WO2016169430A1 - 移动支付装置及移动支付系统 - Google Patents

移动支付装置及移动支付系统 Download PDF

Info

Publication number
WO2016169430A1
WO2016169430A1 PCT/CN2016/079237 CN2016079237W WO2016169430A1 WO 2016169430 A1 WO2016169430 A1 WO 2016169430A1 CN 2016079237 W CN2016079237 W CN 2016079237W WO 2016169430 A1 WO2016169430 A1 WO 2016169430A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile payment
payment device
execution environment
transaction
user
Prior art date
Application number
PCT/CN2016/079237
Other languages
English (en)
French (fr)
Inventor
万四爽
柴洪峰
鲁志军
何朔
尹亚伟
刘国宝
郭伟
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Priority to JP2017554595A priority Critical patent/JP6892391B2/ja
Priority to KR1020177032044A priority patent/KR102622185B1/ko
Priority to US15/566,879 priority patent/US20180089690A1/en
Priority to EP16782577.7A priority patent/EP3287969A4/en
Publication of WO2016169430A1 publication Critical patent/WO2016169430A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/326Payment applications installed on the mobile devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/202Interconnection or interaction of plural electronic cash registers [ECR] or to host computer, e.g. network details, transfer of information from host to ECR or from ECR to ECR
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • G06Q20/3227Aspects of commerce using mobile devices [M-devices] using secure elements embedded in M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction

