[go: up one dir, main page]

WO2018149367A1 - Procédé et système de paiement de transaction - Google Patents

Procédé et système de paiement de transaction Download PDF

Info

Publication number
WO2018149367A1
WO2018149367A1 PCT/CN2018/075998 CN2018075998W WO2018149367A1 WO 2018149367 A1 WO2018149367 A1 WO 2018149367A1 CN 2018075998 W CN2018075998 W CN 2018075998W WO 2018149367 A1 WO2018149367 A1 WO 2018149367A1
Authority
WO
WIPO (PCT)
Prior art keywords
ciphertext
biometric
code
transaction
smart terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/075998
Other languages
English (en)
Chinese (zh)
Inventor
孙权
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Publication of WO2018149367A1 publication Critical patent/WO2018149367A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3274Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks

Definitions

  • the present invention relates to the field of electronic commerce technology, and more particularly to a transaction payment method and system.
  • Two-dimensional code scan code payment can be divided into two modes: main scan and swept mode.
  • the sweep mode is widely used in WeChat payment and Alipay.
  • the client application of the mobile terminal encodes the user account information into a two-dimensional code.
  • the barcode the cashier terminal scan code to determine the user account information to complete the payment transaction.
  • QR code information/barcode is easily copied, which leads to leakage of user account information, thereby posing a risk of fraudulent use and misappropriation.
  • the QR code/barcode does not simply display the account information/transaction information in plain text, but there is still a risk of being easily broken, giving the criminals a chance.
  • the present invention provides a technical solution as follows:
  • a transaction payment method comprising: a registration phase, comprising the steps of: the biometric authentication server acquires a biometric of the registered user from the smart terminal based on the registration request of the smart terminal, and the transaction payment server sends the public key to the smart terminal based on the registration request;
  • the biometric feature is obtained by collecting the biometrics collection device of the smart terminal; and the transaction phase includes the following steps: the smart terminal collects the biometric characteristics of the current user, and generates the first ciphertext based on at least the public key and the biometric characteristics of the current user.
  • the intelligent terminal generates a Hanxin code based on the first ciphertext, generates a two-dimensional code based on the user information of the current user, and displays the Hanxin code and the two-dimensional code for scanning and recognizing the cash register terminal;
  • the transaction payment server obtains the cash register from the cash register terminal.
  • the first ciphertext and the user information scanned and identified by the terminal, and decrypting the first ciphertext by using the private key to obtain the biometric feature of the current user and forwarding to the biometric authentication server; and the transaction payment server is based on the biometric authentication server Current user's biometric authentication And user information to complete the transaction.
  • the Hanxin code and the two-dimensional code are respectively displayed on different parts of the screen or display window of the smart terminal.
  • the Hanxin code is displayed on the central portion of the screen or display window, and the two-dimensional code is displayed on the peripheral portion of the screen or display window.
  • the Hanxin code and the two-dimensional code are displayed synchronously.
  • the smart terminal is further based on the time code of the current time when generating the first ciphertext.
  • the smart terminal performs a hash algorithm on the current user's biometrics to obtain a digest, and encrypts the digest with the public key to generate a first ciphertext.
  • the invention also discloses a transaction payment system, comprising: a transaction execution unit, communicatively coupled with at least one intelligent terminal, comprising: a biometric authentication server for authenticating biometrics of the current user; and a transaction payment server
  • a transaction execution unit communicatively coupled with at least one intelligent terminal, comprising: a biometric authentication server for authenticating biometrics of the current user; and a transaction payment server
  • the cash register terminal acquires the first ciphertext and the user information of the current user, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user and forwards the biometric to the biometric authentication server, and the transaction payment server is further based on the biometric authentication server.
  • the authentication result is completed to complete the transaction; at least one cash register terminal, the cash register terminal scans and identifies the Hanxin code and the two-dimensional code displayed by the smart terminal; and at least one smart terminal, the intelligent terminal includes a biometrics collection device, and the smart terminal is based at least on the transaction payment
  • the first ciphertext is generated by the public key delivered by the server and the biometric feature of the current user, and the Chinese cipher code is generated based on the first ciphertext, and the two-dimensional code is generated based on the user information.
  • the transaction payment method and system provided by the invention can effectively prevent the information such as the QR code/barcode from being copied, thereby bringing security risks to the user account and realizing the biometric information of the user while realizing the electronic transaction in a simple manner.
  • the authentication is implemented to prevent the criminals from stealing the user's smart terminal.
  • the transaction payment system can realize more secure electronic transactions, protect user account security, and bring a good user experience.
  • FIG. 1 is a schematic flowchart diagram of a transaction payment method according to a first embodiment of the present invention.
  • FIG. 2 is a block diagram showing a transaction payment system provided by a second embodiment of the present invention.
  • a first embodiment of the present invention provides a transaction payment method, which is implemented by a smart terminal generating a two-dimensional code for scanning by a cashier terminal.
  • the method includes two phases: a registration phase and a transaction phase.
  • the registration phase includes the step S10: the biometric authentication server acquires the biometric of the registered user based on the registration request of the smart terminal, and the transaction payment server delivers the public key to the smart terminal based on the registration request.
  • the biometrics are obtained by collecting biometrics collection devices of the intelligent terminal.
  • the user who wants to register submits a registration request to the biometric authentication server through the smart terminal, and the biometric authentication server instructs the smart terminal to collect the biometric characteristics of the registered user, and the biometric feature is uploaded to the biometric authentication server after the smart terminal collects, and the biometric feature is collected.
