Information processing system, information processing method, program
The information processing system addresses the challenge of balancing convenience and security in settlement systems by using public key authentication and secure transmission of payment information, resulting in robust and user-friendly payment processing.
Patent Information
- Application Number
- JP2024122111
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-07-29
- Publication Date
- 2025-06-19
- Estimated Expiration
- 2044-07-29
AI Technical Summary
Existing settlement systems face challenges in balancing convenience and security, particularly due to the association of user passwords and credit card information, which can lead to security risks and inconvenience when passwords are forgotten.
An information processing system that includes a payment means information registration unit, a payment information acquisition unit, an authentication unit using public key authentication, and a transmission unit to securely and conveniently process payments by transmitting user and store identifiers along with payment information to a payment processing device.
The system achieves both security and convenience in payment processing by ensuring robust authentication and preventing misuse of credit card information, while allowing for secure transactions without the need for users to input passwords.
Smart Images

Figure 0007695736000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, and a program.
Background Art
[0002] Patent Document 1 discloses an authentication and settlement method that enables settlement for purchasing goods and services with a single medium by associating and managing a user ID, a user password, card information of a credit card, etc.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, for settlement services at the time of purchasing goods and services, while convenience such as ease of use and time saving is required, robustness and security against security risks such as hacking, skimming, and phishing fraud are also required. However, in the technical idea of Patent Document 1, since the user password and card information of the credit card are managed in association with each other, there is a concern that if the user password is stolen, the credit card or the like may be misused. In addition, there is also a concern that if the user forgets the user password, settlement using a credit card or the like will become impossible.
[0005] Therefore, the present invention has been made in view of the above problems, and an object thereof is to provide an information processing system capable of achieving both security and convenience in settlement.
Means for Solving the Problems
[0006] The present invention relates to an information processing system, comprising: a payment means information registration unit that registers payment means information used by a user for payment in a payment processing device; a payment information acquisition unit that acquires payment information including at least the amount purchased by the user at a store from a store terminal or a store server managed by the store; an authentication unit that authenticates the store terminal or the store server and a user terminal used by the user by a public key authentication method; and a transmission unit that transmits, when the authentication by the authentication unit is successful, a user identifier for identifying the user, a store identifier for identifying the store, and the payment information acquired by the payment information acquisition unit to the payment processing device. The payment processing device executes a payment process based on the user identifier, the store identifier, the payment information, and the payment means information registered by the payment means information registration unit.
Effects of the Invention
[0007] According to the information processing system of the present invention, there is an effect that it is possible to achieve both security and convenience in payment.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Embodiments for Carrying Out the Invention
[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Various characteristic matters shown in the following embodiments can be combined with each other.
[0010] Incidentally, the program for realizing the software that appears in this embodiment may be provided as a non-transitory computer-readable medium that can be read by a computer, may be provided so as to be downloadable from an external server, or may be provided so that the program is launched on an external computer and its functions are realized on a client terminal (so-called cloud computing).
[0011] Also, in this embodiment, the "section" may include, for example, a combination of hardware resources implemented by a circuit in a broad sense and information processing of software that can be specifically realized by these hardware resources. Also, in this embodiment, various types of information are handled, and these information are represented, for example, by physical values of signal values representing voltage and current, the high and low of signal values as a set of binary bits composed of 0 or 1, or quantum superposition (so-called quantum bits), and communication and calculation can be executed on a circuit in a broad sense.
[0012] Also, the circuit in a broad sense is a circuit realized by appropriately combining at least a circuit, circuitry, a processor, a memory, and the like. That is, it includes an application specific integrated circuit (ASIC), programmable logic devices (for example, a simple programmable logic device (SPLD), a complex programmable logic device (CPLD), and a field programmable gate array (FPGA)), and the like.
[0013] 1. Hardware Configuration In the first section, the hardware configuration of the information processing system 1 according to this embodiment will be described.
[0014] FIG. 1 is a diagram showing an example of the overall configuration of the information processing system 1 according to the present embodiment. As shown in FIG. 1, the information processing system 1 includes an information processing apparatus 100, a user terminal 200, a store terminal 300, a store server 400, and a settlement processing apparatus 500, which are connected through a network NW. These components will be further described. Here, the system exemplified in the information processing system 1 is composed of one or more devices or components. Therefore, for example, the information processing apparatus 100 alone can be an example of the information processing system 1. Further, such a FIG. 1 is merely an example for explaining the invention, and for example, the number of user terminals 200, the number of store terminals 300, and the number of store servers 400 are not limited as shown in FIG. 1.
[0015] 1-1. Information Processing Apparatus 100 FIG. 2 is a diagram showing the hardware configuration of the information processing apparatus 100. As shown in FIG. 2, the information processing apparatus 100 includes a control unit 110, a storage unit 120, and a communication unit 130, and these components are electrically connected via a communication bus 160 inside the information processing apparatus 100. Each component will be further described.
[0016] The control unit 110 performs processing and control of the overall operation related to the information processing apparatus 100. The control unit 110 is, for example, a central processing unit (CPU) (not shown). The control unit 110 realizes various functions related to the information processing apparatus 100 by reading a predetermined program stored in the storage unit 120. That is, the information processing by software stored in the storage unit 120 is specifically realized by the control unit 110, which is an example of hardware, and can be executed as each functional unit included in the control unit 110. These will be described in more detail in the next section. Note that the control unit 110 is not limited to being single, and may be implemented to have a plurality of control units 110 for each function, or a combination thereof.
[0017] The memory unit 120 stores various information necessary for the information processing of the information processing apparatus 100. This can be implemented, for example, as a storage device such as a solid state drive (SSD) that stores various programs and the like related to the information processing apparatus 100 executed by the control unit 110, or as a memory such as a random access memory (RAM) that stores information (arguments, arrays, etc.) temporarily necessary for the calculation of the program. Also, a combination of these may be used.
[0018] Although wired communication means such as USB, IEEE1394, Thunderbolt (registered trademark), and wired LAN network communication are preferred for the communication unit 130, wireless LAN network communication, mobile communication such as 5G / LTE / 3G, and BLUETOOTH (registered trademark) communication may be included as necessary. That is, it is more preferably implemented as a collection of these multiple communication means. That is, the communication unit 130 communicates various information with the user terminal 200, the store terminal 300, the store server 400, and the payment processing apparatus 500 via the network NW.
[0019] 1-2. User Terminal 200 The user terminal 200 is a terminal device used by a user (hereinafter referred to as "user US"). The user terminal 200 may be a fixed terminal or a mobile terminal realized by a computer device. Examples of the user terminal 200 include smartphones, mobile phones, PCs (personal computers), notebook PCs, tablet PCs, and the like. The user terminal 200 may be realized as the user terminal 200 of the present embodiment by installing, for example, an application on a general terminal device.
[0020] FIG. 3 is a diagram showing the hardware configuration of the user terminal 200. As shown in FIG. 3, the user terminal 200 includes a control unit 210, a storage unit 220, a communication unit 230, an input unit 240, and an output unit 250, and these components are electrically connected via a communication bus 260 inside the user terminal 200. The descriptions of the control unit 210, the storage unit 220, and the communication unit 230 are omitted because they are substantially the same as the descriptions of the control unit 110, the storage unit 120, and the communication unit 130 in the information processing apparatus 100.
