WO2014000601A1 - 安全性信息交互系统、设备及方法 - Google Patents

安全性信息交互系统、设备及方法 Download PDF

Info

Publication number
WO2014000601A1
WO2014000601A1 PCT/CN2013/077649 CN2013077649W WO2014000601A1 WO 2014000601 A1 WO2014000601 A1 WO 2014000601A1 CN 2013077649 W CN2013077649 W CN 2013077649W WO 2014000601 A1 WO2014000601 A1 WO 2014000601A1
Authority
WO
WIPO (PCT)
Prior art keywords
security information
information interaction
interface
request
terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/077649
Other languages
English (en)
French (fr)
Inventor
程志强
王海冰
何朔
鲁志军
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Publication of WO2014000601A1 publication Critical patent/WO2014000601A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems

Definitions

  • the present invention relates to an information interaction system, apparatus and method, and more particularly to a security information interaction system, apparatus and method. Background technique
  • security information such as POS machines
  • security information that is, information requiring high security, such as transactions
  • the interaction of amounts and/or passwords is becoming more and more important.
  • the conventional security information interaction terminal has the following problems: (1) it is difficult to update and install the application, resulting in high maintenance cost; (2) for new applications, it is required to be compatible with security platform of different platforms, resulting in Design and commissioning costs are high.
  • the present invention proposes a security information interaction system, apparatus and method which are easy to use and maintain and which are low in cost.
  • a security information interaction system includes:
  • a security information interaction terminal configured to acquire and display an application main interface and a security information interaction interface from the security information interaction management server based on the security information interaction instruction from the user, and based on the user
  • the security information input by the security information interaction interface constructs a security information interaction request, and sends the security information interaction request to the security information interaction management server;
  • the security information interaction management server is configured to provide the security information interaction terminal with the application main interface and the security information interaction interface, and a solution
  • the received security information interaction request is analyzed and processed to complete the security information interaction process, and the processing result is transmitted back to the security information interaction terminal.
  • the security information interactive terminal is a browser in the B/S mode.
  • the security information interaction terminal is further configured to display the processing result from the security information interaction management server.
  • the security information interaction terminal further includes: a user interface, configured to receive a security information interaction instruction from the user and transmit the security information interaction instruction to a main controller, and displaying the application main interface and the security information interaction interface and receiving the security information input by a user, and transmitting the security information to a main controller, where the user interface is further used for Displaying the processing result from the security information interaction management server;
  • a main controller configured to acquire the application main interface and the security information interaction interface from the security information interaction management server to pass the user interface according to the received security information interaction instruction Displaying, and constructing the security information interaction request based on the received security information, and transmitting the security information interaction request to the security information interaction management server.
  • the main controller acquires the application main interface and the security information interaction interface from the security information interaction management server by requesting a URL, where the application is
  • the main interface and the security information interaction interface are in the form of HTML pages.
  • the main controller passes the security information interaction type information.
  • the manner of requesting the URL obtains the security information interaction interface from the security information interaction management server, wherein the security information interaction interface includes security information interaction processing logic and data required by the processing logic.
  • the main controller processes the security information input by the user through the security information interaction interface displayed by the user interface according to the security information interaction processing logic. Constructing the security information interaction request, and transmitting the security information interaction request to the security information interaction management server in an HTTP message manner, where The security information interaction request contains an indication of the type of security information interaction.
  • the security information interaction management server further includes:
  • a main control module configured to receive an application main interface URL request and a security information interaction interface URL request from the security information interaction terminal, and use the application main interface URL request and the security information interaction interface Sending the URL request to the interface generation module, and receiving and parsing the security information interaction request from the security information interaction terminal, and transmitting the parsed security information interaction request to the security information interaction request processing module;
  • An interface generating module configured to generate a security information interaction interface based on the received application home interface URL and based on the received security information interaction interface URL request, and generate the security information interaction interface Transmitting back to the security information interaction terminal, where the security information interaction interface URL request includes the security information interaction type information;
  • the security information interaction request processing module is configured to process the received parsed security information interaction request, and complete a security information interaction process by performing data interaction with the data processing server, Transmitting the processing result back to the security information interaction terminal, wherein when the security information interaction request indicates that the type of the security information interaction is "offline mode", the security information interaction request processing module
  • the security information interaction data included in the security information interaction request is stored in the storage module;
  • the storage module is configured to store at least the security information interaction data
  • a communication module configured to execute the security information interaction management server, the security information interaction terminal, and the data processing Data communication between servers.
  • the main control module is further configured to authenticate the validity of the security information interaction terminal before parsing the security information interaction request, and the security after parsing The information interaction request is transmitted to the security information interaction request processing module by way of routing.
  • the security information interaction request processing module is based on the security The information interaction request constructs a security information interaction message in a predetermined format, and then And transmitting, in an encrypted manner, the security information interaction message to the data processing server for subsequent processing, and transmitting the processing result sent back by the data processing server to the security information interaction terminal in the form of an HTML page .
  • the security information interaction request processing module when the received security information interaction request indicates that the type of the security information interaction is "offline mode", the security information interaction request processing module will perform the security
  • the security information interaction data included in the sexual information interaction request is stored in the storage module, and the processing result is transmitted back to the security information interaction terminal in the form of an HTML page.
  • the security information interaction request processing module periodically transmits unprocessed security information interaction data stored in the storage module to the data processing in a batch manner.
  • the server performs subsequent processing.
  • the security information interaction terminal performs data transmission with each other in the secure manner.
  • the main control module is further configured to uniformly manage the security information interaction terminal.
  • a security information interaction terminal configured to acquire and display an application main interface and a security information interaction interface from a security information interaction management server based on a security information interaction instruction from a user, and The security information input by the security information interaction interface constructs a security information interaction request, and sends the security information interaction request to the security information interaction management server.
  • a security information interaction management server configured to provide an application main interface and a security information interaction interface for the security information interaction terminal, and parse and process the received interaction from the security information.
  • the security information exchange request of the terminal completes the security information interaction process, and transmits the processing result back to the security information interaction terminal.
  • a security information interaction method includes the following steps:
  • the security information interaction terminal is based on security information from the user to interact with the instruction from the security
  • the information interaction management server acquires and displays the application main interface
  • the security information interaction terminal searches for the security information interaction management server by requesting the URL based on the security information interaction type information.
  • the security information interaction interface includes security information interaction processing logic and data required by the processing logic;
  • the security information interaction management server parses and processes the received security information interaction request to complete the security information interaction process, and transmits the processing result back to the security information interaction terminal.
  • the security information interaction system, device and method disclosed by the present invention have the following advantages: Since the B/S mode is adopted, the processing logic executed in the conventional security information interaction terminal is transferred to the security information interaction management server. Executable, easy to use and maintain and low cost. DRAWINGS
  • FIG. 1 is an architectural diagram of a security information interaction system in accordance with an embodiment of the present invention
  • FIG. 2 is a flow chart of a method of security information interaction in accordance with an embodiment of the present invention. detailed description
  • the security information interaction system disclosed by the present invention includes a security information interaction terminal 1 and a security information interaction management server 2 (exemplarily, the security information interaction management server 2 may be in the financial field) P0S terminal backend system).
  • the security information interaction terminal 1 is configured to acquire and display an application main interface and a security information interaction interface from the security information interaction management server 2 based on the security information interaction instruction from the user, and based on the user passing the security.
  • Information interaction interface input constructs a security information interaction request (where the security information interaction request includes an identifier of the security information interaction terminal 1), and sends the security information interaction request to the security information Interactively manage server 2.
  • the security information interaction management server 2 is configured to provide the security information interaction terminal 1 with the application main interface and the security information interaction interface, and parse and process the received security information interaction request. The security information interaction process is completed, and the processing result is transmitted back to the security information interaction terminal 1.
  • the security information interaction terminal 1 is a browser in the B/S mode (exemplarily, the browser is located at a mobile terminal, or a personal computer, Or in a POS machine, and can be exemplarily, but not limited to, running on a Window CE, or Andro id, or Linux operating system platform).
  • the security information interaction management server 2 is a server in the B/S mode.
  • the security information interaction terminal 1 is further configured to display the processing result from the security information interaction management server 2.
