Individual certification method using bar code
Abstract
A certification procedure for people using a portable terminal (30), said procedure comprising the steps of: generating and transmitting by means of a certification server (10) a query code to the portable terminal (10) following a request from the portable terminal ( 30), in which said query code is different from any query code generated by the certification server (10) in the past; receive the inquiry code transmitted by the certification server (10) via the portable terminal (30); displaying in said portable terminal (30) as a barcode or a two-dimensional code the query code received by said portable terminal (30); read the barcode or the two-dimensional code received by said portable terminal (30) with a reader (21) connected to a sales management server (23) and transfer the query code from the reader (21) to the management server sales (23); return the query code from said sales management server (23) to the certification server (10); verify on the certification server (10) the query code generated with the query code transmitted through the sales management server (23); and transmit personal information corresponding to the query code to the sales management server (10) to the sales management server (23) when the two codes are identical to each other.

Term
Term ended
Projected expiry passed 28 February 2021, 5.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
6 claims: 1 independent, 5 dependent
- 1ES 2 302 722 T3 REIVINDICACIONES 1. Un procedimiento de certificación de personas que usa un terminal portátil (30), comprendiendo dicho procedimiento las etapas de:generar y transmitir mediante un servidor de certificación (10) un código de consulta al terminal portátil (10) tras una solicitud del terminal portátil (30), en el que dicho código de consulta es diferente de cualquier código de consulta generado por el servidor de certificación (10) en el pasado;recibir mediante el terminal portátil (30) el código de consulta transmitido por el servidor de certificación (10);visualizar en dicho terminal portátil (30) como un código de barras o un código bidimensional el código de consulta recibido por dicho terminal portátil (30);leer el código de barras o el código bidimensional recibido por dicho terminal portátil (30) con un lector (21) conectado a un servidor de gestión de ventas (23) y transferir el código de consulta desde el lector (21) al servidor de gestión de ventas (23);devolver el código de consulta desde dicho servidor de gestión de ventas (23) al servidor de certificación (10);verificar en el servidor de certificación (10) el código de consulta generado con el código de consulta transmitido a través del servidor de gestión de ventas (23);y transmitir mediante el servidor de certificación (10) al servidor de gestión de ventas (23) información personal correspondiente al código de consulta cuando los dos códigos son idénticos entre sí.
- 2El procedimiento de certificación de personas según la reivindicación 1, en el que el lector (21) está conectado al servidor de gestión de ventas (23) a través de una red (50), y en el que el código de consulta se transfiere desde el lector (21) al servidor de gestión de ventas (23) a través de la red (50).
- 3El procedimiento de certificación de personas según la reivindicación 1 o la reivindicación 2, en el que el servidor de gestión de ventas (23) está conectado al servidor de certificación (10) a través de una línea privada (60), y en el que el código de consulta se transmite desde el servidor de gestión de ventas (23) al servidor de certificación (10) a través de la línea privada (60).
- 4El procedimiento de certificación de personas según cualquier reivindicación precedente, en el que dicho código de consulta comprende un signo que no tiene nada que ver con la información personal.
- 5El procedimiento de certificación de personas según cualquier reivindicación precedente, en el que el servidor de certificación (10) genera el código de consulta de manera que sea diferente de cualquier código de consulta generado en el pasado verificando el código de consulta generado con los datos del histórico de códigos de consulta almacenados definiendo códigos de consulta generados por el servidor de certificación en el pasado para eliminar la duplicación de códigos de consulta y generar un código de consulta que no se haya usado en el pasado.
- 6El procedimiento de certificación de personas según cualquier reivindicación precedente, que comprende además la etapa de:borrar el código de consulta generado dentro de un periodo de tiempo especificado previamente después de la generación del código de consulta en el servidor de certificación (10) para deshabilitar la verificación descrita anteriormente.
Independent claims6
64 paragraphs in 3 sections, as filed
ES 2 302 722 T3
DESCRIPTION
Authentication procedure.
