WO2017020417A1 - 一种移动支付方法及可穿戴设备 - Google Patents
一种移动支付方法及可穿戴设备 Download PDFInfo
- Publication number
- WO2017020417A1 WO2017020417A1 PCT/CN2015/091337 CN2015091337W WO2017020417A1 WO 2017020417 A1 WO2017020417 A1 WO 2017020417A1 CN 2015091337 W CN2015091337 W CN 2015091337W WO 2017020417 A1 WO2017020417 A1 WO 2017020417A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- wearable device
- mobile terminal
- module
- identity
- security module
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/321—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wearable devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
- G06Q20/204—Point-of-sale [POS] network systems comprising interface for record bearing medium or carrier for electronic funds transfer or payment credit
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
Definitions
- the present invention relates to the field of communications, and in particular, to a mobile payment method and a wearable device.
- NFC Near Field Communication
- Android 4.4 introduces a new open architecture, namely HCE (Host-based Card Emulation) technology, which is equipped with NFC function.
- HCE HyperText-based Card Emulation
- the HCE mobile terminal does not need to provide a physical SE (Security Elements), which makes the application of the NFC simpler and more flexible.
- HCE technology only simulates the protocol and implementation of NFC and SE communication, that is, the security guarantee of the NFC service is completed by the virtual SE, and the SE is not implemented.
- Existing SE solutions based on HCE technology can be implemented by host-based software emulation or cloud-based servers, but host-based software emulation is simple but not very secure, such as when the system is rooted (getting superuser privileges). There is no precautionary ability, so a secure SE solution is needed.
- the embodiment of the invention provides a mobile payment method and a wearable device, so as to improve the security of the transaction when the HCE mobile terminal performs an NFC transaction.
- a first aspect of the embodiments of the present invention provides a mobile payment method, which is applied to a wearable device, where the wearable device has a security module, including:
- the identity identifier is an identity of a management entity of the security module in the wearable device, transmitting the transaction request instruction to the security module in the wearable device.
- a second aspect of the embodiments of the present invention provides a wearable device, where the wearable device has a security module, including:
- a receiving module configured to receive a transaction request instruction that simulates the mobile terminal based on the host card
- a first acquiring module configured to acquire, according to the transaction request instruction, the identity identifier of the mobile terminal based on the host card
- a first determining module configured to determine whether the identity identifier is an identity identifier of a management entity of the security module in the wearable device
- a delivery module configured to pass the transaction request instruction to the security module in the wearable device if the identity identifier is an identity of a management entity of the security module in the wearable device.
- a transaction request instruction based on a host card emulating a mobile terminal is received, the wearable device has a security module; and the host card is obtained from the transaction request instruction. Simulating an identity of the mobile terminal; and then determining whether the identity is an identity of a management entity of the security module in the wearable device; if the identity is an identity of a management entity of the security module in the wearable device Identifying, the transaction request is delivered to the security module in the wearable device.
- the security of the transaction can be improved when the HCE mobile terminal performs the NFC transaction, and the risk prevention is strong.
- FIG. 1 is a schematic flowchart of a mobile payment method according to a first embodiment of the present invention
- FIG. 1 is a schematic diagram of a mobile payment system according to a fifth embodiment of the present invention.
- FIG. 2 is a schematic flowchart of a mobile payment method according to a second embodiment of the present invention.
- FIG. 2 is a schematic diagram of an interaction process of a mobile payment method according to a second embodiment of the present invention
- FIG. 3 is a schematic flowchart of a mobile payment method according to a third embodiment of the present invention.
- FIG. 3 is a schematic flowchart of a mobile payment method according to a third embodiment of the present invention.
- FIG. 4 is a schematic structural diagram of a wearable device according to a fourth embodiment of the present invention.
- FIG. 5 is a schematic structural diagram of a wearable device according to a fifth embodiment of the present invention.
- FIG. 6 is a schematic structural diagram of a wearable device according to a sixth embodiment of the present invention.
- the embodiment of the invention provides a mobile payment method and a wearable device, so as to improve the security of the transaction when the HCE mobile terminal performs an NFC transaction.
- a mobile payment method includes: receiving a transaction request instruction for simulating a mobile terminal based on a host card; and acquiring, by the transaction request instruction, the identity identifier of the mobile terminal based on the host card; Determining whether the identity identifier is an identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, responding to the transaction request and The external terminal conducts transaction communication.
- FIG. 1-a is a schematic flowchart of a mobile payment method according to a first embodiment of the present invention
- FIG. 1-b is a mobile payment system according to a fifth embodiment of the present invention.
- a mobile payment method provided by the first embodiment of the present invention may include:
- S101 Receive a transaction request instruction that simulates a mobile terminal based on a host card.
- the HCE mobile terminal is a mobile terminal equipped with an NFC function, an HCE function, and a corresponding wireless communication module such as a Bluetooth or a wireless network, and may be a mobile phone, a tablet computer, etc.; but the HCE mobile terminal There is no SE module, and the module that implements the SE function is placed on the wearable device, that is, when the HCE mobile terminal performs contactless payment, the NFC controller of the HCE mobile terminal will support The payment information is routed to the SE module of the wearable device to complete the mobile payment.
- the SE module can be implemented by a hardware chip or by software simulation.
- the wearable device refers to a wearable device having an SE module and supporting a corresponding wireless communication module such as a Bluetooth or a wireless network, and can be a smart bracelet, a smart watch, a ring, etc., thereby utilizing the HCE mobile terminal and an external receiving device. Mobile payment needs to be done through the SE module on the wearable device.
- the external receiving device refers to a device having a reader/writer function, such as a card reader, a POS (point of sales terminal) machine, and the like.
- the HCE mobile terminal and the wearable device implement communication through a wireless communication module such as Bluetooth or a wireless network; the HCE mobile terminal uses NFC to complete contactless mobile payment communication with the external receiving device.
- a wireless communication module such as Bluetooth or a wireless network
- the transaction request instruction is an instruction sent by the HCE mobile terminal to the wearable device for requesting a payment transaction, where the transaction instruction includes the identity information of the HCE mobile terminal, the transaction type, and the like.
- the transaction request instruction may further include other non-sensitive information related to the transaction.
- the NFC controller of the HCE mobile terminal routes the transaction to the SE module of the wearable device, and the HCE mobile terminal can The wearable device sends an instruction to request a payment transaction such that the wearable device will receive a transaction request instruction emulating the mobile terminal based on the host card.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card analog mobile terminal.
- the identity of the HCE mobile terminal is a unique identity of the HCE mobile terminal, and the HCE mobile terminal can be uniquely determined by the identity identifier.
- the HCE mobile terminal can be identified by any one of the mobile device international identification code (IMEI), the physical address (MAC address) or the short-range wireless communication chip serial number (NFC chip ID) of the HCE mobile terminal.
- IMEI mobile device international identification code
- MAC address physical address
- NFC chip ID short-range wireless communication chip serial number
- the HCE mobile terminal is identified by either or both of an IMEI, a MAC address, or an NFC chip ID.
- the management entity of the SE module in the wearable device refers to a management entity that is set in advance by the user and has administrative rights to the SE module in the wearable device, and the management entity may be an HCE mobile terminal.
- the management entity may be one.
- the management entity may be multiple.
- the identity identifier can uniquely identify the HCE mobile terminal, the identity identifier can be used to determine whether the HCE mobile terminal is a management entity of the SE module in the wearable device.
- the identity identifier is an identity of a management entity of the security module in the wearable device, transmitting the transaction request instruction to the security module in the wearable device.
- the NFC controller routes the transaction to the wearable device through the above identity authentication request.
- the wearable device receives the transaction request instruction, and transmits the transaction request instruction to the security module in the wearable device, which is implemented by the security module in the wearable device.
- the SE function of the HCE mobile terminal enables mobile payment transactions between the HCE mobile terminal and the external receiving POS machine.
- the sensitive information is read by using a wireless communication manner such as Bluetooth or Wi-Fi between the HCE mobile terminal and the SE module in the wearable device. .
- the wearable device receives a transaction request instruction that simulates the mobile terminal based on the host card, the wearable device has a security module, and the host card simulation is obtained from the transaction request instruction.
- An identity of the mobile terminal where the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card; and then determining whether the identity identifier is An identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, transmitting the transaction request to the security module in the wearable device .
- the method further includes:
- the host card is prohibited from simulating access of the mobile terminal to the security module in the wearable device.
- the identity of the HEC mobile terminal is not the identity of the management entity of the wearable device preset by the user, for security reasons, the HCE mobile terminal will be prohibited from accessing the SE module in the wearable device.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the user transaction request request from being received again.
- the method further includes:
- the host card emulates the mobile terminal as a management entity of the wearable device, wherein the management entity of the wearable device performs authentication by using the identity of the host card module mobile terminal.
- the pairing instruction is used by the user to select and set an HCE mobile terminal that is paired with the wearable device on the wearable device, that is, to set an HCE mobile terminal that allows access to the SE module in the wearable device.
- the HCE mobile terminal that is bound to the wearable device can be selected, and the HCE mobile terminal is bound to the wearable device, that is, the user selects the SE module in the wearable device.
- the entity is managed so that only the set management entity is allowed to access the SE module in the wearable device.
- the subsequent HCE mobile terminal sends a transaction request instruction to the wearable device, only the HCE mobile terminal bound to the wearable device is allowed to transmit the transaction instruction to the SE module of the wearable device as the management entity of the wearable device, thereby increasing the security of the transaction. Sex.
- the identity identifier may be a unique identity of the HCE mobile terminal, such as an IMEI, a MAC address, and an NFC chip ID.
- the method before the delivering the transaction request to the security module in the wearable device, the method further includes:
- the distance prompt is used to remind the user
- the host card is used to simulate that the distance between the mobile terminal and the wearable device is greater than a preset distance.
- the HCE mobile terminal and the wearable device in order to ensure normal communication between the HCE mobile terminal and the wearable device, it is necessary to preset a preset signal strength between the two, thereby ensuring the wireless signal strength between the HCE mobile terminal and the wearable device, only when two
- the transaction request command is transmitted to the SE module in the wearable device, and the HCE mobile terminal can further complete the NFC mobile payment transaction.
- the HCE mobile terminal and the wearable device communicate with each other through Bluetooth or wireless Wi-Fi, so the closer the distance between the two is, the better the communication signal is, so that it can be between the HCE mobile terminal and the wearable device.
- the signal strength does not reach the preset signal strength, the user is reminded that the distance between the two is too far.
- the user can reduce the distance between the two by moving the HCE terminal or the wearable device to ensure the signal strength between the two and ensure communication security.
- the signal strength is controllable in this way, the NFC transaction is not affected by the payment environment, and the user experience is better.
- the preset signal strength is set by a user, or is performed by the wearable device according to the wearable device and the host card-simulated mobile terminal.
- the communication signal strength is determined in a preset manner.
- the preset signal strength may be set by a user, and the wearable device automatically detects the time after the user selects a suitable distance between the HCE mobile terminal and the wearable device.
- the signal strength, plus the allowed interference range, is the final signal strength that can be traded last.
- the preset signal strength may be self-learned by the wearable device.
- the wearable device automatically counts wireless between the HCE mobile terminal and the wearable device during each transaction.
- the strength of the communication signal looking for a period of time, the signal strength of the transaction tends to be relatively stable, that is, when the fluctuation is small, the lower value is added and the interference range is added as the preset signal strength that can be traded.
- the method further includes:
- the application is prohibited from managing the security module card application in the wearable device.
- the application is prohibited from managing the security module card application in the wearable device, and the user is reminded.
- the access control of the SE module card application in the wearable device by the application on the HCE mobile terminal includes downloading, installing, deleting, and data of the card application data on the SE module.
- Personalization and other related operations that is, the card application on the SE module can be initialized and the data can be modified, deleted or added in the middle.
- the Chinese bank APP (Application) on the HCE mobile terminal may initialize the SE module card application in the wearable device, such as using the Bank of China for mobile for the first time.
- the Chinese bank APP Application
- the Chinese bank APP Application
- the Chinese bank APP on the mobile terminal of the HCE may apply the above-mentioned changes on the sensitive information to the SE module card in the wearable device, such as when the user balances on the APP.
- the APP changes the balance information of the card application of the Bank of China in its relevant SE module.
