WO2014153979A1 - 一种动态码的应用实现方法 - Google Patents

一种动态码的应用实现方法 Download PDF

Info

Publication number
WO2014153979A1
WO2014153979A1 PCT/CN2013/088349 CN2013088349W WO2014153979A1 WO 2014153979 A1 WO2014153979 A1 WO 2014153979A1 CN 2013088349 W CN2013088349 W CN 2013088349W WO 2014153979 A1 WO2014153979 A1 WO 2014153979A1
Authority
WO
WIPO (PCT)
Prior art keywords
dynamic code
dynamic
verification
client
algorithm
Prior art date
Application number
PCT/CN2013/088349
Other languages
English (en)
French (fr)
Inventor
汪德嘉
Original Assignee
Wang Dejia
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Wang Dejia filed Critical Wang Dejia
Publication of WO2014153979A1 publication Critical patent/WO2014153979A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes

Definitions

  • the invention relates to a multi-application method for dynamic data verification, in particular to a method for realizing safe and stable dynamic code generation, interaction and verification using computer technology, cloud technology, information coding and decoding technology and mobile communication technology. application.
  • the prior art relies on the intelligence of the mobile terminal, and provides various verification methods such as real cards, tags, short messages, and two-dimensional codes, but these programs are highly targeted, and it is difficult to apply to two methods through one solution.
  • the above applications cause users or merchants to configure different types of devices for different applications, and there are many problems that cannot be performed normally due to the limitation of matching models.
  • the invention aims at the backward situation of the above information interaction and verification, and proposes a dynamic code application implementation method, in order to realize dynamic information interaction and verification based on background or cloud communication, and meet the needs of various applications.
  • the above object of the present invention is a dynamic code application implementation method
  • the technical solution relates to a background server, a client and a merchant terminal, and the implementation method thereof comprises a dynamic code generation mechanism, a dynamic code verification mechanism, and a verification algorithm storage/dynamic loading mechanism.
  • the dynamic code generating mechanism is configured to generate a dynamic code according to an algorithm by a client smart device and present it to a smart device display unit, where the algorithm performs a security factor based on a customer identity factor, a device factor, a region factor, a time factor, and a service type factor.
  • a set of dynamic calculation methods of a composite processing, the dynamic code having at least one of a single validity, a time period validity, a regional validity, and a dynamic privacy;
  • the dynamic code verification mechanism validates the dynamic code and obtains the validity of the dynamic code after the dynamic code generated by the client and the dynamically loaded reductive algorithm are obtained by the merchant terminal, and if the verification succeeds, the merchant terminal performs the corresponding type of service.
  • the verification algorithm storage/dynamic loading mechanism stores a combination of a series of algorithms and a reductive algorithm in a remote background server and periodically updates, and the background server dynamically loads a set of dynamic calculation methods to the client, and correspondingly The reductive algorithm is loaded synchronously to the merchant terminal.
  • the client has a multi-application type including payment verification, anti-counterfeiting verification, ATM identification, vending machine identification, e-commerce user/account verification or game account verification, and the merchant terminal is in a type related to the client application.
  • a device carrier that matches the App or software program.
  • the customer identity factor is an identity card number, a financial card number, a game account number or a product code associated with the user identity
  • the device factor is a unique device ID of the client smart device.
  • the regional factor includes geographic information of the location where the dynamic code is generated, location information of the merchant terminal, and login of the game account. Geographic information or product origin information, where the customer identity factor is bound to the device factor and registered and stored in the background server encryption unit
  • the area factor further includes address range information of the service activity preset by the client.
  • the client is a payment verification or an ATM identification application
  • the regional factor includes geographic information at which the dynamic code is generated and address range information that allows payment or ATM withdrawal execution.
  • the client is an anti-counterfeiting verification application
  • the regional factor includes geographic information of a location where the dynamic code is generated, origin information of the product, and address range information that the product allows to sell or conforms to the definition of the authenticity.
  • the client is an e-commerce user/account verification application
  • the regional factor includes geographical information of the location where the dynamic code is generated, location information of the merchant terminal, and geographic range information of the consumer activity allowed to be performed by the e-commerce.
  • the client is a game account verification application
  • the area factor includes geographic information of a location where the dynamic code is generated, location information of the game account, and address range information that the game account allows to log in.
  • the background server dynamically loads a set of dynamic calculation methods to the client in a real-time synchronization manner, and synchronously loads the corresponding reduction algorithm to the merchant terminal, and the merchant terminal verifies the dynamic state under the online state. code.
  • the background server dynamically loads a set of dynamic computing methods to the client by using a timing synchronization manner, and synchronously loads the corresponding reductive algorithm to the merchant terminal, and the merchant terminal verifies the dynamic state offline. code.
  • the client smart device executes an algorithm based on a time axis, and the dynamic code is displayed at least in a dynamic digital string that changes with time, a dynamic one-dimensional barcode that changes with time, or changes with time. Dynamic QR code.
  • the merchant terminal uses the image acquisition unit to collect dynamic code for the smart device display unit, automatically performs image processing, recognizes a dynamic code presentation form, and performs dynamic code verification on the merchant terminal.