  • the security information interaction terminal 1 further includes a main controller 3 and a user interface 4.
  • the user interface 4 is configured to receive a security information interaction instruction from a user, and transmit the security information interaction instruction to the main controller 3, and display the application main interface and the security information interaction interface.
  • Receiving the security information input by the user exemplarily, the security information may include a transaction type, a consumption amount, track information or smart card information, etc.
  • the user interface 4 is also used to display the processing result from the security information interaction management server 2.
  • the main controller 3 is configured to acquire the application main interface and the security information interaction interface from the security information interaction management server 2 to pass the user interface 4 based on the received security information interaction instruction. Displaying, and constructing the security information interaction request based on the received security information, and transmitting the security information interaction request to the security information interaction management server 2.
  • the main controller 3 acquires the application main interface and the security information interaction from the security information interaction management server 2 by requesting a URL.
  • the interface where the application main interface and the security information interaction interface are in the form of an HTML page.
  • the security information interaction type information is input by the user through the application main interface displayed by the user interface 4 (exemplarily, in the financial field, security After the sex information interaction type may be "balance inquiry", "consumption", "storage”, etc., the main controller 3 interacts with the security information by requesting a URL based on the security information interaction type information.
  • the management server 2 acquires the security information interaction interface, wherein the security information interaction interface includes security information interaction processing logic and data required by the processing logic (exemplarily, the security is provided in the manner of JavaScr ipt Sexual information interaction processing logic).
  • the main controller 3 processes the user's input through the security information interaction interface displayed by the user interface 4 according to the security information interaction processing logic.
  • the security information (for example, the data is packaged) to construct the security information interaction request, and the security information interaction request is transmitted to the security information interaction management server 2 in the form of an HTTP message, where
  • the security information interaction request includes an indication of the type of security information interaction (ie, "online mode” or "offline mode”).
  • the security information interaction management server 2 further includes a main control module 5, a security information interaction request processing module 6, an interface generation module 7, a storage module 8, and Communication module 9.
  • the main control module 5 is configured to receive an application main interface URL request and a security information interaction interface URL request from the security information interaction terminal 1, and interface the application main interface URL request and the security information.
  • the URL request is transmitted to the interface generation module 7, and the security information interaction request from the security information interaction terminal 1 is received and parsed, and the parsed security information interaction request is transmitted to the security information interaction request processing module. 6.
  • the interface generating module 7 is configured to generate a security information interaction interface according to the received application main interface URL request to generate the security information interaction interface URL request (preferably, the security information interaction interface) Include the security information interaction processing logic and data required by the processing logic) and transmit the security information interaction interface back to the security information interaction terminal 1 , wherein the security information interaction interface URL request includes the Security information interaction type information.
  • the security information interaction request processing module 6 is configured to process the received parsed security information interaction request and pass the data processing server (exemplarily, the data processing server may be a financial receipt in the financial field) Data interaction of a single platform) completes the security information interaction process, and transmits the processing result Returning the security information interactive terminal 1 (exemplarily, the processing result is transmitted back to the security information interaction terminal 1 in the form of an HTML page), wherein when the security information interaction request indicates security When the type of the information interaction is "offline mode", the security information interaction request processing module 6 interacts with the security information interaction data included in the security information interaction request (for example, transaction information, which may include transaction type, transaction) The time, the transaction amount, and the like are stored in the storage module 8.
  • the storage module 8 is configured to store at least the security information interaction data.
  • the communication module 9 is configured to perform data communication between the security information interaction management server 2 and the security information interaction terminal 1 and the data processing server.
  • the main control module 5 is further configured to authenticate the validity of the security information interaction terminal 1 before parsing the security information interaction request, and
  • the parsed security information interaction request is transmitted to the security information interaction request processing module 6 by means of routing (for example, transaction routing).
  • the security information interaction request processing module 6 when the received security information interaction request indicates that the type of the security information interaction is "online mode", the security information interaction request processing module 6 constructing a security information interaction message in a predetermined format based on the security information interaction request, and then transmitting the security information interaction message to the data processing server for subsequent processing in an encrypted manner, and The processing result transmitted back by the data processing server is transmitted to the security information interactive terminal 1 in the form of an HTML page.
  • the security information interaction request processing The module 6 stores the security information interaction data (for example, the transaction information, which may include the transaction type, the transaction time, the transaction amount, and the like) included in the security information interaction request in the storage module 8, and the processing result is The form of the HTML page is transmitted back to the security information interactive terminal 1.
  • the security information interaction data for example, the transaction information, which may include the transaction type, the transaction time, the transaction amount, and the like
  • the security information interaction request processing module 6 periodically stores unprocessed security information interaction data stored in the storage module 8 (which is The "offline mode" security information interaction is associated) transferred to the data processing server in batches for subsequent processing.
  • the security information is delivered
  • the mutual terminal 1 communicates with the security information interaction management server 2 by using a secure channel, and performs data transmission between each other in an HTML hypertext manner (ie, the security information interaction terminal 1 and the security
  • the sexual information interaction management server 2 uses the HTTP protocol to transmit data).
  • the main control module 5 is further configured to uniformly manage the security information interaction terminal 1 (exemplarily, the security information disclosed by the present invention
  • the interactive system includes a plurality of security information interaction terminals 1).
  • the management includes at least one of the following: terminal operator management, multi-level rights management policy, terminal parameter management (exemplaryly, the terminal parameters may include a terminal number, a merchant number, a terminal minimum, etc.).
  • the present invention discloses a security information interaction terminal 1 for acquiring and displaying an application owner from a security information interaction management server based on a security information interaction instruction from a user.
  • An interface and a security information interaction interface and a security information interaction request based on the security information input by the user through the security information interaction interface, wherein the security information interaction request includes the security information interaction terminal 1 An identifier), and transmitting the security information interaction request to the security information interaction management server.
  • the security information interactive terminal 1 disclosed in the present invention is a browser in the B/S mode (exemplarily, the browser is located in a mobile terminal, or a personal computer, or a POS machine, and may be exemplarily But not limited to running on Window CE, or Andro id, or Linux operating system platform).
  • the security information interactive terminal 1 disclosed by the present invention is further configured to display the processing result from the security information interaction management server 2.
  • the security information interactive terminal 1 disclosed by the present invention further includes a main controller 3 and a user interface 4.
  • the user interface 4 is configured to receive a security information interaction instruction from a user, and transmit the security information interaction instruction to the main controller 3, and display the application main interface and the security information interaction interface.
  • Receiving the security information input by the user exemplarily, the security information may include a transaction type, a consumption amount, track information or smart card information, etc.
  • the user interface 4 is also used to display the processing result from the security information interaction management server 2.
  • the main controller 3 is configured to acquire the application main interface and the security information interaction interface from the security information interaction management server 2 to pass the user interface 4 based on the received security information interaction instruction. Displaying, and constructing the security information interaction request based on the received security information, and transmitting the security information interaction request Go to the security information interaction management server 2.
  • the main controller 3 acquires the application main interface and the security information from the security information interaction management server 2 by requesting a URL.
  • the interaction interface wherein the application main interface and the security information interaction interface are in the form of an HTML page.
  • the security information interaction type information is input by the user through the application main interface displayed by the user interface 4 (exemplarily, in the financial field, After the security information interaction type may be "balance inquiry”, “consumption”, “storage”, etc., the main controller 3 obtains the security information from the manner of requesting the URL based on the security information interaction type information.
  • the interaction management server 2 acquires the security information interaction interface, where the security information interaction interface includes security information interaction processing logic and data required by the processing logic (exemplarily, the method is provided in the manner of JavaScr ipt Security information interaction processing logic).
  • the main controller 3 processes the security information interaction interface displayed by the user through the user interface 4 according to the security information interaction processing logic. Entering the security information (for example, packaging the data) to construct the security information interaction request, and transmitting the security information interaction request to the security information interaction management server 2 in an HTTP message manner,
  • the security information interaction request includes an indication of a type of security information interaction (ie, "online mode” or "offline mode").
  • the security information interaction terminal 1 disclosed by the present invention performs communication with the security information interaction management server 2 in a secure channel manner, and performs data transmission between each other in an HTML hypertext manner (ie, The security information interaction terminal 1 and the security information interaction management server 2 use the HTTP protocol to transmit data.
