Method for carrying out a secure electronic transaction using a portable data support
Abstract
The invention discloses a method for performing secure electronic transactions using a portable data support device. According to the invention, the user (30) first authenticates himself to the portable data carrier (20). The portable data carrier (20) also generates information about how the verification occurred and verifies the information with the terminal (14). Next, the portable data carrier (20) performs security-based operations within the framework of the transaction, such as the generation of a digital signature. The results of safety-based operations are added to the quality information.

Term
Term ended
Expired 23 October 2023, 2.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
13 claims: 2 independent, 11 dependent
- 1第 1. 一种使用便携式数据载体在终端上实施安全电子交易的方法,用户藉 此对该便携式数据载体验证他自身,该便携式数据载体向该终端确认验证的 证明,接着该便携式数据载体在该电子交易之内执行安全性建立操作,其特 征在于:该便携式数据载体(20)创建关于如何进行用户(30)的验证的质 量信息,并且所述质量信息被附加到该安全性建立操作的结果中。
- 2如权利要求1所述的方法,其特征在于:由便携式数据载体(20)执 行的安全性建立操作在于创建数字签名。
- 3如权利要求1所述的方法,其特征在于:用户(30)的验证是通过提 供生物测量学特征来执行的。
- 4如权利要求3所述的方法,其特征在于:用户(30)的验证是通过提 供表征用户(30)的生理学的或基于行为的特征来执行的。
- 5如权利要求1所述的方法,其特征在于:用户(30)的验证是通过证 明秘密的知晓来执行的。
- 6如权利要求1所述的方法,其特征在于:提供至少两种不同质量的不 同验证方法来验证用户(30)。
- 7如权利要求6所述的方法,其特征在于:使未使用的特定验证方法失 效。 如权利要求6所述的方法,其特征在于:对于两种验证方法中的基于 知识的方法不产生质量信息。
- 89. 如权利要求6所述的方法,其特征在于:要求用户(30)选择验证方 法。
- 910. 一种用于在安全电子交易之内执行安全性建立操作的便携式数据载 体,用户藉此对该便携式数据载体验证他自身,并且该便携式数据载体向终 端确认该验证,其特征在于:该便携式数据载体(20)被设置成创建表明如 何执行用户(30 )的验证的质量信息。
- 1011. 如权利要求10所述的数据载体,其特征在于:该便携式数据载体(20 ) 被设置成创建数字签名。
- 1112. 如权利要求10所述的数据载体,其特征在于:该便携式数据载体(20 ) 支持至少两种质量不同的验证方法。 200380101997.X 第
- 1213. 一种与如权利要求10所述的便携式数据载体结合使用的终端,其特 征在于:该终端具有用于引发用户(30)来选择至少两种可能的验证方法之 一的装置(16、18)。
- 1314. 一种用于实施安全电子交易的系统,在该安全电子交易之内查明用 户对该系统的验证的质量,包括:如权利要求10所述的便携式数据载体和如 权利要求13所述的终端。 200380101997.X
Independent claims13
46 paragraphs in 1 section, as filed
The first method of using a portable data support device to perform a secure electronic transaction The invention starts with a method according to the category of the main claims. This method can be known from, for example, Handbuch der Chipkarten^^ (Chip card manual hereinafter), W. Rankl, W. Ewung, third edition, 1999, pages 692 to 703, titled Digital signature. In order to perform a legally bound electronic signature, a digital signature card containing a secret signature key is used accordingly. The signature is performed on the appropriate terminal from which the card receives the document to be signed in electronic form. In order to be able to perform the signature, the user of the card must establish a proof of his identity through the terminal. The proof is usually provided by entering a PIN (personal identification number), which is compared with a reference PIN stored in the card. In the future, it is planned to perform user authentication by checking biometric characteristics, such as fingerprints. When the electronic document has been signed by means of the signature card after the successful verification of the user, the document can then be delivered in any way. Electronic signatures make it possible to use electronic means to specifically execute security-critical transactions, for example, to issue business orders that involve costs.
Compared with the usual PIN verification to date, the biometric features introduced for the User Verification Program allow for further improvements in the credibility of electronic signatures because it ensures that the signature card is only present when a clear individual authorized to do so is present. can be used.
However, so far, the quality difference in user verification achieved by this has not been reflected in the use of specific electronic signatures generated.
The problem of the present invention is to specify a method for implementing secure electronic transactions using a portable data carrier that takes into account the quality of the user verification performed.
This problem is solved by a method that includes the features of the main claim. This problem is further solved by portable data carriers, terminals and systems for implementing secure electronic transactions according to independent claims 20, 25 and 30.
