WO2016109997A1 - 移动支付信息的保护方法、装置及移动支付系统 - Google Patents

移动支付信息的保护方法、装置及移动支付系统 Download PDF

Info

Publication number
WO2016109997A1
WO2016109997A1 PCT/CN2015/072011 CN2015072011W WO2016109997A1 WO 2016109997 A1 WO2016109997 A1 WO 2016109997A1 CN 2015072011 W CN2015072011 W CN 2015072011W WO 2016109997 A1 WO2016109997 A1 WO 2016109997A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
payment
payment account
code information
account information
Prior art date
Application number
PCT/CN2015/072011
Other languages
English (en)
French (fr)
Inventor
钟焰涛
傅文治
Original Assignee
宇龙计算机通信科技(深圳)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 宇龙计算机通信科技(深圳)有限公司 filed Critical 宇龙计算机通信科技(深圳)有限公司
Priority to EP15876505.7A priority Critical patent/EP3244359A4/en
Publication of WO2016109997A1 publication Critical patent/WO2016109997A1/zh
Priority to US15/490,845 priority patent/US20170221044A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/02Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP]
    • G06Q20/027Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP] involving a payment switch or gateway
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes

Definitions

  • the present invention relates to the field of information security technologies, and in particular, to a method and device for protecting mobile payment information and a mobile payment system.
  • Mobile payment refers to a service mode that allows mobile users to use their mobile terminals (such as mobile phones) to pay for goods or services they consume.
  • the specific process is briefly described as follows: the payment account information (generally the bank card number) is sent to the payment terminal by the mobile terminal, and the payment terminal sends the mobile payment information to the card merchant server, and the card merchant server completes the payment according to the mobile payment information.
  • the mobile payment information includes payment account information, payment amount information, and the like.
  • the mobile payment method brings convenience to people's lives, there are also problems that the user's private information is easily leaked.
  • the mobile payment information can collect the user's payment account information, and the user's mobile payment information can be used for the user. Analysis of purchase habits and lifestyle information for analysis and statistics, resulting in the disclosure of user privacy information. Therefore, there is an urgent need for a method that can protect mobile payment information in a mobile payment process.
  • the present invention provides a method, an apparatus, and a mobile payment system for protecting mobile payment information, so as to solve the problem that the existing private information in the mobile payment process is easily leaked.
  • a method for protecting mobile payment information comprising:
  • the card merchant server dynamically updates the replacement code information corresponding to each stored payment account information
  • the card merchant server After updating the replacement code information corresponding to each stored payment account information, the card merchant server updates the mapping relationship between the payment account information and the replacement code information stored in the card merchant server according to the updated replacement code information;
  • the card merchant server After updating the replacement code information corresponding to each stored payment account information, the card merchant server sends the updated replacement code information and the corresponding payment account information to the mobile terminal, so that the mobile terminal is updated.
  • the substitute code information is used for mobile payment.
  • the mobile terminal performing the mobile payment by using the updated substitute code information specifically includes:
  • the mobile terminal sends the updated replacement code information to the payment terminal;
  • the payment terminal After receiving the updated substitute code information, the payment terminal sends the mobile payment information to the card merchant server, where the mobile payment information includes the updated substitute code information and payment amount information;
  • the card merchant server searches for a mapping relationship between the stored payment account information and the replacement code information, finds the payment account information corresponding to the updated replacement code information, and passes the found payment account information and the payment amount information.
  • the card merchant payment gateway sends the card issuing bank system to enable the card issuing bank system to perform payment processing according to the found payment account information and the payment amount information.
  • the replacement code information corresponding to each payment account information that is dynamically updated and stored by the card merchant server includes:
  • the card merchant server periodically updates the substitute code information corresponding to each stored payment account information according to the update period.
  • the replacement code information corresponding to each payment account information that is dynamically updated and stored by the card merchant server includes:
  • the card merchant server receives a substitute code update request sent by the mobile terminal, where the substitute code update request includes payment account information;
  • the card merchant server updates the substitute code information corresponding to the payment account information in the substitute code update request.
  • a protection device for mobile payment information comprising:
  • a first update unit configured to dynamically update the replacement code information corresponding to each payment account information stored in the card vendor server
  • a second update unit configured to correspond to each payment account information stored in each update card vendor server After the replacement code information, updating the mapping relationship between the payment account information and the replacement code information stored in the card merchant server according to the updated replacement code information;
  • the replacement code synchronization unit is configured to send the updated replacement code information and the corresponding payment account information to the mobile terminal after each replacement of the replacement code information corresponding to each payment account information stored in the card vendor server, so that The mobile terminal performs mobile payment with the updated substitute code information.
  • the device further comprises:
  • a mobile payment information receiving unit configured to receive mobile payment information sent by the payment terminal, where the mobile payment information includes payment amount information and the updated replacement code information sent by the mobile terminal to the payment terminal;
  • a search unit configured to search for a mapping relationship between the payment account information and the replacement code information stored in the card merchant server, find the payment account information corresponding to the updated replacement code information, and find the found payment account information
  • the payment amount information is sent to the card issuing bank system through the card merchant payment gateway, so that the card issuing bank system performs payment processing according to the found payment account information and the payment amount information.
  • the first update unit comprises:
  • An update cycle setting module for setting an update cycle
  • the first update module is configured to periodically update the substitute code information corresponding to each payment account information stored in the card merchant server according to the update period.
  • the first update unit comprises:
  • An update request receiving module configured to receive a substitute code update request sent by the mobile terminal, where the substitute code update request includes payment account information
  • a second update module configured to update the replacement code information corresponding to the payment account information in the substitute code update request.
  • a mobile payment system comprising: a mobile terminal, a payment terminal, a card merchant server, and a card issuing bank system that communicates with the card merchant server through a card merchant payment gateway, where the card merchant server comprises:
  • a first update unit configured to dynamically update the replacement code information corresponding to each payment account information stored in the card vendor server
  • a second updating unit configured to update the payment account information and the replacement code stored in the card merchant server according to the updated replacement code information after updating the replacement code information corresponding to each payment account information stored in the card vendor server Mapping relationship between information;
  • the replacement code synchronization unit is configured to send the updated replacement code information and the corresponding payment account information to the mobile terminal after each replacement of the replacement code information corresponding to each payment account information stored in the card vendor server, so that The mobile terminal performs mobile payment with the updated substitute code information.
  • the card merchant server further includes:
  • a mobile payment information receiving unit configured to receive mobile payment information sent by the payment terminal, where the mobile payment information includes payment amount information and the updated replacement code information sent by the mobile terminal to the payment terminal;
  • a search unit configured to search for a mapping relationship between the payment account information and the replacement code information stored in the card merchant server, find the payment account information corresponding to the updated replacement code information, and find the found payment account information
  • the payment amount information is sent to the card issuing bank system through the card merchant payment gateway, so that the card issuing bank system performs payment processing according to the found payment account information and the payment amount information.
  • the invention dynamically updates the substitute code information corresponding to the payment account information by the card merchant server, and the card merchant server sends the updated substitute code information to the update code information corresponding to the payment account information every time.
  • the mobile terminal uses the updated substitute code information to perform mobile payment, thereby avoiding the leakage of the mobile payment information in the mobile payment process and protecting the user's private data.
  • FIG. 1 is a schematic structural diagram of a mobile payment system according to an embodiment of the present invention.
  • FIG. 2 is a flowchart of implementing a method for protecting mobile payment information according to an embodiment of the present invention
  • FIG. 3 is a flowchart of an implementation of step S201 in FIG. 2 according to an embodiment of the present disclosure
  • FIG. 4 is a flowchart of an implementation of step S201 in FIG. 2 according to another embodiment of the present invention.
  • FIG. 5 is a flowchart of implementing mobile payment by a mobile terminal with updated replacement code information according to an embodiment of the present disclosure
  • FIG. 6 is a flowchart of implementing mobile payment by a mobile terminal with updated replacement code information according to another embodiment of the present invention.
  • FIG. 7 is a flowchart of implementing a method for protecting mobile payment information according to another embodiment of the present invention.
  • FIG. 8 is a structural block diagram of a device for protecting mobile payment information according to an embodiment of the present invention.
  • FIG. 9 is a structural block diagram of a device for protecting mobile payment information according to another embodiment of the present invention.
  • FIG. 1 is a structural diagram of a mobile payment system according to an embodiment of the present invention.
  • the mobile payment system includes a mobile terminal 1, a payment terminal 2 that can communicate with the mobile terminal 1, a card merchant server 3 that can communicate with the mobile terminal 1, the payment terminal 2, and a payment provider gateway 4 with the card merchant server 3
  • the issuing bank system 5 that communicates. among them:
  • the mobile terminal 1 and the payment terminal 2 can communicate through various short-range communication methods, such as a short-range communication method including but not limited to Near Field Communication (NFC).
  • NFC Near Field Communication
  • the mobile terminal 1 and the payment terminal 2 are both NFC-enabled devices.
  • the mobile terminal 1 and the payment terminal 2 both include an NFC communication module, such as an NFC chip. Wait.
  • the mobile terminal 1 can be a mobile phone or the like.
  • the payment terminal 2 is a device that can communicate with the mobile terminal 1 and can scan the payment target information, such as a POS machine or the like.
  • the payment target refers to the subject matter that the user needs to make payment, such as the product or service that needs to be paid. After the payment terminal 2 scans the payment target, the payment amount information can be calculated based on the scanned information of the payment target.
  • the mobile terminal 1 and the card merchant server 3 can communicate via a mobile network (for example, 3G, 4G, etc.) or a wireless network (for example, WIFI or the like).
  • a mobile network for example, 3G, 4G, etc.
  • a wireless network for example, WIFI or the like.
  • the mobile network communicates.
  • the payment terminal 2 scans the payment target information by the merchant, and calculates the payment amount information according to the payment target information, the user approaches the mobile terminal 1 to the payment terminal 2, and inputs the mobile terminal 1 in the mobile terminal 1. Paying for the verification information, the mobile terminal 1 verifies the input payment verification information, and after the verification is passed, transmits the updated replacement code information to the payment terminal 2 by the NFC communication method, and the payment terminal 2 receives the transmission from the mobile terminal 1. After the updated substitute code information, the mobile payment information is sent to the card merchant server 3, and after receiving the mobile payment information, the card merchant server 3 extracts the updated substitute code information in the mobile payment information, and extracts the card from the card.
