WO2014032549A1 - Telecommunication service provider based mobile identity authentication and payment method and system - Google Patents
Telecommunication service provider based mobile identity authentication and payment method and system Download PDFInfo
- Publication number
- WO2014032549A1 WO2014032549A1 PCT/CN2013/082198 CN2013082198W WO2014032549A1 WO 2014032549 A1 WO2014032549 A1 WO 2014032549A1 CN 2013082198 W CN2013082198 W CN 2013082198W WO 2014032549 A1 WO2014032549 A1 WO 2014032549A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- identity authentication
- mobile
- mobile device
- identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/325—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3215—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a plurality of channels
Definitions
- the present invention relates to a mobile identity authentication and payment method and system, and more particularly to a method and system for fast mobile identity authentication and payment based on a telecommunications service provider.
- the present invention provides a method of identity authentication, comprising: (a) connecting to a verification device using a user device; (b) transmitting an authentication request to the identity authentication system server by the verification device; (c) authenticating the system server according to the authentication Requesting to generate a URL webpage address and an encryption code, embedding the encryption code in the URL webpage address to obtain an encrypted webpage address including the encrypted code, and transmitting the URL address containing the encrypted code to the verification device; (d) The verification device instructs the user to use a suitable device to receive the URL web address containing the encrypted code to connect to the identity authentication system server; and (e) the identity authentication system server uses the characteristics of the appropriate device for identity authentication.
- the encryption code further includes using a condition parameter, the condition parameter includes: (i) a valid number of times, and the definition thereof The number of times the encryption code can be used; and (ii) the effective time, which defines the usable time of the encryption code.
- the identity authentication system server determines the user device according to an Internet Protocol Address of the user device included in the authentication request before transmitting the URL page address including the encrypted code to the verification device. Whether it is a mobile device using the mobile phone network to obtain a device determination result, and transmitting the device determination result together with the encrypted URL page address back to the verification device, and then the verification device performs the following steps: (i) if The user device is a mobile device that uses the mobile phone network to access the Internet, and directly transmits the encrypted web page address including the encrypted code to the mobile device for the identity authentication through the mobile phone network; or (ii) if the user device is not using the mobile phone network The mobile device surfing the Internet requires the user to use the mobile device that accesses the Internet via the mobile phone network and transmit the URL address containing the encrypted code to the mobile device for identity authentication through a specific delivery method.
- the mobile device using the mobile phone network to connect to the identity authentication system can use a URL web address including an encrypted code to connect to the identity authentication system.
- the specific delivery methods include barcodes, microwaves, and sound waves.
- the identity authentication system server obtains the mobile device's telephone number (MSISDN) by: (i) obtaining the mobile device's internet Protocol address (Internet Protocol Address) and communication port (Port) and obtain the telephone number (MSISDN) and telecommunication service corresponding to the Internet Protocol Address and the port from the corresponding telecommunication service provider An identifier (IMSI); or (ii) reading data of a subscriber identity module (Sim Card) in the mobile device and determining a telecommunications service provider identifier (IMSI) and a telephone number of the mobile device based on the data (MSISDN); or (iii) Obtaining a Telecommunications Service Identifier (IMSI) and a mobile device's telephone number (MSISDN) from the header of the authentication request (HTTP Header).
- IMSI subscriber identity module
- HTTP Header HTTP Header
- the present invention provides a system for identity authentication, comprising: (a) a user device; (b) a verification device, wherein the user connects to the verification device using the user device and inputs data to the verification device, the verification device according to the And the (c) identity authentication system server receives the authentication request and generates a URL webpage address and an encryption code according to the authentication request; wherein the identity authentication system server embeds the encryption code into the URL webpage address to obtain the URL page including the encryption code The address and the URL address containing the encrypted code are transmitted back to the verification device, and the verification device instructs the user to use a suitable device to receive the URL of the URL containing the encrypted code to connect to the identity authentication system server for identity authentication.
- Encrypted encoding includes the use of conditional parameters including: (a) a valid number of times that defines the number of times the ciphering code can be used; and (b) an effective time that defines the usable time of the ciphering code.
- the identity authentication system server includes a device determining module to: according to the Internet of the user device included in the authentication request, before transmitting the URL address including the encrypted code to the verification device
- the Internet Protocol Address determines whether the user device is a mobile device using the mobile phone network to obtain the device determination result, and transmits the device determination result together with the URL address including the encrypted code to the verification device, and then the verification device performs the following: Step: (i) if the user device is a mobile device that uses the mobile phone network to access the Internet, directly transmits the URL address containing the encrypted code to the mobile device through the mobile phone network to perform the identity authentication; or (ii) if the user device is not A mobile device that uses a mobile phone network to access a network requires the user to use a mobile device that is connected to the mobile phone network and transmit the encrypted web page address containing the encrypted code to the mobile device for the identity authentication by a specific delivery method.
- the specific delivery modes include barcodes, microwaves, and sound waves, and specific examples include fast response matrix codes, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency identification ( RFID).
- the mobile device, the authentication device, and the identity authentication system server each include an authentication abort module to force the suspension of identity authentication as needed and in different situations.
- One of the specific cases is that the discovery is spoofed by the phishing network or the intermediary, and the identity authentication system server notifies the verification device to stop the service to the user.
- the present invention provides a method of mobile payment, comprising: (a) connecting to a verification device using a user device; (b) transmitting an authentication request to the identity authentication system server by the verification device; (c) identity authentication system server Generating a URL webpage address and an encryption code according to the authentication request, embedding the encryption code into the URL webpage address to obtain a URL webpage address including the encryption code, and transmitting the URL webpage address including the encryption code back to the verification apparatus; (d) using the encryption code included URL page address for user authentication; and (e) use established user identity for mobile payment.
- the encryption encoding comprises using a condition parameter, the condition parameter comprising: (i) an effective time, which defines a usable time of the encrypted encoding; (ii) an effective number of times, which defines a usable number of times of the encrypted encoding; And (iii) the amount to be paid, which defines the amount the user needs to pay.
- the identity authentication system server determines the user device according to an Internet Protocol Address of the user device included in the authentication request before transmitting the URL page address including the encrypted code to the verification device.
- the verification device performs the following steps: 1. If the user device is using the mobile device A mobile device that accesses the Internet via a mobile phone transmits a URL address containing an encrypted code directly to the mobile device through the mobile phone network; or II. If the user device is not a mobile device that uses the mobile phone network to access the Internet, the user is required to use the mobile phone network to access the Internet.
- the mobile device transmits the URL address containing the encrypted code to the mobile device through a specific delivery method.
- the step of authenticating the user using the URL web page address including the encryption code comprises: (i) the verification device transmitting the URL web page address including the encrypted code to the mobile device; (ii) the mobile device Receiving a URL web page address including an encrypted code, the URL containing the encrypted code web page address directing the user device to the identity authentication system server; and (iii) the identity authentication system server confirming the identity of the user based on the characteristics of the mobile device.
- the specific delivery manner includes a barcode, a microwave, and an acoustic wave
- specific examples include a fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency identification. (RFID).
- NFC near field communication
- Wi-Fi wireless fidelity
- RFID radio frequency identification
- the identity authentication system server obtains the mobile device's telephone number (MSISDN) by: I. obtaining the user device's internet protocol address ( Internet Protocol Address and a port and obtain a telephone number (MSISDN) and a telecommunication service provider identifier corresponding to the Internet Protocol Address and the port from a corresponding telecommunication service provider (IMSI); or II. reading data of a subscriber identity module (Sim Card) in the mobile device and determining a Telecommunications Service Provider Identifier (IMSI) and a mobile device's telephone number (MSISDN) based on the data; or III.
- the header of the (HTTP Header) authentication request obtains the Telecommunications Service Provider Identifier (IMSI) and the mobile device's telephone number (MSISDN:).
- the step of performing mobile payment using the established user identity comprises: 1. determining whether the encryption code is valid; II. determining whether the account amount of the user is sufficient; and ⁇ . according to determining step I and The result of II completes the transaction or cancels the transaction.
- the present invention provides a method for presetting a fast mobile payment, comprising: (a) pre-generating a URL webpage address and an encryption code, and embedding the encryption code into a URL webpage address to obtain a URL webpage address including an encryption code; (b) using a mobile device to read a URL web address containing an encrypted code, the URL containing the encrypted code, the web page address directing the mobile device to the identity authentication system server; (c) the identity authentication system server root The identity of the user is confirmed based on the characteristics of the mobile device; and (d) the mobile payment is made using the established user identity.
- the encryption coding comprises using a condition parameter, the condition parameter comprising: (i) a valid number of values of 1, which defines that the encryption code can be used only once; (ii) an effective time, which defines the encryption code The usable time; (iii) the amount to be paid, which defines the amount the user needs to pay.
- the identity authentication system server obtains the user device's telephone number (MSISDN) by: (i) obtaining the mobile device's internet protocol An Internet Protocol Address and a port (Port) and a corresponding telephone number (MSISDN) and a telecommunications service provider corresponding to the Internet Protocol Address and the port from the corresponding telecommunications service provider An identifier (IMSI); or (ii) reading data of a subscriber identity module (Sim Card) in the mobile device and determining a telecommunications service provider identifier (IMSI) and a telephone number of the mobile device based on the data ( MSISDN); or (iii) Obtaining a Telecommunications Service Provider Identifier (IMSI) and a telephone number (MSISDN) of the mobile device from the header of the (HTTP Header) authentication request.
- IMSI subscriber identity module
- the step of performing mobile payment using the established user identity comprises: 1. determining whether the encryption code is valid; II. determining whether the account amount of the user is sufficient; and ⁇ . according to determining step I and The result of II completes the transaction or cancels the transaction.
- the present invention provides a method for remittance, comprising: (a) user A using a mobile device to connect to an identity authentication system server; (b) an identity authentication system server confirming the identity of user A and the telecommunications service to which user A belongs (c) User A enters the telecommunications service provider and telephone number to which User B belongs and the amount of the remittance; (d) The identity authentication system server confirms the identity of User B based on the telecommunications service provider and telephone number to which User B belongs; and (e) The remittance amount is directly deducted from the user's telecommunications account and the remittance amount is remitted to the user B's telecommunications account.
- the present invention provides another method of remittance, comprising: (a) user B connects to an identity authentication system server using a mobile device; (b) said identity authentication system server Confirming the identity of the user B and the telecommunications service provider to which the user B belongs; (C) the user B inputs the telephone number of the user A and the associated telecommunications service provider and the amount requested to be transferred;
- the identity authentication system server confirms the identity of the user A according to the phone number of the user A and the associated telecommunications service provider; (e) the identity authentication system server sends information to the mobile device of the user A, To request remittance, the information includes the data of the user B; and (f) the user A decides to conduct the remittance or cancel the remittance procedure.
- the telecommunications service provider to which the user A belongs and the telecommunications service provider to which the user B belongs are the same telecommunications service provider.
- the telecommunications service provider to which the subscriber A belongs and the telecommunications service provider to which the subscriber B belongs are different telecommunications service providers.
- the present invention provides an identity authentication system, comprising: (a) an identity authentication system server loaded with an identity authentication system and storing data records and account passwords for querying identity authentication; (b) mobile devices Including a communication device; (c) an identity authentication request provider, the identity authentication request provider is connected to the identity authentication system and inputs an identity code, a password, and an IP of the mobile device of the identity authentication request provider ( Intemet Protocol), wherein the identity authentication system establishes the identity authentication request provider by using an identity identification code and a password of the identity authentication request provider, and then uses the IP location information of the mobile device from a telecommunication carrier
- the mobile user mobile data server obtains the mobile device's phone number and generates an encrypted code, and then transmits the mobile device's phone number and the encrypted code to the identity authentication request provider for identity authentication.
- the mobile device includes a communication device to receive an encryption code from an identity authentication request provider
- the communication device includes NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasound, and RFID.
- the identity authentication system includes an authentication determining unit, an authentication status unit, and a password management unit, and the authentication determining unit is configured to determine whether the user logs in, whether the user repeats the authentication, and whether the phone number is consistent; the authentication status unit is used to determine Change user The authentication status; the user telephone number judging unit confirms whether the telephone number obtained by the identity authentication system from the telecommunications carrier matches the telephone number provided by the authentication request provider, and feeds back the information to the identity authentication system.
- the present invention provides a mobile payment method based on a two-dimensional code and a telecommunication service provider, comprising: (a) displaying two-dimensional code information obtained from a mobile payment system to a payer, the two-dimensional code information Including an encryption code and a URL location of the mobile payment system; (b) reading the two-dimensional code information using a mobile device, the mobile device utilizing a URL location connection of the mobile payment system in the two-dimensional code information Go to the mobile payment system; (c) the mobile payment system determines the telecommunication service provider used by the user by using the IP address of the mobile device, and then acquires the data of the user from the telecommunication service provider to confirm the user (d) completing the mobile payment using the confirmed identity of the user.
- the user profile includes the user's phone number, user type, and available payment amount.
- the step of completing the mobile payment using the identity of the confirmed user comprises: viewing the account deposit status of the user, and performing the following steps: (i) if the deposit is insufficient, ending the mobile payment and The user displays the cash and retry information that needs to be deposited; or (ii) if the deposit is sufficient, the mobile payment system notifies the telecommunication service provider to deduct the payment amount from the user's telephone account to complete the mobile payment .
- the invention has many advantages. First, users can use their mobile phones for quick authentication or shopping, saving time and efficiency. Secondly, the establishment of the user identity is guaranteed by a third party (telecom service provider) and the security is improved. In addition, users can additionally set login passwords and email notifications, which increases the flexibility of use and further enhances security. Even if the mobile device is lost, there is no need to worry about the account being taken, and the user will be automatically emailed to remind people that they are Use authentication/payment services to prevent misappropriation by others. Users can also customize different effective times, effective time and effective amount according to their needs to meet the different needs of different situations. Furthermore, the flexibility of the present invention is high, and it can be applied to different categories as long as the steps are finely adjusted according to different usage methods.
- the system will display mobile advertisements to the user, and the advertisements can provide the user with information such as shopping discounts, which is different from other advertisement channels, and the method has exact cuts, and no false real people browse. At the same time, it can bring more convenient preferential collection and use to users.
- the advantages of using a method that includes an encrypted encoded URL page address are: a) no need to install specific software, as long as any particular device reads the software, it can receive the URL to open the web page; b) users do not need to change user habits, users are accustomed to using NFC Or QR code scanning software, open the web browsing information after reading (the different place is, not browsing information, open the web page can be authenticated or paid, can make the user more easy to use); c) can use the web page for authentication and payment, Increase cross-platform capabilities and reduce development and maintenance costs; d) For different people's needs, and hope to be more convenient, you can download specific software to run.
- Figure 1 is a system diagram of an embodiment of an identity authentication system based on a telecommunications carrier of the present invention.
- FIG. 2 is a flow chart of an identity authentication system based on a telecommunications carrier of the present invention.
- FIG. 3 is a system diagram of an embodiment of a mobile payment system based on a two-dimensional code and a telecommunications service provider of the present invention.
- FIG. 4 is a flow chart of an embodiment of a mobile payment system based on a two-dimensional code and a telecommunications service provider of the present invention.
- FIG. 5 is a block diagram of a mobile identity authentication system in accordance with one embodiment of the present invention.
- FIG. 6 is a simplified flow chart of mobile identity authentication in one embodiment of the present invention.
- FIG. 7 is a flow chart of mobile payment using an identity authentication system in one embodiment of the present invention.
- Figure 8 is a flow diagram of default fast mobile payment using an identity authentication system in accordance with one embodiment of the present invention.
- Figure 9 is a block diagram of a system for reciprocating funds between users using an identity authentication system in accordance with one embodiment of the present invention.
- FIG. 1 is a system diagram of the present embodiment, including an identity authentication request provider 120, various communication devices 121 receivable in a mobile device, a user mobile device 122, a wireless network 123 of a telecommunications carrier, and an internal carrier.
- Internet internetwork
- an identity authentication system based on a telecommunication operator is characterized in that it includes:
- the identity authentication request provider 120 that is, the merchant that requires confirmation of the identity of the user, the identity authentication request provider 120 first inputs the merchant identification code, the password, and the client (ie, the server facing the user, for example: webpage, electronic gate) After waiting for the IP location and other information, the authentication process is obtained from the identity authentication system.
- the encryption code and/or the identity authentication request provider's mobile terminal's phone number (when the identity authentication request provider's client's IP address is confirmed)
- the authentication processing encryption code can be transmitted to the user's mobile device 122 through the communication device of the user terminal of the identity authentication request provider 120;
- the user mobile device 122 that is, the user's mobile device/mobile terminal, the user uses an application program preinstalled in the mobile device 122 or opens a webpage of the system, and the communication device 121 that activates the mobile device receives the identity processing encryption code;
- the telecommunications carrier's wireless network 123 and the internal network 124, the telecommunications carrier can provide the user's data directly or indirectly;
- the identity authentication system the identity authentication system is authenticated and processed by the encryption code, the query code is valid, and after the user data provided by the telecommunication operator is used, the identity authentication system provides the phone number provided by the telecommunication operator and the required authentication. Matching, or providing the user's phone number to the identity authentication request provider 120, is determined by the identity authentication request provider 120; and
- the authentication system server 128, which is loaded with an authentication system and stores identity authentication data that can be updated, modified, and accessed.
- the above-mentioned identity authentication system using the telecommunication operator is further characterized in that the application telecommunication operator can directly obtain user data, such as a phone number, from the http header or indirectly using the IP location of the user to browse to the telecommunication carrier server.
- the location of the globally located identity authentication system includes an authentication determination unit, an authentication status unit, and a password management unit, wherein the authentication determination unit determines the number of user logins, whether the user repeats the authentication, and whether the telephone number is consistent; the authentication status unit determines and changes the user.
- Authentication status after the user confirms that the identity authentication system obtains the telephone number from the telecommunications carrier and the telephone number of the authentication request provider is matched, the user telephone number judging unit determines that the user's telephone number is correct and feeds back to the The identity authentication system.
- the communication device 121 of the user terminal of the identity authentication request provider is one of NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasonic and RFID communication devices, and other mobile terminal communication devices 121 may also be used.
- the authentication system of the present invention is as follows:
- Step 130 The authentication process begins.
- Step 131 The identity authentication request provider 120 transmits its identity code, password, and IP address of the client (ie, the server facing the user, for example, a web page, an electronic gate, etc.) to the identity authentication system.
- client ie, the server facing the user, for example, a web page, an electronic gate, etc.
- Step 132 The identity authentication request provider 120 obtains the mobile phone number of the mobile terminal that processes the encryption code and the identity authentication request provider 120 from the identity authentication system (when the IP address confirmation of the 120 client of the identity authentication request provider is mobile) Terminal Step 133: The Identity Authentication Request Provider 120 compares whether the mobile phone number of the client of the identity authentication request provider 120 obtained from the identity authentication system is the same as that required.
- Step 134 If it matches, the user identity is passed.
- Step 135 If there is no match, the identity authentication request provider 120 will enable the appropriate delivery device to wait for the user to receive the identity authentication process encryption code, for example: display the two-dimensional code, and let the user use the video scan to transmit the message to the mobile device. terminal.
- the identity authentication request provider 120 will enable the appropriate delivery device to wait for the user to receive the identity authentication process encryption code, for example: display the two-dimensional code, and let the user use the video scan to transmit the message to the mobile device. terminal.
- Step 136 The user opens the application or the mobile authentication website.
- Step 137 Obtain user telephone information from the telecommunications carrier, for example: telephone number.
- Step 138 Establish the identity of the identity authentication system user based on the obtained phone number.
- Step 139 The user turns on the receiving function of the suitable communication device 121 in the mobile device 122, for example: the camera function.
- Step 140 Obtain an identity authentication process encryption code.
- Steps 141 and 142 The mobile identity authentication system confirms whether there is a request for authentication, determines whether it is a duplicate authentication, and prevents duplicate authentication from the same request. If yes, it displays that the authentication information has been completed, and if not, proceeds to the next step to continue the authentication.
- Step 143 The system will transfer the user's mobile phone number to the merchant system, allowing the merchants to compare themselves to increase operational flexibility.
- This embodiment provides an identity authentication system based on a telecom operator, which solves the problem of lack of strong protection and login cumbersome in the account, and does not require the user to install any software. Registration or use of an identity encoder can be used, which simply improves the security of the account, and is convenient and practical.
- An identity authentication system based on a telecommunication carrier characterized in that it comprises:
- the identity authentication request provider 120 that is, the merchant that requires confirmation of the identity of the user, the identity authentication request provider first inputs the merchant identification code, the password, and the IP location data of the client, and obtains the authentication processing encryption code from the identity authentication system.
- the IP address confirmation of the client of the identity authentication request provider 120 is the mobile terminal, the phone number of the mobile terminal of the client of the identity authentication request provider 120 is obtained, and if the identity authentication request provider 120 finds the phone number obtained from the identity authentication system. If the number is incorrect, the authentication device may be transmitted to the mobile device 122 of the user through the communication device 121 of the client of the identity authentication request provider 120, where the user terminal is a server facing the user;
- the user mobile device 122 that is, the user's mobile device/mobile terminal, the user uses the application program preinstalled in the mobile device 122 or opens the webpage of the system, and the communication device 121 that activates the mobile device receives the identity processing plus code;
- the telecommunications carrier's wireless network 123 and the internal network 124, the telecommunications carrier can provide the user's data directly or indirectly;
- the identity authentication system obtains the identity authentication processing encryption code, the query coding effective condition, and after using the user data provided by the telecommunication operator, the identity authentication system compares with the telephone number provided by the telecommunication operator and the identity authentication requirement The match provided by the authentication provider 120, or providing the user's phone number to the identity authentication request provider 120, is determined by the identity authentication request provider 120;
- the identity authentication system server 128, which is loaded with an identity authentication system and stored, is available for querying identity authentication data records and account passwords.
- the telecom operator can directly obtain the user profile from the http header or indirectly using the IP location when the user browses to the telecommunication carrier server.
- the user data obtained by the telecom carrier server is a phone number and a globally located location.
- the identity authentication system includes an authentication determination unit, an authentication status unit, and an information storage unit, wherein the authentication determines whether the user repeats the authentication, whether the phone number is consistent; the authentication status unit determines and changes the user authentication status; and the information storage unit to the system Internal information storage management.
- the authentication judging unit includes: a user telephone number judging unit, after the user confirms that the identity authentication system obtains a phone number from the telecommunication operator and matches the self-phone number, the user phone number judging unit determines that the user phone number is correct and Feedback to the identity authentication system.
- the communication device 121 of the user terminal of the identity authentication request provider is one of NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasonic and RFID communication devices.
- the various communication devices 121 of the mobile terminal receive the information of the identity authentication required in the external or mobile network, and then use the data of the mobile user provided by the telecommunication operator attached to the mobile device.
