WO2012155644A1 - 账单代付管理方法、装置及系统 - Google Patents

账单代付管理方法、装置及系统 Download PDF

Info

Publication number
WO2012155644A1
WO2012155644A1 PCT/CN2012/072562 CN2012072562W WO2012155644A1 WO 2012155644 A1 WO2012155644 A1 WO 2012155644A1 CN 2012072562 W CN2012072562 W CN 2012072562W WO 2012155644 A1 WO2012155644 A1 WO 2012155644A1
Authority
WO
WIPO (PCT)
Prior art keywords
payment
stk
bill
billing
information
Prior art date
Application number
PCT/CN2012/072562
Other languages
English (en)
French (fr)
Inventor
李良熹
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2012155644A1 publication Critical patent/WO2012155644A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/14Payment architectures specially adapted for billing systems

Definitions

  • the invention relates to the field of bill payment, and in particular relates to a bill payment management method, device and system. Background technique
  • Mobile bill payment is a new type of payment method introduced by mobile operators after card payment and network payment. After ordering the product, the user pays the bill delivered to the mobile phone, making full use of the popularity and portability of the mobile phone.
  • Mobile bills are generally divided into SMS bills, MMS bills, and user identification application development tools.
  • STK SIM Tool Kit
  • SMS or MMS bills are used, the risk of counterfeiting bills and phishing messages is prone to occur because the information is transmitted in clear code.
  • the service provider issues a payment bill to the user's mobile phone through the operator;
  • the user's mobile phone decrypts the bill through the STK program to identify the bill;
  • the user checks the received bill through the STK menu and uses the balance to pay.
  • the main object of the embodiments of the present invention is to provide a mobile phone bill payment method, which aims to enhance the security of mobile phone payment, and provides a payment request that is not easily counterfeited through the STK menu of the mobile phone to protect the user property.
  • the embodiment of the invention provides a method for bill payment management, the method specifically comprising the steps of: receiving a first user identification application development tool STK bill payment request sent by the requesting end; performing the first STK bill payment request Verify
  • the second STK bill payment request is sent to the paying end according to the verification result.
  • the requesting end before receiving the first user identification application development tool STK bill payment request sent by the requesting end, the requesting end includes: the requesting end encrypts the original billing information, the requesting end information, and the payment end information, and generates the first STK bill payment request.
  • the verifying the billing information in the first STK billing payment request specifically includes:
  • the bill payment information is verified.
  • the verifying the billing payment information comprises at least:
  • the delivering the second STK billing payment request to the paying end according to the verification result specifically includes:
  • the billing information is recombined and encrypted to obtain a second STK billing payment request;
  • the second STK billing payment request is delivered to the paying end.
  • the second STK billing payment request includes at least original billing information, requesting side information, and payment end information.
  • the embodiment of the present invention provides a bill payment management apparatus, and the apparatus specifically includes: a receiving module, configured to receive a first STK billing payment request sent by the requesting end; and a verification module, configured to set the first STK bill The verification is performed in the payment request, and the sending module is configured to deliver the second STK bill payment request to the payment end according to the verification result.
  • the requesting end comprises: an STK module, configured to combine the original billing information, the requesting end information and the payment end information into a first STK billing payment request and encrypt and send to the receiving module.
  • the verification module specifically includes:
  • the decryption unit is configured to decrypt the first STK bill payment request acquisition bill payment letter verification unit, and set the bill payment information to be verified.
  • the verifying unit verifying the billing payment information at least includes:
  • the sending module specifically includes:
  • the encryption unit is configured to, when the verification succeeds, re-combine and encrypt the bill information to obtain a second STK bill payment request;
  • the sending unit is configured to deliver the second STK billing payment request to the paying end.
  • the second STK billing payment request includes at least original billing information, requesting side information, and payment end information.
  • the embodiment of the invention provides a bill payment system, including a requesting end and a paying end, and further includes The aforementioned bill payment management device,
  • the requesting end is configured to send a first STK billing payment request to the bill payment management device; the paying end is configured to accept the second STK billing payment request, and to the second
  • the STK bill payment request is decrypted to obtain the bill payment information and the payment is confirmed.
  • the requesting end includes an STK module, configured to combine the original billing information, the requesting end information, and the payment end information into a first STK billing payment request, and encrypt and upload the same to the account payment management apparatus;
  • an STK module configured to combine the original billing information, the requesting end information, and the payment end information into a first STK billing payment request, and encrypt and upload the same to the account payment management apparatus;
  • the pay-to-end includes an STK module configured to parse and decrypt the second STK billing payment request.
  • the bill payment management device is further configured to complete the payment through the payment interface, and notify the requesting end and the payment end to pay the result.
  • the method, device and system for bill payment management provided by the embodiment of the invention perform STK encryption on the payment request sent by the requesting end, and perform verification on the STK payment request, and then send it to the paying end to complete the generation by the paying end.
