WO2018232666A1 - 一种支付验证方法和系统 - Google Patents

一种支付验证方法和系统 Download PDF

Info

Publication number
WO2018232666A1
WO2018232666A1 PCT/CN2017/089450 CN2017089450W WO2018232666A1 WO 2018232666 A1 WO2018232666 A1 WO 2018232666A1 CN 2017089450 W CN2017089450 W CN 2017089450W WO 2018232666 A1 WO2018232666 A1 WO 2018232666A1
Authority
WO
WIPO (PCT)
Prior art keywords
payment
server
user terminal
verification
password
Prior art date
Application number
PCT/CN2017/089450
Other languages
English (en)
French (fr)
Inventor
王苏娜
Original Assignee
深圳支点电子智能科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳支点电子智能科技有限公司 filed Critical 深圳支点电子智能科技有限公司
Priority to PCT/CN2017/089450 priority Critical patent/WO2018232666A1/zh
Publication of WO2018232666A1 publication Critical patent/WO2018232666A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a payment verification method and system.
  • Online payment has become a common method of people's generation, such as online shopping, credit card repayment or online transfer.
  • the main method of network payment is the payment account and the payment password verification method.
  • the payment account and password can be entered in the corresponding payment page to complete the payment. But in real life, passwords and payment accounts are easily stolen, which leads to the loss of the user's property.
  • mobile phone SMS verification has been added, but mobile phones are also likely to be stolen. It can be seen that the current payment verification security performance is not high.
  • the object of the present invention is to provide a payment verification method and system, which solves the problem that the payment verification security performance is not high.
  • an embodiment of the present invention provides a payment verification method, including:
  • the server detects the payment request of the user terminal, and identifies the target feature information of the payment merchant of the payment request, and queries, in the preset database, whether the payment merchant in the historical payment record of the user terminal has the target feature information. ;
  • the server selects a first payment verification mode, and the first payment verification mode at least applies to the payment password. Verification with the face image;
  • the server verifies the payment password and the face image, if the payment password and If the face image is verified to pass, the payment is completed, and if any of the payment password and the face image fails to pass the verification, it is determined that the payment verification fails.
  • the method further includes:
  • the server selects a second payment verification mode, and the second payment verification mode performs at least the payment password Payment verification
  • the server verifies the payment password, and if the payment password verification is passed, the payment is completed, and if the payment password verification fails, it is determined that the payment verification fails.
  • the method further includes:
  • the server sends payment prompt information to the target terminal bound by the user terminal, and the payment prompt information is used to prompt the face verification to fail, and to the Whether the target terminal sends a freeze request for freezing the payment account;
  • the server freezes the payment account according to the response message.
  • the method further includes:
  • the server sends an application information acquisition request to the user terminal;
  • the user terminal detects application information currently running by the user terminal according to the application information acquisition request, and sends the application information to the server;
  • the server determines, according to the application information, whether the user terminal currently runs an application that does not allow a child to make a payment, and if so, performs the step of the server selecting the first payment verification mode.
  • the method further includes:
  • the user terminal If the user terminal receives the verification failure message sent by the server, the user terminal hides the application icon displayed on the desktop by the application that logs in the payment account, and closes the application of the login payment account.
  • the embodiment of the invention further provides a payment verification system, comprising: a server and a user terminal, wherein:
  • the server is configured to detect a payment request of the user terminal, and identify target feature information of the payment merchant of the payment request, and query, in a preset database, whether the payment merchant in the historical payment record of the user terminal exists The target feature information;
  • the server is further configured to select a first payment verification mode, where the first payment verification mode is at least, if the target merchant information is not found in the default payment database in the historical payment record of the user terminal. Verify the payment password and face image;
