WO2015109923A1 - 一种电子支付终端验证方法及系统 - Google Patents

一种电子支付终端验证方法及系统 Download PDF

Info

Publication number
WO2015109923A1
WO2015109923A1 PCT/CN2014/095460 CN2014095460W WO2015109923A1 WO 2015109923 A1 WO2015109923 A1 WO 2015109923A1 CN 2014095460 W CN2014095460 W CN 2014095460W WO 2015109923 A1 WO2015109923 A1 WO 2015109923A1
Authority
WO
WIPO (PCT)
Prior art keywords
security
pos machine
user
swiped
pos
Prior art date
Application number
PCT/CN2014/095460
Other languages
English (en)
French (fr)
Inventor
许宗庚
Original Assignee
福建联迪商用设备有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 福建联迪商用设备有限公司 filed Critical 福建联迪商用设备有限公司
Publication of WO2015109923A1 publication Critical patent/WO2015109923A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/202Interconnection or interaction of plural electronic cash registers [ECR] or to host computer, e.g. network details, transfer of information from host to ECR or from ECR to ECR
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]

Definitions

  • the invention relates to the field of electronic payment, in particular to an electronic payment terminal verification method and system.
  • POS machines In recent years, there have been frequent illegal conversion of card-type terminals, referred to here as POS machines, in order to obtain the card number and password of the card-sweeper.
  • the ordinary card-sweeper cannot distinguish whether the card-sending machine provided by the salesman meets the safety requirements (such as PCI certification).
  • the POS machine has been illegally modified, which poses a great hidden danger to the cardholder's card security, which affects the cardholder's willingness to swipe the card.
  • an object of the present invention is to provide an electronic payment terminal verification method and system, which can enable a credit card
  • the person establishes contact with the payment terminal provided by the salesman through his own trusted device to confirm whether the payment terminal is secure.
  • the invention adopts the following scheme: an electronic payment terminal verification method, which is characterized in that: a system server is provided, wherein the system server stores a securely authenticated POS database; the user downloads and installs software for authenticating the POS security. Then, the security data information of the POS machine to be swiped is obtained and transmitted to the system server for verification, and the system server returns the result to the user after verification.
  • the user downloads and installs the software for authenticating the security of the POS machine through the smart device, and obtains the security data information of the POS machine to be swiped by communication.
  • the user downloads and installs the software for authenticating the security of the POS machine through the smart device, and after communicating with the POS machine to be swiped, the POS machine to be swiped transmits the encrypted security.
  • Data information, the security data information is read or scanned by the user equipment.
  • the system server searches and compares the security data information transmitted by the user in the security-certified POS database, and determines whether the POS machine to be swiped is a POS machine that has been authenticated by security. And return the judgment result to the user.
  • the invention also provides an electronic payment terminal verification system, comprising: a system server, a handheld terminal and a POS machine to be swiped, wherein the system server stores a securely authenticated POS database; the user passes The handheld terminal downloads and installs the softness of authenticating the security of the POS machine And then obtain the security data information of the POS machine to be swiped and transmit it to the system server for verification, and the system server returns the result to the user after verification.
  • the user downloads and installs the software for authenticating the security of the POS machine through the handheld terminal, and obtains the security data information of the POS machine to be swiped by communication.
  • the user downloads and installs the software for authenticating the security of the POS machine through the handheld terminal, and after communicating with the POS machine to be swiped, the POS machine to be swiped is back-passed and encrypted. After the security data information, the security data information is read or scanned by the user equipment.
  • the user submits a preset question and answer on the system server, and when the secure data communication with the POS machine to be swiped is performed, the preset problem is attached, and the password is encrypted by the POS machine to be swiped.
  • the system server notifies the user of the judgment result, and simultaneously informs the user of the preset answer. If the answer is correct, the user can judge that the POS is safe.
  • the system server searches and compares the security data information transmitted by the user in the security-certified POS database, and determines whether the POS machine to be swiped is a POS machine that has been authenticated by security. And return the judgment result to the user.
  • the POS machine to be swiped complies with the PCI security specification, and the security data information of the POS machine is saved in the security zone of the POS machine, and the illegal attempt to tamper with or detect the security data information may result in security.
  • the data information is cleared.
  • the invention can confirm the security of the payment terminal, can protect the information related to the cardholder card, eliminate the doubts of the cardholder, protect the rights of the cardholder, and facilitate the improvement of the payment environment.
  • FIG. 1 is a schematic block diagram of an electronic payment terminal verification system of the present invention.
  • the invention provides an electronic payment terminal verification method, and provides a system server, wherein the system server stores a POS machine database that has undergone security authentication (such as PCI certification), and provides a software download service for authenticating the security of the POS machine ( And there is a secure service provided, the software for authenticating the security of the POS machine can also be provided by the server recognized by the system); the user downloads and installs the recognized The security software of the POS machine then obtains the security data information of the POS machine to be swiped and transmits it to the system server for verification, and the system server returns the result to the user after verification.
  • security authentication such as PCI certification
  • the software for authenticating the security of the POS machine can also be provided by the server recognized by the system
