WO2013086857A1 - 一种金融交易验证的方法和系统 - Google Patents

一种金融交易验证的方法和系统 Download PDF

Info

Publication number
WO2013086857A1
WO2013086857A1 PCT/CN2012/078842 CN2012078842W WO2013086857A1 WO 2013086857 A1 WO2013086857 A1 WO 2013086857A1 CN 2012078842 W CN2012078842 W CN 2012078842W WO 2013086857 A1 WO2013086857 A1 WO 2013086857A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication code
information
mobile terminal
bank card
server
Prior art date
Application number
PCT/CN2012/078842
Other languages
English (en)
French (fr)
Inventor
冯林
Original Assignee
Feng Lin
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Feng Lin filed Critical Feng Lin
Publication of WO2013086857A1 publication Critical patent/WO2013086857A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce

Definitions

  • the invention belongs to the field of financial transaction security technology and relates to a method and system for financial transaction verification.
  • the user In the current use of the ATM machine, the user first inserts the bank card into the ATM machine, and then enters the password according to the screen on the ATM machine.
  • the password When inputting the password, the user must input through the keyboard on the ATM machine or the password input device on the touch screen. After the password verification is passed, the financial operations such as withdrawal and transfer can be performed. Therefore, if a criminal wants to impersonate a legitimate user for a withdrawal business, he must first know the bank card information of the legitimate user and the password of the bank card. Description
  • the Chinese patent application number: 200610028515.8 provides a system for realizing the withdrawal or payment by using the mobile terminal.
  • the method includes the following steps: binding a specific bank card to a specific mobile phone number; displaying, on the financial terminal, terminal service information; the user directly dialing the feature code by using the mobile phone, and may also send the short message; The information is sent to the financial server; the financial server finds that the bank card information corresponding to the mobile phone number is transmitted to the financial terminal where the user is located; after the user inputs the password and identifies it, the financial operation is performed.
  • the techniques described in this patent for the use of mobile terminals for withdrawal or payment have the following drawbacks:
  • the feature code is displayed on the display of the ATM machine.
  • the display of the ATM machine will be blocked, causing the waiting person to see the feature code.
  • the operation of inputting the feature code on the mobile terminal in advance if the mobile phone is used to operate when it is arranged for the financial transaction, obviously makes the whole operation slower, and increases the time that other people wait in line for withdrawal. .
  • the feature code is printed on the wall above the display, there is a possibility that it will be modified by the criminals.
  • the financial terminal is located by the feature code, but the user's legal identity cannot be accurately determined because there are many users operating on a financial terminal, if the user is operating the financial terminal Before the book is entered into the feature code through the mobile phone, and just before the user is a criminal, he knows the user's bank card password in advance, so it is easy to impersonate the user to withdraw money.
  • the Chinese invention patent with the patent application number: 201010116443.9 also discloses an ATM-based authentication method and system.
  • the ATM-based authentication method includes: receiving user input including a signed mobile phone number, an authentication code, a withdrawal amount, and a transaction password.
  • the reservation withdrawal request is obtained, and the reservation information including the bank card number, the authentication code, the withdrawal amount, and the transaction password is obtained from the mobile banking bank according to the contracted mobile phone number; the received reservation withdrawal request is authenticated according to the obtained reservation withdrawal information, to be authenticated
  • the same amount of money as the withdrawal amount in the reservation withdrawal request is output.
  • the Chinese invention patent of CN10763692 A discloses a system for inputting the password of the ATM machine.
  • the user connects with the ATM machine through the transmitting device on his mobile phone, and uses the input on the mobile phone.
  • the device replaces the input device originally set on the ATM machine, so as to avoid the password being recorded by the camera or the fake keyboard.
  • the mobile phone The specification includes a transmitting unit, the transmitting unit is a transmitting module using short-distance transmission technology, the ATM machine includes a receiving unit, and the receiving unit is a receiving module using short-distance transmission technology for receiving a personal password transmitted by the transmitting module, a transmitting unit and receiving
  • the units are respectively a transmitting module and a receiving module using a Bluetooth transmission protocol.
  • the Bluetooth module needs to be used on both the ATM machine and the mobile phone, which significantly increases the manufacturing cost of the ATM machine, and is now Some ATMs do not have a Bluetooth module, so the cost of upgrading the ATM is also increased.
  • the two Bluetooth modules need to be paired when establishing a communication link, only when both parties know the pairing password can they be paired. Success, if the default does not require a pairing password, the pairing success will obviously increase the risk of trading, and this will give the criminals a chance to do so.
  • the criminals can also enter the password by pairing with the ATM module of the ATM. By entering the wrong password Disrupting the normal transaction process of the user.
  • the software itself is not installed, it is difficult to operate. Therefore, it is necessary to install some special software on the mobile phone.
  • the object of the present invention is to solve the above technical problems and to propose a new method and system for financial transaction verification.
  • the invention has the characteristics of high safety, simple method, simple user operation and wide application range.
  • the present invention provides a method for verifying a financial transaction, the method comprising: obtaining a pre-verification request sent by a mobile terminal;
  • the financial terminal acquires the bank card information of the user transaction account and the authentication code information input by the user, and sends the bank card information and the authentication code information to the server for verification;
  • the instruction for passing the transaction verification is sent to the financial terminal.
  • the method further includes:
  • the mobile terminal sends a pre-authentication request by means of a call or sending a short message, and the transaction password information is sent to the server by means of short message or dialing or key input.
  • the authentication code sent to the mobile terminal is a dynamic authentication code randomly selected from the authentication code database, and the authentication code is invalidated after being verified correctly.
  • the method further includes:
  • the instruction Determining whether the time interval exceeds a set threshold; When the time interval exceeds the set threshold, the instruction sends an instruction to the financial terminal that the trader identity verification fails and the authentication code times out;
  • the method further includes:
  • the mobile terminal When it is verified that the transaction password is different from the transaction password corresponding to the bank card, the mobile terminal sends the message information with the wrong transaction password to the mobile terminal, and sends the identity to the mobile terminal when the transaction password verification error is consecutively repeated for a certain period of time. Verify the aborted message information and stop extracting the transaction password information contained in the verification message.
  • the method further includes:
  • the packet information with the authentication code error is sent to the financial terminal, and when the authentication code is verified repeatedly for a certain period of time, Sending the message information of the authentication suspension to the financial terminal, and stopping the verification of the authentication code sent by the financial terminal.
  • the method further includes:
  • the present invention further provides a financial transaction verification system, the system comprising: a mobile terminal, configured to send a pre-verification request to a server;
  • a server configured to acquire card number information of the mobile terminal and move to the bank card information
  • the terminal terminal sends the authentication code information
  • a financial terminal configured to obtain bank card information of a user transaction account and authentication code information input by the user, and send the bank card information and the authentication code information to the server for verification;
  • the server verifies whether the authentication code sent by the financial terminal is the same as the authentication code sent to the mobile terminal to which the bank card information is bound, and after the authentication code is the same, the server sends an instruction to the financial terminal to pass the transaction verification.
  • the mobile terminal is further configured to send the verification information; the server verifies whether the transaction password is the same as the transaction password corresponding to the bank card, and the server sends the authentication code information to the mobile terminal after the transaction password is correct.
  • the mobile terminal sends a pre-authentication request by means of a call or a short message, and the transaction password information is sent to the server by means of a short message or a dialing.
  • the authentication code sent to the mobile terminal is a dynamic authentication code randomly selected from the authentication code database, and the authentication code is invalidated after being verified correctly.
  • the server initiates monitoring of the bank card while sending the authentication code to the mobile terminal; the server acquires the location of the financial terminal that sends the monitored bank card information, And transmitting the location information of the financial terminal to the public security alarm system.
  • the server further includes:
  • a timing device configured to calculate a time interval for sending an authentication code to the mobile terminal and receiving an authentication code sent by the financial terminal;
  • An analysis judging device configured to determine whether the time interval exceeds a set threshold; when the time interval exceeds a set threshold, the server sends a trader identity to the financial terminal An instruction to verify that the certificate failed and the authentication code timed out;
  • the server sends an instruction to the financial terminal that the trader is authenticated.
  • the server further includes:
  • the counting device is configured to calculate the number of consecutive verifications of the transaction password and the authentication code error within a certain period of time, and after continuously verifying that the number of transaction password errors exceeds a certain threshold within a certain period of time, the server suspends the holding The bank card trader performs authentication.
  • the invention sends the transaction password through the mobile terminal, and then sends the authentication code through the financial terminal, and makes the authentication code and the transaction password correspond to the bank card number and the mobile terminal card number respectively, and the bank card information corresponds to the card number information of the mobile terminal. , to make the identity of the trader in the transaction process, and improve the security of the transaction.
  • the present invention transmits a transaction request to the server through the mobile terminal, and when the transaction request is sent by way of a call and the transaction password is input by dialing, the user can be conveniently used.
