WO2017052035A1 - 오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치 - Google Patents

오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치 Download PDF

Info

Publication number
WO2017052035A1
WO2017052035A1 PCT/KR2016/006315 KR2016006315W WO2017052035A1 WO 2017052035 A1 WO2017052035 A1 WO 2017052035A1 KR 2016006315 W KR2016006315 W KR 2016006315W WO 2017052035 A1 WO2017052035 A1 WO 2017052035A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
store
information
mobile terminal
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2016/006315
Other languages
English (en)
French (fr)
Inventor
곽세병
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SK Planet Co Ltd
Original Assignee
SK Planet Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020150133763A external-priority patent/KR102505974B1/ko
Priority claimed from KR1020150148084A external-priority patent/KR102505975B1/ko
Priority claimed from KR1020150148087A external-priority patent/KR102505976B1/ko
Application filed by SK Planet Co Ltd filed Critical SK Planet Co Ltd
Publication of WO2017052035A1 publication Critical patent/WO2017052035A1/ko
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/386Payment protocols; Details thereof using messaging services or messaging apps
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models
    • G06Q20/24Credit schemes, i.e. "pay after"
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/42Confirmation, e.g. check or permission by the legal debtor of payment

Definitions

  • the present invention relates to an offline payment processing system, a second authentication-based offline payment processing method, and a device using the same.
  • payment can be easily performed by inputting a cross point of the touch trace for final payment
  • payment can be easily performed by inputting a touch pattern for final payment.
  • the present invention relates to an offline payment processing technology capable of performing pre-approval for a purchase by performing primary authentication through a swipe pattern in a user terminal.
  • the present invention relates to Korean Patent Application No. 10-2015-0133763, filed September 22, 2015, Korean Patent Application No. 10-2015-0148087, filed October 23, 2015, and Korea, filed October 23, 2015. Claims the benefit of the filing date of Patent Application No. 10-2015-0148084, the entire contents of which are incorporated herein.
  • Korean Registered Patent No. 10-1352710 registered on January 10, 2014 (name: credit card mock payment system and simulated payment method in the payment system and apparatus therefor).
  • An object of the present invention is to provide convenience of payment by performing a second authentication using a cross point generated according to a touch trace input by a user when performing offline payment using a mobile terminal.
  • an object of the present invention is to prevent the risk of security that may occur in the purchase process after the first authentication is completed by performing the second authentication based on the first authentication.
  • an object of the present invention is to process the payment based on pre-authentication to perform offline payments safely and conveniently with only the mobile terminal without taking out the wallet or card separately.
  • an object of the present invention is to provide convenience of payment by performing a second authentication based on a touch pattern input by a user when the user performs offline payment using a mobile terminal.
  • an object of the present invention is to provide a higher safety based on the two-channel authentication when the user performs offline payment using a mobile terminal.
  • an object of the present invention is to safely perform offline payment without taking out the mobile terminal based on the swipe pattern-based pre-authentication.
  • an object of the present invention is to provide a stable payment service while maximizing user convenience when offline payment using a mobile terminal.
  • Offline payment processing apparatus for achieving the above object is a check-in information acquisition unit for obtaining the check-in information corresponding to the store entered by the user; A primary authentication unit for receiving primary authentication information for primary authentication corresponding to pre-approval for a purchase corresponding to the store from a mobile terminal; A second authentication unit performing second authentication based on the cross point of the touch trace inputted to the sign pad of the POS and subordinate to the first authentication when the first authentication is valid; And a payment processing unit that performs offline payment in the store based on the result of the second authentication.
  • the second authentication unit may perform the second authentication according to whether or not the registration cross point and the cross point registered in advance by the user match.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • the secondary authentication unit may perform the secondary authentication by further considering at least one condition among the number of the cross points and the location of the cross points.
  • the second authentication unit may move the mobile terminal after the first authentication.
  • the second authentication level may be improved when the movement speed of the mobile terminal after the first authentication exceeds a preset reference movement distance and when the movement speed of the mobile terminal corresponds to at least one of the preset reference movement speeds.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the first authentication unit is a case where the monitoring result, the time before the first authentication is performed after obtaining the check-in information exceeds a predetermined reference authentication time and the number of mobile unauthorized payments occurred in the store is preset
  • the first authentication level may be adjusted to correspond to at least one of cases where the reference number is exceeded.
  • the mobile terminal includes a check-in information collecting unit for obtaining the check-in information corresponding to the store entered by the user;
  • a primary authentication performing unit configured to perform primary authentication corresponding to pre-approval for a purchase corresponding to the store by inputting primary authentication information;
  • a second authentication performing unit performing cross-point based second authentication based on touch trajectory for second authentication dependent on the first authentication when the first authentication is valid;
  • a payment performing unit for transmitting the information corresponding to the second authentication to the server to perform the offline payment in the store, and receives the result of the offline payment.
  • the offline payment processing method comprises the steps of obtaining the check-in information corresponding to the store entered by the user; Receiving first authentication information for first authentication corresponding to pre-approval for a purchase corresponding to the store from a mobile terminal; If the first authentication is valid, performing a second authentication, which is dependent on the first authentication and is performed based on a cross point of a touch trace input to a sign pad of a POS; And performing offline payment at the store based on the result of the second authentication.
  • the performing of the second authentication may perform the second authentication according to whether or not the user crosses the registered cross point and the cross point.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • the second authentication when the second authentication level is improved, the second authentication may be performed by further considering at least one condition among the number of the cross points and the location of the cross points.
  • the step of performing the second authentication is the mobile terminal after the first authentication when the monitoring result exceeds the predetermined reference purchase time from the first authentication until the product is submitted to the POS
  • the second authentication level is improved when the moving distance of the device exceeds at least one of the preset reference moving distances and when the moving speed of the mobile terminal after the first authentication exceeds a preset reference moving speed. You can.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the step of receiving the primary authentication information is when the monitoring result, the time before the first authentication is performed after acquiring the check-in information exceeds a predetermined reference authentication time and the mobile irregularity occurred in the store
  • the number of payments corresponds to at least one of the cases in which the number of payments exceeds a preset reference number
  • the first authentication level may be improved.
  • the offline payment processing apparatus includes a check-in information obtaining unit for obtaining check-in information corresponding to the store entered by the user; A primary authentication unit for receiving primary authentication information for primary authentication corresponding to pre-approval for a purchase corresponding to the store from a mobile terminal; A second authentication unit performing second authentication based on a touch pattern input to a sign pad of a POS and subordinate to the first authentication when the first authentication is valid; And a payment processing unit that performs offline payment in the store based on the result of the second authentication.
  • the second authentication unit may perform the second authentication according to whether or not the touch pattern registered by the user and the touch pattern match.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • the secondary authentication unit may perform the secondary authentication by further considering at least one condition among a touch length, a swipe direction, and a swipe speed.
  • the second authentication unit may move the mobile terminal after the first authentication.
  • the second authentication level may be improved when the movement speed of the mobile terminal after the first authentication exceeds a preset reference movement distance and when the movement speed of the mobile terminal corresponds to at least one of the preset reference movement speeds.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the first authentication unit is a case where the monitoring result, the time before the first authentication is performed after obtaining the check-in information exceeds a predetermined reference authentication time and the number of mobile unauthorized payments occurred in the store is preset
  • the first authentication level may be adjusted to correspond to at least one of cases where the reference number is exceeded.
  • the mobile terminal includes a check-in information collecting unit for obtaining the check-in information corresponding to the store entered by the user;
  • a primary authentication performing unit configured to perform primary authentication corresponding to pre-approval for a purchase corresponding to the store by inputting primary authentication information;
  • a second authentication performing unit performing touch pattern based second authentication for second authentication dependent on the first authentication when the first authentication is valid;
  • a payment performing unit for transmitting the information corresponding to the second authentication to the server to perform the offline payment in the store, and receives the result of the offline payment.
  • the offline payment processing method comprises the steps of obtaining the check-in information corresponding to the store entered by the user; Receiving first authentication information for first authentication corresponding to pre-approval for a purchase corresponding to the store from a mobile terminal; If the first authentication is valid, performing a second authentication that is dependent on the first authentication and is performed based on a touch pattern input to a sign pad of a POS; And performing offline payment at the store based on the result of the second authentication.
  • the performing of the second authentication may perform the second authentication according to whether or not the touch pattern registered by the user and the touch pattern match each other.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • the second authentication when the second authentication level is improved, the second authentication may be performed by further considering at least one of a touch length, a swipe direction, and a swipe speed.
  • the step of performing the second authentication is the mobile terminal after the first authentication when the monitoring result exceeds the predetermined reference purchase time from the first authentication until the product is submitted to the POS
  • the second authentication level is improved when the moving distance of the device exceeds at least one of the preset reference moving distances and when the moving speed of the mobile terminal after the first authentication exceeds a preset reference moving speed. You can.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the step of receiving the primary authentication information is when the monitoring result, the time before the first authentication is performed after acquiring the check-in information exceeds a predetermined reference authentication time and the mobile irregularity occurred in the store
  • the number of payments corresponds to at least one of the cases in which the number of payments exceeds a preset reference number
  • the first authentication level may be improved.
  • the offline payment processing apparatus includes a check-in information obtaining unit for obtaining check-in information corresponding to the store entered by the user; A first authentication unit for first authentication corresponding to pre-approval for a purchase corresponding to the store from a mobile terminal, the first authentication unit receiving first authentication information generated according to a swipe operation pattern for the mobile terminal; Reviewing whether the primary authentication is valid, and when the primary authentication is valid, generates secondary authentication information for secondary authentication dependent on the primary authentication to generate at least the POS corresponding to the mobile terminal and the store. A second authentication unit transmitting one; And a payment processing unit which performs offline payment in the store based on the second authentication result using the second authentication information.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • the first authentication unit may perform the first authentication by comparing the swipe operation pattern with a registration pattern registered by the user in advance through an application installed in the mobile terminal.
  • the registration pattern is a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern according to the first authentication level corresponding to the first authentication. Can be registered within.
  • the primary authentication corresponds to the release conditional authentication, and when the primary authentication is released, the secondary authentication information may be invalidated.
  • the first authentication level may be adjusted according to the monitoring result for the mobile terminal obtained by the check-in information.
  • the first authentication unit is a case where the monitoring result, the time before the first authentication is performed after obtaining the check-in information exceeds a predetermined reference authentication time and the number of mobile unauthorized payments occurred in the store is preset
  • the first authentication level may be adjusted to correspond to at least one of cases where the reference number is exceeded.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • the mobile terminal includes a check-in information collecting unit for obtaining the check-in information corresponding to the store entered by the user;
  • a first authentication performing unit configured to input first authentication information corresponding to a swipe operation pattern to perform first authentication corresponding to pre-approval for a purchase corresponding to the store;
  • a second authentication performing unit generating second authentication information for second authentication dependent on the first authentication when the first authentication is valid;
  • a payment performing unit for transmitting the second authentication information to any one of the server and the POS corresponding to the store in order to perform the offline payment in the store, and receives the result of the offline payment.
  • the offline payment processing method comprises the steps of obtaining the check-in information corresponding to the store entered by the user; Receiving first authentication information generated for a first authentication corresponding to a pre-approval for a purchase corresponding to the store from a mobile terminal, and corresponding to a swipe operation pattern for the mobile terminal; Reviewing whether the primary authentication is valid, and when the primary authentication is valid, generates secondary authentication information for secondary authentication dependent on the primary authentication to generate at least the POS corresponding to the mobile terminal and the store. Transmitting to one; And performing an offline payment at the store based on a second authentication result using the second authentication information.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • the primary authentication may be performed by comparing a swipe operation pattern with a registration pattern previously registered by the user through an application installed in the mobile terminal.
  • the registration pattern is a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern according to the first authentication level corresponding to the first authentication. Can be registered within.
  • the primary authentication corresponds to the release conditional authentication, and when the primary authentication is released, the secondary authentication information may be invalidated.
  • the first authentication level may be adjusted according to the monitoring result for the mobile terminal obtained by the check-in information.
  • the step of receiving the primary authentication information is when the monitoring result, the time before the first authentication is performed after acquiring the check-in information exceeds a predetermined reference authentication time and the mobile irregularity occurred in the store
  • the number of payments corresponds to at least one of the cases in which the number of payments exceeds a preset reference number
  • the first authentication level may be improved.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result of the mobile terminal until the product corresponding to the purchase is submitted to the POS.
  • convenience of payment may be provided by performing second authentication using a cross point generated according to a touch trace input by the user.
  • the present invention can provide a more stable offline payment system by varying the authentication level for payment in accordance with the monitoring condition before payment.
  • the present invention can prevent the risk of security that may occur in the purchase process after the first authentication is completed by performing the second authentication based on the first authentication.
  • the present invention can process the payment based on pre-authentication, and can safely and conveniently perform offline payment only with a mobile terminal without taking out a wallet or a card.
  • the present invention can provide convenience of payment by performing the second authentication based on the touch pattern input by the user when the user performs offline payment using the mobile terminal.
  • the present invention can provide a higher safety based on the two-channel authentication when the user performs the offline payment using the mobile terminal.
  • the present invention can safely perform offline payment without taking out the mobile terminal based on the swipe pattern-based pre-authentication.
  • the present invention can provide a stable payment service while maximizing user convenience when offline payment using a mobile terminal.
  • FIG. 1 is a block diagram showing an offline payment system using an application pay in one embodiment of the present invention.
  • FIG. 2 is a block diagram showing an offline payment processing apparatus according to an embodiment of the present invention.
  • FIG. 3 is a block diagram showing a mobile terminal according to an embodiment of the present invention.
  • 4 to 8 are diagrams showing a payment progress screen when an application member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • 9 to 15 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • 16 is a diagram illustrating an example of registering a cross point according to the present invention.
  • 17 is a diagram illustrating another example of registering a cross point according to the present invention.
  • FIG. 18 is a flowchart illustrating an offline payment processing method in terms of an offline payment processing apparatus according to an embodiment of the present invention.
  • 19 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention in terms of a mobile terminal.
  • FIG. 20 is a diagram illustrating a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 18.
  • FIG. 21 is a detailed diagram illustrating a process of improving first authentication level of first authentication in the offline payment processing method illustrated in FIG. 18.
  • 22 is a block diagram showing an offline payment system using an application pay in one embodiment of the present invention.
  • 23 is a block diagram showing an offline payment processing apparatus according to an embodiment of the present invention.
  • 24 is a block diagram showing a mobile terminal according to an embodiment of the present invention.
  • 25 to 29 are views showing a payment progress screen when an application member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • FIGS. 30 to 36 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • FIG. 37 is a diagram illustrating an example of registering a touch pattern according to the present invention.
  • 38 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention in terms of an offline payment processing device.
  • 39 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention from the mobile terminal side.
  • FIG. 40 is a diagram illustrating in detail a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 38.
  • FIG. 41 is a diagram illustrating a process of improving the first authentication level of first authentication in the offline payment processing method illustrated in FIG. 38.
  • FIG. 42 is a block diagram illustrating an offline payment system using an application pay in one embodiment of the present invention.
  • FIG. 43 is a block diagram showing an offline payment processing apparatus according to an embodiment of the present invention.
  • 44 is a block diagram illustrating a mobile terminal according to an embodiment of the present invention.
  • 45 to 49 are diagrams illustrating a payment progress screen when an application member is used in a payment method through BLE PUSH according to an embodiment of the present invention.
  • 50 to 56 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • 57 is a flowchart illustrating an offline payment processing method in terms of an offline payment processing apparatus according to an embodiment of the present invention.
  • FIG. 58 is a flowchart illustrating an offline payment processing method in a mobile terminal side according to an embodiment of the present invention.
  • FIG. 59 is a detailed diagram illustrating a process of improving first authentication level of first authentication in the offline payment processing method illustrated in FIG. 57.
  • FIG. 60 is a diagram illustrating a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 57.
  • FIG. 1 is a block diagram showing an offline payment system using an application pay in one embodiment of the present invention.
  • a payment system using an application pay includes an application server 110, a terminal 120, a POS device 130, a BLE server 140, and a BLE device 150. Include.
  • the payment system may correspond to a system for performing payment using an application pay based on an application installed in a mobile terminal of a user when purchasing a product at an offline store.
  • the application server 110 may be a server that provides an application 111 for performing payment with information related to payment to the user terminal 120 and performs a procedure related to payment. In this case, the application server 110 may transmit and receive data through the network.
  • the application server 110 may be an offline payment processing device according to an embodiment of the present invention.
  • the application server 110 may include an offline payment processing apparatus according to an embodiment of the present invention.
  • the network provides a passage for transferring data between the application server 110 and the terminal 120, and is a concept encompassing both a network used in the future and a network that can be developed in the future.
  • a network may provide communication between earth stations and earth stations by using a wired / wireless local area network that provides communication of various information devices within a limited area, a mobile communication network that provides communication between each other, and between the mobile device and the outside of the mobile device, and satellites. It may be one of a satellite communication network or a wired or wireless communication network, or a combination of two or more.
  • the transmission standard of the network is not limited to the existing transmission standard, and may include all transmission standard that will be developed in the future.
  • the network used between the application server 110 and the terminal 120 in FIG. 1 is different from the network used between the application server 120 and the POS device 130 and the BLE server 140 and the terminal 120. May be the same or may be the same.
  • the terminal 120 receives information corresponding to product payment from the application server 110 using an application and provides the same to the user.
  • the terminal 120 is a device capable of executing an application connected to a communication network, and includes a mobile phone, a portable multimedia player (PMP), a mobile internet device (MID), a smart phone, a tablet computer, It may be a mobile terminal having various mobile communication specifications such as a notebook (Note book), a net book (Net Book), a personal digital assistant (PDA) and an information communication device.
  • PMP portable multimedia player
  • MID mobile internet device
  • smart phone a tablet computer
  • PDA personal digital assistant
  • the terminal 120 may receive various information such as numerals and text information, and may transmit various signals to the controller through an input unit for setting various functions and controlling functions of the terminal 120.
  • the input unit of the terminal 120 may include at least one of a keypad and a touch pad generating an input signal according to a user's touch or manipulation.
  • the input unit of the terminal 120 is configured in the form of a single touch panel (or touch screen) together with the display unit of the terminal 120 to simultaneously perform input and display functions.
  • the input unit of the terminal 120 may use any type of input means that may be developed in the future.
  • the input unit of the terminal 120 according to the present invention may transmit an input signal for selecting a card or performing a payment to the controller of the terminal 120 based on an optimal card recommendation system.
  • the display unit of the terminal 120 may display information on a series of operation states and operation results generated while performing the function of the terminal 120. In addition, the display unit of the terminal 120 may display a menu of the terminal 120 and user data input by the user.
  • the display unit of the terminal 120 includes a liquid crystal display (LCD), an ultra-thin liquid crystal display (TFT-LCD), a light emitting diode (LED), and an organic light emitting diode (OLED). , Organic LED), an active organic light emitting diode (AMOLED, Active Matrix OLED), a Retina display, a flexible display, and a three-dimensional display.
  • the display unit of the terminal 120 when the display unit of the terminal 120 is configured in the form of a touch screen, the display unit of the terminal 120 may perform some or all of the functions of the input unit of the terminal 120.
  • the display unit of the terminal 120 according to the present invention may display information related to the optimal recommendation card and payment provided on the basis of the optimal card recommendation system on a screen.
  • the storage unit of the terminal 120 is a device for storing data, and includes a main memory device and an auxiliary memory device, and may store an application program required for a functional operation of the terminal 120.
  • the storage unit of the terminal 120 may largely include a program area and a data area. In this case, when the terminal 120 activates each function in response to a user's request, the terminal 120 executes corresponding application programs under the control of the controller to provide each function.
  • the storage unit of the terminal 120 may store an operating system for booting the terminal 120, a program for recommending a card or performing a payment based on an optimal card recommendation system.
  • the storage unit of the terminal 120 may store a content DB for storing a plurality of contents and information of the terminal 120.
  • the content DB may include execution data for executing the content and attribute information on the content, and content usage information according to the content execution may be stored.
  • the information of the terminal 120 may include terminal specification information.
  • the communication unit of the terminal 120 may perform a function for transmitting and receiving data with the application server 110 through a network.
  • the communication unit of the terminal 120 may include RF transmission means for up-converting and amplifying the frequency of the transmitted signal, and RF reception means for low-noise-amplifying and down-converting the received signal.
  • the communication unit of the terminal 120 may include at least one of a wireless communication module and a wired communication module.
  • the wireless communication module is configured to transmit and receive data according to a wireless communication method. When the terminal 120 uses wireless communication, any one of a wireless network communication module, a wireless LAN communication module, and a wireless fan communication module may be used. Data may be transmitted and received to the application server 110.
  • the wired communication module is for transmitting and receiving data by wire.
  • the wired communication module may be connected to a network through a wire to transmit and receive data to and from the application server 110. That is, the terminal 120 accesses a network using a wireless communication module or a wired communication module, and transmits and receives data to and from the application server 110 through the network.
  • the terminal 120, the application server 110, and the BLE server 140 may communicate with each other to transmit and receive data necessary for recommending the optimal card based on the optimal card recommendation system.
  • the controller of the terminal 120 may be a process device for driving an operating system (OS) and each component, for example, the controller may control the overall process of accessing the application server 110.
  • OS operating system
  • the controller may control the overall process of running the service application according to the user's request, and at the same time the service use request to the application server 110 It may be controlled to be transmitted, and in this case, it may be controlled to transmit the information of the terminal 120 required for user authentication.
  • the controller of the terminal 120 may execute specific content stored in the storage of the terminal 120 according to a user's request.
  • the controller may store a content usage history according to content execution as content usage information.
  • the terminal 120 of the user has an application for the application pay service is installed, it may correspond to the terminal 120 of the user subscribed to the application pay service.
  • the POS device 130 is a device for performing payment of goods in the store 160, and may correspond to a device capable of performing an application pay service based on communication with the application server 110.
  • the BLE server 140 may be a server for identifying the location of the terminal 120 and providing information by using a Bluetooth low energy technology.
  • the Bluetooth low power technology is a short-range wireless communication technology that periodically transmits information of an object based on Bluetooth 4.0 within a predetermined radius range. That is, even if a user of the terminal 120 does not take any action, the user of the terminal 120 may automatically detect the location of the user and provide a signal for a payment service.
  • beacon is a short-range data communication technology using Bluetooth Low Energy (BLE), and various application services such as object and situation recognition, content push, indoor location positioning, automatic check-in, and geofencing based on proximity positioning. Can be enabled. Compared with similar technologies in the past, it is more convenient and can be provided at a lower cost, which can serve as a catalyst for forming a new service market.
  • the beacon may refer to any device that periodically transmits a signal.
  • the BLE device 150 illustrated in FIG. 1 may correspond to a beacon.
  • Such beacons may be divided into sound-based low frequency beacons, LED beacons, Wi-Fi beacons, and Bluetooth beacons according to a method of transmitting a signal.
  • the beacon can transmit a periodic signal in a small packet of approximately 21 bytes, does not need to be paired with the receiving target, and operates at low power, but the ID value and the received signal strength of the beacon transmitter up to 50 meters It is possible to transmit a signal corresponding to.
  • the price is small and can be easily attached anywhere, it can be used anywhere even in an offline store.
  • the terminal 120 may detect a corresponding terminal 120 and transmit a signal including information. .
  • the store 160 may correspond to an offline store where payment is performed, and may correspond to an application pay service affiliated store where the application pay agent and the BLE device 150 are installed.
  • the user may enter the store 160 with the terminal 120.
  • the beacon which is a BLE-based short-range data communication technology, may be used to detect that the user has entered the store 160.
  • the BLE signal transmitted from the BLE device 150 which is a beacon located in the store 160, may be received by the Bluetooth-enabled terminal 120 using the BLE SDK 141.
  • the BLE signal may be received through the application 111 installed based on the BLE SDK 141.
  • the BLE server 140 may provide the terminal 120 with information related to the BLE benefit corresponding to the BLE signal. .
  • the terminal 120 may access the application server 110 based on the BLE benefit information received from the BLE server 140 through the application.
  • the application server 110 may include at least one module for performing payment.
  • the application server 110 may include a membership providing module that may provide membership information based on user information of the terminal 120 and store information corresponding to the store 160.
  • the membership providing module may include a separate database for storing membership information for each user and store information for each store.
  • the application server 110 may include an application pay payment module for performing a payment through the application pay.
  • the application pay payment module may include credit card information or bank information for performing a payment through the application pay. For example, when a user pays an application pay through a credit card to purchase a product at the store 160, the application pay payment module and the credit card application may transmit and receive data for performing real time payment.
  • the application pay payment module may include an optimal card recommendation device for recommending an optimal card in consideration of discount benefits, store benefits, and accumulation among credit cards possessed by a user based on credit card information.
  • the best card according to the discount rate or the accumulation rate may be recommended by combining the benefit information provided through the membership card and the benefit information provided through the membership card when the target performance of the previous month was achieved for each type of credit card.
  • the optimal card recommendation device may be configured independently of the application pay payment module.
  • the application server 110 through the membership providing module membership information, coupons or gift information for the user can use in the store 160, event information and marketing information in progress in the store 160, etc. It may include a store information providing module that can provide.
  • the store information providing module provides the application server 110 by searching for the gift icons or coupons that the user can use in the store 160 through the application, so that the user can display the gift icons through the application installed in the terminal 120. You can use the coupon.
  • the store information providing module provides the application server 110 with event information and marketing information corresponding to a plurality of stores that provide a service according to an embodiment of the present invention. Information about the ongoing event and marketing in 160 may be provided to the user terminal 120.
  • the user accessing the application server 110 through the terminal 120 may perform pre-authentication in the application pay service to purchase a product in the store 160.
  • the user may enter a step for pre-authentication by receiving a purchase-related push message through the BLE device 150 and clicking a purchase button included in the push message.
  • various methods such as a PIN number input, a picture image gesture and a touch gesture may be used as pre-authentication for purchase, that is, primary authentication.
  • the offline payment processing apparatus included in the application server 110 or corresponding to the application server 110 receives the corresponding first authentication information of the first authentication performed by the terminal 120 to determine whether to authenticate. You can judge.
  • the user moves to the POS device 130 with the product to be purchased in the store 160, and expresses a willingness to pay through the application pay at the cashier of the store 160, and performs the second authentication for the purchase and payment of the product. can do.
  • the second authentication may be authentication dependent on the first authentication, and the second authentication may be performed while the first authentication is valid.
  • a user has a terminal 120 and is located in a zone for payment near the POS device 130, and inputs a gesture gesture pattern using the terminal 120 within the payment zone.
  • the POS device 130 may check the user who uses the application pay service and proceed with payment.
  • the application server 110 may transmit a message indicating whether payment through the application pay was successfully performed to at least one of the terminal 120 or the POS device 130 of the user.
  • FIG. 2 is a block diagram showing an offline payment processing apparatus according to an embodiment of the present invention.
  • the offline payment processing apparatus is a communication unit 210, check-in information acquisition unit 220, primary authentication unit 230, secondary authentication unit 240, payment processing unit 250 and storage unit 260.
  • the communication unit 210 plays a role of transmitting and receiving information necessary for offline payment processing with a mobile terminal of a user through a communication network such as a network.
  • the communication unit 210 may receive information for performing check-in, first authentication, and second authentication from the mobile terminal, and provide the mobile terminal with information corresponding to offline payment processing. have.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the check-in information obtaining unit 220 obtains check-in information corresponding to a store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the primary authentication unit 230 receives primary authentication information for primary authentication corresponding to a preauthorization of a purchase corresponding to a store from the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the primary authentication may correspond to entering a PIN number in the mobile terminal. That is, the first authentication may be performed at the mobile terminal. For example, when the PIN is input to perform the first authentication in the mobile terminal, the first approval may be made by recognizing the PIN number input to the mobile terminal as the first authentication information and transmitting the same to the offline payment processing device. .
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the primary authentication may be adjusted and performed to add a procedure for inputting a PIN number when the primary authentication level is improved.
  • the keyboard of the mobile terminal may be changed every time a PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication level may be improved by different conditions that may be additionally considered in the first authentication according to the first authentication method. For example, assuming that the primary authentication method corresponds to fingerprint recognition, as the primary authentication level is improved, the user may further request fingerprint recognition of another finger. In addition, in the case of face recognition, in addition to recognizing the front of the face, the left or right side of the face may be recognized.
  • the second authentication unit 240 performs the second authentication which is dependent on the first authentication and is performed based on the cross point of the touch trace input to the sign pad of the POS.
  • the second authentication may be performed according to whether or not the cross point and the registered cross point registered by the user are matched with each other.
  • the touch trace may be input so that the same number of cross points as the registered cross points are generated to perform the second authentication.
  • the second authentication may be performed using a device capable of inputting a touch trace, that is, a mobile terminal or a terminal capable of touch input.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • secondary authentication may be performed by further considering at least one condition among the number of cross points and the location of the cross points.
  • the number of cross points may be increased when the touch trace is input, or the position where the cross points are generated may be set on the screen of the sign pad.
  • the location of the cross point may be adjusted by dividing the area of the sign pad to divide each area and inputting a touch trace to generate a cross point in a specific area.
  • the touch trace may be input such that the position of the second cross point is located below the position of the first cross point.
  • the first touch point is inputted so that the first touch point is created in the first area of the segmented sine pad, and the second cross point is divided into four segments.
  • the touch trace may be input to be generated in area 2 of the sign pad.
  • the number of divisions of the sign pad can be freely set.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, when the primary authentication using the mobile terminal is completed, the POS may perform the secondary authentication for the user who has completed the primary authentication.
  • the payment processor 250 performs offline payment in a store based on the result of the second authentication. That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the storage unit 260 stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage unit 260 may be configured independently of the offline payment processing apparatus to support a function for an offline payment processing service. At this time, the storage unit 260 may operate as a separate mass storage, and may include a control function for performing the operation.
  • the offline payment processing device is equipped with a memory can store information in the device.
  • the memory is a computer readable medium.
  • the memory may be a volatile memory unit, and for other implementations, the memory may be a nonvolatile memory unit.
  • the storage device is a computer readable medium.
  • the storage device may include, for example, a hard disk device, an optical disk device, or some other mass storage device.
  • the convenience of payment can be provided by performing a second authentication using a cross point generated according to a touch trace input by the user. Can be.
  • FIG. 3 is a block diagram illustrating a mobile terminal according to an embodiment of the present invention.
  • another mobile terminal includes a check-in information collecting unit 310, a first authentication performing unit 320, a second authentication performing unit 330, and a payment performing unit 340. Include.
  • the check-in information collecting unit 310 obtains check-in information corresponding to the store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the first certification performing unit 320 performs the first certification corresponding to the approval of the purchase corresponding to the store. For example, when the PIN input window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the first authentication may be performed by inputting the PIN using the mobile terminal. Thereafter, the server and the offline payment processing device may process the first authentication by determining the PIN input through the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • the second authentication performing unit 330 performs cross-point based second authentication by touch trajectory for second authentication dependent on the first authentication.
  • the second authentication may be completed according to whether or not the registration cross point registered by the user in advance and the cross point of the touch trace input by the user are matched with each other. For example, when two registered cross points are included in the touch trace, the touch trace may be input so that the same number of cross points as the registered cross points are generated to perform the second authentication.
  • secondary authentication may be performed by further considering at least one condition among the number of cross points and the location of the cross points.
  • the number of cross points may be increased when the touch trace is input, or the location where the cross points are generated may be set on the touch screen of the mobile terminal.
  • the location of the cross point may be adjusted by dividing the touch screen area of the mobile terminal to divide each area and inputting a touch trace to generate a cross point in a specific area.
  • the relative position between the cross points may be considered or the absolute position of each cross point may be considered according to the touch screen area.
  • the touch trace may be input such that the position of the second cross point is located below the position of the first cross point.
  • the first cross point is inputted with a touch trace such that the first cross point is necessarily created in the first area of the touch screen area of the divided mobile terminal.
  • the touch trace may be input to be generated in area 2 of the divided sign pads.
  • the number of divisions of the touch area can be freely set.
  • the payment performing unit 340 transmits the information corresponding to the second authentication to the server in order to perform the offline payment in the store, and receives the result of the offline payment. For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • 4 to 8 are diagrams showing a payment progress screen when an application member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacons installed in the store, the product benefits screen 410 including the discount information and coupon information in the store included in the BLE signal to expose to the mobile terminal Can be. That is, the mobile terminal may obtain discount information and coupon information by obtaining check-in information corresponding to the store through the beacon of the store. In addition, the mobile terminal may provide check-in information to the offline payment processing device through the application.
  • the product benefit screen 410 may output discount information and coupon information together with a payment button on the lockscreen 412 of the mobile terminal.
  • the product benefit screen 410 may output discount information and coupon information along with a payment button on the BLE Noti 411 of the mobile terminal.
  • the detailed screen 510 of the store corresponding to the product benefits screen 410 through the application as shown in FIG. Can be output to the terminal.
  • the detailed screen 510 of the store may output more detailed discount and coupon information together with the store information.
  • a payment button can be output together so that the user can proceed with the payment process at any time.
  • a payment PIN input window (as shown in FIG. 6) to perform the first authentication for the application pay service ( 610 may be output. That is, based on the offline payment processing device linked through the application, the window for the first authentication corresponding to the approval of the corresponding store may be output to the mobile terminal.
  • the first authentication may use a picture image gesture authentication method, a touch gesture authentication method, a fingerprint recognition, a face recognition, and a voice recognition in addition to the PIN number input authentication method.
  • the PIN can be transferred to the offline payment processing device to complete the first authentication.
  • the offline payment processing device or the server may transmit information such as a picture or a phone number of the user who has completed the first authentication to the POS.
  • information corresponding to a user who has completed primary authentication that is, a buyer who has completed primary authentication may be displayed on the payment screen 710 on the POS device installed in the store.
  • the second authentication may be performed based on the first point authentication and is performed based on the cross point of the touch trace inputted to the sign pad at the POS.
  • the second authentication may be completed when the registration cross point registered in advance by the user is compared with the cross point input to the sign pad.
  • the user's mobile terminal may be inputted using the user's mobile terminal.
  • the payment success message 811 may be transmitted to the user's mobile terminal as shown in FIG. 8.
  • the payment success message 811 may display the name of the paid store, a payment method, and a payment amount.
  • the payment failure message 812 may be transmitted to the mobile terminal of the user, and the payment screen 813 may be output again to the mobile terminal in order to perform the payment again.
  • the payment screen 813 may output a payment button or a barcode for application pay payment.
  • 9 to 15 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacons installed in the store, and exposes the product benefits screen 910 including the discount information and coupon information in the store included in the BLE signal to the mobile terminal. Can be.
  • the product benefit screen 910 when the mobile terminal is locked, the product benefit screen 910 outputs discount information and coupon information to the lockscreen 912 of the terminal, but the payment button may not be output because it is a non-member of the application pay service. .
  • the product benefit screen 910 may output the discount information and coupon information to the BLE Noti (911) of the mobile terminal.
  • the detailed screen 1010 of the store may output more detailed discount and coupon information together with the store information.
  • a pay app subscription button for subscribing to an application pay service may be output together so that a user may subscribe to a service for payment at any time.
  • the user authentication screen 1210 may be output to the mobile terminal to authenticate the user.
  • the user authentication may be performed by inputting a user's name, social security number, communication company and mobile phone number, and the like, and inputting an authentication number.
  • the payment PIN registration screen 1310 may be output to the mobile terminal in order to register the payment PIN number used for the first authentication in the application pay service as shown in FIG. 13.
  • the payment PIN registration screen 1310 not only the payment PIN registration screen 1310 but also a registration screen of various authentication means such as a fingerprint registration screen and a voice registration screen may be output according to the primary authentication method.
  • the card information registration screen 1410 may be output to the mobile terminal as shown in FIG. 14 to register the card to be used in the application pay service.
  • the subscription confirmation screen 1510 is finally outputted as shown in FIG. 15, and when the user selects confirmation, the subscription may be completed.
  • the user may provide an application pay service after performing a first authentication through a PIN number by outputting a payment button to the user's mobile terminal.
  • 16 is a diagram illustrating an example of registering a cross point according to the present invention.
  • a cross point may be registered in advance. For example, when a cross point registration window 1610 is displayed as shown in FIG. 16 in the process of subscribing to an application pay service using a mobile terminal of the user, the user directly registers the cross point 1630 by inputting a touch trace 1620. can do.
  • the cross point 1630 may be a portion that overlaps when the touch trace 1620 is input.
  • at least one cross point 1630 may be included in the touch trace 1620.
  • a plurality of cross points may be included in the touch trace.
  • 17 is a diagram illustrating another example of registering a cross point according to the present invention.
  • a user registers a plurality of cross points as a registration cross point to be used for payment.
  • the second authentication may be performed corresponding to the second authentication level, and the number of cross points or the location of the cross points may be further considered in the second authentication according to the second authentication level.
