[go: up one dir, main page]

CN108780547B - Proxy device for representing multiple certificates - Google Patents

Proxy device for representing multiple certificates Download PDF

Info

Publication number
CN108780547B
CN108780547B CN201680064409.7A CN201680064409A CN108780547B CN 108780547 B CN108780547 B CN 108780547B CN 201680064409 A CN201680064409 A CN 201680064409A CN 108780547 B CN108780547 B CN 108780547B
Authority
CN
China
Prior art keywords
transaction
account
payment
user
message
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201680064409.7A
Other languages
Chinese (zh)
Other versions
CN108780547A (en
Inventor
杰弗里·伊恩·凯恩斯
肯尼思·马格斯
扬·德雷克
丹尼尔·J·麦克唐纳
斯科特·查理斯·巴斯
阿历克斯·本杰明·英格堡
保罗·默里
阿兰·J·摩根
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Transworld Holdings Pcc (s1 Technology Cell)
Original Assignee
Transworld Holdings Pcc (s1 Technology Cell)
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Transworld Holdings Pcc (s1 Technology Cell) filed Critical Transworld Holdings Pcc (s1 Technology Cell)
Priority claimed from PCT/IB2016/001395 external-priority patent/WO2017042629A1/en
Publication of CN108780547A publication Critical patent/CN108780547A/en
Application granted granted Critical
Publication of CN108780547B publication Critical patent/CN108780547B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4016Transaction verification involving fraud or risk level assessment in transaction processing
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K19/00Record carriers for use with machines and with at least a part designed to carry digital markings
    • G06K19/06Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
    • G06K19/067Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
    • G06K19/07Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
    • G06K19/077Constructional details, e.g. mounting of circuits in the carrier
    • G06K19/0772Physical layout of the record carrier
    • G06K19/07722Physical layout of the record carrier the record carrier being multilayered, e.g. laminated sheets
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/02Payment architectures, schemes or protocols involving a neutral party, e.g. certification authority, notary or trusted third party [TTP]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/10Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
    • G06Q20/102Bill distribution or payments
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/202Interconnection or interaction of plural electronic cash registers [ECR] or to host computer, e.g. network details, transfer of information from host to ECR or from ECR to ECR
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/204Point-of-sale [POS] network systems comprising interface for record bearing medium or carrier for electronic funds transfer or payment credit
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • G06Q20/3224Transactions dependent on location of M-devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/352Contactless payments by cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/36Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
    • G06Q20/363Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes with the personal data of a user
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/405Establishing or using transaction specific rules

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Computer Security & Cryptography (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Computer Hardware Design (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

A payment device and a system and method for securely managing financial transactions using the same are provided. In one embodiment, a portable proxy device includes a memory configured to store a plurality of credentials. Each of the plurality of certificates belongs to one of a financial certificate, an identification certificate, or a contract certificate. The portable agent device also includes at least one interface, wherein each of the at least one interface is configured to transmit one of the plurality of credentials to the external device to perform one of a financial function, an identification function, or a contract function.

Description

用于代表多个证书的代理装置Proxy device for representing multiple certificates

相关申请的交叉引用CROSS-REFERENCE TO RELATED APPLICATIONS

本申请要求2015年9月10日提交的美国临时申请US62/283769的权益,通过引用将其全部公开内容并入本文。This application claims the benefit of US Provisional Application US62/283769, filed September 10, 2015, the entire disclosure of which is incorporated herein by reference.

技术领域technical field

本公开总体上涉及金融服务,并且更具体地涉及用于结算金融交易的支付装置和系统。The present disclosure relates generally to financial services, and more particularly to payment devices and systems for settling financial transactions.

背景技术Background technique

20世纪40年代后期,美国引入了例如信用卡等塑料支付卡,作为银行最值得信赖的客户支付用餐和旅行费用的一种方式,无需携带大量现金。从那以后,成千上万家银行已经发行了数十亿支付卡。In the late 1940s, the United States introduced plastic payment cards such as credit cards as a way for the bank's most trusted customers to pay for meals and travel without carrying large amounts of cash. Since then, thousands of banks have issued billions of payment cards.

然而,多种类型的非法活动对传统支付卡系统的安全构成威胁。身份盗用、假冒活动、欺诈、未经授权的账户访问以及其他非法活动都会危害系统的完整性。传统的支付卡以及用于授权和结算卡交易的网络容易受到身份窃贼和其他犯罪分子的广泛攻击。一种主要的支付账户欺诈形式是在进行电子商务时未经授权使用支付账户的明细。另一种主要的支付账户欺诈形式是生产假卡并在商家的销售点(point-of-sale,POS)装置处使用。这些欺诈形式是支付卡本身的生产方式所与生俱来的。具体而言,在传统塑料支付卡上打印或压印的信用卡号码和其他的支付账户明细可以容易地被复制或窃取。另外,支付卡的磁条可被伪造。实际上,由支付卡欺诈造成的银行、商家和消费者的损失正在迅速增加。支付卡欺诈行为使得行业上每年损失近200亿美元。However, many types of illegal activities pose a threat to the security of traditional payment card systems. Identity theft, impersonation, fraud, unauthorized account access, and other illegal activities can compromise system integrity. Traditional payment cards and the networks used to authorize and settle card transactions are vulnerable to widespread attack by identity thieves and other criminals. A major form of payment account fraud is the unauthorized use of payment account details while conducting electronic commerce. Another major form of payment account fraud is the production of counterfeit cards and use at merchants' point-of-sale (POS) devices. These forms of fraud are inherent in the way the payment cards themselves are produced. Specifically, credit card numbers and other payment account details printed or embossed on traditional plastic payment cards can be easily copied or stolen. In addition, the magnetic strip of the payment card can be counterfeited. In fact, losses to banks, merchants and consumers from payment card fraud are rapidly increasing. Payment card fraud costs the industry nearly $20 billion annually.

这些行为是造成银行和支付品牌的主要金融风险的源头,为了打击假冒和盗用欺诈行为,主要的发卡网络已经采用了新的技术来确保在物理销售点仅使用合法的卡。这些由支付卡行业和发卡网络联盟(EMVCo)开发的技术为塑料卡添加了具有保密存储和计算能力的防篡改计算机微芯片。EMVCo是以EuroPay、MasterCard和Visa命名的支付行业联盟,它们是该组织的最初创始人,但现在还包括AmericanExpress、Discover、JCB和UnionPay作为权益合伙人。These practices are a source of major financial risk for banks and payment brands, and in an effort to combat counterfeiting and misappropriation fraud, major card issuing networks have adopted new technology to ensure that only legitimate cards are used at physical points of sale. These technologies, developed by the Payment Card Industry and the Issuing Networks Consortium (EMVCo), add tamper-resistant computer microchips with secure storage and computing power to plastic cards. EMVCo is the payments industry consortium named after EuroPay, MasterCard and Visa, who were the original founders of the group but now also includes AmericanExpress, Discover, JCB and UnionPay as equity partners.

该微芯片保密地存储了在商家POS处进行交易时生成唯一密码签名所需的信息和程序。计算过程在每次交易时都安全且保密地在嵌入式微芯片内部执行,并且其结果与支付账户数据一起通过现有支付网络传递到发卡银行,在发行银行处使用存储在卡中的相同信息进行验证。存储的信息绝不被发行机构披露,并且不能通过任何实际手段从微芯片中提取。如此微芯片嵌入式卡为在物理销售点执行的每次卡交易提供一次性代码。如果所有商家都遵守这一新机制,那么通过盗用账户数据就能制造假卡的风险被大大消除。The microchip confidentially stores the information and procedures needed to generate a unique cryptographic signature when making a transaction at the merchant's POS. The calculation process is performed securely and confidentially inside the embedded microchip at each transaction, and the result is passed along with the payment account data through the existing payment network to the issuing bank, where it is performed using the same information stored in the card. verify. The stored information is never disclosed by the issuing agency and cannot be extracted from the microchip by any practical means. Such microchip embedded cards provide a one-time code for each card transaction performed at the physical point of sale. If all merchants comply with this new mechanism, the risk of counterfeit cards being created by theft of account data is greatly eliminated.

发行机构试图打击欺诈的另一种方式是提供具有近场通信(near fieldcommunication,NFC)组件的卡。启用NFC组件的卡允许用户在NFC读取器附近大约10厘米的范围内轻敲或刷过该卡。Another way issuers are trying to combat fraud is to offer cards with near field communication (NFC) components. An NFC component-enabled card allows the user to tap or swipe the card within about 10 centimeters of the NFC reader.

然而,微芯片嵌入式卡(也称为EMV卡或智能卡)以及启用NFC的卡也必须在尚未采用新标准的环境中工作。许多商家尚未采用能够激活微芯片卡并读取密码的启用EMV的终端或可读取无线通信信号的NFC读取器。为了确保支付卡被普遍接受,发行机构在卡的背面设置一个传统的磁条。However, microchip embedded cards (also known as EMV cards or smart cards) as well as NFC-enabled cards must also work in environments that have not yet adopted the new standard. Many merchants have not yet adopted EMV-enabled terminals that can activate microchip cards and read passwords, or NFC readers that can read wireless communication signals. To ensure payment cards are universally accepted, issuers place a traditional magnetic stripe on the back of the card.

此外,为了实现电子商务和电话交易,发行机构还设置了印刷在卡上和/或压印在塑料上的支付账号。因此,不仅微型芯片和NFC组件可用于进行金融交易,磁条也可用于使用POS刷卡方式的金融交易或者该帐号也可用于电话或互联网交易。卡将账户信息传送给商家终端的方法被称为模式。换句话说,微芯片卡可以用于至少四种不同的金融交易模式,包括例如磁条划动模式、使用EMV芯片的各种模式、NFC模式、和手动卡号输入模式。微芯片也可能启用其他模式,这是可能存在超过四种不同的金融交易模式的一个原因。In addition, in order to enable e-commerce and telephone transactions, issuers also set up payment account numbers printed on cards and/or embossed on plastic. Therefore, not only the microchip and the NFC component can be used for financial transactions, the magnetic strip can also be used for financial transactions using the POS swipe method or the account number can also be used for telephone or Internet transactions. The method by which the card communicates account information to the merchant terminal is called a schema. In other words, the microchip card can be used in at least four different financial transaction modes, including, for example, a magnetic stripe swipe mode, various modes using an EMV chip, an NFC mode, and a manual card number entry mode. Microchips may also enable other modes, which is one reason there may be more than four different modes of financial transactions.

遇到这些新的EMV或NFC支付卡之一并且即便在短暂时间内物理控制了卡的窃贼也可以轻易窃取敏感的支付账户数据,而无需考虑嵌入式芯片或NFC组件。这可以通过从磁条中读取支付数据来完成,以准备一个伪造的卡片。窃贼还可以通过给该卡拍照捕获卡号来窃取数据用于欺诈性电子商务。应该注意的是,磁条数据和打印数据都不受数字安全手段如密码术的保护。然后泄露的数据可能在还没有采用EMV系统的不太安全的零售商处使用,或者窃贼可以上网进行电子商务交易。A thief who encounters one of these new EMV or NFC payment cards and has physical control of the card even for a short period of time can easily steal sensitive payment account data without having to think about the embedded chip or NFC components. This can be done by reading the payment data from the magnetic strip to prepare a counterfeit card. Thieves can also steal data for fraudulent e-commerce by taking a picture of the card to capture the card number. It should be noted that neither the magnetic stripe data nor the print data is protected by digital security means such as cryptography. The leaked data could then be used at less secure retailers that have not yet adopted an EMV system, or thieves could go online to conduct e-commerce transactions.

因此,需要更安全的支付卡。为了解决上述问题并提高客户对支付卡体验的满意度和控制力,本发明为支付卡和金融网络以及金融交易授权和结算引入了若干创新元素。Therefore, there is a need for more secure payment cards. To address the above problems and improve customer satisfaction and control over the payment card experience, the present invention introduces several innovative elements to payment cards and financial networks, as well as financial transaction authorization and settlement.

发明内容SUMMARY OF THE INVENTION

本公开描述了使用支付装置安全地管理金融交易的支付装置以及相关系统和方法。支付装置可以采取例如便携式代理装置、塑料支付卡、虚拟卡、可穿戴商务装置、嵌入在移动装置中的一个或多个组件、在移动装置或计算机上运行的应用等形式,以及其他支付证书形式。根据一个实施方式,便携式代理装置包括被配置为存储多个证书的存储器。多个证书中的每一个都与金融证书、标识证书或合同证书中的一个有关。便携式代理装置还包括至少一个接口,其中,这些接口中的每一个被配置为将多个证书之一与一个外部装置进行通信以完成金融功能、标识功能或合同功能之一。The present disclosure describes payment devices and related systems and methods for securely managing financial transactions using the payment devices. Payment devices may take the form of, for example, portable proxy devices, plastic payment cards, virtual cards, wearable commerce devices, one or more components embedded in a mobile device, an application running on a mobile device or computer, and other forms of payment certificates . According to one embodiment, the portable proxy device includes a memory configured to store a plurality of credentials. Each of the plurality of certificates is related to one of a financial certificate, an identity certificate or a contract certificate. The portable proxy device also includes at least one interface, wherein each of the interfaces is configured to communicate one of the plurality of credentials with an external device to perform one of a financial function, an identification function, or a contract function.

