WO2010071904A2 - Security measures for credit card - Google Patents

Security measures for credit card Download PDF

Info

Publication number
WO2010071904A2
WO2010071904A2 PCT/ZA2009/000111 ZA2009000111W WO2010071904A2 WO 2010071904 A2 WO2010071904 A2 WO 2010071904A2 ZA 2009000111 W ZA2009000111 W ZA 2009000111W WO 2010071904 A2 WO2010071904 A2 WO 2010071904A2
Authority
WO
WIPO (PCT)
Prior art keywords
card
code
generating
related transactions
dynamic authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/ZA2009/000111
Other languages
English (en)
French (fr)
Other versions
WO2010071904A9 (en
WO2010071904A3 (en
Inventor
Grant Paul Weideman
Selvanathan Narainsamy
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Radio Surveillance Security SA Pty Ltd
Original Assignee
Radio Surveillance Security SA Pty Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Radio Surveillance Security SA Pty Ltd filed Critical Radio Surveillance Security SA Pty Ltd
Priority to SG2011044435A priority Critical patent/SG172224A1/en
Priority to CN200980151333.1A priority patent/CN102301384A/zh
Priority to EP09813865A priority patent/EP2380122A2/de
Priority to AU2009327344A priority patent/AU2009327344A1/en
Priority to CA2747249A priority patent/CA2747249A1/en
Publication of WO2010071904A2 publication Critical patent/WO2010071904A2/en
Publication of WO2010071904A3 publication Critical patent/WO2010071904A3/en
Publication of WO2010071904A9 publication Critical patent/WO2010071904A9/en
Priority to ZA2011/00774A priority patent/ZA201100774B/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/102Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measure for e-commerce

Definitions

  • This invention relates to security measures for bank card related transactions.
  • 'card' as applied to card related transactions shall be understood to include any type of 'smartcard' which includes any form of electronic processor and/or electronic memory and/or electronic storage capacity.
  • the code is usually intercepted while being verified by a card reading machine. This may be accomplished by adding software to the machine (or another handheld device) which reads the card and intercepts/copies the code without otherwise affecting the transaction. The user is therefore unaware of this interception. It is an object of this invention to provide an alternative to the single programmed static authentication code on credit and debit cards or similar card related transactions.
  • a method of generating a dynamic authentication code for card related transactions includes the steps of loading algorithm generating software onto the card to generate a time and/or date specific code when used in combination with a card transaction machine, and synchronising the generated code with one similarly generated at a remote terminal.
  • suitable algorithm-generating and/or multifactor authentication software is loaded onto a card such as a credit card.
  • the software may be loaded onto the micro-chip or any similar storage means and/or memory of the card, or wherever suitable.
  • the software may be interpreted by a card reading machine such as an ATM or a card transacting terminal to generate a time and date specific code. This code may be sent to a remote terminal, on which the same software may be running and on which an identical code may be generated on similar terms.
  • a card reading machine such as an ATM or a card transacting terminal
  • This code may be sent to a remote terminal, on which the same software may be running and on which an identical code may be generated on similar terms.
  • the remote terminal may verify the authenticity of the card and allow the transaction to proceed as it would normally.
  • the software loaded onto the card may be any suitable multi factor authentication software.
  • the card transaction terminal transmits a signal to the remote terminal which responds by sending a time and/or the date according to the terminal or the time zone in which the remote terminal is located.
  • This signal and subsequent time and date ensures that the time and/or date on the remote terminal and the card transaction terminal are identical so that an identical or suitably matched code may be generated.
  • the method may be adapted to generate a new code for each new transaction, which may be valid for a specific time interval, for instance three minutes. This variation should negate any delays caused by time-and-date verification or similar communication interruptions and should ensure that the codes are always identical.
  • multi-factor authentication software 12 is loaded onto a credit or debit card 10.
  • multi factor authentication software is used but any suitable algorithm generating authentication software may be used.
  • the software may be loaded onto the microchip (not shown) of the card. It may be possible and necessary for the software to be loaded on other storage means in future depending on the evolution of card transactions.
  • the software is also loaded onto a remote terminal 20.
  • the card terminal transmits a signal or a 'ping' 18 to the remote terminal 20 located at a banking institution or the like (not shown).
  • the remote terminal responds by sending back a signal 18 containing the time and/or date to the card terminal
  • the reasoning behind this step is to ensure that the terminals are synchronised with regards to the time and date, irrespective of time zone differences or whether the machine's time and date are set accurately.
  • the card terminal In the next step that the card terminal reads the software from the card and interprets it, taking the time and date into account, to generate a code 24 unique to the card for that specific time and/or date. Once the card terminal has generated the code it transmits the code 28 to the remote terminal where it is decrypted and interpreted to verify whether it is valid or not. If the codes satisfies the necessary criteria the remote terminal transmits a signal for receipt by the card terminal to authorise the transaction.
  • this whole method takes place in a matter of seconds. It is however envisioned that a code may be time interval generated and that a code will be valid for a few minutes to ensure that communication delays or transaction traffic does not affect the generation and verification of codes.
  • This time interval may for instance be three minutes.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Software Systems (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
PCT/ZA2009/000111 2008-12-17 2009-12-17 Security measures for credit card Ceased WO2010071904A2 (en)

