Remittance device and remittance method
The remittance device and method ensure authorized transactions are executed by matching company-approved information with remittance details, effectively preventing and reducing fraud by halting unauthorized transactions.
Patent Information
- Application Number
- JP2024020542
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-14
- Publication Date
- 2025-08-26
AI Technical Summary
Existing bank transfer fraud targeting companies remains unsolved by current technologies, as they fail to verify if internal procedures are followed within the company, allowing fraudulent remittances to proceed without authorization.
A remittance device and method that registers approval information from the company and matches it with remittance information, executing the remittance only if the approval information matches, and canceling it if it does not, thereby ensuring authorized transactions are processed while halting unauthorized ones.
This approach reduces damage from bank transfer fraud by stopping unauthorized remittances, enhancing security and reliability in financial transactions for companies.
Smart Images

Figure 2025124465000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a money transfer device and a money transfer method. [Background technology]
[0002] In recent years, there has been a surge in bank transfer scams targeting the elderly, known as "ore-ore scams." Bank transfer scams involve perpetrators pretending to be close relatives or police officers and instructing victims to transfer money over the phone. According to the Tokyo Metropolitan Police Department, special frauds, including bank transfer scams, caused losses of 37 billion yen nationwide in 2022.
[0003] In addition to these types of frauds targeting individuals, bank transfer frauds targeting companies are also on the rise. As not all damages from bank transfer frauds targeting companies have been made public, the exact figures are unknown, but the total amount of damage is said to be greater than that from bank transfer frauds targeting individuals. In bank transfer frauds targeting companies, the amount of money transferred per transaction is large, and the methods used by criminals are becoming more sophisticated. Patent Document 1 describes technology to reduce damages from bank transfer frauds. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-168190 Summary of the Invention [Problem to be solved by the invention]
[0005] Patent Document 1 is a technology for preventing remittance fraud targeting individuals, in which when a remittance requester inputs a remittance request into a bank ATM (automated teller machine), the remittance control system notifies other remittance authorizers that a remittance request has been made, and executes the remittance request input by the remittance requester only if the permission of the remittance authorizer is confirmed. However, Patent Document 1 is a technology for preventing remittance fraud targeting individuals, and does not take into consideration remittance fraud targeting companies.
[0006] The following methods are used in bank transfer fraud targeting businesses:
[0007] Method 1: Impersonating a company executive and instructing the accountant to transfer funds urgently to a fake bank account.
[0008] Method 2: Impersonating a lawyer affiliated with a company and requesting money transfers for urgent and confidential matters.
[0009] Method 3: Impersonating a corporate client (a client to whom payments have been made in the past) and using a fake invoice to trick the victim into sending money.
[0010] Method 4: Impersonating a company's accounting officer and issuing instructions for a fake remittance. For example, by infiltrating a company's network from the outside and contacting the accounting officer directly, the perpetrator obtains information such as passwords related to remittances and then impersonates the accounting officer.
[0011] Methods 1 and 2 involve tricking accounting staff into processing a remittance without requiring them to go through any internal procedures within the company. To prevent these types of remittance fraud, banks simply need to verify whether internal procedures are being followed within the company. Generally, when a company purchases materials or uses services, the accounting staff instructs the bank to remit (pay) the remittance to the client after going through internal procedures based on the amount and content of the transaction. However, banks cannot verify whether the remittance instructions issued by the accounting staff have gone through internal procedures. Therefore, even if an accounting staff member is tricked into issuing a remittance instruction, they cannot cancel the remittance. While it may be conceivable for a bank employee to confirm with the company's decision maker by phone or email, this is not practical.
[0012] When a company receives a fake invoice using Method 3, the normal internal procedure is to check the delivery note and determine whether or not to remit the money. In other words, even if a fake invoice arrives, if there is no delivery note, the remittance will not be processed. However, it is possible to combine fake invoices with Methods 1 and 2 to make the transaction appear unusual, allowing the remittance to be processed without any internal procedures.
[0013] Method 4 involves a cyber attack on a company's network from the outside, resulting in the theft of company information. There is also the possibility of criminals directly contacting company employees and using social engineering to steal information. In either case, criminals steal information such as passwords related to company remittances, and then send false remittance instructions to the bank to carry out the transfer. Countermeasures for this method include strengthening internal cybersecurity measures and employee information management, but there is no 100% solution to cyber attacks.
[0014] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a technology that can stop remittances that have not been approved by the company, thereby reducing the damage caused by bank transfer fraud targeting companies. [Means for solving the problem]
[0015] In order to achieve the above-mentioned object, one embodiment of the remittance device of the present invention comprises a registration unit that receives approval information sent from the remittance source company and registers it in a memory unit, and also receives remittance information sent from the company and registers it in the memory unit, and an execution unit that executes the remittance if the approval information included in the remittance information matches the approval information registered in the memory unit, and cancels the remittance if they do not match.
[0016] One aspect of the present invention is a remittance method performed by a remittance device, which receives approval information sent from a remittance source company and registers it in a memory unit, receives remittance information sent from the company, and executes the remittance if the approval information included in the remittance information matches the approval information registered in the memory unit, and cancels the remittance if they do not match.
