Movatterモバイル変換


[0]ホーム

URL:


CN102768744B - A kind of remote safe payment method and system - Google Patents

A kind of remote safe payment method and system
Download PDF

Info

Publication number
CN102768744B
CN102768744BCN201210147405.9ACN201210147405ACN102768744BCN 102768744 BCN102768744 BCN 102768744BCN 201210147405 ACN201210147405 ACN 201210147405ACN 102768744 BCN102768744 BCN 102768744B
Authority
CN
China
Prior art keywords
terminal
remote server
card
key
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201210147405.9A
Other languages
Chinese (zh)
Other versions
CN102768744A (en
Inventor
彭波涛
苏龙
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fujian Landi Commercial Equipment Co Ltd
Original Assignee
Fujian Landi Commercial Equipment Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fujian Landi Commercial Equipment Co LtdfiledCriticalFujian Landi Commercial Equipment Co Ltd
Priority to CN201210147405.9ApriorityCriticalpatent/CN102768744B/en
Publication of CN102768744ApublicationCriticalpatent/CN102768744A/en
Application grantedgrantedCritical
Publication of CN102768744BpublicationCriticalpatent/CN102768744B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Landscapes

Abstract

The present invention discloses a kind of remote safe payment method, comprises the following steps: provide the bank intelligent card that stores secure data; One terminal and a card reader are provided, smart card information is read by card reader, between bank intelligent card and remote server, authentication is carried out to user, and after passing through checking, between above-mentioned bank intelligent card and remote server, set up safe data link carry out online transaction.The present invention uses Web bank to provide a kind of safety prevention measure for user.

