WO2017063545A1 - 与交易数据有关的身份信息输入方法及系统 - Google Patents
与交易数据有关的身份信息输入方法及系统 Download PDFInfo
- Publication number
- WO2017063545A1 WO2017063545A1 PCT/CN2016/101779 CN2016101779W WO2017063545A1 WO 2017063545 A1 WO2017063545 A1 WO 2017063545A1 CN 2016101779 W CN2016101779 W CN 2016101779W WO 2017063545 A1 WO2017063545 A1 WO 2017063545A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- identity information
- input
- information
- transaction
- terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3823—Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
Definitions
- the present invention relates to data encryption techniques and, more particularly, to a method of generating a password associated with transaction data.
- the present invention provides a method for inputting identity information related to transaction data, which is applied in an application environment including a terminal and a transaction server communicably connected to the terminal, wherein the transaction server performs a transaction request from the terminal.
- Processing to complete transaction processing by interaction with the terminal the method comprising: presenting an identity information input option at a user interface of the terminal during user identity information input, and transmitting to the user indicating the user
- the method inputs the input mode information of the identity information, and the input mode information is randomly generated; and when the user inputs the identity information by using the identity input option according to the input mode information, the identity information is transmitted to the transaction server.
- the input mode information is in the form of a picture.
- the input mode information is sent to the mobile terminal of the user by using a short message.
- the input mode information is sent to the mobile terminal of the user by using a short message in the form of a picture.
- the input mode information includes a random number and an information bit for inputting the identity information.
- the information bits are surrounded by the random number as a whole or the information bits are separated into segments by the random number.
- the identity information is transmitted to the transaction server via the network.
- the input mode information is generated by the transaction server.
- the identity information is any one of a name, a password, an identity card number, a combination of any two, or a combination of the three.
- an identity information input system related to transaction data, which is disposed in an application environment including a terminal and a transaction server communicably connected to the terminal, the transaction server Processing a transaction request from a terminal to complete transaction processing by interaction with the terminal, the system comprising: an input mode generation module configured to randomly generate an input for indicating how the user enters identity information in what manner Mode information; a first output module configured to output an identity information input option at a user interface of the terminal during user identity information input; and a second output module configured to output an identity input option when the first output module outputs Transmitting the input mode information to the user; and transmitting a module for transmitting identity information input by the user to the transaction server.
- an input mode generation module configured to randomly generate an input for indicating how the user enters identity information in what manner Mode information
- a first output module configured to output an identity information input option at a user interface of the terminal during user identity information input
- a second output module configured to output an identity input option when the first output module outputs Transmitting the input mode information to the user
- the second output module is disposed at the transaction server.
- the input mode generating module is further configured to generate the input mode information including a random number and an information bit for inputting the identity information.
- the input mode generating module is further configured to generate the input mode information as a picture.
- the input mode generating module is further configured to generate the input mode information including a random number and an information bit for inputting the identity information.
- the identity information bits are surrounded by the random number as a whole.
- an identity information input system associated with transaction data optionally, the identity information bits are separated into segments by the random number.
- An identity information input system related to transaction data optionally, the transmitting module is configured to transmit the identity information to the transaction service via a network if the user inputs the identity information according to the input mode information end.
- a transaction system comprising an identity information input system related to transaction data as described above.
- the security of the transmission of identity information can be improved by performing the methods of the examples of the invention or employing the systems of the examples of the invention.
- FIG. 1 is a flow chart of a method of inputting identity information related to transaction data in accordance with one example of the present invention.
- FIG. 3 is still another example of input mode information according to an example of the present invention.
- FIG. 4 is a block diagram showing an identity information input system related to transaction data in accordance with one example of the present invention.
- An identity information input method related to transaction data is applied to an application environment including a terminal and a transaction server communicably connected to the terminal, the transaction server processing a transaction request from the terminal Transaction processing is completed through interaction with the terminal.
- the terminal in the application environment may be any one of a desktop computer, a notebook computer, a tablet such as an iPad, and an electronic device such as a smart phone;
- the transaction server may be one or more servers, as the case may be. set.
- the terminal and the server may be connected through a network, such as the Internet.
- step 100 during the input of the user identity information, the identity information input option is presented on the user interface of the terminal, and the input mode information for indicating how the user inputs the identity information is transmitted to the user.
- the input mode information is randomly generated.
- step 102 in the case where the user inputs the identity information through the identity input option according to the input mode information, the identity information is transmitted to the transaction server, whereby the identity information input process operation is completed.
