WO2017190633A1 - 验证金融卡用户身份可靠性的方法及装置 - Google Patents
验证金融卡用户身份可靠性的方法及装置 Download PDFInfo
- Publication number
- WO2017190633A1 WO2017190633A1 PCT/CN2017/082457 CN2017082457W WO2017190633A1 WO 2017190633 A1 WO2017190633 A1 WO 2017190633A1 CN 2017082457 W CN2017082457 W CN 2017082457W WO 2017190633 A1 WO2017190633 A1 WO 2017190633A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- financial card
- authentication
- card
- response
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/60—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
Definitions
- the present invention relates to the field of information security, and in particular, to a method for verifying the reliability of a financial card user identity, and a device for verifying the reliability of a financial card user identity.
- an object of the embodiments of the present invention is to provide a method for verifying the reliability of a financial card user identity, and a device for verifying the reliability of a financial card user identity, which can quickly and reliably perform the legality of the identity of the financial card user. Verify and protect information security.
- the embodiment of the present invention adopts the following technical solutions:
- a method for verifying the reliability of a financial card user identity comprising the steps of:
- the ciphertext response information including a card number letter of the financial card
- the first application ciphertext obtained by encrypting the response data by the financial card with the stored private key
- the verification request including the first application ciphertext, the card number information, the transaction password information, and the response data;
- the verification response includes a first authentication result and first authentication data
- the first authentication result includes: the card issuer server acquires the stored and the a card key consistency obtained by comparing the private key corresponding to the card number information, using the private key to encrypt the response data, obtaining the second application ciphertext, and comparing the second application ciphertext with the first application ciphertext a verification result, a password correctness verification result obtained by verifying the transaction password information, where the first authentication data includes the second application ciphertext and a verification result identifier;
- a method for verifying the reliability of a financial card user identity comprising the steps of:
- a method for verifying the reliability of a financial card user identity comprising the steps of:
- the verification request includes the first application ciphertext, the card number information of the financial card, and the payment request Easy password information and response data;
- the verification response including a first authentication result and first authentication data
- the first authentication result including the card person consistency check result, the password correctness check result, and the first authentication
- the data includes the second application ciphertext and a verification result identifier
- the terminal sends the first authentication data to the financial card, and after receiving the second authentication result returned by the financial card, according to the first authentication result, the second The result of the certification determines the legality of the identity of the financial card user.
- a device for verifying the reliability of a financial card user identity comprising:
- a data obtaining module configured to acquire data corresponding to a data type of data sent by the financial card requesting the terminal
- a first information interaction module configured to send data obtained by the data acquisition module to the financial card as response data, and receive ciphertext response information returned by the financial card, where the ciphertext response information includes The card number information of the financial card, the first application ciphertext obtained by encrypting the response data by using the private key stored by the financial card, and transmitting the first authentication data received by the second information interaction module of the terminal to the financial card, And receiving a second authentication result returned by the financial card;
- a password information receiving module configured to receive transaction password information of the financial card input by a user
- a second information interaction module configured to send an authentication request to the card issuer server of the financial card, where the verification request includes the first application ciphertext, the card number information, the transaction password information, and the response data And receiving a verification response returned by the card issuer server according to the verification request;
- a legality determining module configured to determine, according to the first authentication result and the second authentication result, the legality of the identity of the financial card user
- the verification response includes a first authentication result and a first authentication result, where the first authentication result includes: the card issuer server acquires the stored private key corresponding to the card number information, and uses the private key to the response data. Performing encryption to obtain the second application ciphertext, comparing the second application ciphertext with the first application ciphertext, and obtaining the password obtained by verifying the transaction password information. a result of the correctness check, the first authentication data includes the second application ciphertext and a verification result identifier;
- the second authentication result is processed by the financial card to process the verification result identifier and the first application ciphertext to obtain process data, and encrypt the process data with the stored private key to obtain the second authentication data, and then The second authentication data is compared with the first authentication data to determine.
- a device for verifying the reliability of a financial card user identity comprising:
- the card end information interaction module receives the response data sent by the terminal, and the response data includes data corresponding to the data type acquired by the terminal according to the data type of the data that the financial card requires the terminal to send, and returns the password to the terminal.
- the ciphertext response information includes the card number information of the stored financial card, the first application ciphertext generated by the card end encryption module, and the first authentication data sent by the terminal, where the first authentication data includes a second application ciphertext and a verification result identifier, and sending the second authentication result to the terminal, where the terminal determines the financial card according to the second authentication result determined by the authentication module and the first authentication result returned by the card issuer server The legality of the user's identity;
- a process data determining module configured to process the verification result identifier and the first application ciphertext to obtain process data
- a card end encryption module configured to encrypt the response data by using the stored private key to obtain the first application ciphertext, and encrypt the process data by using the stored private key to obtain second authentication data;
- an authentication module configured to compare the second authentication data with the first authentication data to determine the second authentication result.
- a device for verifying the reliability of a financial card user identity comprising:
- the server information interaction module is configured to receive the verification request sent by the terminal, where the verification request includes the first application ciphertext, the card number information of the financial card, the transaction password information, and the response data, and the verification response generated by the verification response generation module is Transmitting, by the terminal, the first authentication data in the verification response is sent by the terminal to the financial card, and after receiving the second authentication result returned by the financial card, according to the first authentication result in the verification response, the second authentication The result determines the legality of the identity of the financial card user;
- a card consistency check module configured to obtain a private key corresponding to the card number information, encrypt the response data by using the private key to obtain a second application ciphertext, and the second application ciphertext and the The first application ciphertext is compared to obtain a cardholder consistency check result;
- a password verification module configured to verify the transaction password information to obtain a password correctness verification result
- a verification response generation module configured to generate the verification response, the verification response including a first authentication result and a
- the first authentication result includes the card person consistency check result and the password correctness check result
- the first authentication data includes the second application ciphertext and the verification result identifier.
- the existing financial card is combined with the terminal (such as a smart phone), so that the identity of the financial card user can be completed conveniently, quickly and reliably.
- the verification of the issue protects the information security by avoiding the security risks caused by fraud.
- the method and device for verifying the reliability of the financial card user identity according to the embodiment of the present invention can be applied to the field of mobile payment, and the NFC technology is used to verify the identity of the user of the financial card, thereby improving the security of the mobile payment.
- FIG. 1 is a schematic view showing the working environment of the solution of the present invention in an embodiment
- FIG. 2 is a schematic structural diagram of a terminal in an embodiment
- FIG. 3 is a schematic structural diagram of a card issuing side server in an embodiment
- FIG. 4 is a schematic flow chart of a method for verifying the reliability of a financial card user identity according to the present invention in an embodiment
- FIG. 5 is a schematic flow chart of a method for verifying the reliability of a financial card user identity according to the present invention in another embodiment
- FIG. 6 is a schematic flow chart of a method for verifying the reliability of a financial card user identity according to the present invention in another embodiment
- FIG. 7 is a schematic diagram of an interaction process when verifying user identity reliability in a specific example
- FIG. 8 is a schematic structural diagram of an apparatus for verifying the reliability of a financial card user identity according to the present invention in an embodiment.
- FIG. 1 shows a schematic diagram of the working environment in one embodiment of the invention.
- the working environment involves a financial card 101 (such as a financial IC card, or a financial card with information storage function), a terminal 102 (such as a smart phone), and a card issuer server 103, and may also involve a cloud payment platform 100, and the financial card 101 passes through
- the field communication method (NFC) interacts with the terminal 102 to implement verification of the identity reliability of the financial card 101 side, and the terminal 102 directly interacts with the card issuer server 103 via the network, or via the cloud payment platform 100 and the issuer server 103. Interacting to implement identity reliability verification of the sender side server 103 side.
- the solution of the embodiment of the present invention relates to the terminal 102 in need of using a financial card. 101-time scheme for verifying the reliability of the financial card user identity.
- the terminal includes a processor, a power supply module, a storage medium, a memory, a communication interface, a display screen, and an input device connected through a system bus.
- the storage medium of the terminal stores an operating system and a device for verifying the reliability of the financial card user identity, and the device for verifying the reliability of the financial card user identity is used to implement a method for verifying the reliability of the financial card user identity.