  • the mobile terminal sends a transaction request to the server, the user may not be required to perform the transaction password verification to directly send the authentication code. This setting is convenient for the user to use, and the operation is more convenient, but the transaction security is reduced.
  • the criminals are prevented from peeking or illegally intercepting the transaction password, and the authentication code sent by the server to the mobile terminal is a random authentication dynamic authentication code, even if it is sneaked or illegally intercepted by the criminals, Will bring unsafe factors to the bank account.
  • the authentication code input process is in public, the authentication code is random and dynamic,
  • the manual sets a dynamic authentication code, which is automatically invalidated after one use, and is valid only for a certain period of time. It is invalid after a certain period of time, and has a very high security compared to a fixed transaction password. Sex.
  • the user can send alarm information to the server in a clever and concealed way to verify the identity of the trader when the user encounters violent coercion, so that the police can track and protect the bank account in time, avoiding the user.
  • the problem of the account being coerced and withdrawn appears, and at the same time it can play a very good blow and threat to the criminals, improving the security of the user's account.
  • Embodiment 1 is a flowchart of a method according to Embodiment 1 of the present invention.
  • Embodiment 1 of the present invention is a block diagram showing the system structure of Embodiment 1 of the present invention.
  • FIG. 3 is a flowchart of a method according to Embodiment 2 of the present invention.
  • FIG. 4 is a block diagram showing the structure of a system according to Embodiment 2 of the present invention.
  • Figure 5 is a flowchart of a method according to Embodiment 3 of the present invention.
  • Figure 6 is a structural diagram of a system according to Embodiment 3 of the present invention.
  • the present invention provides a method and system for financial transaction verification.
  • the invention sends the transaction password through the mobile terminal, and then sends the authentication code through the financial terminal, and makes the authentication code and the transaction password correspond to the bank card number and the mobile terminal card number respectively, and the bank card information corresponds to the card number information of the mobile terminal. , to make the identity of the trader in the transaction process, and improve the security of the transaction.
  • the financial terminal of the present invention includes a POS machine, an ATM machine, a bank teller machine, and other bank transaction terminals.
  • the method of the present invention is more suitable for verifying the identity of the trader when trading on the ATM machine.
  • the following embodiment uses the user on the ATM machine.
  • the financial transaction method and system of the present invention are described by way of example of withdrawal, but the scope of protection of the present invention is not limited.
  • the embodiment provides a method for verifying the identity of a trader on an ATM machine, and the method includes the following steps:
  • the step is specifically as follows: Before the user withdraws money from the ATM machine, the mobile terminal (for example, a mobile phone) sends a verification message of the transaction password to the server in advance.
  • the transaction password can be sent to the server of the Industrial and Commercial Bank of China: 457523, and the mobile phone number can be "13510617608".
  • the content of the mobile phone is "QK#457523#” (QK is the initials of the pinyin of the withdrawal) sent to "955881000”
  • the transaction password "457523” is set after the user manually authenticates the ICBC counter.
  • the legal transaction password the user can only be verified by the bank's server after sending the message containing the content of the correct transaction password.
  • the step is specifically: sending a short message sent by the mobile phone to obtain the card number information of the SIM card registered for the mobile terminal.
  • the short message server can know that the mobile phone number is 13510617608.
  • the step is specifically as follows:
  • the mobile phone number “13510617608” is manually set in the bank counter, and the mobile phone number is bound to the bank card with the card number: “6240993233994435”, and the mobile phone number can be used to query the mobile phone number.
  • Corresponding bank card number you can also query the mobile phone number corresponding to the bank card number through the bank card number.
  • a mobile phone number can be bound to a bank card number.
  • a mobile phone number can be bound to multiple bank banks. card.
  • the difference is which bank's bank card can send the SMS party's number by sending it.
  • the short message server searches for the card number information of the bank card corresponding to the mobile phone number in the database. If the card number information of the bank card corresponding to the mobile phone number is not found in the database, it indicates that the user does not have the advance Bind the mobile phone card to the bank card, and terminate the verification of the identity of the trader.
  • the step is specifically as follows: The mobile phone sends the short message to the short message server in the mobile communication network, and the short message server extracts the transaction password "457523" in the short message content "QK#457523#” and sends the transaction password to the financial server for verification.
  • S15 Verify that the transaction password is the same as the transaction password corresponding to the bank card; the step is specifically: sending a transaction password "457523" sent by the mobile phone and finding the bank card number and the bank card stored in the financial server by using the mobile phone card number The card number is compared with the transaction password corresponding to the bank card number. If the transaction password of the same bank card number is the same, it indicates that the transaction password is verified correctly. If the transaction password of the same bank card number is not the same, the transaction password is incorrect. At this time, the verification of the identity of the trader is suspended and a short message reminder of the transaction password is sent to the mobile phone. The user will send a verification message to the server through the mobile phone again, and the server continues to verify whether the transaction password sent by the user's mobile phone is correct, such as continuously verifying the transaction password of the same bank card within one day. Description
  • S151 Sending, to the mobile terminal, the message information of the transaction password error when the transaction password is incorrect; the step is specifically: after the financial server verifies the transaction password error, sending the card number of the mobile phone card corresponding to the bank card to the short message server, by using the short message The server sends a short message with the wrong transaction password to the mobile phone.
  • S152 Send an authentication code to the mobile terminal after the transaction password is verified correctly.
  • the step is specifically: after the financial server verifies that the transaction password is correct, a dynamic authentication code is randomly extracted from the authentication code database and sent to the mobile phone corresponding to the bank card through the short message server.
  • S16 the ATM machine obtains the bank card information inserted by the user and the authentication code information input by the user, and sends the bank card information and the authentication code information to the server for verification;
  • the step is specifically: after the user's mobile phone receives the authentication code sent by the short message server, after the user inserts the bank card, the ATM machine obtains the information of the bank card through the card reader, and transmits the information of the bank card to the financial server through the Internet.
  • the financial server analyzes the information of the bank card, and determines whether the bank card is bound to the mobile phone. If the bank card is bound to the mobile phone, the legal identity of the user is verified by the authentication code by default, if the bank card is not bound.
  • the mobile phone by default, verifies the legal identity of the user through the transaction password.
  • the ATM machine sends an instruction to authenticate the user legally through the authentication code, the ATM machine.
  • the screen displays the authentication code input window. The user inputs the authentication code into the authentication code input window through the keyboard of the ATM machine.
  • the ATM machine obtains the authentication code input by the user, and sends the authentication code information to the financial server for verification.
  • S17 Obtain authentication code information corresponding to the bank card information.
  • the step of the manual is specifically: using the mobile phone card number corresponding to the bank card, and then searching for the authentication code sent to the mobile phone from the short message server through the card number of the mobile phone card.
  • the step is specifically: comparing the authentication code sent by the ATM machine with the authentication code sent by the short message server to the mobile phone, and determining whether the authentication code sent by the ATM machine is the same as the authentication code corresponding to the bank card information, if both If the authentication code is the same, the authentication code sent by the ATM is considered to be the correct authentication code. If the authentication codes of the two are not the same, the authentication code sent by the ATM is considered to be the error verification code.
  • an instruction for the trader identity verification is sent to the ATM machine.
  • the step is specifically as follows: when the authentication code is verified correctly, the correct instruction of the authentication code is sent to the ATM machine. At this time, the entire process of verifying the identity of the trader is completed, and after the authentication code and the transaction password are correct, the trader is judged to be qualified. The user is allowed to enter the next transaction operation. When the user needs to withdraw money, the user inputs the withdrawal amount instruction, and sends it to the financial server to analyze whether the withdrawal amount is allowed. If the withdrawal amount is allowed, the ATM machine outputs. cash.
  • S182 When the authentication code is incorrectly verified, the ATM machine sends the message information with the wrong authentication code.
  • the step is specifically: when verifying that the authentication code sent by the ATM machine is different from the authentication code corresponding to the bank card information, sending the packet information with the authentication code error to the ATM machine, and the user can be allowed to input again through the ATM machine.
  • the authentication code when the ATM machine obtains the authentication code input by the user again, sends it to the financial server for analysis again, and determines whether the authentication code is correct again. If the user enters the authentication code three times in a day, the authentication code is aborted.
  • the embodiment further provides a system for verifying the identity of a trader on an ATM, the system comprising:
  • the mobile terminal 1 is configured to acquire a verification short message including the transaction password information and send the verification short message to the server;
  • Server 2 includes:
  • a storage device 21 configured to store mobile terminal card number information and bank card information, wherein the card number information of the mobile terminal and the card number information of the bank card are in one-to-one correspondence;
  • the reading device 22 is configured to read bank card information corresponding to the card number information of the mobile terminal that sends the verification short message;
  • the transaction password verification device 23 is configured to extract transaction password information included in the verification short message and verify whether the transaction password is the same as the transaction password corresponding to the bank card;
