Electronic money remittance method and system therefor
Patent Information
- Application Number
- JP2024152790
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2011-10-25
- Filing Date
- 2024-09-05
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2032-10-11
AI Technical Summary
Existing electronic money systems using IC cards and mobile terminals with IC chips lack the ability to securely transfer electronic money without the risk of loss or theft, and do not fully replicate the functionality of cash transactions.
An electronic money remittance method and system that utilizes an electronic money management server to authenticate user terminals through near-field communication, exchange electronic certificates, and issue access keys to securely transfer electronic money between user terminals, ensuring that transactions are only completed if the terminals are authenticated and have sufficient funds.
Enables secure and reliable transfer of electronic money similar to cash transactions, even if the user's terminal is lost or stolen, by ensuring authentication and authorization of terminals and managing electronic money through a centralized server.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an electronic money remittance method and system for remitting electronic money owned by a first user to a second user using a terminal of a first user and a terminal of a second user. [Background technology]
[0002] In recent years, contactless IC cards with embedded IC chips and mobile terminals with embedded IC chips have become widespread. An example of a contactless IC card with embedded IC chip is one used at ticket gates and boarding gates when getting on and off a train or bus, and electronic money is stored in the IC chip of this IC card in advance. When this IC card is brought close to a dedicated reader / writer at the ticket gate or boarding gate, power is supplied to the IC chip of the IC card by electromagnetic waves from the reader / writer, and a signal requesting payment of, for example, the fare is sent from the reader / writer to the IC chip of the IC card. Meanwhile, the IC chip operates with the supplied power to receive a signal from the reader / writer, subtracts the amount of the fare from the remaining balance of electronic money stored in the IC chip, and sends a signal to the reader / writer to pay the fare. Then, the reader / writer that receives the signal from the IC card communicates with a center or the like that manages the electronic money of the IC card to complete the payment of the fare. In the step of completing this payment, the issuer of the electronic money transfers actual cash to the railway company or bus company. In this way, the electronic money is stored in the IC chip of the IC card beforehand, and the IC chip itself holds the electronic money (monetary value).
[0003] On the other hand, even in the case of mobile terminals with embedded IC chips, electronic money can be stored in the IC chip in advance, so fares can be paid when boarding or alighting from trains or buses via the aforementioned reader / writer, just as in the case of IC cards.
[0004] In addition, in the case of a mobile terminal with an embedded IC chip, it is possible to access the IC chip from an application on the mobile terminal and perform Internet shopping and the like through the application. As an example of processing for Internet shopping using an application on a mobile terminal, first, with electronic money of Edy (registered trademark) stored in the IC chip of the mobile terminal, the application accesses an Internet shopping site that can use the electronic money and applies for payment using the electronic money. Then, the shopping site that accepts the application for payment transmits an actual payment request related to the application to the Edy center (where the electronic money is managed). The Edy center displays a payment confirmation email based on the actual payment request on the application of the mobile phone and requests input regarding whether or not the payment is possible. When the mobile terminal inputs that the payment is possible, the application deducts the electronic money of the amount related to the payment from the IC chip of the mobile terminal and transmits the fact that the payment is possible to the Edy center. Then, when the Edy center receives a signal indicating that the payment is possible from the mobile phone, it performs processing for the payment of actual money to the shopping site via a bank or the like and notifies the shopping site and the mobile terminal that the payment has been completed. The shopping site also displays a message in the application on the mobile device that the payment has been completed. In this way, even when using a mobile device with an embedded IC chip to shop online, it is a prerequisite that the IC chip itself holds electronic money (monetary value).
[0005] On the other hand, payments that do not use electronic money include payments using credit cards and payments using debit cards (bank cash cards with debit cards). For example, when making a payment using a debit card at a store that accepts debit cards, the debit card is first handed to a store attendant, who then has the debit card read by a dedicated reading device connected to a POS terminal. The owner of the debit card also inputs a personal identification number into a dedicated device connected to the POS terminal. The POS terminal transmits the card information read by the reading device, the amount of the payment, and the personal identification number to a server of the bank that issued the card. When the bank server judges that the card information inquiry result is OK and that the amount of the payment is stored in an account corresponding to the card information, the amount of the payment is immediately debited from the account, and a process is performed to transfer the amount from the bank to the store. The store is also notified that the debit from the account has been completed, and the payment by the debit card is completed.
[0006] Regarding the IC card, the mobile terminal with an IC chip, and the payment method using a debit card, For this purpose, reference can be made to patent documents such as JP-A-2009-151737, JP-A-2006-048360, and JP-A-2008-264529.
[0007] By the way, while the debit card deals in actual cash, the IC card and I Mobile terminals with C chips handle electronic money.
[0008] Here, since debit cards handle actual cash and are used to withdraw cash directly from a bank account, if the card information or PIN is stolen and misused, the cash that should be in the bank account may disappear, affecting other withdrawals, and it may not be possible to recover the misused cash, which could result in significant damage.
[0009] On the other hand, since the IC cards and mobile terminals with IC chips handle electronic money, even if the IC cards or mobile terminals are stolen and misused, there is a limit to the amount of damage that can be caused by the electronic money, so they can be said to be safer than debit cards. Also, since the IC chips of the IC cards and mobile terminals with IC chips store electronic money (monetary value) in the IC chips themselves, the electronic money cannot be used unless the IC cards or mobile terminals themselves are stolen, so in that respect they can also be said to be safer than debit cards.
[0010] However, when the IC card or mobile terminal with an IC chip is lost or stolen, the electronic money stored in the IC chip is also lost or stolen. Therefore, when the IC card or mobile terminal is lost or stolen, it is possible to restrict its use by contacting the IC card issuer, but it is not possible to recover the electronic money stored in it unless the IC card or mobile terminal itself is recovered.
[0011] On the other hand, whether or not electronic money can be paid at a store using a mobile terminal with an IC chip depends mainly on whether the store's POS terminal is equipped with a reader / writer and has introduced a payment system using that electronic money. When electronic money is paid at a store's POS terminal using a mobile terminal with an IC chip, the amount of electronic money is deducted from the IC chip of the mobile terminal, and the electronic money information, the unique information stored in the IC chip, and the unique information held by the POS terminal are sent to a center that manages electronic money. Then, when the center confirms that there are no problems with the payment, the center carries out a process to pay actual cash to the store, and the payment is deemed to have been made by the owner of the mobile terminal to the store.
[0012] In this way, payments made with electronic money using the IC card or a mobile terminal with an IC chip may appear to be made with electronic money at first glance, but in fact cash is exchanged behind the scenes, and electronic money is not used entirely as a substitute for cash. Summary of the Invention [Problem to be solved by the invention]
[0013] The present invention has been made to solve such problems, and has as its object to provide an electronic money remittance method and system which allows electronic money to be handled in a manner very similar to cash, and which prevents the loss of electronic money even if the terminal for operating the electronic money is lost or stolen. [Means for solving the problem]
[0014] In order to achieve the above object, according to a main aspect of the present invention, there is provided an electronic money remittance method for remitting electronic money from a first user to a second user, using a first user terminal owned by a first user, a second user terminal owned by a second user, and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the electronic money of the first user and the electronic money of the second user, respectively, wherein the electronic money management server and the terminal of the first user store a first electronic certificate associated with information on the first user and / or information on the first user terminal, and the electronic money management server and the second user terminal store a second electronic certificate associated with information on the second user and / or information on the second user terminal, the method comprising the steps of: performing a first receiving step in which the first user terminal receives at least a part of information of the second electronic certificate from the second user terminal via short-range wireless communication or the communication line and stores the information in a memory of the first user terminal; a second receiving step of receiving at least a part of the information of the first electronic certificate from the first user terminal via the communication line and storing the information in a memory of the second user terminal, and a third receiving step of the electronic money management server receiving at least a part of the information of the second electronic certificate from the first user terminal and receiving at least a part of the information of the first electronic certificate from the second user terminal after the first and second receiving steps; an authentication step of authenticating the first user terminal and the second user terminal by determining at least whether or not the at least a part of the information of the second electronic certificate received from the first user terminal corresponds to the information of the second electronic certificate stored in the electronic money management server and whether or not the at least a part of the information of the first electronic certificate received from the second user terminal corresponds to the information of the first electronic certificate stored in the electronic money management server; and an access key transmission step of transmitting an access key to the first user terminal and the second user terminal, respectively, after the first user terminal and the second user terminal are authenticated in the authentication step.The electronic money remittance method includes a fourth receiving step of receiving from the first user terminal the access key and an instruction to remit electronic money to the second user, and receiving from the second user terminal the access key, an instruction to receive electronic money from the first user, and an amount to be received; a settlement determination step of, after the fourth receiving step, determining whether the access key received from the first user terminal corresponds to the access key received from the second user terminal, and determining whether the amount to be received is within the balance of electronic money of the first user stored in the electronic money management server; and a settlement step of reducing the balance of electronic money of the first user in the electronic money management server by the amount of the amount to be received, and increasing the balance of electronic money of the second user in the electronic money management server by the amount of the amount to be received, if it is determined in the settlement determination step that the access key corresponds to the access key and is within the balance.
[0015] According to another main aspect of the present invention, there is provided an electronic money remittance method for remittance of electronic money from a first user to a second user, using a first user terminal owned by a first user, a second user terminal owned by a second user, and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the electronic money of the first user and the electronic money of the second user, respectively, wherein the electronic money management server and the terminal of the first user store a first electronic certificate associated with information of the first user and / or information of the first user terminal, and the electronic money management server and the second user terminal store a second electronic certificate associated with information of the second user and / or information of the second user terminal, the method comprising: a first receiving step in which the first user terminal receives at least a part of information of the second electronic certificate from the second user terminal via short-range wireless communication or the communication line and stores the information in a memory of the first user terminal; a second receiving step of receiving at least a part of the information of the first electronic certificate from the first user terminal via a line and storing the information in a memory of the second user terminal, a third receiving step of the electronic money management server receiving at least a part of the information of the second electronic certificate from the first user terminal and receiving at least a part of the information of the first electronic certificate from the second user terminal after the first and second receiving steps; an authentication step of authenticating the first user terminal and the second user terminal by at least determining whether or not the at least a part of the information of the second electronic certificate received from the first user terminal corresponds to the information of the second electronic certificate stored in the electronic money management server and whether or not the at least a part of the information of the first electronic certificate received from the second user terminal corresponds to the information of the first electronic certificate stored in the electronic money management server; and an access key transmission step of transmitting an access key to the first user terminal and the second user terminal, respectively, after the first user terminal and the second user terminal are authenticated in the authentication step.The electronic money settlement method includes a fourth receiving step of receiving from the first user terminal the access key, a remittance instruction to the second user, and a remittance amount, and receiving from the second user terminal the access key and an instruction to receive electronic money from the first user; a settlement determination step of at least judging whether the access key received from the first user terminal and the access key received from the second user terminal correspond to each other after the fourth receiving step, and judging whether the transmission amount is within the balance of the electronic money of the first user stored in the electronic money management server; and a settlement step of decreasing the balance of the electronic money of the first user in the electronic money management server by the amount of the remittance, and increasing the balance of the electronic money of the second user in the electronic money management server by the amount of the remittance, if it is determined in the settlement determination step that the access key corresponds to the access key and is within the balance.
