VIRTUAL PAYMENT CARD
FIELD OF THE INVENTION
The present invention relates to telecommunication systems. In particular, the invention concerns a method and a system for obtaining and using a payment identification number in a secure way with a wireless communication device.
BACKGROUND OF THE INVENTION Online commerce systems are rapidly increasing all over the world. In an online commerce system merchants are developing sites on the World Wide Web (WWW) . Because the World Wide Web can be accessed practically anywhere in the world the online commerce systems can have customers from different countries.
The methodology in online commerce shopping can be simplified in three stages: selecting a product, placing on order and paying for the product. Typically, the product or service ordered over the Internet is paid with a credit card. When the customer has filled the order containing all relevant information (e.g. product information, name, address, account number and an expiration date) the order is returned to the merchant. The merchant verifies that the credit card number is valid and that it can be charged the payment caused by the ordered product or service . The verification is usually conducted on a special bank payment network. The verification can be conducted automatically or by phoning to a certain number. A credit card (e.g. a Visa card) can be used all over the world in places which accept it as a payment instrument. When the payment is made in a conventional shop it isu easier to be sure about the identity of the customer. A serious problem arises when the shopping is conducted on the Internet. The credit card data travels over the Internet to the merchant, at its
worst, without any protection (encryption) . The credit card information can be intercepted and thus used to make purchases .
US patent 5,883,810 discloses an online com- merce system that facilitates online commerce over a public network using an online commerce card. In the publication an issued card is assigned a permanent customer account number that is maintained behalf of the customer at the issuing institution. A customer is assigned a transaction number submitted to a merchant as a proxy for the customer account number. When the merchant submits a request for authorisation, the issuing institution recognises the number as a transaction number for an online credit card. Every transac- tion number can be used only once. According to the patent, a customer never submits his "real" credit card number to the merchant but a credit card number like number which identifies the customer to the issuing institution. The problem, however, is that the above described system can be used only when buying products or services online. Further, when using the system and method disclosed in the US patent 5,883,810 a special software code has to be downloaded into a computer. This means that whenever a customer wants to make secure shopping online, the computer used has to include said special software code. This in turn reduces the amount of computers or other terminals through which a secure order can be made .
OBJECT OF THE INVENTION
The object of the present invention is to eliminate the drawbacks referred to above or at least to significantly alleviate them. A specific object of the invention is to disclose a new type of method and system in which a wireless communication device can be
used to obtain a payment identification number which, e.g. can be used just like a credit card number.
BRIEF DESCRIPTION OF THE INVENTION The present invention concerns a method and system for obtaining a payment identification number in a secure way with a wireless communication device. The payment identification number can then be inserted into a www-page or used in a conventional way when buying products or services. If the payment identification refers to a credit card number it is not necessary to show the actual credit card at all.
In the method the payment identification number is transferred to a payment terminal. The payment terminal may comprise a www-browser which can be used to buy products or services over the Internet. The validity of the transferred payment identification number is verified, e.g. using VisaNet network or the Veriphone network. The account linked to the payment identification number is charged if the payment identification number is valid. The payment identification number is just like a normal credit card number. It has the same format and number of digits as a regular credit card. When a merchant wants to authorise the payment identification number it is done in the same way as traditional credit card authorisation. Alternatively, the payment identification number may be in the form of a bank account number or some other appropriate form. In the method of the invention, before above mentioned steps a request for the payment identification number is sent from the wireless communication device the request being digitally signed and/or encrypted. Said request sent from the wireless communica- tion device comprises, e.g. a user identification data, an account number and/or account limit information. The wireless communication device is, e.g. a mobile tele-
•phone or a PDA (PDA, Personal Digital Assistant) . In response to the request the payment identification number is sent to the wireless communication device from a payment system in a digitally signed and/or en- crypted message. The message can also contain information about the available credit limit and/or validity period.
The payment identification number and other sensible information travels between the wireless com- munication and the payment system digitally signed and/or encrypted. In an embodiment of the invention, public key cryptography is used. In the public key method, the message is encrypted using the recipient's public encryption key. Digital signature is achieved with the sender' s private signing key and some appropriate public key algorithm.
In an embodiment of the invention, the payment identification number can be used only once. It can also be defined that the payment identification number is valid until a predefined credit limit is exceeded. In an embodiment of the invention, the use of the payment identification number is tied to a certain merchant identity.