  • the authentication code generating and transmitting device 24 after the transaction password verification is correct, the server authentication code database randomly extracts an authentication code, and sends the authentication code to the mobile terminal;
  • the ATM machine 3 is configured to obtain the bank card information inserted by the user, and the bank card information and the authentication code information are sent to the server for verification;
  • the server further includes an authentication code verification device 25, configured to verify whether the authentication code sent by the ATM machine is the same as the authentication code generated by the authentication code generating and transmitting device and corresponding to the bank card information;
  • the server After the authentication code is verified correctly, the server sends an instruction to the ATM to pass the trader's identity verification.
  • the server further includes a counting device 26, configured to calculate the number of consecutive verifications of the transaction password and the authentication code error within a certain period of time, and continuously verify the transaction password error time within a certain period of time. After the number of books exceeds a certain threshold, the server suspends the identity verification of the trader holding the bank card.
  • the mobile terminal 1 is further configured to receive the authentication code sent by the server.
  • the user sends the transaction password to the server by sending a short message.
  • sending the short message is cumbersome, and for these user systems, it is also allowed to send a verification request to the server by calling a specific transaction number and A verification link is established with the server, and the user's transaction password can also be entered by dialing or by the user when the server requires the user to input.
  • this embodiment provides another method for verifying the identity of a trader on an ATM machine, and the method includes the following steps:
  • S25 Verify that the transaction password is the same as the transaction password corresponding to the bank card; S251: Send the transaction password error message information to the mobile terminal when the transaction password is incorrect; S252: After the transaction password verification is correct, move to the mobile The terminal sends an authentication code;
  • the step is specifically: when the server sends the authentication code to the mobile terminal, the time when the authentication code is sent is calculated, and of course, the server sends the mobile terminal to the mobile terminal due to the delay of receiving the short message. There is a large interval between the time when the authentication code is received and the time when the mobile terminal receives the authentication code. At this time, it is determined that the mobile terminal receives the short message containing the authentication code as the starting point of the timing.
  • the ATM machine obtains the bank card information inserted by the user and the authentication code information input by the user, and sends the bank card information and the authentication code information to the server for verification;
  • the step is specifically: when the server receives the authentication code sent by the ATM, records the moment when the server receives the authentication code.
  • S29 Calculate a time interval between sending an authentication code to the mobile terminal and receiving an authentication code sent by the ATM.
  • the step is specifically as follows: If the time interval between sending the authentication code from the server to the mobile terminal to the authentication code sent by the ATM machine is 1 hour, when the time interval between the two is more than 1 hour, the authentication code is determined. If the authentication code corresponding to the bank card is deleted from the server, the authentication code sent by the ATM is determined to be an illegal authentication code, and the transaction is determined. Is authentication failed. At this time, the server sends the result of the authentication code verification failure to the ATM machine that is performing the transaction processing, and the reason why the authentication code verification fails: The authentication code input timeout prompt.
  • S311 After the authentication code is verified correctly, an instruction for the trader identity verification is sent to the ATM machine.
  • S312 When the authentication code is incorrectly verified, the packet information with the authentication code error is sent to the ATM. As shown in FIG. 4, on the basis of Embodiment 1, this embodiment provides another system for verifying the identity of a trader on an ATM machine.
  • the mobile terminal 1 is configured to send a transaction request to the server by using a call, and acquire a transaction password input by the user and send the transaction password to the server;
  • Server 2 includes:
  • a storage device 21 configured to store mobile terminal card number information and bank card information, wherein the card number information of the mobile terminal and the card number information of the bank card are in one-to-one correspondence;
  • the reading device 22 is configured to read bank card information corresponding to the card number information of the mobile terminal that sends the verification request;
  • the transaction password verification device 23 is configured to verify whether the transaction password is the same as the transaction password corresponding to the bank card;
  • the authentication code generating and transmitting device 24 after the transaction password verification is correct, the server authentication code database randomly extracts an authentication code, and sends the authentication code to the mobile terminal;
  • the ATM machine 3 is configured to obtain the bank card information inserted by the user, and the bank card information and the authentication code information are sent to the server for verification;
  • the server further includes an authentication code verification device 25, configured to verify whether the authentication code sent by the ATM machine is the same as the authentication code generated by the authentication code generating and transmitting device and corresponding to the bank card information;
  • the server sends the trader's identity verification to the ATM machine. Explain the book order.
  • the server further includes a counting device 26, configured to calculate the number of consecutive verifications of the transaction password and the authentication code error within a certain period of time, and after continuously verifying that the number of transaction password errors exceeds a certain threshold within a certain period of time, The server suspends the authentication of the trader holding the bank card.
  • the mobile terminal 1 is further configured to receive an authentication code sent by the server.
  • the server 2 of the system also includes:
  • the cache device 27 is configured to store authentication code information corresponding to the card number information of the bank card, and the authentication code information has a one-to-one correspondence with the card number information of the bank card;
  • a timing device 28 configured to calculate a time interval for sending an authentication code to the mobile terminal and receiving an authentication code sent by the ATM;
  • the analyzing and judging device 29 is configured to determine whether the time interval exceeds a set threshold; when the time interval exceeds a set threshold, the server sends an instruction to the ATM machine that the trader identity verification fails and the authentication code times out ;
  • the server sends an instruction to the ATM to pass the trader's identity verification.
  • the timing device 28 is further configured to calculate a time period in which the authentication code information corresponding to the bank card number information stored in the cache device exists, and when the time when the authentication code exists exceeds the same time threshold as the time interval, Then, the authentication code information stored in the cache device is deleted.
  • the mobile terminal after the mobile terminal sends a transaction request to the server and establishes a verification link with the mobile terminal, the mobile terminal sends the transaction password input by the user to the server for verification.
  • the mobile terminal after the mobile terminal sends a transaction request to the server, the user may not directly request the transaction password verification to directly send the authentication code, so that the setting can be conveniently used by the user, and the operation is more convenient, but it will drop.
  • the security of low transaction is explained in this embodiment, the security of low transaction.
  • the embodiment further provides a method for using the system to perform an alarm. Specifically, as shown in FIG. 5, the method includes:
  • the step is specifically as follows:
  • the server monitors that the transaction password sent by the mobile terminal is an alarm code preset by the user, the user may encounter a dangerous situation such as kidnapping or coercion, and the transaction behavior of the bank card needs to be monitored to prevent the user from being prevented.
  • the deposit is forcibly taken away, but cannot be discovered in time.
  • the user is in an unsafe state due to the kidnapping or coercion.
  • the server also sends an authentication code to the mobile terminal, which not only alarms. The role does not prevent the criminals from discovering that their wrongdoing has been monitored.
  • S4612 Send the authentication code to the mobile terminal after the transaction password is verified correctly
  • S48 the ATM machine obtains the bank card information inserted by the user and the authentication code information input by the user, and sends the bank card information and the authentication code information to the server for verification;
  • S49 Obtain a location of the ATM machine that sends the monitored bank card information, and send the location information of the ATM machine to the public security alarm system;
  • the step is specifically: when the ATM machine sends the bank card information inserted by the user to the financial server, the server detects whether the bank card is in the monitored state, and if the bank card is in the monitored state, it will find out
  • the code information of the ATM machine that transmits the bank card information can find the location of the ATM machine through the coded information of the ATM machine, and after transmitting the location information of the ATM machine to the public security alarm system, it is easy to arrest the criminals. And field tracking. Whether the bank card is not a monitored bank card, the steps of the second embodiment are followed.
  • the advantage of this operation is that it always keeps the criminals in a hidden state of being monitored and tracked. Combined with the video surveillance system in the public security alarm system, it is easy to track the whereabouts of criminals, which can protect users and play very much. Good for the purpose of cracking down on criminals.
  • the remaining steps include:
  • S50 recording the time when the ATM sends the authentication code information to the server
  • S51 Calculate a time interval between sending an authentication code to the mobile terminal and receiving an authentication code sent by the ATM.
  • S522 Acquire the bank card information when the time interval does not exceed the set threshold.
  • the corresponding authentication code information of the book
  • the server of the system for verifying the identity of the trader on the ATM machine in this embodiment further includes, as shown in FIG. 6, as shown in FIG. 6:
  • the bank card monitoring device 30 is configured to start monitoring the bank card when the transaction password is an alarm code preset by the user;
  • the alarm device 31 is configured to acquire the location of the ATM machine that sends the monitored bank card information and send the location information of the ATM machine to the public security alarm system.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Marketing (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Finance (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Technology Law (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种金融交易验证的方法和系统,该方法包括移动终端向服务器发送交易请求,服务器验证交易请求的合法性,服务器在验证交易合法性通过后发送认证码,金融终端将用户输入的认证码发送给服务器进行验证,看用户输入的认证码是否与服务器发送给移动终端的认证码相同,如相同则认为认证码正确,同时对用户插入的银行卡的信息进行验证,验证该银行卡信息是否与所述移动终端的电话卡绑定的银行卡信息相同,如相同则认为取款者身份合法,允许其进入下一步的交易操作。上述技术方案安全性高,而且方法简单,用户操作简单,适用范围广。

