Information processing apparatus, information processing system, and program
The user terminal's contactless IC reading application encrypts card information for secure transmission, addressing the risk of leakage in conventional systems and enhancing transaction security.
Patent Information
- Application Number
- JP2024043023
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-10-02
AI Technical Summary
Conventional card payment systems risk card information leakage due to the use of separate terminals for reading and user possession, causing security concerns for users.
A user terminal equipped with a contactless IC reading application that encrypts card information using a public key, allowing secure transmission to a credit card company server without storing sensitive data on external terminals.
Reduces the risk of card information leakage during transactions by encrypting and securely transmitting payment data, ensuring user privacy and security.
Smart Images

Figure 2025143674000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, an information processing system, and a program. [Background technology]
[0002] A technology is known in which a payment terminal device receives payment-related information, such as amount information, payment method, and information on the card brand used for payment, from a user, and then processes and displays a message prompting the user to read the card used for payment. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-114791 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the conventional technology described above, the terminal that reads the card is a terminal (for example, a terminal installed in a store) that is different from the user terminal that the user possesses, so the user is never free from the worry of card information being leaked.
[0005] Therefore, in one aspect, the present invention aims to enable card payments in a manner that reduces the possibility of card information being leaked when the card is read. [Means for solving the problem]
[0006] In one aspect, a start-up processing unit that, when a payment method representing a credit card tap payment is selected by a user, starts an application that enables card information related to the credit card to be read in a contactless manner on a user terminal associated with the user; An information processing device is provided, which includes a card information processing unit that, when card information is read via the application, performs a predetermined process on the card information so that the card information is sent to the card company. [Effects of the Invention]
[0007] According to one aspect, the present invention enables card payments in a manner that reduces the possibility of card information being leaked during reading. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a schematic diagram of the overall configuration of an information processing system according to an embodiment; [Figure 2] FIG. 2 is a diagram illustrating a flow of the user terminal touch payment service according to the present embodiment. [Figure 3] FIG. 10 is a diagram showing an example of a screen (application screen related to an affiliated store application) on a user terminal. [Figure 4] FIG. 10 is a diagram showing an example of a screen (application screen related to a contactless IC reading application) on a user terminal. [Figure 5] FIG. 10 is a diagram schematically illustrating a state in which a credit card is read by a user terminal in a contactless manner. DETAILED DESCRIPTION OF THE INVENTION
[0009] Each embodiment will be described in detail below with reference to the accompanying drawings. In the following description, "app" means an application program.
[0010] FIG. 1 is a schematic diagram of the overall configuration of an information processing system 1 according to an embodiment.
[0011] The information processing system 1 is a system that realizes a user terminal touch payment service described below. The user terminal touch payment service is a service that enables a user to safely receive the touch payment service without registering, for example, credit card information in a store app. An example of the user terminal touch payment service will be described later with reference to FIG. 2 etc.
[0012] The information processing system 1 includes a user terminal 21, an affiliated store server 31, a credit card company server 91, and an authentication server 100. Some or all of the functions of the authentication server 100 may be realized by the credit card company server 91 and / or by the user terminal 21.
[0013] The user terminal 21, the affiliated store server 31, the credit card company server 91, and the authentication server 100 are connected via a network 4. The user terminal 21 and the authentication server 100 can communicate with each other via the network 4. In the following, unless otherwise specified, a user refers to a user of the user terminal touch payment service.
[0014] The network 4 may include, for example, a wireless communication network for mobile phones, the Internet, a Virtual Private Network (VPN), a Wide Area Network (WAN), a wired network, or any combination of these.
[0015] The user terminal 21 is, for example, a smartphone or a tablet, but may also be a wearable terminal (for example, a smart watch, a ring, etc.), a remote control, etc. Furthermore, the user terminal 21 does not need to be a portable terminal, and may also be a fixed terminal such as a desktop personal computer, etc.
[0016] The user terminal 21 includes a communication unit 22, a display unit 24, an input unit 26, and a processing unit 28. The communication unit 22 performs various communications via the network 4. The display unit 24 may be a liquid crystal display, an organic EL (Electro-Luminescence) display, or the like. The input unit 26 may be a touch panel, a voice input device, or the like. The processing unit 28 realizes various functions that can be realized by the user terminal 21. In this embodiment, the processing unit 28 realizes various functions (functions on the user terminal 21 side) described below by executing programs related to an affiliated store app and a contactless IC reading app, which will be described later.
[0017] The user terminal 21 has installed thereon an affiliated store app and an application (hereinafter referred to as a "contactless IC reading app") according to this embodiment. The various functions of the user terminal 21 described below are realized by executing the affiliated store app and the contactless IC reading app. Note that the affiliated store app and the contactless IC reading app may be linked in advance in the user terminal 21.
[0018] The affiliated store app is an app that enables online transactions at affiliated stores. In other words, the affiliated store app is an app related to an EC (Electronic Commerce) site. However, this embodiment is not limited to apps related to so-called online shopping, and can be applied to any app that allows card payments.
