Server device
The server device secures billing information through a two-stage authentication process using SMS authentication keys, preventing unintended access and maintaining purchase confidentiality.
Patent Information
- Application Number
- JP2022116742
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-21
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2042-07-21
AI Technical Summary
Conventional systems risk exposing billing details to unintended recipients due to incorrect email addresses, compromising purchase confidentiality.
A server device manages payment and billing information through a database linked to user account identifiers, requiring two-stage authentication with an authentication key sent via SMS to ensure only the purchaser can access payment and billing information.
Prevents unauthorized access to purchase details, ensuring confidentiality by limiting knowledge of purchase contents to the purchaser alone.
Smart Images

Figure 0007771883000001 
Figure 0007771883000002 
Figure 0007771883000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a server device. [Background technology]
[0002] Patent Document 1 discloses a system that sends a billing email to a buyer terminal, which includes a payment method for the payment server, based on order information received from the seller terminal. The buyer makes payment using the payment method specified in the billing email. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-176446 Summary of the Invention [Problem to be solved by the invention]
[0004] In conventional systems, the billing details are included in the billing email itself, so if an email address is entered incorrectly and the billing email is sent to someone other than the purchaser, there is a risk that the purchase details will become known to others.
[0005] The purpose of this disclosure is to prevent anyone other than the purchaser from knowing the contents of the purchase. [Means for solving the problem]
[0006] The server device according to the present disclosure includes: A server device that manages a database that stores payment information, including information specifying a plurality of payment methods set for each user, in association with each user's account identifier used for authentication by a wallet application, which is a program that is installed in each user's terminal device, allows the user to select an arbitrary payment method from the plurality of payment methods set for the user when authentication of the corresponding user is successful, and executes payment processing using the selected payment method; The system is provided with a control unit that stores billing information, including information specifying the amount to be billed to the customer upon completion of a sales transaction, in the database, linked to the customer's account identifier, and provides information specifying a billing site for viewing the billing information; when the customer's account identifier is entered into the billing site and authentication of the user who has accessed the billing site is successful, sends an authentication key to the customer's terminal device via a short message service; when a key identical to the sent authentication key is entered into the billing site, retrieves the payment information and billing information stored in linkage to the customer's account identifier from the database, and outputs the retrieved payment information and billing information to the billing site. [Effects of the Invention]
[0007] According to the present disclosure, the contents of a purchase are not known to anyone other than the purchaser. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating a configuration of a server device according to an embodiment of the present disclosure. [Figure 3] 1 is a flowchart illustrating a procedure for remote payment according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, an embodiment of the present disclosure will be described with reference to the drawings.
[0010] In each drawing, the same or corresponding parts are denoted by the same reference numerals. In the description of this embodiment, the description of the same or corresponding parts will be omitted or simplified as appropriate.
[0011] The configuration of a system 10 according to this embodiment will be described with reference to FIG.
[0012] The system 10 according to this embodiment includes a first terminal device 11, a second terminal device 12, and a server device 20, and also includes, although not required, a message distribution infrastructure 13 and a point system 14. The server device 20 is capable of communicating with each external issuer 15 via a network 16. The server device 20 is capable of communicating with the first terminal device 11, the second terminal device 12, and the point system 14 via the network 16 or another network. The first terminal device 11 is capable of communicating with the second terminal device 12 and the message distribution infrastructure 13 in addition to the server device 20 via the network 16 or another network.
[0013] The server device 20 is installed in a facility such as a data center and operated by a business operator that provides payment services. The server device 20 is a server computer that belongs to a cloud computing system or other computing system.
[0014] The first terminal device 11 is held by an employee of a dealership such as a car dealer, or is installed in the dealership and used by the employee of the dealership. The first terminal device 11 is, for example, a mobile device such as a mobile phone, a smartphone, or a tablet, or a PC. "PC" is an abbreviation for personal computer.
[0015] The second terminal device 12 is held and used by a customer who is a user. The second terminal device 12 is, for example, a mobile device such as a mobile phone, a smartphone, or a tablet. A wallet application 30 for using a payment service is installed on the second terminal device 12.
