[go: up one dir, main page]

HK1209510B - Methods and systems for accessing account information electronically - Google Patents

Methods and systems for accessing account information electronically Download PDF

Info

Publication number
HK1209510B
HK1209510B HK15110147.4A HK15110147A HK1209510B HK 1209510 B HK1209510 B HK 1209510B HK 15110147 A HK15110147 A HK 15110147A HK 1209510 B HK1209510 B HK 1209510B
Authority
HK
Hong Kong
Prior art keywords
customer
computing device
account information
received
information
Prior art date
Application number
HK15110147.4A
Other languages
Chinese (zh)
Other versions
HK1209510A1 (en
Inventor
A.沃尔伯格-斯多克
S.O.阿尔菲里
D.瓦拉卡利
S.拉哈特
W.布朗宁
Original Assignee
花旗银行,全国协会(N.A.)
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US13/780,666 external-priority patent/US9027109B2/en
Application filed by 花旗银行,全国协会(N.A.) filed Critical 花旗银行,全国协会(N.A.)
Publication of HK1209510A1 publication Critical patent/HK1209510A1/en
Publication of HK1209510B publication Critical patent/HK1209510B/en

Links

Description

用于电子地存取账户信息的方法和系统Method and system for electronically accessing account information

技术领域Technical Field

本发明总体上涉及金融账户信息管理领域,并且更具体来说涉及用于电子地存取账户信息的方法和系统。The present invention relates generally to the field of financial account information management, and more particularly to methods and systems for electronically accessing account information.

背景技术Background Art

客户在购物的时候可能不时地想确切地知道他们在其各种账户中有多少可用的资金或信用及其最近的交易。目前,想要通过移动装置获得此类信息的银行客户通常必需执行鉴定过程,每当这些客户存取该信息时,该鉴定过程通常要求输入用户ID和密码。一些银行客户可以被允许使用与其在网上银行上使用的相同的用户ID和密码在移动装置上存取信息,但是其他客户可能必需使用不同的用户ID和密码在移动装置上存取其余额和近来的交易信息。While shopping, customers may occasionally want to know exactly how much funds or credit they have available in their various accounts and their recent transactions. Currently, bank customers who wish to obtain this information via their mobile devices must typically perform an authentication process that requires entering a user ID and password each time they access this information. Some bank customers may be allowed to access information on their mobile devices using the same user ID and password they use for online banking, but other customers may need to use a different user ID and password to access their balance and recent transaction information on their mobile devices.

在任一种情况下,例如在商场购物的客户可能想相对频繁地检查他或她的余额,以便确保有足够的资金或信用来为购物付款。这样就必需在他或她的移动装置上重复地键入客户的用户名和密码。而且,大多金融机构为客户密码设置了一些标准,这些标准要求有不常见的字符,这些不常见的字符可能让在客户的移动装置上键入密码的过程变得更加复杂。因此,在移动装置的小键盘或触摸屏上键入密码,可能难以处理而且很费时间。In any case, for example, a customer shopping at a mall may want to check their balance relatively frequently to ensure they have sufficient funds or credit to pay for their purchases. This necessitates repeatedly entering their username and password on their mobile device. Furthermore, most financial institutions set standards for customer passwords that require the use of uncommon characters, which can complicate the process of entering a password on a customer's mobile device. Consequently, entering a password on a mobile device's keypad or touchscreen can be awkward and time-consuming.

过去,金融机构为了给客户提供方便,进行了一些相对小幅的改进,诸如,允许客户选择在使用他或她的用户ID和密码登入之后,使会话在有限的一段时间内保持打开。因此,客户可以被允许在客户登入之后使会话长度稍微延长,超过一般给会话分配的时长。此外,一些金融机构已经有动向允许不输入密码就能存取客户的账户信息的一些有限的方面。然而,这样的服务会带来严重程度的风险,诸如将客户的账户信息暴露给未经授权的人。In the past, financial institutions have implemented some relatively minor improvements to provide convenience to customers, such as allowing customers to choose to keep their sessions open for a limited period of time after logging in with their user ID and password. Thus, customers may be allowed to extend their sessions slightly beyond the typical allotted time after logging in. Furthermore, some financial institutions have been moving toward allowing limited access to customer account information without entering a password. However, such services carry significant risks, such as exposing customer account information to unauthorized individuals.

目前,需要用于电子地存取账户信息的方法和系统,这些方法和系统为诸如银行之类金融机构的忙碌的客户提供高度的便利(这些客户想不需要重复地执行复杂的登入过程就能快速且容易地得知其账户上有多少资金或信用),同时,这些方法和系统还提供了多项控制,以确保客户信息的安全性得到安全地保持。Currently, there is a need for methods and systems for electronically accessing account information that provide a high degree of convenience to busy customers of financial institutions, such as banks, who want to quickly and easily know how much money or credit is in their accounts without having to repeatedly perform complex log-in procedures, while also providing multiple controls to ensure that the security of customer information is securely maintained.

发明内容Summary of the Invention

本发明的实施例采用计算机硬件和软件,包括但不限于耦接至存储器和非暂时性计算机可读存储媒体的一个或多个处理器,所述存储器和非暂时性计算机可读存储媒体上存储着一个或多个可执行程序,所述一个或多个可执行程序指示处理器实施本文中说明的方法和系统。本发明的实施例提供用于电子地存取账户信息的方法和系统,所述方法可以包含(例如)使用后端服务器的处理器经由计算装置的至少一个属性和存储在计算装置上的加密的令牌将计算装置与客户的简档绑定。Embodiments of the present invention employ computer hardware and software, including but not limited to one or more processors coupled to a memory and a non-transitory computer-readable storage medium having stored thereon one or more executable programs that instruct the processors to implement the methods and systems described herein. Embodiments of the present invention provide methods and systems for electronically accessing account information, which may include, for example, using a processor of a backend server to bind a computing device to a customer's profile via at least one attribute of the computing device and an encrypted token stored on the computing device.

然后,使用后端服务器的处理器,可以接收鉴定请求,所述鉴定请求至少部分地由计算装置的至少一个属性和存储在计算装置上的加密的令牌组成。同样使用后端服务器的处理器,可以确定在预定的先前时间间隔内是否接收到客户凭证的输入。也使用后端服务器的处理器,当确定在预定的先前时间间隔内接收到客户凭证的输入时,在不要求输入客户凭证的情况下可以在计算装置上显示预定义的客户账户信息。Then, using the processor of the backend server, an authentication request may be received, the authentication request being composed at least in part of at least one attribute of the computing device and an encrypted token stored on the computing device. Also using the processor of the backend server, a determination may be made as to whether entry of client credentials has been received within a predetermined previous time interval. Also using the processor of the backend server, when it is determined that entry of client credentials has been received within the predetermined previous time interval, predefined client account information may be displayed on the computing device without requiring entry of client credentials.

在本发明的实施例的一方面中,绑定计算装置可以包含(例如)只有在从客户接收到选择接受选择时才将计算装置与客户的简档绑定。在另一个方面中,绑定计算装置可以包含(例如)只有在从客户接收到选择接受选择的确认时才绑定计算装置。在另外的方面中,绑定计算装置可以包含(例如)在从客户接收到选择接受选择之后,每当从客户接收到选择退出选择时,就停用计算装置的绑定。In one aspect of embodiments of the present invention, binding the computing device may include, for example, binding the computing device to the client's profile only upon receiving an opt-in selection from the client. In another aspect, binding the computing device may include, for example, binding the computing device only upon receiving confirmation of the opt-in selection from the client. In yet another aspect, binding the computing device may include, for example, deactivating binding of the computing device whenever an opt-out selection is received from the client after receiving the opt-in selection from the client.

在本发明的实施例的另外方面中,绑定计算装置可以包含(例如)每当从客户接收到更改客户凭证的请求时,就停用计算装置的绑定。在又另一个方面中,客户凭证可以包括(例如)客户密码。在又另一个方面中,绑定计算装置可以包含(例如)每当接收到将不同的计算装置与客户的简档绑定的请求时,就停用计算装置的绑定。In another aspect of an embodiment of the present invention, binding a computing device may include, for example, deactivating the binding of the computing device whenever a request is received from a client to change client credentials. In yet another aspect, the client credentials may include, for example, a client password. In yet another aspect, binding a computing device may include, for example, deactivating the binding of the computing device whenever a request is received to bind a different computing device to a client's profile.