According to the present invention, when user authentication is being performed, the data carrier being performed generates quality information about the authentication method used. The voucher is attached to the result of the security establishment operation performed by the portable data carrier. Therefore, before implementing the security establishment operation, the recipient of the message thus formed can clearly identify how the user authenticates himself. This gives the recipient the possibility to make the implementation of a secure transaction dependent on the quality of user verification.
200380101997.X For example, in the purse application, it can be stipulated that after PIN verification, the amount of money below the limit value can be withdrawn from the account, and the amount of money above the limit value is only verified using biometric features It can be taken out later.
The combination of the inventive method of the present invention and the electronic signature has special advantages.
In a preferred embodiment, the implementation of various possible user authentication methods is designed such that the intermediate execution result of the low-quality method cannot be converted into the intermediate execution result of the high-quality method in a simple manner. This results in the following: even when an unauthenticated user can use both the portable data carrier and the related low-level authentication information, that is, when the unauthenticated user has, for example, the portable data carrier and the related PIN, it is impossible Falsification of authentication credentials (voucher).
It is even more advantageous if a specific verification method that is not used in performing user verification is invalidated during verification.
Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 shows the structure of a system for performing digital signatures.
Figures 2 and 3 show the process of executing the digital signature in a flowchart.
Figure 1 shows the basic structure of a transaction system for implementing secure electronic transactions. The basic elements of this structure with respect to the present invention are: a background system 10 connected to a terminal 14 via a data network 12, a portable data carrier 20 carried by a user 30 and set to perform security establishment operations within a transaction, and a portable data carrier 20 to be implemented in the future The data record 40 is safely processed within the transaction.
In the following, it will be assumed that a secure electronic transaction is a transaction that needs to generate a digital signature on behalf of the user 30. Such a transaction may be, for example, the implementation of a financial transaction that debits the account of the user 30. However, the solution is not limited to transactions that require a digital signature, but can basically be used in any application where the portable data carrier 20 processes the data records 40 provided from the terminal 14 and returns them to the terminal 14.
The background system 10 represents a device that implements actual transactions, for example, transferring money between two accounts or starting the delivery of goods according to an order. Accordingly, the background system 10 can be a complex system including a plurality of individual components, or can be omitted altogether in extreme cases. If the transaction is a transfer application, the background system 10 is generally formed by a central bank office.
The data network 12 is used to exchange data between the terminal 14 and the background system 10. It can have any physical form and can be implemented via, for example, the Internet or a mobile phone network.
200380101997.X The first terminal 14 constitutes the user-side interface of the transaction system, and therefore has a display device 16 and an input device 18. The display device 16 is generally in the form of a display screen, and the input device 18 is, for example, in the form of a keyboard. The terminal 14 can be a publicly accessible terminal, such as a device set up in a bank, or a device located in the private area of the user 30, such as a PC or a mobile phone. The data network 12 and the background system 10 can be connected to one or more terminals 14 that can have different designs. The terminal 14 has an interface 19 for communicating with a portable data carrier 20. The interface 19 can be of any physical design, specifically a contact type or a non-contact type.
The terminal 14 also has a sensor device 15 hereinafter referred to as a sensor for detecting the biometric characteristics of the user 30. The sensor 15 can detect physiological features, such as facial features, eye or fingerprint features, or behavior-based features, such as voice or writing sequences represented by voice or writing operations. FIG. 1 shows a fingerprint sensor as the sensor 15. The sensor 15 can be formed to sense a number of different biometric characteristics. The sensor 15 also contains means for pre-evaluating the sensed biometric characteristics. For example, in Chapter & 1.2 of the aforementioned Chip card manual, different types and implementations of biometric verification methods are described.
For example, the portable data carrier 20 is the same as in the Chip card manual<sup>5,</sup>The chip card described in. FIG. 1 specifically indicates that the portable data carrier 20 is a contact type chip card with a contact pad 22, which constitutes an interface corresponding to the interface 19 on the terminal side. Via the interfaces 22 and 19, the communication between the chip card 20 and the terminal 14 is implemented. In addition to the shape of the chip card, the portable data carrier 20 can also have any shape, for example, realized by clothes worn by the user 30 or daily necessities carried by the user 30.
The portable data carrier 20 has an integrated circuit 24, which has all the components of a general-purpose computer, in particular a microprocessor 25 and a storage device 26. The microprocessor 25 is set up to perform the security establishment operation. For example, the microprocessor 25 is set up for subjecting the provided data record 40, hereinafter referred to as the electronic document 40, to an encryption algorithm process, whereby it uses at least one secret key stored in the storage device 26. The establishment of the microprocessor 25 is also used to implement other functions according to the program stored in the storage device 26.
