WO2018149367A1 - 交易支付方法及*** - Google Patents

交易支付方法及*** Download PDF

Info

Publication number
WO2018149367A1
WO2018149367A1 PCT/CN2018/075998 CN2018075998W WO2018149367A1 WO 2018149367 A1 WO2018149367 A1 WO 2018149367A1 CN 2018075998 W CN2018075998 W CN 2018075998W WO 2018149367 A1 WO2018149367 A1 WO 2018149367A1
Authority
WO
WIPO (PCT)
Prior art keywords
ciphertext
biometric
code
transaction
smart terminal
Prior art date
Application number
PCT/CN2018/075998
Other languages
English (en)
French (fr)
Inventor
孙权
Original Assignee
***股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ***股份有限公司 filed Critical ***股份有限公司
Publication of WO2018149367A1 publication Critical patent/WO2018149367A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3274Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks

Definitions

  • the present invention relates to the field of electronic commerce technology, and more particularly to a transaction payment method and system.
  • Two-dimensional code scan code payment can be divided into two modes: main scan and swept mode.
  • the sweep mode is widely used in WeChat payment and Alipay.
  • the client application of the mobile terminal encodes the user account information into a two-dimensional code.
  • the barcode the cashier terminal scan code to determine the user account information to complete the payment transaction.
  • QR code information/barcode is easily copied, which leads to leakage of user account information, thereby posing a risk of fraudulent use and misappropriation.
  • the QR code/barcode does not simply display the account information/transaction information in plain text, but there is still a risk of being easily broken, giving the criminals a chance.
  • the present invention provides a technical solution as follows:
  • a transaction payment method comprising: a registration phase, comprising the steps of: the biometric authentication server acquires a biometric of the registered user from the smart terminal based on the registration request of the smart terminal, and the transaction payment server sends the public key to the smart terminal based on the registration request;
  • the biometric feature is obtained by collecting the biometrics collection device of the smart terminal; and the transaction phase includes the following steps: the smart terminal collects the biometric characteristics of the current user, and generates the first ciphertext based on at least the public key and the biometric characteristics of the current user.
  • the intelligent terminal generates a Hanxin code based on the first ciphertext, generates a two-dimensional code based on the user information of the current user, and displays the Hanxin code and the two-dimensional code for scanning and recognizing the cash register terminal;
  • the transaction payment server obtains the cash register from the cash register terminal.
  • the first ciphertext and the user information scanned and identified by the terminal, and decrypting the first ciphertext by using the private key to obtain the biometric feature of the current user and forwarding to the biometric authentication server; and the transaction payment server is based on the biometric authentication server Current user's biometric authentication And user information to complete the transaction.
  • the Hanxin code and the two-dimensional code are respectively displayed on different parts of the screen or display window of the smart terminal.
  • the Hanxin code is displayed on the central portion of the screen or display window, and the two-dimensional code is displayed on the peripheral portion of the screen or display window.
  • the Hanxin code and the two-dimensional code are displayed synchronously.
  • the smart terminal is further based on the time code of the current time when generating the first ciphertext.
  • the smart terminal performs a hash algorithm on the current user's biometrics to obtain a digest, and encrypts the digest with the public key to generate a first ciphertext.
  • the invention also discloses a transaction payment system, comprising: a transaction execution unit, communicatively coupled with at least one intelligent terminal, comprising: a biometric authentication server for authenticating biometrics of the current user; and a transaction payment server
  • a transaction execution unit communicatively coupled with at least one intelligent terminal, comprising: a biometric authentication server for authenticating biometrics of the current user; and a transaction payment server
  • the cash register terminal acquires the first ciphertext and the user information of the current user, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user and forwards the biometric to the biometric authentication server, and the transaction payment server is further based on the biometric authentication server.
