Summary of the invention
The objective of the invention is to: provide a kind of and carry out the bank card transaction method and the system of cipher authentication, solve the problem that terminal device does not have code keypad, make things convenient for domestic bank to snap into external use by mobile phone.
The present invention proposes a kind of bank card transaction method that carries out cipher authentication by mobile phone, be supported in the POS terminal bank card paying system of no cipher input equipment and carry out safe consumer sale, described bank card paying system comprises the POS terminal, acquirer, background system and issuing bank, described bank card paying system also comprises holder's Accreditation System and registration cardholder data storehouse, described background system links to each other with described registration cardholder data storehouse, described background system links to each other with the Short Message Service Gateway of mobile operator network, and described bank card transaction method comprises the steps:
Step 1, holder register by holder's Accreditation System, deposit log-on message in registration cardholder data storehouse;
Step 2, holder by mobile phone input encrypted message, deliver to background system on mobile operator network and Short Message Service Gateway when consumer sale;
Step 3, holder swipe the card, and deliver to acquirer on the POS Transaction Information, and acquirer will be delivered to background system on the Transaction Information;
No matter step 4, background system are to receive POS Transaction Information or the encrypted message of receiving by SMS earlier, inquiry and registration cardholder data storehouses all, confirm whether holder's card has opened mobile phone input trading password function, if opened then continued step 5, otherwise, walk normally POS consumer sale flow process overseas;
Step 5, background system coupling holder's Transaction Information and encrypted message synthesize common POS consumer sale information by encrypting will swipe the card Transaction Information and encrypted message, are forwarded to issuing bank;
Step 6, issuing bank's checking transaction turn back to the POS terminal with authorization message, finish transaction.
Wherein step 2 is with mobile phone encrypted message to be sent to background system by short message mode, be loaded with the dedicated encrypted program on the mobile phone, guarantee encrypted message encryption back in the mobile operator network delivery, described encrypted message comprises bank card password and part dealing money.
Wherein said step 4 also comprises step: described background system sends note and informs that the holder receives trading password information and effective time.
Wherein said step 6 also comprises step: described background system sends note by Short Message Service Gateway and informs that the holder consumes the result.
A kind of bank card paying system that carries out cipher authentication by mobile phone has also been proposed simultaneously, be supported in the POS terminal bank card paying system of no cipher input equipment and carry out safe consumer sale, described bank card paying system comprises the POS terminal, acquirer, background system and issuing bank, it is characterized in that: described bank card paying system also comprises holder's Accreditation System and registration cardholder data storehouse, described background system links to each other with described registration cardholder data storehouse, and described background system links to each other with the Short Message Service Gateway of mobile operator network.
Further, the holder registers by holder's Accreditation System at bank counter or cooperation site, deposits log-on message in registration cardholder data storehouse.Described log-on message comprises holder name, sex, identification card number, bank card number, cell-phone number, Email address, contact address.
Further, be loaded with the dedicated encrypted program on the described mobile phone mobile phone, the Short Message Service Gateway by the mobile operator network after encrypted message is encrypted sends to background system.
Further, the described mode that the back Short Message Service Gateway by the mobile operator network of encrypted message encryption is sent to background system is to pass through short message mode.
By method and system of the present invention, the security of concluding the business on the POS terminal that can improve at no cipher input equipment.
Embodiment
This paper proposes to utilize mobile phone as cipher input equipment, supports that POS trade company accepts the domestic bank's card that needs password to pay overseas, also can be used as alternatives and some industry application solution that the open credit card overseas of being unwilling does not have the close bank that concludes the business.Utilize almost mobile phone that everybody holds as cipher input equipment, to swipe the card Transaction Information by sending on the POS channel, encrypted message synthesizes common, have password POS transaction on the backstage with above-mentioned information by sending on the SMS, obtains Trading Authorization from issuing bank.
As shown in Figure 1, bank card paying system comprise issuing bank and background system thereof (background system in this paper chart and the word content refer to China Unionpay's inter-bank adapting system with and configuration subsystem etc.), the POS terminal, because external POS terminal does not have cipher input equipment, therefore introduced mobile phone as cipher input equipment.The holder sends password to background system by mobile phone short messages when the POS of no cipher input equipment terminal bankcard consumption, background system synthesizes common, as to have password POS transaction with encrypted message and Transaction Information, thereby carries out the safe transaction of swiping the card.
, synthesize common POS transaction again on the backstage and mainly comprise two flow processs: registration and consumption as cipher input equipment with mobile phone.Because other POS transaction flow and consumer sale are similar, this paper repeats no more.
When concluding the business on the POS machine that the present invention has disclosed at no code keypad, utilize almost mobile phone that everybody holds as cipher input equipment, to swipe the card Transaction Information by sending on the POS channel, encrypted message is by sending on the SMS, on the backstage above-mentioned information is synthesized common, as to have password POS transaction, obtain Trading Authorization from issuing bank.By cell phone keyboard input password, the encrypted message that send on backstage coupling POS swipes the card transaction and mobile phone requires all to use the holder of this pattern payment to register.