The portable data carrier 20 is set up to also perform at least one user authentication method, but advantageously to perform multiple simultaneous user authentication methods. Preferably, it supports at least two verification methods with different levels of verification quality. It advantageously supports at least one knowledge-based verification method, for example, a PIN check, and at least one biological measurement method in which the biometric characteristics of the user 30 appearing at the terminal 14 are checked. Since this biometric method presupposes the existence of 30 users, it constitutes a higher-quality method; since knowledge can be obtained by unauthorized
200380101997.X is the first user acquisition, so knowledge-based methods cannot ensure that 30 users appear. Correspondingly, the storage device 26 stores at least one secret to be provided by the user 30, such as a reference PIN assigned to the user 30, and at least one biometric reference data record assigned to the user 30. The portable data carrier 20 can advantageously be made to support more than two verification methods, especially more biometrics methods. Accordingly, the storage device 26 in this case stores more secret and/or reference data records, and the integrated circuit 24 is arranged to perform other verification methods.
Hereinafter, the implementation of a secure electronic transaction using the structure shown in FIG. 1 will be described with reference to FIGS. 2 and 3. The security establishment operation will be the signature of the electronic document 40.
In step 100, the use is initiated by creating an electronic document 40 in the background system 10 or the terminal 14. Generally, an initial dialogue between the user 30 and the background system 10 via the terminal 14 is performed before the creation. When the electronic document 40 appears in the terminal 14 at the latest, in step 102, the signature application is initiated. The activation can be initiated automatically by the terminal 14 or the background system 10, or initiated by the user 30 after the terminal 14 uses an appropriate display on the display device 16 to request the user 30 to initiate.
After the signature application has been started, the user 30 provides the appropriate portable data carrier 20 to the terminal 14 in step 104. Hereinafter, the portable data carrier 20 will take the form of a contact chip card. Moreover, it will be assumed below that the chip card 20 supports two verification methods, namely, as a knowledge-based PIN check (low-quality method), and as a biometric fingerprint check (a high-quality method).
In step 106, when the terminal 14 has recognized the existence of the chip card 20, it first performs mutual authentication, wherein the chip card 20 first proves its authenticity to the terminal 14 and then the terminal 14 proves to the chip card 20.
If the verification is successful, in step 108, the terminal 14 and the chip card 20 negotiate a dynamic session key so as to allow further communication to be performed securely in a so-called secure messaging mode. For the detailed concepts of secure messaging and dynamic session keys, please refer to the "Chip card manual" again.
Next, the verification of the user 30 with respect to the chip card 20 is implemented. In step 110, the terminal 14 first checks how the verification will be implemented: based on knowledge, that is, by entering a PIN, or by biometrics, that is, providing a fingerprint. The designation of the verification method can be automatically implemented by the terminal 14 based on the information transmitted with the electronic document 40, but it can also be provided to the user 30 via the display device 16 as a decision request. In the latter case, the user 30 uses the input device 18 to make a decision.
If the verification of the user 30 is to be carried out based on knowledge, that is, to be implemented by entering a PIN, then
200380101997.X Step 112, the chip card 20 disables other possible verification methods, that is, fingerprint checking, and requests the user 30 via the display device 16 to input his PIN via the input device 18.
Then, in step 114, the user 30 inputs the PIN via the input device 18, and the terminal 14 transfers it directly or in a modified form to the chip card 20 via the interfaces 19, 22. The transmission of the PIN or the information thus obtained and the subsequent communication with the chip card uses the negotiated session key to further ensure security. All communications between the terminal 14 and the chip card 20 are advantageously implemented in the secure messaging mode.
In step 116, the card checks the transmitted PIN and confirms the correctness to the terminal 14 if there is no error, or if it is checked that the PIN is wrong, the process is terminated.
If there is no error condition, in step 11 & terminal 14, the chip card 20 is triggered to perform a security establishment operation, that is, a digital signature, through corresponding instructions, and the electronic document 40 waiting for signature is transmitted to the chip card 20.
In step 120, the chip card 20 uses the secret key stored in the storage termination 26 to sign the provided electronic document 40, and in step 122, the electronic document 40 is transmitted back to the terminal 14, and the terminal 14 uses it to continue the process. Electronic transactions initiated.
If the check in step 110 shows that the verification of the user 30 will not be based on knowledge but through biometrics, then in step 130, the terminal 14 initiates the verification of the provided biometric features, and makes a statement to the chip card 20 Corresponding report. Then, in step 132, the chip card 20 disables other unused verification methods, that is, the knowledge-based PIN check.
Subsequently, in step 134, the user 30 provides the terminal 14 with a biometric feature corresponding to the verification method used, that is, a fingerprint. The request to provide the fingerprint is preferably implemented through a corresponding display on the display device 16 of the terminal 14. The fingerprint is detected by a sensor 15 installed on the terminal 14.