- the Bank of China APP (Application) on the HCE mobile terminal may change the account in the SE module card application in the wearable device, such as when adding Or, when the account is deleted, since the sensitive information such as the account is stored in the SE module of the wearable device, the account information in the SE module card application in the wearable device is changed by the APP.
- the access control device since the access control of the SE module card application in the wearable device by the APP on the HCE mobile terminal is the access control of the sensitive data, the access control device needs to perform access control authentication on the application on the HCE mobile terminal.
- the APP module application in the wearable device can be accessed by the APP that accesses the control authentication, thereby ensuring the security of the control rules.
- the method before performing the access control authentication on the host-based card emulating an application on the mobile terminal, the method further includes:
- the identity identifier is an identity of a management entity of the security module in the wearable device, triggering, by the wearable device, the step of performing access control authentication on the host computer to simulate an application on the mobile terminal.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip of the host card emulating the mobile terminal.
- the management request instruction is used for management of the HCE mobile terminal requesting access control to the wearable device.
- the wearable device since the wearable device sets the management entity accessing its SE module, it is necessary to determine whether it is the management entity of the SE module in the wearable device by using the identity of the HCE mobile terminal, and if so, allow the HCE to move.
- the terminal manages the SE module in the wearable device, and then further accesses the control and authentication of the SE module card application in the wearable device by the APP on the HCE mobile terminal, thereby making the access security more secure.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the management request instruction of the user from being received again.
- FIG. 2-a is a schematic flowchart of a mobile payment method according to a second embodiment of the present invention
- FIG. 2-b is a mobile diagram according to a second embodiment of the present invention.
- a schematic diagram of the interaction process of the payment method, wherein, as shown in FIG. 2, a mobile payment method provided by the second embodiment of the present invention may include:
- S201 Receive a pairing instruction of a user, where the pairing instruction is used to select a paired host card-based analog mobile terminal for the wearable device.
- the HCE mobile terminal is a mobile terminal equipped with an NFC function, an HCE function, and a corresponding wireless communication module such as a Bluetooth or a wireless network, and may be a mobile phone, a tablet computer, etc.; but the HCE mobile terminal does not have an SE module, and implements the SE function.
- the module is placed on the wearable device, that is, when the HCE mobile terminal performs contactless payment, the NFC controller of the HCE mobile terminal routes the payment information to the SE module of the wearable device to complete the mobile payment, and the SE module can be It can be realized by hardware chip or by software simulation.
- the wearable device refers to a wearable device having an SE module and supporting a corresponding wireless communication module such as a Bluetooth or a wireless network, and can be a smart bracelet, a smart watch, a ring, etc., thereby utilizing the HCE mobile terminal and an external receiving device. Mobile payment needs to be done through the SE module on the wearable device.
- the external receiving device refers to a device having a reader/writer function, such as a card reader, a POS (point of sales terminal) machine, and the like.
- the HCE mobile terminal and the wearable device implement communication through a wireless communication module such as Bluetooth or a wireless network; the HCE mobile terminal uses NFC to complete contactless mobile payment communication with the external receiving device.
- a wireless communication module such as Bluetooth or a wireless network
- the pairing instruction is used by the user to select and set an HCE mobile terminal that is paired with the wearable device on the wearable device, that is, to set an HCE mobile terminal that allows access to the SE module in the wearable device.
- the HCE mobile terminal that is bound to the wearable device can be selected, and the HCE mobile terminal is bound to the wearable device, so that only the set management entity is allowed to access the wearable device.
- the SE module When the subsequent HCE mobile terminal sends a transaction request instruction to the wearable device, only the HCE mobile terminal bound to the wearable device is allowed to transmit the transaction instruction to the SE module of the wearable device as the management entity of the wearable device, thereby increasing the security of the transaction. Sex.
- S202 Determine a management entity that simulates the mobile terminal as a wearable device based on the host card.
- the management entity of the wearable device performs authentication by using the identity of the mobile terminal based on the host card module.
- the management entity of the SE module in the wearable device refers to a management entity that is set in advance by the user and has administrative rights to the SE module in the wearable device, and the management entity may be an HCE mobile terminal.
- the management entity may be one.
- the management entity may be multiple.
- the identity identifier can uniquely identify the HCE mobile terminal, the identity identifier can be used to determine whether the HCE mobile terminal is a management entity of the SE module in the wearable device.
- the user is selected to select the management entity of the SE module in the wearable device, so that only the set management entity is allowed to access the SE module in the wearable device.
- the subsequent HCE mobile terminal sends a transaction request instruction to the wearable device
- only the HCE mobile terminal bound to the wearable device is allowed to transmit the transaction instruction to the SE module of the wearable device as the management entity of the wearable device, thereby increasing the security of the transaction. Sex.
- the transaction request instruction is an instruction sent by the HCE mobile terminal to the wearable device for requesting a payment transaction, where the transaction instruction includes the identity information of the HCE mobile terminal, the transaction type, and the like.
- the transaction request instruction may further include other non-sensitive information related to the transaction.
- the NFC controller of the HCE mobile terminal routes the transaction to the SE module of the wearable device, and the HCE mobile terminal can The wearable device sends an instruction to request a payment transaction such that the wearable device will receive a transaction request instruction emulating the mobile terminal based on the host card.
- the method before the wearable device receives the transaction request instruction of the HCE mobile terminal, the method further includes:
- the identity identifier of the mobile terminal based on the host card, where the identity identifier includes at least the mobile device international identification code, the physical address, and the short-range wireless communication chip of the host card analog mobile terminal One;
- the wearable device performs access control authentication on the host computer to simulate an application on the mobile terminal, where the access control The authentication is used to perform access control authentication on the application module to access the security module card application in the wearable device;
- the application is prohibited from managing the security module card application in the wearable device.
- the identity identifier may be a unique identity of the HCE mobile terminal, such as an IMEI, a MAC address, and an NFC chip ID.
- the application is prohibited from managing the security module card application in the wearable device, and the user is reminded.
- the access control of the SE module card application in the wearable device by the application on the HCE mobile terminal includes downloading, installing, deleting, and data of the card application data on the SE module.
- Personalization and other related operations that is, the card application on the SE module can be initialized and the data can be modified, deleted or added in the middle.
- the Chinese bank APP (Application) on the HCE mobile terminal may initialize the SE module card application in the wearable device, for example, using the Bank of China for mobile payment for the first time.
- the Chinese bank APP Application
- the Chinese bank APP Application on the HCE mobile terminal may initialize the SE module card application in the wearable device, for example, using the Bank of China for mobile payment for the first time.
- the card application data since there is no card application corresponding to the Bank of China in the SE module of the wearable device, it is necessary to download the card application data to the SE module in the wearable device, thereby initializing the card application corresponding to the Bank of China.
- the card application of the SE module in the wearable device is initialized through the above steps, so that the subsequent NFC transaction can be performed, and the identity authentication of the HCE mobile terminal and the access control of the application on the HCE mobile terminal are implemented through the above steps. Authentication ensures the security of the initialization work, thus ensuring the security of subsequent transactions.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip of the host card emulating the mobile terminal.
- the identity of the HCE mobile terminal is a unique identity of the HCE mobile terminal, and the HCE mobile terminal can be uniquely determined by the identity identifier.
- the HCE mobile terminal can be identified by any one of the mobile device international identification code (IMEI), the physical address (MAC address) or the short-range wireless communication chip serial number (NFC chip ID) of the HCE mobile terminal.
- IMEI mobile device international identification code
- MAC address physical address
- NFC chip ID short-range wireless communication chip serial number
- the HCE mobile terminal is identified by either or both of an IMEI, a MAC address, or an NFC chip ID.
- the management entity of the wearable device since the management entity of the wearable device is set in steps S201 and S202, it is determined whether the HCE mobile terminal is a wearable device by using the body identifier of the management entity set above.
- the management entity of the SE module improves security by authenticating the identity of the HCE mobile terminal.
- the identity identifier is an identity of a management entity of the security module in the wearable device, obtaining a host card to simulate a signal strength between the mobile terminal and the wearable device.
- the method further includes:
- the host card is prohibited from simulating access of the mobile terminal to the security module in the wearable device.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the user transaction request request from being received again.
- the identity of the HEC mobile terminal is not the identity of the management entity of the wearable device preset by the user, for security reasons, the HCE mobile terminal will be prohibited from accessing the SE module in the wearable device.
- the sensitive information is read by using a wireless communication manner such as Bluetooth or Wi-Fi between the HCE mobile terminal and the SE module in the wearable device. Therefore, in order to ensure the reliability of the communication, it is necessary to further determine whether the signal strength of the SE module in the HCE mobile terminal and the wearable device is sufficient.
- a wireless communication manner such as Bluetooth or Wi-Fi
- the preset signal strength is set by a user, or is performed by the wearable device according to the wearable device and the host card-simulated mobile terminal.
- the communication signal strength is determined in a preset manner.
- the preset signal strength may be set by a user, and the wearable device automatically detects the time after the user selects a suitable distance between the HCE mobile terminal and the wearable device.
- the signal strength, plus the allowed interference range, is the final signal strength that can be traded last.
- the preset signal strength may be self-learned by the wearable device.
- the wearable device automatically counts wireless between the HCE mobile terminal and the wearable device during each transaction.
- the strength of the communication signal looking for a period of time, the signal strength of the transaction tends to be relatively stable. That is, when the fluctuation is small, the lower value is added and the interference range is added as the preset signal strength that can be traded.
- the HCE mobile terminal and the wearable device in order to ensure normal communication between the HCE mobile terminal and the wearable device, it is necessary to preset a preset signal strength between the two, thereby ensuring the wireless signal strength between the HCE mobile terminal and the wearable device, only when two
- the transaction request command is transmitted to the SE module in the wearable device, and the HCE mobile terminal can further complete the NFC mobile payment transaction.
- the HCE mobile terminal and the wearable device communicate with each other through Bluetooth or wireless Wi-Fi, so the closer the distance between the two is, the better the communication signal is, so that it can be between the HCE mobile terminal and the wearable device.
- the signal strength does not reach the preset signal strength, the user is reminded that the distance between the two is too far.
- the user can reduce the distance between the two by moving the HCE terminal or the wearable device to ensure the signal strength between the two and ensure communication security.
- the signal strength is controllable in this way, the NFC transaction is not affected by the payment environment, and the user experience is better.
- the signal strength is greater than or equal to the preset signal strength, triggering a step of transmitting a transaction request command to the security module in the wearable device. Otherwise, issuing a distance prompt, the distance prompt is used to remind the user of the host card based The distance between the simulated mobile terminal and the wearable device is greater than a preset distance.
- the HCE mobile terminal and the wearable device in order to ensure normal communication between the HCE mobile terminal and the wearable device, it is necessary to preset a preset signal strength between the two, thereby ensuring the wireless signal strength between the HCE mobile terminal and the wearable device, only when two
- the transaction request command is transmitted to the SE module in the wearable device, and the HCE mobile terminal can further complete the NFC mobile payment transaction.
- the HCE mobile terminal and the wearable device communicate with each other through Bluetooth or wireless Wi-Fi, so the closer the distance between the two is, the better the communication signal is, so that it can be between the HCE mobile terminal and the wearable device.
- the signal strength does not reach the preset signal strength, the user is reminded that the distance between the two is too far.
- the user can reduce the distance between the two by moving the HCE terminal or the wearable device to ensure the signal strength between the two and ensure communication security.
- the signal strength is controllable in this way, the NFC transaction is not affected by the payment environment, and the user experience is better.
- the NFC controller routes the transaction to the wearable device through the above identity authentication request.
- the wearable device receives the transaction request instruction, and the transaction request instruction is The security module is transmitted to the security module in the wearable device, and the SE function of the HCE mobile terminal is implemented by the security module in the wearable device, so that the mobile payment transaction between the HCE mobile terminal and the external receiving POS machine can be realized.
- the wearable device receives a transaction request instruction that simulates the mobile terminal based on the host card, the wearable device has a security module, and the host card simulation is obtained from the transaction request instruction.
- An identity of the mobile terminal where the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card; and then determining whether the identity identifier is An identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, transmitting the transaction request to the security module in the wearable device .
- FIG. 3-a is a schematic flowchart of a mobile payment method according to a third embodiment of the present invention
- FIG. 3b is a mobile diagram according to a third embodiment of the present invention. Schematic diagram of the payment method.
- a mobile payment method according to a third embodiment of the present invention may include:
- S301 Receive a pairing instruction of a user, where the pairing instruction is used to select a paired host card-based analog mobile terminal for the wearable device.
