Application program, and service providing system

The application program on user terminal devices detects voice calls and displays warning screens before executing sensitive services, effectively preventing unauthorized use by addressing the broader issue of service misuse.

JP7692542B1Active Publication Date: 2025-06-13PAYPAY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025016794
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-02-04
Publication Date
2025-06-13
Estimated Expiration
2045-02-04

AI Technical Summary

Technical Problem

Existing technologies have not effectively addressed the broader issue of preventing unauthorized use of services, particularly through operations like screen capture or other methods beyond simple duplication of code images.

Method used

An application program operating on a user terminal device that detects voice calls and displays a warning screen before executing specific services, such as electronic payments or money transfers, when the user is on a call and attempts to initiate these services.

Benefits of technology

This approach significantly enhances the reliability of preventing unauthorized use by alerting users to potential fraud during voice calls and requiring explicit user action to proceed with sensitive transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007692542000001_ABST
    Figure 0007692542000001_ABST
Patent Text Reader

Abstract

To more reliably prevent unauthorized use. 【Solution means】An application program that operates on a user terminal device and provides a service to a user in cooperation with a service server, the user terminal device having a process for detecting that the user terminal device is performing at least a voice call, and when the user terminal device is performing the call and an operation for instructing execution of a specific service involving withdrawal of the user is performed, a process for displaying a warning screen before execution of the specific service. An application program for causing the above to be executed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an application program and a service providing system.

Background Art

[0002] Conventionally, there has been disclosed an invention of a service providing apparatus that collaborates with an application operating on a user's terminal device to provide a service to the user, the apparatus including: a service providing unit that provides the service to a user who has been presented with a code image by the application; a management unit that manages the validity of the code image; and a detection unit that detects unauthorized use of the service based on code information read from the code image presented by the user. When the management unit receives from the application a duplication notification indicating that an operation of duplicating the code image has been performed on the terminal device, the management unit invalidates the code image targeted for duplication by the operation. When the detection unit determines that the code information received during use of the service has been invalidated, the detection unit determines that the use of the service is unauthorized use (Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Unauthorized use of a service by duplicating a code image or the like may be possible not only by a simple operation such as a screen capture but also by other operations. The conventional technology has not addressed preventing unauthorized use from a broader perspective.

[0005] The present invention has been made in consideration of such circumstances, and one of its objectives is to provide an application program and a service providing system that can more reliably prevent unauthorized use.

Means for Solving the Problems

[0006] One aspect of the present invention is an application program that operates on a user terminal device and provides a service to a user in cooperation with a service server, the application program causing the user terminal device to execute a process of detecting that the user terminal device is performing at least a voice call, and a process of displaying a warning screen before executing the specific service when the user terminal device is performing the call and an operation for instructing the execution of a specific service involving the user's withdrawal is performed. It is an application program for causing the above to be executed.

Effects of the Invention

[0007] According to one aspect of the present invention, unauthorized use can be more reliably prevented.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

[0009] [Overview] Hereinafter, with reference to the drawings, embodiments of the application program and the service providing system according to the present invention will be described. The application program operates on a user terminal device and provides services to users in cooperation with a service server. The services are various services provided via a network, such as an electronic payment service, an e-commerce service, and a money transfer service between users. In the following description, the service is assumed to be an electronic payment service, and the service server is referred to as a settlement server, and the application program is referred to as a settlement application.

[0010] An electronic payment service is provided, for example, by the cooperation of an application program, a payment server, and a credit card server. The electronic payment service is a service that supports payments related to the purchase of goods and services in a store. A store is, for example, a physical store (actual store) existing in the real space, but may include a virtual store for e-commerce transactions. The virtual store may include those provided by a party different from the operator of the electronic payment service. In that case, when making a payment for shopping in the virtual store, it is controlled to transition to the interface screen of the electronic payment service. In the electronic payment service, a store is treated, for example, as belonging to a franchise (brand), and processes such as payment when a purchase action is performed in the store are mainly carried out between the user and the franchise. Alternatively, processes such as payment may be carried out between the user and the store.

[0011] [Mode of Physical Store-Type Electronic Payment] FIG. 1 is a diagram showing a basic mode of in-store electronic payment. Basically, electronic payment is executed by three parties: a medium M held by a user U, store equipment E, and a payment system S. The medium M is a portable computer device such as a smartphone or a credit card. The store equipment E exists in a physical store in the real space (hereinafter simply referred to as a store), and includes a POS device, a wireless communication device, a credit card reader, a printed matter of a code image such as a QR code (registered trademark), or a display device for displaying a code image. In in-store electronic payment, first, information such as information that can recognize the user's identification information and payment amount information is shared unidirectionally or bidirectionally between the medium M and the store equipment E. At this time, one of the medium M or the store equipment E optically reads various information from the code image displayed by the other, provides information by NFC (Near Field Communication), or reads the PAN (Primary Account Number) by a credit card reader. Then, one of the medium M or the store equipment E (the side that has acquired information from the other) transmits payment information necessary for payment to the payment system S via the network NW. Note that both the medium M and the store equipment E may transmit information to the payment system S. The payment system S manages various information of the user U and performs electronic payment between the store and the user U in various modes. Electronic payment is performed by one or both of the prepaid method and the postpaid method, or by other methods. In addition, electronic payment may include a so-called online shopping mode executed by both the user's terminal device and the payment system. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, and the like. It is assumed that various devices communicating via the network NW that appear hereinafter have communication devices such as network cards and wireless communication modules.