- the system will compare the phone numbers, return the results to the identity certification request provider 120, or provide the user's phone number to the identity certification request provider 120 for their own comparison.
- the present invention uses the mobile phone number as the authentication criterion, is easy to apply, is globally unique and public, not private. By providing the user's data by the telecom operator, it is possible to automatically identify the user's identity without having to pre-register or install any software, and provide convenience. Disguised and bundled with mobile terminals into a third-party guaranteed identity. People without a token can implement third-party protection for the account.
- the various communication devices 121 of the mobile device or the information of the identity authentication request in the mobile network are used, and the data of the mobile user provided by the telecommunication operator attached to the mobile device, such as a telephone number, etc., is used.
- the system will compare the phone numbers, return the results to the certification request provider, or provide the user's phone number to the certification request provider, and they will make their own comparisons. Each certification will be recorded in the system for easy access.
- the identity authentication system can be used to allow the activity participants to self-register or report to the organizer's computer, which can improve the efficiency of the activity.
- the identity authentication system can be used to increase the reliability of the recipient's phone number.
- FIG. 3 is a system diagram of the present embodiment, including a payment request provider 11, two-dimensional code information 12 showing payment requests, a user mobile device 122, a wireless network 123 of a telecommunications service provider, an internal network 124 of a telecommunications service provider, Mobile subscriber IP address of telecommunications service provider The address data server 16, the mobile subscriber payment processing server 126 of the telecommunications service provider, the internet (Internet) 127, and the payment transaction server 19.
- identity authentication request provider 120 is the payment request provider 11 in this example; various communication devices 121 receivable in the mobile device are specifically two-dimensional code information 12; mobile user mobile data server of the telecommunication operator In this embodiment, the mobile subscriber IP address data server 16 of the telecommunications service provider; the identity authentication system server 128 becomes the payment transaction server 19.
- Step 101 The consumer begins to pay with the mobile payment system.
- Step 102 The consumer reads the barcode content through the downloaded application and photography function of the mobile device.
- Step 103 The consumer obtains payment information from the barcode.
- Step 104 The consumer can proceed with the payment process in the downloaded application or on the web page entering the mobile payment system.
- Steps 105 and 106 The mobile payment system confirms whether there is a payment request and prevents the same transaction from being repeated.
- Steps 107 and 108 The mobile payment system uses the IP address of the mobile device to check with the IP address range of the telecommunication service provider to find an appropriate telecommunication service provider.
- Step 109 If the IP address is correct, the mobile payment system obtains the mobile account information from the appropriate telecommunication service provider.
- Steps 110 and 111 The mobile payment system checks the deposit status of the account. If the deposit is insufficient, the payment system displays to the consumer information that needs to deposit cash or transfer cash to increase the payment amount.
- Step 112 The payment system asks the consumer to enter a personal password that has been established when the first use payment system is established.
- Steps 113 and 114 The payment is confirmed by the consumer.
- Step 115 The mobile payment system notifies the telecommunications service provider to deduct the payment amount from the telephone account of the user's mobile device.
- Step 116 The mobile payment system connects the user's telephone account with the payment request, and sets the payment preparation status to the paid status, preventing duplicate payment and notifying the merchant that the payment has been successfully made.
- Step 117 The consumer completes the payment process using the mobile payment system.
- a mobile payment system based on a two-dimensional code and a telecommunication service provider characterized in that it includes;
- the payment request provider 11 that is, the merchant who requests payment and provides the payment amount, and the payment request provider displays the two-dimensional code information 12 obtained from the mobile payment system to the payer;
- the user mobile device 122 uses the two-dimensional code reading application pre-installed in the mobile device 122, or uses the application designed for the invention to activate the video scanning function of the mobile device 122 to read the second The payment encryption code in the dimension code information 12 and the URL location of the system;
- each telecommunication service provider pre-assigns different IP addresses to the user's mobile device, and the IP location is equal to the user's personal identity code.
- the mobile payment system uses this mechanism to obtain user information, such as phone number, user type (monthly payment, stored value card or roaming), available payment amount, etc., using the IP address;
- the mobile payment system After the payer clicks on the URL to enter the web version of the mobile payment system, or processes the URL message using the application designed for the invention, the mobile payment system obtains the payment code from the URL, checks the payment status, and uses the mobile terminal when browsing. IP position to phase After the telecommunications service provider obtains the user's data, the payment amount is deducted from the mobile phone account of the user mobile device 122.
- the embodiment provides a mobile payment system based on a two-dimensional code and a telecommunication service provider, which aims to solve the problem of inconsistent payment methods in online and offline environments, and can be used without prior registration by a bank or a credit card provider. There is no need for the intervention of banks and credit card companies, which greatly improves the security of payment payments. At the same time, people without bank and credit card accounts can achieve mobile payment effects, which is convenient and practical.
- the online and offline payment information is displayed in a pattern by using a two-dimensional code, and then the barcode function (the barcode here refers to the two-dimensional code information 12) is read by the photographing function of the mobile device 122 held by the consumer, and then Using the IP address of the mobile device 122, the mobile account information is obtained from the telecommunication service provider to automatically identify the identity of the consumer; and the user mobile phone account is used as the payment account, and each consumption is recorded in the system for convenient access.
- the barcode here refers to the two-dimensional code information 12
- the advantageous effects are as follows: Using the mobile phone number account as a payment path, the use is safe and convenient, the consumer can use the mobile device 122 as a payment tool with confidence and equal access, and pay the offline and online expenses in the same manner. It can be used without registering in advance with a bank or credit card provider. Without the intervention of banks and credit card companies, the security of payment is greatly enhanced, and people without bank and credit card accounts can realize the dream of mobile payment.
- SMS mobile payment During the mobile payment process, the payer's personal information will not be disclosed to third parties.
- the disadvantage of SMS mobile payment is that the payer must disclose the number of the mobile phone; when using any card type, such as a credit card or debit card, the disadvantage is that the personal data on the card has the opportunity to be stolen and the payer is unaware .
- the mobile payment service of the present invention is not provided by providing data such as a credit card or a bank card, when a young person signs up for a party or a group event, it is only necessary to use ordinary personal smart electricity. In this way, the payment system of the present invention can be paid immediately after registration on the Internet, without waiting, eliminating the time required for young people to register, and facilitating the event organizer to more efficiently know the number of payers and the total amount charged.
- FIG. 5 is a block diagram of the identity authentication system of the present embodiment.
- the identity authentication system includes a user device 20 (a device used by a user requiring authentication), an identity authentication system server 128, a mobile subscriber mobile data server 125 of the telecommunications carrier, and a verification device 26 (ie, the identity authentication request provider of FIG. 1) 120 devices used).
- the user device 20 includes a non-mobile device and a mobile device 122 (mobile terminal), and the non-mobile device includes a device such as a computer that can be connected to the Internet, and the mobile device 122 includes all built-in Subscriber Identity Modules (SIMs).
- SIMs Subscriber Identity Modules
- Portable devices connected to the network such as mobile phones, Personal Digital Assistants (PDAs), and tablets.
- the identity authentication system server 128 is responsible for the authentication work, which receives the authentication request from the verification device 26, and then the identity authentication system server 128 generates the URL web page address and the encryption code (the code is encrypted to prevent others from modifying) according to the authentication request, and The encrypted code is embedded in the URL web page address to obtain a URL web page address containing the encrypted code, and the URL web page address including the encrypted code is transmitted back to the verification device 26, and the verification device 26 thereafter uses the URL address of the web page containing the encrypted code for identity authentication. Verification device 26 After obtaining the URL of the URL containing the encrypted code, the URL page address including the encrypted code is transmitted to the user device 20 when the identity authentication is required to start the user's true authentication process.
- the identity authentication of the present invention is completed by the assistance of a third party, which is a telecommunications service provider (telecom operator).
- the mobile subscriber mobile data server 125 of the telecommunications service provider stores the personal data of the mobile subscriber, including his/her name, address, Mobile phone number, account number, account balance, and more.
- the user needs to require the telecommunications service provider to enable the service, and in addition, the user may also register with the identity authentication system server 128 to indicate that they are using the service.
- the identity authentication system server 128 is coupled to the mobile user mobile data server 125 and obtains the telephone number of the user's mobile device and the user's data to confirm the identity of the user.
- the verification device 26 is provided in a related mechanism that requires authentication, and has the ability to communicate with the user device 20 by a specific delivery method.
- the specific delivery mode includes all delivery modes supported by the user device 20, such as barcode, microwave, sound wave, specifically including fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency. Identification (RFID) and so on.
- the verification device 26 can be a computer, a server, or the like.
- step 28 the authentication process begins at step 28, where the user first opens a particular application installed on the user device 20, or connects to the website via the network function of the user device 20, the website being hosted by the verification device 26, the website It can be a website that requires certification, such as shopping websites, online banking, consumer websites, and government websites.
- step 30 the purpose of step 30 is to connect to the verification device 26 using the user device 20, which is a TCP/IP connection between the user device 20 and the verification device 26, including any wired or wireless technology available now or in the future.
- Wireless technologies include Wi-Fi, General Packet Radio Service (GPRS), Third Generation Mobile Communications (3G), and Fourth Generation Mobile Communications (4G).
- the authentication device 26 collects the necessary data, including the Internet Protocol Address and the communication port (Port) of the user device 20 used by the user.
- the verification device 26 generates an authentication request according to the collected data, and sends the authentication request to the identity authentication system server 128, where the authentication request includes data input by the user, and an Internet Protocol Address of the user device 20. And the communication port (Port).
- the identity authentication system server 128 After receiving the authentication request, the identity authentication system server 128 determines whether the user device is a mobile device connected to the mobile phone network (for example, 3G/4G) based on the Internet Protocol address and the communication port (Port) of the user device 20, thereby obtaining device determining. As a result, the identity authentication system server 128 generates a URL web page address and encryption code based on the authentication request, and embeds the encryption code into the URL web page address to obtain a URL web page address including the encrypted code (step 34), after which the identity authentication system server 128 The device determination result and the URL web page address including the encryption code are transmitted back to the verification device 26 (step 36). At step 38, the verification device 26 uses the resulting URL web page address containing the encrypted code for identity authentication.
- the verification device 26 uses the resulting URL web page address containing the encrypted code for identity authentication.
- Encryption coding includes the use of conditional parameters such as the number of valid times and the effective time, the effective number defines the number of times the encryption code can be used, and the effective time defines the usable time of the encryption code.
- the effective number and effective time of the encryption code are set by the verification device 26 as needed.
- the setting is included in the authentication request, and the identity authentication system server 128 receives the authentication request and generates the appropriate data (including settings). URL page address and encryption code. If you need to perform authentication actions frequently, you can set the number of times of multiple times, such as 10 times. On the contrary, if it is not necessary or for security reasons, you can set the encryption code to be used only once. After the first use, the encryption code is used. It will become invalid, even if others get it.
- the effective time of the encryption code limits the usage time of the encryption code.
- the encryption code can be set to be valid only for a certain period of time, such as one day, one week or one month, exceeding the valid time, even if the encryption code is left. ⁇ Effective times, the encryption code will also become invalid, which greatly improves security.
- the identity authentication can be performed. The present invention mainly uses the user's phone number to complete the identity authentication, so the user must finally use the mobile device 122 to perform the final authentication step, as before.
- the mobile device 122 includes all portable devices that have a Subscriber Identity Module (SIM card) built in and can be connected to the network, such as a mobile phone, a Personal Digital Assistant (PDA), and a tablet. Since the identity authentication system server 128 transmits the device determination result together while transmitting the URL page address including the encrypted code to the verification device 26, the verification device 26 knows that the user is using a non-mobile device or mobile device 122, if the user device 20 is The mobile device 122, which uses the mobile phone network to access the Internet, transmits the URL page address containing the encrypted code directly to the mobile device 122 via the mobile phone network. The mobile device 122 uses the browser or software to read the URL of the URL containing the encrypted code. Identity authentication is performed.
- SIM card Subscriber Identity Module
- the authentication device 26 requires the user to switch to the mobile device 122 on the mobile phone network and transmit the URL containing the encrypted code through a specific delivery method.
- the web page address is transferred to the mobile device 122 for identity authentication.
- the step of determining that the user device 20 is a mobile device that uses the mobile phone network to access the Internet or the mobile device that does not use the mobile phone network to access the Internet may also be performed by the verification device 26, since the user device 20 is sometimes in the same space as the verification device 26.
- the verification device 26 can detect the Internet Protocol Address of the user device 20 to obtain the device determination result, and then the verification device 26 is transmitting. Include an encrypted encoded URL web page address to require the user to open the URL page address containing the encrypted code directly for use in a browser or software for authentication or to switch to another mobile device 122 using the mobile phone network for authentication.
- the specific delivery mode referred to in the present invention includes all transmission modes supported by the user device 20, such as barcode, microwave, sound wave, specifically including fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless. Fidelity (Wi-Fi) and Radio Frequency Identification (RFID) and many more.
- the verification device 26 may transmit the URL web page address containing the encrypted code to the mobile device via a barcode (Quick Response Matrix Code), first the verification device 26 displays the barcode, including in any form such as projection, display display, and the like.
- the user turns on the associated program of the mobile device 122 to read the barcode and receives the URL web address containing the encrypted code, after which the web address will direct the mobile device 122 to the identity authentication system server 128, after which the identity authentication system server 128 will act according to the mobile device 122.
- the characteristics identify the user's identity.
- the feature of the mobile device 122 referred to herein refers to the mobile subscriber international number (MSISDN) of the mobile device 122, referred to herein as the telephone number.
- MSISDN mobile subscriber international number
- IMSI International Mobile Subscriber Identifier
- the identity authentication system server 128 obtains the Internet Protocol address (IP address) of the mobile device 122, because each telecommunication service provider registers and manages from the regional Internet.
- the organization Regional Internet registry (RIR) obtains a certain range of unique Internet Protocol addresses, which are known to the telecommunication service provider according to the scope of the Internet Protocol address, and then the identity authentication system server 128 transmits the Internet Protocol address of the mobile device 122.
- the mobile subscriber data server 125 to the corresponding telecommunications service provider and the mobile subscriber mobile data server 125 are required to pair to provide the telephone number and subscriber data corresponding to the internet protocol address.
- the present invention is applicable to Internet Protocol version 4 (IPv4), Internet Protocol version 6, IPv6, or any future available Internet protocol version.
- IPv4 Internet Protocol version 4
- IPv6 Internet Protocol version 6
- the identity authentication system server 128 can obtain the Internet Protocol Address and the communication port (Port) of the mobile device, and then the identity.
- the authentication system server 128 transmits the Internet Protocol Address and the port of the mobile device to the mobile user mobile data server 125 of the corresponding telecommunication service provider and requests the mobile user to move the data server 125 for matching. Correct.
- the mobile user mobile data server 125 stores a mapping table of an Internet Protocol Address and a communication port (Port), and the mapping table records a specific mobile internet protocol address (Internet Protocol Address) and a communication port (Port).
- the mobile phone number (MSISDN) according to the determined telephone number (MSISDN), the corresponding user can also be determined. Because each mobile phone number (MSISDN) is bundled with a unique Mobile Internet Protocol Address and Port, the user identity determined by this method is true and unique, and is obtained. Third party (telecom company) guarantee. After the mobile device 122 is directed to the identity authentication system server 128, the authentication process is automatically performed, and the user does not need to perform any operations.
- the identity authentication system server 128 automatically completes the authentication and transmits the result back to the mobile device 122 and the verification device 26, the authentication procedure. Then it ends.
- the system of the present invention incorporates a forced suspension function that can be performed on either of the user's mobile device 122, the authentication device 26, or the identity authentication system server 128, for example, the user feels on the way to authentication. If there is a problem with the website or according to its own wishes, the user can enable the forced suspension function to end the authentication process.
- the verification device 26 or the identity authentication system server 128 can automatically enable the forced suspension function when a malicious attack or system instability is detected to prevent data leakage and the like.
- the forced abort function is controlled by an authentication abort module included in mobile device 122, authentication device 26, and identity authentication system server 128.
- the embodiment of the identity authentication has been described in detail above.
- the method and system for identity authentication can be applied to different categories and environments as needed, such as identification of a visitor, authentication of a pass, and confirmation of a consumer identity.
- the following describes the identity authentication method and the specific application of the system.
- the embodiments of the identity authentication system and method are described in detail above.
- the following describes its application in mobile payment (ie, consumer shopping), the main principles of application in mobile payment and
- the procedure is basically the same as the second embodiment of the identity authentication system and method described above, except that the steps are partially increased or decreased.
- the hardware configuration required for the application of the mobile payment in this embodiment is the same as that of the second embodiment of the identity authentication system.
- the user equipment 20, the identity authentication system server 128, the mobile user mobile data server 125, and the verification are included.
- the authentication request provider is a retailer
- the verification device 26 is typically a server hosting a retailer's shopping website.
- the identity authentication system server 128 is responsible for the central settlement of transactions in addition to the authentication work.
- the identity authentication system server 128 is equivalent to the mobile subscriber IP address data server 16 of the telecommunication service provider and the mobile subscriber payment of the telecommunication service provider in the embodiment of the mobile payment system based on the two-dimensional code and the telecommunication operator (telecom service provider)
- the combination of the processing server 126 it is conceivable that the mobile user IP address data server 16 and the mobile user payment processing server 126 are combined to obtain an identity authentication system server 128, which has a mobile user IP address data server 16 and a mobile user payment processing server 126. The function of the person.
- FIG. 7 shows a flow chart for mobile payment using an authentication system.
- the process begins in step 42, and the basic flow of the mobile payment is similar to the process of the second embodiment of the identity authentication system.
- the user connects to the verification device 26 using the user device 20, i.e., browses the relevant shopping website (step 44), and the user selects the appropriate item and settles the account.
- the verification device 26 (shopping website) obtains data such as the amount of money the user needs to pay and obtains the IP address and communication port of the user device 20, and the verification device 26 then sets the data and the IP address and communication port of the user device 20. (Port) is transmitted to the identity authentication system server 128.
- the identity authentication system server 128 In step 48, the identity authentication system server 128 generates a URL webpage address and an encryption code based on the received data, and embeds the encryption code into the URL webpage address to obtain a URL webpage address including the encrypted code, and according to the IP address and communication of the user device 20.
- the port determines whether it is a mobile device that uses the mobile phone network to access the Internet, and then passes the URL page address and device determination result containing the encrypted code back to the verification device 26.
- the steps here are basically the same as the steps of the second embodiment of the identity authentication system, except that the mobile payment implementation is implemented.
- the cryptographically encoded usage condition parameter of the example includes, in addition to the effective time and the effective number of times, an amount to be paid, which defines the amount the user needs to pay.
- the verification device 26 After receiving the URL page address and the device determination result including the encryption code, the verification device 26 knows whether the user device 20 is the mobile device 122 accessing the Internet using the mobile phone network based on the device determination result (step 50), if the mobile phone network is used for mobile Internet access The device 122 allows the URL address containing the encrypted code to be directly transmitted to the mobile device 122 through the mobile phone network. If the mobile device 122 is not using the mobile phone network, the user is required to switch to the mobile device 122 on the mobile phone network. The URL page address containing the encrypted code is transmitted to the mobile device 122 by a particular delivery method.
- the verification device 26 allows the URL page address containing the encrypted code to be transmitted directly to the mobile device 122 over the mobile telephone network, the user has other options, the user may select the mobile device 122 being used for payment (step 52), or may choose to use other The mobile device 122 makes a payment (step 54). After the user makes a selection, the web page address containing the encrypted code is received (step 58). When the verification device 26 knows that the user device 20 is not the mobile device 122 that uses the mobile phone network to access the Internet based on the device determination result, the user is required to receive the URL page address including the encrypted code using the mobile device 122 surfing the Internet through the mobile phone network, and the user switches to the mobile device. After device 122, step 58 is performed.
- the subsequent program is the same as the process of the second embodiment of the identity authentication system, and is not repeated here in detail.
- the mobile device 122 reads the URL web page address containing the encrypted code, which will direct the mobile device to the identity authentication system server 128, after which the identity authentication system server 128 will retrieve the user data from the telecommunications service provider (step 60). And thereby establishing the identity of the user (step 62), the user data report including the user's phone number, its corresponding account information, and account balance.
- the detailed method is to use the mapping of the IP address and the communication port (Port), which has been explained in detail in the second embodiment of the identity authentication system above.
- the identity authentication system server 128 checks if the encryption code is valid (step 64), such as whether the valid time parameter is still within the validity period, whether the effective number is established, and the like. If the encryption code is valid, proceed to step 68. If not, proceed to step 66 to send the invalidation message to the user and end the payment procedure. At step 68, the identity authentication system server 128 checks whether the user account has sufficient amount to pay for the transaction. If the amount is sufficient, proceed to step 72. Otherwise, proceed to step 70. In step 70, the identity authentication system server 128 notifies the user that the amount is insufficient, prompting the user. Add value and end the payment process.
- the encryption code is valid
- the identity authentication system server 128 processes the payment, requesting the mobile subscriber's mobile data server 125 of the telecommunications service provider to deduct the corresponding amount in the user's corresponding account, and the deducted amount is transferred to the corresponding shopping website's account accordingly.
- the corresponding shopping website has been previously registered or registered with the identity authentication system server 128 and obtained the merchant code.
- the identity authentication system server 128 uses the merchant code to confirm the identity of the merchant and knows its related data, such as account number, address, and the like. After the deduction is successful, the mobile user mobile data server 125 sends the confirmation information to the identity authentication system server 128.
- the identity authentication system server 128 After receiving the confirmation information, the identity authentication system server 128 updates the user's data, such as the used amount, and finally sends the payment success information to The retailer's verification device 26 and the user's mobile device 122 complete the payment process at step 74 and finally terminate the payment process (step 76).
- the user uses the mobile payment for consumption, and the used account port is the user's mobile phone account account port, and the consumption amount is directly displayed on the user's mobile phone bill.
- the user can purchase the mobile phone recharge card to recharge anytime and anywhere to increase the flexibility of the payment.
- the identity authentication system server 128, in addition to performing the authentication work in the embodiment of the mobile payment, is also responsible for the central settlement of the transaction, and the identity authentication system server 128 communicates with the mobile user mobile data server 125 and the verification device 26 of the retailer.
- FIG. 8 is a flow chart of the present invention utilizing the identity authentication system of the second embodiment of the identity authentication system for default fast mobile payment.
- the application of the preset fast mobile payment mainly omits part of the above mobile payment embodiment, and generates a URL webpage address and an encryption code in advance.
- the encryption code is embedded in the URL page address to obtain the URL address of the URL containing the encrypted code for use, thereby improving efficiency and facilitating fast payment/purchase.
- the merchant needs to register or register with the identity authentication system server 128 first to enable the identity authentication system server 128 to recognize its identity.
