WO2014186559A2 - Solutions de sécurité de données évoluées - Google Patents

Solutions de sécurité de données évoluées Download PDF

Info

Publication number
WO2014186559A2
WO2014186559A2 PCT/US2014/038164 US2014038164W WO2014186559A2 WO 2014186559 A2 WO2014186559 A2 WO 2014186559A2 US 2014038164 W US2014038164 W US 2014038164W WO 2014186559 A2 WO2014186559 A2 WO 2014186559A2
Authority
WO
WIPO (PCT)
Prior art keywords
security
security device
transaction
smart device
identifier
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2014/038164
Other languages
English (en)
Other versions
WO2014186559A3 (fr
Inventor
Jerome Svigals
Howard M. SVIGALS
Geoff INGALLS
John D. HIPSLEY
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US13/895,155 external-priority patent/US8806603B2/en
Priority claimed from US14/053,373 external-priority patent/US8997188B2/en
Application filed by Individual filed Critical Individual
Priority to EP14797946.2A priority Critical patent/EP2997694A2/fr
Publication of WO2014186559A2 publication Critical patent/WO2014186559A2/fr
Publication of WO2014186559A3 publication Critical patent/WO2014186559A3/fr
Priority to US14/711,619 priority patent/US9319404B2/en
Priority to US14/938,750 priority patent/US9344437B2/en
Anticipated expiration legal-status Critical
Priority to US15/148,519 priority patent/US9432378B1/en
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • H04L63/0838Network architectures or network communication protocols for network security for authentication of entities using passwords using one-time-passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • H04L63/0846Network architectures or network communication protocols for network security for authentication of entities using passwords using time-dependent-passwords, e.g. periodically changing passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • This invention relates to secure data transactions involving smart devices, security devices, and application controlling institutions. Very high levels of security are achieved without the use of encryption, PINs, or passwords.
  • key ring devices for assorted security or operational requirements, for example, a key ring device that computes a onetime password synchronized with a central site computer, and a key ring device used to convert wireless transmission to a second type of signal.
  • Mobile communication devices increasingly are used for performing operations associated with privileged access, such as financial transfers of funds.
  • a lost, stolen, and/or compromised unsecured mobile communication device may result in significant harm to users and/or institutions. If the device is lost or stolen, the security device may be successfully manipulated by a thief, the communications may be overheard by unwanted people, and fraudulent downloads may be made.
  • Advanced data security solutions comprising smart devices (102), security devices (104), and application controlling institutions (101 ). Very high levels of security are achieved without the use of encryption, PINs, or passwords.
  • a one-time identifier is used, comprising a unique security device (104) identification and a one-time transaction identifier. This process of de-identification greatly enhances security. Incoming messages and outgoing messages both adhere to this principle.
  • Major uses for this inventive technology include loyalty applications, automated teller machines (ATMs), control of remote devices, SPARCPrivate, SPARCeiver (1208), and secure health transactions.
  • FIG. 1 is a block diagram of an example of a communication system, in accordance with an embodiment of the present invention.
  • FIG. 2 is an elevational view of an exemplary SPARC Security Device 104 of FIG. 1 , in accordance with an embodiment of the present invention.
  • FIG. 3 is a block/flow diagram of an exemplary method for using the communication system described with reference to FIGs. 1 and 2, in
  • FIGs. 4A through 4C constitute a flow diagram illustrating an example of a method for using the communication system as described with reference to FIGs. 1 -3, in accordance with an embodiment of the present invention.
  • FIG. 5 is a block diagram depicting a conventional client/server
  • FIG. 6 is a block diagram of a typical computer system that, when appropriately configured or designed, can serve as a computer system 600 in which the present invention may be embodied.
  • FIGs. 8A through 8D are block and flow diagrams illustrating the use of SSD 104 and an ACIRD (ACI Response Device) 81 in an Industrial Application.
  • ACIRD ACI Response Device
  • FIG. 9 is a block diagram of an embodiment of the present invention in which Smart Device 102 receives a request for an unsolicited transaction (UT) from an external source 906.
  • UT unsolicited transaction
  • FIG. 10 is a flow diagram of a method embodiment of the present invention corresponding to the apparatus depicted in FIG. 9.
  • FIG. 1 1 is a block diagram of an embodiment of the present invention in which a remote device 1 101 is controlled.
  • FIG. 12 is a block diagram of an embodiment of the present invention in which SPARCeiver 1208 is employed.
  • a commercial implementation in accordance with the spirit and teachings of the present invention may be configured according to the needs of the particular application, whereby any aspect(s), feature(s), function(s), result(s), component(s), approach(es), or step(s) of the teachings related to any described embodiment of the present invention may be suitably omitted, included, adapted, mixed and matched, improved, and/or optimized by those skilled in the art, using their average skills and known techniques, to achieve the desired implementation that addresses the needs of the particular application.
  • Software or “program” refers to prescribed rules to operate a computer. Examples of software include: code segments in one or more computer- readable languages; graphical and or/textual instructions; applets; pre-compiled code; interpreted code; compiled code; applications; and computer programs.
  • Examples of a network include: an internet, such as the Internet; an intranet; a local area network (LAN); a wide area network (WAN); and a combination of networks, such as an internet and an intranet.
  • an internet such as the Internet
  • an intranet such as the Internet
  • LAN local area network
  • WAN wide area network
  • networks such as an internet and an intranet.
  • Secure communication systems include a Smart Device 102 with applications for communicating and interacting with a SPARC Security Device 104, a communication system that enables secure communications between a SPARC Security Device 104 and external entities to secure a communication system.
  • Secure communication protocols use a transaction identifier for protecting transmitted and received return information.
  • SSD Applications and Remote Control
  • the SPARC Security device (SSD) 104 is provided by the Application Controlling Institution (ACI) 101 to a customer when the customer orders his or her first ACI controlled application.
  • ACI Application Controlling Institution
  • SSD 104 may be provided by a third party as an industry service.
  • the SSD 104 is configured to match the
  • Processor portion 1 14 receives information from button/sensor portion 1 10 via a communication channel 122, and is adapted to signal agreement with the transaction. Processor portion 1 14 communicates bi-directionally with memory portion 1 12 via a communication channel 124. Indicator portion 1 16 receives information from processor portion 1 14 via a communication channel 126. Processor portion 1 14 communicates bi-directionally with communication portion 1 18 via a communication channel 128. Power supply portion 120 provides power to button/sensor portion 1 10, memory portion 1 12, processor portion 1 14, indicator portion 1 16, and communication portion 1 18, via a power supply bus 130. Button/sensor portion 1 10 accepts receipt of digital information (e.g.
  • Memory portion 1 12 receives, stores, and retrieves information.
  • information stored include operational codes and data.
  • Smart Device 102 and SPARC Security Device 104 can be configured to communicate only when geographically located within pre-established distance constraints, as specified for operation associated with communication channel 106.
  • SPARC Security Device 104 may be an EMV (Eurocard/MasterCard/Visa) smart card or a NFC (Near Field Communications) smart card.
  • An NFC smart card has a communication range of about 10 cm.
  • SPARC Security Device 104 and associated processes provide secure communications based upon the interaction of the two distinct devices, Smart Device 102 and SPARC Security Device 104, needed to complete a transaction with Application Controlling Institution 101 .
