EP3440609A2 - Verfahren zur einleitung eines authentifizierungsprozesses, insbesondere geeignet zur personenauthentifizierung im rahmen eines bargeldlosen zahlungsverkehrs, und datenverarbeitungeterminal zur verwendung in einem solchen verfahren - Google Patents
Verfahren zur einleitung eines authentifizierungsprozesses, insbesondere geeignet zur personenauthentifizierung im rahmen eines bargeldlosen zahlungsverkehrs, und datenverarbeitungeterminal zur verwendung in einem solchen verfahrenInfo
- Publication number
- EP3440609A2 EP3440609A2 EP17739189.3A EP17739189A EP3440609A2 EP 3440609 A2 EP3440609 A2 EP 3440609A2 EP 17739189 A EP17739189 A EP 17739189A EP 3440609 A2 EP3440609 A2 EP 3440609A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- processing terminal
- data processing
- data
- central station
- individual
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
Definitions
- the invention relates to a method for object and individual authentication, in particular for person authentication, for example in the context of a cashless payment transaction, using an individual or object-related device, such as an electronic device.
- an individual or object-related device such as an electronic device.
- a smartphone on which individual or object-specific data is stored, and a central station that verifies the authentication process, e.g. a server.
- Payment transactions in brick-and-mortar retailing are undergoing profound changes due to changes in regulatory and technical conditions.
- Conventional methods for initiating cashless payment transactions involve a reading device, which is usually connected to a checkout system, such as a card terminal, which communicates with the POS system on the one hand and is connected to the server of a bank via a specially secured network (VPN) on the other hand.
- a checkout system such as a card terminal
- VPN specially secured network
- a two-factor authentication is made, consisting of a physically existing object (card) and a customer-specific identification code (PIN), which the customer uses to combine Identifies the location as the person entitled for a payment order.
- PIN customer-specific identification code
- newer methods for initiating a cashless payment transaction in which a person identification by means of a smartphone or other portable electronics is to be initiated by received via a receiving device (reader?) Received by the smartphone identification data and payments are forwarded by entering a PIN code.
- QR codes pass information from the initiating device to software on the smartphone that uses this information to initiate the payment.
- an existing internet connection on the smartphone is mandatory.
- the user can visually not verify on the basis of the QR codes whether it is the expected QR code or that it was placed by an attacker. This allows phishing attacks.
- NFC works with two superimposed magnetic fields, which must be brought to a close distance of a maximum distance of 20 cm. This is disadvantageous if the payment is to be made at a distance (eg from inside a vehicle).
- there is no possibility to actively promote the system for example via location-based push notifications.
- NFC based payment systems can be attacked by initiating a payment by the attacker placing a payment terminal in the physical vicinity of the victim's smartphone and initiating a payment while the victim does not expect it.
- Necessary protective measures such as aluminum cases also interfere with desirable radio signals such as WI_AN or mobile communications.
- the individual-related device can not verify that it is transmitting its data to a valid, non-compromised remote site. This is due to the fact that both methods do not allow sufficiently fast local bidirectional data transmission, for example, to exchange certificate-based identity information.
- device an individual or object-related device, hereinafter referred to as "device" which provides for the collection and transmission of data, for example within the framework of a cashless
- device provides for the collection and transmission of data, for example within the framework of a cashless
- map further interactions such as the sending of control commands or the exchange of digital invoices and receipts.
- the process enables the flexible, retailer-specific connection of a variable number of payment service providers and other application partners.
- the type and number of available payment methods and services can be defined by the dealer automatically via a terminal-specific administration dashboard.
- the physical basis of the method is that the data processing terminal has a short-distance radio link with the Bluetooth Low Energy (BLE) short-range radio standards or a combination of a radio transmission and a near-field Communication, or a future, faster NFC technology with mobile phones and other portable electronic devices can communicate.
- BLE Bluetooth Low Energy
- Bluetooth As part of the pairing process, it is necessary for Bluetooth that the user manually reconciles a code between the participating devices in order to exclude a "man-in-the-middle" attack with impossibility unlikely makes this step superfluous and makes Bluetooth usable for the first time for processes that have both high demands on security and ease of use.
- a key exchange during connection setup can be carried out extremely fast and extremely secure.
- a combined application of two asymmetric encryption methods or the sole use of a single asymmetric encryption method may also take place.