- the merchant transmits data such as the amount of money that the user needs to pay to the identity authentication system server 128, and the identity authentication system server 128 generates a URL webpage address and encryption code in advance based on the data, and encrypts the code.
- the encryption code includes conditional parameters such as an amount to be paid (which defines the amount of money the user needs to pay), a valid number of times, and a valid time, and these condition parameters can be defined by the merchant. .
- the effective number is set to 1, because an encrypted code corresponds to one item.
- the identity authentication system server 128 immediately updates the data, and the effective number becomes 0 to prevent others from repeating the same. Encrypted encoding, causing confusion. However, in special cases or individual needs, the effective number can also be set to be greater than 1, such as 2, 3, 5, and so on.
- the webpage address including the encrypted code is pre-generated, and can be set in a specific manner in an individual place, and the specific manner includes all the delivery modes supported by the user's mobile device 122, such as a barcode, a microwave, an acoustic wave, and specifically includes a quick response matrix code.
- a quick response matrix code including a URL page address containing an encrypted code can be placed next to the item in the store, and when the buyer selects, the mobile device 122 can be immediately read to read the quick response matrix code (i.e., step 78).
- the URL page address including the encrypted code can be transmitted through Near Field Communication (NFC), Bluetooth, infrared, etc., to allow the mobile device 122 to receive, and the user can select the desired product at any time without After the attendant's participation.
- NFC Near Field Communication
- the web page address directs the mobile device 122 to the identity authentication system server 128, and then the identity authentication system server 128 obtains the user data according to the characteristics of the mobile device 122 (step 79). And establish the user Share (step 80). Subsequent steps 81-87 and steps 64, 66, 68, 70, 72 in FIG.
- Embodiment of the system in Embodiment 2 using the identity authentication system and method of the present invention allows users to remit money to each other
- This embodiment is to facilitate mutual money transfer (transfer of money) between different users through the system of the present invention without going through a bank.
- 9 shows a block diagram of the present embodiment in which mobile devices 122 of different users communicate with the identity authentication system server 128 of the telecommunications service provider, and the identity authentication system server 128 and the mobile user mobile data server 125 communicate with each other.
- the remittance mentioned here refers to the transfer of the amount of mobile accounts of different users.
- User A (remittance user) wants to transfer the amount in his mobile account (telephone account) to the mobile account of User B (the user receiving the remittance), who can open the dedicated application of mobile device 122 or open a specific The URL is connected to the authentication system server 128.
- the identity authentication system server 128 then obtains the IP address and communication port (Port) of the mobile device 122 as described above, communicates with the mobile user mobile data server 125, maps and establishes the identity of the user. The specific steps have been described in detail above and will not be repeated here. After the identity of the user A is confirmed, the user A needs to input the telephone number of the user B, the telecommunications service provider used by the user B, and the transferred amount, and transmit to the identity authentication system server 128, and the identity authentication system server 128 then moves with the corresponding mobile user.
- the data server 125 contacts, and uses the phone number to search for the identity and data of the user B (such as its telecommunications account number, etc.).
- the identity authentication system server 128 After the identity of both parties is confirmed, the identity authentication system server 128 performs central settlement, requiring the same telecommunications service provider or mobile subscriber data server 125 of a different telecommunications service provider to directly deduct the corresponding amount from the subscriber's telecommunications account and The corresponding amount is added to User B's telecommunications account. Upon completion of the settlement, the identity authentication system server 128 will send a success message to both parties' mobile devices to complete the procedure. The transfer of the amount will be directly displayed in the telecom statement of both parties. According to the above, User A and User B may be customers of the same telecommunications service provider or customers of different telecommunications service providers.
- user B (user who requests remittance) can also Remittance is required to require User A (the user who is required to send money) (ie, the remittance procedure can also be initiated by User B).
- User B first connects to the identity authentication system server 128 to establish identity, and then enters the phone number of User A, the telecommunications service provider used by User A, and the amount requested to be transferred.
- the identity authentication system server 128 establishes the identity of the user A based on the provided data, and transmits the information (including the data of the user B) to the mobile device 122 of the user A to request the money transfer.
- User A has the right to decide, and if it agrees, proceed with the steps described above. If User A does not agree, it can cancel the remittance process.
- the identity authentication system server 128 detects an abnormal situation, such as the identity of the user may be stolen, the identity authentication system server 128 suspends the authentication process and automatically emails the user to remind the user that someone is using the authentication service, requesting the user Determine if it is his or her own, otherwise the certification process cannot proceed.
- all of the embodiments described above may incorporate a forced suspension function that can be performed on either of the user's mobile device 122, the authentication device 26, or the identity authentication system server 128, for example, the user is on the way to authentication.
- the user can enable the forced suspension function to end the authentication process, and then the identity authentication system server will notify the merchant to stop the service to the user, in case of being spoofed by the phishing network or the intermediary, so that the user can be provided more Great protection.
- the verification device 26 or the identity authentication system server 128 is detecting a malicious attack or The forced abort function can be automatically enabled in case of unstable system to prevent data leakage and the like.
- the forced abort function is controlled by an authentication abort module included in mobile device 122, authentication device 26, and identity authentication system server 128.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Telephonic Communication Services (AREA)
- Mobile Radio Communication Systems (AREA)
Description
基于电信服务商的移动身份认证和支付的方法与系统 技术领域 Method and system for mobile identity authentication and payment based on telecommunication service provider
本发明涉及一种移动身份认证及支付的方法和系统, 特别是一种 基于电信服务商的快速移动身份认证及支付的方法和系统。 The present invention relates to a mobile identity authentication and payment method and system, and more particularly to a method and system for fast mobile identity authentication and payment based on a telecommunications service provider.
背景技术 Background technique
在现实生活中, 人们在不同的场合都需要进行各种不同的认证以 确认身份,例如:参加会议和进行消费等。但是, 过多的通行证或证件 会造成携带上的不便, 而且认证的过程繁瑣, 花费时间。 此外, 现有 技术的认证方法往往存在安全性的问题,容易发生个人资料外泄的后 果, 特别是在进行消费的时候。 In real life, people need to carry out various certifications on different occasions to confirm their identity, such as attending meetings and making consumption. However, excessive passes or documents can cause inconvenience in carrying, and the authentication process is cumbersome and time consuming. In addition, prior art authentication methods often have security problems, which are prone to the consequences of personal data leakage, especially when making consumption.
目前基于信用卡和银行的消费支付占据了一定的巿场额度, 但是 所述的支付途径都需要用户名、登录用户名和密码作为身份识别的方 法, 所述现有技术的缺陷是容易造成系统和帐户的安全问题, 经常发 生盗用身份, 盗刷信用卡等问题, 干扰了正常的消费秩序。 其次输入 用户名、 登录用户名和密码, 会造成个人信息的外泄, 为不法分子提 供了可乘之机。 另外, 没有银行账户或者信用卡的人, 在异地支付时 造成了不便。 At present, credit card and bank-based consumer payment occupy a certain market quota, but the payment method requires a user name, a login user name and a password as a method for identification, and the prior art has the drawback that it is easy to cause the system and the account. Security issues, frequent misappropriation of identity, theft of credit cards and other issues, interfere with normal consumption order. Secondly, entering the user name, login user name and password will cause the leakage of personal information and provide an opportunity for the criminals. In addition, people who do not have a bank account or a credit card are inconvenienced when paying offsite.
发明内容 Summary of the invention
因此, 本发明提供了一种身份认证的方法, 包括:(a)使用用户装 置连接到验证装置; (b) 通过验证装置发送认证请求到身份认证系统 服务器; (c) 身份认证系统服务器根据认证请求产生 URL 网页地址 和加密编码, 并把所述加密编码嵌入所述 URL 网页地址以得到包含 加密编码的 URL 网页地址, 再把所述包含加密编码的 URL 网页地 址传送回验证装置; (d) 验证装置指示用户使用合适的装置去接收 包含加密编码的 URL 网页地址以连接到身份认证系统服务器;和 (e) 身份认证系统服务器使用合适的装置的特征以进行身份认证。其中加 密编码还包括使用条件参数, 该条件参数包括:(i) 有效次数, 其定义 了所述加密编码的可使用次数; 和 (ii) 有效时间, 其定义了所述加 密编码的可使用时间。 Accordingly, the present invention provides a method of identity authentication, comprising: (a) connecting to a verification device using a user device; (b) transmitting an authentication request to the identity authentication system server by the verification device; (c) authenticating the system server according to the authentication Requesting to generate a URL webpage address and an encryption code, embedding the encryption code in the URL webpage address to obtain an encrypted webpage address including the encrypted code, and transmitting the URL address containing the encrypted code to the verification device; (d) The verification device instructs the user to use a suitable device to receive the URL web address containing the encrypted code to connect to the identity authentication system server; and (e) the identity authentication system server uses the characteristics of the appropriate device for identity authentication. The encryption code further includes using a condition parameter, the condition parameter includes: (i) a valid number of times, and the definition thereof The number of times the encryption code can be used; and (ii) the effective time, which defines the usable time of the encryption code.
在上述身份认证的方法的一个实施例, 其中身份认证系统服务器 在传送包含加密编码的 URL 网页地址到验证装置前, 根据认证请求 中包含的用户装置的互联网协议地址 (Internet Protocol Address)确定 用户装置是否为使用移动电话网络上网的移动设备以得到装置确定 结果, 并把装置确定结果和所述包含加密编码的 URL 网页地址一起 传送回验证装置,然后验证装置执行以下步骤:(i) 若所述用户装置是 使用移动电话网络上网的移动设备,则直接通过移动电话网络传送包 含加密编码的 URL 网页地址到移动设备以进行所述身份认证;或 (ii) 若所述用户装置不是使用移动电话网络上网的移动设备,则要求所述 用户使用以移动电话网络上网的移动设备并通过特定的传递方式传 送包含加密编码的 URL 网页地址到移动设备以进行身份认证。 In an embodiment of the method for identity authentication, wherein the identity authentication system server determines the user device according to an Internet Protocol Address of the user device included in the authentication request before transmitting the URL page address including the encrypted code to the verification device. Whether it is a mobile device using the mobile phone network to obtain a device determination result, and transmitting the device determination result together with the encrypted URL page address back to the verification device, and then the verification device performs the following steps: (i) if The user device is a mobile device that uses the mobile phone network to access the Internet, and directly transmits the encrypted web page address including the encrypted code to the mobile device for the identity authentication through the mobile phone network; or (ii) if the user device is not using the mobile phone network The mobile device surfing the Internet requires the user to use the mobile device that accesses the Internet via the mobile phone network and transmit the URL address containing the encrypted code to the mobile device for identity authentication through a specific delivery method.
在上述身份认证的方法的另一个实施例, 其中合适的装置为使用 移动电话网络上网的移动设备,所述使用移动电话网络上网的移动设 备可使用包含加密编码的 URL 网页地址连接到身份认证系统服务 器。 而所述特定的传递方式包括条形码、 微波和声波。 In another embodiment of the method for identity authentication described above, wherein the suitable device is a mobile device that uses a mobile phone network to access the Internet, the mobile device using the mobile phone network to connect to the identity authentication system can use a URL web address including an encrypted code to connect to the identity authentication system. server. The specific delivery methods include barcodes, microwaves, and sound waves.
在另一实施例, 其中移动设备的特征为该移动设备的电话号码 (MSISDN) , 而身份认证系统服务器取得移动设备的电话号码 (MSISDN)的方法为: (i) 获得所述移动设备的互联网协议地址 (Internet Protocol Address)及通讯端口(Port)并从相应的电信服务商取 得对应于所述互联网协议地址 (Internet Protocol Address)及所述通讯 埠 (Port)的电话号码 (MSISDN)及电信服务商标识符 (IMSI); 或 (ii)读 取所述移动设备中的用户身份模块 (Sim Card)的数据并基于所述数据 确定电信服务商标识符(IMSI)及所述移动设备的电话号码 (MSISDN); 或 (iii) 从所述认证请求的标头 (HTTP Header)获得电信 服务商标识符 (IMSI)及所述移动设备的电话号码 (MSISDN)。 另一方面, 本发明提供了一种身份认证的系统, 包括:(a)用户装 置; (b) 验证装置, 其中用户使用用户装置连接到验证装置并输入数 据到验证装置,验证装置根据所述资料发送认证请求; 和 (c) 身份认 证系统服务器, 以接收认证请求并根据认证请求产生 URL 网页地址 和加密编码; 其中身份认证系统服务器把加密编码嵌入 URL 网页地 址以得到包含加密编码的 URL 网页地址,并把包含加密编码的 URL 网页地址传送回验证装置,验证装置指示用户使用合适的装置去接收 包含加密编码的 URL 网页地址以连接到身份认证系统服务器进行身 份认证。加密编码包括使用条件参数,所述条件参数包括:(a) 有效次 数, 其定义了加密编码的可使用次数; 和 (b) 有效时间, 其定义了 加密编码的可使用时间。 In another embodiment, wherein the mobile device is characterized by the mobile device's telephone number (MSISDN), and the identity authentication system server obtains the mobile device's telephone number (MSISDN) by: (i) obtaining the mobile device's internet Protocol address (Internet Protocol Address) and communication port (Port) and obtain the telephone number (MSISDN) and telecommunication service corresponding to the Internet Protocol Address and the port from the corresponding telecommunication service provider An identifier (IMSI); or (ii) reading data of a subscriber identity module (Sim Card) in the mobile device and determining a telecommunications service provider identifier (IMSI) and a telephone number of the mobile device based on the data (MSISDN); or (iii) Obtaining a Telecommunications Service Identifier (IMSI) and a mobile device's telephone number (MSISDN) from the header of the authentication request (HTTP Header). In another aspect, the present invention provides a system for identity authentication, comprising: (a) a user device; (b) a verification device, wherein the user connects to the verification device using the user device and inputs data to the verification device, the verification device according to the And the (c) identity authentication system server receives the authentication request and generates a URL webpage address and an encryption code according to the authentication request; wherein the identity authentication system server embeds the encryption code into the URL webpage address to obtain the URL page including the encryption code The address and the URL address containing the encrypted code are transmitted back to the verification device, and the verification device instructs the user to use a suitable device to receive the URL of the URL containing the encrypted code to connect to the identity authentication system server for identity authentication. Encrypted encoding includes the use of conditional parameters including: (a) a valid number of times that defines the number of times the ciphering code can be used; and (b) an effective time that defines the usable time of the ciphering code.
在上述身份认证的系统的一个实施例, 其中身份认证系统服务器 包括装置确定模块, 以在传送所述包含加密编码的 URL 网页地址到 所述验证装置前,根据认证请求中包含的用户装置的互联网协议地址 (Internet Protocol Address)确定用户装置是否为使用移动电话网络上 网的移动设备以得到装置确定结果,并把装置确定结果和包含加密编 码的 URL 网页地址一起传送回验证装置, 然后验证装置执行以下步 骤:(i) 若用户装置是使用移动电话网络上网的移动设备,则直接通过 移动电话网络传送包含加密编码的 URL 网页地址到移动设备以进行 所述身份认证; 或 (ii) 若用户装置不是使用移动电话网络上网的移 动设备,则要求用户使用以移动电话网络上网的移动设备并通过特定 的传递方式传送包含加密编码的 URL 网页地址到移动设备以进行所 述身份认证。 In an embodiment of the above-described identity authentication system, wherein the identity authentication system server includes a device determining module to: according to the Internet of the user device included in the authentication request, before transmitting the URL address including the encrypted code to the verification device The Internet Protocol Address determines whether the user device is a mobile device using the mobile phone network to obtain the device determination result, and transmits the device determination result together with the URL address including the encrypted code to the verification device, and then the verification device performs the following: Step: (i) if the user device is a mobile device that uses the mobile phone network to access the Internet, directly transmits the URL address containing the encrypted code to the mobile device through the mobile phone network to perform the identity authentication; or (ii) if the user device is not A mobile device that uses a mobile phone network to access a network requires the user to use a mobile device that is connected to the mobile phone network and transmit the encrypted web page address containing the encrypted code to the mobile device for the identity authentication by a specific delivery method.
在另一实施例, 所述特定的传递方式包括条形码、 微波和声波, 具体例子包括快速响应矩阵码、 近场通讯 (NFC)、 蓝牙、 红外线、 无 线保真 (Wi-Fi)和射频识别 (RFID)。 在另一实施例, 移动设备、 验证装置和身份认证系统服务器都包 括认证中止模块, 以根据需要和不同情况强制中止身份认证。 其中一 种特定情况为发现受到钓鱼网或中间人的欺骗, 身份认证系统服务 器会通知验证装置停止对用户的服务 In another embodiment, the specific delivery modes include barcodes, microwaves, and sound waves, and specific examples include fast response matrix codes, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency identification ( RFID). In another embodiment, the mobile device, the authentication device, and the identity authentication system server each include an authentication abort module to force the suspension of identity authentication as needed and in different situations. One of the specific cases is that the discovery is spoofed by the phishing network or the intermediary, and the identity authentication system server notifies the verification device to stop the service to the user.
进一方面, 本发明提供了一种移动支付的方法, 包括:(a)使用用 户装置连接到验证装置; (b) 通过验证装置发送认证请求到身份认证 系统服务器; (c) 身份认证系统服务器根据认证请求产生 URL 网页 地址和加密编码, 并把加密编码嵌入 URL 网页地址以得到包含加密 编码的 URL 网页地址, 再把包含加密编码的 URL 网页地址传送回 验证装置; (d) 使用包含加密编码的 URL 网页地址进行用户的身份 认证; 和 (e)使用已确立的用户身份进行移动支付。其中加密编码包 括使用条件参数, 所述条件参数包括:(i) 有效时间, 其定义了所述加 密编码的可使用时间; (ii) 有效次数, 其定义了所述加密编码的可使 用次数; 和 (iii) 需要支付的金额, 其定义了所述用户需要支付的金 额。 In a further aspect, the present invention provides a method of mobile payment, comprising: (a) connecting to a verification device using a user device; (b) transmitting an authentication request to the identity authentication system server by the verification device; (c) identity authentication system server Generating a URL webpage address and an encryption code according to the authentication request, embedding the encryption code into the URL webpage address to obtain a URL webpage address including the encryption code, and transmitting the URL webpage address including the encryption code back to the verification apparatus; (d) using the encryption code included URL page address for user authentication; and (e) use established user identity for mobile payment. Wherein the encryption encoding comprises using a condition parameter, the condition parameter comprising: (i) an effective time, which defines a usable time of the encrypted encoding; (ii) an effective number of times, which defines a usable number of times of the encrypted encoding; And (iii) the amount to be paid, which defines the amount the user needs to pay.
在上述移动支付的方法的一个实施例, 其中身份认证系统服务器 在传送包含加密编码的 URL 网页地址到验证装置前, 根据认证请求 中包含的用户装置的互联网协议地址 (Internet Protocol Address)确定 用户装置是否为使用移动电话网络上网的移动设备以得到装置确定 结果, 并把装置确定结果和包含加密编码的 URL 网页地址一起传送 回验证装置, 然后验证装置执行以下步骤:1. 若用户装置是使用移动 电话网络上网的移动设备,则直接通过移动电话网络传送包含加密编 码的 URL 网页地址到移动设备; 或 II. 若用户装置不是使用移动电 话网络上网的移动设备,则要求用户使用以移动电话网络上网的移动 设备并通过特定的传递方式传送包含加密编码的 URL 网页地址到移 动设备。 在另一实施例, 其中使用包含加密编码的 URL 网页地址进行用 户的身份认证的步骤包括: (i) 所述验证装置传送包含加密编码的 URL 网页地址到所述移动设备; (ii) 移动设备接收包含加密编码的 URL 网页地址, 所述包含加密编码的 URL 网页地址把用户装置导 向身份认证系统服务器; 和 (iii) 身份认证系统服务器根据所述移动 设备的特征确认所述用户的身份。 In an embodiment of the method for mobile payment, wherein the identity authentication system server determines the user device according to an Internet Protocol Address of the user device included in the authentication request before transmitting the URL page address including the encrypted code to the verification device. Whether the mobile device using the mobile phone network to obtain the device determination result, and transmitting the device determination result together with the URL address including the encrypted code to the verification device, and then the verification device performs the following steps: 1. If the user device is using the mobile device A mobile device that accesses the Internet via a mobile phone transmits a URL address containing an encrypted code directly to the mobile device through the mobile phone network; or II. If the user device is not a mobile device that uses the mobile phone network to access the Internet, the user is required to use the mobile phone network to access the Internet. The mobile device transmits the URL address containing the encrypted code to the mobile device through a specific delivery method. In another embodiment, the step of authenticating the user using the URL web page address including the encryption code comprises: (i) the verification device transmitting the URL web page address including the encrypted code to the mobile device; (ii) the mobile device Receiving a URL web page address including an encrypted code, the URL containing the encrypted code web page address directing the user device to the identity authentication system server; and (iii) the identity authentication system server confirming the identity of the user based on the characteristics of the mobile device.
在另一实施例, 其中所述特定的传递方式包括条形码、 微波和声 波, 具体例子包括快速响应矩阵码、 近场通讯 (NFC)、 蓝牙、 红外线、 无线保真 (Wi-Fi)和射频识别 (RFID)。 In another embodiment, the specific delivery manner includes a barcode, a microwave, and an acoustic wave, and specific examples include a fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency identification. (RFID).
在另一实施例, 其中移动设备的特征为该移动设备的电话号码 (MSISDN) , 而身份认证系统服务器取得移动设备的电话号码 (MSISDN)的方法为: I. 获得用户装置的互联网协议地址 (Internet Protocol Address)及通讯端口(Port)并从相应的电信服务商取得对应于 所述互联网协议地址 (Internet Protocol Address)及所述通讯埠 (Port)的 电话号码 (MSISDN)及电信服务商标识符 (IMSI);或 II. 读取移动设备 中的用户身份模块 (Sim Card)的数据并基于所述数据确定电信服务商 标识符 (IMSI)及移动设备的电话号码(MSISDN) ; 或 III. 从 (HTTP Header)认证请求的标头获得电信服务商标识符 (IMSI)及移动设备的 电话号码 (MSISDN:)。 In another embodiment, wherein the mobile device is characterized by the mobile device's telephone number (MSISDN), and the identity authentication system server obtains the mobile device's telephone number (MSISDN) by: I. obtaining the user device's internet protocol address ( Internet Protocol Address and a port and obtain a telephone number (MSISDN) and a telecommunication service provider identifier corresponding to the Internet Protocol Address and the port from a corresponding telecommunication service provider (IMSI); or II. reading data of a subscriber identity module (Sim Card) in the mobile device and determining a Telecommunications Service Provider Identifier (IMSI) and a mobile device's telephone number (MSISDN) based on the data; or III. The header of the (HTTP Header) authentication request obtains the Telecommunications Service Provider Identifier (IMSI) and the mobile device's telephone number (MSISDN:).
