, 确认是否已做相关账务处理, 并决 定是否 7 兌, 将交易处理结果返回跨行交换系统;
16-跨行交换系统将交易处理结果返回收单系统; 17-收单系统收到交易结果后通知商户。
交易转接部分处理说明
收单子系统上送确认交易请求时,报文中携带由路由单元产生的 交易唯一标识 id, 发卡子系统可以通过卡号 +收单方代码 +商户代码 + 交易唯一标识 id来确定一笔交易, 用于在收到确认交易时定位一笔交 易, 已确认是否已做相关账务处理。
当收单子系统在限定的时间内没有收到确认交易请求的应答时 , 可以重复发起确认交易, 但必须在确认交易中表明为重复交易。
跨行交换中心收到确认请求后, 若识别交易为重复确认交易, 交 换系统首先查找原交易, 若原交易承兌, 则无须向发卡子系统转发直 接给收单子系统成功应答。 若原交易拒绝, 则无须向发卡子系统转发 直接给收单子系统拒绝应答。 若原交易没有应答, 则向发卡子系统转 发该笔重复确认交易。
发卡子系统收到重复确认交易时, 首先查找原交易, 如果没有查 找到原交易, 则视作新交易处理。 若是查找到原交易, 并且已作相关 处理, 则无须重复, 直接给出应答既可。
由于发卡机构在收到消费确认交易前可能已扣账,仅由收单机构 通过消费确认交易进行确认, 所以消费确认交易不能引发冲正。
消费确认交易类似于消费交易,存在撤销等后续交易。撤销等后 续交易需匹配消费确认交易。
清算部分说明
换行交换中心以消费确认交易为准进行清算。
若交换系统成功从发卡机构接收消费确认交易的应答,而无法向 收单机构转发, 消费确认交易仍然参与清算, 收单机构通过冲正进行 处理。
收单机构可以重复发起消费确认交易, 若交换系统收到多笔,仅 清算一笔。
曰终, 交换系统将当日所有的确认交易汇总成文件, 包括承兌清 算的、 未承兌的, 分别放送给收单机构和发卡机构。 发卡机构根据文 件查找账户系统, 如果已扣账未承兌, 则作相关处理, 减少错账的机 率。 收单机构根据文件查找, 如果某些确认交易未收到应答已承兌, 及时将结果通知商户。同时通过文件确认是否所有的网上交易已上送 消费确认交易, 如果某些交易未包含在文件中, 收单机构需要额外上 送网上交易文件, 通过交换系统转发给发卡机构, 让发卡机构作相关 账务处理, 进一步减少单边账的情形。
差错处理部分说明
消费确认交易差错处理同消费。
由于网上交易的特殊性,在调单时,单据可以是商户发货通知单, 或是持卡人收货接收单。收单机构有责任获取相关单据提供给发卡机 构, 以协助发卡机构确定商户是否发货。
发卡机构针对网上交易结果通知交易发起退单时,退单原因可以 是商户未发货, 但是不能是持卡人认证等问题。
撤销等后续交易的差错处理同消费的后续交易。
本申请人经研究发现, 对现有 VISA提供的网上支付进行改良, 提出了新的一种网上安全支付流程。参照图 11 ,该方法包括以下步骤:
S1210:发卡子系统进行持卡人身份认证后 , 根据认证结果进行扣 款处理,并将持卡人身份认证结果和扣款处理结果通过因特网返回持 卡人终端和商户网站;
S1220:当商户网站在预设时间内未收到所述持卡人身份认证结 果和扣款处理结果, 通过收单子系统向发卡子系统提出消费确认请 求;
S1230: 发卡子系统查找本子系统的数据库, 当查找到经过对应 的扣款处理后, 返回承兌信息至收单子系统, 以便通知商户网站。 具 体地说,发卡子系统收到确定交易后, 查找对应的账号是否做过对应 的扣款处理, 若是, 则给出承兌应答, 否则给出拒绝应答; 收单子系 统将结果通知至商户。
当收单子系统和发卡子系统可以通过路由服务器建立连接时,可 以通过路由服务器进行消费确认。 首先, 持卡人登录商户网站, 选取 商品, 确认订单提交, 然后, 商户网站将持卡人信息发送至路由服务 器, 随后, 路由服务器根据卡号找到对应的发卡机构, 返回发卡机构 子系统的路由信息至商户网站; 随后, 商户网站将持卡人信息及扣款 信息发送至发卡子系统, 然后, 发卡子系统先认证持卡人的身份, 然 后根据认证的结果进行扣款处理,并将扣款处理结果和认证结果通过 因特网返回至持卡人终端和商户网站。 当在预设时间内, 商户网站未 收到扣款处理结果和认证结果, 可以直接向发卡子系统发出查询请 求。考虑到支付的安全性以及商户网站和发卡子系统之间数据链路出 现故障的情况, 商户网站可以向收单子系统发出查询请求, 所述查询 请求中至少包括卡号、 交易识别码等信息。 收单子系统通过路由服务 器获得发卡子系统的路由信息, 建立与发卡子系统的交互: 发送消费 确认请求至发卡子系统以及发卡子系统返回承兌信息。
当然,收单子系统也可以通过现有的银联提供的跨行交换中心建 立发卡子系统与收单子系统的数据交互:发送消费确认请求至发卡子 系统以及发卡子系统返回承兌信息。由于银联的跨行交换中心是目前 较为成熟的技术, 因此, 完全可利用目前的跨行交换中心进行网上支 付及后续的网上确定。跨行交换中心在预设周期内按照确认交易进行 清算步骤:跨行交换中心将预设时间周期内所有未承兌的确认交易汇 总后发送至发卡子系统,由发卡子系统对所述所有未承兌的确认交易 进行比对检测。
以上公开的仅为本发明的一个具体实施例,但是本发明主要是提 供一种网上支付平台,使得目前釆用不同交易模式的银行在该平台上 进行交易处理,以此解决现有网上交易流程混乱以及资源浪费的技术 缺陷。 上述公开的三种交易模式仅是举例说明之用, 并不是用于限制 本发明。