Definitions

  • the present invention relates to the field of mobile payment technologies, and more particularly to a mobile payment device and a mobile payment system.
  • the Trusted execution environment (TEE) proposed by GlobalPlatform has been widely used as a technical implementation platform of the solution.
  • a Rich Execution Environment (REE) 11 and a Trusted Execution Environment 12 are deployed in the mobile device;
  • the rich media execution environment 11 includes a client application 111 and rich media.
  • the execution environment operating system 110 includes a trusted application 121 and a trusted execution environment operating system 120.
  • the REE runs on the hardware device 10 of the mobile device, and the hardware includes a trusted area 101, wherein the TEE runs in the trusted area 101 of the hardware device, and the trusted area 101 cannot be accessed by the REE, through the trusted The area 101 can manage the trusted resource 102, which can access the public resource 100 in the hardware device 10.
  • the REE operating system performs functions such as data input and output and information interaction, and the TEE operating system performs functions related to protecting trusted resources or sensitive data.
  • the present invention provides a technical solution as follows:
  • a mobile payment device for implementing an electronic transaction between a user and a POS machine including: According to the interaction module, for data interaction with the outside; a security management module, which communicates with the data interaction module, for installing and managing applications for electronic transactions, the security management module includes a security chip, and the security chip is used for storing users. Transaction account information; and an authentication module, which communicates with the security management module and the data interaction module, and is used for verifying user identity information; wherein the security management module and the identity verification module work in a trusted execution environment, and the data interaction module works in the rich In the media execution environment, the trusted execution environment runs differently from the rich media execution environment.
  • the data interaction module comprises an NFC communication unit for data exchange between the mobile payment device and the POS machine.
  • a communication channel is provided between the NFC communication unit and the security chip, and the communication channel is configured such that: the communication channel is off by default; after the identity verification module authenticates the identity information of the user, the communication channel is opened to enable the POS machine to pass the NFC.
  • the communication unit and the communication channel perform transaction data communication with the security chip; after the transaction data communication is completed, the communication channel is reset to the closed state.
  • Another object of the present invention is to provide a mobile payment system that is more conducive to protecting transaction security.
  • the present invention provides another technical solution as follows:
  • a mobile payment system includes: a mobile payment device including a security chip, the security chip is used to store the user's transaction account information, the mobile payment device runs a rich media execution environment operating system or a trusted execution environment operating system; the POS machine uses And initiating an electronic transaction between the mobile payment device; and a trusted service platform communicating with the mobile payment device for creating transaction account information; wherein the rich media execution environment operating system controls the mobile payment device and the POS device and the user For data interaction, the trusted execution environment operating system controls the mobile payment device to use the transaction account information to implement the electronic transaction and verify the user identity information.
  • the creating the transaction account information comprises: the user issuing an application for creating a transaction account to the trusted service platform by the rich media execution environment operating system, the trusted service platform responding to the application and issuing a creation instruction, and the rich media execution environment operating system forwards the instruction to Trusted Execution Environment Operating System, Trusted Execution Environment The operating system instructs the security chip to set up and store transaction account information.
  • the mobile payment device further comprises an NFC communication unit, configured to exchange data between the mobile payment device and the POS machine, and a communication channel and a communication channel are provided between the NFC communication unit and the security chip.
  • the communication channel is configured to be in a closed state by default; after the verification of the user identity information is passed, the communication channel is opened to enable the POS machine to perform transaction data communication with the security chip through the NFC communication unit and the communication channel; after the transaction data communication is completed, the communication is completed.
  • the channel is reset to the off state.
  • the present invention also provides a mobile payment method for implementing an electronic transaction, the method comprising the steps of: a) providing the mobile payment device; b), the user applying to the trusted service platform to establish a transaction account using the mobile payment device; After sensing the radio frequency signal sent by the POS machine, the mobile payment device enables the identity verification module to verify the user identity information; d) after the verification is passed, the mobile payment device performs the transaction with the POS machine in the trusted execution environment. Data communication; e) After the transaction data communication is completed, the mobile payment device feeds back the transaction result to the user in the rich media execution environment.
  • the mobile payment device, the mobile payment system and the mobile payment method provided by the embodiments of the present invention place the three operations of applying for a transaction account, identity information verification, and transaction data communication in a trusted execution environment, and the remaining operations are performed in rich media. In an environment that provides a superior user experience, it also provides secure transaction protection throughout the process.
  • the communication channel between the security chip and the NFC communication unit is set to a normally closed state, and the transaction data communication is only temporarily opened after being authenticated, thereby facilitating shielding of possible security vulnerabilities, thereby further enhancing the transaction. Protection ability.
  • FIG. 1 illustrates a conceptual diagram of a prior art mobile device deployed with a rich media execution environment and a trusted execution environment.
  • FIG. 2 is a block diagram showing the structure of a mobile payment device according to a first embodiment of the present invention.
  • 3 is a flow chart showing the switching between various states of the electronic transaction displayed on the display screen of the mobile payment device.
  • FIG. 4 is a schematic flowchart diagram of a mobile payment method according to a third embodiment of the present invention.
  • FIG. 5 shows a specific process in which a user applies for establishing a transaction account to a trusted service platform through a mobile payment device.
  • FIG. 6 shows a specific process of enabling the identity verification module to verify user identity information after the mobile payment device reads the account information.
  • Figure 7 shows the transaction data communication between the mobile payment device and the POS machine after the user identity information is verified. The specific process of the letter.
  • the communication between the security management module or the identity verification module and the data interaction module refers to switching between the rich media execution environment and the trusted execution environment.
  • the rich media execution environment runs differently than the trusted execution environment.
  • the client application, rich media execution environment operating system, and security application, trusted execution environment operating system referred to herein are usually installed and run in software on related modules/units of the mobile payment device.
  • the first embodiment of the present invention provides a mobile payment device.
  • the hardware device 20 includes a trusted area 200.
  • the trusted area 200 can only be accessed by the trusted execution environment 12, but cannot be executed by the rich media. 11 Access, in other words, trusted area 200 is invisible to rich media execution environment 11.
  • the hardware device 20 includes a data interaction module 203 for performing data interaction with an external (eg, user, POS).
  • the data interaction module 203 may include: an input and output sub-module, which is an interface for external data interaction, and specifically includes a user interface device, a data port device, and other types of input and output devices, such as a touch screen, a display screen, a button, and the like; And a wireless communication sub-module, which specifically includes an NFC communication unit, and/or a baseband processor, a GPS unit.
  • the NFC communication unit can exchange data between the mobile payment device and the POS machine.
  • the security management module 201 and the identity verification module 202 are included in the trusted area 200.
  • the trusted zone 200 is only visible to the trusted execution environment 12.
  • the security management module 201 communicates with the data interaction module 203, which includes the hardware required to implement the security management functions on which security applications that can be used for offline transactions, such as electronic cash applications for bank card transactions, etc., can be installed.
  • the security management module 201 further includes a security chip, and the security chip is configured to store the transaction account information of the user.
  • the authentication module 202 communicates with the security management module 201 and the data interaction module 203, respectively, for verifying user identity information, such as fingerprints, irises, heartbeats, voice prints, facial images, and the like.
  • the data interaction module includes a fingerprint collection device.
  • the identity verification module includes a fingerprint identification unit, and the user inputs fingerprint information through the fingerprint collection device for verification by the identity verification module in a trusted execution environment.
  • the mobile payment device may also include other modules, such as a storage module (not shown) including disk storage, flash storage, etc. for storing data; a data processing module (not shown) including a microprocessor
  • a storage module including disk storage, flash storage, etc. for storing data
  • a data processing module including a microprocessor
  • the data processing module needs to support multiple wireless communication protocols, the microcontroller, the digital signal processor, and/or the application specific integrated circuit.