  • the authentication result is completed to complete the transaction; at least one cash register terminal, the cash register terminal scans and identifies the Hanxin code and the two-dimensional code displayed by the smart terminal; and at least one smart terminal, the intelligent terminal includes a biometrics collection device, and the smart terminal is based at least on the transaction payment
  • the first ciphertext is generated by the public key delivered by the server and the biometric feature of the current user, and the Chinese cipher code is generated based on the first ciphertext, and the two-dimensional code is generated based on the user information.
  • the transaction payment method and system provided by the invention can effectively prevent the information such as the QR code/barcode from being copied, thereby bringing security risks to the user account and realizing the biometric information of the user while realizing the electronic transaction in a simple manner.
  • the authentication is implemented to prevent the criminals from stealing the user's smart terminal.
  • the transaction payment system can realize more secure electronic transactions, protect user account security, and bring a good user experience.
  • FIG. 1 is a schematic flowchart diagram of a transaction payment method according to a first embodiment of the present invention.
  • FIG. 2 is a block diagram showing a transaction payment system provided by a second embodiment of the present invention.
  • a first embodiment of the present invention provides a transaction payment method, which is implemented by a smart terminal generating a two-dimensional code for scanning by a cashier terminal.
  • the method includes two phases: a registration phase and a transaction phase.
  • the registration phase includes the step S10: the biometric authentication server acquires the biometric of the registered user based on the registration request of the smart terminal, and the transaction payment server delivers the public key to the smart terminal based on the registration request.
  • the biometrics are obtained by collecting biometrics collection devices of the intelligent terminal.
  • the user who wants to register submits a registration request to the biometric authentication server through the smart terminal, and the biometric authentication server instructs the smart terminal to collect the biometric characteristics of the registered user, and the biometric feature is uploaded to the biometric authentication server after the smart terminal collects, and the biometric feature is collected.
  • the authentication server saves the biometric of the registered user and instructs the transaction payment server to deliver the public key to the smart terminal.
  • the registration phase only needs to be performed once, and the transaction phase can be performed as many times as many times.
  • transaction phase information exchange occurs between the intelligent terminal and the cashier terminal through scanning, and the cash register terminal and the transaction payment server interact with each other through network communication, and the transaction phase specifically includes the following steps.
  • Step S11 The smart terminal collects biometric features of the current user, and generates a first ciphertext based on at least the public key and the biometric characteristics of the current user.
  • the smart terminal after collecting the biometrics of the current user, the smart terminal performs a hash algorithm on the biometrics of the current user to obtain a digest, and encrypts the digest by using the public key sent by the transaction payment server in the registration phase to generate the first A ciphertext.
  • the smart terminal may also be based on the time code of the current time when generating the first ciphertext. Further, in the subsequent step, the transaction payment server can judge the timeliness of the transaction by using the time code, which can also increase the security of the transaction.
  • the smart terminal can also combine the device ID of the mobile terminal when generating the first ciphertext.
  • the device ID of the mobile terminal is not replaceable.
  • it can be beneficial to increase the security of user information (such as an account).
  • Step S12 The intelligent terminal generates a Hanxin code based on the first ciphertext, generates a two-dimensional code based on the user information of the current user, and displays the Hanxin code and the two-dimensional code for scanning and identifying by the cash register terminal.
  • the Hanxin code and the two-dimensional code can be respectively displayed on different parts of the screen or display window of the smart terminal.
  • the Hanxin code is displayed in the central part of the screen or the display window, and the two-dimensional code is displayed on the peripheral part of the screen or the display window; or, the Hanxin code is displayed on the left part, and the two-dimensional code is displayed on the right part.
  • the smart terminal when the smart terminal displays the Hanxin code and the two-dimensional code, the smart terminal can be scaled, and the two can be displayed in different time sequences.