Claims

权 利 要 求
1、 一种网上安全支付系统, 包括持卡人终端、 商户网站、 收单 子系统、发卡子系统, 其特征在于, 还包括与收单子系统和发卡子系 统连接的路由单元, 其中:
所述路由单元, 包括: 存储模块, 用以保存各发卡子系统所采用 的交易模式以及每一卡号 BIN对应的路由信息及处理流程; 处理模 块,用以根据从收单子系统接收的卡号确定对应发卡子系统采用的交 易模式, 按照相应处理流程进行处理。
2、 如权利要求 1所述的网上安全支付系统, 其特征在于, 还包 括安全插件, 与收单子系统相连, 或者设置在收单子系统内; 所述安 全插件用以建立商户网站、 持卡人终端、 路由单元的数据交互: 与持 卡人终端的交互, 获得持卡人的卡号信息, 与路由单元的交互, 获得 路由信息或对应的处理流程。
3、 如权利要求 1或 2所述的网上安全支付系统, 其特征在于, 还包括安全认证授权单元, 与发卡子系统相连, 或者设置在发卡子系 统内; 所述安全认证授权单元至少包含认证子单元和通知子单元, 认 证子单元用于对持卡人进行身份认证; 通知子单元: 将安全认证授权 单元对持卡人的身份认证结果和发卡子系统的扣款处理结果组成网 上交易结果通过因特网发送至持卡人终端。
4、 如权利要求 3所述的网上安全支付系统, 其特征在于, 所述 路由单元保存每个采用直接认证授权模式的发卡子系统对应的安全 认证授权单元的路由信息。
5、 如权利要求 1或 2所述的网上安全支付系统, 其特征在于, 还包括持卡人安全控制单元, 用于建立与持卡人终端的交互,接收持 卡人输入表征持卡人身份的安全信息。
6、 如权利要求 5所述的网上安全支付系统, 其特征在于, 所述 路由单元保存每个采用持卡人安全控制单元认证的发卡子系统对应 的持卡人安全控制单元的路由信息。
7、 如权利要求 6所述的网上安全支付系统, 其特征在于, 还包 括持卡人安全互动单元,所述持卡人安全互动单元连接持卡人安全控 制单元, 用于将认证信息经约定渠道发送至持卡人终端, 以及接收持 卡人输入的认证信息, 并对所述信息进行认证。
8、 如权利要求 7所述的网上安全支付系统, 其特征在于, 所述 持卡人安全控制单元、路由单元、持卡人安全互动单元可设置一服务 器上。
9、 如权利要求 2所述的网上安全支付系统, 其特征在于, 所述 安全插件包含以下单元:
验证商户单元: 用于对发起订单交易请求的商户进行身份认证; 交互控制单元: 用于控制与商户网站、 持卡人终端、 路由单元、 安全认证授权单元、 持卡人安全控制单元的数据交互;
数据存储单元: 用于存储包括商户信息的数据;
认证和传输单元:用于对接收到的数据包和发送的数据包进行安 全认证。
10、 一种路由服务器, 其特征在于, 包括以下部件:
存储单元:用于保存各发卡子系统所采用的交易模式以及每一卡 号 BIN对应的路由信息及处理流程;
直接认证授权模式处理单元: 当所述卡号对应的发卡子系统采用 直接认证授权模式,则返回所述卡号对应的安全认证授权单元的路由 息
持卡人安全控制单元认证模式处理单元: 当所述卡号对应的发卡 子系统采用持卡人安全控制单元认证模式,则返回所述持卡人安全控 制单元的路由信息;
收单子系统自行处理模式处理单元: 当所述卡号对应的发卡子系 统采用收单子系统自行处理模式 ,则将所述处理模式通知对应的收单 子系统。
11、 一种网上安全支付方法, 其特征在于, 包括:
收单子系统获取交易请求和持卡人卡号信息;
路由单元才艮据所述卡号确定对应发卡子系统采用的交易模式,按 照相应处理流程进行信息处理;
收单子系统或者发卡子系统完成交易结算, 返回结果信息。
