Payment management device, payment management method, program, and payment management system
By introducing operational information acquisition and detection units into payment management equipment and systems, obtaining and analyzing user's operational information on payment applications, the shortcomings of relying solely on authorized data to detect credit card fraud in the prior art are solved, and more comprehensive and accurate fraud detection is achieved.
Patent Information
- Application Number
- JP2023181079
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-20
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2043-10-20
AI Technical Summary
When detecting credit card fraud, the prior art only relies on authorized data and cannot consider user behavior that is not related to authorized data.
By introducing an operation information acquisition unit and a detection unit in the payment management device and the system, the user's operation information on the payment application is acquired, and specific operations are detected, their impact is recorded, and they are transmitted to the credit card management device to consider user behavior related to unauthorized data.
It realizes a more comprehensive detection of credit card fraud, and can identify potential fraud activities in user behavior outside of authorized data, improving the accuracy and effectiveness of fraud detection.
Smart Images

Figure 2025070617000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a payment management device, a payment management method, a program, and a payment management system. [Background technology]
[0002] Generally, when a user makes a payment using a credit card, the store side inquires about the credit information of the user to the credit card company and performs a procedure to confirm whether the payment is possible. This procedure is called "authorization" (sometimes called credit inquiry or credit approval), and a payment by credit card is considered to be completed when it is confirmed by authorization that the payment is possible. Conventionally, a technique has been proposed to improve the reliability of a score value for credit judgment based on the electronic message data for this authorization (hereinafter referred to as "authorization data"). For example, a method has been proposed to calculate a score value using history information such as the difference in usage time and the difference in usage amount between the authorization data and the immediately previous usage in addition to the authorization data (see, for example, Patent Document 1). Also, for example, a method has been proposed to calculate the occurrence probability of fraudulent use using a trained model of authorization data, and to calculate a score value by reflecting the reliability of the trained model in the calculated occurrence probability (see, for example, Patent Document 2). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2004-348536 A [Patent Document 2] JP 2004-334526 A Summary of the Invention [Problem to be solved by the invention]
[0004] There are various ways in which a credit card can be used for post-payment settlement, including using a physical credit card at a store, entering credit card information on a website, and registering the credit card in an application program running on a terminal device such as a smartphone and using the credit card via the application program. However, the above conventional technology detects fraudulent use using authorization data exchanged when a credit card is actually used, and therefore, in the conventional technology, even if a behavior related to the fraudulent use of a credit card is not linked to the authorization data, it may not be possible to take such behavior into consideration when determining whether or not the behavior is fraudulent.
[0005] The present invention has been made taking into consideration the above circumstances, and one of its objectives is to provide a payment management device, a payment management method, a program, and a payment management system that enable a system that detects fraudulent use of credit cards based on authorization data to determine whether or not a use has occurred by taking into account user behavior that is not linked to authorization data. [Means for solving the problem]
[0006] One aspect of the present invention is a payment management device that provides an electronic payment service to a user in cooperation with an application program running on the user's terminal device, the payment management device comprising: an acquisition unit that acquires operation information regarding operations performed by the user on the application program from the application program; and a detection unit that detects a specific operation performed on the application program based on the operation information, wherein when the detection unit detects that the specific operation has been performed on the application program, it transmits information for recording the occurrence of the specific operation to a credit payment management device that manages credit cards registered in the application program. Effect of the Invention
[0007] According to one aspect of the present invention, it is possible to provide a payment management device, a payment management method, a program, and a payment management system that enable a system for detecting fraudulent use of a credit card based on authorization data to determine whether or not a use has occurred by taking into account user behavior that is not linked to authorization data. [Brief description of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram showing an example of a configuration for realizing an electronic payment service. [Diagram 2] This is a sequence diagram (part 1) illustrating the general flow of electronic payment. [Diagram 3] This is a sequence diagram (part 2) illustrating the general flow of electronic payment. [Figure 4] 1 is a configuration diagram of a payment server 100 according to a first embodiment. [Diagram 5] FIG. 13 is a diagram showing an example of the contents of user information 172. [Figure 6] FIG. 13 is a diagram showing an example of the contents of affiliated store / store information 176. [Figure 7] FIG. 2 is a diagram conceptually illustrating the processing of terminal payment and card payment. [Figure 8] FIG. 13 is a diagram showing an example of the contents of card payment setting information 272. [Figure 9] FIG. 2 is a configuration diagram of an affiliated credit card company server 200 according to the first embodiment. [Figure 10] A figure showing an example of the contents of authorization information 276. [Figure 11] 11 is a sequence diagram showing an example of a process flow for detecting an unauthorized operation on payment application 20 and notifying affiliated credit card company server 200. FIG. [Figure 12] 11 is a diagram showing an example of a screen transition defined as an unauthorized operation to be detected in the payment server 100. FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] Hereinafter, with reference to the drawings, an embodiment of the payment management device, the payment management method, the program, and the payment management system of the present invention will be described. The application program, the payment server, and the affiliated credit card company server work together to provide an electronic payment service. In the following description, the application program is referred to as a payment application. The payment server and the affiliated credit card company server may be combined and referred to as a payment management system. The electronic payment service is a service that supports payments related to the purchase of goods and services at a store. The store is, for example, a physical store (real store) that exists in the real world, but may also include a virtual store for electronic commerce. The virtual store may include a store provided by an entity different from the operator of the electronic payment service. In that case, when making a payment for shopping at the virtual store, the screen is controlled to transition to an interface screen of the electronic payment service. In the electronic payment service, the store is treated as belonging to, for example, an affiliated store (brand), and processing such as payment when a purchase is made at the store is mainly performed between the user and the affiliated store. Alternatively, processing such as payment may be performed between the user and the store.
