Application program, information processing system, information processing method, and information processing apparatus

By employing a dual authentication process involving a writing password and a one-time code, the system enhances security in online banking transactions, ensuring the legitimacy of user credentials.

JP7708952B1Active Publication Date: 2025-07-15PAYPAY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024154887
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2025-07-15
Estimated Expiration
2044-09-09

AI Technical Summary

Technical Problem

Existing authentication systems in online banking, such as those described in Patent Document 1, may not provide sufficient security measures.

Method used

Implement a system where a computer acquires a first writing password associated with user identification information from a server device and performs a first authentication process using a communication unit in a credit card to determine if the password matches a set password, followed by a second authentication process using a one-time code, to enhance security.

Benefits of technology

The proposed system significantly improves security by verifying the authenticity of user credentials through multiple authentication processes, reducing the risk of fraudulent transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007708952000001_ABST
    Figure 0007708952000001_ABST
Patent Text Reader

Abstract

To improve security. 【Solution means】Have a computer acquire a first writing password associated with the identification information of a user from a server device, and when a card used by the user approaches a terminal device equipped with the computer, use the communication unit of the terminal device to wirelessly communicate with a circuit unit including a communication unit included in the card and a storage unit capable of writing information using a setting password set when writing information, execute a first authentication process for determining whether the first writing password of the user is the setting password, and when a positive determination result is obtained, an application program that determines that the first authentication process has succeeded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an application program, an information processing system, a server device, an information processing method, and an information processing device.

Background Art

[0002] An authentication system is disclosed that issues a one-time password request from a screen after login and allows the notification destination of the issued one-time password to be specified by selecting from among three options: mobile email, mobile phone (voice), and fixed phone, and performs authentication in online banking (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the above technology, the security may not be sufficient.

[0005] The present invention has been made in consideration of such circumstances, and one of the objects is to provide an application program, an information processing system, a server device, an information processing method, and an information processing device that can improve security more.

Means for Solving the Problems

[0006] One aspect of the present invention causes a computer to acquire a first writing password associated with the identification information of a user from a server device, and when a card used by the user approaches a terminal device equipped with the computer, uses a communication unit included in the card and a storage unit including a setting password set when writing information, via the communication unit of the terminal device, to perform wireless communication with a circuit unit, and executes a first authentication process for determining whether the first writing password of the user is the setting password, and when a positive determination result is obtained, it is an application program that determines that the first authentication process has succeeded.

Effect of the Invention

[0007] According to one aspect of the present invention, it is possible to provide an application program, an information processing system, a server device, an information processing method, and an information processing device that can further improve security.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Embodiments for Carrying Out the Invention

[0009] Hereinafter, with reference to the drawings, embodiments of the application program, information processing system, server device, information processing method, and information processing device of the present invention will be described. Various devices such as "servers" that appear below for providing services to users or performing internal analysis may be realized by a decentralized group of devices, and the operators of each device may be different. Also, the holder of the device hardware (provider of the cloud server) and the operator who actually operates the device may be different. The application program and the payment server cooperate to provide an electronic payment service. In the following description, the application program is referred to as a payment app. The electronic payment service is a service that supports payments related to the purchase of goods and services in stores. A store is, for example, a physical store (actual store) existing in the real space, but may also include a virtual store for e-commerce. The virtual store may include those provided by a party different from the operator of the electronic payment service. In that case, when making a purchase payment in the virtual store, it may be controlled to transition to the interface screen of the electronic payment service. In the electronic payment service, a store is, for example, treated as belonging to a franchise (brand), and processing such as payment when a purchase action is performed in the store is mainly carried out between the user and the franchise. Alternatively, processing such as payment may be carried out between the user and the store.

[0010] [Electronic Payment Service] FIG. 1 is a diagram showing an example of the configuration of an electronic payment system in which an electronic payment service is realized. The electronic payment service is realized centering around the payment server 100. The electronic payment system that realizes the electronic payment service includes, for example, one or more credit cards C, one or more user terminal devices 10, one or more first store terminal devices 50, one or more second store terminal devices 70, and a payment server 100. These devices communicate with each other via, for example, a network NW. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, and the like. Some or all of the functional configurations included in the electronic payment system may be distributed among a plurality of devices in an arbitrary form or integrated into an arbitrary device.

[0011] [User terminal device] The user terminal device 10 is a portable terminal device such as a smartphone or a tablet terminal. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input reception function, and a program execution function. In the following description, the configurations for realizing these functions are respectively referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), etc. In the user terminal device 10, when the settlement application 20 is executed by a processor such as a CPU, it operates to provide an electronic settlement service to the user in cooperation with the settlement server 100. The settlement application 20 is installed in the user terminal device 10 from, for example, an application store, and controls a camera, a communication device, a touch panel, etc.

[0012] [First store terminal device] The first store terminal device 50 is installed in a store, for example. The first store terminal device 50 is a computer device having at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The first store terminal device 50 includes a so-called POS (Point of Sale) device, and the product price acquisition function and the optical reading function may be realized by the POS device. The store code image 60 is placed in the store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. Note that the store code image 60 may be displayed by a display placed in the store (which may be a display of a terminal device such as a smartphone).

[0013] [Second store terminal device] The second store terminal device 70 is used by the operator of the franchise store. The second store terminal device 70 is a smartphone, a tablet terminal, a personal computer, or the like. In the second store terminal device 70, an interface 72 for franchise stores operates. The interface 72 for franchise stores may be an application for franchise stores or a browser. The interface 72 for franchise stores accepts settings of coupons and the like by the operator of the franchise store and transmits them to the payment server 100. The second store terminal device 70, which is a smartphone, has functions such as displaying a code image corresponding to the store code image or reading the code image displayed by the user terminal device 10 by executing an application for franchise stores.

[0014] [Payment Server] The payment server 100 realizes electronic payment based on the payment information received from the user terminal device 10 or the first store terminal device 50. The first store terminal device 50 may include a POS device and a franchise server. In that case, the payment information is transmitted from the POS device to the payment server 100 via the franchise server. In the following description, this will not be particularly distinguished, and it is assumed that the payment information is transmitted from the first store terminal device 50.

[0015] Figures 2 and 3 are sequence diagrams illustrating a general flow of electronic payment. There may be two patterns, Pattern 1 and Pattern 2, in electronic payment.

