Card Reader and Payment System

The card reader determines card types and generates masked transaction data to allow partial credit card number output, addressing the inability to display card information in conventional systems, enhancing security and compliance.

JP7717922B2Active Publication Date: 2025-08-04NIDEC INSTR CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024133999
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-08-09
Publication Date
2025-08-04
Estimated Expiration
2040-05-13

AI Technical Summary

Technical Problem

Conventional payment systems cannot output the credit card number at the upper device due to security and legal requirements, preventing display or printing of the card information when a credit card is inserted.

Method used

A card reader that determines the type of card medium and generates transaction data with masked credit card numbers, allowing partial output while ensuring security and compliance with legal standards, such as the PCI DSS standard, by encrypting or deleting data as necessary.

Benefits of technology

Enables partial output of credit card numbers for user recognition while enhancing security by preventing crimes and complying with regulations, reducing processing loads, and maintaining data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007717922000001
    Figure 0007717922000001
  • Figure 0007717922000002
    Figure 0007717922000002
  • Figure 0007717922000003
    Figure 0007717922000003
Patent Text Reader

Abstract

To provide a card reader capable of outputting a portion of a credit card number.SOLUTION: A card information acquisition section 100 acquires card information 300 from a card medium. A card type determination section 110 determines whether the card medium is a credit card or a non-credit card, from the card information 300 acquired by the card information acquisition section 100. When a type of the card medium determined by the card type determination section 110 is a credit card, a data generation section 120 generates truncation data 310 which masks a portion of a card number included in the card information 300. If the most significant digits of the card information are those of the credit card but a result of Luhn calculation does not match a check digit, the card type determination section 110 transmits information indicating that an unauthorized card has been used or that there is a reading error, to a higher-level device 2, stores the information, and makes the credit card unreadable.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a card reader and a payment system, and particularly to a card reader and a payment system using a credit card.

Background Art

[0002] Conventionally, there have been payment systems that perform payments and the like using various types of card-shaped recording media (hereinafter referred to as card media). In such a payment system, for example, a user may be identified using a so-called "house card" such as a medical examination ticket or a point card at a hospital or the like, and then payment may be made using a "credit card" for money payment. That is, in the conventional payment system, two types of card media may be used during one payment.

[0003] As such a conventional payment system, for example, referring to Patent Document 1, an automatic transaction device that processes a received card, i.e., a received card, is described. The automatic transaction device of Patent Document 1 includes a card information acquisition unit that acquires card information stored in the received card, a specification unit that specifies the type of the received card from the card information, a type information acquisition unit that acquires type information indicating the type of the card to be received, and a processing unit that executes processing on the card information based on the processing information switched by a processing setting unit. On this basis, when the type of the card to be received is a type of card for which card information should not be encrypted, and the type of the received card is a type of card for which card information should be encrypted, the processing unit deletes the card information. That is, in the technology of Patent Document 1, when a credit card is inserted while a non-credit card such as a house card is in a waiting state, the configuration is such that the card information is deleted.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the conventional payment system as described in Patent Document 1, when a credit card is inserted in a credit card waiting state, due to security and legal requirements, card information is encrypted and transferred to the server that processes the credit card payment up to the server. For this reason, there has been a problem that at the upper device that outputs the payment result, the credit card number cannot be output at all, such as by display or printing.

[0006] The present invention has been made in view of such a situation, and an object thereof is to enable at least a part of the credit card number to be output at the upper device that outputs the payment result, and to solve the above-described problem.

Means for Solving the Problems

[0007] The card reader of the present invention includes a card information acquisition unit that acquires card information from a card medium, a card type determination unit that determines whether the card medium is a credit card or a non-credit card from the card information acquired by the card information acquisition unit, and when the type of the card medium determined by the card type determination unit is a credit card, a data generation unit that generates transaction data in which a part of the card number included in the card information is masked. The data generation unit transmits all digits of the card medium to the connected upper device without encryption when the card medium is a non-credit card house card, and when the instruction from the upper device is in a credit card reading waiting state and the type of the card medium is a credit card, the transaction data is transmitted without encryption in response to a request from the connected upper device. When the instruction from the upper device is in a house card reading waiting state and the type of the card medium is a credit card, the generated transaction data beforeDo not send it to the host device and notify an error that a credit card has been inserted. The same area for storing the card information is configured to be overwritten when transaction data is generated next, When the leading digits of the card information are the leading digits of a credit card but the Luhn operation result does not match the check digit, the card type determination unit transmits information indicating that an illegal card has been used or that there is a reading error to the host device, stores the information, and makes it impossible to read the card itself. By configuring in this way, at least a part of the credit card number can be output, and the security can be further enhanced. and This can contribute to preventing crimes using counterfeit cards and the like.

[0008] The card reader of the present invention is characterized in that the transaction data includes some or all of the leading or trailing digits defined by the PCI DSS standard. By configuring in this way, while meeting security and legal requirements, it is possible to output a number that the user can recognize as which card.