[0010] [Electronic payment service] FIG. 1 is a diagram showing an example of a configuration for realizing an electronic payment service. The electronic payment service is realized mainly by a payment server 100 and an affiliated credit card company server 200. The payment server 100 communicates with, for example, one or more user terminal devices 10, one or more first store terminal devices 50, one or more credit processing terminals 55, and one or more second store terminal devices 70 via a network NW. The affiliated credit card company server 200 communicates with an administrator terminal device 80 via a network NW. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, and the like. Here, the payment server 100 is an example of a "payment management device," and the affiliated credit card company server 200 is an example of a "credit payment management device."
[0011] The user terminal device 10 is, for example, a portable terminal device such as a smartphone or a tablet terminal. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input reception function, and a program execution function. In the following description, components for realizing these functions are referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, thereby operating to provide an electronic payment service to a user in cooperation with a payment server 100. The payment application 20 is installed in the user terminal device 10 from, for example, an application store, and controls the camera, communication device, touch panel, etc.
[0012] The first store terminal device 50 is installed, for example, in a store. The first store terminal device 50 is a computer device having at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The first store terminal device 50 includes a so-called POS (Point of Sale) device, and the product price acquisition function and the optical reading function may be realized by the POS device. The store code image 60 is placed in the store, and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 60 may be displayed on a display placed in the store (which may be the display of a terminal device such as a smartphone).
[0013] The credit processing terminal 55 is installed in the store, similarly to the first store terminal device 50. The credit processing terminal 55 includes, for example, a credit card settlement terminal (credit card reader) and a POS device. The credit card settlement terminal reads a PIN (Personal Identification Number) from an inserted or held credit card (including the affiliated card 57) and compares it with the PIN entered by the user, or transmits a BIN (Bank Identification Number) code, etc., read from the credit card to the affiliated credit card company server 200 via the POS device. The POS device cooperates with the credit card settlement terminal to transmit information such as the settlement amount to the affiliated credit card company server 200. An advance payment agent server (acquirer) may be interposed between the credit processing terminal 55 and the affiliated credit card company server 200. In the following, the advance payment agent server will be omitted for the sake of simplicity. The affiliated card 57 is, for example, of the same type as a commonly used credit card, with a communication chip embedded in the card substrate. The communication chip includes a storage medium that stores a PIN, and communicates with an external device via a contactor (or a wireless antenna). Alternatively, the affiliate card 57 may be a magnetic card.
[0014] The second store terminal device 70 is used by the operator of the affiliated store. The second store terminal device 70 is a smartphone, a tablet terminal, a personal computer, or the like. An interface 72 for affiliated stores runs on the second store terminal device 70. The interface 72 for affiliated stores may be an app for affiliated stores or a browser. The interface 72 for affiliated stores accepts coupon settings and the like made by the operator of the affiliated store and transmits them to the payment server 100. The second store terminal device 70, which is a smartphone, has the function of displaying a code image corresponding to a store code image and reading a code image displayed by the user terminal device 10 by executing the app for affiliated stores.
[0015] The payment server 100 realizes electronic payment based on payment information received from the user terminal device 10 or the first store terminal device 50. The first store terminal device 50 may include a POS device and an affiliated store server, in which case the payment information is sent from the POS device via the affiliated store server to the payment server 100. In the following explanation, no distinction is made between these two and it is assumed that the payment information is sent from the first store terminal device 50.
[0016] The affiliated credit card company server 200 manages affiliated credit card payments, which are part of the electronic payment service. The affiliated credit card company server 200 is operated, for example, by a group company (affiliated credit card company) of the payment server 100. The affiliated credit card company may be a separate entity from the external credit card company that provides the credit card as a funds source for charging the charge balance.
[0017] When an affiliated credit card payment is requested, the affiliated credit card company server 200 executes authorization to confirm whether the affiliated credit card can be used for payment. If the affiliated credit card company server 200 confirms that the payment is possible through authorization, it executes payment processing, and if it cannot confirm that the payment is possible, it responds with a disapproval of the payment request. More specifically, during authorization, it is confirmed that the payment amount is within the credit limit and that it does not constitute fraudulent use. The affiliated credit card company server 200 pre-stores one or more rules for detecting fraudulent use of the affiliated card 57 as fraud detection rules, and judges whether the card use related to the authorization is fraudulent or not by checking the authorization data against the fraud detection rules.
[0018] The administrator terminal device 80 is a terminal device used by the administrator of the affiliated credit card company server 200 to check and judge the operation status and validity of the fraud detection rules. The administrator terminal device 80 executes a management application 82, which is an application program for managing the fraud detection rules, to provide a user (administrator) of the administrator terminal device 80 with a user interface for judging the fraud detection rules. For example, the management application 82 acquires and displays information on the operation status of the fraud detection rules from the affiliated credit card company server 200, and also accepts an operation to change the fraud detection rules and notifies the affiliated credit card company server 200 of the changes. The affiliated credit card company server 200 reflects the notified changes in the fraud detection rules. The management application 82 may be configured as a dedicated application, or may be configured using a general-purpose application such as a web browser.
[0019] 2 and 3 are sequence diagrams illustrating the general flow of electronic payment. There may be two patterns of electronic payment: pattern 1 and pattern 2.
[0020] In the case of pattern 1 (hereinafter referred to as user scan) shown in FIG. 2, the user terminal device 10 with the payment application 20 activated decodes the store code image 60 by the optical reading function (S1). The store code image 60 includes store URL (Uniform Resource Locator) information. This store URL is an electronic payment service domain to which store-identifying information is added, and is associated with an affiliated store ID, a store ID, etc. in the payment server 100 (described later). The payment application 20 transmits the first payment information including the store URL and the account ID to the payment server 100 (S2). The payment server 100 searches for store information (described later) from the affiliated store ID and the store ID corresponding to the store URL, acquires the affiliated store name and the store name information (S3), and transmits it to the payment application 20 (S4). The user inputs the payment amount into the user terminal device 10 on the screen on which the affiliated store name and the store name are displayed (S5). Then, the user terminal device 10 generates second payment information including at least the payment amount, and transmits it to the payment server 100 (S6). The payment server 100 performs electronic payment based on the received second payment information (S7). The payment server 100 then transmits a payment completion notice (information for displaying a payment completion screen) to the payment application 20 (S8), and the payment application 20 displays the payment completion screen (S9). Note that when the store code image 60 is displayed on a display installed in the store, the store code image 60 may include not only the store URL but also information on the payment amount. In this case, the step of the user inputting the payment amount is omitted, and the information on the payment amount is included in the first payment information and transmitted to the payment server 100. Information on the affiliated store name and the store name may be included in the payment completion screen and displayed.