- the user is required to input identity information, regardless of which terminal the user is using, and the user interface of the terminal displays an option to require the user to input identity information.
- the input mode information is also transmitted to the user to inform the manner in which the identity information is input.
- the input mode information may be generated by a transaction server in the application environment and sent to the terminal for use by the user through the network. Alternatively, it can also be sent to the user's mobile phone terminal via SMS for the user to use.
- the terminal for inputting identity information may be a mobile phone terminal, or may be other terminals as mentioned above.
- the input mode information may be generated by a terminal in the application environment.
- the terminal will directly present the input mode information to the user without passing through the network or the short message, and at the same time, the terminal can transmit the input mode information to the transaction server, so that the transaction server receives the user compliance input mode.
- the input mode information may be generated as a picture, or the input mode information may be generated as a picture carrying an input manner indicating how the user inputs the identity information.
- the picture can be generated by the transaction server, delivered to the terminal via the network or delivered to the user's mobile terminal via SMS for the user to use.
- the picture may be generated by the terminal itself and presented to the user for viewing and inputting identity information accordingly.
- the input mode information includes a random number and an information bit for inputting identity information, wherein the information bit is surrounded by the random number.
- the information bits are located as a whole in a random number, or a random number divides the information bits into segments.
- a random number can be a number, a letter, or a combination of numbers and letters.
- the identity information may be various types of identity or information related to the identity, such as a name, an identity card number, a password, or the like, or may be any combination of one or several of the information.
- the identity information input method related to transaction data according to the present invention is specifically explained using a password as an example.
- the input mode information is generated as a picture, and the picture is, for example, the method shown in FIG. 2, that is, the password is input in the password box by first inputting the random number 1, inputting the password, and then inputting the random number 2.
- the picture is generated by the transaction server and transmitted over the communication network to the terminal communicatively coupled to the transaction server for the user to enter on the terminal.
- the random number 1 is a part of a random number, which may be a number or a plurality of numbers. For example, the random number 1 is 13, and the random number 2 is 562, then the entire random number is 13562.
- the user enters the password by entering 13 first, then entering the password, and then entering 562.
- the random number may also be referred to as a check code, and a randomly generated check code.
- the difference between the second example and the first example is that the random number divides the password bit into several ends.
- the input mode information is generated as a picture, and the picture is, for example, the method shown in FIG. 3, that is, the password is input in the password box by first inputting the random number 1, the first three digits of the password, the random number 2, and the last three digits of the password.
- the random number 1 is a part of a random number, which may be a number or a plurality of numbers. For example, if the random number 1 is 54 and the random number 2 is 34, the user should enter the password by entering 54 first, then entering the first three digits of the password, then entering 34, and finally entering the password three digits.
- the random number can be split into multiple parts, each part can be one bit or multiple bits; accordingly, the password can be separated by multiple pieces of the random number after the split.
- the input mode information is generated in the same manner as in the first example and the second example, except that the generated input mode information is transmitted to the user's mobile phone terminal through the short message, that is, the input mode information is transmitted differently than the transaction data (for example, It is transmitted through the network transmission).
- the password is transmitted to the transaction server via the network.
- the examples enumerated herein relate to input mode information for generating identity information, so that the user knows the input mode information, and transmits the input identity information to the transaction server according to the user input identity information. It should be noted that after the user inputs the identity information according to the input mode information of the identity information, the identity information input by the user is packaged together with the random number provided in the application (which may include encryption and/or compression). Transfer to the transaction server. However, the information transmission process after packaging and packaging is consistent with the information transmission process after the input and subsequent packaging of the identity information, and thus the present invention will not be described.
- the identity information data is illegally intercepted, and the interceptor cannot know the real reason due to the random number.
- an identity information input system related to transaction data is further provided, which is disposed in an application environment including a terminal and a transaction server communicably connected to the terminal, the transaction server terminal from the terminal The transaction request is processed to complete the transaction processing through interaction with the terminal.
- FIG. 4 is a block diagram showing an identity information input system related to transaction data in accordance with one example of the present invention. As shown, the system includes an input mode generation module 20, a first output module 22, a second output module 24, and a transfer module 26.
- the input mode generation module 20 is configured to randomly generate input mode information for indicating how the user inputs the identity information in a manner.
- the first output module 22 is configured to output an identity information input option at a user interface of the terminal during user identity information input.
- the second output module 24 is configured to transmit the input mode information to the user when the first output module outputs the identity information input option.
