WO2012139286A1 - 交易信息确认装置、电子签名工具及系统、电子签名方法 - Google Patents

交易信息确认装置、电子签名工具及系统、电子签名方法 Download PDF

Info

Publication number
WO2012139286A1
WO2012139286A1 PCT/CN2011/072714 CN2011072714W WO2012139286A1 WO 2012139286 A1 WO2012139286 A1 WO 2012139286A1 CN 2011072714 W CN2011072714 W CN 2011072714W WO 2012139286 A1 WO2012139286 A1 WO 2012139286A1
Authority
WO
WIPO (PCT)
Prior art keywords
transaction
module
control module
electronic signature
confirmation
Prior art date
Application number
PCT/CN2011/072714
Other languages
English (en)
French (fr)
Inventor
李东声
Original Assignee
北京天地融科技股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京天地融科技股份有限公司 filed Critical 北京天地融科技股份有限公司
Priority to PCT/CN2011/072714 priority Critical patent/WO2012139286A1/zh
Publication of WO2012139286A1 publication Critical patent/WO2012139286A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures

Definitions

  • the present invention relates to the field of information security, and in particular, to a transaction information confirmation device, an electronic signature tool and system, and an electronic signature method.
  • USB Universal Serial Bus
  • USB is a USB Key that connects to a trading terminal (usually a personal computer) and is used as a tool for identity authentication and transaction authentication.
  • the electronic signature tool is usually required to have a display function, that is, some of the more important transaction information in the current transaction is displayed in text form to the user through a display screen set on the electronic signature tool for the user to Refer to this transaction before confirming it.
  • the electronic signature tool Since the electronic signature tool has a display screen and a button, the cost is high, the size/size is large, and it is not easy to carry, especially when the user is a customer of multiple banks and needs to carry multiple bank electronic signature tools.
  • the drawbacks of existing electronic signature tools in terms of cost and portability are particularly pronounced.
  • the technical problem to be solved by the present invention is to overcome the deficiencies of the prior art, and provide an electronic signature tool, a transaction information confirming device that can be used together with the electronic signature tool, and an electronic component composed of the electronic signature tool and the transaction information confirming device.
  • the signature system, and the corresponding electronic signature method improve the portability of the electronic signature tool without sacrificing the security of the electronic signature tool.
  • the present invention provides an electronic signature method, characterized in that
  • the electronic signature tool After receiving the transaction information of the transaction sent by the transaction terminal, the electronic signature tool sends part or all of the transaction information to the transaction information confirmation device connected thereto;
  • the transaction information confirmation device After receiving the transaction information sent by the electronic signature tool, the transaction information confirmation device displays the transaction information on the display screen of the transaction information confirmation device for the user to confirm the transaction;
  • the electronic signature tool After receiving the confirmation transaction instruction confirming the transaction, the electronic signature tool generates some signature data for completing the transaction using part or all of the transaction information, and transmits the generated signature data to the transaction terminal.
  • confirmation transaction indication for confirming the transaction is received in the following manner:
  • the input module provided in the transaction information confirming device receives the confirmation transaction instruction for confirming the current transaction input by the user; after receiving the confirmation transaction instruction, the transaction information confirming device sends a confirmation to confirm the current transaction to the electronic signature tool. Trading instructions.
  • confirmation transaction indication for confirming the transaction is received in the following manner:
  • the transaction confirmation module set in the electronic signature tool receives the confirmation transaction indication input by the user to confirm the current transaction.
  • the transaction information confirming device receives the identity authentication information of the electronic signature tool input by the user, and sends the identity authentication information to the electronic signature tool;
  • the electronic signature tool After receiving the identity authentication information, the electronic signature tool verifies the identity authentication information.
  • the invention also provides an electronic signature system, which is connected to the transaction terminal, and includes: an electronic signature tool, wherein the system further comprises: a transaction information confirmation device connected to the electronic signature tool; wherein:
  • the electronic signature tool includes: a data processing control module, a second interface module, and a third interface module;
  • the transaction information confirming device includes: a first interface module, a control module, and a display module;
  • the third interface module is connected to the transaction terminal and the data processing control module, and configured to transmit data between the transaction terminal and the data processing control module;
  • the second interface module is connected to the first interface module and the data processing control module, and configured to transmit data between the transaction information confirming device and the data processing control module;
  • the data processing control module is configured to send part or all of the transaction information to the transaction information through the second interface module after receiving the transaction information of the transaction sent by the transaction terminal through the third interface module Confirmation device
  • the first interface module is connected to the second interface module and the control module, and is configured to transmit data between the electronic signature tool and the control module;
  • the display module is connected to the control module and configured to display information sent by the control module;
  • the control module is configured to send the transaction information to the display module for display after receiving the transaction information sent by the electronic signature tool by using the first interface module;
  • the data processing control module is further configured to: after receiving the confirmation transaction indication for confirming the transaction, generate signature data for completing the transaction, and send the generated signature data to the third interface module to Trading terminal.
  • the transaction information confirming device further includes: an input module;
  • the input module is configured to receive a confirmation transaction indication input by the user for confirming the transaction, and send the confirmation transaction instruction to the control module;
  • the control module is further configured to send, by the first interface module and the second interface module, the data processing control module after receiving the confirmation transaction indication.
  • the electronic signature tool further includes: a transaction confirmation module;
  • the transaction confirmation module is configured to receive a confirmation transaction indication input by the user for confirming the current transaction, and send the confirmation transaction instruction to the data processing control module.
  • the transaction information confirming device further includes: an input module;
  • the input module is configured to receive identity authentication information of the electronic signature tool input by a user, and send the same to the control module;
  • the control module is further configured to: after receiving the identity authentication information, send the data to the data processing control module by using the first interface module and the second interface module;
  • the data processing control module is further configured to verify the identity authentication information after receiving the identity verification information.
  • the transaction information confirming device further includes: an input module;
  • the input module is configured to receive a cancellation transaction indication that is cancelled by the user and is sent to the control module;
  • the control module is further configured to: after receiving the cancel transaction indication, send the data to the data processing control module by using the first interface module and the second interface module;
  • the data processing control module is further configured to send, by using the third interface module, a message for canceling the transaction by using the third interface module, if the cancel transaction indication is received before receiving the confirmation transaction indication.
  • the electronic signature tool further includes a transaction cancellation module
  • the transaction cancellation module is configured to receive a cancellation transaction indication that is cancelled by the user and is sent to the data processing control module;
  • the data processing control module is further configured to send, by using the third interface module, a message for canceling the transaction by using the third interface module, if the cancel transaction indication is received before receiving the confirmation transaction indication.
  • the electronic signature tool further includes a timer
  • the data processing control module is further configured to: after receiving the transaction information of the transaction sent by the transaction terminal, send an activation signal to the timer to start the timer;
  • the data processing control module is further configured to send, by using the third interface module, a message for canceling the transaction by using the third interface module, if the cancel transaction indication is received before receiving the confirmation transaction indication.
  • the transaction information confirming means is a dynamic password generating means or a mobile communication terminal.
  • the invention also provides an electronic signature tool, comprising: a data processing control module, and a third interface module, wherein:
  • the electronic signature tool further includes: a second interface module
  • the third interface module is connected to the transaction terminal and the data processing control module, and configured to transmit data between the transaction terminal and the data processing control module;
  • the second interface module is connected to the transaction information confirming device and the data processing control module, and configured to transmit data between the transaction information confirming device and the data processing control module;
  • the data processing control module is configured to send part or all of the transaction information to the transaction information confirming device through the second interface module after receiving the transaction information of the transaction sent by the transaction terminal through the third interface module Display
  • the data processing control module is further configured to generate signature data for completing the transaction, and send the generated signature data to the third interface module.