Description

说 明 书 一种金融交易验证的方法和系统
【技术领域】
本发明属于金融交易安全技术领域, 涉及一种金融交易验证的方法和系 统。
【背景技术】
为了加强金融交易过程中的安全性, 人们想出来各种不同的办法, 通过 手机、个人电脑和 POS机均可实现非常安全的转账、 电子支付以及修改密码 等操作, 但是如果是涉及到现金交易, 则必须到自动柜员机 (ATM ) 上或者 是银行柜台进行存取。 对于小额存取款业务而言, 到银行柜台让银行工作人 员进行操作显得非常不方便, 而 ATM机由于其数量多, 取款无需排队或者排 队时间较短, 而且没有时间限制, 大大的方便了人们在日常生活中对小额金 融业务处理的需求, 但是由于 ATM机处于一种开放式的使用状态, 大多处于 无人看管的状态, 而且 ATM机涉及到现金交易, 而且即使是不法分子偷取了 合法用户账户的现金, 如果不能找到不法分子本人, 也很难以知道窃取的现 金的去向, 所以在 ATM机上进行交易的安全性问题尤为突出。
在目前 ATM机的使用过程中, 使用者是先将银行卡插入 ATM机中, 然 后按照 ATM机上的屏幕提出输入密码, 输入密码时, 必须通过 ATM机上的 键盘或触摸屏上的密码输入器进行输入, 密码验证通过后, 方可进行提款和 转账等金融业务的操作。 所以不法分子要想假冒合法用户进行取款业务, 首 先必须知道合法用户的银行卡信息以及银行卡的密码, 所有就有不法分子在 说 明 书
ATM机上或者门禁系统上安装读卡机获取银行卡的信息, 然后通过复制银行 卡, 并且通过安装摄像头或者密码记录器获取银行卡的密码, 就可以假冒合 法用户轻易地将钱盗取走, 给该卡的用户带来财产损失。
所以为了提高 ATM机交易的安全性, 就必须使不法分子难以获得合法用 户的银行卡信息或 /和密码即可。为了避免合法用户因用银行卡在 ATM机上进 行金融交易时导致的银行卡信息暴露的问题, 中国专利申请号为: 200610028515.8 的中国发明专利提供了一种利用手机终端进行取款或支付 的系统及实现方法, 所述的方法包括如下步骤: 将特定的银行卡与特定的手 机号码相绑定; 在金融终端上, 显示有终端服务信息; 用户利用手机直接拨 打特征代码, 也可以发送短信; 服务网络将信息发送到金融服务器; 金融服 务器找出与手机号码对应的银行卡信息传送至用户所在的金融终端; 用户输 入密码并识别后, 进行金融操作。 该专利所记载的利用手机终端进行取款或 者支付的技术存在以下几个弊端:
1 . 特征代码显示在 ATM机的显示屏上, 当 ATM机上此时有其他人在进 行交易操作时, 会挡住 ATM机的显示屏, 导致处于等待的人无法看到特征代 码, 也就不能在操作金融终端之前, 提前在手机终端上进行输入特征代码的 操作, 如果在排到自己进行金融交易时才开始用手机进行操作, 显然使整个 操作过程较慢, 增加了其他人排队等待取款的时间。 如果将特征代码印刷在 显示屏上方的墙壁上, 则有被不法分子修改的可能。
2. 在进行手机操作后, 还需要在金融终端上输入银行卡密码, 在输入银 行卡密码的过程中密码很有可能被不法分子截获, 造成了安全性下降。
3. 通过特征代码定位金融终端, 但是却不能准确判断用户的合法身份, 因为在一个金融终端上进行操作的用户会有很多, 如果用户在操作金融终端 说 明 书 之前通过手机输入特征代码, 而刚好排在该用户之前的为不法分子, 他提前 知道了用户的银行卡密码, 这样就很容易假冒该用户进行取款操作。
所以该专利所公开的利用手机终端进行取款或支付的系统及实现方法的 安全性不高, 而且操作较为不便。
专利申请号为: 201010116443.9的中国发明专利还公开了一种基于 ATM 的认证方法及系统, 所述基于 ATM的认证方法包括: 接收用户输入的包括签 约手机号码、 认证码、 取款金额以及交易密码的预约取款请求, 根据签约手 机号码从手机银行获取预设值的包括银行卡号、 认证码、 取款金额以及交易 密码的预约信息; 根据获取的预约取款信息对接收的预约取款请求进行认证, 以在认证成功时输出与预约取款请求中的取款金额相同数量的金额。 由于本 发明用户输入签约手机号码、 认证码、 取款金额以及交易密码等都是在 ATM 机上完成的, 由于 ATM机是一个开放的平台, 所以尽管设置了多重密码进行 保护, 但是只要不法分子偷窥到了以上信息就很容易窃取用户的存款。 安全 性并不高。
由于银行卡信息的保密性不如密码的保密性, 所以对密码的保密性将成 为金融交易安全性的最核心的根本, 而银行卡作为一种实物, 可以起到准确 识别用户身份的作用。 如果采用无卡取款, 只要非法用户获取到关于卡号和 密码的相关资料后, 将很容易窃取存款, 所以对采用无卡取款的安全性并不 高。
为了解决密码被非法截获的问题, 专利公开号为 CN10763692 A的中国 发明专利, 公开了一种 ATM机密码输入的系统, 用户通过自己手机上的发射 装置与 ATM机连线, 利用手机上的输入装置取代原先设置在 ATM机上的输 入装置, 以此来避免遭到摄像机或者假冒键盘记录密码, 在该专利中, 手机 说 明 书 包括一个发射单元, 发射单元是利用短距离传输技术的发射模块, ATM机包 括接收单元, 接收单元是利用短距离传输技术的接收模块, 用以接收发射模 块发射的个人密码, 发射单元和接收单元分别是利用蓝牙传输协议的发射模 块和接收模块, 在该专利中, 需要在 ATM机上和手机上均具备蓝牙模块时才 可以使用, 这样的话, 显著的增加了 ATM机的制造成本, 而且现有的 ATM 机上均没有设置蓝牙模块, 所以也增加了升级 ATM机的成本, 不仅如此, 由 于两个蓝牙模块在建立通讯链路时需要进行配对的过程, 只有双方均知道配 对密码时才可以配对成功, 如果默认的不需要配对密码即可配对成功, 很显 然会增加了交易风险, 同时这样会给不法分子以可乘之机, 不法分子也可以 通过与 ATM的蓝牙模块配对进行输入密码的操作, 通过输入错误的密码来以 扰乱用户的正常交易过程, 另一方面, 通过手机蓝牙模块向 ATM机发送交易 密码, 对于手机本身来说如果没有安装软件本身是难以操作的, 所以, 需要 在手机上安装一些特殊的软件才可以进行此项操作, 明显是增加了用户的升 级成本, 这样一来用户的使用率肯定会下降, 给此项技术的推广带来难度, 另一方面, 由于不是每一款手机都带有蓝牙通讯模块, 这样也限制了此技术 的应用范围, 所以, 综上所述该专利所记载的技术是一个消耗成本巨大, 但 是却难以带来经济效益和社会效益的不实用的技术。
【发明内容】
本发明的目的就是为了解决上述的技术问题, 提出了一种新的金融交易 验证的方法和系统。 本发明具有安全性高, 而且方法简单, 用户操作简单, 适用范围广的特点。
本发明的具体技术方案如下: 说 明 书 本发明提供一种金融交易验证方法, 其特征在于, 该方法包括: 获取移动终端发送的预先验证请求;
获取移动终端的卡号信息;
向绑定有银行卡信息的移动终端发送认证码信息;
金融终端获取用户交易账户的银行卡信息以及用户输入的认证码信息 并将所述银行卡信息和认证码信息发送给服务器进行验证;
验证所述金融终端发送的认证码与向绑定有该银行卡信息的移动终端 发送的认证码是否相同;
认证码相同后向金融终端发送交易验证通过的指令。
该方法进一步包括:
获取移动终端发送的验证信息;
获取该验证信息中包含的交易密码信息;
验证所述交易密码与所述银行卡所对应的交易密码是否相同; 交易密码验证正确后向所述移动终端发送认证码信息。
移动终端通过呼叫或者发送短信的方式发送预先验证请求, 所述交易密 码信息通过短信或者拨号或者按键输入的方式发送给服务器。
所述向移动终端发送的认证码为从认证码数据库中随机抽取的动态认 证码, 所述认证码被验证正确后失效。
该方法进一步包括:
计算向所述移动终端发送认证码与接收到所述金融终端发送的认证码的 时间间隔;
判断所述时间间隔是否超出设定的阀值; 说 明 书 当所述时间间隔超出设定的阀值时, 向金融终端发送交易者身份验证不 合格和认证码超时的指令;
当所述时间间隔没有超出设定的阀值时, 向金融终端发送交易者身份验 证合格的指令。
该方法进一步包括:
验证所述交易密码与该银行卡所对应的交易密码不相同时, 向移动终端 发送交易密码错误的报文信息, 在一定的时间段内连续多次交易密码验证错 误时, 向移动终端发送身份验证中止的报文信息, 并停止提取验证短信中包 含的交易密码信息。
该方法进一步包括:
验证所述金融终端发送的认证码与该银行卡信息相对应的认证码不相 同时, 向金融终端发送认证码错误的报文信息, 在一定的时间段内连续多次 认证码验证错误时, 向金融终端发送身份验证中止的报文信息, 并停止对金 融终端发送的认证码进行验证。
该方法进一步包括:
当所述移动终端发送的交易密码为用户预设的报警码时, 向所述移动终 端发送认证码的同时启动对该银行卡的监控;
获取发送被监控银行卡信息的金融终端位置;
向公安报警系统发送所述金融终端的位置信息。
本发明还提供一种金融交易验证系统, 其特征在于, 该系统包括: 移动终端, 用于向服务器发送预先验证请求;
服务器, 用于获取移动终端的卡号信息并且向绑定有银行卡信息的移动 说 明 书 终端发送认证码信息;
金融终端, 用于获取用户交易账户的银行卡信息以及用户输入的认证码 信息并将所述银行卡信息和认证码信息发送给服务器进行验证;
服务器验证所述金融终端发送的认证码与向绑定有该银行卡信息的移 动终端发送的认证码是否相同, 并且在认证码相同后服务器向金融终端发送 交易验证通过的指令。
所述移动终端还用于发送验证信息; 所述服务器验证所述交易密码与所 述银行卡所对应的交易密码是否相同, 并且在交易密码正确后服务器向移动 终端发送认证码信息。
移动终端通过呼叫或者发送短信的方式发送预先验证请求, 所述交易密 码信息通过短信或者拨号的方式发送给服务器。
所述向移动终端发送的认证码为从认证码数据库中随机抽取的动态认 证码, 所述认证码被验证正确后失效。
当所述移动终端发送的交易密码为用户预设的报警码时, 向所述移动终 端发送认证码的同时服务器启动对该银行卡的监控; 服务器获取发送被监控 银行卡信息的金融终端位置, 并且向公安报警系统发送所述金融终端的位置 信息。
