WO2016048255A1 - Platform for payment with digital wallet over internet - Google Patents
Platform for payment with digital wallet over internet Download PDFInfo
- Publication number
- WO2016048255A1 WO2016048255A1 PCT/TR2015/000324 TR2015000324W WO2016048255A1 WO 2016048255 A1 WO2016048255 A1 WO 2016048255A1 TR 2015000324 W TR2015000324 W TR 2015000324W WO 2016048255 A1 WO2016048255 A1 WO 2016048255A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- establishment
- digital wallet
- user
- card
- password
- Prior art date
Links
- 241000542904 Posidoniaceae Species 0.000 claims abstract 5
- 238000000034 methods Methods 0.000 claims description 9
- 101710073617 CVC2 Proteins 0.000 claims description 3
- 230000003213 activating Effects 0.000 claims 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING; COUNTING
- G06Q—DATA PROCESSING SYSTEMS OR METHODS, SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL, SUPERVISORY OR FORECASTING PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL, SUPERVISORY OR FORECASTING PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
Abstract
Description
DESCRIPTION
Platform for Payment with Digital Wallet over Internet
Technical Field
The invention relates to a method which allows users to create a digital wallet over internet. The method comprises identification of any number of credit cards owned by users to their digital wallets and conduct practical and safe transaction while shopping from an establishment without giving card information again and again to the establishment by selecting one of the cards predefined on the electronic wallet.
State of the Art
In other applications similar to the digital wallet, in order to create a digital wallet, the user has to sign up to the system with user name and password and after that card must be identified by entering all important card information to the system. The important information required include complete card number, the validity date of the card and the last three digits of the numbers on the backside of the card (CW2/CVC2). In such wallet applications, all of the important card information are kept on the system and during shopping they are retrieved from the database with inquiry and utilized. As all of the card information are acquired from the users over internet, even though they are acquired for once only, there may be various attacks and the card information can be stolen or used without the knowledge of the card owner. It is seen that this type of fraud is on the rise in recent years.
Object of the Invention
The invention is a method for creating a safe and practical digital wallet, wherein the disadvantages of the state of the art are eliminated by not asking complete card information to the user any time. Another object of the invention is to prevent the establishment from knowing the complete card information and thus, eliminate the risks that may rise from this.
With the invention, apart from some information asked from the user, storing any important information on the database and recording said data are prevented.
Another object of the invention is to request a "single use password" from the card owner in addition to user name and password in card identification and shopping steps while receiving shopping details or identifying a new card, and thus, to increase the transaction security by confirming the identity of the card owner. This method also distinguishes the invention from the state of the art.
Another object of the invention is to further increase the safety of transaction by means of signing (Express Signature: ExpSign) the transactions being conducted with digital methods using the keys previously shared with said card issuing corporations through secure methods in a way to allow confirmation of related transaction by card issuing corporation owning the card via transferring the signature (ExpSign), even if there is a POS owned by the corporation which signed member establishment agreement different from the card issuing corporation therebetween, while transferring conducted transactions to the systems of said corporations for authorization.
Another object of the invention is to increase process security by providing both the confirmation of the establishment messages and the confirmation of the messages received from the digital wallet by the establishment. Messages can be confirmed by both the establishment and the digital wallet in terms of both the integrity of the message content and the validity of the message. This way, attackers that may get in between the messages are prevented from tricking the establishment or the system by altering the message content or by reusing a valid but old message. Besides, provided that the establishment secures its own key, ill-intentioned people are prevented from sending transactions to the digital wallet by acting as said establishment. For this purpose, the establishment places digital signatures calculated by the cryptographic key specific to its own into all the messages. Likewise, the messages transmitted to the establishment by the digital wallet also contain digital signature.
