Method for managing a procedure for a back-up mode of a transaction, and associated device
Abstract
The invention essentially relates to a method for managing a backup procedure of a transaction backup mode, which can be activated in the event of a computer attack or a failure on a transaction network, implemented by an electronic device ( 110) adapted to perform a transaction in a normal mode or the backup mode, said method comprising the following steps: Receiving (F340) an activation command (CA) of said emergency mode procedure, comprising an identifier of the procedure and a first encrypted data, Checking (F360) of the activation command (CA), comprising a verification of said first encrypted data, • if the verification of the command is successful, activation (F370) of the rescue procedure.

Term
12.7 yearsto projected expiry
Projected expiry 22 May 2039, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
11 claims: 1 independent, 10 dependent
- 1Method for managing a backup procedure of a transaction backup mode, which can be activated in the event of a computer attack or breakdown on a transaction network (120), implemented by an electronic device (110) capable to carry out a transaction according to a normal mode or the backup mode, said method comprising the following steps:Reception (F340, F455) of an activation command (CA) of said emergency mode procedure, comprising an identifier of the procedure and a first encrypted datum, • verification (F360) of the activation command (CA), comprising a verification of said first encrypted data, • if the order verification is successful, activation (F370) of the emergency procedure (PMS), • after activation (F370) of the backup procedure (PMS) and following an initialization of a transaction between the electronic device (110) and a reader (130), sending (F520) of a message (M2) said reader (130) comprising a consultation request (RQ) from a normal mode server (124) of the transaction network (120), and • upon receipt (F540) of a message (M3) indicating that the consultation of the server (124) in normal mode has failed, sending (F570) to said reader (130) a cryptogram (CR) comprising at least one item of information on said procedure (PMS).
- 4Method according to any one of Claims 1 to 3, in which the at least one piece of information on said procedure (PMS) of the cryptogram is one of the following pieces of information:• a date for the start of the said procedure (PMS), • a date for the end of the said procedure (PMS), • said identifier of said procedure (PMS), • an indication that said cryptogram (CR) is generated during the implementation of said procedure (PMS).
- 5Method according to any one of Claims 1 to 4, in which said received message (M3) comprises a date of the transaction, the method comprising the following steps:• verification (F550) that the transaction date is between a start date and an end date of the procedure, • if the transaction date is before the start date or after the end date of the procedure, deactivation of this procedure.
- 6Method according to any one of Claims 1 to 5, in which the message (M3) received comprises the amount of the transaction, the method comprising the following steps:• incrementing a transaction number counter, • incrementing a transaction amount counter, • if the incremented transaction number counter is less than a transaction number threshold value and if the transaction amount counter is less than a transaction amount threshold value, a step of accepting the transaction.
Independent claims9
116 paragraphs, as filed
Invention background
0001The present invention relates to the field of transactions carried out by means of an electronic device, and more particularly relates to a method for managing a procedure of a transaction backup mode, which can be activated in the event of an attack or failure. on a transaction network.
0002In known manner, many banking transactions are carried out online, by means of an electronic device, via an electronic banking network.
0003The electronic banking network is a target for hackers with financial or political motivations. Indeed, a computer attack on an electronic banking network can have bad economic repercussions on the scale of a country. When the country is a developed country in which most transactions are carried out electronically, such an attack can typically paralyze the country's economy.
0004In addition to the financial cost, a computer attack or failure on an electronic banking network has a negative impact on the experience of users of the banking network and on the reputation of a banking establishment using the banking network.
0005There is therefore a need for a solution making it possible to improve the resilience of electronic banking networks, by limiting the negative impact of a computer attack on the users and of the banking establishment.
Subject and summary of the invention
0006To this end, the present invention relates to a method for managing a backup procedure of a transaction backup mode, which can be activated in the event of a computer attack or failure on a transaction network, implemented by a electronic device capable of carrying out a transaction according to a normal mode or the backup mode, said method comprising the following steps:<ul id="ul0001" list-style="bullet" compact="compact"><li>receipt of a command to activate said backup mode procedure, comprising an identifier of the procedure and first encrypted data,</li><li>verification of the activation command, comprising a verification of said first encrypted data item,</li><li>if the order verification is successful, activation of the emergency procedure.</li></ul>
0007Activating a rescue mode procedure, in which the attack or failure has no impact, improves the resilience of the transaction network. This activation makes it possible to limit the negative impact of a computer attack on the users and the banking establishment, the users being able to continue to carry out operations by means of the backup procedure.
0008In a particular embodiment, the first encrypted data is an authentication code calculated as a function of a private key, said private key being obtained by using the identifier of said procedure.
0009In a particular embodiment, the verification step comprises a verification that the value of the identifier of said procedure is greater than the value of a procedure identifier stored in the electronic device.
0010In a particular embodiment, the method comprises, after the activation of the backup procedure and following an initialization of a transaction between the electronic device and a reader, a step of sending a message to said reader comprising a request to consult a normal mode server of the transaction network.
0011In a particular embodiment, the method comprises, upon receipt of a message indicating that the consultation of the server of the normal mode has failed, a step of sending said reader a cryptogram comprising at least one information on said procedure among the following information:<ul id="ul0002" list-style="bullet" compact="compact"><li>a start date for this procedure,</li><li>a date for the end of said procedure,</li><li>said identifier of said procedure,</li><li>an indication that said cryptogram is generated during the implementation of said procedure.</li></ul>
0012In a particular embodiment, said received message comprises a date of the transaction, the method comprising the following steps:<ul id="ul0003" list-style="bullet" compact="compact"><li>verification that the transaction date is between a start date and an end date of the procedure,</li><li>if the transaction date is before the start date or after the end date of the procedure, deactivation of the said procedure.</li></ul>
0013In a particular embodiment, the message received comprises the amount of the transaction, the method comprising the following steps:<ul id="ul0004" list-style="bullet" compact="compact"><li>incrementing a transaction number counter,</li><li>incrementing a transaction amount counter,</li><li>if the incremented transaction number counter is less than a transaction number threshold value and if the transaction amount counter is less than a transaction amount threshold value, a transaction acceptance step.</li></ul>
0014In a particular embodiment, the method comprises a step of authenticating a user of the electronic device, the step of verifying the activation command being implemented if the authentication step is successful.
0015In a particular embodiment, the method comprises a step of deactivating said procedure, upon receipt of a command to deactivate said procedure.
0016The invention further relates to an electronic device, capable of implementing a method as described above.
0017In a particular embodiment, the different steps of the management method are determined by instructions of computer programs.
0018Consequently, the invention also relates to a computer program on an information medium (or recording medium), this program being capable of being implemented by an electronic device or more generally in a computer, this program comprising instructions adapted to the implementation of the steps of a management method as defined above.
0019This program can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a particularly compiled form, or in any other desirable form.
0020The invention also relates to an information medium (or recording medium) readable by an electronic device or more generally by a computer, and comprising instructions of a computer program as mentioned above.
0021The information medium can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a rewritable non-volatile memory (of the “EEPROM” or “Flash NAND” type for example), or such as a “ROM”, for example a “CD ROM Or a microelectronic circuit "ROM", or else a magnetic recording means, for example a floppy disc or a hard disk.
0022On the other hand, the information medium can be a transmissible medium such as an electrical or optical signal, which can be routed via an electrical or optical cable, by radio or by other means. The program according to the invention can in particular be downloaded from a network of the Internet type.
0023Alternatively, the information medium can be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.
Brief description of the drawings
0024Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an embodiment thereof devoid of any limiting character. In the figures:<ul id="ul0005" list-style="dash" compact="compact"><li>the <figref idref="f0001">figures 1</figref> and <figref idref="f0002">2</figref> schematically represent management systems in accordance with exemplary embodiments of the invention;</li><li>the <figref idref="f0003">figures 3</figref> and <figref idref="f0004">4</figref> represent, in the form of a flowchart, the main stages of the activation phases of management methods in accordance with exemplary embodiments of the invention;</li><li>the <figref idref="f0005">figure 5</figref> represents, in the form of a flowchart, the main stages of a payment phase of management methods in accordance with exemplary embodiments of the invention;</li><li>the <figref idref="f0006">figure 6</figref> represents, in the form of a flowchart, the main steps of a phase of deactivation of management methods in accordance with exemplary embodiments of the invention;</li><li>the <figref idref="f0007">figure 7</figref> represents, schematically, the data used during a step of generating a cryptogram of management methods in accordance with exemplary embodiments of the invention.</li></ul>
Detailed description of several embodiments
0025The <figref idref="f0001"><b>figures 1</b></figref><b>and</b><figref idref="f0002"><b>2</b></figref> schematically represent management systems 100 or 100 ′ in accordance with exemplary embodiments of the invention, capable of implementing management methods in accordance with exemplary embodiments, for example the method described with reference to <figref idref="f0002">figures 2</figref>, <figref idref="f0004">4</figref> and <figref idref="f0005">5</figref> for system 100 of the <figref idref="f0001">figure 1</figref>, or the process described with reference to <figref idref="f0003">figures 3</figref>, <figref idref="f0004">4</figref> and <figref idref="f0005">5</figref> for the 100 'system of the <figref idref="f0002">figure 2</figref>.
0026The system 100, 100 ′ comprises a first electronic device 110, which presents the conventional architecture of a computer. The first electronic device 110 notably comprises a processor 112, a read-only memory 114 (of “ROM” type), a rewritable non-volatile memory 115 (of “EEPROM” or “Flash NAND” type for example), a volatile rewritable memory 116 ( "RAM" type), and a communication interface 118.
0027In this example, the read-only memory 114 constitutes an information (or recording) medium in accordance with a particular embodiment of the invention. In the read-only memory 114 is stored a computer program P1 allowing the first electronic device 110 to implement a management method in accordance with an exemplary embodiment of the invention, or at least part of this management method . As a variant, the computer program P1 is stored in the rewritable non-volatile memory 115.
0028The first electronic device 110 is capable of carrying out a transaction according to a normal transaction mode or a transaction backup mode.
0029The expression “transaction mode” here designates a set of rules applied during the implementation of a transaction.
0030The normal transaction mode is the transaction mode used by the electronic device 110 under normal conditions of use. The set of rules applied when using the normal mode is typically defined in a specification, for example the EMV specification.
0031The transaction backup mode is a transaction mode used in place of the normal transaction mode when the normal transaction mode cannot be used, typically in the event of a computer attack or failure on the transaction network. The set of rules that can be applied when using the backup mode is described below, with reference to<figref idref="f0003 f0004 f0005 f0006">figures 3 to 6</figref>.
0032In order to carry out a transaction in normal mode or in standby mode, the first electronic device 110 can use an application for carrying out transactions, typically stored in the read-only memory 114 or the rewritable non-volatile memory 115 of the first electronic device 110. Such an application is for example implemented by a transaction operator such as a banking establishment, typically a banking establishment managing a bank account of the user of the first electronic device 110, this application being able then to be downloaded by the first electronic device 110. The application typically includes the P1 program.
0033The application can include one or more data associated with the rescue mode among the following data:<ul id="ul0006" list-style="bullet" compact="compact"><li>an identifier of a PMS procedure of the backup mode,</li><li>a start date for said PMS procedure,</li><li>a date for the end of said PMS procedure,</li><li>a threshold value of a number of transactions that can be carried out during said PMS procedure,</li><li>a threshold value of a total transaction amount that can be debited during said PMS procedure,</li><li>a transaction number counter,</li><li>a transaction amount counter.</li></ul>
0034The application can also include a first key dedicated to the emergency mode, a second key dedicated to the emergency mode, and / or an indicator of the emergency mode which can typically take the value "0" or "1".
0035As a variant, this data is stored in the read-only memory 114 or the rewritable non-volatile memory 115 of the first electronic device 110, outside the application.
0036The normal transaction mode and the transaction backup mode are typically managed by servers distinct from a transaction network 120, the transaction network 120 using a telecommunications network 126 and typically being an electronic banking network.
0037An electronic banking network typically uses a private telecommunications network 126, used by at least one operator of banking transactions, each operator of banking transactions being able to be a banking establishment or a service provider (ensuring for example interbank clearings). Visa or Mastercard networks are examples of electronic banking networks.
0038The transaction backup mode is notably managed by at least one backup mode server 122 of the transaction network, while the normal transaction mode is notably managed by a normal mode server 124 of the transaction network.
0039A transaction is further carried out by means of a reader 130 associated with the other party to the transaction (other than the user of the first electronic device 110). Typically, the reader 130 is a portable telephone, for example of the “smartphone” type, a digital tablet, or a personal computer.
0040The system 100 or 100 ′ can thus also comprise the server 122 of the emergency mode, the server 124 of the normal mode, and / or the reader 130.
0041The server 122 of the emergency mode, the server 124 of the normal mode and / or the reader 130 can also present the conventional architecture of a computer, and can each then in particular comprise a processor, a read only memory (of “ROM” type) ), a rewritable non-volatile memory (of the “EEPROM” or “Flash NAND” type for example), a volatile rewritable memory (of the “RAM” type), and a communication interface.
0042Each read-only memory can constitute a recording medium in accordance with an exemplary embodiment of the invention, readable by the associated processor and on which a computer program is recorded in accordance with an exemplary embodiment of the invention . Alternatively, the computer program is stored in the associated rewritable non-volatile memory. The computer program can allow the implementation of at least part of the management method in accordance with an exemplary embodiment of the invention.
0043As the <figref idref="f0001">figure 1</figref>, the first electronic device 110 is for example a fixed or mobile terminal such as a portable telephone, for example of the “smartphone” type, a digital tablet, or a personal computer.
0044The first electronic device 110 is then able to communicate with the server 122 of the emergency mode via a first telecommunications network 140, this first telecommunications network 140 typically being a long-range network, such as an Internet network, a Wifi network. , or a fixed or mobile telephone network (type 3G, 4G etc.).
0045In addition, the first electronic device 110 and the reader 130 are able to communicate with each other via the first telecommunications network 140 or a second telecommunications network 150. The second telecommunications network 150 is typically a short-range network, such as an NFC network (for “Near Field Communication” in Anglo-Saxon terminology).
0046In addition, the reader 130, the server 124 of the normal mode and / or the server 122 of the standby mode are able to communicate with each other via the telecommunications network 126 used by transaction network 120, this telecommunications network 126 being by the subsequently called the third telecommunications network 126.
0047Alternatively, as shown in the <figref idref="f0002">figure 2</figref>, the first electronic device 110 may be a smart card (typically a bank card), for example of ID-1 format specified in the ISO / IEC 7810 standard, having the dimensions 85.6 millimeters by 53.98 millimeters by 0, 76 millimeters.
0048The system 100 ′ can then further comprise a second electronic device 160, this second electronic device 160 being a fixed or mobile terminal such as a portable telephone, for example of the “smartphone” type, a digital tablet, or a personal computer.
0049The first electronic device 110 and the second electronic device 160 can communicate with each other via a fourth telecommunications network 170, this fourth telecommunications network 170 typically being a short-range network, such as an NFC network. The fourth telecommunications network 170 may be the same network as the second telecommunications network 150, or a separate network.
0050In addition, the second electronic device 160 is capable of communicating with the server 122 of the emergency mode via the first telecommunications network 140. The second electronic device 160 may include an application associated with the transaction operator.
0051In addition, the first electronic device 110 and the reader 130 are able to communicate with each other via the first telecommunications network 140, the second telecommunications network 150, or directly to the contact means when the first electronic device 110 is inserted in the reader. 130.
0052In addition, the reader 130, the server 124 of the normal mode and / or the server 122 of the emergency mode are able to communicate with each other via the third telecommunications network 126.
0053The <figref idref="f0003">figures 3</figref>, <figref idref="f0005">5</figref> and <figref idref="f0006">6</figref>, as well as <figref idref="f0004">figures 4</figref>, <figref idref="f0005">5</figref> and <figref idref="f0006">6</figref> represent methods of managing a procedure of a transaction backup mode in accordance with exemplary embodiments of the invention.
0054The <figref idref="f0003"><b>figure 3</b></figref> represents an activation phase of a management method in accordance with an exemplary embodiment of the invention, this activation phase making it possible to activate a backup PMS procedure of the backup mode, typically in the event of an attack IT on the transaction network or failure on the transaction network.
0055In the following description of the <figref idref="f0003">figure 3</figref>, it is considered that said activation phase is implemented by the system 100 for managing the <figref idref="f0001">figure 1</figref>. However, the method can be implemented by any management system comprising a terminal capable of carrying out a transaction according to the normal transaction mode or the transaction backup mode.
0056In a step 310, a computer attack or a failure on the transaction network 120 is detected (typically at the level of the server 124 of the normal mode).
0057The server 122 of the emergency mode can then activate, in a step E320, the PMS procedure of the emergency mode at the server 122 of the emergency mode, typically after having requested an activation authorization from one or more persons responsible for such activation.
0058The standby mode procedure is a procedure implemented during a predetermined period during which the normal transaction mode cannot be used, due to the failure or attack. Each procedure activated in step E320 is thus associated with a single failure or attack detected in step 310.
0059The standby mode server 122 can then determine an activation command CA of the standby mode PMS procedure (step E330). The CA activation command is typically a command similar to the script commands defined by the EMV standard, the parameters of the activation command being typically defined by the ISO 7816 standard. This CA activation command comprises an identifier of the PMS procedure and first encrypted data.
0060The identifier of the PMS procedure makes it possible to identify the PMS procedure of the emergency mode among one or more possible other procedures of the emergency mode (associated with other failures or attacks). A new backup mode procedure is in fact activated on each detection of a new computer attack or a new failure on the transaction network, and therefore on each new implementation of step 310. Thus, the identifier of the PMS procedure is typically a number, incremented with each new implementation of step 310.
0061The first encrypted data is typically an authentication code calculated as a function of a private key, said private key being obtained by using the identifier of the PMS procedure.
0062For example, the authentication code is a message authentication code (“MAC” for “Message Authentication Code” in English terminology). The MAC code can be calculated using a session key derived from the first dedicated emergency mode key, the identifier of the PMS procedure being used as the derivation value. The first key is typically a symmetric key, used to calculate the integrity of the data of the CA activation command.
0063The activation command CA can also include one or more data relating to the backup PMS procedure among the following data:<ul id="ul0007" list-style="bullet" compact="compact"><li>a start date for the PMS procedure,</li><li>a date for the end of the PMS procedure,</li><li>a threshold value of a number of transactions that can be carried out during said PMS procedure,</li><li>a threshold value of a total transaction amount that can be debited during said PMS procedure.</li></ul>
0064The activation command CA comprises for example a field CLA defining the class of the instruction, a field INS defining the instruction (this instruction being the activation of the procedure PMS of the emergency mode), fields P1 and P2 defining instruction parameters, an LC field defining the length of the activation command CA, a DATA field comprising the identifier of the backup PMS procedure and possibly one or more data relating to the aforementioned backup PMS procedure, and a MAC field comprising the first encrypted data item.
0065The server 122 of the emergency mode can then send, in a step E340 and to the first electronic device 110 (typically to the application of the first electronic device 110), via the first telecommunications network 140, a first message M1 comprising the command d CA activation.
0066The first message M1 can also comprise an information message intended for the user of the first electronic device 110, typically indicating that the PMS procedure of the emergency mode can be activated on the first electronic device 110.
0067Under reception F340 of the first message M1, the first electronic device 110 can display the information message. The first electronic device 110 can also authenticate the user of the first electronic device 110 (step F350). The authentication of the user is for example implemented by means of an authentication code or of a biometric data of the user.
0068In a step F360, the first electronic device 110 verifies the activation command CA received, this step E360 typically being implemented if the user is authenticated. This verification step F360 includes a verification of the first encrypted data.
0069Typically, the first electronic device 110 calculates a second encrypted datum then compares this second encrypted datum with the first encrypted datum. If the second encrypted data is identical to the first encrypted data, the first encrypted data is checked. Thus, the second encrypted datum is typically an authentication code calculated as a function of a private key, said private key being obtained by using the identifier of the PMS procedure, such as the MAC code, calculated by using a session key. derived from the first key dedicated to the emergency mode, the identifier of the PMS procedure being used as the derivation value.
0070Furthermore, the verification step F360 can comprise a verification that the value of the identifier of said PMS procedure is greater than the value of the procedure identifier stored in the first electronic device 110, which corresponds to this stage of the process. on the previous detection 310 of computer attack or failure on the transaction network.
0071The verification step F360 can also comprise a verification that the PMS procedure is not already activated.
0072More specifically, the first electronic device 110 checks whether the indicator for the emergency mode is not at the value "1". This verification makes it possible to counter a possible attack at the level of the first electronic device 110. In fact, as described below, the activation of the PMS procedure may include a reinitialization of one or more data associated with the backup mode, such as for example the total transaction amount. Checking the emergency mode indicator prevents several successive malicious resets of this data.
0073If the verification of the activation command CA is successful, the first electronic device 110 activates the emergency PMS procedure at the level of the first electronic device 110 (step F370).
0074This activation step F370 can comprise an initialization or a reinitialization of one or more data stored by the electronic device 110 and associated with the backup mode. For example :<ul id="ul0008" list-style="bullet" compact="compact"><li>the start and end dates of the PMS procedure stored by the electronic device 110 can be updated as a function of the start and end dates of the PMS procedure received in step F340,</li><li>the transaction number counter and the transaction amount counter can be set to zero,</li><li>the threshold value of a number of transactions and the threshold value of a total transaction amount stored by the electronic device 110 can be updated according to the threshold value of a number of transactions and the threshold value of a total transaction amount received in step F340, and / or</li><li>the emergency mode procedure identifier stored by the electronic device can be updated as a function of the procedure identifier received in step F340, and / or</li><li>the emergency mode indicator is set to "1".</li></ul>
0075The <figref idref="f0004"><b>figure 4</b></figref> represents a variant of the activation phase, implemented by the 100 'system of the <figref idref="f0002">figure 2</figref> or by any management system comprising a smart card capable of carrying out a transaction according to the normal transaction mode or the transaction backup mode.
0076This variant of the activation phase differs from the activation phase described with reference to the <figref idref="f0003">figure 3</figref> in that the standby mode server 122 sends, in step E440, the first message M1 to the second electronic device 160 (for example to the application of the second electronic device 160) via the first telecommunications network 140. The steps E320 and / or E330 previously described with reference to the <figref idref="f0003">figure 3</figref> can thus be implemented by the server 122 of the backup mode following step 310 and before step E440.
0077When G440 receives the first message M1, the second electronic device 160 can display the information message and / or authenticate the user of the first electronic device 110 (step G450), typically by means of an authentication code or user biometric data.
0078The second electronic device 160 can then issue a notification asking the user to position the first electronic device 110 near the second electronic device 160 so that they can communicate via the third telecommunications network 170.
0079The second electronic device 160 transmits the activation command CA in a step G455, via the fourth telecommunications network 170, to the first electronic device 110, this step G455 being typically implemented when the user is authenticated. The first electronic device 110 then implements steps F360 and F370, previously described with reference to the<figref idref="f0003">figure 3</figref>.
0080The <figref idref="f0005"><b>figure 5</b></figref> represents a payment phase for management methods in accordance with exemplary embodiments of the invention. Said payment phase can be implemented by the system 100 of the<figref idref="f0001">figure 1</figref> or the 100 'system of the <figref idref="f0002">figure 2</figref>, after the activation phase of the PMS procedure of the emergency mode of the <figref idref="f0003">figure 3</figref> or from <figref idref="f0004">figure 4</figref>.
0081In a step H510, the reader 130 sends a first transaction command CT1, this first command CT1 typically being a “Generate AC” command. The first transaction command CT1 is typically sent via the second telecommunications network 150.
0082Several other commands can be exchanged between the reader 130 and the first electronic device 110 before sending the first command CT1 "Generate AC". The first command CT1 "Generate AC" allows to carry out the transaction and to provide a result.
0083Step H510 is implemented when the user of the first electronic device 110 wishes to make a transaction with the user of the reader 130, and is thus sent following an initialization of a transaction between the first electronic device 110 and the reader 130.
0084After reception F510 of the first transaction command CT1, the first electronic device 110 executes said first transaction command CT1, in a step F520.
0085The PMS procedure of the backup mode being activated, the first electronic device 110 sends, during the execution of the first transaction command CT1, a second message M2 comprising a request for consultation RQ of the server 124 of the normal transaction mode. The second message M2 can be sent to the reader 130, via the second telecommunications network 150.
0086The reader 130 receives the second message M2 (step H520), then tries to connect to the server 124 of the normal mode by sending to the server 124 of the normal mode the request for consultation RQ of the message M2 (step H530) via the third telecommunications network 126.
0087The PMS procedure of the backup mode being activated, the server 124 of the normal mode does not respond to the request for consultation RQ, and the attempt to connect the reader 130 to the server 124 of the normal mode fails.
0088The reader 130 then sends, to the first electronic device 110, typically via the second telecommunications network 150, a third message M3 comprising a second transaction command, and which can comprise at least one transaction data (step H540). The second command is typically a “Generate AC” command, and indicates that the connection to the server 124 of the normal mode has failed.
0089On receipt F540 of the third message M3, in a step F550, the first electronic device 110 executes the second command by carrying out at least one verification linked to the transaction (step F550).
0090Each verification is typically based on transaction data from the third message M3, the data being for example a date of the transaction or a transaction amount.
0091For example, the first electronic device 110 verifies that the transaction date is between the start date of the PMS procedure and the end date of the PMS procedure stored in the first electronic device 110.
0092If the transaction date is before the start date or after the end date of the PMS procedure, the first electronic device 110 deactivates said PMS procedure, typically by setting the standby mode indicator to "0". The transaction is then processed in normal mode.
0093The first electronic device 110 can also increment the counter for the number of transactions by one unit.
0094Then, the first electronic device 110 can verify that the incremented transaction number counter is less than the transaction number threshold value.
0095If the incremented transaction number counter is greater than the transaction number threshold value, the first electronic device 110 deactivates the PMS procedure of the emergency mode, typically by setting the indicator of the emergency mode to "0", and the transaction is then processed in normal mode.
0096The first electronic device 110 can also increment the transaction amount counter by the transaction amount of the third message M3, then verify that the incremented transaction number counter is less than the threshold number of transaction value than the amount counter. less than a transaction amount threshold value.
0097If the incremented transaction amount counter is greater than the transaction amount threshold value, the first electronic device 110 deactivates the PMS procedure of the emergency mode, typically by setting the indicator of the emergency mode to "0", and the transaction is then processed in normal mode.
0098In the event that the verification or verifications carried out are successful, the first electronic device 110 can accept the transaction.
0099Following the reception of the third message M3, typically after the implementation of the verification (s), the first electronic device 110 can generate a CR cryptogram, in a step F560, said CR cryptogram being generated by means of the second key dedicated to emergency mode, said second key being typically symmetrical.
0100The generated CR cryptogram includes at least one information on the PMS procedure of the emergency mode, among the following information on the PMS procedure of the emergency mode:<ul id="ul0009" list-style="bullet" compact="compact"><li>the start date of the said PMS procedure,</li><li>the end date of said PMS procedure,</li><li>the identifier of said PMS procedure,</li><li>an indication that said CR cryptogram is generated during the implementation of said PMS procedure.</li></ul>
0101The CR cryptogram is generated and sent in case of acceptance of the transaction, but also in case of refusal of the transaction.
0102The <figref idref="f0007"><b>figure 7</b></figref> represents an example of data D1 to D11 used for the generation of the cryptogram. The data D1 to D8 come from the reader 130, and the data D9 to D11 are data from the first electronic device 110, as defined in the document “<nplcit id="ncit0001" npl-type="b"><text>EMV 4.3, Book 2, 8.1.1</text></nplcit> ».
0103Data D11, relating to the application of the first electronic device 110, comprises 32 bytes, bytes 18 to 32 being reserved for the transaction operator who implemented the application, as defined in the document " <nplcit id="ncit0002" npl-type="b"><text>EMV 4.3, Book 3, C7.2</text></nplcit> ". These Bytes 18 to 32 include one or more information among the information on the PMS procedure as described above.
0104In addition, bytes 4 to 8, from the CVR field (for "Card Verification Results", in English terminology) of the data D11, can include information on the type of cryptogram, information according to which the transaction is refused ( AAC data), information according to which the transaction is accepted (TC data), an indication that said CR cryptogram is generated during the implementation of said PMS procedure, etc. Typically, the value "RFU" in the "CVR Byte 1" field of the CVR field can include information that the transaction is accepted in emergency mode.
0105The first electronic device 110 then sends to the reader 130, typically via the first network 140 or the second network 150, a fourth message M4 comprising the cryptogram CR, and which may also include information according to which the transaction took place during the procedure Emergency mode PMS (step F570).
0106The reader 130 receives the fourth message M4 (step H570), and records the cryptogram CR (step H580). In case of validation of the transaction, the reader 130 transmits to the transaction network 120 (typically to the server 124 of the normal mode) information concerning the transaction after the deactivation of the PMS procedure of the backup mode, so that the server 124 of the normal mode can process the transaction once the transaction network 120 is able to function normally again. The server 124 of the normal mode then checks the cryptogram CR.
0107As the <figref idref="f0006"><b>figure 6</b></figref><b>,</b> after processing of the failure or of the attack, when the network 120 of transactions is able to function again normally, the server 122 of the standby mode deactivates, in a step E610, the PMS procedure of the standby mode.
0108The server 124 of the normal mode is then able to respond to consultation requests such as the consultation request RQ sent by the reader 130 in step H530.
0109Thus, upon receipt I630 of the consultation request RQ sent in step H530, the server 124 of the normal mode sends to the reader 130 a command to deactivate CDA of the PMS procedure of the backup mode, typically via the third telecommunications network 126 (step I640), the reader 130 transmitting (step H640) said CDA deactivation command to the first electronic device 110, typically via the second telecommunications network 150.
0110The first electronic device 110 receives F640 the command to deactivate CDA, then executes it in order to deactivate the PMS procedure of the emergency mode (step F650). The transaction is then further processed in normal mode.
0111The CDA deactivation command is typically a script command similar to the script commands defined by the EMV standard.
0112As a variant, when the server 122 of the emergency mode deactivates the PMS procedure of the emergency mode, the server 122 of the emergency mode sends to the first electronic device 110 the deactivation command CDA, typically via the first telecommunications network 140. The deactivation command CDA can be sent upon receipt of the consultation request RQ or can be sent after the deactivation of the PMS procedure by the server 122 of the emergency mode, even if no transaction concerning the first electronic device 110 is in progress. course.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2008076425A1 | Cites | United States of America | Search report |
| US2011321173A1 | Cites | United States of America | Search report |
| EMV: "EMV Integrated Circuit Card Specifications for Payment Systems Book 3 Application Specification Version 4.3", 1 November 2011 (2011-11-01), XP055527907, Retrieved from the Internet <URL:https://www.emvco.com/wp-content/plugins/pmpro-customizations/oy-getfile.php?u=/wp-content/uploads/documents/EMV_v4.3_Book_3_Application_Specification_20120607062110791.pdf> [retrieved on 20181128] | Non-patent | – | Search report |
8 members in 5 offices; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 1855026 | France | – | |
| 1855026 | France | A |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP3579588A1This record | European Patent Office (EPO) | A1 | |
| US2019378114A1 | United States of America | A1 | |
| FR3082332A1 | France | A1 | |
| FR3082332B1 | France | B1 | |
| EP3579588B1 | European Patent Office (EPO) | B1 | |
| PT3579588T | Portugal | T | |
| ES2878161T3 | Spain | T3 | |
| US11640597B2 | United States of America | B2 |
83 legal events, as 13 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Publication of translation of european patent specificationUEP | UEP | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidation of extension of european patentsMG9D | MG9D | LT | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Ep patent validated in finlandFGE | FGE | FI | |
| Translation is availableAVAILABILITY OF NATIONAL TRANSLATIONSC4A | SC4A | PT | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: FRENCHFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN PUBLISHEDSTAA | STAA | EP |
Numbers
- Publication
- 3579588
- Application
- 191759950
Titles3
- German
- VERFAHREN ZUR STEUERUNG EINES TRANSAKTIONSSICHERUNGSVORGANGS, UND ENTSPRECHENDE VORRICHTUNG
- English
- METHOD FOR MANAGING A PROCEDURE FOR A BACK-UP MODE OF A TRANSACTION, AND ASSOCIATED DEVICE
- French
- PROCEDE DE GESTION D'UNE PROCEDURE D'UN MODE DE SECOURS DE TRANSACTION, ET DISPOSITIF ASSOCIE
Classification
- CPC, 18
- G06F11/0751
- G06Q20/3226
- G06Q20/327
- G06Q20/3278
- G06Q20/34
- G06Q20/354
- H04W12/06
- H04W4/80
- H04L69/40
- H04W4/30
- G06F11/0709
- G06F11/2028
- G06F11/2038
- G06F11/2048
- H04W12/03
- G06Q20/401
- G06Q20/3223
- G06Q20/38215
- IPC, 5
- H04W4 80
- G06Q20 32
- G06Q20 34
- H04W4 30
- H04L69 40
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- Montenegro