  • the second authentication may be performed by further considering the relative position between the two cross points 1730 and 1731. That is, it may be further confirmed whether the position on the first generated cross point 1730 is located above the position of the second generated cross point 1731. If the location of the second generated cross point 1731 is located above the first generated cross point 1730, the second authentication may fail.
  • the second authentication may be performed by further considering the absolute positions of each of the two cross points 1730 and 1731. That is, it is checked whether the position of the first generated cross point 1730 is located in the first area of the upper left of the areas of the four divided sign pads, and the sign of the second generated cross point 1731 is divided into four parts. You can check whether it is located in the fourth area of the bottom right of the pad area. If at least one cross point 1730 and 1731 are not located in the corresponding area, the second authentication may fail.
  • FIG. 18 is a flowchart illustrating an offline payment processing method in terms of an offline payment processing apparatus according to an embodiment of the present invention.
  • the offline payment processing method obtains check-in information corresponding to a store where a user enters (S1810).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the offline payment processing method receives the first authentication information for the first authentication corresponding to the approval for the purchase corresponding to the store from the mobile terminal (S1820).
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the primary authentication may correspond to entering a PIN number in the mobile terminal. That is, the first authentication may be performed at the mobile terminal. For example, when the PIN is input to perform the first authentication in the mobile terminal, the first approval may be made by recognizing the PIN number input to the mobile terminal as the first authentication information and transmitting the same to the offline payment processing device. .
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the primary authentication may be adjusted and performed to add a procedure for inputting a PIN number when the primary authentication level is improved.
  • the keyboard of the mobile terminal may be changed every time a PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication level may be improved by different conditions that may be additionally considered in the first authentication according to the first authentication method. For example, assuming that the primary authentication method corresponds to fingerprint recognition, as the primary authentication level is improved, the user may further request fingerprint recognition of another finger. In addition, in the case of face recognition, the left side or the right side of the face may be recognized in addition to recognizing the front side of the face.
  • the offline payment processing method determines whether the first authentication is valid (S1825).
  • the offline payment processing method is dependent on the primary authentication and is based on the cross point of the touch trace input to the sign pad of the POS.
  • Second authentication is performed by performing (S1830).
  • the second authentication may be performed according to whether or not the cross point and the registered cross point registered by the user are matched with each other.
  • the touch trace may be input so that the same number of cross points as the registered cross points are generated to perform the second authentication.
  • the second authentication may be performed using a device capable of inputting a touch trace, that is, a mobile terminal or a terminal capable of touch input.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • secondary authentication may be performed by further considering at least one condition among the number of cross points and the location of the cross points.
  • the number of cross points may be increased when the touch trace is input, or the position where the cross points are generated may be set on the screen of the sign pad.
  • the location of the cross point may be adjusted by dividing the area of the sign pad to divide each area and inputting a touch trace to generate a cross point in a specific area.
  • the touch trace may be input such that the position of the second cross point is located below the position of the first cross point.
  • the first touch point is inputted so that the first touch point is created in the first area of the segmented sine pad, and the second cross point is divided into four segments.
  • the touch trace may be input to be generated in area 2 of the sign pad.
  • the number of divisions of the sign pad can be freely set.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, when the primary authentication using the mobile terminal is completed, the POS may perform the secondary authentication for the user who has completed the primary authentication.
  • the primary authentication information may be received to perform the primary authentication again.
  • the offline payment processing method performs the offline payment in the store based on the result of the second authentication (S1840). That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the offline payment processing method transmits and receives information required for offline payment processing with the mobile terminal of the user through a communication network, such as a network.
  • a communication network such as a network.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the offline payment processing method according to an embodiment of the present invention stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage module for storing information may be configured independently of the offline payment processing device to support a function for an offline payment processing service.
  • the storage module may operate as a separate mass storage and may include a control function for performing an operation.
  • 19 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention in terms of a mobile terminal.
  • the offline payment processing method obtains check-in information corresponding to a store where a user enters (S1910).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the offline payment processing method performs a first authentication corresponding to a pre-approval for a purchase corresponding to a store (S1920). For example, when the PIN input window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the first authentication may be performed by inputting the PIN using the mobile terminal. Thereafter, the server and the offline payment processing device may process the first authentication by determining the PIN input through the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the offline payment processing method determines whether the first authentication is valid (S1925).
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • the first authentication may be performed.
  • the offline payment processing method may be based on crosspoints based on the touch point for secondary authentication dependent on the primary authentication.
  • the second authentication is performed (S1930).
  • the second authentication may be completed according to whether or not the registration cross point registered by the user in advance and the cross point of the touch trace input by the user are matched with each other. For example, when two registered cross points are included in the touch trace, the touch trace may be input so that the same number of cross points as the registered cross points are generated to perform the second authentication.
  • secondary authentication may be performed by further considering at least one condition among the number of cross points and the location of the cross points.
  • the number of cross points may be increased when the touch trace is input, or the location where the cross points are generated may be set on the touch screen of the mobile terminal.
  • the location of the cross point may be adjusted by dividing the touch screen area of the mobile terminal to divide each area and inputting a touch trace to generate a cross point in a specific area.
  • the relative position between the cross points may be considered or the absolute position of each cross point may be considered according to the touch screen area.
  • the touch trace may be input such that the position of the second cross point is located below the position of the first cross point.
  • the first cross point is inputted with a touch trace such that the first cross point is necessarily created in the first area of the touch screen area of the divided mobile terminal.
  • the touch trace may be input so that the touch trace may be generated in area 2 of the touch screen region of the divided mobile terminal.
  • the number of divisions of the touch area can be freely set.
  • the offline payment processing method transmits the information corresponding to the second authentication to the server to perform the offline payment in the store, and receives the result of the offline payment (S1940). For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • FIG. 20 is a diagram illustrating a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 18.
  • a monitoring result of the mobile terminal is obtained until the product is submitted to the POS (S2010). That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the monitoring result exceeds the preset reference purchase time from the first authentication until the product is submitted to the POS
  • the travel distance of the mobile terminal after the first authentication exceeds the preset reference travel distance
  • the second authentication level improvement condition is satisfied when the moving speed of the mobile terminal corresponds to at least one of the cases in which the preset moving speed exceeds the preset reference moving speed.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication is performed by further considering at least one condition among the number of cross points and the location of the cross points (S2020).
  • the number of cross points may be increased or a position at which a cross point is generated may be set on the touch screen of the mobile terminal.
  • the position of the cross point may be adjusted by dividing the sine pad area to divide each area and inputting a touch trace to generate a cross point in a specific area.
  • the touch trace may be input such that the position of the second cross point is located below the position of the first cross point.
  • the touch trajectory is input so that the first cross point is necessarily created in the first segment of the divided sine pad area, and the second cross point is the sine divided.
  • the touch trace may be input to be generated in area 2 of the pad area.
  • the number of divisions of the touch area can be freely set.
  • step S2015 if the monitoring result of the determination result of step S2015 does not satisfy the condition for improving the second authentication level, the second authentication is performed without performing a process for improving the second authentication level (S2030).
  • FIG. 21 is a detailed diagram illustrating a process of improving first authentication level of first authentication in the offline payment processing method illustrated in FIG. 18.
  • a monitoring result of the mobile terminal is obtained based on check-in information (S2110).
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the first authentication level improvement condition is satisfied. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the first authentication level is improved by adding an element considered in the first authentication according to the first authentication method (S2120).
  • the primary authentication method is a PIN input
  • the keyboard of the mobile terminal may be changed every time the PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication may be performed without improving the first authentication level.
  • 22 is a block diagram showing an offline payment system using an application pay in one embodiment of the present invention.
  • a payment system using an application pay includes an application server 2110, a terminal 2120, a POS device 2130, a BLE server 2140, and a BLE device 2150. Include.
  • the payment system may correspond to a system for performing payment using an application pay based on an application installed in a mobile terminal of a user when purchasing a product at an offline store.
  • the application server 2110 may be a server that provides an application 2111 for performing payment with information related to payment to the user's terminal 2120 to perform a procedure related to payment.
  • the application server 2110 may transmit and receive data through a network.
  • the application server 2110 may be an offline payment processing apparatus according to an embodiment of the present invention.
  • the application server 2110 may include an offline payment processing apparatus according to an embodiment of the present invention.
  • the network provides a passage for transferring data between the application server 2110 and the terminal 2120, and is a concept encompassing both a network that is used in the future and a network that can be developed in the future.
  • the network may be a wired / wireless local area network that provides communication of various information devices within a limited area, a mobile communication network that provides communication between each other, and between the mobile device and the outside of the mobile device, and provides communication between earth stations and earth stations using satellites. It may be either a satellite communication network or a wired or wireless communication network, or a combination of two or more.
  • the transmission standard of the network is not limited to the existing transmission standard, and may include all transmission standard that will be developed in the future.
  • the network used between the application server 2110 and the terminal 2120 is different from the network used between the application server 2120 and the POS device 2130 and the BLE server 2140 and the terminal 2120. May be the same or may be the same.
  • the terminal 2120 receives information corresponding to product payment from the application server 2110 using an application and provides the same to the user.
  • the terminal 2120 is a device that is connected to a communication network and executes an application, and includes a mobile phone, a portable multimedia player (PMP), a mobile internet device (MID), a smart phone, a tablet computer, It may be a mobile terminal having various mobile communication specifications such as a notebook (Note book), a net book (Net Book), a personal digital assistant (PDA) and an information communication device.
  • PMP portable multimedia player
  • MID mobile internet device
  • smart phone a tablet computer
  • PDA personal digital assistant
  • the terminal 2120 may receive various information such as numeric and text information, and may set various functions and transmit a signal input in connection with the function control of the terminal 2120 to the controller through the input unit.
  • the input unit of the terminal 2120 may include at least one of a keypad and a touch pad for generating an input signal according to a user's touch or manipulation.
  • the input unit of the terminal 2120 may be configured in the form of one touch panel (or touch screen) together with the display unit of the terminal 2120 to simultaneously perform input and display functions.
  • the input unit of the terminal 2120 may use any type of input means that may be developed in the future.
  • the input unit of the terminal 2120 according to the present invention may transmit an input signal for selecting a card or performing a payment to the controller of the terminal 2120 based on an optimal card recommendation system.
  • the display unit of the terminal 2120 may display information on a series of operation states and operation results generated while the function of the terminal 2120 is performed. In addition, the display unit of the terminal 2120 may display a menu of the terminal 2120 and user data input by the user.
  • the display unit of the terminal 2120 includes a liquid crystal display (LCD), an ultra-thin liquid crystal display (TFT-LCD, thin film transistor LCD), a light emitting diode (LED), and an organic light emitting diode (OLED). , Organic LED), an active organic light emitting diode (AMOLED, Active Matrix OLED), a Retina display, a flexible display, and a three-dimensional display.
  • the display unit of the terminal 2120 when the display unit of the terminal 2120 is configured in the form of a touch screen, the display unit of the terminal 2120 may perform some or all of the functions of the input unit of the terminal 2120.
  • the display unit of the terminal 2120 according to the present invention may display information related to the optimal recommendation card and payment provided on the basis of the optimal card recommendation system on a screen.
  • the storage unit of the terminal 2120 is a device for storing data, and includes a main memory device and an auxiliary memory device, and may store an application program required for a functional operation of the terminal 2120.
  • the storage unit of the terminal 2120 may largely include a program area and a data area. In this case, when the terminal 2120 activates each function in response to a user's request, the terminal 2120 executes corresponding application programs under the control of the controller to provide each function.
  • the storage unit of the terminal 2120 may store an operating system for booting the terminal 2120, a program for recommending a card or performing a payment based on an optimal card recommendation system.
  • the storage unit of the terminal 2120 may store a content DB storing a plurality of contents and information of the terminal 2120.
  • the content DB may include execution data for executing the content and attribute information on the content, and content usage information according to the content execution may be stored.
  • the information of the terminal 2120 may include terminal specification information.
  • the communication unit of the terminal 2120 may perform a function for transmitting and receiving data with the application server 2110 through a network.
  • the communication unit of the terminal 2120 may include RF transmitting means for up-converting and amplifying a frequency of a transmitted signal, and RF receiving means for low-noise amplifying and down-converting a received signal.
  • the communication unit of the terminal 2120 may include at least one of a wireless communication module and a wired communication module.
  • the wireless communication module is configured to transmit and receive data according to a wireless communication method. When the terminal 2120 uses wireless communication, any one of a wireless network communication module, a wireless LAN communication module, and a wireless fan communication module may be used. Data may be transmitted and received to the application server 2110.
  • the wired communication module is for transmitting and receiving data by wire.
  • the wired communication module may connect to a network through a wire and transmit / receive data to / from the application server 2110. That is, the terminal 2120 may access a network using a wireless communication module or a wired communication module, and may transmit and receive data with the application server 2110 through the network.
  • the terminal 2120, the application server 2110, and the BLE server 2140 may communicate with each other to transmit and receive data necessary for recommending the optimal card based on the optimal card recommendation system.
  • the controller of the terminal 2120 may be a process device for driving an operating system (OS) and each component, for example, the controller may control the overall process of accessing the application server 2110.
  • OS operating system
  • the overall process of executing the service application may be controlled according to a user's request, and at the same time, a service use request is sent to the application server 2110. It may be controlled to be transmitted, and at this time, the information of the terminal 2120 required for user authentication may be transmitted together.
  • the controller of the terminal 2120 may execute specific content stored in the storage unit of the terminal 2120 according to a user's request.
  • the controller may store a content usage history according to content execution as content usage information.
  • the user terminal 2120 is installed with an application for the application pay service, it may correspond to the terminal 2120 of the user subscribed to the application pay service.
  • the POS device 2130 is a device for performing payment of goods at the store 2160 and may correspond to a device capable of performing an application pay service based on communication with the application server 2110.
  • the BLE server 2140 may be a server for locating the terminal 2120 and providing information by using a Bluetooth low energy technology.
  • the Bluetooth low power technology is a short-range wireless communication technology that periodically transmits information of an object based on Bluetooth 4.0 within a predetermined radius range. That is, even though the user of the terminal 2120 does not take any action, the user of the terminal 2120 may automatically detect the location of the user and provide a signal for a payment service.
  • beacon is a short-range data communication technology using Bluetooth Low Energy (BLE), and various application services such as object and situation recognition, content push, indoor location positioning, automatic check-in, and geofencing based on proximity positioning. Can be enabled. Compared with similar technologies in the past, it is more convenient and can be provided at a lower cost, which can serve as a catalyst for forming a new service market.
  • the beacon may refer to any device that periodically transmits a signal.
  • the BLE device 2150 illustrated in FIG. 22 may correspond to a beacon.
  • Such beacons may be divided into sound-based low frequency beacons, LED beacons, Wi-Fi beacons, and Bluetooth beacons according to a method of transmitting a signal.
  • the beacon can transmit a periodic signal in a small packet of approximately 21 bytes, does not need to be paired with the receiving target, and operates at low power, but the ID value and the received signal strength of the beacon transmitter up to 50 meters It is possible to transmit a signal corresponding to.
  • the price is small and can be easily attached anywhere, it can be used anywhere even in an offline store.
  • the terminal 2120 may detect the corresponding terminal 2120 and transmit a signal including information. .
  • the store 2160 may correspond to an offline store where payment is performed, and may correspond to an application pay service affiliated store in which an application pay agent and a BLE device 2150 are installed.
  • the user may enter the store 2160 with the terminal 2120.
  • the beacon which is a BLE-based short-range data communication technology, may be used to detect that the user enters the store 2160.
  • the BLE signal transmitted from the BLE device 2150 which is a beacon located in the store 2160, may be received by the Bluetooth-enabled terminal 2120 using the BLE SDK 2141.
  • the BLE signal may be received through the application 2111 installed based on the BLE SDK 2141.
  • the BLE server 2140 may provide the terminal 2120 with information related to BLE benefits corresponding to the BLE signal. .
  • the terminal 2120 may access the application server 2110 based on the BLE benefit information received from the BLE server 2140 through the application.
  • the application server 2110 may include at least one module for performing payment.
  • the application server 2110 may include a membership providing module that may provide membership information based on user information of the terminal 2120 and store information corresponding to the store 2160.
  • the membership providing module may include a separate database for storing membership information for each user and store information for each store.
  • the application server 2110 may include an application pay payment module for performing a payment through an application pay.
  • the application pay payment module may include credit card information or bank information for performing a payment through the application pay. For example, when a user pays an application pay through a credit card to purchase a product at the store 2160, the application pay payment module and the credit card application may transmit and receive data for performing real time payment.
  • the application pay payment module may include an optimal card recommendation device for recommending an optimal card in consideration of discount benefits, store benefits, and accumulation among credit cards possessed by a user based on credit card information.
  • the best card according to the discount rate or the accumulation rate may be recommended by combining the benefit information provided through the membership card and the benefit information provided through the membership card when the target performance of the previous month was achieved for each type of credit card.
  • the optimal card recommendation device may be configured independently of the application pay payment module.
  • the application server 2110 through the membership providing module, along with membership information, coupon information for the user or coupons available in the store 2160, benefits information for the event or marketing in progress in the store 2160, etc. It may include a store information providing module that can provide.
  • the store information providing module searches for a gift icon or a coupon that can be used in the store 2160 by the user and provides the application server 2110 with the application server 2110, so that the user can display the gift icon or the application through the application installed in the terminal 2120. You can use the coupon.
  • the store information providing module provides the application server 2110 with event information and marketing information corresponding to a plurality of stores that provide a service according to an embodiment of the present invention. In operation 2160, information about an ongoing event and marketing may be provided to the user terminal 2120.
  • a user accessing the application server 2110 through the terminal 2120 may perform pre-authentication in the application pay service to purchase a product in the store 2160.
  • the BLE device 2150 may enter a step for pre-authentication by receiving a purchase-related push message and clicking a purchase button included in the push message.
  • various methods such as a PIN number input, a picture image gesture and a touch gesture may be used as pre-authentication for purchase, that is, primary authentication.
  • the offline payment processing apparatus included in the application server 2110 or corresponding to the application server 2110 receives the corresponding first authentication information of the first authentication performed by the terminal 2120 to determine whether to authenticate. You can judge.
  • the user moves to the POS device 2130 with the product to be purchased at the store 2160, and expresses a willingness to pay through an application pay at a store clerk of the store 2160, and performs a second authentication for product purchase and payment. can do.
  • the second authentication may be authentication dependent on the first authentication, and the second authentication may be performed while the first authentication is valid.
  • a user has a terminal 2120 and is located in a zone for payment near the POS device 2130, and inputs a movement gesture pattern using the terminal 2120 within a payment zone.
  • the POS device 2130 may check the user who uses the application pay service and proceed with payment.
  • the application server 2110 may transmit a message indicating whether the payment through the application pay was successfully performed to at least one of the terminal 2120 or the POS device 2130 of the user.
  • 23 is a block diagram showing an offline payment processing apparatus according to an embodiment of the present invention.
  • an offline payment processing apparatus includes a communication unit 2210, a check-in information acquisition unit 2220, a first authentication unit 2230, a second authentication unit 2240, and a payment processing unit. 2250 and storage 2260.
  • the communication unit 2210 transmits and receives information necessary for offline payment processing with a mobile terminal of a user through a communication network such as a network.
  • the communication unit 2210 may receive information for performing check-in, first authentication, and second authentication from the mobile terminal, and provide information corresponding to offline payment processing to the mobile terminal. have.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the check-in information obtaining unit 2220 obtains check-in information corresponding to a store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the primary authenticator 2230 receives primary authentication information for primary authentication corresponding to a preauthorization of a purchase corresponding to a store from the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the primary authentication may correspond to entering a PIN number in the mobile terminal. That is, the first authentication may be performed at the mobile terminal. For example, when the PIN is input to perform the first authentication in the mobile terminal, the first approval may be made by recognizing the PIN number input to the mobile terminal as the first authentication information and transmitting the same to the offline payment processing device. .
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the primary authentication may be adjusted and performed to add a procedure for inputting a PIN number when the primary authentication level is improved.
  • the keyboard of the mobile terminal may be changed every time a PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication level may be improved by different conditions that may be additionally considered in the first authentication according to the first authentication method. For example, assuming that the primary authentication method corresponds to fingerprint recognition, as the primary authentication level is improved, the user may further request fingerprint recognition of another finger. In addition, in the case of face recognition, the left side or the right side of the face may be recognized in addition to recognizing the front side of the face.
  • the second authentication unit 2240 performs the second authentication which is dependent on the first authentication and is performed based on the touch pattern input to the sign pad of the POS.
  • the second authentication may be performed according to whether or not the user's registered touch pattern and the touch pattern match each other.
  • the registered touch pattern registered in advance corresponds to the order of (left, right, left) on the sign pad divided into two areas, the same as the registered touch pattern to perform the second authentication.
  • the left and right areas of the pad can be touched in order (left, right, left).
  • the number of divisions of the sign pad can be freely set.
  • the second authentication may be performed using a device capable of inputting a touch pattern, that is, a mobile terminal or a terminal capable of touch input.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the secondary authentication may be performed by further considering at least one condition of the touch length, the swipe direction, and the swipe speed.
  • the secondary authentication may be performed by further considering whether the touch input is long or short, in which direction the swipe input is swiped, and whether the swipe is fast or slow. Can be performed.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, when the primary authentication using the mobile terminal is completed, the POS may perform the secondary authentication for the user who has completed the primary authentication.
  • the payment processor 2250 performs offline payment in a store based on the result of the second authentication. That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the storage unit 2260 stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage unit 2260 may be configured independently of the offline payment processing device to support a function for an offline payment processing service. At this time, the storage unit 2260 may operate as a separate mass storage, and may include a control function for performing the operation.
  • the offline payment processing device is equipped with a memory can store information in the device.
  • the memory is a computer readable medium.
  • the memory may be a volatile memory unit, and for other implementations, the memory may be a nonvolatile memory unit.
  • the storage device is a computer readable medium.
  • the storage device may include, for example, a hard disk device, an optical disk device, or some other mass storage device.
  • the user when the user performs offline payment using a mobile terminal, the user may provide convenience of payment by performing second authentication using a touch pattern input by the user.
  • 24 is a block diagram illustrating a mobile terminal according to an embodiment of the present invention.
  • another mobile terminal may include a check-in information collecting unit 2310, a first authentication performing unit 2320, a second authentication performing unit 2330, and a payment performing unit 2340. Include.
  • the check-in information collection unit 2310 obtains check-in information corresponding to the store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the first certification performing unit 2320 performs the first certification corresponding to the approval of the purchase corresponding to the store. For example, when the PIN input window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the first authentication may be performed by inputting the PIN using the mobile terminal. Thereafter, the server and the offline payment processing device may process the first authentication by determining the PIN input through the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • the second authentication performing unit 2330 performs the touch pattern based second authentication for the second authentication dependent on the first authentication.
  • the second authentication may be performed according to whether or not the user's registered touch pattern and the touch pattern match each other.
  • the registered touch pattern registered in advance corresponds to the order of (left, right, left) in the touch area of the mobile terminal divided into two areas
  • the registered touch pattern and the registered touch pattern to perform the second authentication.
  • the left and right areas of the touch area may be sequentially touched (left, right, left).
  • the number of divisions of the touch area can be freely set.
  • the secondary authentication may be performed by further considering at least one condition of the touch length, the swipe direction, and the swipe speed.
  • the secondary authentication may be performed by further considering whether the touch input is long or short, in which direction the swipe input is swiped, and whether the swipe is fast or slow. Can be performed.
  • the payment performing unit 2340 transmits the information corresponding to the second authentication to the server in order to perform the offline payment in the store, and receives the result of the offline payment. For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • 25 to 29 are views showing a payment progress screen when an application member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the payment method through the BLE PUSH according to an embodiment of the present invention, when a user who subscribes to the application pay service enters the offline store, the goods through the application installed on the mobile terminal as shown in FIG.
  • the benefit screen 2410 is output to the user.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacon installed in the store, and the product benefits screen 2410 including the discount information and coupon information in the store included in the BLE signal to expose to the mobile terminal Can be. That is, the mobile terminal may obtain discount information and coupon information by obtaining check-in information corresponding to the store through the beacon of the store. In addition, the mobile terminal may provide check-in information to the offline payment processing device through the application.
  • the product benefit screen 2410 may output discount information and coupon information together with a payment button on the lockscreen 2412 of the mobile terminal.
  • the product benefit screen 2410 may output discount information and coupon information together with a payment button on the BLE Noti 2411 of the mobile terminal.
  • the detailed screen 2510 of the store corresponding to the product benefits screen 2410 through the application as shown in FIG. Can be output to the terminal.
  • the detailed screen 2510 of the store may output more detailed discount and coupon information together with the store information.
  • a payment button can be output together so that the user can proceed with the payment process at any time.
  • a payment PIN input window (see FIG. 27) is performed to perform the first authentication for the application pay service. 2610 may be output. That is, based on the offline payment processing device linked through the application, the window for the first authentication corresponding to the approval of the corresponding store may be output to the mobile terminal.
  • the first authentication may use a picture image gesture authentication method, a touch gesture authentication method, a fingerprint recognition, a face recognition, and a voice recognition in addition to the PIN number input authentication method.
  • the PIN can be transferred to the offline payment processing device to complete the first authentication.
  • the offline payment processing device or the server may transmit information such as a picture or a phone number of the user who has completed the first authentication to the POS.
  • information corresponding to a user who has completed primary authentication that is, a buyer who has completed primary authentication may be displayed on the payment screen 2710 on the POS device installed in the store as shown in FIG. 28.
  • the second authentication may be performed based on the touch pattern inputted to the POS and signed on the POS.
  • the second authentication may be completed when the registered touch pattern registered in advance by the user and the touch pattern input to the sign pad match.
  • the touch pattern may be input by using the mobile terminal of the user.
  • the payment success message 2811 may be transmitted to the user's mobile terminal as shown in FIG. 29.
  • the payment success message 2811 may display the name of the paid store, a payment method, and a payment amount.
  • the payment failure message 2812 may be transmitted to the user's mobile terminal, and the payment screen 2813 may be output to the mobile terminal in order to perform the payment again.
  • the checkout screen 2813 may output a payment button or a barcode for application payment.
  • FIGS. 30 to 36 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacons installed in the store, and the product benefit screen 2910 including the discount information and coupon information in the store included in the BLE signal to expose to the mobile terminal Can be.
  • the product benefit screen 2910 when the mobile terminal is locked, the product benefit screen 2910 outputs discount information and coupon information to the lockscreen 2912 of the terminal, but the payment button may not be output because the non-member of the application pay service. .
  • the product benefit screen 2910 may output discount information and coupon information to the BLE Noti 2911 of the mobile terminal.
  • the detailed screen 3010 of the store may output more detailed discount and coupon information together with the store information.
  • a pay app subscription button for subscribing to an application pay service may be output together so that a user may subscribe to a service for payment at any time.
  • a screen agreement agreement 3110 necessary for subscribing to the application pay service based on the offline payment processing system may be output to the user's mobile terminal.
  • the user authentication screen 3210 may be output to the mobile terminal as shown in FIG. 33 to perform authentication of the user.
  • the user authentication may be performed by inputting a user's name, social security number, communication company and mobile phone number, and the like, and inputting an authentication number.
  • the payment PIN registration screen 3310 may be output to the mobile terminal in order to register the payment PIN number used for the first authentication in the application pay service as shown in FIG. 34.
  • the payment PIN registration screen 3310 may be output.
  • a registration screen of various authentication means such as a fingerprint registration screen and a voice registration screen may be output.
  • the card information registration screen 3410 may be output to the mobile terminal as shown in FIG. 35 to register a card to be used in the application pay service.
  • the subscription confirmation screen 3510 is finally output as shown in FIG. 36, and when the user selects confirmation, the subscription may be completed.
  • the user may provide an application pay service after performing a first authentication through a PIN number by outputting a payment button to the user's mobile terminal.
  • FIG. 37 is a diagram illustrating an example of registering a touch pattern according to the present invention.
  • a touch pattern may be registered in advance.
  • the touch pattern registration window 3610 shown in FIG. 37 appears in the process of subscribing to the application pay service using the mobile terminal of the user, the user may directly register a touch pattern by touch input.
  • the user may generate a touch pattern by touching the touch areas 3621, 3622, 3623, and 3624 divided in the touch pattern registration window 3610.
  • the touch patterns may be registered in the order of 1, 2, 3, and 4 according to the numbers of the touch areas.
  • one, one, one, one, one touch pattern may be registered by continuously touching one touch area 3621.
  • the basic touch pattern may be generated in consideration of the number of touches and the touch area.
  • the second authentication may be performed corresponding to the second authentication level, and the touch length, the swipe direction, and the swipe speed may be further considered in the second authentication according to the second authentication level.
  • the second authentication may be performed considering only the number of touches and the touch area.
  • the second authentication may be performed by further considering the touch length. That is, when the second authentication level is the first step, if the touch pattern is generated corresponding to 1, 2, 3, and 1 based on the touch areas 3641, 3622, 3623, and 3624 in FIG. 37, the second authentication level is increased. In the second stage, it is possible to additionally check whether the length of the touch is properly input corresponding to the long 1, the long 2, the short 3, and the short 1.
  • the second authentication may be performed by further considering the swipe direction. That is, when the second authentication level is two levels, if the touch pattern is generated corresponding to the long 1, the long 2, the short 3, and the short 1 based on the touch areas 3641, 3622, 3623, and 3624 of FIG. 37, 2
  • the user swipes from the initial point to the last point with the finger on the touch area, corresponding to the long first, long two, short, three, and short ones. You can further check whether the swipe direction is entered correctly.
  • the second authentication may be performed in consideration of the swipe speed. That is, when the second authentication level is three levels, the touch pattern corresponding to the long first, long two, short, three, and short ones is based on the touch areas 3641, 3622, 3623, and 3624 of FIG. 37. If it is generated, it can be further confirmed that when the secondary authentication level is 4, the swipe speed is correctly input corresponding to the long 1 fast up, the long 2 fast down, the short 3 slow up, and the short 1 fast down.
  • the second authentication may fail.
  • 38 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention in terms of an offline payment processing device.
  • the offline payment processing method obtains check-in information corresponding to a store where a user enters (S3710).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the offline payment processing method receives the first authentication information for the first authentication corresponding to the approval of the purchase corresponding to the store from the mobile terminal (S3720).
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the primary authentication may correspond to entering a PIN number in the mobile terminal. That is, the first authentication may be performed at the mobile terminal. For example, when the PIN is input to perform the first authentication in the mobile terminal, the first approval may be made by recognizing the PIN number input to the mobile terminal as the first authentication information and transmitting the same to the offline payment processing device. .
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication may be performed corresponding to the primary authentication level adjusted according to the monitoring result for the mobile terminal obtained based on the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the primary authentication may be adjusted and performed to add a procedure for inputting a PIN number when the primary authentication level is improved.
  • the keyboard of the mobile terminal may be changed every time a PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication level may be improved by different conditions that may be additionally considered in the first authentication according to the first authentication method. For example, assuming that the primary authentication method corresponds to fingerprint recognition, as the primary authentication level is improved, the user may further request fingerprint recognition of another finger. In addition, in the case of face recognition, the left side or the right side of the face may be recognized in addition to recognizing the front side of the face.
  • the offline payment processing method determines whether the first authentication is valid (S3725).
  • the offline payment processing method is dependent on the primary authentication and is performed based on the touch pattern input to the sign pad of the POS. Second authentication is performed (S3730).
  • the second authentication may be performed according to whether or not the user's registered touch pattern and the touch pattern match each other.
  • the registered touch pattern registered in advance corresponds to the order of (left, right, left) on the sign pad divided into two areas, the same as the registered touch pattern to perform the second authentication.
  • the left and right areas of the pad can be touched in order (left, right, left).
  • the number of divisions of the sign pad can be freely set.
  • the second authentication may be performed using a device capable of inputting a touch trace, that is, a mobile terminal or a terminal capable of touch input.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the secondary authentication may be performed by further considering at least one condition of the touch length, the swipe direction, and the swipe speed.
  • the secondary authentication may be performed by further considering whether the touch input is long or short, in which direction the swipe input is swiped, and whether the swipe is fast or slow. Can be performed.
  • the number of divisions of the sign pad can be freely set.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, when the primary authentication using the mobile terminal is completed, the POS may perform the secondary authentication for the user who has completed the primary authentication.
  • the primary authentication information may be received to perform the primary authentication again.
  • the offline payment processing method performs the offline payment in the store based on the result of the second authentication (S3740). That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the offline payment processing method transmits and receives information required for offline payment processing with a mobile terminal of a user through a communication network such as a network.
  • a communication network such as a network.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the offline payment processing method according to an embodiment of the present invention stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage module for storing information may be configured independently of the offline payment processing device to support a function for an offline payment processing service.
  • the storage module may operate as a separate mass storage and may include a control function for performing an operation.
  • the user may provide convenience of payment by performing second authentication using a touch pattern input by the user.
  • 39 is a flowchart illustrating an offline payment processing method according to an embodiment of the present invention from the mobile terminal side.
  • the offline payment processing method obtains check-in information corresponding to a store where a user enters (S3810).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the offline payment processing method performs the first authentication corresponding to the pre-approval for the purchase corresponding to the store (S3820). For example, when the PIN input window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the first authentication may be performed by inputting the PIN using the mobile terminal. Thereafter, the server and the offline payment processing device may process the first authentication by determining the PIN input through the mobile terminal.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the offline payment processing method determines whether the first authentication is valid (S3825).
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the first authentication corresponds to the release conditional authentication, and when the first authentication is released, the second authentication may be impossible.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • the primary authentication may be performed.
  • the offline payment processing method performs the second pattern-based second authentication for the second authentication dependent on the first authentication. (S3830).
  • the second authentication may be performed according to whether or not the user's registered touch pattern and the touch pattern match each other.
  • the registered touch pattern registered in advance corresponds to the order of (left, right, left) in the touch area of the mobile terminal divided into two areas
  • the registered touch pattern and the registered touch pattern to perform the second authentication.
  • the left and right areas of the touch area may be sequentially touched (left, right, left).
  • the number of divisions of the touch area can be freely set.
  • the secondary authentication may be performed by further considering at least one condition of the touch length, the swipe direction, and the swipe speed.
  • the secondary authentication may be performed by further considering whether the touch input is long or short, in which direction the swipe input is swiped, and whether the swipe is fast or slow. Can be performed.
  • the offline payment processing method transmits the information corresponding to the second authentication to the server to perform the offline payment in the store, and receives the result of the offline payment (S3840). For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • FIG. 40 is a diagram illustrating in detail a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 38.
  • the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the monitoring result exceeds the preset reference purchase time from the first authentication until the product is submitted to the POS
  • the travel distance of the mobile terminal after the first authentication exceeds the preset reference travel distance
  • the second authentication level improvement condition is satisfied when the moving speed of the mobile terminal corresponds to at least one of the cases in which the preset moving speed exceeds the preset reference moving speed.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the second authentication is performed by further considering at least one condition among the touch length, the swipe direction, and the swipe speed (S3920).
  • secondary authentication may be performed by further considering whether the touch input is long or short, in which direction the swipe input is swiped, and whether the swipe is fast or slow.
  • step S3915 if the monitoring result of the determination result of step S3915 does not satisfy the condition for improving the second authentication level, second authentication is performed without performing a process for improving the second authentication level (S3930).
  • FIG. 41 is a diagram illustrating a process of improving the first authentication level of first authentication in the offline payment processing method illustrated in FIG. 38.
  • a monitoring result of the mobile terminal is obtained based on the check-in information (S4010).
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the first authentication level improvement condition is satisfied. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the first authentication level is improved by adding an element considered in the first authentication according to the first authentication method (S4020).
  • the primary authentication method is a PIN input
  • the keyboard of the mobile terminal may be changed every time the PIN is input, rather than a simple PIN input.
  • a method of inputting a color pattern after inputting the PIN or increasing the length of the PIN by using dummy numbers may be used.
  • a method of inputting the PIN through audio feedback may be used as the first authentication level is improved.
  • the first authentication may be performed without improving the first authentication level.
  • FIG. 42 is a block diagram illustrating an offline payment system using an application pay according to an embodiment of the present invention.
  • a payment system using an application pay includes an application server 4110, a terminal 4120, a POS device 4130, a BLE server 4140, and a BLE device 4150. Include.
  • the payment system may correspond to a system for performing payment using an application pay based on an application installed in a mobile terminal of a user when purchasing a product at an offline store.
  • the application server 4110 may be a server that provides an application 4111 for performing payment with information related to payment to the user terminal 4120 and performs a procedure related to payment.
  • the application server 4110 may transmit and receive data through a network.