  • the card merchant server 3 is a server set up by the card manufacturer; the card merchant payment gateway 4 is an interface between the bank system and the network, and is set up by the bank to convert the data transmitted on the network into the bank internal data. Server; the card issuing bank system 5 is another server set up by the bank.
  • the card merchant payment gateway 4 communicates with the card merchant server 3 and the card issuing bank system 5 via a network connection, respectively.
  • FIG. 2 is a flowchart showing an implementation process of a method for protecting mobile payment information according to an embodiment of the present invention, which is described in detail as follows:
  • the card merchant server dynamically updates the replacement code information corresponding to each stored payment account information.
  • the payment account information refers to the information of the payment account used in the mobile payment process, for example, the payment account information may be a bank card number or the like.
  • the substitute code information refers to a substitute code for the payment account information in the mobile payment process generated by the card merchant server for the payment account information in one-to-one correspondence with the payment account information.
  • each payment account needs to be registered in the card merchant server.
  • the specific process of registering the payment account in the card merchant server is as follows:
  • the card merchant server receives a payment account registration request sent by the mobile terminal, where the payment account registration request includes payment account information.
  • the payment account when an account (such as a bank card) needs to be used for mobile payment, the payment account needs to be registered in the card merchant server.
  • an account such as a bank card
  • the mobile terminal provides a human-computer interaction interface, so that the user inputs the payment account information that needs to be registered in the human-computer interaction interface and inputs a payment account registration request, and the mobile terminal receives the payment account information and the payment account registration input by the user. After the request, a payment account registration request including the payment account information is sent to the card merchant server.
  • the card merchant server randomly generates a corresponding substitute code information for the payment account information in the payment account registration request, and stores a mapping between the payment account information in the payment account registration request and the generated substitute code information in the card merchant server. relationship.
  • the card merchant server randomly generates a correspondence for the payment account information in the payment account registration request by using a preset random generation algorithm.
  • Alternative code information may be any one of the prior art algorithms, including but not limited to various encryption algorithms.
  • the mapping relationship between the payment account information in the payment account registration request and the generated substitute code information is established and stored.
  • the mapping relationship between the payment account information and the replacement code information is a one-to-one correspondence.
  • the card merchant server may use various storage methods to store the mapping relationship between the payment account information and the replacement code information, such as the manner of using a database table.
  • various storage methods to store the mapping relationship between the payment account information and the replacement code information, such as the manner of using a database table.
  • the examples are as follows:
  • the replacement code information generated by the card merchant server for the payment account 1 is aaa; when the payment account in the payment account registration request is the payment account 2, if the card merchant server
  • the substitute code information generated for the payment account 2 is bbb, and Table 1 shows an example of the mapping relationship between the payment account information and the replacement code information stored in the manner of the database table, but between the payment account information and the replacement code information.
  • the mapping relationship is not limited to the examples shown in the table.
  • the card merchant server sends the generated substitute code information and the corresponding payment account information to the mobile terminal, so that the mobile terminal stores the mapping relationship between the payment account information and the generated substitute code information.
  • the card dealer server in order to enable the mobile terminal to complete the mobile payment by using the substitute code information instead of the payment account information, the card dealer server generates the substitute code after generating the substitute code information for the payment account information in the payment account registration request.
  • the information and the corresponding payment account information are transmitted to the mobile terminal, and the mobile terminal stores a mapping relationship between the payment account information and the generated substitute code information.
  • the card merchant server After the payment account information is registered in the card merchant server by the mobile terminal, the card merchant server stores the payment account information sent by the mobile terminal, and can dynamically update the replacement code information corresponding to the stored payment account information.
  • the specific process of the card vendor server dynamically updating the replacement code information corresponding to each stored account information is shown in FIG. 3 and FIG. 4 , and details are not described herein again.
  • the card merchant server updates the replacement code information corresponding to each stored payment account information each time. Then, the mapping relationship between the payment account information stored in the card merchant server and the replacement code information is updated according to the updated replacement code information.
  • the card merchant server stores the mapping relationship between the payment account information and the replacement code information, as shown in Table 1 above.
  • the card merchant server updates the replacement code information corresponding to each stored payment account information
  • the updated substitute code information is found from the mapping relationship between the stored payment account information and the replacement code information.
  • the examples are as follows:
  • mapping relationship between the payment account information and the replacement code information stored in the card merchant server is as shown in Table 1. If the card merchant server updates its stored replacement account information aaa of the payment account 1 to a1a1a1, the stored payment is stored. After the replacement code information bbb of the account 2 is updated to b1b1b1, the card merchant server updates the mapping relationship between the payment account information and the replacement code information stored in the card vendor server according to the updated replacement code information, and then obtains the relationship shown in Table 2. The mapping relationship between the payment account information and the replacement code information.
  • Payment account information Alternate code information Payment account 1 A1a1a1 Payment account 2 B1b1b1 ?? ...
  • the card merchant server After updating the replacement code information corresponding to each stored payment account information, the card merchant server sends the updated replacement code information and the corresponding payment account information to the mobile terminal, so that the mobile terminal replaces the mobile terminal with the updated Code information for mobile payments.
  • the card merchant server sends the updated replacement code information and the corresponding payment account information to the mobile terminal.
  • the mobile terminal receives the updated replacement code information and the corresponding payment account information sent by the card merchant server, the mobile terminal searches for the information sent by the card merchant server from the mapping relationship between the payment account information and the replacement code information stored in the mobile terminal.
  • the account information is paid, and the substitute code information of the found payment account information is replaced with the updated substitute code information to implement updating of the mapping relationship between the payment account information and the substitute code information stored in the mobile terminal.
  • the mobile terminal After completing the update of the mapping relationship between the stored payment account information and the replacement code information, the mobile terminal uses the updated replacement code information for subsequent mobile payment.
  • steps S202 and S203 may be sequentially performed in the order shown in FIG. 2, or may be performed in parallel, or the execution order of steps S202 and S203 in FIG. 2 may be reversed, which is not limited herein.
  • the replacement code information corresponding to the payment account information is dynamically updated by the card merchant server, and the card merchant server updates the replacement code information corresponding to the payment account information every time.
  • the code information is sent to the mobile terminal, and after receiving the updated substitute code information, the mobile terminal uses the updated substitute code information to perform mobile payment, thereby avoiding the leakage of the mobile payment information in the mobile payment process, and protecting the user's Privacy data.
  • FIG. 3 shows a specific implementation flow of S201 in FIG. 2 according to an embodiment of the present invention, which is described in detail as follows:
  • the card merchant server sets an update period of the replacement code information.
  • the card merchant server may set a unified update period for the substitute code information corresponding to all the payment account information stored therein, or set different update periods for different payment account information, and may also classify the payment account information.
  • the update period is set for each payment account information classification. It can be understood that the specific manner of setting the update period may also be other manners, which will not be exemplified herein.
  • the card merchant server periodically updates the replacement code information corresponding to each stored payment account information according to the update period.
  • the card merchant server updates the replacement code information each time the update period set for each substitute code information is reached.
  • the specific process of updating the substitute code information may be: re-generating the substitute code information for the payment account information by using the preset random generation algorithm, and using the regenerated substitute code information as the updated substitute code corresponding to the payment account information. information.
  • the replacement code information corresponding to each payment account information can be periodically updated.
  • FIG. 4 shows a specific implementation flow of S201 in FIG. 2 according to another embodiment of the present invention, which is described in detail as follows:
  • the card merchant server receives a substitute code update request sent by the mobile terminal, where the substitute code update request includes payment account information.
  • the mobile terminal when the user using the mobile payment wants to update the substitute code information corresponding to the payment account information, the mobile terminal sends a substitute code update request to the card merchant server, and includes the need to perform the substitute code update request.
  • the replacement account information is updated with the payment account information.
  • the card merchant server updates the substitute code information corresponding to the payment account information in the substitute code update request.
  • the card merchant server after receiving the mobile terminal sending the substitute code update request, the card merchant server re-generates the substitute code information for the payment account information in the substitute code update request by using the preset random generation algorithm, and the The generated substitute code information is used as the updated substitute code information corresponding to the payment account information in the substitute code update request.
  • the card merchant server may update the substitute code information corresponding to the payment account information, thereby being more flexible.
  • FIG. 5 is a schematic diagram of a specific process for a mobile terminal to perform mobile payment with updated replacement code information according to an embodiment of the present invention, which is described in detail as follows:
  • the mobile terminal sends the updated replacement code information to the payment terminal.
  • the mobile terminal may send the updated replacement code information to the payment terminal by using NFC communication. It can be understood that the mobile terminal can also send the updated replacement code information to the payment terminal by using other short-distance communication methods, which is not limited herein.
  • the payment terminal (such as a POS machine) provided by the merchant may first scan the payment target information, and after calculating the payment amount information according to the payment target information, the user approaches the mobile terminal.
  • the payment terminal inputs the payment verification information in the mobile terminal, and the mobile terminal verifies the input payment verification information, and after the verification is passed, sends the updated replacement code information to the payment terminal by using the NFC communication method.
  • the payment verification information may be fingerprint information or the like.
  • the mobile terminal compares the fingerprint information input by the user with the legal fingerprint information stored in the mobile terminal. If the comparison result is a match, the payment verification information is verified, otherwise the verification fails.
