WO2017092202A1 - 交易方法及交易系统 - Google Patents

交易方法及交易系统 Download PDF

Info

Publication number
WO2017092202A1
WO2017092202A1 PCT/CN2016/077347 CN2016077347W WO2017092202A1 WO 2017092202 A1 WO2017092202 A1 WO 2017092202A1 CN 2016077347 W CN2016077347 W CN 2016077347W WO 2017092202 A1 WO2017092202 A1 WO 2017092202A1
Authority
WO
WIPO (PCT)
Prior art keywords
electronic device
transaction
key information
cloud server
token
Prior art date
Application number
PCT/CN2016/077347
Other languages
English (en)
French (fr)
Inventor
杨宗正
Original Assignee
英业达科技有限公司
英业达股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 英业达科技有限公司, 英业达股份有限公司 filed Critical 英业达科技有限公司
Priority to US15/552,296 priority Critical patent/US20180075451A1/en
Publication of WO2017092202A1 publication Critical patent/WO2017092202A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions
    • G06Q30/0601Electronic shopping [e-shopping]
    • G06Q30/0609Buyer or seller confidence or verification
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/305Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wired telephone networks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions

Definitions

  • the invention relates to a trading method and a trading system, in particular to a trading method and a trading system for improving transaction security.
  • the present invention discloses a transaction method, including a first electronic device transmitting a transaction request to a cloud server; the cloud server transmitting a key message to the first electronic device; and the first electronic device performing a message according to the key information Authenticating, generating a verification result; when the verification result is successful, the cloud server transmits a transaction voucher token (Token) to the first electronic device, the transaction voucher token includes an expiration date; and the expiration date
  • the first electronic device is allowed to perform a trading action.
  • the invention further discloses a transaction system, comprising a cloud server, comprising a key generation module for generating a key information; and a transaction voucher token generator for generating a transaction voucher token, the transaction voucher
  • the token includes an expiration date; and a first electronic device includes a network connection module for establishing a connection with the cloud server; wherein the first electronic device transmits a transaction request to the cloud server, and the cloud server transmits the Key information to the first electronic device, when the first electronic device performs a verification result of an identity verification according to the key information is successful, the cloud server transmits the transaction voucher token to the first electronic device, where During the expiration date, the first electronic device is allowed to perform a trading action.
  • FIG. 1 is a schematic diagram of a transaction system according to an embodiment of the present invention.
  • FIG. 2 is a schematic diagram of a transaction flow according to an embodiment of the present invention.
  • FIG. 3 is a schematic diagram of a transaction system according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a transaction flow according to an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of a transaction system 10 according to an embodiment of the present invention.
  • the transaction system 10 includes a cloud service.
  • the server 100 and an electronic device 102.
  • the cloud server 100 can be a commercial server, which includes a key generation module 110, a transaction voucher token generator 112, and a volume code generation module 114.
  • the transaction voucher token generator 112 is used to generate a transaction voucher token TKN (Token).
  • the key generation module 110 is configured to generate a key information KEY, where the key information KEY includes a public key information KEY_PB and a private key information KEY_PV.
  • the volume label generating module 114 is configured to generate a volume label CD.
  • the volume label CD can be a two-dimensional barcode, a QR code, and a Near Field Communication Tag (NFC). Tag) or one of the Bluetooth tags.
  • the cloud server 100 can transmit the volume label CD, the transaction credential token TKN, and the key information KEY to the electronic device 102 via an Internet.
  • the electronic device 102 is an electronic device held by a buyer user BU.
  • the electronic device 102 can be an electronic device with a network communication function, such as a smart phone or a tablet computer.
  • the electronic device 102 includes a network connection module 120 and a volume code reading.
  • the module 122, a processor 124, and a storage device 126 are taken.
  • the network connection module 120 is configured to establish a connection with the cloud server 100 and perform data transmission.
  • the electronic device 102 can receive the key information KEY and the transaction voucher token TKN transmitted by the cloud server 100 through the network connection module 120.
  • the network connection module 120 is a wireless network connection module.
  • the volume code reading module 122 is configured to read the volume code CD.
  • the volume code reading module 122 can include an optical lens and an image recognition module for reading the two-dimensional barcode or responding quickly.
  • the code tag reading module 122 can be a short-range wireless communication technology module or a Bluetooth module for reading a short-range wireless communication technology tag or a Bluetooth tag.
