WO2017101584A1 - 实现线上线下交易安全的设备和方法 - Google Patents

实现线上线下交易安全的设备和方法 Download PDF

Info

Publication number
WO2017101584A1
WO2017101584A1 PCT/CN2016/102851 CN2016102851W WO2017101584A1 WO 2017101584 A1 WO2017101584 A1 WO 2017101584A1 CN 2016102851 W CN2016102851 W CN 2016102851W WO 2017101584 A1 WO2017101584 A1 WO 2017101584A1
Authority
WO
WIPO (PCT)
Prior art keywords
module
payment
security
online
offline
Prior art date
Application number
PCT/CN2016/102851
Other languages
English (en)
French (fr)
Inventor
关思敏
Original Assignee
国民技术股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 国民技术股份有限公司 filed Critical 国民技术股份有限公司
Publication of WO2017101584A1 publication Critical patent/WO2017101584A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/16Payments settled via telecommunication systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification

Definitions

  • the invention belongs to the field of information security technology, and in particular relates to a device for realizing online and offline transaction security.
  • Alipay, WeChat and other third-party payment platforms such as swiping and scanning codes are convenient but less secure.
  • the device for realizing online and offline transaction security includes:
  • the security module is used for security authentication when the online and offline payment is used, and the online payment service includes WeChat payment, Alipay payment, scan code payment or online banking payment;
  • a radio frequency module for establishing a connection with a mobile device or a computer and performing data communication
  • the non-contact module having a financial service application function for an offline payment service
  • the main control module is connected to the power module, the security module, the radio frequency module, and the non-contact module, and is configured to control an operating state of the device.
  • an apparatus for realizing online and offline transaction security further wherein the security module and the main control module can be integrated as a security control module.
  • an apparatus for realizing online and offline transaction security further, the apparatus further includes a power supply module, and is also capable of taking power using a non-contact method.
  • an apparatus for realizing online and offline transaction security further, wherein the non-contact module is capable of performing offline payment service alone.
  • the device further includes one or more of a display module, a button module, a vibration and sensing module, a voice recognition module, and a fingerprint recognition module.
  • the apparatus for realizing online and offline transaction security, is further provided in a wearable form.
  • the device can further load one or several applications of a bus, an access control, a parking, and a membership card.
  • the invention also proposes a method for realizing online transaction security, comprising the following steps:
  • the first device establishes a wireless connection with the second device, and the second device is a mobile device or a computer;
  • the first device confirms the identity authentication information of the second device, and returns the response information, and the second device enters the online payment service client, and stops if not passed;
  • the first device receives the transfer information of the second device, digitally signs the transfer information, and transmits the transfer information to the second device for transaction.
  • identity authentication information and/or The digital signature processing of the transaction data requires the user to confirm, and the confirmation methods include button, voice recognition and fingerprint recognition.
  • the invention also proposes a device for realizing online transaction security, comprising:
  • the security module is configured to authenticate the user identity and digitally sign the user's transfer information, and the online payment service includes WeChat payment, Alipay payment, scan code payment, and online banking payment;
  • a radio frequency module for establishing a connection with a mobile device or a computer and performing data communication
  • the main control module is connected to the power module, the security module, the radio frequency module, and the non-contact module, and is configured to control an operating state of the device.
  • the invention can be used as a line online banking service, an electronic payment security tool and an offline payment device.
  • Combining wearable devices with secure authentication devices eliminates the need for independent security authentication devices and supports financial services such as e-cash.
  • the wireless authentication technology is adopted to realize interconnection with the mobile terminal to ensure the security of the online banking service.
  • Alipay, WeChat and other third-party payment platforms such as swiping cards and scanning codes are convenient but less secure.
  • micropayments are made or the user's identity is determined by inputting a payment password.
  • Adding the device authentication process of the present invention in the transaction process can improve the security level of the payment, and is beneficial to increasing the service range of the existing payment method.
  • FIG. 1 is a schematic diagram of an apparatus for implementing online and offline transaction security according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing a line online silver transfer service according to an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of an apparatus for implementing online and offline transaction security according to an embodiment of the present invention.
  • the device 10 includes a power module 101, a security module 103, a radio frequency module 104, a non-contact module 105, a main control module 102, the main control module 102 and the power module 101, and the security.
