WO2018154885A1 - Ticket-vending machine - Google Patents

Ticket-vending machine Download PDF

Info

Publication number
WO2018154885A1
WO2018154885A1 PCT/JP2017/041718 JP2017041718W WO2018154885A1 WO 2018154885 A1 WO2018154885 A1 WO 2018154885A1 JP 2017041718 W JP2017041718 W JP 2017041718W WO 2018154885 A1 WO2018154885 A1 WO 2018154885A1
Authority
WO
WIPO (PCT)
Prior art keywords
ticket
card
pin pad
credit card
control unit
Prior art date
Application number
PCT/JP2017/041718
Other languages
French (fr)
Japanese (ja)
Inventor
隆久 西野
Original Assignee
オムロン株式会社
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by オムロン株式会社 filed Critical オムロン株式会社
Publication of WO2018154885A1 publication Critical patent/WO2018154885A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/18Payment architectures involving self-service terminals [SST], vending machines, kiosks or multimedia terminals
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07BTICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
    • G07B1/00Machines for printing and issuing tickets
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07BTICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
    • G07B5/00Details of, or auxiliary devices for, ticket-issuing machines

Definitions

  • This invention relates to a technology for paying a transaction amount for issuing a ticket according to input ticket information using a credit card.
  • Patent Document 1 describes a system that encrypts card data read from a card by a card terminal and transmits the encrypted card data to a POS terminal.
  • the POS terminal decrypts the received card data (encrypted card data) and settles the transaction amount using the decrypted card data.
  • Patent Document 1 discloses a configuration in which an encryption key used for encryption of card data is prevented from being estimated, and the encryption key is updated when the card terminal and the POS terminal are turned on in order to improve system security. Is disclosed.
  • a transaction amount related to the ticket issuance is settled with a credit card.
  • the user is asked to enter an authentication code (so-called PIN number) to confirm the identity of the cardholder (user and cardholder) Check if they match.
  • PIN number an authentication code
  • a general ticket vending machine that can settle a transaction amount with a credit card includes a PIN pad.
  • the user inputs an authentication code by operating the numeric keypad of the PIN pad.
  • the user purchases a ticket using the voice guidance function of the ticket vending machine, the user inputs the ticket information by operating the numeric keypad of the PIN pad.
  • the PIN pad is an input device used for inputting an authentication code and inputting ticket information.
  • the authentication code which the PIN pad outputs to the control unit (has a function for processing the transaction amount with the credit card) is output.
  • Patent Document 1 does not specifically disclose the handling of an authentication code used for identity verification of the card owner.
  • An object of the present invention is to provide a technique for improving security against leakage of an authentication code input by a user by operating a numeric keypad of a PIN pad.
  • the ticket vending machine of the present invention is configured as follows.
  • the ticket vending machine can settle a transaction amount of a ticket issued according to the input ticket information with a credit card.
  • the credit card may be a contact IC card, a magnetic card, or a magnetic / IC card.
  • the card processing unit reads card data recorded on a credit card inserted into the main body.
  • the PIN pad has a numeric keypad used for an input operation of ticket information and an input operation of an authentication code used for personal authentication at the time of payment with a credit card. That is, the PIN pad is used for inputting an authentication code and entering ticket information.
  • the control unit uses the card data read by the card processing unit and the authentication code input in the PIN pad to settle the transaction amount for issuing the boarding ticket.
  • the PIN pad encrypts the input authentication code and outputs it to the control unit. Therefore, even if the authentication code output from the PIN pad to the control unit is extracted by a malicious third party from the signal transmission path connecting the PIN pad and the control unit, the extracted authentication code is encrypted. Therefore, it is possible to improve the security against the leakage of the authentication code.
  • the PIN pad is preferably configured to output the input ticket information to the control unit without encryption. If comprised in this way, the encryption process with respect to boarding ticket information which does not require especially security ensuring and a decoding process can be made unnecessary, and it can suppress that the processing load of a ticket vending machine main body becomes large.
  • the control unit may instruct the PIN pad whether information input by operating the numeric keypad (passage ticket information, authentication code, etc.) is output after being encrypted or without being encrypted. . With this configuration, it is possible to easily switch between encryption and non-encryption according to the necessity of ensuring security against information leaked from the PIN pad.
  • control unit determines whether or not the credit card is a valid credit card that can be used for the settlement of the transaction amount using the card data read from the credit card inserted into the main body by the card processing unit, If it is determined that the credit card is not a valid credit card that can be used for the payment of the money amount, the authentication code may not be output to the PIN pad.
  • FIG. 1 is a block diagram showing a configuration of a main part of a ticket vending machine according to this example.
  • FIG. 2 is a schematic front view of the ticket vending machine according to this example.
  • a ticket vending machine 1 according to this example includes a control unit 2, a display unit 3, an operation unit 4, a ticket issuing unit 5, a coin processing unit 6, a bill processing unit 7, a card processing unit 8, and a PIN pad 9. And a communication unit 10.
  • the display unit 3, the operation unit 4, the ticket issuing unit 5, the coin processing unit 6, the banknote processing unit 7, the card processing unit 8, the PIN pad 9, and the communication unit 10 are connected to the control unit 2 by cables or the like that are signal transmission paths.
  • the ticket vending machine 1 is installed at a station and issues tickets such as commuter passes, tickets, and coupon tickets to users. Further, the ticket vending machine 1 can also perform charge processing (payment processing) for an SF card (Stored Fare Card) that can be used as a boarding ticket. The ticket vending machine 1 can settle a transaction amount for issuing a ticket with money, or can settle with a credit card. The money here is a collective term for coins and banknotes.
  • the control unit 2 controls each unit included in the ticket vending machine 1 main body.
  • the control unit 2 has a settlement unit 2a.
  • the settlement unit 2a performs a settlement process in which the transaction amount of the ticket issued according to the entered ticket information is settled with a credit card.
  • the display unit 3 has a display 3a provided on the front surface of the main body. The display unit 3 controls the screen display of the display 3a.
  • the operation unit 4 has a touch panel 4a pasted on the screen of the display 3a.
  • the operation unit 4 detects a user's input operation on the touch panel 4a (a pressing position on the touch panel 4a pressed by the user with a finger) and outputs input operation data corresponding to the detected pressing position to the control unit 2.
  • the operation unit 4 also includes a push button switch as an input device. When the user presses the push button switch, the operation unit 4 outputs input operation data corresponding to the pressed push button switch to the control unit 2.
  • the user performs an operation of inputting the ticket information of the ticket to be purchased into the main body of the ticket vending machine 1 in the operation unit 4.
  • the ticket issuing unit 5 performs a process for issuing a boarding ticket.
  • the ticket vending machine 1 is provided with a ticketing opening 5a on the front surface of the main body.
  • the ticket issuing unit 5 releases a ticket to be issued to the user to the ticket opening 5a.
  • the ticket vending machine 1 is provided with a coin insertion slot 6a and a change coin receiving tray 6b on the front surface of the main body.
  • the user inserts a coin used for the settlement of the transaction amount for issuing a ticket into the coin slot 6a.
  • the coin processing unit 6 accepts coins that the user has inserted into the coin insertion slot 6a.
  • the coin processing unit 6 discharges coins for change to be returned to the user to the change coin receiving tray 6b.
  • the coin slot 6a has a shape that can be inserted into the main body of the ticket vending machine 1 even when a plurality of (about 2 to 3) coins are stacked.
  • the coin processing unit 6 has a coin identifying unit that identifies the denomination and authenticity of coins input by the user and change coins to be released as change to the user.
  • the ticket vending machine 1 is provided with a bill insertion slot 7a and a bill discharge slot 7b on the front surface of the main body.
  • a user inserts the banknote used for the settlement of the transaction amount concerning ticket issuing etc. into the banknote slot 7a.
  • the banknote processing unit 7 accepts banknotes inserted by the user into the banknote slot 7a. Moreover, the banknote processing unit 7 discharge
  • the banknote processing unit 7 has a banknote identification unit that identifies the denomination and authenticity of banknotes inserted by the user and banknotes released as change to the user.
  • the ticket vending machine 1 is provided with a card insertion / release port 8a on the front surface of the main body.
  • the user inserts into the card insertion / release port 8a a credit card used for settlement of the transaction amount related to the ticket issue or an SF card that can be used as a ticket.
  • the card processing unit 8 takes in a card inserted into a card insertion / release port 8a provided on the front face of the ticket vending machine 1 into the main body, reads card data recorded on the card, and card data for the card. Is written (card data is updated).
  • the card processing unit 8 outputs the card data read from the card inserted into the card insertion / release port 8a to the control unit 2 and the update card data input from the control unit 2 or the like to the card insertion / release port. Write to the card inserted in 8a. When the processing for the card inserted into the card insertion / discharge port 8a is completed, the card processing unit 8 discharges the card to the card insertion / discharge port 8a in order to return it to the user.
  • the SF card is described as a non-contact IC card having a wireless communication function.
  • the credit card will be described as a contact IC card having an IC contact formed on the surface.
  • the credit card may be an IC card having a magnetic stripe or an IC card in which no magnetic stripe is formed.
  • the credit card may be a magnetic card that does not have an IC.
  • the card processing unit 8 has a wireless communication function for reading card data to the SF card and writing card data.
  • the card processing unit 8 has an IC terminal that is brought into contact with an IC contact formed on the surface of the credit card, and a mechanism that makes the IC contact come in contact with and separates from the IC contact of the credit card.
  • the card processing unit 8 reads the card data and writes the card data to the credit card in a state where the IC terminal is in contact with the IC contact of the credit card.
  • the PIN pad 9 operates in a plaintext mode or an encryption mode to be described later.
  • the PIN pad 9 is an input device used for an input operation of ticket information of a ticket to be purchased, an input operation of an authentication code for identity verification when making a payment with a credit card, and the like.
  • the communication unit 10 controls communication with an authentication server that issues a credit payment authentication request via a network.
  • the communication unit 10 also controls communication with station equipment such as an automatic ticket gate (not shown) and other ticket vending machines 1.
  • FIG. 3 is a block diagram showing the configuration of the main part of the PIN pad.
  • the PIN pad 9 includes a control unit 21, a numeric keypad operation unit 22, and an input / output I / F 23.
  • the control unit 21 controls the operation of the PIN pad 9.
  • the numeric keypad 22 has ten numeric keys (numeric keys corresponding to 0 to 9) and two symbol keys “*” and “#”.
  • the PIN pad 9 notifies the control unit 21 of the pressed key.
  • the input / output I / F 23 controls input / output with the control unit 2 of the ticket vending machine 1 main body.
  • each key of the numeric keypad operation unit 22 and the control unit 21 are electrically connected not by a cable but by a print pattern, and security against a signal being extracted between the numeric keypad operation unit 22 and the control unit 21. Is secured.
  • the control unit 21 When the operation in the plain text mode is designated from the ticket vending machine 1 main body, the control unit 21 operates the PIN pad 9 in the plain text mode. Further, when the operation in the encryption mode is designated from the ticket vending machine 1 main body, the control unit 21 operates the PIN pad 9 in the encryption mode.
  • the plaintext mode when any key of the numeric keypad 22 is operated, a key code corresponding to the key is output to the control unit 2.
  • the encryption mode when any key of the numeric keypad 22 is operated, the operated keys are sequentially stored in a memory (not shown) of the control unit 21 and the control unit indicates that the key has been pressed. 2 is a mode to output to 2.
