WO2003060789A1 - Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit - Google Patents
Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit Download PDFInfo
- Publication number
- WO2003060789A1 WO2003060789A1 PCT/JP2002/000093 JP0200093W WO03060789A1 WO 2003060789 A1 WO2003060789 A1 WO 2003060789A1 JP 0200093 W JP0200093 W JP 0200093W WO 03060789 A1 WO03060789 A1 WO 03060789A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- transaction
- user
- server
- web
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims description 39
- 238000012790 confirmation Methods 0.000 claims abstract description 277
- 238000012545 processing Methods 0.000 claims abstract description 160
- 230000004044 response Effects 0.000 claims description 9
- 230000008569 process Effects 0.000 claims description 8
- 230000005540 biological transmission Effects 0.000 claims description 3
- 238000010586 diagram Methods 0.000 description 14
- 238000004891 communication Methods 0.000 description 8
- 238000012986 modification Methods 0.000 description 8
- 230000004048 modification Effects 0.000 description 8
- 230000000694 effects Effects 0.000 description 6
- 230000006870 function Effects 0.000 description 5
- 238000007726 management method Methods 0.000 description 5
- 125000002066 L-histidyl group Chemical group [H]N1C([H])=NC(C([H])([H])[C@](C(=O)[*])([H])N([H])[H])=C1[H] 0.000 description 2
- 238000004519 manufacturing process Methods 0.000 description 2
- 230000008520 organization Effects 0.000 description 2
- 238000013475 authorization Methods 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/02—Banking, e.g. interest calculation or account maintenance
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/04—Payment circuits
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/12—Payment architectures specially adapted for electronic shopping systems
Definitions
- the present invention relates to a web browser including a transaction confirmation / credit card information acquisition method in a web electronic commerce, a transaction confirmation server, a transaction confirmation server program, an order processing 'confirmation instruction program, a user authentication program, and a user authentication program. Things.
- personal information is registered in a personal information management server provided on the Internet and stores in advance the personal information of a large number of users, and the user inputs the personal information to a website.
- the "Web site It is conceivable that the server automatically obtains personal information from the personal information management server via the Internet.
- the user himself / herself needs to input at least once to the personal information management server.
- the present invention does not require a user to input his / her credit strength information in web electronic commerce, and furthermore, the transaction confirmation in web electronic commerce that can reliably prevent the leakage of credit card information.
- the purpose is to provide a credit card information acquisition method.
- a step of displaying a product order Web page screen of an electronic commerce Web site on a user terminal in response to a user access request A step in which the web browser of the user terminal reads the order processing / confirmation instruction program included in the source program of the product order web page, and a step in which the web browser executes the read order processing / confirmation instruction program. Transmitting an order processing request to the web site together with transaction ID information specifying each electronic commerce and user identification information specifying each user; and the web browser reads the Based on the order processing and confirmation instruction program, the transaction confirmation server sends the transaction ID information identifying each electronic commerce transaction and the individual user.
- the server transmitting the transaction ID information and the user identification information to the transaction confirmation server; andthe transaction confirmation server receiving the transaction from the web browser of the user terminal. Determining whether or not the ID information and the user identification information match the transaction ID information and the user identification information received from the web site server; and If it is determined that the credit card information of the user registered in advance without going through the Internet, A step of acquiring the credit card information of the user from the stored credit card information storage means and transmitting the credit card information to the payment processing means. You.
- the transaction confirmation server retrieves the credit card information from the credit card storage means registered without going through the Internet and passes it to the settlement processing means, the leakage of the credit card information can be reliably prevented. Further, the transaction confirmation server has a transaction confirmation function of confirming that the electronic commerce is indeed by the user himself by using the coincidence of the transaction ID information and the user recognition information. It is also possible to reliably prevent another person who has illegally acquired credit card information from purchasing a product by impersonating the user.
- the transaction ID information may be Web site ID information for specifying the electronic commerce Web site. Further, when the Web browser of the user terminal transmits the Web site ID information and the user recognition information together with the transaction confirmation request to the transaction confirmation server, the Web browser of the electronic commerce Web site is used.
- the data may be transmitted via a processing branching unit of the server, which is prohibited from being modified by the web site operator.
- the user identification information for specifying each individual user is IP address information assigned to a user terminal
- the credit card information storage means includes It is assumed that user ID information associated with the address information and credit force information of the user corresponding to the user ID information are stored.
- PPP Point to Point Protocol
- a dynamic IP address that is randomly assigned for each connection
- the user authentication can be reliably performed, and the user can be protected by impersonation. Unauthorized acquisition of personal information can be reliably prevented.