- S302. Determine a management entity that simulates the mobile terminal as a wearable device based on the host card.
- the management entity of the wearable device performs authentication by using the identity of the mobile terminal based on the host card module.
- step S301 and step S302 are the same as steps S201 and S202.
- the management request instruction is used for management of the HCE mobile terminal requesting access control to the wearable device.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip of the host card emulating the mobile terminal.
- the wearable device performs access control authentication on the application based on the host card emulating mobile terminal.
- the access control authentication is used to perform access control authentication on the application module to access the security module card application in the wearable device.
- the wearable device since the wearable device sets the management entity accessing its SE module, it is necessary to determine whether it is the management entity of the SE module in the wearable device by using the identity of the HCE mobile terminal, and if so, allow the HCE to move.
- the terminal manages the SE module in the wearable device, and then further accesses the control and authentication of the SE module card application in the wearable device by the APP on the HCE mobile terminal, thereby making the access security more secure.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the management request instruction of the user from being received again.
- the access control of the SE module card application in the wearable device by the application on the HCE mobile terminal includes downloading, installing, deleting, and data of the card application data on the SE module.
- Personalization and other related operations that is, the card application on the SE module can be initialized and the data can be modified, deleted or added in the middle.
- step S307 and step S308 have no specific execution order.
- the Chinese bank APP (Application) on the HCE mobile terminal may initialize the SE module card application in the wearable device, such as using the Bank of China for mobile for the first time.
- the Chinese bank APP Application
- the Chinese bank APP Application
- the Bank of China APP on the middle end of the HCE may apply the above information about the sensitive information to the SE module card in the wearable device. For example, when the user performs balance transfer on the APP, the APP changes the balance information of the card application of the Bank of China in the relevant SE module.
- the Bank of China APP (Application) on the HCE mobile terminal may change the account in the SE module card application in the wearable device, such as when adding Or, when the account is deleted, since the sensitive information such as the account is stored in the SE module of the wearable device, the account information in the SE module card application in the wearable device is changed by the APP.
- the access control device since the access control of the SE module card application in the wearable device by the APP on the HCE mobile terminal is the access control of the sensitive data, the access control device needs to perform access control authentication on the application on the HCE mobile terminal.
- the APP module application in the wearable device can be accessed by the APP that accesses the control authentication, thereby ensuring the security of the control rules.
- the steps of S203 to S209 may be further performed, thereby further completing the NFC payment transaction of the HCE mobile terminal through the SE module in the wearable device.
- the management of the SE module card application in the wearable device by the APP in the HCE mobile terminal may be performed before the payment transaction, if the SE module card application in the wearable device needs to be initialized. In order to make further payment transactions.
- the management of the SE module card application in the wearable device by the APP in the HCE mobile terminal may be in the payment transaction and after, if necessary, the SE module in the wearable device
- the card application performs data deletion and modification. For example, after the payment transaction is completed, the user wants to transfer the account through the Bank of China, thereby utilizing the APP in the HCE mobile terminal to access the SE module card application in the wearable device to manage the SE module card. Make changes in the data in the app.
- the wearable device receives a transaction request instruction that simulates the mobile terminal based on the host card, the wearable device has a security module, and the host card simulation is obtained from the transaction request instruction.
- An identity of the mobile terminal where the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card; and then determining whether the identity identifier is An identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, transmitting the transaction request to the security module in the wearable device .
- the NCE can be performed on the HCE mobile terminal. Improve the security of transactions when trading, and the risk prevention is strong.
- the embodiment of the invention further provides a wearable device, the wearable device comprising:
- a receiving module configured to receive a transaction request instruction that simulates the mobile terminal based on the host card
- a first acquiring module configured to acquire, according to the transaction request instruction, the identity identifier of the mobile terminal based on the host card
- a second determining module configured to determine whether the identity identifier is an identity identifier of a management entity of the security module in the wearable device
- a delivery module configured to pass the transaction request instruction to the security module in the wearable device if the identity identifier is an identity of a management entity of the security module in the wearable device.
- FIG. 4 is a schematic structural diagram of a wearable device according to a fourth embodiment of the present invention, wherein, as shown in FIG. 4, a wearable device 400 according to a fourth embodiment of the present invention is provided.
- Can include:
- the receiving module 410 the first obtaining module 420, the first determining module 430, and the transmitting module 440.
- the receiving module 410 is configured to receive a transaction request instruction that simulates the mobile terminal based on the host card.
- the HCE mobile terminal is a mobile terminal equipped with an NFC function, an HCE function, and a corresponding wireless communication module such as a Bluetooth or a wireless network, and may be a mobile phone, a tablet computer, etc.; but the HCE mobile terminal There is no SE module, and the module that implements the SE function is placed on the wearable device, that is, when the HCE mobile terminal performs contactless payment, the NFC controller of the HCE mobile terminal routes the payment information to the SE module of the wearable device to complete For mobile payment, the SE module can be implemented by a hardware chip or by software simulation.
- the wearable device refers to a wearable device having an SE module and supporting a corresponding wireless communication module such as a Bluetooth or a wireless network, and can be a smart bracelet, a smart watch, a ring, etc., thereby utilizing the HCE mobile terminal and an external receiving device. Mobile payment needs to be done through the SE module on the wearable device.
- the external receiving device refers to a device having a reader/writer function, such as a card reader, a POS (point of sales terminal) machine, and the like.
- the HCE mobile terminal and the wearable device implement communication through a wireless communication module such as Bluetooth or a wireless network; the HCE mobile terminal uses NFC to complete contactless mobile payment communication with the external receiving device.
- a wireless communication module such as Bluetooth or a wireless network
- the transaction request instruction is an instruction sent by the HCE mobile terminal to the wearable device for requesting a payment transaction, where the transaction instruction includes the identity information of the HCE mobile terminal, the transaction type, and the like.
- the transaction request instruction may further include other non-sensitive information related to the transaction.
- the NFC controller of the HCE mobile terminal routes the transaction to the SE module of the wearable device, and the HCE mobile terminal can The wearable device sends an instruction to request a payment transaction such that the wearable device will receive a transaction request instruction emulating the mobile terminal based on the host card.
- the first obtaining module 420 is configured to obtain, according to the transaction request instruction, the identity identifier of the mobile terminal based on the host card.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card analog mobile terminal.
- the identity of the HCE mobile terminal is a unique identity of the HCE mobile terminal, and the HCE mobile terminal can be uniquely determined by the identity identifier.
- the HCE mobile terminal can be identified by any one of the mobile device international identification code (IMEI), the physical address (MAC address) or the short-range wireless communication chip serial number (NFC chip ID) of the HCE mobile terminal.
- IMEI mobile device international identification code
- MAC address physical address
- NFC chip ID short-range wireless communication chip serial number
- the HCE mobile terminal is identified by either or both of an IMEI, a MAC address, or an NFC chip ID.
- the first determining module 430 is configured to determine whether the identity identifier is an identity of a management entity of the security module in the wearable device.
- the management entity of the SE module in the wearable device refers to a management entity that is set in advance by the user and has administrative rights to the SE module in the wearable device, and the management entity may be an HCE mobile terminal.
- the management entity may be one.
- the management entity may be multiple.
- the identity identifier can uniquely identify the HCE mobile terminal, the identity identifier can be used to determine whether the HCE mobile terminal is a management entity of the SE module in the wearable device.
- the delivery module 440 is configured to transmit the transaction request instruction to the security module in the wearable device if the identity identifier is an identity of a management entity of the security module in the wearable device.
- the NFC controller routes the transaction to the wearable device through the above identity authentication request.
- the wearable device receives the transaction request instruction, and the transaction request instruction is The security module is transmitted to the security module in the wearable device, and the SE function of the HCE mobile terminal is implemented by the security module in the wearable device, so that the mobile payment transaction between the HCE mobile terminal and the external receiving POS machine can be realized.
- the sensitive information is read by using a wireless communication manner such as Bluetooth or Wi-Fi between the HCE mobile terminal and the SE module in the wearable device. .
- the wearable device 400 receives a transaction request instruction based on the host card to simulate the mobile terminal, and the wearable device 400 has a security module; the wearable device 400 obtains the transaction request instruction again.
- the host card emulates an identity of the mobile terminal, where the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card; and then the wearable device
- the 400 determines whether the identity identifier is an identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, the wearable device 400 Passing the transaction request to the security module in the wearable device.
- FIG. 5 is a schematic structural diagram of a wearable device according to a fifth embodiment of the present invention.
- a wearable device 500 according to a fifth embodiment of the present invention may include:
- the function of the 440 is the same as that of the fourth embodiment of the present invention.
- the wearable device 500 of the fifth embodiment of the present invention is based on the wearable device 400 of the fourth embodiment of the present invention. Supplement, as detailed below.
- the first determining module 520 is further configured to:
- the identity identifier is not an identity of a management entity of the security module in the wearable device, The host card is then prohibited from emulating access by the mobile terminal to the security module in the wearable device.
- the identity of the HEC mobile terminal is not the identity of the management entity of the wearable device preset by the user, for security reasons, the HCE mobile terminal will be prohibited from accessing the SE module in the wearable device.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the user transaction request request from being received again.
- the wearable device further includes:
- the host card emulates the mobile terminal as a management entity of the wearable device, wherein the management entity of the wearable device performs authentication by using the identity of the host card module mobile terminal.
- the pairing instruction is used by the user to select and set an HCE mobile terminal that is paired with the wearable device on the wearable device, that is, to set an HCE mobile terminal that allows access to the SE module in the wearable device.
- the HCE mobile terminal that is bound to the wearable device can be selected, and the HCE mobile terminal is bound to the wearable device, that is, the user selects the SE module in the wearable device.
- the entity is managed so that only the set management entity is allowed to access the SE module in the wearable device.
- the subsequent HCE mobile terminal sends a transaction request instruction to the wearable device, only the HCE mobile terminal bound to the wearable device is allowed to transmit the transaction instruction to the SE module of the wearable device as the management entity of the wearable device, thereby increasing the security of the transaction. Sex.
- the identity identifier may be a unique identity of the HCE mobile terminal, such as an IMEI, a MAC address, and an NFC chip ID.
- the wearable device 500 further includes:
- a second obtaining module 560 configured to acquire the host card-simulated mobile terminal and the wearable device Signal strength between devices
- the second determining module 570 is configured to determine whether the signal strength is greater than or equal to a preset signal strength
- the prompting module 580 is configured to trigger the step of transmitting, by the transmitting module, the transaction request instruction to the security module in the wearable device if the signal strength is greater than or equal to the preset signal strength, otherwise, issuing a distance prompt
- the distance prompt is used to remind the user that the distance between the mobile terminal and the wearable device based on the host card is greater than a preset distance.
- the HCE mobile terminal and the wearable device in order to ensure normal communication between the HCE mobile terminal and the wearable device, it is necessary to preset a preset signal strength between the two, thereby ensuring the wireless signal strength between the HCE mobile terminal and the wearable device, only when two
- the transaction request command is transmitted to the SE module in the wearable device, and the HCE mobile terminal can further complete the NFC mobile payment transaction.
- the HCE mobile terminal and the wearable device communicate with each other through Bluetooth or wireless Wi-Fi, so the closer the distance between the two is, the better the communication signal is, so that it can be between the HCE mobile terminal and the wearable device.
- the signal strength does not reach the preset signal strength, the user is reminded that the distance between the two is too far.
- the user can reduce the distance between the two by moving the HCE terminal or the wearable device to ensure the signal strength between the two and ensure communication security.
- the signal strength is controllable in this way, the NFC transaction is not affected by the payment environment, and the user experience is better.
- the preset signal strength is set by a user, or is performed by the wearable device according to the wearable device and the host card-simulated mobile terminal.
- the communication signal strength is determined in a preset manner.
- the preset signal strength may be set by a user, and the wearable device automatically detects the time after the user selects a suitable distance between the HCE mobile terminal and the wearable device.
- the signal strength, plus the allowed interference range, is the final signal strength that can be traded last.
- the preset signal strength may be self-learned by the wearable device.
- the wearable device automatically counts wireless between the HCE mobile terminal and the wearable device during each transaction.
- the strength of the communication signal looking for a period of time, the signal strength of the transaction tends to be relatively stable, that is, when the fluctuation is small, the lower value is added and the interference range is added as the preset signal strength that can be traded.