  • the legal execution information refers to fingerprint information used for verification by the user in advance in the mobile terminal.
  • the payment terminal After receiving the updated replacement code information sent by the mobile terminal, the payment terminal sends the mobile payment information to the card merchant server.
  • the mobile payment information includes updated replacement code information and payment amount information.
  • the payment terminal After receiving the updated replacement code information sent by the mobile terminal, the payment terminal obtains the payment amount information calculated according to the scanned payment target information, and combines the payment amount information and the updated replacement code information into The mobile payment information is sent to the card merchant server.
  • the card merchant server searches for a mapping relationship between the stored payment account information and the replacement code information, finds the payment account information corresponding to the updated replacement code information, and passes the found payment account information and the payment amount information.
  • the card merchant payment gateway sends the card issuing bank system to enable the card issuing bank system to perform payment processing according to the found payment account information and the payment amount information.
  • the card merchant server After receiving the mobile payment information sent by the payment terminal, the card merchant server extracts the updated replacement code information in the mobile payment information, and from the payment account information and the substitute code information stored in the card merchant server. Searching for the existence of the updated replacement code information in the mapping relationship, and if so, extracting the payment account information corresponding to the updated replacement code information, and extracting the payment account information and the payment amount information in the mobile payment information After the combination, the card is sent to the card issuing bank system through the card merchant payment gateway.
  • the card issuing bank system can deduct the payment amount corresponding to the payment amount information from the payment account corresponding to the payment account information, thereby realizing mobile payment.
  • the payment failure information is sent to the card supplier through the card merchant payment gateway.
  • the server sends the payment failure information to the payment terminal, and the payment terminal sends the failure information to the mobile terminal to notify the user that the mobile payment operation fails.
  • the payment success information can be sent to the mobile terminal according to the above process.
  • the mobile terminal uses the updated replacement code information to perform mobile payment, thereby avoiding leakage of the mobile payment information, especially the payment account information. Leaked to protect user privacy.
  • the substitute code information corresponding to the payment account information is dynamically updated, the privacy information such as the user's purchasing habits and the goods of interest is obtained by collecting and analyzing the substitute code information, thereby preventing the leakage of the user's private information. .
  • FIG. 6 is a specific flowchart of a mobile terminal performing mobile payment with updated replacement code information according to another embodiment of the present invention, which is an improvement performed on the mobile payment process described in FIG. S602 to S604 are similar to steps S501 to S503 shown in FIG. 5, and are described in detail as follows:
  • the mobile terminal performs encryption processing on the updated replacement code information.
  • the encryption algorithm used in the encryption process may be any encryption algorithm in the prior art, and the encryption algorithm is the same as or different from the encryption algorithm used in the card vendor server.
  • the mobile terminal sends the encrypted updated replacement code information to the payment terminal. Specific The process is as described in the above S501, and details are not described herein again.
  • the payment terminal After receiving the encrypted replacement code information sent by the mobile terminal, the payment terminal decrypts the encrypted updated substitute code information, and sends the mobile payment information to the card merchant server.
  • the mobile payment information includes the decrypted updated replacement code information and the payment amount information.
  • the card merchant server searches for a mapping relationship between the stored payment account information and the replacement code information, finds the payment account information corresponding to the updated replacement code information, and passes the found payment account information and the payment amount information.
  • the card merchant payment gateway sends the card issuing bank system to enable the card issuing bank system to perform payment processing according to the found payment account information and the payment amount information. The specific process is as described in the foregoing S503, and details are not described herein again.
  • FIG. 7 is a flowchart showing an implementation process of a method for protecting mobile payment information according to another embodiment of the present invention.
  • the method for protecting mobile payment information is based on the method for protecting mobile payment information shown in FIG. 2 to FIG.
  • the improvements made are detailed below:
  • the card merchant server dynamically updates the replacement code information corresponding to each stored payment account information.
  • the specific process is as described in the foregoing S201, and details are not described herein again.
  • the card merchant server After updating the replacement code information corresponding to each stored payment account information, the card merchant server updates the mapping relationship between the payment account information and the replacement code information stored in the card vendor server according to the updated replacement code information.
  • the specific process is as described in the above S202, and details are not described herein again.
  • the card merchant server After updating the replacement code information corresponding to each stored payment account information, the card merchant server encrypts the updated replacement code information and the corresponding payment account information.
  • any encryption algorithm provided by the prior art may be used.
  • the updated substitute code information encrypted by the card merchant server and the corresponding payment account information are sent to the mobile terminal, so that the mobile terminal performs mobile payment with the updated substitute code information.
  • the mobile terminal uses the decryption algorithm corresponding to the encryption algorithm to encrypt the updated replacement code information and the corresponding payment account. Decrypting the information, and updating the updated replacement code information obtained by the decryption to update a mapping relationship between the payment account information and the substitute code information stored in the mobile terminal, and The updated replacement code information is used for mobile payment.
  • the payment account information and the substitute code information transmitted between the mobile terminal and the card merchant server are encrypted, thereby improving the transmission security of the payment account information and the substitute code information.
  • FIG. 8 is a diagram of a device for protecting mobile payment information according to an embodiment of the present invention.
  • the device may be implemented by a software unit, a hardware unit, or a combination of hardware and software in a card merchant server built in a mobile payment system.
  • a stand-alone plug-in is integrated into the card merchant server, or an application system of the card vendor server, such as a mobile payment system. Parts that are not described in detail are referred to the corresponding description of the method.
  • the device includes:
  • the first update unit 31 is configured to dynamically update the substitute code information corresponding to each payment account information stored in the card vendor server.
  • the first update unit 31 includes an update period setting module 311 and a first update module 312.
  • the update period setting module 311 is configured to set an update period.
  • the first update module 312 is configured to periodically update the substitute code information corresponding to each payment account information stored in the card vendor server according to the update period.
  • the first update unit 31 includes an update request receiving module 313 and a second update module 314.
  • the update request receiving module 313 is configured to receive a substitute code update request sent by the mobile terminal, where the substitute code update request includes payment account information.
  • the second update module 314 is configured to update the substitute code information corresponding to the payment account information in the substitute code update request.
  • the second update unit 32 is configured to update the payment account information and the replacement code stored in the card merchant server according to the updated replacement code information after updating the replacement code information corresponding to each payment account information stored in the card vendor server.
  • the substitute code synchronization unit 33 is configured to send the updated replacement code information and the corresponding payment account information to the mobile terminal after updating the replacement code information corresponding to each payment account information stored in the card vendor server, so that The mobile terminal updates the mapping relationship between the payment account information and the replacement code information stored in the mobile terminal according to the updated replacement code information, and performs mobile payment with the updated replacement code information.
  • the apparatus further includes a request receiving unit 34, a substitute code generating unit 35, a mapping relationship storage unit 36, and a substitute code transmitting unit 37. among them:
  • the request receiving unit 34 is configured to receive a payment account registration request sent by the mobile terminal, where the payment account registration request includes payment account information.
  • the substitute code generating unit 35 is configured to randomly generate a corresponding substitute code information for the payment account information included in the payment account registration request.
  • the mapping relationship storage unit 36 is configured to store, in the card merchant server, a mapping relationship between the payment account information included in the payment account registration request and the generated substitute code information.
  • the substitute code transmitting unit 37 is configured to send the substitute code information generated by the substitute code generating unit and the corresponding payment account information to the mobile terminal, so that the mobile terminal stores the payment account information and the generated substitute code information. Mapping relationship.
  • the apparatus further includes a mobile payment information receiving unit 38 and a search unit 39. among them:
  • the mobile payment information receiving unit 38 is configured to receive mobile payment information sent by the payment terminal, wherein the mobile payment information includes payment amount information and the updated replacement code information sent by the mobile terminal to the payment terminal.
  • the searching unit 39 is configured to search for a mapping relationship between the payment account information and the replacement code information stored in the card merchant server, find the payment account information corresponding to the updated replacement code information, and find the found payment account information. And the payment amount information is sent to the card issuing bank system through the card merchant payment gateway, so that the card issuing bank system performs payment processing according to the found payment account information and the payment amount information.
  • the structure of the card merchant server in the mobile payment system shown in FIG. 1 includes the above-described structure of the protection device for mobile payment information.
  • the card merchant server includes:
  • the first update unit 31 is configured to dynamically update the substitute code information corresponding to each payment account information stored in the card vendor server.
  • the second update unit 32 is configured to update the payment account information and the replacement code stored in the card merchant server according to the updated replacement code information after updating the replacement code information corresponding to each payment account information stored in the card vendor server.
  • the substitute code synchronization unit 33 is configured to send the updated replacement code information and the corresponding payment account information to the mobile terminal after updating the replacement code information corresponding to each payment account information stored in the card vendor server, so that The mobile terminal updates the mapping relationship between the payment account information and the replacement code information stored in the mobile terminal according to the updated replacement code information, and performs mobile payment with the updated replacement code information.
  • the card merchant server further includes the above-mentioned other components, such as the request receiving unit 34, the substitute code generating unit 35, the mapping relationship storage unit 36, and the substitute code transmitting unit 37, and/or further includes a mobile payment information receiving unit. 38 and search unit 39 and the like.
  • the various embodiments in the present specification are described in a progressive manner, and each embodiment focuses on differences from other embodiments, and the same similar parts between the various embodiments may be referred to each other.
  • the description is relatively simple, and the relevant parts can be referred to the method part.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本发明提供了一种移动支付信息的保护方法、装置及移动支付系统,该方法包括:卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息;卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。本发明可以避免移动支付信息的外泄,保护了用户的隐私数据。

