WO2016177291A1 - 电子交易监控方法及系统 - Google Patents
电子交易监控方法及系统 Download PDFInfo
- Publication number
- WO2016177291A1 WO2016177291A1 PCT/CN2016/080116 CN2016080116W WO2016177291A1 WO 2016177291 A1 WO2016177291 A1 WO 2016177291A1 CN 2016080116 W CN2016080116 W CN 2016080116W WO 2016177291 A1 WO2016177291 A1 WO 2016177291A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- monitoring
- transaction
- electronic
- transaction data
- user terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4016—Transaction verification involving fraud or risk level assessment in transaction processing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/02—Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
Definitions
- the present invention relates to mobile payment technologies and, more particularly, to electronic transaction monitoring techniques that make mobile payments more secure.
- Flash card refers to the fact that during the consumer transaction process, the bank card transaction is successful and the POS terminal is not deducted. This phenomenon is often caused by the transmission of the last physical channel of the transaction, which cannot be solved by software application upgrade.
- the card is not authenticated to the terminal, and a false terminal may be maliciously deducted.
- the fake terminal does not participate in the background clearing, which causes the cardholder's in-card electronic cash account to not match the electronic cash account in the bank server, causing trouble for the cardholder and the bank.
- Flash card phenomenon and malicious terminal deduction will cause cardholders' consumption troubles.
- the cardholder can not intuitively confirm whether his card is successfully consumed on his device, and can only be prompted by the merchant's POS machine.
- the present invention provides an electronic transaction monitoring method, which includes: setting a monitoring module and a trusted root provided by a third party server in the user terminal, wherein the user terminal is further provided with an electronic cash service application module;
- the monitoring module acquires monitoring transaction data during the electronic transaction of the user terminal through the related electronic device of the merchant;
- the monitoring module calls the trusted root to encrypt the monitoring transaction data;
- the monitoring module is based on the monitoring Transaction data, monitoring changes in data corresponding to the monitoring transaction data in the electronic cash service application module, if the data corresponding to the monitoring transaction data in the electronic cash service application module is different from the monitoring transaction data , to remind the user that the transaction is abnormal.
- the electronic transaction monitoring method further includes: initiating an error correction request if the user is alerted that the transaction is abnormal; and in response to the error correction request, the monitoring module decrypts the encrypted monitoring transaction.
- Data, and signing the monitoring transaction data with the trusted root transmitting the signed monitoring transaction data to the third party server; the third party server verifies the signature and, if the verification passes,
- the monitoring transaction data is sent to the issuing bank's server; the issuing bank's server checks the user's account transaction status based on the monitoring transaction data, and processes the abnormal situation, and then sends the related message for the user to learn.
- the user terminal conducts an electronic transaction with the POS terminal of the merchant through the NFC.
- the electronic cash service application module is disposed in an SD memory card of the user terminal, and in the case where the user terminal is a communication device, is disposed on a SIM card or an SD of the communication device. In the card.
- the application system of the user terminal is a trusted system, and the trusted system selects a TrustZone architecture of an ARM chip or a CSE architecture of an Intel chip.
- the present invention also provides an electronic transaction monitoring system, the system comprising: a monitoring module disposed in the user terminal; a trusted root provided by the third party server disposed in the user terminal; and an electronic cash service application disposed in the user terminal a module; the monitoring module is configured to acquire monitoring transaction data during the electronic transaction of the user terminal through the related electronic device of the merchant, and invoke the trusted root to encrypt the monitoring information; The monitoring module is further configured to monitor, according to the monitoring transaction data, a change of data corresponding to the monitoring transaction data in the electronic cash service application module, if the electronic cash service application module corresponds to the monitoring transaction data The change in the data is different from the monitoring transaction data, and the user is reminded that the transaction is abnormal.
- the electronic transaction monitoring system further includes a server of a third party and a server of the issuing bank; and the electronic cash service application module is configured to initiate error correction if the user is alerted that the transaction is abnormal.
- the monitoring module is further configured to, in response to the error correction request, decrypt the encrypted monitoring transaction data, sign the monitoring transaction data with the trusted root, and send the signed monitoring transaction data to the request.