- the transmitting module 26 is configured to transmit the input information to the transaction server after the user inputs the identity information according to the requirement of the input mode information.
- the input mode generating module 20 may be disposed in a transaction server in the application environment, and the randomly generated input mode information may be sent to the terminal through the network for use by the user. Alternatively, it can also be sent to the user's mobile terminal via SMS for the user to use.
- the terminal for inputting identity information may be a mobile phone terminal, or may be other terminals as mentioned above.
- the input mode generating module 20 may be disposed in a terminal in the application environment.
- the input mode information randomly generated by the input mode generating module 20 can be directly presented to the user through the terminal without being transmitted through a network or a short message.
- the input mode information generated by the input mode generating module 20 can be transmitted by the terminal to the transaction server.
- the input mode generating module 20 is configured to generate the input mode information as a picture, or the input mode information is generated as a picture carrying an input manner indicating how the user inputs the identity information.
- input mode generation module 20 generates input mode information including random numbers and information bits for inputting identity information, and according to an example of the present invention, the information bits are surrounded by random numbers.
- the information bits are located as a whole in a random number, or a random number divides the information bits into segments.
- a random number can be a number, a letter, or a combination of numbers and letters.
- an input mode generation module 20 is disposed on the transaction server, the first output module 22 is disposed in the terminal used by the user, the second output module 24 is disposed on the transaction server, and the transmission module 26 is disposed in the terminal used by the user.
- the input mode generating module 20 generates input mode information when the identity information of the transaction data is to be input, and the input mode information is transmitted by the second output module 24 to the terminal used by the user through the network, and the input mode information is presented by the terminal.
- the user in the identity input option of the input interface, enters the identity information according to the indication of the input mode information, and the transmitting module 26 transmits the identity information input by the user to the transaction server, and performs identity authentication and the like. deal with.
- the terminal is set to be responsible only for displaying it to the client without further processing.
- the input mode generating module 20 generates the input mode information and generates it as a picture, for example, the mode shown in FIG. 2, that is, the random number 1 is input first in the password box, and then input. Enter the password by entering the random number 2.
- the random number 1 is a part of a random number, which may be a number or a plurality of numbers. For example, the random number 1 is 13, and the random number 2 is 562, then the entire random number is 13562. The user should enter the password by entering 13 first, then entering the password, and then entering 562.
- the input mode generating module 20 generates the input mode information and generates it as a picture, for example, the mode shown in FIG. 3, that is, the random number 1 and the password are entered first in the password box. Enter the password in the first three digits, the random number 2, and the last three digits of the last password.
- the random number 1 is a part of a random number, which may be a number or a plurality of numbers. For example, if the random number 1 is 54 and the random number 2 is 34, the user should enter the password by entering 54 first, then entering the first three digits of the password, then entering 34, and finally entering the password three digits.
- the present invention also provides a transaction system that performs the identity information input method related to transaction data as described above. And, a transaction system including an identity information input system related to transaction data as described above is provided.
- the generation of the random number can be generated by generating a verification code.
- An identity information input method or system related to transaction data which combines identity information (such as a password) with a random number (authentication code), and the user inputs the identity information input phase Combine together. Since the random number is introduced, even if the input identity information is intercepted by the malicious program on the terminal side and the transaction server (or the message side), or the transmission, the interceptor cannot parse the true identity information, thereby ensuring the security of the transaction data. transmission.
- the transmission of the transaction data and the password is two channels, thereby further improving the ability to resist malicious attacks, and the transmission of the identity information and the password thereof is further improved. Safety.
- the identity information input method related to transaction data may be implemented as software, and portions implementing different functions may be separately disposed in different components of the application environment.
- the software portion for generating the input mode information can be implemented on the transaction server side, and during the user identity information input, the user input interface presenting the identity input option can be implemented in the terminal used by the user.
- input mode information is generated as a picture and transmitted as a picture, which further ensures the security of data transmission.