  • Trading terminal After receiving the confirmation transaction indication for confirming the transaction, the data processing control module is further configured to generate signature data for completing the transaction, and send the generated signature data to the third interface module. Trading terminal.
  • the electronic signature tool further includes: a transaction confirmation module;
  • the transaction confirmation module is configured to receive a confirmation transaction indication input by the user for confirming the current transaction, and send the confirmation transaction instruction to the data processing control module.
  • the electronic signature tool further includes a transaction cancellation module
  • the transaction cancellation module is configured to receive a cancellation transaction indication that is cancelled by the user and is sent to the data processing control module;
  • the data processing control module is further configured to send, by using the third interface module, a message for canceling the transaction by using the third interface module, if the cancel transaction indication is received before receiving the confirmation transaction indication.
  • the electronic signature tool further includes a timer
  • the data processing control module is further configured to: after receiving the transaction information of the transaction sent by the transaction terminal, send an activation signal to the timer to start the timer;
  • the timer is configured to send a cancel transaction indication to the data processing control module after it is full;
  • the data processing control module is further configured to send, by using the third interface module, a message for canceling the transaction by using the third interface module, if the cancel transaction indication is received before receiving the confirmation transaction indication.
  • the invention also provides a transaction information confirming device, characterized in that the device comprises: a first interface module, a control module, a display module;
  • the first interface module is connected to the electronic signature tool and the control module, and configured to transmit data between the electronic signature tool and the control module;
  • the display module is connected to the control module and configured to display information sent by the control module;
  • the control module is configured to send the transaction information to the display module for display after receiving the transaction information sent by the electronic signature tool by using the first interface module.
  • the transaction information confirming device further includes: an input module;
  • the input module is configured to receive a confirmation transaction indication input by the user for confirming the transaction, and send the confirmation transaction instruction to the control module;
  • the control module is further configured to send the acknowledgement transaction indication to the electronic signature tool by using the first interface module.
  • the transaction information confirming device further includes: an input module;
  • the input module is configured to receive identity authentication information of an electronic signature tool input by a user, and send the same to the control module;
  • the control module is further configured to send the identity authentication information to the electronic signature tool for verification by using the first interface module.
  • the transaction information confirming device further includes: an input module;
  • the control module is further configured to send the canceled transaction indication to the electronic signature tool by using the first interface module.
  • the transaction information confirming means is a dynamic password generating means or a mobile communication terminal.
  • the present invention uses the display screen provided in the transaction information confirming device (for example, the dynamic password generating device or the mobile communication terminal) to display the transaction information
  • the input set in the transaction information confirming device can also be used.
  • the module keyboard, touch screen, etc.
  • the button reduces the cost of the electronic signature tool and increases the portability of the electronic signature tool.
  • FIG. 1 is a schematic structural view of a first embodiment of an electronic signature system of the present invention
  • FIG. 2 is a flow chart of a first embodiment of an electronic signature method of the present invention
  • FIG. 3 is a schematic structural diagram of a second embodiment of an electronic signature system of the present invention.
  • FIG. 5 is a schematic structural diagram of a third embodiment of an electronic signature system of the present invention.
  • Figure 6 is a block diagram showing the structure of a fourth embodiment of the electronic signature system of the present invention.
  • the core of the present invention is to connect a transaction information confirming device (for example, a dynamic password generating device or a mobile communication terminal) provided with a display screen or provided with a display screen and a button, and the electronic signature tool is to be confirmed.
  • the transaction information is sent to the transaction information confirmation device for display.
  • the electronic signature tool receives the confirmation transaction instruction and generates the transaction. Complete the signature data for this transaction.
  • the transaction information confirming apparatus in this embodiment is a dynamic password generating apparatus (for example, an OTP token).
  • the electronic signature system is connected to a transaction terminal, and includes: an electronic signature tool, and a dynamic password generation device; wherein:
  • the electronic signature tool includes: a third interface module, a second interface module, and a data processing control module.
  • the third interface module is connected to the transaction terminal (for example, a personal computer) for transmitting the transaction information sent by the transaction terminal to the data processing control module.
  • the transaction terminal for example, a personal computer
  • the third interface module described above may be a USB interface.
  • a second interface module connected to the first interface module in the data processing control module and the dynamic password generating device, configured to send the transaction information received from the data processing control module to the first interface module, and from the first interface module
  • the received confirmation transaction indication or cancellation transaction indication is sent to the data processing control module.
  • the second interface module is further configured to send the user identity authentication request received from the data processing control module to the first interface module, and send the user identity authentication response received from the first interface module to the data processing control module.
  • the above second interface module can adopt an I2C interface.
  • a data processing control module configured to send the transaction information received by the third interface module to the dynamic password generating device by using the second interface module; after receiving the confirmation transaction indication by using the second interface module, generating the signature by using the current transaction information Data, and the generated signature data is sent to the transaction terminal through the third interface module to complete the transaction; after receiving the cancellation transaction indication through the second interface module, sending a message to the transaction terminal through the third interface module to cancel the current transaction.
  • the data processing control module may also be used to record the current state of the electronic signature tool (the initial state of the electronic signature tool is an unusable state); when the data processing control module passes the second
  • the interface module sends a user identity authentication request to the dynamic password generating device, and after receiving the user identity authentication response through the second interface module, the identity authentication information included in the user identity authentication response is verified, and the electronic signature tool is verified after the verification is successful.
  • the current status is marked as usable. That is to say, if the function of authenticating the identity of the user of the electronic signature tool is added, the data processing control module can perform the operations of generating the signature data and the like only when the current state of the electronic signature tool is in the usable state.
  • the dynamic password generating device includes: a first interface module, a control module, a password generating module, a display module (display screen), an input module, and a power module.
  • the first interface module is connected to the second interface module of the electronic signature tool, and is configured to send the transaction information received by the second interface module to the control module, and send the confirmation transaction indication or the cancellation transaction indication sent by the control module to the electronic The second interface module of the signature tool.
  • the first interface module is further configured to send the user identity authentication request received by the second interface module to the control module, and send the user identity authentication response sent by the control module to the second interface module of the electronic signature tool.
  • the first interface module may be an I2C interface.
  • the control module is connected to the first interface module, the input module and the display module, and is configured to send the transaction information received by the first interface module to the display module for display; and receive the page turning/turning screen and the like through the input module.
  • the display module controls the display operation of the page turning/turning of the transaction information; after receiving the button signal for confirming the transaction information through the input module (ie, the user confirms the transaction instruction), The confirmation transaction indication is sent to the electronic signature tool by the first interface module; after receiving the button signal of the cancellation operation (ie, the user cancels the transaction indication) through the input module, the cancellation instruction is sent to the electronic signature tool by the first interface module.
  • control module is further configured to: after receiving the user identity authentication request sent by the first interface module, send a control signal to the display module to display the prompt information, prompting the user to input the identity authentication information; and receiving the user input through the input module.
  • the identity authentication information is included in the user identity authentication response and sent to the electronic signature tool through the first interface module.
  • the password generating module is configured to generate a dynamic password, and send the generated dynamic password to the control module.
  • the control module is further configured to send the dynamic password sent by the password generating module to the display module for display.
  • the power module is used to supply power to each module of the dynamic password generating device, and can implement a power storage function and a data line power taking function, that is, connected to the first interface module, and obtains electric energy from the first interface module and stores the power.
