ITTO20090121A1 - PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. - Google Patents
PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS.Info
- Publication number
- ITTO20090121A1 ITTO20090121A1 IT000121A ITTO20090121A ITTO20090121A1 IT TO20090121 A1 ITTO20090121 A1 IT TO20090121A1 IT 000121 A IT000121 A IT 000121A IT TO20090121 A ITTO20090121 A IT TO20090121A IT TO20090121 A1 ITTO20090121 A1 IT TO20090121A1
- Authority
- IT
- Italy
- Prior art keywords
- procedure
- code
- payment
- password
- protection
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims description 20
- 238000005516 engineering process Methods 0.000 claims 1
- 238000010295 mobile communication Methods 0.000 claims 1
- 238000013475 authorization Methods 0.000 description 1
- 230000001413 cellular effect Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 229920001690 polydopamine Polymers 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)
Description
TITOLO TITLE
Procedura per la protezione delle transazioni effettuate con mezzi di pagamento elettronici. Procedure for the protection of transactions made with electronic means of payment.
<RIASSUNTO PROCEDURA PER LA PROTEZIONE DELLE TRANSAZIONI EFFETTUATE CON MEZZO DI PAGAMENTO ELETTRONICO (ES. CARTA DI>CREDITO. DI DEBITO. O CARTE ELETTRONICHE IN GENERALE ). LA PROCEDURA. DOPO L'INSERIMENTO DEI DATI DEL MEZZO DI <SUMMARY PROCEDURE FOR THE PROTECTION OF TRANSACTIONS MADE BY ELECTRONIC PAYMENT (EX. CREDIT CARD. DEBIT. OR ELECTRONIC CARDS IN GENERAL). THE PROCEDURE. AFTER ENTERING THE DATA OF THE MEANS OF
<DI PASSWORD), SUL DISPOSITIVO PORTATILE DESIGNATO ANTECEDENTEMENTE DAL TITOLARE DEL MEZZO D1 PAGAMENTO.>TALE<PASSWORD DOVRÀ ESSERE INSERITA SUL TERMINALE DI PAGAMENTO>(ES.<POS. VIRTALE O>REALE)<PER PROCEDERE AL PAGAMENTO. SE IL CODICE. PROVENIENTE DAL TERMINALE DI PAGAMENTO. VIENE RICONOSCIUTO DALL'ENTE DESIGNATO A>RICEVERE L'INFORMAZIONE (ES. BANCA O SERVIZI INTERBANCARI). LA TRANSAZIONE PROCEDERA. DIVERSAMENTE VERRA TERMINATA. LA PROCEDURA PREVEDE 3 DIVERSE VARIANTI. <OF PASSWORD), ON THE PORTABLE DEVICE DESIGNATED PREVIOUSLY BY THE HOLDER OF THE MEANS OF PAYMENT.> THIS <PASSWORD MUST BE INSERTED ON THE PAYMENT TERMINAL> (EX. <VIRTAL OR> REAL POS.) <TO PROCEED WITH THE PAYMENT. IF THE CODE. COMING FROM THE PAYMENT TERMINAL. IT IS RECOGNIZED BY THE DESIGNATED BODY TO> RECEIVE THE INFORMATION (EX. BANK OR INTERBANK SERVICES). THE TRANSACTION WILL PROCEED. OTHERWISE IT WILL BE FINISHED. THE PROCEDURE INCLUDES 3 DIFFERENT VARIATIONS.
Descrizione dell'invenzione industriale dal titolo: Description of the industrial invention entitled:
PROCEDURA PER LA PROTEZIONE DELLE TRANSAZIONI EFFETTUATE CON MEZZI D I PAGAMENTO ELETTRONICI PROCEDURE FOR THE PROTECTION OF TRANSACTIONS MADE WITH ELECTRONIC MEANS OF PAYMENT
DESCRIZIONE DESCRIPTION
La procedura oggetto di questo brevetto si riferisce al campo bancario, al fine di proteggere le transazioni effettuate con mezzo di pagamento elettronico. The procedure covered by this patent refers to the banking field, in order to protect the transactions carried out by means of electronic payment.
Questa protezione si basa sul principio di compresenza al momento della transazione del titolo di pagamento e del dispositivo portatile personale (indicato dal titolare), i quali integrano delle azioni al fine di consentire il controllo della legittimità della transazione stessa. This protection is based on the principle of coexistence at the time of the transaction of the payment instrument and of the personal portable device (indicated by the holder), which integrate actions in order to allow the legitimacy of the transaction to be checked.
