WO2020233154A1 - 交易处理方法、装置、设备、介质及系统 - Google Patents

交易处理方法、装置、设备、介质及系统 Download PDF

Info

Publication number
WO2020233154A1
WO2020233154A1 PCT/CN2020/071998 CN2020071998W WO2020233154A1 WO 2020233154 A1 WO2020233154 A1 WO 2020233154A1 CN 2020071998 W CN2020071998 W CN 2020071998W WO 2020233154 A1 WO2020233154 A1 WO 2020233154A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
transaction
user
biometric information
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/071998
Other languages
English (en)
French (fr)
Inventor
侯晓楠
戚跃民
何朔
万四爽
邱雪涛
杨阳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to US17/269,351 priority Critical patent/US20210312465A1/en
Publication of WO2020233154A1 publication Critical patent/WO2020233154A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/325Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4018Transaction verification using the card verification value [CVV] associated with the card
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/405Establishing or using transaction specific rules
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • G06V40/16Human faces, e.g. facial parts, sketches or expressions

Definitions

  • This application relates to the field of mobile payment technology, in particular to a transaction processing method, device, equipment, medium and system.
  • the issuing bank In the era of card-based payment, the issuing bank is in a dominant position in the payment market, able to authorize transactions and control the flow of user funds.
  • the embodiments of the present application provide a transaction processing method, device, equipment, medium, and system, which can improve the security of user property.
  • an embodiment of the present application provides a transaction processing method, the method includes:
  • an embodiment of the present application provides a transaction processing method, the method includes:
  • biometric information determine the user's card information to be fed back
  • the card information is fed back to the terminal device so that the terminal device sends a transaction request to the authorization server corresponding to the card information, receives the transaction authorization verification result fed back by the authorization server in response to the transaction request, and performs the transaction according to the transaction authorization verification result.
  • an embodiment of the application provides a transaction processing method, the method includes:
  • the transaction request includes the user's biometric information and a transaction authorization verification method based on the biometric information;
  • the transaction authorization verification result is fed back to the terminal device that sends the transaction request, so that the terminal device performs the transaction according to the transaction authorization verification result.
  • an embodiment of the present application provides a transaction processing device, which includes:
  • the biometric information collection module is used to collect the user's biometric information
  • the biometric information sending module is used to send the biometric information to the target biometric information server, so that the target biometric information server determines the user's card information to be fed back according to the biometric information;
  • the card information receiving module is used to receive the user's card information fed back by the target biological information server;
  • the transaction request sending module is used to send the transaction request to the authorization server corresponding to the card information, so that the authorization server can authorize and verify the transaction corresponding to the transaction request;
  • the transaction authorization verification result receiving module is used to receive the transaction authorization verification result fed back by the authorization server;
  • the transaction module is used to conduct transactions according to the transaction authorization verification result.
  • an embodiment of the present application provides a transaction processing device, which includes:
  • the biometric information acquisition module is used to obtain the user's biometric information
  • the card information determination module is used to determine the user's card information to be fed back according to the biometric information
  • the card information feedback module is used to feed back card information to the terminal device so that the terminal device sends a transaction request to the authorization server corresponding to the card information, receives the transaction authorization verification result fed back by the authorization server in response to the transaction request, and conducts transactions based on the transaction authorization verification result .
  • an embodiment of the present application provides a transaction processing device, which includes:
  • the transaction request acquisition module is used to acquire the transaction request, the transaction request includes the user's biometric information and a transaction authorization verification method based on the biometric information;
  • the biometric information acquisition module is used to obtain the registered biometric information of the user required by the transaction verification method from the biometric information server;
  • the authorization verification module is used to authorize and verify the transaction corresponding to the transaction request based on the registered biometric information and the biometric information included in the transaction request, and obtain the transaction authorization verification result;
  • the authorization verification result sending module is used to feed back the transaction authorization verification result to the terminal device that sends the transaction request, so that the terminal device performs the transaction according to the transaction authorization verification result.
  • an embodiment of the present application provides a transaction processing device, including a processor, a memory, and a computer program stored on the memory and running on the processor.
  • the computer program is executed by the processor to realize the The steps of the transaction processing method.
  • an embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program.
  • the computer program is executed by a processor, the steps of the transaction processing method provided in the embodiment of the present application are implemented.
  • an embodiment of the present application provides a transaction processing system, which includes a target biological information server and multiple authorization servers;
  • the target biometric information server is used to obtain the user's biometric information; determine the user's card information to be fed back based on the biometric information; feed back the card information to the terminal device; send the user's registered information required by the transaction authorization verification method to the authorization server Biometric information;
  • the authorization server is used to obtain the transaction request.
  • the transaction request includes the user's biometric information and the transaction authorization verification method based on the biometric information; obtains the user's registered biometric information required by the transaction verification method from the target biometric information server; Register the biometric information and the biometric information included in the transaction request, perform authorization verification on the transaction corresponding to the transaction request, and obtain the transaction authorization verification result; feedback the transaction authorization verification result to the terminal device that sent the transaction request, so that the terminal device can verify according to the transaction authorization The result is traded.
  • the terminal device sends the collected user’s biometric information to the target biological information server.
  • the target biological information server determines the user’s card information to be fed back, and The determined card information is fed back to the terminal device, and the terminal device sends a transaction request to the authorization server.
  • the authorization server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device, and the terminal device according to the transaction authorization verification result Trading.
  • the authorization verification of the transaction corresponding to the transaction request through the authorization server can improve the security of the user's property.
  • Figure 1 shows a schematic structural diagram of a transaction processing system provided by an embodiment of the present application
  • FIG. 2 shows a schematic diagram of the architecture of user registration based on face information provided by an embodiment of the present application
  • FIG. 3 shows an overall architecture diagram of a transaction process based on face information provided by an embodiment of the present application
  • FIG. 4 shows a schematic flowchart of a transaction processing method applied to a terminal device according to an embodiment of the present application
  • FIG. 5 shows a schematic flowchart of a transaction processing method applied to a target biological information server according to an embodiment of the present application
  • FIG. 6 shows a schematic flowchart of a transaction processing method applied to an authorization server according to an embodiment of the present application
  • FIG. 7 shows a schematic structural diagram of a transaction processing apparatus applied to terminal equipment according to an embodiment of the present application
  • FIG. 8 shows a schematic structural diagram of a transaction processing device applied to a target biological information server according to an embodiment of the present application
  • FIG. 9 shows a schematic structural diagram of a transaction processing device applied to an authorization server according to an embodiment of the present application.
  • Fig. 10 shows a structural diagram of an exemplary hardware architecture of a computing device capable of implementing the transaction processing method and apparatus according to the embodiments of the present application.
  • the embodiments of the present application provide a transaction processing method, device, equipment, medium, and system to improve the security of the user's property.
  • Fig. 1 shows a schematic structural diagram of a transaction processing system provided by an embodiment of the present application.
  • the transaction processing system may include: a target biological information server and multiple authorization servers. among them,
  • the target biometric information server is used to obtain the user's biometric information; determine the user's card information to be fed back based on the biometric information; feed back the card information to the terminal device; send the user's registered information required by the transaction authorization verification method to the authorization server Biometric information.
  • the authorization server is used to obtain the transaction request.
  • the transaction request includes the user's biometric information and the transaction authorization verification method based on the biometric information; obtains the user's registered biometric information required by the transaction verification method from the target biometric information server; Register the biometric information and the biometric information included in the transaction request, perform authorization verification on the transaction corresponding to the transaction request, and obtain the transaction authorization verification result; feedback the transaction authorization verification result to the terminal device that sent the transaction request, so that the terminal device can verify according to the transaction authorization The result is traded.
  • the authorization server can perform authorization verification on the transaction corresponding to the transaction request, which can improve the security of the user's property.
  • the transaction request includes the information of both parties to the transaction and the transaction amount information. Therefore, the authorized server can also grasp the flow of user funds and supervise user funds.
  • FIG. 1 shows N authorization servers, which are authorization server 1, authorization server 2, ..., authorization server N, respectively. If the transaction is based on a bank card, the above N authorization servers may be servers of different banks.
  • authorization server 1 is a China Merchants Bank server
  • authorization server 2 is a China Construction Bank server
  • authorization server N is an agricultural bank server.
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • the following describes the transaction process by taking the biometric information as face information as an example.
  • the terminal device collects the user's face information, and sends the collected face information to the target biological information server.
  • the target biological information server determines the user's card information to be fed back according to the received face information.
  • the terminal device sends a transaction request to the construction bank server.
  • the China Construction Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server there may be more than one user's card information to be fed back determined by the target biological information server.
  • the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server feeds back the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the terminal device can send a transaction request to the authorization server corresponding to the default card information.
  • the terminal device sends a transaction request to the China Merchants Bank server.
  • the China Merchants Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server there may be more than one user's card information to be fed back determined by the target biological information server. It is assumed that the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server feeds back the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the user can select the bank card used for the transaction, assuming that the bank card selected by the user for the transaction is the Agricultural Bank bank card.
  • the terminal device can send a transaction request to the Agricultural Bank of China server.
  • the Agricultural Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the terminal device When the target biological information server determines that there may be more than one user's card information to be fed back, the terminal device sends a transaction request to the authorization server corresponding to the card information selected by the user from the card information fed back from the target biological information server.
  • the issuance of the bank card of Bank X is Bank X
  • the bank card information of Bank X corresponds to the Bank X server
  • transactions based on the bank card of Bank X need to be authorized by the Bank X server.
  • the target biometric information server determines the user's card information to be fed back according to the received biometric information, and needs to store the user's biometric information and the user's card information in advance, and establish an association relationship between the two. Furthermore, when determining the card information of the user to be fed back, the card information having an association relationship with the collected biometric information may be determined as the card information of the user to be fed back. It is understandable that the user's card information can be only one or more than one.
  • the registered biometric information matching the collected biometric information can be searched; the card information that has an association relationship with the found registered biometric information is determined as the user's card information to be fed back.
  • the user can register through a card issuing bank application (Application Program, APP), a transaction clearing institution APP, or a third-party APP, and obtain the user's biometric information when the user registers.
  • a card issuing bank application Application Program, APP
  • APP Application Program
  • transaction clearing institution APP transaction clearing institution APP
  • third-party APP third-party APP
  • the target biometric information server can directly obtain the user's bank card information, and then establish the association relationship between the user's biometric information and the user's bank card information.
  • the target biometric information server When a user registers through a third-party APP, the user can enter the bank card information.
  • the target biometric information server After the target biometric information server obtains the user's biometric information and bank card information, it needs to verify the bank card information to verify whether the bank card information matches the user
  • Correspondence means verifying whether the cardholder of the bank card corresponding to the bank card information is the user. After verifying that the bank card information corresponds to the user, an association relationship between the user's biometric information and the user's bank card information is established.
  • the target biometric information server can send the user's ID number or mobile phone number to the authorization server, and the authorization server searches for the corresponding ID or mobile phone number according to the user's ID number or mobile phone number Then, the bank card information found is fed back to the target biological information server, and the target biological information server establishes the association relationship between the user’s biological information and the user’s bank card information. It is understandable that the user needs to keep the ID number or mobile phone number when opening a bank card, and the user's bank card information can be found through the ID number or mobile phone number saved when the user opens the card.
  • the aforementioned card information may be original card information that has not been marked.
  • the card token Token information can be generated by using a payment token service (Token Service Provider, TSP).
  • TSP Token Service Provider
  • the payment tokenization service TSP is a basic security service for digital payment, which can be used by banks, payment institutions, and industry organizations. The payment provides security.
  • the payment marking service TSP replaces the traditional bank card number with a specific payment marking Token, which effectively reduces the risk of card information leakage at the merchant and acceptance agency side, and reduces transaction fraud.
  • the target biological information server can search for the bank card token Token information corresponding to the bank card information associated with the user according to the user’s biological characteristic information, and then feed back the found bank card token Token information corresponding to the bank card information associated with the user to the terminal device .
  • the bank card token Token information may include: bank information and information with part of the bank card number.
  • the token information of a bank card is: China Construction Bank, 6666 **** **** 1234. Among them, part of the bank number in the Token information of the bank card is replaced by *.
  • the target biometric information server searches for the bank card token Token information corresponding to the bank card information associated with the user according to the received biometric information, and needs to store the user's biometric information and the bank associated with the user in advance
  • the bank card corresponding to the card information marks the Token information and establishes an association between the two.
  • the user can register through the card issuing bank APP, the transaction clearing institution (such as the card organization) APP or the third-party APP, and obtain the user's biometric information when the user registers.
  • the transaction clearing institution such as the card organization
  • the third-party APP the third-party APP
  • the target biometric information server can directly obtain the user's bank card information, and then use the payment marking service TSP to generate the bank card token Token information corresponding to the user's bank card information, and then Establish the association relationship between the user's biometric information and the bank card token information corresponding to the bank card information associated with the user.
  • the target biometric information server When a user registers through a third-party APP, the user can enter the bank card information.
  • the target biometric information server After the target biometric information server obtains the user's biometric information and bank card information, it needs to verify the bank card information to verify whether the bank card information matches the user Correspondence means verifying whether the cardholder of the bank card corresponding to the bank card information is the user.
  • the payment marking service TSP After verifying that the bank card information corresponds to the user, use the payment marking service TSP to generate the bank card token Token information corresponding to the user's bank card information, and then establish the bank card corresponding to the user's biometric information and the bank card information associated with the user Mark the association relationship of Token information.
  • the target biometric information server can send the user's ID number or mobile phone number to the authorization server, and the authorization server searches for the corresponding ID or mobile phone number according to the user's ID number or mobile phone number Then, the bank card information found is fed back to the target biological information server, and then the payment marking service TSP is used to generate the bank card marking Token information corresponding to the user’s bank card information, and the user’s biological information is associated with the user.