  • the rich media execution environment 11 includes a client application 111, a rich media execution environment operating system 110 that is installed and runs on related modules in the mobile payment device other than the trusted area.
  • the trusted execution environment 12 includes a trusted application 121 and a trusted execution environment operating system 120 that are installed and run in the trusted region 200.
  • a communication channel is provided between the NFC communication unit and the security chip, the communication channel is configured as: A, the communication channel is off by default; B, the identity information of the user is verified in the identity verification module. After the passage, the communication channel is opened to enable the POS machine to perform transaction data communication with the security chip through the NFC communication unit and the communication channel; C. After the transaction data communication is completed, the communication channel is reset to the closed state.
  • the mobile payment device placed all operations related to the transaction account information of the user and the operation of verifying the identity information of the user in a trusted execution environment, and takes all the links of the electronic transaction into consideration. Provides more secure transaction protection.
  • the present invention sets the communication channel between the security chip and the NFC communication unit to a normally closed state, which performs transaction data communication only temporarily after being authenticated. In order to block possible vulnerabilities, the transaction protection capability is further enhanced.
  • the mobile payment device provided by the present invention can display various prompt information to the user on the display screen, and the indication information respectively correspond to different states of the electronic transaction.
  • Figure 3 illustrates the flow of switching between various states of the electronic transaction displayed on the display of the mobile payment device.
  • the user mobile device is in an initial state, such as a lock screen interface
  • a state S05 after the user's mobile payment device completes the transaction with the POS machine, the prompt transaction completion interface is entered.
  • a second embodiment of the present invention provides a mobile payment system, which includes a mobile payment device, a POS machine, and a Trust Service Management (TSM).
  • the mobile payment device is provided with a security chip (Secure Element, SE for short), the security chip is used for storing the transaction account information of the user, and the mobile payment device runs the rich media execution environment operating system or the trusted execution environment operating system, and there is only one type at any time.
  • the operating system is running and the other is in hibernation.
  • the POS machine is located in the merchant for initiating an electronic transaction with the mobile payment device held by the user.
  • the user applies to the trusted service platform to create a transaction account through the mobile payment device, and the created transaction account information is stored in the security chip.
  • the rich media execution environment operating system controls the mobile payment device to interact with the POS machine and the user, and the trusted execution environment operating system controls the mobile payment device to use the transaction account information to implement the electronic transaction and verify the user identity information.
  • the process of creating transaction account information specifically includes: the user sends an application for creating a transaction account to the trusted service platform through the rich media execution environment operating system, the trusted service platform responds to the application and issues a creation instruction, and the rich media execution environment operating system forwards the instruction to Trusted Execution Environment Operating System, Trusted Execution Environment The operating system instructs the security chip to set up and store transaction account information.
  • the mobile payment device in the above mobile payment system further includes an NFC communication unit for performing data exchange between the mobile payment device and the POS machine, and communication communication between the NFC communication unit and the security chip. Road.
  • the communication channel is configured such that the communication channel is off by default; after the verification of the user identity information is passed, the communication channel is opened to enable the POS machine to pass through the NFC communication unit and the communication channel.
  • the security chip performs transaction data communication; after the transaction data communication is completed, the communication channel is reset to the off state.
  • a third embodiment of the present invention provides a mobile payment method for implementing an electronic transaction between a user and a POS device by the mobile payment device of claim 1, as shown in FIG. 4, the method comprising the following steps:
  • Step S1 provides the mobile payment device provided by the above first embodiment of the present invention.
  • the mobile payment device includes a data interaction module, a security management module, and an identity verification module.
  • the data interaction module is used for data interaction with the outside.
  • the security management module communicates with the data interaction module for installing and managing applications for electronic transactions.
  • the security management module includes a security chip, and the security chip is used to store the user's transaction account information.
  • the authentication module communicates with the security management module and the data interaction module to verify the identity information of the user.
  • the security management module and the identity verification module work in a trusted execution environment, the data interaction module works in a rich media execution environment, and the trusted execution environment and the rich media execution environment operate differently.
  • Step S2 The user applies to the trusted service platform to establish a transaction account by using the mobile payment device.
  • FIG. 5 shows a specific process of step S2, and the step S2 specifically includes the following sub-steps:
  • step S20 the user submits the identity information, and applies to the trusted payment platform for the account for mobile payment;
  • Step S21 the trusted service platform verifies the user identity information, and organizes to create an account instruction
  • Step S22 the trusted service platform sends an instruction to create an account to the REE
  • step S24 the TEE writes the creation instruction to the SE
  • the execution result of the instruction is returned from the SE to the TEE, and the execution result is returned from the TEE to the REE, and finally the execution result is returned from the REE to the trusted service platform.
  • Step S3 After sensing the radio frequency (RF) signal sent by the POS machine, the mobile payment device enables the identity verification module to verify the user identity information.
  • RF radio frequency
  • FIG. 6 shows a specific process of step S3, and the step S3 specifically includes the following sub-steps:
  • Step S30 the mobile payment device is close to the POS machine
  • the mobile payment device is provided with an NFC communication unit, and when the POS device senses the NFC communication unit of the mobile payment device, it can be determined that the mobile payment device is close to the POS device.
  • Step S31 the POS machine sends an RF signal, and the mobile payment device receives via the NFC communication unit;
  • the POS machine may have issued an RF signal before the step S30, and the RF signal is received after the mobile payment device approaches the POS machine. Therefore, it can be considered that the above-mentioned sub-step S30 and sub-step S31 are not successive, but can be executed in parallel.
  • Step S32 the REE requests the TEE to read the account information for verifying the identity of the user
  • Step S33 the TEE reads the account information from the SE
  • the account information is returned from the SE to the TEE, and then returned from the TEE to the REE;
  • the REE receives the account information, and requests the TEE to perform identity verification
  • Step S35 the TEE enables the identity verification module to verify the identity of the user
  • the identity verification module determines whether the user identity information matches the account information; if the verification succeeds, the REE will pop up a payment page, prompting the identity verification to pass.
  • Step S4 After the verification is passed, the mobile payment device performs transaction data communication with the POS machine in a trusted execution environment.
  • FIG. 7 shows a specific process of step S4, and the step S4 specifically includes the following sub-steps:
  • Step S40 The identity verification module returns a user identity verification result to the TEE.
  • This sub-step is performed as a result of the sub-step S35, and is executed immediately.
  • Step S41 the TEE opens a communication channel between the NFC communication unit and the SE;
  • the TEE can then return to the result of opening the communication channel and close the authentication module, and continue to prompt the user to bring the mobile payment device close to or close to the POS.
  • step S42 the POS machine and the SE directly perform transaction data communication through the NFC communication unit and the secure channel.
  • the POS machine issues a transaction instruction to the SE, and the SE sends the transaction data to the POS machine, and the SE returns the transaction result to the REE through the NFC communication unit.
  • step S43 the communication channel between the NFC communication unit and the SE is closed.
  • Step S5 After the transaction data communication is completed, the mobile payment device feeds back the transaction result to the user in the rich media execution environment.
  • step S3 when the user does not use the default card (default transaction account) for the transaction and selects to use another bank card (other transaction account), similarly,
  • the REE can request the TEE to read the information of all the bank cards of the user, and the TEE reads the information of all the bank cards from the SE and then returns to the REE.
  • the REE may instruct the TEE to switch the transaction account, the TEE sets the selected bank card as the default transaction account, and then returns the switching result to the REE, and the REE will display the new payment interface to the user.
  • the mobile payment method provided by the foregoing third embodiment places the three operations of applying for a transaction account, identity information verification, and transaction data communication in a trusted execution environment, and the remaining operations are placed in a rich media execution environment, thereby providing excellent users. At the same time as the experience, it also provides secure transaction protection for the entire process.
  • the present invention sets the communication channel between the security chip and the NFC communication unit to a normally closed state, which temporarily opens the transaction data communication after being authenticated. , further improving security.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Cash Registers Or Receiving Machines (AREA)

