WO2014090094A1 - 基于二维码的取款系统以及基于二维码的取款方法 - Google Patents

基于二维码的取款系统以及基于二维码的取款方法 Download PDF

Info

Publication number
WO2014090094A1
WO2014090094A1 PCT/CN2013/088209 CN2013088209W WO2014090094A1 WO 2014090094 A1 WO2014090094 A1 WO 2014090094A1 CN 2013088209 W CN2013088209 W CN 2013088209W WO 2014090094 A1 WO2014090094 A1 WO 2014090094A1
Authority
WO
WIPO (PCT)
Prior art keywords
withdrawal
atm
dimensional code
bank
server
Prior art date
Application number
PCT/CN2013/088209
Other languages
English (en)
French (fr)
Inventor
万四爽
鲁志军
尹亚伟
刘国宝
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Publication of WO2014090094A1 publication Critical patent/WO2014090094A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • G06Q40/02Banking, e.g. interest calculation or account maintenance
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • G07F19/203Dispensing operations within ATMs

Definitions

  • the present invention relates to a data processing method and system based on a two-dimensional code, and in particular to a two-dimensional code based withdrawal system and a two-dimensional code based withdrawal method.
  • a withdrawal or payment system using a mobile phone terminal is disclosed, and the system for withdrawing and paying by using the mobile terminal is a service network through the mobile terminal and the bank.
  • the system for withdrawing and paying by using the mobile terminal is a service network through the mobile terminal and the bank.
  • ABC 95599 initiate a withdrawal request by SMS or telephone, and enter the code and bank card information corresponding to the withdrawal machine in the request to complete the withdrawal.
  • the present invention has been made in an effort to provide a two-dimensional code-based withdrawal system and a two-dimensional code collection method that can eliminate the need for a bank card, a withdrawal order, and a high security.
  • the two-dimensional code-based withdrawal method of the present invention utilizes a mobile terminal and a two-dimensional code acquisition method.
  • the server implements a method for data exchange between an ATM machine and an ATM distribution bank and a card issuing bank, and includes the following steps:
  • the withdrawal request sending step the user sends the withdrawal account information, the withdrawal amount and the two-dimensional code information displayed on the ATM machine to the two-dimensional code withdrawal server through the mobile terminal;
  • the withdrawal request forwarding step the two-dimensional code withdrawal server verifies the legality of the withdrawal request message, and after passing the verification, forwards the withdrawal request to the ATM cloth corresponding to the two-dimensional code information according to the two-dimensional code information Bank
  • the withdrawal request verification step the ATM deploys the bank to verify whether the two-dimensional code information is legal, and after passing the verification, sends the withdrawal request to the two-dimensional code server;
  • the withdrawal request re-forwarding step the two-dimensional code server forwards the withdrawal request to the issuing bank corresponding to the account information according to the account information;
  • Withdrawal acceptance response step The issuing bank verifies the withdrawal request and the legality of the account, and sends the withdrawal acceptance response to the QR code server after passing the verification;
  • the withdrawal acceptance response forwarding step The QR code server forwards the withdrawal acceptance response to the ATM deployment bank;
  • the billing notification step the ATM deployment bank notifies the ATM to perform the billing operation according to the withdrawal acceptance response;
  • Result notification and QR code update procedure The ATM deployment bank notifies the QR code server of the processing result and updates the two-dimensional code displayed on the ATM.
  • the method further comprises: a result notification forwarding step: the two-dimensional code withdrawal server notifies the user of the acceptance result of the ATM distribution bank through the mobile terminal.
  • the withdrawal request sending step comprises the following sub-steps:
  • the user inputs the withdrawal account and the amount in the mobile terminal
  • the user uses the mobile terminal to scan the two-dimensional code displayed on the ATM and obtains the two-dimensional code information.
  • the user uses the mobile terminal to send the withdrawal request message including the withdrawal account, the amount, and the two-dimensional code information to the two-dimensional code server.
  • the two-dimensional code information includes at least:
  • the withdrawal request forwarding step sending a withdrawal request to the ATM deployment specified by the ATM distribution bank identifier according to the ATM distribution bank identifier included in the two-dimensional code
  • the bank includes at least the user's withdrawal account, amount, and QR code information in the withdrawal request.
  • the withdrawal request verification step comprises the following sub-steps:
  • the ATM deploys the bank to verify the legality of the content signature
  • the encrypted information is decrypted; and whether the ATM is working properly is determined according to the decrypted ATM identifier.
  • the two-dimensional codes displayed by each ATM are different.
  • the two-dimensional code-based withdrawal system of the present invention comprises: a mobile terminal, a two-dimensional code withdrawal server, an ATM, an ATM distribution bank, and a card issuing bank.
  • the ATM is configured to be capable of displaying a two-dimensional code and capable of performing a dispensing operation.
  • the mobile terminal is configured to send the account account information, the withdrawal amount, and the two-dimensional code information displayed on the ATM machine to the two-dimensional code withdrawal server as a withdrawal request message, and after verification, according to the two-dimensional code information, the withdrawal request is Sending to the ATM distribution bank corresponding to the two-dimensional code information, in case receiving the withdrawal request returned from the ATM distribution bank, sending the withdrawal request to the issuing bank corresponding to the account information, On the one hand, when the withdrawal acceptance response is received from the issuing bank, the withdrawal acceptance should be forwarded to the ATM for release.