Priority Applications (6)

Application Number Priority Date Filing Date Title
SG2011044435A SG172224A1 (en) 2008-12-17 2009-12-17 Security measures for credit card
CN200980151333.1A CN102301384A (zh) 2008-12-17 2009-12-17 用于信用卡的安全措施
EP09813865A EP2380122A2 (de) 2008-12-17 2009-12-17 Sicherheitsmassnahmen f?r kreditkarten
AU2009327344A AU2009327344A1 (en) 2008-12-17 2009-12-17 Security measures for credit card
CA2747249A CA2747249A1 (en) 2008-12-17 2009-12-17 Security measures for credit card
ZA2011/00774A ZA201100774B (en) 2008-12-17 2011-01-31 Security measures for credit card

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
ZA200810812 2008-12-17
ZA2008/10812 2008-12-17

Publications (3)

Publication Number Publication Date
WO2010071904A2 true WO2010071904A2 (en) 2010-06-24
WO2010071904A3 WO2010071904A3 (en) 2010-08-12
WO2010071904A9 WO2010071904A9 (en) 2010-11-11

Family

ID=42135951

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/ZA2009/000111 Ceased WO2010071904A2 (en) 2008-12-17 2009-12-17 Security measures for credit card

Country Status (7)

Country Link
EP (1) EP2380122A2 (de)
CN (1) CN102301384A (de)
AU (1) AU2009327344A1 (de)
CA (1) CA2747249A1 (de)
SG (1) SG172224A1 (de)
WO (1) WO2010071904A2 (de)
ZA (1) ZA201100774B (de)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3441926A1 (de) * 2017-08-09 2019-02-13 SSenStone Inc. System zur zahlung basierend auf dem intranet eines geschäfts, mobiles endgerät mit zahlungsfunktion basierend auf dem intranet eines geschäfts, verfahren zur bereitstellung eines zahlungsdienstes basierend auf dem intranet eines geschäfts und programm zur durchführung davon

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106330891A (zh) * 2016-08-21 2017-01-11 上海林果实业股份有限公司 智能卡、认证码认证方法及系统

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7363494B2 (en) * 2001-12-04 2008-04-22 Rsa Security Inc. Method and apparatus for performing enhanced time-based authentication
CA2394742A1 (fr) * 2002-01-17 2003-07-17 Michel Caron Appareil portatif, active par l'empreinte digitale de son detenteur, qui fournira un code d'acces unique et different pour chaque utilisation de son detenteur
AU2003293125A1 (en) * 2002-11-27 2004-06-23 Rsa Security Inc Identity authentication system and method
US20060143450A1 (en) * 2003-06-13 2006-06-29 Narendranath Airody Udupa Method and apparatus for authenticating a password
KR100645401B1 (ko) * 2006-05-01 2006-11-15 주식회사 미래테크놀로지 휴대폰에서의 시간동기 방식 오티피 발생장치와 방법
US8359630B2 (en) * 2007-08-20 2013-01-22 Visa U.S.A. Inc. Method and system for implementing a dynamic verification value

