WO2013097358A1 - 网络支付方法及装置 - Google Patents

网络支付方法及装置 Download PDF

Info

Publication number
WO2013097358A1
WO2013097358A1 PCT/CN2012/072397 CN2012072397W WO2013097358A1 WO 2013097358 A1 WO2013097358 A1 WO 2013097358A1 CN 2012072397 W CN2012072397 W CN 2012072397W WO 2013097358 A1 WO2013097358 A1 WO 2013097358A1
Authority
WO
WIPO (PCT)
Prior art keywords
payment
network
mobile terminal
terminal
information
Prior art date
Application number
PCT/CN2012/072397
Other languages
English (en)
French (fr)
Inventor
刘春海
彭辉俊
张忠海
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2013097358A1 publication Critical patent/WO2013097358A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/12Payment architectures specially adapted for electronic shopping systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • G06Q20/3227Aspects of commerce using mobile devices [M-devices] using secure elements embedded in M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4012Verifying personal identification numbers [PIN]

Definitions

  • the present invention relates to the field of communications, and in particular to a network payment method and apparatus.
  • BACKGROUND OF THE INVENTION Near Field Communication (FC) also known as short-range wireless communication, is a short-range high-frequency wireless communication technology that allows non-contact point-to-point data transmission between electronic devices to exchange data.
  • FC Near Field Communication
  • a large number of FC mobile phones are accepted by users, and the close-range payment function of FC mobile phones has also been widely used. Consumers have experienced a convenient and fast shopping experience, but the close-range payment method of FC mobile phones Still a face-to-face shopping method.
  • the traditional face-to-face shopping method can no longer meet the needs of consumers.
  • the shopping method must be developed in many directions and in multiple channels.
  • the online payment method is mainly an electronic wallet (for example, Alipay, etc.).
  • the electronic wallet has complicated use in online payment and needs to apply for an account.
  • the most important point is security. Poor sex, etc., which leads to poor security performance is that e-wallet does not use strict security measures such as proprietary hardware encryption for online payment.
  • there is currently no secure payment method which can solve the problem of poor security performance of the existing network payment method.
  • a network payment method including: a network terminal transmitting a payment request to a mobile terminal, wherein the network terminal is connected to the Internet; and the network terminal determines, in the case that the mobile terminal determines that the security verification information input by the user is correct Receiving the confirmation success message sent by the mobile terminal; the network terminal acquires the encrypted information stored in the mobile terminal by using the confirmation success information; and the network terminal encrypts the payment information according to the encrypted information, and then performs network payment.
  • the determining, by the mobile terminal, the security verification information input by the user includes: receiving, by the mobile terminal, the security verification information input by the user; and determining the security verification information according to the preset security information stored in the mobile terminal; When the determination is YES, the confirmation success information is transmitted to the network terminal.
  • the preset security information comprises one of the following: a security password, fingerprint identification information.
  • the method includes: the network terminal is connected to the mobile terminal by using one of the following methods: a USB interface, a Bluetooth interface.
  • the network terminal is an Internet terminal, and includes: a transaction platform for performing online payment by the Internet.
  • the mobile terminal is an NFC mobile phone
  • the method includes: a security encryption module, wherein the security encryption module stores the encrypted information.
  • the security encryption module is a security device (Secrecy Element, referred to as SE) module.
  • SE Security Element
  • the encrypted information is a digital certificate.
  • a network payment apparatus comprising: a sending module, configured to send a payment request to a mobile terminal, wherein the network terminal is connected to the Internet; and the first receiving module is configured to determine the user at the mobile terminal When the input security verification information is correct, the receiving success information sent by the mobile terminal is received; the obtaining module is configured to acquire the encrypted information stored in the mobile terminal according to the confirmation success information; and the payment module is configured to encrypt the payment information according to the encrypted information.
  • the apparatus further includes: a second receiving module, configured to receive a payment completion message fed back by the bank mobile payment server after the settlement processing.
  • the invention solves the problem that the existing network payment method has low security performance by using the network terminal in combination with the mobile terminal and implementing hardware encryption in the mobile terminal, thereby achieving the improvement of the security performance of the network payment method. It can also meet the needs of users to select face-to-face short-range payment or network payment methods, thereby improving the user experience.
  • FIG. 1 is a flow chart of a network payment method according to an embodiment of the present invention
  • FIG. 2 is a flow chart of network online payment according to a preferred embodiment of the present invention
  • FIG. 3 is a flow chart of data transmission and encryption according to a preferred embodiment of the present invention.
  • 4 is a structural block diagram of a network payment device according to an embodiment of the present invention
  • FIG. 5 is a structural block diagram of a preferred network payment device according to an embodiment of the present invention
  • FIG. 6 is a system for applying a network payment device according to a preferred embodiment of the present invention
  • FIG. 7 is a block diagram showing the hardware configuration of a system for applying a network payment device according to a preferred embodiment of the present invention.
  • the method mainly includes the following steps (step S102 - step S108 ): Step S102 , the network terminal sends a payment request to the mobile terminal, where The network terminal is connected to the Internet. Step S104: The network terminal receives the confirmation success information sent by the mobile terminal when the mobile terminal determines that the security verification information input by the user is correct. Step S106: The network terminal acquires the encrypted information stored in the mobile terminal by using the confirmation success information. Step S108: The network terminal encrypts the payment information according to the encrypted information, and then performs network payment.
  • step S104 the mobile terminal determines the security verification information input by the user, including: when the mobile terminal receives the payment request, receiving the security verification information input by the user; and the security verification information according to the preset security information stored in the mobile terminal. A determination is made; if the determination is YES, the confirmation success information is transmitted to the network terminal.
  • the preset security information may include one of the following: a security password, fingerprint identification information.
  • the network terminal is an Internet terminal, and the Internet terminal includes: a transaction platform for online payment by the Internet; the mobile terminal is a FC mobile phone, and the NFC mobile phone includes: a security encryption module, wherein the security encryption Encrypted information is stored in the module.
  • the security encryption module is an SE module, and the encryption information is a digital certificate.
  • the secure payment method for performing encryption includes the following steps: a mobile terminal (for example, a FC mobile phone) establishes a connection with a terminal (eg, a PC) through a communication interface such as USB or Bluetooth; the user performs a PC On-line consumption, when the payment needs to be made, the PC side sends a payment request to the FC mobile phone to request confirmation of the payment behavior; after receiving the request, the FC mobile phone side authenticates the user identity through security measures such as user input password or fingerprint detection. If the input is verified, the payment request is confirmed and a confirmation message is sent to the PC.
  • a mobile terminal for example, a FC mobile phone
  • Step S202 The terminal is connected to a mobile phone having an NFC function.
