Service providing device, management method, and program

The service providing device manages the login status of lost terminal devices by logging out and issuing temporary passwords, facilitating easy re-login, thus addressing the cumbersome issues of conventional methods.

JP7786000B1Active Publication Date: 2025-12-15PAYPAY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025117215
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-12-15
Estimated Expiration
2045-07-11

AI Technical Summary

Technical Problem

Conventional methods for managing the login status of network services on lost terminal devices are cumbersome, often leading to users abandoning the services.

Method used

A service providing device and method that includes a loss processing unit to log out the application program, issue a temporary password, and store it with the device's telephone number, and a restart processing unit to log in using the matching temporary password.

Benefits of technology

Enables appropriate management of the login status of lost terminal devices, allowing users to seamlessly resume network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007786000000001_ABST
    Figure 0007786000000001_ABST
Patent Text Reader

Abstract

To appropriately manage a login state when a terminal device is lost. [Solution] A service providing device that provides network services via an application program running on a terminal device that is a mobile phone, comprising: a loss processing unit that, in response to notification that the terminal device has been lost, puts the application program into a logged-out state, issues a temporary password, and stores the temporary password in a memory unit in association with the telephone number of the terminal device; and a restart processing unit that, when the temporary password is entered, puts the application program into a logged-in state if the entered temporary password matches the temporary password stored in the memory unit.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a service providing device, a management method, and a program. [Background technology]

[0002] Conventionally, network services provided via application programs running on terminal devices such as smartphones have become widespread. Network services are often provided by users logging in (putting the application program into a logged-in state). For this reason, managing the login state when the terminal device is lost has become an issue. Patent Document 1 describes a system in which, when a communication terminal such as a smartphone is lost or damaged, a request is made to an independent corporation to create a new private key for an individual, and the independent corporation verifies the individual's identity. If the individual's identity is confirmed, a new private key for the individual can be created from two other private keys. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2023-102725 Summary of the Invention [Problem to be solved by the invention]

[0004] In the conventional technology, when a terminal device is lost, complicated procedures are required, which may cause users to abandon network services. As such, in the conventional technology, it is sometimes not possible to appropriately manage the login status when a terminal device is lost.

[0005] The present invention has been made in consideration of these circumstances, and one of its objectives is to provide a service providing device, a management method, and a program that can appropriately manage the login status when a terminal device is lost. [Means for solving the problem]

[0006] One aspect of the present invention is a service providing device that provides network services via an application program running on a terminal device that is a mobile phone, and includes a loss processing unit that, in response to notification that the terminal device has been lost, puts the application program into a logged-out state, issues a temporary password, and stores the temporary password in a memory unit in association with the telephone number of the terminal device; and a restart processing unit that, when the temporary password is input, puts the application program into a logged-in state if the input temporary password matches the temporary password stored in the memory unit. [Effects of the Invention]

[0007] According to one aspect of the present invention, it is possible to appropriately manage the login status when a terminal device is lost. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 illustrates basic aspects of brick-and-mortar electronic payment. [Figure 2] FIG. 1 is a diagram illustrating an example of a configuration for performing electronic payment (terminal payment) using a payment application. [Figure 3] FIG. 10 is a diagram showing an example of the contents of user information 172. [Figure 4] FIG. 10 is a diagram showing an example of the contents of affiliated store / shop information 174. [Figure 5] FIG. 10 is a diagram showing an outline of a processing flow when a user scan is performed. [Figure 6] FIG. 10 is a diagram showing an outline of the processing flow when a store scan is performed. [Figure 7] FIG. 1 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. [Figure 8] FIG. 2 is a diagram showing an example of the configuration and surrounding environment for login management in case of loss performed by the payment server 100. [Figure 9] FIG. 10 is a diagram showing an example of the contents of temporary password correspondence information 176. [Figure 10] FIG. 10 is a sequence diagram showing an example of the flow of a process for login management in case of loss. [Figure 11] FIG. 10 is a diagram illustrating an example of a temporary password input screen. [Figure 12] FIG. 10 is a sequence diagram illustrating an example of a processing flow for requesting reissue of a temporary password. [Figure 13] FIG. 10 is a diagram showing another example of the configuration and surrounding environment for login management in case of loss performed by the payment server 100. DETAILED DESCRIPTION OF THE INVENTION

