WO2013087018A1 - 双信息手机现场支付方法以及双信息手机现场支付系统 - Google Patents

双信息手机现场支付方法以及双信息手机现场支付系统 Download PDF

Info

Publication number
WO2013087018A1
WO2013087018A1 PCT/CN2012/086599 CN2012086599W WO2013087018A1 WO 2013087018 A1 WO2013087018 A1 WO 2013087018A1 CN 2012086599 W CN2012086599 W CN 2012086599W WO 2013087018 A1 WO2013087018 A1 WO 2013087018A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
mobile phone
customer
transaction
merchant
Prior art date
Application number
PCT/CN2012/086599
Other languages
English (en)
French (fr)
Inventor
陈逢源
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Publication of WO2013087018A1 publication Critical patent/WO2013087018A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/325Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
    • G06Q20/3255Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks using mobile network messaging services for payment, e.g. SMS
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification

Definitions

  • the present invention relates to a payment method using a mobile phone and a system thereof, and in particular to using a mobile phone
  • bank cards such as debit cards and credit cards have been more and more widely used in consumers' frequent consumer transactions. Consumers do not have to carry a lot of cash, they only need to use a bank card to install a bank terminal.
  • POS machine consumer sites for consumer settlement. This provides great convenience for consumption.
  • consumers also have certain security risks when using bank cards to conduct consumer settlement on bank terminals. For example, consumers may have 4 credit card accounts and passwords being stolen during consumption.
  • the bank card when using a bank card for consumption, the bank card must be carried, and the use of the general bank card is limited to the use of the bank card.
  • SIMPass is a versatile SIM card that supports SIM card functionality and mobile payment.
  • SIMPass runs on the phone and offers two solutions to solve the problem of antenna layout required for non-contact interface work: custom handset solutions and low-cost antenna group solutions.
  • RFID-SIM is a product that penetrates the mobile phone field with dual-interface smart card technology.
  • RFID-SIM has both the functionality of a SIM card and short-range wireless communication.
  • NFC is a contactless identification and interconnection technology.
  • the NFC mobile phone has a built-in NFC chip, which is part of the RFID module. It can be used as an RFID passive tag to pay for it. It can also be used as an RFID reader for data exchange and collection.
  • the customer mobile terminal and/or the merchant acceptance terminal need to be specially modified. Therefore, the above mobile payment technology has the problems of high implementation cost, difficulty in rapid promotion, and limited restriction. Summary of the invention
  • the present invention has been made in view of the above problems, and aims to provide a dual information mobile phone on-site payment method and a dual information mobile phone on-site payment system that can be realized by using two-way mobile phone information interaction without modifying a customer mobile terminal or a merchant acceptance terminal.
  • the dual information mobile phone on-site payment method of the present invention is characterized in that a method for realizing mobile payment between a core system and a card issuing bank system by using a customer mobile phone terminal and a merchant mobile phone terminal, the method comprising: transmitting transaction authorization request information from the merchant mobile phone terminal a transaction authorization request step sent to the core system; a legality verification step of verifying the legality of the transaction and the legality verification of the customer for the transaction authorization request information; performing authorization verification on the bank authentication for the transaction authorization request information verified by the legality and The authorization request forwarding and notification step of transmitting the authorization result information to the client mobile terminal in the case where the authorization verification is successful; the step of transmitting the transaction settlement request from the merchant mobile terminal to the transaction settlement request of the core system according to the authorization result information obtained from the customer; The verification request legality verification step of verifying the legality of the transaction settlement request.
  • the method further comprises: registering customer information in the core system and establishing an association of customer information registration and bank association steps between the client mobile terminal and the bank card in the core system; and in the core system Establish a merchant information registration step associated with the merchant information between the merchant mobile terminal and the merchant.
  • the step of registering the customer information and the bank association comprises the steps of:
  • a customer information registration step of registering customer information to the core system (2) a bank authentication step of authenticating customer information by the card issuing bank system; and (3) a customer setting a recognition language and storing the identifier in the core system identifier Setup steps.
  • the step of registering the customer information comprises the steps of: (1) inputting customer registration information including at least the customer's mobile phone number into the core system and setting a login password; (2) collecting the customer registration information and transmitting the authentication code to the client (3) The customer enters the received authentication code into the customer's mobile terminal and sends it to the core system; (4) The core system stores the customer registration information in the case of confirming that the authentication code returned by the customer's mobile terminal is correct. In the core system.
  • the customer registration information further includes one or more of a document number, a name, and a mailing address.
  • the step of performing the authentication includes the following steps: (1) inputting bank card related information including at least a bank card number into the core system; (2) connecting the card issuing bank system to the card issuing system; 3) After the bank card is successfully authenticated, the core system sends the bank card association confirmation code to the customer's mobile phone terminal; (4) The customer completes the bank card authentication by using the received bank card association confirmation code, and the successful silver card information and customer registration information are verified. The association is stored in the core system.
  • the identifier setting step comprises the following steps: (1) selecting, by the client, the type of the identifier and determining the identifier, wherein the type of the identifier includes a fixed word and a question set; (2) determining the type The identifier is stored in the core system.
  • the merchant information registration step comprises the following steps: (1) Establishing a merchant number association storage to the core system.
  • the transaction serial number is further included in the transaction authorization request information.
  • the legality verification step includes: (1) determining, according to the merchant mobile phone number association stored in the core system, whether the merchant matches, in the case that the matching is successful, verifying by the merchant legality; (2) according to the storage in the core The customer registration information in the system determines whether the customer mobile phone number included in the transaction authorization request information matches, and if the matching is successful, the customer legality is verified.
  • the authorization request forwarding and notification step comprises the following steps: (1) the core system sends the transaction authorization request information to the corresponding issuing bank system according to the customer mobile phone number; (2) the issuing bank system verifies whether the authorization is successful, if the authorization is successful Then, the authorization code is recorded in the core system; (3) the identifier stored in the core system is checked for the identifier; (4) in the case that the identifier verification is successful, the authorization result information is sent to the client mobile terminal; ) Record authorized transactions in the core system.
  • the 4 authorized result information includes: one or more of a merchant name, a spending amount, a prompt prompt, and a "transaction authorization".
  • the transaction settlement request step comprises the following steps: (1) after the customer confirms the consumption amount, the authorization code and the corresponding identifier are notified to the merchant; (2) the authorization code and the identifier are included by the merchant mobile phone terminal.
  • the transaction settlement request is sent to the core system.
  • the transaction settlement request further includes a merchant code and a transaction serial number.
  • the transaction settlement legality verification step comprises the steps of: matching the mobile phone number associated with the merchant code with the mobile phone number of the requesting request, and if the matching is successful, the verification is successful; the core system is based on the merchant code, the transaction serial number Look for a match in the authorization record; check the transaction authorization code and customer identifier when the authorization record matches successfully; the core system records the check result.
  • the settlement result notification step comprises the following steps: (1) transmitting the settlement result to the merchant mobile phone terminal and the customer mobile phone respectively; (2) the merchant mobile phone terminal compares the transaction serial number and displays information indicating that the transaction is successful.
  • the method further comprises: forwarding the settlement notification transaction to the card issuing bank, so that the issuing bank performs the accounting settlement notification transaction forwarding step.