  • the FC mobile phone is connected to the terminal (for example, a PC) through a communication means such as a USB interface or a Bluetooth interface; after the terminal recognizes the FC mobile phone, it can communicate with the baseband chip of the NFC mobile phone through the USB, thereby completing data exchange and control messages of the PC and the NFC mobile phone information. exchange.
  • Step S204 The terminal side sends a payment request to the NFC mobile phone.
  • the user connects to the public network through the terminal to perform online consumption.
  • the FC mobile phone payment is required, and the terminal sends a payment request command to the mobile phone side.
  • the FC mobile phone performs security confirmation by means of a password or the like.
  • FIG. 3 is a flowchart of data transmission and encryption according to a preferred embodiment of the present invention. As shown in FIG.
  • Step S302 the terminal sends a request to read the digital certificate in the NFC mobile phone.
  • the baseband chip on the terminal side and the FC mobile phone side establishes an underlying driving connection through the communication interface, and the terminal side sends a request to read the digital certificate stored by the SE module in the NFC mobile phone to the FC mobile phone side, and the mobile phone system on the FC mobile phone side processes the request.
  • Step S304 the FC mobile phone sends a password input request of the digital certificate to the terminal side. After the FC mobile phone side responds to the request message, the message is transmitted to the terminal side through the communication interface, and the password request of the digital certificate is sent, and the mobile phone side processes the message.
  • Step S306 After inputting the digital certificate password, the terminal side obtains the digital certificate by using the SE function of the FC mobile phone. After the terminal sends the password, the FC mobile phone sends a command to obtain the SE digital certificate to the FC module through the IIC (Inter Integrated Circuit) communication interface. The SE returns the digital certificate to the FC module, and the FC module passes the number through the IIC interface. The certificate is sent to the baseband chip of the mobile phone, and finally to the FC mobile phone side; the FC mobile phone side transmits the digital certificate to the terminal side.
  • Step S308 the terminal side signs and encrypts the bank account and the payment amount by using the digital certificate, and the terminal finally sends the encrypted account and the payment amount to the bank mobile payment server through the public network to send a payment instruction.
  • a preferred embodiment of the present invention provides two methods:
  • the network payment method provided by the foregoing embodiment solves the problem that the existing network payment method has low security performance, thereby improving the security performance of the network payment method, and at the same time, satisfying the user to select a face-to-face short-range payment or network.
  • the need for payment methods thereby improving the user experience.
  • 4 is a structural block diagram of a network payment device according to an embodiment of the present invention.
  • the device is used to implement the network payment method provided by the foregoing embodiment.
  • the device includes: a sending module 10, a first receiving module 20, an obtaining module 30, and a payment module. 40.
  • the sending module 10 is configured to send a payment request to the mobile terminal, where the network terminal is connected to the Internet; and is connected to the sending module 10, and configured to receive, when the mobile terminal determines that the security verification information input by the user is correct, the receiving mobile terminal sends The confirmation success information; the obtaining module 30 is connected to the first receiving module 20, and configured to acquire the encrypted information stored in the mobile terminal according to the confirmation success information; the payment module 40 is connected to the obtaining module 30, and configured to perform the payment information according to the encrypted information. Perform network payment after encryption.
  • the device can well realize the security of the online payment method of the network.
  • FIG. 5 is a structural block diagram of a preferred network payment device according to an embodiment of the present invention. As shown in FIG.
  • the device further includes: a second receiving module 50 connected to the payment module 40, configured to receive a bank mobile payment server for settlement processing.
  • 6 is a system structural diagram of an application network payment device according to a preferred embodiment of the present invention.
  • an internet payment platform mainly refers to a transaction platform for online payment of a bank through the Internet; It mainly includes various communication terminals, such as PC, netbook, tablet, etc.
  • As the main carrier for network electronic payment it interacts with mobile banking payment platform for online electronic payment
  • FC mobile phone side mainly refers to FC chip and Secure encryption module (SE security module) and NFC-enabled mobile phone.
  • FIG. 7 is a schematic diagram showing the hardware structure of a system for applying a network payment device according to a preferred embodiment of the present invention. As shown in FIG. 7, first, the mobile phone side is connected to the PC side through USB, so that the communication process between the two can be completed through the USB bus.
  • a USB host controller can be set on the PC side
  • a USB slave device controller can be set on the mobile phone side
  • a USB slave controller on the PC side can be connected with the USB slave device controller on the mobile phone side, thereby enabling The process of completing two-way communication between the mobile phone side and the PC side.
  • the FC chip mainly adopts INSIDE SECURE to introduce SECUREAD, and the main data communication interface of the chip is the IIC communication interface.
  • the mobile phone side baseband chip is connected to the FC chip through the IIC main controller, and the FC chip is used as the secondary device of the IIC.
  • the mobile phone baseband chip can transmit to the FC through the IIC, and receive data from the FC, so that the baseband chip on the mobile phone side can be
  • the FC chip controls and performs data interaction with the FC chip.
  • Baseband The chip also provides an external clock to the FC chip for use within the FC chip.
  • the mainstream FC chip and SE one is that the SE module is directly built into the NFC chip; the other is that the SE module is a separate chip, which is via SWP (Single Wire Protocol).
  • the FC chip is connected.
  • the second method is adopted.
  • the NFC chip can also provide power for the SE security module chip, and the communication process between the FC chip and the SE chip is to transmit data through the SWP (single line protocol).
  • the hardware certificate of the SE module can be obtained by controlling the FC chip.
  • the PC side communicates with the mobile phone baseband chip through the USB interface
  • the mobile phone baseband chip communicates with the FC chip through the IIC
  • the FC chip communicates with the SE through the SWP (single line protocol)
  • the PC side can be completed by the driver on the mobile phone side.
  • the communication and the mobile phone side control the SE encryption module on the mobile phone side through the transmission control command to the FC chip, thereby obtaining the encrypted information such as the digital certificate in the SE module, and then encrypting the delivered account amount by using the encrypted information such as the digital certificate to ensure the network. Online payment security.
  • the network payment device provided by the foregoing embodiment solves the problem that the existing network payment mode has low security performance, thereby improving the security performance of the network payment mode, and at the same time, satisfying the user to select a face-to-face short-range payment or network.
  • the need for payment methods thereby improving the user experience. From the above description, it can be seen that the present invention achieves the following technical effects: By connecting the terminal with the FC mobile phone, using the security module of the hardware in the FC mobile phone to perform online payment by the network, the network using the FC mobile phone is greatly expanded.
  • the payment function realizes a unified payment means, that is, the traditional FC close-range payment means can be utilized, and the network payment method can be utilized to secure network payment by using the hardware-encrypted security module (SE) in the FC mobile phone, maximizing It is convenient for users and improves the security of network payment.
  • SE hardware-encrypted security module