[0016] According to yet another main aspect of the present invention, there is provided an electronic money remittance system comprising a first user terminal owned by a first user, a second user terminal owned by a second user, and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the first user's electronic money and the second user's electronic money, respectively, for remittance of electronic money from the first user to the second user, wherein the electronic money management server and the first user's terminal store a first electronic certificate associated with information on the first user and / or information on the first user terminal, and the electronic money management server and the second user terminal store a second electronic certificate associated with information on the second user and / or information on the second user terminal, the system further comprising: a first receiving means for receiving at least a part of information of the second electronic certificate from the second user terminal via short-range wireless communication or the communication line and storing the information in a memory of the first user terminal; a second receiving means for receiving at least a part of the information of the first electronic certificate from the first user terminal via line communication or the communication line and storing the part of the information in a memory of the second user terminal, wherein the electronic money management server has a third receiving means for receiving at least a part of the information of the second electronic certificate from the first user terminal and at least a part of the information of the first electronic certificate from the second user terminal; an authentication means for authenticating the first user terminal and the second user terminal by at least determining whether or not the at least a part of the information of the second electronic certificate received from the first user terminal corresponds to the information of the second electronic certificate stored in the electronic money management server and whether or not the at least a part of the information of the first electronic certificate received from the second user terminal corresponds to the information of the first electronic certificate stored in the electronic money management server; and an access key transmitting means for transmitting an access key to the first user terminal and the second user terminal, respectively, after the first user terminal and the second user terminal are authenticated in the authentication step.The electronic money remittance system includes a fourth receiving means for receiving from the first user terminal the access key and an instruction to remit electronic money to the second user, and for receiving from the second user terminal the access key, an instruction to receive electronic money from the first user, and an amount to be received; a settlement determination means for, when the fourth receiving means receives data from the first user terminal and the second user terminal, determining whether the access key received from the first user terminal corresponds to the access key received from the second user terminal, and determining whether the amount to be received is within the balance of electronic money of the first user stored in the electronic money management server; and a settlement means for, when the settlement determination means determines that the access key corresponds and is within the balance, reducing the balance of electronic money of the first user in the electronic money management server by the amount of the amount to be received, and increasing the balance of electronic money of the second user in the electronic money management server by the amount of the amount to be received.
[0017] According to yet another main aspect of the present invention, there is provided an electronic money remittance system for remittance of electronic money from the first user to the second user, the system comprising: a first user terminal owned by a first user; a second user terminal owned by a second user; and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the electronic money of the first user and the electronic money of the second user, the electronic money management server and the terminal of the first user storing a first electronic certificate associated with information of the first user and / or information of the first user terminal, and the electronic money management server and the second user terminal storing a second electronic certificate associated with information of the second user and / or information of the second user terminal, the system comprising: a first receiving means for receiving at least a part of information of the second electronic certificate from the second user terminal via short-range wireless communication or the communication line and storing the information in a memory of the first user terminal; a second receiving means for receiving at least a part of the information of the first electronic certificate from the first user terminal via wireless communication or the communication line and storing the part in a memory of the second user terminal, wherein the electronic money management server receives at least a part of the information of the second electronic certificate from the first user terminal and receives at least a part of the information of the first electronic certificate from the second user terminal; an authentication means for authenticating the first user terminal and the second user terminal by at least determining whether or not the at least a part of the information of the second electronic certificate received from the first user terminal corresponds to the information of the second electronic certificate stored in the electronic money management server and whether or not the at least a part of the information of the first electronic certificate received from the second user terminal corresponds to the information of the first electronic certificate stored in the electronic money management server; and an access key transmission means for transmitting an access key to the first user terminal and the second user terminal, respectively, after the first user terminal and the second user terminal are authenticated in the authentication step.The electronic money remittance system includes a fourth receiving means for receiving from the first user terminal the access key, an instruction to remit electronic money to the second user, and an amount to be remitted, and also receiving from the second user terminal the access key and an instruction to receive electronic money from the first user; a settlement determination means for, when the fourth receiving means receives data from the first user terminal and the second user terminal, determining at least whether the access key received from the first user terminal corresponds to the access key received from the second user terminal and determining whether the amount to be transmitted is within the balance of electronic money of the first user stored in the electronic money management server; and, when the settlement determination means determines that the access key corresponds and is within the balance, reducing the balance of electronic money of the first user in the electronic money management server by the amount of the amount to be transmitted and increasing the balance of electronic money of the second user in the electronic money management server by the amount of the amount to be remitted.
[0018] Thus, in the present invention, in the first receiving step, the first user terminal receives at least a part of the information of the second electronic certificate from the second user terminal, and in the second receiving step, the second user terminal receives at least a part of the information of the first electronic certificate from the first user terminal. After the first user terminal and the second user terminal exchange at least a part of the electronic certificate in this way, the electronic money management server receives at least a part of the information of the electronic certificate of each transaction partner from each user terminal in the third receiving step, and judges whether or not the part of the information of the electronic certificate corresponds to the information of the electronic certificate stored in the electronic money management server. In other words, the electronic certificate information of the own terminal is sent from the other terminal to the electronic money management server, and the electronic certificate information of the other terminal is sent from the own terminal to the electronic money management server, so that at this point, the two terminals that are about to carry out the transaction are identified, and the electronic certificates sent by each are compared by the electronic money management server. This allows the electronic money management server to reliably authenticate the terminal that is about to send or receive electronic money.
[0019] Here, the first electronic certificate held by the first user terminal is unique information held only by the first user terminal and the electronic money management server, and the second electronic certificate held by the second user terminal is unique information held only by the second user terminal and the electronic money management server. At least a part of the information of the first electronic certificate is transmitted to the electronic money management server by the second user terminal, and at least a part of the information of the second electronic certificate is transmitted to the electronic money management server by the first user terminal. The electronic money management server then authenticates the terminal that is about to send or receive electronic money by accepting at least a part of the information of the electronic certificate from both the first and second user terminals. For this reason, even if the second user terminal illegally obtains the electronic certificate information of the first user terminal and tries to obtain the electronic money held by the first user by some means, the first user will not be able to remit electronic money to the second user unless the first user terminal transmits its own electronic certificate information to the electronic money management server.
[0020] Furthermore, in the present invention, after authenticating two terminals that are about to send and receive electronic money as described above, the electronic money management server transmits an access key to each terminal and receives instructions for sending and receiving electronic money, etc., transmitted from each terminal together with the access key. The electronic money management server also determines whether the access keys received from each terminal are compatible, and then transmits electronic money from the first user to the second user within the electronic money management server. In this way, the access keys are issued and whether the access keys are compatible is determined, so that electronic money can be transmitted from the first user to the second user more safely.
[0021] Furthermore, in the present invention, since each user's electronic money is stored in an electronic money management server, even if, for example, the first user terminal is lost and cannot be recovered, the first user's electronic money will not be reduced by that single incident.
[0022] Furthermore, in the present invention, by exchanging the contents of the electronic certificates held by the first user terminal and the second user terminal, and by sending instructions to send and receive electronic money together with an access key issued by the electronic money management server, it is possible to send electronic money directly from the first user to the second user while ensuring the security of the electronic money transfer. This makes it possible to exchange electronic money in a manner very similar to cash.
[0023] Furthermore, according to an embodiment of the present invention, there is provided an electronic money remittance method, further comprising an authentication transmission step in which the electronic money management server transmits to the first user terminal and the second user terminal a notice that the authentication step has been performed, after the authentication transmission step, and an access key request receiving step in which the electronic money management server receives a request for transmission of the access key from the first user terminal and the second user terminal, after the authentication transmission step, and the access key transmitting step transmits an access key to each of the first user terminal and the second user terminal in response to the access key request receiving step.
[0024] According to another embodiment of the present invention, in the electronic money remittance method, only the electronic money management server stores the first electronic certificate or stores the first electronic certificate in association with the first electronic certificate. An electronic money remittance method is provided, characterized in that the electronic money management server has the private key of the first electronic certificate, and only the electronic money management server has the private key of the second electronic certificate within the second electronic certificate or linked to the second electronic certificate, and in the authentication process, at least a portion of the information of the first and second electronic certificates is decrypted using the private keys of the first and second electronic certificates, and it is determined whether the decrypted information corresponds to the information of the first and second electronic certificates stored in the electronic money management server.
[0025] According to yet another embodiment of the present invention, there is provided an electronic money remittance method, wherein the electronic money management server is capable of storing the first user's electronic money in correspondence with a plurality of electronic money account numbers, and in the fourth receiving step, the electronic money management server further receives from the first user terminal an electronic money account number to which the remittance is to be made, and in the settlement determination step, it is determined whether the received amount is within the remaining balance of the first user's electronic money stored in correspondence with the electronic money account number to which the remittance is to be made, and in the settlement step, when it is determined in the settlement determination step that the access key corresponds and is within the remaining balance, the remaining balance of the first user's electronic money stored in correspondence with the electronic money account number to which the remittance is to be made is reduced by the amount of the received amount.
[0026] Furthermore, according to yet another embodiment of the present invention, there is provided the electronic money remittance method, wherein the first user terminal, after the first receiving step, performs a first replacement processing step of replacing a part of the first electronic certificate with at least a part of information of the second electronic certificate, or a first addition processing step of adding at least a part of the information of the second electronic certificate to the first electronic certificate, and the second user terminal, after the second receiving step, performs a second replacement processing step of replacing a part of the second electronic certificate with at least a part of information of the first electronic certificate, or a second addition processing step of adding at least a part of the information of the first electronic certificate to the second electronic certificate, and the third receiving step receives at least a part of the information of the second electronic certificate by receiving from the first user terminal the first electronic certificate changed by the first replacement processing step or the first addition processing step, and receives at least a part of the information of the first electronic certificate by receiving from the second user terminal the second electronic certificate changed by the second replacement processing step or the second addition processing step.
[0027] Furthermore, according to yet another embodiment of the present invention, there is provided an electronic money remittance method, characterized in that, after the payment step, the electronic money management server further performs an invalidation step of invalidating the access keys received from the first user terminal and the second user terminal and determined in the payment determination step.
[0028] Furthermore, according to yet another embodiment of the present invention, there is provided an electronic money remittance method, characterized in that in the first and second receiving steps, the first user terminal receives at least a portion of the information of the second electronic certificate from the second user terminal, and the second user terminal receives at least a portion of the information of the first electronic certificate from the first user terminal, via short-range wireless communication that enables communication between the first user terminal and the second user terminal when the distance between the first user terminal and the second user terminal becomes a short distance of a few centimeters to a few tens of centimeters.
[0029] According to yet another embodiment of the present invention, there is provided an electronic money remittance method, wherein the electronic money management server stores the first electronic certificate in association with first individual authentication information held by the first user terminal, and stores the second electronic certificate in association with individual authentication information held by the second user terminal, and in the third receiving step, the first individual authentication information is received from the first user terminal, and the second individual authentication information is received from the second user terminal, and in the authentication step, a determination is made as to whether or not the first individual authentication information corresponds to information that has not been changed in the first electronic certificate changed by the first substitution processing step or the first addition processing step, and whether or not the second individual authentication information corresponds to information that has not been changed in the second electronic certificate changed by the second substitution processing step or the second addition processing step, thereby authenticating the first user terminal and the second user terminal.