Description

移动支付信息的保护方法、装置及移动支付系统
本申请要求于2015年01月06日提交中国专利局、申请号为201510005221.2,发明名称为“移动支付信息的保护方法、装置及移动支付系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及信息安全技术领域,更具体地说,涉及一种移动支付信息的保护方法、装置及移动支付系统。
背景技术
随着网络通信技术的飞速发展,账务支付方式也从传统的面对面的支付方式发展到开类支付、网络支付、手机支付(也称为移动支付,Mobile Payment)等。其中移动支付因其便捷性已成为一种普及率较高、应用范围较广的一种账务支付方式,给人们的生活带来了极大的便捷。
其中移动支付是指允许移动用户使用其移动终端(如手机等)对所消费的商品或服务进行账务支付的一种服务方式。其具体过程简述如下:通过移动终端将支付账户信息(一般为银行卡号)发送至支付终端,支付终端将移动支付信息发送至卡商服务器,卡商服务器根据移动支付信息完成支付。其中移动支付信息包括支付账户信息、支付金额信息等。该移动支付方式虽然给人们的生活带来了便利,但同时也存在用户隐私信息容易泄露的问题,如通过移动支付信息可以搜集用户的支付账户信息,可以通过对用户的移动支付信息对用户的购买习惯和生活习惯信息进行分析和统计,导致用户隐私信息的泄露。因此,迫切需要一种可以保护移动支付过程中的移动支付信息的方法。
发明内容
有鉴于此,本发明提供了一种移动支付信息的保护方法、装置及移动支付系统,以解决现有的移动支付过程中存在的隐私信息容易泄露的问题。
第一方面,提供了一种移动支付信息的保护方法,所述方法包括:
卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息;
卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
优选的,所述移动终端以更新后的所述替代码信息进行移动支付具体包括:
移动终端将更新后的所述替代码信息发送至支付终端;
支付终端在接收到更新后的所述替代码信息后,将移动支付信息发送至卡商服务器,其中所述移动支付信息包括更新后的所述替代码信息和支付金额信息;
卡商服务器搜索其存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
优选的,所述卡商服务器动态的更新存储的各支付账户信息对应的替代码信息具体包括:
卡商服务器设置更新周期;
卡商服务器按照所述更新周期对存储的各支付账户信息对应的替代码信息进行周期性更新。
优选的,所述卡商服务器动态的更新存储的各支付账户信息对应的替代码信息具体包括:
卡商服务器接收移动终端发送的替代码更新请求,所述替代码更新请求包括支付账户信息;
卡商服务器更新所述替代码更新请求中的支付账户信息对应的替代码信息。
第二方面,提供了一种移动支付信息的保护装置,所述装置包括:
第一更新单元,用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息;
第二更新单元,用于在每次更新卡商服务器中存储的各支付账户信息对应 的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
替代码同步单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
优选的,所述装置还包括:
移动支付信息接收单元,用于接收支付终端发送的移动支付信息,其中所述移动支付信息包括支付金额信息和移动终端向所述支付终端发送的更新后的所述替代码信息;
搜索单元,用于搜索卡商服务器中存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
优选的,所述第一更新单元包括:
更新周期设置模块,用于设置更新周期;
第一更新模块,用于按照所述更新周期对卡商服务器中存储的各支付账户信息对应的替代码信息进行周期性更新。
优选的,所述第一更新单元包括:
更新请求接收模块,用于接收移动终端发送的替代码更新请求,所述替代码更新请求包括支付账户信息;
第二更新模块,用于更新所述替代码更新请求中的支付账户信息对应的替代码信息。
第三方面,还提供了一种移动支付系统,包括移动终端,支付终端,卡商服务器以及与卡商服务器通过卡商支付网关进行通信的发卡银行系统,所述卡商服务器包括:
第一更新单元,用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息;
第二更新单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
替代码同步单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
优选的,所述卡商服务器还包括:
移动支付信息接收单元,用于接收支付终端发送的移动支付信息,其中所述移动支付信息包括支付金额信息和移动终端向所述支付终端发送的更新后的所述替代码信息;
搜索单元,用于搜索卡商服务器中存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
与现有技术相比,本发明所提供的技术方案具有以下优点:
本发明通过卡商服务器对支付账户信息对应的替代码信息进行动态的更新,且卡商服务器在每次动态更新支付账户信息对应的替代码信息后,均将该更新后的替代码信息发送至移动终端,移动终端接收到更新后的替代码信息后,即采用更新后的替代码信息进行移动支付,从而避免了移动支付过程中的移动支付信息的外泄,保护了用户的隐私数据。
附图说明
图1为本发明实施例提供的移动支付系统的结构示意图;
图2为本发明实施例提供的移动支付信息的保护方法的实现流程图;
图3为本发明实施例提供的图2中的步骤S201的实现流程图;
图4为本发明另一实施例提供的图2中的步骤S201的实现流程图;
图5为本发明实施例提供的移动终端以更新后的替代码信息进行移动支付的实现流程图;
图6为本发明另一实施例提供的移动终端以更新后的替代码信息进行移动支付的实现流程图;
图7为本发明另一实施例提供的移动支付信息的保护方法的实现流程图;
图8为本发明实施例提供的移动支付信息的保护装置的结构框图;
图9为本发明另一实施例提供的移动支付信息的保护装置的结构框图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
图1是本发明实施例提供的移动支付系统的结构图。该移动支付系统包括移动终端1、可与移动终端1进行通信的支付终端2、可分别与移动终端1、支付终端2进行通信的卡商服务器3以及与卡商服务器3通过卡商支付网关4进行通信的发卡银行系统5。其中:
移动终端1与支付终端2之间可以通过各种近距离通信方式进行通信,如近距离通信方式包括但不限于近距离无线通信方式(Near Field Communication,NFC)等。当移动终端1与支付终端2通过NFC通信方式进行通信时,该移动终端1和支付终端2均为支持NFC功能的设备,如移动终端1和支付终端2中均包括NFC通信模块,如NFC芯片等。其中移动终端1可以为手机等。
支付终端2为可与移动终端1进行通信且可扫描支付标的信息的设备,如POS机等。其中支付标的是指用户需要进行支付的标的物,如需要进行支付的产品或服务等。该支付终端2通过对支付标的进行扫描后,可根据扫描到的支付标的信息计算支付金额信息。
移动终端1与卡商服务器3之间可通过移动网络(例如3G、4G等)或无线网络(例如WIFI等)进行通信。优选移动网络进行通信。
当用户需要进行移动支付时,通过商家提供的支付终端2扫描支付标的信息,并根据支付标的信息计算出支付金额信息后,用户将移动终端1靠近该支付终端2,并在移动终端1中输入支付验证信息,移动终端1对输入的支付验证信息进行验证,并在验证通过后,通过NFC通信方式将更新后的替代码信息发送至支付终端2,支付终端2在接收到移动终端1发送的更新后的替代码信息后,将移动支付信息发送至卡商服务器3,卡商服务器3在接收到所述移动支付信息后,提取该移动支付信息中的更新后的替代码信息,并从卡商服务器3中存储的支付账户信息与替代码信息之间的映射关系中搜索是否存在该更新后的替代码信息,如果存在,则提取出该更新后的替代码信息所对应的支付账户信息, 将提取出的支付账户信息和移动支付信息中的支付金额信息组合后通过卡商支付网关4发送至发卡银行系统5,发卡银行系统5从该支付账户信息所对应的支付账户中扣除支付金额信息所对应的支付金额,从而实现移动支付。
其中,所述卡商服务器3为制卡厂商设立的服务器;所述卡商支付网关4是为银行系统和网络之间的接口,是由银行设立的将网络上传输的数据转换为银行内部数据的服务器;所述发卡银行系统5为银行设立的另一服务器。所述卡商支付网关4分别与所述卡商服务器3和所述发卡银行系统5通过网络连接通信。图2示出了本发明实施例提供的移动支付信息的保护方法的实现流程,详述如下:
S201,卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息。