  • the dual information mobile phone on-site payment system of the present invention comprises: a core system, an interface module, an acceptance terminal including a customer mobile phone terminal and a merchant mobile phone terminal, and a card issuing bank system, wherein the interface module is used in the core system, the receiving terminal, and Data exchange between the card issuing bank systems, the merchant mobile phone terminal is configured to send the transaction authorization request information to the core system through the interface module, and used to send the transaction settlement according to the following authorization result information obtained from the customer Requesting to the core system, the core system is configured to accept transaction authorization request information from the merchant mobile phone terminal through the interface module, perform legality verification on the transaction authorization request information, and after the legality verification is successful Transmitting the transaction authorization request information to the card issuing bank system by using the interface module, the card issuing bank system performs authorization verification on the received transaction authorization request, and passes the
  • the interface module has an information collection interface for inputting information by a customer, a short message gateway for connecting and receiving short messages to and from a mobile communication service provider, and a 2G/3G communication interface for connecting with a mobile communication service provider for network communication.
  • the card-issuing bank interface connected to the issuing bank.
  • the core system is: a memory, the server having a database, a database, and an I/O interface; an information processing unit, configured to process various information collected from the information collection interface; A collection, having a plurality of single execution elements for performing various processes; a timer for periodically executing various tasks; and a process scheduling unit for scheduling various processes of the entire system.
  • Figure 2 is a diagram showing the specific flow of the customer registration and bank association steps of the dual information on-site mobile payment method of the present invention.
  • Figure 3 is a diagram showing the specific flow of the merchant information registration step of the dual information on-site mobile payment method of the present invention.
  • FIG. 4 is a schematic diagram showing a specific flow of mobile phone on-site payment according to the dual information on-site mobile payment method of the present invention.
  • FIG. 5 is a block diagram showing the structure of the dual information on-site mobile payment system of the present invention. detailed description
  • the dual information on-site mobile payment method of the present invention is a method for realizing mobile payment between a core system and a card issuing bank system by using a customer mobile terminal and a merchant mobile terminal.
  • the mobile terminal of the customer only needs to be a mobile phone with the function of sending and receiving short messages.
  • the mobile terminal of the merchant can be a smart phone terminal with 2G/3G network communication function, and it can be a mobile phone or an acceptance terminal with mobile phone software.
  • the dual information on-site mobile payment system of the present invention will be further described below.
  • FIG. 1 is a schematic overall flow chart showing a dual information on-site mobile payment method of the present invention.
  • the dual information on-site mobile phone payment method of the present invention can be roughly divided into three. Stages:
  • Phase 1 Customer information registration and bank association
  • Second stage registration of merchant information
  • the third stage mobile phone on-site payment.
  • Figure 2 is a diagram showing the specific flow of the customer registration and bank association steps of the dual information on-site mobile payment method of the present invention.
  • the customer information registration and bank association phase mainly includes the following steps: 1.
  • the client sets the recognizer and stores the recognizer in the recognizer setting step of the core system.
  • the above customer information registration step has the following contents:
  • the customer enters the customer information registration page through the interface such as the Internet;
  • the customer inputs customer registration information, and the customer registration information includes at least a mobile phone number, and may further include a document number, a name, a mailing address, etc.; (3) the customer sets a login password;
  • the core system collects the customer registration information input by the customer, and sends the short message authentication code to the mobile phone number input by the customer;
  • the core system stores the customer registration information in its database (the specific description of the database will be explained later).
  • the above bank certification steps specifically include the following:
  • the customer enters the obtained confirmation code on the associated page according to the short message prompt; (6)
  • the core system associates the bank card information passed the authentication with the customer information and the mobile phone number and stores it in its database.
  • the above-mentioned identifier setting step specifically includes the following contents:
  • the type of the identifier is selected by the client and the identifier is determined, wherein the type of the identifier includes a fixed word and a question set, for example, the first type is a fixed statement, and the second type is a question set;
  • the customer is prompted to input fixed words such as "Puppy Wang Cai”, “Shanghai is my home”, “Shanghai AK1888”, etc.;
  • a question is randomly selected from the problem set data, displayed on the interface, for example, " ⁇ 's name", etc., the customer enters the answer to the question; the process is repeated until the client chooses to end the problem set.
  • the core system stores the customer identification information as in the database.
  • FIG 3 is a diagram showing the specific flow of the merchant information registration step of the dual information on-site mobile payment method of the present invention.
  • the merchant information registration steps mainly include merchant information registration and merchant mobile phone number registration.
  • the merchant information registration means that the merchant registers the basic merchant information according to the traditional process (not in the scope of the present invention, and the detailed description is omitted here), and then registers in the core system according to the merchant code association.
  • the merchant mobile phone number registration specifically includes the following steps:
  • the mobile phone on-site payment mainly includes: 1 transaction authorization request step; 2 legality verification step; 3 authorization request forwarding and notification step; 4 transaction settlement request step; 5 settlement request legality verification step; 6 settlement result notification Step; 7 settlement notification transaction forwarding step.
  • 1 transaction authorization request step sending the transaction authorization request information from the merchant mobile phone terminal to the core system, specifically, (1) after the customer consumes, notifying the merchant to make the mobile phone on-site payment, and informing the associated mobile phone number; (2) the merchant through the merchant mobile phone terminal Enter the consumption amount and the customer's mobile phone number, and the merchant mobile terminal sends a transaction authorization request message to the core system.
  • the short message content includes at least the customer mobile phone number, the consumption amount, and the merchant code, and preferably further includes a transaction serial number.
  • 2 Legality verification step the merchant legality verification and the customer legality verification of the transaction authorization request information, specifically including: (1) The core system matches the mobile phone number associated with the mobile phone number by the merchant code, and the matching is successful. Then, the merchant's legality verification is passed; (2) The core system matches the customer's mobile phone number in the requested short message through the registered customer associated mobile phone number, and if the matching is successful, the customer legality verification is passed.
  • Authorization request forwarding and notification step performing authorization verification on the bank authorization for the transaction authorization request information verified by the legality and transmitting the authorization result information to the customer mobile phone terminal if the authorization verification is successful, specifically including:
  • the core system obtains the account information corresponding to the customer mobile phone number, and sends the transaction authorization request to the corresponding issuing system 4; (2) if 4 is authorized successfully, the 4 authorized code is recorded; (3) obtaining the customer setting from the database of the core system; Recognized prompts ("fixed words” or randomly extracted questions, such as " ⁇ 's name”); (4)
  • the system sends the authorization results to the customer's mobile phone via SMS, including the transaction elements: business name, consumption amount, identification Language prompts, as well as the words "transaction authorization”; (5)
  • the system stores the authorized transaction records in the database.
  • transaction settlement request step sending a transaction settlement request from the merchant mobile phone terminal to the core system according to the authorization result information obtained from the customer, specifically including: (1) after the customer confirms that the consumption amount is correct, the authorization code and the determined identifier are notified to the merchant (2)
  • the merchant inputs the authorization code and the customer identifier through the merchant mobile terminal, and the merchant mobile terminal sends a transaction settlement request message to the core system.
  • the text message here includes the transaction elements: merchant code, transaction serial number, customer identification, transaction authorization code, and so on.
  • 5 settlement request legality verification step verify the legality of the transaction settlement request, specifically including: (1) The core system matches the mobile phone number associated with the mobile phone number by the merchant code, and if the matching is successful, the merchant party passes the verification; (2) The core system searches for the matching in the authorization record through the merchant code and the transaction serial number; (3) checking the transaction authorization code and the customer identifier after the authorization record is successfully matched; (4) if the inspection result is correct, the core system records the inspection result. If successful, modify the authorization record to "settled".
