CN1737845A - IC card network trade affirmation method and its device - Google Patents

IC card network trade affirmation method and its device Download PDF

Info

Publication number
CN1737845A
CN1737845A CNA2004100582403A CN200410058240A CN1737845A CN 1737845 A CN1737845 A CN 1737845A CN A2004100582403 A CNA2004100582403 A CN A2004100582403A CN 200410058240 A CN200410058240 A CN 200410058240A CN 1737845 A CN1737845 A CN 1737845A
Authority
CN
China
Prior art keywords
reader device
card
network
transaction data
data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CNA2004100582403A
Other languages
Chinese (zh)
Inventor
辛华熙
林乔立
杨荣章
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hongbao Sci & Tech Co Ltd
Castles Tech Co Ltd
Original Assignee
Hongbao Sci & Tech Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hongbao Sci & Tech Co Ltd filed Critical Hongbao Sci & Tech Co Ltd
Priority to CNA2004100582403A priority Critical patent/CN1737845A/en
Publication of CN1737845A publication Critical patent/CN1737845A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

This invention relates to one IC network transaction certain method and device, wherein, the method comprises the following steps: the user locates the IC card in one reading card connected to computer and for network transaction through remote banking servo; inputting transaction data for displaying through the device before the customer sending for user comparing with computer display; after being sure, the customer terminal executes sending procedure sent to the banking servo through network.

