WO2017012068A1 - 网上交易方法、装置和系统 - Google Patents

网上交易方法、装置和系统 Download PDF

Info

Publication number
WO2017012068A1
WO2017012068A1 PCT/CN2015/084666 CN2015084666W WO2017012068A1 WO 2017012068 A1 WO2017012068 A1 WO 2017012068A1 CN 2015084666 W CN2015084666 W CN 2015084666W WO 2017012068 A1 WO2017012068 A1 WO 2017012068A1
Authority
WO
WIPO (PCT)
Prior art keywords
server
bank server
bank
data
sent
Prior art date
Application number
PCT/CN2015/084666
Other languages
English (en)
French (fr)
Inventor
张毅
Original Assignee
深圳市银信网银科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市银信网银科技有限公司 filed Critical 深圳市银信网银科技有限公司
Priority to CA2993109A priority Critical patent/CA2993109C/en
Priority to PCT/CN2015/084666 priority patent/WO2017012068A1/zh
Publication of WO2017012068A1 publication Critical patent/WO2017012068A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models

Definitions

  • the present invention relates to the field of Internet technologies, and in particular, to an online transaction method, apparatus, and system.
  • online trading methods mainly use third-party payment platforms.
  • the buyer transfers the transaction funds to the third-party payment platform.
  • the third-party payment platform also stores the relevant information in the transaction.
  • the third-party payment platform transfers the transaction funds to the seller, and the transaction is completed. .
  • the user is exposed to the risk of capital risks, and the transaction funds and transaction information have the risk of being stolen in the third-party payment platform information, and the security is not high. It can be seen that an improved transaction method is needed at this stage to reduce the risk of capital risks and improve the security of transaction information.
  • the technical problem to be solved by the present invention is to provide an online transaction method, apparatus and system to reduce capital risk and improve transaction security.
  • an online transaction method includes the following steps:
  • the commodity server after receiving the order information sent by the client, the commodity server sends the order information to the second bank server. Send a letter of credit certificate request;
  • the second bank server after receiving the request for the bank credit certificate, the second bank server generates a bank certificate to be valid and sends it to the first bank server;
  • the first bank server After receiving the silver credit card sent by the second bank server to be in a valid state, the first bank server obtains the buyer's payment verification information from the client and performs verification;
  • the second bank server updates the status of the received silver letter certificate to the received certificate, and sends the received certificate notification to the commodity server;
  • the commodity server after receiving the first received delivery notification sent by the client, the commodity server sends a second received delivery notification to the first bank server;
  • the first bank server transfers the funds frozen by the buyer account to the seller account of the second bank server.
  • an online transaction method for use in a commodity server, the method comprising the steps of:
  • an online transaction method is provided for application to a second bank server
  • the method includes the following steps:
  • the status of the silver credit card is updated to the received certificate, and the received certificate notification is sent to the commodity server.
  • an online transaction method for application to a first bank server
  • the method includes the following steps:
  • the application is provided to a commodity server, and the apparatus includes the following module: [0026]
  • the first receiving module is configured to receive the order information sent by the client, and the received by the second bank server Notice of the certificate, and the first received notice sent by the client;
  • the certificate requesting module is configured to: after receiving the order information sent by the client, send a silver credit certificate request to the second bank server;
  • the delivery notification module is configured to notify the seller of the delivery after receiving the received notification sent by the second bank server;
  • the second received delivery notification module is configured to send the second received delivery notification to the first bank server after receiving the first received delivery notification sent by the client.
  • an online transaction apparatus for use in a second bank server
  • the device includes the following modules:
  • a second receiving module configured to receive a silver credit certificate request of the commodity server, and a silver credit certificate sent by the first banking server;
  • the silver credit card generating module is configured to generate a silver credit card to be in a valid state after receiving the silver credit card certification request of the commodity server;
  • the silver credit generation module is configured to send the silver credit card to be in a valid state to the first bank server.
  • the received notification notification module is configured to receive the silver letter of the valid state sent by the first bank server
  • an online transaction apparatus for use in a first banking server
  • the device includes the following modules:
  • the third receiving module is configured to receive a silver credit certificate sent by the second bank server to be in a valid state, and a second received delivery notification sent by the commodity server;
  • the verification module is configured to receive the silver certificate sent by the second bank server to be in effect, The client obtains the buyer's payment verification information and verifies it;
  • a freezing module configured to freeze the funds corresponding to the order amount in the buyer account if the verification is passed, and then update the status of the silver credit card to have been validated and sent to the second bank server;
  • the payment module is configured to, after receiving the second received delivery notification sent by the commodity server, transfer the funds frozen by the buyer account to the seller account of the second bank server.
  • an online transaction system comprising a commodity server, a first bank server, and a second bank server, wherein:
  • the commodity server is configured to: after receiving the order information sent by the client, send a silver credit certificate request to the second bank server according to the order information; after receiving the received notification sent by the second bank server, notify The seller delivers; after receiving the first received notification sent by the client, sends a second received notification to the first bank server;
  • the second bank server is configured to: after receiving the silver credit certificate request sent by the commodity server, generate a silver credit certificate to be in a valid state, and send the silver credit card to the first bank server; and receive the second bank server to send After the valid letter of the letter, the status of the received bank letter will be updated to the received certificate, and the received certificate will be sent to the commodity server;
  • the first bank server is configured to: after receiving the silver credit certificate sent by the first bank server to be in a valid state, obtain the buyer's payment verification information from the client and perform verification; if the verification is passed, freeze the order in the buyer account The funds corresponding to the amount, and the status of the bank letter is updated to be valid, sent to the second bank server; after receiving the second received notice sent by the commodity server, the funds frozen by the buyer account are transferred to the second In the seller's account of the bank server.
  • the online transaction method, device and system of the present invention sends a request for a certificate to a second bank server (the seller's bank) to the first bank server (the buyer's bank).
  • the goods notification, the transaction is completed in the interaction of the client, the commodity server, the first bank server, the second bank server, the transaction funds and the transaction information in the transaction process are not transferred to the third-party payment platform, and the bank letter is generated by
  • the actual status of the transaction is monitored, so that there is no deviation between the capital flow and the actual transaction, so that the effective flow of funds to deliver the goods in one hand can effectively reduce the funds. Risk and improve the security of trading information.
  • FIG. 1 is a flowchart of an online transaction method according to an embodiment of the present invention.
  • FIG. 2 is a flow chart of information interaction of another online transaction method according to an embodiment of the present invention.
  • FIG. 3 is a flowchart of a data transmission method according to an embodiment of the present invention.
  • FIG. 4 is a flowchart of an online transaction method applied to a client according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of an online transaction method applied to a commodity server according to an embodiment of the present invention.
  • FIG. 6 is a flowchart of an online transaction method applied to a second bank server according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of an online transaction method applied to a first bank server according to an embodiment of the present invention.
  • FIG. 8 is a system structural diagram of an online transaction system according to an embodiment of the present invention.
  • FIG. 9 is a block diagram of a network transaction system according to an embodiment of the present invention.
  • an online transaction method provided by an embodiment of the present invention includes the following steps: [0057] S101.
  • the client generates an order according to the commodity subscribed by the buyer, and sends the order to the commodity server.
  • the seller pre-stores the product information in the product server, and the buyer communicates with the product server through the client, acquires the product information from the product server, and selects the product to be purchased.
  • the client generates order information based on the item information selected by the buyer, and submits the order information to the product server.