其中支付账户信息是指在移动支付过程中所使用的支付账户的信息,如支付账户信息可以为银行卡卡号等。替代码信息是指卡商服务器为支付账户信息生成的与支付账户信息一一对应的用于代表移动支付过程中的支付账户信息的替代码。
在本实施例中,在卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息之前,需要将各支付账户在卡商服务器中进行注册。其中支付账户在卡商服务器中进行注册的具体过程如下:
A1、卡商服务器接收移动终端发送的支付账户注册请求,该支付账户注册请求中包括支付账户信息。
在本实施例中,当需要将某账户(如某银行卡)用于移动支付时,需要先将该支付账户在卡商服务器中进行注册。
具体的,移动终端提供人机交互界面,以供用户在该人机交互界面中输入需要注册的支付账户信息并输入支付账户注册请求,移动终端在接收到用户输入的支付账户信息和支付账户注册请求后,将包括该支付账户信息的支付账户注册请求发送至卡商服务器。
A2、卡商服务器为支付账户注册请求中的支付账户信息随机生成一对应的替代码信息,并在卡商服务器中存储支付账户注册请求中的支付账户信息与生成的替代码信息之间的映射关系。
具体的,卡商服务器在接收到移动终端发送的支付账户注册请求后,利用预设的随机生成算法为支付账户注册请求中的支付账户信息随机生成一对应 的替代码信息。其中预设的随机生成算法可以为现有技术中的任意一种算法,包括但不限于各种加密算法等。
卡商服务器在为支付账户注册请求中的支付账户信息随机生成一对应的替代码信息后,建立并存储支付账户注册请求中的支付账户信息与生成的替代码信息之间的映射关系。其中支付账户信息与替代码信息之间的映射关系为一一对应关系。
在本实施例中,卡商服务器可以采用各种存储方式来存储支付账户信息与替代码信息之间的映射关系,如采用数据库表格的方式等。为了便于理解,举例说明如下:
当支付账户注册请求中的支付账户为支付账户1时,若卡商服务器为支付账户1生成的替代码信息为aaa;当支付账户注册请求中的支付账户为支付账户2时,若卡商服务器为支付账户2生成的替代码信息为bbb,则表1示出了采用数据库表格的方式存储的支付账户信息与替代码信息之间的映射关系的示例,但支付账户信息与替代码信息之间的映射关系不以该表格所示示例为限。
表1
支付账户信息 替代码信息
支付账户1 aaa
支付账户2 bbb
…… ……
A3、卡商服务器将生成的替代码信息以及对应的支付账户信息发送至移动终端,以使移动终端存储支付账户信息与生成的替代码信息之间的映射关系。
在本实施例中,为了使移动终端可以采用替代码信息代替支付账户信息来完成移动支付,卡商服务器在为支付账户注册请求中的支付账户信息生成了替代码信息之后,即将生成的替代码信息以及对应的支付账户信息发送至移动终端,移动终端存储支付账户信息与生成的替代码信息之间的映射关系。
通过移动终端将支付账户信息在卡商服务器中进行注册后,卡商服务器中即存储有移动终端发送的支付账户信息,即可对其存储的支付账户信息对应的替代码信息进行动态更新。其中卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息的具体过程如图3和图4所示,在此不再赘述。
S202,卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息 后,根据更新后的替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系。
具体的,在移动终端将支付账户在卡商服务器中进行注册后,卡商服务器中即存储有支付账户信息与替代码信息之间的映射关系,如上述表1所示。这样,在卡商服务器每次更新完其存储的各支付账户信息对应的替代码信息后,从其存储的支付账户信息与替代码信息之间的映射关系中查找到更新了的替代码信息所对应的支付账户信息,并将查找到的该支付账户信息所对应的替代码信息更新为该更新后的替代码信息。为了便于理解,举例说明如下:
假设卡商服务器中存储的支付账户信息与替代码信息之间的映射关系如表1所示,若卡商服务器将其存储的支付账户1的替代码信息aaa更新为a1a1a1,将其存储的支付账户2的替代码信息bbb更新为b1b1b1,则卡商服务器根据更新后的替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系后,可得到表2所示的支付账户信息与替代码信息之间的映射关系。
表2
支付账户信息 替代码信息
支付账户1 a1a1a1
支付账户2 b1b1b1
…… ……
S203,卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息之后,将更新后的替代码信息和对应的支付账户信息发送至移动终端,以使移动终端以更新后的替代码信息进行移动支付。
具体的,在卡商服务器每次更新其存储的各支付账户信息对应的替代码信息之后,卡商服务器将更新后的替代码信息和对应的支付账户信息发送至移动终端。移动终端接收到卡商服务器发送的更新后的替代码信息和对应的支付账户信息时,从该移动终端中存储的支付账户信息和替代码信息之间的映射关系中查找到卡商服务器发送的支付账户信息,并将查找到的支付账户信息的替代码信息替换为更新后的替代码信息,以实现对该移动终端中存储的支付账户信息和替代码信息之间的映射关系的更新。
移动终端在完成其存储的支付账户信息和替代码信息之间的映射关系的更新后,即采用更新后的替代码信息进行后续的移动支付。
其中步骤S202和S203之间可以按照图2所示的顺序依次执行,也可以并行执行,也可以将图2中的步骤S202和S203的执行顺序调换,在此不做限定。
在本实施例中,通过卡商服务器对支付账户信息对应的替代码信息进行动态的更新,且卡商服务器在每次动态更新支付账户信息对应的替代码信息后,均将该更新后的替代码信息发送至移动终端,移动终端接收到更新后的替代码信息后,即采用更新后的替代码信息进行移动支付,从而避免了移动支付过程中的移动支付信息的外泄,保护了用户的隐私数据。
图3示出了本发明实施例提供的图2中的S201的具体实现流程,详述如下:
S301,卡商服务器设置替代码信息的更新周期。
具体的,卡商服务器可以为其存储的所有支付账户信息对应的替代码信息设置统一的更新周期,也可以为不同的支付账户信息设置不同的更新周期,还可以对支付账户信息进行分类,在针对每个支付账户信息分类设置更新周期,可以理解,设置更新周期的具体方式还可以为其它方式,在此不再一一举例说明。
S302,卡商服务器按照更新周期对存储的各支付账户信息对应的替代码信息进行周期性更新。
具体的,卡商服务器在为支付账户信息对应的替代码信息设置好更新周期后,卡商服务器在每次到达为各替代码信息设置的更新周期时,即对该替代码信息进行更新。其中对替代码信息进行更新的具体过程可以为采用上述预设的随机生成算法重新为支付账户信息生成替代码信息,将该重新生成的替代码信息作为该支付账户信息对应的更新后的替代码信息。
在本实施例中,通过为各支付账户信息对应的替代码信息设置更新周期,从而可以周期性的对各支付账户信息对应的替代码信息进行更新。
图4示出了本发明另一实施例提供的图2中的S201的具体实现流程,详述如下:
S401,卡商服务器接收移动终端发送的替代码更新请求,该替代码更新请求包括支付账户信息。
在本实施例中,当使用移动支付的用户想要更新支付账户信息所对应的替代码信息时,通过移动终端向卡商服务器发送替代码更新请求,并在该替代码更新请求中包括需要进行替代码信息更新的支付账户信息。
S402,卡商服务器更新替代码更新请求中的支付账户信息对应的替代码信息。
在本实施例中,卡商服务器在接收到移动终端发送替代码更新请求后,采用上述预设的随机生成算法重新为该替代码更新请求中的支付账户信息生成替代码信息,并将该重新生成的替代码信息作为该替代码更新请求中的支付账户信息对应的更新后的替代码信息。
在本实施例中,卡商服务器可以在接收到移动终端发送的替代码更新请求后,再对支付账户信息对应的替代码信息进行更新,从而更具有灵活性。
图5示出了本发明实施例提供的移动终端以更新后的替代码信息进行移动支付的具体流程,详述如下:
S501,移动终端将更新后的替代码信息发送至支付终端。
具体的,移动终端可以通过NFC通信方式将更新后的替代码信息发送至支付终端。可以理解,移动终端还可以通过其它短距离通信方式将更新后的替代码信息发送至支付终端,在此不做限定。
在本实施例中,当用户需要进行移动支付时,可先通过商家提供的支付终端(如POS机)扫描支付标的信息,并根据支付标的信息计算出支付金额信息后,用户将移动终端靠近该支付终端,并在移动终端中输入支付验证信息,移动终端对输入的支付验证信息进行验证,并在验证通过后,通过NFC通信方式将更新后的替代码信息发送至支付终端。其中支付验证信息可以为指纹信息等。当支付验证信息为指纹信息时,移动终端将用户输入的指纹信息与移动终端中存储的合法指纹信息进行比对,若比对结果为匹配,则支付验证信息验证通过,否则验证不通过。其中合法执行信息是指用户预先存储在移动终端中的作为验证用的指纹信息。
S502,支付终端在接收到移动终端发送的更新后的替代码信息后,将移动支付信息发送至卡商服务器。其中移动支付信息包括更新后的替代码信息和支付金额信息。