- the communication interface of the terminal is used for connection communication with the card issuer server 103 or the cloud payment platform 100.
- the input device of the terminal is configured to receive input information of the user, such as transaction password information in the embodiment of the present invention. Input devices can vary based on the type of user terminal.
- the user terminal may be a mobile terminal, such as a mobile phone, a tablet computer, or the like; or other devices having the above structure.
- the server 103 includes a processor, a power supply module, a storage medium, a memory, and a communication interface connected through a system bus.
- the storage medium of the server 103 stores an operating system, a database, and a device for verifying the reliability of the financial card user identity.
- the device is used to cooperate with the terminal 102 and the financial card 101, and implements a verification that the financial card user identity is reliable.
- Sexual approach The communication interface of the server 103 is used to connect and communicate with the terminal 102 or the cloud payment platform 100.
- FIG. 4 is a schematic flowchart of a method for verifying the reliability of a financial card user identity in an embodiment.
- the processing procedure of the terminal 102 is taken as an example for description.
- the method in this embodiment includes:
- Step S401 Acquire data corresponding to the data type of the data that the financial card requires the terminal to send, and send the obtained data as response data to the financial card;
- Step S402 Receive ciphertext response information returned by the financial card, where the ciphertext response information includes card number information of the financial card, and the first obtained by the financial card encrypting the response data by using a stored private key Apply ciphertext;
- Step S403 Receive transaction password information of the financial card input by the user
- Step S404 Send an authentication request to the card issuer server of the financial card, where the verification request includes the first application ciphertext, the card number information, the transaction password information, and the response data;
- Step S405 Receive a verification response returned by the card issuer server according to the verification request, where the verification response includes a first authentication result and first authentication data, where the first authentication result includes: the card issuer server acquires the stored a private key corresponding to the card number information, using the private key to encrypt the response data to obtain a second application ciphertext After the second application ciphertext is compared with the first application ciphertext, the cardholder consistency (the financial card is consistent with the cardholder) verification result, and the transaction password information is verified. a password correctness check result, where the first authentication data includes the second application ciphertext and a verification result identifier;
- Step S406 Send the first authentication data to the financial card, and receive the financial card to process the verification result identifier and the first application ciphertext to obtain process data, and use the stored private key pair. After the process data is encrypted to obtain the second authentication data, the second authentication result is determined by comparing the second authentication data with the first authentication data;
- Step S407 Determine the legality of the identity of the financial card user according to the first authentication result and the second authentication result.
- the existing financial card combined with the terminal can complete the verification of the identity and distribution of the financial card user conveniently, quickly and reliably, and avoids Information security is protected by the security risks posed by fraud.
- the terminal can interact with the financial card through Near Field Communication (abbreviated as NFC, short-range wireless communication technology).
- NFC Near Field Communication
- the above response data can also be obtained based on the demand of the financial card.
- the method in this embodiment may further include:
- Step S4002 Send an application command to the financial card in the near field communication range by near field communication;
- Step S4003 Receive application command response information returned by the financial card based on the application command, where the application command response information includes information of a data type of data required to be sent by the terminal.
- the terminal interacts with the financial card through near field communication, thereby ensuring the security of the communication process between the financial card and the terminal.
- the financial card can be communicated to the terminal when needed.
- the method may further include:
- Step S4001 Presenting prompt information for bringing the financial card close to the near field communication sensing area of the terminal.
- FIG. 5 is a schematic flowchart of a method for verifying the reliability of a financial card user identity in another embodiment.
- the processing procedure of the financial card 101 is taken as an example for description.
- the method in this embodiment includes:
- Step S501 Receive response data sent by the terminal, where the response data includes data corresponding to the data type acquired by the terminal according to the data type of the data that the financial card requires the terminal to send;
- Step S502 Encrypt the response data with the stored private key to obtain a first application ciphertext, and return ciphertext response information to the terminal, where the ciphertext response information includes card number information of the stored financial card, First application ciphertext;
- Step S503 Receive first authentication data sent by the terminal, where the first authentication data includes a second application ciphertext and a verification result identifier;
- Step S504 Process the verification result identifier and the first application ciphertext to obtain process data, encrypt the process data with the stored private key to obtain second authentication data, and compare the second authentication data with the Determining the second authentication result by comparing the first authentication data;
- Step S505 Send the second authentication result to the terminal, and determine, by the terminal, the legality of the identity of the financial card user according to the second authentication result and the first authentication result returned by the card issuer server.
- the terminal can interact with the financial card through Near Field Communication (abbreviated as NFC, short-range wireless communication technology).
- NFC Near Field Communication
- the above response data can also be obtained based on the demand of the financial card.
- the method in this embodiment may further include:
- Step S5001 receiving an application command sent by the terminal through near field communication
- Step S5002 Return application command response information to the terminal according to the application command, where the application command response information includes information of a data type of data required to be sent by the terminal.
- FIG. 6 is a schematic flowchart diagram of a method for verifying the reliability of a financial card user identity in another embodiment.
- the processing of the card issuer server 103 is taken as an example for description.
- the method in this embodiment includes:
- Step S601 Receive an authentication request sent by the terminal, where the verification request includes a first application ciphertext, a card number information of the financial card, transaction password information, and response data.
- Step S602 Acquire a private key corresponding to the card number information, encrypt the response data by using the private key to obtain a second application ciphertext, and compare the second application ciphertext with the first application ciphertext. Obtaining the cardholder consistency check result;
- Step S603 Perform verification on the transaction password information to obtain a password correctness verification result
- Step S604 Generate a verification response, where the verification response includes a first authentication result and first authentication data, where the first authentication result includes the card person consistency check result, the password correctness check result, and the The first authentication data includes the second application ciphertext and a verification result identifier;
- Step S605 returning the verification response to the terminal, after the terminal sends the first authentication data to the financial card, and after receiving the second authentication result returned by the financial card, according to the first authentication result, the The second authentication result determines the legality of the financial card user identity.
- FIG. 7 shows a schematic diagram of the interaction flow when verifying the identity of the user in a specific example.
- the terminal 102 is a mobile terminal as an example, and those skilled in the art can understand that the present invention can be implemented.
- the related functions of the authentication scheme in the embodiment scheme are equally applicable to other terminals than the mobile terminal.
- the mobile terminal may first give prompt information for bringing the financial card close to the near field communication sensing area of the mobile terminal, and the prompt information may be performed in any possible manner, for example, related to the mobile terminal. Display on the display interface, voice reminder by voice, display of display interface and voice reminder at the same time.
- the user can place or close the financial card to the sensing area of the near field communication of the mobile terminal, and the mobile terminal transmits an application command to the financial card in the near field communication range through the near field communication.
- the financial card After receiving the application command, the financial card activates the related application selected by the mobile terminal, causes the financial card to be in a start state, and returns application command response information to the mobile terminal, where the application command response information includes a data type of data required to be sent by the terminal.
- the application command response information includes a data type of data required to be sent by the terminal.
- Information In a specific example, the information of the data type in the application command response information may be sent in the form of a data type list.
- the data type may include: transaction time, transaction type, transaction amount, transaction currency code, random number, terminal performance. .
- transaction time may include: transaction time, transaction type, transaction amount, transaction currency code, random number, terminal performance.
- the mobile terminal After receiving the command response information, the mobile terminal acquires data corresponding to the data type of the data that the financial card requests the terminal to send, and transmits the obtained data composition response data to the financial card. As described above, when the transmission of the response data is transmitted, it is also transmitted to the financial card by Near Field Communication (NFC). In a specific example, the obtained data may be sent to the financial card as response data in the form of a data list.
- NFC Near Field Communication
- the financial card After receiving the response data, the financial card encrypts the response data with the private key stored by the financial card itself to obtain the application ciphertext (referred to as the first application ciphertext for convenience to distinguish from other ciphertexts), and moves to the mobile card.
- the terminal returns ciphertext response information, where the ciphertext response information includes card number information of the financial card stored by the financial card, and the first application ciphertext.