- the third-party server; the third-party server is configured to verify the signature after receiving the signature monitoring information, and send the monitoring transaction data to a server of the issuing bank if the verification is passed;
- the issuing bank's server is configured to check the user's account transaction status based on the monitoring transaction data, and process the abnormal situation, and then send the related message for the user to learn.
- FIG. 1 is a schematic structural diagram of an application environment of an electronic transaction monitoring method according to the present invention.
- FIG. 2 is a flow chart showing an electronic transaction monitoring method according to the present invention.
- server should be understood broadly, and includes electronic devices having data processing capabilities, and is not particularly limited to a certain type of electronic device.
- An electronic transaction monitoring method is applied, for example, in an application environment as shown in FIG.
- the application environment is as shown in FIG. 1, and includes a user terminal 10, a related electronic device 12 of the merchant, a third-party server 14, and a card-issuing server 16.
- the user terminal 10 can be, for example, a portable electronic device such as a mobile phone, a desktop computer, or other data processing device not listed herein.
- the user terminal 10 includes an NFC (Near Field Communication) module, and further includes an electronic cash service application module 102.
- the merchant's associated electronic device 12 is a POS terminal in the example herein, and is therefore sometimes referred to hereinafter as the merchant POS terminal 12.
- the associated electronic device 12 of the merchant is in communication connection with the issuing bank server 16, the issuing bank server 16 is in communication connection with the third party server 14, and the user terminal 10 is also in communication connection with the third party server 14.
- the communication connection can be a wireless connection or a wired connection, as long as the communication function can be achieved.
- a user communicates with a merchant POS terminal 12 through an NFC module of their user terminal 10 to conduct a transaction.
- the merchant POS terminal 12 uploads the transaction data to the issuer server 16 for processing thereof, where the processing flow for a series of transactions from the POS terminal to the issuer is consistent with conventional electronic transactions.
- the user terminal 10 is provided with a monitoring module 100 and a trusted root (not shown) provided by a third party server.
- 2 is a flow chart showing an electronic transaction monitoring method according to the present invention.
- An electronic transaction monitoring method according to the present invention is schematically illustrated in conjunction with FIG. 2 and FIG.
- the monitoring module 100 acquires monitoring transaction data when the user terminal 10 conducts an electronic transaction through the merchant POS terminal 12.
- the monitoring transaction data refers to some key data that can confirm whether the transaction is wrong, such as the amount, the name of the merchant, and so on.
- the monitoring module 100 further calls the trusted root set in the user terminal 10 to encrypt the acquired monitoring transaction data.
- the monitoring module 100 monitors the change of the data corresponding to the monitoring transaction data in the electronic cash service application module 102 based on the monitoring transaction data, if the electronic cash service application module corresponds to the monitoring transaction data.
- the change in the data is different from the monitoring transaction data, and the user is reminded that the transaction is abnormal.
- the amount of cash in the electronic cash service application module 102 may vary with the transaction amount. For example, the cash amount of the 1,500 yuan in the electronic cash service application module 102 is changed after the transaction of 500 yuan. The amount of cash in the amount of 1,000 yuan, and the amount of change is 500. If the monitoring module 100 monitors the change in the cash amount in the electronic cash service application module 102 to 1000 instead of 500, the user is alerted to the transaction exception.
- step 24 it is determined that the change of the data corresponding to the monitoring transaction data in the electronic cash service application module is inconsistent with the monitoring transaction data and the user is reminded of the transaction abnormality, and then proceeds to step 26.
- step 26 in the event that the user is alerted that the transaction is abnormal, an error correction request is initiated, which may be initiated, for example, by the electronic cash service application module 102.
- the monitoring module 100 decrypts the encrypted monitoring transaction data in response to the error correction request, and signs the monitoring transaction data with the trusted root.
- the signed monitoring transaction data is sent to the third party server 14.
- the third party server 14 verifies the signature and, if the verification passes, transmits the monitoring transaction data to the issuer's server 16.
- the issuer's server 16 checks the user's account transaction status based on the monitoring transaction data and processes the abnormal condition, and then sends the relevant message for the user to learn. For example, in the event that a change in the transaction amount is found, the issuer server 16 performs reconciliation processing on the account of the card, and counts the abnormal deduction into the account of the card, and then transmits a related message for the user to learn.
