Electronic monetary system
Abstract
An improved monetary system using electronic media to exchange economic value securely and reliably. The invention provides a complete monetary system having electronic money that is interchangeable with conventional paper money comprising (1) issuing banks or financial institutions that are coupled to a money generator device for generating and issuing to subscribing customers electronic currency backed by demand deposits electronic credit authorizations; (2) correspondent banks that accept and distribute the electronic money; (3) a plurality of transaction devices that are used by subscribers for storing electronic money, for performing money transactions with the on-line systems of the participating banks or for exchanging electronic money with other like transaction devices; (4) automated teller devices, associated with the issuing and correspondent banks, for process handling and interfacing the transaction devices to the issuing and correspondent banks, and for interfacing between the issuing and correspondent banks themselves; and (5) a clearing bank for balancing the electronic money accounts of the different issuing banks (6).
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 5 independent, 5 dependent
- 1CLAIMS 1 16371/2 1 . A method for updating security information stored in amoney module by interacting with a network having a securityserver, comprising the steps Of:sending a time limited certificate of said money moduleto said security server;said security server verifying the validity of saidcertificate and sending updated security information to said moneymodule;and said security server updating a time limit associatedwith said money module's certificate, wherein an expired time limitinhibits said money module's ability to interact "with other money modules .
- 22- The method of claim J, wherein said security informationcomprises an.UDdated list of bad money module identifiers.
- 4The method of claim .3 wherein said certificate furtherincludes said time limit comprising a date and time.
- 66- A system for updating security information stored in amoney module by interacting with a network having a security-server, comprising:a money module having a memory that stores electronicnotes that include a time limit, a clock that maintains a systemtime, and a processor;_ 102 116371/2 wherein when said money module interacts with saidnetwork, said security server updates security information storedin said money module;and wherein an expired time limit on said electronic notesinhibits said money module's ability to transfer said electronicnotes to other money modules.
- 7The system of claim . 6 wherein said electronic notes areupdated when transacting with an electronic monetary system.
Independent claims5
531 paragraphs in 8 sections, as filed
Citibank, N.A C. 100209
Electronic monetary system Ή
The present patent application is a division of Israel No.103397.
Passages of the description which are not within the scope of theclaims do not' constitute part of the invention.
Background of the Invention
The present invention relates to an electronic monetary! system for implementing electronic money payments as an alternative medium of economic exchange to cash, checks, creditand debit cards, and electronics funds transfer. The Electronic-Monetary System is a hybrid of currency, check, card paymentsystems, and electronic funds transfer systems, possessing manyof the benefits of these systems with few of their limitations.
The system utilizes electronic representations of money which aredesigned to be universally accepted and exchanged as economicvalue by subscribers of the monetary system.
Today, approximately 350 billion coin and currencytransactions occur between individuals and institutions everyyear. The extensive use of coin and currency transactions haslimited the automation of individual transactions such aspurchases, fares, and bank account deposits and withdrawals.Individual cash transactions are burdened by the need of havingthe correct amount or providing change therefor. Furthermore,the handling and managing of paper cash and coins isinconvenient, costly and time consuming for both individuals andfinancial institutions alike.
Although checks may be written for any specific amountup to the amount available in the account, checks have verylimited transferability and must be supplied from a physicalinventory. Paper-based checking systems do not offer sufficientrelief from the limitations of cash transactions, sharing many ofthe inconveniences of handling currency while adding the inherentdelays associated with processing checks. To this end, economicexchange has striven for greater convenience at a lower cost,while also seeking improved security.
Automation has achieved some of these qualities forlarge transactions through computerized electronic funds transfer(«EFT") systems. Electronic funds transfer is essentially a process of value exchange achieved through the banking system'scentralized computer transactions. EFT services are a transferof payments utilizing electronic "checks," which are usedprimarily by large commercial organizations.
The Automated Clearing House (ACH) and point of sale(POS) systems are examples of electronic funds transfer systemsthat have become used by retail and commercial organizations on asubstantial basis in recent years. However, the payments madethrough these types of EFT systems are limited in that they \cannot be performed without the banking system. Moreover, ACHtransactions usually cannot be performed during off businesshours. i !
I i
Home Banking bill payment services are examples of anelectronic funds transfer system used by individuals to makepayments. Currently, home banking initiatives have found fewcustomers. Of the banks that have offered services for payments,account transfers and information over the telephone lines usingpersonal computers, less than one percent of the bank's customersare using the service. One reason that Home Banking has not beena successful product is because the customer cannot deposit andwithdraw money as needed in this type of system.
Current EFT systems, credit cards, or debit cards,which are used with an on-line system to transfer money betweenaccounts, such as between the account of a merchant and that of acustomer, cannot satisfy the need for an automated transactionsystem that provides for the transfer of universally acceptedeconomic value outside of the banking system.
To implement an automated, yet more convenienttransaction system that does not reguire the banking system tointermediate the transfer, and that can dispense some form ofeconomic value, there has been a trend towards off-lineelectronic funds transfer. For example, numerous ideas have been 2 proposed for some form of "electronic money" that can be used incashless payment transactions as alternatives to the traditionalcurrency and check types of payment systems. See U.S. Patent No.4,977,595, entitled "METHOD AND APPARATUS FOR IMPLEMENTINGELECTRONIC CASH, and U.S. Patent No. 4,305,059, entitled "MODULARFUNDS TRANSFER SYSTEM."
The more well known techniques include magnetic stripecards purchased for a given amount and from which a prepaid valuecan be deducted for specific purposes. Upon exhaustion of theeconomic value, the cards are thrown away. Other examplesinclude memory cards or so called smart cards which are capableof repetitively storing information representing value that islikewise deducted for specific purposes.
However, these proposed systems suffer from a failureto recognize fully the significance of bank deposits as money,and their necessity to back any form of universally acceptedmonetary representations that may be issued. In the systemsdisclosed thus far, representations of economic value, whetherelectronic or paper, are issued without the backing of equalvalued liabilities as the counterpart to their assets.
None of the paperless payment systems that have beenproposed so far are comprehensive enough so as to implement amultipurpose electronic monetary system that includes not onlythe automated devices that allow subscribers to transferelectronic funds or money between them without any intermediatingsystem, but that also encompasses and includes an entire bankingsystem for generating the value represented by the electronicmoney and for clearing and settling the electronic money accountsof the banks and financial institutions involved to maintain amonetary balance within the system.
Thus, there is a need for a system that allows commonpayor to payee economic exchanges without the intermediation of - 3 - the banking system, and that gives control of the payment processto the individual. Furthermore, a need exists for providing asystem of economic exchange that can be used by largeorganizations for commercial payments of any size, that does nothave the limitations of the current EFT systems.
Accordingly, it is an object of the present inventionto provide a complete electronic monetary system which utilizeselectronic money that is interchangeable with traditional cashand is universally accepted.
It is another object of the present invention toprovide a method of securely transferring economic valueincluding currency and credit among subscribers, among financial j institutions, and between subscribers and financial institutions. A further object of the present invention is to provide j a multipurpose paperless payment system whereby transactions can 1 : be carried out in both an on-line and an off-line mode between i j ' subscribers. | It is yet another object of the present invention to • provide a payment system that reduces the cost of central
I ' electronic funds transfer systems by off loading much of the i ! payments to off-line devices. t
It is still another object of the present invention toprovide a system of inexpensive electronic transfers to reduce aninstitution's cost of managing paper cash, checks and coins.
It is still a further object of the present inventionto provide a user friendly electronic payment system that may beused reliably and securely for real time transfers of moneybetween members of the general public, between members of thegeneral public and commercial organizations, and betweencommercial organizations.
It is still another object of the present invention toprovide a system for depositing and withdrawing economic value - 4 - which may be integrated with a wide variety of data processingand data communication systems including currently available homebanking services.
It is still a further object of the present inventionto provide an electronic monetary system which utilizeselectronic money in the form of multiple currencies.
It is yet a further object of the present invention toprovide a system for safely transferring economic value intransactions of virtually any size denomination.
It is yet another object of the present invention toprovide a medium of economic exchange that is fungible, easilytransferable, undeniably redeemable, and secure from reuse,duplication, and counterfeiting.
The foregoing objects and advantages of the inventionare illustrative of those which can be achieved by the presentinvention and are not intended to be exhaustive or limiting ofthe possible advantages which can be realized. Thus, these andother objects and advantages of the invention will be apparentfrom the description herein or can be learned from practicing theinvention, both as embodied herein or as modified in view of anyvariations which may be apparent to those skilled in the art.Accordingly, the present invention resides in the novel methods,arrangements, combinations and improvements herein shown anddescribed.
Summary_of Exemplary Embodiment
To achieve the foregoing, and other objects, the methodand apparatus of the present invention employ a preferredembodiment in the form of an electronic-monetary system having (1) banks or financial institutions that are coupled to a moneygenerator device for generating and issuing to subscribingcustomers electronic money including electronic currency backed 5 by demand deposits and electronic credit authorizations; (2)correspondent banks that accept and distribute the electronicmoney; (3) a plurality of transaction devices that are used bysubscribers for storing electronic money, for performing moneytransactions with the on-line systems of the participating banksor for exchanging electronic money with other like transactiondevices in off-line transactions; (4) teller devices, associatedwith the issuing and correspondent banks, for process handlingand interfacing the transaction devices to the issuing andcorrespondent banks, and for interfacing between the issuing andcorrespondent banks themselves; (5) a clearing bank for balancingthe electronic money accounts of the different issuing banks; (6)a data communications network for providing communicationsservices to all components of the system; and (7) a securityarrangement for maintaining the integrity of the system, and fordetecting counterfeiting and tampering within the system.
In the preferred embodiment, the functions of the moneygenerating devices, the transaction devices, and the tellerdevices will be performed by a combination of tamper-proofcomputer hardware and application software modules that may benetworked together. Information is transmitted in an encryptedform to provide security from unauthorized inspection. Theelectronic money is transmitted with digital signatures toprovide authentication, and security from modification orcounterfe iting.
The electronic money exchanged by these devices may bean electronic representation of currency or credit. An importantaspect of the electronic currency is that it is the equivalent ofbank notes and is interchangeable with conventional paper moneythrough claims on deposits in an issuing bank, but can bewithdrawn or deposited both at an issuing bank and at a correspondent bank. However, only the issuing banks can generate 6 the electronic currency, and will be liable for its redemption.
The issuing banks later utilize inter-bank clearing andsettling processes to maintain the monetary balance in thebanking system, as is currently practiced by today's bankingindustry.
The electronic money representations are fungible,universally accepted, and undeniably redeemable from the issuingbanks, i.e., they have the characteristics of money transactions.To preserve the integrity of the electronic monetary system, eachexchange of electronic money includes, along with otherinformation, data identifying the monetary unit of the credit orcurrency, (i.e., dollars, yen, etc.) the amount by unit of credit j or currency, the bank issuing the electronic credit or currency,
I and several digital signatures. i i ί Summary of The Invention i J In accordance with these and other objects of the I invention, a brief summary Of the present invention is presented. ! Some simplifications and omissions may be made in the following summary, which is intended to highlight and introduce someaspects of the present invention, but not to limit its scope.Detailed descriptions of a preferred exemplary embodimentadequate to allow those of ordinary skill in the art to make anduse the inventive concepts will follow in later sections.
According to a broad aspect of the invention, anelectronic monetary system provides for transactions utilizingelectronic money including electronic currency backed by demanddeposits in a bank in lieu of cash transactions, and electroniccredit authorizations^ The invention comprises a money modulefor generating the electronic money; a money module for issuing,distributing, and accepting the electronic money; and a moneymodule for accepting, storing, and transferring the electronic 7 money between other accepting money modules and between theaccepting money module and the issuing money module.
According to a further aspect of the invention, anelectronic monetary system is provided for implementing andmaintaining electronic money which includes electronic currencythat is interchangeable with conventional money through claims ondeposits in a bank and electronic credit authorizations.
The system includes a plurality of issuing banks; agenerator module for creating electronic money; teller modulescoupled to the generator module, for performihg tellertransactions and for interfacing with other teller modules, suchtransactions including the accepting and the distributing of theelectronic money; a security system for providing the overallintegrity of the electronic monetary system; a clearing andsettling process for balancing the electronic money accounts ofthe separate issuing banks and for clearing the electronic moneyissued by the issuing banks; and a plurality of transactionmodules owned by authorized users, for transferring theelectronic money between the transaction modules and between thetransaction modules and the teller modules.
In accordance with another aspect of the indention, thefunctions of the generator modules, the transaction modules, andthe teller modules will be performed by a combination of tamper-proof computer hardware and application software that may benetworked together.
The electronic money exchanged by these modules, whichmay be an electronic representation of currency backed by demanddeposit accounts at the issuing bank or credit authorizations,may be transmitted with digital signatures to provide securityfrom unauthorized modification or counterfeiting. In a preferredembodiment, security from counterfeiting and tampering is alsoprovided by requiring the modules and the individual units of 8
I electronic money to be renewed periodically. Offending modulesor counterfeit electronic money can be removed from circulationas soon as they are discovered. J Briefly, a process in accordance with the invention
I comprises the steps of (1) providing a generating module to generateelectronic representations of economic value backed by demanddeposits or by a credit line; (2) providing a teller module to accept the generatedelectronic representations of economic value and to issue theelectronic representations of economic value; (3) providing the authorized users with a transactingmodule for accepting, storing and transferring the electronic ! ' representations of economic value to other authorized users | having the transacting module and to the teller processing
I . module; j (4) accepting and transferring the electronic ' representations of economic value to other authorized users i j • having a transacting module and to the teller module; and (5) providing a security system to allow the transfer| of electronic representations of economic value in a secure^manner between the generating module, the teller module and the! transacting module.
Brief Description of the Drawings
Other objects and advantages of the present inventionwill become more apparent by the following description withreference to accompanying drawings, in which:
Figure 1 is a diagram illustrating general aspects ofthe invention;
Figure 2 is a schematic diagram of the operativearrangement of the components, according to the invention. 9
Figure 3 is a perspective diagram of several embodiments of external systems that may house a money module, according to the invention.
Figure 4 is a block form diagram of a Transaction moneymodule, according to the invention.
Figure 5 is a block form diagram of a Teller moneymodule, according to the invention.
Figure 6 is a block form diagram of a Money Generatormodule, according to the invention.
Figure 7 ie a block diagram of the network arrangement,according to the invention.
Figure 8 is a block diagram of a Network Severyaccording to the invention.
Figure 9 is a flow diagram of the security system,according to the invention.
Figure 10 is a block form diagram of a security server,according to the invention.
Figures 11-24 are flow diagrams of accounting examples,.according to the invention.
Figure 25 a flow diagram of the TransactionReconciliation System, according to the invention.
Figure 26 is a flow diagram of the Clearing System,according;\.to the invention.
Figure 27 is a flow diagram of the Money IssuedReconciliation System, according to the invention.
Figures 28-50A are flow charts of transaction examples, ,, . ., . ., Figure 51 shows according to the invention. ’ an example of a note transfer tree.
Disclosure of the Preferred Embodiment of the Invention
The present invention contemplates an improved monetary system using electronic media to securely and reliably exchange economic value. The system can be implemented by integrating 10 novel data processing systems with other procedures which can beimplemented with the current worldwide banking systems.
Throughout this description, "electronic money" mayalso be referred to by the abbreviation "E-M." Additionally, theterm "bank" is used hereinafter .to indicate any banking, financial institution or the like which is a participant of thepresent invention.