[0017] One aspect of the present invention comprises a registration unit that receives individual remittance information sent from a remittance source company and registers it in a memory unit, and that separately receives the value calculated by the company before the remittance date from the approval information and registers it in the memory unit; and an execution unit that extracts remittance information for the day of remittance from the individual remittance information in the memory unit, calculates the total remittance amount, and executes each remittance for that day if the calculated total matches the total amount for the day of remittance that was separately received and registered in the memory unit, and if they do not match, cancels each remittance for that day.
[0018] One aspect of the present invention is a remittance method performed by a remittance device, in which individual remittance information sent from the remitting company is received and registered in a memory unit, the company calculates the total remittance amount for the remittance date from the approval information before the remittance date and separately receives and registers the transmitted value in the memory unit, individual remittance information corresponding to the remittance date is extracted from the memory unit to calculate the total remittance amount, and if the calculated total amount matches the total amount for the remittance date received separately and registered in the memory unit, individual remittances for that day are executed, and if they do not match, individual remittances for that day are canceled. [Effects of the Invention]
[0019] According to the present invention, it is possible to provide a technology that can reduce damage caused by bank transfer fraud targeting companies by stopping remittances that have not been approved by the company. [Brief explanation of the drawings]
[0020] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a system according to the first embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the approval information according to the first embodiment. [Figure 3] FIG. 3 is a sequence diagram showing the processing of the remittance instruction terminal and the remittance device of the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of authentication information according to the first embodiment. [Figure 5]FIG. 5 is a diagram showing an example of remittance information according to the first embodiment. [Figure 6] FIG. 6 is a flowchart showing the process of the remittance device according to the modified example of the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of the configuration of a system according to the second embodiment including the first embodiment. [Figure 8] FIG. 8 is a sequence diagram showing the processing of the remittance instruction terminal and the remittance device of the second embodiment including the first embodiment. [Figure 9] FIG. 9 is a diagram illustrating an example of the approval information according to the second embodiment. [Figure 10] FIG. 10 is a flowchart showing the process of the remittance device according to a modification of the second embodiment including the first embodiment. [Figure 11] FIG. 11 shows an example of the hardware configuration of a remittance device. DETAILED DESCRIPTION OF THE INVENTION
[0021] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the drawings, the same reference numerals are used to denote the same parts, and the description thereof will not be repeated.
[0022] First Embodiment (System Configuration) Figure 1 is a diagram showing the overall configuration of the system of the first embodiment. The system shown in the figure comprises an electronic settlement device 1 and a remittance instruction terminal 2 provided by a remittance source company, and a remittance device 3 provided by a financial institution such as a bank (hereinafter referred to as "bank, etc.").
[0023] In the illustrated example, one company is shown, but multiple companies may instruct a bank or the like to remit funds. The company may be a public company, a public-private mixed company, or a private company, and may be a for-profit company or a non-profit company. Furthermore, the company in this embodiment may include an organization or group such as an NPO corporation.
[0024] The electronic payment device 1 is a device that electronically performs payment processing (internal procedures) for, for example, purchasing goods, investing in third parties, etc. The payment device 1 may be a payment system equipped with multiple computers.
[0025] The remittance instruction terminal 2 is a computer operated by a company employee. The remittance instruction terminal 2 accepts operations from the employee and transmits instructions corresponding to the operations to the remittance device 3 of the bank or the like. The remittance instruction terminal 2 is equipped with a predetermined application program, a web browser, etc. The remittance instruction terminal 2 can communicate with the remittance device 3 of the bank or the like using a predetermined communication protocol (e.g., TCP / IP). The electronic settlement device 1 and the remittance instruction terminal 2 are generally not connected, but the electronic settlement device 1 and the remittance instruction terminal 2 may be connected via a network (not shown).
[0026] The remittance instruction terminal 2 is also a terminal that provides remote access to the remittance device 3. In order to restrict remote access to or remote operation of the remittance device 3 by unauthorized persons, the remittance instruction terminal 2 preferably has an authentication function for authenticating users. The authentication function may use ID authentication using a login ID and password, or may use IC card authentication in which an IC card held by the user is read with an IC card reader or the like. In this embodiment, the remittance instruction terminal 2 is operated by an accounting clerk who instructs a bank or the like to remit money, and an authorizer who approves the payment using the electronic authorization device 1. For this reason, the authentication information of the accounting clerk and the authorizer is pre-registered in the remittance instruction terminal 2.
[0027] The remittance device 3 provided by a bank or the like receives remittance instructions from the user company (remitter) via a network and executes remittance processing to remit money to the recipient's account in accordance with the remittance instructions. The remittance device 3 may be a remittance system equipped with multiple computers. The remittance device 3 is connected to the company's remittance instruction terminal 2 via a network.
[0028] The remittance device 3 shown in the figure comprises an authentication unit 31, a registration unit 32, an execution unit 33, an authentication information storage unit , an approval information storage unit 35, and a remittance information storage unit .
[0029] The authentication information storage unit 34 stores in advance the authentication information of the settler and the accounting staff for each remittance source company. The authentication unit 31 may authenticate the settler using the login information of the settler transmitted from the company's remittance instruction terminal 2 and the authentication information stored in the authentication information storage unit 34. The authentication unit 31 may authenticate the accounting staff using the login information of the accounting staff transmitted from the company's remittance instruction terminal 2 and the authentication information stored in the authentication information storage unit 34.