- the mobile terminal may give a prompt message for the user to input the transaction password of the financial card, and the prompt information may be prompted by voice, or may be prompted directly through the password input interface, or may be The password input interface is simultaneously performed with the voice prompt, and receives the transaction password information of the financial card input by the user through the password input interface or the password input device.
- the mobile terminal sends an authentication request to the card issuer server of the financial card.
- the mobile terminal sends the verification request to the cloud payment platform, and the cloud payment platform sends the verification request to the card issuer. server.
- the verification request includes: the first application ciphertext, the card number information, the transaction password information, and the response data.
- the mobile terminal may send the verification request after being encrypted, and correspondingly, the issuer server receives the encrypted verification request. After that, perform the subsequent operations.
- the specific encryption and decryption mode may be performed by using any possible encryption and decryption mode, which is not specifically limited in the embodiment of the present invention. For the purpose of simplicity of explanation, the encryption and decryption process is not described in the following description.
- the card issuing party After receiving the verification request, the card issuing party obtains the stored private key corresponding to the card number information in the verification request, and uses the private key to encrypt the response data in the verification request to obtain the application ciphertext (for convenience, it is called The second application ciphertext is compared, and the second application ciphertext is compared with the first application ciphertext in the verification request, thereby obtaining a cardholder consistency check result.
- the obtained second application ciphertext should be dense with the first application.
- the text is consistent, that is, in the case that the second application ciphertext is consistent with the first application ciphertext, the card issuer can determine that the card person is consistent, otherwise it is inconsistent.
- the issuer server further performs transaction password information in the verification request based on the account information in the verification request.
- the verification determines whether the transaction password in the verification request is consistent with the stored information corresponding to the account information, thereby obtaining a password correctness verification result.
- the way the password is verified can be done in any way that is currently available and may occur in the future.
- the card issuer server generates a verification response and sends the verification response to the mobile terminal or to the mobile terminal through the cloud transaction platform.
- the first authentication result includes the cardholder consistency check result and the password correctness check result
- the first authentication data includes the second application password.
- the text and the generated verification result identifier may be any possible manner, for example, the verification result identifier may be the last byte in the first authentication data or is in front of the first authentication data. Bytes.
- the mobile terminal After receiving the verification response, the mobile terminal sends the first authentication data to the financial card.
- the financial card After receiving the verification response, the financial card processes the verification result identifier in the first authentication data and the first application ciphertext generated by itself to obtain process data, and encrypts the process data by using the private key stored by the financial card itself.
- the second authentication data is compared with the first authentication data to determine a second authentication result, and the second authentication result is sent to the mobile terminal.
- the financial card may process the verification result identifier and the first application ciphertext in any manner to obtain process data.
- the verification result identifier may be XORed with the first application ciphertext to obtain the foregoing process data.
- the mobile terminal After receiving the second authentication result, the mobile terminal combines the second authentication result with the first authentication result to determine the legality of the user identity.
- the first authentication result represents the authentication result of the card issuer server to the cardholder consistency
- the second authentication result represents the authentication result of the financial card cardholder consistency. The combination of the two further strengthens the legality of the financial card user identity. Verification of reliability.
- the mobile terminal can further determine the transaction payment result and display the transaction payment result to inform the user of the authentication result and the transaction payment result.
- FIG. 8 is a schematic structural diagram of a device in a specific example.
- the device 81 which is provided on the financial card
- the device 82 provided on the terminal
- the device 83 provided on the card issuer server
- the apparatus for verifying the reliability of the financial card user identity set on the terminal 82 includes:
- the data obtaining module 822 is configured to acquire data corresponding to the data type of the data that the financial card 81 requires the terminal 82 to send;
- the terminal first information interaction module 823 is configured to send the data obtained by the data obtaining module 822 as the response data to the financial card 81, and receive the ciphertext response information returned by the financial card 81, where the ciphertext response information includes the card number of the financial card 81.
- the first application ciphertext obtained by encrypting the response data by using the stored private key, and the first authentication data received by the terminal second information interaction module 825 is sent to the financial card 81 and received.
- the password information receiving module 824 is configured to receive transaction password information of the financial card 81 input by the user;
- the terminal second information interaction module 825 is configured to send an authentication request to the card issuer server 83 of the financial card, where the verification request includes the first application ciphertext, the card number information, the transaction password information, and the response data, and receive the card issuer.
- the verification response returned by the server 83 according to the verification request;
- the legality determining module 826 is configured to determine the legality of the identity of the financial card user according to the first authentication result and the second authentication result.
- the verification response includes a first authentication result and a first authentication result.
- the first authentication result includes: the card issuer server acquires the stored private key corresponding to the card number information, and encrypts the response data by using the private key to obtain a second After the ciphertext is applied, the card application consistency check result obtained by comparing the second application ciphertext with the first application ciphertext, and the password correctness verification result obtained by verifying the transaction password information, the first The authentication data includes the second application ciphertext and the verification result identifier;
- the second authentication result is obtained by the financial card processing the verification result identifier and the first application ciphertext to obtain process data, and encrypting the process data with the stored private key to obtain the second authentication data, and then The second authentication data is compared with the first authentication data to determine.
- the apparatus for verifying the reliability of the financial card user identity of the financial card 81 includes:
- the card end information interaction module 811 receives the response data sent by the terminal 82, and the response data includes data corresponding to the data type acquired by the terminal according to the data type of the data that the financial card requires the terminal to send, and the data is sent to the terminal.
- the ciphertext response information includes card number information of the stored financial card, and the card end encryption module is generated
- the first application ciphertext is received; and the first authentication data sent by the terminal is received, the first authentication data includes a second application ciphertext and a verification result identifier, and the second authentication result is sent to the terminal Determining, by the terminal, the legality of the identity of the financial card user according to the second authentication result determined by the authentication module and the first authentication result returned by the card issuer server;
- the process data determining module 812 is configured to process the verification result identifier and the first application ciphertext to obtain process data.
- the card end encryption module 813 is configured to encrypt the response data by using the stored private key to obtain the first application ciphertext, and encrypt the process data by using the stored private key to obtain second authentication data.
- the authentication module 814 is configured to compare the second authentication data with the first authentication data to determine the second authentication result.
- the apparatus for verifying the reliability of the financial card user identity set by the card issuer server 83 includes:
- the server information interaction module 831 is configured to receive the verification request sent by the terminal, where the verification request includes the first application ciphertext, the card number information of the financial card, the transaction password information, and the response data, and the verification response generated by the verification response generation module Sending to the terminal, after the first authentication data in the verification response is sent by the terminal to the financial card, and receiving the second authentication result returned by the financial card, according to the first authentication result in the verification response, the second The result of the certification determines the legality of the identity of the financial card user;
- the card consistency check module 832 is configured to obtain a private key corresponding to the card number information, encrypt the response data by using the private key to obtain a second application ciphertext, and use the second application ciphertext and the The first application ciphertext is compared to obtain a cardholder consistency check result;
- the password verification module 833 is configured to perform verification on the transaction password information to obtain a password correctness verification result
- the verification response generation module 834 is configured to generate the verification response, where the verification response includes a first authentication result and first authentication data, where the first authentication result includes the cardholder consistency check result, and the password is correct As a result of the verification, the first authentication data includes the second application ciphertext and the verification result identifier.
- the terminal can interact with the financial card through Near Field Communication (abbreviated as NFC, short-range wireless communication technology).
- NFC Near Field Communication
- the above response data can also be obtained based on the demand of the financial card.
- the terminal first information interaction module 823 further sends an application command to the financial card in the near field communication range by the near field communication; and receives the application command response information returned by the financial card based on the application command, and the application command response
- the information includes information indicating the data type of the data transmitted by the terminal.
- the card end information interaction module 811 is further configured to receive an application command sent by the terminal through the near field communication, and return application command response information to the terminal according to the application command, where the application command response information includes Information about the data type of the data that the terminal is required to send.
- the terminal interacts with the financial card through near field communication, thereby ensuring the security of the communication process between the financial card and the terminal.
- the financial card can communicate with the terminal when needed.
- the device for verifying the reliability of the user identity of the financial card on the terminal 82 may further include:
- the information prompting module 821 is configured to give prompt information for bringing the financial card closer to the near field communication sensing area of the terminal.