  • the module 103, the radio frequency module 104, and the non-contact module 105 are connected to control an operating state of the device.
  • the power module 101 includes a battery, and the power module 101 is used to supply power to the entire device 10.
  • the battery in the power module 101 may be one of a disposable battery or a rechargeable battery.
  • the power module 101 in the rechargeable battery solution may further include a battery protection unit, which can prevent the battery from being damaged due to external pressure or other reasons to ensure the stability of the power supply and increase the service life of the battery.
  • the entire device 10 may be powered by a non-contact power take-off without using a power module.
  • the security module 103 includes a security algorithm encryption unit and a security algorithm decryption unit. During the online transaction of the device 10 that implements online and offline transaction security, the security module 103 can confirm the identity information provided by the user and digitally sign the received transaction data after confirming the legality of the user identity. . During the offline transaction, the security module 103 may or may not provide security authentication for the non-contact module 105.
  • the radio frequency module 104 includes a radio frequency circuit unit and a radio frequency antenna, which are used for transceiving and processing radio frequency signals, and provide a data transmission and control interface with the main control module 102.
  • the radio frequency circuit unit is used for radio frequency signal processing, and the radio frequency signal processing may include filtering, amplifying, modulating/demodulating, One or several of encoding/decoding, analog/digital to analog conversion.
  • the radio frequency antenna is used to receive and transmit radio frequency signals.
  • the radio frequency module can establish a connection with a mobile phone through a radio channel such as Bluetooth, thereby performing data communication with the mobile phone, and transmitting and receiving the user's identity authentication information and transaction data. Further, it is also possible to receive data of the update program and load the data of the application through data communication.
  • the main control module 102 includes an interface control unit, a data processing unit, and a storage unit for controlling the working state of the device 10 that implements online and offline transaction security.
  • the operating state of the device 10 includes the system operating sequence of the device, the operating state of each module, and the processing and storage of the transmitted and received data.
  • the interface control unit is configured to provide configuration and switch control of physical connection interfaces with other modules.
  • the data processing unit is configured to perform transparent transmission or encoding/decoding processing on the transmitted and received data, and may also include other data processing methods.
  • the storage unit includes a program storage unit and a data storage unit.
  • the storage unit is one of a mask read only memory, a programmable read only memory, an erasable programmable read only memory, an electrically erasable programmable read only memory, and a flash memory.
  • the main control module is configured to control the power supply/deactivation of the power module during use of the device 10, and instruct the security module to perform user identity authentication information and transaction data transmission and reception through the radio frequency module, and according to the received data
  • the device that implements online and offline transaction security performs program update and application loading.
  • the non-contact module 105 includes an NFC chip and a circuit, and an antenna coil.
  • the NFC chip and circuit are used for processing signals and data, and provide data transmission and control interfaces with the security module and the main control module.
  • the antenna coil is used for transmission and reception of NFC signals.
  • the non-contact module 105 can cooperate with the security module 103 to implement the security of the offline transaction, and can also load the bus, the access control, the parking, and the membership card during the use of the device for implementing online and offline security.
  • the contactless module can also be used separately to implement offline payment services.
  • the device for implementing online and offline transaction security may further include a display screen and a button module, a vibration and sensing module, a voice recognition module, and a fingerprint recognition module.
  • a display screen and a button module may further include a vibration and sensing module, a voice recognition module, and a fingerprint recognition module.
  • the display screen and the button module include at least a display screen and a button hardware unit for providing a data transmission and control interface with the security control module.
  • the display hardware unit may be one of a light emitting diode array, a liquid crystal display, and an electronic paper display.
  • the display hardware unit may further comprise a display drive circuit unit.
  • the key hardware unit includes at least one of a mechanical button or a touch button.
  • the button hardware unit may further include a button driving circuit unit;
  • the vibration and sensing module includes at least one vibration motor and an acceleration sensor for vibration reminding and motion monitoring, and provides a data transmission and control interface with the security module 103 and the main control module 102, and performs instructions on the commands from the main control module. Out of response;