[0030] The registration unit 32 receives the approval information sent from the remittance source company and registers it in the approval information storage unit 35 .
[0031] The execution unit 33 receives remittance information sent from a company, and if the approval information corresponding to the remittance information is stored in the approval information storage unit 35, executes the remittance specified in the remittance information, and if the approval information corresponding to the remittance information is not stored in the approval information storage unit 35, cancels the remittance specified in the remittance information.
[0032] The execution unit 33 may identify from the approval information storage unit 35 the approval information having the same approval number as the approval number set in the remittance information, and execute the remittance specified in the remittance information if the remittance amount set in the remittance information matches the transaction amount (remittance amount) of the identified approval information.
[0033] The approval information storage unit 35 registers the approval information transmitted from the remittance instruction terminal 2. The remittance information storage unit 36 stores the remittance information transmitted from the remittance instruction terminal 2. The approval information and remittance information will be described later.
[0034] Next, the processing of this embodiment will be described. The processing of this embodiment includes an electronic settlement processing, a pre-registration processing, and a remittance processing.
[0035] (Electronic approval processing) First, the electronic approval process in a company or the like will be explained using Figure 1. The initiator logs in to the electronic approval device 1 and inputs the transaction information for which approval is desired into the electronic approval device 1 (S1). The transaction information includes, for example, the name of the business partner, the transaction amount, and the payment date. The initiator may input the transaction information into the electronic approval device 1 using an input device of the electronic approval device 1, or may log in to the electronic approval device 1 using the initiator's terminal (not shown) and input the transaction information into the electronic approval device 1.
[0036] When the transaction information is input, the electronic settlement device 1 sends a notification to the authorizer's terminal, using a predetermined communication means such as e-mail, requesting approval of the transaction information (S2). When the authorizer receives the notification from the electronic settlement device 1, he logs in to the electronic settlement device 1 using a terminal (not shown) and displays (outputs) the transaction information on the terminal's output device. If the authorizer determines that the displayed transaction information is appropriate, he inputs approval of the transaction information into the electronic settlement device 1 using his terminal (S3).
[0037] In addition, for transaction information such as the purchase of high-value goods or investment projects, in addition to the approver, there may be at least one appraiser (not shown) involved in approving the transaction information. In this case, the electronic approval device 1 may send a notification to each appraiser requesting their approval of the transaction information before sending the notification of S2 to the approver's terminal. The means of notification to the appraisers may be the same communication means as that used by the approver. Upon receiving the notification from the electronic approval device 1, the appraiser logs in to the electronic approval device 1, just like the approver, and enters their approval of the transaction information into the electronic approval device 1. In this case, once the approvals of all appraisers have been entered, the electronic approval device 1 sends a notification to the terminal of the approver who makes the final decision (S2), and the approver may approve the transaction information at this time (S3).
[0038] When approval by the authorizer (and all accountants) is completed, the electronic approval device 1 assigns an approval number, generates approval information based on the approved transaction information, and stores it in the memory unit 11. The approval number is identification information that can uniquely identify the approved transaction.
[0039] 2 is a diagram showing an example of approval information. The approval information shown in the figure includes information related to approval, such as the approval number, the date on which the drafter proposed the proposal, the name of the person who made the request, the name of the approver, the date on which the approver approved the proposal, the approval number, the name of the client (remittance destination), the transaction amount (remittance amount), and the payment date.
[0040] The electronic settlement device 1 sends a settlement completion notice including the generated settlement information to the settler's terminal using a predetermined communication means (S4). This settlement completion notice may include a message urging the settler to operate the remittance instruction terminal 2 to register the settlement information in the remittance device 3 of a bank or the like.
[0041] The electronic settlement device 1 may also send a settlement completion notice to the drafter using a predetermined communication means, and the drafter may request the drafter to register the settlement information in the remittance device 3 of a bank or the like.
[0042] (Pre-registration process) Next, the pre-registration process of the approval information will be explained with reference to FIGS.
[0043] Based on the approval completion notice or a request from the initiator, the approver operates the remittance instruction terminal 2 to log in to the remittance device 3 and register the approval information in advance in the remittance device 3 (Fig. 1: S5). The approval information entered by the approver should include at least the approval number, the customer name linked to the approval number, and the transaction amount from among the approval information exemplified in Fig. 2. Because the approver has just approved the transaction on the electronic approval device 1, he or she can enter the approval information into the remittance device 3 while understanding the approval details.
[0044] FIG. 3 is a sequence diagram specifically showing S5 in FIG.
[0045] The settler logs in to the remittance device 3 using the remittance instruction terminal 2 (S5-1). Specifically, the settler inputs authentication information into the remittance instruction terminal 2 to log in to the remittance device 3. The authentication information may be, for example, a login ID and password, or personal identification information stored on an IC card held by the settler. The remittance instruction terminal 2 transmits the input authentication information to the remittance device 3 via the network (S5-2).
[0046] The authentication unit 31 of the remittance device 3 receives the authentication information, authenticates the authentication information, and transmits the authentication result to the remittance instruction terminal 2 (S5-3). Specifically, if the received authentication information is stored in the authentication information storage unit 34, the authentication unit 31 authenticates that the access is from a legitimate user who is permitted to use the remittance device 3, and permits the login request from the settler. The authentication information storage unit 34 pre-stores the authentication information of legitimate users.