根据另一实施方式,一种系统包括一个销售点(POS)装置,该POS被配置为可从移动代理装置获取至少一个证书,所述至少一个证书中的每一个与金融证书、标识证书或合同证书之一有关。该系统还包括支付处理器,该支付处理器被配置为可接收从移动代理装置获得的至少一个证书并执行金融功能、标识功能或合同功能中的至少一个。According to another embodiment, a system includes a point-of-sale (POS) device configured to obtain at least one certificate from a mobile agent device, each of the at least one certificate being associated with a financial certificate, an identification certificate, or a contract One of the certificates is related. The system also includes a payment processor configured to receive at least one credential obtained from the mobile agent device and to perform at least one of a financial function, an identification function, or a contract function.

在本公开中描述的各种实施方式可包括另外的系统、方法、特征和优点,其可能无须在本文中明确地公开,但是对于本领域的普通技术人员来说一查看以下详细描述和附图就将是显而易见的。旨在将所有这些系统、方法、特征和优点包括在本公开内容中并受附加的权利要求所保护。The various embodiments described in this disclosure may include additional systems, methods, features, and advantages that may not need to be explicitly disclosed herein, but will be apparent to those of ordinary skill in the art upon review of the following detailed description and accompanying drawings. will be obvious. It is intended that all such systems, methods, features and advantages be included within this disclosure and protected by the accompanying claims.

附图说明Description of drawings

以下附图的特征和组件被图示以强调本公开的一般原理并且无须按比例绘制。为了一致性和清晰度,贯穿附图的相应特征和组件通过匹配附图标记来指定。The features and components of the following figures are illustrated to emphasize the general principles of the disclosure and are not necessarily drawn to scale. For consistency and clarity, corresponding features and components have been designated throughout the drawings by matching reference numerals.

图1是示出了根据本公开各实施方式的支付系统的框图。FIG. 1 is a block diagram illustrating a payment system according to various embodiments of the present disclosure.

图2A和图2B分别示出了根据本公开各实施方式的第一支付装置的前视图和后视图。2A and 2B illustrate a front view and a rear view, respectively, of a first payment device according to various embodiments of the present disclosure.

图3A和3B分别示出了根据本公开各实施方式的第二支付装置的前视图和后视图。3A and 3B illustrate a front view and a rear view, respectively, of a second payment device according to various embodiments of the present disclosure.

图4是示出了根据本公开各实施方式的图1所示的账户关联装置的框图。FIG. 4 is a block diagram illustrating the account association apparatus shown in FIG. 1 according to various embodiments of the present disclosure.

图5是示出了根据本公开各实施方式的图4所示的用户账户模块的框图。5 is a block diagram illustrating the user account module shown in FIG. 4 in accordance with various embodiments of the present disclosure.

图6是示出了根据本公开各实施方式的代表多个卡的代理装置的图。FIG. 6 is a diagram illustrating a proxy device representing a plurality of cards according to various embodiments of the present disclosure.

图7是示出了根据本公开各实施方式的代表多个装置的移动代理装置的图。7 is a diagram illustrating a mobile agent device representing a plurality of devices in accordance with various embodiments of the present disclosure.

图8是示出了根据本公开各实施方式的允许可选证书的图6和图7的代理装置的一般用途的流程图。8 is a flow diagram illustrating the general use of the proxy device of FIGS. 6 and 7 to allow optional credentials in accordance with various embodiments of the present disclosure.

图9是示出了根据本公开各实施方式的处于默认模式的图6和图7的代理装置的一般用途的流程图。9 is a flow diagram illustrating the general use of the proxy device of FIGS. 6 and 7 in default mode according to various embodiments of the present disclosure.

图10是示出了根据本公开各实施方式的图1的支付系统10的详细操作方法的流程图。FIG. 10 is a flowchart illustrating a detailed method of operation of the payment system 10 of FIG. 1 according to various embodiments of the present disclosure.

图11是示出了根据本公开各实施方式的图1的支付系统10的另一详细操作方法的流程图。FIG. 11 is a flowchart illustrating another detailed method of operation of the payment system 10 of FIG. 1 according to various embodiments of the present disclosure.

图12是示出了根据本公开各实施方式的金融交易的金融信息发送方法的流程图。FIG. 12 is a flowchart illustrating a financial information transmission method of a financial transaction according to various embodiments of the present disclosure.

图13是示出了根据本公开各实施方式的用于用户登记的令牌化过程的操作方法的流程图。13 is a flowchart illustrating a method of operation of a tokenization process for user registration according to various embodiments of the present disclosure.

图14是示出了根据本公开各实施方式的用于注册的令牌化过程的操作方法的流程图。14 is a flowchart illustrating a method of operation of a tokenization process for registration according to various embodiments of the present disclosure.

图15示出了根据本公开各实施方式的交易流程架构。Figure 15 illustrates a transaction flow architecture according to various embodiments of the present disclosure.

图16-20是示出了根据本公开各实施方式的交易流程过程的概览的流程图。16-20 are flowcharts illustrating an overview of a transaction flow process in accordance with various embodiments of the present disclosure.

具体实施方式Detailed ways

本发明涉及支付装置,举例来说,例如塑料支付卡、虚拟卡、可穿戴商务装置、嵌入在移动装置中的组件、在移动装置或计算机上运行的应用以及其他支付证书。本发明还涉及使用支付装置进行金融交易的系统和方法。本发明可包括商业上可行的计算服务、移动应用程序和网站,并且可与使用本文所述的支付卡或其他支付装置的发行机构一起实施。本发明引入了可被现有装置和有效证书发行机构采用以对付各种欺诈形式的若干新颖元素。本文件中使用的术语“有效证书”表示有效的资金调度工具,可能包括但不限于信用卡、签账卡、直接存款账户、储蓄账户、支票账户、会员卡、礼品卡或其他卡或装置。The present invention relates to payment devices such as, for example, plastic payment cards, virtual cards, wearable business devices, components embedded in mobile devices, applications running on mobile devices or computers, and other payment credentials. The present invention also relates to systems and methods for conducting financial transactions using payment devices. The present invention may include commercially viable computing services, mobile applications and websites, and may be implemented with issuers using payment cards or other payment devices as described herein. The present invention introduces several novel elements that can be employed by existing devices and valid certificate issuing authorities to combat various forms of fraud. The term "valid credential" as used in this document means a valid funds transfer instrument, which may include, but is not limited to, a credit card, charge card, direct deposit account, savings account, checking account, loyalty card, gift card or other card or device.

本发明包括多模式支付装置,其可用于针对不同类型的金融交易的各种模式。例如,这里描述的支付装置可包括用于完成交易的多种模式。一些模式可包括涉及嵌入在装置中的微芯片的那些模式、涉及近场通信(NFC)组件的那些模式、涉及磁条的那些模式、涉及在在线交易中输入装置号和卡验证值(CVV)的模式、和/或其他模式。本发明包括新颖的减少欺骗的特征、移动电话应用和伴随的网站以控制该新颖的减少欺诈的功能。另外,在线和零售商的授权和结算网络服务中都可使用计算服务。The present invention includes a multimodal payment device that can be used in various modes for different types of financial transactions. For example, the payment devices described herein may include multiple modes for completing transactions. Some modes may include those involving microchips embedded in the device, those involving Near Field Communication (NFC) components, those involving magnetic stripes, those involving entering device numbers and card verification values (CVVs) in online transactions mode, and/or other modes. The present invention includes novel fraud reduction features, mobile phone applications and accompanying web sites to control the novel fraud reduction functions. In addition, computing services are available in both online and retailer authorization and settlement network services.

支付装置的当前发行实践是在支付装置的所有各种模式(即,包括磁条、EMV芯片、NFC等)中包括用户的单个主帐号(PAN)明细,其直接对应于用户的实际有效证书。然而,如在本公开中所描述的,通过使用替代账号或令牌来代替主账号(PAN),可在商家和发行银行之间插入账户关联装置以补足交易的安全性,或由发行银行作为处理支付的一部分调用该账户关联装置。在交易认证和结算之前,本文描述的支付装置系统安全地在网络中替换用户的PAN明细。这样,防止了将用户的PAN明细泄露给商家。The current issuance practice for payment devices is to include the user's single primary account number (PAN) details in all of the various modes of the payment device (ie including magnetic stripe, EMV chip, NFC, etc.), which directly correspond to the user's actual valid credentials. However, by using an alternate account number or token in place of the primary account number (PAN), as described in this disclosure, account linking means can be inserted between the merchant and the issuing bank to complement the security of the transaction, or by the issuing bank as a Part of processing the payment invokes the account linking means. The payment device system described herein securely replaces the user's PAN details in the network prior to transaction authentication and settlement. In this way, leakage of the user's PAN details to the merchant is prevented.

本发明针对每个支付装置和/或每个支付装置的每个模式使用多组不同、匿名和不可预测的替代账户明细。在物理支付卡的示例中,一组替代账户明细可与EMV芯片的一个或多个模式关联,另一组可与EMV芯片的另一模式关联,另一组替代账户明细可以与NFC组件关联,另一组用于磁条,另一组在电子商务中使用,以及另一组用于手动输入。使用多组不同的替代账户明细可以防止跨模式支付欺诈。The present invention uses multiple sets of distinct, anonymous and unpredictable alternate account details for each payment device and/or each mode of each payment device. In the example of a physical payment card, one set of alternate account details may be associated with one or more modes of the EMV chip, another set may be associated with another mode of the EMV chip, and another set of alternate account details may be associated with the NFC component, Another set is for magnetic stripes, another set is used in e-commerce, and another set is used for manual entry. Using multiple sets of different alternate account details can prevent cross-modal payment fraud.

目前的做法是在EMV芯片中包含相同的PAN,该芯片包含在磁条中并且被印刷在装置上。当出现多种模式中的任何一种时,金融交易均可被接受,这使得交叉模式欺诈成为可能。例如,窃贼可能会拦截EMV装置明细并生成伪造的磁条装置。此外,窃贼可能会使用装置数据读取器同时收集EMV和磁条账户明细,并执行未经授权的电子商务交易。然而,本发明不受限于相同PAN用于所有模式。相反,本发明使用多组不同替代账户明细对应于多个有效证书,其中每个替代账户可关联一个不同模式。这样,可以防止跨模式支付欺诈。Current practice is to include the same PAN in an EMV chip, which is contained in a magnetic strip and printed on the device. Financial transactions are accepted when any of a number of patterns are present, making cross-modal fraud possible. For example, thieves may intercept EMV device details and generate counterfeit magnetic strip devices. Additionally, thieves may use device data readers to collect both EMV and magnetic stripe account details and perform unauthorized e-commerce transactions. However, the present invention is not limited to the same PAN being used for all modes. Instead, the present invention uses multiple sets of different alternate account details corresponding to multiple valid credentials, where each alternate account may be associated with a different schema. In this way, cross-modal payment fraud can be prevented.

应该注意的是,本公开中描述的支付装置可以实现为信用卡、借记卡、虚拟卡、可穿戴装置,物联网(loT)装置、嵌入在移动装置中的组件和/或应用、和/或其他金融证书。在其他实施例中,本公开中描述的支付装置可应用于在除了商业之外的其他环境中使用的非支付装置。举例来说,非支付装置(例如,会员卡、移动装置和其他非金融证书)可以应用于其他功能以作为供电子认证身份的代理证书,诸如用于健康保险目的、驾驶执照目的等,以访问安全的位置、提供用户的影像识别、以及其他用途。此外,可与替代账户明细相关联的有效证书可能是支付和/或非支付证书,例如会员证书、健康保险证书以及其他金融或非金融证书。It should be noted that the payment devices described in this disclosure may be implemented as credit cards, debit cards, virtual cards, wearable devices, Internet of Things (IoT) devices, components and/or applications embedded in mobile devices, and/or Other financial certificates. In other embodiments, the payment devices described in this disclosure may be applied to non-payment devices used in environments other than business. For example, non-payment devices (eg, loyalty cards, mobile devices, and other non-financial credentials) may be applied to other functions as proxy credentials for electronically authenticating identities, such as for health insurance purposes, driver's license purposes, etc., to access Secure location, provide user image recognition, and other uses. Additionally, valid credentials that may be associated with alternate account details may be payment and/or non-payment credentials, such as membership credentials, health insurance credentials, and other financial or non-financial credentials.

图1是示出了支付系统10的一个实施例的框图,其中发行机构28向用户发行诸如信用卡或借记卡的支付装置。在其他实施例中,用户可使用除了支付卡之外的其他类型的代理证书,例如移动装置。根据图1的实施例,支付系统10包括公共网络12、一个或多个用户装置14、一个或多个商家终端16、一个或多个无线通信天线18、一个或多个移动装置20、以及账户关联装置24。1 is a block diagram illustrating one embodiment of a payment system 10 in which an issuer 28 issues a payment device, such as a credit or debit card, to a user. In other embodiments, the user may use other types of proxy credentials than payment cards, such as mobile devices. According to the embodiment of FIG. 1, a payment system 10 includes a public network 12, one or more user devices 14, one or more merchant terminals 16, one or more wireless communication antennas 18, one or more mobile devices 20, and an account Associated device 24 .