[0016] In the case of pattern 1 shown in FIG. 2 (hereinafter referred to as user scan), the user terminal device 10 in the state where the payment application 20 is activated decodes the store code image 60 by the optical reading function (S1). The store code image 60 includes information on the store URL (Uniform Resource Locator). This store URL is obtained by adding information that can identify the store to the domain of the electronic payment service, and is associated with the franchise store ID, store ID, etc. in the payment server 100 (described later). The payment application 20 transmits the first payment information including the store URL and the account ID to the payment server 100 (S2). The payment server 100 searches for store information (described later) from the franchise store ID and store ID corresponding to the store URL, acquires the information on the franchise store name and store name (S3), and transmits it to the payment application 20 (S4). The user inputs the payment amount into the user terminal device 10 on the screen where the franchise store name and store name are displayed (S5). Then, the user terminal device 10 generates the second payment information including at least the payment amount and transmits it to the payment server 100 (S6). The payment server 100 performs an electronic payment based on the received second payment information (S7). Then, the payment server 100 transmits a payment completion notification (information for displaying a payment completion screen) to the payment application 20 (S8), and the payment application 20 displays the payment completion screen (S9). When the store code image 60 is displayed by a display placed in the store, the store code image 60 may include not only the store URL but also payment amount information. In this case, the procedure for the user to input the payment amount is omitted, and the payment amount information is included in the first payment information and transmitted to the payment server 100. The information on the franchise store name and store name may be included and displayed on the payment completion screen.

[0017] In the case of Pattern 2 shown in FIG. 3 (hereinafter referred to as store scan), when the payment application 20 is launched, when a payment operation is performed in the payment application 20, when the automatic update timing (for example, every minute) is reached, and at other timings, the payment application 20 sends a one-time code issuance request to the payment server 100 (S11). The payment server 100 generates a one-time code (S12) and sends it to the payment application 20 (S13). The payment application 20 displays a code image such as a QR code or a barcode generated based on the one-time code (S14). The user shields (presents) the display surface of the user terminal device 10 against the first store terminal device 50, and the first store terminal device 50 decodes the code image by means of an optical reading function and acquires a one-time code or the like (S15). Then, the first store terminal device 50 generates payment information including a one-time code, a payment amount, a franchise ID, a store ID, etc., and sends it to the payment server 100 (S16). The information on the payment amount has been acquired in advance by barcode reading, manual input, or the like. The payment server 100 identifies the user corresponding to the one-time code based on the received information and performs an electronic payment (S17). Then, the payment server 100 sends a payment completion notification to the payment application 20 (S18), and the payment application 20 displays a payment completion screen (S19).

[0018] Note that the electronic payment may be performed in only one of the above patterns. Also, the "account ID" described in FIG. 2 may be other information (for example, a telephone number) that can be used as identification information of the user. Further, in the store scan, the issuance of the one-time code may be omitted, and the payment application 20 may display a code image generated based on the user's account ID. In that case, instead of identifying the user corresponding to the one-time code, the payment server 100 identifies the user corresponding to the account ID.

[0019] [Functional Configuration of Payment Server] FIG. 4 is a configuration diagram of the settlement server 100. The settlement server 100 includes, for example, a communication unit 110, a content providing unit 120, a settlement processing unit 130, an information management unit 140, an authentication processing unit 150, and a storage unit 170. Components other than the communication unit 110 and the storage unit 170 are realized, for example, by a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including a circuit unit; circuitry) such as LSI (Large Scale Integration), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), GPU (Graphics Processing Unit), and SOC (System On Chip), or may be realized by the cooperation of software and hardware. The program may be stored in advance in a storage device (a storage device having a non-transitory storage medium) such as an HDD (Hard Disk Drive) or a flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or a CD-ROM, and may be installed in the storage device when the storage medium is mounted on a drive device.

[0020] The storage unit 170 is an HDD, a flash memory, a RAM (Random Access Memory), or the like. The storage unit 170 may be a NAS (Network Attached Storage) device accessible by the settlement server 100 via a network. Information such as user information 172 including authentication information 173, content information 174, franchise / store information 176, and authentication result information 178 (described later) is stored in the storage unit 170. Some of this information may be stored in the storage unit of the user terminal device 10. Details of each piece of information will be described later.

[0021] The communication unit 110 is a communication interface for connecting to the network NW. The communication unit 110 is, for example, a network interface card.

[0022] The content providing unit 120 has, for example, the function of a web server and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 120 appropriately reads necessary content from the content information 174 and provides it to the user terminal device 10. The user terminal device 10 receives various inputs by the user in a state where the content is reproduced by the payment application 20, and transmits the above-mentioned payment information and the like to the payment server 100. The above content may be generated by the payment application 20. In this case, the content providing unit 120 provides information necessary for the generation of the content to the payment application 20.

[0023] The payment processing unit 130 performs payment processing based on the payment information transmitted by the user terminal device 10 or the first store terminal device 50. The payment processing unit 130 performs payment processing while referring to the user information 172.

[0024] [User Information] FIG. 5 is a diagram showing an example of the content of the user information 172. The user information 172 is an example of the registration information of the user. The user information 172 includes, for example, in addition to the user URL, account ID, telephone number, password, email address, user ID, name, address, date of birth, registration date, remaining charge amount, credit payment setting, credit payment limit, credit payment usage amount, available credit payment amount, payment method setting, bank account, credit card number, charge history information, settlement history information, and other information are associated. The user URL is used for the money transfer process between users. When newly registering for the electronic payment service, the registration of the telephone number and password is required. The account ID is issued to the user by the payment server 100, and the user ID is an ID that the user can optionally set (not necessarily set). Similarly, the email address, and the name, address, and date of birth are also information that the user can optionally set (not necessarily set). The registration date is the date when the user registered for the electronic payment service (the date when the account was created). Hereinafter, an instance of the user (electronic payment account) in which these pieces of information are associated is referred to as an account.