  • the security software of the POS machine then obtains the security data information of the POS machine to be swiped and transmits it to the system server for verification, and the system server returns the result to the user after verification.
  • the user can download and install the software for authenticating the security of the POS machine through the smart device (which may also be a tablet computer), and through a communication method (including wired or wireless methods, such as sound waves, Bluetooth, wifi or mobile signal, etc.) initiates a verification request and receives verification information (security data information) returned by the POS.
  • a communication method including wired or wireless methods, such as sound waves, Bluetooth, wifi or mobile signal, etc.
  • the user can download and install the software for authenticating the security of the POS machine through the smart device (which may also be a tablet computer), and after the communication with the POS machine to be swiped, the card to be swiped.
  • the POS machine returns the encrypted security data information (such as bar code or two-dimensional code information or a piece of sound wave that protects the data), and the security data information is read or scanned by the user equipment.
  • the system server searches and compares the security data information transmitted by the user in the securely authenticated POS database, determines whether the POS machine to be swiped is a POS machine that has been authenticated by security, and returns the judgment result. To the user.
  • the present invention further provides an electronic payment terminal verification system, including a system server, a handheld terminal, and a POS machine to be swiped, wherein the system server stores a securely authenticated POS database;
  • the user downloads and installs the software for authenticating the security of the POS machine through the handheld terminal, and then obtains the security data information of the POS machine to be swiped (the information may be a random number and a POS machine applied by the handheld terminal to the background system)
  • the security information is encrypted by a certain algorithm and transmitted to the system server for verification, and the system server returns the result to the user after verification.
  • the software for authenticating the security of the POS machine may be provided by the system server for downloading, or may be provided by another server, but should be an authenticated server within the system.
  • the user can download and install the software for authenticating the security of the POS machine through the handheld terminal (such as a smart phone or a tablet computer, etc.), and through some communication method (including wired or wireless).
  • the manner such as sound wave, Bluetooth, wifi or mobile signal, etc., acquires the security data information of the POS machine to be swiped.
  • the user A places an online shopping order to select the cash on delivery, and after the courier arrives, the POS machine is provided to the A card.
  • A uses its own smart device to apply the software for authenticating POS security downloaded by the trusted security system server B provider.
  • the smart device applies for a random number RND to the background system to communicate with the POS device (Bluetooth). , wifi, mobile signal, etc.), get The security data on the POS machine (such as the Bluetooth MAC address or other unique identification code and the encrypted data of the random number after a certain algorithm), after the user intelligent device obtains it, it sends back to the system server B through the communication channel, and the system server B verifies the POS.
  • the relevant safety data on the aircraft (which may include other necessary information such as random numbers) is returned to User A's software interface to give conclusions, security, or non-security. Users can judge whether the POS machine is safe or not.
  • the user can download and install the software for authenticating the security of the POS machine through the handheld terminal (such as a smart phone or a tablet computer, etc.), and communicate with the POS machine to be swiped.
  • the POS machine to be swiped returns the encrypted security data information (for example, a piece of sound wave, bar code or two-dimensional code information modulated with data), and the security data information is read or scanned by the user handheld terminal.
  • the system server transmits the security data information transmitted by the user to the securely authenticated POS
  • the search and comparison are performed in the machine database to determine whether the POS machine to be swiped is a POS machine that has been authenticated securely, and the judgment result is returned to the user.
  • the user can submit a preset question and answer on the system server (by software that authenticates the security of the POS machine), and at the same time attach a preset question to the POS machine to be swiped, and pass the POS machine to be swiped.
  • the encrypted data of the algorithm is transmitted back to the handheld terminal.
  • the system server can inform the user of the judgment result, and can also inform the user of the preset answer at the same time. If the answer is correct, the user can judge that the POS is safe.
  • the POS machine to be swiped complies with the PCI security specification, and the security data information of the POS machine is stored in the security zone of the POS machine. Any illegal attempt to tamper with or detect such security data information will cause the security data information to be cleared.
  • the invention enables the cardholder (user) to pass through his own trusted device (such as a smart phone or tablet, etc.), and through a trusted system server provider (for example, UnionPay, Alipay, or a well-known payment terminal provider in the industry).
  • a trusted system server provider for example, UnionPay, Alipay, or a well-known payment terminal provider in the industry.
  • the application software communicates with the credit card machine, obtains the necessary security information of the credit card machine, sends it to the system server via the card reader's device, verifies the legality of the payment terminal, and returns to swipe the card.
  • the human device informs the result, so that the payment terminal can be determined to be safe, then the card can be safely swiped, otherwise, the card is refused.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Cash Registers Or Receiving Machines (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种电子支付终端验证方法,其特征在于:提供一系统服务器,所述系统服务器上存储有经过安全认证的POS机数据库;用户下载并安装认证POS机安全性的软件,然后获取待刷卡的POS机的安全数据信息并传送到所述系统服务器进行验证,所述系统服务器验证后将结果返回给用户。能够确认支付终端的安全性,可以保护刷卡人卡相关信息安全,排除刷卡人的疑虑,保护了刷卡人的权利,有利于支付环境改善。