Referring now to the drawings, wherein like numerals refer to like components, there is disclosed in Figure 1, in block form, broad aspects of the preferred embodiment. In Fig. 1, the general relationship among the features of the system is shown. The system includes Issuing Banks 1 each having a Teller money module 5 and a Money Generator module 6; Correspondent<·
Banks 2 each having a Teller money module 5; an electronic moneyClearing Bank 3; a Certification Agency 28 and a plurality ofTransaction money modules 4 owned by subscribers of the system.
Though money generator module 6 and teller module 5are preferably embodied separately, the functions of these modulesmay be embodied in a unitary device under processor control.
Electronic notes 11, the media for transferringelectronic money, are generated by the Money Generator module 6for an Issuing Bank 1. These notes 11 are then transferred by aTeller money module 5 to a subscriber utilizing a Transactionmoney module 4. Electronic notes 11 may be representations of 'lA> ’ currency or credit authorizations. For security reasons, allelectronic notes 11 will expire after a preset time period. Onceexpired, the notes 11 must be redeemed at a participating bankfor updated ones before they can be transferred.
An Issuing Bank 1 generates and distributes theelectronic notes 11, and is liable for their redemption. AnIssuing Bank 1 performs deposits, withdrawals, payments to loansand inquiries for other money modules. A Correspondent Bank 2 is a participating bank whichdistributes electronic money through accounts it maintains atIssuing Banks 1, but does not generate any electronic money, and 11 is not liable for its redemption. Because it cannot generate anyelectronic money, the Correspondent Bank 2 in the preferredembodiment must make real-time requests of electronic money froman account it maintains at an Issuing Bank 1 whenever asubscriber wishes to withdraw electronic money at a CorrespondentBank 2.
Conversely, a Correspondent Bank 2 deposits allelectronic money deposited by subscribers, to the accounts theCorrespondent Bank 2 holds at Issuing Banks 1. These accountswill be described hereinafter. A Correspondent Bank 2, like anIssuing Bank 1, will perform deposits withdrawals, payments toloans and bank inquiries.
Notably, an Issuing Bank 1 may also be a CorrespondentBank 2 for the monetary units that it does not generate. Forexample, an Issuing Bank 1 for electronic dollar notes 11 may bea Correspondent Bank 2 for electronic notes 11 of yen, marks,etc., issued by other banks.
It is also important to note that the system of the i invention can function without Correspondent Banks 2. Forexample, a subscriber can eliminate the use of a CorrespondentBank 2 by communicating directly with his/her Issuing Bank 1 whenmaking a deposit, withdrawal, etc. Correspondent Banks 2 areincluded in the preferred embodiment for the practical purpose ofexpanding distribution of the system while reducing the risksthat are inherent in any banking system, such as the risks causedby the collapse of a bank issuing money.
The Clearing Bank 3 is utilized when more than one bankis issuing electronic money. According to the invention, it isanticipated that more than one bank will be issuing electronicmoney. Thus, the Clearing Bank 3 is provided to clear theelectronic money deposited and to balance accounts it maintainsfor the Issuing Banks 1. The Clearing Bank 3 maintains demand - 12 - ! accounts for each Issuing Bank 1 in the system.
The Certification Agency 28, is the centerpiece of thesystem security. It provides a process that "certifies" thevalidity of a money module for a certain period of time byissuing a certificate to each money module. A money module musthave a valid certificate in order to be able to transact withother money modules 4, 5, 6.
Before the certificate expires, it must be updated sothat a subscriber can continue to use his/her transaction moneymodule 4. This process makes users of the system establishperiodic contact with the Certification Agency 28.
Periodic contact allows for faster response whentampering with the money modules of the system is detected. Totfiis end, the Certification Agency 28 also provides a list ofoffending or compromised money modules to other money modules sothat transactions with the bad units may be blocked.
The components shown in Figure 1 are best understood by
I referring to the system's operative arrangement illustrated inFigure 2. As illustrated in Figure 2, the preferred embodimentprovides for supplements to the current banking systems thatinclude the following additional components: a plurality of theTransaction money modules 4, the Teller money modules 5, and theMoney Generator modules 6, for creating, transferring and storingthe electronic notes 11 (money); a Clearing System 13 to balancethe accounts of banks issuing currency and credit; a securitysystem 21 to maintain the integrity of the aiectronic notes 11;the current banking systems 20; a network 25 (exemplified by thelines interconnecting modules and systems) to mediate transactions between money modules 4,5,6, the participating banks 1,2,3 of system 20 and the security system 21; a TransactionReconciliation system 22 to detect money module malfunctions andinsider tampering of the system; a Money Issued Reconciliation - 13
System 23 to detect counterfeiting and reuse of electronic money;and a Money Position System 24 to keep track of the electronicmoney in circulation.
Playing major roles in the preferred embodiment arethree classes of "money modules" for creating, storing, andtransferring the electronic objects that represent economicvalue. These include the Transaction money modules 4, the Tellermoney modules 5, and the Money Generator modules 6. It iscontemplated that these money modules 4,5,6 will be a combinationof tamper-proof hardware and application software that are meantto be components of a larger processing environment.
Referring to the top right-hand side of Figure 2, aTransaction money module 4 containing electronic notes 11 storedtherein (not shown) may be used to exchange foreign currency ormake a payment with another Transaction money module 4, using asecure, encrypted protocol either by a telephonic link, or aproximate communication link. Because it is contemplated that anelectronic note 11 will be fungible, i.e., it can be broken intoany desired amount, the amount transacted between the Transaction ι money modules 4 may be of any amount up to the amount stored inthe payor's Transaction money module 4. i A payee's Transaction money module 4 that has received the electronic notes 11 as a payment may, in turn, be used totransfer all or any amount of the electronic money containedtherein to another subscriber's Transaction money module 4.Alternatively, the payee may deposit the electronic money intohis/her bank account.
The value of the electronic money stored in theTransaction money module 4 may also be redeemed at anyparticipating bank (e.g., Correspondent Bank 2 or Issuing Bank 1)for paper money by transferring any amount of the electronicmoney to a bank's Teller money module 5, whereby a teller or an - 14
Automated Teller Machine (ATM) will return an equal amount ofpaper money. Naturally, it is anticipated that paper money mayalso be exchanged for equal valued electronic money.
As will be appreciated, the Transaction money module 4may be configured to make deposits, withdrawals, loan payments,inquiries and exchanges of currencies of electronic notes 11directly through a Teller money module 5 at an Issuing 1 orCorrespondent Bank 2 or remotely through a telephonic connectionto an Issuing 1 or Correspondent Bank 2 Teller money module 5(thereby providing, among other things, the transactions notavailable in current home banking systems). Upon a request totransact with a bank, the Teller money module 5 mediates thetransactions for the subscriber's bank account as well as the ' banking system's electronic money accounts. ! It should be noted that a subscriber will not be required to maintain a bank account in order to own and use aTransaction money module 4. For instance, a subscriber mayobtain a stand-alone computing device that contains a Transactionmoney module 4 and use the device only in off-line peer-to-peertransactions with other devices containing a Transaction money I , module 4, such as a merchant's point-of-sale terminal. Ofcourse, the merchant may then transfer the electronic money toanother commercial organization to meet its obligations, or itmay deposit the electronic money at its own bank.
In the preferred embodiment, electronic money depositedat any Issuing Bank 1 other than the original Issuing Bank 1itself will subsequently be settled for value with the original .Issuing Bank 1 through the central clearing and settling processperformed by the Clearing System 13. It is anticipated that theclearing and settling processes will be managed by the ClearingBank 3 (Figure 1). Each Issuing Bank 1 Teller money module 5sends all the electronic notes 11 deposited at its bank but 15 issued from other Issuing Banks 1 to the Clearing Bank 3 in orderto settle for the value posted to their customers' accounts.
When a withdrawal, an exchange for foreign currencies,an exchange of paper cash for electronic money, or an updating ofthe electronic money occurs, the Money Generator module 6, Figure2, creates and digitally signs electronic objects having economicvalue - either currency or credit notes 11 (Figure 1) - that areto be sent to the Transaction money modules 4 through theparticipating bank's Teller money modules 5 in the form of apacket of electronic notes 11. As mentioned above, the electronic currency notes 11 are the equivalent of bank notesthat are backed by deposits, and can be traded betweenTransaction money modules 4. ί During the withdrawal transaction, the Teller money i module 5 and the Transaction money module 4 may establish a • communications link using an encrypted protocol to securely| transfer the notes 11 from the Teller money module 5 to the • Transaction money module 4.
Records of the notes 11 generated and conveyed by theMoney Generator module 6 are sent to the local bank's TransactionReconciliation System 22 and an Issuing Bank's 1 Money IssuedReconciliation System 23 for maintaining statistical andhousekeeping functions. Records of the electronic notes 11cleared and settled at the Clearing Bank 3 are also provided tothe Money Issued Reconciliation System 23 . From these compilations, a financial position of the system can be producedby the Money Position System 24.
Discrepancies and malfunctions are reported to theSecurity System 21 which downloads the lists of problem moneymodules to all money modules in the system when they areconnected to the Network 25. By carrying this list, aTransaction money module 4 will be inhibited from transacting 16 with other suspect Transaction money modules 4.
Having thus provided in overview of the preferred embodiment, there will now follow a more detailed description ofthe individual elements and the transactions between them.
Money modules
Figure 3 provides several embodiments of externalsystems or devices for housing money modules.
In the preferred embodiment, the external system ordevice will typically contain data display means, data inputmeans, data processing means, memory storage means, directconnection or contactless bidirectional communications means, andthe money module packaged in a tamper-proof housing, allinterfaced by suitable means for information transfer, such asare well known in the art.
As will be understood, a money module may be embodied as a modular component of any larger processing environment while still performing the same functions. For example, Transaction money modules 4 may work as co-processors embedded in personal portable computing devices like the Hewlett-Packard 95LX, or as co-processors in mainframe computers, workstations, point-of-sale terminals or telephone devices (fixed or portable) connected to a network. »··' · ''A Teller money module 5 may be embodied as a co-processor in the bank's financial computer systems. The MoneyGenerator module 6 could be a separate processing unit networkedto the bank, a co-processor in a general purpose computer, or itmay be combined with an Issuing Bank's 1 Teller money module 5 ina larger processor,as illustrated by the unitary device 1001 ofFigure 1.
Because it is anticipated that a money module will beimplemented in a separate processing device, it is assumed thatcorresponding interface circuitry would be provided in the host 17 processing device to provide communication between the processingdevice and the money module.
Notably, all classes of money modules contemplatedby the invention may be implemented programmatically or by directelectrical connection through customized integrated circuits, ora combination of both, using any of the methods known in theindustry for providing the functions described below withoutdeparting from the teachings of the invention. Those skilled inthe art will appreciate that from the disclosure of the inventionprovided herein, commercial semiconductor integrated circuittechnology would suggest numerous alternatives for actualimplementation of the inventive functions of the money modulethat would still be within the scope of the invention.
Transaction Money Module
In one embodiment, the Transaction money module 4 maybe imbedded in any computer of any size or use, like thoseserving as general purpose computers or work-stations, to providefunctions not limited to E-M transaction use. This latterapplication will allow for such uses as real-time, off-linepayments between personal computing devices, or on-line paymentsfor network services such as information retrieval, telephonecalls, or for purchasing airline tickets, theater tickets, etc.
In another embodiment, the Transaction money module 4may be imbedded in an individual hand-held integrated circuitunit, such as a personalized hand-held computer that may bereadily carried by an individual as though it were a wallet. Asan illustration, the device of the preferred embodiment mayinclude a keyboard, a pen or stylus, a touch screen or voicerecognition circuitry as a data input means, an alphanumeric LCDdot matrix display as a display means, an infrared opticaltransceiver as a contactless bidirectional communications means, 18 and an RJ-11 telephone jack coupled to modem circuitry as atelephonic communications means. Additionally, the device mayalso include various electronic processing and storage means forproviding calculator capabilities, for storage and processingdata of the owner, etc.
It is important to note that the particular design ofthe external device is not critical to the invention, and othertechnologies suitable for accomplishing the foregoing functionsmay also be used. For example, an LED instead of an LCD displaypanel may be used; radio, infra red, inductive or capacitivecommunications methods may be used instead of direct connection;optical communications methods may be used; etc.
In general, it is anticipated that any Transactioni money module 4 owned by a subscriber will be embodied in a self- contained, tamper-resistant unit that contains components whichare difficult to access, and thus prevent any person fromimproperly examining, counterfeiting or modifying any of itscontents or arrangements. For example, integrated semiconductorcircuits, whose contents are difficult to examine, encased in atamper-resistant package such as that formed by an epoxy or plastic lamination may provide a high degree of physical security i while providing the necessary storage, computation, timing, andother data processing functions.
However, the invention is not limited to any particulartamper-resistance means, inasmuch as there are a number ofmethods known in the industry for providing such security. Suchtamper-resistance will also prevent the owner, who can controlonly some of the internal operations of the Transaction moneymodules 4, from certain accesses to thereby provide security fromabuse to other relevant institutions and individuals.
Each Transaction money module 4 will have a way ofensuring its own association with a particular subscriber, so 19 that its use by other individuals nay be limited. In addition tothe use of Personalized Identification Number (PIN) methods thatare well known in the art, the Transaction money module 4 mayalso include means such as a fingerprint reader,, voiceprintanalyzer, written signature analyzer, or other so-calledbiometrics means, to determine the physical identity of anauthorized subscriber.
Additionally, the Transaction money module 4 mayutilize personalized interactive proofs using questions that onlya true owner would be able to correctly answer, such as theowner's mother's maiden name, his/her favorite color, etc. Anysuch techniques may provide additional security for organizations, and may also be to the advantage of the authorizeduser since such security can protect the subscriber's data frominspection and use by someone else coming into possession of theTransaction money module 4.
Because the Transaction money module 4 can take on avariety of physical representations, it will be described by thefunctions performed in addition to the pertinent physicalcharacteristics of a preferred embodiment.
Referring now to Fig. 4, a Transaction money module 4is shown diagrammatically in block form. Specifically, aTransaction money module 4 has (1) an external interface 30 thatinterfaces the Transaction money module 4 to the module's dataprocessing means, the input/output means (human interface) andthe communications circuitry of the external device; (2) asession manager 31 to control and commit (i.e., finalize) orabort a transaction session; (3) a transactor 32 to manageapplication functions; and (4) a money holder 38 to contain andmanage the electronic representations of money.
According to the invention, the following applicationfunctions may be implemented in the preferred embodiment of the 20 present Invention:
The To Subscriber application 33 performs the functionof comparing the owner identification characteristics, such as auser's personal identification number (PIN) and biometricscharacteristic (e.g., fingerprint, voiceprint, etc.), that arestored in the memory of the Transaction money module 4, to thoseof the individual who is attempting to gain access to theTransaction money module 4. After the proper ownership isverified, the Transaction money module 4 may be activated, andthe user is allowed certain accesses to the Transaction moneymodule's 4 stored contents. Messages to the subscriber, andsubscriber inquiries as to the information contained within theTransaction money module 4 are also handled by this application ΐ function. i ι The To Teller application 34 interfaces the Transaction money module 4 to the Teller money modules 5 for initiating andperforming deposit, withdrawal, loan payment transactions, andbank inquiries with such Teller money modules 5.
The Pav/Exchanae application 35 supervises the sendingand receiving of electronic notes 11 between Transaction money • modules 4, managing the process in which the electronic notes 11 i ' are properly "packaged" as to amount, digital signatures, etc.This application provides that the electronic notes 11 aretransferred in a recognized, valid format. Notably, this is theapplication that allows a money module to perform payments andforeign exchanges. Without this application in the preferredembodiment, a Transaction money module 4 cannot make a payment toanother Transaction money module 4.