[0030] According to yet another main aspect of the present invention, there is provided an electronic money remittance method for remittance of electronic money from a first user to a second user, using a first user terminal owned by a first user, a second user terminal owned by a second user, and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the electronic money of the first user and the electronic money of the second user, respectively, wherein the electronic money management server and the terminal of the first user store information of the first user and / or first certification information associated with the information, and the electronic money management server and the second user terminal store information of the second user and / or second certification information associated with the information, the method comprising the steps of: a first receiving step in which the first user terminal receives second terminal information, which is at least a part of the second certification information, from the second user terminal via short-range wireless communication or the communication line and stores the second terminal information in a memory of the first user terminal; a second receiving step of receiving first terminal information, which is at least a part of the first certification information, from the first user terminal via the electronic money management server and storing the first terminal information in a memory of the second user terminal; a third receiving step of the electronic money management server receiving the second terminal information from the first user terminal and receiving the first terminal information from the second user terminal after the first and second receiving steps; an authentication step of authenticating the first user terminal and the second user terminal by determining at least whether the second terminal information received from the first user terminal corresponds to the second certification information stored in the electronic money management server and whether the first terminal information received from the second user terminal corresponds to the first certification information stored in the electronic money management server; and after the first user terminal and the second user terminal are authenticated in the authentication step, receiving the access key and an instruction to remit electronic money to the second user from the first user terminal and receiving the access key, an instruction to receive electronic money from the first user and an amount to be received from the second user terminal;The electronic money remittance method further includes a fourth receiving step of receiving an amount to be remitted from the first user terminal to the second user or receiving an amount to be received from the first user from the second user terminal, a settlement determination step of, after the fourth receiving step, determining whether the access key received from the first user terminal corresponds to the access key received from the second user terminal and determining whether the amount to be remitted or the amount to be received is within the balance of the electronic money of the first user stored in the electronic money management server, and a settlement step of reducing the balance of the electronic money of the first user in the electronic money management server by the amount of the received amount and increasing the balance of the electronic money of the second user in the electronic money management server by the amount of the received amount when it is determined in the settlement determination step that the access key corresponds and is within the balance.
[0031] Thus, in the present invention, in the first receiving step, the first user terminal receives second terminal information, which is at least a part of the second certification information, from the second user terminal, and in the second receiving step, the second user terminal receives first terminal information, which is at least a part of the first certification information, from the first user terminal. After the first user terminal and the second user terminal exchange each other's certification information in this way, the electronic money management server receives the certification information of each transaction partner from each user terminal in the third receiving step and judges whether or not the certification information corresponds to the certification information stored in the electronic money management server. In other words, the certification information of one's own terminal is sent from another terminal to the electronic money management server, and the certification information of the other terminal is sent from one's own terminal to the electronic money management server, so that at this point, the two terminals that are about to carry out the transaction are identified, and the electronic money management server compares the certification information sent by each of them. This allows the electronic money management server to reliably authenticate the terminal that is about to send or receive electronic money.
[0032] Here, the first certification information held by the first user terminal is unique information held only by the first user terminal and the electronic money management server, and the second certification information held by the second user terminal is unique information held only by the second user terminal and the electronic money management server. At least a part of the first certification information is transmitted to the electronic money management server by the second user terminal, and at least a part of the second certification information is transmitted to the electronic money management server by the first user terminal. The electronic money management server accepts the certification information from both the first and second user terminals, thereby authenticating the terminal that is attempting to transmit or receive electronic money. For this reason, even if the second user terminal illegally obtains the certification information of the first user terminal and attempts to obtain the electronic money held by the first user by some means, for example, the first user will not be able to transmit electronic money to the second user unless its own certification information is transmitted from the first user terminal to the electronic money management server.
[0033] Furthermore, in the present invention, since each user's electronic money is stored in an electronic money management server, even if, for example, the first user terminal is lost and cannot be recovered, the first user's electronic money will not be reduced by that single incident.
[0034] Furthermore, in the present invention, the first user terminal and the second user terminal exchange the contents of the certification information that each has, and send instructions to send and receive electronic money, so that the first user can send electronic money directly to the second user while ensuring the security of the electronic money transfer. This makes it possible to exchange electronic money in a manner very similar to cash.
[0035] According to yet another main aspect of the present invention, there is provided an electronic money remittance method for remittance of electronic money from a first user to a second user, using a first user terminal owned by a first user, a second user terminal owned by a second user, and an electronic money management server capable of communicating with the first user terminal and the second user terminal via a communication line and storing the electronic money of the first user and the electronic money of the second user, respectively, wherein the electronic money management server and the terminal of the first user store first certification information associated with information of the first user and / or information of the first user terminal, and the electronic money management server and the second user terminal store second certification information associated with information of the second user and / or information of the second user terminal, the method comprising the steps of: the first user terminal receiving second terminal information, which is at least a part of the second certification information, and an amount of electronic money to be received by the second user from the first user via short-range wireless communication or the communication line, from the second user terminal via the short-range wireless communication or the communication line, and a first receiving step of storing the received amount in a memory of the user terminal in the memory of the user terminal; a second receiving step of the electronic money management server receiving, after the first receiving step, from the first user terminal, first terminal information which is at least a part of the certification information of the first user terminal, the second terminal information, an instruction to remit electronic money from the first user terminal to the second user, and the received amount; an authentication step of authenticating the first user terminal and the second user terminal by at least determining whether the first terminal information received from the first user terminal corresponds to the first certification information stored in the electronic money management server and determining whether the second terminal information corresponds to the second certification information stored in the electronic money management server; a settlement determination step of determining, after the authentication step, at least whether the received amount is within the remaining balance of the electronic money of the first user stored in the electronic money management server;and a settlement step of increasing the balance of electronic money of the second user in the electronic money management server by the amount of the received amount.
[0036] Thus, in the present invention, the first user terminal receives the second terminal information, which is at least a part of the second certification information, from the second user terminal in the first receiving step. After the first user terminal receives the certification information from the second user terminal in this way, the electronic money management server receives the certification information of the second user terminal from the first user terminal in the second receiving step, and judges whether the certification information of the first user terminal and the certification information of the second user terminal received from the first user terminal correspond to the certification information of the first and second user terminals stored in the electronic money management server. In other words, since the certification information of the second user terminal is sent from the first user terminal to the electronic money management server, the two terminals that are about to carry out the transaction are identified at this point, and further, the electronic money management server compares the certification information of both parties of the transaction sent from the first user terminal. This allows the electronic money management server to reliably authenticate the terminal that is about to send or receive electronic money.
[0037] Here, the first certification information held by the first user terminal is unique information held only by the first user terminal and the electronic money management server, and the second certification information held by the second user terminal is unique information held only by the second user terminal and the electronic money management server. At least a part of the second certification information is transmitted by the first user terminal to the electronic money management server. The electronic money management server then authenticates the terminal attempting to transmit or receive electronic money by accepting the certification information of both parties in the transaction from the first user terminal. For this reason, even if the second user terminal illegally obtains the certification information of the first user terminal and attempts to obtain the electronic money held by the first user by some means, the first user will not be able to remit electronic money to the second user unless the certification information of both parties in the transaction is transmitted from the first user terminal to the electronic money management server.
[0038] Furthermore, in the present invention, since each user's electronic money is stored in an electronic money management server, even if, for example, the first user terminal is lost and cannot be recovered, the first user's electronic money will not be reduced by that single incident.
[0039] Furthermore, in the present invention, the second user terminal transmits the certification information to the first user terminal, and the instructions to remit and receive electronic money are transmitted, so that the first user can directly transmit electronic money to the second user while ensuring the security of the electronic money remittance. This makes it possible to exchange electronic money in a manner very similar to cash. Effect of the Invention
[0040] According to the present invention, electronic money can be handled in a manner very similar to cash, and electronic money is not lost even if a terminal for handling electronic money is lost or stolen.
[0041] Furthermore, other features and remarkable effects of the present invention will be understood by those skilled in the art by referring to the embodiments and drawings described in the following section of the best mode for carrying out the invention. [Brief description of the drawings]
[0042] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of an electronic money transfer system according to an embodiment of the present invention. [Diagram 2] A diagram showing the schematic configuration of terminal A. [Diagram 3] A diagram showing the schematic configuration of terminal B. [Figure 4] A diagram showing the schematic configuration of an electronic money management server. [Diagram 5] Example of customer contract master data [Figure 6] Example of account data [Figure 7] Flowchart showing the processing in terminal A, terminal B, and electronic money management server [Figure 8] Flowchart showing the processing in terminal A, terminal B, and electronic money management server [Figure 9] Diagram showing the outline of electronic certificates [Figure 10] Flowchart showing the processing in terminal A and electronic money management server [Figure 11] Example of display screen of display device [Figure 12] Example of display screen of display device [Figure 13] Flowchart showing the processing in terminal A, terminal B and electronic money management server [Figure 14] Example of display screen of display device Reference number: Y11A017 Patent application 2011-233596 (Proof) Submission date: October 25, 2011 9 [Figure 15] Flowchart showing the processing in terminal A, terminal B and electronic money management server [Figure 16] Example of display screen of display device [Figure 17] Flowchart showing the processing in terminal A, terminal B and electronic money management server [Figure 18] Example of display screen of display device [Figure 19] Example of display screen of display device [Figure 20] Example of display screen of display device [Figure 21] Example of display screen of display device [Figure 22] Example of display screen of display device [Figure 23] Example of display screen of display device [Figure 24] A diagram showing the schematic configuration of terminal A. [Diagram 25] A diagram showing the schematic configuration of an electronic money management server. [Figure 26] Example of display screen of display device [Figure 27] Example of display screen of display device [Figure 28] Example of a rewards table [Figure 29] Flowchart showing the processing in terminal A, terminal B, and electronic money management server [Diagram 30]Flowchart showing the processing in terminal A, terminal B, and electronic money management server DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0043] An electronic money remittance system according to an embodiment of the present invention will now be described with reference to the drawings.
[0044] FIG. 1 is a diagram showing a schematic configuration of an electronic money remittance system according to a first embodiment of the present invention. This system has, for example, a terminal A owned by a user A (first user) who is a buyer, a terminal B owned by a store as a seller and a user B (second user) who is the owner of the store, and an electronic money management server (hereinafter simply referred to as a management server) 300 that can communicate with each of the terminals A and B via a communication line such as the Internet or a mobile communication network. The terminals A and B may be mobile phones with functions equivalent to a personal digital assistant (PDA) or a personal computer (PC), desktop or laptop PCs, computer devices such as POS terminals, or other known computer devices. In this embodiment, the terminal A is a mobile phone with functions equivalent to a PC, and the terminal B is a POS terminal. Note that illustrations and explanations of well-known configurations such as a firewall and a Web server are omitted.