所述服务器还包括:
计时装置, 用于计算向所述移动终端发送认证码与接收到所述金融终端 发送的认证码的时间间隔;
分析判断装置, 用于判断所述时间间隔是否超出设定的阀值; 当所述时间间隔超出设定的阀值时, 服务器向金融终端发送交易者身份 说 明 书 验证不合格和认证码超时的指令;
当所述时间间隔没有超出设定的阀值时, 服务器向金融终端发送交易者 身份验证合格的指令。
所述服务器还包括:
计次装置, 用于计算在一定的时间段内连续验证交易密码和认证码错误 的次数, 在一定的时间段内连续验证交易密码错误的次数超过一定的阀值后, 服务器中止对持有所述银行卡的交易者进行身份验证。
本发明有益的技术效果在于:
本发明通过移动终端发送交易密码, 然后又通过金融终端发送认证码, 并且使认证码、 交易密码分别与银行卡卡号和移动终端卡号相对应, 同时银 行卡信息又与移动终端的卡号信息相对应, 使得交易过程中对交易者的身份 进行双重认证, 提高了交易的安全性。
本发明通过移动终端向服务器发送交易请求, 当通过呼叫的方式发送交 易请求时并且通过拨号的方式输入交易密码, 能够使用户使用起来非常方便。 在移动终端向服务器发送交易请求后, 也可不要求用户进行交易密码验证直 接发送认证码, 这样设置能够方便用户的使用, 而且操作更加方便, 但是会 降低交易的安全性。
由于通过移动终端发送交易密码, 避免不法分子偷窥到或者非法截获到 交易密码, 而且服务器发送给移动终端的认证码是随机发送的动态认证码, 即使被不法分子偷窥到或者非法截获到, 也不会给银行账户带来不安全的因 素。
虽然认证码的输入过程是在公众场合, 但是认证码是随机动态的, 通过 说 明 书 设置动态的认证码, 该认证码在使用过一次后自动失效, 而且只有在一定的 时间内有效, 超过了一定的时间是无效的, 相比固定的交易密码而言, 具有 非常高的安全性。
通过设置报警码, 可以在用户遭遇暴力胁迫时, 巧妙而又隐蔽性的运用 对交易者身份进行验证的方法流程给服务器发送报警信息, 方便警方及时的 对银行账户进行跟踪和保护, 避免了用户的账户被胁迫取款的问题出现, 同 时能够起到非常好的对不法分子的打击和威胁力, 提高了用户的账户安全。
【附图说明】
图 1为本发明实施例 1 的方法流程图;
图 2为本发明实施例 1 的系统结构框图;
图 3为本发明实施例 2的方法流程图;
图 4为本发明实施例 2的系统结构框图;
图 5为本发明实施例 3的方法流程图;
图 6为本发明实施例 3的系统结构款图。
【具体实施方式】
本发明提供一种金融交易验证的方法和系统。 本发明通过移动终端发送 交易密码, 然后又通过金融终端发送认证码, 并且使认证码、 交易密码分别 与银行卡卡号和移动终端卡号相对应, 同时银行卡信息又与移动终端的卡号 信息相对应, 使得交易过程中对交易者的身份进行双重认证, 提高了交易的 安全性。 说 明 书 本发明的金融终端包括 POS机、 ATM机、 银行柜员机以及其他银行交 易终端。
由于用户在 ATM机上取款之前有足够的时间去通过移动终端进行交易 密码的验证, 所以本发明的方法比较适合于在 ATM机上交易时对交易者身份 进行验证, 下面的实施例以用户在 ATM机上取款为例对本发明的金融交易方 法和系统进行说明, 但是并不是对本发明的保护范围进行限制。
实施例 1
如图 1所示, 本实施例提供一种对 ATM机上的交易者身份进行验证的方 法, 该方法包括如下步骤:
S11 : 获取移动终端发送的预先验证短信;
该步骤具体为: 用户在 ATM机上取款之前, 预先通过移动终端 (例如 手机) 向服务器发送交易密码的验证短信, 例如可以向中国工商银行的服务 器发送交易密码: 457523, 可以通过手机号码为 " 13510617608" 的手机编 写短信内容为 " QK#457523# " ( QK 为取款的拼音的首字母) 发送到 "955881000 ", 所述交易密码 "457523"为用户在工商银行柜台经人工完成 身份验证后设置的合法的交易密码, 用户只有发送短信包含正确的交易密码 的内容后, 才能被银行的服务器通过验证。
S12: 获取发送短信的移动终端的卡号信息;
该步骤具体为: 通过手机发送的短信, 从而获知该注册登记该移动终端 的 SIM卡的卡号信息。 在上述步骤中, 手机号码为 " 13510617608" 的移动 终端向服务器发送预先验证短信后, 短信服务器即可获知该手机号码为 13510617608。 说 明 书
S13: 获取与该移动终端的卡号绑定的银行卡信息;
该步骤具体为: 号码为 " 13510617608"的手机预先在银行柜台通过人 工设置, 将该手机号码与卡号为: "6240993233994435" 的银行卡相绑定, 通过手机号码可以査询到与该手机号码相对应的银行卡卡号, 也可以通过银 行卡卡号查询到与该银行卡卡号相对应的手机号码, 一个手机号码可以与一 家银行的一个卡号相绑定, 一个手机号码可以绑定多家银行的银行卡。 区别 是哪一家银行的银行卡可以通过发送短信对方的号码。 短信服务器获取该手 机号码之后通过在数据库中寻找到与该手机号码相对应的银行卡的卡号信 息, 如果在数据库中寻找不到该手机号码对应的银行卡的卡号信息, 则表明 该用户没有预先将手机卡与银行卡进行绑定, 此时终止交易者身份的验证工 作。
S14: 提取验证短信中包含的交易密码信息;
该步骤具体为: 手机通过发送短信到移动通信网络中的短信服务器, 短 信服务器提取短信内容 "QK#457523#" 中的交易密码 "457523"后将该交 易密码发送到金融服务器验证。
S15: 验证所述交易密码与该银行卡所对应的交易密码是否相同; 该步骤具体为: 将手机发送的交易密码 "457523 "和通过手机卡号查找 到银行卡卡号与金融服务器中存储的银行卡卡号和该银行卡卡号对应的交易 密码做比对, 如果相同银行卡卡号的交易密码也是相同的, 则表明交易密码 验证正确, 如果相同银行卡卡号的交易密码不相同, 则表明交易密码不正确, 此时暂停交易者身份的验证工作并向手机发送交易密码错误的短信提醒。 用 户会再次通过手机向服务器发送验证短信, 服务器继续验证用户手机发送的 交易密码是否正确, 如在一天之内连续验证到同一银行卡的交易密码错误三 说 明 书
次, 中止该银行卡的交易密码验证 24小时, 并且向手机发送交易密码验证中 止的短信息。
S151: 交易密码错误时向所述移动终端发送交易密码错误的报文信息; 该步骤具体为: 在金融服务器验证交易密码错误后, 向短信服务器发送 该银行卡对应的手机卡的卡号, 通过短信服务器向手机发送交易密码错误的 短信息。
S152: 交易密码验证正确后向所述移动终端发送认证码;
该步骤具体为: 在金融服务器验证交易密码正确后, 随机从认证码数据 库中抽取一动态的认证码通过短信服务器发送给该银行卡对应的手机。
S16: ATM机获取用户插入的银行卡信息以及用户输入的认证码信息并 将所述银行卡信息和认证码信息发送给服务器进行验证;
该步骤具体为: 在用户手机接收到短信服务器发送的认证码后, 用户插 入银行卡后, ATM机通过读卡器获取银行卡的信息, 并将该银行卡的信息通 过互联网传输给金融服务器, 金融服务器对该银行卡的信息进行分析, 判断 出该银行卡是否绑定有手机, 如果该银行卡绑定有手机则默认通过认证码对 用户的合法身份进行验证, 如果该银行卡没有绑定手机, 则默认通过交易密 码对通过用户的合法身份进行验证, 在银行的金融服务器检测到该银行卡绑 定有手机后,像 ATM机发送通过认证码对用户合法进行身份验证的指令, ATM 机的屏幕显示认证码输入窗口, 用户通过 ATM机的键盘将接收到认证码输入 到认证码输入窗口中, ATM机获取用户输入的认证码, 将认证码信息发给金 融服务器进行验证。
S17: 获取与所述银行卡信息相对应的认证码信息; 说 明 书 该步骤具体为: 通过银行卡对应的手机卡卡号, 再通过手机卡的卡号从 短信服务器中查找出发送给所述手机的认证码。
S18:验证所述 ATM机发送的认证码与该银行卡信息相对应的认证码是 否相同;
该步骤具体为: 将 ATM机发送的认证码与短信服务器发送给手机的认 证码进行比较, 判断所述 ATM机发送的认证码与该银行卡信息相对应的认证 码是否相同, 如果两者的认证码相同, 则认为 ATM机发送的认证码为正确的 认证码, 如果两者的认证码不相同, 则认为 ATM机发送的认证码为错误验证 码。
S181: 认证码验证正确后向 ATM机发送交易者身份验证合格的指令。 该步骤具体为: 当认证码验证正确后向 ATM机发送认证码正确的指令, 此时, 完成交易者身份验证的整个过程, 认证码和交易密码均正确后, 判断 交易者身份验证合格, 此时允许用户进入下一歩的交易操作, 当用户需要取 款时, 获取用户输入的取款数额指令, 发送给金融服务器分析判断其取款数 额是否被允许, 如果该取款数额是被允许的, 通过 ATM机输出现金。
S182: 认证码验证错误时, 向 ATM机发送认证码错误的报文信息。 该步骤具体为: 验证所述 ATM机发送的认证码与该银行卡信息相对应的 认证码不相同时, 向 ATM机发送认证码错误的报文信息, 此时可以允许用户 再次通过 ATM机输入认证码, 当 ATM机再次获取到用户输入的认证码后, 再次发送给金融服务器进行分析, 判断再次输入是认证码是否正确, 用户在 一天之内连续 3次输入的认证码错误, 则中止对该银行卡对应的认证码的验 证, 并且向 ATM机发送身份验证中止的报文信息。 说 明 书
如图 2所示, 本实施例还提供一种对 ATM机上的交易者身份进行验证的 系统, 该系统包括:
移动终端 1, 用于获取包含交易密码信息的验证短信并将所述验证短信 发送给服务器;
服务器 2, 所述服务器 2包括:
存储装置 21,用于存储移动终端卡号信息和银行卡信息,所述移动终端 的卡号信息与银行卡的卡号信息一一对应;
读取装置 22,用于读取与发送验证短信的移动终端的卡号信息相对应的 银行卡信息;
交易密码验证装置 23,用于提取验证短信中包含的交易密码信息并验证 该交易密码是否与该银行卡所对应的交易密码是否相同;