  • the authentication server saves the biometric of the registered user and instructs the transaction payment server to deliver the public key to the smart terminal.
  • the registration phase only needs to be performed once, and the transaction phase can be performed as many times as many times.
  • transaction phase information exchange occurs between the intelligent terminal and the cashier terminal through scanning, and the cash register terminal and the transaction payment server interact with each other through network communication, and the transaction phase specifically includes the following steps.
  • Step S11 The smart terminal collects biometric features of the current user, and generates a first ciphertext based on at least the public key and the biometric characteristics of the current user.
  • the smart terminal after collecting the biometrics of the current user, the smart terminal performs a hash algorithm on the biometrics of the current user to obtain a digest, and encrypts the digest by using the public key sent by the transaction payment server in the registration phase to generate the first A ciphertext.
  • the smart terminal may also be based on the time code of the current time when generating the first ciphertext. Further, in the subsequent step, the transaction payment server can judge the timeliness of the transaction by using the time code, which can also increase the security of the transaction.
  • the smart terminal can also combine the device ID of the mobile terminal when generating the first ciphertext.
  • the device ID of the mobile terminal is not replaceable.
  • it can be beneficial to increase the security of user information (such as an account).
  • Step S12 The intelligent terminal generates a Hanxin code based on the first ciphertext, generates a two-dimensional code based on the user information of the current user, and displays the Hanxin code and the two-dimensional code for scanning and identifying by the cash register terminal.
  • the Hanxin code and the two-dimensional code can be respectively displayed on different parts of the screen or display window of the smart terminal.
  • the Hanxin code is displayed in the central part of the screen or the display window, and the two-dimensional code is displayed on the peripheral part of the screen or the display window; or, the Hanxin code is displayed on the left part, and the two-dimensional code is displayed on the right part.
  • the smart terminal when the smart terminal displays the Hanxin code and the two-dimensional code, the smart terminal can be scaled, and the two can be displayed in different time sequences.
  • the two-dimensional code surrounds the Hanxin code, and the two are synchronously displayed in the display window of the smart terminal for scanning and identification by the cash register terminal.
  • Step S13 The transaction payment server acquires the first ciphertext and the user information scanned and identified by the cash register terminal, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user.
  • the transaction payment server decrypts the first ciphertext by using the private key to obtain the current user. Biological characteristics. In this process, although the cashier terminal obtains the first ciphertext, the first ciphertext cannot be parsed or saved. The transaction payment server then forwards the current user's biometrics to the biometric authentication server.
  • Step S14 The transaction payment server completes the transaction based on the result of the biometric authentication of the current user and the user information by the biometric authentication server.
  • the biometric authentication server first authenticates the biometrics of the current user, and notifies the transaction payment server of the authentication result, and the transaction payment server completes the transaction based on the authentication result and the user information.
  • the biometric authentication server will give a negative authentication result, and the transaction payment server will reject the current transaction; otherwise, the biometric authentication server will give With a positive certification result, the transaction payment server will continue the current transaction and realize the circulation of funds.
  • the transaction payment method can effectively prevent information such as a two-dimensional code/barcode from being copied while realizing electronic transactions in a simple manner, and can also authenticate biometric information of the user. These measures help to improve the security of electronic transactions and effectively protect user accounts from misappropriation.
  • a second embodiment of the present invention provides a transaction payment system including a transaction execution unit 20, a plurality of cashier terminals 21 (only one is shown in the drawings for simplicity), and a plurality of smart terminals 22 (for simplicity, attached) Only one is shown in the figure, as shown in Figure 2.
  • the transaction execution unit 20 and the plurality of smart terminals 22 can communicate using the mobile communication network, and the transaction execution unit 20 and the plurality of cashier terminals 21 can communicate using the Internet (for example, the Internet).
  • the Internet for example, the Internet
  • the transaction execution unit 20 includes a biometric authentication server 201 and a transaction payment server 202.
  • the smart terminal 22 includes a biometrics collection device for collecting biometric features of the user, such as fingerprints, irises, voice prints, facial images, and the like.
  • the smart terminal 22 generates the first ciphertext based on at least the public key sent by the transaction payment server 202 during the user registration phase and the biometric feature of the current user, and generates a Chinese cryptographic code based on the first ciphertext and generates two based on the user information.
  • the code is displayed, and the Hanxin code and the two-dimensional code are displayed for scanning and recognition by the cash register terminal 21.
  • the cash register terminal 21 includes a scanning device to scan and recognize the Hanxin code and the two-dimensional code displayed by the smart terminal 22.
  • the transaction payment server 202 acquires the first ciphertext and the user information of the current user from the cash register terminal 21, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user and forwards the biometric to the biometric authentication server 201.
  • the transaction payment server 202 also completes the transaction based on the authentication result of the biometric authentication server 201.
  • the smart terminal 22 can display the Hanxin code and the two-dimensional code on different parts of the screen or the display window, respectively.
  • the smart terminal 22 displays the Hanxin code on the central portion of the screen or the display window, and displays the two-dimensional code on the peripheral portion of the screen or the display window. Further, the smart terminal 22 preferably simultaneously displays the Hanxin code and the two-dimensional code.
  • the transaction execution unit 20 is disposed at the financial institution end (local end), and the cash register terminal 21 is disposed at the remote end.
  • the above transaction payment system can be deployed based on a cloud computing system to facilitate system upgrade and maintenance.
  • the transaction payment system has low implementation cost and is convenient for popularization and application.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