[0019] The contactless IC reading application utilizes a communication function installed in the user terminal 21 to perform contactless communication with an IC (Integrated Circuit) mounted on the credit card, thereby reading card information related to the credit card.
[0020] The affiliated store server 31 may be provided for each affiliated store. The affiliated store server 31 performs various processes related to the sale of goods and services via the affiliated store app.
[0021] The credit card company server 91 realizes card payments by processing the card information supplied from the affiliated store server 31. The credit card company server 91 may be realized by a combination of multiple servers working together.
[0022] The authentication server 100 is a server that performs authentication related to the user terminal touch payment service. The authentication server 100 may also be used as a server that performs authentication for services (applications) other than the user terminal touch payment service. The authentication server 100 is formed, for example, by a server computer. The authentication server 100 may be realized by multiple server computers. For example, the authentication server 100 may be realized by the cooperation of multiple server computers located in different locations.
[0023] In this embodiment, the authentication server 100 authenticates whether the merchant number included in the activation request (described later) sent from the merchant side is valid. A merchant who wishes to use this user terminal touch payment service obtains a merchant number by applying and registering in advance. The merchant number may be a unique number assigned to each merchant.
[0024] Fig. 2 is a diagram schematically showing the flow of the user terminal touch payment service according to this embodiment. Figs. 3 to 5 are explanatory diagrams of each scene of the user terminal touch payment service shown in Fig. 2. Fig. 3 shows an example of a screen G20 (an application screen related to the affiliated store application 101) on the user terminal 21, and Fig. 4 is a diagram showing an example of a screen G30 (an application screen related to the contactless IC reading application 102) on the user terminal 21. Fig. 5 is a diagram schematically showing a state in which the user terminal 21 is being made to read a credit card contactlessly.
[0025] Referring to FIG. 2, first, in step S20, the authentication server 100 assigns a member store number to a member store that wishes to use the user terminal touch payment service. A member store that has been assigned a member store number can make "touch payment by credit card" selectable as one of the payment method options in its own member store app 101. FIG. 3 shows an example of a payment screen in the activated state of the member store app 101, which makes it possible to select "touch payment by credit card." Note that in FIG. 3, "touch payment by credit card" is written as "touch payment by credit card."
[0026] Here, it is assumed that a user launches the affiliated store app 101 on their own user terminal 21, and when making any purchase on the affiliated store app 101, selects "tap payment with credit card" and proceeds with the payment. In this case, in step S21, the affiliated store app 101 sets its own affiliated store number and public key and launches the contactless IC reading app 102. That is, the affiliated store app 101 outputs a launch request including the affiliated store number and public key to the contactless IC reading app 102. It is assumed that the private key corresponding to the public key is strictly managed by the affiliated store. In this case, the private key (and therefore the public key) may be changed (updated) periodically.
[0027] When the contactless IC reading application 102 is started in response to such a start-up request, in step S22, an authentication request is made by sending the affiliated store number included in the start-up request to the authentication server 100. Note that when the contactless IC reading application 102 is started in this manner, the linked state between the affiliated store application 101 and the contactless IC reading application 102 may continue until there is no response (exchange) between the two applications for a predetermined time or more (see step S29), or until an end instruction is received from the user.
[0028] In step S23, the authentication server 100 returns the authentication result to the contactless IC reading application 102 of the user terminal 21. Specifically, if the member store number matches the member store number issued in advance, the authentication server 100 returns information indicating that the authentication was successful to the contactless IC reading application 102. On the other hand, if the member store number does not match the member store number issued in advance, the authentication server 100 returns information indicating that the authentication was unsuccessful to the contactless IC reading application 102.
[0029] If the authentication is successful, the contactless IC reading application 102 outputs a screen indicating that the credit card is contactlessly readable in step S24, as shown in Fig. 4. In response to this, the user positions the credit card to be used in a predetermined relationship with the user terminal 21, as shown schematically in Fig. 5. That is, the user causes the contactless IC reading application 102 to read the card information of the credit card. The card information to be read may be information required for card payment, such as the card number, expiration date, security number, etc.
[0030] When the contactless IC reading application 102 reads the card information, in step S25, the contactless IC reading application 102 encrypts the read card information with a public key and returns the encrypted information to the affiliated store application 101. The public key used in this case may be the public key obtained in step S21.
[0031] When the affiliated store app 101 acquires the encrypted card information, in step S26, it decrypts the card information using the private key and transmits the decrypted card information together with information such as the payment amount to the credit card company server 91 (see FIG. 1). In a modified example, the affiliated store app 101 may transmit the card information together with information such as the payment amount to the credit card company server 91 without decrypting it. In this case, the private key may be held by the credit card company server 91. In this case, third parties (affiliated stores) other than the credit card company server 91 cannot know the credit card information, thereby significantly improving security.
