WO2017206680A1 - 点对点转账系统和方法 - Google Patents
点对点转账系统和方法 Download PDFInfo
- Publication number
- WO2017206680A1 WO2017206680A1 PCT/CN2017/083714 CN2017083714W WO2017206680A1 WO 2017206680 A1 WO2017206680 A1 WO 2017206680A1 CN 2017083714 W CN2017083714 W CN 2017083714W WO 2017206680 A1 WO2017206680 A1 WO 2017206680A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- token
- terminal
- peer
- transaction
- point
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/22—Payment schemes or models
- G06Q20/223—Payment schemes or models based on the use of peer-to-peer networks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
Definitions
- the present invention relates to a point-to-point transfer system and method, and more particularly to a transfer system and method based on short-range wireless communication technology and token technology.
- the present application proposes a peer-to-peer (P2P) transfer system based on short-range wireless communication technology (ie, NFC) and token (ie, Token) technology.
- P2P peer-to-peer
- NFC short-range wireless communication technology
- token ie, Token
- a peer-to-peer transfer system comprising: setting in a background system a background application unit; a first application unit disposed at the first terminal; a second application unit disposed at the second terminal; wherein, when the transfer transaction is performed, the first terminal and the second terminal are configured to respectively pass And acquiring, by the first application and the second application, a first token and a second token to a background application of the background system, where the first token includes first account information associated with the first terminal, and the second order
- the card includes second account information associated with the second terminal; the first terminal forwards the first token to the second terminal by short-range wireless communication technology; and receives the forwarded first token Afterwards, the second terminal sends both the first token and the second token to the background system for authenticating and matching the token.
- the second terminal is configured to pass the first order by the second application unit before sending the first token and the second token to the background system
- the card is reorganized with the second token to form a first substitute token and a second substitute token.
- the second terminal is configured to recombine the first token and the second token to form the first substitute token information and the second substitute Generation token: dividing data of the first token into at least two data segments, dividing data of the second token into at least two data segments; and dividing the data segment by the first token with The two token-divided data segments are combined to form a first substitute token and a second substitute token, wherein the first substitute token includes a data segment from the first token and a data segment of the second token, and second The substitute token includes the remaining data segments in the first token and the remaining data segments in the second token.
- the background system performs the first token and the second token after receiving the first token and the second token sent from the second terminal. Authentication and matching to obtain transaction elements for account matching and transaction authorization.
- the first terminal is configured to simulate a payment account carrier
- the second terminal is configured to simulate a payment acceptance terminal
- the background system is configured to utilize transaction time and random number before transmitting the first token and the second token to the first terminal and the second terminal respectively And one or more of the transaction amounts to logically process the first token and/or the second token to ensure transmission security.
- a peer-to-peer transfer method performed in a background system, the method comprising: generating a first token and transmitting the first token to a first of a simulated payment account carrier a terminal, where the first token includes account information associated with the first terminal; generating a second token, and transmitting the second token to a second terminal of the analog payment accepting terminal, where The second token includes account information associated with the second terminal; receiving the first token and the second token from the second terminal, wherein the first token is by the first A terminal forwards to the second terminal by a short-range wireless communication technology; and authenticates and matches the first token and the second token.
- receiving the first token and the second token sent by the second terminal includes: the first token and the second token are recombined to form a first alternative order
- the card and the second substitute token receive the first substitute token and the second substitute token sent.
- the first token and the second token are reorganized according to the following steps to form a first substitute token and a second substitute token: dividing data of the first token into at least two data segments Dividing the data of the second token into at least two data segments; and combining the divided data segments of the first token with the data segments divided by the second token to form data respectively including the first token The first substitute token and the second substitute token of the data segment of the segment and the second token.
- authenticating and matching the first token and the second token includes extracting transaction elements from the first token and the second token.
- the method further includes: transmitting the transaction element to the card issuing system for performing transaction authorization.
- the first token before the generated first token is sent to the first terminal of the analog payment account carrier, the first token is used by using one or more of transaction time, random number, and transaction amount. Performing logical processing, and/or transmitting the generated second token to the second terminal of the simulated payment account carrier, using the transaction time, the random number, the transaction amount, one or more of the second token Perform logical processing.
- FIG. 1 is a schematic structural diagram of a peer-to-peer transfer system and an application environment thereof according to an example of the present invention.
- the personal mobile terminal implanted with the NFC chip is respectively simulated into a payment account carrier and a payment acceptance terminal, and the account information is transmitted by reading a token (ie, Token).
- the personal mobile terminal that simulates the payment receiving terminal initiates the transaction and sends it to the background system for Token check and account matching, and sends it to the card issuer for transaction authorization.
- the first terminal and the second terminal are respectively illustrated by using a mobile phone as an example. But it is not a limitation. All electronic terminals that have an NFC function and can be bound to a user bank card account and can access the network can be used as the first terminal or the second terminal, such as a tablet such as an iPad.
- FIG. 1 is a schematic structural diagram of a point-to-point transfer system and an application environment thereof according to an example of the present invention.
