CN1367908A - 一种实现电子存折(钱包)安全交易的方法 - Google Patents
一种实现电子存折(钱包)安全交易的方法 Download PDFInfo
- Publication number
- CN1367908A CN1367908A CN99816857A CN99816857A CN1367908A CN 1367908 A CN1367908 A CN 1367908A CN 99816857 A CN99816857 A CN 99816857A CN 99816857 A CN99816857 A CN 99816857A CN 1367908 A CN1367908 A CN 1367908A
- Authority
- CN
- China
- Prior art keywords
- card
- lock
- terminal
- ash
- wallet
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
- G06Q20/105—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems involving programming of a portable memory device, e.g. IC cards, "electronic purses"
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
- G06Q20/4097—Device specific authentication in transaction processing using mutual authentication between devices and transaction partners
- G06Q20/40975—Device specific authentication in transaction processing using mutual authentication between devices and transaction partners using encryption therefor
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0813—Specific details related to card security
- G07F7/082—Features insuring the integrity of the data on or in the card
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Finance (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (9)
- 权利要求书1、 一种实现电子存折 (钱包) 安全交易的方法, 其特征在于: 将灰锁标记 并入该电子存折 (钱包) , 成为该电子存折 (钱包) 的属性参数之一; 在灰锁 IC 卡即置灰锁标记的同时, 将锁卡的来源记入 IC卡; 当扣款操作时执行对该锁卡来源 的判断, 并将扣款操作和解灰操作合并为 IC卡上的一步操作, 即扣款成功后自动解 灰。
- 2、 根据权利要求 1所述的方法, 其特征在于: 更进一歩的可在主机上保存 有一条可以实现扣款、强制解灰操作的密钥, 使灰锁后的 IC卡可在联机的终端上通 过联机方式实现补扣款及强制解灰操作。
- 3、 根据权利要求 1所述的方法, 其特征在于建立的 IC卡消费交易流程为: 用户插卡、 终端和 IC卡双向认证、 终端灰锁 IC卡、 消费、 消费实现后终端从 IC 卡的电子存折 (钱包) 扣款并解灰锁。
- 4、 根据权利要求 3所述的方法, 其特征在于所述的灰锁 IC卡是指: IC卡 根据其锁卡的来源生成一认证码, 同时将产生该锁卡来源的所需参数传递给终端, 由终端采用与 IC卡相同的机制产生另一锁卡来源码,并使用该锁卡来源码生成另一 认证码,将该认证码送入 IC卡, IC卡判断与上述 IC卡自身生成的认证码是否相同, 若相同时执行灰锁操作并将这次产生的一灰锁特征码返回给终端, 该灰锁特征码为 根据其锁卡来源及相应信息在内的数据生成。所述的终端从 IC卡的电子存折 (钱包) 扣款并解灰锁是指: 终端根据其锁卡 来源和扣款所需的参数生成一认证码, 将该认证码与相应参数一并送入 IC 卡, IC 卡内部采用其自身的锁卡来源和相同的参数通过相同的机制产生另一认证码, 判断 该认证码与终端产生的认证码一致就从 IC卡的电子存折(钱包)上实现扣款, 扣款 成功的同时将灰标记清除。
- 5、 根据权利要求 4所述的方法, 其特征在于: 终端更进一歩可将扣款时所 需的认证码、 这次的逃卡金额及灰锁特征码共同作为这次灰记录的部分信息保存起 来, 并上传给中心机; 如果某次交易过程未完整结束的未被扣款解灰的 IC卡, 下一 次在任何一个保存有该灰记录的终端上使用时, 终端可先验证该灰锁特征码以确定IC卡上的锁卡来源与计算该条灰记录中的扣款认证码的锁卡来源相同, 通过后执行 补扣款解灰操作。
- 6、 根据权利要求 1 所述的方法, 其特征在于: 所述的锁卡来源即为在 IC 卡上建立的一条过程密钥 (SESPK) , 该过程密钥至少与一 IC卡临时生成的伪随机 数 (ICC ) 相关。
- 7、 根据权利要求 5所述的方法, 其特征在于: 所述的过程密钥 (SESPK )= 3DES ( DPK, DATA), 其中 DPK是电子存折(钱包)的消费密钥, 是由电子存折(钱 包) 消费主密钥 (MPK ) 根据该 IC卡的应用序号分散得到, DATA是特定的参数, 包 括有所述的 IC卡临时生成的伪随机数(ICC)、电子存折(钱包)的交易序号(CTC)、 终端交易序号 (TTC ) 的最后两个字节。8、 根据权利要求 6或 7所述的方法, 其特征在于: 灰锁电子存折 (钱包) 时, 终端将终端交易序号 (TTC) 送入 IC卡, IC卡获得自己的伪随机数 (ICC ) 和 电子存折 (钱包) 交易序号 (CTC ) , 内部建立过程密钥 (SESPK ) , 且将产生过程 密钥 (SESPK) 的相应参数记录下来, 产生这次灰锁特征码同时亦记录下来, 将伪随 机数 (ICC ) 、 电子存折 (钱包) 交易序号 (CTC ) 发给终端, 终端的安全认证模组 ( PSAM) 中存放有电子存折 (钱包) 消费主密钥 (MPK ) , 安全认证模组 (PSAM)根 据 IC卡应用序号推导出 IC卡上该电子存折(钱包)的 DPK,再根据伪随机数(ICC)、 电子存折 (钱包) 交易序号 (CTC ) 、 终端交易序号 (TTC) , 采用与 IC卡相同的机 制建立起相同的过程密钥 (SESPK) ;扣款操作时终端使用该过程密钥 (SESPK ) 根据扣款的金额、 操作的日期时间 等计算出认证码, 一并送入 IC卡, IC卡内部采用相同的数据和算法使用过程密钥 ( SESPK) 同样计算出认证码, 并与终端计算的结果相比较, 相同则内部实现扣款和 解灰, 若认证码与终端计算的不同, 内部不作扣款解灰操作, 而将内部出错计数器 增加, 返回出错代码, 如果内部出错计数器到达一定的次数, 将 IC卡的应用内部锁 定以防止恶意的试探。