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种网络支付方法及装置。其中,该方法包括:网络终端向移动终端发送支付请求,其中,网络终端与互联网连接;网络终端在移动终端判定用户输入的安全验证信息正确的情况下,接收移动终端发送的确认成功信息;网络终端使用确认成功信息获取移动终端中存储的加密信息;网络终端根据加密信息对支付信息进行加密后进行网络支付。通过本发明,可以提高网络在线支付的安全性能。

Description

网络支付方法及装置 技术领域 本发明涉及通信领域, 具体而言, 涉及一种网络支付方法及装置。 背景技术 近场通信 (Near Field Communication, 简称为 FC), 又称近距离无线通信, 是 一种短距离的高频无线通信技术, 该技术允许电子设备之间进行非接触式点对点数据 传输交换数据。 随着 FC技术的商业应用, 大量的 FC手机被用户接受, FC手机 的近距离支付功能也得到了广泛的应用, 消费者从中感受到了方便快捷的购物体验, 但是, FC手机的近距离支付方式仍旧属于面对面的购物方式。 随着网络的发展, 传统的面对面式的购物方式已经不能满足消费者的需求, 购物 方式必须朝着多方面、多渠道的方向发展, 而各种网络技术也顺应了这一个发展方向, 正逐渐改变着人们的购物习惯, 例如, 消费者可以通过网络实现完成交易, 购买自己 满意的商品。 当前, 网络在线支付功能得到了广泛的发展, 在线的网络支付手段主要 为电子钱包(例如: 支付宝等), 但是, 电子钱包在网络支付上存在使用复杂、 需要申 请账号, 最主要的一点是安全性较差等问题, 其中, 导致安全性能较差的原因是电子 钱包没有采用专有的硬件加密等严密的安全措施进行在线支付。 针对上述情况, 目前还没有一种安全支付方法, 可以解决现有网络支付方式的安 全性能较差的问题。 同时, 也没有一种既可以满足面对面的近距离支付, 又可以满足 网络上的在线支付方式的网络支付方式。 发明内容 本发明提供一种网络支付方法及装置, 以至少解决上述问题。 根据本发明的一个方面, 提供了一种网络支付方法, 包括: 网络终端向移动终端 发送支付请求, 其中, 网络终端与互联网连接; 网络终端在移动终端判定用户输入的 安全验证信息正确的情况下, 接收移动终端发送的确认成功信息; 网络终端使用确认 成功信息获取移动终端中存储的加密信息; 网络终端根据加密信息对支付信息进行加 密后进行网络支付。 优选地, 移动终端判定用户输入的安全验证信息, 包括: 当移动终端接收到支付 请求时, 接收用户输入的安全验证信息; 根据存储在移动终端的预设安全信息对安全 验证信息进行判断; 在判定为是的情况下, 向网络终端发送确认成功信息。 优选地, 预设安全信息包括以下之一: 安全密码、 指纹识别信息。 优选地, 在所网络终端向移动终端发送支付请求之前, 包括: 网络终端通过以下 方式之一与移动终端相连: USB接口、 蓝牙接口。 优选地, 网络终端为互联网终端, 包括: 通过互联网进行银行在线支付的交易平 台 优选地, 移动终端为 NFC手机, 包括: 安全加密模块, 其中, 安全加密模块中存 储有加密信息。 优选地, 安全加密模块为安全设备 (Secrecy Element, 简称为 SE) 模块。 优选地, 加密信息为数字证书。 根据本发明的另一方面, 提供了一种网络支付装置, 包括: 发送模块, 设置为向 移动终端发送支付请求, 其中, 网络终端与互联网连接; 第一接收模块, 设置为在移 动终端判定用户输入的安全验证信息正确的情况下, 接收移动终端发送的确认成功信 息; 获取模块, 设置为根据确认成功信息获取移动终端中存储的加密信息; 支付模块, 设置为根据加密信息对支付信息进行加密后进行网络支付。 优选地, 该装置还包括: 第二接收模块, 设置为接收银行移动支付服务器进行结 算处理后反馈的支付完成消息。 通过本发明, 采用在网络终端与移动终端结合使用、 在移动终端实现硬件加密的 方式, 解决了现有的网络支付方式安全性能较低的问题, 进而达到了提高网络支付方 式的安全性能, 同时, 也可以满足用户选取面对面的近距离支付或者网络支付方式的 需求, 从而提高了用户体验的效果。 附图说明 此处所说明的附图用来提供对本发明的进一步理解, 构成本申请的一部分, 本发 明的示意性实施例及其说明用于解释本发明, 并不构成对本发明的不当限定。 在附图 中: 图 1是根据本发明实施例的网络支付方法的流程示意图; 图 2是根据本发明优选实施例的网络在线支付的流程图; 图 3是根据本发明优选实施例的数据传输及加密的流程图; 图 4是根据本发明实施例的网络支付装置的结构框图; 图 5是根据本发明实施例的优选网络支付装置的结构框图; 图 6是根据本发明优选实施例的应用网络支付装置的系统结构图; 图 7是根据本发明优选实施例的应用网络支付装置的系统的硬件结构示意图。 