La présente invention concerne un procédé de paiement de transaction. Le procédé comprend : une étape d'inscription comprenant les étapes suivantes : un serveur d'authentification de caractéristique biométrique obtient, en fonction d'une demande d'inscription d'un terminal intelligent, une caractéristique biométrique d'un utilisateur inscrit, et un serveur de paiement de transaction émet une clé publique pour le terminal intelligent ; et une étape de transaction comprenant les étapes suivantes : le terminal intelligent produit, au moins en fonction de la clé publique et de la caractéristique biométrique de l'utilisateur actuel, un premier texte chiffré ; le terminal intelligent produit, en fonction du premier texte chiffré, un code de Han Xin, et produit, en fonction d'informations d'utilisateur de l'utilisateur actuel, un code bidimensionnel ; le serveur de paiement de transaction obtient le premier texte chiffré et les informations d'utilisateur lues et reconnues par un terminal de caissier, et déchiffre le premier texte chiffré en utilisant une clé privée pour obtenir la caractéristique biométrique de l'utilisateur actuel ; et le serveur de paiement de transaction termine une transaction en utilisant les informations d'utilisateur et un résultat d'authentification du serveur d'authentification de caractéristique biométrique se rapportant à la caractéristique biométrique de l'utilisateur actuel. La présente invention peut réaliser des transactions électroniques plus sécurisées et protéger la sécurité d'un compte d'utilisateur.
PCT/CN2018/075998 2017-02-15 2018-02-09 Procédé et système de paiement de transaction Ceased WO2018149367A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710080394.XA CN107146079B (zh) 2017-02-15 2017-02-15 交易支付方法及系统
CN201710080394.X 2017-02-15

Publications (1)

Publication Number Publication Date
WO2018149367A1 true WO2018149367A1 (fr) 2018-08-23

Family

ID=59783347

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/075998 Ceased WO2018149367A1 (fr) 2017-02-15 2018-02-09 Procédé et système de paiement de transaction

Country Status (3)