  • FIG. 1 is a schematic flowchart of implementation of a dynamic code application according to the present invention.
  • the present invention addresses the urgent need for information interaction in the field of object networking and business, and proposes an application method for dynamic code application. Specifically, it involves hardware such as background server, client, and merchant terminal, but in fact, the implementation of the dynamic code is based on the communication of the background server and the intelligent hardware of the client and the merchant terminal, but is more often given a code generation,
  • a technical solution for interaction and verification It can exist in various smart devices as a stand-alone app, or it can be integrated and large-scale application software programs in a supplementary program, and realize the transmission and verification of code information through multi-party communication, thereby facilitating various application services. Carry out.
  • the following is a detailed description from the various subsystem schemes as shown in Fig. 1 to clearly explain the meaning of the dynamic code of the present invention.
  • the dynamic code generation mechanism generates a dynamic code according to an algorithm by the client smart device and presents it to the smart device display unit.
  • the algorithm is a set of dynamic calculation methods for performing security factor composite processing based on a customer identity factor, a device factor, a region factor, a time factor, and a traffic type factor. Each time one or more dynamic calculation methods in the algorithm are dynamically loaded by the background server to the client for generating dynamic code.
  • the security factor composite processing here refers to the use of the above-mentioned various factors in the generation process of the dynamic code, and the values of the various factors are different according to different application scenarios, and the dynamic calculation is performed.
  • the method may be a specially defined calculation method, which may be a combination of a plurality of factors, a nesting of a plurality of factors or a combination of the two methods, and the dynamic code generation process is based on the above factors. It also performs multiple calculations at a certain frequency based on a certain time axis and obtains multiple results. Thereby, the dynamic code associated with the applied service and the client identity is obtained.
  • the dynamic code has at least one of a single validity, a time period validity, a regional validity, and a dynamic privacy.
  • the dynamic code is presented at least as a dynamic digital string that changes with time, a dynamic one-dimensional barcode that changes with time, or a dynamic two-dimensional code that changes with time.
  • the dynamic code may be a one-dimensional barcode at a certain moment. At another moment, it may become a two-dimensional code, and the information core contained is the same.
  • the merchant terminal uses the image acquisition unit to collect dynamic code for the smart device display unit and automatically performs image processing, recognizes the dynamic code presentation form, and performs dynamic code verification on the merchant terminal.
  • the dynamic code scheme of the present invention is applicable to a plurality of applications, and thus the client has, but is not limited to, a multi-application type including payment verification, anti-counterfeiting verification, ATM identification, vending machine identification, e-commerce user/account verification or game account verification.
  • the merchant terminal is a device carrier of an App or software program that matches the client application type. For details, refer to the embodiments described later.
  • the customer identity factor is the identity card number, the financial card number, the game account number or the product code associated with the user identity
  • the device factor is the client intelligence.
  • the unique device ID of the device includes the geographic information of the location where the dynamic code is generated, the location of the merchant terminal, the information of the game account login location, or the origin information of the product, where the customer identity factor is bound to the device factor and registered and stored in the background server. In the encryption unit, this also serves as the basis for the background server to dynamically load the algorithm to the corresponding client smart device or merchant terminal.
  • the dynamic code verification mechanism validates the dynamic code and identifies the validity of the dynamic code after obtaining the dynamic code generated by the client and the dynamically loaded reductive algorithm, and the so-called reductive algorithm is received and received.
  • the inverse operation method corresponding to the dynamic code generation algorithm Through the analysis of the short moving code, the merchant terminal can automatically identify the service type of the application, the identity of the client, and the condition of the specific service, that is, the validity of the short moving code. The merchant terminal performs the corresponding type of service only when it passes the verification, otherwise the application is aborted.
  • the verification algorithm storage/dynamic loading mechanism stores a combination of a series of algorithms and a reductive algorithm in a remote background server and periodically updates, and the background server dynamically loads a set of dynamic calculations.
  • the method goes to the client and synchronously loads the corresponding reductive algorithm to the merchant terminal.
  • both the algorithm and the reductive algorithm have certain specificity, so the system administrator needs to maintain and update the algorithms and reductive algorithms on the background server or remote access cloud server to prevent the dynamic code from being easily Intercept and decipher, to ensure the security of dynamic code.
  • the invention provides algorithm management based on the background, and the privacy of the dynamic code has been guaranteed from the operation aspect; at the same time, the specific implementation of the different application service types can be considered from the basis of the dynamic code generation operation (ie, various factors), so that Meet the needs of different practical applications.
  • the following is a deeper understanding through several specific embodiments based on regional factor changes, where the geographic factor also includes address range information that allows the business activity to be preset by the client.
  • Embodiment 1 The client is a payment verification or ATM identification application, and the corresponding merchant terminal is a merchant cash register or an ATM device.
