Telecommunication system for personal link to banking service includes transparent use of public terminal avoid any storage of personal data
Abstract
The present invention relates to a telecommunications system including: - a personal object OBJ, held by a user of the system, - a first means of communication M1, made available to the user, and able to communicate with the personal object OBJ and with a data transfer network NETW, and a second communication means M2 able to communicate with said network NETW, belonging to an interlocutor INT of the user. In the system according to the invention, the first means of communication M1 can be configured in a transparent operating mode during which it is unable to act on data passing through it. The invention makes it possible to guarantee to the user that confidential data that he could send will not be altered or stored for illicit use by the first means of communication M1.

Term
Term ended
Projected expiry passed 17 September 2021, 5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
14 claims: 4 independent, 10 dependent
- 1ίο REVENDICATIONS 1) Système de télécommunication incluant :- un premier moyen de communication apte à communiquer avec un réseau de transfert de données et destiné à être mis à disposition d’un utilisateur du système, et - un deuxième moyen de communication apte à communiquer avec ledit réseau, appartenant à un interlocuteur de l’utilisateur, système caractérisé en ce qu’il inclut en outre un objet dit personnel, destiné à être détenu par l’utilisateur du système, et en ce que le premier moyen de communication est apte à être configuré dans un mode de fonctionnement transparent au cours duquel ledit premier moyen est incapable d’agir sur des données transitant entre l’objet personnel et le deuxième moyen de communication.
- 22) Système de télécommunication selon la revendication 1, dans lequel la configuration en mode de fonctionnement transparent du premier moyen de communication est déclenchée par un signal de commande émis par l’objet personnel.
- 33) Système de télécommunication selon la revendication 1, dans lequel la configuration en mode de fonctionnement transparent du premier moyen de communication est déclenchée par un signal de commande émis par le deuxième moyen de communication.
- 44) Système de télécommunication selon l’une des revendications 1 à 3, dans lequel, l’objet personnel étant en outre apte à communiquer avec le deuxième moyen de communication, une communication directe est établie entre l’objet personnel et le deuxième moyen de communication lorsque le premier moyen de communication est configuré en mode transparent.
- 55) Système de télécommunication selon Tune des revendications 1 à 4, incluant des moyens de chiffrement des données transitant entre l’objet personnel et le deuxième moyen de communication, lesquels moyens de chiffrement sont destinés à être activés lorsque le premier moyen de communication est configuré en mode transparent.
- 66) Système de télécommunication selon Tune des revendications 1 à 5, dans lequel l’objet personnel est un radiotéléphone.
- 77) Appareil émetteur/récepteur de signaux radioélectriques apte à remplir les fonctions de l’objet personnel inclus dans un système de télécommunication conforme à Tune des revendications 1 à 5.
- 88) Procédé de transmission de données entre :- un premier moyen de communication apte à communiquer avec un réseau de transfert de données et destiné à être mis à disposition d’un utilisateur du procédé, et - un deuxième moyen de communication apte à communiquer avec ledit réseau, appartenant à un interlocuteur de l’utilisateur, procédé incluant une étape de configuration du premier moyen de communication dans un mode de fonctionnement transparent au cours duquel ledit premier moyen est incapable d’agir sur des données transitant entre un objet personnel détenu par l’utilisateur et le deuxième moyen de communication.
- 99) Procédé de transmission de données selon la revendication 8, dans lequel l’étape de configuration est déclenchée par un signal de commande émis par l’objet personnel.
- 1010) Procédé de transmission de données selon la revendication 8, dans lequel l’étape de configuration est déclenchée par un signal de commande émis par le deuxième moyen de communication.
- 1111) Procédé de transmission de données selon l’une des revendications 8 à 10, dans lequel une communication directe est établie entre l’objet personnel et le deuxième moyen de communication lorsque le premier moyen de communication est configuré en mode transparent.
- 1212) Procédé de transmission de données selon l’une des revendications 8 à 11, dans lequel les données transitant entre l’objet personnel et le deuxième moyen de communication sont chiffrées lorsque le premier moyen de communication est configuré en mode transparent.