  • the server is further configured to send, to the user terminal, a first payment request corresponding to the first payment verification mode;
  • the user terminal is configured to receive the first payment request, receive a payment password input by the user, and collect a face image, and send the payment password and the face image to the server;
  • the server is further configured to verify the payment password and the face image, and if the payment password and the face image are verified to pass, complete payment, if the payment password and the face image If any of the verifications fails, the payment verification fails.
  • the server is further configured to select a second payment verification mode, and the second payment verification The method at least performs payment verification on the payment password;
  • the server is further configured to send, to the user terminal, a second payment request corresponding to the second payment verification mode;
  • the user terminal is further configured to receive the second payment request, and receive a payment password input by the user, and send the payment password to the server;
  • the server is further configured to verify the payment password, and if the payment password verification is passed, complete the payment, and if the payment password verification fails, determine that the payment verification fails.
  • the server is further configured to send payment prompt information to the target terminal bound by the user terminal, where the payment prompt information is used to prompt the face Verifying failure, and sending a freeze request to the target terminal whether to freeze the payment account;
  • the target terminal is configured to receive the freeze request and display the message, and if the user receives the freeze request, send a response message for freezing the payment account to the server;
  • the server is further configured to freeze the payment account according to the response message.
  • the server is further configured to send an application information acquisition request to the user terminal;
  • the user terminal is further configured to detect application information currently running by the user terminal according to the application information acquisition request, and send the application information to the server;
  • the server is further configured to determine, according to the application information, whether the user terminal currently runs an application that does not allow a child to make a payment, and if yes, the server selects a first payment verification mode.
  • the user terminal is further configured to hide the application icon displayed on the desktop by the application that logs in the payment account, and close the login payment. Account application.
  • the server detects the payment request of the user terminal, and identifies the target feature information of the payment merchant of the payment request, and queries in the preset database whether the payment merchant in the historical payment record of the user terminal is The target feature information is present; if the target merchant does not have the target feature information in the default database in the historical database, the server selects the first payment verification mode, the first The payment verification mode verifies at least the payment password and the face image; the server sends the first payment request corresponding to the first payment verification mode to the user terminal; the user terminal receives the first payment request, and Receiving a payment password input by the user and collecting a face image, and transmitting the payment password and the face image to the server; the server verifying the payment password and the face image, if the payment If both the password and the face image are verified, the payment is completed, if the payment password and the face image have any Term verification is not passed, it is determined that the payment verification fails. This can increase the security of payment verification.
  • FIG. 1 is a schematic flowchart of a payment verification method according to an embodiment of the present invention.
  • FIG. 2 is a schematic structural diagram of a payment verification system according to an embodiment of the present invention.
  • FIG. 3 is a schematic structural diagram of another payment verification system according to an embodiment of the present invention.
  • FIG. 1 is a schematic flowchart of a payment verification method according to an embodiment of the present invention. As shown in FIG. 1
  • the server detects a payment request of the user terminal, and identifies target feature information of the payment merchant of the payment request, and queries, in a preset database, whether the payment merchant in the historical payment record of the user terminal has the target. Characteristic information