  • the association relationship of the bank card token Token information corresponding to the bank card information It is understandable that the user needs to keep the ID number or mobile phone number when opening the card at the bank, and the user's card information can be found through the ID number or mobile phone number saved when the user opens the card.
  • the target biological information server can feed back the bank card token Token information corresponding to the bank card information associated with the user to the terminal device, which can prevent the user's card information from leaking and improve the security of the user's property.
  • the target biological information server finds the bank card information associated with the user based on the received biological information, it can use the payment marking service TSP to generate a temporary bank card corresponding to the user’s bank card information
  • the token information is marked, and the token information of the temporary bank card is fed back to the terminal device.
  • the Token information of the temporary bank card is only valid for a period of time, such as 3 minutes.
  • the temporary bank card to mark the Token information
  • the leakage of the user's card information can be prevented and the security of the user's property can be improved.
  • the authorization server needs to verify the transaction using a transaction authorization verification method.
  • a transaction authorization verification method For example, China Construction Bank needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the transaction password of the bank card; China Merchants Bank needs the transaction password of the bank card or the user's biometric information (such as face information, fingerprint information) Etc.); Agricultural Bank of China needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the user's biometric information (such as face information, fingerprint information, etc.).
  • the terminal device can also send the transaction verification capability supported by the terminal device to the target biological information server.
  • the target biological information server determines the user’s card information to be fed back according to the transaction verification capability and the transaction authorization verification method required by the authorization server, and then Card information that is associated with the user and meets the transaction verification capabilities supported by the terminal device is fed back to the terminal device.
  • the transaction authorization verification method of China Construction Bank is SMS verification code verification or fingerprint verification
  • the transaction authorization verification method of China Merchants Bank is face verification or SMS verification code verification
  • the transaction authorization verification method of Agricultural Bank is face verification or fingerprint verification.
  • the terminal device has a camera instead of a fingerprint collector, that is, the terminal device has the face verification capability but not the fingerprint verification capability.
  • the target biological information server determines the user's bank card information to be fed back as: China Merchants Bank bank card information and Agricultural Bank bank card information according to the transaction verification capabilities supported by the terminal device and the transaction authorization verification method required by the authorization server.
  • each authorization server may store the required transaction authorization verification method in the target biological information server.
  • the authorization server may also send the priority of the transaction authorization verification method to the target biometric information server for storage, such as: face verification priority Higher than fingerprint verification, fingerprint verification priority is higher than mobile phone verification code, mobile phone verification code priority is higher than payment password and so on.
  • the terminal device may also send the user's identification information to the target biological information server, and the target biological information server searches for the registered biological information corresponding to the identification information and determines the received biological information and Whether the found registered biometric information belongs to the same user, if it belongs to the same user, the card information corresponding to the found registered biometric information is determined as the card information of the user to be fed back.
  • the user's identification information can quickly retrieve the biometric information corresponding to the user's identification information, and then use the biometric information collected by matching and retrieve the biometric characteristics corresponding to the user's identification information The information is sufficient, and there is no need to compare the biometric information with multiple pre-registered biometric information one by one, which can increase the speed of determining the card information, thereby increasing the efficiency of transaction processing.
  • the terminal device may also perform live body detection on the user.
  • the living body detection is used to determine whether the collected biometric information comes from a living body.
  • the user may be required to blink his eyes, turn his head, open his mouth, and so on.
  • some functions of the target biological information server can be implemented by another server (such as an intermediate biological information server), such as the function of searching for registered biological information matching the collected biological information.
  • the terminal device can send the biometric information to the intermediate biometric information server, and the intermediate biometric information server searches for the registered biometric information matching the collected biometric information, and then compares the identity information corresponding to the found registered biometric information Send to the target biological information server, and the target biological information server determines the user's card information to be fed back according to the received identity information.
  • the identity information includes but is not limited to: the user's mobile phone number, the user's ID number, and so on.
  • the role of the intermediate biological information server may be assumed by a transaction clearing institution or a third-party company, or may be assumed by a merchant or a payment service provider or gateway company serving it.
  • the role of the target biological information server can be assumed by the transaction clearing agency.
  • the authorization server When the authorization server receives the transaction request sent by the terminal device including the user's biometric information and the transaction authorization verification method based on the biometric information, it obtains the user's registered biometric information required by the transaction verification method from the target biometric information server; The registered biometric information and the biometric information included in the transaction request are authorized to verify the transaction corresponding to the transaction request to obtain the transaction authorization verification result; the transaction authorization verification result is fed back to the terminal device that sent the transaction request, and the terminal device is authorized according to the transaction Verify the result for trading.
  • the terminal device A initiates a transaction request to the authorization server, and the transaction request includes the face information a of the user X and the transaction authorization verification method that needs to use the face for authorization verification. It is understandable that the transaction request also includes the card information for the transaction.
  • the authorization server obtains the registered face information b corresponding to the card information from the target biological information server; uses the registered face information b and face information a to authorize the transaction; if the face information b and face information a If the face information of the same person is the same, the authorization is passed; if the face information b and the face information a are the face information of different people, the authorization is not passed.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • Fig. 2 shows a schematic structural diagram of user registration based on face information provided by an embodiment of the present application.
  • the user chooses to register on the APP of the terminal device (card issuing bank APP, transaction clearing institution APP or third-party APP).
  • the terminal device collects the user's face information, and uploads the collected face information to the organization to which the APP belongs.
  • the APP-affiliated organization obtains the card token Token information corresponding to the user from the payment token service TSP. Send the user's face information and the user's corresponding card token Token information to the target biological information server.
  • the target biological information server stores the user's face information and the user's card token Token information, and establishes an association relationship between the user's face information and the user's card token Token information.
  • the authorization server sends the required transaction authorization verification method to the target biological information server.
  • the target biological information server stores the transaction authorization verification method required by the authorization server.
  • the terminal devices used for user registration include, but are not limited to, mobile phones, tablet computers, notebook computers, palmtop computers, and vehicle-mounted terminals.
  • Fig. 3 shows an overall architecture diagram of a transaction process based on face information provided by an embodiment of the present application.
  • the terminal device collects the user's face information, sends the user's face information to the target biological information server, and sends the transaction verification capabilities supported by the terminal device to the target biological information server.
  • the target biological information server determines the user’s bank card information to be fed back based on the received face information, the transaction verification capabilities supported by the terminal device, and the transaction authorization verification method required by the authorization server, and obtains the determined information from the payment marking service TSP. 1.
  • the temporary bank card token Token information corresponding to the bank card information is fed back to the terminal device.
  • the terminal device displays the temporary bank card token Token information.
  • the user selects the bank card and transaction authorization verification method that the exchange needs to use based on the displayed temporary bank card token Token information. Assume that the transaction authorization verification method selected by the user is face verification.
  • the terminal device sends a transaction request to the authorization server through the acquirer and the card organization.
  • the transaction request may include temporary bank card token Token information, face information, and face verification mode.
  • the authorization server obtains the registered face information corresponding to the temporary bank card token Token information from the target biological information server, and then authorizes the transaction based on the obtained face information.
  • the corresponding transaction authorization verification result that passed the authorization verification is fed back to the terminal device through the card organization and the acquiring institution.
  • the terminal device performs a transaction according to the authorization verification through the corresponding transaction authorization verification result.
  • the authorization verification fails, the corresponding transaction authorization verification result that does not pass the authorization verification is fed back to the terminal device through the card organization and the acquiring institution.
  • the terminal device stops the transaction according to the authorization verification result that does not pass the corresponding transaction authorization verification result.
  • the terminal devices used for user transactions include, but are not limited to, mobile phones, tablet computers, notebook computers, handheld computers, offline merchant devices, and automatic teller machines (ATM).
  • ATM automatic teller machines
  • the transactions in the embodiments of this application include but are not limited to offline payment to merchants, online payment to merchants, ATM withdrawals, online transfers, and ATM transfers.
  • a user pays to a merchant offline
  • the terminal device collects the user's facial information and performs a live detection of the user.
  • the terminal device uploads the user's mobile phone number, face information, and transaction verification capabilities supported by the terminal device to the target biological information server.
  • the target biological information server determines the user's bank card information to be fed back based on the face information and the transaction verification capabilities supported by the terminal device.
  • the terminal device collects the user's facial information and performs a live detection on the user.
  • the terminal device uploads the user's face information and the transaction verification capabilities supported by the terminal device to the target biological information server.
  • the target biological information server determines the user's bank card information to be fed back based on the face information and the transaction verification capabilities supported by the terminal device.
  • the terminal equipment collects the user's face information and detects the user's body.
  • the terminal device uploads the user's mobile phone number, face information, and transaction verification capabilities supported by the terminal device to the target biological information server.
  • the target biological information server determines the user's bank card information to be fed back based on the face information and the transaction verification capabilities supported by the terminal device.
  • the target biological information server returns the determined bank card information of the user to be fed back to the terminal device.
  • the terminal device sends a transaction request to the authorization server, where the authorization server may be the authorization server corresponding to the bank card selected by the user for the transaction.
  • the transaction request may include the result of the living body detection, the face verification method and the user's face information.
  • the authorization server obtains the user's face information from the target biological information server based on the face verification method, and decides based on the user's face information obtained from the target biological information server and the user's face information included in the transaction request and the living body detection result included in the transaction request Whether to perform authorization verification on the transaction corresponding to the transaction request, and feedback the authorization verification result to the terminal device.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • the living body detection step can be skipped with the consent of the merchant.
  • the terminal device detects the user's body, collects the user's facial information, and uploads the terminal device number, facial information, and transaction verification capabilities supported by the terminal device to the target biological information server.
  • the target biological information server detects the user's bank card information in the face information database corresponding to the terminal device number. If the user's bank card information is not retrieved, the user is required to enter a mobile phone number.
  • the target biological information server determines the user's bank card information to be fed back based on the face information and the transaction verification capabilities supported by the terminal device.
  • the target biological information server returns the determined bank card information of the user to be fed back to the terminal device.
  • the terminal device sends a transaction request to the authorization server, where the authorization server may be the authorization server corresponding to the bank card selected by the user for the transaction.
  • the transaction request may include the result of the living body detection, the face verification method and the user's face information.
  • the authorization server obtains the user's face information from the target biological information server based on the face verification method, and decides based on the user's face information obtained from the target biological information server and the user's face information included in the transaction request and the living body detection result included in the transaction request Whether to perform authorization verification on the transaction corresponding to the transaction request, and feedback the authorization verification result to the terminal device.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • ATM collects user's facial information and performs live detection on the user.
  • ATM uploads the face information to the target biometric information server.
  • the target biological information server determines the user's bank card information to be fed back based on the face information.
  • the target biological information server returns the bank card information of the determined user to be fed back to the ATM.
  • the ATM sends a transaction request to the authorization server, where the authorization server may be the authorization server corresponding to the bank card selected by the user for the transaction.
  • the transaction request may include the result of the living body detection, the face verification method and the user's face information.
  • the authorization server obtains the user's face information from the target biological information server based on the face verification method, and decides based on the user's face information obtained from the target biological information server and the user's face information included in the transaction request and the living body detection result included in the transaction request Whether to perform authorization verification on the transaction corresponding to the transaction request, and feedback the authorization verification result to the ATM.
  • ATM conducts transactions based on the result of transaction authorization verification.
  • the target biological information server after the target biological information server returns the bank card information of the user determined to be fed back to the ATM, the user can select the bank card for the transaction. After the bank card is selected, the user can directly enter the bank card Transaction password.
  • the ATM sends the transaction request containing the transaction password and the result of the biopsy to the authorization server corresponding to the bank card selected by the user for the transaction.
  • the authorization server corresponding to the bank card for which the user selects the transaction determines whether to perform authorization verification on the transaction (withdrawal transaction or transfer transaction) corresponding to the transaction request based on the biometric test result and the transaction password verification result, and feeds back the authorization verification result to the terminal device.
  • ATM conducts transactions based on the result of transaction authorization verification.
  • the aforementioned target biological information server may include: a first server and a second server.
  • the first server may be responsible for storage of biometric information and retrieval of card information.
  • the second server may be responsible for the application and management of user accounts, the routing of biometric information, the management and query of verification elements of the issuing bank, etc.
  • the terminal device collects the user's facial information, and uploads the user's facial information and the transaction verification capabilities supported by the terminal device to the first server.
  • the first server searches according to the face information, obtains user identity information, and uploads the user identity information and the transaction verification capabilities supported by the terminal device to the second server.
  • the second server determines the user's bank card information to be fed back according to the user identity information, the transaction verification capabilities supported by the terminal device, and the transaction authorization verification method required by the issuing bank, and obtains the bank card Token information corresponding to the determined bank card information, And return to the terminal device through the first server.
  • the terminal device initiates a transaction request to the authorization server, and the transaction request includes a face verification method.
  • the authorization server obtains the face information from the first server, performs authorization verification on the transaction corresponding to the transaction request based on the obtained face information, and then feeds back the authorization verification result to the terminal device.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • the card may also be a transportation card (bus card) or a membership card with payment function.