Description

IC-card network trading confirmation method and device thereof
Technical field
The present invention relates to a kind of IC-card network trading confirmation method and device thereof, relate in particular in a kind of network trading that is applied in IC-card, utilize the IC-card reader device that affirmation mechanism again and again is provided, come method and the device to when confirming for the user by showing transaction data.
Background technology
Along with development of Internet, the network information connects and the characteristic of transmission and reaching its maturity of e-commerce technology fast, make many consumers or user can produce enterprises ends such as selling enterprise by contact bank, the Internet bank, shopping website or the commodity of network, carry out various ecommerce operations fast, such as the network download of the Internet bank, shopping at network, stock etc., for the user provides service very easily.
Yet in described network service, the Internet bank belongs to financial transaction, higher transaction security mechanism must be arranged, otherwise very easily produce controversial issue, even becomes the channel of swindle or money laundering.It is online through the Internet and remote bank server that the work of the Internet bank mainly is not to use the person to pass through its personal computer, after carrying out identity validation, import type of transaction (as transfer accounts or query the balance etc.) by the user, make corresponding work by bank server again.
In utilizing described known and process that network electronic commerce system that be widely used concludes the business,, should under the transfer mechanism of safety, carry out to good because this transaction data etc. all belong to the personal-machine ciphertext data.But network electronic commerce is a kind of mode of doing business of utilizing network to carry out by various application software, though network has agility and convenience, but also has the risk that sizable data are revealed, utilize trojan horse program etc. to implant virus etc. such as hacker attacks or unworthy personage, steal on network, transmit or personal computer or enterprise's servo-drive system in various data.
Therefore, those skilled in the art are for preventing that as far as possible such network electronic commerce data from being intercepted, and develop the encryption technology that network datas such as so-called SSL and SET transmits, be used in network data transmits, forming a security mechanism, ensure the security that network data transmits by these encryption technologies.But the encryption technology that network datas such as described SSL and SET transmit, as its name suggests, the network segment data security that only is useful between contact customer end and remote server is maintained secrecy, but can't take precautions against fully for the misdata that client has promptly been sent.Promptly when the implanted wooden horse type of the computing machine of client virus (or claim Troy type virus), promptly might make the shown information of client computer display be different from the actual information that sends out of this computing machine, promptly after the user imports transaction data, promptly may be altered this transaction data by virus in the dark, and the transaction data that this quilt is altered will can not be presented on user's the display of client, promptly this display still is shown as the transaction data of user's input, the user can't carry out any affirmation fully whether the transaction data that transmits is consistent really with the transaction data of being imported, the number of the account that changes over to that for example user is imported when carrying out money transfer transactions is A, the amount of money of transferring accounts is 1000 yuan, but may be in fact changed into B number of the account and 10000 yuan by virus, but the user still sees the transaction data forged by virus (promptly still being A number of the account and 1000 yuan) on display, the user does not have other any method fully can confirm whether the transaction data on the display is that real the wait sent again, carry out convey program and work as the user, being about to false transaction data (10000 yuan of B numbers of the account) sends, bank server is promptly handled according to this false transaction data, it more can't confirm the true and false of this transaction data, makes the user sustain a great loss.Though TaiWan, China monetary authority office explicit order arranges the money transfer transactions of account with the Internet bank, the user must use on the calculating punch that IC-card is plugged on its computing machine links to each other, and guarantee IC-card by the user all or held via the procurator of its mandate, but present existing calculating punch only has basic card-reading function, promptly when the user carries out network bank trading, confirm whether this IC-card conforms to the account data of being imported, send an Electronic Signature again if conform to, follow transaction data to deliver to bank server in the lump, but this way still can't be stopped described virus problems.So existing network bank trading has high potential risk for the user.
Content of the present invention
The object of the present invention is to provide a kind of IC-card network trading confirmation method and device thereof, in concluding the business by network and bank server, can be before carrying out the transmission of network trading data, utilize the display unit of IC-card reader device, see the real trade data of sending by the client computer of its independent displaying, and then contrast whether with shown identical of graphoscope, if the user confirms identical, promptly send Electronic Signature, and be sent to bank server with transaction data, form the transaction security mechanism of client with this.
For realizing described purpose, the invention provides a kind of IC-card network trading confirmation method and device thereof.The invention provides a reader device and allow the user be connected on its personal computer, described reader device comprises a microcontroller, a display unit, two buttons and IC-card slot.Described reader device is connected on the computing machine of client, and makes described computing machine connect the remote bank server by network.At first import relevant authentication data, be connected to bank server by network and carry out necessary identity validation, then, the user imports transaction data, before obtaining Electronic Signature to reader device, reader device can be presented at described transaction data on its display unit, whether errorlessly confirm for the user, after the instruction of user's input validation, reader device is sent Electronic Signature, be sent to bank server by network in the lump with transaction data, because the work of reader device does not need operating system, will not implanted virus, so its shown transaction data must be data actual to be sent, the user can obtain the affirmation of transaction data thus, is unlikelyly deceived by computer virus.