  • the server selects a first payment verification mode, where the first payment verification mode is at least Payment password and face image for verification;
  • the server sends, to the user terminal, a first payment request corresponding to the first payment verification mode.
  • the user terminal receives the first payment request, receives a payment password input by the user, and collects a face image, and sends the payment password and the face image to the server.
  • the server verifies the payment password and the face image, and if the payment password and the face image are verified to pass, completing payment, if the payment password and the face image are If any of the verifications fails, the payment verification fails.
  • the target feature information may be information such as a name, a type, or a description of the payment merchant. Through the matching of the above target feature information, it can be realized if the payment merchants who have not paid before are supported Pay for face verification to improve the security of payment verification. This can effectively prevent children from using the parent's payment account to purchase online physics, such as: virtual items.
  • the payment account may be a bank account number, or may be another communication account that stores money.
  • the method further includes:
  • the server selects a second payment verification mode, and the second payment verification mode performs at least the payment password Payment verification
  • the server verifies the payment password, and if the payment password verification is passed, the payment is completed, and if the payment password verification fails, it is determined that the payment verification fails.
  • the payment password verification mode is collected.
  • the method further includes:
  • the server sends payment prompt information to the target terminal bound by the user terminal, and the payment prompt information is used to prompt the face verification to fail, and to the Whether the target terminal sends a freeze request for freezing the payment account;
  • the server freezes the payment account according to the response message.
  • the payment account can be frozen, because the face verification does not pass and the account is not used by itself.
  • the method further includes:
  • the server sends an application information acquisition request to the user terminal;
  • the user terminal detects application information currently running by the user terminal according to the application information acquisition request, and sends the application information to the server;
  • the server determines, according to the application information, whether the user terminal currently runs an application that does not allow a child to make a payment, and if so, performs the step of the server selecting the first payment verification mode.
  • an application that is preset to not allow a child to pay in the user terminal may be implemented, and a face payment is adopted to prevent the child from using the parent payment account for payment.
  • the method further includes:
  • the user terminal If the user terminal receives the verification failure message sent by the server, the user terminal hides the application icon displayed on the desktop by the application that logs in the payment account, and closes the application of the login payment account.
  • the user terminal if the user terminal receives the verification failure message sent by the server, the user terminal hides the application icon displayed on the desktop by the application that logs in the payment account, and closes the login. Pay the account application, which can effectively protect the security of the payment account.
  • FIG. 2 is a schematic structural diagram of a payment verification system according to an embodiment of the present invention. As shown in FIG. 2, the method includes: a server 201 and a user terminal 202, where:
  • the server 201 is configured to detect a payment request of the user terminal 202, and identify target feature information of the payment merchant of the payment request, and query the collection in the historical payment record of the user terminal 202 in a preset database. Whether the merchant has the target feature information;
  • the server 201 is further configured to select a first payment verification mode, where the first payment verification mode is used to query the payment merchant in the historical payment record of the user terminal 202 in the preset database.
  • the method at least verifies the payment password and the face image;
  • the server 201 is further configured to send, to the user terminal 202, a first payment request corresponding to the first payment verification mode;
  • the user terminal 202 is configured to receive the first payment request, receive a payment password input by the user, and collect a face image, and send the payment password and the face image to the server 201;