  • Each ACI 101 maintains a corresponding database with a corresponding set of registers for each user account. Verification of the SSD ID is performed by ACI 101 checking for agreement between the components of the SSD ID of the incoming message and the components of the SSD ID stored within the ACI 101 .
  • an application in the SD 102 can tell the SSD 104 which ACI 101 to work with.
  • the SSD 104 can itself determine which ACI 101 to work with, by consulting a pre-established table within the SSD 104.
  • SSD 104 can deal with multiple ACI's 101 directly, without having to designate a primary ACI 101 . If there were no ACI 101 field in the SSD ID, one ACI 101 is designated as the primary ACI 101 , and coordinates communications between or among the other ACI's 101 .
  • Any and all of the SPARC Security Device 104 parameters can be made to be programmable. Such parameters can include the allowable response time before timing out, loss of an NFC signal, the range of allowable operation, etc.
  • the one-time transaction number can comprise bits that represent other than numerical data, such as alphabetical or alphanumeric data.
  • TN time to date
  • a given message can have a first one-time transaction identifier, and the corresponding response can have a different one-time transaction identifier.
  • the transaction identifier serves to differentiate messages sent to and received from the ACI 101 ; and enables the detection of duplicate SSD 104 use, counterfeit messages, counterfeit SSD 104 use, and illegal use of lost or stolen Smart Devices 102.
  • the number of digits comprising the transaction identifier can be expanded, when the transaction identifier is advanced, to reduce the possibility of successful attacks.
  • a transaction identifier can be replaced by the ACI 101 to counteract ACI 101 database attacks, misuse, or theft.
  • Communication system 100 supports “bump” security applications.
  • “Bump” comprises an application operating via a Smart Device 102 and by a matching algorithm operating via servers connected to SD 102 via communication channel 108.
  • CRC Redundancy Check
  • SPARC Security Device 104 may continue to be used in the event of a lost or stolen Smart Device 102.
  • SPARC Security Device 104 communicated to SPARC Security Device 104 for confirmation. If confirmed, SPARC Security Device 104 signals the user, e.g., by illuminating indicator portion 1 16 in a pre-established manner, and requests confirming actuation by the user via button/sensor portion 1 10. If not confirmed by the user's actuating button/sensor 1 10, SPARC Security Device 104 generates an alert, e.g., a flash or other signal repeatedly illuminating indicator 1 16.
  • an alert e.g., a flash or other signal repeatedly illuminating indicator 1 16.
  • an ACI 101 application detects the incorrect SSD unit number and rejects the attempted transaction.
  • Downloading a message from ACI 101 to SSD 104 requires the correct SSD 104 number, plus the correct one-time transaction number.
  • FIG. 2 is a mechanical diagram for an exemplary SPARC Security Device 104 described with reference to FIG. 1 , wherein a containment portion 202 provides containment of associated electrical and mechanical devices.
  • SPARC Security Device 104 may take a wide variety of physical forms, including but not limited to a bracelet, a ring, a key ring device, a pin-on device, a pocket device such as a pen, a set top programmable remote control device, or any similar lightweight and compact devices.
  • SPARC Security Device 104 may be configured such that, when its power 120 runs low, an alarm is generated. The alarm may be an audible alarm, a visual alarm, or a vibration of the SPARC Security Device 104. Similarly, when someone attempts to use SPARC Security Device 104 with no accompanying or available
  • an alarm can be generated.
  • the alarm is kept local, but includes within its range the Smart Device 102 with which the
  • SPARC Security Device 104 is communicating.
  • SPARC Security Device 104 includes a button/sensor portion 1 10, an indicator portion 1 16, a containment portion 202, and an attachment element 204.
  • Button 1 10 may comprise a biometric sensing actuating device.
  • SSD 104 may not require an actuator at all; in this scenario, SSD 104 gives its SSD ID to the Smart Device automatically, as long as the distance requirement is satisfied.
  • Indicator 1 16 can have several different settings, corresponding to several different applications.
  • Containment portion 202 provides mechanical containment of associated electronic and mechanical devices associated with SPARC Security Device 104.
  • Containment portion 202 has a length 206, a height 208, and a width 210.
  • length 206 may be two inches
  • height 208 may be 1 ⁇ 2 inch
  • width 210 may be 1 ⁇ 4 inch.
  • Attachment element 204 provides capability for attachment of SPARC Security Device 104 to other devices.
  • Element 204 can be, e.g., a keychain, key ring, safety pin for attachment to clothing, etc.
  • FIG. 3 is a flow diagram of an exemplary communication system described with reference to FIG. 1 -2, wherein a transaction associated with an Application Controlling Institution 101 , Smart Device 102, and SPARC Security Device 104 is securely executed.
  • a flow diagram 300 presents the communication flow between and among Application Controlling Institution 101 , Smart Device 102, and SPARC Security Device 104.
  • Application Controlling Institution 101 include an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account identifier, an account
  • currency type e.g., U.S. dollars
  • step 304 the user of SD 102 initiates this transaction via selection of a transmit button on SD 102 or via a SEND function on the associated application.
  • Smart Device 102 communicates certain information (see line 305) to SPARC Security Device 104 over logical line 305.
  • Non-limiting examples of this information that is communicated to SSD 104 include account identifier and transaction type.
  • SPARC Security Device 104 stores in its memory the received account identifier and transaction type.
  • SPARC Security Device 104 illuminates its indicator portion 1 16, signaling the user to verify that the transaction should proceed.
  • SPARC Security Device 104 receives an indication that its user has actuated button/sensor 1 10.
  • illumination of indicator portion 1 16 is terminated.
  • the SSD ID identifier is created by SPARC Security Device 104. This SSD ID identifier is communicated to Smart Device 102 over logical line 315.
  • Smart Device 102 receives and validates the unique SSD ID received from SSD 104. If valid, the process continues. If not, the process terminates. Furthermore, Smart Device 102 communicates the SSD ID and the requested transaction to Application Controlling Institution 101 over logical line 317. All or part of the SSD ID can be stored in SD 102, to detect attacks involving use of a counterfeit SSD 104.
  • ACI 101 receives and processes this information.
  • ACI 101 uses the SPARC Security Device 104 unit identifier for retrieving information from its database indexed by the SSD 104 unit identifier.
  • ACI 101 performs a comparison of the retrieved transaction identifier information with transaction identifier information in its database in order to verify that information received over line 317 is valid.
  • Smart Device 102 can also validate the information received over line 317 via the date, time, ACI 101 , and/or subject matter fields in the SSD ID. Smart Device 102 then retrieves a user account identifier from its database via line 317A for performing the transaction processing.
  • ACI 101 processes the transaction.
  • ACI 101 prepares and communicates any relevant information to Smart Device 102 over logical line 319.
  • the information sent over line 319 includes the unique SPARC Security Device 104 unit identifier.
  • Smart Device 102 validates the transaction using information received over logical line 317A.
  • Smart Device 102 transmits information over logical line 321 to SPARC Security Device 104 to complete the validation.
  • Information sent over logical line 317A constitutes a copy of information sent over logical line 317, to validate the return message from the ACI 101 .
  • SPARC Security Device 104 completes validation of the transaction.
  • SPARC Security Device 104 validates that the received unique SSD 104 unit identifier is correct.
  • SSD 104 communicates information over logical line 323 to Smart Device 102.
  • information sent over logical line 323 includes a signal authorizing Smart Device 102 to execute the transaction.
