TWI693570B - System and method of transaction using credit card - Google Patents

System and method of transaction using credit card Download PDF

Info

Publication number
TWI693570B
TWI693570B TW107111030A TW107111030A TWI693570B TW I693570 B TWI693570 B TW I693570B TW 107111030 A TW107111030 A TW 107111030A TW 107111030 A TW107111030 A TW 107111030A TW I693570 B TWI693570 B TW I693570B
Authority
TW
Taiwan
Prior art keywords
transaction
location
reply
electronic device
message
Prior art date
Application number
TW107111030A
Other languages
Chinese (zh)
Other versions
TW201942832A (en
Inventor
簡樹理
Original Assignee
兆豐國際商業銀行股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 兆豐國際商業銀行股份有限公司 filed Critical 兆豐國際商業銀行股份有限公司
Priority to TW107111030A priority Critical patent/TWI693570B/en
Publication of TW201942832A publication Critical patent/TW201942832A/en
Application granted granted Critical
Publication of TWI693570B publication Critical patent/TWI693570B/en

Links

Images

Abstract

A system of transaction using credit card having a communication unit, a storage unit and a processing unit is provided. The storage unit stores a plurality of personal transaction information having an identification information, a preset device identification code and a location setting. When receiving a transaction request, the processing unit obtains a personal transaction information according to the transaction information and determines whether a transaction location of the transaction request conforms the location setting. When the transaction location of the transaction request conforms the location setting, the processing unit sends a confirm message to the electronic device according to the preset device identification code. When receiving a response message, the processing unit determines whether a response location of the response message conforms the transaction location. When the response location of the response message conforms the transaction location, processing unit performs the transaction according to the transaction request.

Description

使用***的交易系統及使用***的交易方法Transaction system using credit card and transaction method using credit card

本發明是有關於一種金融安全交易技術,且特別是有關於一種使用***的交易系統與使用***的交易方法。The invention relates to a financial security transaction technology, and in particular to a transaction system using a credit card and a transaction method using a credit card.

隨著網路交易的盛行,線上刷卡結帳的行為已普及於國人的生活之中。對於提供刷卡的網路服務公司而言,線上刷卡的安全防護即成為一個重要的課題。為了強化線上刷卡的安全性,發卡銀行多採用3-D安全技術(3-D secure),也就是在進行刷卡結帳時,必須再輸入一組3-D驗證密碼才能完成交易,因而提升交易的安全度。With the prevalence of online transactions, online credit card checkout has become popular in the lives of Chinese people. For network service companies that provide card swiping, the security protection of online card swiping has become an important issue. In order to strengthen the security of online card swiping, card-issuing banks mostly use 3-D secure technology (3-D secure), that is, when performing card swiping and checkout, a set of 3-D verification password must be entered to complete the transaction, thus enhancing the transaction Safety.

然而,對於消費者而言,消費者必須多記憶一組平常較少使用的3-D驗證密碼,因此常常發生忘記3-D驗證密碼而交易失敗的情形,導致消費者對於3-D驗證密碼的接受度較低。對於商家而言,為了避免影響消費者的購買意願,商家對於3-D驗證密碼多採取被動態度。在消費者與商家使用意願都很低的情形下,對於***線上交易安全之提升反而造成了阻礙。因此,如何能夠強化***的安全,同時又能夠維持客戶線上刷卡的操作體驗為本領域所面對的課題。However, for consumers, consumers must memorize a set of 3-D verification passwords that are usually less used, so it often happens that the transaction fails when the 3-D verification password is forgotten, resulting in the consumer's 3-D verification password Acceptance is low. For merchants, in order to avoid affecting consumers' willingness to purchase, merchants adopt a passive attitude toward 3-D verification passwords. Under the circumstances that consumers and merchants have low willingness to use, it has caused obstacles to the improvement of online credit card transaction security. Therefore, how to strengthen the security of the credit card and at the same time maintain the customer's online card swiping experience is a subject facing the field.

本發明提供一種使用***的交易系統及使用***的交易方法,用以強化***交易的安全性並維持使用者執行***交易時的體驗。The present invention provides a transaction system using a credit card and a transaction method using a credit card to strengthen the security of credit card transactions and maintain the user's experience when performing credit card transactions.

本揭露提供的使用***的交易系統具有通訊單元、儲存單元以及處理單元。通訊單元接收與傳送訊息。儲存單元儲存多筆個人交易資訊,每一個人交易資訊具有身分資訊、設備預設識別代碼及地理範圍設定,且設備預設識別代碼對應至電子裝置的應用程式。處理單元連接於通訊單元及儲存單元。當處理單元接收到交易請求,依據交易請求獲取相應的個人交易資訊,並判斷交易請求的交易位置是否符合地理範圍設定,當交易位置符合該地理範圍設定,處理單元依據設備預設識別代碼發送確認訊息至電子裝置。當接收到來自電子裝置的回覆訊息,處理單元判斷回覆訊息對應的回覆位置是否符合交易位置,當回覆位置符合交易位置時,處理單元依據交易請求進行交易。The transaction system using a credit card provided by the present disclosure has a communication unit, a storage unit, and a processing unit. The communication unit receives and transmits messages. The storage unit stores multiple pieces of personal transaction information, and each personal transaction information has identity information, a device default identification code, and a geographic range setting, and the device default identification code corresponds to the application of the electronic device. The processing unit is connected to the communication unit and the storage unit. When the processing unit receives the transaction request, it obtains the corresponding personal transaction information according to the transaction request, and determines whether the transaction position of the transaction request conforms to the geographic range setting. Message to electronic device. When receiving the reply message from the electronic device, the processing unit determines whether the reply position corresponding to the reply message matches the transaction position. When the reply position matches the transaction position, the processing unit performs a transaction according to the transaction request.