  • the target biological information server in the embodiment of the present application may be a biological payment service provider (Bio-payment Service Provider, BPSP).
  • BPSP Bio-payment Service Provider
  • FIG. 4 shows a schematic flowchart of a transaction processing method applied to a terminal device according to an embodiment of the present application.
  • the transaction processing method applied to the terminal device may include:
  • S401 Collect biometric information of the user.
  • S402 Send the biometric information to the target biometric information server, so that the target biometric information server determines the card information of the user to be fed back according to the biometric information.
  • S403 Receive the user's card information fed back by the target biological information server.
  • S404 Send the transaction request to the authorization server corresponding to the card information, so that the authorization server performs authorization verification on the transaction corresponding to the transaction request.
  • the biometric information in the embodiment of the present application may include one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • the following describes the transaction processing method for the terminal device by taking the biometric information as the face information as an example.
  • the terminal device collects the user's face information, and sends the collected face information to the target biological information server.
  • the target biological information server determines the user's card information to be fed back according to the received face information.
  • the terminal device sends a transaction request to the construction bank server.
  • the China Construction Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server determines that there may be more than one user's card information to be fed back. It is assumed that the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server feeds back the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the terminal device can send a transaction request to the authorization server corresponding to the default card information. Assuming that the default card information is China Merchants Bank card information, the terminal device sends a transaction request to the China Merchants Bank server.
  • the China Merchants Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server determines that there may be more than one user's card information to be fed back. It is assumed that the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server returns the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the user can select the bank card used for the transaction, assuming that the bank card selected by the user for the transaction is the Agricultural Bank bank card.
  • the terminal device can send a transaction request to the Agricultural Bank of China server.
  • the Agricultural Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the transaction processing method applied to the terminal device provided by the embodiment of the present application can perform authorization verification on the transaction corresponding to the transaction request through the authorization server, and can improve the security of the user's property.
  • sending the transaction request to the authorization server corresponding to the card information may include: sending the transaction request to the authorization server corresponding to the card information selected by the user from the card information fed back from the target biological information server.
  • the user selects the bank card used for the transaction, assuming that the bank card used for the transaction selected by the user is an Agricultural Bank bank card. Then the terminal device can send a transaction request to the Agricultural Bank of China server. The Agricultural Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device. The terminal device performs a transaction according to the result of the transaction authorization verification.
  • the transaction processing method applied to the terminal device provided in the embodiment of the present application may further include:
  • the authorization server needs to verify the transaction using a transaction authorization verification method.
  • a transaction authorization verification method For example, China Construction Bank needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the transaction password of the bank card; China Merchants Bank needs the transaction password of the bank card or the user's biometric information (such as face information, fingerprint information) Etc.); Agricultural Bank of China needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the user's biometric information (such as face information, fingerprint information, etc.).
  • the terminal device can also send the transaction verification capability supported by the terminal device to the target biological information server.
  • the target biological information server determines the user’s card information to be fed back according to the transaction verification capability and the transaction authorization verification method required by the authorization server, and then Card information that is associated with the user and meets the transaction verification capabilities supported by the terminal device is fed back to the terminal device.
  • the transaction authorization verification method of China Construction Bank is SMS verification code verification or fingerprint verification
  • the transaction authorization verification method of China Merchants Bank is face verification or SMS verification code
  • the transaction authorization verification method of Agricultural Bank is face verification or fingerprint verification.
  • the terminal device has a camera instead of a fingerprint collector, that is, the terminal device has the face verification capability but not the fingerprint verification capability.
  • the target biological information server determines the user's bank card information to be fed back as: China Merchants Bank bank card information and Agricultural Bank bank card information according to the transaction verification capabilities supported by the terminal device and the transaction authorization verification method required by the authorization server.
  • the transaction processing method applied to the terminal device provided in the embodiment of the present application may further include:
  • the target biometric information server searches for the registered biometric information corresponding to the identification information and determines whether the received biometric information and the found registered biometric information belong to the same user, If it belongs to the same user, the found card information corresponding to the registered biometric information is determined as the card information of the user to be fed back.
  • the user's identification information can quickly retrieve the biometric information corresponding to the user's identification information, and then use the biometric information collected by matching and retrieve the biometric characteristics corresponding to the user's identification information The information is sufficient, and there is no need to compare the biometric information with multiple pre-registered biometric information one by one, which can increase the speed of determining the card information, thereby increasing the efficiency of transaction processing.
  • the transaction processing method applied to the terminal device provided in the embodiment of the present application may further include:
  • the transaction request includes the live-body detection result.
  • the living body detection is used to determine whether the collected biometric information comes from a living body.
  • the user may be required to blink his eyes, turn his head, open his mouth, and so on.
  • sending biometric information to the target biometric information server may include:
  • the intermediate biometric information server finds the registered biometric information that matches the biometric information, and sends the identity information corresponding to the found registered biometric information to the target biometric information server, So that the target biological information server determines the user's card information to be fed back according to the received identity information.
  • some functions of the target biological information server can be implemented by another server (such as an intermediate biological information server), such as the function of searching for registered biological information matching the collected biological information.
  • the terminal device can send the biometric information to the intermediate biometric information server, and the intermediate biometric information server searches for the registered biometric information that matches the collected biometric information, and then finds the identity information corresponding to the registered biometric information.
  • the aforementioned card information may be original card information that has not been marked.
  • the above-mentioned card information can be marked to generate card marking Token information.
  • the target biological information server can feed back the bank card token Token information corresponding to the bank card information associated with the user to the terminal device, which can prevent the user's card information from leaking and improve the security of the user's property.
  • the embodiment of the present application also provides a transaction processing method applied to the target biological information server.
  • Fig. 5 shows a schematic flowchart of a transaction processing method applied to a target biological information server provided by an embodiment of the present application.
  • the transaction processing method applied to the target biological information server may include:
  • S501 Acquire biometric information of the user.
  • S502 Determine the card information of the user to be fed back according to the biometric information.
  • S503 Feed back the card information to the terminal device, so that the terminal device sends a transaction request to the authorization server corresponding to the card information, receives the transaction authorization verification result fed back by the authorization server in response to the transaction request, and performs the transaction according to the transaction authorization verification result.
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • the following describes the transaction processing method for the terminal device by taking the biometric information as the face information as an example.
  • the terminal device collects the user's face information, and sends the collected face information to the target biological information server.
  • the target biological information server receives the face information sent by the terminal device; according to the received face information, determines the user's card information to be fed back.
  • the target biometric information server determines the user's card information to be fed back according to the received biometric information, and needs to store the user's biometric information and the user's card information in advance, and establish an association relationship between the two. It is understandable that the user's card information can be only one or more than one.
  • the transaction processing method applied to the target biological information server provided by the embodiment of the present application may further include: obtaining the biometric information of the user for registration and one or more card information of the user; The relationship between biometric information and one or more card information of the user.
  • the card information associated with the registered biometric information that matches the biometric information may be determined as the card information of the user to be fed back.
  • the user can register through the card issuing bank APP, the transaction clearing institution APP or the third-party APP, and obtain the user's biometric information when the user registers.
  • the target biometric information server can directly obtain the user's bank card information, and then establish the association relationship between the user's biometric information and the user's bank card information.
  • the target biometric information server When a user registers through a third-party APP, the user can enter the bank card information.
  • the target biometric information server After the target biometric information server obtains the user's biometric information and bank card information, it needs to verify the bank card information to verify whether the bank card information matches the user
  • Correspondence means verifying whether the cardholder of the bank card corresponding to the bank card information is the user. After verifying that the bank card information corresponds to the user, an association relationship between the user's biometric information and the user's bank card information is established.
  • the target biometric information server can send the user's ID number or mobile phone number to the authorization server, and the authorization server searches for the corresponding ID or mobile phone number according to the user's ID number or mobile phone number Then, the bank card information found is fed back to the target biological information server, and the target biological information server establishes the association relationship between the user’s biological information and the user’s bank card information. It is understandable that the user needs to keep the ID number or mobile phone number when opening a bank card, and the user's bank card information can be found through the ID number or mobile phone number saved when the user opens the card.
  • the transaction processing method applied to the target biological information server provided by the embodiment of the present application may further include: obtaining a transaction verification capability supported by the terminal device.
  • determining the card information of the user to be fed back may include: determining the card information of the user to be fed back according to the biometric information, the transaction verification capability, and the transaction authorization verification method required by the authorization server.
  • the authorization server needs to verify the transaction using a transaction authorization verification method.
  • a transaction authorization verification method For example, China Construction Bank needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the transaction password of the bank card; China Merchants Bank needs the transaction password of the bank card or the user's biometric information (such as face information, fingerprint information) Etc.); Agricultural Bank of China needs the SMS verification code received by the mobile phone number reserved when the bank card is opened or the user's biometric information (such as face information, fingerprint information, etc.).
  • the terminal device can also send the transaction verification capability supported by the terminal device to the target biological information server.
  • the target biological information server determines the user's bank card information to be fed back according to the transaction verification capability and the transaction authorization verification method required by the authorization server, and then The card information that is associated with the user and meets the transaction verification capabilities supported by the terminal device is fed back to the terminal device.
  • the transaction authorization verification method of China Construction Bank is SMS verification code verification or fingerprint verification
  • the transaction authorization verification method of China Merchants Bank is face verification or SMS verification code verification
  • the transaction authorization verification method of Agricultural Bank is face verification or fingerprint verification.
  • the terminal device has a camera instead of a fingerprint collector, that is, the terminal device has the face verification capability but not the fingerprint verification capability.
  • the target biological information server determines the user's bank card information to be fed back as: China Merchants Bank bank card information and Agricultural Bank bank card information according to the transaction verification capabilities supported by the terminal device and the transaction authorization verification method required by the authorization server.
  • the transaction processing method applied to the target biological information server provided in the embodiment of the present application may further include: obtaining user identification information.
  • determining the card information of the user to be fed back may include: searching for the registered biometric information corresponding to the identification information; judging whether the received biometric information and the found registered biometric information belong to the same user; If it belongs to the same user, the card information of the user to be fed back is determined according to the registered biometric information found.
  • the user's identification information can quickly retrieve the biometric information corresponding to the user's identification information, and then use the biometric information collected by matching and retrieve the biometric characteristics corresponding to the user's identification information The information is sufficient, and there is no need to compare the biometric information with multiple pre-registered biometric information one by one, which can increase the speed of determining the card information, thereby increasing the efficiency of transaction processing.
  • the target biological information server in order to prevent the user's card information from leaking.
  • the target biological information server can search for the bank card token Token information corresponding to the bank card information associated with the user according to the user’s biological characteristic information, and then feed back the found bank card token Token information corresponding to the bank card information associated with the user to the terminal device .
  • the target biometric information server searches for the bank card token Token information corresponding to the bank card information associated with the user according to the received biometric information, and needs to store the user's biometric information and the bank associated with the user in advance
  • the bank card corresponding to the card information marks the Token information and establishes an association between the two.
  • the user can register through the card issuing bank APP, the transaction clearing institution APP or the third-party APP, and obtain the user's biometric information when the user registers.
  • the target biometric information server can directly obtain the user's bank card information, and then use the payment marking service TSP to generate the bank card token Token information corresponding to the user's bank card information, and then Establish the association relationship between the user's biometric information and the bank card token information corresponding to the bank card information associated with the user.
  • the target biometric information server When a user registers through a third-party APP, the user can enter the bank card information.
  • the target biometric information server After the target biometric information server obtains the user's biometric information and bank card information, it needs to verify the bank card information to verify whether the bank card information matches the user Correspondence means verifying whether the cardholder of the bank card corresponding to the bank card information is the user.
  • the payment marking service TSP After verifying that the bank card information corresponds to the user, use the payment marking service TSP to generate the bank card token Token information corresponding to the user's bank card information, and then establish the bank card corresponding to the user's biometric information and the bank card information associated with the user Mark the association relationship of Token information.
  • the target biometric information server can send the user's ID number or mobile phone number to the authorization server, and the authorization server searches for the corresponding ID or mobile phone number according to the user's ID number or mobile phone number Then, the bank card information found is fed back to the target biological information server, and then the payment marking service TSP is used to generate the bank card marking Token information corresponding to the user’s bank card information, and the user’s biological information is associated with the user.
  • the association relationship of the bank card token Token information corresponding to the bank card information It is understandable that the user needs to keep the ID number or mobile phone number when opening the card at the bank, and the user's card information can be found through the ID number or mobile phone number saved when the user opens the card.
  • the target biological information server can feed back the bank card token Token information corresponding to the bank card information associated with the user to the terminal device, which can prevent the user's card information from leaking and improve the security of the user's property.
  • the card information may include: temporary card marking Token information after marking processing.
  • the target biometric information server finds the bank card information associated with the user based on the received biometric information, and can use the payment marking service TSP to mark the bank card information to generate a contact with the user.
  • the temporary bank card token Token information corresponding to the bank card information is fed back to the terminal device.