  • executing the transaction may include moving funds associated with a bank account.
  • Smart Device 102 executes the transaction.
  • Smart Device 102 posts funds received from ACI 101 .
  • FIGs. 4A through 4C illustrate an exemplary method for using the secure communication system as described with reference to FIGs. 1 through 3, in accordance with an embodiment of the present invention.
  • an application is provided to Smart Device 102 by Application Controlling Institution 101 .
  • Smart Device 102 receives an application from Application Controlling Institution 101 via communication channel 108.
  • SPARC Security Device 104 receives an interrogation from Smart Device 102.
  • SPARC Security Device 104 (Fig. 1 ) receives an interrogation message from Smart Device 102 (Fig. 1 ) via communication channel 106.
  • SPARC Security Device 104 selects its memory 1 12 section associated with the application identifier for the received application.
  • SPARC Security Device 104 (Fig. 1 ) selects a memory section associated with memory portion 1 12 (Fig. 1 ) associated with the application identifier.
  • step 410 an indicator is illuminated.
  • indicator portion 1 16 (Figs. 1 -2) is illuminated.
  • step 412 a determination for input received from button/sensor 1 10 is performed. For a determination of "no input received” in step 412, in step 414 a determination for a timeout condition is performed. For a determination of "no timeout” in step 414, the execution of method 400 transitions to step 412. For a determination of "an input received” in step 412, in step 416, activation associated with button/sensor 1 10 is received by SPARC Security Device 104. As a non-limiting example, processor portion 1 14 (FIG. 1 ) receives an indication from button/sensor portion 1 10 (FIG. 1 ) via communication channel 122 (FIG.
  • step 418 illumination of an indicator is terminated.
  • illumination of indicator portion 1 16 (FIG. 1 ) is terminated.
  • a comparison is performed between received biometric information and stored biometric information to authenticate that an authorized user is performing actuation of sensor.
  • biometric information e.g., a fingerprint
  • processor portion 1 14 FIG. 1
  • step 422 a determination for pass/fail for the biometric comparison performed in step 420 is made.
  • SPARC Security Device 104 communicates a failure message to Smart Device 102.
  • SPARC Security Device 104 (FIG. 1 ) communicates a failure message to Smart Device 102 (FIG. 1 ) via communication channel 106 (FIG. 1 ).
  • step 426 illustrated with reference to FIG. 4B, SPARC Security Device 104 communicates its unique SPARC Security Device unit identifier to Smart Device 102.
  • SPARC Security Device 104 (FIG. 1 ) communicates the unique unit identifier associated with SPARC Security Device 104 (FIG. 1 ) to Smart Device 102 (FIG. 1 ).
  • step 428 a determination for Smart Device 102 receiving SPARC
  • Security Device unit identifier from SPARC Security Device 104 is performed. For a determination of Smart Device 102 not receiving the unique SPARC Security Device 104 unit identifier in step 428, in step 430, a determination for a timeout condition is performed. For a determination of "not a timeout condition" in step 430, the execution of method 400 transitions to step 428. For a determination of receiving the unique SPARC Security Device 104 unit identifier in step 428, in step 438, the Application Controlling Institution 101 identifier is communicated from Application Controlling Institution 101 to Smart Device 102.
  • step 440 a determination for receipt of the Application Controlling
  • step 442 a determination for a timeout condition is performed. For a determination of "not a timeout condition" in step 442, the execution of method 400 transitions to step 440.
  • step 424 determination of a timeout in step 414 (FIG. 4A), step 430 (FIG. 4B) and 442 (FIG. 4B), in a step 444 (FIG. 4B) indicator portion 1 16 (FIGs. 1 -2) is illuminated in a flashing manner.
  • step 446 a determination for a properly configured Smart Device 102 is performed. For a determination of a "not configured Smart Device 102" in step 446, the execution of method 400 returns to step 446.
  • step 448 For a determination of a properly configured Smart Device 102 in step 446, in step 448, as illustrated with reference to FIG. 4C, the user creates a transaction on Smart Device 102 (FIG. 1 ) as described with reference to step 304 (FIG. 3).
  • SPARC Security Device 104 receives an account identifier and transaction type from Smart Device 102.
  • response to the transaction request may be discrete data or a continuous data stream, or both.
  • SPARC Security Device 104 receives an account identifier and transaction type from Smart Device 102 (FIG. 1 ) as described with reference to step 306 (FIG. 3).
  • SPARC Security Device 104 receives actuation information associated with a button or sensor.
  • processor portion 1 14 receives information associated with actuation of button/sensor portion 1 10 (FIG. 1 ) via communication channel 122 (FIG. 1 ) as described with reference to step 310 (FIG. 3).
  • step 458 SPARC Security Device 104 generates an SSD ID as described with reference to event 314 (FIG. 3).
  • Application Controlling Institution (ACI) 101 uses the SSD ID to retrieve the user's account number.
  • ACI 101 processes the transaction if valid.
  • a transaction request passes through the ACI 101 to a second ACI 101 for evaluation or action.
  • ACI 101 uses the SSD ID identifier to respond to Smart Device 102 with reference to step 318 (FIG. 3).
  • step 470 Smart Device 102 receives and processes transaction acceptance from SPARC Security Device 104 as described with reference to step 324 (FIG. 3).
  • step 472 execution of method 400 terminates.
  • Network region 502 and network region 504 can be adapted to operate to represent a network contained within a geographical area or region.
  • Non- limiting examples of representations for the geographical areas for the networked regions include postal zip codes, telephone area codes, states, counties, cities, and countries.
  • Elements within network regions 502 and 504 can communicate with external elements within other networked regions, or within elements contained within the same network region 502, 504.
  • global network 506 is adapted to operate as the Internet.
  • computer system 600 includes a quantity of processors 602 (also referred to as central processing units, or CPUs) that are coupled to storage devices including a primary storage 606 (typically a random access memory, or RAM), and a primary storage 604 (typically a read-only memory, or ROM).
  • processors 602 may be of various types, including microcontrollers (e.g., with embedded RAM/ROM) and microprocessors such as programmable devices (e.g., RISC or SISC based, or CPLDs and FPGAs), and devices not capable of being programmed, such as gate array ASICs
  • Smart Device 102 uses an application program provided by a control center.
  • Smart Device 102 (FIG. 1 ) initiates operation of an application provided by Application Controlling
  • the distance between SPARC Security Device 104 (FIG. 1 ) and Smart Device 102 (FIG. 1 ) is determined to be within a pre-established distance constraint.
  • the devices may be required to be less than Near Field
  • a transmit program is activated and information is transmitted.
  • a program for transmitting information from Smart Device 102 (FIG. 1 ) to SPARC Security Device 104 (FIG. 1 ) is activated, and information is transmitted from Smart Device 102 (FIG. 1 ) to SPARC Security Device 104 (FIG. 1 ).
  • information transmitted include instructions to activate indicator portion 1 16 (FIG. 1 ), select button/sensor portion 1 10 (FIG. 1 ), deactivate indicator portion 1 16 (FIG. 1 ); an account identifier; and a transaction type.
  • a security device stores an account identifier and transaction type in a register.
  • SPARC Security Device 104 (FIG. 1 ) stores an account identifier and a transaction type in a register.
  • a security device transmits an identifier to a smart device program.
  • SPARC Security Device 104 (FIG. 1 ) transmits an SSD ID to a program executing on Smart Device 102 (FIG. 1 ).
  • a smart device transmits a request message to a control center.
  • Smart Device 102 (FIG. 1 ) transmits a request message to Application Controlling Institution 101 (FIG. 1 ).
  • step 738 the transaction is processed and the control center transmits a response message.
  • a response message As a non-limiting example, Application Controlling
  • An incorrect value in the one-time transaction number indicates a
  • the combination of the SD 102 and the SSD 104 can provide identification and access control for any number of industries, including medical, retail, supermarket, government, education, student, and travel.