  • the commodity includes a tangible physical product and an intangible service; the commodity information includes information such as the price and parameters of the commodity; the commodity server may be a commercial computer server, or may be a computer server set up by the seller itself; the client is a buyer-operated communication Terminals, including but not limited to mobile devices, tablet devices, computers and other terminal devices.
  • the commodity server sends a silver credit certificate request to the second bank server according to the order information.
  • the silver credit card is an electronic voucher for bank credit commitment payment, which can be understood as an electronic data, can be stored in a computer system and transmitted through a network, and the commodity server knows the second bank server according to the order information (the seller's defect)
  • the server where the bank is located sends a request for a bank letter to the second bank server.
  • the second bank server After receiving the request for the bank certificate, the second bank server generates a bank certificate to be valid and sends the certificate to the first bank server.
  • the second bank server is notified of the first bank server (the server where the buyer's bank is located), and generates a silver letter to be valid according to the request information of the bank letter certificate Certificate Z
  • step S104 After receiving the silver certificate sent by the second bank server to be valid, the first bank server obtains the payment verification information of the buyer from the client and performs verification. If the verification is passed, step S105 is performed.
  • the first bank server After receiving the silver credit card sent by the second bank server to be in a valid state, the first bank server generates payment verification information according to the silver credit card to be in effect, and sends the payment verification information to the client. After receiving the payment verification request entered by the buyer, the client submits the verification request to the first bank server for verification.
  • the payment verification information may be a payment page, and the buyer inputs information such as the verification information and the payment amount on the payment page on the client.
  • the verification information includes at least a bank account and a password, and may further include information such as a verification code, an expiration date, and the like.
  • S105 Freeze the funds corresponding to the order amount in the buyer account, and update the status of the silver credit card to have been validated and sent to the second bank server.
  • the funds corresponding to the order amount in the buyer's bank account are frozen according to the bank letter Z1, and the bank letter Z1 to be validated is updated to the valid bank letter Z2, and will be effective.
  • the silver letter Z2 is sent to the second bank server.
  • the second bank server updates the status of the received valid silver certificate to the received certificate, and sends the received notification to the commodity server.
  • the second bank server updates the status to the received status. And the sent notification is sent to the commodity server, and the commodity server notifies the seller of the delivery after receiving the received notification. [0069] S107. After the buyer confirms the receipt, the client sends the first receipt notification to the commodity server.
  • the commodity server After receiving the first received delivery notification sent by the client, the commodity server sends a second received delivery notification to the first banking server.
  • the commodity server after receiving the first received delivery notification sent by the client, the commodity server sends a second received delivery notification to the first banking server, thereby notifying the first banking server to allocate the payment.
  • the first bank server transfers the funds frozen by the buyer account to the seller account of the second bank server.
  • the first bank server transfers the frozen funds in the buyer's bank account to the seller's bank account, thereby completing the transaction.
  • the method further includes: if the first bank server does not receive the second received notification sent by the commodity server within the preset time zone, After the preset time is exceeded, the funds frozen by the buyer account are transferred to the seller account of the second bank server.
  • the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored by generating the silver credit card, so that the funds flow in the daytime. There is no deviation from the actual transaction, so that the effective flow of funds to deliver the goods in one hand can effectively reduce the risk of funds and improve the security of transaction information.
  • the client, the commodity server, the first bank server, and the second bank server use the digital envelope to secure the communication data after data transmission and data reception. transmission. Thereby further improving the security of data transmission and ensuring the security of transactions.
  • a method for securely transmitting communication data by using digital envelope technology includes the following steps:
  • Step S301 The data sender generates a symmetric key, and the communication data is encrypted by using a symmetric key to form a first ciphertext.
  • the data sender randomly generates a symmetric key every time the data is sent, thereby achieving the effect of dynamic anti-counterfeiting.
  • the data sender After encrypting the communication data, the data sender preferably encrypts the communication data by the AES algorithm using the symmetric key to form the first ciphertext.
  • Step S302 the data sender encrypts the symmetric key by using the public key of the data receiver to form a second secret. Text.
  • Step S303 The data sender signs the first ciphertext and the second ciphertext respectively by using the private key of the data, and then sends the first ciphertext and the second ciphertext to the data receiver.
  • Step S304 After receiving the first ciphertext and the second ciphertext, the data receiver verifies the signatures of the first ciphertext and the second ciphertext by using the public key of the data sender.
  • Step S305 After the verification is passed, the data receiver decrypts the second ciphertext by using its own private key to obtain a symmetric key.
  • Step S306 The data receiver decrypts the first ciphertext by using a symmetric key to obtain communication data.
  • the signing step in step S303 and the verifying sign step in step S304 may also be omitted.
  • a dual-track verification technique is employed. Specifically: in the data transmission process, the monitoring system collects the data sent by the data sender and the data received by the data receiver, and verifies the consistency of the sent data and the received data, and the collected data to be collected. Compare with the received data to determine whether the two are consistent. Thereby determining whether the data has been tampered with during the communication process.
  • a two-network combination technique is employed. That is, the client, the commodity server, the first bank server, and the second bank server communicate through the public network, and the monitoring system communicates with the first bank server and the second bank server respectively through a dedicated line. Thereby further ensuring the security of the transaction.
  • an online transaction method provided by an embodiment of the present invention is applied to a client, and the method includes the following steps:
  • S401 Generate order information according to the goods subscribed by the buyer, and send the order information to the commodity server.
  • an online transaction method provided by an embodiment of the present invention is applied to a commodity server, The method includes the following steps:
  • the silver credit card is an electronic voucher for bank credit commitment payment, which can be understood as an electronic data, can be stored in a computer system and transmitted through a network, and the commodity server learns the second bank server according to the order information, to the second The bank server sends a request for a bank letter.
  • the commodity server notifying the seller of the shipment includes but is not limited to any one or more of the following manners: sending an email notification to the email address preset by the seller, Sending a short message notification to the seller's preset mobile number, sending a QQ message to the seller's preset QQ number; or sending a WeChat message to the seller's preset microcode code.
  • the seller arranges the delivery after receiving the delivery notice.
  • an online transaction method provided by an embodiment of the present invention is applied to a second bank server.
  • the method includes the following steps:
  • an online transaction method provided by an embodiment of the present invention is applied to a first bank server.
  • the method includes the following steps:
  • step S701. After receiving the silver certificate to be valid in the second bank server, obtain the payment verification information of the buyer from the client and perform verification. If the verification is passed, go to step S702, otherwise, the process ends.
  • an online transaction system includes a client 10, a merchant server 20, a second bank server 30, and a first bank server 40.
  • the client 10 is configured to acquire the product information from the product server 20, generate an order according to the product subscribed by the buyer, and send the order to the product server 20; after receiving the payment verification request sent by the first bank server 40, input the school The information is sent to the first bank server 40; after receiving the customer receipt confirmation, the goods receipt notification is sent to the product server 20.
  • the online transaction device applied to the client 10 includes the following modules:
  • the order information sending module 101 is configured to obtain the product information from the product server 20, generate an order according to the goods ordered by the buyer, and send the order to the commodity server 20;