- a single symmetric encryption can not be regarded as sufficiently secure and not as sufficiently practical, because the key must be known to both communication partners before the transfer and must be withdrawn and / or exchanged upon disclosure to all communication partners.
- symmetric encryption In symmetric encryption, the participants in a communication to encrypt and decrypt use the same key. The security of the method is based on the fact that the effort for calculating the key is so high that the key with the existing computing power can not be determined with reasonable time. However, since the symmetric key holder can decrypt and read the communication encrypted with him, the exchange of a symmetric key must be via a secure channel or by securing a PIN code known only to the communication parties. However, a big advantage of symmetric encryption is the high speed of encryption and decryption.
- asymmetric encryption for example by means of public-key cryptography, a pair of two keys is generated, it being characteristic of this key pair that data encrypted with a key can not be decrypted with the same key, but only with the other one.
- One key is considered public and the other is defined as private.
- To sign or encrypt a communication a subscriber sends his public key to another subscriber. This other party can use the public key sent by the first party to encrypt any messages for the first party. Then this first participant can decrypt the message again with his private key.
- This asymmetric encryption has the advantage over symmetric encryption that the key exchange can take place via an insecure connection and that there is no need to secure by means of a previously agreed PIN (personal identification number).
- PIN personal identification number
- the data processing terminal is connected but not only via the radio link with the personal device (eg smartphone) in connection, but also eg via a data line with a POS system.
- the data processing terminal also has a public key and a private key.
- a data processing terminal suitable for use in the method according to the invention is defined in more detail in claim 10, wherein advantageous embodiments of this data processing terminal are specified in claims 11 to 14.
- the core of this data processing terminal is a cryptochip system on which there is a microprocessor to which an identification security module is assigned.
- This cryptochip system can be modular. In the present case, it is on a motherboard that provides the wired connections to the outside world.
- a cover plate above the cryptochip system which transmits all radio-bound connections to the outside world and has LED modules for visual communication with the user. Above this cover plate, a hardened glass surface is applied on which the LED ring emerges as the boundary of an inner circular area.
- the data processing terminal has a connection for connection to a further board, via which the data processing terminal receives power and cable-linked information streams.
- Fig. 1 shows a structure as it exists for example at a cash register at the POS or an access system.
- An activation unit / controller (AE) requires the authorization of a function offered by the AE. In the example of the cash register this function could be "pay", in the access system "door open”. This authorization is made by the central station, but this must first authenticate the personal device. However, since AE and the personal device have no physical connection to each other, a data processing terminal (DVT) is interposed which is connected to the personal device as well as via data link, via any medium, to AE and to the central station.
- DVD data processing terminal
- the DVT accepts one or more connections from a software (app) installed on the personal device. This connection is encrypted, with the personal device checking the authenticity of the data processing terminal based on system-specific data stored in the app.
- the connection between the DVT and the central station is also encrypted, whereby both sides of a communication mutually authenticate each other.
- the central station takes over the administration of one or more DVTs in figure a.
- the central station in figure a assumes the authentication of the personal device.
- user-specific data was stored on the personal device during or after the installation of the app.
- the command to trigger this function is sent from the AE to the app via the DVT.
- the command is signed by the app with the user-specific data (signed) and command and signature (signature) will be sent to the DVT.
- the DVT sends the data to the central station.
- the personal device is first authenticated (identified) based on the user-specific data and then checked whether the personal device is authorized (authorized) to execute the transmitted command.
- the central station sends the authorization to the DVT.
- This DVT then sends an activation signal to the AE, which then performs the function requiring the authorization.
- FIG 2 shows a variant of figure a, the difference being that the authorization of the function of the activation unit / control unit (AE) takes place by an external station, which is not the central station. In Figure b, this role is taken up by a Payment Service Provider (PSP).
- PSP Payment Service Provider
- An essential feature of the method described is that the user-specific data is encrypted on the personal device for the external station. This ensures that the personal device can authenticate itself to the external station, but is not authenticated (identifiable) for all other devices involved in the communication and potential attackers.
- this feature makes it possible to pay anonymously / pseudonym if the chosen PSP so provides (such as for example, in the case of digital means of payment, eg with the digital currency BitCoin or Etherum).