  • the SSD 104 acts like an "ignition key" for the Smart Device 102.
  • SD 102 is useless unless SSD 104 is present.
  • the distance requirement still has to be met.
  • WiFi and Bluetooth the battery in each of the SD 102 and SSD 104 has to be functioning.
  • the NFC protocol only one battery has to be functioning, in either SD 102 or SSD 104, because in the NFC protocol, the device with the non-functioning battery is powered by the RF signal over which SD 102 and SSD 104 communicate.
  • the SD 102 can comprise a holding buffer memory for containing incoming messages until validated by the associated SSD 104. In these embodiments, if the incoming message does not have the correct SSD ID, the message is destroyed by SD 102 on the grounds that there is a high possibility that the message contains malware.
  • identifiers for the ACI 101 are stored in the SSD 104.
  • the various ACIs 101 can represent different financial resources, such as Credit 1 , Credit 2, Debit 1 , Debit 2, Mortgage 1 , Transfer 1 , Travel, Point of Sale (POS), ATM (Automated Teller Machine).
  • the combination of the SD 102 and the SSD 104 constitutes a payment device, which can completely replace coins, paper currency, and credit or debit cards.
  • the several ACIs 101 can share the single SSD 104 by means of sending ACI 101 to ACI 101 messages amongst themselves.
  • the SSD 104 security scheme described herein is compatible with security concepts used successfully for nearly 50 years for bank card security, i.e., use of a central database for security decisions. This is achieved by using the unique SSD 104 unit number for transaction authorization at the ACI 101 .
  • the ACI 101 database uses the SSD 104 unit number to look up the user account number for the transaction. This successfully removes the actual user account number from the transmitted data.
  • SD 102 performs these steps:
  • Each SSD 104 contains a unique
  • SD 102 performs these steps:
  • Access database retrieve account number, compare TN value with
  • a “Loyalty Application” is one which is principally used by a participating entity or a group of participating entities that share a common nomenclature, and a common set of objectives and practices; and that provide a common set of products or services, in exchange for earned income or loyalty.
  • Participating entities can include, without limitation, one or more merchants, corporations, fraternal organizations, and/or nonprofit organizations.
  • the group of participating entities may be a chain of supermarkets, wherein the chain awards a bonus of $10 worth of groceries to users who purchase $200 worth of groceries at the chain in a given month.
  • the participating entity may be a corporation that offers its employees incentive credits to use local health/wellness facilities, as a means for controlling its health care costs.
  • the participating entity may be a charitable
  • An SSD 104 Loyalty Application can comprise the user of SD 102 and SSD 104 interacting with the process to purchase an article or to use a service so as to: (1 ) uniquely identify and provide the purchaser with a secure method to accept incentives offered by the entity or group of entities (including but not limited to inducements, rebates, loyalty points, or rewards from participating merchants, corporations, fraternal organizations, or nonprofit organizations, some of whom may not even be known to the user); (2) provide a purchasing or loyalty incentive based on the purchaser's or user's prior account relationship and actual account utilization with a preferred provider or group of providers, or through an ACI 101 member base; (3) capture the potential price or incentive value earned in response to selecting a Loyalty Application purchase decision or the use of a service; (4) provide the payment function associated with the selected Loyalty Application purchase or service use, and convert the potential price or loyalty/incentive value into an actual sale or use, with incentive or loyalty point capture; (5) capture the value of the Loyalty Application based transaction for future incentive or loyalty point calculation and
  • the Loyalty Application embodiments of the present invention comprise new stand-alone, programmable ACI Response Device (ACIRD) 81 with communications 82 and display 83 functionality.
  • ACIRD programmable ACI Response Device
  • Device 81 is used at each purchase or service nexus to respond to the Smart Device 102/SSD 104 action.
  • An ACIRD 81 can be reset or interrogated remotely by a central control system, such as an ACI 101 .
  • the ACIRD 81 provides a remote and interim substitute for ACI 101 functions. Examples of its use are these:
  • a local (to SD 102/SSD 104) inquiry device with access to pre-stored data, such as a supermarket shelf product identification device or compilation of gymnasium incentive point values for specified exercise levels.
  • a controlled/secured entry to ACIRD 81 content to observe, upload, download, or change the ACIRD 81 content.
  • ACIRD 81 is a self-contained unit with its own power supply 84, logic device 86, database 85, communications module 82, and display 83.
  • Device 81 accepts the following types of input messages: 1 ) An inquiry. This message activates a prepared display 83 message. The message can include a description of the item or service connected with the device 81 operation. 2) An order. This message allows the user to specify the quantity of product or service requested. 3) A change message, which allows ACIRD 81 to change the unit content and responses. 4) A remote inquiry message, requesting that activity content stored within ACIRD 81 is forwarded to the ACI 101 for record processing, inventory control, and/or preparation of summaries of services delivered.
  • ACIRD 81 has a content equivalent to that provided by an SSD 104, and includes said content with data being transferred to the ACI 101 . This allows the ACI 101 to securely assess its input from a variety of SSD 104 and ACIRD 81 sources. There can be one SSD 104 for multiple ACIRDs 81 .
  • Device 81 is usually physically located in or near the storage area for the cognizant product or service. As non-limiting examples, the ACIRD 81 can be integral to an admission acceptance or service location; integral to a
  • communications originating location a set top box, a smart device, a smart TV, etc.; or located at an educational or health services location, a sports event, or an entertainment venue.
  • Figure 8B1 shows local operation or inquiry of an ACIRD 81 where an SSD 104 is not required for the transaction.
  • these are transactions where transaction data is being captured for future assessment or use, or monetization or redistribution to family members or charitable causes.
  • SD 102 initiates a transaction at step 810.
  • ACIRD 81 receives the transaction request, and, at step 812, accesses an appropriate database.
  • ACIRD 81 displays the results of the access on its display 83.
  • ACIRD 81 performs the transaction, in this case a redistribution of funds, and confirms the transfer to SD 102.
  • SD 102 displays the results of the transfer on its display.
  • the process ends.
  • FIG. 8B2 shows an example where ACIRD 81 is a particular species, namely an ATM (Automated Teller Machine) 91 .
  • ATM 91 initiates a transaction and sends the request to SSD 104.
  • SSD 104 receives the requested transaction.
  • SSD 104 illuminates its indicator 1 16, or otherwise notifies its user that a transaction request is pending.
  • the user acknowledges the transaction request by means of actuating button or sensor 1 10 as previously described, or by any other means.
  • the processor 1 14 within SSD 104 enables the transaction to take place, and at step 825, the communications module 1 18 within SSD 104 instructs ATM 91 to process the transaction.
  • the transaction comprises authorizing ATM 91 to dispense cash to the user of ATM 91 .
  • logic device 86 within ATM 91 checks to see whether the transaction may take place.
  • ATM 91 checks its store of cash to see whether enough cash is available to dispense, and checks to see whether the user of ATM 91 is authorized to receive that amount of cash on that particular day. If these verification steps are not completed successfully, the process ends at step 827 with no cash being dispensed. If, on the other hand, the verification steps do succeed, the cash is dispensed to the user at step 828.
  • ATM 91 updates its database at step 829, and displays on its display 83 at step 830 a message to the user that the cash is being dispensed. The process ends at step 831 .