The Tran Log Mor, application 36 provides themanagement and overseeing of a log that records completedtransactions undertaken by the money module. For each completedtransfer of electronic money, an illustrative Tran Log records: 21 - (1) the type of transfer (i.e., payment, deposit,foreign exchange, etc.), (2) the date of transfer, (3) the amount of transfer, (4) the Issuing Bank 1 identifier (5) the note identifier, (6) the monetary unit, (7) the identifier of the other money module involvedin the transaction, and for deposits, withdrawals and loan payments: (8) the bank account number, (9) the bank identifier, and (10) the amount of the transaction.
I ί
In the preferred embodiment, every money module will ί ί have an identifier. A money module identifier may be thought of i ’ as the "serial number" of the money module and is never changed. 1
It is anticipated that a subscriber may have access to several of the fields of data stored in the Tran Log application,
I j such as histories of the amount, date, and type of transfer. ! Information as to the expiration date of a certificate may also be accessed by the subscriber so that he/she will be informed asi to the need to update or revalidate the money module's certificate.
The Maintain Security application 37 manages a list ofmoney module identifiers that are known to have been generallycompromised. In particular, this is a list that is distributedto each money module when it communicates with the Network 25,and is a list of money modules that have passed an invalid orcounterfeit electronic note 11 or have performed acts deemeddetrimental to the system.
When establishing a session between money modules, each 22 money module checks its list of bad money modules to see if theother is an offending money module. If the other money module'sidentifier appears on the list, the communication is broken off. i
This application also provides the process forobtaining the certificate unique to the money module, forsynchronizing an internal clock, and for managing the creation ofnew cryptography keys.
The Note Directory 39 application performs the function
I of keeping track of the location, identification and value of theelectronic notes 11 stored within the money module, λ note 11,whether it is an electronic currency note or an electronic creditnote, is the basic unit of electronic money. It is the
I j electronic object representing the economic value, the electronic - bits that contain the amount, expiration date, note identifier
I j etc. (described in detail below) that gets digitally signed| (described below) and encrypted when being transferred. Bothί electronic currency notes 11 and electronic credit notes 11 mayj be located by the Note Directory 39. | The Note Directory application 39 updates summary
totals of the current amount of electronic notes 11 (bothcurrency and credit), by monetary unit after every transfer. A j date-of-expiration, a note identification number and an IssuingBank identifier is also recorded with the location of each note 11.
In summary, the Note Directory 39 keeps track of thenote identification number, the Issuing Bank 1 identifier, thedate-of-expiration of the note 11, the location of the note 11 asstored in the Transaction money module 4, and the current amountof the total value of the notes 11 stored for each monetary unit.These records are maintained for both electronic currency andelectronic credit. For a credit note 11, the account number ofthe credit line is also maintained. 23 -
The Notes application 40 manages the storage of the representations of the electronic notes 11 themselves, bothcurrency and credit notes 11. This application also generatesthe transfers when notes 11 are to be conveyed.
The Packet Manager application 41 manages theconstruction and formatting of a packet of electronic notes 11that are to be transferred to another money module. For example,the Packet Manager 41 will utilize an algorithm so that the leastnumber of electronic notes 11 are used to fulfill the requestedamount of transfer, with the earliest dated electronic notes 11being used first. Alternatively, when a packet of notes 11 istransferred to the receiving money module, the Packet Manager 41 ί application "disassembles" the packet, verifying the date andseparating the data fields that represent the differentelectronic notes 11.
The formatted packet gets several data fields appendedto it when electronic notes 11 are "assembled." An identifier j data field provides the indicia that identifies it as a packet,j Additionally, data fields for the total value of the notes 11, the number of notes 11, and the individual locations of the notes11 are provided.
The Verifier application 42 verifies that a receivedpacket contains valid electronic notes 11 before a receivingmoney module accepts them. The Verifier 42 also checks that thetotal amount received is equal to the sum of the electronic notes11 that are to be transferred. If the total amount and theindividual electronic notes 11 are valid, an acknowledgment isreturned to allow for completion of the transfer. Otherwise, an"invalid" message is sent, and the transfer may be aborted.
Services applications that are provided fall under twocategories: Clock/Tlaer 43 and Cryptography. The ClocX/Tijpgx 43provides output pulses for controlling a transaction timeout, 24 such as the time between the sending of a message and the returnof a corresponding message.
As will be appreciated, when two money modules arecommunicating, they may be monitoring a time-out protocol. Forexample, after a first money module has sent a message to asecond money module, the Session Manager 31 of the first moneymodule ("A") may set a timer for a reply if the Transactor 32indicates that a reply is reguired. The Session Manager 31 mayalso number the message sent. This number would appear in thereply message from the Session Manager 31 of the second moneymodule ("B").
If the timer expires before the message has beenreceived, then Session Manager A 31 will query Session Manager B ' 31 to determine if the transaction is still running in B. If BI does not reply then Session Manager A 31 will abort the transaction. If a reply is received that the transaction is
proceeding, then the timer will be reset to a new time. If A ι queries B a predetermined number of times without receiving areply to the original message, then A may abort the transaction.
Separately, this application also maintains the currentί date and time, both for user display and for verifying that an electronic note 11 to be received is not an expired one, alongwith other general clock functions that are commonly used in theindustry.
The Cryptography application contains a Public Key 44operation, a Symmetric Key 45 operation, and a Random NumberGenerator 46. While the tamper-resistance of the Transactionmoney module 4 and its components makes it difficult for a personto modify the structure of the device or its contents, knowncryptographic techniques are also employed to provide securecommunications and payment transfers between money modules.
Public kev cryptography 44, as is well known in the 25 art, may be employed by this application to provide public keydigital signatures, which are called "digital signatures" orsimply "signatures" for brevity. The data in electronic notes11, may be represented by a digital number. The electronic notes11, are signed by digital signatures formed from this number. Adigital signature can then be checked as corresponding to aparticular message by anyone knowing the corresponding publickey, which in the preferred embodiment would be all other moneymodules.
This application provides each money module with theability to check the digital signature for authenticity. A moneymodule receiving the digitally signed electronic note 11 can inturn sign and transfer it to others, who could also check, signand distribute it.
Because of the "one way" nature and computationalcomplexity of public-key digital signatures, it is thought to beinfeasible to decipher and duplicate them within a feasibleperiod of time, making such a security system resistant toforgery.
Lastly, this application also creates new public andprivate keys when needed.
Symmetric Kev cryptography 45 provides private keyalgorithms that are well known in the art, for individual sessionsecurity and privacy between money modules. In the preferredembodiment, this application provides encryption/decryption meansin order to secure information being exchanged between two moneymodules.
Any well known symmetric key cryptography technique,such as the National Data Encryption Standard (DES) system orother cryptography techniques, may be provided in thisapplication. For example, due to the increasing interest inproviding cryptographically secured communications, manufacturers - 26
I are providing various semiconductor integrated circuit deviceswhich perform the encryption and decryption of data. Cylinkcorporation's CIDEC data encryption devices are examples ofcommercially available encryption/decryption circuitry that wouldbe suitable in the present invention for this application. Dueto the federally mandated use of the DES algorithm, devices suchas these are widely utilized to implement that algorithm.
It is important to note that the details of theparticular cryptographic methodology utilized by the moneymodules are not critical and are not limited to a particularcryptographic technique.
The Random Number Generator 46 generates random likenumbers for creating new public/private keys for the Public Key ' application 44 and new private keys for the Symmetric Key 45 i
I , application. This application is utilized to vary in an: unpredictable way the generation of temporary session keys.
Circuitry for providing such random number generationcapability are well known in the art. For instance, a circuit utilizing a "noisy" diode may provide random values, as is well
I known in the industry. Random numbers may also be provided by apseudorandom number generator circuit which implements amathematical algorithm, such as the power-residue algorithm, thatgenerates apparently random values from a "seed" number. The useof clocks or counters provides another often used source ofrandom data. As will be understood, the Random Number Generator46 may use techniques that are well known to a person of ordinaryskill in the art to generate the temporary numbers, and thus neednot be further described.
It should be further understood that the foregoingfunctions disclosed herein may be performed by known programmingtechniques and/or dedicated hardware and in some cases may becombination of both or shared resources from each. As may be 27 appreciated by a person skilled in the art, many changes in form and detail can be made in dependance on specific application requirements without departing from the essential features of themoney modules.
Teller money module
The banking systems 20 of both the Issuing Banks l andthe Correspondent Banks 2 interface to the system of theinvention through a Teller money module 5. The Teller moneymodule 5 may be imbedded in any general purpose computer orworkstation. The particular design of the Teller money module 5,like the Transaction money module 4, may be implemented in readily known programming techniques or dedicated computer i hardware, or a combination of both. As will be appreciated by aperson skilled in the art, various designs of the Teller moneymodule 5 may be employed to implement the functions described • herein.
I
The details of one embodiment of the Teller moneyJ module 5 is shown in block form in Figure 5. The Teller moneyί module 5 contains many of the same components and application functions of the Transaction money module 4 described above,ΐ Therefore, the identical components will only be repeated briefly here, while the distinguishing components will be fullydescribed. It should be noted that the Teller money module 5,like other money modules of the system, is also contained withina tamper-proof enclosure of the type common in the industry, soas to ensure the necessary security involved.
The Teller money module 5 contains an ExternalInterface 30, a Session Manager 31, a Transactor 32 and a MoneyHolder 38 that perform similar functions to the correspondingcomponents in the Transaction money module 4 described above.
Briefly, the External Interface 30 interfaces the - 28
Teller money module 5 to other processing and communicationsmeans within the Teller money module 5 host processor; theSession Manager 31 acts to control and commit (i.e., finalize) orabort a transaction session between the Teller money module 5 andanother money module; the Money Holder 38 manages the storing andretrieval of electronic money; and the Transactor 32 manages theapplication functions of a To Teller 34, the Tran Log Mgr. 36,the Maintain Security 37, the To Bank 47, a To Money Generator48, and the To Transaction 49.
The following list describes in brief, the applicationscontained in the Teller money module 5 that are functionallyidentical to the applications found in the Transaction moneymodule 4:
To Teller 34: Interfaces deposit and withdrawalfunctions to another Teller money module 5 .
Tran Log Mgr. 36: Transaction log manager forrecording transaction details. - Maintain Security 37: Manages the list ofcompromised money modules, applies forcertificates, synchronizes the clocks, and managesthe creation of new digital keys. - Note Directory 39: Keeps track of the location,value and identification of notes 11 by monetaryunit. Summary totals are also maintained. - Notes 40: Manages storage for the electronicnotes 11 of exchange, and creates the transfersfor the notes 11.
Packet Manager 41: Manages the assembly anddisassembly of a packet to be transferred to adifferent money module.
Verifier 42: Verifies that a received packetcontains valid electronic notes 11.
Clock/Timer 43: Controls transaction timeout,expiration of the validity of the electronic notes11, expiration of the certificate, and generalclock functions.
Cryptography (i) Public key 44: used for signatures to signand validate notes 11 and to set up a securetransaction session. 29 (ii) Symmetric key 45: Controls the security of atransaction session. (iii) Random number generator 46: Generates random like numbers for new cryptographic keys.
Some of the distinguishing applications are the To Bank47 and To Transaction 49 applications. The To Bank application47 provides the interfacing means whereby the Teller money module5 can perform exchanges of data for inquiries and accountpostings with the on-line systems of a bank. This application isalso utilized for crosschecking the customer's account numberwith the accounts and type of transaction being requested.
The To Transaction application 49 performs deposits,withdrawals and payments to loans. This application operateswhenever a Teller money module 5 is transacting with a , subscriber's Transaction money module 4.
I ' As mentioned above, a Teller money module 5 may be associated with an Issuing Bank 1 or a Correspondent Bank 2.
When the Teller money module 5 is associated with a Correspondent
I
Bank 2, it is utilized for intermediating deposits, withdrawals,and payments to loan accounts between a Transaction money module4, the Correspondent Bank's 2 on-line systems, and an Tellermoney module 5 at an Issuing Bank 1.
When operating in an Issuing Bank 1 mode, the Tellermoney module 5 is used for intermediating deposits, withdrawals,and payments to loan accounts between other money modules and theIssuing Bank's 1 on-line systems. Additionally, when the Tellermoney module 5 is performing in an Issuing Bank 1 mode, a ToMoney Generator application 48 may be employed when requestingnew notes 11.
Basically, the To Money Generator application 48performs banking functions dealing with requests for electronicnotes 11. It interfaces an Issuing Bank's 1 Teller money module5 to a Money Generator Module 8. 30
All of the other elements performed in an IssuingBank's 1 Teller money module 5 are essentially identical to thesimilarly named components and application functions describedabove.
Money Generator Module
Figure 6 is a block diagram illustrating theapplication functions of a Money Generator module 6. MoneyGenerator modules 6 provide the mechanism that Issuing Banks 1utilize to issue electronic money. A Money Generator module 6 isalso encased in a tamper-resistant package for the same securityreasons stated above for other money modules. A Money Generator module 6 generates the electronicmoney (in the form of electronic notes 11, to be described infurther detail below), and distributes them to other moneymodules through the Teller money module 5 of an Issuing Bank 1.The Money Generator module 6 includes a unique application notpresent in other money modules for responding to requests forelectronic money. This is the Money Creator application 50.
The Money Creator application 50 creates and formatsthe electronic objects representing value - either currencybacked by demand deposits, or credit authorizations - anddigitally signs these "electronic notes 11" using public keycryptography in conjunction with its secret key, so that it maybe sent to an Issuing Bank's Teller money module 5.
Notably, in a Money Generator module 6 the To Bankapplication 47 notifies the bank systems of any irregularities,off-loads transaction records in the Tran Log to the TransactionReconciliation System 22 and transfers electronic notes 11 to theMoney Issued Reconciliation System 23. All of the otherapplications of the Money Generator module 6 are identical to thesimilarly named applications of the money modules described 31 above.
The Network
According to one embodiment of the invention, theindividual components of the present invention may communicateover a Network 25, as shown in Figure 7. The Network 25 willlink together the Issuing Banks 1, Correspondent Banks 2, theClearing Bank 3 and the Certification Agency 28.
Transaction money modules 4 may be coupled to theNetwork 25 over the telephone exchange or via special terminalfacilities at bank locations (e.g., additional contactless orcable connections at an ATM booth). A communication layer willcarry transaction requests (e.g., deposits, withdrawals), packetsof notes 11 and new certificates securely across the Network 25. t In the preferred embodiment, the Network 25 will also provide ι
I : directories of financial services, and update the money moduleclocks and the bad money module list of all money modules. j As will be understood, the Network 25 may use well ' known data link or communications systems and techniques that i i utilize, for example, telephone lines, fiber-optic land lines, ! and satellites, and that include connective, timing and control software and circuitry for allowing access and transmittingdigital information. The Network 25 may use commerciallyavailable protocols and operating techniques such as those setforth by the International Standards Organization ("ISO") forOpen Systems Interconnect network standards. It is important tonote that the particular design of the Network 25 is not criticaland suitable technologies for accomplishing the foregoing datacommunications functions may be used.
Each entity (Banks 1 and 2, Certifying Agency 28, orClearing Bank 3) is also assumed to have an individual localnetwork 16, 17, 18 and a gateway to the larger system Network 25. 32
The larger Network 25 will provide directory services for therouting of messages to connect to the appropriate local network 16, 17, 18. The local network 16, 17, 18 has the responsibilityof routing messages to the correct money module or a SecurityServer 27. A Security Server 27 is associated with eachparticipating bank and the Certification Agency 28, and is usedfor implementing the security of the system.