  • FIG. 2 is a flow chart of a first embodiment of the electronic signature method of the present invention. As shown in FIG. 2, the method includes the following steps:
  • the electronic signature tool of the electronic signature system After the electronic signature tool of the electronic signature system is connected to the dynamic password generating device, the electronic signature tool sends a user identity authentication request to the dynamic password generating device.
  • the dynamic password generating apparatus After receiving the user identity authentication request, the dynamic password generating apparatus displays a prompt message on the display screen thereof to prompt the user to input the identity authentication information.
  • the above identity authentication information may be a user password such as a PIN code.
  • the dynamic password generating apparatus sends the identity authentication information (for example, a PIN code) input by the user to the electronic signature tool in the user identity authentication response.
  • identity authentication information for example, a PIN code
  • the electronic signature tool verifies the received identity authentication information, and after the verification succeeds, marking the current state as a usable state, and performing subsequent operations of generating an electronic signature.
  • sending the user identity authentication request to the dynamic password generating device is an optional step; in other embodiments of the present invention, the dynamic password generating device may display a prompt after detecting that it is connected with the electronic signature tool to prompt The user enters the authentication information without waiting to receive the user identity authentication request.
  • the technique for detecting whether two devices are connected is a prior art, and will not be described in detail herein.
  • the transaction terminal After the user connects the electronic signature tool of the electronic signature system with the transaction terminal (for example, a personal computer), the transaction terminal receives the transaction instruction and the transaction information input by the user, and generates a corresponding transaction message according to the transaction information, and sends the corresponding transaction message to the transaction message.
  • the transaction terminal receives the transaction instruction and the transaction information input by the user, and generates a corresponding transaction message according to the transaction information, and sends the corresponding transaction message to the transaction message.
  • Electronic signature tool for example, a personal computer
  • the electronic signature tool determines whether the current status is in a usable state. If yes, part or all of the transaction information (which may be referred to as to-be-confirmed transaction information) extracted from the transaction message is sent to the dynamic password generation connected thereto. Device.
  • the dynamic password generating device After receiving the transaction information to be confirmed sent by the electronic signature tool, the dynamic password generating device displays the information to be confirmed on the display screen for the user to browse and confirm;
  • the user can use the input module (for example, up and down buttons, etc.) set on the dynamic password generating device to perform browsing operations of transaction information such as page up and page down.
  • the input module for example, up and down buttons, etc.
  • the confirmation transaction operation is performed by an input module (for example, a confirmation button) of the dynamic password generation device (ie, the user sends a confirmation transaction indication through the input module);
  • the cancel transaction operation is performed by the input module of the dynamic password generation device (eg, the cancel button) (ie, the user sends a cancellation transaction indication through the input module).
  • the input module of the dynamic password generation device eg, the cancel button
  • the dynamic password generation device After the user performs the confirmation transaction operation (ie, after the user presses the confirmation button), the dynamic password generation device sends a confirmation transaction indication to the electronic signature tool;
  • the dynamic password generation device After the user performs the cancel transaction operation (ie, after the user presses the cancel button), the dynamic password generation device sends a cancel transaction indication to the electronic signature tool.
  • the electronic signature tool After receiving the confirmation transaction indication sent by the dynamic password generating apparatus, the electronic signature tool generates signature data by using the current transaction information, and sends the generated signature data to the transaction terminal to complete the transaction.
  • the electronic signature tool After receiving the cancellation transaction indication sent by the dynamic password generating device, the electronic signature tool sends a message to the transaction terminal to cancel the transaction.
  • FIG. 3 is a schematic structural diagram of a second embodiment of the electronic signature system of the present invention.
  • the transaction information confirming apparatus in this embodiment is a dynamic password generating apparatus (for example, an OTP token).
  • the difference between the second embodiment of the electronic signature system shown in FIG. 3 and the first embodiment shown in FIG. 1 is that a transaction confirmation module is added to the electronic signature tool, and thus is in the dynamic password generation apparatus in the first embodiment.
  • the operation of confirming the transaction by the input module is completed by the transaction confirmation module in the second embodiment.
  • the transaction confirmation module may perform confirmation of the transaction information, that is, the transaction confirmation module sends a confirmation transaction instruction to the data processing control module; After receiving the confirmation transaction indication, the data processing control module generates signature data using the current transaction information, and sends the generated signature data to the transaction terminal through the third interface module to complete the transaction.
  • the above transaction confirmation module may be a button, a touch screen, or a biometric switch.
  • the transaction cancellation module may be included in the electronic signature tool, and thus the operation of canceling the transaction by the input module in the dynamic password generation device in the first embodiment is performed by the transaction cancellation module in the second embodiment.
  • the current transaction may be cancelled by the transaction cancellation module, that is, the transaction cancellation module sends the data to the data processing control module.
  • the transaction instruction module cancels the transaction indication; after receiving the cancellation transaction indication, the data processing control module sends a message to the transaction terminal through the third interface module to cancel the transaction.
  • the above transaction cancellation module can be a button or a touch screen.
  • the transaction cancellation module is an optional module.
  • the user can perform the operation of canceling the transaction in the transaction terminal.
  • FIG. 4 is a flow chart of a second embodiment of the electronic signature method of the present invention. As shown in FIG. 4, the method includes the following steps:
  • steps 201 to 204 are the same as steps 201 to 204.
  • steps 205 to 207 are the same as steps 205 to 207.
  • the transaction confirmation module eg, a confirmation button of the electronic signature tool performs a confirmation transaction operation (ie, the user sends a confirmation transaction indication through the transaction confirmation module);
  • the transaction cancellation module eg, cancel button
  • the electronic signature tool ie, the user cancels the transaction indication by the transaction cancellation module.
  • the electronic signature tool after the user performs the confirmation transaction operation (for example, the user presses the confirmation button), the electronic signature tool generates signature data using the current transaction information, and sends the generated signature data to the transaction terminal to complete the transaction;
  • the dynamic password generation device After the user performs the cancel transaction operation (ie, after the user presses the cancel button), the dynamic password generation device sends a cancel transaction indication to the electronic signature tool.
  • the transaction cancellation module in the electronic signature tool may be a timer. After receiving the transaction information sent by the transaction terminal, the data processing control module of the electronic signature tool sends a start signal to the timer to start the timer; After counting (ie, timeout), sending a timeout signal (cancelling the transaction indication) to the data processing control module; if the data processing control module does not receive the confirmation transaction indication sent by the transaction confirmation module before receiving the timeout signal sent by the timer, The third interface module sends a message to the transaction terminal to cancel the transaction.
  • FIG. 5 is a schematic structural diagram of a third embodiment of an electronic signature system according to the present invention.
  • the transaction information confirming apparatus in this embodiment is a mobile communication terminal (for example, a mobile phone).
  • the difference between the third embodiment of the electronic signature system shown in FIG. 5 and the first embodiment shown in FIG. 1 is that the transaction information confirming device is a mobile communication terminal, and thus the password generating module in FIG. 1 may not be included; The power module is not shown in 5.
  • the first interface module and the second interface module in the electronic signature system shown in FIG. 5 may be a USB interface, or may be an infrared interface, a Bluetooth interface, or an I2C interface.
  • FIG. 6 is a schematic structural diagram of a fourth embodiment of an electronic signature system according to the present invention.
  • the transaction information confirming apparatus in this embodiment is a mobile communication terminal (for example, a mobile phone).
  • the difference between the fourth embodiment of the electronic signature system shown in FIG. 6 and the second embodiment shown in FIG. 3 is that the transaction information confirming device is a mobile communication terminal, and thus the password generating module in FIG. 3 may not be included; The power module is not shown in 6.
  • the first interface module and the second interface module in the electronic signature system shown in FIG. 6 may be a USB interface, or may be an infrared interface, a Bluetooth interface, or an I2C interface.
  • the present invention uses the display screen provided in the transaction information confirming device (for example, the dynamic password generating device or the mobile communication terminal) to display the transaction information
  • the input set in the transaction information confirming device can also be used.
  • the module keyboard, touch screen, etc.
  • the button reduces the cost of the electronic signature tool and increases the portability of the electronic signature tool.