  • the present invention discloses a security information interaction management server 2 for providing an application main interface and a security information interaction interface for the security information interaction terminal 1 , and The received security information interaction request from the security information interaction terminal 1 is parsed and processed to complete the security information interaction process, and the processing result is transmitted back to the security information interaction terminal 1.
  • the security information interaction management server 2 disclosed in the present invention is a server in the B/S mode.
  • the security information interaction management server 2 disclosed by the present invention further includes a main control module 5, a security information interaction request processing module 6, an interface generation module 7, a storage module 8, and a communication module 9.
  • the main control module 5 is configured to receive an application main interface URL request and a security information interaction interface URL request from the security information interaction terminal 1, and use the application main interface URL request and the security information interaction interface.
  • the URL request is transmitted to the interface generation module 7, and the security information interaction request from the security information interaction terminal 1 is received and parsed, and the parsed security information interaction request is transmitted to the security information interaction request processing module. 6.
  • the interface generating module 7 is configured to generate an application main interface based on the received application main interface URL request and transmit the application main interface back to the security information interaction terminal 1, and based on the received security
  • the information interaction interface URL request generates a security information interaction interface (preferably, the security information interaction interface includes security information interaction processing logic and data required by the processing logic) and transmits the security information interaction interface back to the location
  • the security information interaction terminal 1 wherein the security information interaction interface URL request includes the security information interaction type information.
  • the security information interaction request processing module 6 is configured to process the received parsed security information interaction request and pass the data processing server (exemplarily, the data processing server may be a financial receipt in the financial field)
  • the data interaction of the single platform completes the security information interaction process, and transmits the processing result back to the security information interaction terminal 1 (exemplarily, the processing result is transmitted back to the security information interaction in the form of an HTML page
  • the security information interaction request processing module 6 includes the security information interaction request
  • Security information interaction data (e.g., transaction information, which may include transaction type, transaction time, transaction amount, etc.) is stored in storage module 8.
  • the storage module 8 is configured to store at least the security information interaction data.
  • the communication module 9 is configured to perform data communication between the security information interaction management server 2 and the security information interaction terminal 1 and the data processing server.
  • the main control module 5 is further configured to perform the legality of the security information interaction terminal 1 before parsing the security information interaction request. Authentication, and the parsed security information interaction request is transmitted to the security information interaction request processing module 6 by means of routing (for example, transaction routing).
  • the security information interaction request processing module 6 constructs the security information interaction message in a predetermined format based on the security information interaction request, and then transmits the security information interaction message to the data processing server in an encrypted manner. Subsequent processing, and processing results transmitted back to the data processing server, are transmitted to the security information interactive terminal 1 in the form of an HTML page.
  • the security information interaction management server 2 when the received security information interaction request indicates that the type of the security information interaction is "offline mode", the security information interaction
  • the request processing module 6 stores the security information interaction data (eg, transaction information, which may include transaction type, transaction time, transaction amount, etc.) included in the security information interaction request in the storage module 8 and processes The result is transmitted back to the security information interactive terminal 1 in the form of an HTML page.
  • security information interaction data eg, transaction information, which may include transaction type, transaction time, transaction amount, etc.
  • the security information interaction request processing module 6 periodically stores unprocessed security information interaction data stored in the storage module 8 ( It is associated with the "offline mode" security information interaction) and is delivered to the data processing server in batches for subsequent processing.
  • the security information interaction management server 2 and the security information interaction terminal 1 disclosed in the present invention communicate with each other in a secure channel manner, and perform data transmission between each other in an HTML hypertext manner (ie, The data is transmitted between the security information interaction terminal 1 and the security information interaction management server 2 using the HTTP protocol.
  • the main control module 5 is further configured to uniformly manage the security information interaction terminal 1 (exemplarily, the security disclosed by the present invention
  • the sex information interaction management server 2 manages a plurality of security information interaction terminals 1).
  • the management includes at least one of the following: terminal operator management, multi-level rights management policy, terminal parameter management (exemplarily, the terminal parameters may include a terminal number, a merchant number, a terminal minimum, etc.).
  • the security information interaction method disclosed by the present invention includes the following steps: (A1) The security information interaction terminal is based on the security information interaction instruction from the user from the security information interaction management server (exemplarily, The security information interaction management server may be a P0S terminal background system in the financial field) acquiring and displaying an application main interface; (A2) inputting security information through the application main interface by the user Mutual type information (exemplarily, in the financial field, after the security information interaction type may be "balance inquiry", "consumption", “storage”, etc.), the security information interaction terminal is based on the security information
  • the interaction type information obtains and displays a security information interaction interface from the security information interaction management server by requesting a URL, where the security information interaction interface includes security information interaction processing logic and data required by the processing logic.
  • the security information interaction processing logic is provided in the manner of JavaScr ipt); (A3) constructing a security information interaction request based on security information input by the user through the security information interaction interface (wherein The security information interaction request includes the identifier of the security information interaction terminal 1), and sends the security information interaction request to the security information interaction management server; (A4) the security information interaction management server Parsing and processing the received security information interaction request to complete security information Mutual procedure, and the results back to said security information interaction terminal.
  • the security information interaction terminal is a browser in a B/S mode (exemplarily, the browser is located at a mobile terminal, or a personal computer, or In a POS machine, and can be exemplarily, but not limited to, running on a Window CE, or Android, or Linux operating system platform).
  • the security information interaction management server is a server in the B/S mode.
  • the step (A4) further includes: the security information interaction terminal displaying the processing result from the security information interaction management server.
  • the security information interaction terminal acquires the application main interface and the security information interaction from the security information interaction management server by requesting a URL.
  • the interface, where the application main interface and the security information interaction interface are in the form of an HTML page.
  • the step (A3) further includes: the security information interaction terminal processing the user to interact through the security information according to the security information interaction processing logic Entering the security information (for example, the data is packaged) by the interface to construct the security information interaction request, and transmitting the security information interaction request to the security information interaction management server by using an HTTP message.
  • the security information interaction request packet Contains an indication of the type of security information interaction (ie "online mode” or "offline mode").
  • the step (A1) further includes: the security information interaction management server requests a preference based on the received application home interface URL, in the present invention
  • the step (A2) further includes: the security information interaction management server generates a security information interaction interface based on the received security information interaction interface URL request (preferably, the security The information interaction interface includes security information interaction processing logic and data required by the processing logic, and transmits the security information interaction interface back to the security information interaction terminal, wherein the security information interaction interface URL request The security information interaction type information is included.
  • the step (A4) further includes: the security information interaction management server processes and parses the received security information interaction request, and
  • the data processing server exemplarily, the data processing server may be a financial acquiring platform in the financial field
  • performs a data interaction completion security information interaction process and transmits the processing result back to the security information interaction terminal (exemplarily The processing result is transmitted back to the security information interaction terminal in the form of an HTML page.
  • the step (A4) further includes: the security information interaction management server interacting with the security information before parsing the security information interaction request The legitimacy of the terminal is authenticated.
  • the step (A4) further includes: when the received security information interaction request indicates that the type of the security information interaction is "online mode", The security information interaction management server constructs a security information interaction message in a predetermined format based on the security information interaction request, and then transmits the security information interaction message to the data processing server in an encrypted manner. Subsequent processing, and processing results transmitted back to the data processing server, are transmitted to the security information interactive terminal in the form of an HTML page.
  • the step (A4) further includes: when the received security information interaction request indicates that the type of the security information interaction is "offline mode"
  • the security information interaction management server stores security information interaction data (eg, transaction information, which may include transaction type, transaction) included in the security information interaction request. Time, transaction amount, etc.), and the processing result is transmitted back to the security information interactive terminal in the form of an HTML page.
  • the security information interaction management server periodically stores the stored unprocessed security information interaction data (which is related to the "offline mode" security information.
  • the interaction is associated) transferred to the data processing server in batches for subsequent processing.
  • the security information is exchanged and the data transmission between each other is performed in the manner of HTML hypertext (ie, the security information interaction terminal and the The security information exchange management server uses the HTTP protocol to transfer data between).
  • the security information interaction management server uniformly manages the security information interaction terminal (exemplarily, the security information interaction method disclosed by the present invention Contains multiple security information interaction terminals).
  • the management includes at least one of the following: terminal operator management, multi-level rights management policy, terminal parameter management (exemplaryly, the terminal parameters may include a terminal number, a merchant number, a terminal minimum amount, etc.).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer And Data Communications (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Description