认证码生成和发送装置 24;在交易密码验证正确后,服务器认证码数据 库中随机抽取一认证码, 并将该认证码发送给所述移动终端;
ATM机 3, 用于获取用户插入的银行卡信息述银行卡信息和认证码信息 发送给服务器进行验证;
所述服务器还包括认证码验证装置 25, 用于验证所述 ATM机发送的认 证码与所述认证码生成和发送装置生成的并且和银行卡信息相对应的认证码 是否相同;
在认证码验证正确后, 服务器向 ATM机发送交易者身份验证合格的指 令。
所述服务器还包括计次装置 26,用于计算在一定的时间段内连续验证交 易密码和认证码错误的次数, 在一定的时间段内连续验证交易密码错误的次 说 明 书 数超过一定的阀值后, 服务器中止对持有所述银行卡的交易者进行身份验证 所述移动终端 1还用于接收服务器发送的认证码。
实施例 2
上述的实施例中, 用户通过发送短信的方式将交易密码发送给服务器, 对于有一些用户而言, 发送短信较为繁琐, 对于这些用户系统还允许其通过 呼叫特定的交易号码向服务器发送验证请求并且与服务器建立验证链路, 用 户的交易密码也可以通过拨号的方式或者在服务器要求用户输入的时候, 用 户通过按键输入。
另一方面, 为了避免不法分子在偷窥到或者非法截获到服务器发送给移 动终端的认证码, 将认证码设置成在一定的时间内有效, 而且在使用后自动 失效。 具体的, 如图 3所示, 本实施例提供另外一种对 ATM机上的交易者身 份进行验证的方法, 该方法包括如下步骤:
S21: 获取移动终端发送的验证请求;
S22: 获取呼叫服务器的移动终端的卡号信息;
S23: 获取与该移动终端的卡号绑定的银行卡信息;
S24: 获取用户输入的交易密码信息;
S25: 验证所述交易密码与该银行卡所对应的交易密码是否相同; S251: 交易密码错误时向所述移动终端发送交易密码错误的报文信息; S252: 交易密码验证正确后向所述移动终端发送认证码;
S26: 记录向移动终端发送认证码的时刻;
该歩骤具体为: 当服务器向移动终端发送认证码时, 计算认证码被发送 时的时刻, 当然有的时候, 因短信接收延迟的原因, 服务器向移动终端发送 说 明 书 认证码的时刻与移动终端收到认证码的时刻上会有较大的间隔, 此时以判断 移动终端收到包含有认证码的短信为计时的起点。
S27: ATM机获取用户插入的银行卡信息以及用户输入的认证码信息并 将所述银行卡信息和认证码信息发送给服务器进行验证;
S28: 记录 ATM机将认证码信息发送给服务器的时刻;
该步骤具体为: 在服务器接收到 ATM机发送的认证码时, 记录下服务 器接收到认证码的时刻。
S29:计算向所述移动终端发送认证码与接收到所述 ATM机发送的认证 码的时间间隔;
S30: 判断所述时间间隔是否超出设定的阀值;
S301 : 当所述时间间隔超出设定的阀值时, 向 ATM机发送交易者身份 验证不合格和认证码超时的指令;
该步骤具体为: 假如之前设定从服务器向移动终端发送认证码到接收到 ATM机发送的认证码最大的时间间隔是 1小时, 当计算得到两者的时间间隔 超过 1 小时, 则判定认证码失效, 从服务器中删除与该银行卡对应的认证码 记录, 当服务器中与该银行卡对应的正确认证码删除掉后, ATM机发送的认 证码则被判定为非法的认证码, 判定交易者是身份验证失败。 此时服务器向 正在进行交易处理的 ATM机发送认证码验证失败的结果, 以及认证码验证失 败的原因: 认证码输入超时的提示。
S302: 当所述时间间隔没有超出设定的阀值时,获取与所述银行卡信息 相对应的认证码信息;
S31:验证所述 ATM机发送的认证码与该银行卡信息相对应的认证码是 说 明 书 否相同;
S311 : 认证码验证正确后向 ATM机发送交易者身份验证合格的指令。 S312: 认证码验证错误时, 向 ATM机发送认证码错误的报文信息。 如图 4所示, 在实施例 1的基础之上, 本实施例提供另外一种对 ATM机 上交易者身份进行验证的系统,
移动终端 1, 用于通过呼叫向服务器发送交易请求, 并且获取用户输入 的交易密码并将所述交易密码发送给服务器;
服务器 2, 所述服务器 2包括:
存储装置 21,用于存储移动终端卡号信息和银行卡信息,所述移动终端 的卡号信息与银行卡的卡号信息一一对应;
读取装置 22,用于读取与发送验证请求的移动终端的卡号信息相对应的 银行卡信息;
交易密码验证装置 23,用于验证交易密码是否与该银行卡所对应的交易 密码是否相同;
认证码生成和发送装置 24;在交易密码验证正确后,服务器认证码数据 库中随机抽取一认证码, 并将该认证码发送给所述移动终端;
ATM机 3, 用于获取用户插入的银行卡信息述银行卡信息和认证码信息 发送给服务器进行验证;
所述服务器还包括认证码验证装置 25, 用于验证所述 ATM机发送的认 证码与所述认证码生成和发送装置生成的并且和银行卡信息相对应的认证码 是否相同;
在认证码验证正确后, 服务器向 ATM机发送交易者身份验证合格的指 说 明 书 令。
所述服务器还包括计次装置 26,用于计算在一定的时间段内连续验证交 易密码和认证码错误的次数, 在一定的时间段内连续验证交易密码错误的次 数超过一定的阀值后, 服务器中止对持有所述银行卡的交易者进行身份验证 所述移动终端 1还用于接收服务器发送的认证码。
该系统的服务器 2还包括:
缓存装置 27, 用于存储有与银行卡的卡号信息相对应的认证码信息, 所 述认证码信息与银行卡的卡号信息一一对应;
计时装置 28, 用于计算向所述移动终端发送认证码与接收到所述 ATM 机发送的认证码的时间间隔;
分析判断装置 29, 用于判断所述时间间隔是否超出设定的阀值; 当所述时间间隔超出设定的阀值时, 服务器向 ATM机发送交易者身份验 证不合格和认证码超时的指令;
当所述时间间隔没有超出设定的阅值时, 服务器向 ATM机发送交易者 身份验证合格的指令。
所述计时装置 28还用于计算缓存装置中存储的与银行卡卡号信息相对 应的认证码信息所存在的时间, 当所述认证码存在的时间超出与所述时间间 隔相同的时间阀值, 则删除缓存装置中存储的认证码信息。
在本实施例中, 移动终端向服务器发送交易请求后并且与移动终端建立 验证链路后, 移动终端再将用户输入的交易密码发送给服务器验证。 当然, 移动终端向服务器发送交易请求后, 也可不要求用户进行交易密码验证直接 发送认证码, 这样设置能够方便用户的使用, 而且操作更加方便, 但是会降 说 明 书 低交易的安全性。
实施例 3
在实施例 2所述的对 ATM机上的交易者身份进行验证的系统基础之上, 本实施例还提供了利用该系统进行报警的方法, 具体的, 如图 5所示, 该方 法包括:
S41: 设置与银行卡相对应的报警码;
S42: 获取移动终端发送的验证请求;
S43: 获取呼叫服务器的移动终端的卡号信息;
S44: 获取与该移动终端的卡号绑定的银行卡信息;
S45: 获取用户输入的交易密码信息;
S46: 验证所述交易密码与该银行卡所对应的报警码是否相同;
S461 : 当交易密码与用户预设的报警码不相同时,验证所述交易密码与 该银行卡所对应的交易密码是否相同;
S462: 当交易密码为用户预设的报警码时, 向移动终端发送认证码, 同 时启动对该银行卡的监控;
该步骤具体为: 当服务器监控到移动终端发送的交易密码为用户预先设 置的报警码时, 表明用户可能遭遇到绑架或者胁迫等危险情况, 此时需要对 银行卡的交易行为进行监控, 防止用户的存款被强迫取走, 而不能及时发现 的情况, 由于用户遭遇到绑架或者胁迫情况, 用户处于不安全的状态, 为了 保护用户的安全, 服务器同样向移动终端发送认证码, 既起到报警的作用, 又不至于使不法分子发现他们的不法行为已经被监控。
S4611 :交易密码错误时向所述移动终端发送交易密码错误的报文信息; 说 明 书
S4612: 交易密码验证正确后向所述移动终端发送认证码;
S47: 记录向移动终端发送认证码的时刻;
S48: ATM机获取用户插入的银行卡信息以及用户输入的认证码信息并 将所述银行卡信息和认证码信息发送给服务器进行验证;
S49 :获取发送被监控的银行卡信息的 ATM机的位置并向公安报警系统 发送所述 ATM机的位置信息;
该歩骤具体为: 当 ATM机将用户插入的银行卡信息发送给金融服务器 时, 服务器检测所述银行卡是否处于被监控的状态, 如果该银行卡处于被监 控的状态, 则将査找出发送该银行卡信息的 ATM机的编码信息, 通过 ATM 机的编码信息从而能够寻找出该 ATM机的位置, 将该 ATM机的位置信息发 送给公安报警系统后, 很容易对不法分子进行抓捕和实地的跟踪。 无论所述 银行卡不是被监控的银行卡时, 都按照实施例 2的歩骤进行操作。 这样操作 的好处在于始终使不法分子处于一种隐蔽性的被监控和被跟踪的状态, 结合 公安报警系统中的视频监控系统, 很容易跟踪不法分子的行踪, 既能够保护 用户又能够起到很好的打击不法分子的目的。 即余下的步骤包括:
S50 : 记录 ATM机将认证码信息发送给服务器的时刻;
S51:计算向所述移动终端发送认证码与接收到所述 ATM机发送的认证 码的时间间隔;
S52: 判断所述时间间隔是否超出设定的阀值;
S521 : 当所述时间间隔超出设定的阀值时, 向 ATM机发送交易者身份 验证不合格和认证码超时的指令;
S522:当所述时间间隔没有超出设定的阀值时,获取与所述银行卡信息 说 明 书 相对应的认证码信息;
S53:验证所述 ATM机发送的认证码与该银行卡信息相对应的认证码是 否相同;
S531: 认证码验证正确后向 ATM机发送交易者身份验证合格的指令。
S532: 认证码验证错误时, 向 ATM机发送认证码错误的报文信息。 本实施例的对 ATM机上的交易者身份进行验证的系统的服务器在实施 例 2的基础上还包括, 如图 6所示:
银行卡监控装置 30,用于当交易密码为用户预设的报警码时,启动对该 银行卡的监控;
报警装置 31, 用于获取发送被监控的银行卡信息的 ATM机的位置并向 公安报警系统发送所述 ATM机的位置信息。
需要说明的是, 普通的技术人员针对上述的实施例还可以很容易的想到 其他的技术方案, 只要这些技术方案在本发明的构思范围内, 应等同于本专 利的技术方案, 属于本专利的保护范围。