[0047] 4 is a diagram showing an example of authentication information stored in the authentication information storage unit 34. The illustrated authentication information includes, for each user, the user name, the last login date and time, the company name (enterprise name), the department name, the job title, attributes, and authentication information. The attributes are set as the user attributes (roles such as "decisor" or "accounting officer"). Note that the authentication information stored in the authentication information storage unit 34 only needs to include authentication information, and does not need to include all of the items shown in FIG. 4.
[0048] If the received authentication information is valid authentication information (if authentication is successful), the authentication unit 31 sends a login permission message to the remittance instruction terminal 2. This allows the authorizer to input the authorization information into the remittance instruction terminal 2. On the other hand, if the received authentication information is invalid authentication information (if authentication fails), the authentication unit 31 sends a login rejection message to the remittance instruction terminal 2.
[0049] If authentication is successful, the authentication unit 31 may use the "attributes" of the authentication information stored in the authentication information storage unit 34 to restrict the operations that the logged-in user can use. For example, if the logged-in user has the attribute of "authorizer," the remittance device 3 may restrict the logged-in user to only being able to input authorization information. Also, if the logged-in user has the attribute of "accounting officer," the remittance device 3 may restrict the logged-in user to only being able to input remittance information.
[0050] When the login permission message is sent to the remittance instruction terminal 2, the authorizer inputs the authorization information into the remittance instruction terminal 2 (S5-4). The remittance instruction terminal 2 transmits the input authorization information to the remittance device 3 via the network (S5-5). The input authorization information may include at least the authorization number, the customer name linked to the authorization number, and the transaction amount from among the authorization information exemplified in FIG. 2. The remittance device 3 receives the authorization information and stores (registers) the authorization information in the authorization information storage unit 35 (S5-6).
[0051] (Remittance processing) Next, the remittance process will be explained with reference to FIGS.
[0052] The company's accounting staff extracts the approval information from the electronic approval device 1 based on the payment date of the approved approval information, and uses the remittance instruction terminal 2 to send a remittance instruction to the remittance device 3 (FIG. 1: S6).
[0053] Specifically, as shown in Figure 3, the accounting clerk operates the remittance instruction terminal 2 to log in to the remittance device 3 (S6-1). As in S5-1, the remittance instruction terminal 2 transmits the authentication information entered by the accounting clerk to the remittance device 3 via the network (S6-2).
[0054] The authentication unit 31 of the remittance device 3 receives the authentication information, authenticates the authentication information, and transmits the authentication result to the remittance instruction terminal 2, similarly to S5-3 (S6-3). If the received authentication information is valid authentication information (if authentication is successful), the authentication unit 31 transmits a login permission message to the remittance instruction terminal 2. This allows the accounting clerk to input remittance information into the remittance instruction terminal 2. On the other hand, if the received authentication information is invalid authentication information (if authentication fails), the authentication unit 31 transmits a login rejection message to the remittance instruction terminal 2.
[0055] When the login permission message is sent to the remittance instruction terminal 2, the accounting clerk inputs the remittance information into the remittance instruction terminal 2 (S6-4). Specifically, the accounting clerk inputs the remittance information for each piece of approval information into the remittance instruction terminal 2. The remittance instruction terminal 2 transmits the input remittance information to the remittance device 3 via the network (S6-5).
[0056] The remittance information is information necessary for remittance, and is input by the accounting staff into the remittance instruction terminal 2 and transmitted to the remittance device 3.
[0057] FIG. 5 is a diagram showing an example of remittance information. The remittance information shown in the figure includes an authorization number, a remittee name, the remittee's account information, the remittance amount, and the remittance date. If a correspondence table that associates the remittee name with the remittee's account information is pre-registered in the remittance device 3, the accounting staff does not need to input the remittee's account information into the remittance instruction terminal 2. The remittance information in this embodiment includes an authorization number. The remittance device 3 uses the authorization number when searching for authorization information corresponding to the remittance information.
[0058] Note that the "payment date" is used in the settlement information shown in Figure 2, and the "remittance date" is used in the remittance information shown in Figure 5, but these have the same meaning. However, the "remittance date" is the date used by the remittance device 3, while the electronic settlement device 1 uses the "payment date" (a date set for each approved case). The accounting staff logs in to the remittance device 3 before the "payment date" approved by the electronic settlement device 1, and uses the remittance instruction terminal 2 to set the "remittance date" to the same date as the "payment date."
[0059] The execution unit 33 of the remittance device 3 stores the received remittance information in the remittance information storage unit 36. The execution unit 33 may store the remittance information in a storage unit such as a memory provided in itself. Then, the execution unit 33 determines whether the remittance information is valid (S6-6).
[0060] Specifically, the execution unit 33 searches the authorization information storage unit 35 for authorization information with the same authorization number as the authorization number specified in the remittance information. If the authorization information storage unit 35 contains authorization information with the same authorization number, the execution unit 33 compares the remittance information with the authorization information extracted from the authorization information storage unit 35 and determines whether or not at least the remittance amount in the remittance information matches the transaction amount in the extracted authorization information. If at least the remittance amount matches the transaction amount, the execution unit 33 puts the terminal 2 in a state where it is ready to accept a remittance instruction from the remittance instruction terminal 2. Note that the execution unit 33 may put the terminal 2 in a state where it is ready to accept a remittance instruction from the remittance instruction terminal 2 if not only the remittance amount but also other items of the remittance information (remittee name, remittance date) match other items of the authorization information (client name, transaction date). When the execution unit 33 puts the terminal 2 in a state where it is ready to accept a remittance instruction, it may send, for example, an input screen for remittance instructions to the remittance instruction terminal 2.
