Fraud risk management system for electronic payment and bank account binding based on sim card change and method thereof

The system addresses SIM card anomaly-induced fraud in electronic payments by querying SIM card change status to prevent unauthorized account bindings, thereby improving security and reducing fraud in electronic payment systems.

TWI932425BActive Publication Date: 2026-07-11TAIWAN BUSINESS BANK
0 Cites 0 Cited by

Patent Information

Application Number
TW114139138
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2026-07-11
Estimated Expiration
2045-10-08

AI Technical Summary

Technical Problem

Existing electronic payment systems are vulnerable to fraud due to SIM card anomalies, as traditional verification mechanisms like one-time passwords cannot effectively detect SIM card tampering, allowing fraudsters to bypass security checks and perform unauthorized bank account bindings.

Method used

An electronic payment bank binding fraud risk control system that utilizes SIM card anomaly information to query SIM card change status through a telecommunications server, generating a binding termination response when a physical SIM card replacement occurs within a preset period, thereby preventing unauthorized account bindings.

Benefits of technology

Enhances security in electronic payment systems by reducing fraud risks and protecting user funds through real-time detection and prevention of fraudulent SIM card-based account bindings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMG-2_DRAW_114139138-A0305-14-0001-1
    Figure IMG-2_DRAW_114139138-A0305-14-0001-1
  • Figure IMG-2_DRAW_114139138-A0305-14-0002-2
    Figure IMG-2_DRAW_114139138-A0305-14-0002-2
  • Figure IMG-2_DRAW_114139138-A0305-14-0003-3
    Figure IMG-2_DRAW_114139138-A0305-14-0003-3
Patent Text Reader

Abstract

A system and method for controlling the risk of fraud in electronic payment and banking binding based on SIM card anomalies are disclosed. The system queries SIM card anomaly information from the telecommunications server through the mobile banking server and generates a binding termination response when the anomaly timestamp falls within a preset period and the physical SIM card has been replaced. This prevents fraud groups from using SIM card anomalies to conduct unauthorized binding, thereby achieving the technical effect of improving the security of electronic payment and banking binding, reducing the risk of fraud, and protecting the user's funds.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an electronic payment bank binding fraud risk control system and method, particularly an electronic payment bank binding fraud risk control system and method based on SIM card anomaly, which is used to detect potential fraud risks through SIM card anomaly information and terminate insecure binding requests. Prior Technology

[0002] In existing electronic payment systems, users typically log into electronic payment apps using their mobile phone numbers and link their bank accounts or other personal accounts to conduct transactions. However, fraud groups often exploit SIM card replacements or changes to steal users' phone numbers and link them to unauthorized banks, resulting in financial losses.

[0003] Traditional verification mechanisms rely solely on one-time passwords (OTPs) or basic identity verification, which cannot effectively detect SIM card tampering. Especially after the physical SIM card is replaced, fraudsters can easily bypass security checks, complete bank account binding, and perform high-risk operations such as money transfers.

[0004] In conclusion, it is clear that previous technologies have long suffered from the problem of difficulty in effectively controlling the risk of fraud related to electronic payment and bank binding caused by SIM card anomalies. Therefore, it is necessary to propose improved technical means to solve this problem. Summary of the Invention

[0005] In view of the problem that prior art has difficulty in effectively controlling the risk of electronic payment bank binding fraud caused by SIM card anomalies, the present invention discloses an electronic payment bank binding fraud risk control system and method based on SIM card anomalies, wherein:

[0006] First, this invention discloses an electronic payment bank binding fraud risk control system based on SIM card anomaly. This system includes: a mobile device and a mobile bank server. The mobile device further includes: a non-transitory computer-readable storage medium and a device hardware processor. The mobile bank server further includes: a non-transitory computer-readable storage medium and a hardware processor.

[0007] The device includes a non-transitory computer-readable storage medium storing an electronic payment app containing multiple first computer-readable instructions and a mobile banking app containing multiple second computer-readable instructions; and a device hardware processor electrically connected to the non-transitory computer-readable storage medium, executing the multiple first computer-readable instructions of the electronic payment app and the multiple second computer-readable instructions of the mobile banking app, causing the mobile device to perform:

[0008] Log in to the e-payment app using your mobile phone number; when the e-payment app triggers a bank account / account binding request, it obtains the bank account or bank account number; the e-payment app launches the mobile banking app through the Inter-App Communication (IAC) mechanism, and then provides the mobile phone number and bank account or bank account number to the mobile banking app; the mobile banking app provides the mobile phone number and bank account or bank account number to the mobile banking server; the mobile banking app obtains the binding termination response from the mobile banking server, and then provides the binding termination response to the e-payment app through the IAC mechanism; and the e-payment app terminates the bank account / account binding request based on the binding termination response.