[0021] The input unit 240 is for inputting various information into the user terminal 200, and receives signals input from a mouse, a keyboard, a pointing device, a touch display, a camera, etc. The operation input to the input unit 240 is transferred as a command signal to the control unit 210 via the communication bus 260. Then, the control unit 210 can execute predetermined control and calculations as necessary.
[0022] The output unit 250 is for displaying text and images, and generates information to be displayed on a display device such as a CRT display, a liquid crystal display, an organic EL display, a plasma display, or a touch display.
[0023] 1-3. Store Terminal 300 The store terminal 300 is a terminal device managed by a store (hereinafter referred to as "store SP"). The description of the store terminal 300 is omitted because it is substantially the same as the description of the user terminal 200.
[0024] FIG. 4 is a diagram showing the hardware configuration of the store terminal 300. As shown in FIG. 4, the store terminal 300 includes a control unit 310, a storage unit 320, a communication unit 330, an input unit 340, and an output unit 350, and these components are electrically connected via a communication bus 360 inside the store terminal 300. The descriptions of the control unit 310, the storage unit 320, the communication unit 330, the input unit 340, and the output unit 350 are omitted because they are substantially the same as the descriptions of the control unit 210, the storage unit 220, the communication unit 230, the input unit 240, and the output unit 250 in the user terminal 200.
[0025] 1-4. Store Server 400 The store server 400 is a server device managed by the store SP, and is, for example, an API (Application Programming Interface) server, a Web server, or the like.
[0026] FIG. 5 is a diagram showing the hardware configuration of the store server 400. As shown in FIG. 5, the store server 400 includes a control unit 410, a storage unit 420, and a communication unit 430, and these components are electrically connected via a communication bus 460 inside the store server 400. The descriptions of the control unit 410, the storage unit 420, and the communication unit 430 are omitted because they are substantially the same as the descriptions of the control unit 110, the storage unit 120, and the communication unit 130 in the information processing apparatus 100.
[0027] 1-5. Settlement Processing Device 500 The settlement processing device 500 is a device that executes settlement processing, and is, for example, an API (Application Programming Interface) server, a Web server, or the like. The settlement processing device 500 may be a server managed by a settlement service providing company (credit card company, convenience store, bank, communication carrier, etc.) that provides settlement services by various settlement means, or a settlement agency company.
[0028] FIG. 6 is a diagram showing the hardware configuration of the settlement processing device 500. As shown in FIG. 6, the settlement processing device 500 includes a control unit 510, a storage unit 520, and a communication unit 530, and these components are electrically connected via a communication bus 560 inside the settlement processing device 500. The descriptions of the control unit 510, the storage unit 520, and the communication unit 530 are omitted because they are substantially the same as the descriptions of the control unit 110, the storage unit 120, and the communication unit 130 in the information processing apparatus 100.
[0029] 2. Functional Configuration In Section 2, the functional configuration of the present embodiment will be described. As described above, the information processing by the software stored in the storage unit 120 is specifically realized by the control unit 110 which is an example of hardware, and can be executed as each functional unit included in the control unit 110.
[0030] FIG. 7 is a block diagram showing the functions realized by the information processing apparatus 100 (control unit 110). Specifically, the information processing apparatus 100 (control unit 110) includes a payment means information registration unit 111, an authentication information registration unit 112, a payment information acquisition unit 113, an authentication unit 114, a transmission unit 115, a payment approval acquisition unit 116, and a personal authentication request unit 117.
[0031] (Payment means information registration unit 111) The payment means information registration unit 111 is configured to be able to register various payment means information. For example, the payment means information registration unit 111 is configured to be able to register the payment means information (hereinafter referred to as "payment means information PY") used by the user US for payment in the payment processing apparatus 500. Further, for example, the payment means information registration unit 111 may be configured to be able to register a user identifier (hereinafter referred to as "user identifier USID") for identifying the user US in the payment processing apparatus 500.
[0032] Here, the "user US" includes all users (end users) who purchase goods or services. The "user identifier USID" includes all characters, numbers, symbols, or combinations thereof that can identify the user US, and includes, for example, a user ID and the like.
[0033] The "payment means information PY" includes information necessary for payment processing by any payment means, and includes, for example, information necessary for payment processing by a prepaid payment means, an immediate payment means, or a postpaid payment means. For example, the following information is meant, and these information are registered in the payment processing apparatus by the user. Prepaid payment means refers to a payment method where, before purchasing goods or services, cash or electronic money is charged in advance, enabling payment up to the charged amount. Examples include gift vouchers, catalog gift vouchers, magnetic or IC prepaid cards, or prepaid cards used on the Internet. More specifically, for gift vouchers and catalog gift vouchers, information such as the numbers assigned to the vouchers, expiration dates, and security codes may be included. For prepaid cards, cardholder name, card number, card expiration date, security code, etc. are examples. Note that prepaid payment means also include mobile types (e.g., Suica (registered trademark)), QR code types (e.g., PayPay (registered trademark)), and server types (e.g., Apple (registered trademark) Gift), and the necessary information for registering such registration information in the payment process is also included. Immediate payment means refers to a payment method where, when purchasing goods or services, the payment amount is immediately debited from a bank account, electronic money, or cryptocurrency account. Examples include debit cards. More specifically, for debit cards, for example, cardholder name, card number, card expiration date, security code, etc. may be included. Postpaid payment means refers to a payment method where, after purchasing goods or services, cash or electronic money is paid in a lump sum. Examples include credit cards, bank transfers, or account transfers. More specifically, for credit cards, credit cardholder name, credit card number, credit card expiration date, security code, payment method (e.g., lump sum payment, installment payment, etc.) may be included. For bank transfers, bank name, branch name, deposit type, account number, account holder name, etc. may be included. For account transfers, bank name, branch name, deposit type, account number, account holder name, kana name, address, phone number, etc. may be included. Note that postpaid payment means also include mobile types (e.g., iD (registered trademark)), QR code types (e.g., PayPay (registered trademark)), and the necessary information for registering such registration information in the payment process is also included.
[0034] Note that "registration" includes storing the payment means information PY input by the user US in the storage unit 520 of the payment processing device 500. For example, it may include storing the payment means information PY input to an application or website provided by the payment processing device 500 in the storage unit 520 of the payment processing device 500, or transmitting the payment means information PY input to an application or website provided by the information processing device 100 to the payment processing device 500 and storing it in the storage unit 520 of the payment processing device 500, and the like.
[0035] (Authentication information registration unit 112) The authentication information registration unit 112 is configured to be able to register various authentication information. For example, the authentication information registration unit 112 is configured to be able to register authentication information for authenticating the user terminal 200 and the store terminal 300 or the store server 400.
[0036] Here, "authentication" includes entity authentication for verifying whether the communication partner is genuine. Also, as the "authentication" method, an authentication method using reversible encryption or an authentication method using irreversible encryption can be mentioned. The authentication method using reversible encryption refers to an authentication method using an encryption method in which the encrypted information can be decrypted. For example, a common key authentication method, a public key authentication method, etc. can be mentioned. The authentication method using irreversible encryption refers to an authentication method using an encryption method in which the encrypted information cannot be decrypted. For example, an authentication method using an ID or a password, etc. can be mentioned.
[0037] The authentication method in the present invention is preferably an authentication method using reversible encryption, more preferably a public key authentication method, and even more preferably a two-way public key authentication method, from the viewpoint of achieving both convenience and security in payment. The "public key authentication method" means a method in which one device (terminal) generates a public key and a private key, and transmits the generated public key to the other device (terminal) for authentication. The "two-way public key authentication method" means a method in which one device (terminal) and the other device (terminal) each generate a public key and a private key, exchange the generated public keys, and authenticate each other.
