EP1483645A2 - Vorrichtung und verfahren zur sicherung empfindlicher daten zwischen zwei teilen durch dritte partei - Google Patents

Vorrichtung und verfahren zur sicherung empfindlicher daten zwischen zwei teilen durch dritte partei

Info

Publication number
EP1483645A2
EP1483645A2 EP03717408A EP03717408A EP1483645A2 EP 1483645 A2 EP1483645 A2 EP 1483645A2 EP 03717408 A EP03717408 A EP 03717408A EP 03717408 A EP03717408 A EP 03717408A EP 1483645 A2 EP1483645 A2 EP 1483645A2
Authority
EP
European Patent Office
Prior art keywords
entity
personal
sensitive data
party
personal electronic
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
EP03717408A
Other languages
English (en)
French (fr)
Inventor
Murielle Rose
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Gemplus SA
Original Assignee
Gemplus Card International SA
Gemplus SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemplus Card International SA, Gemplus SA filed Critical Gemplus Card International SA
Publication of EP1483645A2 publication Critical patent/EP1483645A2/de
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6245Protecting personal data, e.g. for financial or medical purposes

Definitions

  • the invention relates to the management of sensitive data in data exchange systems.
  • An example of such systems is based on the realization of electronic contracts between two parties or entities, for example a user and a service provider, using a third party entity. The latter then acts as a representative of the user, being able to negotiate on his behalf with service providers, while protecting his personal data.
  • the trusted intermediary 2 keeps in memory the data characteristic of a contract concluded between two entities, such as a user and a commercial entity for example.
  • the trusted intermediary provides electronic proof of the contract signed.
  • the operating principle of such an organization is presented schematically in FIG. 1.
  • the trusted intermediary 2 has two interfaces: a so-called “service provider agent” 4 which dialogues with the service providers FS, and a so-called “agent staff "6 who dialogues with U users. These two agents 4 and 6 interact with each other via a dedicated link 8.
  • the user U is connected to the personal agent 6 by the Internet network 10, for example by means of a personal computer PC 12.
  • a disadvantage of this system is that the trusted third party 2 needs to know all of the user's personal data in order to carry out the transactions in place of the latter, and that this personal data is vulnerable in two respects of view: they are stored on a computer which is not by nature secure, and they escape the control of ' their owner.
  • the invention provides technical security means which can be integrated functionally in such a system. These means are based on a personal electronic medium held by a user and which can dialogue with the personal agent or other trusted organization.
  • the support manages, under the own control of its holder user, the disclosure of certain sensitive data for which this user judges it undesirable to leave the management of the disclosure to his personal agent. Sensitive data as well are selected by the user.
  • the invention provides, according to a first aspect, a method of representing a first entity by a third entity to which a second entity is addressed to request sensitive data from the first entity, characterized in that it involves the following steps:
  • - the third party entity dialogues with the second entity and with the first entity using a personal agent interface;
  • - the first entity controls the communication of at least part of the sensitive data from the third entity to the second entity by means of a personal electronic medium, via the following steps: - a security agent of the electronic medium personnel ensures dialogue with the personal agent; the security agent of the personal electronic support ensures the reading of at least the part of the sensitive data and / or of the criteria for the inhibition of their disclosure.
  • control can be carried out by interfacing with the user in order to obtain his authorization or prohibition, ensured by the security agent of the personal electronic medium, or by secure storage of at least part of the data. sensitive in the personal electronic medium, outside the third party entity.
  • the invention provides a system for exchanging data between a first and a second entity via a third entity, the system being characterized by a means of communication in the third entity and a support. electronics in the first entity with the characteristics described below.
  • the invention provides a personal electronic medium intended for the method according to the first aspect, comprising:
  • the invention provides a communicating terminal allowing a first entity to communicate with a third entity which represents it, characterized in that it implements a support according to the third aspect.
  • the invention provides a third-party entity representing a first entity, characterized in that it comprises means for dialogue with a personal electronic medium according to the third aspect, making it possible to transmit at least one data item belonging to the first entity under control of said medium.
  • This third-party entity can store in memory the characteristics of a contract concluded between the first entity and a second entity.
  • FIG. 1 is a simplified diagram showing the operation of a trusted third party organization forming a link between service providers and users; and - Figure 2 is a diagram which reproduces that of Figure 1 by adding the elements allowing the implementation of the invention according to a • preferred embodiment.
  • a user U of the trusted third party organization 2 has a personal electronic medium which ensures the management of his sensitive data. These are the data for which he wishes to retain a right of control as to their disclosure by the trusted organization 2 to a service provider for example.
  • the latter can be a commercial enterprise offering online services or wishing to prospect online, an institutional body allowing remote exchanges, etc.
  • the personal electronic medium is a smart card 14 of the SIM or USIM type (English acronym for “(universal) subscriber identification module”) integrated into a mobile telephone terminal 16 of the user U, thus conferring a new function to this card.
  • a SIM chip card in itself contains enough basic technical resources to perform this function: microprocessor 15, memories: RAM of the "RAM” type 18, frozen of the "ROM” type 20, electrically programmable of the "EEPROM” type 22, communication interface (by contacts), communication programs, means of loading data and programs , etc.
  • Card 14 - which constitutes the personal electronic medium - intervenes in management in two possible ways:
  • the sensitive data or data DS in its own memory (for example the EEPROM memory 22), these data then not being stored with the personal agent 6, and / or
  • the card 14 can selectively exercise one or the other of these ways of intervening as a function of the sensitive data in question.