Claims

权 利 要 求 书
1 . 一种金融交易验证方法, 其特征在于, 该方法包括:
获取移动终端发送的预先验证请求;
获取移动终端的卡号信息;
向绑定有银行卡信息的移动终端发送认证码信息;
金融终端获取用户交易账户的银行卡信息以及用户输入的认证码信息并 将所述银行卡信息和认证码信息发送给服务器进行验证;
验证所述金融终端发送的认证码与向绑定有该银行卡信息的移动终端发 送的认证码是否相同;
认证码相同后向金融终端发送交易验证通过的指令。
2.根据权利要求 1所述的金融交易验证方法, 其特征在于, 该方法进一步 包括:
获取移动终端发送的验证信息;
获取该验证信息中包含的交易密码信息;
验证所述交易密码与所述银行卡所对应的交易密码是否相同;
交易密码验证正确后向所述移动终端发送认证码信息。
3.根据权利要求 2所述的金融交易验证方法, 其特征在于, 移动终端通过 呼叫或者发送短信的方式发送预先验证请求, 所述交易密码信息通过短信或者 拨号或者按键输入的方式发送给服务器。
4. 根据权利要求 1 -3任一所述的金融交易验证方法, 其特征在于, 所述 向移动终端发送的认证码为从认证码数据库中随机抽取的动态认证码, 所述认 证码被验证正确后失效。
5. 根据权利要求 4所述的金融交易验证方法, 其特征在于, 该方法进一 权 利 要 求 书
步包括:
计算向所述移动终端发送认证码与接收到所述金融终端发送的认证码的时 间间隔;
判断所述时间间隔是否超出设定的阀值;
当所述时间间隔超出设定的阔值时, 向金融终端发送交易者身份验证不合 格和认证码超时的指令;
当所述时间间隔没有超出设定的阀值时, 向金融终端发送交易者身份验证 合格的指令。
6. 根据权利要求 2所述的金融交易验证方法, 其特征在于, 该方法进一 步包括:
当所述移动终端发送的交易密码为用户预设的报警码时, 向所述移动终端 发送认证码的同时启动对该银行卡的监控;
获取发送被监控银行卡信息的金融终端位置;
向公安报警系统发送所述金融终端的位置信息。
7. 一种金融交易验证系统, 其特征在于, 该系统包括:
移动终端, 用于向服务器发送预先验证请求;
服务器, 用于获取移动终端的卡号信息并且向绑定有银行卡信息的移动终 端发送认证码信息;
金融终端, 用于获取用户交易账户的银行卡信息以及用户输入的认证码信 息并将所述银行卡信息和认证码信息发送给服务器进行验证;
服务器验证所述金融终端发送的认证码与向绑定有该银行卡信息的移动 终端发送的认证码是否相同, 并且在认证码相同后服务器向金融终端发送交易 权 利 要 求 书
验证通过的指令。
8.根据权利要求 7所述的金融交易验证系统, 其特征在于, 所述移动终端 还用于发送验证信息; 所述服务器验证所述交易密码与所述银行卡所对应的交 易密码是否相同, 并且在交易密码正确后服务器向移动终端发送认证码信息。
9.根据权利要求 7或 8所述的金融交易验证系统, 其特征在于, 所述向移 动终端发送的认证码为从认证码数据库中随机抽取的动态认证码, 所述认证码 被验证正确后失效。
10. 根据权利要求 8所述的金融交易验证系统, 其特征在于, 当所述移动 终端发送的交易密码为用户预设的报警码时, 向所述移动终端发送认证码的同 时服务器启动对该银行卡的监控; 服务器获取发送被监控银行卡信息的金融终 端位置, 并且向公安报警系统发送所述金融终端的位置信息。
PCT/CN2012/078842 2011-12-14 2012-07-19 一种金融交易验证的方法和系统 WO2013086857A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110418308.4 2011-12-14
CN 201110418308 CN102402773A (zh) 2011-12-14 2011-12-14 一种金融交易验证的方法和系统