[0009] [overview] Hereinafter, with reference to the drawings, embodiments of a service providing device, a management method, and a program according to the present invention will be described. The service providing device is realized by one or more processors. The service providing device provides network services via an application program running on a terminal device (hereinafter referred to as a user terminal device) that is a mobile phone, and manages the login status of users to the network service. In the following description, the network service is assumed to be an electronic payment service. The application program, a payment server, and a credit card server work together to provide the electronic payment service. In the following description, the application program is referred to as a payment app, and the service providing device is referred to as a payment server. An electronic payment service is a service that supports payments for the purchase of goods and services at a store. A store is, for example, a physical store (real store) existing in real space, but may also include a virtual store for e-commerce transactions. A virtual store may also include a store operated by an entity different from the operator of the electronic payment service. In such a case, control is exercised to transition to an interface screen of the electronic payment service when making a payment for a purchase at the virtual store. In an electronic payment service, a store is treated as belonging to, for example, an affiliated store (brand), and electronic payments when a purchase is made at a store are primarily made between the user and the affiliated store. Alternatively, electronic payment may be made between the user and the store.

[0010] [Electronic payment methods at brick-and-mortar stores] FIG. 1 illustrates the basic aspects of brick-and-mortar electronic payments. Electronic payments are generally carried out by three parties: a medium M held by a user U, store equipment E, and a payment system S. The medium M may be a portable computer device such as a smartphone or a credit card. The store equipment E resides in a physical brick-and-mortar store (hereinafter simply referred to as the store) in real space and may include a POS device, a wireless communication device, a credit card reader, a printed code image such as a QR Code (registered trademark), or a display device displaying the code image. In brick-and-mortar electronic payments, information that can identify the user and information about the payment amount are first shared unidirectionally or bidirectionally between the medium M and the store equipment E. At this time, either the medium M or the store equipment E optically reads various information from a code image displayed by the other, provides information via near-field communication (NFC), or reads the PAN (primary account number) using a credit card reader. Then, either the medium M or the store equipment E (the party that obtains information from the other) transmits the payment information required for the payment to the payment system S via a network NW. Both the medium M and the store equipment E may send some information to the payment system S. The payment system S manages various information about the user U and performs electronic payments between the store and the user U in various ways. Electronic payments are performed using either or both of a prepaid system and a postpaid system, or by other methods. In addition, electronic payments may also include so-called online shopping, which is performed between the user's terminal device and the payment system. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, etc. The various devices that communicate via the network NW, which will be described below, are assumed to have communication devices such as network cards and wireless communication modules.

[0011] [Configuration (Terminal Payment)] 2 is a diagram showing an example of the configuration for performing electronic payment (terminal payment) using a payment app. This electronic payment is performed mainly by a payment app 20 running on a user terminal device 10, which is one of the media M, one or more store payment terminals 30 and one or more store code images 40, which are one of the store facilities E, and a payment server 100, which constitutes part of a payment system S. The payment server 100 communicates with the user terminal device 10, the store payment terminal 30, and one or more information terminals 50 via a network NW.

[0012] The user terminal device 10 is a portable terminal device such as a smartphone or tablet. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input acceptance function, and a program execution function. In the following description, components for realizing these functions are referred to as a camera, a communication device, a touch panel, a central processing unit (CPU), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, which operates in cooperation with a payment server 100 to provide electronic payment services to users. The payment application 20 is installed on the user terminal device 10 from, for example, an application distribution server (not shown) and controls the camera, communication device, touch panel, etc. of the user terminal device 10. In the following description, the terms "send information to the user terminal device 10 (or receive / acquire information from the user terminal device 10)" and "send information to the payment application 20 (or receive / acquire information from the payment application 20)" may be used interchangeably, but these terms are merely different expressions and are not intended to distinguish between them.

[0013] The store payment terminal 30 is installed, for example, in a store. The store payment terminal 30 is a computer device (or a collection of these) that has at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The store payment terminal 30 includes a so-called POS (Point of Sale) device, and the POS device may have a product price acquisition function and an optical reading function.

[0014] The store code image 40 is placed in a store and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 40 may be displayed on a display placed in the store (or on a display of a terminal device such as a smartphone or tablet terminal).