Abstract

一种移动支付装置,包括:数据交互模块(203),用于与外部进行数据交互;安全管理模块(201),用于安装并管理用于电子交易的应用,安全管理模块包括安全芯片,安全芯片用于存储用户的交易帐户信息;以及身份验证模块(202),用于验证用户身份信息;其中安全管理模块(201)、身份验证模块(202)工作于可信执行环境(12)下,数据交互模块(203)工作于富媒体执行环境(11)下,可信执行环境(12)与富媒体执行环境(11)不同时运行。其提供全流程的安全交易保护。

Description

移动支付装置及移动支付系统 技术领域
本发明涉及移动支付技术领域,更具体地说,涉及一种移动支付装置及移动支付系统。
背景技术
随着智能移动设备(如智能手机)逐步“支付工具”化,现有的注重用户优质体验的智能操作系统已无法满足支付应用对其所处的运行环境的安全性要求。由于系统资源所限,若提高智能操作系统的安全性,几乎肯定会使功能及用户体验有所降低。
对此,GlobalPlatform所提出的可信执行环境(Trusted execution environment,简称TEE)作为该方案的一个技术实现平台,得到了广泛应用。根据该平台,如图1所示,在移动设备中部署有富媒体执行环境(Rich execution environment,简称REE)11以及可信执行环境12;富媒体执行环境11中包括客户端应用111和富媒体执行环境操作系统110,可信执行环境12中包括可信应用121和可信执行环境操作系统120。同时,REE运行于移动设备的硬件设备10之上,该硬件中包含一个可信区域101,其中TEE运行在硬件设备的可信区域101,该可信区域101不能被REE访问,通过该可信区域101可以管理可信资源102,REE可以访问硬件设备10中的公共资源100。通过以上方式,REE操作系统执行数据输入输出、信息交互等功能,TEE操作系统则执行与保护可信资源或敏感数据相关的功能。
然而,即使存在可信执行环境这样一种技术实现,现有技术中的移动支付装置仍存在诸多安全隐患,其没有将交易的各个环节全部考虑在内,从而在交易安全方面仍需要进一步的改进。
发明内容
本发明的一个目的在于提供一种更利于保护交易安全的移动支付装置。
为实现上述目的,本发明提供一种技术方案如下:
一种移动支付装置,用于实现用户与POS机之间的电子交易,其包括:数 据交互模块,用于与外部进行数据交互;安全管理模块,其与数据交互模块进行通信,用于安装并管理用于电子交易的应用,安全管理模块包括安全芯片,安全芯片用于存储用户的交易帐户信息;以及身份验证模块,其与安全管理模块、数据交互模块进行通信,用于验证用户身份信息;其中安全管理模块、身份验证模块工作于可信执行环境下,数据交互模块工作于富媒体执行环境下,可信执行环境与富媒体执行环境不同时运行。
优选地,数据交互模块包括NFC通信单元,NFC通信单元用于在移动支付装置与POS机之间进行数据交换。
优选地,NFC通信单元与安全芯片之间设有通信通道,通信通道配置成:通信通道默认为关闭状态;在身份验证模块对用户的身份信息验证通过后,通信通道打开以使POS机通过NFC通信单元以及通信通道与安全芯片进行交易数据通信;在交易数据通信完成后,通信通道重设为关闭状态。
本发明另一目的在于提供一种更利于保护交易安全的移动支付系统。
为实现上述目的,本发明提供另一技术方案如下:
一种移动支付系统,包括:移动支付装置,其包括安全芯片,安全芯片用于存储用户的交易帐户信息,移动支付装置运行富媒体执行环境操作系统或可信执行环境操作系统;POS机,用于发起与移动支付装置之间的电子交易;以及可信服务平台,其与移动支付装置进行通信,用于创建交易帐户信息;其中,富媒体执行环境操作系统操控移动支付装置与POS机以及用户进行数据交互,可信执行环境操作系统操控移动支付装置使用交易帐户信息来实现电子交易,以及对用户身份信息进行验证。
优选地,创建交易帐户信息包括:用户通过富媒体执行环境操作系统向可信服务平台发出创建交易帐户的申请,可信服务平台应答申请并发出创建指令,富媒体执行环境操作系统将指令转发至可信执行环境操作系统,可信执行环境操作系统指示安全芯片设立并存储交易帐户信息。
优选地,移动支付装置还包括NFC通信单元,用于在移动支付装置与POS机之间进行数据交换,NFC通信单元与安全芯片之间设有通信通道,通信通道 配置成:通信通道默认为关闭状态;在对用户身份信息的验证通过后,通信通道打开以使POS机通过NFC通信单元以及通信通道与安全芯片进行交易数据通信;在交易数据通信完成后,通信通道重设为关闭状态。
本发明还提供一种移动支付方法,用于实现电子交易,该方法包括如下步骤:a)、提供上述移动支付装置;b)、用户使用移动支付装置向可信服务平台申请建立交易帐户;c)、在感测到POS机发出的射频信号后,移动支付装置启用身份验证模块对用户身份信息进行验证;d)、在验证通过后,移动支付装置在可信执行环境下与POS机进行交易数据通信;e)、在交易数据通信完成后,移动支付装置在富媒体执行环境下向用户反馈交易结果。
本发明各实施例提供的移动支付装置、移动支付系统以及移动支付方法,将申请交易帐户、身份信息验证、交易数据通信这三个操作置于可信执行环境下,其余操作置于富媒体执行环境下,从而在提供优秀用户体验的同时,也提供全流程的安全交易保护。此外,将安全芯片与NFC通信单元之间的通信通道设置为常闭状态,其仅在通过身份验证后暂时性打开来进行交易数据通信,有利于屏蔽可能存在的安全漏洞,从而进一步提升了交易保护能力。
附图说明