[0016] The wallet application 30 is a program installed on each user's terminal device. When the corresponding user is successfully authenticated, the program allows the user to select an arbitrary payment method from among a plurality of payment methods set for that user, and executes payment processing using the selected payment method. The payment method is set for each user as an arbitrary combination of multiple payment methods, such as prepaid payment, debit payment, credit payment, and point payment. A combination of payment methods may include two or more of the same type of payment method.
[0017] Network 16 may include the Internet, at least one WAN, at least one MAN, or any combination thereof. "WAN" is an abbreviation for wide area network. "MAN" is an abbreviation for metropolitan area network. Network 16 may include at least one wireless network, at least one optical network, or any combination thereof. A wireless network may be, for example, an ad hoc network, a cellular network, a wireless LAN, a satellite communication network, or a terrestrial microwave network. "LAN" is an abbreviation for local area network.
[0018] The outline of this embodiment will be described with reference to FIGS.
[0019] The server device 20 manages a database 24. The database 24 stores payment information 31 linked to each user's account identifier used for authentication by the wallet application 30. The payment information 31 includes information identifying payment methods that can be used by the wallet application 30, i.e., multiple payment methods set for each user. The payment information 31 may also include other information, such as a prepaid balance.
[0020] When a sales transaction, such as a new car purchase, is concluded between a dealership employee and a customer, the server device 20 stores billing information 32 in the database 24, linked to the customer's account identifier. The billing information 32 includes information identifying the billing amount, i.e., the amount to be billed to the customer upon the conclusion of the sales transaction. The billing information 32 may also include other information, such as product information or a payment deadline. The server device 20 provides information identifying a billing site for viewing the billing information 32. When the customer's account identifier is entered into the billing site and the user accessing the billing site is successfully authenticated, the server device 20 transmits an authentication key to the second terminal device 12 via short message service. When the same authentication key as the transmitted key is entered into the billing site, the server device 20 retrieves the payment information 31 and billing information 32, which are stored in association with the customer's account identifier, from the database 24. The server device 20 outputs the retrieved payment information 31 and billing information 32 to the billing site.
[0021] In this embodiment, even if someone other than the purchaser accesses the billing site, the first-stage authentication is not successful, and therefore the person other than the purchaser cannot view the billing information 32, nor can they even obtain the authentication key required for the second-stage authentication. Even if the first-stage authentication is successful, the authentication key is sent to the second terminal device 12, which is the purchaser's own terminal device, and therefore the person other than the purchaser cannot obtain the authentication key. Therefore, according to this embodiment, the purchase details cannot be known by anyone other than the purchaser.
[0022] In this embodiment, the merchant system stores the wallet application ID as the user's account identifier. "ID" is an abbreviation for "identifier." When a product sales transaction is completed, the merchant system transmits a billing address associated with the user's wallet application ID to the second terminal device 12, which is the purchaser's user terminal. The billing address may be transmitted via any method, such as email, chat, or messaging. When the user accesses the billing address, an authentication screen 36 is displayed, prompting the user to enter a wallet application ID and password. After the user enters the wallet application ID and password, an authentication key is transmitted to the second terminal device 12 via short message service. After the user enters the authentication key, billing details, including the purchase amount, are displayed on a payment screen 37. After the billing details are displayed, the user selects any payment method registered in the wallet application 30, and payment is seamlessly completed. Therefore, this embodiment improves the convenience of the system 10. The user can also select credit card payment, eliminating the need to enter information such as a card number.
[0023] The configuration of the server device 20 according to this embodiment will be described with reference to FIG.
[0024] The server device 20 includes a control unit 21, a storage unit 22, and a communication unit 23.
[0025] The control unit 21 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU or GPU, or a dedicated processor specialized for specific processing. "CPU" is an abbreviation for central processing unit. "GPU" is an abbreviation for graphics processing unit. An example of the programmable circuit is an FPGA. "FPGA" is an abbreviation for field-programmable gate array. An example of the dedicated circuit is an ASIC. "ASIC" is an abbreviation for application specific integrated circuit. The control unit 21 controls each part of the server device 20 and executes processing related to the operation of the server device 20.