本揭露提供的使用***的交易方法具有步驟:接收交易請求;依據交易請求獲取相應的個人交易資訊,並判斷交易請求的交易位置是否符合個人交易資訊中的地理範圍設定,其中個人交易資訊具有身分資訊、設備預設識別代碼及地理範圍設定,且設備預設識別代碼對應至電子裝置的應用程式;當交易位置符合地理範圍設定,依據設備預設識別代碼發送確認訊息至電子裝置;接收到來自電子裝置的回覆訊息;判斷回覆訊息對應的回覆位置是否符合交易位置;以及當回覆位置符合交易位置時,依據交易請求進行交易。The transaction method using credit card provided by this disclosure has the steps of: receiving a transaction request; obtaining the corresponding personal transaction information according to the transaction request, and judging whether the transaction location of the transaction request conforms to the geographical range setting in the personal transaction information, wherein the personal transaction information has an identity Information, equipment default identification code and geographic range setting, and the equipment default identification code corresponds to the application of the electronic device; when the transaction location meets the geographic range setting, a confirmation message is sent to the electronic device according to the equipment default identification code; The reply message of the electronic device; determine whether the reply location corresponding to the reply message matches the transaction location; and when the reply location matches the transaction location, conduct the transaction according to the transaction request.

基於上述,本揭露提供的使用***的交易系統及使用***的交易方法會通過相應商家網站的交易位置與使用者的電子裝置的位置作為安全認證的依據。當交易位置、使用者的位置一致時,才會完成交易。藉此強化***交易的安全性,同時維持使用者在執行***交易時的體驗。Based on the above, the transaction system using a credit card and the transaction method using a credit card provided by the present disclosure will use the transaction location of the corresponding merchant website and the location of the user's electronic device as a basis for security authentication. The transaction will only be completed when the transaction location and the user's location match. In this way, the security of credit card transactions is strengthened, while maintaining the user's experience in performing credit card transactions.

為讓本發明的上述特徵和優點能更明顯易懂,下文特舉實施例,並配合所附圖式作詳細說明如下。In order to make the above-mentioned features and advantages of the present invention more obvious and understandable, the embodiments are specifically described below in conjunction with the accompanying drawings for detailed description as follows.

本揭露提供的使用***的交易系統及使用***的交易方法會通過接收來自商家網站的交易請求,並通過獲取交易位置與使用者的電子裝置的位置進行安全認證,以維護交易的安全性。The transaction system using a credit card and the transaction method using a credit card provided by this disclosure will receive the transaction request from the merchant's website and perform security authentication by obtaining the transaction location and the location of the user's electronic device to maintain the security of the transaction.

圖1繪示本揭露一實施例的使用***的交易系統的架構圖。請參考圖1,本揭露所提供的使用***的交易系統100具有通訊單元110、儲存單元120以及處理單元130。通訊單元110用以傳送及接收訊息。在本揭露一實施例中,通訊單元110是以通訊晶片進行實作,通訊晶片可為支援全球行動通信(Global System for Mobile communication, GSM)、個人手持式電話系統(Personal Handy-phone System, PHS)、碼多重擷取(Code Division Multiple Access, CDMA)系統、寬頻碼分多址(Wideband Code Division Multiple Access, WCDMA)系統、長期演進(Long Term Evolution, LTE)系統、全球互通微波存取(Worldwide interoperability for Microwave Access, WiMAX)系統、無線保真(Wireless Fidelity, Wi-Fi)系統或藍牙的信號傳輸的元件。FIG. 1 illustrates an architecture diagram of a transaction system using a credit card according to an embodiment of the disclosure. Please refer to FIG. 1. The transaction system 100 using a credit card provided by the present disclosure has a communication unit 110, a storage unit 120 and a processing unit 130. The communication unit 110 is used to send and receive messages. In an embodiment of the present disclosure, the communication unit 110 is implemented by a communication chip. The communication chip may be a Global System for Mobile Communication (GSM), Personal Handy-phone System (PHS) ), Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, Long Term Evolution (LTE) system, Global Interoperability Microwave Access (Worldwide Interoperability for Microwave Access (WiMAX) system, Wireless Fidelity (Wi-Fi) system or Bluetooth signal transmission component.

儲存單元120是用以儲存運行使用***的交易系統100時所需的軟體、資料及各類程式碼,特別是,儲存單元120儲存多筆個人交易資訊。每一筆個人交易資訊都具備身分資訊、設備預設識別代碼以及地理範圍設定。身分資訊為使用者的姓名、身分證字號/護照號碼、***卡號、手機號碼等,但本揭露並不限於此。設備預設識別代碼為使用者在首次以電子裝置中的應用程式註冊或登入時所產生的識別碼,也就是說,此設備預設識別代碼會綁定使用者電子裝置中的應用程式。地理範圍設定為使用者所設定的交易範圍,舉例來說,此地理範圍設定可以為國內、國外、國內外均可,或者是限定特定區域,例如台灣、美加等,本揭露並不限於此。儲存單元120可以是任何型態的固定或可移動隨機存取記憶體(Random Access Memory,RAM)、唯讀記憶體(Read-Only Memory,ROM)、快閃記憶體(flash memory)、硬碟(Hard Disk Drive,HDD)、固態硬碟(Solid State Drive,SSD)或類似元件或上述元件的組合。The storage unit 120 is used to store software, data, and various types of program codes required when running the transaction system 100 using a credit card. In particular, the storage unit 120 stores multiple personal transaction information. Each personal transaction information has identity information, device default identification code, and geographic range settings. The identity information is the user's name, ID number/passport number, credit card number, mobile phone number, etc., but this disclosure is not limited to this. The device default identification code is the identification code generated when the user first registers or logs in with the application in the electronic device, that is, the device default identification code binds the application in the user's electronic device. The geographic range is set as the transaction range set by the user. For example, the geographic range can be set at home, abroad, or abroad, or it can be limited to a specific area, such as Taiwan, the United States, Canada, etc., the disclosure is not limited to this . The storage unit 120 can be any type of fixed or removable random access memory (RAM), read-only memory (ROM), flash memory (flash memory), hard disk (Hard Disk Drive, HDD), Solid State Drive (SSD) or similar components or a combination of the above components.