[0009] (Deleted)

[0010] (Deleted)

[0011] The payment processing system of the present invention is a payment processing system including a card reader that reads a card medium and a host device that is connected to the card reader and performs payment processing. The card reader includes a card information acquisition unit that acquires card information from the card medium, a card type determination unit that determines whether the card medium is a credit card or a non-credit card from the card information acquired by the card information acquisition unit, and a data generation unit that generates transaction data in which a part of the card number included in the card information is masked when the type of the card medium determined by the card type determination unit is a credit card. The host device includes a data acquisition unit that acquires the transaction data from the card reader and a data output unit that outputs the transaction data acquired by the data acquisition unit included in the payment information in the payment processing. When the type of the card medium is a house card that is a non-credit card, the data generation unit transmits all digits of the card medium to the host device without encryption. When the instruction from the host device is in a state of waiting for reading a credit card and the type of the card medium is a credit card, the data generation unit transmits the transaction data without encryption in response to a request from the connected host device. When the instruction from the host device is in a state of waiting for reading the house card and the type of the card medium is a credit card, the generated transaction data before is not transmitted to the above-mentioned host device, and an error indicating that a credit card has been inserted is notified. The same area for storing the card information is configured to be overwritten when transaction data is generated next, When the upper digit of the card information is the upper digit of a credit card but the Luhn operation result does not match the check digit, the card type determination unit transmits information indicating that an illegal card has been used or a reading error has occurred to the host device, stores the information, and makes it impossible to read itself. By configuring in this way, at least a part of the credit card number can be output by the host device, and the security can be further enhanced. and This can contribute to preventing crimes caused by counterfeit cards and the like.

Effect of the Invention

[0012] According to the present invention, when the type of the identified card medium is a credit card, by generating transaction data in which a part of the card number included in the card information is masked, a card reader capable of outputting a part of the credit card number can be provided.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0014] <Embodiment> 〔Configuration of Payment System〕 First, with reference to FIGS. 1 and 2, the configuration of the payment system X according to an embodiment of the present invention will be described. The payment system X includes a card reader 1 and a host device 2 on which the card reader 1 is mounted. In the present embodiment, the card reader 1 and the host device 2 are connected by a LAN (Local Area Network) such as USB (Universal Serial Bus), RS-232C, or Ethernet (registered trademark). Furthermore, in the present embodiment, the host device 2 of the payment system X is connected via a WAN (Wide Area Network) such as a dedicated line or the Internet to a server 3 for performing credit card payments.

[0015] The card reader 1 is a device to be controlled by the host device 2 and is an example of a device capable of reading (reading) or writing (writing) to / from a card medium 4. The card reader 1 is a manual or motor-conveyed card reader / writer device. In the case of a manual type, the user manually inserts the card medium 4 into the device and extracts the card medium 4 from inside the device to play back the data recorded on the card medium 4. In the case of a motor-conveyed type, the card reader 1 executes various processes such as conveyance and reading / writing of the card medium 4 according to a command from the host device 2.

[0016] The host device 2 is, for example, a settlement system in a hospital, other settlement systems, a kiosk, a ticket issuing system in a transportation facility, a point card settlement system such as in a convenience store, a terminal of a member card issuing system in a retail store, etc. Alternatively, as the host device 2, it is also possible to use a PC (Personal Computer), a cash register, or other settlement terminals.

[0017] The server 3 is a secure server that provides services for credit card payments, etc. Note that the server 3 may be connected to servers of other banks or card companies, etc. Also, various other information in the settlement can be obtained from the server 3 and other servers.

[0018] The card medium 4 is a card-shaped magnetic recording medium such as a rectangular vinyl chloride card with a thickness of about 0.7 to 0.8 mm, an IC card, a non-contact IC card, etc. In the case of a magnetic recording medium, a magnetic stripe for storing magnetic signals is formed on one surface of the card medium 4. In the case of an IC card, the card medium 4 may include, for example, contacts for connecting to the card reader 1 and an IC chip including a storage area and an MPU (Micro Processing Unit), etc. In the case of a non-contact IC card, an electromagnetic induction antenna for short-range wireless is built in. The card medium 4 may be a recording medium combining any one or all of these. In addition, as the card medium 4, a mobile terminal such as a mobile phone or a smartphone used by the user can also be used for transactions.

[0019] In this embodiment, an example will be described in which payment card information 300 as a credit card or a non-credit card is recorded on the magnetic stripe of the card medium 4. In this embodiment, a credit card is a card used for settlement by a bank or the like. Non-credit cards include, for example, so-called "house cards" such as medical examination tickets at hospitals, boarding cards for transportation, point cards at retail stores, and membership cards.

[0020] In addition to this, in this embodiment, the host device 2 is connected to a settlement business server (not shown). This business server is a business server for hospitals, transportation facilities, retail stores, service providers, etc.