  • the Token information of the temporary bank card is only valid for a period of time, such as 3 minutes.
  • the temporary bank card to mark the Token information
  • the leakage of the user's card information can be prevented and the security of the user's property can be improved.
  • the terminal device sends a transaction request to the construction bank server.
  • the China Construction Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server determines that there may be more than one user's card information to be fed back. It is assumed that the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server feeds back the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the terminal device can send a transaction request to the authorization server corresponding to the default card information. Assuming that the default card information is China Merchants Bank card information, the terminal device sends a transaction request to the China Merchants Bank server.
  • the China Merchants Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the target biological information server determines that there may be more than one user's card information to be fed back. It is assumed that the determined card information are: Construction Bank Card Information, China Merchants Bank Card Information, and Agricultural Bank Card Information.
  • the target biological information server feeds back the determined card information (construction bank card information, China Merchants bank card information, and agricultural bank card information) to the terminal device.
  • the user can select the bank card used for the transaction, assuming that the bank card selected by the user for the transaction is the Agricultural Bank bank card.
  • the terminal device can send a transaction request to the Agricultural Bank of China server.
  • the Agricultural Bank server performs authorization verification on the transaction corresponding to the transaction request, and feeds back the transaction authorization verification result to the terminal device.
  • the terminal device performs a transaction according to the result of the transaction authorization verification.
  • the transaction processing method applied to the target biometric information server provided by the embodiment of the present application may further include: sending registered biometric information that matches the biometric information to the authorization server, so that the authorization server can The registered biometric information performs authorization verification on the transaction corresponding to the transaction request.
  • the authorization server When the authorization server receives the transaction request sent by the terminal device including the user's biometric information and the transaction authorization verification method based on the biometric information, it obtains the user's registered biometric information required by the transaction verification method from the biometric information server; Register the biometric information and the biometric information included in the transaction request, perform authorization verification on the transaction corresponding to the transaction request, and obtain the transaction authorization verification result; feedback the transaction authorization verification result to the terminal device that sent the transaction request, and the terminal device verifies according to the transaction authorization The result is traded.
  • the terminal device A initiates a transaction request to the authorization server.
  • the transaction request includes the face information a of the user X and the transaction authorization verification method that needs to use the face for authorization verification. It is understandable that the transaction request also includes the card information for the transaction.
  • the authorization server obtains the registered face information b corresponding to the card information from the target biological information server; uses the registered face information b and face information a to authorize the transaction; if the face information b and face information a If the face information of the same person is the same, the authorization is passed; if the face information b and the face information a are the face information of different people, the authorization is not passed.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • acquiring the user's biometric information may include: receiving the identity information sent by the intermediate biological information server, where the identity information is found by the intermediate biological information server and corresponds to the acquired biological information The identity information corresponding to the registered biometric information.
  • determining the card information of the user to be fed back may include: determining the card information of the user to be fed back according to the received identity information.
  • some functions of the target biological information server can be implemented by another server (such as an intermediate biological information server), such as the function of searching for registered biological information matching the collected biological information.
  • the terminal device can send the biometric information to the intermediate biometric information server.
  • the intermediate biometric information server searches for the registered biometric information that matches the collected biometric information, and then sends the corresponding identity information found to the target biometric information server.
  • the biological information server determines the user's card information to be fed back according to the received identity information.
  • the identity information includes but is not limited to: the user's mobile phone number, the user's ID number, and so on.
  • the embodiment of the present application also provides a transaction processing method applied to the authorization server.
  • Fig. 6 shows a schematic flowchart of a transaction processing method applied to an authorization server provided by an embodiment of the present application.
  • the transaction processing method applied to the authorization server may include:
  • the transaction request includes the user's biometric information and a transaction authorization verification method based on the biometric information.
  • S602 Obtain the registered biometric information of the user required by the transaction verification mode from the target biometric information server.
  • S603 According to the registered biometric information and the biometric information included in the transaction request, perform authorization verification on the transaction corresponding to the transaction request, and obtain a transaction authorization verification result.
  • S604 Feed back the transaction authorization verification result to the terminal device that sent the transaction request, so that the terminal device performs the transaction according to the transaction authorization verification result.
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • the authorization server When the authorization server receives the transaction request sent by the terminal device including the user's biometric information and the transaction authorization verification method based on the biometric information, it obtains the user's registered biometric information required by the transaction verification method from the target biometric information server; The registered biometric information and the biometric information included in the transaction request are authorized to verify the transaction corresponding to the transaction request to obtain the transaction authorization verification result; the transaction authorization verification result is fed back to the terminal device that sent the transaction request, and the terminal device is authorized according to the transaction Verify the result to trade.
  • the terminal device A initiates a transaction request to the authorization server, and the transaction request includes the face information a of the user X and the transaction authorization verification method that needs to use the face for authorization verification. It is understandable that the transaction request also includes the card information for the transaction.
  • the authorization server obtains the registered face information b corresponding to the card information from the target biological information server; uses the registered face information b and face information a to authorize the transaction; if the face information b and face information a If the face information of the same person is the same, the authorization is passed; if the face information b and the face information a are the face information of different people, the authorization is not passed.
  • the terminal device conducts the transaction according to the transaction authorization verification result.
  • the transaction request includes: the result of the living body detection for the user.
  • the authorization server performs authorization verification on the transaction corresponding to the transaction request based on the result of the living body detection, the registered biometric information and the biometric information included in the transaction request, and obtains the transaction authorization verification result.
  • the authorization server can perform authorization verification on the transaction corresponding to the transaction request, which can improve the security of the user's property.
  • an embodiment of the present application also provides a transaction processing device.
  • FIG. 7 shows a schematic structural diagram of a transaction processing apparatus applied to a terminal device according to an embodiment of the present application.
  • the transaction processing device applied to the terminal equipment may include:
  • the biometric information collection module 701 is used to collect user's biometric information.
  • the biometric information sending module 702 is configured to send biometric information to a target biometric information server, so that the target biometric information server determines the user's card information to be fed back according to the biometric information.
  • the card information receiving module 703 is configured to receive the user's card information fed back by the target biological information server.
  • the transaction request sending module 704 is configured to send a transaction request to the authorization server corresponding to the card information, so that the authorization server performs authorization verification on the transaction corresponding to the transaction request.
  • the transaction authorization verification result receiving module 705 is configured to receive the transaction authorization verification result fed back by the authorization server.
  • the transaction module 706 is used to perform transactions according to the transaction authorization verification result.
  • the transaction processing apparatus applied to terminal equipment provided in the embodiment of the present application may further include:
  • the transaction verification capability sending module is used to send the transaction verification capability supported by the terminal device that collects biometric information to the target biometric information server, so that the target biometric information server determines the pending feedback based on the transaction verification capability and the transaction authorization verification method required by the authorization server Card information of the user.
  • the transaction processing apparatus applied to terminal equipment provided in the embodiment of the present application may further include:
  • the identification information sending module is used to send the user's identification information to the target biological information server, so that the target biological information server finds the registered biological information corresponding to the identification information and determines the received biological information and the found registered biological information Whether the characteristic information belongs to the same user, if it belongs to the same user, the card information corresponding to the found registered biometric information is determined as the card information of the user to be fed back.
  • the transaction processing apparatus applied to terminal equipment provided in the embodiment of the present application may further include:
  • the living body detection module is used to perform living body detection on the user; wherein the transaction request includes the result of the living body detection.
  • the biometric information sending module 702 may be specifically used for:
  • the intermediate biometric information server finds the registered biometric information that matches the biometric information, and sends the identity information corresponding to the found registered biometric information to the target biometric information server, So that the target biological information server determines the user's card information to be fed back according to the received identity information.
  • the card information includes:
  • the original card information that has not been marked or the Token information of the card that has been marked is the original card information that has not been marked or the Token information of the card that has been marked.
  • the transaction request sending module 704 can be specifically used for:
  • the transaction request includes the transaction authorization verification method selected by the user.
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • FIG. 8 shows a schematic structural diagram of a transaction processing device applied to a target biological information server according to an embodiment of the present application.
  • the transaction processing device applied to the target biological information server may include:
  • the biometric information acquisition module 801 is used to obtain the user's biometric information.
  • the card information determining module 802 is used to determine the user's card information to be fed back according to the biometric information.
  • the card information feedback module 803 is used to feed back card information to the terminal device so that the terminal device sends a transaction request to the authorization server corresponding to the card information, receives the transaction authorization verification result fed back by the authorization server in response to the transaction request, and performs processing according to the transaction authorization verification result transaction.
  • the biometric information acquisition module 801 may be specifically used to receive the user's biometric information sent by the terminal device.
  • the card information determining module 802 may be specifically used to: search for registered biometric information that matches the biometric information; according to the found registered biometric information, determine the card information of the user to be fed back.
  • the biometric information acquisition module 801 can be specifically used to: receive the user's identity information sent by the intermediate biological information server, where the identity information is the information corresponding to the biological information found by the intermediate biological information server. The identity information corresponding to the registered biometric information.
  • the card information determining module 802 may be specifically used to determine the user's card information to be fed back according to the received identity information.
  • the transaction processing device applied to the target biological information server provided in the embodiment of the present application may further include:
  • the transaction verification capability acquisition module is used to acquire the transaction verification capability supported by the terminal device.
  • the card information determining module 802 can be specifically used for:
  • the transaction processing device applied to the target biological information server provided in the embodiment of the present application may further include:
  • the identification information acquisition module is used to acquire user identification information.
  • the card information determining module 802 can be specifically used for:
  • the card information includes:
  • the temporary card that has been marked is marked with Token information.
  • the card information determining module 802 can be specifically used for:
  • the card information associated with the registered biometric information that matches the biometric information is determined as the user's card information to be fed back.
  • the transaction processing device applied to the target biological information server provided in the embodiment of the present application may further include:
  • the association relationship establishment module is used to obtain the biometric information of the user for registration and one or more card information of the user; to establish the association between the biometric information of the user for registration and one or more card information of the user relationship.
  • the transaction processing device applied to the target biological information server provided in the embodiment of the present application may further include:
  • the registered biometric information sending module is used to send the registered biometric information matching the biometric information to the authorization server, so that the authorization server can authorize and verify the transaction corresponding to the transaction request based on the registered biometric information.
  • the biometric information includes one or more of the following items: face information, fingerprint information, voiceprint information, iris information, and palmprint information.
  • Fig. 9 shows a schematic structural diagram of a transaction processing device applied to an authorization server provided by an embodiment of the present application.
  • the transaction processing device applied to the authorization server may include:
  • the transaction request acquisition module 901 is configured to acquire a transaction request, the transaction request including the user's biometric information and a transaction authorization verification method based on the biometric information.
  • the biometric information obtaining module 902 is used to obtain the registered biometric information of the user required by the transaction verification mode from the target biometric information server.
  • the authorization verification module 903 is configured to perform authorization verification on the transaction corresponding to the transaction request according to the registered biometric information and the biometric information included in the transaction request, and obtain a transaction authorization verification result.
  • the authorization verification result sending module 904 is configured to feed back the transaction authorization verification result to the terminal device that sends the transaction request, so that the terminal device performs a transaction according to the transaction authorization verification result.
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information and palmprint information.
  • the transaction request includes: the result of the living body detection for the user.
  • Fig. 10 shows a structural diagram of an exemplary hardware architecture of a computing device capable of implementing the transaction processing method and apparatus according to the embodiments of the present application.
  • the computing device 100 includes an input device 101, an input interface 102, a central processing unit 103, a memory 104, an output interface 105, and an output device 106.
  • the input interface 102, the central processing unit 103, the memory 104, and the output interface 105 are connected to each other through the bus 110
  • the input device 101 and the output device 106 are connected to the bus 110 through the input interface 102 and the output interface 105, respectively, and then to the computing device 100
  • the other components are connected.
  • the input device 101 receives input information from the outside, and transmits the input information to the central processing unit 103 through the input interface 102; the central processing unit 103 processes the input information based on computer executable instructions stored in the memory 104 to generate output Information, the output information is temporarily or permanently stored in the memory 104, and then the output information is transmitted to the output device 106 through the output interface 105; the output device 106 outputs the output information to the outside of the computing device 100 for the user to use.
  • the computing device shown in FIG. 10 can also be implemented as a transaction processing device.
  • the transaction processing device can include: a memory storing computer-executable instructions; and a processor that executes computer-executable instructions.
  • the transaction processing method and device provided in the embodiments of the present application can be implemented.
  • the embodiments of the present application also provide a computer-readable storage medium on which computer program instructions are stored; when the computer program instructions are executed by a processor, the transaction processing method provided in the embodiments of the present application is implemented.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Multimedia (AREA)
  • Human Computer Interaction (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Health & Medical Sciences (AREA)
  • Oral & Maxillofacial Surgery (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本申请实施例公开了一种交易处理方法、装置、设备、介质及系统。该方法包括:采集用户的生物特征信息;发送生物特征信息至目标生物信息服务器,以使目标生物信息服务器根据生物特征信息确定待反馈的用户的卡片信息;接收目标生物信息服务器反馈的用户的卡片信息;发送交易请求至卡片信息对应的授权服务器,以使授权服务器对交易请求对应的交易进行授权验证;接收授权服务器反馈的交易授权验证结果;根据交易授权验证结果进行交易。本申请实施例的交易处理方法、装置、设备、介质及系统,通过授权服务器对交易请求对应的交易进行授权验证,能够提高用户财产的安全性。