In an embodiment of the invention, an addi- tional security code is required from the wireless communication device before the account is charged. The above mentioned procedure provides security because the payment identification number is now practically useless without an appropriate additional security code. The security code is, e.g. a three digit random number.
In addition, the invention concerns a system for obtaining and using a payment identification number in a secure way with a wireless communication de- vice in the present invention comprising a first telecommunication network, a wireless communication device connected to the first telecommunication network, a
second telecommunication network, a payment terminal connected to the second telecommunication network, a third telecommunication network, a merchant connected to the second telecommunication network and to the third telecommunication network, a payment system connected to the first telecommunication network and to the third telecommunication network, means for transferring the payment identification number to the payment terminal, means for verifying the validity of the transferred payment identification number and means for charging the account linked to the. payment identification number.
In the system of the invention, the wireless communication device comprises means for requesting the payment identification number the request being digitally signed and/or encrypted and the payment system comprises means for sending the payment identification number to the wireless communication device via the first telecommunication network in a message digi- tally signed and/or encrypted.
In an embodiment of the present invention, the payment system comprises means for restricting the use of the payment identification number.
In an embodiment of the present invention, the first telecommunication network is a mobile telephone network.
In an embodiment of the present invention, the second telecommunication network is the Internet .
In an embodiment of the present invention, the third telecommunication network is a bank payment network.
In an embodiment of the present invention, the wireless communication device is a mobile phone or a PDA. In an embodiment of the present invention, the payment terminal comprises means for requesting an
additional security code from the wireless communication device.
In addition, the invention concerns a system for obtaining and using a payment identification num- ber in a secure way with a wireless communication device said system comprising a first telecommunication network, a wireless communication device connected to the first telecommunication network, a third telecommunication network, payment terminal connected to the third telecommunication network, a payment system connected to the first telecommunication network and to the third telecommunication network, means for transferring the payment identification number to the payment terminal, means for verifying the validity of the transferred payment identification number and means for charging the account linked to the payment identification number.
In the system of the invention, the wireless communication device comprises means for requesting the payment identification number the request being digitally signed and/or encrypted and the payment system comprises means for sending the payment identification number to the wireless communication device via the first telecommunication network in a message digi- tally signed and/or encrypted.
In an embodiment of the present invention, the payment system comprises means for restricting the use of the payment identification number.
In an embodiment of the present invention, the first telecommunication network is a mobile telephone network.
In an embodiment of the present invention, the third telecommunication network is a bank payment network. In an embodiment of the present invention, the wireless communication device is a mobile phone or a PDA.
In an embodiment of the present invention, the payment terminal is a cash teller or a vending machine.
In an embodiment of the present invention, the payment terminal comprises means for requesting an additional security code from the wireless communication device.
As compared with prior art, the invention provides the advantage that there is no need to have any extra software (in either of the two sides - merchant or payment terminal) if doing online shopping on the Internet with a computer. Another benefit is that the system integrates with existing card verification and settlement protocols . A further advantage of the invention is that stealing of a payment identification number is practically useless because at its best the payment identification number can be used only once.
Yet another advantage of the invention is that the payment identification number can not be used just in online shopping but also in conventional credit card paying.
Yet another advantage of the invention is its mobility. The payment identification number can be re- quested anywhere within the wireless telecommunication network coverage area.
LIST OF ILLUSTRATIONS
In the following section, the invention will be described in detail by the aid of a few examples of its embodiments, wherein:
Fig. 1 presents a preferred system in which a method according to the invention can be implemented,
Fig. 2 presents a preferred system in which a method according to the invention can be implemented, and
Fig. 3 presents a flow diagram representing a preferred example of the method of the invention.
DETAILED DESCRIPTION OF THE INVENTION Fig. 1 illustrates a preferred system in which a method according to the invention can be implemented. The system comprises a wireless communication device MS connected to a first telecommunication network NET1. Also the payment system BANK is con- nected to the first telecommunication network NET1. In a preferred embodiment of the invention the wireless communication device MS is a mobile phone. It can also be a PDA or any other wireless device. The first telecommunication network NET1 is preferably a mobile telephone network, e.g. GSM (GSM, Global System for Mobile communication) network. The system comprises also a payment terminal PT and a merchant MERC connected to the second telecommunication network NET2. In a preferred embodiment of the invention the second telecommunication network NET2 is the Internet. The merchant is connected to the third telecommunication network NET3 which is preferably a bank payment network, e.g. VisaNet network or Veriphone network. Through the payment network NET3 the merchant MERC can authorise credit card numbers.
