ITTO20090121A1 - PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. - Google Patents

PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.

Info

Publication number
ITTO20090121A1
ITTO20090121A1 IT000121A ITTO20090121A ITTO20090121A1 IT TO20090121 A1 ITTO20090121 A1 IT TO20090121A1 IT 000121 A IT000121 A IT 000121A IT TO20090121 A ITTO20090121 A IT TO20090121A IT TO20090121 A1 ITTO20090121 A1 IT TO20090121A1
Authority
IT
Italy
Prior art keywords
procedure
code
payment
password
protection
Prior art date
Application number
IT000121A
Other languages
Italian (it)
Inventor
Alberto Cabodi
Original Assignee
Alberto Cabodi
Drammis Giuseppina
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alberto Cabodi, Drammis Giuseppina filed Critical Alberto Cabodi
Priority to IT000121A priority Critical patent/ITTO20090121A1/en
Publication of ITTO20090121A1 publication Critical patent/ITTO20090121A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)

Description

TITOLO TITLE

Procedura per la protezione delle transazioni effettuate con mezzi di pagamento elettronici. Procedure for the protection of transactions made with electronic means of payment.

<RIASSUNTO PROCEDURA PER LA PROTEZIONE DELLE TRANSAZIONI EFFETTUATE CON MEZZO DI PAGAMENTO ELETTRONICO (ES. CARTA DI>CREDITO. DI DEBITO. O CARTE ELETTRONICHE IN GENERALE ). LA PROCEDURA. DOPO L'INSERIMENTO DEI DATI DEL MEZZO DI <SUMMARY PROCEDURE FOR THE PROTECTION OF TRANSACTIONS MADE BY ELECTRONIC PAYMENT (EX. CREDIT CARD. DEBIT. OR ELECTRONIC CARDS IN GENERAL). THE PROCEDURE. AFTER ENTERING THE DATA OF THE MEANS OF

<DI PASSWORD), SUL DISPOSITIVO PORTATILE DESIGNATO ANTECEDENTEMENTE DAL TITOLARE DEL MEZZO D1 PAGAMENTO.>TALE<PASSWORD DOVRÀ ESSERE INSERITA SUL TERMINALE DI PAGAMENTO>(ES.<POS. VIRTALE O>REALE)<PER PROCEDERE AL PAGAMENTO. SE IL CODICE. PROVENIENTE DAL TERMINALE DI PAGAMENTO. VIENE RICONOSCIUTO DALL'ENTE DESIGNATO A>RICEVERE L'INFORMAZIONE (ES. BANCA O SERVIZI INTERBANCARI). LA TRANSAZIONE PROCEDERA. DIVERSAMENTE VERRA TERMINATA. LA PROCEDURA PREVEDE 3 DIVERSE VARIANTI. <OF PASSWORD), ON THE PORTABLE DEVICE DESIGNATED PREVIOUSLY BY THE HOLDER OF THE MEANS OF PAYMENT.> THIS <PASSWORD MUST BE INSERTED ON THE PAYMENT TERMINAL> (EX. <VIRTAL OR> REAL POS.) <TO PROCEED WITH THE PAYMENT. IF THE CODE. COMING FROM THE PAYMENT TERMINAL. IT IS RECOGNIZED BY THE DESIGNATED BODY TO> RECEIVE THE INFORMATION (EX. BANK OR INTERBANK SERVICES). THE TRANSACTION WILL PROCEED. OTHERWISE IT WILL BE FINISHED. THE PROCEDURE INCLUDES 3 DIFFERENT VARIATIONS.

Descrizione dell'invenzione industriale dal titolo: Description of the industrial invention entitled:

PROCEDURA PER LA PROTEZIONE DELLE TRANSAZIONI EFFETTUATE CON MEZZI D I PAGAMENTO ELETTRONICI PROCEDURE FOR THE PROTECTION OF TRANSACTIONS MADE WITH ELECTRONIC MEANS OF PAYMENT

DESCRIZIONE DESCRIPTION

La procedura oggetto di questo brevetto si riferisce al campo bancario, al fine di proteggere le transazioni effettuate con mezzo di pagamento elettronico. The procedure covered by this patent refers to the banking field, in order to protect the transactions carried out by means of electronic payment.

Questa protezione si basa sul principio di compresenza al momento della transazione del titolo di pagamento e del dispositivo portatile personale (indicato dal titolare), i quali integrano delle azioni al fine di consentire il controllo della legittimità della transazione stessa. This protection is based on the principle of coexistence at the time of the transaction of the payment instrument and of the personal portable device (indicated by the holder), which integrate actions in order to allow the legitimacy of the transaction to be checked.

Dettagli di glossario. Glossary details.