安全性信息交互系统、 设备及方法 技术领域
本发明涉及信息交互系统、 设备及方法, 更具体地, 涉及安全性信息交互 系统、 设备及方法。 背景技术
目前, 随着网络应用的日益广泛以及不同领域的业务种类的日益丰富,通 过安全性信息交互终端(例如 P0S机)并经由网络进行安全性信息(即对安全 性要求较高的信息, 例如交易金额和 /或密码) 的交互变得越来越重要。
现有的安全性信息交互系统及方法通常采用常规的安全性信息交互终端
(例如常规的 P0S机)。 然而, 常规的安全性信息交互终端存在如下问题: (1 ) 更新和安装应用困难, 从而导致维护成本较高; (2 )针对新的应用, 需要兼容 不同平台的安全性信息交互终端, 从而导致设计和调试成本较高。
因此,存在如下需求: 提供易于使用和维护并且成本较低的安全性信息交 互系统、 设备及方法。 发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了易于使用和维护 并且成本较低的安全性信息交互系统、 设备及方法。
本发明的目的是通过以下技术方案实现的:
一种安全性信息交互系统, 所述安全性信息交互系统包括:
安全性信息交互终端,所述安全性信息交互终端用于基于来自用户的安全 性信息交互指令从安全性信息交互管理服务器获取并显示应用主界面和安全 性信息交互界面,以及基于用户通过所述安全性信息交互界面输入的安全性信 息构造安全性信息交互请求,并将所述安全性信息交互请求发送到所述安全性 信息交互管理服务器;
安全性信息交互管理服务器,所述安全性信息交互管理服务器用于为所述 安全性信息交互终端提供所述应用主界面和所述安全性信息交互界面,以及解 析和处理接收到的所述安全性信息交互请求以完成安全性信息交互过程,并将 处理结果传送回所述安全性信息交互终端。
在上面所公开的方案中,优选地, 所述安全性信息交互终端是 B/ S模式中 的浏览器。
在上面所公开的方案中,优选地, 所述安全性信息交互终端进一步用于显 示来自所述安全性信息交互管理服务器的所述处理结果。
在上面所公开的方案中, 优选地, 所述安全性信息交互终端进一步包括: 用户接口,所述用户接口用于接收来自用户的安全性信息交互指令并将所 述安全性信息交互指令传送到主控制器,以及显示所述应用主界面和所述安全 性信息交互界面并接收用户输入的所述安全性信息,以及将所述安全性信息传 送到主控制器,所述用户接口还用于显示来自所述安全性信息交互管理服务器 的所述处理结果;
主控制器,所述主控制器用于基于接收到的所述安全性信息交互指令从所 述安全性信息交互管理服务器获取所述应用主界面和所述安全性信息交互界 面以通过所述用户接口显示,以及基于接收到的所述安全性信息构造所述安全 性信息交互请求,并将所述安全性信息交互请求发送到所述安全性信息交互管 理服务器。
在上面所公开的方案中,优选地, 所述主控制器通过请求 URL的方式从所 述安全性信息交互管理服务器获取所述应用主界面和所述安全性信息交互界 面, 其中, 所述应用主界面和所述安全性信息交互界面是 HTML页面的形式。
在上面所公开的方案中,优选地,在用户通过由所述用户接口显示的所述 应用主界面输入安全性信息交互类型信息后,所述主控制器基于所述安全性信 息交互类型信息通过请求 URL 的方式从所述安全性信息交互管理服务器获取 所述安全性信息交互界面, 其中, 所述安全性信息交互界面包含安全性信息交 互处理逻辑和该处理逻辑所需的数据。
在上面所公开的方案中,优选地, 所述主控制器按照所述安全性信息交互 处理逻辑处理用户通过由所述用户接口显示的所述安全性信息交互界面输入 的所述安全性信息以构造所述安全性信息交互请求,并将所述安全性信息交互 请求以 HTTP报文的方式传送到所述安全性信息交互管理服务器, 其中, 所述 安全性信息交互请求包含对安全性信息交互的类型的指示。
在上面所公开的方案中,优选地, 所述安全性信息交互管理服务器进一步 包括:
主控制模块,所述主控制模块用于接收来自所述安全性信息交互终端的应 用主界面 URL请求和安全性信息交互界面 URL请求, 并将所述应用主界面 URL 请求和安全性信息交互界面 URL请求传送到界面生成模块,以及接收并解析来 自所述安全性信息交互终端的所述安全性信息交互请求,并将解析后的安全性 信息交互请求传送到安全性信息交互请求处理模块;
界面生成模块, 所述界面生成模块用于基于接收到的所述应用主界面 URL 及基于接收到的所述安全性信息交互界面 URL请求生成安全性信息交互界面 并将所述安全性信息交互界面传送回所述安全性信息交互终端, 其中, 所述安 全性信息交互界面 URL请求包含所述安全性信息交互类型信息;
安全性信息交互请求处理模块,所述安全性信息交互请求处理模块用于处 理接收到的所述解析后的安全性信息交互请求,并通过与数据处理服务器的数 据交互完成安全性信息交互过程,并将处理结果传送回所述安全性信息交互终 端, 其中, 当所述安全性信息交互请求指示安全性信息交互的类型为 "脱机方 式"时, 所述安全性信息交互请求处理模块将所述安全性信息交互请求所包含 的安全性信息交互数据存储在存储模块中;
存储模块, 所述存储模块用于至少存储所述安全性信息交互数据; 通信模块,所述通信模块用于执行所述安全性信息交互管理服务器与所述 安全性信息交互终端和所述数据处理服务器之间的数据通信。
在上面所公开的方案中,优选地, 所述主控制模块进一步用于在解析所述 安全性信息交互请求之前对所述安全性信息交互终端的合法性进行认证,并且 将解析后的安全性信息交互请求通过路由的方式传送到所述安全性信息交互 请求处理模块。
在上面所公开的方案中,优选地, 当接收到的所述安全性信息交互请求指 示安全性信息交互的类型为 "联机方式" 时, 所述安全性信息交互请求处理模 块基于所述安全性信息交互请求以预定格式构造安全性信息交互报文,随后以 加密的方式将所述安全性信息交互报文传送到所述数据处理服务器以进行后 续处理, 以及将所述数据处理服务器传送回的处理结果以 HTML页面的形式传 送到所述安全性信息交互终端。
在上面所公开的方案中,优选地, 当接收到的所述安全性信息交互请求指 示安全性信息交互的类型为 "脱机方式" 时, 所述安全性信息交互请求处理模 块将所述安全性信息交互请求所包含的安全性信息交互数据存储在所述存储 模块中, 并将处理结果以 HTML页面的形式传送回所述安全性信息交互终端。
在上面所公开的方案中,优选地, 所述安全性信息交互请求处理模块周期 性地将存储在所述存储模块中的未处理的安全性信息交互数据以批量地方式 传送到所述数据处理服务器以进行后续的处理。
在上面所公开的方案中,优选地,在所述安全性信息交互终端与所述安全 的方式进行相互之间的数据传输。
在上面所公开的方案中,优选地, 所述主控制模块进一步用于统一管理所 述安全性信息交互终端。
本发明的目的也可以通过以下技术方案实现:
一种安全性信息交互终端,所述安全性信息交互终端用于基于来自用户的 安全性信息交互指令从安全性信息交互管理服务器获取并显示应用主界面和 安全性信息交互界面,以及基于用户通过所述安全性信息交互界面输入的安全 性信息构造安全性信息交互请求,并将所述安全性信息交互请求发送到所述安 全性信息交互管理服务器。
本发明的目的也可以通过以下技术方案实现:
一种安全性信息交互管理服务器,所述安全性信息交互管理服务器用于为 安全性信息交互终端提供应用主界面和安全性信息交互界面,以及解析和处理 接收到的来自所述安全性信息交互终端的安全性信息交互请求以完成安全性 信息交互过程, 并将处理结果传送回所述安全性信息交互终端。
本发明的目的也可以通过以下技术方案实现:
一种安全性信息交互方法, 所述安全性信息交互方法包括下列步骤:
( A1 )安全性信息交互终端基于来自用户的安全性信息交互指令从安全性 信息交互管理服务器获取并显示应用主界面;
( A2 )在用户通过所述应用主界面输入安全性信息交互类型信息后, 所述 安全性信息交互终端基于所述安全性信息交互类型信息通过请求 URL 的方式 从所述安全性信息交互管理服务器获取并显示安全性信息交互界面, 其中, 所 述安全性信息交互界面包含安全性信息交互处理逻辑和该处理逻辑所需的数 据;
( A3 )基于用户通过所述安全性信息交互界面输入的安全性信息构造安全 性信息交互请求,并将所述安全性信息交互请求发送到所述安全性信息交互管 理服务器;
( A4 )所述安全性信息交互管理服务器解析和处理接收到的所述安全性信 息交互请求以完成安全性信息交互过程,并将处理结果传送回所述安全性信息 交互终端。
本发明所公开的安全性信息交互系统、设备及方法具有如下优点: 由于采 用了 B/S模式,故将在常规的安全性信息交互终端中执行的处理逻辑转移到安 全性信息交互管理服务器中执行, 故易于使用和维护并且成本较低。 附图说明
结合附图, 本发明的技术特征以及优点将会被本领域技术人员更好地理 解, 其中:
图 1是根据本发明的实施例的安全性信息交互系统的架构图;
图 2是根据本发明的实施例的安全性信息交互方法的流程图。 具体实施方式
图 1是根据本发明的实施例的安全性信息交互系统的架构图。 如图 1所示, 本发明所公开的安全性信息交互系统包括安全性信息交互终端 1和安全性信息 交互管理服务器 2 (示例性地, 所述安全性信息交互管理服务器 2可以是金融领 域中的 P0S终端后台系统) 。 其中, 所述安全性信息交互终端 1用于基于来自 用户的安全性信息交互指令从安全性信息交互管理服务器 2获取并显示应用主 界面和安全性信息交互界面,以及基于用户通过所述安全性信息交互界面输入 的安全性信息构造安全性信息交互请求(其中, 所述安全性信息交互请求包括 所述安全性信息交互终端 1的标识符) , 并将所述安全性信息交互请求发送到 所述安全性信息交互管理服务器 2。所述安全性信息交互管理服务器 2用于为所 述安全性信息交互终端 1提供所述应用主界面和所述安全性信息交互界面, 以 及解析和处理接收到的所述安全性信息交互请求以完成安全性信息交互过程, 并将处理结果传送回所述安全性信息交互终端 1。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 终端 1是 B/S模式中的浏览器(示例性地, 所述浏览器位于移动终端、 或个人 计算机、 或 P0S 机中, 并且可以示例性地但不限于运行在 Window CE、 或 Andro id , 或 L inux操作系统平台上) 。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 管理服务器 2是 B/S模式中的服务器。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 终端 1进一步用于显示来自所述安全性信息交互管理服务器 2的所述处理结果。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 终端 1进一步包括主控制器 3和用户接口 4。其中, 所述用户接口 4用于接收来自 用户的安全性信息交互指令并将所述安全性信息交互指令传送到主控制器 3 , 以及显示所述应用主界面和所述安全性信息交互界面并接收用户输入的所述 安全性信息(示例性地, 所述安全性信息可以包括交易类型、 消费金额、 磁道 信息或智能卡信息等) , 以及将所述安全性信息传送到主控制器 3 , 所述用户 接口 4还用于显示来自所述安全性信息交互管理服务器 2的所述处理结果。所述 主控制器 3用于基于接收到的所述安全性信息交互指令从所述安全性信息交互 管理服务器 2获取所述应用主界面和所述安全性信息交互界面以通过所述用户 接口 4显示,以及基于接收到的所述安全性信息构造所述安全性信息交互请求, 并将所述安全性信息交互请求发送到所述安全性信息交互管理服务器 2。
