Nothing Special   »   [go: up one dir, main page]

WO2015180578A1 - 一种可视金融卡的安全支付方法 - Google Patents

一种可视金融卡的安全支付方法 Download PDF

Info

Publication number
WO2015180578A1
WO2015180578A1 PCT/CN2015/079284 CN2015079284W WO2015180578A1 WO 2015180578 A1 WO2015180578 A1 WO 2015180578A1 CN 2015079284 W CN2015079284 W CN 2015079284W WO 2015180578 A1 WO2015180578 A1 WO 2015180578A1
Authority
WO
WIPO (PCT)
Prior art keywords
card
pos
transaction
information
terminal
Prior art date
Application number
PCT/CN2015/079284
Other languages
English (en)
French (fr)
Inventor
刘劲彤
Original Assignee
刘劲彤
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 刘劲彤 filed Critical 刘劲彤
Publication of WO2015180578A1 publication Critical patent/WO2015180578A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/356Aspects of software for card payments
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/409Device specific authentication in transaction processing
    • G06Q20/4097Device specific authentication in transaction processing using mutual authentication between devices and transaction partners

Definitions

  • the invention relates to a secure payment method for a visual financial card, belonging to the fields of smart card, secure payment, data communication and electronic payment.
  • the payment scenario of the existing financial IC card requires the cardholder to interact with the terminal device (typically POS) of the payee.
  • the existing payment process is: the user first inputs a PIN code or password at the terminal (POS). Then, the terminal submits the service data to the financial IC card, and the financial IC card encrypts or signs the data by using the built-in private key, and returns the data to the terminal, and the terminal then sends the transaction information to the card issuing institution, and the card issuing institution judges according to the public key of the financial IC card. The cardholder confirms the transaction and completes the payment process. during this process:
  • Both contact and non-contact financial IC cards are passive devices according to EMV (Europay, MasterCard, VISA) or PBOC (China Standard) specifications. In the payment process, especially in large payments, it is necessary to rely on collection.
  • the party device typically is a POS machine
  • a display card which is characterized by a touch keyboard and a display
  • the visual financial card only uses the display history function, although it provides users with The query is convenient, but the keyboard and display do not participate in the payment process, and the transaction security is not improved.
  • the object of the present invention is to provide a secure payment method for a visual financial card, which can well solve the problem of forging transaction information, inputting a PIN code or paying a password.
  • the visual financial card includes a display screen and a keyboard, it can complete the transaction data display, the function of inputting a password, and it also includes the NFC communication capability, combining these capabilities with existing financial card specifications, enabling a more secure payment method. .
  • the invention adds a card POS software to the visual financial card, uses the keyboard and the display on the card to perform menu selection and information input, calls the financial card application according to the financial card specification, and authenticates the user identity when needed (PIN Or the input of the relevant password); communicate with the external terminal through NFC, the external terminal acts as the communication agent, establishes a communication link between the POS and its affiliated institution, and completes the communication of the transaction information.
  • the financial card application adds cache to the transaction data, allows the visible finance to leave the POS in the transaction, displays the main information of the transaction (such as the transaction amount), and allows the cardholder to reconnect the POS after entering the PIN or payment password on the card. Seal the deal.
  • a secure payment method for a visual financial card which can be visualized by a built-in card POS program of a financial card, the steps of which are:
  • the in-card POS program provides the external terminal with the information of the card application or account participating in the transaction, and the external terminal provides the capability information of the card to the in-card POS; when the external terminal initiates the transaction, the transaction of the terminal is provided to the in-card POS. information;
  • the POS in the card verifies the external terminal capability, and when it is confirmed that the transaction requirement is met, the POS in the card invokes the card application to perform payment, and then encapsulates the return result of the card application into payment request information, and forwards the payment request information to the card through the external terminal.
  • the institution affiliated with the card POS the institution affiliated with the POS in the card submits to the institution to which the card application belongs for transaction processing;
  • the POS affiliate of the card and the card issuer of the card application forward the processing result information to the POS in the card through the external terminal.
  • the in-card POS provides a menu for the cardholder to first select a card application participating in the transaction.
  • the in-card POS after confirming that the transaction requirement is met, the in-card POS generates a transaction verification request for the transaction information, and then forwards the request to the POS affiliate institution of the card through the external terminal; After the transaction verification request verifies the transaction information, the transaction information and the verification information are returned to the POS in the card through the external terminal; the POS in the card verifies the transaction by using a preset certificate of the POS affiliate institution of the card.
  • the information and verification information are displayed, and the transaction information and the verification information are displayed to the cardholder; after the cardholder confirms, the POS in the card invokes the card application for payment.
  • the cardholder confirms the PIN code or payment password entered by the keyboard of the visual financial card.
  • the external terminal if the external terminal is a transaction party, the external terminal connects to the POS affiliate institution of the card through its affiliated institution, and establishes a logical communication channel; when the transaction verification request is transmitted, the external terminal belongs to The institution authenticates the external terminal; after the authentication is passed, the external terminal belongs to the transaction verification request and the external The terminal authentication information is forwarded to the POS affiliation mechanism of the card; wherein the affiliation of the external terminal and the POS affiliation mechanism of the card have a trust relationship.