- identity information input system related to transaction data may be implemented in the form of a software module, or may be implemented in hardware, or implemented in a combination of software and hardware.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Accounting & Taxation (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Strategic Management (AREA)
- Finance (AREA)
- General Business, Economics & Management (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
一种与交易数据有关的身份信息输入方法,其应用在包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理,所述方法包括:将身份输入选项呈现在该终端的用户界面上,并向用户传送输入方式信息(100);在用户按照输入方式信息输入身份信息的情况下,传送所述身份信息到交易服务端(102)。还提供相应的系统。采用该方案,可改善交易数据的安全性。
Description
本发明涉及数据加密技术,更为具体地,涉及生成与交易数据有关的密码的方法。
当前,互联网交易已很普及,并且近几年来互联网金融也受到广泛欢迎。在现今基于互连网的支付以及金融业务中,用户(例如持卡人)一般都是通过终端设备输入密码,经过互联网通道送到后台进行验证。在此过程中,虽然有各种基于软件、硬件方式的密码加密保护策略,但依然存在报文信息被恶意截获,并被破解导致密码泄露等风险隐患。
发明内容
本发明提供一种与交易数据有关的身份信息输入方法,其应用在包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理,所述方法包括:在用户身份信息输入期间,在所述终端的用户界面呈现出身份信息输入选项,并且向用户传送用于指示用户以怎样的方式输入身份信息的输入方式信息,所述输入方式信息随机生成;在用户按照输入方式信息通过所述身份输入选项输入身份信息的情况下,将所述身份信息传送到所述交易服务端。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述输入方式信息为图片形式。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述输入方式信息通过短信发送到用户的手机终端。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述输入方式信息被以图片的形式通过短信发送到用户的手机终端。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述输入方式信息包含随机数与用于输入身份信息的信息位。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述信息位作为整体被所述随机数包围或所述信息位被所述随机数分隔成若干段。
根据本发明的与交易数据有关的身份信息输入方法,可选地,在用户按照输入方式信息输入身份信息的情况下,将所述身份信息通过网络传送到所述交易服务端。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述输入方式信息由所述交易服务端生成。
根据本发明的与交易数据有关的身份信息输入方法,可选地,所述身份信息为姓名、密码、身份证号码中的任意一项、任意两项的组合、或该三者的组合。
根据本发明的另一方面,还提供一种与交易数据有关的身份信息输入系统,其设置在包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理,所述系统包括:输入方式生成模块,其设置成用于随机生成用于指示用户以怎样的方式输入身份信息的输入方式信息;第一输出模块,其设置成在用户身份信息输入期间,在所述终端的用户界面输出身份信息输入选项;第二输出模块,其设置成在第一输出模块输出身份输入选项时,将所述输入方式信息传递给所述用户;传送模块,其用于将用户输入的身份信息传送到所述交易服务端。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述第二输出模块设置在所述交易服务端。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述输入方式生成模块被进一步设置成生成包含随机数与用于输入身份信息的信息位的所述输入方式信息。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述输入方式生成模块被进一步设置成将输入方式信息生成为图片。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述输入方式生成模块被进一步设置成生成包含随机数与用于输入身份信息的信息位的所述输入方式信息。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述身份信息位作为整体被所述随机数包围。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述身份信息位被所述随机数分隔成若干段。