  • the server 201 is further configured to perform verification on the payment password and the face image, and if the payment password and the face image are verified to pass, complete payment, if the payment password and the person If any of the face images fails to pass the verification, it is determined that the payment verification failed.
  • the server 201 is further configured to select a second payment verification mode, the second The payment verification method performs at least payment verification on the payment password;
  • the server 201 is further configured to send, to the user terminal 202, a second payment request corresponding to the second payment verification mode;
  • the user terminal 202 is further configured to receive the second payment request, and receive a payment password input by the user, and send the payment password to the server 201;
  • the server 201 is further configured to verify the payment password, and if the payment password verification is passed, complete the payment, and if the payment password verification fails, determine that the payment verification fails.
  • the system further includes a target terminal 203, and if the face image verification fails, the server 201 is further configured to send to the target terminal 203 bound by the user terminal 202.
  • the payment prompt information is used to prompt the face verification to fail, and send a freeze request to the target terminal 203 whether to freeze the payment account;
  • the target terminal 203 is configured to receive the freeze request and display the message, and if the user receives the freeze request, send a response message for freezing the payment account to the server 201;
  • the server 201 is further configured to freeze the payment account according to the response message.
  • the server 201 is further configured to send the application information to the user terminal 202. request;
  • the user terminal 202 is further configured to detect application information currently running by the user terminal 202 according to the application information acquisition request, and send the application information to the server 201;
  • the server 201 is further configured to determine, according to the application information, whether the user terminal 202 currently runs an application that does not allow a child to make a payment, and if so, the server 201 selects a first payment verification mode.
  • the user terminal 202 is further configured to hide the application icon displayed on the desktop by the application that logs in the payment account, and close the The application that logs in to the payment account.
  • the server detects the payment request of the user terminal, and identifies the target feature information of the payment merchant of the payment request, and queries in the preset database whether the payment merchant in the historical payment record of the user terminal is The target feature information is present; if the target merchant does not have the target feature information in the default database in the historical database, the server selects the first payment verification mode, the first The payment verification mode verifies at least the payment password and the face image; the server sends the first payment request corresponding to the first payment verification mode to the user terminal; the user terminal receives the first payment request, and Receiving a payment password input by the user and collecting a face image, and transmitting the payment password and the face image to the server; the server verifying the payment password and the face image, if the payment If both the password and the face image are verified, the payment is completed, if the payment password and the face image have any Term verification is not passed, it is determined that the payment verification fails. This can increase the security of payment verification.
  • the disclosed method and apparatus may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may be physically included separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of hardware plus software functional units.
  • the above-described integrated unit implemented in the form of a software functional unit can be stored in a computer readable storage medium.
  • the above software functional unit is stored in a storage medium and includes a plurality of instructions for causing a computer device (which may be a personal computer, a server, a network device, etc.) to execute Some steps of the transmitting and receiving method according to various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like, and the program code can be stored. Medium.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明提供一种支付验证方法和系统,该方法包括:服务器检测到用户终端的支付请求,并识别支付请求的收款商家的目标特征信息,若在预设数据库中查询用户终端的历史支付记录中的收款商家不存在目标特征信息,则服务器选择第一支付验证方式;服务器向用户终端发送第一支付验证方式对应的第一支付请求;用户终端接收第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向服务器发送支付密码和人脸图像;服务器对支付密码和人脸图像进行验证,若支付密码和人脸图像均验证通过,则完成支付,若支付密码和人脸图像中有任一项验证不通过,则确定支付验证失败。这样可以增加支付验证的安全性能。