[0009] A non-transitory computer-readable storage medium storing a plurality of third-party computer-readable instructions; and a hardware processor electrically connected to the non-transitory computer-readable storage medium, executing the third-party computer-readable instructions to cause the mobile banking server to perform:

[0010] The system obtains the mobile phone number and bank account or bank account number from the mobile banking app; provides the mobile phone number to the telecommunications server through the application programming interface (API), and then obtains a user identity module (SIM) card change information from the telecommunications server through the API; and when the change timestamp of the SIM card change information is within a preset period and the SIM card change information is a physical SIM card replacement, it generates and provides a binding termination response to the mobile banking app.

[0011] In addition, this invention discloses a method for controlling the risk of fraud related to electronic payment bank binding based on SIM card anomalies, which includes the following steps:

[0012] First, the mobile device has an e-payment app and a mobile banking app. The e-payment app is executed to log in using a mobile phone number. Next, when the e-payment app triggers a bank account / account binding request, it obtains the bank account or bank account number. Then, the e-payment app launches the mobile banking app via the IAC mechanism. Next, the e-payment app provides the mobile phone number and bank account or bank account number to the mobile banking app. Next, the mobile banking app provides the mobile phone number and bank account or bank account number to the mobile banking server. Next, the mobile banking server provides the mobile phone number to the telecom server via API. Next, the mobile banking server obtains SIM card change information from the telecom server via API. Next, when the timestamp of the SIM card change information is within a preset period and the SIM card change information indicates a physical SIM card replacement, the mobile banking server generates a binding termination response. Next, the mobile banking server provides the binding termination response to the mobile banking app. Next, the mobile banking app provides the binding termination response to the e-payment app via the IAC mechanism. Finally, the e-payment app terminates the bank account / account binding request based on the binding termination response.

[0013] The system and method disclosed in this invention are as described above. They query SIM card change information from the telecommunications server through the mobile banking server, and generate a binding termination response when the change timestamp falls within a preset period and the physical SIM card has been replaced, in order to prevent fraud groups from using SIM card changes to conduct unauthorized binding.

[0014] Through the aforementioned technical means, this invention can achieve the technical effect of improving the security of electronic payment bank binding, reducing the risk of fraud, and protecting the user's funds. Simple Explanation of the Diagram

[0015] Figure 1 is a system block diagram of the electronic payment bank binding fraud risk control system based on SIM card anomaly according to the present invention. Figure 2 is a schematic diagram of the bank account / account number input page of the electronic payment bank binding fraud risk control system based on SIM card anomaly according to the present invention. Figure 3 is a schematic diagram of the binding request termination dialog window of the electronic payment bank binding fraud risk control system based on SIM card anomaly according to the present invention. Figure 4 is a schematic diagram of the verification pass dialog window of the electronic payment bank binding fraud risk control system based on SIM card anomaly according to the present invention. Figures 5A and 5B are flowcharts of the method for electronic payment bank binding fraud risk control based on SIM card anomaly according to the present invention. Implementation

[0016] The following will describe the implementation of the present invention in detail with reference to the drawings and embodiments, so that the process of how the present invention uses technical means to solve technical problems and achieve technical effects can be fully understood and implemented accordingly.

[0017] The following will first describe the electronic payment bank binding fraud risk control system based on SIM card anomaly disclosed in this invention, and please refer to "Figure 1", which is a system block diagram of the electronic payment bank binding fraud risk control system based on SIM card anomaly of this invention.

[0018] First, this invention discloses an electronic payment bank binding fraud risk control system based on SIM card anomaly. This system includes: a mobile device 10, a mobile bank server 20, and a telecommunications server 30. The mobile device 10 further includes: a non-transitory computer-readable storage medium 11 and a device hardware processor 12; the mobile bank server 20 further includes: a non-transitory computer-readable storage medium 21 and a hardware processor 22.