  • the payment process provides users with a safer bill payment plan, prevents the payment request from being stolen, and improves the security of bill payment, thus protecting the user's property security.
  • FIG. 1 is a schematic flow chart of steps in a method for managing bill payment management according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing the steps of verifying the first STK bill payment request in the embodiment of the bill payment management method of the present invention
  • FIG. 4 is a schematic structural diagram of an embodiment of a bill payment management apparatus according to the present invention.
  • FIG. 5 is a schematic structural diagram of a sending module in an embodiment of a bill payment management apparatus according to the present invention
  • FIG. 6 is a schematic structural diagram of a school insurance module in an embodiment of a bill payment management apparatus according to the present invention
  • the requesting end and the paying end in the embodiment of the present invention may be a mobile communication terminal such as a mobile phone, and a user identification application development tool (SIM Tool Kit) STK module is embedded in the STK card for performing billing data. encryption.
  • the STK card has a unique key, and the key corresponding to each mobile phone STK card is different.
  • the key can adopt the double key group 3DES algorithm, and the message sent and received through the STK card is a kind of data information.
  • receiving and sending payment bills via SMS is different, and it is more difficult to forge. Users can view STK bills through the STK menu.
  • FIG. 1 is a schematic flowchart of an embodiment of a bill payment management method according to the present invention. The method specifically includes the following steps:
  • the requesting end receives the STK bill from the mobile operator, and the user views the STK bill through the STK menu, and the bill payment function is also set in the STK menu. If the local payment account balance is insufficient, the requesting party can select the bill payment function.
  • the bill payment request is issued and the paying end information is input according to the prompt of the screen.
  • the paying end information may be a mobile phone number of the paying user or other identification number capable of uniquely identifying the paying user. More specifically, the requesting end encrypts the original billing information, the requesting side information, and the payment end information combination that need to be requested to be sent as the first STK billing payment request, and the mobile operator receives the first STK bill sent by the requesting end. Pay the request.
  • S120 Verify billing information in the first STK billing payment request; check billing information in the first STK billing payment request, and determine whether the billing information in the first STK payment request is The correct billing information, that is, whether the billing information is The original bill sent to the requester to ensure that the payment request is initiated from the correct requester, and that the billing information is not copied by a third party.
  • the second STK bill payment request is sent to the corresponding paying end in the first STK bill payment request, where the second STK bill payment request includes the original bill information and the request to be paid End information and payment end information.
  • the payment request is abandoned.
  • the bill payment management method provided by the embodiment of the invention performs STK encryption on the STK bill payment request sent by the requesting end, and sends the STK bill payment request to the paying end to be sent to the paying end by the paying end to complete the paying process.
  • the above S120 includes:
  • S121 decrypt the first STK bill payment request, and obtain bill payment information
  • the first STK bill payment request is decrypted to obtain bill payment information, such as original bill information, request side information, and payment end information that need to be paid.
  • the specific content of the verification includes at least verifying whether the original bill exists, verifying whether the original bill status is correct, verifying whether the bill information is consistent with the original bill information, and verifying the request capability.
  • S130 is executed, and when there is a failure in the verification content, the payment request is abandoned.
  • the above S130 includes:
  • the billing information is recombined and encrypted to obtain a second STK billing payment request; wherein the second STK billing payment request includes at least original billing information, requesting end information, and payment end information. After recombining to generate a second STK bill payment request Encrypted.
  • an embodiment of the present invention provides a bill payment management apparatus 400 that can implement the foregoing method, and specifically includes:
  • the receiving module 410 is configured to receive a first STK billing payment request sent by the requesting end, and the checking module 420 is configured to check the billing information in the first STK billing payment request;
  • the sending module 430 is configured to deliver a second STK billing payment request to the payment end according to the verification result.
  • the requesting end receives the STK bill from the mobile operator, and the user views the STK bill through the STK menu, and the bill payment function is also set in the STK menu. If the local payment account balance is insufficient, the requesting party can select the bill payment function.
  • the bill payment request is issued and the paying end information is input according to the prompt of the screen.
  • the paying end information may be a mobile phone number of the paying user or other identification number capable of uniquely identifying the paying user.
  • the requesting end further includes an STK module, and the STK module encrypts the original billing information, the requesting end information, and the payment end information combination that need to be requested for payment into the first STK billing payment request, and encrypts and sends the
  • the receiving module 410 receives the first STK billing payment request sent by the STK module of the requesting end.