- the user identification information for specifying the individual user is user terminal number information assigned to a user terminal
- the credit card information storage means includes the user terminal
- the user ID information associated with the number information and the credit card information of the user corresponding to the user ID information may be stored.
- user terminal number information that differs for each user terminal is used.
- the user identification information for identifying each user is number information of a user authentication program installed in a user terminal, and is stored in the credit card information storage unit. May store user ID information associated with the number information of the user authentication program, and credit card information of the user corresponding to the user ID information.
- user authentication can be performed with the existence of the user authentication program installed on the user terminal.
- the user authentication can be easily performed by using the number information such as the manufacturing serial number of the user authentication program as the user identification information.
- a step of displaying a product order web page screen of an electronic commerce web site on a user terminal in response to a user access request the web browser of the user terminal comprises: Reading the order processing / confirmation command program included in the source program of the product order web page; and reading the order processing / confirmation command program by the web browser. Transmitting a transaction confirmation request to the transaction confirmation server together with the user identification information for identifying each user; and the transaction ID generating means of the tori authorization server, based on the transaction confirmation request, Generating transaction ID information specifying an electronic commerce; and the transaction confirmation server stores the generated transaction ID information in a transaction confirmation information temporary storage unit together with the user identification information received from the web browser.
- the user does not need to input credit card information by himself / herself, and also inputs the credit card information to the Web site.
- the transaction confirmation server retrieves the credit card information from the credit card storage means registered in advance without going through the Internet, and passes it to the settlement processing means. It can be reliably prevented.
- the transaction confirmation server has a transaction confirmation function for confirming that the electronic commerce is indeed the user by utilizing the coincidence of the transaction ID information and the user identification information. It is also possible to reliably prevent another person who has illegally acquired the credit card information from purchasing the product by impersonating the user.
- the transaction ID information in this embodiment is provided by the transaction confirmation server for each electronic commerce transaction, transaction confirmation can be performed for each transaction in more detail.
- a transaction confirmation server for performing transaction confirmation * credit card information acquisition in web electronic commerce, wherein a source program of a product order web page from an electronic commerce web site is provided. Receives transaction ID information identifying individual e-commerce and user identification information identifying individual users, sent by the web browser of the user terminal along with the transaction confirmation request based on the confirmation order program included in the And the transaction ID information and user recognition received from the web browser by the web site server together with the order processing request transmitted by the web browser based on the order processing / confirmation instruction program. Receiving information from a server of the web site; and the transaction ID received from a browser of the user terminal.
- a transaction confirmation server that performs transaction confirmation and credit card information acquisition in web electronic commerce, b Ordering products from the site Order processing included in the source program of the web pageReceiving a transaction confirmation request together with user identification information identifying each user transmitted by the web browser of the user terminal based on the confirmation instruction program
- the transaction ID generation means of the transaction confirmation server generates transaction ID information specifying the electronic commerce transaction based on the transaction confirmation request, and the generated transaction ID information is transmitted to the web browser. Storing the transaction confirmation information in the temporary storage means together with the user recognition information received from the server, and transmitting the transaction confirmation information to the Web browser; and the order processing transmitted by the Web browser based on the order processing / confirmation instruction program.
- the transaction ID information and the user identification information received from the web browser by the web site server together with the request.
- the step of determining whether or not the recognition information matches and in the step of determining, if it is determined that they match, the credit card information of the user registered in advance without going through the Internet. It is also possible to realize a transaction confirmation server having a step of acquiring the credit card information of the user from the credit card information storage means in which is stored and transmitting the credit card information to the settlement processing means.
- the source program of the product order web page from the electronic commerce web site is provided to the transaction confirmation server that performs transaction confirmation and credit card information acquisition in web electronic commerce.
- the Web browser of the user terminal Based on the included order processingconfirmation instruction program, the Web browser of the user terminal sends the transaction confirmation request together with the transaction confirmation request, the transaction ID information identifying each electronic commerce, and the user recognition identifying each user.
- recognition Receiving information from the web site server; the transaction ID information and user identification information received from the browser of the user terminal; and the transaction ID information and user identification received from the web site server.
- a transaction confirmation server that performs transaction confirmation and credit card information acquisition in web electronic commerce is provided with a source program of a product order web page from an electronic commerce web site.
- an order processing / confirmation included in a source program of a product order web page of an electronic commerce web site displayed on a user terminal in response to a user access request, an order processing / confirmation included in a source program of a product order web page of an electronic commerce web site displayed on a user terminal.