- a peer-to-peer transfer system in accordance with an example of the present invention is explained below with reference to FIG.
- the terminal that simulates the payment account carrier, that is, the first terminal 10 includes the first application unit 100
- the analog payment acceptance terminal, that is, the second terminal 20 includes the second application unit 200.
- the first application unit 100 is referred to as a roll-out application unit and the second application unit 200 is referred to as a transfer application unit, but in practical applications,
- the transfer-in application unit and the roll-out application unit can be implemented as an application including both a transfer function and a roll-out function, which also enables the terminal loaded with the application to serve as both a payment account carrier and a payment acceptance terminal.
- Backend system 30 includes a background application unit (not labeled).
- the first terminal 10 simulating the payment account carrier and the second terminal 20 simulating the payment acceptance terminal are respectively connected to the background system 30.
- the first terminal 10 obtains a first token 31 (hereinafter also referred to as Token 1) from the background application of the background system 30 through its first application unit 100, and the second terminal 20 passes through the second application unit 200 thereof to the background system 30.
- the background application acquires a second token 32 (hereinafter also referred to as Token 2).
- the first token 31 is generated by the background application unit of the background system 30, and the second token 32 is also generated by the background application of the background system 30.
- the background application unit of the background system 30 will pass any one of the current transaction time, transaction amount, random number or Their combination performs an exclusive OR logical operation on the generated first token 31 so that the token is more secure.
- the background application unit of the background system 30 will pass any of the current transaction time, transaction amount, and random number.
- One or a combination thereof performs an exclusive OR logical operation on the generated second token 20 so that the token is more secure.
- the first token 31 and the second token 32 may perform an exclusive OR logical operation by using any one of the current transaction time, the transaction amount, the random number, or a combination thereof, or only An exclusive OR operation is performed on one of the first token 31 and the second token 32.
- the first token 31 and the second token 32 are recombined to form a first replacement token and a Two alternative tokens.
- the first token 31 can be divided into two data segments
- the second token 32 can be divided into two data segments, thereby one data segment of the first token 31 and one data of the second token 32.
- the segment combination constitutes a first replacement token and combines the remaining data segments of the first token 31 with the remaining data segments of the second token 32 to form a second replacement token.
- first token 31 can be divided into two data segments and the second token 32 can be divided into three data segments, whereby one data segment of the first token 31 and the two data of the second token 32 are The segments are combined to form an alternate token and the remaining data segments of the first token 31 and the remaining data segments of the second token 32 are combined to form another alternate token.
- first 1/2 and the last 1/2 methods to disassemble, such as: the first 1/2 of Token1 and the last 1/2 of Token2, and the first 1/2 of Token2 and the second 1/2 of Token2. (You can set several kinds, specifically the background and front end of each transaction process can be randomly selected).
- the reorganization process of the first token 31 and the second token 32 as discussed above may be performed by the second application unit 200 of the second terminal 20.
- the mobile phone terminal 10 simulating the payment account carrier and the mobile phone terminal 20 simulating the payment acceptance terminal interact through the NFC technology, through which the mobile phone of the payment acceptance terminal is simulated to obtain the transfer account Token 1, and Token 1 And the self-acquired Token 2 is sent to the background system, or the reassembled first replacement token and the second substitute token are sent to the background system 30, for example, as transaction messages.
- the payment acceptance terminal organizes the transaction message to the background system 30, and the background system performs authentication and matching of the Token, and then sends the transaction request to the card issuer 40 for authorization. After the card issuer authorization is completed, the transaction response is returned to the payment acceptance terminal 20, and a short message is sent to the payment account carrier terminal 10.
- the peer-to-peer transfer method performed in the background system 30 includes: generating a first token and transmitting the first token to a first terminal of a simulated payment account carrier, wherein the a token includes account information associated with the first terminal; generating a second token, and transmitting the second token to a second terminal of the analog payment accepting terminal, wherein the second token includes Account information associated with the second terminal; receiving the first token and the second token sent by the second terminal, wherein the first token is close by the first terminal Transmitting, by the wireless communication technology, the second terminal; and authenticating and matching the first token and the second token.
- receiving the first token and the second token sent by the second terminal comprises recombining the first token with a second token to form a first substitute token and And a second substitute token, so that the first substitute token and the second substitute token are sent by the second terminal to the background system.
- the first token and the second token are recombined to form a first substitute token and a second substitute token in the following manner: dividing data of the first token into at least two data Segment, the number of the second token Dividing into at least two data segments; and combining the divided data segments of the first token with the data segments divided by the second token to form a data segment including the first token and a data segment of the second token, respectively The first alternate token with the second alternate token.
- the two Tokens can be disassembled and reorganized in the first 1/2 and the second 1/2, ensuring that the Tokens of the two accounts cannot be restored even if they are intercepted during the payment receiving terminal and the background system transmission. Further strengthen security.
- authenticating and matching the first token and the second token includes extracting transaction elements from the first token and the second token.
- the transaction element can then be sent to the card issuer system for transaction authorization.
- the first order is used by one or more of a transaction time, a random number, and a transaction amount.