  • the verification module 420 checks the billing information in the first STK billing payment request, and determines whether the billing information in the first STK payment request is the correct billing information, that is, whether the billing information is delivered to the billing information.
  • the original bill of the requester to ensure that the payment request is initiated from the correct requester, ensuring that the billing information is not copied by a third party.
  • the sending module 430 When the verification is successful, the sending module 430 generates a second STK billing payment request to be delivered to the corresponding paying end in the first STK billing payment request, where the second STK billing payment request includes the original bill to be paid Information, request side information, and payment side information.
  • the verification fails, put Discard this payment request.
  • the verification module 420 specifically includes:
  • the decryption unit 421 is configured to decrypt the first STK bill payment request to obtain bill payment information
  • a verification unit 422 is provided to verify the billing information.
  • the decryption unit 421 decrypts the first STK billing payment request to obtain billing payment information, such as original billing information, request side information, and payment end information that need to be paid.
  • the verification unit 422 verifies the bill payment information, wherein the specific content of the check includes at least verifying whether the original bill exists, verifying whether the original bill status is correct, verifying whether the bill information is consistent with the original bill information, and verifying Whether the requesting end is the user who was last issued by the original bill and whether the paying function is activated by the checking end.
  • the sending module 430 sends a second STK bill payment request to the paying end, and when the verification content has a failure, the sending request is abandoned.
  • the foregoing sending module 430 specifically includes:
  • the encryption unit 431 is configured to, when the verification succeeds, recombine and encrypt the bill information to obtain a second STK bill payment request;
  • the sending unit 432 is configured to send the second STK billing payment request to the paying end; when the checking module 420 successfully checks the bill payment information, the encrypting unit 431 recombines the billing information to generate a second The STK bill pays for the request and encrypts, wherein the second STK billing payment request includes at least the original billing information, the requesting side information, and the paying end information.
  • the sending unit 432 delivers the second STK billing payment request to the corresponding paying end.
  • an embodiment of the present invention further provides a bill payment management system, which specifically includes: a requesting end 500, a paying end 600, and a bill payment management apparatus 400 in the foregoing embodiment, wherein the requesting end 500 is set to When the balance of the local payment account is insufficient, the management device is paid to the account.
  • the bill payment management device 400 is configured to receive the first STK billing payment request sent by the requesting end, check the billing payment information in the first STK billing payment request, and issue the second STK bill according to the verification result. Pay the request to the paying end;
  • the payment terminal 600 is configured to receive the second STK bill payment request, and decrypt the second STK bill payment request to obtain the bill payment information and confirm the payment.
  • the user of the requesting terminal 500 views the STK bill through the STK menu.
  • the user selects the bill payment function in the STK menu, and inputs the information for the billing end 600 for bill payment, where the payment is made.
  • the information of the terminal 600 can be a mobile phone number or other unique user identification code.
  • the STK module is set on the requesting end 500, and the STK original billing information, the requesting end information and the payment end information required to be requested for payment are combined into the first STK billing payment request by the STK module, and encrypted and uploaded to the account payment management apparatus. 400.
  • the bill payment management device 400 receives the first STK bill payment request sent by the requesting terminal 500, and parses and decrypts the first STK bill payment request to obtain bill payment information, and verifies the bill payment information.
  • the content of the test at least includes verifying whether the STK original billing information exists, verifying whether the original billing status is correct, verifying whether the billing information is consistent with the original billing information, and verifying the paying function. If the verification fails, the payment request is discarded. If the verification is successful, the bill payment information is reorganized and encrypted to generate a second STK bill payment request, and is sent to the corresponding paying terminal 600.
  • the payment terminal 600 includes an STK decryption module. After receiving the second STK bill payment request, the STK decryption module decrypts the second STK bill payment request. If the decryption is successful, the STK menu in the payend end 600 is The user prompts the payment request, including the request side information, the STK billing information, etc., and the user confirms the payment after viewing the payment request.
  • the bill payment management device 400 is further configured to complete the payment through the payment interface, and notify the requesting end 500 and the paying end 600. The result of the payment.
  • the confirmation payment information is sent to the bill payment management device 400, and the bill payment management device 400 notifies the requesting end 500 and the paying end 600 respectively by the payment interface.
  • the payment interface can be a payment interface commonly used by mobile operators.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Storage Device Security (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明实施例公开了一种账单代付管理方法、装置及系统,其中方法具体包括步骤:接收请求端发送的第一用户识别应用发展工具STK账单代付请求;对第一STK账单代付请求进行校验;根据校验结果下发第二STK账单代付请求至代付端。本发明实施例提供的账单代付管理方法、装置及系统,对请求端发送的代付请求进行STK加密,并对STK代付请求进行校验后发送至代付端后由代付端完成代付过程,为用户提供更为安全的账单代付方案,防止代付请求被盗用,提高账单代付的安全性,从而保护了用户财产安全。