[0019] Mobile device 10 establishes a connection with mobile banking server 20 via wireless transmission, and mobile banking server 20 establishes a connection with telecommunications server 30 via wired or wireless transmission. The aforementioned wired transmission methods include, for example, cable networks, fiber optic networks, etc., and the aforementioned wireless transmission methods include, for example, Wi-Fi, mobile communication networks (e.g., 4G, 5G, etc.). These are merely examples and are not intended to limit the scope of application of the present invention.

[0020] The mobile device 10's device non-transitory computer-readable storage medium 11 stores an electronic payment app 111 containing multiple first computer-readable instructions and a mobile banking app 112 containing multiple second computer-readable instructions. The mobile device 10's device hardware processor 12 is electrically connected to the device non-transitory computer-readable storage medium 11, and executes the multiple first computer-readable instructions of the electronic payment app and the multiple second computer-readable instructions of the mobile banking app, causing the mobile device 10 to perform:

[0021] Users log in to the electronic payment APP 111 using their mobile phone number. That is, the electronic payment APP 111 receives the mobile phone number and uses one-time password technology to achieve the purpose of logging into the electronic payment APP 111 using the mobile phone number. This is only an example and is not intended to limit the application scope of the present invention.

[0022] Next, when the user triggers the bank account / account binding request of the electronic payment APP 111, the electronic payment APP 111 provides a bank account / account input page 41. For a schematic diagram of the bank account / account input page 41, please refer to "Figure 2". "Figure 2" is a schematic diagram of the bank account / account input page of the present invention for fraud risk control of electronic payment bank binding based on SIM card anomaly. The user can enter the bank account or bank account number in the bank account / account input field 411 of the bank account / account input page 41, and the electronic payment APP 111 can obtain the bank account or bank account number from the bank account / account input page 41.

[0023] After the electronic payment app 111 obtains a bank account or bank account number, it launches the mobile banking app 112 through the Inter-App Communication (IAC) mechanism provided by the operating system of the mobile device 10. It's worth noting that if the mobile device 10's operating system is Android, Android uses Intent objects to carry actions, data URIs, extras, etc., to enable the electronic payment app 111 to launch the mobile banking app 112 via the IAC mechanism. That is, the electronic payment app 111 uses Intent objects to carry a specified launch action for the mobile banking app 112 to launch the mobile banking app 112. If the mobile device 10's operating system is iOS, iOS uses a custom URL scheme (e.g., myapp: / / action?param=value) to allow the electronic payment app 111 to call the mobile banking app 112. The electronic payment app 111 and the mobile banking app 112 need to agree on the URL format, and the mobile banking app... 112 The Scheme must be registered. This is only an example and is not intended to limit the scope of application of the present invention.

[0024] After the electronic payment app 111 launches the mobile banking app 112 via the IAC mechanism, the electronic payment app 111 still provides the mobile phone number and bank account or bank account number to the mobile banking app 112 via the IAC mechanism. It is worth noting that if the mobile device 10's operating system is Android, Android carries the mobile phone number and bank account or bank account number information through the message object Intent, so that the electronic payment app 111 can provide the mobile phone number and bank account or bank account number to the mobile banking app 112 via the IAC mechanism. If the mobile device 10's operating system is iOS, iOS uses the App Extension mechanism to enable the electronic payment app 111 to share the mobile phone number and bank account or bank account number to the mobile banking app 112 in specific situations, so that the electronic payment app 111 can provide the mobile phone number and bank account or bank account number to the mobile banking app 112 via the IAC mechanism. This is only an example for illustration and does not limit the application scope of the present invention.

[0025] After the electronic payment APP 111 provides the mobile phone number and bank account or bank account number to the mobile banking APP 112 through the IAC mechanism, the mobile banking APP 112 provides the mobile phone number and bank account or bank account number to the mobile banking server 20.

[0026] After the mobile banking app 112 receives the binding termination response from the mobile banking server 20, the mobile banking app 112 then provides the binding termination response to the electronic payment app 111 through the IAC mechanism. Next, the electronic payment app 111 terminates the bank account / account binding request based on the binding termination response, and the electronic payment app 111 displays the binding termination response in the binding request termination dialog window 42. For a schematic diagram of the binding request termination dialog window 42, please refer to "Figure 3". "Figure 3" is a schematic diagram of the binding request termination dialog window for the electronic payment bank binding fraud risk control based on SIM card anomaly according to the present invention. In "Figure 3", the binding termination response is presented in the form of a dialog window. In addition, the binding termination response can also be presented in the form of a page or a toast. This is only an example for illustration and does not limit the application scope of the present invention.