- the electronic cash service application module is disposed in an SD memory card of the user terminal 10, and in the case where the user terminal 10 is a communication device, is disposed in an SD card of a SIM card or a communication device.
- the application system of the user terminal is an application system of the trusted system
- the trusted system may be a TrustZone architecture of an ARM chip or a CSE architecture of an Intel chip, and other trusted systems not listed herein also can.
- the user terminal 10 makes a cash payment to the merchant POS terminal through the electronic cash service application module through the NFC module.
- the monitoring module 100 accesses the NFC module to obtain monitoring transaction data.
- the monitoring module 100 encrypts the monitoring transaction data with a trusted root stored in the user terminal 10, and stores the monitoring transaction data, for example, and stores it in the storage module.
- the monitoring module 100 further accesses the SE device of the user terminal 10 to acquire data after the transaction in the electronic cash service application module 102 in the SE device.
- the monitoring module 100 compares the monitoring transaction data with the post-trade data obtained from the electronic cash service application module 102 in the SE device, such as the amount of the item or other information corresponding to the monitoring transaction data presented by the post-transaction data. If it is different from the acquired transaction data for monitoring, it is determined that the transaction is abnormal.
- the monitoring module 100 issues a warning to the user via the user terminal 10 indicating that the transaction is abnormal, such as displaying information or buzzing.
- the user can initiate an error correction request through the electronic cash application service module 102 of the user terminal 10.
- the monitoring module 100 reads the stored transaction data related to the transaction, that is, the stored monitoring transaction data, and calls the trusted root, decrypts the transaction data and signs.
- the monitoring module 100 further transmits the signed transaction data to the third party server 14.
- the third party server 14 verifies the signed transaction data and, if the verification passes, transmits the transaction data to the issuer server.
- the account reconciliation process is performed, for example, the transaction amount of the multi-deduction is counted to the user's main account.
- the issuer server 16 can return the reconciliation result to the user, indicating that the error correction was successful.
- an electronic transaction monitoring system is also provided.
- the electronic transaction monitoring system is illustrated in conjunction with FIG.
- the electronic transaction monitoring system includes a monitoring module 100 disposed in the user terminal 10, a trusted root (not shown) provided by the third party server 14 disposed in the user terminal 10, and an electronic cash service provided in the user terminal 10.
- the monitoring module 100 is configured to be in the process of electronic transactions by the user terminal 10 through the associated electronic device 12 of the merchant. Obtaining monitoring transaction data, and calling the trusted root to encrypt the monitoring information.
- the monitoring module 100 acquires monitoring transaction data through the NFC module used by the user terminal 10 for electronic data transactions, and finally encrypts and stores the data.
- the monitoring module 100 further monitors, according to the monitoring transaction data, the change of the data corresponding to the monitoring transaction data in the electronic cash service application module 102, if the data corresponding to the monitoring transaction data in the electronic cash service application module changes Different from the monitoring transaction data, the user is reminded that the transaction is abnormal.
- the monitoring module 100 acquires data after the transaction in the electronic cash service application module 102 in the SE device from the SE device of the user terminal 10.
- the monitoring module 100 compares the monitoring transaction data with the post-trade data obtained from the electronic cash service application module 102 in the SE device, such as the amount of the item or other information corresponding to the monitoring transaction data presented by the post-transaction data. If it is different from the acquired transaction data for monitoring, it is determined that the transaction is abnormal.
- the electronic cash service application module 102 initiates an error correction request.
- the monitoring module 100 decrypts the encrypted monitoring transaction data, signs the monitoring transaction data with the trusted root, and transmits the signed monitoring transaction data to the third party server. 14.
- the third party server 14 verifies the signature after receiving the signature monitoring transaction data, and transmits the monitoring transaction data to the card issuing bank server 16 when the verification is passed.
- the issuing bank's server 16 is configured to perform reconciliation processing on the card's account based on the monitoring transaction data, and to charge the abnormal debit to the card's account, and then send the relevant message for the user to learn.
- the application system of the user terminal 10 is a trusted system, such as a TrustZone architecture of an ARM chip or a CSE architecture of an Intel chip, or other trusted system not mentioned herein.
- the transaction data is monitored by the monitoring module, and in the case where the transaction data is abnormal, the transaction situation can be sent to the issuing bank via the third party for verification processing, and finally the occurrence of the erroneous transaction is ensured.