  • FIG. 8B2 has been described in terms of ACIRD 81 being an ATM 91 , the method just described can be used where ACIRD 81 is a ticket dispenser for any activity requiring a ticket, such as a ride on public
  • ACIRD 81 can be a repository of loyalty information.
  • the transaction can involve the distribution of loyalty coupons to the user, and corresponding update of database 85.
  • Figure 8B3 illustrates an embodiment of the present invention in which the database 85 of ACIRD 81 is updated, changed, or unloaded. In this
  • ACIRD 81 initiates the transaction at step 840, and sends a transaction request to SSD 104.
  • SSD 104 receives the transaction request, and, at step 842, SSD 104 signals its user, by any of the means previously described (such as by illuminating indicator 1 16) that a request has been received.
  • the user authorizes the transaction, he or she actuates button/sensor 1 10, or uses any other technique, to notify SSD 104, at step 843.
  • SSD 104 enables and processes the transaction request, utilizing its processor 1 14.
  • SSD 104 communicates the transaction to ACIRD 81 via its communications module 1 18.
  • ACIRD 81 receives this transaction message and accesses appropriate areas within its database 85.
  • ACIRD 81 implements the cognizant transfer or change using its logic device 86.
  • ACIRD 81 displays the transaction on its display 83.
  • the method ends at step 849.
  • Figure 8C illustrates confidential load and unload of ACIRD 81 data locally. In this context, "locally" means without needing to communicate with an ACI 101 .
  • the method includes, e.g., ACIRD 81 accumulating the device or service value of multiple purchases or service actions to determine accumulated incentive value and position.
  • SD 102 creates a transaction request and sends it to ACIRD 81 .
  • ACIRD 81 receives the transaction request.
  • ACIRD 81 checks the SSD unit identifier that was given to it with the transaction request, and forwards the transaction request to SSD 104.
  • SSD 104 receives the transaction request, and, at step 864, notifies its user (by any of the means previously discussed, such as by activation of indicator 1 16) that a transaction request is pending. Assuming that the user desires to go ahead with the transaction, SSD 104 receives actuation from the user at step 865 via any of the means previously discussed, such as the user activating
  • SSD 104 authorizes and processes the transaction using its processor 1 14, and conveys this fact to ACIRD 81 via its communications module 1 18.
  • ACIRD 81 opens logic within its logic device 86 to decode the transaction. If the transaction is to unload data from ACIRD 81 to SD 102, ACIRD 81 prepares instructions to accomplish this at step 868 and, at step 869, so notifies SD 102. At step 870, SD 102 stores the data it has just received from ACIRD 81 and, at step 871 , displays a message to its user. The process then ends at step 872.
  • ACIRD 81 prepares instructions to accomplish this and sends the instructions to SD 102.
  • SD 102 then prepares the necessary data package and transfer instructions, and sends this to ACIRD 81 .
  • ACIRD 81 then stores the data it has just received from SD 102. The process then ends at step 876.
  • Figure 8D illustrates the confidential exchange of ACIRD 81 data with ACI 101 data.
  • selected data accumulated over time within ACIRD 81 is forwarded to the account based ACI 101 , and stored there as identified in the transaction captured data.
  • the ACIRD 81 is used as a buffer and a data aggregator to avoid overwhelming the ACI 101 with a mass of individual transactions and their detailed data. From the perspective of time, ACIRD 81 acts as an interim data capture facilitating device.
  • ACI 101 provides stored, retrieved, and generated data. Note that the method described in Figure 8D occurs, at least in part, online, because an ACI 101 is involved.
  • SD 102 creates a transaction request and sends it to ACIRD 81 .
  • ACIRD 81 receives the transaction request, and at step 882 checks the SSD unit identifier that was given along with the transaction request. If the SSD unit identifier checks out, ACIRD 81 forwards the transaction request to SSD 104, which receives it at step 883 and stores it within its memory 1 12.
  • SSD 104 sends a message to its user by any of the means previously described, such as by illuminating indicator 1 16, that a transaction request is pending. Assuming that the user wishes the transaction to proceed, the user actuates button/sensor 1 10, or notifies SSD 104 by any other means, at step 885.
  • SSD 104 uses its processor 1 14 to enable and process the transaction, and so notifies ACIRD 81 in a message that includes the unit identifier for SSD 104 as a security precaution.
  • ACIRD 81 processes the message and considers appropriate options that it may offer to the user of SD 102, and forwards this message to SD 102.
  • SD 102 displays the message on its display.
  • SD 102 then authorizes the data transfer and sends the transfer message to ACI 101 using the SSD ID as an index.
  • ACI 101 verifies the validity of the SSD ID.
  • ACI 101 generates appropriate housekeeping and storage commands.
  • ACIRD 81 stores the data in its database.
  • ACI 101 retrieves selected information from its database and, at step 894, sends a confirmatory response containing the SSD unit identifier to SSD 104.
  • SSD 104 confirms the validity of the SSD unit identifier, and forwards the confirmatory message to ACIRD 81 .
  • ACIRD 81 updates its database with this confirmation and forwards the confirmation to SD 102.
  • SD 102 puts a confirmation message on its display so as to notify its user that the transaction has been successfully completed.
  • the method ends.
  • ACIRD 81 -based transaction sample As an example of an ACIRD 81 -based transaction sample, consider a purchase environment such as purchase of a supermarket shelf item. The user brings his or her Smart Device 102 into the communications required range of the shelf item. An application within SD 102 transmits a signal to the user's SPARC Security Device 104.
  • the SSD 104 executes the following sequence of events: 1 ) it interrogates ACIRD 81 (which can be physically located on the supermarket shelf) to receive a description of the shelf item, its cost, and transaction loyalty value; 2) it exercises a purchase action, supported by the SD 102; 3) it transmits the purchase transaction to the ACI 101 associated with that application, including the loyalty value of the transaction; and 4) it initiates a value transaction to the ACIRD 81 , where the value transactions for a preset period are accumulated for that user for later transfer to the ACI 101 .
  • the application within SD 102 can use the value for deciding whether subsequent purchases are worth making, and for generating reports of the user's
  • the ACI 101 processes the user's account based monetary data and/or other transactions, after assuring correct security content of the transaction messages.
  • the ACIRD 81 processes the incentive, loyalty, or quantity related value data and transactions, again using a security
  • the SSD 104 provides a vital control function which prevents Smart Device 102 misuse when the device 102 is lost or stolen. As described previously, SSD 104 prevents use of overheard transmission to steal vital transaction or identification data, provides a means to prevent downloading fraudulent applications, and allows loyalty incentive monetization programs.
  • Unsolicited Transactions (UTs) UFTs
  • the source 906 may be a bank wishing to communicate with its customer 102.
  • the first UT register 901 contains a validity identifier used to identify validly screened content that has been originated by an external communication source 906 and has been addressed to a Smart Device 102 that has subscribed to the UT service.
  • the second UT register 902 contains a similar validity identifier that is used to re-synchronize the validly screened content if and when the message flow is interrupted for any reason.
  • Figure 9 shows registers 901 , 902 being associated within SISC 900 (which is described below), but these registers 901 , 902 can also be contained within a participating SSD 104.
  • a service entity 900 which we call here the SPARC Internet Security Corporation (SISC), contains a processor 907 that scans or otherwise receives externally-originated incoming messages that are addressed to the e-mail address of a participating Smart Device 102 (step 910 in Figure 10).
  • SISC SPARC Internet Security Corporation
