WO2007107093A1 - Systeme et procede de confirmation de transaction de commerce electronique - Google Patents

Systeme et procede de confirmation de transaction de commerce electronique Download PDF

Info

Publication number
WO2007107093A1
WO2007107093A1 PCT/CN2007/000856 CN2007000856W WO2007107093A1 WO 2007107093 A1 WO2007107093 A1 WO 2007107093A1 CN 2007000856 W CN2007000856 W CN 2007000856W WO 2007107093 A1 WO2007107093 A1 WO 2007107093A1
Authority
WO
WIPO (PCT)
Prior art keywords
confirmation
electronic service
terminal
center
electronic
Prior art date
Application number
PCT/CN2007/000856
Other languages
English (en)
French (fr)
Inventor
Shiyong Wang
Yuhua Zheng
Original Assignee
Shiyong Wang
Yuhua Zheng
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shiyong Wang, Yuhua Zheng filed Critical Shiyong Wang
Publication of WO2007107093A1 publication Critical patent/WO2007107093A1/zh
Priority to US12/233,746 priority Critical patent/US20090012890A1/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/12Payment architectures specially adapted for electronic shopping systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/325Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
    • G06Q20/3255Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks using mobile network messaging services for payment, e.g. SMS
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/326Payment applications installed on the mobile devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/42Confirmation, e.g. check or permission by the legal debtor of payment
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes

Definitions

  • the present invention relates to the field of electronic service technologies, and more particularly to an electronic service confirmation system and an implementation method thereof. Background of the invention
  • Electronic business Due to the advantages of convenience, low cost, and geographical location, the electronic business is developing rapidly around the world. Electronic business usually includes various forms of expression such as e-commerce, mobile commerce, and e-government. Although the current electronic business is developing very fast, it may cause a series of security problems because the electronic business occurs automatically without the presence of people or without the participation of others. For example: When conducting online electronic services such as online transactions and online payment, the user's physical signature cannot be obtained, but the user's identity can only be verified based on the user name and password. It is difficult for banks and merchants to guarantee the online transaction and payment. Identity legitimacy, which provides a hotbed of bullying, and brings huge economic losses to banks, credit card companies, businesses and cardholders.
  • the service generation system when some important data, such as the amount in the bank account, changes, the service generation system sends a short message to the relevant person's mobile phone through the mobile phone gateway to notify, if the notified person perceives If there is a problem, then perform a telephone inquiry and other corresponding processing.
  • this method since only short messages are displayed in the mobile phone, the short messages are not further processed, so this method cannot control the occurrence of the service, and at most, the business can be known after the occurrence of the service, so this The prior art cannot monitor electronic services, so the security of electronic services cannot be guaranteed. Summary of the invention
  • the main object of the present invention is to provide an electronic service confirmation system capable of monitoring the occurrence of electronic services, thereby improving the security of electronic services.
  • Another object of the present invention is to provide an electronic service confirmation method capable of monitoring the occurrence of an electronic service, thereby improving the security of the electronic service.
  • Another object of the present invention is to provide an electronic service confirmation center that can be used to monitor the occurrence of electronic services, thereby improving the security of electronic services.
  • Another object of the present invention is to provide a confirmation terminal, which can monitor the occurrence of electronic services by using the confirmation terminal, thereby improving the security of the electronic service.
  • An electronic service confirmation system comprising:
  • An electronic service application system configured to send an electronic service confirmation request to the confirmation center when performing the electronic service, and operate the electronic service according to the confirmation result of the electronic service returned by the confirmation center;
  • a confirmation center configured to determine a corresponding confirmation terminal according to the electronic service confirmation request, send an electronic service confirmation message to the confirmation terminal, and confirm the electronic service returned by the terminal The result is sent to the electronic business application system;
  • the confirmation terminal is configured to receive an electronic service confirmation message, generate an electronic service confirmation result according to the feedback of the user, and send the electronic service confirmation result to the confirmation center.
  • the confirmation center sends the electronic service confirmation message to the confirmation terminal in a short message (SMS) protocol, or a Socket protocol, or a Datagram protocol.
  • SMS short message
  • Socket Socket protocol
  • Datagram Datagram protocol
  • the confirmation terminal is a mobile phone, a PDA, a PC, a laptop computer.
  • the electronic business application system is a bank account monitoring system, a telephone banking transaction system, a network 4 transaction system, an e-commerce transaction system, a mobile asset monitoring system, and a network password protection system.
  • the confirmation center includes:
  • a web server configured to receive the electronic service confirmation request, and the control application server searches for a corresponding confirmation terminal in the database, confirms that the communication mode registered by the terminal sends an electronic service confirmation message to the confirmation terminal, and confirms the location sent by the terminal.
  • the confirmation result of the electronic service is sent to the electronic business application system;
  • An application server configured to query an ID of the confirmation terminal in the database according to a command of the web server, and a communication manner;
  • a database configured to store an ID of the confirmation terminal and the electronic service confirmation message and the electronic service confirmation result.
  • the database is further for storing personal information of the user; the web server is further for accepting user registration via an internet web connection with the confirmation terminal, and/or querying and/or modifying the user's personal information according to the request of the web server.
  • the confirmation center includes:
  • a Socket server configured to receive the electronic service confirmation request, and the control application server searches for a corresponding confirmation terminal in the database, confirms that the communication mode registered by the terminal sends an electronic service confirmation message to the confirmation terminal, and confirms the location sent by the terminal.
  • Electronic business confirmation The result is sent to the electronic business application system;
  • An application server configured to query an ID of the confirmation terminal in the database according to a command of the Socket server;
  • a database configured to store an ID of the confirmation terminal and the electronic service confirmation message and the electronic service confirmation result.
  • the communication method for confirming the registration of the terminal is: communicating with the confirmation center by using the SMS protocol, or the Socket protocol, or the Datagram protocol.
  • the database is further configured to store personal information of the user;
  • the Socket server is further configured to accept user registration via an Internet Socket connection with the confirmation terminal, and/or to query and/or modify the user's personal information according to the request of the Socket server.
  • the confirmation terminal includes an electronic service confirmation module, and the electronic service confirmation module is configured to generate an electronic service confirmation result according to the electronic service confirmation message and user feedback.
  • An electronic service confirmation center receives an electronic service confirmation request sent by the electronic service application system, and searches for a corresponding confirmation terminal according to the electronic service confirmation request, to confirm that the communication mode registered by the terminal is sent to the confirmation terminal.
  • the electronic service confirms the message, and sends an electronic service confirmation result returned by the confirmation terminal to the electronic service application system, and the confirmation center includes:
  • an information transmission server configured to receive the electronic service confirmation request, and the control application server searches for a corresponding confirmation terminal in the database, and confirms that the communication mode registered by the terminal sends an electronic service confirmation message to the confirmation terminal, and confirms that the terminal sends the Sending the electronic service confirmation result to the electronic service application system;
  • An application server configured to query an ID of the confirmation terminal and a communication mode in the database according to a command of the information transmission server;
  • the communication method for confirming the registration of the terminal is: communicating with the confirmation center by using an SMS protocol, or a Socket protocol, or a Datagram protocol.
  • the information transmission server is a web server or a Socket server.
  • a mobile terminal configured to receive an electronic service confirmation message from an electronic service confirmation center, and generate an electronic service confirmation result according to the user feedback, and send the electronic service confirmation result to an electronic service confirmation center, where the mobile terminal includes a communication module for transmitting and receiving electronic service confirmation information and an electronic service confirmation module,
  • a communication module configured to receive an electronic service confirmation message, and send the electronic service confirmation result generated by the electronic service confirmation module to the electronic service confirmation center;
  • the electronic service confirmation module is configured to generate an electronic service confirmation result according to the electronic service confirmation message and the user feedback.
  • the communication module transmits the electronic service confirmation result to an electronic service confirmation center in an SMS, or Hypertext Transfer Protocol (HTTP) manner.
  • SMS Short, or Hypertext Transfer Protocol (HTTP) manner.
  • HTTP Hypertext Transfer Protocol
  • the mobile terminal is a mobile phone, a PDA.
  • the electronic service confirmation module is disposed in the mobile terminal in a PUSH manner, or is disposed in the mobile terminal in an OTA manner.
  • An electronic service confirmation method comprising:
  • the electronic service application system sends an electronic service confirmation request to the confirmation center when performing the electronic service
  • the confirmation center locates the confirmation terminal corresponding to the confirmation request by the electronic service confirmation request, and sends an electronic service confirmation message to the confirmation terminal;
  • the confirmation center will confirm the electronic service confirmation result returned by the terminal to the electronic service application system, and the electronic service application system will perform the electronic service according to the confirmation result of the electronic service. Operation.
  • the method includes: setting an electronic service confirmation trigger condition in the electronic service application system in advance, stepping in: when the electronic service application system performs the electronic service, when the electronic service confirmation trigger condition is met, sending the electronic to the confirmation center Business confirmation request.
  • the confirmation center sends an electronic service confirmation message to the confirmation terminal as:
  • the confirmation center sends the encrypted electronic service confirmation message to the confirmation terminal.
  • the confirmation center transmits an electronic service confirmation message to the confirmation terminal as follows:
  • the confirmation center transmits an electronic service confirmation message to the confirmation terminal by confirming the communication mode of the terminal registration.
  • the operation of the electronic service application system to the electronic service includes: the electronic service application system determines whether to permit execution of the electronic service according to the electronic service confirmation result, and if yes, executes, otherwise the electronic service is not executed.
  • the electronic service confirmation system includes an electronic service application system, a confirmation center, and a confirmation terminal.
  • the confirmation terminal generates an electronic service confirmation result according to the feedback of the user, and sends the electronic service confirmation result to the confirmation center; the confirmation center sends the electronic service confirmation result to the electronic service application system; and then the electronic service application system lives in the electronic service confirmation result.
  • the implementation of the electronic business is handled. Therefore, after the application of the present invention, the electronic service application system, the confirmation center, and the confirmation terminal can perform the monitoring of the occurrence of the electronic service in a timely manner, instead of simply performing the simple notification after the completion of the electronic service, so the present invention is extremely The earth has improved the security of the electronic business.
  • FIG. 1 is a schematic diagram showing an exemplary structure of an electronic service confirmation system according to the present invention.
  • Fig. 2 is a schematic view showing an exemplary structure of a confirmation center according to an embodiment of the present invention.
  • FIG. 3 is a schematic diagram showing an exemplary structure of an electronic service confirmation system according to an embodiment of the present invention.
  • 4 is a schematic flow chart of an electronic service confirmation method in accordance with the present invention.
  • FIG. 5 is a schematic diagram of an electronic service confirmation service according to an embodiment of the present invention.
  • FIG. 6 is a schematic flow chart of a method for a user to register an electronic service confirmation notification according to an embodiment of the present invention.
  • FIG. 2 is a schematic flowchart of a method for a user to test an electronic service confirmation notification according to an embodiment of the present invention.
  • FIG. 8 is a schematic flowchart of a method for a user to bind an electronic service confirmation notification according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a user UCD according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of a confirmation center UCD according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of an electronic service application system UCD according to an embodiment of the present invention. Mode for carrying out the invention
  • FIG. 1 is a schematic block diagram showing an electronic service confirmation system according to an embodiment of the present invention. As shown in FIG. 1, the electronic service confirmation system includes:
  • the electronic service application system 101 is configured to send an electronic service confirmation request to the confirmation center 102 when performing the electronic service, and operate the electronic service according to the electronic service confirmation result returned by the confirmation center 102;
  • the confirmation center 102 is configured to determine the corresponding confirmation terminal 103 according to the electronic service confirmation request, send an electronic service confirmation message to the confirmation terminal 103, and send the electronic service confirmation result returned by the confirmation terminal 103 to the electronic service application system 101;
  • the confirmation terminal 103 is configured to receive an electronic service confirmation message, generate an electronic service confirmation result according to the feedback of the user, and send the electronic service confirmation result to the confirmation center 10 2 .
  • the confirmation center 102 can send an electronic service confirmation message to the confirmation terminal through a protocol such as an SMS protocol, a Socket protocol, or a Datagram.
  • the electronic service confirmation result returned by the confirmation terminal 103 can be transmitted to the electronic service application system 101 by means of SMS, or Hypertext Transfer Protocol (HTTP).
  • HTTP Hypertext Transfer Protocol
  • the confirmation center 102 sends an electronic service confirmation message to the confirmation terminal, and confirms that the terminal 103 applies to the electronic service.
  • the manner in which the system 101 transmits the electronic service confirmation result is not limited.
  • the confirmation terminal 103 can first register the corresponding communication mode at the confirmation center 102, and then implement mutual communication according to the communication mode.
  • the electronic service application system 101 can be any electronic business operation system or an electronic business operation system, and specifically can be: a bank account monitoring system, a telephone banking transaction system, a network 4 transaction system, an e-commerce transaction system, and a mobile asset monitoring system.