  • the two-dimensional code surrounds the Hanxin code, and the two are synchronously displayed in the display window of the smart terminal for scanning and identification by the cash register terminal.
  • Step S13 The transaction payment server acquires the first ciphertext and the user information scanned and identified by the cash register terminal, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user.
  • the transaction payment server decrypts the first ciphertext by using the private key to obtain the current user. Biological characteristics. In this process, although the cashier terminal obtains the first ciphertext, the first ciphertext cannot be parsed or saved. The transaction payment server then forwards the current user's biometrics to the biometric authentication server.
  • Step S14 The transaction payment server completes the transaction based on the result of the biometric authentication of the current user and the user information by the biometric authentication server.
  • the biometric authentication server first authenticates the biometrics of the current user, and notifies the transaction payment server of the authentication result, and the transaction payment server completes the transaction based on the authentication result and the user information.
  • the biometric authentication server will give a negative authentication result, and the transaction payment server will reject the current transaction; otherwise, the biometric authentication server will give With a positive certification result, the transaction payment server will continue the current transaction and realize the circulation of funds.
  • the transaction payment method can effectively prevent information such as a two-dimensional code/barcode from being copied while realizing electronic transactions in a simple manner, and can also authenticate biometric information of the user. These measures help to improve the security of electronic transactions and effectively protect user accounts from misappropriation.
  • a second embodiment of the present invention provides a transaction payment system including a transaction execution unit 20, a plurality of cashier terminals 21 (only one is shown in the drawings for simplicity), and a plurality of smart terminals 22 (for simplicity, attached) Only one is shown in the figure, as shown in Figure 2.
  • the transaction execution unit 20 and the plurality of smart terminals 22 can communicate using the mobile communication network, and the transaction execution unit 20 and the plurality of cashier terminals 21 can communicate using the Internet (for example, the Internet).
  • the Internet for example, the Internet
  • the transaction execution unit 20 includes a biometric authentication server 201 and a transaction payment server 202.
  • the smart terminal 22 includes a biometrics collection device for collecting biometric features of the user, such as fingerprints, irises, voice prints, facial images, and the like.
  • the smart terminal 22 generates the first ciphertext based on at least the public key sent by the transaction payment server 202 during the user registration phase and the biometric feature of the current user, and generates a Chinese cryptographic code based on the first ciphertext and generates two based on the user information.
  • the code is displayed, and the Hanxin code and the two-dimensional code are displayed for scanning and recognition by the cash register terminal 21.
  • the cash register terminal 21 includes a scanning device to scan and recognize the Hanxin code and the two-dimensional code displayed by the smart terminal 22.
  • the transaction payment server 202 acquires the first ciphertext and the user information of the current user from the cash register terminal 21, and decrypts the first ciphertext by using the private key to obtain the biometric feature of the current user and forwards the biometric to the biometric authentication server 201.
  • the transaction payment server 202 also completes the transaction based on the authentication result of the biometric authentication server 201.
  • the smart terminal 22 can display the Hanxin code and the two-dimensional code on different parts of the screen or the display window, respectively.
  • the smart terminal 22 displays the Hanxin code on the central portion of the screen or the display window, and displays the two-dimensional code on the peripheral portion of the screen or the display window. Further, the smart terminal 22 preferably simultaneously displays the Hanxin code and the two-dimensional code.
  • the transaction execution unit 20 is disposed at the financial institution end (local end), and the cash register terminal 21 is disposed at the remote end.
  • the above transaction payment system can be deployed based on a cloud computing system to facilitate system upgrade and maintenance.
  • the transaction payment system has low implementation cost and is convenient for popularization and application.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