Abstract

一种交易信息确认装置、电子签名工具及系统、电子签名方法,所述方法包括:电子签名工具接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息发送给与其相连的交易信息确认装置;交易信息确认装置接收到电子签名工具发送的交易信息后,将其显示在交易信息确认装置的显示屏上供用户对本次交易进行确认;接收到对本次交易进行确认的确认交易指示后,电子签名工具使用部分或全部交易信息生成用于完成本次交易的签名数据,并将生成的签名数据发送给交易终端。由于本发明使用设置在交易信息确认装置的显示屏进行交易信息的显示,因此无需在电子签名工具中设置显示模块,降低了电子签名工具的成本,增加了电子签名工具的便携性。

Description

交易信息确认装置、电子签名工具及系统、电子签名方法
技术领域
本发明涉及信息安全领域,尤其涉及一种交易信息确认装置、电子签名工具及系统、电子签名方法。
背景技术
目前,电子签名工具的应用越来越广泛,特别是在金融领域,为了保证交易的安全性,网上银行的用户越来越多地使用电子签名工具,例如,通过USB(Universal Serial Bus,通用串行总线)接口与交易终端(通常为个人计算机)相连的USB Key等,作为身份认证和交易认证的工具。
为了进一步保障电子交易的安全性,通常要求电子签名工具具有显示功能,即将当前交易中的一些比较重要的交易信息以文字形式通过设置于电子签名工具上的显示屏显示给用户,供用户在对本次交易进行确认前进行参考。
由于上述电子签名工具中设置有显示屏和按键,因此成本较高,体积/尺寸较大,不便于携带,尤其是当用户是多个银行的客户,需要携带多个银行的电子签名工具时,现有的电子签名工具在成本和便携性方面的弊端尤其明显。
发明内容
本发明所要解决的技术问题是,克服现有技术的不足,提供一种电子签名工具、可以与上述电子签名工具配合使用的交易信息确认装置,由上述电子签名工具和交易信息确认装置构成的电子签名系统,以及相应的电子签名方法,在不牺牲电子签名工具安全性的前提下提高电子签名工具的便携性。
为了解决上述问题,本发明提供一种电子签名方法,其特征在于,
电子签名工具接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息发送给与其相连的交易信息确认装置;
交易信息确认装置接收到电子签名工具发送的交易信息后,将其显示在交易信息确认装置的显示屏上供用户对本次交易进行确认;
接收到对本次交易进行确认的确认交易指示后,电子签名工具使用部分或全部交易信息生成用于完成本次交易的签名数据,并将生成的签名数据发送给交易终端。
此外,采用如下方式接收所述对本次交易进行确认的确认交易指示:
设置在交易信息确认装置中的输入模块接收用户输入的对本次交易进行确认的确认交易指示;接收到该确认交易指示后,交易信息确认装置向电子签名工具发送对本次交易进行确认的确认交易指示。
此外,采用如下方式接收所述对本次交易进行确认的确认交易指示:
设置在电子签名工具中的交易确认模块接收用户输入的对本次交易进行确认的确认交易指示。
此外,交易信息确认装置接收到电子签名工具发送的交易信息前,还包含如下步骤:
交易信息确认装置接收用户输入的电子签名工具的身份认证信息,并将所述身份认证信息发送给电子签名工具;
电子签名工具接收到所述身份认证信息后,对所述身份认证信息进行验证。
本发明还提供一种电子签名系统,与交易终端相连,包括:电子签名工具,其特征在于,该系统还包含:与所述电子签名工具相连的交易信息确认装置;其中:
所述电子签名工具中包含:数据处理控制模块,第二接口模块,第三接口模块;
所述交易信息确认装置中包含:第一接口模块,控制模块,显示模块;
所述第三接口模块,与交易终端和所述数据处理控制模块相连,用于在交易终端与所述数据处理控制模块之间传输数据;
所述第二接口模块,与所述第一接口模块和数据处理控制模块相连,用于在所述交易信息确认装置和数据处理控制模块之间传输数据;
所述数据处理控制模块,用于在通过所述第三接口模块接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息通过所述第二接口模块发送给所述交易信息确认装置;
所述第一接口模块,与所述第二接口模块和所述控制模块相连,用于在所述电子签名工具与所述控制模块之间传输数据;
所述显示模块,与所述控制模块相连,用于显示所述控制模块发送的信息;
所述控制模块,用于在通过所述第一接口模块接收到所述电子签名工具发送的交易信息后,将所述交易信息发送给所述显示模块进行显示;
所述数据处理控制模块还用于在接收到对本次交易进行确认的确认交易指示后,生成用于完成本次交易的签名数据,并通过所述第三接口模块将生成的签名数据发送给交易终端。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述确认交易指示后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块。
此外,所述电子签名工具中还包含:交易确认模块;
所述交易确认模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述数据处理控制模块。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的所述电子签名工具的身份认证信息,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述身份认证信息后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块;
所述数据处理控制模块还用于在接收到所述身份认证信息后,对其进行验证。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述取消交易指示后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块;
如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
此外,所述电子签名工具中还包含交易取消模块;
所述交易取消模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述数据处理控制模块;
如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
此外,所述电子签名工具中还包含定时器;
所述数据处理控制模块还用于在接收到交易终端发送的本次交易的交易信息后,向所述定时器发送启动信号,以启动所述定时器;
所述定时器用于在其计满后向所述数据处理控制模块发送取消交易指示;
如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
此外,所述交易信息确认装置为:动态口令生成装置、或移动通信终端。
本发明还提供一种电子签名工具,包含:数据处理控制模块,第三接口模块,其特征在于:
所述电子签名工具中还包含:第二接口模块;
所述第三接口模块,与交易终端和所述数据处理控制模块相连,用于在交易终端与所述数据处理控制模块之间传输数据;
所述第二接口模块,与交易信息确认装置和所述数据处理控制模块相连,用于在交易信息确认装置和所述数据处理控制模块之间传输数据;
所述数据处理控制模块,用于在通过所述第三接口模块接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息通过所述第二接口模块发送给交易信息确认装置进行显示;