根据本发明的与交易数据有关的身份信息输入系统,可选地,所述传送模块设置成在用户按照输入方式信息输入身份信息的情况下,将所述身份信息通过网络传送到所述交易服务端。
还提供一种交易系统,其执行如上所述的与交易数据有关的身份信息输入方法。
还另外提供一种交易系统,其包括如上所述的与交易数据有关的身份信息输入系统。
执行本发明示例的方法或采用本发明示例的系统,可改善身份信息的传输的安全性。
图1是根据本发明的一个示例的与交易数据有关的身份信息输入方法的流程图。
图2是根据本发明示例的输入方式信息的一种示例。
图3是根据本发明示例的输入方式信息的又一种示例。
图4示意了根据本发明的一个示例的与交易数据有关的身份信息输入系统的结构图。
现在参照附图描述本发明的示意性示例,相同的附图标号表示相同的元件。下文描述的各实施例有助于本领域技术人员透彻理解本发明,且意在示例而非限制。除非另有限定,文中使用的术语(包括科学、技术和行业术语)具有与本发明所属领域的技术人员普遍理解的含义相同的含义。另外,下文多个示例可以相互参照或相互结合。
根据本发明示例的与交易数据有关的身份信息输入方法,其应用在包括终端以及与该终端以可通信方式连接的交易服务端的应用环境中,该交易服务端对来自终端的交易请求进行处理从而通过与该终端的交互完成交易处理。在此,该应用环境中的终端可以是台式电脑、笔记本电脑、如ipad的平板、以及智能手机等电子产品中的任何一种;该交易服务端可以是一个或多个服务器,视具体情况而定。其中,终端与服务器可以通过网络连接,该网络例如为因特网。
图1是根据本发明的一个示例的与交易数据有关的身份信息输入方法的流程图。如图所示,在步骤100,在用户身份信息输入期间,将身份信息输入选项呈现在该终端的用户界面上,并向用户传送用于指示用户以怎样的方式输入身份信息的输入方式信息,该输入方式信息随机生成。在步骤102,在用户按照输入方式信息通过所述身份输入选项输入身份信息的情况下,将所述身份信息传送到所述交易服务端,由此,身份信息输入过程操作完成。
交易过程中,需要用户输入身份信息,无论用户使用的是哪一种终端,在该终端的用户界面显示出要求用户输入身份信息的选项。根据本发明,在通过用户界面要求用户输入身份信息的时候,也向用户传送输入方式信息,以告知用于以何种方式输入身份信息。
根据本发明的示例,该输入方式信息可以由所述应用环境中的交易服务端生成,通过网络发送到终端供用户使用。可替代地,也可通过短信发送到用户的手机终端供用户使用。本领域技术人员可以理解到,在本发明的所有示例中,用于输入身份信息的终端可以是手机终端,也可以是如上文提到的其它终端。
根据本发明的又一示例,该输入方式信息可以由所述应用环境中的终端自行生成。在该示例下,终端将直接呈现该输入方式信息给用户,而无需通过网络或短信传递,同时,终端可将该输入方式信息传送给交易服务端,以便交易服务端在接收到用户遵照输入方式信息
输入的身份信息后,可正确解读身份信息。
根据本发明的又一示例,该输入方式信息可以生成为图片,或者说,该输入方式信息生成为承载了指示用户如何输入身份信息的输入方式的图片。该图片可由交易服务端生成,通过网络传递到终端或通过短信传递到用户的手机终端以供用户使用。可替代地,该图片可以由终端自行生成,并将该图片呈现给用户以便查看并据其输入身份信息。
根据本发明的又一示例,输入方式信息包含随机数及用于输入身份信息的信息位,其中,该信息位被所述随机数包围。作为示例,例如,信息位作为整体位于随机数中,或随机数将信息位分成若干段。随机数可以是数字、字母、或数字与字母的组合。
根据本明的示例,该身份信息可以是姓名、身份证号码、密码等各类表征身份或与表征身份有关的信息,也可以是这些信息中任意一个、或若干个的相互结合。
在以下各示例中,以密码作为示例来具体说明根据本发明所述的与交易数据有关的身份信息输入方法。
示例一:
输入方式信息生成为图片,该图片例如为图2所示的方式,即在密码框中按照先输入随机数1,再输入密码,然后输入随机数2的方式来输入密码。
该图片由交易服务端生成并通过通信网络传送到与该交易服务端通信连接的终端,以便用户据其在终端上输入。
随机数1是随机数的一部分,其可以是一个数字,也可以是多个数字。例如,随机数1为13,随机数2为562,则整个随机数是13562。用户按照先输入13,再输入密码,然后输入562的方式输入密码。
在各示例中,也可将随机数称为校验码,以及随机生成的校验码。
示例二:
示例二与示例一的区别在于随机数将密码位分成若干端。
输入方式信息生成为图片,该图片例如为图3所示的方式,即在密码框中按照先输入随机数1、密码前三位、随机数2、密码后三位的方式来输入密码。
随机数1是随机数的一部分,其可以是一个数字,也可以是多个数字。例如,随机数1是54,随机数2是34,则用户应该按照先输入54,再输入密码前三位,然后输入34的方式,最后输入密码后三位的方式输入密码。
示例二中,随机数可以被拆分为多个部分,每个部分可以是一位,也可以是多位;相应地,密码可以被拆分后的多个随机数部分分隔开。
示例三:
该例中,输入方式信息的生成与示例一与示例二相同,不同在于,生成的输入方式信息通过短信传送到了用户的手机终端,也就是说,输入方式信息是以不同于交易数据传输(例如其通过网络传输)的途径传输的。在用户按照输入方式信息指示的方式输入密码后,该密码即通过网络传送给了交易服务端。
因此不再赘述示例三。
本文所列举的各示例,涉及到生成身份信息的输入方式信息,使用户获知该输入方式信息,并在用户据其输入身份信息的情况下将输入后的身份信息传输该交易服务端。要说明的是,在用户据身份信息的输入方式信息,输入了身份信息之后,用户输入的身份信息连同本申请中提供的随机数一起会被打包(其中可能包括加密和/或压缩等过程)传输给交易服务端。但打包及打包后的信息传输过程与目前在用的身份信息输入后的打包及打包后的信息传输过程一致,因此本发明不再描述。