  • System network password protection system, etc.
  • the network password protection system can be various forms of email systems, network game systems, and the like. Therefore, after the application of the present invention, it is possible to provide further protection for e-mail, network games, etc., to prevent illegal login.
  • the confirmation terminal 103 can be a communication function entity such as a mobile phone, a personal digital assistant (PDA), a personal computer (PC), a laptop computer or the like.
  • a communication function entity such as a mobile phone, a personal digital assistant (PDA), a personal computer (PC), a laptop computer or the like.
  • the confirmation terminal 103 includes a communication module having the electronic service confirmation information, and an electronic service confirmation module, and the electronic service confirmation module is configured to generate an electronic service confirmation result according to the electronic service confirmation message and the user feedback.
  • the electronic service confirmation module may be a JAVA program running on the confirmation terminal 103.
  • the JAVA program MID1 et
  • the JAVA program can be downloaded and automatically installed on the confirmation terminal 102 by remote setting such as OTA (Over-The-Ai r). It is confirmed that the JAVA program of the terminal 102 does not need to be started normally.
  • the confirmation center 102 activates it by means of Push Regi s try.
  • Push Regi s try is a new addition to MIDlet 2.
  • Is one that can make MIDl et A new mechanism that can be activated by a server-side connection or timer. This technology enables the MIDl et run on the mobile terminal to be automatically started from the server side when an event occurs without user intervention.
  • the JAVA program on the terminal 103 registers with the AMS (Appl i Management Management Sof tware) on the terminal 103, and can be activated by the connection of the SMS communication protocol on the 6000 port. (sms: ⁇ : 6000).
  • the confirmation center 102 Upon receiving the confirmation request from the electronic service application system 101, the confirmation center 102 sends a short message to the 6000 port on the corresponding confirmation terminal 103.
  • the JAVA program is activated by a short message on the 6000 port, it starts to start, receives and processes the short message.
  • JAVA language is taken as an example to explain how to implement the function of the confirmation terminal, those skilled in the art can realize that the present invention is not limited to the JAVA language, but can be applied to various object-oriented objects.
  • Programming language For example, C language, C++ language, PASCAL language, etc.
  • the validation center 102 is the core of the overall system and is used to provide validation services for the electronic business application system 101.
  • the confirmation center 102 receives the confirmation request from the electronic service application system 101, the confirmation center 102 sends a confirmation request to the corresponding confirmation terminal 103.
  • the confirmation center 102 receives the confirmation result from the confirmation terminal 103, the "fc confirmation result notification is corresponding.
  • Electronic Business Application System 101 The validation center 102 is the core of the overall system and is used to provide validation services for the electronic business application system 101.
  • the confirmation center includes:
  • the web server 201 is configured to receive the electronic service confirmation request, and the control application server 202 searches the database 203 for the corresponding confirmation terminal to confirm that the communication mode registered by the terminal sends an electronic service confirmation message to the confirmation terminal, and confirms the terminal. Sending the electronic service confirmation result sent to the electronic service application system;
  • the application server 202 is configured to query the database 203 according to the command of the web server. Confirm the ID of the terminal and the communication method;
  • the database 203 is configured to store an ID of the confirmation terminal, and the electronic service confirmation message and the electronic service confirmation result.
  • the web server 201 can also accept the user registration confirmation service via the Internet web connection with the confirmation terminal, and/or query and/or modify the user's personal information in the database 203 according to the request of the web server.
  • the user can download the JAVA program from the Web server 201 to the confirmation terminal.
  • the web server 201 stores the notification request from the electronic business application system 101 and the confirmation result from the confirmation terminal 103 to the database 203 via the application server 202.
  • the Socket server accepts the user registration via the Internet Socke t connection with the confirmation terminal 103, and/or queries and/or modifies the user's personal information according to the request of the Socke t server.
  • the application server 202 processes requests from the web server, such as querying/modifying the user's personal information, storing the notification request from the electronic business application system, and confirming the result from the confirmation terminal.
  • the database 203 stores various information in the entire system, such as personal information of the user, a notification request from the electronic service application system 101, and a confirmation result from the confirmation terminal 103.
  • a server that supports both the Web and the Socket can be used as the external interface of the confirmation center as long as it supports information transmission based on the Internet and mobile communication.
  • the normal confirmation center includes: an information transmission server, configured to receive an electronic service confirmation request, and the control application server searches for a corresponding confirmation terminal in the database to confirm that the communication mode registered by the terminal sends an electronic service confirmation message to the confirmation terminal. And transmitting the confirmation result of the electronic service sent by the terminal to the electronic service application system; the application service And a method for querying the ID and communication mode of the confirmation terminal in the database according to the command of the information transmission server; the database is configured to store the ID of the confirmation terminal and the electronic service confirmation message and the electronic service confirmation result.
  • FIG. 3 is a schematic diagram showing an exemplary structure of an electronic service confirmation system according to an embodiment of the present invention.
  • the mobile terminal can register the electronic service confirmation service in the WEB server of the confirmation center according to the browser it contains. After registering the electronic service confirmation service, the mobile terminal can monitor the occurrence of the electronic service.
  • FIG. 4 is a schematic flow chart of an electronic service confirmation method according to the present invention. As shown in Figure 4, the method includes:
  • Step 401 The electronic service application system sends an electronic service confirmation request to the confirmation center when performing the electronic service;
  • Step 402 The confirmation center determines the confirmation terminal corresponding to the confirmation request according to the electronic service confirmation request, and sends an electronic service confirmation message to the confirmation terminal.
  • Step 403 Confirm that the terminal prompts the electronic service confirmation message to the user, generates an electronic service confirmation result according to the feedback of the user, and sends the electronic service confirmation result to the confirmation center.
  • the electronic business application system the electronic business application system operates on the electronic business based on the electronic business confirmation result.
  • the electronic service confirmation trigger condition may be set in advance in the electronic service application system, and then the electronic service application system executes the electronic service, and only sends the electronic service to the confirmation center when the electronic service confirmation trigger condition is met.
  • the confirmation request does not perform the confirmation request operation when the electronic service confirmation trigger condition is not satisfied.
  • the electronic service confirmation message sent by the confirmation center to the confirmation terminal is preferably encrypted, and the confirmation center preferably transmits the electronic service confirmation message to the confirmation terminal in the form of a short message.
  • the electronic service application system determines whether the electronic service confirmation result is It is permitted to perform electronic business, and if so, it is executed, otherwise electronic business is not executed.
  • FIG. 5 is a schematic flow chart of a method for a user to register an electronic service confirmation notification according to an embodiment of the present invention. It is assumed here that the electronic service is a one-time transfer in the online mode.
  • the electronic business application system is used for a transaction.
  • the electronic business application system determines whether the transaction needs to notify the user to confirm according to the conditions set by the user in advance, and if the transaction does not need to notify the user, the existing method is completed;
  • the transaction requires confirmation by the user, the electronic service application system generates notification information, and sends a confirmation request to the confirmation center.
  • the confirmation center first suspends the confirmation request to the database, and then finds the corresponding confirmation terminal according to the ID in the confirmation request. (The ID in the confirmation request and the confirmation terminal can be bound in the database at the time of registration), and then the confirmation information is sent to the corresponding confirmation terminal in the form of a short message.
  • the confirmation request information is displayed, and the user's confirmation is awaited, and then the confirmation result information is generated according to the confirmation result of the user, and the confirmation result information is sent to the confirmation. center.
  • the confirmation center updates the corresponding confirmation request record in the database, and sends the confirmation result to the electronic business application system, and then the electronic business application system completes or rejects the transaction made by the user according to the confirmation result.
  • FIG. 6 is a schematic flow chart of a method for a user to register an electronic service confirmation notification according to an embodiment of the invention.
  • the user can log in to the website of the confirmation center through the browser, select a valid ID, set a password, provide personal information such as a mobile terminal number, and then submit the registration.
  • the confirmation center sends the information for downloading the JAVA program to the corresponding mobile terminal. If the JAVA program is not available on the user's mobile terminal, the JAVA program is automatically downloaded and automatically installed on the mobile terminal according to the prompt of the download information. If the JAVA program is already installed on the user's mobile terminal, registration is completed.
  • FIG. 7 is a schematic flow chart of a method for a user to test an electronic service confirmation notification according to an embodiment of the present invention.
  • the user logs in to the website of the confirmation center through the browser, generates test JAVA program information, and then confirms that the center sends the test JAVA program information to the user's mobile terminal, and the user confirms the test JAVA program information, and then The user can check the confirmation result from the confirmation center's website through the browser to see if the test is successful.
  • FIG. 8 is a schematic flowchart of a method for binding a user's electronic service confirmation notification according to an embodiment of the present invention.
  • the user can enter the electronic service system by calling, surfing or other means, and bind the ID to the account of the electronic business application system; for example: in the electronic banking system, the ID and the bank account number are used. Bind.
  • the user sets the confirmation electronic service confirmation trigger condition to complete the binding. For example: When the transfer from the account reaches 100 yuan or the accumulated transfer reaches 200 yuan in one day, the owner needs to be notified and wait for the confirmation of the owner. In other cases, the owner is not required to be notified.
  • FIG. 9 is a schematic diagram of a user UCD according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of a confirmation center UCD according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of an electronic service application system UCD according to an embodiment of the present invention.
  • the bank name is: Bank 1
  • User 1 has an account at Bank 1.
  • Bank 1 has established a validation center and integrated the validation center interface program with the e-banking system.
  • Step 1 User 1 to the Bank 1 confirmation center website registration use confirmation service.
  • the user provides personal information such as the mobile terminal number, and chooses a valid one.
  • this ID corresponds to the mobile terminal number of the user, and the confirmation center stores the correspondence between the ID and the mobile terminal number.
  • Step 2 After User 1 registers successfully, the confirmation center sends a message to User 1's mobile terminal. Download the JAVA program information, this JAVA program is used to generate an electronic service confirmation result based on the user's feedback, and send the electronic service confirmation result to the confirmation center. If the JAVA program is not on the mobile terminal of the user 1, the JAVA program is downloaded and automatically installed to the mobile terminal of the user 1 according to the prompt of the information. If the JAVA program t is already installed on the mobile terminal of User 1, there is no need to download again.
  • Step 3 User 1 to 4 ⁇ 1 at the business counter or call, bind the ID to User 1 at Bank 1. And set the notification and confirmation conditions. For example: When the amount in the account is reduced by 100 yuan or the total decrease is 200 yuan in one day, the system will automatically notify the user 1 and wait for the confirmation result of the user 1. If the banking system does not receive a response from User 1 within a certain period of time, the corresponding action to reduce the account amount is cancelled.
  • Step 4 User 1 uses Bank 1's account for online payment.
  • Step 5 The banking system checks whether the payment amount meets the confirmation conditions. If not, the online payment is processed in the existing way. If the condition is met, a notification and confirmation message is generated and a confirmation request is sent to the confirmation center.
  • Step 6 The confirmation center finds the corresponding mobile terminal number according to the ID, and sends the confirmation message to the corresponding mobile terminal in the form of a short message, and activates the JAVA program running on the mobile terminal.
  • Step 7 User 1 sends a confirmation result to the confirmation center through the JAVA program, allowing this online payment.
  • Step 8 The confirmation center sends the confirmation result of the payment to the electronic banking system.
  • Step 9 The electronic banking system handles online payments.
  • the online payment request of the fourth step is not issued by the user 1, but is sent by another person such as a hacker
  • the user 1 can monitor the time in the seventh step, and can send the rejection payment to the confirmation center through the JAVA program. Confirmation result, then, the confirmation center will send the confirmation result of the rejection of payment to the electronic banking system, and the electronic banking system cancels the online payment. This will eliminate illegal electronic services and greatly improve the security of electronic services.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Theoretical Computer Science (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Finance (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Marketing (AREA)
  • Technology Law (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