[0021] In the case of pattern 2 (hereinafter referred to as store scan) shown in FIG. 3, when the payment application 20 is started, when a payment operation is performed in the payment application 20, when an automatic update timing (for example, every minute) occurs, and at other timings, the payment application 20 transmits a request for issuing a one-time code to the payment server 100 (S11). The payment server 100 generates a one-time code (S12) and transmits it to the payment application 20 (S13). The payment application 20 displays a code image such as a QR code (registered trademark) or a barcode generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the first store terminal device 50, and the first store terminal device 50 decodes the code image by an optical reading function and obtains the one-time code, etc. (S15). The first store terminal device 50 then generates payment information including the one-time code, payment amount, affiliated store ID, store ID, etc., and transmits it to the payment server 100 (S16). The payment amount information is acquired in advance by reading a barcode or manually entering it. The payment server 100 identifies the user corresponding to the one-time code based on the received information and performs electronic payment (S17). The payment server 100 then transmits a payment completion notice to the payment application 20 (S18), and the payment application 20 displays a payment completion screen (S19).
[0022] Note that electronic payment may be performed using only one of the above patterns. Furthermore, the "account ID" described in FIG. 2 may be other information (e.g., a phone number) that can be used as user identification information. Furthermore, issuance of a one-time code may be omitted in the store scan, and the payment application 20 may display a code image generated based on the user's account ID. In this case, the payment server 100 identifies the user corresponding to the account ID instead of identifying the user corresponding to the one-time code.
[0023] [Payment server] FIG. 4 is a configuration diagram of the payment server 100 according to the first embodiment. The payment server 100 includes, for example, a communication unit 110, a payment content providing unit 120, a payment processing unit 130, an information management unit 140, an attention operation detection unit 150, and a storage unit 170. The components other than the communication unit 110 and the storage unit 170 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI (Large Scale Integration), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a GPU (Graphics Processing Unit), or may be realized by cooperation between software and hardware. The program may be stored in advance in a storage device (a storage device with a non-transient storage medium) such as an HDD (Hard Disk Drive) or flash memory, or may be stored in a removable storage medium (non-transient storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device.
[0024] The storage unit 170 is a HDD, a flash memory, a RAM (Random Access Memory), etc. The storage unit 170 may be a NAS (Network Attached Storage) device that the payment server 100 can access via a network. The storage unit 170 stores information such as user information 172, payment content information 174, and affiliated store / shop information 176.
[0025] The communication unit 110 is a communication interface for connecting to the network NW. The communication unit 110 is, for example, a network interface card.
[0026] The payment content providing unit 120 has, for example, a function of a Web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The payment content providing unit 120 appropriately reads necessary content from the payment content information 174 and provides it to the user terminal device 10. The user terminal device 10 accepts various inputs by the user while the content is being played by the payment application 20, and transmits the above-mentioned payment information and the like to the payment server 100.
[0027] The payment processing unit 130 performs payment processing based on the payment information transmitted by the user terminal device 10 or the first store terminal device 50. The payment processing unit 130 performs payment processing while referring to the user information 172.
[0028] FIG. 5 is a diagram showing an example of the contents of the user information 172. The user information 172 is an example of the registration information of a user. The user information 172 is information associated with, for example, a user URL, an account ID, a telephone number, a password, an email address, a user ID, a name, an address, a date of birth, a registration date, a charge balance, a deferred payment setting, a deferred payment limit, a deferred payment usage amount, a deferred payment available amount, a terminal payment method, a card payment method, an affiliated card number, a bank account, a credit card number, charge history information, and payment history information. The user URL is used for a remittance process between users. When registering for the electronic payment service, it is necessary to register a telephone number and a password. The account ID is issued to the user by the payment server 100, and the user ID is an ID that can be set by the user at will (does not have to be set). Similarly, the email address, and the name, address, and date of birth are information that can be set by the user at will (does not have to be set). The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). Hereinafter, the user's instance (electronic payment account) to which this information is associated will be referred to as an account.
[0029] The charge balance is information indicating the balance of electronic money that is set by a user by transferring money to an account in advance. Means of transfer include transfer from an ATM (Automatic Teller Machine) of a designated company (bank) and transfer from a registered bank account. The deferred payment setting is information indicating whether or not the setting for enabling electronic payment by deferred payment has been completed, and is set to either "completed" or "not completed". The deferred payment setting is flag information common to "terminal payment" and "card payment" described later. A user who can use deferred payment of terminal payment is a user who has been given an affiliated card 57. Alternatively, the deferred payment setting may be setting information that is set separately for "terminal payment" and "card payment". The terminal payment method is setting information indicating whether the user performs electronic payment using the charge balance or deferred payment in "terminal payment". The card payment method is setting information indicating whether the user performs electronic payment using the charge balance or deferred payment in "card payment". The card payment method is setting information indicating whether the user performs electronic payment using the charge balance or deferred payment in "card payment". The card payment method is synchronized with the affiliated credit card company server 200 in real time. The affiliated card number is the number of the affiliated card 57 (e.g., PAN (Primary Account Number)). The bank account and credit card number are information on the bank account or credit card number (account number, card number) that can be used to deposit funds into the electronic payment service. This credit card number is the number of a credit card other than the affiliated card 57. The charge history information is a history of the user transferring money to the electronic payment service in advance to increase the charge balance. The payment history information is information that indicates the details of payments made by the user for each payment (date and time, store ID of the store where the purchase was made, payment amount, payment method, etc.).