[0038] When the authentication method is the public key authentication method, the authentication information registration unit 112 may be configured to be able to register an authentication key for authenticating the user terminal 200 and the store terminal 300 or the store server 400. For example, the authentication information registration unit 112 may be configured to be able to register the user-side public key (hereinafter referred to as "user-side public key USOP") among the user-side private key (hereinafter referred to as "user-side private key USSC") and the user-side public key generated by the user terminal 200 in the store terminal 300 or the store server 400. In addition, the authentication information registration unit 112 may be configured to be able to register the store-side public key (hereinafter referred to as "store-side public key SPOP") among the store-side private key (hereinafter referred to as "store-side private key SPSC") and the store-side public key generated by the store terminal 300 or the store server 400 in the user terminal 200.
[0039] Furthermore, when the authentication method is the two-way public key authentication method, the authentication information registration unit 112 may be configured to register the user-side public key USOP in the store terminal 300 or the store server 400 and register the store-side public key SPOP in the user terminal 200. Thereby, two-way public key authentication is executed between the user terminal 200 and the store terminal 300 or the store server 400, so that the convenience and security in settlement can be further made compatible.
[0040] Note that "registration" includes storing predetermined authentication information in the storage unit 220 of the user terminal 200, the storage unit 320 of the store terminal 300, or the storage unit 420 of the store server 400.
[0041] (Settlement information acquisition unit 113) The settlement information acquisition unit 113 is configured to be able to acquire various settlement information. For example, the settlement information acquisition unit 113 is configured to be able to acquire settlement information (hereinafter referred to as "settlement information GS") that at least includes the amount of purchase made by the user US at the store SP from the store terminal 300 or the store server 400 managed by the store SP. Further, for example, the settlement information acquisition unit 113 may be configured to be able to acquire a store identifier (hereinafter referred to as "store identifier SPID") that identifies the store SP from the store terminal 300 or the store server 400 managed by the store SP.
[0042] "Store SP" includes a physically existing actual store or a virtual store on a website (EC (Electronic Commerce) site) that conducts e-commerce transactions. "Store identifier SPID" includes any characters, numbers, symbols, or combinations thereof that can identify the store SP, and includes, for example, a store ID, etc. "Management" includes ownership, possession, occupancy, borrowing, contracting, or use, etc. by employees or staff of the store SP, or a contractor commissioned by the store SP.
[0043] "Settlement information GS" includes all settlement information for goods or services, and includes, for example, an identification ID, name, amount, unit price, quantity, discount rate, discounted amount, or other information for the goods or services. The types of goods or services are not particularly limited, and include all goods or services such as clothing, food, daily necessities, electrical appliances, financial products, furniture, books, beauty treatments, training, seminars, travel, chiropractic, massage, etc.
[0044] Note that "acquisition" includes receiving the settlement information GS from the store terminal 300 or the store server 400, and may further include storing the received settlement information GS in the storage unit 120.
[0045] (Authentication unit 114) The authentication unit 114 is configured to be able to authenticate various terminals and servers. For example, the authentication unit 114 is configured to be able to authenticate the store terminal 300 or the store server 400 and the user terminal 200 used by the user US. Note that "authentication" includes entity authentication for verifying whether the communication partner is genuine, as described above. Also, the "authentication" method is preferably an authentication method using reversible encryption, more preferably a public key authentication method, and even more preferably a two-way public key authentication method, from the perspective of achieving both convenience and security in settlement, as described above.
[0046] That is, the authentication unit 114 is configured to be able to authenticate the store terminal 300 or the store server 400 and the user terminal 200 used by the user US by means of a public key authentication method. For example, the authentication unit 114 is configured to be able to authenticate the user terminal 200 using the user-side public key USOP registered in the store terminal 300 or the store server 400. Also, for example, the authentication unit 114 is configured to be able to authenticate the store terminal 300 or the store server 400 using the store-side public key SPOP registered in the user terminal 200.
[0047] Furthermore, the authentication unit 114 is configured to be able to authenticate the store terminal 300 or the store server 400 and the user terminal 200 used by the user US by means of a two-way public key authentication method. For example, the authentication unit 114 is configured to authenticate the user terminal 200 using the user-side public key USOP registered in the store terminal 300 or the store server 400, and to be able to authenticate the store terminal 300 or the store server 400 using the store-side public key SPOP registered in the user terminal 200. Note that the details of the authentication method will be described later.
[0048] (Transmission unit 115) The transmission unit 115 is configured to be able to transmit various information. For example, when the authentication by the authentication unit 114 is successful, the transmission unit 115 is configured to be able to transmit the user identifier USID that identifies the user US, the store identifier SPID that identifies the store SP, and the payment information GS acquired by the payment information acquisition unit 113 to the payment processing device 500.
[0049] Furthermore, for example, when the authentication by the authentication unit 114 fails, the transmission unit 115 can be configured to be unable to transmit the user identifier USID, the store identifier SPID, and the payment information GS to the payment processing device 500.
[0050] Here, when the user terminal 200 and the store terminal 300 or the store server 400 are authenticated by a two-way public key authentication method, "when the authentication is successful" means that the authentication of the user terminal 200 using the user-side public key USOP registered in the store terminal 300 or the store server 400, and the authentication of the store terminal 300 or the store server 400 using the store-side public key SPOP registered in the user terminal 200 are successful.
[0051] (Payment Approval Acquisition Unit 116) The payment approval acquisition unit 116 is configured to be able to acquire various payment approvals. For example, the payment approval acquisition unit 116 is configured to be able to acquire a payment approval (hereinafter referred to as "payment approval AG") for the payment information GS from the user terminal 200.
[0052] Here, the method of acquiring the payment approval AG is not particularly limited. For example, the payment approval acquisition unit 116 may display the payment information GS on the user terminal 200 and accept the input of the payment approval AG by the user US. Note that the input of the payment approval AG may include, for example, tapping or clicking a payment approval button.
[0053] (Identity Authentication Request Unit 117) The identity authentication request unit 117 is configured to be able to request various identity authentications. For example, the identity authentication request unit 117 is configured to be able to request identity authentication (hereinafter referred to as "identity authentication CF") from the user terminal 200. Here, the "user authentication CF" includes any authentication that can confirm that the person operating the user terminal 200 is the user US himself / herself. For example, the "user authentication CF" includes knowledge authentication that authenticates an individual using memory information memorized by the user US, possession authentication that authenticates an individual using possession information possessed by the user US, biometric authentication that authenticates an individual using biometric information of the user US, or multi-factor authentication combining these. Further, for example, it may include password authentication, authentication by secret questions (security questions), fingerprint authentication, face authentication, iris authentication, vocal cord authentication, vein authentication, PIN (Personal Identification Number) code authentication, one-time password authentication, mnemonic authentication, CAPTCHA authentication, 3D Secure authentication, SMS authentication, or other authentication.
[0054] 3. Information Processing In Section 3, the operation flow of the information processing system 1 configured as described above will be explained. FIGS. 8 to 11 are flowcharts showing an example of information processing in the information processing system 1 according to the present embodiment.
[0055] 3-1. Payment Method Information Registration Process FIG. 8 is a flowchart showing an example of the payment method information registration process in the information processing system 1 according to the present embodiment (steps S101 to S105).