[0012] [Configuration (Terminal Payment)] FIG. 2 is a diagram showing an example of a configuration for performing electronic payment (terminal payment) using a payment application. This electronic payment is executed centering around a payment application 20 operating on a user terminal device 10 which is one of the media M, one or more store payment terminals 30 which are one of the store facilities E, one or more store code images 40, and a payment server 100 which constitutes a part of the payment system S. The payment server 100 communicates with the user terminal device 10, the store payment terminals 30, and one or more information terminals 50 via a network NW.

[0013] The user terminal device 10 is a portable terminal device such as a smartphone or a tablet terminal, for example. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input reception function, and a program execution function. In the following description, the configurations for realizing these functions are respectively referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), etc. In the user terminal device 10, the payment application 20 is executed by a processor such as a CPU, and thus operates to provide an electronic payment service to the user in cooperation with the payment server 100. The payment application 20 is installed in the user terminal device 10 from, for example, an application distribution server (not shown), and controls the camera, the communication device, the touch panel, etc. of the user terminal device 10. In the following description, cases where it is described as "transmitting information to the user terminal device 10 (or receiving / acquiring information from the user terminal device 10)" and cases where it is described as "transmitting information to the payment application 20 (or receiving / acquiring information from the payment application 20)" may be mixed, but these are only differences in expression and are not intended to distinguish anything.

[0014] The store payment terminal 30 is installed in a store, for example. The store payment terminal 30 is a computer device (or an aggregate thereof) having at least a commodity price acquisition function, an optical reading function, a program execution function, and a communication function. The store payment terminal 30 includes a so-called POS (Point of Sale) device, and the POS device may have a commodity price acquisition function or an optical reading function.

[0015] The store code image 40 is placed in the store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. Note that the store code image 40 may be displayed by a display placed in the store (which may be a display of a terminal device such as a smartphone or a tablet terminal).

[0016] The information terminal 50 is used by the operator of the franchise that manages the store. In the electronic payment service, the customer as the provider of goods or services is treated as a franchise (brand), and there are one or more stores under its umbrella. There may be a franchise that operates only one store. The information terminal 50 is a smartphone, a tablet terminal, a personal computer, or the like. The information terminal 50 operates a franchise interface 55. The franchise interface 55 may be a franchise application or a web page displayed by a general-purpose browser. The franchise interface 55 accepts settings of coupons and the like by the operator of the franchise and transmits them to the payment server 100. The information terminal 50 may have a function of displaying a code image corresponding to the store code image 40 or reading the code image displayed by the user terminal device 10 by executing the franchise interface 55 (in the latter case, an optical reading function is required).

[0017] The payment server 100 communicates with the credit card server 200 via the network NW. The payment server 100 has, for example, a content providing unit 110, an information management unit 120, a payment processing unit 130, a code image providing unit 140, an authentication unit 150, and a storage unit 170. The code image providing unit 140 may be included in other functional units such as the content providing unit 110 and the authentication unit 150.

[0018] Components other than the storage unit 170 in the settlement server 100 are realized, for example, by a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including a circuit unit; circuitry) such as an LSI (Large Scale Integration), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or may be realized by the cooperation of software and hardware. The program may be stored in advance in a storage device (a storage device having a non-transitory storage medium) such as an HDD (Hard Disk Drive) or a flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or a CD-ROM, and may be installed in the storage device when the storage medium is mounted on a drive device.

[0019] The storage unit 170 is an HDD, a flash memory, a RAM (Random Access Memory), or the like. The storage unit 170 may be a NAS (Network Attached Storage) device accessible by the settlement server 100 via a network. Information such as user information 172 and affiliated store / store information 174 is stored in the storage unit 170.

[0020] The content providing unit 110 has, for example, the function of a web server and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 110 provides content to the user terminal device 10 in the form of a web page, or provides parameters necessary for the payment application 20 to render an image to the user terminal device 10.

[0021] The information management unit 120 edits, adds, deletes, etc. the user information 172 and the affiliated store / store information 174, and manages them.

[0022] FIG. 3 is a diagram showing an example of the content of user information 172. The user information 172 is, for example, a set of information such as a user URL, an account ID, a phone number, a password, a registration date, a remaining charge amount, an electronic money type, a terminal payment method, a card payment method, various history information, an identity verified flag, a name, an address, a date of birth, an email address, a bank account, a post-payment setting, post-payment condition information, and authentication information, which are associated with each other. Hereinafter, an instance (electronic payment account) of a user in which these pieces of information are associated may be referred to as an account. In the figure, items indicated by "-" indicate that they are not set.