  • the encryption mode is a key sequence stored in the memory of the control unit 21 (this key sequence is the numeric keypad And the encrypted data is output to the control unit 2.
  • the control unit 21 stores an encryption key used for encryption of the key string in the memory.
  • FIG. 4 is a flowchart showing the ticket issuing process in the ticket vending machine.
  • the ticket vending machine 1 determines whether the user has selected the voice guidance mode or the normal mode (s1).
  • the voice guidance mode in a voice guidance section (not shown), a guidance message for guiding an input operation related to purchase of a ticket is sent to the user, and the user inputs the ticket information using the PIN pad 9.
  • This mode accepts and issues a ticket.
  • the normal mode is a mode in which the display unit 3 controls the display screen on the display device 3a, and the operation unit 4 accepts an input operation of ticket information by the user and issues a ticket.
  • the control unit 2 determines that the voice guidance mode is selected, for example, when a voice guidance mode selection key (for example, “*” key) of the numeric keypad 22 of the PIN pad 9 is pressed. That is, the user can select the voice guidance mode by pressing the voice guidance mode selection key on the numeric keypad 22 of the PIN pad 9.
  • the control unit 2 determines that the normal mode has been selected when the operation unit 4 detects the pressing position of the user on the touch panel 4a without pressing the voice guidance mode selection key of the numeric keypad operation unit 22 of the PIN pad 9. judge. That is, the user can select the normal mode by pressing the touch panel 4a pasted on the screen of the display 3a without operating the numeric keypad 22 of the PIN pad 9.
  • the voice guidance unit When the control unit 2 determines that the selected mode is the voice guidance mode, the voice guidance unit starts voice guidance (s2). At this time, the control unit 2 designates the plain text mode for the PIN pad 9.
  • the control unit 2 may be configured to designate either the plaintext mode or the encryption mode to be described later on the PIN pad 9, or the type of information that accepts an input operation by the user (ticket information, authentication code, etc. ) May be output to the PIN pad 9, and the PIN pad 9 may select a plaintext mode or an encryption mode depending on the type of information.
  • the PIN pad 9 accepts an input operation of ticket information by the user (s3).
  • the user presses a key on the numeric keypad 22 to input the ticket information.
  • the PIN pad 9 outputs a key code corresponding to the key pressed by the user to the control unit 2.
  • the PIN pad 9 since the plain text mode is designated at this time, the PIN pad 9 does not encrypt the key code corresponding to the pressed key every time the user presses the key. And output to the control unit 2 (details of the operation of the PIN pad 9 in the plaintext mode will be described later).
  • the operation unit 4 accepts an input operation of ticket information by the user (s4).
  • the operation unit 4 outputs an input code corresponding to the pressed position of the user on the touch panel 4a to the control unit 2.
  • the settlement of the transaction amount relating to the ticket issuance is a credit settlement by a credit card, or a cash by money It is determined whether it is a settlement (s5). If the control unit 2 determines that it is a credit settlement, the card processing unit 8 accepts a credit card used for settlement of the transaction amount (s6).
  • the card processing unit 8 receives a credit card inserted by the user into the card insertion / release port 8a.
  • the coin processing unit 6 accepts the insertion of coins by the user
  • the bill processing unit 7 accepts the insertion of bills by the user (s10).
  • the determination as to credit settlement or cash settlement may be made in accordance with the user's selection input operation.
  • the structure which determines with it being a credit card payment may be sufficient when the card processing unit 8 receives the credit card inserted in the card insertion / release port 8a.
  • the coin processing unit 6 receives a coin inserted into the coin insertion slot 6a, or when the banknote processing unit 7 receives a banknote inserted into the banknote insertion slot 7a, it is determined to be a cash settlement. That's fine.
  • the control unit 2 transports the credit card received in s6 to the card data reading position, brings the IC terminal into contact with the IC contact of the credit card, reads the card data, and instructs the PIN pad 9 on the encryption mode. To do. Details of the operation of the PIN pad 9 in the encryption mode will be described later.
  • the PIN pad 9 accepts an input operation of an authentication code (so-called password) by the user at the numeric keypad 22 (s7).
  • the authentication code is a number of multiple digits (for example, 4 digits).
  • the user presses the numeric key of the numeric keypad 22 in order from the upper digit and inputs the authentication code.
  • the PIN pad 9 generates encrypted data obtained by encrypting key strings arranged in the order in which the numeric keys are pressed in the control unit 21, and outputs the encrypted data to the control unit 2.
  • the control unit 2 performs a settlement process (credit settlement) in which the transaction amount of the ticket issued with the current ticket information is settled with the credit card accepted in s6 (s8).
  • transaction authentication may be performed by offline authentication or online authentication.
  • the off-line authentication whether the credit card accepted by the card processing unit 8 is within the validity period, the authentication code recorded on the IC of the credit card and the authentication code input on the PIN pad 9 this time match.
  • the communication unit 10 transmits transaction authentication data including the card number of the credit card received by the card processing unit 8, the input authentication code, the current transaction amount, etc. to the authentication server.
  • the authentication server determines whether the card is valid / invalid (in this case, not only whether it is within the validity period but also whether it is an invalid card registered in the negative file), and the authentication code is appropriate. Whether or not the transaction is possible is verified by whether or not the transaction is within the credit limit range.
  • the card processing unit 8 releases the credit card accepted this time to the card insertion / release port 8a and the ticketing unit 5 accepts this time
  • a ticketing process for releasing the boarding ticket corresponding to the information to the ticketing slot 5a is performed (s9), and the process returns to s1.
  • the settlement unit 2a fails to settle the transaction amount for issuing the ticket using a credit card
  • the card processing unit 8 releases the accepted credit card to the card insertion / release port 8a, but the ticketing unit 5 Do not issue a ticket according to the ticket information received this time.
  • the settlement unit 2a cannot settle the transaction amount for issuing a ticket with a credit card
  • the present ticketing process may be shifted to the process after s10 described later.
  • the control unit 2 determines whether the credit card accepted by the card processing unit 8 is within the expiration date before accepting the input of the authentication code. If the credit card is not within the expiration date, the PIN pad 9 The authentication code input may not be accepted.
  • the control unit 2 determines that the payment is a cash settlement, the total amount of money inserted at the coin insertion slot 6a and the banknote insertion slot 7a corresponds to the ticket information received at s3 or s4. Wait until the transaction amount exceeds (s10).
  • the control unit 2 issues a ticket when the total amount of money inserted at the coin insertion slot 6a and the bill insertion slot 7a is equal to or greater than the transaction amount of the ticket corresponding to the ticket information received at s3 or s4.
  • the transaction amount of the ticket is settled with cash (s11).
  • the coin processing unit 6 and the banknote processing unit 7 release the change as necessary, and the ticket issuing unit 5 responds to the ticket information received this time.
  • the ticket issuing process for releasing the boarded ticket to the ticket opening 5a is performed (s12), and the process returns to s1.
  • the ticket vending machine 1 can perform settlement of the transaction amount related to the ticket issuing with a credit card or money.
  • the operation in the plain text mode and the operation in the encryption mode of the PIN pad 9 will be described.
  • FIG. 5 is a flowchart showing the operation of the plain text mode of the PIN pad.
  • FIG. 6 is a flowchart showing the operation of the PIN pad encryption mode.
  • the numeric keypad 22 notifies the controller 21 of the operated key (s22).
  • the control unit 21 outputs a key code corresponding to the key notified from the numeric keypad operation unit 22 (the key operated this time) to the control unit 2 connected to the input / output I / F 23 (s23), and to s21 Return.
  • the PIN pad 9 does not encrypt the key code corresponding to the key operated at any time when any key of the numeric keypad operation unit 22 is operated. Output to.
  • the operation in the encryption mode will be described.
  • the numeric keypad 22 notifies the controller 21 of the operated key (s32).
  • the control unit 21 determines whether or not the key notified from the numeric keypad operation unit 22 is a predetermined specific key (in this example, “#” key) (s33).
  • This specific key is a key operated when the operator inputs completion of the input operation. For example, when the operator inputs a 4-digit number string 3648 on the PIN pad 9, the “3”, “6”, “4”, and “8” keys on the PIN pad 9 are sequentially operated, and then “#” is operated. To do.
  • the control unit 21 When determining that the key is not a specific key in s33, the control unit 21 stores the key operated this time (that is, the key notified from the numeric keypad operation unit 22 in s22) in a memory (not shown) (s34). In s34, the control part 21 memorize
  • the control unit 2 can determine how many digits have been input at that time by outputting that the key operation of the PIN pad 9 has been performed. Therefore, the control unit 2 can instruct the display unit 3 to display on the display 3a a screen on which the number of digits input by the operator can be confirmed, for example.
  • This screen is a screen that displays, for example, the same number of “*” as the number of digits input by the operator.
  • the order of the processes concerning s34 and s35 may be the reverse order of the above.
  • the control unit 21 encrypts the key string stored in the memory (the key stored in the order operated in s34) (s36). For example, when the operator inputs a 4-digit number string 3648, the key strings “3”, “6”, “4”, and “8” are stored in the memory.
  • the control unit 21 stores an encryption key used for encryption of the key string in the memory.
  • the control unit 21 outputs the encrypted data of the key string encrypted in s36 to the control unit 2 connected to the input / output I / F 23 (s35), and returns to s31.
  • the PIN pad 9 when the PIN pad 9 is in the encryption mode, the data output from the PIN pad 9 to the control unit 2 is encrypted data. Therefore, when the user is required to input an authentication code that requires security against leakage through the PIN pad 9, the PIN pad 9 is operated in the encryption mode to improve security against the leakage of the authentication code. Can be planned. Even if a malicious third party pulls out the authentication code from the signal transmission line connecting the PIN pad 9 and the control unit 2, the extracted authentication code is encrypted, so this authentication code leaks. Can be prevented.
  • the PIN pad 9 is operated in the plaintext mode, so that encryption processing and decryption processing are unnecessary. It is possible to suppress an increase in processing load on the ticket vending machine 1 main body.
  • the encryption process is performed by the PIN pad 9, and the decryption process is performed by the control unit 2 as necessary.
  • the PIN pad 9 may be operated in the encryption mode not only when the authentication code in the above example is input but also when information that requires security against leakage is input. Further, the PIN pad 9 may be operated in the plain text mode not only when inputting the ticket information in the above example but also when inputting information that does not particularly require security against leakage.
  • a ticket vending machine 1 according to another example will be described. The ticket vending machine 1 according to this example is different in that the ticket issuing process shown in FIG. 7 is performed instead of the ticket issuing process shown in FIG.
  • This ticket vending machine 1 also performs the processes of s1 to s6 described above, and when the card processing unit 8 receives a credit card in s6, it determines whether or not the credit card received this time is within the expiration date (s15). If the control unit 2 determines that it is within the expiration date, it executes the processing of s7 to s9 described in the above example. On the other hand, if the control unit 2 determines that the expiration date is not within s15, the card processing unit 8 releases the credit card accepted this time to the card insertion / release port 8a (s16), and returns to s1.
  • the ticket vending machine 1 in this example does not allow the user to input the authentication code when accepting a credit card that is not within the expiration date. This not only prevents the user from inputting the authentication code in vain, but also prevents the authentication code encrypted by the PIN pad 9 from being output to the control unit 2 in vain.