在本发明的实施例的另一个方面中,至少一个计算装置属性可以包括(例如)唯一计算装置识别符。在其他方面中,计算装置可以包括(例如)移动通信装置,并且至少一个计算装置属性可以包括移动网络识别符。在其他方面中,加密的令牌可以包括(例如)使用哈希算法加密的令牌。In another aspect of embodiments of the present invention, the at least one computing device attribute may include, for example, a unique computing device identifier. In other aspects, the computing device may include, for example, a mobile communication device, and the at least one computing device attribute may include a mobile network identifier. In other aspects, the encrypted token may include, for example, a token encrypted using a hash algorithm.

在本发明的实施例的另一个方面中,确定是否接收到客户凭证的输入可以包含(例如)确定在预定的先前时间间隔内是否至少一次接收到客户凭证的输入。在另外的方面中,确定是否接收到客户凭证的输入可以包含(例如)确定在前十五天内是否至少一次接收到客户凭证的输入。In another aspect of an embodiment of the present invention, determining whether input of customer credentials has been received may include, for example, determining whether input of customer credentials has been received at least once within a predetermined previous time interval. In another aspect, determining whether input of customer credentials has been received may include, for example, determining whether input of customer credentials has been received at least once within the previous fifteen days.

在本发明的实施例的又另一个方面中,显示预定义的客户账户信息可以包含(例如)在计算装置上显示非个人身份客户账户信息。在另一个方面中,显示非个人身份客户账户信息可以包含(例如)在计算装置上显示非个人身份客户支票、储蓄和信用卡账户信息。在其他方面中,显示非个人身份客户支票账户信息可以包含(例如)在计算装置上显示部分支票账户识别符和支票账户的一个或多个可用余额。在另外其他方面中,部分支票账户识别符可以包括(例如)支票账号的预定部分。In yet another aspect of embodiments of the present invention, displaying predefined customer account information can include, for example, displaying non-personally identifiable customer account information on a computing device. In another aspect, displaying non-personally identifiable customer account information can include, for example, displaying non-personally identifiable customer checking, savings, and credit card account information on a computing device. In other aspects, displaying non-personally identifiable customer checking account information can include, for example, displaying a partial checking account identifier and one or more available balances of the checking account on a computing device. In still other aspects, the partial checking account identifier can include, for example, a predetermined portion of the checking account number.

在本发明的实施例的又另一个方面中,显示非个人身份客户储蓄账户信息可以包含(例如)在计算装置上显示部分储蓄账户识别符和一个或多个储蓄账户余额。在另外的方面中,所述部分储蓄账户识别符可以包括(例如)储蓄账号的预定部分。在另一个方面中,显示非个人身份客户信用卡账户信息可以包含(例如)在计算装置上显示部分信用卡账户识别符、一个或多个信用卡账户余额。在又另一个方面中,部分信用卡账户识别符可以包括(例如)信用卡账号的预定部分。In yet another aspect of embodiments of the present invention, displaying non-personally identifiable customer savings account information may include, for example, displaying a portion of a savings account identifier and one or more savings account balances on a computing device. In further aspects, the portion of the savings account identifier may include, for example, a predetermined portion of the savings account number. In another aspect, displaying non-personally identifiable customer credit card account information may include, for example, displaying a portion of a credit card account identifier and one or more credit card account balances on a computing device. In yet another aspect, the portion of the credit card account identifier may include, for example, a predetermined portion of the credit card account number.

在本发明的实施例的另外的方面中,显示非个人身份客户账户信息可以包含(例如)在计算装置上显示预定数目的交易的非个人身份客户账户交易信息。在另一个方面中,预定数目的交易可以包括(例如)最近十五笔交易。在又另一个方面中,显示预定义的客户账户信息可以包含(例如)拒绝在未输入客户凭证的情况下接收到的客户交易请求。In further aspects of embodiments of the present invention, displaying non-personally identifiable customer account information can include, for example, displaying non-personally identifiable customer account transaction information for a predetermined number of transactions on a computing device. In another aspect, the predetermined number of transactions can include, for example, the fifteen most recent transactions. In yet another aspect, displaying predefined customer account information can include, for example, rejecting a customer transaction request received without entering customer credentials.

本发明的这些方面和其他方面部分地将在下文的说明中得到阐述,并且部分地在本领域的技术人员审查下文后将对其变得更加明显,或者可以通过实践本发明而获悉。希望所有这些方面都包括在本说明里面,在本发明的范围内,并且受到所附权利要求书的保护。These and other aspects of the present invention will be set forth in part in the following description and in part will become apparent to those skilled in the art upon examination of the following or may be learned through practice of the present invention. It is intended that all such aspects be included within this description, be within the scope of the present invention, and be protected by the appended claims.

附图说明BRIEF DESCRIPTION OF THE DRAWINGS

图1是图解说明经由本发明的实施例的预览应用能够存取的信息类型的示例的图表;1 is a diagram illustrating an example of the types of information that can be accessed by a preview application via an embodiment of the present invention;

图2是图解说明在未输入客户的密码的情况下打开本发明的实施例的预览应用后能够存取的菜单项的示例的截屏;2 is a screenshot illustrating an example of menu items that can be accessed after opening the preview application of an embodiment of the present invention without entering a customer's password;

图3A和图3B是图解说明本发明的实施例的预览应用的主屏的示例的截屏;3A and 3B are screenshots illustrating examples of a home screen of a preview application according to an embodiment of the present invention;

图4和图5是图解说明本发明的实施例的预览应用的支票总账视图和储蓄总账视图的示例的截屏;4 and 5 are screenshots illustrating examples of a checking ledger view and a savings ledger view of a preview application according to an embodiment of the present invention;

图6是图解说明本发明的实施例的预览应用的信用卡总账视图的示例的截屏;6 is a screenshot illustrating an example of a credit card ledger view of a preview application according to an embodiment of the present invention;

图7是图解说明本发明的实施例的基于客户的卡片关系的一份优惠的示例的截屏;FIG7 is a screenshot illustrating an example of an offer based on a customer's card relationship in accordance with an embodiment of the present invention;

图8是图解说明在本发明的实施例的预览登记过程中将客户的移动装置绑定到客户的简档的过程的示例的流程图;8 is a flow chart illustrating an example of a process of binding a customer's mobile device to a customer's profile during a preview registration process of an embodiment of the present invention;

图9A至图9D是图解说明本发明的实施例的预览登入画面的方面的示例的截屏;9A-9D are screenshots illustrating examples of aspects of a preview login screen according to an embodiment of the present invention;

图10是图解说明本发明的实施例的关键组件的示例概况和关键组件之间的信息流的示意图;以及FIG10 is a schematic diagram illustrating an example overview of key components of an embodiment of the present invention and the flow of information between the key components; and

图11是图解说明使用本发明的实施例的预览应用来存取客户账户信息的过程的示例的流程图。11 is a flow diagram illustrating an example of a process for accessing customer account information using a preview application of an embodiment of the present invention.

具体实施方式DETAILED DESCRIPTION

现在将具体参照本发明的实施例,附图中图解说明了这些实施例的一个或多个示例。每个示例是通过说明本发明而不是限制本发明的方式提供的。本领域的技术人员将明白的是,可以对本发明作出各种修改和变化,而并不背离本发明的范围或精神。例如,作为一个实施例的一部分图解说明或描述的特征可以用于另一个实施例中,得到又一个实施例。因此,希望本发明涵盖属于本发明的范围内的这类修改和变化。Reference will now be made in detail to embodiments of the present invention, one or more examples of which are illustrated in the accompanying drawings. Each example is provided by way of illustration, not limitation, of the present invention. It will be appreciated by those skilled in the art that various modifications and variations may be made to the present invention without departing from the scope or spirit of the invention. For example, features illustrated or described as part of one embodiment may be used in another embodiment to yield yet another embodiment. Therefore, it is intended that the present invention encompass such modifications and variations as fall within the scope of the invention.

本发明的实施例为诸如银行之类金融机构的忙碌的客户提供空前程度的便利(这些客户想不需要重复地执行复杂的登入过程就能快速且容易地得知其账户上有多少资金),同时,本发明的实施例还提供了多项控制,以确保客户信息的安全性得到安全地保持。本发明的实施例允许金融机构的客户粗略浏览看到例如他们在其所有存款账户和信用卡上的当前余额,并且看到他们有多少资金可供消费,并且无需每当他们存取这类信息时都要输入其密码。此外,本发明的实施例同样还允许这些客户无需每次都输入其密码就能看到他们最近的交易。本发明的实施例不需要每次都在客户的移动装置上键入他或她的密码以存取最近的信息,而是只要求客户在移动装置上周期性地刷新和重新打开应用。Embodiments of the present invention provide an unprecedented level of convenience for busy customers of financial institutions, such as banks, who want to quickly and easily see how much money is in their accounts without having to repeatedly perform complex log-in procedures, while also providing multiple controls to ensure that the security of customer information is securely maintained. Embodiments of the present invention allow customers of financial institutions to see, at a glance, their current balances on all of their deposit accounts and credit cards, and see how much money they have available for spending, without having to enter their password each time they access such information. Furthermore, embodiments of the present invention also allow these customers to see their most recent transactions without having to enter their password each time. Rather than requiring the customer to enter his or her password on their mobile device each time to access recent information, embodiments of the present invention only require the customer to periodically refresh and reopen the application on the mobile device.