优选地, 在本发明所公开的安全性信息交互系统中, 所述主控制器 3通过 请求 URL的方式从所述安全性信息交互管理服务器 2获取所述应用主界面和所 述安全性信息交互界面, 其中, 所述应用主界面和所述安全性信息交互界面是 HTML页面的形式。 优选地,在本发明所公开的安全性信息交互系统中,在用户通过由所述用 户接口 4显示的所述应用主界面输入安全性信息交互类型信息 (示例性地, 在 金融领域中, 安全性信息交互类型可以是 "余额查询" 、 "消费" 、 "圏存" 等)后, 所述主控制器 3基于所述安全性信息交互类型信息通过请求 URL的方 式从所述安全性信息交互管理服务器 2获取所述安全性信息交互界面, 其中, 所述安全性信息交互界面包含安全性信息交互处理逻辑和该处理逻辑所需的 数据(示例性地, 以 JavaScr ipt的方式提供所述安全性信息交互处理逻辑)。
优选地, 在本发明所公开的安全性信息交互系统中, 所述主控制器 3按照 所述安全性信息交互处理逻辑处理用户通过由所述用户接口 4显示的所述安全 性信息交互界面输入的所述安全性信息(例如将数据打包)以构造所述安全性 信息交互请求, 并将所述安全性信息交互请求以 HTTP报文的方式传送到所述 安全性信息交互管理服务器 2 , 其中, 所述安全性信息交互请求包含对安全性 信息交互的类型的指示 (即 "联机方式" 或 "脱机方式" ) 。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 管理服务器 2进一步包括主控制模块 5、 安全性信息交互请求处理模块 6、 界面 生成模块 7、 存储模块 8和通信模块 9。 其中, 所述主控制模块 5用于接收来自所 述安全性信息交互终端 1的应用主界面 URL请求和安全性信息交互界面 URL请 求,并将所述应用主界面 URL请求和安全性信息交互界面 URL请求传送到界面 生成模块 7 ,以及接收并解析来自所述安全性信息交互终端 1的所述安全性信息 交互请求,并将解析后的安全性信息交互请求传送到安全性信息交互请求处理 模块 6。所述界面生成模块 7用于基于接收到的所述应用主界面 URL请求生成应 收到的所述安全性信息交互界面 URL请求生成安全性信息交互界面 (优选地, 所述安全性信息交互界面包含安全性信息交互处理逻辑和该处理逻辑所需的 数据 )并将所述安全性信息交互界面传送回所述安全性信息交互终端 1 , 其中, 所述安全性信息交互界面 URL请求包含所述安全性信息交互类型信息。所述安 全性信息交互请求处理模块 6用于处理接收到的所述解析后的安全性信息交互 请求, 并通过与数据处理服务器(示例性地, 该数据处理服务器可以是金融领 域中的金融收单平台)的数据交互完成安全性信息交互过程, 并将处理结果传 送回所述安全性信息交互终端 1 (示例性地, 所述处理结果以 HTML页面的形式 被传送回所述安全性信息交互终端 1 ) , 其中, 当所述安全性信息交互请求指 示安全性信息交互的类型为 "脱机方式" 时, 所述安全性信息交互请求处理模 块 6将所述安全性信息交互请求所包含的安全性信息交互数据 (例如交易信息, 其可以包括交易类型、 交易时间、 交易金额等)存储在存储模块 8中。 所述存 储模块 8用于至少存储所述安全性信息交互数据。所述通信模块 9用于执行所述 安全性信息交互管理服务器 2与所述安全性信息交互终端 1和所述数据处理服 务器之间的数据通信。
优选地, 在本发明所公开的安全性信息交互系统中, 主控制模块 5进一步 用于在解析所述安全性信息交互请求之前对所述安全性信息交互终端 1的合法 性进行认证, 并且将解析后的安全性信息交互请求通过路由的方式(例如交易 路由 )传送到所述安全性信息交互请求处理模块 6。
优选地,在本发明所公开的安全性信息交互系统中, 当接收到的所述安全 性信息交互请求指示安全性信息交互的类型为 "联机方式" 时, 所述安全性信 息交互请求处理模块 6基于所述安全性信息交互请求以预定格式构造安全性信 息交互报文,随后以加密的方式将所述安全性信息交互报文传送到所述数据处 理服务器以进行后续处理, 以及将所述数据处理服务器传送回的处理结果以 HTML页面的形式传送到所述安全性信息交互终端 1。
优选地,在本发明所公开的安全性信息交互系统中, 当接收到的所述安全 性信息交互请求指示安全性信息交互的类型为 "脱机方式" 时, 所述安全性信 息交互请求处理模块 6将所述安全性信息交互请求所包含的安全性信息交互数 据(例如交易信息, 其可以包括交易类型、 交易时间、 交易金额等)存储在所 述存储模块 8中,并将处理结果以 HTML页面的形式传送回所述安全性信息交互 终端 1。
优选地,在本发明所公开的安全性信息交互系统中, 所述安全性信息交互 请求处理模块 6周期性地将存储在所述存储模块 8中的未处理的安全性信息交 互数据(其与 "脱机方式" 的安全性信息交互相关联)以批量地方式传送到所 述数据处理服务器以进行后续的处理。
优选地,在本发明所公开的安全性信息交互系统中,在所述安全性信息交 互终端 1与所述安全性信息交互管理服务器 2之间采用安全通道进行通信,并且 以 HTML超文本的方式进行相互之间的数据传输(即在所述安全性信息交互终 端 1与所述安全性信息交互管理服务器 2之间采用 HTTP协议传输数据) 。
优选地, 在本发明所公开的安全性信息交互系统中, 所述主控制模块 5进 一步用于统一管理所述所述安全性信息交互终端 1 (示例性地, 本发明所公开 的安全性信息交互系统包含多个安全性信息交互终端 1 ) 。 示例性地, 所述管 理包括下列中的至少一项: 终端操作员管理、 多级权限管理策略、 终端参数管 理(示例性地, 终端参数可以包括终端编号、 商户编号、 终端最低限额等) 。
如图 1所示, 本发明公开了一种安全性信息交互终端 1 , 所述安全性信息交 互终端 1用于基于来自用户的安全性信息交互指令从安全性信息交互管理服务 器获取并显示应用主界面和安全性信息交互界面,以及基于用户通过所述安全 性信息交互界面输入的安全性信息构造安全性信息交互请求(其中, 所述安全 性信息交互请求包括所述安全性信息交互终端 1的标识符) , 并将所述安全性 信息交互请求发送到所述安全性信息交互管理服务器。
优选地,本发明所公开的安全性信息交互终端 1是 B/S模式中的浏览器(示 例性地, 所述浏览器位于移动终端、 或个人计算机、 或 P0S机中, 并且可以示 例性地但不限于运行在 Window CE、 或 Andro i d , 或 L inux操作系统平台上)。
优选地, 本发明所公开的安全性信息交互终端 1进一步用于显示来自所述 安全性信息交互管理服务器 2的处理结果。
优选地,本发明所公开的安全性信息交互终端 1进一步包括主控制器 3和用 户接口 4。其中, 所述用户接口 4用于接收来自用户的安全性信息交互指令并将 所述安全性信息交互指令传送到主控制器 3 , 以及显示所述应用主界面和所述 安全性信息交互界面并接收用户输入的所述安全性信息(示例性地, 所述安全 性信息可以包括交易类型、 消费金额、 磁道信息或智能卡信息等), 以及将所 述安全性信息传送到主控制器 3 ,所述用户接口 4还用于显示来自所述安全性信 息交互管理服务器 2的所述处理结果。所述主控制器 3用于基于接收到的所述安 全性信息交互指令从所述安全性信息交互管理服务器 2获取所述应用主界面和 所述安全性信息交互界面以通过所述用户接口 4显示, 以及基于接收到的所述 安全性信息构造所述安全性信息交互请求,并将所述安全性信息交互请求发送 到所述安全性信息交互管理服务器 2。
优选地,在本发明所公开的安全性信息交互终端 1中, 所述主控制器 3通过 请求 URL的方式从所述安全性信息交互管理服务器 2获取所述应用主界面和所 述安全性信息交互界面, 其中, 所述应用主界面和所述安全性信息交互界面是 HTML页面的形式。
优选地, 在本发明所公开的安全性信息交互终端 1中, 在用户通过由所述 用户接口 4显示的所述应用主界面输入安全性信息交互类型信息 (示例性地, 在金融领域中, 安全性信息交互类型可以是 "余额查询" 、 "消费" 、 "圏存" 等)后, 所述主控制器 3基于所述安全性信息交互类型信息通过请求 URL的方 式从所述安全性信息交互管理服务器 2获取所述安全性信息交互界面, 其中, 所述安全性信息交互界面包含安全性信息交互处理逻辑和该处理逻辑所需的 数据(示例性地, 以 JavaScr ipt的方式提供所述安全性信息交互处理逻辑)。
优选地,在本发明所公开的安全性信息交互终端 1中, 所述主控制器 3按照 所述安全性信息交互处理逻辑处理用户通过由所述用户接口 4显示的所述安全 性信息交互界面输入的所述安全性信息(例如将数据打包)以构造所述安全性 信息交互请求, 并将所述安全性信息交互请求以 HTTP报文的方式传送到所述 安全性信息交互管理服务器 2 , 其中, 所述安全性信息交互请求包含对安全性 信息交互的类型的指示 (即 "联机方式" 或 "脱机方式" ) 。
优选地, 本发明所公开的安全性信息交互终端 1采用安全通道的方式进行 与所述安全性信息交互管理服务器 2的通信,并且以 HTML超文本的方式进行相 互之间的数据传输(即在所述安全性信息交互终端 1与所述安全性信息交互管 理服务器 2之间采用 HTTP协议传输数据) 。
如图 1所示, 本发明公开了一种安全性信息交互管理服务器 2 , 所述安全性 信息交互管理服务器 2用于为安全性信息交互终端 1提供应用主界面和安全性 信息交互界面, 以及解析和处理接收到的来自所述安全性信息交互终端 1的安 全性信息交互请求以完成安全性信息交互过程,并将处理结果传送回所述安全 性信息交互终端 1。