- An instruction program, the order processing-confirmation instruction program is read into a Web browser of a user terminal, and to the Web site, transaction ID information for specifying individual electronic commerce and individual users. Transmitting an order processing request together with user identification information specifying the transaction ID; and causing the web browser to transmit a transaction confirmation request to the transaction confirmation server together with the transaction ID information and the user identification information.
- Order processing to be executed ⁇ A confirmation instruction program can also be realized.
- the order processing and confirmation included in the source program of the product order web page of the electronic commerce web site displayed on the user terminal in response to a user access request An instruction program, wherein the order processing / confirmation instruction program is transmitted to a web browser of a user terminal, and a transaction confirmation request is transmitted to a transaction confirmation server together with user identification information for identifying each user; Receiving from the transaction confirmation server transaction ID information for identifying the electronic commerce generated based on the transaction confirmation request, the transaction ID generation means of the transaction confirmation server; transmitting an order processing request to the eb site together with the received transaction ID information and the user identification information. Order processing to be executed ⁇ A confirmation instruction program can also be realized.
- the program installed in the user terminal wherein the number information of the program is used as user identification information for identifying an individual user.
- the number information of the program is used as user identification information for identifying an individual user.
- a user authentication program used in the operation can also be realized.
- a Web browser including the user authentication program in the ninth aspect as a plug-in program can also be realized.
- FIG. 1 is a diagram showing the overall configuration of a first embodiment of a transaction confirmation / credit card information acquisition method in web electronic commerce according to the present invention
- FIG. 2 is a diagram showing a transaction confirmation server and the like in the first embodiment
- FIG. 3 is a diagram showing an internal configuration
- FIG. 3 is an image diagram of a data configuration stored in credit card information storage means in the first embodiment
- FIG. 4 is a flowchart showing a processing procedure in the first embodiment
- FIG. Is a diagram showing an internal configuration of a transaction confirmation server and the like in the second embodiment
- FIG. 6 is a diagram showing an internal configuration of a transaction confirmation server and the like in the third embodiment
- FIG. FIG. 8 is a diagram showing an overall configuration in another modified example.
- FIG. 1 is a diagram showing an overall configuration according to a first embodiment of a transaction confirmation / credit card information acquisition method in web electronic commerce according to the present invention.
- a user terminal 10 such as a personal computer is connected to an Internet service provider (hereinafter referred to as ISP) 20 via a dial-up line 40 such as a telephone line or an ISDN line. Point Protocol) connection to Internet 50.
- ISP Internet service provider
- a dial-up line 40 such as a telephone line or an ISDN line. Point Protocol
- IP addresses hereinafter simply IP addresses
- EC Electronic Commerce
- ISP 20 which is a central institution that provides users with transaction confirmation and credit card information acquisition and payment processing services of this embodiment.
- ISP 20 is a central institution that provides users with transaction confirmation and credit card information acquisition and payment processing services of this embodiment.
- the ISP 20 system mainly consists of a transaction confirmation server 30, credit card information storage means 31 as a database for relational databases, and a payment processing module 3 2 as a payment processing means (Fig. 2). , And an Internet connection processing unit (not shown).
- the credit card information storage means 31 stores various personal information of the user (name, address, telephone number, e-mail address, etc.) registered when the user first applied to the ISP 20 for the Internet connection service. ) Is stored with credit card information (credit card company, card number, expiration date, etc.).
- the transaction confirmation server 30 receives the credit power stored in the credit card information storage means 31. The information is obtained and passed to the payment processing module 32 for payment processing. At that time, it confirms whether or not the product order (electronic commerce) was originally ordered by the user who is a member of the ISP 20 (transaction confirmation). Therefore, the transaction confirmation server 30 performs various functions such as transaction confirmation, acquisition of credit card information, and settlement processing.
- the processing unit (not shown) for generating the product order page of the EC site 60 receives the request (“HTTPGET” command) from the user and generates the product order page.
- Order processing indicated by a star in the figure ⁇ Confirmation instruction program 60a is embedded in the page.
- the order processing / confirmation instruction program 60a is a program (code) written in a language such as script language, and is a source program in HTML language or the like for each product order page of each partner EC site 60. It is embedded anywhere in the.
- Order processing ⁇ Confirmation instruction program 60a is a format that does not require rewriting of existing source programs and functions only by adding a few new lines. This is preferable because it is simple for the website.
- the order processing / confirmation instruction program 60a is read into the web browser 10a of the user terminal 10.
- the web browser 10a sends a transaction confirmation request to the transaction confirmation server 30 of the ISP 20 and an order processing request to the EC site 60 based on the order processing / confirmation instruction program 60a.