按照本发明,在用户按照输入方式信息输入身份信息后,即使在后期将身份信息传输给交易服务端的过程中,该身份信息数据被非法截获,因随机数的原因,截获者也无法获知真实的身份信息。
根据本发明的示例,还提供与交易数据有关的身份信息输入系统,其设置在包括终端及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理。
图4示意了根据本发明的一个示例的与交易数据有关的身份信息输入系统的结构图。如图所示,该系统包括输入方式生成模块20,第一输出模块22,第二输出模块24,以及传送模块26。
输入方式生成模块20设置成用于随机生成用于指示用户以怎样的方式输入身份信息的输入方式信息。第一输出模块22,其设置成在用户身份信息输入期间,在所述终端的用户界面输出身份信息输入选项。第二输出模块24,其设置成在第一输出模块输出身份信息输入选项时,将所述输入方式信息传递给所述用户。传送模块26,其用于在用户按照所述输入方式信息的要求输入身份信息后,将输入的信息传送到所述交易服务端。
根据本发明的一个示例,输入方式生成模块20可以设置在所述应用环境中的交易服务端,其随机生成的输入方式信息可通过网络发送给终端,以供用户使用。可替代地,也可通过短信发送到用户手机终端,供用户使用。本领域技术人员可以理解到,在本发明的所有示例中,用于输入身份信息的终端可以是手机终端,也可以是如上文提到的其它终端。
根据本发明的又一示例,输入方式生成模块20可以设置在所述应用环境中的终端中。在该示例下,输入方式生成模块20随机生成的输入方式信息可直接通过终端呈现给用户,而无需通过网络或短信传递。在这种情况下,输入方式生成模块20生成的输入方式信息可由终端传输给交易服务端。
根据本发明的又一示例,输入方式生成模块20被设置成将该输入方式信息生成为图片,或者说,该输入方式信息生成为承载了指示用户如何输入身份信息的输入方式的图片。
根据本发明的又一示例,输入方式生成模块20生成包含随机数与信息位的输入方式信息,该信息位用于输入身份信息,且根据本发明的示例,该信息位由随机数包围。例如,信息位作为整体位于随机数中,或随机数将信息位分成了若干段。随机数可以是数字、字母、或数字与字母的组合。
在将根据本发明示例的与交易数据有关的身份信息输入系统应用到包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中时,可按照如下方式设置:将输入方式生成模块20设置在交易服务端,第一输出模块22设置在用户使用的终端中,第二输出模块24设置在交易服务端,及传送模块26设置在用户使用的终端中。输入方式生成模块20在要输入交易数据的身份信息时,生成输入方式信息,并由第二输出模块24将该输入方式信息通过网络传送给用户使用的终端,由该终端将该输入方式信息呈现给用户,进而用户在输入界面的身份输入选项中按照该输入方式信息的指示输入身份信息,而传送模块26将用户输入的身份信息传送到所述交易服务端,由其进行身份认证等一系列处理。此外,根据本发明的一个示例,无论输入方式信息是图片还是非图片的形式,终端都设置成只负责将其显示给客户而无需做更多处理。
结合到如上所示的示例一中,则输入方式生成模块20生成输入方式信息且将其生成为图片,例如为图2所示的方式,即在密码框中按照先输入随机数1,再输入密码,然后输入随机数2的方式来输入密码。随机数1是随机数的一部分,其可以是一个数字,也可以是多个数字。例如,随机数1为13,随机数2为562,则整个随机数是13562。用户应该按照先输入13,再输入密码,然后输入562的方式输入密码。
结合到如上所示的示例二中,输入方式生成模块20生成输入方式信息且将其生成为图片,该图片例如为图3所示的方式,即在密码框中按照先输入随机数1、密码前三位、随机数2、最后密码后三位的方式来输入密码。随机数1是随机数的一部分,其可以是一个数字,也可以是多个数字。例如,随机数1是54,随机数2是34,则用户应该按照先输入54,再输入密码前三位,然后输入34的方式,最后输入密码后三位的方式输入密码。
可以类似的方式结合到如上所示的示例三中。
本发明还提供执行如上所述的与交易数据有关的身份信息输入方法的交易系统。以及,提供包括如上所述的与交易数据有关的身份信息输入系统的交易系统。
在本发明的以上各示例中,随机数的生成可以通过产生验证码的方式产生。
根据本发明的示例所提供的与交易数据有关的身份信息输入方法或系统,其采用将身份信息(如密码)与随机数(验证码)相结合,且在用户输入身份信息输入阶段即将该两者结合在一起。由于引入了随机数,终端侧和交易服务端(或报文侧)、或传输中即使输入的身份信息被恶意程序截获,截获者也无法解析出真正的身份信息,从而保证了交易数据的安全传输。
进一步,在通过短信发送输入方式信息的情况下,则相当于交易数据与密码的传输是两个通道,由此,更进一步提高了对抗恶意攻击的能力,使得身份信息及其密码的传输更为安全。
根据本发明示例的与交易数据有关的身份信息输入方法可实现为软件,实现不同功能的部分可分别设置在所述应用环境的不同部件中。例如用于生成输入方式信息的软件部分可实现在交易服务端,而在用户身份信息输入期间,在所述终端的用户界面呈现出身份输入选项可实现在用户使用的终端中等。此外,输入方式信息被生成为图片且以图片传输,这都更进一步保证了数据传输的安全性。
同样地,根据本发明示例的与交易数据有关的身份信息输入系统可以软件模块的形式实现,也可以硬件实现,或以软件与硬件相结合的方式实现。