[0061] In this state, the accounting staff inputs a remittance instruction into the remittance instruction terminal 2 (S6-7). The remittance instruction terminal 2 transmits the remittance instruction to the remittance device 3 via the network (S6-8). The execution unit 33 of the remittance device 3 remits the remittance amount to the account specified in the remittance recipient's account information on the remittance date based on the remittance information transmitted in S6-5 (S6-9). Note that if no date is set for the remittance date in the remittance information, the remittance may be executed on the day the remittance instruction is received.
[0062] On the other hand, in S6-6, if there is no approval information with the same approval number as the remittance information in the approval information storage unit 35, or if there is a discrepancy between the remittance information and the approval information (for example, if the remittance amount in the remittance information differs from the transaction amount in the approval information extracted from the approval information storage unit 35), the execution unit 33 will cancel the remittance process.
[0063] (Modification of the first embodiment) In this embodiment, for all approval information registered in the electronic approval device 1, the approver sends the approval information to the remittance device 3 in advance, and when the remittance device 3 receives the remittance information, it controls whether to execute the remittance depending on whether the corresponding approval information has been received in advance.
[0064] The remittance processing of this embodiment is performed only in the case of large remittances of a predetermined amount (e.g., 100 million yen or more), and the remittance processing of this embodiment does not need to be applied in the case of relatively small remittances below the predetermined amount.
[0065] 6 is a flowchart showing the processing (FIG. 3: S6-6, S6-9) of the execution unit 33 of the remittance device 3 in a modified example of this embodiment. The execution unit 33 performs different processing depending on whether the remittance amount of the received remittance information is equal to or greater than a predetermined amount.
[0066] Specifically, the execution unit 33 receives remittance information from the remittance instruction terminal 2 (S6-6-1), and if the remittance amount in the remittance information is less than a predetermined amount (S6-6-2: NO), executes the remittance (S6-9-1). That is, the execution unit 33 executes the remittance based on the remittance information received in S6-6-1 (S6-9-1) without determining the validity of the remittance information. That is, the execution unit 33 executes the remittance process to transfer the remittance amount to the account specified in the remittance destination account information on the remittance date.
[0067] On the other hand, if the remittance amount of the remittance information is equal to or greater than the predetermined amount (S6-6-2: YES), the execution unit 33 determines whether or not the authorization information corresponding to the remittance information exists in the authorization information storage unit 35 (S6-6-3), as explained in S6-6 of FIG. 3. If the corresponding authorization information exists (S6-6-3: YES), the execution unit 33 executes the remittance based on the remittance information (S6-9-1). If the corresponding authorization information does not exist (S6-6-3: NO), the execution unit 33 cancels the remittance of the remittance information (S6-9-2).
[0068] In this case, even in the company-side processing shown in Figure 1, if the transaction amount of the transaction information entered into the electronic payment device 1 is less than a specified amount, the payment authorizer does not perform the process (S5) of sending the payment information to the remittance device 3 in advance.
[0069] (Action and effect) The remittance device 3 of this embodiment described above comprises a registration unit 32 that receives approval information sent from the remittance source company and registers it in the approval information storage unit 35, and an execution unit 33 that receives the remittance information sent from the company and, if approval information corresponding to the remittance information is stored in the approval information storage unit 35, executes the remittance specified in the remittance information, and, if approval information corresponding to the remittance information is not stored in the approval information storage unit 35, cancels the remittance specified in the remittance information.
[0070] As a result, in this embodiment, even if an accounting clerk sends unsettled remittance information and instructs the remittance device 3 to remit, the remittance device 3 determines that the remittance instruction is unsettled and halts the remittance. Therefore, this embodiment can achieve safer remittance processing. That is, this embodiment can halt unsettled remittances that have not been approved by the company, thereby reducing damage caused by bank transfer frauds targeting companies. Furthermore, this embodiment can halt fraudulent remittances that have not been approved by the company, among the many remittance instructions received from companies by the remittance device 3 of a bank, etc., without causing a significant amount of work for the company or bank, etc.
[0071] Specifically, this embodiment focuses on procedures within a company. In corporate procedures, if the date and time when an authorizer approves a transaction is X, then the date and time Y when a remittance instruction is sent to the remittance device 3, such as a bank, is later than the date and time X. In this embodiment, at the date and time X, the authorizer electronically approves the transaction using the electronic authorization device 1 and registers the authorization information in the remittance device 3. Then, at the date and time Y after the date and time X, when an accounting clerk sends a remittance instruction to the remittance device 3, the remittance device 3 searches for authorization information corresponding to the remittance information, and if authorization information corresponding to the remittance information is registered, it executes the remittance. If the authorization information that should be registered at the date and time X does not exist, or if there is a discrepancy between the remittance information and the authorization information registered at the date and time X, it cancels the remittance. Even if remittance information is sent fraudulently at the date and time Y and a remittance instruction is sent to the remittance device 3, the remittance device 3 can cancel the remittance if there is no authorization information from the authorizer at the date and time X.
