Summary of the invention
The invention provides a kind of method that mobile phone is finished identification and near field payment of passing through of safe ready.
In the following description, the meaning of the related English alphabet of respectively abridging is respectively:MSISDNEnglishMobile Subscriber International ISDN/PSTN numberAbbreviation, i.e. mobile subscriber number;IPEnglishInternet ProtocolAbbreviation, the agreement that namely interconnects between the network; GGSN is the abbreviation of English Gateway GPRS Support Node, and namely Gateway GPRS Support Node is also referred to as internet gateway, has the functions such as access route, forwarding of packets, IP address assignment, user authenticate;WAPEnglishWireless Application ProtocolAbbreviation, be WAP (wireless application protocol), be a global network communication protocol.
For achieving the above object, technical scheme of the present invention is:
The method of a kind of identification of mobile phone and near field payment has been utilized mobile phone and Mobile phone card thereof and phone number, it is characterized in that may further comprise the steps:
(1) by the MSISDN information in the checking communications protocol, guarantees identifiability and unique legitimacy of Mobile phone card or phone number;
(2) application developers is set up intermediate database, and Mobile phone card or phone number and application data are bundled, and finishes one to one, one-to-many, many-to-one binding, sensitive information is translated to the form of not divulging a secret safely such as the card account, realizes the identity of application data and cellphone subscriber's corresponding relation;
(3) mobile phone is installed corresponding software, sends authentication request, compares by the identity data of retrieval intermediate database, realizes online authentication.
Further, also comprise the step of mobile phone near field payment: banking system is carried out authentication by the real-time online mode, after checking, finishes the near field payment transaction by cellphone subscriber's request.
In addition, also comprise the step of gate inhibition's identification: the gate control system of property is carried out identification by the real-time online mode, finishes cellphone subscriber's switch gate request after the identification.
Described application data comprises Bank Account Number, authentication account or owner's account, and for safety, account is translated to encryption format.
Above-mentioned step (2) realizes by following substep:
Behind the internet gateway GGSN of common carrier, set up authentication server, be responsible for processing ID authentication request;
Authentication serverIPThe address is added the access white list of common carrier internet gateway GGSN to;
Behind the internet gateway GGSN and authentication server of common carrier, set up application server, be responsible for Business Processing and related management;
Application server by the service management module, when service fulfillment, is set up the subscriber identity information through confirming;
Application server by the service management module, produces up-to-date subscriber identity information and Mobile phone card or phone number corresponding relation in authentication server.
Above-mentioned step (3) realizes by following substep:
Mobile phone is installed specific software;
The cellphone subscriber opens the switch of data communication, and sends ID authentication request to internet gateway GGSN;
When internet gateway GGSN received ID authentication request, the MSISDN information the access authentication of user system was inserted in the communications protocol, together with authentication request, is submitted to authentication server;
Authentication server extracts MSISDN information after request is deciphered, and corresponds to the identity information of user through confirming, and returns corresponding authentication result by its service authority, thereby has realized the authentication to the user.
Further, described near field payment step realizes by following substep:
On the basis based on identification, in banking system, increase the payment transaction server, be connected with banking system with intermediate database respectively; The payment transaction server is responsible for trading activity, the trading privilege of receiving, paying both sides are managed, and submits the payment request to banking system;
During the transaction beginning, by the corresponding software of installing in the mobile phone and application server communication, application server is pressed the corresponding relation of intermediate database, respectively both parties is carried out authentication;
The payment transaction both sides are by the input of a side wherein payment;
Corresponding software in the mobile phone confirms that by bluetooth communication or the camera scan module of control mobile phone payment the other side is really near field range;
Both parties confirm payment, submit to respectively transaction request to arrive the payment transaction server;
The information such as trading server realization affirmation both parties' authority, amount;
Trading server is submitted the payment request to banking system;
Return results after the bank paying operation is finished, the trading server record is also notified the user operating result.
Further, described door control identity authentication step realizes by following substep:
In the main control system of gate control system, increase a mobile phone that is used for access control, be connected with gate inhibition's main frame with intermediate database respectively;
On the basis based on authentication, the legal validity of user profile is fed back authentication result to gate inhibition's mobile phone terminal;
Gate inhibition's mobile phone is realized the switch motion of opposite house by the equipment of gate inhibition's host driven gate control system after the passenger carries out authentication.
The present invention takes full advantage of Mobile phone card and possesses uniqueness, safety encipher, identification, the characteristics such as communication capacity, by wireless telecommunications operator with bank card or access card and Mobile phone card or phone number binding, do not changing mobile phone hardware, do not change Mobile phone card, to realizing one to one in the situation of the additional any identification apparatus of mobile phone, one-to-many, the binding of many-to-one bank card or access card and user identity and user right, realize user's identity naturally extending to mobile phone of bank card or access card, thereby realize near field mobile-phone payment and identity authentication function, this method is safe, simple operation greatly facilitates people's work and life.