Description

一种电子支付终端验证方法及系统 技术领域
本发明涉及电子支付领域,尤其是一种电子支付终端验证方法及系统。
背景技术
近年来经常发生有不法分子改装刷卡类终端,这里简称POS机,以获取刷卡人的卡号,密码为目的,普通刷卡人无法辨别业务员提供的刷卡机是否是符合安全要求的(比如经过PCI认证过)POS机还是被非法改装过的,对刷卡人的刷卡安全造成极大的隐患,影响了刷卡人刷卡意愿。
发明内容
有鉴于此,本发明的目的是提供一种电子支付终端验证方法及系统,能够让刷卡
人通过自己的可以信任的设备,与业务员提供的支付终端建立联系,以确认该支付终端是否安全。
本发明采用以下方案实现:一种电子支付终端验证方法,其特征在于:提供一系统服务器,所述系统服务器上存储有经过安全认证的POS机数据库;用户下载并安装认证POS机安全性的软件,然后获取待刷卡的POS机的安全数据信息并传送到所述系统服务器进行验证,所述系统服务器验证后将结果返回给用户。
在本发明一实施例中,用户通过智能设备下载并安装所述的认证POS机安全性的软件,并通过通信获取所述待刷卡的POS机的安全数据信息。
在本发明一实施例中,用户通过智能设备下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机回传加密后的安全数据信息,由用户设备读取或扫描所述的安全数据信息。
在本发明一实施例中,所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。
本发明还提供一种电子支付终端验证系统,其特征在于:包括一系统服务器、一手持终端和一待刷卡的POS机,所述的系统服务器上存储有经过安全认证的POS机数据库;用户通过所述的手持终端下载并安装认证POS机安全性的软 件,然后获取所述的待刷卡的POS机的安全数据信息并传送到所述的系统服务器进行验证,所述的系统服务器验证后将结果返回给用户。
在本发明一实施例中,用户通过所述的手持终端下载并安装所述的认证POS机安全性的软件,并通过通信获取所述待刷卡的POS机的安全数据信息。
在本发明一实施例中,用户通过所述的手持终端下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机回传加密后的安全数据信息,由用户设备读取或扫描所述的安全数据信息。
在本发明一实施例中,用户在系统服务器上提交预设的问题和答案,在与待刷卡POS机的安全数据通信时,同时附上所述预设的问题,经由待刷卡POS机加密后返回手持终端,手持终端将此加密后的数据上传到系统服务器后,系统服务器将判断结果告知用户,同时告知用户预设的答案,如果答案正确,用户自身能够判断该POS是安全的。
在本发明一实施例中,所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。
在本发明一实施例中,所述待刷卡的POS机符合PCI安全规范要求,POS机的安全数据信息保存在POS机的安全区内,非法企图篡改或探测这些安全数据信息的行为都会导致安全数据信息被清除。
本发明能够确认支付终端的安全性,可以保护刷卡人卡相关信息安全,排除刷卡人的疑虑,保护了刷卡人的权利,有利于支付环境改善。
为使本发明的目的、技术方案及优点更加清楚明白,以下将通过具体实施例和相关附图,对本发明作进一步详细说明。
附图说明
图1是本发明电子支付终端验证系统原理框图。
具体实施方式
本发明提供一种电子支付终端验证方法,提供一系统服务器,所述系统服务器上存储有经过安全认证(比如经过PCI认证过)的POS机数据库,并且提供认证POS机安全性的软件下载服务(并且有安全的服务提供,该认证POS机安全性的软件也可以是该系统认可的服务器提供下载);用户下载并安装所述的认 证POS机安全性的软件,然后获取待刷卡的POS机的安全数据信息并传送到所述系统服务器进行验证,所述系统服务器验证后将结果返回给用户。
在本发明一实施例中,用户可以通过智能设备(也可以是平板电脑)下载并安装所述的认证POS机安全性的软件,并通过一种通讯方式(包括有线或无线方式,例如声波、蓝牙、wifi或移动信号等方式)发起验证请求,并接收POS返回的验证信息(安全数据信息)。