[0021] Next, the control configuration of the payment system X will be described. The card reader 1 includes a control unit 10, a storage unit 11, and a magnetic head 12. The host device 2 includes a control unit 20, a storage unit 21, an input unit 22, a display unit 23, and a printing unit 24.

[0022] The control unit 10 controls the entire card reader 1. The control unit 10 is a control arithmetic means including, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), etc.

[0023] The storage unit 11 is a recording medium that stores various setting values, control programs, temporary data, etc. of the card reader 1. Among these various setting values, the details of the setting values related to transactions will be described later. The control program is firmware or the like for controlling the entire card reader 1 and performing reading and writing of the card medium 4.

[0024] The storage unit 11 includes a volatile recording medium such as a RAM and a non-volatile recording medium such as a ROM. Among these, as the ROM, for example, it includes recording media such as flash memory, EEPROM, ReRAM, FeRAM, etc.

[0025] The magnetic head 12 is a reading unit that reads the recorded information of the card medium 4. Specifically, the magnetic head 12 reads and reproduces the recorded information written on the magnetic stripe of the card medium 4 as a magnetic signal. The magnetic signal of the magnetic stripe or the like of the card medium 4 read by the magnetic head 12 is output as an analog signal and converted into a digital signal by a magnetic information processing circuit (not shown) and then output. Here, the magnetic head 12 may be an encryption circuit that encrypts this digital signal or an encrypted magnetic head incorporating an MPU (Micro Processing Unit). In addition, for reading and writing the recorded information of the card medium 4, IC contacts other than the magnetic head, a receiving circuit and an antenna of NFC (Near-Field Communications, short-range wireless) may be further provided.

[0026] In addition to these, the card reader 1 also includes an LED (Light Emitting Diode) for displaying the status of transactions and the like, various buttons and dip switches for setting, and interfaces such as USB and RS-232C for connecting to the upper device 2, etc.

[0027] The control unit 20 is, for example, a CPU, MPU, DSP, ASIC, GPU (Graphics Processing Unit), etc. that controls the entire upper device 2. The control unit 20 may be provided with an accelerator circuit for performing high-speed encryption and decryption of codes.

[0028] The storage unit 21 is a recording medium that stores various setting values, control programs, temporary data, etc. of the upper device 2. This control program includes an OS (Operating System), various application software (hereinafter simply referred to as "apps"), middleware for relaying between the card reader 1 and the upper device 2, etc. The storage unit 21 includes a RAM, ROM, HDD (Hard Disk Drive), and other optical recording media, etc.

[0029] The input unit 22 is an operation input unit including buttons such as a touch panel and numeric keypad. In addition to this, the input unit 22 may be provided with a biometric information input device such as a fingerprint, vein pattern, iris pattern, and face recognition camera.

[0030] The display unit 23 is a dot matrix display including a liquid crystal display, an organic EL display, a vacuum fluorescent display, an LED, etc. The input unit 22 and the display unit 23 may be integrally formed like a touch panel display.

[0031] The printing unit 24 is a printing device such as a thermal method, a dot impact method, an inkjet method, etc. The printing unit 24 may be capable of printing using an ink ribbon or liquid ink. Thereby, the printing unit 24 can record information about the settlement on recording paper such as a settlement receipt or a receipt.

[0032] In addition to this, the host device is provided with a network connection unit for connecting to the server 3 and the like. In addition, the host device may be provided with an audio output unit for outputting audio and the like.

[0033] Next, the functional configuration of the settlement system X will be described. The control unit 10 of the card reader 1 includes a card information acquisition unit 100, a card type determination unit 110, and a data generation unit 120. The storage unit 11 stores card information 300, transaction data 310, and status information 320. The control unit 20 of the host device 2 includes a data acquisition unit 200 and a data output unit 210. The storage unit 21 stores transaction data 310 and settlement information 330.

[0034] The card information acquisition unit 100 acquires card information 300 from the card medium. In the present embodiment, the card information acquisition unit 100 acquires card information 300 based on the analog signal acquired by the magnetic head 12. At this time, the card information acquisition unit 100 can also decrypt the encrypted signal from the encrypted magnetic head and acquire it as the card information 300.

[0035] The card type determination unit 110 determines whether the card medium is a credit card or a non-credit card from the card information 300 acquired by the card information acquisition unit 100. Specifically, the card type determination unit 110 can determine whether it is a credit card or a non-credit card other than that from the PAN upper digit and the Luhn operation result, which will be described later, among the card information 300.

[0036] When the type of the card medium determined by the card type determination unit 110 is a credit card, the data generation unit 120 generates transaction data 310 in which a part of the card number included in the card information 300 is masked.