The mobile phone MS comprises means TU for transferring the -payment identification number to the payment terminal PT. If the payment terminal PT is a normal computer, the payment identification number can be input into the computer PT, e.g. through a keyboard or through some wireless interface, e.g. infrared transmission or Bluetooth. The mobile phone MS also comprises means RU for requesting the payment identification number the request being digitally signed and/or encrypted. The request is transferred to the payment system BANK via the mobile telephone network
NET1. The request can be in the form of a short message or in another appropriate form.
The payment identification number and other order related information is input into the computer PT and transferred to the merchant MERC via the Internet NET2. The merchant MERC comprises means CU for verifying the validity of the payment identification number and means SU for requesting an additional security code from the wireless communication device. The verification is a carried out through the payment network NET3. The payment identification number is related to certain account number the account having, e.g. certain credit limit or other restrictions. After the verification procedure the payment system BANK sends an authorisation reply to the merchant MERC.
The payment identification number is just like a normal credit card number. It has the same format and number of digits as a regular credit card. When a merchant wants to authorise the payment identi- fication number it is done in the same way as traditional credit card authorisation. Alternatively, the payment identification number may be in the form of a bank account number or some other appropriate form.
The payment system BANK comprises means PU for charging the account related to the payment identification number and means LU for restricting the use of the payment identification number. The payment identification number may be used only once. In another embodiment of the invention, the payment identi- fication number can be used until a predefined credit limit is exceeded. In another embodiment of the invention, the use of the payment identification number is tied to a certain merchant identity. The payment system BANK comprises also means MU for sending the payment identification number to the mobile phone MS via the mobile telephone network NET1 in a message digitally signed and/or encrypted. The message can
contain also other information, e.g. about the credit limit and/or the validity period of the payment identification number.
Fig. 2 illustrates another preferred system in which a method according to the invention can be implemented. The system comprises a wireless communication device MS connected to a first telecommunication network NET1. Also the payment system BANK is connected to the first telecommunication network NET1. In a preferred embodiment of the invention, the wireless communication device MS is a mobile phone. It can also be a PDA or any other wireless device. The first telecommunication network NET1 is preferably a mobile telephone network, e.g. GSM network. The system com- prises also a payment terminal PT connected to the third telecommunication network NET3. In a preferred embodiment of the invention, the third telecommunication network NET3 is a bank payment network, e.g. VisaNet network or Veriphone network. Through the pay- ment network NET3 credit card numbers can be authorised.
The mobile phone MS comprises means RU for requesting the payment identification number the request being digitally signed and/or encrypted. The re- quest is transferred to the payment system BANK via the mobile telephone network NET1. The request can be in the form of a short message or in another appropriate form. The mobile phone MS comprises also means TU for transferring the payment identification number to the payment terminal PT.
In a preferred embodiment of the invention, the payment terminal PT is a cash teller or a vending machine. The payment identification number can be transferred to the payment terminal PT, e.g. via a wireless interface, e.g. infrared transmission or Bluetooth. The payment identification number can be transmitted to the payment terminal also manually,
e.g. by reading the payment identification number from the display of the mobile phone MS and inputting it into the payment terminal PT.
The payment terminal PT comprises means CU for verifying the validity of the payment identification number and means SU for requesting an additional security code from the wireless communication device. The verification is carried out through the payment network NET3. The payment identification number is re- lated to certain account number the account having, e.g. certain credit limit or other restrictions. After the verification procedure the payment system BANK sends an authorisation reply to the payment terminal PT. The payment system BANK comprises means PU for charging an account related to the payment identification number and means LU for restricting the use of the payment identification number. The payment identification number may be used only once. In an- other embodiment of the invention, the payment identification number can be used until a predefined credit limit is exceeded. In another embodiment of the invention, the use of the payment identification number is tied to a certain merchant identity. The payment sys- tem BANK comprises also means MU for sending the payment identification number to the mobile phone MS via the mobile telephone network NET1 in a message digitally signed and/or encrypted. The message can contain also other information, e.g. about the credit limit and/or the validity period of the payment identification number. ■ ■
Fig. 3 presents a flow diagram representing a preferred example of the method of the invention. In order to acquire a payment identification number, the wireless communication device MS sends a request to the payment system BANK, arrows la and lb. The payment identification number refers to a credit card like
number which can be used just like credit card is used, although the payment identification number's validity has certain restrictions. The wireless communication device MS is preferably a mobile phone or a PDA. The digitally signed and/or encrypted request is transferred to the payment system BANK in the form of a short message via the first telecommunication network NET1 which is preferably a mobile telephone network. However, this is only one example of the form of the request and telecommunication network used and thus other combinations can be used as well.