  • the storage device 126 is configured to store the transaction credential token TKN and the key information KEY transmitted by the cloud server 100.
  • the storage device 126 stores a process code 128, and the process code 128 is used to instruct the processor 124 to perform the transfer transaction. Demand, perform an authentication process, or perform an online payment.
  • FIG. 2 is a schematic diagram of a transaction process 20 according to an embodiment of the present invention.
  • the transaction process 20 is performed by the transaction system 10, which includes the following steps:
  • Step 200 Start.
  • Step 202 The electronic device 102 transmits a transaction demand to the cloud server 100.
  • Step 204 The cloud server 100 transmits the key information KEY to the electronic device 102.
  • Step 206 The electronic device 102 performs identity verification according to the key information KEY to generate a verification result. If the verification result is successful, step 208 is performed.
  • Step 208 The cloud server 100 transmits the transaction credential token TKN to the electronic device 102, and the transaction voucher token TKN includes an expiration date EPD.
  • Step 210 The cloud server 100 generates a volume label CD according to the key information KEY and the transaction credential token TKN.
  • Step 212 The electronic device 102 reads the volume label CD, and the electronic device 102 generates a reading result and determines whether the time for reading the label code CD is within the expiration date EPD; if the reading result is successful and the volume label is read The time of the code CD is within the expiration date EPD, and step 214 is performed.
  • Step 214 A transaction action that the electronic device 102 is allowed to perform.
  • Step 216 End.
  • the transaction process 20 can enhance the transaction security of the buyer user BU for online shopping, and the operation details thereof are as follows.
  • the buyer user BU transmits the transaction demand related to a transaction to the cloud server 100 through the electronic device 102, and the transaction demand may include the product information, the commodity price, and the transaction method of the product GD that the buyer user BU wants to purchase.
  • the transaction method can be through the delivery of goods by home delivery or super-commercial pick-up and so on.
  • the cloud server 100 transmits the key information KEY to the electronic device 102.
  • the key information KEY includes the public key information KEY_PB and the private key information KEY_PV.
  • the key information KEY is obtained. It is stored in the storage device 126.
  • the home delivery person or the super store owner needs to perform identity verification via the key information KEY in the electronic device 102, that is, by verifying that the electronic device 102 is The electronic device held by the buyer of the transaction confirms the identity of the buyer.
  • the electronic device 102 performs identity verification based on the key information KEY.
  • the processor 124 of the electronic device 102 can read and store the storage device 126 for the buyer user to perform authentication, or the process code 128 can instruct the processor 124 to perform a decoding process according to the public key information KEY_PB and the private key information KEY_PV.
  • the details of the execution of the decoding process by the key information KEY_PB and the private key information KEY_PV are well known to those of ordinary skill in the art and will not be described here.
  • the cloud server 100 transmits the transaction voucher token TKN to the electronic device 102, and the transaction voucher token TKN contains the expiration date EPD.
  • the electronic device 102 stores the transaction voucher token TKN in the storage device 126 after receiving the transaction voucher token TKN.
  • the cloud server 100 generates the volume label CD according to the key information KEY and the transaction credential token TKN.
  • a seller can attach the label code CD to the product GD that the buyer user BU wants to purchase, that is, the label code CD is shipped with the product GD through a logistics company to the address specified by the buyer or super-commercial.
  • the tag code CD is generated according to the key information KEY, and must be successfully read by the electronic device having the key information KEY.
  • the home delivery delivery person or the super store owner delivers the product GD to the buyer user BU.
  • the buyer user BU needs to utilize Electronic device 102
  • the volume label CD is read, and the electronic device 102 generates a reading result and determines whether the time when the electronic device 102 reads the volume label CD is within the expiration date EPD.
  • the reading result is displayed as failure.
  • the product taken out by the delivery delivery staff or the super shop assistant is not the product GD specified by the buyer user BU, or the electronic device for reading the volume label CD is not the electronic device 102 (ie, The representative who wants to receive the goods GD from the delivery delivery staff or the super shop assistant is not the buyer user BU), thereby ensuring the transaction security of the buyer and the seller to ensure that the goods GD are correctly delivered to the buyer user BU.
  • the electronic device 102 needs to determine whether the time when the electronic device 102 reads the volume label CD is within the expiration date EPD, so as to avoid the goods GD being hit by the buyer if the buyer user BU loses the electronic device 102.