Country Link
CN (1) CN107146079B (fr)
TW (1) TWI720287B (fr)
WO (1) WO2018149367A1 (fr)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107146079B (zh) * 2017-02-15 2020-05-22 中国银联股份有限公司 交易支付方法及系统
CN108038529B (zh) * 2017-12-08 2020-10-09 北京中星仝创科技有限公司 一种带图像的圆形二维码生成及读取的方法
CN115189898B (zh) * 2021-04-01 2024-05-24 富联精密电子(天津)有限公司 交易处理方法、终端及存储介质
CN116629887A (zh) * 2023-07-20 2023-08-22 鼎铉商用密码测评技术(深圳)有限公司 基于生物特征的注册方法、认证方法、装置及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130275309A1 (en) * 2012-04-13 2013-10-17 Francis King Hei KWONG Electronic-payment authentication process with an eye-positioning method for unlocking a pattern lock
CN103489102A (zh) * 2013-09-13 2014-01-01 惠州Tcl移动通信有限公司 一种基于二维码通过手机实现信用卡防盗刷的方法及系统
CN104835039A (zh) * 2015-04-03 2015-08-12 成都爱维科创科技有限公司 一种数据标签生成方法
CN105590199A (zh) * 2014-11-14 2016-05-18 中国银联股份有限公司 一种基于动态二维码的支付方法以及支付系统
CN107146079A (zh) * 2017-02-15 2017-09-08 中国银联股份有限公司 交易支付方法及系统

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102254380A (zh) * 2010-05-31 2011-11-23 北京汇冠金财科技有限公司 基于混合加密机制的手机安全支付方法及系统
CN104486356A (zh) * 2014-12-29 2015-04-01 芜湖乐锐思信息咨询有限公司 基于互联网在线交易的数据传输方法
CN104835030A (zh) * 2015-05-26 2015-08-12 丹阳飓风物流股份有限公司 一种用于物流行业的询价业务流程管理方法
CN106296197A (zh) * 2015-06-25 2017-01-04 深圳市中兴微电子技术有限公司 一种支付的方法、设备和系统
CN105631501A (zh) * 2015-11-24 2016-06-01 上海透云物联网科技有限公司 复合识别码结构、使用复合识别码结构的产品及监控方法
CN105574743A (zh) * 2016-01-18 2016-05-11 上海透云物联网科技有限公司 识别码结构及制作方法及产品监控方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130275309A1 (en) * 2012-04-13 2013-10-17 Francis King Hei KWONG Electronic-payment authentication process with an eye-positioning method for unlocking a pattern lock
CN103489102A (zh) * 2013-09-13 2014-01-01 惠州Tcl移动通信有限公司 一种基于二维码通过手机实现信用卡防盗刷的方法及系统
CN105590199A (zh) * 2014-11-14 2016-05-18 中国银联股份有限公司 一种基于动态二维码的支付方法以及支付系统
CN104835039A (zh) * 2015-04-03 2015-08-12 成都爱维科创科技有限公司 一种数据标签生成方法
CN107146079A (zh) * 2017-02-15 2017-09-08 中国银联股份有限公司 交易支付方法及系统

Also Published As

Publication number Publication date
TWI720287B (zh) 2021-03-01
CN107146079A (zh) 2017-09-08
CN107146079B (zh) 2020-05-22
TW201832153A (zh) 2018-09-01

Similar Documents

Publication Publication Date Title
US11847652B2 (en) Wireless biometric authentication system and method
US11777736B2 (en) Use of biometrics and privacy preserving methods to authenticate account holders online
US8775814B2 (en) Personalized biometric identification and non-repudiation system
CN108460593B (zh) 一种离线二维码支付方法及装置
CN114358793A (zh) 基于服务器的生物测定认证
US11451394B2 (en) Efficient hands free interaction using biometrics
US11783336B2 (en) Camera device enabled identification and disambiguation system and method
CN105809447A (zh) 基于人脸识别和hce的支付认证方法及认证系统
WO2018094584A1 (fr) Système de paiement et d'authentification d'identité basé sur la reconnaissance de caractéristiques biométriques
CN102314731A (zh) 移动支付方法和用于实现该移动支付方法的设备
WO2018149367A1 (fr) Procédé et système de paiement de transaction
US20240380597A1 (en) Remote identity interaction
WO2016083987A1 (fr) Procédé et système pour obtenir la preuve de l'autorisation d'une transaction
EP3718035A1 (fr) Mise en correspondance centrale en deux étapes d'empreintes digitales
WO2018148900A1 (fr) Procédé et dispositif d'authentification basée sur une identification d'empreintes digitales, et système d'opérations
CN111353144A (zh) 一种身份认证的方法和装置
HK1242453B (zh) 交易支付方法及系统
KR102079667B1 (ko) 금융 거래 서비스 제공 시스템
HK1242453A (en) Transaction payment method and system
HK1242453A1 (en) Transaction payment method and system
TW202347148A (zh) 基於生物辨識認證裝置及其方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18753638

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18753638

Country of ref document: EP

Kind code of ref document: A1