  • the application server 4110 may be an offline payment processing apparatus according to an embodiment of the present invention.
  • the application server 4110 may include an offline payment processing apparatus according to an embodiment of the present invention.
  • the network provides a passage for transferring data between the application server 4110 and the terminal 4120, and is a concept encompassing both an existing network and a future developable network.
  • the network may be a wired / wireless local area network that provides communication of various information devices within a limited area, a mobile communication network that provides communication between each other, and between the mobile device and the outside of the mobile device, and provides communication between earth stations and earth stations using satellites. It may be either a satellite communication network or a wired or wireless communication network, or a combination of two or more.
  • the transmission standard of the network is not limited to the existing transmission standard, and may include all transmission standard that will be developed in the future.
  • the network used between the application server 4110 and the terminal 4120 is different from the network used between the application server 4120 and the POS device 4130 and the BLE server 4140 and the terminal 4120. May be the same or may be the same.
  • the terminal 4120 receives information corresponding to product payment from the application server 4110 using an application and provides the same to the user.
  • the terminal 4120 is a device that is connected to a communication network to execute an application, and includes a mobile phone, a portable multimedia player (PMP), a mobile internet device (MID), a smart phone, a tablet computer, It may be a mobile terminal having various mobile communication specifications such as a notebook (Note book), a net book (Net Book), a personal digital assistant (PDA) and an information communication device.
  • PMP portable multimedia player
  • MID mobile internet device
  • smart phone a tablet computer
  • PDA personal digital assistant
  • the terminal 4120 may receive various information such as numeric and text information, and may set various functions and transmit a signal input in relation to the function control of the terminal 4120 to the controller through the input unit.
  • the input unit of the terminal 4120 may include at least one of a keypad and a touch pad for generating an input signal according to a user's touch or manipulation.
  • the input unit of the terminal 4120 may be configured in the form of one touch panel (or touch screen) together with the display unit of the terminal 4120 to simultaneously perform input and display functions.
  • the input unit of the terminal 4120 may use any type of input means that may be developed in the future.
  • the input unit of the terminal 4120 according to the present invention may transmit an input signal for selecting a card or performing a payment to the controller of the terminal 4120 based on an optimal card recommendation system.
  • the display unit of the terminal 4120 may display information on a series of operation states and operation results generated while the function of the terminal 4120 is performed. In addition, the display unit of the terminal 4120 may display a menu of the terminal 4120 and user data input by the user.
  • the display unit of the terminal 4120 includes a liquid crystal display (LCD), an ultra-thin liquid crystal display (TFT-LCD, thin film transistor LCD), a light emitting diode (LED), and an organic light emitting diode (OLED). , Organic LED), an active organic light emitting diode (AMOLED, Active Matrix OLED), a Retina display, a flexible display, and a three-dimensional display.
  • the display unit of the terminal 4120 when the display unit of the terminal 4120 is configured as a touch screen, the display unit of the terminal 4120 may perform some or all of the functions of the input unit of the terminal 4120.
  • the display unit of the terminal 4120 according to the present invention may display information related to the optimal recommendation card and payment provided on the basis of the optimal card recommendation system on a screen.
  • the storage unit of the terminal 4120 is a device for storing data, and includes a main memory device and an auxiliary memory device, and may store an application program required for a functional operation of the terminal 4120.
  • the storage unit of the terminal 4120 may largely include a program area and a data area. In this case, when the terminal 4120 activates each function in response to a user's request, the terminal 4120 executes corresponding application programs under the control of the controller to provide each function.
  • the storage unit of the terminal 4120 may store an operating system for booting the terminal 4120, a program for recommending a card or performing a payment based on an optimal card recommendation system.
  • the storage unit of the terminal 4120 may store a content DB storing a plurality of contents and information of the terminal 4120.
  • the content DB may include execution data for executing the content and attribute information on the content, and content usage information according to the content execution may be stored.
  • the information of the terminal 4120 may include terminal specification information.
  • the communication unit of the terminal 4120 may perform a function for transmitting and receiving data with the application server 4110 through a network.
  • the communication unit of the terminal 4120 may include RF transmission means for up-converting and amplifying a frequency of a transmitted signal, and RF reception means for low-noise-amplifying and down-converting a received signal.
  • the communication unit of the terminal 4120 may include at least one of a wireless communication module and a wired communication module.
  • the wireless communication module is configured to transmit and receive data according to a wireless communication method. When the terminal 4120 uses wireless communication, any one of a wireless network communication module, a wireless LAN communication module, and a wireless fan communication module may be used. Data may be transmitted and received to the application server 4110.
  • the wired communication module is for transmitting and receiving data by wire.
  • the wired communication module may connect to a network through a wire and transmit / receive data to / from the application server 4110. That is, the terminal 4120 may access a network using a wireless communication module or a wired communication module, and may transmit / receive data with the application server 4110 through the network.
  • the terminal 4120, the application server 4110, and the BLE server 4140 may communicate with each other to transmit and receive data necessary for recommending the optimal card based on the optimal card recommendation system.
  • the controller of the terminal 4120 may be a process device that drives an operating system (OS) and each component.
  • OS operating system
  • the controller may control the overall process of accessing the application server 4110.
  • the overall process of executing the service application can be controlled according to a user's request, and at the same time, the service use request is transmitted to the application server 4110.
  • the information of the terminal 4120 required for user authentication may be transmitted together.
  • the controller of the terminal 4120 may execute specific content stored in the storage unit of the terminal 4120 according to a user's request.
  • the controller may store a content usage history according to content execution as content usage information.
  • the user terminal 4120 is installed with an application for the application pay service, and may correspond to the terminal 4120 of the user subscribed to the application pay service.
  • the POS device 4130 is a device for performing payment of goods in the store 4160 and may correspond to a device capable of performing an application pay service based on communication with the application server 4110.
  • the BLE server 4140 may be a server for identifying a location of the terminal 4120 and providing information by using a Bluetooth low energy technology.
  • the Bluetooth low power technology is a short-range wireless communication technology that periodically transmits information of an object based on Bluetooth 4.0 within a predetermined radius range. That is, even though the user of the terminal 4120 does not take any action, the user of the terminal 4120 may automatically detect the location of the user and provide a signal for a payment service.
  • beacon is a short-range data communication technology using Bluetooth Low Energy (BLE), and various application services such as object and situation recognition, content push, indoor location positioning, automatic check-in, and geofencing based on proximity positioning. Can be enabled. Compared with similar technologies in the past, it is more convenient and can be provided at a lower cost, which can serve as a catalyst for forming a new service market.
  • the beacon may refer to any device that periodically transmits a signal.
  • the BLE device 4150 illustrated in FIG. 42 may correspond to a beacon.
  • Such beacons may be divided into sound-based low frequency beacons, LED beacons, Wi-Fi beacons, and Bluetooth beacons according to a method of transmitting a signal.
  • the beacon can transmit a periodic signal in a small packet of approximately 21 bytes, does not need to be paired with the receiving target, and operates at low power, but the ID value and the received signal strength of the beacon transmitter up to 50 meters It is possible to transmit a signal corresponding to.
  • the price is small and can be easily attached anywhere, it can be used anywhere even in an offline store.
  • the terminal 4120 may detect the corresponding terminal 4120 and transmit a signal including information. .
  • the store 4160 may correspond to an offline store where payment is performed, and may correspond to an application pay service affiliated store in which an application pay agent and a BLE device 4150 are installed.
  • the user may enter the store 4160 with the terminal 4120.
  • the beacon which is a BLE-based short-range data communication technology, may be used to detect that the user enters the store 4160.
  • the BLE signal transmitted from the BLE device 4150 which is a beacon located in the store 4160, may be received by the Bluetooth-enabled terminal 4120 using the BLE SDK 4141.
  • the BLE signal may be received through the application 4111 installed based on the BLE SDK 4141.
  • the BLE server 4140 may provide the terminal 4120 with information related to the BLE benefit corresponding to the BLE signal. .
  • the terminal 4120 may access the application server 4110 based on the BLE benefit information received from the BLE server 4140 through the application.
  • the application server 4110 may include at least one module for performing payment.
  • the application server 4110 may include a membership providing module that may provide membership information based on user information of the terminal 4120 and store information corresponding to the store 4160.
  • the membership providing module may include a separate database for storing membership information for each user and store information for each store.
  • the application server 4110 may include an application pay payment module for performing a payment through an application pay.
  • the application pay payment module may include credit card information or bank information for performing a payment through the application pay. For example, when a user pays an application pay through a credit card to purchase a product at the store 4160, the application pay payment module and the credit card application may transmit and receive data for performing real time payment.
  • the application pay payment module may include an optimal card recommendation device for recommending an optimal card in consideration of discount benefits, store benefits, and accumulation among credit cards possessed by a user based on credit card information.
  • the best card according to the discount rate or the accumulation rate may be recommended by combining the benefit information provided through the membership card and the benefit information provided through the membership card when the target performance of the previous month was achieved for each type of credit card.
  • the optimal card recommendation device may be configured independently of the application pay payment module.
  • the application server 4110 may use the membership providing module, together with membership information, offer information on coupons or gifticons that can be used by the user in the store 4160, event and marketing information in progress in the store 4160, and the like. It may include a store information providing module that can provide.
  • the store information providing module provides the application server 4110 by searching for the gift icons or coupons that the user can use in the store 4160 through the application, so that the user can display the gift icons through the application installed on the terminal 4120. You can use the coupon.
  • the store information providing module provides the application server 4110 with event information and marketing information corresponding to a plurality of stores that provide a service according to an embodiment of the present invention, such that the user visits the store. In operation 4160, information about the event and the marketing in progress may be provided to the user terminal 4120.
  • a user accessing the application server 4110 through the terminal 4120 may perform pre-authentication in an application pay service to purchase a product in the store 4160.
  • the user may enter a step for pre-authentication by receiving a purchase-related push message through the BLE device 4150 and clicking a purchase button included in the push message.
  • various methods such as a PIN number input, a picture image gesture and a touch gesture may be used as pre-authentication for purchase, that is, primary authentication.
  • the offline payment processing apparatus included in the application server 4110 or corresponding to the application server 4110 receives the corresponding first authentication information of the first authentication performed by the terminal 4120 to determine whether to authenticate. You can judge.
  • the user moves to the POS device 4130 with the product to be purchased at the store 4160, indicates the intention that the cashier of the store 4160 pays through the application pay, and performs the second authentication for the purchase and payment of the product. can do.
  • the second authentication may be authentication dependent on the first authentication, and the second authentication may be performed while the first authentication is valid.
  • a user has a terminal 4120 and is located in a zone for payment near the POS device 4130, and inputs a movement gesture pattern using the terminal 4120 in the payment zone.
  • the POS device 4130 may check the user who uses the application pay service and proceed with payment.
  • the application server 4110 may transmit a message indicating whether the payment through the application pay was successfully performed to at least one of the user terminal 4120 or the POS device 4130.
  • FIG. 43 is a block diagram illustrating an offline payment processing apparatus according to an embodiment of the present invention.
  • an offline payment processing apparatus includes a communication unit 4210, a check-in information obtaining unit 4220, a first authentication unit 4230, a second authentication unit 4240, and a payment processing unit. 4250 and storage 4260.
  • the communication unit 4210 is responsible for transmitting and receiving information necessary for offline connection processing with the mobile terminal of the user through a communication network such as a network.
  • the communication unit 4210 may receive information for performing check-in, first authentication, and second authentication from a mobile terminal, and provide information corresponding to offline payment processing to the mobile terminal. have.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the check-in information obtaining unit 4220 acquires check-in information corresponding to a store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the first authentication unit 4230 is for first authentication corresponding to a preauthorization of a purchase corresponding to a store from a mobile terminal, and receives first authentication information generated corresponding to a swipe operation pattern for the mobile terminal. .
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the swipe operation pattern may be a pattern generated by using a swipe technique in which the user moves from the initial point to the final point with a finger on the touch screen.
  • data may be generated according to the direction and the number of times the finger is moved on the touch screen to generate a swipe operation pattern.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • various patterns may be input in a direction corresponding to up, down, left, and right on the touch screen to generate a swipe operation pattern.
  • a pattern combining a direction and a speed such as fast up, slow up, fast down, and slow down is inputted on the touch screen. Can be generated.
  • swipe length is taken into account in the swipe direction and the swipe speed when generating the swipe motion pattern
  • direction such as fast-long-up, fast-short-up, slow-long-down, slow-short-down, A pattern combining speed and length may be input to generate a swipe motion pattern.
  • the primary authentication may be performed by comparing a swipe operation pattern and a registration pattern registered by the user in advance through an application installed in the mobile terminal.
  • the registration pattern may be a pattern in the same manner as the swipe operation pattern, and may be registered by touching in the same manner as the method of inputting the swipe operation pattern.
  • the registration pattern is registered within a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern, according to the primary authentication level corresponding to the primary authentication. Can be.
  • the total length of the registration pattern may correspond to the total number of patterns input through one swipe. For example, if the total length of the registration pattern is 5, the registration pattern may be registered through a pattern input through 5 swipes in total.
  • the overall length of the registration pattern may be increased for safety.
  • the factors considered in setting the registration pattern may correspond to the swipe direction, the swipe speed, and the swipe length. Therefore, in order to perform the first authentication corresponding to the high authentication level according to the first authentication level, a more secure registration pattern can be registered using many factors. For example, a registration pattern can be registered to use all of the swipe direction, swipe speed, and swipe length if the primary authentication level is the highest, or only swipe direction if the primary authentication level is the lowest. The registration pattern may be registered so as to.
  • the first authentication may be performed through various methods such as PIN input, fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the primary authentication corresponds to the release conditional authentication, and when the primary authentication is released, the secondary authentication information may be invalidated.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication level may be adjusted according to the monitoring result for the mobile terminal obtained by the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the second authentication unit 4240 reviews the validity of the first authentication, and when the first authentication is valid, generates second authentication information for second authentication dependent on the first authentication to correspond to the mobile terminal and the store. Send to at least one of the POS.
  • the user may determine a product or service that the user wants to purchase in the store and deliver the same to the POS of the store.
  • the second authentication may be performed at the POS and may be performed using at least one of the user's mobile terminal and the POS. Therefore, the second authentication information for the second authentication may be generated and transmitted to at least one of the mobile terminal and the POS.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, based on the first authentication using the mobile terminal, the second authentication information for the second authentication is provided to the POS of the store, and the POS uses the second authentication information provided to the second authentication for the user who wants to purchase the product. Can be done.
  • secondary authentication may require a face or phone number to be displayed to a user who wants to purchase a product, that is, a picture or phone number of a payer through a mobile terminal, and a store clerk approaches the POS to purchase a product.
  • the verification may be a method of performing second authentication.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the additional authentication information is generated based on at least one of the sign pad connected to the mobile terminal and the POS, and the additional authentication information is transmitted to at least one of the mobile terminal and the POS in order to perform additional authentication according to the improvement of the second authentication level. Can be.
  • a method of authenticating a user's mobile terminal by shaking it according to a predetermined shaking pattern in the POS, and a question transmitted to the POS based on a call list or calendar registered in the mobile terminal during the first authentication How to check and answer, how to input preset tapping pattern on sign pad linked to POS, how to input preset crossing pattern on sign pad, and how to be located in payment zone corresponding to a certain range based on POS There are many easy ways to do this.
  • the payment processor 4250 performs offline payment in a store based on the second authentication result using the second authentication information. That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the storage unit 4260 stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage unit 4260 may be configured independently of the offline payment processing device to support a function for an offline payment processing service. At this time, the storage unit 4260 may operate as a separate mass storage, and may include a control function for performing the operation.
  • the offline payment processing device is equipped with a memory can store information in the device.
  • the memory is a computer readable medium.
  • the memory may be a volatile memory unit, and for other implementations, the memory may be a nonvolatile memory unit.
  • the storage device is a computer readable medium.
  • the storage device may include, for example, a hard disk device, an optical disk device, or some other mass storage device.
  • 44 is a block diagram illustrating a mobile terminal according to an embodiment of the present invention.
  • another mobile terminal includes a check-in information collection unit 4310, a first authentication performing unit 4320, a second authentication performing unit 4330, and a payment performing unit 4340. Include.
  • the check-in information collection unit 4310 obtains check-in information corresponding to the store entered by the user.
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the primary authentication performing unit 4320 may perform primary authentication corresponding to a pre-approval for a purchase corresponding to a store by inputting primary authentication information corresponding to a swipe operation pattern. For example, when the swipe input window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the first authentication may be performed by inputting the swipe operation pattern using the mobile terminal. Can be. Thereafter, the server and the offline payment processing apparatus may process the first authentication in the same case by comparing the swipe operation pattern input through the mobile terminal with a registration pattern registered in advance.
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the swipe operation pattern may be a pattern generated by using a swipe technique in which the user moves from the initial point to the final point with a finger on the touch screen.
  • data may be generated according to the direction and the number of times the finger is moved on the touch screen to generate a swipe operation pattern.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • the registration pattern may be a pattern in the same manner as the swipe operation pattern, and may be registered by touching in the same manner as the method of inputting the swipe operation pattern.
  • the registration pattern is registered within a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern, according to the primary authentication level corresponding to the primary authentication. Can be.
  • the total length of the registration pattern may correspond to the total number of patterns input through one swipe. For example, if the total length of the registration pattern is 5, the registration pattern may be registered through a pattern input through 5 swipes in total.
  • the overall length of the registration pattern may be increased for safety.
  • the factors considered in setting the registration pattern may correspond to the swipe direction, the swipe speed, and the swipe length. Therefore, in order to perform the first authentication corresponding to the high authentication level according to the first authentication level, a more secure registration pattern can be registered using many factors. For example, a registration pattern can be registered to use all of the swipe direction, swipe speed, and swipe length if the primary authentication level is the highest, or only swipe direction if the primary authentication level is the lowest. The registration pattern may be registered so as to.
  • the first authentication may be performed through various methods such as fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the primary authentication corresponds to the release conditional authentication, and when the primary authentication is released, the secondary authentication information may be invalidated.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • the secondary authentication performing unit 4330 generates secondary authentication information for secondary authentication dependent on the primary authentication when the primary authentication is valid.
  • the second authentication information may correspond to information such as a picture or a phone number of the user who uses the mobile terminal.
  • additional authentication information according to the additional authentication method may be generated.
  • the payment performing unit 4340 transmits the second authentication information to any one of a server and a POS corresponding to the store to perform offline payment in a store, and receives a result of the offline payment. For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • 45 to 49 are diagrams illustrating a payment progress screen when an application member is used in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the payment method through the BLE PUSH according to an embodiment of the present invention, when a user who subscribes to an application pay service enters an offline store, a product through an application installed in a mobile terminal as shown in FIG. 4.
  • the benefit screen 4410 is output to the user.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacon installed in the store, and the product benefits screen 4410 including the discount information and coupon information in the store included in the BLE signal to expose to the mobile terminal.
  • the mobile terminal may obtain discount information and coupon information by obtaining check-in information corresponding to the store through the beacon of the store.
  • the mobile terminal may provide check-in information to the offline payment processing device through the application.
  • the product benefit screen 4410 may output discount information and coupon information together with a payment button on the lockscreen 4412 of the mobile terminal.
  • the product benefit screen 4410 may output discount information and coupon information together with a payment button on the BLE Noti 4411 of the mobile terminal.
  • the detailed screen 4510 of the store corresponding to the product benefits screen 4410 through the application as shown in FIG. Can be output to the terminal.
  • the detailed screen 4510 of the store may output more detailed discount and coupon information together with the store information.
  • a payment button can be output together so that the user can proceed with the payment process at any time.
  • the input window 4610 may be output. That is, based on the offline payment processing device linked through the application, the swipe input window for the first authentication corresponding to the approval of the corresponding store may be output to the mobile terminal.
  • the primary authentication may use a picture image gesture authentication method or a PIN authentication method in addition to the swipe operation pattern authentication method.
  • the user who completed the first authentication that is, the purchaser who completed the first authentication
  • the user who completed the first authentication is displayed on the payment screen 4710 of the POS device installed in the store as shown in FIG.
  • Corresponding secondary authentication information is displayed.
  • the swipe operation pattern may be transferred to the offline payment processing device to complete the first authentication.
  • the offline payment processing device may transmit information such as a picture or a phone number of the buyer corresponding to the second authentication information to the POS for the second authentication.
  • the cashier may perform the second authentication through the payment screen 4710 and proceed with the payment.
  • the second authentication information such as the user's photo or telephone number may check whether the payer who performed the first authentication in the mobile terminal matches the buyer who wants to purchase the product in the POS.
  • the second authentication for the application pay service may proceed after additional authentication according to the second authentication level.
  • a payment success message 4811 may be transmitted to the mobile terminal of the user as shown in FIG. 49.
  • the payment success message 4811 may display the name of the paid store, a payment method, and a payment amount.
  • the payment failure message 4812 may be transmitted to the user's mobile terminal, and the payment screen 4813 may be output to the mobile terminal in order to perform the payment again.
  • the payment screen 4813 may output a payment button or a barcode for application pay payment.
  • 50 to 56 are views illustrating a member registration screen when an application is a non-member in a payment method through BLE PUSH according to an embodiment of the present invention.
  • the application installed on the mobile terminal recognizes the BLE signal transmitted by the beacons installed in the store, and the product benefits screen 4910 including the discount information and coupon information in the store included in the BLE signal to expose to the mobile terminal. Can be.
  • the product benefit screen 4910 may output discount information and coupon information to the lockscreen 4912 of the terminal when the mobile terminal is locked, but the payment button may not be output because it is a non-member of the application pay service. .
  • the product benefit screen 4910 may output discount information and coupon information to the BLE Noti 4911 of the mobile terminal.
  • the detailed screen 5010 of the store may output more detailed discount and coupon information together with the store information.
  • a pay app subscription button for subscribing to an application pay service may be output together so that a user may subscribe to a service for payment at any time.
  • the user authentication screen 5210 may be output to the mobile terminal to perform authentication of the user as shown in FIG. 53.
  • the user authentication may be performed by inputting a user's name, social security number, communication company and mobile phone number, and the like, and inputting an authentication number.
  • the registration pattern registration screen 5310 may be output to the mobile terminal in order to register the registration pattern to be used for the first authentication in the application pay service as shown in FIG. 54.
  • the card information registration screen 5410 may be output to the mobile terminal as shown in FIG. 55 to register a card to be used in the application pay service.
  • the subscription confirmation screen 5510 is finally output as shown in FIG. 56, and when the user selects confirmation, the subscription may be completed.
  • the user may provide an application pay service after performing a first authentication through a swipe operation pattern by outputting a payment button to the user's mobile terminal.
  • 57 is a flowchart illustrating an offline payment processing method in terms of an offline payment processing apparatus according to an embodiment of the present invention.
  • check-in information corresponding to a store entered by a user is obtained (S5610).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • a device such as a BLE beacon may be installed at an entrance of a store, and when a user's mobile terminal enters an area of the BLE beacon, the terminal may be detected to transmit a signal including information of the store.
  • the mobile terminal receiving the signal may obtain the information of the store included in the signal through the application, and transmit the information to the offline payment processing device using the information as check-in information.
  • any technology capable of detecting that the user's mobile terminal has visited the store may be used as a technology for obtaining check-in information without being limited to any technology.
  • the offline payment processing method for the first authentication corresponding to the approval of the purchase corresponding to the store from the mobile terminal, it is generated corresponding to the swipe operation pattern for the mobile terminal First authentication information is received (S5620).
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the swipe operation pattern may be a pattern generated by using a swipe technique in which the user moves from the initial point to the final point with a finger on the touch screen.
  • data may be generated according to the direction and the number of times the finger is moved on the touch screen to generate a swipe operation pattern.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • various patterns may be input in a direction corresponding to up, down, left, and right on the touch screen to generate a swipe operation pattern.
  • a pattern combining a direction and a speed such as fast up, slow up, fast down, and slow down is inputted on the touch screen. Can be generated.
  • swipe length is taken into account in the swipe direction and the swipe speed when generating the swipe motion pattern
  • direction such as fast-long-up, fast-short-up, slow-long-down, slow-short-down, A pattern combining speed and length may be input to generate a swipe motion pattern.
  • the primary authentication may be performed by comparing a swipe operation pattern and a registration pattern registered by the user in advance through an application installed in the mobile terminal.
  • the registration pattern may be a pattern in the same manner as the swipe operation pattern, and may be registered by touching in the same manner as the method of inputting the swipe operation pattern.
  • the registration pattern is registered within a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern, according to the primary authentication level corresponding to the primary authentication. Can be.
  • the total length of the registration pattern may correspond to the total number of patterns input through one swipe. For example, if the total length of the registration pattern is 5, the registration pattern may be registered through a pattern input through 5 swipes in total.
  • the overall length of the registration pattern may be increased for safety.
  • the factors considered in setting the registration pattern may correspond to the swipe direction, the swipe speed, and the swipe length. Therefore, in order to perform the first authentication corresponding to the high authentication level according to the first authentication level, a more secure registration pattern can be registered using many factors. For example, a registration pattern can be registered to use all of the swipe direction, swipe speed, and swipe length if the primary authentication level is the highest, or only swipe direction if the primary authentication level is the lowest. The registration pattern may be registered so as to.
  • the first authentication may be performed through various methods such as PIN input, fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the primary authentication corresponds to the release conditional authentication, and when the primary authentication is released, the secondary authentication information may be invalidated.
  • primary authentication may correspond to authentication involving spatial or temporal release conditions.
  • one of the release conditions of the primary authentication may be a timeout time corresponding to the time that the primary authentication is valid. That is, after performing the first authentication, if the preset timeout time is exceeded, the first authentication may be automatically released.
  • the timeout time may be set differently according to the type of store. For example, a store such as a supermarket may set a timeout time of 30 minutes to 1 hour to suit a shopping time. In addition, in a store such as a restaurant, a timeout time may be set from 2 to 3 hours to suit a meal time.
  • the payment through the mobile terminal may not be performed regardless of whether the second authentication is valid. Therefore, in order to perform the payment through the mobile terminal after the first authentication is released, the first authentication may be performed again, and then the second authentication may be performed to process the payment.
  • the first authentication may be released when the mobile terminal moves away from the store by a predetermined distance or more.
  • the mobile terminal is located by using a short range wireless communication device installed at various locations of the store entrance and the inside of the store, and the mobile terminal is determined to be out of the store and distanced more than a certain distance, the first authentication is released. Can be.
  • the primary authentication level may be adjusted according to the monitoring result for the mobile terminal obtained by the check-in information.
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the primary authentication level can be adjusted to improve. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • the offline payment processing method determines whether the first authentication is valid (S5625). That is, it may be checked whether the primary authentication is released by satisfying the release condition.
  • the primary authentication information may be received to perform the primary authentication again.
  • the offline payment processing method generates the secondary authentication information for secondary authentication dependent on the primary authentication, and generates a mobile terminal. It transmits to at least one of the POS corresponding to the store (S5630).
  • the user may determine a product or service that the user wants to purchase in the store and deliver the same to the POS of the store.
  • the second authentication may be performed at the POS and may be performed using at least one of the user's mobile terminal and the POS. Therefore, the second authentication information for the second authentication may be generated and transmitted to at least one of the mobile terminal and the POS.
  • the second authentication may be lower than the first authentication level. That is, since the purchase intention of the user who wants to purchase the product through the first authentication through the mobile terminal is confirmed, if the first authentication is not released because the conditions for canceling the first authentication are satisfied, the purchase is made only with the second level authentication of the lower level. Confirmation can also reduce the likelihood of fraud. Therefore, although the authentication level is lower than that of the first authentication, the second authentication may be an authentication method that can maximize the user's convenience.
  • secondary authentication may correspond to authentication dependent on primary authentication. That is, based on the first authentication using the mobile terminal, the second authentication information for the second authentication is provided to the POS of the store, and the POS uses the second authentication information provided to the second authentication for the user who wants to purchase the product. Can be done.
  • secondary authentication may require a face or phone number to be displayed to a user who wants to purchase a product, that is, a picture or phone number of a payer through a mobile terminal, and a store clerk approaches the POS to purchase a product.
  • the verification may be a method of performing second authentication.
  • the second authentication may be performed corresponding to the second authentication level adjusted according to the monitoring result for the mobile terminal until the product corresponding to the purchase is submitted to the POS. That is, the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the second authentication level may be adjusted to be improved.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • the additional authentication information is generated based on at least one of the sign pad connected to the mobile terminal and the POS, and the additional authentication information is transmitted to at least one of the mobile terminal and the POS in order to perform additional authentication according to the improvement of the second authentication level. Can be.
  • a method of authenticating a user's mobile terminal by shaking it according to a predetermined shaking pattern in the POS, and a question transmitted to the POS based on a call list or calendar registered in the mobile terminal during the first authentication How to check and answer, how to input preset tapping pattern on sign pad linked to POS, how to input preset crossing pattern on sign pad, and how to be located in payment zone corresponding to a certain range based on POS There are many easy ways to do this.
  • the offline payment processing method performs the offline payment in the store based on the second authentication result using the second authentication information (S5640). That is, when the second authentication is completed, the user may complete the payment for the product or service to be purchased.
  • the offline payment processing method transmits and receives information necessary for offline payment processing with the mobile terminal of the user through a communication network, such as a network.
  • a communication network such as a network.
  • information for performing offline payment processing may be received from a separate application server or a POS installed in a store.
  • the offline payment processing method stores various information generated in the offline payment processing service process according to an embodiment of the present invention as described above.
  • the storage module for storing information may be configured independently of the offline payment processing device to support a function for an offline payment processing service.
  • the storage module may operate as a separate mass storage and may include a control function for performing an operation.
  • FIG. 58 is a flowchart illustrating an offline payment processing method in a mobile terminal side according to an embodiment of the present invention.
  • the offline payment processing method obtains check-in information corresponding to a store where a user enters (S5710).
  • the check-in information may be obtained by using Bluetooth low energy (BLE) technology or technologies such as WiFi and GPS.
  • BLE Bluetooth low energy
  • the mobile terminal may receive a beacon signal from a BLE beacon device installed at the entrance of the store.
  • the beacon signal may include check-in information including the information of the store.
  • the offline payment processing method performs the first authentication corresponding to the pre-approval for the purchase corresponding to the store (S5720).
  • the first certification may correspond to the pre-payment certification that is made before the product to be purchased or the amount to be paid for settlement is confirmed.
  • the first authentication may be performed based on the first authentication information generated corresponding to the swipe operation pattern for the mobile terminal. For example, when the swipe operation pattern window corresponding to the first authentication is received from the server corresponding to the application installed in the mobile terminal and the offline payment processing device, the swipe operation is performed in the same manner as the registration pattern registered in advance using the mobile terminal. Primary authentication can be performed by entering a pattern. That is, the server and the offline payment processing device may process the first authentication as completed when the swipe operation pattern input through the mobile terminal is the same as the registration pattern.
  • the swipe operation pattern may be set in consideration of any one or more of a swipe direction, a swipe speed, and a swipe length.
  • the registration pattern may be a pattern in the same manner as the swipe operation pattern, and may be registered by touching in the same manner as the method of inputting the swipe operation pattern.
  • the registration pattern is registered within a preset pattern setting range including at least one of the total length of the registration pattern and the number of elements considered in setting the registration pattern, according to the primary authentication level corresponding to the primary authentication. Can be.
  • the total length of the registration pattern may correspond to the total number of patterns input through one swipe. For example, if the total length of the registration pattern is 5, the registration pattern may be registered through a pattern input through 5 swipes in total.
  • the overall length of the registration pattern may be increased for safety.
  • the factors considered in setting the registration pattern may correspond to the swipe direction, the swipe speed, and the swipe length. Therefore, in order to perform the first authentication corresponding to the high authentication level according to the first authentication level, a more secure registration pattern can be registered using many factors. For example, a registration pattern can be registered to use all of the swipe direction, swipe speed, and swipe length if the primary authentication level is the highest, or only swipe direction if the primary authentication level is the lowest. The registration pattern may be registered so as to.
  • the first authentication may be performed through various methods such as PIN input, fingerprint recognition, face recognition, voice recognition, etc. available through the mobile terminal.
  • the offline payment processing method determines whether the first authentication is valid (S5725).
  • the primary authentication may be performed.
  • the offline payment processing method generates secondary authentication information for secondary authentication dependent on the primary authentication (S5730).
  • the second authentication information may correspond to information such as a picture or a phone number of the user who uses the mobile terminal.
  • additional authentication information according to the additional authentication method may be generated.
  • the offline payment processing method transmits the second authentication information to any one of the server and the POS corresponding to the store to perform the offline payment in the store, and receives the result of the offline payment (S5740). For example, when the offline payment is successful, a payment success message including a name of a store corresponding to the offline payment, a payment method, and a payment amount may be received. In addition, when the offline payment has failed, a payment failure message may be received that briefly includes the details of the failed payment.
  • FIG. 59 is a detailed diagram illustrating a process of improving first authentication level of first authentication in the offline payment processing method illustrated in FIG. 57.
  • a monitoring result for the mobile terminal is first obtained based on check-in information (S5810).
  • the security level can be enhanced depending on the situation by improving the primary authentication level for more secure authentication.
  • the monitoring result may correspond to the situation until the first authentication is performed.
  • the first authentication level improvement condition is satisfied. In other words, if a user with a mobile terminal enters a store, it takes an unusually long time before performing the first authentication, or if the store where the user enters is a store where frequent mobile fraud occurs. In order to secure payment, the first authentication level for the first authentication can be improved.
  • step S5815 when the monitoring result satisfies the first authentication level improvement condition, at least one of a method of increasing the total length of the registration pattern and a method of increasing the number of elements considered in setting the registration pattern is performed.
  • Improve the primary authentication level (S5820). For example, when the primary authentication level is increased, stability can be improved by increasing the length of the registration pattern registered in the third pattern to the fifth pattern. For another example, stability can be improved by registering a registration pattern registered in consideration of the swipe direction only to further consider at least one of a swipe speed and a swipe length.
  • an appropriate authentication method may be set between the authentication level and the user's convenience depending on the situation.
  • the first authentication may be performed without improving the first authentication level.
  • FIG. 60 is a diagram illustrating a process of improving a second authentication level of second authentication in the offline payment processing method illustrated in FIG. 57.
  • the second authentication level may be determined in consideration of the situation after the first authentication is performed and before the second authentication is performed.
  • the monitoring result exceeds the preset reference purchase time from the first authentication until the product is submitted to the POS
  • the travel distance of the mobile terminal after the first authentication exceeds the preset reference travel distance
  • the second authentication level improvement condition is satisfied when the moving speed of the mobile terminal corresponds to at least one of the cases in which the preset moving speed exceeds the preset reference moving speed.
  • the preset reference purchase time may correspond to a time less than the timeout time satisfying the release condition of the first authentication.
  • step S5915 If the monitoring result of the determination result in step S5915 satisfies the condition for improving the second authentication level, additional authentication information is generated based on at least one of a sign pad connected to the mobile terminal and the POS (S5920).
  • the additional authentication information is transmitted to at least one of the mobile terminal and the POS (S5930).
  • the secondary authentication may be performed without improving the secondary authentication level.
  • Computer-readable media suitable for storing computer program instructions and data include, for example, magnetic media such as hard disks, floppy disks, and magnetic tape, such as magnetic disks, compact disk read only memory (CD-ROM), and DVDs.
  • Optical Media such as Digital Video Disk, Magnetic-Optical Media such as Floppy Disk, and Read Only Memory, RAM, Random Semiconductor memories such as access memory (EPM), flash memory, erasable programmable ROM (EPROM), and electrically erasable programmable ROM (EEPROM).
  • the processor and memory can be supplemented by or integrated with special purpose logic circuitry.
  • Examples of program instructions may include high-level language code that can be executed by a computer using an interpreter as well as machine code such as produced by a compiler.
  • Such hardware devices may be configured to operate as one or more software modules to perform the operations of the present invention, and vice versa.
  • the user obtains check-in information corresponding to a store entered, receives first authentication information for first authentication corresponding to pre-approval for a purchase corresponding to a store from a mobile terminal, and the first authentication is performed. If valid, the secondary authentication is performed based on the crosspoint of the touch trajectory input to the POS's sign pad, and the offline payment in the store is performed based on the result of the second authentication. Can be. Furthermore, it is possible to provide stable offline payment service while maximizing convenience for users.
  • the present invention obtains the check-in information corresponding to the store entered by the user, receives the first authentication information for the first authentication corresponding to the first approval for the purchase corresponding to the store from the mobile terminal, If the authentication is valid, it is possible to perform the second authentication, which is dependent on the first authentication and is performed based on the touch pattern entered in the sign pad of the POS, and the offline payment in the store can be performed based on the result of the second authentication. have. Furthermore, it is possible to provide stable offline payment service while maximizing convenience for users.
  • the swipe operation pattern for the mobile terminal Receives the first authentication information generated corresponding to the first authentication information, and if the first authentication is valid, generates the second authentication information for the second authentication dependent on the first authentication and transmits it to at least one of the POS corresponding to the mobile terminal and the store.
  • offline payment in the store may be performed. Furthermore, it is possible to provide stable offline payment service while maximizing convenience for users.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Software Systems (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Cash Registers Or Receiving Machines (AREA)