- the second token is performed using one or more of transaction time, random number, and transaction amount Logical processing. In this way, the security of the transfer processing is further enhanced.
- a peer-to-peer transfer system in another specific embodiment, includes: a background system located at the server side; a first terminal; and a second terminal.
- the first terminal and the second terminal are configured to respectively acquire the first token and the second token from the background system, the first token including the first account information associated with the first terminal
- the second token includes second account information associated with the second terminal.
- the first terminal forwards the first token to the second terminal by a short-range wireless communication technology. After receiving the forwarded first token, the second terminal sends both the first token and the second token to the background system for authenticating and matching the token.
- the peer-to-peer transfer system further includes a card issuance system, the second terminal being configured to be first before transmitting the first token and the second token to the background system
- the token is reorganized with the second token to form a first alternate token and a second alternate token.
- the second terminal is configured to recombine the first token with the second token to form the first substitute token information and the second substitute token by dividing the data of the first token into at least Two data segments, dividing the data of the second token into at least two data segments; and combining the divided data segments of the first token with the data segments divided by the second token to constitute a first The data segment of the token and the first replacement token and the second replacement token of the data segment of the second token.
- two Tokens can be disassembled and reassembled in the first 1/2 and the second 1/2 in the transmission process to ensure that they are transmitted in the payment receiving terminal and the background system.
- the Token of the two accounts during the transfer process cannot be restored even if intercepted, further enhancing security.
- the background system authenticates and matches the first token and the second token after receiving the first token and the second token sent by the second terminal, Thereby acquiring transaction elements for account matching and transaction authorization.
- the first terminal is configured to simulate a payment account carrier
- the second terminal is configured to simulate a payment acceptance terminal
- the second terminal acquires information of the first token transmitted by the first terminal by using the short-range wireless communication technology And then the background system that transmits the first token and the second token.
- the first terminal is the initiator (master device) of the NFC transmission
- the first terminal provides the radio frequency field during the data transmission process between the first terminal and the second terminal, and vice versa.
- the request is initiated to the background via the second terminal as the analog payment accepting terminal, which can be understood as the originator of the entire transfer service or in the active mode and the second terminal is passive. Operating mode.
- the background system is configured to utilize transaction time, random number, before transmitting the first token and the second token to the first terminal and the second terminal, respectively.
- One or more of the transaction amounts are used to logically process the first token and/or the second token to ensure transmission security.
- the reorganization method between the background system and the terminal is pre-agreed, and different In the reorganization mode, an indication is sent in the message information sent by the second terminal to the background system, so that the background system correctly identifies the first token and the second token from the first substitute token and the second substitute token. More specifically, the background application unit of the background system and the second application unit disposed in the terminal pre-arrange which reorganization methods are adopted, and in different reorganization manners, the second terminal sends the message information to the background system. An indication is made that the background application unit of the backend system can correctly identify the first token and the second token from the first alternate token and the second alternate token.
- the first application unit, the second application unit, and the background application unit may each be implemented in the form of software, thereby being loaded into the first terminal, the second terminal, and the existing backend system;
- the first application unit, the second application unit, and the background application unit can each be implemented in the form of software in combination with hardware, thereby being loaded into the first terminal, the second terminal, and the existing backend system.
- the peer-to-peer transfer system according to an example of the present invention may be in software, or hardware, or software and Hardware combined way to achieve.
- the system of the present application realizes that the transfer party actively initiates the transfer of funds to the background authorization under the premise of ensuring security.
- the account information is automatically read by the personal mobile terminal without contact, and the transfer party is not required to inform the transfer party card number information, which is convenient and improves security.
- the token information is used to transfer the account information, and then the background system matches, so as to avoid the transfer of the card number to be accepted by the receiving terminal, avoiding risk risks such as leakage of the card number, and improving security.
