A kind of both parties are the near field payment method of authentication mutuallyTechnical field
The present invention relates to utilize mobile communication to realize the method for commerce of near field payment, be specifically related to a kind of both parties near field payment method of authentication mutually.
Background technology
Existing near field payment (transaction face-to-face), generally realize the near field payment by identification cards such as POS machine brush magnetic stripe card, smart card, NFC label, rfid cards, and be all by beneficiary, paying party to be carried out authentication, conclude the business by backward Unionpay or bank's transmission transaction request realization.The authentication mode of existing like this near field payment exists a lot of leaks, might allow the lawless person is organic to be taken advantage of, as: paying party can't be verified the legitimacy of beneficiary.Along with the POS machine is more and more general, there is the risk of being forged by the lawless person; When the client provided bank card to swipe the card, client's card had the risk that is replicated, the password of input that the possibility that is recorded is also arranged, and the lawless person is easy to falsely claim to be bank card information and the password that legal businessman extracts the client like this; The distinguishing ability that there is no POS machine legitimacy due to the client, the technical threshold of forging along with POS is more and more lower, and the risk of present this trade mode is increasing.Therefore, people begin one's study and use the more reliable modes of payments, and the use of mobile phone now is universal, and phone number has uniqueness, the mobile-phone payment mode also becomes the focus of people's research, number be 201110190955.4 to disclose a kind of Novel mobile phone payment method as Chinese patent application, realize real-time mobile-phone payment and need not special-purpose POS machine, solving the conventional mobile phone modes of payments has limitation, problem that cost is high, and the main points of its technical scheme are: a. installs bar code scanning software and mobile-phone payment software in mobile phone; B. when the user need to carry out mobile-phone payment, adopt the mobile telephone scanning window that the bar code of beneficiary is scanned; C. the mobile phone master chip is identified the bar code of beneficiary and is parsed the beneficiary relevant information; D. the user selects payment account input dealing money and payment cipher; E. the mobile phone master chip sends to bank's platform of correspondence the payment request information that comprises the beneficiary relevant information; F. result processed and returns by bank's platform to payment request information.But the technical scheme of this patent provides a kind of hand set paying method of authenticating identity, the bar code that but this authenticating identity is based on beneficiary to be provided authenticates, this still exists risk, be difficult to guarantee in bar code, whether all information is really, the account of the inside numeral card number and name on account might not be associated; Therefore, we still need to make improvements, and guarantee to the full extent the authenticity of accounts information, reduce transaction risk.
Summary of the invention
The object of the invention is to for the deficiencies in the prior art, provide a kind of based on phone number uniqueness, background server carry out authentication, safe reliability is high and the mutual method of payment of authentication of the both parties of easy realization.
To achieve these goals, the present invention has adopted following technical scheme:
A kind of both parties are the near field payment method of authentication mutually, comprises the following steps:
(1) at first set up phone number and Bank Account Number one to one in the application server data or the binding relationship of one-to-many;
(2) when the payment transaction of needs near fields, both parties carry out authentication and binding relationship and verify by communication function and the trading server communication of mobile phone self;
(3) after being verified of both parties, beneficiary is inputted collection amount on own mobile phone, and submits the gathering request to trading server; The trading server generating trading order form also returns to beneficiary to order number;
(4) beneficiary selects paying party to conclude the business, and sends order number by Near Field Communication mode (being the wireless communication function of mobile phone self) to paying party;
(5) paying party from trading server order downloaded information, after confirmation, is inputted payment cipher according to order number on own mobile phone, submits payment request to;
(6) trading server agrees with checking to both parties' the transaction request information of carrying out, after being proved to be successful, trading server is submitted the transaction processing request to the banking front end processor, the banking front end processor returns to trading server with the transaction processing result after completing the transaction operation, trading server records the transaction processing result and simultaneously the transaction processing result is handed down to both parties' mobile phone, completes the near field payment transaction one time; If it is unsuccessful to agree with checking, not submit the transaction processing request to the banking front end processor, but issue the information of Fail Transaction to both parties' mobile phone, order cancels.