[0025] The remaining balance of the charge indicates the information of the remaining balance of the electronic money set by the user by remitting money to the account in advance. As means of remittance, there are remittance from the ATM (Automatic Teller Machine) of the designated operator (bank), remittance from the registered bank account, etc. The credit payment setting indicates whether the setting for enabling electronic payment by credit payment using the payment application 20 has been completed or not, and is set to either "completed" or "not completed". The credit payment limit is the limit amount of credit payment available per month. The credit payment used amount is the amount of credit payment already used in the current month. The available credit payment amount is the amount of credit payment available in the current month, which is obtained by subtracting the credit payment used amount from the credit payment limit. Although only one credit payment limit is shown in the figure, actually there are further upper limits per day, etc., and the lower of them may be set as the credit payment limit. Further details of the credit payment will be described later. The payment method setting is the setting information indicating whether the user makes an electronic payment using the remaining balance of the charge or makes a payment by credit payment at that time. Each of the bank account and the credit card number is the information (account number, card number) of the bank account or credit card number that can receive payments for the electronic payment service. The charge history information is the history of the user increasing the remaining balance of the charge by remitting money to the electronic payment service in advance. The payment history information is the information showing the breakdown of the payments made by the user (date and time, store ID of the store where the purchase action was taken, payment amount, payment method, etc.) for each payment.

[0026] [Authentication information] FIG. 6 is a diagram showing an example of the content of the authentication information 173. The authentication information 173 stores, for example, a write password, code information (one-time code), and information related to a credit card (such as a credit card number, the user's name, expiration date, etc.) for the user's identification information. The code information is information used for authentication stored in the storage unit C4 of the credit card C. The write password is a password used by the payment application 20 to write the code information into the storage unit C4. The authentication information 173 may include a URL (such as a one-time URL: one-time Uniform Resource Locator) in addition to these pieces of information.

[0027] [Franchise / Store Information] FIG. 7 is a diagram showing an example of the content of the franchise / store information 176. The franchise / store information 176 includes, for example, a first table 176A in which a franchise ID and a store ID are associated with a store URL, a second table 176B in which a franchise name and sales amount (described above) are associated with the franchise ID, and a third table 176C in which a store name is associated with the store ID. In addition to these pieces of information, the franchise / store information 176 may include information such as the category of the franchise or store, the location of the store, and the payment pattern.

[0028] The information management unit 140 acquires information provided by other server devices, terminal devices, and the card server 400. Based on the information acquired from the user terminal device 10 and the second store terminal device 70, the information management unit 140 manages the user information 172 and the franchise / store information 176. The information management unit 140 performs operations such as adding, editing, and deleting new records for the user information 172 and the franchise / store information 176.

[0029] The authentication processing unit 150 executes a first authentication process and a second authentication process (details will be described later). The authentication processing unit 150 may execute either the first authentication process or the second authentication process.

[0030] [Electronic Payment] When the settlement processing unit 130 acquires settlement information from the user terminal device 10 or the first store terminal device 50, it refers to the user information 172 to acquire the "settlement method setting" of the user. For users whose "settlement method setting" is set to "charge balance", the settlement processing unit 130 performs electronic settlement as follows. For example, the settlement processing unit 130 performs electronic settlement by reducing the charge balance managed in association with the user ID and increasing the item value of the sales amount of the franchise store. The item value of the sales amount of the franchise store is not used as electronic money itself, for example, and the amount corresponding to the item value of the sales amount is transferred to the bank account in a cycle according to the agreement between the franchise store and the electronic settlement service.

[0031] For users whose "setting information" is set to "credit payment (credit payment using code information)", the settlement processing unit 130 performs electronic settlement as follows. Credit payment is a payment method through cooperation with a credit card company, which is a separate entity from the operator of the electronic settlement service. The operator of the electronic settlement service acts as a creditor and allows electronic settlement that does not depend on the charge balance within the credit payment limit. In addition, in order to receive the credit payment service, it may be required to obtain a credit card provided by the operator of the electronic settlement service. The amount used for credit payment is settled in one lump sum on the payment date of the following month, for example, by debit from the bank account. In this case, the settlement processing unit 130 performs a provisional settlement by adding the settlement amount to the credit payment usage amount and subtracting the same amount from the available credit payment amount. When the closing date arrives, the processing for debiting the settlement of the current month to the payment date of the following month as described above is performed, or the operator of the credit card company is requested to perform the processing. If the settlement amount exceeds the available credit payment amount at the time of provisional settlement, an error notification is returned to the settlement application 20.

[0032] [Overview] This embodiment relates to the authentication of a credit card in cooperation with an electronic payment service. For the credit card, a service for authentication using the payment application 20 is provided. Thereby, it is authenticated whether the use (ownership) by the user who has the authority to use the credit card is valid.

[0033] When the linked credit card is used at a credit card affiliated store, information regarding various services such as usage history may be linked to the payment server 100, the payment application 20, etc. For example, the payment application 20 causes the display unit of the user terminal device to display the usage history.

[0034] [Credit Card] The above credit card may be a credit card used for credit payments or a different credit card. For example, it suffices if the credit card linked to the electronic payment service is the credit card of this embodiment. In the user information 172, information regarding the credit card and the authentication information 173 of the user are associated with the identification information of the user.

[0035] As shown in FIG. 1, the credit card C includes a circuit section C1. The circuit section C1 is, for example, an integrated circuit (IC chip; Integrated Circuit chip). The circuit section C1 includes, for example, a communication section C2, a control section C3, and a storage section C4. The communication section C2 communicates with the communication section of the user terminal device 10. Thereby, the circuit section C1 communicates with the payment application 20 to transmit and receive information. The control section C3 executes, for example, processes related to communication, processes related to reading information, and processes related to writing information in cooperation with the communication section C2 and the storage section C4. The storage section C4 reads the stored information, writes information, and stores the information.

[0036] The memory unit C4 may store code information. For example, for the information processing between the circuit unit C1 and the payment application 20, a predetermined format (e.g., NDEF: NFC Data Exchange Format) is used. The code information is, for example, a one-time code that is changed for each authentication process described later, but is not limited to this. This one-time code is written by using the write password described later. The one-time code is information written in a region different from, for example, the EMV region in which the identification information and expiration date of the credit card are written.

[0037] [Overview of Authentication Process] FIG. 8 is a diagram showing an example of a scene where the authentication process is performed. When the user performs a predetermined operation on the payment application 20, the payment application 20 causes the interface screen IM1 to be displayed on the display unit of the user terminal device. The interface screen IM includes information indicating that the authentication process is to be performed and that the credit card C is to be tapped (brought close to) the user terminal device 10. Next, when the user taps the credit card C, the authentication process is performed. When the authentication process is successful, the payment application 20 causes the interface screen IM2 to be displayed on the display unit. On the interface screen IM2, for example, information indicating that the authentication (e.g., login authentication) has been performed is displayed. The authentication process will be described later.