[0023] The user URL is used for money transfer processing between users. When newly registering for the electronic payment service, registration of a phone number and a password is required. The account ID is issued to the user by the payment server 100. The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). The remaining charge amount is information indicating the remaining amount of electronic money set by the user by remitting money to the account in advance. Examples of means of remittance include depositing money into an ATM (Automatic Teller Machine) of a designated operator (bank) and remitting money from a registered bank account. The type of electronic money is information indicating, for example, whether the electronic money is withdrawable or can be used only for electronic payments. The terminal payment method is setting information indicating whether the user makes an electronic payment using the remaining charge amount (balance payment) or makes a payment on a post-payment basis in terminal payment. The card payment method is setting information indicating whether the user makes an electronic payment using the remaining charge amount (balance payment) or makes a payment on a post-payment basis in card payment. The various history information includes a charge history, which is a history of the user increasing the remaining charge amount by remitting money to the electronic payment service in advance, and a settlement history, which shows, for each settlement, the breakdown of the settlements made by the user (date and time, store ID of the store where the purchase action was performed, settlement amount, settlement method, etc.).

[0024] The identity verification flag is information indicating whether the user has completed identity verification using an identity certificate. Post-payment becomes selectable when identity verification has been completed. Since the user with the account ID "002" in the figure has not completed identity verification, the only available terminal payment method is balance payment. A bank account is the account number of a bank account where deposits can be made for the electronic payment service. The post-payment setting is information indicating whether the setting operation to enable post-payment has been completed. The post-payment condition information is information indicating various conditions such as the limit amount and the monthly usage amount in post-payment. The authentication information will be described later.

[0025] Figure 4 is a diagram showing an example of the content of the affiliated store / store information 174. The affiliated store / store information 174 includes, for example, a first table 174A in which an affiliated store ID and a store ID are associated with a store URL, a second table 174B in which an affiliated store name and sales amount (described above) are associated with the affiliated store ID, and a third table 174C in which a store ID is associated with the store ID. In addition to these pieces of information, the affiliated store / store information 174 may include information such as the category of the affiliated store or store, the location of the store, and the payment pattern.

[0026] The payment processing unit 130 performs various processes for electronic payment. There are two methods for terminal payment: the first method (user scan) and the second method (store scan), which will be described below.

[0027] FIG. 5 is a diagram showing an overview of the processing flow when a user scan is performed. First, the user terminal device 10 in a state where the payment application 20 is launched reads and decodes the store code image 40 by means of an optical reading function (S1). The store code image 40 contains information on the store URL. The payment application 20 transmits first payment information including the store URL and the user's account ID to the payment server 100 (S2). The payment server 100 searches for the affiliated store / store information 174 using the affiliated store ID and store ID corresponding to the store URL, obtains information on the affiliated store name and store name (S3), and transmits it to the payment application 20 (S4). The user inputs the payment amount into the payment application 20 on the screen where the affiliated store name and store name are displayed (S5). Then, the payment application 20 generates second payment information including at least the payment amount and transmits it to the payment server 100 (S6).

[0028] When the payment method of the user information 172 of the user is "balance payment", the payment processing unit 130 of the payment server 100 performs an electronic payment based on the received second payment information (S7-1). At this time, the payment processing unit 130 performs an electronic payment, for example, by reducing the charged balance managed in association with the user ID and increasing the item value of the affiliated store's sales amount. The item value of the affiliated store's sales amount is not used as electronic money itself, for example, and the amount corresponding to the item value of the sales amount is transferred to the bank account in a cycle according to the agreement between the affiliated store and the electronic payment service. On the other hand, when the "payment method" is "payment later", the payment processing unit 130 transmits the first payment information and the second payment information to the credit card server 200 to request an electronic payment (S7-2). The credit card server 200 performs an electronic payment by adding the payment amount to the user's monthly usage amount based on the received information and deducting the monthly usage amount from the user's bank account after the closing date (S7-3).

[0029] Then, the settlement processing unit 130 transmits a settlement completion notice (information for displaying a settlement completion screen) to the settlement app 20 via the content providing unit 110 (S8), and the settlement app 20 displays a settlement completion screen (S9). When the store code image 40 is displayed on a display placed in the store, the store code image 40 may include not only the store URL but also settlement amount information. In this case, the procedure for the user to input the settlement amount is omitted, and the settlement amount information is included in the first settlement information and transmitted to the settlement server 100. Information such as the franchise name and store name may be included and displayed on the settlement completion screen.