Field of the invention
This invention relates to a person certification procedure using a portable terminal. Previous technology
Conventionally, the most representative technological trend in the people certification system is a procedure that uses a plastic card with a magnetic strip attached to it as represented by a credit card and, in this procedure, the data of a person stored in the magnetic tape is read with a card reader and the person is certified by comparing the data read with that stored in a company that manages credit information. However, nowadays many criminal acts such as credit card counterfeiting are frequently committed, so recently IC cards have been developed which can hardly be counterfeited.
In an online certification case, as security is further strengthened by combining encryption technology or a person certification number with it, the card number can be said to be read illegally from outside.
Furthermore, as a procedure for certifying a person using a cellular telephone terminal, a procedure is known in which the data for the certification of the person is previously sent through a cellular telephone terminal from the credit company and the person is certifies for payment by matching the person's certification data with the person's certification number.
However, in any use of the IC card, online certification and issuance of people's certification data through a cellular telephone terminal, there are problems of "use of fixed information" and the "existence of a card recorder" and therefore the risk of personal data being read illegally has not been completely eliminated. Also, there is still no complete solution for online payment and e-business authorization that will develop more and more in the future.
Document WO-A-95/19593 discloses a method for preventing unauthorized access to a central computer system by a user at a remote terminal using paging system technology. In the procedure, a user enters his user identification code entry into the terminal which transmits it to the central computer system. The system then generates a random code (Code A) and subjects Code A to a transformation characteristic of a transformation algorithm identified by the input user identification code to generate a transformed code (Code B). Code A is transmitted through a paging system to a user-held receiver. The receiver comprises transformation means adapted to transform the received Code A into a second transformed code (Code C), and means to display Code C to the user. The user then enters the Code C displayed on the terminal which transmits it to the central system. The input C code is then compared to Code B and access is only allowed if Code C matches Code B.
Document JP08130536 describes a mutual authentication procedure between terminals and a tone card system to obtain a communication circuit required for mutual certification by executing an operation three times in a system having, for example, a tone card and a central terminal connected to each other through a communication line. A tone card 1 sends a first random number code and key information to a central terminal (first processing). The terminal generates a first authentication code by encrypting the first random number code acquired by the key information and sends the first authentication code to the card along with a second random number (second processing). The tone card evaluates the correlation of the authentication code obtained by encrypting the first random number code using the key information with a first authentication code, generates a second authentication code based on the second random number code and key information at the time of matching and generates a fake authentication code consisting of a third random number code at the time of de-correlation and sends any from them to the central terminal (third processing). The central terminal verifies the tone card based on the authentication codes.
Document EP-A-1104973 (filed on December 3, 1999 without any priority claim and published on June 6, 2001) discloses procedures and systems to allow users of a cellular telecommunication system to obtain services, goods or other profits from one third. The procedures and systems allow the user to request a voucher from a voucher issuance system, receive the voucher on their mobile means of communication and obtain a service, goods or other type of benefit by communicating the voucher to a verification system, the which verifies the voucher and allows the user to obtain the desired service.
Description of the invention
According to the present invention, there is provided a method of certification of persons according to the attached independent claim 1.
Optional features are set out in the dependent claims.
Brief description of the drawings fig. 1 is an explanatory view showing a person certification system as a whole according to one embodiment;
fig. 2 is an explanatory view showing a basic principle of an embodiment;
fig. 3 is a block diagram showing a data file for the certification of persons stored in a certification server 10;
fig. 4 is a flow chart showing a sequence of operations from the generation of a "query code" in the certification server 10 to its deletion;
fig. 5 is a block diagram showing the configuration of the certification server 10; and fig. 6 is an example of displaying look-up code data on a monitor of a portable terminal.