在本发明另一实施例中,用户可以通过智能设备(也可以是平板电脑)下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机返回加密后的安全数据信息(例如条码或二维码信息或者一段保护数据的声波),由用户设备读取或扫描所述的安全数据信息。
优选的,所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。
如图1所示,本发明还提供一种电子支付终端验证系统,包括一系统服务器、一手持终端和一待刷卡的POS机,所述的系统服务器上存储有经过安全认证的POS机数据库;用户通过所述的手持终端下载并安装认证POS机安全性的软件,然后获取所述的待刷卡的POS机的安全数据信息(该信息可以是由手持终端向后台系统申请的随机数和POS机上的安全信息经一定算法加密后的安全数据)并传送到所述的系统服务器进行验证,所述的系统服务器验证后将结果返回给用户。所述认证POS机安全性的软件可以是由所述的系统服务器提供下载,也可以是另外的服务器提供下载,但应该是这个系统内的经过认证的服务器。
在本发明一实施例中,用户可以通过所述的手持终端(例如智能手机或平板电脑等)下载并安装所述的认证POS机安全性的软件,并通过某种通讯方式(包括有线或无线方式,例如声波、蓝牙、wifi或移动信号等方式)获取所述待刷卡的POS机的安全数据信息。
在本实施例中,用户A网上购物下单选择货到付款,快递员到了之后,提供POS机给A刷卡。A用自己的智能设备,应用之前在信任的安全系统服务器B提供方下载的认证POS安全性的软件,该软件启动后,智能设备向后台系统申请随机数RND,通过与该POS机通信(蓝牙,wifi,移动信号等方式),获取 POS机上的安全数据(比如蓝牙MAC地址或其他唯一识别代码和刚才的随机数经一定算法后的加密数据),用户智能设备获取后,通过通信渠道,发送回系统服务器B,系统服务器B验证POS机上相关安全数据(可能包括随机数等其他必要信息)后返回用户A的软件界面上,给出结论,安全,或非安全。用户可以借此判断,POS机安全与否。
在本发明另一实施例中,用户可以通过所述的手持终端(例如智能手机或平板电脑等)下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机回传加密后的安全数据信息(例如一段调制了数据的声波、条码或二维码信息),由用户手持终端读取或扫描所述的安全数据信息。
优选的,所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS
机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。另外,用户可以(通过认证POS机安全性的软件)在系统服务器上提交预设的问题和答案,在与待刷卡POS机的通信时,同时附上预设的问题,经由待刷卡POS机通过一定算法加密后的数据传回手持终端,经由手持终端上传到系统服务器后,系统服务器可以将判断结果告知用户,也可以同时告知用户预设的答案,如果答案正确,用户自身可以判断该POS是安全的。
所述待刷卡的POS机符合PCI安全规范要求,POS机的安全数据信息保存在POS机的安全区内,任何非法企图篡改或探测这些安全数据信息的行为都会导致安全数据信息被清除。
本发明能够让刷卡人(用户)通过自己的可以信任的设备(例如智能手机或平板电脑等,),以及通过可以信任的系统服务器提供方(比如,银联,支付宝,或者业内知名支付终端提供商,甚至独立专业安装认证方)提供的应用软件,与刷卡机之间通信,获取刷卡机的必要安全信息,经由刷卡人的设备,发送到系统服务器,验证该支付终端的合法性,并返回刷卡人设备告知结果,如此可以确定该支付终端安全,则可以放心刷卡,否则,拒绝刷卡。
上列较佳实施例,对本发明的目的、技术方案和优点进行了进一步详细说明, 所应理解的是,以上所述仅为本发明的较佳实施例而已,并不用以限制本发明,凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (10)