[0030] 6 is a diagram showing an example of the contents of affiliated store / store information 176. The affiliated store / store information 176 includes, for example, a first table 176A in which an affiliated store ID and a store ID are associated with a store URL, a second table 176B in which an affiliated store name and sales amount (described above) are associated with an affiliated store ID, and a third table 176C in which a store ID is associated with a store ID. In addition to this information, the affiliated store / store information 176 may also include information such as the category of the affiliated store or store, the location of the store, and payment patterns.
[0031] The information management unit 140 manages user information 172 and affiliated store / store information 176 based on information acquired from the user terminal device 10 and the second store terminal device 70. The information management unit 140 adds new records to, edits, and deletes the user information 172 and affiliated store / store information 176.
[0032] The focused operation detection unit 150 detects that a focused operation has been performed on the payment application 20 based on the operation information received from the payment application 20. Here, the operation information is information related to an operation performed on the payment application 20. The focused operation here is an operation performed on the payment application 20, the history of which is determined to be effective information for detecting fraudulent use of a credit card, among operations performed on the payment application 20. Which operation is to be the focused operation may be arbitrarily set according to the content and occurrence status of past fraudulent use, the fraud detection policy, and the like. The focused operation detection unit 150 recognizes an operation performed on the payment application 20 based on the operation information, and if the recognized operation corresponds to the focused operation, notifies the affiliated credit card company server 200 of that effect. Hereinafter, this notification is referred to as a "focused operation detection notification." It is assumed that an operation to be detected as a focused operation is registered in advance in the storage unit 170 as focused operation information 178 in the affiliated credit card company server 200. Here, the focused operation is an example of a "specific operation", and the focused operation information 178 is an example of "operation definition information". Moreover, the focused operation detection unit 150 is an example of an "acquisition unit" and a "detection unit."
[0033] Here, terminal payment and card payment will be explained. Figure 7 is a diagram conceptually showing the processing of each of terminal payment and card payment. As described below, the electronic payment service allows four types of electronic payment: (1) terminal payment / payment with charge balance, (2) terminal payment / payment after delivery, (3) card payment / payment with charge balance, and (4) card payment / payment after delivery.
[0034] [Terminal payment] (1) When the payment server 100 (payment processing unit 130) acquires payment information from the user terminal device 10 or the first store terminal device 50, terminal payment is initiated. The payment server 100 acquires the "terminal payment method" of the user by referring to the user information 172. The payment server 100 performs electronic payment by its own processing for a user whose "terminal payment method" is set to "charge balance". In this case, the payment processing unit 130 performs electronic payment by decreasing the charge balance managed in association with the user ID and increasing the item value of the affiliated store's sales. The item value of the affiliated store's sales is not used as electronic money itself, for example, and an amount corresponding to the item value of the sales is transferred to a bank account in a cycle according to an agreement between the affiliated store and the electronic payment service.
[0035] (2) In terminal payment, the payment server 100 transfers the payment information to the affiliated credit card company server 200 together with the affiliated card number of the user obtained by referring to the user information 172 for the user who has set the "terminal payment method" to "deferred payment." The affiliated credit card company server 200 checks whether the cumulative payment amount indicated in the payment information does not exceed the upper limit for the current month, and if it does not exceed the upper limit, performs processing such as adding the obtained payment amount to the cumulative payment amount for the user. The cumulative payment amount for the month is settled, for example, by withdrawing the payment amount from a bank account all at once on the payment date of the following month.
[0036] [Credit card payment] (3) When the affiliated credit card company server 200 acquires the payment information from the credit processing terminal 55, electronic payment (card payment) using the affiliated card 57 is started. The affiliated credit card company server 200 refers to the card payment setting information 272 stored in the storage unit 270. FIG. 8 is a diagram showing an example of the contents of the card payment setting information 272. The card payment setting information 272 is information in which information unique to a user (e.g., PAN), a card payment method, and the account ID of the user are associated with each other. The card payment method and the account ID are the same information as those included in the user information 172 in FIG. 5, and are synchronized with the payment server 100. The affiliated credit card company server 200 transfers the payment information to the payment server 100 together with the account ID of the user obtained by referring to the card payment setting information 272 for a user whose "card payment method" is set to "charge balance". The payment server 100 performs the same process as when the "terminal payment method" is set to "charge balance" in the terminal payment based on the acquired payment information.
[0037] (4) In card payments, the affiliated credit card company server 200 performs electronic payments by its own processing for users whose "card payment method" is set to "deferred payment." In this case, the affiliated credit card company server 200 performs processing similar to that in terminal payments when the "terminal payment method" is set to "deferred payment."
[0038] Switching between "charge balance" and "deferred payment" in each of "terminal payment" and "card payment" is performed according to a user's operation on the payment application 20. The payment application 20 separately provides the user with an interface screen for selecting either the "charge balance" or "deferred payment" payment method (or other payment methods) in "terminal payment", and an interface screen for selecting either the "charge balance" or "deferred payment" payment method (or other payment methods) in "card payment".
[0039] In addition, in "terminal payment" and "card payment", when a payment using a credit card (in the example of this embodiment, it is a credit card payment or postpaid) is requested, the affiliated credit card company server 200 obtains authorization data regarding the use of the credit card from the credit processing terminal 55, and judges whether the use of the credit card is fraudulent or not by checking the obtained authorization data against the fraud detection rules, and responds with the judgment result to the credit processing terminal 55. The credit processing terminal 55 continues or cancels the payment depending on the judgment result. The affiliated credit card company server 200 performs such an authorization judgment process every time a payment using a credit card occurs, and records and accumulates the judgment result.