- 9、 根据权利要求 1所述的方法,其特征在于:将灰锁标记并入电子存折(钱 包) 成为一特殊的加油电子存折 (钱包) 时, 除具备通常的读余额、 圈存、 圈提、 消费 /取现、 改透支限额等功能外, 同时增加了加油消费、 本地解灰锁和联机解灰锁 功能。
- 10、 根据权利要求 9所述的方法,其特征在于: 描述该加油电子存折(钱包) 的状态除通常的空闲状态、 圈存状态、 消费 /取现状态、 圈提状态、 修改状态外, 还 存在预加油状态、 灰锁状态、 和解灰锁状态, 并在电子存折 (钱包) 通常的命令集 中增加了加油初始化、 加油锁卡、 加油消费、 解锁初始化、 解锁、 读取状态命令, 其中, 加油初始化命令用于初始化加油消费交易, 加油锁卡命令用于灰锁加油消费 电子存折 (钱包) , 加油消费命令用于本地加油消费交易同时解灰锁, 解锁初始化 命令用于初始化联机解灰锁消费交易, 解锁命令用于联机解灰锁交易同时补扣加油 消费, 读取状态命令用于读取灰锁状态并启动本地解灰锁交易。
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN1999/000124 WO2001015024A1 (en) | 1999-08-23 | 1999-08-23 | A method for the accomplishment secure transaction for electronicbankbook (purse) |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN1367908A true CN1367908A (zh) | 2002-09-04 |
| CN100468452C CN100468452C (zh) | 2009-03-11 |
Family
ID=4575137
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CNB998168572A Expired - Lifetime CN100468452C (zh) | 1999-08-23 | 1999-08-23 | 一种实现电子存折(钱包)安全交易的方法 |
Country Status (7)
| Country | Link |
|---|---|
| US (1) | US7512565B2 (zh) |
| EP (1) | EP1237112A4 (zh) |
| CN (1) | CN100468452C (zh) |
| AU (1) | AU5405899A (zh) |
| EA (1) | EA003949B1 (zh) |
| HK (1) | HK1047643B (zh) |
| WO (1) | WO2001015024A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106600274A (zh) * | 2017-02-07 | 2017-04-26 | 桂林理工大学 | 多算法多密钥的光认证离线支付装置 |
| CN107146075A (zh) * | 2016-03-01 | 2017-09-08 | 阿里巴巴集团控股有限公司 | 请求处理方法及装置 |
Families Citing this family (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101895652A (zh) * | 2010-07-13 | 2010-11-24 | 宇龙计算机通信科技(深圳)有限公司 | 一种对移动终端充值的方法、移动终端及服务器 |
| US20140244507A1 (en) * | 2011-07-28 | 2014-08-28 | Upc Konsultointi Oy | Offline transaction |
| EP3079115A4 (en) * | 2013-12-04 | 2017-10-11 | Tendyron Corporation | Method and smart card for processing transaction data |
| US11507935B1 (en) | 2017-02-14 | 2022-11-22 | Wells Fargo Bank, N.A. | Mobile wallet card control |
| CN107483185A (zh) * | 2017-07-25 | 2017-12-15 | 贵州眯果创意科技有限公司 | 一种基于安全密钥的移动端psam卡支付系统 |
| US11769132B1 (en) | 2019-05-22 | 2023-09-26 | Wells Fargo Bank, N.A. | P2P payments via integrated 3rd party APIs |
| CN110851806A (zh) * | 2019-10-24 | 2020-02-28 | 广州江南科友科技股份有限公司 | 一种基于Linux的账户管理方法、系统、装置及存储介质 |
| CN111489471A (zh) * | 2020-03-10 | 2020-08-04 | 深圳市海威达科技有限公司 | 一种基于云端的一卡通识别设备鉴权方法 |
| CN112185031A (zh) * | 2020-09-18 | 2021-01-05 | 广州市贺氏办公设备有限公司 | 一种消费机异常数据的处理方法、系统、装置及介质 |
| CN113706165A (zh) * | 2021-01-23 | 2021-11-26 | 深圳市玄羽科技有限公司 | 一种基于云计算的智能设备全生命周期监测查询系统 |