术语“商家终端”用于描述为发起支付的商家提供功能的物理终端、网站或其他装置。商家终端可以嵌入到POS装置中,并且可以像在商务网站处理中那样是“虚拟的”。此外,商家终端可以是不涉及装置、卡片、客户、商家或货物的后台装置,例如当针对服务启动经常性支付时,“商家终端”可以代表POS装置、商家在线系统、以及商家拥有/控制的其他机制以开展各种购买模式。商家终端可包括使用一种或多种类型的技术(例如,EMV芯片、磁条、NFC、电子商务等)以用于不同支付模式的任何商家系统。The term "merchant terminal" is used to describe a physical terminal, website or other device that provides functionality for the merchant who initiates the payment. Merchant terminals can be embedded into POS devices and can be "virtual" as in commerce website processing. Additionally, a merchant terminal may be a backend device that does not involve devices, cards, customers, merchants, or goods, such as when initiating recurring payments for services, "merchant terminals" may represent POS devices, merchant online systems, and merchant owned/controlled Other mechanisms to carry out various buying patterns. Merchant terminals may include any merchant system that uses one or more types of technology (eg, EMV chip, magnetic strip, NFC, e-commerce, etc.) for different payment modes.

网络12可包括广域网、因特网、专用网络和/或其他公共可访问的网络。而且,网络12可包括与各商家相关联的局域网。网络12也可与连接到天线18的一个或多个蜂窝网络进行通信。Network 12 may include a wide area network, the Internet, a private network, and/or other publicly accessible networks. Also, the network 12 may include local area networks associated with various merchants. The network 12 may also communicate with one or more cellular networks connected to the antenna 18 .

用户装置14、商家终端16和天线18可通过一个或多个有线或无线连接装置连接到网络12,以实现各组件之间的电子通信。无线通信天线18可包括用于与移动装置20通信的一个或多个蜂窝塔、轨道卫星或其他无线通信集线器。User devices 14, merchant terminals 16, and antennas 18 may be connected to network 12 through one or more wired or wireless connections to enable electronic communication between the various components. The wireless communication antenna 18 may include one or more cellular towers, orbiting satellites, or other wireless communication hubs for communicating with the mobile device 20 .

账户关联装置24可以是服务器、网页服务器、运行在服务器上的软件、硬件装置、或任何合适的中间计算装置,用于提供各种交易服务。账户关联装置24还连接到网络26,网络26也经由有线或无线连接装置连接到一个或多个发行机构28以及一个或多个数据库30。网络26可以是专用网络、局域网、虚拟专用网络(VPN)、或具有高加密级别的公共网络。账户关联装置24可配置为将信息存储在数据库30中,该数据库将一个或多个替代账户指引到发行机构28的用户或客户所拥有的真实账户。Account linking device 24 may be a server, a web server, software running on a server, a hardware device, or any suitable intermediate computing device for providing various transaction services. Account linking means 24 is also connected to a network 26, which is also connected to one or more issuers 28 and one or more databases 30 via wired or wireless connection means. The network 26 may be a private network, a local area network, a virtual private network (VPN), or a public network with a high level of encryption. Account linking device 24 may be configured to store information in database 30 that directs one or more alternate accounts to real accounts owned by users or customers of issuer 28 .

在购买操作期间,已向其发放支付装置的用户可将该支付装置用于商品或服务的支付。支付装置可以在商家终端16的其中之一处展示给商家。应该注意的是,多个商家终端16可与相同的商家关联,以通过各种模式获得账户信息。实际上,多个商家终端16可与商家使用的单个装置关联以在单个POS装置处获取信息。POS装置可通过利用嵌入在装置中的微芯片的第一模式或通过其他模式从支付装置获得信息,这可能涉及在装置上使用NFC组件或磁条。在其他交易中,例如在线或电话交易,在装置上打印和/或压印的装置号可以通过电子方式或由商家的接单代表输入。During a purchase operation, the user to whom the payment device has been issued can use the payment device to pay for goods or services. The payment device may be presented to the merchant at one of the merchant terminals 16 . It should be noted that multiple merchant terminals 16 may be associated with the same merchant to obtain account information through various modes. In effect, multiple merchant terminals 16 may be associated with a single device used by the merchant to obtain information at a single POS device. The POS device may obtain information from the payment device through a first mode utilizing a microchip embedded in the device or through other modes, which may involve the use of an NFC component or a magnetic strip on the device. In other transactions, such as online or telephone transactions, the device number printed and/or imprinted on the device may be entered electronically or by the merchant's order taking representative.

根据替代实施例,支付系统10可替代地配置为一种用于执行非支付动作的系统。代替如本文所公开的执行与金融账户有关的各种功能,非支付系统可处理发行机构以外的实体的其他类型的证书。According to alternative embodiments, payment system 10 may alternatively be configured as a system for performing non-payment actions. Instead of performing various functions related to financial accounts as disclosed herein, non-payment systems may process other types of credentials from entities other than issuers.

账户关联装置24使用数据库30将任意替代账户数据值关联至用户的有效证书明细的明细中。任意替代账户数据值和有效证书明细可由用户在登入账户关联装置24提供的服务时提供。在一个实施例中,用户可在任意时间使用移动装置20之一上的移动应用或使用一台用户装置14经由账户关联装置24提供的网络服务来改变与替代账户相关联的有效证书明细,用户装置14可以是传统的计算机或网络浏览器。账户关联装置24启用与多个替代账户相关联的多个有效证书,有效证书可能是金融证书或非金融证书。在一个实施例中,账户关联装置24使得来自发行机构28的有效证书与多个替代账户相关联。在一个实施例中,账户关联装置24使得来自发行机构28和其他金融或非金融机构的有效证书与多个替代账户相关联。The account association means 24 uses the database 30 to associate any alternate account data values to the details of the user's valid credential details. Any alternate account data values and valid credential details may be provided by the user when logging into the services provided by the account linking device 24 . In one embodiment, the user may use a mobile application on one of the mobile devices 20 at any time or use a web service provided by one of the user devices 14 via the account association device 24 to change the valid credential details associated with the alternate account, the user Device 14 may be a conventional computer or web browser. Account association means 24 enables a plurality of valid credentials, which may be financial or non-financial credentials, associated with a plurality of alternate accounts. In one embodiment, account associating means 24 associates valid credentials from issuer 28 with a plurality of alternate accounts. In one embodiment, account associating means 24 associates valid credentials from issuers 28 and other financial or non-financial institutions with a plurality of alternate accounts.

账户关联装置24被部署到支付系统10中,使得由商家通过商家终端16之一展示的所有交易由账户关联装置24接收,这些交易用于针对在每个装置上代表的多个替代账户之一授权。账户关联装置24使用可定制规则引擎将多个替代账户与一个或多个用户有效证书相关联,该可定制规则引擎对包括但不限于当前交易数据的一个或多个事实敏感。当前交易数据可包括但不限于例如商家类别代码、商家ID、交易量、替代账号、服务代码、装置安全代码等。The account linking device 24 is deployed into the payment system 10 such that all transactions presented by the merchant through one of the merchant terminals 16 are received by the account linking device 24 for one of the multiple alternate accounts represented on each device authorized. Account association device 24 associates the plurality of alternate accounts with one or more user valid credentials using a customizable rules engine that is sensitive to one or more facts including, but not limited to, current transaction data. Current transaction data may include, but is not limited to, for example, merchant category codes, merchant IDs, transaction volumes, alternate account numbers, service codes, device security codes, and the like.

账户关联装置24也可通过数据库30访问数据,这些数据包括但不限于针对特定替代账户展示的先前交易、针对与同一用户关联的另一替代账户展示的先前交易、针对同一商家或商家位置的其他用户的先前交易、交易时用户的主要移动电话的地理位置被展示。地理位置的确定可通过例如全球定位系统(GPS)、与诸如Wi-FiTM、BluetoothTM、蓝牙低能量信标、ZigbeeTM、Z-waveTM、或这些及其他位置敏感因素的任意组合的无线电信号的距离。替代账户可以与有效证书关联,除非另有关联,否则它们自身没有余额或既定信用,并且不能用于结算任何交易。Account linking device 24 may also access data through database 30 including, but not limited to, previous transactions presented for a particular alternate account, previous transactions presented for another alternate account associated with the same user, other transactions for the same merchant or merchant location The user's previous transactions, the geographic location of the user's primary mobile phone at the time of the transaction, are displayed. The geographic location can be determined by, for example, the Global Positioning System (GPS), radios such as Wi-Fi , Bluetooth , Bluetooth Low Energy Beacons, Zigbee , Z-wave , or any combination of these and other location-sensitive factors distance of the signal. Alternative accounts can be associated with valid credentials, unless otherwise associated, have no balance or established credit of their own, and cannot be used to settle any transactions.

支付系统10可用于为支付装置的使用提供安全性。支付系统10可包括连接到公共网络12的第一商家终端16,其中第一商家终端16配置为从与用户拥有的支付装置关联的第一组信息中获得第一替代账户的明细。支付系统10可包括连接到公共网络12的第二商家终端16,其中第二商家终端16配置为从与支付装置关联的第二组信息中获得第二替代账户的明细。在该实施例中,支付系统10还包括连接到公共网络12的账户关联装置24。账户关联装置24配置为分别从第一和第二商家终端16接收第一和第二替代账户的明细。账户关联装置24进一步配置为将第一和第二替代账户与属于用户的有效证书相关联。账户关联装置24还管理发行机构28与第一和第二商家终端16之间的金融交易,用户从发行机构28保存有效证书。而且,应该注意的是,第一组信息优选不同于第二组信息。The payment system 10 may be used to provide security for the use of payment devices. The payment system 10 may include a first merchant terminal 16 connected to the public network 12, wherein the first merchant terminal 16 is configured to obtain details of the first alternate account from a first set of information associated with a payment device owned by the user. The payment system 10 may include a second merchant terminal 16 connected to the public network 12, wherein the second merchant terminal 16 is configured to obtain details of the second alternate account from a second set of information associated with the payment device. In this embodiment, the payment system 10 also includes account linking means 24 connected to the public network 12 . The account associating means 24 is configured to receive details of the first and second alternate accounts from the first and second merchant terminals 16, respectively. The account association means 24 is further configured to associate the first and second alternate accounts with valid credentials belonging to the user. The account linking device 24 also manages financial transactions between the issuer 28 and the first and second merchant terminals 16, from which the user maintains valid credentials. Furthermore, it should be noted that the first set of information is preferably different from the second set of information.

支付系统10还可包括连接到公共网络12的第三商家终端16,其中第三商家终端16可配置为从第三个并优选与支付装置关联的不同组的信息中获得第三替代账户的明细。在一些实施例中,第一组信息获取自支付装置上的微芯片,第二组信息获取自嵌入在支付装置中的NFC组件,第三组信息获取自支付装置上的磁条,以及第四组信息获取自打印和/或压印在支付装置上的卡号。第一、第二、第三、第四和其他组的信息可由发行机构生成。这些组信息中的某些可手动输入商家终端中。The payment system 10 may also include a third merchant terminal 16 connected to the public network 12, wherein the third merchant terminal 16 may be configured to obtain details of the third alternate account from a third and preferably a different set of information associated with the payment device . In some embodiments, a first set of information is obtained from a microchip on the payment device, a second set of information is obtained from an NFC component embedded in the payment device, a third set of information is obtained from a magnetic strip on the payment device, and a fourth set of information is obtained from a magnetic stripe on the payment device. The group information is obtained from the card number printed and/or embossed on the payment device. The first, second, third, fourth and other sets of information may be generated by the issuing agency. Some of these group information can be manually entered into the merchant terminal.

替代实施例包括支付系统10,其中支付装置没有印刷和/或压印帐号。而且,支付装置可能没有磁条或者其他模式。在这种情况下,用户可仅在商家终端处使用支付装置,仅使用微芯片和/或NFC组件、或装置上剩余的模式。Alternative embodiments include payment system 10 wherein the payment device does not have a printed and/or embossed account number. Also, the payment device may not have a magnetic strip or other pattern. In this case, the user may use the payment device only at the merchant terminal, using only the microchip and/or NFC components, or the remaining modes on the device.

可将不同组的账户明细传送给用户以进行在线或电话交易。可通过计算机(例如,用户装置14)和/或经由移动装置20将不同组的明细邮寄、发送电子邮件或发信息给用户。Account details for different groups can be communicated to the user for online or telephone transactions. Details of the different groups may be mailed, emailed, or messaged to the user by computer (eg, user device 14 ) and/or via mobile device 20 .

在一些实施例中,与用户关联的移动装置20可并入支付系统10中。商家终端16中的其中一个可以配置为进行在线交易的在线商家装置,并且移动装置20可配置为存储、检索从账户关联装置24生成的一个或者计算动态卡验证值(d-CVV),其被发送到或手动输入至在线商家装置。在一些情况下,一个或多个商家终端16可被嵌入在销售点(POS)装置内。In some embodiments, the mobile device 20 associated with the user may be incorporated into the payment system 10 . One of the merchant terminals 16 may be configured as an online merchant device that conducts online transactions, and the mobile device 20 may be configured to store, retrieve, or calculate a dynamic card verification value (d-CVV) generated from the account association device 24, which is Sent to or manually entered into an online merchant device. In some cases, one or more merchant terminals 16 may be embedded within a point-of-sale (POS) device.