  • the transaction settlement result according to the transaction settlement request is separately sent to the customer mobile phone and the merchant mobile phone terminal, which specifically includes: (1) The core system sends the settlement result to the merchant mobile phone terminal through the short message, and the merchant mobile phone terminal compares After the transaction serial number, the current consumption amount and the information such as "transaction success" are displayed; (2) The core system sends the settlement result to the customer's mobile phone via SMS.
  • the content of the message includes the transaction elements: the name of the merchant, the amount of the purchase, and the words "transaction success".
  • the merchant acceptance terminal is a smart phone with 2G/3G network communication function or a terminal with mobile phone software, and does not need to modify the merchant acceptance terminal, so it has small investment and convenience for merchants, especially small businesses.
  • value-added functions such as summary reconciliation can be integrated to further increase the added value of the system function.
  • FIG. 5 is a block diagram showing the structure of the dual information on-site mobile payment system of the present invention.
  • the dual information mobile phone on-site payment system of the present invention has: a core system 100; an interface module; an acceptance module, including a customer mobile terminal 301 and a merchant mobile terminal 302; and a card issuing system 500.
  • the interface module is for data exchange between the core system 100, the receiving terminal, and the issuing bank system 500.
  • the interface module includes an information handset interface 201, a short message gateway 202, a card issuing bank interface 203, and a 2G/3G network interface 204.
  • the information collection interface 201 is for collecting customer registration information and merchant registration information from the Internet 400.
  • the short message gateway 202 is configured to perform short message transmission and delivery between the customer collection terminal 301 and the core system 100 and between the merchant mobile terminal 302 and the core system 100.
  • the card issuing bank interface 203 is used to connect the core system 100 and the issuing bank system 500 for transaction request authorization, transaction settlement, and the like.
  • the 2G/3G network interface 204 is used for data interaction between the merchant handset terminal 302 and the core system 100.
  • the core system 100 includes: a memory 101, an information processing unit 102, an execution unit set 103, a timer 104, and a flow schedule 105.
  • the memory 101 includes a database and its server, an I/O interface, and the like.
  • the database is used to store customer registration information, merchant registration information, bank card information and customer information and mobile phone number association, customer set identifiers, merchants and their associated mobile phone number information, authorized transaction records, authorization result records, and settlement transaction records.
  • the information processing unit 102 is for processing various kinds of information collected from the Internet 400 through the information collecting interface 201.
  • the processing here includes, for example, customer access. Enter information through the browser, verify the information, and save it to the database.
  • the execution unit set 103 is a collection of various execution units, such as bank authorization, short message content analysis and generation, settlement instruction processing, and the like.
  • the timer 104 is used to time various tasks.
  • the process scheduling unit 105 is configured to schedule various processes of the entire system.
  • the short message gateway 202 and the issuing bank interface 203 perform customer information registration, bank authentication, and merchant information registration.
  • the customer enters the customer information registration page through the interface of the Internet 400 or the like, that is, the customer registration information is input to the core system 100 through the information collection interface 201.
  • the customer registration information includes at least the mobile phone number, and may further include a document number, a name, a mailing address, etc., and the customer sets a login password.
  • the core system 100 collects customer registration information entered by the customer and sends the short message authentication code to the client mobile terminal 301 via the short message gateway 202, while the core system 100 stores the customer registration information in a database in its memory 101. Items for setting the identifier can also be included in the customer information registration.
  • the core system 100 collects the identification words selected by the customer according to preferences through the information collection interface 201, and stores the identification information in a database of the memory 101.
  • the bank is authenticated. Specifically, the customer logs in to the core system 100 through the Internet 400, and the bank card related information is input to the core system 100 through the information mobile phone interface 201.
  • the bank card related information includes at least the bank card number.
  • the card may also include one or more of a bank card expiration date, CVV2 information, a bank transaction password, and a bank card cardholder name.
  • the core system 100 connects to the issuing bank system 500 via the issuing bank interface 203 for bank card authentication. After the card issuing bank system 500 is successfully issued, the core system 100 sends the bank card association confirmation code to the customer mobile phone terminal 301 via the short message gateway 202 by SMS.
  • the customer inputs the obtained confirmation code on the associated page according to the short message prompt and transmits the confirmation code through the information collecting interface 201.
  • the core system 100 associates the approved bank card information with the customer information and the mobile phone number and stores it in the database of its memory 101.
  • the merchant information registration is performed, and the business personnel log in to the core system 100, and the merchant can have more than one mobile phone number, and can set several hands associated with the merchant. Machine number.
  • the core system 100 will complete the associated merchant and its associated handset number information into a database of its memory 101.
  • the merchant mobile phone terminal 302 transmits the transaction authorization request information to the core system 100 through the short message gateway 202. Specifically, after the customer consumes, the merchant is notified to make a mobile phone on-site payment, and the associated mobile phone number is notified to the merchant, and the merchant sends the transaction authorization information including the consumption amount, the customer mobile phone number, the merchant code, the transaction serial number, etc. through the merchant mobile phone terminal 302. To the core system 100.
  • the core system 100 matches the mobile phone number associated with the merchant code stored in its memory 101 with the mobile phone number that sends the request short message. If the matching is successful, the merchant's legality verification passes, and at the same time, the core system 100 stores the memory in its memory 101. The registered customer associated mobile phone number is matched with the customer mobile phone number in the requested short message. If the matching is successful, the customer legality verification is passed.
  • the core system 100 obtains the account information corresponding to the customer mobile phone number, and sends the transaction authorization request to the corresponding issuing bank system 500, and the authorization is issued by the issuing bank system 500. If the authorization is successful, the authorization code returned by the issuing bank is recorded to the memory 101. in. Next, a fingerprint prompt ("fixed word" identifier or a question set identifier) set by the client is obtained from the database of the core system 100. The core system 100 transmits the authorization results to the client handset terminal 301 via the SMS gateway 202, while the core system 100 stores the authorization transaction records in the database of its memory 101.
  • a fingerprint prompt (fixed word" identifier or a question set identifier) set by the client
  • the customer informs the merchant of the obtained authorization result information, such as the authorization number and the identifier, and the merchant mobile terminal 302 passes the transaction settlement request including the authorization code and the customer identifier through the short message gateway 202 to the core system 100.
  • the merchant mobile terminal 302 passes the transaction settlement request including the authorization code and the customer identifier through the short message gateway 202 to the core system 100.
  • the core system 100 matches the merchant code associated mobile phone number stored in its database with the mobile phone number that sends the transaction settlement request short message. If the matching is successful, the merchant party verifies that the core system 100 passes the merchant code and the transaction serial number in it. Look for a match in the authorization record of the database. If the authorization record matches successfully, check the transaction authorization code and the customer identifier. If the check result is correct, the core system 100 records the check result into the database of its memory 101, and modifies the authorization record as "settled".
  • the core system 100 sends the settlement result to the merchant hand through the short message gateway 202.
  • the merchant mobile terminal 302 compares the transaction serial number, the current consumption amount and the "transaction success" information are displayed, and the core system 100 also transmits the settlement result to the customer mobile phone terminal 301 through the short message gateway 202.
  • the core system 100 notifies the corresponding issuance system 4 of the settlement result and records the settlement transaction into the database of its memory 101.