[0056] In step S101, the control unit 210 of the user terminal 200 requests the information processing apparatus 100 to register the payment means information PY. Step S101 is composed of the following five-stage information processing. (1) The control unit 210 of the user terminal 200 activates a predetermined application. (2) The output unit 250 of the user terminal 200 outputs a menu screen (hereinafter referred to as "menu screen W100") that can request the registration of the payment means information PY. (3) The input unit 240 of the user terminal 200 receives a registration request for the payment means information PY. (4) The input unit 240 of the user terminal 200 transfers the input registration request for the payment means information PY to the control unit 210 via the communication bus 260. (5) The control unit 210 of the user terminal 200 transmits a registration request for the payment means information PY to the information processing apparatus 100 via the communication unit 230.
[0057] In step S102, the payment means information registration unit 111 of the information processing apparatus 100 requests the payment processing apparatus 500 to accept the input of the payment means information PY. Step S102 is composed of the following three-stage information processing. (1) The communication unit 130 of the information processing apparatus 100 receives a registration request for the payment means information PY from the user terminal 200. (2) The communication unit 130 of the information processing apparatus 100 transfers the registration request for the payment means information PY to the payment means information registration unit 111 via the communication bus 160. (3) The payment means information registration unit 111 of the information processing apparatus 100 transmits a request to accept the input of the payment means information PY to the payment processing apparatus 500 via the communication unit 130.
[0058] In step S103, the control unit 510 of the payment processing device 500 receives the input of payment means information PY from the user terminal 200. Step S103 is composed of the following three-stage information processing. (1) The communication unit 530 of the payment processing device 500 receives a request to receive the input of payment means information PY from the information processing device 100. (2) The communication unit 530 of the payment processing device 500 transfers the request to receive the input of payment means information PY to the control unit 510 via the communication bus 560. (3) The control unit 510 of the payment processing device 500 transmits a payment means information input screen (hereinafter referred to as "payment means information input screen W200") capable of inputting payment means information PY to the user terminal 200 via the communication unit 530.
[0059] In step S104, the control unit 210 of the user terminal 200 transmits the payment means information PY input by the user US to the payment processing device 500. Step S104 is composed of the following six-stage information processing. (1) The communication unit 230 of the user terminal 200 receives the payment means information input screen W200 from the payment processing device 500. (2) The communication unit 230 of the user terminal 200 transfers the payment means information input screen W200 to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 outputs the payment means information input screen W200 to the output unit 250. (4) The input unit 240 of the user terminal 200 receives the input of the payment means information PY. (5) The input unit 240 of the user terminal 200 transfers the input payment means information PY to the control unit 210 via the communication bus 260. (6) The control unit 210 of the user terminal 200 transmits the payment means information PY to the payment processing device 500 via the communication unit 230.
[0060] In step S105, the control unit 510 of the payment processing device 500 registers the payment means information PY. Step S105 is composed of the following three-stage information processing. (1) The communication unit 530 of the payment processing device 500 receives the payment means information PY from the user terminal 200. (2) The communication unit 530 of the payment processing device 500 transfers the payment means information PY to the control unit 510 via the communication bus 560. (3) The control unit 510 of the payment processing device 500 stores the payment means information PY in the storage unit 520.
[0061] In addition, as another embodiment, the payment means information registration unit 111 of the information processing apparatus 100 may be configured to transmit the payment means information input screen W200 to the user terminal 200 and transmit the payment means information PY input on the payment means information input screen W200 to the payment processing apparatus 500.
[0062] 3-2. Authentication Information Registration Process FIG. 9 is a flowchart showing an example of the authentication information registration process in the information processing system 1 according to the present embodiment (Steps S201 to S207).
[0063] In step S201, the control unit 210 of the user terminal 200 requests the store server 400 to register an authentication key for logging in to the store server 400. Step S201 is composed of the following three stages of information processing. (1) The input unit 240 of the user terminal 200 receives a request for registering an authentication key from the user US. (2) The input unit 240 of the user terminal 200 transfers the input request for registering the authentication key to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 transmits the request for registering the authentication key to the store server 400 via the communication unit 230.
[0064] In step S202, the control unit 410 of the store server 400 generates a store-side secret key SPSC and a store-side public key SPOP. Step S202 is composed of the following eight-stage information processing. (1) The control unit 410 of the store server 400 generates a code (hereinafter referred to as "code CD"), and transmits the generated code CD to the user terminal 200 via the communication unit 430. (2) The communication unit 230 of the user terminal 200 receives the code CD and transfers it to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 outputs the code CD to the output unit 250. (4) The input unit 240 of the user terminal 200 accepts the input or reading of the code CD. (5) The input unit 240 of the user terminal 200 transfers the input or read code CD to the control unit 210 via the communication bus 260. (6) The control unit 210 of the user terminal 200 transmits the code CD to the store server 400 via the communication bus 260. (7) The communication unit 430 of the store server 400 receives the code CD and transfers it to the control unit 410 via the communication bus 460. (8) When the code CD matches, the control unit 410 of the store server 400 generates a store-side secret key SPSC and a store-side public key SPOP, and stores the generated store-side secret key SPSC and store-side public key SPOP in the storage unit 420.
[0065] Here, the "code CD" includes any code that can be input or read by the user terminal 200 and can connect the user terminal 200 to the store terminal 300 or the store server 400. For example, it includes any digital sequence, character string, symbol string, or a combination thereof, a one-dimensional code, a two-dimensional code, or other codes. The one-dimensional code includes, for example, barcodes, specifically, JAN / EAN / UPC, ITF, CODE39, NW-7 (CODABAR), CODE128, or other barcodes. The two-dimensional code includes, for example, a stacked two-dimensional code or a matrix two-dimensional code, specifically, QR code (registered trademark), PDF417, Data Matrix, Maxi Code, Aztec Code, EAN / UCC composite, or other two-dimensional codes. From the perspective of achieving both convenience and security, it is preferable that the code CD has a one-time property that is updated every time a certain period of time elapses.
[0066] In step S203, the control unit 410 of the store server 400 transmits the store identifier SPID and the store-side public key SPOP to the information processing device 100. Step S203 is composed of the following three stages of information processing. (1) The control unit 410 of the store server 400 transmits the store identifier SPID and the store-side public key SPOP to the information processing device 100 via the communication unit 430. (2) The communication unit 130 of the information processing device 100 receives the store identifier SPID and the store-side public key SPOP and transfers them to the authentication information registration unit 112 via the communication bus 160. (3) The authentication information registration unit 112 of the information processing device 100 stores the store identifier SPID and the store-side public key SPOP in the storage unit 120.
[0067] In step S204, the authentication information registration unit 112 of the information processing device 100 transmits the store identifier SPID and the store-side public key SPOP to the user terminal 200. Step S204 is composed of the following three stages of information processing. (1) The authentication information registration unit 112 of the information processing device 100 transmits the store identifier SPID and the store-side public key SPOP to the user terminal 200 via the communication unit 130. (2) The communication unit 230 of the user terminal 200 receives the store identifier SPID and the store-side public key SPOP and transfers them to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 stores the store identifier SPID and the store-side public key SPOP in the storage unit 220.