[0038] The authentication process is executed, for example, when logging in to the payment application 20. For example, when the user changes the model of the smartphone and logs in to the payment application 20 on the smartphone (user terminal device 10) after the model change, the authentication process is performed by tapping (bringing closer) a predetermined card such as the credit card C on the smartphone. When the authentication process is successful, information indicating that the login authentication has been successful is displayed as shown on the interface screen IM2. The authentication process may be prompted to be executed, for example, when preset conditions are met. The preset conditions are, for example, an operation to change the content of the service set for the user in the electronic payment service or an operation to use a predetermined service. The change in the content of the service is, for example, a change in the payment amount available in the electronic payment service (raising the upper limit amount) or a raise in the payment upper limit amount of the credit card C linked to the electronic payment service. The use of a predetermined service is, for example, the use of a service to transfer electronic money handled in the electronic payment service to the bank account of another user, or the use for personal authentication via the payment application 20 using an application program linked to the electronic payment service. For example, in some cases, the above-mentioned personal authentication is required as a condition when using other services. Specifically, in a bank service partnered with the electronic payment service, personal authentication is required when remitting money to the first account number.

[0039] The preset conditions may be, for example, an attempt to use the credit card C for a predetermined payment (for example, a payment of a predetermined amount or a payment at a predetermined store). The preset conditions may be a predetermined use in the electronic payment service such as charging in the electronic payment service using the credit card C. In addition, it may be prompted to execute the authentication process when a predetermined operation is performed in various services (for example, financial services) provided in the electronic payment service.

[0040] In this embodiment, it is described that the authentication process is performed in relation to an electronic payment service, a payment application 20, etc. However, instead of (or in addition to) this, the authentication process may be performed in other services (for example, other services alone). For example, when the service provider of the credit card C or the provider of the banking service performs the authentication process in cooperation with the application of the service for the user of the service, the authentication process of this embodiment may be applied. For example, the server of the provider of the credit card C and the application of the credit card C may cooperate to perform the authentication process.

[0041] FIG. 9 is a diagram showing another example of a scene where the authentication process is performed. In FIG. 8, the authentication was performed to display information regarding login, but in FIG. 9, it is the authentication process for activating the credit card C.

[0042] When the user performs a predetermined operation on the payment application 20, the payment application 20 causes the interface screen IM1# to be displayed on the display unit of the user terminal device 10. The interface screen IM# includes information indicating that activation is to be performed and that the credit card C is to be tapped (brought close to) the user terminal device 10. Next, when the user taps the credit card C, the authentication process related to activation is performed. When the authentication process is successful, the payment application 20 causes the interface screen IM2# to be displayed on the display unit. The interface screen IM2# displays information indicating, for example, that the activation has been performed. As a result, the user can start using the credit card C.

[0043] [Description of the authentication process] The payment application 20 executes one or both of the first authentication process using the write password and the second authentication process using the one-time code. FIG. 10 is a diagram for explaining the authentication process.

[0044] (First authentication process) (0) In the credit card C (memory unit C4), the first one-time code is written using the first write password. (1) The payment application 20 acquires the first write password associated with the user's identification information from the payment server 100. When the credit card C used by the user approaches the user terminal device 10, the payment application 20 uses the communication unit of the user terminal device 10 to perform wireless communication with the circuit unit C1 including the communication unit C2 included in the credit card C and the memory unit C4 capable of writing information using the set password set when writing information.

[0045] The payment application 20 executes a first authentication process for determining whether the user's first write password is the set password. When a positive determination result is obtained, it is determined that the first authentication process has succeeded. The payment application 20 acquires the first write password (write password) of the user of the credit card C from the payment server 100 and checks the validity of the first write password. For example, the payment application 20 tries to write information to the memory unit C4 using the first write password or executes a process for checking a predetermined validity. It is assumed that the validity is confirmed in this process.

[0046] (Second authentication process) (2) The payment application 20 acquires the first one-time code (one-time code) stored in the memory unit C4. The payment application 20 transmits the acquired first one-time code to the payment server 100 and requests a second authentication process for determining whether the first one-time code matches the code information associated with the user's identification information. The payment server 100 determines whether the one-time code of the user's authentication information 173 matches the first one-time code and performs authentication. In this process, it is assumed that the authentication has succeeded.

[0047] (3) After the first authentication process and the second authentication process, the payment server 100 issues a second write password and a second one-time code. The payment server 100 manages the second write password and the second one-time code in association with the user's identification information in the authentication information 173. (4) The payment app 20 writes the second one-time code into the storage unit C4 of the credit card C using the issued second write password. (5) As a result, the second one-time code is written into the storage unit C4 of the credit card C instead of the first one-time code. The write password required for writing is the second write password.

[0048] As described above, by executing the first authentication process and the second authentication process, the security is improved. For example, since the one-time code and the write password are changed for each authentication process, the security is improved.

[0049] Hereinafter, the first authentication process and the second authentication process will be specifically described. FIG. 11 is a sequence diagram centered on the second authentication process, and FIG. 12 is a sequence diagram centered on the first authentication process.

[0050] FIG. 11 is a sequence diagram showing an example of the flow of a process (second authentication process) executed by the electronic payment system. The storage unit C4 of the credit card C stores a one-time code written with a write password. Assume that the user executes a process that requires authentication using the payment app 20.

[0051] The payment app 20 acquires the one-time code stored in the storage unit C4 of the credit card C (S100), and transmits the acquired one-time code and the user's identification information to the payment server 100 (S102). Next, the payment server 100 acquires the one-time code and the user's identification information transmitted by the payment app 20 (S104).

[0052] Next, the payment server 100 determines whether or not the authentication of the one-time code has been successful (S106). For example, the payment server 100 determines whether or not the one-time code associated with the user identification information stored in the authentication information 173 matches the acquired one-time code. If they match, it is determined that the authentication has been successful. If the authentication fails, the payment server 100 executes a second process (S108). The second process is, for example, notifying the payment application 20 of information indicating that the authentication has failed, or stopping the use of the credit card C. The above authentication may be executed by the payment application 20. In this case, the payment application 20 acquires the one-time code associated with the user identification information.

[0053] Next, the payment server 100 stores the result of the above authentication in the storage unit (S109). For example, the payment server 100 stores the user identification information and the result of the authentication in association with each other. As a result, the authentication result for each user can be confirmed retrospectively.