图1示出现有技术中部署有富媒体执行环境以及可信执行环境的移动设备的概念性示意图。
图2示出本发明第一实施例提供的移动支付装置的模块结构示意图。
图3为移动支付装置显示屏上所显示的电子交易各种状态间的切换流程图。
图4为本发明第三实施例提供的移动支付方法的流程示意图。
图5示出用户通过移动支付装置向可信服务平台申请建立交易帐户的具体流程。
图6示出移动支付装置读取帐户信息后启用身份验证模块对用户身份信息进行验证的具体流程。
图7示出用户身份信息验证通过后移动支付装置与POS机进行交易数据通 信的具体流程。
具体实施方式
需要说明的是,本文所指安全管理模块或身份验证模块与数据交互模块所进行的通信,需要经过富媒体执行环境与可信执行环境之间的切换。富媒体执行环境与可信执行环境不同时运行。
本文所指客户端应用、富媒体执行环境操作系统以及安全应用、可信执行环境操作系统通常以软件形式安装并运行在移动支付装置的相关模块/单元上。
如图2所示,本发明第一实施例提供一种移动支付装置,其硬件设备20中包括可信区域200,可信区域200仅可由可信执行环境12访问,而不能由富媒体执行环境11访问,换言之,可信区域200对富媒体执行环境11为不可见。
具体地,硬件设备20中包括数据交互模块203,其用于与外部(例如用户、POS机)进行数据交互。数据交互模块203可包括:输入、输出子模块,其是与外部进行数据交互的接口,其具体包括用户界面设备、数据端口设备以及其他类型的输入输出设备,例如触摸屏、显示屏、按键等;以及无线通信子模块,其具体包括NFC通信单元、和/或基带处理器、GPS单元。
其中,当移动支付装置接近POS机,NFC通信单元可在移动支付装置与POS机之间进行数据交换。
可信区域200中包括安全管理模块201和身份验证模块202。可信区域200仅对可信执行环境12为可见。
安全管理模块201与数据交互模块203通信,其包括实现安全管理功能所需的硬件,其上可安装能够用于脱机交易的安全应用,比如银行卡交易的电子现金应用等。
其中,安全管理模块201还包括安全芯片,安全芯片用于存储用户的交易帐户信息。
身份验证模块202分别与安全管理模块201、数据交互模块203通信,其用于验证用户身份信息,如指纹、虹膜、心跳、声纹、面部图像等。
优选情况下,数据交互模块包括指纹收集装置,相应地,身份验证模块包括指纹识别单元,用户通过指纹收集装置输入指纹信息,供身份验证模块在可信执行环境下进行验证。
可以理解,移动支付装置还可包括其他模块,例如:存储模块(未示出),其包括磁盘存储、flash存储等,用于存储数据;数据处理模块(未示出),其包括微处理器、微控制器、数字信号处理器、和/或专用集成电路等,为了使移动支付装置能够与外部设备经由数据交互模块203进行通信,数据处理模块需要支持多个无线通信协议。
富媒体执行环境11包括客户端应用111、富媒体执行环境操作系统110,其安装并运行在移动支付装置中除可信区域之外的相关模块上。可信执行环境12包括可信应用121和可信执行环境操作系统120,其安装并运行在可信区域200中。
根据上述实施例进一步改进的实施方式,NFC通信单元与安全芯片之间设有通信通道,该通信通道配置成:A、通信通道默认为关闭状态;B、在身份验证模块对用户的身份信息验证通过后,通信通道打开以使POS机通过NFC通信单元以及通信通道与安全芯片进行交易数据通信;C、在交易数据通信完成后,通信通道重设为关闭状态。
上述第一实施例提供的移动支付装置,将与用户的交易帐户信息相关的操作、以及验证用户身份信息的操作全部置于可信执行环境下,将电子交易的各个环节全部考虑在内,因而能够提供更安全的交易保护。
此外,相比于现有技术中提供的移动支付装置,本发明将安全芯片与NFC通信单元之间的通信通道设置为常闭状态,其仅在通过身份验证后暂时性打开来进行交易数据通信,以便屏蔽可能存在的漏洞,从而进一步提升了交易保护能力。
本发明所提供的移动支付装置可在显示屏上向用户显示各种提示信息,这些指示信息分别对应于电子交易的不同状态。图3示出移动支付装置显示屏上所显示的电子交易各种状态间的切换流程。
状态S01、用户移动设备处于初始状态,例如锁屏界面;
状态S02、当用户所持移动支付装置接近POS机,弹出默认卡支付界面,并提示用户进行身份验证;
状态S03、如果用户进行身份验证并通过,则提示用户将移动支付装置靠近POS机;
状态S04、如果用户选择使用其他银行卡,则不进行身份验证,而进入银行卡列表界面;
状态S02、当用户选中使用的银行卡后,重新进入默认卡支付界面;
状态S05、当用户的移动支付装置与POS机完成交易后,进入提示交易完成界面。
本发明第二实施例提供一种移动支付系统,其包括移动支付装置、POS机以及可信服务平台(Trust Service Management,简称TSM)。移动支付装置中设有安全芯片(Secure Element,简称SE),安全芯片用于存储用户的交易帐户信息,移动支付装置运行富媒体执行环境操作系统或可信执行环境操作系统,任何时刻只有一种操作系统处于运行状态,另一种可处于休眠状态。
POS机设置于商户中,用于发起与用户所持移动支付装置之间的电子交易。
用户通过移动支付装置向可信服务平台申请创建交易帐户,创建好的交易帐户信息将存储于安全芯片中。
其中,富媒体执行环境操作系统操控移动支付装置与POS机以及用户进行数据交互,可信执行环境操作系统操控移动支付装置使用交易帐户信息来实现电子交易,以及对用户身份信息进行验证。