處理單元130連接於通訊單元110及儲存單元120。處理單元130可以是中央處理單元(Central Processing Unit,CPU),或是其他可程式化之一般用途或特殊用途的微處理器(Microprocessor)、數位信號處理器(Digital Signal Processor,DSP)、可程式化控制器、特殊應用積體電路(Application Specific Integrated Circuit,ASIC)或其他類似元件或上述元件的組合,本揭露不限於此。The processing unit 130 is connected to the communication unit 110 and the storage unit 120. The processing unit 130 can be a central processing unit (Central Processing Unit, CPU), or other programmable general-purpose or special-purpose microprocessor (Microprocessor), digital signal processor (Digital Signal Processor, DSP), programmable The controller, the application specific integrated circuit (Application Specific Integrated Circuit, ASIC) or other similar components or the combination of the above components are not limited to this disclosure.

圖2繪示本揭露一實施例使用***的交易系統運行使用***的交易方法的流程圖。以下將同時搭配圖1與圖2說明如何通過比對使用者的位置與交易所在位置是否一致作為安全認證的依據。FIG. 2 illustrates a flowchart of an embodiment of the present disclosure using a credit card transaction system to run a credit card transaction method. The following will also illustrate how to compare the user's location with the exchange's location as the basis of security certification by combining Figures 1 and 2.

在步驟S210,處理單元130通過通訊單元110接收到交易請求。具體來說,在使用者於商家網站上進行交易時,商家網站必須通過使用***的交易系統100執行交易,因此商家網站必須發送交易請求至使用***的交易系統100。交易請求具有此筆交易的***刷卡資料以及交易網頁位置資訊。***刷卡資料例如但不限於刷卡人姓名、***卡號、交易安全碼。在本實施例中,交易網頁位置是以刷卡人連結至商家網站的地理位置為基礎,因此交易網頁位置資訊例如但不限於刷卡人上網的所在地址(例如:台灣台北市)。在其他實施例中,交易網頁位置資訊也可以是刷卡人連結商家網站的網際網路協定位址(Internet Protocol,IP)、所在座標位置、媒體存取控制位置(Media Access Control Address,MAC位址)等,然本揭露並不限於此。任何可以讓處理單元130直接獲取刷卡人線上付款網頁所在位置的資訊,或者是通過分析比對而確認網站所在位置的資訊,都可被應用為交易網頁位置資訊。In step S210, the processing unit 130 receives the transaction request through the communication unit 110. Specifically, when a user performs a transaction on a merchant website, the merchant website must perform the transaction through the transaction system 100 using a credit card, so the merchant website must send a transaction request to the transaction system 100 using a credit card. The transaction request has the credit card swipe data of this transaction and the location information of the transaction web page. Credit card swipe data such as but not limited to the name of the credit card reader, credit card number, transaction security code. In this embodiment, the location of the transaction webpage is based on the geographic location where the card reader is connected to the merchant's website. Therefore, the location information of the transaction webpage is, for example, but not limited to, the address where the card reader is online (for example, Taipei, Taiwan). In other embodiments, the transaction webpage location information may also be the Internet Protocol (IP), coordinate location, and Media Access Control Address (MAC address) of the credit card link to the merchant’s website ) Wait, but this disclosure is not limited to this. Any information that allows the processing unit 130 to directly obtain the location of the online payment webpage of the credit card reader, or to confirm the location of the website through analysis and comparison, can be used as the location information of the transaction webpage.

在步驟S220,處理單元130依據交易請求找出相應的個人交易資訊。由於交易請求中具有***刷卡資料,處理單元130可以基於***卡號或/及刷卡人姓名而於儲存單元120中讀取相應的個人交易資訊。In step S220, the processing unit 130 finds corresponding personal transaction information according to the transaction request. Since the transaction request has credit card swipe data, the processing unit 130 may read the corresponding personal transaction information in the storage unit 120 based on the credit card number or/and the name of the credit card person.

在步驟S230,處理單元130判斷交易請求的交易位置是否符合地理範圍設定。詳細地說,處理單元130通過交易請求中的交易網頁位置資訊獲取交易位置,此外,處理單元130讀取的個人交易資訊中具有此使用者事先設定的地理範圍設定。基此,處理單元130會判斷交易位置是否位於地理範圍設定中。In step S230, the processing unit 130 determines whether the transaction location of the transaction request conforms to the geographic range setting. In detail, the processing unit 130 obtains the transaction location through the transaction webpage location information in the transaction request. In addition, the personal transaction information read by the processing unit 130 has the geographical range setting set by the user in advance. Based on this, the processing unit 130 determines whether the transaction location is in the geographical range setting.

當交易位置不符合地理範圍設定時,執行步驟S280,處理單元130會通過通訊單元110傳送交易失敗的訊息至電子裝置。詳細地說,處理單元130會依據步驟S220所讀取的個人交易資訊的設備預設識別代碼推播交易失敗的訊息至使用者的電子裝置,也就是說,處理單元130會將交易失敗的訊息推播到使用者預先綁定的電子裝置中。或者是,處理單元130也可以通過通訊單元110而發送訊息至使用者所留下來的電話號碼。藉此,若是使用者本人執行此交易時,其可明確得知交易失敗的原因;而若非使用者本人執行此交易時,使用者可以快速的獲知有非法人士想要盜刷***。When the transaction location does not meet the geographical range setting, step S280 is executed, and the processing unit 130 sends a transaction failure message to the electronic device through the communication unit 110. In detail, the processing unit 130 will broadcast the transaction failure message to the user's electronic device according to the device default identification code of the personal transaction information read in step S220, that is, the processing unit 130 will send the transaction failure message Push to the user's pre-bound electronic device. Alternatively, the processing unit 130 may also send a message to the phone number left by the user through the communication unit 110. In this way, if the user himself performs the transaction, he can clearly know the reason for the transaction failure; and if the user himself does not execute the transaction, the user can quickly learn that an illegal person wants to steal the credit card.