具体的,支付终端在接收到移动终端发送的更新后的替代码信息后,获取其根据扫描到的支付标的信息计算得到的支付金额信息,并将支付金额信息和更新后的替代码信息组合成移动支付信息,将该移动支付信息发送至卡商服务器。
S503,卡商服务器搜索其存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
具体的,卡商服务器在接收到支付终端发送的移动支付信息后,提取该移动支付信息中的更新后的替代码信息,并从卡商服务器中存储的支付账户信息与替代码信息之间的映射关系中搜索是否存在该更新后的替代码信息,如果存在,则提取出该更新后的替代码信息所对应的支付账户信息,将提取出的支付账户信息和移动支付信息中的支付金额信息组合后通过卡商支付网关发送至发卡银行系统。
发卡银行系统即可从该支付账户信息所对应的支付账户中扣除支付金额信息所对应的支付金额,从而实现移动支付。
在本实施例中,若发卡银行系统从该支付账户信息所对应的支付账户中扣除支付金额信息所对应的支付金额的操作失败时,则通过卡商支付网关将该支付失败信息发送至卡商服务器,卡商服务器将该支付失败信息发送至支付终端,支付终端将该失败信息发送至移动终端,以告知用户该次移动支付操作失败。同理,当支付成功时,可以按照上述流程将支付成功信息发送至移动终端。
在本实施例中,在每次更新支付账户信息所对应的替代码信息后,移动终端均采用更新后的替代码信息进行移动支付,从而避免了移动支付信息的泄露,特别是支付账户信息的泄露,保护了用户隐私。而且由于支付账户信息所对应的替代码信息是动态更新的,从而避免了通过对替代码信息进行搜集和分析而获得用户购买习惯、感兴趣的商品等隐私信息,进而避免了用户隐私信息的泄露。
图6示出了本发明另一实施例提供的移动终端以更新后的替代码信息进行移动支付的具体流程,其是在图5所述的移动支付过程的基础上所进行的改进,其中步骤S602至S604与图5所示的步骤S501至S503近似,详述如下:
S601,移动终端对更新后的替代码信息进行加密处理。其中加密处理所采用的加密算法可以为现有技术中的任意一种加密算法,该加密算法与卡商服务器中所采用的加密算法相同或者不同。
S602,移动终端将加密的更新后的替代码信息发送至支付终端。其具体过 程如上述S501所述,在此不再赘述。
S603,支付终端在接收到移动终端发送的加密的更新后的替代码信息后,对加密的更新后的替代码信息进行解密,并将移动支付信息发送至卡商服务器。其中移动支付信息包括解密的更新后的替代码信息和支付金额信息。其具体过程如上述S502所述,在此不再赘述。
S604,卡商服务器搜索其存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。其具体过程如上述S503所述,在此不再赘述。
在本实施例中,通过对移动终端与支付终端之间传输的替代码信息进行加密处理,从而提高了替代码信息的传输安全性。
图7示出了本发明另一实施例提供的移动支付信息的保护方法的实现流程,该移动支付信息的保护方法是在上述图2至6所示的移动支付信息的保护方法的基础上所做的改进,详述如下:
S701,卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息。其具体过程如上述S201所述,在此不再赘述。
S702,卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息后,根据更新后的替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系。其具体过程如上述S202所述,在此不再赘述。
S703,卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息之后,对更新后的替代码信息和对应的支付账户信息进行加密处理。
其中对更新后的替代码信息和对应的支付账户信息进行加密处理时,可采用现有技术提供的任意一种加密算法。
S704,卡商服务器加密的更新后的替代码信息和对应的支付账户信息发送至移动终端,以使移动终端以更新后的替代码信息进行移动支付。
具体的,卡商服务器加密的更新后的替代码信息和对应的支付账户信息发送至移动终端后,移动终端采用与加密算法对应的解密算法对加密的更新后的替代码信息和对应的支付账户信息进行解密,并将解密得到的更新后的替代码信息更新移动终端中存储的支付账户信息和替代码信息之间的映射关系,并以 更新后的替代码信息进行移动支付。
在本实施例中,通过对移动终端与卡商服务器之间传输的支付账户信息和替代码信息进行加密处理,从而提高了支付账户信息和替代码信息的传输安全性。
图8示出了本发明实施例提供的移动支付信息的保护装置,该装置可以使内置于移动支付系统中的卡商服务器中的软件单元、硬件单元或者软硬件相结合的单元,也可以作为独立的插件集成到该卡商服务器中,或者该卡商服务器的应用系统,如移动支付系统中。其中未详细描述的部分参见方法的相应描述。该装置包括:
第一更新单元31用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息。
优选的,该第一更新单元31包括更新周期设置模块311和第一更新模块312。其中更新周期设置模块311用于设置更新周期。第一更新模块312用于按照所述更新周期对卡商服务器中存储的各支付账户信息对应的替代码信息进行周期性更新。
在本发明另一实施例中,请参见图9,该第一更新单元31包括更新请求接收模块313和第二更新模块314。其中更新请求接收模块313用于接收移动终端发送的替代码更新请求,所述替代码更新请求包括支付账户信息。第二更新模块314用于更新所述替代码更新请求中的支付账户信息对应的替代码信息。
第二更新单元32用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系。
替代码同步单元33用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端根据更新后的所述替代码信息更新所述移动终端中存储的支付账户信息和替代码信息之间的映射关系,并以更新后的所述替代码信息进行移动支付。
优选的,该装置还包括请求接收单元34、替代码生成单元35、映射关系存储单元36以及替代码发送单元37。其中:
请求接收单元34用于接收移动终端发送的支付账户注册请求,所述支付账户注册请求中包括支付账户信息。
替代码生成单元35用于为所述支付账户注册请求中包括的支付账户信息随机生成一对应的替代码信息。
映射关系存储单元36用于在所述卡商服务器中存储所述支付账户注册请求中包括的支付账户信息与生成的所述替代码信息之间的映射关系。
替代码发送单元37用于将替代码生成单元生成的所述替代码信息以及对应的支付账户信息发送至移动终端,以使移动终端存储所述支付账户信息与生成的所述替代码信息之间的映射关系。
优选的,该装置还包括移动支付信息接收单元38和搜索单元39。其中:
移动支付信息接收单元38用于接收支付终端发送的移动支付信息,其中所述移动支付信息包括支付金额信息和移动终端向所述支付终端发送的更新后的所述替代码信息。
搜索单元39用于搜索卡商服务器中存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
在本发明另一实施例中,图1所示的移动支付系统中的卡商服务器的结构包括上述的移动支付信息的保护装置的结构。具体的,该卡商服务器包括:
第一更新单元31用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息。
第二更新单元32用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系。
替代码同步单元33用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端根据更新后的所述替代码信息更新所述移动终端中存储的支付账户信息和替代码信息之间的映射关系,并以更新后的所述替代码信息进行移动支付。
优选的,该卡商服务器还包括上述的其它组成结构,如请求接收单元34,替代码生成单元35,映射关系存储单元36,以及替代码发送单元37,和/或还包括移动支付信息接收单元38和搜索单元39等。本说明书中各个实施例采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似部分互相参见即可。对于实施例公开的装置而言,由于其与实施例公开的方法相对应,所以描述的比较简单,相关之处参见方法部分说明即可。
对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本发明。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本发明的精神或范围的情况下,在其它实施例中实现。因此,本发明将不会被限制于本文所示的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽范围。