[0026] The storage unit 22 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, a RAM, a ROM, or a flash memory. "RAM" is an abbreviation for random access memory. "ROM" is an abbreviation for read only memory. RAM is, for example, an SRAM or a DRAM. "SRAM" is an abbreviation for static random access memory. "DRAM" is an abbreviation for dynamic random access memory. ROM is, for example, an EEPROM. "EEPROM" is an abbreviation for electrically erasable programmable read only memory. Flash memory is, for example, an SSD. "SSD" is an abbreviation for solid-state drive. Magnetic memory is, for example, an HDD. "HDD" is an abbreviation for hard disk drive. The storage unit 22 functions, for example, as a main storage device, an auxiliary storage device, or a cache memory. The storage unit 22 stores data used in the operation of the server device 20 and data obtained by the operation of the server device 20. The database 24 may be constructed in the storage unit 22, or may be constructed in an external storage and connected to the server device 20.
[0027] The communication unit 23 includes at least one communication interface. The communication interface is, for example, an interface compatible with a wired LAN communication standard such as Ethernet (registered trademark), or an interface compatible with a wireless LAN communication standard such as IEEE802.11. "IEEE" is an abbreviation for Institute of Electrical and Electronics Engineers. The communication unit 23 communicates with the first terminal device 11, the second terminal device 12, the point system 14, and each issuer 15. The communication unit 23 receives data used in the operation of the server device 20, and transmits data obtained by the operation of the server device 20.
[0028] The functions of the server device 20 are realized by executing a program according to this embodiment on a processor serving as the control unit 21. That is, the functions of the server device 20 are realized by software. The program causes a computer to execute the operations of the server device 20, thereby causing the computer to function as the server device 20. That is, the computer functions as the server device 20 by executing the operations of the server device 20 in accordance with the program.
[0029] The program can be stored on a non-transitory computer-readable medium. Examples of non-transitory computer-readable media include flash memory, magnetic recording devices, optical disks, magneto-optical recording media, and ROMs. The program can be distributed by selling, transferring, or lending portable media such as SD cards, DVDs, or CD-ROMs that store the program. "SD" is an abbreviation for Secure Digital. "DVD" is an abbreviation for digital versatile disc. "CD-ROM" is an abbreviation for compact disc read only memory. The program can also be distributed by storing it in the storage of a server and transferring it from the server to another computer. The program can also be provided as a program product.
[0030] A computer temporarily stores a program stored on a portable medium or transferred from a server in its main storage device. The computer then reads the program stored in the main storage device using a processor and executes processing in accordance with the read program. The computer may also read the program directly from a portable medium and execute processing in accordance with the program. The computer may also execute processing in accordance with the received program each time a program is transferred from a server to the computer. Processing may also be executed through a so-called ASP-type service that achieves its functions by issuing execution instructions and obtaining results without transferring the program from the server to the computer. "ASP" is an abbreviation for application service provider. A program is information used for processing by a computer and includes something equivalent to a program. For example, data that is not a direct instruction to a computer but has properties that specify computer processing falls under the category of "something equivalent to a program."
[0031] Some or all of the functions of the server device 20 may be realized by a programmable circuit or a dedicated circuit as the control unit 21. In other words, some or all of the functions of the server device 20 may be realized by hardware.
[0032] The operation of the system 10 according to this embodiment will be described with reference to Figures 1 and 2. This operation corresponds to the remote payment method according to this embodiment.
[0033] A customer number is stored in advance in the first terminal device 11. The customer number may be the wallet application ID of the customer, or may be a number stored in the database 24 in association with the wallet application ID of the customer.
[0034] The database 24 stores payment information 31 linked to each user's wallet application ID. The wallet application ID is an example of an account identifier for each user used for authentication by the wallet application 30. The payment information 31 includes, for example, information such as payment methods available for the wallet application 30 and prepaid balances. The database 24 also stores a password set for each user linked to each user's wallet application ID.