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Strategic Management (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Mobile Radio Communication Systems (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
本申请公开了一种点对点转账系统,该系统应用在包括第一终端、第二终端以及设置在服务器端的后台系统的应用环境中,该点对点转账系统包括:设置在后台系统的后台应用单元;设置在第一终端的第一应用单元;设置在第二终端的第二应用单元;其中,在进行转账交易时,第一终端和终端配置成分别通过第一应用与第二应用,向后台系统的后台应用获取第一令牌和第二令牌,第一令牌包括与第一终端关联的第一账户信息而第二令牌包括与第二终端关联的第二账户信息;第一终端通过近距离无线通讯技术将第一令牌转发给第二终端;以及在收到所转发的第一令牌后,第二终端将第一令牌和所述第二令牌两者发送给后台系统。
Description
本发明涉及点对点转账系统和方法,尤其涉及基于近距离无线通讯技术和令牌技术的转账系统和方法。
现有方式下,微信、支付宝、银行等都提供了各自的转账产品,但是这些转账产品都不够便捷和安全。例如,在现有转账方式下,需要转出方提供卡号,并由转出方发起交易,需要输入密码等要素。这些方式不够便捷,难以满足用户的需求。
发明内容
为了解决上述问题,本申请提出了一种基于近距离无线通讯技术(即NFC)和令牌(即Token)技术的点对点(即P2P)转账系统。该系统适用于移动互联支付线下场景中个人对个人之间资金的方便划转。
根据本申请的一个方面,提供了一种点对点转账系统,所述系统应用在包括第一终端、第二终端以及设置在服务器端的后台系统的应用环境中,该点对点转账系统包括:设置在后台系统的后台应用单元;设置在第一终端的第一应用单元;设置在第二终端的第二应用单元;其中,在进行转账交易时,所述第一终端和所述第二终端配置成分别通过第一应用与第二应用,向所述后台系统的后台应用获取第一令牌和第二令牌,所述第一令牌包括与第一终端关联的第一账户信息而所述第二令牌包括与第二终端关联的第二账户信息;所述第一终端通过近距离无线通讯技术将所述第一令牌转发给所述第二终端;以及在收到所转发的第一令牌后,所述第二终端将所述第一令牌和所述第二令牌两者发送给所述后台系统,以便进行令牌的鉴权和匹配。
在上述点对点转账系统中,所述第二终端设置成在将所述第一令牌和所述第二令牌两者发送给所述后台系统之前,通过所述第二应用单元将第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌。作为示例,所述第二终端设置成通过如下方式将第一令牌与第二令牌重组以形成第一替代令牌信息与第二替
代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合,以构成第一替代令牌与第二替代令牌,其中,第一替代令牌包括来自第一令牌的数据段与第二令牌的数据段,第二替代令牌包括第一令牌中剩余的数据段与第二令牌中剩余的数据段。
在上述点对点转账系统中,其中,所述后台系统在收到从所述第二终端发送的第一令牌和第二令牌后,对所述第一令牌和所述第二令牌进行鉴权和匹配,从而获取交易要素以进行账户匹配和交易授权。
在上述点对点转账系统中,其中,所述第一终端配置成模拟支付账户载体,而所述第二终端配置成模拟支付受理终端。
在上述点对点转账系统中,所述后台系统配置成在将所述第一令牌和所述第二令牌分别发送给所述第一终端和所述第二终端之前,利用交易时间、随机数、交易金额中的一项或多项来对所述第一令牌和/或所述第二令牌进行逻辑处理,从而确保传输安全。
根据本申请的另一个方面,提供了一种在后台系统中执行的点对点转账方法,所述方法包括:生成第一令牌,并将所述第一令牌发送给模拟支付账户载体的第一终端,其中,所述第一令牌包括与所述第一终端关联的账户信息;生成第二令牌,并将所述第二令牌发送给模拟支付受理终端的第二终端,其中,所述第二令牌包括与所述第二终端关联的账户信息;从所述第二终端接收所述第一令牌和所述第二令牌,其中,所述第一令牌由所述第一终端通过近距离无线通讯技术转发给所述第二终端;以及对所述第一令牌和所述第二令牌进行鉴权和匹配。
在上述点对点转账方法中,接收由所述第二终端发送的所述第一令牌和所述第二令牌包括:所述第一令牌与第二令牌被重组以形成第一替代令牌与第二替代令牌,接收所发送的所述第一替代令牌与第二替代令牌。作为示例,其中,所述第一令牌与第二令牌被按照如下步骤重组以形成第一替代令牌与第二替代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合,以构成分别包括第一令牌的数据段与第二令牌的数据段的第一替代令牌与第二替代令牌。
在上述点对点转账方法中,对所述第一令牌和所述第二令牌进行鉴权和匹配包括:从所述第一令牌和所述第二令牌提取交易要素。
在上述点对点转账方法中,还包括:将所述交易要素发送给发卡系统,以便进行交易授权。
在上述点对点转账方法中,将所生成的第一令牌发送给模拟支付账户载体的第一终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第一令牌进行逻辑处理,和/或将所生成的第二令牌发送给模拟支付账户载体的第二终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第二令牌进行逻辑处理。
在参照附图阅读了本发明的具体实施方式以后,本领域技术人员将会更清楚地了解本发明的各个方面。本领域技术人员应当理解的是:这些附图仅仅用于配合具体实施方式说明本发明的技术方案,而并非意在对本发明的保护范围构成限制。
图1是是根据本发明示例的点对点转账系统及其应用环境的结构示意图。
下面介绍的是本发明的多个可能实施例中的一些,旨在提供对本发明的基本了解,并不旨在确认本发明的关键或决定性的要素或限定所要保护的范围。容易理解,根据本发明的技术方案,在不变更本发明的实质精神下,本领域的一般技术人员可以提出可相互替换的其它实现方式。因此,以下具体实施方式以及附图仅是对本发明的技术方案的示例性说明,而不应当视为本发明的全部或者视为对本发明技术方案的限定或限制。
,即近距离无线通讯技术,可以在移动设备间进行近距离(通常几厘米内)无线通信,支持主动模式、被动模式和双向模式等。在本申请的一个实施例中,利用NFC技术的,将植入NFC芯片的个人移动终端分别模拟成支付账户载体和支付受理终端,通过读取令牌(即,Token)方式传递账户信息,由模拟支付受理终端的个人移动终端发起交易上送到后台系统进行Token校验和账户匹配,并发送到发卡机构进行交易授权。
在如下各示例中,第一终端与第二终端分别是以手机作为示例来说明的,
但并不以此为限制。所有具有NFC功能且可与用户银行卡账户绑定且可接入网络的电子终端都可用作第一终端或第二终端,例如ipad等平板等。
图1是根据本发明示例的点对点转账系统及其应用环境的结构示意图。下面参照图1阐述根据本发明示例的点对点转账系统。如图1所示,模拟支付账户载体的终端,即第一终端10包括第一应用单元100,模拟支付受理终端,即第二终端20包括第二应用单元200。在本例中,依据第一终端10与第二终端20的转账角色,将第一应用单元100称作转出应用单元而将第二应用单元200称作转入应用单元,但实际应用中,转入应用单元与转出应用单元可实现为既包括转入功能又包括转出功能的应用,这也使得装载了该应用的终端既可以作为支付账户载体也可作为支付受理终端。后台系统30则包括了后台应用单元(未标号)。
模拟支付账户载体的第一终端10与模拟支付受理终端的第二终端20分别连接后台系统30。第一终端10通过其第一应用单元100向后台系统30的后台应用获取第一令牌31(下文中也称为Token 1),第二终端20通过其第二应用单元200向后台系统30的后台应用获取第二令牌32(下文中也称为Token 2)。
根据本发明的该示例,第一令牌31由后台系统30的后台应用单元生成,第二令牌32同样由后台系统30的后台应用生成。在有关转账的操作中,当后台系统30在接收到第一终端10传送的操作请求时,后台系统30的后台应用单元将会通过当前的交易时间、交易金额、随机数中的任意一项或它们的结合对所产生的第一令牌31进行异或等逻辑操作,以便该令牌更为安全。类似地,在有关转账的操作中,当后台系统30在接收到第二终端20传送的操作请求时,后台系统30的后台应用单元将会通过当前的交易时间、交易金额、随机数中的任意一项或它们的结合对所产生的第二令牌20进行异或等逻辑操作,以便该令牌更为安全。需要说明的是,可以通过当前的交易时间、交易金额、随机数中的任意一项或其结合对第一令牌31与第二令牌32两者均进行异或等逻辑操作,也可仅对第一令牌31与第二令牌32中的一个进行异或等逻辑操作。
更进一步,为了使Token 1和Token 2即使被非法截取也不产生信息泄露的情况,按照本发明的示例,将第一令牌31与第二令牌32重组以形成第一替代令牌与第二替代令牌。示例地,可将第一令牌31分成两个数据段,将第二令牌32分成两个数据段,由此将第一令牌31的一个数据段与第二令牌32的一个数据
段组合构成第一替代令牌而将第一令牌31剩余的数据段与第二令牌32剩余的数据段组合以构成第二替代令牌。同样地,可将第一令牌31分成两个数据段而将第二令牌32分成三个数据段,由此将第一令牌31的一个数据段与第二令牌32的两个数据段组合以构成一个替代令牌而将第一令牌31剩余的数据段与第二令牌32剩余的数据段组成以构成另一个替代令牌。举例来说,可以用前1/2和后1/2方式拆解重组,如:Token1的前1/2和Token2的后1/2,以及Token2的前1/2和Token2的后1/2(可以设置几种,具体每次交易过程后台和前端随机选取即可)。如上讨论的第一令牌31与第二令牌32的重组过程可以由第二终端20的第二应用单元200来执行。
在现场交易的过程中,模拟支付账户载体的手机终端10和模拟支付受理终端的手机终端20通过NFC技术进行交互,通过该过程模拟支付受理终端的手机获取转出账户Token 1,并将Token 1以及自身获得Token 2发送给后台系统,或将经过重组的第一替代令牌与第二替代令牌例如作为交易报文发送给后台系统30。
支付受理终端组织交易报文到后台系统30,由后台系统进行Token的鉴权和匹配,再将交易请求发送到发卡机构40进行授权。发卡机构授权完成后,交易应答原路返回到支付受理终端20,并发短信给支付账户载体终端10。
在一个具体的实施例中,在后台系统30中执行的点对点转账方法包括:生成第一令牌,并将所述第一令牌发送给模拟支付账户载体的第一终端,其中,所述第一令牌包括与所述第一终端关联的账户信息;生成第二令牌,并将所述第二令牌发送给模拟支付受理终端的第二终端,其中,所述第二令牌包括与所述第二终端关联的账户信息;接收由所述第二终端发送的所述第一令牌和所述第二令牌,其中,所述第一令牌由所述第一终端通过近距离无线通讯技术转发给所述第二终端;以及对所述第一令牌和所述第二令牌进行鉴权和匹配。
在一个实施例中,接收由所述第二终端发送的所述第一令牌和所述第二令牌包括将所述第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌,从而由所述第二终端发送第一替代令牌与第二替代令牌给后台系统。作为一个具体示例,按照如下方式来将所述第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数
据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合,以构成分别包括第一令牌的数据段与第二令牌的数据段的第一替代令牌与第二替代令牌。作为一个具体的示例,两个Token可以用前1/2和后1/2等方式进行拆解重组,确保在支付受理终端和后台系统传输过程中两个账户的Token即使被截取也无法还原,进一步加强安全。
根据本发明的各示例中,对所述第一令牌和所述第二令牌进行鉴权和匹配包括:从所述第一令牌和所述第二令牌提取交易要素。随后,可将所述交易要素发送给发卡系统,以便进行交易授权。
根据本发明的一个实施例,将所生成的第一令牌发送给模拟支付账户载体的第一终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第一令牌进行逻辑处理,以及将所生成的第二令牌发送给模拟支付账户载体的第二终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第二令牌进行逻辑处理。如此,进一步加强转账处理的安全性。
在另一个具体的实施例中,提供了一种点对点转账系统。该系统包括:位于服务器端的后台系统;第一终端;以及第二终端。在进行转账交易时,第一终端和第二终端配置成分别从所述后台系统获取第一令牌和第二令牌,所述第一令牌包括与第一终端关联的第一账户信息而所述第二令牌包括与第二终端关联的第二账户信息。第一终端通过近距离无线通讯技术将所述第一令牌转发给所述第二终端。在收到所转发的第一令牌后,第二终端将所述第一令牌和所述第二令牌两者发送给所述后台系统,以便进行令牌的鉴权和匹配。
在一个实施例中,上述点对点转账系统还包括发卡系统,所述第二终端设置成在将所述第一令牌和所述第二令牌两者发送给所述后台系统之前,将第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌。示例地,所述第二终端设置成通过如下方式将第一令牌与第二令牌重组以形成第一替代令牌信息与第二替代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合,以构成分别包括第一令牌的数据段与第二令牌的数据段的第一替代令牌与第二替代令牌。作为一个更为具体的示例,例如,在传输过程中两个Token可以用前1/2和后1/2等方式进行拆解重组,确保在支付受理终端和后台系统传
输过程中两个账户的Token即使被截取也无法还原,进一步加强安全。
在一个实施例中,后台系统在收到从所述第二终端发送的第一令牌和第二令牌后,对所述第一令牌和所述第二令牌进行鉴权和匹配,从而获取交易要素以进行账户匹配和交易授权。
在一个实施例中,第一终端配置成模拟支付账户载体,第二终端配置成模拟支付受理终端,采用所述近距离无线通讯技术,第二终端获取第一终端传输的第一令牌的信息,并进而将第一令牌与第二令牌传输的后台系统。在该示例中,如果是第一终端作为NFC传输的发起方(主设备),则在第一终端与第二终端之间的数据传输过程中,第一终端提供射频场,反之,第二终端提供射频场。但是,就处理转账业务而言,是经由作为模拟支付受理终端的第二终端来向后台发起请求,可将其理解为整个转账业务的发起方或称其处于主动工作模式而第二终端处于被动工作模式。
在一个实施例中,所述后台系统配置成在将所述第一令牌和所述第二令牌分别发送给所述第一终端和所述第二终端之前,利用交易时间、随机数、交易金额中的一项或多项来对所述第一令牌和/或所述第二令牌进行逻辑处理,从而确保传输安全。
在此所描述的各示例或实施例中,关于第一令牌与第二令牌重组的方式有多种,根据本发明,后台系统与终端之间会预先约定采用哪些重组方式,采用不同的重组方式,则在第二终端发给后台系统的报文信息中会进行指示,以便后台系统正确地从第一替代令牌与第二替代令牌识别出第一令牌与第二令牌。更为具体地,后台系统的后台应用单元与设置在终端的第二应用单元之间会预先约定采用哪些重组方式,采用不同的重组方式,则在第二终端发给后台系统的报文信息中会进行指示,以便后台系统的后台应用单元可正确地从第一替代令牌与第二替代令牌识别出第一令牌与第二令牌。
在本发明的各示例中,第一应用单元、第二应用单元以及后台应用单元每一个都可以软件的形式实现,从而装载到第一终端、第二终端以及现有的后台系统中;可替代地,第一应用单元、第二应用单元以及后台应用单元每一个都可以软件结合硬件的形式实现,从而装载到第一终端、第二终端以及现有的后台系统中。更进一步,根据本发明示例的点对点转账系统可以软件、或硬件、或软件与
硬件结合的方式实现。
本申请的系统在保证安全的前提下实现了由转入方主动发起资金划转交易到后台授权。账户信息由个人移动终端自动非接触方式读取,无需转出方告知转入方卡号信息,方便且提高安全性。另外,利用令牌方式传递账户信息,再由后台系统匹配,避免转出卡卡号被受理终端获取,避免卡号泄露等风险隐患,提高安全性。
上文中,参照附图描述了本发明的具体实施方式。但是,本领域中的普通技术人员能够理解,在不偏离本发明的精神和范围的情况下,还可以对本发明的具体实施方式作各种变更和替换。这些变更和替换都落在本发明权利要求书所限定的范围内。
Claims (13)
- 一种点对点转账系统,所述系统应用在包括第一终端、第二终端及设置在服务器端的后台系统的应用环境中,该点对点转账系统包括:设置在后台系统的后台应用单元;设置在第一终端的第一应用单元;设置在第二终端的第二应用单元;其中,在进行转账交易时,所述第一终端和所述第二终端配置成分别通过第一应用与第二应用,向所述后台系统的后台应用获取第一令牌和第二令牌,所述第一令牌包括与第一终端关联的第一账户信息而所述第二令牌包括与第二终端关联的第二账户信息;所述第一终端通过近距离无线通讯技术将所述第一令牌转发给所述第二终端;以及在收到所转发的第一令牌后,所述第二终端将所述第一令牌和所述第二令牌两者发送给所述后台系统,以便进行令牌的鉴权和匹配。
- 如权利要求1所述的点对点转账系统,其中,所述第二终端设置成在将所述第一令牌和所述第二令牌两者发送给所述后台系统之前,通过所述第二应用单元将第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌。
- 如权利要求2所述的点对点转账系统,其中,所述第二应用单元设置成通过如下方式将第一令牌与第二令牌重组以形成第一替代令牌与第二替代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合以构成第一替代令牌与第二替代令牌,其中,所述第一替代令牌与第二替代令牌各自都包括第一令牌的部分数据段与第二令牌的部分数据段。
- 如权利要求1到3中任意一项所述的点对点转账系统,其中,所述后台系统在收到从所述第二终端发送的第一令牌和第二令牌后,对所述第一令牌和所述第二 令牌进行鉴权和匹配,从而获取交易要素以进行账户匹配和交易授权。