- the transaction is safe.
- the communication is illustrated by the communication of the NFC module with the POS terminal as an example, other communicable modules of the user terminal may be employed to trade with the POS terminal.
- the transaction abnormality is indicated by the change in the transaction amount or the amount, but it may also be a transaction abnormality caused by other transaction data changes, such as a payee.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Computer Security & Cryptography (AREA)
- Finance (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Cash Registers Or Receiving Machines (AREA)
Abstract
本发明提供一种电子交易监控方法,该方法包括在用户终端中设置监控模块及由第三方服务器提供的可信根,用户终端中还设置有电子现金服务应用模块;监控模块在用户终端通过商户的相关电子设备进行电子交易的过程中,获取监控用交易数据;监控模块调用所述可信根,加密所述监控用交易数据;监控模块基于所述监控用交易数据,监控所述电子现金服务应用模块中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据变动与所述监控用交易数据不同,则提醒用户交易异常。还提供电子交易监控系统。采用本发明的技术方案,可提高电子交易的安全性。
Description
本发明涉及移动支付技术,更为具体地,涉及使移动支付更为安全的电子交易监控技术。
现有电子现金应用中脱机消费偶尔会出现“闪卡”及恶意终端扣款现象。“闪卡”指的是消费交易过程中,银行卡片交易成功而POS终端并未扣到款,这种现象往往是由于交易最后物理信道传输出错引起的,通过软件应用升级无法解决该难题。
又因电子现金应用脱机交易中,卡片对终端不认证,可能会出现假终端恶意扣款。但假终端不参与后台清算,造成持卡人的卡内电子现金账户与银行服务器内电子现金账户不匹配,给持卡人和银行造成困扰。
闪卡现象和恶意终端扣款都会造成持卡人的消费困扰。首先,持卡人无法直观的在自身设备上确认自己的卡是否消费成功,只能通过商家的POS机提示。其次,发生交易争议后无法快速有效地对账找回。
发明内容
有鉴于此,本发明提供一种电子交易监控方法,该方法包括:在用户终端中设置监控模块及由第三方服务器提供的可信根,所述用户终端中还设置有电子现金服务应用模块;监控模块在所述用户终端通过商户的相关电子设备进行电子交易的过程中,获取监控用交易数据;监控模块调用所述可信根,加密所述监控用交易数据;监控模块基于所述监控用交易数据,监控所述电子现金服务应用模块中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。
根据本发明,可选地,所述的电子交易监控方法,还包括:在用户被提醒交易异常的情况下,发起纠错请求;响应于该纠错请求,监控模块解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名;将签名后的监控用交易数据发送给所述第三方服务器;所述第三方服务器验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器;所述发卡行的服务器基于该监控用交易数据核对用户的账户交易情况,并对异常情况进行处理,随后,发送相关消息以便用户获悉。
根据本发明,可选地,用户终端通过NFC与商户的POS终端进行电子交易。
根据本发明,可选地,所述电子现金服务应用模块设置在所述用户终端的SD存储卡中,在所述用户终端为通信设备的情况下,设置在SIM卡或所述通信设备的SD卡中。
根据本发明,可选地,所述用户终端的应用系统为可信系统,所述可信系统选择ARM芯片的TrustZone架构或Intel芯片的CSE架构。
本发明还提供一种电子交易监控系统,该系统包括:设置在用户终端中的监控模块;设置在用户终端中的由第三方服务器提供的可信根;设置在用户终端中的电子现金服务应用模块;所述监控模块配置成用于在所述用户终端通过商户的相关电子设备进行电子交易的过程中,获取监控用交易数据,并调用所述可信根,加密所述监控用信息;所述监控模块还配置成基于所述监控用交易数据,监控所述电子现金服务应用模块中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。
根据本发明,可选地,所述电子交易监控系统还包括第三方的服务器与发卡行的服务器;且所述电子现金服务应用模块被配置成在用户被提醒交易异常的情况下,发起纠错请求;所述监控模块进一步配置成响应于该纠错请求,解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名,将签名后的监控用交易数据发送给所述第三方服务器;所述第三方服务器设置成在收到该签名的监控用信息后验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器;以及所述发卡行的服务器配置成基于该监控用交易数据核对用户的账户交易情况,并对异常情况进行处理,随后,发送相关消息以便用户获悉。