Embodiment
Below the invention will be further described:
This method is to utilize the uniqueness of Mobile phone card to finish identification and near field payment, and operating procedure comprises:
(1) by the MSISDN information in the communications protocol of checking common carrier, guarantees identifiability and unique legitimacy of Mobile phone card or phone number.
(2) application developers is set up intermediate database, and Mobile phone card or phone number and application data are bundled, finish one to one, and one-to-many, many-to-one binding realizes the identity of application data and cellphone subscriber's corresponding relation.
Application developers will realize above function, need proceed as follows step: 1. after the internet gateway of operator, set up authentication server, be responsible for processing authentication request; 2. authentication serverIPThe address is added the access white list of operator's internet gateway to; 3. after the internet gateway of operator, set up application server, be responsible for Business Processing and related management; 4. application server by the service management module, when service fulfillment, is set up the subscriber identity information through confirming, wherein, the service management module comprises importing, increase, deletion, revises; 5. application server by the service management module, produces up-to-date subscriber identity information and phone number corresponding relation in authentication server.
(3) mobile phone is installed corresponding software, sends authentication request, compares by the identity data of retrieval intermediate database, realizes online authentication.The operating procedure of authentication comprises: 1. mobile phone is installed corresponding software; 2. the cellphone subscriber opens the switch of data communication and sends request; When 3. internet gateway was received user's authentication request, the MSISDN information the access authentication of user system was inserted in the communications protocol,, together with the checking request, be submitted to authentication server; 4. after authentication server is deciphered request, extract MSISDN information, correspond to the identity information of user through confirming, and return corresponding the result by its service authority, thereby realized the authentication to the user.
On the basis based on above authentication, mobile phone can be finished the function of near field payment and identification, below enumerates two kinds of embodiment:
Embodiment 1: the near field payment
On the basis of the existing security strategy of bank, cooperate to increase corresponding operation flow Mobile phone card or phone number and bank card or bank account are carried out one to one one-to-many, many-to-one binding.The Mobile phone card of the communication network by operator or identifiability and the uniqueness characteristics of phone number are carried out authentication to the cellphone subscriber, in the real-time communication process, have guaranteed the authentication of the payment of mobile phone near field or transferring account with mobile phone process.
Concrete operation step is as follows:
(1) in banking system, increases the payment transaction server, be connected with banking system with authentication server respectively.The payment transaction server is responsible for trading activity, the trading privilege of receiving, paying both sides are managed, and submits the payment request to banking system;
(2) open corresponding application software, bank card or the Bank Account Number that can show and select to have bound also can regularly obtain relevant information from intermediate database, comprise new Binding information, bank card amount etc., and automatically calculate the bank card of selecting the amount coupling.
When (3) beginning to conclude the business, payment transaction server one end connects the internet gateway of operator, and an end connects the operation system of the e-bank of bank.Transaction request sends to trading server from mobile phone terminal by the common carrier network, trading server according to the intersection record of the Mobile phone card in the intermediate database or phone number match judge the legal validity of transaction after, again by modes such as bluetooth communication or camera scanning two-dimension codes, confirm payer really near field range, then confirm the amount of money of payment.After the payment transaction server realize to be confirmed both parties' the information such as authority, amount, the payment transaction server sent request to banking system, finishes funds transfer by banking system, immediately arrives account, and finishes information to the mobile phone terminal feedback trading.
Embodiment 2: gate inhibition's identification
On the basis of former gate control system, increase the mobile phone access control, identifiability and the uniqueness characteristics of Mobile phone card or phone number by common carrier, the cellphone subscriber is carried out authentication, according to authentication result, by the mobile phone that is connected with gate inhibition's main frame gate inhibition's main frame is sent message, realize the switching of system.
Concrete operation step is as follows:
1, cooperate with property and security department, in the main control system of gate control system, increase an access control mobile phone, be connected with gate inhibition's main frame with application server respectively (byUSBAnd open bluetooth and connect interface); Set up the user of gate control system and the intermediate database that Mobile phone card/phone number carries out man-to-man bundle relation with the application server after the internet gateway.
2, open corresponding application software, the user uses mobile phone to connect gate inhibition's mobile phone by bluetooth;
3, user profile sends to intermediate database by carrier network, and intermediate database User card or Subscriber Number and user profile are matched judgement, confirms the backward gate inhibition's mobile phone terminal feedback of legal validity authentication result.
4, the strategy by prior setting provides the facilitating functions such as user gate inhibition's access, and the equipment of gate inhibition's mobile phone by gate inhibition's host driven gate control system realizes the passenger is carried out carrying out after the identification switching function of door.