WO2018040976A1 - 基于Token的支付方法以及基于Token的支付系统 - Google Patents
基于Token的支付方法以及基于Token的支付系统 Download PDFInfo
- Publication number
- WO2018040976A1 WO2018040976A1 PCT/CN2017/098401 CN2017098401W WO2018040976A1 WO 2018040976 A1 WO2018040976 A1 WO 2018040976A1 CN 2017098401 W CN2017098401 W CN 2017098401W WO 2018040976 A1 WO2018040976 A1 WO 2018040976A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- token
- payment
- mobile terminal
- bank card
- management system
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/326—Payment applications installed on the mobile devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3276—Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being read by the M-device
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
Definitions
- the present invention relates to the field of computer application technologies, and in particular, to a Token-based payment method and a Token-based payment system.
- QR code payment is a mobile phone channel that the consumer provides through the bank or third party payment to scan the product QR code to complete the payment.
- the merchant compiles the transaction information such as the account number and the commodity price into a two-dimensional code and publishes it on various carriers.
- More and more lawless elements regard bank card information as the target of attack.
- the QR code is generally generated in plain text of the bank card's main account.
- the leakage of the cardholder's account information causes the merchant to face huge economic risks.
- an object of the present invention is to provide a Token-based payment method and a Token-based payment system capable of improving transaction security.
- the binding step is to generate a static token based on the bank card information, and bind the static token to the terminal identification information, where the bank card information includes at least a bank card account number;
- a payment identifier image generating step when the payment is required, generating a dynamic token according to the terminal identification information and the static token to replace the bank card account with the dynamic token, and generating a payment identifier image according to the dynamic token;
- the payment transaction step reads the payment identification image, and replaces the dynamic token included in the payment identification image with the bank card account number to complete the subsequent payment transaction.
- the Token management system generates a static Token based on the bank card information sent from the mobile terminal, binds the static Token with the terminal identification information, and binds the static Token is stored in the Token management system and mobile terminal.
- the Token management system verifies the terminal identification information and the static Token sent from the mobile terminal, generates a dynamic Token when the verification is successful, and sends the dynamic Token to the mobile terminal, and the mobile terminal generates a payment identification image according to the dynamic Token.
- the merchant terminal scans the payment identification image and sends it to the payment system, and then forwards the Token management system to verify the dynamic Token. After the verification is successful, the dynamic Token is replaced with the bank card information and then returned to the payment system. The payment system completes the subsequent payment transaction.
- the binding step comprises the following sub-steps:
- the cardholder submits the bank card information to the Token management system through the mobile terminal;
- the mobile terminal collects terminal identification information and sends the information to the Token management system;
- the Token management system verifies the identity information of the cardholder
- the Token management system In case the verification is successful, the Token management system generates a static token
- the Token management system stores the static Token and sends it to the mobile terminal; and the mobile terminal replaces the bank card account with the static Token and stores it in the mobile terminal.
- the payment identification image generating step comprises the following sub-steps:
- the mobile terminal sends the static token and the terminal identification information to the Token management system according to the payment request;
- the Token management system verifies the terminal identification information and the static token sent from the mobile terminal;
- the mobile terminal generates a payment identification image according to the dynamic Token.
- the payment transaction step comprises:
- the dynamic Token is replaced with a bank card account and returned to the payment system;
- the payment identification image is a two-dimensional code or a barcode.
- the bank card information further includes a number name and a mobile phone number
- the terminal identification information includes a terminal device number and a MAC address.
- the Token-based payment system of the present invention is characterized in that it comprises: a mobile terminal, a Token Management systems, merchant terminals, and payment systems,
- the mobile terminal is communicably connected to the Token management system, and is configured to store a static token in a binding phase for generating a payment identifier image according to the dynamic Token described below, in the binding phase, the Token management system Used in the binding phase to generate a dynamic token based on the generation of a static token for replacing the bank card account, and on the other hand to verify the payment uploaded from the mobile terminal in the case of a call by the payment system Identify the dynamic Token contained in the image and replace the dynamic Token with the bank card account and return to the payment system if the verification is successful.
- the merchant terminal is configured to read the payment identification image and send it to a payment system in a payment phase, and the payment system invokes the Token management system to obtain a bank card account number and completes the receipt of the payment mark image. Subsequent payment transactions.
- the mobile terminal is configured to send bank card information and terminal identification information to the Token management system during the binding phase and to store the following static Token returned from the Token management system, in the payment phase.
- the Token management system is configured to generate, according to the bank card information from the mobile terminal, a static Token for replacing the bank card account number and bind the static Token with the terminal identification information during the binding phase;
- the terminal identification information and the static token sent from the mobile terminal are generated and sent to the mobile terminal when the verification is successful, and used to verify the upload from the mobile terminal when the payment system is called by the payment system.