Abstract

오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치가 개시된다. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하고, 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하고, 1차 인증이 유효한 경우에, 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하고, 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행할 수 있다. 나아가, 사용자들에게 편의성을 극대화하면서도 안정적인 오프라인 결제 서비스를 제공하는 것이 가능하다.

Description

오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치
본 발명은 오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치 (SYSTEM FOR PROCESSING OFFLINE PAYMENT, METHOD OF PROCESSING OFFLINE PAYMENT BASED ON SECONDARY AUTHENTICATION AND METHOD AND APPARATUS FOR THE SAME)에 관한 것으로, 더욱 상세하게는 1차 인증 수행 후 최종 결제를 위해 터치궤적의 크로스 포인트를 입력하여 간편하게 결제를 수행할 수 있고, 1차 인증 수행 후 최종 결제를 위해 터치 패턴을 입력하여 간편하게 결제를 수행할 수 있고, 사용자의 단말에서 스와이프 패턴을 통해 1차 인증을 수행함으로써 구매에 대한 선승인을 수행할 수 있는 오프라인 결제 처리 기술에 관한 것이다.
본 발명은 2015년 9월 22일 출원된 한국특허출원 제10-2015-0133763호, 2015년 10월 23일 출원된 한국특허출원 제10-2015-0148087호 및 2015년 10월 23일 출원된 한국특허출원 제10-2015-0148084호의 출원일의 이익을 주장하며, 그 내용 전부는 본 명세서에 포함된다.
모바일 단말기가 보편화 되어감에 따라 온라인뿐만 아니라 오프라인에서도 모바일 단말기를 이용한 결제의 필요성이 지속적으로 증가하고 있는 추세이다. 이와 같은 모바일 단말기 기반 결제에서 중요한 테마로는 사용자 인증과 같은 보안과 편의성을 꼽을 수 있다. 즉, 결제를 수행할 때 사용자에게 최소한의 절차나 동작을 요구하면서도 효율적으로 비정상적인 결제를 감지하여 부정결제가 발생하는 것을 방지하여야 한다.
종래에는 사용자가 매장에 도착하기 전에 미리 모바일 단말기를 통해 결제를 수행한 뒤, 사용자가 매장에 도착하면 미리 결제된 상품을 받아가는 등의 편리성을 위한 기술이 존재하고 있다. 그러나, 이와 같은 기술은 사용자가 매장에 방문하기 전에 모바일 단말기를 통해 상품을 선택하여 결제를 수행하는 것으로, 사용자가 직접 매장에 방문해서 구매할 상품을 결정한 뒤 이를 매장의 POS에서 보다 간결한 과정을 통해 결제하는 기술과는 그 차이가 있다.
또한, 이와 같이 간결한 결제 과정에서도 물건을 수령하는 구매자와 결제를 수행하는 결제자 간의 일치 여부를 확인하여 부정결제의 가능성을 차단하는 보안적 기술은 종래의 기술에서는 찾아보기 어렵다.
관련 선행기술로는, 한국 등록 특허 제10-1352710호, 2014년 1월 10일 등록 (명칭: 신용카드 모의 결제 시스템 및 그 결제 시스템에서의 모의 결제 방법 및 이를 위한 장치)이 있다.
본 발명의 목적은, 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치궤적에 따라 생성된 크로스 포인트를 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공하는 것이다.
또한, 본 발명의 목적은 결제전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공하는 것이다.
또한, 본 발명의 목적은 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지하는 것이다.
또한, 본 발명의 목적은 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행하는 것이다.
또한, 본 발명의 목적은 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치 패턴에 기반하여 2차 인증을 수행함으로써 결제의 편의성을 제공하는 것이다.
또한, 본 발명의 목적은 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 2채널 인증을 기반으로 보다 높은 안전성을 제공하는 것이다.
또한, 본 발명의 목적은 스와이프 패턴 기반의 선인증을 기반으로 모바일 단말을 꺼내지 않고도 안전하게 오프라인 결제를 수행하는 것이다.
또한, 본 발명의 목적은 모바일 단말을 이용한 오프라인 결제 시 사용자 편의를 극대화함과 동시에 안정적인 결제 서비스를 제공하는 것이다.
상기한 목적을 달성하기 위한 본 발명에 따른 오프라인 결제 처리 장치는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 1차 인증부; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하는 2차 인증부; 및 상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부를 포함한다.
이 때, 2차 인증부는 상기 사용자가 사전에 등록한 등록 크로스 포인트와 상기 크로스 포인트를 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 2차 인증부는 상기 2차 인증 레벨이 향상된 경우에 상기 크로스 포인트의 개수 및 상기 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증부는 상기 모니터링 결과가 상기 1차 인증부터 상기 상품이 상기 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 상기 1차 인증 이후 상기 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 상기 1차 인증 이후 상기 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 2차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증의 진행이 불가능할 수 있다.
이 때, 1차 인증은 상기 체크인 정보를 기반으로 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절된 1차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 1차 인증부는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
또한, 본 발명에 따른 모바일 단말은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 수집부; 1차 인증 정보를 입력하여 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행하는 1차 인증 수행부; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적인 2차 인증을 위해서 터치궤적에 의한 크로스 포인트 기반의 2차 인증을 수행하는 2차 인증 수행부; 및 상기 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증에 상응하는 정보를 서버로 전송하고, 상기 오프라인 결제의 결과를 수신하는 결제 수행부를 포함한다.
또한, 본 발명에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 단계; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하는 단계; 및 상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계를 포함한다.
이 때, 2차 인증을 수행하는 단계는 상기 사용자가 사전에 등록한 등록 크로스 포인트와 상기 크로스 포인트를 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 2차 인증을 수행하는 단계는 상기 2차 인증 레벨이 향상된 경우에 상기 크로스 포인트의 개수 및 상기 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증을 수행하는 단계는 상기 모니터링 결과가 상기 1차 인증부터 상기 상품이 상기 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 상기 1차 인증 이후 상기 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 상기 1차 인증 이후 상기 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 2차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증의 진행이 불가능할 수 있다.
이 때, 1차 인증은 상기 체크인 정보를 기반으로 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절된 1차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 1차 인증 정보를 수신하는 단계는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
또한, 본 발명에 따른 오프라인 결제 처리 장치는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 1차 인증부; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행하는 2차 인증부; 및 상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부를 포함한다.
이 때, 2차 인증부는 상기 사용자가 사전에 등록한 등록 터치 패턴과 상기 터치 패턴을 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 2차 인증부는 상기 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증부는 상기 모니터링 결과가 상기 1차 인증부터 상기 상품이 상기 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 상기 1차 인증 이후 상기 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 상기 1차 인증 이후 상기 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 2차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증의 진행이 불가능할 수 있다.
이 때, 1차 인증은 상기 체크인 정보를 기반으로 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절된 1차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 1차 인증부는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
또한, 본 발명에 따른 모바일 단말은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 수집부; 1차 인증 정보를 입력하여 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행하는 1차 인증 수행부; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적인 2차 인증을 위해서 터치 패턴 기반의 2차 인증을 수행하는 2차 인증 수행부; 및 상기 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증에 상응하는 정보를 서버로 전송하고, 상기 오프라인 결제의 결과를 수신하는 결제 수행부를 포함한다.
또한, 본 발명에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 단계; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행하는 단계; 및 상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계를 포함한다.
이 때, 2차 인증을 수행하는 단계는 상기 사용자가 사전에 등록한 등록 터치 패턴과 상기 터치 패턴을 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 2차 인증을 수행하는 단계는 상기 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행할 수 있다.
이 때, 2차 인증을 수행하는 단계는 상기 모니터링 결과가 상기 1차 인증부터 상기 상품이 상기 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 상기 1차 인증 이후 상기 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 상기 1차 인증 이후 상기 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 2차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증의 진행이 불가능할 수 있다.
이 때, 1차 인증은 상기 체크인 정보를 기반으로 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절된 1차 인증 레벨에 상응하게 수행될 수 있다.
이 때, 1차 인증 정보를 수신하는 단계는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
또한, 본 발명에 따른 오프라인 결제 처리 장치는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 상기 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신하는 1차 인증부; 상기 1차 인증의 유효 여부를 검토하고, 상기 1차 인증이 유효한 경우에 상기 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 상기 모바일 단말 및 상기 매장에 상응하는 POS 중 적어도 하나로 전송하는 2차 인증부; 및 상기 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부를 포함한다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
이 때, 1차 인증부는 상기 모바일 단말에 설치된 어플리케이션을 통해 상기 사용자가 사전에 등록한 등록 패턴과 상기 스와이프 동작 패턴을 비교하여 상기 1차 인증을 수행할 수 있다.
이 때, 등록 패턴은 상기 1차 인증에 상응하는 1차 인증 레벨에 따라, 상기 등록 패턴의 전체 길이 및 상기 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증 정보는 무효화될 수 있다.
이 때, 1차 인증 레벨은 상기 체크인 정보가 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절될 수 있다.
이 때, 1차 인증부는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 상기 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
또한, 본 발명에 따른 모바일 단말은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 수집부; 스와이프 동작 패턴에 상응하는 1차 인증 정보를 입력하여 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행하는 1차 인증 수행부; 상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하는 2차 인증 수행부; 및 상기 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증 정보를 서버 및 상기 매장에 상응하는 POS 중 어느 하나로 전송하고, 상기 오프라인 결제의 결과를 수신하는 결제 수행부를 포함한다.
또한, 본 발명에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계; 모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 상기 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신하는 단계; 상기 1차 인증의 유효 여부를 검토하고, 상기 1차 인증이 유효한 경우에 상기 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 상기 모바일 단말 및 상기 매장에 상응하는 POS 중 적어도 하나로 전송하는 단계; 및 상기 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계를 포함한다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
이 때, 1차 인증 정보를 수신하는 단계는 상기 모바일 단말에 설치된 어플리케이션을 통해 상기 사용자가 사전에 등록한 등록 패턴과 상기 스와이프 동작 패턴을 비교하여 상기 1차 인증을 수행할 수 있다.
이 때, 등록 패턴은 상기 1차 인증에 상응하는 1차 인증 레벨에 따라, 상기 등록 패턴의 전체 길이 및 상기 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증 정보는 무효화될 수 있다.
이 때, 1차 인증 레벨은 상기 체크인 정보가 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절될 수 있다.
이 때, 1차 인증 정보를 수신하는 단계는 상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 상기 2차 인증은 상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다.
또한, 본 발명의 과제 해결을 위한 또 다른 수단으로써, 상술한 방법을 실행시키기 위하여 매체에 저장된 컴퓨터 프로그램을 제공한다.
본 발명에 따르면, 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치궤적에 따라 생성된 크로스 포인트를 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 본 발명은 결제전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공할 수 있다.
또한, 본 발명은 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지할 수 있다.
또한, 본 발명은 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행할 수 있다.
또한, 본 발명은 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치 패턴에 기반하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 본 발명은 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 2채널 인증을 기반으로 보다 높은 안전성을 제공할 수 있다.
또한, 본 발명은 스와이프 패턴 기반의 선인증을 기반으로 모바일 단말을 꺼내지 않고도 안전하게 오프라인 결제를 수행할 수 있다.
또한, 본 발명은 모바일 단말을 이용한 오프라인 결제 시 사용자 편의를 극대화함과 동시에 안정적인 결제 서비스를 제공할 수 있다.
도 1은 본 발명의 일실시예에 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록동이다.
도 2는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록동이다.
도 3은 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록동이다.
도 4 내지 도 8은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 9 내지 도 15는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 16은 본 발명에 따른 크로스 포인트를 등록하는 일 예를 나타낸 도면이다.
도 17은 본 발명에 따른 크로스 포인트를 등록하는 다른 예를 나타낸 도면이다.
도 18은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 19는 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 20은 도 18에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 21은 도 18에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 22는 본 발명의 일실시예에 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록동이다.
도 23은 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록동이다.
도 24는 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록동이다.
도 25 내지 도 29는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 30 내지 도 36은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 37은 본 발명에 따른 터치 패턴을 등록하는 일 예를 나타낸 도면이다.
도 38은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 39는 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 40은 도 38에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 41은 도 38에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 42는 본 발명의 일실시예에 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록동이다.
도 43은 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록동이다.
도 44는 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록동이다.
도 45 내지 도 49는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 50 내지 도 56은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 57은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 58은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 59는 도 57에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 60은 도 57에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
본 발명을 첨부된 도면을 참조하여 상세히 설명하면 다음과 같다. 여기서, 반복되는 설명, 본 발명의 요지를 불필요하게 흐릴 수 있는 공지 기능, 및 구성에 대한 상세한 설명은 생략한다. 본 발명의 실시형태는 당 업계에서 평균적인 지식을 가진 자에게 본 발명을 보다 완전하게 설명하기 위해서 제공되는 것이다. 따라서, 도면에서의 요소들의 형상 및 크기 등은 보다 명확한 설명을 위해 과장될 수 있다.
이하, 본 발명에 따른 바람직한 실시예를 첨부된 도면을 참조하여 상세하게 설명한다.
도 1은 본 발명의 일실시예에 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록동이다.
도 1을 참조하면, 본 발명의 일실시예에 따른 어플리케이션 페이를 이용한 결제 시스템은 어플리케이션 서버(110), 단말(120), POS 장치(130), BLE 서버(140) 및 BLE 장치(150)를 포함한다.
본 발명의 일실시예에 따른 결제 시스템은 오프라인 매장에서 상품을 구매할 때, 사용자의 모바일 단말에 설치된 어플리케이션을 기반으로 어플리케이션 페이를 이용하여 결제를 수행하기 위한 시스템에 상응할 수 있다.
어플리케이션 서버(110)는 사용자의 단말(120)로 결제와 관련된 정보와 함께 결제를 수행하기 위한 어플리케이션(111)을 제공하여 결제와 관련된 절차를 진행하는 서버일 수 있다. 이 때, 어플리케이션 서버(110)는 네트워크를 통해 데이터를 송수신할 수 있다.
이 때, 어플리케이션 서버(110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치일 수 있다. 또한, 어플리케이션 서버(110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 포함할 수도 있다.
이 때, 네트워크는 어플리케이션 서버(110)와 단말(120) 사이에 데이터를 전달하는 통로를 제공하는 것으로서, 기존에 이용되는 네트워크 및 향후 개발 가능한 네트워크를 모두 포괄하는 개념이다. 예를 들어, 네트워크는 한정된 지역 내에서 각종 정보장치들의 통신을 제공하는 유무선근거리 통신망, 이동체 상호 간 및 이동체와 이동체 외부와의 통신을 제공하는 이동통신망, 위성을 이용해 지구 국과 지구국간 통신을 제공하는 위성통신망이거나 유무선 통신망 중에서 어느 하나이거나, 둘 이상의 결합으로 이루어질 수 있다. 한편, 네트워크의 전송 방식 표준은, 기존의 전송 방식 표준에 한정되는 것은 아니며, 향후 개발될 모든 전송 방식 표준을 포함할 수 있다. 또한, 도 1에서 어플리케이션 서버(110)와 단말(120) 사이에 사용되는 네트워크는 어플리케이션 서버(120)와 POS 장치(130) 및 BLE 서버(140)와 단말(120) 상호간에 사용되는 네트워크와 상이한 것일 수도 있고, 동일한 것일 수도 있다.
단말(120)은 어플리케이션을 이용하여 어플리케이션 서버(110)로부터 상품 결제에 상응하는 정보를 수신하여 사용자에게 제공한다.
이 때, 단말(120)은 통신망에 연결되어 어플리케이션을 실행할 수 있는 장치로, 휴대폰, PMP(Portable Multimedia Played), MID(Mobile Internet Device), 스마트 폰(Smart Phone), 태블릿컴퓨터(Tablet PC), 노트북(Note book), 넷북(Net Book), 개인휴대용 정보단말(Personal Digital Assistant; PDA) 및 정보통신 기기 등과 같은 다양한 이동통신 사양을 갖는 모바일(Mobile) 단말일 수 있다.
또한, 단말(120)은 숫자 및 문자 정보 등의 다양한 정보를 입력 받고, 각종 기능을 설정 및 단말(120)의 기능 제어와 관련하여 입력되는 신호를 입력부를 통해 제어부로 전달할 수 있다. 또한, 단말(120)의 입력부는 사용자의 터치 또는 조작에 따른 입력 신호를 발생하는 키패드와 터치패드 중 적어도 하나를 포함하여 구성할 수 있다. 이 때, 단말(120)의 입력부는 단말(120)의 표시부와 함께 하나의 터치패널(또는 터치 스크린(touch screen))의 형태로 구성되어 입력과 표시 기능을 동시에 수행할 수 있다. 또한, 단말(120)의 입력부는 키보드, 키패드, 마우스, 조이스틱 등과 같은 입력 장치 외에도 향후 개발될 수 있는 모든 형태의 입력 수단이 사용될 수 있다. 특히, 본 발명에 따른 단말(120)의 입력부는 최적 카드 추천 시스템 기반으로 카드를 선택하거나 결제를 수행하기 위한 입력 신호를 단말(120)의 제어부로 전달할 수 있다.
또한, 단말(120)의 표시부는 단말(120)의 기능 수행 중에 발생하는 일련의 동작상태 및 동작결과 등에 대한 정보를 표시할 수 있다. 또한, 단말(120)의 표시부는 단말(120)의 메뉴 및 사용자가 입력한 사용자 데이터 등을 표시할 수 있다. 여기서, 단말(120)의 표시부는 액정표시장치(LCD, Liquid Crystal Display), 초박막 액정표시장치(TFT-LCD, Thin Film Transistor LCD), 발광다이오드(LED, Light Emitting Diode), 유기 발광다이오드(OLED, Organic LED), 능동형 유기발광다이오드(AMOLED, Active Matrix OLED), 레티나 디스플레이(Retina Display), 플렉시블 디스플레이(Flexible display) 및 3차원(3 Dimension) 디스플레이 등으로 구성될 수 있다. 이 때, 단말(120)의 표시부가 터치스크린 형태로 구성된 경우, 단말(120)의 표시부는 단말(120)의 입력부의 기능 중 일부 또는 전부를 수행할 수 있다. 특히, 본 발명에 따른 단말(120)의 표시부는 최적 카드 추천 시스템 기반으로 제공되는 최적 추천 카드 및 결제와 관련된 정보를 화면으로 표시할 수 있다.
또한, 단말(120)의 저장부는 데이터를 저장하기 위한 장치로, 주 기억장치 및 보조 기억장치를 포함하고, 단말(120)의 기능 동작에 필요한 응용 프로그램을 저장할 수 있다. 이러한 단말(120)의 저장부는 크게 프로그램 영역과 데이터 영역을 포함할 수 있다. 여기서, 단말(120)은 사용자의 요청에 상응하여 각 기능을 활성화하는 경우, 제어부의 제어 하에 해당 응용 프로그램들을 실행하여 각 기능을 제공하게 된다. 특히, 본 발명에 따른 단말(120)의 저장부는 단말(120)을 부팅시키는 운영체제, 최적 카드 추천 시스템을 기반으로 카드를 추천하거나 결제를 수행하기 위한 프로그램 등을 저장할 수 있다. 또한, 단말(120)의 저장부는 다수의 컨텐츠를 저장하는 컨텐츠 DB와 단말(120)의 정보를 저장할 수 있다. 이 때, 컨텐츠 DB는 컨텐츠를 실행하기 위한 실행 데이터와 컨텐츠에 대한 속성 정보를 포함하고, 컨텐츠 실행에 따른 컨텐츠 사용 정보 등이 저장될 수 있다. 그리고, 단말(120)의 정보는 단말 사양 정보를 포함할 수 있다.
또한, 단말(120)의 통신부는 어플리케이션 서버(110)와 네트워크를 통해 데이터를 송수신하기 위한 기능을 수행할 수 있다. 여기서 단말(120)의 통신부는 송신되는 신호의 주파수를 상승 변환 및 증폭하는 RF 송신 수단과 수신되는 신호를 저잡음 증폭하고 주파수를 하강 변환하는 RF 수신 수단 등을 포함할 수 있다. 이러한 단말(120)의 통신부는 무선통신 모듈 및 유선통신 모듈 중 적어도 하나를 포함할 수 있다. 그리고, 무선통신 모듈은 무선 통신 방법에 따라 데이터를 송수신하기 위한 구성이며, 단말(120)이 무선 통신을 이용하는 경우, 무선망 통신 모듈, 무선랜 통신 모듈 및 무선팬 통신 모듈 중 어느 하나를 이용하여 데이터를 어플리케이션 서버(110)로 송수신할 수 있다. 또한, 유선통신 모듈은 유선으로 데이터를 송수신하기 위한 것이다. 유선통신 모듈은 유선을 통해 네트워크에 접속하여, 어플리케이션 서버(110)에 데이터를 송수신할 수 있다. 즉 단말(120)은 무선통신 모듈 또는 유선통신 모듈을 이용하여 네트워크에 접속하며, 네트워크를 통해 어플리케이션 서버(110)와 데이터를 송수신할 수 있다. 특히, 본 발명에 따른 네트워크는 단말(120)과 어플리케이션 서버(110) 및 BLE 서버(140)등이 통신하여 최적 카드 추천 시스템 기반으로 최적 카드를 추천하는데 필요한 데이터를 송수신할 수 있다.
또한, 단말(120)의 제어부는 운영 체제((OS, Operation System) 및 각 구성을 구동시키는 프로세스 장치가 될 수 있다. 예를 들어, 제어부는 어플리케이션 서버(110)에 접속하는 과정 전반을 제어할 수 있다. 별도의 서비스 어플리케이션을 통해 어플리케이션 서버(110)에 접속하는 경우, 사용자의 요청에 따라 서비스 어플리케이션을 실행되는 과정 전반을 제어할 수 있으며, 실행과 동시에 어플리케이션 서버(110)로 서비스 이용 요청이 전송되도록 제어할 수 있으며, 이때 사용자 인증에 필요한 단말(120)의 정보가 함께 전송되도록 제어할 수 있다.
또한, 단말(120)의 제어부는 사용자의 요청에 따라 단말(120)의 저장부에 저장된 특정 컨텐츠를 실행할 수 있다. 이때, 제어부는 컨텐츠 실행에 따른 컨텐츠 사용 이력을 컨텐츠 사용 정보로 저장할 수 있다.
또한, 사용자의 단말(120)은 어플리케이션 페이 서비스를 위한 어플리케이션이 설치되어 있으며, 어플리케이션 페이 서비스에 가입된 사용자의 단말(120)에 상응할 수 있다.
POS 장치(130)는 매장(160)에서 상품의 결제를 수행하기 위한 장치로서, 어플리케이션 서버(110)와 통신을 기반으로 어플리케이션 페이 서비스를 수행할 수 있는 장치에 상응할 수 있다.
BLE 서버(140)는 블루투스 저전력 기술(bluetooth low energy)을 활용하여 단말(120)의 위치를 파악하고 정보를 제공하기 위한 서버일 수 있다.
이 때, 블루투스 저전력 기술은 주변의 일정 반경 범위 내에서 블루투스 4.0을 기반으로 사물의 정보를 주기적으로 전송하는 근거리 무선 통신 기술이다. 즉, 단말(120)의 사용자가 별도의 행동을 취하기 않더라도 자동으로 사용자의 위치를 파악하여 결제 서비스를 위한 신호를 제공할 수 있다.
이 때, 비콘은 BLE(Bluetooth Low Energy)를 활용한 근거리 데이터 통신 기술로, 근접도 측위를 바탕으로 사물 및 상황인식, 콘텐츠 푸시, 실내위치측위, 자동 체크인, 지오펜싱(GeoFencing) 등 다양한 응용 서비스를 가능하게 할 수 있다. 이전의 유사한 기술과 비교하면 보다 편리하고, 적은 비용으로 제공이 가능하기 때문에 새로운 서비스 시장 형성에 촉매제 역할을 할 수 있다. 이 때, 비콘은 어떤 신호를 알리기 위해 주기적으로 전송하는 기기를 모두 의미할 수 있다. 예를 들어, 도 1에 도시된 BLE 장치(150)가 비콘에 해당할 수 있다.
이와 같은 비콘은 신호를 전송하는 방법에 따라 사운드 기반의 저주파 비콘, LED 비콘, 와이파이 비콘, 블루투스 비콘 등으로 나눌 수 있다. 또한, 비콘은 대략 21 바이트에 해당하는 소량의 패킷으로 주기적 신호를 전송할 수 있고, 신호를 받는 대상과 별도로 페어링이 필요하지 않으며, 저전력으로 동작하지만 최대 50미터까지 비콘 송신기의 ID값과 수신신호세기에 상응하는 신호를 전송하는 것이 가능하다. 또한, 가격이 저렴하고 소형으로 어디든 쉽게 부착이 가능하기 때문에 오프라인 매장의 경우에도 어느 곳이든 자유롭게 사용할 수 있다.
예를 들어, 매장(160) 내의 특정 장소에 비콘을 설치하여 단말(120)을 소지한 사용자 및 고객이 BLE 비콘의 영역 내에 들어올 경우 해당 단말(120)을 감지하여 정보를 포함한 신호를 전송할 수 있다.
매장(160)은 결제가 수행되는 오프라인상의 매장에 해당할 수 있으며, 어플리케이션 페이 에이전트 및 BLE 장치(150)가 설치된 어플리케이션 페이 서비스 가맹점에 상응할 수 있다.
아래에서는 본 발명의 일실시예에 따른 결제 시스템을 서비스 흐름에 따라 설명한다.
먼저 사용자가 단말(120)을 가지고 매장(160)에 진입할 수 있다.
이 때, BLE 기반 근거리 데이터 통신 기술인 비콘을 이용하여 사용자가 매장(160)에 진입한 것을 감지할 수 있다.
즉, 본 발명에 따르면 매장(160)에 위치하는 비콘인 BLE 장치(150)에서 전송되는 BLE 신호를 블루투스가 활성화된 단말(120)에서 BLE SDK(141)를 이용하여 수신할 수 있다. 이 때, BLE SDK(141)를 기반으로 설치된 어플리케이션(111)을 통해 BLE 신호를 수신할 수도 있다. 이 후, 단말(120)이 BLE 서버(140)로 BLE 신호에 포함된 정보를 전송하면, BLE 서버(140)에서는 BLE 신호에 상응하는 BLE 혜택과 관련된 정보를 단말(120)로 제공할 수 있다.
이 후, 단말(120)에서는 어플리케이션을 통하여 BLE 서버(140)로부터 수신한 BLE 혜택 정보를 기반으로 어플리케이션 서버(110)에 접속할 수 있다.
이 때, 어플리케이션 서버(110)는 결제를 수행하기 위한 적어도 하나의 모듈을 포함할 수 있다.
예를 들어, 어플리케이션 서버(110)는 단말(120)의 사용자 정보와 매장(160)에 상응하는 매장 정보를 기반으로 멤버십 정보를 제공할 수 있는 멤버십 제공 모듈을 포함할 수 있다. 이 때, 멤버십 제공 모듈은 사용자 별 멤버십 정보와 매장 별 매장 정보를 저장할 수 있는 별도의 데이터베이스를 포함할 수 있다.
또 다른 예를 들어, 어플리케이션 서버(110)는 어플리케이션 페이를 통해 결제를 수행하기 위한 어플리케이션 페이 결제 모듈을 포함할 수 있다. 이 때, 어플리케이션 페이 결제 모듈은 어플리케이션 페이를 통해 결제를 수행하기 위한 신용카드 정보 또는 은행 정보를 포함할 수 있다. 예를 들어, 사용자가 매장(160)에서 상품을 구입하기 위해 신용카드를 통해 어플리케이션 페이를 결제할 때 어플리케이션 페이 결제 모듈과 신용카드 어플리케이션이 실시간 결제를 수행하기 위한 데이터를 송신 및 수신할 수 있다.
이 때, 어플리케이션 페이 결제 모듈은 신용카드 정보를 바탕으로 사용자가 보유한 신용카드 중 할인혜택, 매장혜택 및 적립 등을 고려한 최적 카드를 추천하는 최적 카드 추천 장치를 포함할 수 있다. 예를 들어, 신용카드의 종류별로 전월 목표 실적을 달성하였을 경우에 제공되는 혜택 정보와 멤버십 카드를 통해 제공되는 혜택 정보를 종합하여 할인율이나 적립율에 따른 최적 카드를 추천할 수 있다. 또한, 최적 카드 추천 장치는 어플리케이션 페이 결제 모듈과 독립적으로 구성될 수도 있다.
또 다른 예를 들어, 어플리케이션 서버(110)는 멤버십 제공 모듈을 통해 멤버십 정보와 함께 매장(160)에서 사용자가 사용할 수 있는 쿠폰이나 기프티콘에 대한 혜택 정보나 매장(160)에서 진행중인 이벤트 및 마케팅 정보 등을 제공할 수 있는 매장 정보 제공 모듈을 포함할 수 있다. 예를 들어, 매장 정보 제공 모듈은 사용자가 어플리케이션을 통해 매장(160)에서 사용할 수 있는 기프티콘이나 쿠폰을 조회하여 어플리케이션 서버(110)에게 제공함으로써, 사용자가 단말(120)에 설치된 어플리케이션을 통해 기프티콘이나 쿠폰을 사용하도록 할 수 있다. 또한, 매장 정보 제공 모듈은 본 발명의 일실시예에 따른 결제 시스템에 따른 서비스를 제공하는 복수 개의 매장들에 해당하는 이벤트 정보 및 마케팅 정보를 어플리케이션 서버(110)에게 제공함으로써, 사용자가 방문하는 매장(160)에서 진행 중인 이벤트 및 마케팅에 대한 정보를 사용자의 단말(120)로 제공할 수 있다.
이 후, 단말(120)을 통해 어플리케이션 서버(110)에 접속한 사용자는 매장(160)에서 상품의 구매를 위해 어플리케이션 페이 서비스에서 선 인증을 수행할 수 있다. 예를 들어, BLE 장치(150)를 통해 구매관련 푸시 메시지를 수신하고, 푸시 메시지에 포함된 구매버튼을 클릭하는 등의 행위로 선 인증을 위한 단계로 진입할 수 있다. 이 때, 구매를 위한 선 인증, 즉 1차 인증의 수단으로는 PIN 번호 입력, 픽처 이미지제스처 및 터치제스처 등 다양한 방식을 사용할 수 있다.
이 때, 어플리케이션 서버(110)에 포함되거나, 어플리케이션 서버(110)에 상응할 수 있는 오프라인 결제 처리 장치가 단말(120)에서 수행된 1차 인증의 해당하는 1차 인증 정보를 수신하여 인증 여부를 판단할 수 있다.
이 후, 사용자가 매장(160)에서 구매할 상품을 가지고 POS 장치(130)로 이동하여 매장(160)의 점원에서 어플리케이션 페이를 통해 결제한다는 의사를 밝히고, 상품 구매 및 결제를 위한 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 1차 인증에 종속적인 인증일 수 있으며, 1차 인증이 유효한 상태에서 2차 인증이 수행될 수 있다.
예를 들어, 2차 인증 방법으로는, 사용자가 단말(120)을 가지고 POS 장치(130) 근처에 결제를 위한 zone에 위치하는 방식, 결제 zone 내에서 단말(120)을 이용한 움직임 제스처 패턴을 입력하는 방식, POS 장치(130)에 포함된 사인패드에 터치 패턴을 입력하는 방식, 사인패드에 교차점을 생성하는 방식, 질의응답 방식 등을 포함할 수 있다.
또한, 2차 인증은 매장(160)의 점원이 구매 상품을 스캔한 뒤에 POS 장치(130)를 통해 어플리케이션 페이 서비스를 사용하는 사용자를 확인한 뒤 결제를 진행할 수 있다.
이 후, 2차 인증까지 완료되면 어플리케이션 서버(110)가 어플리케이션 페이를 통한 결제가 성공적으로 수행되었는지 여부를 알리는 메시지를 사용자의 단말(120) 또는 POS 장치(130) 중 적어도 하나로 전송할 수 있다.
이와 같은 어플리케이션 페이를 이용한 결제 시스템을 이용하면, 사용자가 매장(160)에서 1차 인증을 수행하고 간단한 2차 인증을 수행하는 것만으로 보다 안전하고 편리하게 최적의 카드를 이용하여 상품을 결제하는 것이 가능하다.
도 2는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록도이다.
도 2를 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 장치는 통신부(210), 체크인 정보 획득부(220), 1차 인증부(230), 2차 인증부(240), 결제 처리부(250) 및 저장부(260)를 포함한다.
통신부(210)는 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결제 처리를 위해 필요한 정보를 송수신하는 역할을 한다. 특히, 본 발명의 일실시예에 따른 통신부(210)는 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
체크인 정보 획득부(220)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
1차 인증부(230)는 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신한다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 1차 인증은 모바일 단말에 PIN 번호를 입력하는 것에 상응할 수 있다. 즉, 1차 인증은 모바일 단말에서 수행될 수 있다. 예를 들어, 모바일 단말에서 1차 인증을 수행하기 위해 PIN 번호를 입력하면, 모바일 단말에 입력된 PIN 번호를 1차 인증 정보로 인식하고 오프라인 결제 처리 장치로 전송함으로써 1차 승인이 이루어 질 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증은 체크인 정보를 기반으로 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절되는 1차 인증 레벨에 상응하게 수행될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은, 1차 인증 레벨이 향상된 경우에 PIN 번호를 입력하는 절차를 추가하도록 조절되어 수행될 수 있다. 예를 들어, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
이 때, 1차 인증의 방식에 따라 1차 인증 시 추가로 고려할 수 있는 조건들을 달리하여 1차 인증 레벨을 향상시킬 수도 있다. 예를 들어, 1차 인증 방식이 지문 인식에 상응한다고 가정하면, 1차 인증 레벨이 향상됨에 따라 추가로 다른 손가락의 지문 인식을 요청하도록 할 수 있다. 또한, 얼굴 인식의 경우에는 얼굴의 정면을 인식하는 것에 추가하여 얼굴의 좌측 또는 우측을 인식하도록 할 수도 있다.
2차 인증부(240)는 1차 인증이 유효한 경우에 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행한다.
이 때, 사용자가 사전에 등록한 등록 크로스 포인트와 크로스 포인트를 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 크로스 포인트가 터치궤적에 2개가 포함된 경우에는 2차 인증을 수행하기 위해서 등록 크로스 포인트와 동일한 개수의 크로스 포인트가 생성되도록 터치궤적을 입력할 수 있다.
이 때, POS의 사인패드 이외에도 터치궤적을 입력할 수 있는 장치, 즉 모바일 단말이나 터치입력이 가능한 단말을 이용하여 2차 인증을 수행할 수도 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 크로스 포인트의 개수 및 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에는 터치궤적을 입력할 때 크로스 포인트의 개수가 증가하도록 하거나 또는 사인패드의 화면 상에서 크로스 포인트가 생성되는 위치를 설정할 수 있다. 이 때, 사인패드의 영역을 분할하여 각각의 영역을 구분하고 특정한 영역에서 크로스 포인트가 생성되도록 터치궤적을 입력하는 방식으로 크로스 포인트의 위치를 조절할 수 있다.
또한, 크로스 포인트의 위치를 고려하는 경우에는, 크로스 포인트 간의 상대적 위치를 고려하거나 또는 사인패드의 영역에 따라 크로스 포인트 각각의 절대적 위치를 고려할 수도 있다.
예를 들어, 크로스 포인트 간의 상대적 위치를 고려하는 경우에는, 두번째로 생성되는 크로스 포인트의 위치가 첫번째로 생성되는 크로스 포인트의 위치보다 아래에 위치하도록 터치궤적을 입력할 수 있다. 또 다른 예를 들어, 크로스 포인트 각각의 절대적 위치를 고려하는 경우에는, 첫번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 1번 영역에 생성되도록 터치궤적을 입력하고, 두번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 2번 영역에 생성되도록 터치궤적을 입력할 수 있다.
이 때, 사인패드의 분할개수는 자유롭게 설정될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증이 완료된 경우에, POS에서는 1차 인증이 완료된 사용자에 대한 2차 인증을 수행할 수 있다.
결제 처리부(250)는 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행한다. 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