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Engineering & Computer Science (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102016004293.1A DE102016004293A1 (de) | 2016-04-07 | 2016-04-07 | Verfahren zur Einleitung eines Authentifizierungsprozesses, insbesondere geeignet zur Personenauthentifizierung im Rahmen eines bargeldlosen Zahlungsverkehrs, und Datenverarbeitungsterminal zur Verwendung in einem solchen Verfahren |
| PCT/EP2017/000443 WO2017174200A2 (de) | 2016-04-07 | 2017-04-07 | Verfahren zur einleitung eines authentifizierungsprozesses, insbesondere geeignet zur personenauthentifizierung im rahmen eines bargeldlosen zahlungsverkehrs, und datenverarbeitungeterminal zur verwendung in einem solchen verfahren |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3440609A2 true EP3440609A2 (de) | 2019-02-13 |
Family
ID=59325257
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP17739189.3A Withdrawn EP3440609A2 (de) | 2016-04-07 | 2017-04-07 | Verfahren zur einleitung eines authentifizierungsprozesses, insbesondere geeignet zur personenauthentifizierung im rahmen eines bargeldlosen zahlungsverkehrs, und datenverarbeitungeterminal zur verwendung in einem solchen verfahren |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP3440609A2 (de) |
| DE (1) | DE102016004293A1 (de) |
| WO (1) | WO2017174200A2 (de) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11037139B1 (en) | 2015-03-19 | 2021-06-15 | Wells Fargo Bank, N.A. | Systems and methods for smart card mobile device authentication |
| US11188919B1 (en) | 2015-03-27 | 2021-11-30 | Wells Fargo Bank, N.A. | Systems and methods for contactless smart card authentication |
| US11113688B1 (en) | 2016-04-22 | 2021-09-07 | Wells Fargo Bank, N.A. | Systems and methods for mobile wallet provisioning |
| EP3627434A1 (de) * | 2018-09-24 | 2020-03-25 | Youki GmbH | System, verfahren und vorrichtung zur durchführung von kryptographisch gesicherten transaktionen |
| US11928666B1 (en) | 2019-09-18 | 2024-03-12 | Wells Fargo Bank, N.A. | Systems and methods for passwordless login via a contactless card |
| US12450591B1 (en) | 2020-09-16 | 2025-10-21 | Wells Fargo Bank, N.A. | Systems and methods for contactless card activation via unique activation codes |
| US11423392B1 (en) | 2020-12-01 | 2022-08-23 | Wells Fargo Bank, N.A. | Systems and methods for information verification using a contactless card |
| DE102022114588A1 (de) | 2022-06-09 | 2023-12-14 | Deutsche Telekom Ag | Verfahren und System zur Authentifizierung einer Person |
| DE102023211449A1 (de) * | 2023-09-15 | 2025-03-20 | QuiB UG (haftungsbeschränkt) | Verfahren und System zur Erstellung und Verarbeitung eines elektronischen Kassenbelegs zu einem Kaufvorgang |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150032558A1 (en) * | 2013-07-29 | 2015-01-29 | Exxonmobil Research And Engineering Company | System and method to purchase and dispense fuel and other products using a mobile device with improved user experience |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7804274B2 (en) * | 2008-07-21 | 2010-09-28 | Coulomb Technologies, Inc. | Vehicle charging station having a dual position locking door |
| US20100042848A1 (en) * | 2008-08-13 | 2010-02-18 | Plantronics, Inc. | Personalized I/O Device as Trusted Data Source |
| US20140025577A1 (en) * | 2012-07-17 | 2014-01-23 | Slawomir LISZNIANSKI | System and method for secure transactions utilizing passive near-field communications devices |
| US20150118958A1 (en) * | 2013-10-25 | 2015-04-30 | Devicefidelity, Inc. | Switching between near-field communication systems |
| GB2519798B (en) * | 2013-10-30 | 2017-06-07 | Barclays Bank Plc | Transaction authentication |
| US20160012408A1 (en) * | 2014-07-09 | 2016-01-14 | Pay(Q)R, LLC | Cloud-based mobile payment system |
| US9336523B2 (en) * | 2014-07-28 | 2016-05-10 | International Business Machines Corporation | Managing a secure transaction |
-
2016