采用本发明的技术方案,可提高电子交易的安全性。
图1是根据本发明的电子交易监控方法的应用环境的结构示意图。
图2是根据本发明所述的电子交易监控方法的流程示意图。
现在参照附图描述本发明的示意性示例,相同的附图标号表示相同的元件。下文描述的各实施例有助于本领域技术人员透彻理解本发明,且意在示例而非限制。除非另有限定,文中使用的术语(包括科学、技术和行业术语)具有与本发明所属领域的技术人员普遍理解的含义相同的含义。此外,流程图中各步骤的先后顺序也不以图示的顺序为限。
在本发明中,术语“服务器”应做广义理解,其包括具备数据处理能力的电子设备,并不特别限定于某一类电子设备。
根据本发明示例的电子交易监控方法例如应用在如图1所示的应用环境中。示例地,该应用环境如图1所示,包括用户终端10、商户的相关电子设备12、第三方服务器14以及发卡行服务器16。用户终端10可以例如为手机等便携式电子设备,也可为台式计算机,还可以是在此未列出的其它可进行数据处理的设备。根据本发明的示例,用户终端10包括NFC(Near Field Communication,近场通信)模块,还包括电子现金服务应用模块102。商户的相关电子设备12在本文示例中为POS终端,因此下文中有时也称为商户POS终端12。商户的相关电子设备12与发卡行服务器16之间通信连接,发卡行服务器16与第三方服务器14之间通信连接,用户终端10与第三方服务器14之间也是通信连接。本文中,通信连接可为无线连接,也可以是有线连接,只要能达成通信功能即可。
作为示例,用户通过其用户终端10的NFC模块与商户POS终端12通信,以进行交易。商户POS终端12会将交易数据上传发卡行服务器16以便其进行处理,在此,从POS终端到发卡行的一系列有关交易的处理流程与常规的电子交易一致。
根据本发明的示例,用户终端10中设置有监控模块100及第三方服务器提供的可信根(未示出)。图2是根据本发明所述的电子交易监控方法的流程示意图。结合图2与图1来示意性地阐述根据本发明所述的电子交易监控方法。在步骤20,监控模块100在用户终端10通过商户POS终端12进行电子交易时,获取监控用交易数据。监控用交易数据在本文中指的是能够确认该次交易是否有误的一些关键数据,比如数额、商户名称等。在步骤22,监控模块100进一步调用设置在用户终端10中的可信根,将获取的监控用交易数据加密。在步骤24,监控模块100基于所述监控用交易数据,监控电子现金服务应用模块102中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。根据本发明的示例,电子现金服务应用模块102中的现金数额会随着交易数额而发生变化,例如电子现金服务应用模块102中本有1500元的现金数额,在交易了500元之后,则变成1000元的现金数额,以及金额的变动为500。如果监控模块100监控到电子现金服务应用模块102中的现金数额变动为1000而非500,则提醒用户交易异常。
可选地,在步骤24确定电子现金服务应用模块中与监控用交易数据相对应的数据的变动出现了与所述监控用交易数据不一致的情况并提醒用户交易异常之后,进到步骤26。在步骤26,在用户被提醒交易异常的情况下,发起纠错请求,该纠错请求例如可通过电子现金服务应用模块102来发起。在步骤28,监控模块100响应于该纠错请求,解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名。在步骤30,由用户终端10将
该签名后的监控用交易数据发送给所述第三方服务器14。在步骤32,第三方服务器14验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器16。在步骤34,该发卡行的服务器16基于该监控用交易数据核对用户的账户交易情况,并对异常情况进行处理,随后,发送相关消息以便用户获悉。例如,在发现交易金额发生变动的情况下,发卡行服务器16对该卡的账户进行对帐处理,并将异常的扣款计入该卡的账户,随后,发送相关消息以便用户获悉。
根据本发明的示例,该电子现金服务应用模块设置在用户终端10的SD存储卡中,在用户终端10为通信设备的情况下,设置在SIM卡或通信设备的SD卡中。
根据本发明的示例,该用户终端的应用系统为可信系统的应用系统,而该可信系统可以是ARM芯片的TrustZone架构或Intel芯片的CSE架构,其它在此未列出的可信系统亦可。
根据本发明的电子交易监控方法的一个更为具体的示例,用户终端10通过NFC模块向商户POS终端通过电子现金服务应用模块进行现金支付。监控模块100访问NFC模块获取监控用交易数据。监控模块100用存储在用户终端10内的可信根加密该监控用交易数据,并存储该监控用交易数据,例如将其存储到存储模块中。监控模块100进一步访问用户终端10的SE装置,获取SE装置内的电子现金服务应用模块102内交易后的数据。监控模块100将监控用交易数据与从SE装置内的电子现金服务应用模块102获得的交易后数据进行对比,如发现交易后数据所呈现的与监控用交易数据相对应的项目的数额或其它信息,与所获取的监控用交易数据有所不同,则确定交易发生异常。