本发明涉及一种交易支付方法,注册阶段包括:生物特征认证服务器基于智能终端的注册请求而获取注册用户的生物特征,交易支付服务器向智能终端下发公钥;交易阶段包括:智能终端至少基于公钥及当前用户的生物特征而生成第一密文;智能终端基于第一密文生成汉信码、基于当前用户的用户信息生成二维码;交易支付服务器获取经收银终端扫描并识别的第一密文及用户信息,并利用私钥对第一密文进行解密,以获得当前用户的生物特征;以及,交易支付服务器基于生物特征认证服务器对当前用户的生物特征认证的结果及用户信息来完成交易。其能够实现更加安全的电子交易、保护用户帐户安全。

Description

交易支付方法及*** 技术领域
本发明涉及电子商务技术领域,更具体地说,涉及一种交易支付方法及***。
背景技术
现今,扫码支付在生活中得到了广泛应用。二维码扫码支付又可分为主扫和被扫两种模式,其中被扫模式在微信支付、支付宝中被广泛使用,例如,移动终端的客户端应用将用户帐户信息编码成二维码或者条形码,收银终端扫码来确定用户帐户信息以完成支付交易。
该支付方式的一个重要问题是存在安全性问题,二维码信息/条形码容易被复制,进而导致用户帐户信息泄露,从而带来冒用、盗用风险。一些应用虽然对帐户信息/交易信息进行了处理,使得二维码/条形码不是简单地以明文显示帐户信息/交易信息,但仍然存在比较容易攻破的风险,给不法分子可乘之机。
另一方面,现有技术中,已存在利用生物特征(例如指纹)来验证交易的方案,但是,一些收银终端可以直接获取甚至保留用户的指纹特征数据,这同样给用户带来了安全风险。
发明内容
本发明的目的在于以供一种更加安全可靠的、基于扫描二维码的交易支付方法。
为实现上述目的,本发明提供一种技术方案如下:
一种交易支付方法,包括:注册阶段,包括如下步骤:生物特征认证服务器基于智能终端的注册请求而从智能终端获取注册用户的生物特征,交易支付服务器基于注册请求向智能终端下发公钥;其中生物特征由智能终端的生物特征采集设备进行采集而得到;以及交易阶段,包括如下步骤:智能终端采集当前用户的生物特征,并至少基于公钥及当前用户的生物特征而生成第一密文;智能终端基于第一密文生成汉信码、基于当前用户的用户信息生成二维码,并显示汉信码及二维码以供收银终端扫描并识别;交易支付服务器从收银终端获取经收银终端扫描并 识别的第一密文及用户信息,并利用私钥对第一密文进行解密,以获得当前用户的生物特征并转送至生物特征认证服务器;以及交易支付服务器基于生物特征认证服务器对当前用户的生物特征认证的结果及用户信息来完成交易。
优选地,汉信码及二维码分别显示在智能终端的屏幕或显示窗口的不同部分。
优选地,汉信码显示于屏幕或显示窗口的中央部分,二维码显示于屏幕或显示窗口的***部分。
优选地,汉信码及二维码同步显示。
优选地,智能终端在生成第一密文时还基于当前时间的时间码。
优选地,智能终端对当前用户的生物特征执行哈希算法而获得摘要,并利用公钥对摘要进行加密而生成第一密文。
本发明还公开一种交易支付***,包括:交易执行单元,与至少一智能终端在通信上耦合,其包括:生物特征认证服务器,用于对当前用户的生物特征进行认证;交易支付服务器,从收银终端获取第一密文及当前用户的用户信息,并利用私钥对第一密文进行解密,以获得当前用户的生物特征并转送至生物特征认证服务器,交易支付服务器还基于生物特征认证服务器的认证结果来完成交易;至少一收银终端,收银终端扫描并识别智能终端所显示的汉信码及二维码;以及至少一智能终端,智能终端包括生物特征采集设备,智能终端至少基于交易支付服务器下发的公钥及当前用户的生物特征而生成第一密文,以及基于第一密文生成汉信码、基于用户信息生成二维码。
本发明所提供的交易支付方法及***,在以简单方式实现电子交易的同时,能够有效防止二维码/条形码等信息被复制从而给用户帐户带来安全隐患,还能够对用户的生物特征信息进行认证从而防止不法分子盗用用户的智能终端,进而,该交易支付***能够实现更加安全的电子交易、保护用户帐户安全,也给用户带来了良好的使用体验。
附图说明
图1示出本发明第一实施例提供的交易支付方法的流程示意图。
图2示出本发明第二实施例提供的交易支付***的框图。
具体实施方式
如图1所示,本发明第一实施例提供一种交易支付方法,其以智能终端生成二维码供收银终端扫描的方式来实现,该方法包括两个阶段:注册阶段与交易阶段。
注册阶段包括步骤S10:生物特征认证服务器基于智能终端的注册请求而获取注册用户的生物特征,交易支付服务器基于注册请求向智能终端下发公钥。其中生物特征由智能终端的生物特征采集设备进行采集而得到。
具体地,希望注册的用户通过所持智能终端向生物特征认证服务器提交注册请求,生物特征认证服务器指示智能终端采集注册用户的生物特征,智能终端采集后将生物特征上传到生物特征认证服务器,生物特征认证服务器保存该注册用户的生物特征,并指示交易支付服务器向该智能终端下发公钥。