  • the card issuing bank is configured to verify the legality of the withdrawal request and the account sent from the two-dimensional code server, and send the withdrawal acceptance response to the two-dimensional code server after passing the verification, and the ATM is used for the withdrawal of the bank according to the withdrawal
  • the response notification ATM performs a dispensing operation, notifies the two-dimensional code server of the acceptance result, and simultaneously causes the generation and update of the two-dimensional code displayed on the ATM.
  • the two-dimensional code withdrawal server is further configured to notify the mobile terminal of the 7-transfer result of the ATM deployment.
  • the mobile terminal is configured to scan a two-dimensional code displayed on the ATM machine and obtain two-dimensional code information.
  • the withdrawal request message includes a withdrawal account, an amount, and two-dimensional code information.
  • the two-dimensional code information includes at least:
  • the serial number of the withdrawal transaction on the ATM And encrypting the content identifier of the character string obtained by splicing the ATM identifier, the ATM distribution bank identifier, and the serial number in a predetermined format by using a private key.
  • the two-dimensional code shown is such that the two-dimensional codes displayed by each ATM and each withdrawal are different.
  • the mobile terminal is communicably connected to the two-dimensional code collection server, and the two-dimensional code withdrawal server is in communication connection with the ATM deployment bank.
  • the two-dimensional code withdrawal server is in communication connection with the card issuing bank,
  • the ATM is in communication with the ATM deployment.
  • the user data does not need to pass through the ATM but directly exchanges data with the ATM distribution bank and the issuing bank through the mobile terminal, thereby being able to avoid being The bank card caused by the side record is copied and the password is stolen, which improves the security of the transaction.
  • the user can perform operations such as selecting an account, inputting a password, and the like on the mobile terminal before scanning the two-dimensional code displayed on the ATM, the withdrawal operation can be completed, thereby reducing the waiting time for the withdrawal of the withdrawal.
  • the two-dimensional code-based withdrawal method of the present invention does not require any modification to the ATM device, and therefore has the advantage of low cost.
  • the size of the withdrawal machine can be greatly reduced, and the cost can be reduced.
  • FIG. 1 is a schematic structural view showing a two-dimensional code-based withdrawal system of the present invention.
  • FIG. 2 is a flow chart showing a method of withdrawing a two-dimensional code according to the present invention.
  • the two-dimensional code withdrawal system of the present invention comprises: a mobile terminal 100, an ATM 200, an ATM distribution bank 300, a two-dimensional code withdrawal server 400, and a card issuing bank 500.
  • the mobile terminal 100 is in communication with the two-dimensional code collection server 300
  • the two-dimensional code collection server 300 is in communication with the ATM distribution bank 400
  • the two-dimensional code withdrawal server 300 is in communication with the issuing bank 500
  • the ATM 200 is connected to the ATM distribution bank 500.
  • the mobile terminal 100 is configured to send the account account information, the withdrawal amount, and the two-dimensional code information displayed on the ATM to the two-dimensional code withdrawal server 400 as the withdrawal request message.
  • the mobile terminal 100 may be a mobile terminal device such as a mobile phone terminal or a tablet computer, as long as it has a function of capturing a two-dimensional code and transmitting related information such as account account information, withdrawal amount, and two-dimensional code information displayed on the ATM machine through mobile communication.
  • the network may transmit the function to the relevant server (in the present invention, the two-dimensional code collection server 400).
  • the ATM 200 is a conventional automatic teller machine, and the ATM 200 needs to be able to display a two-dimensional code in the present invention.
  • the legality of the message after passing the verification, sends the withdrawal request to the ATM distribution bank 300 corresponding to the two-dimensional code information according to the two-dimensional code information, and receives the withdrawal request returned from the ATM distribution bank 300.
  • the withdrawal request is sent to the issuing bank 500 corresponding to the account information, and on the other hand, when the withdrawal acceptance response is received from the issuing bank 500, the withdrawal acceptance should be forwarded to the ATM distribution bank 300, and When the ATM distribution bank 300 receives the processing result, it notifies the mobile terminal 100 of the processing result.
  • the card issuing bank 500 is configured to verify the legality of the withdrawal request and the account transmitted from the two-dimensional code server 400, and transmits the withdrawal acceptance response to the two-dimensional code server 400 after the verification.
  • the ATM distribution bank 300 is configured to perform a money dispensing operation according to the withdrawal acceptance response ATM 200, notify the two-dimensional code server 400 of the acceptance result, and simultaneously cause the two-dimensional code displayed on the ATM to be generated and updated.
  • FIG. 2 is a flow chart showing a method of withdrawing a two-dimensional code according to the present invention.
  • a specific flow of the two-dimensional code-based withdrawal method of the present invention will be described with reference to Figs. 1 and 2 .
  • step 1 when a user withdraws money through the ATM 200, a withdrawal account is selected on the mobile terminal 100, such as a mobile phone, and the account may be a background account bound according to the user identification. It may be an account stored in the security chip of the mobile terminal 100, or it may be an account number manually input by the user. After entering or selecting an account, enter the withdrawal amount and enter the password.
  • the mobile terminal 100 such as a mobile phone
  • the account may be a background account bound according to the user identification. It may be an account stored in the security chip of the mobile terminal 100, or it may be an account number manually input by the user.
  • step 2 the mobile terminal 100 activates the camera and prompts the user to scan the two-dimensional code displayed on the ATM 200.