  • the verification information sending module 102 is configured to receive the payment verification information sent by the first bank server 40.
  • the first received delivery notification module 103 is configured to send the first received delivery notification to the product server 20 after receiving the customer receipt confirmation.
  • the commodity server 20 is configured to, after receiving the order information sent by the client 10, send a silver credit certificate request to the second bank server 30 according to the order information; and receive the received certificate sent by the second bank server 30. After the notification, the seller is notified of the shipment; after receiving the first received notification sent by the client 10, the second received notification is sent to the first bank server 40.
  • the online transaction device applied to the commodity server 20 includes the following modules:
  • the first receiving module 201 is configured to receive the order information sent by the client 10, the received notification sent by the second bank server 30, and the first received notification sent by the client 10.
  • the certificate requesting module 202 is configured to send a bank letter verification request to the second bank server 30 after receiving the order information sent by the client 10.
  • the delivery notification module 203 is configured to notify the seller of the shipment after receiving the received notification sent by the second bank server 30;
  • the second received delivery notification module 204 is configured to receive the first received notification sent by the client 10, A second received notification is sent to the first bank server 40.
  • the second bank server 30 is configured to: after receiving the silver credit certificate request sent by the commodity server 20, generate a bank certificate to be valid and send it to the first bank server 40; and receive the second bank After the valid silver certificate sent by the server 30, the status of the received valid silver certificate is updated to the received certificate, and the received certificate notification is sent to the commodity server 20.
  • the online transaction apparatus applied to the second bank server 30 includes the following modules: [0124]
  • the second receiving module 301 is configured to receive the silver credit certificate request of the commodity server 20, and A bank letter 40 sent by the bank server 40 in effect.
  • the silver credit generation module 302 is configured to generate a silver credit certificate to be valid after receiving the silver credit certificate request from the commodity server 20.
  • the silver credit generation module 303 is configured to send the silver credential to be valid to the first bank server 40.
  • the received notification notification module 304 is configured to update the status of the silver credit card to the received certificate after receiving the silver certificate of the valid state sent by the first bank server 40, and send the received receipt to the commodity server 20. Notice of the certificate.
  • the first bank server 40 is configured to receive the payment verification information from the client 10 after receiving the silver certificate sent by the first bank server 40, and perform verification; if the verification is passed, the buyer account is frozen.
  • the funds corresponding to the order amount, and the status of the bank letter is updated to be valid, sent to the second bank server 30; after receiving the second received notice sent by the commodity server 20, the funds frozen by the buyer account are transferred Go to the seller account of the second bank server 30.
  • the online transaction apparatus applied to the first bank server 40 includes the following modules: [0130]
  • the third receiving module 401 is configured to receive the silver letter to be valid sent by the second bank server 30. certificate
  • the verification module 402 is configured to receive the silver credit certificate to be valid after being sent by the second bank server 30.
  • the freezing module 403 is configured to freeze the funds corresponding to the order amount in the buyer account if the verification is passed, and then update the status of the bank letter to be valid and send it to the second bank server 30.
  • the payment module 404 is configured to, after receiving the second received delivery notification sent by the commodity server 20, transfer the funds frozen by the buyer account to the seller account of the second bank server 30. [0134] In order to prevent the buyer from receiving the goods receipt confirmation after receiving the goods, the payment module 404 is further configured to: if the first bank server does not receive the second received goods notification sent by the commodity server within the preset time interval , after the default time is exceeded, the funds frozen by the buyer account are transferred to the seller account of the second bank server.
  • the monitoring server 50 is configured to collect data sent by the data sender and data received by the data receiver during the data transmission process, and verify the consistency of the transmitted data and the received data. Wherein, when the client 10, the commodity server 20, the first bank server 40 or the second bank server 30 is transmitting data as a data sender, when the client 10, the commodity server 20, the first bank server 40 or the second bank server 30 is the data receiver after receiving the data.
  • the seller pre-stores the product information in the product server 20, and the buyer communicates with the product server 20 via the client 10, acquires the product information from the product server 20, and selects the product to be purchased.
  • the client 1 0 generates order information based on the item information selected by the buyer, and submits the order information to the item server 20.
  • commodities include tangible physical products and intangible services; commodity information includes information such as price and parameters of commodities.
  • the merchandise server 20 can be a commercial computer server. It can also be a computer server set up by the seller himself.
  • the client 10 is a communication terminal operated by the buyer, including but not limited to a terminal device such as a mobile phone, a tablet device, or a computer.
  • the second bank server 30 refers to the bank server where the buyer's bank account is located
  • the first bank server 40 refers to the bank server where the seller's bank account is located
  • the second bank server 30 and the first bank server 40 may be servers of the same bank. (ie, the buyer and the seller's Seto Bank are the same), or it may be the server of a different bank (ie, the buyer and the seller's Seto Bank are different).
  • a bank letter is an electronic certificate that a bank credit promises to pay. It can be understood as an electronic data that can be stored in a computer system and transmitted over a network.
  • monitoring server 50 is a dual-track verification mechanism that prevents data from being tampered with during communication, and in some embodiments, may be omitted.
  • the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored by generating the silver credit card, so that the funds flow and There is no deviation between the actual transactions, so that the effective flow of funds to deliver the goods in one hand and the next hand is effective, reducing the risk of funds and improving the security of transaction information.
  • the client 10 in order to prevent transaction information from being stolen, the client 10, the commodity server 20, The second bank server 30 and the first bank server 40 are further configured to: securely transmit the communication data using digital envelope technology after data transmission and data reception. Thereby further improving the security of data transmission and ensuring the security of transactions.
  • the client 10 When the client 10, the commodity server 20, the second bank server 30, and the first bank server 40 are used as data senders, it is further configured to: generate a symmetric key, and encrypt the communication data by using a symmetric key to form a first
  • the ciphertext is encrypted by using the public key of the data receiver to form a second ciphertext; the first ciphertext and the second ciphertext are respectively signed by the private key of the data and sent to the data receiver.
  • the data sender randomly generates a symmetric key each time the data is transmitted, thereby achieving the effect of dynamic anti-counterfeiting.
  • the data sender After encrypting the communication data, the data sender preferably encrypts the communication data with the AES algorithm using the symmetric key to form the first ciphertext.
  • the client 10 When the client 10, the commodity server 20, the second bank server 30, and the first bank server 40 are used as data senders, they are also set to:
  • the data sender may not sign the first ciphertext and the second ciphertext, and the corresponding data receiver does not need to perform signature verification on the first ciphertext and the second ciphertext.
  • the two-network combination technology is also used in this embodiment. That is, the client 10, the commodity server 20, the second bank server 30, and the first bank server 40 communicate via a public network, and the monitoring server 50 communicates with the second bank server 30 and the first bank server 40 via a dedicated line, respectively.
  • the online transaction method, device and system of the present invention send a request for a certificate to a second bank server (the seller's bank), and the client sends a receipt notification to the first bank server (the buyer's bank).
  • the transaction is completed in the interaction between the client, the commodity server, the first bank server, and the second bank server, and the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is performed by generating a silver letter certificate.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种网上交易方法、装置和系统,属于互联网技术领域。其中,该方法包括:商品服务器(20)根据客户端(10)发送的订单信息向第二银行服务器(30)发送银信证开证请求;第二银行服务器(30)生成待生效状态的银信证发送给第一银行服务器(40);第一银行服务器(40)向客户端(10)获取买方的付款校验信息并进行验证;如果验证通过,冻结买方账户中订单金额对应的资金,并将已生效的银信证发送给第二银行服务器(30);第二银行服务器(30)向商品服务器(20)发送已收证通知;商品服务器(20)接收到客户端(10)发送的第一已收货通知后,向第一银行服务器(40)发送第二已收货通知;第一银行服务器(40)将买方账户冻结的资金转款到第二银行服务器(30)的卖方账户中。上述方案能有效降低资金风险和提高交易信息的安全性。