Landscapes

  • Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Business, Economics & Management (AREA)
  • Theoretical Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Ticket-Dispensing Machines (AREA)
  • Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)

Abstract

Provided is a ticket-vending machine (1), which settles with a credit card a transaction amount for issuing a ticket corresponding to inputted ticket information. A credit card processing unit (8) reads in card data which is recorded in a credit card that has been inserted into a main body. A PIN pad (9) is provided with a ten-key pad which is used in an input operation of the ticket information and an input operation of an authentication code which is used in identification of a person at the time of settlement with a credit card. Using the card data which the credit card processing unit (8) has read in and the authentication code which has been inputted in the PIN pad (9), a control unit (2) carries out the settlement of the transaction amount for issuing the ticket. With regard to the inputted authentication code, the PIN pad (9) encrypts and outputs same to a control section.

Description

券売機Ticket-vending machine
 この発明は、入力された乗車券情報に応じた乗車券の発券にかかる取引金額をクレジットカードで決済する技術に関する。 This invention relates to a technology for paying a transaction amount for issuing a ticket according to input ticket information using a credit card.
 従来、取引金額の決済を現金ではなく、クレジットカードで決済するカード取引が店舗等で行われている。例えば、特許文献1には、カード端末がカードから読み取ったカードデータを暗号化し、暗号化したカードデータをPOS端末に送信するシステムが記載されている。POS端末は、受信したカードデータ(暗号化されたカードデータ)を復号化し、復号化したカードデータを用いて取引金額の決済を行う。 Conventionally, a card transaction in which a transaction amount is settled with a credit card instead of cash is performed at a store or the like. For example, Patent Document 1 describes a system that encrypts card data read from a card by a card terminal and transmits the encrypted card data to a POS terminal. The POS terminal decrypts the received card data (encrypted card data) and settles the transaction amount using the decrypted card data.
 また、特許文献1には、カードデータの暗号化に用いる暗号鍵が推定されるのを防止し、システムのセキュリティを向上させるために、カード端末およびPOS端末の電源オン時に暗号鍵を更新する構成を開示している。 Patent Document 1 discloses a configuration in which an encryption key used for encryption of card data is prevented from being estimated, and the encryption key is updated when the card terminal and the POS terminal are turned on in order to improve system security. Is disclosed.
特開2013-51577号公報JP 2013-51577 A
 最近では、利用者が入力した乗車券情報に応じて乗車券を発券する券売機においても、乗車券の発券にかかる取引金額をクレジットカードで決済することが行われている。
 クレジットカードでの決済時には、偽造カードやなりすまし等に対するセキュリティを確保するため、認証コード(所謂、暗証番号)を利用者に入力させて、カード所有者の本人確認(利用者と、カード所有者とが一致しているかどうかの確認)を行っている。取引金額の決済がクレジットカードで行える一般的な券売機は、PINパッドを備えている。利用者は、このPINパッドのテンキーを操作して認証コードを入力する。また、利用者は、券売機の音声案内機能等を利用して乗車券を購入するとき、PINパッドのテンキーを操作して乗車券情報を入力する。すなわち、PINパッドは、認証コードの入力、および乗車券情報の入力に利用される入力デバイスである。
Recently, even in a ticket vending machine that issues a ticket according to ticket information input by a user, a transaction amount related to the ticket issuance is settled with a credit card.
At the time of payment with a credit card, in order to ensure security against counterfeit cards and impersonation, the user is asked to enter an authentication code (so-called PIN number) to confirm the identity of the cardholder (user and cardholder) Check if they match. A general ticket vending machine that can settle a transaction amount with a credit card includes a PIN pad. The user inputs an authentication code by operating the numeric keypad of the PIN pad. In addition, when the user purchases a ticket using the voice guidance function of the ticket vending machine, the user inputs the ticket information by operating the numeric keypad of the PIN pad. In other words, the PIN pad is an input device used for inputting an authentication code and inputting ticket information.
 そして、乗車券の発券にかかる取引金額の決済がクレジットカードで行える券売機において、PINパッドが制御部(取引金額をクレジットカードで決済するための処理行う機能を有する。)に出力する認証コードが、このPINパッドと制御部とを接続する信号の伝送路から漏洩する(悪意のある第3者に抜き取られる。)ことに対するセキュリティの確保が要望されている。 And in the ticket vending machine which can settle the transaction amount concerning the ticket issuance with a credit card, the authentication code which the PIN pad outputs to the control unit (has a function for processing the transaction amount with the credit card) is output. There is a demand for ensuring security against leakage from a signal transmission path connecting the PIN pad and the control unit (extracted by a malicious third party).
 なお、特許文献1には、カード所有者の本人確認に用いる認証コードの取り扱いについては、特に開示されていない。
 この発明の目的は、利用者がPINパッドのテンキーを操作して入力した認証コードの漏洩に対するセキュリティの向上を図る技術を提供することにある。
 この発明の券売機は、上記目的を達するために、以下のように構成している。
Note that Patent Document 1 does not specifically disclose the handling of an authentication code used for identity verification of the card owner.
An object of the present invention is to provide a technique for improving security against leakage of an authentication code input by a user by operating a numeric keypad of a PIN pad.
In order to achieve the above object, the ticket vending machine of the present invention is configured as follows.
 この発明にかかる券売機は、入力された乗車券情報に応じた乗車券の発券にかかる取引金額をクレジットカードで決済することができる。クレジットカードは、接触式のICカードであってもよいし、磁気カードであってもよいし、磁気・ICカードであってもよい。
 カード処理部は、本体に挿入されたクレジットカードに記録されているカードデータを読み取る。PINパッドは、乗車券情報の入力操作、およびクレジットカードでの決済時に本人認証に用いる認証コードの入力操作に用いるテンキーを有する。すなわち、PINパッドは、認証コードの入力、および乗車券情報の入力に利用される。制御部は、カード処理部が読み取ったカードデータ、およびPINパッドにおいて入力された認証コードを用いて、乗車券の発券にかかる取引金額の決済を行う。
The ticket vending machine according to the present invention can settle a transaction amount of a ticket issued according to the input ticket information with a credit card. The credit card may be a contact IC card, a magnetic card, or a magnetic / IC card.
The card processing unit reads card data recorded on a credit card inserted into the main body. The PIN pad has a numeric keypad used for an input operation of ticket information and an input operation of an authentication code used for personal authentication at the time of payment with a credit card. That is, the PIN pad is used for inputting an authentication code and entering ticket information. The control unit uses the card data read by the card processing unit and the authentication code input in the PIN pad to settle the transaction amount for issuing the boarding ticket.
 そして、PINパッドは、入力された認証コードについては、暗号化して制御部に出力する。
 したがって、PINパッドが制御部に出力する認証コードが、このPINパッドと制御部とを接続する信号の伝送路から悪意のある第3者に抜き取られても、抜き取られた認証コードは暗号化されているので、認証コードの漏洩に対するセキュリティの向上を図ることができる。
Then, the PIN pad encrypts the input authentication code and outputs it to the control unit.
Therefore, even if the authentication code output from the PIN pad to the control unit is extracted by a malicious third party from the signal transmission path connecting the PIN pad and the control unit, the extracted authentication code is encrypted. Therefore, it is possible to improve the security against the leakage of the authentication code.
 また、PINパッドは、入力された乗車券情報を暗号化することなく制御部に出力する構成にするのがよい。このように構成すれば、特にセキュリティの確保が必要でない乗車券情報に対する暗号化処理や、復号化処理を不要にでき、券売機本体の処理負荷が大きくなるのを抑えられる。
 また、制御部が、テンキーの操作によって入力された情報(乗車券情報、認証コード等)を暗号化して出力するか、暗号化することなく出力するかをPINパッドに指示する構成にしてもよい。このように構成すれば、PINパッドにおいて入力された情報が漏洩することに対するセキュリティの確保の要否に応じて、暗号化するかしないかを容易に切り替えることができる。
The PIN pad is preferably configured to output the input ticket information to the control unit without encryption. If comprised in this way, the encryption process with respect to boarding ticket information which does not require especially security ensuring and a decoding process can be made unnecessary, and it can suppress that the processing load of a ticket vending machine main body becomes large.
In addition, the control unit may instruct the PIN pad whether information input by operating the numeric keypad (passage ticket information, authentication code, etc.) is output after being encrypted or without being encrypted. . With this configuration, it is possible to easily switch between encryption and non-encryption according to the necessity of ensuring security against information leaked from the PIN pad.
 また、制御部は、カード処理部が本体に挿入されたクレジットカードから読み取ったカードデータを用いて、このクレジットカードが取引金額の決済に使用できる有効なクレジットカードであるかどうかを判定し、取引金額の決済に使用できる有効なクレジットカードでないと判定した場合には、PINパッドに対して認証コードの出力を要求しない構成にしてもよい。このように構成すれば、利用者が認証コードを無駄に入力するのを防止できるだけでなく、PINパッドが暗号化した認証コードを制御部に無駄に出力するのを防止できる。
(発明の効果)
 この発明によれば、利用者がPINパッドのテンキーを操作して入力した認証コードの漏洩に対するセキュリティを向上させることができる。
In addition, the control unit determines whether or not the credit card is a valid credit card that can be used for the settlement of the transaction amount using the card data read from the credit card inserted into the main body by the card processing unit, If it is determined that the credit card is not a valid credit card that can be used for the payment of the money amount, the authentication code may not be output to the PIN pad. With this configuration, it is possible not only to prevent the user from inputting the authentication code in vain, but also to prevent the authentication code encrypted by the PIN pad from being output to the control unit in vain.
(The invention's effect)
According to the present invention, it is possible to improve security against leakage of an authentication code input by a user by operating a numeric keypad of a PIN pad.
券売機の主要部の構成を示すブロック図である。It is a block diagram which shows the structure of the principal part of a ticket vending machine. 券売機の正面概略図である。It is a front schematic diagram of a ticket machine. PINパッドの主要部の構成を示すブロック図である。It is a block diagram which shows the structure of the principal part of a PIN pad. 券売機における発券処理を示すフローチャートである。It is a flowchart which shows the ticketing process in a ticket vending machine. PINパッドの平文モードの動作を示すフローチャートである。It is a flowchart which shows operation | movement of the plaintext mode of a PIN pad. PINパッドの暗号化モードの動作を示すフローチャートである。It is a flowchart which shows operation | movement of the encryption mode of PIN pad. 別の例にかかる券売機における発券処理を示すフローチャートである。It is a flowchart which shows the ticketing process in the ticket vending machine concerning another example.
 以下、この発明の実施形態である券売機について説明する。
 図1は、この例にかかる券売機の主要部の構成を示すブロック図である。図2は、この例にかかる券売機の正面概略図である。この例にかかる券売機1は、制御ユニット2と、表示ユニット3と、操作ユニット4と、発券ユニット5と、硬貨処理ユニット6と、紙幣処理ユニット7と、カード処理ユニット8と、PINパッド9と、通信ユニット10と、を備えている。表示ユニット3、操作ユニット4、発券ユニット5、硬貨処理ユニット6、紙幣処理ユニット7、カード処理ユニット8、PINパッド9、および通信ユニット10は、信号の伝送路であるケーブル等で制御ユニット2に接続されている。券売機1は、駅に設置され、定期券、キップ、回数券等の乗車券を利用者に発券する。また、券売機1は、乗車券として使用できるSFカード(Stored Fare Card)に対するチャージ処理(入金処理)も行える。この券売機1は、乗車券の発券にかかる取引金額を貨幣で精算することもできれば、クレジットカードで決済することもできる。ここで言う貨幣は、硬貨、および紙幣の総称である。
Hereinafter, a ticket vending machine according to an embodiment of the present invention will be described.
