US2014344898A1PendingUtilityA1

Stand-in authorization system and stand-in authorization method

Assignee: CHINA UNIONPAY CO LTDPriority: Dec 22, 2011Filed: Dec 20, 2012Published: Nov 20, 2014
Est. expiryDec 22, 2031(~5.4 yrs left)· nominal 20-yr term from priority
H04L 63/123G06Q 20/40G06Q 20/027H04L 63/10G06Q 40/12
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The invention provides an entrusted-authorization system and an entrusted-authorization method. The entrusted-authorization system comprises an accounting system, a switch module and an entrusted-authorization module, wherein the entrusted-authorization module stores entrusted-authorization parameters determined by the accounting system, the switch module is connected with the accounting system and the entrusted-authorization module for transmitting transaction request messages from the client terminal to the entrusted-authorization module for processing in case that the accounting system is unavailable, wherein the entrusted-authorization module verifies the transaction request messages according to the entrusted-authorization parameters; otherwise, the messages are sent to the accounting system for processing. The transaction request messages comprise financial account information, financial mechanism information, transaction initiation mechanism information and transaction amount. With the entrusted-authorization system and entrusted-authorization method of the invention, a normal processing of transaction request can be ensured when the accounting system is unavailable.

Claims

exact text as granted — not AI-modified
1 . An entrusted-authorization system, characterized in that, the entrusted-authorization system comprises an accounting system, a switch module and an entrusted-authorization module, wherein
 the entrusted-authorization module stores entrusted-authorization parameters determined by the accounting system;   the switch module is connected with the accounting system and the entrusted-authorization module for transmitting transaction request messages from client terminals to the entrusted-authorization module in case that the accounting system is unavailable, the entrusted-authorization module verifies the transaction request messages according to the entrusted-authorization parameters; otherwise, the messages are sent to the accounting system for processing, the transaction request messages comprise financial account information, financial mechanism information, transaction initiation mechanism information and transaction amount.   
     
     
         2 . The entrusted-authorization system according to  claim 1 , characterized in that, the entrusted-authorization module comprises data communication module, verification processing module and database, wherein
 the data communication module is connected between the switch module and the verification processing module so as to transfer information therebetween;   the database stores the entrusted-authorization parameters, the transaction information and cause of failure, the entrusted-authorization parameters comprise financial mechanism information, transaction initiation mechanism information, account amount and account information, the account information comprises the information selected from a group comprising the following items: card numbers, terms of validity of the cards, check digits of the card, password encryption data, verification number of the card (CVN), information in IC card which corresponds to items in validity verification events of account;   the verification processing module stores the validity verification events of account, where the validity verification events of account comprise at least one of verification of card numbers, verification of terms of validity of the cards, verification of check digits of the cards, verification of passwords, verification of CVN, and verification of IC card information;   the verification processing module is configured to perform the following steps:   A. verifying the validity of the transaction request messages, and performing subsequent steps if the verification is approved, or otherwise generating and sending a response message indicating failure to the data communication module and sending the cause of failure to the database;   B. verifying the transaction request messages according to the financial mechanism information and the transaction initiation mechanism information in the entrusted-authorization parameters, and performing subsequent steps if the verification is approved, or otherwise generating and sending a response message indicating failure to the data communication module and sending the cause of failure to the database;   C. determining the validity verification events of account according to account information and performing the verification according to the determined validity verification events of account, and performing subsequent steps if the verification is approved, or otherwise generating and sending a response message indicating failure to the data communication module and sending the cause of failure to the database; and   D. verifying transaction request according to account amount, and in case of the verification being approved, encashing the transaction request, generating and sending a response message indicating success to the data communication module, and generating and sending transaction information to the database, or otherwise generating and sending a response message indicating failure to the data communication module and sending the cause of failure to the database, the transaction information comprises financial account information, financial mechanism information, transaction initiation mechanism information, transaction amounts, transaction types and transaction dates.   
     
     
         3 . The entrusted-authorization system according to  claim 2 , characterized in that, the verification processing module stores verification events of account risk, the verification events of account risk comprises at least one of verification of account blacklist, verification of commercial tenant blacklist and verification of limit control, the entrusted-authorization parameters further comprise account risk information which further comprises information selected from a group comprising the following items: information in the account blacklist, commercial tenant blacklist and limit control that corresponds to items in the verification events of account risk; wherein the verification processing module determines the verification events of account risk according to account risk information and performing the verification according to the determined verification events of account risk, and step D is performed if the verification is approved, or otherwise, the verification processing module generates and sends a response message indicating failure to the data communication module and sending the cause of failure to the database. 
     
     
         4 . The entrusted-authorization system according to  claim 2 , characterized in that, the entrusted-authorization parameters further comprises permitted transaction types and the verification processing module is further configured to:
 determine transaction types according to the transaction request messages; and   verify the transaction types according to the permitted transaction types.   
     