[0015] The information terminal 50 is used by the operator of the affiliated store who oversees the stores. In electronic payment services, customers who provide goods or services are treated as affiliated stores (brands), and one or more stores exist under the affiliated store. An affiliated store may operate only one store. The information terminal 50 is a smartphone, tablet terminal, personal computer, etc. An affiliated store interface 55 runs on the information terminal 50. The affiliated store interface 55 may be an affiliated store app or a web page displayed by a general-purpose browser. The affiliated store interface 55 accepts coupon settings and the like from the affiliated store operator and transmits them to the payment server 100. By executing the affiliated store interface 55, the information terminal 50 may have the function of displaying a code image corresponding to the store code image 40 or reading a code image displayed by the user terminal device 10 (in the latter case, an optical reading function is required).

[0016] The payment server 100 communicates with the credit card server 200 via a network NW. The payment server 100 has, for example, a content provider 110, an information management unit 120, a payment processing unit 130, and a storage unit 170. The components other than the storage unit 170 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be implemented using a large scale integration (LSI), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like. The program may be realized by hardware (including circuitry) such as a Gate Array (GPU) or a Graphics Processing Unit (GPU), or may be realized by a combination of software and hardware. The program may be stored in advance in a storage device (a storage device with a non-transitory storage medium) such as a hard disk drive (HDD) or flash memory, or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device.

[0017] The storage unit 170 is a HDD, flash memory, RAM (Random Access Memory), etc. The storage unit 170 may be a NAS (Network Attached Storage) device that can be accessed by the payment server 100 via a network. The storage unit 170 stores information such as user information 172 and affiliated store / shop information 174.

[0018] The content providing unit 110 has, for example, a function of a web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The content providing unit 110 provides the content to the user terminal device 10 in the form of a web page, and provides the user terminal device 10 with parameters required for the payment application 20 to render an image.

[0019] The information management unit 120 edits, adds, deletes, etc., user information 172 and affiliated store / shop information 174, and manages them.

[0020] FIG. 3 is a diagram showing an example of the contents of user information 172. User information 172 is information in which, for example, user URL, account ID, phone number, password, registration date, charge balance, electronic money type, terminal payment method, card payment method, various history information, identity verification flag, name, address, date of birth, email address, bank account, deferred payment settings, deferred payment condition information, and login status flag indicating login status are associated with each other. Hereinafter, a user instance (electronic payment account) in which this information is associated may be referred to as an account. In the figure, items marked with "-" indicate that they are not set. The login status flag is set to, for example, "logged in," "logged out," or "login restricted."

[0021] The user URL is used for remittance processing between users. When registering for the electronic payment service, registration of a phone number and password is required. The account ID is issued to the user by the payment server 100. The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). The charge balance is information indicating the balance of electronic money that the user has set by transferring money to the account in advance. Remittance methods include depositing money into an ATM (Automatic Teller Machine) of a designated service provider (bank) or transferring money from a registered bank account. The type of electronic money is information indicating, for example, whether the electronic money can be withdrawn or can only be used for electronic payments. The terminal payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in terminal payment. The card payment method is setting information indicating whether the user will make electronic payment using the charge balance (balance payment) or by deferred payment in card payment. The various historical information includes charge history, which is a record of the user transferring money to the electronic payment service in advance to increase the charge balance, and payment history, which shows the details of the payments made by the user for each payment (date and time, store ID of the store where the purchase was made, affiliated store ID, payment amount, payment method, etc.).

[0022] The identity verification flag is information indicating whether or not the user has completed identity verification using an ID document. Deferred payment can be selected if identity verification has been completed, and the user with account ID "002" in the figure has not completed identity verification and can only select balance payment as the terminal payment method. The bank account is the account number of a bank account that can be used to deposit funds into the electronic payment service. Deferred payment settings is information indicating whether or not the settings have been completed to make deferred payment selectable. Deferred payment condition information is information indicating various conditions such as the deferred payment limit and the amount used for the current month.

[0023] 4 is a diagram showing an example of the contents of affiliated store / store information 174. The affiliated store / store information 174 includes, for example, a first table 174A in which an affiliated store ID and a store ID are associated with a store URL, a second table 174B in which an affiliated store ID is associated with an affiliated store name and sales amount (described above), and a third table 174C in which a store ID is associated with a store ID. In addition to this information, the affiliated store / store information 174 may also include information such as the category of the affiliated store or store, the store's location, and payment patterns.