Abstract

本发明涉及双信息手机现场支付方法以及双信息手机现场支付系统。本发明的双信息手机现场支付方法是利用客户手机终端和商户手机终端在核心系统和发卡银行系统之间实现手机支付的方法,该方法包括:交易授权请求步骤;合法性验证步骤;授权请求转发及通知步骤;交易结算请求步骤;以及结算请求合法性验证步骤。利用本发明的双信息手机现场支付方法及其系统,客户和商户只要具备短信接收功能的手机即可,不需要对客户手机或者商户受理终端进行改造,具有实现成本低、容易普及适用面广的优点。

Description

双信息手机现场支付方法以及双信息手机现场支付系统 技术领域
本发明涉及利用手机的支付方法及其系统,具体地涉及利用手机
背景技术
随着银行网络服务系统的发展,各种借记卡、信用卡之类的银行 卡在消费者的曰常消费交易中得到了越来越广泛的应用。 消费者出 行不必携带大量现金, 只需要使用银行卡就能够在安装有银行终端
( POS机)的消费场所进行消费结算。这为消费提供了极大的便利。 然而,消费者在使用银行卡在银行终端上进行消费结算时也存在 着一定的安全隐患, 例如, 消费者在消费过程中可能出现 4艮行卡的 帐号以及密码被盗窃的现象。另一方面,在使用银行卡进行消费时, 必须要携带该银行卡出行, 而且, 一般银行卡的使用也只限于本人 使用, 消费方式比较单一。
另一方面, 随着电子与通讯技术的快速发展,利用手机进行消费 支付, 也已经成为可能。 目前已经存在多种手机支付的方法, 常用 的有四种: SIM Pass, RFID-SIM, NFC和智能 SD卡。
( 1 ) SIM Pass技术
SIM Pass是一种多功能的 SIM卡, 支持 SIM卡功能和移动支付 的功能。 SIMPass运行于手机内, 为解决非接触界面工作所需的天 线布置问题给予了两种解决方案: 定制手机方案和低成本天线组方 案。
( 2 ) RFID-SIM
RFID-SIM 是双界面智能卡技术向手机领域渗透的产品。 RFID-SIM既有 SIM卡的功能, 也可实现近距离无线通信。
( 3 ) NFC技术 NFC是一种非接触式识别和互联技术。 NFC手机内置 NFC芯片, 组成 RFID模块的一部分, 可以当做 RFID无源标签来支付使用, 也可以当做 RFID读写器来数据交换和采集。
( 4 )智能 SD卡
在目前 SIM卡的封装形势下, EEPROM容量已经达到极限。 通 过使用智能 SD卡来扩大 SIM卡的容量,可以满足业务拓展的需要。
但是上述技术中需要对客户手机终端和 /或商户受理终端均进行 特殊改造, 因此上述手机支付技术存在实现成本高、 不容易快速推 广、 受限制多的问题。 发明内容
本发明鉴于上述问题,旨在提供一种无需对客户手机终端或商户 受理终端进行改造而利用双向手机信息交互就能够实现的双信息 手机现场支付方法以及双信息手机现场支付系统。
本发明的双信息手机现场支付方法,其特征在于,利用客户手机 终端和商户手机终端在核心系统和发卡银行系统之间实现手机支 付的方法, 该方法包括: 从商户手机终端将交易授权请求信息发送 到核心系统的交易授权请求步骤; 对交易授权请求信息进行商户合 法性验证和客户合法性验证的合法性验证步骤; 对经过合法性验证 的交易授权请求信息进行有关银行认证的授权性验证并且在授权 验证成功的情况下将授权结果信息发送到客户手机终端的授权请 求转发及通知步骤; 根据从客户获得的授权结果信息从商户手机终 端发送交易结算请求至核心系统的交易结算请求步骤; 以及验证交 易结算请求的合法性的结算请求合法性验证步骤。
优选地,在所述交易请求步骤之前还具备: 在核心系统中注册客 户信息并且在核心系统中建立客户手机终端与银行卡之间的关联 的客户信息注册及银行关联步骤; 以及在核心系统中建立商户手机 终端和商户之间的商户信息关联的商户信息注册步骤。
优选地,在所述交易请求合法性验证步骤之后还具备: 将根据交 易结算请求进行的交易结算结果分别发送到客户手机终端、 商户手 机终端的结算结果通知步骤, 以及结算通知交易转发到发卡银行步 骤。
优选地, 在所述客户信息注册及银行关联步骤包括下述步骤:
( 1 )将客户信息注册到核心系统的客户信息注册步骤; (2 ) 由发 卡银行系统认证客户信息的银行认证步骤; 以及( 3 )客户设置识 别语并且将识别语存储在核心系统的识别语设置步骤。
优选地, 在客户信息注册步骤包括下述步骤: (1 )将至少包括 客户手机号码的客户注册信息输入到核心系统并且设置登录密码; ( 2 )收集到客户注册信息并且将认证码发送到客户手机终端; ( 3 ) 客户将收到的认证码输入客户手机终端并发送给核心系统; ( 4 ) 核心系统在确认收到由客户手机终端返回的认证码无误的情况下 将客户注册信息存储在核心系统中。
优选地, 所述客户注册信息还包括证件号码、姓名、通讯地址中 的一项或多项。
优选地, 在所述 4艮行认证步骤包括下述步骤: (1 )将至少包括 银行卡卡号的银行卡相关信息输入到核心系统; (2 )核心系统连 接发卡银行系统进行银行卡认证; ( 3 )银行卡认证成功后核心系 统发送银行卡关联确认码至客户手机终端; ( 4 )客户利用收到的 银行卡关联确认码完成银行卡认证, 将认证成功的银卡信息与客户 注册信息的关联存储在核心系统。
优选地, 所述银行卡相关信息还包括银行卡有效期限、 CVV2信 息、 银行交易密码、 银行卡持卡人姓名中的一项或多项。
优选地, 所述识别语设置步骤包括下述步骤: (1 ) 由客户选择 识别语的类型并且确定识别语, 其中, 所述识别语的类型包括固定 词句和问题集; (2 )将确定的识别语存入到核心系统中。
优选地, 所述商户信息注册步骤包括下述步骤: (1 )建立商户 号关联存储到核心系统。
优选地,所述交易请求授权步骤包括以下步骤: 在所述交易请求 步骤中通过商户受理终端输入至少包含消费金额、 客户手机号以及 商户代码的交易授权请求信息到核心系统。
优选地, 在所述交易授权请求信息中还包括交易流水号。
优选地, 所述合法性验证步骤包括: (1 )根据存储在核心系统 中的商户手机号关联判断商户是否匹配, 在匹配成功的情况下, 通 过商户合法性验证; (2 )根据存储在核心系统中的客户注册信息 判断交易授权请求信息中包含的客户手机号是否匹配, 在匹配成功 的情况下, 通过客户合法性验证。
优选地, 所述授权请求转发及通知步骤包括以下步骤: (1 )核 心系统根据客户手机号将交易授权请求信息发送到对应的发卡银 行系统; (2 )发卡银行系统验证是否授权, 若授权成功则将授权 码记录在核心系统; ( 3 ) 居存储在核心系统中的识别语进行识 别语核对; (4 )在识别语核对成功的情况下, 将授权结果信息发 送到客户手机终端; (5 )在核心系统中记录授权交易。
优选地, 所述 4受权结果信息包括: 商户名称、 消费金额、 识别语 提示以及 "交易授权" 字样中的一项或者多项。
优选地, 所述交易结算请求步骤包括以下步骤: (1 )在由客户 确认消费金额后, 将授权码及对应的识别语告知商户; (2 )通过 商户手机终端将包含授权码和识别语的交易结算请求发送到核心 系统。
优选地, 所述交易结算请求中还包括商户代码、 交易流水号。 优选地,所述交易结算合法性验证步骤包括下述步骤:对商户代 码关联手机号码和发送请求的手机号进行匹配, 在匹配成功的情况 下, 验证成功; 核心系统根据商户代码、 交易流水号在授权记录中 查找匹配;在授权记录匹配成功,则检查交易授权码和客户识别语; 核心系统记录检查结果。
优选地, 所述结算结果通知步骤包括下述步骤: ( 1 )将结算结 果分别发送到商户手机终端、 客户手机; ( 2 ) 商户手机终端对比 交易流水号并显示标识交易成功的信息。
优选地,在所述结算结果通知步骤之后还包括:将结算通知交易 转发到发卡银行, 以便发卡银行进行记账结算通知交易转发步骤。 本发明的双信息手机现场支付系统,具备:核心系统、接口模块、 包括客户手机终端和商户手机终端的受理终端、 以及发卡银行系 统, 所述接口模块用于在所述核心系统、 受理终端和发卡银行系统 之间进行数据交换, 所述商户手机终端用于将交易授权请求信息通 过所述接口模块发送到将所述核心系统, 并且用于根据从客户得到 的下述授权结果信息发送交易结算请求到所述核心系统, 所述核心 系统用于通过所述接口模块接受来自所述商户手机终端的交易授 权请求信息, 对所述交易授权请求信息进行合法性验证, 并且在合 法性验证成功后将所述交易授权请求信息通过所述接口模块发送 到所述发卡银行系统, 所述发卡银行系统对接收到的所述交易授权 请求进行授权验证并且在授权验证成功后将授权结果信息通过所 述接口模块发送到所述客户手机终端, 所述客户手机终端用于通过 所述接口模块接收从所述核心系统发送来的授权结果信息。
优选地, 所述接口模块具备用于客户输入信息的信息收集接口、 用于与移动通讯服务商连接进行短信收发的短信网关、 用于与移动 通讯服务商连接进行网络通信的 2G/3G通信接口以及与发卡银行 连接的发卡银行接口。