[0040] [Affiliated credit card company server] FIG. 9 is a configuration diagram of the affiliated credit card company server 200 according to the first embodiment. The affiliated credit card company server 200 includes, for example, a communication unit 210, a credit settlement processing unit 230, an information management unit 240, a fraud detection unit 250, and a storage unit 270. The components other than the communication unit 210 and the storage unit 270 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI (Large Scale Integration), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a GPU (Graphics Processing Unit), or may be realized by cooperation between software and hardware. The program may be stored in advance in a storage device (a storage device having a non-transient storage medium) such as an HDD (Hard Disk Drive) or a flash memory, or may be stored in a removable storage medium (non-transient storage medium) such as a DVD or a CD-ROM, and installed in the storage device by mounting the storage medium in a drive device.
[0041] The communication unit 210 is a communication interface for connecting to the network NW. The communication unit 210 is, for example, a network interface card.
[0042] The credit card payment processing unit 230 executes a payment process for credit card payment using the affiliated card 57 based on the payment information sent or transferred from the credit card processing terminal 55 or the payment server 100. More specifically, the credit card payment processing unit 230 executes authorization in response to a payment request received from the credit card processing terminal 55 or the payment server 100, and executes the payment process when the target user is approved as a result of the authorization to use a credit card for payment. The credit card payment processing unit 230 saves the contents of the executed authorization in the authorization information 276 described below.
[0043] The credit card payment processing unit 230 performs payment processing while referring to the user information 274. The user information 274 is information that manages various information of a user related to electronic payment services using a credit card in association with the user's identification information. The user information 274 includes, for example, information such as a credit card number, a bank account, and a transaction history.
[0044] In addition, when the affiliated credit card company server 200 is operated, for example, by a group company (affiliated credit card company) of the payment server 100, the user information 274 of the affiliated credit card company server 200 may manage the same content as the user information 172 held by the payment server 100. In this case, the user information 274 held by the affiliated credit card company server 200 and the user information 172 held by the payment server 100 may be synchronized with each other at a predetermined timing.
[0045] The storage unit 270 is a HDD, a flash memory, a RAM (Random Access Memory), etc. The storage unit 270 may be a NAS (Network Attached Storage) device that the affiliated credit card company server 200 can access via a network. The storage unit 270 stores information such as card payment setting information 272, user information 274, authorization information 276, and fraud detection rules 278.
[0046] FIG. 10 is a diagram showing an example of the contents of the authorization information 276. The authorization information 276 is information related to authorizations previously performed by the affiliated credit card company server 200. The authorization information 276 is, for example, information in which an authorization ID, which is identification information of an authorization, is associated with the time when a payment request was generated, the payment amount, the affiliated store ID, the user ID, the judgment result by the fraud detection rule 278, and the like. The authorization ID is, for example, uniquely assigned at the timing when the affiliated credit card company server 200 accepts a payment request. For example, as an example of the judgment result by the fraud detection rule 278, the possibility of payment and the applicable rule when it is judged that payment is not possible may be retained. The authorization information is an example of "history information".
[0047] Returning to FIG. 9, the fraud detection rule 278 is a rule for detecting fraudulent use of the affiliated card 57. The fraud detection rule 278 may prescribe a rule for determining whether or not a use of the affiliated card 57 that has occurred is fraudulent, or may prescribe a rule for determining whether or not the use is fraudulent. More specifically, the fraud detection rule 278 prescribes a rule for determining whether or not a target payment is fraudulent based on authorization data. The fraud detection rule 278 may determine whether or not a fraudulent use has occurred by combining items recognized from the authorization data and the contents of an operation performed on the payment application 20.
[0048] For example, an example of a fraud detection rule for determining fraudulent use of a lost card may be "used consecutively a certain number of times or more at a convenience store late at night," while an example of a fraud detection rule for determining fraudulent use by a specific method may be "used at store A, followed immediately by use at store B to make a payment of a certain amount or more."
[0049] The information management unit 240 manages the fraud detection rules 278 based on information acquired from the administrator terminal device 80. For example, the information management unit 240 accepts an edit operation of the fraud detection rules 278 via the management application 82 of the administrator terminal device 80, and adds a new rule to the fraud detection rules 278, or edits or deletes an existing rule. Here, the information management unit 240 is an example of a "support information provision unit."
[0050] The information management unit 240 provides the administrator with support information for supporting the management of the fraud detection rules 278. The support information may be any information that is useful for the administrator to maintain the fraud detection rules 278. For example, the support information may include information such as the contents of past payments, the detection record of fraudulent use according to existing rules, the contents of operation information notified from the payment application 20, or various trends ascertained from those contents. In addition, for example, the support information may include information such as the presentation of rules that are recommended to be deleted or changed, the grounds for the recommendation, and the effects obtained when the presented rules are deleted or changed. The administrator can check the support information via the management application 82, and can review the existing rules or consider new rules based on the contents of the support information.
[0051] When the affiliated card 57 is used, the fraud detection unit 250 detects fraudulent use of the affiliated card 57 based on the authorization information 276 and the fraud detection rule 278. The fraud detection unit 250 may be provided in a server separate from the affiliated credit card company server 200 together with the fraud detection rule 278.
[0052] 11 is a sequence diagram showing an example of a process flow for detecting a predetermined notable operation (hereinafter referred to as a "notable operation") related to fraudulent use of affiliated card 57 in payment application 20 and notifying affiliated credit card company server 200. In the following, the process flow is categorized into (1) transmission of operation information by payment application 20, (2) detection and notification of the notable operation by payment server 100, and (3) recording of the notable operation by affiliated credit card company server 200 for explanation.
[0053] (1) Transmission of operation information by payment application 20 First, in response to the payment application 20 receiving a user's operation in the user terminal device 10, operation information regarding the operation is generated and transmitted to the payment server 100 (S210). As described above, the operation information is information for notifying the payment server 100 of an operation performed on the payment application 20. In this embodiment, a case where a terminal identification number is used as an example of the operation information will be described. The terminal identification number is a 13-digit identification number (also called TID) set in a terminal device that executes credit payment processing, such as the credit processing terminal 55. The terminal identification number includes a number for identifying the business entity that manages the terminal device, and by referring to the terminal identification number, it is possible to identify which terminal device performed the payment processing.