  • the electronic device 102) the possibility of piracy.
  • the electronic device 102 When the electronic device 102 successfully reads the volume label CD and the electronic device 102 reads the volume code CD within the expiration date EPD, in step 212, the electronic device 102 is allowed to perform the transaction action of the transaction.
  • the buyer user BU can perform an online payment action through the electronic device 102.
  • the buyer user BU can perform online card swiping through the electronic device 102 or transmit a confirmation transfer message to the cloud server 100 via the electronic device 102, and the cloud server 100 can transfer the confirmation transfer message to the buyer and the seller.
  • the designated financial institution enables it to complete a transfer action.
  • the present invention generates the volume label CD by using the key information KEY and the transaction document token TKN, and is effective according to whether the electronic device 102 can read the volume label CD and the electronic device 102 reads the volume code CD.
  • the term EPD is used as the basis for verifying the product GD and the buyer user BU.
  • the present invention can ensure that the correct goods are delivered to the correct buyer, thereby further improving transaction security.
  • FIG. 3 is a schematic diagram of a transaction system 30 according to an embodiment of the present invention.
  • the transaction system 30 is similar to the transaction system 10, so the same components follow the same symbols.
  • the transaction system 30 The electronic device 302 is an electronic device held by a seller user SU.
  • the electronic device 302 can be an electronic device with a network communication function, such as a smart phone or a tablet computer.
  • the electronic device 302 includes a network connection module 320 and a storage device 326.
  • the network connection module 320 is configured to receive the key information KEY and the transaction voucher token TKN transmitted by the cloud server 100. After the electronic device 302 receives the key information KEY and the transaction voucher token TKN, the electronic device 302 transmits the key information KEY. And the transaction voucher token TKN is stored in the storage device 326.
  • the buyer user BU and the seller user SU can use the electronic device 102 and the electronic device 302 and the key information KEY stored therein to perform mutual authentication, and the identity verification succeeds.
  • the cloud server 100 transmits the transaction voucher token TKN to the electronic device 102, 302.
  • the electronic device 102, 302 receives the transaction voucher token TKN
  • the transaction action can be performed.
  • the seller user SU can use the buyer user BU.
  • the product GD to be purchased is delivered to the buyer user BU, and the buyer user BU can perform an online payment action through the electronic device 102.
  • FIG. 4 is a schematic diagram of a transaction flow 40 according to an embodiment of the present invention.
  • the transaction process 40 is performed by the transaction system 30, which includes the following steps:
  • Step 400 Start.
  • Step 402 The electronic device 102 transmits a transaction request to the cloud server 100.
  • Step 404 The cloud server 100 transmits the key information KEY to the electronic devices 102, 302.
  • Step 406 The electronic device 102, 302 performs identity verification according to the key information KEY to generate a verification result. If the verification result is successful, step 408 is performed.
  • Step 408 The cloud server 100 transmits the transaction credential token TKN to the electronic device 102, 302, and the transaction voucher token TKN contains the expiration date EPD.
  • Step 410 The electronic device 102, 302 determines whether the one-time delivery time is within the validity period EPD; if it is within the validity period EPD, step 412 is performed.
  • Step 412 The electronic device 102 is allowed to perform a transaction action.
  • the transaction process 40 is similar to the transaction process 20. Unlike the transaction process 20, according to the transaction process 40, the cloud server 100 transmits the key information KEY and the transaction voucher token TKN to the electronic device 102 and the electronic device 302, that is, both the buyer and the seller. The identity of each other can be verified by the key information KEY, and the electronic device 102, 302 determines whether the face-to-face time is within the expiration date EPD to further confirm the authenticity of the identity of the buyer and the seller and improve the transaction security. For details of the remaining operations, refer to the aforementioned related paragraphs, and will not be repeated here.
  • the present invention utilizes key information and transaction voucher tokens for product verification and identity verification of both buyers and sellers. Compared with the prior art, the present invention can ensure correct product delivery and correct buyers, and further enhance transaction security.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Economics (AREA)
  • Marketing (AREA)
  • Development Economics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种交易方法,包含有一第一电子装置传送一交易需求至一云端服务器;该云端服务器传送一密钥信息至该第一电子装置;该第一电子装置根据该密钥信息进行一身份验证,产生一验证结果;当该验证结果为成功时,该云端服务器传送一交易凭证令牌(Token)至该第一电子装置,该交易凭证令牌包含一有效期限;以及于该有效期限内,该第一电子装置被允许进行一交易动作。

Description

交易方法及交易系统 技术领域
本发明是指一种交易方法及交易系统,尤指一种提升交易安全的交易方法及交易系统。
背景技术
随着网络科技的发达与普遍,网络购物为人们带来许多便利性。然而,交易安全性仍是买家选择网络购物的最大顾忌。举例来说,虽然网络购物可选择以信用卡刷卡付款,但买家仍会担心付款后,卖家未如期出货而无法取得欲购买的物品。即使买家可选择货到付款或透过第三方支付,但货到付款需事先准备好现金,造成使用上的不便,而第三方支付需事先汇款以及存在有公正性的疑虑。另外,若买家选择事先付款超商取货,存在有欲购买的物品备有心人士盗领的风险。因此,习知技术实有改善的必要。
发明内容
因此,本发明的主要目的即在于提供一种提升交易安全的交易方法及交易系统,以改善习知技术的缺点。
本发明揭露一种交易方法,包含有一第一电子装置传送一交易需求至一云端服务器;该云端服务器传送一密钥信息至该第一电子装置;该第一电子装置根据该密钥信息进行一身份验证,产生一验证结果;当该验证结果为成功时,该云端服务器传送一交易凭证令牌(Token)至该第一电子装置,该交易凭证令牌包含一有效期限;以及于该有效期限内,该第一电子装置被允许进行一交易动作。
本发明另揭露一种交易系统,包含有一云端服务器,包含有一密钥产生模块,用来产生一密钥信息;以及一交易凭证令牌产生器,用来产生一交易凭证令牌,该交易凭证令牌包含一有效期限;以及一第一电子装置,包含一网络联机模块,用来与该云端服务器建立联机;其中,该第一电子装置传送一交易需求至该云端服务器,该云端服务器传送该密钥信息至该第一电子装置,当该第一电子装置根据该密钥信息进行一身份验证的一验证结果为成功时,该云端服务器传送该交易凭证令牌至该第一电子装置,于该有效期限内,该第一电子装置被允许进行一交易动作。
附图说明
图1为本发明实施例一交易系统的示意图。
图2为本发明实施例一交易流程的示意图。
图3为本发明实施例一交易系统的示意图。
图4为本发明实施例一交易流程的示意图。
组件标号说明:
Figure PCTCN2016077347-appb-000001
具体实施方式
请参考图1,图1为本发明实施例一交易系统10的示意图,交易系统10包含有一云端服 务器100以及一电子装置102。云端服务器100可为一商用服务器,其包含有一密钥产生模块110、一交易凭证令牌产生器112及一卷标码产生模块114。交易凭证令牌产生器112用来产生一交易凭证令牌TKN(Token)。密钥产生模块110用来产生一密钥信息KEY,密钥信息KEY包含有一公钥信息KEY_PB以及一私钥信息KEY_PV。卷标码产生模块114用来产生一卷标码CD,卷标码CD可为一二维条形码、一快速响应码(QR Code)、一近距离无线通讯技术卷标(Near Field Communication Tag,NFC Tag)或一蓝牙标签其中之一。云端服务器100可透过一因特网,将卷标码CD、交易凭证令牌TKN及密钥信息KEY传送至电子装置102。
电子装置102为一买方用户BU所持有的电子装置,电子装置102可为智能型手机、平板计算机等具有网络通讯功能的电子装置,电子装置102包含有一网络联机模块120、一卷标码读取模块122、一处理器124及一存储装置126。网络联机模块120用来与云端服务器100建立联机并进行数据传输,举例来说,电子装置102可透过网络联机模块120接收云端服务器100所传送的密钥信息KEY及交易凭证令牌TKN,较佳地,网络联机模块120为一无线网络联机模块。另外,卷标码读取模块122用来读取卷标码CD,举例来说,卷标码读取模块122可包含一光学镜头及一影像识别模块,用来读取二维条形码或快速响应码,此外,卷标码读取模块122可为一近距离无线通讯技术模块或是一蓝牙模块,用来读取近距离无线通讯技术卷标或是蓝牙卷标。存储装置126用来存储云端服务器100所传送的交易凭证令牌TKN及密钥信息KEY,除此之外,存储装置126存储一进程代码128,进程代码128用来指示处理器124以进行传送交易需求、进行一身份验证进程或是进行一在线付款等操作。