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
None

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3441926A1 (de) * 2017-08-09 2019-02-13 SSenStone Inc. System zur zahlung basierend auf dem intranet eines geschäfts, mobiles endgerät mit zahlungsfunktion basierend auf dem intranet eines geschäfts, verfahren zur bereitstellung eines zahlungsdienstes basierend auf dem intranet eines geschäfts und programm zur durchführung davon
CN109389390A (zh) * 2017-08-09 2019-02-26 森斯通株式会社 基于卖场内通信网的结算移动终端、系统、方法及程序
US11301921B2 (en) 2017-08-09 2022-04-12 SSenStone Inc. System for payment based on store's intranet, mobile terminal including payment function based on store's intranet, method for providing payment service based on store's intranet, and program for performing the same

Also Published As

Publication number Publication date
CA2747249A1 (en) 2010-06-24
AU2009327344A1 (en) 2011-07-21
ZA201100774B (en) 2011-10-26
CN102301384A (zh) 2011-12-28
WO2010071904A9 (en) 2010-11-11
SG172224A1 (en) 2011-07-28
WO2010071904A3 (en) 2010-08-12
EP2380122A2 (de) 2011-10-26

Similar Documents

Publication Publication Date Title
JP7345509B2 (ja) 安全な読み取り専用の認証のためのシステム及び方法
RU2427917C2 (ru) Устройство, система и способ сокращения времени взаимодействия при бесконтактной транзакции
KR101236957B1 (ko) 모바일 otp 보안을 이용한 휴대단말기의 신용카드 결제 시스템 및 그 방법
US20200286088A1 (en) Method, device, and system for securing payment data for transmission over open communication networks
US9984371B2 (en) Payment de-tokenization with risk evaluation for secure transactions
KR101330867B1 (ko) 결제 디바이스에 대한 상호인증 방법
Lacmanović et al. Contactless payment systems based on RFID technology
AU2012265824B2 (en) A transaction system and method for use with a mobile device
Ceipidor et al. KerNeeS: A protocol for mutual authentication between NFC phones and POS terminals for secure payment transactions
US11432155B2 (en) Method and system for relay attack detection
US20190362341A1 (en) Binding cryptogram with protocol characteristics
US10248947B2 (en) Method of generating a bank transaction request for a mobile terminal having a secure module
CA3047954A1 (en) Method for carrying out a transaction, corresponding terminal, server and computer program
EP2380122A2 (de) Sicherheitsmassnahmen f?r kreditkarten
EP4179697B1 (de) Sichere end-zu-end-paarung eines sicheren elements mit einer mobilen vorrichtung
KR101190745B1 (ko) 인터넷 otp 보안을 이용한 휴대단말기의 신용카드 결제 시스템 및 그 방법
RU2736507C1 (ru) Способ и система создания и использования доверенного цифрового образа документа и цифровой образ документа, созданный данным способом
Ion et al. Don’t trust POS terminals! Verify in-shop payments with your phone
WO2025045876A1 (en) Method for relay attack protection of monetary transactions
Barisani et al. Practical EMV PIN interception and fraud detection
HK40120918A (zh) 用於安全只读认证的系统和方法
HK40048471B (zh) 用於安全只读认证的系统和方法

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200980151333.1

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09813865

Country of ref document: EP

Kind code of ref document: A2

WWE Wipo information: entry into national phase

Ref document number: 2747249

Country of ref document: CA

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 1326/MUMNP/2011

Country of ref document: IN

WWE Wipo information: entry into national phase

Ref document number: 2009327344

Country of ref document: AU

WWE Wipo information: entry into national phase

Ref document number: 2009813865

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2009327344

Country of ref document: AU

Date of ref document: 20091217

Kind code of ref document: A