- the URL of the EC site 60 (Web site ID information) as transaction ID information that specifies individual transactions
- the IP of the user terminal 10 as user identification information that specifies individual users The address is sent.
- the web browser 10a transmits a dummy web page having no information at all. (Or a dummy image such as a transparent GIF) to send a command (“HTTP GET” command).
- a command (“HTTP GET” command).
- This IP address is used by ISP 20 to authenticate that the user is a registered user of ISP 20, and in the transaction confirmation process described later, the order of the product to EC site 60 is definitely by the user himself. It is also used to confirm that The IP address of the present embodiment is used for connection to ISP 20. Since it is a dynamic IP address that is randomly assigned every time, the security effect is also high. It is also possible to use a fixed IP address instead of a dynamic IP address.
- FIG. 2 is a diagram showing details of the internal configurations of the system of the ISP 20 such as the transaction confirmation server 30 and the system of the EC site 60.
- the web server 30a at the transaction confirmation server 30 of the ISP 20 and the web server 61 at the EC site 60 serve as a point of contact with the user terminal 10 to transfer various programs and data to the HTTP protocol.
- Receive with L is the IP address, which is the user identification information, and the UR of the EC site 60, which is the web site ID information.
- the transaction confirmation server 30 receives the transaction confirmation request received by the web server 30a, and sends the IP address and web site ID of the user received with the request to the order confirmation module by using 30c.
- the information (hereinafter, IP-ID pair) is stored in the transaction information temporary storage means 30f.
- the EC site 60 receives the order processing request received by the web server 61, executes the order processing by the order processing module 62, and checks the inventory of the ordered products and arranges the delivery. And so on.
- the order processing module 62 when the order processing is completed, in this service, the settlement of the price for the user is performed by the ISP 20 and a settlement request is transmitted to the transaction confirmation module 30b of the ISP 20.
- a server may be provided.
- the order processing module 62 sends the IP-ID pair received from the user terminal 10 by the web server 61 together with the settlement request to the transaction confirmation module 30b.
- the transaction confirmation module 30b the same IP-ID pair as the transaction confirmation information Request the order confirmation module 30c to perform a collation process for checking whether or not the information is stored in the temporary report storage means 30f.
- the order confirmation module 30c searches for the IP-ID pair that has already been received from the user terminal 10 via the web server 30a and is supposed to be stored in the transaction confirmation information temporary storage means 30f. However, if a matching pair is found, it is determined that the order for this product is indeed the member user himself, and the process is recommended to the next step. In other words, even if another person illegally impersonates this user and tries to purchase a product on the EC site 60, the other person does not have the dynamic IP address assigned to the user, and the user terminal 10 The IP-ID pair transmitted directly to the transaction confirmation server and stored in the transaction confirmation information temporary storage means 30 f is not found, and the settlement request is rejected.
- IP_ID is transmitted from the user terminal 10 directly to the transaction confirmation server 30 and is stored in the transaction confirmation information temporary storage means 30f.
- the allowable time (time range) until the ID pair reaches the transaction confirmation module 30b can be freely set. A pair that arrives beyond the allowable time may be notified to the administrator of the transaction confirmation server 30 even if they match.
- the transaction confirmation server 30 executes a credit card information acquisition step for the user.
- the transaction confirmation module 30b passes the IP address, which is the user identification information, to the personal information acquisition module 30g, and uses the IP address as key information to store the credit card information of the user in credit card information storage means. 3 Request to get from 1.
- the personal information acquisition module 30d executes a query request statement (for example, SQL: Structured Query) that describes what type of information should be acquired from the credit card information storage means 31 from the personal information setting file 30g. Language) Get.
- the credit card information storage means 31 stores the inquiry method and the like in the personal information setting file 30 g because the manner of defining data in the database differs for each ISP 20.
- the various DB adapters 30e receive the personal information acquisition command from the personal information acquisition module 30d, and acquire the credit card of each user from the credit card information storage means 31.
- the IP address of the user is used as key information for user identification.
- information on a connection method with the credit card information storage means 31 is acquired from the DB setting file 3 Oh.
- the connection method with the credit card information storage means 31 means the address (host name, etc.) of the credit card information storage means 31 which is a database, and a transaction confirmation server for the credit card information storage means database 31. Settings such as the access ID and password of the client.
- FIG. 3 is an image diagram of the data configuration stored in the credit card information storage means 31.
- the ID 31 a and various personal information 31 b (name, zip code, address, credit card number, etc.) of each user registered in the internetwork connection service of ISP 20 are stored. Since the IP address given each time a user connects to the Internet is uniquely determined for each user, credit card information is stored in various DB adapters 30 e of the transaction confirmation server 30.