[0037] Furthermore, when the type of the card medium is a non-credit card, the data generation unit 120 can transmit all the digits of the card medium to the connected upper device without encryption. On the other hand, when the type of the card medium is a credit card, the data generation unit 120 can transmit the transaction data 310 without encryption in response to a request from the connected upper device. In addition, when the type of the card medium is a credit card but the instruction from the upper device is not in the credit card waiting state, the data generation unit 120 can be configured to delete the generated transaction data 310 or not transmit it to the upper device.

[0038] The data acquisition unit 200 acquires the transaction data 310 from the card reader 1. More specifically, the data acquisition unit 200 can acquire the encrypted card information 300 of the credit card when in the credit card waiting state.

[0039] The data output unit 210 outputs the transaction data 310 acquired by the data acquisition unit 200 included in the settlement information 330 in the settlement process. At this time, the data output unit 210 can print, for example, part or all of the transaction data 310 on a receipt, a payment receipt, etc. by the printing unit 24.

[0040] The card information 300 is information for identifying the card medium 4 recorded on a magnetic stripe or the like of the card medium 4. In the present embodiment, an example is shown in which information of 14 to 16 digits such as at least the PAN (Primary Account Number) information described below is used as the card information 300. In the case of a house card, arbitrary values are set by the provider of the card medium 4 at the positions of each digit of this PAN information. In addition to this, the card information 300 may include other information recorded on the card medium 4.

[0041] Here, an example of the card information 300 will be described with reference to FIGS. 2(a) and 2(b). FIG. 2(a) shows an example in which PAN information is used as the card information 300-1 of a credit card. Here, the PAN information indicates the card number of the user, and the number is different for each individual user. FIG. 2(b) shows an example in which house card information is used as the card information 300-2 of a house card, which is an example of a non-credit card. This card information 300-2 is arbitrary information recorded at the position where the PAN information of the credit card is recorded, and the number of digits is also variable length. That is, in the case of a non-credit card, it is possible to use arbitrary information according to the configuration of the payment system X instead of the PAN information.

[0042] The transaction data 310 is information obtained by masking a part of the card number of the credit card. In the present embodiment, the transaction data 310 includes a part or all of the upper digits or lower digits defined by the PCI DSS standard among the above-described PAN information.

[0043] Here, an example of the transaction data 310 will be described with reference to FIG. 2(c). FIG. 3(c) shows an example of using, as transaction data 310, a 6-digit number for the first half digits of the PAN information and a 4-digit number for the second half digits of the PAN information. That is, for the 7 to 12 digits to be masked, values or characters different from the values of the corresponding digits of the card information 300, such as "0", "1", "N (None)", or random numbers, are set (hereinafter referred to as "transaction"). When printed, this truncated part is output as "*" (asterisk) or the like so that the entire card number cannot be identified.

[0044] The status information 320 is information indicating the status of the card reader 1 corresponding to commands from the upper device. In the present embodiment, as the status information 320, for example, information such as a flag indicating whether it is in a waiting state for reading a house card or a waiting state for reading a credit card is used.

[0045] The settlement information 330 is information on settlement (payment) using a house card and a credit card in the settlement system X of the present embodiment. In the present embodiment, the settlement information 330 includes, for example, information printed on a receipt or a payment receipt as text data, XML data, or the like.

[0046] Here, the control unit 10 of the card reader 1 functions as a card information acquisition unit 100, a card type determination unit 110, and a data generation unit 120 by executing a control program including firmware and the like stored in the storage unit 11. The control unit 10 of the upper device 2 functions as a data acquisition unit 200 and a data output unit 210 by executing a control program including firmware, an OS (Operating System), application software, and the like stored in the storage unit 11. Note that the data stored in the storage unit 11 and the storage unit 21 may be variable depending on the processing state, procedure, and the like.

[0047] 〔Settlement Process〕 Next, with reference to FIGS. 3 to 5, the settlement process according to the embodiment of the present invention will be described. In the settlement process of this embodiment, the card information 300 is read by the card reader 1 in the order of the house card and the credit card, and the settlement is performed. When reading this credit card, the host device 2 acquires the transaction data 310 from the card reader 1. Then, the acquired transaction data 310 is output including it in the settlement information 330 in the settlement process.

[0048] The settlement process of this embodiment is mainly executed by the control unit 10 and the control unit 20 in cooperation with each unit using the hardware resources by executing the control programs stored in the storage unit 11 and the storage unit 21. Hereinafter, first, the main processes of the settlement process of this embodiment will be described step by step with reference to the flowchart of FIG. 3. Here, in the flowchart of FIG. 3, the transmission and reception of data and commands in plain text (non-encrypted state) are indicated by a one-dot chain line, and the transmission and reception of encrypted data are indicated by a two-dot chain line.

[0049] (Step S201) First, the data acquisition unit 200 of the host device 2 performs house card standby processing. After the start of the settlement, the data acquisition unit 200 displays on the display unit 23 an instruction to insert, for example, a house card as a non-credit card. Then, the data acquisition unit 200 transmits a command to acquire the card information 300 of the house card, which is a non-credit card, to the card reader 1.