Description

账单代付管理方法、 装置及系统 技术领域
本发明涉及账单支付领域, 具体是一种账单代付管理方法、 装置及系 统。 背景技术
手机账单支付是移动运营商继卡类支付、 网络支付之后推出的一种新 型的支付方式。 用户在订购了商品之后, 通过下发到手机上的账单进行支 付, 充分利用了手机的普及性和便携性。
手机账单一般来说分为短信账单、 彩信账单和用户识别应用发展工具
( STK, SIM Tool Kit )账单三种方式。 其中由于 STK程序能对用户数据进 行底层加密解密, 所以最为安全。 而采用短信、 彩信账单时, 由于信息采 用明码传输, 容易出现伪造账单和钓鱼短信的危险。
目前, 使用手机支付 STK账单的一种处理流程是:
1、 服务提供商 (SP )通过运营商下发支付账单到用户手机;
2、 用户手机通过 STK程序解密账单, 进行账单的识别;
3、 用户通过 STK菜单查看收到的账单, 并使用余额进行支付。
当用户余额不足的时候, 为了便于用户完成账单的支付, 相关技术中 存在一种代付技术, 用户在网页上付款时, 输入代付人的信息, 或者将付 款链接发送给代付人, 请求代付人代付。 代付人会收到一条普通的短信, 按照短信回复后完成代付。 但此代付技术存在一定的不安全因素: 一、 申 请代付人的身份可以是虚假的, 或者是假冒的, 很难判断该代付请求是否 来自真实的好友; 二、 代付请求和同意该代付请求的回复可以被伪造, 真 假信息难以分辨; 三、 网络上存在大量的钓鱼网站, 用户账号容易被盗号, 造成用户信息的不安全, 一旦被盗则盗用者可以大量购买虚假商品, 并且 申请失主的好友代付, 由此带来的风险不言而喻。 发明内容
本发明实施例的主要目的是提供一种手机账单代付方法, 旨在增强手 机代付的安全性, 通过手机 STK菜单提供不易被仿造的代付请求, 保护用 户财产。
本发明实施例提出一种账单代付管理的方法, 所述方法具体包括步驟: 接收请求端发送的第一用户识别应用发展工具 STK账单代付请求; 对所述第一 STK账单代付请求进行校验;
根据校验结果下发第二 STK账单代付请求至代付端。
优选地, 在接收请求端发送的第一用户识别应用发展工具 STK账单代 付请求之前包括: 请求端将原始账单信息、 请求端信息以及代付端信息加 密, 生成所述第一 STK账单代付请求。
优选地, 所述对第一 STK账单代付请求中的账单信息进行校验具体包 括:
对所述第一 STK账单代付请求解密获取账单代付信息;
对所述账单代付信息进行校验。
优选地, 所述对账单代付信息进行校验至少包括:
校验原始账单是否存在、 校验原始账单状态是否正确、 校验账单信息 是否与原始账单信息一致、 校验所述请求端是否为原始账单上次下发的用 户以及校验所述代付端是否开通了代付功能。
优选地, 所述根据校验结果下发第二 STK账单代付请求至代付端具体 包括:
当校验成功时, 对所述账单信息进行重新组合并加密后获得第二 STK 账单代付请求; 将所述第二 STK账单代付请求下发至代付端。
优选地, 所述第二 STK账单代付请求至少包括原始账单信息、 请求端 信息和代付端信息。
本发明实施例提出一种账单代付管理装置, 所述装置具体包括: 接收模块, 设置为接收请求端发送的第一 STK账单代付请求; 校验模块, 设置为对所述第一 STK账单代付请求中进行校验; 发送模块,设置为根据校验结果下发第二 STK账单代付请求至代付端。 优选地, 所述请求端包括: STK模块, 设置为将原始账单信息、 请求 端信息以及代付端信息组合为第一 STK账单代付请求并加密后发送至接收 模块。
优选地, 所述校验模块具体包括:
解密单元, 设置为对所述第一 STK账单代付请求解密获取账单代付信 校验单元, 设置为将所述账单代付信息进行校验。
优选地, 所述校验单元对账单代付信息进行校验至少包括:
校验原始账单是否存在、 校验原始账单状态是否正确、 校验账单信息 是否与原始账单信息一致、 校验所述请求端是否为原始账单上次下发的用 户以及校验所述代付端是否开通了代付功能。
优选地, 所述发送模块具体包括:
加密单元, 设置为当校验成功时, 对所述账单信息进行重新组合并加 密后获得第二 STK账单代付请求;
发送单元, 设置为将所述第二 STK账单代付请求下发至代付端。
优选地, 所述第二 STK账单代付请求至少包括原始账单信息、 请求端 信息和代付端信息。
本发明实施例提出一种账单代付系统, 包括请求端和代付端, 还包括 前述的账单代付管理装置,
所述请求端 ,设置为向账单代付管理装置发送第一 STK账单代付请求; 所述代付端, 设置为接受所述第二 STK账单代付请求, 并对所述第二
STK账单代付请求进行解密获取账单代付信息后确认代付。
优选地, 所述请求端包括 STK模块, 设置为将原始账单信息、 请求端 信息以及代付端信息组合为第一 STK账单代付请求并加密后上传至账户代 付管理装置;
所述代付端包括 STK模块,设置为对所述第二 STK账单代付请求进行 解析及解密。