- the user ID 31a is specified using this IP address information as key information, and the credit card number of the user corresponding to the ID is identified. Get information 3 1 c and so on.
- the user ID 31 a in the personal information storage means 31 the same ID as each user for the Internet connection service of the ISP 20 may be used, or the user ID 31 a dedicated to the credit card information acquisition processing may be used. It may be something.
- the acquired credit card information is settled from the transaction confirmation module 30b. It is transmitted to the settlement processing module 32 as a means, and then the settlement processing step is executed. It is preferable that the purchase of the merchandise at the EC site 60 be billed to the user together with the Internet connection service fee of the ISP 20 because the payment is simple and easy.
- the transaction confirmation server 30 retrieves the credit card information from the credit card storage means 31 registered in advance without going through the Internet and sends it to the payment processing module 32. Because it passes, the leakage of credit card information can be reliably prevented.
- the transaction confirmation server 30 has a transaction confirmation function for confirming that the electronic commerce is indeed the user himself by using a match between pairs of transaction ID information and user identification information. Therefore, it is possible to surely prevent a person who has acquired credit card information illegally by any means from purchasing the product by impersonating the user.
- FIG. 4 is a flowchart showing a basic processing procedure of the present embodiment.
- the processes in the ISP 20, the user terminal 10, and the EC site 60 are separately shown.
- the detailed processing of the modules 30a to 30h, such as each module, in the transaction confirmation server 30 has already been described in the description of FIG.
- the user makes an Internet connection request by dial-up connection from the user terminal 10 to the ISP 20 (step s200).
- the user ID and password for the Internet connection service are entered and transmitted to ISP 20.
- ISP 20 key The Internet connection processing unit makes a PPP connection to the Internet (step s100).
- the ISP 20 gives an IP address as user authentication information for specifying the user terminal 10.
- the user starts the browser 10a of the user terminal 10, specifies the URL of the EC site 60, and requests access. If login is required, enter the ID and password for EC site 60, log in, and access the EC site (step s202).
- the order page for the product is requested (step s204).
- the web server 61 of the EC site 60 transmits the product order page in response to the request (step S300).
- This product order page includes an order processing / confirmation instruction program 60a, which is read by the web browser 10a of the user terminal 10 (step s206).
- the browser 10a transmits a transaction confirmation request to the transaction confirmation server 30 of the ISP 20, and transmits an order processing request to the EC site 60 (step s208).
- the URL of the EC site 60 (Web site ID information) as transaction ID information for specifying each transaction
- the IP of the user terminal 10 as user identification information for specifying each user
- the address (collectively, the IP_ID pair) is sent.
- the transaction confirmation server 30 of the ISP 20 receives the information via the web server 30a and the order confirmation module 30c, and stores the received IP_ID pair in the transaction confirmation information temporary storage means 30f. (Step s102).
- the EC site 60 receives the information via the web server 61, and performs order processing in the order processing module 62 based on the order processing request (step S302).
- the order processing module 62 sends a settlement processing request to the transaction confirmation module 30b of the ISP 20 transaction confirmation server 30 and the user terminal 10
- the IP-ID pair received from is transmitted (step 304).
- the order confirmation module 30c receives the IP-ID pair received from the user terminal 10 and stored in the transaction confirmation information temporary storage means 30f, and the EC site 60
- the IP-ID pair received from is compared with the IP-ID pair (step s104), and if they match, the process proceeds to a credit card acquisition process (step s106). If the order does not match, or if the information received from the EC site 60 does not include the IP address, the order is rejected if a fraudulent order is suspected.
- the transaction confirmation server 30 stores the credit card information of the user corresponding to the IP address from the credit card information storage means 31 via the personal information acquisition module 30d and various DB adapters 30e. Acquisition (step s106) and passes this information to the settlement module 32.
- the payment module 32 performs payment processing using the received credit card information (step s108).
- the ISP 20 performs transaction confirmation, obtains credit card information, and performs settlement processing for the user.
- the system such as a credit card company has a transaction confirmation server 30 ⁇ credit card storage means 3 1, and a payment processing module 32 may be provided, and a credit card company or the like may perform these processing.
- the user identification information for identifying each user may be other than the IP address. Details of how to use such user identification information other than the IP address will be described later.
- the transaction confirmation server 30 and the credit card storage means 31 may be provided in the ISP 20, only the payment processing module 32 may be provided in the credit card company, and only the payment processing may be performed by the credit card company or the like.