与用户关联的用户装置14配置为使用户能够经由账户关联装置24管理替代账户和有效证书。账户关联装置24配置为使用户能够输入登记信息、监视替代账户的活动、启用和禁用与支付装置进行交易的一种或多种模式、若支付装置丢失或被盗的话就报警、以及提供与各种有效证书有关的信息。举例来说,账户关联装置24可提供包括一个或多个网页的网站,使得用户能够使用用户装置14浏览该网站。User device 14 associated with the user is configured to enable the user to manage alternate accounts and valid credentials via account association device 24 . The account linking device 24 is configured to enable the user to enter registration information, monitor the activity of the alternate account, enable and disable one or more modes of transaction with the payment device, alert the police if the payment device is lost or stolen, and provide communication with various accounts. information about a valid certificate. For example, account association device 24 may provide a website that includes one or more web pages, enabling a user to browse the website using user device 14 .

图2A和2B示出了根据本发明各实施例的第一类型的支付装置36。图2A示出了支付装置36的正面38,而图2B示出了支付装置36的背面40。支付装置36可在其正面38上包括发行机构28的名称42、微芯片44、装置编号46、客户名称48和到期日50。在一些实施例中,装置编号46可被压印在支付装置36上。另外,支付装置36的背面40可包括磁条52、签名框54和卡验证值(CVV)56。支付装置36可进一步包括可能被嵌入在支付装置36的表面下的NFC组件,用于实现非接触式交易。2A and 2B illustrate a first type of payment device 36 in accordance with various embodiments of the present invention. FIG. 2A shows the front side 38 of the payment device 36 and FIG. 2B shows the back side 40 of the payment device 36 . The payment device 36 may include the name 42 of the issuer 28 , the microchip 44 , the device number 46 , the customer name 48 and the expiration date 50 on the front face 38 thereof. In some embodiments, the device number 46 may be embossed on the payment device 36 . Additionally, the back 40 of the payment device 36 may include a magnetic strip 52 , a signature box 54 and a card verification value (CVV) 56 . Payment device 36 may further include an NFC component, possibly embedded under the surface of payment device 36, for enabling contactless transactions.

在一个实施例中,支付装置36可以是由发行银行根据数个全球品牌支付网络之一的发行规则发行的塑料EMV微芯片卡。支付装置36包括配置和个性化,使得它可在任何支持EMV的商家POS处使用。In one embodiment, payment device 36 may be a plastic EMV microchip card issued by the issuing bank according to the issuing rules of one of several global branded payment networks. Payment device 36 includes configuration and personalization so that it can be used at any EMV enabled merchant POS.

然而,包含在微芯片44或其他模式中的账户明细并不是主账号的账户明细,而是由发行机构生成的任意值。账户明细在这里可被称为“替代账户明细”。替代账户明细用作有效证书的替代品,但不能标识任何特定用户。而是指由发行机构生成的替代账户,但不与任何特定的有效证书相关联。However, the account details contained in the microchip 44 or other schema are not account details for the primary account number, but rather arbitrary values generated by the issuer. Account details may be referred to herein as "alternative account details". Alternate account details are used as a substitute for a valid certificate, but do not identify any specific user. Rather, it refers to an alternate account generated by the issuer, but not associated with any specific valid certificate.

在图2的实施例中,微芯片44和磁条52包含用于两个不同替代账户的不同支付账户号码、到期日和其他令牌账户明细。简而言之,微芯片44和磁条52似乎代表完全不同的支付账户。在支持EMV的商家处使用微芯片44执行的交易将包含与在同一装置36上使用磁条52的商家处执行的交易不同的账户明细。此外,NFC交易可使用与EMV启用模式和磁条模式不同的支付账户明细。In the embodiment of Figure 2, microchip 44 and magnetic strip 52 contain different payment account numbers, expiration dates, and other token account details for two different alternate accounts. In short, the microchip 44 and the magnetic strip 52 appear to represent completely different payment accounts. A transaction performed at a merchant that supports EMV using the microchip 44 will contain different account details than a transaction performed at a merchant using the magnetic strip 52 on the same device 36 . Additionally, NFC transactions can use different payment account details than EMV enabled mode and magnetic stripe mode.

在一个实施例中,发行机构28向顾客提供在电子商务和电话商务交易中使用的替代账户明细,使得该明细与微芯片44或磁条52的替代账户明细不同。可以理解的是,也可使用传真、电子邮件和其他形式的电子和电话通信。还可以理解的是,替代账户明细可记录在通过邮寄进行的交易的邮购表单上。取决于不同实施例,电子商务替代账户明细可不印刷或压印在支付装置36上而是单独提供给用户,或者也可印刷或压印在支付装置上。In one embodiment, issuer 28 provides customers with alternative account details for use in electronic commerce and telecommerce transactions, such that the details are different from the alternative account details of microchip 44 or magnetic strip 52 . It will be appreciated that facsimile, electronic mail and other forms of electronic and telephone communication may also be used. It will also be appreciated that alternate account details may be recorded on the mail order form for transactions made by mail. Depending on the embodiment, the e-commerce alternative account details may not be printed or embossed on the payment device 36 but provided to the user separately, or may also be printed or embossed on the payment device.

图3A和3B示出了根据本发明各实施例的第二种支付装置60。图3A示出了支付装置60的正面62,而图3B示出了支付装置60的背面64。支付装置60可在其正面62上包括发行机构的名称66和微芯片68。应该注意的是,支付装置60没有通常可能出现在传统支付装置上的装置号码和用户姓名。支付装置60的背面64可以是空白的,或者可简单地包括发行机构的名称和地址。因此背面64没有传统的磁条和CVV编号。支付装置60没有预先印刷的账号、压印的账户数据、到期数据、用户姓名或其他账户数据。通过使装置匿名并且不包括人类可读的账号,可以防止账户数据从装置的正面和背面轻易被窃取。3A and 3B illustrate a second payment device 60 according to various embodiments of the present invention. FIG. 3A shows the front 62 of the payment device 60 and FIG. 3B shows the back 64 of the payment device 60 . The payment device 60 may include the name 66 of the issuer and a microchip 68 on the front face 62 thereof. It should be noted that payment device 60 does not have the device number and user name that would normally appear on conventional payment devices. The back 64 of the payment device 60 may be blank, or may simply include the name and address of the issuer. Thus the backside 64 does not have the traditional magnetic stripe and CVV numbering. Payment device 60 does not have pre-printed account numbers, embossed account data, expiration data, user names, or other account data. By making the device anonymous and not including a human-readable account number, account data can be prevented from being easily stolen from the front and back of the device.

目前,VisaTM和MasterCardTM包含了根据其特许经营协议发行的卡和其他装置的规定,要求在装置上显示用户的姓名和账号。因此,图3的实施例不遵循这些当前规则。尽管如此,本发明所述的支付装置60可以在没有丢失或被盗风险的情况下公开携带,因为用户姓名和账号不能视觉检索。对于在线、邮购、电话和类似的交易,可以在用户家中安全地储藏一个单独的装置或电子文件。Currently, Visa and MasterCard include provisions for cards and other devices issued under their franchise agreements that require the user's name and account number to be displayed on the device. Therefore, the embodiment of Figure 3 does not follow these current rules. Nonetheless, the payment device 60 of the present invention can be carried openly without risk of loss or theft, since user names and account numbers are not visually retrievable. For online, mail order, telephone and similar transactions, a separate device or electronic file can be securely stored in the user's home.

在一些实施例中,支付装置36、60可由塑料基板(“卡”)形成。第一组件(例如,微芯片44)可并入图2和3所示的卡上的塑料基板中。第一组件可配置为提供与用户的有效证书关联的第一替代账户的明细。图2的支付卡36还可包括并入塑料基板中的附加组件。附加组件配置为提供与用户的有效证书关联的其他替代帐户的明细。第一个替代账户包括不同于第二个替代账户明细并且也不同于所有其他替代账户的明细。将第一、第二或其他替代账户中的至少一个提供给商家(例如使用商家终端16)以与商家进行金融交易。In some embodiments, the payment devices 36, 60 may be formed from a plastic substrate ("card"). The first component (eg, microchip 44 ) may be incorporated into the plastic substrate on the card shown in FIGS. 2 and 3 . The first component may be configured to provide details of the first alternate account associated with the user's valid credentials. The payment card 36 of FIG. 2 may also include additional components incorporated into the plastic substrate. The add-on is configured to provide details of other alternate accounts associated with the user's valid credentials. The first surrogate account includes details that are different from the details of the second surrogate account and are also different from all other surrogate accounts. At least one of the first, second or other alternate accounts is provided to the merchant (eg, using the merchant terminal 16) to conduct financial transactions with the merchant.

商家配置为经由网络12将至少一个替代账户明细传送到账户关联装置24。账户关联装置24配置为将至少一个替代账户与用户的有效证书之一相关联,并且其中账户关联装置24进一步配置为管理与用户的主要金融账户关联的发行机构28和与商家相关联的商家终端16之间的金融交易。The merchant is configured to communicate at least one alternate account detail to the account association device 24 via the network 12 . The account linking means 24 is configured to associate at least one alternate account with one of the user's valid credentials, and wherein the account linking means 24 is further configured to manage the issuer 28 associated with the user's primary financial account and the merchant terminal associated with the merchant Financial transactions between 16.

根据一些实施例,图2的支付装置36可进一步包括并入塑料基板中的其他部件(例如,装置编号46)。该装置编号可以印刷和/或压印在塑料基板上。在替代实施例中,支付装置(例如,支付卡60)可缺少印刷或压印帐号、磁条和/或其他模式中的至少一个。According to some embodiments, the payment device 36 of FIG. 2 may further include other components (eg, device number 46 ) incorporated into the plastic substrate. The device number can be printed and/or embossed on the plastic substrate. In alternate embodiments, the payment device (eg, payment card 60) may lack at least one of a printed or embossed account number, a magnetic stripe, and/or other patterns.

第一、第二和其他替代账户的明细可由诸如商家终端16的销售点(POS)装置从第一、第二和额外组件中读取。为了进行金融交易,一些实施方式可包括使用与用户关联的移动装置20。Details of the first, second and other alternate accounts may be read from the first, second and additional components by a point of sale (POS) device such as the merchant terminal 16 . To conduct financial transactions, some embodiments may include the use of a mobile device 20 associated with the user.

图4是示出了图1所示的账户关联装置24的一个实施例的框图。在图4的实施例中,账户关联装置24包括安全模块74、一个或多个网页76、用户账户模块78、一个或多个网络接口80以及交易认证模块82。一个或多个网络接口80配置为启用第一公共网络12上的通信并且还启用网络26上的通信。用户账户模块78允许用户或顾客执行与金融账户以及支付装置36、60如何被使用有关的多个不同动作。下面参考图5更详细地描述用户账户模块78。FIG. 4 is a block diagram illustrating one embodiment of the account linking device 24 shown in FIG. 1 . In the embodiment of FIG. 4 , the account association device 24 includes a security module 74 , one or more web pages 76 , a user account module 78 , one or more web interfaces 80 , and a transaction authentication module 82 . The one or more network interfaces 80 are configured to enable communication over the first public network 12 and also enable communication over the network 26 . The user account module 78 allows a user or customer to perform a number of different actions related to the financial account and how the payment devices 36, 60 are used. The user account module 78 is described in more detail below with reference to FIG. 5 .

安全模块74可包括用于生成临时动态卡验证值(d-CVV)的随机号码生成器。d-CVV可被传送给移动装置。而安全模块74可包括用于加密通过公共网络12传输的数据的加密引擎。账户关联装置24可配置为一个网络服务器,其允许一个或多个用户访问来自网页76的信息并建立安全连接以实现敏感数据(例如用户信息,装置编号等)的传输。交易认证模块82配置为使用支付装置36、60来认证金融交易。The security module 74 may include a random number generator for generating a temporary dynamic card verification value (d-CVV). The d-CVV can be transmitted to the mobile device. In turn, the security module 74 may include an encryption engine for encrypting data transmitted over the public network 12 . Account linking device 24 may be configured as a web server that allows one or more users to access information from web page 76 and establish a secure connection for the transfer of sensitive data (eg, user information, device numbers, etc.). The transaction authentication module 82 is configured to authenticate financial transactions using the payment devices 36 , 60 .

在一个实施例中,通过使用可由安全模块74提供的加密密钥进行加密来保护令牌账户明细。在一个实施例中,加密密钥源于用户创建的密码。相反,在另一个实施例中,加密密钥可依赖于其他数据,包括但不限于移动装置20的身份、账户关联装置24的安全模块74所已知的用户身份号码、用户注册计算服务的国家、由用户的生物认证控制的主密钥,诸如指纹、虹膜扫描、面部或语音识别或者匹配一个或多个身体节律的生物节律模式,所述身体节律包括但不限于脉搏率、表皮电导率、虹膜大小、眨眼率、脑电图、心电图或作为个体生物标记独立或联合考虑的其他因素。In one embodiment, the token account details are protected by encryption using an encryption key that may be provided by the security module 74 . In one embodiment, the encryption key is derived from a user-created password. Conversely, in another embodiment, the encryption key may rely on other data including, but not limited to, the identity of the mobile device 20, the user identification number known to the security module 74 of the account association device 24, the country in which the user registered for the computing service , a master key controlled by the user's biometric authentication, such as a fingerprint, iris scan, facial or voice recognition, or a biorhythm pattern that matches one or more body rhythms including, but not limited to, pulse rate, epidermal conductivity, Iris size, blink rate, EEG, ECG, or other factors considered independently or in combination as individual biomarkers.