[0068] In step S205, the control unit 210 of the user terminal 200 generates a user-side secret key USSC and a user-side public key USOP. Step S205 is composed of the following six-stage information processing. (1) The control unit 210 of the user terminal 200 generates a code CD and transmits the generated code CD to the store server 400 via the communication unit 230. (2) The communication unit 430 of the store server 400 receives the code CD and transfers it to the control unit 410 via the communication bus 460. (3) The control unit 410 of the store server 400 accepts the input of the code CD from the user terminal 200. (4) The control unit 410 of the store server 400 transmits the input code CD to the user terminal 200 via the communication unit 430. (5) The communication unit 230 of the user terminal 200 receives the code CD and transfers it to the control unit 210 via the communication bus 260. (6) When the code CD matches, the control unit 210 of the user terminal 200 generates a user-side secret key USSC and a user-side public key USOP, and stores the generated user-side secret key USSC and user-side public key USOP in the storage unit 220.
[0069] Note that in step S205, the user terminal 200 may be one or a plurality. For example, when there are two user terminals 200, it is composed of the following six-stage information processing. (1) The control unit 210 of the first user terminal 200 generates a code CD and transmits the generated code CD to the store server 400 via the communication unit 430. (2) The communication unit 430 of the store server 400 receives the code CD and transfers it to the control unit 410 via the communication bus 460. (3) The control unit 410 of the store server 400 accepts the input of the code CD from the second user terminal 200. (4) The control unit 410 of the store server 400 transmits the input code CD to the first user terminal 200 via the communication unit 430. (5) The communication unit 230 of the first user terminal 200 receives the code CD and transfers it to the control unit 210 via the communication bus 260. (6) When the code CD matches, the control unit 210 of the first user terminal 200 generates a user-side secret key USSC and a user-side public key USOP, and stores the generated user-side secret key USSC and user-side public key USOP in the storage unit 220.
[0070] In step S206, the control unit 210 of the user terminal 200 transmits the user identifier USID and the user-side public key USOP to the information processing apparatus 100. Step S206 is composed of the following three stages of information processing. (1) The control unit 210 of the user terminal 200 transmits the user identifier USID and the user-side public key USOP to the information processing apparatus 100 via the communication unit 230. (2) The communication unit 130 of the information processing apparatus 100 receives the user identifier USID and the user-side public key USOP and transfers them to the authentication information registration unit 112 via the communication bus 160. (3) The authentication information registration unit 112 of the information processing apparatus 100 stores the user identifier USID and the user-side public key USOP in the storage unit 120.
[0071] In step S207, the authentication information registration unit 112 of the information processing apparatus 100 transmits the user identifier USID and the user-side public key USOP to the store server 400 via the communication unit 130. Step S207 is composed of the following three stages of information processing. (1) The authentication information registration unit 112 of the information processing apparatus 100 transmits the user identifier USID and the user-side public key USOP to the store server 400 via the communication unit 130. (2) The communication unit 430 of the store server 400 receives the user identifier USID and the user-side public key USOP and transfers them to the control unit 410 via the communication bus 460. (3) The control unit 410 of the store server 400 stores the user identifier USID and the user-side public key USOP in the storage unit 420.
[0072] 3-3. Physical Store Settlement Processing FIG. 10 is a flowchart showing an example of the physical store settlement processing in the information processing system 1 according to the present embodiment (steps S301 to S318).
[0073] In step S301, the control unit 310 of the store terminal 300 transmits the payment information GS of the user US input by the staff or employee of the store SP or the like to the store server 400 on the payment information input screen (hereinafter referred to as "payment information input screen W300"). Step S301 is composed of the following three stages of information processing. (1) The input unit 340 of the store terminal 300 receives the input of the payment information GS. (2) The input unit 340 of the store terminal 300 transfers the input payment information GS to the control unit 310 via the communication bus 360. (3) The control unit 310 of the store terminal 300 transmits the payment information GS to the store server 400 via the communication unit 330.
[0074] In step S302, the control unit 410 of the store server 400 acquires the payment information GS from the store terminal 300 and transmits the acquired payment information GS to the information processing device 100. Step S302 is composed of the following three stages of information processing. (1) The communication unit 430 of the store server 400 receives the payment information GS from the store terminal 300 and transfers it to the control unit 410 via the communication bus 460. (2) The control unit 410 of the store server 400 stores the payment information GS in the storage unit 420. (3) The control unit 410 of the store server 400 transmits the payment information GS to the information processing device 100 via the communication unit 430.
[0075] In step S303, the authentication unit 114 of the information processing device 100 generates a code CD for connecting the user terminal 200 to the store terminal 300 or the store server 400, and transmits the generated code CD to the store server 400.
[0076] In step S304, the control unit 410 of the store server 400 transmits the code CD to the store terminal 300. Step S304 is composed of the following three stages of information processing. (1) The communication unit 430 of the store server 400 receives the code CD from the information processing device 100 and transfers it to the control unit 410 via the communication bus 460. (2) The control unit 410 of the store server 400 stores the code CD in the storage unit 420. (3) The control unit 410 of the store server 400 transmits the code CD to the store terminal 300 via the communication unit 430.
[0077] In step S305, the control unit 310 of the store terminal 300 causes the output unit 350 to display a code output screen including the code CD (hereinafter referred to as "code output screen W400"). Step S305 is composed of the following three stages of information processing. (1) The communication unit 330 of the store terminal 300 receives the code output screen W400 including the code CD from the store server 400. (2) The communication unit 330 of the store terminal 300 transfers the code output screen W400 including the code CD to the control unit 310 via the communication bus 360. (3) The control unit 310 of the store terminal 300 causes the output unit 350 to display the code output screen W400 including the code CD.
[0078] In step S306, the input unit 210 of the user terminal 200 accepts the input or reading of the code CD by the user US. Step S306 is composed of the following four stages of information processing. (1) The control unit 210 of the user terminal 200 outputs a code input screen (hereinafter referred to as "code input screen W500") capable of inputting the code CD or a code reading screen (hereinafter referred to as "code reading screen W600") capable of reading the code CD to the user terminal 200. (2) The input unit 240 of the user terminal 200 accepts the input or reading of the code CD. (3) The input unit 240 of the user terminal 200 transfers the input or read code CD to the control unit 210 via the communication bus 260. (4) The control unit 210 of the user terminal 200 transmits the code CD and the user identifier USID to the store server 400 via the communication unit 230. (5) The control unit 410 of the store server 400 transmits the store identifier SPID to the user terminal 200 via the communication unit 430.
[0079] In step S307, when the code CD received from the user terminal 200 matches, the control unit 410 of the store server 400 executes an authentication process using the user-side public key USOP corresponding to the user identifier USID. Step S307 consists of the following nine stages of information processing. (1) The communication unit 430 of the store server 400 receives the code CD and the user identifier USID from the user terminal 200 and transfers them to the control unit 410 via the communication bus 460. (2) When the code CD matches, the control unit 410 of the store server 400 encrypts the plaintext (hereinafter referred to as "plaintext CL") using the user-side public key USOP corresponding to the user identifier USID stored in the storage unit 420 to obtain a ciphertext (hereinafter referred to as "ciphertext CR"). Note that the plaintext CL may include, for example, a random number. (3) The control unit 410 of the store server 400 transmits the obtained ciphertext CR to the user terminal 200 via the communication unit 430. (4) The communication unit 230 of the user terminal 200 receives the ciphertext CR from the store server 400 and transfers it to the control unit 210 via the communication bus 260. (5) The control unit 210 of the user terminal 200 decrypts the ciphertext CR using the user-side secret key USSC stored in the storage unit 220 to obtain the plaintext CL. (6) The control unit 210 of the user terminal 200 converts the obtained plaintext CL into a converted text (hereinafter referred to as "converted text CO") using a predetermined hash function (hereinafter referred to as "hash function SH"). (7) The control unit 210 of the user terminal 200 transmits the converted converted text CO to the store server 400 via the communication unit 230. (8) The communication unit 430 of the store server 400 receives the converted text CO from the user terminal 200 and transfers it to the control unit 410 via the communication bus 460. (9) The control unit 410 of the store server 400 converts the plaintext CL into an answer text (hereinafter referred to as "answer text AS") using the hash function SH and determines whether the answer text AS matches the converted text CO.