[0054] In this embodiment, among the screens displayed by the payment application 20 to provide various functions, each screen (attention screen) corresponding to the above-mentioned attention operation is associated in advance with a unique terminal identification number as screen identification information. The terminal identification number is used as the screen identification information here in order to record the fact that the attention operation has been performed on the payment application 20 in the affiliated credit card company server 200 by the "0 yen payment" described later. When the user operates the attention screen, the payment application 20 transmits the terminal identification number associated with the attention screen to the payment server 100 as operation information. FIG. 11 shows the flow of processing when one attention screen is operated, but when multiple attention screens are operated in the payment application 20, the series of processing shown in FIG. 11 is executed each time a new attention screen is operated. Here, the 0 yen payment is an example of the "specific credit card payment".
[0055] As described above, the terminal identification number is originally an identification number set in credit processing terminal 55. Also, the target operation needs to be recorded so that it can be traced back to which payment application 20 it was an operation on. For this reason, the terminal identification number used as screen identification information in this embodiment is generated so as to satisfy the following conditions. Note that the terminal identification number as screen identification information may be generated in any manner as long as it satisfies the following conditions. -Includes information that enables identification of the screen displayed by the focus operation - The number must not overlap with the number set in the credit card processing terminal 55 - Including information that enables identification of the payment application 20 to be operated Note that the information that enables identification of payment application 20 may be, for example, identification information of the user, identification information of user terminal device 10 on which payment application 20 operates, or a combination thereof. Furthermore, the operation information may include other information in addition to the above-mentioned terminal identification number.
[0056] (2) Detection of attention operations on payment application 20 Next, in the payment server 100, the focused operation detection unit 150 detects a focused operation performed on the payment application 20 based on the operation information received from the payment application 20 (S220). More specifically, the focused operation detection unit 150 recognizes an operation (target operation) performed on the payment application 20 based on the operation information (S221), and determines whether the target operation is a focused operation based on the focused operation information 178 (S222). More specifically, if the target operation is registered in the focused operation information 178, the focused operation detection unit 150 determines that the target operation is a focused operation, and if not registered, determines that the target operation is not a focused operation. Here, if it is determined that the target operation is not a focused operation, the subsequent process is skipped and a series of processes is terminated. On the other hand, if it is determined that the target operation is a focused operation in S222, the focused operation detection unit 150 notifies the affiliated credit card company server 200 of that effect (S230: focused operation detection notification).
[0057] (3) Recording of operations of interest by affiliated credit card company servers Next, when the affiliated credit card company server 200 receives the notice of detection of the noted operation, it records that the noted operation has been performed on the payment application 20 (S240). In this way, the affiliated credit card company server 200 records that the noted operation has been performed on the payment application 20, so that the affiliated credit card company server 200 can detect fraudulent use of the credit card due to an operation of the payment application 20 by combining the fraud detection rule 278 and the detection status of the noted operation. In addition, the affiliated credit card company server 200 records that the noted operation has been performed on the payment application 20, so that the operator of the affiliated credit card company can add new fraud detection rules or review fraud detection rules based on the occurrence status of the noted operation on the payment application 20.
[0058] The following describes a method of transmitting "0 yen authorization data" (specific authorization data) to affiliated credit card company server 200 as an example of a method of having affiliated credit card company server 200 record that a target operation has been performed on payment application 20. The 0 yen authorization data is authorization data that requests affiliated credit card company server 200 to make a credit payment with a payment amount of 0 yen (hereinafter referred to as "0 yen payment").
[0059] Generally, authorization data exchanged in credit card payment includes information such as the terminal identification number of the credit processing terminal, the credit card member number, and the payment amount. The focused operation detection unit 150 generates 0 yen authorization data based on the terminal identification number, which is assigned as screen identification information so as not to overlap with the terminal identification number for normal payment, and the card member number of the affiliated card 57 (affiliated card number in the example of FIG. 5). The focused operation detection unit 150 transmits the generated 0 yen authorization data to the affiliated credit card company server 200 as a focused operation detection notification. The affiliated credit card company server 200 executes the credit card payment process based on the 0 yen authorization data received from the payment server 100 (S241).
[0060] As a result, in response to the detection of the target operation on payment application 20, the 0 yen payment is executed in affiliated credit card company server 200. That is, the fact that the target operation has been performed on payment application 20 is recorded in affiliated credit card company server 200 as the payment history of the 0 yen payment (S242). More specifically, since the contents of the 0 yen authorization data are recorded in the payment history of the 0 yen payment, affiliated credit card company server 200 can identify the screen displayed by the target operation, the payment application 20 on which the target operation was performed, and the credit card used by referring to the terminal identification number for the 0 yen payment.
[0061] FIG. 12 is a diagram showing an example of a screen (attention screen) defined as an attention operation in the payment server 100. In FIG. 12, TID represents a terminal identification number. FIG. 12 shows four screens as an example of attention screens: a campaign screen PG1 (TID=A), a top-up screen PG2 (TID=B), a stamp card screen PG3 (TID=C), and an account information management screen PG4 (TID=D). The campaign screen PG1 is a screen for providing information and functions related to an ongoing campaign. The top-up screen PG2 is a screen for providing a fund transfer means. The stamp card screen PG3 is a screen for providing a stamp card function. The account information management screen PG4 is a screen for providing a management function of account information. When any one of the campaign screen PG1, the top-up screen PG2, the stamp card screen PG3, and the account information management screen PG4 is displayed by a user's operation, the payment application 20 transmits operation information including the terminal identification number of the displayed screen to the payment server 100.