[0050] (Step S101) Next, the card information acquisition unit 100, the card type determination unit 110, and the data generation unit 120 of the card reader 1 perform read data transmission processing. Here, the status information 320 is set to the house card reading waiting state. And the information of the house card is transmitted in plain text. Details of this process will be described later.

[0051] (Step S202) Here, the data output unit 210 of the host device 2 performs house card processing. The data output unit 210 identifies the user based on the card information 300 of the house card and performs various settlement processes. Specifically, for example, when the card medium 4 is a medical examination ticket or a point card, the data output unit 210 can separately connect to the business server to calculate the payment amount of the user or obtain the settlement information 330 including the calculation result. In addition, when an error is returned in the above-described read data transmission process, the data output unit 210 performs processes such as warning to insert a correct house card or canceling the settlement.

[0052] (Step S203) Next, the data acquisition unit 200 of the host device 2 performs a credit card standby process. After processing the house card, when the user selects to pay with a credit card, the data acquisition unit 200 displays an instruction on the display unit 23 to insert the credit card. Then, the data acquisition unit 200 sends a command to the card reader 1 to acquire the card information 300 of the credit card.

[0053] (Step S102) Here, the card information acquisition unit 100, the card type determination unit 110, and the data generation unit 120 of the card reader 1 perform a read data transmission process. The content of this process itself is the same as that of step S101 described above. However, here, the status information 320 is set to the credit card reading waiting state. And the information of the credit card is transmitted in encrypted data. In the host device 2 that receives this encrypted data, this is directly transferred to the server 3.

[0054] (Step S301) Next, the server 3 performs a credit card settlement process. Server 3 acquires the encrypted card number (encrypted data) of the credit card obtained by card reader 1 via upper-level device 2 and performs a settlement. At this time, server 3 can also acquire the PIN number, biometric information, signature, etc. input at input unit 22 of upper-level device 2. Except for transaction data 310, card reader 1 and upper-level device 2 do not hold these credit card data due to security and legal requirements. Server 3 returns this settlement result data to upper-level device 2.

[0055] (Step S204) Next, data output unit 210 of upper-level device 2 performs a result printing process. When data output unit 210 acquires the settlement result data, it renders (draws) settlement information 330 at printing unit 24 and causes it to be printed on a receipt, invoice, etc. At this time, data output unit 210 can include at least a part of transaction data 310 in settlement information 330 and print and output it on a recording paper. For example, data output unit 210 can output the last four digits, etc. of the card information 300 of the credit card as card details on the recording paper. Thus, the settlement process according to the embodiment of the present invention ends.

[0056] Next, the details of the read data transmission process in steps S101 and S102 of FIG. 3 will be described. In this read data transmission process, first, card information 300 is acquired from the card medium. Then, it is determined from the acquired card information 300 whether the card medium is a credit card or a non-credit card. In the present embodiment, it is determined whether the card medium 4 inserted into card reader 1 is a credit card or a house card, and the operation is changed according to the determination result. When the determined type of the card medium is a credit card, transaction data 310 in which a part of the card number included in card information 300 is masked is generated. Hereinafter, with reference to the flowchart of FIG. 4 and the conceptual diagram of FIG. 5, the details of the read data transmission process will be described step by step.

[0057] (Step S110) First, the card information acquisition unit 100 performs command reception processing. The card information acquisition unit 100 receives a command to acquire card information 300 of a credit card or a non-credit card. In this embodiment, as the non-credit card, a command to acquire card information 300 of a house card is received. Then, corresponding to this command, the card information acquisition unit 100 sets the status information 320 to a waiting state for reading a credit card or a non-credit card.

[0058] (Step S111) Next, the card information acquisition unit 100 performs card information acquisition processing. The card information acquisition unit 100 acquires the card information 300 of the card medium 4 read by the magnetic head 12 and temporarily stores it in the storage unit 11. At this time, the card information acquisition unit 100 acquires all the information recorded on the card medium 4. That is, the card information acquisition unit 100 acquires the card information 300 including the values of all digit positions corresponding to the PAN information.

[0059] (Step S112) Next, the card type determination unit 110 performs upper digit acquisition processing. The card type determination unit 110 acquires the data at the upper digit position of the PAN of the card information 300. Specifically, the card type determination unit 110 can acquire the upper (first) 6 digits, which are called the Issuer Identification Number (IIN) or the Bank Identification Number (BIN), among the locations corresponding to the PAN information of the card information 300.

[0060] (Step S113) Next, the card type determination unit 110 determines whether the acquired upper digit is the upper digit of a credit card. The card type determination unit 110 determines whether the obtained upper digits represent a credit card. Specifically, for example, when the most significant digit among the upper digits of the obtained card information 300 conforms to the Major Industry Identifier (MII) indicating the issuing business operator of the credit card, and it is clear that the remaining digits also represent an international brand or the card issuing business operator, the card type determination unit 110 determines it as Yes. In other cases, that is, when the industrial classification or category of the above-mentioned most significant digit is not a credit card, or the remaining digits are unknown, etc., the card type determination unit 110 determines it as No. In the case of Yes, the card type determination unit 110 proceeds with the process to step S114. In the case of No, the card type determination unit 110 proceeds with the process to step S120.