  • the voice recognition module may pre-store the feature parameters of the user voice and store the user voice feature parameters to verify the legality of the user identity by comparing with the stored legitimate user voice.
  • voice recognition the security and reliability of online and offline transactions can be greatly increased.
  • the fingerprint identification module can be used to provide security authentication for online and offline transactions.
  • the legal fingerprint feature parameters are extracted and stored in advance, and the user fingerprint feature parameters are compared with the stored legitimate user fingerprints to confirm the legality of the user identity.
  • fingerprint identification the security and reliability of online and offline transactions can be greatly increased.
  • the security module 103 and the main control module 102 as described above may be integrated into a security control module, and the security control module may complete the confirmation of the user identity authentication information of the security module 103 as described above, the signature of the transaction data, and the The main control module 102 controls the functions of the entire device that implements online and offline transaction security.
  • the device for implementing online and offline transaction security may be set in a wearable form. Compared with traditional smart wearable devices, it can be used as a wire online banking service, an electronic payment security tool and an offline payment device. Combining wearable devices with secure authentication devices eliminates the need for independent security authentication devices and supports financial services such as e-cash.
  • the device for implementing online and offline transaction security provided by the embodiment, and security Compared with the U shield of the authentication device, it uses radio frequency technology to interconnect with the mobile terminal to ensure the security of the online banking service.
  • Alipay, WeChat and other third-party payment platforms such as swiping cards and scanning codes are convenient but less secure.
  • micropayments are made or the user's identity is determined by inputting a payment password.
  • Adding the device authentication process of the present invention in the transaction process can improve the security level of the payment, and is beneficial to increasing the service range of the existing payment method.
  • This embodiment adopts the following method to implement security of online transaction security, and the method includes the following steps:
  • the first device establishes a wireless connection with the second device, and the second device is a mobile device or a computer;
  • the first device confirms the identity authentication information of the second device, and returns the response information, and the second device enters the online payment service client, and stops if not passed;
  • the first device receives the transfer information of the second device, digitally signs the transfer information, and transmits the transfer information to the second device for transaction.
  • the identity authentication information and/or the digital signature processing of the transaction data requires the user to confirm, and the confirmation method includes a button and a fingerprint identification method.
  • the embodiment can also be used as a device for realizing online transaction security, which includes the following modules:
  • the security module is configured to authenticate the user identity and digitally sign the user's transfer information, and the online payment service includes WeChat payment, Alipay payment, scan code payment, and online banking payment;
  • a radio frequency module for establishing a connection with a mobile device or a computer and performing data communication
  • the main control module is connected to the power module, the security module, the radio frequency module, and the non-contact module, and is configured to control an operating state of the device.
  • FIG. 2 shows a flow chart of the online online silver transfer service of the present invention.
  • the user turns on the device and waits to establish a connection with the phone. Specifically, the user can search for the device to be connected through the mobile phone Bluetooth.
  • the device After establishing a connection with the mobile phone, the device receives the identity authentication information sent by the mobile phone, and returns a response message to confirm, and the authentication passes to enter the mobile phone client service interface. If the certification does not pass, it will stop.
  • the user selects the transfer service and fills in the transfer information.
  • the transfer information is processed, it is sent to the device for digital signature through Bluetooth, and the user device performs digital signature and returns the signature data to the user's mobile phone.
  • the mobile client connects to the backend server through the network, and performs the transfer of the signature data check.
  • the transaction was successful and the device received a return result, arguing that the transaction was over.
  • the user can confirm whether the data has been tampered with, whether the transaction is performed, and the confirmed information needs to be digitally signed and transmitted back to the mobile phone client to further improve payment security.
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention can take the form of a hardware embodiment, a software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the device is implemented in a flow chart Or multiple processes and/or block diagrams of the functions specified in one or more blocks.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