[0080] In step S308, the control unit 410 of the store server 400 transmits the authentication result to the information processing device 100. When the answer text AS matches the converted text CO, the authentication result is successful. On the other hand, when the answer text AS does not match the converted text CO, the authentication result is a failure.
[0081] In step S309, the control unit 210 of the user terminal 200 executes an authentication process using the store - side public key SPOP corresponding to the store identifier SPID. Step S309 is composed of the following nine - stage information processing. (1) The communication unit 230 of the user terminal 200 receives the store identifier SPID from the store server 400 and transfers it to the control unit 210 via the communication bus 260. (2) The control unit 210 of the user terminal 200 encrypts the plaintext CL using the store - side public key SPOP corresponding to the store identifier SPID stored in the storage unit 220 to obtain the ciphertext CR. (3) The control unit 210 of the user terminal 200 transmits the obtained ciphertext CR to the store server 400 via the communication unit 230. (4) The communication unit 430 of the store server 400 receives the ciphertext CR from the user terminal 200 and transfers it to the control unit 410 via the communication bus 460. (5) The control unit 410 of the store server 400 decrypts the ciphertext CR using the store - side secret key SPSC stored in the storage unit 420 to obtain the plaintext CL. (6) The control unit 410 of the store server 400 converts the obtained plaintext CL into a converted text CO using the hash function SH. (7) The control unit 410 of the store server 400 transmits the converted converted text CO to the user terminal 200 via the communication unit 430. (8) The communication unit 230 of the user terminal 200 receives the converted text CO from the store server 400 and transfers it to the control unit 210 via the communication bus 260. (9) The control unit 210 of the user terminal 200 converts the plaintext CL into an answer text AS using the hash function SH and determines whether the answer text AS and the converted text CO match.
[0082] In step S310, the control unit 210 of the user terminal 200 transmits the authentication result to the information processing device 100. When the answer text AS and the converted text CO match, the authentication result is successful. On the other hand, when the answer text AS and the converted text CO do not match, the authentication result is a failure.
[0083] In step S311, when the authentication results of the user terminal 200 and the store server 400 are successful, the transmission unit 115 of the information processing apparatus 100 transmits the user identifier USID, the store identifier SPID, and the payment information GS to the payment processing apparatus 500. Step S311 is composed of the following four-stage information processing. (1) The communication unit 130 of the information processing apparatus 100 receives the authentication results from the user terminal 200 and the store server 400, and transfers them to the transmission unit 115 via the communication bus 160. (2) When the authentication results of the user terminal 200 and the store server 400 are successful, the transmission unit 115 transmits the user identifier USID, the store identifier SPID, and the payment information GS to the payment processing apparatus 500. (3) The communication unit 530 of the payment processing apparatus 500 receives the user identifier USID, the store identifier SPID, and the payment information GS from the information processing apparatus 100, and transfers them to the control unit 510 via the communication bus 560. (4) The control unit 510 of the payment processing apparatus 500 stores the user identifier USID, the store identifier SPID, and the payment information GS in the storage unit 520.
[0084] In step S312, the payment approval acquisition unit 116 of the information processing apparatus 100 requests the user terminal 200 for a payment approval AG for the payment information GS. Step S312 is composed of the following four-stage information processing. (1) The payment approval acquisition unit 116 of the information processing apparatus 100 transmits a payment approval screen (hereinafter referred to as "payment approval screen W700") including the payment information GS to the user terminal 200 via the communication unit 130. (2) The communication unit 230 of the user terminal 200 receives the payment approval screen W700 from the information processing apparatus 100, and transfers it to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 displays the payment approval screen W700 on the output unit 250. (4) The input unit 240 of the user terminal 200 accepts the input of the payment approval AG by the user US.
[0085] In step S313, the control unit 210 of the user terminal 200 transmits the payment approval AG input by the user US to the information processing apparatus 100. Step S313 is composed of the following three-stage information processing. (1) The input unit 240 of the user terminal 200 transfers the payment approval AG input on the payment approval screen W700 to the control unit 210 via the communication bus 260. (2) The control unit 210 of the user terminal 200 transmits the payment approval AG to the information processing apparatus 100 via the communication unit 230. (3) The communication unit 130 of the information processing apparatus 100 receives the payment approval AG from the user terminal 200 and transfers it to the payment approval acquisition unit 116 via the communication bus 160.
[0086] In step S314, the personal authentication request unit 117 of the information processing apparatus 100 requests the user terminal 200 for personal authentication CF via the communication unit 130.
[0087] In step S315, the control unit 210 of the user terminal 200 executes personal authentication and transmits the authentication result to the information processing apparatus 100. Step S315 is composed of the following six-stage information processing. (1) The communication unit 230 of the user terminal 200 receives the personal authentication CF request from the information processing apparatus 100 and transfers it to the control unit 210 via the communication bus 260. (2) The control unit 210 of the user terminal 200 executes personal authentication. (3) The input unit 240 of the user terminal 200 accepts the input or reading of personal information. (4) The input unit 240 of the user terminal 200 transfers the input or read personal information to the control unit 210 via the communication bus 260. (5) The control unit 210 of the user terminal 200 determines whether the personal authentication is successful based on the personal information. (6) The control unit 210 of the user terminal 200 transmits the authentication result of the personal authentication CF to the information processing apparatus 100 via the communication unit 230.
[0088] In step S316, the transmission unit 115 of the information processing apparatus 100 transmits the payment approval AG to the payment processing apparatus 500 when the payment approval acquisition unit 116 acquires the payment approval AG and the personal authentication CF is successful.
[0089] In step S317, the control unit 510 of the payment processing device 500 executes payment processing. Step S317 is composed of the following two-stage information processing. (1) The communication unit 530 of the payment processing device 500 receives the payment approval AG from the information processing device 100 and transfers it to the control unit 510 via the communication bus 560. (2) The control unit 510 of the payment processing device 500 executes payment processing based on the user identifier USID, store identifier SPID, payment information GS, and payment means information PY stored in the storage unit 520.
[0090] In step S318, when the payment processing is completed, the control unit 510 of the payment processing device 500 outputs a payment completion screen (hereinafter referred to as "payment completion screen W800") indicating that the payment processing is completed to the user terminal 200 and the store terminal 300. Step S318 is composed of the following three-stage information processing. (1) The control unit 510 of the payment processing device 500 transmits the payment completion screen W800 to the user terminal 200 and the store terminal 300 via the communication unit 530. (2) The communication unit 230 of the user terminal 200 and the communication unit 330 of the store terminal 300 receive the payment completion screen W800 and transfer it to the control unit 210 and the control unit 310 via the communication bus 260 and the communication bus 360. (3) The control unit 210 and the control unit 310 display the payment completion screen W800 on the output unit 250 and the output unit 350.
[0091] 3-4. Virtual store payment processing FIG. 11 is a flowchart showing an example of virtual store payment processing in the information processing system 1 according to the present embodiment (steps S401 to S418).