[0054] FIG. 12 is a sequence diagram showing an example of the flow of a process (first authentication process) executed by the electronic payment system. In FIG. 12, the user is tapping the credit card C on the user terminal device 10, and the credit card C and the payment application 20 are in a communicable state.

[0055] The payment application 20 transmits the write password together with the user identification information to the payment server 100 (S150). Next, the payment server 100 acquires the user identification information and the request for the write password (S152). Next, the payment server 100 refers to the authentication information 173, acquires the write password associated with the user identification information, and transmits the acquired write password to the payment application 20 (S154). The write password may be held in the user terminal device 10.

[0056] The payment app 20 acquires the written password that has been transmitted (S156), and requests the user to tap (bring close) the credit card C to the user terminal device 10 (S158). For example, an interface screen regarding the request is provided. Assume that the user taps the credit card C to the user terminal device 10 accordingly.

[0057] Next, the payment app 20 checks the validity of the written password (S160). For example, the payment app 20 checks whether it can write information to the storage unit C4 using the written password. Next, the payment app 20 determines whether the validity has been confirmed (S162). If the validity cannot be confirmed, the payment app 20 executes the first process (S164). If the payment app 20 has executed the process of checking the validity a predetermined number of times but still cannot confirm the validity, as the first process, it causes the display unit of the user terminal device 10 to display that the authentication of the credit card C cannot be confirmed, or notifies the payment server 100 that the validity cannot be confirmed. Also, the payment server 100 may stop the use of the credit card C in response to the notification from the payment app 20.

[0058] If the validity is confirmed, the payment app 20 notifies the payment server 100 of information indicating that the validity has been confirmed (S166). Next, the payment server 100 stores the above authentication result in the storage unit (S167). For example, the payment server 100 stores the user's identification information and the authentication result in association with each other. Thereby, the authentication result for each user can be confirmed afterwards.

[0059] The payment server 100 generates the authentication result information 178 in which the user's identification information and the authentication result are associated as described above. FIG. 13 is a diagram showing an example of the authentication result information 178. The authentication result information 178 is information indicating the result of the first authentication process and the result of the second authentication process for each user's identification information.

[0060] For example, when the second authentication process is successful and the first authentication process fails, for example, there is a possibility that the IC chip of credit card C has been forged. For example, there is a possibility that the one-time code of credit card C has been illegally obtained and a forged IC chip with this one-time code written therein is being used. As described above, by storing the results of the first authentication process and the second authentication process, the legitimacy of credit card C of the user's identification information can be managed.

[0061] Based on the authentication result information 178, the payment server 100 determines whether the card (credit card C) used by the user has been forged. For example, the payment server 100 generates authentication result information 178 in which the results of the first authentication process and the second authentication process are associated with the user's identification information, and refers to the generated authentication result information 178 to determine whether there is forgery. If the payment server 100 determines that there is forgery, it may notify an alert to the terminal device of the card administrator. For example, the payment server 100 may generate a blacklist by referring to the authentication result information 178. For example, the credit card C of the user's identification information for which the second authentication process in the authentication result information 178 is successful and the first authentication process fails may be generated as a blacklisted forged credit card C. In this way, the payment server 100 can perform blacklist management using the authentication process and the results of the authentication process.

[0062] FIG. 14 is a sequence diagram showing an example of the processing flow regarding a new one-time code and a new write password. In the sequence diagram of FIG. 12, after authentication is established, the payment server 100 issues a new one-time code and a new write password, and transmits the issued new one-time code and new write password to the payment application 20 (S180).

[0063] The payment app 20 acquires the new one-time code and the new write password transmitted in S180, and uses the new write password to write and store the new one-time code in the storage unit C4 (S182). At this time, the payment app 20 may control the storage unit C4 to a writable state using the write password acquired in S156 of FIG. 12, and write the new one-time code using the new write password. If there is no need to use the write password acquired in S156 of FIG. 12, the payment app 20 writes the new one-time code into the storage unit C using the new write password. By this process, the storage unit C4 of the credit card C stores the new one-time code (S184). The issuance of the above new one-time code or write password may be executed by the payment app 20. The payment app 20 may acquire the new one-time code or write password from the payment server 100, or may acquire it by itself.

[0064] Next, the payment app 20 determines whether the process of writing the new one-time code was successful (S186). If the process is not successful, the payment app 20 executes the third process (S188). The third process is, for example, a process in which the payment app 20 causes the display unit of the user terminal device 10 to display that the authentication of the credit card C cannot be confirmed, or notifies the payment server 100 that the process was not successful. Also, the payment server 100 may stop the use of the credit card C in response to the notification from the payment app 20.

[0065] If the process is successful, the payment app 20 sends information indicating that the process is successful to the payment server 100 (S190). Next, the payment server 100 acquires the information indicating that the process is successful, executes the fourth process, and notifies the payment app 20 that the authentication process is completed (S192). The fourth process is a process in which the payment server 100 registers a new one-time code and a new write password in the authentication information 173. The payment server 100 may rewrite the one-time code and the write password registered in the authentication information 173 with the new one-time code and the new write password, or may register the new one-time code and the new write password as the one-time code and the write password to be used in the future. A new one-time code and a new write password may be registered in the authentication information 173 after the process of S180 described above. This new one-time code and new write password are information used in the next authentication process after the authentication process.

[0066] Further, the fourth process may include a process in which the payment server 100 confirms or determines that both (or one) of the first authentication process and the second authentication process are established and the current authentication process for the credit card C is established.

[0067] When the payment app 20 acquires a notification from the payment server 100 that the authentication process is established, the payment app 20 displays information indicating that the authentication process is completed on the display unit of the user terminal device 10 (S194). Also, at this time, information corresponding to the purpose of the authentication process is displayed. For example, when the authentication process is performed for login, information indicating that the login is successful is displayed on the display unit of the user terminal device 10. Thereby, one routine of the authentication process ends, and the new one-time code and the new write password registered in the next authentication process are used to execute the first authentication process and the second authentication process.

[0068] As described above, the electronic payment system can improve security by executing one or both of the first authentication process and the second authentication process.

[0069] [Variation of the processing order] Hereinafter, the first authentication process and the second authentication process will be specifically described. The second authentication process may be executed after the first authentication process. FIG. 15 is a sequence diagram centered on the first authentication process, and FIG. 16 is a sequence diagram centered on the second authentication process.