优选地, 当代付端确认代付后, 所述账单代付管理装置还设置为通过 支付接口完成代付, 并通知所述请求端和所述代付端代付结果。
本发明实施例提供的账单代付管理的方法、 装置及系统, 对请求端发 送的代付请求进行 STK加密,并对 STK代付请求进行校验后发送至代付端 由代付端完成代付过程, 为用户提供更为安全的账单代付方案, 防止代付 请求被盗用, 提高账单代付的安全性, 从而保护了用户财产安全。 附图说明
图 1为本发明账单代付管理方法一实施例中的步驟流程示意图; 图 2为本发明账单代付管理方法实施例中对所述第一 STK账单代付请 求进行校验的步驟流程示意图; 账单代付请求至代付端的步驟流程示意图;
图 4为本发明账单代付管理装置实施例中的结构示意图;
图 5为本发明账单代付管理装置实施例中发送模块的结构示意图; 图 6为本发明账单代付管理装置实施例中校险模块的结构示意图; 图 7为本发明账单代付管理系统实施例中的结构示意图。 具体实施方式
本发明目的的实现、 功能特点及优点将结合实施例, 参照附图做进一 步说明。 为了使本发明的目的、 技术方案及优点更加清楚明白, 以下结合 附图及实施例, 对本发明进行进一步详细说明。 应当理解, 此处所描述的 具体实施例仅仅用以解释本发明, 并不用于限定本发明。
本发明实施例中的请求端和代付端可以是手机等移动通信终端, 其设 有用户识别应用发展工具(SIM Tool Kit ) STK模块, 该模块嵌入于 STK 卡中,用于对账单数据进行加密。 STK卡自带有唯一的密钥,每个手机 STK 卡对应的密钥都不一样, 该密钥可采用双密钥组的 3DES算法, 通过 STK 卡发送和收到的消息是一种数据信息, 传统的通过手机短信接收和发送支 付账单不一样, 更难以被伪造, 用户可以通过 STK菜单查看 STK账单。
参照图 1 ,图 1为本发明提出的账单代付管理方法一实施例的流程示意 图, 该方法具体包括以下步驟:
S110: 接收请求端发送的第一 STK账单代付请求;
请求端接收到移动运营商下发 STK账单, 用户通过 STK菜单查看该 STK账单, 并且在 STK菜单中还设置有账单代付功能, 若本地支付账户余 额不足时, 请求端可以选择账单代付功能发出账单代付请求并根据屏幕的 提示输入代付端信息, 例如, 代付端信息可以为代付用户的手机号码或者 是其它能够唯一标识代付用户的识别号码。 更为具体的, 请求端将需要请 求代付的原始账单信息、 请求端信息以及代付端信息组合加密为第一 STK 账单代付请求后发送, 移动运营商接收请求端发送的第一 STK账单代付请 求。
S120: 对第一 STK账单代付请求中的账单代付信息进行校验; 对第一 STK账单代付请求中的账单信息进行校验,判断该第一 STK代 付请求中的账单信息是否为正确的账单信息, 也就是说该账单信息是否为 下发至请求端的原始账单, 以确保代付请求是从正确的请求端上发起的, 保证账单信息并未被第三方仿造。
S130: 根据校验结果下发第二 STK账单代付请求至代付端;
当校验成功时,生成第二 STK账单代付请求下发至第一 STK账单代付 请求中对应的代付端, 其中第二 STK账单代付请求中包含需要代付的原始 账单信息、 请求端信息和代付端信息。 当校验失败时, 则放弃此次代付请 求。
本发明实施例提供的账单代付管理方法, 对请求端发送的 STK账单代 付请求进行 STK加密,并对 STK账单代付请求进行校验后发送至代付端由 代付端完成代付过程, 为用户提供更为安全的账单代付方法, 防止代付请 求被盗用, 从而保护了用户财产安全。
具体的, 参照图 2, 以上 S120中包括:
S121 : 对第一 STK账单代付请求解密, 获取账单代付信息;
对第一 STK账单代付请求进行解密后获得账单代付信息, 例如需要代 付的原始账单信息、 请求端信息以及代付端信息。
S122: 对账单代付信息进行校验;
其中, 校验的具体内容至少包括校验原始账单是否存在、 校验原始账 单状态是否正确、 校验账单信息是否与原始账单信息一致、 校验所述请求 能。 当校验成功时, 执行 S130, 当校验内容有一项失败时, 放弃此次代付 请求。
参照图 3 , 上述 S130中包括:
S131 : 当校验成功时, 对所述账单信息进行重新组合并加密后获得第 二 STK账单代付请求;其中第二 STK账单代付请求至少包括原始账单信息、 请求端信息和代付端信息, 在重新组合生成第二 STK账单代付请求后进行 加密。
S132: 将第二 STK账单代付请求下发至对应的代付端。
参照图 4,本发明实施例提出一种可实现上述方法的账单代付管理装置 400, 具体包括:
接收模块 410, 设置为接收请求端发送的第一 STK账单代付请求; 校验模块 420, 设置为对所述第一 STK账单代付请求中的账单信息进 行校验;
发送模块 430, 设置为根据校验结果下发第二 STK账单代付请求至代 付端。