[0030] FIG. 6 is a diagram showing an overview of the processing flow when store scanning is performed. First, when the settlement app 20 is launched, when an operation to pay is performed in the settlement app 20, when the automatic update timing (for example, every minute) arrives, and at other timings, the settlement app 20 transmits a request to issue a one-time code to the settlement server 100 (S11). The code image providing unit 140 of the settlement server 100 generates a one-time code (S12) and transmits it to the settlement app 20 (S13). The settlement app 20 displays a code image such as a QR code or barcode generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the store settlement terminal 30, and the store settlement terminal 30 reads and decodes the code image by means of an optical reading function to obtain a one-time code or the like (S15). Then, the store settlement terminal 30 generates settlement information including the one-time code, settlement amount, franchise ID, store ID, etc., and transmits it to the settlement server 100 (S16). The settlement amount information has been obtained in advance by barcode reading, manual input, or the like.

[0031] The settlement processing unit 130 of the settlement server 100 identifies the user corresponding to the one-time code based on the received information, and when the "terminal settlement method" in the user information 172 of the user is "balance payment", it performs electronic settlement based on the received second settlement information (S17-1). The content of the processing at this time is the same as the processing of S7-1 in FIG. 5. On the other hand, when the "terminal settlement method" is "post-payment", the settlement server 100 transmits the first settlement information and the second settlement information to the credit card server 200 to request electronic settlement (S17-2). The credit card server 200 adds the settlement amount to the monthly usage amount of the user based on the received information, and performs electronic settlement by subtracting the monthly usage amount from the user's bank account after the closing date (S17-3).

[0032] Then, the settlement processing unit 130 transmits a settlement completion notification to the settlement application 20 via the content providing unit 110 (S18), and the settlement application 20 displays a settlement completion screen (S19).

[0033] Note that electronic settlement may be performed in only one of the above patterns. Also, the "account ID" described in FIG. 2 may be other information (such as a phone number) that can be used as the identification information of the user. Further, in the store scan, the issuance of the one-time code may be omitted, and the settlement application 20 may display a code image generated based on the user's account ID. In that case, instead of identifying the user corresponding to the one-time code, the settlement server 100 identifies the user corresponding to the account ID.

[0034] Note that the "post-payment" settlement may be performed inside the settlement server 100 instead of being managed by the credit card server 200. In this case, the configurations such as the settlement card 60 and the credit card server 200 may be omitted.

[0035] [Configuration (Card Settlement)] FIG. 7 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. This electronic payment is executed centering around a payment card 60 which is one of the media M, a credit processing terminal 70 which is one of the store facilities E, a payment server 100 and a credit card server 200 which constitute part of the payment system S. The credit card server 200 communicates with the credit processing terminal 70 via the network NW.

[0036] The credit processing terminal 70 is installed in the store, similar to the store payment terminal 30. The credit processing terminal 70 includes, for example, a credit payment terminal (credit card reader) and a POS device. The credit payment terminal reads a PIN (Personal Identification Number) from the inserted or swiped credit card and collates it with the PIN input by the user, or transmits the PAN (Primary Account Number) read from the credit card to the credit card server 200 via the POS device. The POS device transmits information such as the payment amount to the credit card server 200 in cooperation with the credit payment terminal. An acquirer server may be interposed between the credit processing terminal 70 and the credit card server 200, but hereinafter, for simplicity of explanation, the description of the acquirer server will be omitted. The payment card 60 is, for example, in a form similar to a generally popular credit card, with a communication chip embedded in the card substrate. The communication chip incorporates a storage medium storing the PIN and communicates with an external device via a contactor (or a wireless antenna). Alternatively, the payment card 60 may be a magnetic card. Note that, among the information (messages) transmitted and received during the use of the credit card, there are an authorization message for authentication and a sales message for transmitting the payment amount, but hereinafter, a detailed description distinguishing these will be omitted.

[0037] The credit card server 200 communicates with the payment server 100 via the network NW. The credit card server 200 has, for example, an information management unit 210, a credit interface 220, a payment allocation unit 230, a credit payment processing unit 240, and a storage unit 270. Components other than the storage unit 270 are realized, for example, by a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry such as LSI, ASIC, FPGA, GPU), or may be realized by the cooperation of software and hardware. The program may be stored in advance in a storage device (a storage device having a non-transitory storage medium) such as an HDD or a flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or a CD-ROM, and may be installed in the storage device when the storage medium is mounted on a drive device. Information such as card user information 272 is stored in the storage unit 270.

[0038] The information management unit 210 edits, adds, deletes, etc. the card user information 272 and manages them. The card user information 272 is information in which, for example, information unique to the user (e.g., PAN), a card payment method, and the user's account ID (used by the payment server 100) are associated with each other. The card payment method is setting information indicating whether the user performs electronic payment based on the charge balance (balance payment) or performs payment by deferred payment in card payment.

[0039] The credit interface 220 determines whether the BIN (Bank Identification Number) in the PAN included in the telegram received from the credit processing terminal 70 is a code for the company itself. If it is a code for the company itself, the telegram received from the credit processing terminal 70 is passed to the payment allocation unit 230, and if it is not a code for the company itself, the received telegram is discarded.