具体实施方式 下文中将参考附图并结合实施例来详细说明本发明。 需要说明的是, 在不冲突的 情况下, 本申请中的实施例及实施例中的特征可以相互组合。 图 1是根据本发明实施例的网络支付方法的流程示意图, 如图 1所示, 该方法主 要包括以下步骤 (步骤 S102-步骤 S108 ): 步骤 S102, 网络终端向移动终端发送支付请求, 其中, 网络终端与互联网连接。 步骤 S104, 网络终端在移动终端判定用户输入的安全验证信息正确的情况下, 接 收移动终端发送的确认成功信息。 步骤 S106, 网络终端使用确认成功信息获取移动终端中存储的加密信息。 步骤 S108, 网络终端根据加密信息对支付信息进行加密后进行网络支付。 其中, 在步骤 S104中, 移动终端判定用户输入的安全验证信息, 包括: 当移动终 端接收到支付请求时, 接收用户输入的安全验证信息; 根据存储在移动终端的预设安 全信息对安全验证信息进行判断; 在判定为是的情况下, 向网络终端发送确认成功信 息。 在本发明的一个优选实施方式中, 预设安全信息可以包括以下之一: 安全密码、 指纹识别信息。 通过采取以用户输入安全验证信息的方式, 可以提高使用移动终端时 的安全性。 优选地, 在所网络终端向移动终端发送支付请求之前, 包括: 网络终端通过以下 方式之一与移动终端相连: USB接口、 蓝牙接口。 在本发明的一个优选实施方式中, 网络终端为互联网终端, 该互联网终端包括: 通过互联网进行银行在线支付的交易平台; 移动终端为 FC手机, 该 NFC手机包括: 安全加密模块, 其中, 安全加密模块中存储有加密信息。 通过以上较为安全的交易平 台和模块可以提高在线支付的安全性能。 优选地, 安全加密模块为 SE模块, 加密信息为数字证书。 例如, 在本发明的一个优选方式中, 进行加密的安全支付方法包括以下步骤: 移 动终端 (例如, FC手机) 通过 USB或者蓝牙等通信接口与终端 (例如, PC) 建立 连接; 用户通过 PC 进行网上消费, 在需要进行支付时, PC 侧发送一个支付请求给 FC手机, 用来请求确认支付行为; FC手机侧接收到请求后, 通过用户输入密码或 者指纹检测等安全措施对用户身份进行认证处理, 如果输入通过验证, 则确认允许支 付请求, 并向 PC发送确认成功的消息。 PC得到允许请求后, 从 FC 手机中的安全 模块(SE模块)获取加密信息,根据加密信息对账户信息和交付金额进行安全加密后, 再安全地通过外网传给移动银行服务器支付系统, 从而完成网络支付行为。 下面结合具体实施例对上述网络支付方法进行具体描述。 图 2是根据本发明优选实施例的网络在线支付的流程图, 如图 2所示, 该流程主 要包括以下步骤 (步骤 S202-步骤 S210): 步骤 S202, 终端与具有 NFC功能的手机连接。 FC手机通过 USB接口、 蓝牙接口等通信手段与终端 (例如, PC) 相连; 终端 识别 FC手机后可以通过 USB与 NFC手机的基带芯片通信,从而完成 PC与 NFC手 机信息的数据交换及控制消息的交换。 步骤 S204, 终端侧发送一个支付请求给 NFC手机。 用户通过终端与公网相连, 进行网上消费, 当需要支付时, 需要选择 FC手机支 付, 终端则向手机侧发送支付请求指令。 步骤 S206, FC手机通过密码等手段进行安全确认。 FC手机侧收到了终端发送的支付请求指令后, 用户需要通过手机侧进行安全验 证, 验证的方式可以通过指纹识别、手机密码等手段进行安全确认; 安全认证成功后, FC手机侧向终端回传一个确认成功指令。 步骤 S208, 终端利用 FC 手机中的安全模块, 将账户信息, 交付金额, 进行安 全加密后, 安全的传给网络服务器, 进行网络支付行为。 步骤 S210, 银行移动支付服务器进行结算处理后, 反馈支付完成信息。 以下结合图 3对 S208中的数据传输及加密过程进行具体描述: 图 3是根据本发明优选实施例的数据传输及加密的流程图, 如图 3所示, 该流程 主要包括以下步骤 (步骤 S302-步骤 S308): 步骤 S302, 终端发送请求读 NFC手机中的数字证书。 首先终端侧与 FC手机侧的基带芯片通过通信接口建立底层驱动连接,终端侧向 FC手机侧发送读取 NFC手机中的 SE模块存储的数字证书的请求, FC手机侧的手 机系统处理这个请求。 步骤 S304, FC手机侧向终端侧发送数字证书的密码输入请求。 FC手机侧对请求消息做出应答后, 通过通信接口把消息传给终端侧, 并发送数 字证书的密码请求, 手机侧进行消息的处理。 