在确定交易发生异常的情况下,监控模块100通过用户终端10向用户发出提示交易异常的警示,例如以信息显示或蜂鸣等。用户可通过用户终端10的电子现金应用服务模块102发起纠错请求。响应于该纠错请求,监控模块100,即读取所存储的与该条交易有关的交易数据,即存储的监控用交易数据,并调用可信根,解密该交易数据并签名。监控模块100进一步将签名后的该交易数据发送给第三方服务器14。第三方服务器14验证该签名的交易数据,并在验证通过的情况下,将交易数据发送给发卡行服务器。该发卡行服务器收到来自第三方服务器14的交易数据后,进行账户对帐处理,例如多扣的交易金额便会计入到用户的主账号。发卡行服务器16可将对帐结果返回给用户,提示纠错成功。
根据本发明,还提供电子交易监控系统。结合图1来阐述该电子交易监控系统。该电子交易监控系统包括设置在用户终端10中的监控模块100,设置在用户终端10中的由第三方服务器14提供的可信根(未图示),设置在用户终端10中的电子现金服务应用模块102。该监控模块100配置成在用户终端10通过商户的相关电子设备12进行电子交易的过程中,
获取监控用交易数据,并调用所述可信根,加密所述监控用信息。例如,监控模块100通过用户终端10用来进行电子数据交易的NFC模块获取监控用交易数据,最后对其加密并存储。
监控模块100还基于监控用交易数据,监控所述电子现金服务应用模块102中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。例如,监控模块100从用户终端10的SE装置,获取SE装置内的电子现金服务应用模块102内交易后的数据。监控模块100将监控用交易数据与从SE装置内的电子现金服务应用模块102获得的交易后数据进行对比,如发现交易后数据所呈现的与监控用交易数据相对应的项目的数额或其它信息,与所获取的监控用交易数据有所不同,则确定交易发生异常。
在交易异常的情况下,电子现金服务应用模块102发起纠错请求。响应于该纠错请求,监控模块100解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名,并将签名后的监控用交易数据发送给所述第三方服务器14。第三方服务器14在收到该签名的监控用交易数据后验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器16。所述发卡行的服务器16配置成基于该监控用交易数据对该卡的账户进行对帐处理,并将异常的扣款计入该卡的账户,随后,发送相关消息以便用户获悉。
根据本发明,用户终端10的应用系统是包含可信系统,例如为ARM芯片的TrustZone架构或Intel芯片的CSE架构,或在此未提到的其它可信系统。
根据本发明的各示例,由于通过监控模块来监控交易数据,并在交易数据异常的情况下,可将交易情况经由第三方发送给发卡行以便其进行核对处理,最终放置误交易的发生,保证了交易安全。
尽管在本发明各示例中,是以NFC模块与POS终端的通信作为示例来说明交易,但也可采用用户终端的其它可通信模块来与POS终端交易。同时,在上文的具体示例中,是以交易数额或金额发生变动来说明交易异常,但也可以是其它交易数据变化产生的交易异常,比如收款方等。
Claims (10)
- 一种电子交易监控方法,该方法包括:在用户终端中设置监控模块及由第三方服务器提供的可信根,所述用户终端中还设置有电子现金服务应用模块;监控模块在所述用户终端通过商户的相关电子设备进行电子交易的过程中,获取监控用交易数据;监控模块调用所述可信根,加密所述监控用交易数据;监控模块基于所述监控用交易数据,监控所述电子现金服务应用模块中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。
- 如权利要求1所述的电子交易监控方法,还包括:在用户被提醒交易异常的情况下,发起纠错请求;响应于该纠错请求,监控模块解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名;将签名后的监控用交易数据发送给所述第三方服务器;所述第三方服务器验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器;所述发卡行的服务器基于该监控用交易数据核对用户的账户交易情况,并对异常情况进行处理,随后,发送相关消息以便用户获悉。
- 如权利要求1或2所述的电子交易监控方法,其特征在于,用户终端通过NFC与商户的POS终端进行电子交易。
- 如权利要求1或2所述的电子交易监控方法,其特征在于,所述电子现金服务应用模块设置在所述用户终端的SD存储卡中,在所述用户终端为通信设备的情况下,设置在SIM卡或所述通信设备的SD卡中。
- 如权利要求1或2所述的电子交易监控方法,其特征在于,所述用户终端的应用系统为可信系统,所述可信系统选择ARM芯片的TrustZone架构或Intel芯片的CSE架构。
- 一种电子交易监控系统,该系统包括:设置在用户终端中的监控模块;设置在用户终端中的由第三方服务器提供的可信根;设置在用户终端中的电子现金服务应用模块;所述监控模块配置成用于在所述用户终端通过商户的相关电子设备进行电子交易的过程中,获取监控用交易数据,并调用所述可信根,加密所述监控用信息;所述监控模块还配置成基于所述监控用交易数据,监控所述电子现金服务应用模块中与监控用交易数据相对应的数据的变动,如果电子现金服务应用模块中与监控用交易数据相对应的数据的变动与所述监控用交易数据不同,则提醒用户交易异常。