- the wearable device further includes:
- the first management module 590 is configured to
- the control authentication is used to perform access control authentication on the application module to access the security module card application in the wearable device;
- the application is prohibited from managing the security module card application in the wearable device.
- the application is prohibited from managing the security module card application in the wearable device, and the user is reminded.
- the access control of the SE module card application in the wearable device by the application on the HCE mobile terminal includes downloading, installing, deleting, and data of the card application data on the SE module.
- Personalization and other related operations that is, the card application on the SE module can be initialized and the data can be modified, deleted or added in the middle.
- the Chinese bank APP (Application) on the HCE mobile terminal may initialize the SE module card application in the wearable device, such as using the Bank of China for mobile for the first time.
- the Chinese bank APP Application
- the Chinese bank APP Application
- the Chinese bank APP on the mobile terminal of the HCE may apply the above-mentioned changes on the sensitive information to the SE module card in the wearable device, such as when the user balances on the APP.
- the APP changes the balance information of the card application of the Bank of China in its relevant SE module.
- the Bank of China APP (Application) on the HCE mobile terminal may change the account in the SE module card application in the wearable device, such as when adding Or, when the account is deleted, since the sensitive information such as the account is stored in the SE module of the wearable device, the account information in the SE module card application in the wearable device is changed by the APP.
- the access control of the SE module card application in the wearable device by the APP on the HCE mobile terminal is the access control of the sensitive data
- the access control device needs to perform access control authentication on the application on the HCE mobile terminal.
- the access control authentication APP can be accessed.
- the SE module card application in the device is worn to ensure the security of the control rules.
- the wearable device further includes:
- a second management module 5100 configured to:
- the identity identifier is an identity of a management entity of the security module in the wearable device, triggering, by the first management module, a step of performing access control authentication on the host computer to simulate an application on the mobile terminal .
- the management request instruction is used for management of the HCE mobile terminal requesting access control to the wearable device.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip of the host card analog mobile terminal.
- the wearable device since the wearable device sets the management entity accessing its SE module, it is necessary to determine whether it is the management entity of the SE module in the wearable device by using the identity of the HCE mobile terminal, and if so, allow the HCE to move.
- the terminal manages the SE module in the wearable device, and then further accesses the control and authentication of the SE module card application in the wearable device by the APP on the HCE mobile terminal, thereby making the access security more secure.
- the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the management request instruction of the user from being received again.
- the wearable device 500 receives a transaction request instruction based on the host card to simulate the mobile terminal, and the wearable device 500 has a security module; the wearable device 500 Obtaining, by the transaction request instruction, the identity identifier of the mobile terminal based on the host card, where the identity identifier includes the mobile device international identification code, the physical address, and the short-range wireless communication chip serial number of the host card analog mobile terminal. At least one; the wearable device 500 then determines whether the identity is an identity of a management entity of the security module in the wearable device; if the identity is a management entity of the security module in the wearable device The identity device then passes the transaction request to the security module in the wearable device.
- the security of the transaction can be improved when the HCE mobile terminal performs the NFC transaction, and the risk prevention is strong.
- FIG. 6 is a schematic structural diagram of a wearable device according to a sixth embodiment of the present invention.
- a sixth embodiment of the present invention provides a wearable device 600 that can include at least one bus 601, at least one processor 602 connected to the bus, and at least one memory 603 connected to the bus.
- the processor 602 calls, by using the bus 601, the code stored in the memory 603 to receive a transaction request instruction for emulating the mobile terminal based on the host card; and acquiring, by the transaction request instruction, the identity of the mobile terminal based on the host card. Determining whether the identity identifier is an identity of a management entity of the security module in the wearable device; and if the identity identifier is an identity of a management entity of the security module in the wearable device, responding to the transaction request Transaction communication with external terminals.
- the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip of the host card emulating the mobile terminal.
- the processor 602 is further configured to:
- the host card is prohibited from simulating access of the mobile terminal to the security module in the wearable device.
- the processor 602 is further configured to:
- the host card emulates the mobile terminal as a management entity of the wearable device, wherein the management entity of the wearable device performs authentication by using the identity of the host card module mobile terminal.
- the processor 602 before the delivering the transaction request to the security module in the wearable device, the processor 602 is further configured to:
- the distance prompt is used to remind the user
- the host card is used to simulate that the distance between the mobile terminal and the wearable device is greater than a preset distance.
- the preset signal strength is set by a user, or is performed by the wearable device according to the wearable device and the host card-simulated mobile terminal.
- the communication signal strength is determined in a preset manner.
- the processor 602 is further configured to:
- the application is prohibited from managing the security module card application in the wearable device.
- the application is prohibited from managing the security module card application in the wearable device, and the user is reminded.
- the processor 602 before the wearable device performs access control authentication on the application on the host card-simulated mobile terminal, the processor 602 is further configured to:
- the identity identifier is an identity of a management entity of the security module in the wearable device, triggering, by the wearable device, the step of performing access control authentication on the host computer to simulate an application on the mobile terminal.
- the management request instruction is used for management of the HCE mobile terminal requesting access control to the wearable device.
- the identity identifier is not an identity of a management entity of a security module in the wearable device, the host card is prohibited from simulating the mobile terminal to the Wear access to the security module in the device and alert the user to unauthorized device access.
- the user may add the HCE mobile terminal to the blacklist to prevent the management request instruction of the user from being received again.
- the wearable device 600 receives a transaction request instruction based on the host card emulating the mobile terminal, and the wearable device 600 has a security module; the wearable device 600 obtains the transaction request instruction again.