The method and system used for realizing the invention is shown in the figures. Description of the Figures
Fig. 1: Shopping Flow Chart
Fig. 2: Money Transfer Flow
Fig. 3: System Topography
The elements in the figures are numbered and their explanations are shown below. Description of the Reference Numbers
References
1- Establishment Payment Media
2- Member Establishment
3- The Corporation Which Signed Member Establishment Agreement and Which Works With The Establishment
4- Card Owning/Card Issuing Corporation
5- Digital Wallet
6- Digital Wallet Receiving Section
7- Confirmation Input Media
8- Establishment Digital Wallet Service
9- Digital Wallet Integration Unit
10- POS (Point of Sale)
11- Establishment Result Service
12- Sending Establishment
13- Receiving Establishment
14- Authorization Infrastructure
15- User Detailed Description of the Reference List and the Invention
The invention is a digital wallet (5) which is an overall of systems providing fast, easy and secure payment for the users (15) while shopping.
It comprises the process steps of creating the digital wallet (5), signing up of the user (15), and identification of current credit cards, bank cards or any type of cards to the digital wallet (5), even if they are issued by different Card Issuing Corporations, for future or current uses.
Using the digital wallet (5) comprises also the establishment (2) where the products and services are sold for the purchase of the users (15), establishment payment media (1) belonging to the establishment to which the user (15) will make payment after deciding the products he or she will purchase, the corporation (3) which signed the member establishment agreement and which works with the member establishment (2) providing real/virtual POS (10) to the establishments as a result of the agreement to the establishments to allow them receive payment with cards, and the card issuing corporation (4) which supplies the payment card of the user.
This digital wallet method comprises the digital receiving section (6) which stores a part of the card information of the users (15) to be used in payment and money transaction and which receives the information regarding special offers, installment etc. transmitted to the digital wallet (5) by the relevant establishment (2) at the moment of the use of digital wallet; and the digital wallet confirmation input media (7) through which the user (15) enters the confirmation information to the digital wallet (5) in order to sign in.
It comprises the establishment digital wallet service (8) through which the establishment (2) transmits to the digital wallet (5) the selection regarding which POS (10) will the transaction be transmitted to (if there are more than one POS); and digital wallet integration unit (9) which provides integration of the digital wallet (5) with the external systems (messaging with Establishments and Payment Systems). The establishment result service (1 1 ), to which the result of the financial transaction received from the establishment (2) POS (10) by the digital wallet (5) by means of the POS (10) device or system provided by the corporation (3) which signed the member establishment agreement with which the establishment (2) works in order to be able to receive payment with card, is transmitted for displaying to the user (15), operates integrated with the establishment (12) sending money over the digital wallet (5), with the establishment (13) to which the money is sent over the digital wallet (5), and with the authorization and direction (switch) infrastructure (14), which provides transmitting credit/bank card transactions to the relevant establishment by the BKM (Interbank Card Center).
Creating the Digital Wallet
The user (15) creates an account for himself/herself on the secure website of the digital wallet (5).
While creating the account, the user enters e-mail address and other required information. The user designates the fixed password to access the digital wallet (5).
The Flow for Adding a New Card to the Digital Wallet
Not all of the card information are requested while adding cards to the digital wallet (5). This method distinguishes the invention from other techniques in the state of the art. The user (15) logs in to the digital wallet (5) with the user name (e-mail address) and the password.
The user (15) enters ID number, the first six and last four digits of the card number and the last three digits of the number on the backside of the card (CW2/CVC2). Digital wallet (5) transmits related card information to the card issuing corporation owning the card (4) and a single use password is transmitted to the phone number of the user which is registered to the card issuing corporation (5). The user enters the password on the digital wallet (5) display.
The digital wallet (5) confirms the password with the confirmation input media (7) and generates a limited amount of single use password if the password is wrong. If the password is correct, the card is added to the electronic wallet of the user.
Shopping Flow Chart
The user (15) enters the website of the member establishment (2) from which he or she will shop.
Upon completing the shopping and reaching payment step, the user select payment with "Digital Wallet" (5) option.
The user (15) logs in with the user name (e-mail address) and predefined the password. The cards previously added to the digital wallet (5) by the user (1 ) and the installments (if any) applied for these cards by the establishment (2) are displayed. Optionally, the user (15) can add a new card during shopping.