优选地, 所述核心系统具备: 存储器, 该存储具有数据库、 数据 库的服务器以及 I/O接口; 信息加工单元, 用于对从所述信息收集 接口收集到的各种信息进行加工处理; 执行单元集合, 具备执行各 种处理的多个单执行元; 定时器, 用于定时执行各种任务; 以及流 程调度单元, 用于对整个系统的各种流程进行调度。
利用本发明的双信息手机现场支付方法以及双信息手机现场支 付系统, 进行消费的客户和需要进行消费结算的商户只要是具备短 信接收功能的手机即可, 不需要对客户手机或者商户受理终端进行 改造, 具有实现成本低、 容易普及适用面广的优点, 尤其是对小型 商户来说, 投入小、 设置和操作便捷。 而且, 在整个手机现场支付 过程不出现卡号、 密码等敏感信息, 交易的安全性得以保证。再者, 不仅通过手机号、 授权码而且还利用了识别语, 通过这样的三重保 险组成的安全体系, 其安全度高于单纯的卡号、 密码安全体系。 另 夕卜, 除了消费结算外, 还可以容易地进行系统增值功能, 进一步增 加系统功能附加值。 附图说明
图 1 是表示本发明的双信息现场手机支付方法的总体流程示意 图。
图 2 是表示本发明的双信息现场手机支付方法的客户注册及银 行关联步骤的具体流程的示意图。
图 3 是表示本发明的双信息现场手机支付方法的商户信息注册 步骤的具体流程的示意图。
图 4是表示本发明的双信息现场手机支付方法的有关手机现场 支付的具体流程的示意图。
图 5是表示本发明的双信息现场手机支付系统的结构示意图。 具体实施方式
下面介绍的是本发明的多个可能实施例中的一些, 旨在提供对本发 明的基本了解。 并不旨在确认本发明的关键或决定性的要素或限定所 要保护的范围。
为使本发明的目的、技术方案和优点更加清楚, 下面结合附图对本 发明作进一步的详细描述。
以下,对于本发明双信息现场手机支付方法进行说明。本发明双 信息现场手机支付方法是利用客户手机终端和商户手机终端在核 心系统和发卡银行系统之间实现手机支付的方法。 客户手机终端只 要是具有短信收发功能的手机即可,商户手机终端只要是 2G/3G网 络通信功能的智能手机终端即可, 可以是手机, 也可以是具有手机 软件的受理终端。 对于这里所称的核心系统的具体结构和功能, 将 在以下对本发明的双信息现场手机支付系统再进行详细说明。
图 1 是表示本发明的双信息现场手机支付方法的总体流程示意 图。
如图 1所示,本发明的双信息现场手机支付方法粗略可以分为三 个阶段:
第一阶段: 客户信息注册及银行关联;
第二阶段: 商户信息注册;
第三阶段: 手机现场支付。
首先,对于本发明的双信息现场手机支付方法的第一阶段的 "客 户信息注册及银行关联" 进行说明。
图 2是表示本发明的双信息现场手机支付方法的客户注册及银 行关联步骤的具体流程的示意图。
如图 2所示, 客户信息注册及银行关联阶段主要包括下述步骤: 1、 将客户信息注册到核心系统的客户信息注册步骤;
2、 由发卡银行系统认证客户信息的银行卡认证及关联步骤; 以 及
3、 客户设置识别语并且将识别语存储在核心系统的识别语设置 步骤。
下面具体对这些步骤的具体内容进行说明。
上述客户信息注册步骤具有包括下述内容:
( 1 )客户通过互联网等的界面进入客户信息注册页面;
( 2 )客户输入客户注册信息, 该客户注册信息至少包含手机号 码, 在此基础上还可以进一步包含证件号码、 姓名、 通讯地址等; ( 3 )客户设置登录密码;
( 4 )核心系统收集客户输入的客户注册信息, 并发送短信认证 码到客户输入的手机号码;
( 5 )核心系统将客户注册信息存储到其数据库中 (该数据库的 具体说明将在后文进行说明) 。
上述银行认证步骤具体包括下述内容:
( 1 )客户通过互联网等登录核心系统;
( 2 )将 4艮行卡相关信息输入到核心系统, 其中, 4艮行卡相关信 息至少包括银行卡卡号, 在此基础上还可以包括银行卡有效期限、 CVV2信息、 银行交易密码、 银行卡持卡人姓名中的一项或多项; ( 3 )核心系统连接发卡银行系统进行银行卡认证; ( 4 )银行卡认证成功后核心系统以短信方式发送银行卡关联确 认码至客户手机终端;
( 5 )客户按照短信提示, 在关联页面输入得到的确认码; ( 6 )核心系统将认证通过的银行卡信息与客户信息及手机号码 关联并存储到其数据库。
上述识别语设置步骤具体包括下述内容:
( 1 ) 由客户选择识别语的类型并且确定识别语, 其中, 所述识 别语的类型包括固定词句和问题集,例如,第一种类型是固定语句, 第二种类型是问题集;
( 2 )根据客户选择:
选择第一种类型的情况下, 提示客户输入固定词句, 比如 "小狗 旺财" 、 "上海是我家" 、 "沪 AK1888" 等;
选择第二种类型的情况下, 从问题集数据中随机抽取一个问题, 显示在界面上, 例如, "舅舅的名字" 等, 客户输入问题的答案; 重复此过程, 直至客户选择结束问题集.
( 3 )提示客户牢记识别语, 将在以后的现场支付中适用; ( 4 )核心系统将客户识别语信息存储如数据库中。
其次,对于本发明的双信息现场手机支付方法的第二阶段的 "客 商户信息注册" 进行说明。
图 3 是表示本发明的双信息现场手机支付方法的商户信息注册 步骤的具体流程的示意图。 如图 3所示, 商户信息注册步骤主要包 括商户信息注册、 商户手机号码登记。
其中, 商户信息注册是指商户按照传统流程登记基本商户信息 (不属于本发明的范畴, 这里省略具体说明)后, 根据商户代码关 联在核心系统中进行注册。
接着, 商户手机号码登记具体包括下述步骤:
( 1 ) 由业务人员登录核心系统, 建立商户与商户手机终端的手 机号码的商户手机号关联。这里,商户可以拥有不止一个手机号码。 在商户拥有多个手机号码的情况下, 重复进行该步骤, 直到该商户 的所有手机号码都被关联。 ( 2 )将完成关联的商户及其关联手机号码信息存入数据库。 接着,对于本发明的双信息现场手机支付方法的第三阶段的 "手 机现场支付" 进行说明。
图 4是表示本发明的双信息现场手机支付方法的有关手机现场 支付的具体流程的示意图。 如图 4所示, 手机现场支付主要包括: ①交易授权请求步骤; ②合法性验证步骤; ③授权请求转发及通知 步骤; ④交易结算请求步骤; ⑤结算请求合法性验证步骤; ⑥结算 结果通知步骤; ⑦结算通知交易转发步骤。
以下, 对于上述步骤进行具体说明。
①交易授权请求步骤:从商户手机终端将交易授权请求信息发送 到核心系统, 具体地, ( 1 )客户消费后, 通知商户进行手机现场 支付, 告知关联手机号; (2 ) 商户通过商户手机终端输入消费金 额和客户手机号, 商户手机终端发送交易授权请求短信至核心系 统。 其中, 短信内容至少包含客户手机号、 消费金额、 商户代码, 在此基础上最好进一步包括交易流水号等。
②合法性验证步骤:对交易授权请求信息进行商户合法性验证和 客户合法性验证, 具体地包括: ( 1 )核心系统通过商户代码关联 手机号与发送请求短信的手机号进行匹配, 匹配成功, 则商户合法 性验证通过; ( 2 )核心系统通过已注册客户关联手机号与请求短 信中的客户手机号进行匹配, 匹配成功, 则客户合法性验证通过。
③授权请求转发及通知步骤:对经过合法性验证的交易授权请求 信息进行有关银行认证的授权性验证并且在授权验证成功的情况 下将授权结果信息发送到客户手机终端, 具体地包括: (1 )核心 系统获取客户手机号对应账户信息, 将交易授权请求发送到对应发 卡 4艮行系统; ( 2 )如 4受权成功, 则记录 4受权码; ( 3 )从核心系统 的数据库获取客户设定的识别语提示( "固定词句" 或随机抽取的 问题, 例如 "舅舅的名字" ) ; (4 ) 系统将授权结果通过短信发 送到客户手机, 短信内容包括交易要素: 商户名称、 消费金额、 识 别语提示, 以及 "交易授权" 字样等; (5 ) 系统将授权交易记录 存入数据库。 ④交易结算请求步骤:根据从客户获得的授权结果信息从商户手 机终端发送交易结算请求至核心系统, 具体地包括: (1 )客户确 认消费金额无误后, 将授权码及确定的识别语告知商户; (2 ) 商 户通过商户手机终端输入授权码及客户识别语, 商户手机终端发送 交易结算请求短信至核心系统。 这里短信内容包括交易要素: 商户 代码、 交易流水号、 客户识别语、 交易授权码等。
⑤结算请求合法性验证步骤:验证交易结算请求的合法性,具体 包括: ( 1 )核心系统通过商户代码关联手机号与发送请求短信的 手机号进行匹配, 若匹配成功, 则商户方验证通过; (2 )核心系 统通过商户代码、 交易流水号在授权记录中查找匹配; (3 )授权 记录匹配成功, 则检查交易授权码及客户识别语; (4 )若检查结 果正确,核心系统记录检查结果,成功则修改授权记录为 "已结算"。