  1. 一种电子支付终端验证方法,其特征在于:提供一系统服务器,所述系统服务器上存储有经过安全认证的POS机数据库;用户下载并安装认证POS机安全性的软件,然后获取待刷卡的POS机的安全数据信息并传送到所述系统服务器进行验证,所述系统服务器验证后将结果返回给用户。
  2. 根据权利要求1所述的一种电子支付终端验证方法,其特征在于:用户通过智能设备下载并安装所述的认证POS机安全性的软件,并通过通讯获取所述待刷卡的POS机的安全数据信息。
  3. 根据权利要求1所述的一种电子支付终端验证方法,其特征在于:用户通过智能设备下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机回传加密后的安全数据信息,由用户设备读取或扫描所述的安全数据信息。
  4. 根据权利要求1所述的一种电子支付终端验证方法,其特征在于:所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。
  5. 一种根据权利要求1所述的电子支付终端验证方法设计的验证系统,其特征在于:包括一系统服务器、一手持终端和一待刷卡的POS机,所述的系统服务器上存储有经过安全认证的POS机数据库;用户通过所述的手持终端下载并安装认证POS机安全性的软件,然后获取所述的待刷卡的POS机的安全数据信息并传送到所述的系统服务器进行验证,所述的系统服务器验证后将结果返回给用户。
  6. 根据权利要求5所述的一种电子支付终端验证系统,其特征在于:用户通过所述的手持终端下载并安装所述的认证POS机安全性的软件,并通过通讯获取所述待刷卡的POS机的安全数据信息。
  7. 根据权利要求5所述的一种电子支付终端验证系统,其特征在于:用户通过所述的手持终端下载并安装所述的认证POS机安全性的软件,与所述待刷卡的POS机通讯后,所述待刷卡的POS机回传加密后的安全数据信息,由用户读取或扫描所述的安全数据信息。
  8. 根据权利要求5所述的一种电子支付终端验证系统,其特征在于:用户在系统服务器上提交预设的问题和答案,在与待刷卡POS机的安全数据通信时,同时附上所述预设的问题,经由待刷卡POS机加密后返回手持终端,手持终端将此加密后的数据上传到系统服务器后,系统服务器将判断结果告知用户,同时告知用户预设的答案,如果答案正确,用户自身能够判断该POS是安全的。
  9. 根据权利要求5所述的一种电子支付终端验证系统,其特征在于:所述系统服务器将用户传送的安全数据信息在所述经过安全认证的POS机数据库中进行检索对比,判断该待刷卡的POS机是否为经过安全认证的POS机,并将判断结果返回给用户。
  10. 根据权利要求5所述的一种电子支付终端验证系统,其特征在于:所述待刷卡的POS机符合PCI安全规范要求,POS机的安全数据信息保存在POS机的安全区内,非法企图篡改或探测这些安全数据信息的行为都会导致安全数据信息被清除。
PCT/CN2014/095460 2014-01-23 2014-12-30 一种电子支付终端验证方法及系统 WO2015109923A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410030274.5A CN103745353A (zh) 2014-01-23 2014-01-23 一种电子支付终端验证方法及系统
CN201410030274.5 2014-01-23