电子业务确认系统及其实现方法
技术领域
本发明涉及电子业务技术领域, 更具体地, 涉及电子业务确认系统 及其实现方法。 发明背景
由于方便、 成本低、跨地域等优点, 电子业务正在全球飞速发展着。 电子业务通常包括电子商务、 移动商务、 电子政务等各种表现形式。 虽 然目前电子业务发展得很快, 但是由于电子业务的发生是在人不出现或 者没有人的参与下自动完成的,这可能会引起一系列的安全问题。比如: 在进行网上交易、 网上支付等网上电子业务时, 由于无法得到用户的物 理签名, 而只能根据用户名和密码来验证用户的身份, 银行和商家很难 保证进行网上交易、 支付的人的身份合法性, 这就给欺祚的产生提供了 温床, 并给银行、 信用卡公司, 商家和持卡人带来了巨大的经济损失。
根据权威调查统计: 2003年美国信用卡欺 i乍损失为 23. 7亿美元, 其中网上欺诈损失为 12. 3亿美元, 2002年全球银行卡欺祚损失甚至达 到 38亿美元。 再根据 Lpsos-Ins ights , 2004年 1月统计: 大约 70%的 用户害怕在互联网上用卡支付。
因此, 迫切需要一种能够监控电子业务发生的通知与确认方式, 并 且这种方式是安全和方便的。 比如, 当银行帐户里的金额减少时, 能够 自动通知持卡人或授权监控人, 只有收到被通知人的确认后, 再准予进 行转帐。 另外, 海关、 货运、 航空、 订单、 各种申请批复等一系列靠传 统邮件、 电话通知或者人们主动查询的系统, 需要一种方式能够自动通 知有关的人, 并接收有关人的回应 (确认) 结果。 目前, 在现有技术中有一种利用移动电话短消息通知电子业务中数 据变化的方法。 在这种方法中, 当某些重要的数据, 比如银行帐户里的 金额发生变化时, 业务发生系统通过移动电话网关向相关的人的移动电 话发送短消息以进行通知, 如果被通知的人觉察出有问题, 则再进行电 话查询等相应处理。 在这种方法中, 由于移动电话中仅仅显示短消息, 并不对短消息进行进一步处理, 因此这种方式并不能够控制业务的发 生, 至多只能在业务发生后了解到业务的发生, 因此这种现有技术无法 监控电子业务, 从而电子业务的安全性无法得到保证。 发明内容
有鉴于此, 本发明的主要目的是提出一种电子业务确认系统, 能够 对电子业务的发生予以监控, 从而提高电子业务的安全性。
本发明的另一目的是提出一种电子业务确认方法, 能够对电子业务 的发生予以监控, 从而提高电子业务的安全性。
本发明的另一目的是提出一种电子业务确认中心, 应用该中心能够 对电子业务的发生予以监控, 从而提高电子业务的安全性。
本发明的另一目的是提出一种确认终端, 应用该确认终端能够实现 对电子业务的发生予以监控, 从而提高电子业务的安全性。
为达到上述目的, 本发明的技术方案是这样实现的:
一种电子业务确认系统, 该电子业务确认系统包括:
电子业务应用系统, 用于当执行电子业务时向确认中心发送电子业 务确认请求 , 并根据确认中心返回的电子业务确认结果对电子业务进行 操作;
确认中心, 用于根据所述电子业务确认请求确定对应的确认终端, 向该确认终端发送电子业务确认消息, 并将确认终端返回的电子业务确 认结果发送到电子业务应用系统;
确认终端, 用于接收电子业务确认消息, 根据用户的反馈生成电子 业务确认结果, 并将所述电子业务确认结果发送到确认中心。
所述确认中心以短消息(SMS )协议、 或 Socket协议、 或 Datagram 协议向确认终端发送所述电子业务确认消息。
所述确认终端为移动电话、 PDA、 PC、 膝上型计算机。
所述电子业务应用系统为银行帐户监控系统、 电话银行交易系统、 网络 4艮行交易系统、 电子商务交易系统、 流动资产监控系统、 网络密码 保护系统。
所述确认中心包括:
Web服务器, 用于接收所述电子业务确认请求, 控制应用服务器在 数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述确认 终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确认结 果发送到电子业务应用系统;
应用服务器, 用于根据 Web服务器的命令查询数据库中的确认终端 的 ID和通信方式;
数据库,用于存储确认终端的 ID以及所述电子业务确认消息和电子 业务确认结果。
所述数据库进一步用于存储用户的个人信息; Web服务器进一步用 于经由与确认终端的互联网 Web连接接受用户注册, 和 /或, 根据 Web 服务器的请求查询和 /或修改用户的个人信息。
所述确认中心包括:
Socket服务器, 用于接收所述电子业务确认请求, 控制应用服务器 在数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述确 认终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确认 结果发送到电子业务应用系统;
应用服务器, 用于根据 Socket服务器的命令查询数据库中的确认终 端的 ID;
数据库,用于存储确认终端的 ID以及所述电子业务确认消息和电子 业务确认结果。
所述确认终端注册的通信方式为: 以 SMS协议、 或 Socket协议、 或 Datagram协议与确认中心进行通信。
所述数据库进一步用于存储用户的个人信息; Socket服务器进一步 用于经由与确认终端的互联网 Socket连接接受用户注册, 和 /或, 根据 Socket服务器的请求查询和 /或修改用户的个人信息。
所述确认终端包括电子业务确认模块, 所述电子业务确认模块用于 根据所述电子业务确认消息以及用户反馈生成电子业务确认结果。
一种电子业务确认中心, 该电子业务确认中心接收由电子业务应用 系统发送的电子业务确认请求, 并根据电子业务确认请求查找对应的确 认终端, 以确认终端注册的通信方式向所述确认终端发送电子业务确认 消息, 并发送确认终端返回的电子业务确认结果到电子业务应用系统, 该确认中心包括:
信息传输服务器, 用于接收所述电子业务确认请求, 控制应用服务 器在数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述 确认终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确 认结果发送到电子业务应用系统;
应用服务器, 用于根据信息传输服务器的命令查询数据库中的确认 终端的 ID和通信方式;
数据库,用于存储确认终端的 ID以及所述电子业务确认消息和电子 业务确认结果。 所述确认终端注册的通信方式为: 以 SMS协议、 或 Socket协议、 或 Datagram协议与所述确认中心进行通信。
所述信息传输服务器为 Web服务器或 Socket服务器。
一种移动终端, 该移动终端用于从电子业务确认中心接收电子业务 确认消息, 并根据用户反馈生成将电子业务确认结果, 以及将电子业务 确认结果发送到电子业务确认中心, 该移动终端包括具有收发电子业务 确认信息的通信模块和电子业务确认模块,
通信模块, 用于接收电子业务确认消息, 并将电子业务确认模块生 成的电子业务确认结果以发送到电子业务确认中心;
电子业务确认模块, 用于根据所述电子业务确认消息以及用户反馈 生成电子业务确认结果。
所述通信模块以 SMS、 或超文本传输协议(HTTP ) 的方式将所述 电子业务确认结果发送到电子业务确认中心。
所述移动终端为移动电话、 PDA。
所述电子业务确认模块, 是以 PUSH的方式被设置在所述移动终端 中, 或者以 OTA的方式被设置在所述移动终端中。
一种电子业务确认方法, 该方法包括:
A、 电子业务应用系统当执行电子业务时向确认中心发送电子业务 确认请求;
B、 确认中心 居所述电子业务确认请求查找与该确认请求所对应 的确认终端, 并向确认终端发送电子业务确认消息;
C、 确认终端向用户提示电子业务确认消息, 根据用户的反馈生成 电子业务确认结果, 并将电子业务确认结果发送到确认中心;
D、 确认中心将确认终端返回的电子业务确认结果发送到电子业务 应用系统, 电子业务应用系统才艮据该电子业务确认结果对电子业务进行 操作。