| CN113298965B (zh) * | 2021-04-15 | 2023-02-17 | 北京云星宇交通科技股份有限公司 | 一种etc车道系统防止psam卡锁定的方法及系统 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| NL9401406A (nl) * | 1994-08-31 | 1996-04-01 | Nederland Ptt | Betaalsysteem met verbeterde integriteit. |
| EP0803846B1 (en) * | 1994-10-19 | 2003-10-01 | Hitachi, Ltd. | Transaction-oriented electronic accommodation system |
| KR0149946B1 (ko) * | 1995-01-20 | 1999-05-15 | 김광호 | 전자통장시스템 및 그 거래방법 |
| CN101398871B (zh) | 1995-02-13 | 2011-05-18 | 英特特拉斯特技术公司 | 用于安全交易管理和电子权利保护的系统和方法 |
| FR2732486B1 (fr) | 1995-03-31 | 1997-05-09 | Solaic Sa | Procede pour fiabiliser une demande d'acces au programme de gestion d'une application d'une carte a memoire, et carte a memoire pour la mise en oeuvre de ce procede |
| US5661803A (en) * | 1995-03-31 | 1997-08-26 | Pitney Bowes Inc. | Method of token verification in a key management system |
| JPH103568A (ja) * | 1996-06-14 | 1998-01-06 | Hitachi Ltd | 電子財布応用システム及びicカードを用いた取引装置 |
| EP0831433A1 (en) * | 1996-09-24 | 1998-03-25 | Koninklijke KPN N.V. | Method of making recoverable smart card transactions, a method of recovering such a transaction, as well as a smart card allowing recoverable transactions |
| EP0851396A1 (en) * | 1996-12-23 | 1998-07-01 | Koninklijke KPN N.V. | System for increasing a value of an electronic payment card |
-
1999
- 1999-08-23 HK HK02109223.8A patent/HK1047643B/zh not_active IP Right Cessation
- 1999-08-23 CN CNB998168572A patent/CN100468452C/zh not_active Expired - Lifetime
- 1999-08-23 WO PCT/CN1999/000124 patent/WO2001015024A1/zh active Application Filing
- 1999-08-23 AU AU54058/99A patent/AU5405899A/en not_active Abandoned
- 1999-08-23 EP EP99939899A patent/EP1237112A4/en not_active Ceased
- 1999-08-23 EA EA200200273A patent/EA003949B1/ru not_active IP Right Cessation
-
2002
- 2002-02-25 US US10/082,371 patent/US7512565B2/en not_active Expired - Lifetime
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107146075A (zh) * | 2016-03-01 | 2017-09-08 | 阿里巴巴集团控股有限公司 | 请求处理方法及装置 |
| CN107146075B (zh) * | 2016-03-01 | 2020-11-10 | 创新先进技术有限公司 | 请求处理方法及装置 |
| CN106600274A (zh) * | 2017-02-07 | 2017-04-26 | 桂林理工大学 | 多算法多密钥的光认证离线支付装置 |
| CN106600274B (zh) * | 2017-02-07 | 2023-08-11 | 桂林理工大学 | 多算法多密钥的光认证离线支付装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP1237112A4 (en) | 2006-05-17 |
| EA003949B1 (ru) | 2003-10-30 |
| AU5405899A (en) | 2001-03-19 |
| HK1047643B (zh) | 2009-06-26 |
| US20020138429A1 (en) | 2002-09-26 |
| EP1237112A1 (en) | 2002-09-04 |
| HK1047643A1 (zh) | 2003-02-28 |
| EA200200273A1 (ru) | 2002-08-29 |
| WO2001015024A1 (en) | 2001-03-01 |
| US7512565B2 (en) | 2009-03-31 |
| CN100468452C (zh) | 2009-03-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR100389229B1 (ko) | 거래처리시스템 및 거래처리방법 | |
| EP0668579B1 (en) | Secure money transfer techniques using smart cards | |
| CN102081821B (zh) | Ic卡支付系统和方法以及多应用ic卡、支付终端 | |