Description

一种支付验证方法和系统 技术领域
本发明涉及通信技术领域,尤其涉及一种支付验证方法和系统。
背景技术
网络支付已经成为人们生成中常用的方式,例如:网上购物、信用卡还款或者网上转账等等。目前网络支付主要的方式是支付帐号和支付密码的验证方式,例如:用户需要在网上购买某件物品时,只要在对应的支付网页中输入支付帐号和密码就可以完成支付。但在实际生活中,密码和支付帐号是很容易被盗取的,这样导致用户的财产丢失。虽然,现在针对一些比较大金额的支付,增加了手机短信验证,但手机同样存在被盗取的可能。可见,目前支付验证安全性能不高。
发明内容
本发明的目的在于提供一种支付验证方法和系统,解决了支付验证安全性能不高的问题。
为了达到上述目的,本发明实施例提供一种支付验证方法,包括:
服务器检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
所述服务器向所述用户终端发送所述第一支付验证方式对应的第一支付请求;
所述用户终端接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;
所述服务器对所述支付密码和所述人脸图像进行验证,若所述支付密码和 所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。
优选的,所述在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息的步骤之后,所述方法还包括:
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
所述服务器向所述用户终端发送所述第二支付验证方式对应的第二支付请求;
所述用户终端接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器发送所述支付密码;
所述服务器对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
优选的,所述服务器对所述支付密码和所述人脸图像进行验证的步骤之后,所述方法还包括:
若所述人脸图像验证不通过,则所述服务器向所述用户终端绑定的目标终端发送的支付提示信息,所述支付提示信息用于提示所述人脸验证不通过,以及向所述目标终端发送是否冻结所述支付帐号的冻结请求;
所述目标终端接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器发送冻结所述支付帐号的响应消息;
所述服务器根据所述响应消息冻结所述支付帐号。
优选的,所述方法还包括:
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器向所述用户终端发送应用程序信息获取请求;
所述用户终端根据所述应用程序信息获取请求,检测所述用户终端当前运行的应用程序信息,并向所述服务器发送所述应用程序信息;
所述服务器根据所述应用程序信息判断所述用户终端当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则执行所述服务器选择第一支付验证方式的步骤。
优选的,所述方法还包括:
若所述用户终端接收所述服务器发送的验证失败消息,则所述用户终端将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
本发明实施例还提供一种支付验证系统,包括:服务器和用户终端,其中:
所述服务器,用于检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器还用于选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
所述服务器还用于向所述用户终端发送所述第一支付验证方式对应的第一支付请求;
所述用户终端,用于接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;
所述服务器还用于对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。
优选的,若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器还用于选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
所述服务器还用于向所述用户终端发送所述第二支付验证方式对应的第二支付请求;
所述用户终端还用于接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器发送所述支付密码;
所述服务器还用于对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
优选的,若所述人脸图像验证不通过,则所述服务器还用于向所述用户终端绑定的目标终端发送的支付提示信息,所述支付提示信息用于提示所述人脸 验证不通过,以及向所述目标终端发送是否冻结所述支付帐号的冻结请求;
所述目标终端,用于接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器发送冻结所述支付帐号的响应消息;
所述服务器还用于根据所述响应消息冻结所述支付帐号。
优选的,若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器还用于向所述用户终端发送应用程序信息获取请求;
所述用户终端还用于根据所述应用程序信息获取请求,检测所述用户终端当前运行的应用程序信息,并向所述服务器发送所述应用程序信息;
所述服务器还用于根据所述应用程序信息判断所述用户终端当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则所述服务器选择第一支付验证方式。
优选的,若所述用户终端接收所述服务器发送的验证失败消息,则所述用户终端还用于将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
本发明实施例中,服务器检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;所述服务器向所述用户终端发送所述第一支付验证方式对应的第一支付请求;所述用户终端接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;所述服务器对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。这样可以增加支付验证的安全性能。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要 使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本发明实施例提供的一种支付验证方法的流程示意图;
图2是本发明实施例提供的一种支付验证系统的结构示意图;
图3是本发明实施例提供的另一种支付验证系统的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
请参考图1,图1是本发明实施例提供的一种支付验证方法的流程示意图,如图1所示,包括:
101、服务器检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;
102、若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
103、所述服务器向所述用户终端发送所述第一支付验证方式对应的第一支付请求;
104、所述用户终端接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;
105、所述服务器对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。
其中,上述目标特征信息可以是收款商家的名称、类型或者描述等信息。通过上述目标特征信息的匹配可以实现若向之前没有支付的收款商家进行支 付需要进行人脸验证,以提高支付验证的安全性能。这样可以有效避免小孩拿家长的支付帐号购买网上的物理,例如:虚拟物品。其中,支付帐号可以是银行帐号,也可以是其他存储有钱财的通信帐号。