  • consumers generally use real cards to pay at the cash register or direct cash transactions, and most people need to insert a real card, enter a password or enter a longer card number to realize card-free withdrawal when withdrawing money from ATM equipment.
  • the inconvenience of these methods is becoming more and more obvious and there is a greater risk of property damage.
  • some developers have proposed software and hardware transformation of ATM equipment or merchant cash registers, implanted video or fingerprint acquisition equipment, thus replacing the real card to achieve cardless payment applications.
  • the cost of such retrofits is very expensive, and there are many management problems to be solved, which invisibly increases the actual benefits.
  • the proposed dynamic code of the present invention can provide an efficient and convenient solution for various payment applications.
  • dynamic algorithm can be used to replace the traditional real card to complete the cash register or ATM withdrawal through remote algorithm management and simple APP interaction.
  • the latter does not require extensive hardware modification of the ATM device, and can be simply extended and integrated based on the anti-theft eye of the ATM device and its own software system.
  • simple hardware device modification is performed for the existing ATM device, that is, independent of the anti-theft.
  • a photographing module for dynamic code collection of the present invention may be provided in addition to the eye.
  • the user needs to limit the area in which the payment application is executed, the user only needs to set the regional factor on the smart device of the client.
  • the regional factors that can be generated by the state code include the geographic information of the location where the dynamic code is generated and the address range information that allows the payment or ATM withdrawal to be performed.
  • the dynamic code thus obtained can only be verified in the preset defined address range to implement a payment or withdrawal application.
  • the client is an anti-counterfeiting verification application
  • the corresponding merchant terminal becomes an anti-counterfeiting inspection device and the like.
  • the smart device can be loaded in the one-time open seal after any product is finished, and the corresponding device is implanted in the non-writeable storage area of the smart device.
  • Regional factors to facilitate the logistics management, sales operations and other activities in the later stages of the product.
  • the regional factor may include geographic information at which the dynamic code is generated, origin information of the product, and address range information that the product allows to sell or conform to the definition of the product.
  • it further clarifies the regionality of product license sales. If the actual sales behavior exceeds the information that the product included in the regional factor allows for sale or meets the definition of the address range of the genuine definition, the anti-counterfeiting tester in the illegal area cannot verify whether it is genuine or not, thus hindering the sales activity.
  • Embodiment 3 The client is an e-commerce user/account verification application, and the corresponding merchant terminal is a server of various e-commerce portal websites.
  • the user of the client can generate the corresponding dynamic code through the smart device of his own, and the e-commerce portal can collect the dynamic code through various channels of the image, and the corresponding algorithm can be obtained by the reduction algorithm. Account number and corresponding service permissions.
  • the user can set the regional factor through the smart device, so that the regional factor that the dynamic code can generate includes the location information of the merchant terminal and the geographical range information of the consumer activity allowed by the e-commerce. As a result, other users can no longer use the same device to log in to e-commerce or spend activities outside of the defined geographic range.
  • the dynamic code implementation method of the present invention provides an extended implementation scheme, which can effectively monitor such a two-dimensional code including a Trojan virus through a background server, promptly remind the consumer to take preventive measures, avoid property loss, and provide a practical Protection.
  • Embodiment 4 The client is a game account verification application, and the corresponding merchant terminal is a game server of various online games.
  • the dynamic code can replace the traditional login account, which is convenient for the game player to enter and pass the verification.
  • the regional factor may be set to include the registration information of the game account and the address range information that the game account allows to log in. This aspect can effectively prevent the game account from being logged in and stolen in different places, and effectively protect the player's property.
  • the application implementation method of the dynamic code of the present invention also has a service type of multiple applications, and is not limited to the above embodiment.
  • the TV box or TV set-top box
  • the opening and closing control the borrowing and storage of the public bicycle, and the like.
  • the specific implementation is not limited to the definition of the regional factor in the foregoing embodiment, or may be defined in multiple ways of the time factor, and can also meet the requirements of different application services from various ways.
  • the background server dynamically loads a set of dynamic calculation methods to the client in a real-time synchronization manner, and synchronously loads the corresponding reduction algorithm to the merchant terminal, and the merchant terminal is online. Verify the dynamic code in the status. Or the background server dynamically loads a dynamic computing method to the client by using a timing synchronization manner, and synchronously loads the corresponding reductive algorithm to the merchant terminal, and the merchant terminal verifies the dynamic code in an offline state.
  • the back-end server may be a large-scale server or a cloud-based cloud server, which is not limited by the present invention.
  • the implementation and implementation of the dynamic code application implementation method of the present invention breaks through the rigid and targeted manner of the traditional information interaction mode, and realizes the generation of dynamic code on the client side based on the communication network and the background server or the cloud server, at the merchant terminal.
  • Verification, and the dynamic code generation algorithm and the verification algorithm are respectively stored and dynamically loaded from the remote end, which improves the convenience and security of key information interaction, and provides an effective technical solution for interaction of various practical applications. .