- the host card emulates an identity of the mobile terminal, where the identity identifier includes at least one of a mobile device international identification code, a physical address, and a short-range wireless communication chip serial number of the host card; and then the wearable device 600, determining whether the identity identifier is an identity of a management entity of the security module in the wearable device; if the identity identifier is an identity of a management entity of the security module in the wearable device, the wearable device 600 Passing the transaction request to the security module in the wearable device.
- the security of the transaction can be improved when the HCE mobile terminal performs the NFC transaction, and the risk prevention is strong.
- the embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium can store a program, and the program includes some or all of the steps of any mobile payment method described in the foregoing method embodiments.
- the disclosed apparatus may be implemented in other ways.
- the device embodiments described above are merely illustrative.
- the division of the unit is only a logical function division.
- there may be another division manner for example, multiple units or components may be combined or may be Integrate into another system, or some features can be ignored or not executed.
- the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be electrical or otherwise.
- the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
- each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
- the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
- the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
- the technical solution of the present invention which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium.
- a number of instructions are included to cause a computer device (which may be a personal computer, server or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
- the foregoing storage medium includes: a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, and the like. .
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Economics (AREA)
- Development Economics (AREA)
- Telephone Function (AREA)
Abstract
一种移动支付方法及可穿戴设备,所述方法,包括:接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备具有安全模块(S101);从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识(S102);判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识(S103);若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块(S104)。通过将HCE移动终端的SE功能在可穿戴设备中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
Description
本发明涉及通信领域,具体涉及一种移动支付方法及可穿戴设备。
目前,基于Android4.4的NFC(Near Field Communication,近距离无线通讯技术)支付引入了一个新的开放式架构,即HCE(Host-based Card Emulation,主机卡模拟)技术,从而在配备NFC功能的终端中实现卡模块后,HCE移动终端不需要提供物理SE(Security Elements,安全模块),使得NFC的应用更加简单与灵活。
但是HCE技术只是模拟了NFC和SE通信的协议和实现,也即以虚拟SE的方式完成NFC业务的安全保证,并没有实现SE。现有基于HCE技术的SE解决方案,可以是通过基于主机软件模拟或者基于云端服务器来实现,但是基于主机软件模拟虽然简单但是安全性很差,比如在系统被Root(获取超级用户权限)的情况下没有任何防范能力,所以需要一种安全性强的SE方案。
发明内容
本发明实施例提供了一种移动支付方法及可穿戴设备,以期可以在HCE移动终端进行NFC交易的时候提高交易的安全性。
本发明实施例第一方面提供一种移动支付方法,应用于可穿戴设备,所述可穿戴设备具有安全模块,包括:
接收基于主机卡模拟移动终端的交易请求指令;
从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;
判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
本发明实施例第二方面提供一种可穿戴设备,所述可穿戴设备具有安全模块,包括:
接收模块,用于接收基于主机卡模拟移动终端的交易请求指令;
第一获取模块,用于从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;
第一判断模块,用于判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
传递模块,用于若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
可以看出,在本发明实施例提供的技术方案中,接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备具有安全模块;再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;然后再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1-a是本发明第一实施例提供的一种移动支付方法的流程示意图;
图1-b是本发明第五实施例提供的移动支付系统的示意图;
图2-a是本发明第二实施例提供的一种移动支付方法的流程示意图;
图2-b是本发明第二实施例提供的一种移动支付方法的交互流程示意图;
图3-a是本发明第三实施例提供的一种移动支付方法的流程示意图;
图3-b是本发明第三实施例提供的一种移动支付方法的流程示意图;
图4是本发明第四实施例提供的一种可穿戴设备的结构示意图;
图5是本发明第五实施例提供的一种可穿戴设备的结构示意图;
图6是本发明第六实施例提供一种可穿戴设备的结构示意图。
本发明实施例提供了一种移动支付方法及可穿戴设备,以期可以在HCE移动终端进行NFC交易的时候提高交易的安全性。
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”和“第三”等是用于区别不同对象,而非用于描述特定顺序。此外,术语“包括”以及它们任何变形,意图在于覆盖不排他的包含。例如包含了一系列步骤或单元的过程、方法、系统、产品或设备没有限定于已列出的步骤或单元,而是可选地还包括没有列出的步骤或单元,或可选地还包括对于这些过程、方法、产品或设备固有的其它步骤或单元。
本发明实施例的一种移动支付方法,一种移动支付方法包括:接收基于主机卡模拟移动终端的交易请求指令;从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则响应所述交易请求与外部终端进行交易通信。
首先参见图1-a和图1-b,图1-a是本发明第一实施例提供的一种移动支付方法的流程示意图,图1-b是本发明第五实施例提供的移动支付系统的示意图。其中,如图1所示,本发明第一实施例提供的一种移动支付方法可以包括:
S101、接收基于主机卡模拟移动终端的交易请求指令。
如图1-b所示,其中,HCE移动终端为配备有NFC功能、HCE功能以及对应的如蓝牙、无线网络等无线通信模块的移动终端,可以为手机,平板电脑等;但该HCE移动终端没有SE模块,其实现SE功能的模块放置在可穿戴设备上,也即HCE移动终端在进行非接触支付时,HCE移动终端的NFC控制器会将支
付信息路由到可穿戴设备的SE模块来完成移动支付,该SE模块可以是通过硬件芯片来实现,也可以通过软件模拟实现。其中,可穿戴设备是指具有SE模块并支持对应的如蓝牙、无线网络等无线通信模块的可穿戴设备,可以为智能手环、智能手表以及戒指等,从而利用HCE移动终端与外部受理设备进行移动支付时,需要通过可穿戴设备上的SE模块来完成。其中,外部受理设备是指具有读写器功能的设备,如读卡器、POS(point of sales terminal,销售点情报管理系统)机等。
其中,HCE移动终端和可穿戴设备之间通过蓝牙、无线网络等无线通信模块实现通信;HCE移动终端利用NFC完成与外部受理设备之间的非接触移动支付通信。
其中,交易请求指令为HCE移动终端发送给可穿戴设备的用于请求支付交易的指令,该交易指令包括HCE移动终端的身份识别信息以及交易类型等。
可选地,在本发明一些可能的实施方式中,该交易请求指令还可以包括与交易相关的其它非敏感信息。
可选地,在本发明的一些可能的实施方式中,HCE移动终端靠近外部受理POS机时,HCE移动终端的NFC控制器就会将交易路由到可穿戴设备的SE模块,HCE移动终端向可穿戴设备发送用于请求支付交易的指令,从而可穿戴设备将接收到基于主机卡模拟移动终端的交易请求指令。
S102、从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识。
其中,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个。
其中,HCE移动终端的身份标识为HCE移动终端的唯一身份标识,可以用该身份标识唯一确定该HCE移动终端。
可以理解,由于HCE移动终端的移动设备国际识别码(IMEI)、物理地址(MAC地址)或近距离无线通讯芯片序列号(NFC芯片ID)中的任一可均可识别HCE移动终端,所以可通过IMEI、MAC地址或NFC芯片ID中的任一个或几个来识别HCE移动终端。
S103、判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识。
其中,可穿戴设备中SE模块的管理实体是指预先由用户设定的、对可穿戴设备中SE模块具有管理权限的管理实体,该管理实体可以是HCE移动终端。
可选地,在本发明的一些可能的实施方式中,该管理实体可以是一个。
可选地,在本发明的另一些可能的实施方式中,该管理实体可以是多个。
可以理解,由于身份标识可以唯一标识HCE移动终端,所以可以利用身份标识来判断该HCE移动终端是否为可穿戴设备中SE模块的管理实体。
S104、若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
举例说明,在本发明的一些可能的实施方式中,当HCE移动终端利用其自身的NFC功能与外部受理POS机进行支付交易时,NFC控制器通过上述身份认证请求将交易路由到可穿戴设备中SE模块中,当利用HCE移动终端的身份标识通过身份认证后,可穿戴设备接收该交易请求指令,并将该交易请求指令传递至可穿戴设备中的安全模块,由可穿戴设备中安全模块实现HCE移动终端的SE功能,从而可以实现HCE移动终端和外部受理POS机之间的移动支付交易。
可选地,在本发明的一些可能的实施方式中,在移动支付的过程中,HCE移动终端和可穿戴设备中SE模块之间通过蓝牙或Wi-Fi等无线通信方式完成敏感信息的读取。
可以看出,本实施例的方案中,可穿戴设备接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备具有安全模块;再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
可选地,在本发明的一些可能的实施方式中,所述方法还包括:
若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
可以理解,如果HEC移动终端的身份标识不是由用户预设的可穿戴设备的管理实体的身份标识,为了安全起见,将禁止该HCE移动终端对可穿戴设备中SE模块进行访问。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户交易指令请求。
可选地,在本发明的一些可能的实施方式中,所述方法还包括:
接收用户的配对指令,所述配对指令用于为所述可穿戴设备选择配对的基于主机卡模拟移动终端;
确定所述基于主机卡模拟移动终端为所述可穿戴设备的管理实体,其中,所述可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
其中,配对指令用于用户在可穿戴设备上选择并设定与可穿戴设备进行配对连接的HCE移动终端,即设定允许访问可穿戴设备中SE模块的HCE移动终端。
可以理解,通过用户的配对指令,可以选择与可穿戴设备进行绑定的HCE移动终端,通过将HCE移动终端与可穿戴设备之间进行绑定,也即实现用户选择可穿戴设备中SE模块的管理实体,从而只允许设定的管理实体访问可穿戴设备中SE模块。在后续HCE移动终端向可穿戴设备发送交易请求指令时,只允许与可穿戴设备绑定的HCE移动终端做为可穿戴设备的管理实体传递交易指令给可穿戴设备中SE模块,增加交易的安全性。
可选地,在本发明的一些可能的实施方式中,该身份标识可以是HCE移动终端的唯一身份标识,如IMEI、MAC地址以及NFC芯片ID等。
可选地,在本发明的一些可能的实施方式中,所述传递所述交易请求到所述可穿戴设备中安全模块之前,所述方法还包括:
获取所述基于主机卡模拟移动终端和所述可穿戴设备之间的信号强度;
判断所述信号强度是否大于或等于预设信号强度;
若所述信号强度大于或等于所述预设信号强度,则触发传递所述交易请求指令到所述可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
可以理解,为了保证HCE移动终端和可穿戴设备之间的正常通信,需要预设两者之间的预设信号强度,从而确保HCE移动终端和可穿戴设备之间的无线信号强度,只有当两者之间信号强度达到预设信号强度时才传递交易请求指令至可穿戴设备中SE模块,HCE移动终端也才能进一步完成NFC移动支付交易。而HCE移动终端和可穿戴设备之间是通过蓝牙或无线Wi-Fi进行通信的,所以两者之间的距离越近则通信信号越好,从而可在HCE移动终端和可穿戴设备之间的信号强度未达到预设信号强度时,则提醒用户两者距离太远,用户可以通过移动HCE终端或可穿戴设备,减少两者之间的距离,确保两者之间的信号强度,保证通信安全,从而保证交易的安全性,并且由于此种方式使得信号强度可控,所以使得该NFC交易不受支付环境的影响,用户体验更好。
可选地,在本发明的一些可能的实施方式中,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
可选地,在本发明的一些可能的实施方式中,预设信号强度可由用户设定,由用户在HCE移动终端和可穿戴设备之间选择一个合适的距离后,可穿戴设备自动检测此时的信号强度,并加上允许的干扰范围作为最后可进行交易的预设信号强度。
可选地,在本发明的另一些可能的实施方式中,预设信号强度可由可穿戴设备自学习完成,具体地,可穿戴设备自动统计每次交易时HCE移动终端和可穿戴设备之间无线通信信号强度,查找一段时间交易信号强度趋于较平稳范围,也即波动较小时取较低值并加上干扰范围作为可进行交易的预设信号强度。
可选地,在本发明的一些可能的实施方式中,所述方法还包括:
对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;
若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全
模块卡片应用进行管理;
若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
可选地,在本发明的一些可能的实施方式中,若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理,并提醒用户。
可选地,在本发明的一些可能的实施方式中,HCE移动终端上的应用程序对可穿戴设备中SE模块卡片应用的访问控制包括对SE模块上卡片应用数据的下载、安装、删除、数据个人化等相关操作,也即可以对SE模块上卡片应用进行初始化以及中间对数据的修改、删除或增加等操作。
举例说明,在本发明一些可能的实施方式中,可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用的初始化,如第一次使用中国银行进行移动支付时,由于可穿戴设备中SE模块中并没有中国银行对应的卡片应用,所以需要对可穿戴设备中SE模块下载卡片应用数据,从而对中国银行对应的卡片应用进行初始化。