该方法包括, 进一步预先在电子业务应用系统中设定电子业务确认 触发条件, 步 入为: 电子业务应用系统在执行电子业务时, 当满足所 述电子业务确认触发条件时, 向确认中心发送电子业务确认请求。
所述确认中心向确认终端发送电子业务确认消息为: 确认中心向确 认终端发送经过加密的电子业务确认消息。
所述确认中心向确认终端发送电子业务确认消息为: 确认中心以确 认终端注册的通信方式向确认终端发送电子业务确认消息。
步骤 D所述电子业务应用系统对电子业务进行操作包括: 电子业务应用系统根据电子业务确认结果判断是否准许执行电子业 务, 如果是, 则执行, 否则不执行电子业务。
从上述技术方案中可以看出, 在本发明中, 电子业务确认系统包括 电子业务应用系统、 确认中心和确认终端。 确认终端根据用户的反馈生 成电子业务确认结果, 并将电子业务确认结果发送到确认中心; 确认中 心将电子业务确认结果发送到电子业务应用系统; 然后电子业务应用系 统才 居电子业务确认结果来对电子业务的执行情况进行处理。 因此, 应 用本发明以后, 通过电子业务应用系统、 确认中心和确认终端的上述交 互, 能够对电子业务的发生予以及时监控, 而不只是在电子业务完成后 才进行简单的通知, 所以本发明极大地提高了电子业务的安全性。 附图简要说明
图 1为才艮据本发明的电子业务确认系统的示范性结构示意图。
图 2为才 据本发明实施例的确认中心的示范性结构示意图。
图 3 为根据本发明实施例的电子业务确认系统的示范性结构示意 图。 图 4为根据本发明的电子业务确认方法的示范性流程示意图。
图 5为 >据本发明实施例的电子业务确认业务的示意图。
图 6为根据本发明实施例的用户注册电子业务确认通知的方法流程 示意图。
图 Ί为根据本发明实施例的用户测试电子业务确认通知的方法流程 示意图。
图 8为根据本发明实施例的用户绑定电子业务确认通知的方法流程 示意图。
图 9为根据本发明实施例的用户 UCD示意图。
图 10为根据本发明实施例的确认中心 UCD示意图。
图 11为根据本发明实施例的电子业务应用系统 UCD示意图。 实施本发明的方式
为使本发明的目的、 技术方案和优点表达得更加清楚明白, 下面结 合附图及具体实施例对本发明再作进一步详细的说明。
图 1 为根据本发明实施例的电子业务确认系统的示范性结构示意 图。 如图 1所示, 该电子业务确认系统包括:
电子业务应用系统 101 , 用于当执行电子业务时向确认中心 102发 送电子业务确认请求, 并根据确认中心 102返回的电子业务确认结果对 电子业务进行操作;
确认中心 102 , 用于根据所述电子业务确认请求确定对应的确认终 端 103, 向该确认终端 103发送电子业务确认消息, 并将确认终端 103 返回的电子业务确认结果发送到电子业务应用系统 101 ;
确认终端 103, 用于接收电子业务确认消息, 根据用户的反馈生成 电子业务确认结果, 并将所述电子业务确认结果发送到确认中心 102。 其中, 确认中心 102可以通过 SMS协议、 Socket协议、 Datagram 等协议向确认终端发送电子业务确认消息。 确认终端 103返回的电子业 务确认结果可以利用以 SMS、 或超文本传输协议(HTTP )等方式发送到 电子业务应用系统 101。 在这里, 本领域技术人员可以意识到: 以上虽 然罗列出一些具体的协议和实现方式, 但本发明对确认中心 102向确认 终端发送电子业务确认消息的方式, 以及确认终端 103向电子业务应用 系统 101发送电子业务确认结果的方式并无限定。优选地,确认终端 103 可以首先在确认中心 102注册相应的通信方式, 然后再 据该通信方式 实现相互通信。
其中, 电子业务应用系统 101可以为任意的电子业务运行系统或者 电子业务操作系统, 具体可为: 银行帐户监控系统、 电话银行交易系统、 网络 4艮行交易系统、 电子商务交易系统、 流动资产监控系统、 网络密码 保护系统等。 具体地, 网络密码保护系统可以为各种形式的电子邮件系 统、 网络游戏系统等。 因此, 应用本发明以后, 还能够为电子邮件、 网 络游戏等提供进一步的保护, 以防止非法登陆。
确认终端 103可以为移动电话、 个人数字助理(PDA )、 个人计算机 ( PC ), 膝上型计算机等具有通信功能的实体。
具体地,确认终端 103包括具有收发电子业务确认信息的通信模块, 还包括电子业务确认模块, 电子业务确认模块用于根据所述电子业务确 认消息以及用户反馈生成电子业务确认结果。 在这里, 电子业务确认模 块可以是运行在确认终端 103上的 JAVA程序。 优选地, 可以将该 JAVA 程序 (MIDl et )通过 OTA ( Over- The- Ai r )等远程设置的方式下载并自 动安装到确认终端 102上。 确认终端 102的 JAVA程序平时不需启动, 当需要执行确认时, 确认中心 102用 Push Regi s try的方式将其激活。
Push Regi s try是 MIDlet 2. 0新增加的功能。 是一种可以使 MIDl et 能够被服务器端的连接或者定时器激活的新机制。 这种技术能够实现当 某个事件发生时, 不需要用户的介入, 从服务器端让运行在移动终端上 的 MIDl et 自动启动。
本发明实施例中, 确认终端 103 上的 JAVA 程序向其上的 AMS ( Appl i ca t ion Management Sof tware ) 注册可以被 6000口上 SMS通信 协议的连接激活。 (sms:〃:6000)。 接到来自电子业务应用系统 101 的 确认请求后, 确认中心 102向相应的确认终端 103上的 6000 口上发送 短消息。 当 JAVA程序被 6000口上的短消息激活, 开始启动, 接收并处 理短消息。
在以上过程中,虽然以 JAVA语言为例详细说明了如何实现确认终端 的功能, 但是本领域技术人员可以意识到, 本发明并不局限于 JAVA语 言, 而是可以适用到各种面对对象的编程语言。 比如, C语言, C + +语 言, PASCAL语言等。
确认中心 102是整个系统的核心, 用于为电子业务应用系统 101提 供确认服务。当确认中心 102收到电子业务应用系统 101的确认请求后, 确认中心 102向相应的确认终端 103发出确认请求, 当确认中心 102收 到来自确认终端 103的确认结果后, 《fc确认结果通知相应的电子业务应 用系统 101。
图 2为才艮据本发明实施例的确认中心的示范性结构示意图。 如图 2 所示, 确认中心包括:
Web服务器 201, 用于接收所述电子业务确认请求,控制应用服务器 202在数据库 203中查找对应的确认终端, 以确认终端注册的通信方式 向所述确认终端发送电子业务确认消息, 并将确认终端发送的所述电子 业务确认结果发送到电子业务应用系统;
应用服务器 202, 用于根据 Web服务器的命令查询数据库 203中的 确认终端的 ID和通信方式;
数据库 203 , 用于存储确认终端的 ID以及所述电子业务确认消息和 电子业务确认结果。
在这里, Web服务器 201还可以经由与确认终端的互联网 Web连接 接受用户注册确认服务, 和 /或, 根据 Web服务器的请求在数据库 203 中查询和 /或修改用户的个人信息。 用户从可以从 Web服务器 201下载 JAVA程序到确认终端上。 另外, Web服务器 201通过应用服务器 202存 储来自电子业务应用系统 101的通知请求和来自确认终端 103的确认结 果到数据库 203。
在这里, 还可以用 Socket服务器来替代 Web服务器。 此时, Socke t 服务器经由与确认终端 103的互联网 Socke t连接接受用户注册,和 /或, 根据 Socke t服务器的请求查询和 /或修改用户的个人信息。
具体地,应用服务器 202处理来自 Web服务器的请求,如查询 /修改 用户的个人信息, 存储来自电子业务应用系统的通知请求和来自确认终 端的确认结果等。 数据库 203中存储整个系统中的各种信息, 比如用户 的个人信息、来自电子业务应用系统 1 01的通知请求和来自确认终端 103 的确认结果等。