  • the two-dimensional code of the present invention includes at least an ATM distribution bank identifier (which may be information such as the bank institution code or bank name), an ATM identifier (which can uniquely correspond to an ATM machine of the bank), The serial number of the withdrawal transaction on the ATM and the signature of the above content.
  • ATM Distribution Bank Identification may be information such as the banking institution code or bank name, as long as the ATM can be uniquely identified.
  • ATM logo is the identifier of an ATM that can uniquely correspond to a bank.
  • Signature of the above content means placing the above ATM logo and the above ATM
  • the bank identifier and the character string obtained by splicing the serial number according to the specified format are encrypted by the private key.
  • the content signature is generated when the AM deployment bank 400 generates the two-dimensional code for preventing the two-dimensional code from being forged and tombed.
  • a two-dimensional code (also known as a two-dimensional bar code) is an information code for recording data symbol information of black and white graphics distributed in a plane (two-dimensional direction) by a certain geometric pattern.
  • the two-dimensional code uses several geometric shapes corresponding to binary to represent literal numerical information, and is automatically read by an image input device or an optical scanning device for automatic information processing: it has some common features of bar code technology: each code has Its specific character set; each character occupies a certain width; has a certain check function. At the same time, it also has the functions of automatic identification of different lines of information, and processing of graphic rotation changes.
  • the ATM identification, the serial number of the withdrawal transaction, and the signature of the above content need to be encrypted, so that the other person cannot forge the two-dimensional code.
  • Step 3 After the mobile terminal 100 scans the two-dimensional code, the mobile terminal 100 sends the withdrawal account information, the withdrawal amount, and the two-dimensional code information to the two-dimensional code withdrawal server 300 as the withdrawal request message.
  • Step 4 After receiving the withdrawal request message, the two-dimensional code withdrawal server 300 verifies the legality of the withdrawal request message, and after passing the verification, deploys according to the ATM included in the two-dimensional code information.
  • the bank identification forwards the withdrawal request to the placement bank uniquely identified by the ATM distribution bank identification.
  • the withdrawal request includes at least a withdrawal account, a withdrawal amount, and two-dimensional code information.
  • Step 5 After receiving the withdrawal request from the two-dimensional code withdrawal server 300, the ATM deployment bank 400 acquires the two-dimensional code included in the withdrawal request, and then first, according to the two-dimensional code. Whether the serial number of the withdrawal transaction is normal, whether the content signature is correct, etc. to verify whether the two-dimensional code information is legal. If it is legal, the ATM identifier is decrypted according to the information contained in the two-dimensional code to determine whether the ATM is working normally. In this way, by verifying the signature information and the like, it is possible to ensure that the two-dimensional code information is not modified by the tomb, thereby ensuring transaction security.
  • Step 6 After the ATM deployment bank 400 passes the verification, the withdrawal request is initiated to the two-dimensional code withdrawal server 300.
  • Step 7 The two-dimensional code server 300 forwards the withdrawal request to the issuing bank 500 corresponding to the account information according to the account information included in the withdrawal request.
  • Step 8 The card issuing bank 500 verifies the legality of the withdrawal request and the account, and sends the withdrawal acceptance response to the two-dimensional code server 300 after passing the verification.
  • Step 9 After receiving the withdrawal acceptance response, the two-dimensional code server 300 forwards the withdrawal response to the corresponding ATM distribution bank 400 according to the ATM distribution bank identifier included in the withdrawal acceptance response.
  • Step 10 The ATM deployment bank 400 that receives the withdrawal response notifies the corresponding ATM to perform the money dispensing operation according to the ATM identifier included in the withdrawal response.
  • Step 11 The ATM deployment bank 400 notifies the result of the processing to the two-dimensional code withdrawal server 300, and simultaneously generates and updates the two-dimensional code on the ATM. That is to say, after each withdrawal is completed, the ATM deployment bank 400 updates the two-dimensional code displayed on the ATM 200 according to the transaction serial number to ensure that the two-dimensional codes scanned by each ATM and each withdrawal are different. This can prevent the illegitimate agent from replacing the two-dimensional code on the current ATM with the two-dimensional code on the other ATM, so that the user withdraws money at the current ATM and dispenses money at another ATM, thereby causing the risk of funds being stolen.
  • Step 12 The two-dimensional code withdrawal server 300 receives the ATM distribution bank 400 The mobile terminal 100 is notified after the result of the ⁇ .
  • user data does not need to pass through the ATM but data is transmitted between the mobile terminal and the two-dimensional code withdrawal server, the ATM distribution bank, and the issuing bank.
  • Exchange thereby avoiding the risk of bank card being copied and password being stolen caused by the side record, thereby improving the security of the transaction.
  • the user can perform operations such as selecting an account, inputting a password, and the like on the mobile terminal before scanning the two-dimensional code displayed on the ATM, the withdrawal operation can be completed, thereby reducing the waiting time for the withdrawal of the withdrawal.
  • the two-dimensional code-based withdrawal method of the present invention does not require any modification to the ATM device, and therefore has the advantage of low cost. Moreover, since it is not necessary to provide a device such as a PIN pad, the size of the withdrawal machine can be greatly reduced, and the cost can be reduced.