  • Management at the level of the card 14 is carried out by application software, called "security agent application" 24, contained in the support (for example in the EEPROM memory 22 of the card 14).
  • the security application ensures in particular: i) the dialogue with the personal agent 6, ii) the reading of the memory 22 storing the sensitive data DS and / or of the criteria CD for 1 inhibition of their disclosure and iii) 1 interfacing with the user.
  • the personal agent 6 has software 26 for dialog with the security agent application 24.
  • the security agent application 24 presents the user with a request for authorization to transmit (with indication of the data item and its disclosure condition).
  • the security agent application 24 extracts in response the sensitive data in question from the memory 22 and transmits it to the personal agent 6.
  • the security agent application 24 blocks the sensitive data in its memory 22. 2.
  • the personal agent 6 has the sensitive data, but in association with an indication not to disclose it to a third party only with the user's prior agreement to each request. Two possibilities are then taken into account: - 2.1. .
  • the security guard application 24 in the card 14 includes an indication of the disclosure condition.
  • the personal agent 6 indicates on the card, with his request, the disclosure condition (for example the name of the requesting third party).
  • the security guard application 24 first determines whether it is able to pass judgment on the condition transmitted by the agent. If the answer is negative, it goes to the possibility presented in section 2.2 below; if the answer is positive, it compares the condition indicated by the agent with that (s) recorded for this data.
  • the security agent application 24 sends a validation signal to the personal agent 6, allowing the latter to disclose the data to the requesting third party (for example a service provider FS).
  • a service provider FS for example a service provider FS
  • the security application 24 sends an inhibition signal to the personal agent 6, preventing the latter from extracting the data from its memory.
  • the security guard application 24 in the card 14 has not recorded conditions for disclosing the sensitive data, or is confronted with a condition indication of a type not listed among its possible conditions (for example the name of a new third party).
  • the security agent application 24 presents the user U with a request for authorization to disclose (with indication of the data item and its disclosure condition).
  • the security application 24 sends a validation signal to the personal agent 6, allowing the latter to disclose the data to the requesting third parties. If he expresses his refusal, the security agent application sends an inhibition signal to the personal agent, preventing the latter from extracting the data from his memory.
  • the safety officer applying • 24 is in the form of an applet (called "Applet security agent") loaded into the card 14 is in personalization, either postpersonnalisation.
  • the security agent applet 24 also manages the interface with the user U on the mobile telephone terminal 16, in particular to communicate to him a request for authorization to transmit sensitive data or to accept a validation or inhibition signal. access by the personal agent 6.
  • This interface advantageously uses the display 16a of the mobile terminal to present the conditions and the keyboard 16b to receive a response from the user U.
  • the communication between the applet security guard 24 and the personal agent 6 is carried out on the wireless channel used by the mobile telephone terminal 16, for example according to the GSM protocol. In the example, this communication passes through a mobile telephone network operator 28 and the communications are advantageously made by SMS messages.
  • MMS (acronym for "multimedia messaging service”).
  • the security agent applet 24 can respond to the personal agent 6, via the dialogue software 26, also by SMS messages, the latter serving to transmit sensitive data, a validation signal or a signal inhibition.
  • the security agent applet 24 can respond to the personal agent 6, via the dialogue software 26, also by SMS messages, the latter serving to transmit sensitive data, a validation signal or a signal inhibition.
  • the dialogue between the card 14 and the personal agent 6 can be secured by any known means (encryption, etc.).
  • the recipient of sensitive data (or inhibition / validation signals) emitted by the medium this recipient can be any centralized private or public management system; - the personal electronic medium held by the user, this medium being able to be a smart card of any type, an electronic token, an electronic badge, or any other personal electronic object making it possible to communicate via a platform or by himself, terminal on the user side, this terminal can be any mobile telephone, landline telephone, communicating personal digital assistant, personal computer, etc., of the link connecting the material medium held by the user or his terminal with the recipient of sensitive data , this link can be based on any wireless or wired communication protocol,
  • the security agent applet 24 (or the like) can be provided for transmitting a secure data item not in return to the personal agent 6 (or the like) having made the request, but directly to the final recipient (for example the service provider FS), by calling the connection number of the latter.
  • the hardware support 14, 16 held by the user can also allow an update or a controlled loading of sensitive data from the personal agent 6 (or any other authorized third party).
  • the security agent applet 24 will then ensure the validation of the loading or modification under control of the user, either by presenting the request for loading or updating with the possibility of accepting or refusing, or by performing automatic filtering on the basis of criteria fixed beforehand by the user.
  • the invention is suitable for financial transactions, in particular for processing electronic payment in the context of electronic commerce.
  • the bank details will be stored on the smart card of the personal electronic medium and used as described above in section 1.2.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Databases & Information Systems (AREA)
  • Storage Device Security (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Lock And Its Accessories (AREA)
EP03717408A 2002-02-18 2003-02-18 Vorrichtung und verfahren zur sicherung empfindlicher daten zwischen zwei teilen durch dritte partei Ceased EP1483645A2 (de)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
FR0202028A FR2836251B1 (fr) 2002-02-18 2002-02-18 Dispositif et procede de securisation de donnees sensibles, notamment entre deux parties via un organisme tiers
FR0202028 2002-02-18
PCT/FR2003/000529 WO2003071400A2 (fr) 2002-02-18 2003-02-18 Dispositif et procede de securisation de donnees sensibles, notamment entre deux parties via un organisme tiers