步骤 S306, 终端侧在输入数字证书密码通过后, 通过 FC手机的 SE功能获取数 字证书。 终端侧发送密码后, FC手机侧通过 IIC (Inter Integrated Circuit, 内部集成电路) 通信接口向 FC模块发送获取 SE数字证书的命令, SE将数字证书返回给 FC模块, FC模块将通过 IIC接口把数字证书发送给手机基带芯片, 最终交给了 FC手机侧; FC手机侧再将数字证书传给终端侧。 步骤 S308, 终端侧通过数字证书对银行账户及支付金额进行签名加密, 终端最终 将加密后的账号和支付金额通过公网向银行移动支付服务器发送支付指令。 对于 S210的实现, 本发明的优选实施例提供两种方法:
( 1 ) 通过银行支付后结果通过公网进行反馈, 以网页的形式反馈给用户;
(2)通过手机短信的方式通知给用户, 使用户可以方便得到交易的结果, 这样既 安全又方便。 采用上述实施例提供的网络支付方法, 解决了现有的网络支付方式安全性能较低 的问题, 进而达到了提高网络支付方式的安全性能, 同时, 也可以满足用户选取面对 面的近距离支付或者网络支付方式的需求, 从而提高了用户体验的效果。 图 4是根据本发明实施例的网络支付装置的结构框图, 该装置用以实现上述实施 例提供的网络支付方法, 该装置包括: 发送模块 10、 第一接收模块 20、 获取模块 30 以及支付模块 40。 其中, 发送模块 10, 设置为向移动终端发送支付请求, 其中, 网络 终端与互联网连接; 连接至发送模块 10, 设置为在移动终端判定用户输入的安全验证 信息正确的情况下, 接收移动终端发送的确认成功信息; 获取模块 30, 连接至第一接 收模块 20, 设置为根据确认成功信息获取移动终端中存储的加密信息; 支付模块 40, 连接至获取模块 30, 设置为根据加密信息对支付信息进行加密后进行网络支付。 该装 置可以很好地实现网络在线支付方式的安全性。 图 5是根据本发明实施例的优选网络支付装置的结构框图, 如图 5所示, 该装置 还包括: 第二接收模块 50, 连接至支付模块 40, 设置为接收银行移动支付服务器进行 结算处理后反馈的支付完成消息。 图 6是根据本发明优选实施例的应用网络支付装置的系统结构图, 如图 6所示, 在该系统中: 互联网支付平台, 主要是指通过互联网进行银行的在线支付的交易平台; 终端侧, 主要包含各类通信终端, 例如, PC机, 上网本, 平板电脑等, 作为进行网络 电子支付的主要载体, 与移动银行支付平台交互进行在线电子支付; FC手机侧, 主 要是指包含 FC芯片及安全加密模块(SE安全模块)且具有 NFC功能的手机。 在本 系统中, 主要是利用 FC手机中的 SE安全模块来保证网络在线交易的安全性。 下面以图 6中的 PC侧与手机侧之间通过 USB通信接口进行通信为例, 结合图 7 对该通信流程进行描述。 图 7是根据本发明优选实施例的应用网络支付装置的系统的硬件结构示意图, 如 图 7所示, 首先, 手机侧通过 USB连接到 PC侧, 使二者的通信过程可以通过 USB 总线来完成, 在本实例例中, PC侧可以设置一个 USB主控制器, 手机侧可以设置一 个 USB从设备控制器, PC侧的 USB主控制器与手机侧的 USB从设备控制器进行连 接, 进而可以使手机侧与 PC侧完成双向通信的过程。 在本实施例中, FC芯片主要 采用 INSIDE SECURE公司推出 SECUREAD,芯片主要的数据通信接口是 IIC 通信接 口。手机侧基带芯片通过 IIC 主控制器与 FC芯片连接, FC芯片作为 IIC的从设备, 因此, 手机基带芯片可以通过 IIC向 FC发送, 和接收来自 FC的数据, 从而使手 机侧的基带芯片可以对 FC芯片进行控制, 并与 FC芯片进行数据交互。 同时基带 芯片还要向 FC 芯片提供一个外部的时钟, 以供 FC芯片内部工作时使用。 目前, 主流的 FC芯片与 SE的组合有两种方式: 一种是 SE模块直接内置到 NFC芯片内; 另一种是 SE模块是一个单独的芯片, 通过 SWP ( Single Wire Protocol, 单线协议) 与 FC芯片连接,本实施例采用第二种方式, NFC芯片还可以为 SE安全模块芯片提供 电源, FC芯片与 SE芯片的通信过程是通过 SWP (单线协议) 传输数据的。 因此, 通过对 FC芯片的控制可以获得 SE模块的硬件加密的数字证书。综上所述, PC侧通 过 USB接口与手机基带芯片通信, 手机基带芯片通过 IIC与 FC芯片通信, FC芯 片通过 SWP (单线协议) 与 SE通信, 最终, 通过驱动可以完成 PC侧对手机侧的通 信和手机侧通过向 FC芯片的发送控制命令控制手机侧的 SE加密模块, 从而获得存 在 SE模块中的数字证书等加密信息, 进而利用数字证书等加密信息对交付的账户金 额进行加密, 保证网络在线支付的安全。 