首页> 外国专利> System and method for secure credit and debit card transactions using dynamic random CVV2 code to mobile communications device

System and method for secure credit and debit card transactions using dynamic random CVV2 code to mobile communications device

机译:使用动态随机CVV2代码向移动通信设备进行安全的信用卡和借记卡交易的系统和方法

摘要

A method and system for conducting secure credit and debit card transactions between a customer and a merchant. The customer is issued with a pseudorandom security string by a host computer, the security string being sent to the customer's mobile telephone. A cryptographic algorithm running in a SIM card of the mobile telephone performs a hash on the security string or the One Time Code extracted from the security string, a customer PIN and a transaction amount, these last two items being entered by way of a keypad of the mobile telephone. A three-digit response code is generated by the algorithm and then passed to the merchant. The merchant then transmits the response code, transaction amount and a customer account number (card number) to the host computer, where the pseudorandom security string and PIN are retrieved from memory. The host computer then applies the same algorithm to the security string, PIN and transaction amount so as to generate a check code, and if the check code matches the response code transmitted by the merchant, the transaction is authorised. Embodiments of the present invention make use of existing CVV2 security infrastructure, but provide a significantly greater degree of security. Embodiments of the present invention may be used with ordinary face-to-face or telephone transactions, and also in e-commerce (web-based) and m-commerce (mobile telephone-based) transactions.
机译:一种用于在顾客和商人之间进行安全的信用卡和借记卡交易的方法和系统。主机向客户发出伪随机安全字符串,该安全字符串被发送到客户的移动电话。在移动电话的SIM卡中运行的加密算法对安全字符串或从安全字符串中提取的一次性代码,客户PIN和交易金额执行哈希运算,后两项通过键盘输入。移动电话。该算法生成一个三位数的响应代码,然后将其传递给商家。然后,商人将响应代码,交易金额和客户帐号(卡号)发送到主机,从内存中检索伪随机安全字符串和PIN。然后,主计算机对安全字符串,PIN和交易金额应用相同的算法,以生成支票代码,并且如果该支票代码与商人发送的响应代码匹配,则该交易被授权。本发明的实施例利用现有的CVV2安全性基础结构,但是提供明显更高的安全性。本发明的实施例可以与普通的面对面或电话交易一起使用,并且还可以用于电子商务(基于网络)和m商务(基于移动电话)的交易中。

著录项

  • 公开/公告号NZ535428A

    专利类型

  • 公开/公告日2006-08-31

    原文格式PDF

  • 申请/专利权人 SWIVEL SECURE LIMITED;

    申请/专利号NZ20030535428

  • 发明设计人 KEECH WINSTON DONALD;

    申请日2003-03-14

  • 分类号G07F7/10;G07F19/00;

  • 国家 NZ

  • 入库时间 2022-08-21 21:38:05

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号