Further illustrate as of the present invention, above-described trading server is included in authentication server and the application server that sets up after the Communication Gateway of operator; Described authentication server is processed ID authentication request; Described application server is deposited the subscriber identity information that corresponding relation is arranged and the Bank Account Number information through confirming.
Further illustrate as of the present invention, the step of above-described authentication is:
A. mobile phone open Mobile data communication access way is obtained the identifying information of the other side's mobile phone and is submitted the identifying information of the other side's mobile phone from the trend trading server to, carries out ID authentication request;
When b. operator's Communication Gateway is received request, obtain MSISDN information from communications protocol after, together with authentication request, be submitted to authentication server after encryption;
C. authentication server is to after request deciphering, extract MSISDN information and judge legal after, be given to application server, application server returns to mobile phone client software after obtaining corresponding identity information and Bank Account Number information, has realized two-way identification.
Further illustrate as of the present invention, above-described ID authentication request adopts the rivest, shamir, adelman of rsa 1024, carry out transmitting after digital certificate is encrypted, and the symmetrical enciphering and deciphering algorithm of aes256, the transmission private key.Digital certificate is relevant to handset identity information, and mobile phone and trading server can by checking handset identity information, be realized the effect of double verification.
Further illustrate as of the present invention, the identifying information of above-described mobile phone is the Mobile phone card number, or with Mobile phone card related identification code one to one.
Further illustrate as of the present invention, the communication function of above-described mobile phone self comprises the intrinsic bluetooth of mobile phone, two-dimension code and less radio-frequency close range communication function.That is, the wireless data communication function of described mobile phone comprises: GPRS, EDGE, WCDMA, TD-WCDMA, CDMA2000, HSDPA etc.
Further illustrate as of the present invention, the sequence information in above step (5) comprises the identity information of beneficiary, identity information and the payment information of paying party.
In the present invention, after on both parties' mobile phone, the application software of appointment being installed all, by wireless data communication (GPRS, EDGE, WCDMA, TD-WCDMA, CDMA2000, HSDPA etc.) function, transmit MSISDN(Mobile Subscriber International ISDN/PSTN number, mobile subscriber number to application server in communications protocol) etc. user profile.MSISDN information is identified and authenticated to application server, then notifies the cell-phone customer terminal authentication result.
In the present invention, utilize the MSISDN information with uniqueness, set up with Bank Account Number one to one, the binding relationship of one-to-many, utilize the communication function of mobile phone self, only need mobile phone and POS non-contacting communication before can realize identification to Bank Account Number.Avoided the operation of swiping the card of process of exchange, the possibility of also having avoided bank card to be replicated; And use the real-time online mode to carry out transaction verification, and allow on both parties' oneself mobile phone, identify at an easy rate the other side's identity, thereby stopped to assume another's name transaction and forge and conclude the business.
Compared with prior art, advantage of the present invention:
High and the easy realization of near field payment method safe reliability of the present invention is embodied in the following aspects:
1. set up binding relationship by MSISDN and the Bank Account Number of uniqueness, do not need to swipe the card, only need " brush mobile phone ", avoided bank card to be replicated.
2. the information such as the true identity of paying party identification beneficiary and Bank Account Number are issued to mobile phone by trading server, avoid the beneficiary personation and forge POS.
3. trading server is on the basis of checking both parties true identity, and the transaction request that both parties are sent is done and agreed with checking, completes just now transaction processing after being proved to be successful, and transaction results is also by server notification both parties mobile phone.This has guaranteed authenticity and the non repudiation of both sides' transaction, and the situation of the access checking beneficiary of just paying the bill before having changed guarantees transaction security greatly.
4. input the mode of password in process of exchange on the mobile phone of paying party oneself, avoided the possibility that password is revealed and password is recorded.
5. easily realize, both parties' mobile phone only needs that software according to the invention is installed and just can realize safe near field mobile-phone payment, the application of transferring account with mobile phone under not additional any hardware case.
Description of drawings
Fig. 1 is schematic flow sheet of the present invention.
Embodiment
The present invention is further described below in conjunction with embodiment.