[0061] (Step S114) When it is the upper digit of a credit card, the card type determination unit 110 performs a Luhn operation process. The card type determination unit 110 performs an operation on each digit at the position corresponding to the PAN information according to the Luhn algorithm defined in ISO / IEC 7812-1, etc. The card type determination unit 110 temporarily stores this operation result in the storage unit 11.

[0062] (Step S115) Next, the card type determination unit 110 determines whether the Luhn operation result matches the last digit. The card type determination unit 110 determines whether the value of the least significant (last) digit of the card information 300 corresponds to the operation result by the above-mentioned Luhn algorithm. That is, the card type determination unit 110 checks the "check digit", which is the last digit of the credit card number. When the value of the least significant digit at the position corresponding to the PAN information of the card information 300 matches the operation result, the card type determination unit 110 determines it as Yes. In this case, the card type determination unit 110 determines that it is a credit card. In other cases, the card type determination unit 110 determines "No". In this case, the card type determination unit 110 determines that it is a non-credit card, and in this embodiment, it determines that it is a house card. If it is "Yes", the card type determination unit 110 advances the process to step S116. If it is "No", the card type determination unit 110 advances the process to step S120.

[0063] (Step S116) If it is a credit card, the data generation unit 120 performs a transaction data generation process. The data generation unit 120 generates transaction data 310 by masking a part of the card number included in the card information 300. Specifically, the data generation unit 120 creates transaction data 310 including a part or all of the upper digits or lower digits specified by the PCI DSS standard. In this embodiment, the data generation unit 120 generates data in which the 7th to 12th digits of the PAN information as shown in FIG. 2(c) above are truncated.

[0064] (Step S117) Next, the data generation unit 120 determines whether it was in a credit card waiting state. The data generation unit 120 refers to the status information 320 and determines "Yes" when it was in a state of waiting to read a credit card due to the reception of a command. The data generation unit 120 determines "No" in other cases. If it is "Yes", the data generation unit 120 advances the process to step S118. If it is "No", the data generation unit 120 advances the process to step S119.

[0065] (Step S118) If it was in a credit card waiting state, the data generation unit 120 performs a credit card transmission process. This process is the process when a credit card is inserted while in a credit card waiting state. As shown in Fig. 5(a), the data generation unit 120 encrypts the card information 300 of the credit card and transmits it to the host device 2 once as encrypted data. Then, the data generation unit 120 also transmits the transaction data 310 to the host device 2 in plain text. After that, the data generation unit 120 finishes the read data transmission process.

[0066] (Step S119) If it is not in the credit card reading waiting state, the data generation unit 120 performs a data deletion process. In the present embodiment, this process is the process when the type of the card medium 4 is a credit card but the instruction from the host device 2 is in the house card reading waiting state or the like. As shown in Fig. 5(b), in the present embodiment, the data generation unit 120 deletes (erases) the transaction data 310 from the storage unit 11 and does not transmit it to the host device 2. Or, instead of simply deleting the transaction data 310, the data generation unit 120 may simply not transmit it. In this case, when the next transaction data 310 is generated, it may be overwritten in the same area where the card information 300 of the storage unit 11 is stored. Then, the data generation unit 120 notifies the host device 2 of an error that a credit card has been inserted. After that, the data generation unit 120 finishes the read data transmission process.

[0067] (Step S120) Here, the data generation unit 120 performs a house card transmission process. In the present embodiment, this process is the process when a house card is inserted regardless of whether it is in the credit card or house card reading waiting state. Referring to FIG. 5(c), the data generation unit 120 transmits, without encrypting, to the host device 2 in plain text (unencrypted data), the card information 300 which is the information of the position corresponding to the PAN information recorded on the house card which is a non-credit card. That is, the data generation unit 120 transmits, without encrypting, the values of all digits of the card medium 4 to the host device 2 connected to the card reader 1.

[0068] Accordingly, when the card information 300 is transmitted while waiting for the house card to be read, the host device 2 that has acquired this can execute house card processing. On the other hand, when the house card is read while in the credit card waiting state, the host device 2 can display an error such as "Please insert a credit card" on the display unit 23 and request the insertion of the credit card again. Thus, the reading data transmission process according to the embodiment of the present invention ends.

