WO2001008055A9 - Transaction sure et terminal permettant d'executer ladite transaction - Google Patents

Transaction sure et terminal permettant d'executer ladite transaction

Info

Publication number
WO2001008055A9
WO2001008055A9 PCT/AU2000/000880 AU0000880W WO0108055A9 WO 2001008055 A9 WO2001008055 A9 WO 2001008055A9 AU 0000880 W AU0000880 W AU 0000880W WO 0108055 A9 WO0108055 A9 WO 0108055A9
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
data
biometric data
person
card
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/AU2000/000880
Other languages
English (en)
Other versions
WO2001008055A1 (fr
Inventor
Barry John Taylor
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Grosvenor Leisure Inc
Original Assignee
Grosvenor Leisure Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from AUPQ1786A external-priority patent/AUPQ178699A0/en
Priority claimed from AUPQ7029A external-priority patent/AUPQ702900A0/en
Application filed by Grosvenor Leisure Inc filed Critical Grosvenor Leisure Inc
Priority to AU59542/00A priority Critical patent/AU5954200A/en
Publication of WO2001008055A1 publication Critical patent/WO2001008055A1/fr
Anticipated expiration legal-status Critical
Publication of WO2001008055A9 publication Critical patent/WO2001008055A9/fr
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1008Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/30Individual registration on entry or exit not involving the use of a pass
    • G07C9/32Individual registration on entry or exit not involving the use of a pass in combination with an identity check
    • G07C9/37Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition

Definitions

  • THIS INVENTION relates to the provision of a secure method for the positive identification of an individual, particularly as a means for the authentication of a purchase of goods or services or for cash withdrawals over a telecommunication medium.
  • the invention finds particular, but not exclusive, use as a means for secure purchasing of goods or services over a visual medium such as television or other visual display medium or the Internet or as part of an EFTPOS system (electronic funds transfer at point of sale).
  • EFTPOS system electronic funds transfer at point of sale.
  • the invention is not to be regarded as limited to such applications and includes within its scope the secure transfer of any data between two or more distanced stations.
  • a significant disadvantage of telecommunication purchasing is that it does not provide positive identification of individuals which is important for preventing unauthorized access to bank account or credit card details by a person wishing to purchase goods or services fraudulently.
  • a code specific for a particular account are known as PIN numbers (Personal Identification Number) and are used in combination with the particular account number.
  • PIN numbers Personal Identification Number
  • PIN and account numbers are not dependent on any cross-checking to ensure that they are being quoted over the telecommunication medium by the true proprietor of that PIN number and its associated credit card or bank account, this type of secure transaction is not too difficult to circumvent.
  • both the user's account identification and PIN number are stored on the card. While this data is encoded, the card can be easily duplicated and then used fraudulently in at least two ways:
  • a transaction can be completed, without a signature or PIN number, by several methods including over the telephone and the Internet using the card number, card name and expiry date.
  • biometric techniques include fingerprint analysis, thermograms and DNA analysis. These methodologies are considered less vulnerable to mistaken identity.
  • One such method includes comparing the biometric data on a card proffered by an individual to a previously created database of biometric data of authorized individuals.
  • this system can still be foiled by individuals who have obtained a biometric card from its rightful owner.
  • a fraudulent user of the card may partially duplicate the card, retaining any credit details but substituting his/her own biometric data for that of the rightful owner of the card.
  • the data obtained from the individual is usually compared to a vast remote databank of such information which is usually difficult and/or slow to locate and access.
  • a method for a secure transfer of data over a telecommunication medium including:
  • said validation means includes biometric data of said person but, more preferably, includes only a part of said biometric data together with a date and time stamp.
  • said validation means includes:
  • identification means adapted for carriage with said person, said identification means containing said unique description
  • said encryption key is determined from only a part of said biometric data.
  • said biometric data is a fingerprint analysis.
  • said identification means is a card of the type capable of holding information in a machine-readable form.
  • said verification biometric data is transmitted to a remote databank for further comparison with biometric data held in said databank.
  • said person attends a point of issue for said identification means, such as a bank, where normal identification procedures for banking or credit card facilities must be met before said identification means is issued.
  • said identification means such as a bank
  • said transmission means includes a terminal remote from said party whereby said person can supply said data to said party and which includes a cellular telephone or wireless data transmission link.
  • a terminal for use in a method for a secure transfer of data as hereinbefore described, said terminal including: transmission means to transmit identification details relevant to said person to said party; and
  • said transmission means further includes a credit or debit card slot assembly.
  • said facility includes:
  • reading means to read said identification means
  • decoding means to obtain biometric data from said identification means
  • comparison means to compare said biometric data with said verification biometric data
  • authentication means to authenticate said transfer of data.
  • said procuring means is a fingerprint reader.
  • said reading means is a smart card slot assembly wherein said smart card contains said biometric data.
  • said reading means is, or is incorporated as part of, a computer, mobile telephone, EFTPOS terminal, ATM, or similar terminal.
  • said identification means is preferably incorporated into the SIM card of the mobile telephone.
  • said facility further includes a printout means to produce a hard copy for recording details of said transfer of data.
  • said printout means is a printer either integral with, or separate from, said facility.
  • said printout means is located within said smart card slot assembly.
  • a print head assembly which may be of a mechanical, thermal, laser or inkjet type, prints a receipt when the receipt is entered (or withdrawn) from the slot assembly subsequent to the completion of the transfer of data and removal of the smart card from the slot assembly.
  • a sensor of either optical or magnetic type detects the presence of the inserted blank receipt and activates the printing process.
  • said receipt is a single, duplicate or triplicate receipt in the form of a "tear off pad”.
  • said receipt is a multiple copy receipt of comparable size to a credit or debit card.
  • said receipt is in triplicate.
  • FIG. 1 is a diagrammatic simplistic representation of all features of the present invention
  • FIG. 2a is a top plan view schematic representation of the terminal of the present invention.
  • FIG. 2b is a top edge view schematic representation of the terminal of FIG. 2a.
  • FIG. 1 there is a central processing unit (1) connected to a cellular telecommunications network (2).
  • a fingerprint reader (3) is connected to a smart card (4) issuing terminal (5) which can communicate with the network (2).
  • a transaction terminal (6) placed at a merchant's place of business, is also in communication with the network (2).
  • the terminal (6) includes a keyboard (7) to enter details of a transaction, a screen (8) to display the thus-entered details, a fingerprint reader (9), a smart card reader assembly (10) and a printhead assembly (not illustrated) incorporated within the card reader assembly (10).
  • the operating software of the terminal (6) includes code to decrypt encrypted information read from the smart card (4).
  • An individual wishing to undertake a secure financial transaction using a machine-readable card first obtains a card which incorporates encrypted biometric and financial data of that individual. This is achieved by presenting him- or herself to an institution such as a bank which issues machine-readable "smart" cards. As is usual when applying for a credit or debit card at such an institution, the individual must first provide positive identification which meets the requirements of the institution before proceeding.
  • biometric data in particular, fingerprint data
  • fingerprint data of the individual is taken at the institution using any suitable fingerprint reader known in the art. Although not essential, data can be taken from two fingerprints to minimize any subsequent false rejection that may occur when the present invention is in use at a merchant's place of business.
  • This encrypted biometric data and the financial details of the individual are stored in the memory of the smart card.
  • the card (4) is placed in the reader assembly (10) of the terminal (6) whereby the value of the transaction is enter by the merchant using the keyboard (7).
  • the value of the purchase is displayed on the visual display screen (8).
  • the account details and encrypted biometric data are also read by the terminal (6).
  • the appropriate fingerprint of the individual is then taken at the fingerprint reader (9) of the terminal (6) from which the encryption key is determined.
  • the encrypted fingerprint data read from the card (4) is then decrypted using the encryption key just determined and the thus-decoded fingerprint data from the card (4) is compared with the fingerprint data obtained at the terminal (6); if the thus-read fingerprint data is identical with that decoded from the card (4), identification is deemed positive and the financial transaction proceeds. If the comparison is deemed negative, the customer represents the finger, or alternative finger if two such fingerprints have been stored on the card (4), for a second scan whereby the comparison process described above is repeated. Although this procedure could be repeated several times, in practice, it is expected that the terminal (6) will be set to allow only a maximum of three consecutive attempts to obtain the verification biometric data and compare with the biometric data included within the smart card (4). If validation does not occur within those three attempts, the identification is deemed negative.
  • a receipt is inserted in the reader/printer slot (10) and the details of the transaction are recorded on the receipt. Details of the transaction are also transmitted to the central processing facilities (1) for record purposes.
  • the method and terminal of the present invention are particularly suitable for point of sale purchasing of goods or services in all markets.
  • the terminal can be a self-contained stand-alone unit, or used in cooperation with a palmtop, laptop or desktop computer or any other unit which includes a visual display unit.
  • the terminal of the present invention can utilise any convenient telecommunication network, and can be any combination of cellular, satellite, microwave or hard wire telephone or other communication network although, preferably, the terminal will be a wireless communication device incorporating the functionality and convenience of a mobile cellular telephone.
  • secure transfer features of the present invention can be attached to existing ATM machines (Automatic Teller Machines) thus increasing the security of withdrawals therefrom.
  • Fraudulent use of a credit or debit card can be eliminated. Although a partial duplicate of smart card data can be made keeping the credit data, replacing biometric data of the true owner of the card with that of the fraudulent user is insufficient to create a valid card as the encryption key is different being based on the original biometric data.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Human Computer Interaction (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