Description

A kind of remote safe payment method and system
Technical field
The present invention relates to E-Payment field, especially a kind of remote safe payment method and system.
Background technology
Along with the development of ecommerce, online transaction is more and more universal.In addition, along with the prices of smart mobile phone, its sales volume also grows with each passing day.This just makes the demand of being carried out online payment by mobile phone day by day obvious, and each big bank is also proposed respective Mobile banking.At present, the common mobile payment mode based on mobile phone has:
Mode 1: by local file certificate, provide safety certification to remote payment.
Mode 2: by note code, provide safety certification to remote payment.
Mode 3: mobile phone part being provided to USB-OTG interface, has had specific U-key to use.The safety of remote payment is ensured by this U-key.
The shortcoming of aforesaid way:
The shortcoming of mode 1 and mode 2: because smart mobile phone may by virus and hacker attacks, the document certificate in mode 1 and mode 2 or note code may be obtained by Malware, thus jeopardize safety of network trade
Mode 3 shortcoming: bank needs to issue U-key specially, this U-key is usually only for the online transaction of a bank.Which increase the operation cost of bank, also make user except bank card, also need to carry multiple U-key, very inconvenient in use.
Summary of the invention
For solving the problem, the present invention uses Web bank to provide a kind of safety prevention measure for user.
The concrete technological means that the present invention adopts is as follows: a kind of remote safe payment method, is characterized in that, comprises the following steps:
The bank intelligent card that one stores secure data is provided;
One terminal and a card reader are provided, smart card information is read by card reader, between bank intelligent card and remote server, authentication is carried out to user, and after passing through checking, between above-mentioned bank intelligent card and remote server, set up safe data link carry out online transaction.
Especially, described authentication comprises the following steps: described terminal reads the secure data of bank intelligent card, described remote server initiates a cipher key agreement process by the Internet to above-mentioned terminal, described terminal key is consulted successfully, return success to above-mentioned remote server, both sides carry out two-way authentication by this cipher key agreement process and produce a process key, this process key in subsequent communications process as the encryption key of described remote server and described terminal switch data, thus between described server and this bank intelligent card, form the data transmission link of a safety.
Especially, described terminal is mobile phone, and described remote server is Mobile banking's server.
Especially, described terminal is POS, and described remote server is POS server.
Especially, described terminal is mobile phone, and described remote server is online banking service device, and described mobile phone is communicated with described online banking service device by computer.
Especially, described bank intelligent card is provided with ISO7816 interface, and described card reader reads secure data in card by this interface.
Especially, described bank intelligent card is provided with the contactless communication interface meeting ISO14443 standard, and described card reader reads secure data in card by this interface.
Especially, described secure data comprises digital certificate and private key.
The present invention is a kind of telesecurity payment system also, it is characterized in that, comprising:
Bank intelligent card, in order to storage security data;
Card reader, in order to read above-mentioned secure data;
Terminal, is provided with client software, in order to carry out online transaction;
Described terminal reads smart card information by card reader, between bank intelligent card and remote server, authentication is carried out to user, and after by checking, between above-mentioned bank intelligent card and remote server, set up safe data link carry out online transaction.
Especially, described terminal is mobile phone, and described remote server is the ebanking server of bank.
Especially, described terminal is POS, and described remote server is POS server.
Especially, described terminal is mobile phone, and described remote server is online banking service device, and described mobile phone is communicated with described online banking service device by computer.
Especially, described bank intelligent card is provided with ISO7816 interface, and described card reader reads secure data in card by this interface.
Especially, described bank intelligent card is provided with the contactless communication interface meeting ISO14443 standard, and described card reader reads secure data in card by this interface.
Especially, described secure data comprises digital certificate and private key.
Beneficial effect of the present invention:
The present invention is on existing financial IC card basis, increase storage and the software interface of digital certificate, in order to verify user identity, ensure the safety of user's online transaction, the function of existing U shield can be realized, and IC-card process chip volume is little, and use the ISO7816 interface extensively existed, thus the present invention uses Web bank to provide a kind of safety prevention measure for user.
Accompanying drawing explanation
Fig. 1 is the structure chart of the bank intelligent card of the embodiment of the present invention;
Fig. 2 is a kind of remote safe payment method flow chart of the embodiment of the present invention;
Fig. 3 is the telesecurity payment system structure chart of the embodiment of the present invention;
Fig. 4 is authentication interaction figure between smart card of the present invention, Net silver client, server.
Embodiment
By describing technology contents of the present invention, structural feature in detail, realized object and effect, accompanying drawing is coordinated to be explained in detail below in conjunction with execution mode.
Referring to Fig. 1, is the structure chart of the bank intelligent card of the embodiment of the present invention.This bank intelligent card is on the fiscard IC-card basis of issuing to client in bank, increase security module, storage and the software interface of consumer digital certificate and private key is stored in security module, digital certificate and private key are referred to as secure data, and possessing logical encrypt calculation function, alternative USBKEY realizes the function of authenticating user identification.IC-card sheet compact, and each bank all can issue corresponding IC-card.In the present embodiment, bank IC card has ISO7816 interface, and card reader can read secure data in card by ISO7816 interface, also to wirelessly, can such as meet the contactless communication interface of ISO14443 standard, reads card internal information.
Please refer to Fig. 2, is a kind of remote safe payment method flow chart of the embodiment of the present invention.Wherein safe payment method comprises the following steps:
S1., the bank intelligent card that stores secure data is provided;
S2., one terminal and a card reader are provided, smart card information is read by card reader, between bank intelligent card and remote server, authentication is carried out to user, and after passing through checking, between above-mentioned bank intelligent card and remote server, set up safe data link carry out online transaction.