[0070] [Sequence diagram (1)] FIG. 15 is a sequence diagram showing an example of the flow of processing (first authentication process) executed by the electronic payment system. In the storage unit C4 of the credit card C, a one-time code written with a write password is stored. Assume that the user executes a process that requires authentication using the payment application 20.

[0071] The payment application 20 transmits the write password together with the user's identification information to the payment server 100 (S150). Next, the payment server 100 acquires the user's identification information and the request for the write password (S152). Next, the payment server 100 refers to the authentication information 173, acquires the write password associated with the user's identification information, and transmits the acquired write password to the payment application 20 (S154). The write password may be held in the user terminal device 10.

[0072] The payment application 20 acquires the transmitted write password (S156) and requests the user to tap (bring close to) the credit card C on the user terminal device 10 (S158). For example, an interface screen regarding the request is provided. Assume that the user taps the credit card C on the user terminal device 10 in response to this.

[0073] Next, the payment app 20 checks the validity of the write password (S160). For example, the payment app 20 checks whether it can write information to the storage unit C4 using the write password. Next, the payment app 20 determines whether the validity has been confirmed (S162). If the validity cannot be confirmed, the payment app 20 executes the first process (S164). If the payment app 20 has executed the process of checking the validity a predetermined number of times but still cannot confirm the validity, as the first process, it may display on the display unit of the user terminal device 10 that the authentication of the credit card C cannot be confirmed, or notify the payment server 100 that the validity cannot be confirmed. Also, the payment server 100 may stop the use of the credit card C in response to the notification from the payment app 20.

[0074] If the validity is confirmed, the payment app 20 notifies the payment server 100 of information indicating that the validity has been confirmed (S166). This process may be omitted. In this case, when the one-time code described in FIG. 16 is transmitted, the payment server 100 may recognize that the validity has been confirmed. As described above, the process of S167 may be performed.

[0075] FIG. 16 is a sequence diagram showing another example of the flow of a process (second authentication process) executed by the electronic payment system. In FIG. 16, the user is tapping the credit card C on the user terminal device 10, and the credit card C and the payment app 20 are in a communicable state.

[0076] The payment app 20 acquires the one-time code stored in the storage unit C4 of the credit card C (S100), and transmits the acquired one-time code and the user's identification information to the payment server 100 (S102). Next, the payment server 100 acquires the one-time code and the user's identification information transmitted by the payment app 20 (S104).

[0077] Next, the payment server 100 determines whether the one-time code authentication is successful (S106). For example, the payment server 100 determines whether the one-time code associated with the user identification information stored in the authentication information 173 matches the acquired one-time code. If they match, it is determined that the authentication is successful. If the authentication fails, the payment server 100 executes a second process (S108). The second process may include, for example, notifying the payment app 20 of information indicating that the authentication has failed, or stopping the use of the credit card C. The above authentication may be executed by the payment app 20. In this case, the payment app 20 acquires the one-time code associated with the user identification information.

[0078] If the authentication is successful, the payment server 100 issues a new one-time code and a new write password, and transmits the issued new one-time code and new write password to the payment app 20 (S180).

[0079] The payment app 20 acquires the new one-time code and new write password transmitted in S180, and uses the new write password to write and store the new one-time code in the storage unit C4 (S182). At this time, the payment app 20 may, if necessary, control the storage unit C4 to a writable state using the write password acquired in S156 of FIG. 15, and write the new one-time code using the new write password. If there is no need to use the write password acquired in S156 of FIG. 15, the payment app 20 writes the new one-time code into the storage unit C using the new write password. By this process, the storage unit C4 of the credit card C stores the new one-time code (S184). The issuance of the above new one-time code or write password may be executed by the payment app 20. The payment app 20 may acquire the new one-time code or write password from the payment server 100, or may acquire it by itself.

[0080] Next, the payment application 20 determines whether the process of writing a new one-time code was successful (S186). If the process is not successful, the payment application 20 executes a third process (S188). The third process is, for example, a process in which the payment application 20 causes the display unit of the user terminal device 10 to display that the authentication of the credit card C cannot be confirmed, or notifies the payment server 100 that the process was not successful. Also, the payment server 100 may stop the use of the credit card C in response to a notification from the payment application 20.

[0081] If the process is successful, the payment application 20 transmits information indicating that the process was successful to the payment server 100 (S190). Next, the payment server 100 acquires the information indicating that the process was successful, executes a fourth process, and notifies the payment application 20 that the authentication process has been completed (S192). The fourth process is a process in which the payment server 100 registers a new one-time code and a new writing password in the authentication information 173. The payment server 100 may rewrite the one-time code and the writing password registered in the authentication information 173 to the new one-time code and the new writing password, or may register the new one-time code and the new writing password as the one-time code and the writing password to be used in the future. After the process of S160 described above, a new one-time code and a new writing password may be registered in the authentication information 173. This new one-time code and new writing password are information used in the next authentication process after the authentication process.

[0082] Also, the fourth process may include a process in which the payment server 100 confirms or determines that both (or one) of the first authentication process and the second authentication process are established and that the current authentication process for the credit card C is established.

[0083] When the payment app 20 obtains a notification from the payment server 100 that the authentication process has been successful, it displays information indicating that the authentication process has been completed on the display unit of the user terminal device 10 (S194). At this time, information corresponding to the purpose of the authentication process is also displayed. For example, when the authentication process is performed for login, information indicating that the login has been successful is displayed on the display unit of the user terminal device 10. Thus, one routine of the authentication process ends, and in the next authentication process, the newly registered one-time code and the newly written password are used to execute the first authentication process and the second authentication process.

[0084] In the above first authentication process and second authentication process, the processes executed by the payment app 20 may be executed by the payment server 100, and the processes executed by the payment server 100 may be executed by the payment app 20. For example, as described above, the confirmation of the validity of the written password may be executed by the payment server 100. For example, the determination of the match of the one-time code and the issuance of the new one-time code and the new written password may be executed by the payment app 20. Also, part or all of the authentication information 173 may be held in the user terminal device 10.

[0085] One of the above first authentication process and second authentication process may be omitted. For example, the second authentication process may be omitted and the first authentication process may be executed. In this case, the processes of determining the match of the one-time code and issuing the new one-time code are omitted.