因此,本发明的实施例在全局移动应用内提供一种“预览”(sneak peek)模式,每当客户在例如客户的移动装置上进入该应用时,该模式允许客户“随时地”预览余额和最近交易。在本发明的实施例中,仅提供非个人身份信息,并且仅将这些信息提供给这样的客户:其选择接受预览服务,并且接着在预定时间间隔期间至少一次(诸如,每十五天至少一次)在预览应用中成功地输入客户的密码。Thus, embodiments of the present invention provide a "sneak peek" mode within the global mobile application that allows customers to preview their balances and recent transactions "on the fly" whenever they access the application, for example, on their mobile device. In embodiments of the present invention, only non-personally identifiable information is provided, and this information is only provided to customers who opt-in to the preview service and who then successfully enter their password into the preview application at least once during a predetermined time interval (e.g., at least once every fifteen days).

本发明的实施例的一个重要方面要求客户必须选择接受以确保客户愿意参与。在“仅选择接受”方面,例如,可以在首次登录本发明的实施例的预览应用时要求客户选择接受该服务。然后,客户可能能够经由设置菜单随时改变其预览选择接受/选择退出状态。因此,当客户第一次登入时,向客户建议本发明的实施例的特征。如果客户未选择接受和立即注册本发明的实施例的预览应用,则可以给客户机会在以后的时机注册。An important aspect of embodiments of the present invention is that they require the customer to opt-in to ensure their willingness to participate. In an "opt-in-only" approach, for example, the customer can be asked to opt-in to the service upon first logging into a preview application of embodiments of the present invention. The customer may then be able to change their preview opt-in/opt-out status at any time via a settings menu. Thus, when the customer first logs in, the features of embodiments of the present invention are suggested to the customer. If the customer does not choose to accept and immediately register for the preview application of embodiments of the present invention, the customer may be given the opportunity to register at a later time.

本发明的实施例的预览应用的另一个安全特征(例如)确保能够存取的仅有的信息类型包括账户余额和预定数目的最近交易,诸如最近十五笔交易。此外,在预览模式中,可能根本不允许客户执行任何交易。可以显示非个人身份信息,并且在未输入客户的密码的情况下可能不允许任何人从本发明的实施例的预览应用内执行任何种类的任何资金流动。Another security feature of the preview application of embodiments of the present invention ensures, for example, that the only types of information that can be accessed include account balances and a predetermined number of recent transactions, such as the last fifteen transactions. Furthermore, in preview mode, the customer may not be allowed to perform any transactions at all. Non-personally identifiable information may be displayed, and no one may be allowed to perform any type of fund movement from within the preview application of embodiments of the present invention without entering the customer's password.

如果客户选择接受并且注册了本发明的实施例的预览应用,他或她然后可能无须输入客户的密码就能够经由客户的移动装置存取他或她的某些账户信息。因此,本发明的实施例让客户能够看到(例如):支票账户信息,包括账户名和一个或多个可用余额;储蓄账户信息,包括账户名和一个或多个可用余额;以及信用卡信息,包括持卡人姓名和一个或多个卡片额度,还有持有金融机构信用卡账户的客户的商户优惠。If a customer chooses to accept and register for a preview application of an embodiment of the present invention, he or she may then be able to access certain of his or her account information via the customer's mobile device without having to enter the customer's password. Thus, embodiments of the present invention allow a customer to view, for example: checking account information, including account name and one or more available balances; savings account information, including account name and one or more available balances; and credit card information, including cardholder name and one or more card limits, as well as merchant offers for customers who hold a credit card account with a financial institution.

图1是图解说明经由本发明的实施例的预览应用能够存取的信息类型的示例的图表。参照图1,可以使用预览功能性存取的余额信息100可以包括(例如):客户的信用卡账户102的账号后四位数、当前欠结、和可用信用额度;客户的支票账户104的账号后四位数、存款金额、和可用金额;以及客户的储蓄账户106的账号后四位数、存款金额、可用金额、和年初至今的利息。进一步参照图1,可以使用预览功能性存取的欠款信息108可包括(例如)客户的信用卡账户102的欠款金额、最低还款额和还款日期。FIG1 is a diagram illustrating an example of the type of information that can be accessed via a preview application according to an embodiment of the present invention. Referring to FIG1 , balance information 100 that can be accessed using the preview functionality can include, for example: the last four digits of the account number, the current balance, and the available credit limit for a customer's credit card account 102; the last four digits of the account number, the amount on deposit, and the available balance for a customer's checking account 104; and the last four digits of the account number, the amount on deposit, the available balance, and the year-to-date interest for a customer's savings account 106. Further referring to FIG1 , balance information 108 that can be accessed using the preview functionality can include, for example, the amount on deposit, the minimum payment, and the payment date for a customer's credit card account 102.

再次参照图1,可以使用预览功能性存取的账户历史信息110可以包括(例如)涉及到客户的信用卡账户102、支票账户104或储蓄账户106中的任一个的最多最近十五笔交易。本发明的实施例的移动应用为客户提供真正差异化的移动银行体验,利用动态的方式让客户接触和存取客户的金融信息。允许选择接受该功能的客户存取高级的非个人身份账户信息,可以利用移动电话的如下性质:移动电话一般每天大多数时间都在移动电话使用者个人的身上或附近,并且是使用者之间一般不会共享的一种个人装置。Referring again to FIG. 1 , the account history information 110 that can be accessed using the preview functionality may include, for example, up to the most recent fifteen transactions involving any of the customer's credit card account 102, checking account 104, or savings account 106. The mobile application of embodiments of the present invention provides customers with a truly differentiated mobile banking experience, providing dynamic access to and storage of their financial information. Enabling customers who opt in to this functionality to access advanced, non-personally identifiable account information can take advantage of the fact that mobile phones are typically on or near the user's person for most of the day and are personal devices that are not typically shared between users.

选择接受使用本发明的实施例的预览应用的客户在打开应用后无需每次输入客户的密码就可以存取各种功能性。图2是图解说明打开本发明的实施例的预览应用后在未输入客户的密码的情况下能够存取的菜单项的示例的截屏200。参照图2,客户在打开本发明的实施例的预览应用后在未输入密码的情况下能够存取的全部功能性菜单项可以包括(例如)支行定位器202、常见问题帮助204、联系金融机构206、和累计奖励积分显示208。然而,当在本发明的实施例的预览应用中时,可能不允许客户使用设置按钮210来更新设置。登入/退出菜单项212让客户能够通过输入客户的密码而登入,于是让客户能够存取完整的预览应用,并且执行另外的活动,诸如支付、转账、存入支票和查看全部交易。Customers who choose to accept the use of the preview application of an embodiment of the present invention can access various functionalities without having to enter their password each time after opening the application. FIG2 is a screenshot 200 illustrating an example of menu items that can be accessed after opening the preview application of an embodiment of the present invention without entering the customer's password. Referring to FIG2 , the full range of functional menu items that a customer can access after opening the preview application of an embodiment of the present invention without entering a password may include, for example, a branch locator 202, FAQ help 204, contact the financial institution 206, and a cumulative reward points display 208. However, while in the preview application of an embodiment of the present invention, the customer may not be allowed to update settings using the settings button 210. A log in/out menu item 212 enables the customer to log in by entering the customer's password, thereby allowing the customer to access the full preview application and perform additional activities such as making payments, transferring money, depositing checks, and viewing all transactions.

图2的截屏上示出的主屏菜单项214可以允许客户在打开本发明的实施例的预览应用后无需输入客户的密码就能访问主屏。图3A和图3B是图解说明本发明的实施例的预览应用的主屏300的示例的截屏。主屏300提供对包括(例如)支票302、储蓄304和信用卡306在内的所有账户类型的可用余额信息的存取。对于支票账户302,主屏300可以提供账户名和一个或多个可用余额。对于储蓄账户304,主屏300可以提供账户名和一个或多个可用余额。对于信用卡账户306,主屏300可以提供持卡人姓名和一个或多个信用卡额度。The home screen menu item 214 shown in the screenshot of FIG2 may allow a customer to access the home screen without entering the customer's password after opening the preview application of an embodiment of the present invention. FIG3A and FIG3B are screenshots illustrating an example of a home screen 300 of the preview application of an embodiment of the present invention. The home screen 300 provides access to available balance information for all account types, including, for example, checking 302, savings 304, and credit card 306. For a checking account 302, the home screen 300 may provide the account name and one or more available balances. For a savings account 304, the home screen 300 may provide the account name and one or more available balances. For a credit card account 306, the home screen 300 may provide the cardholder name and one or more credit card limits.

