Information processing device and method

The information processing device verifies user identity through line authentication and additional methods to ensure secure payment processing, addressing the challenge of unauthorized transactions in existing systems.

JP2025122976AActive Publication Date: 2025-08-22NTT DOCOMO INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024018758
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-09
Publication Date
2025-08-22
Estimated Expiration
2044-02-09

AI Technical Summary

Technical Problem

Existing payment systems lack the ability to verify user identity effectively before permitting or prohibiting payment processing, leading to potential fraudulent activities.

Method used

An information processing device and method that utilizes line authentication and user-specific authentication information to confirm the identity of a user before allowing or denying payment transactions, incorporating additional methods like eKYC and JPKI for enhanced security.

Benefits of technology

Ensures that payment processing is permitted only after verifying the user's identity, reducing the risk of fraudulent transactions and enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025122976000001_ABST
    Figure 2025122976000001_ABST
Patent Text Reader

Abstract

To allow or prohibit settlement processing after identity confirmation of a user when a settlement request from the user matches a condition for prohibiting the settlement processing.SOLUTION: An information processing device includes: a confirmation unit 35 that, when a settlement request for which settlement processing is prohibited is made from a terminal of a user via a communication network, confirms identity of the user using a first method that uses line authentication using a line to which the user subscribes and authentication information registered for the user; and an allowance unit 36 that allows the settlement processing for the user when the identity of the user is confirmed by the confirmation unit 35.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technology for verifying the identity of a user who uses a payment service. [Background technology]

[0002] With the widespread use of user terminals such as smartphones, payment services that use the user terminals to make electronic payments are becoming more widely used. This type of service requires user identity verification, and Patent Document 1, for example, describes that when a payment device on the store side accepts a payment request, it outputs multiple countermeasures, such as suspending the transaction for a certain period of time until the user's identity can be verified, based on the user's attribute information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7000503 Summary of the Invention [Problem to be solved by the invention]

[0004] The present invention aims to permit or prohibit the payment process after verifying the identity of the user when a payment request from the user matches the conditions for prohibiting the payment process. [Means for solving the problem]

[0005] In order to solve the above problems, the present invention provides an information processing device comprising: a confirmation unit that, when a payment request for which payment processing is prohibited via a communication network is made, confirms the identity of the user using a first method that uses line authentication using a line subscribed to by the user and authentication information registered for the user, and an approval unit that allows the payment processing for the user if the identity of the user is confirmed by the confirmation unit.The present invention also provides an information processing method that, when a payment request for which payment processing is prohibited via a communication network is made by a user, comprises: a step of confirming the identity of the user using a first method that uses line authentication using a line subscribed to by the user and authentication information registered for the user, and a step of allowing the payment processing for the user if the identity of the user is confirmed. [Effects of the Invention]

[0006] According to the present invention, when a payment request from a user matches the conditions for prohibiting payment processing, the payment processing can be permitted or prohibited after verifying the identity of the user. [Brief explanation of the drawings]

[0007] [Figure 1] 1 is a diagram showing an example of a configuration of an information processing system 1 according to a first embodiment of the present invention. [Figure 2] 2 is a diagram illustrating an example of a hardware configuration of a server device 30 according to the first embodiment. FIG. [Figure 3] 1 is a diagram illustrating an example of a hardware configuration of a user terminal 10 according to the first embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a server device 30 according to the first embodiment. [Figure 5] 3 is a diagram illustrating an example of authentication information stored in the server device 30 according to the first embodiment. FIG. [Figure 6] 3 is a diagram illustrating a payment history stored by the server device 30 according to the first embodiment. FIG. [Figure 7]FIG. 10 is a sequence diagram showing an example of the operation of the information processing system 1 in the first embodiment when a payment request from a user does not meet the conditions for prohibiting payment processing. [Figure 8] FIG. 10 is a sequence diagram showing an example of the operation of the information processing system 1 when a payment request from a user matches a condition for prohibiting payment processing in the first embodiment. [Figure 9] FIG. 10 is a diagram showing an example of the configuration of an information processing system 1a according to a second embodiment of the present invention. [Figure 10] FIG. 11 is a sequence diagram showing an example of the operation of the information processing system 1a in the second embodiment when a payment request from a user matches a condition for prohibiting payment processing. [Figure 11] FIG. 10 is a diagram illustrating an example of a functional configuration of a server device 30a according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0008] [First embodiment] [composition] FIG. 1 is a diagram illustrating an example of the configuration of an information processing system 1 according to a first embodiment of the present invention. The information processing system 1 is a system for electronically performing payments in commercial transactions in which a user pays for goods or services at a store or the like. This embodiment is based on the premise that a payment service known as barcode payment is used, in which a user terminal 10 in FIG. 1 displays a barcode, which is then read by a store terminal 20 in FIG. 1 to initiate the payment service. This embodiment is also based on the premise that a payment service known as combined communication fee payment is used, in which a communication carrier providing communication services to the user terminal 10 in FIG. 1 collects from the user the communication fees collected from the user as payment for the communication services, as well as the payment for goods or services at a store or the like. However, the types of payment services used in the present invention are not limited to these examples.