请求端接收到移动运营商下发 STK账单, 用户通过 STK菜单查看该 STK账单, 并且在 STK菜单中还设置有账单代付功能, 若本地支付账户余 额不足时, 请求端可以选择账单代付功能发出账单代付请求并根据屏幕的 提示输入代付端信息, 例如, 代付端信息可以为代付用户的手机号码或者 是其它能够唯一标识代付用户的识别号码。 在本实施例中, 请求端还包括 STK模块, 所述 STK模块将需要请求代付的原始账单信息、 请求端信息以 及代付端信息组合加密为第一 STK账单代付请求并加密后发送至接收模块 410, 接收模块 410接收到请求端的 STK模块发送的该第一 STK账单代付 请求。
校验模块 420对第一 STK账单代付请求中的账单信息进行校验, 判断 该第一 STK代付请求中的账单信息是否为正确的账单信息, 也就是说该账 单信息是否为下发至请求端的原始账单, 以确保代付请求是从正确的请求 端上发起的, 保证账单信息并未被第三方仿造。
当校验成功时, 发送模块 430生成第二 STK账单代付请求下发至第一 STK账单代付请求中对应的代付端, 其中第二 STK账单代付请求中包含需 要代付的原始账单信息、 请求端信息和代付端信息。 当校验失败时, 则放 弃此次代付请求。
参照图 5 , 上述校验模块 420具体包括:
解密单元 421 , 设置为对所述第一 STK账单代付请求解密获取账单代 付信息;
校验单元 422, 设置为将所述账单代付信息进行校验。
解密单元 421对第一 STK账单代付请求进行解密后获得账单代付信息, 例如需要代付的原始账单信息、 请求端信息以及代付端信息。
校验单元 422对账单代付信息进行校验, 其中, 校验的具体内容至少 包括校验原始账单是否存在、 校验原始账单状态是否正确、 校验账单信息 是否与原始账单信息一致、 校验所述请求端是否为原始账单上次下发的用 户以及校验所述代付端是否开通了代付功能。 当校验成功时,发送模块 430 发送第二 STK账单代付请求至代付端, 当校验内容有一项失败时, 放弃此 次代付请求。
参照图 6, 上述发送模块 430具体包括:
加密单元 431 ,设置为当校验成功时,对所述账单信息进行重新组合并 加密后获得第二 STK账单代付请求;
发送单元 432, 设置为将所述第二 STK账单代付请求下发至代付端; 当校验模块 420对账单代付信息校验成功时, 加密单元 431对账单信 息进行重新组合生成第二 STK账单代付请求并加密,其中第二 STK账单代 付请求至少包括原始账单信息、 请求端信息和代付端信息。
发送单元 432将第二 STK账单代付请求下发至对应的代付端。
参照图 7, 本发明实施例还提出一种账单代付管理系统, 具体包括: 请 求端 500、 代付端 600以及前述实施例中的账单代付管理装置 400, 其中, 请求端 500,设置为当本地支付账户余额不足时, 向账户代付管理装置
400发送第一 STK账单代付请求; 账单代付管理装置 400, 设置为接收请求端发送的第一 STK账单代付 请求, 对第一 STK账单代付请求中的账单代付信息进行校验, 根据校验结 果下发第二 STK账单代付请求至代付端;
代付端 600, 设置为接收所述第二 STK账单代付请求, 并对所述第二 STK账单代付请求进行解密获取账单代付信息后确认代付。
请求端 500的用户通过 STK菜单查看到 STK账单,当本地账户账单余 额不足时, 用户在 STK菜单中选择账单代付功能, 并输入用于账单代付的 代付端 600的信息, 其中代付端 600的信息可以为手机号码或者其它的唯 一用户标识码。请求端 500上设置有 STK模块,通过 STK模块将需要请求 代付的 STK原始账单信息、请求端信息以及代付端信息组合为第一 STK账 单代付请求并加密后上传至账户代付管理装置 400。
账单代付管理装置 400接收请求端 500发送的第一 STK账单代付请求, 并对第一 STK账单代付请求进行解析及解密后获得账单代付信息, 对账单 代付信息进行校验,校验的内容至少包括校验 STK原始账单信息是否存在、 校验原始账单状态是否正确、 校验账单信息是否与原始账单信息一致、 校 通了代付功能。 若校验失败, 则放弃该次代付请求, 若校验成功, 则对账 单代付信息进行重组并加密生成第二 STK账单代付请求, 并将其下发至对 应的代付端 600。
代付端 600包括 STK解密模块, 在接收到第二 STK账单代付请求后, STK解密模块对第二 STK账单代付请求进行解密, 若解密成功, 则在代付 端 600的 STK菜单中向用户提示代付请求, 包括请求端信息、 STK账单信 息等, 用户查看该代付请求后确认代付。
在前述实施例的基础上, 当代付端 600确认代付后, 账单代付管理装 置 400还设置为通过支付接口完成代付, 并通知请求端 500和代付端 600 代付结果。 代付端 600确认代付后将确认代付信息发送至账单代付管理装 置 400,账单代付管理装置 400通过支付接口完成代付后将代付结果分别通 知请求端 500和代付端 600,该支付接口可以为移动运营商常用的支付接口。
以上仅为本发明的较佳实施例而已, 并不用以限制本发明, 凡在本发 明的精神和原则之内所作的任何修改、 等同替换和改进等, 均应包含在本 发明的保护范围之内。