Publications (1)

Publication Number Publication Date
WO2015109923A1 true WO2015109923A1 (zh) 2015-07-30

Family

ID=50502369

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/095460 WO2015109923A1 (zh) 2014-01-23 2014-12-30 一种电子支付终端验证方法及系统

Country Status (2)

Country Link
CN (1) CN103745353A (zh)
WO (1) WO2015109923A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106886730A (zh) * 2017-01-22 2017-06-23 白长晶 一种基于wifi和摄像头的手机app刷卡系统

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103745353A (zh) * 2014-01-23 2014-04-23 福建联迪商用设备有限公司 一种电子支付终端验证方法及系统
CN105243541A (zh) * 2015-11-13 2016-01-13 广西米付网络技术有限公司 一种ble蓝牙与声波结合的移动支付方法及系统
US11107071B2 (en) 2016-02-01 2021-08-31 Apple Inc. Validating online access to secure device functionality
CN106022769A (zh) * 2016-06-10 2016-10-12 中山市科全软件技术有限公司 一种智能机器人超市的安全支付方法
CN106100854A (zh) * 2016-08-16 2016-11-09 黄朝 基于权威主体的终端设备的逆向认证方法及系统
US10740007B2 (en) 2018-03-06 2020-08-11 International Business Machines Corporation Synchronized primary-secondary role swaps with synchronized safe data commit scans
US10809938B2 (en) * 2018-03-06 2020-10-20 International Business Machines Corporation Synchronized safe data commit scans in multiple data storage systems

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070284433A1 (en) * 2006-06-08 2007-12-13 American Express Travel Related Services Company, Inc. Method, system, and computer program product for customer-level data verification
CN101114399A (zh) * 2007-09-14 2008-01-30 杭州华三通信技术有限公司 一种pos机的管理方法和管理设备
CN102064939A (zh) * 2009-11-13 2011-05-18 福建联迪商用设备有限公司 Pos文件认证的方法及认证证书的维护方法
CN103035081A (zh) * 2011-09-29 2013-04-10 中国移动通信集团公司 一种无线pos机的交易权限验证方法、装置及系统
CN103745353A (zh) * 2014-01-23 2014-04-23 福建联迪商用设备有限公司 一种电子支付终端验证方法及系统