[0040] The settlement transfer unit 230 refers to the user's card user information 272 corresponding to the message obtained from the credit interface 220, and determines whether the "card settlement method" is set to "post-payment". If the "card settlement method" is set to "post-payment", the settlement transfer unit 230 notifies the credit interface 220 to that effect and passes the message obtained from the credit interface 220 to the credit settlement processing unit 240. On the other hand, if the "card settlement method" is set to "balance payment", the settlement transfer unit 230 adds the user's account ID to the message obtained from the credit interface 220 and sends it to the settlement server 100 to request an electronic payment. The settlement server 100 requested for an electronic payment performs the same processing as S7-1 in FIG. 5 and S17-1 in FIG. 6.

[0041] The credit interface 220 checks the PAN and expiration date, and checks whether the cumulative settlement amount exceeds the monthly limit. The credit settlement processing unit 240 performs an electronic payment by adding the settlement amount to the user's monthly usage amount based on the information contained in the message obtained from the settlement transfer unit 230, and deducting the monthly usage amount from the user's bank account after the closing date.

[0042] [Anti-fraud] The operation of the settlement server 100 for preventing unauthorized use will be described below. As described in connection with FIG. 6, the code image providing unit 140 generates a one-time code, which is an example of information for displaying a code image, and sends it to the settlement application 20. The code image is used for authenticating the user in various scenarios for receiving the electronic payment service.

[0043] When the authentication unit 150 obtains notification information indicating that a predetermined operation (described later) enabling copying of the predetermined screen has been performed while the predetermined screen of the settlement application 20 is being displayed, the authentication unit 150 permits the provision of the electronic payment service based on the confirmation results of a plurality of confirmation items including whether the notification information has been obtained. The predetermined screen includes a screen on which a code image is displayed.

[0044] For example, when the authentication unit 150 acquires decoding information based on the information obtained by decoding a code image from a new user terminal device 10-2 that has read a code image for login authentication in order to transfer an account from an old user terminal device 10-1 to the new user terminal device 10-2, the authentication unit 150 permits the provision of services (transfer of the account) to the new user terminal device 10-2 based on the decoding information and the confirmation results of a plurality of confirmation items. The content of the decoding information will be described later. FIG. 8 is a diagram showing an example of the display screens respectively displayed by the old user terminal device 10-1 and the new user terminal device 10-2 when the account transfer is performed. As shown in the figure, in the old user terminal device 10-1, first, when an account transfer operation is performed, a one-time code request is made from the payment application 20 to the code image providing unit 140, and a code image for login authentication is displayed based on the one-time code provided by the code image providing unit 140. By reading this with the new user terminal device 10-2, the new user terminal device 10-2 can log in.

[0045] In addition, when the authentication unit 150 acquires decoding information based on the information obtained by decoding a code image from a device that has read a code image for payment using an electronic payment service, the authentication unit 150 may permit the provision of services (in this case, performing payment) based on the decoding information and the confirmation results of a plurality of confirmation items. FIG. 9 is a diagram showing an example of the display screen on which the user terminal device 10 displays a code image for payment. In this display screen, a code image is displayed in area A1, and payment is performed according to the process described with reference to FIG. 6. Also, the available amount and the like at this point are displayed together. Note that the code image is displayed not only when a payment operation is performed but also on the home screen of the payment application 20. Similar to the code image for payment, the home image is also treated as an object for permission / forbiddance of service provision.

[0046] In addition, the electronic payment service includes a money transfer service between users. When the authentication unit 150 obtains decoded information based on the information obtained by decoding a code image from another user terminal device 10 that has read the code image for confirming the other party when a money transfer between users (both the sender and the recipient of the amount) is made, the authentication unit 150 may permit service provision (in this case, registration as the recipient of the money transfer or the money transfer itself for the user related to the user terminal device 10 that has displayed the code image) based on the decoded information and the confirmation results of a plurality of confirmation items. FIG. 10 is a diagram showing an example of a display screen on which the user terminal device 10 displays a code image for confirming the other party when a money transfer between users is made. On this display screen, a code image is displayed in area A1, and links for transitioning to a screen for inputting the user name (if registered) of the user and the requested amount are also displayed.

[0047] Not limited to this, the predetermined screen of the payment application 20 may include various screens that are not preferably shared with third parties, such as a charge screen, a wallet screen, and a payment confirmation screen. Further, the predetermined screen may include an image on which no code image is displayed. On the charge screen, input or selection of the charge amount and selection of the fund source (the source of the charge) are accepted, and the remaining charge amount is displayed. On the wallet screen, various values held by the user, such as the remaining charge amount, the point amount, and the investment amount, are displayed. The payment confirmation screen is displayed as a final confirmation immediately before the payment, and details of the transaction to be paid (such as the name of the affiliated store and the payment amount) and the payment source (the remaining charge amount, points, the limit for deferred payment, etc.) are displayed.