[0024] The payment processing unit 130 performs various processes for electronic payment. There are two methods for terminal payment: a first method (user scan) and a second method (store scan), which will be explained below.

[0025] FIG. 5 shows an overview of the process flow when a user scan is performed. First, the user terminal device 10, with the payment application 20 running, reads and decodes the store code image 40 using its optical reading function (S1). The store code image 40 contains store URL information. The payment application 20 sends first payment information, including the store URL and the user's account ID, to the payment server 100 (S2). The payment server 100 searches the affiliated store / store information 174 using the affiliated store ID and store ID corresponding to the store URL, acquires information about the affiliated store name and store name (S3), and sends this to the payment application 20 (S4). The user enters the payment amount into the payment application 20 on the screen displaying the affiliated store name and store name (S5). The payment application 20 then generates second payment information including at least the payment amount and sends it to the payment server 100 (S6).

[0026] If the "Terminal Payment Method" in the user information 172 of the user is set to "Balance Payment," the payment processing unit 130 of the payment server 100 performs electronic payment based on the received second payment information (S7-1). At this time, the payment processing unit 130 performs electronic payment by, for example, decreasing the charge balance managed in association with the user ID and increasing the item value of the affiliated store's sales proceeds. The item value of the affiliated store's sales proceeds is not used as electronic money itself, for example, but rather the amount corresponding to the item value of the sales proceeds is transferred to a bank account in a cycle determined by an agreement between the affiliated store and the electronic payment service. On the other hand, if the "Terminal Payment Method" is set to "Deferred Payment," the payment processing unit 130 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S7-2). The credit card server 200 performs electronic payment by adding the payment amount to the user's monthly usage amount based on the received information and deducting the monthly usage amount from the user's bank account after the closing date (S7-3).

[0027] Then, the payment processing unit 130 sends a payment completion notice (information for displaying a payment completion screen) to the payment app 20 via the content providing unit 110 (S8), and the payment app 20 displays the payment completion screen (S9). When the store code image 40 is displayed on a display installed in the store, the store code image 40 may include information on the payment amount in addition to the store URL. In this case, the procedure for the user to input the payment amount is omitted, and the information on the payment amount is included in the first payment information and sent to the payment server 100. Information on the affiliated store name and store name may be included and displayed on the payment completion screen.

[0028] FIG. 6 is a diagram showing an overview of the processing flow when a store scan is performed. First, when the payment app 20 is launched, when a payment operation is performed using the payment app 20, when an automatic update timing (e.g., every minute) occurs, and at other timings, the payment app 20 sends a request to issue a one-time code to the payment server 100 (S11). The payment processing unit 130 of the payment server 100 generates a one-time code (S12) and sends it to the payment app 20 (S13). The payment app 20 displays a code image, such as a QR code or barcode, generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the store payment terminal 30, and the store payment terminal 30 reads and decodes the code image using its optical reading function to obtain the one-time code, etc. (S15). The store payment terminal 30 then generates payment information including the one-time code, payment amount, affiliated store ID, store ID, etc., and sends it to the payment server 100 (S16). The payment amount information is acquired in advance by reading a barcode or manually entering it.

[0029] The payment processing unit 130 of the payment server 100 identifies the user corresponding to the one-time code based on the received information, and if the "terminal payment method" in the user information 172 of the user is set to "balance payment," it performs electronic payment based on the received second payment information (S17-1). The processing content at this time is the same as the processing of S7-1 in FIG. 5. On the other hand, if the "terminal payment method" is set to "post-payment," the payment server 100 transmits the first payment information and the second payment information to the credit card server 200 to request electronic payment (S17-2). The credit card server 200 adds the payment amount to the user's monthly usage amount based on the received information, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date (S17-3).

[0030] Then, the payment processing unit 130 transmits a payment completion notification to the payment application 20 via the content providing unit 110 (S18), and the payment application 20 displays a payment completion screen (S19).

[0031] Note that electronic payment may be performed using only one of the above patterns. Furthermore, the "account ID" described in FIG. 2 may be other information (e.g., a phone number) that can be used as user identification information. Furthermore, issuing a one-time code may be omitted in store scanning, and the payment application 20 may display a code image generated based on the user's account ID. In this case, the payment server 100 identifies the user corresponding to the account ID instead of identifying the user corresponding to the one-time code.