Figure 7 illustrates the preferred embodiment of theNetwork 25 generally, indicating that money modules of anyparticipating bank may be intercoupled to the money modules ofother banks and financial institutions, or another subscriber'sTransaction money module 4 via a communications link directlyconnected into switching and processing centers and alternativelyconnected to a local network 16, 17, 18 at each entity. A money module need only identify the local network 16, 17, 18 destination (typically a bank subnetwork) for thetransmission of most messages. The local network 16, 17, 18 will j route the message to an appropriate money module for establishing J a session. Once a session is established, the Network 25 directs
I ; all messages between the two money modules. The Network 25 also
I controls messages between money modules and Security Servers 27.
Transaction money modules 4 may communicate over theNetwork 25 for deposits, withdrawals, payments to loan accounts,updates or inquiries. The Teller 5 and Money Generator modules 6will sign on the Network 25 periodically to update securityinformation. The sign-on will be initiated by the money moduleSession Manager 31, or by the bank Security Server 27 ifrecertification is required or if there are changes to the badmoney module list. A bank services directory may be available to the moneymodules primarily for updating the electronic notes 11 andperforming foreign exchange. A list of participating banks for 33 either service will be available from the Network 25.
In the preferred embodiment, the Network 25 willprovide time services to the individual components of the presentinvention. Transaction 4, Teller 5 and Money Generator modules 6and Security Server 27 clocks may be updated from a NetworkServer 26 in the Network 25 every time that the respective moneymodule accesses the Network 25.
Network Servers 26 may provide the money moduleservices described below, and gateway services to the localnetworks 16, 17, 18. The application functions of the preferredembodiment of the Network Server 26 are shown in the blockdiagram of Figure 8. The following application functions arecontemplated for the Network Sever 26: (1) External Interface 56 - a communications layerwhich interfaces to the Network 25; and (2) Communication Session Manager 57 - manages a I ' communication session between money modules, andbetween a money module and the Security Server 27. j Application Services are provided by: ί (3) Manage Network Sign-on 58 - controls the money module Network sign-on process; (4) Synchronized Time/Date 59 - keeps money moduleClock/Timer 43 services synchronized to a systemtime; (5) Route Message 60 - directory services for routingmessages, controlling message routing during sign-on and during a money module session; and (6) Direct to Bank Services 61 - provides informationon services provided by participating banks.
As will be appreciated by one skilled in the art,switching and processing centers that are known in the industrymay be used to enable the networking cooperation between a 34
I financial institution and any other that is coupled to the samecenters.
Electronic notes
We turn now to a further description of the elements ofthe electronic notes 11 themselves.
An electronic currency note 11 representing value isessentially an electronic object created from a transactionrequest (deposit or withdrawal) which is backed by demanddeposits at an Issuing Bank 1. At various times and in variouspoints of the system, the notes may appear in electrical ormagnetic forms or as electromagnetic radiation. These notes 11may be transferred over several transactions just like papermoney, with the additional property of fungibility that allowsthe electronic notes 11 to be commuted and transferred in amountsless than or equal to the value of the note 11.
Notes 11 may be split by appending a transfer record tothe note 11 and signing the note 11 using the privatecryptographic key of the money module transferring the note 11.Electronic credit notes 11, however, can only be transferred oncein the preferred embodiment, because it is anticipated that itsreceiver must deposit the credit note 11 so that the loan may berealized.
Credit notes 11, unlike currency notes 11 are drawn ona subscriber's loan account. Each credit note 11 carries theaccount number it is drawn on. The account may be a revolvingcredit or credit line on which the note 11 is drawn, operatingmuch in the same way that a check or a credit card account worksin today's banking industry. Credit notes 11 can represent apart of or all of the credit line of the account.
In the preferred embodiment, the credit notes 11 canonly be transferred to another Transaction money module 4 by the 35 owner of the account, and the receiver of a credit note 11 canonly deposit it into his or her account as currency. From there,the credit note 11 is cleared with the currency at the ClearingBank 3. The subscriber's bank recognizes the loan upon receiptof the cleared credit note 11.
When credit notes 11 are withdrawn, they do not triggerany accounting transactions in the preferred embodiment. Currentcredit line processing may to be modified to keep track of theamount of the credit line in the subscriber's Transaction moneymodule 4. Whenever the subscriber communicates with the IssuingBank 1 maintaining the credit line, the amount of the credit line
I in the Transaction money module 4 is removed and replaced basedon any adjustments to the credit line in the banking system 20.Total credit notes 11 plus outstanding loans must be less than oregual to the total amount of the credit line.
Electronic notes 11 are comprised of three collectionsof data fields, namely a Body group, a Transfer group, and aSignatures and Certificate group. The Body group of data fieldsincludes the following information: (1) the type of electronic note 11, i.e., whether itis a currency note 11 or a credit note 11; (2) the Issuing Bank's 1 identifier; (3) the monetary unit identifier; (4) a Note identifier; (5) its date-of-issue; (6) its date-of-expiration; (7) the subscriber's account number (used only forcredit notes 11); (8) the amount or value of the note 11; and (9) the Money Generator module 6 identifier.
The Transfer group of data fields includes: (1) a total of the number of times that the electronic 36 note ll was transferred; (provided for currencynotes ll only) (2) a list of transfer records that indicate to whomthe apportioned note 11 was transferred from, thedate-of-transfer, the amount transferred and theidentification number of the receiver.
The Signature and Certificates group of data fields includes: (1) the digital signature of the Money Generatormodule 6; (2) the Money Generator module 6 certificate; (3) a list of payers which contains each payor'ssignature and certificate; (4) the digital signature of the payor; and (5) the payor money module certificate.
The notes 11, transfer records, the signature and the i certificate of the chain of the transferred payments constitute i ! the electronic note 11 sent; the remaining amount of the note 11i is recorded in the Note Directory 39 of the money module in which it is stored.
It is important to note that the authenticity of an
I electronic note 11 is determined by the validity of the digitalsignature of the Money Generator module 6, and the validity ofthe signatures of past payors (if present). Any inconsistenciesin this information will cause the transfer of any electronicnotes 11 to be aborted.
It is also important to note that as a securitymeasure, a note 11 will be valid for a limited time, up to itsexpiration date. An expired note 11 cannot be transferred, itmust be updated by transacting with a participating bank. Tothis end, whenever a Transaction money module 4 performs anytransaction with a Teller money module 5, all of the electronicnotes 11 stored in a Transaction money module 4 will betransferred to the Teller money module 5 so that the notes 11 may 37 be replaced with updated ones before they expire. This securityprocedure also helps to keep offending notes 11 from beingcirculated broadly.
As will be understood, every time that a note 11 istransferred to another money module, a digitally signed transferrecord indicating from whom it is transferred is appended. Thus,the recipient of an electronic note 11 will also receive a recordof all of the past holders of the note 11.
For example, a $50 electronic note 11 may be generated,and withdrawn by a Transaction money module 4. Assuming it istransferred to other money modules in $10, $10, and $30denominations, the recipient money modules will receive the note . . . 45 . 11 with the transfer record identifying the first Transactionmoney module 4. When a recipient of the $10 note 11 transfers $5of it to a third party, the third party receives the note 11along with the record indicating the previous two holders. .Assuming this $5 note' 11 is then deposited, a record of. it willbe matched with other segments of the original $50 note 11 thatfind there way back into the banking system by the clearing andreconciliation processes of the present embodiment.
In accordance with the previous example,
Figure 51 shows how the subsequent transfer of an electronicrepresentation of currency produces a tree-like structure of electronic representations of currency derived fromthe initial note produced by the money generator module. The moneygenerator module 1003 having identifier "1" (module identifiers arecontained in digitally signed certificates) produces the electronicrepresentation of currency 1005 having a body group of data fields1007 and a transfer group of data fields 1009. The signatures andcertificates group of data fields is not shown for convenience.
The body group of data fields 1007 includes a noteidentifier 1011 (e.g., "12"), a money generator module identifier1013 (e.g., "1"), an issuing bank identifier 1015 (e.g., X), a 38 date-of-issue 1017 (e.g., 1:00:00), a date-of-expiration 1019 (e.g., 12:00:00), a note amount and a monetary unit identifier 1021(e.g., $50). Other body group data fields such as type of note are not shown for convenience.
The transfer group of data fields 1009 includes atransfer record having a transferee identification 'number (e.g.,"2"), a date-of-transfer (e.g., 1:00:00), and a transfer amount (e.g., $50). The transfer group data field indicating total numberof transfers is not shown for convenience. The various date.fieldsin the electronic notes are shown for illustrative purposes asbeing in the form day:hr:min. Other time monitoring forms (e.g.,including seconds) are, of course, possible.
The electronic representation of currency 1005 from money generator module 1003 is stored in teller module 1023 having identifier "2". As part of the withdrawal of $50 by transaction module 1025 having identifier "3", teller module 1023 formsΎ\. | .’· · > electronic representation of currency 1027 by appending transferrecord 1029 to a copy of the data fields in the electronic , representation of currency 1005. The note 1027 is stored intransaction module 1025 upon completion of the withdrawal. Forillustrative convenience, the remaining note transfers only showthe newly appended transfer record portion of the transferred note. '>>·· At 1:10:00, transaction module 1025 pays $10 by transferrecord 1031 to transaction module 1033 having identifier "4". At1:20:00, transaction module 1025 pays $10 by transfer record 1035to transaction module 1037 having identifier "5". At 1:30:00, transaction module 1025 pays $30 by transfer record 1039 to transaction module 104 1 having identifier "6". At 2:00:00, transaction module 103 3 pays $5 by transfer record 1043 to transaction module 1045 having identifier "7". At 2:10:00, transaction module 1045 deposits $5 by transfer record 1047 to teller module 1049 having identifier "8". Of course, alternativelytransaction module 1045 could have deposited its electronic money in teller module 1023. 38.a-
Only the receiver of the transferred note 11 can either deposit the note 11 or use it in payment. The Verifier 42 application of a money module is used to check the signature of each transfer, to determine if the note 11 is valid and to verify the identifier in the last transferor as the current holder of the note 11. This thwarts the new holder of a note 11 fromtrying to use a value greater than that which was transferred.
It also inhibits copying notes 11 for use in another money modulesince the identifiers will not match.
As can be appreciated, a subscriber may be able toaccess certain information about the electronic notes storedwithin the Transaction money module 4. - 38 b -
In particular, the subscriber may be able to selectinformation on the total amount of the electronic notes 11stored, the monetary unit of the notes 11, the type of electronicnotes 11, i.e., currency or credit, and the denomination of eachnote 11.
System Security
The security of the system is maintained by theparticipating banks and the Certification Agency 28, whichcreates and distributes money module certificates. A certificateof a money module is actually the money module's identifier, its public key, a digital signature of the money module's identifier Ϊ . and public key using the certificatory key (described below), and ! the version of the certificatory key. The certificate is unique i J in that it is associated with only one particular money module.
I
The Certification Agency 28 provides a secure means for i 1 money modules to validate each other prior to transacting, first i ! by controlling the money module certificate process and second, ι
I ' by distributing a list of bad money module identifiers.
In the preferred embodiment, the money moduleI certificate will be initially loaded into the money module by the
I
Certification Agency 28. The Certification Agency 28 generatesthe certificate for each money module using a certificatory key(a private key of the Certificatory Agency 28). It may bechanged periodically and distributed under version controlprocesses that are commonly used in the industry· As will beappreciated, every money module will store several versions ofthe certificatory key in order to verify certificates created byan older key. Because it is anticipated that certificates willexpire over time, it is expected that only a few versions need bekept. A certificate will only be valid for a limited period 39 of time after its creation. Upon expiration of the certificate,the money module will not be allowed to transact with other moneymodules. Any money modules discovered to have been tampered withwill be limited in the amount of damage that they can do to thesystem since their certificate will not be updated.
To block offending modules from transacting it is alsodesirable to have legitimate money modules receive the latestlist of offending money modules soon after the list is updated.Naturally, this requires that Transaction money modules 4 accessthe Certification Agency 28 on a periodic basis to obtain thelatest list. Placing a time limit on the Transaction moneymodule's 4 ability to transact (in addition to the time limitplaced on electronic notes 11) will force subscribers to accessthe Certification Agency 28 through the Network 25 on a periodicbasis to receive the latest bad money module list along with thea new certificate. Advantageously, the period of the certificatevalidity can be closely monitored and adjusted according tosecurity needs.
The Certification Agency 28 distributes its updatedcertificatory key and money module certificates on-line throughthe Security Server 27 (see Figure 9). An important component ofthe system's security is provided by Security Servers 27 at theparticipating banks and Security Servers 27 at the CertificationAgency 28.
Referring now to Figure 10, a block diagram of apreferred embodiment of the Security Server 27 is shown. It iscontemplated that the Security Server 27 at the CertificationAgency 28 or on a bank's local network 18 will contain thefollowing application functions: (1) External Interface 54 - a communications layer forconnecting to a bank's local network 18 or theCertification Agency's local network 17; 40 (2) Session Manager 55 - controls the security aspectsof a transaction session; (3) Create Certificate 50 - certifies a certificatefor any of the money modules; (4) Create Account Profile 51 - certifies and signs abank account profile (described in detailhereinafter) that allows a Transaction moneymodule 4 to access the subscriber's different bank accounts; (5) Distribute Certification Keys 52 - distributes theCertification Agency's 28 list of valid publickeys to the money modules; (6) Bad Money Module Control 53 - controls anddistributes the list of bad money modules; and (7) Services - identical to the cryptographicfunctions 44, 45, 46 in the money modulesdescribed above
Since certificates will expire over time, money moduleswill be required to apply for new certificates periodically. Inorder to receive a new certificate, the money module creates anew public key and private key. The new public key, the moneymodule identifier and the old certificate are presented to theCertification Agency 28 after being digitally signed using theold private key.
The Certification Agency 28 checks the signature and ifit is valid, signs the new public key and identifier and sendsthe certificate to the money module with a future expirationdate. The Certification Agency's 28 Security Server 27 alsodistributes a list of bad money modules via the Network 25.Initially, each participating bank's Security Server 27 reportsthe identifiers of mohey modules which hold notes 11 invalidly orthat are counterfeit. Those identifiers are passed through the 41
Security Servers 27 and are compiled by the Certification Agency 28.
All such identifiers are distributed to the Teller andMoney Generator modules 5, C respectively. A money module willnot transact with another money module found on the list of badmoney modules. Optionally, only those money modules which havedemonstrated a flagrant breach of security will be distributed toTransaction money modules 4.
If a Transaction money module 4 is lost or stolen, thesubscriber would report it to his/her bank or to theCertification Agency 28 so that the money module identifier maybe placed on the bad money module list to inhibit any furthertransactions.
While the security of the system is provided by beingable to block a money module from transacting, system security isalso maintained by providing the expiration date on the electronic notes IX in addition to the money module certificates.
As mentioned previously, a note XI will be valid onlyfor a limited time period after it is generated. Its date-of-expiration is a security parameter which may also be monitoredand varied as needed. The period of validity of a note XX can bevaried by the value of the note XX. Preferably, a large note XXwill expire in a shorter time period than a smaller one. Forexample, a $1,000,000 note may be set to expire five days afterthe date of its creation since it would provide a significantincentive to counterfeit, while a $50 note XX may be set toexpire after a month from the date of its creation. A Transaction money module 4 will not accept expirednotes XX, but it can deposit or exchange expired notes XX it maycontain for new notes XX. The expiration dates are checked bythe Verifier 42 and Clock/Timer 43 applications in a money modulebefore any electronic note XX is transferred. Separately, it is 42 also anticipated that if the money module loses power then itwill not be able to pay or exchange notes 11 after power has beenregained until it has communicated again with the Network 25 andhas its security parameters updated.