Wherein, authentication comprises the following steps: described terminal reads the secure data of bank intelligent card, described remote server initiates a cipher key agreement process by the Internet to above-mentioned terminal, described terminal key is consulted successfully, return success to above-mentioned remote server, both sides carry out two-way authentication by this cipher key agreement process and produce a process key, this process key in subsequent communications process as the encryption key of described remote server and described terminal switch data, thus between described server and this bank intelligent card, form the data transmission link of a safety.
In the present embodiment, terminal comprises mobile terminal, also comprises immobile terminal, comprises personal terminal, also comprises business terminal.Described mobile terminal comprises mobile phone, PAD, mobile PC etc., and the remote server of its correspondence is the ebanking server of bank; Described immobile terminal can make Desktop PC, and corresponding server is Web bank, and PC reads card internal information by card reader, logs in internet bank trade; Described business terminal can make commercial POS, and the server of its correspondence is POS server.
Wherein, described bank intelligent card is provided with ISO7816 interface, when described terminal does not have card-reading function, just can read secure data in card by card reader by this interface.Described bank intelligent card can also be provided with radio-frequency card near field communication interface, and card reader reads card internal information by adopting wireless mode such as wireless radio frequency mode.
Fig. 4 is authentication interaction figure between smart card of the present invention, Net silver client, server.This flow process is described for common Web bank's login process at this.Terminal is provided with Net silver client, needs use contact intelligent card to protect process of exchange.This smart card is equivalent to the effect of U-key, and Web bank is deposited for identifying digital certificate and the private key of client identity in the inside, and the processor of card inside can complete encryption and Digital Signature Algorithm.
In login process, mainly carry out mutual between smart card and system server (far end system).Client software is undertaken alternately by terminal, card reader and smart card, sends server command and receives response from smart card, thus completing login process.
Mutual in order to carry out, smart card and system server respectively have a digital certificate and corresponding private key.Certificate on smart card and private key are called client certificate and client private key, and on server, certificate and private key are called server certificate and privacy key.In addition, smart card and the server root certificate that has these certificates corresponding.
Smart card and remote server reciprocal process as follows:
1. client allows smart card produce 32 byte random numbers, add that some information package generate client handshaking information, here client is a kind of call relative to server, is on the whole treated by some row assemblies of client software, terminal, smart card, certificate etc. as one.From the angle of server, be exactly client with the object of server interaction;
2. client handshaking information is transferred to server by client;
3. server produces 32 byte random numbers, adds some information package, generation server handshaking information;
4. server handshaking information and server certificate are sent to client by server;
5. server certificate is sent to smart card by client, is verified the server certificate received by smart card, if the verification passes, then logins successfully; Otherwise login failure;
6. client uses smart card to carry out following process:
Produce the random number of 48 bytes as shared master key
PKI in this master key server certificate is encrypted, and generates encryption and shares master key
Client handshaking information and service end handshaking information are calculated handshaking information cryptographic Hash, is then encrypted by client private key, generate handshaking information digital signature;
7. client obtains encryption shared master key, handshaking information digital signature from smart card;
8. client certificate, the shared master key of encryption, handshaking information digital signature are sent to server by client;
9. server checks client certificate validity, if effectively, then shakes hands successfully; Otherwise shake hands unsuccessfully;
10. whether server uses the public key verifications handshaking information digital signature in client certificate to mate with client and service end handshaking information, if coupling, then shakes hands successfully; Otherwise shake hands unsuccessfully, return mistake;
11. servers use privacy key will be decrypted shared master key, draw shared master key;
12. both sides use shared master key to calculate session key.Subsequent communications process, all uses session key to be encrypted packet, namely establishes escape way, login successfully.
Please refer to Fig. 3, is the safety payment system structure chart of the embodiment of the present invention.Safety payment system comprises: bank intelligent card, in order to storage security data; Card reader, in order to read above-mentioned secure data; Terminal, is provided with client software, in order to carry out online transaction; Described terminal reads smart card information by card reader, between bank intelligent card and remote server, authentication is carried out to user, and after by checking, between above-mentioned bank intelligent card and remote server, set up safe data link carry out online transaction.Wherein, secure data comprises digital certificate and private key.In the present embodiment, for PC and online banking service device, described online banking service device holds initiation cipher key agreement process by the Internet to above-mentioned PC, after this PC holds key agreement success, return success to above-mentioned online banking service device, both sides carry out two-way authentication by this cipher key agreement process and produce a process key, this process key in subsequent communications process as the encryption key of this online banking service device and described terminal switch data, thus between this online banking service device and this smart card, form the data transmission link of a safety, follow-up transaction data transmits on this link.
The present invention is on existing financial IC card basis, increase storage and the software interface of digital certificate, in order to verify user identity, ensure the safety of user's online transaction, the function of existing U shield can be realized, and IC-card process chip volume is little, and use the ISO7816 interface extensively existed, with low cost, process technology is ripe, thus uses Web bank to provide the safeguard procedures of a kind of safety, low cost for user.
The foregoing is only embodiments of the invention; not thereby the scope of the claims of the present invention is limited; every utilize specification of the present invention and accompanying drawing content to do equivalent structure or equivalent flow process conversion; or be directly or indirectly used in other relevant technical fields, be all in like manner included in scope of patent protection of the present invention.