Claims

权利要求书
1、 一种账单代付管理的方法, 具体包括步驟:
接收请求端发送的第一用户识别应用发展工具 STK账单代付请求; 对所述第一 STK账单代付请求进行校验;
根据校验结果下发第二 STK账单代付请求至代付端。
2、 如权利要求 1所述的账单代付管理的方法, 其中, 在接收请求端发 送的第一用户识别应用发展工具 STK账单代付请求之前包括: 请求端将原 始账单信息、 请求端信息以及代付端信息加密, 生成所述第一 STK账单代 付请求。
3、 如权利要求 1所述的账单代付管理的方法, 其中, 所述对第一 STK 账单代付请求进行校验具体包括:
对所述第一 STK账单代付请求解密, 获取账单代付信息;
对所述账单代付信息进行校验。
4、 如权利要求 3所述的账单代付管理的方法, 其中, 所述对账单代付 信息进行校验至少包括:
校验原始账单是否存在、 校验原始账单状态是否正确、 校验账单信息 是否与原始账单信息一致、 校验所述请求端是否为原始账单上次下发的用 户以及校验所述代付端是否开通了代付功能。
5、 如权利要求 1至 4任一项所述的账单代付管理的方法, 其中, 所述 根据校验结果下发第二 STK账单代付请求至代付端具体包括:
当校验成功时, 对所述账单信息进行重新组合并加密后获得第二 STK 账单代付请求;
将所述第二 STK账单代付请求下发至代付端。
6、 如权利要求 5 所述的账单代付管理的方法, 其中, 所述第二 STK 账单代付请求至少包括原始账单信息、 请求端信息和代付端信息。
7、 一种账单代付管理装置, 具体包括:
接收模块, 设置为接收请求端发送的第一 STK账单代付请求; 校验模块, 设置为对所述第一 STK账单代付请求进行校验;
发送模块,设置为根据校验结果下发第二 STK账单代付请求至代付端。
8、 如权利要求 7所述的账单代付管理装置, 其中, 所述请求端包括: STK模块, 设置为将原始账单信息、 请求端信息以及代付端信息组合为第 一 STK账单代付请求并加密后发送至接收模块。
9、 如权利要求 7所述的账单代付管理装置, 其中, 所述校验模块具体 包括:
解密单元, 设置为对所述第一 STK账单代付请求解密, 获取账单代付 信息;
校验单元, 设置为将所述账单代付信息进行校验。
10、 如权利要求 9所述的账单代付管理装置, 其中, 所述校验单元对 账单代付信息进行校验至少包括:
校验原始账单是否存在、 校验原始账单状态是否正确、 校验账单信息 是否与原始账单信息一致、 校验所述请求端是否为原始账单上次下发的用 户以及校验所述代付端是否开通了代付功能。
11、 如权利要求 7至 10任一项所述的账单代付管理装置, 其中, 所述 发送模块具体包括:
加密单元, 设置为当校验成功时, 对所述账单信息进行重新组合并加 密后获得第二 STK账单代付请求;
发送单元, 设置为将所述第二 STK账单代付请求下发至代付端。
12、 如权利要求 11所述的账单代付管理装置, 其中, 所述第二 STK账 单代付请求至少包括原始账单信息、 请求端信息和代付端信息。
13、 一种账单代付系统, 包括请求端和代付端, 还包括如权利要求 7 至 12中任一项所述的账单代付管理装置,
所述请求端 ,设置为向账单代付管理装置发送第一 STK账单代付请求; 所述代付端, 设置为接收所述第二 STK账单代付请求, 并对所述第二 STK账单代付请求进行解密获取账单代付信息后确认代付。
14、 如权利要求 13所述的账单代付系统, 其中,
所述请求端包括 STK模块, 设置为将原始账单信息、 请求端信息以及 代付端信息组合为第一 STK账单代付请求并加密后上传至账户代付管理装 置;
所述代付端包括 STK模块,设置为对所述第二 STK账单代付请求进行 解析及解密。
15、 如权利要求 13或 14所述的账单代付系统, 其中, 当代付端确认 代付后, 所述账单代付管理装置还设置为通过支付接口完成代付, 并通知 所述请求端和所述代付端代付结果。
PCT/CN2012/072562 2011-11-18 2012-03-19 账单代付管理方法、装置及系统 WO2012155644A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110369433.0 2011-11-18
CN2011103694330A CN103123706A (zh) 2011-11-18 2011-11-18 账单代付管理方法、装置及系统

Publications (1)

Publication Number Publication Date
WO2012155644A1 true WO2012155644A1 (zh) 2012-11-22

Family

ID=47176245

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/072562 WO2012155644A1 (zh) 2011-11-18 2012-03-19 账单代付管理方法、装置及系统

Country Status (2)

Country Link
CN (1) CN103123706A (zh)
WO (1) WO2012155644A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015096510A1 (en) * 2013-12-25 2015-07-02 Tencent Technology (Shenzhen) Company Limited Data processing method, apparatus and system

Families Citing this family (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP6098400B2 (ja) * 2013-07-01 2017-03-22 富士ゼロックス株式会社 情報処理装置及びプログラム
CN104703160B (zh) * 2013-12-06 2018-07-24 中国移动通信集团公司 一种电子凭证处理方法及设备
CN103632260B (zh) * 2013-12-15 2016-08-03 程振国 基于二维码的电费抄表支付的系统
CN103617717B (zh) * 2013-12-15 2016-03-16 程振国 基于二维码的电费抄表支付的方法
CN104753906B (zh) * 2013-12-31 2017-05-24 腾讯科技(深圳)有限公司 转移数据方法、装置和系统
CN104753907B (zh) * 2013-12-31 2017-03-29 腾讯科技(深圳)有限公司 基于即时通信或社交应用的数据处理方法和装置
CN105608569A (zh) * 2014-11-24 2016-05-25 阿里巴巴集团控股有限公司 基于支付平台的代付方法及支付平台
CN104463450A (zh) * 2014-11-28 2015-03-25 小米科技有限责任公司 一种订单处理的方法和装置
CN106209953B (zh) * 2015-05-08 2020-06-26 阿里巴巴集团控股有限公司 订单信息的处理方法、装置及系统
KR20160138684A (ko) * 2015-05-26 2016-12-06 에스케이플래닛 주식회사 대리결제장치 및 그 동작 방법
CN105989494A (zh) * 2015-05-27 2016-10-05 中国银联股份有限公司 一种代理支付方法、装置以及电子设备
WO2017011995A1 (zh) * 2015-07-21 2017-01-26 深圳市银信网银科技有限公司 一种电子凭证变更以及数据交互处理的方法、系统及装置
CA2993525C (en) * 2015-07-21 2023-04-25 10353744 Canada Ltd. Method, system, and apparatus for altering electronic certificates and processing data exchange
WO2017012062A1 (zh) * 2015-07-21 2017-01-26 深圳市银信网银科技有限公司 开立电子凭证的方法、装置和系统
WO2017012007A1 (zh) * 2015-07-21 2017-01-26 深圳市银信网银科技有限公司 电子凭证开证确认权限转让方法、系统和设备
CA2993033A1 (en) * 2015-07-21 2017-01-26 10353744 Canada Ltd. Method, system, and apparatus for altering electronic certificates and processing
CN106651366A (zh) * 2015-11-03 2017-05-10 国民技术股份有限公司 一种移动终端及其交易确认方法、装置以及一种智能卡
CN106855812A (zh) * 2015-12-08 2017-06-16 北京三星通信技术研究有限公司 配置用户终端的方法和装置
CN106910055A (zh) * 2015-12-23 2017-06-30 北京奇虎科技有限公司 一种基于移动终端的支付数据处理方法和装置
CN106228359A (zh) * 2016-08-12 2016-12-14 北京东方车云信息技术有限公司 司机客户端的账单结算方法、打车系统服务器及相关系统
CN113535382A (zh) 2016-12-23 2021-10-22 创新先进技术有限公司 资源处理方法及装置
CN107895264B (zh) * 2017-11-13 2021-12-10 招商华软信息有限公司 车辆费用的缴纳方法和装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101273373A (zh) * 2006-01-20 2008-09-24 阿捷·阿迪谢山 通过移动通信装置支付的方法和系统
CN101853458A (zh) * 2010-05-17 2010-10-06 成都中联信通科技有限公司 在移动互联网销售中实现手机支付的方法
CN102117520A (zh) * 2009-12-31 2011-07-06 亿阳信通股份有限公司 基于ic卡的支付方法、管理装置、服务器及移动终端