在另一实施例, 其中使用已确立的用户身份进行移动支付的步骤 包括:1. 确定所述加密编码是否有效; II. 确定所述用户的帐户金额是 否足够; 和 ΠΙ. 根据确定步骤 I和 II的结果完成交易或取消交易。 In another embodiment, the step of performing mobile payment using the established user identity comprises: 1. determining whether the encryption code is valid; II. determining whether the account amount of the user is sufficient; and ΠΙ. according to determining step I and The result of II completes the transaction or cancels the transaction.
另一方面,本发明提供了一种预设快速移动支付的方法,包括:(a) 预先产生 URL 网页地址和加密编码, 并把加密编码嵌入 URL 网页 地址以得到包含加密编码的 URL 网页地址; (b)使用移动设备读取 包含加密编码的 URL 网页地址, 所述包含加密编码的 URL 网页地 址把移动设备导向身份认证系统服务器; (c) 身份认证系统服务器根 据移动设备的特征确认用户的身份; 和 (d) 使用已确立的用户身份 进行所述移动支付。 其中加密编码包括使用条件参数, 所述条件参数 包括: (i) 值为 1 的有效次数, 其定义了所述加密编码的只可使用一 次; (ii) 有效时间, 其定义了所述加密编码的可使用时间; (iii) 需要 支付的金额, 其定义了所述用户需要支付的金额。 In another aspect, the present invention provides a method for presetting a fast mobile payment, comprising: (a) pre-generating a URL webpage address and an encryption code, and embedding the encryption code into a URL webpage address to obtain a URL webpage address including an encryption code; (b) using a mobile device to read a URL web address containing an encrypted code, the URL containing the encrypted code, the web page address directing the mobile device to the identity authentication system server; (c) the identity authentication system server root The identity of the user is confirmed based on the characteristics of the mobile device; and (d) the mobile payment is made using the established user identity. Wherein the encryption coding comprises using a condition parameter, the condition parameter comprising: (i) a valid number of values of 1, which defines that the encryption code can be used only once; (ii) an effective time, which defines the encryption code The usable time; (iii) the amount to be paid, which defines the amount the user needs to pay.
在一实施例, 其中移动设备的特征为该移动设备的电话号码 (MSISDN) , 而身份认证系统服务器取得用户装置的电话号码 (MSISDN)的方法为: (i) 获得所述移动设备的互联网协议地址 (Internet Protocol Address)及通讯端口(Port)并从相应的电信服务商取 得对应于所述互联网协议地址 (Internet Protocol Address)及所述通讯 埠 (Port)的电话号码 (MSISDN)和电信服务商标识符 (IMSI); 或 (ii)读 取所述移动设备中的用户身份模块 (Sim Card)的数据并基于所述数据 确定电信服务商标识符(IMSI)及所述移动设备的电话号码 (MSISDN); 或 (iii) 从所述 (HTTP Header)认证请求的标头获得电信 服务商标识符 (IMSI)及所述移动设备的电话号码 (MSISDN)。 In an embodiment, wherein the mobile device is characterized by the mobile device's telephone number (MSISDN), and the identity authentication system server obtains the user device's telephone number (MSISDN) by: (i) obtaining the mobile device's internet protocol An Internet Protocol Address and a port (Port) and a corresponding telephone number (MSISDN) and a telecommunications service provider corresponding to the Internet Protocol Address and the port from the corresponding telecommunications service provider An identifier (IMSI); or (ii) reading data of a subscriber identity module (Sim Card) in the mobile device and determining a telecommunications service provider identifier (IMSI) and a telephone number of the mobile device based on the data ( MSISDN); or (iii) Obtaining a Telecommunications Service Provider Identifier (IMSI) and a telephone number (MSISDN) of the mobile device from the header of the (HTTP Header) authentication request.
在另一实施例, 其中使用已确立的用户身份进行移动支付的步骤 包括:1. 确定所述加密编码是否有效; II. 确定所述用户的帐户金额是 否足够; 和 ΠΙ. 根据确定步骤 I和 II的结果完成交易或取消交易。 In another embodiment, the step of performing mobile payment using the established user identity comprises: 1. determining whether the encryption code is valid; II. determining whether the account amount of the user is sufficient; and ΠΙ. according to determining step I and The result of II completes the transaction or cancels the transaction.
另一方面, 本发明提供了一种汇款的方法, 包括:(a)用户甲使用 移动设备连接到身份认证系统服务器; (b) 身份认证系统服务器确认 用户甲的身份和用户甲所属的电讯服务商; (c) 用户甲输入用户乙所 属的电讯服务商和电话号码以及汇款金额; (d) 身份认证系统服务器 根据用户乙所属的电讯服务商和电话号码确认用户乙的身份; 和 (e) 直接从用户甲的电讯帐户扣除所述汇款金额并汇入所述汇款金额到 用户乙的电讯帐户。 In another aspect, the present invention provides a method for remittance, comprising: (a) user A using a mobile device to connect to an identity authentication system server; (b) an identity authentication system server confirming the identity of user A and the telecommunications service to which user A belongs (c) User A enters the telecommunications service provider and telephone number to which User B belongs and the amount of the remittance; (d) The identity authentication system server confirms the identity of User B based on the telecommunications service provider and telephone number to which User B belongs; and (e) The remittance amount is directly deducted from the user's telecommunications account and the remittance amount is remitted to the user B's telecommunications account.
进一方面, 本发明提供了另一汇款的方法, 包括:(a)用户乙使用 移动设备连接到身份认证系统服务器; (b) 所述身份认证系统服务器 确认所述用户乙的身份和所述用户乙所属的电讯服务商; (C) 所述用 户乙输入用户甲的电话号码和所属电讯服务商以及要求转移的金额;In a further aspect, the present invention provides another method of remittance, comprising: (a) user B connects to an identity authentication system server using a mobile device; (b) said identity authentication system server Confirming the identity of the user B and the telecommunications service provider to which the user B belongs; (C) the user B inputs the telephone number of the user A and the associated telecommunications service provider and the amount requested to be transferred;
(d) 所述身份认证系统服务器根据所述用户甲的电话号码和所属电 讯服务商确认所述用户甲的身份; (e) 所述身份认证系统服务器发送 信息到所述用户甲的移动设备, 以要求其汇款, 所述信息包括所述用 户乙的数据; 和 (f) 所述用户甲决定进行汇款或取消汇款程序。 (d) the identity authentication system server confirms the identity of the user A according to the phone number of the user A and the associated telecommunications service provider; (e) the identity authentication system server sends information to the mobile device of the user A, To request remittance, the information includes the data of the user B; and (f) the user A decides to conduct the remittance or cancel the remittance procedure.
在一实施例, 其中用户甲所属的电讯服务商和用户乙所属的电讯 服务商是同一电讯服务商。 In an embodiment, the telecommunications service provider to which the user A belongs and the telecommunications service provider to which the user B belongs are the same telecommunications service provider.
在另一实施例, 其中用户甲所属的电讯服务商和用户乙所属的电 讯服务商是不同的电讯服务商。 In another embodiment, the telecommunications service provider to which the subscriber A belongs and the telecommunications service provider to which the subscriber B belongs are different telecommunications service providers.
另一方面, 本发明提供了一种身份认证系统, 包括:(a) 身份认证 系统服务器,其加载有身份认证系统及存储有可供查询身份认证的数 据记录和户口密码; (b) 移动设备包括通讯装置; (c) 身份认证要求 提供者,所述身份认证要求提供者连接到所述身份认证系统并输入所 述身份认证要求提供者的身份识别码、 密码、 所述移动设备的 IP(Intemet Protocol)位置资料; 其中所述身份认证系统利用所述身份 认证要求提供者的身份识别码和密码确立所述身份认证要求提供者, 然后利用所述移动设备的 IP位置资料从电信运营商的移动用户移动 资料服务器获取所述移动设备的电话号码并产生加密编码,再传送所 述移动设备的电话号码和所述加密编码到所述身份认证要求提供者 以进行身份认证。 In another aspect, the present invention provides an identity authentication system, comprising: (a) an identity authentication system server loaded with an identity authentication system and storing data records and account passwords for querying identity authentication; (b) mobile devices Including a communication device; (c) an identity authentication request provider, the identity authentication request provider is connected to the identity authentication system and inputs an identity code, a password, and an IP of the mobile device of the identity authentication request provider ( Intemet Protocol), wherein the identity authentication system establishes the identity authentication request provider by using an identity identification code and a password of the identity authentication request provider, and then uses the IP location information of the mobile device from a telecommunication carrier The mobile user mobile data server obtains the mobile device's phone number and generates an encrypted code, and then transmits the mobile device's phone number and the encrypted code to the identity authentication request provider for identity authentication.
在一实施例, 其中移动设备包括通讯装置以接收来自身份认证要 求提供者的加密编码,所述通讯装置包括 NFC近场通讯、蓝牙、 WIFI、 红外线、 条形码、 超声波和 RFID。 In an embodiment, wherein the mobile device includes a communication device to receive an encryption code from an identity authentication request provider, the communication device includes NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasound, and RFID.
在另一实施例, 其中身份认证系统包括认证判断单元、 认证状态 单元和密码管理单元, 认证判断单元用于判断用户登录次数、用户是 否重复认证、 电话号码是否吻合; 认证状态单元用于确定及更改用户 认证状态; 用户电话号码判断单元, 以确认身份认证系统从电信运营 商获得的电话号码与认证要求提供者提供的电话号码是否吻合,并反 馈信息给身份认证系统。 In another embodiment, the identity authentication system includes an authentication determining unit, an authentication status unit, and a password management unit, and the authentication determining unit is configured to determine whether the user logs in, whether the user repeats the authentication, and whether the phone number is consistent; the authentication status unit is used to determine Change user The authentication status; the user telephone number judging unit confirms whether the telephone number obtained by the identity authentication system from the telecommunications carrier matches the telephone number provided by the authentication request provider, and feeds back the information to the identity authentication system.
进一方面, 本发明提供了一种基于二维码和电信服务商的移动支 付方法, 包括: (a) 将从移动支付系统得到的二维码信息显示给付款 人, 所述二维码信息包括加密编码以及所述移动支付系统的 URL位 置; (b)使用移动设备读取所述二维码信息, 所述移动设备利用所述 二维码信息中的所述移动支付系统的 URL位置连接到所述移动支付 系统; (c)所述移动支付系统运用所述移动设备的 IP地址确定用户所 使用的电信服务商,再从所述电信服务商获取所述用户的数据以确认 所述用户的身份; (d)使用已确认的所述用户的身份完成所述移动支 付。 In a further aspect, the present invention provides a mobile payment method based on a two-dimensional code and a telecommunication service provider, comprising: (a) displaying two-dimensional code information obtained from a mobile payment system to a payer, the two-dimensional code information Including an encryption code and a URL location of the mobile payment system; (b) reading the two-dimensional code information using a mobile device, the mobile device utilizing a URL location connection of the mobile payment system in the two-dimensional code information Go to the mobile payment system; (c) the mobile payment system determines the telecommunication service provider used by the user by using the IP address of the mobile device, and then acquires the data of the user from the telecommunication service provider to confirm the user (d) completing the mobile payment using the confirmed identity of the user.
在一实施例, 其中用户资料包括用户的电话号码、 用户类型和可 用支付额度。 In an embodiment, wherein the user profile includes the user's phone number, user type, and available payment amount.
在另一实施例, 其中使用已确认的用户的身份完成移动支付的步 骤包括: 查看所述用户的账户存款情况, 并执行以下步骤:(i) 若存款 不足,结束所述移动支付并向所述用户显示需要存入的现金及重试的 信息; 或 (ii) 若存款足够, 所述移动支付系统通知所述电信服务商 在所述用户的电话账户扣除付款金额, 以完成所述移动支付。 In another embodiment, the step of completing the mobile payment using the identity of the confirmed user comprises: viewing the account deposit status of the user, and performing the following steps: (i) if the deposit is insufficient, ending the mobile payment and The user displays the cash and retry information that needs to be deposited; or (ii) if the deposit is sufficient, the mobile payment system notifies the telecommunication service provider to deduct the payment amount from the user's telephone account to complete the mobile payment .
本发明具有很多优点。 首先, 用户可直接使用其移动电话进行快 速认证或购物, 方便省时且高效率。 其次, 用户身份的确立由第三方 (电讯服务商)保证, 安全性得到提高。 另外, 用户可额外设定登入密 码和电邮通知, 增加了使用的弹性并进一步加强了安全性, 即使移动 设备遗失了也不用担心账户被取用, 还会自动发电邮给用户, 以提醒 有人正在使用认证 /支付服务, 以防止被他人盗用。 用户还可以根据 自身需要, 自定义不同的有效次数、 有效时间和有效金额, 以满足不 同情况的不同需要。 再者, 本发明的灵活性高, 只要根据不同的使用方法相应地对其 中的步骤作出微调, 即可应用到不同的范畴。 The invention has many advantages. First, users can use their mobile phones for quick authentication or shopping, saving time and efficiency. Secondly, the establishment of the user identity is guaranteed by a third party (telecom service provider) and the security is improved. In addition, users can additionally set login passwords and email notifications, which increases the flexibility of use and further enhances security. Even if the mobile device is lost, there is no need to worry about the account being taken, and the user will be automatically emailed to remind people that they are Use authentication/payment services to prevent misappropriation by others. Users can also customize different effective times, effective time and effective amount according to their needs to meet the different needs of different situations. Furthermore, the flexibility of the present invention is high, and it can be applied to different categories as long as the steps are finely adjusted according to different usage methods.
还有, 使用本发明的支付或认证程序后, 系统会展示移动广告给 用户,广告可以为用户提供购物优惠等信息, 有别于其它的广告渠道, 该方法具有确确切切, 无虛假真人浏览, 同时可为用户带来更方便的 优惠收集和使用。 Moreover, after using the payment or authentication program of the present invention, the system will display mobile advertisements to the user, and the advertisements can provide the user with information such as shopping discounts, which is different from other advertisement channels, and the method has exact cuts, and no false real people browse. At the same time, it can bring more convenient preferential collection and use to users.
使用包含加密编码的 URL网页地址的方法的好处是: a)无须安装 特定软件, 只要任何特定装置读取软件, 即能接收该 URL从而打开 网页运行; b)无须改变用户习惯,用户习惯使用 NFC或二维码扫瞄 软件, 读取后打开网页浏览信息 (不同的地方是, 不是浏览信息, 打开 网页就可以认证或支付, 可以令用户更易上手); c)可以使用网页进行 认证和支付, 增加跨平台的能力和减少开发及维护成本; d)适合不同 人需要, 希望更方便的, 可以下载特定软件运行。 The advantages of using a method that includes an encrypted encoded URL page address are: a) no need to install specific software, as long as any particular device reads the software, it can receive the URL to open the web page; b) users do not need to change user habits, users are accustomed to using NFC Or QR code scanning software, open the web browsing information after reading (the different place is, not browsing information, open the web page can be authenticated or paid, can make the user more easy to use); c) can use the web page for authentication and payment, Increase cross-platform capabilities and reduce development and maintenance costs; d) For different people's needs, and hope to be more convenient, you can download specific software to run.
附图说明 DRAWINGS
参照本说明书的佘下部分和附图可以对本发明的性能和优点作 进一步的理解。 The performance and advantages of the present invention will be further understood by reference to the appended claims and appended claims.
图 1是本发明基于电信运营商的身份认证系统的实施例的系统关 系图。 BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a system diagram of an embodiment of an identity authentication system based on a telecommunications carrier of the present invention.
图 2是本发明基于电信运营商的身份认证系统的流程图。 2 is a flow chart of an identity authentication system based on a telecommunications carrier of the present invention.
图 3是本发明基于二维码和电信服务商的移动支付系统的实施例 的系统关系图。 3 is a system diagram of an embodiment of a mobile payment system based on a two-dimensional code and a telecommunications service provider of the present invention.
图 4是本发明基于二维码和电信服务商的移动支付系统的实施例 的流程图。 4 is a flow chart of an embodiment of a mobile payment system based on a two-dimensional code and a telecommunications service provider of the present invention.
图 5是本发明一个实施例中移动身份认证系统的框图。 Figure 5 is a block diagram of a mobile identity authentication system in accordance with one embodiment of the present invention.
图 6是本发明一个实施例中移动身份认证的简单流程图。 6 is a simplified flow chart of mobile identity authentication in one embodiment of the present invention.
图 7是本发明一个实施例中利用身份认证系统进行移动支付的流 程图。 图 8是本发明一个实施例中利用身份认证系统进行默认快速移动 支付的流程图。 7 is a flow chart of mobile payment using an identity authentication system in one embodiment of the present invention. Figure 8 is a flow diagram of default fast mobile payment using an identity authentication system in accordance with one embodiment of the present invention.
图 9是本发明一个实施例中利用身份认证系统进行用户之间互相 汇款的系统框图。 Figure 9 is a block diagram of a system for reciprocating funds between users using an identity authentication system in accordance with one embodiment of the present invention.
具体实施方式 基于电信运营商(电信服各商)的身份认证系统的实施例一 DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Embodiment 1 of an identity authentication system based on a telecommunications carrier (telecom service provider)
下面将结合本实施例中的附图, 对本实施例中的技术方案进行清 楚、完整地描述, 当然,所描述的实施例仅仅是本发明一部分实施例, 而不是全部的实施例,基于本发明中权利要求, 除了实施例外的但属 于权利要求范围内的, 也均属于本发明保护的范围。 The technical solutions in this embodiment will be clearly and completely described in the following with reference to the accompanying drawings in the embodiments. Of course, the described embodiments are only a part of the embodiments of the present invention, but not all embodiments, based on the present invention. It is intended that the appended claims be interpreted as falling within the scope of the appended claims
图 1 是本实施例的系统关系图, 其中包括身份认证要求提供者 120、 移动设备内可接收的各种通讯装置 121、 用户移动设备 122、 电 信运营商的无线网络 123、 电信运营商的内部网络 124、 电信运营商 的移动用户移动资料服务器 125、 电信服务商的移动用户付款处理服 务器 126、 网际网络(互联网 ) 127和身份认证系统服务器 128。 1 is a system diagram of the present embodiment, including an identity authentication request provider 120, various communication devices 121 receivable in a mobile device, a user mobile device 122, a wireless network 123 of a telecommunications carrier, and an internal carrier. The network 124, the mobile subscriber mobile data server 125 of the telecommunications carrier, the mobile subscriber payment processing server 126 of the telecommunications service provider, the internetwork (Internet) 127 and the identity authentication system server 128.
如图 1所示, 一种基于电信运营商 (电信服务商)的身份认证系统, 其特征在于, 它包括: As shown in FIG. 1, an identity authentication system based on a telecommunication operator (telecom service provider) is characterized in that it includes:
身份认证要求提供者 120, 即要求确认用户身份的商户, 所述身 份认证要求提供者 120会先输入商户身份识别码、 密码及用户端 (即 面对用户的服务端, 例如: 网页、 电子闸门等等)的 IP位置等等资料 后,会从身份认证系统得到的认证处理加密编码及或身份认证要求提 供者的用户端的移动终端的电话号码 (当身份认证要求提供者的用户 端的 IP位置确认是移动终端时),若商户发现从身份认证得来的电话 号码不对, 可通过身份认证要求提供者 120的用户端的通讯设备, 将 认证处理加密编码传到用户的移动设备 122; 用户移动设备 122, 即用户的移动设备 /移动终端, 用户运用预装 在移动设备 122内的应用程序或打开本系统的网页, 启动移动设备的 通讯装置 121接收身份处理加密编码; The identity authentication request provider 120, that is, the merchant that requires confirmation of the identity of the user, the identity authentication request provider 120 first inputs the merchant identification code, the password, and the client (ie, the server facing the user, for example: webpage, electronic gate) After waiting for the IP location and other information, the authentication process is obtained from the identity authentication system. The encryption code and/or the identity authentication request provider's mobile terminal's phone number (when the identity authentication request provider's client's IP address is confirmed) In the case of the mobile terminal, if the merchant finds that the telephone number obtained from the identity authentication is incorrect, the authentication processing encryption code can be transmitted to the user's mobile device 122 through the communication device of the user terminal of the identity authentication request provider 120; The user mobile device 122, that is, the user's mobile device/mobile terminal, the user uses an application program preinstalled in the mobile device 122 or opens a webpage of the system, and the communication device 121 that activates the mobile device receives the identity processing encryption code;
电信运营商的无线网络 123和内部网络 124, 电信运营商可直接 或间接地提供用户的数据; The telecommunications carrier's wireless network 123 and the internal network 124, the telecommunications carrier can provide the user's data directly or indirectly;
身份认证系统, 所述身份认证系统得到身份认证处理加密编码 , 查询编码有效情况, 以及运用电信营运商提供的用户数据后, 身份认 证系统会对照电信运营商所提供的电话号码是否和要求认证提供者 的吻合,或提供用户电话号码给身份认证要求提供者 120,由身份认证 要求提供者 120自行决定; 和 The identity authentication system, the identity authentication system is authenticated and processed by the encryption code, the query code is valid, and after the user data provided by the telecommunication operator is used, the identity authentication system provides the phone number provided by the telecommunication operator and the required authentication. Matching, or providing the user's phone number to the identity authentication request provider 120, is determined by the identity authentication request provider 120; and
身份认证系统服务器 128, 其加载有身份认证系统及存储可供更 新、 修改、 访问的身份认证数据。 The authentication system server 128, which is loaded with an authentication system and stores identity authentication data that can be updated, modified, and accessed.
上述运用电信运营商的身份认证系统, 其特征还在于, 所述运用 电信运营商可直接地从 http header或间接地运用用户浏览时的 IP位 置向电信运营商服务器获取用户资料, 如:电话号码及全球定位的位 置等等 身份认证系统包括认证判断单元、认证状态单元、密码管理单元, 其中, 认证判断单元判断用户登录次数、 用户是否重复认证、 电话号 码是否吻合; 认证状态单元确定及更改用户认证状态; 用户电话号码 判断单元,用户确认所述身份认证系统从电信运营商获得电话号码与 认证要求提供者的电话号码是否吻合后,用户电话号码判断单元即判 定用户电话号码无误并反馈给所述身份认证系统。 The above-mentioned identity authentication system using the telecommunication operator is further characterized in that the application telecommunication operator can directly obtain user data, such as a phone number, from the http header or indirectly using the IP location of the user to browse to the telecommunication carrier server. And the location of the globally located identity authentication system includes an authentication determination unit, an authentication status unit, and a password management unit, wherein the authentication determination unit determines the number of user logins, whether the user repeats the authentication, and whether the telephone number is consistent; the authentication status unit determines and changes the user. Authentication status; user telephone number judging unit, after the user confirms that the identity authentication system obtains the telephone number from the telecommunications carrier and the telephone number of the authentication request provider is matched, the user telephone number judging unit determines that the user's telephone number is correct and feeds back to the The identity authentication system.