Description

交易处理方法、装置、设备、介质及系统
相关申请的交叉引用
本申请要求享有于2019年05月20日提交的名称为“交易处理方法、装置、设备、介质及系统”的中国专利申请第201910417482.3号的优先权,该申请的全部内容通过引用并入本文中。
技术领域
本申请涉及移动支付技术领域,尤其涉及一种交易处理方法、装置、设备、介质及系统。
背景技术
在卡基支付时代,发卡行处于支付市场的主导地位,能够对交易进行授权,掌握用户资金的流向。
但在手机支付模式下,无需发卡行进行授权,即可进行交易,用户财产安全性低,且发卡行难以掌握用户资金流向,不利于资金监管。
发明内容
本申请实施例提供一种交易处理方法、装置、设备、介质及系统,能够提高用户财产的安全性。
第一方面,本申请实施例提供了一种交易处理方法,方法包括:
采集用户的生物特征信息;
发送生物特征信息至目标生物信息服务器,以使目标生物信息服务器根据生物特征信息确定待反馈的用户的卡片信息;
接收目标生物信息服务器反馈的用户的卡片信息;
发送交易请求至卡片信息对应的授权服务器,以使授权服务器对交易请求对应的交易进行授权验证;
接收授权服务器反馈的交易授权验证结果;
根据交易授权验证结果进行交易。
第二方面,本申请实施例提供了一种交易处理方法,方法包括:
获取用户的生物特征信息;
根据生物特征信息,确定待反馈的用户的卡片信息;
反馈卡片信息至终端设备,以使终端设备向卡片信息对应的授权服务器发送交易请求,接收授权服务器响应于交易请求反馈的交易授权验证结果,根据交易授权验证结果进行交易。
第三方面,本申请实施例提供了一种交易处理方法,方法包括:
获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式;
从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;
根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;
向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
第四方面,本申请实施例提供了一种交易处理装置,装置包括:
生物特征信息采集模块,用于采集用户的生物特征信息;
生物特征信息发送模块,用于发送生物特征信息至目标生物信息服务器,以使目标生物信息服务器根据生物特征信息确定待反馈的用户的卡片信息;
卡片信息接收模块,用于接收目标生物信息服务器反馈的用户的卡片信息;
交易请求发送模块,用于发送交易请求至卡片信息对应的授权服务器,以使授权服务器对交易请求对应的交易进行授权验证;
交易授权验证结果接收模块,用于接收授权服务器反馈的交易授权验证结果;
交易模块,用于根据交易授权验证结果进行交易。
第五方面,本申请实施例提供了一种交易处理装置,装置包括:
生物特征信息获取模块,用于获取用户的生物特征信息;
卡片信息确定模块,用于根据生物特征信息,确定待反馈的用户的卡片信息;
卡片信息反馈模块,用于反馈卡片信息至终端设备,以使终端设备向卡片信息对应的授权服务器发送交易请求,接收授权服务器响应于交易请求反馈的交易授权验证结果,根据交易授权验证结果进行交易。
第六方面,本申请实施例提供了一种交易处理装置,装置包括:
交易请求获取模块,用于获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式;
生物特征信息获取模块,用于从生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;
授权验证模块,用于根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;
授权验证结果发送模块,用于向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
第六方面,本申请实施例提供了一种交易处理设备,包括处理器、存储器及存储在存储器上并可在处理器上运行的计算机程序,计算机程序被处理器执行时实现本申请实施例提供的交易处理方法的步骤。
第七方面,本申请实施例提供了一种计算机可读存储介质,计算机可读存储介质上存储计算机程序,计算机程序被处理器执行时实现本申请实施例提供的交易处理方法的步骤。
第八方面,本申请实施例提供了一种交易处理系统,系统包括:目标生物信息服务器和多个授权服务器;
目标生物信息服务器,用于获取用户的生物特征信息;根据生物特征信息,确定待反馈的用户的卡片信息;反馈卡片信息至终端设备;向授权服务器发送交易授权验证方式所要求的用户的已注册生物特征信息;
授权服务器,用于获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式;从目标生物信息服务器获取交 易验证方式所要求的用户的已注册生物特征信息;根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
根据本申请实施例的交易处理方法、装置、设备、介质及系统,终端设备向目标生物信息服务器发送所采集到的用户的生物特征信息,目标生物信息服务器确定待反馈的用户的卡片信息,将所确定的卡片信息反馈至终端设备,终端设备向授权服务器发送交易请求,授权服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备,终端设备根据交易授权验证结果进行交易。通过授权服务器对交易请求对应的交易进行授权验证,能够提高用户财产的安全性。
附图说明
为了更清楚地说明本申请实施例的技术方案,下面将对本申请实施例中所需要使用的附图作简单地介绍,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1示出了本申请实施例提供的交易处理系统的结构示意图;
图2示出了本申请实施例提供的基于人脸信息的用户注册的架构示意图;
图3示出了本申请实施例提供的基于人脸信息的交易过程的整体架构图;
图4示出了本申请实施例提供的应用于终端设备的交易处理方法的流程示意图;
图5示出了本申请实施例提供的应用于目标生物信息服务器的交易处理方法的流程示意图;
图6示出了本申请实施例提供的应用于授权服务器的交易处理方法的流程示意图;
图7示出了本申请实施例提供的应用于终端设备的交易处理装置的结构示意图;
图8示出了本申请实施例提供的应用于目标生物信息服务器的交易处理装置的结构示意图;
图9示出了本申请实施例提供的应用于授权服务器的交易处理装置的结构示意图;
图10示出了能够实现根据本申请实施例的交易处理方法及装置的计算设备的示例性硬件架构的结构图。
具体实施方式
下面结合附图和实施例对本申请的实施方式作进一步详细描述。以下实施例的详细描述和附图用于示例性地说明本申请的原理,但不能用来限制本申请的范围,即本申请不限于所描述的实施例。
为了解决现有技术问题,本申请实施例提供一种交易处理方法、装置、设备、介质及系统,来提高用户财产的安全性。下面首先对本申请实施例提供的交易处理系统进行说明。
如图1所示,图1示出了本申请实施例提供的交易处理系统的结构示意图。交易处理系统可以包括:目标生物信息服务器和多个授权服务器。其中,
目标生物信息服务器,用于获取用户的生物特征信息;根据生物特征信息,确定待反馈的用户的卡片信息;反馈卡片信息至终端设备;向授权服务器发送交易授权验证方式所要求的用户的已注册生物特征信息。
授权服务器,用于获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式;从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
根据本申请实施例提供的交易处理系统,授权服务器能够对交易请求对应的交易进行授权验证,能够提高用户财产的安全性。
通常交易请求中包括交易双方信息以及交易金额信息。因此,授权服 务器还能够掌握用户资金流向和对用户资金进行监管。
图1示出了N个授权服务器,分别为授权服务器1、授权服务器2、……、授权服务器N。若基于银行卡进行交易,则上述N个授权服务器可以分别为不同银行的服务器,比如,授权服务器1为招商银行服务器、授权服务器2为建设银行服务器、授权服务器N为农业银行服务器。
本申请实施例中的生物特征信息可以包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
下面以生物特征信息为人脸信息为例对交易过程进行说明。
终端设备采集用户的人脸信息,将所采集到的人脸信息发送至目标生物信息服务器。
目标生物信息服务器根据接收到的人脸信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,目标生物信息服务器确定出的待反馈的用户的卡片信息可能仅有1个,假设该卡片信息为建设银行卡信息。则终端设备向建设银行服务器发送交易请求。建设银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定出的待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端设备反馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,终端设备可以向默认的卡片信息对应的授权服务器发送交易请求。假设默认的卡片信息为招商银行卡信息,则终端设备向招商银行服务器发送交易请求。招商银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定出的待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端 设备反馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,用户可以选择用于交易的银行卡,假设用户所选择的用于交易的银行卡为农业银行银行卡。则终端设备可以向农业银行服务器发送交易请求。农业银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
当目标生物信息服务器确定出待反馈的用户的卡片信息可能不止1个时,终端设备向用户从目标生物信息服务器反馈的卡片信息中所选择的卡片信息对应的授权服务器发送交易请求。
可以理解的是,X银行的银行卡的发卡行为X银行,X银行的银行卡信息与X银行服务器对应,基于X银行的银行卡的交易需要X银行服务器授权。
可以理解的是,目标生物信息服务器根据接收到的生物特征信息,确定待反馈的用户的卡片信息,需要预先存储用户的生物特征信息和用户的卡片信息,并建立二者的关联关系。进而在确定待反馈的用户的卡片信息时,可以将与采集到的生物特征信息具有关联关系的卡片信息,确定为待反馈的用户的卡片信息。可以理解的是,用户的卡片信息可以仅有一个,也可以有多个。
具体的,可以查找与采集到的生物特征信息匹配的已注册生物特征信息;将与查找到的已注册生物特征信息具有关联关系的卡片信息,确定为待反馈的用户的卡片信息。
在本申请的一个实施例中,用户可以通过发卡行应用程序(Application Program,APP)、交易清算机构APP或第三方APP进行注册,在用户进行注册时获得用户的生物特征信息。
当用户通过发卡行APP或交易清算机构APP进行注册时,目标生物信息服务器可以直接获得用户的银行卡信息,进而建立用户的生物特征信息与用户的银行卡信息的关联关系。
当用户通过第三方APP进行注册时,用户可以输入银行卡信息,目标生物信息服务器在获得用户的生物特征信息和银行卡信息后,需要对银行 卡信息验证,验证该银行卡信息是否与该用户对应,即验证该银行卡信息对应的银行卡的持卡人是否为该用户。当验证该银行卡信息与该用户对应后,建立用户的生物特征信息与用户的银行卡信息的关联关系。
当用户通过第三方APP进行注册时,目标生物信息服务器可以将用户的身份证号或手机号发送授权服务器,授权服务器根据用户的身份证号或手机号查找与用户的身份证号或手机号对应的银行卡信息,进而将查找到的银行卡信息反馈给目标生物信息服务器,进而目标生物信息服务器建立用户的生物特征信息与用户的银行卡信息的关联关系。可以理解是,用户在银行开卡时,需要留存身份证号或手机号,通过用户开卡时留存的身份证号或手机号,可以查找到用户的银行卡信息。
在本申请的一个实施例中,上述卡片信息可以为未经过标记处理的卡片原始信息。
在本申请的一个实施例中,为了防止用户的卡片信息泄露。可以对上述卡片信息进行标记处理,生成卡片标记Token信息。在本申请的一个实施例中,卡片标记Token信息可以是利用支付标记服务(Token Service Provider,TSP)生成的,支付标记化服务TSP是数字支付基础安全服务,能为银行、支付机构、行业机构的支付提供安全保障。支付标记服务TSP用特定的支付标记Token替代传统的银行卡号,有效降低了商户、受理机构侧发生的卡片信息泄露风险,减少交易欺诈。目标生物信息服务器可以根据用户的生物特征信息,查找与用户关联的银行卡信息对应的银行卡标记Token信息,进而向终端设备反馈查找到的与用户关联的银行卡信息对应的银行卡标记Token信息。示例性的,银行卡标记Token信息可以包括:银行信息和带有部分银行卡号的信息。比如,一个银行卡标记Token信息为:建设银行,6666 **** **** 1234。其中,该银行卡标记Token信息中的部分银行号使用*代替。
在本申请的一个实施例中,目标生物信息服务器根据接收到的生物特征信息,查找与用户关联的银行卡信息对应的银行卡标记Token信息,需要预先存储用户的生物特征信息和用户关联的银行卡信息对应的银行卡标记Token信息,并建立二者的关联关系。
在本申请的一个实施例中,用户可以通过发卡行APP、交易清算机构(比如卡组织)APP或第三方APP进行注册,在用户进行注册时获得用户的生物特征信息。
当用户通过发卡行APP或交易清算机构APP进行注册时,目标生物信息服务器可以直接获得用户的银行卡信息,进而利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,进而建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。
当用户通过第三方APP进行注册时,用户可以输入银行卡信息,目标生物信息服务器在获得用户的生物特征信息和银行卡信息后,需要对银行卡信息验证,验证该银行卡信息是否与该用户对应,即验证该银行卡信息对应的银行卡的持卡人是否为该用户。当验证该银行卡信息与该用户对应后,利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,进而建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。
当用户通过第三方APP进行注册时,目标生物信息服务器可以将用户的身份证号或手机号发送授权服务器,授权服务器根据用户的身份证号或手机号查找与用户的身份证号或手机号对应的银行卡信息,进而将查找到的银行卡信息反馈给目标生物信息服务器,进而利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。可以理解是,用户在银行开卡时,需要留存身份证号或手机号,通过用户开卡时留存的身份证号或手机号,可以查找到用户的卡片信息。
通过本申请实施例,目标生物信息服务器可以向终端设备反馈与用户关联的银行卡信息对应的银行卡标记Token信息,能够防止用户的卡片信息泄露,提高用户财产的安全性。
在本申请的一个实施例中,目标生物信息服务器根据接收到的生物特征信息,查找到与用户关联的银行卡信息后,可以利用支付标记服务TSP生成与用户的银行卡信息对应的临时银行卡标记Token信息,将该临时银 行卡标记Token信息反馈给终端设备。该临时银行卡标记Token信息仅在一段时间内有效,比如3分钟。
通过本申请实施例,通过使用临时银行卡标记Token信息,能够防止用户的卡片信息泄露,提高用户财产的安全性。
在本申请的一个实施例中,授权服务器需要利用交易授权验证方式对交易进行验证。比如,建设银行需要银行卡开卡时预留的手机号码接收到的短信验证码或银行卡的交易密码;招商银行需要银行卡的交易密码或用户的生物特征信息(比如人脸信息、指纹信息等等);农业银行需要银行卡开卡时预留的手机号码接收到的短信验证码或用户的生物特征信息(比如人脸信息、指纹信息等等)。基于此,终端设备还可以向目标生物信息服务器发送终端设备支持的交易验证能力,目标生物信息服务器根据交易验证能力以及授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息,进而将与用户关联的、且满足终端设备支持的交易验证能力的卡片信息反馈至终端设备。
示例性的,假设用户拥有三张银行的银行卡。其中,一张建设银行银行卡,一张招商银行银行卡,一张农业银行银行卡。其中,建设银行的交易授权验证方式为短信验证码验证或指纹验证;招商银行的交易授权验证方式为人脸验证或短信验证码验证;农业银行的交易授权验证方式为人脸验证或指纹验证。终端设备具有摄像头,而不具有指纹采集器,即终端设备具备人脸验证能力,而不具有指纹验证能力。则目标生物信息服务器根据终端设备支持的交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的银行卡信息为:招行银行银行卡信息和农业银行银行卡信息。
在本申请的一个实施例中,各个授权服务器可以将其要求的交易授权验证方式存储在目标生物信息服务器。
在本申请的一个实施例中,授权服务器要求的交易授权验证方式可能有多个,授权服务器还可以将交易授权验证方式的优先级发送给目标生物信息服务器进行存储,比如:人脸验证优先级高于指纹验证,指纹验证优先级高于手机验证码,手机验证码优先级高于支付密码等等。
在本申请的一个实施例中,终端设备还可以将用户的标识信息发送至目标生物信息服务器,目标生物信息服务器查找与该标识信息对应的已注册生物特征信息并判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户,若属于同一用户,则将查找到的已注册生物特征信息对应的卡片信息,确定为待反馈的用户的卡片信息。
相比于生物特征信息匹配,通过用户的标识信息,能快速检索到与用户的标识信息对应的生物特征信息,进而利用匹配采集到的生物特征信息和检索到与用户的标识信息对应的生物特征信息即可,无需利用生物特征信息与预先注册的多个生物特征信息进行逐个比对,能够提高卡片信息的确定速度,进而提高交易处理效率。
在本申请的一个实施例中,终端设备还可以对用户进行活体检测。其中,活体检测用于判断采集到的生物特征信息是否来源于活体。在活体检测时,可以要求用户眨眼睛、转头、张嘴等等。
通过活体检测,能够防止其他用户利用用户的照片盗刷用户的银行卡,提高用户财产的安全性。
在本申请的一个实施例中,目标生物信息服务器的某些功能可以由另一服务器(比如中间生物信息服务器)实现,比如查找与采集到的生物特征信息匹配的已注册生物特征信息的功能。基于此,终端设备可以发送生物特征信息至中间生物信息服务器,中间生物信息服务器查找与采集到的生物特征信息匹配的已注册生物特征信息,进而将查找到的已注册生物特征信息对应的身份信息发送至目标生物信息服务器,目标生物信息服务器根据接收到的身份信息确定待反馈的用户的卡片信息。在本申请的一个实施例中,身份信息包括但不限于:用户的手机号、用户的身份证号等等。
在本申请的一个实施例中,中间生物信息服务器这个角色可以由交易清算机构或第三方公司承担,也可以由商户或为其服务的支付服务提供商或网关公司承担。目标生物信息服务器这个角色可以由交易清算机构承担。