Dettagli di glossario. Glossary details.
1. Con il termine "mezzo di pagamento" si intende, qui, qualsiasi oggetto che permetta una transazione con trasferimento di fondi senza l'uso della carta-moneta fisica. Esempio: carta di credito, carta di debito, carte elettroniche in generale. 1. The term "means of payment" here means any object that allows a transaction with transfer of funds without the use of physical paper money. Example: credit card, debit card, electronic cards in general.
2. Con il termine "server preposto all'autorizzazione della transazione" si intende,qui, il server che si occupa di smistare attraverso la propria rete le informazioni relative alla transazione stessa e che viene definito dal circuito di appartenenza. D'ora in poi chiamato Server. 2. The term "server responsible for authorizing the transaction" here means the server that is responsible for sorting the information relating to the transaction through its network and which is defined by the circuit to which it belongs. From now on called Server.
3. Con il termine "dispositivo portatile personale" si intende, qui, il dispositivo portatile in grado di trasmettere e ricevere informazioni collegandosi ad un network e che è identificato univocamente da un numero (o codice) il cui uso è considerato personale. Esempio: dispositivi cellulari, PDA. 3. The term "personal portable device" here means the portable device capable of transmitting and receiving information by connecting to a network and which is uniquely identified by a number (or code) whose use is considered personal. Example: cellular devices, PDAs.
A conoscenza dell'inventore non sono note, al momento, delle procedure di controllo dell'uso del mezzo di pagamento per evitarne l'uso fraudolento. Le procedure che sono state brevettate fino ad ora sono differenti e poco usabili. La ricerca è stata fatta sul sito dell'European Patent Office su database World Wide La procedura, di cui si richiede il brevetto, prevede, dopo l'inserimento dei dati del mezzo di pagamento (ad esempio strisciando la carta di credito o inserendone i dati sul sito internet), l'invio da parte del Server di un codice univoco (random ed utilizzabile solo per una quantità di tempo minimo e predefiriito) ad un dispositivo portatile personale, e che si possa utilizzare come password di autorizzazione alla transazione. To the knowledge of the inventor, at the moment, the procedures for controlling the use of the means of payment to avoid its fraudulent use are not known. The procedures that have been patented so far are different and not very usable. The research was carried out on the European Patent Office website on a World Wide database.The procedure, for which the patent is requested, provides, after entering the data of the means of payment (for example by swiping the credit card or entering the data on the website), the sending by the Server of a unique code (random and usable only for a minimum and predefined amount of time) to a personal portable device, and which can be used as a transaction authorization password.
Tale codice-password viene inviato dal Server sul dispositivo portatile designato antecedentemente dal titolare del mezzo di pagamento. This password-code is sent by the Server to the portable device previously designated by the holder of the means of payment.
Tale codice-password dovrà essere inserito sul terminale di pagamento (es. POS, virtuale o reale) per procedere alla transazione. Se il codice viene riconosciuto dall'ente designato a ricevere l'informazione, la transazione procederà, diversamente verrà terminata. La procedura prevede 3 diverse varianti,che si differenziano solo dopo la fase iniziale di inserimento dei dati del mezzo di pagamento: This password-code must be entered on the payment terminal (eg POS, virtual or real) to proceed with the transaction. If the code is recognized by the body designated to receive the information, the transaction will proceed, otherwise it will be terminated. The procedure includes 3 different variants, which differ only after the initial phase of entering the data of the means of payment:
l. Denominabile Input Control. L. Callable Input Control.
I l cliente inserisce la password ricevuta nel messaggio sul terminale di pagamento, virtuale o reale. La password viene inviata al Server e, se viene riconosciuta la corrispondenza, la transazione prosegue. Vedi disegno l delllAllegato Disegni pagina 1 e schema 1 delllAllegato Disegni pagina 2. The customer enters the password received in the message on the payment terminal, virtual or real. The password is sent to the Server and, if the match is recognized, the transaction continues. See drawing l of the Drawings Annex page 1 and diagram 1 of the Drawings Annex page 2.
2. Denominabile Doppio Controllo. 2. Callable Double Check.
Può essere utilizzata per transazioni più complesse, ad esempio sopra una certa cifra che può essere impostata dalla banca o dall'utente. I n questo caso i codici inviati sono 2: It can be used for more complex transactions, for example above a certain amount that can be set by the bank or by the user. In this case the codes sent are 2:
l. Al dispositivo portatile del cliente da inserire sul terminale di pagamento. L. To the customer's portable device to be inserted on the payment terminal.