- 1313) Procédé pour réaliser une transaction entre deux entités économiques, comportant une étape au cours de laquelle au moins une des entités est informée du fait que ladite transaction sera réalisée au moyen d’un système de télécommunication conforme à la revendication 1.
- 1414) Procédé pour réaliser une transaction entre deux entités économiques, comportant une étape au cours de laquelle au moins une des entités est informée du fait que ladite transaction sera réalisée au moyen d’un procédé de transmission de données conforme à la revendication 8.
Independent claims14
48 paragraphs, as filed
The present invention relates to a telecommunications system including:
a first means of communication capable of communicating with a data transfer network and intended to be made available to a user of the system, and
a second means of communication able to communicate with said network, belonging to an interlocutor of the user.
In this type of system, the first means of communication can be constituted by a terminal connected to an Internet-type network, made available to the user in an internet café, a hotel or an airport lounge.
The second means of communication could be a server connected to a database belonging to the interlocutor who will be, according to the user's choice, a bank or even an online trading company.
In such a system, the user does not have control over the confidentiality of his own data. If, during an exchange with the interlocutor, the latter asks the user for his identity or an access code or even a password, the information that will be provided in return by the user will pass through the first means of communication over which the user exercises only limited control most often to interface functions. In particular, the user cannot be sure that the first means of communication will not store in a hidden register the confidential information that will pass through it, with a view to future illicit use of said information by an unauthorized person. who will have access to the hidden registry.
Such a state of affairs creates a feeling of insecurity among users which is detrimental to the development of online commerce through means of communication of which they do not own, and which is detrimental not only to online merchants, but also to network operators and manufacturers of equipment intended for said networks.
The object of the present invention is to remedy to a large extent these drawbacks by proposing a telecommunications system ensuring the user greater control over the confidentiality of his own data.
Indeed, according to the invention, a system in accordance with the introductory paragraph further includes a personal object, intended to be held by the user, the first means of communication being able to be configured in a transparent operating mode during which said first means is unable to act on data passing between the personal object and the second means of communication.
The personal object can be a radiotelephone, a pocket organizer or any other device, preferably of the portable type, in which the user will have stored confidential data which are specific to him, such as identity numbers, personal data. access codes and other passwords, as well as banking or medical data.
The personal object will most often be provided with capacities that are less important than those offered to the user by the first means of communication in terms of speed and man / machine interface.
The personal object and the first means of communication will be able to communicate via a wire or radio link.
In the system according to the invention, the first means of communication no longer has the physical possibility of handling or storing the data which pass through it once it has been placed in transparent operating mode. Thus, if during an exchange between the interlocutor and the user, the latter is invited to produce confidential data, the first means of communication will be placed in transparent operating mode before the confidential data is actually sent by personal object.
Such a measure, when communicated to them, will have the effect of reassuring users as to the preservation of the confidentiality of their own data and will thus contribute to the development of online commerce.
The invention therefore also relates to a method for carrying out a transaction between two economic entities, comprising a step during which at least one of the entities is informed that said transaction will be carried out by means of a telecommunications system as described herein. -above.
The configuration of the first means of communication in transparent operating mode may, depending on the case, be triggered by a control signal sent by the personal object, for example after receipt of a request for confidential data, or by the second means of communication, for example simultaneously or immediately after sending such a request.
The personal object will be able to generate such a control signal automatically before sending confidential data or after having received the order from the user.
In an advantageous variant of the invention, the personal object will be able to communicate directly with the second means of communication, for example by means of radio waves if the personal object and the second means of communication both have available resources. radio transmission / reception, for example compatible with GSM or UMTS standards. In the telecommunications system according to this variant, direct communication is established between the personal object and the second communication means when the first communication means is configured in transparent mode.
Such direct communication makes it possible to guarantee, by keeping the first means of communication away, that the latter cannot endanger the confidentiality of the data exchanged between the personal object and the second means of communication.
In a particularly advantageous embodiment of the invention, a telecommunications system as described above includes means for encrypting data passing between the personal object and the second means of communication, which means of encryption are intended to be activated. when the first means of communication is configured in transparent mode.