As stated above, a subscriber will typically obtain aTransaction money module 4 already loaded with a certificate.Securing the Transaction money module 4 itself to a subscribermay be accomplished by assigning it a unique PIN, biometrics orother personal secret characteristics.
Before any personalization of the money module 4 mayproceed, the Transaction money module 4 checks if there is a bankaccount already stored in the To Teller 34 application or if theNotes 40 application contains any electronic notes 11. In eitherof these cases, the Transaction money module 4 will inhibit thesubscriber from securing the module with new secret information. j If the Transaction money module 4 has no account
I j numbers or no stored notes 11, then the subscriber can secure it j by either entering a PIN, which is reverified by the Transaction i • money module 4, or by executing a process in which the I Transaction money module 4 learns the subscriber's biometrics.Once the personalization has been completed, subscriber access tothe Transaction money module 4 requires the successful completionof a sign-on in which the secret information is presented to theTransaction money module 4. If the subscriber can sign on to theTransaction money module 4, then he/she will be permitted tochange PIN's or reintroduce biometrics.
In the situation where a subscriber has forgottenhis/her PIN or had an incident which has affected his/herbiometric reading, then the subscriber may take his/herTransaction money module 4 to a participating bank. A specialtransaction may be executed which deposits any electronic notes11 in a holding account and destroys the stored bank account 43 numbers. The subscriber can now enter new secret sign-on numbersand characteristics. Any electronic notes 11 that were removedare returned to the Transaction money module 4 and the bankaccount numbers may then be recreated (see Bank Access below).
It should be noted that it is not a requirement for asubscriber to identify himself to the system when he takespossession of a Transaction money module 4. Though the identityof the money module is contained in every transaction, the holderof a Transaction money module 4 can be kept secret. If therelationship is revealed then one could trace all of thetransactions of a subscriber for the period that the relationshipcan be corroborated. The only time a subscriber must reveal hisidentity is if he/she links the money module to a bank account orwishes to redeem money lost. j If the subscriber chooses to use the Transaction money module 4 only for payments and foreign exchange then he/she cankeep the relationship secret. As may be appreciated, the| subscriber may also acquire a plurality of Transaction moneyj modules 4 and, for example, link one to bank accounts and
I maintain the others for anonymous payments. The otherTransaction money modules 4 may be loaded with notes 11 byexchanges with other money modules or by exchanging cash forelectronic notes 11.
Replacement of Money Module Value
If a Transaction money module 4 malfunctions or is lostor stolen, it may be possible for the subscriber to recoup thevalue that was stored in the money module at the time of theincident. This would necessitate that the subscriber relinquishthe option of anonymity for that money module, since upon makinga claim for the lost money, he/she would have to verify thathe/she is the owner of the Transaction money module 4. 44
To provide for the replacement of electronic notes 11,the subscriber may first link his/her Transaction money module 4to a bank account or register ownership of the Transaction moneymodule 4 with the Certification Agency 28. After everytransaction involving the transfer of electronic notes 11, thesubscriber could save the Tran Log, which identifies thecounterparty money module identifier and the note identifier, toinexpensive, non-volatile storage which is removable from thehost computing environment. This log may be presented by thesubscriber when making a claim to replace value. The log maythen be compared to reconciliation files to determine the truevalue of the lost electronic money.
An alternative to this procedure would be to refreshthe money in the Transaction money module 4 frequently!. Thiswould mean that the notes 11 in the Transaction money module 4
I • would be represented by transaction records at the Issuing Banksj 1. The existence of the notes 11 could be verified by scanning | these files. A third alternative would allow the system to capture a • money module's Tran Log when money is refreshed. These records ! would be copied and routed to Issuing Banks 1 for storage on t ι their transaction histories. The existence of the notes 11 could
I then be verified as in the previous alternative.
Bank Access
According to one aspect of the invention, a customer'sTransaction money module 4 may access his/her accounts fordeposits, withdrawals, transfers, etc., at any bank participatingin the system and in particular any bank holding an account withthe subscriber. For instance, a typical subscriber may have asavings account and a checking account at one of theparticipating banks, while maintaining a so-called money market 45 account at a separate financial institution, and perhaps acredit-line account at a third participating bank. It isanticipated that a subscriber's Transaction money module 4 willaccess his/her accounts for deposits, withdrawals, loan paymentsand inquiries at any bank or financial institution which can beaccessed through the Network 25.
If a subscriber has multiple accounts, the subscriber'saccount relationships with a bank will be stored in an accountprofile in the To Teller 34 application of the Transaction moneymodule 4. The multiple accounts can be linked together by thepersonal account number ("PAN") associated with the individualsubscriber.
The account profile may be created either in person,under the control of a bank subscriber service representative ata branch, or over the telephone utilizing a special dialogue.
For example, the subscriber may identify himself by his PAN andPIN. He may then enter each account number he wishes to accessfrom his Transaction money module 4. The account numbers may beverified in the bank's account reference files. A cross-reference of accounts to Transaction money modules 4 may bemaintained by each bank if they so choose.
The composition of an exemplary account profile may be: (1) Bank Identifier — one for each bank; (2) Account Numbers; (3) Account Types — e.g., checking, savings, credit;and (4) Security Server's 27 signature on the list ofaccounts.
It will be understood that the list of account numberswill be digitally signed by the bank Security Server 27. As afurther security measure the account profile may be re-signedwith an updated public key on a periodic basis. The fundamental 46 access security is provided by the digital signature of thebank's Security Server 27.
Banking System fAccounting Architecture)
It is a notable feature of the preferred embodiment,that the method of the system can parallel the existing andvarying types of accounting methods that exist today. The systemof the preferred embodiment follows the various types ofaccounting methods practiced presently in various banks.
However, it is important to note that unlike the present bankingsystem, in the preferred embodiment of the invention, economicvalue is created on demand. Thus, there is no inventory of cashor checks involved; electronic currency from demand deposits andelectronic credit are created on a real-time basis. Thiselimination of a paper inventory by using an electronic media ofexchange requires certain supplements to the commonly practicedaccounting techniques to provide the real-time accounting needed.
Accordingly, the embodiment of the present inventionprovides an accounting structure to supplement those used in thepresent banking systems 20. The improved accounting arrangementmay be utilized to monitor the electronic money and each bank'sobligation when a financial transaction between a Transactionmoney module 4 and a Teller money module 5 occurs, or when aClearing Bank 3 performs any clearing processes.
When electronic notes ll are transferred to or from aTeller money module 5, in most cases accounting transactionsaffecting the records of the banking system 20 are created.Conversely, transfers between Transaction money modules 4 do notinvolve any formal accounting procedures -- they involve only thetransfer of electronic notes 11.
In the system being described, it is anticipated thatthe following arrangements of accounts are to be utilized for - 47 each type of bank, categorized under each monetary unit:
At an Issuing Bank 1- (1) Money Issued Account: A liability account whichreflects the money issued but not cleared. (2) Money Due Account: An asset account reflectingthe money deposited to the bank's accounts. (3) Deposited at Clearing Bank Account: An assetaccount reflecting the balance of a clearingaccount at a Clearing Bank 3. (4) Correspondent Bank Money Account: A liabilityaccount owned by a Correspondent Bank 2 which isdrawn upon by the Correspondent Bank 2 to dispenseelectronic money. (5) Money In Transit Account: A zero-balanceliability account owned by each bank, which isused to temporarily maintain electronic moneyduring a financial transaction. (6) Foreign Exchange Account: A zero-balanceliability account owned by each bank, which isused to handle multiple currency exchanges.
At a Correspondent Bank 2 - (1) Deposited at Issuing Bank Account: An assetaccount reflecting the balance of theCorrespondent Bank 2 account at the Issuing Bank 1. (2) Money Due Account: An assetaccount reflecting the moneydeposited to the bank's accounts. (3) Foreign Exchange Account: A zero-balanceliability account owned by each bank, which isused to handle multiple currency exchanges. (4) Money In Transit Account: A zero-balanceliability account owned by each bank, which isused to temporarily maintain electronic moneyduring a financial transaction.
At the Clearing Bank 3: (1) Issuing Bank Clearing Account: A liability account to net the amount of money cleared for anIssuing Bank 1.
The accounts, with their corresponding symbols, are summarized below: 48 -
Type of Bank Account Name Type Owner Symbol Issuing Money Issued Liability Issuing MI Money Due Asset Issuing MD Deposited atClearing Bank Asset Issuing DC CorrespondentBank Money Liability Correspondent CM Money In Transit Liability Issuing IT Foreign Exchange Liability Issuing FX Correspondent Deposited atIssuing Bank Asset Corre spondent DI Money Due Asset Correspondent MD Money In Transit Liability Corre spondent IT - Foreign Exchange Liability Correspondent FX Clearing Clearing Liability Issuing CA
Account
Transaction processing, for a transaction such as arequest for a withdrawal from savings, selects accountingprocesses so that the appropriate accounts may be credited anddebited accordingly. It is anticipated that the accountingprocesses will be using software programs and methods that arewell known in the art and presently available; inasmuch as any ofthe programs and methods currently practiced and known forproviding the foregoing accounting procedures would be suitablefor use in the invention. To better understand the accountingprocesses of the invention, several examples of typicaltransactions and their associated accounting steps will be described.
Accordingly, Figures 11-24 illustrate the accountingtransactions for deposits, withdrawals, foreign exchanges,receipt of cleared money, electronic money/cash exchanges, andnote 11 updates. Figures 11-14 and 19-22 also illustrate theaccounting flows when a Transaction money module 4 contains notes11 that are not involved in the particular transaction that isoccurring. The notes 11 that are not part of the transaction are 49 - removed and replaced with updated notes as discussed in thesecurity procedures described above. For example, when asubscriber deposits less electronic money than is stored inhis/her Transaction Money Module 4 and leaves a balance, theelectronic notes 11 representing the balance are then replacedwith electronic notes 11 containing the most up-to-datecertificates. This latter case is indicated in the parentheticalentries on Figures 11-14 and 19-22.
In an example of the accounting arrangements accordingto the invention (illustrated by Figure 11), if a subscriber wereto deposit $50.00 out of $100.00 of electronic money contained inhis/her Transaction money modules 4 at a Correspondent Bank'sTeller money module 5 (Step 1), the entire $100 of electronicmoney would be extracted of which $50.00 would first be creditedto his/her customer account (herein denoted by "A"), theremaining $50.00 would be credited to the Correspondent Bank's
Money In-Transit account, and $100 would be debited to the Money !
Due account at the Correspondent Bank 2. See "IT" and "MD" inFigure 11.
After the $100 of electronic notes 11 is removed, thenotes 11 are deposited from the Correspondent Teller money module5 to the Teller money module 5 of an Issuing Bank 1 (Step 2). Inaccomplishing this transfer, the Money Due account at theCorrespondent Bank 2 is credited $100 while its Deposited atIssuing Bank account is debited by $100; the Issuing Bank 1credits its Correspondent Bank Money account by $100 and debitsits Money Due account by $100.
In Step 3, the updated notes 11 are requested. Thus,the Correspondent Bank 2 requests from the Issuing Bank 1 thewithdrawal of $50 of electronic money containing the most recentcertificates from its Money Generator module 6. To support thisrequest, $50 is credited to the Deposited at Issuing Bank account 50 t and $50 is debited from its Money In Transit account. TheIssuing Bank 1 then debits $50 from its Correspondent Bank Moneyaccount and credits $50 to its Money Issued account.
To complete the transaction, the $50 is thentransferred from the Money Generator module 6 to theCorrespondent Bank's 2 Teller money module 5 through the IssuingBank's 1 Teller money module 5, and finally to the Transactionmoney module 4 (Steps 4-6). The net result of all of thesetransactions is that $50 remains deposited in the subscriber'saccount and $50 of newly issued electronic notes 11 are nowstored in the Transaction money module 4 of the subscriber.
Alternatively, if a subscriber begins with $50 inhis/her Transaction money module 4 and deposits all of it, thecustomer account would be credited $50 and the Money Due accountwould be debited by $50 (Step 1 of Figure 11; parentheticalentries).
When there are only $50 of electronic notes 11 that areremoved, the Correspondent Bank 2 credits the Money Due account$50 and the Deposited at Issuing Bank account is debited $50(Step 2, parenthetical entries). This money is then deposited atthe Issuing Bank 1 for later clearing, wherein the CorrespondentBank Money account is credited by $50 and the Money Due accountis debited by $50. Because no updated electronic notes 11 needbe returned in this situation, the deposit and its correspondingaccounting is completed at Step 2.
The accounting processes of an electronic money depositat an Issuing Bank 1 instead of a Correspondent Bank involvefewer operational steps, which are illustrated in Figure 12.
Using the same dollar amounts as in the previous exemplarytransaction, when $50 of $100 in electronic money stored in theTransaction money module 4 are deposited directly to an IssuingTeller money module (Step 1), $50 would be credited to the 51 customers account (A). Fifty dollars would simultaneously becredited to the Money In Transit account, and $100 would bedebited to the Money Due account at the Issuing Bank 1.
Since the entire $100 stored in the Transaction moneymodule 4 is removed and transferred to the Issuing Bank's Tellermoney module 5, it is necessary to return $50 of updated notes tothe Transaction money module 4. Accordingly, as shown in Step 2the Teller money module 5 requests $50 from its Money Generatormodule 8, debiting its Money In Transit account by $50 andcrediting its Money Issued account by $50.
In response, $50 is created by the Money Generatormodule 6 and transferred to the Teller money module 5, which inturn transfers this electronic money to the Transaction moneymodule 4 (Steps 3-4).
When only $50 is stored in the Transaction money module4 and all of it is deposited, the customer's account (A) is I credited $50, the Money Due account is credited $50, and that is ί the end of it. See parenthetical entries in Step 1 in Figure 12.
In the case of a withdrawal from a Correspondent Bank(see Figure 13), a withdrawal request of $100 by a subscriberusing a Transaction money module 4 at a Correspondent Bank 2 willcause the subscriber's account (A) to be debited by $100 and the ί Correspondent Bank's 2 Money In Transit account to be credited by$100 (Step 1). The request for the $100 withdrawal is forwardedto the Issuing Bank 1 from the Correspondent Bank 2, and theCorrespondent Bank's Deposited at Issuing Bank account iscredited by $100 while its Money In Transit account is debited by$100 (Step 3).
Next, the request for $100 is forwarded by the Issuing
Bank's 1 Teller money module 5 to the Money Generator module 6.
Accordingly, the Correspondent Bank Money account gets a $100 debit while the Money Issued account gets a $100 credit (Step 4). 52
The Money Generator module 6 then creates the $100 ofelectronic notes 11, and transfers it to the Transaction moneymodule 4 via the Issuing Bank's 1 Teller money module 5 and theCorrespondent Bank's 2 Teller money module 5 (Steps 5-6).
When, e.g., the subscriber makes the $100 withdrawalrequest with a Transaction Money Module 4 that contains $50 ofelectronic notes 11, the notes 11 are removed and now the MoneyDue account is debited $50, the subscriber's account is stilldebited $100, and the Money In Transit account is credited $150(parenthetical entries, Step 1).