舉例來說,使用者所預先設定的地理範圍設定為「國內」。當交易位置在美國時,於步驟S230中,處理單元130會判斷交易請求的交易位置不符合地理範圍設定,因而執行步驟S280,依據設備預設識別代碼而將交易失敗的訊息推播到使用者預先綁定的電子裝置中。然若當交易位置在台灣台北市時,於步驟S230中,處理單元130會判斷交易位置符合地理範圍設定,因而接續執行步驟S240。For example, the geographical range preset by the user is set to "domestic". When the transaction location is in the United States, in step S230, the processing unit 130 determines that the transaction location of the transaction request does not conform to the geographic range setting, so step S280 is executed to broadcast the transaction failure message to the user according to the device's default identification code Pre-bound electronic device. However, if the transaction location is in Taipei, Taiwan, in step S230, the processing unit 130 determines that the transaction location conforms to the geographic range setting, and then proceeds to step S240.

在步驟S240,處理單元130會依據設備預設識別代碼發送確認訊息至電子裝置。確認訊息具有但不限於:交易日期、交易金額以及店家資訊,藉此以讓使用者確認此筆消費交易。此外,此確認訊息並同時請求使用者的電子裝置回傳具有回覆位置資訊的回覆訊息。在本實施例中,使用者必須在預設時間(例如:180秒)內按下確認鍵,以確保交易的即時與安全性。若使用者沒有在預設時間內按下確認鍵,則處理單元130會拒絕此筆交易,並發送交易失敗的訊息至使用者的電子裝置。而當使用者按下確認鍵時,電子裝置會自動擷取電子裝置的位置資訊,例如:回覆位置資訊,回傳回覆訊息,並通過通訊單元110被傳送到至處理單元130。In step S240, the processing unit 130 sends a confirmation message to the electronic device according to the device preset identification code. The confirmation message includes, but is not limited to: the transaction date, transaction amount, and store information, so that the user can confirm the consumption transaction. In addition, this confirmation message also requests the user's electronic device to return a reply message with reply location information. In this embodiment, the user must press the confirmation key within a preset time (for example: 180 seconds) to ensure the real-time and security of the transaction. If the user does not press the confirmation key within the preset time, the processing unit 130 will reject the transaction and send a message that the transaction failed to the user's electronic device. When the user presses the confirmation key, the electronic device automatically retrieves the location information of the electronic device, for example: replying to the location information, returning the reply message, and transmitting it to the processing unit 130 through the communication unit 110.

在步驟S250,處理單元130接收到來自電子裝置的回覆訊息。回覆訊息中具有電子裝置的回覆位置資訊,舉例來說,回覆位置資訊可以為電子裝置的全球定位系統位置(Global Positioning System,GPS)、電子裝置通過WiFi定位所獲取的定位位置等,但本揭露不限於此。In step S250, the processing unit 130 receives a reply message from the electronic device. The reply message includes the reply location information of the electronic device. For example, the reply location information may be a global positioning system (GPS) location of the electronic device, a positioning location obtained by the electronic device through WiFi positioning, etc., but this disclosure Not limited to this.

在步驟S260,處理單元130會進一步判斷回覆訊息的回覆位置是否符合交易位置。承前述實施例,若交易位置在台灣台北市,然處理單元130依據回覆訊息中的回覆位置資訊得知,電子裝置的回覆位置在於日本,則表示這筆交易與使用者所在位置並不相符,並非由使用者本人所執行。此時,執行步驟S280,處理單元130會通過通訊單元110傳送交易失敗的訊息至電子裝置。需說明的是,由於回覆位置與交易位置可能會因為判斷位置的依據不同而導致位置、精度有所差異,因此在判斷回覆位置是否符合交易位置時,可以以一個區域為一致的標準,例如:位於同一個國家、同一個城市等,本揭露並不限制區域的大小與範圍。In step S260, the processing unit 130 further determines whether the reply position of the reply message matches the transaction position. According to the foregoing embodiment, if the transaction location is in Taipei, Taiwan, the processing unit 130 knows that the reply location of the electronic device is in Japan based on the reply location information in the reply message, indicating that the transaction does not match the user’s location, Not performed by the user himself. At this time, step S280 is executed, and the processing unit 130 transmits a transaction failure message to the electronic device through the communication unit 110. It should be noted that since the reply position and the transaction position may differ in position and accuracy due to the different basis for determining the position, when judging whether the reply position meets the transaction position, a region can be used as a consistent standard, for example: Located in the same country, the same city, etc., this disclosure does not limit the size and scope of the area.

在本揭露的其他實施例中,為了確保回覆位置沒有被竄改或者飄移太遠,在步驟S250的回覆訊息中更具有第一回覆位置訊息以及第二回覆位置訊息。並在步驟S260中,處理單元130會判斷第一回覆位置及第二回覆位置是否都符合交易位置(例如:是否位於相同的國家或城市)。In other embodiments of the present disclosure, in order to ensure that the reply position has not been tampered with or drifted too far, the reply message in step S250 further has a first reply position message and a second reply position message. In step S260, the processing unit 130 determines whether both the first reply position and the second reply position match the transaction position (for example, whether they are located in the same country or city).