[0069] 〔Main effects of this embodiment〕 By configuring as described above, the following effects can be obtained. The card reader 1 according to the embodiment of the present invention is characterized by including: a card information acquisition unit 100 that acquires card information 300 from a card medium; a card type determination unit 110 that determines whether the card medium 4 is a credit card or a non-credit card from the card information 300 acquired by the card information acquisition unit 100; and a data generation unit 120 that generates transaction data 310 in which a part of the card number included in the card information 300 is masked when the type of the card medium determined by the card type determination unit 110 is a credit card. By configuring in this way, a part of the credit card number can be output. Specifically, since the credit card number is truncated, it can be held without being encrypted by the card reader 1 or the host device 2. As a result, in the host device 2, although the card number cannot be specified, the user can print a recognizable number for which card it is. That is, for example, the last four digits of the card number or the like can be printed on a receipt or a statement. Therefore, in accordance with regulations such as the Installment Sales Act, while being able to present a part of the card number, the convenience of the user can be enhanced.

[0070] The card reader 1 according to an embodiment of the present invention is characterized in that the transaction data 310 includes a part or all of the upper digits or lower digits defined by the PCI DSS standard. By configuring in this way, the transaction data 310 required for security and legal requirements can be prepared, and based on this, a number recognizable by the user for which card it is can be printed on a receipt or a statement.

[0071] The card reader 1 according to an embodiment of the present invention is characterized in that when the type of the card medium 4 is a non-credit card, the data generation unit 120 transmits all the digits of the card medium 4 to the connected host device 2 without encryption, and when the type of the card medium 4 is a credit card, the transaction data 310 can be transmitted without encryption in response to a request from the connected host device 2. By configuring in this way, while securely settling the credit card, the transaction data 310 can be transmitted in plain text and held and used by the host device 2. Furthermore, the processing load and the like can be reduced compared to encrypting and transmitting the transaction data 310.

[0072] The card reader 1 according to an embodiment of the present invention is characterized in that when the type of the card medium 4 is a credit card, but the instruction from the host device 2 is not in the state of waiting for reading the credit card, the generated transaction data 310 is deleted or not transmitted to the host device. By configuring it in this way, even if a credit card is accidentally inserted and read, the generated transaction data 310 can be prevented from being acquired by the upper device 2 once. As a result, security can be enhanced and the transaction data 310 can be effectively utilized.

[0073] The settlement system X according to an embodiment of the present invention is a settlement system including a card reader 1 that reads a card medium and an upper device 2 that is connected to the card reader 1 and performs settlement processing. The card reader 1 includes a card information acquisition unit 100 that acquires card information 300 from the card medium 4, a card type determination unit 110 that determines whether the card medium 4 is a credit card or a non-credit card from the card information 300 acquired by the card information acquisition unit 100, and when the type of the card medium 4 determined by the card type determination unit 110 is a credit card, a data generation unit 120 that generates transaction data 310 in which a part of the card number included in the card information 300 is masked. The upper device 2 includes a data acquisition unit 200 that acquires the transaction data 310 from the card reader and a data output unit 210 that outputs the transaction data 310 acquired by the data acquisition unit 200 included in the settlement information 330 in the settlement processing. By configuring it in this way, a part of the credit card number can be output by the printing unit 24 or the like of the upper device 2, and the convenience for the user can be enhanced. That is, even in the settlement system X that encrypts and transmits the card number to the server, it is possible to print the last four digits or the like of the card number on a receipt or a receipt at the upper device 2 which is a settlement terminal.

[0074] 〔Other embodiments〕 In the above-described embodiment, it has been described that the card information 300 is deleted when a credit card is inserted in a waiting state for reading a house card or the like. However, instead of deleting the card information 300 itself, the address information (location information) of the memory area of the storage unit 11 in which the card information 300 is recorded may be erased. That is, it is also possible to delete a pointer or the like of the card information 300. By configuring in this way, it becomes possible to effectively utilize the memory area of the storage unit 11.

[0075] In addition, in the above-described embodiment, it is described that when the house card is inserted in the credit card waiting state for reading, all digits of data of the card information 300 are transmitted in plain text. However, in such a case, it may be possible to simply notify only an error to the upper device 2 or to transmit only a part of the house card information 300. By configuring in this way, it becomes possible for the upper device 2 to immediately recognize that an incorrect card has been inserted, and the processing load on the upper device 2 can be reduced. In addition, security can be further improved.

[0076] In addition, in the above-described embodiment, it is described that even when the Luhn operation result does not match the check digit, the card information 300 is transmitted to the upper device 2 in plain text as it is. However, in such a case, it is also possible to transmit to the upper device 2 that an illegal card has been used or that it is a reading error. Furthermore, this information may be stored in the card reader 1 or the reading itself may be made impossible. By configuring in this way, it becomes possible to further enhance security and contribute to preventing crimes using forged cards or the like.

[0077] In addition, in the above-described embodiment, it is described that in the settlement process, after reading the house card, the credit card is read. However, it may be configured so that the house card is read after the payment is made by credit card. In this case, it is possible to perform house card processing to confirm the user's intention, and then transmit the encrypted data to the server 3 to make the actual payment. Alternatively, it is possible to use a non-credit card other than the house card, or to read multiple house cards such as a point card and a card for another service, etc. Furthermore, if the user pays with cash, it is not necessary to read the credit card itself. This configuration makes it possible to accommodate a variety of payment system configurations.