Publications (1)

Publication Number Publication Date
EP1483645A2 true EP1483645A2 (de) 2004-12-08

Family

ID=27636271

Family Applications (1)

Application Number Title Priority Date Filing Date
EP03717408A Ceased EP1483645A2 (de) 2002-02-18 2003-02-18 Vorrichtung und verfahren zur sicherung empfindlicher daten zwischen zwei teilen durch dritte partei

Country Status (6)

Country Link
US (1) US20050177729A1 (de)
EP (1) EP1483645A2 (de)
JP (1) JP2005518039A (de)
AU (1) AU2003222576A1 (de)
FR (1) FR2836251B1 (de)
WO (1) WO2003071400A2 (de)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070073889A1 (en) * 2005-09-27 2007-03-29 Morris Robert P Methods, systems, and computer program products for verifying an identity of a service requester using presence information
US7788499B2 (en) * 2005-12-19 2010-08-31 Microsoft Corporation Security tokens including displayable claims
US8117459B2 (en) 2006-02-24 2012-02-14 Microsoft Corporation Personal identification information schemas
US8104074B2 (en) 2006-02-24 2012-01-24 Microsoft Corporation Identity providers in digital identity system
US20070208750A1 (en) * 2006-03-01 2007-09-06 International Business Machines Corporation Method and system for access to distributed data
US20070220009A1 (en) * 2006-03-15 2007-09-20 Morris Robert P Methods, systems, and computer program products for controlling access to application data
US8078880B2 (en) 2006-07-28 2011-12-13 Microsoft Corporation Portable personal identity information
CA2571666A1 (en) * 2006-12-12 2008-06-12 Diversinet Corp. Secure identity and personal information storage and transfer
US8407767B2 (en) 2007-01-18 2013-03-26 Microsoft Corporation Provisioning of digital identity representations
US8087072B2 (en) 2007-01-18 2011-12-27 Microsoft Corporation Provisioning of digital identity representations
US8689296B2 (en) 2007-01-26 2014-04-01 Microsoft Corporation Remote access of digital identities