[0092] In step S401, the control unit 210 of the user terminal 200 transmits the payment information GS input by the user US on the EC site of the store SP to the store server 400. Step S401 is composed of the following three-stage information processing. (1) The input unit 240 of the user terminal 200 receives the input of the payment information GS. (2) The input unit 240 of the user terminal 200 transfers the input payment information GS to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 transmits the payment information GS to the store server 400 via the communication unit 230.
[0093] In step S402, the control unit 410 of the store server 400 acquires the payment information GS from the user terminal 200 and transmits the acquired payment information GS to the information processing device 100. Step S402 is composed of the following three-stage information processing. (1) The communication unit 430 of the store server 400 receives the payment information GS from the user terminal 200 and transfers it to the control unit 410 via the communication bus 460. (2) The control unit 410 of the store server 400 stores the payment information GS in the storage unit 420. (3) The control unit 410 of the store server 400 transmits the payment information GS to the information processing device 100 via the communication unit 430.
[0094] In step S403, the authentication unit 114 of the information processing device 100 generates a code CD for connecting the user terminal 200 and the store server 400, and transmits the generated code CD to the store server 400.
[0095] In step S404, the control unit 410 of the store server 400 transmits the code CD to the user terminal 200. Step S404 is composed of the following three-stage information processing. (1) The communication unit 430 of the store server 400 receives the code CD from the information processing device 100 and transfers it to the control unit 410 via the communication bus 460. (2) The control unit 410 of the store server 400 stores the code CD in the storage unit 420. (3) The control unit 410 of the store server 400 transmits the code CD to the user terminal 200 via the communication unit 430.
[0096] In step S405, the control unit 210 of the user terminal 200 displays the code CD on the output unit 250. Step S405 is composed of the following three stages of information processing. (1) The communication unit 230 of the user terminal 200 receives the code CD from the store server 400. (2) The communication unit 230 of the user terminal 200 transfers the code CD to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 displays the code CD on the output unit 250.
[0097] In step S406, the input unit 210 of the user terminal 200 accepts the input of the code CD by the user US. Step S406 is composed of the following four stages of information processing. (1) The input unit 240 of the user terminal 200 accepts the input of the code CD. (2) The input unit 240 of the user terminal 200 transfers the input code CD to the control unit 210 via the communication bus 260. (3) The control unit 210 of the user terminal 200 transmits the code CD and the user identifier USID to the store server 400 via the communication unit 230. (4) The control unit 410 of the store server 400 transmits the store identifier SPID to the user terminal 200 via the communication unit 430.
[0098] Steps S407 to S417 are omitted because they are substantially the same as the explanations of steps S307 to S317.
[0099] In step S418, when the settlement process is completed, the control unit 510 of the settlement processing device 500 outputs a settlement completion screen W800 indicating that the settlement process is completed to the user terminal 200. Step S418 is composed of the following three stages of information processing. (1) The control unit 510 of the settlement processing device 500 transmits the settlement completion screen W800 to the user terminal 200 via the communication unit 530. (2) The communication unit 230 of the user terminal 200 receives the settlement completion screen W800 and transfers it to the control unit 210 via the communication bus 260. (3) The control unit 210 displays the settlement completion screen W400 on the output unit 250.
[0100] 4. Screen display example In Section 4, display examples of the menu screen W100, payment means information input screen W200, payment information input screen W300, code output screen W400, code input screen W500, code reading screen W600, payment approval screen W700, and payment completion screen W800 will be described.
[0101] (Menu screen W100) FIG. 12 is a diagram showing an example of the menu screen W100 in which the user terminal 200 requests registration of the payment means information PY. As shown in FIG. 12, the menu screen W100 has a payment means information registration request button W101 for requesting registration of the payment means information PY. When the payment means information registration request button W101 is operated by the user US, the menu screen W100 transitions to the payment means information input screen W200.
[0102] (Payment means information input screen W200) FIG. 13 is a diagram showing an example of the payment means information input screen W200 in which the payment processing device 500 accepts input of the payment means information PY. As shown in FIG. 13, the payment means information input screen W200 has a payment means information input area W201 for inputting the payment means information PY, and a payment means information registration button W202 for registering the payment means information PY input in the payment means information input area W201. From the viewpoint of achieving both convenience and security, the payment means information input screen W200 preferably conforms to the PCI DSS (Payment Card Industry Data Security Standard).
[0103] (Payment information input screen W300) FIG. 14 is a diagram showing an example of a payment information input screen W300 on which the store terminal 300 receives the input of payment information GS. As shown in FIG. 14, the payment information input screen W300 includes an amount input area W301 for inputting the purchase amount of the user US in the store SP, a numeric keypad W302 for inputting an amount into the amount input area W301, and a confirmation button W303 for confirming the amount input into the amount input area W301. When the confirmation button W303 is operated by a staff member or an employee of the store SP or the like, the control unit 310 of the store terminal 300 transmits the payment information GS including the amount to the information processing apparatus 100.
[0104] (Code Output Screen W400) FIG. 15 is a diagram showing an example of a code output screen W400 on which the store terminal 300 outputs a code CD. As shown in FIG. 15, the code output screen W400 includes an amount display area W401 for displaying the purchase amount of the user US in the store SP, and code display areas W402 and W403 for displaying the code CD. The code output screen W400 is presented to the user US by a staff member or an employee of the store SP or the like.
[0105] (Code Input Screen W500) FIG. 16 is a diagram showing an example of a code input screen W500 on which the user terminal 200 inputs a code CD. As shown in FIG. 16, the code input screen W500 includes a code input area W501 for inputting the code CD output on the code output screen W400 of the store terminal 300, an elapsed time display area W502 for displaying the elapsed time for inputting the code CD, and a numeric keypad W503 for inputting the code CD into the code input area W501. When the code CD displayed on the store terminal 300 is correctly input, communication is established among the user terminal 200, the store terminal 300, and the store server 400.
[0106] (Code Reading Screen W600) FIG. 17 is a diagram showing an example of a code reading screen W600 on which the user terminal 200 reads the code CD. As shown in FIG. 17, the code reading screen W600 has a code reading frame W601. For example, the control unit 210 of the user terminal 200 activates a reader mounted on the user terminal 200 and outputs the code reading screen W600 to the output unit 250, and when the code reading frame W601 matches the code CD to be read, the code CD may be read. When the user terminal 200 reads the code CD displayed on the store terminal 300, communication is established among the user terminal 200, the store terminal 300, and the store server 400.
[0107] (Payment approval screen W700) FIG. 18 is a diagram showing an example of a payment approval screen W700 on which the user terminal 200 inputs a payment approval AG. As shown in FIG. 18, the payment approval screen W700 has a payment information display area W701 for displaying payment information GS and a payment approval button W702 for inputting the payment approval AG. When the payment approval button W702 is operated by the user US, the payment approval AG is transmitted to the information processing apparatus 100.
[0108] (Payment completion screen W800) FIG. 19 is a diagram showing an example of a payment completion screen W800 indicating that the payment process has been completed. As shown in FIG. 19, the payment completion screen W800 has a payment completion display area W801 for displaying that the payment process has been completed and a transaction information display area W802 for displaying transaction information including the payment information GS. When the payment completion screen W800 is displayed on the user terminal 200 and the store terminal 300, the payment is completed.
[0109] 5. Operational effects In Section 5, the operational effects of the present embodiment will be described.