[0032] It should be noted that the "post-payment" settlement may be performed within the settlement server 100, rather than being managed by the credit card server 200. In this case, the components such as the settlement card 60 and the credit card server 200 may be omitted.

[0033] [Configuration (Card Payment)] 7 is a diagram showing an example of a configuration for performing electronic payment (card payment) using a payment card. This electronic payment is performed mainly using a payment card 60, which is one of the media M, a credit card processing terminal 70, which is one of the store facilities E, a payment server 100, which constitutes part of a payment system S, and a credit card server 200. The credit card server 200 communicates with the credit card processing terminal 70 via a network NW.

[0034] The credit processing terminal 70 is installed in the store, similar to the in-store payment terminal 30. The credit processing terminal 70 includes, for example, a credit card reader and a POS device. The credit card terminal reads a personal identification number (PIN) from an inserted or held-up credit card and compares it with the PIN entered by the user. It also transmits a primary account number (PAN) read from the credit card to the credit card server 200 via the POS device. The POS device cooperates with the credit card terminal to transmit information such as the payment amount to the credit card server 200. A payment agent (acquirer) server may be interposed between the credit processing terminal 70 and the credit card server 200; however, for simplicity, the following description omits the server. The payment card 60 is, for example, similar to a commonly used credit card, with a communication chip embedded in the card substrate. The communication chip incorporates a storage medium storing the PIN and communicates with an external device via a contactor (or a wireless antenna). Alternatively, the payment card 60 may be a magnetic card. The information (messages) sent and received when using a credit card include an authorization message for authentication and a sales message for conveying the payment amount, but detailed explanations distinguishing between these will be omitted below.

[0035] The credit card server 200 communicates with the payment server 100 via a network NW. The credit card server 200 includes, for example, an information management unit 210, a credit interface 220, a payment allocation unit 230, a credit payment processing unit 240, and a memory unit 270. The components other than the memory unit 270 are implemented by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be implemented by hardware (including circuitry) such as an LSI, ASIC, FPGA, or GPU, or may be implemented by a combination of software and hardware. The program may be stored in advance in a storage device such as an HDD or flash memory (a storage device with a non-transitory storage medium), or may be stored in a removable storage medium (a non-transitory storage medium) such as a DVD or CD-ROM, and installed in the storage device by inserting the storage medium into a drive device. The memory unit 270 stores information such as card user information 272.

[0036] The information management unit 210 edits, adds, deletes, etc., and manages the card user information 272. The card user information 272 is information in which, for example, information unique to a user (e.g., PAN), a card payment method, and the user's account ID (used by the payment server 100) are associated with one another. The card payment method is setting information that indicates whether the user will make electronic payment using the charged balance (balance payment) or deferred payment when making a card payment.

[0037] The credit interface 220 determines whether the BIN (Bank Identification Number) in the PAN included in the message received from the credit processing terminal 70 is a code for the company, and if it is a code for the company, passes the message received from the credit processing terminal 70 to the payment allocation unit 230, and if it is not a code for the company, discards the received message.

[0038] The payment allocating unit 230 refers to the card user information 272 of the user corresponding to the message obtained from the credit interface 220, and determines whether the "card payment method" is set to "post-payment." If the "card payment method" is set to "post-payment," the payment allocating unit 230 notifies the credit interface 220 of this and passes the message obtained from the credit interface 220 to the credit payment processing unit 240. On the other hand, if the "card payment method" is set to "balance payment," the payment allocating unit 230 adds the user's account ID to the message obtained from the credit interface 220 and sends it to the payment server 100, requesting electronic payment. When requested to make electronic payment, the payment server 100 performs the same processes as S7-1 in Figure 5 and S17-1 in Figure 6.

[0039] The credit interface 220 checks the PAN and expiration date, and verifies whether the cumulative payment amount exceeds the current month's upper limit, etc. The credit payment processing unit 240 adds the payment amount to the user's monthly usage amount based on the information contained in the message obtained from the payment allocation unit 230, and performs electronic payment by deducting the monthly usage amount from the user's bank account after the closing date.

[0040] [Login management in case of loss] FIG. 8 is a diagram showing an example of the configuration and surrounding environment for login management in case of loss performed by the payment server 100. For example, the payment server 100 communicates with an automated response system 300. The automated response system 300 is a system that automatically responds to telephone inquiries by voice, and is also called an IVR (Interactive Voice Response) system. The automated response system 300 may acquire a number entered by the user as a response into the telephone 80, or may have a voice recognition function and acquire the meaning of the user's voice inquiries and responses.