- 如权利要求6所述的电子交易监控系统,其特征在于,所述电子交易监控系统还包括第三方的服务器与发卡行的服务器;且所述电子现金服务应用模块被配置成在用户被提醒交易异常的情况下,发起纠错请求;所述监控模块进一步配置成响应于该纠错请求,解密已加密的监控用交易数据,并用所述可信根对该监控用交易数据进行签名,将签名后的监控用交易数据发送给所述第三方服务器;所述第三方服务器设置成在收到该签名的监控用信息后验证该签名并在验证通过的情况下,将该监控用交易数据发送给发卡行的服务器;以及所述发卡行的服务器配置成基于该监控用交易数据核对用户的账户交易情况,并对异常情况进行处理,随后,发送相关消息以便用户获悉。
- 如权利要求6或7所述的电子交易监控系统,其特征在于,用户终端通过NFC与商户的POS终端进行电子交易。
- 如权利要求6或7所述的电子交易监控系统,其特征在于,所述电子现金服务应用模块设置在所述用户终端的SD存储卡中,在所述用户终端为通信设备的情况下,设置在SIM卡或所述通信设备的SD卡中。
- 如权利要求6或7所述的电子交易监控系统,其特征在于,所述用户终端的应用系统为可信系统,所述可信系统选择ARM芯片的TrustZone架构或Intel芯片的CSE架构。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510227631.1 | 2015-05-07 | ||
| CN201510227631.1A CN105590209A (zh) | 2015-05-07 | 2015-05-07 | 电子交易监控方法及系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016177291A1 true WO2016177291A1 (zh) | 2016-11-10 |
Family
ID=55929774
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/080116 Ceased WO2016177291A1 (zh) | 2015-05-07 | 2016-04-25 | 电子交易监控方法及系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105590209A (zh) |
| WO (1) | WO2016177291A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110826994A (zh) * | 2019-11-01 | 2020-02-21 | 腾讯科技(深圳)有限公司 | 一种数据处理方法、装置、设备及存储介质 |
| CN111539736A (zh) * | 2020-04-27 | 2020-08-14 | 中国银行股份有限公司 | 交易的监控方法及相关装置 |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108053214B (zh) * | 2017-12-12 | 2021-11-23 | 创新先进技术有限公司 | 一种虚假交易的识别方法和装置 |
| CN109034821A (zh) * | 2018-06-29 | 2018-12-18 | 深圳春沐源控股有限公司 | 交易监控方法及监控装置、存储介质及服务器 |
| CN110827150B (zh) * | 2019-11-11 | 2023-06-27 | 成都三泰智能设备有限公司 | 一种数字资产存管系统 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101661654A (zh) * | 2008-08-05 | 2010-03-03 | 英赛康特雷斯公司 | 用于保护用可编程便携装置执行的交易的方法 |
| CN103049851A (zh) * | 2012-12-27 | 2013-04-17 | 中国建设银行股份有限公司 | 一种基于交易数据的反欺诈监控方法和装置 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101527024A (zh) * | 2008-03-06 | 2009-09-09 | 同方股份有限公司 | 一种安全网上银行系统及其实现方法 |
| US9436940B2 (en) * | 2012-07-09 | 2016-09-06 | Maxim Integrated Products, Inc. | Embedded secure element for authentication, storage and transaction within a mobile terminal |
| CN103440706B (zh) * | 2013-08-23 | 2015-11-11 | 捷德(中国)信息科技有限公司 | 一种解决金融ic卡qpboc异常交易的方法及装置 |
-
2015
- 2015-05-07 CN CN201510227631.1A patent/CN105590209A/zh active Pending
-
2016
- 2016-04-25 WO PCT/CN2016/080116 patent/WO2016177291A1/zh not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101661654A (zh) * | 2008-08-05 | 2010-03-03 | 英赛康特雷斯公司 | 用于保护用可编程便携装置执行的交易的方法 |