Description

说明书 发明名称:网上交易方法、 装置和系统 技术领域
[0001] 本发明涉及互联网技术领域, 尤其涉及一种网上交易方法、 装置和系统。
背景技术
[0002] 随着互联网技术的迅速发展, 电子商务在世界范围内蓬勃兴起, 出现了如亚马 逊、 阿里巴巴、 淘宝等以电子商务为主要运营方式的网上交易平台。 目前, 网 上交易方式主要采用第三方支付平台。 交易过程中, 买方将交易资金转至第三 方支付平台, 第三方支付平台还同吋存储交易中相关的信息, 待买方收货后, 第三方支付平台再将交易资金转给卖方, 至此交易完成。
[0003] 然而, 常常出现以下的情况: 客户尚未收到商户提供的商品或服务, 其资金已 经被第三方支付机构支付给商户; 或者商户提供了商品或服务后, 客户迟迟不 能够支付相应的资金。 由此可知, 由于交易资金流出了银行体系, 银行服务器 的支付完全依赖第三方支付平台的操作, 不利于银行对资金进行监管。 在第三 方支付平台出现上述状况的吋候, 银行服务器并不能做到线下一手交钱一手交 货的有效资金流动, 从而可能导致银行服务器的资金流动吋间和实际交易吋间 偏差很大, 给用户带来资金风险问题, 并且交易资金和交易信息在第三方支付 平台信息有被窃取的风险, 安全性不高。 由此可见, 现阶段需要一种改进的交 易方法, 以降低资金风险问题和提高交易信息安全。
技术问题
[0004] 有鉴于此, 本发明要解决的技术问题是提供一种网上交易方法、 装置和系统,以 降低资金风险和提高交易安全。
问题的解决方案
技术解决方案
[0005] 本发明解决上述技术问题所采用的技术方案如下:
[0006] 根据本发明的一个方面, 提供的一种网上交易方法包括以下步骤:
[0007] 商品服务器接收到客户端发送的订单信息后, 根据订单信息向第二银行服务器 发送银信证幵证请求;
[0008] 第二银行服务器接收到银信证幵证请求后, 生成待生效状态的银信证, 并发送 给第一银行服务器;
[0009] 第一银行服务器接收到第二银行服务器发送的待生效状态的银信证后, 向客户 端获取买方的付款校验信息并进行验证;
[0010] 如果验证通过, 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新 为已生效, 发送给第二银行服务器;
[0011] 第二银行服务器将接收到的已生效的银信证的状态更新为已收证, 并向商品服 务器发送已收证通知;
[0012] 商品服务器在接收到客户端发送的第一已收货通知后, 向第一银行服务器发送 第二已收货通知;
[0013] 第一银行服务器接收到商品服务器发送的第二已收货通知后, 将买方账户冻结 的资金转款到第二银行服务器的卖方账户中。
[0014] 根据本发明的另一个方面, 提供的一种网上交易方法, 应用于商品服务器, 该 方法包括以下步骤:
[0015] 接收到客户端发送的订单信息之后, 向第二银行服务器发送银信证幵证请求;
[0016] 在接收到第二银行服务器发送的已收证通知后, 通知卖方发货;
[0017] 在接收到客户端发送的第一已收货通知后, 向第一银行服务器发送第二已收货 通知。
[0018] 根据本发明的又一个方面, 提供的一种网上交易方法, 应用于第二银行服务器
, 该方法包括以下步骤:
[0019] 接收到商品服务器的银信证幵证请求后, 生成待生效状态的银信证, 并发送给 第一银行服务器;
[0020] 接收到第一银行服务器发送的已生效状态的银信证后, 将银信证的状态更新为 已收证, 并向商品服务器发送已收证通知。
[0021] 根据本发明的再一个方面, 提供的一种网上交易方法, 应用于第一银行服务器
, 该方法包括以下步骤:
[0022] 接收到第二银行服务器发送的待生效状态的银信证后, 向客户端获取买方的付 款校验信息并进行验证;
[0023] 如果验证通过, 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新 为已生效, 发送给第二银行服务器;
[0024] 在接收到商品服务器发送的第二已收货通知后, 将买方账户冻结的资金转款到 第二银行服务器的卖方账户中。
[0025] 根据本发明的再一个方面, 提供的应用于商品服务器, 该装置包括以下模块: [0026] 第一接收模块, 设置为接收客户端发送的订单信息、 第二银行服务器发送的已 收证通知、 以及客户端发送的第一已收货通知;
[0027] 幵证请求模块, 设置为接收到客户端发送的订单信息之后, 向第二银行服务器 发送银信证幵证请求;
[0028] 发货通知模块, 设置为接收到第二银行服务器发送的已收证通知后, 通知卖方 发货;
[0029] 第二已收货通知模块, 设置为接收到客户端发送的第一已收货通知后, 向第一 银行服务器发送第二已收货通知。
[0030] 根据本发明的再一个方面, 提供的一种网上交易装置, 应用于第二银行服务器
, 该装置包括以下模块:
[0031] 第二接收模块, 设置为接收商品服务器的银信证幵证请求、 以及第一银行服务 器发送的已生效状态的银信证;
[0032] 银信证生成模块, 设置为接收到商品服务器的银信证幵证请求后, 生成待生效 状态的银信证;
[0033] 银信证生成模块, 设置为将待生效状态的银信证发送给第一银行服务器。
[0034] 已收证通知模块, 设置为接收到第一银行服务器发送的已生效状态的银信证后
, 将银信证的状态更新为已收证, 并向商品服务器发送已收证通知。
[0035] 根据本发明的再一个方面, 提供的一种网上交易装置, 应用于第一银行服务器
, 该装置包括以下模块:
[0036] 第三接收模块, 设置为接收第二银行服务器发送的待生效状态的银信证、 以及 商品服务器发送的第二已收货通知;
[0037] 验证模块, 设置为接收到第二银行服务器发送的待生效状态的银信证后, 向客 户端获取买方的付款校验信息并进行验证;
[0038] 冻结模块, 设置为如果验证通过, 冻结买方账户中订单金额对应的资金, 然后 将银信证的状态更新为已生效, 并发送给第二银行服务器;
[0039] 划款模块, 设置为接收到商品服务器发送的第二已收货通知后, 将买方账户冻 结的资金转款到第二银行服务器的卖方账户中。
[0040] 根据本发明的再一个方面, 提供的一种网上交易系统, 包括商品服务器、 第一 银行服务器和第二银行服务器, 其中:
[0041] 商品服务器, 设置为接收到客户端发送的订单信息后, 根据订单信息向第二银 行服务器发送银信证幵证请求; 在接收到第二银行服务器发送的已收证通知后 , 通知卖方发货; 在接收到客户端发送的第一已收货通知后, 向第一银行服务 器发送第二已收货通知;
[0042] 第二银行服务器, 设置为接收到商品服务器发送的银信证幵证请求后, 生成待 生效状态的银信证, 并发送给第一银行服务器; 在接收到第二银行服务器发送 的已生效的银信证后, 将接收到的已生效的银信证的状态更新为已收证, 并向 商品服务器发送已收证通知;
[0043] 第一银行服务器, 设置为接收到第一银行服务器发送的待生效状态的银信证后 , 向客户端获取买方的付款校验信息并进行验证; 如果验证通过, 冻结买方账 户中订单金额对应的资金, 并将银信证的状态更新为已生效, 发送给第二银行 服务器; 在接收到商品服务器发送的第二已收货通知后, 将买方账户冻结的资 金转款到第二银行服务器的卖方账户中。
发明的有益效果
有益效果
[0044] 本发明的网上交易方法、 装置和系统, 通过商品服务器向的第二银行服务器 ( 卖方幵户银行) 发送幵证请求, 客户端向第一银行服务器 (买方幵户银行) 发 送已收货通知, 在客户端、 商品服务器、 第一银行服务器、 第二银行服务器的 交互中完成交易, 交易过程中的交易资金和交易信息并未转至第三方支付平台 , 且通过生成银信证对交易状态进行实吋监控, 使得资金流动吋间和实际交易 吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 能有效降低资金 风险和提高交易信息的安全性。
对附图的简要说明
附图说明
[0045] 图 1为本发明实施例提供的一种网上交易方法的流程图。
[0046] 图 2为本发明实施例提供的另一种网上交易方法的信息交互流程图。
[0047] 图 3为本发明实施例提供的一种数据传输方法的流程图。
[0048] 图 4为本发明实施例提供的应用于客户端的网上交易方法的流程图。
[0049] 图 5为本发明实施例提供的应用于商品服务器的网上交易方法的流程图。
[0050] 图 6为本发明实施例提供的应用于第二银行服务器的网上交易方法的流程图。
[0051] 图 7为本发明实施例提供的应用于第一银行服务器的网上交易方法的
[0052] 图 8为本发明实施例提供的网上交易系统的系统结构图。
[0053] 图 9为本发明实施例提供的网上交易系统的模块结构图。
本发明的实施方式
[0054] 为了使本发明所要解决的技术问题、 技术方案及有益效果更加清楚、 明白, 以 下结合附图和实施例, 对本发明进行进一步详细说明。 应当理解, 此处所描述 的具体实施例仅仅用以解释本发明, 并不用于限定本发明。
[0055] 实施例一
[0056] 如图 1和图 2所示, 本发明实施例提供的一种网上交易方法包括以下步骤: [0057] S101、 客户端根据买方预订的商品生成订单, 并发送给商品服务器。