저장부(260)는 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결제 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 저장부(260)는 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장부(260)는 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
한편, 오프라인 결제 처리 장치는 메모리가 탑재되어 그 장치 내에서 정보를 저장할 수 있다. 일 구현예의 경우, 메모리는 컴퓨터로 판독 가능한 매체이다. 일 구현 예에서, 메모리는 휘발성 메모리 유닛일 수 있으며, 다른 구현예의 경우, 메모리는 비휘발성 메모리 유닛일 수도 있다. 일 구현예의 경우, 저장장치는 컴퓨터로 판독 가능한 매체이다. 다양한 서로 다른 구현 예에서, 저장장치는 예컨대 하드디스크 장치, 광학디스크 장치, 혹은 어떤 다른 대용량 저장장치를 포함할 수도 있다.
이와 같은 오프라인 결제 처리 장치를 사용함으로써, 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치궤적에 따라 생성된 크로스 포인트를 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 결제 전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공할 수 있다.
또한, 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지할 수 있다.
또한, 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행할 수 있다.
도 3은 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록도이다.
도 3을 참조하면, 본 발명의 일실시예에 다른 모바일 단말은 체크인 정보 수집부(310), 1차 인증 수행부(320), 2차 인증 수행부(330) 및 결제 수행부(340)를 포함한다.
체크인 정보 수집부(310)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 있다.
1차 인증 수행부(320)는 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다. 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 PIN 입력 창을 수신하면 모바일 단말을 이용하여 PIN을 입력함으로써 1차 인증을 수행할 수 있다. 이 후, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 PIN을 판단하여 1차 인증을 처리할 수 있다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
2차 인증 수행부(330)는 1차 인증이 유효한 경우에, 1차 인증에 종속적인 2차 인증을 위해서 터치궤적에 의한 크로스 포인트 기반의 2차 인증을 수행한다.
이 때, 사용자가 사전에 등록한 등록 크로스 포인트와 사용자가 입력한 터치궤적의 크로스 포인트를 비교하여 일치하는지 여부에 따라 2차 인증이 완료될 수 있다. 예를 들어, 사전에 등록한 등록 크로스 포인트가 터치궤적에 2개가 포함된 경우에는 2차 인증을 수행하기 위해서 등록 크로스 포인트와 동일한 개수의 크로스 포인트가 생성되도록 터치궤적을 입력할 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 크로스 포인트의 개수 및 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에는 터치궤적을 입력할 때 크로스 포인트의 개수가 증가하도록 하거나 또는 모바일 단말의 터치화면 상에서 크로스 포인트가 생성되는 위치를 설정할 수 있다. 이 때, 모바일 단말의 터치화면 영역을 분할하여 각각의 영역을 구분하고 특정한 영역에서 크로스 포인트가 생성되도록 터치궤적을 입력하는 방식으로 크로스 포인트의 위치를 조절할 수 있다.
또한, 크로스 포인트의 위치를 고려하는 경우에는, 크로스 포인트 간의 상대적 위치를 고려하거나 또는 터치화면 영역에 따라 크로스 포인트 각각의 절대적 위치를 고려할 수도 있다.
예를 들어, 크로스 포인트 간의 상대적 위치를 고려하는 경우에는, 두번째로 생성되는 크로스 포인트의 위치가 첫번째로 생성되는 크로스 포인트의 위치보다 아래에 위치하도록 터치궤적을 입력할 수 있다. 또 다른 예를 들어, 크로스 포인트 각각의 절대적 위치를 고려하는 경우에는, 첫번째 크로스 포인트는 사분할된 모바일 단말의 터치화면 영역 중 반드시 1번 영역에 생성되도록 터치궤적을 입력하고, 두번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 2번 영역에 생성되도록 터치궤적을 입력할 수 있다.
이 때, 터치영역의 분할개수는 자유롭게 설정될 수 있다.
결제 수행부(340)는 매장에서의 오프라인 결제를 수행하기 위해 2차 인증에 상응하는 정보를 서버로 전송하고, 오프라인 결제의 결과를 수신한다. 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 4 내지 도 8은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 4 내지 도 8을 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법은 어플리케이션 페이 서비스에 가입한 사용자가 오프라인 매장에 진입하면, 도 4와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(410)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(410)을 모바일 단말에 노출할 수 있다. 즉, 모바일 단말이 매장의 비콘을 통해 매장에 상응하는 체크인 정보를 획득함으로써 할인 정보 및 쿠폰 정보를 획득할 수 있다. 또한, 모바일 단말은 어플리케이션을 통해 오프라인 결제 처리 장치로 체크인 정보를 제공할 수 있다.
이 때, 상품 혜택 화면(410)은, 모바일 단말이 잠겨있는 경우에는 모바일 단말의 Lockscreen(412)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수 있다.
또한, 상품 혜택 화면(410)은, 모바일 단말의 BLE Noti(411)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(410)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 도 5와 같이 어플리케이션을 통해 상품 혜택 화면(410)에 상응하는 매장의 상세 화면(510)을 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(510)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 결제하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 절차를 진행할 수 있도록 할 수 있다.
이 때, 사용자가 매장의 상세 화면(510) 또는 상품 혜택 화면(410)에 출력되는 결제하기 버튼을 선택하면, 어플리케이션 페이 서비스를 위한 1차 인증을 수행하기 위해 도 6과 같이 결제 PIN 입력 창(610)을 출력할 수 있다. 즉, 어플리케이션을 통해 연동된 오프라인 결제 처리 장치를 기반으로 해당 매장에서의 선승인에 해당하는 1차 인증을 위한 창을 모바일 단말에 출력할 수 있다.
이 때, 1차 인증은 PIN 번호 입력 인증 방식 이외에도 픽처 이미지제스처 인증 방식이나 터치 제스처 인증 방식, 지문 인식, 얼굴 인식 및 목소리 인식 등의 방식을 이용할 수도 있다.
이 때, 사용자가 PIN을 입력하면, 해당 PIN을 오프라인 결제 처리 장치로 전달하여 1차 인증을 완료할 수 있다.
이 때, 오프라인 결제 처리 장치나 서버에서 1차 인증이 완료된 사용자에 대한 사진이나 전화번호 등의 정보를 POS로 전송할 수도 있다.
이 후, 도 7과 같이 매장에 설치된 POS 장치에 결제 화면(710)에 1차 인증이 완료된 사용자, 즉 1차 인증이 완료된 구매자에 상응하는 정보가 표시될 수 있다.
이 후, 1차 인증이 완료되면 1차 인증에 종속적이고 POS에 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행할 수 있다.
이 때, 사용자가 사전에 등록한 등록 크로스 포인트와 사인패드에 입력된 크로스 포인트를 비교하여 일치하는 경우에 2차 인증이 완료될 수 있다.
이 때, 사용자의 모바일 단말을 이용하여 터체궤적을 입력할 수도 있다.
이 후, 2차 인증이 완료되어 어플리케이션 페이를 이용한 결제가 성공하면, 도 8과 같이 사용자의 모바일 단말로 결제 성공 메시지(811)를 전송할 수 있다.
이 때, 결제 성공 메시지(811)에는 결제된 매장의 이름과 결제 수단 및 결제 금액을 표시할 수 있다.
또한, 결제가 실패한 경우에는 사용자의 모바일 단말로 결제 실패 메시지(812)를 전송하고, 다시 결제를 수행하기 위해서 모바일 단말에 다시 결제하기 화면(813)을 출력할 수 있다.
이 때, 다시 결제하기 화면(813)에는 결제하기 버튼을 출력하거나 또는 어플리케이션 페이 결제를 위한 바코드를 출력할 수도 있다.
도 9 내지 도 15는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 9 내지 도 15를 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 페이 서비스의 비회원인 사용자가 오프라인 매장에 진입하면, 도 9와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(910)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(910)을 모바일 단말에 노출할 수 있다.
이 때, 상품 혜택 화면(910)은, 모바일 단말이 잠겨있는 경우에는 단말의 Lockscreen(912)에 할인 정보 및 쿠폰 정보를 출력하되, 어플리케이션 페이 서비스의 비회원이기 때문에 결제하기 버튼은 출력되지 않을 수 있다.
또한, 상품 혜택 화면(910)은, 모바일 단말의 BLE Noti(911)에 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(910)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 상품 혜택 화면(910)에 상응하는 도 10과 같은 매장의 상세 화면(1010)을 모바일 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(1010)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 어플리케이션 페이 서비스에 가입하기 위한 pay app 가입하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 서비스에 가입할 수 있도록 할 수 있다.
이 때, 사용자가 pay app 가입하기 버튼을 선택하면, 도 11과 같이 오프라인 결제 처리 시스템을 기반으로 어플리케이션 페이 서비스에 가입하기 위해 필요한 약관동의 화면(1110)을 사용자의 모바일 단말에 출력할 수 있다.
이 후, 사용자가 약관에 동의하면, 도 12와 같이 본인인증 화면(1210)을 모바일 단말에 출력하여 사용자 본인의 인증을 수행할 수 있다.
이 때, 본인인증은 사용자의 이름, 주민등록번호, 통신사 및 핸드폰 번호 등을 입력하고, 인증번호를 입력하는 방식으로 수행될 수 있다.
이 후, 사용자의 본인인증이 완료되면, 도 13과 같이 어플리케이션 페이 서비스에서 1차 인증에 사용할 결제 PIN 번호를 등록하기 위해 모바일 단말에 결제 PIN 등록 화면(1310)을 출력할 수 있다.
이 때, 1차 인증 방법에 따라 결제 PIN 등록 화면(1310)뿐만 아니라, 지문 등록 화면, 목소리 등록 화면 등 다양한 인증 수단의 등록 화면이 출력될 수도 있다.
이 후, 어플리케이션 페이 서비스에서 사용할 카드를 등록하기 위해 모바일 단말에 도 14와 같이 카드정보 등록 화면(1410)을 출력할 수 있다.
이 후, 모든 정보를 입력한 뒤, 도 15와 같이 최종적으로 가입확인 화면(1510)을 출력하고, 사용자가 확인을 선택하면 가입이 완료될 수 있다.
이 후, 사용자의 모바일 단말로 결제하기 버튼을 출력하여 PIN 번호를 통한 1차 인증을 수행한 뒤 어플리케이션 페이 서비스를 제공할 수 있다.
도 16은 본 발명에 따른 크로스 포인트를 등록하는 일 예를 나타낸 도면이다.
도 16을 참조하면, 본 발명의 일실시예에 따른 어플리케이션 페이 서비스를 사용하기 위해서는 사전에 크로스 포인트를 등록할 수 있다. 예를 들어, 사용자의 모바일 단말을 이용하여 어플리케이션 페이 서비스에 가입하는 과정에서 도 16과 같은 크로스 포인트 등록창(1610)이 나타나면 사용자가 직접 터치궤적(1620)을 입력함으로써 크로스 포인트(1630)를 등록할 수 있다.
이 때, 크로스 포인트(1630)는 터치궤적(1620)을 입력할 때 겹쳐지는 부분일 수 있다. 크로스 포인트(1630)를 등록할 때에는 터치궤적(1620)에 최소 하나 이상의 크로스 포인트(1630)가 포함되어야 할 수 있다. 물론, 터치궤적에 복수개의 크로스 포인트가 포함되어 있을 수 있다.
도 17은 본 발명에 따른 크로스 포인트를 등록하는 다른 예를 나타낸 도면이다.
도 17을 참조하면, 사용자가 복수개의 크로스 포인트를 결제 시 사용할 등록 크로스 포인트로 등록하는 것을 확인할 수 있다.
이 때, 2차 인증은 2차 인증 레벨에 상응하게 수행될 수 있으며, 2차 인증 레벨에 따라서 2차 인증 시 크로스 포인트의 개수나 크로스 포인트의 위치가 더 고려될 수 있다.
예를 들어, 2차 인증 레벨이 가장 낮은 1단계에 상응하는 경우에는 도 17과 같이 터치궤적(1720)에 두 개의 크로스 포인트(1730, 1731)가 포함되어 있는지 여부만을 비교할 수 있다.
이 때, 2차 인증 레벨이 1단계보다 높은 2단계로 향상되는 경우에는 두 개의 크로스 포인트(1730, 1731) 간의 상대적 위치를 더 고려하여 2차 인증을 수행할 수 있다. 즉, 첫번째로 생성된 크로스 포인트(1730)위 위치가 두번째로 생성된 크로스 포인트(1731)의 위치보다 위에 위치하는지 여부를 추가로 확인할 수 있다. 만약, 두번째로 생성된 크로스 포인트(1731)의 위치가 첫번째로 생성된 크로스 포인트(1730)보다 위에 위치한다면 2차 인증이 실패할 수 있다.
이 때, 2차 인증 레벨이 2단계보다 높은 3단계로 향상되는 경우에는 두 개의 크로스 포인트(1730), 1731) 각각의 절대적 위치를 더 고려하여 2차 인증을 수행할 수 있다. 즉, 첫번째로 생성된 크로스 포인트(1730)의 위치가 4분할된 사인패드의 영역들 중 좌 상단의 첫번째 영역에 위치하는지 확인하고, 두번째로 생성된 크로스 포인트(1731)의 위치가 4분할된 사인패드의 영역들 중 우 하단의 4번째 영역에 위치하는지 확인할 수 있다. 만약, 각각의 크로스 포인트(1730, 1731)가 하나라도 해당 영역의 위치하지 않을 경우에는 2차 인증이 실패할 수 있다.
도 18은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 18을 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S1810).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신한다(S1820).
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 1차 인증은 모바일 단말에 PIN 번호를 입력하는 것에 상응할 수 있다. 즉, 1차 인증은 모바일 단말에서 수행될 수 있다. 예를 들어, 모바일 단말에서 1차 인증을 수행하기 위해 PIN 번호를 입력하면, 모바일 단말에 입력된 PIN 번호를 1차 인증 정보로 인식하고 오프라인 결제 처리 장치로 전송함으로써 1차 승인이 이루어 질 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증은 체크인 정보를 기반으로 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절되는 1차 인증 레벨에 상응하게 수행될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은, 1차 인증 레벨이 향상된 경우에 PIN 번호를 입력하는 절차를 추가하도록 조절되어 수행될 수 있다. 예를 들어, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
이 때, 1차 인증의 방식에 따라 1차 인증 시 추가로 고려할 수 있는 조건들을 달리하여 1차 인증 레벨을 향상시킬 수도 있다. 예를 들어, 1차 인증 방식이 지문 인식에 상응한다고 가정하면, 1차 인증 레벨이 향상됨에 따라 추가로 다른 손가락의 지문 인식을 요청하도록 할 수 있다. 또한, 얼굴 인식의 경우에는 얼굴의 정면을 인식하는 것에 추가하여 얼굴의 좌측 또는 우측을 인식하도록 할 수도 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S1825).
이 후, 단계(S1825)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행한다(S1830).
이 때, 사용자가 사전에 등록한 등록 크로스 포인트와 크로스 포인트를 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 크로스 포인트가 터치궤적에 2개가 포함된 경우에는 2차 인증을 수행하기 위해서 등록 크로스 포인트와 동일한 개수의 크로스 포인트가 생성되도록 터치궤적을 입력할 수 있다.
이 때, POS의 사인패드 이외에도 터치궤적을 입력할 수 있는 장치, 즉 모바일 단말이나 터치입력이 가능한 단말을 이용하여 2차 인증을 수행할 수도 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 크로스 포인트의 개수 및 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에는 터치궤적을 입력할 때 크로스 포인트의 개수가 증가하도록 하거나 또는 사인패드의 화면 상에서 크로스 포인트가 생성되는 위치를 설정할 수 있다. 이 때, 사인패드의 영역을 분할하여 각각의 영역을 구분하고 특정한 영역에서 크로스 포인트가 생성되도록 터치궤적을 입력하는 방식으로 크로스 포인트의 위치를 조절할 수 있다.
또한, 크로스 포인트의 위치를 고려하는 경우에는, 크로스 포인트 간의 상대적 위치를 고려하거나 또는 사인패드의 영역에 따라 크로스 포인트 각각의 절대적 위치를 고려할 수도 있다.
예를 들어, 크로스 포인트 간의 상대적 위치를 고려하는 경우에는, 두번째로 생성되는 크로스 포인트의 위치가 첫번째로 생성되는 크로스 포인트의 위치보다 아래에 위치하도록 터치궤적을 입력할 수 있다. 또 다른 예를 들어, 크로스 포인트 각각의 절대적 위치를 고려하는 경우에는, 첫번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 1번 영역에 생성되도록 터치궤적을 입력하고, 두번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 2번 영역에 생성되도록 터치궤적을 입력할 수 있다.
이 때, 사인패드의 분할개수는 자유롭게 설정될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증이 완료된 경우에, POS에서는 1차 인증이 완료된 사용자에 대한 2차 인증을 수행할 수 있다.
또한, 단계(S1825)의 판단결과 1차 인증이 유효하지 않으면, 다시 1차 인증을 수행하기 위해 1차 인증 정보를 수신할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행한다(S1840). 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
또한, 도 18에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결제 처리를 위해 필요한 정보를 송수신 한다. 특히, 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
또한, 도 18에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결제 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 정보를 저장하는 저장모듈은 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장모듈은 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
이와 같은 오프라인 결제 처리 방법을 통해 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치궤적에 따라 생성된 크로스 포인트를 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 결제 전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공할 수 있다.
또한, 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지할 수 있다.
또한, 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행할 수 있다.
도 19는 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 19를 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S1910).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다(S1920). 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 PIN 입력 창을 수신하면 모바일 단말을 이용하여 PIN을 입력함으로써 1차 인증을 수행할 수 있다. 이 후, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 PIN을 판단하여 1차 인증을 처리할 수 있다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S1925).
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
단계(S1925)의 판단결과 1차 인증이 유효하지 않으면 1차 인증을 수행할 수 있다.
또한, 단계(S1925)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은, 1차 인증에 종속적인 2차 인증을 위해서 터치궤적에 의한 크로스 포인트 기반의 2차 인증을 수행한다(S1930).
이 때, 사용자가 사전에 등록한 등록 크로스 포인트와 사용자가 입력한 터치궤적의 크로스 포인트를 비교하여 일치하는지 여부에 따라 2차 인증이 완료될 수 있다. 예를 들어, 사전에 등록한 등록 크로스 포인트가 터치궤적에 2개가 포함된 경우에는 2차 인증을 수행하기 위해서 등록 크로스 포인트와 동일한 개수의 크로스 포인트가 생성되도록 터치궤적을 입력할 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 크로스 포인트의 개수 및 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에는 터치궤적을 입력할 때 크로스 포인트의 개수가 증가하도록 하거나 또는 모바일 단말의 터치화면 상에서 크로스 포인트가 생성되는 위치를 설정할 수 있다. 이 때, 모바일 단말의 터치화면 영역을 분할하여 각각의 영역을 구분하고 특정한 영역에서 크로스 포인트가 생성되도록 터치궤적을 입력하는 방식으로 크로스 포인트의 위치를 조절할 수 있다.
또한, 크로스 포인트의 위치를 고려하는 경우에는, 크로스 포인트 간의 상대적 위치를 고려하거나 또는 터치화면 영역에 따라 크로스 포인트 각각의 절대적 위치를 고려할 수도 있다.
예를 들어, 크로스 포인트 간의 상대적 위치를 고려하는 경우에는, 두번째로 생성되는 크로스 포인트의 위치가 첫번째로 생성되는 크로스 포인트의 위치보다 아래에 위치하도록 터치궤적을 입력할 수 있다. 또 다른 예를 들어, 크로스 포인트 각각의 절대적 위치를 고려하는 경우에는, 첫번째 크로스 포인트는 사분할된 모바일 단말의 터치화면 영역 중 반드시 1번 영역에 생성되도록 터치궤적을 입력하고, 두번째 크로스 포인트는 사분할된 모바일 단말의 터치화면 영역 중 반드시 2번 영역에 생성되도록 터치궤적을 입력할 수 있다.
이 때, 터치영역의 분할개수는 자유롭게 설정될 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 는 매장에서의 오프라인 결제를 수행하기 위해 2차 인증에 상응하는 정보를 서버로 전송하고, 오프라인 결제의 결과를 수신한다(S1940). 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 20은 도 18에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 20을 참조하면, 도 18에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정은 먼저 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과를 획득한다(S2010). 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 후, 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S2015).
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
단계(S2015)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하면, 크로스 포인트의 개수 및 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행한다(S2020).
예를 들어, 터치궤적을 입력할 때 크로스 포인트의 개수가 증가하도록 하거나 또는 모바일 단말의 터치화면 상에서 크로스 포인트가 생성되는 위치를 설정할 수 있다. 이 때, 사인패드 영역을 분할하여 각각의 영역을 구분하고 특정한 영역에서 크로스 포인트가 생성되도록 터치궤적을 입력하는 방식으로 크로스 포인트의 위치를 조절할 수 있다.
또한, 크로스 포인트의 위치를 고려하는 경우에는, 크로스 포인트 간의 상대적 위치를 고려하거나 또는 사인패드 영역에 따라 크로스 포인트 각각의 절대적 위치를 고려할 수도 있다.
예를 들어, 크로스 포인트 간의 상대적 위치를 고려하는 경우에는, 두번째로 생성되는 크로스 포인트의 위치가 첫번째로 생성되는 크로스 포인트의 위치보다 아래에 위치하도록 터치궤적을 입력할 수 있다. 또 다른 예를 들어, 크로스 포인트 각각의 절대적 위치를 고려하는 경우에는, 첫번째 크로스 포인트는 사분할된 사인패드 영역 중 반드시 1번 영역에 생성되도록 터치궤적을 입력하고, 두번째 크로스 포인트는 사분할된 사인패드의 영역 중 반드시 2번 영역에 생성되도록 터치궤적을 입력할 수 있다.
이 때, 터치영역의 분할개수는 자유롭게 설정될 수 있다.
또한, 단계(S2015)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하지 않으면, 2차 인증 레벨을 향상시키기 위한 과정을 수행하지 않고 2차 인증을 수행한다(S2030).
도 21은 도 18에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 21을 참조하면, 도 18에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정은 먼저 체크인 정보를 기반으로 모바일 단말에 대한 모니터링 결과를 획득한다(S2110). 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 후, 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S2115).
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
단계(S2115)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하면, 1차 인증 방식에 따라 1차 인증 시 고려되는 요소를 추가하여 1차 인증 레벨을 향상시킨다(S2120). 예를 들어, 1차 인증 방식이 PIN 입력이라고 가정한다면, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
또한, 단계(S2115)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하지 않으면, 1차 인증 레벨을 향상시키지 않고 1차 인증을 수행할 수 있다.
도 22는 본 발명의 일실시예에 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록도이다.
도 22을 참조하면, 본 발명의 일실시예에 따른 어플리케이션 페이를 이용한 결제 시스템은 어플리케이션 서버(2110), 단말(2120), POS 장치(2130), BLE 서버(2140) 및 BLE 장치(2150)를 포함한다.
본 발명의 일실시예에 따른 결제 시스템은 오프라인 매장에서 상품을 구매할 때, 사용자의 모바일 단말에 설치된 어플리케이션을 기반으로 어플리케이션 페이를 이용하여 결제를 수행하기 위한 시스템에 상응할 수 있다.
어플리케이션 서버(2110)는 사용자의 단말(2120)로 결제와 관련된 정보와 함께 결제를 수행하기 위한 어플리케이션(2111)을 제공하여 결제와 관련된 절차를 진행하는 서버일 수 있다. 이 때, 어플리케이션 서버(2110)는 네트워크를 통해 데이터를 송수신할 수 있다.
이 때, 어플리케이션 서버(2110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치일 수 있다. 또한, 어플리케이션 서버(2110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 포함할 수도 있다.
이 때, 네트워크는 어플리케이션 서버(2110)와 단말(2120) 사이에 데이터를 전달하는 통로를 제공하는 것으로서, 기존에 이용되는 네트워크 및 향후 개발 가능한 네트워크를 모두 포괄하는 개념이다. 예를 들어, 네트워크는 한정된 지역 내에서 각종 정보장치들의 통신을 제공하는 유무선근거리 통신망, 이동체 상호 간 및 이동체와 이동체 외부와의 통신을 제공하는 이동통신망, 위성을 이용해 지구국과 지구국간 통신을 제공하는 위성통신망이거나 유무선 통신망 중에서 어느 하나이거나, 둘 이상의 결합으로 이루어질 수 있다. 한편, 네트워크의 전송 방식 표준은, 기존의 전송 방식 표준에 한정되는 것은 아니며, 향후 개발될 모든 전송 방식 표준을 포함할 수 있다. 또한, 도 22에서 어플리케이션 서버(2110)와 단말(2120) 사이에 사용되는 네트워크는 어플리케이션 서버(2120)와 POS 장치(2130) 및 BLE 서버(2140)와 단말(2120) 상호간에 사용되는 네트워크와 상이한 것일 수도 있고, 동일한 것일 수도 있다.
단말(2120)은 어플리케이션을 이용하여 어플리케이션 서버(2110)로부터 상품 결제에 상응하는 정보를 수신하여 사용자에게 제공한다.
이 때, 단말(2120)은 통신망에 연결되어 어플리케이션을 실행할 수 있는 장치로, 휴대폰, PMP(Portable Multimedia Played), MID(Mobile Internet Device), 스마트폰(Smart Phone), 태블릿컴퓨터(Tablet PC), 노트북(Note book), 넷북(Net Book), 개인휴대용 정보단말(Personal Digital Assistant; PDA) 및 정보통신 기기 등과 같은 다양한 이동통신 사양을 갖는 모바일(Mobile) 단말일 수 있다.
또한, 단말(2120)은 숫자 및 문자 정보 등의 다양한 정보를 입력 받고, 각종 기능을 설정 및 단말(2120)의 기능 제어와 관련하여 입력되는 신호를 입력부를 통해 제어부로 전달할 수 있다. 또한, 단말(2120)의 입력부는 사용자의 터치 또는 조작에 따른 입력 신호를 발생하는 키패드와 터치패드 중 적어도 하나를 포함하여 구성할 수 있다. 이 때, 단말(2120)의 입력부는 단말(2120)의 표시부와 함께 하나의 터치패널(또는 터치 스크린(touch screen))의 형태로 구성되어 입력과 표시 기능을 동시에 수행할 수 있다. 또한, 단말(2120)의 입력부는 키보드, 키패드, 마우스, 조이스틱 등과 같은 입력 장치 외에도 향후 개발될 수 있는 모든 형태의 입력 수단이 사용될 수 있다. 특히, 본 발명에 따른 단말(2120)의 입력부는 최적 카드 추천 시스템 기반으로 카드를 선택하거나 결제를 수행하기 위한 입력 신호를 단말(2120)의 제어부로 전달할 수 있다.
또한, 단말(2120)의 표시부는 단말(2120)의 기능 수행 중에 발생하는 일련의 동작상태 및 동작결과 등에 대한 정보를 표시할 수 있다. 또한, 단말(2120)의 표시부는 단말(2120)의 메뉴 및 사용자가 입력한 사용자 데이터 등을 표시할 수 있다. 여기서, 단말(2120)의 표시부는 액정표시장치(LCD, Liquid Crystal Display), 초박막 액정표시장치(TFT-LCD, Thin Film Transistor LCD), 발광다이오드(LED, Light Emitting Diode), 유기 발광다이오드(OLED, Organic LED), 능동형 유기발광다이오드(AMOLED, Active Matrix OLED), 레티나 디스플레이(Retina Display), 플렉시블 디스플레이(Flexible display) 및 3차원(3 Dimension) 디스플레이 등으로 구성될 수 있다. 이 때, 단말(2120)의 표시부가 터치스크린 형태로 구성된 경우, 단말(2120)의 표시부는 단말(2120)의 입력부의 기능 중 일부 또는 전부를 수행할 수 있다. 특히, 본 발명에 따른 단말(2120)의 표시부는 최적 카드 추천 시스템 기반으로 제공되는 최적 추천 카드 및 결제와 관련된 정보를 화면으로 표시할 수 있다.
또한, 단말(2120)의 저장부는 데이터를 저장하기 위한 장치로, 주 기억장치 및 보조 기억장치를 포함하고, 단말(2120)의 기능 동작에 필요한 응용 프로그램을 저장할 수 있다. 이러한 단말(2120)의 저장부는 크게 프로그램 영역과 데이터 영역을 포함할 수 있다. 여기서, 단말(2120)은 사용자의 요청에 상응하여 각 기능을 활성화하는 경우, 제어부의 제어 하에 해당 응용 프로그램들을 실행하여 각 기능을 제공하게 된다. 특히, 본 발명에 따른 단말(2120)의 저장부는 단말(2120)을 부팅시키는 운영체제, 최적 카드 추천 시스템을 기반으로 카드를 추천하거나 결제를 수행하기 위한 프로그램 등을 저장할 수 있다. 또한, 단말(2120)의 저장부는 다수의 컨텐츠를 저장하는 컨텐츠 DB와 단말(2120)의 정보를 저장할 수 있다. 이 때, 컨텐츠 DB는 컨텐츠를 실행하기 위한 실행 데이터와 컨텐츠에 대한 속성 정보를 포함하고, 컨텐츠 실행에 따른 컨텐츠 사용 정보 등이 저장될 수 있다. 그리고, 단말(2120)의 정보는 단말 사양 정보를 포함할 수 있다.
또한, 단말(2120)의 통신부는 어플리케이션 서버(2110)와 네트워크를 통해 데이터를 송수신하기 위한 기능을 수행할 수 있다. 여기서 단말(2120)의 통신부는 송신되는 신호의 주파수를 상승 변환 및 증폭하는 RF 송신 수단과 수신되는 신호를 저잡음 증폭하고 주파수를 하강 변환하는 RF 수신 수단 등을 포함할 수 있다. 이러한 단말(2120)의 통신부는 무선통신 모듈 및 유선통신 모듈 중 적어도 하나를 포함할 수 있다. 그리고, 무선통신 모듈은 무선 통신 방법에 따라 데이터를 송수신하기 위한 구성이며, 단말(2120)이 무선 통신을 이용하는 경우, 무선망 통신 모듈, 무선랜 통신 모듈 및 무선팬 통신 모듈 중 어느 하나를 이용하여 데이터를 어플리케이션 서버(2110)로 송수신할 수 있다. 또한, 유선통신 모듈은 유선으로 데이터를 송수신하기 위한 것이다. 유선통신 모듈은 유선을 통해 네트워크에 접속하여, 어플리케이션 서버(2110)에 데이터를 송수신할 수 있다. 즉 단말(2120)은 무선통신 모듈 또는 유선통신 모듈을 이용하여 네트워크에 접속하며, 네트워크를 통해 어플리케이션 서버(2110)와 데이터를 송수신할 수 있다. 특히, 본 발명에 따른 네트워크는 단말(2120)과 어플리케이션 서버(2110) 및 BLE 서버(2140)등이 통신하여 최적 카드 추천 시스템 기반으로 최적 카드를 추천하는데 필요한 데이터를 송수신할 수 있다.
또한, 단말(2120)의 제어부는 운영 체제((OS, Operation System) 및 각 구성을 구동시키는 프로세스 장치가 될 수 있다. 예를 들어, 제어부는 어플리케이션 서버(2110)에 접속하는 과정 전반을 제어할 수 있다. 별도의 서비스 어플리케이션을 통해 어플리케이션 서버(2110)에 접속하는 경우, 사용자의 요청에 따라 서비스 어플리케이션을 실행되는 과정 전반을 제어할 수 있으며, 실행과 동시에 어플리케이션 서버(2110)로 서비스 이용 요청이 전송되도록 제어할 수 있으며, 이때 사용자 인증에 필요한 단말(2120)의 정보가 함께 전송되도록 제어할 수 있다.
또한, 단말(2120)의 제어부는 사용자의 요청에 따라 단말(2120)의 저장부에 저장된 특정 컨텐츠를 실행할 수 있다. 이때, 제어부는 컨텐츠 실행에 따른 컨텐츠 사용 이력을 컨텐츠 사용 정보로 저장할 수 있다.
또한, 사용자의 단말(2120)은 어플리케이션 페이 서비스를 위한 어플리케이션이 설치되어 있으며, 어플리케이션 페이 서비스에 가입된 사용자의 단말(2120)에 상응할 수 있다.
POS 장치(2130)는 매장(2160)에서 상품의 결제를 수행하기 위한 장치로서, 어플리케이션 서버(2110)와 통신을 기반으로 어플리케이션 페이 서비스를 수행할 수 있는 장치에 상응할 수 있다.
BLE 서버(2140)는 블루투스 저전력 기술(bluetooth low energy)을 활용하여 단말(2120)의 위치를 파악하고 정보를 제공하기 위한 서버일 수 있다.
이 때, 블루투스 저전력 기술은 주변의 일정 반경 범위 내에서 블루투스 4.0을 기반으로 사물의 정보를 주기적으로 전송하는 근거리 무선 통신 기술이다. 즉, 단말(2120)의 사용자가 별도의 행동을 취하기 않더라도 자동으로 사용자의 위치를 파악하여 결제 서비스를 위한 신호를 제공할 수 있다.
이 때, 비콘은 BLE(Bluetooth Low Energy)를 활용한 근거리 데이터 통신 기술로, 근접도 측위를 바탕으로 사물 및 상황인식, 콘텐츠 푸시, 실내위치측위, 자동 체크인, 지오펜싱(GeoFencing) 등 다양한 응용 서비스를 가능하게 할 수 있다. 이전의 유사한 기술과 비교하면 보다 편리하고, 적은 비용으로 제공이 가능하기 때문에 새로운 서비스 시장 형성에 촉매제 역할을 할 수 있다. 이 때, 비콘은 어떤 신호를 알리기 위해 주기적으로 전송하는 기기를 모두 의미할 수 있다. 예를 들어, 도 22에 도시된 BLE 장치(2150)가 비콘에 해당할 수 있다.
이와 같은 비콘은 신호를 전송하는 방법에 따라 사운드 기반의 저주파 비콘, LED 비콘, 와이파이 비콘, 블루투스 비콘 등으로 나눌 수 있다. 또한, 비콘은 대략 21 바이트에 해당하는 소량의 패킷으로 주기적 신호를 전송할 수 있고, 신호를 받는 대상과 별도로 페어링이 필요하지 않으며, 저전력으로 동작하지만 최대 50미터까지 비콘 송신기의 ID값과 수신신호세기에 상응하는 신호를 전송하는 것이 가능하다. 또한, 가격이 저렴하고 소형으로 어디든 쉽게 부착이 가능하기 때문에 오프라인 매장의 경우에도 어느 곳이든 자유롭게 사용할 수 있다.
예를 들어, 매장(2160) 내의 특정 장소에 비콘을 설치하여 단말(2120)을 소지한 사용자 및 고객이 BLE 비콘의 영역 내에 들어올 경우 해당 단말(2120)을 감지하여 정보를 포함한 신호를 전송할 수 있다.
매장(2160)은 결제가 수행되는 오프라인상의 매장에 해당할 수 있으며, 어플리케이션 페이 에이전트 및 BLE 장치(2150)가 설치된 어플리케이션 페이 서비스 가맹점에 상응할 수 있다.
아래에서는 본 발명의 일실시예에 따른 결제 시스템을 서비스 흐름에 따라 설명한다.
먼저 사용자가 단말(2120)을 가지고 매장(2160)에 진입할 수 있다.
이 때, BLE 기반 근거리 데이터 통신 기술인 비콘을 이용하여 사용자가 매장(2160)에 진입한 것을 감지할 수 있다.
즉, 본 발명에 따르면 매장(2160)에 위치하는 비콘인 BLE 장치(2150)에서 전송되는 BLE 신호를 블루투스가 활성화된 단말(2120)에서 BLE SDK(2141)를 이용하여 수신할 수 있다. 이 때, BLE SDK(2141)를 기반으로 설치된 어플리케이션(2111)을 통해 BLE 신호를 수신할 수도 있다. 이 후, 단말(2120)이 BLE 서버(2140)로 BLE 신호에 포함된 정보를 전송하면, BLE 서버(2140)에서는 BLE 신호에 상응하는 BLE 혜택과 관련된 정보를 단말(2120)로 제공할 수 있다.
이 후, 단말(2120)에서는 어플리케이션을 통하여 BLE 서버(2140)로부터 수신한 BLE 혜택 정보를 기반으로 어플리케이션 서버(2110)에 접속할 수 있다.
이 때, 어플리케이션 서버(2110)는 결제를 수행하기 위한 적어도 하나의 모듈을 포함할 수 있다.
예를 들어, 어플리케이션 서버(2110)는 단말(2120)의 사용자 정보와 매장(2160)에 상응하는 매장 정보를 기반으로 멤버십 정보를 제공할 수 있는 멤버십 제공 모듈을 포함할 수 있다. 이 때, 멤버십 제공 모듈은 사용자 별 멤버십 정보와 매장 별 매장 정보를 저장할 수 있는 별도의 데이터베이스를 포함할 수 있다.
또 다른 예를 들어, 어플리케이션 서버(2110)는 어플리케이션 페이를 통해 결제를 수행하기 위한 어플리케이션 페이 결제 모듈을 포함할 수 있다. 이 때, 어플리케이션 페이 결제 모듈은 어플리케이션 페이를 통해 결제를 수행하기 위한 신용카드 정보 또는 은행 정보를 포함할 수 있다. 예를 들어, 사용자가 매장(2160)에서 상품을 구입하기 위해 신용카드를 통해 어플리케이션 페이를 결제할 때 어플리케이션 페이 결제 모듈과 신용카드 어플리케이션이 실시간 결제를 수행하기 위한 데이터를 송신 및 수신할 수 있다.
이 때, 어플리케이션 페이 결제 모듈은 신용카드 정보를 바탕으로 사용자가 보유한 신용카드 중 할인혜택, 매장혜택 및 적립 등을 고려한 최적 카드를 추천하는 최적 카드 추천 장치를 포함할 수 있다. 예를 들어, 신용카드의 종류별로 전월 목표 실적을 달성하였을 경우에 제공되는 혜택 정보와 멤버십 카드를 통해 제공되는 혜택 정보를 종합하여 할인율이나 적립율에 따른 최적 카드를 추천할 수 있다. 또한, 최적 카드 추천 장치는 어플리케이션 페이 결제 모듈과 독립적으로 구성될 수도 있다.
또 다른 예를 들어, 어플리케이션 서버(2110)는 멤버십 제공 모듈을 통해 멤버십 정보와 함께 매장(2160)에서 사용자가 사용할 수 있는 쿠폰이나 기프티콘에 대한 혜택 정보나 매장(2160)에서 진행중인 이벤트 및 마케팅 정보 등을 제공할 수 있는 매장 정보 제공 모듈을 포함할 수 있다. 예를 들어, 매장 정보 제공 모듈은 사용자가 어플리케이션을 통해 매장(2160)에서 사용할 수 있는 기프티콘이나 쿠폰을 조회하여 어플리케이션 서버(2110)에게 제공함으로써, 사용자가 단말(2120)에 설치된 어플리케이션을 통해 기프티콘이나 쿠폰을 사용하도록 할 수 있다. 또한, 매장 정보 제공 모듈은 본 발명의 일실시예에 따른 결제 시스템에 따른 서비스를 제공하는 복수 개의 매장들에 해당하는 이벤트 정보 및 마케팅 정보를 어플리케이션 서버(2110)에게 제공함으로써, 사용자가 방문하는 매장(2160)에서 진행 중인 이벤트 및 마케팅에 대한 정보를 사용자의 단말(2120)로 제공할 수 있다.
이 후, 단말(2120)을 통해 어플리케이션 서버(2110)에 접속한 사용자는 매장(2160)에서 상품의 구매를 위해 어플리케이션 페이 서비스에서 선 인증을 수행할 수 있다. 예를 들어, BLE 장치(2150)를 통해 구매관련 푸시 메시지를 수신하고, 푸시 메시지에 포함된 구매버튼을 클릭하는 등의 행위로 선 인증을 위한 단계로 진입할 수 있다. 이 때, 구매를 위한 선 인증, 즉 1차 인증의 수단으로는 PIN 번호 입력, 픽처 이미지제스처 및 터치제스처 등 다양한 방식을 사용할 수 있다.
이 때, 어플리케이션 서버(2110)에 포함되거나, 어플리케이션 서버(2110)에 상응할 수 있는 오프라인 결제 처리 장치가 단말(2120)에서 수행된 1차 인증의 해당하는 1차 인증 정보를 수신하여 인증 여부를 판단할 수 있다.
이 후, 사용자가 매장(2160)에서 구매할 상품을 가지고 POS 장치(2130)로 이동하여 매장(2160)의 점원에서 어플리케이션 페이를 통해 결제한다는 의사를 밝히고, 상품 구매 및 결제를 위한 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 1차 인증에 종속적인 인증일 수 있으며, 1차 인증이 유효한 상태에서 2차 인증이 수행될 수 있다.
예를 들어, 2차 인증 방법으로는, 사용자가 단말(2120)을 가지고 POS 장치(2130) 근처에 결제를 위한 zone에 위치하는 방식, 결제 zone 내에서 단말(2120)을 이용한 움직임 제스처 패턴을 입력하는 방식, POS 장치(2130)에 포함된 사인패드에 터치 패턴을 입력하는 방식, 사인패드에 교차점을 생성하는 방식, 질의응답 방식 등을 포함할 수 있다.
또한, 2차 인증은 매장(2160)의 점원이 구매 상품을 스캔한 뒤에 POS 장치(2130)를 통해 어플리케이션 페이 서비스를 사용하는 사용자를 확인한 뒤 결제를 진행할 수 있다.
이 후, 2차 인증까지 완료되면 어플리케이션 서버(2110)가 어플리케이션 페이를 통한 결제가 성공적으로 수행되었는지 여부를 알리는 메시지를 사용자의 단말(2120) 또는 POS 장치(2130) 중 적어도 하나로 전송할 수 있다.
이와 같은 어플리케이션 페이를 이용한 결제 시스템을 이용하면, 사용자가 매장(2160)에서 1차 인증을 수행하고 간단한 2차 인증을 수행하는 것만으로 보다 안전하고 편리하게 최적의 카드를 이용하여 상품을 결제하는 것이 가능하다.
도 23은 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록도이다.