The $50 is then deposited to an Issuing Bank 1, causingthe Money Due account to be credited $50 and the Deposited atIssuing Bank account to be debited by $50. At the Issuing Bank1, the Correspondent Bank Money account is credited $50 while theMoney Due account is debited $50 (Step 2, parenthetical entries). j Because $50 of notes 11 have been removed, the jwithdrawal request in Step 3 must be for $150. This request! causes the Deposited at Issuing Bank account to by credited byΐ $150 and the Money In Transit account to be debited by $150 (Step
I
I : 3 parenthetical entries). I At the Issuing Bank, $150 is requested from the Money
Generator Module 6 and the Correspondent Bank Money account getsa $150 debit while the Money Issued account gets a $150 credit(Step 4 parenthetical entries). As above, the money generated bythe Money Generator Module 6 ($150) gets conveyed to theTransaction money module 4 via the Issuing Bank 1 and
Correspondent Bank 2 Teller money modules 5 (Steps 5-6,parenthetical entries). A withdrawal from an Issuing Bank 1 involves feweraccounting procedures. Referring now to Figure 14, a withdrawalrequest by a Transaction money module 4 from an Issuing Bank 1,will cause the Issuing Bank 1 Teller money module 5 to debit the 53 subscriber's account (A) by $100 and credit its Money Issuingaccount by $100 (Steps 1-2). A request for an updated $100 is then made by theIssuing Bank's 1 Teller money module 5 to the Money Generatormodule 6, which upon its creation will return $100 to the IssuingBank's Teller money module 5 (Step 3). In completing thetransaction, the Issuing Bank's 1 Teller money module 5 simplytransfers this new $100 containing the most recent certificate tothe Transaction money module 4 (Step 4).
Alternatively, when the Transaction money modulecontains $50 at the time of the $100 withdrawal, (parentheticalentries) the $50 will be removed, the Issuing Bank's Money In
I
Transit account will be credited $50 and the Money Due accountwill be debited $50 (Step 1).
The Issuing Bank 1 must now request $150 from the MoneyGenerator module 6. Naturally, the customer's account is debited$100. The Money Issued account is credited by $150 when the newnotes 11 are created, and the Money In Transit account is debited$50 (Step 2). From there, $150 is returned to the Transactionmoney module 4 via the Issuing Bank's 1 Teller money module 5(Steps 3-4).
Figure 15 illustrates the case of a foreign exchangewith an Issuing Bank 1. In this example, a subscriber wishes toexchange $100 of electronic money stored in his/her Transactionmoney module 4 for £60 of British currency. The deposit at theIssuing Bank's 1 Teller money module 5 will cause the IssuingBank's 1 Foreign Exchange account to be credited by £60, whileits Money Due account would be debited by $100 (Step 1). Here,the $100 is transferred from the Transaction money module 4 tothe Teller money module 5, which then requests that an electronicnote 11 representing £60 be created by the Money Generator module6 (Step 2). 54
At the Issuing Bank 1, the foreign exchange account isnow debited by £60 while the Money Issued account is credited by£60. The £60 electronic note 11 created by the Money Generatormodule 6 is transferred to the Teller money module 5, which nowstores both the $100 and the £60 (Step 3). The £60 is thentransferred from the Teller money module 5 to the Transactionmoney module 4 resulting in a net balance of £60 in theTransaction money module 4 and $100 remaining in the Teller moneymodule 5, completing the transfer (Step 4).
The accounting procedures for a foreign exchange of$100 for £60 at a Correspondent Bank 2 are shown in Fig. 16. TheTransaction money module 4, in this example, requests that its$100 be used to "purchase" £60 from the Correspondent Bank'sTeller money module 5, which causes the Correspondent Bank'sForeign Exchange account to be credited by £60 while its MoneyDue account is debited by $100 (Step 1). The $100 stored in theTransaction money module 4 is transferred to the CorrespondentBank's 2 Teller money module 5, which sends a request to theIssuing Bank's 1 Teller money module 5 to withdraw £60, anddebits its Foreign Exchange account by £60 and credits itsDeposited at Issuing Bank account by £60 (Step 2).
The corresponding account transaction at the IssuingBank 1 debits the Correspondent Bank Money account by £60 andcredits the Money Issued account by £60 (Step 3). The IssuingBank's Teller money module 5 then requests that the MoneyGenerator module 6 create £60 and transfer it to the IssuingBank's Teller money module 5, which in turn transfers it to theCorrespondent Bank's 2 Teller money module 5 (Steps 4-5). Fromthere, the £60 note 11 is transferred to the Transaction moneymodule 4, leaving it with a balance of £60 while theCorrespondent Bank's 2 Teller money module 5 finishes with abalance of $100 (Step 6). 55
The accounting transactions for a withdrawal or depositof credit notes 11 also involves several accounting operations,as shown in Figure 17. When a subscriber wishes to withdrawmoney from his/her credit line (Step 1), the proper credit note11 is simply transferred from the Money Generator module 6 to theTransaction money module 4, reducing the customer's credit lineby an equal amount to the amount transferred (Steps 2-4).
Alternatively, when credit notes 11 are deposited by asubscriber's Transaction money module 4, the subscriber's accountis increased by the amount deposited, and the Money Due accountis debited by an equal amount (Step 1).
The accounting operations involving the Issuing Bank's' 1 receipt of cleared electronic money will now be described.Referring to Figure 18, in this example $100 of electronic money and $100 of credit notes 11 have been cleared by the ClearingBank 3 to settle the balances among several Issuing Banks 1. The$100 of electronic money and the $100 of credit notes are | transferred to the proper Issuing Bank 1 (Step 1). Additionally,$50 of electronic notes 11 that it has issued are also depositedat the Issuing Bank 1. Consequently, the Issuing Bank 1 willdebit the subscriber's account A by $100, debit the IssuingBank's Money Issued account by $150, credit the Money Due accountby $50 and credit the Issuing Bank's Deposited at Clearing Bankaccount by $200 to complete the transaction.
Turning now to Fig. 19, an accounting example of anexchange of cash for electronic notes 11 at an Issuing Bank 1 isshown. In this example, the subscriber wishes to exchange $50 ofcash for $50 of electronic notes 11 to add to the $100 ofelectronic notes 11 already stored in his/her Transaction moneymodule 4.
In the first transaction, the $50 of cash is depositedat the Issuing Bank 1 which causes the Money In Transit account 56 - to be credited by $50, while the cash account is debited by $50(Step 1).
Next, the $100 of electronic notes 11 in theTransaction money module 4 is removed, resulting in the Money InTransit account being credited by $100, while the Money Dueaccount is debited by $100 (Step 2).
The Teller money module 5 will now request $150 ofelectronic notes 11 from the Money Generator module 6 to return$150 of electronic notes 11 to the subscriber (Step 3).Accordingly, the Money In Transit account is debited by $150while the Money Issued account is credited by $150.
The newly generated $150 of electronic notes 11 is thentransferred from the Money Generator module 6 to the Teller money ίmodule 5, which in turn transfers the $150 to the subscriber's ; Transaction money module 4 (Steps 4-5). The completed
I transaction leaves the subscriber with $150 of electronic notes11 and the Issuing Bank's Cash account containing a $50 balance. j Also shown parenthetically in Fig. 19 is the case when j the subscriber exchanges $50 of cash for electronic notes 11 whenί there is a zero balance in his/her Transaction money module 4. ί !In Step 1, the $50 of cash is deposited at the Issuing Bank 1-which causes the Money In Transit account to be credited by $50,while the cash account is debited by $50. Since no notes 11 areremoved, no accounting is performed in Step 2.
In Step 3, only $50 is requested from the MoneyGenerator module 8, and the Money In Transit account is debitedby $50 while the Money Issued account is credited by $50. Thesame transfer between money modules occurs as in Steps 4-5 ofFig. 19 described above, using only the $50 that was requested.This would leave the subscriber with $50 of electronic notes 11in lieu of his original $50 of paper money.
In Fig. 20, an exchange of cash for electronic notes ll 57
Bank 2 for results inj account byί account by at a Correspondent Bank 2 is shown. This example uses the sameparameters as in Figure 19, namely, the subscriber has $50 ofcash and $100 of electronic notes 11 in his Transaction moneymodule 4.
When the $50 in cash is deposited to the CorrespondentBank 2, its Money In Transit account is credited $50 while itsCash account is debited $50 (Step 1). The $100 of electronicnotes 11 is then transferred from the Transaction money module 4to the Correspondent Bank 2 which credits its Money In Transitaccount by $100 and debits its Money Due account by $100 (Step2).
From there, the $100 of electronic notes 11 isdeposited at the Issuing Bank 1, wherein its Money Due account isdebited by $100 while its Correspondent Bank Money account iscredited by $100 (Step 3). At the Correspondent Bank 2, theDeposited at Issuing Bank account is debited by $100 while theMoney Due account is credited by $100. A withdrawal request is then made by the Correspondent$150 from the Issuing Bank 1 (Step 4). This requestthe Correspondent Bank 2 debiting its Money In Transit$150 and crediting its Deposited at Issuing Bank$150. :orrespondingly, the Issuing Bank 1 Teller money module5 requests $150 of notes 11 from the Money Generator Module 6,debits its Correspondent Bank Money account by $150 and creditsits Money Issued account by $150 (Step 5).
Finally, the $150 of electronic notes 11 is transferredfrom the Money Generator module 6 to the Issuing Bank's 1 Tellermoney module 5 which transfers it to the Transaction money module4 after passing through the Correspondent Bank's 2 Teller moneymodule 5 (Steps 6-8).
Alternatively, a subscriber having $50 of cash and no 58 notes 11 in his/her Transaction money module 4 is also shown inFig. 20. As in the first case, the $50 in cash is deposited tothe Correspondent Bank 2, its Money In Transit account iscredited $50 while its Cash account is debited $50 (Step 1). A $50 withdrawal request is then made to the IssuingBank 1, and the Money In Transit account is debited by $50 whilethe Deposited at Issuing Bank account is credited $50 (Step 4,parenthetical entry). Thereafter, $50 is requested from theMoney Generator Module 6, the Correspondent Bank Money account isdebited $50 and the money issued account is credited $50 in Step5 (parenthetical entry). Here, $50 in electronic notes 11 aretransferred through the same money module path as Steps 6-8above, to reach the Transaction money module 4.
Figure 21 illustrates the exchange of electronic notes11 for cash at an Issuing Bank 1. Here the subscriber has $100 1 of electronic notes 11 stored in his/her Transaction money module4 and wishes to exchange $50 of the electronic notes 11 for $50
I ί of paper cash.
After the Transaction money module 4 establishes. communications with the Issuing Bank's 1 Teller money module 5, I all $100 of the electronic notes 11 is removed from the
Transaction money module 4 (Step 1). This causes the Money InTransit account to be credited by $100 and the Money Due account(at the Issuing Bank 1) to be debited by $100.
The Teller money module 5 then requests $50 of updatedelectronic notes 11 from the Money Generator module 6, and thistransaction requires the Money In Transit account to be debitedby $50 and the Money Issued account to be credited by $50 (Step2). The newly generated $50 of electronic notes 11 is thentransferred to the Transaction money module 4 through the Tellermoney module 5. The $50 of paper cash is then transferred to thesubscriber through a Teller or ATM (Steps 3-5). 59
Also shown in this figure (parenthetically) is thesubscriber making the same exchange for cash when only $50 isstored in his/her Transaction Money Module 4. At the IssuingBank, $50 of electronic notes 11 is removed for which the MoneyIn Transit account is credited $50 and the Money Due account isdebited $50. Fifty dollars of paper cash is then returned to thesubscriber since he/she only deposited $50 of electronic notes 11(Step 5).
Completing this transaction, in both cases the Money InTransit account is debited by $50 while the cash account at theIssuing Bank 1 is credited by $50. The net result is that thesubscriber ends up with $50 of paper cash and, in the former casei only, $50 of updated electronic notes 11 in his/her Transaction
I money module 4.
The exchange of electronic notes 11 for paper cash at a: Correspondent Bank 2 is illustrated in Figure 22. As in the! example illustrated in Figure 21, although the subscriber is only! exchanging $50 of electronic notes 11, all $100 of electronic
I notes 11 are transferred from the subscriber's Transaction money
I • module 4 (Step 1). ί I After the notes 11 are transferred, the Correspondent ι
Bank's 2 Teller money module 5 credits its Money In Transitaccount by $100 and debits its Money Due account by $100. This$100 of electronic notes 11 is now deposited at an Issuing Bank1, causing the Correspondent Bank 2 to credit its Money Dueaccount by $100 while debiting its Deposited at Issuing Bankaccount by $100 (Step 2).
At the Issuing Bank 1, $100 is credited to theCorrespondent Bank Money account while $100 is debited to theMoney Due account. The Correspondent Bank 2 now makes a requestto withdraw $50 of electronic notes 11 from the Issuing Bank 1(Step 3). Consequently, the Deposited at Issuing Bank account is 60 credited by $50 while the Money In Transit account at theCorrespondent Bank 2 is debited by $50.
Now, the Issuing Bank's 1 Teller money module 5requests $50 from the Money Generator module 6 and debits itsCorrespondent Bank Money account by $50 while crediting its MoneyIssued account by $50 (Step 4). The $50 of updated electronicnotes 11 is transferred from the Money Generator module 6 throughIssuing Bank 1 Teller money module 5 and the Correspondent Bank 2Teller money module 5, back to the Transaction money module 4 inSteps 5-7.
Also illustrated is this same example with only $50stored in the Transaction money module 4, which is deposited at aCorrespondent Bank 2, to be exchanged for paper money. For thisdeposit, the Money In Transit account is credited $50, and theMoney Due account is debited $50 (Step 1). The $50 is thendeposited by the Correspondent Bank 2 to its account at theIssuing Bank 1. At the Correspondent Bank 2, the Money Dueaccount receives a $50 credit, while the Deposited at IssuingBank account receives a $50 debit. On the Issuing Bank 1 side,it credits the Correspondent Bank Money account by $50 and debitsthe Money Due account by $50 after receiving the $50 deposit(Step 2).
In both illustrations, fifty dollars of paper cash isthen transferred from the Correspondent Bank 2 to the subscriber,while the Correspondent Bank 2 debits its Money In Transitaccount by $50 and credits its cash account by $50 (Step 8). Thesubscriber is now left with $50 of paper cash and, in the firstillustration, $50 of electronic notes 11 stored in his/herTransaction money module 4.
Figure 23, the accounting process for clearing theelectronics money issued by different Issuing Banks is shown.
This illustration uses an example in which $100 of electronic - 61 notes 11 issued by Bank B has been deposited at Issuing Bank A,and $150 of electronic notes 11 issued by Bank A have beendeposited at Issuing Bank B.
In Step 1, Issuing Bank A transfers the $100 issued byBank B to the Clearing Bank 3. It then credits its Money Dueaccount by $100 and debits its Deposited at Clearing Bank accountby the same amount. In Step 2, Issuing Bank B transfers the $150of Issuing Bank A's money to the Clearing Bank 3. Its Money Dueaccount is credited by $150, while its Deposited at Clearing Bankaccount is debited $150.
In sum, $50 is due to Bank B. Accordingly, $50 getsdebited to the Clearing account of Bank A, while $50 getscredited to the Clearing account of Bank B (Step 3).
In Figure 24, the accounting transactions correspondingto updating electronic notes 11 is shown. Here, $100 ofelectronic notes 11 are stored in a Transaction money module 4and are transferred to an Issuing Bank 1, where $100 is creditedto the Money In Transit account and $100 is debited to the MoneyDue account (Step 1).