詳細來說,承前步驟S210所述,交易位置是刷卡人開啟商家網站之網頁IP位址。而步驟S250的回覆訊息中,第一回覆位置訊息是電子裝置的全球定位系統位置(Global Positioning System,GPS),第二回覆位置訊息是通過WiFi定位所獲取的定位位置。處理單元130會分別判斷交易位置與第一回覆位置是否一致,以及交易位置與第二回覆位置是否一致。藉此,以判斷交易位置、第一回覆位置以及第二回覆位置是否皆一致。若任一位置與其他兩個位置之間不一致,執行步驟S280,處理單元130會通過通訊單元110傳送交易失敗的訊息至電子裝置。In detail, as described in the previous step S210, the transaction location is the IP address of the webpage of the merchant website opened by the card reader. In the reply message of step S250, the first reply location message is the global positioning system (GPS) position of the electronic device, and the second reply location message is the positioning location obtained through WiFi positioning. The processing unit 130 will separately determine whether the transaction position is consistent with the first reply position, and whether the transaction position is consistent with the second reply position. In this way, to determine whether the transaction position, the first reply position and the second reply position are all consistent. If any position is inconsistent with the other two positions, step S280 is executed, and the processing unit 130 sends a transaction failure message to the electronic device through the communication unit 110.

倘若回覆訊息的回覆位置與交易位置一致,在步驟S270,處理單元130依據交易請求進行交易。處理單元130會將定位資料、交易日期、時間、消費內容等資料留存在儲存單元120作為日後舉證的依據。並且,處理單元130會通過通訊單元110回傳交易成功的訊息至商家網站以及使用者的電子裝置,藉此以通知使用者交易成功。If the reply position of the reply message is consistent with the transaction position, in step S270, the processing unit 130 performs the transaction according to the transaction request. The processing unit 130 will store the positioning data, transaction date, time, consumption content and other data in the storage unit 120 as a basis for proof in the future. In addition, the processing unit 130 returns a successful transaction message to the merchant website and the user's electronic device through the communication unit 110, thereby notifying the user that the transaction was successful.

須說明的是,為了尊重使用者對於使用***的交易系統100及使用***的交易方法的體驗,並且確保電子裝置確實為使用者所擁有的,在開始使用***的交易系統100與使用***的交易方法前,使用者需通過電子裝置而於使用***的交易系統100中進行登入與註冊,藉此以讓使用***的交易系統100執行身分認證方法。以下將說明通過電子裝置而於使用***的交易系統100中進行登入與註冊,並讓使用***的交易系統100執行身分認證的方法。It should be noted that in order to respect the user’s experience with the transaction system 100 using credit cards and the transaction method using credit cards, and to ensure that the electronic device is indeed owned by the user, the transaction system 100 using credit cards and the transactions using credit cards are started Before the method, the user needs to log in and register in the transaction system 100 using a credit card through an electronic device, so that the transaction system 100 using a credit card can perform the identity authentication method. Hereinafter, a method of performing login and registration in the transaction system 100 using a credit card through an electronic device and allowing the transaction system 100 using a credit card to perform identity authentication will be described.

首先,使用者必須先於電子裝置中下載指定的應用程式(例如:銀行專用的應用程式),並於此應用程式中輸入註冊/登入資訊。註冊/登入資訊例如但不限於:身分證字號、出生年月日、***卡號以及安全驗證碼等資料,以及同意應用程式可以持續讀取電子裝置的全球衛星定位資訊、透過WiFi獲取的定位資訊及讀取網頁IP位址等位置資訊。使用者於電子裝置中執行完上述步驟後,通過電子裝置而將使用者所輸入的註冊/登入資訊傳送到使用***的交易系統100中。First, the user must first download the specified application (for example, a bank-specific application) in the electronic device, and enter the registration/login information in this application. Registration/login information such as but not limited to: ID card number, date of birth, credit card number and security verification code, etc., and agree that the application can continuously read global satellite positioning information of electronic devices, positioning information obtained through WiFi and Read location information such as web page IP address. After performing the above steps in the electronic device, the user transmits the registration/login information input by the user to the transaction system 100 using a credit card through the electronic device.

當處理單元130接收到由此應用程式首次傳送的註冊/登入資訊時,處理單元130會連線至銀行的資料庫,並於銀行的資料庫中獲取相應註冊/登入資訊中的使用者身分資訊的手機號碼(即:經過銀行認證並儲存的手機號碼)。處理單元130會發送簡訊驗證碼至此手機號碼之中。When the processing unit 130 receives the registration/login information transmitted by this application for the first time, the processing unit 130 will connect to the bank's database and obtain the user identity information in the corresponding registration/login information in the bank's database Mobile phone number (ie: a mobile phone number that has been certified and stored by the bank). The processing unit 130 sends the SMS verification code to the mobile phone number.

當使用者通過其手機接收到此簡訊驗證碼時,必須於電子裝置的應用程式中輸入此簡訊驗證碼。處理單元130於收到使用者的簡訊驗證碼時,會比對其所發送至手機號碼的簡訊驗證碼以及接收到來自使用者輸入的簡訊驗證碼是否一致。當發送至手機號碼的簡訊驗證碼以及接收到來自使用者輸入的簡訊驗證碼一致時,表示確實是由使用者本人在此應用程式中執行的註冊/登入行為,因而完成身分驗證程序。處理單元130依據此註冊/登入資訊、安裝日期及時間以及手機軟、硬體資訊等內容,以雜湊演算法(Hash function)進行運算,以產生唯一的設備預設識別代碼。處理單元130並將使用者的註冊/登入資訊以及此設備預設識別代碼儲存至儲存單元120,藉此以綁定使用者電子裝置中的應用程式。在本揭露的一實施例中,每當使用者移除此應用程式並重新安裝,或者當使用者更換電子裝置並重新下載此應用程式時,都會被視為是第一次透過應用程式進行註冊/登入。也就是說,每當使用者移除此應用程式並重新安裝,或者當使用者更換電子裝置並重新下載此應用程式時,都必須要重新通過電子裝置而於使用***的交易系統100中進行登入,並讓使用***的交易系統100執行身分認證程序以及更新設備預設識別代碼。藉此,以確保應用程式確實是由使用者重新下載與登入的。When the user receives the SMS verification code through their mobile phone, they must enter the SMS verification code in the application of the electronic device. When the processing unit 130 receives the user's SMS verification code, it will compare with the SMS verification code sent to the mobile phone number and the SMS verification code received from the user. When the SMS verification code sent to the mobile phone number and the SMS verification code received from the user are consistent, it means that the registration/login action performed by the user himself in this application is completed, thus completing the identity verification process. The processing unit 130 performs calculation with a hash function (Hash function) according to the registration/login information, installation date and time, mobile phone software and hardware information, etc. to generate a unique device preset identification code. The processing unit 130 stores the user's registration/login information and the device's default identification code in the storage unit 120, thereby binding the application in the user's electronic device. In an embodiment of the present disclosure, whenever the user removes the application and reinstalls it, or when the user replaces the electronic device and downloads the application again, it will be regarded as the first time to register through the application /Sign in. In other words, whenever the user removes the application and reinstalls it, or when the user replaces the electronic device and downloads the application again, it is necessary to log in to the transaction system 100 using a credit card through the electronic device again , And allow the transaction system 100 using a credit card to perform the identity authentication procedure and update the device preset identification code. This is to ensure that the application is indeed re-downloaded and logged in by the user.