另一方面,为了提升交易安全,买方用户BU可透过交易系统10进行网络购物。相关操作请参考图2,图2为本发明实施例一交易流程20的示意图。交易流程20由交易系统10来执行,交易流程20包含以下步骤:
步骤200:开始。
步骤202:电子装置102传送一交易需求至云端服务器100。
步骤204:云端服务器100传送密钥信息KEY至电子装置102。
步骤206:电子装置102根据密钥信息KEY进行身份验证,产生一验证结果;若该验证结果显示为成功,执行步骤208。
步骤208:云端服务器100传送交易凭证令牌TKN至电子装置102,交易凭证令牌TKN包含有效期限EPD。
步骤210:云端服务器100根据密钥信息KEY及交易凭证令牌TKN产生卷标码CD。
步骤212:电子装置102读取卷标码CD,电子装置102产生一读取结果并判断读取标签码CD的时间是否于有效期限EPD内;若该读取结果显示为成功且读取卷标码CD的时间于有效期限EPD内,执行步骤214。
步骤214:电子装置102被允许进行的一交易动作。
步骤216:结束。
交易流程20可提升买方用户BU进行网络购物的交易安全性,其操作细节说明如下。于步骤202中,买方用户BU透过电子装置102传送相关于一交易的交易需求至云端服务器100,交易需求可包含买方使用者BU欲购买的一商品GD的商品信息、商品价格及其交易方式,交易方式可为透过宅配货到付款或超商取货等等。于步骤204中,云端服务器100即传送密钥信息KEY至电子装置102,密钥信息KEY包含有公钥信息KEY_PB以及私钥信息KEY_PV,电子装置102收到密钥信息KEY后即将密钥信息KEY存储于存储装置126中。换句话说,不论交易方式为宅配货到付款或超商取货,宅配送货员或超商店员都需经过电子装置102中的密钥信息KEY进行身份验证,即藉由验证电子装置102为该交易的买家所持有的电子装置来确认买家的身份。
于步骤206中,电子装置102根据密钥信息KEY进行身份验证。电子装置102的处理器124可读取存储于存储装置126供买家用户进行身份验证,或是进程代码128可指示处理器124根据公钥信息KEY_PB及私钥信息KEY_PV执行一译码进程,公钥信息KEY_PB及私钥信息KEY_PV执行译码进程的细节为本领域具通常知识者所熟知,故不在此赘述。
当身份验证成功时,于步骤208中,云端服务器100传送交易凭证令牌TKN至电子装置102,交易凭证令牌TKN包含有效期限EPD。电子装置102收到交易凭证令牌TKN后即将交易凭证令牌TKN存储于存储装置126中。另外,于步骤210中,云端服务器100根据密钥信息KEY及交易凭证令牌TKN产生卷标码CD。一卖方可将标签码CD黏贴于买方使用者BU欲购买的商品GD之上,即标签码CD随着商品GD透过一物流公司运送至买方所指定的地址或是超商。需注意的是,标签码CD为根据密钥信息KEY所产生,必须由具有密钥信息KEY的电子装置才能成功读取。
待商品GD透过物流公司运送至买方所指定的地址或是超商后,宅配送货员或超商店员在将商品GD交付给买方使用者BU之前,于步骤212中,买方用户BU需利用电子装置102 读取卷标码CD,电子装置102产生读取结果并判断电子装置102读取卷标码CD的时间是否于有效期限EPD内。读取结果显示为失败代表宅配送货员或超商店员所取出的商品并非买方使用者BU所指定的商品GD,或是代表用来读取卷标码CD的电子装置并非电子装置102(即代表欲向宅配送货员或超商店员接收商品GD的人员并非买方使用者BU本人),藉此可保障买卖双方的交易安全性,以确保商品GD被正确地交付予买方使用者BU。另外,电子装置102需判断电子装置102读取卷标码CD的时间是否于有效期限EPD内,以避免在买方用户BU遗失电子装置102的情况下,商品GD遭到有心人士(以拾获的电子装置102)盗领的可能性。