Abstract

本发明涉及基于二维码的取款方法以及基于二维码的取款系统。本发明的方法包括下述步骤:用户通过移动终端将取款请求报文上送到二维码取款服务器;二维码服务器验证取款请求报文的合法性,将取款请求转发至相应的ATM布放银行;ATM布放银行在验证二维码信息后将取款请求发送至二维码服务器;二维码服务器将取款请求转发至发卡银行;发卡银行验证取款请求及账户的合法性,在通过验证后将取款承兑应答发送到二维码服务器;二维码服务器将取款承兑应答转发到ATM布放银行;ATM布放银行根据取款承兑应答通知该ATM执行吐钞操作;ATM布放银行将处理结果通知二维码服务器并且更新该ATM上显示的二维码。

Description

基于二维码的取款系统以及基于二维码的取款方法 技术领域
[0001] 本发明涉及基于二维码的数据处理方法以及系统, 具体地涉及 基于二维码的取款系统以及基于二维码的取款方法。
背景技术
[0002] 目前的取款方法中, 一方面, 需要用户随身携带银行卡, 使用 不够方便; 另一方面, ATM (自动取款机器)上经常会被不法份子安 装的侧录机具窃取用户银行卡和密码等信息从而带来安全问题。
[0003] 作为一种解决办法,在公开号为 CN201440289U的专利中公开 了一种利用手机终端进行的取款或支付系统, 该利用手机终端进行取 款及支付的系统是通过手机终端与银行的服务网络(如农行 95599 ) 之间采用短信或者电话的方式发起取款请求, 在请求中输入取款机器 对应的编码和银行卡信息完成取款。
[0004] 这种方式虽然能够解决安全问题但是会增加用户的使用难度 和体验, 并不能解决便利性问题。 另外, 由于用户在电话或者短信中 需要输入取款机器的编码, 如果不法份子替换了当前机器的编码可能 导致用户取出的钞票在别的机器上吐出这一潜在的安全问题。
发明内容
[0005] 鉴于上述问题, 本发明旨在提供一种能够不需要使用银行卡、 取款手续筒单并且安全性高的基于二维码的取款系统以及二维码取 款方法。
[0006] 本发明的基于二维码的取款方法是利用移动终端和二维码取 款服务器实现 ATM机与 ATM布放银行以及发卡银行之间的数据交换 的方法, 其包括下述步骤:
取款请求上送步骤: 用户通过移动终端将取款账户信息、 取款金额以 及 ATM机上显示的二维码信息作为取款请求报文上送到二维码取款 服务器;
取款请求转发步骤: 二维码取款服务器验证所述取款请求报文的合法 性, 在通过验证后, 根据所述二维码信息, 将取款请求转发至与所述 二维码信息相应的 ATM布放银行;
取款请求验证步骤: ATM布放银行验证二维码信息是否合法性, 在 通过验证后, 将取款请求发送至二维码服务器;
取款请求再转发步骤: 二维码服务器根据所述账户信息, 将取款请求 转发至与所述账户信息相应的发卡银行;
取款承兌应答步骤: 发卡银行验证取款请求及账户的合法性, 在通过 验证后将取款承兌应答发送到二维码服务器;
取款承兌应答转发步骤: 二维码服务器将取款承兌应答转发到 ATM 布放银行;
吐钞通知步骤: ATM布放银行根据取款承兌应答通知该 ATM执行吐 钞操作;
结果通知及二维码更新步骤: ATM布放银行将处理结果通知二维码 服务器并且更新该 ATM上显示的二维码。
[0007] 优选地, 在所述结果通知及二维码更新步骤之后还具备: 结果通知转发步骤: 二维码取款服务器将 ATM布放银行的承兌结果 通过移动终端通知用户。 [0008] 优选地, 所述取款请求上送步骤包括下述子步骤:
用户在移动终端输入取款账户、 金额;
用户利用移动终端扫描 ATM机上显示的二维码并获取二维码信息; 用户利用移动终端向二维码服务器上送至少包括取款账户、 金额、 二 维码信息的取款请求报文。
[0009] 优选地, 所述二维码信息至少包括:
能够唯一确定该 ATM的 ATM标识;
能够唯一确定 ATM布放银行的 ATM布放银行标识;
该 ATM上取款交易的流水号; 以及
将所述 ATM标识、所述 ATM布放银行标识、所述流水号按照规定格 式拼接后得到的字符串通过私钥进行加密后的内容签名。
[0010] 优选地, 在所述取款请求转发步骤中, 根据所述二维码内包含 的所述 ATM布放银行标识,将取款请求发送到所述 ATM布放银行标 识所指定的 ATM布放银行, 在该取款请求中至少包括用户的取款账 户、 金额、 二维码信息。
[0011] 优选地, 所述取款请求验证步骤包括下述子步骤:
ATM布放银行验证所述内容签名的合法性;
在验证所述内容签名合法的情况下, 对被加密的信息进行解密; 根据解密得到的 ATM标识判断该 ATM是否工作正常。
[0012] 优选地, 在所述结果返回及二维码更新步骤中, 使得每台 ATM, 每次取款所显示的二维码都不相同。
[0013] 本发明的基于二维码的取款系统包括: 移动终端、 二维码取款 服务器、 ATM、 ATM布放银行以及发卡银行, 所述 ATM设置为能够显示二维码并能够执行吐钞操作,
所述移动终端用于将款账户信息、 取款金额以及 ATM机上显示的二 维码信息作为取款请求报文上送到二维码取款服务器 , 验证后, 根据所述二维码信息, 将取款请求发送至与所述二维码信息 相应的 ATM布放银行,在收到从所述 ATM布放银行返回的取款请求 的情况下, 将取款请求发送至与所述账户信息相应的发卡银行, 另一 方面, 当从发卡银行收到取款承兌应答的情况下将该取款承兌应转发 到 ATM布放艮行,