[0045] Fig. 2 is a diagram showing a schematic configuration of a terminal A (a mobile phone having functions equivalent to a PC) according to the present embodiment. As shown in Fig. 2, the terminal A has a CPU 110, a RAM 120, a display device 130 such as a liquid crystal display, a communication unit 140 having a communication interface including a communication antenna and a communication protocol stack for communication using a mobile communication network or an Internet network, a short-range wireless communication unit 150 having a communication interface including an antenna for short-range wireless communication (Near Field Communication [NFC]) and a communication protocol stack for short-range wireless communication, a well-known touch panel type input device 160 that accepts input by a user touching the display device 130 with a finger, a certificate storage unit 171 for storing an electronic certificate, an access key storage unit 172 for storing an access key, a card information storage unit 173, an application storage unit 174, and a program storage unit 180 for storing various programs.
[0046] This terminal A has, in a program storage unit 180, an electronic certificate exchange processing unit 181, which causes terminal A to perform a predetermined operation, an electronic certificate information embedding processing unit 182, an electronic certificate information transmission processing unit 183, an access key request processing unit 184, a money transfer request processing unit 185, and a card design transmission / reception processing unit 186. These functions will be described later along with examples of processing performed by terminal A, terminal B, management server 300, etc. (see Figs. 7, 8, 10, 13, etc.).
[0047] Fig. 3 is a diagram showing a schematic configuration of a terminal B (POS terminal) of this embodiment. As shown in Fig. 3, the terminal B has a CPU 210, a RAM 220, a display device 230 such as a liquid crystal display, a communication unit 240 having a communication interface including a communication protocol stack for communication using a connector or an Internet network, a reader / writer (near field communication unit) 250 having a communication interface including an antenna for near field communication (NFC) and a communication protocol stack for near field communication, an input device 260 consisting of a plurality of buttons, a certificate storage unit 271 for storing an electronic certificate, an access key storage unit 272 for storing an access key, a card information storage unit 273, an application storage unit 274, and a program storage unit 280 for storing various programs.
[0048] This terminal B has, in the program storage unit 280, an electronic certificate exchange processing unit 281, an electronic certificate information embedding processing unit 282, an electronic certificate information transmission processing unit 283, an access key request processing unit 284, a money transfer request processing unit 285, and a card design transmission / reception processing unit 286, each of which causes terminal B to perform a predetermined operation. These functions will be described later along with examples of processing performed by terminal A, terminal B, management server 300, etc. (see Figs. 7, 8, 10, 13, etc.). Also, components in terminal B with the same names as those in terminal A have functions equivalent to those of the same components in terminal A.
[0049] 4 is a diagram showing a schematic configuration of management server 300 of this embodiment. This management server 300 has a CPU 310, RAM 320, a display device 330 such as a liquid crystal display, a communication unit 340 having a communication interface including a communication protocol stack for communication using a connector or the Internet network, a customer master storage unit 350, an account data storage unit 360 for storing data on electronic money accounts, an application storage unit 370 for storing applications for members, and a program storage unit 380 for storing various programs.
[0050] The customer master storage unit 350 of the management server 300 has customer contract master 351 as shown in Fig. 5, which associates customer information in the management server 300 (such as name, appellation, nickname, email address, and answer to security question) with login ID, password, electronic certificate, account number of electronic money account, etc. The account data storage unit 360 stores account balance and remittance / received history for each account number as shown in Fig. 6.
[0051] The management server 300 has, in a program storage unit 380, a member registration processing unit 381, which causes the management server 300 to perform a predetermined operation, a member screen display processing unit 382, an electronic certificate issuance processing unit 383, an electronic money card issuance processing unit 384, an electronic certificate information reception processing unit 385, an access key issuance processing unit 386, a money transfer request reception processing unit 387, and a money transfer processing unit 388. These functions will be described later along with examples of processing performed by terminal A, terminal B, management server 300, etc. (see Figs. 7, 8, 10, 13, etc.).
[0052] First, along with an example of the processing performed by terminal A and management server 300 (see FIG. 7), a processing will be described in which user A having terminal A performs membership registration required for purchasing electronic money on management server 300 and sending and receiving electronic money. User A may be an individual or an organization.
[0053] First, when the terminal A requests the management server 300 to download an application for electronic money transactions (step S1), the management server 300 downloads the application to the terminal A in response (step S2). Then, when the application is started on the terminal A, a screen for confirming the intention to register as a member is displayed on the display device 130. When the user A performs an operation on the terminal A indicating the intention to register as a member, a request for member registration is sent from the terminal A to the management server 300 (step S3), and in response to this, the member registration processing unit 381 of the management server 300 displays a member registration screen on the display device 130 of the terminal A (step S4). In this member registration screen that is displayed first, the user A is requested to input an email address. Next, when the user A inputs an email address on the member registration screen and transmits it (step S5), in response to this, the member registration processing unit 381 of the management server 300 transmits the URL of the main registration screen to the email address of the user A (step S6). It is also possible to configure the steps S4 and S5 to transmit the phone number of the terminal A (mobile phone) instead of the email address.
[0054] Next, when user A operates terminal A to send a display request for the screen of the URL from terminal A (step S7), the member registration processing unit 381 of management server 300 displays a main registration screen on the display device 130 of terminal A (step S8). Next, when user A enters a nickname, name, title, password, answer to security question, etc. on the main registration screen and sends it (step S9), in response to this, the member registration processing unit 381 of management server 300 sends a login ID to the email address of user A (step S10). By using the login ID, password, etc., user A can log in to the member screen displayed by the member screen display processing unit 382.
[0055] As described above, in the process of registering user A as a member, management server 300 stores information about user A in customer master 351 of customer master storage unit 350 (step S11) (see FIG. 5).
[0056] Also, when user B having terminal B registers as a member required for purchasing electronic money on the management server 300 or sending and receiving electronic money, as shown in FIG. 7, processing equivalent to that described above for user A (steps S21 to S31) is performed on terminal B and management server 300.
[0057] Next, a process in which terminal A obtains a digital certificate required for sending and receiving electronic money on management server 300 will be described along with an example of the process performed by terminal A and management server 300 (see FIG. 8).
[0058] First, the member screen display processing unit 382 of the management server 300 displays a screen requesting a login ID and a password on the terminal A, and when the login ID and the password are transmitted from the terminal A to the management server 300 (step S41), in response to this, the member screen display processing unit 382 causes the display unit 130 of the terminal A to display the member screen after login (step S42). A button for requesting issuance of an electronic certificate is arranged in this member screen, and when the user A operates the terminal A to request issuance of an electronic certificate, the terminal A transmits the request for issuance of an electronic certificate to the management server 300 (step S43). In addition, together with or after the request for issuance of the electronic certificate, the terminal A transmits individual information of the terminal A to the management server 300 (step S44). Here, the user A logs in to the member screen using his / her own login ID and password on the terminal A, and transmits the request for issuance of an electronic certificate in this state, so that the individual information is associated with the login ID, password, etc. of the user A and stored in the customer contract master 351 (see FIG. 5). As the individual information, the manufacturing ID of terminal A can be used, but other information unique to terminal A can also be used.
[0059] Next, the management server 300 creates a first electronic certificate for user A by the electronic certificate issuance processing unit 383, associates the first electronic certificate with terminal A, and stores it in the customer master storage unit 350 (step S45). Here, the first electronic certificate created by the electronic certificate issuance processing unit 383 has a digital signature, a public key, etc., as shown in FIG. 9. The electronic certificate issuance processing unit 383 of the management server 300 also creates a private key corresponding to the created first electronic certificate at the same time, and associates the private key with the first electronic certificate and stores it in the customer master storage unit 350. In this embodiment, the electronic certificate is created by the management server 300, but it is also possible to request an external electronic certificate issuer to create the electronic certificate.
[0060] Next, the electronic certificate issuance processing unit 383 of the management server 300 transmits the first electronic certificate to terminal A (step S46), and terminal A stores the received first electronic certificate in the certificate storage unit 171 of terminal A (step S47).
[0061] Also, when terminal B obtains an electronic certificate necessary for sending and receiving electronic money on management server 300, the same processes (steps S51 to S57) as those described above for terminal A are performed in terminal B and management server 300, as shown in Fig. 8. In this embodiment, a second electronic certificate and its private key are created for terminal B. Note that the private key of the first electronic certificate is uniquely capable of decrypting the digital signature of the first electronic certificate, and the private key of the second electronic certificate is uniquely capable of decrypting the digital signature of the second electronic certificate.
[0062] Next, a process in which user A purchases an electronic money card using terminal A will be described along with an example of a process (see FIG. 10) performed by terminal A and management server 300. This process can also be performed by terminal B.
[0063] First, a screen requesting a login ID and password is displayed on terminal A by the member screen display processing unit 382 of the management server 300, and when the login ID and password are transmitted from terminal A to the management server 300 (step S61), in response to this, the member screen display processing unit 382 of the management server 300 displays a member screen after login on the display unit 130 of terminal A (step S62). A button for purchasing an electronic money card is arranged in this member screen, and when user A performs an operation on terminal A to request the purchase of an electronic money card, a purchase request for an electronic money card is transmitted from terminal A to the management server 300 (step S63). Next, the management server 300 causes the electronic money card issuance processing unit 384 to display an electronic money card purchase screen (see FIG. 11) on the display device 130 of terminal A (step S64). When user A enters information into each item as shown in FIG. 11 and presses the purchase button, the card purchase information is transmitted from terminal A to the management server 300 (step S65). In this embodiment, the card design (design) selected in Fig. 11 allows the user to set his / her favorite image as the card design. In this case, user A selects an image he / she wants to use as the card design from among those in terminal A, and the selected image is sent to management server 300 in step S65. Thereafter, electronic money card issuance processing unit 384 of management server 300 displays the necessary screen on display device 130 of terminal A as necessary, and when payment of the fee for the purchased electronic money card and input of all information are completed, the electronic money card is purchased.
[0064] Next, the electronic money card issuing processing unit 384 of the management server 300 sets the account number (card number), security number, etc. of the electronic money account corresponding to the electronic money card purchased by the user A (step S66), stores the account data of the electronic money account in the account data storage unit 360 (step S67), and stores the account number in the customer master as shown in FIG. 5 (step S68). In this embodiment, the same number is used for the account number and the card number. The account data is, for example, as shown in FIG. 6, and stores the history of remittances and receipts, the remaining balance, etc. Note that each user can create multiple electronic money accounts in the management server 300, and in this case, an account number (card number) is set for each electronic money account. In other words, each user can own multiple electronic money cards, and the management server 300 manages each electronic money card by linking it to its account number (card number).
[0065] Furthermore, the management server 300 transmits card information such as the design of the card, the amount of the purchased card, the account number (card number) and the like to the terminal A through the electronic money card issuing processing unit 384 (step S69). Meanwhile, the terminal A stores the received card information in the card information storage unit 173 (step S70).
[0066] In terminal A, the application can display the card design, the balance corresponding to the account number (card number), the account number (card number), and the security code on display device 130 as shown in Fig. 12. Masking 400 is displayed on part of the card number and part of the security code, and part of the card number and part of the security code are hidden by masking 400. When a finger is touched to a position on display screen 130 corresponding to masking 400, masking 400 disappears, and the hidden part of the card number and part of the security code can be seen. If terminal A is a PC or a POS terminal, it is also possible to configure it so that masking 400 disappears when the pointer is positioned on masking 400.