[0009] As shown in FIG. 1, the information processing system 1 includes a user terminal 10 used by a user, a store terminal 20 installed in a store or the like, a server device 30 corresponding to the information processing device of the present invention, and a communication network 2 including a wireless communication network or a wired communication network that communicatively connects these devices. The user terminal 10, the store terminal 20, and the server device 30 are all computers capable of communication. More specifically, the user terminal 10 is a computer that can be carried by a user, such as a smartphone, a wearable device, or a tablet. The store terminal 20 is a terminal operated in a store and may be, for example, a computer integrated with a point-of-sale (POS) register or a computer connected to a POS register, or a computer called a payment terminal. The server device 30 may be composed of a single computer or multiple computers. Note that while FIG. 1 shows one user terminal, one store terminal, and one server device, there may be multiple of each.

[0010] FIG. 2 is a diagram showing the hardware configuration of the server device 30. The server device 30 is physically configured as a computer including a processor 3001, a memory 3002, a storage 3003, a communication device 3004, an input device 3005, an output device 3006, and a bus connecting these devices. Each of these devices operates using power supplied from a battery (not shown). In the following description, the term "device" can be interpreted as a circuit, a device, a unit, or the like. The hardware configuration of the server device 30 may be configured to include one or more of the devices shown in FIG. 2, or may be configured without including some of the devices. Furthermore, the server device 30 may be configured by communicating with multiple devices each having a different housing.

[0011] Each function in the server device 30 is realized by loading predetermined software (programs) onto hardware such as the processor 3001 and memory 3002, causing the processor 3001 to perform calculations, control communication via the communication device 3004, and control at least one of reading and writing data in the memory 3002 and storage 3003.

[0012] The processor 3001 controls the entire computer by running, for example, an operating system. The processor 3001 may be configured as a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic unit, a register, etc. Furthermore, for example, a baseband signal processing unit, a call processing unit, etc. may be realized by the processor 3001.

[0013] The processor 3001 reads programs (program codes), software modules, data, etc. from at least one of the storage 3003 and the communication device 3004 into the memory 3002, and executes various processes in accordance with these. The programs used are those that cause a computer to execute at least some of the operations described below. The functional blocks of the server device 30 may be implemented by a control program stored in the memory 3002 and running on the processor 3001. Various processes may be executed by one processor 3001, or may be executed simultaneously or sequentially by two or more processors 3001. The processor 3001 may be implemented by one or more chips. The programs may be transmitted to the server device 30 via a telecommunications line.

[0014] The memory 3002 is a computer-readable recording medium and may be configured by, for example, at least one of a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), an EEPROM (Electrically Erasable Programmable ROM), a RAM (Random Access Memory), etc. The memory 3002 may also be called a register, a cache, a main memory (primary storage device), etc. The memory 3002 can store an executable program (program code), a software module, etc. for implementing the method according to this embodiment.

[0015] Storage 3003 is a computer-readable recording medium, and may be constituted by at least one of, for example, an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. Storage 3003 may also be referred to as an auxiliary storage device.