[0048] The plurality of confirmation items include at least the presence or absence of reception of notification information, and further include authentication information (FIG. 3) such as decoded information, the device ID of the user terminal device 10, the device name, the client type, the language, the time zone, the IP address, the latitude of the IP address location, the longitude of the IP address location, the effective radius of the IP address location, the name of the IP address location, the name of the ISP (Internet Service Provider), the OS, the version of the OS, and the emulator.

[0049] Here, the decoded information may include only the one-time code (assuming that the above-described settlement information is separate from the decoded information), or may include some or all of the above authentication information. Alternatively, the authentication information may be shared by communication between the payment application 20 and the authentication unit 150 separately from the decoded information, for example, when the payment application 20 is started or at regular intervals. In any case, some or all of the authentication information is transmitted from the payment application 20 to the authentication unit 150 after the OS of the user terminal device 10 and the payment application 20 share information.

[0050] Then, the authentication unit 150 calculates a score such that the degree of coincidence between the items of a plurality of confirmation items acquired most recently and the items of a plurality of comparison target confirmation items acquired at any previous timing becomes higher (a preferable value), and restricts the provision of the service when the score is not preferable (for example, lower than a threshold value). For example, the authentication unit 150 restricts the provision of the service by prohibiting login for a certain period or execution of a predetermined service (such as settlement, money transfer, or receipt).

[0051] The "predetermined operation" includes, for example, an operation of sharing a predetermined screen in a video call. The video call is a function of services provided under various names such as Zoom (registered trademark), Teams (registered trademark), and SKYPE (registered trademark). The predetermined operation may also include an operation of taking a screenshot of a predetermined screen, or may further include other operations. Also, being in a video call or being in a voice call may be added as a parameter to the score SC. In the present invention, the call described below refers to at least a voice call, and may or may not include a video call.

[0052] Also, when an inter - user transfer is attempted before or after screen sharing, the score SC may be adjusted according to the characteristics of the recipient's account (such as the account creation date, presence or absence of KYC, etc.), or the score SC may be adjusted according to the usage history of the settlement destination (if there is no usage history in the past, electronic settlement may be made unavailable). Also, when an inter - user transfer is attempted or made during a call, the score SC may be adjusted according to the characteristics of the recipient's account (such as the account creation date, presence or absence of KYC, etc.), or the score SC may be adjusted according to the usage history of the settlement destination (if there is no usage history in the past, electronic settlement may be made unavailable). Also, the recipient's account may be associated with the transfer identification information and recorded in the storage unit 170. Also, when a web settlement service (described later) is provided during a call, the merchant of the e - commerce transaction related to the web settlement service may be associated with the settlement identification information and recorded, or may be flagged in the settlement identification information.

[0053] The settlement app 20 has a function of making the code image non - visible when the above - mentioned predetermined operation is performed on a specific screen where the code image is displayed, in cooperation with the operating system (OS) of the user terminal device 10. FIG. 11 is a diagram showing an example of a screen where the code image is made non - visible. This screen is a screen that transitions by taking a screenshot from the image where the code image was displayed. A caution message prompting not to save the code image is displayed in area A3, and the code image is filled with black paint or the like. Furthermore, in the authentication device of the embodiment, by calculating the score SC as described above, permission to provide the electronic settlement service is given based on the confirmation results of a plurality of confirmation items, so that it is possible to preferably balance the prevention of unauthorized use and the maintenance of convenience.

[0054] FIG. 12 is a flowchart showing an example of the flow of processing executed centering on the authentication device. First, at an arbitrary timing, the settlement app 20 transmits the authentication information to the authentication device (integrated with the settlement server 100 in this embodiment) (S20), and the authentication device registers the authentication information in the user information 172 (S21).

[0055] Thereafter, the payment application 20 sends a one-time code request to the authentication device (S22), and the authentication device sends the one-time code to the payment application 20 (S23). Using this, the payment application 20 displays a code image (S24). When a predetermined operation is detected in that state (S25), the payment application 20 sends notification information to the authentication device (S26). Also, together with this, the payment application 20 sends authentication information to the authentication device (S27).

[0056] The authentication device compares the authentication information registered in S21 with the authentication information sent in S27, and calculates a score as described above (S28). The authentication device determines whether the score is equal to or greater than a threshold value (S29). If the score is equal to or greater than the threshold value, service provision is permitted (S30). If the score is less than the threshold value, service provision is restricted (S31). Information regarding the restriction of service provision is transmitted to the payment processing unit 130 etc., and is reflected in the subsequent processing of the payment server 100.

[0057] [Operations during a call in the payment application] In the payment application 20, further, processing for preventing unauthorized use is performed as follows. The payment application 20 detects that the user terminal device is making a call, and when the user terminal device is making a call and an operation for instructing the execution of a specific service involving the user's withdrawal is performed, a warning screen is displayed before the execution of the specific service.

[0058] The specific service is, for example, a money transfer service to another user by user-to-user money transfer and / or a web payment service. The web payment service is a service for performing electronic payment on the web in an e-commerce different from the electronic payment service using the electronic payment service, and is started by accessing a web page provided by an e-commerce operator. Other services involving the user's withdrawal may be treated as specific services in the same way.