2. Al terminale di pagamento da digitare sul dispositivo portatile. 2. To the payment terminal to be typed on the portable device.
Le password sono inviate al Server e, se sono riconosciute le corrispondenze, la transazione prosegue. Vedi disegno 2 delllAllegato Disegni pagina l. The passwords are sent to the Server and, if matches are recognized, the transaction continues. See drawing 2 of the Drawings Annex on page l.
3. Denominabile Doppio Controllo B. 3. Callable Double Check B.
La procedura è simile alla precedente con la seguente variante : The procedure is similar to the previous one with the following variation:
- L'operatore che nel punto vendita porta a termine le procedure per il pagamento può avere un suo codice personale (password) attribuitogli in precedenza dalla banca. Tale codice verrà inserito sul terminale di pagamento. Le password sono inviate al Server e, se vengono riconosciute le corrispondenze, la transazione prosegue. Vedi disegno 3 dell'Allegato Disegni pagina l. - The operator who completes the payment procedures at the point of sale can have his own personal code (password) previously assigned by the bank. This code will be entered on the payment terminal. The passwords are sent to the Server and, if matches are recognized, the transaction continues. See drawing 3 of the Drawings Annex page l.
Al fine di rendere più sicuro il sistema il codice ricevuto sul dispositivo portatile può essere corribinato ad un codice fisso di poche cifre già conosciuto dall'utente. Esempio: due cifre del codice fisso più tre cifre del codice random. In order to make the system more secure, the code received on the portable device can be matched to a fixed code of a few digits already known by the user. Example: two digits of the fixed code plus three digits of the random code.
Esempio l di un modo di attuazione della procedura che è oggetto della presente invenzione. Basato sulla variante l della procedura. Example 1 of a way of carrying out the procedure which is the object of the present invention. Based on variant l of the procedure.
Ambientazione: "Paaamento con carta di credito di un acauisto effettuato in un punto vendita ." Setting: "Paaamento with credit card of a purchase made in a point of sale."
Dopo che il commesso ha strisciato la carta di credito il cliente riceve sul cellulare (di cui aveva fornito il numero alla banca al momento della richiesta della carta di credito) un codice numerico di un massimo di 5 cifre tramite un FLASH MESSAGE (un tipo di sms che non resta memorizzato nel box dei messaggi in entrata). I l cliente digita il codice ricevuto sul tastierino del POS. Se il codice corrisponde la transazione prosegue, diversamente viene terminata. After the clerk has swiped the credit card, the customer receives on his mobile phone (whose number he had provided to the bank when requesting the credit card) a numeric code of up to 5 digits via a FLASH MESSAGE (a type of SMS that is not stored in the inbox). The customer enters the code received on the POS keypad. If the code matches, the transaction continues, otherwise it is terminated.
Esempio 2 di un modo di attuazione della procedura che è oggetto della presente invenzione. Basato sulla variante 2 della procedura. Example 2 of a way of carrying out the procedure which is the object of the present invention. Based on variant 2 of the procedure.
Ambientazione: "Paaamento con carta di credito di un acquisto effettuato in un punto vendita, con un i m p o r t o superiore al limite scelto dalla banca per la procedura sem~lificata." Setting: "Pairing by credit card of a purchase made at a point of sale, with an i m p o r t or higher than the limit chosen by the bank for the simplified procedure."
Dopo che il commesso ha strisciato la carta di credito si verificano i seguenti accadimenti : After the salesman swipes the credit card, the following events occur:
l. I l cliente riceve sul cellulare (di cui aveva fornito il numero alla banca al momento della richiesta della carta di credito) un codice numerico di un massimo di 5 cifre tramite un SMS. Il cliente digita il codice ricevuto sul tastierino del POS. L. The customer receives a numeric code of up to 5 digits via SMS on his mobile phone (whose number he had provided to the bank at the time of requesting the credit card). The customer enters the code received on the POS keypad.
2. I 1 commesso riceve un codice sul Pos da digitare sul cellulare del cliente in risposta al messaggio ricevuto. I l commesso in alternativa può dettare il codice al cliente, o inviarlo al cellulare del cliente tramite bluetooth (o similare). 2. The salesman receives a code on the Pos to be typed on the customer's mobile phone in response to the message received. The clerk can alternatively dictate the code to the customer, or send it to the customer's mobile phone via bluetooth (or similar).