1. Con il termine "mezzo di pagamento" si intende, qui, qualsiasi oggetto che permetta una transazione con trasferimento di fondi senza l'uso della carta-moneta fisica. Esempio: carta di credito, carta di debito, carte elettroniche in generale. 1. The term "means of payment" here means any object that allows a transaction with transfer of funds without the use of physical paper money. Example: credit card, debit card, electronic cards in general.

2. Con il termine "server preposto all'autorizzazione della transazione" si intende,qui, il server che si occupa di smistare attraverso la propria rete le informazioni relative alla transazione stessa e che viene definito dal circuito di appartenenza. D'ora in poi chiamato Server. 2. The term "server responsible for authorizing the transaction" here means the server that is responsible for sorting the information relating to the transaction through its network and which is defined by the circuit to which it belongs. From now on called Server.

3. Con il termine "dispositivo portatile personale" si intende, qui, il dispositivo portatile in grado di trasmettere e ricevere informazioni collegandosi ad un network e che è identificato univocamente da un numero (o codice) il cui uso è considerato personale. Esempio: dispositivi cellulari, PDA. 3. The term "personal portable device" here means the portable device capable of transmitting and receiving information by connecting to a network and which is uniquely identified by a number (or code) whose use is considered personal. Example: cellular devices, PDAs.

A conoscenza dell'inventore non sono note, al momento, delle procedure di controllo dell'uso del mezzo di pagamento per evitarne l'uso fraudolento. Le procedure che sono state brevettate fino ad ora sono differenti e poco usabili. La ricerca è stata fatta sul sito dell'European Patent Office su database World Wide La procedura, di cui si richiede il brevetto, prevede, dopo l'inserimento dei dati del mezzo di pagamento (ad esempio strisciando la carta di credito o inserendone i dati sul sito internet), l'invio da parte del Server di un codice univoco (random ed utilizzabile solo per una quantità di tempo minimo e predefiriito) ad un dispositivo portatile personale, e che si possa utilizzare come password di autorizzazione alla transazione. To the knowledge of the inventor, at the moment, the procedures for controlling the use of the means of payment to avoid its fraudulent use are not known. The procedures that have been patented so far are different and not very usable. The research was carried out on the European Patent Office website on a World Wide database.The procedure, for which the patent is requested, provides, after entering the data of the means of payment (for example by swiping the credit card or entering the data on the website), the sending by the Server of a unique code (random and usable only for a minimum and predefined amount of time) to a personal portable device, and which can be used as a transaction authorization password.

Tale codice-password viene inviato dal Server sul dispositivo portatile designato antecedentemente dal titolare del mezzo di pagamento. This password-code is sent by the Server to the portable device previously designated by the holder of the means of payment.

Tale codice-password dovrà essere inserito sul terminale di pagamento (es. POS, virtuale o reale) per procedere alla transazione. Se il codice viene riconosciuto dall'ente designato a ricevere l'informazione, la transazione procederà, diversamente verrà terminata. La procedura prevede 3 diverse varianti,che si differenziano solo dopo la fase iniziale di inserimento dei dati del mezzo di pagamento: This password-code must be entered on the payment terminal (eg POS, virtual or real) to proceed with the transaction. If the code is recognized by the body designated to receive the information, the transaction will proceed, otherwise it will be terminated. The procedure includes 3 different variants, which differ only after the initial phase of entering the data of the means of payment:

l. Denominabile Input Control. L. Callable Input Control.

I l cliente inserisce la password ricevuta nel messaggio sul terminale di pagamento, virtuale o reale. La password viene inviata al Server e, se viene riconosciuta la corrispondenza, la transazione prosegue. Vedi disegno l delllAllegato Disegni pagina 1 e schema 1 delllAllegato Disegni pagina 2. The customer enters the password received in the message on the payment terminal, virtual or real. The password is sent to the Server and, if the match is recognized, the transaction continues. See drawing l of the Drawings Annex page 1 and diagram 1 of the Drawings Annex page 2.

2. Denominabile Doppio Controllo. 2. Callable Double Check.

Può essere utilizzata per transazioni più complesse, ad esempio sopra una certa cifra che può essere impostata dalla banca o dall'utente. I n questo caso i codici inviati sono 2: It can be used for more complex transactions, for example above a certain amount that can be set by the bank or by the user. In this case the codes sent are 2:

l. Al dispositivo portatile del cliente da inserire sul terminale di pagamento. L. To the customer's portable device to be inserted on the payment terminal.

2. Al terminale di pagamento da digitare sul dispositivo portatile. 2. To the payment terminal to be typed on the portable device.

Le password sono inviate al Server e, se sono riconosciute le corrispondenze, la transazione prosegue. Vedi disegno 2 delllAllegato Disegni pagina l. The passwords are sent to the Server and, if matches are recognized, the transaction continues. See drawing 2 of the Drawings Annex on page l.