[0072] Furthermore, in a company, the approver who approves the transaction varies depending on the transaction and the amount, and the number of transactions is enormous. Fraud targeting companies is characterized by large transaction amounts. For example, if this embodiment is applied only to transactions with large amounts of money (over 100 million yen), the approver and the target transactions can be limited. The approver for large transactions can be pre-registered in the remittance device 3. After the approver completes the internal transaction, the approver logs in to the remittance device 3 of a bank or the like and registers the approval information, including the company's unique approval number and the transaction amount, in the remittance device 3 in advance. Later, an accounting staff member logs in to the remittance device 3 and transmits the remittance information, including the company's unique approval number, the remittance destination, and the remittance amount. The remittance device 3 compares the remittance information with the pre-registered approval information to control the execution of the remittance. In this embodiment, the remittance device 3 of a bank or the like registers the approval information in advance in accordance with the timing of the internal transaction. If this embodiment is applied only to large remittances, it will not be possible to prevent all frauds targeting companies, but it is highly effective in preventing large-amount transfer frauds, which cause significant damage.
[0073] Second Embodiment Next, we will explain the second embodiment. In the first embodiment, the company's authorizer sent the authorization information to the remittance device of a bank or the like through a remittance instruction terminal. This was a method of matching the remittance details instructed by the accounting staff with the company's authorization details. In the second embodiment, similarly, the remittance details instructed by the accounting staff are matched with the company's internal authorization information.
[0074] In this embodiment, the total amount of remittance (transaction amount) to be paid on each remittance date is registered in advance in the remittance device 3 by the company's verifier, and the remittance device 3 executes the remittance on each remittance date when the total remittance amount in the remittance information entered by the accounting staff matches the total remittance amount registered by the verifier.
[0075] It is a business practice that remittance processing performed by the remittance device 3 is usually carried out on the remittance date entered by the accountant (for example, a date ending in 5 or 0), rather than on the date on which the remittance instruction is received from the accountant. Therefore, on the actual remittance date, multiple transactions are collectively remitted on the same day. Therefore, in this embodiment, remittance processing is carried out on the condition that the total amount of remittance processing to be carried out on the same day is calculated by a checker other than the accountant from values extracted from the company's internal approval information, and matches the total amount of the remittance details individually instructed by the accountant.
[0076] As a result, in this embodiment, if a remittance instruction is given for a transaction for which internal procedures have not been obtained at the electronic settlement device 1, the total amount will not match and the remittance will be canceled, thereby realizing a safer remittance system.
[0077] (System Configuration) FIG. 7 is a diagram showing the overall configuration of the system according to the second embodiment.
[0078] In this embodiment, as an internal company procedure, for each payment date (remittance date) set in each piece of approval information stored in the memory unit 11 of the electronic approval device 1, the confirmer obtains from the electronic approval device 1 the total remittance amount (total transaction amount) scheduled to be remitted on that payment date (S7), and transmits the total remittance amount to the remittance device 3 using the remittance instruction terminal 2 (S8). The notification to the approver (S4) and the pre-registration of the approval information in the remittance device 3 (S5) in Fig. 7 are necessary when implementing Example 1 together, but are not necessarily required, and the system can function with just the confirmer's work (S7, S8) and the accounting staff's work (S6).
[0079] The remittance device 3 of a bank or the like of this embodiment differs from the first embodiment in that the registration unit 32 and the execution unit 33 further have the following functions, but is otherwise similar to the first embodiment. That is, for each remittance date, the registration unit 32 receives from the remittance instruction terminal 2 the total amount of remittance to be remitted on that remittance date. The execution unit 33 extracts remittance information for which the current day is set as the remittance date, calculates the total amount of remittance set in each extracted remittance information, and executes the remittance of each extracted remittance information if the calculated total amount matches the received total amount. In this embodiment, a description of the same configuration and processing as in the first embodiment will be omitted.
[0080] Next, the processing of this embodiment will be described. The processing of this embodiment includes an electronic settlement processing, a pre-registration processing, and a remittance processing.
[0081] (Electronic approval processing) The electronic decision-making process (FIG. 7: S1 to S4) of this embodiment is similar to the electronic decision-making process (FIG. 1: S1 to S4) of the first embodiment, and therefore a description thereof will be omitted here.
[0082] (Pre-registration process) The pre-registration process of the approval information in this embodiment (FIG. 7: S5) is the same as the pre-registration process in the first embodiment (FIG. 1: S5).
[0083] Fig. 8 is a sequence diagram specifically showing S5 of this embodiment. The pre-registration process of the approval information (S5-1 to S5-6) shown in Fig. 8 is the same as the pre-registration process of the approval information (S5-1 to S5-6) shown in Fig. 3, so a description thereof will be omitted here.
[0084] In this embodiment, since the total remittance amount is confirmed for each remittance date, the pre-registration process of the approval information is not necessarily required, and in this embodiment, the pre-registration process may be omitted.
[0085] (Remittance processing) Next, the remittance process of this embodiment will be described (FIG. 7: S6).