於經過身分驗證程序之後,使用者即可在此應用程式中設定地理範圍設定(例如:國內、國外、美加、歐洲等)。在本實施例中,為了維持交易的安全性,若使用者並未在此應用程式中設定地理範圍設定時,此應用程式會將地理範圍設定預設為國內。然在其他實施例中,應用程式也可以將此地理範圍設定維持空值,並當處理單元130判斷此地理範圍設定為空值時,拒絕所有的交易請求。After going through the identity verification process, users can set the geographic range settings in this application (for example: domestic, foreign, American, Canadian, European, etc.). In this embodiment, in order to maintain the security of the transaction, if the user does not set the geographic range setting in this application, the application will preset the geographic range setting to domestic. However, in other embodiments, the application may also maintain the null value of the geographic range setting, and when the processing unit 130 determines that the geographic range is set to the null value, reject all transaction requests.

為了減少對使用者的干擾,在本實施例中,使用者重新下載此應用程式,並經過身分驗證程序後,處理單元130可以保留先前應用程式中所設定的地理範圍設定,以降低使用者設定的麻煩性。In order to reduce the interference to the user, in this embodiment, after the user downloads the application again, and after undergoing the identity verification process, the processing unit 130 can retain the geographical range setting set in the previous application to reduce the user setting Troublesome.

綜上所述,本揭露提供的使用***的交易系統及使用***的交易方法會通過相應商家網站的交易位置與使用者的電子裝置的位置作為安全認證的依據,並通過多種定位方式交叉比對使用者的位置與交易的位置。當交易位置、使用者的位置一致時,才會完成交易。藉此使用者即便不記得額外的密碼,仍然可以強化***交易的安全性,降低***被盜刷的可能。同時,也維持了使用者在執行***交易時的體驗。In summary, the transaction system using a credit card and the transaction method using a credit card provided by this disclosure will use the transaction location of the corresponding merchant website and the location of the user's electronic device as a basis for security authentication, and cross-check through multiple positioning methods The location of the user and the location of the transaction. The transaction will only be completed when the transaction location and the user's location match. Therefore, even if the user does not remember the extra password, the security of the credit card transaction can be strengthened, and the possibility of the credit card being stolen is reduced. At the same time, it also maintains the user's experience when performing credit card transactions.

雖然本發明已以實施例揭露如上,然其並非用以限定本發明,任何所屬技術領域中具有通常知識者,在不脫離本發明的精神和範圍內,當可作些許的更動與潤飾,故本發明的保護範圍當視後附的申請專利範圍所界定者為準。Although the present invention has been disclosed as above with examples, it is not intended to limit the present invention. Any person with ordinary knowledge in the technical field can make some changes and modifications without departing from the spirit and scope of the present invention. The scope of protection of the present invention shall be subject to the scope defined in the appended patent application.

100‧‧‧使用***的交易系統110‧‧‧通訊單元120‧‧‧儲存單元130‧‧‧處理單元S210~S280‧‧‧步驟100‧‧‧Transaction system using credit card 110‧‧‧Communication unit 120‧‧‧Storage unit 130‧‧‧Processing unit S210~S280‧‧‧Step

圖1繪示本揭露一實施例的使用***的交易系統的架構圖。 圖2繪示本揭露一實施例使用***的交易系統運行使用***的交易方法的流程圖。FIG. 1 illustrates an architecture diagram of a transaction system using a credit card according to an embodiment of the disclosure. FIG. 2 illustrates a flowchart of an embodiment of the present disclosure using a credit card transaction system to run a credit card transaction method.

100‧‧‧使用***的交易系統 100‧‧‧Credit card transaction system

110‧‧‧通訊單元 110‧‧‧Communication unit

120‧‧‧儲存單元 120‧‧‧storage unit

130‧‧‧處理單元 130‧‧‧Processing unit

Claims (8)