图4和图5分别是图解说明在打开本发明的实施例的预览应用后无需每当客户使用预览应用存取信息时重新输入客户的密码就能够存取的支票总账视图400和储蓄总账视图500的示例的截屏。支票总账视图400和储蓄总账视图500分别可以提供(例如)一个或多个可用余额402、一个或多个可用余额502和预定数目的(诸如十五笔)最近未出账和已出账支票账户交易404和储蓄账户交易504的交易信息。所显示的支票账户交易信息和储蓄账户交易信息可以包括(例如)交易金额、交易描述和每笔交易的日期。请注意,本发明的实施例不限于对最近交易和余额信息的数字式显示。也可以采用对相同信息的视觉表示或者对这类信息的任何其他的合适的表示。根据本发明的实施例,账户信息不是个人身份信息,并且在未输入客户的密码的情况下,不能存取更多的账户详情。Figures 4 and 5 are screenshots illustrating examples of a checking account view 400 and a savings account view 500, respectively, that can be accessed after opening a preview application according to an embodiment of the present invention without re-entering the customer's password each time the customer accesses information using the preview application. The checking account view 400 and the savings account view 500 may provide, for example, one or more available balances 402 and one or more available balances 502, respectively, and transaction information for a predetermined number (e.g., fifteen) of the most recent unposted and posted checking account transactions 404 and savings account transactions 504. The displayed checking account transaction information and savings account transaction information may include, for example, transaction amounts, transaction descriptions, and the date of each transaction. It should be noted that embodiments of the present invention are not limited to digital display of recent transaction and balance information. Visual representations of the same information or any other suitable representation of such information may also be employed. According to embodiments of the present invention, account information is not personally identifiable information, and further account details cannot be accessed without entering the customer's password.

图6是图解说明在打开本发明的实施例的预览应用后无需每当客户使用预览应用存取信息时重新输入客户的密码就能够存取的信用卡总账视图600的示例的截屏。信用卡总账视图600可以提供(例如)可用额度602、当前欠结604、最低还款额和还款日期606、以及预定数目的(诸如十五笔)最近未出账交易和已出账交易的交易信息608。所显示的信用卡交易信息608可以包括(例如)每笔交易的金额、交易描述和购买日期。在本发明的实施例的信用卡总账视图600中,不提供更多的交易详情或账户详情。如前所述,持有信用卡账户的客户可能还能够看到基于其具体卡片关系可供其使用的优惠。图7是图解说明基于客户的卡片关系的优惠700的示例的截屏。FIG6 is a screenshot illustrating an example of a credit card ledger view 600 that can be accessed after opening a preview application according to an embodiment of the present invention, without requiring the customer to re-enter their password each time they access information using the preview application. Credit card ledger view 600 may provide, for example, available credit 602, current balance 604, minimum payment amount and payment date 606, and transaction information 608 for a predetermined number (e.g., fifteen) of the most recent unbilled and billed transactions. The displayed credit card transaction information 608 may include, for example, the amount, transaction description, and purchase date of each transaction. In credit card ledger view 600 according to an embodiment of the present invention, no further transaction details or account details are provided. As previously mentioned, customers holding credit card accounts may also be able to view offers available to them based on their specific card relationships. FIG7 is a screenshot illustrating an example of offers 700 based on a customer's card relationships.

如前所述,本发明的实施例提供多种控制方面以保证客户的信息的安全性得到安全地保持。在选择确认方面中,每当客户重新启动客户的移动装置、更新应用或在15天未输入客户的密码的时间段到期之后输入客户的密码时,可以向客户提醒客户的安全偏好,并且要求客户重新确认他或她的偏好以便继续操作。确认选择方面保证客户熟悉并且知晓客户的安全偏好。又一个方面是持久选择退出选项,即一直能够经由应用显示的设置菜单来选择退出本发明的实施例的预览应用功能性。因此,可以允许客户选择退出本发明的实施例的特征,并且将来将不提示客户选择接受这类特征。As previously mentioned, embodiments of the present invention provide a variety of control aspects to ensure that the security of a customer's information is securely maintained. In the opt-in confirmation aspect, each time a customer restarts the customer's mobile device, updates an application, or enters the customer's password after a period of 15 days has expired in which the customer's password has not been entered, the customer may be reminded of the customer's security preferences and asked to reconfirm his or her preferences in order to proceed. The opt-in confirmation aspect ensures that the customer is familiar with and aware of the customer's security preferences. Yet another aspect is a persistent opt-out option, i.e., the ability to opt-out of the preview application functionality of embodiments of the present invention at all times via a settings menu displayed by the application. Thus, a customer may be allowed to opt-out of features of embodiments of the present invention and will not be prompted to opt-in to such features in the future.

此外,选择接受的客户可以通过经由任何其他计算装置(包括移动装置)登录和更改客户的网上密码来停用本发明的实施例的预览特征。例如,假设选择接受的客户丢失了他或她的移动装置,并且即使未经授权的第三方将不能使用客户的移动装置存取客户的任何个人身份账户信息,客户也会顾虑安全性。例如,通过允许客户更改客户的网上密码,而允许客户立即停用本发明的实施例的预览应用的特征,可以解决这样的顾虑。Furthermore, opt-in customers can disable the preview features of embodiments of the present invention by logging in and changing their online password via any other computing device (including a mobile device). For example, suppose an opt-in customer loses their mobile device and is concerned about security, even though an unauthorized third party would not be able to use the customer's mobile device to access any of the customer's personally identifiable account information. This concern can be addressed, for example, by allowing the customer to change their online password while immediately disabling the preview features of embodiments of the present invention.

银行和卡片的客服代理可能能够向手机丢失或钱包被窃的客户提供指导。例如,可以将打来电话的客户引导到网上银行预览应用以更改其密码,从而远程地停用本发明的实施例的应用功能性。因此,客户可能能够通过使用不同的接触点访问网上银行服务器和简单地更改客户的密码来远程地停用预览应用功能性。替代地,客服代表可能能够按照客户的请求停用客户的用户ID。此外,客户的移动装置如果带有“找回我的手机”特征,则客户可以启用客户的装置上的“找回我的手机”特征,并且如果找不到手机,就用密码远程地锁定他或她的装置,并且客户还可以远程地销毁其移动装置上的数据。Customer service agents at banks and credit cards may be able to provide guidance to customers whose phones have been lost or whose wallets have been stolen. For example, a calling customer may be directed to the online banking preview application to change their password, thereby remotely deactivating the application functionality of embodiments of the present invention. Thus, a customer may be able to remotely deactivate the preview application functionality by simply changing the customer's password using a different contact point to access the online banking server. Alternatively, a customer service representative may be able to deactivate the customer's user ID at the customer's request. In addition, if the customer's mobile device has a "find my phone" feature, the customer can enable the "find my phone" feature on the customer's device and remotely lock his or her device with a password if the phone is lost. The customer can also remotely destroy the data on his or her mobile device.

在另一个方面中,对客户的网上银行凭证有任何更改,都可以停用预览功能性,并且要求客户在打开预览应用时输入他或她的密码。在密码更改的情况下,可能不提示客户继续进行预览选择接受流,而是可以改为提示客户验证他或她的关于客户的记住的用户ID的客户设置和预览设置。在用户ID更改的情况下,可以提示客户继续进行完整的预览选择接受流以实现预览功能性。In another aspect, any change to the customer's online banking credentials may disable the preview functionality and require the customer to enter his or her password when opening the preview application. In the event of a password change, the customer may not be prompted to proceed with the preview opt-in flow, but instead may be prompted to verify his or her customer settings and preview settings for the customer's remembered user ID. In the event of a user ID change, the customer may be prompted to proceed with the full preview opt-in flow to enable the preview functionality.