在接收到对本次交易进行确认的确认交易指示后,所述数据处理控制模块还用于生成用于完成本次交易的签名数据,并通过所述第三接口模块将生成的签名数据发送给交易终端。
此外,所述电子签名工具中还包含:交易确认模块;
所述交易确认模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述数据处理控制模块。
此外,所述电子签名工具中还包含交易取消模块;
所述交易取消模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述数据处理控制模块;
如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
此外,所述电子签名工具中还包含定时器;
所述数据处理控制模块还用于在接收到交易终端发送的本次交易的交易信息后,向所述定时器发送启动信号,以启动所述定时器;
所述定时器用于在其计满后向所述数据处理控制模块发送取消交易指示;
如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
本发明还提供一种交易信息确认装置,其特征在于,装置中包含:第一接口模块,控制模块,显示模块;
所述第一接口模块,与电子签名工具和所述控制模块相连,用于在电子签名工具与所述控制模块之间传输数据;
所述显示模块,与所述控制模块相连,用于显示所述控制模块发送的信息;
所述控制模块,用于在通过所述第一接口模块接收到电子签名工具发送的交易信息后,将所述交易信息发送给所述显示模块进行显示。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述确认交易指示后,通过所述第一接口模块将其发送给电子签名工具。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的电子签名工具的身份认证信息,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述身份认证信息后,通过所述第一接口模块将其发送给电子签名工具进行验证。
此外,所述交易信息确认装置中还包含:输入模块;
所述输入模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述控制模块;
所述控制模块还用于在接收到所述取消交易指示后,通过所述第一接口模块将其发送给电子签名工具。
此外,所述交易信息确认装置为:动态口令生成装置、或移动通信终端。
综上所述,由于本发明使用设置在交易信息确认装置(例如,动态口令生成装置、或移动通信终端)中的显示屏进行交易信息的显示,还可以使用设置在交易信息确认装置中的输入模块(键盘、触摸屏等)进行交易的确认和取消,因此在不降低交易安全性的前提下,既无需在电子签名工具中设置显示模块(显示屏),也可以不设置按键或仅设置少量的按键,降低了电子签名工具的成本,增加了电子签名工具的便携性。
附图概述
图1是本发明电子签名系统第一实施例的结构示意图;
图2是本发明电子签名方法第一实施例的流程图;
图3是本发明电子签名系统第二实施例的结构示意图;
图4是本发明电子签名方法第二实施例的流程图;
图5是本发明电子签名系统第三实施例的结构示意图;
图6是本发明电子签名系统第四实施例的结构示意图。
本发明的较佳实施方式
本发明的核心是,将设置有显示屏、或设置有显示屏和按键的交易信息确认装置(例如,动态口令生成装置、或移动通信终端)与电子签名工具连接,电子签名工具将待确认的交易信息发送给交易信息确认装置进行显示,用户确认交易信息无误后,通过交易信息确认装置或电子签名工具中设置的按键对本次交易进行确认,电子签名工具接收到确认交易指示后,生成用于完成本次交易的签名数据。
下面将结合附图和实施例对本发明进行详细描述。
第一实施例
图1是本发明电子签名系统第一实施例的结构示意图;本实施例中的交易信息确认装置为动态口令生成装置(例如,OTP令牌)。
如图1所示,该电子签名系统与交易终端相连,包含:电子签名工具,动态口令生成装置;其中:
电子签名工具中包含:第三接口模块,第二接口模块,数据处理控制模块。
第三接口模块,与交易终端(例如,个人电脑)相连,用于将交易终端发送的交易信息发送给数据处理控制模块。
上述第三接口模块可以是USB接口。
第二接口模块,与数据处理控制模块和动态口令生成装置中的第一接口模块相连,用于将从数据处理控制模块接收到的交易信息发送给第一接口模块,并将从第一接口模块接收到的确认交易指示或取消交易指示发送给数据处理控制模块。
此外,第二接口模块还用于将从数据处理控制模块接收到的用户身份认证请求发送给第一接口模块,并将从第一接口模块接收到的用户身份认证应答发送给数据处理控制模块。
上述第二接口模块可以采用I2C接口。
数据处理控制模块,用于将通过第三接口模块接收到的交易信息通过第二接口模块发送给动态口令生成装置;在通过第二接口模块接收到确认交易指示后,使用当前的交易信息生成签名数据,并将生成的签名数据通过第三接口模块发送给交易终端以完成本次交易;在通过第二接口模块接收到取消交易指示后,通过第三接口模块向交易终端发送消息以取消本次交易。
此外,为了对电子签名工具的使用者身份进行认证,数据处理控制模块还可以用于记录电子签名工具的当前状态(电子签名工具的初始状态为不可使用状态);当数据处理控制模块通过第二接口模块向动态口令生成装置发送用户身份认证请求,并在通过第二接口模块接收到用户身份认证应答后,对用户身份认证应答中包含的身份认证信息进行验证,验证成功后将电子签名工具的当前的状态标记为可使用状态。也就是说,如果增加了对电子签名工具的使用者身份进行认证的功能,则只有在电子签名工具的当前状态为可使用状态时,数据处理控制模块才可以执行上述生成签名数据等操作。
动态口令生成装置中包含:第一接口模块,控制模块,口令生成模块,显示模块(显示屏),输入模块,电源模块。
第一接口模块,与电子签名工具的第二接口模块相连,用于将通过第二接口模块接收到的交易信息发送给控制模块,并将控制模块发送的确认交易指示或取消交易指示发送给电子签名工具的第二接口模块。
此外,第一接口模块还用于将通过第二接口模块接收到的用户身份认证请求发送给控制模块,将控制模块发送的用户身份认证应答发送给电子签名工具的第二接口模块。
上述第一接口模块可以是I2C接口。
控制模块,与第一接口模块、输入模块和显示模块相连,用于将通过第一接口模块接收到的交易信息发送给显示模块进行显示;在通过输入模块接收到翻页/翻屏等对交易信息进行浏览操作的按键信号后,控制显示模块进行交易信息的翻页/翻屏等显示操作;在通过输入模块接收到对交易信息进行确认操作的按键信号(即用户的确认交易指示)后,通过第一接口模块向电子签名工具发送确认交易指示;在通过输入模块接收到取消操作的按键信号(即用户的取消交易指示)后,通过第一接口模块向电子签名工具发送取消交易指示。
此外,控制模块还用于在接收到第一接口模块发送的用户身份认证请求后,通过向显示模块发送控制信号以显示提示信息,提示用户输入身份认证信息;在通过输入模块接收到用户输入的身份认证信息后,将身份认证信息包含在用户身份认证应答中通过第一接口模块发送给电子签名工具。
口令生成模块,用于生成动态口令,并将生成的动态口令发送给控制模块;控制模块还用于将口令生成模块发送的动态口令发送给显示模块进行显示。
电源模块用于为动态口令生成装置的各模块提供电源,并可以实现电源储存功能和数据线取电功能,即与第一接口模块相连,从第一接口模块中获取电能并储存电能。