[0067] User B can also purchase an electronic money card using terminal B in the same manner as user A purchases an electronic money card using terminal A.
[0068] Next, we will explain the process when user A (buyer) purchases a product from user B (seller such as a store) and pays for it with electronic money, using an example of the process performed by terminal A, terminal B, and management server 300 (see Figure 13).
[0069] First, user A decides to purchase product X and takes it to user B's terminal B (POS terminal). Terminal B is equipped with a barcode reader and the like, and reads the barcode attached to product X with the barcode reader. As a result, the price of product X, 300 yen, is displayed on the display device 230 of the POS terminal. When user A checks the price by looking at the display of terminal B and decides to pay, he uses terminal A to access and log in to a member's screen provided by member's screen display processing unit 382 of management server 300. Then, he causes the display device 130 to display a payment screen such as that shown in FIG. 14, for example, and brings terminal A close to the reader / writer 250 of terminal B and touches the Pay button in FIG. 14 with his finger. As a result, the following steps S101 to S123 are performed, and electronic money is transferred from user A to user B.
[0070] Specifically, first, when terminal A is brought close to reader / writer 250 of terminal B and Pay button 410 in FIG. 14 is touched with a finger, terminal B transmits the digital signature in the second electronic certificate to terminal A via short-distance wireless communication by electronic certificate exchange processing unit 281, and terminal A receives the digital signature of the second electronic certificate transmitted from terminal B by electronic certificate exchange processing unit 181 (step S101). Then, terminal A stores the received digital signature in the certificate storage unit or other part of the memory of terminal A (step S102). Meanwhile, terminal A transmits the digital signature in the first electronic certificate to terminal B via short-distance wireless communication by electronic certificate exchange processing unit 181, and terminal B receives the digital signature of the first electronic certificate transmitted from terminal A by electronic certificate exchange processing unit 281 (step S103). Then, terminal B stores the received digital signature in the certificate storage unit or other part of the memory of terminal B (step S104). Either step S101 or step S103 may be performed first, or they may be performed simultaneously. The short-distance wireless communication is performed via the short-distance wireless communication unit 150 of terminal A and the reader / writer 250 of terminal B. The short-distance wireless communication unit 150 and the reader / writer 250 are capable of short-distance wireless communication when the distance between them is several centimeters to several tens of centimeters, and communication is not possible at a distance greater than that. Examples of such short-distance wireless communication technology include Type A and B of ISO / IEC14443, or Felica (registered trademark) of ISO / IEC18092. Although this embodiment uses such short-distance wireless communication, it is of course possible to use short-distance wireless communication that communicates at a distance greater than that.
[0071] Next, terminal A replaces the digital signature of its own first electronic certificate with the digital signature of the received second electronic certificate by using electronic certificate embedding processing unit 182 to create a first electronic certificate with the replaced digital signature, and stores it in certificate storage unit 171 (step S105). Meanwhile, terminal B replaces the digital signature of its own second electronic certificate with the digital signature of the received first electronic certificate to create a second electronic certificate with the replaced digital signature, and stores it in certificate storage unit 271 (step S106).
[0072] Next, terminal A transmits the first electronic certificate with the replaced digital signature to management server 300 by digital certificate information transmission processing unit 183 (step S107), and terminal B transmits the second electronic certificate with the replaced digital signature to management server 300 by digital certificate information transmission processing unit 283 (step S108). At this time, the transmission data from terminal A includes individual information of terminal A, and the transmission data from terminal B includes individual information of terminal B.
[0073] Next, the management server 300 receives the first and second electronic certificates with the replaced digital signatures from terminals A and B via the electronic certificate information reception processing unit 385 (step S109). Then, the management server 300 decrypts the first electronic certificate with the replaced digital signature and the digital signature of the second electronic certificate included therein using the corresponding private key stored in the customer master storage unit 350, and also decrypts the second electronic certificate with the replaced digital signature and the digital signature of the first electronic certificate included therein using the corresponding private key stored in the customer master storage unit 350 (step S110).
[0074] Next, the management server 300, by using the electronic certificate information reception processing unit 385, determines (1) whether or not the digital signature of the decrypted first electronic certificate corresponds to the digital signature of the first electronic certificate stored in the customer master storage unit 350, and (2) whether or not the digital signature of the decrypted second electronic certificate corresponds to the digital signature of the second electronic certificate stored in the customer master storage unit 350 (step S111). In addition, the management server 300, by using the electronic certificate information reception processing unit 385, determines (3) whether or not the sender of the digital signature of the second electronic certificate is terminal A (terminal corresponding to the first electronic certificate), and (4) whether or not the sender of the digital signature of the first electronic certificate is terminal B (terminal corresponding to the second electronic certificate) (step S112). Here, the determination in step S112 can be made by comparing the parts of the first and second electronic certificates in which the digital signatures have been replaced, other than the digital signatures, with the parts of the first and second electronic certificates stored in the customer master storage unit 350, other than the digital signatures. Alternatively, the determination in step S112 can be made by comparing the individual information included in the transmission data from each of the terminals A and B with the individual information stored in the customer master 351 in the customer master storage unit 350. It is also possible to make the determination in step S112 using other methods that can determine (3) and (4) above. That is, in step S112, it is only necessary to determine whether or not the electronic certificate information of the own terminal (terminal A) has been sent from another terminal (terminal B) to the management server 300, and whether or not the electronic certificate information of the other terminal (terminal B) has been sent from the own terminal (terminal A) to the management server 300.
[0075] Next, when it is determined that all of the above (1) to (4) are met, the electronic certificate information reception processing unit 385 transmits the determination result to each of terminals A and B (steps S113, S114). Next, when a request for an access key is transmitted from terminal A to the management server 300 by the access key request processing unit 184 (step S115), the management server 300 transmits a first access key to terminal A by the access key issuance processing unit 386 (step S116), and terminal A stores the first access key in the access key storage unit 172. The access key issuance processing unit 386 issues a different unique access key each time there is a request for access key issuance. On the other hand, when a request for an access key is sent from terminal B to the management server 300 by the access key request processing unit 284 (step S117), the management server 300 sends a second access key to terminal B by the access key issuance processing unit 386 (step S118), and terminal B stores the second access key in the access key storage unit 272. In this embodiment, the issuance of the access key in steps S116 and S118 is not performed unless it is determined in steps S111 and S112 that the above (1) to (4) correspond. In addition, the access key issuance processing unit 386 issues the first access key and the second access key so that the money transfer request acceptance processing unit 387 recognizes that the first access key corresponds to the second access key.
[0076] Next, terminal A uses the money transfer request processor 185 to transmit the first access key, a remittance instruction to user B, the owner of terminal B, and the account number of the electronic money account to which the remittance is to be made (the card number of the electronic money card displayed on display device 130) to the management server 300 (step S119), and the management server 300 receives these via the money transfer request acceptance processor 387. Meanwhile, terminal B uses the money transfer request processor 285 to transmit the second access key, 300 yen, the amount to be received from user A, the owner of terminal A, and a receipt instruction to the management server 300 (step S120), and the management server 300 receives these via the money transfer request acceptance processor 387.
[0077] Next, the management server 300, through the money transfer request reception processing unit 387, determines whether the access key received from terminal A corresponds to the access key received from terminal B (step S121). The management server 300 also determines through the money transfer request reception processing unit 387 whether the received amount is within the account balance of user A stored in the account data storage unit 360 of the management server 300, more specifically, whether it is within the balance of the account (hereinafter referred to as account A) corresponding to the card number (account number) displayed on the display screen 130 of terminal A (step S122).
[0078] Next, if it is determined in step S121 that the access key corresponds and that the amount is within the balance in step S122, the management server 300, through the sending / receiving money processing unit 388, reduces the remaining balance of the account data of user A's account a stored in the account data storage unit 360 by the amount of the received amount, and increases the remaining balance of the account data of user B's account (hereinafter referred to as account b) stored in the account data storage unit 360 by the amount of the received amount (step S123). Next, the management server 300 invalidates the first and second access keys, preventing transactions using these access keys.
[0079] Here, when steps S101 to S123 are performed, there may be cases where no electronic money account of user B is set in the management server 300. In this case, user B may be prompted to create an electronic money account at an appropriate timing. For example, when it is determined in steps S121 and S122 that the access key corresponds and the balance is within the limit, user B may be prompted to create an electronic money account in terminal B. Specifically, a screen in FIG. 11 that allows only the card type and card name to be selected is displayed on terminal B, and a message for confirming whether or not to set an electronic money card with a balance of 0 yen is displayed on terminal B of user B. When user B creates an electronic money card according to such processing, an electronic money account into which the received amount is transferred is set in the management server 300 in step S123.
[0080] In this embodiment, in step S101, terminal A as the first user terminal receives at least a part of the information of the second electronic certificate from terminal B as the second user terminal, and in step S103, terminal B receives at least a part of the information of the first electronic certificate from terminal A. After terminal A and terminal B exchange at least a part of the electronic certificate in this way, the management server 300 receives at least a part of the information of the electronic certificate of each of the transaction partners from terminals A and B in steps S107 and S108, and judges whether the part of the information of the received electronic certificate corresponds to the information of the electronic certificate stored in the management server 300. That is, the electronic certificate information of the own terminal is sent from another terminal to the management server 300, and the electronic certificate information of the other terminal is sent from the own terminal to the management server 300, so that at this point, the two terminals that are about to carry out the transaction are identified, and the electronic certificates sent by each are compared by the management server 300. This allows the management server 300 to reliably authenticate terminals A and B that are about to send and receive electronic money.
[0081] Here, the first electronic certificate held by terminal A is unique information held only by terminal A and the management server 300, and the second electronic certificate held by terminal B is unique information held only by terminal B and the management server 300. At least a part of the information of the first electronic certificate is transmitted to the management server 300 by terminal B, and at least a part of the information of the second electronic certificate is transmitted to the management server 300 by terminal A. The management server 300 accepts at least a part of the information of the electronic certificates from both terminals A and B, thereby authenticating the terminal that is about to send or receive electronic money. For this reason, even if terminal B illegally obtains electronic certificate information of terminal A and tries to obtain electronic money held by user A by some means, the remittance of electronic money from user A to user B cannot be made unless terminal A transmits its own electronic certificate information to the management server 300.
[0082] In this embodiment, after authenticating two terminals A and B that are about to send and receive electronic money as described above, the management server 300 transmits an access key to each of terminals A and B, and receives a remittance instruction, an instruction to receive electronic money, and the like transmitted together with the access key from each of terminals A and B. The management server 300 also determines whether the access keys received from each of terminals A and B are compatible, and then transmits electronic money from user A to user B within the management server 300. In this way, the access keys are issued and a determination is made as to whether the access keys are compatible, so that the remittance of electronic money from user A to user B can be performed more safely.