Claims (15)
- 一种与交易数据有关的身份信息输入方法,其应用在包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理,所述方法包括:在用户身份信息输入期间,在所述终端的用户界面呈现出身份信息输入选项,并且向用户传送用于指示用户以怎样的方式输入身份信息的输入方式信息,所述输入方式信息随机生成;在用户按照输入方式信息通过所述身份输入选项输入身份信息的情况下,将所述身份信息传送到所述交易服务端。
- 如权利要求1所述的与交易数据有关的身份信息输入方法,所述输入方式信息由所述交易服务端生成。
- 如权利要求1所述的与交易数据有关的身份信息输入方法,其特征在于,所述输入方式信息包含随机数与用于输入身份信息的信息位。
- 如权利要求3所述的与交易数据有关的身份信息输入方法,其特征在于,所述信息位作为整体被所述随机数包围或所述信息位被所述随机数分隔成若干段。
- 如权利要求1所述的与交易数据有关的身份信息输入方法,其特征在于,所述身份信息为姓名、密码、身份证号码中的任意一项、任意两项的组合、或该三者的组合。
- 如权利要求1所述的与交易数据有关的身份信息输入方法,其特征在于,所述输入方式信息为图片形式。
- 如权利要求2到6中任意一项所述的与交易数据有关的身份信息输入方法,其特征在于,所述输入方式信息通过短信发送到用户的手机终端。
- 一种与交易数据有关的身份信息输入系统,其设置在包括终端以及与所述终端以可通信方式连接的交易服务端的应用环境中,所述交易服务端对来自终端的交易请求进行处理从而通过与所述终端的交互完成交易处理,所述系统包括:输入方式生成模块,其设置成用于随机生成用于指示用户以怎样的方式输入身份信息的输入方式信息;第一输出模块,其设置成在用户身份信息输入期间,在所述终端的用户界面输出身份信息输入选项;第二输出模块,其设置成在第一输出模块输出身份输入选项时,将所述输入方式信息传递给所述用户;传送模块,其用于将用户输入的身份信息传送到所述交易服务端。
- 如权利要求11所述的与交易数据有关的身份信息输入系统,其特征在于,所述第二输出模块设置在所述交易服务端。
- 如权利要求8所述的与交易数据有关的身份信息输入系统,其特征在于,所述输入方式生成模块被进一步设置成生成包含随机数与用于输入身份信息的信息位的所述输入方式信息。
- 如权利要求8所述的与交易数据有关的身份信息输入系统,其特征在于,所述输入方式生成模块被进一步设置成将输入方式信息生成为图片。
- 如权利要求8到11中任意一项所述的与交易数据有关的身份信息输入系统,其特征在于,所述第二输出模块设置成通过短信将所述用户信息发送到用户的手机终端。
- 如权利要求8所述的与交易数据有关的身份信息输入系统,其特征在于,所述传送模块设置成在用户按照输入方式信息输入身份信息的情况下,将所述身份信息通过网络传送到所述交易服务端。
- 一种交易系统,其执行如权利要求1到7中任意一项所述的与交易数据有关的身份信息输入方法。
- 一种交易系统,其包括如权利要求8到13中任意一项所述的与交易数据有关的身份信息输入系统。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510668565.1A CN105373921A (zh) | 2015-10-13 | 2015-10-13 | 与交易数据有关的身份信息输入方法及系统 |
| CN201510668565.1 | 2015-10-13 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017063545A1 true WO2017063545A1 (zh) | 2017-04-20 |
Family
ID=55376100
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/101779 Ceased WO2017063545A1 (zh) | 2015-10-13 | 2016-10-11 | 与交易数据有关的身份信息输入方法及系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105373921A (zh) |
| WO (1) | WO2017063545A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105373921A (zh) * | 2015-10-13 | 2016-03-02 | 中国银联股份有限公司 | 与交易数据有关的身份信息输入方法及系统 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050149739A1 (en) * | 2003-12-31 | 2005-07-07 | Hewlett-Packard Development Company, L.P. | PIN verification using cipher block chaining |
| CN101604366A (zh) * | 2009-07-13 | 2009-12-16 | 中山爱科数字科技有限公司 | 一种密码分割式动态验证方法和系统 |
| CN101639957A (zh) * | 2009-05-26 | 2010-02-03 | 深圳市安捷信联科技有限公司 | 一种实现圈存或圈提的方法、终端及银行业务系统 |
| CN105373921A (zh) * | 2015-10-13 | 2016-03-02 | 中国银联股份有限公司 | 与交易数据有关的身份信息输入方法及系统 |
-
2015
