1: First merchant to the Yi Bao Company application account, after the successful application of Yi Bao Company assigned to a merchant: electronic signature
The so-called electronic signature includes an account number, which is the account that the buyer pays, the colleague provides a set of cryptographic algorithms, and
a secret key;
2: The local website in the third-party payment when the need to submit information: Payment account, beneficiary account, payment amount, order number, Bank type; colleagues provide a set of cryptographic algorithms and key pairs provided by a third party to be submitted: Payment account, beneficiary account, payment amount, order number, The bank type is encrypted to get the HMAC code to easy treasure.
3: ePRO According to the data submitted by the user, with the same set of encryption algorithm to submit: Payment account, collection account, payment amount, order number, bank type to encrypt to get an HMAC code, compared to the user submitted by the HMAC code, if the same is done after the major banks of the payment work, If the two HMAC codes are different, the data is intercepted and tampered with, and the payment fails
4 .....
ePRO Payment principle