- 2016-04-07 DE DE102016004293.1A patent/DE102016004293A1/de not_active Withdrawn
-
2017
- 2017-04-07 WO PCT/EP2017/000443 patent/WO2017174200A2/de not_active Ceased
- 2017-04-07 EP EP17739189.3A patent/EP3440609A2/de not_active Withdrawn
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150032558A1 (en) * | 2013-07-29 | 2015-01-29 | Exxonmobil Research And Engineering Company | System and method to purchase and dispense fuel and other products using a mobile device with improved user experience |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2017174200A3 (de) | 2017-11-30 |
| WO2017174200A2 (de) | 2017-10-12 |
| DE102016004293A1 (de) | 2017-10-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3440609A2 (de) | Verfahren zur einleitung eines authentifizierungsprozesses, insbesondere geeignet zur personenauthentifizierung im rahmen eines bargeldlosen zahlungsverkehrs, und datenverarbeitungeterminal zur verwendung in einem solchen verfahren | |
| DE60131534T2 (de) | Umfassender Authentifizierungsmechanismus | |
| DE102012214018B3 (de) | Autorisierung eines Nutzers durch ein tragbares Kommunikationsgerät | |
| DE60104411T2 (de) | Verfahren zur übertragung einer zahlungsinformation zwischen einem endgerät und einer dritten vorrichtung | |
| EP2962439B1 (de) | Lesen eines attributs aus einem id-token | |
| DE102012219618B4 (de) | Verfahren zur Erzeugung eines Soft-Tokens, Computerprogrammprodukt und Dienst-Computersystem | |
| DE112013005682T5 (de) | Auf NFC basierendes Fingerdruckbestätigungssystem und -verfahren | |
| DE10224209A1 (de) | Autorisierungseinrichtung-Sicherheitsmodul -Terminal-System | |
| EP1368929B1 (de) | Verfahren zur authentikation | |
| DE102011116489A1 (de) | Mobiles Endgerät, Transaktionsterminal und Verfahren zur Durchführung einer Transaktion an einem Transaktionsterminal mittels eines mobilen Endgeräts | |
| EP4128695B1 (de) | Personalisierter, serverindividueller authentifizierungsmechanismus | |
| EP3246839A1 (de) | Zugangskontrolle mit einem mobilfunkgerät | |
| DE102018005038A1 (de) | Smartcard als Sicherheitstoken | |
| WO2023134166A1 (zh) | 车载支付方法、终端、服务器、系统及介质 | |
| DE102017122799A1 (de) | Verfahren und Anordnung zur Übermittlung von Transaktionsdaten unter Nutzung eines öffentlichen Datennetzes | |
| EP3135546A1 (de) | Autoschlüssel, kommunikationssystem sowie verfahren hierzu | |
| CN106060073B (zh) | 信道密钥协商方法 | |
| EP4295605B1 (de) | Nutzerauthentifizierung unter verwendung zweier unabhängiger sicherheitselemente | |
| EP3641369B1 (de) | Absicherung einer p2p-kommunikation | |
| EP3882796B1 (de) | Nutzerauthentifizierung unter verwendung zweier unabhängiger sicherheitselemente | |
| DE102017006200A1 (de) | Verfahren, Hardware und System zur dynamischen Datenübertragung an ein Blockchain Rechner Netzwerk zur Abspeicherung Persönlicher Daten um diese Teils wieder Blockweise als Grundlage zur End zu Endverschlüsselung verwendet werden um den Prozess der Datensammlung über das Datenübertragungsmodul weitere Daten in Echtzeit von Sensoreinheiten dynamisch aktualisiert werden. Die Blockmodule auf dem Blockchaindatenbanksystem sind unbegrenzt erweiterbar. | |
| EP2661022A2 (de) | Verfahren zur gesicherten Kommunikation zwischen einem mobilen Endgerät und einem Gerät der Gebäudesystemtechnik oder der Türkommunikation | |
| DE102010050195A1 (de) | Lesegerät als elektronischer Ausweis | |
| EP2880810B1 (de) | Authentifizierung eines dokuments gegenüber einem lesegerät | |
| EP2819077A1 (de) | Verfahren zum Freischalten mindestens eines Dienstes im E-Wallet |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20181030 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: BECKMANN, FREDERICK Inventor name: HARTMANN, GEORG Inventor name: HERKENHOFF, SEBASTIAN Inventor name: SEIDEL, KEVIN |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20200709 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN WITHDRAWN |
|
| 18W | Application withdrawn |
Effective date: 20220406 |