L'invention concerne un procédé et un appareil permettant d'identifier, de manière positive, un individu qui utilise des moyens surs pour acheter des marchandises ou des services sur un support visuel, tel qu'une télévision, Internet, et des systèmes de transfert électronique de fonds au niveau du point de vente (EFTPOS). L'appareil est un terminal (6) point de vente, qui comprend un clavier (7), un écran (8), un lecteur d'empreintes (9), un ensemble lecteur (10) de carte à puce, et un ensemble de tête d'impression incorporé dans ledit ensemble lecteur (10) de carte à puce. Le logiciel d'exploitation du terminal (6) comprend un code permettant de décrypter des informations cryptées lues à partir de la carte à puce (4). Un individu qui souhaite effectuer une transaction financière sure obtient d'abord une carte à puce (4) incorporant des données biométriques et des données financières cryptées relatives audit individu. Au niveau du point d'achat désiré, la carte (4) est placée dans l'ensemble lecteur (10) du terminal (6). Les détails de compte et les données biométriques cryptées sont lues par le terminal (6). Les empreintes digitales appropriées de l'individu sont ensuite prises au niveau du lecteur d'empreintes (9) du terminal (6), à partir duquel on détermine la clé de cryptage. Les données d'empreintes digitales cryptées lues à partir de la carte (4) sont ensuite décryptées à l'aide de la clé de décryptage qui vient d'être déterminée, et les données d'empreintes digitales décodées à partir de la carte (4) sont comparées avec les données d'empreintes digitales obtenues au niveau du terminal (6). Si les données d'empreintes digitales ainsi lues sont identiques à celles décodées à partir de la carte (4), l'identification est considérée comme positive et la transaction financière peut s'exécuter.
PCT/AU2000/000880 1999-07-23 2000-07-21 Transaction sure et terminal permettant d'executer ladite transaction Ceased WO2001008055A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
AU59542/00A AU5954200A (en) 1999-07-23 2000-07-21 Secure transaction and terminal therefor

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
AUPQ1786 1999-07-23
AUPQ1786A AUPQ178699A0 (en) 1999-07-23 1999-07-23 Secure transaction and terminal therefor
AUPQ7029 2000-04-20
AUPQ7029A AUPQ702900A0 (en) 2000-04-20 2000-04-20 Secure biometric loop

Publications (2)

Publication Number Publication Date
WO2001008055A1 WO2001008055A1 (fr) 2001-02-01
WO2001008055A9 true WO2001008055A9 (fr) 2002-09-06

Family

ID=25646109

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/AU2000/000880 Ceased WO2001008055A1 (fr) 1999-07-23 2000-07-21 Transaction sure et terminal permettant d'executer ladite transaction

Country Status (1)

Country Link
WO (1) WO2001008055A1 (fr)

Families Citing this family (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
PL355475A1 (en) 2000-02-21 2004-05-04 Trek 2000 International Ltd. A portable data storage device
US6453301B1 (en) * 2000-02-23 2002-09-17 Sony Corporation Method of using personal device with internal biometric in conducting transactions over a network
US6950939B2 (en) 2000-12-08 2005-09-27 Sony Corporation Personal transaction device with secure storage on a removable memory device
US7251633B2 (en) 2000-12-11 2007-07-31 Sony Corporation Method or system for executing deferred transactions
SE0100598L (sv) * 2001-02-22 2002-08-23 Flink Administration Ab Anläggning för genomförande av betalningsuppdrag
CO5070684A1 (es) * 2001-05-04 2001-08-28 Leon Carlos Guillerm Velasquez Metodo de identificacion plena personal
ATE335236T1 (de) 2001-06-28 2006-08-15 Trek 2000 Int Ltd Verfahren und einrichtungen zum datentransfer
TWI246028B (en) * 2001-06-28 2005-12-21 Trek 2000 Int Ltd A portable device having biometrics-based authentication capabilities
WO2003003295A1 (fr) 2001-06-28 2003-01-09 Trek 2000 International Ltd. Dispositif portable comportant des fonctions d'authentification biometrique
DE10135527A1 (de) 2001-07-20 2003-02-13 Infineon Technologies Ag Mobilstation eines Mobilkommunikationssystems und Verfahren zum Zugreifen auf einen Dienst und/oder einen Datensatz im Bereitschaftsmodus der Mobilstation
US20030046247A1 (en) * 2001-08-31 2003-03-06 Stiasny Janos G. Cardholder transaction control methods, apparatus, signals and media
GB2382207A (en) * 2001-11-19 2003-05-21 Muhammad Alhamdani Fingerprint recognition
GB0218898D0 (en) * 2002-08-14 2002-09-25 Scient Generics Ltd Authenticated objects
GB2398151B (en) 2002-05-13 2005-06-01 Trek 2000 Int Ltd System and apparatus for compressing and decompressing data stored to a portable data storage device
TW588243B (en) 2002-07-31 2004-05-21 Trek 2000 Int Ltd System and method for authentication
US7207480B1 (en) * 2004-09-02 2007-04-24 Sprint Spectrum L.P. Certified digital photo authentication system
FR2882878B1 (fr) * 2005-03-07 2007-04-27 Christophe Richard Dispositif, procede et systeme de securite pour transactions financieres, reposant sur l'identification d'un individu grace a son profil biometrique, et utilisant une carte a microprocesseur
DE102005018561A1 (de) * 2005-04-21 2006-11-02 Giesecke & Devrient Gmbh Verfahren zum Betreiben eines Systems mit einem tragbaren Datenträger und einem Endgerät
EP1878199A1 (fr) 2005-05-03 2008-01-16 Lincor Solutions Limited Systeme de divertissement et de gestion d'informations
WO2008113110A1 (fr) * 2007-03-16 2008-09-25 Microlatch Pty Ltd Méthode et appareil d'exécution d'un processus de transaction utilisant une station de vérification
CN110503430A (zh) * 2019-07-15 2019-11-26 捷德(中国)信息科技有限公司 交易处理方法、安全元件及智能卡