3. Denominabile Doppio Controllo B. 3. Callable Double Check B.

La procedura è simile alla precedente con la seguente variante : The procedure is similar to the previous one with the following variation:

- L'operatore che nel punto vendita porta a termine le procedure per il pagamento può avere un suo codice personale (password) attribuitogli in precedenza dalla banca. Tale codice verrà inserito sul terminale di pagamento. Le password sono inviate al Server e, se vengono riconosciute le corrispondenze, la transazione prosegue. Vedi disegno 3 dell'Allegato Disegni pagina l. - The operator who completes the payment procedures at the point of sale can have his own personal code (password) previously assigned by the bank. This code will be entered on the payment terminal. The passwords are sent to the Server and, if matches are recognized, the transaction continues. See drawing 3 of the Drawings Annex page l.

Al fine di rendere più sicuro il sistema il codice ricevuto sul dispositivo portatile può essere corribinato ad un codice fisso di poche cifre già conosciuto dall'utente. Esempio: due cifre del codice fisso più tre cifre del codice random. In order to make the system more secure, the code received on the portable device can be matched to a fixed code of a few digits already known by the user. Example: two digits of the fixed code plus three digits of the random code.

Esempio l di un modo di attuazione della procedura che è oggetto della presente invenzione. Basato sulla variante l della procedura. Example 1 of a way of carrying out the procedure which is the object of the present invention. Based on variant l of the procedure.

Ambientazione: "Paaamento con carta di credito di un acauisto effettuato in un punto vendita ." Setting: "Paaamento with credit card of a purchase made in a point of sale."

Dopo che il commesso ha strisciato la carta di credito il cliente riceve sul cellulare (di cui aveva fornito il numero alla banca al momento della richiesta della carta di credito) un codice numerico di un massimo di 5 cifre tramite un FLASH MESSAGE (un tipo di sms che non resta memorizzato nel box dei messaggi in entrata). I l cliente digita il codice ricevuto sul tastierino del POS. Se il codice corrisponde la transazione prosegue, diversamente viene terminata. After the clerk has swiped the credit card, the customer receives on his mobile phone (whose number he had provided to the bank when requesting the credit card) a numeric code of up to 5 digits via a FLASH MESSAGE (a type of SMS that is not stored in the inbox). The customer enters the code received on the POS keypad. If the code matches, the transaction continues, otherwise it is terminated.

Esempio 2 di un modo di attuazione della procedura che è oggetto della presente invenzione. Basato sulla variante 2 della procedura. Example 2 of a way of carrying out the procedure which is the object of the present invention. Based on variant 2 of the procedure.

Ambientazione: "Paaamento con carta di credito di un acquisto effettuato in un punto vendita, con un i m p o r t o superiore al limite scelto dalla banca per la procedura sem~lificata." Setting: "Pairing by credit card of a purchase made at a point of sale, with an i m p o r t or higher than the limit chosen by the bank for the simplified procedure."

Dopo che il commesso ha strisciato la carta di credito si verificano i seguenti accadimenti : After the salesman swipes the credit card, the following events occur:

l. I l cliente riceve sul cellulare (di cui aveva fornito il numero alla banca al momento della richiesta della carta di credito) un codice numerico di un massimo di 5 cifre tramite un SMS. Il cliente digita il codice ricevuto sul tastierino del POS. L. The customer receives a numeric code of up to 5 digits via SMS on his mobile phone (whose number he had provided to the bank at the time of requesting the credit card). The customer enters the code received on the POS keypad.

2. I 1 commesso riceve un codice sul Pos da digitare sul cellulare del cliente in risposta al messaggio ricevuto. I l commesso in alternativa può dettare il codice al cliente, o inviarlo al cellulare del cliente tramite bluetooth (o similare). 2. The salesman receives a code on the Pos to be typed on the customer's mobile phone in response to the message received. The clerk can alternatively dictate the code to the customer, or send it to the customer's mobile phone via bluetooth (or similar).

3. Se entrambi i codici corrispondono, la transazione prosegue, diversamente viene terminata. 3. If both codes match, the transaction continues, otherwise it is terminated.