Realizations
Fig. 1 is an explanatory view showing a person certification server as a whole according to one embodiment and a delimited field 20
ES 2 302 722 T3 by the dashed line in the figure shows the state in which a reader 21 provided on one side to provide various types of items or services, or a reader incorporated in a machine such as an automatic vending machine 22 ( not shown) and a sales management server 23 to control that the readers are connected through a network such as the Internet.
In conventional technology, payment of a fee with a common type of credit card or the like is made within field 20, and the credit card is read by the reader 21 or the like to certify the person.
In figure 1, a server 31 for portable terminals that manages a group of portable terminals 30, 30, ... is connected to the network 50, and the group of portable terminals 30, 30 ... and the server 31 for terminals Laptops are connected to each other through a radio link. Code 10 indicates a certification server to certify a person from each portable terminal 30 in the group of portable terminals 30, 30 ..., and this certification server is connected to the network 50 and also to the sales administration server 23 through a private line 60.
In the method according to the present embodiment, when an owner of the portable terminal 30 pays a service fee, when the owner expects to identify or identify him, the owner uses the portable terminal 30 instead of a credit card, a debit card, a cash card or any type of certificate, and the basic principles are described later with reference to figure 2.
First, when certification is requested from the portable terminal 30 to the certification server 10 (via path 201) the certification server 10 transmits the inquiry code to the portable terminal 30 (via path 202). The portable terminal 30 sends the inquiry code to the sales management server 23, for example, via the reader 21 (via path 203). This reader 21 is of the contactless type. This sales management server 23 transmits the query code to the certification server 10 to request the certification of the query code (via path 204). The certification server 10 verifies the query code with the previously generated one and returns a verification result and the personal data required by the sales management server 23 to the sales management server 23 (via path 205).
The consultation code for the certification described above is generated again when requested by the portable terminal 30, and the code is a temporary and meaningless sign that is never used for any other portable terminal 30 or even when requested again by itself. portable terminal 30.
It should be noted that the certification server 10 and the sales management server 23 may be physically identical servers.
Referring back to Fig. 1, a flow of the look-up code is described. When a user tries to make a payment using the reader 21 connected to the network 50, an automatic vending machine 22, or the like, is required in the first certification of the user.
The user waiting to make a payment requests the transmission of the user's query code to the certification server 10 from the portable terminal 30 that the user currently carries. This request signal is carried by an electrical wave provided by a cellular telephone company and reaches the certification server 10 through a server 31 for a portable terminal which is a signal conversion server for connection to the network 50.
The certification server generates a query code for the requesting user, and transmits the query code through the same signal path used for transmission, but in the opposite direction. After the handheld terminal 30 has received the inquiry code, it causes the reader 21, or other related device, to read the inquiry code in the contactless mode and thus the inquiry code is transmitted through the network 50 to sales management server 23.
The sales management server 23 transmits the inquiry code to the certification server 10 so that the inquiry code is verified. At this stage, the look-up code can be transmitted over the network 50, but full security is required between the communicating servers, and a signal path such as a private line 60 that can never be accessed from the outside is preferred.
The certification server 10 verifies the query code of the query token with the previously generated query code and returns the verification result and the requested subject to the sales management server 23. Once the affirmative result has been returned After verification, the user is certified and the subsequent procedure goes to the normal procedure performed by a credit or similar company on a routine basis.
The "query code" is described below with reference to FIG. 3 showing the configuration of a data file for the certification of persons stored in the certification server 10. In FIG. 3, a data file 310 for the Person certification consisting of a group of data records for person certification is recorded on a data storage medium 300 provided in the certification server 10. Each data record 320 for person certification comprises a member ID 311, which is an identification number for each person and other elements 312, and a "look-up code" 321 is present as one of the elements 312.
Specifically, the "query code" 321 is a piece of data that exists as a field of the data record 320 for the identification of persons in the data file 310 for the certification of persons which is a group of data records, each one for the certification of persons to be stored in the data storage medium 300 of the certification server 10.