  • the transaction information is generated by selecting and inputting data through the menu of the in-card POS, or the transaction is obtained by inputting the transaction information on the external terminal and transmitting it to the in-card POS. information.
  • the data connection is an NFC P2P connection.
  • a secure payment method for a visual financial card which is composed of a financial card application and a human card interaction program on a financial card, the steps of which are:
  • the visual financial card establishes a connection with the terminal, and the terminal sends the transaction data to the visible financial card for caching;
  • the human card interaction program displays the cache transaction data to the cardholder, and after receiving the confirmation information input through the visual financial card, the financial card application uses the built-in private key to complete the encryption or signature of the cached transaction data. ;
  • the terminal sends the encrypted or signed data to the card issuing institution of the visible financial card;
  • the card issuing institution verifies the encrypted or signed data by using the public key of the visible financial card, and if the verification passes, the transaction is completed and the information is returned to the terminal, otherwise the transaction is rejected and the information is returned to the terminal;
  • the terminal sends the received return information to the visual financial card
  • the visual financial card presets the public key of the card issuing institution and the private key of the visible card, and the card issuing institution saves the private key of the private key and the visible financial card.
  • the visual financial card waits for the input of the confirmation information after displaying the setting information in the transaction data on its display screen.
  • the confirmation information is a PIN password or a payment password input through a keyboard of the visual financial card.
  • step 2) after the visual financial card disconnects the data from the terminal, the confirmation information is received.
  • the authentication method can be added, and the PIN is input using the keyboard on the card.
  • the terminal When the terminal selects to complete the cardholder authentication according to the authentication method of the visual financial card, the terminal generates challenge data (random number) or transaction information.
  • the implementation method is: adding a verification program to the visual financial card, and the financial card application needs to be modified.
  • the authentication method can be added, and the PIN is input using the keyboard on the card.
  • the terminal When the terminal selects to complete the cardholder authentication according to the authentication method of the visual financial card, the terminal generates challenge data (random number) or transaction information.
  • the payee enters the amount to be paid at the POS;
  • the terminal After reading the basic information of the card, the terminal selects to send the transaction data (amount, currency, payee institution information, terminal identifier, etc.) to the visual financial card, and the visible financial card saves the data in the memory;
  • the cardholder takes the card away from the terminal and opens the power switch of the visual financial card, and confirms the status through the keyboard access transaction.
  • the cardholder checks the main information of the transaction (such as the payment amount) saved in step 3 on the visual financial card, and inputs the PIN code or payment password on the card;
  • the program of the visual financial card uses the built-in private key of the card to complete the payment information. Confirmation, complete signature or encryption in the agreed format, and save it in the built-in memory;
  • the cardholder places the visual financial card in the card state (turns off the power of the visual financial card), and inserts the card into the card reader slot or approaches the non-contact card reading area again;
  • the terminal reads the transaction information return value and obtains the payment information including the card private key signature, and sends the payment information to the card issuing institution;
  • the card issuer uses the cardholder public key certificate to verify the signature or decrypt the transaction data in the transaction data, confirms that the cardholder confirms the transaction, completes the transaction, sends the notification information to the payment terminal or its organization, and forwards it to the visible by the payment terminal.
  • Debit Card uses the cardholder public key certificate to verify the signature or decrypt the transaction data in the transaction data, confirms that the cardholder confirms the transaction, completes the transaction, sends the notification information to the payment terminal or its organization, and forwards it to the visible by the payment terminal.
  • the external terminal is a POS machine or a NFC-enabled wireless terminal (such as a mobile phone, a tablet) and a software client of a payment institution.
  • a POS machine or a NFC-enabled wireless terminal (such as a mobile phone, a tablet) and a software client of a payment institution.
  • the terminal when the terminal is the payee, it needs to connect with the card issuer through its organization, and the terminal belongs to the institution. Verify the identity of the terminal and prove the identity of the payee to the card issuer.
  • the card POS application generates a PKI key pair of the in-card POS when generating the card, and can apply for a digital certificate for it.
  • the card POS retains the private key and the card issuer retains the public key or certificate.
  • the external terminal When the external terminal is the payee, especially when the payee is not using the financial grade POS, such as the NFC mobile phone + payment institution client software, the payee must be authenticated by the payee.
  • the external terminal When the external terminal is not the party to pay, the external terminal can directly connect to the card issuer server, and only serves as the communication agent of the POS in the card.
  • the card POS relies on the communication capability and transaction capability of the terminal.
  • the communication capability refers to the terminal accepting the data transmitted by the NFC, submitting the data to the designated server (in-card POS) according to the communication protocol, and forwarding the data returned by the server to the card through the NFC.