[0035] In step S1, the first terminal device 11 accepts an operation to register billing information 32 via an input unit of the first terminal device 11, such as a keyboard, a pointing device, or a touch screen. This operation is performed by a store employee entering the billing information 32 when completing a sales transaction with a customer in-store or remotely. The billing information 32 includes information such as the billing amount, product information, and payment deadline. For example, as shown in FIG. 3 , the store employee enters information such as the product category, payment amount, and customer name as the billing information 32 into the first terminal device 11. The first terminal device 11 transmits the entered billing information 32, along with a pre-stored customer number, to the server device 20 via a communication unit of the first terminal device 11 that supports a mobile communication standard such as LTE, 4G, or 5G, a wireless LAN communication standard such as IEEE802.11, or a wired LAN communication standard such as Ethernet (registered trademark). "LTE" is an abbreviation for Long Term Evolution. "4G" is an abbreviation for 4th generation. "5G" is an abbreviation for 5th generation.
[0036] In step S2, the control unit 21 of the server device 20 receives the customer number and billing information 32 from the first terminal device 11 via the communication unit 23. The control unit 21 associates the received billing information 32 with the wallet application ID corresponding to the received customer number and stores it in the database 24. The control unit 21 issues a URL of a billing site for viewing the billing information 32. "URL" is an abbreviation for Uniform Resource Locator. The URL of the billing site is an example of information that identifies the billing site. The control unit 21 transmits the URL of the billing site to the first terminal device 11 via the communication unit 23.
[0037] In step S3, the first terminal device 11 receives the URL of the billing site from the server device 20 via the communication unit of the first terminal device 11. The first terminal device 11 transmits the URL of the billing site to the message distribution infrastructure 13 via the communication unit of the first terminal device 11.
[0038] In step S4, the message distribution infrastructure 13 receives the URL of the billing site from the first terminal device 11. The message distribution infrastructure 13 transmits the URL of the billing site to the second terminal device 12 using the instant message distribution function 35 corresponding to the message reception function provided in the wallet application 30. The second terminal device 12 receives the URL of the billing site from the message distribution infrastructure 13 via a communication unit of the second terminal device 12 that supports a mobile communication standard such as LTE, 4G standard, or 5G standard, or a wireless LAN communication standard such as IEEE802.11. Specifically, the second terminal device 12 receives the URL of the billing site from the message distribution infrastructure 13 using the message reception function provided in the wallet application 30.
[0039] As a variation of this embodiment, in step S3, the first terminal device 11 may directly transmit the URL of the billing site to the second terminal device 12 using a chat distribution function corresponding to the chat reception function provided in the wallet application 30. For example, as shown in FIG. 3 , an employee of the retailer may enter the URL of the billing site into a chat screen displayed on the first terminal device 11 and notify the customer of the URL of the billing site by pressing an approval button. In step S4, the second terminal device 12 may directly receive the URL of the billing site from the first terminal device 11 using the chat reception function provided in the wallet application 30. The chat reception function may be available only when the retailer is registered in the wallet application 30.
[0040] As another variation of this embodiment, in step S3, the first terminal device 11 may send the URL of the billing site to the second terminal device 12 by email, instant message, or any method selected by the store employee. In step S4, the second terminal device 12 may receive the URL of the billing site from the first terminal device 11 by email, instant message, or any method selected by the store employee.