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • Finance (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明揭示了一种云支付系统中动态码的实现方法,通过后台服务器面向客户端和商户终端实现动态码的产生、验证和验证算法存储/动态加载。具体地,通过算法的动态加载,由客户端通过算法进行安全因子复合处理产生动态码,并由商户终端采集得到该动态码后进行反运算并验证动态码或客户端用户的有效性。该动态码可用于支付验证、防伪验证、ATM识别、自动贩售机识别、电商用户/账户验证或游戏账户验证的多元应用中。应用本发明动态码方案:基于通信网络和后台服务器或云服务器实现,该动态码的产生算法和验证算法分别存储和动态加载自远端,提高了关键信息交互的便利性、安全性,为各种实用应用的交互提供了行之有效的技术解决方案。

Description

一种动态码的应用实现方法
技术领域
本发明涉及一种动态数据验证的多元应用方法, 尤其涉及一种综合利用计算机技术、 云 技术、 信息编译码技术及移动通讯技术实现安全稳定的动态码产生、 交互、 验证实现方法及 其多元的应用。
背景技术 说
随着科学技术的不断进步, 当今世上各种人、 物、 事的交互越来越电子化。 而在通信技 术的支持下, 越来越多元化发展的商品物流、 金融交易也进一步推进了电子化交互的趋势。 在这个过程中, 各种应用大都会经历一个必不可少的过程, 即验证。 任何电子设备都需要实 现最基本的识别: 验证执行业务操作的双方为直接关联的 (而非假冒、 冒充的) 。
现有技术依赖于移动终端的智能化, 提供了各种各样的实卡、 标签、 短信、 二维码等验 证方式, 但这些方案针对性较强, 很难通过一种方案适用于两种以上的应用, 造成用户或商 户需要分别对应不同应用配置各类大小设备, 更有受匹配型号之限导致许多应用无法正常执 行的问题。
物联网的飞速发展, 商业模式的转变日渐加速, 电子商务空前发达。 从应用执行的现状 来看, 支付验证尚且停留在基于实卡或短信的点对点交互, 易书丢失或易被劫持; 产品的防伪 验证还仅仅停留在产品包装表面加贴防伪标贴, 难免以次充好或以假乱真; ATM 取款必须 使用实卡或输入账号, 需要不忘账号或携带实物、 操作繁杂; 诸如此类的窘境在自动贩售 机、 电商登陆、 游戏账户登陆等方面也时有发生, 可见面向用户和商户的各类应用对信息交 互提出了新的要求, 迫切需要一种运作灵活、 配置实现简单、 安全可靠性强、 易于维护和应 用扩展性较大的方案, 实现便捷、 安全的信息交互, 满足各种应用所需。
发明内容
本发明针对上述信息交互、 验证的落后现状, 提出了一种动态码的应用实现方法, 以期 实现基于后台或云端通讯的动态信息交互、 验证, 满足各种应用之需。
本发明的上述目的, 一种动态码的应用实现方法, 其技术解决方案涉及后台服务器、 客 户端和商户终端, 其实现方法包括动态码产生机制、 动态码验证机制和验证算法存储 /动态 加载机制三部分, 其中:
所述动态码产生机制, 为由客户端智能设备按照算法产生动态码并呈现于智能设备显示 单元, 所述算法为基于客户身份因子、 设备因子、 地域因子、 时间因子和业务类型因子进行 安全因子复合处理的动态计算方法的集合, 所述动态码至少具有单次有效性、 时段有效性、 地域有效性、 动态私密性之一或多种兼具;
所述动态码验证机制, 为商户终端得到客户端所产生的动态码和动态加载的还原性算法 后对动态码进行验证并识别动态码的有效性, 若通过验证则商户终端执行相应类型的业务; 所述验证算法存储 /动态加载机制, 在远程的后台服务器中存储一系列算法和还原性算 法的组合并定期更新, 并且后台服务器动态加载一组动态计算方法至客户端, 并将相对应的 还原性算法同步加载至商户终端。
进一步地, 所述客户端具有包含支付验证、 防伪验证、 ATM 识别、 自动贩售机识别、 电 商用户 /账户验证或游戏账户验证的多元应用类型, 所述商户终端为与客户端应用类型相匹 配的 App或软件程序的设备载体。
进一步地, 动态码的产生机制中, 所述客户身份因子为与用户身份相关联的身份证号 码、 金融卡卡号、 游戏账号或产品代码, 所述设备因子为客户端智能设备唯一性的设备 ID, 所述地域因子包括动态码产生所在地的地理信息、 商户终端所在地信息、 游戏账号登陆 地信息或产品的产地信息, 其中客户身份因子与设备因子相绑定并注册存储于后台服务器加 密单元中
更进一步地, 所述地域因子还包括客户端预设的允许业务活动的地址范围信息。
再进一步地, 所述客户端为支付验证或 ATM识别应用, 所述地域因子包括动态码产生所 在地的地理信息及允许支付或 ATM取款执行的地址范围信息。
再进一步地, 所述客户端为防伪验证应用, 所述地域因子包括动态码产生所在地的地理 信息、 产品的产地信息及产品允许销售或符合正品定义的地址范围信息。
再进一步地, 所述客户端为电商用户 /账户验证应用, 所述地域因子包括动态码产生所 在地的地理信息、 商户终端所在地信息及允许通过电商进行消费活动的地理范围信息。