普通塑料卡片可在卡片的背面或正面印有单独的三位或四位的CVV。电子商务网站现在经常要求该数值以确保用户拥有该卡。但由于CVV是印在卡上的短号码,所以很容易与帐号数据一起被盗。因此,使用在交易时可由安全模块74生成并且仅适用于一次交易的动态CVV(d-CVV)可防止这种盗窃形式。在一些实施例中,所生成的d-CVV不是仅仅用于一次交易,而是可应用于与特定商家关联的多次交易,或者可以根据其他标准使用多次,例如某个日期范围、一周中的某几天、商家区号、购买类别等。根据一些实施例,在与用户关联的移动装置20上运行的移动应用可配置为按需检索d-CVV。在另一个实施例中,在与用户关联的移动装置20上运行的移动应用可配置为按需生成d-CVV。作为选择的,当移动装置20不可用时,可使用由账户关联装置24提供的网站。因此,在这种情况下,账户关联装置24可生成该d-CVV。Ordinary plastic cards can have a separate three- or four-digit CVV printed on the back or front of the card. E-commerce sites now often require this value to ensure that the user owns the card. But since the CVV is a short number printed on the card, it can easily be stolen along with account data. Thus, this form of theft can be prevented using a dynamic CVV (d-CVV) that can be generated by the security module 74 at the time of the transaction and that is only applicable to one transaction. In some embodiments, the generated d-CVV is not used for only one transaction, but may be applied to multiple transactions associated with a particular merchant, or may be used multiple times based on other criteria, such as a certain date range, week days, business area codes, purchase categories, etc. According to some embodiments, the mobile application running on the mobile device 20 associated with the user may be configured to retrieve the d-CVV on demand. In another embodiment, a mobile application running on the mobile device 20 associated with the user may be configured to generate the d-CVV on demand. Alternatively, a website provided by account linking device 24 may be used when mobile device 20 is unavailable. Therefore, in this case, the account linking device 24 may generate the d-CVV.

除了在金融交易期间使用之外,支付系统10还可替代地应用于非支付用途。例如,支付系统10可用于使用令牌或替代标识符替换某些形式的标识符。这些标识符可包括社会安全号(在美国)、公共健康识别号码、会员计划、其他形式的帐号,其中使用真实号码可存在泄露、身份盗用或其他欺诈的风险。In addition to being used during financial transactions, the payment system 10 may alternatively be used for non-payment purposes. For example, payment system 10 may be used to replace certain forms of identifiers with tokens or alternative identifiers. These identifiers may include social security numbers (in the United States), public health identification numbers, membership programs, other forms of account numbers, where using real numbers may present a risk of compromise, identity theft, or other fraud.

账户关联装置24还可找到应用以提供对受保护记录组的有限交易访问,诸如医疗记录请求、实验室结果、信用查询、专业许可、商业许可以及利用政府或企业发布的识别帐号的其他形式的信赖方查询。Account linking device 24 may also find applications to provide limited transactional access to protected sets of records, such as medical record requests, laboratory results, credit inquiries, professional licenses, commercial licenses, and other forms of identification using government or corporate issued accounts. Relying Party Inquiries.

支付系统10还可用于一些非支付用途的交易,包括驾驶执照、边境控制文件、建筑和资源访问卡以及礼品卡。在该实施例中,支付装置36、60可使用非支付用途的一个或多个模式,同时仍可使用支付交易的一个或多个模式,该支付交易对于不同模式使用单独替代账户明细。Payment system 10 may also be used for some non-payment-purpose transactions, including driver's licenses, border control documents, building and resource access cards, and gift cards. In this embodiment, the payment device 36, 60 may use one or more modes of non-payment usage, while still using one or more modes of payment transactions that use separate alternate account details for the different modes.

在一些实施例中,账户关联装置24可包括至少一个网络接口80,该网络接口80配置为经由第一公共网络12与多个商家终端16通信并且经由网络26与发行机构28通信。例如,发行机构28可以是向用户发行支付装置36、60的银行。账户关联装置24还可包括交易认证模块82,该交易认证模块82被配置为基于由与用户拥有的支付装置36、60关联的第一替代账户的第一商家终端获得的第一组明细、为多个商家终端16中的第一商家终端认证第一金融交易。交易认证模块82可进一步配置为基于由与用户拥有的支付装置36、60关联的第二替代账户的第二商家终端获得的第二组不同的明细、为多个商家终端16中的第二商家终端认证第二金融交易。In some embodiments, the account association device 24 may include at least one network interface 80 configured to communicate with the plurality of merchant terminals 16 via the first public network 12 and with the issuer 28 via the network 26 . For example, the issuer 28 may be a bank that issues the payment devices 36, 60 to users. The account association device 24 may also include a transaction authentication module 82 configured to, based on the first set of details obtained by the first merchant terminal of the first alternate account associated with the user-owned payment device 36, 60, for A first merchant terminal of the plurality of merchant terminals 16 authenticates the first financial transaction. The transaction authentication module 82 may be further configured to be a second merchant of the plurality of merchant terminals 16 based on a second different set of details obtained by a second merchant terminal of a second alternate account associated with the user-owned payment device 36 , 60 The terminal authenticates the second financial transaction.

交易认证模块82可进一步配置为确定该替代账户是否对应于有效用户证书。交易认证模块82可进一步配置为确定接收到的替代账户明细是否对应于预期的支付装置使用的模式的替代账户明细。交易认证模块82进一步配置为管理发行机构28与第一和第二商家终端16之间的金融交易。交易认证模块82进一步配置为基于与用户拥有的支付装置36、60的主账户关联的其他替代账户的其他商家终端获取其他组明细、为多个商家终端16中的其他商家终端认证其他金融交易。第一组明细可获取自支付装置36、60上的微芯片44,第二组明细可获取自支付装置36上的磁条52,而第三组明细可获取自支付装置36上印刷和/或压印的账户编号46。Transaction authentication module 82 may be further configured to determine whether the alternate account corresponds to a valid user credential. The transaction authentication module 82 may be further configured to determine whether the received alternate account details correspond to alternate account details for the intended mode of use of the payment device. The transaction authentication module 82 is further configured to manage financial transactions between the issuer 28 and the first and second merchant terminals 16 . The transaction authentication module 82 is further configured to obtain other group details based on other merchant terminals of other alternate accounts associated with the primary account of the payment device 36 , 60 owned by the user, to authenticate other financial transactions for other merchant terminals of the plurality of merchant terminals 16 . The first set of details may be obtained from the microchip 44 on the payment device 36, 60, the second set of details may be obtained from the magnetic strip 52 on the payment device 36, and the third set of details may be obtained from printing and/or printing on the payment device 36 Imprinted account number 46.

网络接口80可进一步配置为经由网络12与用户关联的远程装置(例如,用户装置14或移动装置20)通信。网络接口80可进一步配置为从远程装置14、20接收指令以使得用户能够管理与支付装置36、60关联的主账户,其中管理主账户包括以下中的至少一个:输入注册信息86、监视主账户的活动94、启用和禁用一种或多种通过支付装置进行的交易模式90、报告支付装置已经丢失或被盗92、以及提供与第一和第二替代账户有关的信息88。Network interface 80 may be further configured to communicate with a remote device (eg, user device 14 or mobile device 20 ) associated with the user via network 12 . The network interface 80 may be further configured to receive instructions from the remote devices 14, 20 to enable the user to manage a master account associated with the payment device 36, 60, wherein managing the master account includes at least one of: entering registration information 86, monitoring the master account activities 94, enable and disable one or more modes of transactions through the payment device 90, report that the payment device has been lost or stolen 92, and provide information 88 related to the first and second alternate accounts.

图5是示出了图4所示的用户账户模块78的一个实施例的框图。在该实施例中,用户账户模块78包括注册模块86、供应模块88、启用模块90、报告模块92和监控模块94。用户可使用在用户的移动装置20上运行的移动应用、或者通过使用用户的用户装置14访问由账户关联装置24提供的网站来访问用户账户模块78。FIG. 5 is a block diagram illustrating one embodiment of the user account module 78 shown in FIG. 4 . In this embodiment, the user account module 78 includes a registration module 86 , a provisioning module 88 , an enabling module 90 , a reporting module 92 and a monitoring module 94 . The user may access the user account module 78 using a mobile application running on the user's mobile device 20 or by accessing a website provided by the account association device 24 using the user's user device 14 .

用户账户模块78使得用户能够创建和管理规则,账户关联装置24代表用户执行该规则。这样的规则可对用户已知的一个或多个事实敏感,包括但不限于支付值、商家ID、交易消息中编码的本地时间和日期、交易时商家的注册位置与用户移动装置的地理位置之间的距离、交易的本地货币、交易发起的国家、商家成立的国家、交易是否呈现为磁条交易、EMV交易、或是电子商务、电话、或邮购交易、以及用户验证方法,例如下述方法的一个或多个但不限于,将个人识别码(PIN)码输入到商家POS终端、签署收据、将密码输入移动装置、以及指纹或其他生物识别方法。The user account module 78 enables the user to create and manage rules that the account association device 24 executes on behalf of the user. Such rules may be sensitive to one or more facts known to the user, including, but not limited to, the payment value, the merchant ID, the local time and date encoded in the transaction message, the relationship between the merchant's registered location at the time of the transaction and the geographic location of the user's mobile device. distance, the local currency of the transaction, the country in which the transaction was initiated, the country in which the merchant was established, whether the transaction appears as a magnetic stripe transaction, EMV transaction, or an e-commerce, telephone, or mail order transaction, and user authentication methods such as the following One or more of, but not limited to, entering a personal identification number (PIN) code into a merchant POS terminal, signing a receipt, entering a password into a mobile device, and fingerprint or other biometric method.

注册模块86可配置为使得用户(其中,尤其可以是持卡人、有效证书持有者或发行机构适当批准的个人)可注册其他替代账户和其他有效证书。启用模块90可用于允许用户根据用户可能基于各种标准参与的各种用途、启用或禁用交易的某些模式或类型,或者允许用户在认证之前自行启用或禁用特定交易。启用模块90可用于允许用户在多种场景或标准中挑选针对哪个有效证书付款。若支付装置36、60丢失或被盗的话,报告模块92允许用户报告。报告模块92的一个实施例可使得账户关联装置24能够向用户或发行机构28手动或自动报告相关信息,包括报告所有替代账户明细和/或支付装置上的潜在欺诈活动。监视模块94允许用户查看先前的交易来监控该装置的所有活动。The registration module 86 may be configured to enable the user (which may be, among other things, a cardholder, a valid credential holder, or an individual appropriately approved by the issuer) to register for other alternate accounts and other valid credentials. The enablement module 90 may be used to allow the user to enable or disable certain modes or types of transactions based on various uses that the user may engage in based on various criteria, or to allow the user to enable or disable certain transactions on their own prior to authentication. The enablement module 90 may be used to allow the user to choose among a variety of scenarios or criteria for which valid certificate to pay. The reporting module 92 allows the user to report if the payment device 36, 60 is lost or stolen. One embodiment of the reporting module 92 may enable the account association device 24 to manually or automatically report relevant information to the user or issuer 28, including reporting all alternative account details and/or potential fraudulent activity on the payment device. The monitoring module 94 allows the user to view previous transactions to monitor all activities of the device.

供应模块88可允许用户分别区分多个不同组的替代账户明细。The provisioning module 88 may allow the user to distinguish between multiple different sets of alternate account details, respectively.

传统的装置发行系统可假设某些数据元素在微芯片、磁条和印刷/压印的帐号之间共享。然而,与常规装置发行系统相反,供应模块88允许使用分离的数据元素来提供这些模式以及另外的元素和/或模式中的每一个。供应模块88配置为分别识别这些多个不同组的替代账户数据,其可存储在卡或装置供应步骤期间传送的公共供应数据文件中。Traditional device issuance systems may assume that certain data elements are shared between microchips, magnetic strips, and printed/embossed account numbers. However, in contrast to conventional device distribution systems, provisioning module 88 allows for each of these schemas and additional elements and/or schemas to be provided using separate data elements. Provisioning module 88 is configured to identify these multiple distinct sets of alternate account data, respectively, which may be stored in a common provisioning data file communicated during the card or device provisioning step.

如果支付装置36、60丢失或被盗,用户可能会遭受未经授权的支付装置的使用。然而,虽然在一些国家窃贼可能能够在某个花费阈值(例如100美元)限度内使用NFC功能进行购买,但是窃贼通常无法在没有用户的PIN码的情况下使用该装置的EMV功能,该PIN码可以在使用供应模块88的供应过程期间输入。而且,由于该单独的交易模式的不同账户明细,被盗装置不能用于电子或电话交易。If the payment device 36, 60 is lost or stolen, the user may be exposed to unauthorized use of the payment device. However, while in some countries thieves may be able to make purchases using NFC capabilities within a certain spending threshold (eg, $100), thieves typically cannot use the device's EMV capabilities without the user's PIN code, which This may be entered during the provisioning process using provisioning module 88 . Furthermore, the stolen device cannot be used for electronic or telephone transactions due to the different account details of this separate transaction model.