⑥结算结果通知步骤:将根据交易结算请求进行的交易结算结果 分别发送到客户手机和商户手机终端, 具体包括: (1 )核心系统 将结算结果通过短信发送到商户手机终端, 商户手机终端比对交易 流水号后, 显示本次消费金额以及 "交易成功" 等信息; (2 )核 心系统将结算结果通过短信发送到客户手机。 短信内容包括交易要 素: 商户名称、 消费金额, 以及 "交易成功" 字样等。
⑦结算通知交易转发步骤:将结算交易记录到核心系,以及将结 算结果通知对应的发卡银行系统以便发卡银行进行记账。
利用上述本发明的双信息手机现场支付方法,能够获得下述技术 效果:
( 1 )进行消费的客户只需要具备短信接收功能的手机即可, 不 需要对客户手机进行改造, 因此, 实现成本低、 容易普及、 适用面 广;
( 2 )商户受理终端为具有 2G/3G网络通信功能的智能手机或者 具有手机软件的终端即可, 不需要对商户受理终端进行改造, 因此 对于商户,尤其是小型商户来说具有投入小、便于快速推广的好处;
( 3 )在整个手机现场支付过程不出现卡号、 密码等敏感信息, 安全性得以保证, 客户信任度也得到提高; ( 4 )通过手机号、 授权码、 识别语组成的安全体系, 其安全度 高于单纯的卡号、 密码安全体系;
( 5 )授权、 结算的 "双信息" 交易, 既保证交易过程安全可靠, 又简化系统的异常处理流程;
( 6 )基于智能手机软件功能的商户终端应用, 可以整合汇总对 账等增值功能, 进一步增加系统功能附加值。
以上对本发明的双信息手机现场支付方法进行了说明。下面对于 实现本发明的双信息手机现场支付方法的双信息手机现场支付系 统进行具体说明。
图 5是表示本发明的双信息现场手机支付系统的结构示意图。本 发明的双信息手机现场支付系统具备: 核心系统 100; 接口模块; 受理模块, 包括客户手机终端 301和商户手机终端 302; 以及发卡 4艮行系统 500。
接口模块用于在所述核心系统 100、 受理终端和发卡银行系统 500之间进行数据交换。 接口模块包括信息手机接口 201、 短信网 关 202、 发卡银行接口 203以及 2G/3G网络接口 204。 信息收集接 口 201用于从互联网络 400收集客户注册信息和商户注册信息。 短 信网关 202用于在客户收集终端 301和核心系统 100之间以及在商 户手机终端 302和核心系统 100之间进行短信收发传递。 发卡银行 接口 203用于连接核心系统 100和发卡银行系统 500之间, 以进行 交易请求授权、 交易结算等。 2G/3G网络接口 204用于在商户手机 终端 302和核心系统 100之间进行数据交互。
核心系统 100包括: 存储器 101、 信息加工单元 102、 执行单元 集合 103、 定时器 104、 流程调度 105。
其中, 存储器 101包含数据库及其服务器、 I/O接口等。 数据库 用于存储客户注册信息、 商户注册信息、 银行卡信息与客户信息及 手机号关联、 客户设置的识别语、 商户及其关联手机号信息、 授权 交易记录、 授权结果记录、 结算交易记录。
信息加工单元 102用于对从互联网 400通过信息收集接口 201 收集到的各种信息进行加工处理。 这里的加工处理例如包括客户通 过浏览器输入信息, 将信息进行验证, 并存入数据库等。 执行单元 集合 103是各种执行单元的集合, 例如银行授权、 短信内容解析以 及生成、 结算指令处理等。 定时器 104用于定时各种任务。 流程调 度单元 105用于对整个系统的各种流程进行调度。
在实现手机支付之前, 客户和商户需要分别通过信息收集接口
201、 短信网关 202以及发卡银行接口 203进行客户信息注册及银 行认证、 以商户信息注册。
首先,客户通过互联网 400等的界面进入客户信息注册页面即通 过信息收集接口 201向核心系统 100输入客户注册信息。 该客户注 册信息至少包含手机号码, 在此基础上还可以进一步包含证件号 码、 姓名、 通讯地址等, 客户设置登录密码。 核心系统 100收集客 户输入的客户注册信息, 并通过短信网关 202发送短信认证码到客 户手机终端 301 , 同时核心系统 100将客户注册信息存储到其存储 器 101中的数据库中。 在客户信息注册中还可以包括设定识别语的 项目。 核心系统 100通过信息收集接口 201收集客户根据喜好选择 的识别语, 并且将识别语信息存储到存储器 101的数据库中。
接着, 进行银行认证, 具体地, 客户通过互联网 400等登录核心 系统 100, 将银行卡相关信息通过信息手机接口 201输入到核心系 统 100, 其中, 银行卡相关信息至少包括银行卡卡号, 在此基础上 还可以包括银行卡有效期限、 CVV2信息、 银行交易密码、 银行卡 持卡人姓名中的一项或多项。 核心系统 100通过发卡银行接口 203 连接发卡银行系统 500进行银行卡认证。 在发卡银行系统 500证成 功后核心系统 100通过短信网关 202以短信方式发送银行卡关联确 认码至客户手机终端 301 , 客户按照短信提示, 在关联页面输入得 到的确认码并通过信息收集接口 201传送到核心系统 100。 核心系 统 100将认证通过的银行卡信息与客户信息及手机号码关联并存储 到其存储器 101的数据库中。
另一方面,进行商户信息注册,通过业务人员登录核心系统 100, 商户可以拥有不止一个手机号码, 可以设置若干个与商户关联的手 机号码。 核心系统 100将完成关联的商户及其关联手机号码信息到 其存储器 101的数据库中。
在经过上述客户信息注册及银行认证、以商户信息注册, 当进行 现场收集支付时, 商户手机终端 302将交易授权请求信息通过短信 网关 202发送到核心系统 100。 具体地, 在客户消费后, 通知商户 进行手机现场支付, 并且将关联手机号码告诉商户, 商户通过商户 手机终端 302将包含消费金额、 客户手机号、 商户代码、 交易流水 号等的交易授权信息发送到核心系统 100。
接着,核心系统 100通过存储在其存储器 101中的商户代码关联 手机号与发送请求短信的手机号进行匹配, 匹配成功, 则商户合法 性验证通过, 同时, 核心系统 100通过存储在其存储器 101的已注 册客户关联手机号与请求短信中的客户手机号进行匹配, 匹配成 功, 则客户合法性验证通过。
接着,核心系统 100获取客户手机号对应账户信息,将交易授权 请求发送到对应的发卡银行系统 500, 由发卡银行系统 500进行授 权,如授权成功,则将发卡银行返回的授权码记录到存储器 101中。 接着, 从核心系统 100的数据库获取客户设定的识别语提示( "固 定词句" 识别语或者问题集的识别语) 。 核心系统 100将授权结果 通过短信网关 202发送到客户手机终端 301 , 同时核心系统 100将 授权交易记录存入到其存储器 101的数据库。
客户将获得的授权结果信息告知商户, 例如授权号和识别语等, 商户手机终端 302将包含授权码及客户识别语的交易结算请求通过 短信网关 202至核心系统 100。
核心系统 100将存储在其数据库中的商户代码关联手机号与发 送交易结算请求短信的手机号进行匹配, 若匹配成功, 则商户方验 证通过, 则核心系统 100通过商户代码、 交易流水号在其数据库的 授权记录中查找匹配, 授权记录匹配成功, 则检查交易授权码及客 户识别语。 若检查结果正确, 核心系统 100记录检查结果到其存储 器 101的数据库中, 并且修改授权记录为 "已结算" 。
接着,核心系统 100将结算结果通过短信网关 202发送到商户手 机终端 302, 商户手机终端 302比对交易流水号后, 显示本次消费 金额以及 "交易成功" 等信息, 同时, 核心系统 100也将结算结果 通过短信网关 202发送到客户手机终端 301。
最后, 核心系统 100 将结算结果通知对应的发卡 4艮行系统 500 并且将结算交易记录到其存储器 101的数据库中。
利用本发明的双信息手机现场支付方法以及双信息手机现场支 付系统, 进行消费的客户和需要进行消费结算的商户只要是具备短 信接收功能的手机即可, 不需要对客户手机或者商户受理终端进行 改造, 具有实现成本低、 容易普及适用面广的优点, 尤其是对小型 商户来说, 投入小、 设置和操作便捷。 而且, 在整个手机现场支付 过程不出现卡号、 密码等敏感信息, 交易的安全性得以保证。再者, 不仅通过手机号、 授权码而且还利用了识别语, 通过这样的三重保 险组成的安全体系, 其安全度高于单纯的卡号、 密码安全体系。 另 夕卜, 除了消费结算外, 还可以容易地进行系统增值功能, 进一步增 加系统功能附加值。
以上例子主要说明了本发明的双信息手机现场支付方法以及双 信息手机现场支付系统。 尽管只对其中一些本发明的实施方式进行 了描述, 但是本领域普通技术人员应当了解, 本发明可以在不偏离 其主旨与范围内以许多其他的形式实施。 因此, 所展示的例子与实 施方式被视为示意性的而非限制性的, 在不脱离如所附各权利要求 所定义的本发明精神及范围的情况下, 本发明可能涵盖各种的修改 与替换。