12、 如权利要求 11所述的网上安全支付方法, 其特征在于: 如果所述卡号对应的发卡子系统采用收单子系统自行处理模式 , 则路由单元通知对应的收单子系统;
收单子系统完成交易结算, 返回结果信息。
13、 如权利要求 11所述的网上安全支付方法, 其特征在于: 如果所述卡号对应的发卡子系统采用持卡人安全控制单元认证 模式, 则路由单元返回所述持卡人安全控制单元的路由信息;
所述持卡人安全控制单元建立与持卡人终端的交互,接收持卡人 输入表征持卡人身份的安全信息;
发卡子系统认证后完成交易结算, 返回结果信息。
14、 如权利要求 11所述的网上安全支付方法, 其特征在于: 如果所述卡号对应的发卡子系统采用直接认证授权模式,则路由 单元返回所述卡号对应的安全认证授权单元的路由信息;
发卡子系统认证后完成交易结算, 返回结果信息。
15、 一种网上安全支付方法, 其特征在于, 所述方法包括:
( 1 ) 当商户网站接收到持卡人的订单信息时, 建立持卡人与安 全插件的交互,所述安全插件接收持卡人输入的需要支付交易额的卡 号;
( 2 )安全插件将卡号、 订单信息转发至路由单元; 路由单元根 据持卡人输入的卡号,判断是否是采用持卡人安全控制单元进行认证 的认证方式, 若是, 将对应的持卡人安全控制单元的路由信息发送至 安全插件;安全插件将所述卡号及持卡人信息发送至持卡人安全控制 单元;
( 3 )持卡安全控制单元与持卡人建立交互, 接收持卡人输入表 征持卡人身份的安全信息, 并将所述安全信息发送至安全插件;
( 4 )安全插件将所述安全信息及订单信息组入交易请求报文, 通过跨行交换中心或者根据路由单元提供的路由信息发送至对应的 发卡子系统;
( 5 )发卡子系统对其进行身份认证和授权扣款处理后, 返回处 理结果。
16、 如权利要求 15所述的网上安全支付方法, 其特征在于, 通 过以下步骤完成持卡安全控制单元与持卡人的交互:
bl: 持卡人安全控制单元将卡号发送至持卡人安全互动单元,持 卡人安全互动单元向持卡人安全控制单元返回界面输入要求;
b2: 持卡人安全互动单元经约定渠道将认证信息发送至持卡人; b3: 持卡人安全控制单元接收输入信息, 并将所述输入信息发送 至持卡人安全互动单元;
b4: 持卡人安全互动单元认证所述输入信息, 并将认证后的信息 发送至持卡人安全控制单元。
17、如权利要求 15或者 16所述的网上安全支付方法, 其特征在 于, 还包括:
安全插件引导持卡人建立与持卡人安全控制单元认证的 SSL安 全通道, 检验持卡人证书的有效性并建立提供安全传输数据的通道; 证书有效性被认可后,持卡人安全控制单元通过持卡人终端的浏 览器显示需要持卡人输入信息, 并通过 SSL服务器模块获得证书的 DN和持卡人输入的卡号, 验证该证书和卡号是否是有效绑定, 若是 有效, 则将持卡人输入的信息发送至安全插件, 否则将验证无效结果 传送至安全插件。
18、一种网上安全支付方法,其特征在于,该方法包括以下步骤:
(1)持卡人终端向商户网站提交订单;
(2)商户网站向收单子系统发起交易请求;
(3)收单子系统与持卡人终端建立交互, 获得持卡人输入的卡号 信息;
(4)收单子系统将卡号信息和交易信息发送至路由单元; 式,则路由单元将所述卡号信息及 易信息发送至发卡机构对应的安 全认证授权单元;
(6)安全认证授权单元认证所述持卡人;
(7)认证通过后, 发卡子系统进行扣款处理;
(8)发卡子系统将扣款处理结果和认证结果发送至收单子系统;
(9)收单子系统通知商户。
19、 如权利要求 18所述的网上安全支付方法, 其特征在于, 步 骤(5 )和步骤(6 )之间还包括:
安全认证授权单元判断所述持卡人是否已注册,并将注册结果返 回至路由单元;
路由单元给本次支付分配一交易标识码,并将注册结果和标识码 分配至收单子系统;
若注册结果为持卡人已注册, 则收单子系统将卡号信息、订单信 息和业务标识码发送至安全认证授权单元, 请求认证持卡人。
20、 如权利要求 19所述的网上安全支付方法, 其特征在于, 通 过以下步驟将交易结果信息发送至收单子系统:
发卡子系统发送网上交易结果通知至跨行交换中心,所述网上交 易结果中包含唯一交易标识码;
当发卡子系统在预设时间内未收到网上交易结果的应答,在限定 次数内重新发出网上交易结果通知;
跨行交换中心接收到网上交易结果后,返回应答消息, 并向对应 的收单子系统发送网上交易结果;
当跨行交换中心在预设时间内未收到网上交易结果的应答,在限 定次数内重新发出网上交易结果通知至收单子系统。
21、如权利要求 18或 20所述的网上安全支付方法,其特征在于, 还包括:
跨行交换中心在预设周期内按照交易标识码进行清算步骤:跨行 交换中心将预设时间周期内所有的网上交易结果通知汇总后发送至 对应的收单子系统;
收单子系统将未收到的网上交易结果通知发送至对应的商户网 站。
22、 如权利要求 18所述的网上安全支付方法, 其特征在于, 通 过以下步骤将交易结果信息发送至收单子系统:
发卡子系统将认证结果和扣款处理结果组成网上交易结果通过 因特网发送至持卡人终端, 网上交易结果还包括交易标识码; 持卡人 终端通过因特网将所述网上交易结果发送至收单子系统。
23、一种网上安全支付方法,其特征在于,该方法包括以下步骤:
(1) 持卡人终端向商户网站提交订单;
(2)商户网站向收单子系统发起交易请求;
(3)收单子系统与持卡人终端建立交互, 获得持卡人输入的卡号 信息;
(4)收单子系统将卡号信息和交易信息发送至路由单元;
(5)若所述卡号对应的发卡机构釆用发卡机构直接认证授权模 式,则路由单元将所述卡号信息及交易信息发送至发卡机构对应的安 全认证授权单元;
(6)安全认证授权单元认证所述持卡人;
(7)认证通过后, 发卡子系统进行扣款处理, 并返回交易结果;
(8) 当收单子系统在预设时间内未收到网上交易结果,则通过跨 行交换中心或者路由单元向发卡子系统发送消费确定请求;
(9) 发卡子系统接收到消费确定请求后查找对应的数据库,当查 找到经过对应的扣款处理后, 返回承兌信息至收单子系统。
24、 如权利要求 23所述的网上安全支付方法, 其特征在于, 还 包括:跨行交换中心将预设时间周期内所有未承兌的确认交易汇总后 发送至发卡子系统,由发卡子系统对所述所有未承兌的确认交易进行 比对检测。
PCT/CN2006/001739 2005-07-18 2006-07-18 Procede et systeme de paiement securise dans un reseau et un serveur d'acheminement WO2007009373A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP06761474A EP1906583A4 (en) 2005-07-18 2006-07-18 SECURE PAYMENT PROCESS AND SYSTEM ON A NETWORK AND ROUTE SERVER
US11/994,365 US20080228655A1 (en) 2005-07-18 2006-07-18 Secure Payment Method and System on Network and Route Server