[0058] 具体地, 卖方将商品信息预存到商品服务器中, 买方通过客户端与商品服务器 通信, 从商品服务器获取商品信息, 选择需要购买的商品。 客户端根据买方选 择的商品信息生成订单信息, 并将订单信息提交到商品服务器。 其中, 商品包 括有形的实体产品和无形的服务; 商品信息包括商品的价格、 参数等信息; 商 品服务器可以是商业的计算机服务器, 也可以是卖方自己架设的计算机服务器 ; 客户端是买方操作的通信终端, 包括但不限于手机、 平板设备、 电脑等终端 设备。
[0059] S102、 商品服务器根据订单信息向第二银行服务器发送银信证幵证请求。 [0060] 具体地, 银信证是银行信用承诺支付的电子凭证, 可以理解为一种电子数据, 能存储于计算机系统并通过网络传输, 商品服务器根据订单信息获知第二银行 服务器 (卖方的幵户银行所在的服务器) , 向第二银行服务器发送银信证幵证 请求。
[0061] S103、 第二银行服务器接收到银信证幵证请求后, 生成待生效状态的银信证, 并发送给第一银行服务器。
[0062] 具体地, 第二银行服务器接收到银信证幵证请求后, 获知第一银行服务器 (买 方的幵户银行所在的服务器) , 根据银信证幵证请求信息生成待生效的银信证 Z
1, 将待生效的银信证 Z1发送给第一银行服务。
[0063] S104、 第一银行服务器接收到第二银行服务器发送的待生效状态的银信证后, 向客户端获取买方的付款校验信息并进行验证, 如果验证通过, 执行步骤 S105
, 否则结束流程。
[0064] 具体地, 第一银行服务器接收到第二银行服务器发送的待生效状态的银信证后 , 根据待生效状态的银信证生成付款校验信息, 将付款校验信息发送给客户端 , 客户端接收买方输入的付款校验请求后, 提交给第一银行服务器进行验证。 其中, 付款校验信息可以是付款页面, 买方在客户端上通过付款页面上输入校 验信息、 付款金额等信息。 校验信息至少包括银行账户和密码, 还可以进一步 包括验证码、 有效期等信息。
[0065] S105、 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新为已生效 , 发送给第二银行服务器。
[0066] 具体地, 当验证通过后, 根据银信证 Z1冻结买方银行账户中订单金额对应的资 金, 并将待生效的银信证 Z1更新为已生效的银信证 Z2, 并将已生效的银信证 Z2 发送给第二银行服务器。
[0067] S106、 第二银行服务器将接收到的已生效的银信证的状态更新为已收证, 并向 商品服务器发送已收证通知。
[0068] 具体地, 第二银行服务器将接收到已生效的银信证后, 将状态更新为已收证状 态。 并向商品服务器发送已收证通知, 商品服务器接收到已收证通知后, 通知 卖方发货。 [0069] S107、 客户端在买方确认收货后, 向商品服务器发送第一已收货通知。
[0070] S108、 商品服务器在接收到客户端发送的第一已收货通知后, 向第一银行服务 器发送第二已收货通知。
[0071] 具体地, 商品服务器在接收到客户端发送的第一已收货通知后, 向第一银行服 务器发送第二已收货通知, 从而通知第一银行服务器划款。
[0072] S109、 第一银行服务器接收到商品服务器发送的第二已收货通知后, 将买方账 户冻结的资金转款到第二银行服务器的卖方账户中。
[0073] 具体地, 第一银行服务器接收到商品服务器发送的第二已收货通知后, 将买方 银行账户中冻结的资金转账至卖方银行账户, 从而完成交易。
[0074] 为了方式买方在收到商品之后不进行已收货确认, 上述方法还包括: 如果第一 银行服务器在预设吋间内没有收到商品服务器发送的第二已收货通知, 则在超 过预设吋间后, 将买方账户冻结的资金转款到第二银行服务器的卖方账户中。
[0075] 本发明实施例的网上交易方法中, 交易过程中的交易资金和交易信息并未转至 第三方支付平台, 且通过生成银信证对交易状态进行实吋监控, 使得资金流动 吋间和实际交易吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 能有效降低资金风险和提高交易信息的安全性。
[0076] 作为一种优选实施例, 为了防止交易信息被窃取, 客户端、 商品服务器、 第一 银行服务器、 第二银行服务器在数据发送和数据接收吋, 采用数字信封的方式 对通信数据进行安全传输。 从而进一步提高数据传输的安全性, 保证交易的安 全性。
[0077] 请参阅图 3, 采用数字信封技术对通信数据进行安全传输的方法, 包括以下步 骤:
[0078] 步骤 S301、 数据发送方生成对称密钥, 利用对称密钥对通信数据进行加密形成 第一密文。
[0079] 为防止对称密钥被窃取, 数据发送方每次发送数据吋, 均随机生成对称密钥, 由此达到动态防伪的效果。 在对通信数据进行加密吋, 数据发送方优选利用对 称密钥以 AES算法对通信数据进行加密形成第一密文。
[0080] 步骤 S302、 数据发送方利用数据接收方的公钥对对称密钥进行加密形成第二密 文。
[0081] 步骤 S303、 数据发送方利用自身的私钥分别对第一密文和第二密文进行签名后 发送给数据接收方。
[0082] 步骤 S304、 数据接收方接收到第一密文和第二密文后, 利用数据发送方的公钥 验证第一密文和第二密文的签名。
[0083] 步骤 S305、 当验证通过后, 数据接收方利用自身的私钥对第二密文解密获得对 称密钥。
[0084] 步骤 S306、 数据接收方利用对称密钥对第一密文解密获得通信数据。
[0085] 在某些实施例中, 也可以省略步骤 S303中的签名步骤和步骤 S304中的验证签名 步骤。
[0086] 作为另一种优选实施例, 为防止数据在通信过程中被篡改后引起的资金安全、 信息安全等问题, 故采用双轨校验技术。 具体为: 在数据传输过程中, 利用监 控系统同吋收集数据发送方所发送的数据和数据接收方所接收的数据, 校验发 送的数据和接收的数据的一致性, 即将收集的发送的数据和接收的数据进行比 较, 判断二者是否一致。 从而判断数据在通信过程中是否被篡改。
[0087] 作为再一种优选实施例, 为平衡通信的方便以及保证数据安全, 采用两网并用 技术。 即客户端、 商品服务器、 第一银行服务器和第二银行服务器之间通过公 网进行通信, 监控系统分别与第一银行服务器和第二银行服务器通过专线进行 通信。 从而进一步保证交易的安全性。
[0088] 实施例二
[0089] 如图 4所示, 本发明实施例提供的一种网上交易方法, 应用于客户端, 该方法 包括以下步骤:
[0090] S401、 根据买方预订的商品生成订单信息, 并发送给商品服务器。
[0091] S402、 接收到第一银行服务器发送的付款校验请求后, 向第一银行服务器反馈 客户输入的付款校验信息。
[0092] S403、 在买方确认收货后, 向商品服务器发送第一已收货通知。
[0093] 实施例三
[0094] 如图 5所示, 本发明实施例提供的一种网上交易方法, 应用于商品服务器, 该 方法包括以下步骤:
[0095] S501、 接收到客户端发送的订单信息之后, 向第二银行服务器发送银信证幵证 请求。
[0096] 具体地, 银信证是银行信用承诺支付的电子凭证, 可以理解为一种电子数据, 能存储于计算机系统并通过网络传输, 商品服务器根据订单信息获知第二银行 服务器, 向第二银行服务器发送银信证幵证请求。
[0097] S502、 在接收到第二银行服务器发送的已收证通知后, 通知卖方发货。
[0098] 具体地, 商品服务器接收到第二银行服务器发送的已收证通知后, 通知卖方发 货包括但不限于以下任意一种或几种方式: 向卖方预设的电子邮箱发送邮件通 知、 向卖方预设的移动号码发送短信通知、 向卖方预设的 QQ号码发送 QQ消息; 或者向卖方预设的微信号码发送微信消息。 卖方收到发货通知后安排发货。
[0099] S503、 在接收到客户端发送的第一已收货通知后, 向第一银行服务器发送第二 已收货通知。
[0100] 实施例四
[0101] 如图 6所示, 本发明实施例提供的一种网上交易方法, 应用于第二银行服务器
, 该方法包括以下步骤:
[0102] S601、 接收到商品服务器的银信证幵证请求后, 生成待生效状态的银信证, 并 发送给第一银行服务器;
[0103] S602、 接收到第一银行服务器发送的已生效状态的银信证后, 将银信证的状态 更新为已收证, 并向商品服务器发送已收证通知。
[0104] 实施例四
[0105] 如图 7所示, 本发明实施例提供的一种网上交易方法, 应用于第一银行服务器
, 该方法包括以下步骤:
[0106] S701、 接收到第二银行服务器发送的待生效状态的银信证后, 向客户端获取买 方的付款校验信息并进行验证, 如果验证通过, 执行步骤 S702, 否则结束流程
[0107] S702、 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新为已生效
, 发送给第二银行服务器。 [0108] S703、 在接收到商品服务器发送的第二已收货通知后, 将买方账户冻结的资金 转款到第二银行服务器的卖方账户中。
[0109] 实施例五
[0110] 如图 8和图 9所示, 本发明实施例提供的一种网上交易系统, 包括客户端 10、 商 品服务器 20、 第二银行服务器 30和第一银行服务器 40。
[0111] 客户端 10, 设置为从商品服务器 20获取商品信息, 根据买方预订的商品生成订 单, 并发送给商品服务器 20; 在接收到第一银行服务器 40发送的付款校验请求 后, 输入校验信息并发送给第一银行服务器 40; 在接收到客户收货确认后, 向 商品服务器 20发送已收货通知。
[0112] 其中, 请参阅图 9, 应用于客户端 10的网上交易装置包括以下模块:
[0113] 订单信息发送模块 101, 设置为从商品服务器 20获取商品信息, 根据买方预订 的商品生成订单, 并发送给商品服务器 20;
[0114] 校验信息发送模块 102, 设置为接收到第一银行服务器 40发送的付款校验信息
, 输入校验信息并发送给第一银行服务器 40;
[0115] 第一已收货通知模块 103, 设置为在接收到客户收货确认后, 向商品服务器 20 发送第一已收货通知。
[0116] 商品服务器 20, 设置为接收到客户端 10发送的订单信息后, 根据订单信息向第 二银行服务器 30发送银信证幵证请求; 在接收到第二银行服务器 30发送的已收 证通知后, 通知卖方发货; 在接收到客户端 10发送的第一已收货通知后, 向第 一银行服务器 40发送第二已收货通知。
[0117] 其中, 请参阅图 9, 应用于商品服务器 20的网上交易装置包括以下模块:
[0118] 第一接收模块 201, 设置为接收客户端 10发送的订单信息、 第二银行服务器 30 发送的已收证通知、 以及客户端 10发送的第一已收货通知;
[0119] 幵证请求模块 202, 设置为接收到客户端 10发送的订单信息之后, 向第二银行 服务器 30发送银信证幵证请求。
[0120] 发货通知模块 203, 设置为接收到第二银行服务器 30发送的已收证通知后, 通 知卖方发货;
[0121] 第二已收货通知模块 204, 设置为接收到客户端 10发送的第一已收货通知后, 向第一银行服务器 40发送第二已收货通知。
[0122] 第二银行服务器 30, 设置为接收到商品服务器 20发送的银信证幵证请求后, 生 成待生效状态的银信证, 并发送给第一银行服务器 40; 在接收到第二银行服务 器 30发送的已生效的银信证后, 将接收到的已生效的银信证的状态更新为已收 证, 并向商品服务器 20发送已收证通知。
[0123] 其中, 请参阅图 9, 应用于第二银行服务器 30的网上交易装置包括以下模块: [0124] 第二接收模块 301, 设置为接收商品服务器 20的银信证幵证请求、 以及第一银 行服务器 40发送的已生效状态的银信证。
[0125] 银信证生成模块 302, 设置为接收到商品服务器 20的银信证幵证请求后, 生成 待生效状态的银信证。
[0126] 银信证生成模块 303, 设置为将待生效状态的银信证发送给第一银行服务器 40
[0127] 已收证通知模块 304, 设置为接收到第一银行服务器 40发送的已生效状态的银 信证后, 将银信证的状态更新为已收证, 并向商品服务器 20发送已收证通知。
[0128] 第一银行服务器 40, 设置为接收到第一银行服务器 40发送的待生效状态的银信 证后, 向客户端 10获取付款校验信息并进行验证; 如果验证通过, 冻结买方账 户中订单金额对应的资金, 并将银信证的状态更新为已生效, 发送给第二银行 服务器 30; 在接收到商品服务器 20发送的第二已收货通知后, 将买方账户冻结 的资金转款到第二银行服务器 30的卖方账户中。
[0129] 其中, 请参阅图 9, 应用于第一银行服务器 40的网上交易装置包括以下模块: [0130] 第三接收模块 401, 设置为接收第二银行服务器 30发送的待生效状态的银信证
、 以及商品服务器 20发送的第二已收货通知。
[0131] 验证模块 402, 设置为接收到第二银行服务器 30发送的待生效状态的银信证后
, 向客户端 10获取付款校验信息并进行验证。
[0132] 冻结模块 403, 设置为如果验证通过, 冻结买方账户中订单金额对应的资金, 然后将银信证的状态更新为已生效, 并发送给第二银行服务器 30。
[0133] 划款模块 404, 设置为接收到商品服务器 20发送的第二已收货通知后, 将买方 账户冻结的资金转款到第二银行服务器 30的卖方账户中。 [0134] 为了方式买方在收到商品之后不进行已收货确认, 划款模块 404还设置为: 如 果第一银行服务器在预设吋间内没有收到商品服务器发送的第二已收货通知, 则在超过预设吋间后, 将买方账户冻结的资金转款到第二银行服务器的卖方账 户中。
[0135] 监控服务器 50, 设置为在数据传输过程中, 同吋收集数据发送方所发送的数据 和数据接收方所接收的数据, 校验发送的数据和接收的数据的一致性。 其中, 当客户端 10、 商品服务器 20、 第一银行服务器 40或第二银行服务器 30在发送数 据吋为数据发送方, 当客户端 10、 商品服务器 20、 第一银行服务器 40或第二银 行服务器 30在接收数据吋为数据接收方。
[0136] 具体来说, 卖方将商品信息预存到商品服务器 20中, 买方通过客户端 10与商品 服务器 20通信, 从商品服务器 20获取商品信息, 选择需要购买的商品。 客户端 1 0根据买方选择的商品信息生成订单信息, 并将订单信息提交到商品服务器 20。 其中, 商品包括有形的实体产品和无形的服务; 商品信息包括商品的价格、 参 数等信息。 商品服务器 20可以是商业的计算机服务器。 , 也可以是卖方自己架 设的计算机服务器。 客户端 10是买方操作的通信终端, 包括但不限于手机、 平 板设备、 电脑等终端设备。 第二银行服务器 30是指买方的银行账户所在的银行 服务器, 第一银行服务器 40是指卖方的银行账户所在的银行服务器, 第二银行 服务器 30和第一银行服务器 40可能是同一所银行的服务器 (即买方和卖方的幵 户银行相同吋) , 也可能是不同银行的服务器 (即买方和卖方的幵户银行不同 吋) 。 银信证是银行信用承诺支付的电子凭证, 可以理解为一种电子数据, 可 以存储于计算机系统并通过网络传输。
[0137] 其中, 监控服务器 50是防止数据在通信过程中被篡改而设置的双轨校验机制, 在某些实施例中, 可以省略。
[0138] 通过本实施例的网上交易系统, 交易过程中的交易资金和交易信息并未转至第 三方支付平台, 且通过生成银信证对交易状态进行实吋监控, 使得资金流动吋 间和实际交易吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 育 有效降低资金风险和提高交易信息的安全性。
[0139] 作为一种优选实施例, 为了防止交易信息被窃取, 客户端 10、 商品服务器 20、 第二银行服务器 30和第一银行服务器 40还设置为: 在数据发送和数据接收吋, 采用数字信封技术对通信数据进行安全传输。 从而进一步提高数据传输的安全 性, 保证交易的安全性。
[0140] 当客户端 10、 商品服务器 20、 第二银行服务器 30和第一银行服务器 40作为数据 发送方吋, 还设置为: 生成对称密钥, 利用对称密钥对通信数据进行加密形成 第一密文; 利用数据接收方的公钥对对称密钥进行加密形成第二密文; 利用自 身的私钥分别对第一密文和第二密文进行签名后发送给数据接收方。
[0141] 为了进一步防止对称密钥被窃取, 数据发送方每次发送数据吋, 均随机生成对 称密钥, 由此达到动态防伪的效果。 在对通信数据进行加密吋, 数据发送方优 选利用对称密钥以 AES算法对通信数据进行加密形成第一密文。
[0142] 当客户端 10、 商品服务器 20、 第二银行服务器 30和第一银行服务器 40作为数据 发送方吋, 还设置为:
[0143] 接收到第一密文和第二密文后, 利用数据发送方的公钥验证第一密文和第二密 文的签名; 当验证通过后, 利用自身的私钥对第二密文解密获得对称密钥; 利 用对称密钥对第一密文解密获得通信数据。
[0144] 在某些实施例中, 数据发送方也可以不用对第一密文和第二密文进行签名, 相 应的数据接收方则无需对第一密文和第二密文进行签名验证。
[0145] 作为另一种优选实施例, 为平衡通信的方便以及保证数据安全, 本实施例中还 采用两网并用技术。 即客户端 10、 商品服务器 20、 第二银行服务器 30和第一银 行服务器 40之间通过公网进行通信, 监控服务器 50分别与第二银行服务器 30和 第一银行服务器 40通过专线进行通信。
[0146] 需要说明的是, 上述方法实施例中的技术特征在本系统均对应适用, 这里不再 重述。
[0147] 本领域普通技术人员可以理解实现上述实施例方法中的全部或部分步骤是可以 通过程序来控制相关的硬件完成, 所述的程序可以在存储于一计算机可读取存 储介质中, 所述的存储介质, 如 ROM/RAM、 磁盘、 光盘等。
[0148] 以上参照附图说明了本发明的优选实施例, 并非因此局限本发明的权利范围。
本领域技术人员不脱离本发明的范围和实质, 可以有多种变型方案实现本发明 , 比如作为一个实施例的特征可用于另一实施例而得到又一实施例。 凡在运用 本发明的技术构思之内所作的任何修改、 等同替换和改进, 均应在本发明的权 利范围之内。
工业实用性
本发明的网上交易方法、 装置和系统, 通过商品服务器向的第二银行服务器 ( 卖方幵户银行) 发送幵证请求, 客户端向第一银行服务器 (买方幵户银行) 发 送已收货通知, 在客户端、 商品服务器、 第一银行服务器、 第二银行服务器的 交互中完成交易, 交易过程中的交易资金和交易信息并未转至第三方支付平台 , 且通过生成银信证对交易状态进行实吋监控, 使得资金流动吋间和实际交易 吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 能有效降低资金 风险和提高交易信息的安全性, 此外, 采用数字信封和动态防伪技术对通信数 据进行安全传输,能保证通信数据的安全性; 采用双轨校验能防止数据被篡改技 术; 采用两网并用能平衡通信的方便以及安全性。