[0062] The example of FIG. 12 shows a case where an operation to display a campaign screen PG1 is performed on the payment application 20. In this case, operation information including the terminal identification number TID=A is sent from the payment application 20 to the payment server 100. The payment server 100 detects that the focused operation has been performed on the payment application 20 because the terminal identification number (TID=A) indicated by the operation information is defined as the focused screen in the focused operation information 178. The payment server 100 generates 0 yen authorization data for performing 0 yen payment using the terminal identification number (TID=A) corresponding to the focused operation and transmits it to the affiliated credit card company server 200 (focused operation detection notification). Next, in the affiliated credit card company server 200, the credit payment processing unit 230 executes credit payment processing using the 0 yen authorization data received from the payment server 100, thereby recording the 0 yen authorization data in the authorization information 276.
[0063] In this way, the noted operation on the payment application 20 is recorded as 0 yen authorization data in the authorization information 276 together with the authorization data of the normal payment, so that the affiliated credit card company server 200 can perform fraud detection focusing on the operation on the payment application 20 within the framework of fraud detection based on the fraud detection rule 278. Furthermore, by managing the authorization information 276 in this manner, the operator of the affiliated credit card company can create new fraud detection rules based on the contents of the operation performed on the payment application 20 or review existing fraud detection rules. For example, the administrator can refer to the authorization information 276 (an example of support information) via the administrator terminal device 80 and perform maintenance of the fraud detection rules based on the contents of the operation performed on the payment application 20.
[0064] For example, if it is considered that an operation of changing registered information on the account information management screen PG4, then transitioning to the top-up screen PG2 to transfer funds is highly likely to be an operation aimed at fraudulent use, then by defining the screen transition as an unauthorized screen transition pattern in the fraud detection rule 278, it becomes possible for the affiliated credit card company server 200 to detect such an operation accompanied by a screen transition as an unauthorized operation. According to such a method of detecting screen transition, it is possible to detect any screen transition, not limited to an operation not aimed at fraudulent use. For example, if it is considered that an operation accompanied by a campaign screen PG1 or a stamp card screen PG3 is transitioned to the top-up screen PG2 to transfer funds after checking the campaign screen PG1 or the stamp card screen PG3, then it is highly likely to be an operation aimed at legitimate use, then by defining the screen transition as a legitimate screen transition pattern, it is possible for the affiliated credit card company server 200 to detect such an operation accompanied by a screen transition as a legitimate operation. In addition, whether an operation accompanied by a certain screen transition is considered to be a fraudulent operation or a legitimate operation may be determined depending on the duration of stay on each screen. For this reason, the definition of an unauthorized pattern or a legitimate pattern may include the duration of stay on each screen in addition to the screen transition pattern. In this case, the payment server 100 can recognize the duration of stay on each screen by calculating the interval during which 0 yen payments were made based on the authorization information 276.
[0065] The fraud detection rule 278 may include a rule for detecting fraudulent use based on authorization data of a normal payment, may include a rule for detecting fraudulent use based on a target operation performed on the payment application 20, or may include a rule for detecting fraudulent use by combining both. For example, the fraud detection rule may be one that determines that a normal payment is fraudulent if a target operation performed during a predetermined period prior to the payment satisfies a predetermined condition (e.g., conditions such as the type or combination of operations, the order of execution, the number of times of execution, and the interval between executions).
[0066] Also, for example, the fraud detection rules 278 may include a rule for excluding from fraudulent use a situation that was previously determined to be fraudulent use based on authorization data, based on a noted operation. For example, the fraud detection rules 278 have conventionally included a rule for determining fraudulent use when multiple payments have been made within a certain period of time in the past at a specific affiliated store when a normal payment is made (when authorization is made). The fraud detection rules 278 may include a rule for not determining fraudulent use in such a situation that would have been determined to be fraudulent use based on the conventional fraud detection rules, if a certain screen transition (a specific noted operation or a combination thereof) occurs between the multiple payments. In this way, by adding a rule based on a noted operation to the conventional fraud detection rules, it is possible to set more accurate fraud detection rules.
[0067] According to the embodiment described above, in a system that detects fraudulent use of a credit card based on authorization data, it is possible to determine whether or not a use has occurred by taking into consideration user behavior that is not linked to the authorization data. For example, in a mechanism that detects fraudulent use of a credit card based on authorization data, it is possible to take into consideration the content of operations performed on the payment application 20 running on the user terminal device 10.
[0068] <Modification> In the above embodiment, a unique terminal identification number is assigned to all screens of the payment application 20, and the payment server 100 detects the target operation based on the target operation information 178 and the operation information received from the payment application 20. However, the terminal identification number as the operation information may be assigned only to the target screen among the screens of the payment application 20. In this case, the terminal identification number is notified to the payment server 100 only when the target operation is performed in the payment application 20. Therefore, in this case, the payment server 100 may be configured to generate 0 yen authorization data only for the operation for which the terminal identification number is notified.
[0069] The payment application 20 may be configured to restrict some of the functions provided by the payment application 20 when the attention operation detection notification is transmitted. For example, in the example of FIG. 12, the payment application 20 may restrict the use of the top-up screen PG2 (TID=B) to temporarily disable fund transfer. Also, for example, in the example of FIG. 12, the payment application 20 may restrict the use of the account information management screen PG4 (TID=D) to temporarily disable account information change. The payment application 20 may be configured to release the above-mentioned function restriction in response to an instruction from the affiliated credit card company server 200. On the other hand, after receiving the attention operation detection notification from the payment application 20, the affiliated credit card company server 200 may instruct the payment application 20 to release the above-mentioned function restriction when a predetermined condition is satisfied with respect to the payment application 20 that is the transmission source. The predetermined condition may be that a predetermined time has elapsed since the start of the function restriction, or that it has been confirmed that the operation detected as the attention operation is not intended for fraudulent use. The affiliated credit card company server 200 may be configured to notify the payment application 20 of these release instructions via the payment server 100. Furthermore, the function restriction may be implemented in response to the detection of one focused operation, or in response to the detection of a combination of multiple focused operations or the detection of multiple focused operations.