- the information is connected between ISP 20 and the credit card company by a secure line other than the Internet, such as a dedicated line, or by a communication method that uses security measures such as encryption and SSL. Is preferably exchanged.
- the overall configuration of the second embodiment is the same as that of the first embodiment (see FIG. 1), in which a user terminal 10 such as a personal computer is connected to an Internet service provider (hereinafter referred to as an ISP) 20. It is connected to the Internet 50 by a PPP (Point-to-Point Protocol) connection via a telephone line or a dial-up line 40 such as an SDN line.
- PPP Point-to-Point Protocol
- IP address a global IP address (hereinafter simply referred to as an IP address) is randomly assigned from the ISP 20 to the user terminal 10, and this IP address is used as user identification information.
- the transaction confirmation server 30 executes transaction confirmation, acquisition of credit card information, settlement processing, and the like.
- the web browser 10a of the user terminal 10 transmits both the order processing request and the transaction confirmation request transmitted based on the order processing / confirmation instruction program 60a. The point is that it is sent to the server 61.
- FIG. 5 is a diagram showing an internal configuration of the transaction confirmation server 30 and the like according to the second embodiment of the present invention.
- the order processing request sent together with the IP-ID pair is processed in the order processing module 62 via the web server 61 of the EC site 60 as in the first embodiment, and the order processing request is processed.
- Transaction confirmation server as a settlement request with the pair Sent to 30 transaction confirmation module 30b.
- the transaction confirmation request sent together with the IP-ID pair is branched by the processing branch module 63 via the Web server 61 of the EC site 60, and the transaction confirmation is performed. It is transmitted to the order confirmation module 30c via the web server 30a of the server 30.
- the processing branch module 63 is, for example, a transaction confirmation / credit card. It is a central provider of acquisition services
- No one other than the person in charge of 1 SP 20 can modify the internal structure.
- the internal configuration of the ISP 20 system is the same as that of the transaction confirmation server 30 except that a web server is not provided, that is, the transaction confirmation server 30 ⁇ credit card information storage means 31 and the like.
- the internal configuration of is exactly the same as in the first embodiment.
- the processing procedure of transaction confirmation—credit card information acquisition—payment processing in the ISP 20 is completely the same as in the first embodiment. Omitted.
- the effects of this embodiment are exactly the same as those of the first embodiment.
- a user terminal 10 such as a personal computer is connected to a telephone line or an ISDN line by an ISP 20. It is connected to the Internet 50 by a PPP connection via a dial-up line 40. Each time a connection is made, I S P
- IP address A global IP address (hereinafter simply referred to as an IP address) is randomly allocated from 20 and this IP address is used as user identification information.
- the transaction confirmation server 30 executes transaction confirmation, acquisition of credit card information, and settlement processing based on the confirmation order program 60a.
- the difference from the first embodiment is that the transaction ID information for identifying each electronic commerce is not the URL of the EC site 60 (Web site ID information), but is used for each transaction (product order) by the transaction confirmation server 30. This is the transaction ID assigned to.
- FIG. 6 is a diagram showing an internal configuration of a transaction confirmation server 30 and the like according to the third embodiment of the present invention.
- the order confirmation module 30c of the transaction confirmation server 30 in the first and second embodiments is changed to a transaction ID generation module 30i in the present embodiment.
- Order processing ⁇ Web browser 10a of the user terminal 10 that reads the confirmation instruction program 60a first sends the transaction ID generation module 3 via the web server 30a of the transaction confirmation server 30. Send a transaction confirmation request to 0 i.
- the transaction confirmation request is not a dummy Web page or the like but an “HTTPGET” command requesting transmission of the transaction ID setting script program 33.
- the IP address of the user terminal 10 is transmitted to the transaction ID generation module 30i.
- the transaction ID setting script program 33 is loaded into the web browser 10a, and the transaction ID information generated by the transaction ID generation module 30i based on the transaction confirmation request is automatically sent to the product order web page. It is a script language program for executing the processing set in the.
- the transaction ID information to be set may or may not be displayed so as to be visible on the product order web page.
- the transaction ID information generated by the transaction ID generation module 30 i is transmitted to the user terminal 10 together with the transaction ID setting script program 33, while the transaction confirmation information as an IP-ID pair together with the IP address of the user terminal. It is stored in the temporary storage means 30f.
- the transaction ID information transmitted to the user terminal 10 forms an IP address and IP_ID pair together with an order processing request sent from the web browser 10a of the user terminal 10 to the EC site 60. Then, the data is transmitted to the Web server 61 of the EC site 60 in the same manner as in the first and second embodiments.