[0027] It is worth noting that when the mobile banking app 112 receives a response to the termination of account binding, it further restricts or prohibits high-risk operations and settings such as non-agreed transfers, password changes, and data changes to bank accounts or bank account numbers, providing further fraud prevention.

[0028] It is worth noting that after the mobile banking APP 112 receives the verification response from the mobile banking server 20, the mobile banking APP 112 then provides the verification response to the electronic payment APP 111 through the IAC mechanism. Then, the electronic payment APP 111 can proceed with the subsequent binding process of mobile phone number and bank account or bank account number. The electronic payment APP 111 displays the verification response in the verification dialog window 43. For a schematic diagram of the verification dialog window 43, please refer to "Figure 4". "Figure 4" is a schematic diagram of the verification dialog window for the electronic payment bank binding fraud risk control based on SIM card anomaly according to the present invention. In "Figure 4", the verification response is presented in the form of a dialog window. In addition, the verification response can also be presented in the form of a page or a toast. This is only an example for illustration and does not limit the application scope of the present invention.

[0029] The mobile banking server 20 has a non-transitory computer-readable storage medium 21 storing a plurality of third-party computer-readable instructions; and a hardware processor 22 of the mobile banking server 20, electrically connected to the non-transitory computer-readable storage medium 21, executing the third-party computer-readable instructions to cause the mobile banking server 20 to perform:

[0030] After obtaining the mobile phone number and bank account or bank account number from the mobile banking APP 112, the mobile banking server 20 provides the mobile phone number to the telecommunications server 30 through the Application Programming Interface (API). The mobile banking server 20 then obtains the Subscriber Identity Module (SIM) change information from the telecommunications server 30 via the API. It is worth noting that when the mobile banking server 20 communicates with the telecommunications server 30 through the API, it also includes performing mutual authentication and encrypted transmission protocols. The purpose is to prevent man-in-the-middle (MIT) attacks, data theft, and forged requests. The aforementioned mutual authentication means that both the mobile banking server 20 and the telecommunications server 30 must prove their identities to each other, rather than it being a one-way process of the mobile banking server 20 proving its identity to the telecommunications server 30 or vice versa. Mutual authentication is achieved through digital credentials. The encrypted transmission protocol ensures that the data transmitted between the mobile banking server 20 and the telecommunications server 30 cannot be eavesdropped or tampered with. The common protocol is TLS (Transport Layer Security), which is only used as an example and is not intended to limit the application scope of this invention.

[0031] The telecommunications server 30 records information such as SIM card change status, SIM card change date and time, mobile number status, number portability status, and user basic information. After the telecommunications server 30 obtains the mobile number from the mobile banking server 20 via API, the telecommunications server 30 can query the information recorded for the mobile number on the telecommunications server 30 and generate corresponding SIM card change information. The SIM card change information includes the SIM card change status (e.g., physical SIM card replacement, eSIM application, etc., which are only examples and do not limit the scope of application of this invention) and the change timestamp (i.e., SIM card change date and time). The SIM card change information is fed back to the mobile banking server 20 via API. It is worth noting that the telecommunications server 30 also includes setting a fraud risk warning for the mobile number when it receives a binding termination response from the mobile banking server 20 via API, thus achieving further fraud prevention.

[0032] When the mobile banking server 20 receives SIM card anomaly information from the telecom server 30 via API, the mobile banking server 20 determines whether the timestamp of the SIM card anomaly information falls within a preset period range. Specifically, assuming the system time of the mobile banking server 20 is "2025 / 09 / 06 / 08", and assuming the timestamp of the SIM card anomaly information is "2025 / 09 / 05 / 12", the preset period range is the period before the system time. Three days after the system time, i.e., the preset period range is from "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08", the mobile banking server 20 can determine that the SIM card change information change timestamp "2025 / 09 / 05 / 12" falls within the preset period range of "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08". This is only an example for illustration and does not limit the application scope of the present invention. In the case of SIM card change information being a physical SIM card replacement, the mobile banking server 20 will generate a binding termination response and then provide the binding termination response to the mobile banking APP 112 through the API.

[0033] It is worth noting that, assuming the system time of the mobile banking server 20 is "2025 / 09 / 06 / 08", and assuming the timestamp of the SIM card change information is "2024 / 09 / 05 / 12", the default period range is three days prior to the system time, i.e., the default period range is "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08". The mobile banking server 20 can then determine that the timestamp of the SIM card change information, "2024 / 09 / 05 / 12", does not fall within the default period range of "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08". Even though the SIM card change information indicates a physical SIM card replacement, the mobile banking server 20 will not generate a binding termination response but will instead generate a verification pass response, and then provide the verification pass response to the mobile banking app via API. 112 is merely an example and is not intended to limit the scope of application of this invention.

[0034] It is worth noting that, assuming the system time of the mobile banking server 20 is "2025 / 09 / 06 / 08", and assuming the timestamp of the SIM card change information is "2025 / 09 / 05 / 12", the default period range is three days prior to the system time, i.e., the default period range is "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08". The mobile banking server 20 can then determine that the timestamp of the SIM card change information "2025 / 09 / 05 / 12" falls within the default period range of "2025 / 09 / 03 / 08" to "2025 / 09 / 03 / 08". However, if the SIM card change information pertains to an eSIM application, the mobile banking server 20 will not generate a binding termination response but will instead generate a verification pass response, and then provide the verification pass response to the mobile banking app via API. 112 is merely an example and is not intended to limit the scope of application of this invention.

[0035] It is worth noting that the mobile banking server 20 obtains SIM card anomaly information from the telecom server 30 via API, including the telecom operator identification code and SIM card replacement location information. The mobile banking server 20 can further utilize this information for fraud prevention. Specifically, the mobile banking server 20 can compare the telecom company information provided during registration with the telecom operator identification code of the current SIM card. If the comparison is inconsistent, high-risk behavior is identified, and relevant fraud alert mechanisms are activated. Furthermore, the mobile banking server 20 analyzes the frequency of SIM card anomalies and the incidence of fraud cases for different telecom operators. This allows the mobile banking server 20 to conduct stricter reviews of transactions by users of that telecom operator and activate relevant fraud alert mechanisms. The mobile banking server 20 also compares the SIM card replacement location information with the user's frequently used login locations (e.g., IP address or GPS). The location is compared. If the user usually logs in in Taipei, but the SIM card is replaced at a store in Kaohsiung, it is obviously a high-risk behavior and the relevant fraud warning mechanism is activated. The mobile banking server 20 sets a location blacklist. When the abnormal location of the SIM card is located in a location on the blacklist, the relevant fraud warning mechanism is activated. This is only an example and does not limit the application scope of the present invention.

[0036] The mobile banking server 20 further includes a feature where, when the timestamp of the SIM card change information is not within a preset period, or when the timestamp of the SIM card change information is within a preset period and the SIM card change information is not related to a physical SIM card replacement, the mobile banking server 20 further confirms via API from the risk sharing server 60 whether the mobile number has been requested to terminate its binding by another bank within a preset period. If so, the mobile banking server 20 generates and provides a binding termination response to the mobile banking app 112, and the mobile banking app 112 then provides a binding termination response to the e-payment app 111 via the IAC mechanism. The e-payment app 111 terminates the bank account / account binding request based on the binding termination response.

[0037] The mobile banking server 20 further includes a feature where, when the timestamp of the SIM card change information falls within a preset period and the SIM card change information indicates a physical SIM card replacement, the mobile banking server 20 selects at least two of the following methods—graphical verification, OTP verification, facial verification, and fingerprint verification—and provides them to the mobile device 10. The mobile banking app 112 then executes the selected verification combination. Upon successful verification, the mobile banking app 112 generates a verification success response and provides it to the electronic payment app 111 via the IAC mechanism. The electronic payment app 111 can then proceed with the subsequent binding process of the mobile phone number and bank account or bank account number. Conversely, if verification fails, the mobile banking app 112 generates a binding termination response and provides it to the electronic payment app 111 via the IAC mechanism. The electronic payment app 111 then terminates the bank account / account binding request based on the binding termination response.

[0038] The mobile banking server 20 further includes a feature where, when the timestamp of the SIM card change information falls within a preset period and the SIM card change information indicates a physical SIM card replacement, the mobile banking server 20 calculates a risk score based on the SIM card change information, the user's login IP address, device fingerprint, and recent transaction behavior. Based on the risk score, it then selects at least two of the following methods—graphical verification, OTP verification, facial verification, and fingerprint verification—and provides them to the mobile device 10: Specifically, assuming that the risk score range for graphical verification is 50 to 80, and the risk score range for OTP verification is 50 to... 80. Face verification can be selected with a corresponding risk score range of 60 to 80, and fingerprint verification can be selected with a corresponding risk score range of 70 to 80. When the risk score is "50", a combination of image verification and OTP verification can be provided to the mobile device 10. When the risk score is "65", at least two of the following methods can be provided to the mobile device 10: image verification, OTP verification, and face verification. When the risk score is "70", at least two of the following methods can be provided to the mobile device 10: image verification, OTP verification, face verification, and fingerprint verification. This enables the mobile banking APP to... 112 executes the selected verification combination for verification. If the verification is successful, the mobile banking app 112 generates a verification success response. The mobile banking app 112 then provides the verification success response to the e-payment app 111 through the IAC mechanism. The e-payment app 111 can then proceed with the subsequent binding process of mobile phone number and bank account or bank account number. If the verification fails, the mobile banking app 112 generates a binding termination response. The mobile banking app 112 then provides the binding termination response to the e-payment app 111 through the IAC mechanism. The e-payment app 111 terminates the bank account / account number binding request based on the binding termination response.

[0039] It is particularly noted that, in practical implementation, the invention may be implemented on the basis of partly or completely on hardware, for example, one or more components in the system may be implemented through an integrated circuit chip, System on Chip (SoC), Complex Programmable Logic Device (CPLD), Field Programmable Gate Array (FPGA) and other hardware processors (FPGAs). The non-transient computer-readable storage media of the invention, which uploads computer-readable instructions (or referred to as computer program instructions) for enabling the processor to implement various aspects of the invention, the non-transient computer-readable storage media may be a tangible device that can hold and store instructions used by the command execution equipment. Non-transient computer-readable storage media may be, but are not limited to, electrical storage equipment, magnetic storage equipment, optical storage equipment, electromagnetic storage equipment, semiconductor storage equipment, or any suitable combination of the above. More specific examples of computer-readable storage media (a nonexhaustive list) include: hard drives, random access memory, read-only memory, flash memory, optical discs, floppy disks, and any suitable combination of the above. The non-transient computer-readable storage media used here are not interpreted as instantaneous signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., optical signals via fiber optic cables), or electrical signals transmitted through wires. In addition, the computer-readable commands described here can be downloaded to various computing / processing equipment from non-transient computer-readable storage media, or to external computer equipment or external storage equipment via a network, such as: an Internet, LAN, WAN, and / or wireless network. The network may include copper transmission cables, fiber optic transmissions, wireless transmissions, routers, firewalls, switches, hubs and / or gateways. The network card or network interface in each of the computing / processing equipment receives computer-readable instructions from the network and forwards these computer-readable instructions for the non-transient computer-readable storage media stored in the respective computing / processing equipment. A computer-readable instruction performing the operations of the present invention may be a combination language instruction, an instruction set architecture instruction, a machine instruction, a machine-related instruction, a microinstruction, a firmware instruction, or a source or object code (Object Code) written in any combination of one or more programming languages, including object-oriented programming languages, such as Common Lisp, Python, C++, Objective-C, Smalltalk, Delphi, Java, Swift, C#, Perl, Ruby and PHP, etc., as well as conventional procedural (Procedural) programming languages, such as C language or similar programming languages.

[0040] Next, the operation method of the present invention will be described below, and please refer to Figures 5A and 5B. Figures 5A and 5B are flowcharts of the method for controlling the risk of fraud in electronic payment bank binding based on SIM card anomalies according to the present invention.

[0041] This invention discloses a method for controlling the risk of fraud related to electronic payment bank binding based on SIM card anomalies, which includes the following steps:

[0042] First, the mobile device has an e-payment app and a mobile banking app. The e-payment app is executed to log in using the mobile phone number (step 501). Next, when the e-payment app triggers a bank account / account binding request, it obtains the bank account or bank account number (step 502). Next, the e-payment app launches the mobile banking app through the IAC mechanism (step 503). Next, the e-payment app provides the mobile phone number and bank account or bank account number to the mobile banking app (step 504). Next, the mobile banking app provides the mobile phone number and bank account or bank account number to the mobile banking server (step 505). Next, the mobile banking server provides the mobile phone number to the mobile banking app via API. The mobile banking server then obtains the SIM card change information from the telecom server via API (step 507); next, when the change timestamp of the SIM card change information is within a preset period and the SIM card change status is a physical SIM card replacement, the mobile banking server generates a binding termination response (step 508); next, the mobile banking server provides the binding termination response to the mobile banking APP (step 509); next, the mobile banking APP provides the binding termination response to the e-payment APP via the IAC mechanism (step 510); and the e-payment APP terminates the bank account / account binding request based on the binding termination response (step 511).