- the apparatus of the embodiment of the present invention as described above can be applied to any field that needs to be combined with the financial card to verify the legality and reliability of the identity of the financial card user, such as transaction payment.
- the response data may include: transaction time, transaction type, transaction amount, transaction currency code, random number, terminal performance information.
- the apparatus for verifying the reliability of the user identity of the financial card on the terminal 82 may further include:
- the transaction result determining module 827 is configured to determine a transaction payment result according to the legality of the financial card user identity determined by the legality determination module 826, and display the transaction payment result.
- the program can be stored in a non-volatile computer readable storage.
- the program may be stored in a storage medium of the computer system and executed by at least one processor in the computer system to implement a flow comprising an embodiment of the methods as described above.
- the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Accounting & Taxation (AREA)
- General Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Finance (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
一种验证金融卡用户身份可靠性的方法及装置,该包括步骤:将金融卡需要的应答数据发送给金融卡,与金融卡交互获得包括卡号信息、第一应用密文的密文响应信息,接收用户输入的交易密码信息;将密文响应信息、交易密码信息以及应答数据发送给发卡方服务器,与发卡方服务器进行交互获得第一认证结果以及第一认证数据,将第一认证数据发送给金融卡,获得金融卡基于该第一认证数据进行验证后获得的第二认证结果,根据第一认证结果、第二认证结果,确定用户身份的合法性。本发明实施例方案,不需要额外的硬件设备,即可方便、快捷、可靠地完成对用户身份和发行的验证,避免了因欺诈所带来的安全风险,保护了信息安全。
Description
本发明涉及信息安全领域,特别是涉及一种验证金融卡用户身份可靠性的方法、一种验证金融卡用户身份可靠性的装置。
随着计算机网络的不断完善和互联网数据业务产业链的日益成熟,手机互联网用户不断增多,用户身份可靠性的验证也面临着严峻的挑战。例如,在金融领域,手机银行登录、转账、查询、理财等交易都面临着身份合法性验证,目前部分银行在手机银行转账时是通过银行额外发行的U盾来验证用户身份的合法性,不仅增加了成本,而且U盾还需要随身携带,易丢失,增加了用户的使用难度。还有其它的领域,例如个人信用征信平台,其验证用户身份合法性需要银行卡、U盾和手机,如果用户没有办理U盾就会存在一定的泄漏风险。此外,在移动支付领域,也同样面临用户身份合法性验证的难题。
对于移动设备端,手机网上银行、购物支付、转账等交易都面临用户身份合法性验证的问题,有些仅仅通过用户名和密码来实现验证,有些通过手机短信发送验证码来验证,这些方式都很容易被截取,手机也很容易被盗取,有些通过银行U盾或者发行加密模块验证用户身份的合法性,不仅增加了用户携带的难度,而且增加了用户的成本。
发明内容
基于此,本发明实施例的目的在于提供一种验证金融卡用户身份可靠性的方法、一种验证金融卡用户身份可靠性的装置,其可以快捷可靠地对金融卡用户的身份的合法性进行验证,保护信息安全。
为达到上述目的,本发明实施例采用以下技术方案:
一种验证金融卡用户身份可靠性的方法,包括步骤:
获取与金融卡要求终端发送的数据的数据类型对应的数据,并将获得的数据作为应答数据向所述金融卡发送;
接收所述金融卡返回的密文响应信息,所述密文响应信息包括所述金融卡的卡号信
息、所述金融卡用存储的私钥对所述应答数据进行加密获得的第一应用密文;
接收用户输入的所述金融卡的交易密码信息;
向所述金融卡的发卡方服务器发送验证请求,所述验证请求包括所述第一应用密文、所述卡号信息、所述交易密码信息以及所述应答数据;
接收所述发卡方服务器根据所述验证请求返回的验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括:所述发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文后、将该第二应用密文与所述第一应用密文进行比对获得的卡人一致性校验结果、对所述交易密码信息进行校验获得的密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;
将所述第一认证数据发送给所述金融卡,并接收所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定的第二认证结果;
根据所述第一认证结果、所述第二认证结果,确定金融卡用户身份的合法性。
一种验证金融卡用户身份可靠性的方法,包括步骤:
接收终端发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据;
用存储的私钥对所述应答数据进行加密获得第一应用密文,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、所述第一应用密文;
接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识;
将所述验证结果标识与所述第一应用密文进行处理获得过程数据,用存储的私钥对所述过程数据进行加密获得第二认证数据,并将该第二认证数据与所述第一认证数据进行对比确定第二认证结果;
将所述第二认证结果向所述终端发送,由所述终端根据所述第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性。
一种验证金融卡用户身份可靠性的方法,包括步骤:
接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交
易密码信息以及应答数据;
获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;
对所述交易密码信息进行校验获得密码正确性校验结果;
生成验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;
向所述终端返回所述验证响应,由所述终端将所述第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据所述第一认证结果、所述第二认证结果确定金融卡用户身份的合法性。
一种验证金融卡用户身份可靠性的装置,包括:
数据获取模块,用于获取与金融卡要求终端发送的数据的数据类型对应的数据;
终端第一信息交互模块,用于将所述数据获取模块获得的数据作为应答数据向所述金融卡发送,并接收所述金融卡返回的密文响应信息,所述密文响应信息包括所述金融卡的卡号信息、所述金融卡用存储的私钥对所述应答数据进行加密获得的第一应用密文;将终端第二信息交互模块接收的第一认证数据发送给所述金融卡,并接收所述金融卡返回的第二认证结果;
密码信息接收模块,用于接收用户输入的所述金融卡的交易密码信息;
终端第二信息交互模块,用于向所述金融卡的发卡方服务器发送验证请求,所述验证请求包括所述第一应用密文、所述卡号信息、所述交易密码信息以及所述应答数据;并接收所述发卡方服务器根据所述验证请求返回的验证响应;
合法性判定模块,用于根据所述第一认证结果、所述第二认证结果,确定金融卡用户身份的合法性;
所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括:所述发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文后、将该第二应用密文与所述第一应用密文进行比对获得的卡人一致性校验结果、对所述交易密码信息进行校验获得的密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;
第二认证结果由所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定。
一种验证金融卡用户身份可靠性的装置,包括:
卡端信息交互模块,接收终端发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、卡端加密模块生成的第一应用密文;以及接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识,并将所述第二认证结果向所述终端发送,由所述终端根据认证模块确定的第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性;
过程数据确定模块,用于将所述验证结果标识与所述第一应用密文进行处理,获得过程数据;
卡端加密模块,用于用存储的私钥对所述应答数据进行加密获得所述第一应用密文,并用存储的所述私钥对所述过程数据进行加密获得第二认证数据;
认证模块,用于将所述第二认证数据与所述第一认证数据进行对比确定所述第二认证结果。