[0086] As described above, the electronic payment system can improve security by executing one or both of the first authentication process and the second authentication process.

[0087] [Modification Example] In addition to the one-time code, a URL (for example, one-time URL: one-time Uniform Resource Locator) may be stored in the storage unit C4 of the credit card C.

[0088] FIG. 17 is a diagram for explaining the process of a modified example. (0#) In the credit card C (storage unit C4), a first one-time URL and a first one-time code are written using a first write password. When the credit card C is tapped on the user terminal device 10, the user terminal device 10 reads the first one-time URL and accesses the access destination of the first one-time URL. For example, the user terminal device 10 may access the payment server 100 or may access the payment application 20 as in this process.

[0089] (0##) The user terminal device 10, for example, reads the first one-time URL, activates the payment application 20 installed in the user terminal device 10, and displays a specified interface screen. When the user has not logged in to the payment application 20, the payment application 20 displays a login screen on the display unit to allow the user to log in. When the user is logged in, the first authentication process and the second authentication process are executed.

[0090] (1) The first authentication process and (2) the second authentication process are the same as the process of FIG. 10 described above.

[0091] (3#) After the first authentication process and the second authentication process, the payment server 100 issues a second write password, a second one-time URL, and a second one-time code. The payment server 100 manages the second one-time URL, the second write password, and the second one-time code in the authentication information 173 in association with the user's identification information. (4#) The payment application 20 writes the second one-time URL and the second one-time code to the storage unit C4 of the credit card C using the issued second write password. (5) As a result, the second one-time code and the second one-time URL are written to the storage unit C4 of the credit card C instead of the first one-time code and the first one-time URL.

[0092] FIG. 18 is a diagram showing another example of a scene where authentication processing is performed. For example, when the user taps the credit card C on the user terminal device 10, the payment application 20 starts up, initiates the first authentication process and the second authentication process, and causes the interface screen IM11 to be displayed on the display unit. On the interface screen IM11, for example, information indicating that authentication is in progress is displayed. When the first authentication process and the second authentication process are successful, the payment application 20 causes the interface screen IM12 to be displayed on the display unit. On the interface screen IM12, for example, information indicating that the authentication process has been completed is displayed, and information corresponding to the authentication process (such as successful login) is displayed.

[0093] As described above, when the user brings the credit card C close to the user terminal device 10, the authentication process is performed, thereby improving the convenience for the user.

[0094] In the above example, it has been described that the write password is used in the first authentication process. However, instead of (or in addition to) the write password, a read password for reading the information stored in the storage unit C4 may be used, or a password set for the other circuit unit C may be used. When the read password is used, the first authentication process may be determined to be successful when one or both of the information related to the credit card and the one-time code can be read. When the above information cannot be read, the second authentication process cannot be performed. Therefore, when the first authentication process is successful (when the information can be read), the second authentication process is executed.

[0095] Note that in the above example, it has been described that the authentication process is performed on the credit card C. However, instead of (or in addition to) this, the authentication process may be performed on any medium. For example, the authentication process may be executed on an insurance card, a my number card, a driver's license, or other medium including the circuit unit C.

[0096] Also, in the above example, although the payment app 20 of the electronic payment service has been described as being used for the authentication process, the application program is not limited to the payment app 20, and an application program according to the medium may execute the process of this embodiment.

[0097] According to the embodiment described above, the computer is made to execute a first authentication process for determining whether the first writing password of the user is the set password, and when a positive determination result is obtained, it is determined that the first authentication process has succeeded, whereby the security can be improved. Further, the computer is made to acquire the first code information stored in the storage unit, transmit the acquired first code information to the server device, and request a second authentication process for determining whether the first code information matches the code information associated with the user of the identification information, whereby the security can be improved.

[0098] As described above, the embodiments for implementing the present invention have been described using the embodiments. However, the present invention is not limited to such embodiments, and various modifications and substitutions can be made without departing from the gist of the present invention.

Explanation of Reference Numerals

[0099] 10 User terminal device 20 Payment app 100 Payment server 120 Content providing unit 130 Payment processing unit 140 Information management unit 150 Authentication processing unit

Claims

1. Cause a computer to obtain a first writing password associated with identification information of a user managed in a terminal device from a server device, when the card used by the user is brought close to the terminal device equipped with the computer, wirelessly communicate with a circuit unit including a communication unit included in the card and a storage unit capable of writing information using a setting password set when writing information, using the communication unit of the terminal device, execute a first authentication process for determining whether the user's first writing password is the setting password, when a positive determination result is obtained, determine that the first authentication process has succeeded, obtain first code information stored in the storage unit, send the obtained first code information to a server device and request a second authentication process for determining whether the first code information matches code information associated with the user of the identification information, obtain second code information issued in response to the success of the second authentication process, when the first authentication process is successful, obtain a second writing password different from the first writing password, set the second writing password as the setting password, and write the second code information to the storage unit using the second writing password, An application program.

2. Cause a computer to obtain a first writing password associated with identification information of a user managed in a terminal device from a server device, when the card used by the user is brought close to the terminal device equipped with the computer, wirelessly communicate with a circuit unit including a communication unit included in the card and a storage unit capable of writing information using a setting password set when writing information, using the communication unit of the terminal device, execute a first authentication process for determining whether the user's first writing password is the setting password, when a positive determination result is obtained, determine that the first authentication process has succeeded, obtain first code information stored in the storage unit, execute a second authentication process for determining whether the obtained first code information matches code information associated with the user of the identification information, obtain second code information issued in response to the success of the second authentication process, When the first authentication process is successful, obtain a second writing password different from the first writing password, set the second writing password as the setting password, and use the second writing password to write the second code information to the storage unit. Application program.

3. Cause a computer to Execute the second authentication process before the first authentication process, and execute the first authentication process when the second authentication process is successful. The application program according to claim 1 or 2.

4. The card is a credit card, Cause a computer to When the first authentication process is successful, provide the user with a service associated with the credit card. The application program according to claim 1 or 2.

5. The application program according to claim 1, and A server device that issues the second writing password and the second code information in response to the successful completion of the first authentication process and the second authentication process, and transmits them to the application program. An information processing system comprising:

6. The server device Manages the second writing password and the second code information in association with the identification information of the user, Transmits the managed second writing password to the application program during the next first authentication process, Uses the managed second code information during the next second authentication process. The information processing system according to claim 5.