     
         5 . The entrusted-authorization system according to one of  claims 2  to  4 , characterized in that, the entrusted-authorization module further comprises:
 a parameter uploading module for uploading the entrusted-authorization parameters determined by the accounting system to the database when the accounting system is available; and 
 a transaction delivering module for delivering transaction information and cause of failure during entrusted-authorization in the database to the accounting system when the switch module switches transaction to the accounting system. 
 
     
     
         6 . An entrusted-authorization method applied to entrusted-authorization system, characterized in that, the entrusted-authorization system comprises an accounting system, an entrusted-authorization module and a switch module connected with the accounting system and the entrusted-authorization module, the entrusted-authorization module stores entrusted-authorization parameters determined by the accounting system, the entrusted-authorization method comprising:
 the switch module transmits transaction request messages from the client terminal to the entrusted-authorization module in case that the accounting system is unavailable, the entrusted-authorization module verifies the transaction request messages according to the entrusted-authorization parameters; otherwise, sends the messages to the accounting system for processing, wherein the transaction request messages comprise financial account information, financial mechanism information, transaction initiation mechanism information and transaction amounts.   
     
     
         7 . The entrusted-authorization method according to  claim 6 , characterized in that, the entrusted-authorization parameters comprise financial mechanism information, transaction initiation mechanism information, account amount and account information, the account information comprises information selected from a group comprising the following items: card number, term of validity of the card, check digit of the card, password encryption data, verification number of the card (CVN), information in IC card which corresponds to items in the validity verification events of account, wherein the entrusted-authorization module verifying the transaction request messages according to the entrusted-authorization parameters comprises the following steps:
 A. the entrusted-authorization module verifies the validity of the transaction request messages, and performing subsequent steps if the verification is approved, or otherwise generates and sends a response message indicating failure to the switch module and saves the cause of failure in the entrusted-authorization module;   B. verifying the transaction request messages according to the financial mechanism information and the transaction initiation mechanism information in the entrusted-authorization parameters, and performing subsequent steps if the verification is approved, or otherwise generating and sending a response message indicating failure to the switch module and saving the cause of failure in the entrusted-authorization module;   C. determining the validity verification events of account according to account information and performing verification according to the determined validity verification events of account, and performing subsequent steps if the verification is approved, or otherwise generating and sending a response message indicating failure to the switch module and saving the cause of failure in the entrusted-authorization module; wherein the validity verification events of account is stored in the entrusted-authorization module, and the validity verification events of account comprise at least one of verification of card number, verification of term of validity of the card, verification of check digits of the card, verification of password, verification of CVN, and verification of IC card information;   D. verifying transaction request according to account amount, and in case of approved verification, encashing the transaction request, generating and sending a response message indicating success to the switch module, and generating and saving transaction information to the entrusted-authorization module, or otherwise generating and sending a response message indicating failure to the switch module and saving the cause of failure in the entrusted-authorization module, the transaction information comprises financial account information, financial mechanism information, transaction initiation mechanism information, transaction amount, transaction types and transaction dates.   
     
     
         8 . The entrusted-authorization method according to  claim 7 , characterized in that, the entrusted-authorization module verifying the transaction request messages according to the entrusted-authorization parameters comprises the following steps:
 E. the entrusted-authorization module determines verification events of account risk according to account risk information and performs verification according to the determined verification events of account risk, and performs step D if the verification is approved, or otherwise, generates and sends a response message indicating failure to the switch module and saves the cause of failure in the entrusted-authorization module, wherein the verification events of account risk is stored in the entrusted-authorization module, the verification events of account risk comprises at least one of verification of account blacklist, verification of commercial tenant blacklist and verification of limit control, the entrusted-authorization parameters further comprises information selected from a group comprising the following items: information in the account blacklist, commercial tenant blacklist and limit control that corresponds to items in verification events of account risk.   
     
     
         9 . The entrusted-authorization method according to  claim 7 , characterized in that, the entrusted-authorization parameters further comprise permitted transaction types and verifying the transaction request messages according to the entrusted-authorization parameters comprises:
 the entrusted-authorization module determines transaction types according to the transaction request messages; and   the entrusted-authorization module verifies the transaction types according to the permitted transaction types.   
     
     
         10 . The entrusted-authorization method according to one of  claims 6  to  9 , characterized in that, the method further comprises:
 uploading the entrusted-authorization parameters determined by the accounting system to the entrusted-authorization module when the accounting system is available; and 
 the entrusted-authorization module delivers transaction information and cause of failure during entrusted-authorization to the accounting system when the switch module switches the transaction to the accounting system.

Join the waitlist — get patent alerts

Track US2014344898A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.