一种验证金融卡用户身份可靠性的装置,包括:
服务端信息交互模块,用于接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交易密码信息以及应答数据,并将验证响应生成模块生成的验证响应向所述终端发送,由所述终端将验证响应中的第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据验证响应中的第一认证结果、所述第二认证结果确定金融卡用户身份的合法性;
卡人一致性校验模块,用于获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;
密码校验模块,用于对所述交易密码信息进行校验获得密码正确性校验结果;
验证响应生成模块,用于生成所述验证响应,所述验证响应包括第一认证结果以及第
一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识。
根据如上所述的本发明实施例的方案,其不需要额外的硬件设备,使用已有的金融卡结合终端(如智能手机),即可方便、快捷、可靠地完成对金融卡用户的身份和发行的验证,避免了因欺诈所带来的安全风险,保护了信息安全。本发明实施例的验证金融卡用户身份可靠性的方法和装置,可适用于移动支付等领域,结合NFC技术,实现对金融卡的用户身份进行验证,提高移动支付的安全性。
图1是一个实施例中本发明方案的工作环境示意图;
图2是一个实施例中终端的组成结构示意图;
图3是一个实施例中发卡方服务器的组成结构示意图;
图4是一个实施例中本发明的验证金融卡用户身份可靠性的方法的流程示意图;
图5是另一个实施例中本发明的验证金融卡用户身份可靠性的方法的流程示意图;
图6是另一个实施例中本发明的验证金融卡用户身份可靠性的方法的流程示意图;
图7是一个具体示例的验证用户身份可靠性时的交互流程示意图;
图8是一个实施例中本发明的验证金融卡用户身份可靠性的装置的结构示意图。
为使本发明的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本发明进行进一步的详细说明。应当理解,此处所描述的具体实施方式仅仅用以解释本发明,并不限定本发明的保护范围。
图1示出了本发明一个实施例中的工作环境示意图。该工作环境涉及金融卡101(如金融IC卡,或具有信息存储功能的金融卡片)、终端102(如智能手机)以及发卡方服务器103,同时还可能涉及云端支付平台100,金融卡101通过近场通信方式(NFC)与终端102进行交互,实现金融卡101方的身份可靠性的验证,终端102通过网络直接与发卡方服务器103进行交互,或者是经由云端支付平台100与发卡方服务器103进行交互,以实现发卡方服务器103方的身份可靠性验证。本发明实施例方案涉及的是终端102在需要使用金融卡
101时的对金融卡用户身份可靠性进行验证的方案。
终端102在一个实施例中的结构示意图如图2所示。该终端包括通过系统总线连接的处理器、供电模块、存储介质、内存、通信接口、显示屏幕和输入设备。其中,终端的存储介质中存储有操作系统和一种验证金融卡用户身份可靠性的装置,该验证金融卡用户身份可靠性的装置用于实现一种验证金融卡用户身份可靠性的方法。终端的通信接口用于与发卡方服务器103或者云端支付平台100连接通信。终端的输入设备用以接收用户的输入信息,例如本发明实施例中的交易密码信息。输入设备基于用户终端的类型的不同可以有所不同。用户终端可以是移动终端,比如手机、平板电脑等;也可以是其它具有上述结构的设备。
发卡方服务器103在一个实施例中的结构示意图如图3所示。服务器103包括通过系统总线连接的处理器、供电模块、存储介质、内存和通信接口。其中,服务器103的存储介质存储有操作系统、数据库和一种验证金融卡用户身份可靠性的装置,该装置用于与终端102、金融卡101配合工作,并实现一种验证金融卡用户身份可靠性的方法。服务器103的通信接口用于与终端102或者云端支付平台100进行连接和通信。
图4中示出了一个实施例中的验证金融卡用户身份可靠性的方法的流程示意图,该实施例中是以终端102的处理过程为例进行说明。
如图4所示,该实施例中的方法包括:
步骤S401:获取与金融卡要求终端发送的数据的数据类型对应的数据,并将获得的数据作为应答数据向所述金融卡发送;
步骤S402:接收所述金融卡返回的密文响应信息,所述密文响应信息包括所述金融卡的卡号信息、所述金融卡用存储的私钥对所述应答数据进行加密获得的第一应用密文;
步骤S403:接收用户输入的所述金融卡的交易密码信息;
步骤S404:向所述金融卡的发卡方服务器发送验证请求,所述验证请求包括所述第一应用密文、所述卡号信息、所述交易密码信息以及所述应答数据;
步骤S405:接收所述发卡方服务器根据所述验证请求返回的验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括:所述发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文
后、将该第二应用密文与所述第一应用密文进行比对获得的卡人一致性(金融卡与持卡人一致)校验结果、对所述交易密码信息进行校验获得的密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;
步骤S406:将所述第一认证数据发送给所述金融卡,并接收所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定的第二认证结果;
步骤S407:根据所述第一认证结果、所述第二认证结果,确定金融卡用户身份的合法性。
根据如上所述的本发明实施例的方案,其不需要额外的硬件设备,使用已有的金融卡结合终端,即可方便、快捷、可靠地完成对金融卡用户身份和发行的验证,避免了因欺诈所带来的安全风险,保护了信息安全。
考虑到终端与金融卡通信的安全性,在一个具体示例中,终端可以通过近场通信(Near Field Communication,缩写为NFC,近距离无线通讯技术,)与金融卡进行交互。而上述应答数据也可以基于金融卡的需求来获取。
据此,在一个具体示例中,如图4所示,在上述步骤S401之前,本实施例中的方法还可以包括:
步骤S4002:通过近场通信向近场通信范围内的金融卡发送应用命令;
步骤S4003:接收所述金融卡基于所述应用命令返回的应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
可见,基于本实施例方案,终端与金融卡通过近场通信进行交互,进而可以确保金融卡与终端之间通信过程的安全性。此外,可以在需要时再让金融卡与终端进行通信。据此,如图4所示,在上述步骤S4002之前,还可以包括:
步骤S4001:给出将金融卡靠近终端近场通信感应区域的提示信息。
图5中示出了另一个实施例中的验证金融卡用户身份可靠性的方法的流程示意图,该实施例中是以金融卡101的处理过程为例进行说明。
如图5所示,该实施例中的方法包括:
步骤S501:接收终端发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据;
步骤S502:用存储的私钥对所述应答数据进行加密获得第一应用密文,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、所述第一应用密文;
步骤S503:接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识;
步骤S504:将所述验证结果标识与所述第一应用密文进行处理获得过程数据,用存储的私钥对所述过程数据进行加密获得第二认证数据,并将该第二认证数据与所述第一认证数据进行对比确定第二认证结果;
步骤S505:将所述第二认证结果向所述终端发送,由所述终端根据所述第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性。
考虑到终端与金融卡通信的安全性,在一个具体示例中,终端可以通过近场通信(Near Field Communication,缩写为NFC,近距离无线通讯技术,)与金融卡进行交互。而上述应答数据也可以基于金融卡的需求来获取。
据此,在一个具体示例中,如图5所示,在上述步骤S501之前,本实施例中的方法还可以包括:
步骤S5001:接收终端通过近场通信发送的应用命令;
步骤S5002:根据所述应用命令向所述终端返回应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
图6中示出了另一个实施例中的验证金融卡用户身份可靠性的方法的流程示意图,该实施例中是以发卡方服务器103的处理为例进行说明。
如图6所示,该实施例中的方法包括:
步骤S601:接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交易密码信息以及应答数据;
步骤S602:获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;
步骤S603:对所述交易密码信息进行校验获得密码正确性校验结果;
步骤S604:生成验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;
步骤S605:向所述终端返回所述验证响应,由所述终端将所述第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据所述第一认证结果、所述第二认证结果确定金融卡用户身份的合法性。
为了更好的理解发明实施例的方法,图7中示出了一个具体示例中验证用户身份可靠性时的交互流程示意图。考虑到移动终端身份的可靠性验证的应用和需求较为普遍,在图7所示示例的说明中,是以终端102为移动终端为例进行说明,本领域技术人员可以理解,只要能够执行本发明实施例方案中的验证方案的相关功能,除了移动终端之外的其他终端同样适用。
在需要进行用户身份可靠性的验证时,例如在使用电子钱包等进行移动支付时,使用金融终端过程中的安全验证时(例如手机银行APP软件等),购物类软件进行登陆或者进行购物时的身份验证时等等,如图7所示,移动终端可以先给出将金融卡靠近移动终端近场通信感应区域的提示信息,该提示信息可以采用任何可能的方式进行,例如在移动终端的相关显示界面上进行显示、通过语音进行语音提醒、显示界面的显示与语音提醒同时进行等等。
基于该提示信息,用户可将金融卡放置或者靠近移动终端近场通信的感应区域,移动终端通过近场通信向其近场通信范围内的金融卡发送应用命令。
金融卡接收到该应用命令后,激活移动终端所选择的相关应用,使金融卡处于开始状态,并向移动终端返回应用命令响应信息,该应用命令响应信息中包括要求终端发送的数据的数据类型的信息。在一个具体示例中,该应用命令响应信息中的数据类型的信息,可以是以数据类型列表的方式发送。