[0016] The communication device 3004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also called, for example, a network device, a network controller, a network card, or a communication module. Each device, such as the processor 3001 and the memory 3002, is connected by a bus for communicating information. The bus may be configured using a single bus, or may be configured using different buses between each device.

[0017] The server device 30 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 3001 may be implemented using at least one of these pieces of hardware.

[0018] 3 is a diagram showing an example of the hardware configuration of the user terminal 10. The user terminal 10 is a computer such as a smartphone, a mobile phone, a tablet, or a wearable terminal. The user terminal 10 is physically configured as a computer device including a processor 1001, a memory 1002, a storage 1003, a communication device 1004, an input device 1005, an output device 1006, and a bus connecting these. The processor 1001, the memory 1002, and the storage 1003 are the same hardware as the processor 3001, the memory 3002, and the storage 3003 of the server device 30.

[0019] The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc., to realize at least one of Frequency Division Duplex (FDD) and Time Division Duplex (TDD). For example, a transmitting / receiving antenna, an amplifier unit, a transmitting / receiving unit, a transmission path interface, etc. may be realized by the communication device 1004. The transmitting / receiving unit may be implemented as a transmitting unit and a receiving unit that are physically or logically separated.

[0020] The input device 1005 is an input device (for example, a key, a microphone, a switch, a button, a sensor, etc.) that receives input from the outside. The output device 1006 is an output device (for example, a display, a speaker, an LED lamp, etc.) that outputs to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (for example, a touch screen).

[0021] 4 is a block diagram showing the functional configuration of server device 30. In server device 30, processor 3001 reads programs and the like from storage 3003 to memory 3002 and executes them, thereby realizing the functions of payment request acquisition unit 31, payment permission determination unit 32, payment processing unit 33, payment suspension notification unit 34, confirmation unit 35, and permission unit 36.

[0022] The payment request acquisition unit 31 acquires a payment request from the store terminal 20 or the user terminal 10 via the communication network 2. This payment request includes the payment amount as well as information for identifying the store terminal 20 and the user terminal 10, respectively.

[0023] The payment permission determination unit 32 determines whether or not a payment request acquired by the payment request acquisition unit 31 satisfies predetermined payment prohibition conditions that prohibit payment processing. These payment prohibition conditions are determined arbitrarily by the payment service provider (here, a telecommunications carrier), and may be, for example, that the payment amount is y yen or more or the number of payments is z or more within x days of the account used for payment being opened. These payment prohibition conditions are stored in the payment permission determination unit 32. In addition, in order to determine whether or not a payment request satisfies the payment prohibition conditions, the payment permission determination unit 32 stores payment history in association with a user ID that identifies the user, as shown in FIG. 6.

[0024] The payment processing unit 33 performs a process of collecting the payment amount from the user in accordance with predetermined rules, i.e., a payment process. If the payment permission determination unit 32 determines that the payment request does not match the payment prohibition conditions, i.e., that the payment is permitted, the payment processing unit 33 immediately performs a payment process according to the payment request acquired by the payment request acquisition unit 31.

[0025] When the payment possibility determination unit 32 determines that the payment request meets the payment prohibition conditions, i.e., that the payment is not permitted, the payment suspension notification unit 34 notifies the store terminal 20 or the user terminal 10 via the communication network 2 that the payment is not permitted.

[0026] When the payment permission determination unit 32 determines that the payment request meets the payment prohibition condition, i.e., that the payment is not permitted, the confirmation unit 35 confirms the identity of the user using an identity confirmation method (hereinafter referred to as the first method) that uses line authentication using the line subscribed to by the user and user authentication using the password registered for the user before performing the payment processing related to the payment request. The line authentication here refers to an authentication process in which the line number assigned to the user terminal 10 is confirmed in the communication network 2 to confirm that the user terminal 10 is a terminal of a user who has a communication service contract with a telecommunications carrier. The password-based user authentication refers to an authentication process in which the identity of the user is confirmed by checking whether the password registered for the user matches the password entered into the user terminal 10 by the user. The password referred to here may be any information equivalent to authentication information that can only be known by the user who registered the user terminal 10. For this reason, the confirmation unit 35 stores the line number assigned to the user terminal 10 under the communication service contract and the password registered for the user who uses the user terminal 10 in association with each other, as illustrated in FIG. 5. This confirms that the user terminal 10 is the terminal of a user who has a contract for communication services with the communication carrier, and that the user knows the password registered for that user.