It should be noted that this data is a temporary data that is first generated when a request signal is received from the portable terminal 30 and exists for a previously specified period of time and is cleared when a query signal is not received from the management server. sales 23 within a specified period of time. The data is not a fixed data and varies each time it is generated in the field. It is preferable that the data is different from meaningful and specific data such as a data record for the certification of persons, and also that the data is not a data converted or encrypted from fixed data. As understood from the
ES 2 302 722 T3 previous description of the transmission means, no manual work is required, so that a number of digits, figures or characters used for the data can be high, for example 50 digits that include numeric or alphabetic letters medium-sized and some medium-sized signs. Therefore, extremely long number of digits such as 1000 digits can be used for the data.
The processing steps from the generation of a "look-up code" to its deletion in the certification server 10 are described below with reference to FIG. 4.
First, when the certification server 10 receives a request for an inquiry code from the portable terminal 30 belonging to a registered member (step 401), certification is performed to check whether the user is a registered member or not.
When the user is certified as a registered member, the certification server 10 generates a "query code" (step 402), this query code is immediately verified with the data from the query code generation history (step 403) to check whether the query code is a code generated in the past or not (step 404), and if it is determined that the data is a duplicate data, the query code is generated again (step 405). A new query code is generated to avoid risks that could occur if someone else knew about the query code generated in the past and used it illegally.
The generated query code described above is issued (step 406) and transmitted to the portable terminal 30 (step 407). Then, the query code is controlled by a timer or the like, and it is checked whether or not a verification request has been issued from the sales management server 23 (step 408). When it is determined with a time or the like that a verification request has not been received within a previously specified time period, the query code is cleared (step 412). On the other hand, when it is determined that a verification request has been received in the sales management server 23 within the previously specified time period, the inquiry code is verified (step 410) with the requested person data transmitted (step 411) and at the same time the previously generated "lookup data" is erased (step 412).
Figure 5 is a block diagram showing the configuration of the certification server 10. The server 10 comprises, as components to be provided in a server for the processing, input, output, transmission and reception of various types of data, a control section 520 for controlling operations of the certification server 10 in its entirety, a section processing 530 to perform data processing, an input / output interface 510 connected to various types of input / output devices and to network 50 or the like, an input section 550 for receiving data from the input / output interface 510, an output section 560 for outputting data, a storage section 540 for temporarily storing data therein during data processing, a receiving section 570 for receiving various types of data and a transmission section 580 for transmitting various types of data.
In addition to the components that should generally be provided, the certification server 10 further comprises an ID determining section 502 for determining an ID from a request token or an inquiry signal, an ID storage section 503 for storing the registered IDs therein, a logged data retrieval section 504 for retrieving the member information from the member ID, a member information storage section 505 for storing member information such as query code data, a query code generation section 506 for generating new query code data, a query code history verification section 507 to check the new query code data with those generated in the past to eliminate duplication, a query code history storage section 508 for storing query code data generated in the past, a display data generation section 509 for converting the query code data into those that have a format for display on a portable terminal, a certification data generation section 511 for extracting and generating requested personal data with an inquiry signal, a look-up code timer management section 512 for managing the new look-up code data as a member information part for a certain period of time, a transmitter signal generation section 513 of personal data generated by the certification data generation section 511 for those having a signal format acceptable to the sales management server 23 and a query code verification section 514 to verify the query code in a query signal of the sales management server 23 with that stored therein.
The actions of the certification server 10 are described below.
At the certification server 10, the inquiry code request signal from the portable terminal 30 is transmitted through the input / output interface 510 to a reception section 570. Following an instruction from the control section 520, the processing section 530 consults the ID determining section 502 to check whether the request signal is already registered or not previously, and the ID determining section 502 verifies the request signal. with the data stored in the ID storage section 503 and transmits the request signal to the storage section 540 only after the request signal is determined to be a registered signal.