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP0917119A3 (de) * 1997-11-12 2001-01-10 Citicorp Development Center, Inc. Verteilte netzwerkbasierte elektronische Geldbörse
US20020004783A1 (en) * 1997-11-12 2002-01-10 Cris T. Paltenghe Virtual wallet system
WO2001050299A2 (en) * 1999-12-29 2001-07-12 Pango Systems B.V. System and method for incremental disclosure of personal information to content providers
DE60104518T2 (de) * 2000-01-28 2005-09-01 Fundamo (Pty.) Ltd., Bellville Bankensystem mit verbesserter identifizierung von finanzbuchhaltungskonten
AU2001226996A1 (en) * 2000-01-28 2001-08-07 Fundamo (Proprietary) Limited Personal information data storage system and its uses

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO03071400A3 *

Also Published As

Publication number Publication date
JP2005518039A (ja) 2005-06-16
US20050177729A1 (en) 2005-08-11
FR2836251A1 (fr) 2003-08-22
WO2003071400A3 (fr) 2003-11-13
WO2003071400A2 (fr) 2003-08-28
AU2003222576A1 (en) 2003-09-09
FR2836251B1 (fr) 2004-06-25

Similar Documents

Publication Publication Date Title
EP0932317B1 (de) Verfahren zur verschlüsselten Datenübertragung zwischen einem Teilnehmer-Identifikationsmodul und einem Mobilfunkendgerät
EP1008257A2 (de) Verfahren und system zur absicherung von fernsprech-anrufssteuerungseinrichtungen
FR2821225A1 (fr) Systeme de paiement electronique a distance
FR2751814A1 (fr) Systeme de controle et de gestion de services
EP1483645A2 (de) Vorrichtung und verfahren zur sicherung empfindlicher daten zwischen zwei teilen durch dritte partei
EP1226725A1 (de) System und verfahren zur übertragung der nachrichten, und systemverwendung für untersuchung der zu verfügung gestellten dienstleistungen
FR2809260A1 (fr) Procede d'approvisionnement d'un compte prepaye
FR2810433A1 (fr) Systeme et procede de couponnage electronique
WO2002052389A2 (fr) Methode anti-clonage d'un module de securite
EP1358641A1 (de) Chipkarte mit sicherheitssoftware und mit einer solchen karte zusammenarbeitende kommunikationsvorrichtung
EP1912182A1 (de) Berechtigung zur Durchführung einer Transaktion zwischen einem elektronischen Schaltkreis und einem Endgerät
FR2867650A1 (fr) Procede et terminaux communicants pour l'identification d'eligibilite d'un utilisateur par un code a barres
EP0172047B1 (de) Verfahren und System zum Chiffrieren und Dechiffrieren von zwischen einem Sender und einem Empfänger übertragenen Daten
EP0817144B1 (de) Verfahren zur Steuerung der Benutzung eines Rufempfängers, nach diesem Verfahren arbeitender Rufempfänger und Chipkarte für bedingten Zugang eines Rufempfängers
WO1997031343A1 (fr) Carte de gestion de comptes multiples et procede de mise en ×uvre
EP0831434A1 (de) Verfahren zum Schliessen einer Vielzahl von Dienstleistungen, insbesondere durch Setzen auf eine schwarze Liste, und entsprechende Server zum Schliessen, Annahmeendgerät und tragbare Vorrichtungen
BE1019350A3 (fr) Usage d'une carte d'identite electronique en tant que carte d'affiliation.
EP1479255A1 (de) Verfahren zur steurung des zugriffs auf mindestens einige funktionen eines telekommunikations-mobilendgerät
FR2865341A1 (fr) Procedes de securisation de terminaux mobiles, et ensembles securises comprenant de tels terminaux
FR2752977A1 (fr) Dispositif portatif de mise en opposition d'une carte de transaction, terminal d'acceptation et procede correspondant
FR3042374A1 (fr) Aide a l'etablissement d'une communication telephonique par provision d'informations sur l'utilisateur appelant
WO2003065181A1 (fr) Procede de controle de l'exploitation de contenus numeriques par un module de securite ou une carte a puce comprenant ledit module
EP1400935A1 (de) System und Anwendung zum vereinfachten Übertragen von Nachrichten, mittels einer Fest-Verbindung
EP1588252B1 (de) System und verfahren zur übertragung von daten zwischen interaktiven öffentlichen terminalgeräten und persönlichen terminalgeräten
EP1371036A2 (de) Verfahren und system für erneuerung von identifikationsdaten in einer tragbaren transaktionseinrichtung

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20040920

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PT SE SI SK TR

AX Request for extension of the european patent

Extension state: AL LT LV MK RO

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED

18R Application refused

Effective date: 20070415