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNA2005100278978A CN1900963A (zh) 2005-07-18 2005-07-18 网上安全支付系统
CN200510027897.8 2005-07-18

Publications (1)

Publication Number Publication Date
WO2007009373A1 true WO2007009373A1 (fr) 2007-01-25

Family

ID=37656843

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2006/001739 WO2007009373A1 (fr) 2005-07-18 2006-07-18 Procede et systeme de paiement securise dans un reseau et un serveur d'acheminement

Country Status (4)

Country Link
US (1) US20080228655A1 (zh)
EP (1) EP1906583A4 (zh)
CN (1) CN1900963A (zh)
WO (1) WO2007009373A1 (zh)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8249950B2 (en) 2008-07-11 2012-08-21 Ebay Inc. Payment mechanism integration wizard
CN101414404B (zh) * 2008-11-28 2011-04-13 中国民生银行股份有限公司 公共业务实现方法、银行前置设备和银行前置系统
CN102780686A (zh) * 2011-05-13 2012-11-14 中国银联股份有限公司 一种基于可信资源保护银行用户信息的方法和装置
CN102855560B (zh) * 2011-06-29 2018-07-17 国民技术股份有限公司 一种移动支付方法及系统
CN102880962A (zh) * 2011-07-11 2013-01-16 陈佩滢 个人化弹性认证授权的开放式付款服务平台
CN102880982A (zh) * 2012-09-03 2013-01-16 常州嘴馋了信息科技有限公司 网络安全购物系统
CN103679466A (zh) * 2012-09-04 2014-03-26 蒋树雄 一种指纹消费终端联合分销系统
CN103714456B (zh) * 2014-01-06 2015-08-19 同济大学 软件行为监控验证系统
CN103927659A (zh) * 2014-04-18 2014-07-16 刘志望 一种虚拟货币的即时转移和安全支付方法
EP3660767A1 (en) * 2018-11-28 2020-06-03 Mastercard International Incorporated Improvements relating to security and authentication of interaction data