FIG. 1 is a block diagram showing a configuration of a main part of a ticket vending machine according to this example. FIG. 2 is a schematic front view of the ticket vending machine according to this example. A ticket vending machine 1 according to this example includes a control unit 2, a display unit 3, an operation unit 4, a ticket issuing unit 5, a coin processing unit 6, a bill processing unit 7, a card processing unit 8, and a PIN pad 9. And a communication unit 10. The display unit 3, the operation unit 4, the ticket issuing unit 5, the coin processing unit 6, the banknote processing unit 7, the card processing unit 8, the PIN pad 9, and the communication unit 10 are connected to the control unit 2 by cables or the like that are signal transmission paths. It is connected. The ticket vending machine 1 is installed at a station and issues tickets such as commuter passes, tickets, and coupon tickets to users. Further, the ticket vending machine 1 can also perform charge processing (payment processing) for an SF card (Stored Fare Card) that can be used as a boarding ticket. The ticket vending machine 1 can settle a transaction amount for issuing a ticket with money, or can settle with a credit card. The money here is a collective term for coins and banknotes.
 制御ユニット2は、券売機1本体が備える各ユニットを制御する。制御ユニット2は、決済部2aを有する。決済部2aは、入力された乗車券情報に応じた乗車券の発券にかかる取引金額をクレジットカードで決済する決済処理を行う。
 表示ユニット3は、本体正面に設けた表示器3aを有する。表示ユニット3は、この表示器3aの画面表示を制御する。
The control unit 2 controls each unit included in the ticket vending machine 1 main body. The control unit 2 has a settlement unit 2a. The settlement unit 2a performs a settlement process in which the transaction amount of the ticket issued according to the entered ticket information is settled with a credit card.
The display unit 3 has a display 3a provided on the front surface of the main body. The display unit 3 controls the screen display of the display 3a.
 操作ユニット4は、表示器3aの画面上に貼付したタッチパネル4aを有する。操作ユニット4は、タッチパネル4aにおける利用者の入力操作(利用者が指で押下したタッチパネル4a上の押下位置)を検出し、検出した押下位置に応じた入力操作データを制御ユニット2に出力する。また、操作ユニット4は、入力デバイスとして押し釦スイッチも備えている。操作ユニット4は、利用者が押し釦スイッチを押下すると、押下された押し釦スイッチに応じた入力操作データを制御ユニット2に出力する。利用者は、操作ユニット4において、購入する乗車券の乗車券情報等を券売機1本体に入力する操作を行う。 The operation unit 4 has a touch panel 4a pasted on the screen of the display 3a. The operation unit 4 detects a user's input operation on the touch panel 4a (a pressing position on the touch panel 4a pressed by the user with a finger) and outputs input operation data corresponding to the detected pressing position to the control unit 2. The operation unit 4 also includes a push button switch as an input device. When the user presses the push button switch, the operation unit 4 outputs input operation data corresponding to the pressed push button switch to the control unit 2. The user performs an operation of inputting the ticket information of the ticket to be purchased into the main body of the ticket vending machine 1 in the operation unit 4.
 発券ユニット5は、乗車券を発券する処理を行う。券売機1には、本体正面に発券口5aが設けられている。発券ユニット5は、利用者に対して発券する乗車券を発券口5aに放出する。
 券売機1には、本体正面に硬貨投入口6a、および釣銭硬貨受皿6bが設けられている。利用者は、乗車券の発券等にかかる取引金額の精算に用いる硬貨を硬貨投入口6aに投入する。硬貨処理ユニット6は、利用者が硬貨投入口6aに投入した硬貨を受け付ける。また、硬貨処理ユニット6は、利用者に対して返却するつり銭等にかかる硬貨を釣銭硬貨受皿6bに放出する。硬貨投入口6aは、複数枚(2~3枚程度)の硬貨が重なった状態であっても、券売機1本体に投入できる形状である。硬貨処理ユニット6は、利用者が投入した硬貨や、利用者に対して釣銭等として放出する釣銭硬貨について、金種や真偽を識別する硬貨識別部を有している。
The ticket issuing unit 5 performs a process for issuing a boarding ticket. The ticket vending machine 1 is provided with a ticketing opening 5a on the front surface of the main body. The ticket issuing unit 5 releases a ticket to be issued to the user to the ticket opening 5a.
The ticket vending machine 1 is provided with a coin insertion slot 6a and a change coin receiving tray 6b on the front surface of the main body. The user inserts a coin used for the settlement of the transaction amount for issuing a ticket into the coin slot 6a. The coin processing unit 6 accepts coins that the user has inserted into the coin insertion slot 6a. Moreover, the coin processing unit 6 discharges coins for change to be returned to the user to the change coin receiving tray 6b. The coin slot 6a has a shape that can be inserted into the main body of the ticket vending machine 1 even when a plurality of (about 2 to 3) coins are stacked. The coin processing unit 6 has a coin identifying unit that identifies the denomination and authenticity of coins input by the user and change coins to be released as change to the user.
 券売機1には、本体正面に紙幣投入口7a、および紙幣放出口7bが設けられている。利用者は、乗車券の発券等にかかる取引金額の精算に用いる紙幣を紙幣投入口7aに投入する。紙幣処理ユニット7は、利用者が紙幣投入口7aに投入した紙幣を受け付ける。また、紙幣処理ユニット7は、利用者に対して返却するつり銭にかかる紙幣を紙幣放出口7bに放出する。紙幣処理ユニット7は、利用者が投入した紙幣や、利用者に対して釣銭として放出する紙幣について、金種や真偽を識別する紙幣識別部を有している。 The ticket vending machine 1 is provided with a bill insertion slot 7a and a bill discharge slot 7b on the front surface of the main body. A user inserts the banknote used for the settlement of the transaction amount concerning ticket issuing etc. into the banknote slot 7a. The banknote processing unit 7 accepts banknotes inserted by the user into the banknote slot 7a. Moreover, the banknote processing unit 7 discharge | releases the banknote concerning the change returned with respect to a user to the banknote discharge port 7b. The banknote processing unit 7 has a banknote identification unit that identifies the denomination and authenticity of banknotes inserted by the user and banknotes released as change to the user.
 また、券売機1には、本体正面にカード挿入/放出口8aが設けられている。利用者は、乗車券の発券にかかる取引金額の決済に用いるクレジットカードや、乗車券として使用できるSFカードをカード挿入/放出口8aに挿入する。カード処理ユニット8は、券売機1本体の正面に設けたカード挿入/放出口8aに挿入されたカードを本体内部に取り込み、このカードに記録されているカードデータの読み取りや、このカードに対するカードデータの書き込み(カードデータの更新)等を行う。カード処理ユニット8は、カード挿入/放出口8aに挿入されたカードから読み取ったカードデータを制御ユニット2に出力するとともに、制御ユニット2等から入力された更新用のカードデータをカード挿入/放出口8aに挿入されたカードに書き込む。カード処理ユニット8は、カード挿入/放出口8aに挿入されたカードに対する処理が完了すると、このカードを利用者に返却するためにカード挿入/放出口8aに放出する。 Further, the ticket vending machine 1 is provided with a card insertion / release port 8a on the front surface of the main body. The user inserts into the card insertion / release port 8a a credit card used for settlement of the transaction amount related to the ticket issue or an SF card that can be used as a ticket. The card processing unit 8 takes in a card inserted into a card insertion / release port 8a provided on the front face of the ticket vending machine 1 into the main body, reads card data recorded on the card, and card data for the card. Is written (card data is updated). The card processing unit 8 outputs the card data read from the card inserted into the card insertion / release port 8a to the control unit 2 and the update card data input from the control unit 2 or the like to the card insertion / release port. Write to the card inserted in 8a. When the processing for the card inserted into the card insertion / discharge port 8a is completed, the card processing unit 8 discharges the card to the card insertion / discharge port 8a in order to return it to the user.
 この例では、SFカードは、無線通信機能を有する非接触ICカードであるとして説明する。また、クレジットカードは、IC接点が表面に形成されている接触式ICカードであるとして説明する。クレジットカードは、磁気ストライプを有するICカードであってもよいし、磁気ストライプが形成されていないICカードであってもよい。また、クレジットカードは、ICを有していない磁気カードであってもよい。 In this example, the SF card is described as a non-contact IC card having a wireless communication function. The credit card will be described as a contact IC card having an IC contact formed on the surface. The credit card may be an IC card having a magnetic stripe or an IC card in which no magnetic stripe is formed. The credit card may be a magnetic card that does not have an IC.
 カード処理ユニット8は、SFカードに対するカードデータの読み取りや、カードデータの書き込みを行うための無線通信機能を有する。また、カード処理ユニット8は、クレジットカードの表面に形成されているIC接点に接触させるIC端子を有するとともに、このIC接点をクレジットカードのIC接点に対して接離させる機構部を有する。カード処理ユニット8は、IC端子をクレジットカードのIC接点に接触させた状態で、このクレジットカードに対するカードデータの読み取りや、カードデータの書き込みを行う。 The card processing unit 8 has a wireless communication function for reading card data to the SF card and writing card data. The card processing unit 8 has an IC terminal that is brought into contact with an IC contact formed on the surface of the credit card, and a mechanism that makes the IC contact come in contact with and separates from the IC contact of the credit card. The card processing unit 8 reads the card data and writes the card data to the credit card in a state where the IC terminal is in contact with the IC contact of the credit card.
 PINパッド9は、後述する平文モード、または暗号化モードで動作する。PINパッド9は、購入する乗車券の乗車券情報の入力操作や、クレジットカードで決済するときの本人確認のための認証コードの入力操作等に用いる入力デバイスである。
 通信ユニット10は、ネットワークを介して、クレジット決済の認証要求を行う認証サーバとの間における通信を制御する。また、通信ユニット10は、図示していない自動改札機や、他の券売機1等の駅務機器との間における通信の制御も行う。
The PIN pad 9 operates in a plaintext mode or an encryption mode to be described later. The PIN pad 9 is an input device used for an input operation of ticket information of a ticket to be purchased, an input operation of an authentication code for identity verification when making a payment with a credit card, and the like.
The communication unit 10 controls communication with an authentication server that issues a credit payment authentication request via a network. The communication unit 10 also controls communication with station equipment such as an automatic ticket gate (not shown) and other ticket vending machines 1.
 ここで、PINパッド9について、より詳細に説明する。図3は、PINパッドの主要部の構成を示すブロック図である。PINパッド9は、制御部21と、テンキー操作部22と、入出力I/F23とを有する。
 制御部21は、PINパッド9の動作を制御する。テンキー操作部22は、10個の数字キー(0~9のそれぞれに対応する数字キー)と、「*」、および「#」の2つの記号キーとを有する。PINパッド9は、押下されたキーを制御部21に通知する。入出力I/F23は、券売機1本体の制御ユニット2との間における入出力を制御する。また、テンキー操作部22の各キーと制御部21とは、ケーブルではなく、プリントパターンで電気的に接続されており、テンキー操作部22と制御部21との間で信号が抜き取られることに対するセキュリティは確保されている。
Here, the PIN pad 9 will be described in more detail. FIG. 3 is a block diagram showing the configuration of the main part of the PIN pad. The PIN pad 9 includes a control unit 21, a numeric keypad operation unit 22, and an input / output I / F 23.
The control unit 21 controls the operation of the PIN pad 9. The numeric keypad 22 has ten numeric keys (numeric keys corresponding to 0 to 9) and two symbol keys “*” and “#”. The PIN pad 9 notifies the control unit 21 of the pressed key. The input / output I / F 23 controls input / output with the control unit 2 of the ticket vending machine 1 main body. Further, each key of the numeric keypad operation unit 22 and the control unit 21 are electrically connected not by a cable but by a print pattern, and security against a signal being extracted between the numeric keypad operation unit 22 and the control unit 21. Is secured.
 制御部21は、券売機1本体から平文モードでの動作が指定されると、PINパッド9を平文モードで動作させる。また、制御部21は、券売機1本体から暗号化モードでの動作が指定されると、PINパッド9を暗号化モードで動作させる。平文モードは、テンキー操作部22のいずれかのキーが操作されると、そのキーに応じたキーコードを制御ユニット2に出力する。暗号化モードは、テンキー操作部22のいずれかのキーが操作されると、操作されたキーを制御部21のメモリ(不図示)に順番に記憶するとともに、キーが押されたことを制御ユニット2に出力するモードである。また、暗号化モードは、テンキー操作部22の特定のキー(この例では「#」)が押下されると、制御部21のメモリに記憶しているキー列(このキー列は、テンキー操作部22において操作されたキーの順番に並んでいる。)を暗号化し、この暗号化データを制御ユニット2に出力する。制御部21は、キー列の暗号化に用いる暗号鍵をメモリに記憶している。 When the operation in the plain text mode is designated from the ticket vending machine 1 main body, the control unit 21 operates the PIN pad 9 in the plain text mode. Further, when the operation in the encryption mode is designated from the ticket vending machine 1 main body, the control unit 21 operates the PIN pad 9 in the encryption mode. In the plaintext mode, when any key of the numeric keypad 22 is operated, a key code corresponding to the key is output to the control unit 2. In the encryption mode, when any key of the numeric keypad 22 is operated, the operated keys are sequentially stored in a memory (not shown) of the control unit 21 and the control unit indicates that the key has been pressed. 2 is a mode to output to 2. In addition, when a specific key (“#” in this example) of the numeric keypad 22 is pressed, the encryption mode is a key sequence stored in the memory of the control unit 21 (this key sequence is the numeric keypad And the encrypted data is output to the control unit 2. The control unit 21 stores an encryption key used for encryption of the key string in the memory.