创建交易帐户信息的过程具体包括:用户通过富媒体执行环境操作系统向可信服务平台发出创建交易帐户的申请,可信服务平台应答申请并发出创建指令,富媒体执行环境操作系统将指令转发至可信执行环境操作系统,可信执行环境操作系统指示安全芯片设立并存储交易帐户信息。
上述移动支付系统中的移动支付装置还包括NFC通信单元,用于在移动支付装置与POS机之间进行数据交换,NFC通信单元与安全芯片之间设有通信通 道。为屏蔽可能存在的安全漏洞,作为进一步改进,该通信通道配置成:通信通道默认为关闭状态;在对用户身份信息的验证通过后,通信通道打开以使POS机通过NFC通信单元以及通信通道与安全芯片进行交易数据通信;在交易数据通信完成后,通信通道重设为关闭状态。
上述支付系统在进行电子交易时,交易信息和/或敏感数据能得到更完善的保护。即使在创建交易帐户的过程中,安全芯片设立并存储交易帐户信息的这一过程也是在可信执行环境下进行的,从而确保电子交易的各环节都具有较佳的数据保护能力。NFC通信单元与安全芯片之间的通信通道默认为常闭状态,仅在进行交易数据通信时暂时性打开,也有助于屏蔽安全漏洞,实现全方位的交易保护。
本发明第三实施例提供一种移动支付方法,用于实现用户通过如权利要求1的移动支付装置与POS机进行的电子交易,如图4所示,该方法包括如下步骤:
步骤S1、提供本发明上述第一实施例所提供的移动支付装置。
该移动支付装置包括数据交互模块、安全管理模块以及身份验证模块。数据交互模块用于与外部进行数据交互。安全管理模块与数据交互模块进行通信,用于安装并管理用于电子交易的应用,安全管理模块包括安全芯片,安全芯片用于存储用户的交易帐户信息。身份验证模块与安全管理模块、数据交互模块进行通信,用于验证用户身份信息。其中安全管理模块、身份验证模块工作于可信执行环境下,数据交互模块工作于富媒体执行环境下,可信执行环境与富媒体执行环境不同时运行。
步骤S2、用户使用移动支付装置向可信服务平台申请建立交易帐户。
图5示出步骤S2的具体流程,该步骤S2具体包括如下分步骤:
分步骤S20、用户提交身份信息,向可信支付平台申请用于移动支付的帐户;
分步骤S21、可信服务平台验证用户身份信息,组织创建帐户指令;
分步骤S22、可信服务平台向REE下发创建帐户的指令;
分步骤S23、REE将指令转发到TEE;
分步骤S24、TEE将创建指令写到SE中;
随后,从SE向TEE返回创建指令执行结果,再从TEE向REE返回执行结果,最后从REE向可信服务平台返回执行结果。
步骤S3、在感测到POS机发出的射频(RF)信号后,移动支付装置启用身份验证模块对用户身份信息进行验证。
图6示出步骤S3的具体流程,该步骤S3具体包括如下分步骤:
分步骤S30、移动支付装置靠近POS机;
优选情况下,移动支付装置中设有NFC通信单元,POS机感测到移动支付装置的NFC通信单元时,即可判断出移动支付装置靠近POS机。
分步骤S31、POS机发出RF信号,移动支付装置经由NFC通信单元接收;
可以理解,在分步骤S30之前,POS机可能已发出RF信号,而在移动支付装置靠近POS机后才接收到RF信号。因此也可认为上述分步骤S30、分步骤S31没有先后之分,而是可以并行执行。
分步骤S32、REE向TEE请求读取帐户信息,以用于对用户身份进行验证;
分步骤S33、TEE从SE中读取帐户信息;
随后,从SE向TEE返回帐户信息,再从TEE向REE返回;
分步骤S34、REE收到帐户信息后,向TEE请求进行身份验证;
分步骤S35、TEE启用身份验证模块,对用户身份进行验证;
具体地,身份验证模块判断用户身份信息与帐户信息是否相符;如果相符则验证通过,REE会弹出支付页面,提示身份验证通过。
步骤S4、在验证通过后,移动支付装置在可信执行环境下与POS机进行交易数据通信。
图7示出步骤S4的具体流程,该步骤S4具体包括如下分步骤:
分步骤S40、身份验证模块向TEE返回用户身份验证结果;
该分步骤作为分步骤S35的执行结果,紧接其执行。
分步骤S41、TEE打开NFC通信单元与SE之间的通信通道;
随后,TEE可返回打开通信通道的结果,并关闭身份验证模块,以及继续提示用户将移动支付装置靠近或保持靠近POS机。
分步骤S42、POS机与SE通过NFC通信单元以及该安全通道直接进行交易数据通信。
具体地,POS机向SE发出交易指令,SE将交易数据上送至POS机,SE通过NFC通信单元向REE返回交易结果。
分步骤S43、关闭NFC通信单元与SE之间的通信通道。
步骤S5、在交易数据通信完成后,移动支付装置在富媒体执行环境下向用户反馈交易结果。
按照上述实施例的改进实施方式,在步骤S3中,结合图3所示,当用户不使用默认卡(默认交易帐户)进行交易,而选择使用其他银行卡(其他交易帐户)时,类似地,REE可请求TEE读取用户所有银行卡的信息,TEE从SE中读出所有银行卡的信息后再向REE返回。当用户通过REE选中某一银行卡时,REE可指示TEE切换交易帐户,TEE将被选中的银行卡设置为默认交易帐户,随后向REE返回切换结果,REE将向用户显示新的支付界面。
上述第三实施例提供的移动支付方法,将申请交易帐户、身份信息验证、交易数据通信这三个操作置于可信执行环境下,其余操作置于富媒体执行环境下,从而在提供优秀用户体验的同时,也提供全流程的安全交易保护。
此外,相比于现有技术中提供的移动支付方法,本发明将安全芯片与NFC通信单元之间的通信通道设置为常闭状态,其仅在通过身份验证后暂时性打开来进行交易数据通信,进一步提升了安全性。
上述说明仅针对于本发明的优选实施例,并不在于限制本发明的保护范围。 本领域技术人员可作出各种变形设计,而不脱离本发明的思想及附随的权利要求。