优选地, 本发明所公开的安全性信息交互管理服务器 2是 B/S模式中的服 务器。 优选地, 本发明所公开的安全性信息交互管理服务器 2进一步包括主控制 模块 5、 安全性信息交互请求处理模块 6、 界面生成模块 7、 存储模块 8和通信模 块 9。 其中, 所述主控制模块 5用于接收来自所述安全性信息交互终端 1的应用 主界面 URL请求和安全性信息交互界面 URL请求, 并将所述应用主界面 URL 请求和安全性信息交互界面 URL请求传送到界面生成模块 7 , 以及接收并解析 来自所述安全性信息交互终端 1的所述安全性信息交互请求, 并将解析后的安 全性信息交互请求传送到安全性信息交互请求处理模块 6。所述界面生成模块 7 用于基于接收到的所述应用主界面 URL 请求生成应用主界面并将所述应用主 界面传送回所述安全性信息交互终端 1 , 以及基于接收到的所述安全性信息交 互界面 URL请求生成安全性信息交互界面(优选地, 所述安全性信息交互界面 包含安全性信息交互处理逻辑和该处理逻辑所需的数据)并将所述安全性信息 交互界面传送回所述安全性信息交互终端 1 , 其中, 所述安全性信息交互界面 URL请求包含所述安全性信息交互类型信息。 所述安全性信息交互请求处理模 块 6用于处理接收到的所述解析后的安全性信息交互请求, 并通过与数据处理 服务器(示例性地, 该数据处理服务器可以是金融领域中的金融收单平台 )的 数据交互完成安全性信息交互过程,并将处理结果传送回所述安全性信息交互 终端 1 (示例性地, 所述处理结果以 HTML页面的形式被传送回所述安全性信息 交互终端 1 ) , 其中, 当所述安全性信息交互请求指示安全性信息交互的类型 为 "脱机方式" 时, 所述安全性信息交互请求处理模块 6将所述安全性信息交 互请求所包含的安全性信息交互数据(例如交易信息, 其可以包括交易类型、 交易时间、 交易金额等 )存储在存储模块 8中。 所述存储模块 8用于至少存储所 述安全性信息交互数据。 所述通信模块 9用于执行所述安全性信息交互管理服 务器 2与所述安全性信息交互终端 1和所述数据处理服务器之间的数据通信。
优选地, 在本发明所公开的安全性信息交互管理服务器 2中, 所述主控制 模块 5进一步用于在解析所述安全性信息交互请求之前对所述安全性信息交互 终端 1的合法性进行认证, 并且将解析后的安全性信息交互请求通过路由的方 式(例如交易路由)传送到所述安全性信息交互请求处理模块 6。
优选地, 在本发明所公开的安全性信息交互管理服务器 2中, 当接收到的 所述安全性信息交互请求指示安全性信息交互的类型为 "联机方式" 时, 所述 安全性信息交互请求处理模块 6基于所述安全性信息交互请求以预定格式构造 安全性信息交互报文,随后以加密的方式将所述安全性信息交互报文传送到所 述数据处理服务器以进行后续处理,以及将所述数据处理服务器传送回的处理 结果以 HTML页面的形式传送到所述安全性信息交互终端 1。
优选地, 在本发明所公开的安全性信息交互管理服务器 2中, 当接收到的 所述安全性信息交互请求指示安全性信息交互的类型为 "脱机方式" 时, 所述 安全性信息交互请求处理模块 6将所述安全性信息交互请求所包含的安全性信 息交互数据 (例如交易信息, 其可以包括交易类型、 交易时间、 交易金额等) 存储在所述存储模块 8中,并将处理结果以 HTML页面的形式传送回所述安全性 信息交互终端 1。
优选地, 在本发明所公开的安全性信息交互管理服务器 2中, 所述安全性 信息交互请求处理模块 6周期性地将存储在所述存储模块 8中的未处理的安全 性信息交互数据(其与 "脱机方式" 的安全性信息交互相关联)以批量地方式 传送到所述数据处理服务器以进行后续的处理。
优选地, 本发明所公开的安全性信息交互管理服务器 2与所述安全性信息 交互终端 1之间以安全通道的方式进行通信,并且以 HTML超文本的方式进行相 互之间的数据传输(即在所述安全性信息交互终端 1与所述安全性信息交互管 理服务器 2之间采用 HTTP协议传输数据) 。
优选地, 在本发明所公开的安全性信息交互管理服务器 2中, 所述主控制 模块 5进一步用于统一管理所述所述安全性信息交互终端 1 (示例性地, 本发明 所公开的安全性信息交互管理服务器 2管理多个安全性信息交互终端 1 )。 示例 性地,所述管理包括下列中的至少一项:终端操作员管理、多级权限管理策略、 终端参数管理(示例性地, 终端参数可以包括终端编号、 商户编号、 终端最低 限额等) 。
图 2是根据本发明的实施例的安全性信息交互方法的流程图。 如图 2所示, 本发明所公开的安全性信息交互方法包括下列步骤: ( A1 )安全性信息交互终 端基于来自用户的安全性信息交互指令从安全性信息交互管理服务器(示例性 地, 所述安全性信息交互管理服务器可以是金融领域中的 P0S终端后台系统 ) 获取并显示应用主界面; ( A2 )在用户通过所述应用主界面输入安全性信息交 互类型信息(示例性地, 在金融领域中, 安全性信息交互类型可以是 "余额查 询" 、 "消费" 、 "圏存" 等)后, 所述安全性信息交互终端基于所述安全性 信息交互类型信息通过请求 URL 的方式从所述安全性信息交互管理服务器获 取并显示安全性信息交互界面, 其中, 所述安全性信息交互界面包含安全性信 息交互处理逻辑和该处理逻辑所需的数据(示例性地, 以 JavaScr ipt的方式 提供所述安全性信息交互处理逻辑); ( A3 )基于用户通过所述安全性信息交 互界面输入的安全性信息构造安全性信息交互请求(其中, 所述安全性信息交 互请求包括所述安全性信息交互终端 1的标识符) , 并将所述安全性信息交互 请求发送到所述安全性信息交互管理服务器; ( A4 )所述安全性信息交互管理 服务器解析和处理接收到的所述安全性信息交互请求以完成安全性信息交互 过程, 并将处理结果传送回所述安全性信息交互终端。
优选地,在本发明所公开的安全性信息交互方法中, 所述安全性信息交互 终端是 B/S模式中的浏览器(示例性地, 所述浏览器位于移动终端、 或个人计 算机、或 P0S机中,并且可以示例性地但不限于运行在 Window CE、或 Android, 或 Linux操作系统平台上) 。
优选地,在本发明所公开的安全性信息交互方法中, 所述安全性信息交互 管理服务器是 B/S模式中的服务器。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A4 )进一 步包括:所述安全性信息交互终端显示来自所述安全性信息交互管理服务器的 所述处理结果。
优选地,在本发明所公开的安全性信息交互方法中, 所述安全性信息交互 终端通过请求 URL 的方式从所述安全性信息交互管理服务器获取所述应用主 界面和所述安全性信息交互界面, 其中, 所述应用主界面和所述安全性信息交 互界面是 HTML页面的形式。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A3 )进一 步包括:所述安全性信息交互终端按照所述安全性信息交互处理逻辑处理用户 通过所述安全性信息交互界面输入的所述安全性信息(例如将数据打包 )以构 造所述安全性信息交互请求, 并将所述安全性信息交互请求以 HTTP报文的方 式传送到所述安全性信息交互管理服务器, 其中, 所述安全性信息交互请求包 含对安全性信息交互的类型的指示 (即 "联机方式" 或 "脱机方式" ) 。 优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A1 )进一 步包括:所述安全性信息交互管理服务器基于接收到的应用主界面 URL请求生 优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A2 )进一 步包括: 所述安全性信息交互管理服务器基于接收到的安全性信息交互界面 URL请求生成安全性信息交互界面(优选地, 所述安全性信息交互界面包含安 全性信息交互处理逻辑和该处理逻辑所需的数据)并将所述安全性信息交互界 面传送回所述安全性信息交互终端, 其中, 所述安全性信息交互界面 URL请求 包含所述安全性信息交互类型信息。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A4 )进一 步包括:所述安全性信息交互管理服务器处理并解析接收到的所述安全性信息 交互请求, 并通过与数据处理服务器(示例性地, 该数据处理服务器可以是金 融领域中的金融收单平台)的数据交互完成安全性信息交互过程, 并将处理结 果传送回所述安全性信息交互终端 (示例性地, 所述处理结果以 HTML页面的 形式被传送回所述安全性信息交互终端) 。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A4 )进一 步包括:所述安全性信息交互管理服务器在解析所述安全性信息交互请求之前 对所述安全性信息交互终端的合法性进行认证。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A4 )进一 步包括: 当接收到的所述安全性信息交互请求指示安全性信息交互的类型为 "联机方式" 时, 所述安全性信息交互管理服务器基于所述安全性信息交互请 求以预定格式构造安全性信息交互报文,随后以加密的方式将所述安全性信息 交互报文传送到所述数据处理服务器以进行后续处理,以及将所述数据处理服 务器传送回的处理结果以 HTML页面的形式传送到所述安全性信息交互终端。
优选地, 在本发明所公开的安全性信息交互方法中, 所述步骤(A4 )进一 步包括: 当接收到的所述安全性信息交互请求指示安全性信息交互的类型为 "脱机方式" 时, 所述安全性信息交互管理服务器存储所述安全性信息交互请 求所包含的安全性信息交互数据(例如交易信息, 其可以包括交易类型、 交易 时间、 交易金额等) , 并将处理结果以 HTML页面的形式传送回所述安全性信 息交互终端。
优选地,在本发明所公开的安全性信息交互方法中, 所述安全性信息交互 管理服务器周期性地将存储的未处理的安全性信息交互数据(其与 "脱机方式" 的安全性信息交互相关联 )以批量地方式传送到所述数据处理服务器以进行后 续的处理。
优选地,在本发明所公开的安全性信息交互方法中,在所述安全性信息交 并且以 HTML超文本的方式进行相互之间的数据传输(即在所述安全性信息交 互终端与所述安全性信息交互管理服务器之间采用 HTTP协议传输数据) 。
优选地,在本发明所公开的安全性信息交互方法中, 所述安全性信息交互 管理服务器统一管理所述所述安全性信息交互终端(示例性地, 本发明所公开 的安全性信息交互方法包含多个安全性信息交互终端)。 示例性地, 所述管理 包括下列中的至少一项: 终端操作员管理、 多级权限管理策略、 终端参数管理 (示例性地, 终端参数可以包括终端编号、 商户编号、 终端最低限额等) 。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不 局限于上述的实施方式。 应该认识到: 在不脱离本发明主旨和范围的情况下,