7. The application program according to claim 1 or 2, and A server device that transmits the first writing password associated with the identification information of the managed user to the application program in response to the identification information of the user and the request transmitted from the application program. An information processing system comprising:

8. Cause a computer to By transmitting to the server device the identification information of the user of the electronic payment service managed by the application program installed in the terminal device on which the computer is mounted, and a request for transmission of the first writing password, Cause the server device to obtain the first writing password associated with the identification information of the user. When the card used by the user approaches the terminal device equipped with the computer, perform wireless communication with a circuit unit including a communication unit included in the card and a storage unit that can write information using a setting password set when writing information, using the communication unit of the terminal device. Execute a first authentication process for determining whether the user's first write password is the setting password. When a positive determination result is obtained, determine that the first authentication process has succeeded. Cause the first code information stored in the storage unit to be acquired. An application program that transmits the acquired first code information to a server device and requests a second authentication process for determining whether the first code information matches the code information associated with the user of the identification information. Based on the authentication result information in which the result of the first authentication process, the result of the second authentication process, and the user's identification information are associated, a server device that determines that there is a high possibility of forgery or that the card for which the first authentication process has failed and the second authentication process has succeeded has been forged. An information processing system comprising the above.

9. On a computer, By transmitting a request for transmission of the identification information of the user of the electronic payment service managed by the application program installed in the terminal device equipped with the computer and the first write password to the server device, Cause the first write password associated with the user's identification information to be acquired from the server device. When the card used by the user approaches the terminal device equipped with the computer, perform wireless communication with a circuit unit including a communication unit included in the card and a storage unit that can write information using a setting password set when writing information, using the communication unit of the terminal device. Execute a first authentication process for determining whether the user's first write password is the setting password. When a positive determination result is obtained, determine that the first authentication process has succeeded. Cause the first code information stored in the storage unit to be acquired. An application program that executes a second authentication process for determining whether the acquired first code information matches the code information associated with the user of the identification information. Based on the authentication result information in which the result of the first authentication process, the result of the second authentication process, and the identification information of the user are associated, for a card in which the second authentication process has succeeded and the first authentication process has failed, a server device that determines that there is a high possibility of forgery or that it has been forged, An information processing system comprising the same.

10. A computer performs a process of obtaining a first write password associated with the identification information of the user managed in the terminal device from the server device, when the card used by the user approaches the terminal device equipped with the computer, using the communication unit of the terminal device, the communication unit included in the card, and a storage unit capable of writing information using the set password set when writing information, a process of performing wireless communication with the circuit unit, a process of executing a first authentication process for determining whether or not the user's first write password is the set password, when a positive determination result is obtained, a process of determining that the first authentication process has succeeded, a process of obtaining the first code information stored in the storage unit, a process of transmitting the obtained first code information to the server device and requesting a second authentication process for determining whether or not the first code information matches the code information associated with the user of the identification information, a process of obtaining the second code information issued in response to the success of the second authentication process, when the first authentication process has succeeded, a process of obtaining a second write password different from the first write password, setting the second write password as the set password, and writing the second code information to the storage unit using the second write password, An information processing method for executing the same.

11. a process of obtaining a first write password associated with the identification information of the user managed in the terminal device from the server device, when the card used by the user approaches the terminal device equipped with the computer, using the communication unit of the terminal device, the communication unit included in the card, and a storage unit capable of writing information using the set password set when writing information, a process of performing wireless communication with the circuit unit, a process of executing a first authentication process for determining whether or not the user's first write password is the set password, When a positive determination result is obtained, a process of determining that the first authentication process has succeeded, and a process of acquiring first code information stored in the storage unit, a process of transmitting the acquired first code information to a server device and requesting a second authentication process for determining whether the first code information matches the code information associated with the user of the identification information, a process of acquiring second code information issued in response to the success of the second authentication process, when the first authentication process succeeds, a process of acquiring a second writing password different from the first writing password, setting the second writing password as the setting password, and writing the second code information to the storage unit using the second writing password, An information processing apparatus that executes the above.

12. A first computer, By transmitting a request for transmission of identification information of a user of an electronic payment service managed by an application program installed in a terminal device on which the first computer is mounted, and a first writing password to a server device, a process of acquiring the first writing password associated with the identification information of the user from the server device, When the card used by the user approaches the terminal device on which the first computer is mounted, a process of performing wireless communication with a circuit unit including a communication unit included in the card and a storage unit capable of writing information using a setting password set when writing information using the communication unit of the terminal device, a process of executing a first authentication process for determining whether the first writing password of the user is the setting password, when a positive determination result is obtained, a process of determining that the first authentication process has succeeded, a process of causing the first code information stored in the storage unit to be acquired, a process of transmitting the acquired first code information to a server device and requesting a second authentication process for determining whether the first code information matches the code information associated with the user of the identification information, and executes, A second computer, Based on the authentication result information in which the result of the first authentication process, the result of the second authentication process, and the identification information of the user are associated, a process of determining that there is a high possibility that a card for which the second authentication process has succeeded and the first authentication process has failed has been forged or has been forged is executed, An information processing method.

13. A first computer, By sending a request for transmission of the identification information of a user of an electronic payment service managed by an application program installed in a terminal device equipped with the first computer and a first write password to a server device, a process of obtaining a first write password associated with the identification information of the user from the server device; when the card used by the user is brought close to the terminal device equipped with the first computer, a process of performing wireless communication with a circuit unit including a communication unit included in the card and a storage unit capable of writing information using a setting password set when writing information using the communication unit of the terminal device; a process of executing a first authentication process for determining whether the first write password of the user is the setting password; a process of determining that the first authentication process has succeeded when a positive determination result is obtained; a process of obtaining first code information stored in the storage unit; a process of executing a second authentication process for determining whether the obtained first code information matches the code information associated with the user of the identification information; and perform, a second computer, Based on the authentication result information in which the result of the first authentication process, the result of the second authentication process, and the identification information of the user are associated, a process of determining that there is a high possibility that a card for which the second authentication process has succeeded and the first authentication process has failed has been forged or has been forged is executed, Information processing method.

Citation Information

Patent Citations

  • Method for card settlement using portable information terminal and its system

    JP2002163584A

  • Authentication system and method in internet banking

    JP2007328381A

  • Collation system

    JP2014197321A

  • JPP7190081B