再举例说明,在本发明的一些可能的实施方式中,可以是HCE移动中端上的中国银行APP对可穿戴设备中SE模块卡片应用上面关于敏感信息的更改,如当用户在APP上进行余额转帐时,则APP对其相关SE模块中的中国银行的卡片应用上面的余额信息进行更改。
再举例说明,在本发明的另一些可能的实施方式中,还可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用中帐户的更改,如当增加或者删除帐户时,由于帐户等敏感信息存放在可穿戴设备中SE模块中,所以通过APP对可穿戴设备中SE模块卡片应用中的帐户信息进行更改。
可以理解,由于HCE移动终端上APP对可穿戴设备中SE模块卡片应用的访问控制为对敏感数据的访问控制,所以需要通过可穿戴设备对HCE移动终端上的应用程序进行访问控制鉴权,只有通过访问控制鉴权的APP才可以访问可穿戴设备中SE模块卡片应用,从而保证控制规则的安全性。
可选地,在本发明的一些可能的实施方式中,所述对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权之前,所述方法还包括:
接收基于主机卡模拟移动终端的管理请求指令;
从所述管理请求指令中获取所述基于主机卡模拟移动终端的身份标识;
判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则触发所述可穿戴设备对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权的步骤。
其中,身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个。
其中,该管理请求指令用于HCE移动终端请求对可穿戴设备进行访问控制等管理。
可以理解,由于可穿戴设备对访问其SE模块的管理实体进行设定,所以需要通过HCE移动终端的身份标识确定其是否为可穿戴设备中SE模块的管理实体,如果是,才允许该HCE移动终端管理可穿戴设备中SE模块,继而再对HCE移动终端上的APP访问可穿戴设备中SE模块卡片应用进行进一步访问控制鉴权,从而使得访问的安全性更高。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户的管理请求指令。
为了便于更好理解和实施本发明实施例的上述方案,下面结合一些具体的应用场景进行举例说明。
请参见图2-a和图2-b,图2-a是本发明第二实施例提供的一种移动支付方法的流程示意图,图2-b是本发明第二实施例提供的一种移动支付方法的交互流程示意图,其中,如图2所示,本发明第二实施例提供的一种移动支付方法可以包括:
S201、接收用户的配对指令,配对指令用于为可穿戴设备选择配对的基于主机卡模拟移动终端。
其中,HCE移动终端为配备有NFC功能、HCE功能以及对应的如蓝牙、无线网络等无线通信模块的移动终端,可以为手机,平板电脑等;但该HCE移动终端没有SE模块,其实现SE功能的模块放置在可穿戴设备上,也即HCE移动终端在进行非接触支付时,HCE移动终端的NFC控制器会将支付信息路由到可穿戴设备的SE模块来完成移动支付,该SE模块可以是通过硬件芯片来实现,也可以通过软件模拟实现。其中,可穿戴设备是指具有SE模块并支持对应的如蓝牙、无线网络等无线通信模块的可穿戴设备,可以为智能手环、智能手表以及戒指等,从而利用HCE移动终端与外部受理设备进行移动支付时,需要通过可穿戴设备上的SE模块来完成。其中,外部受理设备是指具有读写器功能的设备,如读卡器、POS(point of sales terminal,销售点情报管理系统)机等。
其中,HCE移动终端和可穿戴设备之间通过蓝牙、无线网络等无线通信模块实现通信;HCE移动终端利用NFC完成与外部受理设备之间的非接触移动支付通信。
其中,配对指令用于用户在可穿戴设备上选择并设定与可穿戴设备进行配对连接的HCE移动终端,即设定允许访问可穿戴设备中SE模块的HCE移动终端。
可以理解,通过用户的配对指令,可以选择与可穿戴设备进行绑定的HCE移动终端,通过将HCE移动终端与可穿戴设备之间进行绑定,从而只允许设定的管理实体访问可穿戴设备中SE模块。在后续HCE移动终端向可穿戴设备发送交易请求指令时,只允许与可穿戴设备绑定的HCE移动终端做为可穿戴设备的管理实体传递交易指令给可穿戴设备中SE模块,增加交易的安全性。
S202、确定基于主机卡模拟移动终端为可穿戴设备的管理实体。
其中,可穿戴设备的管理实体通过基于主机卡模块移动终端的身份标识进行认证。
其中,可穿戴设备中SE模块的管理实体是指预先由用户设定的、对可穿戴设备中SE模块具有管理权限的管理实体,该管理实体可以是HCE移动终端。
可选地,在本发明的一些可能的实施方式中,该管理实体可以是一个。
可选地,在本发明的另一些可能的实施方式中,该管理实体可以是多个。
可以理解,由于身份标识可以唯一标识HCE移动终端,所以可以利用身份标识来判断该HCE移动终端是否为可穿戴设备中SE模块的管理实体。
可以理解,通过HCE移动终端的身份标识确定可穿戴设备的管理实体后,即实现用户选择可穿戴设备中SE模块的管理实体,从而只允许设定的管理实体访问可穿戴设备中SE模块。在后续HCE移动终端向可穿戴设备发送交易请求指令时,只允许与可穿戴设备绑定的HCE移动终端做为可穿戴设备的管理实体传递交易指令给可穿戴设备中SE模块,增加交易的安全性。
S203、接收基于主机卡模拟移动终端的交易请求指令。
其中,交易请求指令为HCE移动终端发送给可穿戴设备的用于请求支付交易的指令,该交易指令包括HCE移动终端的身份识别信息以及交易类型等。
可选地,在本发明一些可能的实施方式中,该交易请求指令还可以包括与交易相关的其它非敏感信息。
可选地,在本发明的一些可能的实施方式中,HCE移动终端靠近外部受理POS机时,HCE移动终端的NFC控制器就会将交易路由到可穿戴设备的SE模块,HCE移动终端向可穿戴设备发送用于请求支付交易的指令,从而可穿戴设备将接收到基于主机卡模拟移动终端的交易请求指令。
可选地,在本发明的一些可能的实施方式中,可穿戴设备接收HCE移动终端的交易请求指令之前,所述方法还包括:
接收基于主机卡模拟移动终端的管理请求指令;
从所述管理请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个;
判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则所述可穿戴设备对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;
若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理;
若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
可选地,在本发明的一些可能的实施方式中,该身份标识可以是HCE移动终端的唯一身份标识,如IMEI、MAC地址以及NFC芯片ID等。
可选地,在本发明的一些可能的实施方式中,若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理,并提醒用户。
可选地,在本发明的一些可能的实施方式中,HCE移动终端上的应用程序对可穿戴设备中SE模块卡片应用的访问控制包括对SE模块上卡片应用数据的下载、安装、删除、数据个人化等相关操作,也即可以对SE模块上卡片应用进行初始化以及中间对数据的修改、删除或增加等操作。
举例说明,在本发明第二实施例中,可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用的初始化,如第一次使用中国银行进行移动支付时,由于可穿戴设备中SE模块中并没有中国银行对应的卡片应用,所以需要对可穿戴设备中SE模块下载卡片应用数据,从而对中国银行对应的卡片应用进行初始化。
可以理解,通过上述步骤对可穿戴设备中SE模块的卡片应用进行初始化,从而才能进行后续的NFC交易,并且通过上述步骤,实现对HCE移动终端的身份认证以及HCE移动终端上应用程序的访问控制鉴权,保证初始化工作的安全性,从而保证了后续交易的安全性。
S204、从交易请求指令中获取基于主机卡模拟移动终端的身份标识。
其中,身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个。
其中,HCE移动终端的身份标识为HCE移动终端的唯一身份标识,可以用该身份标识唯一确定该HCE移动终端。
可以理解,由于HCE移动终端的移动设备国际识别码(IMEI)、物理地址(MAC地址)或近距离无线通讯芯片序列号(NFC芯片ID)中的任一可均可识别HCE移动终端,所以可通过IMEI、MAC地址或NFC芯片ID中的任一个或几个来识别HCE移动终端。
S205、判断身份标识是否为可穿戴设备中安全模块的管理实体的身份标识。
可以理解,由于在步骤S201和S202设定了可穿戴设备的管理实体,所以利用上述设定的管理实体的身体标识来判断该HCE移动终端是否为可穿戴设备
中SE模块的管理实体,通过对HCE移动终端的身份进行认证,提高安全性。
S206、若身份标识是可穿戴设备中安全模块的管理实体的身份标识,则获取基于主机卡模拟移动终端和可穿戴设备之间的信号强度。
可选地,在本发明的一些可能的实施方式中,所述方法还包括:
若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户交易指令请求。
可以理解,如果HEC移动终端的身份标识不是由用户预设的可穿戴设备的管理实体的身份标识,为了安全起见,将禁止该HCE移动终端对可穿戴设备中SE模块进行访问。
可选地,在本发明的一些可能的实施方式中,在移动支付的过程中,HCE移动终端和可穿戴设备中SE模块之间通过蓝牙或Wi-Fi等无线通信方式完成敏感信息的读取,所以为了保证通信的可靠性,需要进一步确定HCE移动终端和可穿戴设备中SE模块的信号强度是否足够。
S207、判断信号强度是否大于或等于预设信号强度。
可选地,在本发明的一些可能的实施方式中,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
可选地,在本发明的一些可能的实施方式中,预设信号强度可由用户设定,由用户在HCE移动终端和可穿戴设备之间选择一个合适的距离后,可穿戴设备自动检测此时的信号强度,并加上允许的干扰范围作为最后可进行交易的预设信号强度。
可选地,在本发明的另一些可能的实施方式中,预设信号强度可由可穿戴设备自学习完成,具体地,可穿戴设备自动统计每次交易时HCE移动终端和可穿戴设备之间无线通信信号强度,查找一段时间交易信号强度趋于较平稳范围,
也即波动较小时取较低值并加上干扰范围作为可进行交易的预设信号强度。
可以理解,为了保证HCE移动终端和可穿戴设备之间的正常通信,需要预设两者之间的预设信号强度,从而确保HCE移动终端和可穿戴设备之间的无线信号强度,只有当两者之间信号强度达到预设信号强度时才传递交易请求指令至可穿戴设备中SE模块,HCE移动终端也才能进一步完成NFC移动支付交易。而HCE移动终端和可穿戴设备之间是通过蓝牙或无线Wi-Fi进行通信的,所以两者之间的距离越近则通信信号越好,从而可在HCE移动终端和可穿戴设备之间的信号强度未达到预设信号强度时,则提醒用户两者距离太远,用户可以通过移动HCE终端或可穿戴设备,减少两者之间的距离,确保两者之间的信号强度,保证通信安全,从而保证交易的安全性,并且由于此种方式使得信号强度可控,所以使得该NFC交易不受支付环境的影响,用户体验更好。
S208、若信号强度大于或等于所述预设信号强度,则触发传递交易请求指令到可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
可以理解,为了保证HCE移动终端和可穿戴设备之间的正常通信,需要预设两者之间的预设信号强度,从而确保HCE移动终端和可穿戴设备之间的无线信号强度,只有当两者之间信号强度达到预设信号强度时才传递交易请求指令至可穿戴设备中SE模块,HCE移动终端也才能进一步完成NFC移动支付交易。而HCE移动终端和可穿戴设备之间是通过蓝牙或无线Wi-Fi进行通信的,所以两者之间的距离越近则通信信号越好,从而可在HCE移动终端和可穿戴设备之间的信号强度未达到预设信号强度时,则提醒用户两者距离太远,用户可以通过移动HCE终端或可穿戴设备,减少两者之间的距离,确保两者之间的信号强度,保证通信安全,从而保证交易的安全性,并且由于此种方式使得信号强度可控,所以使得该NFC交易不受支付环境的影响,用户体验更好。
S209、传递交易请求指令到可穿戴设备中安全模块。
举例说明,在本发明的一些可能的实施方式中,当HCE移动终端利用其自身的NFC功能与外部受理POS机进行支付交易时,NFC控制器通过上述身份认证请求将交易路由到可穿戴设备中SE模块中,当利用HCE移动终端的身份标识通过身份认证后,可穿戴设备接收该交易请求指令,并将该交易请求指令
传递至可穿戴设备中的安全模块,由可穿戴设备中安全模块实现HCE移动终端的SE功能,从而可以实现HCE移动终端和外部受理POS机之间的移动支付交易。
可以看出,本实施例的方案中,可穿戴设备接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备具有安全模块;再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
请参见图3-a和图3-b,图3-a是本发明第三实施例提供的一种移动支付方法的流程示意图,图3-b是本发明第三实施例提供的一种移动支付方法的流程示意图。其中,如图3所示,本发明第三实施例提供的一种移动支付方法可以包括:
S301、接收用户的配对指令,配对指令用于为可穿戴设备选择配对的基于主机卡模拟移动终端。
S302、确定基于主机卡模拟移动终端为可穿戴设备的管理实体。
其中,可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
其中,步骤S301和步骤S302与步骤S201和步骤S202相同。
S303、接收基于主机卡模拟移动终端的管理请求指令。
其中,该管理请求指令用于HCE移动终端请求对可穿戴设备进行访问控制等管理。
S304、从管理请求指令中获取基于主机卡模拟移动终端的身份标识。
其中,身份标识包括主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个。
S305、判断身份标识是否为可穿戴设备中安全模块的管理实体的身份标识。
S306、若身份标识是可穿戴设备中安全模块的管理实体的身份标识,则可
穿戴设备对基于主机卡模拟移动终端上的应用程序进行访问控制鉴权。
其中,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权。
可以理解,由于可穿戴设备对访问其SE模块的管理实体进行设定,所以需要通过HCE移动终端的身份标识确定其是否为可穿戴设备中SE模块的管理实体,如果是,才允许该HCE移动终端管理可穿戴设备中SE模块,继而再对HCE移动终端上的APP访问可穿戴设备中SE模块卡片应用进行进一步访问控制鉴权,从而使得访问的安全性更高。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户的管理请求指令。
可选地,在本发明的一些可能的实施方式中,HCE移动终端上的应用程序对可穿戴设备中SE模块卡片应用的访问控制包括对SE模块上卡片应用数据的下载、安装、删除、数据个人化等相关操作,也即可以对SE模块上卡片应用进行初始化以及中间对数据的修改、删除或增加等操作。
S307、若访问控制鉴权通过,则允许应用程序对可穿戴设备中安全模块卡片应用进行管理。
S308、若访问控制鉴权未通过,则禁止应用程序对可穿戴设备中安全模块卡片应用进行管理。
可以理解,步骤S307和步骤S308没有特定的执行先后顺序。
举例说明,在本发明一些可能的实施方式中,可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用的初始化,如第一次使用中国银行进行移动支付时,由于可穿戴设备中SE模块中并没有中国银行对应的卡片应用,所以需要对可穿戴设备中SE模块下载卡片应用数据,从而对中国银行对应的卡片应用进行初始化。
再举例说明,在本发明的一些可能的实施方式中,可以是HCE移动中端上的中国银行APP对可穿戴设备中SE模块卡片应用上面关于敏感信息的更改,
如当用户在APP上进行余额转帐时,则APP对其相关SE模块中的中国银行的卡片应用上面的余额信息进行更改。
再举例说明,在本发明的另一些可能的实施方式中,还可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用中帐户的更改,如当增加或者删除帐户时,由于帐户等敏感信息存放在可穿戴设备中SE模块中,所以通过APP对可穿戴设备中SE模块卡片应用中的帐户信息进行更改。
可以理解,由于HCE移动终端上APP对可穿戴设备中SE模块卡片应用的访问控制为对敏感数据的访问控制,所以需要通过可穿戴设备对HCE移动终端上的应用程序进行访问控制鉴权,只有通过访问控制鉴权的APP才可以访问可穿戴设备中SE模块卡片应用,从而保证控制规则的安全性。
可选地,在本发明的一些可能实施方式中,执行完S301至S308的步骤后,可进一步执行S203至S209的步骤,从而进一步完成HCE移动终端通过可穿戴设备中SE模块的NFC支付交易。
可选地,在本发明的一些可能的实施方式中,HCE移动终端中APP对可穿戴设备中SE模块卡片应用的管理可以在支付交易之前,如需要对可穿戴设备中SE模块卡片应用进行初始化,才能进行进一步地支付交易。
可选地,在本发明的另一些可能的实施方式中,HCE移动终端中APP对可穿戴设备中SE模块卡片应用的管理可以在支付交易之中以及之后,如需要对可穿戴设备中SE模块卡片应用进行数据删除及更改等,例如,支付交易完成后,用户又想通过中国银行APP转帐,从而可利用HCE移动终端中APP对可穿戴设备中SE模块卡片应用的访问控制管理对SE模块卡片应用中的数据进行更改。
可以看出,本实施例的方案中,可穿戴设备接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备具有安全模块;再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备中实现,从而可以在HCE移动终端进行NFC
交易的时候提高交易的安全性,风险防范性强。
本发明实施例还提供一种可穿戴设备,该可穿戴设备包括:
接收模块,用于接收基于主机卡模拟移动终端的交易请求指令;
第一获取模块,用于从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;
第二判断模块,用于判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
传递模块,用于若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
具体的,请参见图4,图4是本发明第四实施例提供的一种可穿戴设备的结构示意图,其中,如图4所示,本发明第四实施例提供的一种可穿戴设备400可以包括:
接收模块410、第一获取模块420、第一判断模块430和传递模块440。