The user (15) selects the card from which the payment will be made.
A single use password is sent to the user (15) by the card issuing corporation (4).
The user (15) enters the single use password he or she receives on the display.
If the password is correct, transaction confirmation is received from the digital wallet (5) through POS (10) and afterwards, the user (15) is redirected to the website of the establishment (2) and sees the transaction result.
Detailed Description of the Shopping Flow
The user (15) enters the website of the member establishment (2) from which he or she will shop.
Upon completing the shopping and reaching payment (1) step, the user select payment with "Digital wallet" (5) option. The establishment (2) transmits information such as special offers and installment to the digital wallet (5) online through digital wallet receiving unit (6). Digital wallet (5) transmits the establishment (2) a token stating the transaction.
Establishment (2) directs the user (15) to the digital wallet (5) confirmation input media (7) with this token.
The user (15) logs in to the digital wallet (5) with his/her e-mail address and predefined the password.
The cards previously added to the digital wallet (5) by the user (15) and the installments (if any) applied for these cards by the establishment (2) and card points (if any) are displayed. Optionally, the user (15) can add a new card during shopping. The user (15) selects the card to be used for payment.
Digital wallet (5) summarizes the transaction details on the display for confirmation and requests the single use password. A single use password is transmitted to the phone number registered for related card by the card owning/card issuing corporation (4). The user (15) enters the single use password on the digital wallet (5) display.
In accordance with the selection and by means of the digital wallet (5) risk management feature, the current transaction information and predefined information such as transaction amount, transactions made by the user in a specific period, the establishment (2) on which the transaction is made, and if the user has a main card identified for said establishment (2); and in some suitable transactions one, few or all of the abovementioned steps can be skipped;
logging in to the digital wallet (5) with the user name (e-mail address) and the password by the user,
selecting the cards previously added to the digital wallet (5) by the user (15) and the installments (if any) applied for these cards by the establishment (2) and card points (if any), summarizing the transaction details on the display for confirmation and requesting the single use password by the digital wallet (5).
Digital wallet (5) checks the password with the confirmation input media (7). If the password is incorrect, the single use password can be sent again. If the password is correct, the POS (10) selection of the establishment (2) is requested from the establishment digital wallet service (8) through the integration unit (9) with an online message. Establishment (2) digital wallet service (8) transmits to the integration unit (9) in the reply message the POS (10) information.
The digital wallet calculates the digital signature (Expsign) of the transaction and requests financial confirmation of the transaction via POS (10) through the integration unit (9). POS (10) transmits the financial confirmation result to the digital wallet (5). The digital wallet (5) transmits the POS (10) transaction result to the establishment (2) via establishment result service (11). The user (15) and the result of the POS (10) transaction result are directed back to the establishment (2) through the establishment result service (11).
If the the transaction is successful, the establishment (2) displays the success screen and continues its internal processes such as delivery of the product, billing and e-mail notification. Money Transfer Flow
The user (15) logs in to the mobile application of the digital wallet (5) with the user name (e-mail) and the password and selects Money Transfer option. The user enters the phone number and card information of the recepient.
Digital wallet (5) checks the mobile phone information of the recipient, if the recipient is a registered user (5), the option for money transfer with mobile phone information is displayed as active. In the cases the sending establishment supports, money transfer from the users (15) to unregistered recipients through an ATM is provided as an option by the digital wallet (5).
Digital wallet (5) receives explanation and amount information regarding the money transfer from the user (15). If the recipient is a registered user, the digital wallet (5) requests recipient card information from the receiving establishment (13).
The receiving establishment (13) transmits recipient card information to the digital wallet (5). Digital wallet (5) transmits information regarding the sender and the recipient to the sending establishment.
The sending establishment (13) gets in contact with the receiving establishment (13) through the BKM (Interbank Card Center) authorization and direction (switch) infrastructure; receives the first two letters of the name and last name of the user (15) and transmits the information to the digital wallet (5) together with the commission amount determined by the sending establishment (12).