再进一步地, 所述客户端为游戏账户验证应用, 所述地域因子包括动态码产生所在地的 地理信息、 游戏账号的注册地信息及游戏账号允许登陆的地址范围信息。
进一步地, 验证算法存储 /动态加载机制中, 后台服务器采用实时同步方式动态加载一 组动态计算方法至客户端, 并将相对应的还原性算法同步加载至商户终端, 商户终端在线状 态下验证动态码。
进一步地, 验证算法存储 /动态加载机制中, 后台服务器采用定时同步方式动态加载一 组动态计算方法至客户端, 并将相对应的还原性算法同步加载至商户终端, 商户终端离线状 态下验证动态码。
进一步地, 动态码产生机制中, 所述客户端智能设备基于时间轴执行算法, 所述动态码 的呈现形式至少随时间变化的动态数字串、 随时间变化的动态一维条形码或随时间变化的动 态二维码。
进一步地, 动态码验证机制中, 所述商户终端利用图像采集单元面向智能设备显示单元 采集动态码并自动进行图像处理、 识别动态码呈现形式, 在商户终端上执行动态码验证。
应用本发明动态码方案: 基于通信网络和后台服务器或云服务器实现动态码在客户端的 产生、 在商户终端的验证, 并且该动态码的产生算法和验证算法分别存储和动态加载自远 端, 提高了关键信息交互的便利性、 安全性, 为各种实用应用的交互提供了行之有效的技术 解决方案。
附图说明
图 1为本发明动态码应用实现的流程示意图。
具体实施方式
本发明应对当前在物联领域和商业领域中信息交互的迫切需求, 创新提出了一种动态码 的应用实现方法。 具体涉及后台服务器、 客户端和商户终端等硬件, 但实际上该动态码的实 现虽然基于后台服务器的通讯及客户端和商户终端的智能化硬件, 但更多地被寄予了一种代 码产生、 交互、 验证的技术性方案。 它可以以独立的 App应用存在于各种智能设备之中, 也 可以以一种辅助程序整合与大型应用软件程序之中, 通过多方通讯实现代码信息的传递、 验 证, 从而便于各种应用业务的开展。 以下结合图 1所示从各个子系统方案详细描述以使本发 明动态码的意义得以明确阐释。
首先动态码产生机制, 为由客户端智能设备按照算法产生动态码并呈现于智能设备显示 单元。 这里算法为基于客户身份因子、 设备因子、 地域因子、 时间因子和业务类型因子进行 安全因子复合处理的一系列动态计算方法的集合。 而每次由后台服务器动态加载算法中的一 种或多种动态计算方法给客户端, 供其产生动态码。 特别地, 这里安全因子复合处理指的是 动态码的产生过程中或多或少会用到上述各类因子, 而各类因子的取值又根据不同的应用场 景而有所区别, 该动态计算方法可以是一种专门定义的计算方式, 可以是多种因子的并用, 也可以是多种因子的嵌套或两种方式的结合等, 而且该动态码产生过程中除基于上述因子外 它还基于一定的时间轴, 以一定的频率进行多次计算、 得到多次结果。 由此得到与所进行应 用业务、 客户端身份向关联的动态码。 该动态码至少具有单次有效性、 时段有效性、 地域有 效性、 动态私密性之一或多种兼具。 且动态码的呈现形式至少为随时间变化的动态数字串、 随时间变化的动态一维条形码或随时间变化的动态二维码, 实际应用中该动态码在某一时刻 可能是一维条形码, 在另一个时刻可能变成二维码, 且所包含的信息核心一致。 商户终端利 用图像采集单元面向智能设备显示单元采集动态码并自动进行图像处理、 识别动态码呈现形 式, 在商户终端上执行动态码验证。
本发明该动态码方案适用于多种应用, 故上述客户端具有但不限于包含支付验证、 防伪 验证、 ATM 识别、 自动贩售机识别、 电商用户 /账户验证或游戏账户验证的多元应用类型, 而商户终端为与客户端应用类型相匹配的 App 或软件程序的设备载体。 具体参见后述实施 例。
而在该动态码的产生机制中的诸多因子的含义和取值来看, 客户身份因子为与用户身份 相关联的身份证号码、 金融卡卡号、 游戏账号或产品代码, 设备因子为客户端智能设备唯一 性的设备 ID, 地域因子包括动态码产生所在地的地理信息、 商户终端所在地信息、 游戏账 号登陆地信息或产品的产地信息, 其中客户身份因子与设备因子相绑定并注册存储于后台服 务器加密单元中, 这也作为后台服务器向相应客户端智能设备或商户终端动态加载算法的依 据。
再者动态码验证机制, 为商户终端得到客户端所产生的动态码和动态加载的还原性算法 后对动态码进行验证并识别动态码的有效性, 这里所谓的还原性算法是与所接收的动态码产 生算法所对应的逆运算方法。 通过对该短动码的解析, 商户终端能自动识别应用的业务类 型、 客户端的身份及具体业务的许否条件等, 即短动码的有效性。 仅当通过验证则商户终端 执行相应类型的业务, 否则报错中止应用。
作为本发明动态码实现方法的另一个重点, 该验证算法存储 /动态加载机制是在远程的 后台服务器中存储一系列算法和还原性算法的组合并定期更新, 并且后台服务器动态加载一 组动态计算方法至客户端, 并将相对应的还原性算法同步加载至商户终端。 如前所述, 这里 的算法和还原性算法均具有一定的专用性, 因此系统管理员需要对后台服务器或远程访问云 端服务器对该些算法和还原性算法进行维护、 更新, 防止动态码被轻易拦截、 破译, 保障动 态码的安全性。