 次に、この券売機1の動作について説明する。図4は、券売機における発券処理を示すフローチャートである。券売機1は、制御ユニット2において、利用者が音声案内モードを選択したか、通常モードを選択したかを判定する(s1)。音声案内モードは、図示していない音声案内部において、利用者に対して乗車券の購入にかかる入力操作を案内する案内メッセージを送出し、利用者による乗車券情報の入力操作をPINパッド9で受け付けて乗車券を発券するモードである。また、通常モードは、表示ユニット3が表示器3aにおける表示画面を制御し、利用者による乗車券情報の入力操作を操作ユニット4で受け付けて乗車券を発券するモードである。 Next, the operation of the ticket vending machine 1 will be described. FIG. 4 is a flowchart showing the ticket issuing process in the ticket vending machine. In the control unit 2, the ticket vending machine 1 determines whether the user has selected the voice guidance mode or the normal mode (s1). In the voice guidance mode, in a voice guidance section (not shown), a guidance message for guiding an input operation related to purchase of a ticket is sent to the user, and the user inputs the ticket information using the PIN pad 9. This mode accepts and issues a ticket. The normal mode is a mode in which the display unit 3 controls the display screen on the display device 3a, and the operation unit 4 accepts an input operation of ticket information by the user and issues a ticket.
 制御ユニット2は、例えばPINパッド9のテンキー操作部22の音声案内モード選択キー(例えば、「*」のキー)が押下されたとき、音声案内モードが選択されたと判定する。すなわち、利用者は、PINパッド9のテンキー操作部22の音声案内モード選択キーを押下することによって、音声案内モードを選択することができる。また、制御ユニット2は、PINパッド9のテンキー操作部22の音声案内モード選択キーが押下されることなく、操作ユニット4がタッチパネル4aにおける利用者の押下位置を検知すると、通常モードが選択されたと判定する。すなわち、利用者は、PINパッド9のテンキー操作部22を操作することなく、表示器3aの画面上に貼付されているタッチパネル4aを押下することによって、通常モードを選択することができる。 The control unit 2 determines that the voice guidance mode is selected, for example, when a voice guidance mode selection key (for example, “*” key) of the numeric keypad 22 of the PIN pad 9 is pressed. That is, the user can select the voice guidance mode by pressing the voice guidance mode selection key on the numeric keypad 22 of the PIN pad 9. In addition, the control unit 2 determines that the normal mode has been selected when the operation unit 4 detects the pressing position of the user on the touch panel 4a without pressing the voice guidance mode selection key of the numeric keypad operation unit 22 of the PIN pad 9. judge. That is, the user can select the normal mode by pressing the touch panel 4a pasted on the screen of the display 3a without operating the numeric keypad 22 of the PIN pad 9.
 制御ユニット2が、選択されたモードが音声案内モードであると判定すると、音声案内部が音声案内を開始する(s2)。このとき、制御ユニット2は、PINパッド9に対して平文モードを指定する。制御ユニット2は、平文モード、または後述する暗号化モードのどちらかをPINパッド9に指定する構成であってもよいし、利用者による入力操作を受け付ける情報の種別(乗車券情報、認証コード等)をPINパッド9に出力し、PINパッド9が情報の種別によって、平文モード、または暗号化モードを選択する構成であってもよい。 When the control unit 2 determines that the selected mode is the voice guidance mode, the voice guidance unit starts voice guidance (s2). At this time, the control unit 2 designates the plain text mode for the PIN pad 9. The control unit 2 may be configured to designate either the plaintext mode or the encryption mode to be described later on the PIN pad 9, or the type of information that accepts an input operation by the user (ticket information, authentication code, etc. ) May be output to the PIN pad 9, and the PIN pad 9 may select a plaintext mode or an encryption mode depending on the type of information.
 PINパッド9は、利用者による乗車券情報の入力操作を受け付ける(s3)。利用者は、テンキー操作部22のキーを押下して、乗車券情報を入力する。PINパッド9は、利用者が押下したキーに応じたキーコードを制御ユニット2に出力する。PINパッド9は、上述したように、この時点においては平文モードが指定されているので、利用者がキーを押下する毎に、そのとき押下されたキーに応じたキーコードを暗号化することなく、制御ユニット2に出力する(平文モードにおけるPINパッド9の動作の詳細については後述する。)。 The PIN pad 9 accepts an input operation of ticket information by the user (s3). The user presses a key on the numeric keypad 22 to input the ticket information. The PIN pad 9 outputs a key code corresponding to the key pressed by the user to the control unit 2. As described above, since the plain text mode is designated at this time, the PIN pad 9 does not encrypt the key code corresponding to the pressed key every time the user presses the key. And output to the control unit 2 (details of the operation of the PIN pad 9 in the plaintext mode will be described later).
 また、制御ユニット2が、選択されたモードが通常モードであると判定すると、操作ユニット4が利用者による乗車券情報の入力操作を受け付ける(s4)。操作ユニット4は、タッチパネル4aにおける利用者の押下位置に応じた入力コードを制御ユニット2に出力する。
 制御ユニット2は、s3、またはs4で、今回発券する乗車券の乗車券情報の入力を受け付けると、乗車券の発券にかかる取引金額の決済が、クレジットカードによるクレジット決済であるか、貨幣による現金決済であるかを判定する(s5)。制御ユニット2がクレジット決済であると判定すると、カード処理ユニット8が取引金額の決済に用いるクレジットカードを受け付ける(s6)。カード処理ユニット8は、利用者がカード挿入/放出口8aに挿入したクレジットカードを受け付ける。一方、制御ユニット2が現金決済であると判定すると、硬貨処理ユニット6が利用者による硬貨の投入を受け付けるとともに、紙幣処理ユニット7が利用者による紙幣の投入を受け付ける(s10)。
If the control unit 2 determines that the selected mode is the normal mode, the operation unit 4 accepts an input operation of ticket information by the user (s4). The operation unit 4 outputs an input code corresponding to the pressed position of the user on the touch panel 4a to the control unit 2.
When the control unit 2 receives the ticket information of the ticket to be issued this time at s3 or s4, the settlement of the transaction amount relating to the ticket issuance is a credit settlement by a credit card, or a cash by money It is determined whether it is a settlement (s5). If the control unit 2 determines that it is a credit settlement, the card processing unit 8 accepts a credit card used for settlement of the transaction amount (s6). The card processing unit 8 receives a credit card inserted by the user into the card insertion / release port 8a. On the other hand, when it is determined that the control unit 2 is cash settlement, the coin processing unit 6 accepts the insertion of coins by the user, and the bill processing unit 7 accepts the insertion of bills by the user (s10).
 なお、クレジット決済であるか、現金決済であるかの判定は、利用者の選択入力操作に応じて行う構成であってもよい。また、カード処理ユニット8がカード挿入/放出口8aに挿入されたクレジットカードを受け付けたときにクレジット決済であると判定する構成であってもよい。この場合、硬貨処理ユニット6が硬貨投入口6aに投入された硬貨を受け付けたとき、または紙幣処理ユニット7が紙幣投入口7aに挿入された紙幣を受け付けたときに、現金決済であると判定すればよい。 It should be noted that the determination as to credit settlement or cash settlement may be made in accordance with the user's selection input operation. Moreover, the structure which determines with it being a credit card payment may be sufficient when the card processing unit 8 receives the credit card inserted in the card insertion / release port 8a. In this case, when the coin processing unit 6 receives a coin inserted into the coin insertion slot 6a, or when the banknote processing unit 7 receives a banknote inserted into the banknote insertion slot 7a, it is determined to be a cash settlement. That's fine.
 制御ユニット2は、s6で受け付けたクレジットカードをカードデータの読取位置に搬送し、IC端子をクレジットカードのIC接点に接触させ、カードデータを読み取るとともに、PINパッド9に対して暗号化モードを指示する。暗号化モードにおけるPINパッド9の動作の詳細については後述する。PINパッド9は、テンキー操作部22において利用者による認証コード(所謂、暗証番号)の入力操作を受け付ける(s7)。認証コードは、複数桁(例えば、4桁)の数字である。利用者は上位の桁から順番にテンキー操作部22の数字キーを押下して認証コードを入力する。PINパッド9は、制御部21において数字キーが押下された順番に並ぶキー列を暗号化した暗号化データを生成し、この暗号化データを制御ユニット2に出力する。 The control unit 2 transports the credit card received in s6 to the card data reading position, brings the IC terminal into contact with the IC contact of the credit card, reads the card data, and instructs the PIN pad 9 on the encryption mode. To do. Details of the operation of the PIN pad 9 in the encryption mode will be described later. The PIN pad 9 accepts an input operation of an authentication code (so-called password) by the user at the numeric keypad 22 (s7). The authentication code is a number of multiple digits (for example, 4 digits). The user presses the numeric key of the numeric keypad 22 in order from the upper digit and inputs the authentication code. The PIN pad 9 generates encrypted data obtained by encrypting key strings arranged in the order in which the numeric keys are pressed in the control unit 21, and outputs the encrypted data to the control unit 2.
 制御ユニット2は、決済部2aにおいて、今回乗車券情報が入力された乗車券の発券にかかる取引金額を、s6で受け付けたクレジットカードで決済する決済処理(クレジット決済)を行う(s8)。s8では、取引の認証をオフライン認証で行ってもよいし、オンライン認証で行ってもよい。オフライン認証では、カード処理ユニット8が受け付けたクレジットカードが有効期限内であるかどうか、このクレジットカードのICに記録されている認証コードと、今回PINパッド9において入力された認証コードとが一致しているかどうか等によって取引の可否を認証する。また、オンライン認証では、通信ユニット10において、カード処理ユニット8が受け付けたクレジットカードのカード番号、入力された認証コード、今回の取引金額等を含む取引認証データを認証サーバに送信し、この認証サーバから取引可否を示す認証結果を受信する。認証サーバは、カードの有効/無効(ここでは、有効期限内であるかどうかだけでなく、ネガファイルに登録されている無効カードであるかどうか等も判定される。)、認証コードが適正であるかどうか、今回の取引が与信限度額の範囲内であるかどうか等によって取引の可否を認証する。 In the settlement unit 2a, the control unit 2 performs a settlement process (credit settlement) in which the transaction amount of the ticket issued with the current ticket information is settled with the credit card accepted in s6 (s8). In s8, transaction authentication may be performed by offline authentication or online authentication. In the off-line authentication, whether the credit card accepted by the card processing unit 8 is within the validity period, the authentication code recorded on the IC of the credit card and the authentication code input on the PIN pad 9 this time match. Authenticates whether or not the transaction is possible depending on whether or not In the online authentication, the communication unit 10 transmits transaction authentication data including the card number of the credit card received by the card processing unit 8, the input authentication code, the current transaction amount, etc. to the authentication server. Receives an authentication result indicating whether or not the transaction is possible. The authentication server determines whether the card is valid / invalid (in this case, not only whether it is within the validity period but also whether it is an invalid card registered in the negative file), and the authentication code is appropriate. Whether or not the transaction is possible is verified by whether or not the transaction is within the credit limit range.
 決済部2aが乗車券の発券にかかる取引金額をクレジットカードで決済すると、カード処理ユニット8が今回受け付けたクレジットカードをカード挿入/放出口8aに放出し、且つ発券ユニット5が今回受け付けた乗車券情報に応じた乗車券を発券口5aに放出する発券処理を行って(s9)、s1に戻る。
 なお、決済部2aが乗車券の発券にかかる取引金額をクレジットカードで決済できなかったときには、カード処理ユニット8は今回受け付けたクレジットカードをカード挿入/放出口8aに放出するが、発券ユニット5は今回受け付けた乗車券情報に応じた乗車券を発券しない。また、決済部2aが乗車券の発券にかかる取引金額をクレジットカードで決済できなかったときには、本発券処理を後述するs10以降の処理に移行させてもよい。また、制御ユニット2は、認証コードの入力を受け付ける前に、カード処理ユニット8が受け付けたクレジットカードが有効期限内であるかどうかを判定し、有効期限内のクレジットカードでなければ、PINパッド9において認証コードの入力を受け付けない構成にしてもよい。
When the settlement unit 2a settles the transaction amount for ticketing with a credit card, the card processing unit 8 releases the credit card accepted this time to the card insertion / release port 8a and the ticketing unit 5 accepts this time A ticketing process for releasing the boarding ticket corresponding to the information to the ticketing slot 5a is performed (s9), and the process returns to s1.
When the settlement unit 2a fails to settle the transaction amount for issuing the ticket using a credit card, the card processing unit 8 releases the accepted credit card to the card insertion / release port 8a, but the ticketing unit 5 Do not issue a ticket according to the ticket information received this time. In addition, when the settlement unit 2a cannot settle the transaction amount for issuing a ticket with a credit card, the present ticketing process may be shifted to the process after s10 described later. The control unit 2 determines whether the credit card accepted by the card processing unit 8 is within the expiration date before accepting the input of the authentication code. If the credit card is not within the expiration date, the PIN pad 9 The authentication code input may not be accepted.