[0110] The information processing system 1 according to this embodiment includes a payment means information registration unit 111 that registers payment means information PY used by the user US for payment with the payment processing device 500, a payment information acquisition unit 113 that acquires payment information GS including at least the amount purchased by the user US at the store SP from the store terminal 300 or the store server 400 managed by the store SP, an authentication unit 114 that authenticates the store terminal 300 or the store server 400 and the user terminal 200 used by the user US by a public key authentication method, and when the authentication by the authentication unit 114 is successful, a transmission unit 115 that transmits a user identifier USID for identifying the user US, a store identifier SPID for identifying the store SP, and the payment information GS acquired by the payment information acquisition unit 113 to the payment processing device 500. The payment processing device 500 executes payment processing based on the user identifier USID, the store identifier SPID, the payment information GS, and the payment means information PY registered by the payment means information registration unit 111. Thereby, when the authentication by the public key authentication method between the store terminal 300 or the store server 400 and the user terminal 200 is successful without the user US having to input a password, the payment information GS is transmitted to the payment processing device 500 and the payment processing is executed, so that both the security and convenience in payment can be achieved.
[0111] In the information processing system 1 according to this embodiment, the authentication unit 114 authenticates the store terminal 300 or the store server 400 and the user terminal 200 used by the user US by a two-way public key authentication method. Thereby, when the authenticity of both the user US and the store SP is proven without the user US having to input a password, the payment information GS is transmitted to the payment processing device 500 and the payment processing is executed, so that both the security and convenience in payment can be achieved.
[0112] In the information processing system 1 according to this embodiment, the store terminal 300 and the store server 400 do not acquire the payment means information PY. Thereby, the user terminal 200 can perform payment processing without transmitting the payment means information PY to the store terminal 300 and the store server 400, so that the security can be further improved without impairing the convenience in payment.
[0113] The information processing system 1 according to this embodiment further includes a payment approval acquisition unit 116 that acquires a payment approval AG for payment information GS from the user terminal 200. When the payment approval acquisition unit 116 acquires the payment approval AG, the payment processing device 500 executes payment processing based on the user identifier USID, the store identifier SPID, the payment information GS, and the payment means information PY registered by the payment means information registration unit 111. Thereby, since payment processing is executed when the payment approval AG for the payment information GS is acquired from the user terminal 200, the security in payment can be further improved.
[0114] The information processing system 1 according to this embodiment further includes an identity authentication request unit 117 that requests the user terminal 200 for identity authentication CF. When the payment approval acquisition unit 116 acquires the payment approval AG and the identity authentication CF is successful, the payment processing device 500 executes payment processing based on the user identifier USID, the store identifier SPID, the payment information GS, and the payment means information PY registered by the payment means information registration unit 111. Thereby, in addition to the case where the payment approval AG for the payment information GS is acquired from the user terminal 200, since payment processing is executed when the identity authentication CF is successful, the security in payment can be further improved.
[0115] In the information processing system 1 according to this embodiment, the identity authentication CF includes knowledge authentication, possession authentication, biometric authentication, or multi-factor authentication combining these. Thereby, since the identity authentication CF includes knowledge authentication, possession authentication, biometric authentication, or multi-factor authentication combining these, the security in payment can be further improved.
[0116] 6. Others As described above, the embodiments of the present invention have been described. However, the present invention is not limited to this, and can be appropriately changed without departing from the technical idea of the invention.
[0117] The aspect of the embodiment of the present invention may be a program. This program causes a computer to function as each part of the information processing system 1.
[0118] Aspects of embodiments of the present invention may be an information processing method executed by the information processing system 1. This information processing method includes each process executed by each part of the information processing system 1.
[0119] As a modification, each control unit performs a write process (storage process) and a read process on the storage unit for various data and various information, but is not limited thereto. For example, the information processing of each flow may be executed using a register, a cache memory, etc. within the control unit.
Explanation of Reference Numerals
[0120] 1 Information processing system 100 Information processing device 110 Control unit 111 Settlement means information registration unit 112 Authentication information registration unit 113 Settlement information acquisition unit 114 Authentication unit 115 Transmission unit 116 Settlement approval acquisition unit 117 Personal authentication request unit 120 Storage unit 130 Communication unit 160 Communication bus 200 User terminal 210 Control unit 220 Storage unit 230 Communication unit 240 Input unit 250 Output unit 260 Communication bus 300 Store terminal 310 Control unit 320 Storage unit 330 Communication unit 340 Input unit 350 Output unit 360 Communication bus 400 Store server 410 Control unit 420 Storage unit 430 Communication unit 460 Communication bus 500 Settlement processing device 510 Control unit 520 Storage unit 530 Communication unit 560 Communication bus
Claims
1. An information processing device, A store server managed by the store; A user terminal used by a user; A payment processing device that executes a payment process; Equipped with the store server includes a communication unit that receives from the information processing device a code generated by the information processing device, receives from the user terminal a code input or read by the user terminal and a user identifier that identifies the user, and transmits a store identifier that identifies the store to the user terminal; and a control unit that, when the code received from the information processing device and the code received from the user terminal match, authenticates the user terminal using a user-side public key that corresponds to the user identifier and is registered in the store server; the user terminal includes a communication unit that transmits the code and the user identifier to the store server and receives the store identifier from the store server, and a control unit that authenticates the store server using a store-side public key that corresponds to the store identifier and is registered in the user terminal; the information processing device comprises: a payment method information registration unit that registers, in the payment processing device, payment method information used by the user for payment; a payment information acquisition unit that acquires from the store server payment information including at least an amount of purchases made by the user at the store; an authentication unit that generates a code for connecting the user terminal and the store server and transmits the generated code to the store server; and a transmission unit that transmits, when authentication of the user terminal using the user side public key and authentication of the store server using the store side public key are successful, the user identifier, the store identifier, and the payment information acquired by the payment information acquisition unit to the payment processing device; the payment processing device executes a payment process based on the user identifier, the store identifier, the payment information, and the payment method information registered by the payment method information registration unit; Information processing system.
2. The store server does not acquire the payment method information. The information processing system according to claim 1 .
3. The information processing device further includes a payment approval acquisition unit that acquires payment approval for the payment information from the user terminal, when the payment approval acquisition unit acquires payment approval, the payment processing device executes payment processing based on the user identifier, the store identifier, the payment information, and the payment method information registered by the payment method information registration unit. The information processing system according to claim 1 .
4. The information processing device further includes an authentication request unit that requests authentication of the user terminal, When the payment approval acquisition unit acquires payment approval and the identity authentication is successful, the payment processing device executes payment processing based on the user identifier, the store identifier, the payment information, and the payment method information registered by the payment method information registration unit. The information processing system according to claim 3 .
5. The identity authentication includes knowledge authentication, possession authentication, biometric authentication, or a combination of these multiple factor authentication.
5. The information processing system according to claim 4.
6. A program comprising: A program for causing a computer to function as each unit of the information processing system according to any one of claims 1 to 5.
7. An information processing method executed by an information processing system, comprising: The information processing system according to claim 1 , further comprising: Information processing methods.
Citation Information
Patent Citations
Processing system, server, processing terminal, communication terminal, processing method, data managing method, processing performing method and program
JP2001344545A
Cardless debit settlement system, method, and control program thereof
JP2007249349A
Method for non-repudiation, and payment managing server and user terminal therefor
JP2016096547A
Authentication device, authentication system, authentication method, and program
JP2021082359A
Authentication and payment methods
JP4218297B2