WO2017012069A1 - 网上交易方法、装置和系统 - Google Patents

网上交易方法、装置和系统 Download PDF

Info

Publication number
WO2017012069A1
WO2017012069A1 PCT/CN2015/084667 CN2015084667W WO2017012069A1 WO 2017012069 A1 WO2017012069 A1 WO 2017012069A1 CN 2015084667 W CN2015084667 W CN 2015084667W WO 2017012069 A1 WO2017012069 A1 WO 2017012069A1
Authority
WO
WIPO (PCT)
Prior art keywords
bank server
server
data
client
bank
Prior art date
Application number
PCT/CN2015/084667
Other languages
English (en)
French (fr)
Inventor
张毅
Original Assignee
深圳市银信网银科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市银信网银科技有限公司 filed Critical 深圳市银信网银科技有限公司
Priority to CA2993110A priority Critical patent/CA2993110C/en
Priority to PCT/CN2015/084667 priority patent/WO2017012069A1/zh
Publication of WO2017012069A1 publication Critical patent/WO2017012069A1/zh

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models

Definitions

  • the present invention relates to the field of Internet technologies, and in particular, to an online transaction method, apparatus, and system.
  • online trading methods mainly use third-party payment platforms.
  • the buyer transfers the transaction funds to the third-party payment platform.
  • the third-party payment platform also stores the relevant information in the transaction.
  • the third-party payment platform transfers the transaction funds to the seller, and the transaction is completed. .
  • the user is exposed to the risk of capital risks, and the transaction funds and transaction information have the risk of being stolen in the third-party payment platform information, and the security is not high. It can be seen that an improved transaction method is needed at this stage to reduce the risk of capital risks and improve the security of transaction information.
  • the technical problem to be solved by the present invention is to provide an online transaction method, apparatus and system to reduce capital risk and improve transaction security.
  • an online transaction method comprising the steps of:
  • the client generates order information according to the goods subscribed by the buyer, and sends the order information to the commodity server; [0008] The client sends a request for a silver credit card to the first bank server according to the order information;
  • the first bank server After receiving the request for the bank letter certificate, the first bank server generates a bank letter to be valid;
  • the first bank server obtains the buyer's payment verification information from the client and performs verification
  • the second bank server updates the status of the silver letter certificate to the received certificate, and sends the received certificate notification to the commodity server;
  • the client sends the received delivery notification to the first bank server;
  • the first bank server transfers the funds frozen by the buyer account to the seller account of the second bank server.
  • an online transaction method for a client, the method comprising the following steps:
  • the receipt notification is sent to the first bank server.
  • an online transaction method for use in a first banking server
  • the method includes the following steps:
  • an online transaction apparatus for a client, the apparatus comprising the following modules:
  • an order sending module configured to generate order information according to the goods ordered by the buyer, and send the goods to the goods service Device
  • the verification request module is configured to send a silver credit certificate request to the first bank server according to the order information;
  • the verification information sending module is configured to receive the payment verification request sent by the first bank server , feeding back to the first bank server the payment verification information input by the buyer;
  • the goods receipt notification module is configured to send the received goods notification to the first bank server after the buyer confirms the goods receipt.
  • an online transaction apparatus for use in a first banking server
  • the device includes the following modules:
  • the first receiving module is configured to receive a silver credit certificate request sent by the client, and a received delivery notification sent by the client;
  • the silver credit generation module is configured to generate a silver credit certificate to be valid after receiving the silver credit certificate request sent by the client;
  • the verification module is configured to obtain the payment verification information of the buyer from the client according to the silver certificate to be validated, and perform verification;
  • the freezing module is configured to, if the verification is passed, freeze the funds corresponding to the order amount in the buyer account, update the status of the silver credit card to have been validated, and send it to the second bank server;
  • the payment module is configured to, after receiving the received delivery notification sent by the client, transfer the funds frozen by the buyer account to the seller account of the second bank server.
  • an online transaction system comprising: a commodity server for receiving order information, further comprising a client, a first bank server, and a second bank server, wherein: [0037] a customer End, set to generate order information according to the goods subscribed by the buyer, and send to the commodity server; send a silver letter certificate request to the first bank server according to the order information; also set to the first bank server after the buyer confirms the receipt Send a receipt notification.
  • the first bank server is configured to generate a bank letter to be valid after receiving the request for the bank letter certificate; obtain the buyer's payment verification information from the client and perform verification, and if the verification is passed, freeze the buyer account The funds corresponding to the order amount, and the status of the bank letter is updated to be valid, and sent to the second bank server; after receiving the received goods notification sent by the client, the funds frozen by the buyer account are transferred to the second bank server. In the seller's account.
  • the second bank server is configured to, after receiving the valid silver certificate, update the status of the bank certificate to the received certificate, and send the received certificate notification to the commodity server.
  • the online transaction method, device and system of the present invention send a request for a certificate to the first bank server (the buyer's bank), and send the received goods to the first bank server (the buyer's bank).
  • the transaction is completed in the interaction between the buyer and the seller and their bank, and the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored by generating the silver letter certificate, so that the funds are made.
  • There is no deviation between the liquidity and the actual transaction so that the effective flow of funds to deliver the goods in one hand can effectively reduce the risk of funds and improve the security of transactions.
  • FIG. 1 is a flowchart of an online transaction method according to an embodiment of the present invention.
  • FIG. 2 is a flow chart of information interaction of an online transaction method according to an embodiment of the present invention.
  • FIG. 3 is a flowchart of a data transmission method according to an embodiment of the present invention.
  • FIG. 4 is a flowchart of an online transaction method applied to a client according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of an online transaction method applied to a first bank server according to an embodiment of the present invention.
  • FIG. 6 is a system structural diagram of an online transaction system according to an embodiment of the present invention.
  • FIG. 7 is a block diagram of a network transaction system according to an embodiment of the present invention.
  • an online transaction method provided by an embodiment of the present invention includes the following steps: [0051] S101.
  • a client generates order information according to a product subscribed by a buyer, and sends the order information to the commodity server.
  • the seller pre-stores the product information in the product server, and the buyer communicates with the product server through the client, acquires the product information from the product server, and selects the product to be purchased.
  • the client generates order information based on the item information selected by the buyer, and submits the order information to the product server.
  • the product package Includes tangible physical products and intangible services.
  • Product information includes information such as the price and parameters of the product.
  • the commodity server may be a commercial computer server or a computer server set up by the seller himself.
  • the client is a communication terminal operated by the buyer, including but not limited to a terminal device such as a mobile phone, a tablet device, or a computer.