其中,所述身份认证要求提供者的用户端的通讯装置 121为 NFC 近场通讯, 蓝牙, WIFI, 红外线, 条形码, 超声波和 RFID通讯装置 中的一种, 也可以釆用其他移动终端通讯装置 121。 The communication device 121 of the user terminal of the identity authentication request provider is one of NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasonic and RFID communication devices, and other mobile terminal communication devices 121 may also be used.
如图 2所示, 本发明认证系统流程如下: As shown in FIG. 2, the authentication system of the present invention is as follows:
步骤 130: 认证程序开始。 步骤 131: 身份认证要求提供者 120将其身份编码、 密码和用户 端 (即面对用户的服务端, 例如: 网页、 电子闸门等等)的 IP位置等资 料, 传送到本身份认证系统。 Step 130: The authentication process begins. Step 131: The identity authentication request provider 120 transmits its identity code, password, and IP address of the client (ie, the server facing the user, for example, a web page, an electronic gate, etc.) to the identity authentication system.
步骤 132: 身份认证要求提供者 120会从本身份认证系统得到处 理加密编码及身份认证要求提供者 120 的用户端的移动终端的电话 号码 (当身份认证要求提供者的 120用户端的 IP位置确认是移动终端 步骤 133: 身份认证要求提供者 120 比较从本身份认证系统得到 的身份认证要求提供者 120 的用户端的移动电话号码是否和要求的 一样。 Step 132: The identity authentication request provider 120 obtains the mobile phone number of the mobile terminal that processes the encryption code and the identity authentication request provider 120 from the identity authentication system (when the IP address confirmation of the 120 client of the identity authentication request provider is mobile) Terminal Step 133: The Identity Authentication Request Provider 120 compares whether the mobile phone number of the client of the identity authentication request provider 120 obtained from the identity authentication system is the same as that required.
步骤 134: 若吻合, 用户身份获得通过。 Step 134: If it matches, the user identity is passed.
步骤 135: 若不相符, 身份认证要求提供者 120会开启适合的传 递装置, 等待用户接收身份认证处理加密编码, 例如: 显示二维码, 让用户用摄录扫瞄的方式将讯息传入移动终端。 Step 135: If there is no match, the identity authentication request provider 120 will enable the appropriate delivery device to wait for the user to receive the identity authentication process encryption code, for example: display the two-dimensional code, and let the user use the video scan to transmit the message to the mobile device. terminal.
步骤 136: 用户打开应用程序或移动认证网站。 Step 136: The user opens the application or the mobile authentication website.
步骤 137: 从电信运营商获得用户电话资料,例如: 电话号码。 步骤 138: 根据得来电话号码确立本身份认证系统用户身份。 Step 137: Obtain user telephone information from the telecommunications carrier, for example: telephone number. Step 138: Establish the identity of the identity authentication system user based on the obtained phone number.
步骤 139: 用户打开移动设备 122中适合的通讯装置 121 的接收 功能, 例如: 摄像功能。 Step 139: The user turns on the receiving function of the suitable communication device 121 in the mobile device 122, for example: the camera function.
步骤 140: 获取身份认证处理加密编码。 Step 140: Obtain an identity authentication process encryption code.
步骤 141及 142: 移动身份认证系统确认是否有认证的要求, 判 断是否属于重复认证, 防止重复认证同一个要求, 如果是, 则显示已 完成认证信息, 如果不是进入下一步骤继续认证。 Steps 141 and 142: The mobile identity authentication system confirms whether there is a request for authentication, determines whether it is a duplicate authentication, and prevents duplicate authentication from the same request. If yes, it displays that the authentication information has been completed, and if not, proceeds to the next step to continue the authentication.
步骤 143: 系统会将用户手机号码传到商户系统, 让商户自我进 行比较, 以增加运作灵活性。 Step 143: The system will transfer the user's mobile phone number to the merchant system, allowing the merchants to compare themselves to increase operational flexibility.
本实施例提供一种基于电信运营商的身份认证系统, 皆在解决户 口缺乏有力保护和登入繁瑣的问题, 另外不需要用户安装任何软件, 注册或使用身份编码器就能够使用, 简简单单就提升了户口的安全 性, 方便实用。 This embodiment provides an identity authentication system based on a telecom operator, which solves the problem of lack of strong protection and login cumbersome in the account, and does not require the user to install any software. Registration or use of an identity encoder can be used, which simply improves the security of the account, and is convenient and practical.
本技术方案如下所述: 一种基于电信运营商的身份认证系统, 其 特征在于, 它包括: The technical solution is as follows: An identity authentication system based on a telecommunication carrier, characterized in that it comprises:
身份认证要求提供者 120, 即要求确认用户身份的商户, 所述的 身份认证要求提供者会先输入商户身份识别码、 密码及用户端的 IP 位置资料, 从身份认证系统获取认证处理加密编码, 当身份认证要求 提供者 120的用户端的 IP位置确认是移动终端时, 会获取身份认证 要求提供者 120 的用户端的移动终端的电话号码,若身份认证要求提 供者 120发现从身份认证系统得来的电话号码不对,可通过身份认证 要求提供者 120的用户端的通讯装置 121, 将认证处理加密编码传到 用户的移动设备 122, 其中, 所述用户端为面对用户的服务端; The identity authentication request provider 120, that is, the merchant that requires confirmation of the identity of the user, the identity authentication request provider first inputs the merchant identification code, the password, and the IP location data of the client, and obtains the authentication processing encryption code from the identity authentication system. When the IP address confirmation of the client of the identity authentication request provider 120 is the mobile terminal, the phone number of the mobile terminal of the client of the identity authentication request provider 120 is obtained, and if the identity authentication request provider 120 finds the phone number obtained from the identity authentication system. If the number is incorrect, the authentication device may be transmitted to the mobile device 122 of the user through the communication device 121 of the client of the identity authentication request provider 120, where the user terminal is a server facing the user;
用户移动设备 122, 即用户的移动设备 /移动终端, 用户运用预装 在移动设备 122内的应用程序或打开本系统的网页, 启动移动设备的 通讯装置 121接收身份处理加处编码; The user mobile device 122, that is, the user's mobile device/mobile terminal, the user uses the application program preinstalled in the mobile device 122 or opens the webpage of the system, and the communication device 121 that activates the mobile device receives the identity processing plus code;
电信运营商的无线网络 123和内部网络 124, 电信运营商可直接 或间接地提供用户的数据; The telecommunications carrier's wireless network 123 and the internal network 124, the telecommunications carrier can provide the user's data directly or indirectly;
身份认证系统, 所述身份认证系统得到身份认证处理加密编码 , 查询编码有效情况, 以及运用电信营运商提供的用户数据后, 身份认 证系统会对照电信运营商所提供的电话号码是否和身份认证要求认 证提供者 120所提供的吻合,或提供用户电话号码给身份认证要求提 供者 120,由身份认证要求提供者 120自行决定; 和 The identity authentication system, the identity authentication system obtains the identity authentication processing encryption code, the query coding effective condition, and after using the user data provided by the telecommunication operator, the identity authentication system compares with the telephone number provided by the telecommunication operator and the identity authentication requirement The match provided by the authentication provider 120, or providing the user's phone number to the identity authentication request provider 120, is determined by the identity authentication request provider 120;
身份认证系统服务器 128, 其加载有身份认证系统及存储可供查 询身份认证数据记录及户口密码。 The identity authentication system server 128, which is loaded with an identity authentication system and stored, is available for querying identity authentication data records and account passwords.
进一步地, 运用电信运营商可直接地从 http header或间接地运用 用户浏览时的 IP位置向电信运营商服务器获取用户资料。 进一步地, 所述向电信运营商服务器获取的用户资料为电话号码 及全球定位的位置。 Further, the telecom operator can directly obtain the user profile from the http header or indirectly using the IP location when the user browses to the telecommunication carrier server. Further, the user data obtained by the telecom carrier server is a phone number and a globally located location.
进一步地,所述身份认证系统包括认证判断单元、认证状态单元、 信息存储单元, 其中, 认证判断用户是否重复认证、 电话号码是否吻 合; 认证状态单元确定及更改用户认证状态; 信息存储单元对系统内 信息存储管理。 Further, the identity authentication system includes an authentication determination unit, an authentication status unit, and an information storage unit, wherein the authentication determines whether the user repeats the authentication, whether the phone number is consistent; the authentication status unit determines and changes the user authentication status; and the information storage unit to the system Internal information storage management.
进一步地, 所述认证判断单元包括: 用户电话号码判断单元, 用 户确认所述身份认证系统从电信运营商获得电话号码与自己电话号 码是否吻合后,用户电话号码判断单元即判定用户电话号码无误并反 馈给所述身份认证系统。 Further, the authentication judging unit includes: a user telephone number judging unit, after the user confirms that the identity authentication system obtains a phone number from the telecommunication operator and matches the self-phone number, the user phone number judging unit determines that the user phone number is correct and Feedback to the identity authentication system.
进一步地, 所述身份认证要求提供者的用户端的通讯装置 121为 NFC近场通讯, 蓝牙, WIFI, 红外线, 条形码, 超声波和 RFID通讯 装置中的一种。 Further, the communication device 121 of the user terminal of the identity authentication request provider is one of NFC near field communication, Bluetooth, WIFI, infrared, bar code, ultrasonic and RFID communication devices.
本实施例釆用移动终端 (用户移动设备 122)的各种通讯装置 121 接收外界或移动网络内对身份要求认证的信息,再运用移动设备所附 属的电信运营商所提供的移动用户的资料。本系统会进行对比电话号 码,将结果返回给身份认证要求提供者 120, 或提供用户电话号码给身 份认证要求提供者 120,由他们自行做对比。 In this embodiment, the various communication devices 121 of the mobile terminal (the user mobile device 122) receive the information of the identity authentication required in the external or mobile network, and then use the data of the mobile user provided by the telecommunication operator attached to the mobile device. The system will compare the phone numbers, return the results to the identity certification request provider 120, or provide the user's phone number to the identity certification request provider 120 for their own comparison.
根据上述的结构, 本实施例的有益效果在于: 本发明釆用移动电 话号码作为认证准则, 易于申请, 全球独一无二和公开而非私隐性。 再通过由电信运营商提供用户的资料,可达到不需要预先注册或安装 任何软件就能够使用,便能自动识别用户身份,提供方便之佘。 变相与 移动终端捆绑成有第三方保证的身份识别的功能。没有口令牌的人们 都可以实现对账户的第三方保障。 According to the above configuration, the advantageous effects of the present embodiment are as follows: The present invention uses the mobile phone number as the authentication criterion, is easy to apply, is globally unique and public, not private. By providing the user's data by the telecom operator, it is possible to automatically identify the user's identity without having to pre-register or install any software, and provide convenience. Disguised and bundled with mobile terminals into a third-party guaranteed identity. People without a token can implement third-party protection for the account.
具体来说, 使用本身份认证系统, 较其它身份认证系统来说, 其 好处如下: 1、带有免登入名和密码的快速安全登入功能: 商户可以釆用本身 份认证系统取代输入登入名和密码,一来是省却用户登入时所需时间 和程序, 二来减轻用户记载太多登入或身份数据。 Specifically, the advantages of using this identity authentication system over other identity authentication systems are as follows: 1. Fast and secure login function with no login name and password: Merchants can use this identity authentication system instead of entering the login name and password, which saves the time and procedures required for the user to log in. Identity data.
2、 带有第三方保证功能: 很多重要的决定时,例如: 买卖,转账和 付款等等,都可使用本系统以确保功能不被盗用,较传统省时,简易和 不用特制口令牌。 2, with third-party guarantee function: Many important decisions, such as: trading, transfer and payment, etc., can use the system to ensure that the function is not stolen, more traditional time-saving, simple and no special token.
3、 带有身份卷标的功能: 如活动开始前的登记, 釆用本身份认证 系统可作为用户自助登记, 以增加活动营办效率。 3. Function with identity tag: If the registration before the event starts, the identity authentication system can be used as self-registration for users to increase the efficiency of the event.
本实施例釆用移动设备的各种通讯装置 121或移动网络里的接收 身份认证要求的信息,再运用移动设备所附属的电信运营商所提供的 移动用户的资料,如:电话号码等等。 本系统会进行对比电话号码,将结 果返回给认证要求提供者, 或提供用户电话号码给认证要求提供者, 由他们自行做对比, 每次认证都会记录在本系统里面, 方便查阅。 In this embodiment, the various communication devices 121 of the mobile device or the information of the identity authentication request in the mobile network are used, and the data of the mobile user provided by the telecommunication operator attached to the mobile device, such as a telephone number, etc., is used. The system will compare the phone numbers, return the results to the certification request provider, or provide the user's phone number to the certification request provider, and they will make their own comparisons. Each certification will be recorded in the system for easy access.
由于不用携带任何口令牌或安装任何身份软件就能开通本发明 的移动身份服务, 任何人都可以无拘无束地在任何计算机 (包括个人 计算机,手提电脑及流动终端机等等)处理个人数据, 以增加生活的便 利和质素。 By opening the mobile identity service of the present invention without carrying any tokens or installing any identity software, anyone can process personal data on any computer (including personal computers, laptops, mobile terminals, etc.) without any restrictions, to increase The convenience and quality of life.
当一些活动需要点名或登记时, 釆用本身份认证系统, 可以让活 动参与者向主办单位的计算机自助登记或报到,这样可以提升活动的 效率。 When some activities need to be named or registered, the identity authentication system can be used to allow the activity participants to self-register or report to the organizer's computer, which can improve the efficiency of the activity.
当需要确认领取物品的人身份时, 又可釆用本身份认证系统, 对 照领取者的电话号码,增加可靠性。 When it is necessary to confirm the identity of the person who receives the item, the identity authentication system can be used to increase the reliability of the recipient's phone number.
基于二维码和电信 营商 (电信服各商)的移动玄付系统 Based on two-dimensional code and telecommunications, business (telecom service providers) mobile Xuanfu system
图 3是本实施例的系统关系图, 其中包括付款要求提供者 11、 显 示付款要求的二维码信息 12、用户移动设备 122、 电信服务商的无线 网络 123、 电信服务商的内部网络 124、 电信服务商的移动用户 IP地 址资料服务器 16、 电信服务商的移动用户付款处理服务器 126、 网际 网络(互联网 ) 127和付款交易服务器 19。 3 is a system diagram of the present embodiment, including a payment request provider 11, two-dimensional code information 12 showing payment requests, a user mobile device 122, a wireless network 123 of a telecommunications service provider, an internal network 124 of a telecommunications service provider, Mobile subscriber IP address of telecommunications service provider The address data server 16, the mobile subscriber payment processing server 126 of the telecommunications service provider, the internet (Internet) 127, and the payment transaction server 19.
比较图 1和图 3 , 可发现两图中的系统构造基本上是一样的, 不 过图 3中不同的组成部件更形象化, 以使人更易理解。 还有, 因为本 实施例是把身份认证系统应用于基于二维码的移动支付系统, 所以 在图 3中一部份的组成部件相对于图 1中相应的组成部件用了不同的 名称或更适合的命名,例如: 身份认证要求提供者 120在这实例就是 付款要求提供者 11; 移动设备内可接收的各种通讯装置 121特定为二 维码信息 12; 电信运营商的移动用户移动资料服务器 125在此实施例 就是电信服务商的移动用户 IP地址资料服务器 16; 身份认证系统服 务器 128成为付款交易服务器 19。 Comparing Figure 1 with Figure 3, it can be seen that the system construction in the two figures is basically the same, but the different components in Figure 3 are more visualized to make it easier to understand. Also, since the present embodiment applies the identity authentication system to a mobile payment system based on a two-dimensional code, a part of the components in FIG. 3 have different names relative to the corresponding components in FIG. Suitable naming, for example: identity authentication request provider 120 is the payment request provider 11 in this example; various communication devices 121 receivable in the mobile device are specifically two-dimensional code information 12; mobile user mobile data server of the telecommunication operator In this embodiment, the mobile subscriber IP address data server 16 of the telecommunications service provider; the identity authentication system server 128 becomes the payment transaction server 19.
图 4是本实施例的流程图, 具体步骤如下: 4 is a flow chart of this embodiment, and the specific steps are as follows:
步骤 101: 消费者开始利用本移动支付系统付款。 Step 101: The consumer begins to pay with the mobile payment system.
步骤 102: 消费者通过移动设备已下载的应用程序及摄影功能读 取条码内容。 Step 102: The consumer reads the barcode content through the downloaded application and photography function of the mobile device.
步骤 103: 消费者从条形码获取付款的信息。 Step 103: The consumer obtains payment information from the barcode.
步骤 104: 消费者可在下载的应用程序或进入移动支付系统的网 页继续进行付款程序。 Step 104: The consumer can proceed with the payment process in the downloaded application or on the web page entering the mobile payment system.
步骤 105及 106: 移动支付系统确认是否有支付的要求, 防止重 复支付同一交易。 Steps 105 and 106: The mobile payment system confirms whether there is a payment request and prevents the same transaction from being repeated.
步骤 107及 108: 移动支付系统运用移动设备的 IP地址, 与电信 服务商的 IP地址范围记彔核对, 找出适当的电信服务商。 Steps 107 and 108: The mobile payment system uses the IP address of the mobile device to check with the IP address range of the telecommunication service provider to find an appropriate telecommunication service provider.
步骤 109: 如 IP地址正确, 移动支付系统向适当的电信服务商获 取移动账户资料。 Step 109: If the IP address is correct, the mobile payment system obtains the mobile account information from the appropriate telecommunication service provider.
步骤 110及 111: 移动支付系统查看账户的存款情况, 如存款不 足, 支付系统向消费者显示需要存入现金或转账现金以提高支付额 的信息。 步骤 112: 支付系统要求消费者输入已在首次使用支付系统成立 时的个人密码。 Steps 110 and 111: The mobile payment system checks the deposit status of the account. If the deposit is insufficient, the payment system displays to the consumer information that needs to deposit cash or transfer cash to increase the payment amount. Step 112: The payment system asks the consumer to enter a personal password that has been established when the first use payment system is established.
步骤 113及 114: 由消费者确认支付费用。 Steps 113 and 114: The payment is confirmed by the consumer.
步骤 115: 移动支付系统通知电信服务商在用户的移动设备的电 话账户扣除付款金额。 Step 115: The mobile payment system notifies the telecommunications service provider to deduct the payment amount from the telephone account of the user's mobile device.
步骤 116: 移动支付系统将用户的电话账户和支付请求连接, 并 设置付款准备状态到已支付的状态, 防止重复支付并通知商户已成 功支付。 Step 116: The mobile payment system connects the user's telephone account with the payment request, and sets the payment preparation status to the paid status, preventing duplicate payment and notifying the merchant that the payment has been successfully made.
步骤 117: 消费者利用本移动支付系统付款的程序完结。 Step 117: The consumer completes the payment process using the mobile payment system.
如图 3及图 4所示, 一种基于二维码和电信服务商的移动支付系 统, 其特征在于, 它包括; As shown in FIG. 3 and FIG. 4, a mobile payment system based on a two-dimensional code and a telecommunication service provider, characterized in that it includes;
付款要求提供者 11 , 即要求付款以及提供付款金额的商户, 所述 的付款要求提供者会将从移动支付系统得到的二维码信息 12显示给 付款人; The payment request provider 11 , that is, the merchant who requests payment and provides the payment amount, and the payment request provider displays the two-dimensional code information 12 obtained from the mobile payment system to the payer;
用户移动设备 122, 付款人运用预装在移动设备 122内的二维码 读取应用程序, 或使用专为本发明而设的应用程序, 启动移动设备 122的视像扫瞄功能来读取二维码信息 12 内的付款加密编码以及系 统的 URL位置; The user mobile device 122, the payer uses the two-dimensional code reading application pre-installed in the mobile device 122, or uses the application designed for the invention to activate the video scanning function of the mobile device 122 to read the second The payment encryption code in the dimension code information 12 and the URL location of the system;
电信服务商提供的无线网络 123和内部网络服务 124, 每家电信 服务商会预先分派不同的 IP地址给用户的移动设备, IP位置等于用 户的个人身份编码。 移动支付系统运用这个机制, 运用 IP地址便可 向电信服务商获取到用户资料, 如电话号码、 用户类型(月付、 储值 卡或者漫游)、 可用支付额度等; 和 The wireless network provided by the telecommunication service provider 123 and the internal network service 124, each telecommunication service provider pre-assigns different IP addresses to the user's mobile device, and the IP location is equal to the user's personal identity code. The mobile payment system uses this mechanism to obtain user information, such as phone number, user type (monthly payment, stored value card or roaming), available payment amount, etc., using the IP address;
付款人点击 URL进入移动支付系统的网页版本, 又或使用专为 本发明而设的应用程序处理 URL讯息后, 移动支付系统会从 URL得 到付款编码, 查询付款情况, 以及运用浏览时移动终端的 IP位置向相 关的电信服务商获取用户的数据后,在用户移动设备 122的移动电话 账户扣除付款金额。 After the payer clicks on the URL to enter the web version of the mobile payment system, or processes the URL message using the application designed for the invention, the mobile payment system obtains the payment code from the URL, checks the payment status, and uses the mobile terminal when browsing. IP position to phase After the telecommunications service provider obtains the user's data, the payment amount is deducted from the mobile phone account of the user mobile device 122.
本实施例提供了一种基于二维码和电信服务商的移动支付系统, 其旨在解决在线及离线环境付款方式不一致的问题,另外不需要在银 行或者信用卡提供者等预先注册就能够使用,不需要银行以及信用卡 公司的介入, 大大提升了付款支付的安全问题, 同时没有银行和信用 卡帐号等的人都可以实现移动支付效果, 方便实用。 The embodiment provides a mobile payment system based on a two-dimensional code and a telecommunication service provider, which aims to solve the problem of inconsistent payment methods in online and offline environments, and can be used without prior registration by a bank or a credit card provider. There is no need for the intervention of banks and credit card companies, which greatly improves the security of payment payments. At the same time, people without bank and credit card accounts can achieve mobile payment effects, which is convenient and practical.
该技术方案如下所述: The technical solution is as follows:
本实施例釆用二维码将在线以及离线付款信息用图样显示, 再通 过消费者持有的移动设备 122 的摄影功能读取条码 (这里的条码指的 是二维码信息 12)内容, 再运用移动设备 122的 IP地址, 向电信服务 商获取移动账户资料来自动识别消费者的身份; 同时釆用用户移动 电话账户作为支付账户之用, 每次消费都会记录在本系统里面, 方便 查阅。 In this embodiment, the online and offline payment information is displayed in a pattern by using a two-dimensional code, and then the barcode function (the barcode here refers to the two-dimensional code information 12) is read by the photographing function of the mobile device 122 held by the consumer, and then Using the IP address of the mobile device 122, the mobile account information is obtained from the telecommunication service provider to automatically identify the identity of the consumer; and the user mobile phone account is used as the payment account, and each consumption is recorded in the system for convenient access.