供应模块88可进一步包括接收未印刷在支付装置36、60上的用户标识信息。根据一些实施例,供应模块88可通过在交易时要求出示用户移动装置20、而使用支付装置36、60设置用户的使用规则。另外,移动装置20的移动应用也可用于立即阻止由报告模块92报告被盗的被盗装置的交易。除非用户每次使用移动装置20上的移动应用解锁,否则用户账户模块78可配置其规则以阻止该磁条交易。后一种方法将有效地防止使用假冒磁条装置。用户账户模块78还可配置其规则以阻止来自任何和所有不同模式的交易,或者阻止符合某些标准的交易,除非用户每次都解锁这些交易。The provisioning module 88 may further include receiving user identification information that is not printed on the payment device 36 , 60 . According to some embodiments, the provisioning module 88 may use the payment device 36, 60 to set the user's usage rules by requiring presentation of the user's mobile device 20 at the time of transaction. Additionally, the mobile application of the mobile device 20 may also be used to immediately block transactions of stolen devices reported by the reporting module 92 as stolen. The user account module 78 may configure its rules to block this magnetic stripe transaction unless the user unlocks using the mobile application on the mobile device 20 each time. The latter method will effectively prevent the use of counterfeit magnetic strip devices. The user account module 78 may also configure its rules to block transactions from any and all different modes, or to block transactions that meet certain criteria unless the user unlocks these transactions each time.

在一个实施例中,一移动应用在用户的主移动装置20上可用。用户可使用该移动应用将一个替代账户或有效证书注册到账户关联装置24中,控制有效证书的供应或者与供应给支付装置的一个或多个替代账户明细的关联。该移动应用还允许用户对于通过在塑料支付装置上的任何替代账户展示的交易启用或禁用授权,报告支付装置丢失或被盗,以及报告敏感或高价值或高风险交易的其他认证因素。In one embodiment, a mobile application is available on the user's primary mobile device 20 . The user can use the mobile application to register an alternate account or valid credential into the account association device 24, control the provisioning of valid credentials or association with one or more alternate account details provided to the payment device. The mobile application also allows users to enable or disable authorization for transactions presented through any alternate account on the plastic payment device, report a lost or stolen payment device, and report other authentication factors for sensitive or high value or high risk transactions.

移动装置20还可在存储器中存储替代账户明细,替代账户细节可与“有卡”交易和“无卡”交易相关联。这些替代账户明细可存储在存储器中,并且可以通过向移动装置20输入密码和/或另一认证因素由用户重新调用。作为用于与电子商务网站交互的手段,移动应用安全地保存电子商务替代账户明细,并且在用密码、生物识别和/或其他因素进行适当的认证时将它们显示给用户。在另一个实施例中,替代账户明细由账户关联装置24传送并由移动装置20接收,然后可由用户通过向移动装置20输入密码和/或另一认证因素而被重新调用。The mobile device 20 may also store alternative account details in memory, which may be associated with "card-present" transactions and "no-card" transactions. These alternate account details may be stored in memory and recalled by the user by entering a password and/or another authentication factor into the mobile device 20 . As a means for interacting with e-commerce websites, mobile applications securely store e-commerce alternative account details and display them to the user upon appropriate authentication with passwords, biometrics, and/or other factors. In another embodiment, alternate account details are transmitted by account association device 24 and received by mobile device 20, which can then be recalled by the user by entering a password and/or another authentication factor into mobile device 20.

图6示出了配置为代表多个有效证书102a,102b,...,102n的代理装置100的示例。每个有效证书102a,102b,...,102n的明细被组合到单个代理装置100中,然后可以使用该单个代理装置100来代替任何有效证书102a,102b,...,102n。有效证书102可以是信用卡、借记卡、积分卡、会员卡、身份证、健康保险卡、礼品卡以及包括账户信息、身份信息和其他类型数据的其他卡。在使用期间,领取单个代理装置100的用户可以选择任何一套有效证书来正常使用,就好像出示了实际有效证书102一样。在一些实施例中,代理装置100可包括一个或多个微芯片、一个或多个非接触式电路(例如NFC电路)、磁条、印刷和/或压印的替代账号、和/或CVV码。代理装置100还可包括标识用户的印刷信息,诸如用户的姓名和联系信息。Figure 6 shows an example of a proxy device 100 configured to represent a plurality of valid credentials 102a, 102b, . . . , 102n. The details of each valid certificate 102a, 102b, . . . , 102n are combined into a single proxy device 100, which can then be used in place of any valid certificate 102a, 102b, . . . , 102n. Valid credentials 102 may be credit cards, debit cards, loyalty cards, loyalty cards, ID cards, health insurance cards, gift cards, and other cards that include account information, identity information, and other types of data. During use, a user claiming a single proxy device 100 may select any set of valid credentials for normal use, as if the actual valid credentials 102 were presented. In some embodiments, proxy device 100 may include one or more microchips, one or more contactless circuits (eg, NFC circuits), magnetic stripes, printed and/or embossed alternate account numbers, and/or CVV codes . The agent device 100 may also include printed information identifying the user, such as the user's name and contact information.

图7示出了移动代理装置104的一个示例,其可配置为代表如上所述的任何数量的有效证书102a,102b,...,102n。不以信用卡的形式配置,移动代理装置104可代之以构建为移动电话、智能电话、平板电脑、可穿戴移动装置或另一合适的基于处理器的移动装置。在一些实施例中,移动代理装置104可包括下载到现有移动电话、智能电话、平板电脑、可穿戴移动装置等之中的软件和/或固件。在使用期间,移动代理装置104可在支持NFC的读取器上轻敲或者按照本公开中描述的其他方法以其他方式使用。Figure 7 shows one example of a mobile agent device 104 that may be configured to represent any number of valid credentials 102a, 102b, . . . , 102n as described above. Instead of being configured in the form of a credit card, the mobile agent device 104 may instead be constructed as a mobile phone, smartphone, tablet, wearable mobile device, or another suitable processor-based mobile device. In some embodiments, the mobile agent device 104 may include software and/or firmware downloaded into existing mobile phones, smartphones, tablets, wearable mobile devices, and the like. During use, the mobile agent device 104 may be tapped on an NFC-enabled reader or otherwise used in accordance with other methods described in this disclosure.

图8是示出了启用超过预定阈值的交易的方法110的一个实施例的流程图。例如,该阈值可由用户或由发行机构基于偏好或者基于用户的金融稳定性的预定规则来建立。在一个示例中,该阈值可设置为100美元。因此,任何超过100美元的未决金融交易将执行图8的方法。FIG. 8 is a flow diagram illustrating one embodiment of a method 110 of enabling transactions that exceed a predetermined threshold. For example, the threshold may be established by the user or by the issuer based on preferences or predetermined rules based on the financial stability of the user. In one example, the threshold may be set to $100. Therefore, any pending financial transaction over $100 will execute the method of Figure 8.

在操作中,在代理装置(例如代理卡100或移动代理装置104)和与商家相关联的读取器112之间执行读取步骤(1)。读取器112可以是图1所示的商家终端16的一个实施例。读取步骤(1)涉及将代理装置100、104交给收银员或者客户自己使用代理装置100、104。代理装置100、104被刷过读取器112的磁条传感器、被在读取器112的NFC传感器上轻敲、被插入到读取器112的芯片槽中、或者以其他方式操作以使得读取器112能够读取存储在代理装置100、104中的金融信息。In operation, the reading step (1) is performed between a proxy device (eg, proxy card 100 or mobile proxy device 104) and a reader 112 associated with the merchant. Reader 112 may be one embodiment of merchant terminal 16 shown in FIG. 1 . The reading step (1) involves handing over the proxy device 100, 104 to the cashier or the customer using the proxy device 100, 104 himself. The proxy device 100, 104 is swiped across the magnetic stripe sensor of the reader 112, tapped on the NFC sensor of the reader 112, inserted into the chip slot of the reader 112, or otherwise manipulated to cause a read The reader 112 is capable of reading financial information stored in the agent devices 100 , 104 .

在步骤(2)中,与代理装置100,104关联的银行识别号码(BIN)被发送到支付处理器114,支付处理器114可以是第三方代表,用于处理与商家关联的收单银行的各种信用和借记交易。例如,支付处理器114可以是用于处理单个卡或代理装置的合适的处理器。在步骤(3)中,执行授权,其包括付款处理器114标记用户付款以由授权模块116(诸如padlocTM或另一授权模块)进行授权。交易明细被发送到授权模块116,授权模块116可包括已经下载至用户的移动装置20中的应用。在一些实施例中,移动装置20可以是与移动代理装置104相同的装置,既用于发起交易(步骤(1))也用于接收授权(步骤(3))。In step (2), the bank identification number (BIN) associated with the agent device 100, 104 is sent to the payment processor 114, which may be a third party representative for processing various Credit and debit transactions. For example, payment processor 114 may be a suitable processor for processing a single card or proxy device. In step (3), authorization is performed, which includes the payment processor 114 marking the user payment for authorization by an authorization module 116, such as a padloc or another authorization module. The transaction details are sent to the authorization module 116 , which may include an application that has been downloaded to the user's mobile device 20 . In some embodiments, mobile device 20 may be the same device as mobile agent device 104 for both initiating transactions (step (1)) and receiving authorizations (step (3)).

方法110的步骤(4)包括与用户通信以接收对由单个代理装置100、104代表的多个有效证书102之一的选择。授权模块116接收用户的选择以及完成交易所需的任何PIN码或其他安全码。在步骤(5)中,授权模块116包括从证书选择数据库118中安全地检索所选证书的明细。Step (4) of method 110 includes communicating with the user to receive a selection of one of a plurality of valid credentials 102 represented by a single proxy device 100 , 104 . The authorization module 116 receives the user's selection and any PIN or other security code required to complete the transaction. In step (5), the authorization module 116 includes securely retrieving the details of the selected certificate from the certificate selection database 118.

在步骤(6)中,授权模块116将具有BIN码的支付信息发送给选定卡的发行机构。支付处理器114接收支付信息和BIN码信息并将该信息发送给适当的发行机构以处理支付(步骤(7))。In step (6), the authorization module 116 sends the payment information with the BIN code to the issuer of the selected card. The payment processor 114 receives the payment information and BIN code information and sends the information to the appropriate issuer to process the payment (step (7)).

图9是示出了启用低于图8所述的预定阈值的交易的方法120的另一实施例的流程图。根据其中阈值设置为100美元的上述示例,任何低于100美元的未决金融交易将执行图9的方法。在该实施例中,当交易低于该阈值时,用户可预先选择要使用的有效证书。以这种方式,可以简化较小的交易,而不需要图8所述的一些额外步骤。FIG. 9 is a flowchart illustrating another embodiment of a method 120 of enabling transactions below the predetermined threshold described in FIG. 8 . According to the above example where the threshold is set to $100, any pending financial transaction below $100 will execute the method of FIG. 9 . In this embodiment, the user may preselect a valid certificate to use when the transaction falls below the threshold. In this way, smaller transactions can be simplified without some of the extra steps described in Figure 8.

图9中所示的装置可与图8中的装置相同。而且,图9的步骤(1)和(2)与图8相同,这里不再重复。然而,步骤(3)涉及发送所识别的用户支付偏好,并且从证书选择数据库118中检索已选择的有效证书。步骤(4)包括为预先选择的有效证书的发行机构发送带有BIN码的支付信息,发送给支付处理器114。步骤(5)包括照常处理该付款。The device shown in FIG. 9 may be the same as the device in FIG. 8 . Moreover, steps (1) and (2) of FIG. 9 are the same as those of FIG. 8 and will not be repeated here. However, step (3) involves sending the identified user payment preferences and retrieving the selected valid certificate from the certificate selection database 118 . Step (4) includes sending payment information with a BIN code to the payment processor 114 for the pre-selected issuer of the valid certificate. Step (5) includes processing the payment as usual.

图10示出了根据本发明的操作的方法130的一个实施例。用户使用代理卡100(或移动代理装置104)在销售点(POS)装置132处进行交易。POS装置132发送符合至少一个金融交易标准的加密金融消息,所述金融交易标准包括例如ISO 8583、ISO 20022和AS 2805。商家收单机构134接收该加密消息,该商家收单机构134可配置为解密消息并为支付交换机136重新加密该消息,支付交换机136可配置为处理该加密的和/或令牌化的金融交易消息。加密的金融交易消息可存储在加密数据库138中。Figure 10 illustrates one embodiment of a method 130 of operation in accordance with the present invention. A user conducts a transaction at a point-of-sale (POS) device 132 using the proxy card 100 (or mobile proxy device 104). The POS device 132 sends encrypted financial messages that conform to at least one financial transaction standard including, for example, ISO 8583, ISO 20022, and AS 2805. The encrypted message is received by a merchant acquirer 134, which may be configured to decrypt the message and re-encrypt the message for a payment switch 136, which may be configured to process the encrypted and/or tokenized financial transaction information. Encrypted financial transaction messages may be stored in encrypted database 138 .