The encryption means offer an additional guarantee to the user as to the confidential nature of the communication of his own data to the second means of communication.
The invention also relates to a radioelectric signal transmitter / receiver device capable of fulfilling the functions of the personal object included in a telecommunications system as described above.
More generally, the invention further relates to a method of transmitting data between:
a first means of communication capable of communicating with a data transfer network and intended to be made available to a user of the method, and
a second communication means capable of communicating with said network, belonging to an interlocutor of the user, method including a step of configuring the first communication means in a transparent operating mode during which said first means is unable to act on data passing between a personal object held by the user and the second means of communication.
In a variant of this method, direct communication is established between the personal object and the second means of communication when the first means of communication is configured in transparent mode.
In a particularly advantageous embodiment of such a method, the data passing between the personal object and the second means of communication are encrypted when the first means of communication is configured in transparent mode.
As explained above, such a method makes it possible to provide the user with better confidentiality of his own data and contributes to the development of electronic commerce.
The invention therefore also relates to a method for carrying out a transaction between two economic entities, comprising a step during which at least one of the entities is informed that said transaction will be carried out by means of a data transmission method such as described above.
The characteristics of the invention mentioned above, as well as others, will emerge more clearly on reading the following description of an exemplary embodiment, said description being given in relation to the accompanying drawings, among which:
Fig. 1 is a functional diagram describing a telecommunications system according to the invention, FIG. 2 is a functional diagram describing a variant of such a telecommunications system, FIG. 3 is a flowchart describing a method for transmitting data implemented. work in such systems, and Fig. 4 is a flowchart depicting a variation of such a method.
Fig.l shows schematically a telecommunications system including:
- a so-called personal object OBJ, intended to be held by a user of the system,
a first means of communication M1 able to communicate with the personal object OBJ, on the one hand, and with a data transfer network NETW, on the other hand, and intended to be made available to the user, and
a second communication means M2 able to communicate with said network NETW, belonging to an interlocutor INT of the user.
The personal object OBJ is, in this example, a pocket organizer, the first means of communication M1 being a multimedia terminal made available to the user in an internet cafe or in an airport lounge, the second means of communication M2 being a server belonging to the interlocutor INT.
In this system, the first means of communication M1 is able to be configured in a transparent operating mode during which said first means M1 is incapable of acting on data passing between the personal object OBJ and the second means of communication M2 . The configuration in transparent operating mode of the first communication means M1 can be triggered, depending on the case, either by means of a control signal SC (OBJ) transmitted by the personal object OBJ, or by means of a control signal. command SC (M2) sent by the second means of communication M2.
For example, if the interlocutor INT is a banking establishment and issues a request to the user in order to obtain confidential codes from the latter, such as an account number and a password allowing the user to consult the statement of said account, such a request will be signaled to the user who will be able to order the personal object to send the control signal SC (OBJ) to the first communication means M1 with a view to placing said first means M1 in transparent operating mode before d 'effectively send the confidential data to the INT interlocutor. Such sending can be done in encrypted form via encryption means not shown in the figure, which will for example comply with SSL (Secure Sockets Layer) specifications.
The sending of the control signal SC (OBJ) by the personal object can be done automatically by said object if it has been previously programmed to send such a signal as soon as a request for confidential data has been identified.
It is also conceivable that the second means of communication M2 is configured such that it transmits a control signal SC (M2) aiming to place the first means of communication M1 in transparent operating mode simultaneously or immediately after transmission of a request for confidential data by the second means of communication, which avoids any intervention by the personal object OBJ and / or by the user himself.
Such a control signal SC (OBJ) or SC (M2) can for example take the form of a particular escape sequence inserted into a data stream sent to the first communication means M1.
The transparent operating mode can be obtained in various ways: the first means of communication M1 could for example be configured so that, during this mode of operation, said first means M1 will be prohibited from performing functions above it. a predetermined level O SI, corresponding for example to error recovery activities. Any function of a higher OSI level, such as read operations, storage or alteration of data, will then be momentarily inhibited, thus guaranteeing the confidentiality of the data passing through the first communication means M1 thus configured. A fortiori, if these data are encrypted, the first means of communication M1 will be incapable of deciphering them, and even less of altering them in a manner that cannot be detected by the interlocutor INT.