采用上述实施例提供的网络支付装置, 解决了现有的网络支付方式安全性能较低 的问题, 进而达到了提高网络支付方式的安全性能, 同时, 也可以满足用户选取面对 面的近距离支付或者网络支付方式的需求, 从而提高了用户体验的效果。 从以上的描述中, 可以看出, 本发明实现了如下技术效果: 通过终端与 FC手机 连接, 利用 FC手机中的硬件的安全模块进行网络在线支付的方式, 极大地扩充了利 用 FC手机进行网络支付的功能, 实现统一的支付手段, 即可以利用传统的 FC近 距离支付手段,又可以利用网络支付方法通过利用 FC手机中的硬件加密的安全模块 ( SE) 进行安全的网络支付, 最大化的方便了用户, 提高了网络支付的安全性能。 显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤可以用通用 的计算装置来实现, 它们可以集中在单个的计算装置上, 或者分布在多个计算装置所 组成的网络上, 可选地, 它们可以用计算装置可执行的程序代码来实现, 从而, 可以 将它们存储在存储装置中由计算装置来执行, 并且在某些情况下, 可以以不同于此处 的顺序执行所示出或描述的步骤, 或者将它们分别制作成各个集成电路模块, 或者将 它们中的多个模块或步骤制作成单个集成电路模块来实现。 这样, 本发明不限制于任 何特定的硬件和软件结合。 以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于本领域的技 术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精神和原则之内, 所作的 任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书
1. 一种网络支付方法, 包括:
网络终端向移动终端发送支付请求, 其中, 所述网络终端与互联网连接; 所述网络终端在所述移动终端判定用户输入的安全验证信息正确的情况 下, 接收所述移动终端发送的确认成功信息;
所述网络终端使用所述确认成功信息获取所述移动终端中存储的加密信 息;
所述网络终端根据所述加密信息对支付信息进行加密后进行网络支付。
2. 根据权利要求 1所述的方法, 其中, 所述移动终端判定用户输入的安全验证信 息, 包括:
当所述移动终端接收到所述支付请求时, 接收用户输入的所述安全验证信 息;
根据存储在所述移动终端的预设安全信息对所述安全验证信息进行判断; 在判定为是的情况下, 向所述网络终端发送所述确认成功信息。
3. 根据权利要求 2所述的方法, 其中, 所述预设安全信息包括以下之一: 安全密 码、 指纹识别信息。
4. 根据权利要求 2所述的方法, 其中, 在所网络终端向移动终端发送支付请求之 前, 包括:
所述网络终端通过以下方式之一与所述移动终端相连: USB接口、 蓝牙接 曰。
5. 根据权利要求 2所述的方法, 其中,
所述网络终端为互联网终端, 包括: 通过互联网进行银行在线支付的交易 平台。
6. 根据权利要求 2所述的方法, 其中,
所述移动终端为 FC手机, 包括: 安全加密模块, 其中, 所述安全加密模 块中存储有所述加密信息。
7. 根据权利要求 6所述的方法, 其中, 所述安全加密模块为安全设备 SE模块。
8. 根据权利要求 1至 7中任一项所述的方法, 其中, 所述加密信息为数字证书。
9. 一种网络支付装置, 包括:
发送模块, 设置为向移动终端发送支付请求, 其中, 所述网络终端与互联 网连接;
第一接收模块, 设置为在所述移动终端判定用户输入的安全验证信息正确 的情况下, 接收所述移动终端发送的确认成功信息;
获取模块, 设置为根据所述确认成功信息获取所述移动终端中存储的加密 信息;
支付模块,设置为根据所述加密信息对支付信息进行加密后进行网络支付。
10. 根据权利要求 9所述的装置, 其中, 所述装置还包括: 第二接收模块, 设置为接收银行移动支付服务器进行结算处理后反馈的支 付完成消息。
PCT/CN2012/072397 2011-12-26 2012-03-15 网络支付方法及装置 WO2013097358A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110441862.4 2011-12-26
CN201110441862.4A CN102521744B (zh) 2011-12-26 2011-12-26 网络支付方法及装置