上述电子签名系统的具体功能在下文中详细描述。
图2是本发明电子签名方法第一实施例的流程图。如图2所示,该方法包括如下步骤:
电子签名工具用户认证:
201,电子签名系统的电子签名工具与动态口令生成装置相连后,电子签名工具向动态口令生成装置发送用户身份认证请求。
202,接收到用户身份认证请求后,动态口令生成装置在其显示屏上显示提示信息,以提示用户输入身份认证信息;
上述身份认证信息可以是PIN码等用户密码。
203,动态口令生成装置将用户输入的身份认证信息(例如,PIN码)包含在用户身份认证应答中发送给电子签名工具。
204,电子签名工具对接收到的身份认证信息进行验证,验证成功后将当前的状态标记为可使用状态,即可执行后续的生成电子签名的操作。
需要注意的是,向动态口令生成装置发送用户身份认证请求为可选步骤;在本发明的其它实施例中,动态口令生成装置可以在检测到其与电子签名工具连接后即显示提示,以提示用户输入身份认证信息,无需等待接收到用户身份认证请求。检测两个设备是否已连接的技术为现有技术,本文不再赘述。
电子签名生成:
205,用户将电子签名系统的电子签名工具与交易终端(例如,个人电脑)相连后,交易终端接收用户输入的交易指令及交易信息,并根据交易信息生成相应的交易报文,将其发送给电子签名工具。
206,电子签名工具判断当前的状态是否为可使用状态,如果是,则将从交易报文中提取出的部分或全部交易信息(可以称为待确认交易信息)发送给与其相连的动态口令生成装置。
207,动态口令生成装置接收到电子签名工具发送的待确认交易信息后,将其显示在显示屏上,以便用户进行浏览和确认;
用户可以使用动态口令生成装置上设置的输入模块(例如,向上、向下按键等)进行向上翻页、向下翻页等交易信息的浏览操作。
208,如果用户确认当前显示的待确认交易信息正确,则通过动态口令生成装置的输入模块(例如,确认按键)进行确认交易操作(即用户通过输入模块发送确认交易指示);
如果用户判定当前显示的待确认交易信息不正确、或希望取消当前交易,则通过动态口令生成装置的输入模块(例如,取消按键)进行取消交易操作(即用户通过输入模块发送取消交易指示)。
209,用户执行确认交易操作后(即用户按下确认按键后),动态口令生成装置向电子签名工具发送确认交易指示;
用户执行取消交易操作后(即用户按下取消按键后),动态口令生成装置向电子签名工具发送取消交易指示。
210,接收到动态口令生成装置发送的确认交易指示后,电子签名工具使用当前的交易信息生成签名数据,并将生成的签名数据发送给交易终端以完成本次交易;
接收到动态口令生成装置发送的取消交易指示后,电子签名工具向交易终端发送消息以取消本次交易。
根据交易信息生成签名数据的具体方法为现有技术,本文不再赘述。
第二实施例
图3是本发明电子签名系统第二实施例的结构示意图;本实施例中的交易信息确认装置为动态口令生成装置(例如,OTP令牌)。
图3所示的电子签名系统第二实施例与图1所示的第一实施例的区别是:在电子签名工具中增加了交易确认模块,因此在第一实施例中由动态口令生成装置中的输入模块完成的对交易进行确认的操作在第二实施例中由交易确认模块完成。
具体地说,用户通过动态口令生成装置的显示屏浏览交易信息,并确认交易信息无误后,可以通过交易确认模块进行交易信息的确认,即通过交易确认模块向数据处理控制模块发送确认交易指示;数据处理控制模块接收到确认交易指示后,使用当前的交易信息生成签名数据,并将生成的签名数据通过第三接口模块发送给交易终端以完成本次交易。
上述交易确认模块可以是按键、触摸屏、生物特征识别开关。
此外,电子签名工具中还可以包含交易取消模块,因此在第一实施例中由动态口令生成装置中的输入模块完成的对交易进行取消的操作在第二实施例中由交易取消模块完成。
具体地说,用户通过动态口令生成装置的显示屏浏览交易信息,并判定交易信息错误、或需要取消当前交易时,可以通过交易取消模块取消当前交易,即通过交易取消模块向数据处理控制模块发送取消交易指示;数据处理控制模块接收到取消交易指示后,通过第三接口模块向交易终端发送消息以取消本次交易。
上述交易取消模块可以是按键、触摸屏。
需要注意的是交易取消模块是可选模块,在本发明的其它实施例中,用户可以在交易终端中执行取消交易的操作。
图3所示的电子签名系统的其它各模块的功能与图1所示的电子签名系统相同,不再赘述。
图4是本发明电子签名方法第二实施例的流程图。如图4所示,该方法包括如下步骤:
电子签名工具用户认证:
401~404,与步骤201~204相同。
电子签名生成:
405~407,与步骤205~207相同。
408,如果用户确认当前显示的待确认交易信息正确,则通过电子签名工具的交易确认模块(例如,确认按键)进行确认交易操作(即用户通过交易确认模块发送确认交易指示);
如果用户判定当前显示的待确认交易信息不正确、或希望取消当前交易,则通过电子签名工具的交易取消模块(例如,取消按键)进行取消交易操作(即用户通过交易取消模块发送取消交易指示)。
409,用户执行确认交易操作后(例如,用户按下确认按键),电子签名工具使用当前的交易信息生成签名数据,并将生成的签名数据发送给交易终端以完成本次交易;
用户执行取消交易操作后(即用户按下取消按键后),动态口令生成装置向电子签名工具发送取消交易指示。
根据本发明的基本原理,还可以对图3和图4所示的第二实施例进行多种变换,例如:
在电子签名工具中的交易取消模块可以是一个定时器,当电子签名工具的数据处理控制模块接收到交易终端发送的交易信息后,向该定时器发送启动信号,以启动该定时器;定时器计满(即超时)后向数据处理控制模块发送超时信号(取消交易指示);如果数据处理控制模块在接收到定时器发送的超时信号前没有接收到交易确认模块发送的确认交易指示,则通过第三接口模块向交易终端发送消息以取消本次交易。
第三实施例
图5是本发明电子签名系统第三实施例的结构示意图;本实施例中的交易信息确认装置为移动通信终端(例如,手机)。
图5所示的电子签名系统第三实施例与图1所示的第一实施例的区别是:交易信息确认装置为移动通信终端,因此可以不包含图1中的口令生成模块;此外,图5中未示出电源模块。
图5所示的电子签名系统中的第一接口模块和第二接口模块可以是USB接口,也可以是红外接口、蓝牙接口或I2C接口。
图5所示的电子签名系统中的其它模块的功能及连接关系与图1所示的电子签名系统相同,不再赘述。
与图5所示的电子签名系统相对应的电子签名方法的具体流程与图2所示的流程相同,不再赘述。
第四实施例
图6是本发明电子签名系统第四实施例的结构示意图;本实施例中的交易信息确认装置为移动通信终端(例如,手机)。
图6所示的电子签名系统第四实施例与图3所示的第二实施例的区别是:交易信息确认装置为移动通信终端,因此可以不包含图3中的口令生成模块;此外,图6中未示出电源模块。
图6所示的电子签名系统中的第一接口模块和第二接口模块可以是USB接口,也可以是红外接口、蓝牙接口或I2C接口。
图6所示的电子签名系统中的其它模块的功能及连接关系与图3所示的电子签名系统相同,不再赘述。
与图6所示的电子签名系统相对应的电子签名方法的具体流程与图4所示的流程相同,不再赘述。
综上所述,由于本发明使用设置在交易信息确认装置(例如,动态口令生成装置、或移动通信终端)中的显示屏进行交易信息的显示,还可以使用设置在交易信息确认装置中的输入模块(键盘、触摸屏等)进行交易的确认和取消,因此在不降低交易安全性的前提下,既无需在电子签名工具中设置显示模块(显示屏),也可以不设置按键或仅设置少量的按键,降低了电子签名工具的成本,增加了电子签名工具的便携性。