In step 136, the detected biometric features, that is, the fingerprint of the user 30, are preprocessed by the terminal 14. In this preprocessing, it extracts specific identification features from the signal acquired on the sensor 15. If fingerprints are used, determine the main characteristics of the Henry classification method, such as those described in the Chip card manual.
In step 138, the extracted features are transmitted by the terminal 14 to the portable data carrier 20 via the interfaces 19, 22.
In step 140, when the data carrier receives them, it performs verification of the transferred extracted features. Here, the integrated circuit 24 compares the received extracted feature with the reference feature stored in the storage device, and checks whether a sufficient match occurs. If it appears
200380101997.X is a sufficient match, then in step 142, the portable data carrier '20 confirms to the terminal 14 the successful verification of the transmitted biometric characteristics. Moreover, the portable data carrier 20 transforms itself so as to be ready to perform a security establishment operation, that is, to perform a digital signature.
In step 144, after receiving the confirmation of the successful verification of the verification, the terminal 14 causes the data carrier 20 to execute the digital signature through a corresponding instruction. The terminal 14 transmits the electronic document 40 to be signed or at least a part of it together with the finger to the portable data carrier 20. Then, in step 146, the integrated circuit 24 of the portable data carrier 20 performs the operations required to create the digital signature. Generally, It forms a hash value on the received part of the electronic document 40, and encrypts it with a secret key in an asymmetric key pair composed of a secret key and a public key, and the secret key is stored in the storageDevice26in. Device 26.
In addition, in step 148, the integrated circuit 24 forms quality information indicating that the authentication of the user 30 was performed using biometric features. Furthermore, the quality information is firmly combined with the created digital signature, so as to advantageously form a security message within a secure messaging mechanism using a pre-negotiated session key.
In step 150, the thus formed security message consisting of the digital signature and quality information is transmitted back to the terminal 14 by the portable data carrier 20. From here on, the transmitted security message is transmitted within the implemented secure electronic transaction until the recipient involved in the transaction, such as the background system 10» In addition to the security establishment operation performed by the portable data carrier 20, The recipient of the security message simultaneously receives the status of the authentication quality of the user 30 performed through the quality information contained therein.
In the above example, quality information is only created when using biometric verification methods, and not when using knowledge-based methods. Thus, the lack of quality information has indicated the use of low-quality methods. However, it can of course be provided that quality information is always formed, that is, regardless of whether a knowledge-based method or a biometric method is selected for verification.
While maintaining the basic idea of attaching quality information about user authentication performed in advance to the result of the security establishment operation performed by the portable data entity, the above-mentioned concept allows other implementations and changes. This also applies to the design of the system used in the implementation of transactions, which can include more components and different types of components. The above process can also include other steps such as intermediate steps.
200380101997.X
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0182190A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO02067091A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| EP1045346A2 | Cites | European Patent Office (EPO) | Search report |
| CN1160891A | Cites | China | Search report |
| CN1272188A | Cites | China | Search report |
| US4993068A | Cites | United States of America | Search report |
| US6263447B1 | Cites | United States of America | Search report |
| US6408388B1 | Cites | United States of America | Search report |
14 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10249801 | Germany | A | |
| 10249801 | Germany | A | |
| 102498016 | Germany | – | |
| 102498016 | – | – | – |
| DE2002149801 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| DE10249801B3 | Germany | B3 | |
| WO2004038665A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003276154A1 | Australia | A1 | |
| BR0315675A | Brazil | A | |
| EP1573689A1 | European Patent Office (EPO) | A1 | |
| CN1708773A | China | A | |
| JP2006504167A | Japan | A | |
| RU2005115843A | Russian Federation | A | |
| US2006242691A1 | United States of America | A1 | |
| CN100365666CThis record | China | C | |
| RU2397540C2 | Russian Federation | C2 | |
| JP4578244B2 | Japan | B2 | |
| US8205249B2 | United States of America | B2 | |
| EP1573689B1 | European Patent Office (EPO) | B1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Termination of patent right due to non-payment of annual feeCF01 | CF01 | |
| Transfer of patent rightTR01 | TR01 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 100365666
- Publication, DOCDB
- 100365666
- Publication, EPODOC
- CN100365666C
- Application
- 80101997
- Application, DOCDB
- 200380101997
- Application, EPODOC
- CN200380101997
Titles2
- Chinese
- 使用便携式数据支持装置来执行安全电子交易的方法
- English
- Method for executing safe electronic transaction using portable data support device
Classification
- CPC, 8
- G07F7/1008
- G06Q20/341
- G06Q20/4014
- H04L9/3231
- H04L9/3247
- H04L2209/56
- H04L2209/805
- H04L9/3218
- IPC, 5
- G07F7 10
- G06F21 32
- G06F21 34
- G06F21 35
- G06F21 44