上述注册阶段完成后,即可进入交易阶段。本领域技术人员可以理解,注册阶段只需进行一次,而交易阶段可以进行任意多次。
在交易阶段中,智能终端与收银终端之间通过扫描的方式发生信息交互,收银终端与交易支付服务器之间通过网络通信发生信息交互,交易阶段具体包括如下各步骤。
步骤S11、智能终端采集当前用户的生物特征,并至少基于公钥及当前用户的生物特征而生成第一密文。
具体地,作为示例,智能终端采集当前用户的生物特征后,对当前用户的生物特征执行哈希算法而获得摘要,并利用交易支付服务器在注册阶段下发的公钥对摘要进行加密而生成第一密文。
进一步地,智能终端在生成第一密文时还可以基于当前时间的时间码。进而,在后续步骤中,交易支付服务器可以通过时间码来判断交易的时效性,这也能够增加交易的安全性。
此外,智能终端在生成第一密文时还可以结合移动终端的设备ID。通常,移动终端的设备ID是不可更换的。结合了设备ID后,能够有利于增加用户信息(例如帐户)的安全性。
步骤S12、智能终端基于第一密文生成汉信码、基于当前用户的用户信息生成二维码,并显示汉信码及二维码以供收银终端扫描并识别。
在该步骤中,汉信码及二维码可以分别显示在智能终端的屏幕或显示窗口的不同部分。例如,汉信码显示于屏幕或显示窗口的中央部分,二维码显示于屏幕或显示窗口的***部分;或者,汉信码显示于左侧部分,二维码显示于右侧部分。
可以理解,智能终端在显示汉信码、二维码时,可以对两者进行缩放,还可以以不同的时间顺序来先后显示两者。
优选情况下,二维码环绕汉信码,两者同步显示于智能终端的显示窗口内,供收银终端进行扫描、识别。
步骤S13、交易支付服务器获取经收银终端扫描并识别的第一密文及用户信息,并利用私钥对第一密文进行解密,以获得当前用户的生物特征。
具体地,收银终端扫描并识别汉信码、二维码后,将第一密文及用户信息上送至交易支付服务器,交易支付服务器利用私钥对第一密文进行解密,获得当前用户的生物特征。在此过程中,收银终端虽然获得第一密文,但无法解析或保存第一密文。随后,交易支付服务器将当前用户的生物特征转送到生物特征认证服务器。
步骤S14、交易支付服务器基于生物特征认证服务器对当前用户的生物特征认证的结果及用户信息来完成交易。
其中,生物特征认证服务器首先对当前用户的生物特征进行认证,并将认证结果通知交易支付服务器,交易支付服务器再基于认证结果、用户信息来完成交易。
具体地,若当前用户的生物特征未在已注册用户的生物特征库中得到匹配,生物特征认证服务器将给出否定的认证结果,交易支付服务器将拒绝当前交易;反之,生物特征认证服务器将给出肯定的认证结果,交易支付服务器将继续进行当前交易,实现款项的流转。
该交易支付方法在以简单方式实现电子交易的同时,能够有效防止二维码/条形码等信息被复制,还能够对用户的生物特征信息进行认证。这些措施有利于提高电子交易的安全性、并有效保护用户帐户不受盗用。
本发明第二实施例提供一种交易支付***,其包括交易执行单元20、多个收银终端21(为简单起见,附图中仅示出一个)以及多个智能终端22(为简 单起见,附图中仅示出一个),如图2所示。
其中,交易执行单元20与多个智能终端22可以利用移动通信网络进行通信,交易执行单元20与多个收银终端21可以利用互联网(例如Internet网)进行通信。
交易执行单元20包括生物特征认证服务器201、交易支付服务器202。智能终端22包括生物特征采集设备,用于采集用户的生物特征,例如,指纹、虹膜、声纹、面部图像等。
具体地,智能终端22至少基于交易支付服务器202在用户注册阶段下发的公钥及当前用户的生物特征而生成第一密文,以及基于第一密文生成汉信码、基于用户信息生成二维码,并显示汉信码及二维码以供收银终端21进行扫描、识别。
收银终端21包括扫描设备,以扫描并识别智能终端22所显示的汉信码及二维码。
随后,交易支付服务器202从收银终端21获取第一密文及当前用户的用户信息,并利用私钥对第一密文进行解密,以获得当前用户的生物特征并转送至生物特征认证服务器201,在生物特征认证服务器201进行认证之后,交易支付服务器202还基于生物特征认证服务器201的认证结果来完成交易。
进一步地,智能终端22可以将汉信码及二维码分别显示在屏幕或显示窗口的不同部分。优选情况下,智能终端22将汉信码显示于屏幕或显示窗口的中央部分,将二维码显示于屏幕或显示窗口的***部分。此外,智能终端22优选地同步显示汉信码、二维码。
进一步地,交易执行单元20设置于金融机构端(本地端),收银终端21设置于远端。上述交易支付***可以基于云计算***来部署,以促进***升级与维护。
用户在向上述交易支付***注册完成后,即能够安全、快捷地进行电子交易,获得良好的使用体验。该交易支付***实现成本低、便于推广应用。
上述说明仅针对于本发明的优选实施例,并不在于限制本发明的保护范围。本领域技术人员可作出各种变形设计,而不脱离本发明的思想及附随的权利要求。