- 2015-10-13 CN CN201510668565.1A patent/CN105373921A/zh active Pending
-
2016
- 2016-10-11 WO PCT/CN2016/101779 patent/WO2017063545A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050149739A1 (en) * | 2003-12-31 | 2005-07-07 | Hewlett-Packard Development Company, L.P. | PIN verification using cipher block chaining |
| CN101639957A (zh) * | 2009-05-26 | 2010-02-03 | 深圳市安捷信联科技有限公司 | 一种实现圈存或圈提的方法、终端及银行业务系统 |
| CN101604366A (zh) * | 2009-07-13 | 2009-12-16 | 中山爱科数字科技有限公司 | 一种密码分割式动态验证方法和系统 |
| CN105373921A (zh) * | 2015-10-13 | 2016-03-02 | 中国银联股份有限公司 | 与交易数据有关的身份信息输入方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105373921A (zh) | 2016-03-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9838205B2 (en) | Network authentication method for secure electronic transactions | |
| US10389531B2 (en) | Authentication system and authentication method | |
| CN113014400B (zh) | 用户和移动装置的安全认证 | |
| CN112425118B (zh) | 公钥-私钥对账户登录和密钥管理器 | |
| CN103380592B (zh) | 用于个人认证的方法、服务器以及系统 | |
| CN117579281A (zh) | 用于使用区块链的所有权验证的方法和系统 | |
| US20150134531A1 (en) | Method, apparatus, and system for information transmission | |
| US20200196143A1 (en) | Public key-based service authentication method and system | |
| CN102946384B (zh) | 用户验证方法和设备 | |
| EP3937040A1 (en) | Systems and methods for securing login access | |
| CN113630412B (zh) | 资源下载方法、资源下载装置、电子设备以及存储介质 | |
| HK1213076A1 (zh) | 捕捉移動安全裝置、方法和系統 | |
| CN111161056A (zh) | 一种提高数字资产交易安全性的方法、系统及设备 | |
| US20180262471A1 (en) | Identity verification and authentication method and system | |
| EP3133791B1 (en) | Double authentication system for electronically signed documents | |
| CN121532764A (zh) | 用于增强登录移动应用的安全性的系统和方法 | |
| JP2016100007A (ja) | カード装置を用いたネットワーク認証方法 | |
| US20160300220A1 (en) | System and method for enabling a secure transaction between users | |
| KR101856530B1 (ko) | 사용자 인지 기반 암호화 프로토콜을 제공하는 암호화 시스템 및 이를 이용하는 온라인 결제 처리 방법, 보안 장치 및 거래 승인 서버 | |
| JP5120951B2 (ja) | 複数の端末を用いた改ざん命令実行防止技術 | |
| CN105678542B (zh) | 支付业务交互方法、支付终端和支付云端 | |
| KR20190050159A (ko) | 통신 구간 보안 상태 제공 방법 및 장치 | |
| US10845990B2 (en) | Method for executing of security keyboard, apparatus and system for executing the method | |
| WO2017063545A1 (zh) | 与交易数据有关的身份信息输入方法及系统 | |
| CN113032761B (zh) | 保护远程认证 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16854923 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16854923 Country of ref document: EP Kind code of ref document: A1 |