Fig. 2 is a functional diagram which represents a variant of the previously described telecommunications system. The elements common to the two systems have been provided with the same reference signs and will not be described again. In this system, the personal object OBJ is a radiotelephone and the second means of communication M2 is provided with transmission / reception ANT resources which make it capable of communicating with the personal object OBJ, for example by means of a cellular network of the GSM or UMTS type. In this telecommunication system, direct communication is established between the personal object OBJ and the second telecommunication means M2 when the first communication means is configured in transparent mode. Such an embodiment of the configuration in transparent operating mode of the first communication means M1 makes it possible to guarantee, by keeping said means M1 away from the exchange of data between the personal object OBJ and the second communication means M2, that the first means of communication M1 cannot endanger the confidentiality of the data thus exchanged between the personal object OBJ and the second means of communication M2.
FIG. 3 is a flowchart which illustrates the flow of a data transmission method according to the invention. In accordance with this method, during a first step CONM1, the user connects to the first means of communication M1, possibly via his personal object OBJ. During a subsequent NAV step, the user launches a browser serving as an interface with the data transfer network. During a next URL step, he composes an address in order to establish a connection with the interlocutor he has chosen. During a following step CNM2.INFO, the connection is established and the interlocutor INT informs the user that the data exchange will be carried out by means of a telecommunications system or a method in accordance with the invention. , in order to convince the user that the transmission of any sensitive data that he may be required to provide to his interlocutor will benefit from optimal confidentiality conditions. During a following step REQM2, the interlocutor INT requests from the user data which are specific to him. For example, if the interlocutor is an online merchant, he may be required, during a transaction, to ask the user for a bank card number in order to withdraw the amount of the transaction from an associated bank account. Such a request may be accompanied by a control signal SC (M2) sent, simultaneously or immediately after said request, by the second communication means M2 to the first communication means M1, under the conditions described above, intended to configure the first. Ml communication means in transparent operating mode. Failing this, the personal object OBJ can, upon receipt of this request, automatically or on the order of the user, send a control signal SC (OBJ) intended for the same purposes. The possible alternating character of these events is indicated by the transition SC (M2) + SC (OBJ), in which the “+” sign must be taken in its Boolean “OR” meaning. During a following step DISM1, the first means of communication M1 is configured in transparent mode and incapable of acting on the data passing through it during this operating mode, thus guaranteeing the confidentiality of the exchange then taking place between the second means of communication M2 and the personal object OBJ. During a following step GRNTOBJ, the personal object OBJ accesses the request of the interlocutor INT and transmits the confidential data required by the latter. In a following step RECM2, the second communication means receives said data and lifts the inhibition imposed on the first communication means. In a next step ENM1, said first communication means M1 abandons the transparent operating mode and resumes a normal and non-secure operating regime, until a new exchange of sensitive data becomes necessary, for example in as part of a new transaction between the user and the same interlocutor INT, possibility materialized by the NEWTR transition, or another transaction with a new interlocutor, possibility materialized by the NEWINT transition.
It is well understood that, the user having been informed during step CONM2 + INFO of the securing, made possible thanks to the invention, of the exchange of data to take place during the transaction that he intends to conclude, said user will be more inclined to actually proceed with this transaction. It is entirely conceivable to entrust the first means of communication M1 with the task of informing the user even more upstream of this advantage in order to establish a climate of confidence as soon as possible, for example from step CONM1. at the end of which the user is connected to the first means of communication Ml.