  • S102 Send a silver credit certificate request to the first bank server according to the order information.
  • the client first bank server (to the server where the buyer's bank is located) sends a silver certificate certificate request, and the bank letter is an electronic certificate paid by the bank credit commitment, which can be understood as an electronic data.
  • the first bank server After receiving the request for the bank certificate, the first bank server generates a bank letter Z1 to be valid according to the request information of the bank letter certificate.
  • step S104 Acquire payment verification information of the buyer to the client and perform verification. If the verification is passed, execute step S105, otherwise, the process ends.
  • the first bank server generates payment verification information according to the silver credit card to be in a valid state, and sends the payment verification information to the client, and the client receives the payment verification information input by the buyer, and submits the first to the first
  • the bank server verifies.
  • the payment verification information may be a payment page, and the buyer inputs information such as verification information and payment amount on the payment page on the client.
  • the verification information includes at least a bank account and a password, and may further include information such as a verification code, an expiration date, and the like.
  • S105 Freeze the funds corresponding to the order amount in the buyer account, update the status of the bank letter to be valid, and send it to the second bank server.
  • the funds corresponding to the order amount in the buyer's bank account are frozen according to the bank letter Z1, and the bank letter Z1 to be validated is updated to the valid bank letter Z2, and will be effective.
  • the silver letter Z2 is sent to the second bank server.
  • the second bank server updates the status of the received silver letter certificate to the received certificate, and sends the received certificate notification to the product server.
  • the second bank server updates the status to the received status. And the sent notification is sent to the commodity server, and the commodity server notifies the seller of the delivery after receiving the notification of the receipt. [0063] S107. After the buyer confirms the receipt, the client sends the received delivery notification to the first bank server.
  • the client After receiving the receipt confirmation input by the buyer, the client sends the receipt notification to the first banking service, thereby notifying the first bank server to make a payment.
  • the first bank server transfers the funds frozen by the buyer account to the seller account of the second bank server.
  • the second bank server transfers the frozen funds in the buyer's bank account to the seller's bank account. Thereby the transaction is completed.
  • the method further includes: if the first bank server does not receive the received goods notification sent by the client within the preset time zone, After setting up the room, the funds frozen by the buyer account are transferred to the seller account of the second bank server.
  • the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored through the generation of the silver credit card, so that the funds flow in the daytime. There is no deviation from the actual transaction, so that the effective flow of funds to deliver the goods in one hand can effectively reduce the risk of funds and improve the security of transaction information.
  • the client, the commodity server, the first bank server, and the second bank server use the digital envelope to secure the communication data after data transmission and data reception. transmission. Thereby further improving the security of data transmission and ensuring the security of transactions.
  • a method for securely transmitting communication data by using digital envelope technology includes the following steps.
  • Step S301 The data sender generates a symmetric key, and the communication data is encrypted by using a symmetric key to form a first ciphertext.
  • the data sender randomly generates a symmetric key every time the data is sent, thereby achieving the effect of dynamic anti-counterfeiting.
  • the data sender After encrypting the communication data, the data sender preferably encrypts the communication data by the AES algorithm using the symmetric key to form the first ciphertext.
  • Step S302 The data sender encrypts the symmetric key by using the public key of the data receiver to form a second ciphertext.
  • Step S103 After the data sender signs the first ciphertext and the second ciphertext respectively by using the private key of the user, Send to the data receiver.
  • Step S304 After receiving the first ciphertext and the second ciphertext, the data receiver verifies the signatures of the first ciphertext and the second ciphertext by using the public key of the data sender.
  • Step S305 After the verification is passed, the data receiver decrypts the second ciphertext by using its own private key to obtain a symmetric key.
  • Step S106 The data receiver decrypts the first ciphertext by using a symmetric key to obtain communication data.
  • the signing step in step S303 and the verifying sign step in step S304 may also be omitted.
  • a dual-track verification technique is employed. Specifically, in the data transmission process, the monitoring system collects the data sent by the data sender and the data received by the data receiver, and checks the consistency of the sent data and the received data, and the collected data to be collected. Compare with the received data to determine whether the two are consistent. Thereby determining whether the data has been tampered with during the communication process.
  • a two-network combination technique is employed. That is, the client, the first bank server, the second bank server, and the commodity server communicate through the public network, and the monitoring system communicates with the first bank server and the second bank server respectively through a dedicated line. Thereby further ensuring the security of the transaction.
  • an online transaction method provided by an embodiment of the present invention is applied to a client, and the method includes the following steps:
  • S401 Generate order information according to the goods reserved by the buyer, and send the order information to the commodity server.
  • the client acquires the item information from the product server, generates order information based on the item subscribed by the buyer, and transmits the order information to the item server.
  • S402. Send a silver credit certificate request to the first bank server according to the order information.
  • Embodiment 3 As shown in FIG. 5, an online transaction method provided by an embodiment of the present invention is applied to a first bank server.
  • the method includes the following steps:
  • step S502. Acquire payment verification information of the buyer to the client and perform verification. If the verification is passed, step S503 is performed, otherwise the process ends.
  • an online transaction system provided by an embodiment of the present invention includes a client 10, a first bank server 20, a second bank server 30, and a commodity server 40.
  • the client 10 is configured to acquire the product information from the product server 40, generate order information according to the product subscribed by the buyer, and send the order information to the commodity server 40; and send a silver credit card certification request to the first bank server 20 according to the order information; It is also used to send a receipt notification to the first bank server 20.
  • the online transaction device applied to the client 10 includes the following modules:
  • the order sending module 101 is set to generate order information according to the goods ordered by the buyer, and sent to the commodity server 40;
  • the certificate requesting module 102 is configured to send a silver credit certificate request to the first bank server 20 according to the order information;
  • the verification information sending module 103 is configured to, after receiving the payment verification information sent by the first bank server 20, feed back the payment verification information input by the buyer to the first bank server 20;
  • the received goods notification module 104 is configured to send the received goods notification to the first bank server 20 after the buyer confirms the receipt.
  • the first bank server 20 is configured to: after receiving the request for the bank credit certificate, generate a bank letter to be valid; obtain the buyer's payment verification information from the client 10 and perform verification, if the verification is passed, freeze the buyer The funds corresponding to the order amount in the account, and the status of the bank letter is updated to be valid, sent to the second bank server 30; after receiving the received goods notification sent by the client, the funds frozen by the buyer account are transferred Go to the seller account of the second bank server 30.
  • the online transaction device applied to the first bank server 20 includes the following modules: [0104]
  • the first receiving module 201 is configured to receive a silver credit certificate request sent by the client 10, and Client 1
  • the silver credit generation module 202 is configured to generate a silver credit certificate to be valid after receiving the silver credit certificate request sent by the client 10;
  • the verification module 203 is configured to obtain the payment verification information of the buyer from the client 10 according to the silver certificate to be validated, and perform verification;
  • the freezing module 204 is set to freeze the funds corresponding to the order amount in the buyer account if the verification is passed, update the status of the silver credit card to have been valid, and send it to the second bank server 30;
  • the payment module 205 is configured to, after receiving the received notification sent by the client 10, transfer the funds frozen by the buyer account to the seller account of the second bank server 30.
  • the payment module 205 is further configured to: if the first bank server does not receive the received delivery notification sent by the client within the preset time, After the preset time is exceeded, the funds frozen by the buyer account are transferred to the seller account of the second bank server.
  • the second bank server 30 is configured to update the status of the silver credit to the received certificate after receiving the valid silver certificate, and send the received notification to the commodity server 40.
  • the online transaction device applied to the second bank server 30 includes the following modules:
  • the second receiving module 301 is configured to receive the valid silver certificate and update the status of the silver certificate to the received certificate.
  • the received notification 302 is set to send the received notification to the commodity server 40.
  • the commodity server 40 is configured to receive the order information sent by the client 10; after receiving the received notification sent by the second banking server 30, notify the seller of the shipment.
  • the online transaction device applied to the commodity server 40 includes the following modules:
  • the third receiving module 401 is configured to receive the order information sent by the client 10 and the received notification sent by the second banking server 30.
  • the delivery notification module 402 is configured to notify the seller of the shipment after receiving the received notification sent by the second bank server 30.
  • the monitoring server 50 is configured to collect data sent by the data sender and data received by the data receiver during the data transmission process, and verify the consistency of the transmitted data and the received data. Wherein, when the client 10, the first bank server 20, the second bank server 30, or the commodity server 40 is transmitting data as a data sender, when the client 10, the first bank server 20, the second bank server 30, or the commodity server 40 is the data receiver after receiving the data.
  • the seller pre-stores the product information in the product server 40, and the buyer communicates with the product server 40 via the client 10, acquires the product information from the product server 40, and selects the product to be purchased.
  • the client 10 generates order information based on the item selected by the buyer, and submits the order information to the item server 40.
  • commodities include tangible physical products and intangible services.
  • Product information includes information such as the price and parameters of the product.
  • the merchandise server 40 may be a commercial computer server or a computer server built by the seller himself.
  • the client 10 is a communication terminal operated by the buyer, including but not limited to a terminal device such as a mobile phone, a tablet device, or a computer.
  • the first bank server 20 refers to the bank server where the buyer's bank account is located
  • the second bank server 30 refers to the bank server where the seller's bank account is located
  • the first bank server 20 and the second bank server 30 may be servers of the same bank. (ie, the buyer and the seller's Seto Bank are the same), or it may be the server of a different bank (ie, the buyer and the seller's Seto Bank are different).
  • a bank letter is an electronic certificate that a bank credit promises to pay. It can be understood as an electronic data that can be stored in a computer system and transmitted over a network.
  • monitoring server 50 is a dual-track verification mechanism that prevents data from being tampered with during communication, and in some embodiments, may be omitted.
  • the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored through the generation of the silver credit card, so that the funds flow and There is no deviation between the actual transactions, so that the effective flow of funds to deliver the goods in one hand and the next hand is effective, reducing the risk of funds and improving the security of transaction information.
  • the client 10 in order to prevent transaction information from being stolen, when the client 10, the first bank server 20, the second bank server 30, and the commodity server 40 are further set to: after data transmission and data reception, Digital envelope technology securely transmits communication data. Thereby further improving the security of data transmission and ensuring the security of transactions.
  • the sending party is further configured to: generate a symmetric key, encrypt the communication data by using a symmetric key to form a first ciphertext; encrypt the symmetric key by using a public key of the data receiver to form a second ciphertext; The private key respectively signs the first ciphertext and the second ciphertext and sends them to the data receiver.
  • the data sender randomly generates a symmetric key each time the data is transmitted, thereby achieving the effect of dynamic anti-counterfeiting.
  • the data sender After encrypting the communication data, the data sender preferably encrypts the communication data with the AES algorithm using the symmetric key to form the first ciphertext.
  • the client 10 When the client 10, the first bank server 20, the second bank server 30, and the commodity server 40 are used as data senders, they are also set to:
  • the data sender may not sign the first ciphertext and the second ciphertext, and the corresponding data receiver does not need to perform signature verification on the first ciphertext and the second ciphertext.
  • the present embodiment in order to balance the convenience of communication and ensure data security, also employs a two-network combination technique. That is, the client 10, the first bank server 20, the second bank server 30, and the commodity server 40 communicate via a public network, and the monitoring server 50 communicates with the first bank server 20 and the second bank server 30 via a dedicated line, respectively.
  • the online transaction method, device and system of the present invention send a request for a certificate to the first bank server (the buyer's bank), and send the received goods to the first bank server (the buyer's bank).
  • the transaction is completed in the interaction between the buyer and the seller and their bank, and the transaction funds and transaction information in the transaction process are not transferred to the third-party payment platform, and the transaction status is monitored by generating the silver letter certificate, so that the funds are made.
  • There is no deviation between the liquidity and the actual transaction so that the effective flow of funds to deliver the goods in one hand can effectively reduce the risk of funds and improve the security of transactions.
  • the use of digital envelopes and dynamic anti-counterfeiting technology for secure transmission of communication data can ensure the security of communication data; the use of dual-track verification can prevent data from being tampered with; the use of two networks can balance the convenience and security of communication.
  • the use of digital envelopes and dynamic anti-counterfeiting technology for secure transmission of communication data can ensure the security of communication data; the use of dual-track verification can prevent data from being tampered with; the use of two networks can balance the convenience and security of communication.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种网上交易方法、装置和系统,属于互联网技术领域。其中,该方法包括:客户端根据买方预订的商品生成订单信息发送给商品服务器(S101),并向第一银行服务器发送银信证开证请求(S102);第一银行服务器生成待生效的银信证(S103),并向客户端获取买方的付款校验信息并进行验证(S104);如果验证通过,冻结买方账户中订单金额对应的资金,将银信证的状态更新为已生效并发送给第二银行服务器(S105);第二银行服务器将接收到的银信证的状态更新为已收证,并向商品服务器发送已收证通知(S106);客户端在买方确认收货后,向第一银行服务器发送已收货通知(S107);第一银行服务器将买方账户冻结的资金转款到卖方账户中(S108)。采用该方法,能有效降低资金风险和提高交易的安全性。

Description

网上交易方法、 装置和系统
技术领域
[0001] 本发明涉及互联网技术领域, 尤其涉及一种网上交易方法、 装置和系统。
背景技术
[0002] 随着互联网技术的迅速发展, 电子商务在世界范围内蓬勃兴起, 出现了如亚马 逊、 阿里巴巴、 淘宝等以电子商务为主要运营方式的网上交易平台。 目前, 网 上交易方式主要采用第三方支付平台。 交易过程中, 买方将交易资金转至第三 方支付平台, 第三方支付平台还同吋存储交易中相关的信息, 待买方收货后, 第三方支付平台再将交易资金转给卖方, 至此交易完成。
[0003] 然而, 常常出现以下的情况: 客户尚未收到商户提供的商品或服务, 其资金已 经被第三方支付机构支付给商户; 或者商户提供了商品或服务后, 客户迟迟不 能够支付相应的资金。 由此可知, 由于交易资金流出了银行体系, 银行服务器 的支付完全依赖第三方支付平台的操作, 不利于银行对资金进行监管。 在第三 方支付平台出现上述状况的吋候, 银行服务器并不能做到线下一手交钱一手交 货的有效资金流动, 从而可能导致银行服务器的资金流动吋间和实际交易吋间 偏差很大, 给用户带来资金风险问题, 并且交易资金和交易信息在第三方支付 平台信息有被窃取的风险, 安全性不高。 由此可见, 现阶段需要一种改进的交 易方法, 以降低资金风险问题和提高交易信息安全。
技术问题
[0004] 有鉴于此, 本发明要解决的技术问题是提供一种网上交易方法、 装置和系统,以 降低资金风险和提高交易安全。
问题的解决方案
技术解决方案
[0005] 本发明解决上述技术问题所采用的技术方案如下:
[0006] 根据本发明的一个方面, 提供的一种网上交易方法, 包括以下步骤:
[0007] 客户端根据买方预订的商品生成订单信息, 并发送给商品服务器; [0008] 客户端根据订单信息向第一银行服务器发送银信证幵证请求;
[0009] 第一银行服务器接收到银信证幵证请求后, 生成待生效的银信证;
[0010] 第一银行服务器向客户端获取买方的付款校验信息并进行验证;
[0011] 如果验证通过, 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新 为已生效, 发送给第二银行服务器;
[0012] 第二银行服务器接收到已生效的银信证后, 将银信证的状态更新为已收证, 并 向商品服务器发送已收证通知;
[0013] 客户端在买方确认收货后, 向第一银行服务器发送已收货通知;
[0014] 第一银行服务器接收到客户端发送的已收货通知后, 将买方账户冻结的资金转 账到第二银行服务器的卖方账户中。
[0015] 根据本发明的一个方面, 提供的一种网上交易方法, 应用于客户端, 该方法包 括以下步骤:
[0016] 根据买方预订的商品生成订单信息, 并发送给商品服务器;
[0017] 根据订单信息向第一银行服务器发送银信证幵证请求;
[0018] 接收到第一银行服务器发送的付款校验请求后, 向第一银行服务器反馈买方输 入的付款校验信息;
[0019] 在买方确认收货后, 向第一银行服务器发送已收货通知。
[0020] 根据本发明的另一个方面, 提供的一种网上交易方法, 应用于第一银行服务器
, 该方法包括以下步骤:
[0021] 接收到客户端发送的银信证幵证请求后, 生成待生效的银信证;
[0022] 向客户端获取买方的付款校验信息并进行验证;
[0023] 如果验证通过, 冻结买方账户中订单金额对应的资金, 并将银信证的状态更新 为已生效, 发送给第二银行服务器;
[0024] 接收到客户端发送的已收货通知后, 将买方账户冻结的资金转账到第二银行服 务器的卖方账户中。
[0025] 根据本发明的又一个方面, 提供的一种网上交易装置, 应用于客户端, 该装置 包括以下模块:
[0026] 订单发送模块, 设置为根据买方预订的商品生成订单信息, 并发送给商品服务 器;
[0027] 幵证请求模块, 设置为根据订单信息向第一银行服务器发送银信证幵证请求; [0028] 校验信息发送模块, 设置为接收到第一银行服务器发送的付款校验请求后, 向 第一银行服务器反馈买方输入的付款校验信息;
[0029] 已收货通知模块, 设置为在买方确认收货后, 向第一银行服务器发送已收货通 知。
[0030] 根据本发明的再一个方面, 提供的一种网上交易装置, 应用于第一银行服务器
, 该装置包括以下模块:
[0031] 第一接收模块, 设置为接收客户端发送的银信证幵证请求、 以及客户端发送的 已收货通知;
[0032] 银信证生成模块, 设置为接收到客户端发送的银信证幵证请求后, 生成待生效 的银信证;
[0033] 验证模块, 设置为根据待生效状态的银信证, 向客户端获取买方的付款校验信 息并进行验证;
[0034] 冻结模块, 设置为如果验证通过, 冻结买方账户中订单金额对应的资金, 将银 信证的状态更新为已生效, 并发送给第二银行服务器;
[0035] 划款模块, 设置为接收到客户端发送的已收货通知后, 将买方账户冻结的资金 转账到第二银行服务器的卖方账户中。
[0036] 根据本发明的再一个方面, 提供的 一种网上交易系统, 包括用于接收订单信 息的商品服务器, 还包括客户端、 第一银行服务器和第二银行服务器, 其中: [0037] 客户端, 设置为根据买方预订的商品生成订单信息, 并发送给商品服务器; 根 据订单信息向第一银行服务器发送银信证幵证请求; 还设置为在买方确认收货 后, 向第一银行服务器发送已收货通知。
[0038] 第一银行服务器, 设置为接收到银信证幵证请求后, 生成待生效的银信证; 向 客户端获取买方的付款校验信息并进行验证, 如果验证通过, 冻结买方账户中 订单金额对应的资金, 并将银信证的状态更新为已生效, 发送给第二银行服务 器; 在接收到客户端发送的已收货通知后, 将买方账户冻结的资金转账到第二 银行服务器的卖方账户中。 [0039] 第二银行服务器, 设置为接收到已生效的银信证后, 将银信证的状态更新为已 收证, 并向商品服务器发送已收证通知。
发明的有益效果
有益效果
[0040] 本发明的网上交易方法、 装置和系统, 通过客户端向的第一银行服务器 (买方 幵户银行) 发送幵证请求, 并向第一银行服务器 (买方幵户银行) 发送已收货 通知, 在买卖双方和其幵户银行的交互中完成交易, 交易过程中的交易资金和 交易信息并未转至第三方支付平台, 且通过生成银信证对交易状态进行实吋监 控, 使得资金流动吋间和实际交易吋间没有偏差, 做到线下一手交钱一手交货 的有效资金流动, 能有效降低资金风险和提高交易的安全性。
[0041] 图 1为本发明实施例提供的一种网上交易方法的流程图。
[0042] 图 2为本发明实施例提供的一种网上交易方法的信息交互流程图。
[0043] 图 3为本发明实施例提供的一种数据传输方法的流程图。
[0044] 图 4为本发明实施例提供的应用于客户端的网上交易方法的流程图。
[0045] 图 5为本发明实施例提供的应用于第一银行服务器的网上交易方法的流程图。
[0046] 图 6为本发明实施例提供的网上交易系统的系统结构图。
[0047] 图 7为本发明实施例提供的网上交易系统的模块结构图。
本发明的实施方式
[0048] 为了使本发明所要解决的技术问题、 技术方案及有益效果更加清楚、 明白, 以 下结合附图和实施例, 对本发明进行进一步详细说明。 应当理解, 此处所描述 的具体实施例仅仅用以解释本发明, 并不用于限定本发明。
[0049] 实施例一
[0050] 如图 1和图 2所示, 本发明实施例提供的一种网上交易方法, 包括以下步骤: [0051] S101、 客户端根据买方预订的商品生成订单信息, 并发送给商品服务器。
[0052] 具体地, 卖方将商品信息预存到商品服务器中, 买方通过客户端与商品服务器 通信, 从商品服务器获取商品信息, 选择需要购买的商品。 客户端根据买方选 择的商品信息生成订单信息, 并将订单信息提交到商品服务器。 其中, 商品包 括有形的实体产品和无形的服务。 商品信息包括商品的价格、 参数等信息。 商 品服务器可以是商业的计算机服务器, 也可以是卖方自己架设的计算机服务器 。 客户端是买方操作的通信终端, 包括但不限于手机、 平板设备、 电脑等终端 设备。
[0053] S102、 根据订单信息向第一银行服务器发送银信证幵证请求。
[0054] 具体地, 客户端第一银行服务器 (向买方的幵户银行所在的服务器)发送银信证 幵证请求, 银信证是银行信用承诺支付的电子凭证, 可以理解为一种电子数据
, 能存储于计算机系统并通过网络传输。
[0055] S103、 第一银行服务器接收到银信证幵证请求后, 生成待生效的银信证。
[0056] 具体地, 第一银行服务器接收到银信证幵证请求后, 根据银信证幵证请求信息 生成待生效的银信证 Zl。
[0057] S104、 向客户端获取买方的付款校验信息并进行验证, 如果验证通过, 执行步 骤 S 105,否则结束流程。
[0058] 具体地, 第一银行服务器根据待生效状态的银信证生成付款校验信息, 将付款 校验信息发送给客户端, 客户端接收买方输入的付款校验信息后, 提交给第一 银行服务器进行验证。 其中, 付款校验信息可以是付款页面, 买方在客户端上 通过付款页面上输入校验信息、 付款金额等信息。 校验信息至少包括银行账户 和密码, 还可以进一步包括验证码、 有效期等信息。
[0059] S105、 冻结买方账户中订单金额对应的资金, 将银信证的状态更新为已生效, 并发送给第二银行服务器。
[0060] 具体地, 当验证通过后, 根据银信证 Z1冻结买方银行账户中订单金额对应的资 金, 并将待生效的银信证 Z1更新为已生效的银信证 Z2, 并将已生效的银信证 Z2 发送给第二银行服务器。
[0061] S106、 第二银行服务器将接收到已生效的银信证的状态更新为已收证, 并向商 品服务器发送已收证通知。
[0062] 具体地, 第二银行服务器将接收到已生效的银信证后, 将状态更新为已收证状 态。 并向商品服务器发送已收证通知, 商品服务器收到已收证通知后, 通知卖 方发货。 [0063] S107、 客户端在买方确认收货后, 向第一银行服务器发送已收货通知。
[0064] 具体地, 客户端接收到买方输入的收货确认后, 向第一银行服务发送已收货通 知, 从而通知第一银行服务器划款。
[0065] S108、 第一银行服务器接收到客户端发送的已收货通知后, 将买方账户冻结的 资金转账到第二银行服务器的卖方账户中。
[0066] 具体地, 第二银行服务器接收到客户端发送的已收货通知后, 将买方银行账户 中冻结的资金转账至卖方银行账户。 从而交易完成。
[0067] 为了防止买方在收到商品后不进行已收货确认, 上述方法还包括: 如果第一银 行服务器在预设吋间内没有收到客户端发送的已收货通知, 则在超过预设吋间 后, 将买方账户冻结的资金转款到第二银行服务器的卖方账户中。
[0068] 本发明实施例的网上交易方法中, 交易过程中的交易资金和交易信息并未转至 第三方支付平台, 且通过生成银信证对交易状态进行实吋监控, 使得资金流动 吋间和实际交易吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 能有效降低资金风险和提高交易信息的安全性。
[0069] 作为一种优选实施例, 为了防止交易信息被窃取, 客户端、 商品服务器、 第一 银行服务器、 第二银行服务器在数据发送和数据接收吋, 采用数字信封的方式 对通信数据进行安全传输。 从而进一步提高数据传输的安全性, 保证交易的安 全性。
[0070] 请参阅图 3, 采用数字信封技术对通信数据进行安全传输的方法包括以下步骤
[0071] 步骤 S301、 数据发送方生成对称密钥, 利用对称密钥对通信数据进行加密形成 第一密文。
[0072] 为防止对称密钥被窃取, 数据发送方每次发送数据吋, 均随机生成对称密钥, 由此达到动态防伪的效果。 在对通信数据进行加密吋, 数据发送方优选利用对 称密钥以 AES算法对通信数据进行加密形成第一密文。
[0073] 步骤 S302、 数据发送方利用数据接收方的公钥对对称密钥进行加密形成第二密 文。
[0074] 步骤 S103、 数据发送方利用自身的私钥分别对第一密文和第二密文进行签名后 发送给数据接收方。
[0075] 步骤 S304、 数据接收方接收到第一密文和第二密文后, 利用数据发送方的公钥 验证第一密文和第二密文的签名。
[0076] 步骤 S305、 当验证通过后, 数据接收方利用自身的私钥对第二密文解密获得对 称密钥。
[0077] 步骤 S106、 数据接收方利用对称密钥对第一密文解密获得通信数据。
[0078] 在某些实施例中, 也可以省略步骤 S303中的签名步骤和步骤 S304中的验证签名 步骤。
[0079] 作为另一种优选实施例, 为防止数据在通信过程中被篡改后引起的资金安全、 信息安全等问题, 故采用双轨校验技术。 具体为, 在数据传输过程中, 利用监 控系统同吋收集数据发送方所发送的数据和数据接收方所接收的数据, 校验发 送的数据和接收的数据的一致性, 即将收集的发送的数据和接收的数据进行比 较, 判断二者是否一致。 从而判断数据在通信过程中是否被篡改。
[0080] 作为再一种优选实施例, 为平衡通信的方便以及保证数据安全, 采用两网并用 技术。 即客户端、 第一银行服务器、 第二银行服务器和商品服务器之间通过公 网进行通信, 监控系统分别与第一银行服务器和第二银行服务器通过专线进行 通信。 从而进一步保证交易的安全性。
[0081] 实施例二
[0082] 如图 4所示, 本发明实施例提供的 一种网上交易方法, 应用于客户端, 该方法 包括以下步骤:
[0083] S401、 根据买方预订的商品生成订单信息, 并发送给商品服务器。
[0084] 具体地, 客户端从商品服务器获取商品信息, 根据买方预订的商品生成订单信 息, 并发送给商品服务器。
[0085] S402、 根据订单信息向第一银行服务器发送银信证幵证请求。
[0086] S403、 接收到第一银行服务器发送的付款校验请求后, 向第一银行服务器反馈 买方输入的付款校验信息。
[0087] S404、 在买方确认收货后, 向第一银行服务器发送已收货通知。
[0088] 实施例三 [0089] 如图 5所示, 本发明实施例提供的一种网上交易方法, 应用于第一银行服务器
, 该方法包括以下步骤:
[0090] S501、 接收到客户端发送的银信证幵证请求后, 生成待生效的银信证。
[0091] S502、 向客户端获取买方的付款校验信息并进行验证, 如果验证通过, 则执行 步骤 S503, 否则结束流程。
[0092] S503、 冻结买方账户中订单金额对应的资金, 将银信证的状态更新为已生效, 并发送给第二银行服务器。
[0093] S504、 接收到客户端发送的已收货通知后, 将买方账户冻结的资金转账到第二 银行服务器的卖方账户中。
[0094] 实施例四
[0095] 如图 6和图 7所示, 本发明实施例提供的一种网上交易系统包括客户端 10、 第一 银行服务器 20、 第二银行服务器 30和商品服务器 40。
[0096] 客户端 10, 设置为从商品服务器 40获取商品信息, 根据买方预订的商品生成订 单信息, 并发送给商品服务器 40; 根据订单信息向第一银行服务器 20发送银信 证幵证请求; 还用于向第一银行服务器 20发送已收货通知。
[0097] 其中, 请参阅图 7, 应用于客户端 10的网上交易装置包括以下模块:
[0098] 订单发送模块 101, 设置为根据买方预订的商品生成订单信息, 并发送给商品 服务器 40;
[0099] 幵证请求模块 102, 设置为根据订单信息向第一银行服务器 20发送银信证幵证 请求;
[0100] 校验信息发送模块 103, 设置为接收到第一银行服务器 20发送的付款校验信息 后, 向第一银行服务器 20反馈买方输入的付款校验信息;
[0101] 已收货通知模块 104, 设置为在买方确认收货后, 向第一银行服务器 20发送已 收货通知。
[0102] 第一银行服务器 20, 设置为接收到银信证幵证请求后, 生成待生效的银信证; 向客户端 10获取买方的付款校验信息并进行验证, 如果验证通过, 冻结买方账 户中订单金额对应的资金, 并将银信证的状态更新为已生效, 发送给第二银行 服务器 30; 在接收到客户端发送的已收货通知后, 将买方账户冻结的资金转款 到第二银行服务器 30的卖方账户中。
[0103] 其中, 请参阅图 7, 应用于第一银行服务器 20的网上交易装置包括以下模块: [0104] 第一接收模块 201, 设置为接收客户端 10发送的银信证幵证请求、 以及客户端 1
0发送的已收货通知;
[0105] 银信证生成模块 202, 设置为接收到客户端 10发送的银信证幵证请求后, 生成 待生效的银信证;
[0106] 验证模块 203, 设置为根据待生效状态的银信证, 向客户端 10获取买方的付款 校验信息并进行验证;
[0107] 冻结模块 204, 设置为如果验证通过, 冻结买方账户中订单金额对应的资金, 将银信证的状态更新为已生效, 并发送给第二银行服务器 30;
[0108] 划款模块 205, 设置为接收到客户端 10发送的已收货通知后, 将买方账户冻结 的资金转账到第二银行服务器 30的卖方账户中。
[0109] 为了防止买方在收到商品后不进行已收货确认, 划款模块 205还设置为: 如果 第一银行服务器在预设吋间内没有收到客户端发送的已收货通知, 则在超过预 设吋间后, 将买方账户冻结的资金转款到第二银行服务器的卖方账户中。
[0110] 第二银行服务器 30, 设置为接收到已生效的银信证后, 将银信证的状态更新为 已收证, 并向商品服务器 40发送已收证通知。
[0111] 其中, 请参阅图 7, 应用于第二银行服务器 30的网上交易装置包括以下模块:
[0112] 第二接收模块 301, 设置为接收已生效的银信证, 并将银信证的状态更新为已 收证。
[0113] 已收证通知 302, 设置为向商品服务器 40发送已收证通知。
[0114] 商品服务器 40, 设置为接收客户端 10发送的订单信息; 在接收到第二银行服务 器 30发送的已收证通知后, 通知卖方发货。
[0115] 其中, 请参阅图 7, 应用于商品服务器 40的网上交易装置包括以下模块:
[0116] 第三接收模块 401, 设置为接收到客户端 10发送的订单信息、 以及第二银行服 务器 30发送的已收证通知。
[0117] 发货通知模块 402, 设置为接收第二银行服务器 30发送的已收证通知后, 通知 卖方发货。 [0118] 监控服务器 50, 设置为在数据传输过程中, 同吋收集数据发送方所发送的数据 和数据接收方所接收的数据, 校验发送的数据和接收的数据的一致性。 其中, 当客户端 10、 第一银行服务器 20、 第二银行服务器 30或商品服务器 40在发送数 据吋为数据发送方, 当客户端 10、 第一银行服务器 20、 第二银行服务器 30或商 品服务器 40在接收数据吋为数据接收方。
[0119] 在本实施例中, 卖方将商品信息预存到商品服务器 40中, 买方通过客户端 10与 商品服务器 40通信, 从商品服务器 40获取商品信息, 选择需要购买的商品。 客 户端 10根据买方选择的商品生成订单信息, 并将订单信息提交到商品服务器 40 。 其中, 商品包括有形的实体产品和无形的服务。 商品信息包括商品的价格、 参数等信息。 商品服务器 40可以是商业的计算机服务器, 也可以是卖方自己架 设的计算机服务器。 客户端 10是买方操作的通信终端, 包括但不限于手机、 平 板设备、 电脑等终端设备。 第一银行服务器 20是指买方的银行账户所在的银行 服务器, 第二银行服务器 30是指卖方的银行账户所在的银行服务器, 第一银行 服务器 20和第二银行服务器 30可能是同一所银行的服务器 (即买方和卖方的幵 户银行相同吋) , 也可能是不同银行的服务器 (即买方和卖方的幵户银行不同 吋) 。 银信证是银行信用承诺支付的电子凭证, 可以理解为一种电子数据, 可 以存储于计算机系统并通过网络传输。
[0120] 其中, 监控服务器 50是防止数据在通信过程中被篡改而设置的双轨校验机制, 在某些实施例中, 可以省略。
[0121] 通过本实施例的网上交易系统, 交易过程中的交易资金和交易信息并未转至第 三方支付平台, 且通过生成银信证对交易状态进行实吋监控, 使得资金流动吋 间和实际交易吋间没有偏差, 做到线下一手交钱一手交货的有效资金流动, 育 有效降低资金风险和提高交易信息的安全性。
[0122] 作为一种优选实施例, 为了防止交易信息被窃取, 当客户端 10、 第一银行服务 器 20、 第二银行服务器 30和商品服务器 40还设置为: 在数据发送和数据接收吋 , 采用数字信封技术对通信数据进行安全传输。 从而进一步提高数据传输的安 全性, 保证交易的安全性。
[0123] 当客户端 10、 第一银行服务器 20、 第二银行服务器 30和商品服务器 40作为数据 发送方吋, 还设置为: 生成对称密钥, 利用对称密钥对通信数据进行加密形成 第一密文; 利用数据接收方的公钥对对称密钥进行加密形成第二密文; 利用自 身的私钥分别对第一密文和第二密文进行签名后发送给数据接收方。
[0124] 为了进一步防止对称密钥被窃取, 数据发送方每次发送数据吋, 均随机生成对 称密钥, 由此达到动态防伪的效果。 在对通信数据进行加密吋, 数据发送方优 选利用对称密钥以 AES算法对通信数据进行加密形成第一密文。
[0125] 当客户端 10、 第一银行服务器 20、 第二银行服务器 30和商品服务器 40作为数据 发送方吋, 还设置为:
[0126] 接收到第一密文和第二密文后, 利用数据发送方的公钥验证第一密文和第二密 文的签名; 当验证通过后, 利用自身的私钥对第二密文解密获得对称密钥; 利 用对称密钥对第一密文解密获得通信数据。
[0127] 在某些实施例中, 数据发送方也可以不用对第一密文和第二密文进行签名, 相 应的数据接收方则无需对第一密文和第二密文进行签名验证。
[0128] 作为另一种优选实施例, 为平衡通信的方便以及保证数据安全, 本实施例还采 用两网并用技术。 即客户端 10、 第一银行服务器 20、 第二银行服务器 30和商品 服务器 40之间通过公网进行通信, 监控服务器 50分别与第一银行服务器 20和第 二银行服务器 30通过专线进行通信。
[0129] 需要说明的是, 上述方法实施例中的技术特征在本系统均对应适用, 这里不再 重述。
[0130] 本领域普通技术人员可以理解实现上述实施例方法中的全部或部分步骤是可以 通过程序来控制相关的硬件完成, 所述的程序可以在存储于一计算机可读取存 储介质中, 所述的存储介质, 如 ROM/RAM、 磁盘、 光盘等。
[0131] 以上参照附图说明了本发明的优选实施例, 并非因此局限本发明的权利范围。
本领域技术人员不脱离本发明的范围和实质内所作的任何修改、 等同替换和改 进, 均应在本发明的权利范围之内。
工业实用性
[0132] 本发明的网上交易方法、 装置和系统, 通过客户端向的第一银行服务器 (买方 幵户银行) 发送幵证请求, 并向第一银行服务器 (买方幵户银行) 发送已收货 通知, 在买卖双方和其幵户银行的交互中完成交易, 交易过程中的交易资金和 交易信息并未转至第三方支付平台, 且通过生成银信证对交易状态进行实吋监 控, 使得资金流动吋间和实际交易吋间没有偏差, 做到线下一手交钱一手交货 的有效资金流动, 能有效降低资金风险和提高交易的安全性。 此外, 采用数字 信封和动态防伪技术对通信数据进行安全传输,能保证通信数据的安全性; 采用 双轨校验能防止数据被篡改技术; 采用两网并用能平衡通信的方便以及安全性 。 此外, 采用数字信封和动态防伪技术对通信数据进行安全传输,能保证通信数 据的安全性; 采用双轨校验能防止数据被篡改技术; 采用两网并用能平衡通信 的方便以及安全性。

Claims

权利要求书
一种网上交易方法, 包括以下步骤:
客户端根据买方预订的商品生成订单信息, 并发送给商品服务器; 所述客户端根据所述订单信息向第一银行服务器发送银信证幵证请求 第一银行服务器接收到所述银信证幵证请求后, 生成待生效的银信证 第一银行服务器向所述客户端获取买方的付款校验信息并进行验证; 如果验证通过, 冻结所述买方账户中订单金额对应的资金, 然后将所 述银信证的状态更新为已生效, 并发送给第二银行服务器; 所述第二银行服务器接收到已生效的银信证后, 将所述银信证的状态 更新为已收证, 并向商品服务器发送已收证通知;
所述客户端在买方确认收货后, 向所述第一银行服务器发送已收货通 知;
所述第一银行服务器接收到所述已收货通知后, 将所述买方账户冻结 的资金转款到所述第二银行服务器的卖方账户中。
根据权利要求 1所述的网上交易方法, 其中, 该方法还包括: 所述客 户端、 商品服务器、 第一银行服务器、 第二银行服务器在数据发送和 数据接收吋, 采用数字信封的方式对通信数据进行安全传输。
根据权利要求 2所述的网上交易方法, 其中, 所述采用数字信封技术 对通信数据进行安全传输包括:
数据发送方生成对称密钥, 利用所述对称密钥对通信数据进行加密形 成第一密文, 利用数据接收方的公钥对所述对称密钥进行加密形成第 二密文, 将所述第一密文和第二密文发送给数据接收方;
数据接收方利用自身的私钥对所述第二密文解密获得所述对称密钥, 利用所述对称密钥对所述第一密文解密获得所述通信数据。
根据权利要求 3所述的网上交易方法, 其中,
所述将所述第一密文和第二密文发送给数据接收方的步骤之前还包括 : 数据发送方利用自身的私钥分别对所述第一密文和第二密文进行签 名;
所述数据接收方利用自身的私钥对所述第二密文解密获得所述对称密 钥的步骤之前还包括: 数据接收方利用数据发送方的公钥验证所述第 一密文和第二密文的签名。
根据权利要求 3所述的网上交易方法, 其中, 所述数据发送方生成对 称密钥的具体方式为: 所述数据发送方随机动态生成对称密钥。 根据权利要求 3所述的网上交易方法, 其中, 所述利用所述对称密钥 对通信数据进行加密形成第一密文的具体方式为: 利用所述对称密钥 以 AES算法对通信数据进行加密形成第一密文。
根据权利要求 1所述的网上交易方法, 其中, 所述方法还包括: 如果 所述第一银行服务器在预设吋间内没有收到客户端发送的已收货通知 , 则在超过所述预设吋间后, 将所述买方账户冻结的资金转款到所述 第二银行服务器的卖方账户中。
根据权利要求 1-7任意一项权利要求所述的网上交易方法, 其中, 所 述方法还包括以下步骤:
监控服务器在数据传输过程中, 同吋收集数据发送方所发送的数据和 数据接收方所接收的数据, 校验所述发送的数据和接收的数据的一致 性;
其中, 当所述客户端、 商品服务器、 第一银行服务器或第二银行服务 器在发送数据吋为数据发送方, 当所述客户端、 商品服务器、 第一银 行服务器或第二银行服务器在接收数据吋为数据接收方。
根据权利要求 8所述的网上交易方法, 其中, 所述方法还包括以下步 骤:
所述客户端、 第一银行服务器、 第二银行服务器和商品服务器之间通 过公网进行通信, 所述监控服务器分别与所述第一银行服务器和第二 银行服务器通过专线进行通信。
一种网上交易方法, 应用于客户端, 该方法包括以下步骤: 根据买方预订的商品生成订单信息, 并发送给商品服务器;
根据所述订单信息向第一银行服务器发送银信证幵证请求; 接收到所述第一银行服务器发送的付款校验请求后, 向所述第一银行 服务器反馈买方输入的付款校验信息;
在买方确认收货后, 向所述第一银行服务器发送已收货通知。
[权利要求 11] 一种网上交易方法, 应用于第一银行服务器, 该方法包括以下步骤: 接收到客户端发送的银信证幵证请求后, 生成待生效的银信证; 向所述客户端获取买方的付款校验信息并进行验证;
如果验证通过, 冻结所述买方账户中订单金额对应的资金, 然后将所 述银信证的状态更新为已生效, 并发送给第二银行服务器; 接收到客户端发送的已收货通知后, 将所述买方账户冻结的资金转款 到所述第二银行服务器的卖方账户中。
[权利要求 12] —种网上交易装置, 应用于客户端, 该装置包括以下模块:
订单发送模块, 设置为根据买方预订的商品生成订单信息, 并发送给 商品服务器;
幵证请求模块, 设置为根据所述订单信息向第一银行服务器发送银信 证幵证请求;
校验信息发送模块, 设置为接收到所述第一银行服务器发送的付款校 验请求后, 向所述第一银行服务器反馈买方输入的付款校验信息; 已收货通知模块, 设置为在买方确认收货后, 向所述第一银行服务器 发送已收货通知。
[权利要求 13] —种网上交易装置, 应用于第一银行服务器, 该装置包括以下模块: 第一接收模块, 设置为接收客户端发送的银信证幵证请求、 以及客户 端发送的已收货通知;
银信证生成模块, 设置为接收到客户端发送的银信证幵证请求后, 生 成待生效的银信证;
验证模块, 设置为根据待生效状态的银信证, 向客户端获取买方的付 款校验信息并进行验证; 冻结模块, 设置为如果验证通过, 冻结买方账户中订单金额对应的资 金, 将银信证的状态更新为已生效, 并发送给第二银行服务器; 划款模块, 设置为接收到客户端发送的已收货通知后, 将买方账户冻 结的资金转账到第二银行服务器的卖方账户中。
一种网上交易系统, 包括用于接收订单信息的商品服务器, 还包括客 户端、 第一银行服务器和第二银行服务器, 其中:
所述客户端, 设置为根据买方预订的商品生成订单信息, 并发送给商 品服务器; 根据所述订单信息向第一银行服务器发送银信证幵证请求 ; 还设置为在买方确认收货后, 向所述第一银行服务器发送已收货通 知;
所述第一银行服务器, 设置为接收到所述银信证幵证请求后, 生成待 生效的银信证; 向所述客户端获取买方的付款校验信息并进行验证, 如果验证通过, 冻结所述买方账户中订单金额对应的资金, 并将所述 银信证的状态更新为已生效, 发送给第二银行服务器; 在接收到客户 端发送的已收货通知后, 将所述买方账户冻结的资金转款到所述第二 银行服务器的卖方账户中;
所述第二银行服务器, 设置为接收到已生效的银信证后, 将所述银信 证的状态更新为已收证, 并向商品服务器发送已收证通知。
根据权利要求 14所述的网上交易系统, 其中, 所述客户端、 第一银行 服务器、 第二银行服务器和商品服务器还设置为: 在数据发送和数据 接收吋, 采用数字信封技术对通信数据进行安全传输。
根据权利要求 15所述的网上交易系统, 其中,
当所述客户端、 第一银行服务器、 第二银行服务器和商品服务器作为 数据发送方吋, 还设置为: 生成对称密钥, 利用所述对称密钥对通信 数据进行加密形成第一密文, 利用所述数据接收方的公钥对所述对称 密钥进行加密形成第二密文, 将所述第一密文和第二密文发送给所述 数据接收方;
当所述客户端、 第一银行服务器、 第二银行服务器和商品服务器作为 数据发送方吋, 还设置为: 利用自身的私钥对所述第二密文解密获得 所述对称密钥, 利用所述对称密钥对所述第一密文解密获得所述通信 数据。
根据权利要求 16所述的网上交易系统, 其中:
当所述客户端、 第一银行服务器、 第二银行服务器和商品服务器作为 数据发送方吋, 还设置为: 利用自身的私钥分别对所述第一密文和第 二密文进行签名后, 再发送给所述数据接收方;
当所述客户端、 第一银行服务器、 第二银行服务器和商品服务器作为 数据接收方吋, 还设置为: 利用所述数据发送方的公钥验证所述第一 密文和第二密文的签名, 当验证通过后, 再进行解密操作。
根据权利要求 16所述的网上交易系统, 其中, 当所述客户端、 第一银 行服务器、 第二银行服务器和商品服务器作为数据发送方吋, 还设置 为: 随机动态生成对称密钥。
根据权利要求 16所述的网上交易系统, 其中, 当所述客户端、 第一银 行服务器、 第二银行服务器和商品服务器作为数据发送方吋, 还设置 为: 利用所述对称密钥以 AES算法对通信数据进行加密形成第一密文 根据权利要求 14所述的网上交易系统, 其中, 所述第一银行服务器还 设置为: 如果在预设吋间内没有收到客户端发送的已收货通知, 则在 超过所述预设吋间后, 将所述买方账户冻结的资金转款到所述第二银 行服务器的卖方账户中。
根据权利要求 14-20任意一项权利要求所述的网上交易系统, 其中, 该系统还包括监控服务器, 设置为:
在数据传输过程中, 同吋收集数据发送方所发送的数据和数据接收方 所接收的数据, 校验所述发送的数据和接收的数据的一致性; 其中, 当所述客户端、 商品服务器、 第一银行服务器或第二银行服务 器在发送数据吋为数据发送方, 当所述客户端、 商品服务器、 第一银 行服务器或第二银行服务器在接收数据吋为数据接收方。 [权利要求 22] 根据权利要求 21所述的网上交易系统, 其中, 所述客户端、 第一银行 服务器、 第二银行服务器和商品服务器之间通过公网进行通信, 所述 监控服务器分别与所述第一银行服务器和第二银行服务器通过专线进 行通信。
PCT/CN2015/084667 2015-07-21 2015-07-21 网上交易方法、装置和系统 WO2017012069A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CA2993110A CA2993110C (en) 2015-07-21 2015-07-21 Online transaction method, device and system
PCT/CN2015/084667 WO2017012069A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/084667 WO2017012069A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Publications (1)