IC-card network trading confirmation method of the present invention and device thereof avoid utilizing wooden horse type Virus to control or alter the transaction risk of transaction data transmission; Compare with the transaction security (only limiting to the SSL or the SET encryption safe mechanism of network transfer phase) of known network electronic commerce, the present invention more can be increased in the security that the client transaction is carried out.
Brief description of drawings
Fig. 1 is the system architecture block scheme of IC-card internet trading system of the present invention and reader device;
Fig. 2 is the architecture block diagram of reader device of the present invention;
Fig. 3 is the workflow diagram of the affirmation mechanism again of one embodiment of the present invention.
In the accompanying drawing, the list of parts of each label representative is as follows:
1-bank server 2-network
3-client 4-reader device
41-microcontroller 42-display unit
43-YES acknowledgement key 44-NO acknowledgement key
45-IC card slot 46-connectivity port
200~209-flow chart step
Embodiment
In order to make those skilled in the art can further understand feature of the present invention and technology contents, see also following about detailed description of the present invention and accompanying drawing, accompanying drawing only provide with reference to and explanation, be not to be used for limiting the present invention.
As shown in Figure 1 and Figure 2, be the IC-card internet trading system of a preferred embodiment of the present invention and the system architecture block scheme of reader device.This IC-card internet trading system, as shown in Figure 1, the reader device 4 (can be an IC-card calculating punch) that comprises a bank server 1, a network 2, user's client 3 and be connected client 3.Client 3 is connected on the bank server 1 by network, and the ecommerce of setting up network trading is online.In the present embodiment, client 3 is the operated main frame of a user, connects reader device 4 by a standard interface (as USB), and reader device 4 is used to the IC-card of pegging graft, and reads data stored on the card.
The reader device 4 that is connected with client 3 as shown in Figure 2, comprises a microcontroller 41, a display unit 42, one or more acknowledgement key 43,44 and IC-card slots 45.Wherein IC-card slot 45 be used to plant user's IC-card comes reading of data; Display unit 42 can show the transaction data from client 3, as the demonstration once more before verification msg, the transaction data convey program; One or more acknowledgement keys 43,44 are used for the user display unit video data are carried out affirmation instruction again; Microcontroller 41 connects display units 42, two acknowledgement key 43,44 and IC-card slots 45, and utilizes connectivity port 46 to be connected with client 3, reading and transmitting and affirmation mechanism again for the IC-card data.
Below confirm device and when client 3 is carried out Internet bank's money transfer transactions, carry out again the workflow of affirmation mechanism, as shown in Figure 3, be the workflow diagram of affirmation mechanism again of one embodiment of the present invention for IC-card network trading of the present invention.
The user is plugged on reader device 4 with obtained IC-card, utilizing client 3 to be connected to bank server 1 by network 2 forms online, carry out necessary identity validation by the user immediately, promptly by client 3 input relevant authentication data, as individual appointment data such as number of the account, passwords; If it is errorless that this verification msg is confirmed through bank server 1, the user promptly obtains the transaction qualification of the Internet bank, can carry out network bank trading, as money transfer transactions etc.
Then, the user utilizes the input media input transaction data 200 of client 3, as changing number of the account over to and the amount of money etc. of transferring accounts in the money transfer transactions, and after input is finished, this transaction data is sent to before the bank server 1, must obtain Electronic Signature (generating) from reader device 4 by IC-card, promptly this transaction data is before sending, can deliver to reader device 4 in advance, this moment, reader device 4 promptly began to carry out the affirmation program, check that by reader device 4 whether complete the transaction data of these inputs 201, will return error in data information 202 for non-complete data input; Complete for the data input, promptly utilize the display unit 42 of reader device 4 to show this transaction data content 203 one by one, 205, transfer is gone into number of the account and the amount of money etc. of transferring accounts as money transfer transactions, and for the transaction data that shows one by one, all need the user to utilize YES or NO acknowledgement key 43,44 confirm 204 one by one, 206, this transaction data content is confirmed operation again through finishing item by item, and being the input content that conforms to, then data are sent to IC-card 207, and passback IC-card response data 209 (being Electronic Signature) are to client 3, and client 3 is about to transaction data and is sent to bank server 1 by network 2 and concludes the business.If it is inconsistent that transaction content has arbitrary content to find in showing the affirmation program one by one, the instruction through the user imports NO acknowledgement key 44 then returns the user and cancels information 208.
From the above mentioned, IC-card network trading confirmation method of the present invention and device thereof can be set up the security mechanism of a transaction data input validation in client 3, affirmation mechanism more whether transaction data that allows transaction data that the user can reaffirm and be imported and transmit by network 2 conforms to particularly, thus, can avoid utilizing wooden horse type Virus to control or alter the transaction risk of transaction data transmission; Compare with the transaction security (only limiting to the SSL or the SET encryption safe mechanism of network transfer phase) of known network electronic commerce, the present invention more can be increased in the security that client 3 transaction are carried out.
The above only is the preferred embodiments of the present invention, be not so promptly limit claim of the present invention, the equivalent structure transformation that every utilization instructions of the present invention and accompanying drawing content are done, or directly or indirectly be used in other relevant technical field, all in like manner be included in the claim of the present invention.