以支付、购物等交易支付过程中的用户身份可靠性验证为例,在一个具体示例中,这里的数据类型可以是包括:交易时间、交易类型、交易金额、交易货币代码、随机数、终端性能。本领域技术人员可以理解,基于实际交易过程的需要,还可以是其他的数据类型。
移动终端接收到该命令响应信息后,获取与金融卡要求终端发送的数据的数据类型对应的数据,并将获得的数据组成应答数据向所述金融卡发送。如上所述,在发送应答数据发送时,也是通过近场通信(NFC)发送给金融卡。在一个具体示例中,所获得的数据,可以是以数据列表的方式作为应答数据发送给金融卡。
金融卡接收到该应答数据后,用金融卡自身存储的私钥对该应答数据进行加密获得应用密文(为便于与其他密文区分,在此称为第一应用密文),并向移动终端返回密文响应信息,该密文响应信息中包括有该金融卡存储的金融卡的卡号信息、以及上述第一应用密文。
移动终端接收到该密文响应信息后,可以给出让用户输入该金融卡的交易密码的提示信息,该提示信息可以是通过语音进行提示,也可以是直接通过密码输入界面进行提示,也可以是密码输入界面与语音提示同时进行,并接收用户通过密码输入界面或者密码输入设备输入的该金融卡的交易密码信息。
随后,移动终端向该金融卡的发卡方服务器发送验证请求,在通过云端支付平台100进行支付交易的情况下,移动终端将该验证请求发送给该云端支付平台,由云端支付平台发送给发卡方服务器。该验证请求中包括有:上述第一应用密文、上述卡号信息、上述交易密码信息以及上述应答数据。可以理解的是,为了加强移动终端与发卡方服务器通信过程的安全性,移动终端在发送该验证请求时,可以是加密之后在发送,相对应地,发卡方服务器在接收到该加密的验证请求后,再执行后续的操作。具体的加解密方式可以采用任何可能的加解密方式进行,本发明实施例不做具体限定。出于简便说明的目的,下述说明中未对加解密过程进行说明。
发卡方服务器接收到该验证请求后,获取存储的与验证请求中的卡号信息对应的私钥,采用该私钥对验证请求中的应答数据进行加密获得应用密文(为便于区分,称之为第二应用密文),并将第二应用密文与验证请求中的第一应用密文进行比对,从而获得卡人一致性校验结果。可以理解的是,通常情况下,由于获得第一应用密文、第二应用密文的加密方式是一样的,因此,正常情况下,所获得的第二应用密文应当是与第一应用密文是一致的,即在第二应用密文与第一应用密文一致的情况下,发卡方即可判定卡人是一致的,否则是不一致的。
此外,发卡方服务器还基于验证请求中的账号信息对验证请求中的交易密码信息进行
校验,判断校验请求中的交易密码是否与存储的该账号信息对应的信息是否一致,从而获得密码正确性校验结果。对密码进行校验的方式,可以采用目前已有以及以后可能出现的任何方式进行。
随后,发卡方服务器生成验证响应,并将该验证响应向移动终端发送,或者是通过云端交易平台发送给移动终端。该验证响应中包括有第一认证结果以及第一认证数据,其中,第一认证结果包括上述卡人一致性校验结果、上述密码正确性校验结果,第一认证数据包括上述第二应用密文及生成的验证结果标识。其中,该第一认证数据中,第二应用密文和验证结果标识的组合方式,可以是任何可能的方式,例如验证结果标识可以是第一认证数据中的在后的字节或者是在前的字节。
移动终端接收到该验证响应后,将第一认证数据发送给金融卡。
金融卡接收到该验证响应后,将第一认证数据中的验证结果标识与上述自身生成的第一应用密文进行处理获得过程数据,并用金融卡自身存储的私钥对该过程数据进行加密获得第二认证数据,并将该第二认证数据与上述第一认证数据进行对比,确定第二认证结果,并将该第二认证结果发送给移动终端。金融卡可以采用任何方式对验证结果标识与第一应用密文进行处理获得过程数据,在一个具体示例中,可以是将验证结果标识与第一应用密文进行异或处理获得上述过程数据。
移动终端在接收到第二认证结果后,将第二认证结果与第一认证结果结合,确定用户身份的合法性。其中,第一认证结果代表了发卡方服务器对卡人一致性的认证结果,第二认证结果代表了金融卡对卡人一致性的认证结果,二者的结合进一步加强了金融卡用户身份合法性验证的可靠性。
在用在交易支付系统的情况下,在确认了金融卡用户身份的合法性之后,移动终端可以进一步确定交易支付结果,并将交易支付结果进行显示,以告知用户认证结果和交易支付结果。
基于与上述方法相同的思想,本发明实施例还提供一种验证金融卡用户身份可靠性的装置,图8中示出了一个具体示例中的装置的结构示意图。在图8所示的结构示意图中,是以结合了设置在金融卡上的装置81、设置在终端上的装置82以及设置在发卡方服务器上的装置83为例进行说明。
如图8所示,在一个具体示例中,设置在终端82上的验证金融卡用户身份可靠性的装置包括:
数据获取模块822,用于获取与金融卡81要求终端82发送的数据的数据类型对应的数据;
终端第一信息交互模块823,用于将数据获取模块822获得的数据作为应答数据向金融卡81发送,并接收金融卡81返回的密文响应信息,该密文响应信息包括金融卡81的卡号信息、金融卡81用存储的私钥对所述应答数据进行加密获得的第一应用密文;还用于将终端第二信息交互模块825接收的第一认证数据发送给金融卡81,并接收金融卡81返回的第二认证结果;
密码信息接收模块824,用于接收用户输入的金融卡81的交易密码信息;
终端第二信息交互模块825,用于向金融卡的发卡方服务器83发送验证请求,该验证请求包括上述第一应用密文、上述卡号信息、上述交易密码信息以及上述应答数据;并接收发卡方服务器83根据该验证请求返回的验证响应;
合法性判定模块826,用于根据上述第一认证结果、上述第二认证结果,确定金融卡用户身份的合法性。
其中,上述验证响应包括第一认证结果以及第一认证数据,第一认证结果包括:发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对应答数据进行加密获得第二应用密文后、将该第二应用密文与第一应用密文进行比对获得的卡人一致性校验结果、对交易密码信息进行校验获得的密码正确性校验结果,上述第一认证数据包括所述第二应用密文及验证结果标识;
上述第二认证结果由所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定。
相对应地,如图8所示,在该具体示例中,设置在金融卡81的验证金融卡用户身份可靠性的装置包括:
卡端信息交互模块811,接收终端82发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、卡端加密模块生
成的第一应用密文;以及接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识,并将所述第二认证结果向所述终端发送,由所述终端根据认证模块确定的第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性;
过程数据确定模块812,用于将所述验证结果标识与所述第一应用密文进行处理,获得过程数据;
卡端加密模块813,用于用存储的私钥对所述应答数据进行加密获得所述第一应用密文,并用存储的所述私钥对所述过程数据进行加密获得第二认证数据;
认证模块814,用于将所述第二认证数据与所述第一认证数据进行对比确定所述第二认证结果。
相对应地,如图8所示,在该具体示例中,设置在发卡方服务器83的验证金融卡用户身份可靠性的装置包括:
服务端信息交互模块831,用于接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交易密码信息以及应答数据,并将验证响应生成模块生成的验证响应向所述终端发送,由所述终端将验证响应中的第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据验证响应中的第一认证结果、所述第二认证结果确定金融卡用户身份的合法性;
卡人一致性校验模块832,用于获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;
密码校验模块833,用于对所述交易密码信息进行校验获得密码正确性校验结果;
验证响应生成模块834,用于生成所述验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识。
考虑到终端与金融卡通信的安全性,在一个具体示例中,终端可以通过近场通信(Near Field Communication,缩写为NFC,近距离无线通讯技术,)与金融卡进行交互。而上述应答数据也可以基于金融卡的需求来获取。
据此,在一个具体示例中:
上述终端第一信息交互模块823,还通过近场通信向近场通信范围内的金融卡发送应用命令;并接收所述金融卡基于所述应用命令返回的应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
相对应地,上述卡端信息交互模块811,还用于接收终端通过近场通信发送的应用命令;并根据所述应用命令向所述终端返回应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
可见,基于本实施例方案,终端与金融卡通过近场通信进行交互,进而可以确保金融卡与终端之间通信过程的安全性。
此外,可以在需要时再让金融卡与终端进行通信,据此,如图8所示,设置在终端82上的验证金融卡用户身份可靠性的装置还可以包括:
信息提示模块821,用于给出将金融卡靠近终端近场通信感应区域的提示信息。
如上所述的本发明实施例的装置,可以应用到任何需要结合金融卡对金融卡用户身份的合法性和可靠性进行验证的领域,例如交易支付。以交易支付为例,在交易支付的应用场景,上述应答数据可以包括:交易时间、交易类型、交易金额、交易货币代码、随机数、终端性能信息。
此时,结合图8所示,在此情况下,设置在终端82上的验证金融卡用户身份可靠性的装置还可以包括:
交易结果确定模块827,用于根据合法性判定模块826确定的金融卡用户身份的合法性确定交易支付结果,并将交易支付结果进行显示。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一非易失性的计算机可读取存储介质中,如本发明实施例中,该程序可存储于计算机系统的存储介质中,并被该计算机系统中的至少一个处理器执行,以实现包括如上述各方法的实施例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存储记忆体(Random Access Memory,RAM)等。
以上所述实施例的各技术特征可以进行任意的组合,为使描述简洁,未对上述实施例中的各个技术特征所有可能的组合都进行描述,然而,只要这些技术特征的组合不存在矛