Claims

权利要求
1. 一种安全性信息交互系统, 所述安全性信息交互系统包括: 安全性信息交互终端, 所述安全性信息交互终端用于基于来自用户 的安全性信息交互指令从安全性信息交互管理服务器获取并显示应用主 界面和安全性信息交互界面, 以及基于用户通过所述安全性信息交互界 面输入的安全性信息构造安全性信息交互请求, 并将所述安全性信息交 互请求发送到所述安全性信息交互管理服务器;
安全性信息交互管理服务器, 所述安全性信息交互管理服务器用于 为所述安全性信息交互终端提供所述应用主界面和所述安全性信息交互 界面, 以及解析和处理接收到的所述安全性信息交互请求以完成安全性 信息交互过程, 并将处理结果传送回所述安全性信息交互终端。
2. 根据权利要求 1所述的安全性信息交互系统, 其特征在于, 所述 安全性信息交互终端是 B/S模式中的浏览器。
3. 根据权利要求 2所述的安全性信息交互系统, 其特征在于, 所述 安全性信息交互终端进一步用于显示来自所述安全性信息交互管理服务 器的所述处理结果。
4. 根据权利要求 3所述的安全性信息交互系统, 其特征在于, 所述 安全性信息交互终端进一步包括:
用户接口, 所述用户接口用于接收来自用户的安全性信息交互指令 并将所述安全性信息交互指令传送到主控制器, 以及显示所述应用主界 面和所述安全性信息交互界面并接收用户输入的所述安全性信息, 以及 将所述安全性信息传送到主控制器, 所述用户接口还用于显示来自所述 安全性信息交互管理服务器的所述处理结果;
主控制器, 所述主控制器用于基于接收到的所述安全性信息交互指 令从所述安全性信息交互管理服务器获取所述应用主界面和所述安全性 信息交互界面以通过所述用户接口显示, 以及基于接收到的所述安全性 信息构造所述安全性信息交互请求, 并将所述安全性信息交互请求发送 到所述安全性信息交互管理服务器。
5. 根据权利要求 4所述的安全性信息交互系统, 其特征在于, 所述 主控制器通过请求 URL的方式从所述安全性信息交互管理服务器获取所 述应用主界面和所述安全性信息交互界面, 其中, 所述应用主界面和所 述安全性信息交互界面是 HTML页面的形式。
6. 根据权利要求 5所述的安全性信息交互系统, 其特征在于, 在用 户通过由所述用户接口显示的所述应用主界面输入安全性信息交互类型 信息后, 所述主控制器基于所述安全性信息交互类型信息通过请求 URL 的方式从所述安全性信息交互管理服务器获取所述安全性信息交互界 面, 其中, 所述安全性信息交互界面包含安全性信息交互处理逻辑和该 处理逻辑所需的数据。
7. 根据权利要求 6所述的安全性信息交互系统, 其特征在于, 所述 主控制器按照所述安全性信息交互处理逻辑处理用户通过由所述用户接 口显示的所述安全性信息交互界面输入的所述安全性信息以构造所述安 全性信息交互请求, 并将所述安全性信息交互请求以 HTTP报文的方式 传送到所述安全性信息交互管理服务器, 其中, 所述安全性信息交互请 求包含对安全性信息交互的类型的指示。
8. 根据权利要求 7所述的安全性信息交互系统, 其特征在于, 所述 安全性信息交互管理服务器进一步包括:
主控制模块, 所述主控制模块用于接收来自所述安全性信息交互终 端的应用主界面 URL请求和安全性信息交互界面 URL请求, 并将所述 应用主界面 URL请求和安全性信息交互界面 URL请求传送到界面生成 模块, 以及接收并解析来自所述安全性信息交互终端的所述安全性信息 交互请求, 并将解析后的安全性信息交互请求传送到安全性信息交互请 求处理模块;
界面生成模块, 所述界面生成模块用于基于接收到的所述应用主界 交互终端, 以及基于接收到的所述安全性信息交互界面 URL请求生成安 全性信息交互界面并将所述安全性信息交互界面传送回所述安全性信息 交互终端, 其中, 所述安全性信息交互界面 URL请求包含所述安全性信 息交互类型信息;
安全性信息交互请求处理模块, 所述安全性信息交互请求处理模块 用于处理接收到的所述解析后的安全性信息交互请求, 并通过与数据处 理服务器的数据交互完成安全性信息交互过程, 并将处理结果传送回所 述安全性信息交互终端, 其中, 当所述安全性信息交互请求指示安全性 信息交互的类型为 "脱机方式" 时, 所述安全性信息交互请求处理模块 将所述安全性信息交互请求所包含的安全性信息交互数据存储在存储模 块中;
存储模块, 所述存储模块用于至少存储所述安全性信息交互数据; 通信模块, 所述通信模块用于执行所述安全性信息交互管理服务器 与所述安全性信息交互终端和所述数据处理服务器之间的数据通信。
9. 根据权利要求 8所述的安全性信息交互系统, 其特征在于, 所述 主控制模块进一步用于在解析所述安全性信息交互请求之前对所述安全 性信息交互终端的合法性进行认证, 并且将解析后的安全性信息交互请 求通过路由的方式传送到所述安全性信息交互请求处理模块。
10. 根据权利要求 9所述的安全性信息交互系统, 其特征在于, 当接 收到的所述安全性信息交互请求指示安全性信息交互的类型为 "联机方 式" 时, 所述安全性信息交互请求处理模块基于所述安全性信息交互请 求以预定格式构造安全性信息交互报文, 随后以加密的方式将所述安全 性信息交互报文传送到所述数据处理服务器以进行后续处理, 以及将所 述数据处理服务器传送回的处理结果以 HTML页面的形式传送到所述安 全性信息交互终端。
11. 根据权利要求 10所述的安全性信息交互系统, 其特征在于, 当 接收到的所述安全性信息交互请求指示安全性信息交互的类型为 "脱机 方式" 时, 所述安全性信息交互请求处理模块将所述安全性信息交互请 求所包含的安全性信息交互数据存储在所述存储模块中, 并将处理结果 以 HTML页面的形式传送回所述安全性信息交互终端。
12. 根据权利要求 11所述的安全性信息交互系统, 其特征在于, 所 述安全性信息交互请求处理模块周期性地将存储在所述存储模块中的未 处理的安全性信息交互数据以批量地方式传送到所述数据处理服务器以 进行后续的处理。
13. 根据权利要求 12所述的安全性信息交互系统, 其特征在于, 在 所述安全性信息交互终端与所述安全性信息交互管理服务器之间以安全 通道的方式进行通信, 并且以 HTML超文本的方式进行相互之间的数据 传输。
14. 根据权利要求 13所述的安全性信息交互系统, 其特征在于, 所 述主控制模块进一步用于统一管理所述安全性信息交互终端。
15. —种安全性信息交互终端, 所述安全性信息交互终端用于基于 来自用户的安全性信息交互指令从安全性信息交互管理服务器获取并显 示应用主界面和安全性信息交互界面, 以及基于用户通过所述安全性信 息交互界面输入的安全性信息构造安全性信息交互请求, 并将所述安全 性信息交互请求发送到所述安全性信息交互管理服务器。
16. —种安全性信息交互管理服务器, 所述安全性信息交互管理服 务器用于为安全性信息交互终端提供应用主界面和安全性信息交互界 面, 以及解析和处理接收到的来自所述安全性信息交互终端的安全性信 息交互请求以完成安全性信息交互过程, 并将处理结果传送回所述安全 性信息交互终端。
17. —种安全性信息交互方法, 所述安全性信息交互方法包括下列 步骤:
( A1 )安全性信息交互终端基于来自用户的安全性信息交互指令从安 全性信息交互管理服务器获取并显示应用主界面;
( A2 )在用户通过所述应用主界面输入安全性信息交互类型信息后, 所述安全性信息交互终端基于所述安全性信息交互类型信息通过请求 URL的方式从所述安全性信息交互管理服务器获取并显示安全性信息交 互界面, 其中, 所述安全性信息交互界面包含安全性信息交互处理逻辑 和该处理逻辑所需的数据;
( A3 )基于用户通过所述安全性信息交互界面输入的安全性信息构造 安全性信息交互请求, 并将所述安全性信息交互请求发送到所述安全性 信息交互管理服务器;
( A4 )所述安全性信息交互管理服务器解析和处理接收到的所述安 全性信息交互请求以完成安全性信息交互过程, 并将处理结果传送回所 述安全性信息交互终端。
PCT/CN2013/077649 2012-06-27 2013-06-21 安全性信息交互系统、设备及方法 Ceased WO2014000601A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210214595.1A CN103516688A (zh) 2012-06-27 2012-06-27 安全性信息交互系统、设备及方法
CN201210214595.1 2012-06-27