Embodiment:
A kind of both parties are the near field payment method of authentication mutually, comprises the following steps:
(1) at first set up phone number and Bank Account Number one to one in the application server data or the binding relationship of one-to-many;
(2) when the payment transaction of needs near fields, both parties carry out authentication and binding relationship and verify by wireless communication function and the trading server communication of mobile phone self;
The step of above-mentioned authentication is:
A. mobile phone open Mobile data communication access way is obtained the identifying information of the other side's mobile phone and is submitted the identifying information of the other side's mobile phone from the trend trading server to, carries out ID authentication request;
When b. operator's Communication Gateway is received request, obtain MSISDN information from communications protocol after, together with authentication request, be submitted to authentication server after encryption;
C. authentication server is to after request deciphering, extract MSISDN information and judge legal after, be given to application server, application server returns to mobile phone after obtaining corresponding identity information and Bank Account Number information, has realized two-way identification.
Above-mentioned ID authentication request adopts the rivest, shamir, adelman of rsa 1024, carries out transmitting after digital certificate is encrypted, and the symmetrical enciphering and deciphering algorithm of aes256, the transmission private key.Digital certificate is relevant to handset identity information, and mobile phone and trading server can by checking handset identity information, be realized the effect of double verification.
(3) after being verified of both parties, beneficiary is inputted collection amount on own mobile phone, and submits the gathering request to trading server; The trading server generating trading order form also returns to beneficiary to order number;
Described trading server is included in authentication server and the application server that sets up after the Communication Gateway of operator; Described authentication server is processed ID authentication request; Described application server is deposited the subscriber identity information that corresponding relation is arranged and the Bank Account Number information through confirming;
(4) beneficiary selects paying party to conclude the business, and sends order number by the Near Field Communication mode to paying party;
(5) paying party from trading server order downloaded information (comprising the identity information of beneficiary, identity information and the payment information of paying party), after confirmation, is inputted payment cipher according to order number on own mobile phone, submits payment request to;
(6) trading server agrees with checking to both parties' the transaction request information of carrying out, after being proved to be successful, trading server is submitted the transaction processing request to the banking front end processor, the banking front end processor returns to trading server with the transaction processing result after completing the transaction operation, trading server records the transaction processing result and simultaneously the transaction processing result is handed down to both parties' mobile phone, completes the near field payment transaction one time; If it is unsuccessful to agree with checking, not submit the transaction processing request to the banking front end processor, but issue the information of Fail Transaction to both parties' mobile phone, order cancels.
Zhang San's (paying party) and Li Si's (beneficiary) use the application example flow process of near field payment method of the present invention:
(1) at first, it is related that Zhang San and Li Si will use respectively cell-phone number that own I.D. handles and the bank account of oneself to bind, and then mobile-phone payment software according to the invention is installed on own mobile phone;
When (2) the near field payment transaction need to occur for they, both parties moved mobile-phone payment software, by wireless communication function and the trading server communication of mobile phone self, carried out the checking of authentication and binding relationship;
(3) by after checking, Li Si inputs collection amount in software, and selects bluetooth discovery near Zhang San; At this moment mobile-phone payment software has been submitted the gathering application to from the trend trading server, and server has returned to the order number of new generation.Zhang San's mobile phone has been received order number by bluetooth, automatically downloads this sequence information from trading server;
(4) Zhang San is the information of confirming an order at own mobile-phone payment software, selects the Send only Account of oneself, and the input account password, sends transaction request to trading server;
(5) trading server agrees with checking to both parties' the transaction request information of carrying out, after being proved to be successful, trading server is submitted the transaction processing request to the banking front end processor, the banking front end processor returns to trading server with the transaction processing result after completing the transaction operation, trading server records the transaction processing result and simultaneously the transaction processing result is handed down to both parties' mobile phone, and Zhang San and Li Si receive after information is completed in transaction and namely complete the near field payment transaction one time.
In current transaction, Zhang San, Li Si all verify the other side's identity information, bank account information etc., have guaranteed the authenticity of both parties' identity; When concluding the business, Zhang San's (paying party) inputs account password on own mobile phone, so both guaranteed that Zhang San's account password is not revealed, and Li Si's (beneficiary) obtains the time of Transaction Success message from server, be collection amount after account, guarantee dealing money safety.