- 如权利要求1到3中任意一项所述的点对点转账系统,其中,所述第一终端被配置成模拟支付账户载体。
- 如权利要求1到3中任意一项所述的点对点转账系统,其中,所述第二终端被配置成模拟支付受理终端。
- 如权利要求1到3中任意一项所述的点对点转账系统,其中,所述后台应用单元配置成在将所述第一令牌和所述第二令牌分别发送给所述第一终端和所述第二终端之前,利用交易时间、随机数、交易金额中的一项或多项来对所述第一令牌和/或所述第二令牌进行逻辑处理,从而确保传输安全。
- 一种在后台系统中执行的点对点转账方法,所述方法包括:生成第一令牌,并将所述第一令牌发送给模拟支付账户载体的第一终端,其中,所述第一令牌包括与所述第一终端关联的账户信息;生成第二令牌,并将所述第二令牌发送给模拟支付受理终端的第二终端,其中,所述第二令牌包括与所述第二终端关联的账户信息;接收由所述第二终端发送的所述第一令牌和所述第二令牌,其中,所述第一令牌由所述第一终端通过近距离无线通讯技术转发给所述第二终端;以及对所述第一令牌和所述第二令牌进行鉴权和匹配。
- 如权利要求8所述的点对点转账方法,其中,接收由所述第二终端发送的所述第一令牌和所述第二令牌包括:所述第一令牌与第二令牌被重组以形成第一替代令牌与第二替代令牌,接收所发送的第一替代令牌与第二替代令牌。
- 如权利要求9所述的点对点转账方法,其中,所述第一令牌与第二令牌被按照如下步骤重组以形成第一替代令牌与第二替代令牌:将所述第一令牌的数据分成至少两个数据段,将所述第二令牌的数据分成至少两个数据段;以及将由第一令牌的分成的数据段与由第二令牌分成的数据段组合以构成第一替代令牌与第二替代令牌,其中,所述第一替代令牌与第二替代令牌各自都包括第一令牌的部分数据段与第二令牌的部分数据段。
- 如权利要求8到10中任意一项所述的点对点转账方法,其中,对所述第一令牌和所述第二令牌进行鉴权和匹配包括:从所述第一令牌和所述第二令牌提取交易要素。
- 如权利要求8到10中任意一项所述的点对点转账方法,还包括:将所述交易要素发送给发卡系统,以便进行交易授权。
- 如权利要求8到10中任意一项所述的点对点转账方法,其中,将所生成的第一令牌发送给模拟支付账户载体的第一终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第一令牌进行逻辑处理,和/或将所生成的第二令牌发送给模拟支付账户载体的第二终端之前,利用交易时间、随机数、交易金额中的一项或多项对所述第二令牌进行逻辑处理。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610379732.5A CN106022743A (zh) | 2016-06-01 | 2016-06-01 | 点对点转账系统和方法 |
| CN201610379732.5 | 2016-06-01 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017206680A1 true WO2017206680A1 (zh) | 2017-12-07 |
Family
ID=57092020
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/083714 Ceased WO2017206680A1 (zh) | 2016-06-01 | 2017-05-10 | 点对点转账系统和方法 |
Country Status (3)
| Country | Link |
|---|---|
| CN (1) | CN106022743A (zh) |
| TW (1) | TWI684945B (zh) |
| WO (1) | WO2017206680A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106022743A (zh) * | 2016-06-01 | 2016-10-12 | 中国银联股份有限公司 | 点对点转账系统和方法 |
| CN110663055A (zh) | 2017-05-16 | 2020-01-07 | 苹果公司 | 促进用户帐户之间的资金转移 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103679443A (zh) * | 2012-09-18 | 2014-03-26 | 中国银联股份有限公司 | 一种利用手机终端进行的支付方法及其处理系统 |
| US20140256251A1 (en) * | 2013-03-11 | 2014-09-11 | Cellco Partnership D/B/A Verizon Wireless | Secure nfc data authentication |
| CN104951937A (zh) * | 2015-04-27 | 2015-09-30 | 上海浩恺信息科技有限公司 | 一种移动设备之间的鉴权方法和鉴权系统 |
| CN105139193A (zh) * | 2015-07-31 | 2015-12-09 | 腾讯科技(深圳)有限公司 | 一种电子资源处理方法、装置及服务器 |
| WO2016049745A1 (en) * | 2014-09-29 | 2016-04-07 | Royal Bank Of Canada | Secure processing of data |
| CN106022743A (zh) * | 2016-06-01 | 2016-10-12 | 中国银联股份有限公司 | 点对点转账系统和方法 |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103067385B (zh) * | 2012-12-27 | 2015-09-09 | 深圳市深信服电子科技有限公司 | 防御会话劫持攻击的方法和防火墙 |