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
MXPA06000174A (es) * 2003-07-02 2006-04-11 Mobipay International S A Sistema de transacciones y pagos mediante telefono movil digital.
CN1222134C (zh) * 2003-08-25 2005-10-05 大唐微电子技术有限公司 实现非结构化补充数据业务中数据安全传输的方法及系统
CN101841783A (zh) * 2010-02-03 2010-09-22 北京道通天下信息科技有限责任公司 基于stk业务的短信安全通信方法和系统以及装置
WO2011128913A1 (en) * 2010-04-13 2011-10-20 Pranamesh Das Secure and shareable payment system using trusted personal device
CN101841806A (zh) * 2010-04-21 2010-09-22 钱袋网(北京)信息技术有限公司 业务卡信息处理方法、装置、系统及通信终端
CN101840549A (zh) * 2010-05-17 2010-09-22 成都中联信通科技有限公司 在互联网销售中实现手机支付的系统和方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101273373A (zh) * 2006-01-20 2008-09-24 阿捷·阿迪谢山 通过移动通信装置支付的方法和系统
CN102117520A (zh) * 2009-12-31 2011-07-06 亿阳信通股份有限公司 基于ic卡的支付方法、管理装置、服务器及移动终端
CN101853458A (zh) * 2010-05-17 2010-10-06 成都中联信通科技有限公司 在移动互联网销售中实现手机支付的方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015096510A1 (en) * 2013-12-25 2015-07-02 Tencent Technology (Shenzhen) Company Limited Data processing method, apparatus and system
US10636025B2 (en) 2013-12-25 2020-04-28 Tencent Technology (Shenzhen) Company Limited Payment processing conditioned on multi-party geolocation constraints

Also Published As

Publication number Publication date
CN103123706A (zh) 2013-05-29

Similar Documents

Publication Publication Date Title
WO2012155644A1 (zh) 账单代付管理方法、装置及系统
CN102801710B (zh) 一种网络交易方法和系统
CN107609866B (zh) 基于虚拟货币的电子支付、电子收款方法及装置
CN103731259B (zh) 一种终端主密钥tmk安全下载方法及系统
CN108834144B (zh) 运营商码号与账号的关联管理方法与系统
US20090187980A1 (en) Method of authenticating, authorizing, encrypting and decrypting via mobile service
CN102945526B (zh) 一种提高移动设备在线支付安全的装置及方法
CN102789607A (zh) 一种网络交易方法和系统
CN103326862B (zh) 电子签名方法及系统
CN102790767B (zh) 信息安全控制方法,信息安全显示设备,及电子交易系统
CN102831518A (zh) 一种支持第三方授权的移动支付方法及系统
CN101631305B (zh) 一种加密方法及系统
CN101373528A (zh) 基于位置认证的电子支付系统、设备、及方法
US20160321656A1 (en) Method and system for protecting information against unauthorized use (variants)
CN105046488A (zh) 用于生成交易签署一次性密码的方法、设备和系统
CN102694780A (zh) 一种数字签名认证方法及包含该方法的支付方法及系统
CN101335754B (zh) 一种利用远程服务器进行信息验证的方法
TWI591553B (zh) Systems and methods for mobile devices to trade financial documents
CN104464117A (zh) 基于动态二维码银行自动柜员机取款方法及系统
CN103093341A (zh) 一种基于rfid智能支付系统的安全支付方法
CN103903140A (zh) 一种o2o安全支付方法、系统和一种安全支付后台
CN104935441A (zh) 一种认证方法及相关装置、系统
CN103761644A (zh) 移动互联网在线支付的下单处理方法
WO2000039958A1 (en) Method and system for implementing a digital signature
CN107609878B (zh) 一种共享汽车的安全认证方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12785159

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12785159

Country of ref document: EP

Kind code of ref document: A1