[0027] The permission unit 36 ​​allows the payment process for the user when the identity of the user is confirmed by the confirmation unit 35. When the payment process is allowed by the permission unit 36, the payment processing unit 33 performs the payment process according to the payment request acquired by the payment request acquisition unit 31.

[0028] As described above, in this embodiment, when a payment request from a user matches the conditions for prohibiting payment processing, the payment processing is permitted when the user's identity is confirmed.

[0029] [Operation] Next, the operation of the information processing system 1 according to the first embodiment will be described with reference to Figures 7 and 8. In the following description, for example, when the server device 30 is described as the subject of processing, this specifically means that the processor 3001 performs calculations by loading predetermined software (programs) onto hardware such as the processor 3001 and memory 3002, and controls communication via the communication device 3004 and reading and / or writing of data from and to the memory 3002 and storage 3003, thereby executing processing. The same applies to the user terminal 10.

[0030] [Behavior when payment request does not meet payment prohibition conditions] 7, the store terminal 20 or the user terminal 10 (here, the store terminal 20) transmits a payment request to the server device 30 via the communication network 2 (step S11). This payment request is acquired by the payment request acquisition unit 31 of the server device 30.

[0031] The payment permission determination unit 32 determines whether payment is permitted or not depending on whether the payment request acquired by the payment request acquisition unit 31 matches the payment prohibition condition (step S12).

[0032] If the payment permission determination unit 32 determines that the payment request does not meet the payment prohibition conditions, that is, that the payment is permitted, the payment processing unit 33 immediately performs payment processing according to the payment request acquired by the payment request acquisition unit 31 (step S13).Then, the payment processing unit 33 transmits a payment completion notification to the store terminal 20 and the user terminal 10 (steps S14 and S15).

[0033] [Behavior when payment request matches payment prohibition conditions] 8, the store terminal 20 or the user terminal 10 (here, the store terminal 20) transmits a payment request to the server device 30 via the communication network 2 (step S11). This payment request is acquired by the payment request acquisition unit 31 of the server device 30.

[0034] The payment permission determination unit 32 determines whether payment is permitted or not depending on whether the payment request acquired by the payment request acquisition unit 31 matches the payment prohibition condition (step S12).

[0035] Here, if the payment possibility determination unit 32 determines that the payment request meets the payment prohibition conditions, that is, that the payment is not permitted, the payment suspension notification unit 34 notifies the store terminal 20 or the user terminal 10 (here, the store terminal 20 and the user terminal 10) that the payment is not permitted via the communication network 2 (steps S111, S112).

[0036] When the user confirms this notification of payment denial on the user terminal 10, the user performs an operation to request identity verification using line authentication using the line subscribed to by the user and user authentication using the password registered for the user. Specifically, in response to the above notification, the user terminal 10 displays soft buttons to be selected when requesting identity verification and a text box for entering a password, and the user enters a password according to this display and performs an operation to select a soft button. In response to this operation, the user terminal 10 transmits an identity verification request including the entered password to the server device 30 via the communication network 2 (step S113).

[0037] The confirmation unit 35 confirms the identity of the user by using the first method using the above-mentioned line authentication and user authentication by password (step S114). That is, when a payment request is made by a user who is prohibited from making a payment via the communication network 2, the confirmation unit 35 confirms the identity of the user by using the first method using line authentication using the line subscribed by the user and the password (authentication information) registered for the user.

[0038] When the user's identity is confirmed by the confirmation unit 35, the permission unit 36 ​​allows the payment process for that user (step S115). When the permission unit 36 ​​allows the payment process, the payment processing unit 33 performs payment processing according to the payment request acquired by the payment request acquisition unit 31 (step S116). Thereafter, similar to FIG. 7, the payment processing unit 33 transmits a payment completion notification to the store terminal 20 and the user terminal 10 (not shown).