[0083] Furthermore, in this embodiment, the electronic money of each user A and B is stored in the management server 300, so even if, for example, terminal A is lost and cannot be retrieved, user A's electronic money will not be reduced by that single event.
[0084] Furthermore, in this embodiment, by terminal A and terminal B exchanging the contents of their respective electronic certificates and sending instructions to remit and receive electronic money together with an access key issued by management server 300, it is possible to send electronic money directly from user A to user B while ensuring the security of the electronic money remittance. This makes it possible to exchange electronic money in a manner very similar to cash.
[0085] In this embodiment, terminal A and terminal B exchange portions of each other's electronic certificates, but it is also possible to transmit the first electronic certificate itself from terminal A to terminal B in step S103, and transmit the second electronic certificate itself from terminal B to terminal A in step S101.
[0086] Here, for example, it is conceivable to embed IC chips in two mobile terminals that carry out a transaction, and to have a security module certified by a specified certification organization in the IC chip of each mobile terminal, and to authenticate the two terminals that carry out the transaction based on the contents of the security module of each terminal. However, in this case, if the specifications of the security modules of the two terminals are different, each terminal cannot decrypt the other's security module, which is likely to cause inconvenience such as making it impossible to carry out a transaction. In contrast, in this embodiment, the management server 300 issues electronic certificates to each terminal A and B, and although the management server 300 has a simple configuration in which the issued electronic certificates and their private keys are owned by the management server 300, it is possible to realize a secure transaction as described above, and therefore it is more useful in the real world than the case of using a security module.
[0087] In this embodiment, after the access keys are requested from both terminal A and terminal B in steps S115 and S117, an access key is issued to each of terminals A and B. In this manner, a transaction cannot be carried out using only one of terminals A and B, which is extremely advantageous in ensuring the security of electronic money remittance.
[0088] Furthermore, in this embodiment, only the management server 300 has the private keys of the first and second electronic certificates. Therefore, even if terminal A receives a part of the second electronic certificate from terminal B, terminal A cannot decrypt that part of the electronic certificate. Furthermore, even if terminal B receives a part of the first electronic certificate from terminal A, terminal B cannot decrypt that part of the electronic certificate. This ensures the security of electronic money remittance. Note that, in this embodiment, the management server 300 has private keys linked to the first and second electronic certificates, but it is also possible to include private keys in the first and second electronic certificates held by the management server 300.
[0089] Furthermore, in this embodiment, management server 300 can store user A's electronic money in association with multiple electronic money account numbers. Furthermore, in step S119, terminal A transmits the account number of the electronic money account from which remittance is to be made to management server 300. In this way, user A can own multiple electronic money accounts, and can select which electronic money account to remit from when making a remittance. This allows user A to determine the purpose of each electronic money account, and to remit in accordance with that purpose.
[0090] In this embodiment, in step S112, it is determined whether (3) the sender of the digital signature of the second electronic certificate is terminal A (terminal compatible with the first electronic certificate) and (4) the sender of the digital signature of the first electronic certificate is terminal B (terminal compatible with the second electronic certificate). Here, in step S105, terminal A replaces the digital signature of its own first electronic certificate with the digital signature of the received second electronic certificate, and in step S106, terminal B replaces the digital signature of its own second electronic certificate with the digital signature of the received first electronic certificate. Therefore, the determination in step S112 can be made by comparing the parts of the first and second electronic certificates with the replaced digital signatures other than the digital signatures with the parts of the first and second electronic certificates stored in the customer master storage unit 350 other than the digital signatures, which is efficient and extremely advantageous in ensuring the security of electronic money remittance.
[0091] Furthermore, after step S123, the management server 300 invalidates the first and second access keys, so that further transactions using the first and second access keys cannot be performed. In this way, the present embodiment has a configuration that is extremely advantageous in ensuring the security of electronic money remittance.
[0092] In this embodiment, short-distance wireless communication is possible when the short-distance wireless communication unit 150 and the reader / writer 250 are at a distance of several centimeters to several tens of centimeters from each other, and communication is not possible at a distance greater than that. Therefore, when terminal A and terminal B attempt to carry out a transaction, an error is unlikely to occur when exchanging electronic certificates with other terminals, which is extremely advantageous in ensuring the security of the transaction.
[0093] In this embodiment, the terminal B is a POS terminal, but the terminal B can be a mobile phone similar to the terminal A. In this case, the reader / writer 250 of the terminal B is a short-distance wireless communication unit, and the input device 260 is a touch panel type input device. Even if the terminal B is configured as a mobile phone in this way, it is possible to buy and sell the product X using the processes in steps S101 to S123. Moreover, if the terminals A and B are configured as mobile phones, the user A and the user B can buy and sell the product X anytime and anywhere. For example, if the product X is a fruit harvested in the farm owned by the user B, or if the user A and the user B happen to meet on the street and want to buy and sell the item Y, the user A can pay the electronic money to the user B.
[0094] For example, by configuring the management server 300 or the application to allow user B to input the sales price of product X or item Y (the amount to be received from user A) on the display device 230 of terminal B, terminal B will function in the same manner as terminal B as the POS terminal. Then, by bringing the short-range wireless communication unit 150 of terminal A and the short-range wireless communication unit 250 of terminal B close to each other and user A pressing the Pay button in Fig. 14, the processing of steps S101 to S123 is performed.
[0095] Furthermore, not only for buying and selling product X or item Y, but also when user B wishes to receive electronic money from user A, the amount that user B wishes to receive from user A can be input into display device 230 of terminal B of user B, so that user B can receive electronic money by the processing of steps S101 to S123.
[0096] In this embodiment, the management server 300 stores the electronic money of user A and user B as linked to the electronic money card. In contrast, when something like an electronic money wallet or an electronic money folder is set in the management server 300 as the electronic money accounts of user A and user B, the management server 300 can store the electronic money of user A and user B by linking it to the electronic money wallet or electronic money folder.
[0097] In this embodiment, step S101 is started by operating the Pay button displayed on the display device 130 of terminal A. Alternatively, it is also possible to configure so that step S101 is started automatically when the short-range wireless communication unit 150 of terminal A and the reader / writer 250 of terminal B are brought closer than a few centimeters or a dozen centimeters, or to configure so that step S101 is started by some other trigger.
[0098] In this embodiment, in steps S101 and S103, terminals A and B exchange parts of their electronic certificates via short-range wireless communication. However, in steps S101 and S103, terminals A and B can also exchange parts of their electronic certificates via a mobile communication network or the Internet.
[0099] In this embodiment, after it is determined in steps S111 and S112 that all of the above (1) to (4) are met, an access key is used in steps S113 to S121 to make the transaction safer. On the other hand, even if steps S113 to S118 are omitted, the transmission of the access key is omitted in steps S119 and S120, and the determination in step S121 is omitted, it is possible to transfer electronic money from user A to user B. In other words, since the access key is used to make the transaction safer, it can be omitted in the case of simple transactions. Even if the access key is not used, the terminal performing the transaction can be reliably authenticated in steps S111 and S112, so that electronic money can be safely transferred from user A to user B.
[0100] Furthermore, even if step S111 is omitted, it is possible to transfer electronic money from user A to user B. This is because the terminal to perform the transaction can be determined even in step S112 alone.
[0101] The electronic money remittance system according to the second embodiment of the present invention will be described below. This system has a configuration basically similar to that of the first embodiment, but terminal B is a mobile phone similar to terminal A. As a result, the reader / writer 250 of terminal B is a short-range wireless communication unit, and the input device 260 is also a touch panel input device.
[0102] In this system, a case where user A (sender) remits electronic money to user B (receiver) will be described along with an example of processing performed by terminal A, terminal B, and management server 300 (see FIG. 15). Cases where user A (sender) remits electronic money to user B (receiver) include cases where user A gives pocket money to user B or lends electronic money. The following describes a case where user A lends 300 yen to user B. In addition, in the case of this embodiment, a screen such as that shown in FIG. 16 is displayed on display device 130 of terminal A of user A by management server 300 or the application, and user A is configured to be able to input the amount of money he or she wishes to remit on this screen. The following description will be given assuming that the amount has already been entered.
[0103] First, when the short-range wireless communication units 150 and 250 of terminal A and terminal B are brought close to each other and, for example, the Send button 420 in Fig. 16 is touched with a finger, steps S201 to S223 in Fig. 15 are performed. Here, steps S201 to S218 are the same as steps S101 to S118 in the first embodiment, and therefore a description thereof will be omitted.
[0104] After step 218, terminal A transmits to the management server 300, by means of the money transfer request processing unit 185, the first access key, a remittance instruction to user B who is the owner of terminal B, the account number of the electronic money account to which the remittance should be made (the card number of the electronic money card displayed on the display device 130), and the remittance amount of 300 yen (step S219), and the management server 300 receives these by means of the money transfer request reception processing unit 387. Meanwhile, terminal B transmits to the management server 300, by means of the money transfer request processing unit 285, the second access key and a receipt instruction (step S220), and the management server 300 receives these by means of the money transfer request reception processing unit 387. Here, terminal B can also transmit to the management server 300 the account number of the electronic money account to which the remittance should be deposited.
[0105] Next, the management server 300, through the money transfer request acceptance processor 387, determines whether the access key received from terminal A corresponds to the access key received from terminal B (step S221). The management server 300 also determines through the money transfer request acceptance processor 387 whether the remittance amount is within the account balance of user A stored in the account data storage unit 360 of the management server 300, more specifically, whether it is within the balance of the account (hereinafter referred to as account A) associated with the card number (account number) displayed on the display screen 130 of terminal A (step S222).
[0106] Next, if it is determined in step S221 that the access key corresponds and that the amount is within the balance in step S222, the management server 300, through the sending / receiving money processing unit 388, reduces the remaining balance of the account data of account a of user A stored in the account data storage unit 360 by the amount of the remittance, and increases the remaining balance of the account data of account (hereinafter referred to as account b) of user B stored in the account data storage unit 360 by the amount of the remittance (step S223). Next, the management server 300 invalidates the first and second access keys, disabling transactions using these access keys.
[0107] With this configuration, the present embodiment also achieves the same effects as those described in the first embodiment, and it is also possible to make the various modifications described above in relation to the first embodiment.
[0108] The electronic money remittance system according to the third embodiment of the present invention will be described below. This system basically has the same configuration as the second embodiment.
[0109] In this system, an example of the processing performed by terminal A, terminal B and management server 300 when user A (sender) sends user B (recipient) an electronic money card owned by user A as a gift (see FIG. 17) will be described below. A case in which user A sends an electronic money card worth 3000 yen to user B will be described below. In addition, in the case of this embodiment, the management server 300 and the application are configured to display a screen as shown in FIG. 18 on the display device 130 of terminal A of user A, and user A is configured to instruct the transmission of the displayed electronic money card on this screen.
[0110] First, when the short-range wireless communication units 150 and 250 of terminal A and terminal B are brought close to each other and the Send button 430 in Fig. 18 is touched with a finger, the management server 300 or the application causes the display device 230 of terminal B to display amount information of the electronic money card displayed on terminal A and a button for selecting whether to receive or not receive the electronic money card (see Fig. 19). In this state, when the Yes button 431 on the display device 230 of terminal B is touched with a finger, steps S301 to S324 in Fig. 17 are performed. Here, steps S301 to S318 are the same as steps S201 to S218 in the second embodiment, and therefore a description thereof will be omitted.