[0086] FIG. 8 is a sequence diagram specifically illustrating S6 of this embodiment. Steps S6-1 to S6-8 shown in FIG. 8 are the same as the remittance process (S6-1 to S6-8) shown in FIG. 3, and therefore will not be described here. In S6-9 of FIG. 8, if the authorization information corresponding to the remittance information exists in the authorization information storage unit 35 in S6-6, the execution unit 33 reserves the remittance based on the remittance information transmitted in S6-5 (S6-9). The remittance information of this embodiment includes the remittance date as shown in FIG. 5, and the execution unit 33 waits until the remittance date to remit to the remittance destination account. On the other hand, if the authorization information corresponding to the remittance information does not exist in the authorization information storage unit 35 in S6-6, the execution unit 33 cancels the remittance process.
[0087] If the pre-registration process for the approval information described above is not performed, the process of S6-6 is not necessary, and the remittance information sent by the accounting staff does not need to include the approval number.
[0088] In the remittance process of this embodiment, the remittance device 3 checks the total remittance amount for each remittance date (Fig. 7: S7, S8). The company's verifier transmits the total remittance amount to be remitted for each remittance date to the remittance device 3.
[0089] Specifically, after the accounting staff sends the remittance information (S6 in Figure 7) and before the remittance date, the verifier logs in to the electronic settlement device 1, obtains the total amount of the remittance amount (transaction amount) to be remitted on that remittance date (S7), and sends the obtained total amount to the remittance device 3 (S8).
[0090] For example, the verifier calculates the total remittance amount by adding up the remittance amounts (transaction amounts) for the target remittance date (payment date) from among the unpaid (unremitted) approval information stored in the memory unit 11 of the electronic approval device 1. In the approval information shown in Figure 9, the verifier calculates the total remittance amount for 10 / 30 / 202x (122,000,000 + 87,000 = 122,087,000 yen). As shown in Figure 9, the total remittance amount for a certain payment date does not necessarily include only transactions with the same business partner.
[0091] In addition, when the remittance date approaches, the remittance device 3 may send a message to the confirming person stored in the authentication information storage unit 34, using a predetermined communication means such as email, prompting them to enter the total amount of remittance planned for that remittance date.
[0092] Figure 8 specifically shows the process of S8 in Figure 7. The verifying person operates the remittance instruction terminal 2 to log in to the remittance device 3 (S8-1). The remittance instruction terminal 2 transmits the authentication information entered by the verifying person to the remittance device 3 via the network (S8-2).
[0093] The authentication unit 31 of the remittance device 3 receives the authentication information, authenticates the authentication information using the authentication information storage unit 34, and transmits the authentication result to the remittance instruction terminal 2 (S8-3). In this embodiment, the authentication information storage unit 34 is assumed to have pre-stored therein the authentication information of the verifier in addition to the authorizer and accounting officer.
[0094] For greater security, it is desirable that the verifier be someone different from the accounting staff. In this case, the "attribute" of the authentication information (Fig. 4) stored in the authentication information storage unit 34 is set to "verifier." If the attribute of the logged-in user is "verifier," the remittance device 3 may limit the user to only being able to input the total amount of remittance.
[0095] If the received authentication information is valid authentication information (if authentication is successful), the authentication unit 31 sends a login permission message to the remittance instruction terminal 2. This allows the verifying person to input the total remittance amount into the remittance instruction terminal 2. On the other hand, if the received authentication information is invalid authentication information (if authentication fails), the authentication unit 31 sends a login rejection message to the remittance instruction terminal 2.
[0096] When the login permission message is sent to the remittance instruction terminal 2, the verifying person inputs the total remittance amount and the remittance date obtained in S7 into the remittance instruction terminal 2 (S8-4). The remittance instruction terminal 2 transmits the input remittance date and total amount to the remittance device 3 via the network (S8-5).
[0097] The execution unit 33 of the remittance device 3 stores the remittance date and total amount received from the remittance instruction terminal 2 in the remittance information storage unit 36. At a predetermined time on the remittance date, the execution unit 33 calculates the total amount of remittances set in the remittance information reserved for that remittance date. The execution unit 33 then compares the calculated total amount with the total amount corresponding to that remittance date stored in the remittance information storage unit 36. If the two match, the execution unit 33 executes the remittance of each remittance information reserved in S6-9 (S8-6). If the two do not match, the execution unit 33 cancels the remittance of each remittance information reserved in S6-9.
[0098] (Modification of the second embodiment) In this embodiment, as in the modified example of the first embodiment, the remittance device 3 may compare the remittance information with pre-registered approval information only in the case of large remittances of a predetermined amount (e.g., 100 million yen or more).
[0099] 10 is a flowchart showing the processing (FIG. 8: S6-6, S6-9, S8-6) of the execution unit 33 of the remittance device 3 in a modified example of this embodiment. S6-6-1 to S6-6-3 and S6-9-2 are the same as S6-6-1 to S6-6-3 and S6-9-2 shown in FIG. 6, so their explanation will be omitted here.
[0100] In S6-9-1, the execution unit 33 of the remittance device 3 reserves a remittance. The execution unit 33 stores the remittance date and total amount received from the remittance instruction terminal 2 in the remittance information storage unit 36 (S8-6-1). On the remittance date, the execution unit 33 calculates the total remittance amount set in the remittance information reserved for that remittance date, and compares it with the total remittance amount sent by the confirmer corresponding to that remittance date from the remittance information storage unit 36 (S8-6-2). If the two match (S8-6-2: YSE), the execution unit 33 executes the remittance of each remittance information reserved in S6-9-1 (S8-6-3). If the two do not match, the execution unit 33 cancels the remittance of each remittance information reserved in S6-9-1 (S8-6-4).