[0043] In summary, by querying SIM card change information from the telecom server through the mobile banking server, and generating a binding termination response when the change timestamp falls within a preset period and the physical SIM card has been replaced, fraud groups can prevent unauthorized binding by using SIM card changes.

[0044] This technology can solve the problem of difficulty in effectively controlling the risk of fraud in electronic payment and bank binding caused by SIM card anomalies in previous technologies, thereby improving the security of electronic payment and bank binding, reducing the risk of fraud and protecting users' funds.

[0045] While the embodiments disclosed in this invention are as described above, the content is not intended to directly limit the scope of patent protection for this invention. Anyone skilled in the art to which this invention pertains may make minor modifications in form and detail without departing from the spirit and scope disclosed herein. The scope of patent protection for this invention shall still be determined by the appended claims.

[0046] 10: Mobile Devices 11: Device non-transitory computer-readable storage medium 111: Electronic Payment App 112: Mobile Banking App 12: Device Hardware Processor 20: Mobile Banking Server 21: Non-transitory computer-readable storage media 22: Hardware Processor 30: Telecom Server 41: Bank Account / Number Input Page 411: Bank Account / Number Input Field 42: Binding Request Termination Dialog Box 43: Verification passed in the dialog box 60: Risk-sharing server Step 501: The mobile device has an electronic payment app and a mobile banking app. The electronic payment app is executed to log in using the mobile phone number. Step 502: When the electronic payment APP triggers a bank account / account binding request, it then obtains the bank account or bank number. Step 503: The electronic payment app launches the mobile banking app via the IAC mechanism. Step 504: The e-payment app provides the mobile phone number and bank account or bank account number to the mobile banking app. Step 505: The mobile banking app provides the mobile phone number and bank account or bank account number to the mobile banking server. Step 506: The mobile banking server provides the mobile phone number to the telecom server via API. Step 507: The mobile banking server obtains SIM card anomaly information from the telecom server via API. Step 508: When the timestamp of the SIM card change information is within a preset period and the SIM card change status is physical SIM card replacement, the mobile banking server generates a binding termination response. Step 509: The mobile banking server provides a binding termination response to the mobile banking app. Step 510: The mobile banking app provides a termination response to the e-payment app via the IAC mechanism. Step 511: The electronic payment app responds to the request to terminate the binding of the bank account / account based on the termination of binding.

Claims

1. A risk control system for electronic payment bank binding fraud based on SIM card anomaly, the system comprising: a mobile device, the mobile device further comprising: a device non-transitory computer-readable storage medium storing an electronic payment APP containing a plurality of first computer-readable instructions and a mobile banking APP containing a plurality of second computer-readable instructions; and a device hardware processor electrically connected to the device non-transitory computer-readable storage medium, executing the plurality of first computer-readable instructions of the electronic payment APP and the plurality of second computer-readable instructions of the mobile banking APP, causing the mobile device to perform: logging into the electronic payment APP using a mobile phone number; obtaining a bank account or a bank account number when the electronic payment APP triggers a bank account / account binding request; launching the mobile banking APP through an inter-application communication (IAC) mechanism and providing the mobile phone number and the bank account or the bank account number to the mobile banking APP; and the mobile banking APP providing the mobile phone number and the bank account or the bank account number to a mobile banking server. The mobile banking app receives a binding termination response from the mobile banking server and then provides the binding termination response to the electronic payment app through an IAC mechanism; and the electronic payment app terminates the bank account / account binding request based on the binding termination response; the mobile banking server further includes: a non-transitory computer-readable storage medium storing a plurality of third-party computer-readable instructions; and a hardware processor electrically connected to the non-transitory computer-readable storage medium, executing the third-party computer-readable instructions to cause the mobile banking server to perform: obtaining the mobile phone number and the bank account or the bank account number from the mobile banking app; providing the mobile phone number to a telecommunications server through an application programming interface (API), and then obtaining a user identity module (SIM) card change information from the telecommunications server through the API; and generating and providing the binding termination response to the mobile banking app when the change timestamp of the SIM card change information is within a preset period range and the SIM card change status of the SIM card change information is a physical SIM card replacement.