[0041] The payment server 100 further includes a loss processing unit 140 and a restart processing unit 150 as a configuration for login management in the event of loss, in addition to the configuration shown in Fig. 2. These components are realized, for example, by a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware such as an LSI, ASIC, FPGA, or GPU, or may be realized by a combination of software and hardware. The configuration including the loss processing unit 140 and the restart processing unit 150 may be a device separate from the payment server 100. In this case, the device having these configurations may be called a management device.

[0042] User U shown in FIG. 8 is a user who lost and later found user terminal device 10. For example, temporary password correspondence information 176 is further stored in storage unit 170. FIG. 9 is a diagram showing an example of the contents of temporary password correspondence information 176. For example, temporary password correspondence information 176 associates a user's telephone number with a temporary password (to be described later), the date and time (or date) when user terminal device 10 was lost, and other information. The temporary password is set to, for example, a four-digit number.

[0043] FIG. 10 is a sequence diagram showing an example of the flow of a process for login management in the event of loss. First, a user U who has lost the user terminal device 10 calls a predetermined telephone number using any telephone 80. An automated answering system 300 responds to calls made to the predetermined telephone number, and the user U notifies the automated answering system 300 that the user terminal device 10 has been lost (S20). The automated answering system 300 requests the telephone number, date and time of loss, and other information from the telephone 80 (S21). In response, the user U contacts the automated answering system 300 with the telephone number, date and time of loss, and other information by inputting the information or by voice (by the user's own action) (S22).

[0044] The automatic response system 300 transmits the telephone number, the date and time of loss, and other information to the payment server 100 (S23). The loss event processing unit 140 of the payment server 100 simultaneously logs out all payment applications 20 (including those logged in via a browser) corresponding to the telephone number (S24). At this time, the loss event processing unit 140 changes the login information flag of the user information 172 corresponding to the payment application 20 corresponding to the telephone number to flag information indicating "login restricted" rather than "logged out." The loss event processing unit 140 then issues a temporary password (temp. pw in the figure), associates it with the telephone number, the date and time of loss, and other information, and registers and stores it in the temporary password association information 176 (S25). The loss event processing unit 140 transmits the temporary password to the automatic response system 300 (S26), and the automatic response system 300 communicates the temporary password to the telephone 80 by voice or the like, and contacts the user U (S27).

[0045] If the user terminal device 10 is subsequently found, the user U, who has memorized or saved the temporary password as a memo, performs an operation to resume login to the electronic payment service using the user terminal device 10. First, the user U opens the non-login screen of the payment application 20 and enters a phone number and a password (S30). This password is the same as that described with reference to FIG. 3 and is different from the temporary password. The payment application 20 transmits the entered phone number and password to the payment server 100 (S31). The resumption processing unit 150 of the payment server 100 compares the phone number and password with the information registered in the user information 172 (S32). Here, it is assumed that the comparison is successful. Alternatively, a login request linked to another service may be made. When a login request linked to another service is made, the information transmitted in S30 to S31 is login information for the other service (e.g., user identification information such as an account name or a username, and a password). In this case, the payment server 100 compares the user by sharing information with the other linked service (S32).

[0046] If the verification is successful, the restart processing unit 150 refers to the login status flag of the user information 172, and if the login status flag is set to "login restricted," it sends information requesting a temporary password to the payment application 20 (S33). The payment application 20 displays a screen for entering a temporary password and accepts the entry of the temporary password (S34). The payment application 20 sends the entered temporary password to the payment server 100 (S35). When the temporary password is acquired from the payment application 20 and entered, the restart processing unit 150 verifies the entered temporary password with the temporary password stored in the storage unit 170 (registered in the temporary password correspondence information 176) (S36). If they match, the restart processing unit 150 changes the login status flag to "logged in" and sends a login permission notification to the payment application 20, putting the payment application 20 into a logged-in state (S37). When verifying the temporary password, the telephone number associated with payment application 20, which is the destination of the processes in S30 to S35, is used to obtain the corresponding temporary password from temporary password correspondence information 176. This telephone number is recognized through communication with payment application 20 and is known to payment server 100.