One hundred dollars of electronic notes 11 arerequested from the Money Generator module 6 causing the Money InTransit account to be debited by $100 while the Money Issuedaccount is credited by $100 (Step 2). With this accomplished,the $100 of electronic notes 11 is transferred from the MoneyGenerator module C to the Issuing Bank's 1 Teller money module 5,which in turn transfers the money to the subscriber's Transactionmoney module 4 (Steps 3-4).
Reconciliation and Clearing Systems
Referring to Figure 25, the Transaction ReconciliationSystem 22 is shown. It will be understood that the Teller moneymodules 5, the Money Generator modules 6 and the banking system 62 20 may periodically pass transaction records to a TransactionReconciliation System 22 maintained at each participating bank.These transactions will be analyzed and matched to determine ifthere is any faulty process occurring in the system of theinvention.
The Transaction Reconciliation System 22, which may beembodied in any appropriately sized and suitably programmedgeneral purpose computer but is not so limited, will ensure thatall Teller money module 5 transactions with a financial impact,e.g., deposits, withdrawals and payments, match the appropriateaccounting transactions. Any mismatches could indicateincomplete transactions or possible fraudulent actions.
Transactions reflecting the money issued by the MoneyGenerator modules 6 also should correspond to Teller money module5 transactions and have the appropriate accounting transactionsrecorded. Any mismatched data may indicate incomplete processingor a security breach. Unmatched accounting transactions may becaused by incomplete transactions or an attempt to tamper withthe records of the banking system 20.
In the preferred embodiment, these unmatchedtransactions may then be transferred to an investigation system12 where the causes of the problems may be determined. On-linedialogues may be provided to allow investigators to review themismatches against transaction records and to determineappropriate actions to correct the situation. Investigators maythen take corrective actions by adjusting accounts, deactivatingfaulty Teller money modules 5 and Money Generator modules 6, andnotifying subscribers of the actions.
Attention is now directed to Figure 26, whichillustrates the clearing process for handling deposittransactions. Correspondent Banks are not involved in thisprocess because subscriber deposits are deposited to their - 63 - accounts at Issuing Banks 1 on a real-time basis. At Issuing
Banks, deposits are aggregated by the Clearing System 13 to consolidate all deposited electronic money (including the deposits from Correspondent Banks) for transmission to the
Clearing Bank 3.
The Clearing Bank 3 may be implemented in any computerprocessing facility capable of accommodating the large number oftransactions and corresponding amounts of data which the systemwill typically handle. A high volume mainframe computer, asuitably sized minicomputer system, a number of networked workstations having the necessary data processing capabilities or acombination of the foregoing may also be used. As will beappreciated by a person skilled in the art, the particular designof the Clearing Bank 3 hardware system is not critical to theinvention. I It is anticipated that Issuing Banks 1 may clear money in one of several procedures. In one of these procedures,electronic money may be deposited on-line from the Issuing Bank 1 I to the Clearing Bank 3. This could be done on-line in a real-• time mode when transactions are actually occurring.
Alternatively, an Issuing Bank 1 may record the details oftransactions being performed during the course of the day for later batch processing. Interbank processing could occur severaltimes a day.
As shown in Figure 26, an Issuing Bank 1 mayperiodically transfer its electronic money to a depositconsolidation file (consolidate deposits) which may be processedand transmitted to the Clearing Bank 3. Transaction records fromthis file are also conveyed to the bank's TransactionReconciliation System 22 for statistical and housekeepingfunctions.
At the Clearing Bank 3, the deposit consolidation files 64 are processed creating a single debit or credit by monetary unitfor each Issuing Bank's 1 demand account. Of course, theappropriate accounting transactions for these demand accounts areposted during the clearing processes. Any accounts which areoverdrawn will be settled via the usual interbank settlementprocesses that are commonly used in the industry.
The processed electronic money that is cleared is sentback to the Money Issued Reconciliation System 23 of each of thebanks that issued it in order to be reconciled and checked fortampering and duplication.
Additional statistical and housekeeping functions areimplemented in the Money Issued Reconciliation System 23, asshown in Figure 27. Issuing Bank's 1 provide their own MoneyIssued Reconciliation System 23, typically embodied in a generalpurpose computer but not so limited, for matching the electronicmoney issued to the electronic money cleared at the Clearing Bank 3.
As indicated in Figure 27, the electronic money issued| and electronic money deposited at Issuing Banks 1, and money' cleared transactions received from Clearing Bank 3 are conveyedto the Money Issued Reconciliation System 23. The Money IssuedReconciliation System 23 generates accounting transactions forthe money cleared, and updates a master file of all the bank'smoney issued. Additionally, the Money Issued ReconciliationSystem 23 passes to an investigation subsystem 13 money which hascleared but which was not issued or was possibly transferred morethan once.
Any unmatched cases may indicate a potential breach ofsecurity. Investigators may then determine whether MoneyGenerator modules β are not working properly or money modules arebeing tampered with. Money module identifiers of faulty orabused money modules are passed to each bank's Security Servers 65 27 for distribution to the other money modules on the bank'slocal network 18. The identifiers are also sent to theCertification Agency 28 for appropriate distribution throughoutthe Network 25.
Separately, the Money Issued master file is accessed bythe Money Position system 24 which creates a file to betransmitted to the Clearing Bank 3 to create a consolidated moneyposition. It is contemplated that all Issuing Banks 1 willprovide a report reflecting their position at the end of aspecified period, typically at the end of every day. The MoneyPosition System 24 may consolidate these reports to reflect theamount of money issued by the Issuing Banks 1 for each monetary j unit. The reports will reflect the outstanding position of eachIssuing Bank 1 in order to assess the risk of interbanksettlement problems.
Operational Sequences
Although some aspects of the preferred embodiment may ! be described in terms of detailed schematic diagrams, the
I transaction functions are best illustrated by use of processflowcharts. Thus, to facilitate understanding of the operationof the money modules, several examples of transactions are setforth in the flowcharts of Figures 28-50A. Referring to thesefigures, a detailed description of the system processes and theassociated application functions that incorporate the principlesof the preferred embodiment of the present invention will now bedescribed.
Throughout the descriptions of the flowcharts (exceptwhere indicated otherwise), the application functions of theTransaction money module 4, whether they are imbedded in a hand-held unit or other type of processing device, are hereinafterdesignated with the suffix "A", and the Teller money module 5 66 applications and its associated bank are hereinafter designatedwith the suffix "Β". In the case where a Correspondent Bank 2interacts with an Issuing Bank 1, the Issuing or CorrespondentBank 1 and its associated Teller money module 5 applications arehereinafter designated with a "C."
Additionally, transitions to steps in another figureare indicated by a pentagonal tag having an alphanumeric symbol,and continue on the other figure with a circle having the samealphanumeric symbol therein.
Withdrawal From An Issuing Bank
In Figures 28-35A, a process flowchart of a transactionbetween a Transaction money module 4 and a Teller money module 5is shown. In this process example, it is assumed that thesubscriber is desirous of completing a monetary transaction witha participating bank; specifically, a withdrawal of some amountof electronic money from his/her account, to be stored in his/herTransaction money module 4.
The process flow to set up a withdrawal transactionbegins at the top of Figure 28. The first flow block is awithdrawal set up between a money module A and a bank's Tellermoney module B 5, which is described further in Figure 29. Thisprocess begins with money module A performing a sign-on processthat is also described in further detail in another figure,specifically Figure 31.
Subscriber Sign-On
Referring to the top of Figure 31, the subscriberprompts his/her Transaction money module 4 to perform a sign-onfunction (Step 10). The Session Manager 31 application receivesthe sign-on message (Step 12) and checks to see if theTransaction money module 4 has inhibited subscribers from signing - 67 on (Step 14).
Subscriber sign-on may be inhibited if a user makesseveral unsuccessful attempts to sign-on to the Transaction moneymodule 4. For example, the allowable attempts to sign-on may belimited to three, such that if a person makes more than threeconsecutive unsuccessful attempts to sign-on to the Transactionmoney module 4, the Session Manager 31 will prohibit any furthersign-on attempts. Additionally, this "lock-out" feature may bemaintained for any predetermined time period, such as twenty-four
I hours, for example. Such an arrangement will provide securityfrom use by persons who come into possession of the Transactionmoney module 4 but who are not properly authorized to access it.
It should be noted that while this type of anarrangement is anticipated in the preferred embodiment of theinvention, the invention should not be limited as such, since anyof the methods known in the industry for providing security fromunauthorized persons would be suitable for use herein.
When the sign-on is not inhibited, as will typically be
I ; the case, To Subscriber 33 prompts the subscriber to enterhis/her sign-on characteristics, such as his/her PIN and'biometric identifiers (Step 22). Inputs from the subscriber are
I forwarded through the Session Manager 31 to the To Subscriber 33application (Steps 24-28), which responds to the characteristicsentered and entitles the subscriber to operate the Transactionmoney module 4 if the subscriber's identification characteristicsare the correct ones when compared to those stored in the memoryof the Transaction money module 4 (Steps 30-32).
If the subscriber's identification characteristics donot match the identifiers stored in memory, the To Subscriber 33application notifies the subscriber of the invalid sign-oncondition (Step 34). From there, the To Subscriber 33 applicationchecks to see how many times the user has attempted to sign-on 68 (Step 36), and if the predetermined count has not been reached,the Session Manager 31 is notified (Step 38).
The Session Manager 31 works in conjunction with theClock/Timer 43 application to set and to monitor the time thathas elapsed between unsuccessful sign-on attempts (Step 40). Inone embodiment, too many unsuccessful attempts within the settime period will cause the Session Manager 31 to prohibit anyfurther sign-on attempts, effectively shutting down theTransaction money module 4. The Session Manager 31 notes thatthe sign on is terminated in Step 42.
Turning back to Step 14 of Figure 31, assuming that theTransaction money module 4 is inhibited, the Session Manager 31checks to see if the predetermined time period has expired (Step16). If the Transaction money module 4 is still in the prohibitedsign-on mode, the To Subscriber 33 sends a message to thesubscriber that further access to the Transaction money module 4is prohibited (Steps 18-20). The Session Manager 31 then notesthat the sign-on attempt is terminated, again in Step 42.
Setup Withdrawal
Turning to Figure 29, when a proper sign-on is
I accomplished, the To Subscriber A 33 prompts the subscriber forthe type of transaction that is desired (Step 43). As mentionedpreviously, it is anticipated that a subscriber may transact withany one of a multitude of accounts at several differentparticipating banks and financial institutions.
After selecting the particular bank and account (Step44), the Transaction money module 4 initiates a procedure forcommunicating with the bank that was selected, by engaging theNetwork 25. The overall program flow now passes to theprocedures illustrated by flowcharts in Figure 33. In Figure 33,there is shown the data processing and flow for implementing a 69 sign-on to the Network 25.
Network Sign-On
The illustrative Network 25 sign-on method about to bedescribed is in general applicable to any of the money modules 4,5,6 of the present embodiment. Thus, in this example, "A"denotes any class of money module.
After the bank that is to be accessed is selected, themoney module initiates communication with the Network 25 underthe control of its Session Manager A 31 (Step 50). The NetworkServer 26 begins by requesting the certificate of the Transactionmoney module 4 from Session Manager A 31 (Steps 52-54). TheMaintain Security A application 37 retrieves and sends thecertificate to Session Manager A 31 (Step 56). Session ManagerA 31 sends the certificate to the Network Server 26 (Step 58),which, upon receipt, routes it to the Security Server 27 (Step60).
The Security Server 27 tests the certificate to checkits validity (Steps 62-64), and if it is not valid for anyreason, the Security Server 27 will signal the Network Server 26to deny access (Step 66). The Network Server 26 may in turnconvey an access-denied message to Session Manager A of theTransaction money module 4 (Steps 68-70).
If the Session Manager A that receives the deniedaccess message is a Transaction money module 4, its To Subscriberapplication A will inform the subscriber of this condition (Step74). If it is a Teller money module 5 or Money Generator Module6 that is trying to access the Network 25, the To Bank Aapplication 47 notifies the bank's systems 20 that its accesswill not be permitted (Step 76).
Assuming the certificate validity check is satisfied,the Security Server 27 sends an updated list of the bad money 70 modules, and a new list of certificatory keys to the SessionManager A, (Step 78, Fig. 33A). The keys are signed using thelast version of the certificatory key. This information isreceived by Session Manager A and forwarded to the MaintainSecurity A 37 application, which validates the certificatory keylist and the bad money module list (Steps 80-82, Fig. 33A).
Public Key A 44 tests the validity of the signature(Step 84) and if the signature is not valid, a message warning ofa network security problem is sent by the To Subscriber application A 33 of a Transaction money module 4 (Steps 86-90),or alternatively, by the To Bank application A 47 of a Tellermoney module 5 or Money Generator module 6, (Steps 86-88, &amp; 92).Advantageously, all money modules will check the validity of ajsignature received from even the Security Server 27. This helps’ to ensure the integrity of the overall system.
In the case of a valid signature, Maintain Security A i • updates the bad money module list and the certificatory key list. ' (Step 94). If the certificate is to be recertified or thecertificate has expired (Steps 96 and 98), the Maintain Securityj A generates a new certificate (Step 126 of Figure 33C) whilePublic Key A generates new keys and signs the certificate usingthe old public key (Step 128). Session Manager A sends the newί certificate to the Security Server 27 which accepts thecertificate and tests the validity of the signature (Steps 130- 136).
Assuming that the signature of the new certificate isnot valid at this stage, Steps 66-76, Fig. 33, are repeated so asto terminate the communication link into the Network 25.
On the other hand, a valid signature, Fig. 33C, willallow the Security Server 27 to sign the new certificate and sendit back to the money module (Step 138). Session Manager A 31receives the new certificate, Step 140, Fig. 33D, and forwards it 71 to its Maintain Security application A to again validate thecertificate through use of the Public Key application (Steps 142-146). Here, the money modules will repeat the test of thevalidity of the certificate issued from the Security Server 27.For a valid signature, the Session Manager A 31 sends anacknowledgment to the Security Server 27 (Step 148) who respondsby returning the process to Step 78, Fig. 33A.
Conversely, if the Security Server's signature on thenew certificate generated by Transaction money module A proves tobe invalid, Fig. 33D, Session Manager A will send an invalidcertificate message along with the certificate back to theSecurity Server 27 (Step 150), which will again attempt tovalidate the signature on the certificate (Step 152). A validsignature will return the process to Step 66, Fig. 33.
Alternatively, an invalid signature will cause the SecurityServer 27 to disconnect from the Network 25 (Step 156, Fig. 33D)and cause the Network Server 26 to notify the money module of amalfunction (Step 158).
The Session Manager A that receives the message (Step160) will, in the case of a Transaction money module 4, get theTo Subscriber A 33 to inquire of the subscriber if they desire toretry the whole process of signing on to the Network 25 (Steps164 &amp; 168). In the case of a Teller money module 5 or a MoneyGenerator Module 6, the To Bank application A will inquire ifthere is a request to retry the Network 25 sign-on procedure(Steps 166 &amp; 168).
No attempts for a retry will, of course, end thecommunication link into the Network 25, and conversely, a requestfor retry of Network 25 access will return the procedure back toStep 56, Fig. 33, wherein Maintain Security A will again retrievethe Transaction money module's certificate for the Network Server 26. 72
Back at Step 98, Fig. 33A if the certificate does notneed to be recertified or has not expired, Session Manager A 31will request the date and time (Step 100) from Clock/Timer A(Step 102, Fig. 33B), and forward this data to the Network Server26 (Step 104).