[0101] (Action and effect) In the remittance device 3 of this embodiment, the remittance information includes the remittance date and the remittance amount, and the registration unit 32 receives from the remittance instruction terminal 2, for each remittance date, the total amount of the remittance amount to be remitted on that remittance date, and the execution unit 33 extracts remittance information for which the current day is set as the remittance date, calculates the total amount of the remittance amount set in each extracted remittance information, and if the calculated total amount matches the received total amount, executes the remittance of each extracted remittance information.
[0102] As a result, in this embodiment, even if an accounting staff member sends a remittance instruction to the remittance device 3 for an unsettled transaction that has not gone through internal procedures, the total amount of the remittance that has been approved differs from the total amount of the remittance in the remittance information sent by the accounting staff member, so the remittance can be canceled, thereby achieving safer remittance processing.
[0103] A company's remittance instruction rarely specifies a same-day or instantaneous remittance, and typically specifies a remittance date Z, which is later than the remittance instruction date Y. Electronic settlement is also common among companies, and remittance instruction data for the remittance device 3 is created by extracting approved data stored in an internal system, including electronic settlement. In this embodiment, the approval information stored in the memory unit 11 of the electronic approval device 1 is used between date Y and the day before date Z to send only the total remittance amount to the remittance device 3. Specifically, the remittance device 3 of a bank or other such institution may receive the total remittance amount for remittance date Z before the company's remittance date Z, and add a process to compare the received total amount with the total remittance amount scheduled for remittance date Z on remittance date Z. According to this embodiment, even if a fraudulent remittance is added, the remittance can be stopped because the total remittance amount obtained from the approval information that has undergone normal internal procedures does not match the total remittance amount instructed to the remittance device 3.
[0104] In this embodiment, a safer remittance process can be achieved by having an employee (confirmer) other than the accounting staff member who issues the remittance instruction send the total remittance amount to the remittance device 3 before the remittance date.
[0105] <Hardware configuration> The remittance device 3 of this embodiment described above can be, for example, a general-purpose computer system as shown in Figure 11. The computer system shown in the figure comprises a CPU (Central Processing Unit, processor) 901, memory 902, storage 903 (HDD: Hard Disk Drive, SSD: Solid State Drive), communication device 904, input device 905, and output device 906. The memory 902 and storage 903 are storage devices. In this computer system, the CPU 901 executes a predetermined program loaded on the memory 902, thereby realizing each function of the remittance device 3.
[0106] The remittance device 3 may be implemented on one computer or on multiple computers. The remittance device 3 may also be a virtual machine implemented on a computer. Each program of the remittance device 3 can be stored on a computer-readable recording medium such as an HDD, SSD, USB (Universal Serial Bus) memory, CD (Compact Disc), or DVD (Digital Versatile Disc), or can be distributed via a network. The computer-readable recording medium is, for example, a non-transitory recording medium.
[0107] The present disclosure is not limited to the above-described embodiments, and various modifications are possible within the scope of the present disclosure. [Explanation of symbols]
[0108] 1: Electronic approval device 2: Remittance instruction terminal 3: Money transfer device 31: Authentication section 32: Registration Department 33: Executive Department 34: Authentication information storage unit 35: Approval information storage unit (storage unit) 36: Remittance information storage unit
Claims
1. a registration unit that receives approval information sent from a remittance source company and registers it in a storage unit, and also receives remittance information sent from the company and registers it in the storage unit; an execution unit that executes the remittance if the authorization information included in the remittance information matches the authorization information registered in the storage unit, and cancels the remittance if they do not match. Money transfer device.
2. A remittance method performed by a remittance device, Receives the approval information sent from the remittance source company and registers it in the memory unit, The remittance information sent from the company is received, and if the approval information included in the remittance information matches the approval information registered in the storage unit, the remittance is executed, and if they do not match, the remittance is cancelled. Remittance method.
3. a registration unit that receives individual remittance information sent from the remittance source company and registers it in a storage unit, and also receives a value calculated by the company before the remittance date from the approval information and transmits the calculated value, and registers it in the storage unit; an execution unit that extracts remittance information for the day of remittance from the individual remittance information stored in the storage unit, calculates the total amount of remittances, and executes the individual remittances for that day if the calculated total amount matches the total amount for that day that was separately received and registered in the storage unit, and cancels the individual remittances for that day if they do not match. Money transfer device.
4. A remittance method performed by a remittance device, After receiving each remittance information sent from the remittance source company, it is registered in the memory unit. The company calculates the total amount of remittances on the day of remittance from the approval information before the day of remittance, receives the calculated value separately, and registers it in the storage unit; The individual remittance information corresponding to the remittance date is extracted from the storage unit, and the total amount of remittances is calculated. If the calculated total amount matches the total amount for the remittance date separately received and registered in the storage unit, the individual remittances for that day are executed, and if they do not match, the individual remittances for that day are cancelled. Remittance method.
Citation Information
Patent Citations
Remittance control system, and program
JP2013168190A