[0047] If the entered temporary password does not match the temporary password registered in the temporary password correspondence information 176, up to n errors are allowed, but if more than n errors occur, the temporary password will be invalidated. FIG. 11 is a diagram showing an example of a temporary password input screen. When the user enters the temporary password in area A1 and operates button B1, the temporary password is sent to the payment server 100. When link L1 is operated, for example, a telephone number for requesting temporary password reissue is displayed. The left diagram of FIG. 11 shows the input screen when the number of errors is k or less (n>k), and the right diagram of FIG. 11 shows the input screen when the number of errors is more than k but not more than n. For example, n is set to a value of approximately 10 and k is set to a value of approximately 5. As shown in the figure, if the number of errors exceeds k, the number of remaining errors before the temporary password is invalid is displayed.

[0048] If user U has memorized the temporary password or saved it in a memo or the like, the process for re-login is completed by the process in the flowchart of Fig. 10. On the other hand, if user U has not memorized or saved the temporary password in a memo or the like (if the user has forgotten it), or if the user has entered the wrong temporary password more than n times, the user must call a specified phone number (which may be the same phone number as when the password was lost, or a different phone number) and request (ask) that the automatic answering system 300 reissue the temporary password.

[0049] FIG. 12 is a sequence diagram showing an example of the processing flow for requesting reissue of a temporary password. The processing of S20 to S27 will not be illustrated or described again. First, user U notifies the automatic answering system 300 that he / she requests reissue of a temporary password (S40). This notification is an example of "user action." Here, it is assumed that the lost user terminal device 10 has been found, and therefore user U is to call a predetermined telephone number using the found user terminal device 10.

[0050] The automatic response system 300 transmits to the payment server 100 a notification that a temporary password reissue request has been made (S41). The restart processing unit 150 of the payment server 100 executes processing to confirm whether the user terminal device 10 that has made the temporary password reissue request is the same as the lost user terminal device 10 (S42). For example, the restart processing unit 150 performs SMS authentication. That is, the restart processing unit 150 sends a short message to the phone number registered in the user information 172, and when the PIN number included in the short message is entered into the payment application 20 or the URL included in the short message is operated, it determines that the user terminal device 10 that has made the temporary password reissue request is the same as the lost user terminal device 10. The "processing to confirm whether they are the same" is not limited to this, and any processing may be performed.

[0051] If it is determined that the user terminal device 10 that requested the reissue of the temporary password is the same as the lost user terminal device 10, the restart processing unit 150 requests the automatic answering system 300 to verify the user's identity and accepts input of identity verification information from the automatic answering system 300 (S43). The automatic answering system 300 requests the user U to input identity verification information (S44). The identity verification information required is more detailed information than that required when notifying the user of the loss, such as a telephone number, name, date of birth, postal code, address, email address, and secret password. In response, the user U contacts the automatic answering system 300 with the identity verification information by inputting the information or by voice (S45).

[0052] The automated response system 300 transmits the personal identification information to the payment server 100 (S46). The restart processing unit 150 of the payment server 100 compares the acquired (input) personal identification information with the user's previously acquired personal information, i.e., the information registered as user information 172 (S47). If they match, the restart processing unit 150 reissues a temporary password and associates the reissued temporary password with the phone number, the date and time of loss, and other information, and registers and stores the temporary password in the temporary password correspondence information 176 (S48). Note that "matching" may mean a perfect match or may include only differences that are considered to be identical, such as differences between old and new character styles. The restart processing unit 150 transmits the reissued temporary password to the automated response system 300 (S49). The automated response system 300 then communicates the temporary password to the user terminal device 10 by voice or other means, and contacts the user U (S50).

[0053] The processing entity of S40 to S48 may be loss processing unit 140. If it is not specified that the found user terminal device 10 should be used to make a call to a predetermined phone number, the terminal confirmation process of S42 may include a process of requesting that some information for identifying the user terminal device 10 be sent to payment server 100 (for example, this may be achieved by performing some operation on payment application 20 in a logged-out state).

[0054] For login management in the event of loss, a call center staffed by an operator may be used instead of the automatic response system 300. FIG. 13 is a diagram showing another example of the configuration and surrounding environment for login management in the event of loss performed by the payment server 100. A telephone 410 and a CS terminal 420 are installed in the call center 400. An operator OP answers telephone calls made to the telephone 410 corresponding to a predetermined telephone number, and asks questions similar to those asked by the automatic response system 300. The operator OP then inputs the answers, requests, and contents of the requests of the user U into the CS terminal 420. The CS terminal 420 transmits the input contents to the payment server 100.