其中,接收模块410,用于接收基于主机卡模拟移动终端的交易请求指令。
如图1-b所示,其中,HCE移动终端为配备有NFC功能、HCE功能以及对应的如蓝牙、无线网络等无线通信模块的移动终端,可以为手机,平板电脑等;但该HCE移动终端没有SE模块,其实现SE功能的模块放置在可穿戴设备上,也即HCE移动终端在进行非接触支付时,HCE移动终端的NFC控制器会将支付信息路由到可穿戴设备的SE模块来完成移动支付,该SE模块可以是通过硬件芯片来实现,也可以通过软件模拟实现。其中,可穿戴设备是指具有SE模块并支持对应的如蓝牙、无线网络等无线通信模块的可穿戴设备,可以为智能手环、智能手表以及戒指等,从而利用HCE移动终端与外部受理设备进行移动支付时,需要通过可穿戴设备上的SE模块来完成。其中,外部受理设备是指具有读写器功能的设备,如读卡器、POS(point of sales terminal,销售点情报管理系统)机等。
其中,HCE移动终端和可穿戴设备之间通过蓝牙、无线网络等无线通信模块实现通信;HCE移动终端利用NFC完成与外部受理设备之间的非接触移动支付通信。
其中,交易请求指令为HCE移动终端发送给可穿戴设备的用于请求支付交易的指令,该交易指令包括HCE移动终端的身份识别信息以及交易类型等。
可选地,在本发明一些可能的实施方式中,该交易请求指令还可以包括与交易相关的其它非敏感信息。
可选地,在本发明的一些可能的实施方式中,HCE移动终端靠近外部受理POS机时,HCE移动终端的NFC控制器就会将交易路由到可穿戴设备的SE模块,HCE移动终端向可穿戴设备发送用于请求支付交易的指令,从而可穿戴设备将接收到基于主机卡模拟移动终端的交易请求指令。
第一获取模块420,用于从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识。
其中,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个。
其中,HCE移动终端的身份标识为HCE移动终端的唯一身份标识,可以用该身份标识唯一确定该HCE移动终端。
可以理解,由于HCE移动终端的移动设备国际识别码(IMEI)、物理地址(MAC地址)或近距离无线通讯芯片序列号(NFC芯片ID)中的任一可均可识别HCE移动终端,所以可通过IMEI、MAC地址或NFC芯片ID中的任一个或几个来识别HCE移动终端。
第一判断模块430,用于判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识。
其中,可穿戴设备中SE模块的管理实体是指预先由用户设定的、对可穿戴设备中SE模块具有管理权限的管理实体,该管理实体可以是HCE移动终端。
可选地,在本发明的一些可能的实施方式中,该管理实体可以是一个。
可选地,在本发明的另一些可能的实施方式中,该管理实体可以是多个。
可以理解,由于身份标识可以唯一标识HCE移动终端,所以可以利用身份标识来判断该HCE移动终端是否为可穿戴设备中SE模块的管理实体。
传递模块440,用于若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
举例说明,在本发明的一些可能的实施方式中,当HCE移动终端利用其自身的NFC功能与外部受理POS机进行支付交易时,NFC控制器通过上述身份认证请求将交易路由到可穿戴设备中SE模块中,当利用HCE移动终端的身份标识通过身份认证后,可穿戴设备接收该交易请求指令,并将该交易请求指令
传递至可穿戴设备中的安全模块,由可穿戴设备中安全模块实现HCE移动终端的SE功能,从而可以实现HCE移动终端和外部受理POS机之间的移动支付交易。
可选地,在本发明的一些可能的实施方式中,在移动支付的过程中,HCE移动终端和可穿戴设备中SE模块之间通过蓝牙或Wi-Fi等无线通信方式完成敏感信息的读取。
可以理解的是,本实施例的可穿戴设备400的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,可穿戴设备400接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备400具有安全模块;可穿戴设备400再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后可穿戴设备400再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则可穿戴设备400传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备400中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
请参见图5,图5是本发明第五实施例提供的一种可穿戴设备的结构示意图,其中,如图5所示,本发明第五实施例提供的一种可穿戴设备500可以包括:
接收模块510、第一获取模块520、第一判断模块530和传递模块540。
其中,接收模块510、第一获取模块520、第一判断模块530和传递模块540的部分功能和本发明第四实施例的接收模块410、第一获取模块420、第一判断模块430和传递模块440功能一样,与本发明第四实施例相同的功能在此不再赘述,另外,本发明第五实施例的可穿戴设备500在本发明第四实施例的可穿戴设备400的基础上有所补充,详述如下。
可选地,在本发明的一些可能的实施方式中,所述第一判断模块520还用于:
若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,
则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
可以理解,如果HEC移动终端的身份标识不是由用户预设的可穿戴设备的管理实体的身份标识,为了安全起见,将禁止该HCE移动终端对可穿戴设备中SE模块进行访问。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户交易指令请求。
可选地,在本发明的一些可能的实施方式中,所述可穿戴设备还包括:
配对模块550,用于
接收用户的配对指令,所述配对指令用于为所述可穿戴设备选择配对的基于主机卡模拟移动终端;
确定所述基于主机卡模拟移动终端为所述可穿戴设备的管理实体,其中,所述可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
其中,配对指令用于用户在可穿戴设备上选择并设定与可穿戴设备进行配对连接的HCE移动终端,即设定允许访问可穿戴设备中SE模块的HCE移动终端。
可以理解,通过用户的配对指令,可以选择与可穿戴设备进行绑定的HCE移动终端,通过将HCE移动终端与可穿戴设备之间进行绑定,也即实现用户选择可穿戴设备中SE模块的管理实体,从而只允许设定的管理实体访问可穿戴设备中SE模块。在后续HCE移动终端向可穿戴设备发送交易请求指令时,只允许与可穿戴设备绑定的HCE移动终端做为可穿戴设备的管理实体传递交易指令给可穿戴设备中SE模块,增加交易的安全性。
可选地,在本发明的一些可能的实施方式中,该身份标识可以是HCE移动终端的唯一身份标识,如IMEI、MAC地址以及NFC芯片ID等。
可选地,在本发明的一些可能的实施方式中,所述可穿戴设备500还包括:
第二获取模块560,用于获取所述基于主机卡模拟移动终端和所述可穿戴设
备之间的信号强度;
第二判断模块570,用于判断所述信号强度是否大于或等于预设信号强度;
提示模块580,用于若所述信号强度大于或等于所述预设信号强度,则触发所述传递模块传递所述交易请求指令到所述可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
可以理解,为了保证HCE移动终端和可穿戴设备之间的正常通信,需要预设两者之间的预设信号强度,从而确保HCE移动终端和可穿戴设备之间的无线信号强度,只有当两者之间信号强度达到预设信号强度时才传递交易请求指令至可穿戴设备中SE模块,HCE移动终端也才能进一步完成NFC移动支付交易。而HCE移动终端和可穿戴设备之间是通过蓝牙或无线Wi-Fi进行通信的,所以两者之间的距离越近则通信信号越好,从而可在HCE移动终端和可穿戴设备之间的信号强度未达到预设信号强度时,则提醒用户两者距离太远,用户可以通过移动HCE终端或可穿戴设备,减少两者之间的距离,确保两者之间的信号强度,保证通信安全,从而保证交易的安全性,并且由于此种方式使得信号强度可控,所以使得该NFC交易不受支付环境的影响,用户体验更好。
可选地,在本发明的一些可能的实施方式中,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
可选地,在本发明的一些可能的实施方式中,预设信号强度可由用户设定,由用户在HCE移动终端和可穿戴设备之间选择一个合适的距离后,可穿戴设备自动检测此时的信号强度,并加上允许的干扰范围作为最后可进行交易的预设信号强度。
可选地,在本发明的另一些可能的实施方式中,预设信号强度可由可穿戴设备自学习完成,具体地,可穿戴设备自动统计每次交易时HCE移动终端和可穿戴设备之间无线通信信号强度,查找一段时间交易信号强度趋于较平稳范围,也即波动较小时取较低值并加上干扰范围作为可进行交易的预设信号强度。
可选地,在本发明的一些可能的实施方式中,所述可穿戴设备还包括:
第一管理模块590,用于
对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访
问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;
若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理;
若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
可选地,在本发明的一些可能的实施方式中,若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理,并提醒用户。
可选地,在本发明的一些可能的实施方式中,HCE移动终端上的应用程序对可穿戴设备中SE模块卡片应用的访问控制包括对SE模块上卡片应用数据的下载、安装、删除、数据个人化等相关操作,也即可以对SE模块上卡片应用进行初始化以及中间对数据的修改、删除或增加等操作。
举例说明,在本发明一些可能的实施方式中,可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用的初始化,如第一次使用中国银行进行移动支付时,由于可穿戴设备中SE模块中并没有中国银行对应的卡片应用,所以需要对可穿戴设备中SE模块下载卡片应用数据,从而对中国银行对应的卡片应用进行初始化。
再举例说明,在本发明的一些可能的实施方式中,可以是HCE移动中端上的中国银行APP对可穿戴设备中SE模块卡片应用上面关于敏感信息的更改,如当用户在APP上进行余额转帐时,则APP对其相关SE模块中的中国银行的卡片应用上面的余额信息进行更改。
再举例说明,在本发明的另一些可能的实施方式中,还可以是HCE移动终端上的中国银行APP(Application,应用程序)对可穿戴设备中SE模块卡片应用中帐户的更改,如当增加或者删除帐户时,由于帐户等敏感信息存放在可穿戴设备中SE模块中,所以通过APP对可穿戴设备中SE模块卡片应用中的帐户信息进行更改。
可以理解,由于HCE移动终端上APP对可穿戴设备中SE模块卡片应用的访问控制为对敏感数据的访问控制,所以需要通过可穿戴设备对HCE移动终端上的应用程序进行访问控制鉴权,只有通过访问控制鉴权的APP才可以访问可
穿戴设备中SE模块卡片应用,从而保证控制规则的安全性。
可选地,在本发明的一些可能的实施方式中,所述可穿戴设备还包括:
第二管理模块5100,用于
接收基于主机卡模拟移动终端的管理请求指令;
从所述管理指令中获取所述基于主机卡模拟移动终端的身份标识;
判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则触发所述第一管理模块执行对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权的步骤。
其中,该管理请求指令用于HCE移动终端请求对可穿戴设备进行访问控制等管理。
其中,,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个。
可以理解,由于可穿戴设备对访问其SE模块的管理实体进行设定,所以需要通过HCE移动终端的身份标识确定其是否为可穿戴设备中SE模块的管理实体,如果是,才允许该HCE移动终端管理可穿戴设备中SE模块,继而再对HCE移动终端上的APP访问可穿戴设备中SE模块卡片应用进行进一步访问控制鉴权,从而使得访问的安全性更高。
可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户的管理请求指令。
可以理解的是,本实施例的可穿戴设备500的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,可穿戴设备500接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备500具有安全模块;可穿戴设备500再
从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后可穿戴设备500再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则可穿戴设备500传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备500中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
参见图6,图6是本发明第六实施例提供一种可穿戴设备的结构示意图。如图6所示,本发明第六实施例提供一种可穿戴设备600可以包括:至少一个总线601、与总线相连的至少一个处理器602以及与总线相连的至少一个存储器603。
其中,处理器602通过总线601,调用存储器603中存储的代码以用于接收基于主机卡模拟移动终端的交易请求指令;从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则响应所述交易请求与外部终端进行交易通信。
其中,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片中的至少一个。
可选地,在本发明的一些可能的实施方式中,所述处理器602还用于:
若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
可选地,在本发明的一些可能的实施方式中,所述处理器602还用于:
接收用户的配对指令,所述配对指令用于为所述可穿戴设备选择配对的基于主机卡模拟移动终端;
确定所述基于主机卡模拟移动终端为所述可穿戴设备的管理实体,其中,所述可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
可选地,在本发明的一些可能的实施方式中,所述传递所述交易请求到所述可穿戴设备中安全模块之前,所述处理器602还用于:
获取所述基于主机卡模拟移动终端和所述可穿戴设备之间的信号强度;
判断所述信号强度是否大于或等于预设信号强度;
若所述信号强度大于或等于所述预设信号强度,则触发传递所述交易请求指令到所述可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
可选地,在本发明的一些可能的实施方式中,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
可选地,在本发明的一些可能的实施方式中,所述处理器602还用于:
对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;
若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理;
若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
可选地,在本发明的一些可能的实施方式中,若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理,并提醒用户。
可选地,在本发明的一些可能的实施方式中,所述可穿戴设备对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权之前,所述处理器602还用于:
接收基于主机卡模拟移动终端的管理请求指令;
从所述管理指令中获取所述基于主机卡模拟移动终端的身份标识,;
判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;
若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则触发所述可穿戴设备对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权的步骤。
其中,该管理请求指令用于HCE移动终端请求对可穿戴设备进行访问控制等管理。可选地,在本发明的一些可能的实施方式中,若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问,并提醒用户有非法设备访问。
可选地,在本发明的一些可能的实施方式中,当提醒用户有非法设备访问后,用户可将此HCE移动终端加入黑名单,以防下次再接收到该用户的管理请求指令。
可以理解的是,本实施例的可穿戴设备600的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,可穿戴设备600接收基于主机卡模拟移动终端的交易请求指令,所述可穿戴设备600具有安全模块;可穿戴设备600再从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识,所述身份标识包括所述主机卡模拟移动终端的移动设备国际识别码、物理地址和近距离无线通讯芯片序列号中的至少一个;然后可穿戴设备600再判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则可穿戴设备600传递所述交易请求到所述可穿戴设备中安全模块。通过将HCE移动终端的SE功能在可穿戴设备600中实现,从而可以在HCE移动终端进行NFC交易的时候提高交易的安全性,风险防范性强。
本发明实施例还提供一种计算机存储介质,其中,该计算机存储介质可存储有程序,该程序执行时包括上述方法实施例中记载的任何移动支付方法的部分或全部步骤。
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为依据本发明,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本发明所必须的。