本发明提供了基于后台的算法管理, 已从运算方面保障了动态码的私密性; 同时面向不 同应用业务类型的具体实施, 可以从动态码产生运算基础 (即各类因子) 考虑, 以使其满足 不同实用应用的需求。 以下通过几个基于地域因子变化的具体实施例来加深理解, 其中地域 因子还包括客户端预设的允许业务活动的地址范围信息。
实施例一、 客户端为支付验证或 ATM识别应用, 对应的商户终端便是商户收银机或 ATM 设备。 目前情况下, 消费者普遍采用实卡在收银机刷卡或直接现金交易完成支付, 而人们在 ATM设备取款时大都需要插入实卡、 输入密码或输入较长的卡号实现无卡取款。 这些方式的 不便越来越显见而且存在较大的财产损失风险。 虽然也有开发者提出对 ATM设备或商户收银 机进行软硬件改造, 植入摄像或指纹采集设备, 从而取代实卡实现无卡支付应用。 但是这类 改造的成本是十分昂贵的, 而且存在很多管理方面的问题有待解决, 无形中增加了实际效 益。 为此本发明动态码的提出, 能够针对各类支付应用提供高效、 便捷的解决方案。 例如收 银支付方面, 可以通过远程算法管理和简单的 APP交互实现动态码取代传统的实卡完成收银 或 ATM取款。 尤其对于后者不需要对 ATM设备进行大幅硬件的改造, 可基于 ATM设备的防盗 眼和自身软件系统进行简单扩展融合即可, 当然对于现有 ATM设备进行简单的硬件设备改 造, 即独立于防盗眼之外可设置用于本发明动态码收集的拍摄模块。 再者如果用户需要限制 该支付应用得以执行的地区, 只需由用户在客户端的智能设备上对地域因子进行设定, 使动 态码得以产生的地域因子包括动态码产生所在地的地理信息及允许支付或 ATM取款执行的地 址范围信息。 如此所得到的动态码只能在预设定义的地址范围内通过验证, 实现支付或取款 应用。
实施例二、 客户端为防伪验证应用, 对应的商户终端便成为防伪检验仪等具体化设 备。 在这个实施例中, 基于十分成熟的单片机或微芯片技术, 可在任意产品在完成生产后, 在一次性开启的封口处加载智能设备, 并在该智能设备非易写存储区植入相应的地域因子, 以利于产品后期的物流管理、 销售经营活动等。 特别地, 该地域因子可以包括动态码产生所 在地的地理信息、 产品的产地信息及产品允许销售或符合正品定义的地址范围信息。 由此除 明确了产品的产地信息外, 还进一步明确了产品许可销售的地区性。 如果实际销售行为超出 了地域因子所包含的产品允许销售或符合正品定义的地址范围信息时, 非法地区的防伪检验 仪同样无法验证其是否为正品, 从而掣肘销售活动的进行。
实施例三、 客户端为电商用户 /账户验证应用, 对应的商户终端便是各类电商门户网站 的服务器。 在这个实施例中, 客户端的用户可以通过自己专属的智能设备产生相应的动态 码, 而电商门户网站可通过各种途径的图像采集该动态码, 经还原性算法即可得到对应用户 的登陆账号及相应服务权限。 与实施例二相似, 用户可以通过智能设备对地域因子进行设 定, 使动态码得以产生的地域因子包括商户终端所在地信息及允许通过电商进行消费活动的 地理范围信息。 由此其它用户便无法再使用相同设备在定义的地理范围之外登陆电商或进行 消费活动。 如今随着电商的繁荣, 一些不法分子的诈骗手段也日渐高端, 消费者通过智能手 机接收 "伪商品" 的二维码而导致智能手机中木马被劫持, 继而造成巨额经济损失的情况时 有发生。 本发明动态码实现方法提供了一种扩展实施方案, 它能通过后台服务器有效监控此 类二维码包含木马病毒与否, 及时提醒消费者采取防范措施, 避免财产损失, 为消费者提供 了切实的保障。
实施例四、 客户端为游戏账户验证应用, 对应的商户终端便是各种网游的游戏服务器。 在这个实施例中, 动态码便可取代传统登陆账号, 便于游戏玩家录入及通过验证。 同样, 也 可以设定地域因子包括游戏账号的注册地信息及游戏账号允许登陆的地址范围信息。 这方面 可以有效防止游戏账号被异地登陆、 偷盗, 切实保障玩家财产。
除上述实施例外, 本发明动态码的应用实现方法还具有多元应用的业务类型, 并不限于 上述实施例。 例如电视盒 (或电视机顶盒) 启闭控制、 公公自行车的借取存放等等。 而且其 具体实施也不限于上述实施例对地域因子的定义, 也可以是时间因子的多种方式定义, 也能 从各种途径满足不同应用业务的需求。
另外值得一提的是: 验证算法存储 /动态加载机制中, 后台服务器采用实时同步方式动 态加载一组动态计算方法至客户端, 并将相对应的还原性算法同步加载至商户终端, 商户终 端在线状态下验证动态码。 或者后台服务器采用定时同步方式动态加载一组动态计算方法至 客户端, 并将相对应的还原性算法同步加载至商户终端, 商户终端离线状态下验证动态码。 这里后台服务器可以是定点的大型服务器, 也可以是基于云技术的云服务器, 本发明对此不 作限定。
综上所述, 本发明动态码应用实现方法的提出和实施, 突破了传统信息交互方式的死板 和针对性, 它基于通信网络和后台服务器或云服务器实现动态码在客户端的产生、 在商户终 端的验证, 并且该动态码的产生算法和验证算法分别存储和动态加载自远端, 提高了关键信 息交互的便利性、 安全性, 为各种实用应用的交互提供了行之有效的技术解决方案。
以上仅是本发明的具体应用范例, 对本发明的保护范围不构成任何限制。 凡采用等同变 换或是等效替换而形成的技术方案, 均落在本发明权利保护范围之内。