Claims (13)

  1. 一种移动支付信息的保护方法,其特征在于,所述方法包括:
    卡商服务器动态的更新其存储的各支付账户信息对应的替代码信息;
    卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
    卡商服务器在每次更新其存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
  2. 如权利要求1所述的移动支付信息的保护方法,其特征在于,在所述卡商服务器动态的更新移动终端发送的各支付账户信息对应的替代码信息之前,所述方法还包括:
    卡商服务器接收移动终端发送的支付账户注册请求,所述支付账户注册请求中包括支付账户信息;
    卡商服务器为所述支付账户信息随机生成一对应的替代码信息,并在所述卡商服务器中存储所述支付账户信息与生成的所述替代码信息之间的映射关系;
    卡商服务器将生成的所述替代码信息以及对应的支付账户信息发送至移动终端,以使移动终端存储所述支付账户信息与生成的所述替代码信息之间的映射关系。
  3. 如权利要求1所述的移动支付信息的保护方法,其特征在于,所述移动终端以更新后的所述替代码信息进行移动支付具体包括:
    移动终端将更新后的所述替代码信息发送至支付终端;
    支付终端在接收到更新后的所述替代码信息后,将移动支付信息发送至卡商服务器,其中所述移动支付信息包括更新后的所述替代码信息和支付金额信息;
    卡商服务器搜索其存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户 信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
  4. 如权利要求3所述的移动支付信息的保护方法,其特征在于,所述移动终端通过近距离通信方式NFC与所述支付终端进行通信。
  5. 如权利要求1至4任一项所述的移动支付信息的保护方法,其特征在于,所述卡商服务器动态的更新存储的各支付账户信息对应的替代码信息具体包括:
    卡商服务器设置更新周期;
    卡商服务器按照所述更新周期对存储的各支付账户信息对应的替代码信息进行周期性更新。
  6. 如权利要求1至4任一项所述的移动支付信息的保护方法,其特征在于,所述卡商服务器动态的更新存储的各支付账户信息对应的替代码信息具体包括:
    卡商服务器接收移动终端发送的替代码更新请求,所述替代码更新请求包括支付账户信息;
    卡商服务器更新所述替代码更新请求中的支付账户信息对应的替代码信息。
  7. 一种移动支付信息的保护装置,其特征在于,所述装置包括:
    第一更新单元,用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息;
    第二更新单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
    替代码同步单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
  8. 如权利要求7所述的移动支付信息的保护装置,其特征在于,所述装置还包括:
    请求接收单元,用于接收移动终端发送的支付账户注册请求,所述支付账户注册请求中包括支付账户信息;
    替代码生成单元,用于为所述支付账户注册请求中包括的支付账户信息随机生成一对应的替代码信息;
    映射关系存储单元,用于在所述卡商服务器中存储所述支付账户注册请求中包括的支付账户信息与生成的所述替代码信息之间的映射关系;
    替代码发送单元,用于将替代码生成单元生成的所述替代码信息以及对应的支付账户信息发送至移动终端,以使移动终端存储所述支付账户信息与生成的所述替代码信息之间的映射关系。
  9. 如权利要求7所述的移动支付信息的保护装置,其特征在于,所述装置还包括:
    移动支付信息接收单元,用于接收支付终端发送的移动支付信息,其中所述移动支付信息包括支付金额信息和移动终端向所述支付终端发送的更新后的所述替代码信息;
    搜索单元,用于搜索卡商服务器中存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
  10. 如权利要求7至10任一项所述的移动支付信息的保护装置,其特征在于,所述第一更新单元包括:
    更新周期设置模块,用于设置更新周期;
    第一更新模块,用于按照所述更新周期对卡商服务器中存储的各支付账户信息对应的替代码信息进行周期性更新。
  11. 如权利要求7至10任一项所述的移动支付信息的保护装置,其特征在于,所述第一更新单元包括:
    更新请求接收模块,用于接收移动终端发送的替代码更新请求,所述替代码更新请求包括支付账户信息;
    第二更新模块,用于更新所述替代码更新请求中的支付账户信息对应的替代码信息。
  12. 一种移动支付系统,包括移动终端,支付终端,卡商服务器以及与卡商服务器通过卡商支付网关进行通信的发卡银行系统,其特征在于,所述卡商服务器包括:
    第一更新单元,用于动态的更新卡商服务器中存储的各支付账户信息对应的替代码信息;
    第二更新单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息后,根据更新后的所述替代码信息更新卡商服务器中存储的支付账户信息与替代码信息之间的映射关系;
    替代码同步单元,用于在每次更新卡商服务器中存储的各支付账户信息对应的替代码信息之后,将更新后的所述替代码信息和对应的支付账户信息发送至移动终端,以使所述移动终端以更新后的所述替代码信息进行移动支付。
  13. 如权利要求11所述的移动支付系统,其特征在于,所述卡商服务器还包括:
    移动支付信息接收单元,用于接收支付终端发送的移动支付信息,其中所述移动支付信息包括支付金额信息和移动终端向所述支付终端发送的更新后的所述替代码信息;
    搜索单元,用于搜索卡商服务器中存储的支付账户信息与替代码信息之间的映射关系,查找到与更新后的所述替代码信息对应的支付账户信息,并将查找到的支付账户信息和支付金额信息通过卡商支付网关发送至发卡银行系统,以使发卡银行系统根据查找到的支付账户信息和支付金额信息进行支付处理。
PCT/CN2015/072011 2015-01-06 2015-01-30 移动支付信息的保护方法、装置及移动支付系统 WO2016109997A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP15876505.7A EP3244359A4 (en) 2015-01-06 2015-01-30 Protection method and apparatus of mobile payment information, and mobile payment system
US15/490,845 US20170221044A1 (en) 2015-01-06 2017-04-18 Protection method and device of mobile payment information based on communication terminal, and mobile payment system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510005221.2A CN104599124A (zh) 2015-01-06 2015-01-06 移动支付信息的保护方法、装置及移动支付系统
CN201510005221.2 2015-01-06