| US6012049A (en) | System for performing financial transactions using a smartcard | |
| JP3083187B2 (ja) | 電子財布システムの鍵管理方式 | |
| US6023508A (en) | Polymorphic data structures for secure operation of a virtual cash system | |
| CN102893297A (zh) | 包括非信任商户终端的可信储值支付系统 | |
| CN1367908A (zh) | 一种实现电子存折(钱包)安全交易的方法 | |
| CN101706933A (zh) | 一种实现联名账户业务操作的方法及后台系统 | |
| JPH07507647A (ja) | 物または用役を提供する端末に介入する方法 | |
| CN103310338A (zh) | 一种主副银行卡支付系统及方法 | |
| CN109034766A (zh) | 借款方法及系统、设备和存储介质 | |
| CN102074077B (zh) | 一种预防ic卡加油机作弊的系统及方法 | |
| JP3403456B2 (ja) | 電子小口決済システムにおける取引方法 | |
| CN101501708A (zh) | 具有增强的安全pin和截止日期生成的交易工具 | |
| EP0769767A2 (en) | Secure money transfer techniques using smart cards | |
| JP3061710B2 (ja) | レジスタシステム | |
| CN103871163B (zh) | 复合金融交易方法和系统 | |
| CN100410957C (zh) | 提高应用灰锁技术的业务交易ic卡可靠性的方法 | |
| AU723525B2 (en) | A method for certifying a running total in a reader | |
| JP2003271885A (ja) | クレジットカード決済における情報漏洩防止システム | |
| JPS62280965A (ja) | Icカ−ドの情報保護方式 | |
| CN118071349A (zh) | 一种基于区块链的预付费卡使用方法和系统 | |
| TW491980B (en) | Chip card and its using method | |
| JPS58142476A (ja) | 取引処理装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C06 | Publication | ||
| PB01 | Publication | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant | ||
| REG | Reference to a national code |
Ref country code: HK Ref legal event code: GR Ref document number: 1047643 Country of ref document: HK |
|
| ASS | Succession or assignment of patent right |
Owner name: BEIJING TENDYRON SCI-TECH CO., LTD. Free format text: FORMER OWNER: LI DONGSHENG Effective date: 20100707 |
|
| C41 | Transfer of patent application or patent right or utility model | ||
| COR | Change of bibliographic data |
Free format text: CORRECT: ADDRESS; FROM: 100085 4/F, NO.26, STREET 4, CHUANGYE MIDDLE ROAD, SHANGDI INFORMATION INDUSTRY BASE, BEIJING CITY, CHINA TO: 100083 1810, TOWER B, JINMA BUILDING, NO.17, QINGHUA EAST ROAD, HAIDIAN DISTRICT, BEIJING CITY |
|
| TR01 | Transfer of patent right |
Effective date of registration: 20100707 Address after: 100083, B, block 17, golden building, No. 1810 Qinghua East Road, Beijing, Haidian District Patentee after: Beijing Tendyron Technology Co., Ltd. Address before: 100085, Beijing, China Information Industry Base on the road, four 26 street, 4 Patentee before: Li Dongsheng |
|
| C56 | Change in the name or address of the patentee | ||
| CP03 | Change of name, title or address |
Address after: 100083, room 1810, block B, golden building, No. 17, Qinghua East Road, Beijing, Haidian District Patentee after: Tendyron Technology Co., Ltd. Address before: 100083, B, block 17, golden building, No. 1810 Qinghua East Road, Beijing, Haidian District Patentee before: Beijing Tendyron Technology Co., Ltd. |
|
| CX01 | Expiry of patent term |
Granted publication date: 20090311 |
|
| CX01 | Expiry of patent term |