Claims

权 利 要 求 书
1 . 一种动态码的应用实现方法, 涉及后台服务器、 客户端和商户终端, 其特征在于: 所述 应用实现方法包含动态码产生机制、 动态码验证机制和验证算法存储 /动态加载机制三部 分, 其中:
所述动态码产生机制, 为由客户端智能设备按照算法产生动态码并呈现于智能设备显示单 元, 所述算法为基于客户身份因子、 设备因子、 地域因子、 时间因子和业务类型因子进行安 全因子复合处理的动态计算方法的集合, 所述动态码至少具有单次有效性、 时段有效性、 地 域有效性、 动态私密性之一或多种兼具;
所述动态码验证机制, 为商户终端得到客户端所产生的动态码和动态加载的还原性算法后对 动态码进行验证并识别动态码的有效性, 若通过验证则商户终端执行相应类型的业务; 所述验证算法存储 /动态加载机制, 在远程的后台服务器中存储一系列算法和还原性算法的 组合并定期更新, 并且后台服务器动态加载一组动态计算方法至客户端, 并将相对应的还原 性算法同步加载至商户终端。
2. 根据权利要求 1 所述动态码的应用实现方法, 其特征在于: 所述客户端具有包含支付验 证、 防伪验证、 ATM 识别、 自动贩售机识别、 电商用户 /账户验证或游戏账户验证的多元应 用类型, 所述商户终端为与客户端应用类型相匹配的 App或软件程序的设备载体。
3. 根据权利要求 1 所述动态码的应用实现方法, 其特征在于: 动态码的产生机制中, 所述 客户身份因子为与用户身份相关联的身份证号码、 金融卡卡号、 游戏账号或产品代码, 所述 设备因子为客户端智能设备唯一性的设备 ID, 所述地域因子包括动态码产生所在地的地理 信息、 商户终端所在地信息、 游戏账号登陆地信息或产品的产地信息, 其中客户身份因子与 设备因子相绑定并注册存储于后台服务器加密单元中。
4. 根据权利要求 3 所述动态码的应用实现方法, 其特征在于: 所述地域因子还包括客户端 预设的允许业务活动的地址范围信息。
5. 根据权利要求 4 所述动态码的应用实现方法, 其特征在于: 所述客户端为支付验证或 ATM识别应用, 所述地域因子包括动态码产生所在地的地理信息及允许支付或 ATM取款执行 的地址范围信息。
6. 根据权利要求 4 所述动态码的应用实现方法, 其特征在于: 所述客户端为防伪验证应 用, 所述地域因子包括动态码产生所在地的地理信息、 产品的产地信息及产品允许销售或符 合正品定义的地址范围信息。
7. 根据权利要求 4所述动态码的应用实现方法, 其特征在于: 所述客户端为电商用户 /账户 验证应用, 所述地域因子包括动态码产生所在地的地理信息、 商户终端所在地信息及允许通 过电商进行消费活动的地理范围信息。
8. 根据权利要求 4 所述动态码的应用实现方法, 其特征在于: 所述客户端为游戏账户验证 应用, 所述地域因子包括动态码产生所在地的地理信息、 游戏账号的注册地信息及游戏账号 允许登陆的地址范围信息。
9. 根据权利要求 1所述动态码的应用实现方法, 其特征在于: 验证算法存储 /动态加载机制 中, 后台服务器采用实时同步方式动态加载一组动态计算方法至客户端, 并将相对应的还原 性算法同步加载至商户终端, 商户终端在线状态下验证动态码。
10. 根据权利要求 1 所述动态码的应用实现方法, 其特征在于: 验证算法存储 /动态加载机 制中, 后台服务器采用定时同步方式动态加载一组动态计算方法至客户端, 并将相对应的还 原性算法同步加载至商户终端, 商户终端离线状态下验证动态码。
11. 根据权利要求 1所述动态码的应用实现方法, 其特征在于: 动态码产生机制中, 所述客 户端智能设备基于时间轴执行算法, 所述动态码的呈现形式至少随时间变化的动态数字串、 随时间变化的动态一维条形码或随时间变化的动态二维码。
12. 根据权利要求 1所述动态码的应用实现方法, 其特征在于: 动态码验证机制中, 所述商 户终端利用图像采集单元面向智能设备显示单元采集动态码并自动进行图像处理、 识别动态 码呈现形式, 在商户终端上执行动态码验证。
PCT/CN2013/088349 2013-03-26 2013-12-02 一种动态码的应用实现方法 WO2014153979A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310097980.7 2013-03-26
CN2013100979807A CN103218715A (zh) 2013-03-26 2013-03-26 一种云支付系统中动态支付码的实现方法

Publications (1)

Publication Number Publication Date
WO2014153979A1 true WO2014153979A1 (zh) 2014-10-02

Family

ID=48816478

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/088349 WO2014153979A1 (zh) 2013-03-26 2013-12-02 一种动态码的应用实现方法

Country Status (2)

Country Link
CN (1) CN103218715A (zh)
WO (1) WO2014153979A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106157009A (zh) * 2015-04-10 2016-11-23 中华国际通讯网路股份有限公司 一种以变化的条码作为身份辨识的系统的实施方法
CN108492109A (zh) * 2018-03-15 2018-09-04 平安科技(深圳)有限公司 电子装置、动态码请求的处理方法及存储介质
RU2735614C1 (ru) * 2016-12-12 2020-11-05 Алибаба Груп Холдинг Лимитед Способ и устройство выделения ресурсов и способ электронного платежа
US10902393B2 (en) 2014-05-15 2021-01-26 Advanced New Technologies Co., Ltd. Method, apparatus, and system for operating an electronic account in connection with an electronic transaction
US11449636B2 (en) 2019-10-04 2022-09-20 Mastercard International Incorporated Systems and methods for secure provisioning of data using secure tokens
US11652813B2 (en) 2019-10-04 2023-05-16 Mastercard International Incorporated Systems and methods for real-time identity verification using a token code
US20230394619A1 (en) * 2018-04-06 2023-12-07 Groundspeak, Inc. System and method for view adjustment