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3816881B2 (ja) * 2003-03-03 2006-08-30 東芝テック株式会社 商品販売データ処理装置の操作権限規定方法、商品販売データ処理装置の操作権限規定システム、商品販売データ処理装置及び商品販売データ処理装置の操作権限規定用プログラム
CN101178822A (zh) * 2007-11-29 2008-05-14 信雅达系统工程股份有限公司 一种支持用户核验银行刷卡终端设备合法性的方法
CN101247618B (zh) * 2008-03-19 2011-04-06 中兴通讯股份有限公司 一种终端合法性检测方法及系统
CN102056169A (zh) * 2009-11-05 2011-05-11 中兴通讯股份有限公司 一种防止非法终端接入的方法、终端及系统
CN102196436B (zh) * 2010-03-11 2014-12-17 华为技术有限公司 安全认证方法、装置及系统
CN102625306A (zh) * 2011-01-31 2012-08-01 电信科学技术研究院 认证方法、系统和设备
CN102622631A (zh) * 2012-02-28 2012-08-01 深圳润鸿鑫数码技术有限公司 一种用于防伪设备的防伪检验装置及防伪方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070284433A1 (en) * 2006-06-08 2007-12-13 American Express Travel Related Services Company, Inc. Method, system, and computer program product for customer-level data verification
CN101114399A (zh) * 2007-09-14 2008-01-30 杭州华三通信技术有限公司 一种pos机的管理方法和管理设备
CN102064939A (zh) * 2009-11-13 2011-05-18 福建联迪商用设备有限公司 Pos文件认证的方法及认证证书的维护方法
CN103035081A (zh) * 2011-09-29 2013-04-10 中国移动通信集团公司 一种无线pos机的交易权限验证方法、装置及系统
CN103745353A (zh) * 2014-01-23 2014-04-23 福建联迪商用设备有限公司 一种电子支付终端验证方法及系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106886730A (zh) * 2017-01-22 2017-06-23 白长晶 一种基于wifi和摄像头的手机app刷卡系统

Also Published As

Publication number Publication date
CN103745353A (zh) 2014-04-23

Similar Documents

Publication Publication Date Title
WO2015109923A1 (zh) 一种电子支付终端验证方法及系统
TWI667585B (zh) 一種基於生物特徵的安全認證方法及裝置
KR101617569B1 (ko) 허브 앤드 스포크 핀 검증
AU2018214800B2 (en) Methods and systems for securely storing sensitive data on smart cards
US11972428B2 (en) Information transmission method, apparatus and system
AU2012303620B2 (en) System and method for secure transaction process via mobile device
JP5805790B2 (ja) 個人情報盗難防止及び情報セキュリティシステムプロセス
CN104285229B (zh) 经由嵌入式控制器增强系统的传感器数据的安全性
US9876786B2 (en) Method for verifying security data, system, and a computer-readable storage device
JP2014512579A5 (zh)
KR20120108599A (ko) 온라인 신용카드 결제 단말기를 활용한 신용카드 결제 서비스
US20160027011A1 (en) Transaction terminal device, transaction processing method, and transaction processing system
KR101607935B1 (ko) 지문인식을 이용한 모바일 지불 시스템 및 그 방법
KR101542111B1 (ko) 카드를 이용한 결제방법, 이를 위한 디지털 시스템, 및 결제측 시스템
KR101545129B1 (ko) 전자결제 시스템 및 방법
KR101550825B1 (ko) 무선단말을 이용한 카드 결제방법
CN106156549B (zh) 应用程序授权处理方法及装置
KR102122555B1 (ko) 사용자가 소지한 금융 카드 기반 본인 인증 시스템 및 방법
KR102348823B1 (ko) 사용자가 소지한 금융 카드 기반 본인 인증 시스템 및 방법
US11663584B2 (en) System and method for indicating entry of personal identification number
KR101768318B1 (ko) 본인 인증 방법, 장치 및 컴퓨터 프로그램
KR101502377B1 (ko) 등록된 보안카드를 이용한 인증 기능을 가지는 이동통신단말기, 상기 이동통신단말기를 이용한 지불 결제 인증 시스템 및 방법
KR20090132818A (ko) 유에스비 토큰과 지문을 이용한 이중 보안 시스템
JP2006215699A (ja) 認証装置、認証システム、認証支援システム、及び機能カード
JP2006293473A (ja) 認証システム及び認証方法、端末装置及び認証装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14879961

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14879961

Country of ref document: EP

Kind code of ref document: A1