Claims (21)

  1. 一种电子签名方法,其特征在于,
    电子签名工具接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息发送给与其相连的交易信息确认装置;
    交易信息确认装置接收到电子签名工具发送的交易信息后,将其显示在交易信息确认装置的显示屏上供用户对本次交易进行确认;
    接收到对本次交易进行确认的确认交易指示后,电子签名工具使用部分或全部交易信息生成用于完成本次交易的签名数据,并将生成的签名数据发送给交易终端。
  2. 如权利要求1所述的方法,其特征在于,
    采用如下方式接收所述对本次交易进行确认的确认交易指示:
    设置在交易信息确认装置中的输入模块接收用户输入的对本次交易进行确认的确认交易指示;接收到该确认交易指示后,交易信息确认装置向电子签名工具发送对本次交易进行确认的确认交易指示。
  3. 如权利要求1所述的方法,其特征在于,
    采用如下方式接收所述对本次交易进行确认的确认交易指示:
    设置在电子签名工具中的交易确认模块接收用户输入的对本次交易进行确认的确认交易指示。
  4. 如权利要求1至3中任一权利要求所述的方法,其特征在于,
    交易信息确认装置接收到电子签名工具发送的交易信息前,还包含如下步骤:
    交易信息确认装置接收用户输入的电子签名工具的身份认证信息,并将所述身份认证信息发送给电子签名工具;
    电子签名工具接收到所述身份认证信息后,对所述身份认证信息进行验证。
  5. 一种电子签名系统,与交易终端相连,包括:电子签名工具,其特征在于,该系统还包含:与所述电子签名工具相连的交易信息确认装置;其中:
    所述电子签名工具中包含:数据处理控制模块,第二接口模块,第三接口模块;
    所述交易信息确认装置中包含:第一接口模块,控制模块,显示模块;
    所述第三接口模块,与交易终端和所述数据处理控制模块相连,用于在交易终端与所述数据处理控制模块之间传输数据;
    所述第二接口模块,与所述第一接口模块和数据处理控制模块相连,用于在所述交易信息确认装置和数据处理控制模块之间传输数据;
    所述数据处理控制模块,用于在通过所述第三接口模块接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息通过所述第二接口模块发送给所述交易信息确认装置;
    所述第一接口模块,与所述第二接口模块和所述控制模块相连,用于在所述电子签名工具与所述控制模块之间传输数据;
    所述显示模块,与所述控制模块相连,用于显示所述控制模块发送的信息;
    所述控制模块,用于在通过所述第一接口模块接收到所述电子签名工具发送的交易信息后,将所述交易信息发送给所述显示模块进行显示;
    所述数据处理控制模块还用于在接收到对本次交易进行确认的确认交易指示后,生成用于完成本次交易的签名数据,并通过所述第三接口模块将生成的签名数据发送给交易终端。
  6. 如权利要求5所述的系统,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述确认交易指示后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块。
  7. 如权利要求5所述的系统,其特征在于,
    所述电子签名工具中还包含:交易确认模块;
    所述交易确认模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述数据处理控制模块。
  8. 如权利要求5所述的系统,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的所述电子签名工具的身份认证信息,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述身份认证信息后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块;
    所述数据处理控制模块还用于在接收到所述身份认证信息后,对其进行验证。
  9. 如权利要求5所述的系统,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述取消交易指示后,通过所述第一接口模块和第二接口模块将其发送给所述数据处理控制模块;
    如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
  10. 如权利要求5所述的系统,其特征在于,
    所述电子签名工具中还包含交易取消模块;
    所述交易取消模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述数据处理控制模块;
    如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
  11. 如权利要求5所述的系统,其特征在于,
    所述电子签名工具中还包含定时器;
    所述数据处理控制模块还用于在接收到交易终端发送的本次交易的交易信息后,向所述定时器发送启动信号,以启动所述定时器;
    所述定时器用于在其计满后向所述数据处理控制模块发送取消交易指示;
    如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
  12. 如权利要求5至11中任一权利要求所述的系统,其特征在于,
    所述交易信息确认装置为:动态口令生成装置、或移动通信终端。
  13. 一种电子签名工具,包含:数据处理控制模块,第三接口模块,其特征在于:
    所述电子签名工具中还包含:第二接口模块;
    所述第三接口模块,与交易终端和所述数据处理控制模块相连,用于在交易终端与所述数据处理控制模块之间传输数据;
    所述第二接口模块,与交易信息确认装置和所述数据处理控制模块相连,用于在交易信息确认装置和所述数据处理控制模块之间传输数据;
    所述数据处理控制模块,用于在通过所述第三接口模块接收到交易终端发送的本次交易的交易信息后,将部分或全部交易信息通过所述第二接口模块发送给交易信息确认装置进行显示;
    在接收到对本次交易进行确认的确认交易指示后,所述数据处理控制模块还用于生成用于完成本次交易的签名数据,并通过所述第三接口模块将生成的签名数据发送给交易终端。
  14. 如权利要求13所述的电子签名工具,其特征在于,
    所述电子签名工具中还包含:交易确认模块;
    所述交易确认模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述数据处理控制模块。
  15. 如权利要求13所述的电子签名工具,其特征在于,
    所述电子签名工具中还包含交易取消模块;
    所述交易取消模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述数据处理控制模块;
    如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
  16. 如权利要求13所述的电子签名工具,其特征在于,
    所述电子签名工具中还包含定时器;
    所述数据处理控制模块还用于在接收到交易终端发送的本次交易的交易信息后,向所述定时器发送启动信号,以启动所述定时器;
    所述定时器用于在其计满后向所述数据处理控制模块发送取消交易指示;
    如果接收到所述确认交易指示前接收到所述取消交易指示,所述数据处理控制模块还用于通过所述第三接口模块向交易终端发送用于取消本次交易的消息。
  17. 一种交易信息确认装置,其特征在于,装置中包含:第一接口模块,控制模块,显示模块;
    所述第一接口模块,与电子签名工具和所述控制模块相连,用于在电子签名工具与所述控制模块之间传输数据;
    所述显示模块,与所述控制模块相连,用于显示所述控制模块发送的信息;
    所述控制模块,用于在通过所述第一接口模块接收到电子签名工具发送的交易信息后,将所述交易信息发送给所述显示模块进行显示。
  18. 如权利要求17所述的装置,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的对本次交易进行确认的确认交易指示,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述确认交易指示后,通过所述第一接口模块将其发送给电子签名工具。
  19. 如权利要求17所述的装置,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的电子签名工具的身份认证信息,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述身份认证信息后,通过所述第一接口模块将其发送给电子签名工具进行验证。
  20. 如权利要求17所述的装置,其特征在于,
    所述交易信息确认装置中还包含:输入模块;
    所述输入模块,用于接收用户输入的取消本次交易的取消交易指示,并将其发送给所述控制模块;
    所述控制模块还用于在接收到所述取消交易指示后,通过所述第一接口模块将其发送给电子签名工具。
  21. 如权利要求17至20中任一权利要求所述的装置,其特征在于,
    所述交易信息确认装置为:动态口令生成装置、或移动通信终端。
PCT/CN2011/072714 2011-04-13 2011-04-13 交易信息确认装置、电子签名工具及系统、电子签名方法 WO2012139286A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/072714 WO2012139286A1 (zh) 2011-04-13 2011-04-13 交易信息确认装置、电子签名工具及系统、电子签名方法