Claims

权利要求书
1.一种双信息手机现场支付方法, 其特征在于, 利用客户手机 终端和商户手机终端在核心系统和发卡银行系统之间实现手机支 付的方法, 该方法包括:
从商户手机终端将交易授权请求信息发送到核心系统的交易授 权请求步骤;
对交易授权请求信息进行商户合法性验证和客户合法性验证的 合法性验证步骤;
对经过合法性验证的交易授权请求信息进行有关银行账户交易 授权并且在授权成功的情况下将授权结果信息发送到客户手机终 端的交易授权步骤;
根据从客户获得的授权结果信息从商户手机终端发送交易结算 请求至核心系统的交易结算请求步骤; 以及
验证交易结算请求的合法性的结算请求合法性验证步骤。
2. 如权利要求 1所述的双信息手机现场支付方法,其特征在于, 在所述交易请求步骤之前还具备:
在核心系统中注册客户信息并且在核心系统中建立客户手机终 端与银行卡之间的关联的客户信息注册及银行关联步骤; 以及
在核心系统中建立商户手机终端和商户之间的商户信息关联的 商户信息注册步骤。
3. 如权利要求 2所述的双信息手机现场支付方法,其特征在于, 在所述交易请求合法性验证步骤之后还具备:
将根据交易结算请求进行的交易结算结果分别发送到客户手机 终端、 商户手机终端的结算结果通知步骤。
4.如权利要求 3所述的双信息手机现场支付方法,其特征在于, 在所述客户信息注册及银行关联步骤包括下述步骤:
( 1 )将客户信息注册到核心系统的客户信息注册步骤;
( 2 ) 由发卡银行系统认证客户信息的银行认证步骤; 以及 ( 3 )客户设置识别语并且将识别语存储在核心系统的识别语设 置步骤。
5.如权利要求 4所述的双信息手机现场支付方法,其特征在于, 在客户信息注册步骤包括下述步骤:
( 1 )将至少包括客户手机号码的客户注册信息输入到核心系统 并且设置登录密码;
( 2 )收集到客户注册信息并且将认证码发送到客户手机终端;
( 3 )客户将收到的认证码输入客户手机终端并发送给核心系 统;
( 4 )核心系统在确认收到由客户手机终端返回的认证码无误的 情况下将客户注册信息存储在核心系统中。
6.如权利要求 5所述的双信息手机现场支付方法,其特征在于, 所述客户注册信息还包括证件号码、 姓名、 通讯地址中的一项 或多项。
7. 如权利要求 6所述的双信息手机现场支付方法,其特征在于, 在所述银行认证步骤包括下述步骤:
( 1 )将至少包括 4艮行卡卡号的 4艮行卡相关信息输入到核心系统;
( 2 )核心系统连接发卡银行系统进行银行卡认证;
( 3 )银行卡认证成功后核心系统发送银行卡关联确认码至客户 手机终端;
( 4 )客户利用收到的银行卡关联确认码完成银行卡认证, 将认 证成功的银卡信息与客户注册信息的关联存储在核心系统。
8.如权利要求 7所述的双信息手机现场支付方法,其特征在于, 所述银行卡相关信息还包括银行卡有效期限、 CVV2信息、 银 行卡交易密码、 银行卡持卡人姓名中的一项或多项。
9. 如权利要求 8 所述的双信息手机现场支付方法, 其特征在 于,
所述识别语设置步骤包括下述步骤:
( 1 ) 由客户选择识别语的类型并且确定识别语, 其中, 所述识 别语的类型包括固定词句和问题集;
( 2 )将确定的识别语存入到核心系统中。
10. 如权利要求 9所述的双信息手机现场支付方法,其特征在于, 所述商户信息注册步骤包括下述步骤:
( 2 )将商户手机号关联存储到核心系统。
11. 如权利要求 10所述的双信息手机现场支付方法, 其特征在 于,
所述交易请求授权步骤包括以下步骤:
在所述交易请求步骤中通过商户受理终端输入至少包含消费金 额、 客户手机号以及商户代码的交易授权请求信息到核心系统。
12. 如权利要求 11所述的双信息手机现场支付方法,其特征在 于,
在所述交易授权请求信息中还包括交易流水号。
13. 如权利要求 12所述的双信息手机现场支付方法,其特征在 于,
所述合法性验证步骤包括:
( 1 )根据存储在核心系统中的商户手机号关联判断商户是否匹 配, 在匹配成功的情况下, 通过商户合法性验证;
( 2 )根据存储在核心系统中的客户注册信息判断交易授权请求 信息中包含的客户手机号是否匹配, 在匹配成功的情况下, 通过客 户合法性 3 证。
14. 如权利要求 13所述的双信息手机现场支付方法,其特征在 于,
所述授权请求转发及通知步骤包括以下步骤:
( 1 )核心系统根据客户手机号将交易授权请求信息发送到对应 的发卡银行系统;
( 2 )发卡银行系统验证是否授权,若授权成功则将授权码记录 在核心系统;
( 3 )根据存储在核心系统中的识别语类型进行识别语提示提 取;
( 4 )将授权结果信息和识别语提示发送到客户手机终端; ( 5 )在核心系统中记录授权交易。
15. 如权利要求 14所述的双信息手机现场支付方法,其特征在 于,
所述授权结果信息包括: 商户名称、 消费金额、 识别语提示以 及 "交易授权" 字样中的一项或者多项。
16. 如权利要求 15所述的双信息手机现场支付方法,其特征在 于,
所述交易结算请求步骤包括以下步骤:
( 1 )在由客户确认消费金额后,将授权码及对应的识别语告知 商户;
( 2 )通过商户手机终端将包含授权码和识别语的交易结算请求 发送到核心系统。
17. 如权利要求 16所述的双信息手机现场支付方法,其特征在 于,
其中所述交易结算请求中还包括商户代码、 交易流水号。
18. 如权利要求 17所述的双信息手机现场支付方法,其特征在 于,
所述交易结算合法性验证步骤包括下述步骤:
( 1 )对商户代码关联手机号码和发送请求的手机号进行匹配, 在匹配成功的情况下, 3 证成功;
( 2 )核心系统根据商户代码、交易流水号在授权记录中查找匹 配;
( 3 )在授权记录匹配成功, 则检查交易授权码和客户识别语;
( 4 )核心系统记录检查结果。
19.如权利要求 18 所述的双信息手机现场支付方法, 其特征在 于,
所述结算结果通知步骤包括下述步骤:
( 1 )将结算结果分别发送到商户手机终端、 客户手机;
( 2 ) 商户手机终端对比交易流水号并显示标识交易成功的信 息。
20.如权利要求 18所述的双信息手机现场支付方法, 其特征在 于, 在所述结算结果通知步骤之后还包括:
将结算通知交易转发到发卡银行, 以便发卡银行进行记账结算 通知交易转发步骤。
21.—种双信息手机现场支付系统,具备:核心系统、接口模块、 包括客户手机终端和商户手机终端的受理终端、 以及发卡银行系 统,
所述接口模块用于在所述核心系统、 受理终端和发卡银行系统 之间进行数据交换,
所述商户手机终端用于将交易授权请求信息通过所述接口模块 发送到将所述核心系统, 并且用于根据从客户得到的下述授权结果 信息发送交易结算请求到所述核心系统,
所述核心系统用于通过所述接口模块接受来自所述商户手机终 端的交易授权请求信息, 对所述交易授权请求信息进行合法性验 证, 并且在合法性验证成功后将所述交易授权请求信息通过所述接 口模块发送到所述发卡银行系统,
所述发卡银行系统对接收到的所述交易授权请求进行授权验证 并且在授权验证成功后将授权结果信息通过所述接口模块发送到 所述客户手机终端,
所述客户手机终端用于通过所述接口模块接收从所述核心系统 发送来的 4受权结果信息。
22.如权利要求 21所述的双信息手机现场支付系统, 其特征在 于,
所述接口模块具备用于客户输入信息的信息收集接口、 用于与 移动通讯服务商连接进行短信收发的短信网关、 用于与移动通讯服 务商连接进行网络通信的 2G/3G通信接口,以及与发卡银行连接的 发卡银行接口。
23.如权利要求 22所述的双信息手机现场支付系统, 其特征在 于,
所述核心系统具备:
存储器, 该存储具有数据库、 数据库的服务器以及 I/O接口; 信息加工单元, 用于对从所述信息收集接口收集到的各种信息 进行加工处理;
执行单元集合, 具备执行各种处理的多个单执行元;
定时器, 用于定时执行各种任务; 以及
流程调度单元, 用于对整个系统的各种流程进行调度。
PCT/CN2012/086599 2011-12-15 2012-12-13 双信息手机现场支付方法以及双信息手机现场支付系统 WO2013087018A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2011104202032A CN103164793A (zh) 2011-12-15 2011-12-15 双信息手机现场支付方法以及双信息手机现场支付系统
CN201110420203.2 2011-12-15