支付交换机136配置为将来自商家收单机构134的原始加密消息转发到交易服务器142的交易库以进行令牌化。交易服务器142的交易库对原始消息进行解密并将该令牌化的消息发送回支付交换机136。交易规则引擎140可配置为将代理令牌交换为目标证书令牌。而且,交易规则引擎140可配置为根据需要编辑规则。Payment switch 136 is configured to forward the raw encrypted message from merchant acquirer 134 to the transaction repository of transaction server 142 for tokenization. The transaction repository of transaction server 142 decrypts the original message and sends the tokenized message back to payment switch 136 . The transaction rules engine 140 may be configured to exchange the proxy token for the target credential token. Also, the transaction rules engine 140 may be configured to edit the rules as needed.

支付交换机136然后将所选择的有效证书和所请求的交易编辑的令牌提供给交易服务器142的交易监护人146。交易监护人146和交易拒绝规则被用来验证规则以对提交的交易采取允许、拒绝或其他动作。如果该交易被允许,则交易监护人146根据编辑规则将原始消息传递到目标令牌。交易服务器142的交易库将加密和编辑过的交易消息返回给支付交换机136。然后,支付交换机136加密该消息并将加密的消息发送给商家收单机构134。The payment switch 136 then provides the selected valid credentials and the requested transaction edited token to the transaction guardian 146 of the transaction server 142 . Transaction Guardian 146 and Transaction Deny Rules are used to validate the rules to allow, deny or other actions on submitted transactions. If the transaction is allowed, the transaction guardian 146 passes the original message to the target token according to the editing rules. The transaction repository of the transaction server 142 returns the encrypted and edited transaction message to the payment switch 136 . Payment switch 136 then encrypts the message and sends the encrypted message to merchant acquirer 134 .

图11是用于安全地存储有效证书并使其能够经由代理装置访问的方法160的一个实施例的流程图。方法160包括使用代理装置(代理卡100或移动代理装置104)将有效证书明细加载到账户关联装置24的数据存储162中。有效证书明细可使用磁刷读取方式获得或任何其他方式从支付装置的其他模式获得替代账户明细。将与已使用的模式相关联的替代账户明细发送至证书管理装置164。证书管理装置164配置为将加密的刷卡数据发送给发行机构172的证书转移装置174的证书装置180。Figure 11 is a flow diagram of one embodiment of a method 160 for securely storing and making a valid credential accessible via a proxy device. The method 160 includes using the proxy device (the proxy card 100 or the mobile proxy device 104 ) to load the valid credential details into the data store 162 of the account association device 24 . Valid certificate details may be obtained using a magnetic brush reading method or any other means to obtain alternative account details from other modes of the payment device. The alternate account details associated with the used schema are sent to the credential management device 164 . The certificate management device 164 is configured to send the encrypted swipe data to the certificate device 180 of the certificate transfer device 174 of the issuer 172 .

支付交换机166与证书转移装置174的令牌化装置176交换入站数据168,并与证书转移装置174的解密装置178交换出站数据170。证书转移装置174还将加密的证书数据与以加密形式存储数据的数据存储186交换。证书转移装置174还将由解密装置178解密的解密证书与证书数据存储182交换。将来自密钥缓存184的密钥提供给证书转移装置174。密钥可包括窗格(pod)特定证书数据存储密钥、派生的令牌化密钥、和刷卡(swiper)密钥。高速存储器HSM188向密钥缓存184提供刷卡密钥、每窗格CMAC、窗格特定存储密钥、以及派生的令牌化密钥。Payment switch 166 exchanges inbound data 168 with tokenizer 176 of certificate transfer device 174 and outbound data 170 with decryption device 178 of certificate transfer device 174 . The certificate transfer device 174 also exchanges encrypted certificate data with a data store 186 that stores the data in encrypted form. The certificate transfer device 174 also exchanges the decrypted certificate decrypted by the decryption device 178 with the certificate data store 182 . The key from key cache 184 is provided to certificate transfer device 174 . The keys may include pod specific credential data store keys, derived tokenization keys, and swiper keys. The high-speed memory HSM 188 provides the key cache 184 with the swipe key, the per-pane CMAC, the pane-specific storage key, and the derived tokenization key.

图12是金融交易的金融信息发送方法196。收单机构198向上游信道200发送ISO8583消息或其他消息类型。上游信道200向交换机202发送ISO 20022消息(规范的)。交换机202将PAN和过期信息发送到账户关联装置24的令牌化窗格204。令牌化窗格204将PAN和令牌发回给交换机202。交换机202然后将ISO 20022(白名单密钥)发送到账户关联装置24的映射窗格206。映射窗格206比较该映射并将映射动作发送回交换机202,然后交换机202应用该映射动作。交换机202然后将映射的PAN令牌发送到账户关联装置24的解密窗格208。解密窗格208然后将解密的证书数据发回给交换机202。FIG. 12 is a financial information transmission method 196 for a financial transaction. Acquirer 198 sends an ISO8583 message or other message type to upstream channel 200 . The upstream channel 200 sends an ISO 20022 message (canonical) to the switch 202 . The switch 202 sends the PAN and expiration information to the tokenization pane 204 of the account association device 24 . The tokenization pane 204 sends the PAN and token back to the switch 202 . The switch 202 then sends the ISO 20022 (whitelist key) to the mapping pane 206 of the account association device 24 . The mapping pane 206 compares the mapping and sends the mapping action back to the switch 202, which then applies the mapping action. Switch 202 then sends the mapped PAN token to decrypt pane 208 of account association device 24 . The decryption pane 208 then sends the decrypted certificate data back to the switch 202 .

在一些实施例中接下来的几个步骤可以是可选的,并且当与原子ID相关时可以涉及日志发送功能。交换机202将已映射和杀毒的映射的20022消息发送到账户关联装置24的日志窗格210。日志窗格210将确认消息发回至交换机202。交换机202然后将映射的20022消息发送到下游信道212。下游信道212然后将映射的8583消息或其他消息类型发送到发行机构214。The next few steps may be optional in some embodiments and may involve a log sending function when related to atomic IDs. The switch 202 sends the mapped and sanitized mapped 20022 message to the log pane 210 of the account association device 24 . Log pane 210 sends a confirmation message back to switch 202 . The switch 202 then sends the mapped 20022 message to the downstream channel 212. Downstream channel 212 then sends the mapped 8583 message or other message type to issuer 214.

发行机构214将对ISO8583消息或其他消息类型的响应发送回下游信道212。下游信道212发送响应20022消息给交换机202,交换机202然后应用缓存的映射的逆变换。The issuer 214 sends back the downstream channel 212 a response to the ISO8583 message or other message type. Downstream channel 212 sends a response 20022 message to switch 202, which then applies the inverse transform of the cached map.

接下来的几个步骤也可以是可选的,并且在与原子ID相关时可涉及日志发送功能。如上所述,交换机202将已映射和杀毒的映射的20022消息发送到日志窗格210,并且日志窗格210通过确认信号进行响应。在该实施方式中,交换机202然后将20022消息发送到上游信道200,并且上游信道200将8583消息或其他消息类型发送到收单机构198。The next few steps may also be optional and may involve log sending functionality when related to atomic IDs. As described above, switch 202 sends a mapped and sanitized mapped 20022 message to log pane 210, and log pane 210 responds with an acknowledgment signal. In this embodiment, the switch 202 then sends a 20022 message to the upstream channel 200, and the upstream channel 200 sends an 8583 message or other message type to the acquirer 198.

图13是用于用户登记的令牌化过程的操作的方法220。用户222使用刷卡器224、连接到移动装置228的刷卡附件226、和/或移动装置229来获取有效的证书。加密的卡信息被发送到网络服务230,诸如账户关联装置24。网络服务232包括登记应用程序接口(API)234和令牌器236。登记API 234允许用户注册一个或多个证书以将证书与代理装置100、104相关联。令牌器236将令牌分配给证书。所登记的证书和令牌存储在数据库238中,例如图1所示的数据库30中。而且,交换高速缓存240可用于将令牌的映射存储到相应证书。FIG. 13 is a method 220 of operation of a tokenization process for user registration. User 222 uses card swipe 224, card swipe accessory 226 connected to mobile device 228, and/or mobile device 229 to obtain a valid credential. The encrypted card information is sent to a network service 230 , such as the account linking device 24 . Web services 232 include a registration application programming interface (API) 234 and a tokenizer 236 . Enrollment API 234 allows a user to enroll one or more credentials to associate credentials with proxy devices 100 , 104 . Tokenizer 236 assigns tokens to certificates. The registered certificates and tokens are stored in a database 238, such as the database 30 shown in FIG. Also, the exchange cache 240 may be used to store a mapping of tokens to corresponding certificates.

图14示出了用于注册的令牌化过程的操作方法250。用户252可通过金融机构或发行机构254创建账户。在注册过程中,客户数据被安全地从发行机构254发送256到账户关联装置258或其他网络服务器。账户关联装置258可对应于图1所示的账户关联装置24,它包括注册API 260和令牌器262。注册和令牌数据存储在数据库264和交换高速缓存266中。FIG. 14 shows a method of operation 250 for a tokenization process for registration. User 252 may create an account with a financial institution or issuer 254 . During the registration process, customer data is securely sent 256 from the issuer 254 to the account linking device 258 or other web server. Account association device 258 may correspond to account association device 24 shown in FIG. 1 and includes registration API 260 and tokenizer 262 . Registration and token data are stored in database 264 and exchange cache 266 .

图15是交易流程示意图。在该流程的第一实施例中,用户在多个商家的第一商家302处展示支付装置100。第一商家302使用来自用户支付装置100的第一账户明细发起支付交易,并将该金融交易发送给收单机构306。收单机构306将金融交易发送给发行机构处理器310。收单机构306可以可选地使用方案308来将金融交易发送到发行机构处理器310。发行机构处理器310将金融交易发送到账户关联装置312,账户关联装置312将第一替代账户明细映射到第一有效证书并将金融交易发送到第一有效证书316的发行机构。账户关联装置312可以可选地将金融交易发送给方案314,后者接着将金融交易发送给第一有效证书316的发行机构。来自发行机构316的响应沿着反向路径直至商家302。在该流程的第二实施例中,用户在多个商家中的第一商家302处展示支付装置104。第二商家304使用来自用户支付装置104的第二账户明细发起支付交易,并将该金融交易发送给非伙伴收单机构320。非伙伴收单机构320使用方案308将金融交易发送到发行机构处理器310。发行机构处理器310将金融交易发送到账户关联装置312,账户关联装置312将第二账户明细映射到第二有效证书并将金融交易发送到第二有效证书316的发行机构。SecureOne解决方案312可以可选地将金融交易发送到方案314,方案314接着将金融交易发送到第二有效证书316的发行机构。来自发行机构316的响应沿着反向路径直至商家304。Figure 15 is a schematic diagram of a transaction flow. In a first embodiment of the process, the user presents the payment device 100 at a first merchant 302 of the plurality of merchants. The first merchant 302 initiates a payment transaction using the first account details from the user payment device 100 and sends the financial transaction to the acquirer 306 . Acquirer 306 sends the financial transaction to issuer processor 310 . The acquirer 306 may optionally use the scheme 308 to send the financial transaction to the issuer processor 310 . The issuer processor 310 sends the financial transaction to the account association device 312 which maps the first alternate account details to the first valid credential and sends the financial transaction to the issuer of the first valid credential 316 . The account linking device 312 may optionally send the financial transaction to the scheme 314 which in turn sends the financial transaction to the issuer of the first valid certificate 316 . The response from the issuer 316 follows the reverse path to the merchant 302 . In a second embodiment of the process, the user presents the payment device 104 at a first merchant 302 of the plurality of merchants. The second merchant 304 initiates a payment transaction using the second account details from the user payment device 104 and sends the financial transaction to the non-partner acquirer 320 . The non-partner acquirer 320 sends the financial transaction to the issuer processor 310 using the scheme 308 . The issuer processor 310 sends the financial transaction to the account association device 312 which maps the second account details to the second valid credential and sends the financial transaction to the issuer of the second valid credential 316 . The SecureOne solution 312 may optionally send the financial transaction to the solution 314, which in turn sends the financial transaction to the issuer of the second valid certificate 316. The response from the issuer 316 follows the reverse path to the merchant 304 .

如果交易进行于诸如商家A 302所表示的那些合作伙伴收单机构之间,则账户关联装置312作为伙伴收单机构306交换证书。伙伴收单机构306将交易路由到发行机构316并照常结算该交易。账户关联装置312配置为记载所有交易活动。If the transaction is between partner acquirers such as those represented by Merchant A 302, account linking device 312 exchanges credentials as partner acquirer 306. Partner acquirer 306 routes the transaction to issuer 316 and settles the transaction as usual. Account linking device 312 is configured to log all transaction activity.

当交易进行于诸如由商家B 304代表的那些非伙伴收单机构之间时,非伙伴收单机构320将交易路由到诸如收单机构306的伙伴收单机构。账户关联装置312作为伙伴收单机构交换证书并记录交易活动。在这种情况下,可能适用第二级交换费。When a transaction occurs between non-partner acquirers, such as those represented by Merchant B 304 , non-partner acquirer 320 routes the transaction to a partner acquirer, such as acquirer 306 . The account linking device 312 acts as a partner acquirer to exchange certificates and record transaction activity. In this case, a second level interchange fee may apply.

因此,账户关联装置312可配置为交换证书数据、收集交易数据、并且结算交易。账户关联装置312还可执行用户规则、要求验证用户在交易中出现、并且可在识别欺诈的过程中涉及消费者、发行机构316、322和/或其他方。Accordingly, account linking device 312 may be configured to exchange credential data, collect transaction data, and settle transactions. The account association device 312 may also enforce user rules requiring verification of the user's presence in a transaction, and may involve consumers, issuers 316, 322 and/or other parties in the process of identifying fraud.

图16-20是示出了交易流程过程概览的流程图。图16可以是用于进行交易的一种常规方法330。在这个例子中,持卡人332或用户使用代理装置100、104与商家334进行购买。商家334获得交易信息,例如第一账户信息,并创建授权请求。商家334将该信息传递给收单机构336。收单机构336然后将该授权请求传递给该方案或交换机338,该方案或交换机338然后将该授权请求发送到发行机构340。发行机构340使用通过反向路径发送给商家的授权响应、来响应该来自商家334的授权请求。16-20 are flowcharts showing an overview of the transaction flow process. Figure 16 may be a conventional method 330 for conducting a transaction. In this example, the cardholder 332 or user uses the proxy device 100, 104 to make a purchase with the merchant 334. Merchant 334 obtains transaction information, such as first account information, and creates an authorization request. Merchant 334 passes this information to acquirer 336 . The acquirer 336 then passes the authorization request to the scheme or switch 338 , which then sends the authorization request to the issuer 340 . Issuer 340 responds to the authorization request from merchant 334 with an authorization response sent via the reverse path to the merchant.

在图17中,图16的方法330包括账户关联装置352,其可对应于图1中所示的账户关联装置24。账户关联装置352可包括代理翻译装置354。在该实施例中,发行机构340既是第一账户明细也是第一有效证书明细的发行机构。交易如图16所描述的那样以通常的方式进行,不同的是方案/交换机338向账户关联装置352发送授权请求。In FIG. 17 , the method 330 of FIG. 16 includes account linking means 352 , which may correspond to the account linking means 24 shown in FIG. 1 . Account association means 352 may include proxy translation means 354 . In this embodiment, the issuer 340 is the issuer of both the first account details and the first valid certificate details. The transaction proceeds in the usual manner as described in FIG. 16 , except that the scheme/exchange 338 sends an authorization request to the account association device 352 .

账户关联装置352将第一授权请求置于保持状态。代理翻译装置354分析消费者规则以将第一账户明细映射到替代有效证书。账户关联装置352创建第二授权请求(其可以是新的金融交易或直接对发行机构的API调用),并且账户关联装置352将第二授权请求发送到发行机构340。Account association means 352 places the first authorization request on hold. The proxy translator 354 analyzes the consumer rules to map the first account details to alternate valid credentials. Account linking device 352 creates a second authorization request (which may be a new financial transaction or a direct API call to the issuer), and account linking device 352 sends the second authorization request to issuer 340 .

发行机构340处理第二授权请求并发送响应。账户关联装置352使用第二授权响应请求来创建对第一授权请求的响应,并将该响应发送给商家334。Issuer 340 processes the second authorization request and sends a response. Account association device 352 uses the second authorization response request to create a response to the first authorization request and sends the response to merchant 334 .

在图18中方法360与图17的方法350相同,不同的是在该实施例中发行机构(代理)362是第一账户明细的发行机构并且发行机构(证书)366是第一有效证书明细的发行机构。在方法360中,交易流程与方法350相同,不同的是账户关联装置352将第二授权请求发送至方案/交换机364,其中方案/交换机364将第二授权请求发送至发行机构(证书)366。The method 360 in Figure 18 is the same as the method 350 of Figure 17, except that in this embodiment issuer (agent) 362 is the issuer of the first account detail and issuer (certificate) 366 is the issuer of the first valid certificate detail G. In method 360 , the transaction flow is the same as in method 350 , except that account association device 352 sends a second authorization request to scheme/switch 364 , which sends the second authorization request to issuer (certificate) 366 .

发行机构(证书)366处理第二授权请求并发送响应。账户关联装置352使用第二授权响应请求来创建对第一授权请求的响应,并将该响应发送给商家。Issuer (Certificate) 366 processes the second authorization request and sends a response. Account association means 352 uses the second authorization response request to create a response to the first authorization request and sends the response to the merchant.

在图19中方法370与图17的方法350相同,不同的是在该实施例中第三方令牌库372被包括在交易流程中。在该实施例中,持卡者332可以是在其上存储令牌化替代第一账户明细的装置。商家创建包含令牌化的替代第一账户明细的第一授权请求,并以与图17的方法350描述的相同方式将第一授权请求发送给方案/交换机。然而,在方法370中,方案/交换机338将令牌化的替代第一账户明细发送到第三方令牌库372,该令牌库将令牌翻译成去令牌化的替代第一账户明细并且将该去令牌化的替代第一账户明细发送到方案/交换机。方案/交换机然后将该去令牌化的替代第一账户明细发送到账户关联装置352。在接收到该响应之后,帐户关联装置352以方法350中描述的方式处理该响应。The method 370 in Figure 19 is the same as the method 350 of Figure 17, except that in this embodiment a third-party token repository 372 is included in the transaction flow. In this embodiment, the cardholder 332 may be the device on which the tokenized surrogate first account details are stored. The merchant creates a first authorization request containing the tokenized alternate first account details and sends the first authorization request to the plan/exchange in the same manner as described for method 350 of FIG. 17 . However, in the method 370, the scheme/exchange 338 sends the tokenized alternate first account details to the third party token store 372, which translates the token into the de-tokenized alternate first account details and The de-tokenized alternate first account details are sent to the scheme/exchange. The scheme/exchange then sends the de-tokenized alternate first account details to the account association means 352. After receiving the response, account association device 352 processes the response in the manner described in method 350 .

在图20中方法380与图20的方法370相同,不同的是在该实施例中,发行机构(代理)362是第一账户明细的发行机构并且发行机构(证书)366是第一有效证书明细的发行机构。在方法380中,交易流程与方法370相同,不同的是账户关联装置352将第二授权请求发送给方案/交换机364,方案/交换机364将第二授权请求发送给发行机构(证书)366。发行机构(证书)366处理第二授权请求并发送响应。账户关联装置352使用第二授权响应请求创建对第一授权请求的响应,并以方法370描述的方式将该响应发送给商家。The method 380 in FIG. 20 is the same as the method 370 of FIG. 20, except that in this embodiment, the issuer (agent) 362 is the issuer of the first account detail and the issuer (certificate) 366 is the first valid certificate detail issuer. In method 380 , the transaction flow is the same as in method 370 , except that account association device 352 sends a second authorization request to scheme/switch 364 , which sends the second authorization request to issuer (certificate) 366 . Issuer (Certificate) 366 processes the second authorization request and sends a response. The account association device 352 uses the second authorization response request to create a response to the first authorization request and sends the response to the merchant in the manner described in method 370 .

这里描述的各实施方式表示多种可能的实现方式和示例,并且不旨在将本公开限制为任何特定实施方式。相反,如本领域普通技术人员将会理解的,可以对这些实施方式进行各种修改。任何这样的修改旨在包括在本公开的精神和范围内。The various implementations described herein represent various possible implementations and examples, and are not intended to limit the present disclosure to any particular implementation. Rather, various modifications may be made to these embodiments, as will be understood by those of ordinary skill in the art. Any such modifications are intended to be included within the spirit and scope of this disclosure.

Claims (13)

1. A system, comprising:
a point-of-sale (POS) device configured to obtain a proxy certificate corresponding to a valid certificate of a user from a mobile proxy device as part of a financial transaction and to send an encrypted financial message including the proxy certificate to a merchant acquirer;
a merchant acquirer configured to receive, decrypt, re-encrypt financial messages to generate an original encrypted message including the proxy certificate, and send the original encrypted message to a payment switch;
a payment switch configured to receive the original encrypted message from the merchant acquirer and send the original encrypted message to an issuer processor;
an issuer processor configured to receive the original encrypted message from the payment switch and send the proxy certificate to an account association device;
account association means configured to receive the original encrypted message from the issuer processor, decrypt the original encrypted message, generate an edited transaction message, and re-encrypt the edited transaction message, the edited transaction message including a tokenized message including a valid credential of the user corresponding to the proxy credential; and
an issuer for receiving the re-encrypted edited transaction message from the account association device, sending a response message indicating whether to accept or decline the financial transaction based at least in part on the re-encrypted edited transaction message;
wherein the account association means is configured to generate an edited response message from the response message by reversing the mapping from the proxy certificate to the user valid certificate and to send the edited response message to the merchant acquirer.
2. The system of claim 1, wherein the mobile proxy device is in the form of a card.
3. The system of claim 1, wherein the mobile proxy device is a smartphone.
4. The system of claim 1, wherein the account association device is configured to select a valid credential for the user from a plurality of credentials based on configurable rules related to usage of the mobile agent device.
5. The system of claim 4, wherein the configurable rules are predetermined by at least one of a user of the mobile proxy device and the issuer.
6. The system of claim 5, wherein the configurable rules are generated by the user using a web browser on a mobile device or computer.
7. The system of claim 5, wherein the configurable rules are generated by an operator associated with the issuer.
8. The system of claim 4, wherein the configurable rule depends on a computed location of the mobile proxy device.
9. The system of claim 4, wherein the configurable rule depends on a value of a transaction.
10. The system of claim 1, wherein the account correlation device is configured to generate the edited raw transaction message using a customizable rules engine.
11. The system of claim 1, further comprising:
a transaction repository configured to:
decrypting and tokenizing the original encrypted message to produce the tokenized message; and
sending the tokenized message.
12. The system of claim 1, further comprising:
a transaction guardian configured to receive the selected valid certificate and the requested transaction-edited token.
13. The system of claim 12, wherein the transaction guardian is further configured for verifying the original encrypted message and the original transaction of the requested transaction compilation.
CN201680064409.7A 2015-09-10 2016-08-24 Proxy device for representing multiple certificates Expired - Fee Related CN108780547B (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US201562283769P 2015-09-10 2015-09-10
US62/283,769 2015-09-10
PCT/IB2016/001395 WO2017042629A1 (en) 2015-09-10 2016-08-24 Proxy device for representing multiple credentials

Publications (2)

Publication Number Publication Date
CN108780547A CN108780547A (en) 2018-11-09
CN108780547B true CN108780547B (en) 2022-10-14

Family

ID=62527707

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201680064409.7A Expired - Fee Related CN108780547B (en) 2015-09-10 2016-08-24 Proxy device for representing multiple certificates

Country Status (2)

Country Link
EP (1) EP3347866A1 (en)
CN (1) CN108780547B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4379632A1 (en) * 2022-11-30 2024-06-05 Thales Dis France Sas Method for managing a card

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101258509A (en) * 2005-07-13 2008-09-03 万事达卡国际股份有限公司 Apparatus and method for integrated payment and electronic merchandise transfer
CN102160061A (en) * 2008-08-20 2011-08-17 X卡控股有限公司 Secure smart card system
CN103164738A (en) * 2013-02-06 2013-06-19 厦门盛华电子科技有限公司 Mobile phone user identification card based on mobile payment multichannel digital certificate

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8977569B2 (en) * 2011-09-29 2015-03-10 Raj Rao System and method for providing smart electronic wallet and reconfigurable transaction card thereof

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101258509A (en) * 2005-07-13 2008-09-03 万事达卡国际股份有限公司 Apparatus and method for integrated payment and electronic merchandise transfer
CN102160061A (en) * 2008-08-20 2011-08-17 X卡控股有限公司 Secure smart card system
CN103164738A (en) * 2013-02-06 2013-06-19 厦门盛华电子科技有限公司 Mobile phone user identification card based on mobile payment multichannel digital certificate

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4379632A1 (en) * 2022-11-30 2024-06-05 Thales Dis France Sas Method for managing a card
WO2024115124A1 (en) * 2022-11-30 2024-06-06 Thales Dis France Sas Method for managing a card

Also Published As

Publication number Publication date
EP3347866A1 (en) 2018-07-18
CN108780547A (en) 2018-11-09

Similar Documents

Publication Publication Date Title
US20210073821A1 (en) Proxy device for representing multiple credentials
US12008088B2 (en) Recurring token transactions
US11138593B1 (en) Systems and methods for contactless smart card authentication
AU2015259162B2 (en) Master applet for secure remote payment processing
US8281991B2 (en) Transaction secured in an untrusted environment
US11157895B2 (en) Payment devices having multiple modes of conducting financial transactions
CA2686280A1 (en) Method and system for payment authorization and card presentation using pre-issued identities
US20180322501A1 (en) Systems and methods for registering for card authentication reads
US20140365366A1 (en) System and device for receiving authentication credentials using a secure remote verification terminal
US12413580B2 (en) Token processing system and method
US20020095580A1 (en) Secure transactions using cryptographic processes
CN114788223B (en) Token management system and method
CN112970234B (en) Account assertion
CN107230078A (en) The method and system of digital cash payment is carried out using viewable numbers currency chip card
US20020073315A1 (en) Placing a cryptogram on the magnetic stripe of a personal transaction card
CN108475374B (en) Payment devices with multiple modes for conducting financial transactions
CN108780547B (en) Proxy device for representing multiple certificates
CN107230074A (en) The method and system of digital cash is stored in digital cash chip card

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20221014

CF01 Termination of patent right due to non-payment of annual fee