当电子装置102成功读取卷标码CD时且电子装置102读取卷标码CD的时间于有效期限EPD内,于步骤212中,电子装置102被允许进行该交易的交易动作。换句话说,当电子装置102成功读取卷标码CD时且电子装置102读取卷标码CD的时间于有效期限EPD内,买方用户BU才可以透过电子装置102进行一在线付款动作,举例来说,买方用户BU可透过电子装置102进行在线刷卡,或是透过电子装置102将一确认转账讯息传送至云端服务器100,云端服务器100即可将该确认转账讯息转送至买卖双方所指定的金融机构,使其能完成一转账动作。
由上述可知,本发明利用密钥信息KEY及交易凭证令牌TKN产生卷标码CD,并根据电子装置102是否能读取卷标码CD以及电子装置102读取卷标码CD的时间于有效期限EPD内作为验证商品GD以及买方使用者BU的依据。相较于习知技术,本发明更能确保正确的商品被交付与正确的买家,进一步提升交易安全性。
需注意的是,前述实施例是用以说明本发明的概念,本领域具通常知识者当可据以做不同之修饰,而不限于此。举例来说,前述实施例以宅配货到付款或超商取货为例进行说明,而不限于此,本发明可应用于交易方式为面交的情境之下。具体来说,请参考图3,图3为本发明实施例一交易系统30的示意图,交易系统30与交易系统10类似,故相同组件沿用相同符号,与交易系统10不同的是,交易系统30另包含一电子装置302,电子装置302为一卖方用户SU所持有的电子装置,电子装置302可为智能型手机、平板计算机等具有网络通讯功能的电子装置。电子装置302包含有一网络联机模块320及一存储装置326。网络联机模块320用来接收云端服务器100所传送的密钥信息KEY及交易凭证令牌TKN,当电子装置302收到密钥信息KEY及交易凭证令牌TKN后,电子装置302将密钥信息KEY及交易凭证令牌TKN存储于存储装置326中。当买卖双方见面时,买方使用者BU与卖方用户SU可利用电子装置102与电子装置302以及存储于其中的密钥信息KEY进行相互身份验证,于身份验证成功之 后,云端服务器100传送交易凭证令牌TKN至电子装置102、302,电子装置102、302收到交易凭证令牌TKN之后即可进行交易动作,此时,卖方使用者SU可将买方使用者BU欲购买的商品GD交付给买方使用者BU,且买方用户BU可透过电子装置102进行在线付款动作。
关于上述交易系统30的操作流程可进一步归纳成一交易流程40,请参考图4,图4为本发明实施例交易流程40的示意图。交易流程40由交易系统30来执行,交易流程40包含以下步骤:
步骤400:开始。
步骤402:电子装置102传送一交易需求至云端服务器100。
步骤404:云端服务器100传送密钥信息KEY至电子装置102、302。
步骤406:电子装置102、302根据密钥信息KEY进行身份验证,产生一验证结果;若该验证结果显示为成功,执行步骤408。
步骤408:云端服务器100传送交易凭证令牌TKN至电子装置102、302,交易凭证令牌TKN包含有效期限EPD。
步骤410:电子装置102、302判断一面交时间是否于有效期限EPD内;若于有效期限EPD内,执行步骤412。
步骤412:电子装置102被允许进行一交易动作。
步骤414:结束。
交易流程40与交易流程20类似,与交易流程20不同的是,根据交易流程40,云端服务器100将密钥信息KEY、交易凭证令牌TKN传送至电子装置102以及电子装置302,即买卖双方皆可透过密钥信息KEY验证彼此身份,同时电子装置102、302判断面交时间是否于有效期限EPD内,以进一步确认买卖双方身份的真实度,提升交易安全性。其余操作细节可参考前述相关段落,而不在此赘述。
综上所述,本发明利用密钥信息及交易凭证令牌进行商品验证以及买卖双方的身份验证。相较于习知技术,本发明能确保正确的商品交付与正确的买家,进一步提升交易安全性。
以上所述仅为本发明的较佳实施例,凡依本发明权利要求范围所做的均等变化与修饰,皆应属本发明的涵盖范围。