도 23를 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 장치는 통신부(2210), 체크인 정보 획득부(2220), 1차 인증부(2230), 2차 인증부(2240), 결제 처리부(2250) 및 저장부(2260)를 포함한다.
통신부(2210)는 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결제 처리를 위해 필요한 정보를 송수신하는 역할을 한다. 특히, 본 발명의 일실시예에 따른 통신부(2210)는 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
체크인 정보 획득부(2220)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
1차 인증부(2230)는 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신한다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 1차 인증은 모바일 단말에 PIN 번호를 입력하는 것에 상응할 수 있다. 즉, 1차 인증은 모바일 단말에서 수행될 수 있다. 예를 들어, 모바일 단말에서 1차 인증을 수행하기 위해 PIN 번호를 입력하면, 모바일 단말에 입력된 PIN 번호를 1차 인증 정보로 인식하고 오프라인 결제 처리 장치로 전송함으로써 1차 승인이 이루어 질 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증은 체크인 정보를 기반으로 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절되는 1차 인증 레벨에 상응하게 수행될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은, 1차 인증 레벨이 향상된 경우에 PIN 번호를 입력하는 절차를 추가하도록 조절되어 수행될 수 있다. 예를 들어, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
이 때, 1차 인증의 방식에 따라 1차 인증 시 추가로 고려할 수 있는 조건들을 달리하여 1차 인증 레벨을 향상시킬 수도 있다. 예를 들어, 1차 인증 방식이 지문 인식에 상응한다고 가정하면, 1차 인증 레벨이 향상됨에 따라 추가로 다른 손가락의 지문 인식을 요청하도록 할 수 있다. 또한, 얼굴 인식의 경우에는 얼굴의 정면을 인식하는 것에 추가하여 얼굴의 좌측 또는 우측을 인식하도록 할 수도 있다.
2차 인증부(2240)는 1차 인증이 유효한 경우에 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행한다.
이 때, 사용자가 사전에 등록한 등록 터치 패턴과 터치 패턴을 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 터치 패턴이 좌, 우 두개의 영역으로 나눠진 사인패드에서 (좌, 우, 좌)의 순서에 상응하는 경우에는 2차 인증을 수행하기 위해서 등록 터치 패턴과 동일하게 사인패드의 좌, 우 영역을 순서대로 (좌, 우, 좌)로 터치할 수 있다.
이 때, 사인패드의 분할개수는 자유롭게 설정될 수 있다.
이 때, POS의 사인패드 이외에도 터치 패턴을 입력할 수 있는 장치, 즉 모바일 단말이나 터치입력이 가능한 단말을 이용하여 2차 인증을 수행할 수도 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에 터치 입력의 길이가 긴지 짧은지, 스와이프 입력은 어느 방향으로 스와이프 되었는지 및 스와이프의 속도가 빠른지 느린지 등을 추가로 고려하여 2차 인증이 수행될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증이 완료된 경우에, POS에서는 1차 인증이 완료된 사용자에 대한 2차 인증을 수행할 수 있다.
결제 처리부(2250)는 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행한다. 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
저장부(2260)는 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결제 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 저장부(2260)는 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장부(2260)는 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
한편, 오프라인 결제 처리 장치는 메모리가 탑재되어 그 장치 내에서 정보를 저장할 수 있다. 일 구현예의 경우, 메모리는 컴퓨터로 판독 가능한 매체이다. 일 구현 예에서, 메모리는 휘발성 메모리 유닛일 수 있으며, 다른 구현예의 경우, 메모리는 비휘발성 메모리 유닛일 수도 있다. 일 구현예의 경우, 저장장치는 컴퓨터로 판독 가능한 매체이다. 다양한 서로 다른 구현 예에서, 저장장치는 예컨대 하드디스크 장치, 광학디스크 장치, 혹은 어떤 다른 대용량 저장장치를 포함할 수도 있다.
이와 같은 오프라인 결제 처리 장치를 사용함으로써, 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치 패턴을 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 결제 전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공할 수 있다.
또한, 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지할 수 있다.
또한, 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행할 수 있다.
도 24는 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록도이다.
도 24을 참조하면, 본 발명의 일실시예에 다른 모바일 단말은 체크인 정보 수집부(2310), 1차 인증 수행부(2320), 2차 인증 수행부(2330) 및 결제 수행부(2340)를 포함한다.
체크인 정보 수집부(2310)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 있다.
1차 인증 수행부(2320)는 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다. 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 PIN 입력 창을 수신하면 모바일 단말을 이용하여 PIN을 입력함으로써 1차 인증을 수행할 수 있다. 이 후, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 PIN을 판단하여 1차 인증을 처리할 수 있다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
2차 인증 수행부(2330)는 1차 인증이 유효한 경우에, 1차 인증에 종속적인 2차 인증을 위해서 터치 패턴 기반의 2차 인증을 수행한다.
이 때, 사용자가 사전에 등록한 등록 터치 패턴과 터치 패턴을 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 터치 패턴이 좌, 우 두개의 영역으로 나눠진 모바일 단말의 터치 영역에서 (좌, 우, 좌)의 순서에 상응하는 경우에는 2차 인증을 수행하기 위해서 등록 터치 패턴과 동일하게 터치 영역의 좌, 우 영역을 순서대로 (좌, 우, 좌)로 터치할 수 있다.
이 때, 터치 영역의 분할개수는 자유롭게 설정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에 터치 입력의 길이가 긴지 짧은지, 스와이프 입력은 어느 방향으로 스와이프 되었는지 및 스와이프의 속도가 빠른지 느린지 등을 추가로 고려하여 2차 인증이 수행될 수 있다.
결제 수행부(2340)는 매장에서의 오프라인 결제를 수행하기 위해 2차 인증에 상응하는 정보를 서버로 전송하고, 오프라인 결제의 결과를 수신한다. 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 25 내지 도 29는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 25 내지 도 29을 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법은 어플리케이션 페이 서비스에 가입한 사용자가 오프라인 매장에 진입하면, 도 25와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(2410)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(2410)을 모바일 단말에 노출할 수 있다. 즉, 모바일 단말이 매장의 비콘을 통해 매장에 상응하는 체크인 정보를 획득함으로써 할인 정보 및 쿠폰 정보를 획득할 수 있다. 또한, 모바일 단말은 어플리케이션을 통해 오프라인 결제 처리 장치로 체크인 정보를 제공할 수 있다.
이 때, 상품 혜택 화면(2410)은, 모바일 단말이 잠겨있는 경우에는 모바일 단말의 Lockscreen(2412)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수 있다.
또한, 상품 혜택 화면(2410)은, 모바일 단말의 BLE Noti(2411)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(2410)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 도 26와 같이 어플리케이션을 통해 상품 혜택 화면(2410)에 상응하는 매장의 상세 화면(2510)을 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(2510)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 결제하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 절차를 진행할 수 있도록 할 수 있다.
이 때, 사용자가 매장의 상세 화면(2510) 또는 상품 혜택 화면(2410)에 출력되는 결제하기 버튼을 선택하면, 어플리케이션 페이 서비스를 위한 1차 인증을 수행하기 위해 도 27과 같이 결제 PIN 입력 창(2610)을 출력할 수 있다. 즉, 어플리케이션을 통해 연동된 오프라인 결제 처리 장치를 기반으로 해당 매장에서의 선승인에 해당하는 1차 인증을 위한 창을 모바일 단말에 출력할 수 있다.
이 때, 1차 인증은 PIN 번호 입력 인증 방식 이외에도 픽처 이미지제스처 인증 방식이나 터치 제스처 인증 방식, 지문 인식, 얼굴 인식 및 목소리 인식 등의 방식을 이용할 수도 있다.
이 때, 사용자가 PIN을 입력하면, 해당 PIN을 오프라인 결제 처리 장치로 전달하여 1차 인증을 완료할 수 있다.
이 때, 오프라인 결제 처리 장치나 서버에서 1차 인증이 완료된 사용자에 대한 사진이나 전화번호 등의 정보를 POS로 전송할 수도 있다.
이 후, 도 28과 같이 매장에 설치된 POS 장치에 결제 화면(2710)에 1차 인증이 완료된 사용자, 즉 1차 인증이 완료된 구매자에 상응하는 정보가 표시될 수 있다.
이 후, 1차 인증이 완료되면 1차 인증에 종속적이고 POS에 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행할 수 있다.
이 때, 사용자가 사전에 등록한 등록 터치 패턴과 사인패드에 입력된 터치 패턴을 비교하여 일치하는 경우에 2차 인증이 완료될 수 있다.
이 때, 사용자의 모바일 단말을 이용하여 터치 패턴을 입력할 수도 있다.
이 후, 2차 인증이 완료되어 어플리케이션 페이를 이용한 결제가 성공하면, 도 29과 같이 사용자의 모바일 단말로 결제 성공 메시지(2811)를 전송할 수 있다.
이 때, 결제 성공 메시지(2811)에는 결제된 매장의 이름과 결제 수단 및 결제 금액을 표시할 수 있다.
또한, 결제가 실패한 경우에는 사용자의 모바일 단말로 결제 실패 메시지(2812)를 전송하고, 다시 결제를 수행하기 위해서 모바일 단말에 다시 결제하기 화면(2813)을 출력할 수 있다.
이 때, 다시 결제하기 화면(2813)에는 결제하기 버튼을 출력하거나 또는 어플리케이션 페이 결제를 위한 바코드를 출력할 수도 있다.
도 30 내지 도 36은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 30 내지 도 36를 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 페이 서비스의 비회원인 사용자가 오프라인 매장에 진입하면, 도 30와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(2910)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(2910)을 모바일 단말에 노출할 수 있다.
이 때, 상품 혜택 화면(2910)은, 모바일 단말이 잠겨있는 경우에는 단말의 Lockscreen(2912)에 할인 정보 및 쿠폰 정보를 출력하되, 어플리케이션 페이 서비스의 비회원이기 때문에 결제하기 버튼은 출력되지 않을 수 있다.
또한, 상품 혜택 화면(2910)은, 모바일 단말의 BLE Noti(2911)에 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(2910)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 상품 혜택 화면(2910)에 상응하는 도 31과 같은 매장의 상세 화면(3010)을 모바일 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(3010)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 어플리케이션 페이 서비스에 가입하기 위한 pay app 가입하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 서비스에 가입할 수 있도록 할 수 있다.
이 때, 사용자가 pay app 가입하기 버튼을 선택하면, 도 32과 같이 오프라인 결제 처리 시스템을 기반으로 어플리케이션 페이 서비스에 가입하기 위해 필요한 약관동의 화면(3110)을 사용자의 모바일 단말에 출력할 수 있다.
이 후, 사용자가 약관에 동의하면, 도 33와 같이 본인인증 화면(3210)을 모바일 단말에 출력하여 사용자 본인의 인증을 수행할 수 있다.
이 때, 본인인증은 사용자의 이름, 주민등록번호, 통신사 및 핸드폰 번호 등을 입력하고, 인증번호를 입력하는 방식으로 수행될 수 있다.
이 후, 사용자의 본인인증이 완료되면, 도 34과 같이 어플리케이션 페이 서비스에서 1차 인증에 사용할 결제 PIN 번호를 등록하기 위해 모바일 단말에 결제 PIN 등록 화면(3310)을 출력할 수 있다.
이 때, 1차 인증 방법에 따라 결제 PIN 등록 화면(3310)뿐만 아니라, 지문 등록 화면, 목소리 등록 화면 등 다양한 인증 수단의 등록 화면이 출력될 수도 있다.
이 후, 어플리케이션 페이 서비스에서 사용할 카드를 등록하기 위해 모바일 단말에 도 35와 같이 카드정보 등록 화면(3410)을 출력할 수 있다.
이 후, 모든 정보를 입력한 뒤, 도 36와 같이 최종적으로 가입확인 화면(3510)을 출력하고, 사용자가 확인을 선택하면 가입이 완료될 수 있다.
이 후, 사용자의 모바일 단말로 결제하기 버튼을 출력하여 PIN 번호를 통한 1차 인증을 수행한 뒤 어플리케이션 페이 서비스를 제공할 수 있다.
도 37은 본 발명에 따른 터치 패턴을 등록하는 일 예를 나타낸 도면이다.
도 37을 참조하면, 본 발명의 일실시예에 따른 어플리케이션 페이 서비스를 사용하기 위해서는 사전에 터치 패턴을 등록할 수 있다. 예를 들어, 사용자의 모바일 단말을 이용하여 어플리케이션 페이 서비스에 가입하는 과정에서 도 37과 같은 터치 패턴 등록창(3610)이 나타나면 사용자가 직접 터치 입력함으로써 터치 패턴을 등록할 수 있다.
이 때, 사용자는 터치 패턴 등록창(3610)에 분할되어 있는 터치 영역(3621, 3622, 3623, 3624)들을 터치하여 터치 패턴을 생성할 수 있다. 예를 들어, 터치 영역(3621, 3622, 3623, 3624)들을 순서대로 한번씩 터치하면 터치 영역의 번호에 따라서 1, 2, 3, 4의 순서로 터치 패턴이 등록될 수 있다. 또한, 하나의 터치 영역(3621)을 연속으로 터치하여 1, 1, 1, 1의 터치 패턴을 등록할 수도 있다.
즉, 기본적인 터치 패턴은 터치 횟수와 터치 영역을 고려하여 생성될 수 있다.
이 때, 2차 인증은 2차 인증 레벨에 상응하게 수행될 수 있으며, 2차 인증 레벨에 따라서 2차 인증 시 터치 길이, 스와이프 방향 및 스와이프 속도 등이 더 고려될 수 있다.
예를 들어, 2차 인증 레벨이 가장 낮은 1단계에 상응하는 경우에는 터치 횟수와 터치 영역만을 고려하여 2차 인증을 수행할 수 있다.
이 때, 2차 인증 레벨이 2단계보다 높은 2단계로 향상되는 경우에는 터치 길이를 더 고려하여 2차 인증을 수행할 수 있다. 즉, 2차 인증 레벨이 1단계일 때에는 도 37에 터치 영역(3621, 3622, 3623, 3624)들에 기반하여 1, 2, 3, 1에 상응하게 터치 패턴이 생성되었다면, 2차 인증 레벨이 2단계일 때에는 긴 1, 긴 2, 짧은 3, 짧은 1에 상응하게 터치의 길이까지 제대로 입력되었는지 추가로 확인할 수 있다.
이 때, 2차 인증 레벨이 2단계보다 높은 3단계로 향상되는 경우에는 스와이프 방향을 더 고려하여 2차 인증을 수행할 수 있다. 즉, 2차 인증 레벨이 2단계일 때에는 도 37의 터치 영역(3621, 3622, 3623, 3624)들에 기반하여 긴 1, 긴 2, 짧은 3, 짧은 1에 상응하게 터치 패턴이 생성되었다면, 2차 인증 레벨이 3단계일 때에는 사용자가 터치 영역에 손가락을 댄 상태로 초기지점에서 최종지점으로 이동하는 스와이프 기술을 이용하여 긴 1 위, 긴 2 아래, 짧은 3 위, 짧은 1 아래에 상응하게 스와이프 방향까지 제대로 입력되었는지 추가로 확인할 수 있다.
이 때, 2차 인증 레벨이 3단계보다 높은 4단계로 향상되는 경우에는 스와이프 속도를 더 고려하여 2차 인증을 수행할 수 있다. 즉, 2차 인증 레벨이 3단계일 때에는 도 37의 터치 영역(3621, 3622, 3623, 3624)들에 기반하여 긴 1 위, 긴 2 아래, 짧은 3 위, 짧은 1 아래에 상응하게 터치 패턴이 생성되었다면, 2차 인증 레벨이 4단계일 때에는 긴 1 빠른 위, 긴 2 빠른 아래, 짧은 3 느린 위, 짧은 1 빠른 아래에 상응하게 스와이프 속도까지 제대로 입력되었는지 추가로 확인할 수 있다.
만약, 각각의 2차 인증 레벨에서 고려되는 조건에 대해서 하나라도 일치하지 않을 경우에는 2차 인증이 실패할 수 있다.
도 38은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 38을 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S3710).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신한다(S3720).
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 1차 인증은 모바일 단말에 PIN 번호를 입력하는 것에 상응할 수 있다. 즉, 1차 인증은 모바일 단말에서 수행될 수 있다. 예를 들어, 모바일 단말에서 1차 인증을 수행하기 위해 PIN 번호를 입력하면, 모바일 단말에 입력된 PIN 번호를 1차 인증 정보로 인식하고 오프라인 결제 처리 장치로 전송함으로써 1차 승인이 이루어 질 수 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증은 체크인 정보를 기반으로 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절되는 1차 인증 레벨에 상응하게 수행될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
이 때, 1차 인증은, 1차 인증 레벨이 향상된 경우에 PIN 번호를 입력하는 절차를 추가하도록 조절되어 수행될 수 있다. 예를 들어, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
이 때, 1차 인증의 방식에 따라 1차 인증 시 추가로 고려할 수 있는 조건들을 달리하여 1차 인증 레벨을 향상시킬 수도 있다. 예를 들어, 1차 인증 방식이 지문 인식에 상응한다고 가정하면, 1차 인증 레벨이 향상됨에 따라 추가로 다른 손가락의 지문 인식을 요청하도록 할 수 있다. 또한, 얼굴 인식의 경우에는 얼굴의 정면을 인식하는 것에 추가하여 얼굴의 좌측 또는 우측을 인식하도록 할 수도 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S3725).
이 후, 단계(S3725)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행한다(S3730).
이 때, 사용자가 사전에 등록한 등록 터치 패턴과 터치 패턴을 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 터치 패턴이 좌, 우 두개의 영역으로 나눠진 사인패드에서 (좌, 우, 좌)의 순서에 상응하는 경우에는 2차 인증을 수행하기 위해서 등록 터치 패턴과 동일하게 사인패드의 좌, 우 영역을 순서대로 (좌, 우, 좌)로 터치할 수 있다.
이 때, 사인패드의 분할개수는 자유롭게 설정될 수 있다.
이 때, POS의 사인패드 이외에도 터치궤적을 입력할 수 있는 장치, 즉 모바일 단말이나 터치입력이 가능한 단말을 이용하여 2차 인증을 수행할 수도 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에 터치 입력의 길이가 긴지 짧은지, 스와이프 입력은 어느 방향으로 스와이프 되었는지 및 스와이프의 속도가 빠른지 느린지 등을 추가로 고려하여 2차 인증이 수행될 수 있다.
이 때, 사인패드의 분할개수는 자유롭게 설정될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증이 완료된 경우에, POS에서는 1차 인증이 완료된 사용자에 대한 2차 인증을 수행할 수 있다.
또한, 단계(S3725)의 판단결과 1차 인증이 유효하지 않으면, 다시 1차 인증을 수행하기 위해 1차 인증 정보를 수신할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행한다(S3740). 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
또한, 도 38에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결제 처리를 위해 필요한 정보를 송수신 한다. 특히, 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
또한, 도 38에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결제 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 정보를 저장하는 저장모듈은 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장모듈은 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
이와 같은 오프라인 결제 처리 방법을 통해 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 사용자가 입력하는 터치 패턴을 이용하여 2차 인증을 수행함으로써 결제의 편의성을 제공할 수 있다.
또한, 결제 전 모니터링 상황에 따라 결제를 위한 인증 레벨을 가변함으로써 보다 안정성 있는 오프라인 결제 시스템을 제공할 수 있다.
또한, 1차 인증을 기반으로 한 2차 인증을 수행함으로써 1차 인증이 완료된 후 구매과정에서 발생할 수 있는 보안의 위험을 방지할 수 있다.
또한, 선인증을 기반으로 결제를 처리함으로써 별도로 지갑이나 카드를 꺼내지 않고도 모바일 단말만으로 안전하고 편리하게 오프라인 결제를 수행할 수 있다.
도 39는 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 39을 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S3810).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다(S3820). 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 PIN 입력 창을 수신하면 모바일 단말을 이용하여 PIN을 입력함으로써 1차 인증을 수행할 수 있다. 이 후, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 PIN을 판단하여 1차 인증을 처리할 수 있다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S3825).
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증의 진행이 불가능할 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
단계(S3825)의 판단결과 1차 인증이 유효하지 않으면 1차 인증을 수행할 수 있다.
또한, 단계(S3825)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은, 1차 인증에 종속적인 2차 인증을 위해서 터치 패턴 기반의 2차 인증을 수행한다(S3830).
이 때, 사용자가 사전에 등록한 등록 터치 패턴과 터치 패턴을 비교하여 일치하는지 여부에 따라 2차 인증을 수행할 수 있다.
예를 들어, 사전에 등록한 등록 터치 패턴이 좌, 우 두개의 영역으로 나눠진 모바일 단말의 터치 영역에서 (좌, 우, 좌)의 순서에 상응하는 경우에는 2차 인증을 수행하기 위해서 등록 터치 패턴과 동일하게 터치 영역의 좌, 우 영역을 순서대로 (좌, 우, 좌)로 터치할 수 있다.
이 때, 터치 영역의 분할개수는 자유롭게 설정될 수 있다.
이 때, 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행할 수 있다.
예를 들어, 2차 인증 레벨이 향상된 경우에 터치 입력의 길이가 긴지 짧은지, 스와이프 입력은 어느 방향으로 스와이프 되었는지 및 스와이프의 속도가 빠른지 느린지 등을 추가로 고려하여 2차 인증이 수행될 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 매장에서의 오프라인 결제를 수행하기 위해 2차 인증에 상응하는 정보를 서버로 전송하고, 오프라인 결제의 결과를 수신한다(S3840). 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 40은 도 38에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 40를 참조하면, 도 38에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정은 먼저 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과를 획득한다(S3910). 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 후, 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S3915).
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
단계(S3915)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하면, 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 2차 인증을 수행한다(S3920).
예를 들어, 터치 입력의 길이가 긴지 짧은지, 스와이프 입력은 어느 방향으로 스와이프 되었는지 및 스와이프의 속도가 빠른지 느린지 등을 추가로 고려하여 2차 인증이 수행될 수 있다.
또한, 단계(S3915)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하지 않으면, 2차 인증 레벨을 향상시키기 위한 과정을 수행하지 않고 2차 인증을 수행한다(S3930).
도 41은 도 38에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 41을 참조하면, 도 38에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정은 먼저 체크인 정보를 기반으로 모바일 단말에 대한 모니터링 결과를 획득한다(S4010). 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 후, 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S4015).
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
단계(S4015)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하면, 1차 인증 방식에 따라 1차 인증 시 고려되는 요소를 추가하여 1차 인증 레벨을 향상시킨다(S4020). 예를 들어, 1차 인증 방식이 PIN 입력이라고 가정한다면, 1차 인증 레벨이 높아지면 단순한 PIN의 입력이 아니라 PIN을 입력할 때마다 모바일 단말의 자판을 변경할 수 있다. 또한, PIN을 입력한 뒤 색깔패턴까지 입력하도록 하거나 더미숫자를 이용하여 PIN의 길이를 증가시키는 방법을 사용할 수도 있다. 또한, PIN 입력 시, 모바일 단말의 오디오 잭에 이어폰이나 헤드폰이 연결되어 음악을 감상하는 중이라면 1차 인증 레벨이 향상됨에 따라 오디오 피드백을 통해 PIN을 입력하는 방법을 사용할 수도 있다.
또한, 단계(S4015)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하지 않으면, 1차 인증 레벨을 향상시키지 않고 1차 인증을 수행할 수 있다.
도 42는 본 발명의 일실시예에 따른 어플리케이션 페이를 이용한 오프라인 결제 시스템을 나타낸 블록도이다.
도 42을 참조하면, 본 발명의 일실시예에 따른 어플리케이션 페이를 이용한 결제 시스템은 어플리케이션 서버(4110), 단말(4120), POS 장치(4130), BLE 서버(4140) 및 BLE 장치(4150)를 포함한다.
본 발명의 일실시예에 따른 결제 시스템은 오프라인 매장에서 상품을 구매할 때, 사용자의 모바일 단말에 설치된 어플리케이션을 기반으로 어플리케이션 페이를 이용하여 결제를 수행하기 위한 시스템에 상응할 수 있다.
어플리케이션 서버(4110)는 사용자의 단말(4120)로 결제와 관련된 정보와 함께 결제를 수행하기 위한 어플리케이션(4111)을 제공하여 결제와 관련된 절차를 진행하는 서버일 수 있다. 이 때, 어플리케이션 서버(4110)는 네트워크를 통해 데이터를 송수신할 수 있다.
이 때, 어플리케이션 서버(4110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치일 수 있다. 또한, 어플리케이션 서버(4110)는 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 포함할 수도 있다.
이 때, 네트워크는 어플리케이션 서버(4110)와 단말(4120) 사이에 데이터를 전달하는 통로를 제공하는 것으로서, 기존에 이용되는 네트워크 및 향후 개발 가능한 네트워크를 모두 포괄하는 개념이다. 예를 들어, 네트워크는 한정된 지역 내에서 각종 정보장치들의 통신을 제공하는 유무선근거리 통신망, 이동체 상호 간 및 이동체와 이동체 외부와의 통신을 제공하는 이동통신망, 위성을 이용해 지구국과 지구국간 통신을 제공하는 위성통신망이거나 유무선 통신망 중에서 어느 하나이거나, 둘 이상의 결합으로 이루어질 수 있다. 한편, 네트워크의 전송 방식 표준은, 기존의 전송 방식 표준에 한정되는 것은 아니며, 향후 개발될 모든 전송 방식 표준을 포함할 수 있다. 또한, 도 42에서 어플리케이션 서버(4110)와 단말(4120) 사이에 사용되는 네트워크는 어플리케이션 서버(4120)와 POS 장치(4130) 및 BLE 서버(4140)와 단말(4120) 상호간에 사용되는 네트워크와 상이한 것일 수도 있고, 동일한 것일 수도 있다.
단말(4120)은 어플리케이션을 이용하여 어플리케이션 서버(4110)로부터 상품 결제에 상응하는 정보를 수신하여 사용자에게 제공한다.
이 때, 단말(4120)은 통신망에 연결되어 어플리케이션을 실행할 수 있는 장치로, 휴대폰, PMP(Portable Multimedia Played), MID(Mobile Internet Device), 스마트폰(Smart Phone), 태블릿컴퓨터(Tablet PC), 노트북(Note book), 넷북(Net Book), 개인휴대용 정보단말(Personal Digital Assistant; PDA) 및 정보통신 기기 등과 같은 다양한 이동통신 사양을 갖는 모바일(Mobile) 단말일 수 있다.
또한, 단말(4120)은 숫자 및 문자 정보 등의 다양한 정보를 입력 받고, 각종 기능을 설정 및 단말(4120)의 기능 제어와 관련하여 입력되는 신호를 입력부를 통해 제어부로 전달할 수 있다. 또한, 단말(4120)의 입력부는 사용자의 터치 또는 조작에 따른 입력 신호를 발생하는 키패드와 터치패드 중 적어도 하나를 포함하여 구성할 수 있다. 이 때, 단말(4120)의 입력부는 단말(4120)의 표시부와 함께 하나의 터치패널(또는 터치 스크린(touch screen))의 형태로 구성되어 입력과 표시 기능을 동시에 수행할 수 있다. 또한, 단말(4120)의 입력부는 키보드, 키패드, 마우스, 조이스틱 등과 같은 입력 장치 외에도 향후 개발될 수 있는 모든 형태의 입력 수단이 사용될 수 있다. 특히, 본 발명에 따른 단말(4120)의 입력부는 최적 카드 추천 시스템 기반으로 카드를 선택하거나 결제를 수행하기 위한 입력 신호를 단말(4120)의 제어부로 전달할 수 있다.
또한, 단말(4120)의 표시부는 단말(4120)의 기능 수행 중에 발생하는 일련의 동작상태 및 동작결과 등에 대한 정보를 표시할 수 있다. 또한, 단말(4120)의 표시부는 단말(4120)의 메뉴 및 사용자가 입력한 사용자 데이터 등을 표시할 수 있다. 여기서, 단말(4120)의 표시부는 액정표시장치(LCD, Liquid Crystal Display), 초박막 액정표시장치(TFT-LCD, Thin Film Transistor LCD), 발광다이오드(LED, Light Emitting Diode), 유기 발광다이오드(OLED, Organic LED), 능동형 유기발광다이오드(AMOLED, Active Matrix OLED), 레티나 디스플레이(Retina Display), 플렉시블 디스플레이(Flexible display) 및 3차원(3 Dimension) 디스플레이 등으로 구성될 수 있다. 이 때, 단말(4120)의 표시부가 터치스크린 형태로 구성된 경우, 단말(4120)의 표시부는 단말(4120)의 입력부의 기능 중 일부 또는 전부를 수행할 수 있다. 특히, 본 발명에 따른 단말(4120)의 표시부는 최적 카드 추천 시스템 기반으로 제공되는 최적 추천 카드 및 결제와 관련된 정보를 화면으로 표시할 수 있다.
또한, 단말(4120)의 저장부는 데이터를 저장하기 위한 장치로, 주 기억장치 및 보조 기억장치를 포함하고, 단말(4120)의 기능 동작에 필요한 응용 프로그램을 저장할 수 있다. 이러한 단말(4120)의 저장부는 크게 프로그램 영역과 데이터 영역을 포함할 수 있다. 여기서, 단말(4120)은 사용자의 요청에 상응하여 각 기능을 활성화하는 경우, 제어부의 제어 하에 해당 응용 프로그램들을 실행하여 각 기능을 제공하게 된다. 특히, 본 발명에 따른 단말(4120)의 저장부는 단말(4120)을 부팅시키는 운영체제, 최적 카드 추천 시스템을 기반으로 카드를 추천하거나 결제를 수행하기 위한 프로그램 등을 저장할 수 있다. 또한, 단말(4120)의 저장부는 다수의 컨텐츠를 저장하는 컨텐츠 DB와 단말(4120)의 정보를 저장할 수 있다. 이 때, 컨텐츠 DB는 컨텐츠를 실행하기 위한 실행 데이터와 컨텐츠에 대한 속성 정보를 포함하고, 컨텐츠 실행에 따른 컨텐츠 사용 정보 등이 저장될 수 있다. 그리고, 단말(4120)의 정보는 단말 사양 정보를 포함할 수 있다.
또한, 단말(4120)의 통신부는 어플리케이션 서버(4110)와 네트워크를 통해 데이터를 송수신하기 위한 기능을 수행할 수 있다. 여기서 단말(4120)의 통신부는 송신되는 신호의 주파수를 상승 변환 및 증폭하는 RF 송신 수단과 수신되는 신호를 저잡음 증폭하고 주파수를 하강 변환하는 RF 수신 수단 등을 포함할 수 있다. 이러한 단말(4120)의 통신부는 무선통신 모듈 및 유선통신 모듈 중 적어도 하나를 포함할 수 있다. 그리고, 무선통신 모듈은 무선 통신 방법에 따라 데이터를 송수신하기 위한 구성이며, 단말(4120)이 무선 통신을 이용하는 경우, 무선망 통신 모듈, 무선랜 통신 모듈 및 무선팬 통신 모듈 중 어느 하나를 이용하여 데이터를 어플리케이션 서버(4110)로 송수신할 수 있다. 또한, 유선통신 모듈은 유선으로 데이터를 송수신하기 위한 것이다. 유선통신 모듈은 유선을 통해 네트워크에 접속하여, 어플리케이션 서버(4110)에 데이터를 송수신할 수 있다. 즉 단말(4120)은 무선통신 모듈 또는 유선통신 모듈을 이용하여 네트워크에 접속하며, 네트워크를 통해 어플리케이션 서버(4110)와 데이터를 송수신할 수 있다. 특히, 본 발명에 따른 네트워크는 단말(4120)과 어플리케이션 서버(4110) 및 BLE 서버(4140)등이 통신하여 최적 카드 추천 시스템 기반으로 최적 카드를 추천하는데 필요한 데이터를 송수신할 수 있다.
또한, 단말(4120)의 제어부는 운영 체제(OS, Operation System) 및 각 구성을 구동시키는 프로세스 장치가 될 수 있다. 예를 들어, 제어부는 어플리케이션 서버(4110)에 접속하는 과정 전반을 제어할 수 있다. 별도의 서비스 어플리케이션을 통해 어플리케이션 서버(4110)에 접속하는 경우, 사용자의 요청에 따라 서비스 어플리케이션을 실행되는 과정 전반을 제어할 수 있으며, 실행과 동시에 어플리케이션 서버(4110)로 서비스 이용 요청이 전송되도록 제어할 수 있으며, 이때 사용자 인증에 필요한 단말(4120)의 정보가 함께 전송되도록 제어할 수 있다.
또한, 단말(4120)의 제어부는 사용자의 요청에 따라 단말(4120)의 저장부에 저장된 특정 컨텐츠를 실행할 수 있다. 이때, 제어부는 컨텐츠 실행에 따른 컨텐츠 사용 이력을 컨텐츠 사용 정보로 저장할 수 있다.
또한, 사용자의 단말(4120)은 어플리케이션 페이 서비스를 위한 어플리케이션이 설치되어 있으며, 어플리케이션 페이 서비스에 가입된 사용자의 단말(4120)에 상응할 수 있다.
POS 장치(4130)는 매장(4160)에서 상품의 결제를 수행하기 위한 장치로서, 어플리케이션 서버(4110)와 통신을 기반으로 어플리케이션 페이 서비스를 수행할 수 있는 장치에 상응할 수 있다.
BLE 서버(4140)는 블루투스 저전력 기술(bluetooth low energy)을 활용하여 단말(4120)의 위치를 파악하고 정보를 제공하기 위한 서버일 수 있다.
이 때, 블루투스 저전력 기술은 주변의 일정 반경 범위 내에서 블루투스 4.0을 기반으로 사물의 정보를 주기적으로 전송하는 근거리 무선 통신 기술이다. 즉, 단말(4120)의 사용자가 별도의 행동을 취하기 않더라도 자동으로 사용자의 위치를 파악하여 결제 서비스를 위한 신호를 제공할 수 있다.
이 때, 비콘은 BLE(Bluetooth Low Energy)를 활용한 근거리 데이터 통신 기술로, 근접도 측위를 바탕으로 사물 및 상황인식, 콘텐츠 푸시, 실내위치측위, 자동 체크인, 지오펜싱(GeoFencing) 등 다양한 응용 서비스를 가능하게 할 수 있다. 이전의 유사한 기술과 비교하면 보다 편리하고, 적은 비용으로 제공이 가능하기 때문에 새로운 서비스 시장 형성에 촉매제 역할을 할 수 있다. 이 때, 비콘은 어떤 신호를 알리기 위해 주기적으로 전송하는 기기를 모두 의미할 수 있다. 예를 들어, 도 42에 도시된 BLE 장치(4150)가 비콘에 해당할 수 있다.
이와 같은 비콘은 신호를 전송하는 방법에 따라 사운드 기반의 저주파 비콘, LED 비콘, 와이파이 비콘, 블루투스 비콘 등으로 나눌 수 있다. 또한, 비콘은 대략 21 바이트에 해당하는 소량의 패킷으로 주기적 신호를 전송할 수 있고, 신호를 받는 대상과 별도로 페어링이 필요하지 않으며, 저전력으로 동작하지만 최대 50미터까지 비콘 송신기의 ID값과 수신신호세기에 상응하는 신호를 전송하는 것이 가능하다. 또한, 가격이 저렴하고 소형으로 어디든 쉽게 부착이 가능하기 때문에 오프라인 매장의 경우에도 어느 곳이든 자유롭게 사용할 수 있다.
예를 들어, 매장(4160) 내의 특정 장소에 비콘을 설치하여 단말(4120)을 소지한 사용자 및 고객이 BLE 비콘의 영역 내에 들어올 경우 해당 단말(4120)을 감지하여 정보를 포함한 신호를 전송할 수 있다.
매장(4160)은 결제가 수행되는 오프라인상의 매장에 해당할 수 있으며, 어플리케이션 페이 에이전트 및 BLE 장치(4150)가 설치된 어플리케이션 페이 서비스 가맹점에 상응할 수 있다.
아래에서는 본 발명의 일실시예에 따른 결제 시스템을 서비스 흐름에 따라 설명한다.
먼저 사용자가 단말(4120)을 가지고 매장(4160)에 진입할 수 있다.
이 때, BLE 기반 근거리 데이터 통신 기술인 비콘을 이용하여 사용자가 매장(4160)에 진입한 것을 감지할 수 있다.
즉, 본 발명에 따르면 매장(4160)에 위치하는 비콘인 BLE 장치(4150)에서 전송되는 BLE 신호를 블루투스가 활성화된 단말(4120)에서 BLE SDK(4141)를 이용하여 수신할 수 있다. 이 때, BLE SDK(4141)를 기반으로 설치된 어플리케이션(4111)을 통해 BLE 신호를 수신할 수도 있다. 이 후, 단말(4120)이 BLE 서버(4140)로 BLE 신호에 포함된 정보를 전송하면, BLE 서버(4140)에서는 BLE 신호에 상응하는 BLE 혜택과 관련된 정보를 단말(4120)로 제공할 수 있다.
이 후, 단말(4120)에서는 어플리케이션을 통하여 BLE 서버(4140)로부터 수신한 BLE 혜택 정보를 기반으로 어플리케이션 서버(4110)에 접속할 수 있다.
이 때, 어플리케이션 서버(4110)는 결제를 수행하기 위한 적어도 하나의 모듈을 포함할 수 있다.
예를 들어, 어플리케이션 서버(4110)는 단말(4120)의 사용자 정보와 매장(4160)에 상응하는 매장 정보를 기반으로 멤버십 정보를 제공할 수 있는 멤버십 제공 모듈을 포함할 수 있다. 이 때, 멤버십 제공 모듈은 사용자 별 멤버십 정보와 매장 별 매장 정보를 저장할 수 있는 별도의 데이터베이스를 포함할 수 있다.
또 다른 예를 들어, 어플리케이션 서버(4110)는 어플리케이션 페이를 통해 결제를 수행하기 위한 어플리케이션 페이 결제 모듈을 포함할 수 있다. 이 때, 어플리케이션 페이 결제 모듈은 어플리케이션 페이를 통해 결제를 수행하기 위한 신용카드 정보 또는 은행 정보를 포함할 수 있다. 예를 들어, 사용자가 매장(4160)에서 상품을 구입하기 위해 신용카드를 통해 어플리케이션 페이를 결제할 때 어플리케이션 페이 결제 모듈과 신용카드 어플리케이션이 실시간 결제를 수행하기 위한 데이터를 송신 및 수신할 수 있다.
이 때, 어플리케이션 페이 결제 모듈은 신용카드 정보를 바탕으로 사용자가 보유한 신용카드 중 할인혜택, 매장혜택 및 적립 등을 고려한 최적 카드를 추천하는 최적 카드 추천 장치를 포함할 수 있다. 예를 들어, 신용카드의 종류별로 전월 목표 실적을 달성하였을 경우에 제공되는 혜택 정보와 멤버십 카드를 통해 제공되는 혜택 정보를 종합하여 할인율이나 적립율에 따른 최적 카드를 추천할 수 있다. 또한, 최적 카드 추천 장치는 어플리케이션 페이 결제 모듈과 독립적으로 구성될 수도 있다.
또 다른 예를 들어, 어플리케이션 서버(4110)는 멤버십 제공 모듈을 통해 멤버십 정보와 함께 매장(4160)에서 사용자가 사용할 수 있는 쿠폰이나 기프티콘에 대한 혜택 정보나 매장(4160)에서 진행중인 이벤트 및 마케팅 정보 등을 제공할 수 있는 매장 정보 제공 모듈을 포함할 수 있다. 예를 들어, 매장 정보 제공 모듈은 사용자가 어플리케이션을 통해 매장(4160)에서 사용할 수 있는 기프티콘이나 쿠폰을 조회하여 어플리케이션 서버(4110)에게 제공함으로써, 사용자가 단말(4120)에 설치된 어플리케이션을 통해 기프티콘이나 쿠폰을 사용하도록 할 수 있다. 또한, 매장 정보 제공 모듈은 본 발명의 일실시예에 따른 결제 시스템에 따른 서비스를 제공하는 복수 개의 매장들에 해당하는 이벤트 정보 및 마케팅 정보를 어플리케이션 서버(4110)에게 제공함으로써, 사용자가 방문하는 매장(4160)에서 진행 중인 이벤트 및 마케팅에 대한 정보를 사용자의 단말(4120)로 제공할 수 있다.
이 후, 단말(4120)을 통해 어플리케이션 서버(4110)에 접속한 사용자는 매장(4160)에서 상품의 구매를 위해 어플리케이션 페이 서비스에서 선 인증을 수행할 수 있다. 예를 들어, BLE 장치(4150)를 통해 구매관련 푸시 메시지를 수신하고, 푸시 메시지에 포함된 구매버튼을 클릭하는 등의 행위로 선 인증을 위한 단계로 진입할 수 있다. 이 때, 구매를 위한 선 인증, 즉 1차 인증의 수단으로는 PIN 번호 입력, 픽처 이미지제스처 및 터치제스처 등 다양한 방식을 사용할 수 있다.
이 때, 어플리케이션 서버(4110)에 포함되거나, 어플리케이션 서버(4110)에 상응할 수 있는 오프라인 결제 처리 장치가 단말(4120)에서 수행된 1차 인증의 해당하는 1차 인증 정보를 수신하여 인증 여부를 판단할 수 있다.
이 후, 사용자가 매장(4160)에서 구매할 상품을 가지고 POS 장치(4130)로 이동하여 매장(4160)의 점원에서 어플리케이션 페이를 통해 결제한다는 의사를 밝히고, 상품 구매 및 결제를 위한 2차 인증을 수행할 수 있다.
이 때, 2차 인증은 1차 인증에 종속적인 인증일 수 있으며, 1차 인증이 유효한 상태에서 2차 인증이 수행될 수 있다.
예를 들어, 2차 인증 방법으로는, 사용자가 단말(4120)을 가지고 POS 장치(4130) 근처에 결제를 위한 zone에 위치하는 방식, 결제 zone 내에서 단말(4120)을 이용한 움직임 제스처 패턴을 입력하는 방식, POS 장치(4130)에 포함된 사인패드에 스와이프 패턴을 입력하는 방식, 사인패드에 교차점을 생성하는 방식, 질의응답 방식 등을 포함할 수 있다.