| CN105847000A (zh) * | 2016-05-27 | 2016-08-10 | 深圳市雪球科技有限公司 | 令牌产生方法以及基于该令牌产生方法的通信系统 |
-
2016
- 2016-06-01 CN CN201610379732.5A patent/CN106022743A/zh active Pending
-
2017
- 2017-05-10 WO PCT/CN2017/083714 patent/WO2017206680A1/zh not_active Ceased
- 2017-05-11 TW TW106115671A patent/TWI684945B/zh active
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103679443A (zh) * | 2012-09-18 | 2014-03-26 | 中国银联股份有限公司 | 一种利用手机终端进行的支付方法及其处理系统 |
| US20140256251A1 (en) * | 2013-03-11 | 2014-09-11 | Cellco Partnership D/B/A Verizon Wireless | Secure nfc data authentication |
| WO2016049745A1 (en) * | 2014-09-29 | 2016-04-07 | Royal Bank Of Canada | Secure processing of data |
| CN104951937A (zh) * | 2015-04-27 | 2015-09-30 | 上海浩恺信息科技有限公司 | 一种移动设备之间的鉴权方法和鉴权系统 |
| CN105139193A (zh) * | 2015-07-31 | 2015-12-09 | 腾讯科技(深圳)有限公司 | 一种电子资源处理方法、装置及服务器 |
| CN106022743A (zh) * | 2016-06-01 | 2016-10-12 | 中国银联股份有限公司 | 点对点转账系统和方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201743268A (zh) | 2017-12-16 |
| TWI684945B (zh) | 2020-02-11 |
| CN106022743A (zh) | 2016-10-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12141266B2 (en) | Proof of affinity to a secure event for frictionless credential management | |
| JP7204705B2 (ja) | セキュアデバイス機能へのオンラインアクセスの妥当性検査 | |
| AU2018202542B2 (en) | Automated account provisioning | |
| CN102088353B (zh) | 基于移动终端的双因子认证方法及系统 | |
| CN103903141B (zh) | 一种o2o安全支付方法、系统和一种pos终端 | |
| US8438288B2 (en) | Device-pairing by reading an address provided in device-readable form | |
| US20180331837A1 (en) | Secure information transmitting system and method for personal identity authentication | |
| US20170364911A1 (en) | Systems and method for enabling secure transaction | |
| CN110073387A (zh) | 证实通信设备与用户之间的关联 | |
| AU2015247929A1 (en) | Systems, apparatus and methods for improved authentication | |
| CN103914774B (zh) | 一种o2o安全支付方法和系统 | |
| WO2020107233A1 (zh) | 基于区块链的钱包系统及钱包使用方法、以及存储介质 | |
| CN103577983A (zh) | 一种脱机消费电子货币的圈存方法 | |
| WO2018166359A1 (zh) | 移动支付转授权方法、及利用该方法实现的支付系统 | |
| CN105243542A (zh) | 一种动态电子凭证认证的系统及方法 | |
| CN104835038A (zh) | 一种联网支付装置及方法 | |
| WO2017206680A1 (zh) | 点对点转账系统和方法 | |
| US20240370846A1 (en) | Secure payment transactions | |
| TW201419820A (zh) | 藉由使用者位置檢驗身份的網路安全驗證方法 | |
| US11397940B2 (en) | Secure payment transactions | |
| HK1230322A (zh) | 点对点转账系统和方法 | |
| HK1230322A1 (zh) | 點對點轉賬系統和方法 | |
| CN103581126A (zh) | 安全性信息交互系统、设备及方法 | |
| CN114066626A (zh) | 密码货币交易系统 | |
| CN103457728A (zh) | 安全性信息交互系统、设备及方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17805625 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17805625 Country of ref document: EP Kind code of ref document: A1 |