一种实现线上线下交易安全的设备(10),包括:安全模块(103),用于线上线下支付时进行安全认证,所述线上支付业务包括微信支付、支付宝支付、扫码支付、网银支付;射频模块(104),用于与移动设备或电脑建立连接并进行数据通信;非接触模块(105),所述非接触模块具有金融业务应用功能,用于线下支付业务;主控模块(102),所述主控模块与所述电源模块(101)、所述安全模块、所述射频模块、所述非接触模块连接,用于控制所述设备的工作状态。该线上线下交易安全的设备可应用在诸如网银支付、微信支付,扫码支付和支付宝支付业务中,还可用在IC卡等线下支付业务提高交易的便利性。

Description

实现线上线下交易安全的设备和方法 技术领域
本发明属于信息安全技术领域,尤其涉及一种实现线上线下交易安全的设备。
背景技术
随着智能可穿戴设备市场的规模化及网络技术的不断发展,用户对产品体验、功能性等有了更多的需求,功能不断增强的可穿戴产品可以给用户带来更便捷的生活,这也是可穿戴设备发展的趋势。然而,目前的可穿戴设备,如智能手环,仅有记录、提醒等应用,不具备用于实现线上线下交易安全的功能。
目前,支付宝、微信等第三方支付平台刷卡、扫码等支付方式便捷但是安全性较低,通常只进行小额支付或通过输入支付密码来确定使用者身份。由于交易流程中通常缺乏安全认证过程,导致支付的安全等级不高,不利于增大上述支付方式的业务范围。
因此,现有技术中缺乏一种设备,其可以设置为可穿戴的形式,并且作为安全认证的设备,用于线上线下的交易流程中,提高支付的安全等级。
发明内容
本发明的目的是提供一种实现线上线下交易安全的设备,其可以设置为可穿戴的形式,用于线上线下的交易流程中,以提高支付的安全等级。
根据本发明的实现线上线下交易安全的设备,包括:
安全模块,用于线上线下支付时进行安全认证,所述线上支付业务包括微信支付、支付宝支付、扫码支付或网银支付;
射频模块,用于与移动设备或电脑建立连接并进行数据通信;
非接触模块,所述非接触模块具有金融业务应用功能,用于线下支付业务;
主控模块,所述主控模块与所述电源模块、所述安全模块、所述射频模块、所述非接触模块连接,用于控制所述设备的工作状态。
根据本发明的实现线上线下交易安全的设备,进一步,其中所述安全模块和所述主控模块可以集成为安全控制模块。
根据本发明的实现线上线下交易安全的设备,进一步,所述设备还包括电源模块,还能够使用非接触方式取电。
根据本发明的实现线上线下交易安全的设备,进一步,其中非接触模块单独能够进行线下支付业务。
根据本发明的实现线上线下交易安全的设备,进一步,所述设备还包括显示屏模块、按键模块、振动及传感模块、语音识别模块、指纹识别模块中的一种或几种。
根据本发明的实现线上线下交易安全的设备,进一步,所述设备设置为可佩戴的形式。
根据本发明的实现线上线下交易安全的设备,进一步,所述设备能够加载公交、门禁、停车、会员卡中的一种或几种应用。
本发明还提出了一种实现线上交易安全的方法,包括以下步骤:
第一设备与第二设备建立无线连接,所述第二设备为移动设备或电脑;
所述第一设备对所述第二设备的身份认证信息进行确认,通过则回传应答信息,所述第二设备进入线上支付业务客户端,不通过则停止;
所述第一设备接收所述第二设备的转账信息,对所述转账信息做数字签名并回传至所述第二设备用于交易。
根据本发明的实现线上交易安全的方法,进一步,身份认证信息和/或 对交易数据进行数字签名处理需要用户进行确认,确认方式包括按键、语音识别和指纹识别方式。
本发明还提出了一种实现线上交易安全的设备,包括:
安全模块,用于对用户身份进行认证和对用户的转账信息做数字签名,所述线上支付业务包括微信支付、支付宝支付、扫码支付、网银支付;
射频模块,用于与移动设备或电脑建立连接并进行数据通信;
主控模块,所述主控模块与所述电源模块、所述安全模块、所述射频模块和所述非接触模块连接,用于控制所述设备的工作状态。
本发明的有益效果在于:
本发明与传统的智能可穿戴设备相比,可作为线上网银业务、电子支付安全工具和线下支付设备。将可穿戴设备与安全认证设备相结合,可以免去独立的安全认证设备还可支持电子现金等金融业务。
在本发明提供的的实现线上线下交易安全的设备的线上应用中,与安全认证设备U盾相比,其采用无线射频技术,实现与移动终端的互联,保证网银业务安全。