Claims (10)

  1. 一种交易支付方法,包括:
    注册阶段,包括如下步骤:
    a)、生物特征认证服务器基于智能终端的注册请求而从所述智能终端获取注册用户的生物特征,交易支付服务器基于所述注册请求向所述智能终端下发公钥;其中所述生物特征由所述智能终端的生物特征采集设备进行采集而得到;以及
    交易阶段,包括如下步骤:
    b)、所述智能终端采集当前用户的所述生物特征,并至少基于所述公钥及所述当前用户的生物特征而生成第一密文;
    c)、所述智能终端基于所述第一密文生成汉信码、基于所述当前用户的用户信息生成二维码,并显示所述汉信码及所述二维码以供收银终端扫描并识别;
    d)、所述交易支付服务器从所述收银终端获取经所述收银终端扫描并识别的所述第一密文及所述用户信息,并利用私钥对所述第一密文进行解密,以获得所述当前用户的生物特征并转送至所述生物特征认证服务器;以及
    e)、所述交易支付服务器基于所述生物特征认证服务器对所述当前用户的生物特征认证的结果及所述用户信息来完成交易。
  2. 根据权利要求1所述的方法,其特征在于,所述汉信码及所述二维码分别显示在所述智能终端的屏幕或显示窗口的不同部分。
  3. 根据权利要求2所述的方法,其特征在于,所述汉信码显示于所述屏幕或显示窗口的中央部分,所述二维码显示于所述屏幕或显示窗口的***部分。
  4. 根据权利要求2所述的方法,其特征在于,所述汉信码及所述二维码同步显示。
  5. 根据权利要求1所述的方法,其特征在于,所述智能终端在生成所述第一密文时还基于当前时间的时间码。
  6. 根据权利要求1所述的方法,其特征在于,所述智能终端对所述当前用户的生物特征执行哈希算法而获得摘要,并利用所述公钥对所述摘要进行加密而生成所述第一密文。
  7. 一种交易支付***,包括:
    交易执行单元,与至少一智能终端在通信上耦合,其包括:
    生物特征认证服务器,用于对当前用户的生物特征进行认证;
    交易支付服务器,从收银终端获取第一密文及当前用户的用户信息,并利用私钥对所述第一密文进行解密,以获得所述当前用户的生物特征并转送至所述生物特征认证服务器,所述交易支付服务器还基于所述生物特征认证服务器的认证结果来完成交易;
    至少一所述收银终端,所述收银终端扫描并识别所述智能终端所显示的汉信码及二维码;以及
    至少一所述智能终端,所述智能终端包括生物特征采集设备,所述智能终端至少基于所述交易支付服务器下发的公钥及所述当前用户的生物特征而生成第一密文,以及基于所述第一密文生成所述汉信码、基于所述用户信息生成所述二维码。
  8. 根据权利要求7所述的***,其特征在于,所述智能终端将所述汉信码及所述二维码分别显示在屏幕或显示窗口的不同部分。
  9. 根据权利要求8所述的***,其特征在于,所述智能终端将所述汉信码显示于所述屏幕或显示窗口的中央部分,将所述二维码显示于所述屏幕或显示窗口的***部分。
  10. 根据权利要求7至9中任一项所述的***,其特征在于,所述交易执行单元设置于金融机构端,所述收银终端设置于远端。
PCT/CN2018/075998 2017-02-15 2018-02-09 交易支付方法及*** WO2018149367A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710080394.XA CN107146079B (zh) 2017-02-15 2017-02-15 交易支付方法及***
CN201710080394.X 2017-02-15

Publications (1)

Publication Number Publication Date
WO2018149367A1 true WO2018149367A1 (zh) 2018-08-23

Family

ID=59783347

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/075998 WO2018149367A1 (zh) 2017-02-15 2018-02-09 交易支付方法及***

Country Status (3)