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO1991006920A1 (fr) * 1989-11-02 1991-05-16 Tms, Incorporated Procedes et systeme d'identification automatique d'empreintes digitales ne tenant pas compte des petits details
US5764789A (en) * 1994-11-28 1998-06-09 Smarttouch, Llc Tokenless biometric ATM access system
US5870723A (en) * 1994-11-28 1999-02-09 Pare, Jr.; David Ferrin Tokenless biometric transaction authorization method and system
US5657389A (en) * 1995-05-08 1997-08-12 Image Data, Llc Positive identification system and method
AUPO084896A0 (en) * 1996-07-05 1996-07-25 Dynamic Data Systems Pty Ltd Identification storage medium and system and method for providing access to authorised users
EP0924655B2 (fr) * 1997-12-22 2007-08-29 TRW Inc. Contrôle d'accès à des portes ou à des machines à l'aide de comparaisons d'empreintes digitales

Also Published As

Publication number Publication date
WO2001008055A1 (fr) 2001-02-01

Similar Documents

Publication Publication Date Title
EP1305749A1 (fr) Procede biometrique sur d'identification
US20060174134A1 (en) Secure steganographic biometric identification
WO2001008055A9 (fr) Transaction sure et terminal permettant d'executer ladite transaction
US6182894B1 (en) Systems and methods for authorizing a transaction card
CA2665417C (fr) Procedes et appareil d'authentification de serveur mandataire
US4357529A (en) Multilevel security apparatus and method
US4304990A (en) Multilevel security apparatus and method
US4328414A (en) Multilevel security apparatus and method
EP0729120A2 (fr) Méthode et dispositif pour la validation de documents imprimés à partir de leur image
US20070185820A1 (en) Multi-account security verification system with a virtual account and linked multiple real accounts
US8152056B2 (en) Secure cards and methods
KR20010025234A (ko) 지문정보를 이용한 카드거래 인증방법 및 그 시스템
US20070078780A1 (en) Bio-conversion system for banking and merchant markets
US20120091199A1 (en) Multi-account card system
AU2001255978B2 (en) Secure biometric identification
AU2001255978A1 (en) Secure biometric identification
JP2002158655A (ja) 認証装置、照合装置およびそれらを接続した電子認証システム
WO2007006084A1 (fr) Appareil et procédé de traitement de carte
RU2208247C2 (ru) Способ аутентификации пользователя пластиковой карточки
KR100655696B1 (ko) 지문인식을 이용한 금융카드 보안방법 및 그 시스템
HK1058979B (en) Method and device for secure biometric identification
JP2002190005A (ja) 多機能icカード
KR20020033274A (ko) 아이시카드타입 신용카드와 지문인식기를 통한 신용카드결재승인 시스템
HK1113420B (en) Secure cards and methods

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DE DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG US UZ VN YU ZA ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
REG Reference to national code

Ref country code: DE

Ref legal event code: 8642

122 Ep: pct application non-entry in european phase
COP Corrected version of pamphlet

Free format text: PAGES 1/2-2/2, DRAWINGS, REPLACED BY NEW PAGES 1/2-2/2; DUE TO LATE TRANSMITTAL BY THE RECEIVING OFFICE

NENP Non-entry into the national phase in:

Ref country code: JP