Publications (1)

Publication Number Publication Date
WO2013097358A1 true WO2013097358A1 (zh) 2013-07-04

Family

ID=46292653

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/072397 WO2013097358A1 (zh) 2011-12-26 2012-03-15 网络支付方法及装置

Country Status (2)

Country Link
CN (1) CN102521744B (zh)
WO (1) WO2013097358A1 (zh)

Families Citing this family (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102790767B (zh) * 2012-07-03 2015-07-08 北京神州绿盟信息安全科技股份有限公司 信息安全控制方法,信息安全显示设备,及电子交易系统
CN103679531A (zh) * 2012-09-25 2014-03-26 动信科技股份有限公司 行动金融交易系统及方法
CN103049850A (zh) * 2013-01-05 2013-04-17 深圳市中兴移动通信有限公司 一种基于nfc的移动支付终端、系统及其支付方法
CN103093350A (zh) * 2013-02-05 2013-05-08 山东泰信电子股份有限公司 一种基于nfc技术的在线支付方法
CN103218713A (zh) * 2013-05-13 2013-07-24 上海盛本通讯科技有限公司 基于智能平台的多功能pos终端、系统及其支付方法
CN103268547A (zh) * 2013-06-04 2013-08-28 北京邮电大学 具有指纹认证机制的nfc手机支付系统
CN104301293B (zh) * 2013-07-19 2018-11-30 阿里巴巴集团控股有限公司 数据处理方法、装置和系统
CN103455913B (zh) * 2013-08-26 2017-09-19 天地融科技股份有限公司 Nfc支付方法、装置、系统及移动终端
CN103824185B (zh) * 2014-03-05 2017-08-08 平安壹钱包电子商务有限公司 一种基于低功耗蓝牙的移动智能终端支付方法及系统
CN103927658A (zh) * 2014-04-08 2014-07-16 深圳市中兴移动通信有限公司 移动支付方法和移动支付终端
CN104809611A (zh) * 2015-04-20 2015-07-29 王宏旭 一种基于云平台下物联网移动金融支付方法和系统
CN104881779A (zh) * 2015-06-17 2015-09-02 恒宝股份有限公司 一种移动融合支付装置、系统及支付方法
CN113115285B (zh) * 2015-06-23 2024-06-07 创新先进技术有限公司 信息处理方法及装置
CN106296197A (zh) * 2015-06-25 2017-01-04 深圳市中兴微电子技术有限公司 一种支付的方法、设备和系统
CN105069442B (zh) * 2015-08-25 2018-12-07 杭州晟元数据安全技术股份有限公司 一种指纹安全单元se模组及支付验证方法
CN105225110A (zh) * 2015-09-14 2016-01-06 李思贤 一种支付处理方法及系统
CN106651366A (zh) * 2015-11-03 2017-05-10 国民技术股份有限公司 一种移动终端及其交易确认方法、装置以及一种智能卡
CN106941615B (zh) * 2016-01-04 2020-01-07 中国移动通信集团公司 一种支付方法、机顶盒及系统
KR102646892B1 (ko) * 2016-03-18 2024-03-13 삼성전자 주식회사 결제 수행 방법 및 이를 제공하는 전자 장치
CN106101984B (zh) * 2016-05-31 2019-08-02 东莞宇龙通信科技有限公司 一种nfc移动支付终端的安全模块管理方法及终端
CN106651331B (zh) * 2016-12-22 2019-11-29 飞天诚信科技股份有限公司 一种基于数字货币的电子交易方法及系统
CN110558976A (zh) * 2019-10-15 2019-12-13 听心(上海)智能科技有限公司 一种无电池的便携式心电监测装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101014985A (zh) * 2004-04-05 2007-08-08 佩兹公司B.V. 使用作为储值装置的普通的移动装置使跨越不同的支付系统的非接触支付交易便利的系统和方法
CN101567109A (zh) * 2009-06-03 2009-10-28 普天信息技术研究院有限公司 一种集成支付和收款功能的装置、系统和交易方法
CN101668288A (zh) * 2009-08-25 2010-03-10 钱袋网(北京)信息技术有限公司 身份认证的方法、身份认证系统及终端