所述发卡银行用于验证从所述二维码服务器发送来的取款请求及账 户的合法性, 在通过验证后将取款承兌应答发送到二维码服务器, 所述 ATM布放银行用于根据取款 兌应答通知 ATM执行吐钞操作, 将承兌结果通知二维码服务器, 并且同时使得生成并更新该 ATM上 显示的二维码。
[0014] 优选地, 所述二维码取款服务器还用于向所述移动终端通知 ATM布放 4艮行的 7 兌结果。
[0015] 优选地, 所述移动终端用于扫描 ATM机上显示的二维码并获 取二维码信息。
[0016] 优选地,所述取款请求报文包括取款账户、金额、二维码信息。
[0017] 优选地, 所述二维码信息至少包括:
能够唯一确定该 ATM的 ATM标识;
能够唯一确定该 ATM布放银行的 ATM布放银行标识;
该 ATM上取款交易的流水号; 以及 将所述 ATM标识、所述 ATM布放银行标识、所述流水号按照规定格 式拼接后得到的字符串通过私钥进行加密后的内容签名。
示的二维码以使得每台 ATM、 每次取款所显示的二维码都不相同。
[0019] 优选地, 所述移动终端与所述二维码取款 务器通信连接, 所述二维码取款服务器与所述 ATM布放银行通信连接,
所述二维码取款服务器与所述发卡银行通信连接,
所述 ATM与所述 ATM布放艮行通信连接。
[0020] 根据本发明的基于二维码的取款方法以及二维码取款系统, 用 户数据不需要通过 ATM而是直接通过移动终端与 ATM布放银行、发 卡银行进行数据交换, 由此能够避免被侧录导致的银行卡被复制及密 码被窃取风险, 提高了交易的安全性。 而且, 由于用户可以事先在移 动终端上完成选择账户、 输入密码等操作, 再扫描 ATM上显示的二 维码后便可以完成取款操作, 因此, 能够减少取款的排队等待时间。 另一方面, 本发明的基于二维码的取款方法对 ATM设备不需要进行 任何改造, 因此, 具有成本低的优点。 而且, 由于不需要设置密码键 盘等设备, 还能够大大减少取款机器的大小, 降低成本。
[0021]
附图说明
[0022] 图 1是表示本发明的基于二维码的取款系统的构造示意图。
[0023] 图 2是表示本发明的基于二维码的取款方法的流程示意图。
[0024]
具体实施方式
[0025] 下面介绍的是本发明的多个实施例中的一些, 旨在提供对本发 明的基本了解。 并不旨在确认本发明的关键或决定性的要素或限定所 要保护的范围。
[0026] 图 1是表示本发明的二维码取款系统的构造示意图。如图 1所 示, 本发明的二维码取款系统包括: 移动终端 100、 ATM200、 ATM 布放银行 300、 二维码取款服务器 400以及发卡银行 500。 移动终端 100与二维码取款服务器 300通信连接, 二维码取款服务器 300与 ATM布放银行 400通信连接,二维码取款服务器 300与发卡银行 500 通信连接, ATM200与 ATM布放银行 500通信连接。
[0027] 移动终端 100用于将款账户信息、 取款金额以及 ATM机上显 示的二维码信息作为取款请求报文上送到二维码取款服务器 400。 这 里移动终端 100可以是手机终端、 平板电脑等的移动终端设备, 只要 其具备拍摄二维码的功能以及将款账户信息、 取款金额以及 ATM机 上显示的二维码信息等的相关信息通过移动通信网络发送到相关服 务器(在本发明中是二维码取款服务器 400 ) 的功能即可。
[0028] ATM 200是普通的自动取款机, ATM200在本发明中需要能够 显示二维码。 报文的合法性, 在通过验证后, 根据二维码信息, 将取款请求发送至 与二维码信息相应的 ATM布放银行 300,并且在收到从 ATM布放银 行 300返回的取款请求的情况下, 将取款请求发送至与账户信息相应 的发卡银行 500, 另一方面当从发卡银行 500收到取款承兌应答的情 况下将该取款承兌应转发到 ATM布放银行 300, 而且, 当从 ATM布 放银行 300收到处理结果的情况下,将该处理结果通知移动终端 100。 [0030] 发卡银行 500用于验证从二维码服务器 400发送来的取款请求 及账户的合法性, 在通过验证后将取款承兌应答发送到二维码服务器 400。
[0031] ATM布放银行 300用于根据取款承兌应答通知 ATM200执行 吐钞操作, 将承兌结果通知二维码服务器 400, 并且同时使得生成并 更新该 ATM上显示的二维码。
[0032] 图 2是表示本发明的基于二维码的取款方法的流程示意图。 以 下, 参照图 1以及图 2对于本发明的基于二维码的取款方法的具体流 程进行说明。
[0033] 首先, 如图 1和 2所示, 在步骤 1中, 当用户通过 ATM200 取款时, 在移动终端 100例如手机上选择取款账户, 该账户可以是根 据用户标识绑定的后台账户, 也可以是存储在移动终端 100的安全芯 片中的账户, 或者也可以是用户手工输入的账户号码。 在输入或选择 账户之后, 输入取款金额和输入密码。
[0034] 此后, 在步骤 2中, 移动终端 100激活摄像头并提示用户扫描 ATM200上显示的二维码。