在上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置,可通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明的各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。
Claims (14)
- 一种移动支付方法,其特征在于,应用于可穿戴设备,所述可穿戴设备具有安全模块,所述方法包括:接收基于主机卡模拟移动终端的交易请求指令;从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
- 根据权利要求1或2所述的方法,其特征在于,所述传递所述交易请求指令到所述可穿戴设备中安全模块之前,所述方法还包括:获取所述基于主机卡模拟移动终端和所述可穿戴设备之间的信号强度;判断所述信号强度是否大于或等于预设信号强度;若所述信号强度大于或等于所述预设信号强度,则触发所述传递所述交易请求指令到所述可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
- 根据权利要求3所述的方法,其特征在于,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
- 根据权利要求1或2所述的方法,其特征在于,所述方法还包括:对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理;若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
- 根据权利要求5所述的方法,其特征在于,所述对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权之前,所述方法还包括:接收基于主机卡模拟移动终端的管理请求指令;从所述管理请求指令中获取所述基于主机卡模拟移动终端的身份标识;判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则触发所述可穿戴设备对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权的步骤。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:接收用户的配对指令,所述配对指令用于为所述可穿戴设备选择配对的基于主机卡模拟移动终端;确定所述基于主机卡模拟移动终端为所述可穿戴设备的管理实体,其中,所述可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
- 一种可穿戴设备,其特征在于,所述可穿戴设备具有安全模块,所述可穿戴设备包括:接收模块,用于接收基于主机卡模拟移动终端的交易请求指令;第一获取模块,用于从所述交易请求指令中获取所述基于主机卡模拟移动终端的身份标识;第一判断模块,用于判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;传递模块,用于若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则传递所述交易请求指令到所述可穿戴设备中安全模块。
- 根据权利要求8所述的可穿戴设备,其特征在于,所述第一判断模块还用于:若所述身份标识不是所述可穿戴设备中安全模块的管理实体的身份标识,则禁止所述基于主机卡模拟移动终端对所述可穿戴设备中安全模块的访问。
- 根据权利要求8或9所述的可穿戴设备,其特征在于,所述可穿戴设备还包括:第二获取模块,用于获取所述基于主机卡模拟移动终端和所述可穿戴设备之间的信号强度;第二判断模块,用于判断所述信号强度是否大于或等于预设信号强度;提示模块,用于若所述信号强度大于或等于所述预设信号强度,则触发所述传递模块执行所述传递所述交易请求指令到所述可穿戴设备中安全模块的步骤,否则,发出距离提示,所述距离提示用于提醒用户所述基于主机卡模拟移动终端和所述可穿戴设备之间的距离大于预设距离。
- 根据权利要求10所述的可穿戴设备,其特征在于,所述预设信号强度由用户设定,或由所述可穿戴设备根据所述可穿戴设备与所述基于主机卡模拟移动终端之间的通信信号强度按照预设方式确定。
- 根据权利要求8或9所述的可穿戴设备,其特征在于,所述可穿戴设备还包括:第一管理模块,用于对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权,所述访问控制鉴权用于对所述应用程序访问所述可穿戴设备中安全模块卡片应用进行访问控制鉴权;若所述访问控制鉴权通过,则允许所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理;若所述访问控制鉴权未通过,则禁止所述应用程序对所述可穿戴设备中安全模块卡片应用进行管理。
- 根据权利要求12所述的可穿戴设备,其特征在于,所述可穿戴设备还包括:第二管理模块,用于接收基于主机卡模拟移动终端的管理请求指令;从所述管理指令中获取所述基于主机卡模拟移动终端的身份标识;判断所述身份标识是否为所述可穿戴设备中安全模块的管理实体的身份标识;若所述身份标识是所述可穿戴设备中安全模块的管理实体的身份标识,则 触发所述第一管理模块执行所述对所述基于主机卡模拟移动终端上的应用程序进行访问控制鉴权的步骤。
- 根据权利要求8所述的可穿戴设备,其特征在于,所述可穿戴设备还包括:配对模块,用于接收用户的配对指令,所述配对指令用于为所述可穿戴设备选择配对的基于主机卡模拟移动终端;确定所述基于主机卡模拟移动终端为所述可穿戴设备的管理实体,其中,所述可穿戴设备的管理实体通过所述基于主机卡模块移动终端的身份标识进行认证。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510466760.6A CN105550863A (zh) | 2015-07-31 | 2015-07-31 | 一种移动支付方法及可穿戴设备 |
| CN201510466760.6 | 2015-07-31 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017020417A1 true WO2017020417A1 (zh) | 2017-02-09 |
Family
ID=55830043
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/091337 Ceased WO2017020417A1 (zh) | 2015-07-31 | 2015-09-30 | 一种移动支付方法及可穿戴设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105550863A (zh) |
| WO (1) | WO2017020417A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113178028A (zh) * | 2021-04-13 | 2021-07-27 | 歌尔股份有限公司 | 控制方法、可穿戴设备、移动终端及可读存储介质 |
Families Citing this family (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107358419B (zh) * | 2016-05-09 | 2020-12-11 | 阿里巴巴集团控股有限公司 | 机载终端支付鉴权方法、装置以及系统 |
| KR101730626B1 (ko) * | 2016-05-18 | 2017-05-04 | 주식회사 비코닉스 | 블루투스를 이용한 단말 인증장치 및 방법 |
| CN106204021A (zh) * | 2016-06-30 | 2016-12-07 | 宇龙计算机通信科技(深圳)有限公司 | Nfc移动支付方法、装置及终端 |
| CN106255102B (zh) * | 2016-07-26 | 2019-12-27 | Oppo广东移动通信有限公司 | 一种终端设备的鉴定方法及相关设备 |
| CN107818464A (zh) | 2016-09-14 | 2018-03-20 | 百度在线网络技术(北京)有限公司 | 一种在移动终端实现的nfc支付方法与装置 |
| CN108369627B (zh) * | 2016-09-30 | 2020-10-09 | 华为技术有限公司 | 一种获得进行用户相关操作时的距离阈值的方法和装置 |
| CN106971169B (zh) * | 2017-03-31 | 2020-08-14 | 北京酷云互动科技有限公司 | 交易行为识别方法和交易行为识别系统 |
| CN107256578A (zh) * | 2017-04-12 | 2017-10-17 | 深圳市微付充科技有限公司 | 一种闸机支付方法、etc终端、终端附件及移动终端 |
| CN112001402B (zh) * | 2017-05-11 | 2023-10-03 | 创新先进技术有限公司 | 身份认证方法、装置和系统 |
| US10068114B1 (en) * | 2017-09-12 | 2018-09-04 | Nxp B.V. | System and method for implementing a host card emulation (HCE) command stack in a mobile phone |
| CN108197929B (zh) * | 2017-11-27 | 2019-07-23 | 拉卡拉支付股份有限公司 | 一种可穿戴设备的安全支付方法和装置 |
| CN110602689B (zh) * | 2019-07-30 | 2021-01-05 | 华为技术有限公司 | 一种设备安全操作的方法和装置 |
| EP4060588B1 (en) | 2021-02-05 | 2026-03-25 | Shenzhen Goodix Technology Co., Ltd. | Virtual electronic card management method and system, security chip, terminal, and storage medium |
| CN115689550A (zh) * | 2022-11-11 | 2023-02-03 | 中国人民银行数字货币研究所 | 交易方法、装置、设备及存储介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050187882A1 (en) * | 2004-02-25 | 2005-08-25 | Sampo Sovio | Electronic payment schemes in a mobile environment for short-range transactions |
| CN101154281A (zh) * | 2006-09-30 | 2008-04-02 | 联想(北京)有限公司 | 迁移智能卡上的金融数据的方法和移动设备 |
| CN102685073A (zh) * | 2011-03-11 | 2012-09-19 | 中国移动通信集团公司 | 安全支付方法和移动终端 |
| CN102968722A (zh) * | 2012-12-21 | 2013-03-13 | 北京惠银通联科技有限公司 | 一种交易确认的方法和系统 |
| CN204117191U (zh) * | 2014-08-21 | 2015-01-21 | 北京大明五洲科技有限公司 | 移动安全支付装置、移动终端、usbkey |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104021469A (zh) * | 2014-06-13 | 2014-09-03 | 捷德(中国)信息科技有限公司 | 进行支付交易的方法、设备以及系统 |
| CN104102939A (zh) * | 2014-07-15 | 2014-10-15 | 陈业军 | 一种基于hce的nfc系统 |
| CN104796258A (zh) * | 2015-03-24 | 2015-07-22 | 百度在线网络技术(北京)有限公司 | 一种用于移动认证的方法、设备与系统 |
-
2015
- 2015-07-31 CN CN201510466760.6A patent/CN105550863A/zh active Pending
- 2015-09-30 WO PCT/CN2015/091337 patent/WO2017020417A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050187882A1 (en) * | 2004-02-25 | 2005-08-25 | Sampo Sovio | Electronic payment schemes in a mobile environment for short-range transactions |
| CN101154281A (zh) * | 2006-09-30 | 2008-04-02 | 联想(北京)有限公司 | 迁移智能卡上的金融数据的方法和移动设备 |
| CN102685073A (zh) * | 2011-03-11 | 2012-09-19 | 中国移动通信集团公司 | 安全支付方法和移动终端 |
| CN102968722A (zh) * | 2012-12-21 | 2013-03-13 | 北京惠银通联科技有限公司 | 一种交易确认的方法和系统 |
| CN204117191U (zh) * | 2014-08-21 | 2015-01-21 | 北京大明五洲科技有限公司 | 移动安全支付装置、移动终端、usbkey |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113178028A (zh) * | 2021-04-13 | 2021-07-27 | 歌尔股份有限公司 | 控制方法、可穿戴设备、移动终端及可读存储介质 |
| CN113178028B (zh) * | 2021-04-13 | 2023-04-07 | 歌尔股份有限公司 | 控制方法、可穿戴设备、移动终端及可读存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105550863A (zh) | 2016-05-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2017020417A1 (zh) | 一种移动支付方法及可穿戴设备 | |
| US10803452B2 (en) | Method and apparatus for performing payment | |
| US11461498B2 (en) | Systems and methods for secured, managed, multi-party interchanges with a software application operating on a client device | |
| US11595820B2 (en) | Secure elements broker (SEB) for application communication channel selector optimization | |
| KR102577054B1 (ko) | 전자 결제 기능을 제공하는 전자 장치 및 그의 동작 방법 | |
| KR101820573B1 (ko) | 금융 거래를 위한 모바일 머천트 접근 솔루션 | |
| US11107047B2 (en) | Electronic device providing electronic payment function and operating method thereof | |
| US20200167775A1 (en) | Virtual pos terminal method and apparatus | |
| KR101830952B1 (ko) | Nfc 기반 결제를 위한 생체인식 인증 사용 | |
| TWI551074B (zh) | 用於近場通訊之通訊系統及方法 | |
| US20180341937A1 (en) | Method and apparatus for performing settlement transaction | |
| US20160253652A1 (en) | Electronic device providing electronic payment function and operation method thereof | |
| EP3438812A1 (en) | System and method for providing secure data communication permissions to trusted applications on a portable communication device | |
| KR102329258B1 (ko) | 보안 모듈을 이용한 결제 방법 및 장치 | |
| KR20180017218A (ko) | 분실된 전자 디바이스의 모바일 결제 비활성화 | |
| US12088700B2 (en) | Method by which device shares digital key | |
| CN105307287B (zh) | 一种连接方法及可穿戴设备 | |
| KR102586443B1 (ko) | 전자 결제 기능을 제공하는 전자 장치 및 그 동작 방법 | |
| CN105659523A (zh) | 能够重新编程的安全密码设备 | |
| KR20170030408A (ko) | 결제를 위한 방법 및 장치 | |
| KR20170008645A (ko) | 전자 장치, 인증 대행 서버 및 결제 시스템 | |
| US11010749B2 (en) | Payment processing method and electronic device supporting the same | |
| CN105847292B (zh) | 一种基于nfc-hce的云端鉴权方法、装置及系统 | |
| WO2020052753A1 (en) | Intermediary system for faciliting communication between virtual smart cards and a smart card interface | |
| EP2996368B1 (en) | Mobile electronic device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15900187 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15900187 Country of ref document: EP Kind code of ref document: A1 |