At least comprise following information during registration: name, sex, identification card number, bank card number, cell-phone number, Email address, the contact address, registration must be carried out at bank's cabinet face or cooperation site (as mobile operator), guarantees to register the authenticity of holder's relevant information.The holder registers by holder's Accreditation System at bank counter or cooperation site, and log-on message is write registration cardholder data storehouse, confirms during in order to bankcard consumption whether the holder has opened the function of carrying out password confirming by mobile phone.
After registration, log-on message and bank card information have formed relation one to one, bank's background system can confirm whether the holder has opened the function of carrying out password confirming by mobile phone by inquiry and registration cardholder data storehouse, if it is open-minded, then encrypted message and Transaction Information are merged, obtain Trading Authorization from issuing bank.
The holder can have following three kinds of mode annunciations holders to input password when carrying out consumer sale:
Pattern one:, inform the holder by the cashier again by POS terminal notifying cashier.
Pattern two: directly inform the holder, without any system prompt by the cashier.
Pattern three: by sending SMS prompting holder.
Above-mentioned three kinds of patterns are only different on the password prompt mode, are that example is described the consumer sale flow process with pattern two here, and as shown in Figure 2, at first the holder registers by holder's Accreditation System in each site, and log-on message leaves registration cardholder information storehouse in; When the holder consumes, on the POS machine, swipe the card, the backstage does not send the information indicating holder in real time and imports trading password, before swiping the card, point out the holder to input the note password by the cashier, the encrypted message of Transaction Information and mobile phone input of swiping the card can be delivered to the backstage in no particular order, respectively and synthesizes, POS sends to background system with Transaction Information by acquirer, and encrypted message passes through the mobile operator network by mobile phone short messages, sends to background system by Short Message Service Gateway again; Send to issuing bank after background system is synthetic, issuing bank's checking transaction is authorized.Concrete steps are as follows:
1-3, point out the holder to send the password note before swiping the card by the cashier, the holder imports encrypted message by mobile phone, delivers to the backstage on mobile operator network and Short Message Service Gateway;
4, the holder swipes the card, and delivers to the acquirer system on the POS Transaction Information;
5, the acquirer system will deliver to background system on the Transaction Information;
6, no matter background system is to receive POS Transaction Information or the encrypted message of importing by mobile phone earlier, all inquiry and registration cardholder data storehouse (holder's log-on data is synchronized to background system from holder's Accreditation System), open mobile phone input trading password function if confirm holder's card, continued step 7; Otherwise, walk normally not have password POS consumer sale flow process overseas;
7-9, background system send note and inform that the holder receives Transaction Information and encrypted message and effective time;
10, background system coupling holder's Transaction Information and encrypted message synthesize common POS consumer sale information by will swipe the card Transaction Information and encrypted message of encryption safe ground, are forwarded to issuing bank;
11-13, issuing bank's checking transaction turn back to the POS terminal with authorization message, finish transaction;
14-16, background system send note by Short Message Service Gateway and inform that the holder consumes result's (success or failure).
The present invention has higher security, and is basic identical with conventional P OS transaction security by the transaction of mobile phone input password, but far above the security of no close transaction.Fig. 3 has illustrated the controling mechanism of conventional P OS password transaction, and code keypad is encrypted PIN, carries out sending on the MAC signature back with magnetic track information, guarantees that PIN is not revealed and Transaction Information is not distorted.
Fig. 4 is the controling mechanism of mobile phone input password of the present invention transaction:
1, magnetic track information carries out MAC signature back by delivering to background system on the acquirer, and the information that prevents is distorted (this and conventional P OS password transaction security identical), and the POS terminal need not to carry out any transformation;
2,, guarantee after the password encryption to solve the problem of SMS plaintext transmission in the mobile operator network delivery by loading the dedicated encrypted program on the mobile phone;
3, do not utilized by other transaction is illegal in order to ensure the password of input in advance simultaneously, suggestion is sent part dealing money (for example back 3 bit digital) in the lump by mobile phone when the input password, background system comparison dealing money, the transaction that can the district office takes place.Back 3 bit digital of this dealing money can be before password or behind the password, as long as consistent with the background system agreement, the alleged encrypted message of this paper all comprises the dealing money data, for the sake of simplicity, and no longer explanation;
4, the password that sends by SMS with by the magnetic track information that send on the POS at encryption equipment secure decryption, synthetic, whole process guarantees that trading password is not expressly revealed outside.
The other measure of striving for password plaintext transmission transaction security also has:
Before the holder goes abroad, send a dynamic password, allow it that the trading password of this dynamic password with the needs input sent to it;
Take similar online payment pin mode by promoting bank, the special purpose system that is different from POS consumption is set.
In addition, advise supporting following risk control measure, further promote this payment mode security:
1, the function that provides the holder to open and close this trade mode in Accreditation System allows holder's front opening of going abroad, and closes after coming back home, and strengthens holder's confidence, improves service experience;
2, the acquirer of this pattern of suggestion monitoring, accept conclude the business situation and steal the card loss of trade company and holder, regularly carry out risk assessment, set up the blacklist mechanism of trade company, holder, card and mobile phone.
Has great realistic meaning by SMS input password, the input of note password is a kind of novel, basic holder's authentication mode, owing to need not to transform the POS terminal, do not replenish mutually with there being the password modes of payments overseas, greatly made things convenient for the holder to realize that domestic bank is stuck in use overseas.