[0035] 为了保证安全, 本发明的二维码中至少包含 ATM布放银行标 识(可以是该银行机构代码或银行名称等信息) 、 ATM标识(可以 唯一对应该银行的某台 ATM机)、该 ATM上取款交易的流水号以及 上述内容的签名。 这里, "ATM布放银行标识" 可以是该银行机构 代码或银行名称等信息的,只要能够唯一地标识 ATM布放银行即可。
"ATM标识" 是能够唯一对应该银行的某台 ATM的标识。
[0036] "上述内容的签名" 是指将上述 ATM标识、 上述 ATM布放 银行标识、 上述流水号按照规定格式拼接后得到的字符串通过私钥进 行加密后的内容签名。 该内容签名是 AM布放银行 400在产生二维码 的时候产生的, 用于防止二维码被伪造和墓改。 二维码( dimensional barcode, 也称为二维条码)是用某种特定的几何图形按一定规律在平 面 (二维方向上)分布的黑白相间的图形记录数据符号信息的信息编 码。 二维码使用若干个与二进制相对应的几何形体来表示文字数值信 息, 通过图象输入设备或光电扫描设备自动识读以实现信息自动处 理: 它具有条码技术的一些共性: 每种码制有其特定的字符集; 每个 字符占有一定的宽度; 具有一定的校验功能等。 同时还具有对不同行 的信息自动识别功能、 及处理图形旋转变化等特点。
[0037] 再者, 除了 ATM布放银行标识不需要加密外, ATM标识、 取 款交易的流水号以及上述内容的签名都需要被加密, 这样能够保证他 人无法伪造二维码。
[0038] 步骤 3: 在移动终端 100扫描二维码之后, 移动终端 100将取 款账户信息、 取款金额以及该二维码信息作为取款请求报文上送到二 维码取款服务器 300。
[0039] 步骤 4: 二维码取款服务器 300在收到取款请求报文之后, 验 证所述取款请求报文的合法性, 在通过验证后, 根据所述二维码信息 中包含的 ATM布放银行标识,将取款请求转发至由该 ATM布放银行 标识唯一确定的布放银行。 其中, 该取款请求至少包含取款账户、 取 款金额以及二维码信息。
[0040] 步骤 5: ATM布放银行 400从二维码取款服务器 300接收到取 款请求后, 获取取款请求中包含的二维码, 接着, 首先根据二维码中 的取款交易的流水号是否正常、 内容签名是否正确等来验证二维码信 息是否合法, 如果合法, 则根据二维码所含信息解密得到 ATM标识, 判断该 ATM是否工作正常。 这样, 通过对签名信息等进行验证, 能 够保证二维码信息没有被墓改, 确保交易安全性。
[0041] 步骤 6: ATM布放银行 400通过验证后, 则发起取款请求至二 维码取款服务器 300。
[0042] 步骤 7: 二维码服务器 300根据取款请求中所含的账户信息, 将取款请求转发至与所述账户信息相应的发卡银行 500。
[0043] 步骤 8: 发卡银行 500验证取款请求及账户的合法性, 在通过 验证后将取款承兌应答发送到二维码服务器 300。
[0044] 步骤 9: 在收到取款承兌应答后二维码服务器 300根据取款承 兌应答中含有的 ATM布放银行标识,将取款应答转发到相应的 ATM 布放银行 400。
[0045] 步骤 10: 收到取款应答的 ATM布放银行 400, 根据取款应答 中包含的 ATM标识, 通知相应的的 ATM执行吐钞操作。
[0046] 步骤 11: ATM布放银行 400将处理的结果通知到二维码取款 服务器 300, 并且同时生成并更新该 ATM上二维码。 也就是说, 在 每次取款完成后, ATM布放银行 400根据交易流水号更新 ATM 200 上显示的二维码, 以保证每台 ATM、 每次取款所扫描的二维码是不 相同的。 这样能够避免不法份子用别的 ATM上的二维码替换当前 ATM上的二维码, 从而用户在当前 ATM取款, 而在另外的 ATM上 吐钞, 造成资金被盗取风险。
[0047] 步骤 12: 二维码取款服务器 300在接收到 ATM布放银行 400 的^^兌结果后通知移动终端 100。
[0048] 根据本发明的基于二维码的取款方法以及二维码取款系统, 用 户数据不需要通过 ATM而是通过移动终端与二维码取款服务器、 ATM布放银行以及发卡银行之间进行数据交换, 由此能够避免被侧 录导致的银行卡被复制及密码被窃取风险, 提高了交易的安全性。 而 且, 由于用户可以事先在移动终端上完成选择账户、输入密码等操作, 再扫描 ATM上显示的二维码后便可以完成取款操作, 因此, 能够减 少取款的排队等待时间。 另一方面, 本发明的基于二维码的取款方法 对 ATM设备不需要进行任何改造, 因此, 具有成本低的优点。 而且, 由于不需要设置密码键盘等设备, 还能够大大减少取款机器的大小, 降低成本。
[0049] 以上例子主要说明了本发明的基于二维码的取款系统以及基 于二维码的取款方法。 尽管只对其中一些本发明的具体实施方式进行 了描述, 但是本领域普通技术人员应当了解, 本发明可以在不偏离其 主旨与范围内以许多其他的形式实施。 因此, 所展示的例子与实施方 式被视为示意性的而非限制性的, 在不脱离如所附各权利要求所定义 的本发明精神及范围的情况下, 本发明可能涵盖各种的修改与替换。