- the order confirmation module 30 c of the transaction confirmation server 30 has been changed to the transaction ID generation module 30 c, the internal configuration of the transaction confirmation server 30 ⁇ credit card information storage means 31, etc. Since it is completely the same as the first embodiment, the details of the same parts as those of the first embodiment are omitted.
- the IP address information assigned to the user terminal at the time of dial-up connection is used as the user identification information for identifying each user.
- the present invention is not limited to this. May be user terminal number information assigned to the user terminal.
- FIG. 7 is a diagram showing the overall configuration in such a modification.
- a user terminal 10 such as a personal computer is always connected to the Internet 50 via a dedicated line 41 by an Internet service provider (hereinafter, ISP) 21.
- ISP Internet service provider
- Other configurations are the same as those of the first embodiment.
- the user accesses the EC (Electronic Commerce) site 60, which is a Web site, using the browser 10a of the user terminal 10. And buy a certain product.
- EC Electronic Commerce
- a dynamic IP address is not assigned from the ISP 20 to the user terminal 10 because the connection is always on. Therefore, the user terminal number information assigned in advance to the user terminal is used as unique user identification information for each user to ensure user authentication.
- the user terminal number information for example, in the case of ISP 20 using a cable TV line, a management number or the like assigned to a set-top box installed in a user's house may be used.
- the Web browser 10a of the user terminal 10 issues a transaction confirmation request to the transaction confirmation server 30 of ISP20, and E.
- the user terminal number information is transmitted together with those requests in place of the IP address in the first embodiment, and in the subsequent processing steps, the IP address Used instead.
- the organization that performs transaction confirmation, credit card information acquisition, and payment processing is not ISP 20 but a credit card company. Good.
- the credit card information may be provided by a credit card company's transaction confirmation server 30 or credit card information storage means 31 in a highly secure communication network such as a dedicated line. All the effects of the above-described embodiments can be realized in the same manner by preventing leakage to a low-security communication network.
- the number information of the user authentication program installed in the user terminal may be used instead of the IP address as the user identification information for specifying each user.
- FIG. 8 is a diagram showing an overall configuration in such a modification.
- a user authentication program 10b is installed in a user terminal 10 such as a personal computer. Based on the order processing embedded in the product order page of the EC site 60 and the confirmation instruction program 60a, the web browser 10a of the user terminal 10 first executes the user authentication program 10b It acquires number information such as the manufacturing serial number as user identification information.
- the connection to the Internet 1 network 50 Form and communication line 40 may be in any form.
- the web browser 10a of the user terminal 10 sends a transaction confirmation request to the transaction confirmation server 30 of the ISP 20 and an order processing request to the EC site 60
- the organization that performs transaction confirmation, credit card information acquisition, and payment processing is not ISP 20 but a credit card company. Good.
- the credit card information may be provided by a credit card company's transaction confirmation server 30 or credit card information storage means 31 in a highly secure communication network such as a dedicated line. All the effects of the above embodiments can be realized in the same way if they are prevented from leaking to a low-security communication network. Is done.
- the number information of the user authentication program 10b is used as the user identification information for specifying each user
- the user installed on the user terminal is used regardless of the user's Internet connection form.
- User authentication can be performed with the existence of the authentication program 10b itself, and user authentication can be performed easily.
- the user authentication program 10b may be integrally included in the Web browser 10a of the user terminal 10 as a plug-in program.
- the user does not need to input his / her own credit card information, and the credit card information is leaked. Can be reliably prevented. Also, it is possible to reliably prevent another person who has illegally acquired credit card information by any means from purchasing the product by impersonating the user.
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Finance (AREA)
- Theoretical Computer Science (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Marketing (AREA)
- Technology Law (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Description
Claims
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/JP2002/000093 WO2003060789A1 (fr) | 2002-01-10 | 2002-01-10 | Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit |
AU2002219584A AU2002219584A1 (en) | 2002-01-10 | 2002-01-10 | Method for confirming web electronic transanction and method for acquiring credit card information |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/JP2002/000093 WO2003060789A1 (fr) | 2002-01-10 | 2002-01-10 | Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2003060789A1 true WO2003060789A1 (fr) | 2003-07-24 |
Family
ID=11738118
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2002/000093 WO2003060789A1 (fr) | 2002-01-10 | 2002-01-10 | Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit |
Country Status (2)
Country | Link |
---|---|
AU (1) | AU2002219584A1 (ja) |
WO (1) | WO2003060789A1 (ja) |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO1997003410A1 (en) * | 1995-07-07 | 1997-01-30 | Andrew Egendorf | Internet billing method |
WO1998021677A1 (fr) * | 1996-11-14 | 1998-05-22 | Matsushita Electric Industrial Co., Ltd. | Systeme de reglement electronique personnel, terminal de ce dernier et appareil permettant de gerer ce systeme |
US5845070A (en) * | 1996-12-18 | 1998-12-01 | Auric Web Systems, Inc. | Security system for internet provider transaction |
JP2001312665A (ja) * | 2000-04-28 | 2001-11-09 | Computer Consulting:Kk | インターネット上の電子商店サーバーとインターネット接続サービス装置を介してインターネットに接続する利用者コンピュータとの間で行われる電子商取引に伴う課金処理方法、インターネット接続サービス装置における課金処理システムおよび電子商店サーバー |
-
2002
- 2002-01-10 WO PCT/JP2002/000093 patent/WO2003060789A1/ja active Application Filing
- 2002-01-10 AU AU2002219584A patent/AU2002219584A1/en not_active Abandoned
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO1997003410A1 (en) * | 1995-07-07 | 1997-01-30 | Andrew Egendorf | Internet billing method |
WO1998021677A1 (fr) * | 1996-11-14 | 1998-05-22 | Matsushita Electric Industrial Co., Ltd. | Systeme de reglement electronique personnel, terminal de ce dernier et appareil permettant de gerer ce systeme |
US5845070A (en) * | 1996-12-18 | 1998-12-01 | Auric Web Systems, Inc. | Security system for internet provider transaction |
JP2001312665A (ja) * | 2000-04-28 | 2001-11-09 | Computer Consulting:Kk | インターネット上の電子商店サーバーとインターネット接続サービス装置を介してインターネットに接続する利用者コンピュータとの間で行われる電子商取引に伴う課金処理方法、インターネット接続サービス装置における課金処理システムおよび電子商店サーバー |
Also Published As
Publication number | Publication date |
---|---|
AU2002219584A1 (en) | 2003-07-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP5638046B2 (ja) | コンピュータ・ネットワーク上において行われる購買を許可する方法およびシステム | |
KR100806993B1 (ko) | 전자 거래를 수행하기 위한 방법 및 장치 | |
JP4363800B2 (ja) | 電子商取引支援装置,電子商取引支援方法およびコンピュータプログラム | |
RU2427893C2 (ru) | Способ аутентификации служебного сервера (варианты) и способ оплаты услуг (варианты) в беспроводном интернете | |
US20070244831A1 (en) | System and method for secure online transaction | |
US20120253978A1 (en) | Methods and apparatus for conducting electronic transactions | |
US20060089906A1 (en) | Method for securing a payment transaction over a public network | |
US20020049914A1 (en) | Electronic service system using safe user information management scheme | |
KR20030001552A (ko) | 안전 트랜잭션 프로토콜 | |
JP2003308438A (ja) | カード決済システム及びカード決済方法 | |
KR20030072852A (ko) | 전자티켓을 구매하고 인증하기 위한 시스템 및 방법 | |
JP2010092477A (ja) | インターネットを利用した電子商取引における顧客情報活用システム及びその方法 | |
JP2002298055A (ja) | 電子商取引システム | |
JP4606680B2 (ja) | 情報家電装置 | |
KR20010008360A (ko) | 전자상거래 신용카드 결제방법 | |
KR100952335B1 (ko) | 범용 id 기반 전자상거래 서비스 제공 방법, 선물추천서비스 제공 방법, 그를 위한 전자상거래 서비스 시스템 및통합 서버 시스템 | |
US20040073491A1 (en) | Off-line buying authentication system and method | |
JP2004126976A (ja) | 電子商取引与信処理方法及び電子商取引システム | |
KR102486527B1 (ko) | 중고 물품 거래자의 신용도 평가 방법 및 서버 | |
WO2003060789A1 (fr) | Procede de confirmation d'une transaction electronique faite sur le web et procede d'acquisition d'informations de carte de credit | |
JP3362353B2 (ja) | 電子商取引決済の方法およびシステム | |
JP2004094619A (ja) | 認証方法およびシステム | |
KR20030073453A (ko) | 전자지불시스템 및 그 운용방법 | |
JP2001265972A (ja) | インターネット上の取引でのエージェントシステム | |
JP2005332416A (ja) | 電子商取引支援サーバ,電子商取引支援方法およびコンピュータプログラム |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ OM PH PL PT RO RU SD SE SG SI SK SL TJ TM TN TR TT TZ UA UG US UZ VN YU ZA ZM ZW |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
122 | Ep: pct application non-entry in european phase | ||
NENP | Non-entry into the national phase |
Ref country code: JP |