[0078] In the above embodiment, the server 3 is a server that provides a payment service for credit card payments. Furthermore, in the above embodiment, the upper device 2 is described as being separately connected to a business server for settlement. However, the upper device 2 and the server 3 may be the only devices that can handle bill settlement and credit card payments. Alternatively, the server 3 may also function as the business server. Furthermore, the business server may be configured using a so-called "cloud" service. Additionally, in the above embodiment, an example has been described in which the server 3 and the higher-level device 2 are directly connected. However, a configuration in which the server 3 and the higher-level device 2 are connected via the above-mentioned business server may also be used. This configuration allows for flexible payment system configurations using credit cards and house cards.

[0079] In the above embodiment, an example has been described in which the card reader 1 and the higher-level device 2 are separate devices. However, a settlement terminal device (system) that integrates the functions of a card reader and a higher-level device may also be used. Such a configuration allows for flexible configuration.

[0080] Note that the configurations and operations of the above embodiments are examples, and it goes without saying that they can be appropriately modified and implemented without departing from the spirit of the present invention.

Explanation of Signs

[0081] 1 Card reader 2 Host device 3 Server 4 Card medium 10, 20 Control unit 11, 21 Storage unit 12 Magnetic head 22 Input unit 23 Display unit 24 Printing unit 100 Card information acquisition unit 110 Card type determination unit 120 Data generation unit 200 Data acquisition unit 210 Data output unit 300, 300-1, 300-2 Card information 310 Transaction data 320 Status information 330 Settlement information X Payment system

Claims

1. A card information acquisition unit that acquires card information from a card medium; A card type determination unit that determines whether the card medium is a credit card or a non-credit card from the card information acquired by the card information acquisition unit; A data generation unit that generates transaction data by masking a part of the card number included in the card information when the type of the card medium determined by the card type determination unit is a credit card, and The data generation unit When the card medium is a house card of a non-credit card type, transmits all digits of the card medium to an upper device to which they are connected without encryption, When the instruction from the upper device is in a state of waiting for credit card reading and the type of the card medium is a credit card, transmits the transaction data without encryption in response to a request from the connected upper device, When the instruction from the upper device is in a state of waiting for house card reading and the type of the card medium is a credit card, does not transmit the generated transaction data to the upper device, notifies an error that a credit card has been inserted, and overwrites the same area where the card information is stored when the next transaction data is generated, The card type determination unit When the upper digits of the card information are the upper digits of a credit card but the Luhn operation result does not match the check digit, transmits information indicating that an illegal card has been used or that there is a reading error to the upper device, stores the information, and makes it impossible to read itself, A card reader characterized by the above.

2. The transaction data Includes some or all of the upper digits or lower digits defined by the PCI DSS standard The card reader according to claim 1, characterized by the above.

3. A payment system including a card reader that reads a card medium and an upper device that is connected to the card reader and performs payment processing, The card reader A card information acquisition unit that acquires card information from the card medium; A card type determination unit that determines whether the card medium is a credit card or a non-credit card from the card information acquired by the card information acquisition unit; When the type of the card medium determined by the card type determination unit is a credit card, it includes a data generation unit that generates transaction data by masking a part of the card number included in the card information. The host device includes a data acquisition unit that acquires the transaction data from the card reader, and a data output unit that includes the transaction data acquired by the data acquisition unit in the payment information in the payment process and outputs it. The data generation unit in the case of a house card where the type of the card medium is a non-credit card, transmits all digits of the card medium to the host device without encryption. when the instruction from the host device is in a credit card waiting state for reading and the type of the card medium is a credit card, transmits the transaction data without encryption in response to a request from the connected host device. when the instruction from the host device is in a house card waiting state for reading and the type of the card medium is a credit card, does not transmit the generated transaction data to the host device, notifies an error that a credit card has been inserted, and allows it to be overwritten when the next transaction data is generated in the same area where the card information is stored. The card type determination unit when the upper digits of the card information are the upper digits of a credit card but the Luhn operation result does not match the check digit, transmits information indicating that an illegal card has been used or that there is a reading error to the host device, stores the information, and makes the reading itself impossible. A payment system characterized by the above.

Citation Information

Patent Citations

  • Forged identification card deciding method, identification card reader, identification card settling device, identification card and computer-readable recording medium with program for making computer perform the method

    JP2001338272A

  • Transaction settlement apparatus

    JP2006215723A

  • Systems and methods for flexibly securing card data

    JP2017097875A

  • Automatic transaction device, automatic transaction system, automatic transaction method, and automatic transaction program

    JP2019109723A

  • Card data acquisition system, card reader and card data acquisition method

    JP2020052444A