根据上述的结构, 其有益效果在于: 釆用移动电话号码账户作为 支付途径, 使用安全方便, 消费者可以放心以及平等地使用移动设备 122作为支付工具, 以及运用相同方式支付离线以及在线的费用。 不 需要预先在银行或者信用卡提供者等注册就能够使用。没有银行以及 信用卡公司等的介入, 大大提升了付款的安全问题, 同时没有银行和 信用卡帐号等的人都可以实现移动支付的梦想。 According to the above structure, the advantageous effects are as follows: Using the mobile phone number account as a payment path, the use is safe and convenient, the consumer can use the mobile device 122 as a payment tool with confidence and equal access, and pay the offline and online expenses in the same manner. It can be used without registering in advance with a bank or credit card provider. Without the intervention of banks and credit card companies, the security of payment is greatly enhanced, and people without bank and credit card accounts can realize the dream of mobile payment.
具体来说, 使用本移动支付系统, 较其他支付系统来说, 其好处 的地方如下: Specifically, the advantages of using this mobile payment system compared to other payment systems are as follows:
1、带有移动收款机的功能: 商户可在任何移动终端装置登入本移 动支付系统后, 启动商户收款功能, 随即显示产生付款要求的二维码 给顾客过目, 顾客可实时通过本移动支付系统即时付款; 商户会实时 知道付款结果, 省却商户来回传统收款机的时间, 提升营运效率, 也 省却顾客等候收款确认的时间。 由于任何移动终端都可作为移动收 款机使用, 这样可免装昂贵专用的收款机, 成本减省之佘, 又能达到 1. With the function of mobile cash register: Merchants can activate the merchant payment function after any mobile terminal device logs in to the mobile payment system, and then display the QR code that generates the payment request to the customer, and the customer can pass the mobile in real time. The payment system pays instantly; the merchant knows the payment result in real time, saves the time for the merchant to go back and forth to the traditional cash register, improves the operational efficiency, and saves the time for the customer to wait for the payment confirmation. Since any mobile terminal can be used as a mobile receiver The use of the machine, so that you can avoid expensive and expensive cash registers, the cost can be reduced, and can reach
2、 带有纸上付款的功能: 很多传统的收款机都祗装有简单的屏 幕, 不能显示丰富的画面。 使用本移动支付系统的商户只需将付款 要求的二维码打印出来, 顾客可依照纸上的二维码釆用本移动支付 方法。 好处是在不需加装或更换硬件的前提下, 稍为改动付款程序, 就可适应本移动支付的方法,是一种低成本、 快速易办的改装。 2, with the function of payment on paper: Many traditional cash registers are equipped with simple screens, can not display rich pictures. The merchant using the mobile payment system only needs to print the QR code of the payment request, and the customer can use the mobile payment method according to the two-dimensional code on the paper. The advantage is that the mobile payment method can be adapted to the mobile payment method without changing or replacing the hardware. It is a low-cost, quick-to-do modification.
3、 带有服务账单付款的功能: 如每月或每季的电力、煤气账单加 载付款要求的二维码, 付款者可在家中或任何地方,用移动终端使用 本移动支付系统付款, 省却特地到专门店或使用网上验证支付程序 的时间,提升时间效益。 3. Function with service bill payment: If the monthly or quarterly electricity and gas bills load the QR code of the payment request, the payer can use the mobile payment system to pay with the mobile terminal at home or anywhere, saving the special Increase time efficiency by going to a specialty store or using an online verification payment program.
4、 带有消费者新体验 /商户巿场推广的功能: 有别于 SMS文字式 移动支付, 本系统在付款者付账后, 会提供更多回馈、 折扣、 抽奖 及个人特别款待等的活动或丰富的消费信息。 客户付款后的片刻, 也就是商户向消费者宣传的大好时机, 同时亦是消费者获得多重优 惠及大量购物信息的时段。 对商户的好处就是促进巿场产品流动, 将 不同客户群引进到不同的销售点。 4. With the new consumer experience / merchant market promotion function: Different from SMS text mobile payment, the system will provide more rewards, discounts, sweepstakes and personal special treats after the payer pays the bill or Rich consumer information. The moment after the customer pays, it is also a good time for the merchant to publicize to the consumer, and it is also the time for consumers to get multiple benefits and a lot of shopping information. The benefit to merchants is to promote market flow of products and introduce different customer groups to different points of sale.
5、 带有保障个人隐私的功能: 本移动支付的过程中, 付款者的 个人资料不会被泄漏让第三方知道。 SMS 移动支付的坏处是, 付款 者必须透露移动电话的号码; 又使用任何卡类付款时, 如信用卡或 借记卡等, 其坏处是卡上的个人资料有机会被盗用而付款者懵然不 知。 5. Features with personal privacy protection: During the mobile payment process, the payer's personal information will not be disclosed to third parties. The disadvantage of SMS mobile payment is that the payer must disclose the number of the mobile phone; when using any card type, such as a credit card or debit card, the disadvantage is that the personal data on the card has the opportunity to be stolen and the payer is unaware .
6、 带有环保的功能: 由于是运用通用存在的硬件 (移动终端), 本 移动支付系统可作为支付或收款用途, 省却制造为配合移动支付系 统专有设备的资源。 6. Environmentally-friendly functions: Due to the use of ubiquitous hardware (mobile terminals), this mobile payment system can be used for payment or collection purposes, eliminating the need to manufacture resources for the mobile payment system's proprietary equipment.
由于不用提供信用卡或银行卡等数据来开通本发明的移动支付 服务, 年青人报名参加派对或集体活动时, 只要用普通的个人智能电 话, 釆用本发明的支付系统即可在网上报名后马上付款, 无需轮候, 省却年青人报名所需的时间,以及方便活动主办者更有效率得知付款 人数和所收取的总数额。 Since the mobile payment service of the present invention is not provided by providing data such as a credit card or a bank card, when a young person signs up for a party or a group event, it is only necessary to use ordinary personal smart electricity. In this way, the payment system of the present invention can be paid immediately after registration on the Internet, without waiting, eliminating the time required for young people to register, and facilitating the event organizer to more efficiently know the number of payers and the total amount charged.
当公干或者旅游人士来到异地, 可以购买流动电话充值卡, 一来 可以省却高昂的漫游费用, 二来可以即时开通移动支付服务, 免除在 外地使信用卡而要支付昂贵的汇率费用,享受电子付款的方便以及拥 有完整的消费记录。 当需要增加账户的可用额度时, 消费者可到附近 的电信商店或者便利店充值,增加账户支付弹性,以减低损失的风险。 When a business or tourist person comes to a different place, you can purchase a mobile phone recharge card, which can save high roaming charges. Secondly, you can immediately open a mobile payment service, exempting the credit card from paying foreign exchange rates and enjoying electronic payment. Convenience and a complete consumption record. When it is necessary to increase the available amount of the account, the consumer can recharge to a nearby telecommunications store or convenience store to increase the account payment flexibility to reduce the risk of loss.
身份认证系统和方法的实施例二 Embodiment 2 of identity authentication system and method
图 5是本实施例的身份认证系统的框图, 在本实施例, 所使用的 原理和技术与上文所述第一个实施例的基本上相同, 不过当中有部 份的修改和改进。 理论上,该两实施例的系统构造是一样的。 比较图 1和图 5, 可发现两图有不少分别, 原因在于图 5作出了简化, 只显示 了本身份认证系统的主要硬件配置。 该身份认证系统包括用户装置 20(需要进行认证的用户所使用的装置)、 身份认证系统服务器 128、 电信运营商的移动用户移动资料服务器 125和验证装置 26(即图 1的 身份认证要求提供者 120所使用的装置)。 用户装置 20包括非移动设 备和移动设备 122(移动终端), 非移动设备包括计算机等可连接上网 的装置, 而移动设备 122 包括所有内置有用户身份模块 (Subscriber Identity Module, 即 SIM卡)并可连接到网络的手提装置, 例如手机、 个人数码助理 (Personal Digital Assistant, 即 PDA)和平板电脑等。身份 认证系统服务器 128负责进行认证的工作, 其接收来自验证装置 26 的认证请求, 然后身份认证系统服务器 128根据认证请求产生 URL 网页地址和加密编码 (编码经过加密, 以防止别人修改), 并把该加密 编码嵌入 URL 网页地址以得到包含加密编码的 URL 网页地址, 再 把包含加密编码的 URL 网页地址传送回验证装置 26, 验证装置 26 其后使用包含加密编码的 URL 网页地址进行身份认证。验证装置 26 得到此包含加密编码的 URL 网页地址后, 在需要进行身份认证时就 会把此包含加密编码的 URL 网页地址传送到用户装置 20 以启动用 户的真正认证程序 。 当用户的真正认证程序启动了, 所有的核心认 证步骤都在身份认证系统服务器 128 进行, 详细步骤会在下文会描 述。 本发明的身份认证依赖第三方的帮助来完成, 该第三方是电信服 务商 (电信运营商), 电信服务商的移动用户移动资料服务器 125储存 有移动用户的个人资料, 包括其姓名、 住址、 移动电话号码、 帐户号 码、 帐户结佘等等。 在一个实施例中,用户需要要求电信服务商启用 本服务, 另外, 用户也可在身份认证系统服务器 128登记, 表示其使 用本服务。 身份认证系统服务器 128与移动用户移动资料服务器 125 连接,并取得用户行动装置的电话号码和用户的数据以确认用户的身 份。 验证装置 26设置在需要进行认证的相关机构, 其具备通过特定 传递方式与用户装置 20通信的能力。 所述特定传递方式包括用户装 置 20支持的所有传递方式, 如条形码、 微波、 声波, 具体包括快速 响应矩阵码、 近场通讯 (NFC)、 蓝牙、 红外线、 无线保真 (Wi-Fi)和射 频识别 (RFID)等等。 验证装置 26可以是计算机、 服务器等。 Figure 5 is a block diagram of the identity authentication system of the present embodiment. In this embodiment, the principles and techniques used are substantially the same as those of the first embodiment described above, with some modifications and improvements. In theory, the system configurations of the two embodiments are the same. Comparing Fig. 1 with Fig. 5, it can be found that there are quite a few differences between the two figures. The reason is that Fig. 5 is simplified, showing only the main hardware configuration of the identity authentication system. The identity authentication system includes a user device 20 (a device used by a user requiring authentication), an identity authentication system server 128, a mobile subscriber mobile data server 125 of the telecommunications carrier, and a verification device 26 (ie, the identity authentication request provider of FIG. 1) 120 devices used). The user device 20 includes a non-mobile device and a mobile device 122 (mobile terminal), and the non-mobile device includes a device such as a computer that can be connected to the Internet, and the mobile device 122 includes all built-in Subscriber Identity Modules (SIMs). Portable devices connected to the network, such as mobile phones, Personal Digital Assistants (PDAs), and tablets. The identity authentication system server 128 is responsible for the authentication work, which receives the authentication request from the verification device 26, and then the identity authentication system server 128 generates the URL web page address and the encryption code (the code is encrypted to prevent others from modifying) according to the authentication request, and The encrypted code is embedded in the URL web page address to obtain a URL web page address containing the encrypted code, and the URL web page address including the encrypted code is transmitted back to the verification device 26, and the verification device 26 thereafter uses the URL address of the web page containing the encrypted code for identity authentication. Verification device 26 After obtaining the URL of the URL containing the encrypted code, the URL page address including the encrypted code is transmitted to the user device 20 when the identity authentication is required to start the user's true authentication process. When the user's authentic authentication process is initiated, all core authentication steps are performed at the identity authentication system server 128, and the detailed steps are described below. The identity authentication of the present invention is completed by the assistance of a third party, which is a telecommunications service provider (telecom operator). The mobile subscriber mobile data server 125 of the telecommunications service provider stores the personal data of the mobile subscriber, including his/her name, address, Mobile phone number, account number, account balance, and more. In one embodiment, the user needs to require the telecommunications service provider to enable the service, and in addition, the user may also register with the identity authentication system server 128 to indicate that they are using the service. The identity authentication system server 128 is coupled to the mobile user mobile data server 125 and obtains the telephone number of the user's mobile device and the user's data to confirm the identity of the user. The verification device 26 is provided in a related mechanism that requires authentication, and has the ability to communicate with the user device 20 by a specific delivery method. The specific delivery mode includes all delivery modes supported by the user device 20, such as barcode, microwave, sound wave, specifically including fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless fidelity (Wi-Fi), and radio frequency. Identification (RFID) and so on. The verification device 26 can be a computer, a server, or the like.
参见图 6, 其展示了本实施例的身份认证的简单流程图。 这里以 用户通过某一网站确立其身份为例解释本发明的此实施例。 首先, 认 证流程在步骤 28开始, 在步骤 30, 用户先打开安装在用户装置 20 上的特定应用程序, 或者通过用户装置 20的网络功能连接到网站, 该网站由验证装置 26托管, 所述网站可以是购物网站、 网上银行、 消费网站和政府网站等需要认证的网站。 简单地说, 步骤 30的目的 就是使用用户装置 20连接到验证装置 26, 用户装置 20与验证装置 26之间是釆用 TCP/IP连接方式, 包括现在或未来可用的任何有线或 无线技术, 所述无线技术包括无线保真 (Wi-Fi)、 通用封包无线服务技 术 (GPRS)、 第三代行动通讯技术 (3G)和第四代行动通讯技术 (4G)等。 在连接到验证装置 26(其所托管的网站)后, 用户可输入数据 (或不输 入), 并示意进行认证, 验证装置 26会收集必要的数据, 其中包括用 户使用的用户装置 20的互联网协议地址 (Internet Protocol Address)及 通讯端口 (Port)。 然后, 在步骤 32, 验证装置 26根据收集的数据产生 认证请求, 并发送该认证请求到身份认证系统服务器 128, 认证请求 中包括用户输入的数据、 用户装置 20 的互联网协议地址 (Internet Protocol Address)及通讯端口(Port)。 身份认证系统服务器 128接收认 证请求后,会基于用户装置 20的互联网协议地址及通讯端口 (Port) 确 定所述用户装置是否为移动电话网络 (例如 3G/4G)上网的移动设备, 从而得到装置确定结果,而且身份认证系统服务器 128会根据认证请 求产生 URL 网页地址和加密编码, 并把加密编码嵌入 URL 网页地 址以得到包含加密编码的 URL 网页地址 (步骤 34), 其后身份认证系 统服务器 128会把装置确定结果和包含加密编码的 URL 网页地址传 送回验证装置 26(步骤 36)。 在步骤 38, 验证装置 26使用得到的包含 加密编码的 URL 网页地址进行身份认证。 加密编码包括使用条件参 数,如有效次数和有效时间,有效次数定义了加密编码的可使用次数, 而有效时间定义了加密编码的可使用时间。加密编码的有效次数和有 效时间由验证装置 26按需要设定, 该设定会包含在认证请求中, 身 份认证系统服务器 128接收认证请求后会按当中包含的数据 (包括设 定)而产生适当的 URL 网页地址和加密编码。如果经常需要进行认证 动作, 可以设定多次的有效次数, 如 10次, 相反, 如果没有必要或 者为了安全理由, 可以设定加密编码只可使用一次, 在第一次使用完 之后该加密编码就会变成无效,即使别人获得也不能使用。相同道理, 加密编码的有效时间限制了该加密编码的使用时间,可设定该加密编 码只在某一段时间内有效, 如一天、 一星期或一个月内, 超过有效时 间, 即使加密编码还剩佘有效次数, 加密编码也会变得无效, 从而大 大提升了安全性。 验证装置 26得到包含加密编码的 URL 网页地址后即可进行身份 认证, 本发明主要是利用用户的电话号码来完成身份的认证, 所以用 户最后必须使用移动设备 122来进行最后的认证步骤, 如之前所述, 移动设备 122 包括所有内置有用户身份模块 (Subscriber Identity Module, 即 SIM卡)并可连接到网络的手提装置, 例如手机、 个人数 码助理 (Personal Digital Assistant, 即 PDA)和平板电脑等。因为身份认 证系统服务器 128在传送包含加密编码的 URL 网页地址到验证装置 26的同时会一起传送装置确定结果, 所以验证装置 26知道用户正在 使用的是非移动设备或移动设备 122, 若用户装置 20是使用移动电 话网络上网的移动设备 122, 验证装置 26则直接通过移动电话网络 传送包含加密编码的 URL 网页地址到移动设备 122, 移动设备 122 使用浏览器或软体读取包含加密编码的 URL 网页地址以进行身份认 证,相反,若用户装置 20不是使用移动电话网络上网的移动设备 122, 验证装置 26则要求用户改用以移动电话网络上网的移动设备 122并 通过特定的传递方式传送包含加密编码的 URL 网页地址到转用的移 动设备 122以进行身份认证。 确定用户装置 20是使用移动电话网络 上网的移动设备或非使用移动电话网络上网的移动设备 122 的步骤 也可以由验证装置 26来进行, 因为用户装置 20有时与验证装置 26 是在同一个空间,例如:手机网电等等, 用户装置 20首先连接到验证 装置 26 时, 验证装置 26 已可检测用户装置 20 的互联网协议地址 (Internet Protocol Address)来得到装置确定结果, 其后验证装置 26在 传送包含加密编码的 URL 网页地址时即可要求用户直接使用浏览器 或软体来打开包含加密编码的 URL 网页地址以进行认证或转用其它 使用移动电话网络上网的移动设备 122来进行认证。 Referring to Figure 6, a simplified flow chart of the identity authentication of this embodiment is shown. This embodiment of the invention is explained herein by taking the user as an example of establishing his identity through a website. First, the authentication process begins at step 28, where the user first opens a particular application installed on the user device 20, or connects to the website via the network function of the user device 20, the website being hosted by the verification device 26, the website It can be a website that requires certification, such as shopping websites, online banking, consumer websites, and government websites. Briefly, the purpose of step 30 is to connect to the verification device 26 using the user device 20, which is a TCP/IP connection between the user device 20 and the verification device 26, including any wired or wireless technology available now or in the future. Wireless technologies include Wi-Fi, General Packet Radio Service (GPRS), Third Generation Mobile Communications (3G), and Fourth Generation Mobile Communications (4G). After connecting to the verification device 26 (the website it hosts), the user can enter data (or not lose) The authentication device 26 collects the necessary data, including the Internet Protocol Address and the communication port (Port) of the user device 20 used by the user. Then, in step 32, the verification device 26 generates an authentication request according to the collected data, and sends the authentication request to the identity authentication system server 128, where the authentication request includes data input by the user, and an Internet Protocol Address of the user device 20. And the communication port (Port). After receiving the authentication request, the identity authentication system server 128 determines whether the user device is a mobile device connected to the mobile phone network (for example, 3G/4G) based on the Internet Protocol address and the communication port (Port) of the user device 20, thereby obtaining device determining. As a result, the identity authentication system server 128 generates a URL web page address and encryption code based on the authentication request, and embeds the encryption code into the URL web page address to obtain a URL web page address including the encrypted code (step 34), after which the identity authentication system server 128 The device determination result and the URL web page address including the encryption code are transmitted back to the verification device 26 (step 36). At step 38, the verification device 26 uses the resulting URL web page address containing the encrypted code for identity authentication. Encryption coding includes the use of conditional parameters such as the number of valid times and the effective time, the effective number defines the number of times the encryption code can be used, and the effective time defines the usable time of the encryption code. The effective number and effective time of the encryption code are set by the verification device 26 as needed. The setting is included in the authentication request, and the identity authentication system server 128 receives the authentication request and generates the appropriate data (including settings). URL page address and encryption code. If you need to perform authentication actions frequently, you can set the number of times of multiple times, such as 10 times. On the contrary, if it is not necessary or for security reasons, you can set the encryption code to be used only once. After the first use, the encryption code is used. It will become invalid, even if others get it. By the same token, the effective time of the encryption code limits the usage time of the encryption code. The encryption code can be set to be valid only for a certain period of time, such as one day, one week or one month, exceeding the valid time, even if the encryption code is left.佘 Effective times, the encryption code will also become invalid, which greatly improves security. After the verification device 26 obtains the URL of the URL containing the encrypted code, the identity authentication can be performed. The present invention mainly uses the user's phone number to complete the identity authentication, so the user must finally use the mobile device 122 to perform the final authentication step, as before. The mobile device 122 includes all portable devices that have a Subscriber Identity Module (SIM card) built in and can be connected to the network, such as a mobile phone, a Personal Digital Assistant (PDA), and a tablet. Since the identity authentication system server 128 transmits the device determination result together while transmitting the URL page address including the encrypted code to the verification device 26, the verification device 26 knows that the user is using a non-mobile device or mobile device 122, if the user device 20 is The mobile device 122, which uses the mobile phone network to access the Internet, transmits the URL page address containing the encrypted code directly to the mobile device 122 via the mobile phone network. The mobile device 122 uses the browser or software to read the URL of the URL containing the encrypted code. Identity authentication is performed. Conversely, if the user device 20 is not a mobile device 122 that uses the mobile phone network to access the Internet, the authentication device 26 requires the user to switch to the mobile device 122 on the mobile phone network and transmit the URL containing the encrypted code through a specific delivery method. The web page address is transferred to the mobile device 122 for identity authentication. The step of determining that the user device 20 is a mobile device that uses the mobile phone network to access the Internet or the mobile device that does not use the mobile phone network to access the Internet may also be performed by the verification device 26, since the user device 20 is sometimes in the same space as the verification device 26. For example, when the user device 20 is first connected to the verification device 26, the verification device 26 can detect the Internet Protocol Address of the user device 20 to obtain the device determination result, and then the verification device 26 is transmitting. Include an encrypted encoded URL web page address to require the user to open the URL page address containing the encrypted code directly for use in a browser or software for authentication or to switch to another mobile device 122 using the mobile phone network for authentication.