一種使用***的交易系統,包括:通訊單元,接收與傳送訊息;儲存單元,儲存多筆個人交易資訊,其中每一該個人交易資訊包括身分資訊、設備預設識別代碼及地理範圍設定,該設備預設識別代碼對應至電子裝置的應用程式,且該地理範圍設定為預先設定允許的交易範圍;處理單元,連接於該通訊單元及該儲存單元,其中該處理單元還於接收到交易請求時,依據該交易請求獲取相應的個人交易資訊,並判斷該交易請求的交易位置是否符合該地理範圍設定,該處理單元還於該交易位置符合該地理範圍設定時,依據該設備預設識別代碼發送確認訊息至該電子裝置,該處理單元還於一預設時間內接收到來自該電子裝置的回覆訊息,判斷該回覆訊息對應的回覆位置是否符合該交易位置,其中,該處理單元還於該回覆位置符合該交易位置時,依據該交易請求進行交易,其中,該處理單元還依據該交易請求中的交易網頁位置資訊判斷該交易位置,並依據該回覆訊息中的回覆位置資訊判斷該回覆位置,並且,該交易網頁位置資訊至少包括該交易請求來源的網頁IP位址,該回覆位置資訊至少包括該電子裝置的全球定位系統位置以及該電子裝置通過WiFi定位所獲取的定位位置的其中之一。 A transaction system using a credit card, including: a communication unit to receive and transmit messages; a storage unit to store multiple pieces of personal transaction information, wherein each of the personal transaction information includes identity information, device default identification code, and geographic range settings, the device The preset identification code corresponds to the application program of the electronic device, and the geographical range is set to the allowed transaction range set in advance; the processing unit is connected to the communication unit and the storage unit, where the processing unit also receives the transaction request, Obtain the corresponding personal transaction information according to the transaction request, and determine whether the transaction position of the transaction request conforms to the geographical range setting, and the processing unit also sends confirmation according to the preset identification code of the device when the transaction position conforms to the geographical range setting Message to the electronic device, the processing unit also receives a reply message from the electronic device within a preset time to determine whether the reply position corresponding to the reply message matches the transaction position, wherein the processing unit is still at the reply position When the transaction location is met, the transaction is performed according to the transaction request, wherein the processing unit also determines the transaction location based on the transaction webpage location information in the transaction request, and the response location information in the response message to determine the response location, and The location information of the transaction webpage at least includes the IP address of the webpage of the source of the transaction request, and the location information of the reply at least includes one of the global positioning system location of the electronic device and the positioning location obtained by the electronic device through WiFi positioning. 如申請專利範圍第1項所述的使用***的交易系統,其中該回覆訊息包括第一回覆位置訊息以及第二回覆位置訊息,該處理單元還依據該第一回覆位置訊息以及該第二回覆位置訊息獲取相應的第一回覆位置及第二回覆位置,並判斷該第一回覆位置、該第二回覆位置以及該交易位置是否一致,若該第一回覆位置、該第二回覆位置以及該交易位置中的任何一個與其他兩者不一致,該處理單元傳送交易失敗的訊息至該電子裝置。 The transaction system using a credit card as described in item 1 of the patent application scope, wherein the reply message includes a first reply location message and a second reply location message, and the processing unit further depends on the first reply location message and the second reply location The message obtains the corresponding first reply position and second reply position, and judges whether the first reply position, the second reply position and the transaction position are consistent, if the first reply position, the second reply position and the transaction position If any one of them is inconsistent with the other two, the processing unit sends a transaction failure message to the electronic device. 如申請專利範圍第2項所述的使用***的交易系統,其中該第一回覆位置訊息至少包括該電子裝置的全球衛星定位資訊,該第二回覆位置訊息至少包括該電子裝置透過WiFi獲取的定位資訊。 The transaction system using a credit card as described in item 2 of the patent application scope, wherein the first reply location information includes at least the global satellite positioning information of the electronic device, and the second reply location information includes at least the location obtained by the electronic device through WiFi News. 如申請專利範圍第1項所述的使用***的交易系統,其中該處理單元還於接收到由該電子裝置的應用程式首次傳送的註冊/登入資訊時執行身分認證程序,並更新該設備預設識別代碼。 The transaction system using a credit card as described in item 1 of the patent application scope, wherein the processing unit also performs an identity authentication process when receiving the registration/login information transmitted by the application of the electronic device for the first time, and updates the device preset Identification code. 一種使用***的交易方法,包括:接收交易請求;依據該交易請求獲取相應的個人交易資訊,並判斷該交易請求的交易位置是否符合該個人交易資訊中的該地理範圍設定,其中該個人交易資訊包括身分資訊、設備預設識別代碼及地理範圍設定,該設備預設識別代碼對應至電子裝置的應用程式,且該地 理範圍設定為預先設定允許的交易範圍;當該交易位置符合該地理範圍設定,依據該設備預設識別代碼發送確認訊息至該電子裝置;於一預設時間內接收到來自該電子裝置的回覆訊息;判斷該回覆訊息對應的回覆位置是否符合該交易位置;以及當該回覆位置符合該交易位置時,依據該交易請求進行交易,其中,於判斷該交易請求的該交易位置是否符合該地理範圍設定的步驟中,還包括:依據該交易請求中的交易網頁位置資訊判斷該交易位置,且於判斷該回覆訊息對應的該回覆位置是否符合該交易位置中,包括依據該回覆訊息中的回覆位置資訊判斷該回覆位置,其中該交易網頁位置資訊至少包括該交易請求來源的交易網頁IP位址位置,該回覆位置資訊至少包括該電子裝置的全球定位系統位置以及該電子裝置通過WiFi定位所獲取的定位位置的其中之一。 A transaction method using a credit card includes: receiving a transaction request; obtaining corresponding personal transaction information according to the transaction request, and determining whether the transaction location of the transaction request conforms to the geographical range setting in the personal transaction information, wherein the personal transaction information Including identity information, device default identification code and geographic range settings, the device default identification code corresponds to the application of the electronic device, and the place The management range is set to the pre-set allowed transaction range; when the transaction location meets the geographical range setting, a confirmation message is sent to the electronic device according to the device's preset identification code; a reply from the electronic device is received within a preset time Message; determine whether the reply location corresponding to the reply message matches the transaction location; and when the reply location matches the transaction location, conduct a transaction based on the transaction request, wherein, in determining whether the transaction location of the transaction request meets the geographic range The setting step also includes: judging the transaction location according to the transaction webpage location information in the transaction request, and determining whether the reply location corresponding to the reply message matches the transaction location, including according to the reply location in the reply message The information determines the reply location, wherein the transaction webpage location information includes at least the transaction webpage IP address location of the transaction request source, the reply location information includes at least the electronic device's global positioning system location and the electronic device's location obtained through WiFi positioning Position one of them. 如申請專利範圍第5項所述的使用***的交易方法,其中該回覆訊息包括第一回覆位置訊息以及第二回覆位置訊息,並且包括:依據該第一回覆位置訊息以及該第二回覆位置訊息獲取相應的第一回覆位置及第二回覆位置,並判斷該第一回覆位置、該第二回覆位置以及該交易位置是否一致;以及 若該第一回覆位置、該第二回覆位置以及該交易位置中的任何一個與其他兩者不一致,該處理單元傳送交易失敗的訊息至該電子裝置。 The transaction method using a credit card as described in item 5 of the patent application scope, wherein the reply message includes a first reply location message and a second reply location message, and includes: based on the first reply location message and the second reply location message Obtain corresponding first and second reply positions, and determine whether the first reply position, the second reply position, and the transaction position are consistent; and If any one of the first reply position, the second reply position, and the transaction position is inconsistent with the other two, the processing unit sends a transaction failure message to the electronic device. 如申請專利範圍第6項所述的使用***的交易方法,其中該第一回覆位置訊息至少包括該電子裝置的全球衛星定位資訊,該第二回覆位置訊息至少包括該電子裝置透過WiFi獲取的定位資訊。 The transaction method using a credit card as described in item 6 of the patent application scope, wherein the first reply location information includes at least global satellite positioning information of the electronic device, and the second reply location information includes at least the location obtained by the electronic device through WiFi News. 如申請專利範圍第5項所述的使用***的交易方法,更包括:接收到由該電子裝置的應用程式首次傳送的註冊/登入資訊時執行身分認證程序,並更新該設備預設識別代碼。 The transaction method using a credit card as described in item 5 of the patent application scope further includes: performing an identity authentication process when receiving the registration/login information transmitted by the application of the electronic device for the first time, and updating the default identification code of the device.
TW107111030A 2018-03-29 2018-03-29 System and method of transaction using credit card TWI693570B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW107111030A TWI693570B (en) 2018-03-29 2018-03-29 System and method of transaction using credit card