Claims (11)

CN201210147405.9A2012-05-112012-05-11A kind of remote safe payment method and systemActiveCN102768744B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201210147405.9ACN102768744B (en)2012-05-112012-05-11A kind of remote safe payment method and system

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201210147405.9ACN102768744B (en)2012-05-112012-05-11A kind of remote safe payment method and system

Publications (2)

Publication NumberPublication Date
CN102768744A CN102768744A (en)2012-11-07
CN102768744Btrue CN102768744B (en)2016-03-16

Family

ID=47096138

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201210147405.9AActiveCN102768744B (en)2012-05-112012-05-11A kind of remote safe payment method and system

Country Status (1)

CountryLink
CN (1)CN102768744B (en)

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103116843A (en)*2012-12-182013-05-22福建联迪商用设备有限公司Electronic payment method and device thereof and peripheral device of electronic payment
CN103905388A (en)*2012-12-262014-07-02中国移动通信集团广东有限公司Authentication method, authentication device, smart card, and server
CN103714638B (en)*2013-03-152015-09-30福建联迪商用设备有限公司A kind of method and system of quick position terminal master key failed download
CN103237004A (en)*2013-03-152013-08-07福建联迪商用设备有限公司Key download method, key management method, method, device and system for download management
CN103617532A (en)*2013-12-162014-03-05杭州信雅达科技有限公司Offline payment and collection method and device for mobile terminals
CN105023154A (en)*2014-04-212015-11-04航天信息股份有限公司Electronic paying method and apparatus based on multifunctional financial IC cards
CN105515773B (en)*2014-09-262018-12-07杭州华为数字技术有限公司Portable device, user equipment and data interactive method
CN105528537A (en)*2014-09-292016-04-27联芯科技有限公司Portable wireless broad-band apparatus and safety protection method thereof
CN104410968A (en)*2014-11-182015-03-11王家城Portable universal integrated circuit card (UICC) subscriber terminal equipment and identity authentication system thereof
CN104915689B (en)*2015-04-152017-10-31四川量迅科技有限公司A kind of smart card information processing method
CN105138892A (en)*2015-08-062015-12-09深圳市文鼎创数据科技有限公司Data interaction method and apparatus applied to composite smart card device
CN108256855A (en)*2016-12-292018-07-06夏飞A kind of cross-border electric business utilizes long-distance intelligent card method of payment
CN108416952B (en)*2018-03-092020-07-24上海商米科技集团股份有限公司Alarm relieving method of POS terminal, server and system applying alarm relieving method
CN108600218B (en)*2018-04-232020-12-29捷德(中国)科技有限公司Remote authorization system and remote authorization method
CN108681909B (en)*2018-05-182021-09-24浙江超脑时空科技有限公司Intelligent anti-counterfeiting device and source tracing anti-counterfeiting method based on block chain intelligent contract
CN109816379B (en)*2019-01-152022-02-22重庆乔松信息技术有限公司Network payment system for directly reading and writing IC card by mobile phone
CN109858295B (en)*2019-01-152022-02-01重庆乔松信息技术有限公司Network payment method for directly reading and writing IC card by mobile phone

Citations (2)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN101394615A (en)*2007-09-202009-03-25中国银联股份有限公司 A mobile payment terminal and payment method based on PKI technology
CN102006275A (en)*2010-07-212011-04-06恒宝股份有限公司System and method for financial IC (Integrated Circuit) card transaction

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
JP4729839B2 (en)*2003-05-202011-07-20株式会社日立製作所 IC card
CN1921682B (en)*2005-08-262010-04-21华为技术有限公司 Enhancing the key agreement method in the general authentication framework
WO2007135619A2 (en)*2006-05-222007-11-29Nxp B.V.Secure internet transaction method and apparatus
CN101458853A (en)*2007-12-112009-06-17结行信息技术(上海)有限公司On-line POS system and smart card on-line payment method

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN101394615A (en)*2007-09-202009-03-25中国银联股份有限公司 A mobile payment terminal and payment method based on PKI technology
CN102006275A (en)*2010-07-212011-04-06恒宝股份有限公司System and method for financial IC (Integrated Circuit) card transaction

Also Published As

Publication numberPublication date
CN102768744A (en)2012-11-07

Similar Documents

PublicationPublication DateTitle
CN102768744B (en)A kind of remote safe payment method and system
US11258777B2 (en)Method for carrying out a two-factor authentication
CN102737311B (en)Internet bank security authentication method and system
JP6701431B2 (en) Establishing a secure channel
YangSecurity Enhanced EMV‐Based Mobile Payment Protocol
JP7595001B2 (en) System and method for cryptographic authentication of contactless cards - Patents.com
US20160117673A1 (en)System and method for secured transactions using mobile devices
JP6092415B2 (en) Fingerprint authentication system and fingerprint authentication method based on NFC
JP7594999B2 (en) System and method for cryptographic authentication of contactless cards - Patents.com
CN107784499B (en)Secure payment system and method of near field communication mobile terminal
US20130226812A1 (en)Cloud proxy secured mobile payments
US20150142666A1 (en)Authentication service
CN101334884B (en)Improve the method and system of account transfer safety
JP2016537887A (en) System and method for securing communication between a card reader device and a remote server
CN102710611A (en)Network security authentication method and system
CN103123708A (en)Secure payment method, mobile device and secure payment system
US20150142669A1 (en)Virtual payment chipcard service
CN104217327A (en)Financial IC (integrated circuit) card Internet terminal and trading method thereof
CN101770619A (en)Multiple-factor authentication method for online payment and authentication system
JP2025011229A (en) System and method for cryptographic authentication of contactless cards - Patents.com
US20150142667A1 (en)Payment authorization system
JP2016528613A (en) How to secure the online transaction verification step
CN102147662A (en)Input terminal with keyboard and encryption module
JP2025016511A (en) System and method for notifying potential attacks on contactless cards - Patents.com
KR101499906B1 (en)Smart card having OTP generation function and OTP authentication server

Legal Events

DateCodeTitleDescription
C06Publication
PB01Publication
C10Entry into substantive examination
SE01Entry into force of request for substantive examination
C14Grant of patent or utility model
GR01Patent grant

[8]ページ先頭

©2009-2025 Movatter.jp