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1635525A (zh) * 2003-12-31 2005-07-06 中国银联股份有限公司 一种安全的网上支付系统及安全的网上支付认证方法

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6105008A (en) * 1997-10-16 2000-08-15 Visa International Service Association Internet loading system using smart card
US8086539B2 (en) * 2002-06-11 2011-12-27 The Western Union Company Value processing network and methods
US6993653B1 (en) * 2000-02-22 2006-01-31 International Business Machines Corporation Identity vectoring via chained mapping records
US7155415B2 (en) * 2000-04-07 2006-12-26 Movielink Llc Secure digital content licensing system and method
US7499889B2 (en) * 2000-10-23 2009-03-03 Cyota Inc. Transaction system
US20020087469A1 (en) * 2000-12-28 2002-07-04 Ravi Ganesan Technique of registration for and direction of electronic payments in real-time
WO2002054652A2 (en) * 2001-01-05 2002-07-11 Yozons, Inc. System and method for processing digital documents utilizing secure communications over a network
JP2002366859A (ja) * 2001-06-11 2002-12-20 Sony Corp 与信仲介システム、与信仲介装置および方法、記録媒体、並びにプログラム
US6805289B2 (en) * 2002-05-23 2004-10-19 Eduardo Noriega Prepaid card payment system and method for electronic commerce
US7069244B2 (en) * 2002-09-17 2006-06-27 First Data Corporation Method and system for merchant processing of purchase card transactions with expanded card type acceptance

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1635525A (zh) * 2003-12-31 2005-07-06 中国银联股份有限公司 一种安全的网上支付系统及安全的网上支付认证方法

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
LI X. ET AL.: "A research for the payment authentication system based on 3D secure protocol", CHINA FINANCIAL COMPUTER, no. 11, 2004, pages 55 - 57 *
YANG Z. ET AL.: "A payment on network based on the SET protocol", COMPUTER AND INFORMATION TECHNOLOGY, no. 6, 2000, pages 4 - 8 *

Also Published As

Publication number Publication date
CN1900963A (zh) 2007-01-24
US20080228655A1 (en) 2008-09-18
EP1906583A4 (en) 2012-01-25
EP1906583A1 (en) 2008-04-02

Similar Documents

Publication Publication Date Title
US11398910B2 (en) Token provisioning utilizing a secure authentication system
WO2007009373A1 (fr) Procede et systeme de paiement securise dans un reseau et un serveur d'acheminement
US20210209583A1 (en) Single Sign-On Using A Secure Authentication System
US7111789B2 (en) Enhancements to multi-party authentication and other protocols
US8245044B2 (en) Payment transaction processing using out of band authentication
US7280981B2 (en) Method and system for facilitating payment transactions using access devices
RU2292589C2 (ru) Аутентифицированный платеж
US8229855B2 (en) Method and system for facilitating payment transactions using access devices
RU2438172C2 (ru) Способ и система для осуществления двухфакторной аутентификации при транзакциях, связанных с заказами по почте и телефону
US8571975B1 (en) System and method for sending money via E-mail over the internet
US6327578B1 (en) Four-party credit/debit payment protocol
US20020178122A1 (en) System and method for confirming electronic transactions
US20090292642A1 (en) Method and system for automatically issuing digital merchant based online payment card
US20060173776A1 (en) A Method of Authentication
TW201023067A (en) Payment method, system and payment platform capable of improving payment safety by virtual card
AU2010256666A1 (en) System and method for providing authentication for card not present transactions using mobile device
TW200929031A (en) On-line payment system and payment procedure
US11263638B2 (en) Scheme for frictionless cardholder authentication
EP1234223A2 (en) System and method for secure electronic transactions
CA2947281C (en) Method and system for authentication token generation
TW538357B (en) Authorization method and system for electronic commerce financial transaction

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 11994365

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2006761474

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

WWW Wipo information: withdrawn in national office

Country of ref document: DE

WWP Wipo information: published in national office

Ref document number: 2006761474

Country of ref document: EP