当授权服务器接收到终端设备发送包括用户的生物特征信息和基于生物特征信息的交易授权验证方式的交易请求后,从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;根据已注册生物特 征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;将交易授权验证结果反馈至发送交易请求的终端设备反馈,终端设备根据交易授权验证结果进行交易。
示例性的,假设终端设备A向授权服务器发起交易请求,该交易请求中包括用户X的人脸信息a和需要利用人脸进行授权验证的交易授权验证方式。可以理解的是,该交易请求中还包括进行交易的卡片信息。授权服务器从目标生物信息服务器获取到与该卡片信息对应的已注册人脸信息b;利用已注册人脸信息b和人脸信息a对交易进行授权验证;若人脸信息b和人脸信息a为同一人的人脸信息,则授权通过;若人脸信息b和人脸信息a为不同人的人脸信息,则授权不通过。终端设备根据交易授权验证结果进行交易。
图2示出了本申请实施例提供的基于人脸信息的用户注册的架构示意图。
用户在终端设备的APP(发卡行APP、交易清算机构APP或第三方APP)上选择注册。终端设备采集用户的人脸信息,将采集到的人脸信息上传至APP所属机构。
APP所属机构从支付标记服务TSP获取与用户对应的卡片标记Token信息。将用户的人脸信息和用户对应的卡片标记Token信息发送至目标生物信息服务器。
目标生物信息服务器存储用户的人脸信息和用户的卡片标记Token信息,并建立用户的人脸信息和用户的卡片标记Token信息的关联关系。
授权服务器将其要求的交易授权验证方式发送至目标生物信息服务器。
目标生物信息服务器存储授权服务器要求的交易授权验证方式。
在本申请实施例中,用户注册所使用的终端设备包括但不限于手机、平板电脑、笔记本电脑、掌上电脑和车载终端等。
图3示出了本申请实施例提供的基于人脸信息的交易过程的整体架构图。
终端设备采集用户的人脸信息,将用户的人脸信息发送至目标生物信息服务器,并将终端设备支持的交易验证能力发送至目标生物信息服务器。
目标生物信息服务器基于接收到的人脸信息、终端设备支持的交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的银行卡信息,并从支付标记服务TSP获取所确定的每一银行卡信息对应的临时银行卡标记Token信息,将临时银行卡标记Token信息反馈给终端设备。
终端设备显示临时银行卡标记Token信息。用户基于所显示的临时银行卡标记Token信息选择交易所需要使用的银行卡和交易授权验证方式。假设用户所选择的交易授权验证方式为人脸验证。终端设备通过收单机构和卡组织向授权服务器发送交易请求,该交易请求中可以包括临时银行卡标记Token信息、人脸信息和人脸验证方式。
授权服务器从目标生物信息服务器获取与临时银行卡标记Token信息对应的已注册人脸信息,进而依据获取到的人脸信息对交易进行授权验证。当授权验证通过时,将授权验证通过对应的交易授权验证结果通过卡组织和收单机构反馈至终端设备。终端设备根据该授权验证通过对应的交易授权验证结果进行交易。当授权验证不通过时,将授权验证不通过对应的交易授权验证结果通过卡组织和收单机构反馈至终端设备。终端设备根据该授权验证不通过对应的交易授权验证结果,停止交易。
在本申请实施例中,用户交易所使用的终端设备包括但不限于手机、平板电脑、笔记本电脑、掌上电脑、线下商户设备和自动柜员机(Automatic Teller Machine,ATM)。
本申请实施例的交易包括但不限于线下向商户付款、线上向商户付款、ATM取款、线上转账和ATM转账等。
在用户线下向商户付款的场景中,如果用户第一次向某商户付款,则需要用户输入手机号,终端设备采集用户人脸信息和对用户进行活体检测。终端设备将用户手机号、人脸信息和终端设备支持的交易验证能力上传至目标生物信息服务器。目标生物信息服务器根据人脸信息和终端设备支持的交易验证能力,确定待反馈的用户的银行卡信息。
如果用户上一次向该商户付款的时间至当前时间的时长没有超过某一特定时间(比如一个月),则无需用户输入手机号,终端设备采集用户人脸信息和对用户进行活体检测。终端设备将用户人脸信息和终端设备支持 的交易验证能力上传至目标生物信息服务器。目标生物信息服务器根据人脸信息和终端设备支持的交易验证能力,确定待反馈的用户的银行卡信息。
如果用户上一次向该商户付款的时间至当前时间的时长超过某一特定时间(比如一个月)或者向该商家付款的人数超过某一特定数量(比如5000),则需要用户重新输入手机号,终端设备采集用户人脸信息和对用户进行活体检测。终端设备将用户手机号、人脸信息和终端设备支持的交易验证能力上传至目标生物信息服务器。目标生物信息服务器根据人脸信息和终端设备支持的交易验证能力,确定待反馈的用户的银行卡信息。
目标生物信息服务器将所确定的待反馈的用户的银行卡信息返回给终端设备。
终端设备向授权服务器发送交易请求,其中,该授权服务器可以为用户选择的用于交易的银行卡对应的授权服务器。该交易请求中可以包括活体检测结果、人脸验证方式和用户人脸信息。
授权服务器基于人脸验证方式从目标生物信息服务器获取用户人脸信息,基于从目标生物信息服务器获取到的用户人脸信息和交易请求包括的用户人脸信息以及交易请求包括的活体检测结果,决定是否对交易请求对应的交易进行授权验证,将授权验证结果反馈给终端设备。
终端设备根据交易授权验证结果进行交易。
在本申请的一个实施例中,如果用户线下向商户付款时有商户值守,在商户的同意下,可以跳过活体检测步骤。
在用户线上向商户付款或线上转账的场景中,终端设备对用户进行活体检测和采集用户人脸信息,将终端设备号、人脸信息和终端设备支持的交易验证能力上传至目标生物信息服务器。目标生物信息服务器在根据终端设备号对应的人脸信息库中,检测用户的银行卡信息。如果未检索到用户的银行卡信息,则要求用户输入手机号。目标生物信息服务器根据人脸信息和终端设备支持的交易验证能力,确定待反馈的用户的银行卡信息。
目标生物信息服务器将所确定的待反馈的用户的银行卡信息返回给终端设备。
终端设备向授权服务器发送交易请求,其中,该授权服务器可以为用 户选择的用于交易的银行卡对应的授权服务器。该交易请求中可以包括活体检测结果、人脸验证方式和用户人脸信息。
授权服务器基于人脸验证方式从目标生物信息服务器获取用户人脸信息,基于从目标生物信息服务器获取到的用户人脸信息和交易请求包括的用户人脸信息以及交易请求包括的活体检测结果,决定是否对交易请求对应的交易进行授权验证,将授权验证结果反馈给终端设备。
终端设备根据交易授权验证结果进行交易。
在ATM取款和ATM转账的场景中,ATM采集用户人脸信息和对用户进行活体检测。ATM将人脸信息上传至目标生物信息服务器。目标生物信息服务器根据人脸信息,确定待反馈的用户的银行卡信息。
目标生物信息服务器将所确定待反馈的用户的银行卡信息返回给ATM。
ATM向授权服务器发送交易请求,其中,该授权服务器可以为用户选择的用于交易的银行卡对应的授权服务器。该交易请求中可以包括活体检测结果、人脸验证方式和用户人脸信息。
授权服务器基于人脸验证方式从目标生物信息服务器获取用户人脸信息,基于从目标生物信息服务器获取到的用户人脸信息和交易请求包括的用户人脸信息以及交易请求包括的活体检测结果,决定是否对交易请求对应的交易进行授权验证,将授权验证结果反馈给ATM。
ATM根据交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器将所确定待反馈的用户的银行卡信息返回给ATM后,用户可以选择交易的银行卡,银行卡选择完毕后,用户可以直接输入该银行卡的交易密码。ATM将包含交易密码和活体检测结果的交易请求发送至用户选择交易的银行卡对应的授权服务器。
用户选择交易的银行卡对应的授权服务器根据活体检测结果和交易密码验证结果,决定是否对交易请求对应的交易(取款交易或转账交易)进行授权验证,将授权验证结果反馈给终端设备。
ATM根据交易授权验证结果进行交易。
在本申请的一个实施例中,上述目标生物信息服务器可以包括:第一 服务器和第二服务器。
其中,第一服务器可以负责生物特征信息的存储和卡片信息的检索。第二服务器可以负责用户账户的申请和管理,生物特征信息的路由,发卡行验证要素的管理和查询等。
具体的,终端设备采集用户人脸信息,将用户人脸信息和终端设备支持的交易验证能力上传至第一服务器。第一服务器根据人脸信息进行检索,得到用户身份信息,将用户身份信息和终端设备支持的交易验证能力上传至第二服务器。第二服务器根据用户身份信息、终端设备支持的交易验证能力以及发卡行要求的交易授权验证方式,确定待反馈的用户的银行卡信息,获取与所确定的银行卡信息对应的银行卡Token信息,并通过第一服务器返回至终端设备。终端设备发起交易请求至授权服务器,该交易请求包括人脸验证方式。授权服务器从第一服务器获取人脸信息,基于获取到的人脸信息对交易请求对应的交易进行授权验证,进而向终端设备反馈授权验证结果。终端设备根据交易授权验证结果进行交易。
需要说明的是,上述以人脸信息为例进行说明,仅为本申请的一具体实例,并不构成对本申请的限定。
需要说明的是,上述以卡片为银行卡为例进行说明,仅为本申请的一具体实例,并不构成对本申请的限定。在本申请的一个实施例中,卡片还可以为交通卡(公交卡)或者具备支付功能的会员卡等等。
本申请实施例的目标生物信息服务器可以为生物支付服务提供商(Bio-payment Service Provider,BPSP)。
基于上述,本申请实施例提供了一种应用于终端设备的交易处理方法,如图4所示。图4示出了本申请实施例提供的应用于终端设备的交易处理方法的流程示意图。应用于终端设备的交易处理方法可以包括:
S401:采集用户的生物特征信息。
S402:发送生物特征信息至目标生物信息服务器,以使目标生物信息服务器根据生物特征信息确定待反馈的用户的卡片信息。
S403:接收目标生物信息服务器反馈的用户的卡片信息。
S404:发送交易请求至卡片信息对应的授权服务器,以使授权服务器 对交易请求对应的交易进行授权验证。
S405:接收授权服务器反馈的交易授权验证结果。
S406:根据交易授权验证结果进行交易。
在本申请的一个实施例中,本申请实施例中的生物特征信息可以包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
下面以生物特征信息为人脸信息为例对应用于终端设备的交易处理方法进行说明。
终端设备采集用户的人脸信息,将所采集到的人脸信息发送至目标生物信息服务器。
目标生物信息服务器根据接收到的人脸信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,目标生物信息服务器确定出的待反馈的用户的卡片信息可能仅有1个,假设该卡片信息为建设银行卡信息。则终端设备向建设银行服务器发送交易请求。建设银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端设备反馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,终端设备可以向默认的卡片信息对应的授权服务器发送交易请求。假设默认的卡片信息为招商银行卡信息,则终端设备向招商银行服务器发送交易请求。招商银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端设备反 馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,用户可以选择用于交易的银行卡,假设用户所选择的用于交易的银行卡为农业银行银行卡。则终端设备可以向农业银行服务器发送交易请求。农业银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
本申请实施例提供的应用于终端设备的交易处理方法,能够通过授权服务器对交易请求对应的交易进行授权验证,能够提高用户财产的安全性。
在本申请的一个实施例中,发送交易请求至卡片信息对应的授权服务器,可以包括:发送交易请求至用户从目标生物信息服务器反馈的卡片信息中所选择的卡片信息对应的授权服务器。
用户选择用于交易的银行卡,假设用户所选择的用于交易的银行卡为农业银行银行卡。则终端设备可以向农业银行服务器发送交易请求。农业银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理方法还可以包括:
发送采集生物特征信息的终端设备支持的交易验证能力至目标生物信息服务器,以使目标生物信息服务器根据交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,授权服务器需要利用交易授权验证方式对交易进行验证。比如,建设银行需要银行卡开卡时预留的手机号码接收到的短信验证码或银行卡的交易密码;招商银行需要银行卡的交易密码或用户的生物特征信息(比如人脸信息、指纹信息等等);农业银行需要银行卡开卡时预留的手机号码接收到的短信验证码或用户的生物特征信息(比如人脸信息、指纹信息等等)。基于此,终端设备还可以向目标生物信息服务器发送终端设备支持的交易验证能力,目标生物信息服务器根据交易验证能力以及授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息,进而将与用户关联的、且满足终端设备支持的交易验证能力的 卡片信息反馈至终端设备。
示例性的,假设用户拥有三张银行的银行卡。其中,一张建设银行银行卡,一张招商银行银行卡,一张农业银行银行卡。其中,建设银行的交易授权验证方式为短信验证码验证或指纹验证;招商银行的交易授权验证方式为人脸验证或短信验证码;农业银行的交易授权验证方式为人脸验证或指纹验证。终端设备具有摄像头,而不具有指纹采集器,即终端设备具备人脸验证能力,而不具有指纹验证能力。则目标生物信息服务器根据终端设备支持的交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的银行卡信息为:招行银行银行卡信息和农业银行银行卡信息。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理方法还可以包括:
发送用户的标识信息至目标生物信息服务器,以使目标生物信息服务器查找与标识信息对应的已注册生物特征信息并判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户,若属于同一用户,则将查找到的已注册生物特征信息对应的卡片信息,确定为待反馈的用户的卡片信息。
相比于生物特征信息匹配,通过用户的标识信息,能快速检索到与用户的标识信息对应的生物特征信息,进而利用匹配采集到的生物特征信息和检索到与用户的标识信息对应的生物特征信息即可,无需利用生物特征信息与预先注册的多个生物特征信息进行逐个比对,能够提高卡片信息的确定速度,进而提高交易处理效率。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理方法还可以包括:
对用户进行活体检测;其中,交易请求中包括活体检测结果。
其中,活体检测用于判断采集到的生物特征信息是否来源于活体。在活体检测时,可以要求用户眨眼睛、转头、张嘴等等。
通过活体检测,能够防止其他用户利用用户的照片盗刷用户的银行卡,提高用户财产的安全性。
在本申请的一个实施例中,发送生物特征信息至目标生物信息服务器,可以包括:
发送生物特征信息至中间生物信息服务器,以使中间生物信息服务器查找与生物特征信息匹配的已注册生物特征信息,并将查找到的已注册生物特征信息对应的身份信息发送至目标生物信息服务器,以使目标生物信息服务器根据接收到的身份信息确定待反馈的用户的卡片信息。
在本申请的一个实施例中,目标生物信息服务器的某些功能可以由另一服务器(比如中间生物信息服务器)实现,比如查找与采集到的生物特征信息匹配的已注册生物特征信息的功能。基于此,终端设备可以发送生物特征信息至中间生物信息服务器,中间生物信息服务器查找与采集到的生物特征信息匹配的已注册生物特征信息,并将查找到的已注册生物特征信息对应的身份信息发送至目标生物信息服务器,目标生物信息服务器根据接收到的身份信息确定待反馈的用户的卡片信息。
在本申请的一个实施例中,上述卡片信息可以为未经过标记处理的卡片原始信息。
在本申请的一个实施例中,为了防止用户的卡片信息泄露。可以对上述卡片信息进行标记处理,生成卡片标记Token信息。
通过本申请实施例,目标生物信息服务器可以向终端设备反馈与用户关联的银行卡信息对应的银行卡标记Token信息,能够防止用户的卡片信息泄露,提高用户财产的安全性。
本申请实施例还提供一种应用于目标生物信息服务器的交易处理方法。图5示出了本申请实施例提供的应用于目标生物信息服务器的交易处理方法的流程示意图。应用于目标生物信息服务器的交易处理方法可以包括:
S501:获取用户的生物特征信息。
S502:根据生物特征信息,确定待反馈的用户的卡片信息。
S503:反馈卡片信息至终端设备,以使终端设备向卡片信息对应的授权服务器发送交易请求,接收授权服务器响应于交易请求反馈的交易授权验证结果,根据交易授权验证结果进行交易。
在本申请的一个实施例中,生物特征信息包括以下所列项中的一种或 多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
下面以生物特征信息为人脸信息为例对应用于终端设备的交易处理方法进行说明。
终端设备采集用户的人脸信息,将所采集到的人脸信息发送至目标生物信息服务器。
目标生物信息服务器接收终端设备发送的人脸信息;根据接收到的人脸信息,确定待反馈的用户的卡片信息。
可以理解的是,目标生物信息服务器根据接收到的生物特征信息,确定待反馈的用户的卡片信息,需要预先存储用户的生物特征信息和用户的卡片信息,并建立二者的关联关系。可以理解的是,用户的卡片信息可以仅有一个,也可以有多个。基于此,本申请实施例提供的应用于目标生物信息服务器的交易处理方法还可以包括:获取用于注册的用户的生物特征信息以及用户的一个或多个卡片信息;建立用于注册的用户的生物特征信息与用户的一个或多个卡片信息之间的关联关系。
进而在确定待反馈的用户的卡片信息时,可以将与生物特征信息匹配的已注册生物特征信息关联的卡片信息,确定为待反馈的用户的卡片信息。
在本申请的一个实施例中,用户可以通过发卡行APP、交易清算机构APP或第三方APP进行注册,在用户进行注册时获得用户的生物特征信息。
当用户通过发卡行APP或交易清算机构APP进行注册时,目标生物信息服务器可以直接获得用户的银行卡信息,进而建立用户的生物特征信息与用户的银行卡信息的关联关系。
当用户通过第三方APP进行注册时,用户可以输入银行卡信息,目标生物信息服务器在获得用户的生物特征信息和银行卡信息后,需要对银行卡信息验证,验证该银行卡信息是否与该用户对应,即验证该银行卡信息对应的银行卡的持卡人是否为该用户。当验证该银行卡信息与该用户对应后,建立用户的生物特征信息与用户的银行卡信息的关联关系。
当用户通过第三方APP进行注册时,目标生物信息服务器可以将用户的身份证号或手机号发送授权服务器,授权服务器根据用户的身份证号或 手机号查找与用户的身份证号或手机号对应的银行卡信息,进而将查找到的银行卡信息反馈给目标生物信息服务器,进而目标生物信息服务器建立用户的生物特征信息与用户的银行卡信息的关联关系。可以理解是,用户在银行开卡时,需要留存身份证号或手机号,通过用户开卡时留存的身份证号或手机号,可以查找到用户的银行卡信息。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理方法还可以包括:获取终端设备支持的交易验证能力。根据生物特征信息,确定待反馈的用户的卡片信息,可以包括:根据生物特征信息、交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,授权服务器需要利用交易授权验证方式对交易进行验证。比如,建设银行需要银行卡开卡时预留的手机号码接收到的短信验证码或银行卡的交易密码;招商银行需要银行卡的交易密码或用户的生物特征信息(比如人脸信息、指纹信息等等);农业银行需要银行卡开卡时预留的手机号码接收到的短信验证码或用户的生物特征信息(比如人脸信息、指纹信息等等)。基于此,终端设备还可以向目标生物信息服务器发送终端设备支持的交易验证能力,目标生物信息服务器根据交易验证能力以及授权服务器要求的交易授权验证方式,确定待反馈的用户的银行卡信息,进而将与用户关联的、且满足终端设备支持的交易验证能力的卡片信息反馈至终端设备。
示例性的,假设用户拥有三张银行的银行卡。其中,一张建设银行银行卡,一张招商银行银行卡,一张农业银行银行卡。其中,建设银行的交易授权验证方式为短信验证码验证或指纹验证;招商银行的交易授权验证方式为人脸验证或短信验证码验证;农业银行的交易授权验证方式为人脸验证或指纹验证。终端设备具有摄像头,而不具有指纹采集器,即终端设备具备人脸验证能力,而不具有指纹验证能力。则目标生物信息服务器根据终端设备支持的交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的银行卡信息为:招行银行银行卡信息和农业银行银行卡信息。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理方法还可以包括:获取用户的标识信息。根据生物特征信息,确定待反馈的用户的卡片信息,可以包括:查找与标识信息对应的已注册生物特征信息;判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户;若属于同一用户,根据查找到的已注册生物特征信息,确定待反馈的用户的卡片信息。
相比于生物特征信息匹配,通过用户的标识信息,能快速检索到与用户的标识信息对应的生物特征信息,进而利用匹配采集到的生物特征信息和检索到与用户的标识信息对应的生物特征信息即可,无需利用生物特征信息与预先注册的多个生物特征信息进行逐个比对,能够提高卡片信息的确定速度,进而提高交易处理效率。
在本申请的一个实施例中,为了防止用户的卡片信息泄露。目标生物信息服务器可以根据用户的生物特征信息,查找与用户关联的银行卡信息对应的银行卡标记Token信息,进而向终端设备反馈查找到的与用户关联的银行卡信息对应的银行卡标记Token信息。
在本申请的一个实施例中,目标生物信息服务器根据接收到的生物特征信息,查找与用户关联的银行卡信息对应的银行卡标记Token信息,需要预先存储用户的生物特征信息和用户关联的银行卡信息对应的银行卡标记Token信息,并建立二者的关联关系。
在本申请的一个实施例中,用户可以通过发卡行APP、交易清算机构APP或第三方APP进行注册,在用户进行注册时获得用户的生物特征信息。
当用户通过发卡行APP或交易清算机构APP进行注册时,目标生物信息服务器可以直接获得用户的银行卡信息,进而利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,进而建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。
当用户通过第三方APP进行注册时,用户可以输入银行卡信息,目标生物信息服务器在获得用户的生物特征信息和银行卡信息后,需要对银行卡信息验证,验证该银行卡信息是否与该用户对应,即验证该银行卡信息 对应的银行卡的持卡人是否为该用户。当验证该银行卡信息与该用户对应后,利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,进而建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。
当用户通过第三方APP进行注册时,目标生物信息服务器可以将用户的身份证号或手机号发送授权服务器,授权服务器根据用户的身份证号或手机号查找与用户的身份证号或手机号对应的银行卡信息,进而将查找到的银行卡信息反馈给目标生物信息服务器,进而利用支付标记服务TSP生成与用户的银行卡信息对应的银行卡标记Token信息,建立用户的生物特征信息与用户关联的银行卡信息对应的银行卡标记Token信息的关联关系。可以理解是,用户在银行开卡时,需要留存身份证号或手机号,通过用户开卡时留存的身份证号或手机号,可以查找到用户的卡片信息。
通过本申请实施例,目标生物信息服务器可以向终端设备反馈与用户关联的银行卡信息对应的银行卡标记Token信息,能够防止用户的卡片信息泄露,提高用户财产的安全性。
在本申请的一个实施例中,卡片信息可以包括:经过标记处理的临时卡片标记Token信息。
在本申请的一个实施例中,目标生物信息服务器根据接收到的生物特征信息,查找到与用户关联的银行卡信息后,可以利用支付标记服务TSP对银行卡信息进行标记处理,生成与用户的银行卡信息对应的临时银行卡标记Token信息,将该临时银行卡标记Token信息反馈给终端设备。该临时银行卡标记Token信息仅在一段时间内有效,比如3分钟。
通过本申请实施例,通过使用临时银行卡标记Token信息,能够防止用户的卡片信息泄露,提高用户财产的安全性。
在本申请的一个实施例中,目标生物信息服务器确定出的待反馈的用户的卡片信息可能仅有1个,假设该卡片信息为建设银行卡信息。则终端设备向建设银行服务器发送交易请求。建设银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端设备反馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,终端设备可以向默认的卡片信息对应的授权服务器发送交易请求。假设默认的卡片信息为招商银行卡信息,则终端设备向招商银行服务器发送交易请求。招商银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,目标生物信息服务器确定待反馈的用户的卡片信息可能不止1个。假设确定出的卡片信息分别为:建设银行卡信息、招商银行卡信息和农业银行卡信息。则目标生物信息服务器向终端设备反馈所确定的卡片信息(建设银行卡信息、招商银行卡信息和农业银行卡信息)。此时,用户可以选择用于交易的银行卡,假设用户所选择的用于交易的银行卡为农业银行银行卡。则终端设备可以向农业银行服务器发送交易请求。农业银行服务器对该交易请求对应的交易进行授权验证,并将交易授权验证结果反馈至终端设备。终端设备根据该交易授权验证结果进行交易。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理方法还可以包括:发送与生物特征信息匹配的已注册生物特征信息至授权服务器,以使授权服务器根据已注册生物特征信息对交易请求对应的交易进行授权验证。
当授权服务器接收到终端设备发送包括用户的生物特征信息和基于生物特征信息的交易授权验证方式的交易请求后,从生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;将交易授权验证结果反馈至发送交易请求的终端设备反馈,终端设备根据交易授权验证结果进行交易。
示例性的,假设终端设备A向授权服务器发起交易请求,该交易请求 中包括用户X的人脸信息a和需要利用人脸进行授权验证的交易授权验证方式。可以理解的是,该交易请求中还包括进行交易的卡片信息。授权服务器从目标生物信息服务器获取到与该卡片信息对应的已注册人脸信息b;利用已注册人脸信息b和人脸信息a对交易进行授权验证;若人脸信息b和人脸信息a为同一人的人脸信息,则授权通过;若人脸信息b和人脸信息a为不同人的人脸信息,则授权不通过。终端设备根据交易授权验证结果进行交易。
在本申请的一个实施例中,获取用户的生物特征信息,可以包括:接收中间生物信息服务器发送的身份信息,其中,该身份信息为中间生物信息服务器查找到的与获取到的生物特征信息对应的已注册生物特征信息对应的身份信息。根据生物特征信息,确定待反馈的用户的卡片信息,可以包括:根据接收到的身份信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,目标生物信息服务器的某些功能可以由另一服务器(比如中间生物信息服务器)实现,比如查找与采集到的生物特征信息匹配的已注册生物特征信息的功能。终端设备可以发送生物特征信息至中间生物信息服务器,中间生物信息服务器查找与采集到的生物特征信息匹配的已注册生物特征信息,进而将查找到的对应的身份信息发送至目标生物信息服务器,目标生物信息服务器根据接收到的身份信息确定待反馈的用户的卡片信息。在本申请的一个实施例中,身份信息包括但不限于:用户的手机号、用户的身份证号等等。
本申请实施例还提供一种应用于授权服务器的交易处理方法。图6示出了本申请实施例提供的应用于授权服务器的交易处理方法的流程示意图。应用于授权服务器的交易处理方法可以包括:
S601:获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式。
S602:从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息。
S603:根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果。
S604:向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
本申请实施例中的生物特征信息可以包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
当授权服务器接收到终端设备发送包括用户的生物特征信息和基于生物特征信息的交易授权验证方式的交易请求后,从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息;根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果;将交易授权验证结果反馈至发送交易请求的终端设备反馈,终端设备根据交易授权验证结果进行交易。
示例性的,假设终端设备A向授权服务器发起交易请求,该交易请求中包括用户X的人脸信息a和需要利用人脸进行授权验证的交易授权验证方式。可以理解的是,该交易请求中还包括进行交易的卡片信息。授权服务器从目标生物信息服务器获取到与该卡片信息对应的已注册人脸信息b;利用已注册人脸信息b和人脸信息a对交易进行授权验证;若人脸信息b和人脸信息a为同一人的人脸信息,则授权通过;若人脸信息b和人脸信息a为不同人的人脸信息,则授权不通过。终端设备根据交易授权验证结果进行交易。
在本申请的一个实施例中,交易请求中包括:针对用户的活体检测结果。授权服务器根据活体检测结果、已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果。
本申请实施例提供的应用于授权服务器的交易处理方法,授权服务器能够对交易请求对应的交易进行授权验证,能够提高用户财产的安全性。
与上述的方法实施例相对应,本申请实施例还提供一种交易处理装置。
图7示出了本申请实施例提供的应用于终端设备的交易处理装置的结构示意图。应用于终端设备的交易处理装置可以包括:
生物特征信息采集模块701,用于采集用户的生物特征信息。
生物特征信息发送模块702,用于发送生物特征信息至目标生物信息 服务器,以使目标生物信息服务器根据生物特征信息确定待反馈的用户的卡片信息。
卡片信息接收模块703,用于接收目标生物信息服务器反馈的用户的卡片信息。
交易请求发送模块704,用于发送交易请求至卡片信息对应的授权服务器,以使授权服务器对交易请求对应的交易进行授权验证。
交易授权验证结果接收模块705,用于接收授权服务器反馈的交易授权验证结果。
交易模块706,用于根据交易授权验证结果进行交易。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理装置还可以包括:
交易验证能力发送模块,用于发送采集生物特征信息的终端设备支持的交易验证能力至目标生物信息服务器,以使目标生物信息服务器根据交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理装置还可以包括:
标识信息发送模块,用于发送用户的标识信息至目标生物信息服务器,以使目标生物信息服务器查找与标识信息对应的已注册生物特征信息并判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户,若属于同一用户,则将查找到的已注册生物特征信息对应的卡片信息,确定为待反馈的用户的卡片信息。
在本申请的一个实施例中,本申请实施例提供的应用于终端设备的交易处理装置还可以包括:
活体检测模块,用于对用户进行活体检测;其中,交易请求中包括活体检测结果。
在本申请的一个实施例中,生物特征信息发送模块702,具体可以用于:
发送生物特征信息至中间生物信息服务器,以使中间生物信息服务器 查找与生物特征信息匹配的已注册生物特征信息,并将查找到的已注册生物特征信息对应的身份信息发送至目标生物信息服务器,以使目标生物信息服务器根据接收到的身份信息确定待反馈的用户的卡片信息。
在本申请的一个实施例中,卡片信息,包括:
未经过标记处理的卡片原始信息或经过标记处理的卡片标记Token信息。
在本申请的一个实施例中,交易请求发送模块704,具体可以用于:
发送交易请求至用户从目标生物信息服务器反馈的卡片信息中所选择的卡片信息对应的授权服务器。
在本申请的一个实施例中,交易请求包括用户所选择的交易授权验证方式。
在本申请的一个实施例中,生物特征信息包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
图8示出了本申请实施例提供的应用于目标生物信息服务器的交易处理装置的结构示意图。应用于目标生物信息服务器的交易处理装置可以包括:
生物特征信息获取模块801,用于获取用户的生物特征信息。
卡片信息确定模块802,用于根据生物特征信息,确定待反馈的用户的卡片信息。
卡片信息反馈模块803,用于反馈卡片信息至终端设备,以使终端设备向卡片信息对应的授权服务器发送交易请求,接收授权服务器响应于交易请求反馈的交易授权验证结果,根据交易授权验证结果进行交易。
在本申请的一个实施例中,生物特征信息获取模块801,具体可以用于:接收终端设备发送的用户的生物特征信息。卡片信息确定模块802,具体可以用于:查找与生物特征信息匹配的已注册生物特征信息;根据查找到的已注册生物特征信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,生物特征信息获取模块801,具体可以用于:接收中间生物信息服务器发送的用户的身份信息,身份信息为中间生 物信息服务器查找到的与生物特征信息对应的已注册生物特征信息对应的身份信息。卡片信息确定模块802,具体可以用于:根据接收到的身份信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理装置还可以包括:
交易验证能力获取模块,用于获取终端设备支持的交易验证能力。
卡片信息确定模块802,具体可以用于:
根据生物特征信息、交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理装置还可以包括:
标识信息获取模块,用于获取用户的标识信息。
卡片信息确定模块802,具体可以用于:
查找与标识信息对应的已注册生物特征信息;判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户;若属于同一用户,根据查找到的已注册生物特征信息,确定待反馈的用户的卡片信息。
在本申请的一个实施例中,卡片信息,包括:
经过标记处理的临时卡片标记Token信息。
在本申请的一个实施例中,卡片信息确定模块802,具体可以用于:
将与生物特征信息匹配的已注册生物特征信息关联的卡片信息,确定为待反馈的用户的卡片信息。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理装置还可以包括:
关联关系建立模块,用于获取用于注册的用户的生物特征信息以及用户的一个或多个卡片信息;建立用于注册的用户的生物特征信息与用户的一个或多个卡片信息之间的关联关系。
在本申请的一个实施例中,本申请实施例提供的应用于目标生物信息服务器的交易处理装置还可以包括:
已注册生物特征信息发送模块,用于发送与生物特征信息匹配的已注 册生物特征信息至授权服务器,以使授权服务器根据已注册生物特征信息对交易请求对应的交易进行授权验证。
在本申请的一个实施例中,生物特征信息包括以下所列项中的一种或多种:人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
图9示出了本申请实施例提供的应用于授权服务器的交易处理装置的结构示意图。应用于授权服务器的交易处理装置可以包括:
交易请求获取模块901,用于获取交易请求,交易请求包括用户的生物特征信息和基于生物特征信息的交易授权验证方式。
生物特征信息获取模块902,用于从目标生物信息服务器获取交易验证方式所要求的用户的已注册生物特征信息。
授权验证模块903,用于根据已注册生物特征信息和交易请求包括的生物特征信息,对交易请求对应的交易进行授权验证,得到交易授权验证结果。
授权验证结果发送模块904,用于向发送交易请求的终端设备反馈交易授权验证结果,以使终端设备根据交易授权验证结果进行交易。
在本申请的一个实施例中,生物特征信息包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
在本申请的一个实施例中,交易请求,包括:针对用户的活体检测结果。
图10示出了能够实现根据本申请实施例的交易处理方法及装置的计算设备的示例性硬件架构的结构图。如图10所示,计算设备100包括输入设备101、输入接口102、中央处理器103、存储器104、输出接口105、以及输出设备106。其中,输入接口102、中央处理器103、存储器104、以及输出接口105通过总线110相互连接,输入设备101和输出设备106分别通过输入接口102和输出接口105与总线110连接,进而与计算设备100的其他组件连接。
具体地,输入设备101接收来自外部的输入信息,并通过输入接口102将输入信息传送到中央处理器103;中央处理器103基于存储器104中存储 的计算机可执行指令对输入信息进行处理以生成输出信息,将输出信息临时或者永久地存储在存储器104中,然后通过输出接口105将输出信息传送到输出设备106;输出设备106将输出信息输出到计算设备100的外部供用户使用。
也就是说,图10所示的计算设备也可以被实现为交易处理设备,该交易处理设备可以包括:存储有计算机可执行指令的存储器;以及处理器,该处理器在执行计算机可执行指令时可以实现本申请实施例提供的交易处理方法和装置。
本申请实施例还提供一种计算机可读存储介质,该计算机可读存储介质上存储有计算机程序指令;该计算机程序指令被处理器执行时实现本申请实施例提供的交易处理方法。
虽然已经参考优选实施例对本申请进行了描述,但在不脱离本申请的范围的情况下,可以对其进行各种改进并且可以用等效物替换其中的部件。尤其是,只要不存在结构冲突,各个实施例中所提到的各项技术特征均可以任意方式组合起来。本申请并不局限于文中公开的特定实施例,而是包括落入权利要求的范围内的所有技术方案。