  • Internal POS communication capability also includes the communication capability between the financial institution of the terminal, and the transaction request and payment request of the POS in the card can be sent to the POS affiliate of the card, and the processing result is returned;
  • Transaction ability refers to the ability of the institution to which the terminal belongs and the POS affiliate of the card to support inter-institutional transactions.
  • the information transmission of the terminal identity authentication by the organization to which the terminal belongs is also included; the method flow of the present invention is as shown in the accompanying drawings.
  • the external terminal is the payee and the payment process is:
  • the S103 terminal inputs the payment amount in advance
  • Step S101 the card holder opens the card power supply and sets the card POS working mode through the keyboard; if there are multiple card applications or accounts in the card, the card holder can select the card application or account used in the transaction in step S102;
  • the card is close to the terminal, and the POS in the card and the terminal establish a connection of the NFC P2P;
  • step S105 the POS and the terminal interact with each other to confirm whether the payment behavior can be completed.
  • the card POS informs the terminal of the payment card information; the terminal sends the transaction information to the card POS terminal, and can dynamically change the payee according to the payment card or the account information, and select the mode of paying the minimum commission; the transaction information can be determined by the POS in the card. Menu selection and input data, can also be input on the terminal and passed to the card POS;
  • step S106 selects to perform the card issuer risk assessment
  • the POS in the card generates the complete transaction information in step S107, so that the POS private key signature is encapsulated into an authentication request sent to the POS affiliate institution, and sent to the external terminal for forwarding.
  • the POS affiliates
  • the terminal sends the transaction information to the institution to which the terminal belongs, and the collection institution completes the identity authentication of the terminal;
  • the terminal forwards the verification request to the institution of the POS in the card;
  • Step S108 The card issuing institution in the card performs security verification on the payment institution to determine whether the payment party is safe; after verification, the card issuing institution signs the transaction information and the verification result, and the step S109 is sent to the payment institution and forwarded to the terminal. And sent to the card POS through the NFC connection.
  • step S110 the POS receives the transaction information and verification information of the card issuer, and after verifying the signature of the card issuer, it will pay Easy main information and verification information are displayed to the user through the display on the card;
  • step S111 the user confirms the payment, the POS in the card calls the financial card application according to the financial card application specification, and when the PIN code needs to be input, the user inputs using the card keyboard;
  • the card may leave the terminal; when approaching the terminal again, the in-card POS and the terminal re-establish an NFC P2P connection and continue the previous working session.
  • step S112 the POS in the card returns data according to the financial card application. If the card returns the payment success authentication information or the online authentication information, the POS in the card signs or encrypts the information using the POS private key in the card, and then sends the card to the card through the external terminal. mechanism;
  • Step S113 The financial card issuing institution verifies the online authentication information of the financial card application, and completes the payment by the card issuing institution and the collecting institution according to the payment confirmation information of the financial card and the transaction information of the POS in the card.
  • the financial card issuer also generates a return script.
  • the acquiring mechanism of the card POS (technically, it is allowed to install a plurality of different financial card applications on one card, and there is a possibility that the in-card POS and the financial card application are not the same institution; generally the same as the card issuing institution of the financial card application) Forward, generate payment result information to the receiving institution.
  • step S114 the POS affiliate institution returns the payment result information to the organization to which the terminal belongs and forwards it to the terminal, and forwards it to the in-card POS.
  • the POS in the card receives the payment result and the return information, if the card script is included, the financial card specification is installed to send the script to the financial card application.
  • a method of generating a transaction by a card POS such as using a debit card to complete a transaction for repaying a credit card, the flow is as follows:
  • Step S101 the card holder opens the card power supply and sets the card POS working mode through the keyboard; if there are multiple card applications or accounts in the card, the card holder can select the card application or account used in the transaction in step S102;
  • step S103 the cardholder selects the in-card POS menu; in step 201, the cardholder selects the menu function and inputs the required data.
  • the card is close to the terminal, and the POS in the card and the terminal establish a connection of the NFC P2P;
  • Step S202 the in-card POS receives the capability information of the terminal, and determines whether the terminal supports the communication capability required for the transaction;
  • step S203 the in-card POS generates a transaction.
  • the card application when invoked, when the PIN or password is required, the cardholder can input through the keyboard on the card.
  • step S204 the POS in the card sends the data to the terminal, and the terminal submits the information to the POS affiliate institution.
  • step S205 the POS affiliate institution completes the transaction and returns data (to the terminal and returns to the in-card POS through the NFC P2P interface).
  • step S206 the in-card POS process returns information, such as: displaying the transaction result to the cardholder or calling the card application.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Cash Registers Or Receiving Machines (AREA)