Claims (4)

L'invenzione descrive una procedura che ha lo scopo di tutelare dalle frodi le transazioni effettuate con dispositivi elettronici, o comunque con materialità diversa dal contante. l. La tutela è rivolta a tutte le parti coinvolte in quanto permette il controllo che il possesso del documento di pagamento sia nelle mani del titolare (o di chi egli ha deputato o autorizzato). Questo avviene tramite l'invio di un codicepassword sul dispositivo di comunicazione mobile il cui identificativo è stato fornito dal titolare stesso del documento di pagamento. The invention describes a procedure which has the purpose of protecting transactions carried out with electronic devices, or in any case with materiality other than cash, from fraud. L. The protection is aimed at all the parties involved as it allows the control that the possession of the payment document is in the hands of the holder (or whoever he has deputed or authorized). This is done by sending a password code on the mobile communication device whose identification has been provided by the owner of the payment document. 2. I 1 codice-password deve essere generato in maniera univoca, random e deve avere un timeto-live definito. 2. The 1 password-code must be generated uniquely, randomly and must have a defined timeto-live. 3. Se il codice-password non viene digitato sul dispotivo di pagamento entro il time-to-live la procedura sarà terminata. Dopo un numero di tentativi errati l'ente preposto al controllo potrà contattare il cliente o bloccare il servizio. 3. If the password-code is not entered on the payment device within the time-to-live, the procedure will be terminated. After a number of incorrect attempts, the control body may contact the customer or block the service. 4. I 1 brevetto può essere implementato sui server di banche, servizi interbancari o chi per essi in base alla tecnologia deputata più appropriata.4. The 1 patent can be implemented on the servers of banks, interbank services or whoever for them on the basis of the most appropriate technology.
IT000121A 2009-02-20 2009-02-20 PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. ITTO20090121A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
IT000121A ITTO20090121A1 (en) 2009-02-20 2009-02-20 PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
IT000121A ITTO20090121A1 (en) 2009-02-20 2009-02-20 PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.

Publications (1)

Publication Number Publication Date
ITTO20090121A1 true ITTO20090121A1 (en) 2009-05-22

Family

ID=40738562

Family Applications (1)

Application Number Title Priority Date Filing Date
IT000121A ITTO20090121A1 (en) 2009-02-20 2009-02-20 PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.

Country Status (1)

Country Link
IT (1) ITTO20090121A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19718103A1 (en) * 1997-04-29 1998-06-04 Kim Schmitz Data transmission system authorise method e.g. for telebanking
SI21436A (en) * 2003-02-04 2004-08-31 Renderspace - Pristop Interactive D.O.O. Identification system for accessing protected areas
WO2007010541A2 (en) * 2005-07-20 2007-01-25 Backvon Ltd. Method and system for secure redirection of incoming and outgoing multimedia sessions over a data network
WO2007143795A1 (en) * 2006-06-16 2007-12-21 Fmt Worldwide Pty Ltd An authentication system and process

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19718103A1 (en) * 1997-04-29 1998-06-04 Kim Schmitz Data transmission system authorise method e.g. for telebanking
SI21436A (en) * 2003-02-04 2004-08-31 Renderspace - Pristop Interactive D.O.O. Identification system for accessing protected areas
WO2007010541A2 (en) * 2005-07-20 2007-01-25 Backvon Ltd. Method and system for secure redirection of incoming and outgoing multimedia sessions over a data network
WO2007143795A1 (en) * 2006-06-16 2007-12-21 Fmt Worldwide Pty Ltd An authentication system and process

Similar Documents

Publication Publication Date Title
US11620654B2 (en) Methods and apparatus for conducting secure magnetic stripe card transactions with a proximity payment device
AU2015214271B2 (en) Token verification using limited use certificates
CN107004192B (en) Method and apparatus for tokenizing requests via access device
Harb et al. SecureSMSPay: secure SMS mobile payment model
KR101236959B1 (en) System for paying credit card of mobile security click using smart phone and method therefor
CN106462843A (en) Master applet for secure remote payment processing
WO2007076476A2 (en) Methods and systems for two-factor authentication using contactless chip cards or devices and mobile devices or dedicated personal readers
CN109118241A (en) remote variable authentication processing
KR20110094176A (en) The electronic payment application system and payment authorization method
US12293371B2 (en) Systems and methods for authentication based on personal network
KR101384846B1 (en) Simple payment method using mobile terminal
Alhothaily et al. A novel verification method for payment card systems
KR20130034111A (en) Simple payment method using mobile terminal
AU2015358442B2 (en) Methods and apparatus for conducting secure magnetic stripe card transactions with a proximity payment device
CN105096119A (en) Virtual bank system and realization method thereof
Alhothaily et al. Towards more secure cardholder verification in payment systems
US10496985B2 (en) Loading and disbursement of an electronic amount of money
ITTO20090121A1 (en) PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.
KR101990512B1 (en) System for Exchanging and Cash Calculating of Virtual Money and Method Thereof
ES2930849T3 (en) Payment method with a cash card
WO2015036642A1 (en) Mobile payment system and method based on a single use token
CN121079709A (en) Secure remote interaction using portable transaction device
Mladenović et al. EXPANSION OF E-PAYMENT
GB2522235A (en) Cashless payment system
TWM529225U (en) Electronic device