[0039] If the verification unit 35 cannot verify the identity of the user using the first method, the permission unit 36 ​​will not permit the payment process, and the payment process by the payment processing unit 33 will not be performed.

[0040] According to the first embodiment described above, when a payment request from a user matches the conditions for prohibiting payment processing, the user's identity can be verified and then the payment processing can be permitted or prohibited.

[0041] [Second embodiment] In the first embodiment, the identity of the user was confirmed using a first method that used line authentication and user authentication by password. In the second embodiment described below, in addition to the first method, the identity of the user is confirmed by using a method that mainly confirms the existence of the user, specifically, a second method that confirms the identity via a network using data read from an IC chip held by the user, or a third method that confirms the identity using a public personal authentication service. Confirming the existence of the user means confirming whether the user actually exists, whether the information and attributes submitted by the user are correct, or whether the information and attributes are related to the user.

[0042] More specifically, the second method includes eKYC (electronic Know Your Customer). eKYC includes two methods: (1) in which a user takes a photograph of their own face and a facial image included in an identity verification document and uploads them; and (2) in which a user takes a photograph of their own face and reads an IC chip in a driver's license or the like with a user terminal to verify their identity. The second embodiment uses the (3) method.

[0043] The third method involves JPKI (Japanese Public Key Infrastructure), which is a method of identity verification used to prevent impersonation and data tampering by others during online procedures, using a "digital signature certificate" or "digital user certificate" recorded on the IC chip of a My Number card.

[0044] [composition] As shown in Figure 9, the information processing system 1a according to the second embodiment includes a user terminal 10 used by a user, a store terminal 20 installed in a store or the like, a server device 30 corresponding to the information processing device of the present invention, an IC chip 40 embedded in the driver's license or My Number card held by the user, an online authentication system 50 that verifies the identity of the user via a communication network 2 using data read from the IC chip, and a public personal authentication system 60 that verifies the identity of the user using a public personal authentication service.

[0045] [Operation] Next, a description will be given of the operation of the information processing system 1a according to the second embodiment. The operation when the payment request does not match the payment prohibition condition is the same as in the first embodiment, and therefore the description will be omitted.

[0046] [Behavior when payment request matches payment prohibition conditions] 10, the store terminal 20 or the user terminal 10 (here, the store terminal 20) transmits a payment request to the server device 30 via the communication network 2 (step S11). This payment request is acquired by the payment request acquisition unit 31 of the server device 30.

[0047] The payment permission determination unit 32 determines whether payment is permitted or not depending on whether the payment request acquired by the payment request acquisition unit 31 matches the payment prohibition condition (step S12).

[0048] Here, if the payment possibility determination unit 32 determines that the payment request meets the payment prohibition conditions, that is, that the payment is not permitted, the payment suspension notification unit 34 notifies the store terminal 20 or the user terminal 10 (here, the store terminal 20 and the user terminal 10) that the payment is not permitted via the communication network 2 (steps S111, S112).

[0049] When the user confirms this notification of payment denial on the user terminal 10, the user performs an operation to request identity verification using line authentication using the line subscribed to by the user and user authentication using the password registered for the user. Specifically, in response to the above notification, the user terminal 10 displays soft buttons to be selected when requesting identity verification and a text box for entering a password, and the user enters a password according to this display and performs an operation to select a soft button. In response to this operation, the user terminal 10 transmits an identity verification request including the entered password to the server device 30 via the communication network 2 (step S113).

[0050] The verification unit 35 verifies the identity of the user using the first method using the line authentication and password-based user authentication described above (step S114).

[0051] Furthermore, the verification unit 35 verifies the identity of the user (step S119) in cooperation with the online authentication system 50 or the public personal authentication system 60 using the second or third method described above (step S118). When using the second method in cooperation with the online authentication system 50, the user takes a picture of his or her face with the user terminal 10, and then reads the IC chip 40 in the driver's license or the like with the user terminal 10 and uploads it to the online authentication system 50, etc., to perform authentication. When using the third method in cooperation with the public personal authentication system 60, the user is authenticated by reading the electronic certificate recorded on the IC chip 40 of the My Number card with the user terminal 10 and uploading it to the public personal authentication system 60, etc.