Abstract

一种可视金融卡的安全支付方法。本方法为:1)可视金融卡与终端建立连接,根据该可视金融卡的基本信息与其发卡机构连接,将交易数据发送给该发卡机构;2)该发卡机构用其私钥对该交易数据签名后发送给该终端;3)该终端将该签名数据发送给该可视金融卡;该可视金融卡使用发卡机构公钥验证信息,如果验证通过则通过该可视金融卡输入确认信息,并对该交易数据签名发送给该终端;4)该终端将签名数据发送给发卡机构;发卡机构利用该卡的公钥对该签名数据进行验证,如果验证通过则完成交易,并通过该终端返回信息给该可视金融卡。大大提高了交易支付的安全性。

Description

一种可视金融卡的安全支付方法 技术领域
本发明涉及一种可视金融卡的安全支付方法,属于智能卡、安全支付、数据通讯及电子支付领域。
背景技术
现有的金融IC卡的支付场景,都需要持卡人和收款方的终端设备(典型为POS)进行交互,现有的支付流程是:用户首先在终端(POS)输入PIN码或密码,然后终端再将业务数据提交给金融IC卡,金融IC卡使用内置私钥对数据进行加密或签名,返回给终端,终端再联机向发卡机构发出交易信息,发卡机构根据金融IC卡的公钥判断持卡人确认交易,完成支付流程。在此过程中:
●持卡人查看POS上显示的交易金额
●在POS上输入PIN码,验证持卡人身份
这两个环节中都可以产生安全漏洞,如恶意POS可以:
●显示假的交易金额,而实际交易金额大于显示金额;
●拦截用户PIN输入信息,窃取用户PIN码或支付密码
无论是接触型还非接触型金融IC卡,根据EMV(Europay、MasterCard、VISA)或PBOC(中国标准)的规范都是被动设备,在支付过程中,特别是大额支付时,需要依赖收款方设备(典型的设备是POS机)输入PIN(用户身份码,用于保护持卡人权利),POS上输入PIN或密码成为一种的安全隐患。
目前已经出现了新一代的金融IC卡:可视金融卡(display Card,其特征是包含了触摸键盘和显示屏),但是目前可视金融卡仅采用了显示历史记录功能,虽然为用户提供了查询便利,但其键盘、显示器没有参与支付流程,并没有提高交易安全性。
发明内容
针对现有技术中存在的技术问题,本发明的目的在于提供一种可视金融卡的安全支付方法,可以很好的解决伪造交易信息,输入PIN码或者支付密码的安全问题。
由于可视金融卡包含有显示屏和键盘,可以完成交易数据显示,输入密码的功能,并且它还包括的NFC通讯能力,将这些能力和现有金融卡规范结合,可以实现更加安全的支付方法。
本发明通过在可视金融卡中增加一个卡内POS软件,使用卡上的键盘和显示器,进行菜单选择和信息输入,按金融卡规范调用金融卡应用,需要时则对用户身份进行认证(PIN或相关密码的输入);通过NFC与外部终端通讯,外部终端作为通讯代理,卡内POS和其所属机构之间建立通讯链路,完成交易信息的通讯。
或者:金融卡应用中增加对交易数据的缓存,允许交易中可视金融离开POS,显示交易主要信息(如交易金额),并允许持卡人在卡上输入PIN或支付密码后,重新连接POS完成交易。
本发明的技术方案为:
一种可视金融卡的安全支付方法,可视金融卡内置卡内POS程序,其步骤为:
1)将可视金融卡设置为卡内POS工作状态,当可视金融卡内含有多个卡应用或多个账号时,首先选择参与本次交易的卡应用或账号,然后与外部终端建立数据连接;
2)卡内POS程序向该外部终端提供参与交易的卡应用或账号的信息,该外部终端向卡内POS提供本身能力信息;当该外部终端发起交易时,向卡内POS提供该终端的交易信息;
3)该卡内POS验证该外部终端能力,确认满足交易需求时,该卡内POS调用该卡应用进行支付,然后将该卡应用的返回结果封装为支付请求信息,通过该外部终端转发给该卡内POS所属机构,卡内POS所属机构提交给卡应用所属机构进行交易处理;
4)该卡内POS所属机构及该卡应用的发卡机构将处理结果信息通过该外部终端转发给该卡内POS。
进一步的,当所述可视金融卡中包含多个卡应用,卡内POS提供菜单,让持卡人首先选择参与本次交易的卡应用。
进一步的,所述步骤3)中,确认满足交易需求后,该卡内POS将该交易信息生成交易验证请求,然后通过该外部终端转发给该卡内POS所属机构;该卡内POS所属机构根据该交易验证请求对该交易信息进行验证后,将该交易信息及验证信息通过该外部终端返回给该卡内POS;该卡内POS使用预置的该卡内POS所属机构的证书验证所述交易信息和验证信息,并将交易信息和验证信息显示给持卡人;持卡人确认后,该卡内POS调用该卡应用进行支付。