[0041] In step S5, the second terminal device 12 accepts an operation to access the billing site via an input unit, such as a touchscreen, of the second terminal device 12. This operation is performed by the customer selecting or inputting the URL of the billing site received in step S4. For example, as shown in FIG. 3, the customer accesses the billing site by selecting the link to the billing site displayed on the second terminal device 12 and pressing the confirmation button. The second terminal device 12 acquires an authentication screen 36 from the billing site via the communication unit of the second terminal device 12. The second terminal device 12 displays the acquired authentication screen 36 on a display unit, such as an LCD or organic EL, of the second terminal device 12. "LCD" is an abbreviation for liquid crystal display. "EL" is an abbreviation for electroluminescent. The second terminal device 12 accepts an operation to request first-stage authentication from the billing site via the input unit of the second terminal device 12. This operation is performed by the customer entering a wallet application ID and password into the authentication screen 36. The second terminal device 12 transmits the input wallet application ID and password to the server device 20 via the billing site via the communication unit of the second terminal device 12. The control unit 21 of the server device 20 receives the wallet application ID and password from the second terminal device 12 via the communication unit 23. The control unit 21 compares the received password with a password associated with the received wallet application ID and stored in the database 24. If the passwords match, the first-stage authentication is successful. If the passwords do not match, the first-stage authentication is unsuccessful. If the first-stage authentication is successful, the control unit 21 transmits an authentication key to the second terminal device 12 via short message service. The second terminal device 12 receives the authentication key from the server device 20 via short message service. The second terminal device 12 displays the received authentication key on the display unit of the second terminal device 12. The second terminal device 12 accepts an operation to request second-stage authentication from the billing site via the input unit of the second terminal device 12. This operation is performed by the customer entering an authentication key.The second terminal device 12 transmits the input authentication key to the server device 20 via the billing site via the communication unit of the second terminal device 12. The control unit 21 of the server device 20 receives the authentication key from the second terminal device 12 via the communication unit 23. The control unit 21 compares the received authentication key with the authentication key transmitted via the short message service. If the authentication keys match, the second-stage authentication is successful. If the authentication keys do not match, the second-stage authentication is unsuccessful. If the second-stage authentication is successful, the control unit 21 retrieves the payment information 31 and billing information 32 stored in association with the customer's wallet application ID from the database 24. The control unit 21 transmits a screen including the retrieved payment information 31 and billing information 32 as a payment screen 37 to the second terminal device 12 via the billing site via the communication unit 23. The second terminal device 12 retrieves the payment screen 37 from the billing site via the communication unit of the second terminal device 12. The second terminal device 12 displays the acquired payment screen 37 on the display unit of the second terminal device 12.
[0042] In step S6 or S7, the second terminal device 12 accepts an operation to pay the bill amount via the input unit of the second terminal device 12. This operation is performed by the customer selecting one of the payment methods available in the wallet application 30 by referring to the payment information 31. For example, as shown in FIG. 3, the customer confirms information such as the product category, payment amount, and customer name displayed as billing information 32 on the second terminal device 12, selects one of the payment methods displayed as payment information 31, and specifies the payment method by pressing the "Pay" button. The second terminal device 12 notifies the server device 20 of the selected payment method via the communication unit of the second terminal device 12 via the billing site. The control unit 21 of the server device 20 receives the notification from the second terminal device 12 via the communication unit 23. When point payment is selected as the payment method, in step S6, the control unit 21 of the server device 20 requests the point system 14 to perform payment processing using points via the communication unit 23. The point system 14 refers to the point information 38, and if the point balance is greater than the billing amount, executes the payment process using points. If the point balance is less than the billing amount, the point system 14 notifies the server device 20 of the insufficient points. When the control unit 21 of the server device 20 receives the notification of the insufficient points, it instructs the second terminal device 12 via the billing site to select a payment method other than point payment. If a payment method other than point payment is selected, in step S7, the control unit 21 of the server device 20 executes the payment process using the selected payment method. Depending on the selected payment method, in step S8, the control unit 21 communicates with each issuer 15 via the communication unit 23 regarding EC payment. "EC" is an abbreviation for electronic commerce.
[0043] When the payment process is completed in step S6 or step S7, the control unit 21 of the server device 20 updates the payment information 31 stored in the database 24, linking it to the customer's wallet application ID. The control unit 21 stores the payment history corresponding to the billing information 32 in the database 24, linking it to the customer's wallet application ID.