After the processing section 530 has received an instruction from the control section 520, it consults the registration data retrieval section 504 to check which member ID 311 the request signal corresponds to, the data retrieval section from Register 504 further verifies the request signal with the data stored in the member information storage section 505, and reports the data to the processing section 530. After the processing section 530 has received the notification, it issues an instruction for the generation of the new query code data in the query code field for the data to the query code generation section 506, and transfers the new query code data generated to storage section 540.
ES 2 302 722 T3
Then, the processing section 530 consults the query code history verification section 507 to check whether or not the new query code data is the same as any of the query code data generated in the past. The 507 query code history verification section verifies the new query code data with the 508 query code history storage section and when the new query code data is reported as a duplicate data, the section check code history check 507 again issues an instruction for the generation of a new query code data to the query code field for the data and, therefore, the processing steps are repeated.
The replay ends and the processing proceeds to the next task only when the processing section 530 receives a notification that the new query code data is not a duplicate data. In this case, the query code data is stored in the member information storage section 505, and the processing section 503 instructs the display data generation section 509 to convert a data format of the new code data. query in the previously decided and transmit the converted data to the storage section 540. The new look-up code data with the previously specified data format is transferred by the processing section 530 after the instruction has been received from the control section 520 to the transmission section 570, and transmitted through the interface interface. input / output 510 to requesting handheld terminal 30. Then, the new query code data is managed by the query code timer management section 512 and when a query signal is not received within a previously specified time period from the sales management server 23, the New query code data is automatically cleared by query code timer management section 512.
As described above, a data format of the new query code data is converted in the display data generation section 509, so that the portable terminal 30 can receive the new query code data having various kinds of data formats. As shown in figure 6, the new query code data is displayed on a liquid crystal monitor
600 of the handheld terminal 30 as a barcode
601 or as a two-dimensional code 602. The bar code 601 and the two-dimensional code are optimal because the meaning cannot be understood visually, so that the security of the data is guaranteed for the certification of people even if the data is exposed to anyone.
When the portable terminal 30 has a terminal for connection to external devices or a port for infrared data communication, the portable terminal 30 can deliver the new received inquiry code data to the reader 21 or the like installed in various locations for sales activities. through these external connection terminals.
The new query code data is transmitted from the various types of readers 21 or the like to the sales management server 23.
The sales management server 23 transmits an inquiry signal to the certification server 10, and the inquiry signal is transmitted through the input / output interface 510 of the certification server 10 to the reception section 570. The processing section 530 consults the ID determination section 502, after an instruction from the control section 520, to check whether the inquiry signal is a signal previously registered or not for the sales management server 23 that has a relationship contractual, and the ID determination section 502 verifies the signal with the data stored in the ID storage section 503, and transfers the signal to storage section 540 only when the signal is determined to be a registered signal.
Then, the processing section 530 issues an inquiry instruction of the inquiry signal passed to the inquiry code verification section 514. The query code verification section 514 extracts a query code from the query token stored in the storage section 540, verifies the query code with the member information storage section 505 where the query code is stores in it, and returns member ID 311 to processing section 530 only when the query code is determined to match any of the data stored in storage section 505.
After the processing section 530 has received the member ID 311, it provides the certification data generation section 511 with an instruction for the extraction and generation of personal data corresponding to the requirements by means of the query signal transferred from member storage section 505. Personal data is transferred from processing section 530 after receipt of the instruction from control section 520 to storage section 540. A token format of the personal data stored in the storage section 540 becomes that previously specified and acceptable to the sales management server 23 such as a token format based on the public key cryptographic system or the cryptographic system. common key, following an instruction by the processing section 530 after receiving the instruction from the control section 520, via the transmitter signal generation section 513, and the converted signal is transferred via the transmission section 580 and received via the input / output interface 510 by the requesting sales management server 23.
As described above, in this embodiment, based on the assumption that illegal interceptions are made on a network such as the Internet, as a countermeasure to illegal interception of signals, only temporarily transmitted nonsense signals are used to avoid the use of signals. meaningful across the network, and meaningful signals are only used between systems that have a higher level of security.