以上虽然具体描述了确认中心的结构, 但是本领域普通技术人员可 以意识到, 本发明并不局限于此。 比如, 可以釆用既支持 Web 又支持 Socket的服务器作为确认中心的对外接口,只要其支持基于互联网和移 动通信的信息传输即可。
也就是说, 通常确认中心包括: 信息传输服务器, 用于接收电子业 务确认请求, 控制应用服务器在数据库中查找对应的确认终端, 以确认 终端注册的通信方式向所述确认终端发送电子业务确认消息, 并将确认 终端发送的所述电子业务确认结果发送到电子业务应用系统; 应用服务 器, 用于根据信息传输服务器的命令查询数据库中的确认终端的 ID 和 通信方式; 数据库, 用于存储确认终端的 ID以及所述电子业务确认消 息和电子业务确认结果。
结合图 1和图 2 , 图 3为根据本发明实施例的电子业务确认系统的 示范性结构示意图。 其中移动终端可以根据其所包含的浏览器在确认中 心的 WEB服务器中注册电子业务确认服务。 当注册完电子业务确认服务 后, 移动终端便能够监控电子业务的发生。
图 4为根据本发明的电子业务确认方法的示范性流程示意图。 如图 4所示, 该方法包括:
步骤 401: 电子业务应用系统当执行电子业务时向确认中心发送电 子业务确认请求;
步驟 402: 确认中心根据电子业务确认请求确定与该确认请求所对 应的确认终端, 并向确认终端发送电子业务确认消息;
步骤 403: 确认终端向用户提示电子业务确认消息, 根据用户的反 馈生成电子业务确认结果, 并将电子业务确认结果发送到确认中心; 步骤 404: 确认中心将确认终端返回的电子业务确认结果发送到电 子业务应用系统, 电子业务应用系统根据该电子业务确认结果对电子业 务进行操作。
以上过程中, 可以预先在电子业务应用系统中设定电子业务确认触 发条件, 然后电子业务应用系统在执行电子业务中, 只有当满足所述电 子业务确认触发条件时, 才向确认中心发送电子业务确认请求, 当不满 足电子业务确认触发条件, 并不执行确认请求操作。
其中,确认中心向确认终端发送的电子业务确认消息优选是加密的, 并且确认中心优选以短消息形式向确认终端发送电子业务确认消息。 电 子业务应用系统收到电子业务确认结果后, 判断电子业务确认结果是否 准许执行电子业务, 如果是, 则执行, 否则不执行电子业务。
图 5为根据本发明实施例的用户注册电子业务确认通知的方法流程 示意图。 此处假设该电子业务为网上 4艮行模式中的一次转帐。
首先使用电子业务应用系统进行一次交易, 电子业务应用系统根据 用户事先设定的条件判断这次交易是否需要通知用户确认, 如果这次交 易不需要通知用户, 则按现有的方式完成; 如果这次交易需要用户的确 认, 电子业务应用系统生成通知信息, 并向确认中心发送确认请求。 确 认中心首先将确认请求暂存到数据库中, 然后才艮据确认请求中的 ID, 找 到对应的确认终端。 (此处确认请求中的 ID和确认终端可以在注册时已 经绑定在数据库中), 然后将确认信息以短消息的形式发给对应的确认 终端。 然后, 确认终端上的 JAVA程序被短消息激活, 开始运行, 具体 为: 显示确认请求信息, 并等待用户的确认, 然后根据用户的确认结果, 生成确认结果信息, 并把确认结果信息送到确认中心。 确认中心再更新 数据库中对应的确认请求记录, 并把确认结果送给电子业务应用系统, 然后电子业务应用系统根据确认结果, 完成或者拒绝用户所做的交易。
下面对用户注册电子业务确认通知的方法进行说明。 图 6为根据本 发明实施例的用户注册电子业务确认通知的方法流程示意图。
如图 6所示, 首先, 用户可以通过浏览器登录到确认中心的网站, 选择有效的 ID、 设定密码、 提供移动终端号码等个人信息、 然后提交注 册。 当注册成功后, 确认中心发送下载 JAVA程序的信息给对应的移动 终端。 如果用户的移动终端上没有该 JAVA程序, 则^^据下载信息的提 示, 自动下载并自动安装该 JAVA程序到移动终端上。 如果用户的移动 终端上已经安装了该 JAVA程序, 则完成注册。
下面对用户测试电子业务确认通知的方法进行说明。 图 7为 居本 发明实施例的用户测试电子业务确认通知的方法流程示意图。 如图 7所示, 首先用户通过浏览器登录到确认中心的网站, 生成测 试 JAVA程序信息, 然后确认中心发送该测试 JAVA程序信息给用户的移 动终端, 用户对该测试 JAVA程序信息进行确认, 然后用户通过浏览器 从确认中心的网站查看确认结果来了解测试是否成功。
下面对用户绑定电子业务确认通知的方法进行说明。 图 8为 居本 发明实施例的用户绑定电子业务确认通知的方法流程示意图。
如图 8所示, 用户可以通过打电话、 上网或者其它方式进入电子业 务症用系统, 将 ID和电子业务应用系统的帐户绑定起来; 例如: 在电 子银行系统中, 将 ID和银行帐号进行绑定。 然后, 用户设置确认电子 业务确认触发条件, 以完成绑定。 例如: 当一次从帐户中转帐达到 100 元或者一天内累计转帐达到 200元时,需要通知户主并等待户主的确认, 在其它情况下, 则不需要通知户主。
图 9为根据本发明实施例的用户 UCD示意图;图 10为根据本发明实 施例的确认中心 UCD示意图; 图 11为根据本发明实施例的电子业务应 用系统 UCD示意图。
下面详细描述本发明的一个实例。 以电子 4艮行系统中电子业务通知 系统保护流动资产为例, 描述本发明的完整流程。
首先假定: 银行名称为: 银行 1, 并且用户 1在银行 1开有帐户。 此处银行 1已经建立了确认中心, 并把确认中心接口程序和电子银行系 统集成在一起。
第一步: 用户 1到银行 1的确认中心网站注册使用确认服务。
在这里, 用户提供移动终端号码等个人信息, 自己选择一个有效的
ID, 此 ID与该用户的移动终端号码相对应, 确认中心存储此 ID和移动 终端号码的对应关系。
第二步: 用户 1注册成功后, 确认中心给用户 1的移动终端发送一 个下载 JAVA程序的信息, 此 JAVA程序用于根据用户的反馈生成电子业 务确认结果, 并将电子业务确认结果发送到确认中心。 其中, 如果用户 1的移动终端上没有该 JAVA程序, 则按照信息的提示, 下载并自动安装 该 JAVA程序到用户 1 的移动终端上。 如果用户 1 的移动终端上已经安 装有该 JAVA程序 t , 则不需要再下载。
第三步: 用户 1到 4艮行 1的营业柜台或者打电话, 将该 ID与用户 1 在银行 1的帐户绑定起来。 并设定通知和确认条件。 例如: 当帐户里的 金额一次减少达到 100元或者一天内累计减少达到 200元时, 4艮行系统 自动通知用户 1 , 并等待用户 1的确认结果。 如果银行系统在一定时间 内没有收到用户 1允许的回应, 则取消相应的减少帐户金额的操作。
第四步: 用户 1用银行 1的帐户进行网上支付。
第五步: 银行系统检查支付金额是否满足确认条件。 如果不满足, 则按现有的方式处理网上支付。如果满足条件,则生成通知和确认信息, 并向确认中心发送确认请求。
第六步: 确认中心根据该 ID找到对应的移动终端号码, 并把确认信 息以短消息的形式发给相应的移动终端, 并激活运行在移动终端上的 JAVA程序。
第七步: 用户 1通过 JAVA程序向确认中心发送确认结果, 允许这次 网上支付。
第八步: 确认中心把允许支付的确认结果发给电子银行系统。
第九步: 电子银行系统处理网上支付。
其中, 如果第四步的网上支付请求不是用户 1发出的, 而是黑客等 其它人发出的, 则第七步中用户 1能够对此进行及时监控, 并可以通过 JAVA程序向确认中心发送拒绝支付的确认结果, 然后, 确认中心将拒绝 支付的确认结果发给电子银行系统, 电子银行系统取消本次网上支付, 从而能够杜绝非法电子业务, 极大地提高电子业务的安全性。
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的 保护范围。 凡在本发明的精神和原则之内, 所作的任何修改、等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权利要求书