在另外一个安全方面中,如前所述,客户在预定时间间隔中必须输入其密码至少一次(诸如,每十五天一次),以便让本发明的实施例的预览应用的功能性保持活动。应当理解的是,重新输入客户的密码的这个周期性调度不限于每十五天一次,而是可以是任何其他重新输入次数和任何其他合适的时间间隔。例如,如果客户选择接受预览应用的功能性,但是然后十五天内没有输入他或她的密码(通过执行交易,查看要求客户输入他或她的密码的信息,或者通过经由应用菜单主动选择电子地登入),那么下一次客户打开应用时,将要求他或她输入他或她的密码以满足15天的密码要求。一旦客户输入他或她的密码,就可以提醒客户他或她的偏好,包括客户选择接受本发明的实施例的功能性的偏好,并且如果客户的偏好已经改变的话,则可以给客户机会选择退出。In another security aspect, as previously described, the customer must enter their password at least once within a predetermined time interval (e.g., once every fifteen days) in order for the functionality of the preview application of embodiments of the present invention to remain active. It should be understood that this periodic schedule for re-entering the customer's password is not limited to once every fifteen days, but can be any other number of re-entries and any other suitable time interval. For example, if a customer chooses to accept the functionality of the preview application, but then does not enter his or her password within fifteen days (by performing a transaction, viewing a message requiring the customer to enter his or her password, or by actively choosing to log in electronically via the application menu), then the next time the customer opens the application, he or she will be required to enter his or her password to satisfy the 15-day password requirement. Once the customer enters his or her password, the customer can be reminded of his or her preferences, including the customer's preference to accept the functionality of embodiments of the present invention, and can be given an opportunity to opt out if the customer's preferences have changed.

另一方面,如果客户选择接受预览功能性,并且启动应用且输入客户的密码(通过执行要求这个输入的活动,请求查看要求这个输入的信息,或者每十五天至少一次经由应用菜单主动选择登入),则客户将已经满足15天的登入要求。因此,只要客户继续至少每十五天满足这个要求,本发明的实施例的预览应用就不会另外强制要求客户输入密码。On the other hand, if the customer chooses to accept the preview functionality and launches the application and enters the customer's password (by performing an activity requiring such input, requesting to view information requiring such input, or actively selecting to log in via the application menu at least once every fifteen days), the customer will have satisfied the 15-day login requirement. Therefore, as long as the customer continues to meet this requirement at least every fifteen days, the preview application of embodiments of the present invention will not further force the customer to enter a password.

在另一个安全方面中,允许客户每次仅在一台装置上登记本发明的实施例的预览应用的功能性。因此,如果客户试图从另一台装置选择接受该功能性,则可以立即在先前登记的装置上停用预览应用功能性。此外,在完成新装置上的登记之前,可以向试图在其他装置上登记的客户呈现一条通知,告知他或她新的登记将使客户先前登记的装置的登记失效。因此,如果客户有两台或更多台移动装置可以供他或她存取他或她的账户,则客户限于仅为这些装置中的一台登记本发明的实施例的预览特征。如果客户为他或她的这些移动装置之一登记了预览功能性,后来又想换成另一台装置,则这样做的话将会停用先前登记的装置,以便登记这台其他装置。In another security aspect, a customer is permitted to register for the preview application functionality of embodiments of the present invention on only one device at a time. Thus, if a customer attempts to opt-in to the functionality from another device, the preview application functionality can be immediately deactivated on the previously registered device. Furthermore, before completing registration on the new device, the customer attempting to register on the other device can be presented with a notification informing him or her that the new registration will invalidate the registration for the customer's previously registered device. Thus, if a customer has two or more mobile devices through which he or she can access his or her account, the customer is limited to registering for the preview features of embodiments of the present invention on only one of these devices. If a customer registers for the preview functionality on one of his or her mobile devices and later decides to switch to another device, doing so will deactivate the previously registered device in order to register the other device.

在另一个安全方面中,每当登记过的移动装置被重新启动或重新开机,或者客户升级或更新本发明的实施例的预览应用的先前版本,就要求客户重新输入他或她的密码以便继续使用本发明的特征。在装置重新启动方面,每当客户重新启动他或她的移动装置时,下一次客户打开本发明的实施例的预览应用时,可能就会提示客户输入他或她的密码。在应用更新方面,每当客户用应用的较新的版本来升级预览应用时,就可能要求客户输入他或她的密码。在任一方面中,在启动预览应用并输入客户的密码后,可以向客户提醒他或她的偏好,包括客户选择接受本发明的实施例的功能性的偏好,并且如果客户的偏好已经改变,则可以给客户机会选择退出。In another security aspect, each time a registered mobile device is restarted or powered on again, or a customer upgrades or updates a previous version of a preview application of an embodiment of the present invention, the customer may be required to re-enter their password in order to continue using the features of the present invention. In the device restart aspect, each time a customer restarts their mobile device, the next time the customer opens a preview application of an embodiment of the present invention, the customer may be prompted to enter their password. In the application update aspect, each time a customer upgrades the preview application with a newer version of the application, the customer may be required to enter their password. In either aspect, after launching the preview application and entering the customer's password, the customer may be reminded of their preferences, including the customer's preference to accept functionality of an embodiment of the present invention, and may be given an opportunity to opt out if their preferences have changed.

本发明的实施例的一个重要的安全方面(例如)包括将客户的实物装置(诸如客户的移动电话)紧紧地绑定到客户个人简档。图8是图解说明在本发明的实施例的登记过程中将客户的移动装置绑定到客户的简档的过程的示例的流程图。参照图8,在S1,在登记过程中,使用诸如金融机构处理器之类的处理器,接收客户的用户ID;客户的移动装置的唯一装置识别符,诸如媒体访问控制(MAC)地址、国际移动台设备标识码(IMEI)、或其他移动设备识别符(MEID);以及客户的移动装置处理器的网络详情。An important security aspect of embodiments of the present invention, for example, includes tightly binding a customer's physical device (such as the customer's mobile phone) to the customer's personal profile. FIG8 is a flow chart illustrating an example of a process for binding a customer's mobile device to the customer's profile during a registration process in an embodiment of the present invention. Referring to FIG8 , at S1, during a registration process, a processor, such as a financial institution processor, is used to receive a customer's user ID; a unique device identifier for the customer's mobile device, such as a Media Access Control (MAC) address, International Mobile Equipment Identity (IMEI), or other Mobile Equipment Identifier (MEID); and network details for the customer's mobile device processor.

进一步参照图8,在S2,在接收到这个信息后,同样使用处理器,可以基于诸如基于哈希的消息鉴定码(HMAC)的算法、使用诸如安全哈希算法SHA256之类的算法用当前时戳和随机数作为输入来生成加密的令牌。请注意,本发明的实施例不限于使用HMAC-SHA256算法,并且可以采用任何其他合适的加密方法或算法。此外,本发明的实施例可以采用或对称或不对称的加密。再次参照图8,在S3,也使用处理器,可以将加密的令牌发送回客户的移动装置处理器,该移动装置处理器然后可以存储接收到的令牌。此外,使用处理器,可以存储客户的移动装置属性和加密的令牌,以便每当客户打开应用时,对本发明的实施例的预览应用功能性的鉴定执行验证。With further reference to FIG8 , at S2 , upon receiving this information, also using a processor, an encrypted token may be generated based on an algorithm such as a Hash-based Message Authentication Code (HMAC), using an algorithm such as the Secure Hash Algorithm SHA256, with the current timestamp and a random number as input. Note that embodiments of the present invention are not limited to the use of the HMAC-SHA256 algorithm, and any other suitable encryption method or algorithm may be employed. Furthermore, embodiments of the present invention may employ either symmetric or asymmetric encryption. Referring again to FIG8 , at S3 , also using a processor, the encrypted token may be sent back to the customer's mobile device processor, which may then store the received token. Furthermore, using a processor, the customer's mobile device attributes and the encrypted token may be stored so that verification of the authentication of the preview application functionality of embodiments of the present invention may be performed each time the customer opens the application.

然后,再次参照图8,在S4,每当客户打开本发明的实施例的预览应用时,在鉴定过程期间,使用处理器,可以从客户的移动装置处理器接收在登记过程期间发送到客户的装置的信息,包括(例如)客户的用户ID、客户的唯一装置识别符、客户的网络详情和加密的令牌。请注意,可以在令牌信息中包括网络详情,以便使得在客户丢失了他或她的移动装置的情况下,金融机构能够远程地停用本发明的实施例的特征。在S5,使用处理器,可以用所存储的信息来验证接收到的加密的令牌和装置属性,以保证请求是相同的装置发出的。如果用户ID或密码更改,则令牌验证过程可能会失败,并且可以通知客户要求客户使用他或她的密码继续执行正常的登入过程。Then, referring again to Figure 8, at S4, each time a customer opens a preview application of an embodiment of the present invention, during the authentication process, using the processor, information sent to the customer's device during the registration process can be received from the customer's mobile device processor, including (for example) the customer's user ID, the customer's unique device identifier, the customer's network details, and an encrypted token. Note that the network details can be included in the token information so that the financial institution can remotely disable the features of an embodiment of the present invention in the event that the customer loses his or her mobile device. At S5, using the processor, the received encrypted token and device attributes can be verified using the stored information to ensure that the request was made by the same device. If the user ID or password changes, the token verification process may fail, and the customer can be notified to continue the normal login process using his or her password.