The digital wallet (5) displays on the screen the recipient and commission information to the user (15) for confirmation. After the user (15) confirms the details, the sending establishment (12) transmits a single use password to the mobile phone of the user (15) confirmed for the related card.
The user enters the password on the digital wallet (5) display, if the password is incorrect, it can be sent again for a limited number of time. If the password is correct, digital wallet (5) transmits the confirmation of the user to the sending establishment (12).
The sending establishment (12) gets in contact with the receiving establishment (13) through the BKM (Interbank Card Center) authorization and direction (switch) infrastructure; transmits that the transaction is confirmed by the user (15); the receiving establishment (13) confirms receiving the confirmation via the authorization infrastructure; and the sending establishment (12) transmits the confirmation to the digital wallet (5). After the reply messages of the establishments, the transaction result is displayed to the user (15) on the screen by the digital wallet (5).
Claims
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TR2014/11400 | 2014-09-26 | ||
TR201411400 | 2014-09-26 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2016048255A1 true WO2016048255A1 (en) | 2016-03-31 |
Family
ID=54780451
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/TR2015/000324 WO2016048255A1 (en) | 2014-09-26 | 2015-09-23 | Platform for payment with digital wallet over internet |
Country Status (1)
Country | Link |
---|---|
WO (1) | WO2016048255A1 (en) |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20130054336A1 (en) * | 2011-04-05 | 2013-02-28 | Roam Data Inc | System and method for incorporating one-time tokens, coupons, and reward systems into merchant point of sale checkout systems |
US20130179337A1 (en) * | 2012-01-09 | 2013-07-11 | Walter Ochynski | Account free possession and transfer of electronic money |
-
2015
- 2015-09-23 WO PCT/TR2015/000324 patent/WO2016048255A1/en active Application Filing
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20130054336A1 (en) * | 2011-04-05 | 2013-02-28 | Roam Data Inc | System and method for incorporating one-time tokens, coupons, and reward systems into merchant point of sale checkout systems |
US20130179337A1 (en) * | 2012-01-09 | 2013-07-11 | Walter Ochynski | Account free possession and transfer of electronic money |
Non-Patent Citations (1)
Title |
---|
None |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10692076B2 (en) | Device pairing via trusted intermediary | |
US20180268404A1 (en) | Remote variable authentication processing | |
US20180114210A1 (en) | Secure payments with untrusted devices | |
JP6214724B2 (en) | Method, apparatus and system for secure provisioning, transmission and authentication of payment data | |
RU2713703C2 (en) | Advance authorization of digital requests | |
US10049357B2 (en) | System and method of processing PIN-based payment transactions via mobile devices | |
US20190102776A1 (en) | Methods and systems for using physical payment cards in secure e-commerce transactions | |
US20190325405A1 (en) | System and method for rendering virtual currency related services | |
US9818099B2 (en) | Self-authenticating peer to peer transaction | |
US20180255460A1 (en) | Device enrollment system and method | |
US20200090182A1 (en) | Authenticating remote transactions using a mobile device | |
US10078835B2 (en) | Authentication token for wallet based transactions | |
US20180130033A1 (en) | Acquisition of card information to enhance user experience | |
AU2017200988B2 (en) | Payment device with integrated chip | |
US10037516B2 (en) | Secure transactions using a point of sale device | |
US8874913B1 (en) | Secure communications between devices using a trusted server | |
US9361619B2 (en) | Secure and convenient mobile authentication techniques | |
US10592899B2 (en) | Master applet for secure remote payment processing | |
KR101617569B1 (en) | Hub and spokes pin verification | |
US8788389B1 (en) | Methods and systems for providing a customer controlled account lock feature | |
US20180006821A1 (en) | Token and cryptogram using transaction specific information | |
US20170039566A1 (en) | Method and system for secured processing of a credit card | |
US20140337237A1 (en) | System and method for authenticating a payment terminal | |
CN103765861B (en) | The payment of mobile device selects and authorizes | |
US20170140379A1 (en) | Credit card randomly generated pin |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15804636 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase in: |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 15804636 Country of ref document: EP Kind code of ref document: A1 |