上文已提到, 本发明所说的特定传递方式包括用户装置 20 支持 的所有传递方式, 如条形码、微波、声波, 具体包括快速响应矩阵码、 近场通讯 (NFC)、 蓝牙、 红外线、 无线保真 (Wi-Fi)和射频识另 (RFID) 等等。 作为例子, 验证装置 26 可通过条形码 (快速响应矩阵码)传送 包含加密编码的 URL 网页地址到行动装置, 首先验证装置 26展示 条形码, 包括以投射、 显示屏展示等任何形式。 用户开启移动设备 122的相关程序以读取条形码, 并接收包含加密编码的 URL 网页地 址, 其后该网址会把移动设备 122导向身份认证系统服务器 128, 之 后身份认证系统服务器 128会根据移动设备 122的特征确认用户的身 份。这里所说的移动设备 122的特征指的是该移动设备 122的移动用 户国际号码 (MSISDN), 这里简称电话号码。 有多种方法可以用来确 定移动设备 122的电话号码 (MSISDN)及电信服务商标识符 /国际移动 用户标识符, 即 IMSI), 在本发明的一个实施例, 使用以下方法: 首 先, 移动设备 122被导向到身份认证系统服务器 128时, 身份认证系 统服务器 128 会获取该移动设备 122 的互联网协议地址 (Internet Protocol address, 即 IP address) , 因为每间电信服务商都会从区域网 际网路注册管理机构 Regional Internet registry(RIR)获得某些范围独 一无二的互联网协议地址, 所述根据互联网协议地址所属范围就得 知所属的电信服务商, 然后身份认证系统服务器 128 把该移动设备 122的互联网协议地址传送到相应的电信服务商的移动用户移动资料 服务器 125并要求移动用户移动资料服务器 125进行配对,从而提供 所述互联网协议地址对应的电话号码和用户数据。本发明适用于互联 网协议版本 4(Intemet Protocol version 4 , IPv4)、 互联网协议版本 6(Intemet Protocol version 6, IPv6)或任何未来可用的互联网协议版 本。 为了更准确地确认用户的身份, 移动设备 122被导向到身份认证 系统服务器 128时,身份认证系统服务器 128可以获取该行动装置的 互联网协议地址 (Internet Protocol Address)及通讯端口(Port) , 然后身 份认证系统服务器 128 把该行动装置的互联网协议地址 (Internet Protocol Address)及通讯端口(Port)传送到相应的电信服务商的移动用 户移动资料服务器 125并要求移动用户移动资料服务器 125进行配 对。 移动用户移动资料服务器 125 储存有互联网协议地址 (Internet Protocol Address)及通讯端口(Port)的映射表, 该映射表记载了特定的 移动互联网协议地址 (Internet Protocol Address)及通讯端口(Port)相对 应的移动电话号码 (MSISDN), 根据确定的电话号码 (MSISDN), 相应 的用户也能被确定。 因为每个移动电话号码 (MSISDN)与一个唯一的 移动互联网协议地址 (Internet Protocol Address)及通讯端口(Port)捆绑 在一起, 通过此方法确定的用户身份是真确的, 也是唯一的, 并且得 到了第三方(电讯公司)的保证。 移动设备 122被导向身份认证系统服 务器 128后, 认证程序是自动进行的, 用户无需作任何操作, 身份认 证系统服务器 128会自动完成认证,并把结果传送回移动设备 122和 验证装置 26, 认证程序继而结束。 为了进一步加强安全性, 本发明 的系统加入了强制中止功能, 该强制中止功能可在用户的移动设备 122、 验证装置 26或身份认证系统服务器 128任何一方进行, 例如, 用户在进行认证的途中觉得网站有问题或根据自身的意愿,用户可以 启用强制中止功能以结束认证程序。 另一方面, 验证装置 26或身份 认证系统服务器 128 在检测到恶意攻击或系统不稳定的情况下可自 动启用强制中止功能, 以防止数据外泄等情况。该强制中止功能由包 含在移动设备 122、 验证装置 26和身份认证系统服务器 128中的认 证中止模块控制。 As mentioned above, the specific delivery mode referred to in the present invention includes all transmission modes supported by the user device 20, such as barcode, microwave, sound wave, specifically including fast response matrix code, near field communication (NFC), Bluetooth, infrared, wireless. Fidelity (Wi-Fi) and Radio Frequency Identification (RFID) and many more. As an example, the verification device 26 may transmit the URL web page address containing the encrypted code to the mobile device via a barcode (Quick Response Matrix Code), first the verification device 26 displays the barcode, including in any form such as projection, display display, and the like. The user turns on the associated program of the mobile device 122 to read the barcode and receives the URL web address containing the encrypted code, after which the web address will direct the mobile device 122 to the identity authentication system server 128, after which the identity authentication system server 128 will act according to the mobile device 122. The characteristics identify the user's identity. The feature of the mobile device 122 referred to herein refers to the mobile subscriber international number (MSISDN) of the mobile device 122, referred to herein as the telephone number. There are a number of methods that can be used to determine the mobile device 122's telephone number (MSISDN) and the telecommunications service provider identifier/International Mobile Subscriber Identifier (IMSI). In one embodiment of the invention, the following method is used: First, the mobile device When the server 122 is directed to the identity authentication system server 128, the identity authentication system server 128 obtains the Internet Protocol address (IP address) of the mobile device 122, because each telecommunication service provider registers and manages from the regional Internet. The organization Regional Internet registry (RIR) obtains a certain range of unique Internet Protocol addresses, which are known to the telecommunication service provider according to the scope of the Internet Protocol address, and then the identity authentication system server 128 transmits the Internet Protocol address of the mobile device 122. The mobile subscriber data server 125 to the corresponding telecommunications service provider and the mobile subscriber mobile data server 125 are required to pair to provide the telephone number and subscriber data corresponding to the internet protocol address. The present invention is applicable to Internet Protocol version 4 (IPv4), Internet Protocol version 6, IPv6, or any future available Internet protocol version. In order to more accurately confirm the identity of the user, when the mobile device 122 is directed to the identity authentication system server 128, the identity authentication system server 128 can obtain the Internet Protocol Address and the communication port (Port) of the mobile device, and then the identity. The authentication system server 128 transmits the Internet Protocol Address and the port of the mobile device to the mobile user mobile data server 125 of the corresponding telecommunication service provider and requests the mobile user to move the data server 125 for matching. Correct. The mobile user mobile data server 125 stores a mapping table of an Internet Protocol Address and a communication port (Port), and the mapping table records a specific mobile internet protocol address (Internet Protocol Address) and a communication port (Port). The mobile phone number (MSISDN), according to the determined telephone number (MSISDN), the corresponding user can also be determined. Because each mobile phone number (MSISDN) is bundled with a unique Mobile Internet Protocol Address and Port, the user identity determined by this method is true and unique, and is obtained. Third party (telecom company) guarantee. After the mobile device 122 is directed to the identity authentication system server 128, the authentication process is automatically performed, and the user does not need to perform any operations. The identity authentication system server 128 automatically completes the authentication and transmits the result back to the mobile device 122 and the verification device 26, the authentication procedure. Then it ends. In order to further enhance security, the system of the present invention incorporates a forced suspension function that can be performed on either of the user's mobile device 122, the authentication device 26, or the identity authentication system server 128, for example, the user feels on the way to authentication. If there is a problem with the website or according to its own wishes, the user can enable the forced suspension function to end the authentication process. On the other hand, the verification device 26 or the identity authentication system server 128 can automatically enable the forced suspension function when a malicious attack or system instability is detected to prevent data leakage and the like. The forced abort function is controlled by an authentication abort module included in mobile device 122, authentication device 26, and identity authentication system server 128.
以上已详细描述该身份认证的实施例, 该身份认证的方法和系统 可以按需要应用到不同的范畴和环境, 例如会埸访客的身份确认、 关 口通行的认证和消费身份的确认等。以下会描述本身份认证方法和系 统的特定应用。 The embodiment of the identity authentication has been described in detail above. The method and system for identity authentication can be applied to different categories and environments as needed, such as identification of a visitor, authentication of a pass, and confirmation of a consumer identity. The following describes the identity authentication method and the specific application of the system.
使用本发明的身份认证系统和方法的实施例二中的系统进行移动支 付的实施例 Embodiment for performing mobile payment using the system in Embodiment 2 of the identity authentication system and method of the present invention
以上详细描述了身份认证系统和方法的实施例, 以下会描述其在 移动支付 (即消费购物)的应用, 在移动支付方面的应用的主要原理和 程序与上文所述的身份认证系统和方法的实施例二基本上都相同,只 是步骤有部份的增减。 The embodiments of the identity authentication system and method are described in detail above. The following describes its application in mobile payment (ie, consumer shopping), the main principles of application in mobile payment and The procedure is basically the same as the second embodiment of the identity authentication system and method described above, except that the steps are partially increased or decreased.
本实施例在移动支付方面的应用所需要的硬件配备与身份认证 系统实施例二是一样的, 如图 5所示, 包括用户装置 20、 身份认证 系统服务器 128、 移动用户移动资料服务器 125和验证装置 26。 在此 实施例中, 认证要求提供者为零售商, 而验证装置 26通常是托管了 零售商的购物网站的服务器。 另外, 身份认证系统服务器 128除了进 行认证工作, 还负责交易的中央结算。 换言之, 身份认证系统服务器 128 相当于基于二维码和电信运营商 (电信服务商)的移动支付系统的 实施例中的电信服务商的移动用户 IP地址资料服务器 16和电信服务 商的移动用户付款处理服务器 126的结合, 可想象为移动用户 IP地 址资料服务器 16和移动用户付款处理服务器 126组合在一起得到身 份认证系统服务器 128, 其拥有移动用户 IP地址资料服务器 16和移 动用户付款处理服务器 126两者的功能。 The hardware configuration required for the application of the mobile payment in this embodiment is the same as that of the second embodiment of the identity authentication system. As shown in FIG. 5, the user equipment 20, the identity authentication system server 128, the mobile user mobile data server 125, and the verification are included. Device 26. In this embodiment, the authentication request provider is a retailer, and the verification device 26 is typically a server hosting a retailer's shopping website. In addition, the identity authentication system server 128 is responsible for the central settlement of transactions in addition to the authentication work. In other words, the identity authentication system server 128 is equivalent to the mobile subscriber IP address data server 16 of the telecommunication service provider and the mobile subscriber payment of the telecommunication service provider in the embodiment of the mobile payment system based on the two-dimensional code and the telecommunication operator (telecom service provider) The combination of the processing server 126, it is conceivable that the mobile user IP address data server 16 and the mobile user payment processing server 126 are combined to obtain an identity authentication system server 128, which has a mobile user IP address data server 16 and a mobile user payment processing server 126. The function of the person.
图 7展示了利用认证系统进行移动支付的流程图。程序在步骤 42 开始,本移动支付的基本流程与身份认证系统实施例二的流程大同小 异。 首先用户使用用户装置 20连接到验证装置 26, 即浏览相关的购 物网站 (步骤 44), 用户选择合适的货品并结账。 在步骤 46, 验证装 置 26(购物网站) 得到用户需要支付的金额等数据并取得用户装置 20 的 IP地址及通讯端口(Port), 验证装置 26然后把数据和用户装置 20 的 IP地址及通讯端口 (Port)传送给身份认证系统服务器 128。 在步骤 48, 身份认证系统服务器 128根据接收到的数据产生 URL 网页地址 和加密编码, 并把加密编码嵌入 URL 网页地址以得到包含加密编码 的 URL 网页地址,并且根据用户装置 20的 IP地址及通讯端口(Port) 确定其是否为使用移动电话网络上网的行动装置,之后把包含加密编 码的 URL 网页地址和装置确定结果传回验证装置 26。这里的步骤基 本上与身份认证系统实施例二的步骤一样,不同的是本移动支付实施 例的加密编码的使用条件参数除了包括有效时间和有效次数,还包括 需要支付的金额, 其定义了所述用户需要支付的金额。 验证装置 26 接收包含加密编码的 URL 网页地址和装置确定结果后, 其基于装置 确定结果知道用户装置 20是否为使用移动电话网络上网的移动设备 122 (步骤 50), 若是使用移动电话网络上网的移动设备 122, 则允许 直接通过移动电话网络传送包含加密编码的 URL 网页地址到移动设 备 122, 若不是使用移动电话网络上网的移动设备 122, 则要求用户 改用以移动电话网络上网的移动设备 122 并通过特定的传递方式传 送包含加密编码的 URL 网页地址到移动设备 122。 即使验证装置 26 允许直接通过移动电话网络传送包含加密编码的 URL 网页地址到移 动设备 122, 用户也有其他选择权, 用户可以选择正在使用的移动设 备 122进行付款 (步骤 52),也可以选择使用其他的移动设备 122进行 付款 (步骤 54)。 用户进行选择后, 接收包含加密编码的 URL 网页地 址 (步骤 58)。验证装置 26基于装置确定结果知道用户装置 20不是使 用移动电话网络上网的移动设备 122时,则会要求用户使用以移动电 话网络上网的移动设备 122接收包含加密编码的 URL 网页地址, 用 户转用移动设备 122后, 则进行步骤 58。 用户的移动设备 122接收 包含加密编码的 URL 网页地址后, 之后的程序与身份认证系统实施 例二的流程一样, 这里不详细重复。 简单地说, 移动设备 122会读取 此包含加密编码的 URL 网页地址, 该网页地址会把行动装置导向身 份认证系统服务器 128, 之后身份认证系统服务器 128会从电信服务 商获取用户数据 (步骤 60), 从而确立用户的身份 (步骤 62), 所述用户 数据报括用户的电话号码、其相应帐户信息和账户结佘等。 详细方法 是使用 IP地址及通讯端口(Port)的映射, 其在上文身份认证系统实施 例二已详细解释。 确立用户身份后, 身份认证系统服务器 128会检查 加密编码是否有效 (步骤 64),例如当中的有效时间参数是否还在有效 期内、 有效次数是否成立等等。 若加密编码有效, 则进行步骤 68, 若无效, 则进行步骤 66, 即向用户发送失效信息并结束支付程序。 在步骤 68, 身份认证系统服务器 128会检查用户帐户是否有足够金 额支付该交易, 若金额足够, 进行步骤 72, 否则进行步骤 70, 在步 骤 70, 身份认证系统服务器 128通知用户金额不足, 提示用户增值, 并结束支付程序。 在步骤 72, 身份认证系统服务器 128处理支付, 要求电信服务商的移动用户移动资料服务器 125 在用户的相应帐户 中扣除相应的金额,而扣除的金额则相应转移到相应的购物网站的账 户。 相应的购物网站已预先在身份认证系统服务器 128注册或登记, 并得到商户编码,身份认证系统服务器 128利用商户编码确认商户的 身份, 并知道其相关数据, 如帐户号、 地址等。 扣款成功后, 移动用 户移动资料服务器 125发送确认信息到身份认证系统服务器 128, 身 份认证系统服务器 128收到确认信息后, 更新该用户的数据, 如已使 用金额等, 最后发送付款成功信息给零售商的验证装置 26和用户的 移动设备 122, 即在步骤 74完成付款程序, 最后结束支付程序 (步骤 76)。 用户使用本移动支付进行消费, 所用的结账户口是该用户的移 动电话结账户口, 其消费金额会直接显示在该用户的移动电话账单 中。 当需要增加帐户的可用金额, 用户可以随时随地购买移动电话充 值卡进行充值, 以增加支付的弹性。 由上述可知, 身份认证系统服务 器 128在本移动支付的实施例中除了进行认证工作,还负责交易的中 央结算, 身份认证系统服务器 128与移动用户移动资料服务器 125、 零售商的验证装置 26沟通, 处理金额的结算, 当中用户的移动设备 122从不与移动用户移动资料服务器 125有联系或沟通。 Figure 7 shows a flow chart for mobile payment using an authentication system. The process begins in step 42, and the basic flow of the mobile payment is similar to the process of the second embodiment of the identity authentication system. First, the user connects to the verification device 26 using the user device 20, i.e., browses the relevant shopping website (step 44), and the user selects the appropriate item and settles the account. At step 46, the verification device 26 (shopping website) obtains data such as the amount of money the user needs to pay and obtains the IP address and communication port of the user device 20, and the verification device 26 then sets the data and the IP address and communication port of the user device 20. (Port) is transmitted to the identity authentication system server 128. In step 48, the identity authentication system server 128 generates a URL webpage address and an encryption code based on the received data, and embeds the encryption code into the URL webpage address to obtain a URL webpage address including the encrypted code, and according to the IP address and communication of the user device 20. The port determines whether it is a mobile device that uses the mobile phone network to access the Internet, and then passes the URL page address and device determination result containing the encrypted code back to the verification device 26. The steps here are basically the same as the steps of the second embodiment of the identity authentication system, except that the mobile payment implementation is implemented. The cryptographically encoded usage condition parameter of the example includes, in addition to the effective time and the effective number of times, an amount to be paid, which defines the amount the user needs to pay. After receiving the URL page address and the device determination result including the encryption code, the verification device 26 knows whether the user device 20 is the mobile device 122 accessing the Internet using the mobile phone network based on the device determination result (step 50), if the mobile phone network is used for mobile Internet access The device 122 allows the URL address containing the encrypted code to be directly transmitted to the mobile device 122 through the mobile phone network. If the mobile device 122 is not using the mobile phone network, the user is required to switch to the mobile device 122 on the mobile phone network. The URL page address containing the encrypted code is transmitted to the mobile device 122 by a particular delivery method. Even if the verification device 26 allows the URL page address containing the encrypted code to be transmitted directly to the mobile device 122 over the mobile telephone network, the user has other options, the user may select the mobile device 122 being used for payment (step 52), or may choose to use other The mobile device 122 makes a payment (step 54). After the user makes a selection, the web page address containing the encrypted code is received (step 58). When the verification device 26 knows that the user device 20 is not the mobile device 122 that uses the mobile phone network to access the Internet based on the device determination result, the user is required to receive the URL page address including the encrypted code using the mobile device 122 surfing the Internet through the mobile phone network, and the user switches to the mobile device. After device 122, step 58 is performed. After the user's mobile device 122 receives the URL page address including the encrypted code, the subsequent program is the same as the process of the second embodiment of the identity authentication system, and is not repeated here in detail. Briefly, the mobile device 122 reads the URL web page address containing the encrypted code, which will direct the mobile device to the identity authentication system server 128, after which the identity authentication system server 128 will retrieve the user data from the telecommunications service provider (step 60). And thereby establishing the identity of the user (step 62), the user data report including the user's phone number, its corresponding account information, and account balance. The detailed method is to use the mapping of the IP address and the communication port (Port), which has been explained in detail in the second embodiment of the identity authentication system above. After the identity of the user is established, the identity authentication system server 128 checks if the encryption code is valid (step 64), such as whether the valid time parameter is still within the validity period, whether the effective number is established, and the like. If the encryption code is valid, proceed to step 68. If not, proceed to step 66 to send the invalidation message to the user and end the payment procedure. At step 68, the identity authentication system server 128 checks whether the user account has sufficient amount to pay for the transaction. If the amount is sufficient, proceed to step 72. Otherwise, proceed to step 70. In step 70, the identity authentication system server 128 notifies the user that the amount is insufficient, prompting the user. Add value and end the payment process. At step 72, the identity authentication system server 128 processes the payment, requesting the mobile subscriber's mobile data server 125 of the telecommunications service provider to deduct the corresponding amount in the user's corresponding account, and the deducted amount is transferred to the corresponding shopping website's account accordingly. The corresponding shopping website has been previously registered or registered with the identity authentication system server 128 and obtained the merchant code. The identity authentication system server 128 uses the merchant code to confirm the identity of the merchant and knows its related data, such as account number, address, and the like. After the deduction is successful, the mobile user mobile data server 125 sends the confirmation information to the identity authentication system server 128. After receiving the confirmation information, the identity authentication system server 128 updates the user's data, such as the used amount, and finally sends the payment success information to The retailer's verification device 26 and the user's mobile device 122 complete the payment process at step 74 and finally terminate the payment process (step 76). The user uses the mobile payment for consumption, and the used account port is the user's mobile phone account account port, and the consumption amount is directly displayed on the user's mobile phone bill. When it is necessary to increase the available amount of the account, the user can purchase the mobile phone recharge card to recharge anytime and anywhere to increase the flexibility of the payment. As can be seen from the above, the identity authentication system server 128, in addition to performing the authentication work in the embodiment of the mobile payment, is also responsible for the central settlement of the transaction, and the identity authentication system server 128 communicates with the mobile user mobile data server 125 and the verification device 26 of the retailer. The settlement of the processing amount, in which the user's mobile device 122 never contacts or communicates with the mobile user mobile data server 125.
设快速移动玄付的实施例 Example of setting up fast moving
图 8是本发明利用身份认证系统实施例二的身份认证系统进行默 认快速移动支付的流程图。此预设快速移动支付的应用主要省略了上 述移动支付实施例的部份程序,预先产生 URL 网页地址和加密编码, 并把加密编码嵌入 URL 网页地址以得到包含加密编码的 URL 网页 地址以供使用, 从而提高效率, 逹到快速支付 /购买的目的。 FIG. 8 is a flow chart of the present invention utilizing the identity authentication system of the second embodiment of the identity authentication system for default fast mobile payment. The application of the preset fast mobile payment mainly omits part of the above mobile payment embodiment, and generates a URL webpage address and an encryption code in advance. The encryption code is embedded in the URL page address to obtain the URL address of the URL containing the encrypted code for use, thereby improving efficiency and facilitating fast payment/purchase.
与使用身份认证系统和方法的实施例二中的系统进行移动支付 的实施例相同, 商户需先在身份认证系统服务器 128注册或登记, 以 使身份认证系统服务器 128能辨认其身份。 如图 8所示, 在步骤 77, 商户把其用户需要支付的金额等数据传送给身份认证系统服务器 128, 身份认证系统服务器 128根据该资料会预先产生 URL 网页地 址和加密编码, 并把加密编码嵌入 URL网页地址以得到包含加密编 码的 URL 网页地址,加密编码包括需要支付的金额 (其定义了所述用 户需要支付的金额)、 有效次数和有效时间等条件参数, 这些条件参 数都可由商户定义。 通常情况下, 有效次数设定为 1 , 因为一个加密 编码对应一种货品, 当有人购买了该货品, 身份认证系统服务器 128 会立即更新数据, 有效次数变为 0, 以防止其他人重复使用相同的加 密编码, 造成混乱的情况。 但是, 在特殊情况下或个别需要, 有效次 数也可以设定为大于 1 , 如 2、 3、 5等。 包含加密编码的 URL 网页 地址预先产生后, 可把其以特定方式设置在个别地方, 特定方式包括 用户的移动设备 122支持的所有传递方式, 如条形码、 微波、 声波, 具体包括快速响应矩阵码、 近场通讯 (NFC)、 蓝牙、 红外线、 无线保 真 (Wi-Fi)和射频识别 (RFID)等等。 例如, 可把包括包含加密编码的 URL 网页地址的快速响应矩阵码放置在商店里的货品的旁边, 当买 家选中, 可立即使用移动设备 122读取快速响应矩阵码(即步骤 78)。 又如, 在不同的销售点, 可通过近场通讯 (NFC)、 蓝牙、 红外线等发 送包含加密编码的 URL 网页地址, 以允许移动设备 122接收, 用户 可随时选定其需要的商品, 而无需经过服务员的参与。用户使用移动 设备 122接收包含加密编码的 URL 网页地址后, 该网页地址会把移 动设备 122导向身份认证系统服务器 128, 之后身份认证系统服务器 128根据移动设备 122的特征获取用户数据 (步骤 79), 并确立用户身 份 (步骤 80)。 其后的步骤 81-87与图 7中的步骤 64、 66、 68、 70、 72、As with the embodiment of the mobile payment system of the system in the second embodiment using the identity authentication system and method, the merchant needs to register or register with the identity authentication system server 128 first to enable the identity authentication system server 128 to recognize its identity. As shown in FIG. 8, in step 77, the merchant transmits data such as the amount of money that the user needs to pay to the identity authentication system server 128, and the identity authentication system server 128 generates a URL webpage address and encryption code in advance based on the data, and encrypts the code. Embedding a URL webpage address to obtain a URL webpage address including an encrypted code, the encryption code includes conditional parameters such as an amount to be paid (which defines the amount of money the user needs to pay), a valid number of times, and a valid time, and these condition parameters can be defined by the merchant. . Normally, the effective number is set to 1, because an encrypted code corresponds to one item. When someone purchases the item, the identity authentication system server 128 immediately updates the data, and the effective number becomes 0 to prevent others from repeating the same. Encrypted encoding, causing confusion. However, in special cases or individual needs, the effective number can also be set to be greater than 1, such as 2, 3, 5, and so on. The webpage address including the encrypted code is pre-generated, and can be set in a specific manner in an individual place, and the specific manner includes all the delivery modes supported by the user's mobile device 122, such as a barcode, a microwave, an acoustic wave, and specifically includes a quick response matrix code. Near Field Communication (NFC), Bluetooth, Infrared, Wireless Fidelity (Wi-Fi), and Radio Frequency Identification (RFID). For example, a quick response matrix code including a URL page address containing an encrypted code can be placed next to the item in the store, and when the buyer selects, the mobile device 122 can be immediately read to read the quick response matrix code (i.e., step 78). For another example, at different point of sale, the URL page address including the encrypted code can be transmitted through Near Field Communication (NFC), Bluetooth, infrared, etc., to allow the mobile device 122 to receive, and the user can select the desired product at any time without After the attendant's participation. After the user receives the URL web page address including the encrypted code using the mobile device 122, the web page address directs the mobile device 122 to the identity authentication system server 128, and then the identity authentication system server 128 obtains the user data according to the characteristics of the mobile device 122 (step 79). And establish the user Share (step 80). Subsequent steps 81-87 and steps 64, 66, 68, 70, 72 in FIG.