Publications (1)

Publication Number Publication Date
WO2014000601A1 true WO2014000601A1 (zh) 2014-01-03

Family

ID=49782229

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/077649 Ceased WO2014000601A1 (zh) 2012-06-27 2013-06-21 安全性信息交互系统、设备及方法

Country Status (2)

Country Link
CN (1) CN103516688A (zh)
WO (1) WO2014000601A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105631371A (zh) * 2014-11-25 2016-06-01 南京斯代尔网络科技有限公司 安全性信息交互系统、设备及方法
CN104809413A (zh) * 2015-05-13 2015-07-29 上海瓶钵信息科技有限公司 基于TrustZone技术的移动平台可信用户界面框架

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101938520A (zh) * 2010-09-07 2011-01-05 中兴通讯股份有限公司 一种基于移动终端签名的远程支付系统及方法
CN102255924A (zh) * 2011-08-29 2011-11-23 浙江中烟工业有限责任公司 基于可信计算的多级安全互联平台及其处理流程
CN102368780A (zh) * 2011-06-27 2012-03-07 奇智软件(北京)有限公司 一种基于应用的信息交互方法及系统

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1776732A (zh) * 2005-12-02 2006-05-24 肖勇 基于移动终端的通用交易方法及其系统
CN101197667B (zh) * 2007-12-26 2010-07-14 北京飞天诚信科技有限公司 一种动态口令认证的方法
CN101841517A (zh) * 2009-03-18 2010-09-22 蓝海星空信息技术(北京)有限公司 基于蓝牙协议用soa构建b/s蓝牙网络系统
CN101515389B (zh) * 2009-03-20 2011-04-27 深圳市新国都软件技术有限公司 Pos机系统安全消费方法
CN101551894A (zh) * 2009-05-21 2009-10-07 候万春 监控信用卡套现的系统及方法
CN201622651U (zh) * 2009-12-29 2010-11-03 江西科技师范学院 支持二维条码识别的无线pos机
CN102104589A (zh) * 2010-01-13 2011-06-22 刘文祥 专有网系列
CN102497452B (zh) * 2011-12-28 2014-07-30 山东大学 一种基于嵌入式终端的在线流媒体服务方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101938520A (zh) * 2010-09-07 2011-01-05 中兴通讯股份有限公司 一种基于移动终端签名的远程支付系统及方法
CN102368780A (zh) * 2011-06-27 2012-03-07 奇智软件(北京)有限公司 一种基于应用的信息交互方法及系统
CN102255924A (zh) * 2011-08-29 2011-11-23 浙江中烟工业有限责任公司 基于可信计算的多级安全互联平台及其处理流程

Also Published As

Publication number Publication date
CN103516688A (zh) 2014-01-15

Similar Documents

Publication Publication Date Title
US11922492B2 (en) System and method for programmatically accessing financial data
US11676133B2 (en) Method and system for mobile cryptocurrency wallet connectivity
JP2025029021A5 (zh)
JP6787932B2 (ja) 情報インタラクションの方法、装置及びシステム
CA2795594C (en) Credential provision and proof system
SE539192C2 (en) Method and a system for authenticating a user
CN101316424A (zh) 一种信息传输方法、系统及装置
SE1450928A1 (en) Method and a system for authenticating a user
JP5443943B2 (ja) 商取引システム、商取引方法、商取引サーバ、ユーザ端末およびユーザプログラム
KR20120084576A (ko) Qr 코드를 이용하는 motp 인증 시스템 및 motp 인증 방법
WO2017107733A1 (zh) 线下支付方法、终端设备、后台支付装置及线下支付系统
CN115297137A (zh) 一种共享单车使用方法、电子设备和存储介质
CN102299928A (zh) 一种网络终端业务认证方法及装置
WO2014000601A1 (zh) 安全性信息交互系统、设备及方法
CN110650477A (zh) Nb-iot设备的交互方法、平台、服务器及存储介质
CN104980276B (zh) 用于安全性信息交互的身份认证方法
US20150317630A1 (en) Method and system for authentication token generation
CN113973004B (zh) 经由设备通知提供多因素认证凭证
CN109471723B (zh) 一种用于对任务的处理结果进行验证的方法及系统
WO2015014254A1 (zh) 与资源的转移相关联的安全性信息交互方法
CN118070316A (zh) 基于安全设备的离线授权方法、离线授权系统和存储介质
WO2014048319A1 (zh) 安全性信息交互系统、设备及方法
US10924297B2 (en) Agent system including an information processing device for executing an agent
WO2017150083A1 (ja) 認証処理装置および認証処理方法
KR20150055563A (ko) 가상 머신 클라이언트 구동 방법, 온라인 금융 서비스 제공 방법 및 이를 수행하는 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13809708

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 10/06/2015)

122 Ep: pct application non-entry in european phase

Ref document number: 13809708

Country of ref document: EP

Kind code of ref document: A1