 また、制御ユニット2は、現金決済であると判定すると、硬貨投入口6a、および紙幣投入口7aにおいて投入された貨幣の合計金額が、s3、またはs4で受け付けた乗車券情報に応じた乗車券の取引金額以上になるのを待つ(s10)。制御ユニット2は、硬貨投入口6a、および紙幣投入口7aにおいて投入された貨幣の合計金額が、s3、またはs4で受け付けた乗車券情報に応じた乗車券の取引金額以上になると、今回発券する乗車券の取引金額を現金で決済する(s11)。乗車券の発券にかかる取引金額が現金で決済されると、硬貨処理ユニット6、および紙幣処理ユニット7が必要に応じてつり銭の放出を行い、且つ発券ユニット5が今回受け付けた乗車券情報に応じた乗車券を発券口5aに放出する発券処理を行って(s12)、s1に戻る。 If the control unit 2 determines that the payment is a cash settlement, the total amount of money inserted at the coin insertion slot 6a and the banknote insertion slot 7a corresponds to the ticket information received at s3 or s4. Wait until the transaction amount exceeds (s10). The control unit 2 issues a ticket when the total amount of money inserted at the coin insertion slot 6a and the bill insertion slot 7a is equal to or greater than the transaction amount of the ticket corresponding to the ticket information received at s3 or s4. The transaction amount of the ticket is settled with cash (s11). When the transaction amount required for issuing the ticket is settled in cash, the coin processing unit 6 and the banknote processing unit 7 release the change as necessary, and the ticket issuing unit 5 responds to the ticket information received this time. The ticket issuing process for releasing the boarded ticket to the ticket opening 5a is performed (s12), and the process returns to s1.
 このように、この例にかかる券売機1は、乗車券の発券にかかる取引金額の決済がクレジットカード、または貨幣で行える。
 ここで、PINパッド9の平文モードにおける動作、および暗号化モードにおける動作について説明する。図5は、PINパッドの平文モードの動作を示すフローチャートである。図6は、PINパッドの暗号化モードの動作を示すフローチャートである。
As described above, the ticket vending machine 1 according to this example can perform settlement of the transaction amount related to the ticket issuing with a credit card or money.
Here, the operation in the plain text mode and the operation in the encryption mode of the PIN pad 9 will be described. FIG. 5 is a flowchart showing the operation of the plain text mode of the PIN pad. FIG. 6 is a flowchart showing the operation of the PIN pad encryption mode.
 まず、平文モードの動作について説明する。テンキー操作部22は、いずれかのキーが操作されると(s21)、操作されたキーを制御部21に通知する(s22)。制御部21は、テンキー操作部22から通知されたキー(今回操作されたキー)に応じたキーコードを、入出力I/F23に接続されている制御ユニット2に出力し(s23)、s21に戻る。 First, the operation in plain text mode will be described. When any key is operated (s21), the numeric keypad 22 notifies the controller 21 of the operated key (s22). The control unit 21 outputs a key code corresponding to the key notified from the numeric keypad operation unit 22 (the key operated this time) to the control unit 2 connected to the input / output I / F 23 (s23), and to s21 Return.
 このように、PINパッド9は、平文モードでは、テンキー操作部22のいずれかのキーが操作される毎に、そのとき操作されたキーに応じたキーコードを暗号化することなく、制御ユニット2に出力する。
 次に、暗号化モードの動作について説明する。テンキー操作部22は、いずれかのキーが操作されると(s31)、操作されたキーを制御部21に通知する(s32)。制御部21は、テンキー操作部22から通知されたキーが、予め定めた特定のキー(この例では、「#」のキー)であるかどうかを判定する(s33)。この特定のキーは、操作者が入力操作の完了を入力するときに操作するキーである。例えば、操作者がPINパッド9において4桁の数字列3648を入力する場合、PINパッド9の「3」「6」「4」「8」のキーを順番に操作した後、「#」を操作する。
As described above, in the plain text mode, the PIN pad 9 does not encrypt the key code corresponding to the key operated at any time when any key of the numeric keypad operation unit 22 is operated. Output to.
Next, the operation in the encryption mode will be described. When any key is operated (s31), the numeric keypad 22 notifies the controller 21 of the operated key (s32). The control unit 21 determines whether or not the key notified from the numeric keypad operation unit 22 is a predetermined specific key (in this example, “#” key) (s33). This specific key is a key operated when the operator inputs completion of the input operation. For example, when the operator inputs a 4-digit number string 3648 on the PIN pad 9, the “3”, “6”, “4”, and “8” keys on the PIN pad 9 are sequentially operated, and then “#” is operated. To do.
 制御部21は、s33で特定のキーでないと判定すると、今回操作されたキー(すなわちs22でテンキー操作部22から通知されたキー)をメモリ(不図示)に記憶する(s34)。s34では、制御部21は、PINパッド9のテンキー操作部22において操作されたキーを、操作された順番に記憶する。また、制御部21は、入出力I/F23に接続されている制御ユニット2に、キー操作があった旨を出力し(s35)、s31に戻る。 When determining that the key is not a specific key in s33, the control unit 21 stores the key operated this time (that is, the key notified from the numeric keypad operation unit 22 in s22) in a memory (not shown) (s34). In s34, the control part 21 memorize | stores the key operated in the ten key operation part 22 of the PIN pad 9 in the operated order. Further, the control unit 21 outputs a key operation to the control unit 2 connected to the input / output I / F 23 (s35), and returns to s31.
 制御ユニット2は、PINパッド9のキー操作があった旨の出力によって、その時点において数字が何桁入力されたかを判断できる。したがって、制御ユニット2は、表示ユニット3に対して、例えば操作者が入力した桁数の確認が行える画面を表示器3aに表示させる指示が行える。この画面は、例えば、操作者が入力した桁数と同数の「*」を並べて表示する画面である。 The control unit 2 can determine how many digits have been input at that time by outputting that the key operation of the PIN pad 9 has been performed. Therefore, the control unit 2 can instruct the display unit 3 to display on the display 3a a screen on which the number of digits input by the operator can be confirmed, for example. This screen is a screen that displays, for example, the same number of “*” as the number of digits input by the operator.
 なお、s34、s35にかかる処理の順番は、上記と逆の順番であってもよい。
 また、制御部21は、s33で特定のキーであると判定すると、メモリに記憶しているキー列(s34で操作された順番に記憶したキー)を暗号化する(s36)。例えば、操作者が4桁の数字列3648を入力した場合、メモリには「3」「6」「4」「8」のキー列が記憶されている。制御部21は、キー列の暗号化に用いる暗号鍵をメモリに記憶している。制御部21は、入出力I/F23に接続されている制御ユニット2に、s36で暗号化したキー列の暗号化データを出力し(s35)、s31に戻る。
In addition, the order of the processes concerning s34 and s35 may be the reverse order of the above.
When determining that the key is a specific key in s33, the control unit 21 encrypts the key string stored in the memory (the key stored in the order operated in s34) (s36). For example, when the operator inputs a 4-digit number string 3648, the key strings “3”, “6”, “4”, and “8” are stored in the memory. The control unit 21 stores an encryption key used for encryption of the key string in the memory. The control unit 21 outputs the encrypted data of the key string encrypted in s36 to the control unit 2 connected to the input / output I / F 23 (s35), and returns to s31.
 このように、PINパッド9が暗号化モードであるとき、PINパッド9から制御ユニット2に出力するデータは暗号化されたデータである。
 したがって、漏洩に対するセキュリティの確保が必要である認証コードをPINパッド9で利用者に入力させるときには、このPINパッド9を暗号化モードで動作させることによって、認証コードが漏洩することに対するセキュリティの向上を図ることができる。悪意のある第3者がPINパッド9と制御ユニット2とを接続する信号の伝送路から認証コードを抜き取っても、抜き取られた認証コードは暗号化されているので、この認証コードが漏洩するのを防止できる。
As described above, when the PIN pad 9 is in the encryption mode, the data output from the PIN pad 9 to the control unit 2 is encrypted data.
Therefore, when the user is required to input an authentication code that requires security against leakage through the PIN pad 9, the PIN pad 9 is operated in the encryption mode to improve security against the leakage of the authentication code. Can be planned. Even if a malicious third party pulls out the authentication code from the signal transmission line connecting the PIN pad 9 and the control unit 2, the extracted authentication code is encrypted, so this authentication code leaks. Can be prevented.
 また、漏洩に対するセキュリティの確保が特に必要でない乗車券情報をPINパッド9で利用者に入力させるときには、このPINパッド9を平文モードで動作させることによって、暗号化処理や、復号化処理を不要にでき、券売機1本体の処理負荷が大きくなるのを抑えられる。暗号化処理は、PINパッド9が行い、複合化処理は必要に応じて制御ユニット2が行う。 In addition, when the user inputs ticket information that does not particularly require security against leakage through the PIN pad 9, the PIN pad 9 is operated in the plaintext mode, so that encryption processing and decryption processing are unnecessary. It is possible to suppress an increase in processing load on the ticket vending machine 1 main body. The encryption process is performed by the PIN pad 9, and the decryption process is performed by the control unit 2 as necessary.
 なお、PINパッド9は、上記した例の認証コードの入力時に限らず、漏洩に対するセキュリティの確保が必要である情報の入力時に、暗号化モードで動作させればよい。また、PINパッド9は、上記した例の乗車券情報の入力時に限らず、漏洩に対するセキュリティの確保が特に必要でない情報の入力時に、平文モードで動作させればよい。
 次に、別の例にかかる券売機1について説明する。この例にかかる券売機1は、図4に示した発券処理にかえて、図7に示す発券処理を行う点で相違する。この券売機1も、上記したs1~s6の処理を行い、s6でカード処理ユニット8がクレジットカードを受け付けると、今回受け付けたクレジットカードが有効期限内であるかどうかを判定する(s15)。制御ユニット2は、有効期限内であると判定すると、上記例で説明したs7~s9の処理を実行する。一方、制御ユニット2は、s15で有効期限内でないと判定すると、カード処理ユニット8が今回受け付けたクレジットカードをカード挿入/放出口8aに放出し(s16)、s1に戻る。
Note that the PIN pad 9 may be operated in the encryption mode not only when the authentication code in the above example is input but also when information that requires security against leakage is input. Further, the PIN pad 9 may be operated in the plain text mode not only when inputting the ticket information in the above example but also when inputting information that does not particularly require security against leakage.
Next, a ticket vending machine 1 according to another example will be described. The ticket vending machine 1 according to this example is different in that the ticket issuing process shown in FIG. 7 is performed instead of the ticket issuing process shown in FIG. This ticket vending machine 1 also performs the processes of s1 to s6 described above, and when the card processing unit 8 receives a credit card in s6, it determines whether or not the credit card received this time is within the expiration date (s15). If the control unit 2 determines that it is within the expiration date, it executes the processing of s7 to s9 described in the above example. On the other hand, if the control unit 2 determines that the expiration date is not within s15, the card processing unit 8 releases the credit card accepted this time to the card insertion / release port 8a (s16), and returns to s1.
 このように、この例の券売機1は、有効期限内でないクレジットカードを受け付けた場合、利用者に認証コードの入力を行わせない。これにより、利用者が認証コードを無駄に入力するのを防止できるだけでなく、PINパッド9が暗号化した認証コードを制御ユニット2に無駄に出力するのを防止できる。 Thus, the ticket vending machine 1 in this example does not allow the user to input the authentication code when accepting a credit card that is not within the expiration date. This not only prevents the user from inputting the authentication code in vain, but also prevents the authentication code encrypted by the PIN pad 9 from being output to the control unit 2 in vain.
1…券売機
2…制御ユニット
2a…決済部
3…表示ユニット
3a…表示器
4…操作ユニット
4a…タッチパネル
5…発券ユニット
5a…発券口
6…硬貨処理ユニット
6a…硬貨投入口
6b…釣銭硬貨受皿
7…紙幣処理ユニット
7a…紙幣投入口
7b…紙幣放出口
8…カード処理ユニット
8a…カード挿入/放出口
9…PINパッド
10…通信ユニット
21…制御部
22…テンキー操作部
23…入出力I/F
DESCRIPTION OF SYMBOLS 1 ... Ticket vending machine 2 ... Control unit 2a ... Settlement unit 3 ... Display unit 3a ... Display unit 4 ... Operation unit 4a ... Touch panel 5 ... Ticket issuing unit 5a ... Ticket issuing slot 6 ... Coin processing unit 6a ... Coin insertion slot 6b ... Change coin tray 7 ... Banknote processing unit 7a ... Banknote insertion slot 7b ... Banknote release slot 8 ... Card processing unit 8a ... Card insertion / release slot 9 ... PIN pad 10 ... Communication unit 21 ... Control unit 22 ... Numeric keypad control unit 23 ... Input / output I / F