  • Processor 907 directs each incoming message through a Contamination Detector 903 (step 91 1 ), which determines whether the incoming message contains the identical validity identifier that is stored in the first UT register 901 (step 912). A message that contains this validity identifier 901 is deemed to be a valid message or an "uncontaminated message”. A message that does not contain the validity identifier stored in the first UT register 901 is deemed to be "contaminated”.
  • the validity identifier 901 can be any combination of numbers, letters, and/or other characters, such as ASCII characters.
  • processor 907 For contaminated messages, processor 907 preferably generates a notice to the intended recipient Smart Device 102. The notice informs the user of the recipient Smart Device 102 of his/her option to ask that the message be sent to the Smart Device 102 despite its having been declared to be "contaminated" (step 913). Contaminated messages are stored in a register 904 within SISC 900 for a preselected period (waiting time) pending the recipient's 102 reply. If a request to forward the contaminated message to the Smart Device 102 is not received by SISC 900 from the SD 102 within the specified waiting period, processor 907 destroys the contaminated message.
  • SISC 900 maintains a register 905 of valid SSD 104 addresses, i.e., addresses of SSD 104's that are pre-authorized to participate in the UT scheme.
  • Each uncontaminated message contains the e-mail address of the recipient Smart Device 102.
  • Processor 907 adds an SSD UT Identifier to the message, signifying that the message has been determined by Contamination Detector 903 to be uncontaminated (step 914).
  • the SSD UT Identifier comprises the address (or other unique identifier) of the SSD 104 that has been pre-authorized to participate in this UT scheme by SD 102, and an optional message count. The message count facilitates detection of any overheard transmission being illegally reused.
  • processor 907 This illegal reuse can be detected by processor 907 observing that two incoming messages have the same message count.
  • the message count is added to the SSD UT Identifier by processor 907, and is a count of the number of valid messages that have been sent to the particular Smart Device 102, regardless of the source 906.
  • Processor 907 changes the count from message to message by applying an algorithm. The algorithm does not simply increment the count by 1 from one message to the next, as doing so would make it easier for nefarious persons to break into the system.
  • Processor 907 then sends the UT message with the appended SSD UT Identifier to SD 102 (step 915).
  • Smart Device 102 checks the unique SSD 104 identifier portion of the SSD UT Identifier against its internal database (step 916), and, when SD 102 determines that the unique SSD 104 identifier is valid, processes the incoming message as a valid message (step 917).
  • a bumping action is a communication between two Smart Devices 102 that are proximate to each other, e.g., within NFC range, and that share a bumping application program. In this case, the recipient Smart Device 102 accepts or rejects the content based upon the dictates of the shared bumping application program.
  • SSD 104 The human user of SSD 104 is alerted (e.g., via indicator 1 16) that an outgoing message has been presented to SSD 104, and must affirmatively take some action, such as by pressing button 1 10, before the message is released and relayed to external network 506. Similarly, an incoming message from external network 506 to SD 102 is first routed through the matching SSD 104, where again the human user of SSD 104 is alerted, e.g., via indicator 1 16. The user of SSD 104 then must take affirmative action, such as by pressing button 1 10, before the message is released and relayed to SD 102.
  • Action Portion 1 103 controls and/or measures one or more Devices 1 109.
  • Device parameters that can be controlled by Action Portion 1 103 include, but are not limited to, temperature in a room or building, air flow in a room or building, lighting in a room or building, and operation of a burglar alarm.
  • Action Portion 1 103 can be instructed by Application Control Device 1 102 to control one or more than one Device 1 109, simultaneously or seriatim.
  • rolling transaction code generator 1 120 that is associated with (e.g., contained within) Application Control Device 1 102.
  • this rolling transaction code is analogous to the one-time transaction number previously described in this specification.
  • the rolling transaction code typically comprises the current date, the current time, a unique identification of the Remote Device 1 101 being controlled, and an optional field, which may include relevant comments, subject matter information, etc.
  • This rolling transaction code follows the principle of de-identification, which means that no user account numbers are used. This greatly contributes to the overall security of the system.
  • processor 1 141 checks the rolling transaction code against pre-stored information contained in a random access memory 1 143 associated with processor 1 141 , and verifies the validity of the rolling transaction code before allowing the transaction to proceed. As another security feature, processor 1 141 also checks that each control message sent from Application Control Device 1 102 to Security Portion 1 104 contains the correct security portion identifier 1 142 for that particular Security Portion 1 104. Of course, it is important to maintain the confidentiality of security portion identifier 1 142.
  • Processor 1 141 also checks to see that there is a valid connection from processor 1 131 before processor 1 141 forwards commands to processor 1 131 . This guards against the first security issue identified above, namely, the eventuality that Remote Device 1 101 has become disabled.
  • SPARCPrivate Control Center 1201 in some embodiments adds two physical return addresses to the message 1207 before sending the message 1207 to the merchant 1205.
  • the first physical address is that of the entity associated with the Smart Device 1202, i.e., the address where the user of the Smart Device 1202 wishes the package from the merchant 1205 to be sent.
  • the second physical address is that of an intermediary fulfillment center 1206.
  • the merchant 1205 sends the package that has been ordered to the physical address of the fulfillment center 1206, along with the first physical address.
  • the fulfillment center 1206, sends the package to the first physical address by usual delivery means, such as USPS, Federal Express, UPS, DHL, etc.
  • SPARCeiver 1208 can be a stand-alone interface to the Internet 1203, and can be used in conjunction with any Smart Device 1202. Alternatively,
  • Processor 1212 is coupled to Smart Device 1202, and is also coupled to three memories (storage areas): a memory module 1213 that stores software applications that are used by the processor 1212, a memory module 1214 containing a set of valid security device identifications, and a memory module 1215 that serves as a temporary storage for messages that are being worked on by processor 1212.
  • the companion SPARC Security Device 1204 is coupled to processor 1212 (e.g., indirectly via buffer 121 1 ) via memory 1214.
  • the coupling means is typically an NFC interface 1216.
  • the three memories, 1213, 1214, and 1215 can be flash drives each having a capacity of about 3 Gigabytes.
  • the presence of a security device identification in the incoming message provides an additional level of security, compared to those incoming messages that do not contain a security device identification.
  • processor 1212 checks the validity of the security device identification by means of consulting the memory 1214. If the security device identification is valid, processor 1212 moves the incoming message from temporary storage 1215 into Smart Device 1202, which processes the message. If the security device identification in the incoming message is invalid, processor 1212 obliterates the message.
  • One or more of memories 131 1 , 1312, 1313, 1315, 1319 can comprise a flash drive memory, e.g., one having about 3 Gigabytes of data capacity and the ability to connect to SPARChealth Security Device 1304 via a USB port associated with communications module 1318.
  • Memory 1312 stores a SPARChealth security device identification, which is unique for each SPARChealth Security Device 1304.
  • Smart Device 1302 communicates a transaction to HACI
  • Smart Device 1302 forwards to HACI 1301 the unique SPARC security device identification 1312 and the rolling transaction count, but not any account information, credit card information, or other information that would identify the true user. This communication thus adheres to the principle of de-identification which has been previously discussed in this specification.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