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/072714 WO2012139286A1 (zh) 2011-04-13 2011-04-13 交易信息确认装置、电子签名工具及系统、电子签名方法

Publications (1)

Publication Number Publication Date
WO2012139286A1 true WO2012139286A1 (zh) 2012-10-18

Family

ID=47008790

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/072714 WO2012139286A1 (zh) 2011-04-13 2011-04-13 交易信息确认装置、电子签名工具及系统、电子签名方法

Country Status (1)

Country Link
WO (1) WO2012139286A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2916483A4 (en) * 2012-11-02 2016-07-13 Tendyron Corp TRANSACTION SYSTEM AND TRANSACTION METHOD

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101221641A (zh) * 2007-12-20 2008-07-16 魏恺言 一种联机交易的安全确认设备及联机交易方法
CN101540677A (zh) * 2009-04-30 2009-09-23 北京飞天诚信科技有限公司 签名方法、设备及系统
US20100122080A1 (en) * 2008-11-11 2010-05-13 Electronics And Telecommunications Research Institute Pseudonym certificate process system by splitting authority
CN201548998U (zh) * 2009-09-15 2010-08-11 中信银行股份有限公司 一种辅助实现USB Key安全性的装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101221641A (zh) * 2007-12-20 2008-07-16 魏恺言 一种联机交易的安全确认设备及联机交易方法
US20100122080A1 (en) * 2008-11-11 2010-05-13 Electronics And Telecommunications Research Institute Pseudonym certificate process system by splitting authority
CN101540677A (zh) * 2009-04-30 2009-09-23 北京飞天诚信科技有限公司 签名方法、设备及系统
CN201548998U (zh) * 2009-09-15 2010-08-11 中信银行股份有限公司 一种辅助实现USB Key安全性的装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2916483A4 (en) * 2012-11-02 2016-07-13 Tendyron Corp TRANSACTION SYSTEM AND TRANSACTION METHOD

Similar Documents

Publication Publication Date Title
WO2020171538A1 (en) Electronic device and method for providing digital signature service of block chain using the same
WO2018230875A1 (ko) 단말 및 그 제어 방법
WO2018076865A1 (zh) 数据分享方法、装置、存储介质及电子设备
WO2018076844A1 (zh) 数据备份的方法、装置、存储介质及电子设备
WO2018076443A1 (zh) 一种无卡取款的方法、装置和系统
WO2018076841A1 (zh) 数据分享方法、装置、存储介质及服务器
WO2019144738A1 (zh) 金融业务的验证方法、装置、设备和计算机存储介质
WO2010124565A1 (zh) 签名方法、设备及系统
WO2013004065A1 (zh) 一种基于图像采集的信息安全方法及系统
WO2018035930A1 (zh) 一种系统解锁方法和设备
WO2015041401A1 (ko) 근거리 무선 통신 기능을 가지는 이동통신단말기를 이용한 일회용 패스워드 무선 인증 시스템 및 방법
WO2019006788A1 (zh) 基于步态的支付方法、可穿戴设备及计算机可读存储介质
WO2017012433A1 (zh) 一种智能移动pos机与支付系统
WO2020091525A1 (ko) 생체 인증을 이용한 결제 방법 및 그 전자 장치
WO2018034491A1 (en) A primary device, an accessory device, and methods for processing operations on the primary device and the accessory device
WO2017071326A1 (zh) 一种终端的控制方法、装置和系统
WO2020103275A1 (zh) 扣款控制方法、装置、设备及可读存储介质
WO2014042476A1 (ko) 지문을 이용한 파일 관리 방법, 사용자 단말기 및 기록 매체
WO2018076881A1 (zh) 数据同步方法、装置、存储介质及服务器
WO2020171608A1 (en) Electronic device for providing handwriting input function and method of operating the same
WO2017016272A1 (zh) 一种虚拟资源数据的处理方法、装置及系统
WO2017222204A1 (ko) 화상 형성 장치, 모바일 단말 및 그 장치들의 로컬 로그인 처리 방법
WO2017206881A1 (zh) 一种关联应用的处理方法、装置、存储介质及电子设备
WO2017067282A1 (zh) 一种指纹信息的使用方法、装置及终端
WO2012139286A1 (zh) 交易信息确认装置、电子签名工具及系统、电子签名方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11863402

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11863402

Country of ref document: EP

Kind code of ref document: A1