目前支付宝、微信等第三方支付平台刷卡、扫码等支付方式便捷但是安全性较低,通常只进行小额支付或通过输入支付密码来确定使用者身份。在交易流程中增加本发明的设备认证过程,可以提高支付的安全等级,有利于增大现有支付方式的业务范围。
附图说明
图1示出了根据本发明实施例提供的实现线上线下交易安全的设备的示意图;
图2示出了本发明实施例的线上网银转账业务流程图。
具体实施方式
为了更清楚地说明本发明实施例和技术方案,下面将结合附图及实施例对本发明的技术方案进行更详细的说明,显然,所描述的实施例是本发明的一部分实施例,而不是全部实施例。基于本发明的实施例,本领域普通技术人员在不付出创造性劳动的前提下所获得的所有其他实施例,都属于本发明保护的范围。
图1示出了根据本发明实施例提供的实现线上线下交易安全的设备的示意图。如图1所示,所述设备10包括:电源模块101、安全模块103、射频模块104、非接触模块105、主控模块102,所述主控模块102与所述电源模块101、所述安全模块103、所述射频模块104、所述非接触模块105连接,用于控制所述设备的工作状态。
所述电源模块101包括电池,电源模块101用于为整个设备10供电。电源模块101中的电池可以是一次性电池或充电电池中的一种。进一步,充电电池方案中电源模块101内还可以包括电池保护单元,其可以避免电池由于外部压力或其它原因导致损坏,以保证供电的稳定性以及增加电池的使用寿命。另外,也可以不使用电源模块,利用非接触式取电的方式为整个设备10进行供电。
所述安全模块103包括安全算法加密单元及安全算法解密单元。在所述实现线上线下交易安全的设备10的线上交易过程中,安全模块103可以对用户提供的身份信息进行确认,并在确认用户身份的合法性之后,对接收的交易数据进行数字签名。在线下交易过程中,安全模块103可以为非接触模块105提供安全认证,也可以不提供。
所述射频模块104包括射频电路单元及射频天线,其用于射频信号的收发和处理,并且提供与主控模块102的数据传输及控制接口。所述射频电路单元用于射频信号处理,所述射频信号处理可以包括滤波、放大、调制/解调、 编码/解码、模数/数模转换的一种或几种。所述射频天线用于接受和发送射频信号。在所述实现线上线下交易安全的设备10的使用过程中,所述射频模块可以通过蓝牙等射频通道与手机等设备建立连接,从而与手机进行数据通信,收发用户的身份认证信息以及交易数据,进一步,还可以通过数据通讯,接收更新程序的数据以及加载应用的数据。
所述主控模块102包括接口控制单元、数据处理单元、存储单元,用于控制实现线上线下交易安全的设备10的工作状态。所述设备10的工作状态包括所述设备的系统工作时序、各模块工作状态以及收发数据的处理和存储。所述接口控制单元用于提供与其他模块的物理连接接口的配置和开关控制。所述数据处理单元用于将发送和接收的数据进行透传或编/解码处理,还可以包含其他数据处理方法。所述存储单元包括程序存储单元和数据存储单元。存储单元为掩膜只读存储器、可编程只读存储器、可擦可编程只读存储器、电可擦可编程只读存储器、快闪存储器中的一种。所述主控模块在所述设备10的使用过程中,用于控制电源模块的供/断电,指示安全模块通过射频模块进行用户身份认证信息和交易数据的收发,并根据接收的数据对所述实现线上线下交易安全的设备进行程序更新和应用加载。
所述非接触模块105包括NFC芯片及电路、天线线圈。所述NFC芯片及电路用于收发信号及数据的处理,并提供与安全模块和主控模块的数据传输及控制接口。所述天线线圈用于NFC信号的发送和接收。所述非接触模块105在所述实现线上线下交易安全的设备的使用过程中,既可与安全模块103配合,用于实现线下交易的安全,也可以加载公交、门禁、停车、会员卡等应用中的一种或几种应用。另外,非接触模块也可以单独使用,实现线下支付业务。
此外,上述本发明实施例提供的实现线上线下交易安全的设备还可以包括显示屏及按键模块、振动及传感模块、语音识别模块、指纹识别模块中的 一种或全部,其中:
所述显示屏及按键模块至少包括显示屏及按键硬件单元,用于提供与安全控制模块的数据传输及控制接口。具体地,所述显示屏硬件单元可以为发光二级管阵列、液晶显示屏、电子纸显示屏的一种。此外,所述显示屏硬件单元还可以包括显示屏驱动电路单元。所述按键硬件单元至少包括机械按键或触摸按键的一种。此外,所述按键硬件单元还可以包括按键驱动电路单元;
所述振动及传感模块至少包括一个振动马达和一个加速度传感器,用于振动提醒及运动监测,提供与安全模块103和主控模块102的数据传输及控制接口,对来自主控模块的指令做出响应;
所述语音识别模块可预先将用户语音提取特征参数并进行存储,使用者语音特征参数需与已存储合法用户语音对比来确认用户身份的合法性。通过语音识别方式,可以大大增加线上线下交易的安全性和可靠性。
所述指纹识别模块可用于对线上线下交易提供安全认证,通过预先将合法用户指纹特征参数提取并进行存储,使用者指纹特征参数需与已存储合法用户指纹对比来确认用户身份的合法性。通过指纹识别方式,可以大大增加线上线下交易的安全性和可靠性。
进一步,如上所述的安全模块103和主控模块102可集成为安全控制模块,所述安全控制模块可以完成如上所述安全模块103的对用户身份认证信息的确认,交易数据的签名,以及所述主控模块102的控制整个实现线上线下交易安全的设备的功能。
本实施例提供的实现线上线下交易安全的设备可设置为可穿戴的形式。其与传统的智能可穿戴设备相比,可作为线上网银业务、电子支付安全工具和线下支付设备。将可穿戴设备与安全认证设备相结合,可以免去独立的安全认证设备还可支持电子现金等金融业务。
在本实施例提供的实现线上线下交易安全的设备的线上应用中,与安全 认证设备U盾相比,其采用无线射频技术,实现与移动终端的互联,保证网银业务安全。
目前支付宝、微信等第三方支付平台刷卡、扫码等支付方式便捷但是安全性较低,通常只进行小额支付或通过输入支付密码来确定使用者身份。在交易流程中增加本发明的设备认证过程,可以提高支付的安全等级,有利于增大现有支付方式的业务范围。
本实施例采用如下方法实现线上交易安全的安全,该方法包括以下步骤:
第一设备与第二设备建立无线连接,所述第二设备为移动设备或电脑;
所述第一设备对所述第二设备的身份认证信息进行确认,通过则回传应答信息,所述第二设备进入线上支付业务客户端,不通过则停止;
所述第一设备接收所述第二设备的转账信息,对所述转账信息做数字签名并回传至所述第二设备用于交易。
进一步,身份认证信息和/或对交易数据进行数字签名处理需要用户进行确认,确认方式包括按键和指纹识别方式。
此外,本实施例也可以作为实现线上交易安全的设备,其包括以下模块:
安全模块,用于对用户身份进行认证和对用户的转账信息做数字签名,所述线上支付业务包括微信支付、支付宝支付、扫码支付、网银支付;
射频模块,用于与移动设备或电脑建立连接并进行数据通信;
主控模块,所述主控模块与所述电源模块、所述安全模块、所述射频模块、所述非接触模块连接,用于控制所述设备的工作状态。
图2示出了本发明线上网银转账业务流程图。
首先,用户打开设备等待与手机建立连接。具体的,用户可通过手机蓝牙搜索到要连接的设备。
与手机建立连接后,设备收到手机发来的身份认证信息,并回传应答信息确认,认证通过则进入手机客户端业务界面。认证不通过则停止。
认证通过后,用户选择转账业务并填写转账信息,转账信息经处理后通过蓝牙发送至设备做数字签名,用户设备做数字签名并返回签名数据至用户手机。
手机客户端通过网络连接到后台服务器,对签名数据验签通过执行转账。交易成功,设备收到返回结果,认为此次交易结束。
进一步,在数字签名处理过程中,用户可以确认数据是否被篡改、是否进行此次交易,确认的信息需要做数字签名并传回手机客户端,进一步提高支付安全。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用硬件实施例、软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程 或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
再次说明,以上所述仅为本发明的实施例,并非因此限制本发明的专利范围,凡是利用本发明说明书及附图内容所作的等效结构或等效流程变换,例如各实施例之间技术特征的相互结合,或直接或间接运用在其他相关的技术领域,均同理包括在本发明的专利保护范围内。