本发明的实施例的网络详情要求方面可以识别何时在没有蜂窝或Wi-Fi连接的情况下访问预览应用,并且可以在下一次在重新建立蜂窝或Wi-Fi连接之后访问该应用时要求重新鉴定。又另一个安全方面可以包含(例如)一个主开关,该主开关允许金融机构对金融机构的所有客户完全停用预览服务。在主开关方面中,不是在逐个客户的基础上停用预览功能性,而是如果发生了任何类型的违规导致需要停用所有客户的该功能性,则主开关方面可以允许金融机构停用这个功能性。又另一个安全方面可以包含(例如)选择性控制,其允许金融机构在选择性基础上(例如,在客户的移动装置号码更换的情况下)为金融机构的一个或多个客户停用本发明的实施例的特征。The network detail requirement aspect of an embodiment of the present invention can identify when a preview application is accessed without a cellular or Wi-Fi connection and can require re-authentication the next time the application is accessed after a cellular or Wi-Fi connection is re-established. Yet another security aspect can include, for example, a master switch that allows a financial institution to completely disable the preview service for all of the financial institution's customers. In the master switch aspect, rather than disabling the preview functionality on a customer-by-customer basis, the master switch aspect can allow the financial institution to disable this functionality if any type of violation occurs that requires disabling this functionality for all customers. Yet another security aspect can include, for example, a selective control that allows a financial institution to disable features of an embodiment of the present invention for one or more of the financial institution's customers on a selective basis (e.g., if a customer's mobile device number changes).

应当理解的是,使用本发明的实施例的预览特征,可以不执行涉及到客户的任何账户的诸如支付、转账或存款之类的任何类型的交易。因此,为了执行一个或多个交易,诸如进行支付或设置客户的账户之间的资金转账,客户必须输入他或她的密码。如果客户使用本发明的实施例的特征来存取他或她的账户信息并且决定进行支付,那么客户然后必须输入他或她的密码以继续并进行这样的支付。其他可能要求客户输入客户的密码的动作可以包括(例如)编辑或删除已安排的支付;执行资金转账交易;或存取与投资、退休账户、信用额度、贷款、抵押、交易账户或企业账户有关的信息。可能要求客户输入客户的密码的另外的动作可以包括(例如)收款人模块(包括收款人的支付信息汇总)的支付、移动支票存款、存取预定数目的最近交易之前的交易、或者存取交易或账户详情。It should be understood that using the preview features of embodiments of the present invention, any type of transaction, such as a payment, transfer, or deposit, involving any of the customer's accounts may not be performed. Therefore, in order to perform one or more transactions, such as making a payment or setting up a funds transfer between the customer's accounts, the customer must enter his or her password. If the customer uses features of embodiments of the present invention to access his or her account information and decides to make a payment, the customer must then enter his or her password to proceed and make such a payment. Other actions that may require the customer to enter the customer's password may include, for example, editing or deleting a scheduled payment; executing a funds transfer transaction; or accessing information related to investments, retirement accounts, lines of credit, loans, mortgages, trading accounts, or business accounts. Additional actions that may require the customer to enter the customer's password may include, for example, payments to a payee module (including a summary of the payee's payment information), mobile check deposits, accessing transactions prior to a predetermined number of recent transactions, or accessing transaction or account details.

图9A至图9D是图解说明本发明的实施例的登入画面900的方面的示例的截屏。参照图9A至图9D,在首次登录过程中,在首次登入本发明的实施例的预览应用时,一旦客户正确地输入了他或她的用户名和密码,就可以引导客户执行初始登入过程,该初始登入过程可能由与客户的移动装置上的多个画面显示组成。第一个这样的画面可以是预览介绍和选择接受画面,图9B中示出了其示例截屏902,在这个截屏上,客户可以阅读关于预览功能性的信息。可以提示客户点击“了解更多/安全”链接图标904,该图标可以将客户引导到“了解更多/安全”画面906,如图9C所示,在这个画面上,客户可以了解在预览模式中他或她可以得到哪些信息。客户还可以了解哪些信息可能要求输入密码才能存取,还有可能与启用预览功能性相关的风险。此外,在客户丢失了他或她的移动装置并且想要远程地停用预览特征的情况下,可以向客户建议可供使用的安全措施。Figures 9A through 9D are screenshots illustrating examples of aspects of a login screen 900 according to an embodiment of the present invention. Referring to Figures 9A through 9D , during the initial login process, upon first logging into a preview application according to an embodiment of the present invention, once a customer correctly enters their username and password, the customer may be guided through an initial login process, which may consist of multiple screens displayed on the customer's mobile device. The first such screen may be a preview introduction and opt-in screen, an example screenshot 902 of which is shown in Figure 9B , where the customer can read information about the preview functionality. The customer may be prompted to click a "Learn More/Security" link icon 904, which directs the customer to a "Learn More/Security" screen 906, shown in Figure 9C , where the customer can learn about the information available in preview mode. The customer may also learn about information that may require a password to access, as well as the risks associated with enabling the preview functionality. Furthermore, the customer may be advised of available security measures in the event that the customer loses their mobile device and wishes to remotely disable the preview feature.

参照图9B,在预览功能性的选择接受方面中,“激活预览”框908的默认状态可以是未勾选的条件,并且客户必须主动选择接受预览功能性以激活预览功能性。如果客户选择接受,并且先前在早先的画面上未选择记住他或她的用户ID,则可以向客户建议为了让预览方面生效,客户必须选择记住他或她的用户ID。如果客户不同意,则客户可以选择退出预览功能性,并且直接被引导到主屏。9B , in the opt-in aspect of the preview functionality, the default state of the "Activate Preview" box 908 may be an unchecked condition, and the customer must actively opt-in to the preview functionality in order to activate it. If the customer opts in, and has not previously opted-in to have their user ID remembered on an earlier screen, the customer may be advised that they must opt-in to have their user ID remembered in order for the preview aspect to take effect. If the customer disagrees, they may opt-out of the preview functionality and be directed directly to the home screen.

图9D示出了本发明的实施例的确认偏好移动装置截屏910的示例。当客户选择接受时,可以将他或她引导到确认偏好画面910,在这个画面上,客户可以通过记住他或她的用户ID 912和启用预览功能性914来确认他或她的偏好。当客户对他或她的设置满意时,客户可以点击“完成登入”916以确认他或她的设置。一旦确认了客户的设置,就可以将客户引导到本发明的实施例的预览应用的主屏,这时候,客户已经完全登入,并且能够查看和执行本发明的实施例的应用内的所有功能。FIG9D illustrates an example of a mobile device screenshot 910 for confirming preferences according to an embodiment of the present invention. When the customer chooses to accept, they are directed to a confirm preferences screen 910 where they can confirm their preferences by remembering their user ID 912 and enabling preview functionality 914. When the customer is satisfied with their settings, they can click "Complete Login" 916 to confirm their settings. Once the customer's settings have been confirmed, they are directed to the home screen of the preview application according to an embodiment of the present invention, at which point they are fully logged in and can view and execute all functions within the application according to an embodiment of the present invention.

图10是图解说明本发明的实施例的关键组件的示例概况和关键组件之间的信息流的示意图。参照图10,关键组件可以包括(例如)客户的计算装置1002的处理器(诸如客户的智能手机),该处理器经由网络1004耦接至诸如金融机构服务器之类的后端服务器1006的处理器。图11是图解说明本发明的实施例的存取客户账户信息的过程的示例的流程图。参照图10和图11,在S10,使用后端服务器1006的处理器,可以经由计算装置1002的至少一个属性和存储在计算装置1002上的加密的令牌将计算装置1002与客户的简档绑定。FIG10 is a schematic diagram illustrating an example overview of key components and the flow of information between key components of an embodiment of the present invention. Referring to FIG10 , the key components may include, for example, a processor of a customer's computing device 1002 (such as a customer's smartphone), which is coupled to a processor of a back-end server 1006, such as a financial institution's server, via a network 1004. FIG11 is a flow diagram illustrating an example of a process for accessing customer account information according to an embodiment of the present invention. Referring to FIG10 and FIG11 , at S10, using the processor of the back-end server 1006, the computing device 1002 may be bound to the customer's profile via at least one attribute of the computing device 1002 and an encrypted token stored on the computing device 1002.