优选的,所述在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息的步骤之后,所述方法还包括:
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
所述服务器向所述用户终端发送所述第二支付验证方式对应的第二支付请求;
所述用户终端接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器发送所述支付密码;
所述服务器对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
该实施方式中,可以实现若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,才采集支付密码验证的方式。
优选的,所述服务器对所述支付密码和所述人脸图像进行验证的步骤之后,所述方法还包括:
若所述人脸图像验证不通过,则所述服务器向所述用户终端绑定的目标终端发送的支付提示信息,所述支付提示信息用于提示所述人脸验证不通过,以及向所述目标终端发送是否冻结所述支付帐号的冻结请求;
所述目标终端接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器发送冻结所述支付帐号的响应消息;
所述服务器根据所述响应消息冻结所述支付帐号。
该实施方式中,可以实现若人脸验证不通过,则可以冻结支付帐号,因为人脸验证不通过肯定不用支付帐号本人在使用。
优选的,所述方法还包括:
若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器向所述用户终端发送应用程序信息获取请求;
所述用户终端根据所述应用程序信息获取请求,检测所述用户终端当前运行的应用程序信息,并向所述服务器发送所述应用程序信息;
所述服务器根据所述应用程序信息判断所述用户终端当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则执行所述服务器选择第一支付验证方式的步骤。
该实施方式中,可以实现在所述用户终端当前运行有预设的不允许小孩进行支付的应用程序,采用人脸支付,以避免小孩使用家长支付帐号进行支付。
优选的,所述方法还包括:
若所述用户终端接收所述服务器发送的验证失败消息,则所述用户终端将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
该实施方式中,可以实现若所述用户终端接收所述服务器发送的验证失败消息,则所述用户终端将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序,这样可以有效保护支付帐号的安全。
请参考图2,图2是本发明实施例提供的一种支付验证系统的结构示意图,如图2所示,包括:服务器201和用户终端202,其中:
所述服务器201,用于检测到用户终端202的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端202的历史支付记录中的收款商家是否存在所述目标特征信息;
若在预设数据库中查询所述用户终端202的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器201还用于选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
所述服务器201还用于向所述用户终端202发送所述第一支付验证方式对应的第一支付请求;
所述用户终端202,用于接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器201发送所述支付密码和所述人脸图像;
所述服务器201还用于对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人 脸图像中有任一项验证不通过,则确定支付验证失败。
优选的,若在预设数据库中查询所述用户终端202的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器201还用于选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
所述服务器201还用于向所述用户终端202发送所述第二支付验证方式对应的第二支付请求;
所述用户终端202还用于接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器201发送所述支付密码;
所述服务器201还用于对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
优选的,如图3所示,所述系统还包括目标终端203,若所述人脸图像验证不通过,则所述服务器201还用于向所述用户终端202绑定的目标终端203发送的支付提示信息,所述支付提示信息用于提示所述人脸验证不通过,以及向所述目标终端203发送是否冻结所述支付帐号的冻结请求;
所述目标终端203,用于接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器201发送冻结所述支付帐号的响应消息;
所述服务器201还用于根据所述响应消息冻结所述支付帐号。
优选的,若在预设数据库中查询所述用户终端202的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器201还用于向所述用户终端202发送应用程序信息获取请求;
所述用户终端202还用于根据所述应用程序信息获取请求,检测所述用户终端202当前运行的应用程序信息,并向所述服务器201发送所述应用程序信息;
所述服务器201还用于根据所述应用程序信息判断所述用户终端202当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则所述服务器201选择第一支付验证方式。
优选的,若所述用户终端202接收所述服务器201发送的验证失败消息,则所述用户终端202还用于将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
本发明实施例中,服务器检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;所述服务器向所述用户终端发送所述第一支付验证方式对应的第一支付请求;所述用户终端接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;所述服务器对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。这样可以增加支付验证的安全性能。
在本申请所提供的几个实施例中,应该理解到,所揭露方法和装置,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理包括,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。
上述以软件功能单元的形式实现的集成的单元,可以存储在一个计算机可读取存储介质中。上述软件功能单元存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行 本发明各个实施例所述收发方法的部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,简称ROM)、随机存取存储器(Random Access Memory,简称RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述是本发明的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明所述原理的前提下,还可以作出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。