Country Link
CN (1) CN107146079B (zh)
TW (1) TWI720287B (zh)
WO (1) WO2018149367A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107146079B (zh) * 2017-02-15 2020-05-22 ***股份有限公司 交易支付方法及***
CN108038529B (zh) * 2017-12-08 2020-10-09 北京中星仝创科技有限公司 一种带图像的圆形二维码生成及读取的方法
CN115189898B (zh) * 2021-04-01 2024-05-24 富联精密电子(天津)有限公司 交易处理方法、终端及存储介质
CN116629887A (zh) * 2023-07-20 2023-08-22 鼎铉商用密码测评技术(深圳)有限公司 基于生物特征的注册方法、认证方法、装置及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130275309A1 (en) * 2012-04-13 2013-10-17 Francis King Hei KWONG Electronic-payment authentication process with an eye-positioning method for unlocking a pattern lock
CN103489102A (zh) * 2013-09-13 2014-01-01 惠州Tcl移动通信有限公司 一种基于二维码通过手机实现***防盗刷的方法及***
CN104835039A (zh) * 2015-04-03 2015-08-12 成都爱维科创科技有限公司 一种数据标签生成方法
CN105590199A (zh) * 2014-11-14 2016-05-18 ***股份有限公司 一种基于动态二维码的支付方法以及支付***
CN107146079A (zh) * 2017-02-15 2017-09-08 ***股份有限公司 交易支付方法及***

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102254380A (zh) * 2010-05-31 2011-11-23 北京汇冠金财科技有限公司 基于混合加密机制的手机安全支付方法及***
CN104486356A (zh) * 2014-12-29 2015-04-01 芜湖乐锐思信息咨询有限公司 基于互联网在线交易的数据传输方法
CN104835030A (zh) * 2015-05-26 2015-08-12 丹阳飓风物流股份有限公司 一种用于物流行业的询价业务流程管理方法
CN106296197A (zh) * 2015-06-25 2017-01-04 深圳市中兴微电子技术有限公司 一种支付的方法、设备和***
WO2017088240A1 (zh) * 2015-11-24 2017-06-01 上海透云物联网科技有限公司 复合识别码结构、使用复合识别码结构的产品及监控方法
CN105574743A (zh) * 2016-01-18 2016-05-11 上海透云物联网科技有限公司 识别码结构及制作方法及产品监控方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130275309A1 (en) * 2012-04-13 2013-10-17 Francis King Hei KWONG Electronic-payment authentication process with an eye-positioning method for unlocking a pattern lock
CN103489102A (zh) * 2013-09-13 2014-01-01 惠州Tcl移动通信有限公司 一种基于二维码通过手机实现***防盗刷的方法及***
CN105590199A (zh) * 2014-11-14 2016-05-18 ***股份有限公司 一种基于动态二维码的支付方法以及支付***
CN104835039A (zh) * 2015-04-03 2015-08-12 成都爱维科创科技有限公司 一种数据标签生成方法
CN107146079A (zh) * 2017-02-15 2017-09-08 ***股份有限公司 交易支付方法及***

Also Published As

Publication number Publication date
TWI720287B (zh) 2021-03-01
TW201832153A (zh) 2018-09-01
CN107146079A (zh) 2017-09-08
CN107146079B (zh) 2020-05-22

Similar Documents

Publication Publication Date Title
US11847652B2 (en) Wireless biometric authentication system and method
US11777736B2 (en) Use of biometrics and privacy preserving methods to authenticate account holders online
CN105590199B (zh) 一种基于动态二维码的支付方法以及支付***
US8775814B2 (en) Personalized biometric identification and non-repudiation system
WO2018149367A1 (zh) 交易支付方法及***
WO2018094584A1 (zh) 基于生物特征识别的支付及身份认证***
CN108460593B (zh) 一种离线二维码支付方法及装置
EP3887982B1 (en) Biometric authentication
TW201734907A (zh) 基於人臉識別和hce的支付認證方法及認證系統
US11783336B2 (en) Camera device enabled identification and disambiguation system and method
US11451394B2 (en) Efficient hands free interaction using biometrics
US20200293643A1 (en) Biometric data security system and method
WO2018148900A1 (zh) 基于指纹识别的校验方法、装置、以及交易***
CN115051812A (zh) 一种基于二维码和生物特征的用户身份双重识别方法
WO2019108111A1 (en) Two-step central matching of fingerprints
WO2016086708A1 (zh) 支付验证方法、装置及***
WO2016083987A1 (en) Method of and system for obtaining proof of authorisation of a transaction
CN111353144A (zh) 一种身份认证的方法和装置
TWM415521U (en) User identification system
KR102079667B1 (ko) 금융 거래 서비스 제공 시스템
WO2023055562A1 (en) Remote identity interaction
CN117291607A (zh) 手指静脉数字资产支付***
TWM620132U (zh) 具有人臉辨識功能之交易系統

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18753638

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18753638

Country of ref document: EP

Kind code of ref document: A1