[0052] When the user's identity is confirmed by the verification unit 35 using the first method, the second method, or the third method, the permission unit 36 ​​allows the payment process for that user (step S120). When the payment process is allowed by the permission unit 36, the payment processing unit 33 performs payment processing according to the payment request acquired by the payment request acquisition unit 31 (step S121). Thereafter, similar to FIG. 7, the payment processing unit 33 transmits a payment completion notification to the store terminal 20 and the user terminal 10 (not shown).

[0053] If the confirmation unit 35 is unable to confirm the identity of the user using the first method, the second method, or the third method, the permission unit 36 ​​will not allow the payment process, and the payment process will not be performed by the payment processing unit 33.

[0054] According to the second embodiment described above, when a payment request from a user matches the conditions for prohibiting payment processing, the payment processing can be permitted or prohibited after verifying the identity of the user. In the first embodiment, there is a risk of fraudulent activity if a third party uses, for example, proxy-type malware that spoofs line authentication or if the user terminal 10 is stolen, but according to the second embodiment, this risk can be reduced.

[0055] [Variations] The present invention is not limited to the above-described embodiment. The above-described embodiment may be modified as follows. Furthermore, two or more of the following modifications may be combined and implemented.

[0056] [Variation 1] A fourth method including identity verification using a call may also be used. Specifically, in FIGS. 6, 7, and 10, the operator, having received a notice of payment rejection from the server device 30 at the operator terminal, makes a call to the user terminal 10, and confirms the identity by asking predetermined questions and confirmations, and then inputs the confirmation into the operator terminal. The confirmation unit 35 confirms the identity of the user in response to this input. When the identity of the user is confirmed by the confirmation unit 35, the permission unit 36 ​​allows the payment process for that user (step S120). In this way, the confirmation unit 35 may confirm the identity of the user using the fourth method of confirming the identity based on the result of the call to the user terminal 10. This further improves the accuracy of identity verification.

[0057] [Variation 2] The payment prohibition conditions may be changed depending on the credit risk assessment of the user. For example, the payment prohibition conditions may be tightened (making it easier to meet the payment prohibition conditions) when the credit risk is high, and relaxed (making it harder to meet the payment prohibition conditions) when the credit risk is low. In this case, as illustrated in FIG. 11, the server device 30a includes a risk assessment acquisition unit 37 that acquires information related to the risk assessment of the user. The verification unit 35 stores multiple payment prohibition conditions according to the level of the user's risk assessment, and when a user's payment request is acquired, the verification unit 35 verifies the user's identity based on the information acquired by the risk assessment acquisition unit 37 if the conditions according to the user's risk assessment are met. This allows the use of appropriate payment prohibition conditions according to the user's credit risk assessment.

[0058] [Variation 3] Identity verification may be performed using an appropriate method depending on the risk assessment of the user. For example, if the credit risk is low, identity verification may be performed using the first method, and if the credit risk is high, identity verification may be performed using the first method, the second method, or the third method. In this case, as illustrated in FIG. 11, the server device 30a includes a risk assessment acquisition unit 37 that acquires information regarding the risk assessment of the user. The verification unit 35 stores the identity verification method to be performed depending on the level of the risk assessment of the user, and when a payment request from the user is acquired, the identity of the user is verified using a method depending on the risk assessment of the user based on the information acquired by the risk assessment acquisition unit 37. In this way, the identity of the user can be verified using an appropriate method depending on the credit risk assessment of the user.

[0059] [Variation 4] If a payment request from a user terminal 10 of a certain user previously met the payment prohibition conditions and the identity of the user was confirmed, the confirmation unit 35 may not confirm the identity of the user if a payment request from the user terminal 10 of the same user subsequently meets the payment prohibition conditions again. This makes it possible to avoid duplicate identity confirmation.

[0060] [Other variations] The block diagrams used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may also be realized by combining the single device or multiple devices with software.

[0061] Functions include, but are not limited to, judgment, determination, assessment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, election, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.

[0062] For example, the server device 30 in one embodiment of the present disclosure may function as a computer that performs the processing of the present disclosure.