[0111] After step S318, terminal A transmits to the management server 300, by means of the money transfer request processor 185, the first access key, a money transfer instruction to user B who is the owner of terminal B, the account number of the electronic money account to which the transfer is to be made (the card number of the electronic money card displayed on the display device 130), and the amount to be transferred, which is the total balance on the electronic money card (step S319), and the management server 300 receives these by means of the money transfer request acceptance processor 387. Note that in step S319, the instruction from terminal A to the management server 300 to send the electronic money card in question to terminal B means that the account number of the electronic money account to which the transfer is to be made and the total balance on the electronic money card are transmitted to the management server 300, as described above.
[0112] On the other hand, terminal B transmits the second access key and a receipt instruction to the management server 300 by the remittance / reception request processor 285 (step S320), and the management server 300 receives them by the remittance / reception request receiver 387.
[0113] Next, the management server 300, through the money transfer request acceptance processor 387, determines whether the access key received from terminal A corresponds to the access key received from terminal B (step S321). The management server 300 also determines through the money transfer request acceptance processor 387 whether the remittance amount is within the account balance of user A stored in the account data storage unit 360 of the management server 300, more specifically, whether it is the total balance of the account (hereinafter referred to as account A) associated with the card number (account number) displayed on the display screen 130 of terminal A (step S322).
[0114] Next, if it is determined in step S321 that the access key corresponds and in step S322 that the remaining balance is the entire amount, the management server 300, by the sending / receiving money processing unit 388, reduces the remaining balance of the account data of account a of user A stored in the account data storage unit 360 by the amount of the remittance, and sets a new electronic money account (hereinafter referred to as account b) for user B in the account data storage unit 360 and increases the remaining balance of the account data by the amount of the remittance (step S323). In this embodiment, after step S322, account a is deleted from the account data storage unit 360, and the account number for user B newly set in step S323 is set to the account number of the deleted account a. Next, the management server 300 invalidates the first and second access keys, and makes it impossible to perform transactions using these access keys.
[0115] Next, terminal A transmits the design of the electronic money card of account a to terminal B via short-range wireless communication or a mobile communication network (step S324). After that, a screen such as that shown in FIG. 20 is displayed on the display device 230 of terminal B by the management server 300 or the application.
[0116] With this configuration, the present embodiment also achieves the same effects as those described in the first embodiment, and it is also possible to make the various modifications described above in relation to the first embodiment.
[0117] Furthermore, by exchanging the contents of the electronic certificates held by terminal A and terminal B, and sending instructions to remit and receive electronic money together with an access key issued by management server 300, it is possible to send an electronic money card directly from user A to user B while ensuring the security of the electronic money remittance. This allows the electronic money card to be exchanged in a manner that is extremely close to the handover of an actual card.
[0118] The electronic money cards shown in the above embodiments can also be used for normal internet shopping. For example, when user A uses a PC to visit an internet shopping site that accepts electronic money, and when paying for a desired product, he or she can purchase the product by inputting the card number and security code of the electronic money card he or she owns in the same way as when paying with a credit card. When making this payment, the internet shopping site manager makes an inquiry to the management server 300, and the management server 300 performs a process to determine the remaining balance of the card number, etc.
[0119] Furthermore, when user A has logged in to terminal A and the application or the like is displaying a member screen after login on the display device 130 of terminal A, it is possible to display an Internet shopping page via the application and purchase products therein using an electronic money card. In this case, when making payment for the Internet shopping, a screen such as that shown in Fig. 21 is displayed on the display device 130 of terminal A by the application or management server 300. As described above, Fig. 21 also shows a screen for inputting the card number and security code of the electronic money card.
[0120] However, since user A has already logged in to terminal A using a login ID and password, the possibility of unauthorized use of the electronic money card in this state is low. Also, since electronic money cards are prepaid, there is a limit to the amount of damage that can be caused. Therefore, in FIG. 21, a button 440 showing information about the electronic money card is displayed in the lower right, and by touching the position of the button with a finger without entering the card number or security code of the electronic money card, the screens of FIG. 22 and FIG. 23 are displayed on the display device 130. In the screen of FIG. 22, the card number, security code, etc. that user A should have entered have already been entered. In other words, payment can be made without entering the card number or security code of the electronic money card.
[0121] In the first embodiment, the terminal B directly communicates with the management server 300. However, it is also possible for the terminal B to communicate with the management server 300 via a card company's system such as JCB (registered trademark) or VISA (registered trademark) and perform the steps S101 to S123. In this case, the card company's system may simply relay data exchange between the terminal B and the management server 300, or may function in place of the management server 300 or terminal B in any of steps S101 to S123. Furthermore, it is also possible for the card company's system and the management server 300 to function as a substantially integrated system. In this way, if the card company's system is used or if the system functions as a substantially integrated system with the card company's system, the electronic money card can be used at the affiliated stores of the card company.
[0122] The electronic money remittance system according to the fourth embodiment of the present invention will be described below. The basic configuration of this system is the same as that of the first embodiment, and terminal A and management server 300 are configured as shown in Figs. 24 and 25.
[0123] Terminal A in this embodiment has a first user information storage unit 175 and a GPS 176, and also has in a program storage unit 180 a privilege information display unit 187, an enjoyment intention receiving unit 188, a location information detection unit 189, a location information transmission unit 190, and an account information display unit 191, which each cause terminal A to perform a predetermined operation.
[0124] The first user information storage unit 175 stores first user information, and this first user terminal specific information includes at least the account number of the electronic money account of user A (first user), or specific information such as the name and date of birth of user A linked to the account number, or first user terminal specific information specific to terminal A (the terminal of the first user), such as individual information of user A's terminal A.
[0125] The bonus information display unit 187 displays bonus information transmitted by a selected bonus content transmission unit 390 (described later) on the display unit 130 of terminal A. For example, as shown in FIG. 26, the bonus information is displayed on the display unit 130. The bonus information to be displayed may be one or multiple, and may be only the information on the bonus that user B provides to the customer, or the information on the bonus that user B provides to the customer and the information on the bonus that other users provide to the customer may be displayed simultaneously. In FIG. 26, the information on the bonus that user B provides to the customer and the information on the bonus that other users provide to the customer are displayed simultaneously.
[0126] 26, the enjoyment intention receiving unit 188 receives the operation via the touch panel input device 160 and transmits the received intention of the user to the management server 300. In addition, depending on the case, the enjoyment intention receiving unit 188 transmits a part or the whole of the first user information stored in the first user information storage unit 175 to the management server 300.
[0127] The position information detection unit 189 is linked to map information and specifies the position of terminal A on the map information based on the position information of terminal A detected by the GPS 176. In addition, the position information transmission unit 190 transmits the position information of terminal A on the map information specified by the position information detection unit 189 to the management server 300.
[0128] The account information display unit 191 displays the account information transmitted by the account information transmission unit 394, which will be described later, on the display device 130 of the terminal A. For example, as shown in Fig. 27, the account information of the electronic money of the user A is displayed on the display device 130.
[0129] The management server 300 of this embodiment has a first user information storage unit 371 which stores the same first user information as the first user information storage unit 175, and a benefit storage unit 372 which stores the content of the benefit and the conditions for granting the benefit to be provided to customers by user B (second user) and other users, and the program storage unit 380 has a benefit content selection unit 389 which causes the management server 300 to perform a predetermined operation, a selected benefit content transmission unit 390, an enjoyment intention receiving unit 391 which receives the user's intention transmitted by the enjoyment intention receiving unit 188, a grant judgment unit 392, a benefit granting unit 393, and an account information transmission unit 394.
[0130] The benefit storage unit 372 stores the contents of the benefit provided to the user B or other users and the conditions for providing the benefit, as shown in FIG. 28, for example. In FIG. 28, the benefit of the user B is a benefit of cashback according to the amount paid by the user B at the store, the benefit of the user C is a benefit of cashback or a discount on parking lots operated by an organization other than the user C according to the amount paid by the user C at the store, and the benefit of the user D is a benefit of discounting the cost of the next meal according to the amount paid by the user D at the store. In addition, as shown in FIG. 28, a delivery condition is also set for each benefit, and for example, the conditions for the age, the number of times the user has used the store of the user B in the past, and the area are set for the benefit of the user B.
[0131] The benefit content selection unit 389 selects a benefit content suitable for the user based on a part of the first user information transmitted by the enjoyment intention reception unit 188 and the location information transmitted by the location information transmission unit 190. For example, when the location information transmission unit 190 transmits that the user A is near a department store a or a station b, the enjoyment intention reception unit 188 transmits an account number, which is a part of the first user information of the user A, and the age and gender of the user A stored in the first user information storage unit in the server 300 in correspondence with the account number is 28 years old and male, the five benefits are selected because they meet the conditions for delivering the five benefits shown in FIG. 28. Note that when selecting a benefit, it is also possible to set the number of times the target store is used as a condition, and it is also possible to configure the system to provide a benefit to a user who has used the store of user B three or more times, as in the case of the benefit of user B in FIG. 28. Furthermore, it is possible to assign a priority rate to each benefit stored in Figure 28, vary the priority rate according to the benefit-granting service fee paid by the user providing the benefit to the company managing the management server 300, and change the selection priority according to the priority rate.It is also possible to change the priority transmission order when transmitted by the selected benefit content transmitting unit 390 described below, and to change the priority display order and display position when displayed by the benefit information display unit 187 described above.
[0132] The selected privilege content transmitting unit 390 transmits to the terminal A privilege information relating to the privilege content selected by the privilege content selecting unit 389 .
[0133] The operations of the benefit determination unit 392, the benefit provision unit 393, and the account information transmission unit 394 will be described later along with an example of processing (see FIG. 29) performed by terminal A, terminal B, and management server 300. Like the first embodiment, FIG. 29 illustrates the processing when user A (buyer) purchases a product from user B (seller such as a store) and pays for it with electronic money.
[0134] First, before user A visits user B's store, terminal A detects terminal A using location information detection unit 189 (step S401), and terminal A transmits the identified location information to management server 300 (step S402). When management server 300 receives the location information of terminal A, it selects a benefit suitable for user A from a benefit table stored in benefit storage unit 372 using benefit content selection unit 389 (step S403), and transmits benefit information related to the selected benefit content to terminal A using selected benefit content transmission unit 390 (step S404). This transmission may be display data to be displayed on the browser of terminal A, or may be an email transmission.
[0135] Terminal A, which has received the information transmitted in step S404, causes the privilege information display unit 187 to display the information transmitted, for example, by e-mail on the display device 130, as shown in Fig. 26 (step S405). When user A operates the "Enjoy this privilege" button 450 shown in Fig. 26, for example, the enjoyment intention receiving unit 188 receives the operation via the touch panel input device 160 (step S406) and transmits the received intention of user A to the management server 300 (step S407), and the management server 300 receives the intention of the user transmitted by the enjoyment intention receiving unit 391 and stores it in memory. Here, it is assumed that the privilege of user B in Fig. 26 is selected by user A.