[0059] FIG. 13 is a diagram showing an example of screen transition of the settlement application 20 when an instruction to execute a money transfer service to another user is given during a call. The screen IM1 shown on the left side is an example of a screen for receiving a money transfer instruction to another user. In the screen IM1, areas A1-1 and A1-2 are provided. In the area A1-1, identification information of another user who is the recipient of the money transfer, the set money transfer amount, etc. are displayed, and buttons for receiving additional messages are provided. In the area A1-2, the money transfer amount, charge balance, etc. are displayed, and a button B1 for instructing the execution of the money transfer is provided.

[0060] When the button B1 is operated, if the user terminal device 10 of the user attempting to transfer money is in a call, a screen IM2, which is an example of a warning screen, is displayed. The fact that the user terminal device 10 is in a call can be detected, for example, by the settlement application 20 making an inquiry to the operating system (OS) using an API (Application Programming Interface) or the like. Alternatively, the operating system (OS) may automatically notify the settlement application 20 that it is in a call.

[0061] The screen IM2 includes an area A2 that is displayed as a half-sheet (refers to something that is displayed using a partial area rather than the entire screen). The warning content is described in the area A2. The warning content is, for example, to inform that there has been a fraud where an illegal actor induced a call with a counterpart through SNS or the like and deceived the counterpart into making a money transfer by saying something like "Please transfer a security deposit before I transfer money from here". A button B2 is provided on the screen IM2, but the button B2 is in a non-operable state at the start of the display of the screen IM2. A check box CB2 is provided on the screen IM2, and when the user operates the check box CB2 to check it, the button B2 becomes operable. When the button B2 is operated in that state, the settlement application 20 instructs the settlement server 100 to execute the money transfer. Operating the button B2 after operating the check box CB2 is an example of an "operation to accept the warning content".

[0062] Figures 14 to 15 are diagrams showing an example of the screen transition of the payment application 20 when the start of the web payment service is instructed during a call. Figure 14 is a diagram exemplifying a message (e-mail, short message, message of a message application, or message of user-to-user communication in the payment application 20, etc.) transmitted to the user terminal device 10 in order to cause the user to execute the web payment service. When the code image shown in the left diagram of Figure 14 is read by the payment application 20, or when the link (URL) shown in the right diagram of Figure 14 is operated by the user, the screen IM3 of the payment application 20 shown in Figure 15 is displayed. The payment application 20 reading the code image can be achieved, for example, by an operation of downloading the code image to the user terminal device 10 once and uploading the image file to the payment application 20 (an operation of selecting the image file from the "scan" instruction). Since the code image has information equivalent to the URL of the link destination embedded therein, when this is read by the payment application 20, the same phenomenon as when the link shown on the right side of Figure 14 is operated occurs.

[0063] The code image or the link has information embedded therein for performing web-based payment in an e-commerce service (a service referred to as shopping, auction, free market, e-commerce, etc.) different from the electronic payment service using the electronic payment service. This information is, for example, information for reproducing the state when a malicious person accesses a web page provided by an e-commerce operator and instructs to use the electronic payment service for payment regarding the purchase of goods or services (and starts up the payment application 20 accordingly). However, the delivery destination of the goods or services in the e-commerce service embedded in the code image or the link is the malicious actor, and the user cannot receive the goods or services even if the user makes a payment in the electronic payment service. Note that there may be cases where false inducement information such as whether the user can receive a refund is also displayed in the message shown in Figure 14.

[0064] The screen IM3 shown in FIG. 15 has an area A3 displayed and a button B3 provided for instructing the execution of payment. In the area A3, the payment amount, balance, etc. of the web payment service are displayed, and a switch for selecting whether to use points is provided.

[0065] When the button B3 is operated, if the user terminal device 10 of the user attempting to make a payment is in a call, a screen IM3, which is another example of a warning screen, is displayed. The screen IM3 includes an area A4 displayed in a half-sheet (referring to something displayed using a partial area rather than the full screen). In the area A4, the warning content is described. The warning content is, for example, to inform that there has occurred a fraud where an illegal actor induces a counterpart to make a payment by deceiving the counterpart with content such as "Please make a predetermined payment before we refund from our side" while making a call with the counterpart solicited on SNS or the like. A button B4 is provided on the screen IM4, but the button B4 is in a state where it cannot be operated at the start of the display of the screen IM4. A check box CB4 is provided on the screen IM4, and when the user operates the check box CB4 to check it, the button B4 becomes operable. When the button B4 is operated in that state, the payment application 20 instructs the payment server 100 to execute the payment. Operating the button B4 after operating the check box CB4 is another example of an "operation to approve the warning content".

[0066] FIG. 16 is a flowchart showing an example of the flow of processing executed by the payment application 20 described above. The processing of this flowchart is repeated, for example, at a predetermined cycle. First, the payment application 20 determines whether an operation for instructing the execution of a specific service has been made by the user (S40). If no operation for instructing the execution of the specific service has been made, the processing of this flowchart ends.