Claims (12)

  1. 一种交易方法,其特征为,该方法包含有:
    一第一电子装置传送一交易需求至一云端服务器;
    该云端服务器传送一密钥信息至该第一电子装置;
    该第一电子装置根据该密钥信息进行一身份验证,产生一验证结果;
    当该验证结果为成功时,该云端服务器传送一交易凭证令牌至该第一电子装置,该交易凭证令牌包含一有效期限;以及
    于该有效期限内,该第一电子装置被允许进行一交易动作。
  2. 如权利要求1所述的交易方法,其特征为,该密钥信息包含一公钥信息以及一私钥信息。
  3. 如权利要求1所述的交易方法,其特征为,另包含:
    该云端服务器根据该密钥信息或该交易凭证令牌产生一卷标码。
  4. 如权利要求3所述的交易方法,其特征为,另包含:
    该第一电子装置根据该密钥信息或该交易凭证令牌对该卷标码进行判读;以及
    当该第一电子装置成功读取该卷标码时且于该有效期限内,该第一电子装置被允许进行该交易动作。
  5. 如权利要求1所述的交易方法,其特征为,于该有效期限内该交易被允许进行为该第一电子装置被允许进行一在线付款动作。
  6. 如权利要求1所述的交易方法,其特征为,另包含:
    该云端服务器传送该密钥信息至该第一电子装置及一第二电子装置;
    该第一电子装置与该第二电子装置根据该密钥信息进行该身份验证,产生该验证结果;以及
    当该验证结果为成功时,该云端服务器传送该交易凭证令牌至该第一电子装置及该第二电子装置。
  7. 一种交易系统,包含有:
    一云端服务器,包含有:
    一密钥产生模块,用来产生一密钥信息;以及
    一交易凭证令牌产生器,用来产生一交易凭证令牌,该交易凭证令牌包含一有效期限;以及
    一第一电子装置,包含一网络联机模块,用来与该云端服务器建立联机;
    其中,该第一电子装置传送一交易需求至该云端服务器,该云端服务器传送该密钥信息至该第一电子装置,当该第一电子装置根据该密钥信息进行一身份验证的一验证结 果为成功时,该云端服务器传送该交易凭证令牌至该第一电子装置,于该有效期限内,该第一电子装置被允许进行一交易动作。
  8. 如权利要求7所述的交易系统,其特征为,该密钥信息包含一公钥信息以及一私钥信息。
  9. 如权利要求7所述的交易系统,其特征为,该云端服务器另包含一卷标码产生模块,用来根据该密钥信息或该交易凭证令牌产生一卷标码。
  10. 如权利要求9所述的交易系统,其特征为,该第一电子装置另包含:
    一卷标码读取模块,用来根据该密钥信息或该交易凭证令牌对该卷标码进行判读;
    其中,当该第一电子装置成功读取该卷标码时且于该有效期限内,该第一电子装置被允许进行该交易动作。
  11. 如权利要求7所述的交易系统,其特征为,于该有效期限内该第一电子装置进行该交易动作为该第一电子装置被允许进行一在线付款动作。
  12. 如权利要求7所述的交易系统,另包含:
    一第二电子装置,包含一网络联机模块,用来与该云端服务器建立联机;
    其中,该云端服务器传送该密钥信息至该第一电子装置及该第二电子装置,该第一电子装置与该第二电子装置根据该密钥信息进行该身份验证,产生该验证结果,当该验证结果为成功时,该云端服务器传送该交易凭证令牌至该第一电子装置及该第二电子装置。
PCT/CN2016/077347 2015-11-30 2016-03-25 交易方法及交易系统 WO2017092202A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US15/552,296 US20180075451A1 (en) 2015-11-30 2016-03-25 Transaction Method and Transaction System

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510856123.X 2015-11-30
CN201510856123.XA CN105512925A (zh) 2015-11-30 2015-11-30 交易方法及交易系统

Publications (1)

Publication Number Publication Date
WO2017092202A1 true WO2017092202A1 (zh) 2017-06-08

Family

ID=55720885

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/077347 WO2017092202A1 (zh) 2015-11-30 2016-03-25 交易方法及交易系统