Publications (1)

Publication Number Publication Date
WO2013087018A1 true WO2013087018A1 (zh) 2013-06-20

Family

ID=48587857

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/086599 WO2013087018A1 (zh) 2011-12-15 2012-12-13 双信息手机现场支付方法以及双信息手机现场支付系统

Country Status (2)

Country Link
CN (1) CN103164793A (zh)
WO (1) WO2013087018A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015101057A1 (en) * 2013-12-30 2015-07-09 Tencent Technology (Shenzhen) Company Limited Data processing method and related device and system
US10255429B2 (en) 2014-10-03 2019-04-09 Wells Fargo Bank, N.A. Setting an authorization level at enrollment
US10743181B1 (en) 2014-12-23 2020-08-11 Wells Fargo Bank, N.A. System for binding multiple sim cards to an electronic device

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104346727A (zh) * 2013-07-25 2015-02-11 信帧电子技术(北京)有限公司 一种基于人的自然特征匹配的手机认证支付系统及方法
CN104318439A (zh) * 2014-10-29 2015-01-28 重庆智韬信息技术中心 动态授权码安全支付的短消息授权方法
CN104318438A (zh) * 2014-10-29 2015-01-28 重庆智韬信息技术中心 动态授权码安全支付的集成授权方法
CN104331801A (zh) * 2014-10-29 2015-02-04 重庆智韬信息技术中心 通过动态码授权实现安全支付的方法
CN104361493B (zh) * 2014-11-07 2018-12-11 深兰科技(上海)有限公司 一种基于生物特征的电子支付方法
CN106034151A (zh) * 2015-03-13 2016-10-19 阿里巴巴集团控股有限公司 终端设备关联关系的建立方法及装置
CN105654301A (zh) * 2015-12-23 2016-06-08 大唐微电子技术有限公司 车辆钥匙支付方法和装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2005004069A1 (es) * 2003-07-02 2005-01-13 Mobipay International, S.A. Sistema de transacciones y pagos mediante teléfono móvil digital
CN1588388A (zh) * 2004-07-27 2005-03-02 杭州中正生物认证技术有限公司 一种具有指纹认证的手机支付方法
CN101714275A (zh) * 2009-05-27 2010-05-26 北京创原天地科技有限公司 一套新型手机支付方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020152179A1 (en) * 2000-10-27 2002-10-17 Achiezer Racov Remote payment method and system
US20020069165A1 (en) * 2000-12-06 2002-06-06 O'neil Joseph Thomas Efficient and secure bill payment via mobile IP terminals
CN1753011A (zh) * 2005-09-22 2006-03-29 邵军利 一种新型的电子支付系统和实现方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2005004069A1 (es) * 2003-07-02 2005-01-13 Mobipay International, S.A. Sistema de transacciones y pagos mediante teléfono móvil digital
CN1588388A (zh) * 2004-07-27 2005-03-02 杭州中正生物认证技术有限公司 一种具有指纹认证的手机支付方法
CN101714275A (zh) * 2009-05-27 2010-05-26 北京创原天地科技有限公司 一套新型手机支付方法

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015101057A1 (en) * 2013-12-30 2015-07-09 Tencent Technology (Shenzhen) Company Limited Data processing method and related device and system
US10255429B2 (en) 2014-10-03 2019-04-09 Wells Fargo Bank, N.A. Setting an authorization level at enrollment
US11423137B1 (en) 2014-10-03 2022-08-23 Wells Fargo Bank, N.A. Setting an authorization level at enrollment
US10743181B1 (en) 2014-12-23 2020-08-11 Wells Fargo Bank, N.A. System for binding multiple sim cards to an electronic device
US11381967B1 (en) 2014-12-23 2022-07-05 Wells Fargo Bank, N.A System for binding multiple SIM cards to an electronic device
US11910190B1 (en) 2014-12-23 2024-02-20 Wells Fargo Bank, N.A. System for binding multiple SIM cards to an electronic device

Also Published As

Publication number Publication date
CN103164793A (zh) 2013-06-19

Similar Documents

Publication Publication Date Title
WO2013087018A1 (zh) 双信息手机现场支付方法以及双信息手机现场支付系统
US10552828B2 (en) Multiple tokenization for authentication
US20180240115A1 (en) Methods and systems for payments assurance
US11875317B2 (en) Electronic money transfer method and system for the same
US10402803B1 (en) Initiating a kiosk transaction
TWI697855B (zh) 基於移動終端卡模擬的信用支付方法及裝置
CN101098371B (zh) 金融数据处理方法和移动终端设备
US20070203850A1 (en) Multifactor authentication system
US20150193765A1 (en) Method and System for Mobile Payment and Access Control
US20140201086A1 (en) Method and system for reversed near field contact electronic transaction
KR20140125449A (ko) 거래 프로세싱 시스템 및 방법
CN102197407A (zh) 安全支付交易的系统和方法
WO2001088785A1 (fr) Systeme de reglement electronique, dispositif de reglement et terminal
CN103198405A (zh) 一种基于摄像头扫描验证的智能支付方法与系统
KR20110039946A (ko) 가맹점 무선 결제 방법 및 시스템과 이를 위한 기록매체
JP2007241359A (ja) 自動取引システム
CN101449509A (zh) 用于增强的消费者支付的方法和系统
CN104933565A (zh) 一种ic卡交易方法及系统
WO2007071157A1 (fr) Procede de reconnaissance pour paiement electronique et terminal d'authentification d'identite et guichet automatique
JP2004199269A (ja) 携帯端末によるクレジット決済システムおよび方法、クレジット決済サーバ、並びにプログラム
KR101865879B1 (ko) 선승인에 의한 금융거래 제공 시스템 및 그 방법
US20210133726A1 (en) Transaction support program and system
WO2015139623A1 (en) Method and system for mobile payment and access control
CN103430199B (zh) 利用移动手机的安全支付系统及利用该支付系统的支付方法
US20100153223A1 (en) Method and system for registering a customer with an organization

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12856622

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC, FORM 1205A DATED 14-11-2014

122 Ep: pct application non-entry in european phase

Ref document number: 12856622

Country of ref document: EP

Kind code of ref document: A1