[0044] In step S9, the first terminal device 11 accepts an operation to check the payment history via the input unit of the first terminal device 11. This operation is performed by an employee of the retail store inputting a store code with reference to the retail store master information 34. The store code is a code that identifies the retail store and is stored in the database 24 in association with the wallet application ID of the customer handled by the retail store. The retail store employee may also input an employee number with reference to the retail store employee information 33. The employee number is a number that identifies the retail store employee and is stored in the database 24 in association with the wallet application ID of the customer handled by the employee. The first terminal device 11 transmits the input store code or the combination of the store code and employee number to the server device 20 via the communication unit of the first terminal device 11. The control unit 21 of the server device 20 receives the store code or the combination of the store code and employee number from the first terminal device 11 via the communication unit 23. The control unit 21 acquires from the database 24 the payment history stored in association with the customer's wallet application ID corresponding to the received store code or the combination of the store code and employee number. The control unit 21 transmits the acquired payment history to the first terminal device 11 via the communication unit 23. The first terminal device 11 receives the payment history from the server device 20 via its communication unit. The first terminal device 11 displays the received payment history on its display unit, such as an LCD or organic EL.
[0045] On e-commerce sites, payment is made at the same time as the sale, so authentication at the time of payment is not required. However, in the case of new car sales, payment is made at the time of delivery several months later, so an authentication system at the time of payment is necessary. Even when an invoice is issued at the time of sale and payment is made at a later date, an authentication system at the time of payment is necessary. This embodiment can provide such an authentication system at the time of payment. For example, it can realize non-face-to-face payments between dealership staff and customers.
[0046] This embodiment can be applied not only to new car sales but also to the provision of vehicle inspections or other services. For example, this embodiment can be used when a dealer's sales staff picks up a car from a customer's home and returns it to the customer's home after inspection or repair is complete. In this case, the sales staff can complete the process from providing the service to payment without ever meeting the customer face-to-face.
[0047] In one variation of this embodiment, payments may be made within the wallet application 30 rather than via a billing site. Such a variation would eliminate the need to enter a wallet application ID and password.
[0048] The present disclosure is not limited to the above-described embodiments. For example, two or more blocks shown in the block diagrams may be integrated, or one block may be divided. Two or more steps shown in the flowcharts may be executed in parallel or in a different order, instead of being executed in chronological order as described, depending on the processing capabilities of the device executing each step, or as needed. Other modifications are possible within the scope of the present disclosure. [Explanation of symbols]
[0049] 10 Systems 11 First terminal device 12 Second terminal device 13 Message Delivery Platform 14-point system 15 Issuer 16 Network 20 Server device 21 Control section 22 Memory section 23 Communications Department 24 databases 30 Wallet Applications 31 Payment Information 32 Billing Information 33 Dealer employee information 34 Dealer master information 35 Instant message delivery function 36 Authentication screen 37 Payment screen 38 Points Information
Claims
[Claim 1] A server device that manages a database that stores payment information, including information specifying a plurality of payment methods set for each user, in association with each user's account identifier used for authentication by a wallet application, which is a program that is installed in each user's terminal device, allows the user to select an arbitrary payment method from the plurality of payment methods set for the user when authentication of the corresponding user is successful, and executes payment processing using the selected payment method; a server device having a control unit that stores billing information, including information specifying an amount to be billed to a customer upon completion of a sales transaction between the biller and the customer, in the database by linking it to the customer's account identifier, and transmits information specifying a billing site for viewing the billing information to the biller's terminal device, and when the information specifying the billing site is transmitted from the biller's terminal device to the customer's terminal device, the customer's account identifier is entered into the billing site and authentication of the user who has accessed the billing site is successful, transmits an authentication key to the customer's terminal device via short message service, and when a key identical to the transmitted authentication key is entered into the billing site, retrieves from the database the payment information and billing information stored in linkage to the customer's account identifier, and outputs the retrieved payment information and billing information to the billing site.
Citation Information
Patent Citations
Commodity delivery system, commodity server, program and commodity delivery method
JP2010176446A
Administration system and communication system
JP2017073113A
Sales system, portable terminal, and store computer
JP2020123306A