Publications (1)

Publication Number Publication Date
WO2013086857A1 true WO2013086857A1 (zh) 2013-06-20

Family

ID=45884953

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/078842 WO2013086857A1 (zh) 2011-12-14 2012-07-19 一种金融交易验证的方法和系统

Country Status (2)

Country Link
CN (2) CN102402773A (zh)
WO (1) WO2013086857A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016070295A1 (es) 2014-11-06 2016-05-12 Toc S.A. Método de autenticación de dos factores para aumentar la seguridad de las transacciones entre un usuario y un punto o sistema de transacción

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102402773A (zh) * 2011-12-14 2012-04-04 王筱雨 一种金融交易验证的方法和系统
WO2014043905A1 (zh) * 2012-09-22 2014-03-27 Feng Lin 结合智能手机对atm机上交易者身份信息进行验证的方法和系统
CN104113514B (zh) * 2013-04-19 2019-01-22 腾讯科技(深圳)有限公司 信息安全的处理方法和装置
CN103745538B (zh) * 2013-12-31 2016-09-21 宇龙计算机通信科技(深圳)有限公司 金融账户的密码保护方法及系统
CN105450590B (zh) * 2014-07-31 2018-12-28 阿里巴巴集团控股有限公司 一种提供资源的方法和设备
CN104240370B (zh) * 2014-09-24 2016-09-07 福建今日特价网络有限公司 基于动态二维码的存取款系统
CN104240371B (zh) * 2014-09-24 2016-08-17 福建今日特价网络有限公司 基于静态二维码的存取款系统
US11966907B2 (en) * 2014-10-25 2024-04-23 Yoongnet Inc. System and method for mobile cross-authentication
CN104320422A (zh) * 2014-11-18 2015-01-28 中国建设银行股份有限公司 一种密码管理方法,相关设备及系统
CN104462934B (zh) * 2014-12-01 2018-02-27 联想(北京)有限公司 一种信息处理方法及电子设备
CN105426735A (zh) * 2015-11-05 2016-03-23 上海斐讯数据通信技术有限公司 基于移动终端进行身份验证的系统及方法
US10114854B2 (en) * 2015-11-17 2018-10-30 International Business Machines Corporation Validation rule management across entities
CN106228368A (zh) * 2016-08-03 2016-12-14 四川易想电子商务有限公司 一种多重认证的安全交易方法
CN106846666B (zh) * 2017-01-18 2019-05-07 北京云知科技有限公司 一种基于区块链的存取款方法
CN114582078B (zh) * 2020-12-01 2024-04-16 比亚迪股份有限公司 自助存取款方法及自助存取款系统
CN114023015A (zh) * 2021-11-04 2022-02-08 中国银行股份有限公司 一种业务处理方法、系统及装置
CN115131923A (zh) * 2022-06-27 2022-09-30 中国银行股份有限公司 基于身份验证结果解锁密码键盘的方法、设备及产品

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1427609A (zh) * 2001-12-20 2003-07-02 西北工业大学 一次性口令及交易认证方法
CN1832401A (zh) * 2006-04-06 2006-09-13 陈珂 一种保护帐号密码安全的方法
CN101727646A (zh) * 2008-10-31 2010-06-09 深圳富泰宏精密工业有限公司 网络银行报警系统及方法
CN102368338A (zh) * 2011-04-09 2012-03-07 冯林 一种对atm机上交易者身份进行验证的方法和系统
CN102402773A (zh) * 2011-12-14 2012-04-04 王筱雨 一种金融交易验证的方法和系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1435985A (zh) * 2002-01-30 2003-08-13 鸿联九五信息产业股份有限公司 动态密码安全系统及动态密码生成方法
US7415720B2 (en) * 2003-10-31 2008-08-19 Samsung Electronics Co., Ltd. User authentication system and method for controlling the same
CN101140672A (zh) * 2007-10-23 2008-03-12 张师祝 一种对银行卡持卡者真实身份识别方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1427609A (zh) * 2001-12-20 2003-07-02 西北工业大学 一次性口令及交易认证方法
CN1832401A (zh) * 2006-04-06 2006-09-13 陈珂 一种保护帐号密码安全的方法
CN101727646A (zh) * 2008-10-31 2010-06-09 深圳富泰宏精密工业有限公司 网络银行报警系统及方法
CN102368338A (zh) * 2011-04-09 2012-03-07 冯林 一种对atm机上交易者身份进行验证的方法和系统
CN102402773A (zh) * 2011-12-14 2012-04-04 王筱雨 一种金融交易验证的方法和系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016070295A1 (es) 2014-11-06 2016-05-12 Toc S.A. Método de autenticación de dos factores para aumentar la seguridad de las transacciones entre un usuario y un punto o sistema de transacción

Also Published As

Publication number Publication date
CN102402773A (zh) 2012-04-04
CN102663642A (zh) 2012-09-12

Similar Documents

Publication Publication Date Title
WO2013086857A1 (zh) 一种金融交易验证的方法和系统
WO2012139350A1 (zh) 一种对atm机上交易者身份进行验证的方法和系统
US11832099B2 (en) System and method of notifying mobile devices to complete transactions
US10402803B1 (en) Initiating a kiosk transaction
JP6479769B2 (ja) 顧客制御口座の施錠機能を提供する方法及びシステム
US10467604B1 (en) ATM transaction with a mobile device
RU2608002C2 (ru) Обработка закодированной информации
CN102197407A (zh) 安全支付交易的系统和方法
KR20170039672A (ko) 장치에 대해 클라이언트를 인증하기 위한 시스템 및 방법
CN102411817B (zh) 一种鉴别银行自助设备的方法及系统
US20120303527A1 (en) Process and host and computer system for card-free authentication
CN104967553A (zh) 消息交互方法和相关装置及通信系统
KR20140065818A (ko) 안전 계좌 확인 시스템 및 방법
WO2013064269A1 (en) A method, transaction unit, terminal unit and backend server unit for processing a personal identification number
WO2015029064A2 (en) A computer implemented system and method for facilitating cardless transactions
CN107862601B (zh) 一种自动定位报警的取现方法及系统
TWM637453U (zh) 基於晶片金融卡的fido身分驗證系統
CN111754237B (zh) 一种转账交易的验证方法及装置
CN106973032B (zh) 一种信息认证方法、服务器、终端设备及系统
JP6511409B2 (ja) 金融機関における取引施錠システム及び取引施錠方法
JP2007034626A (ja) Atm利用限度額設定方法、atm利用限度額設定装置およびatm利用限度額設定用プログラム
WO2012155818A1 (zh) 一种基于可信资源保护银行用户信息的方法和装置
US9462467B2 (en) Secure processing system for use with a portable communication device
EP3971851A1 (en) An electronic device, method and computer program product for instructing performance of a transaction which has been requested at an automated teller machine
KR20040098407A (ko) 금융거래에 있어서 비상비밀번호 관리 시스템 및 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12857612

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205N DATED 21/08/2014)

122 Ep: pct application non-entry in european phase

Ref document number: 12857612

Country of ref document: EP

Kind code of ref document: A1