Claims

权利要求 书
1. 一种基于二维码的取款方法, 是利用移动终端和二维码取款 服务器实现 ATM机与 ATM布放银行以及发卡银行之间的数据交换的 方法, 其特征在于, 包括下述步骤:
取款请求上送步骤: 用户通过移动终端将取款账户信息、 取款 金额以及 ATM机上显示的二维码信息作为取款请求报文上送到二维 码取款服务器;
取款请求转发步骤: 二维码取款服务器验证所述取款请求报文 的合法性, 在通过验证后, 根据所述二维码信息, 将取款请求转发至 与所述二维码信息相应的 ATM布放银行;
取款请求验证步骤: ATM布放银行验证二维码信息是否合法性, 在通过验证后, 将取款请求发送至二维码服务器;
取款请求再转发步骤: 二维码服务器根据所述账户信息, 将取 款请求转发至与所述账户信息相应的发卡银行;
取款承兌应答步骤: 发卡银行验证取款请求及账户的合法性, 在通过验证后将取款承兌应答发送到二维码服务器;
取款承兌应答转发步骤: 二维码服务器将取款承兌应答转发到 ATM布放银行;
吐钞通知步骤: ATM布放银行根据取款承兌应答通知该 ATM 执行吐钞操作;
结果通知及二维码更新步骤: ATM布放银行将处理结果通知二 维码服务器并且更新该 ATM上显示的二维码。
2. 如权利要求 1所述的基于二维码的取款方法, 其特征在于, 在所述结果通知及二维码更新步骤之后还具备: 结果通知转发步骤:二维码取款服务器将 ATM布放银行的承兌 结果通过移动终端通知用户。
3. 如权利要求 2所述的基于二维码的取款方法, 其特征在于, 所述取款请求上送步骤包括下述子步骤:
用户在移动终端输入取款账户、 金额;
用户利用移动终端扫描 ATM机上显示的二维码并获取二维码 信息;
用户利用移动终端向二维码服务器上送至少包括取款账户、 金 额、 二维码信息的取款请求报文。
4. 如权利要求 3所述的基于二维码的取款方法, 其特征在于, 所述二维码信息至少包括:
能够唯一确定该 ATM的 ATM标识;
能够唯一确定 ATM布放银行的 ATM布放银行标识; 该 ATM上取款交易的流水号; 以及
将所述 ATM标识、 所述 ATM布放银行标识、 所述流水号按照 规定格式拼接后得到的字符串通过私钥进行加密后的内容签名。
5. 如权利要求 4所述的基于二维码的取款方法, 其特征在于, 在所述取款请求转发步骤中, 根据所述二维码内包含的所述
ATM布放银行标识,将取款请求发送到所述 ATM布放银行标识所指 定的 ATM布放银行, 在该取款请求中至少包括用户的取款账户、 金 额、 二维码信息。
6. 如权利要求 5所述的基于二维码的取款方法, 其特征在于, 所述取款请求验证步骤包括下述子步骤:
ATM布放银行验证所述内容签名的合法性;
在验证所述内容签名合法的情况下, 对被加密的信息进行解密; 根据解密得到的 ATM标识判断该 ATM是否工作正常。
7. 如权利要求 6所述的二维码取款方法, 其特征在于, 在所述结果返回及二维码更新步骤中, 使得每台 ATM、 每次取 款所显示的二维码都不相同。
8. 一种基于二维码的取款系统, 其特征在于, 包括: 移动终端、 二维码取款服务器、 ATM、 ATM布放银行以及发卡银行,
所述 ATM设置为能够显示二维码并能够执行吐钞操作, 所述移动终端用于将款账户信息、取款金额以及 ATM机上显示 的二维码信息作为取款请求报文上送到二维码取款服务器 , 在通过验证后, 根据所述二维码信息, 将取款请求发送至与所述二维 码信息相应的 ATM布放银行,在收到从所述 ATM布放银行返回的取 款请求的情况下, 将取款请求发送至与所述账户信息相应的发卡银 行, 另一方面, 当从发卡银行收到取款承兌应答的情况下将该取款承 兌应转发到 ATM布放银行,
所述发卡银行用于验证从所述二维码服务器发送来的取款请求 及账户的合法性, 在通过验证后将取款承兌应答发送到二维码服务 器,
所述 ATM布放银行用于根据取款承兌应答通知 ATM执行吐钞 操作, 将承兌结果通知二维码服务器, 并且同时使得生成并更新该 ATM上显示的二维码。
9. 如权利要求 8所述的基于二维码的取款系统, 其特征在于, 所述二维码取款服务器还用于向所述移动终端通知 ATM布放 银行的承兌结果。
10. 如权利要求 9所述的基于二维码的取款系统, 其特征在于, 所述移动终端用于扫描 ATM机上显示的二维码并获取二维码 信息。
11. 如权利要求 10所述的基于二维码的取款系统,其特征在于, 所述取款请求报文包括取款账户、 金额、 二维码信息。
12. 如权利要求 11所述的基于二维码的取款系统,其特征在于, 所述二维码信息至少包括:
能够唯一确定该 ATM的 ATM标识;
能够唯一确定该 ATM布放银行的 ATM布放银行标识; 该 ATM上取款交易的流水号; 以及
将所述 ATM标识、 所述 ATM布放银行标识、 所述流水号按照 规定格式拼接后得到的字符串通过私钥进行加密后的内容签名。 显示的二维码以使得每台 ATM、 每次取款所显示的二维码都不相同。
14. 如权利要求 12所述的基于二维码的取款系统,其特征在于, 所述移动终端与所述二维码取款服务器通信连接,
所述二维码取款服务器与所述 ATM布放银行通信连接, 所述二维码取款服务器与所述发卡银行通信连接,
所述 ATM与所述 ATM布放 4艮行通信连接。
PCT/CN2013/088209 2012-12-11 2013-11-29 基于二维码的取款系统以及基于二维码的取款方法 WO2014090094A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210530694.0A CN103871159A (zh) 2012-12-11 2012-12-11 基于二维码的取款系统以及基于二维码的取款方法
CN201210530694.0 2012-12-11

Publications (1)

Publication Number Publication Date
WO2014090094A1 true WO2014090094A1 (zh) 2014-06-19

Family

ID=50909656

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/088209 WO2014090094A1 (zh) 2012-12-11 2013-11-29 基于二维码的取款系统以及基于二维码的取款方法

Country Status (2)

Country Link
CN (1) CN103871159A (zh)
WO (1) WO2014090094A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107103450A (zh) * 2017-04-10 2017-08-29 广州正虹科技发展有限公司 一种运营督查管理方法及系统
US11562351B2 (en) 2019-08-09 2023-01-24 Its, Inc. Interoperable mobile-initiated transactions with dynamic authentication
US11881087B2 (en) 2022-02-10 2024-01-23 Its, Inc. Fund disbursement at an automated teller machine (ATM) using a credit push