It is necessary to abort the nonsense and non-fixed "query code" every time it is used once, and a large number of query codes are required for the actual use of the present embodiment.
However, when using the barcode described above, since generally the barcode is based on a combination of 13 numeric digits (in the case of the JAN code), only
ES 2 302 722 T3 there are 10<sup>13</sup> number combinations when JAN code related rules are ignored. Furthermore, in the case of a "two-dimensional code", a number of combinations is theoretically only several hundred times of an ordinary barcode.
With the described embodiment:
(a) It is possible to establish a safe and fast personal certification by making use of a portable terminal. Therefore, with this embodiment, it is possible not only to prevent theft and accidents by decoding fixed data stored in a credit card, a debit card or a purse card, all of which are easily falsifiable, or to encrypt data from the same, but to use the realization as a means of payment for cyber businesses that are currently expanding.
(b) Security can be improved.
(c) Person certification can be done easily and quickly, and since the data transfer between a portable terminal and a reader can be done in the contactless state, problems such as breakage of a portable terminal never occur.
(d) With the features set forth in claim 6, the reliability of the certification of persons can be further improved.
Contents3
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
23 members in 11 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 20000058390 | Japan | – | |
| 2000058390 | Japan | A | |
| 2000058390 | Japan | A | |
| 20000381019 | Japan | – | |
| 2000381019 | Japan | A | |
| 2000381019 | Japan | A | |
| 200005839001908119 | – | – | – |
| 2000381019 | – | – | – |
| JP20000058390 | – | – | – |
| JP20000381019 | – | – | – |
Members23
| Document | Office | Kind | |
|---|---|---|---|
| WO0165386A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3598401A | Australia | A | |
| JP2001318894A | Japan | A | |
| US2003023566A1 | United States of America | A1 | |
| EP1282044A1 | European Patent Office (EPO) | A1 | |
| JP3385270B2 | Japan | B2 | |
| KR20030031888A | Republic of Korea | A | |
| EP1282044A4 | European Patent Office (EPO) | A4 | |
| JP2003196568A | Japan | A | |
| CN1432158A | China | A | |
| HK1056936A1 | Hong Kong, China | A1 | |
| KR100610479B1 | Republic of Korea | B1 | |
| CN1285043C | China | C | |
| EP1282044B1 | European Patent Office (EPO) | B1 | |
| AT391959T | Austria | T | |
| ATE391959T1 | Austria | T1 | |
| DE60133542D1 | Germany | D1 | |
| ES2302722T3This record | Spain | T3 | |
| EP1980967A2 | European Patent Office (EPO) | A2 | |
| EP1980967A3 | European Patent Office (EPO) | A3 | |
| DE60133542T2 | Germany | T2 | |
| EP2110768A1 | European Patent Office (EPO) | A1 | |
| US8412634B2 | United States of America | B2 |
Numbers
- Publication
- 2302722
- Publication, DOCDB
- 2302722
- Publication, EPODOC
- ES2302722T
- Application
- 1908119
- Application, DOCDB
- 01908119
- Application, EPODOC
- ES20010908119T
Titles2
- Spanish
- PROCEDIMIENTO DE AUTENTICACION.
- English
- AUTHENTICATION PROCEDURE
Classification
- CPC, 12
- G06F21/33
- G06Q20/00
- G06Q20/341
- G06Q20/3674
- G06Q20/4014
- G07F7/1008
- H04L63/0823
- H04W12/06
- H04L67/04
- H04W12/65
- H04W12/77
- H04L67/00
- IPC, 12
- G06Q20 40
- G06F21 31
- G06F21 34
- G06Q20 00
- G06Q20 42
- G06Q40 00
- G06Q40 02
- G07F7 10
- H04L9 32
- H04L29 06
- H04L29 08
- H04W12 06