进一步的,持卡人通过该可视金融卡的键盘输入的PIN密码或支付密码进行确认。
进一步的,所述步骤3)中,如果该外部终端为交易一方时,外部终端通过其所属机构连接所述卡内POS所属机构,建立逻辑通讯通道;传输该交易验证请求时,该外部终端所属机构对该外部终端进行身份认证;认证通过后由该外部终端所属机构将该交易验证请求及外 部终端认证信息转发给该卡内POS所属机构;其中,该外部终端所属机构和卡内POS所属机构存在信任关系。
进一步的,所述步骤2)中,通过该卡内POS的菜单选择并输入数据生成交易信息,或者通过在该外部终端上输入所述交易信息并将其发送给该卡内POS获取所述交易信息。
进一步的,所述数据连接为NFC P2P连接。
一种可视金融卡的安全支付方法,在金融卡上由金融卡应用及人卡交互程序组成,其步骤为:
1)可视金融卡与终端建立连接,该终端将交易数据发送给该可视金融卡进行缓存;
2)人卡交互程序将缓存交易数据显示给持卡人,需要时接收到通过该可视金融卡输入的确认信息后,金融卡应用使用内置私钥完成对缓存的该交易数据进行加密或签名;
3)该可视金融卡将该加密或签名数据发送给该终端;
4)该终端将该加密或签名数据发送给该可视金融卡的发卡机构;
5)该发卡机构利用该可视金融卡的公钥对该加密或签名数据进行验证,如果验证通过,则完成交易并返回信息给该终端,否则拒绝交易并返回信息给该终端;
6)该终端将收到的返回信息发送给该可视金融卡;
其中,可视金融卡预置发卡机构的公钥和可视卡私钥,发卡机构保存自己的私钥和可视金融卡的公钥。
进一步的,该可视金融卡先在其显示屏上显示该交易数据中的设定信息后等待输入所述确认信息。
进一步的,所述确认信息为通过该可视金融卡的键盘输入的PIN密码或支付密码。
进一步的,步骤2)中,该可视金融卡与该终端断开数据连接后,接收所述确认信息。
现有技术相比,本申请的技术优点:
1、提高了安全性,用户可以完全相信发卡机构(如银行)的可视金融卡,无需依赖安全的收款方设备。
2、可以在非安全支付环境中,安全支付。
附图说明
附图为本发明的方法流程图。
具体实施方式
下面以为用户持卡人使用可视金融卡在POS上支付为例,说明本发明的流程:
在可视金融卡的基础信息中可以增加认证方式,使用卡上键盘输入PIN。
终端根据可视金融卡的认证方式,选择完成持卡人认证时,由终端产生挑战数据(随机数)或交易信息。
实施例1:
实施方法是:在可视金融卡上增加一个验证程序,金融卡应用需要修改。在可视金融卡的基础信息中可以增加认证方式,使用卡上键盘输入PIN。
终端根据可视金融卡的认证方式,选择完成持卡人认证时,由终端产生挑战数据(随机数)或交易信息。
1.收款方在POS上输入待支付金额;
2.持卡人确认后,将可视金融卡置于卡状态(关闭卡电源),卡片插入终端的读卡器插槽或接近非接触读卡区(非接触方式);可视金融卡工作于卡状态;
3.终端读取卡基本信息后,选择将交易数据(金额、币种、收款方机构信息,终端标识符等)发送给可视金融卡,可视金融卡将数据保存在存储器中;
4.持卡人将卡片拿离终端,并打开可视金融卡的电源开关,并通过键盘接入交易确认状态。持卡人在可视金融卡上查看步骤3中保存的交易主要信息(如支付金额),并在卡片上输入PIN码或支付密码;可视金融卡的程序使用卡内置私钥完成对支付信息的确认,按约定格式完成签名或加密,保存在内置存储器中;
5.持卡人将可视金融卡置于卡状态(关闭可视金融卡的电源),再次将卡片插入读卡器插槽或接近非接触读卡区;
6.终端读取交易信息返回值获得包含卡私钥签名的支付信息,发送给发卡机构;
7.发卡机构使用持卡人公钥证书验证交易数据中签名或解密交易数据,确认持卡人确认交易后,完成交易,发送通知信息给支付终端或其机构,并由支付终端转发给可视金融卡。
这种实施方式需要对金融卡应用规范进行修改,相应的POS处理流程也需要修改,实现难道较大。
实施例2:
外部终端为POS机或支持NFC的无线终端(如手机、平板)及收款机构的软件客户端。根据支付的方式不同,终端为收款方时,需要和通过其机构与发卡机构对接,终端所属机构 验证终端身份,并向发卡机构证明收款方身份。
卡内POS应用在生成卡片时生成了卡内POS的PKI密钥对,并可以为其申请数字证书。卡内POS保留私钥,发卡机构保留公钥或证书。