[0055] In the configuration shown in Figure 8 or Figure 13, each of the loss processing unit 140 and the restart processing unit 150 of the payment server 100 acquires the voice uttered by the user U from the automatic response system 300 or the call center 400, and the restart processing unit 150 may allow login of an account that is currently under login restriction, on the further condition that the voice acquired by the loss processing unit 140 and the voice acquired by the restart processing unit 150 are determined to be the voice of the same person by voiceprint analysis or the like.

[0056] According to the embodiment described above, it is possible to suitably manage the login status when a terminal device is lost.

[0057] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]

[0058] E. Store Facilities M medium S payment system 10 User terminal device 20. Payment App 30 Store payment terminals 40 Store code image 60 Payment Cards 70 Credit card processing terminal 80 telephone 100 Payment Server 130 Payment processing unit 140 Lost item handling unit 150 Restart processing unit 170 Storage section 172 User information 176 Temporary Password Support Information 200 Credit Card Server 300 Auto Response System 400 Call Center

Claims

1. A service providing device that provides a network service via an application program that runs on a terminal device that is a mobile phone, a loss processing unit that, in response to a notification that the terminal device has been lost, puts the application program into a logout state, issues a temporary password, and stores the telephone number of the terminal device and the temporary password in a storage unit in association with each other; a restart processing unit that, when the temporary password is input, puts the application program into a login state if the input temporary password matches the temporary password stored in the storage unit; A service providing device comprising:

2. the loss event processing unit acquires a telephone number of the terminal device together with a notification that the terminal device has been lost; The service providing device according to claim 1.

3. the loss event processing unit acquires a notification that the terminal device has been lost and the telephone number of the terminal device based on an action taken by a user to an automated answering system that responds to telephone calls made to a predetermined telephone number; The service providing device according to claim 2.

4. the restart processing unit executes a process of confirming that the other party of the telephone call made to the predetermined telephone number is the lost terminal device in response to an action by the user made to an automatic answering system that handles telephone calls made to the predetermined telephone number. The service providing device according to claim 1.

5. the restart processing unit, when it is confirmed that the terminal device is the lost terminal device, accepts an input for identity verification to the automatic answering system, and when the content of the input for identity verification matches the personal information of the user that has been acquired in advance, requests the input of the temporary password. The service providing device according to claim 4.

6. the restart processing unit detects that the user's action is an action to request reissue of the temporary password, 6. The service providing device according to claim 4 or 5.

7. the restart processing unit accepts input for identity verification when it is confirmed that the destination of a telephone call made to a predetermined telephone number is the lost terminal device, and requests input of the temporary password when the content of the input for identity verification matches the personal information of the user that has been acquired in advance; The service providing device according to claim 1.

8. the loss event processing unit receives a notification from a user that the terminal device has been lost, the restart processing unit acquires the user's voice when acquiring the temporary password, and when it is determined that the voice acquired by the loss processing unit and the voice acquired by the restart processing unit are the same person's voice, puts the application program into a login state. The service providing device according to claim 1.

9. A service providing device that provides a network service via an application program that runs on a terminal device that is a mobile phone, a process of putting the application program into a logout state, issuing a temporary password, and storing the telephone number of the terminal device and the temporary password in a storage unit in association with each other in response to a notification that the terminal device has been lost; a process of putting the application program into a login state when the input temporary password matches the temporary password stored in the storage unit; Management method to carry out.

10. A processor of a service providing device that provides a network service via an application program running on a terminal device that is a mobile phone, a process of putting the application program into a logout state, issuing a temporary password, and storing the telephone number of the terminal device and the temporary password in a storage unit in association with each other in response to a notification that the terminal device has been lost; a process of putting the application program into a login state when the input temporary password matches the temporary password stored in the storage unit; A program to execute.

Citation Information

Patent Citations

  • Mobile communication apparatus, and apparatus, method and program for managing mobile communication apparatus

    JP2004260345A

  • Method and system for financial transaction in mobile environment

    JP2015062125A

  • Using a non-browser based application for mobile banking

    US20250200550A1

  • Systems and methods for trustworthy electronic authentication using a computing device

    WO2023091982A1

  • Secret-key management simplifying system

    JP2023102725A