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103218715A (zh) * 2013-03-26 2013-07-24 苏州通付盾信息技术有限公司 一种云支付系统中动态支付码的实现方法
CN104599123A (zh) * 2013-10-31 2015-05-06 腾讯科技(深圳)有限公司 账户信息的管理方法、账户管理服务器和销售终端及系统
CN104573547B (zh) * 2014-10-21 2018-06-19 江苏通付盾信息安全技术有限公司 一种信息交互的安全防范系统及其操作实现方法
CN105989491A (zh) * 2015-02-17 2016-10-05 孙宏铭 一种动态授权码生成方法及装置、支付交易方法及系统
CN106779640B (zh) * 2016-12-15 2021-08-20 北京奇虎科技有限公司 面对面电子支付控制方法及其装置
CN108197935A (zh) * 2017-11-29 2018-06-22 无锡雅座在线科技股份有限公司 动态码的使用方法及终端
CN108462699A (zh) * 2018-02-09 2018-08-28 苏州酷豆物联科技有限公司 基于时序加密的二维码生成及验证方法和系统
CN108960385A (zh) * 2018-06-29 2018-12-07 苏州酷豆物联科技有限公司 基于多重秘钥加密的二维码生成及验证方法和系统
CN109993524A (zh) * 2019-03-29 2019-07-09 深圳前海微众银行股份有限公司 卡券管理方法、装置、设备及计算机可读存储介质
CN111222886A (zh) * 2020-01-03 2020-06-02 深圳市华宇讯科技有限公司 一种消费卡使用方法、系统、设备和存储介质
CN114862387B (zh) * 2022-07-04 2022-11-04 成都桐领智能科技有限公司 一种基于可信条码的支付方法、系统和装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102184498A (zh) * 2011-05-26 2011-09-14 吴昱程 移动互联网自由支付交易模式
US20120185317A1 (en) * 2008-12-02 2012-07-19 Ebay, Inc. Mobile barcode generation and payment
CN103020818A (zh) * 2013-01-09 2013-04-03 重庆新亚盟电子科技有限公司 动态二维验证码支付系统
CN103218715A (zh) * 2013-03-26 2013-07-24 苏州通付盾信息技术有限公司 一种云支付系统中动态支付码的实现方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1667632A (zh) * 2005-05-08 2005-09-14 郑茵 一种基于支付确认码的移动支付方法
US20080189212A1 (en) * 2006-12-21 2008-08-07 Michael Kulakowski Electronic secure authentication for exchange buyer assurance system (eSafeBay)
CN102143188A (zh) * 2011-04-10 2011-08-03 上海擎龙通信技术有限公司 基于云计算加密存储服务的控制系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120185317A1 (en) * 2008-12-02 2012-07-19 Ebay, Inc. Mobile barcode generation and payment
CN102184498A (zh) * 2011-05-26 2011-09-14 吴昱程 移动互联网自由支付交易模式
CN103020818A (zh) * 2013-01-09 2013-04-03 重庆新亚盟电子科技有限公司 动态二维验证码支付系统
CN103218715A (zh) * 2013-03-26 2013-07-24 苏州通付盾信息技术有限公司 一种云支付系统中动态支付码的实现方法

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10902393B2 (en) 2014-05-15 2021-01-26 Advanced New Technologies Co., Ltd. Method, apparatus, and system for operating an electronic account in connection with an electronic transaction
CN106157009A (zh) * 2015-04-10 2016-11-23 中华国际通讯网路股份有限公司 一种以变化的条码作为身份辨识的系统的实施方法
RU2735614C1 (ru) * 2016-12-12 2020-11-05 Алибаба Груп Холдинг Лимитед Способ и устройство выделения ресурсов и способ электронного платежа
US11222327B2 (en) 2016-12-12 2022-01-11 Advanced New Technologies Co., Ltd. Resource allocation method and device, and electronic payment method
US11734667B2 (en) 2016-12-12 2023-08-22 Advanced New Technologies Co., Ltd. Resource allocation method and device, and electronic payment method
CN108492109A (zh) * 2018-03-15 2018-09-04 平安科技(深圳)有限公司 电子装置、动态码请求的处理方法及存储介质
US20230394619A1 (en) * 2018-04-06 2023-12-07 Groundspeak, Inc. System and method for view adjustment
US11449636B2 (en) 2019-10-04 2022-09-20 Mastercard International Incorporated Systems and methods for secure provisioning of data using secure tokens
US11652813B2 (en) 2019-10-04 2023-05-16 Mastercard International Incorporated Systems and methods for real-time identity verification using a token code
US11914752B2 (en) 2019-10-04 2024-02-27 Mastercard International Incorporated Systems and methods for secure provisioning of data using secure tokens

Also Published As

Publication number Publication date
CN103218715A (zh) 2013-07-24

Similar Documents

Publication Publication Date Title
WO2014153979A1 (zh) 一种动态码的应用实现方法
US20230281612A1 (en) Virtual pos terminal method and apparatus
TWI716056B (zh) 身份認證、號碼保存和發送、綁定號碼方法、裝置及設備
US9710804B2 (en) Virtual payment cards issued by banks for mobile and wearable devices
CN102763115B (zh) 通过读取按照设备可读形式提供的地址来进行设备配对
Ahmed et al. Security in next generation mobile payment systems: A comprehensive survey
CN108027926A (zh) 基于服务的支付的认证系统和方法
US20170116614A1 (en) Card payment device and card payment system
CN104038924B (zh) 实现资源交换信息处理的方法和系统
WO2016004183A1 (en) Enhanced user authentication platform
US9842332B2 (en) Systems and methods for processing a financial transaction
CN105590199A (zh) 一种基于动态二维码的支付方法以及支付系统
CN107004194A (zh) 精简的数字钱包交易的方法和装置
CN106875173A (zh) 一种认证交易的方法
US20120254041A1 (en) One-time credit card numbers
WO2015084816A1 (en) Multi-factor authentication system and method
CN103942897A (zh) 一种在atm机上实现无卡取款的方法
JP2023134791A (ja) 安全な読み取り専用の認証のためのシステム及び方法
CN104933565A (zh) 一种ic卡交易方法及系统
CN110599155A (zh) 一种支付方法和支付系统
US20230222482A1 (en) Device account activation
WO2023107446A1 (en) Utilization of biometrics in creation of secure key or digital signature
Alhothaily et al. A novel verification method for payment card systems
Yu et al. Security issues of in-store mobile payment
US20170344992A1 (en) Payment verification method, apparatus and system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13879703

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13879703

Country of ref document: EP

Kind code of ref document: A1