또한, 2차 인증은 매장(4160)의 점원이 구매 상품을 스캔한 뒤에 POS 장치(4130)를 통해 어플리케이션 페이 서비스를 사용하는 사용자를 확인한 뒤 결제를 진행할 수 있다.
이 후, 2차 인증까지 완료되면 어플리케이션 서버(4110)가 어플리케이션 페이를 통한 결제가 성공적으로 수행되었는지 여부를 알리는 메시지를 사용자의 단말(4120) 또는 POS 장치(4130) 중 적어도 하나로 전송할 수 있다.
이와 같은 어플리케이션 페이를 이용한 결제 시스템을 이용하면, 사용자가 매장(4160)에서 1차 인증을 수행하고 간단한 2차 인증을 수행하는 것만으로 보다 안전하고 편리하게 최적의 카드를 이용하여 상품을 결제하는 것이 가능하다.
도 43은 본 발명의 일실시예에 따른 오프라인 결제 처리 장치를 나타낸 블록도이다.
도 43를 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 장치는 통신부(4210), 체크인 정보 획득부(4220), 1차 인증부(4230), 2차 인증부(4240), 결제 처리부(4250) 및 저장부(4260)를 포함한다.
통신부(4210)는 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결체 처리를 위해 필요한 정보를 송수신하는 역할을 한다. 특히, 본 발명의 일실시예에 따른 통신부(4210)는 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
체크인 정보 획득부(4220)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
1차 인증부(4230)는 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신한다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 스와이프 동작 패턴은 사용자가 터치화면에 손가락을 댄 상태로 초기 지점에서 최종 지점으로 이동하는 스와이프 기술을 이용하여 생성된 패턴일 수 있다. 예를 들어, 터치화면에 손가락을 대고 이동한 방향과 횟수에 따라 각각 데이터가 생성되어 스와이프 동작 패턴이 생성될 수 있다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
예를 들어, 스와이프 동작 패턴 생성 시 스와이프 방향을 고려한다면, 터치 화면에서 위, 아래, 좌, 우에 상응하는 방향으로 여러 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
또한, 스와이프 동작 패턴 생성 시 스와이프 방향뿐만 아니라 스와이프 속도를 더 고려한다면, 터치 화면에서 빠른 위, 느린 위, 빠른 아래, 느린 아래와 같이 방향과 속도를 결합한 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
또한, 스와이프 동작 패턴 생성 시 스와이프 방향과 스와이프 속도에 스와이프 길이를 함께 고려한다면, 빠른-긴-위, 빠른-짧은-위, 느린-긴-아래, 느린-짧은-아래와 같이 방향, 속도 그리고 길이까지 결합한 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 사용자가 사전에 등록한 등록 패턴과 스와이프 동작 패턴을 비교하여 1차 인증을 수행할 수 있다.
이 때, 등록 패턴은 스와이프 동작 패턴과 동일한 방식의 패턴일 수 있으며, 스와이프 동작 패턴을 입력하는 방식과 동일하게 터치하여 등록될 수 있다.
이 때, 등록 패턴은 1차 인증에 상응하는 1차 인증 레벨에 따라, 등록 패턴의 전체 길이 및 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 등록 패턴의 전체 길이는 한번의 스와이프를 통해 입력되는 패턴의 전체 개수에 상응할 수 있다. 예를 들어, 등록 패턴의 전체 길이가 5 라고 가정한다면, 총 5번의 스와이프를 통한 패턴 입력을 통해 등록 패턴이 등록될 수 있다.
따라서, 1차 인증 레벨이 높을수록 안전성을 위해 등록 패턴의 전체 길이를 증가시킬 수 있다.
이 때, 등록 패턴의 설정 시 고려되는 요소는 스와이프 방향, 스와이프 속도 및 스와이프 길이에 상응할 수 있다. 따라서, 1차 인증 레벨에 따라 높은 인증 레벨에 상응하게 1차 인증을 수행하기 위해서는 많은 요소를 사용하여 보다 안전한 등록 패턴을 등록할 수 있다. 예를 들어, 1차 인증 레벨이 가장 높은 경우에는 스와이프 방향, 스와이프 속도 및 스와이프 길이를 모두 사용하도록 등록 패턴이 등록될 수 있고, 1차 인증 레벨이 가장 낮은 경우에는 스와이프 방향만을 사용하도록 등록 패턴이 등록될 수도 있다.
이 때, 1차 인증은 모바일 단말을 통해 가능한 PIN 입력, 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증 정보는 무효화될 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증 레벨은 체크인 정보가 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
2차 인증부(4240)는 1차 인증의 유효 여부를 검토하고, 1차 인증이 유효한 경우에 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 모바일 단말 및 매장에 상응하는 POS 중 적어도 하나로 전송한다. 예를 들어, 1차 인증 이후에 사용자가 매장에서 구매하고자 하는 상품 또는 서비스를 확정하여 매장의 POS로 전달할 수 있다. 이 때, POS에서는 2차 인증이 수행될 수 있으며 이를 사용자의 모바일 단말 및 POS 중 적어도 하나를 이용하여 수행될 수 있다. 따라서, 2차 인증을 위한 2차 인증 정보를 생성하여 모바일 단말과 POS 중 적어도 하나로 전송할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증에 기반하여 2차 인증을 위한 2차 인증 정보가 매장의 POS로 제공되고, POS에서는 제공된 2차 인증 정보를 이용하여 물건을 구매하려는 사용자에 대한 2차 인증을 수행할 수 있다. 예를 들어, 2차 인증은 상품을 구매하려는 사용자, 즉 모바일 단말을 통한 결제자의 사진이나 전화번호가 POS에 표시되고, 매장의 점원이 상품을 구매하려고 POS에 접근한 사용자에게 얼굴이나 전화번호를 확인하여 2차 인증을 수행하는 방식일 수 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 모바일 단말 및 POS에 연결된 사인패드 중 적어도 하나를 기반으로 추가 인증 정보를 생성하고, 2차 인증 레벨의 향상에 따른 추가 인증을 수행하기 위해 추가 인증 정보를 모바일 단말 및 POS 중 적어도 하나로 전송할 수 있다.
예를 들어, 추가 인증의 방법으로는 POS에서 사용자의 모바일 단말을 기설정된 흔들기 패턴에 상응하게 흔들어 인증하는 방법, 1차 인증 시 모바일 단말에 등록된 통화목록이나 캘린더를 기반으로 POS로 전송된 질문과 답변을 확인하는 방법, POS와 연동된 사인패드에 기설정된 두드림 패턴을 입력하는 방법, 사인패드에 기설정된 교차점 패턴을 입력하는 방법 및 POS를 기준으로 일정한 범위에 상응하는 결제 존에 위치하는 방법 등 여러 가지 간편한 방법을 이용할 수 있다.
결제 처리부(4250)는 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 매장에서의 오프라인 결제를 수행한다. 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
저장부(4260)는 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결체 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 저장부(4260)는 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장부(4260)는 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
한편, 오프라인 결제 처리 장치는 메모리가 탑재되어 그 장치 내에서 정보를 저장할 수 있다. 일 구현예의 경우, 메모리는 컴퓨터로 판독 가능한 매체이다. 일 구현 예에서, 메모리는 휘발성 메모리 유닛일 수 있으며, 다른 구현예의 경우, 메모리는 비휘발성 메모리 유닛일 수도 있다. 일 구현예의 경우, 저장장치는 컴퓨터로 판독 가능한 매체이다. 다양한 서로 다른 구현 예에서, 저장장치는 예컨대 하드디스크 장치, 광학디스크 장치, 혹은 어떤 다른 대용량 저장장치를 포함할 수도 있다.
이와 같은 오프라인 결제 처리 장치를 사용함으로써, 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 2채널 인증을 기반으로 보다 높은 안전성을 제공할 수 있다.
또한, 스와이프 패턴 기반의 선인증을 기반으로 모바일 단말을 꺼내지 않고도 안전하게 오프라인 결제를 수행할 수 있다.
또한, 모바일 단말을 이용한 오프라인 결제 시 사용자 편의를 극대화함과 동시에 안정적인 결제 서비스를 제공할 수 있다.
도 44는 본 발명의 일실시예에 따른 모바일 단말을 나타낸 블록도이다.
도 44을 참조하면, 본 발명의 일실시예에 다른 모바일 단말은 체크인 정보 수집부(4310), 1차 인증 수행부(4320), 2차 인증 수행부(4330) 및 결제 수행부(4340)를 포함한다.
체크인 정보 수집부(4310)는 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다.
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 잇다.
1차 인증 수행부(4320)는 스와이프 동작 패턴에 상응하는 1차 인증 정보를 입력하여 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다. 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 스와이프 입력 창을 수신하면 모바일 단말을 이용하여 스와이프 동작 패턴을 입력함으로써 1차 인증을 수행할 수 있다. 이 후, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 스와이프 동작 패턴을 사전에 등록된 등록 패턴과 비교하여 동일한 경우에 1차 인증을 처리할 수 있다.
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 스와이프 동작 패턴은 사용자가 터치화면에 손가락을 댄 상태로 초기 지점에서 최종 지점으로 이동하는 스와이프 기술을 이용하여 생성된 패턴일 수 있다. 예를 들어, 터치화면에 손가락을 대고 이동한 방향과 횟수에 따라 각각 데이터가 생성되어 스와이프 동작 패턴이 생성될 수 있다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
이 때, 등록 패턴은 스와이프 동작 패턴과 동일한 방식의 패턴일 수 있으며, 스와이프 동작 패턴을 입력하는 방식과 동일하게 터치하여 등록될 수 있다.
이 때, 등록 패턴은 1차 인증에 상응하는 1차 인증 레벨에 따라, 등록 패턴의 전체 길이 및 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 등록 패턴의 전체 길이는 한번의 스와이프를 통해 입력되는 패턴의 전체 개수에 상응할 수 있다. 예를 들어, 등록 패턴의 전체 길이가 5 라고 가정한다면, 총 5번의 스와이프를 통한 패턴 입력을 통해 등록 패턴이 등록될 수 있다.
따라서, 1차 인증 레벨이 높을수록 안전성을 위해 등록 패턴의 전체 길이를 증가시킬 수 있다.
이 때, 등록 패턴의 설정 시 고려되는 요소는 스와이프 방향, 스와이프 속도 및 스와이프 길이에 상응할 수 있다. 따라서, 1차 인증 레벨에 따라 높은 인증 레벨에 상응하게 1차 인증을 수행하기 위해서는 많은 요소를 사용하여 보다 안전한 등록 패턴을 등록할 수 있다. 예를 들어, 1차 인증 레벨이 가장 높은 경우에는 스와이프 방향, 스와이프 속도 및 스와이프 길이를 모두 사용하도록 등록 패턴이 등록될 수 있고, 1차 인증 레벨이 가장 낮은 경우에는 스와이프 방향만을 사용하도록 등록 패턴이 등록될 수도 있다.
또한, 1차 인증은 모바일 단말을 통해 가능한 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증 정보는 무효화될 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
2차 인증 수행부(4330)는 1차 인증이 유효한 경우에, 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성한다. 이 때, 2차 인증 정보는 모바일 단말을 사용하는 사용자의 사진이나 전화번호 등의 정보에 해당할 수 있다.
이 때, 2차 인증에 대한 2차 인증 레벨이 향상됨에 따라 추가 인증을 수행하는 경우에는 추가 인증 방식에 따른 추가 인증 정보를 생성할 수도 있다.
결제 수행부(4340)는 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증 정보를 서버 및 매장에 상응하는 POS 중 어느 하나로 전송하고, 오프라인 결제의 결과를 수신한다. 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 45 내지 도 49는 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 회원일 경우의 결제 진행 화면을 나타낸 도면이다.
도 45 내지 도 49을 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법은 어플리케이션 페이 서비스에 가입한 사용자가 오프라인 매장에 진입하면, 도 4와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(4410)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(4410)을 모바일 단말에 노출할 수 있다. 즉, 모바일 단말이 매장의 비콘을 통해 매장에 상응하는 체크인 정보를 획득함으로써 할인 정보 및 쿠폰 정보를 획득할 수 있다. 또한, 모바일 단말은 어플리케이션을 통해 오프라인 결제 처리 장치로 체크인 정보를 제공할 수 있다.
이 때, 상품 혜택 화면(4410)은, 모바일 단말이 잠겨있는 경우에는 모바일 단말의 Lockscreen(4412)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수 있다.
또한, 상품 혜택 화면(4410)은, 모바일 단말의 BLE Noti(4411)에 결제하기 버튼과 함께 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(4410)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 도 46와 같이 어플리케이션을 통해 상품 혜택 화면(4410)에 상응하는 매장의 상세 화면(4510)을 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(4510)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 결제하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 절차를 진행할 수 있도록 할 수 있다.
이 때, 사용자가 매장의 상세 화면(4510) 또는 상품 혜택 화면(4410)에 출력되는 결제하기 버튼을 선택하면, 어플리케이션 페이 서비스를 위한 1차 인증을 수행하기 위해 도 47과 같이 결제 스와이프 동작 패턴 입력 창(4610)을 출력할 수 있다. 즉, 어플리케이션을 통해 연동된 오프라인 결제 처리 장치를 기반으로 해당 매장에서의 선승인에 해당하는 1차 인증을 위한 스와이프 입력 창을 모바일 단말에 출력할 수 있다.
이 때, 1차 인증은 스와이프 동작 패턴 인증 방식 이외에도 픽처 이미지제스처 인증 방식이나 PIN 인증 방식을 이용할 수도 있다.
이 후, 사용자의 스와이프 동작 패턴 입력을 통해 1차 인증이 완료되면, 도 48과 같이 매장에 설치된 POS 장치의 결제 화면(4710)에 1차 인증이 완료된 사용자, 즉 1차 인증이 완료된 구매자에 상응하는 2차 인증 정보가 표시된다.
이 때, 사용자가 스와이프 동작 패턴을 입력하면, 해당 스와이프 동작 패턴을 오프라인 결제 처리 장치로 전달하여 1차 인증을 완료할 수 있다. 또한, 1차 인증이 완료되면 오프라인 결제 처리 장치가 2차 인증을 위해 2차 인증 정보에 해당하는 구매자의 사진이나 전화번호 등의 정보를 POS로 전송할 수 있다.
이 후, 1차 인증이 완료된 사용자가 구매할 상품을 가지고 POS 장치로 가서 점원에게 어플리케이션 페이로 결제를 요청하면, 점원은 결제 화면(4710)을 통해 2차 인증을 수행한 뒤 결제를 진행할 수 있다. 예를 들어, 사용자의 사진이나 전화번호 등의 2차 인증 정보를 통해 모바일 단말에서 1차 인증을 수행한 결제자와 POS에서 상품을 구매하려는 구매자가 일치하는지 체크할 수 있다.
이 때, 어플리케이션 페이 서비스를 위한 2차 인증은 2차 인증 레벨에 따라 추가적인 인증을 수행한 뒤 결제를 진행할 수도 있다.
이 후, 어플리케이션 페이를 이용한 결제가 성공하면, 도 49과 같이 사용자의 모바일 단말로 결제 성공 메시지(4811)를 전송할 수 있다.
이 때, 결제 성공 메시지(4811)에는 결제된 매장의 이름과 결제 수단 및 결제 금액을 표시할 수 있다.
또한, 결제가 실패한 경우에는 사용자의 모바일 단말로 결제 실패 메시지(4812)를 전송하고, 다시 결제를 수행하기 위해서 모바일 단말에 다시 결제하기 화면(4813)을 출력할 수 있다.
이 때, 다시 결제하기 화면(4813)에는 결제하기 버튼을 출력하거나 또는 어플리케이션 페이 결제를 위한 바코드를 출력할 수도 있다.
도 50 내지 도 56은 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 비회원일 경우의 회원 가입 화면을 나타낸 도면이다.
도 50 내지 도 56를 참조하면, 본 발명의 일실시예에 따른 BLE PUSH를 통한 결제 방법에서 어플리케이션 페이 서비스의 비회원인 사용자가 오프라인 매장에 진입하면, 도 50와 같이 모바일 단말에 설치된 어플리케이션을 통해 상품 혜택 화면(4910)을 사용자에게 출력한다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 매장에 설치된 비콘이 전송하는 BLE 신호를 인식하고, BLE 신호에 포함된 매장 내의 할인 정보 및 쿠폰 정보를 포함하는 상품 혜택 화면(4910)을 모바일 단말에 노출할 수 있다.
이 때, 상품 혜택 화면(4910)은, 모바일 단말이 잠겨있는 경우에는 단말의 Lockscreen(4912)에 할인 정보 및 쿠폰 정보를 출력하되, 어플리케이션 페이 서비스의 비회원이기 때문에 결제하기 버튼은 출력되지 않을 수 있다.
또한, 상품 혜택 화면(4910)은, 모바일 단말의 BLE Noti(4911)에 할인 정보 및 쿠폰 정보를 출력할 수도 있다.
이 때, 만약 사용자가 상품 혜택 화면(4910)에서 할인 정보 및 쿠폰 정보를 나타내는 body 영역을 선택하면, 상품 혜택 화면(4910)에 상응하는 도 51과 같은 매장의 상세 화면(5010)을 모바일 단말에 출력할 수 있다.
이 때, 매장의 상세 화면(5010)에는 매장 정보와 함께 보다 상세한 할인 및 쿠폰 정보를 출력할 수 있다. 또한, 어플리케이션 페이 서비스에 가입하기 위한 pay app 가입하기 버튼을 함께 출력하여 사용자가 언제든지 결제를 위한 서비스에 가입할 수 있도록 할 수 있다.
이 때, 사용자가 pay app 가입하기 버튼을 선택하면, 도 52과 같이 오프라인 결제 처리 시스템을 기반으로 어플리케이션 페이 서비스에 가입하기 위해 필요한 약관동의 화면(5110)을 사용자의 모바일 단말에 출력할 수 있다.
이 후, 사용자가 약관에 동의하면, 도 53와 같이 본인인증 화면(5210)을 모바일 단말에 출력하여 사용자 본인의 인증을 수행할 수 있다.
이 때, 본인인증은 사용자의 이름, 주민등록번호, 통신사 및 핸드폰 번호 등을 입력하고, 인증번호를 입력하는 방식으로 수행될 수 있다.
이 후, 사용자의 본인인증이 완료되면, 도 54과 같이 어플리케이션 페이 서비스에서 1차 인증에 사용할 등록 패턴을 등록하기 위해 모바일 단말에 등록 패턴 등록 화면(5310)을 출력할 수 있다.
이 후, 어플리케이션 페이 서비스에서 사용할 카드를 등록하기 위해 모바일 단말에 도 55와 같이 카드정보 등록 화면(5410)을 출력할 수 있다.
이 후, 모든 정보를 입력한 뒤, 도 56와 같이 최종적으로 가입확인 화면(5510)을 출력하고, 사용자가 확인을 선택하면 가입이 완료될 수 있다.
이 후, 사용자의 모바일 단말로 결제하기 버튼을 출력하여 스와이프 동작 패턴을 통한 1차 인증을 수행한 뒤 어플리케이션 페이 서비스를 제공할 수 있다.
도 57은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 오프라인 결제 처리 장치 측면에서 나타낸 동작 흐름도이다.
도 57을 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S5610).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, BLE 비콘과 같은 장치를 매장의 입구에 설치하고, BLE 비콘의 영역 내에 사용자의 모바일 단말이 들어올 경우에 해당 단말을 감지하여 매장의 정보를 포함한 신호를 전송할 수 있다. 이 때, 신호를 수신한 모바일 단말은 어플리케이션을 통해 해당 신호에 포함된 매장의 정보를 획득하고, 해당 정보를 체크인 정보로 하여 오프라인 결제 처리 장치로 전송할 수 있다.
이 때, 사용자의 모바일 단말이 매장을 방문한 것을 감지할 수 있는 기술이라면 어떤 기술에 국한되지 않고 체크인 정보를 획득하는 기술로 활용될 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신한다(S5620).
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 스와이프 동작 패턴은 사용자가 터치화면에 손가락을 댄 상태로 초기 지점에서 최종 지점으로 이동하는 스와이프 기술을 이용하여 생성된 패턴일 수 있다. 예를 들어, 터치화면에 손가락을 대고 이동한 방향과 횟수에 따라 각각 데이터가 생성되어 스와이프 동작 패턴이 생성될 수 있다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
예를 들어, 스와이프 동작 패턴 생성 시 스와이프 방향을 고려한다면, 터치 화면에서 위, 아래, 좌, 우에 상응하는 방향으로 여러 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
또한, 스와이프 동작 패턴 생성 시 스와이프 방향뿐만 아니라 스와이프 속도를 더 고려한다면, 터치 화면에서 빠른 위, 느린 위, 빠른 아래, 느린 아래와 같이 방향과 속도를 결합한 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
또한, 스와이프 동작 패턴 생성 시 스와이프 방향과 스와이프 속도에 스와이프 길이를 함께 고려한다면, 빠른-긴-위, 빠른-짧은-위, 느린-긴-아래, 느린-짧은-아래와 같이 방향, 속도 그리고 길이까지 결합한 패턴이 입력되어 스와이프 동작 패턴이 생성될 수 있다.
이 때, 모바일 단말에 설치된 어플리케이션을 통해 사용자가 사전에 등록한 등록 패턴과 스와이프 동작 패턴을 비교하여 1차 인증을 수행할 수 있다.
이 때, 등록 패턴은 스와이프 동작 패턴과 동일한 방식의 패턴일 수 있으며, 스와이프 동작 패턴을 입력하는 방식과 동일하게 터치하여 등록될 수 있다.
이 때, 등록 패턴은 1차 인증에 상응하는 1차 인증 레벨에 따라, 등록 패턴의 전체 길이 및 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 등록 패턴의 전체 길이는 한번의 스와이프를 통해 입력되는 패턴의 전체 개수에 상응할 수 있다. 예를 들어, 등록 패턴의 전체 길이가 5 라고 가정한다면, 총 5번의 스와이프를 통한 패턴 입력을 통해 등록 패턴이 등록될 수 있다.
따라서, 1차 인증 레벨이 높을수록 안전성을 위해 등록 패턴의 전체 길이를 증가시킬 수 있다.
이 때, 등록 패턴의 설정 시 고려되는 요소는 스와이프 방향, 스와이프 속도 및 스와이프 길이에 상응할 수 있다. 따라서, 1차 인증 레벨에 따라 높은 인증 레벨에 상응하게 1차 인증을 수행하기 위해서는 많은 요소를 사용하여 보다 안전한 등록 패턴을 등록할 수 있다. 예를 들어, 1차 인증 레벨이 가장 높은 경우에는 스와이프 방향, 스와이프 속도 및 스와이프 길이를 모두 사용하도록 등록 패턴이 등록될 수 있고, 1차 인증 레벨이 가장 낮은 경우에는 스와이프 방향만을 사용하도록 등록 패턴이 등록될 수도 있다.
이 때, 1차 인증은 모바일 단말을 통해 가능한 PIN 입력, 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
이 때, 1차 인증은 해제조건부 인증에 상응하고, 1차 인증이 해제되는 경우에 2차 인증 정보는 무효화될 수 있다. 즉, 1차 인증은 공간적 또는 시간적 해제 조건을 수반하는 인증에 상응할 수 있다.
이 때, 1차 인증의 해제조건 중 하나로 1차 인증이 유효한 시간에 해당하는 타임아웃 시간이 설정될 수 있다. 즉, 1차 인증을 수행한 뒤 미리 설정된 타임아웃 시간이 초과되면 자동으로 1차 인증이 해제될 수 있다.
이 때, 타임아웃 시간은 매장의 종류에 따라 상이하게 설정될 수 있다. 예를 들어, 슈퍼마켓과 같은 매장에서는 쇼핑 시간에 적합하게 30분에서 1시간 정도로 타임아웃 시간을 설정할 수 있다. 또한, 레스토랑과 같은 매장에서는 식사시간에 적합하게 2시간에서 3시간 정도로 타임아웃 시간을 설정할 수 있다.
이 때, 타임아웃 시간이 초과하여 1차 인증이 해제된 경우에는 2차 인증의 유효성 유무에 상관없이 모바일 단말을 통한 결제를 수행하지 못할 수 있다. 따라서, 1차 인증이 해제된 후 모바일 단말을 통한 결제를 수행하기 위해서는, 1차 인증을 다시 수행한 뒤 이에 따른 2차 인증을 수행하여 결제를 처리할 수 있다.
또한, 모바일 단말이 매장에서 일정한 거리 이상 멀어졌을 경우에 1차 인증을 해제할 수도 있다. 예를 들어, 매장의 입구와 매장의 내부 여러 곳에 설치된 근거리 무선 통신 장치를 이용하여 모바일 단말의 위치를 측위하고, 모바일 단말이 매장에서 빠져나가 일정거리 이상 멀어진것으로 판단되는 경우에 1차 인증이 해제될 수 있다.
이 때, 1차 인증 레벨은 체크인 정보가 획득한 모바일 단말에 대한 모니터링 결과에 따라 조절될 수 있다. 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨이 향상되도록 조절할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S5625). 즉, 1차 인증이 해제조건을 만족하여 해제되었는지 여부를 확인할 수 있다.
단계(S5625)의 판단결과 1차 인증이 유효하지 않으면, 다시 1차 인증을 수행하기 위해 1차 인증 정보를 수신할 수 있다.
또한, 단계(S5625)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 모바일 단말 및 매장에 상응하는 POS 중 적어도 하나로 전송한다(S5630). 예를 들어, 1차 인증 이후에 사용자가 매장에서 구매하고자 하는 상품 또는 서비스를 확정하여 매장의 POS로 전달할 수 있다. 이 때, POS에서는 2차 인증이 수행될 수 있으며 이를 사용자의 모바일 단말 및 POS 중 적어도 하나를 이용하여 수행될 수 있다. 따라서, 2차 인증을 위한 2차 인증 정보를 생성하여 모바일 단말과 POS 중 적어도 하나로 전송할 수 있다.
이 때, 2차 인증은 1차 인증보다는 인증 레벨이 낮을 수 있다. 즉, 모바일 단말을 통한 1차 인증을 통해 상품을 구매하고자 하는 사용자의 구매 의사가 확인되었으므로, 1차 인증의 해제조건이 만족되어 1차 인증이 해제되지 않았다면 보다 낮은 레벨의 2차 인증만으로 구매를 확정하여도 부정결제가 발생할 가능성이 낮아질 수 있다. 따라서, 2차 인증은 1차 인증보다 인증 레벨은 낮지만 사용자의 편의성을 최대한 도모할 수 있는 방식의 인증일 수 있다.
또한, 2차 인증은 1차 인증에 종속적인 인증에 상응할 수 있다. 즉, 모바일 단말을 이용한 1차 인증에 기반하여 2차 인증을 위한 2차 인증 정보가 매장의 POS로 제공되고, POS에서는 제공된 2차 인증 정보를 이용하여 물건을 구매하려는 사용자에 대한 2차 인증을 수행할 수 있다. 예를 들어, 2차 인증은 상품을 구매하려는 사용자, 즉 모바일 단말을 통한 결제자의 사진이나 전화번호가 POS에 표시되고, 매장의 점원이 상품을 구매하려고 POS에 접근한 사용자에게 얼굴이나 전화번호를 확인하여 2차 인증을 수행하는 방식일 수 있다.
이 때, 2차 인증은 구매에 상응하는 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행될 수 있다. 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨이 향상되도록 조절할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
이 때, 모바일 단말 및 POS에 연결된 사인패드 중 적어도 하나를 기반으로 추가 인증 정보를 생성하고, 2차 인증 레벨의 향상에 따른 추가 인증을 수행하기 위해 추가 인증 정보를 모바일 단말 및 POS 중 적어도 하나로 전송할 수 있다.
예를 들어, 추가 인증의 방법으로는 POS에서 사용자의 모바일 단말을 기설정된 흔들기 패턴에 상응하게 흔들어 인증하는 방법, 1차 인증 시 모바일 단말에 등록된 통화목록이나 캘린더를 기반으로 POS로 전송된 질문과 답변을 확인하는 방법, POS와 연동된 사인패드에 기설정된 두드림 패턴을 입력하는 방법, 사인패드에 기설정된 교차점 패턴을 입력하는 방법 및 POS를 기준으로 일정한 범위에 상응하는 결제 존에 위치하는 방법 등 여러 가지 간편한 방법을 이용할 수 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 매장에서의 오프라인 결제를 수행한다(S5640). 즉, 2차 인증까지 완료되면 사용자가 구매하고자 하는 상품이나 서비스에 대한 결제를 완료처리 할 수 있다.
또한, 도 57에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 네트워크와 같은 통신망을 통해 사용자의 모바일 단말과 오프라인 결체 처리를 위해 필요한 정보를 송수신 한다. 특히, 모바일 단말로부터 체크인, 1차 인증 및 2차 인증을 수행하기 위한 정보들을 수신하고, 모바일 단말에게 오프라인 결제 처리에 상응하는 정보를 제공할 수 있다.
이 때, 별도의 어플리케이션 서버 또는 매장에 설치된 POS로부터 오프라인 결제 처리를 수행하기 위한 정보들을 수신할 수도 있다.
또한, 도 57에는 도시하지 아니하였으나, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 상술한 바와 같이 본 발명의 일실시예에 따른 오프라인 결체 처리 서비스 과정에서 발생되는 다양한 정보를 저장한다.
실시예에 따라, 정보를 저장하는 저장모듈은 오프라인 결제 처리 장치와 독립적으로 구성되어 오프라인 결제 처리 서비스를 위한 기능을 지원할 수 있다. 이 때, 저장모듈은 별도의 대용량 스토리지로 동작할 수 있고, 동작 수행을 위한 제어 기능을 포함할 수 있다.
이와 같은 오프라인 결제 처리 방법을 통해 사용자가 모바일 단말을 이용하여 오프라인 결제를 수행할 때 2채널 인증을 기반으로 보다 높은 안전성을 제공할 수 있다.
또한, 스와이프 패턴 기반의 선인증을 기반으로 모바일 단말을 꺼내지 않고도 안전하게 오프라인 결제를 수행할 수 있다.
또한, 모바일 단말을 이용한 오프라인 결제 시 사용자 편의를 극대화함과 동시에 안정적인 결제 서비스를 제공할 수 있다.
도 58은 본 발명의 일실시예에 따른 오프라인 결제 처리 방법을 모바일 단말 측면에서 나타낸 동작 흐름도이다.
도 58을 참조하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 사용자가 진입한 매장에 상응하는 체크인 정보를 획득한다(S5710).
이 때, 체크인 정보는 BLE(Bluetooth low energy) 기술이나, WiFi 및 GPS 등의 기술을 이용하여 획득할 수 있다. 예를 들어, 사용자가 모바일 단말을 소지하고 매장에 진입하면, 모바일 단말이 매장의 입구에 설치된 BLE 비콘 장치로부터 비콘 신호를 수신할 수 있다. 이 때, 비콘 신호에는 해당 매장의 정보를 포함하는 체크인 정보를 포함할 수 잇다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행한다(S5720).
이 때, 1차 인증은 오프라인 결제 시 구매할 상품이나 결제할 금액이 확정되기 전에 이루어지는 사전 결제 인증에 상응할 수 있다.
이 때, 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 기반으로 1차 인증을 수행할 수 있다. 예를 들어, 모바일 단말에 설치된 어플리케이션에 상응하는 서버 및 오프라인 결제 처리 장치로부터 1차 인증에 상응하는 스와이프 동작 패턴 창을 수신하면 모바일 단말을 이용하여 사전에 등록된 등록 패턴과 동일하게 스와이프 동작 패턴을 입력함으로써 1차 인증을 수행할 수 있다. 즉, 서버 및 오프라인 결제 처리 장치에서는 모바일 단말을 통해 입력된 스와이프 동작 패턴을 등록 패턴과 비교하여 동일한 경우에 1차 인증이 완료된 것으로 처리할 수 있다.
이 때, 스와이프 동작 패턴은 스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정될 수 있다.
이 때, 등록 패턴은 스와이프 동작 패턴과 동일한 방식의 패턴일 수 있으며, 스와이프 동작 패턴을 입력하는 방식과 동일하게 터치하여 등록될 수 있다.
이 때, 등록 패턴은 1차 인증에 상응하는 1차 인증 레벨에 따라, 등록 패턴의 전체 길이 및 등록 패턴의 설정 시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록될 수 있다.
이 때, 등록 패턴의 전체 길이는 한번의 스와이프를 통해 입력되는 패턴의 전체 개수에 상응할 수 있다. 예를 들어, 등록 패턴의 전체 길이가 5 라고 가정한다면, 총 5번의 스와이프를 통한 패턴 입력을 통해 등록 패턴이 등록될 수 있다.
따라서, 1차 인증 레벨이 높을수록 안전성을 위해 등록 패턴의 전체 길이를 증가시킬 수 있다.
이 때, 등록 패턴의 설정 시 고려되는 요소는 스와이프 방향, 스와이프 속도 및 스와이프 길이에 상응할 수 있다. 따라서, 1차 인증 레벨에 따라 높은 인증 레벨에 상응하게 1차 인증을 수행하기 위해서는 많은 요소를 사용하여 보다 안전한 등록 패턴을 등록할 수 있다. 예를 들어, 1차 인증 레벨이 가장 높은 경우에는 스와이프 방향, 스와이프 속도 및 스와이프 길이를 모두 사용하도록 등록 패턴이 등록될 수 있고, 1차 인증 레벨이 가장 낮은 경우에는 스와이프 방향만을 사용하도록 등록 패턴이 등록될 수도 있다.
이 때, 1차 인증은 모바일 단말을 통해 가능한 PIN 입력, 지문인식, 얼굴인식, 목소리 인식 등 다양한 방식을 통해 수행될 수도 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증이 유효한지 여부를 판단한다(S5725).
단계(S5725)의 판단결과 1차 인증이 유효하지 않으면 1차 인증을 수행할 수 있다.
또한, 단계(S5725)의 판단결과 1차 인증이 유효하면, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성한다(S5730). 이 때, 2차 인증 정보는 모바일 단말을 사용하는 사용자의 사진이나 전화번호 등의 정보에 해당할 수 있다.
이 때, 2차 인증에 대한 2차 인증 레벨이 향상됨에 따라 추가 인증을 수행하는 경우에는 추가 인증 방식에 따른 추가 인증 정보를 생성할 수도 있다.
또한, 본 발명의 일실시예에 따른 오프라인 결제 처리 방법은 는 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증 정보를 서버 및 매장에 상응하는 POS 중 어느 하나로 전송하고, 오프라인 결제의 결과를 수신한다(S5740). 예를 들어, 오프라인 결제가 성공한 경우에는 오프라인 결제에 상응하는 매장의 이름과 결제 수단 및 결제 금액 등을 포함하는 결제 성공 메시지를 수신할 수 있다. 또한, 오프라인 결제가 실패한 경우에는 결제가 실패한 내용을 간략하게 포함하는 결제 실패 메시지를 수신할 수도 있다.
도 59는 도 57에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 59을 참조하면, 도 57에 도시된 오프라인 결제 처리 방법 중 1차 인증의 1차 인증 레벨을 향상시키는 과정은 먼저 체크인 정보를 기반으로 모바일 단말에 대한 모니터링 결과를 획득한다(S5810). 즉, 모니터링 결과에서 이상한 점이 발견되면 보다 안전한 인증을 위해 1차 인증 레벨을 향상시킴으로써 상황에 따라 보안을 강화할 수 있다.
이 때, 모니터링 결과는 1차 인증을 수행하기 이전까지의 상황에 상응할 수 있다.
이 후, 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S5815).
이 때, 모니터링 결과가, 체크인 정보를 획득한 후 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 1차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다. 즉, 모바일 단말을 소지한 사용자가 매장에 진입한 이후에 1차 인증을 수행하기 이전까지 비정상적으로 오랜 시간이 소요되었거나, 사용자가 진입한 매장이 모바일 부정결제가 빈번하게 발생하는 매장일 경우에는 보다 안전한 결제를 위해 1차 인증을 위한 1차 인증 레벨을 향상시킬 수 있다.
단계(S5815)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하면, 등록 패턴의 전체 길이를 증가시키는 방법 및 등록 패턴의 설정 시 고려되는 요소의 개수를 증가시키는 방법 중 적어도 하나의 방법을 이용하여 1차 인증 레벨을 향상시킨다(S5820). 예를 들어, 1차 인증 레벨이 높아지면 3번의 패턴으로 등록되어 있던 등록 패턴을 5번의 패턴으로 길이를 증가시킴으로써 안정성을 향상시킬 수 있다. 다른예를 들면, 스와이프 방향만을 고려하여 등록되어 있던 등록 패턴을 스와이프 속도 및 스와이프 길이 중 적어도 하나를 더 고려하도록 등록함으로써 안정성을 향상시킬 수 있다.
이 때, 등록 패턴의 설정 시 고려되는 요소의 개수가 증가할수록 인증의 안정성은 높아지지만, 정확도는 낮아질 수 있다. 따라서, 상황에 따라 인증 레벨과 사용자의 편의성 사이에서 적절한 인증 방식을 설정하여 사용할 수도 있다.
또한, 단계(S5815)의 판단결과 모니터링 결과가 1차 인증 레벨 향상 조건에 만족하지 않으면, 1차 인증 레벨을 향상시키지 않고 1차 인증을 수행할 수 있다.
도 60은 도 57에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정을 상세하게 나타낸 도면이다.
도 60를 참조하면, 도 57에 도시된 오프라인 결제 처리 방법 중 2차 인증의 2차 인증 레벨을 향상시키는 과정은 먼저 상품이 POS에 제출되기 전까지 모바일 단말에 대한 모니터링 결과를 획득한다(S5910). 즉, 1차 인증이 수행되고 나서 2차 인증이 수행되기 전까지의 상황을 고려하여 2차 인증 레벨이 결정될 수 있다.
이 후, 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하는지 여부를 판단한다(S5915).
이 때, 모니터링 결과가 1차 인증부터 상품이 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 1차 인증 이후 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 1차 인증 이후 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 2차 인증 레벨 향상 조건에 만족한 것으로 판단할 수 있다.
이 때, 기설정된 기준 구매시간은 1차 인증의 해제조건에 만족하는 타임아웃 시간보다는 적은 시간에 상응할 수 있다.
단계(S5915)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하면, 모바일 단말 및 POS에 연결된 사인패드 중 적어도 하나를 기반으로 추가 인증 정보를 생성한다(S5920).
이 후, 추가 인증을 수행하기 위해 추가 인증 정보를 모바일 단말 및 POS 중 적어도 하나로 전송한다(S5930).
또한, 단계(S5915)의 판단결과 모니터링 결과가 2차 인증 레벨 향상 조건에 만족하지 않으면, 2차 인증 레벨을 향상시키지 않고 2차 인증을 수행할 수 있다.
컴퓨터 프로그램 명령어와 데이터를 저장하기에 적합한 컴퓨터로 판독 가능한 매체는, 예컨대 기록매체는 하드 디스크, 플로피 디스크 및 자기 테이프와 같은 자기 매체(Magnetic Media), CD-ROM(Compact Disk Read Only Memory), DVD(Digital Video Disk)와 같은 광 기록 매체(Optical Media), 플롭티컬 디스크(Floptical Disk)와 같은 자기-광 매체(Magneto-Optical Media), 및 롬(ROM, Read Only Memory), 램(RAM, Random Access Memory), 플래시 메모리, EPROM(Erasable Programmable ROM), EEPROM(Electrically Erasable Programmable ROM)과 같은 반도체 메모리를 포함한다. 프로세서와 메모리는 특수 목적의 논리 회로에 의해 보충되거나, 그것에 통합될 수 있다. 프로그램 명령의 예에는 컴파일러에 의해 만들어지는 것과 같은 기계어 코드뿐만 아니라 인터프리터 등을 사용해서 컴퓨터에 의해서 실행될 수 있는 고급 언어 코드를 포함할 수 있다. 이러한 하드웨어 장치는 본 발명의 동작을 수행하기 위해 하나 이상의 소프트웨어 모듈로서 작동하도록 구성될 수 있으며, 그 역도 마찬가지이다.
본 명세서는 다수의 특정한 구현물의 세부사항들을 포함하지만, 이들은 어떠한 발명이나 청구 가능한 것의 범위에 대해서도 제한적인 것으로서 이해되어서는 안되며, 오히려 특정한 발명의 특정한 실시형태에 특유할 수 있는 특징들에 대한 설명으로서 이해되어야 한다. 개별적인 실시형태의 문맥에서 본 명세서에 기술된 특정한 특징들은 단일 실시형태에서 조합하여 구현될 수도 있다. 반대로, 단일 실시형태의 문맥에서 기술한 다양한 특징들 역시 개별적으로 혹은 어떠한 적절한 하위 조합으로도 복수의 실시형태에서 구현 가능하다. 나아가, 특징들이 특정한 조합으로 동작하고 초기에 그와 같이 청구된 바와 같이 묘사될 수 있지만, 청구된 조합으로부터의 하나 이상의 특징들은 일부 경우에 그 조합으로부터 배제될 수 있으며, 그 청구된 조합은 하위 조합이나 하위 조합의 변형물로 변경될 수 있다.
마찬가지로, 특정한 순서로 도면에서 동작들을 묘사하고 있지만, 이는 바람직한 결과를 얻기 위하여 도시된 그 특정한 순서나 순차적인 순서대로 그러한 동작들을 수행하여야 한다거나 모든 도시된 동작들이 수행되어야 하는 것으로 이해되어서는 안 된다. 특정한 경우, 멀티태스킹과 병렬 프로세싱이 유리할 수 있다. 또한, 상술한 실시형태의 다양한 시스템 컴포넌트의 분리는 그러한 분리를 모든 실시형태에서 요구하는 것으로 이해되어서는 안되며, 설명한 프로그램 컴포넌트와 시스템들은 일반적으로 단일의 소프트웨어 제품으로 함께 통합되거나 다중 소프트웨어 제품에 패키징 될 수 있다는 점을 이해하여야 한다.
한편, 본 명세서와 도면에 개시된 본 발명의 실시 예들은 이해를 돕기 위해 특정 예를 제시한 것에 지나지 않으며, 본 발명의 범위를 한정하고자 하는 것은 아니다. 여기에 개시된 실시 예들 이외에도 본 발명의 기술적 사상에 바탕을 둔 다른 변형 예들이 실시 가능하다는 것은, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 자명한 것이다.
본 발명에 의하면 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하고, 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하고, 1차 인증이 유효한 경우에, 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하고, 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행할 수 있다. 나아가, 사용자들에게 편의성을 극대화하면서도 안정적인 오프라인 결제 서비스를 제공하는 것이 가능하다.
또한, 본 발명에 의하면 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하고, 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하고, 1차 인증이 유효한 경우에, 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행하고, 2차 인증의 결과에 기반하여 매장에서의 오프라인 결제를 수행할 수 있다. 나아가, 사용자들에게 편의성을 극대화하면서도 안정적인 오프라인 결제 서비스를 제공하는 것이 가능하다.
또한, 본 발명에 의하면 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하고, 모바일 단말로부터 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신하고, 1차 인증이 유효한 경우에 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 모바일 단말 및 매장에 상응하는 POS 중 적어도 하나로 전송하고, 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 매장에서의 오프라인 결제를 수행할 수 있다. 나아가, 사용자들에게 편의성을 극대화하면서도 안정적인 오프라인 결제 서비스를 제공하는 것이 가능하다.