1、一种电子业务确认系统,其特征在于,该电子业务确认系统包括: 电子业务应用系统, 用于当执行电子业务时向确认中心发送电子业 务确认请求, 并根据确认中心返回的电子业务确认结果对电子业务进行 操作;
确认中心, 用于才艮据所述电子业务确认请求确定对应的确认终端, 向该确认终端发送电子业务确认消息, 并将确认终端返回的电子业务确 认结果发送到电子业务应用系统;
确认终端, 用于接收电子业务确认消息, 根据用户的反馈生成电子 业务确认结果, 并将所述电子业务确认结果发送到确认中心。
2、根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述确 认中心以短消息 SMS协议、 或 Socket协议、 或 Datagram协议向确认终 端发送所述电子业务确认消息。
3、根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述确 认终端为移动电话、 个人数字助理 PDA、 个人计算机 PC、 膝上型计算 机。
4、根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述电 子业务应用系统为银行帐户监控系统、 电话银行交易系统、 网络银行交 易系统、 电子商务交易系统、 流动资产监控系统、 网络密码保护系统。
5、根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述确 认中心包括:
Web服务器, 用于接收所述电子业务确认请求, 控制应用服务器在 数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述确认 终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确认结 果发送到电子业务应用系统;
应用服务器,用于根据 Web服务器的命令查询数据库中的确认终端 的 ID和通信方式;
数据库, 用于存储确认终端的 ID 以及所述电子业务确认消息和电 子业务确认结果。
6、根据权利要求 5所述的电子业务确认系统, 其特征在于, 所述数 据库进一步用于存储用户的个人信息; Web服务器进一步用于经由与确 认终端的互联网 Web连接接受用户注册, 和 /或, 根据 Web服务器的请 求查询和 /或修改用户的个人信息。
7、根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述确 认中心包括:
Socket服务器, 用于接收所述电子业务确认请求, 控制应用服务器 在数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述确 认终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确认 结果发送到电子业务应用系统;
应用服务器, 用于根据 Socket服务器的命令查询数据库中的确认终 端的 ID;
数据库, 用于存储确认终端的 ID 以及所述电子业务确认消息和电 子业务确认结果。
8、根据权利要求 5或 7所述的电子业务确认系统, 其特征在于, 所 述确认终端注册的通信方式为:以 SMS协议、或 Socket协议、或 Datagram 协议与确认中心进行通信。
9、根据权利要求 7所述的电子业务确认系统, 其特征在于, 所述数 据库进一步用于存储用户的个人信息; Socket服务器进一步用于经由与 确认终端的互联网 Socket连接接受用户注册, 和 /或, 根据 Socket服务 器的请求查询和 /或修改用户的个人信息。
10、 根据权利要求 1所述的电子业务确认系统, 其特征在于, 所述 确认终端包括电子业务确认模块, 所述电子业务确认模块用于根据所述 电子业务确认消息以及用户反馈生成电子业务确认结果。
11、 一种电子业务确认中心, 其特征在于, 该电子业务确认中心接 收由电子业务应用系统发送的电子业务确认请求, 并才艮据电子业务确认 请求查找对应的确认终端, 以确认终端注册的通信方式向所述确认终端 发送电子业务确认消息, 并发送确认终端返回的电子业务确认结果到电 子业务应用系统, 该确认中心包括:
信息传输服务器, 用于接收所述电子业务确认请求, 控制应用服务 器在数据库中查找对应的确认终端, 以确认终端注册的通信方式向所述 确认终端发送电子业务确认消息, 并将确认终端发送的所述电子业务确 认结果发送到电子业务应用系统;
应用服务器, 用于根据信息传输服务器的命令查询数据库中的确认 终端的 ID和通信方式;
数据库, 用于存储确认终端的 ID 以及所述电子业务确认消息和电 子业务确认结果。
12、根据权利要求 11所述的电子业务确认中心, 其特征在于, 所述 确认终端注册的通信方式为:以 SMS协议、或 Socket协议、或 Datagram 协议与所述确认中心进行通信。
13、根据权利要求 11所述的电子业务确认中心, 其特征在于, 所述 信息传输服务器为 Web服务器或 Socket服务器。
14、 一种移动终端, 其特征在于, 该移动终端用于从电子业务确认 中心接收电子业务确认消息, 并根据用户反馈生成将电子业务确认结 果, 以及将电子业务确认结果发送到电子业务确认中心, 该移动终端包 括具有收发电子业务确认信息的通信模块和电子业务确认模块, 通信模块, 用于接收电子业务确认消息, 并将电子业务确认模块生 成的电子业务确认结果以发送到电子业务确认中心;
电子业务确认模块, 用于根据所述电子业务确认消息以及用户反馈 生成电子业务确认结果。
15、根据权利要求 14所述的移动终端, 其特征在于, 所述通信模块 以 SMS、或超文本传输协议 HTTP的方式将所述电子业务确认结果发送 到电子业务确认中心。
16、根据权利要求 15所述的移动终端, 其特征在于, 所述移动终端 为移动电话、 PDA。
17、根据权利要求 15所述的移动终端, 其特征在于, 所述电子业务 确认模块, 是以 PUSH的方式被设置在所述移动终端中, 或者以 OTA 的方式被设置在所述移动终端中。
18、 一种电子业务确认方法, 其特征在于, 该方法包括:
A、 电子业务应用系统当执行电子业务时向确认中心发送电子业务 确认请求;
B、 确认中心根据所述电子业务确认请求查找与该确认请求所对应 的确认终端, 并向确认终端发送电子业务确认消息;
C、 确认终端向用户提示电子业务确认消息, 根据用户的反馈生成 电子业务确认结果, 并将电子业务确认结果发送到确认中心;
D、 确认中心将确认终端返回的电子业务确认结果发送到电子业务 应用系统, 电子业务应用系统根据该电子业务确认结果对电子业务进行 操作。
19、 根据权利要求 18所述的方法, 其特征在于, 该方法包括, 进一 步预先在电子业务应用系统中设定电子业务确认触发条件, 步骤 A为: 电子业务应用系统在执行电子业务时, 当满足所述电子业务确认触发条 件时, 向确认中心发送电子业务确认请求。
20、根据权利要求 18所述的方法, 其特征在于, 所述确认中心向确 认终端发送电子业务确认消息为: 确认中心向确认终端发送经过加密的 电子业务确认消息。
21、根据权利要求 18所述的方法, 其特征在于, 所述确认中心向确 认终端发送电子业务确认消息为: 确认中心以确认终端注册的通信方式 向确认终端发送电子业务确认消息。
22、 根据权利要求 18所述的方法, 其特征在于, 步骤 D所述电子 业务应用系统对电子业务进行操作包括:
电子业务应用系统根据电子业务确认结果判断是否准许执行电子业 务, 如果是, 则执行, 否则不执行电子业务。
PCT/CN2007/000856 2006-03-22 2007-03-16 Systeme et procede de confirmation de transaction de commerce electronique WO2007107093A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US12/233,746 US20090012890A1 (en) 2006-03-22 2008-09-19 System and method for confirming electronic service