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/490,845 Continuation-In-Part US20170221044A1 (en) 2015-01-06 2017-04-18 Protection method and device of mobile payment information based on communication terminal, and mobile payment system

Publications (1)

Publication Number Publication Date
WO2016109997A1 true WO2016109997A1 (zh) 2016-07-14

Family

ID=53124882

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/072011 WO2016109997A1 (zh) 2015-01-06 2015-01-30 移动支付信息的保护方法、装置及移动支付系统

Country Status (4)

Country Link
US (1) US20170221044A1 (zh)
EP (1) EP3244359A4 (zh)
CN (1) CN104599124A (zh)
WO (1) WO2016109997A1 (zh)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105260451A (zh) * 2015-10-13 2016-01-20 Tcl移动通信科技(宁波)有限公司 一种基于移动终端的聊天记录信息处理方法及系统
CN107291318A (zh) * 2016-03-31 2017-10-24 宇龙计算机通信科技(深圳)有限公司 一种电子交易实现方法以及装置
CN106022762A (zh) * 2016-05-13 2016-10-12 广东欧珀移动通信有限公司 一种支付方法及终端
CN106682908B (zh) * 2016-12-29 2021-08-10 努比亚技术有限公司 支付装置及方法
US10503488B2 (en) * 2017-04-18 2019-12-10 Ncr Corporation Updating a payment processing system to conform with a standard
CN107657533B (zh) * 2017-08-10 2021-01-01 深圳怡化电脑股份有限公司 自助交易提醒方法、装置及终端设备
CN109474565B (zh) * 2017-09-08 2021-06-25 腾讯科技(深圳)有限公司 信息验证方法和装置、存储介质和电子装置
CN107730231A (zh) * 2017-11-02 2018-02-23 东信和平科技股份有限公司 一种基于sim卡的转账方法、装置及介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102119740A (zh) * 2010-12-27 2011-07-13 陈慧婷 缓解肠胃功能失调山奈花生乳的配方及制备方法
CN102129740A (zh) * 2010-01-18 2011-07-20 上海启电信息科技有限公司 一种防止银行卡被盗用的方法
CN103443813A (zh) * 2010-12-14 2013-12-11 极限移动有限公司 使用移动设备标识符认证交易

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6880084B1 (en) * 2000-09-27 2005-04-12 International Business Machines Corporation Methods, systems and computer program products for smart card product management
US20040114766A1 (en) * 2002-08-26 2004-06-17 Hileman Mark H. Three-party authentication method and system for e-commerce transactions
US9240009B2 (en) * 2006-09-24 2016-01-19 Rich House Global Technology Ltd. Mobile devices for commerce over unsecured networks
CN101118629A (zh) * 2007-09-25 2008-02-06 魏恺言 一种银行电子支付安全系统及其处理方法
US9947002B2 (en) * 2008-02-15 2018-04-17 First Data Corporation Secure authorization of contactless transaction
US10037524B2 (en) * 2009-01-22 2018-07-31 First Data Corporation Dynamic primary account number (PAN) and unique key per card
US8788429B2 (en) * 2009-12-30 2014-07-22 First Data Corporation Secure transaction management
CN101976402A (zh) * 2010-09-08 2011-02-16 无锡中星微电子有限公司 手机支付系统及方法
SG10201605288SA (en) * 2011-07-15 2016-08-30 Mastercard International Inc Methods and systems for payments assurance
KR102058175B1 (ko) * 2013-05-15 2019-12-20 비자 인터네셔널 서비스 어소시에이션 모바일 토큰화 허브
US9426302B2 (en) * 2013-06-20 2016-08-23 Vonage Business Inc. System and method for non-disruptive mitigation of VOIP fraud
CN104079581B (zh) * 2014-07-16 2017-07-11 金红宇 身份认证方法及设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102129740A (zh) * 2010-01-18 2011-07-20 上海启电信息科技有限公司 一种防止银行卡被盗用的方法
CN103443813A (zh) * 2010-12-14 2013-12-11 极限移动有限公司 使用移动设备标识符认证交易
CN102119740A (zh) * 2010-12-27 2011-07-13 陈慧婷 缓解肠胃功能失调山奈花生乳的配方及制备方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3244359A4 *

Also Published As

Publication number Publication date
CN104599124A (zh) 2015-05-06
US20170221044A1 (en) 2017-08-03
EP3244359A1 (en) 2017-11-15
EP3244359A4 (en) 2018-06-06

Similar Documents

Publication Publication Date Title
WO2016109997A1 (zh) 移动支付信息的保护方法、装置及移动支付系统
KR101815430B1 (ko) 결제 데이터의 보안 프로비저닝, 전송 및 인증을 위한 방법, 디바이스 및 시스템
JP2020145752A (ja) セキュアデバイス機能へのオンラインアクセスの妥当性検査
US11636472B2 (en) Terminal configuration server for the remote configuration of terminals
US20240095713A1 (en) Method, client device and pos terminal for offline transaction
US11151571B2 (en) Method and system for processing resource exchange information
US20140019367A1 (en) Method to send payment data through various air interfaces without compromising user data
US20150066778A1 (en) Digital card-based payment system and method
US20170011394A1 (en) Cryptographic security for mobile payments
WO2015161699A1 (zh) 数据安全交互方法和系统
US20180012213A1 (en) Systems and method for payment transaction processing with payment application driver
JP2015508541A5 (zh)
WO2016112675A1 (zh) 一种金融自助系统的处理方法
AU2017277523A1 (en) Multi-level communication encryption
KR20160119803A (ko) 인증 시스템 및 방법
JP2013514556A (ja) 安全に取引を処理するための方法及びシステム
WO2009136404A2 (en) A system and method for implementing a secure transaction through mobile communicating device
WO2017072647A1 (en) Mobile payment system
WO2017162164A1 (zh) 电子签名设备的交易方法
WO2017107733A1 (zh) 线下支付方法、终端设备、后台支付装置及线下支付系统
US20240013205A1 (en) Discovery and communication using direct radio signal communication
KR101449425B1 (ko) 지불 서비스 제공 방법 및 장치
Sung et al. Mobile Payment Based on Transaction Certificate Using Cloud Self‐Proxy Server
CN105184558B (zh) 交易信息发送方法、装置以及移动终端
KR20150031594A (ko) 휴대폰을 이용한 결제 시스템 및 결제 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15876505

Country of ref document: EP

Kind code of ref document: A1

REEP Request for entry into the european phase

Ref document number: 2015876505

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2015876505

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE