The transfer of verification data
Abstract
A method and system are provided for transferring verification data from a first carrier to at least a second carrier in a secure manner. A first carrier, which is typically a smart card based ID card, contains verification data to identify the card holder securely. The method of the invention verifies the verification data on the ID smart card, reads the verification data, compresses and encrypts it, and writes it onto a second carrier, which may be a second smart card or a printed document, for example, in a machine readable form. The invention permits verification data to be securely transferred from one carrier to another, which permits a high degree of security in numerous applications such as the issuing of bank cards, medical aid claims, and other valuable documents.

Term
Term ended
Projected expiry passed 17 August 2021, 5.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
19 claims: 19 independent, 0 dependent
- 1Method for the transmission of verification data from a first carrier (12) Which is a portable data storage device, to a second carrier (30), The method comprising the steps of:To verify the verification data on the first support (12);Reading the verification data with a carrier reader;To back up the verification data with Verschlüsselungs- and / or compressing means;and Writing the data to authentication on the second carrier (30) In a machine readable format using a card reader / writer or a printer;characterized, that the Step of verifying the verification data the following steps comprising: controlling access to the first carrier (12) By verifying identity and / or the authorization of an operator to implement at least the reading step is determined;and verifying the identity of the holder the first carrier (12), Wherein the steps of the verification of the operator and the holder PIN / password and / or include biometrics-based verification procedures. Verfahren zur Übertragung von Daten zur Echtheitsprüfung von einem ersten Träger (12), welcher eine tragbare Datenspeichereinrichtung ist, auf einen zweiten Träger (30), wobei das Verfahren die Schritte umfasst: Verifizieren der Daten zur Echtheitsprüfung auf dem ersten Träger (12);Lesen der Daten zur Echtheitsprüfung mit einem Trägerleser;Sichern der Daten zur Echtheitsprüfung mit Verschlüsselungs- und/oder Komprimierungsmitteln;und Schreiben der Daten zur Echtheitsprüfung auf den zweiten Träger (30) in einem maschinenlesbaren Format mit einem Kartenleser/-schreiber oder einem Drucker;dadurch gekennzeichnet, dass der Schritt des Verifizierens der Daten zur Echtheitsprüfung folgende Schritte umfasst: Steuern des Zugriffs auf den ersten Träger (12) durch Verifizieren der Identität und/oder der Berechtigung eines Bedieners, der zur Implementierung zumindest des Leseschritts bestimmt ist;und Verifizieren der Identität des Inhabers des ersten Trägers (12), wobei die Schritte der Verifikation des Bedieners und des Inhabers PIN-/Passwort- und/oder auf Biometrie basierende Verifikationsverfahren umfassen.
- 2A method according to claim 1, characterized in that that the method includes the further steps of:controlling access to the verification data responsive to the second carrier (30) are written, reading the verification data (24;26;28) in terms of identity the holder of the second carrier and verifying the read data. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass das Verfahren die weiteren Schritte einschließt: Steuern des Zugriffs auf die Daten zur Echtheitsprüfung, die auf den zweiten Träger (30) geschrieben sind, Lesen der Daten zur Echtheitsprüfung (24;26;28) in Bezug auf die Identität des Inhabers des zweiten Trägers und Verifizieren der gelesenen Daten.
- 5A method according to claim 4, characterized in that that the second carrier (30) Is a second smart card. Verfahren nach Anspruch 4, dadurch gekennzeichnet, dass der zweite Träger (30) eine zweite Smartcard ist.
- 6A method according to claim 4, characterized in that that the second carrier (30) Comprises a document to which the verification data in be applied to a machine-readable format. Verfahren nach Anspruch 4, dadurch gekennzeichnet, dass der zweite Träger (30) ein Dokument umfasst, auf welches die Daten zur Echtheitsprüfung in einem maschinenlesbaren Format appliziert werden.
- 7A method according to any one of claims 1 to 6, characterized in that that the first carrier (12) A belonging to an individual's identity-based carrier is. Verfahren nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass der erste Träger (12) ein zu einer Einzelperson gehörender identitätsbasierter Träger ist.
- 8A method according to any one of claims 1 to 7, characterized in that that based on PIN / password and biometrically method used in conjunction with each other in a matching process will. Verfahren nach einem der Ansprüche 1 bis 7, dadurch gekennzeichnet, dass die auf PIN/Passwort und auf Biometrie basierenden Verfahren in Zusammenwirken miteinander in einem Abgleichverfahren verwendet werden.
- 9A method according to any one of claims 1 to 8, characterized in that that the securing step includes the steps of:adding additional Safety data on the verification data and compressing and encrypting the combined security and verification data. Verfahren nach einem der Ansprüche 1 bis 8, dadurch gekennzeichnet, dass der Sicherungsschritt die Schritte einschließt: Hinzufügen zusätzlicher Sicherheitsdaten zu den Daten zur Echtheitsprüfung und Komprimieren und Verschlüsseln der kombinierten Sicherheits- und Daten zur Echtheitsprüfung.
- 10A method according to claim 2, characterized in that that the step of controlling access to the written Verification data on the second carrier (30) Is substantially identical to the corresponding access control step in relation to the first carrier is. Verfahren nach Anspruch 2, dadurch gekennzeichnet, dass der Schritt des Steuerns des Zugriffs auf die geschriebenen Daten zur Echtheitsprüfung auf dem zweiten Träger (30) im Wesentlichen identisch mit dem entsprechenden Zugriffssteuerungsschritt in Bezug auf den ersten Träger ist.
- 11The method of claim 2 or claim 10, characterized in that the step of verifying the read Data on the second carrier (30) Is substantially identical to the corresponding verification step in relation to the first carrier is. Verfahren nach Anspruch 2 oder Anspruch 10, dadurch gekennzeichnet, dass der Schritt des Verifizierens der gelesenen Daten auf dem zweiten Träger (30) im Wesentlichen identisch mit dem entsprechenden Verifikationsschritt in Bezug auf den ersten Träger ist.
- 12A method according to any one of claims 2, 10 or 11, characterized in that the method still further includes the steps of:reading the verification data from the second carrier (30) and writing the verification data to a third carrier in machine Format. Verfahren nach einem der Ansprüche 2, 10 oder 11, dadurch gekennzeichnet, dass das Verfahren noch die weiteren Schritte einschließt: Lesen der Daten zur Echtheitsprüfung von dem zweiten Träger (30) und Schreiben der Daten zur Echtheitsprüfung auf einen dritten Träger in maschinenlesbarem Format.
- 13A method according to claim 12, characterized in that that the second carrier (30) Is a document to which the verification data in be applied to a machine-readable format, and the third carrier a portable data storage device. Verfahren nach Anspruch 12, dadurch gekennzeichnet, dass der zweite Träger (30) ein Dokument ist, auf welches die Daten zur Echtheitsprüfung in einem maschinenlesbaren Format appliziert werden, und der dritte Träger eine tragbare Datenspeichereinrichtung ist.
- 14A method according to claim 13, characterized in that that the third carrier is a smart card. Verfahren nach Anspruch 13, dadurch gekennzeichnet, dass der dritte Träger eine Smartcard ist.
- 15A method according to claim 12, characterized in that that the second carrier (30) Is a portable data storage device and the third carrier a document to which the verification data in be applied to a machine-readable format. Verfahren nach Anspruch 12, dadurch gekennzeichnet, dass der zweite Träger (30) eine tragbare Datenspeichereinrichtung ist und der dritte Träger ein Dokument ist, auf welches die Daten zur Echtheitsprüfung in einem maschinenlesbaren Format appliziert werden.
- 16A method according to any one of claims 1 to 15, characterized in that that the method for the secure transmission of verification data from a first carrier to an n th carrier via n - 2 carriers ensures, each data transfer step intervening secured. Verfahren nach einem der Ansprüche 1 bis 15, dadurch gekennzeichnet, dass das Verfahren für die sichere Übertragung von Daten zur Echtheitsprüfung von einem ersten Träger auf einen n-ten Träger über n – 2 Träger sorgt, wobei jeder dazwischen liegende Datentransferschritt gesichert ist.
- 17System for transmitting of verification data from a first carrier (12) Which is a portable data storage device, at least a second carrier (30) In a secure manner, the system comprising means for Verifying the verification data on the first carrier (12) a carrier reader for reading the verification data, means for securing the Verification data, and a card reader / writer or a printer for writing the data to Verification to a second carrier including in a machine readable format;characterized, that the means for verifying the verification data means for controlling access to the first carrier (12) By verifying the identity and / or the authorization of an operator to implement at least the reading of the data is determined for authenticity testing, and means for verifying the identity the holder of the first carrier (12), Wherein the means for controlling access the first carrier PIN / password and / or used in biometrics-based verification procedures. System zum Übertragen von Daten zur Echtheitsprüfung von einem ersten Träger (12), welcher eine tragbare Datenspeichereinrichtung ist, auf zumindest einen zweiten Träger (30) in einer sicheren Weise, wobei das System Mittel zum Verifizieren der Daten zur Echtheitsprüfung auf dem ersten Träger (12), einen Trägerleser zum Lesen der Daten zur Echtheitsprüfung, Mittel zum Sichern der Daten zur Echtheitsprüfung, und einen Kartenleser/-schreiber oder einen Drucker zum Schreiben der Daten zur Echtheitsprüfung auf einen zweiten Träger in einem maschinenlesbaren Format einschließt;dadurch gekennzeichnet, dass das Mittel zum Verifizieren der Daten zur Echtheitsprüfung Mittel zum Steuern des Zugriffs auf den ersten Träger (12) durch Verifizieren der Identität und/oder der Berechtigung eines Bedieners, der zur Implementierung zumindest des Lesens der Daten zur Echtheitsprüfung bestimmt ist, und Mittel zum Verifizieren der Identität des Inhabers des ersten Trägers (12) umfasst, wobei das Mittel zum Steuern des Zugriffs auf den ersten Träger PIN-/Passwort- und/oder auf Biometrie basierende Verifikationsverfahren verwendet.
- 18System nach Anspruch 17, des Weiteren dadurch gekennzeichnet, dass das System Mittel zum Steuern des Zugriffs auf die Daten zur Echtheitsprüfung auf dem zweiten Träger (30), Mittel zum Lesen der Daten zur Echtheitsprüfung (24;26;28) in Bezug auf die Identität des Inhabers des zweiten Trägers (30) und Mittel zum Verifizieren der gelesenen Daten zur Echtheitsprüfung auf dem zweiten Träger (30) einschließt. The system of claim 17, further characterized in that the system comprises means for controlling access to the data for authentication on the second carrier (30), Means for reading the verification data (24;26;28) in terms of identity of the holder of the second carrier (30) and means for verifying the read verification data on the second carrier (30) Includes.
- 19System according to claim 18, characterized in that that the securing means of encryption and decryption means and compressing and decompressing means for compressing, encrypt, decipher and decompress the data includes the authentication. System nach Anspruch 18, dadurch gekennzeichnet, dass das Sicherungsmittel Verschlüsselungs- und Entschlüsselungsmittel sowie Komprimierungs- und Dekomprimierungsmittel zum Komprimieren, Verschlüsseln, Entschlüsseln und Dekomprimieren der Daten zur Echtheitsprüfung einschließt.
Independent claims19
63 paragraphs in 4 sections, as filed
BACKGROUND THE INVENTION
These Invention relates to a method and a system for secure transmission of verification data.
Smart Cards be due to their ability, size Amounts of portable data in a safe and compact way Way to carry, more popular.
especially with respect to the fight against fraud grows increasingly the importance of verification and identification issues in the smart card technology. Most users still prefer the documentation to Paper base and associated with such documentation usual Verification procedures so that certain documentation likely will never be replaced by electronic forms.
On Another problem which is connected to the smart card technology, is that the owner of the smart card, the card in his Possession has, which means that institutions such as banks only upon presentation of the smart card have access to the verification data. In many cases this makes it difficult an institution to regular access to safety data.
In many countries is the multi-functional smart card technology already for use accepted with identity documents and cards. It is an object of this Invention, the simple integration of such identity cards with other technologies portable data files as well as documents to allow paper-based.
SUMMARY THE INVENTION
General expressed the invention aims at a method for transmitting of verification data from a first carrier at least a second carrier to provide in a safe manner, so that data on the second verified carrier independent can be.
On Such a method is broadly described in FR-A-2771528. This prior art is in the preamble of claims 1 and 17 appreciated.
In a first aspect of the invention is a method for transmitting of verification data from a first carrier, which is a portable data storage device, a second on carrier created, the method comprising the steps of: verifying the verification data on the first carrier; Reading the verification data with a carrier reader; Securing the verification data with encryption and / or compression means; and writing the verification data on the second carrier in a machine-readable format using a card reader / writer or a Printer; characterized in that the step of verifying the verification data comprising the steps of: controlling access to the first carrier by Verifying the identity and / or credentials of an operator, at least for implementing the reading step is determined; and verifying the identity of the holder the first carrier, the steps of the verification of the operator and the owner PIN / password and / or biometrically-based verification procedures.
In a preferred embodiment, of the invention, the method comprises the further steps of: controlling access to the verification data written to the second carrier, Reading the verification data and verifying the read data.
Of the first carrier may be a first smart card.
Of the second carrier may similarly As a portable data storage device in the form of a second his smart card.
alternative , the second carrier comprise a document to which data for the authenticity check in a machine-readable format, for example by printing applied, will.
Of the first carrier , a belonging to an individual's identity-based carrier be.
The be on PIN / password and biometrically-based procedures preferably in cooperation with one another in a matching process used.
Of the Securing step may include the steps of: adding additional security data to the verification data and compressing and encrypting the combined security and verification data.
Of the Step of controlling the access to the data written to authentication on the second carrier is essentially identical to the corresponding access control step in relation to the first carrier.
Similarly Manner, the step of verifying the read data on the second carrier <?page 3?>in the Substantially identical to the corresponding verification step in relation to the first carrier.
The The method may still include the further steps of: reading the data concerning authentication of the second carrier and writing the verification data to a third carrier in machine Format.
Of the second carrier is typically a document to which the verification data in be applied to a machine-readable format, and the third carrier is typically a portable data storage device such as, for Example a smart card.
alternative , the second carrier can be a portable data storage device, and the third carrier be a document to which the verification data in be applied to a machine-readable format.
The Invention can thus for secure transmission of verification data from a first carrier on an n-th carrier via n - 2 straps provide, each data transfer step intervening secured.
The Invention also extends to a system for transmitting of verification data from a first carrier, which is a portable data storage device, to at least a second carrier in a secure manner, the system including means for verifying the verification data on the first carrier, a carrier reader for reading the verification data, means for securing the Verification data, and a card reader / writer or a printer for writing the verification data to a second carrier including in a machine readable format; characterized, that the means for verifying the verification data means for controlling access to the first carrier by verifying the identity and / or the authorization of an operator to implement at least the reading of the data is intended for authentication; and means for verifying the identity of the Holder of the first carrier , wherein the means for controlling access to the first Support PIN / password and / or used in biometrics-based verification procedures.
Preferably closes the system further comprises means for controlling access to the Verification data on the second carrier in terms of identity the holder of the second carrier, Means for reading the verification data on the second carrier, and Means for verifying the read verification data on the second carrier on.
The Securing means includes typically encryption and decryption means and compressing and decompressing means for compressing, encrypt, decrypting and Decompressing a the verification data.
SUMMARY THE DRAWINGS
<figref idrefs="S22">1</figref> shows a schematic flow diagram of a first embodiment a method for transmitting of verification data from a first smart card to a second smart card;
<figref idrefs="S23">2</figref> shows a schematic flow diagram of a second embodiment a method for transmitting of verification data from a first smart card to a document;
<figref idrefs="S24">3</figref> shows a schematic flow diagram of a third embodiment a method for transmitting of verification data, in which the data from a first smart card to a second SmartCard over transmit a secured document will; and
<figref idrefs="S25">4</figref> on conventional Flowchart summarizing the major steps of the method.
DESCRIPTION THE EMBODIMENTS
The Invention will now be described by way of three embodiments which various possible Applications thereof illustrate. The first embodiment applies for the issue of a second smart card, typically by a bank or another financial institution, to the holder a first smart card, which is typically an identity card is.
Among Referring first to <figref idrefs="S22">1</figref> A first series of Steps for user access control, identification of the cardholder and Read the smartcard schematically in block <figref>10</figref> illustrated. A first smart card in the form of a personal identity card <figref>12</figref> becomes presented to an operator of an institution such as a bank. In the first step of the access control verification is the Operator required. This can be achieved by a number of ways, either verifying the PIN code or password <figref>14</figref> of Operator or by matching the fingerprint <figref>16</figref> of Operator using finger biometrics. Naturally, the PIN code is not as secure as the method for matching of the fingerprint, because the identity the operator does not ensure. As is known, may a third Party a PIN code on different ways to acquire so Biome<?page 4?>industry is preferred.
Three alternative method of verifying the finger biometrics of the operator was developed. In the first method, known as "password-controlled One-to-one matching process " the operator enters the password <figref>14</figref> into a computer and then places his finger on the fingerprint scanner. The password serving as a search key for the database entry, containing the finger biometrics of the operator, and the biometric data are from the live finger scan with the out of the database entry retrieved data compared.
In the second method, known as "map / live scan finger matching method", is the operator equipped with an access card. This card is either in the form of a smart card or a card with a two-dimensional Barcode before, wherein the fingerprint biometric machine-readable in the Data of the card is included. To gain access, the obtained from the card finger biometric data with those derived from the live finger scan compared.
The includes third method to identify the finger biometrics a one-to-many finger matching method. This method is the similar manner, in which a number working of automatic fingerprint identification systems. A live finger scan is registered with many in a database fingerprints compared. If a match occurs, access is granted. There many database entries need to be searched, the fingerprint patterns are usually classified, in order to reduce the search time. This method is typically only with 150 or fewer registered users really handy. An alternative is the use of fingerprint scanners, that have a firmware within the scanner, which biometric one Live Scan can compare many biometrics, within the Scanner apparatus are stored in memory.
As soon as the fingerprint <figref>16</figref> and / or password <figref>14</figref> of are matched operator, the data from the server database are logged on the computer. These recorded data usually for the purpose of portable verifiability to the smart card <figref>12</figref> read Data added. If a positive operator verification and identification takes place is the smart card <figref>12</figref> in to a PC <figref>22</figref> connected Smart card reader <figref>20</figref> introduced. Instead of a conventional Desktop PC, a laptop or notebook PC or other portable Computing device used. A secret public Keycode the for access to the data of the smart card is required, in Hidden from the program used to access the data the user's smart card to receive as well as the verification data, together with other types of data to decode.
Of the next Step in the method for testing the authenticity is the identity of the cardholder to verify. The nature of the method for verifying the identity depends on what verification data on the smart card <figref>12</figref> Are available. In cases where the smart card simply a PIN code or password for the cardholder which gives the operator or preferably the cardholder the PIN code on the keyboard of the PC, then the PIN code is then verified. Preferably, the smart card transmits a digitized Portrait Photo and / or a digitized signature image. In this case, this on the monitor of the PC <figref>22</figref> displayed, and the identity of the cardholder is visually confirmed by the operator. If fingerprint biometrics in the verification data available is, it can with a live finger scan <figref>28</figref> Cardholder are compared. In this case, the verification is done automatically rather than by visual matching by the operator, as with the portrait photo <figref>24</figref> and Signature image <figref>26</figref> the case was.
Just in the case of the verification of the operator and cardholder verification for rewriting a second smart card <figref>30</figref> processed, such as This schematically at <figref>32</figref> is shown. Now, the Amount of data to the second smart card <figref>30</figref> written Need to become, additional data added. This information includes details on the operator and possible added verification details, which are derived from other documentaries and which institution the may require. These are, for example, amounts of money, time and expiration dates, Warranty and so on. Also timestamps of transactions can appended to the data will.
The read from the first smart card data is now with together the additional captured data compressed by various compression techniques. In the case of digital image compression is a lossy Compression technology used. This can be either on fractal or wavelet image compression based. Both of these techniques compress the image by filtering out the less relevant image information less critical for the human visual identification process is. If the not based on data images, a lossless compression used. In this type of compression which on arithmetic Coding is based, no data is discarded. Arithmetic coding provides the best compression ratios, but is one of the slowest lossless Komprimie<?page 5?>tech- nologies. Since the amounts of data are not particularly large, this compression technology is the most suitable. Different Data elements are compressed using different encryptions. After the data is compressed, it is encrypted again with the private key the institution (in this case the bank) in secret by the Program is used to encrypt the data again.
On encryption scheme with private / public key is used. The private key can only encrypt and any operator ever known. The public key can the data only decrypt. The public key can for the decryption are distributed in many places, the private / public encryption on the RSA encryption based. Both the private and the public keys are typically determined from digital certificates, which provide this key, when the correct passwords be entered. below the layer of the public / private key two additional layers of encryption. The one layer generates unique keys from the uniqueness the data in the dataset of each card. The other layer merely scrambles the data using a number of Verwürfelungsalgorithmen.
For additional Security has also developed a technology to the HASP "dongle" of Aladdin company. This is a highly secure device which at the parallel, USB or serial port of the PC is connected and used is to hold the digital certificate which the secret private and public key for the encoding and decryption data supplies. An additional Alternative is another product of the company Aladdin, known as "e-Token", the device is a is that is connected to a USB port of a PC and what especially designed for was to passwords, key and digital certificates digital signatures and encryption by means of a public key infrastructure to supply. The dongle also additional scrambled codes stored together with operator log data. A further use the HASP dongle is executable programs on the other hand, protect, that they observed, manipulated, copied, or on another machine accomplished are used as those for which they were registered. This is the secret by a combination of surrounding seed codes on the dongle and an executable program achieved software.
Among Referring back to the step of writing the card, the schematically at <figref>32</figref> is shown, will now be the second Smart Card <figref>30</figref> in the smart card reader <figref>20</figref> introduced. Before the data on the smart card <figref>20</figref> can be written, is further access to the private key of the smart card in secret carried out by the program. Once the data to the smart card <figref>30</figref> were written, the bank or other institution the features for authenticity testing, the originally on the first identity card SmartCard <figref>12</figref> were worn, on the second smart card <figref>30</figref> captured, and any other Data that combines the institution with the detected characteristics for the authenticity check need like. additional Details of other institutions may also in this second Card be written.
The next Stage in the transfer procedure is the verification stage to the bank's own smart card <figref>30</figref>In which the data of the first smart card detected and written to the second smart card were to be retrieved and used. This method is schematically in block <figref>34</figref> shown. The Smart Card<figref>30</figref> becomes in a smart card reader <figref>36</figref> introduced, which to a PC <figref>38</figref> affiliated is. Again, the operator must comply with the procedures for operator verification / access control, above with reference to block <figref>10</figref> have been described. After positive operator identification and verification is the public keycode in secret to the smart card <figref>30</figref> passed so that data from the smart card can be read. After reading the data is then decrypted by the program in Secret password to the digital certificate is, which the private key for the decryption the data provides. Each data type, whether based on images or image based, is decompressed as soon as it is decoded. The decompressed, decrypted Such data is then displayed on the monitor of the PC as at <figref>39</figref> shown that the operator the identity of the cardholder <figref>24</figref> to verify can. In the case of finger biometrics, the cardholder places a finger on the fingerprint scanner, as in <figref>28</figref> shown, and the derived biometric data are in a one-to-one matching process with those from the smart card read compared, the verification takes place automatically. The result of the verification can together with the details of the operator for the purpose of verification are logged.
Among with reference to <figref idrefs="S23">2</figref> Now, a second embodiment a method for transmitting of verification data shown. The first steps of operator access control, reading the Smart card and verification and identification of the cardholder are identical to those in <figref idrefs="S22">1</figref> illustrated, as specified in the blocks <figref>40</figref> or. <figref>42</figref> shown. In block <figref>44</figref> the data for Echtheitsprü<?page 6?>tion together with any additional Data such as those in the above in connection with <figref idrefs="S22">1</figref> reference was taken, in the same way with the combined <figref idrefs="S22">1</figref> described was compressed and encrypted. This data is then in a two-dimensional symbol or barcode <figref>46</figref> coded. The two-dimensional barcode has a Reed-Solomon error correction, which a complete enables recovery in the event of partial destruction of the symbol. The two dimensional symbol may either be an image based on two-dimensional symbology or a font based on a be such symbology. It can available image-based two-dimensional commercially Symbologies are used, including PDF417, Super Code, Aztec QR Code and Data Matrix.
It It can be seen that such two dimensional symbols are not conventional limited printing techniques are, and etched, for example, metal surfaces, laser engraved or many other ways can be applied. The use of other multi-dimensional machine readable code forms such as stacked Barcodes or matrix barcodes, is also possible.
Of the Applicant also has a font-based two-dimensional symbology developed, which in text form on the basis of a particular Font set can be sent to a printer. A particularly constructed TrueType font interprets the text line by line. This type of two-dimensional symbology can also mass printing used extreme in which image-based icons memory requirements have and tend to high-speed production to slow down. This means that the verification data, the are obtained from the smart card, in mass printing devices may be used in which the data is integrated in the two-dimensional barcodes are printed in high-speed mass printing.
Of the Applicant has also developed a two-dimensional symbology that can not be copied, and the subject of international patent application No. PCT / IB01 / 00362 forms. This provides additional protection for the data concerning authentication within the two-dimensional barcode or symbol <figref>46</figref> on printed documents, since it prevents such symbols copied can be.
The from the verification smart card data obtained in a the aforementioned two-dimensional symbols <figref>46</figref> encodes then to a document <figref>48</figref>. such as a check is printed. If the document an electronic Document, the read data are in a PC <figref>50</figref> electronic appended to the document and then a printer <figref>52</figref> printed. Alternatively, the document, if it is not electronically in the printer <figref>52</figref> inserted, so that the symbol <figref>46</figref> can be printed on it. It can a label on which the symbol is printed on the Document attached. Non-removable labels of the Type, which is manufactured by the 3M Company are preferred. It is sometimes easier to print a label on the document and to install, especially when an existing document want to verify. The same applies to a electronically-signed paper document. The verification data which obtained from the verification smart card, can additional Data are combined, the derived from the document itself be such as amounts or Data appearing on the document, which then, in the data which are contained in the two dimensional symbol on the document, be included.
Among Referring to block <figref>54</figref> Now place a verification process instead, in which the verification details of the operator using a hand-held scanner <figref>56</figref> scanned on a PC <figref>58</figref> decrypts and using password or fingerprint biometrics identification means <figref>14</figref> or. <figref>16</figref> verified are as defined above in reference to block <figref>34</figref> from <figref idrefs="S22">1</figref> described.
Of the scanner <figref>56</figref> can be either a laser or a linear two-dimensional CCD scanner, an image-based two-dimensional scanner, or a its flatbed scanner. If the symbol of a non-reproducible Type is a special scanner to be used in the Is able to read the symbol form, the scanner is able is the icon while the scanning process to be separated from the protective layer.
The data can then through the scanner device <figref>56</figref> decoded and on the serial port on the PC <figref>58</figref> (Or other computing device) sent will. Alternatively, the image of the symbol of a flatbed scanner "captured" or scanned and from the host PC <figref>58</figref> decoded. The decoded data using a public key, is passed in secret from the system, decrypts, and the data is then decompressed, as shown in block <figref>60</figref> displayed. The decoded and decompressed data are then used for operator verification or Automatic Verification by finger biometrics by matching a live finger swipes the card holder against the encrypted finger scan <figref>62</figref>Consisting of the two-dimensional symbol from the <figref>46</figref> read Data is obtained on the monitor of the host PC <figref>58</figref> displayed.
<?page 7?>
data concerning authentication can for subsequent verification and analysis are stored, and the computer <figref>58</figref> can Also various forms of verification data, such as about the ID number of the cardholder, verify. automated Verification can be obtained by scanning the documents in a batch process using flatbed scanners, which equipped with a document feeder are carried out.
Among with reference to <figref idrefs="S24">3</figref> Now, a third embodiment a method for transmitting of verification data shown. The first Zugriffssteuerung- and card reading steps, the Block <figref>64</figref> are displayed, and the step of Kartenin haber verification and identification, the block <figref>66</figref> is shown, substantially identical to the corresponding initial steps from <figref idrefs="S22">1</figref> and <figref idrefs="S23">2</figref>, Similarly, the step of encoding and printing of the two-dimensional symbol, the in block <figref>68</figref> appears identical to the corresponding in block <figref>44</figref> from <figref idrefs="S23">2</figref> Step illustrated. block<figref>70</figref> shows the subsequent steps, in which the two-dimensional symbol <figref>46</figref> scanned and to a third smart card <figref>72</figref> is written. In this Step is the two-dimensional symbol <figref>46</figref> on the document <figref>48</figref> under use scanner <figref>56</figref> scanned, as described above with reference to block <figref>54</figref> from <figref idrefs="S23">2</figref> described has been. The scanned data is in sequence with a card reader / writer<figref>74</figref> under use exactly the same method based on reference block <figref>32</figref> from <figref idrefs="S22">1</figref> has been described, to the third smart card <figref>72</figref> written. The third smart card is read in the sequence the data is processed and the Verification and identification of the cardholder takes place in exactly the same manner instead of as referring to the blocks <figref>34</figref> and <figref>38</figref> from <figref idrefs="S22">1</figref> described has been.
The Flow chart of <figref idrefs="S25">4</figref> summarizes the main steps the underlying process together.
The Invention will now be described with reference to two specific applications described in the "real world".
The dramatic increase in vehicle theft and kidnapping has led to a global demand for countermeasures. The in this application described invention may be particularly useful and cost-effective Protection used against vehicle theft. This application also shows the effective use of this invention with the proposed new smart card identity card of the Republic of South Africa.
at the application for vehicle registration is the identity card of the applicant the submitted operator. The identity card in this case is a smart card, the identity data and verification data contains. The operator carries out the ID smart card in the card reader and gets a finger biometric method concerning authentication Access control. The verification data are from the smart card Read. The applicant shall then his finger on a fingerprint scanner and his biometric data with those obtained from the ID card reconciled. This ensured that the person really the holder of the card. The personal data of the Map obtained, will now be compared to the online vehicle owner database checked, to ensure that the cardholder actually the owner of the vehicle. The operator details, vehicle registration details and verification details obtained from the map, are compressed and encrypted. The data is then encoded into a two dimensional symbol and printed on a pre-printed, blank admission badge. In this case allows the previously printed, blank admission badge the creation of a non-reproducible two-dimensional symbol. transmits the license disk now all the details of the identity card of the applicant in a machine-readable Form on the vehicle license disk. Between the operator and the applicant, there can be no collusion, and actually bears admission badge now a highly secure copy of the identity document of the applicant itself.
The Invention also has useful applications in health care systems, ie systems or programs in their subscriber payment support of medical treatments (such programs are in the United States than traditional health insurance Refund known). A smart card is particularly useful and safe for medical card Supply, especially since the person presenting the card, can be verified as real owner of the card. Other Uses are safe writing of diagnoses, prescriptions and medical Certificates on the smartcard. Funds for medical care and related have institutions no over an identity card infrastructure that will enable them would, Smart cards with positive identity features to produce it. It is very convenient and inexpensive, these Verification data the identity card SmartCard be able to remove.
On Another problem with existing cards for medical care is the fact that the authentication in the consulting rooms of doctor or hospital and not the medical provider itself takes place. The medical providers can thus never quite sure be that the <?page 8?>Verification is really done. The medical Device can not be sure that the claimed investigation has actually taken place.
In this application, the data on the authentication of the ID card on the smart card for medical care (Or a card for medical care with a two-dimensional barcode) Read. The card for medical care now has the same features for authenticity testing on as a personal identification card. If the smart card for medical Supply from hospital is presented, the Patient be identified and verified. The positive detection the verification, the verification data from the smart card, the be doctor's diagnosis, details about prescriptions and certificates then compresses and encrypts and in the form of a two-dimensional symbol on an application form for medical benefits printed. This request is sent to a secure application form, not changed tampered with or fraudulently Intent can be created, and now in a safe way a received medical providers can be. The facility in which medical providers and scans decodes the application form, analyzed and verified the patient with reference to the verification data, and processes the application form automatically.
The Invention expands the application of smart card technology particularly in terms of security and authentication, enormous. It integrates smart card technology and paper documentation on effective manner. The invention also leads to considerable Cost savings, since the created by the smart card identification Features for authenticity testing in effectively can be used by many institutions, without that this infrastructure to create these secure features concerning authentication need. Expenditure a secure identity card system (these are considerably if If the cost of a large national "automatic Identity search system "taken into account, the but is required to multiple registrations of a single Person to prevent) be justified if the use of Map can be extended in such a drastically.
The Invention finds particular application in the field of processing regulatory and business applications and the same. The extent of the territory is matched only by its versatility. Virtually all applications require proof of identity. Currently, the card book of the applicant is required and a Photocopy created. This is a very unsafe practice and in Connection not particularly effective with the new smart card identity card, since most of the details contained on the card's chip. For all kinds applications be the verification details in a two-dimensional symbol encoded and printed on the relevant application form. The application form is now permanently through a verifiable proof of the applicant connected. The data read from the smart card details can be used be to the personal Applicant data entered automatically. The data within the two-dimensional symbol can even later are scanned, so that the application will be processed automatically can.
Some important examples in which the invention through the fight against fraud Creation of a suitable method for testing the authenticity as will prove effective include contract documents, insurance documents, Certificates and applications Receiving documents in hospitals and medical facilities, cards for medical care, Application forms for medical services, medical Certificates and prescriptions, and bank documents, including forms employee information, Application forms for Accounts, loans and mortgages. Other areas of application are documents and Applications personal include information, application forms and questionnaires on Employment and accounts, and created by the government forms such as in connection with censuses, Elections, requests Registration on the electoral roll, and various kinds of approvals such as approvals for broadcasting, Commercial and Military passports. In the field of education, the invention is applicable to such documents Test documents, applied student application forms and cards and diplomas will. Vehicle-related documents such as vehicle registration papers and Registration tags for the windshield can also benefit from the invention, and all kinds of bankable Papers such as checks, bills, invoices and tickets.
The the above examples are not exhaustive or limiting and were cited merely as an example.
Contents4
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
14 members in 9 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 200004221 | South Africa | A | |
| 200004221 | South Africa | A | |
| 200004221 | South Africa | – | |
| 0101481 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 0101481 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 0101481 | International Bureau of the World Intellectual Property Organization (WIPO) | – | |
| 200004221 | – | – | – |
| PCTIB0101481 | – | – | – |
| WO2001IB01481 | – | – | – |
| ZA20000004221 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO0215117A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU8431401A | Australia | A | |
| WO0215117A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1312033A2 | European Patent Office (EPO) | A2 | |
| BR0113327A | Brazil | A | |
| US2004026502A1 | United States of America | A1 | |
| ZA200302120B | South Africa | B | |
| EP1312033B1 | European Patent Office (EPO) | B1 | |
| AT317572T | Austria | T | |
| ATE317572T1 | Austria | T1 | |
| DE60117153D1 | Germany | D1 | |
| ES2259669T3 | Spain | T3 | |
| DE60117153T2This record | Germany | T2 | |
| US7789302B2 | United States of America | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 60117153
- Publication, DOCDB
- 60117153
- Publication, EPODOC
- DE60117153T
- Application
- 60117153
- Application, DOCDB
- 60117153
- Application, EPODOC
- DE20016017153T
Titles3
- English
- TRANSMISSION OF DATA FOR AUTHENTICATION
- German
- ÃBERTRAGUNG VON DATEN ZUR ECHTHEITSPRÃFUNG
- German
- ÜBERTRAGUNG VON DATEN ZUR ECHTHEITSPRÜFUNG
Classification
- CPC, 6
- G07F7/1008
- G06Q20/341
- G06Q20/3552
- G06Q20/40145
- G06Q20/4097
- G07F7/1016
- IPC, 2
- G06K7 00
- G07F7 10