L'invention concerne des solutions de sécurité de données évoluées, comprenant des dispositifs intelligents (102), des dispositifs de sécurité (104) et des institutions de commande d'application (101). Des niveaux très élevés de sécurité sont atteints sans déchiffrement, codes PIN ni mots de passe. À la place de numéros de compte d'utilisateurs ou d'autres informations personnelles, un identifiant unique est utilisé, comprenant une identification de dispositif de sécurité unique (104) et un identifiant de transaction unique. Ce processus d'annulation d'identification renforce considérablement la sécurité. Ce principe s'applique aux messages entrants et sortants. Des utilisations principales de cette technologie inventive comprennent des applications de fidélité, des guichets automatiques (ATM), de commande de dispositifs à distance, SPARCPrivate, SPARCeiver (1208) et des transactions sécurisées relatives à la santé.
PCT/US2014/038164 2011-09-23 2014-05-15 Solutions de sécurité de données évoluées Ceased WO2014186559A2 (fr)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP14797946.2A EP2997694A2 (fr) 2013-05-15 2014-05-15 Solutions de sécurité de données évoluées
US14/711,619 US9319404B2 (en) 2011-09-23 2015-05-13 Security for the internet of things
US14/938,750 US9344437B2 (en) 2011-09-23 2015-11-11 Internet of things security
US15/148,519 US9432378B1 (en) 2011-09-23 2016-05-06 Internet of things security