Claims (10)

  1. 一种支付验证方法,其特征在于,包括:
    服务器检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;
    若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
    所述服务器向所述用户终端发送所述第一支付验证方式对应的第一支付请求;
    所述用户终端接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;
    所述服务器对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。
  2. 如权利要求1所述的方法,其特征在于,所述在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息的步骤之后,所述方法还包括:
    若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
    所述服务器向所述用户终端发送所述第二支付验证方式对应的第二支付请求;
    所述用户终端接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器发送所述支付密码;
    所述服务器对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
  3. 如权利要求2所述的方法,其特征在于,所述服务器对所述支付密码和所述人脸图像进行验证的步骤之后,所述方法还包括:
    若所述人脸图像验证不通过,则所述服务器向所述用户终端绑定的目标终端发送的支付提示信息,所述支付提示信息用于提示所述人脸验证不通过,以及向所述目标终端发送是否冻结所述支付帐号的冻结请求;
    所述目标终端接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器发送冻结所述支付帐号的响应消息;
    所述服务器根据所述响应消息冻结所述支付帐号。
  4. 如权利要求1-3中任一项所述方法,其特征在于,所述方法还包括:
    若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器向所述用户终端发送应用程序信息获取请求;
    所述用户终端根据所述应用程序信息获取请求,检测所述用户终端当前运行的应用程序信息,并向所述服务器发送所述应用程序信息;
    所述服务器根据所述应用程序信息判断所述用户终端当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则执行所述服务器选择第一支付验证方式的步骤。
  5. 如权利要求1-3中任一项所述方法,其特征在于,所述方法还包括:
    若所述用户终端接收所述服务器发送的验证失败消息,则所述用户终端将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
  6. 一种支付验证系统,其特征在于,包括:服务器和用户终端,其中:
    所述服务器,用于检测到用户终端的支付请求,并识别所述支付请求的收款商家的目标特征信息,在预设数据库中查询所述用户终端的历史支付记录中的收款商家是否存在所述目标特征信息;
    若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,则所述服务器还用于选择第一支付验证方式,所述第一支付验证方式至少对支付密码和人脸图像进行验证;
    所述服务器还用于向所述用户终端发送所述第一支付验证方式对应的第一支付请求;
    所述用户终端,用于接收所述第一支付请求,并接收用户输入的支付密码和采集人脸图像,并向所述服务器发送所述支付密码和所述人脸图像;
    所述服务器还用于对所述支付密码和所述人脸图像进行验证,若所述支付密码和所述人脸图像均验证通过,则完成支付,若所述支付密码和所述人脸图像中有任一项验证不通过,则确定支付验证失败。
  7. 如权利要求6所述的系统,其特征在于,若在预设数据库中查询所述用户终端的历史支付记录中的收款商家存在所述目标特征信息,则所述服务器还用于选择第二支付验证方式,所述第二支付验证方式至少对支付密码进行支付验证;
    所述服务器还用于向所述用户终端发送所述第二支付验证方式对应的第二支付请求;
    所述用户终端还用于接收所述第二支付请求,并接收用户输入的支付密码,并向所述服务器发送所述支付密码;
    所述服务器还用于对所述支付密码进行验证,若所述支付密码验证通过,则完成支付,若所述支付密码验证不通过,则确定支付验证失败。
  8. 如权利要求7所述的系统,其特征在于,若所述人脸图像验证不通过,则所述服务器还用于向所述用户终端绑定的目标终端发送的支付提示信息,所述支付提示信息用于提示所述人脸验证不通过,以及向所述目标终端发送是否冻结所述支付帐号的冻结请求;
    所述目标终端,用于接收所述冻结请求并进行显示,若接收到用户响应所述冻结请求,则向所述服务器发送冻结所述支付帐号的响应消息;
    所述服务器还用于根据所述响应消息冻结所述支付帐号。
  9. 如权利要求6-8中任一项所述系统,其特征在于,若在预设数据库中查询所述用户终端的历史支付记录中的收款商家不存在所述目标特征信息,所述服务器还用于向所述用户终端发送应用程序信息获取请求;
    所述用户终端还用于根据所述应用程序信息获取请求,检测所述用户终端当前运行的应用程序信息,并向所述服务器发送所述应用程序信息;
    所述服务器还用于根据所述应用程序信息判断所述用户终端当前是否运行有预设的不允许小孩进行支付的应用程序,若是,则所述服务器选择第一支付验证方式。
  10. 如权利要求6-8中任一项所述系统,其特征在于,若所述用户终端接 收所述服务器发送的验证失败消息,则所述用户终端还用于将登录支付帐号的应用程序在桌面上显示的应用程序图标进行隐藏,并关闭所述登录支付帐号的应用程序。
PCT/CN2017/089450 2017-06-21 2017-06-21 一种支付验证方法和系统 WO2018232666A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/089450 WO2018232666A1 (zh) 2017-06-21 2017-06-21 一种支付验证方法和系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/089450 WO2018232666A1 (zh) 2017-06-21 2017-06-21 一种支付验证方法和系统