外部终端是收款方时,特别是收款方不是使用金融级POS时,如NFC手机+收款机构客户端软件时,需要通过收款机构对收款方进行身份认证。外部终端不是支付的一方时,外部终端可以直接连接发卡机构服务器,仅仅作为卡内POS的通讯代理。
卡内POS依赖终端的通讯能力和交易能力,通讯能力指终端接受NFC传递的数据,按通讯协议,将数据提交给(卡内POS)指定服务器,并将服务器返回的数据,通过NFC转发给卡内POS;通讯能力还包括终端所属机构支持金融机构间的通讯能力,可以将卡内POS的交易请求和支付请求发送到卡内POS所属机构,并返回处理结果;
交易能力是指终端所属机构和卡内POS所属机构,支持机构间交易的能力。本方案中,还包括终端所属机构对终端身份认证的信息传递;本发明的方法流程如附图所示。
外部终端为收款方,支付过程为:
1.S103终端预先输入支付金额;
2.步骤S101持卡人打开卡电源,并通过键盘设置为卡内POS工作模式;如果卡内存在多个卡应用或账号,步骤S102持卡人可以选择本次交易使用的卡应用或账号;
3.卡片接近终端,卡内POS和终端建立NFC P2P的连接;
4.步骤S105卡内POS和终端交互双方能力,确认是否可以完成支付行为;
5.卡内POS通知终端支付卡信息;终端将交易信息发给卡内POS终端可以根据支付卡或账号信息,动态改变收款方,选择支付佣金最少的方式;交易信息可以由卡内POS的菜单选择并输入数据,也可以在终端上输入并传递给卡内POS;
6.当步骤S106选择进行发卡机构风险评估,则步骤S107卡内POS生成完整交易信息,使卡内POS私钥签名,封装成发送给卡内POS所属机构的验证请求,发送给外部终端请求转发给卡内POS所属机构;
终端将交易信息发给终端所属机构‐收款机构,收款机构完成对终端的身份认证后;
终端将验证请求转发给卡内POS所属机构;
步骤S108卡内POS的发卡机构对收款机构进行安全验证,判断收款方是否安全;通过验证后,发卡机构对交易信息和验证结果进行签名,步骤S109发给收款机构并转发给终端,并通过NFC连接发送给卡内POS。
7.步骤S110卡内POS收到发卡机构交易信息及验证信息,验证发卡机构签名后,将交 易主要信息和验证信息,通过卡上显示器显示给用户;
8.步骤S111用户确认支付后,卡内POS根据金融卡应用规范,调用金融卡应用,当需要输入PIN码时,用户使用卡键盘输入;
9.上述7‐8步骤时,卡片可能离开终端;再次接近终端时,卡内POS和终端重新建立NFC P2P连接,并继续之前的工作会话。
10.步骤S112卡内POS根据金融卡应用返回数据,如果卡返回了支付成功认证信息或联机认证信息,卡内POS将上述信息使用卡内POS私钥签名或加密后,通过外部终端发送给发卡机构;
11.步骤S113金融卡发卡机构验证金融卡应用的联机认证信息,根据金融卡的支付确认信息及卡内POS的交易信息,完成发卡机构和收款机构的支付。如果是联机认证,金融卡发卡机构还要生成返回脚本。卡内POS的收单机构(技术上,允许一张卡上安装多个不同的金融卡应用,存在卡内POS和金融卡应用不是同一机构的可能性;一般和金融卡应用的发卡机构相同)转发,生成给收款机构的支付结果信息。
12.步骤S114卡内POS所属机构将支付结果信息返回给终端所属机构并转发到终端,转发到卡内POS。
13.步骤S115卡内POS收到支付结果和返回信息后,如果包括卡脚本则安装金融卡规范将脚本发给金融卡应用。
实施例3:
由卡内POS生成交易的方法,如使用借记卡完成对信用卡还款的交易,流程如下:
1.步骤S101持卡人打开卡电源,并通过键盘设置为卡内POS工作模式;如果卡内存在多个卡应用或账号,步骤S102持卡人可以选择本次交易使用的卡应用或账号;
2.步骤S103,持卡人选择卡内POS菜单;步骤201,持卡人选择菜单功能并输入所需数据。
3.卡片接近终端,卡内POS和终端建立NFC P2P的连接;
4.步骤S202,卡内POS接收终端的能力信息,判断终端是否支持交易所需的通讯能力;
5.步骤S203,卡内POS生成交易,当调用卡应用时,需要输入PIN或密码时,持卡人可通过卡上键盘输入。
6.步骤S204,卡内POS将数据发送给终端,终端提交给卡内POS所属机构。
7.步骤S205,卡内POS所属机构完成交易,返回数据(给终端并通过NFC P2P接口返回到卡内POS)。
步骤S206,卡内POS处理返回信息,如:显示交易结果给持卡人或调用卡应用等。