Claims (10)

  1. 一种移动支付装置,用于实现用户与POS机之间的电子交易,其包括:
    数据交互模块,用于与外部进行数据交互;
    安全管理模块,其与所述数据交互模块进行通信,用于安装并管理用于电子交易的应用,所述安全管理模块包括安全芯片,所述安全芯片用于存储用户的交易帐户信息;以及
    身份验证模块,其与所述安全管理模块、数据交互模块进行通信,用于验证用户身份信息;
    其中所述安全管理模块、身份验证模块工作于可信执行环境下,所述数据交互模块工作于富媒体执行环境下,所述可信执行环境与所述富媒体执行环境不同时运行。
  2. 根据权利要求1所述的移动支付装置,其特征在于,所述数据交互模块包括NFC通信单元,所述NFC通信单元用于在所述移动支付装置与POS机之间进行数据交换。
  3. 根据权利要求2所述的移动支付装置,其特征在于,所述数据交互模块包括指纹收集装置,所述身份验证模块包括指纹识别单元,用户通过所述指纹收集装置输入指纹信息,供所述身份验证模块在所述可信执行环境下进行验证。
  4. 根据权利要求2所述的移动支付装置,其特征在于,所述NFC通信单元与所述安全芯片之间设有通信通道,所述通信通道配置成:
    所述通信通道默认为关闭状态;
    在所述身份验证模块对用户的身份信息验证通过后,所述通信通道打开以使所述POS机通过所述NFC通信单元以及所述通信通道与所述安全芯片进行交易数据通信;
    在所述交易数据通信完成后,所述通信通道重设为关闭状态。
  5. 根据权利要求1至4中任一项所述的移动支付装置,其特征在于,所述移动支付装置为智能手机。
  6. 一种移动支付系统,包括:
    移动支付装置,其包括安全芯片,所述安全芯片用于存储用户的交易帐户信息,所述移动支付装置运行富媒体执行环境操作系统或可信执行环境操作系统;
    POS机,用于发起与所述移动支付装置之间的电子交易;以及
    可信服务平台,其与所述移动支付装置进行通信,用于创建所述交易帐户信息;
    其中,所述富媒体执行环境操作系统操控所述移动支付装置与所述POS机以及用户进行数据交互,所述可信执行环境操作系统操控所述移动支付装置使用所述交易帐户信息来实现所述电子交易,以及对用户身份信息进行验证。
  7. 如权利要求6所述的移动支付系统,其特征在于,所述创建交易帐户信息包括:
    用户通过所述富媒体执行环境操作系统向所述可信服务平台发出创建所述交易帐户的申请,所述可信服务平台应答所述申请并发出创建指令,所述富媒体执行环境操作系统将所述指令转发至所述可信执行环境操作系统,所述可信执行环境操作系统指示所述安全芯片设立并存储所述交易帐户信息。
  8. 如权利要求6或7所述的移动支付系统,其特征在于,所述移动支付装置还包括NFC通信单元,用于在所述移动支付装置与POS机之间进行数据交换,所述NFC通信单元与所述安全芯片之间设有通信通道,所述通信通道配置成:
    所述通信通道默认为关闭状态;
    在所述对用户身份信息的验证通过后,所述通信通道打开以使所述POS机通过所述NFC通信单元以及所述通信通道与所述安全芯片进行交易数据通信;
    在所述交易数据通信完成后,所述通信通道重设为关闭状态。
  9. 一种移动支付方法,用于实现电子交易,所述方法包括如下步骤:
    a)、提供如权利要求1所述的移动支付装置;
    b)、用户使用所述移动支付装置向可信服务平台申请建立交易帐户;
    c)、在感测到POS机发出的射频信号后,所述移动支付装置启用身份验证模块对用户身份信息进行验证;
    d)、在所述验证通过后,所述移动支付装置在所述可信执行环境下与所述POS机进行交易数据通信;
    e)、在所述交易数据通信完成后,所述移动支付装置在所述富媒体执行环境下向用户反馈交易结果。
  10. 如权利要求9所述的方法,其特征在于,所述移动支付装置还包括NFC通 信单元,用于在所述移动支付装置与所述POS机之间进行数据交换,所述NFC通信单元与所述安全芯片之间设有通信通道,所述步骤d)具体包括:
    d1)、在所述用户身份信息通过验证后,打开所述通信通道;
    d2)、所述POS机与所述安全芯片通过所述NFC通信单元以及所述安全通道进行所述交易数据通信;
    d3)、在所述交易数据通信完成后,关闭所述通信信道。
PCT/CN2016/079237 2015-04-23 2016-04-14 移动支付装置及移动支付系统 WO2016169430A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
JP2017554595A JP6892391B2 (ja) 2015-04-23 2016-04-14 モバイル決済装置及びモバイル決済システム
KR1020177032044A KR102622185B1 (ko) 2015-04-23 2016-04-14 모바일 결제 장치 및 모바일 결제 시스템
US15/566,879 US20180089690A1 (en) 2015-04-23 2016-04-14 Mobile payment device and mobile payment system
EP16782577.7A EP3287969A4 (en) 2015-04-23 2016-04-14 Mobile payment device and mobile payment system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510194852.3 2015-04-23
CN201510194852.3A CN105590201B (zh) 2015-04-23 2015-04-23 移动支付装置及移动支付系统

Publications (1)

Publication Number Publication Date
WO2016169430A1 true WO2016169430A1 (zh) 2016-10-27

Family

ID=55929766

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/079237 WO2016169430A1 (zh) 2015-04-23 2016-04-14 移动支付装置及移动支付系统

Country Status (7)

Country Link
US (1) US20180089690A1 (zh)
EP (1) EP3287969A4 (zh)
JP (1) JP6892391B2 (zh)
KR (1) KR102622185B1 (zh)
CN (1) CN105590201B (zh)
TW (1) TW201702951A (zh)
WO (1) WO2016169430A1 (zh)

Families Citing this family (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11373168B2 (en) * 2015-06-05 2022-06-28 Apple Inc. Value added services polling
CN105069442B (zh) * 2015-08-25 2018-12-07 杭州晟元数据安全技术股份有限公司 一种指纹安全单元se模组及支付验证方法
KR20170041465A (ko) * 2015-10-07 2017-04-17 삼성전자주식회사 결제 서비스 제공 방법 및 이를 구현한 전자 장치
CN106127474A (zh) * 2016-06-30 2016-11-16 宇龙计算机通信科技(深圳)有限公司 一种移动支付的方法及终端
CN106228072A (zh) * 2016-07-21 2016-12-14 恒宝股份有限公司 一种通用ta支付平台和支付方法
CN107992729A (zh) * 2016-10-26 2018-05-04 中国移动通信有限公司研究院 一种控制方法、终端及用户识别模块卡
CN106506472B (zh) * 2016-11-01 2019-08-02 黄付营 一种安全的移动终端电子认证方法及系统
CN106845282A (zh) * 2017-01-06 2017-06-13 奇酷互联网络科技(深圳)有限公司 移动终端及其安全控制方法和装置
CN107240157B (zh) * 2017-05-12 2020-08-21 南京心视窗信息科技有限公司 近场通信安全控制方法、移动终端及计算机可读存储介质
CN107622396B (zh) * 2017-09-15 2021-03-12 深圳怡化电脑股份有限公司 自助交易方法、系统及终端设备
CN107769928A (zh) * 2017-10-11 2018-03-06 深圳市金立通信设备有限公司 一种终端及计算机可读存储介质
CN107679858B (zh) * 2017-10-24 2019-12-10 恒宝股份有限公司 移动终端及移动支付方法
US11171989B1 (en) * 2017-11-21 2021-11-09 Medallia, Inc. Secure messaging integration with messaging applications
CN109905350B (zh) * 2017-12-08 2022-08-12 阿里巴巴集团控股有限公司 一种数据传输方法及系统
CN112232801B (zh) * 2018-01-05 2021-08-20 华为终端有限公司 一种电子交易的方法及终端
EP3620942B1 (en) 2018-04-12 2021-08-04 Guangdong Oppo Mobile Telecommunications Corp., Ltd. Security control method and apparatus for application program, and mobile terminal and computer-readable storage medium
CN109214215B (zh) * 2018-06-19 2021-10-26 中国银联股份有限公司 基于tee和ree的分离式切换方法及其系统
CN111383015B (zh) * 2018-12-29 2023-11-03 华为技术有限公司 交易安全处理方法、装置及终端设备
CN111148070B (zh) * 2019-12-31 2021-06-15 华为技术有限公司 V2x通信方法、装置及车辆
CN113192237B (zh) * 2020-01-10 2023-04-18 阿里巴巴集团控股有限公司 支持tee和ree的物联网设备以及实现tee和ree间通信的方法
CN113962676A (zh) * 2020-07-20 2022-01-21 华为技术有限公司 交易验证的方法、装置
CN112288429B (zh) * 2020-10-23 2023-12-12 中国银联股份有限公司 交易方法、终端设备、支付系统、商户系统及存储介质
CN112700234A (zh) * 2020-12-28 2021-04-23 中国银联股份有限公司 支付方法、装置、系统、服务器、设备及介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007226684A (ja) * 2006-02-24 2007-09-06 Fujitsu Ltd サービス提供サーバ、情報端末、サービス提供方法およびサービス提供プログラム
CN103270526A (zh) * 2010-12-30 2013-08-28 Skc&C株式会社 用于管理移动钱包和其相关凭证的系统和方法
CN103793815A (zh) * 2014-01-23 2014-05-14 武汉天喻信息产业股份有限公司 适用于银行卡和行业卡的移动智能终端收单系统及方法
CN103942678A (zh) * 2014-04-01 2014-07-23 武汉天喻信息产业股份有限公司 一种基于可信执行环境的移动支付系统及方法