FIG. 4 illustrates a variant of the method described above, intended for implementation in a telecommunications system in which the second communication means M2 is integral with the first communication means M1. In such a case, the second means of communication M2 could be for example the server of a central database specific to a chain of cybercafés or airport lounges, to use the previous examples, to which the chain belongs. first means of communication Ml. The user may indeed want to create and save a profile, that is to say a set of network addresses and / or passwords and access codes relating thereto, and wish that his real identity cannot be not be associated with this profile by the local terminal through which it communicates with this central database, in order to locally preserve cybernetic anonymity. A telecommunication method according to this variant of the invention will then advantageously comprise a first step CONM1.INFO, during which the user connects to the first means of communication M1, optionally via his personal object OBJ. During this same step, the user is informed of the fact that, thanks to the use of a telecommunications system or of a method in accordance with the invention, he has the possibility of creating a personal profile or of extracting a personal profile from his personal object and having it recorded in the central database without any trace of his real identity being able to remain locally in association with said profile. During a next step PROT (M1), an information exchange protocol between the personal object OBJ and the first means of communication M1 is implemented in order to allow said object to send a control signal SC (OBJ) to said first means in order to configure the latter in transparent operating mode after the user has produced his profile. During a next step DISM1, the first means of communication M1 is configured in transparent mode and incapable of acting on the data passing through it during this operating mode, thus guaranteeing the confidentiality of any exchange then taking place between the personal object OBJ and the second means of communication M2. During a following step S (PROF.ID.ALIAS) M2, the personal object OBJ transmits the profile produced by the user, accompanied by his real identity and an alias chosen by the user, by the second means communication M2. In a next step
R (PROF.ID.ALIAS) M2, the second means of communication acknowledges receipt of said profile to the personal object OBJ, which triggers a lifting of the inhibition imposed on the first means of communication M1. In a following step ENM1, said first communication means M1 abandons the transparent operating mode and resumes a normal and non-secure operating regime. In a next step ALIAS, the user gives his alias to the first means of communication M1, with the aim of having his profile installed on said first means of communication M1. In a next step INSTPROF, the second means of communication M2 supplies to the first means of communication M1, at the latter's request, the profile previously defined by the user, which profile is then effectively installed on the first means of communication M1 . During a following NAV step, the user can launch a browser serving as an interface with the data transfer network. This step can be followed by the steps which follow the homonymous step in the previous figure.
It is clear from the preceding description that the invention, by improving the security conditions for electronic data exchanges, will have the consequence of reassuring those involved in such exchanges, provided that they are informed of the advantages of the invention. The invention will thus contribute to the development of electronic commerce and to respect for the privacy of users of data transfer networks.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both waysCites: the store holds 4 of 5
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2005083544A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| FR2865594A1 | Cited by | France | – | Search report | – |
| WO0165340A2 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-14 |
| WO0165340A2 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-14 |
| EP1026641A1 | Cites | European Patent Office (EPO) | A | Search report | 1-14 |
| EP1026641A1 | Cites | European Patent Office (EPO) | A | Search report | 1-14 |
| STEPHEN ELMY: "Found on Internet at <<http://www.travelpress.com/users/webworld/c159.html>> on 16 July 2002", CANADIAN TRAVEL PRESS, April 1999 (1999-04-01), XP002206220 | Non-patent | – | – | Search report | – |
10 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0112022 | France | A | |
| 0112022 | France | A | |
| FR20010012022 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| FR2829894A1This record | France | A1 | |
| WO03026256A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03026256A3 | World Intellectual Property Organization (WIPO) | A3 | |
| FR2829894B1 | France | B1 | |
| EP1428372A2 | European Patent Office (EPO) | A2 | |
| US2005020251A1 | United States of America | A1 | |
| EP1428372B1 | European Patent Office (EPO) | B1 | |
| DE60237290D1 | Germany | D1 | |
| ES2349626T3 | Spain | T3 | |
| US7933582B2 | United States of America | B2 |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Transmission of propertyTP | TP | |
| Transmission of propertyTP | TP |
Numbers
- Publication
- 2829894
- Publication, DOCDB
- 2829894
- Publication, EPODOC
- FR2829894
- Application
- 112022
- Application, DOCDB
- 0112022
- Application, EPODOC
- FR20010012022
Titles2
- French
- SYSTEME DE TELECOMMUNICATION A CONFIDENTIALITE AMELIOREE
- English
- ENHANCED CONFIDENTIALITY TELECOMMUNICATION SYSTEM
Classification
- CPC, 5
- H04L67/34
- G06Q20/108
- H04L63/10
- H04L69/329
- H04L9/40
- IPC, 3
- G06Q20 10
- H04L29 06
- H04L29 08