The request contains, e.g. user identification data, an account number and/or account limit information. The payment system BANK receives the re- quest and assigns the user a payment identification number. The payment identification number may be valid for only one transaction. There may be other restrictions, too in using the payment identification number. It can be defined that the payment identification num- ber is usable within certain time limits and/or the use of the payment identification number is tied to a certain merchant identity. Sometimes it might be reasonable to set a credit limit within which the same payment identification number can be used more than once.
The payment system BANK sends the payment identification number to the wireless communication device MS, arrows 2a and 2b. The message may contain also other information than the payment identification number, e.g. information about the validity and credit limit. The messages between the wireless communication device MS and the payment system BANK are preferably digitally signed and/or encrypted. In this manner integrity and confidentiality are achieved. In a pre- ferred embodiment of the invention, signing and encryption are based on public key cryptography (PKC) .
The wireless communication device MS transfers or the user inputs the received payment identification number into the payment terminal PT. Also some other order related information may be input into the payment terminal PT . All the information is transferred to the merchant MERC via the second telecommunication network NET2 which is preferably the Internet, arrows 3a and 3b. The merchant MERC verifies the validity of the payment identification number. The verification request is sent to the payment system BANK via the payment network NET3 , arrows 4a and 4b. The payment identification number is related to a certain account number the account having e.g. certain credit limit or other restrictions. The payment system BANK checks if the payment identification number meets all the requirements addressed to it. The payment system BANK sends an authorisation reply to the merchant MERC, arrows 5a and 5b.
The above mentioned examples may comprise also other actions, which improves security. An additional security code may be required from the wireless communication device before the account linked to the payment identification number is charged. The above mentioned procedure provides security because the pay- ment identification number is now practically useless without an appropriate additional security code. The security code is, e.g. a three digit random number. Hence, if someone has somehow been able to acquire the credit card number (payment identification number) il- legally, it can not be used without a proper security code. The security code may also include some additional information about the credit limit etc. The wireless communication device is asked, e.g. by phone or short message, to send the security code to the merchant, payment terminal or payment system. The security code in a preferred embodiment varies each time used.
In a preferred embodiment of the Fig. 3, before the account linked to the credit card number is charged, a security code request is sent to the wireless communication device MS. If the response from the wireless communication device MS contains the right security code, the account linked to the credit card number can now be charged. Although it is described here that the security code checking procedure is carried out by the payment system BANK, it can as well be the merchant MERC that is responsible for the security code checking procedure .
In a preferred embodiment of the Fig. 3, the payment identification number refers to a security code. In order to acquire the security code, the wire- less communication device MS sends a request to the payment system BANK, arrows la and lb. The request contains, e.g. user identification data, an account number and/or account limit information. The payment system BANK receives the request and assigns the user a security code. The security code is valid for only one transaction and is, e.g. a three digit random number. There may be other restrictions, too in- using the security code. It can be defined that the security code is usable within certain time limits and/or the use of the security code is tied to a certain merchant identity. The payment system BANK sends the security code to the wireless communication device MS, arrows 2a and 2b. It can also be arranged that the user receives more than one security code in response to the request. In doing so, it is not necessary to send a request for a security code so often.
Therefore, when a user wants to make an order, the wireless communication device MS transfers or the user inputs his/her fixed credit card number into the payment terminal PT. Also some other order related information may be input into the payment terminal PT. All the information is transferred to the merchant
MERC via the second telecommunication network NET2 which is preferably the Internet, arrows 3a and 3b. The merchant MERC verifies the validity of the credit card number. The verification request is sent to the payment system BANK via the payment network NET3 , arrows 4a and 4b. Before the account linked to the credit card number is charged, a security code request is sent to the wireless communication device MS. If the response from the wireless communication device MS contains the right security code, the account linked to the credit card number can now be charged. The payment system BANK sends an authorisation reply to the merchant MERC, arrows 5a and 5b. Although it is de- scribed here that the security code checking procedure is carried out by the payment system BANK, it can as well be the merchant MERCH that is responsible for the checking procedure .
The invention is not restricted to the exam- pies of its embodiments described above, instead many variations are possible within the scope of the inventive idea defined in the claims.