盾,都应当认为是本说明书记载的范围。
以上所述实施例仅表达了本发明的几种实施方式,其描述较为具体和详细,但并不能因此而理解为对发明专利范围的限制。应当指出的是,对于本领域的普通技术人员来说,在不脱离本发明构思的前提下,还可以做出若干变形和改进,这些都属于本发明的保护范围。因此,本发明专利的保护范围应以所附权利要求为准。
Claims (12)
- 一种验证金融卡用户身份可靠性的方法,其特征在于,包括步骤:获取与金融卡要求终端发送的数据的数据类型对应的数据,并将获得的数据作为应答数据向所述金融卡发送;接收所述金融卡返回的密文响应信息,所述密文响应信息包括所述金融卡的卡号信息、所述金融卡用存储的私钥对所述应答数据进行加密获得的第一应用密文;接收用户输入的所述金融卡的交易密码信息;向所述金融卡的发卡方服务器发送验证请求,所述验证请求包括所述第一应用密文、所述卡号信息、所述交易密码信息以及所述应答数据;接收所述发卡方服务器根据所述验证请求返回的验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括:所述发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文后、将该第二应用密文与所述第一应用密文进行比对获得的卡人一致性校验结果、对所述交易密码信息进行校验获得的密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;将所述第一认证数据发送给所述金融卡,并接收所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定的第二认证结果;根据所述第一认证结果、所述第二认证结果,确定金融卡用户身份的合法性。
- 根据权利要求1所述的验证金融卡用户身份可靠性的方法,其特征在于,在获取与金融卡要求终端发送的数据的数据类型对应的数据之前,还包括步骤:通过近场通信向近场通信范围内的金融卡发送应用命令;接收所述金融卡基于所述应用命令返回的应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
- 根据权利要求1或2所述的验证金融卡用户身份可靠性的方法,其特征在于,还包括步骤:根据确定的金融卡用户身份的合法性确定交易支付结果,并将交易支付结果进行显示。
- 一种验证金融卡用户身份可靠性的方法,其特征在于,包括步骤:接收终端发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据;用存储的私钥对所述应答数据进行加密获得第一应用密文,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、所述第一应用密文;接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识;将所述验证结果标识与所述第一应用密文进行处理获得过程数据,用存储的私钥对所述过程数据进行加密获得第二认证数据,并将该第二认证数据与所述第一认证数据进行对比确定第二认证结果;将所述第二认证结果向所述终端发送,由所述终端根据所述第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性。
- 根据权利要求4所述的验证金融卡用户身份可靠性的方法,其特征在于,在接收终端发送的应答数据之前,还包括步骤:接收终端通过近场通信发送的应用命令;根据所述应用命令向所述终端返回应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
- 一种验证金融卡用户身份可靠性的方法,其特征在于,包括步骤:接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交易密码信息以及应答数据;获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;对所述交易密码信息进行校验获得密码正确性校验结果;生成验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;向所述终端返回所述验证响应,由所述终端将所述第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据所述第一认证结果、所述第二认证结果确定金融卡用户身份的合法性。
- 一种验证金融卡用户身份可靠性的装置,其特征在于,包括:数据获取模块,用于获取与金融卡要求终端发送的数据的数据类型对应的数据;终端第一信息交互模块,用于将所述数据获取模块获得的数据作为应答数据向所述金融卡发送,并接收所述金融卡返回的密文响应信息,所述密文响应信息包括所述金融卡的卡号信息、所述金融卡用存储的私钥对所述应答数据进行加密获得的第一应用密文;将终端第二信息交互模块接收的第一认证数据发送给所述金融卡,并接收所述金融卡返回的第二认证结果;密码信息接收模块,用于接收用户输入的所述金融卡的交易密码信息;终端第二信息交互模块,用于向所述金融卡的发卡方服务器发送验证请求,所述验证请求包括所述第一应用密文、所述卡号信息、所述交易密码信息以及所述应答数据;并接收所述发卡方服务器根据所述验证请求返回的验证响应;合法性判定模块,用于根据所述第一认证结果、所述第二认证结果,确定金融卡用户身份的合法性;所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括:所述发卡方服务器获取存储的与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文后、将该第二应用密文与所述第一应用密文进行比对获得的卡人一致性校验结果、对所述交易密码信息进行校验获得的密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识;第二认证结果由所述金融卡将所述验证结果标识与所述第一应用密文进行处理获得过程数据、用存储的私钥对所述过程数据进行加密获得第二认证数据后、将所述第二认证数据与所述第一认证数据进行对比确定。
- 根据权利要求7所述的验证金融卡用户身份可靠性的装置,其特征在于,所述终端第一信息交互模块,还通过近场通信向近场通信范围内的金融卡发送应用命令;并接收所述金融卡基于所述应用命令返回的应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
- 根据权利要求7或8所述的验证金融卡用户身份可靠性的装置,其特征在于,还包括:交易结果确定模块,用于根据所述合法性判定模块确定的金融卡用户身份的合法性确 定交易支付结果,并将交易支付结果进行显示。
- 一种验证金融卡用户身份可靠性的装置,其特征在于,包括:卡端信息交互模块,接收终端发送的应答数据,所述应答数据包括所述终端根据金融卡要求终端发送的数据的数据类型获取的与所述数据类型对应的数据,并向所述终端返回密文响应信息,所述密文响应信息包括存储的金融卡的卡号信息、卡端加密模块生成的第一应用密文;以及接收所述终端发送的第一认证数据,所述第一认证数据包括第二应用密文以及验证结果标识,并将所述第二认证结果向所述终端发送,由所述终端根据认证模块确定的第二认证结果以及发卡方服务器返回的第一认证结果确定金融卡用户身份的合法性;过程数据确定模块,用于将所述验证结果标识与所述第一应用密文进行处理,获得过程数据;卡端加密模块,用于用存储的私钥对所述应答数据进行加密获得所述第一应用密文,并用存储的所述私钥对所述过程数据进行加密获得第二认证数据;认证模块,用于将所述第二认证数据与所述第一认证数据进行对比确定所述第二认证结果。
- 根据权利要求10所述的验证金融卡用户身份可靠性的装置,其特征在于:所述卡端信息交互模块,还用于接收终端通过近场通信发送的应用命令;并根据所述应用命令向所述终端返回应用命令响应信息,所述应用命令响应信息中包括要求终端发送的数据的数据类型的信息。
- 一种验证金融卡用户身份可靠性的装置,其特征在于,包括:服务端信息交互模块,用于接收终端发送的验证请求,所述验证请求包括第一应用密文、金融卡的卡号信息、交易密码信息以及应答数据,并将验证响应生成模块生成的验证响应向所述终端发送,由所述终端将验证响应中的第一认证数据发送给金融卡、接收到金融卡返回的第二认证结果后,根据验证响应中的第一认证结果、所述第二认证结果确定金融卡用户身份的合法性;卡人一致性校验模块,用于获取与所述卡号信息对应的私钥、采用该私钥对所述应答数据进行加密获得第二应用密文,并将该第二应用密文与所述第一应用密文进行比对获得卡人一致性校验结果;密码校验模块,用于对所述交易密码信息进行校验获得密码正确性校验结果;验证响应生成模块,用于生成所述验证响应,所述验证响应包括第一认证结果以及第一认证数据,所述第一认证结果包括所述卡人一致性校验结果、所述密码正确性校验结果,所述第一认证数据包括所述第二应用密文及验证结果标识。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610289386.1 | 2016-05-03 | ||
| CN201610289386.1A CN105897721B (zh) | 2016-05-03 | 2016-05-03 | 验证金融卡用户身份可靠性的方法及装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017190633A1 true WO2017190633A1 (zh) | 2017-11-09 |
Family
ID=56703165
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/082457 Ceased WO2017190633A1 (zh) | 2016-05-03 | 2017-04-28 | 验证金融卡用户身份可靠性的方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105897721B (zh) |
| WO (1) | WO2017190633A1 (zh) |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108320152A (zh) * | 2018-01-17 | 2018-07-24 | 深圳喆行科技有限公司 | 一种储值卡的充值方法与系统 |
| CN109815803A (zh) * | 2018-12-18 | 2019-05-28 | 平安科技(深圳)有限公司 | 面审风险控制方法、装置、计算机设备和存储介质 |
| CN110084607A (zh) * | 2019-03-23 | 2019-08-02 | 嘉兴捷威进出口有限公司 | 云闪付方法及装置 |