3. Se entrambi i codici corrispondono, la transazione prosegue, diversamente viene terminata. 3. If both codes match, the transaction continues, otherwise it is terminated.
Claims (4)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IT000121A ITTO20090121A1 (en) | 2009-02-20 | 2009-02-20 | PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IT000121A ITTO20090121A1 (en) | 2009-02-20 | 2009-02-20 | PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| ITTO20090121A1 true ITTO20090121A1 (en) | 2009-05-22 |
Family
ID=40738562
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| IT000121A ITTO20090121A1 (en) | 2009-02-20 | 2009-02-20 | PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. |
Country Status (1)
| Country | Link |
|---|---|
| IT (1) | ITTO20090121A1 (en) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19718103A1 (en) * | 1997-04-29 | 1998-06-04 | Kim Schmitz | Data transmission system authorise method e.g. for telebanking |
| SI21436A (en) * | 2003-02-04 | 2004-08-31 | Renderspace - Pristop Interactive D.O.O. | Identification system for accessing protected areas |
| WO2007010541A2 (en) * | 2005-07-20 | 2007-01-25 | Backvon Ltd. | Method and system for secure redirection of incoming and outgoing multimedia sessions over a data network |
| WO2007143795A1 (en) * | 2006-06-16 | 2007-12-21 | Fmt Worldwide Pty Ltd | An authentication system and process |
-
2009
- 2009-02-20 IT IT000121A patent/ITTO20090121A1/en unknown
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19718103A1 (en) * | 1997-04-29 | 1998-06-04 | Kim Schmitz | Data transmission system authorise method e.g. for telebanking |
| SI21436A (en) * | 2003-02-04 | 2004-08-31 | Renderspace - Pristop Interactive D.O.O. | Identification system for accessing protected areas |
| WO2007010541A2 (en) * | 2005-07-20 | 2007-01-25 | Backvon Ltd. | Method and system for secure redirection of incoming and outgoing multimedia sessions over a data network |
| WO2007143795A1 (en) * | 2006-06-16 | 2007-12-21 | Fmt Worldwide Pty Ltd | An authentication system and process |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11620654B2 (en) | Methods and apparatus for conducting secure magnetic stripe card transactions with a proximity payment device | |
| AU2015214271B2 (en) | Token verification using limited use certificates | |
| CN107004192B (en) | Method and apparatus for tokenizing requests via access device | |
| Harb et al. | SecureSMSPay: secure SMS mobile payment model | |
| KR101236959B1 (en) | System for paying credit card of mobile security click using smart phone and method therefor | |
| CN106462843A (en) | Master applet for secure remote payment processing | |
| WO2007076476A2 (en) | Methods and systems for two-factor authentication using contactless chip cards or devices and mobile devices or dedicated personal readers | |
| CN109118241A (en) | remote variable authentication processing | |
| KR20110094176A (en) | The electronic payment application system and payment authorization method | |
| US12293371B2 (en) | Systems and methods for authentication based on personal network | |
| KR101384846B1 (en) | Simple payment method using mobile terminal | |
| Alhothaily et al. | A novel verification method for payment card systems | |
| KR20130034111A (en) | Simple payment method using mobile terminal | |
| AU2015358442B2 (en) | Methods and apparatus for conducting secure magnetic stripe card transactions with a proximity payment device | |
| CN105096119A (en) | Virtual bank system and realization method thereof | |
| Alhothaily et al. | Towards more secure cardholder verification in payment systems | |
| US10496985B2 (en) | Loading and disbursement of an electronic amount of money | |
| ITTO20090121A1 (en) | PROCEDURE FOR THE PROTECTION OF TRANSACTIONS CARRIED OUT WITH ELECTRONIC PAYMENT MEANS. | |
| KR101990512B1 (en) | System for Exchanging and Cash Calculating of Virtual Money and Method Thereof | |
| ES2930849T3 (en) | Payment method with a cash card | |
| WO2015036642A1 (en) | Mobile payment system and method based on a single use token | |
| CN121079709A (en) | Secure remote interaction using portable transaction device | |
| Mladenović et al. | EXPANSION OF E-PAYMENT | |
| GB2522235A (en) | Cashless payment system | |
| TWM529225U (en) | Electronic device |