[0136] Thereafter, similarly to the first embodiment, user A decides to purchase product X at user B's store, and steps S408 to S431 are performed similarly to steps S101 to S123 in the first embodiment. Note that in this embodiment, in step S426, terminal A transmits user A's account number as the first user information about user A, and management server 300 stores the first user information in memory.
[0137] Next, the management server 300 determines whether the granting conditions are met by comparing the amount received in step 428 with at least one of the increase / decrease in the electronic money in steps S414, S415, S418, S419, S426, S428, S429, S430 or S431 and the amount of increase / decrease in the electronic money in step S431 with the granting conditions for the benefit selected by user A (step S432).
[0138] Next, when the intention of user A to use the privilege of user B transmitted in step S407 is received by the management server 300 and it is determined in step S432 that the granting condition is satisfied, the management server 300 grants the privilege to the electronic money account of user A based on the privilege content by the privilege granting unit 393 (step S433). For example, as shown in the account information of user A shown in FIG. 27, a cashback of 200 yen is given for the payment of 2500 yen at the store of user B on September 10, 2012. Here, it is also possible to transmit the account number of user A as the first user information about user A from terminal A to the management server 300 in step S407, and to determine in step S432 whether the account number corresponds to the account number transmitted in step S426, and to perform the step S433 when it is determined that the account number corresponds. In this case, the privilege is granted more accurately.
[0139] Next, the management server 300 transmits the account information of user A's electronic money account together with the granted benefit information granted in step S433 to terminal A via the account information transmission unit 394 (step S434), and terminal A displays the granted benefit information together with the account information of user A's account via the account information display unit 191, for example as shown in FIG. 27 (step S435).
[0140] In this way, according to the present embodiment, the privilege information is displayed on the terminal of the user A based on the attributes (age and sex) of the user A and the location information of the terminal A owned by the user A, so that the user A can save the trouble and time of searching for the privilege information related to him / her, and the user B can effectively inform the customer of the privilege information. In addition, the user A's intention of whether or not to enjoy the privilege is accepted in step S406, and when the user A indicates his / her intention to use the privilege and then makes a payment that satisfies the condition for granting the privilege at, for example, the store of the user B, the privilege is granted to the account of the user A. Therefore, the fact that the privilege has been granted to the account of the user A and the contents of the privilege are more likely to be remembered than when, for example, the privilege is automatically granted without the user A being aware of what kind of privilege is granted. This can contribute to improving the purchasing motivation of the user A and to leaving a strong impression on the store of, for example, the user B. In addition, the information on the granted privilege is displayed on the display device 130 of the user A together with the account data of the account of the user A, so that the fact that the privilege has been granted to the account of the user A and the contents of the privilege are more likely to be remembered.
[0141] Incidentally, this embodiment also provides the same operational effects as those described in the first embodiment, and it is possible to make the various modifications described above in relation to the first embodiment.
[0142] In the first and fourth embodiments, the digital signature of the first electronic certificate is transmitted from terminal A to terminal B, which then embeds it in the second electronic certificate in terminal B, which then transmits it from terminal B to management server 300 (steps S103, S104, S106, S108, S410, S411, S413, S415, etc.). In contrast, it is also possible to configure in such a way that the digital signature of the first electronic certificate is not transmitted from terminal A to terminal B.
[0143] Specifically, the process is performed as shown in Fig. 30. As in the first embodiment, the following description will be given assuming that user A decides to purchase product X and takes it to user B's terminal B (POS terminal).
[0144] First, when terminal A is brought close to reader / writer 250 of terminal B and Pay button 410 in Fig. 14 is touched with a finger, terminal B causes digital certificate exchange processing unit 281 to transmit the digital signature in the second digital certificate to terminal A via short-range wireless communication, and also transmits the amount of 300 yen received from user A, which terminal A receives (step S501). Terminal A then stores the received digital signature in the certificate storage unit or another part of terminal A's memory (step S502).
[0145] Next, terminal A uses electronic certificate embedding processing unit 182 to replace the digital signature of its own first electronic certificate with the digital signature of the received second electronic certificate, thereby creating a first electronic certificate with the replaced digital signature, and stores it in certificate storage unit 171 (step S503). Next, terminal A uses digital certificate information transmission processing unit 183 to transmit the first electronic certificate with the replaced digital signature and the amount received to management server 300 (step S504).
[0146] Next, the management server 300 receives the first electronic certificate with the replaced digital signature from terminal A via the electronic certificate information reception processing unit 385 (step S505). Then, the management server 300 causes the electronic certificate information reception processing unit 385 to decrypt the first electronic certificate with the replaced digital signature and the digital signature of the second electronic certificate contained therein, using the corresponding private key stored in the customer master storage unit 350 (step S506).
[0147] Next, the management server 300, by using the electronic certificate information reception processing unit 385, determines (1) whether or not the decrypted first electronic certificate corresponds to the first electronic certificate stored in the customer master storage unit 350, and (2) whether or not the digital signature of the decrypted second electronic certificate corresponds to the digital signature of the second electronic certificate stored in the customer master storage unit 350 (step S507). In addition, the management server 300, by using the electronic certificate information reception processing unit 385, determines (3) whether or not the sender of the digital signature of the second electronic certificate is terminal A (a terminal corresponding to the first electronic certificate) (step S508).
[0148] Next, the management server 300, via the money transfer request reception processing unit 387, determines whether the amount to be received is within the account balance of user A stored in the account data storage unit 360 of the management server 300, more specifically, whether it is within the balance of the account (hereinafter referred to as account A) corresponding to the card number (account number) displayed on the display screen 130 of terminal A (step S509).
[0149] Next, if it is determined in step S509 that the amount is within the balance, the management server 300, via the remittance / received funds processing unit 388, reduces the remaining balance in the account data of user A's account a stored in the account data storage unit 360 by the amount of the received amount, and increases the remaining balance in the account data of user B's account (hereinafter referred to as account b) stored in the account data storage unit 360 by the amount of the received amount (step S510).
[0150] Even in the configuration of this embodiment, terminal A receives a digital signature, which is at least a part of the information of the second electronic certificate, from terminal B. After terminal A receives the digital signature from terminal B in this way, management server 300 receives the digital signature of terminal B from terminal A and judges whether the electronic certificate of terminal A and the digital signature of terminal B received from terminal A correspond to the information of the electronic certificates of terminal A and terminal B stored in management server 300. In other words, since the digital signature of terminal B is sent from terminal A to management server 300, the two terminals that are about to carry out the transaction are identified at this point, and further, the certification information of both parties of the transaction sent from terminal A is collated by management server 300. This allows management server 300 to reliably authenticate the terminal that is about to send or receive electronic money.
[0151] Here, the first electronic certificate held by terminal A is unique information held only by terminal A and the management server 300, and the second electronic certificate held by terminal B is unique information held only by terminal B and the management server 300. At least a part of the information of the second electronic certificate is transmitted by terminal A to the management server 300. Then, the management server 300 authenticates the terminal that is about to send or receive electronic money by receiving the authentication information of both parties in the transaction from terminal A. Therefore, even if terminal B illegally obtains the electronic certificate of terminal A and tries to obtain electronic money held by user A by some means, the remittance of electronic money from user A to user B will not be made unless authentication information of both parties in the transaction is transmitted from terminal A to the management server 300.
[0152] Furthermore, in this embodiment, the electronic money of each user is stored in the management server 300, so even if, for example, terminal A is lost and cannot be retrieved, user A's electronic money will not be reduced by that single event.
[0153] Furthermore, in this embodiment, the certification information is sent from terminal B to terminal A, and instructions to remit and receive electronic money are sent, so that electronic money can be sent directly from user A to user B while ensuring the security of the electronic money remittance. This makes it possible to exchange electronic money in a manner very similar to cash.
[0154] Incidentally, the present invention is not limited to the above-described embodiment, and various modifications are possible without departing from the spirit and scope of the invention.
[0155] Needless to say, the present invention can be modified in various ways, is not limited to the embodiment described above, and can be modified in various ways without departing from the spirit and scope of the invention. [Explanation of symbols]
[0156] 110...CPU, 120...RAM, 130...display device, 140...communication unit, 150...near-field wireless communication unit, 160...touch panel input device, 171...certificate storage unit, 172...access key storage unit, 173...card information storage unit, 174...application storage unit, 180...program storage unit, 210...CPU, 220...RAM, 230...display device, 240...communication unit, 250...reader / writer, 260...input device, 271...certificate storage unit, 272...access key storage unit, 273...card information storage unit, 274...application storage unit, 280...program storage unit, 300...management server, 310...CPU, 320...RAM, 330...display device, 340...communication unit, 350...customer master, 360...account data storage unit, 370...application storage unit, 380...program storage unit.
Claims
1. An authentication method for processing a payment using electronic money between a first user and a second user in an electronic money management server, the first user terminal (A) reads at least a part of the second certification information output by the second user terminal (B) and transmits it to the electronic money management server (300) via the first user terminal (A), and / or the second user terminal (B) reads at least a part of the first certification information output by the first user terminal (A) and transmits it to the electronic money management server (300) via the second user terminal (B); The electronic money management server (300) Whether or not at least a part of the information of the second certification information received from the first user terminal (A) corresponds to the second certification information stored in the electronic money management server (300), and whether or not the first user terminal that is the source of the second certification information corresponds to the first certification information stored in the electronic money management server (300), and / or whether or not at least a part of the first certification information received from the second user terminal (B) corresponds to the first certification information stored in the electronic money management server (300), and whether or not the second user terminal which is the source of the first certification information corresponds to the second certification information stored in the electronic money management server (300); The authentication method according to claim 1, wherein the first user and the second user are authenticated by determining whether or not the first user and the second user are authenticated.
2. 10. The method of claim 1 , The electronic money remittance / settlement is a payment of a purchase price of a product purchased by a first user from a second user using electronic money, The terminal (B) of the second user is provided with an input means for inputting product information including the price of the product. A method comprising:
3. An authentication system for processing a payment using electronic money between a first user and a second user in an electronic money management server, the first user terminal (A) reads at least a part of the second certification information output by the second user terminal (B) and transmits it to the electronic money management server (300) via the first user terminal (A), and / or the second user terminal (B) reads at least a part of the first certification information output by the first user terminal (A) and transmits it to the electronic money management server (300) via the second user terminal (B); The electronic money management server (300), Whether or not at least a part of the information of the second certification information received from the first user terminal (A) corresponds to the second certification information stored in the electronic money management server (300), and whether or not the first user terminal that is the source of the second certification information corresponds to the first certification information stored in the electronic money management server (300), and / or whether or not at least a part of the first certification information received from the second user terminal (B) corresponds to the first certification information stored in the electronic money management server (300), and whether or not the second user terminal which is the source of the first certification information corresponds to the second certification information stored in the electronic money management server (300); and an authentication means for authenticating the first user and the second user by determining A system characterized by:
4. 4. The system of claim 3, The electronic money settlement is a payment by the first user of a purchase price of a product purchased from a second user using electronic money, The terminal (B) of the second user is provided with an input means for inputting product information including the price of the product. A system characterized by: