WO2024080556A1 - Procédé d'authentification de paiement par double chiffrement et serveur de paiement le mettant en œuvre - Google Patents

Procédé d'authentification de paiement par double chiffrement et serveur de paiement le mettant en œuvre Download PDF

Info

Publication number
WO2024080556A1
WO2024080556A1 PCT/KR2023/013114 KR2023013114W WO2024080556A1 WO 2024080556 A1 WO2024080556 A1 WO 2024080556A1 KR 2023013114 W KR2023013114 W KR 2023013114W WO 2024080556 A1 WO2024080556 A1 WO 2024080556A1
Authority
WO
WIPO (PCT)
Prior art keywords
payment
value
unique value
encryption
store
Prior art date
Application number
PCT/KR2023/013114
Other languages
English (en)
Korean (ko)
Inventor
오명재
Original Assignee
주식회사 플렉스데이
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from KR1020220130511A external-priority patent/KR102673516B1/ko
Application filed by 주식회사 플렉스데이 filed Critical 주식회사 플렉스데이
Publication of WO2024080556A1 publication Critical patent/WO2024080556A1/fr

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3823Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/04Payment circuits
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/04Payment circuits
    • G06Q20/045Payment circuits using payment protocols involving tickets
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/04Payment circuits
    • G06Q20/06Private payment circuits, e.g. involving electronic currency used among participants of a common payment scheme
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/04Payment circuits
    • G06Q20/06Private payment circuits, e.g. involving electronic currency used among participants of a common payment scheme
    • G06Q20/065Private payment circuits, e.g. involving electronic currency used among participants of a common payment scheme using e-cash
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Definitions

  • the present invention relates to a product trading system using asymmetric key-based payment authentication electronic gift certificates.
  • a gift certificate is a type of ticket containing a certain amount of money or the value of a product, and is used by businesses as a means to promote and encourage purchases of their products. These gift certificates have been mainly used in the form of paper printed on paper.
  • a unique random number consisting of at least one of numbers and letters is assigned to the issued electronic gift certificate, and an electronic gift certificate image showing at least one of the given random number and the random number displayed in the form of a barcode or QR code Provided to the user terminal.
  • the purpose of the present invention is to solve the above problems, and to provide a product trading system by encrypting the unique address and access rights token using an asymmetric key to prevent damage caused by forgery and unauthorized use of electronic gift certificates. there is.
  • the purpose of the present invention is to encrypt the unique address of the gift certificate using a private key managed by the payment server and a public key corresponding to the private key, and by additionally performing an encryption and decryption process of the public key in conjunction with the store terminal that performs payment.
  • the goal is to provide a safe payment service.
  • the object of the present invention is not limited to the object mentioned above, and other objects not mentioned can be clearly understood from the description below.
  • a payment authentication method through double encryption performed in a payment server includes the steps of generating a first unique value for payment for a product registered in a store; generating a first password value by encrypting the generated first unique value with a private key; generating and providing the first password value as a visualized code according to predetermined rules; Decrypting the first encryption value recognized from the provided code with a public key corresponding to the private key and receiving a second encryption value obtained by encrypting the extracted second unique value with the public key; extracting a second unique value by decrypting the received second encryption value with the private key; and approving payment by comparing the extracted second eigenvalue with the generated first eigenvalue.
  • the first unique value is preferably an API address for requesting payment approval from the payment server.
  • the method further includes generating a token for identification of the store, and the receiving step includes receiving the API request address combining the token with the second unique value.
  • the approval step preferably involves approving payment by comparing the first unique value generated for the registered product of the store identified with the received token with the second unique value.
  • the first unique value for payment for the product registered in the store is entered into the personal information.
  • the first unique value is preferably an API address for requesting payment approval from the payment server.
  • the method further includes generating a token for identification of the store, and the receiving step includes receiving the API request address combining the token with the second unique value.
  • the approval step preferably involves approving payment by comparing the first unique value generated for the registered product of the store identified with the received token with the second unique value.
  • a computing device constituting a payment server includes a processor; and a memory in communication with the processor, wherein the memory stores instructions that cause the processor to perform operations, the operations comprising generating a first unique value for payment for a registered product in a store.
  • an operation of generating a first password value by encrypting the generated first unique value with a private key an operation of generating and providing the first password value as a visualized code according to a predetermined rule, and the operation of generating and providing the first password value as a visualized code according to a predetermined rule
  • the unique address generated when creating an e-gift certificate is encrypted using a private key and generated in the form of a QR code, and the e-gift certificate is distributed, the unique address contained in the QR code can be decrypted only with the public key provided by the e-gift certificate creator. Therefore, it can have the effect of proving the issuer/original on the same principle as an electronic signature.
  • the unique address generated when creating an electronic gift certificate is encrypted and decrypted using a private key and a public key, and the status information of the electronic gift certificate is changed using a composite address generated based on the unique address, access permission token, and request code. , unauthorized use and counterfeiting of electronic gift certificates can be prevented.
  • the unique address encrypted with a private key and printed in the form of a QR code can be printed not only on digital images but also on physical objects, so it replaces paper gift certificates with anti-counterfeit technology applied, and furthermore, it can be used online/offline without the boundary between paper gift certificates and electronic gift certificates. It can be used as an integrated payment method.
  • FIG. 1 is a block diagram of a payment system through double encryption according to an embodiment of the present invention.
  • Figure 2 is a flowchart showing a method of performing payment through double encryption according to an embodiment of the present invention.
  • Figures 3 and 4 are exemplary diagrams showing an asymmetric key-based gift certificate encryption and decryption process according to an embodiment of the present invention.
  • Figure 5 is an exemplary diagram showing the process of generating a service request URL performed in a store terminal according to an embodiment of the present invention.
  • Figure 6 is a flowchart showing a payment approval method through double encryption according to an embodiment of the present invention.
  • Figure 7 is a timing diagram showing information transmission and reception between components of a payment system through double encryption according to an embodiment of the present invention.
  • Figure 8 is an exemplary diagram showing the implementation of a payment server on a computing device according to an embodiment of the present invention.
  • a product transaction system using an electronic gift certificate includes status information having a status value corresponding to one of status values including unused and used, product information including the product name and product price, Generating gift certificate information including a unique address generated in response to a purchase request for a product corresponding to the product information and an access right token having a preset string form, and processing the unique address, the access right token, and use, Receives a composite address generated based on a request code corresponding to either cancellation of use or cancellation of refund and encrypted with a public key corresponding to the private key from the outside, and decrypts the composite address encrypted with the public key using the private key. , Characterized in that the status information is changed based on the gift certificate information and the complex address.
  • Figure 1 is a diagram illustrating a server system that performs a payment authentication method according to an embodiment of the present invention.
  • the payment server 300 may generate a unique address for payment for a product registered in advance for sale at the store 400 and perform encryption using a private key.
  • the unique address is an API (Application Programming Interface) request URL ( It can be defined as a uniform resource locator address.
  • the store terminal 200 of the store 400 recognizes the information written on the gift certificate presented by the user who visited the store 400, and when the API of the payment server 300 is called using the recognized value, the payment server ( 300) performs internal approval procedures.
  • the payment server 300 determines the authenticity of the gift certificate during the approval process and the user is truly the purchaser, the payment is made by providing approval information to the terminal of the store 400.
  • the payment server 300 may perform asymmetric key-based encryption to verify the authenticity of the issued gift certificate.
  • an asymmetric key uses two keys, but consists of a pair of keys so that the ciphertext encrypted using one key can only be decrypted using the other key.
  • Each key constituting the asymmetric key consists of a pair, and the payment server 300 can store one of the asymmetric keys to prevent it from being leaked as a private key.
  • the public key corresponding to the private key is provided to the outside so that the store 400 or the user can use it for payment.
  • the payment server 300 encrypts the gift certificate issued using the above asymmetric key.
  • the unique address generated for the product requested to be sold by the user is encrypted and provided using a private key, and the store 400 in the payment stage The information received from is decrypted again with the private key to determine whether the unique address matches.
  • the payment server 300 may perform additional encoding operations so that encrypted information consisting of a complex combination of random numbers can be easily recognized through a device including a camera module, such as a smartphone.
  • the payment server 300 may code 17 the unique address to have a specific pixel value according to a predetermined pattern.
  • the code 17 used in this embodiment may be made of two-dimensional pixels in the form of, for example, a QR (Quick Response) code, and the address value encrypted with the above-described unique address is imaged and provided to the user in the form of a gift certificate.
  • QR Quick Response
  • additional information about the product such as store (400) information, product photo, product name, product price, discount status, and discount rate, can be expressed as visual elements. Therefore, the user can select a specific product from among various gift certificates. You can identify the corresponding gift certificate and request payment at the designated store (400).
  • Gift certificates can be purchased by the user selecting a product and paying in advance through an online market or open market-type platform operated by the payment server 300, and the purchased gift certificate is sent to the user terminal 100 according to the user's stored information. is transmitted.
  • the user stores the received gift certificate in the user terminal 100, visits the corresponding store 400, and requests payment for the product.
  • the store 400 may recognize the gift certificate presented through the user terminal 100 using the store terminal 200 provided in the store 400 .
  • the store terminal 200 may include a camera module to recognize the code 17 displayed on the gift certificate.
  • the store terminal 200 can recognize the encrypted ciphertext of the unique address generated by the initial payment server 300 through the code 17 displayed on the gift certificate.
  • the store terminal 200 Since the ciphertext recognized by the store terminal 200 is a direct address that can request an API from the payment server 300 encrypted with a private key, the store terminal 200 performs decryption using the public key received in advance.
  • the store terminal 200 calls the API to the payment server 300 using the decrypted unique address, and creates a combined address to which the identification information of the store 400 or specific service information to be requested through the API is added to make the payment. Payment approval may be requested from the server 300.
  • the store terminal 200 of the store 400 can prevent unauthorized approval through a third party that does not possess the private key by re-encrypting and transmitting the combined address for the API call using the public key.
  • the payment server 300 can perform original proof by decrypting the payment request information received through the above process with a private key and comparing the unique address value in the decrypted plaintext with the value generated when the gift certificate was initially issued.
  • payment approval information is provided to the store terminal 200 in response to the API call.
  • the payment system receives information encrypted using a private key from the store 400 through the QR code 17 and encrypts it using a public key along with additional information provided by the store 400.
  • the payment server 300 receives the received information, allowing payment to be approved through original proof.
  • the payment server 300 generates a first unique value 10 for payment for a product registered in the store 400 (S100).
  • the first unique value 10 may be a unique address generated for each product by the payment server 300 at the request of the store 400.
  • the first eigenvalue 10 may be composed of a random number with bits of a predetermined size, and together with the domain address of the payment server 300, defines a series of actions related to payment, such as payment approval or payment cancellation for products. By combining the values, you can request a service.
  • the payment server 300 generates a first password value 15 by encrypting the generated first unique value 10 with a private key (S200).
  • the payment server 300 encrypts and transmits the first unique value 10 using a private key that has not been leaked to the outside, but the private key For decryption, the original can be proven by performing public key-based encryption through the store terminal.
  • encryption can be performed through a modular operation process for the exponent and the exponent result according to the private key for the first eigenvalue (10), and decryption is performed using the exponent of the public key that has an inverse relationship with the private key. It can be performed through modular operations.
  • a predetermined bit of the predetermined size of the first eigenvalue 10 can be encrypted with a private key, and the generated first password 15 is a visualized code in a form that can be recognized by an image sensor such as a camera module ( 17) is created.
  • the method of generating the code 17 is determined according to the dimension in which the value of the code 17 is defined, and can be generated as a two-dimensional pattern like the QR code 17.
  • the first password value 15 generated through the above process is provided to the user terminal 100 according to the user's request to purchase a gift certificate (S300).
  • the Daum payment server 300 When a user visits the offline store 400 to purchase a physical product through a gift certificate, the Daum payment server 300 recognizes the code 17 generated in the gift certificate on the store terminal 200 of the store 400. You can proceed with the payment request process by doing so.
  • the store terminal 200 decrypts the first encryption value 15 recognized from the provided QR code 17 with the public key corresponding to the private key.
  • the camera module can be executed through a payment application installed on the store terminal 200, and the encrypted first password value 15 can be extracted from the pixel value received from the image sensor of the camera module.
  • the store terminal 200 decrypts the first encryption value 15 using the public key stored in the payment application.
  • the store terminal 200 may receive and secure in advance a public key corresponding to the private key used for encryption of the payment server 300, for example, in the process of registering the sale of a product at the store terminal 200.
  • a public key generated along with the issuance of a token for identification of the store terminal 200 may be received from the payment server 300.
  • the store terminal 200 decrypts the first encryption value 15 recognized from the QR code 17 using a pre-stored public key. As described above, since it can be performed symmetrically with the encryption process, a public key-based exponent operation is performed on the first password value (15), and the second eigenvalue (20) corresponding to the plaintext is extracted through the modular value. .
  • the second unique value 20 contains only information for identification of the product generated by the payment server 300 during the product registration process, so the store terminal 200 uses the second unique value 20
  • An API request URL for payment approval can be created by adding service identification information requesting the actual service and identification information of the store 400 itself.
  • a token for identification of the store 400 itself may be issued in the process of registering the store 400 with the payment server 300, and the payment server 300 may register the product and
  • the corresponding server program in the payment server 300 can be executed later when a payment request is made from the store terminal 200.
  • the service identification information can be set in advance in the payment server 300 by classifying it as a value for distinguishing actions such as payment approval cancellation in addition to requesting payment approval in relation to products in the store 400.
  • the address where the final target program is located can be called through the API.
  • the API call URL for payment approval can be encrypted using a public key and provided to the payment server 300.
  • the encrypted second password value 25 is encrypted with a public key, it can be decrypted only through the private key stored by the corresponding payment server 300, so it is impossible to steal and interpret the URL from the outside, and payment approval can be arbitrarily Blocks provision in response to .
  • the payment server 300 receives the second password value 25 re-encrypted with the public key (S105). .
  • the payment server 300 extracts the second unique value 20 by decrypting it using the private key (S110).
  • the second eigenvalue 20 includes the above-described service identification information and store identification information, decoding can be performed by distinguishing the corresponding bits during the decoding process.
  • the payment server 300 proves the original of the gift certificate by comparing the bit value of the section corresponding to the first unique value 10 generated during the product registration process.
  • the payment server 300 may respond with payment approval information and complete the payment procedure through the store terminal 200. Let it be (S120).
  • the payment authentication method according to the present embodiment is different from the general digital signature method that proves the original of the message by comparing the value decrypted from the signature and the value of the message by providing an encrypted signature and message in the general original proof process, and the payment server (300), the authentication process can be performed through a three-party one-way communication process through an organic relationship between the user terminal 100 and the store terminal 200.
  • security can be increased by providing only the encrypted password value in the form of code 17 to the store terminal 200, and the actual signature is provided through the value decrypted through the value encrypted with the public key on the store terminal 200 side.
  • a more stable payment service can be provided by having the created payment server 300 finally prove the original.
  • the store terminal 200 can register the product by accessing information about the product actually sold to an application or website operated by the payment server 300 (s2).
  • the payment server 300 can first determine the authenticity of the product to register it, and allows the payment amount when the user purchases a gift certificate for the product to be settled at the store 400 after final approval. It is also possible to perform an escrow function between (400) and the user.
  • the payment server 300 can generate a unique value for identification of the registered product (s4), and the unique value is used to request execution of a specific program of the payment server 300 in terms of approving payment through online. It can be used as an API URL address for
  • the payment server 300 can directly generate a token for identification of the store 400 that registered the product (s6), and then the store terminal 200 creates a combined URL address to which the identification information of the store 400 is added. If provided, the program for the store 400 can be executed directly.
  • the payment server 300 can encrypt the unique value with a private key (s8) and generate the encrypted password value as a QR code 17 so that it can be more conveniently recognized at the store 400 (s12).
  • the QR code 17 can be dynamically generated at the time when the user requests to purchase a gift certificate for the product (s10), and through this, the QR code 17 provides information on the purchase time of the gift certificate and the buyer in addition to the password value. It can be created by including additional information.
  • the generated code 17 may be provided to the user terminal 100 of the user who purchased the gift certificate and may be provided as a gift certificate in the form of an electronic image including the above-described code 17 (s14).
  • the user can visit the store 400 and purchase the corresponding product using the gift certificate received on the user terminal 100, and the code 17 of the electronic gift certificate is recognized by the store terminal 200 in response to a request to purchase the gift certificate. It can be started by doing (s16).
  • the store terminal 200 extracts the password value by recognizing the coded pixel information (17) through the image sensor of the camera module (s18).
  • decryption is performed using the public key provided at the time of registration of the product in the payment server 300, and a unique value is extracted (s20).
  • tokens or action URLs for service requests are added as identification information of the store 400, and encryption is performed again with the public key (s22).
  • the password value re-encrypted with the public key is sent to the payment server 300 (s24), and the payment server 300 extracts the unique value decrypted with the private key from the received password value and interacts with the unique value generated at the time of initial product registration. Perform comparison (s28).
  • the payment can be approved and the approval information can be transmitted to the store terminal 200 (s30).
  • the unique address generated when creating a gift certificate is encrypted using a private key and generated in the form of a QR code (17), and then when the electronic gift certificate is distributed, the QR code ( Since the unique address contained in 17) can be decrypted, it can have the effect of proving the issuer/original on the same principle as a digital signature.
  • the payment server 300 may be implemented in the form of a computing device.
  • Each module constituting the payment server 300 is implemented on a general-purpose computing processor, and thus includes a processor 308, input/output I/O 302, memory 340, and interface. It may include 306 and bus 314.
  • the processor 308, input/output device 302, memory 340, and/or interface 306 may be coupled to each other through a bus 314.
  • the bus 314 corresponds to a path along which data moves.
  • the processor 308 includes a Central Processing Unit (CPU), Micro Processor Unit (MPU), Micro Controller Unit (MCU), Graphic Processing Unit (GPU), microprocessor, digital signal processor, microcontroller, and application processor (AP). , application processor) and logic elements capable of performing similar functions.
  • CPU Central Processing Unit
  • MPU Micro Processor Unit
  • MCU Micro Controller Unit
  • GPU Graphic Processing Unit
  • microprocessor digital signal processor
  • microcontroller microcontroller
  • AP application processor
  • application processor application processor
  • the input/output device 302 may include at least one of a keypad, a keyboard, a touch screen, and a display device.
  • the memory device 340 may store data and/or programs.
  • the interface 306 may perform the function of transmitting data to or receiving data from a communication network.
  • Interface 306 may be wired or wireless.
  • the interface 306 may include an antenna or a wired or wireless transceiver.
  • the memory 340 is a volatile operating memory that improves the operation of the processor 308 and protects personal information, and may further include high-speed DRAM and/or SRAM.
  • memory 340 stores programming and data configurations that provide the functionality of some or all of the modules described herein. For example, it may include logic to perform selected aspects of the learning method described above.
  • a program or application is loaded with a set of instructions including each step of performing the above-described learning method stored in the memory 340 and allows the processor to perform each step. For example, an operation of generating a first unique value for payment for a product registered in a store, an operation of encrypting the generated first unique value with a private key to generate a first password value, and the first password value. An operation of generating and providing a visualized code according to a predetermined rule, decrypting the first encryption value recognized from the provided code with a public key corresponding to the private key, and encrypting the extracted second unique value with the public key.
  • a computer program including steps such as performing each step may be performed by a processor.
  • the embodiments described herein include application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), and field programmable gate arrays (FPGAs). In some cases, it may be implemented using at least one of processors, controllers, micro-controllers, microprocessors, and other electrical units for performing functions.
  • ASICs application specific integrated circuits
  • DSPs digital signal processors
  • DSPDs digital signal processing devices
  • PLDs programmable logic devices
  • FPGAs field programmable gate arrays
  • ASICs application specific integrated circuits
  • DSPs digital signal processors
  • DSPDs digital signal processing devices
  • PLDs programmable logic devices
  • FPGAs field programmable gate arrays
  • embodiments such as procedures and functions described in this specification may be implemented as separate software modules.
  • Each of the software modules may perform one or more functions and operations described herein.
  • Software code can be implemented as a software application written in an appropriate programming language.
  • the software code may be stored in a memory module and executed by a control module.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

La présente invention concerne un système de transaction de produit utilisant un certificat de cadeau électronique à authentification de paiement basé sur une clé asymétrique, et un procédé d'authentification de paiement par double chiffrement, qui est mis en œuvre par un serveur de paiement, selon la présente invention, comprend les étapes consistant à : générer une première valeur unique pour un paiement pour un produit enregistré dans un magasin ; générer avec une clé privée une première valeur chiffrée par chiffrement de la première valeur unique générée ; générer et fournir la première valeur chiffrée en tant que code visualisé selon une règle prédéterminée ; recevoir une seconde valeur chiffrée obtenue par chiffrement, avec une clé publique, d'une seconde valeur unique extraite par décodage de la première valeur chiffrée reconnue à partir du code fourni avec la clé publique correspondant à la clé privée ; extraire la seconde valeur unique par déchiffrement de la seconde valeur chiffrée reçue avec la clé privée ; et approuver le paiement en comparant la seconde valeur unique extraite à la première valeur unique générée. Selon la présente invention, une étape d'authentification chiffrée peut être effectuée par l'intermédiaire d'une étape de communication unidirectionnelle entre un serveur de paiement, un terminal utilisateur et un terminal de magasin.
PCT/KR2023/013114 2022-10-12 2023-09-01 Procédé d'authentification de paiement par double chiffrement et serveur de paiement le mettant en œuvre WO2024080556A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020220130511A KR102673516B1 (ko) 2022-10-12 이중 암호화를 통한 결제 인증 방법 및 이를 수행하는 결제서버
KR10-2022-0130511 2022-10-12

Publications (1)

Publication Number Publication Date
WO2024080556A1 true WO2024080556A1 (fr) 2024-04-18

Family

ID=90669611

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2023/013114 WO2024080556A1 (fr) 2022-10-12 2023-09-01 Procédé d'authentification de paiement par double chiffrement et serveur de paiement le mettant en œuvre

Country Status (1)

Country Link
WO (1) WO2024080556A1 (fr)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20110124929A (ko) * 2010-05-12 2011-11-18 브이피 주식회사 모바일 안전 결제 방법 및 시스템
KR20140103019A (ko) * 2013-02-15 2014-08-25 류창화 안전결제코드를 이용한 결제 방법 및 이에 이용되는 안전결제중개서버
KR20160121231A (ko) * 2015-04-10 2016-10-19 (주)인스타페이 이중 암호화를 이용한 사용자 인증 방법과 시스템 및 기록매체
KR20190089861A (ko) * 2016-12-21 2019-07-31 페이스북, 인크. 장치 및 시스템 중립적 전자 결제 토큰의 제공
KR20220044933A (ko) * 2020-11-18 2022-04-12 김재형 무선 간편 결제 방법

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20110124929A (ko) * 2010-05-12 2011-11-18 브이피 주식회사 모바일 안전 결제 방법 및 시스템
KR20140103019A (ko) * 2013-02-15 2014-08-25 류창화 안전결제코드를 이용한 결제 방법 및 이에 이용되는 안전결제중개서버
KR20160121231A (ko) * 2015-04-10 2016-10-19 (주)인스타페이 이중 암호화를 이용한 사용자 인증 방법과 시스템 및 기록매체
KR20190089861A (ko) * 2016-12-21 2019-07-31 페이스북, 인크. 장치 및 시스템 중립적 전자 결제 토큰의 제공
KR20220044933A (ko) * 2020-11-18 2022-04-12 김재형 무선 간편 결제 방법

Also Published As

Publication number Publication date
KR20240050748A (ko) 2024-04-19

Similar Documents

Publication Publication Date Title
US10491379B2 (en) System, device, and method of secure entry and handling of passwords
WO2018194378A1 (fr) Procédé d'approbation de l'utilisation d'une carte à l'aide d'un identifiant de jeton basé sur une chaîne de blocs et serveur l'utilisant
WO2018124857A1 (fr) Procédé et terminal d'authentification sur la base d'une base de données de chaînes de blocs d'un utilisateur sans face-à-face au moyen d'un id mobile, et serveur utilisant le procédé et le terminal
WO2019124610A1 (fr) Procédé d'authentification utilisant une séparation, puis le stockage distribué et combinaison d'informations personnelles utilisant une chaîne de blocs
WO2018194379A1 (fr) Procédé d'approbation de l'utilisation d'une carte à l'aide d'un identificateur de jeton sur la base d'une chaîne de blocs et structure en arbre de merkle associée à celui-ci, et serveur l'utilisant
WO2017119564A1 (fr) Système et procédé de transmission d'informations sécurisées pour une authentification d'identité personnelle
CN110383757A (zh) 用于安全处理电子身份的系统和方法
CN109978688A (zh) 分布式共识系统之访问控制方法及其契约产生器与服务器
WO2018048051A1 (fr) Procédé et système d'authentification de paiement utilisant un générateur de nombres aléatoires quantiques
CN108389059A (zh) 基于权属的数字版权作品保护、交易和发行方法及系统
CN105933119B (zh) 一种认证方法及设备
US20100153273A1 (en) Systems for performing transactions at a point-of-sale terminal using mutating identifiers
TW486902B (en) Method capable of preventing electronic documents from being illegally copied and its system
JPH08166879A (ja) 提供用ソフトウェアの安全性強化方法及び装置
JP2002183633A (ja) 情報記録媒体、情報処理装置および情報処理方法、プログラム記録媒体、並びに情報処理システム
CN104798083A (zh) 用于验证访问请求的方法和系统
WO2020005034A1 (fr) Système de commande de compte de sécurité à signatures multiples
UA113415C2 (xx) Спосіб, сервер і система аутентифікації особи
WO2023163286A1 (fr) Procédé de détection de contrefaçon ou de falsification pour détecter une contrefaçon ou une falsification de nft, qui est effectué par un serveur de plateforme à l'aide d'un nft basé sur une chaîne de blocs
US20210160050A1 (en) Method for establishing anonymous digital identity
CN108449322A (zh) 身份注册、认证方法、系统及相关设备
EA003921B1 (ru) Способ востребования приобретателем исполнения обязательства, связанного с карточкой, и признания этого обязательства эмитентом
CN1333610A (zh) 验证用户的方法
WO2024080556A1 (fr) Procédé d'authentification de paiement par double chiffrement et serveur de paiement le mettant en œuvre
WO2022245069A1 (fr) Système de transaction de commission de cryptomonnaie par dépôt de pièce de monnaie

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23877486

Country of ref document: EP

Kind code of ref document: A1