[0032] In this way, according to this embodiment, touch payment using a credit card on the user terminal 21 is possible, so there is no need to register important credit information related to the credit card in advance in the affiliated store app 101. Therefore, the user can enjoy online shopping using the affiliated store app 101 without worrying about the leakage of credit information.
[0033] Although each embodiment has been described in detail above, it is not limited to the specific embodiment, and various modifications and changes are possible within the scope of the claims. It is also possible to combine all or a plurality of the components of the above-described embodiments.
[0034] For example, the above-described embodiment relates to an application example of the affiliated store app 101 mainly targeted at online shopping, but it can also be applied to shopping at a physical store. In this case, an app corresponding to the affiliated store app 101 may be installed on a terminal at the physical store. In this case, the user can make a touch payment on their own user terminal 21 without using a touch payment terminal provided by the physical store.
[0035] For example, in the above-described embodiment, the merchant number is fixed, but to prevent merchants from impersonating other merchants, the merchant number may be updated periodically. Alternatively, other authentication information such as a one-time pass may be used in combination.
[0036] In addition, in the above-described embodiment, authentication based on the member store number is performed to enhance security, but such authentication may be omitted. Also, the public key may not be used. In the above-described embodiment, the activation request includes the member store number and the public key, but it may include only one of the member store number and the public key. In this case, the other may be passed to the contactless IC reading application 102 side separately from the activation request.
[0037] Furthermore, the above-described embodiment is realized on the assumption that the contactless IC reading application 102 is also installed in the user terminal 21 on which the affiliated store application 101 is installed. However, the affiliated store application 101 and the contactless IC reading application 102 may be installed in different user terminals 21. Furthermore, the user terminal 21 may be installed with two or more contactless IC reading applications 102 that can launch the contactless IC reading application 102. In either case, it is desirable for the user to launch the contactless IC reading application 102 on a user terminal 21 that the user himself / herself trusts.
[0038] Furthermore, in the above-described embodiment, the name holder of the credit card used to make a touch payment via the contactless IC reading application 102 does not necessarily have to be the same person as the user who owns the user terminal 21. For example, a father can use his credit card to make a payment on his child's user terminal instead.
[0039] Furthermore, in the above-described embodiment, the affiliated store app 101 is a so-called native app that is installed and runs on the user terminal 21, but it may also be in another form such as a web app. For example, in the case of a web app, the affiliated store app 101 can run on the user terminal 21 via a browser installed on the user terminal 21. [Explanation of symbols]
[0040] 1. Information Processing Systems 4 Network 21 User terminal (an example of an information processing device) 22 Communications Department 24 Display 26 Input section 28 Processing section (an example of a startup processing section, a card information processing section) 31 Merchant Server 91 Credit card company server 100 Authentication server (an example of an authentication processing unit, a server) 101 Affiliated store app (example of the first application) 102 Contactless IC reader app (an example of a second application)
Claims
1. a start-up processing unit that, when a payment method representing credit card tap payment is selected by a user, starts an application that enables contactless reading of card information related to a credit card on a user terminal associated with the user; an information processing device comprising: a card information processing unit that, when card information is read via the application, performs a predetermined process on the card information so that the card information is sent to a card company.
2. the activation processing unit, when receiving an activation request including a member store number from the member store side, activates the application and performs processing such that authentication of whether the member store number is valid is performed by an authentication processing unit; The information processing device according to claim 1 , wherein the card information processing unit performs the predetermined process when authentication is obtained that the affiliated store number is valid.
3. the activation request further includes a public key; The information processing device according to claim 2 , wherein the card information processing unit performs the predetermined process using the public key when authentication is obtained that the affiliated store number is valid.
4. 4. The information processing device according to claim 3, wherein the predetermined process includes a process of encrypting the card information using the public key, and a process of transmitting the encrypted card information to the affiliated store that sent the activation request.
5. The information processing device according to claim 2 , wherein the startup request is generated when a payment method representing credit card contact payment is selected by a user on a shopping site operated and managed by an affiliated store.
6. a first application at the affiliated store operable on a user terminal; a second application installed on the user terminal; The first application sends a startup request to the second application when a payment method representing credit card contact payment is selected by the user; In response to the startup request, the second application launches an application that enables contactless reading of card information related to a credit card, and when the card information is read contactlessly, performs a predetermined process on the card information so that the card information is sent to the card company.
7. further comprising an authentication server; The activation request includes a merchant number; The authentication server authenticates whether the member store number included in the activation request is valid based on the member store number previously assigned to each member store; 7. The information processing system according to claim 6, wherein the predetermined process is executed when authentication is obtained that the member store number is valid.
8. When a payment method representing a credit card touch payment is selected by a user, an application that enables contactless reading of card information relating to the credit card on a user terminal associated with the user is started, A program that causes a computer to execute a process that, when card information is read via the application, performs a predetermined process on the card information so that the card information is sent to the card company.
Citation Information
Patent Citations
Portable settlement terminal
JP2015114791A