[0063] Each aspect / embodiment described in the present disclosure may be applied to at least one of systems using LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark), IEEE 802.20, UWB (Ultra-Wideband), Bluetooth (registered trademark), or other appropriate systems, and next-generation systems extended based on these. Furthermore, a combination of multiple systems (e.g., a combination of at least one of LTE and LTE-A with 5G, etc.) may also be applied.

[0064] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described in this disclosure may be changed unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order, and are not limited to the particular order presented.

[0065] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be sent to another device.

[0066] The determination may be made based on a value represented by one bit (0 or 1), a Boolean value (true or false), or a numerical comparison (e.g., comparison with a predetermined value).

[0067] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure.

[0068] Software, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise, shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc. Additionally, software, instructions, information, etc. may be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then such wired and / or wireless technologies are included within the definition of a transmission medium.

[0069] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof. In addition, terms explained in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings.

[0070] Furthermore, the information, parameters, etc. described in this disclosure may be expressed using absolute values, may be expressed using relative values ​​from a predetermined value, or may be expressed using other corresponding information.

[0071] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0072] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.

[0073] The "unit" in the configuration of each of the above devices may be replaced with "means," "circuit," "device," etc.

[0074] When used in this disclosure, the terms "include," "including," and variations thereof are intended to be inclusive, similar to the term "comprising." Furthermore, when used in this disclosure, the term "or" is not intended to be an exclusive or.

[0075] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.

[0076] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different." [Explanation of symbols]

[0077] 1: Information processing system, 2: Communication network, 10: User terminal, 1001: Processor, 1002: Memory, 1003: Storage, 1004: Communication device, 1005: Input device, 1006: Output device, 20: Store terminal, 30: Server device, 3001: Processor, 3002: Memory, 3003: Storage, 3004: Communication device, 40: IC chip, 50: Online authentication system, 60: Public personal authentication system.

Claims

1. a confirmation unit that, when a payment request is made by a user who is prohibited from making payment via a communication network, confirms the identity of the user by using a first method that uses line authentication using a line subscribed to by the user and authentication information registered for the user; an authorization unit that authorizes a payment process for the user when the identity of the user is confirmed by the confirmation unit; An information processing device comprising:

2. The verification unit verifies the identity of the user using a second method of verifying the identity of the user via a communication network using data read from an IC chip held by the user.

2. The information processing apparatus according to claim 1, wherein:

3. The verification unit verifies the identity of the user using a third method for verifying the identity of the user by utilizing a public personal authentication service.

2. The information processing apparatus according to claim 1, wherein:

4. The verification unit verifies the identity of the user using a fourth method for verifying the identity of the user based on the result of a call made to the user's terminal.

3. The information processing apparatus according to claim 2.

5. an acquisition unit that acquires information regarding a risk assessment for the user; The confirmation unit performs the confirmation when the payment request matches a condition according to the risk assessment specified by the information.

2. The information processing apparatus according to claim 1, wherein:

6. an acquisition unit that acquires information regarding a risk assessment for the user; The confirmation unit performs the confirmation in a manner according to the risk assessment specified by the acquired information.

2. The information processing apparatus according to claim 1, wherein:

7. In the past, when the payment request of a certain user met the conditions for prohibiting payment processing and the identity of the user was confirmed, if the payment request of the same user again meets the conditions for prohibiting payment processing, the confirmation unit will not confirm the identity of the user.

2. The information processing apparatus according to claim 1, wherein:

8. When a payment request is made by a user who is prohibited from making a payment via a communication network, the step of verifying the identity of the user by using a first method that uses line authentication using a line subscribed to by the user and authentication information registered for the user; allowing the user to complete a payment process if the user's identity is confirmed; An information processing method comprising:

Citation Information

Patent Citations

  • Temporary settling number system, managing device of temporary settling number and computer-readable recording medium

    JP2001067396A

  • Principal confirming method and system using portable terminal

    JP2002183641A

  • Method and system for approving payment in card payment method

    JP2003168063A

  • Information processing method, information processing device, and program

    JP2021033460A

  • Settlement method and settlement system using portable terminal

    WO2010013296A1