Claims (5)

  1.  入力された乗車券情報に応じた乗車券の発券にかかる取引金額をクレジットカードで決済する券売機において、
     本体と、
     前記本体に挿入されたクレジットカードに記録されているカードデータを読み取るカード処理部と、
     前記乗車券情報の入力操作、および前記クレジットカードでの決済時に本人認証に用いる認証コードの入力操作に用いられるテンキーを有するPINパッドと、
     前記カード処理部が読み取った前記カードデータ、および前記PINパッドにおいて入力された前記認証コードを用いて、前記乗車券の発券にかかる取引金額の決済を行う制御部と、
    を備え、
     前記PINパッドは、入力された前記認証コードを暗号化して前記制御部に出力する、券売機。
    In a ticket vending machine that uses a credit card to settle the transaction amount for ticketing according to the ticket information entered,
    The body,
    A card processing unit for reading card data recorded on a credit card inserted in the main body;
    A PIN pad having a numeric keypad used for an input operation of the ticket information and an input operation of an authentication code used for identity authentication at the time of payment with the credit card;
    Using the card data read by the card processing unit and the authentication code input in the PIN pad, a control unit for settlement of the transaction amount related to the ticket issuing;
    With
    The PIN pad is a ticket vending machine that encrypts the input authentication code and outputs it to the control unit.
  2.  前記PINパッドは、入力された前記乗車券情報を暗号化することなく前記制御部に出力する、
    請求項1に記載の券売機。
    The PIN pad outputs the input ticket information to the control unit without encryption.
    The ticket vending machine according to claim 1.
  3.  前記制御部は、前記テンキーの操作によって入力された情報を暗号化して出力するか、暗号化することなく出力するかを、前記PINパッドに指示する、
    請求項1または2に記載の券売機。
    The control unit instructs the PIN pad to output the information input by operating the numeric keypad, whether the information is encrypted or output without encryption.
    The ticket vending machine according to claim 1 or 2.
  4.  前記制御部は、前記カード処理部が本体に挿入された前記クレジットカードから読み取った前記カードデータを用いて、前記クレジットカードが取引金額の決済に使用できる有効なクレジットカードであるかどうかを判定し、取引金額の決済に使用できる有効なクレジットカードでないと判定した場合には、前記PINパッドに対して前記認証コードの出力を要求しない、
    請求項1から3のいずれかに記載の券売機。
    The control unit determines whether the credit card is a valid credit card that can be used for settlement of a transaction amount, using the card data read from the credit card inserted into the main body by the card processing unit. If it is determined that the credit card is not a valid credit card that can be used to settle the transaction amount, the authentication code is not requested to be output to the PIN pad.
    The ticket vending machine according to any one of claims 1 to 3.
  5.  前記クレジットカードは、接触式のICカードである、
    請求項1から4のいずれかに記載の券売機。
    The credit card is a contact type IC card.
    The ticket vending machine according to any one of claims 1 to 4.
PCT/JP2017/041718 2017-02-24 2017-11-20 Ticket-vending machine WO2018154885A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2017-032955 2017-02-24
JP2017032955A JP6888325B2 (en) 2017-02-24 2017-02-24 Ticket-vending machine