然后,另外参照图10和图11,在S11,同样使用后端服务器1006的处理器,可以接收到鉴定请求,该鉴定请求至少部分地由计算装置1002的至少一个属性和存储在计算装置1002上的加密的令牌组成。在S12,再次使用后端服务器1006的处理器,可以确定在预定的先前时间间隔内是否接收到客户凭证的输入。在S13,也使用后端服务器1006的处理器,当确定在预定的先前时间间隔内接收到客户凭证输入时,在不要求输入客户凭证的情况下可以在计算装置1002上显示预定义的客户账户信息。10 and 11 , at S11, again using the processor of the backend server 1006, an authentication request may be received, the authentication request being composed at least in part of at least one attribute of the computing device 1002 and an encrypted token stored on the computing device 1002. At S12, again using the processor of the backend server 1006, a determination may be made as to whether input of client credentials has been received within a predetermined previous time interval. At S13, also using the processor of the backend server 1006, if it is determined that input of client credentials has been received within the predetermined previous time interval, predefined client account information may be displayed on the computing device 1002 without requiring input of client credentials.

在首次登录之后预定的时间周期(诸如60天)内,可以向首次登入过程中未选择接受的客户提示预览功能性选择接受画面。在首次登入过程中或经由设置选择接受的客户,在登记后的预定义的时间周期(诸如前十五天)内,每当客户打开本发明的实施例的预览应用时,可以立即到达主屏,并且能够存取预览功能性内允许的级别的信息。如前所述,作为一项安全措施,将要求客户每隔预定的时间间隔(诸如每十五天)至少一次输入他或她的密码。如果客户关掉本发明的实施例的预览应用,则下一次客户试图存取他或她的信息时,可能发生令牌的验证和账户信息的刷新。此外,当预览应用在后台运转,并且被客户调到前台时,同样可能发生令牌的验证和账户信息的刷新。Within a predetermined time period (such as 60 days) after the first login, customers who did not choose to accept during the first login process may be prompted with a preview functionality selection acceptance screen. Customers who choose to accept during the first login process or through settings, within a predefined time period (such as the first fifteen days) after registration, each time the customer opens the preview application of an embodiment of the present invention, they can immediately reach the home screen and access the level of information allowed within the preview functionality. As mentioned above, as a security measure, the customer will be required to enter his or her password at least once at predetermined time intervals (such as every fifteen days). If the customer closes the preview application of an embodiment of the present invention, the next time the customer attempts to access his or her information, token verification and account information refresh may occur. In addition, when the preview application is running in the background and is called to the foreground by the customer, token verification and account information refresh may also occur.

应当理解的是,本发明的实施例可以实施为计算机程序产品的过程,其中的每个过程可以在一个或多个处理器上操作,或者是单独在单个实物平台(诸如个人计算机)上操作,或者是跨越多个平台(诸如系统或网络,包括诸如因特网、内联网、WAN、LAN、蜂窝网络或任何其他的合适网络之类的网络)操作。本发明的实施例可以采用客户端装置,每个客户端装置可以包括计算机可读媒体,包括但不限于耦接至处理器的随机存取存储器(RAM)。该处理器可以执行存储在存储器中的计算机可执行程序指令。这些处理器可以包括但是不限于微处理器、专用集成电路(ASIC)和或状态机。这些处理器可以包括诸如计算机可读媒体之类的媒体,或者可以与该媒体通信,该媒体中存储着指令,这些指令在被处理器执行时,使得处理器实施本文中说明的步骤中的一个或多个。It should be understood that embodiments of the present invention may be implemented as processes of a computer program product, each of which may operate on one or more processors, either solely on a single physical platform (such as a personal computer), or across multiple platforms (such as a system or network, including networks such as the Internet, an intranet, a WAN, a LAN, a cellular network, or any other suitable network). Embodiments of the present invention may employ client devices, each of which may include computer-readable media, including but not limited to random access memory (RAM) coupled to a processor. The processor may execute computer-executable program instructions stored in the memory. These processors may include, but are not limited to, microprocessors, application-specific integrated circuits (ASICs), and or state machines. These processors may include, or may be in communication with, a medium such as a computer-readable medium having instructions stored therein that, when executed by the processor, cause the processor to perform one or more of the steps described herein.

还应当理解,这些计算机可读媒体可以包括但是不限于电子、光学、磁性、RFID、或其他存储或传输装置,这些装置能够向处理器提供计算机可读指令。合适的媒体的其他示例包括但是不限于CD-ROM、DVD、磁盘、存储器芯片、ROM、RAM、ASIC、经过配置的处理器、光学媒体、磁性媒体、或任何其他合适的媒体,计算机处理器能从该媒体读取指令。本发明的实施例可以采用其他形式的这样的计算机可读媒体将指令传输或携带到计算机,包括路由器、私用或公用网络、或其他的传输装置或信道(有线或无线两种形式)。这些指令可以包括任何合适的计算机编程语言编写的代码,该计算机编程语言包括但不限于C、C++、C#、Visual Basic、Java、Python、Perl、和JavaScript。It should also be understood that these computer-readable media may include, but are not limited to, electronic, optical, magnetic, RFID, or other storage or transmission devices that can provide computer-readable instructions to the processor. Other examples of suitable media include, but are not limited to, CD-ROMs, DVDs, disks, memory chips, ROMs, RAMs, ASICs, configured processors, optical media, magnetic media, or any other suitable media from which a computer processor can read instructions. Embodiments of the present invention may employ other forms of such computer-readable media to transmit or carry instructions to a computer, including routers, private or public networks, or other transmission devices or channels (wired or wireless). These instructions may include code written in any suitable computer programming language, including, but not limited to, C, C++, C#, Visual Basic, Java, Python, Perl, and JavaScript.

还应该理解,本发明的实施例可以采用的客户端装置还可以包括多个外部或内部装置,诸如鼠标、CD-ROM、DVD、键盘、显示器、或其他输入或输出装置。总的来说,这些客户端装置可以是任何合适类型的基于处理器的平台,该平台连接至网络,并且与一个或多个应用程序交互,并且可以在任何合适的操作系统上操作。服务器装置也可以耦接至网络,并且类似于客户端装置,这些服务器装置可以包括处理器,该处理器耦接至计算机可读媒体,诸如随机存取存储器(RAM)。这些服务器装置(其可以是单个计算机系统)还可以实施为计算机处理器的网络。这些服务器装置的示例是服务器、主机计算机、联网计算机、基于处理器的装置和类似类型的系统和装置。It should also be understood that the client device that embodiments of the present invention can adopt can also comprise multiple external or internal devices, such as mouse, CD-ROM, DVD, keyboard, display or other input or output devices.In general, these client devices can be the platform based on processor of any suitable type, and this platform is connected to network, and interacts with one or more application programs, and can operate on any suitable operating system.Server device can also be coupled to network, and is similar to client device, and these server devices can comprise processor, and this processor is coupled to computer-readable media, such as random access memory (RAM).These server devices (it can be single computer system) can also be embodied as the network of computer processor.The example of these server devices is server, mainframe computer, networked computer, system and device based on the device of processor and similar type.

Claims (19)