| CN103049851A (zh) * | 2012-12-27 | 2013-04-17 | 中国建设银行股份有限公司 | 一种基于交易数据的反欺诈监控方法和装置 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110826994A (zh) * | 2019-11-01 | 2020-02-21 | 腾讯科技(深圳)有限公司 | 一种数据处理方法、装置、设备及存储介质 |
| CN111539736A (zh) * | 2020-04-27 | 2020-08-14 | 中国银行股份有限公司 | 交易的监控方法及相关装置 |
| CN111539736B (zh) * | 2020-04-27 | 2024-01-23 | 中国银行股份有限公司 | 交易的监控方法及相关装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105590209A (zh) | 2016-05-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113168635B (zh) | 用于非接触式卡的密码认证的系统和方法 | |
| TWI576778B (zh) | 針對遺失的電子裝置停用行動付款 | |
| US20200097960A1 (en) | Methods and systems for provisioning mobile devices with payment credentials | |
| KR102025816B1 (ko) | 보안 요소 없이 사용자 및 모바일 장치를 보안 인증하는 방법 및 시스템 | |
| TWI556178B (zh) | 用於金融交易之攜帶型電子裝置、方法以及電腦程式產品 | |
| JP7594999B2 (ja) | 非接触カードの暗号化認証のためのシステムおよび方法 | |
| US10733598B2 (en) | Systems for storing cardholder data and processing transactions | |
| AU2013298189B2 (en) | Issuing and storing of payment credentials | |
| CN112639854B (zh) | 非接触式卡的密码认证的系统和方法 | |
| EP2962421B1 (en) | Systems, methods and devices for performing passcode authentication | |
| US20140337235A1 (en) | Person-to-person electronic payment processing | |
| CN105518732A (zh) | 基于规则而利用移动装置授权交易 | |
| WO2016177291A1 (zh) | 电子交易监控方法及系统 | |
| JP2025131604A (ja) | 制限された仮想番号を使用したカード発行 | |
| JP2025016511A (ja) | 非接触カードへの潜在的な攻撃を通知するためのシステムおよび方法 | |
| US20250141700A1 (en) | Systems and methods for transaction card-based authentication | |
| GB2544829A (en) | System and method for enabling a secure transaction between users | |
| US20170024729A1 (en) | Secure Transmission of Payment Credentials | |
| EP3853796A1 (en) | A payment authentication device, a payment authentication system and a method of authenticating payment | |
| US12124830B2 (en) | Method and system for configuring a mobile point-of-sales application | |
| CN116097686B (zh) | 安全元件与移动设备的安全端到端配对 | |
| TWM639065U (zh) | 用於進行金融交易的電子裝置及金融交易系統 | |
| JP2026513935A (ja) | 所定の条件を満たすことに応答してモバイルアプリケーションまたはブラウザ拡張を起動するシステムおよび方法 | |
| HK40106150A (zh) | 用於基於交易卡的认证的系统和方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16789285 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 12/01/2018) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16789285 Country of ref document: EP Kind code of ref document: A1 |