- the dynamic token included in the logo image is paid and the dynamic token is replaced with the bank card account and returned to the payment system if the verification is successful.
- the Token management system is used in the transaction phase to generate a one-time use dynamic token.
- the payment identification image generated by the mobile terminal in the payment phase according to the dynamic token is a two-dimensional code or a barcode.
- the bank card information further includes a number name and a mobile phone number
- the terminal identification information includes a terminal device number and a MAC address.
- the Token-based payment method and the Token-based payment system of the present invention since the original bank card account number is replaced by the dynamic token information, the possibility of the card number information leakage can be eliminated.
- the scope of the Token application is limited when the Token is generated, that is, by adding the terminal identifier
- the information makes the application scope of the Token only limited to the mobile terminal, thereby further reducing the range of influence after the payment mark is leaked.
- the association information verification of the Token and the mobile terminal it is possible to prevent fraudulent transactions caused by information leakage.
- FIG. 1 is a configuration diagram showing a Token-based payment system of the present invention.
- FIG. 2 is a flow chart showing a Token-based payment method of the present invention.
- the invention provides a Token-based payment method and payment system.
- the bank token main account, the name, the mobile phone number, the validity period and the like are replaced by a unique static token by the payment tokenization technology, and the binding relationship between the static token and the terminal identification information is established, and at the same time, the dynamic token is used.
- the terminal identification information generates a payment token (for example, a two-dimensional code, etc.), and replaces the bank card master account with the dynamic token in the transaction process, and simultaneously submits the terminal identification information bound to the static token.
- the transaction information is sent from the payment system to the issuing bank to complete the transaction.
- the security of the sensitive information such as the bank card master account is ensured, and the security of the payment is improved.
- FIG. 1 is a configuration diagram showing a Token-based payment system of the present invention.
- the Token-based payment system of the present invention includes a mobile terminal 100, a Token management system 200, a payment system 400, and a merchant terminal 300.
- the mobile terminal 100 is, for example, a mobile terminal such as a mobile phone, a mobile pad, or the like, in which an application for realizing payment is installed.
- the mobile terminal 100 is communicably connected to the Token management system 200 for transmitting terminal identification information and bank card information to the Token management system 200 during the binding phase and storing the terminal identification information returned from the Token management system 200 and the static Token described below.
- the mobile terminal 100 is configured to transmit the terminal identification information and the static token to the Token management system 200 and generate a payment identification image for acquisition by the merchant terminal 300 according to the dynamic Token returned from the Token management system 200.
- the Token management system 200 is used to implement Token application, generation, management, de-marking, and the like.
- the body of the lifecycle management is responsible for the association of the Token with the mobile terminal 100 and provides the Token related service to the payment system 400.
- the Token management system 200 is configured to generate a static token for replacing the bank card account according to the bank card information from the mobile terminal 100 and bind the static token with the terminal identification information during the binding phase, and is used for verifying in the payment phase.
- the terminal identification information and the static Token sent by the mobile terminal 100 generate a dynamic Token and transmit it to the mobile terminal 100 if the verification is successful, and the Token management system 200 is used for verification when the payment system 300 is called by the payment system 300.
- the dynamic Token uploaded from the mobile terminal 100 and returned to the payment system 400 after replacing the dynamic Token with the bank card account in the case where the verification is successful.
- the merchant terminal 300 is used to read the payment identification image generated by the mobile terminal 100 in the payment phase and transmit it to the payment system 400.
- the payment system 400 is for implementing the processing of the payment transaction, is capable of processing the payment mark image generated by the Token and the terminal identification information, and is capable of verifying the Token information and the terminal identification information by calling the service of the Token management system 200. Specifically, the payment system 400 calls the Token management system to obtain a bank card account number upon receipt of the payment identification image, thereby completing the subsequent payment transaction. Subsequent payments will be forwarded by the payment system 400 to the issuing bank for execution and return to the original results. These processes are not part of the present invention and will not be described in detail herein.
- Token refers to a substitute value of the bank card master account, for example, generally can be composed of 13 to 19 digits, and can be used to replace the bank card account number in the transaction without affecting the transaction processing.
- FIG. 2 is a flow chart showing a Token-based payment method of the present invention.
- the Token-based payment method of the present invention can be roughly divided into the following three stages:
- Binding phase a static token is generated based on the bank card information, and the static token is bound to the terminal identification information, wherein the bank card information includes at least a bank card account number;
- Binding phase ie, the card binding process
- the cardholder submits the bank card information such as the bank card, the name, the mobile phone number, and the validity period to the Token management system 200 through the mobile terminal 100.
- the mobile terminal 100 collects the terminal device number, the MAC address, and the like.
- the terminal identifies the information and submits the information to the Token management system 200 for binding application.
- the Token management system 200 After the cardholder submits the application, the Token management system 200 verifies the identity information of the cardholder (including account verification, mobile phone number verification, etc.). After the verification is successful, the Token management system 200 generates a static Token, and binds the static Token with the terminal identification information, and stores it in the Token management system 200.
- the Token management system 200 delivers the static token to the mobile terminal.
- the mobile terminal 100 replaces the bank card account number with the static token and saves it locally and the server.
- the identity verification and the terminal identification information binding are required to be re-established; only when the verification is successful, the Token and the terminal binding relationship are allowed to be updated.
- S104 The cardholder submits the payment application at the mobile terminal 100, and the mobile terminal 100 sends the static Token generated during the card-binding process to the Token management system 200, and simultaneously sends the terminal device number, the MAC address, and the like to identify the terminal identification information.
- S105 The Token management system 200 verifies static token information and terminal identification information.
- S106 After the Token management system 200 successfully verifies, generate a dynamic Token, and return the dynamic Token to the mobile terminal.
- the dynamic Token is preferably valid for only one use.
- the mobile terminal 100 generates a payment mark image using the dynamic token and the terminal identification information.
- the payment mark image it may be a two-dimensional code, a barcode, or any other image that can implicitly include dynamic tokens and terminal identification information.
- S108 The merchant terminal 300 reads the payment mark image displayed on the cardholder's mobile terminal 100.
- S109 The merchant terminal 300 sends the identified transaction information to the payment system 400, and the bank card account number in the transaction information is replaced by the dynamic token information.
- the payment system 400 calls the service provided by the Token management system 200.
- the Token management system 200 verifies the card holder's dynamic token information and terminal identification information, and replaces the dynamic token with the bank card account number, completes the de-marking process, and returns to the payment system 400.
- the payment system 400 sends the payment message to the card issuer to complete the debit and return the transaction result source to the payment system.
- This part does not belong to the content of the present application, and therefore this part is not shown in FIG.
- the Token-based payment method and the Token-based payment system of the present invention since the original bank card account number is replaced by the dynamic token information, the possibility of the card number information leakage can be eliminated.
- the scope of the Token application is limited when the Token is generated, that is, the application scope of the Token is limited to the mobile terminal by adding the terminal identification information, thereby further reducing the impact range after the payment token is leaked. .
- the association information verification of the Token and the mobile terminal it is possible to prevent fraudulent transactions caused by information leakage.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Security & Cryptography (AREA)
- Finance (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
本发明涉及基于Token的支付方法以及基于Token的支付系统。该方法包括下述步骤:绑定步骤,基于银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定,其中,所述银行卡信息至少包括银行卡帐号;支付标识图像生成步骤,在需要进行支付时,根据终端标识信息和静态Token生成动态Token以使得用该动态Token替换银行卡帐号,根据该动态Token生成支付标识图像;以及支付交易步骤,读取该支付标识图像,将该支付标识图像中包含的动态Token替换回银行卡帐号来完成后续的支付交易。根据本发明的能够提高移动支付的安全性,能够防止信息泄露导致的欺诈交易。
Description
本发明涉及计算机应用技术领域,特别地涉及一种基于Token的支付方法以及基于Token的支付系统。
随着二维码应用的兴起,国内各个互联网公司及商业银行都在推动二维码技术应用于支付,目前二维码支付技术已广泛应用。二维码支付是消费者通过银行或第三方支付提供的手机端通道扫描商品二维码,进而完成支付。在该支付技术方案下,商家把账号、商品价格等交易信息汇编成一个二维码,并在各种载体上发布。这种方式有如下缺点:
越来越多的不法分子将银行卡信息视为攻击目标,目前二维码普遍以银行卡主账号明文生成,持卡人账户信息的泄露导致商户面临巨大的经济风险。
一旦在互联网上攻击手机客户端和商户二维码设备,篡改支付信息和支付结果,支付过程将不可控。
发明内容
鉴于上述问题,本发明的目的在于,提供一种能够提高交易安全性的基于Token的支付方法以及基于Token的支付系统。
本发明的基于Token的支付方法,其特征在于,包括下述步骤:
绑定步骤,基于银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定,其中,所述银行卡信息至少包括银行卡帐号;
支付标识图像生成步骤,在需要进行支付时,根据终端标识信息和静态Token生成动态Token以使得用该动态Token替换银行卡帐号,根据该动态Token生成支付标识图像;以及
支付交易步骤,读取该支付标识图像,将该支付标识图像中包含的动态Token替换回银行卡帐号来完成后续的支付交易。
优选地,在所述绑定步骤中,Token管理系统根据从移动终端发送来的银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定并将所述静态
Token储存于Token管理系统和移动终端,
在支付标识图像生成步骤中,Token管理系统验证从移动终端发送来的终端标识信息和静态Token,在验证成功的情况下生成动态Token并发送给移动终端,移动终端根据该动态Token生成支付标识图像,
在所述支付交易步骤中,商户终端扫描所述支付标识图像并发送到支付系统后转发Token管理系统验证动态Token,在验证成功的情况下将动态Token替换成银行卡信息后返回支付系统,由支付系统完成后续支付交易。
优选地,所述绑定步骤包括下述子步骤:
持卡人通过移动终端向Token管理系统提交银行卡信息;
移动终端采集终端标识信息发送到Token管理系统;
Token管理系统验证持卡人的身份信息;
在验证成功的情况下,Token管理系统生成静态Token;
Token管理系统储存该静态Token并发送到移动终端;以及在移动终端用该静态Token替换银行卡帐号并储存于移动终端。
优选地,所述支付标识图像生成步骤包括下述子步骤:
移动终端根据支付请求将静态Token和终端标识信息发送到Token管理系统;
Token管理系统验证从移动终端发送来的终端标识信息和静态Token;
在验证成功的情况下生成一次性使用的动态Token并发送给移动终端;
移动终端根据该动态Token生成支付标识图像。
优选地,所述支付交易步骤包括:
商户终端扫描所述支付标识图像并识别交易信息;
将交易信息发送到支付系统并调用Token管理系统验证所述交易信息中包含的动态Token和终端标识信息;
在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统;
由支付系统完成后续支付交易。
优选地,所述支付标识图像是二维码或者条形码。
优选地,所述银行卡信息还包括号姓名、手机号码,所述终端标识信息包括终端设备号、MAC地址。
本发明的基于Token的支付系统,其特征在于,具备:移动终端、Token
管理系统、商户终端以及支付系统,
其中,所述移动终端与所述Token管理系统能够通信连接,在绑定阶段用于储存下述的静态Token,在支付阶段用于根据下述的动态Token生成支付标识图像,所述Token管理系统在绑定阶段用于根据生成用于替代银行卡帐号的静态Token,在支付阶段用于生成动态Token,另一方面在受到所述支付系统调用的情况下,用于验证从移动终端上传的支付标识图像中包含的动态Token并且在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统,
所述商户终端在支付阶段用于读取所述支付标识图像并发送到支付系统,所述支付系统在收到所述支付标记图像的情况下调用所述Token管理系统以获得银行卡帐号并完成后续支付交易。
优选地,所述移动终端在绑定阶段用于将银行卡信息和终端标识信息发送到所述Token管理系统并且用于储存从所述Token管理系统返回的下述的静态Token,在支付阶段用于根据从所述Token管理移动终端发送来的动态Token生成支付标识图像,
所述Token管理系统在绑定阶段用于根据来自所述移动终端的银行卡信息生成用于替代银行卡帐号的静态Token并且将所述静态Token与终端标识信息绑定;在支付阶段用于验证从移动终端发送来的终端标识信息和静态Token,在验证成功的情况下生成动态Token并发送给移动终端,另一方面在受到所述支付系统调用的情况下,用于验证从移动终端上传的支付标识图像中包含的动态Token并且在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统。
优选地,所述Token管理系统在交易阶段用于生成一次性使用的动态Token。
优选地,所述移动终端在支付阶段用于根据所述动态Token生成的支付标识图像是二维码或者条形码。
优选地,所述银行卡信息还包括号姓名、手机号码,所述终端标识信息包括终端设备号、MAC地址。
本发明的基于Token的支付方法以及基于Token的支付系统中,由于使用动态Token信息替换了原始的银行卡帐号,能够杜绝卡号信息泄露的可能。另外,由于在Token产生时,对Token应用的范围进行了限定,即,通过增加终端标识
信息使得该Token的应用范围仅是限定在该移动终端,由此能够进一步降低支付标记泄露后的影响范围。而且,通过Token与移动终端的关联信息验证,能够防止信息泄露导致的欺诈交易。
图1是表示本发明的基于Token的支付系统的构造图。
图2是表示本发明的基于Token的支付方法的流程图。
_
下面介绍的是本发明的多个实施例中的一些,旨在提供对本发明的基本了解。并不旨在确认本发明的关键或决定性的要素或限定所要保护的范围。
本发明提供了一种基于Token的支付方法和支付系统。本发明中通过支付标记化技术将银行卡主账号、姓名、手机号、有效期等信息用一个唯一的静态Token来替代,并建立静态Token与终端标识信息的绑定关系,同时,使用动态Token与终端标识信息生成支付标记向(例如,二维码等),在交易过程中,使用动态Token替换银行卡主账号,同时提交与静态Token绑定的终端标识信息。最终通过Token管理方的验证与替换,将交易信息从支付系统发送到发卡行,完成交易。通过支付标记化技术的替换与终端的绑定,保证了银行卡主账号等敏感信息的安全,同时又提高支付的安全性。
图1是表示本发明的基于Token的支付系统的构造图。
如图1所示,本发明的基于Token的支付系统包括:移动终端100、Token管理系统200、支付系统400以及商户终端300。
移动终端100例如是手机、移动Pad等的移动终端,其中安装有实现支付的应用。移动终端100与Token管理系统200能够通信连接,在绑定阶段用于将终端标识信息和银行卡信息发送到Token管理系统200并且储存从Token管理系统200返回的终端标识信息和下述的静态Token,在支付阶段移动终端100用于将终端标识信息和静态Token发送到Token管理系统200并且根据从Token管理系统200返回的动态Token生成支付标识图像以供商户终端300获取。
Token管理系统200用于实现Token的申请、生成、管理、去标记化等全
生命周期管理的主体,同时负责Token与移动终端100的关联,并向支付系统400提供Token相关服务。具体地,Token管理系统200在绑定阶段用于根据来自移动终端100的银行卡信息生成用于替代银行卡帐号的静态Token并且将静态Token与终端标识信息绑定,在支付阶段用于验证从移动终端100发送来的终端标识信息和静态Token,在验证成功的情况下生成动态Token并发送给移动终端100,另一方面在受到支付系300统调用的情况下,Token管理系统200用于验证从移动终端100上传的动态Token并且在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统400。
商户终端300在支付阶段用于读取由移动终端100生成的支付标识图像并发送到支付系统400。
支付系统400用于实现支付交易的处理,能够处理通过Token和终端标识信息生成的支付标记图像,并能够通过调用Token管理系统200的服务验证Token信息与终端标识信息。具体地,支付系统400在收到支付标识图像的情况下调用Token管理系统以获得银行卡帐号,由此完成后续支付交易。后续的支付将由支付系统400转发到发卡行机构执行完成并原路返回结果,这些过程不属于本发明的内容,在此不做详细描述。
在本发明中,Token(即支付标记),是指银行卡主账户的一个替代值,例如一般可以由13至19位数字组成,在交易中可用来替换银行卡帐号,不影响交易处理。
图2是表示本发明的基于Token的支付方法的流程图。
本发明的基于Token的支付方法大致可以分为以下三个阶段:
(1)绑定阶段:基于银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定,其中,所述银行卡信息至少包括银行卡帐号;
(2)支付标识图像生成阶段,在需要进行支付时,根据终端标识信息和静态Token生成动态Token以使得用该动态Token替换银行卡帐号,根据该动态Token生成支付标识图像;以及
(3)支付交易步骤,读取将该支付标识图像,将该支付标识图像中包含的动态Token替换回银行卡帐号来完成后续的支付交易。
接着,参照图2对于本发明的基于Token的支付方法进行具体说明。
(1)绑定阶段(即绑卡过程):
S100:持卡人通过移动终端100向Token管理系统200提交银行卡、姓名、手机号、有效期等银行卡信息,持卡人初次提交绑定申请时,移动终端100采集终端设备号、MAC地址等的终端标识信息,并向Token管理系统200提交信息进行绑定申请。
S101:持卡人提交申请后,Token管理系统200方验证持卡人的身份相关信息(包括账户验证、手机号验证等)。在验证成功后,Token管理系统200方生成静态Token,同时将静态Token与终端标识信息进行绑定,并储存在Token管理系统200。
S102:Token管理系统200将静态Token下发移动终端。
S103:移动终端100使用静态Token替换银行卡帐号并保存在本地与服务端。另外,当持卡人更换移动终端时,需重新进行身份验证与终端标识信息绑定;仅当验证成功时允许更新Token与终端绑定关系。
(2)支付标识图像生成阶段:
S104:持卡人在移动终端100提交支付申请,移动终端100将绑卡过程中产生的静态Token发送Token管理系统200,同时上送终端设备号、MAC地址等标识终端标识信息。
S105:Token管理系统200验证静态Token信息与终端标识信息。
S106:在Token管理系统200验证成功后,生成动态Token,并将该动态Token返回给移动终端。这里,动态Token优选地为仅一次使用有效。
S107:移动终端100使用动态Token与终端标识信息生成支付标记图像。这里,作为支付标记图像,可以是二维码、条形码、或者其他任意能够隐藏地包含动态Token与终端标识信息的图像。
(3)支付交易阶段:
S108:商户终端300读取持卡人的移动终端100上显示的支付标记图像。
S109:商户终端300将识别的交易信息发送支付系统400,交易信息中的银行卡帐号由动态Token信息替代。
S110:支付系统400调用Token管理系统200方提供的服务。
S110:Token管理系统200验证持卡人的动态Token信息与终端标识信息,同时将动态Token替换成银行卡帐号,完成去标记化过程并返回到支付系统400。
接着,支付系统400将支付报文发送到发卡机构完成扣款并将交易结果源流返回到支付系统。这一部分不属于本发明申请的内容,因此未在图2中表示出该部分内容。
使用动态Token替代传统的使用银行卡主账号生成二维码的过程,既限定了应用的使用场景和渠道,有可以在支付的全环节使用,确保的通用性。
本发明的基于Token的支付方法以及基于Token的支付系统中,由于使用动态Token信息替换了原始的银行卡帐号,能够杜绝卡号信息泄露的可能。另外,由于在Token产生时,对Token应用的范围进行了限定,即,通过增加终端标识信息使得该Token的应用范围仅是限定在该移动终端,由此能够进一步降低支付标记泄露后的影响范围。而且,通过Token与移动终端的关联信息验证,能够防止信息泄露导致的欺诈交易。
以上例子主要说明了本发明的基于Token的支付方法以及基于Token的支付系统。尽管只对其中一些本发明的具体实施方式进行了描述,但是本领域普通技术人员应当了解,本发明可以在不偏离其主旨与范围内以许多其他的形式实施。因此,所展示的例子与实施方式被视为示意性的而非限制性的,在不脱离如所附各权利要求所定义的本发明精神及范围的情况下,本发明可能涵盖各种的修改与替换。
Claims (12)
- 一种基于Token的支付方法,其特征在于,包括下述步骤:绑定步骤,基于银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定,其中,所述银行卡信息至少包括银行卡帐号;支付标识图像生成步骤,在需要进行支付时,根据终端标识信息和静态Token生成动态Token以使得用该动态Token替换银行卡帐号,根据该动态Token生成支付标识图像;以及支付交易步骤,读取该支付标识图像,将该支付标识图像中包含的动态Token替换回银行卡帐号来完成后续的支付交易。
- 如权利要求1所述的基于Token的支付方法,其特征在于,在所述绑定步骤中,Token管理系统根据从移动终端发送来的银行卡信息生成静态Token,将所述静态Token与终端标识信息绑定并将所述静态Token储存于Token管理系统和移动终端,在支付标识图像生成步骤中,Token管理系统验证从移动终端发送来的终端标识信息和静态Token,在验证成功的情况下生成动态Token并发送给移动终端,移动终端根据该动态Token生成支付标识图像,在所述支付交易步骤中,商户终端扫描所述支付标识图像并发送到支付系统后调用Token管理系统验证动态Token,在验证成功的情况下将动态Token替换成银行卡信息后返回支付系统,由支付系统完成后续支付交易。
- 如权利要求2所述的基于Token的支付方法,其特征在于,所述绑定步骤包括下述子步骤:持卡人通过移动终端向Token管理系统提交银行卡信息;移动终端将终端标识信息发送到Token管理系统;Token管理系统验证持卡人的身份信息;在验证成功的情况下,Token管理系统生成静态Token;Token管理系统储存该静态Token并发送到移动终端;以及在移动终端用该静态Token替换银行卡帐号并储存于移动终端。
- 如权利要求2所述的基于Token的支付方法,其特征在于,所述支付标识图像生成步骤包括下述子步骤:移动终端根据支付请求将静态Token和终端标识信息发送到Token管理系统;Token管理系统验证从移动终端发送来的终端标识信息和静态Token;在验证成功的情况下生成一次性使用的动态Token并发送给移动终端;移动终端根据该动态Token生成支付标识图像。
- 如权利要求2所述的基于Token的支付方法,其特征在于,所述支付交易步骤包括:商户终端读取所述支付标识图像并识别包含的交易信息;将交易信息发送到支付系统并调用Token管理系统验证所述交易信息中包含的动态Token和终端标识信息;在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统;由支付系统完成后续支付交易。
- 如权利要求1~5任意一项所述的基于Token的支付方法,其特征在于,所述支付标识图像是二维码或者条形码。
- 如权利要求1~5任意一项所述的基于Token的支付方法,其特征在于,所述银行卡信息还包括号姓名、手机号码,所述终端标识信息包括终端设备号、MAC地址。
- 一种基于Token的支付系统,其特征在于,具备:移动终端、Token管理系统、商户终端以及支付系统,其中,所述移动终端与所述Token管理系统能够通信连接,在绑定阶段用于储存下述的静态Token,在支付阶段用于根据下述的动态Token生成支付标识图像,所述Token管理系统在绑定阶段用于根据生成用于替代银行卡帐号的静态Token,在支付阶段用于生成动态Token,另一方面在受到所述支付系统调用的情况下,用于验证从移动终端上传的支付标识图像中包含的动态Token并且在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统,所述商户终端在支付阶段用于读取所述支付标识图像并发送到支付系统,所述支付系统在收到所述支付标记图像的情况下调用所述Token管理系统以获得 银行卡帐号并完成后续支付交易。
- 如权利要求8所述的基于Token的支付系统,其特征在于,所述移动终端在绑定阶段用于将银行卡信息和终端标识信息发送到所述Token管理系统并且用于储存从所述Token管理系统返回的下述的静态Token,在支付阶段用于根据从所述Token管理移动终端发送来的动态Token生成支付标识图像,所述Token管理系统在绑定阶段用于根据来自所述移动终端的银行卡信息生成用于替代银行卡帐号的静态Token并且将所述静态Token与终端标识信息绑定;在支付阶段用于验证从移动终端发送来的终端标识信息和静态Token,在验证成功的情况下生成动态Token并发送给移动终端,另一方面在受到所述支付系统调用的情况下,用于验证从移动终端上传的支付标识图像中包含的动态Token并且在验证成功的情况下将动态Token替换成银行卡帐号后返回支付系统。
- 如权利要求9所述的基于Token的支付系统,其特征在于,所述Token管理系统在交易阶段生成一次性使用的动态Token。
- 如权利要求9所述的基于Token的支付系统,其特征在于,所述移动终端在支付阶段根据所述动态Token生成的支付标识图像是二维码或者条形码。
- 如权利要求8~11任意一项所述的基于Token的支付系统,其特征在于,所述银行卡信息还包括号姓名、手机号码,所述终端标识信息包括终端设备号、MAC地址。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610756992.X | 2016-08-30 | ||
| CN201610756992.XA CN106339873A (zh) | 2016-08-30 | 2016-08-30 | 基于Token的支付方法以及基于Token的支付系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018040976A1 true WO2018040976A1 (zh) | 2018-03-08 |
Family
ID=57823896
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/098401 Ceased WO2018040976A1 (zh) | 2016-08-30 | 2017-08-22 | 基于Token的支付方法以及基于Token的支付系统 |
Country Status (3)
| Country | Link |
|---|---|
| CN (1) | CN106339873A (zh) |
| TW (1) | TWI662492B (zh) |
| WO (1) | WO2018040976A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111553678A (zh) * | 2020-01-23 | 2020-08-18 | 中国银联股份有限公司 | 基于手机名片的二维码支付方法及其系统 |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106339873A (zh) * | 2016-08-30 | 2017-01-18 | 中国银联股份有限公司 | 基于Token的支付方法以及基于Token的支付系统 |
| CN107944867A (zh) * | 2017-11-17 | 2018-04-20 | 阿里巴巴集团控股有限公司 | 支付凭证信息生成方法及装置、设备 |
| CN108734248A (zh) * | 2018-04-17 | 2018-11-02 | 新大陆(福建)公共服务有限公司 | 一种快速生成安全二维码的方法以及二维码的扫码方法 |
| CN110880115A (zh) * | 2018-09-05 | 2020-03-13 | 雅座在线(北京)科技发展有限公司 | 一种电子卡防盗刷方法 |
| CN110048998B (zh) * | 2018-12-29 | 2021-09-14 | 中国银联股份有限公司 | 基于Token的身份验证方法及其系统、智能门锁 |
| CN112016918B (zh) * | 2019-05-30 | 2024-06-25 | 小米数字科技有限公司 | 一种签名写入方法、签名验证方法、装置及存储介质 |
| CN111951110A (zh) * | 2020-08-10 | 2020-11-17 | 神话科技传媒(深圳)有限公司上海分公司 | 一种基于区块链的激励的经济模型 |
| CN114219478A (zh) * | 2021-11-11 | 2022-03-22 | 中国建设银行股份有限公司 | 银行卡的绑定方法、装置、电子设备及存储介质 |
| TWI816390B (zh) * | 2022-05-09 | 2023-09-21 | 兆豐國際商業銀行股份有限公司 | 使用虛擬號碼執行金融交易的伺服器和方法 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103337023A (zh) * | 2013-07-19 | 2013-10-02 | 上海讯联数据服务有限公司 | 一种基于二维码技术的移动支付解决方案 |
| US20140074637A1 (en) * | 2012-09-11 | 2014-03-13 | Visa International Service Association | Cloud-based virtual wallet nfc apparatuses, methods and systems |
| CN104899741A (zh) * | 2014-03-05 | 2015-09-09 | 中国银联股份有限公司 | 一种基于ic银行卡的在线支付方法以及在线支付系统 |
| CN105590199A (zh) * | 2014-11-14 | 2016-05-18 | 中国银联股份有限公司 | 一种基于动态二维码的支付方法以及支付系统 |
| CN106339873A (zh) * | 2016-08-30 | 2017-01-18 | 中国银联股份有限公司 | 基于Token的支付方法以及基于Token的支付系统 |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10089606B2 (en) * | 2011-02-11 | 2018-10-02 | Bytemark, Inc. | System and method for trusted mobile device payment |
| US9092776B2 (en) * | 2012-03-15 | 2015-07-28 | Qualcomm Incorporated | System and method for managing payment in transactions with a PCD |
| CN104125064B (zh) * | 2013-04-28 | 2018-04-03 | 阿里巴巴集团控股有限公司 | 一种动态密码认证方法、客户端及认证系统 |
| TW201504961A (zh) * | 2013-07-16 | 2015-02-01 | Quick Retrieval Corp | 以商品安全識別碼進行交易之系統及其方法 |
| CN105590198B (zh) * | 2014-10-30 | 2020-12-15 | 中国银联股份有限公司 | 一种二维码支付方法以及支付系统 |
| SG10201501246TA (en) * | 2015-02-17 | 2016-09-29 | Mastercard Asia Pacific Pte Ltd | Methods and systems for processing an electronic payment |
-
2016
- 2016-08-30 CN CN201610756992.XA patent/CN106339873A/zh active Pending
-
2017
- 2017-08-22 WO PCT/CN2017/098401 patent/WO2018040976A1/zh not_active Ceased
- 2017-08-28 TW TW106129174A patent/TWI662492B/zh active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20140074637A1 (en) * | 2012-09-11 | 2014-03-13 | Visa International Service Association | Cloud-based virtual wallet nfc apparatuses, methods and systems |
| CN103337023A (zh) * | 2013-07-19 | 2013-10-02 | 上海讯联数据服务有限公司 | 一种基于二维码技术的移动支付解决方案 |
| CN104899741A (zh) * | 2014-03-05 | 2015-09-09 | 中国银联股份有限公司 | 一种基于ic银行卡的在线支付方法以及在线支付系统 |
| CN105590199A (zh) * | 2014-11-14 | 2016-05-18 | 中国银联股份有限公司 | 一种基于动态二维码的支付方法以及支付系统 |
| CN106339873A (zh) * | 2016-08-30 | 2017-01-18 | 中国银联股份有限公司 | 基于Token的支付方法以及基于Token的支付系统 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111553678A (zh) * | 2020-01-23 | 2020-08-18 | 中国银联股份有限公司 | 基于手机名片的二维码支付方法及其系统 |
| CN111553678B (zh) * | 2020-01-23 | 2024-02-09 | 中国银联股份有限公司 | 基于手机名片的二维码支付方法及其系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201807634A (zh) | 2018-03-01 |
| CN106339873A (zh) | 2017-01-18 |
| TWI662492B (zh) | 2019-06-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2018040976A1 (zh) | 基于Token的支付方法以及基于Token的支付系统 | |
| US20230351833A1 (en) | Tap to copy data to clipboard via nfc | |
| US12388619B2 (en) | System and method for authorizing transactions in an authorized member network | |
| US8818904B2 (en) | Generation systems and methods for transaction identifiers having biometric keys associated therewith | |
| TWI715805B (zh) | 資源調配方法和裝置以及電子支付方法 | |
| US20150193765A1 (en) | Method and System for Mobile Payment and Access Control | |
| US20140201086A1 (en) | Method and system for reversed near field contact electronic transaction | |
| US11303434B2 (en) | Techniques for secure channel communications | |
| US20170039557A1 (en) | Virtual point of sale | |
| US10748169B2 (en) | Methods and systems for rewarding customers in a tokenized payment transaction | |
| US11151579B2 (en) | Authentication of goods | |
| US12321907B2 (en) | Data processing utilizing a digital tag | |
| CN105931035A (zh) | 一种支付标记生成方法及装置 | |
| CN104951837A (zh) | 采用近距离无线通信标签生成订单的方法和系统 | |
| US20220358473A1 (en) | Remittance with recipient alias | |
| WO2015139623A1 (en) | Method and system for mobile payment and access control | |
| CN110414982A (zh) | 一种一卡通交易方法及系统 | |
| TWI643148B (zh) | Mobile device, method, computer program product, and distribution system thereof for configuring ticket co-branded credit card based on coding technology | |
| US12340356B2 (en) | Unattended mobile point of sale system | |
| CN105185002B (zh) | 移动终端、业务平台及卡片业务系统 | |
| HK1233364A1 (zh) | 基於token的支付方法以及基於token的支付系统 | |
| HK1233364A (zh) | 基於token的支付方法以及基於token的支付系統 | |
| US20250285116A1 (en) | Virtual credential to support continuity following migration of a deactivated credential | |
| TW202607641A (zh) | 行動支付系統 | |
| KR20110078147A (ko) | 결제카드를 이용한 결제시 문자메시지를 이용한 인증방법 및 시스템 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17845278 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17845278 Country of ref document: EP Kind code of ref document: A1 |