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US13/895,155 US8806603B2 (en) 2012-04-11 2013-05-15 Dual device system for secure transactions
US13/895,155 2013-05-15
US14/053,373 US8997188B2 (en) 2012-04-11 2013-10-14 System for enabling a smart device to securely accept unsolicited transactions
US14/053,373 2013-10-14

Related Parent Applications (1)

Application Number Title Priority Date Filing Date
US14/053,373 Continuation-In-Part US8997188B2 (en) 2011-09-23 2013-10-14 System for enabling a smart device to securely accept unsolicited transactions

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/711,619 Continuation-In-Part US9319404B2 (en) 2011-09-23 2015-05-13 Security for the internet of things

Publications (2)

Publication Number Publication Date
WO2014186559A2 true WO2014186559A2 (fr) 2014-11-20
WO2014186559A3 WO2014186559A3 (fr) 2015-04-16

Family

ID=51899006

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2014/038164 Ceased WO2014186559A2 (fr) 2011-09-23 2014-05-15 Solutions de sécurité de données évoluées

Country Status (2)

Country Link
EP (1) EP2997694A2 (fr)
WO (1) WO2014186559A2 (fr)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016198713A1 (fr) * 2015-06-08 2016-12-15 Latorre Lopez Fernando Procédé d'enregistrement unifié et d'identification de donneurs de sang
US10303867B2 (en) 2013-07-25 2019-05-28 Giesecke+Devrient Mobile Security Gmbh External secure unit
CN115017498A (zh) * 2021-11-19 2022-09-06 荣耀终端有限公司 小应用程序的操作方法和电子设备
CN115292472A (zh) * 2022-10-09 2022-11-04 四川师范大学 一种小程序消息的推送方法以及系统
US12057202B2 (en) 2018-10-24 2024-08-06 Connecting Solution & Applications Ltd. Procedure for unified global registry and universal identification of products of biological origin for medicinal purposes
US12183439B2 (en) 2015-06-08 2024-12-31 Conectate Soluciones Y Aplicaciones S L Procedure for the global unified registration and universal identification of donors

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3761505B2 (ja) * 2002-03-04 2006-03-29 株式会社東芝 通信システム、無線通信端末及び無線通信装置
US7849020B2 (en) * 2005-04-19 2010-12-07 Microsoft Corporation Method and apparatus for network transactions
WO2012037479A1 (fr) * 2010-09-17 2012-03-22 Universal Secure Registry, Llc Appareil, système et procédé employant un dispositif d'utilisateur sans fil
US8453223B2 (en) * 2011-09-23 2013-05-28 Jerome Svigals Method, device and system for secure transactions

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10303867B2 (en) 2013-07-25 2019-05-28 Giesecke+Devrient Mobile Security Gmbh External secure unit
EP3025474B1 (fr) * 2013-07-25 2020-04-08 Giesecke+Devrient Mobile Security GmbH Unité externe sûre
WO2016198713A1 (fr) * 2015-06-08 2016-12-15 Latorre Lopez Fernando Procédé d'enregistrement unifié et d'identification de donneurs de sang
ES2615815A1 (es) * 2015-06-08 2017-06-08 Conectate Soluciones Y Aplicaciones, S.L.U. Procedimiento de registro unificado e identificación de donantes de sangre
US12183439B2 (en) 2015-06-08 2024-12-31 Conectate Soluciones Y Aplicaciones S L Procedure for the global unified registration and universal identification of donors
US12057202B2 (en) 2018-10-24 2024-08-06 Connecting Solution & Applications Ltd. Procedure for unified global registry and universal identification of products of biological origin for medicinal purposes
CN115017498A (zh) * 2021-11-19 2022-09-06 荣耀终端有限公司 小应用程序的操作方法和电子设备
CN115017498B (zh) * 2021-11-19 2023-02-28 荣耀终端有限公司 小应用程序的操作方法和电子设备
CN115292472A (zh) * 2022-10-09 2022-11-04 四川师范大学 一种小程序消息的推送方法以及系统

Also Published As

Publication number Publication date
WO2014186559A3 (fr) 2015-04-16
EP2997694A2 (fr) 2016-03-23

Similar Documents

Publication Publication Date Title
US9319404B2 (en) Security for the internet of things
US9344437B2 (en) Internet of things security
US9432378B1 (en) Internet of things security
US8806603B2 (en) Dual device system for secure transactions
US11263636B2 (en) Systems for providing and processing pre-authorized customizable gift tokens
RU2713703C2 (ru) Заблаговременная авторизация цифровых запросов
JP6518244B2 (ja) 相互運用可能なネットワーク・トークン処理のシステム及び方法
JP5932053B2 (ja) ネットワークアクセス可能な販売時点情報管理デバイスインスタンス
US7698567B2 (en) System and method for tokenless biometric electronic scrip
US8997188B2 (en) System for enabling a smart device to securely accept unsolicited transactions
ES2748847T3 (es) Transacciones de tarjeta de pago seguras
US20190122222A1 (en) Computer-based system and method for payment processing
US20130041776A1 (en) Cash payment apparatus, system and method
US20210224795A1 (en) Escrow non-face-to-face cryptocurrency transaction device and method using phone number
US20140040145A1 (en) Systems and methods for distributed enhanced payment processing
US20140214670A1 (en) Method for verifying a consumer's identity within a consumer/merchant transaction
US20150242825A1 (en) Generation, storage, and validation of encrypted electronic currency
US10192213B2 (en) Mobile payment system and method
JP2006285329A (ja) モバイルセキュリティ決定支援システム、方法、プログラム、移動体通信端末装置及び情報管理運営サーバ
US12361419B2 (en) Systems and methods for distributed enhanced payment processing
WO2014186559A2 (fr) Solutions de sécurité de données évoluées
JP2019537776A (ja) 携帯型支払い用リーダにおける詐欺検出
Kanimozhi et al. Security aspects of mobile based E wallet
US9009807B2 (en) Smart device lockout
WO2020009658A1 (fr) Dispositif d'authentification d'identité ou de sécurité pour système électronique utilisant des motifs ou des codes visuels

Legal Events

Date Code Title Description
REEP Request for entry into the european phase

Ref document number: 2014797946

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2014797946

Country of ref document: EP

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14797946

Country of ref document: EP

Kind code of ref document: A2