Claims

权利要求书
[权利要求 1] 一种网上交易方法, 包括以下步骤:
商品服务器接收到客户端发送的订单信息后, 根据所述订单信息向第 二银行服务器发送银信证幵证请求;
所述第二银行服务器接收到所述银信证幵证请求后, 生成待生效状态 的银信证, 并发送给第一银行服务器;
第一银行服务器接收到所述第二银行服务器发送的待生效状态的银信 证后, 向所述客户端获取付款校验信息并进行验证;
如果验证通过, 冻结所述买方账户中订单金额对应的资金, 并将所述 银信证的状态更新为已生效, 发送给第二银行服务器;
所述第二银行服务器将接收到的已生效的银信证的状态更新为已收证
, 并向商品服务器发送已收证通知;
所述商品服务器在接收到客户端发送的第一已收货通知后, 向所述第 一银行服务器发送第二已收货通知;
所述第一银行服务器接收到所述第二已收货通知后, 将所述买方账户 冻结的资金转款到所述第二银行服务器的卖方账户中。
[权利要求 2] 根据权利要求 1所述的网上交易方法, 其中, 该方法还包括: 所述客 户端、 商品服务器、 第一银行服务器、 第二银行服务器在数据发送和 数据接收吋, 采用数字信封的方式对通信数据进行安全传输。
[权利要求 3] 根据权利要求 2所述的网上交易方法, 其中, 所述采用数字信封技术 对通信数据进行安全传输包括:
数据发送方生成对称密钥, 利用所述对称密钥对通信数据进行加密形 成第一密文, 利用数据接收方的公钥对所述对称密钥进行加密形成第 二密文, 将所述第一密文和第二密文发送给数据接收方;
数据接收方利用自身的私钥对所述第二密文解密获得所述对称密钥, 利用所述对称密钥对所述第一密文解密获得所述通信数据。
[权利要求 4] 根据权利要求 3所述的网上交易方法, 其中,
所述将所述第一密文和第二密文发送给数据接收方的步骤之前还包括 : 数据发送方利用自身的私钥分别对所述第一密文和第二密文进行签 名;
所述数据接收方利用自身的私钥对所述第二密文解密获得所述对称密 钥的步骤之前还包括: 数据接收方利用数据发送方的公钥验证所述第 一密文和第二密文的签名。
根据权利要求 3所述的网上交易方法, 其中, 所述数据发送方生成对 称密钥的具体方式为: 所述数据发送方随机动态生成对称密钥。 根据权利要求 3所述的网上交易方法, 其中, 所述利用所述对称密钥 对通信数据进行加密形成第一密文的具体方式为: 利用所述对称密钥 以 AES算法对通信数据进行加密形成第一密文。
根据权利要求 1所述的网上交易方法, 其中, 所述方法还包括: 如果 所述第一银行服务器在预设吋间内没有收到商品服务器发送的第二已 收货通知, 则在超过所述预设吋间后, 将所述买方账户冻结的资金转 款到所述第二银行服务器的卖方账户中。
根据权利要求 1-7任意一项权利要求所述的网上交易方法, 其中, 所 述方法还包括以下步骤:
监控服务器在数据传输过程中, 同吋收集数据发送方所发送的数据和 数据接收方所接收的数据, 校验所述发送的数据和接收的数据的一致 性;
其中, 当所述客户端、 商品服务器、 第一银行服务器或第二银行服务 器在发送数据吋为数据发送方, 当所述客户端、 商品服务器、 第一银 行服务器或第二银行服务器在接收数据吋为数据接收方。
根据权利要求 8所述的网上交易方法, 其中, 所述方法还包括以下步 骤:
所述客户端、 商品服务器、 第一银行服务器和第二银行服务器之间通 过公网进行通信, 所述监控服务器分别与所述第一银行服务器和第二 银行服务器通过专线进行通信。
一种网上交易方法, 应用于商品服务器, 该方法包括以下步骤: 接收到客户端发送的订单信息之后, 向第二银行服务器发送银信证幵 证请求;
在接收到第二银行服务器发送的已收证通知后, 通知卖方发货; 在接收到客户端发送的第一已收货通知后, 向所述第一银行服务器发 送第二已收货通知。
一种网上交易方法, 应用于第二银行服务器, 该方法包括以下步骤: 接收到商品服务器的银信证幵证请求后, 生成待生效状态的银信证, 并发送给第一银行服务器;
接收到第一银行服务器发送的已生效状态的银信证后, 将所述银信证 的状态更新为已收证, 并向商品服务器发送已收证通知。
一种网上交易方法, 应用于第一银行服务器, 该方法包括以下步骤: 接收到第二银行服务器发送的待生效状态的银信证后, 向所述客户端 获取付款校验信息并进行验证;
如果验证通过, 冻结所述买方账户中订单金额对应的资金, 并将所述 银信证的状态更新为已生效, 发送给第二银行服务器;
在接收到商品服务器发送的第二已收货通知后, 将所述买方账户冻结 的资金转款到所述第二银行服务器的卖方账户中。
一种网上交易装置, 应用于商品服务器, 该装置包括以下模块: 第一接收模块, 设置为接收所述客户端发送的订单信息、 第二银行服 务器发送的已收证通知、 以及客户端发送的第一已收货通知; 幵证请求模块, 设置为接收到所述客户端发送的订单信息之后, 向第 二银行服务器发送银信证幵证请求;
发货通知模块, 设置为接收到第二银行服务器发送的已收证通知后, 通知卖方发货;
第二已收货通知模块, 设置为接收到客户端发送的第一已收货通知后 , 向所述第一银行服务器发送第二已收货通知。
一种网上交易装置, 应用于第二银行服务器, 该装置包括以下模块: 第二接收模块, 设置为接收商品服务器的银信证幵证请求、 以及第一 银行服务器发送的已生效状态的银信证;
银信证生成模块, 设置为接收到商品服务器的银信证幵证请求后, 生 成待生效状态的银信证, 并发送给第一银行服务器;
银信证生成模块, 设置为将待生效状态的银信证发送给第一银行服务 器;
已收证通知模块, 设置为接收到第一银行服务器发送的已生效状态的 银信证后, 将所述银信证的状态更新为已收证, 并向商品服务器发送 已收证通知。
[权利要求 15] —种网上交易装置, 应用于第一银行服务器, 该装置包括以下模块: 第三接收模块, 设置为接收第二银行服务器发送的待生效状态的银信 证、 以及商品服务器发送的第二已收货通知;
验证模块, 设置为接收到所述第二银行服务器发送的待生效状态的银 信证后, 向所述客户端获取付款校验信息并进行验证;
冻结模块, 设置为如果验证通过, 冻结所述买方账户中订单金额对应 的资金, 然后将所述银信证的状态更新为已生效, 并发送给第二银行 服务器;
划款模块, 设置为接收到商品服务器发送的第二已收货通知后, 将所 述买方账户冻结的资金转款到所述第二银行服务器的卖方账户中。
[权利要求 16] —种网上交易系统, 包括商品服务器、 第一银行服务器和第二银行服 务器, 其中:
所述商品服务器, 设置为接收到客户端发送的订单信息后, 根据所述 订单信息向第二银行服务器发送银信证幵证请求; 在接收到第二银行 服务器发送的已收证通知后, 通知卖方发货; 在接收到客户端发送的 第一已收货通知后, 向所述第一银行服务器发送第二已收货通知; 所述第二银行服务器, 设置为接收到所述商品服务器发送的银信证幵 证请求后, 生成待生效状态的银信证, 并发送给第一银行服务器; 在 接收到第二银行服务器发送的已生效的银信证后, 将接收到的已生效 的银信证的状态更新为已收证, 并向商品服务器发送已收证通知; 所述第一银行服务器, 设置为接收到第一银行服务器发送的待生效状 态的银信证后, 向所述客户端获取付款校验信息并进行验证; 如果验 证通过, 冻结所述买方账户中订单金额对应的资金, 并将所述银信证 的状态更新为已生效, 发送给第二银行服务器; 在接收到商品服务器 发送的第二已收货通知后, 将所述买方账户冻结的资金转款到所述第 二银行服务器的卖方账户中。
[权利要求 17] 根据权利要求 16所述的网上交易系统, 其中, 所述客户端、 商品服务 器、 第一银行服务器和第二银行服务器还设置为: 在数据发送和数据 接收吋, 采用数字信封技术对通信数据进行安全传输。
[权利要求 18] 根据权利要求 17所述的网上交易系统, 其中,
当所述客户端、 商品服务器、 第一银行服务器和第二银行服务器作为 数据发送方吋, 还设置为: 生成对称密钥, 利用所述对称密钥对通信 数据进行加密形成第一密文, 利用所述数据接收方的公钥对所述对称 密钥进行加密形成第二密文, 将所述第一密文和第二密文发送给所述 数据接收方;
当所述客户端、 商品服务器、 第一银行服务器和第二银行服务器作为 数据发送方吋, 还设置为: 利用自身的私钥对所述第二密文解密获得 所述对称密钥, 利用所述对称密钥对所述第一密文解密获得所述通信 数据。
[权利要求 19] 根据权利要求 18所述的网上交易系统, 其中:
当所述客户端、 商品服务器、 第一银行服务器和第二银行服务器作为 数据发送方吋, 还设置为: 利用自身的私钥分别对所述第一密文和第 二密文进行签名后再发送给所述数据接收方;
当所述客户端、 商品服务器、 第一银行服务器和第二银行服务器作为 数据接收方吋, 还设置为: 利用所述数据发送方的公钥验证所述第一 密文和第二密文的签名, 当验证通过后, 再进行解密操作。
[权利要求 20] 根据权利要求 18所述的网上交易系统, 其中, 当所述客户端、 商品服 务器、 第一银行服务器和第二银行服务器作为数据发送方吋, 还设置 为: 每次发送数据吋随机生成一对称密钥。
[权利要求 21] 根据权利要求 18所述的网上交易系统, 其中, 当所述客户端、 商品服 务器、 第一银行服务器和第二银行服务器作为数据发送方吋, 利用所 述对称密钥以 AES算法对通信数据进行加密形成第一密文。
[权利要求 22] 根据权利要求 16所述的网上交易系统, 其中, 所述第一银行服务器还 设置为: 在预设吋间内没有收到商品服务器发送的第二已收货通知, 则在超过所述预设吋间后, 将所述买方账户冻结的资金转款到所述第 二银行服务器的卖方账户中。
[权利要求 23] 根据权利要求 16-22任意一项权利要求所述的网上交易系统, 其中, 该系统还包括监控服务器, 设置为:
在数据传输过程中, 同吋收集数据发送方所发送的数据和数据接收方 所接收的数据, 校验所述发送的数据和接收的数据的一致性; 其中, 当所述客户端、 商品服务器、 第一银行服务器或第二银行服务 器在发送数据吋为数据发送方, 当所述客户端、 商品服务器、 第一银 行服务器或第二银行服务器在接收数据吋为数据接收方。
[权利要求 24] 根据权利要求 23所述的网上交易系统, 其中, 所述客户端、 商品服务 器、 第一银行服务器和第二银行服务器之间通过公网进行通信, 所述 监控服务器分别与所述第一银行服务器和第二银行服务器通过专线进 行通信。
PCT/CN2015/084666 2015-07-21 2015-07-21 网上交易方法、装置和系统 WO2017012068A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CA2993109A CA2993109C (en) 2015-07-21 2015-07-21 Online transaction method, device and system
PCT/CN2015/084666 WO2017012068A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/084666 WO2017012068A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Publications (1)