Claims (6)

1. IC-card network trading confirmation method, client computer connects a reader device, connects bank server by network and carries out network bank trading, the method for the input data being confirmed again by described reader device, it is characterized in that described method comprises:
One IC-card reader device is provided, is connected client, described reader device has independently display unit;
Behind the transaction data of client fan-in network bank, client is about to described transaction data and delivers to reader device and obtain Electronic Signature;
Before reader device was sent Electronic Signature, its display unit showed transaction data;
Person to be used confirms that described transaction data sends Electronic Signature after errorless again.
2. IC-card network trading confirmation method as claimed in claim 1 is characterized in that described reader device is an IC-card calculating punch.
3. IC-card network trading confirmation method as claimed in claim 2 is characterized in that described reader device has display unit and a plurality of acknowledgement key.
4. IC-card network trading confirmation method as claimed in claim 1 is characterized in that described input data comprise at least to change number of the account over to and the amount of money of transferring accounts.
5. an IC-card network trading is confirmed device, is an IC-card reader device, is connected on the client computer, and carries out network bank trading with this, it is characterized in that described device comprises:
One IC-card slot is used to the IC-card of planting;
One display unit, but display text numerical information;
A plurality of acknowledgement keys;
One connectivity port is for linking to each other with client computer;
One microcontroller connects described display unit, acknowledgement key, connectivity port and IC-card slot, is used to control the work of whole reader device;
When the user behind client input transaction data, client is about to described transaction data and is sent to reader device, the microcontroller of reader device is about to described transaction data and is sent to display unit and is shown, if the user confirms errorless with acknowledgement key, microcontroller is promptly sent Electronic Signature, if it is wrong that the user confirms, then do not send Electronic Signature.
6. IC-card network trading as claimed in claim 5 is confirmed device, it is characterized in that a plurality of acknowledgement keys of described reader device, includes the YES acknowledgement key, and execution display unit data presented is item by item confirmed instruction with the transmission that the data of user's input conform to; And the NO acknowledgement key, carry out display unit item by item the inconsistent cancel transmission of data presented and the data of user's input confirm to instruct.
CNA2004100582403A 2004-08-17 2004-08-17 IC card network trade affirmation method and its device Pending CN1737845A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNA2004100582403A CN1737845A (en) 2004-08-17 2004-08-17 IC card network trade affirmation method and its device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNA2004100582403A CN1737845A (en) 2004-08-17 2004-08-17 IC card network trade affirmation method and its device

Publications (1)

Publication Number Publication Date
CN1737845A true CN1737845A (en) 2006-02-22

Family

ID=36080631

Family Applications (1)

Application Number Title Priority Date Filing Date
CNA2004100582403A Pending CN1737845A (en) 2004-08-17 2004-08-17 IC card network trade affirmation method and its device

Country Status (1)

Country Link
CN (1) CN1737845A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108830589A (en) * 2018-05-17 2018-11-16 郑州升达经贸管理学院 A kind of mobile security financial terminal and its financial trade method
DE102014219793B4 (en) 2013-10-09 2024-05-29 Castles Technology Co., Ltd A financial transaction system with a security module

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102014219793B4 (en) 2013-10-09 2024-05-29 Castles Technology Co., Ltd A financial transaction system with a security module
CN108830589A (en) * 2018-05-17 2018-11-16 郑州升达经贸管理学院 A kind of mobile security financial terminal and its financial trade method

Similar Documents

Publication Publication Date Title
US8443200B2 (en) Biometric verification for electronic transactions over the web
CN1399753A (en) Method and system for authorizing purchases made over computer network
TWI811323B (en) Mobile payment system and method using a mobile payment device without an installed application
US20190114616A1 (en) Device account activation
KR20090074114A (en) System for payment by using picture information of face
CN102236855A (en) Method and system for electronic transaction by using QR (Quick Response) codes
CN1737845A (en) IC card network trade affirmation method and its device
JP2003016364A (en) Credit card dealing requesting device, credit settlement server, credit card dealing requesting method, computer program, and ic chip
CN102542696B (en) Security information interaction system and method
JP5589471B2 (en) Royalty management system, royalty management method and token
US20060118615A1 (en) System and method for secure transmission of electronic information
TWM582631U (en) Inductive financial card system
CN110675210B (en) Commodity transaction payment website system
KR101004081B1 (en) System for Asset Backed Securitization Investment Process
TW588537B (en) Network encryption method among terminals of IC card
JP2003016361A (en) Method and system for settlement processing
JP2002024737A (en) Payment processing system
KR20090036039A (en) Method for balancing between cyber account and circulating account and program recording medium
KR100876590B1 (en) Method and system for trading beneficiary certificates using F & A account and program recording medium
KR100982292B1 (en) System and Method for Processing Financial Goods Investment Linked Goods Buying and Program Recording Medium
KR20080080471A (en) System for operating loan management account
KR20090023444A (en) System for managing account
KR100876592B1 (en) How to process a beneficiary account transfer and record program
WO2008117212A1 (en) Electronic commerce
KR20090104226A (en) System and Method Managing Gold Accumulated Goods and Program Recording Medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Open date: 20060222