[0070] When affiliated credit card company server 200 detects fraudulent use of affiliated card 57 not due to the target operation (for example, when fraudulent use is detected only from authorization data of normal payment), it may be configured to notify payment application 20 of that fact. In this case, payment application 20 may be configured to restrict some of the functions provided by payment application 20 in response to receiving the notification. Also in this case, similarly to the above, payment application 20 may be configured to release the above-mentioned function restrictions in response to an instruction from affiliated credit card company server 200.
[0071] The affiliated credit card company server 200 may be configured to analyze the tendency of fraudulent use based on the occurrence of fraudulent use recognized by the noted operation and the occurrence of fraudulent use detected based on the authorization data of normal payment. For example, the affiliated credit card company server 200 may be configured to learn the noted operation or a combination thereof that is likely to occur at the timing of the fraudulent use based on the detection result of the fraudulent use based on the authorization data. Conversely, when there is fraudulent use that cannot be detected by the authorization data, the affiliated credit card company server 200 may be configured to learn the characteristics of the noted operation or a combination thereof that occurred at the timing of the fraudulent use. A machine learning algorithm (e.g., supervised learning) may be used for these learnings.
[0072] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]
[0073] 10 User terminal device 20. Payment App 50 First store terminal device 55 Credit card processing terminal 57 Affiliated Cards 60 Store Code Image 70 Second store terminal device 72 Merchant Interface 80 Administrator terminal device 82 Management App 100 Payment Server 110 Communications Department 120 Payment Contents Provider 130 Payment processing unit 140 Information Management Department 150 Attention operation detection unit 170 Storage section 172 User information 174 Payment Content Information 176 Affiliated Stores / Store Information 178 Important Operation Information 200 Affiliated credit card company server 210 Communications Department 230 Credit card payment processing unit 240 Information Management Department 250 Fraud Detection Department 270 Storage section 272 Card payment setting information 274 User information 276 Authorization Information 278 Fraud Detection Rules
Claims
1. A payment management device that provides an electronic payment service to a user in cooperation with an application program running on a terminal device of the user, an acquisition unit that acquires operation information related to an operation performed by the user on the application program from the application program; a detection unit that detects a specific operation performed on the application program based on the operation information; Equipped with When the detection unit detects that the specific operation has been performed on the application program, the detection unit transmits information for recording the occurrence of the specific operation to a credit settlement management device that manages credit cards registered in the application program. Payment management device.
2. the detection unit preliminarily stores operation definition information in which the specific operation to be detected is defined, and determines whether an operation performed on the application program is the specific operation based on the operation information and the operation definition information; The payment management device according to claim 1 .
3. The specific operations are each associated in advance with unique identification information, the application program is configured to, when the specific operation is performed, transmit the operation information including the identification information corresponding to the specific operation to the payment management device; The detection unit detects that the specific operation has been performed on the application program based on the identification information included in the operation information. The payment management device according to claim 1 .
4. the credit card payment management device executes a credit card payment process for a designated amount based on authorization data requesting a credit card payment using the credit card; The detection unit transmits specific authorization data requesting a specific credit payment with a payment amount of 0 yen to the credit payment management device as information for recording the occurrence of the specific operation. The payment management device according to claim 1 .
5. The detection unit transmits operation information regarding the specific operation to the credit settlement management device in association with the specific authorization data. The payment management device according to claim 4.
6. The authorization data includes a terminal identification number for uniquely identifying an implementation terminal of the target payment, the detection unit generates the specific authorization data using a terminal identification number used for a specific credit payment in which the payment amount is 0 yen, the terminal identification number being assigned so as not to overlap with terminal identification numbers used in normal credit payments; The payment management device according to claim 4.
7. a payment management device for providing an electronic payment service to a user in cooperation with an application program running on the user's terminal device, acquiring operation information relating to an operation performed by the user on the application program from the application program; Detecting a specific operation performed on the application program based on the operation information; when detecting that the specific operation has been performed on the application program, transmitting information for recording the occurrence of the specific operation to a credit card settlement management device that manages the credit cards registered in the application program; Payment management methods.
8. A payment management device that provides an electronic payment service to a user in cooperation with an application program that runs on the user's terminal device, acquiring operation information relating to an operation performed by the user on the application program from the application program; detecting a specific operation performed on the application program based on the operation information; when it is detected that the specific operation has been performed on the application program, transmitting information for recording the occurrence of the specific operation to a credit settlement management device that manages the credit cards registered in the application program; Program for.
9. A payment management system comprising: a payment management device that provides an electronic payment service to a user in cooperation with an application program that runs on a terminal device of the user; and a credit card payment management device that manages credit cards registered in the application program, The payment management device, an acquisition unit that acquires operation information related to an operation performed by the user on the application program from the application program; a detection unit that detects a specific operation performed on the application program based on the operation information; Equipped with when the detection unit detects that the specific operation has been performed on the application program, the detection unit transmits information for recording the occurrence of the specific operation to a credit settlement management device that manages credit cards registered in the application program, the credit card transaction management device executes a credit card transaction process in which the transaction amount is set to 0 yen based on the information for recording the occurrence of the specific operation received from the transaction management device, thereby recording the occurrence of the specific operation; Payment management system.
10. The detection unit detects fraudulent use of the credit card based on authorization data received during normal credit card payment processing and a record indicating the occurrence of the specific operation. The payment management system according to claim 9.
Citation Information
Patent Citations
Determination system, determination method, and program
JP7190072B1
Monitoring assistance device
WO2015071980A1
Calculation program and method for illegal determination score value, and calculation system for illegal determination score value of credit card
JP2004334526A
History information addition program, fraudulent determination program using history information, and fraudulent determination system using history information
JP2004348536A
Cited By
Steering shaft assembly for a materials handling vehicle
US12509337B2