Claims (10)

  1. 一种可视金融卡的安全支付方法,由可视金融卡内置卡内POS程序、卡应用和外部终端及其各自所属机构共同实现,其步骤为:
    1)将可视金融卡设置为卡内POS工作状态,当可视金融卡内含有多个卡应用或多个账号时,首先通过菜单选择参与本次交易的卡应用或账号,然后与外部终端建立数据连接;
    2)卡内POS程序向该外部终端提供参与交易的卡应用或账号的信息,该外部终端向卡内POS提供本身能力信息;当该外部终端发起交易时,向卡内POS提供该终端的交易信息;卡内POS验证该外部终端能力,确认满足交易需求时开始交易处理;
    3)卡内POS将交易信息显示给持卡人,持卡人确认后,该卡内POS调用该卡应用进行支付,然后将该卡应用的返回结果封装为支付请求信息;
    4)支付请求信息通过该外部终端转发给该卡内POS所属机构,卡内POS所属机构提交给卡应用所属机构进行交易处理;
    5)该卡内POS所属机构及该卡应用的发卡机构将处理结果信息通过该外部终端转发给该卡内POS,卡内POS使用返回数据对卡应用进行相应处理。
  2. 如权利要求1所述的方法,其特征在于所述步骤1)卡内POS还提供菜单,提供和卡应用相关的业务功能选择,并输入功能所需参数,生成交易信息。
  3. 如权利要求1或2所述的方法,其特征在于所述步骤3),如果需要卡内POS所属机构进行交易风险评估,卡内POS将该交易信息生成交易验证请求,然后通过该外部终端转发给该卡内POS所属机构;该卡内POS所属机构根据该交易验证请求对该交易信息进行验证后,将该交易信息及验证信息通过该外部终端返回给该卡内POS;该卡内POS使用预置的该卡内POS所属机构的证书验证所述交易信息和验证信息。
  4. 如权利要求1所述的方法,其特征在所述步骤3)于持卡人通过该可视金融卡的键盘输入的PIN密码或支付密码进行确认。
  5. 如权利要求3所述的方法,其特征在于,如果该外部终端为交易一方时,外部终端通过其所属机构连接所述卡内POS所属机构,建立逻辑通讯通道;传输该交易验证请求时,该外部终端所属机构对该外部终端进行身份认证;认证通过后由该外部终端所属机构将该交易验证请求及外部终端认证信息转发给该卡内POS所属机构;其中,该外部终端所属机构和卡内POS所属机构存在信任关系。
  6. 如权利要求1或2所述的方法,其特征在于所述步骤2)中,通过该卡内POS的菜单选择并输入数据生成交易信息,或者通过在该外部终端上输入所述交易信息并将其发送给该卡 内POS获取所述交易信息。
  7. 如权利要求1所述的方法,其特征在于所述数据连接为NFC P2P连接。
  8. 一种可视金融卡的安全支付方法,其步骤为:
    1)可视金融卡与终端建立连接,该终端将交易数据发送给该可视金融卡进行缓存;
    2)该可视金融卡接收到通过该可视金融卡输入的确认信息后,使用内置私钥完成对缓存的该交易数据进行加密或签名;
    3)该可视金融卡将该加密或签名数据发送给该终端;
    4)该终端将该加密或签名数据发送给该可视金融卡的发卡机构;
    5)该发卡机构利用该可视金融卡的公钥对该加密或签名数据进行解密验证,如果验证通过,则完成交易并返回信息给该终端,否则拒绝交易并返回信息给该终端;
    6)该终端将收到的返回信息发送给该可视金融卡;
    其中,可视金融卡预置发卡机构的公钥和可视卡私钥,发卡机构保存自己的私钥和可视金融卡的公钥。
  9. 如权利要求8所述的方法,其特征在于该可视金融卡先在其显示屏上显示该交易数据中的设定信息后等待输入所述确认信息。
  10. 如权利要求8或9所述的方法,其特征在于所述确认信息为通过该可视金融卡的键盘输入的PIN密码或支付密码。
PCT/CN2015/079284 2014-05-30 2015-05-19 一种可视金融卡的安全支付方法 WO2015180578A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2014102394544 2014-05-30
CN201410239454.4A CN104021473A (zh) 2014-05-30 2014-05-30 一种可视金融卡的安全支付方法

Publications (1)

Publication Number Publication Date
WO2015180578A1 true WO2015180578A1 (zh) 2015-12-03

Family

ID=51438213

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/079284 WO2015180578A1 (zh) 2014-05-30 2015-05-19 一种可视金融卡的安全支付方法

Country Status (2)

Country Link
CN (1) CN104021473A (zh)
WO (1) WO2015180578A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112288422A (zh) * 2020-10-29 2021-01-29 珠海优特物联科技有限公司 一种数字货币交易方法及装置
US20210312431A1 (en) * 2020-04-06 2021-10-07 Mastercard Asia/Pacific Pte. Ltd. Method and system for use of an emv card in a multi-signature wallet for cryptocurrency transactions

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104021473A (zh) * 2014-05-30 2014-09-03 刘劲彤 一种可视金融卡的安全支付方法
CN105490708B (zh) * 2015-12-09 2018-01-23 广东欧珀移动通信有限公司 一种读写智能卡的方法及装置
CN107230078B (zh) * 2016-03-25 2020-12-15 中国人民银行数字货币研究所 使用可视数字货币芯片卡进行数字货币支付的方法和系统
CN107230073B (zh) * 2016-03-25 2021-03-16 中国人民银行数字货币研究所 在可视数字货币芯片卡之间支付数字货币的方法和系统
CN105897721B (zh) * 2016-05-03 2019-01-25 广州广电运通金融电子股份有限公司 验证金融卡用户身份可靠性的方法及装置
CN106339874B (zh) * 2016-08-11 2019-03-15 飞天诚信科技股份有限公司 一种联机交易方法、可视金融ic卡、客户端和服务器
CN106529925A (zh) * 2016-10-27 2017-03-22 飞天诚信科技股份有限公司 一种蓝牙可视卡及实现电子现金交易的方法
CN106603239B (zh) * 2016-11-11 2018-06-26 飞天诚信科技股份有限公司 一种基于蓝牙可视卡的主账户余额查询方法及蓝牙可视卡
CN109427157B (zh) * 2017-08-22 2021-03-26 佛山市顺德区顺达电脑厂有限公司 金融交易支付之触控计算机装置及其管理方法
CN110119946B (zh) * 2018-02-05 2022-12-13 库币科技有限公司 电子交易装置的配对认证方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020091646A1 (en) * 2000-11-03 2002-07-11 Lake Lawrence L. Method and system for verifying the identity of on-line credit card purchasers through a proxy transaction
CN102096972A (zh) * 2009-12-15 2011-06-15 中国移动通信集团公司 一种基于用户终端完成联机支付的方法、系统及用户终端
CN102298718A (zh) * 2011-07-07 2011-12-28 天速特信息科技(上海)有限公司 多功能金融ic可视卡
CN102542323A (zh) * 2010-11-16 2012-07-04 北京中电华大电子设计有限责任公司 一种多功能的可视智能卡
CN104021473A (zh) * 2014-05-30 2014-09-03 刘劲彤 一种可视金融卡的安全支付方法