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6253269B1 (en) * 1998-12-22 2001-06-26 3Com Corporation Bus arbiter system and method for managing communication buses
JP2003016398A (ja) * 2001-06-27 2003-01-17 Sony Corp 携帯端末機
JP2004272561A (ja) * 2003-03-07 2004-09-30 Bitwallet Inc 携帯端末装置、携帯端末方法、携帯端末プログラム、提供サーバ装置、提供サーバ方法、及び提供サーバプログラム
JP2005117116A (ja) * 2003-10-03 2005-04-28 Matsushita Electric Ind Co Ltd 携帯通信装置
US20070235539A1 (en) * 2006-04-05 2007-10-11 Jarkko Sevanto Mobile device with near field communication module and secure chip
JP5216486B2 (ja) * 2008-08-28 2013-06-19 株式会社日立製作所 半導体素子、携帯端末、および情報端末
US8807440B1 (en) * 2010-12-17 2014-08-19 Google Inc. Routing secure element payment requests to an alternate application
CN102136170A (zh) * 2011-01-05 2011-07-27 深圳市文鼎创数据科技有限公司 移动支付装置
CN201965698U (zh) * 2011-01-05 2011-09-07 深圳市文鼎创数据科技有限公司 移动支付装置
US8935746B2 (en) * 2013-04-22 2015-01-13 Oracle International Corporation System with a trusted execution environment component executed on a secure element
US10121144B2 (en) * 2013-11-04 2018-11-06 Apple Inc. Using biometric authentication for NFC-based payments
US10650372B2 (en) * 2014-05-29 2020-05-12 Apple Inc. Apparatuses and methods for managing payment applets on a secure element to conduct mobile payment transactions
KR20160111286A (ko) * 2015-03-16 2016-09-26 삼성전자주식회사 결제 부가 서비스 정보 처리 방법 및 이를 지원하는 전자 장치

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007226684A (ja) * 2006-02-24 2007-09-06 Fujitsu Ltd サービス提供サーバ、情報端末、サービス提供方法およびサービス提供プログラム
CN103270526A (zh) * 2010-12-30 2013-08-28 Skc&C株式会社 用于管理移动钱包和其相关凭证的系统和方法
CN103793815A (zh) * 2014-01-23 2014-05-14 武汉天喻信息产业股份有限公司 适用于银行卡和行业卡的移动智能终端收单系统及方法
CN103942678A (zh) * 2014-04-01 2014-07-23 武汉天喻信息产业股份有限公司 一种基于可信执行环境的移动支付系统及方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3287969A4 *

Also Published As

Publication number Publication date
CN105590201B (zh) 2019-05-10
TW201702951A (zh) 2017-01-16
JP6892391B2 (ja) 2021-06-23
KR20180005660A (ko) 2018-01-16
CN105590201A (zh) 2016-05-18
US20180089690A1 (en) 2018-03-29
JP2018513494A (ja) 2018-05-24
EP3287969A4 (en) 2018-10-17
EP3287969A1 (en) 2018-02-28
KR102622185B1 (ko) 2024-01-09

Similar Documents

Publication Publication Date Title
WO2016169430A1 (zh) 移动支付装置及移动支付系统
US10432620B2 (en) Biometric authentication
US9495524B2 (en) Secure user authentication using a master secure element
US10229410B2 (en) Method and device for end-user verification of an electronic transaction
CA2734206C (en) Methods and systems for authenticating users
EP2605567A1 (en) Methods and systems for increasing the security of network-based transactions
JP2017510909A (ja) 指紋認証方法、装置、インテリジェント端末及びコンピュータ記憶媒体
EP3186739B1 (en) Secure on device cardholder authentication using biometric data
JP2022553463A (ja) 非接触カードに格納された身元データに基づく安全な認証
JP2023538854A (ja) Nfcベースの認証による拡張現実情報の表示及び対話
AU2023204154A1 (en) Delegated administration of permissions using a contactless card
US20240177149A1 (en) Secure authentication based on passport data stored in a contactless card
KR20150067813A (ko) 비밀번호 입력 방법 및 장치와, 이를 이용한 프로그램을 기록한 기록매체

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16782577

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15566879

Country of ref document: US

ENP Entry into the national phase

Ref document number: 2017554595

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 20177032044

Country of ref document: KR

Kind code of ref document: A