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104240371B (zh) * 2014-09-24 2016-08-17 福建今日特价网络有限公司 基于静态二维码的存取款系统
CN106228707B (zh) * 2014-09-24 2019-07-09 柳欢 基于动态二维码的存取款系统
CN105741102A (zh) * 2014-12-07 2016-07-06 联芯科技有限公司 取现系统及取现方法
CN104537562A (zh) * 2015-01-12 2015-04-22 广州广电运通金融电子股份有限公司 一种金融自助系统的处理方法
CN105447997A (zh) * 2015-11-16 2016-03-30 上海斐讯数据通信技术有限公司 一种在atm机上无卡取钞的方法及智能终端
CN107292609A (zh) * 2016-04-03 2017-10-24 汪风珍 一种和银行卡相关的商业交易方法
CN106339938A (zh) * 2016-08-25 2017-01-18 深圳怡化电脑股份有限公司 一种金融交易方法与系统
CN107481445A (zh) * 2017-06-29 2017-12-15 台山市金讯互联网络科技有限公司 一种无卡取款的方法
CN108492488A (zh) * 2018-04-03 2018-09-04 广州奥翼电子科技股份有限公司 支付码显示设备、支付码显示系统及支付码显示方法
CN110322244A (zh) * 2019-07-05 2019-10-11 中国工商银行股份有限公司 一种基于虚拟账户的跨行无卡取现处理方法及装置
CN110458692A (zh) * 2019-08-06 2019-11-15 聊城农村商业银行股份有限公司 一种农村普惠金融信贷服务的实现方法
CN112039677B (zh) * 2020-11-05 2021-03-16 飞天诚信科技股份有限公司 基于服务器进行扫码操作处理的方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005346129A (ja) * 2004-05-31 2005-12-15 Oki Electric Ind Co Ltd 自動取引システム
CN101377875A (zh) * 2007-08-30 2009-03-04 北京方维银通科技有限公司 自动柜员机支付方法和自动柜员机
CN102461229A (zh) * 2009-04-20 2012-05-16 欧特科尔有限公司 使用移动设备进行个人验证的系统和方法
US20120160912A1 (en) * 2010-12-23 2012-06-28 Kevin Laracey Mobile phone atm processing methods and systems

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1758276A (zh) * 2004-10-10 2006-04-12 中国银联股份有限公司 一种支付服务管理系统及方法
CN101482948A (zh) * 2008-01-07 2009-07-15 唐红波 基于二维码实现手机支付的方法
CN101436280B (zh) * 2008-12-15 2012-09-05 北京华大智宝电子系统有限公司 实现移动终端电子支付的方法及系统
CN102831514A (zh) * 2011-06-15 2012-12-19 上海博路信息技术有限公司 一种基于条码的支付凭证
CN102243739A (zh) * 2011-07-04 2011-11-16 中国建设银行股份有限公司 基于二维码的手机银行支付方法、系统及客户端

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005346129A (ja) * 2004-05-31 2005-12-15 Oki Electric Ind Co Ltd 自動取引システム
CN101377875A (zh) * 2007-08-30 2009-03-04 北京方维银通科技有限公司 自动柜员机支付方法和自动柜员机
CN102461229A (zh) * 2009-04-20 2012-05-16 欧特科尔有限公司 使用移动设备进行个人验证的系统和方法
US20120160912A1 (en) * 2010-12-23 2012-06-28 Kevin Laracey Mobile phone atm processing methods and systems

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107103450A (zh) * 2017-04-10 2017-08-29 广州正虹科技发展有限公司 一种运营督查管理方法及系统
US11562351B2 (en) 2019-08-09 2023-01-24 Its, Inc. Interoperable mobile-initiated transactions with dynamic authentication
US11881087B2 (en) 2022-02-10 2024-01-23 Its, Inc. Fund disbursement at an automated teller machine (ATM) using a credit push

Also Published As

Publication number Publication date
CN103871159A (zh) 2014-06-18

Similar Documents

Publication Publication Date Title
WO2014090094A1 (zh) 基于二维码的取款系统以及基于二维码的取款方法
EP2378451B1 (en) User authentication in a tag-based service
CN103282929B (zh) 操作移动装置完成账户持有者的atm交易的方法及交易系统
CN102881071B (zh) 电子票券防伪系统与方法
US9830588B2 (en) Methods and arrangements for smartphone payments
US9886688B2 (en) System and method for secure transaction process via mobile device
US10270587B1 (en) Methods and systems for electronic transactions using multifactor authentication
US20130046697A1 (en) Using Mobile Device to Prevent Theft of User Credentials
US10453105B2 (en) Encrypted payment image
US8186586B2 (en) System, method, and apparatus for smart card pin management via an unconnected reader
CN102968717A (zh) 一种电子支付方法、相关设备及系统
KR20120116902A (ko) 데이터 교환의 개별화된 형태의 인증 및 제어를 소유하는 개인화된 다기능 액세스 디바이스
EP2962262A2 (en) Methods and arrangements for smartphone payments and transactions
CN106506496A (zh) 一种无卡取款的方法、装置和系统
US20170337553A1 (en) Method and appartus for transmitting payment data using a public data network
US20140358786A1 (en) Virtual certified financial instrument system
KR20140145190A (ko) 전자 거래 방법
KR101638787B1 (ko) 위치정보와 단말기 고유번호 기반의 모바일 티켓 보안시스템 및 그 방법
US11631062B2 (en) Voucher verification auxiliary device, voucher verification auxiliary system, and voucher verification auxiliary method
JP2011211666A (ja) 伝票処理システム
CN114207578A (zh) 移动应用程序集成
WO2004112275A1 (en) An electronic billing system using blinking signal of display panel of mobile communication terminal and a method thereof
CN106157037B (zh) 移动支付方法及移动支付设备
JP5904200B2 (ja) 情報発行システム及びプログラム
KR20150145208A (ko) 생체 인증에 기반한 모바일 지불 시스템 및 모바일 지불 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13861807

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 24.09.2015)

122 Ep: pct application non-entry in european phase

Ref document number: 13861807

Country of ref document: EP

Kind code of ref document: A1