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100542088C (zh) * 2005-08-11 2009-09-16 北京握奇数据系统有限公司 一种物理认证方法及一种电子装置
US20070156436A1 (en) * 2005-12-31 2007-07-05 Michelle Fisher Method And Apparatus For Completing A Transaction Using A Wireless Mobile Communication Channel And Another Communication Channel
CN1805339B (zh) * 2005-12-31 2010-05-12 北京握奇数据系统有限公司 支持数字签名的个人可信设备及其实现签名的方法
US20080268938A1 (en) * 2007-04-28 2008-10-30 Stephane Pierre Doutriaux Systems and methods for gambling using combinations of gaming devices
CN101222333B (zh) * 2007-12-24 2010-11-10 北京握奇数据系统有限公司 一种数据交易处理方法及设备
CN101710433A (zh) * 2008-12-31 2010-05-19 深圳市江波龙电子有限公司 一种电子支付卡的交易方法及电子支付卡
CN102271012A (zh) * 2011-08-18 2011-12-07 中兴通讯股份有限公司 近场通信终端、系统及方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101014985A (zh) * 2004-04-05 2007-08-08 佩兹公司B.V. 使用作为储值装置的普通的移动装置使跨越不同的支付系统的非接触支付交易便利的系统和方法
CN101567109A (zh) * 2009-06-03 2009-10-28 普天信息技术研究院有限公司 一种集成支付和收款功能的装置、系统和交易方法
CN101668288A (zh) * 2009-08-25 2010-03-10 钱袋网(北京)信息技术有限公司 身份认证的方法、身份认证系统及终端

Also Published As

Publication number Publication date
CN102521744B (zh) 2017-11-03
CN102521744A (zh) 2012-06-27

Similar Documents

Publication Publication Date Title
WO2013097358A1 (zh) 网络支付方法及装置
US10733603B2 (en) Method and apparatus for facilitating electronic payments using a wearable device
KR101596279B1 (ko) 신뢰성있는 원격 지불 거래를 수행하기 위한 방법 및 장치
WO2017193741A1 (zh) 机载终端支付鉴权方法、装置以及系统
US9471916B2 (en) Wireless establishment of identity via bi-directional RFID
CA2676848A1 (en) Methods and a system for providing transaction related information
WO2012151894A1 (zh) 移动终端支付方法、系统及移动终端
KR101926020B1 (ko) 동적 결정된 인증번호를 이용한 결제 운영 시스템
TWI626607B (zh) Smart card with dynamic token OTP function and working method thereof
CN105554013A (zh) 基于usb设备的分离式身份认证装置及系统及方法
CN103761647A (zh) 电子支付系统及电子支付方法
WO2011137600A1 (zh) 一种带低频磁通信的射频通信接入方法
WO2015058576A1 (zh) 移动通信支付系统及其用于费用支付的方法
WO2017044677A1 (en) Method and apparatus for facilitating electronic payments using a wearable device
KR102172855B1 (ko) 사용자의 휴대형 매체를 이용한 매체 분리 기반 서버형 일회용코드 제공 방법
CN103813318B (zh) 一种信息配置方法、设备及系统
KR20160006646A (ko) 엔에프씨오티피카드를 이용한 비대면 거래 인증 방법
KR20160093197A (ko) 비접촉 매체를 이용한 무선 결제 방법
CN105322983A (zh) 移动设备使用的蓝牙Key和蓝牙POS
CN105245257B (zh) 近场通信设备间的点对点支付通信方法
KR20150065996A (ko) 카드를 이용한 일회용코드 기반 안심 로그인 방법
KR20150000081A (ko) 카드와 서버 사이의 종단간 인증을 이용한 일회용코드 제공 방법
KR20160006647A (ko) 엔에프씨오티피카드를 이용한 비대면 거래 인증 방법
KR20160093194A (ko) 비접촉 매체를 이용한 2채널 결제 방법
KR101445001B1 (ko) Nfc를 이용한 종단간 보안 결제 제공 방법 및 시스템

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12862715

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12862715

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 12862715

Country of ref document: EP

Kind code of ref document: A1