Claims (10)

  1. 一种实现线上线下交易安全的设备,其特征在于,包括:
    安全模块,用于线上线下支付时进行安全认证,所述线上支付业务包括微信支付、支付宝支付、扫码支付或网银支付;
    射频模块,用于与移动设备或电脑建立连接并进行数据通信;
    非接触模块,所述非接触模块具有金融业务应用功能,用于线下支付业务;
    主控模块,所述主控模块与所述电源模块、所述安全模块、所述射频模块、所述非接触模块连接,用于控制所述设备的工作状态。
  2. 根据权利要求1所述的设备,其特征在于,其中所述安全模块和所述主控模块可以集成为安全控制模块。
  3. 根据权利要求1所述的设备,其特征在于,所述设备还包括电源模块,或者所述设备能够使用非接触方式取电。
  4. 根据权利要求1所述的设备,其特征在于,其中非接触模块单独能够进行线下支付业务。
  5. 根据权利要求1所述的设备,其特征在于,所述设备还包括显示屏模块、按键模块、振动及传感模块、语音识别模块、指纹识别模块中的一种或几种。
  6. 根据上述权利要求1所述的设备,其特征在于,所述设备设置为可佩戴的形式。
  7. 根据上述权利要求1所述的设备,其特征在于,所述设备能够加载公交、门禁、停车、会员卡中的一种或几种应用。
  8. 一种实现线上交易安全的方法,其特征在于,包括以下步骤:
    第一设备与第二设备建立无线连接,所述第二设备为移动设备或电脑;
    所述第一设备对所述第二设备的身份认证信息进行确认,通过则回传应答信息,所述第二设备进入线上支付业务客户端,不通过则停止;
    所述第一设备接收所述第二设备的转账信息,对所述转账信息做数字签名并回传至所述第二设备用于交易。
  9. 根据权利要求8所述的方法,其特征在于,身份认证信息和/或对交易数据进行数字签名处理需要用户进行确认,确认方式包括按键、语音识别和指纹识别方式。
  10. 一种实现线上交易安全的设备,其特征在于,包括:
    安全模块,用于对用户身份进行认证和对用户的转账信息做数字签名,所述线上支付业务包括微信支付、支付宝支付、扫码支付或网银支付;
    射频模块,用于与移动设备或电脑建立连接并进行数据通信;
    主控模块,所述主控模块与所述电源模块、所述安全模块、所述射频模块和所述非接触模块连接,用于控制所述设备的工作状态。
PCT/CN2016/102851 2015-12-15 2016-10-21 实现线上线下交易安全的设备和方法 WO2017101584A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510929888.1 2015-12-15
CN201510929888.1A CN106886897A (zh) 2015-12-15 2015-12-15 实现线上线下交易安全的设备和方法

Publications (1)

Publication Number Publication Date
WO2017101584A1 true WO2017101584A1 (zh) 2017-06-22

Family

ID=59055692

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/102851 WO2017101584A1 (zh) 2015-12-15 2016-10-21 实现线上线下交易安全的设备和方法

Country Status (3)