Publication Number Publication Date
WO2017012069A1 true WO2017012069A1 (zh) 2017-01-26

Family

ID=57833741

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/084667 WO2017012069A1 (zh) 2015-07-21 2015-07-21 网上交易方法、装置和系统

Country Status (2)

Country Link
CA (1) CA2993110C (zh)
WO (1) WO2017012069A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114331765A (zh) * 2022-03-03 2022-04-12 北京焦点新干线信息技术有限公司 一种线上交易方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1845164A (zh) * 2006-04-30 2006-10-11 西安电子科技大学 无需第三方的公平安全电子交易方法
JP2012174075A (ja) * 2011-02-23 2012-09-10 Dainippon Printing Co Ltd 自動構築システム、自動構築サーバ、およびプログラム
CN103827903A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种利用网络支付的方法及系统
CN103827902A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种网络支付的方法及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1845164A (zh) * 2006-04-30 2006-10-11 西安电子科技大学 无需第三方的公平安全电子交易方法
JP2012174075A (ja) * 2011-02-23 2012-09-10 Dainippon Printing Co Ltd 自動構築システム、自動構築サーバ、およびプログラム
CN103827903A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种利用网络支付的方法及系统
CN103827902A (zh) * 2013-03-18 2014-05-28 深圳市银信网银科技有限公司 一种网络支付的方法及系统

Also Published As

Publication number Publication date
CA2993110C (en) 2023-01-10
CA2993110A1 (en) 2017-01-26

Similar Documents

Publication Publication Date Title
EP3540671B1 (en) Systems and methods for software based encryption
EP1984890A2 (en) A point-of-sale terminal transaction using mutating identifiers
CN105809417A (zh) 一种安全可信的实时电子支付结算商户终端、用户终端、银行前端系统及系统与方法
JP2024003002A (ja) 公正な電子交換を実施するための仮想ブロックチェーンプロトコルの利用
WO2017012069A1 (zh) 网上交易方法、装置和系统
WO2017012070A1 (zh) 网上交易方法、装置和系统
WO2017012066A1 (zh) 网上交易方法、装置和系统
CA2993091C (en) Online transaction method, device and system
CA2993088C (en) Online transaction method, device and system
CA2993112C (en) Online transaction method, device and system
WO2017012068A1 (zh) 网上交易方法、装置和系统
US11842338B2 (en) Payment encryption system
WO2017012065A1 (zh) 网上交易方法、装置和系统
WO2017012063A1 (zh) 网上交易方法、装置和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15898625

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2993110

Country of ref document: CA

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 15.05.18)

122 Ep: pct application non-entry in european phase

Ref document number: 15898625

Country of ref document: EP

Kind code of ref document: A1