| CN113132101A (zh) * | 2021-04-19 | 2021-07-16 | 上海同态信息科技有限责任公司 | 基于数据隐私计算的金融用户身份认证方法及系统 |
| US11244296B2 (en) | 2017-01-23 | 2022-02-08 | Mastercard International Incorporated | Method and system for authentication via a trusted execution environment |
| CN115829635A (zh) * | 2022-11-16 | 2023-03-21 | 康键信息技术(深圳)有限公司 | 一种电子卡发放方法、装置、电子设备及存储介质 |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105897721B (zh) * | 2016-05-03 | 2019-01-25 | 广州广电运通金融电子股份有限公司 | 验证金融卡用户身份可靠性的方法及装置 |
| CN109816359B (zh) * | 2019-02-27 | 2021-05-18 | 银联商务股份有限公司 | 一种服务调用方法及系统 |
| CN111951019B (zh) * | 2020-08-28 | 2024-12-06 | 浪潮软件股份有限公司 | 身份验证方法和装置 |
| CN112630570A (zh) * | 2020-12-16 | 2021-04-09 | 满帮信息咨询有限公司 | Etc套装设备的有效性检测方法、装置、电子设备及介质 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101162535A (zh) * | 2006-10-13 | 2008-04-16 | 中国银联股份有限公司 | 利用ic卡实现磁条卡交易的方法及系统 |
| CN101710433A (zh) * | 2008-12-31 | 2010-05-19 | 深圳市江波龙电子有限公司 | 一种电子支付卡的交易方法及电子支付卡 |
| CN104021473A (zh) * | 2014-05-30 | 2014-09-03 | 刘劲彤 | 一种可视金融卡的安全支付方法 |
| CN104408620A (zh) * | 2014-11-13 | 2015-03-11 | 中国科学院数据与通信保护研究教育中心 | 一种安全的nfc支付方法及系统 |
| EP2889823A1 (en) * | 2013-12-31 | 2015-07-01 | Gemalto SA | Method for securing a completion step of an online transaction |
| CN105897721A (zh) * | 2016-05-03 | 2016-08-24 | 广州广电运通金融电子股份有限公司 | 验证金融卡用户身份可靠性的方法及装置 |
-
2016
- 2016-05-03 CN CN201610289386.1A patent/CN105897721B/zh active Active
-
2017
- 2017-04-28 WO PCT/CN2017/082457 patent/WO2017190633A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101162535A (zh) * | 2006-10-13 | 2008-04-16 | 中国银联股份有限公司 | 利用ic卡实现磁条卡交易的方法及系统 |
| CN101710433A (zh) * | 2008-12-31 | 2010-05-19 | 深圳市江波龙电子有限公司 | 一种电子支付卡的交易方法及电子支付卡 |
| EP2889823A1 (en) * | 2013-12-31 | 2015-07-01 | Gemalto SA | Method for securing a completion step of an online transaction |
| CN104021473A (zh) * | 2014-05-30 | 2014-09-03 | 刘劲彤 | 一种可视金融卡的安全支付方法 |
| CN104408620A (zh) * | 2014-11-13 | 2015-03-11 | 中国科学院数据与通信保护研究教育中心 | 一种安全的nfc支付方法及系统 |
| CN105897721A (zh) * | 2016-05-03 | 2016-08-24 | 广州广电运通金融电子股份有限公司 | 验证金融卡用户身份可靠性的方法及装置 |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11244296B2 (en) | 2017-01-23 | 2022-02-08 | Mastercard International Incorporated | Method and system for authentication via a trusted execution environment |
| CN108320152A (zh) * | 2018-01-17 | 2018-07-24 | 深圳喆行科技有限公司 | 一种储值卡的充值方法与系统 |
| CN109815803A (zh) * | 2018-12-18 | 2019-05-28 | 平安科技(深圳)有限公司 | 面审风险控制方法、装置、计算机设备和存储介质 |
| CN109815803B (zh) * | 2018-12-18 | 2023-04-18 | 平安科技(深圳)有限公司 | 面审风险控制方法、装置、计算机设备和存储介质 |
| CN110084607A (zh) * | 2019-03-23 | 2019-08-02 | 嘉兴捷威进出口有限公司 | 云闪付方法及装置 |
| CN113132101A (zh) * | 2021-04-19 | 2021-07-16 | 上海同态信息科技有限责任公司 | 基于数据隐私计算的金融用户身份认证方法及系统 |
| CN115829635A (zh) * | 2022-11-16 | 2023-03-21 | 康键信息技术(深圳)有限公司 | 一种电子卡发放方法、装置、电子设备及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105897721A (zh) | 2016-08-24 |
| CN105897721B (zh) | 2019-01-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20250211443A1 (en) | Contactless card emulation system and method | |
| US20240242203A1 (en) | Device provisioning using partial personalization scripts | |
| EP3474211B1 (en) | Offline payment method and device | |
| WO2017190633A1 (zh) | 验证金融卡用户身份可靠性的方法及装置 | |
| EP3535724B1 (en) | Verifying an association between a communication device and a user | |
| JP7641890B2 (ja) | 非接触カードの暗号化認証のためのシステムおよび方法 | |
| US10956905B2 (en) | System and method of session key generation and exchange | |
| CN106716916B (zh) | 认证系统和方法 | |
| CN112805737A (zh) | 用于令牌邻近交易的技术 | |
| US20110238573A1 (en) | Cardless atm transaction method and system | |
| US20080046988A1 (en) | Authentication Method | |
| CN105684346A (zh) | 确保移动应用和网关之间空中下载通信安全的方法 | |
| JP2013514556A (ja) | 安全に取引を処理するための方法及びシステム | |
| WO2015065249A1 (ru) | Способ и система защиты информации от несанкционированного использования (её варианты) | |
| CN106372942B (zh) | 一种基于安全认证机制的支付方法及支付系统 | |
| CN108234385A (zh) | 一种用户身份认证方法及装置 | |
| CN112308555B (zh) | 远程交易系统、方法和销售点终端 | |
| WO2016112675A1 (zh) | 一种金融自助系统的处理方法 | |
| CN104871186A (zh) | 用于移动支付的应用程序系统和用于提供并使用移动支付工具的方法 | |
| EP3662430A1 (en) | System and method for authenticating a transaction | |
| US20250141700A1 (en) | Systems and methods for transaction card-based authentication | |
| CN104429036A (zh) | 用于安全id认证的系统 | |
| CN105931047A (zh) | 线下支付方法、终端设备、后台支付装置及线下支付系统 | |
| WO2015162276A2 (en) | Secure token implementation | |
| CN104980276B (zh) | 用于安全性信息交互的身份认证方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17792459 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17792459 Country of ref document: EP Kind code of ref document: A1 |