Country Status (3)

Country Link
US (1) US20180075451A1 (zh)
CN (1) CN105512925A (zh)
WO (1) WO2017092202A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI840727B (zh) 2021-12-29 2024-05-01 華南商業銀行股份有限公司 信用卡控卡系統

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111027978B (zh) * 2019-12-10 2023-05-02 腾讯科技(深圳)有限公司 支付方法、装置、计算机可读存储介质和计算机设备
CN114697007B (zh) * 2020-12-29 2024-01-16 华为技术有限公司 一种密钥管理的方法、相应装置及系统

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102831734A (zh) * 2011-06-15 2012-12-19 上海博路信息技术有限公司 一种移动终端客户端的支付方法
CN104395917A (zh) * 2012-05-21 2015-03-04 金主汉 用于将移动通信终端用作支付终端的应用程序、应用服务提供商系统及方法
CN104680361A (zh) * 2015-02-05 2015-06-03 王钧 一种基于第三方平台的取现方法和系统

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070174042A1 (en) * 2006-01-24 2007-07-26 Thompson Sidney S Electronic tour guide system
US10242368B1 (en) * 2011-10-17 2019-03-26 Capital One Services, Llc System and method for providing software-based contactless payment
US9800408B2 (en) * 2011-12-01 2017-10-24 Unik Systems Design & Marketing Pvt Ltd Method of generating secure tokens and transmission based on (TRNG) generated tokens and split into shares and the system thereof
CN105103578A (zh) * 2013-04-05 2015-11-25 交互数字专利控股公司 安全端对端和组通信
US9166791B2 (en) * 2013-11-20 2015-10-20 At&T Intellectual Property I, L.P. Method and apparatus for user identity verification

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102831734A (zh) * 2011-06-15 2012-12-19 上海博路信息技术有限公司 一种移动终端客户端的支付方法
CN104395917A (zh) * 2012-05-21 2015-03-04 金主汉 用于将移动通信终端用作支付终端的应用程序、应用服务提供商系统及方法
CN104680361A (zh) * 2015-02-05 2015-06-03 王钧 一种基于第三方平台的取现方法和系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI840727B (zh) 2021-12-29 2024-05-01 華南商業銀行股份有限公司 信用卡控卡系統

Also Published As

Publication number Publication date
US20180075451A1 (en) 2018-03-15
CN105512925A (zh) 2016-04-20

Similar Documents

Publication Publication Date Title
TW591459B (en) Enabling use of smart cards by consumer devices for Internet commerce
CN107408170B (zh) 认证激活的增强现实显示装置
AU2011223674B2 (en) Systems and methods using mobile device in payment transaction
AU2019253872A1 (en) Seamless transaction minimizing user input
US20140100973A1 (en) Smartphone virtual payment card
TWI734764B (zh) 多維條碼行動支付方法
US20150193765A1 (en) Method and System for Mobile Payment and Access Control
Surekha et al. E-payment transactions using encrypted QR codes
JP2014513825A5 (zh)
JP2014513825A (ja) 安全な2者照合取引システム
US20180314814A1 (en) System and method employing reduced time device processing
JPWO2006082913A1 (ja) ネットワーク決済カード、ネットワーク決済プログラム、認証サーバ、及びショッピングシステムと決済方法
WO2017103701A1 (en) A system and method for facilitating cross-platform financial transactions
US20150248676A1 (en) Touchless signature
US20130339196A1 (en) Online shopping system and method
WO2017092202A1 (zh) 交易方法及交易系统
CN105096115A (zh) 无销售点终端的电子支付交易的方法及移动装置
WO2015139623A1 (en) Method and system for mobile payment and access control
US11823200B2 (en) Smart physical payment cards
TW201721543A (zh) 交易方法及交易系統
KR102079668B1 (ko) 개인간 대면식 자금거래 처리 시스템 및 처리 방법
US20150286996A1 (en) Method and apparatus for carrying out an electronic transaction
JP6217043B2 (ja) 出入金管理サーバ装置、出入金管理システム、およびその動作方法
JP6974385B2 (ja) デジタル資産取引の多重確認方法
TWM514614U (zh) 線上支付防盜刷系統

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16869516

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15552296

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16869516

Country of ref document: EP

Kind code of ref document: A1