Claims (28)

  1. 一种交易处理方法,其特征在于,所述方法包括:
    采集用户的生物特征信息;
    发送所述生物特征信息至目标生物信息服务器,以使所述目标生物信息服务器根据所述生物特征信息确定待反馈的所述用户的卡片信息;
    接收所述目标生物信息服务器反馈的所述用户的卡片信息;
    发送交易请求至所述卡片信息对应的授权服务器,以使所述授权服务器对所述交易请求对应的交易进行授权验证;
    接收所述授权服务器反馈的交易授权验证结果;
    根据所述交易授权验证结果进行交易。
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    发送采集所述生物特征信息的终端设备支持的交易验证能力至所述目标生物信息服务器,以使所述目标生物信息服务器根据所述交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的所述用户的卡片信息。
  3. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    发送所述用户的标识信息至所述目标生物信息服务器,以使所述目标生物信息服务器查找与所述标识信息对应的已注册生物特征信息并判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户,若属于同一用户,则将查找到的已注册生物特征信息对应的卡片信息,确定为待反馈的所述用户的卡片信息。
  4. 根据权利要求1所述的方法,其特征在于,所述卡片信息,包括:
    未经过标记处理的卡片原始信息或经过标记处理的卡片标记Token信息。
  5. 根据权利要求1所述的方法,其特征在于,所述发送所述生物特征信息至目标生物信息服务器,包括:
    发送所述生物特征信息至中间生物信息服务器,以使所述中间生物信息服务器查找与所述生物特征信息匹配的已注册生物特征信息,并将查找 到的已注册生物特征信息对应的身份信息发送至目标生物信息服务器,以使所述目标生物信息服务器根据接收到的所述身份信息确定待反馈的所述用户的卡片信息。
  6. 根据权利要求1所述的方法,其特征在于,所述发送交易请求至所述卡片信息对应的授权服务器,包括:
    发送交易请求至所述用户从所述目标生物信息服务器反馈的卡片信息中所选择的卡片信息对应的授权服务器。
  7. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    对所述用户进行活体检测;其中,所述交易请求中包括活体检测结果。
  8. 根据权利要求1所述的方法,其特征在于,所述交易请求包括用户所选择的交易授权验证方式。
  9. 根据权利要求1所述的方法,其特征在于,所述生物特征信息包括以下所列项中的一种或多种:
    人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
  10. 一种交易处理方法,其特征在于,所述方法包括:
    获取用户的生物特征信息;
    根据所述生物特征信息,确定待反馈的所述用户的卡片信息;
    反馈所述卡片信息至终端设备,以使所述终端设备向所述卡片信息对应的授权服务器发送交易请求,接收所述授权服务器响应于所述交易请求反馈的交易授权验证结果,根据所述交易授权验证结果进行交易。
  11. 根据权利要求10所述的方法,其特征在于,所述获取用户的生物特征信息,包括:
    接收终端设备发送的所述用户的生物特征信息;
    其中,所述根据所述生物特征信息,确定待反馈的所述用户的卡片信息,包括:
    查找与所述生物特征信息匹配的已注册生物特征信息;根据查找到的已注册生物特征信息,确定待反馈的所述用户的卡片信息。
  12. 根据权利要求10所述的方法,其特征在于,所述获取用户的生物特征信息,包括:
    接收中间生物信息服务器发送的所述用户的身份信息,其中,所述身份信息为所述中间生物信息服务器查找到的与所述生物特征信息对应的已注册生物特征信息对应的身份信息;
    其中,所述根据所述生物特征信息,确定待反馈的所述用户的卡片信息,包括:
    根据接收到的所述身份信息,确定待反馈的所述用户的卡片信息。
  13. 根据权利要求10所述的方法,其特征在于,所述方法还包括:
    获取所述终端设备支持的交易验证能力;
    其中,所述根据所述生物特征信息,确定待反馈的所述用户的卡片信息,包括:
    根据所述生物特征信息、所述交易验证能力和授权服务器要求的交易授权验证方式,确定待反馈的所述用户的卡片信息。
  14. 根据权利要求10所述的方法,其特征在于,所述方法还包括:
    获取所述用户的标识信息;
    其中,所述根据所述生物特征信息,确定待反馈的所述用户的卡片信息,包括:
    查找与所述标识信息对应的已注册生物特征信息;
    判断接收到的生物特征信息和查找到的已注册生物特征信息是否属于同一用户;
    若属于同一用户,根据查找到的已注册生物特征信息,确定待反馈的所述用户的卡片信息。
  15. 根据权利要求10所述的方法,其特征在于,所述卡片信息,包括:
    经过标记处理的临时卡片标记Token信息。
  16. 根据权利要求10所述的方法,其特征在于,所述根据所述生物特征信息,确定待反馈的所述用户的卡片信息,包括:
    将与所述生物特征信息匹配的已注册生物特征信息关联的卡片信息,确定为待反馈的所述用户的卡片信息。
  17. 根据权利要求16所述的方法,其特征在于,所述方法还包括:
    获取用于注册的所述用户的生物特征信息以及所述用户的一个或多个 卡片信息;
    建立所述用于注册的所述用户的生物特征信息与所述用户的一个或多个卡片信息之间的关联关系。
  18. 根据权利要求10所述的方法,其特征在于,所述方法还包括:
    发送与所述生物特征信息匹配的已注册生物特征信息至所述授权服务器,以使所述授权服务器根据所述已注册生物特征信息对所述交易请求对应的交易进行授权验证。
  19. 根据权利要求10所述的方法,其特征在于,所述生物特征信息包括以下所列项中的一种或多种:
    人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
  20. 一种交易处理方法,其特征在于,所述方法包括:
    获取交易请求,所述交易请求包括用户的生物特征信息和基于所述生物特征信息的交易授权验证方式;
    从目标生物信息服务器获取所述交易验证方式所要求的所述用户的已注册生物特征信息;
    根据所述已注册生物特征信息和所述交易请求包括的生物特征信息,对所述交易请求对应的交易进行授权验证,得到交易授权验证结果;
    向发送所述交易请求的终端设备反馈所述交易授权验证结果,以使所述终端设备根据所述交易授权验证结果进行交易。
  21. 根据权利要求20所述的方法,其特征在于,所述生物特征信息包括以下所列项中的一种或多种:
    人脸信息、指纹信息、声纹信息、虹膜信息和掌纹信息。
  22. 根据权利要求20所述的方法,其特征在于,所述交易请求,包括:
    针对所述用户的活体检测结果。
  23. 一种交易处理装置,其特征在于,所述装置包括:
    生物特征信息采集模块,用于采集用户的生物特征信息;
    生物特征信息发送模块,用于发送所述生物特征信息至目标生物信息服务器,以使所述目标生物信息服务器根据所述生物特征信息确定待反馈的所述用户的卡片信息;
    卡片信息接收模块,用于接收所述目标生物信息服务器反馈的所述用户的卡片信息;
    交易请求发送模块,用于发送交易请求至所述卡片信息对应的授权服务器,以使所述授权服务器对所述交易请求对应的交易进行授权验证;
    交易授权验证结果接收模块,用于接收所述授权服务器反馈的交易授权验证结果;
    交易模块,用于根据所述交易授权验证结果进行交易。
  24. 一种交易处理装置,其特征在于,所述装置包括:
    生物特征信息获取模块,用于获取用户的生物特征信息;
    卡片信息确定模块,用于根据所述生物特征信息,确定待反馈的所述用户的卡片信息;
    卡片信息反馈模块,用于反馈所述卡片信息至终端设备,以使所述终端设备向所述卡片信息对应的授权服务器发送交易请求,接收所述授权服务器响应于所述交易请求反馈的交易授权验证结果,根据所述交易授权验证结果进行交易。
  25. 一种交易处理装置,其特征在于,所述装置包括:
    交易请求获取模块,用于获取交易请求,所述交易请求包括用户的生物特征信息和基于所述生物特征信息的交易授权验证方式;
    生物特征信息获取模块,用于从生物信息服务器获取所述交易验证方式所要求的所述用户的已注册生物特征信息;
    授权验证模块,用于根据所述已注册生物特征信息和所述交易请求包括的生物特征信息,对所述交易请求对应的交易进行授权验证,得到交易授权验证结果;
    授权验证结果发送模块,用于向发送所述交易请求的终端设备反馈所述交易授权验证结果,以使所述终端设备根据所述交易授权验证结果进行交易。
  26. 一种交易处理设备,其特征在于,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求1至9中任意一项所述的交易处理方法 的步骤或实现如权利要求10至19中任意一项所述的交易处理方法的步骤或实现如权利要求20至22任意一项所述的交易处理方法的步骤。
  27. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现如权利要求1至9中任意一项所述的交易处理方法的步骤或实现如权利要求10至19中任意一项所述的交易处理方法的步骤或实现如权利要求20至22任意一项所述的交易处理方法的步骤。
  28. 一种交易处理系统,其特征在于,所述系统包括:目标生物信息服务器和多个授权服务器;
    所述目标生物信息服务器,用于获取用户的生物特征信息;根据所述生物特征信息,确定待反馈的所述用户的卡片信息;反馈所述卡片信息至终端设备;向授权服务器发送交易授权验证方式所要求的所述用户的已注册生物特征信息;
    所述授权服务器,用于获取交易请求,所述交易请求包括用户的生物特征信息和基于所述生物特征信息的交易授权验证方式;从目标生物信息服务器获取所述交易验证方式所要求的所述用户的已注册生物特征信息;根据所述已注册生物特征信息和所述交易请求包括的生物特征信息,对所述交易请求对应的交易进行授权验证,得到交易授权验证结果;向发送所述交易请求的终端设备反馈所述交易授权验证结果,以使所述终端设备根据所述交易授权验证结果进行交易。
PCT/CN2020/071998 2019-05-20 2020-01-14 交易处理方法、装置、设备、介质及系统 Ceased WO2020233154A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US17/269,351 US20210312465A1 (en) 2019-05-20 2020-01-14 Transaction processing method, apparatus, device, medium and system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910417482.3 2019-05-20
CN201910417482.3A CN110189136A (zh) 2019-05-20 2019-05-20 交易处理方法、装置、设备、介质及系统

Publications (1)

Publication Number Publication Date
WO2020233154A1 true WO2020233154A1 (zh) 2020-11-26

Family

ID=67716808

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/071998 Ceased WO2020233154A1 (zh) 2019-05-20 2020-01-14 交易处理方法、装置、设备、介质及系统

Country Status (4)

Country Link
US (1) US20210312465A1 (zh)
CN (1) CN110189136A (zh)
TW (1) TWI751499B (zh)
WO (1) WO2020233154A1 (zh)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110189136A (zh) * 2019-05-20 2019-08-30 中国银联股份有限公司 交易处理方法、装置、设备、介质及系统
CN112446704A (zh) * 2019-09-03 2021-03-05 上海云从汇临人工智能科技有限公司 一种安全交易管理方法及安全交易管理装置
CN111160920A (zh) * 2019-12-31 2020-05-15 中国银行股份有限公司 一种防止银行卡盗刷的方法及装置
CN111144895B (zh) * 2019-12-31 2023-10-31 中国银联股份有限公司 一种数据处理方法、装置与系统
US11416594B2 (en) * 2020-04-28 2022-08-16 Daon Enterprises Limited Methods and systems for ensuring a user is permitted to use an object to conduct an activity
CN112435031A (zh) * 2020-08-06 2021-03-02 中国银联股份有限公司 基于用户绑定关系的数据处理方法及其系统
CN115189898B (zh) * 2021-04-01 2024-05-24 富联精密电子(天津)有限公司 交易处理方法、终端及存储介质
CN114511328B (zh) * 2021-12-29 2025-01-10 江苏苏州农村商业银行股份有限公司 基于云计算的信息标记系统及支付标记方法
CN114881790B (zh) * 2022-05-19 2025-12-09 中国银行股份有限公司 交易授权信息处理方法及系统、授权服务器、交易服务器
CN116434350A (zh) * 2023-03-31 2023-07-14 江苏日颖慧眼智能设备有限公司 一种人脸识别的活体识别方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105590194A (zh) * 2014-12-03 2016-05-18 中国银联股份有限公司 一种线下支付方法以及支付系统
CN207182543U (zh) * 2017-08-29 2018-04-03 深圳怡化电脑股份有限公司 不插卡atm
CN109753779A (zh) * 2019-01-11 2019-05-14 北京信息科技大学 一种基于生物特征识别的全网统一身份认证方法及系统
CN110189136A (zh) * 2019-05-20 2019-08-30 中国银联股份有限公司 交易处理方法、装置、设备、介质及系统

Family Cites Families (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6591249B2 (en) * 2000-03-26 2003-07-08 Ron Zoka Touch scan internet credit card verification purchase process
US7237117B2 (en) * 2001-03-16 2007-06-26 Kenneth P. Weiss Universal secure registry
US20080147481A1 (en) * 2001-09-21 2008-06-19 Robinson Timothy L System and method for encouraging use of a biometric authorization system
TW200622767A (en) * 2004-12-30 2006-07-01 Systex Corp System and method for enhancing security of log-in account number
CN103886453A (zh) * 2012-12-21 2014-06-25 黄金富 一种利用人体生物特征确认的支付系统和相应方法
CN103632268A (zh) * 2013-12-03 2014-03-12 康连生 安全认证方法及安全认证支付终端
CN105825382B (zh) * 2015-09-14 2022-03-11 维沃移动通信有限公司 一种移动支付方法及电子设备
CN105471884B (zh) * 2015-12-21 2019-05-31 联想(北京)有限公司 一种认证方法、服务器
CN105930765A (zh) * 2016-02-29 2016-09-07 中国银联股份有限公司 一种支付方法及装置
TWI645308B (zh) * 2016-10-18 2018-12-21 富邦綜合證券股份有限公司 Electronic transaction authentication method and system using mobile device application
US20180189767A1 (en) * 2016-12-29 2018-07-05 Fotonation Limited Systems and methods for utilizing payment card information with a secure biometric processor on a mobile device
CN106850201B (zh) * 2017-02-15 2019-11-08 济南晟安信息技术有限公司 智能终端多因子认证方法、智能终端、认证服务器及系统
CN107153960A (zh) * 2017-04-25 2017-09-12 北京小米移动软件有限公司 交易的结算方法及装置
CN107220830A (zh) * 2017-05-08 2017-09-29 深圳市牛鼎丰科技有限公司 支付方法、装置、存储介质和计算机设备
SG10201706801YA (en) * 2017-08-21 2019-03-28 Mastercard Asia Pacific Pte Ltd Biometric system for authenticating a biometric request
US20190065874A1 (en) * 2017-08-30 2019-02-28 Mastercard International Incorporated System and method of authentication using image of a user
US10805288B2 (en) * 2017-11-30 2020-10-13 Oath Inc. Authenitcation entity for user authentication

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105590194A (zh) * 2014-12-03 2016-05-18 中国银联股份有限公司 一种线下支付方法以及支付系统
CN207182543U (zh) * 2017-08-29 2018-04-03 深圳怡化电脑股份有限公司 不插卡atm
CN109753779A (zh) * 2019-01-11 2019-05-14 北京信息科技大学 一种基于生物特征识别的全网统一身份认证方法及系统
CN110189136A (zh) * 2019-05-20 2019-08-30 中国银联股份有限公司 交易处理方法、装置、设备、介质及系统

Also Published As

Publication number Publication date
US20210312465A1 (en) 2021-10-07
CN110189136A (zh) 2019-08-30
TW202044156A (zh) 2020-12-01
TWI751499B (zh) 2022-01-01

Similar Documents

Publication Publication Date Title
WO2020233154A1 (zh) 交易处理方法、装置、设备、介质及系统
RU2595885C2 (ru) Способ и система, использующие универсальный идентификатор и биометрические данные
US9542684B2 (en) Biometric based authorization systems for electronic fund transfers
US20130232073A1 (en) Authentication Using Biometric Technology Through a Consumer Device
US20070284432A1 (en) Method and system for flexible purchases using only fingerprints at the time and location of purchase
US20070174186A1 (en) Authenticated and distributed transaction processing
US20180089688A1 (en) System and methods for authenticating a user using biometric data
CN106204033A (zh) 一种基于人脸识别和指纹识别的支付系统
CN111553312A (zh) 业务办理方法及装置
US20090171827A1 (en) Authenticated third-party check cashing
WO2020029384A1 (zh) 无卡信用支付方法、系统、计算机设备和存储介质
US11599882B2 (en) Data processing method, apparatus, and system
US20250217784A1 (en) Method and System for Large Transfer Authentication
CN1760904A (zh) 基于指纹验证的付费系统
JPH11338947A (ja) 個人認証を利用した金融取引方式
US12430625B2 (en) Systems and methods for inter-institutional ATM functionality
US20240037555A1 (en) Payment ownership validation
TWM583963U (zh) 用於金融交易的身分驗證系統
JP6476344B2 (ja) 現金取引システムおよび現金取引方法
HK40011600A (zh) 交易处理方法、装置、设备、介质及系统
TWI718541B (zh) 用於金融交易的身分驗證系統與方法
KR20040086026A (ko) 모바일 단말기를 이용한 뱅킹 서비스 시스템 및 서비스 방법
WO2026086413A1 (zh) 拒付请求的处理方法、装置、设备、介质及程序产品
CN110458575A (zh) 一种计算机系统以及一种计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20810277

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20810277

Country of ref document: EP

Kind code of ref document: A1