2. The electronic payment bank binding fraud risk control system based on SIM card anomaly as described in claim 1, wherein when the mobile banking server communicates with the telecommunications server through the API, it further includes executing a two-way authentication and encrypted transmission protocol, and the mobile banking server obtains the SIM card anomaly information from the telecommunications server through the API, which further includes the telecommunications operator identification code and card replacement location information to provide the mobile banking server with further fraud prevention.

3. The electronic payment bank binding fraud risk control system based on SIM card anomaly as described in claim 1, wherein the mobile banking server further includes, when the anomaly timestamp of the SIM card anomaly information is within the preset period range and the SIM card anomaly status of the SIM card anomaly information is physical SIM card replacement, selecting at least two of the following methods—graphical verification, OTP verification, facial verification, and fingerprint verification—and providing them to the mobile device, so that the mobile banking APP executes the selected verification combination for verification, generating a verification success response when verification is successful, and generating a binding termination response when verification fails.

4. The electronic payment bank binding fraud risk control system based on SIM card anomaly as described in Request 1, wherein the mobile banking APP further restricts or prohibits high-risk operations and settings such as non-agreement transfers, password changes, and data anomalies of the bank account or the bank account number upon obtaining the binding termination response.

5. The electronic payment bank binding fraud risk control system based on SIM card anomaly as described in Request 1, wherein the telecommunications server further includes setting a fraud risk warning for the mobile phone number when the binding termination response is obtained from the mobile bank server via the API.

6. A method for risk control of electronic payment bank binding fraud based on SIM card anomaly, comprising the following steps: A mobile device has an electronic payment APP and a mobile banking APP, wherein the electronic payment APP is executed to log in using a mobile phone number; when the electronic payment APP triggers a bank account / account binding request, it obtains a bank account or a bank account number; the electronic payment APP launches the mobile banking APP through an IAC mechanism; the electronic payment APP provides the mobile phone number and the bank account or the bank account number to the mobile banking APP; the mobile banking APP provides the mobile phone number and the bank account or the bank account number to a mobile banking server; the mobile banking server provides the mobile phone number to a telecommunications server through an API; the mobile banking server obtains SIM card anomaly information fed back by the telecommunications server through the API; when the anomaly timestamp of the SIM card anomaly information is within a preset period range and the SIM card anomaly status of the SIM card anomaly information is a physical SIM card replacement, the mobile banking server generates a binding termination response; the mobile banking server provides the binding termination response to the mobile banking APP. The mobile banking app provides the binding termination response to the electronic payment app through the IAC mechanism; and the electronic payment app terminates the bank account / account binding request based on the binding termination response.

7. The method for managing electronic payment bank binding fraud based on SIM card anomaly as described in claim 6, wherein when the mobile banking server communicates with the telecommunications server through the API, it further includes executing a two-way authentication and encrypted transmission protocol, and the mobile banking server obtains the SIM card anomaly information from the telecommunications server through the API, which further includes the telecommunications operator identification code and card replacement location information to provide the mobile banking server with further fraud prevention.

8. The method for managing electronic payment bank binding fraud based on SIM card anomaly as described in claim 6, wherein the mobile banking server further includes, when the timestamp of the SIM card anomaly information is within the preset period range and the SIM card anomaly status of the SIM card anomaly information is a physical SIM card replacement, selecting at least two of the following methods—graphical verification, OTP verification, facial verification, and fingerprint verification—and providing them to the mobile device, so that the mobile banking APP executes the selected verification combination for verification, generating a verification success response when verification is successful, and generating a binding termination response when verification fails.

9. The method for controlling the risk of fraud in electronic payment bank binding based on SIM card anomalies as described in claim 6, wherein the mobile banking APP further restricts or prohibits high-risk operations and settings such as non-agreement transfers, password changes, and data anomalies of the bank account or the bank account number upon obtaining the binding termination response.

10. The method for controlling fraud risks of electronic payment bank binding based on SIM card anomalies as described in claim 6, wherein the telecommunications server further includes setting a fraud risk warning for the mobile phone number when obtaining the binding termination response from the mobile bank server through the API.