[0067] When an operation is performed to instruct the execution of a specific service, the payment application 20 determines whether the user terminal device 10 is in a call state (S41). If the user terminal device 10 is not in a call state, the payment application 20 instructs the payment server 100 to execute the specific service (S42). If the user terminal device 10 is in a call state, the payment application 20 displays a warning message (S43). Then, it is determined whether an operation to approve the warning content has been performed by the user (S44). If an operation to approve the warning content has been performed, the payment server 100 is instructed to execute the specific service (S42). If a cancel operation is performed without an operation to approve the warning content, the processing of this flowchart ends.

[0068] In this way, the execution of a money transfer service or a web payment service to another user during a call may be configured not to be performed until prohibited by the payment server 100 when an approval operation is performed. However, users who make many money transfers during a call, users who receive many money transfers, franchise stores that perform many web payments during a call, etc. within a certain period may be determined (extracted) using a threshold value or the like, and a warning display may be made on the administrator's screen (not shown) of the payment server 100, a warning may be notified to the payment application 20 of the user, or it may be used as a fraud detection score. Furthermore, for users who are subject to a warning or a caution, instead of a warning display, the execution of the money transfer service and / or the web payment service may be prohibited.

[0069] In this way, the payment application 20 of the embodiment causes the user terminal device 10 to execute a process of detecting that the user terminal device 10 is performing at least a voice call, and a process of displaying a warning screen before the execution of a specific service when the user terminal device 10 is in a call and an operation is performed to instruct the execution of a specific service involving the user's withdrawal. Thereby, unauthorized use can be more reliably prevented.

[0070] As described above, the embodiments for carrying out the present invention have been described using the embodiments. However, the present invention is not limited to such embodiments at all, and various modifications and substitutions can be made without departing from the gist of the present invention.

Explanation of Signs

[0071] E Store equipment M Medium S Settlement system 10 User terminal device 20 Settlement application 30 Store settlement terminal device 40 Store code image 100 Settlement server 140 Code image providing unit 150 Authentication unit 172 User information

Claims

1. An application program that operates on a user terminal device and cooperates with a service server to provide a service to a user, The user terminal device Detecting that the user terminal device is engaged in at least a voice call by querying an operating system running on the user terminal device; a process of displaying a warning screen before execution of a specific service involving withdrawal by the user, when the user terminal device is making the call and an operation for instructing execution of the specific service involving withdrawal by the user is performed; An application program for executing the following:

2. When an operation is performed on the user terminal device to instruct the execution of a specific service involving a withdrawal by the user, an inquiry is made to the operating system.

2. The application program according to claim 1.

3. An application program that operates on a user terminal device and cooperates with a service server to provide a service to a user, The user terminal device detecting that the user terminal device is engaged in at least a voice call by receiving a notification from an operating system running on the user terminal device; a process of displaying a warning screen before execution of a specific service involving withdrawal by the user, when the user terminal device is making the call and an operation for instructing execution of the specific service involving withdrawal by the user is performed; An application program for executing the following:

4. The specific service is a remittance service to another user.

4. The application program according to claim 1.

5. the service is an electronic payment service; the specific service is a service for making an electronic payment on a web site in an electronic commerce transaction different from the electronic payment service by using the electronic payment service; 4. The application program according to claim 1.

6. The specific service is started to be provided by accessing a web page provided by the electronic commerce business operator.

6. The application program according to claim 5.

7. The user terminal device when the user performs an operation to accept the warning content on the warning screen, a process of instructing the service server to execute the specific service is further executed.

4. The application program according to claim 1.

8. An application program according to any one of claims 1 to 3; The service server; The application program notifies the service server that the user terminal device is engaged in at least a voice call; the service server restricts provision of services based on a result of checking a plurality of check items including whether the user terminal device is at least making a voice call; Service delivery system.

9. the service server calculates a score based on the check results of the plurality of check items, and restricts provision of the service if the score is unfavorable. The service providing system according to claim 8.

10. The service server extracts at least a portion of users whose remittance amount or number of remittances during a certain period of time is equal to or exceeds a threshold, users whose received remittance amount or number of received remittances is equal to or exceeds a threshold, and affiliated stores whose web payment amount or number of web payments during a certain period of time is equal to or exceeds a threshold, and displays a warning on the screen of a terminal device of an administrator of the service server based on the extracted information. The service providing system according to claim 8.

Citation Information

Patent Citations

  • Transaction device and program

    JP2014021784A

  • Frequency calculation device, method, and program

    JP2015138141A

  • Information processing device, information processing method, and information processing program

    JP7583203B1

  • Monitoring apparatus and monitoring apparatus method

    WO2023243172A1

  • SERVICE PROVIDING APPARATUS, SERVICE PROVIDING METHOD, AND PROGRAM

    JP7453458B1