1.一种用于存取客户账户信息的方法,其包括:1. A method for accessing customer account information, comprising: 使用处理器经由计算装置的至少一个属性和存储在所述计算装置上的加密的令牌将所述计算装置与客户的简档绑定;The processor binds the computing device to the customer's profile using at least one attribute of the computing device and an encrypted token stored on the computing device. 使用所述处理器接收鉴定请求,所述鉴定请求至少部分地由所述计算装置的所述至少一个属性和存储在所述计算装置上的所述加密的令牌组成;The processor receives an authentication request, which consists at least in part of the at least one attribute of the computing device and the encrypted token stored on the computing device; 使用所述处理器确定在预定的先前时间间隔内是否接收到客户凭证的输入;以及The processor is used to determine whether input of customer credentials has been received within a predetermined previous time interval; and 当确定在所述预定的先前时间间隔内接收到所述客户凭证的输入时,使用所述处理器,在不要求输入所述客户凭证的情况下在所述计算装置上显示预定义的客户账户信息,When it is determined that input of the customer credential has been received within the predetermined previous time interval, the processor uses the processor to display predefined customer account information on the computing device without requiring input of the customer credential. 其中,显示所述预定义的客户账户信息还包括在所述计算装置上显示非个人身份客户账户信息,The display of the predefined customer account information also includes displaying non-personally identifiable customer account information on the computing device. 其中,显示所述非个人身份客户账户信息还包括在所述计算装置上显示非个人身份客户支票、储蓄和信用卡账户信息,以及The display of the non-personally identifiable customer account information also includes displaying the non-personally identifiable customer's checking, savings, and credit card account information on the computing device, and 其中,非个人身份客户支票、储蓄和信用卡账户信息包括部分账户识别符和一个或多个可用余额。The information on non-personally identified customers' checking, savings, and credit card accounts includes a portion of the account identifier and one or more available balances. 2.根据权利要求1所述的方法,其中,绑定所述计算装置还包括只有在从所述客户接收到选择接受选择时,才将所述计算装置与所述客户的简档绑定。2. The method of claim 1, wherein binding the computing device further includes binding the computing device to the client's profile only when the client receives an acceptance of the selection from the client. 3.根据权利要求2所述的方法,其中,绑定所述计算装置还包括只有在从所述客户接收到对所述选择接受选择的确认的情况下才绑定所述计算装置。3. The method of claim 2, wherein binding the computing device further comprises binding the computing device only upon receiving confirmation from the client that the selection is accepted. 4.根据权利要求2所述的方法,其中,绑定所述计算装置还包括在从所述客户接收到所述选择接受选择之后,每当从所述客户接收到选择退出选择时,就停用所述计算装置的所述绑定。4. The method of claim 2, wherein binding the computing device further includes deactivating the binding of the computing device whenever a selection to exit is received from the client after receiving the selection to accept the selection from the client. 5.根据权利要求2所述的方法,其中,绑定所述计算装置还包括每当从所述客户接收到更改所述客户凭证的请求时,就停用所述计算装置的所述绑定。5. The method of claim 2, wherein binding the computing device further comprises deactivating the binding of the computing device whenever a request to change the customer credentials is received from the customer. 6.根据权利要求1所述的方法,其中,所述客户凭证包括客户密码。6. The method according to claim 1, wherein the customer credential includes a customer password. 7.根据权利要求2所述的方法,其中,绑定所述计算装置还包括每当接收到将不同的计算装置与所述客户的简档绑定的请求时,就停用所述计算装置的所述绑定。7. The method of claim 2, wherein binding the computing device further includes deactivating the binding of the computing device whenever a request to bind a different computing device to the client’s profile is received. 8.根据权利要求1所述的方法,其中,所述至少一个计算装置属性包括唯一计算装置识别符。8. The method of claim 1, wherein the at least one computing device attribute includes a unique computing device identifier. 9.根据权利要求1所述的方法,其中,所述计算装置包括移动通信装置,并且所述至少一个计算装置属性还包括移动网络详情。9. The method of claim 1, wherein the computing device includes a mobile communication device, and the at least one computing device attribute further includes mobile network details. 10.根据权利要求1所述的方法,其中,所述加密的令牌包括使用哈希算法加密的令牌。10. The method of claim 1, wherein the encrypted token comprises a token encrypted using a hash algorithm. 11.根据权利要求1所述的方法,其中,确定是否接收到所述客户凭证的输入还包括确定在所述预定的先前时间间隔内是否至少一次接收到所述客户凭证的输入。11. The method of claim 1, wherein determining whether input of the customer credential has been received further comprises determining whether input of the customer credential has been received at least once within the predetermined prior time interval. 12.根据权利要求11所述的方法,其中,确定是否接收到所述客户凭证的输入还包括确定在前十五天内是否至少一次接收到所述客户凭证的输入。12. The method of claim 11, wherein determining whether the input for the customer credential has been received further includes determining whether the input for the customer credential has been received at least once within the preceding fifteen days. 13.根据权利要求1所述的方法,其中,所述部分支票账户识别符包括支票账号的预定部分。13. The method of claim 1, wherein the partial cheque account identifier comprises a predetermined portion of the cheque account number. 14.根据权利要求1所述的方法,其中,所述部分储蓄账户识别符包括储蓄账号的预定部分。14. The method of claim 1, wherein the partial savings account identifier comprises a predetermined portion of the savings account number. 15.根据权利要求1所述的方法,其中,所述部分信用卡账户识别符包括信用卡片账号的预定部分。15. The method of claim 1, wherein the partial credit card account identifier comprises a predetermined portion of the credit card number. 16.根据权利要求1所述的方法,其中,显示所述非个人身份客户账户信息还包括在所述计算装置上显示预定数目的交易的非个人身份客户账户交易信息。16. The method of claim 1, wherein displaying the non-personally identifiable customer account information further includes displaying a predetermined number of non-personally identifiable customer account transaction information on the computing device. 17.根据权利要求16所述的方法,其中,所述预定数目的交易包括最近十五笔交易。17. The method of claim 16, wherein the predetermined number of transactions includes the most recent fifteen transactions. 18.根据权利要求1所述的方法,其中,显示所述预定义的客户账户信息还包括拒绝在未输入所述客户凭证的情况下接收到的客户交易请求。18. The method of claim 1, wherein displaying the predefined customer account information further includes rejecting customer transaction requests received without the customer credentials being entered. 19.一种用于存取客户账户信息的系统,其包括:19. A system for accessing customer account information, comprising: 耦接至存储器的处理器,所述处理器经过编程以:A processor coupled to memory, the processor being programmed to: 经由计算装置的至少一个属性和存储在所述计算装置上的加密的令牌将所述计算装置与客户的简档绑定;The computing device is bound to a customer's profile via at least one attribute of the computing device and an encrypted token stored on the computing device; 接收鉴定请求,所述鉴定请求至少部分地由所述计算装置的所述至少一个属性和存储在所述计算装置上的所述加密的令牌组成;Receive an authentication request, the authentication request consisting at least in part of the at least one attribute of the computing device and the encrypted token stored on the computing device; 确定在预定的先前时间间隔内是否接收到客户凭证的输入;以及Determine whether customer credentials have been received within a predetermined previous time interval; and 当确定在所述预定的先前时间间隔内接收到所述客户凭证的输入时,在不要求输入所述客户凭证的情况下在所述计算装置上显示预定义的客户账户信息,When it is determined that input of the customer credential has been received within the predetermined previous time interval, predefined customer account information is displayed on the computing device without requiring the input of the customer credential. 其中,显示所述预定义的客户账户信息还包括在所述计算装置上显示非个人身份客户账户信息,The display of the predefined customer account information also includes displaying non-personally identifiable customer account information on the computing device. 其中,显示所述非个人身份客户账户信息还包括在所述计算装置上显示非个人身份客户支票、储蓄和信用卡账户信息,以及The display of the non-personally identifiable customer account information also includes displaying the non-personally identifiable customer's checking, savings, and credit card account information on the computing device, and 其中,非个人身份客户支票、储蓄和信用卡账户信息包括部分账户识别符和一个或多个可用余额。The information on non-personally identified customers' checking, savings, and credit card accounts includes a portion of the account identifier and one or more available balances.
HK15110147.4A 2013-02-28 2014-02-24 Methods and systems for accessing account information electronically HK1209510B (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US13/780,666 2013-02-28
US13/780,666 US9027109B2 (en) 2013-02-28 2013-02-28 Methods and systems for accessing account information electronically
PCT/US2014/017901 WO2014133931A1 (en) 2013-02-28 2014-02-24 Methods and systems for accessing account information electronically

Publications (2)

Publication Number Publication Date
HK1209510A1 HK1209510A1 (en) 2016-04-01
HK1209510B true HK1209510B (en) 2019-08-23

Family

ID=

Similar Documents

Publication Publication Date Title
CN104919446B (en) For the method and system for the information that electronically accesses to your account
US12309151B2 (en) Credential storage manager for protecting credential security during delegated account use
US11785008B1 (en) Passive authentication during mobile application registration
US10992660B2 (en) Authentication and authorization of a privilege-constrained application
US20220188786A1 (en) Systems and methods for user data management across multiple devices
US20210390548A1 (en) Passwordless authentication through use of device tokens or web browser cookies
US20210295335A1 (en) Secure access-based resource delegation
US20150161608A1 (en) Systems, apparatus and methods for improved authentication
US11966923B2 (en) Systems and methods facilitating account access delegation
US20170345003A1 (en) Enhancing electronic information security by conducting risk profile analysis to confirm user identity
CA2832754A1 (en) Method and system for enabling merchants to share tokens
US20220383355A1 (en) Automatic linking of loyalty accounts of authorized users to loyalty accounts of primary users
US11968216B1 (en) Methods and systems for managing delegates for secure account fund transfers
US20240289782A1 (en) Systems and methods for providing queued credentials for an account
HK1209510B (en) Methods and systems for accessing account information electronically