Publications (1)

Publication Number Publication Date
WO2018232666A1 true WO2018232666A1 (zh) 2018-12-27

Family

ID=64737487

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/089450 WO2018232666A1 (zh) 2017-06-21 2017-06-21 一种支付验证方法和系统

Country Status (1)

Country Link
WO (1) WO2018232666A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230262053A1 (en) * 2022-02-11 2023-08-17 Bank Of America Corporation Intelligent authentication mechanism for applications
WO2023173666A1 (zh) * 2022-03-18 2023-09-21 上海商汤智能科技有限公司 人脸支付方法、装置、电子设备、存储介质、程序和产品

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104504569A (zh) * 2014-12-24 2015-04-08 网易宝有限公司 一种验证方法及装置
WO2015062236A1 (en) * 2013-10-30 2015-05-07 Tencent Technology (Shenzhen) Company Limited Method, device and system for information verification
CN106067113A (zh) * 2016-05-25 2016-11-02 努比亚技术有限公司 快捷支付装置、移动终端及方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015062236A1 (en) * 2013-10-30 2015-05-07 Tencent Technology (Shenzhen) Company Limited Method, device and system for information verification
CN104504569A (zh) * 2014-12-24 2015-04-08 网易宝有限公司 一种验证方法及装置
CN106067113A (zh) * 2016-05-25 2016-11-02 努比亚技术有限公司 快捷支付装置、移动终端及方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230262053A1 (en) * 2022-02-11 2023-08-17 Bank Of America Corporation Intelligent authentication mechanism for applications
WO2023173666A1 (zh) * 2022-03-18 2023-09-21 上海商汤智能科技有限公司 人脸支付方法、装置、电子设备、存储介质、程序和产品

Similar Documents

Publication Publication Date Title
US10748147B2 (en) Adaptive authentication options
US9348896B2 (en) Dynamic network analytics system
CA2889006C (en) Dongle facilitated wireless consumer payments
US20150120559A1 (en) Enhancements to transaction processing in a secure environment
US20150170148A1 (en) Real-time transaction validity verification using behavioral and transactional metadata
JP2018527659A (ja) 安全なリアルタイムの支払取引
WO2020107233A1 (zh) 基于区块链的钱包系统及钱包使用方法、以及存储介质
WO2010053899A2 (en) Online challenge-response
CN107705128A (zh) 一种支付验证方法和系统
US10489565B2 (en) Compromise alert and reissuance
JP6707607B2 (ja) 個人クラウドプラットフォームを用いてオンラインユーザ認証を強化するシステム及び方法
WO2018232666A1 (zh) 一种支付验证方法和系统
TWI695288B (zh) 實人認證方法及裝置
KR100968941B1 (ko) Otp를 이용한 금융거래 시스템
US11037146B2 (en) Managing product returns associated with a user device
CN105719130B (zh) 支付验证方法、装置及系统
US20230206246A1 (en) Systems for Securing Transactions Based on Merchant Trust Score
EP4163854A1 (en) Systems and methods for conducting remote user authentication
US9443233B1 (en) Payment using a fractal image
CA3156390A1 (en) Systems and methods for providing in-person status to a user device
WO2018232667A1 (zh) 一种网络支付方法和系统
US10672054B2 (en) System and method for purchase recommendation for wallet linked user
Kumar et al. Authentication on Payment gateway using Face Recognition System
CA2982061A1 (en) Managing product returns associated with a user device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17914425

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 15/05/2020)

122 Ep: pct application non-entry in european phase

Ref document number: 17914425

Country of ref document: EP

Kind code of ref document: A1