Country Link
CN (1) CN106886897A (zh)
TW (1) TW201723944A (zh)
WO (1) WO2017101584A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108269086A (zh) * 2017-12-12 2018-07-10 福州汇思博信息技术有限公司 一种扫码支付的方法及系统
CN113240414A (zh) * 2021-06-18 2021-08-10 中国银行股份有限公司 支付唤醒系统及工作方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN203573402U (zh) * 2013-07-18 2014-04-30 深圳市文鼎创数据科技有限公司 智能金融终端
CN104331796A (zh) * 2014-11-04 2015-02-04 北京握奇智能科技有限公司 一种可穿戴设备及其工作方法
CN104881779A (zh) * 2015-06-17 2015-09-02 恒宝股份有限公司 一种移动融合支付装置、系统及支付方法
CN204667407U (zh) * 2015-06-09 2015-09-23 武汉天喻信息产业股份有限公司 一种实现安全身份认证的可穿戴设备及系统

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104850990A (zh) * 2015-05-27 2015-08-19 拉卡拉支付有限公司 一种支付方法及系统、key终端和key支撑系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN203573402U (zh) * 2013-07-18 2014-04-30 深圳市文鼎创数据科技有限公司 智能金融终端
CN104331796A (zh) * 2014-11-04 2015-02-04 北京握奇智能科技有限公司 一种可穿戴设备及其工作方法
CN204667407U (zh) * 2015-06-09 2015-09-23 武汉天喻信息产业股份有限公司 一种实现安全身份认证的可穿戴设备及系统
CN104881779A (zh) * 2015-06-17 2015-09-02 恒宝股份有限公司 一种移动融合支付装置、系统及支付方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108269086A (zh) * 2017-12-12 2018-07-10 福州汇思博信息技术有限公司 一种扫码支付的方法及系统
CN113240414A (zh) * 2021-06-18 2021-08-10 中国银行股份有限公司 支付唤醒系统及工作方法

Also Published As

Publication number Publication date
CN106886897A (zh) 2017-06-23
TW201723944A (zh) 2017-07-01

Similar Documents

Publication Publication Date Title
US10140479B1 (en) Systems and methods for a wearable user authentication factor
US10133979B1 (en) Wearable computing device-powered chip-enabled card
KR102089201B1 (ko) 지불 방법 및 시스템
KR101788149B1 (ko) 오티피 생성 방법
EP3756116B1 (en) Efficient biometric self-enrollment
US9626673B2 (en) Financial transaction based on device-to-device communications
US20150213452A1 (en) Electronic payment system and method
CN107657441B (zh) 自助交易方法、系统、服务器及移动终端
CN113641967B (zh) 一种可穿戴设备解锁终端设备的方法及通信系统
TWI626607B (zh) Smart card with dynamic token OTP function and working method thereof
KR101541600B1 (ko) 코드 이미지를 이용한 매체 기반 거래 연동 오티피 제공 방법
WO2017101584A1 (zh) 实现线上线下交易安全的设备和方法
CN104933379A (zh) 身份证信息获取方法、装置及系统
CN106886728A (zh) 一种智能卡的读取装置和方法
KR101103189B1 (ko) 범용 가입자 식별 모듈 정보를 이용한 공인 인증서 발급방법 및 시스템과 이를 위한 기록매체
KR101187932B1 (ko) 대리인 무선단말을 이용한 결제 처리 시스템과 이를 위한 무선단말
KR102172855B1 (ko) 사용자의 휴대형 매체를 이용한 매체 분리 기반 서버형 일회용코드 제공 방법
KR101192485B1 (ko) 코드 이미지를 이용한 개인 간 송금 방법 및 시스템
KR20160006646A (ko) 엔에프씨오티피카드를 이용한 비대면 거래 인증 방법
KR20110005616A (ko) 생체 인식을 이용한 무선 오티피 운영 방법 및 시스템과 이를 위한 무선단말 및 기록매체
US20200193433A1 (en) System and method for securely processing verification data
CN108665267A (zh) 安全认证装置及系统
KR101592897B1 (ko) Nfc 보안 디지털 시스템, 상기 보안 디지털 시스템과 페어를 이루는 페어 시스템, 및 그 제공방법
KR102165105B1 (ko) 생체정보를 이용한 지정 서비스 제공 방법
KR20170142983A (ko) 생체정보를 이용한 지정 서비스 제공 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16874642

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 25/10/18)

122 Ep: pct application non-entry in european phase

Ref document number: 16874642

Country of ref document: EP

Kind code of ref document: A1