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW107111030A TWI693570B (en) 2018-03-29 2018-03-29 System and method of transaction using credit card

Publications (2)

Publication Number Publication Date
TW201942832A TW201942832A (en) 2019-11-01
TWI693570B true TWI693570B (en) 2020-05-11

Family

ID=69184623

Family Applications (1)

Application Number Title Priority Date Filing Date
TW107111030A TWI693570B (en) 2018-03-29 2018-03-29 System and method of transaction using credit card

Country Status (1)

Country Link
TW (1) TWI693570B (en)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103164802A (en) * 2013-03-14 2013-06-19 北京恒远创智信息技术有限公司 Position detection based method and system for preventing illegal electronic transaction
TWI476713B (en) * 2010-07-29 2015-03-11 Intel Corp Method, server and tangible machine readable medium for location-based payment authorization
US20150170135A1 (en) * 2009-08-19 2015-06-18 Mastercard International Incorporated Location controls on payment card transactions
CN105550873A (en) * 2015-12-02 2016-05-04 努比亚技术有限公司 Device and method of controlling bank card trading behavior
CN107833033A (en) * 2017-11-01 2018-03-23 深圳位置网科技有限公司 A kind of method that registration card transaction illegal activities are docked with Skynet system
TWM563032U (en) * 2018-03-29 2018-07-01 兆豐國際商業銀行股份有限公司 System of transaction using credit card

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150170135A1 (en) * 2009-08-19 2015-06-18 Mastercard International Incorporated Location controls on payment card transactions
TWI476713B (en) * 2010-07-29 2015-03-11 Intel Corp Method, server and tangible machine readable medium for location-based payment authorization
CN103164802A (en) * 2013-03-14 2013-06-19 北京恒远创智信息技术有限公司 Position detection based method and system for preventing illegal electronic transaction
CN105550873A (en) * 2015-12-02 2016-05-04 努比亚技术有限公司 Device and method of controlling bank card trading behavior
CN107833033A (en) * 2017-11-01 2018-03-23 深圳位置网科技有限公司 A kind of method that registration card transaction illegal activities are docked with Skynet system
TWM563032U (en) * 2018-03-29 2018-07-01 兆豐國際商業銀行股份有限公司 System of transaction using credit card

Also Published As

Publication number Publication date
TW201942832A (en) 2019-11-01

Similar Documents

Publication Publication Date Title
US10848564B2 (en) Device specific remote disabling of applications
US10621326B2 (en) Identity authentication method, server, and storage medium
AU2011342282B2 (en) Authenticating transactions using a mobile device identifier
US20190287109A1 (en) Method and apparatus for facilitating performing payment option aggregation utilizing an automated authentication engine
CA3026227A1 (en) Biometric identification and verification among iot devices and applications
US20140279523A1 (en) System and Method for Authenticating Payment Transactions
CN107682336B (en) Geographic position-based identity authentication method and device
US11240220B2 (en) Systems and methods for user authentication based on multiple devices
JP2012531689A (en) Device, system, and method for performing location-based payment authorization
WO2022193594A1 (en) Card binding method, terminal device, authentication server and storage medium
US20180225671A1 (en) Method and apparatus for facilitating performing payment option aggregation utilizing an automated authentication engine
CN107679383B (en) Identity verification method and device based on geographic position and touch area
CN108431843B (en) Transaction processing method and device
TWI693570B (en) System and method of transaction using credit card
TWM563032U (en) System of transaction using credit card
US20220230166A1 (en) System, method, and computer program product for authenticating a transaction based on behavioral biometric data
US11792165B2 (en) Supporting data processing transactions using machine to machine (M2M) data transfer
US11784981B2 (en) Data processing transactions using machine to machine (M2M) data transfer
US11265370B1 (en) Machine to machine (M2M) data transfer between data servers
WO2019191365A1 (en) Method and apparatus for facilitating performing payment option aggregation utilizing an automated authentication engine
TWI775113B (en) Transaction examining system and method thereof
US11930014B2 (en) Information security using multi-factor authorization
US10812459B2 (en) Method for verifying identity during virtualization
KR101561686B1 (en) Method for Providing OTP based on Location
TWM603157U (en) Transaction verification system