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2009018683A1 (fr) * 2007-08-08 2009-02-12 Kamfu Wong Méthode et système de paiement à certification par carte à puce doté d'un écran et d'un clavier, utilisant un code chiffré dynamique à usage unique
SK288757B6 (sk) * 2008-09-19 2020-05-04 Smk Kk Systém a spôsob bezkontaktnej autorizácie pri platbe
US20110010254A1 (en) * 2009-07-07 2011-01-13 Chenot Richard H Transaction processing systems and methods for per-transaction personal financial management
CN107730240B (zh) * 2011-09-09 2021-03-26 成都天钥科技有限公司 多因子多信道id认证和交易控制及多选项支付系统及方法
CN103136668A (zh) * 2011-11-28 2013-06-05 中兴通讯股份有限公司 终端支付方法、终端和支付平台
WO2014030875A1 (en) * 2012-08-24 2014-02-27 Samsung Electronics Co., Ltd. Apparatus and method for providing interaction information by using image on device display
CN102968717A (zh) * 2012-11-07 2013-03-13 华为技术有限公司 一种电子支付方法、相关设备及系统
CN103198401B (zh) * 2013-03-06 2016-09-14 天地融科技股份有限公司 具有电子签名功能的智能卡交易方法及系统
CN103258264A (zh) * 2013-06-06 2013-08-21 李万君 基于nfc的支付方法和设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020091646A1 (en) * 2000-11-03 2002-07-11 Lake Lawrence L. Method and system for verifying the identity of on-line credit card purchasers through a proxy transaction
CN102096972A (zh) * 2009-12-15 2011-06-15 中国移动通信集团公司 一种基于用户终端完成联机支付的方法、系统及用户终端
CN102542323A (zh) * 2010-11-16 2012-07-04 北京中电华大电子设计有限责任公司 一种多功能的可视智能卡
CN102298718A (zh) * 2011-07-07 2011-12-28 天速特信息科技(上海)有限公司 多功能金融ic可视卡
CN104021473A (zh) * 2014-05-30 2014-09-03 刘劲彤 一种可视金融卡的安全支付方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210312431A1 (en) * 2020-04-06 2021-10-07 Mastercard Asia/Pacific Pte. Ltd. Method and system for use of an emv card in a multi-signature wallet for cryptocurrency transactions
CN112288422A (zh) * 2020-10-29 2021-01-29 珠海优特物联科技有限公司 一种数字货币交易方法及装置

Also Published As

Publication number Publication date
CN104021473A (zh) 2014-09-03

Similar Documents

Publication Publication Date Title
WO2015180578A1 (zh) 一种可视金融卡的安全支付方法
JP7536751B2 (ja) 非接触カードの暗号化認証のためのシステムおよび方法
JP7467432B2 (ja) 非接触カードの暗号化認証のためのシステムおよび方法
US11620647B2 (en) Provisioning of access credentials using device codes
CN107210918B (zh) 用于使用基于交易特定信息的令牌和密码的交易处理的装置和方法
TWI792284B (zh) 用於驗證對安全裝置功能性之線上存取之方法
CN111582859B (zh) 用于进行销售点交易的方法、电子设备和介质
JP7483688B2 (ja) 非接触カードの暗号化認証のためのシステムおよび方法
US20110103586A1 (en) System, Method and Device To Authenticate Relationships By Electronic Means
AU2019351911A1 (en) Systems and methods for cryptographic authentication of contactless cards
CN102118251B (zh) 基于多界面安全智能卡的网上银行远程支付的安全认证方法
US20190347661A1 (en) Coordinator managed payments
US20150142669A1 (en) Virtual payment chipcard service
AU2013298189A1 (en) Issuing and storing of payment credentials
CN111386688B (zh) 用于防范中继攻击的系统和方法
EP3861510A1 (en) Systems and methods for cryptographic authentication of contactless cards
US20150142667A1 (en) Payment authorization system
US20120173433A1 (en) Method and system for providing financial service
JP2019525645A (ja) 暗号認証とトークン化されたトランザクション
GB2519143A (en) Virtual POS System and Method
CN106330888A (zh) 一种保证互联网线上支付安全性的方法及装置
CN201947283U (zh) 基于多界面安全智能卡的网上银行远程支付的安全认证装置
KR20170007601A (ko) 복합금융단말기, 복합금융단말기를 이용한 복합금융서비스 시스템 및 그 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15799949

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 31.03.2017)

122 Ep: pct application non-entry in european phase

Ref document number: 15799949

Country of ref document: EP

Kind code of ref document: A1