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNA2006100585877A CN101042764A (zh) 2006-03-22 2006-03-22 电子业务确认系统及其实现方法
CN200610058587.7 2006-03-22

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US12/233,746 Continuation US20090012890A1 (en) 2006-03-22 2008-09-19 System and method for confirming electronic service

Publications (1)

Publication Number Publication Date
WO2007107093A1 true WO2007107093A1 (fr) 2007-09-27

Family

ID=38522035

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2007/000856 WO2007107093A1 (fr) 2006-03-22 2007-03-16 Systeme et procede de confirmation de transaction de commerce electronique

Country Status (3)

Country Link
US (1) US20090012890A1 (zh)
CN (1) CN101042764A (zh)
WO (1) WO2007107093A1 (zh)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101789151A (zh) * 2009-12-31 2010-07-28 中兴通讯股份有限公司 移动终端电子钱包的应用方法及移动终端
CN102291376B (zh) * 2010-06-18 2013-11-20 普天信息技术研究院有限公司 一种支持移动终端的电子交易实现方法和系统
US20140358752A1 (en) * 2013-05-28 2014-12-04 Bank Of America Corporation Transaction monitoring to ensure policy compliance
KR20160092716A (ko) * 2015-01-28 2016-08-05 한국전자통신연구원 리슬리 프리즘을 이용한 홀로그램 프로젝션 시스템
CN105049237A (zh) * 2015-06-24 2015-11-11 云南电网有限责任公司信息中心 一种多级业务性能模型及瓶颈发现方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001035186A2 (en) * 1999-11-05 2001-05-17 Simon Property Group, L.P. Interactive in-store and online shopping system
CN1453982A (zh) * 2002-04-28 2003-11-05 黄金富 手机来电显示信息的多种金融卡支付确认电讯方法及系统
CN1588383A (zh) * 2004-08-25 2005-03-02 周星 银行转帐手机短信确认系统

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7003497B2 (en) * 2001-05-23 2006-02-21 International Business Machines Corporation System and method for confirming electronic transactions

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001035186A2 (en) * 1999-11-05 2001-05-17 Simon Property Group, L.P. Interactive in-store and online shopping system
CN1453982A (zh) * 2002-04-28 2003-11-05 黄金富 手机来电显示信息的多种金融卡支付确认电讯方法及系统
CN1588383A (zh) * 2004-08-25 2005-03-02 周星 银行转帐手机短信确认系统

Also Published As

Publication number Publication date
CN101042764A (zh) 2007-09-26
US20090012890A1 (en) 2009-01-08

Similar Documents

Publication Publication Date Title
AU2006312456B2 (en) Authentication for service server in wireless internet and settlement using the same
JP5719871B2 (ja) フィッシング攻撃を防ぐ方法および装置
CN106357644B (zh) 基于区块链网络的身份认证方法、系统及服务器
Abadi et al. Bankable postage for network services
WO2002102104A1 (en) Method and apparatus for remotely disabling and enabling access to secure transaction functions of a mobile terminal
KR20040037074A (ko) 전자 메시징을 이용한 금융 거래 시스템 및 방법
WO2010129357A2 (en) Verification of portable consumer devices
JP2005158066A (ja) ベンダサービス用の自動化された顧客資格付与システム
JP2005209083A (ja) サービスシステム、及びそれを用いた通信システム、通信方法
WO2007107093A1 (fr) Systeme et procede de confirmation de transaction de commerce electronique
KR102116587B1 (ko) 사이버 id를 이용하여 보안 트랜잭션을 제공하는 방법 및 시스템
AU2020266302A1 (en) Online payment system
EP2075736A2 (en) Method for verifying server end apparatus
JP2001319058A (ja) 金融処理システム、金融処理システムのシステム処理方法、及び、そのためのプログラムを記録した記録媒体
JP2003264551A (ja) 通信端末とサーバとのセキュリティ確保方法
CN114944947B (zh) 客户端的权限认证方法、装置、设备及存储介质
JP2023118166A (ja) 認証システム及びコンピュータプログラム
KR100822957B1 (ko) 금융거래 처리용 프로그램을 기록한 것을 특징으로 하는기록매체와, 이를 이용한 금융거래 처리방법 및 시스템
CN114971645A (zh) 资源转移认证方法、装置、计算机设备和存储介质
TWM639374U (zh) 電子請款及付款系統
JP2002324203A (ja) ネットワークにおける双方向認証システムおよび方法、ならびにそのプログラムと記録媒体
AU2010246247B2 (en) Verification of portable consumer devices
WO2006016850A1 (en) Authentication method and system
WO2002084551A1 (fr) Systeme de paiement postal au moyen d'un numero de telephone en tant que cle
JP2004139302A (ja) 電子決済サーバ、電子決済システム、電子決済方法及びプログラム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 07720434

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 07720434

Country of ref document: EP

Kind code of ref document: A1