Publication Number Publication Date
WO2017012068A1 true WO2017012068A1 (zh) 2017-01-26

Family

ID=57833701

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/084666 WO2017012068A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Country Status (2)

Country Link
CA (1) CA2993109C (zh)
WO (1) WO2017012068A1 (zh)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1845164A (zh) * 2006-04-30 2006-10-11 西安电子科技大学 无需第三方的公平安全电子交易方法
CN101567070A (zh) * 2008-04-24 2009-10-28 中国银联股份有限公司 一种交易数据处理方法、系统及一种支付系统
JP2012174075A (ja) * 2011-02-23 2012-09-10 Dainippon Printing Co Ltd 自動構築システム、自動構築サーバ、およびプログラム
CN102801710A (zh) * 2012-07-04 2012-11-28 北京天龙融和软件有限公司 一种网络交易方法和系统
CN103827903A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种利用网络支付的方法及系统
CN103827902A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种网络支付的方法及系统

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1845164A (zh) * 2006-04-30 2006-10-11 西安电子科技大学 无需第三方的公平安全电子交易方法
CN101567070A (zh) * 2008-04-24 2009-10-28 中国银联股份有限公司 一种交易数据处理方法、系统及一种支付系统
JP2012174075A (ja) * 2011-02-23 2012-09-10 Dainippon Printing Co Ltd 自動構築システム、自動構築サーバ、およびプログラム
CN102801710A (zh) * 2012-07-04 2012-11-28 北京天龙融和软件有限公司 一种网络交易方法和系统
CN103827903A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种利用网络支付的方法及系统
CN103827902A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种网络支付的方法及系统

Also Published As

Publication number Publication date
CA2993109C (en) 2021-12-21
CA2993109A1 (en) 2017-01-26

Similar Documents

Publication Publication Date Title
JP2018185852A (ja) セキュアな遠隔決済取引処理
EP3843023A1 (en) Secure remote payment transaction processing using a secure element
US20100153273A1 (en) Systems for performing transactions at a point-of-sale terminal using mutating identifiers
JP2024003002A (ja) 公正な電子交換を実施するための仮想ブロックチェーンプロトコルの利用
CN114584355A (zh) 一种用于数字货币交易的安全认证方法、装置和系统
WO2017012070A1 (zh) 网上交易方法、装置和系统
WO2017012069A1 (zh) 网上交易方法、装置和系统
WO2017012066A1 (zh) 网上交易方法、装置和系统
WO2017012064A1 (zh) 网上交易方法、装置和系统
WO2017012068A1 (zh) 网上交易方法、装置和系统
CA2993091C (en) Online transaction method, device and system
CA2993112C (en) Online transaction method, device and system
WO2017012063A1 (zh) 网上交易方法、装置和系统
US11842338B2 (en) Payment encryption system
WO2017012065A1 (zh) 网上交易方法、装置和系统
CN102571716A (zh) 适用于网上购物的安全通信方法
KR20060019928A (ko) 전자지불 인증방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15898624

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2993109

Country of ref document: CA

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC , EPO FORM 1205A DATED 03.04.18.

122 Ep: pct application non-entry in european phase

Ref document number: 15898624

Country of ref document: EP

Kind code of ref document: A1