Claims (20)

  1. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 1차 인증부;
    상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하는 2차 인증부; 및
    상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  2. 청구항 1에 있어서,
    상기 2차 인증부는
    상기 사용자가 사전에 등록한 등록 크로스 포인트와 상기 크로스 포인트를 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  3. 청구항 2에 있어서,
    상기 2차 인증은
    상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행되는 것을 특징으로 하는 오프라인 결제 처리 장치.
  4. 청구항 3에 있어서,
    상기 2차 인증부는
    상기 2차 인증 레벨이 향상된 경우에 상기 크로스 포인트의 개수 및 상기 크로스 포인트의 위치 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  5. 청구항 4에 있어서,
    상기 2차 인증부는
    상기 모니터링 결과가 상기 1차 인증부터 상기 상품이 상기 POS에 제출되기 전까지의 시간이 기설정된 기준 구매시간을 초과한 경우, 상기 1차 인증 이후 상기 모바일 단말의 이동 거리가 기설정된 기준 이동 거리를 초과한 경우 및 상기 1차 인증 이후 상기 모바일 단말의 이동 속도가 기설정된 기준 이동 속도를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 2차 인증 레벨을 향상시키는 것을 특징으로 하는 오프라인 결제 처리 장치.
  6. 청구항 1에 있어서,
    상기 1차 인증은
    해제조건부 인증에 상응하고, 상기 1차 인증이 해제되는 경우에 상기 2차 인증의 진행이 불가능한 것을 특징으로 하는 오프라인 결제 처리 장치.
  7. 청구항 6에 있어서,
    상기 1차 인증은
    상기 체크인 정보를 기반으로 획득한 상기 모바일 단말에 대한 모니터링 결과에 따라 조절된 1차 인증 레벨에 상응하게 수행되는 것을 특징으로 하는 오프라인 결제 처리 장치.
  8. 청구항 7에 있어서,
    상기 1차 인증부는
    상기 모니터링 결과가, 상기 체크인 정보를 획득한 후 상기 1차 인증이 수행되기 전까지 시간이 기설정된 기준 인증시간을 초과한 경우 및 상기 매장에서 발생한 모바일 부정결제 횟수가 기설정된 기준 횟수를 초과한 경우 중 적어도 하나에 상응하는 경우에 상기 1차 인증 레벨이 향상되도록 조절하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  9. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 수집부;
    1차 인증 정보를 입력하여 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 수행하는 1차 인증 수행부;
    상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적인 2차 인증을 위해서 터치궤적에 의한 크로스 포인트 기반의 2차 인증을 수행하는 2차 인증 수행부; 및
    상기 매장에서의 오프라인 결제를 수행하기 위해 상기 2차 인증에 상응하는 정보를 서버로 전송하고, 상기 오프라인 결제의 결과를 수신하는 결제 수행부
    를 포함하는 것을 특징으로 하는 모바일 단말.
  10. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 단계;
    상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치궤적의 크로스 포인트에 기반하여 수행되는 2차 인증을 수행하는 단계; 및
    상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 방법.
  11. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 1차 인증부;
    상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행하는 2차 인증부; 및
    상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  12. 청구항 11에 있어서,
    상기 2차 인증부는
    상기 사용자가 사전에 등록한 등록 터치 패턴과 상기 터치 패턴을 비교하여 일치하는지 여부에 따라 상기 2차 인증을 수행하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  13. 청구항 12에 있어서,
    상기 2차 인증은
    상기 구매에 상응하는 상품이 상기 POS에 제출되기 전까지 상기 모바일 단말에 대한 모니터링 결과에 따라 조절되는 2차 인증 레벨에 상응하게 수행되는 것을 특징으로 하는 오프라인 결제 처리 장치.
  14. 청구항 13에 있어서,
    상기 2차 인증부는
    상기 2차 인증 레벨이 향상된 경우에 터치 길이, 스와이프 방향 및 스와이프 속도 중 적어도 하나의 조건을 더 고려하여 상기 2차 인증을 수행하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  15. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 1차 인증 정보를 수신하는 단계;
    상기 1차 인증이 유효한 경우에, 상기 1차 인증에 종속적이고 POS의 사인패드에 입력된 터치 패턴에 기반하여 수행되는 2차 인증을 수행하는 단계; 및
    상기 2차 인증의 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 방법.
  16. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 체크인 정보 획득부;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 상기 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신하는 1차 인증부;
    상기 1차 인증의 유효 여부를 검토하고, 상기 1차 인증이 유효한 경우에 상기 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 상기 모바일 단말 및 상기 매장에 상응하는 POS 중 적어도 하나로 전송하는 2차 인증부; 및
    상기 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 결제 처리부
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  17. 청구항 16에 있어서,
    상기 스와이프 동작 패턴은
    스와이프 방향, 스와이프 속도 및 스와이프 길이 중 어느 하나 이상을 고려하여 설정되는 것을 특징으로 하는 오프라인 결제 처리 장치.
  18. 청구항 17에 있어서,
    상기 1차 인증부는
    상기 모바일 단말에 설치된 어플리케이션을 통해 상기 사용자가 사전에 등록한 등록 패턴과 상기 스와이프 동작 패턴을 비교하여 상기 1차 인증을 수행하는 것을 특징으로 하는 오프라인 결제 처리 장치.
  19. 청구항 18에 있어서,
    상기 등록 패턴은
    상기 1차 인증에 상응하는 1차 인증 레벨에 따라, 상기 등록 패턴의 전체 길이 및 상기 등록 패턴의 설정시 고려되는 요소의 개수 중 어느 하나 이상을 포함하는 기설정된 패턴 설정 범위 내에서 등록되는 것을 특징으로 하는 오프라인 결제 처리 장치.
  20. 사용자가 진입한 매장에 상응하는 체크인 정보를 획득하는 단계;
    모바일 단말로부터 상기 매장에 상응하는 구매에 대한 선승인에 해당하는 1차 인증을 위한 것으로, 상기 모바일 단말에 대한 스와이프 동작 패턴에 상응하여 생성된 1차 인증 정보를 수신하는 단계;
    상기 1차 인증의 유효 여부를 검토하고, 상기 1차 인증이 유효한 경우에 상기 1차 인증에 종속적인 2차 인증을 위한 2차 인증 정보를 생성하여 상기 모바일 단말 및 상기 매장에 상응하는 POS 중 적어도 하나로 전송하는 단계; 및
    상기 2차 인증 정보를 이용한 2차 인증 결과에 기반하여 상기 매장에서의 오프라인 결제를 수행하는 단계
    를 포함하는 것을 특징으로 하는 오프라인 결제 처리 방법.
PCT/KR2016/006315 2015-09-22 2016-06-14 오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치 Ceased WO2017052035A1 (ko)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
KR10-2015-0133763 2015-09-22
KR1020150133763A KR102505974B1 (ko) 2015-09-22 2015-09-22 2채널 인증을 이용한 오프라인 결제 처리 시스템, 스와이프 패턴을 이용한 1차 인증 기반의 2채널 인증을 이용한 오프라인 결제 처리 방법 및 이를 이용한 장치
KR10-2015-0148084 2015-10-23
KR1020150148084A KR102505975B1 (ko) 2015-10-23 2015-10-23 오프라인 결제 처리 시스템, 터치 패턴을 이용한 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치
KR10-2015-0148087 2015-10-23
KR1020150148087A KR102505976B1 (ko) 2015-10-23 2015-10-23 오프라인 결제 처리 시스템, 터치궤적의 크로스 포인트를 이용한 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치

Publications (1)

Publication Number Publication Date
WO2017052035A1 true WO2017052035A1 (ko) 2017-03-30

Family

ID=58386196

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2016/006315 Ceased WO2017052035A1 (ko) 2015-09-22 2016-06-14 오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치

Country Status (1)

Country Link
WO (1) WO2017052035A1 (ko)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112950219A (zh) * 2021-03-09 2021-06-11 支付宝(杭州)信息技术有限公司 支付处理方法和系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20130107497A (ko) * 2012-03-22 2013-10-02 유비벨록스(주) 터치 패턴을 이용한 사용자 인증 시스템 및 방법
KR20140110025A (ko) * 2012-01-30 2014-09-16 이베이 인크. 체크인 기반 지불 프로세스를 제공하기 위한 시스템 및 방법
KR20150049075A (ko) * 2013-10-29 2015-05-08 포항공과대학교 산학협력단 사용자 인증 방법 및 이를 수행하는 장치
KR20150052886A (ko) * 2013-11-05 2015-05-15 주식회사 투게더 무선 통신 장치의 방문 데이터를 기록하기 위한 데이터 전송 장치
JP2015519620A (ja) * 2012-01-16 2015-07-09 クアルコム,インコーポレイテッド ポータブルコンピューティングデバイスを用いた製品およびサービスの個人化された買い物体験および個人化された価格設定を提供するためのシステムおよび方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2015519620A (ja) * 2012-01-16 2015-07-09 クアルコム,インコーポレイテッド ポータブルコンピューティングデバイスを用いた製品およびサービスの個人化された買い物体験および個人化された価格設定を提供するためのシステムおよび方法
KR20140110025A (ko) * 2012-01-30 2014-09-16 이베이 인크. 체크인 기반 지불 프로세스를 제공하기 위한 시스템 및 방법
KR20130107497A (ko) * 2012-03-22 2013-10-02 유비벨록스(주) 터치 패턴을 이용한 사용자 인증 시스템 및 방법
KR20150049075A (ko) * 2013-10-29 2015-05-08 포항공과대학교 산학협력단 사용자 인증 방법 및 이를 수행하는 장치
KR20150052886A (ko) * 2013-11-05 2015-05-15 주식회사 투게더 무선 통신 장치의 방문 데이터를 기록하기 위한 데이터 전송 장치

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112950219A (zh) * 2021-03-09 2021-06-11 支付宝(杭州)信息技术有限公司 支付处理方法和系统
CN112950219B (zh) * 2021-03-09 2023-10-27 支付宝(中国)网络技术有限公司 支付处理方法和系统

Similar Documents

Publication Publication Date Title
WO2017111271A1 (en) Mobile device and operating method hereof
WO2016032231A1 (en) Method for managing beacon, terminal device, server and storage medium
WO2016129863A1 (en) Payment processing method and electronic device supporting the same
WO2021071012A1 (ko) 무매체 신원 확인을 통한 상품 구매 서비스 제공 장치 및 방법
WO2013187680A1 (ko) 사용자 단말 장치, 서버 장치 및 이들을 포함하는 시스템과 그 광고 서비스 방법
WO2017039354A1 (ko) 결제 거래를 수행하는 방법 및 장치
WO2017030220A1 (ko) 워치 타입의 이동 단말기 및 그 제어 방법
WO2016143962A1 (en) Terminal and operating method thereof
WO2017018622A1 (en) Mobile terminal and method for controlling the same
WO2019132555A1 (ko) 이모지가 포함된 메시지를 송수신하는 전자 장치 및 그 전자 장치를 제어하는 방법
WO2020189977A1 (ko) 동적 지오펜싱을 위한 전자 장치 및 방법
WO2018101625A1 (en) Method for providing point of interest information and electronic device supporting the same
WO2016093444A1 (ko) 시간을 단위로 하는 판촉 포인트의 유통 방법
WO2023106759A1 (ko) Qr코드 스캔·셀픽형 웹중개제어로 이루어진 하이브리드식 사진인화키오스크형 오프라인 이지 결제장치 및 방법
WO2018088704A1 (ko) 자동 결제를 위한 주차 관리 시스템, 그 방법 및 컴퓨터 프로그램이 기록된 비휘발성 기록매체
WO2017119578A1 (en) Method for providing services and electronic device thereof
WO2014171572A1 (ko) 쇼핑정보 제공방법 및 사용자 인터페이스
WO2017057832A1 (ko) 사용자 장치, 비콘, 서비스 제공 장치, 그를 포함하는 결제 시스템, 그의 제어 방법 및 컴퓨터 프로그램이 기록된 기록매체
WO2016137300A1 (en) Electronic device providing electronic payment function and operation method thereof
WO2015163553A1 (ko) 근거리 무선 데이터 통신을 이용한 위치 기반 서비스 장치, 방법 및 시스템
WO2016182308A1 (ko) 블루투스 통신을 이용한 비접촉식 모바일 결제 디바이스, 상기 모바일 결제 디바이스의 결제데이터 처리방법, 블루투스 통신을 이용한 비접촉식 모바일 결제 디바이스를 포함하는 모바일 결제 시스템, 및 상기 프로그램이 기록된 기록매체
WO2017052035A1 (ko) 오프라인 결제 처리 시스템, 2차 인증 기반의 오프라인 결제 처리 방법 및 이를 이용한 장치
WO2016072573A1 (ko) 시간을 단위로 하는 판촉 포인트의 유통 방법 및 유통 관리 시스템
WO2019103341A1 (ko) 콘텐트를 제공하기 위한 방법 및 이를 지원하는 전자 장치
WO2017052034A1 (ko) 2채널 인증을 이용한 오프라인 결제 처리 시스템, 2채널 인증을 이용한 오프라인 결제 처리 방법 및 이를 이용한 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16848761

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16848761

Country of ref document: EP

Kind code of ref document: A1