Publications (1)

Publication Number Publication Date
WO2018154885A1 true WO2018154885A1 (en) 2018-08-30

Family

ID=63254194

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2017/041718 WO2018154885A1 (en) 2017-02-24 2017-11-20 Ticket-vending machine

Country Status (2)

Country Link
JP (1) JP6888325B2 (en)
WO (1) WO2018154885A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005293401A (en) * 2004-04-02 2005-10-20 Nec Corp Bank procedure work agent system
JP2006350687A (en) * 2005-06-16 2006-12-28 Seiko Epson Corp Pos device, printer, credit processing terminal, and pos processing method
JP2009059083A (en) * 2007-08-30 2009-03-19 Hitachi Ltd Automatic ticket issuing system
JP2009116567A (en) * 2007-11-06 2009-05-28 Oki Electric Ind Co Ltd Transaction device, and method of processing personal identification number in the transaction device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005293401A (en) * 2004-04-02 2005-10-20 Nec Corp Bank procedure work agent system
JP2006350687A (en) * 2005-06-16 2006-12-28 Seiko Epson Corp Pos device, printer, credit processing terminal, and pos processing method
JP2009059083A (en) * 2007-08-30 2009-03-19 Hitachi Ltd Automatic ticket issuing system
JP2009116567A (en) * 2007-11-06 2009-05-28 Oki Electric Ind Co Ltd Transaction device, and method of processing personal identification number in the transaction device

Also Published As

Publication number Publication date
JP2018139021A (en) 2018-09-06
JP6888325B2 (en) 2021-06-16

Similar Documents

Publication Publication Date Title
KR100389229B1 (en) Transaction Processing System and Transaction Processing Method
US5577121A (en) Transaction system for integrated circuit cards
US4968873A (en) Smart card issuing and receiving apparatus
US5559887A (en) Collection of value from stored value systems
US5596643A (en) Network settlement performed on consolidated information
KR100805280B1 (en) Automated teller machine using a biometrics
US20080249948A1 (en) Financial information input method using symmetrical key security algorithm and commercial transaction system for mobile communications
EP1096450A2 (en) Automated teller machine and method therof
JP5125413B2 (en) Electronic payment processing system
WO2018154885A1 (en) Ticket-vending machine
JP6950198B2 (en) Transaction execution device, transaction execution program, information communication system and cash processing device
KR20100033904A (en) Novel electric cash card system and managing method thereof
JP2003006449A (en) System and method for transaction processing, password number input device, transaction terminal, and host device
US20190034891A1 (en) Automated transaction system, method for control thereof, and card reader
JPH0619945A (en) Data transfer system portable terminal equipment
JP6888334B2 (en) Ticket-vending machine
JP5055935B2 (en) Automatic transaction system and automatic transaction device
JP7336394B2 (en) Money handling system and money handling method
JP5141085B2 (en) Electronic payment processing system
JP6998647B2 (en) Automatic teller machine
JP2007334682A (en) Automatic transaction system, and automatic transaction device
JP2022135315A (en) Automatic transaction system and transaction method
EP3690783A1 (en) Data processing apparatuses and methods
JP5061801B2 (en) Automatic transaction device authentication switching system
JPH10105624A (en) Telegraphic message enciphering processing system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17897236

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17897236

Country of ref document: EP

Kind code of ref document: A1