74和 76是一样的, 上文已详细描述, 这里不再重复。 74 and 76 are the same, have been described in detail above, and will not be repeated here.
利用本发明身份认证系统和方法的实施例二中的系统允许用户之间 互相汇款的实施例 Embodiment of the system in Embodiment 2 using the identity authentication system and method of the present invention allows users to remit money to each other
本实施例是为了方便不同用户之间通过本发明的系统互相汇款 (转移金钱), 而无需经过银行。 图 9展示了本实施例的框图, 不同用 户的移动设备 122与电讯服务商的身份认证系统服务器 128互相通 信,而身份认证系统服务器 128与移动用户移动资料服务器 125互相 通信。 这里说的汇款指的是不同用户的移动帐户金额的转移。 首先, 用户甲(汇款用户)想把自己移动帐户(电讯帐户)内的金额转移到用户 乙 (接收汇款的用户)的移动帐户内, 该用户甲可以打开移动设备 122 的专用应用程序或打开特定的网址连接到身份认证系统服务器 128。 身份认证系统服务器 128其后会根据上文所述获取移动设备 122的 IP 地址及通讯端口 (Port), 再与移动用户移动资料服务器 125通信, 进 行映像并确立用户的身份。 具体步骤在上文已详细描述, 这里不再重 复。 用户甲的身份确认后, 用户甲需要输入用户乙的电话号码、 用户 乙使用的电讯服务商和转移的金额, 并传送到身份认证系统服务器 128, 身份认证系统服务器 128随后与相应的移动用户移动资料服务 器 125联系, 利用该电话号码搜寻出用户乙的身份和数据 (如其电讯 帐户号码等)。 双方的身份都确认后, 身份认证系统服务器 128就会 进行中央结算,要求相同的电讯服务商或不同的电讯服务商的移动用 户移动资料服务器 125 直接从用户甲的电讯帐户扣除相应的款项并 把该相应的款项加到用户乙的电讯帐户。 完成结算后, 身份认证系统 服务器 128会发送成功信息到双方的行动装置以完成程序。金额的转 移会直接显示在双方的电讯月结单中。 根据上述所说, 用户甲和用户 乙可以是相同电讯服务商的客户, 也可以是不同电讯服务商的客户。 另外, 除了用户甲主动汇款到用户乙, 用户乙 (要求汇款的用户)也可 以要求用户甲 (被要求汇款的用户)进行汇款 (即汇款程序也可以由用 户乙启动)。 用户乙首先连接到身份认证系统服务器 128以确立身份, 然后输入用户甲的电话号码、用户甲使用的电讯服务商和要求转移的 金额。 身份认证系统服务器 128 根据所提供的数据确立用户甲的身 份, 并发送信息 (包含用户乙的数据)到用户甲的移动设备 122, 以要 求其汇款。 不过用户甲有决定权, 如果其同意, 则进行上文所述的步 骤。 如果用户甲不同意, 其可取消汇款程序。 This embodiment is to facilitate mutual money transfer (transfer of money) between different users through the system of the present invention without going through a bank. 9 shows a block diagram of the present embodiment in which mobile devices 122 of different users communicate with the identity authentication system server 128 of the telecommunications service provider, and the identity authentication system server 128 and the mobile user mobile data server 125 communicate with each other. The remittance mentioned here refers to the transfer of the amount of mobile accounts of different users. First, User A (remittance user) wants to transfer the amount in his mobile account (telephone account) to the mobile account of User B (the user receiving the remittance), who can open the dedicated application of mobile device 122 or open a specific The URL is connected to the authentication system server 128. The identity authentication system server 128 then obtains the IP address and communication port (Port) of the mobile device 122 as described above, communicates with the mobile user mobile data server 125, maps and establishes the identity of the user. The specific steps have been described in detail above and will not be repeated here. After the identity of the user A is confirmed, the user A needs to input the telephone number of the user B, the telecommunications service provider used by the user B, and the transferred amount, and transmit to the identity authentication system server 128, and the identity authentication system server 128 then moves with the corresponding mobile user. The data server 125 contacts, and uses the phone number to search for the identity and data of the user B (such as its telecommunications account number, etc.). After the identity of both parties is confirmed, the identity authentication system server 128 performs central settlement, requiring the same telecommunications service provider or mobile subscriber data server 125 of a different telecommunications service provider to directly deduct the corresponding amount from the subscriber's telecommunications account and The corresponding amount is added to User B's telecommunications account. Upon completion of the settlement, the identity authentication system server 128 will send a success message to both parties' mobile devices to complete the procedure. The transfer of the amount will be directly displayed in the telecom statement of both parties. According to the above, User A and User B may be customers of the same telecommunications service provider or customers of different telecommunications service providers. In addition, in addition to user A's active remittance to user B, user B (user who requests remittance) can also Remittance is required to require User A (the user who is required to send money) (ie, the remittance procedure can also be initiated by User B). User B first connects to the identity authentication system server 128 to establish identity, and then enters the phone number of User A, the telecommunications service provider used by User A, and the amount requested to be transferred. The identity authentication system server 128 establishes the identity of the user A based on the provided data, and transmits the information (including the data of the user B) to the mobile device 122 of the user A to request the money transfer. However, User A has the right to decide, and if it agrees, proceed with the steps described above. If User A does not agree, it can cancel the remittance process.
以上已详细描述了本发明的不同实施例, 然而本发明的应用并不 只限于本说明书内的实施例, 系统配置和结构也不限于以上的实施 例。 此外, 也可对系统的构造作修改, 或增加不同功能, 以使本发明 的系统更完善和方便。例如, 可对加密编码加入不同的现有或未来的 加密技术, 以防止数据外泄, 还可对各实施例加入 SSL等数据加密 技术, 以保障用户。 还有, 用户被身份认证系统服务器 128确认身份 后, 用户可以额外设定登入密码和电邮通知, 增加了使用的弹性并进 一步加强了安全性, 用户在下一次连接到身份认证系统服务器 128 时, 除了身份认证系统服务器 128进行的自动步骤, 用户还必须输入 其设定的登入密码才能得到系统的身份确认。当身份认证系统服务器 128侦察到异常情况, 如用户的身份可能被盗用了的情况下, 身份认 证系统服务器 128会暂停认证程序并自动发电邮给用户, 以提醒用户 正有人使用认证服务, 要求用户确定是否是其本人, 否则认证程序不 能继续进行下去。 再者, 以上所述的所有实施例都可加入强制中止功 能, 该强制中止功能可在用户的移动设备 122、 验证装置 26或身份 认证系统服务器 128任何一方进行, 例如, 用户在进行认证的途中觉 得网站有问题或根据自身的意愿,用户可以启用强制中止功能以结束 认证程序, 然后身份认证系统服务器会通知商户停止对用户的服务, 以防受到钓鱼网或中间人欺骗, 这样能提供给用户更大的保护。 另一 方面, 验证装置 26或身份认证系统服务器 128在检测到恶意攻击或 系统不稳定的情况下可自动启用强制中止功能,以防止数据外泄等情 况。 该强制中止功能由包含在移动设备 122、 验证装置 26和身份认 证系统服务器 128中的认证中止模块控制。 The various embodiments of the present invention have been described in detail above, but the application of the present invention is not limited to the embodiments in the specification, and the system configuration and structure are not limited to the above embodiments. In addition, modifications may be made to the construction of the system, or different functions may be added to make the system of the present invention more complete and convenient. For example, different existing or future encryption technologies may be added to the encryption code to prevent data leakage, and data encryption technologies such as SSL may be added to the embodiments to protect users. Also, after the user is authenticated by the identity authentication system server 128, the user can additionally set the login password and email notification, which increases the flexibility of use and further enhances the security. The next time the user connects to the identity authentication system server 128, In the automatic step performed by the identity authentication system server 128, the user must also enter his or her login password to obtain the identity confirmation of the system. When the identity authentication system server 128 detects an abnormal situation, such as the identity of the user may be stolen, the identity authentication system server 128 suspends the authentication process and automatically emails the user to remind the user that someone is using the authentication service, requesting the user Determine if it is his or her own, otherwise the certification process cannot proceed. Furthermore, all of the embodiments described above may incorporate a forced suspension function that can be performed on either of the user's mobile device 122, the authentication device 26, or the identity authentication system server 128, for example, the user is on the way to authentication. If the website is faulty or according to its own wishes, the user can enable the forced suspension function to end the authentication process, and then the identity authentication system server will notify the merchant to stop the service to the user, in case of being spoofed by the phishing network or the intermediary, so that the user can be provided more Great protection. On the other hand, the verification device 26 or the identity authentication system server 128 is detecting a malicious attack or The forced abort function can be automatically enabled in case of unstable system to prevent data leakage and the like. The forced abort function is controlled by an authentication abort module included in mobile device 122, authentication device 26, and identity authentication system server 128.
因此,在介绍了几个实施例之后,本领域的技术人员可以认识到, 不同的改动、 另外的结构、 等同物, 都可以被使用而不会背离本发明 的本质。相应的, 以上的描述不应该被视为对如以下的权利要求所确 定的本发明范围的限制。 Having thus described several embodiments, those skilled in the art will recognize that various modifications, other structures, and equivalents can be used without departing from the spirit of the invention. Accordingly, the above description should not be taken as limiting the scope of the invention as defined by the following claims.
Claims
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN2012103153813A CN102915604A (en) | 2012-08-31 | 2012-08-31 | Mobile payment system based on two-dimensional code and telecommunication service provider |
| CN201210315381.3 | 2012-08-31 | ||
| CN201310027672.7 | 2013-01-25 | ||
| CN201310027672.7A CN103138935B (en) | 2013-01-25 | 2013-01-25 | An Identity Authentication System Based on Telecom Operators |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014032549A1 true WO2014032549A1 (en) | 2014-03-06 |
Family
ID=50182494
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/082198 Ceased WO2014032549A1 (en) | 2012-08-31 | 2013-08-23 | Telecommunication service provider based mobile identity authentication and payment method and system |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2014032549A1 (en) |
Cited By (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104158668A (en) * | 2014-09-09 | 2014-11-19 | 北京数字认证股份有限公司 | Method and system for realizing electronic signature |
| CN105678540A (en) * | 2016-02-04 | 2016-06-15 | 腾讯科技(深圳)有限公司 | Payment processing method and device, and intelligent equipment |
| TWI640885B (en) * | 2014-05-30 | 2018-11-11 | 阿里巴巴集團服務有限公司 | Data uniqueness control method, information storage method and device |
| CN109460999A (en) * | 2018-09-28 | 2019-03-12 | 珠海横琴现联盛科技发展有限公司 | Payment information method based on optical character identification |
| CN111144531A (en) * | 2019-12-10 | 2020-05-12 | 深圳左邻永佳科技有限公司 | Two-dimensional code generation method and device, electronic device, computer-readable storage medium |
| CN111160892A (en) * | 2020-02-19 | 2020-05-15 | 青海集睿信息技术有限公司 | Customized payment method triggered by telephone dialing behavior |
| EP3579495A4 (en) * | 2017-02-01 | 2020-06-03 | Chan, Tai Chiu | Authentication server, authentication system, and authentication method |
| US10949869B1 (en) * | 2018-06-25 | 2021-03-16 | Sprint Communications Company L.P. | Method for generating and using a 2D barcode |
| US20210266312A1 (en) * | 2014-10-25 | 2021-08-26 | Seung Eun Hong | System and method for mobile cross-authentication |
| WO2021188081A1 (en) * | 2020-03-20 | 2021-09-23 | Crenno Bi̇li̇şi̇m Hi̇zmetleri̇ Ar-Ge San. Ti̇c. Ltd. Şti̇ | Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area |
| US11877218B1 (en) | 2021-07-13 | 2024-01-16 | T-Mobile Usa, Inc. | Multi-factor authentication using biometric and subscriber data systems and methods |
| US12219350B2 (en) | 2022-03-03 | 2025-02-04 | T-Mobile Usa, Inc. | Enabling peer-to-peer authentication between at least two mobile devices associated with one or more wireless telecommunication networks |
Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090061831A1 (en) * | 2007-08-31 | 2009-03-05 | Vishwanath Shastry | Mobile remittances/payments |
| WO2011021868A2 (en) * | 2009-08-21 | 2011-02-24 | 주식회사 디에이치씨 | Mobile card/account transaction system and transaction method employing the same |
| US20110270758A1 (en) * | 2010-08-08 | 2011-11-03 | Ali Mizani Oskui | Method for providing electronic transaction using mobile phones |
| EP2424282A1 (en) * | 2009-04-20 | 2012-02-29 | Alter Core, S.L. | System and method for personal certification using a mobile device |
| CN102457842A (en) * | 2010-10-22 | 2012-05-16 | 中国移动通信集团宁夏有限公司 | Mobile phone transaction method, device and system |
| CN102457514A (en) * | 2011-05-31 | 2012-05-16 | 高儒振 | Short message identity authentication method for wireless network of mobile terminal |
| WO2012072022A1 (en) * | 2010-11-30 | 2012-06-07 | 中国银联股份有限公司 | Remote payment method |
| CN102546165A (en) * | 2010-12-31 | 2012-07-04 | 中国银联股份有限公司 | Dynamic uniform resource locator (URL) generator, generation method, dynamic-URL-based authentication system and method |
| CN102542503A (en) * | 2010-12-09 | 2012-07-04 | 同方股份有限公司 | System and method for realizing bank security transaction by mobile communication terminal |
| CN102915604A (en) * | 2012-08-31 | 2013-02-06 | 宝利数码有限公司 | Mobile payment system based on two-dimensional code and telecommunication service provider |
| CN103116844A (en) * | 2013-03-06 | 2013-05-22 | 李锦风 | Near field communication payment method authenticated by both sides of deal |
| CN103138935A (en) * | 2013-01-25 | 2013-06-05 | 宝利数码有限公司 | Identity authentication system based on telecom operator |
-
2013
- 2013-08-23 WO PCT/CN2013/082198 patent/WO2014032549A1/en not_active Ceased
Patent Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090061831A1 (en) * | 2007-08-31 | 2009-03-05 | Vishwanath Shastry | Mobile remittances/payments |
| EP2424282A1 (en) * | 2009-04-20 | 2012-02-29 | Alter Core, S.L. | System and method for personal certification using a mobile device |
| WO2011021868A2 (en) * | 2009-08-21 | 2011-02-24 | 주식회사 디에이치씨 | Mobile card/account transaction system and transaction method employing the same |
| US20110270758A1 (en) * | 2010-08-08 | 2011-11-03 | Ali Mizani Oskui | Method for providing electronic transaction using mobile phones |
| CN102457842A (en) * | 2010-10-22 | 2012-05-16 | 中国移动通信集团宁夏有限公司 | Mobile phone transaction method, device and system |
| WO2012072022A1 (en) * | 2010-11-30 | 2012-06-07 | 中国银联股份有限公司 | Remote payment method |
| CN102542503A (en) * | 2010-12-09 | 2012-07-04 | 同方股份有限公司 | System and method for realizing bank security transaction by mobile communication terminal |
| CN102546165A (en) * | 2010-12-31 | 2012-07-04 | 中国银联股份有限公司 | Dynamic uniform resource locator (URL) generator, generation method, dynamic-URL-based authentication system and method |
| CN102457514A (en) * | 2011-05-31 | 2012-05-16 | 高儒振 | Short message identity authentication method for wireless network of mobile terminal |
| CN102915604A (en) * | 2012-08-31 | 2013-02-06 | 宝利数码有限公司 | Mobile payment system based on two-dimensional code and telecommunication service provider |
| CN103138935A (en) * | 2013-01-25 | 2013-06-05 | 宝利数码有限公司 | Identity authentication system based on telecom operator |
| CN103116844A (en) * | 2013-03-06 | 2013-05-22 | 李锦风 | Near field communication payment method authenticated by both sides of deal |
Cited By (17)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| TWI640885B (en) * | 2014-05-30 | 2018-11-11 | 阿里巴巴集團服務有限公司 | Data uniqueness control method, information storage method and device |
| CN104158668A (en) * | 2014-09-09 | 2014-11-19 | 北京数字认证股份有限公司 | Method and system for realizing electronic signature |
| US11966907B2 (en) * | 2014-10-25 | 2024-04-23 | Yoongnet Inc. | System and method for mobile cross-authentication |
| US20210266312A1 (en) * | 2014-10-25 | 2021-08-26 | Seung Eun Hong | System and method for mobile cross-authentication |
| US11341478B2 (en) | 2016-02-04 | 2022-05-24 | Tencent Technology (Shenzhen) Company Limited | Payment processing method and apparatus, and intelligent device |
| CN105678540A (en) * | 2016-02-04 | 2016-06-15 | 腾讯科技(深圳)有限公司 | Payment processing method and device, and intelligent equipment |
| EP3579495A4 (en) * | 2017-02-01 | 2020-06-03 | Chan, Tai Chiu | Authentication server, authentication system, and authentication method |
| US10949869B1 (en) * | 2018-06-25 | 2021-03-16 | Sprint Communications Company L.P. | Method for generating and using a 2D barcode |
| US11574332B1 (en) | 2018-06-25 | 2023-02-07 | Sprint Communications Company, L.P. | Method for generating and using a 2D barcode |
| CN109460999A (en) * | 2018-09-28 | 2019-03-12 | 珠海横琴现联盛科技发展有限公司 | Payment information method based on optical character identification |
| CN111144531A (en) * | 2019-12-10 | 2020-05-12 | 深圳左邻永佳科技有限公司 | Two-dimensional code generation method and device, electronic device, computer-readable storage medium |
| CN111144531B (en) * | 2019-12-10 | 2023-11-17 | 深圳左邻永佳科技有限公司 | Two-dimensional code generation method and device, electronic equipment, computer-readable storage medium |
| CN111160892A (en) * | 2020-02-19 | 2020-05-15 | 青海集睿信息技术有限公司 | Customized payment method triggered by telephone dialing behavior |
| WO2021188081A1 (en) * | 2020-03-20 | 2021-09-23 | Crenno Bi̇li̇şi̇m Hi̇zmetleri̇ Ar-Ge San. Ti̇c. Ltd. Şti̇ | Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area |
| US11877218B1 (en) | 2021-07-13 | 2024-01-16 | T-Mobile Usa, Inc. | Multi-factor authentication using biometric and subscriber data systems and methods |
| US12245119B2 (en) | 2021-07-13 | 2025-03-04 | T-Mobile Usa, Inc. | Multi-factor authentication using biometric and subscriber data systems and methods |
| US12219350B2 (en) | 2022-03-03 | 2025-02-04 | T-Mobile Usa, Inc. | Enabling peer-to-peer authentication between at least two mobile devices associated with one or more wireless telecommunication networks |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111357025B (en) | Secure QR code service | |
| US11615414B2 (en) | Virtualization and secure processing of data | |
| WO2014032549A1 (en) | Telecommunication service provider based mobile identity authentication and payment method and system | |
| JP5275632B2 (en) | System and method for conversion between Internet-based and non-Internet-based transactions | |
| KR100860628B1 (en) | A mobile phone for wireless computing device authenticable transactions, a computer system and a method thereof | |
| US8934865B2 (en) | Authentication and verification services for third party vendors using mobile devices | |
| EP2701415A1 (en) | Mobile electronic device and use thereof for electronic transactions | |
| AU2019236733A1 (en) | Transaction Processing System and Method | |
| CN105260886B (en) | Payment processing method and device, NFC portable terminal and wearable terminal | |
| US20130275308A1 (en) | System for verifying electronic transactions | |
| US20120089521A1 (en) | Method and apparatus for billing purchases from a mobile phone application | |
| CN104169954A (en) | Systems and methods for secure offline payment transactions using portable computing devices | |
| US10460316B2 (en) | Two device authentication | |
| WO2015107442A1 (en) | Systems and methods for issuing mobile payment cards via a mobile communication network and internet-connected devices | |
| JP2013529327A (en) | A secure and sharable payment system using trusted personal devices | |
| JP6667498B2 (en) | Remote transaction system, method and POS terminal | |
| CN1922623A (en) | Wireless wallet | |
| KR20110107311A (en) | Payment service system and method using mobile network, and computer program therefor | |
| US20190156334A1 (en) | System and method for providing anonymous payments | |
| CN104077841A (en) | Method and system for mobile identity authentication and payment | |
| KR101346705B1 (en) | System for processing small payment | |
| KR20170029941A (en) | Payment service providing apparatus and method for supporting multiple authentication based on web, system and computer readable medium having computer program recorded thereon | |
| KR20120040181A (en) | Method for operating mobile gift certificate | |
| KR20180058008A (en) | Electronics settlement service by sns |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13834235 Country of ref document: EP Kind code of ref document: A1 |
|
| DPE1 | Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101) | ||
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13834235 Country of ref document: EP Kind code of ref document: A1 |