The Network Server 26 checks the time and date afterreceiving it (Step 106) and if it is outside of an acceptablepredetermined parameter, the Network Server 26 will send the newtime and date (Step 110) to Clock/Timer A through Session ManagerA (Steps 112 &amp; 114). If Clock/Timer A 43 cannot adjust the dateand time to be synchronized with the Network 25, the operator ofthe money module for the subscriber or the bank is notified ofthe clock malfunction (Steps 116-124).
In response to the apparent malfunction, the operatormay attempt to have the time and date resent from the NetworkServer 26, Step 124, and the procedure reverts back to Step 102in which it attempts to send the new date and time to the moneymodule. Alternatively, an acceptable date and time check, Step108 allows the Network Server 26 and Session Manager A toexchange acknowledgements and note the successful Network 25ΐ sign-on (Steps 126-128).
Establishing A Session
As shown in Figure 29, after the steps of money modulesign-on, transaction selection and network sign-on are completed,sessions are established between the money modules. Figure 34diagrams the flow process for establishing a money-module tomoney-module session, which, as will be understood by one skilledin the art, will in general be applicable as well to othersessions established between the various types of money modulesof the present invention.
Referring to the top of Figure 34, the Session Manager 73 A will first check to see if the subscriber has requestedconnection to a specific destination in the Network 25 (Step !190). For instance, where a subscriber is desirous oftransacting with his/her account at a specific bank, the Network25 will connect the Transaction money module 4 to the selectedbank, Steps 192-198. Conversely, when a subscriber is performingupdating functions on the Network 25, there is no need toestablish a session with any specific bank, and the NetworkServer 26 may decide where to route the connection, based onNetwork 25 traffic.
If a specific destination has been selected by thesubscriber, Session Manager A conveys the destination informationto the Network Server 26 (Step 194). The Network Server 26initiates a communication link to the money module of the
I selected destination (Step 196) and sends an acknowledgement toSession Manager A 31.
After receiving the acknowledgement that thedestination money module has been contacted (Step 198), the * Maintain Security application A will send its certificate to the
Maintain Security application B through each application's i
J respective Session Manager (Steps 200-206).
It is anticipated that the money modules will exchangecertificates to verify that each money module is interacting withanother valid money module. To this end (as seen in Fig. 34A),the Public Key application B 44 tests the certificate of moneymodule A by using the public key algorithm and the public keycorresponding to the private key used by money module A, toencrypt and check A's certificate and verify that it is valid(Step 208).
If the certificate is found invalid, the sessionManager B will note the session is terminated (Step 210). In thecase of a Transaction money module 4, the To Subscriber B informs - 74 -
I the subscriber of the transaction termination (Step 212).Likewise, a Teller money module 5 or Money Generator module 6,uses the To Bank application B 47 to notify the bank of thetermination, Step 213. It is anticipated that the counterpartymoney module will then timeout to end the exchange.
In Step 214, Fig. 34A, assuming that the certificate ofmoney module A is valid, the Maintain Security application B 37checks to see if money module A is on the list of compromisedmoney modules (Step 215). If money module A is on that list, theprocess flow returns to Step 210 so that the communications canbe terminated.
Alternatively, when money module A is not on the listof compromised money modules, the Random Number Generator B 46 ! creates a session key (Step 216) and encodes the session keyalong with money module B’s certificate and a verification jmessage, using money module A's public key (Step 218). Thisj encoded message is sent to money module A by Session Manager B 31 i • (Step 220).
I
Session Manager A 31 receives the message from moneymodule B (Step 222), and uses its Public Key 44 algorithmsapplication to decode the message (Step 224, Fig. 34B), and toverify money module B's certificate (Step 226).
If the test determines that money module B'scertificate is invalid, the operation branches to an "aborttransaction" procedure to terminate the steps taken thus far inestablishing a session (Steps 500-524). This procedure may beused, for example, to end the communication session and tofunctionally shut off money module A, which results in thecommunication link ending. (Steps 500-524, Figure 32).
Abort Transaction
Branching to Figure 32, the functional shut-off of a - 75 money module through the abort transaction process will now be described in detail. It will be understood that the following process may be used when any two money modules are abnormally terminating the transactions occurring between them.
Accordingly, the money modules will be designated "X" and "Y" toillustrate the generic applicability of the process steps.
An abort transaction process initiated by money moduleX to terminate communications with money module Y begins withSession Manager X 31 capturing and then reversing or rolling backany programmatic changes that were made to the money module (Step500), and then noting that the session has been aborted (Step502).
In the case where the money module that is initiatingthe termination is a Transaction money module 4, the ToSubscriber application 33 informs the subscriber of thecommunication termination (Step 510). Likewise, a Teller moneymodule 5 informs its To Bank application 47 of the termination sothat any accounting changes may be undone (Step 508). Next, theSession Manager X 31 of the terminating money module sends anencoded message to the other money module involved (Step 512).
Briefly referring to Figure 37, all encrypted messagesbetween modules will be exchanged by the following steps. Thesending money module (here also referred to as "X") uses itsSymmetric Key 45 to encode the message to be sent to thereceiving money module (here also referred to as "Y") (Step 2).Again, it will be appreciated that there are a number of knownencryption techniques which may be utilized.
The Session Manager X 31 sends the encoded message toSession Manger Y 31 which in turn decodes the message using itsSymmetric Key Y 45 (Steps 4-8).
Continuing with Figure 32, the Session Manger Yresponds to the termination notice sent by also undoing any 76 changes it may have made towards establishing the session, andnoting the aborted session (Steps 514-516). If it is aTransaction money module 4 that is now shutting down, the ToSubscriber application 33 alerts the subscriber of the condition(Steps 518 &amp; 524). Correspondingly, in a Teller money module 5,the To Bank application 47 will reverse all accountingtransactions that have been undertaken (Steps 518-522).
Returning to Figure 34B, assuming that the money moduleB certificate is valid, in Step 228 Maintain Security λ checks tosee if money module B is on the list of compromised moneymodules. If money module B is on the list (Step 230), thesession reverts to the abort transaction procedure, Steps 500-524. Thereafter, the communications session is dissolved.
More typically, money module B will not be on the listof compromised money modules, and the Clock/Timer A 43 willretrieve the date and time (Step 232) and send this informationto the Maintain Security application A 37 so that theverification message may be assembled with the date and time(Step 234).
Symmetric Key A 45 then encrypts the verificationmessage with the date and time information, using the randomsession key provided by money module B (Step 236). SessionManager A 31 sends this encrypted message (Step 238) to SessionManager B 31 (Step 240). From there, the Symmetric Keyapplication B 45 decrypts the message (Step 242) and passes it tothe Maintain Security B 37 for message verification (Step 244,Fig. 34C). An incorrect message will cause the session to beaborted through Steps 500-524, while a correct message willadvance the procedure so that Maintain Security B 37 can comparethe time and date with that of money module A (Step 248).
Clock/Timer B 43 will verify that money module A'sclock is within a preset amount of deviation from the clock of 77 - money module B (Step 250). If the discrepancy between the twoclocks is greater than a predetermined amount, the session willbe aborted by branching to Steps 500-524.
If there is no discrepancy that is greater than thepermissible amount, Session Manager B 31 will note its start of asession (Step 252), and send an acknowledgement to money module Ato start the transaction (Step 254). After the encoded messageis sent from money module B to Session Manager A 31 usingprocess steps 2-8, Fig. 37, Session Manager A 31 acknowledges themessage receipt and also notes the start of session (Steps 256-258) .
Request Withdrawal
After a session is established between the Transactionmoney module 4 and Teller money module 5, the Transaction moneymodule 4 makes a withdrawal request from the Teller money module5. See Figure 29. Referring now to Figure 30, a process forrequesting a withdrawal will now be described. It should benoted that although the figure denotes the parties as "X" and"Y," in the process steps describe below, they are applicable toany money module transacting with a Teller money module 5.
To begin, the To Teller X 34 sends a withdrawal requestto the Teller money module 5, requesting a certain amount ofmoney to be withdrawn from a specific account. In itstransmission of the withdrawal request, the account number andthe account profile will be transmitted from the requesting moneymodule to the Teller money module 5 (Step 700). To send thisrequest, the process Steps 2-8 are repeated, in which the messageis encrypted using the previously described cryptographictechniques. - 78 1
Validate Account Number 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32
Once the withdrawal request and the account number and ll : profile are transmitted to the Teller money module 5, a procedure
I to validate the account number is initiated (Steps 7041-7056). A,· flow diagram depicting how an account number is validated is .;shown in Figure 38. ί; II In this process, the Maintain Security application 37of the Teller money module 5 receives the account profile andsignature and conveys them to its Public Key application 44 toverify the profile signature (Steps 7041-7042). The signature is ii tested using the public key generated and distributed by the I!
Bank's Security Server 27. An invalid signature causes theMaintain Security 37 application to inform the Session Managerthat the account profile is invalid (Step 7044), whereby Steps500-524, Fig. 32, are followed to abort the transaction betweenthe two money modules.
If the signature test confirms a valid signature, theprocedure advances to the To Bank application 47 which sends theaccount number it has received to the bank's computer systems(Step 7046). An inactive account will cause the MaintainSecurity application 37 to inform the Session Manager of theinactive account (Step 7048) and have the transaction aborted . following steps 500-524; an account that has not been inactivatedpwill allow the Maintain Security application 37 to check if the 'account profile needs to be recertified (Steps 7047-7050). i.
If the account profile does need to be recertified, the
J pMaintain Security application 37 will send the account profile toμ the Security Server 27 (Fig. 38A, Steps 7051-7052), which will recertify the account profile and send it to the Teller moneymodule 5 (Step 7053). In response, the Teller money module 5sends it to the money module making the withdrawal request (Step7054). 79
The communication from the Teller money module 5 to themoney module utilizes the previously described routine forsending messages Steps 2-8. The Maintain Security application 37then updates the account profile in the money module and returnsan acknowledgement to the Maintain Security application 37 in theTeller money module 5 (Step 7055), also using Steps 2-8. Theelectronic message is received by the Maintain Securityapplication 37 of the Teller money module 5, and acknowledged inStep 7056.
With the account information checked, the processreturns to Step 704 of Figure 30. The To Bank application 47 nowverifies that there are sufficient funds to support the withdrawal request (Step 704). Sufficient funds will prompt thereturn of an acknowledgement to a Transaction money module 4,utilizing process Steps 2-8 to transmit the acknowledgement toits To Teller 34 application function (Steps 706-714). In thecase of a Teller money module 5, no acknowledgement is required.
In the case of a Transaction money module 4, aninsufficient amount of funds will cause the subscriber to beprompted to enter a new amount for the withdrawal (Steps 718-720,Figure 30A). As shown by Step 724, the newly entered amountcauses the To Teller application 34 to send the new request tothe To Bank application 47 (using Steps 2-8) of the Teller moneymodule 5 to verify if there are sufficient funds to cover thelatest requested amount, returning to Step 704 of Fig. 30. Ifthe new request is still greater than the funds on balance at thebank, the Teller money module 5 will initiate Steps 500-524 toabort the transaction between the to money modules. In the caseof a Teller Money Module 5, the transaction is allowed tooverdraw the account. 80
Transfer Notes
Referring back to Figure 29, To Teller A 34 transfersthe total of its currency notes 11 to the Teller money module 5(Step 45). If there are no notes 11 being held in theTransaction money module 4 at the time the withdrawal reguest ismade, the To Teller A application 34 sends a message to theTeller money module 5 that there are no notes 11 present (Step47), using process Steps 2-8.
Electronic notes 11 are transferred between moneymodules using the procedure described below (referring now toFigure 39). The Note Directory application 39 of the transferormoney module chooses the notes of proper values for the transfer(Step 750), and has the Notes application 40 create a transferfor each note 11 (Step 752). The Public Key application 44creates signatures for all the notes 11 (Step 754) and sends thenotes 11 to the Packet Manager application 41, for assembling thenote 11 transfers and signatures into a packet to be sent to therequesting money module (Step 756).
Steps 2-8 are utilized to transfer the packet of
I 1 electronic notes 11 to the Packet Manager application 41 of therequesting money module for receipt and disassembly (Step 758).The Verifier application 42 verifies the transfers appended toi the certificates, and verifies that the total amount conforms tothe notes 11 that should be sent (Step 760).
Any invalid information will cause the transactionbetween the two money modules to be aborted, using the procedureoutlined in steps 500-524 above (Step 761). Valid notes 11 willhave their expiration dates checked (Step 762) by the Verifierapplication 42 when it is a Transaction money modules 4 that hasconveyed the notes 11 (Step 763). Any expired notes 11 (Step t 764) will cause the sessions to be aborted using the proceduresoutlined in Steps 500-524, Fig. 32. - 81 -
Assuming the notes 11 have not expired, or in the casewhere a Teller money module 5 is accepting them, the process flowresumes at Step 765, Fig. 39A. In this Step, the Public Key Yapplication 44 verifies the digital signatures. Invalidsignatures invoke the transaction abort process of Steps 500-524.
Valid electronic notes 11 are then sent to the Notesapplication 40 (Step 768) and the Note Directory 39 is updatedwith the new note locations and amount (Step 770).
Returning to Figure 28, the To Transaction B 49 checksif any electronic notes 11 have been transferred (Step 772), andif notes 11 have indeed been transferred from a Transaction moneymodule 4, accounting transactions are posted to reflect thissituation (Step 776; see also Fig. 14, Step 1) by the To Bankapplication B 47. Both in the case when no notes 11 have been ί transferred from the money module and after the later accountingΐ transactions are posted in Step 776, a session is established i ! between the Teller money module 5 and the Money Generator module
I 6 using the procedure outlined above in Steps 190-258, Figs. 34,34A-C.
As notes ll are requested to satisfy the withdrawal, anaccount posting occurs to reflect the request. The To Bankapplication B 47 will post the proper accounting transactions(Step 778, Fig. 28) as also illustrated in Figure 14, Step 2.
Request Notes
Directing attention to Figure 40, notes 11 may berequested between Teller money modules 5 and Money Generatormodules C using the following procedure described below.
The To Money Generator application 48 of the requestingTeller money module 5 will issue a request for a specific amountof electronic money to be created (Step 780). The request willbe sent using the above described Steps 2-8 for encrypted 82 transmission, to the To Teller application 34 of the MoneyGenerator module 6 so that the Money Creator application 50 maybe activated (Step 784) to create the electronic notes 11 (Step786) .
After the creation of electronic notes 11, they aresigned by the Public Key application 44 of the Money Generatormodule 6 (Step 788) and placed in a holder by its Notesapplication 40 (Step 790). Finally, the Note Directory 3® isupdated with the information about the newly created electronicnotes 11 (Step 792).
The process flow now returns to the procedures shown inFigure 28. The requested notes in the Money Generator module 6are transferred to the Teller money module B 5 using processSteps 750-770 outlined above for transferring electronic notes11. The notes 11 are then transferred from the Teller moneymodule B 5 to the Transaction money module 4 using these sameprocess Steps 750-770 for transferring electronic notes 11.
Finally, to successfully complete the withdrawal ofelectronic notes 11, the money modules will "commit" to orfinalize the transaction by utilizing the following procedure.Referring now to Figure 41 for a detailed description of thisprocess, the Tran Log Mgr. application 36 updates its Tran Log torecord the transaction that has occurred above (Step 690). Whenit is a Transaction money module 4 that is committing to theexchange (Step 691), the To Subscriber application will notifythe subscriber that the transaction has been successfullycompleted (Step 692). Of course, the Session Manager applicationA 31 will note the end of session (Step 693), and employ processSteps 2-8 to send the message to the money module it istransacting with.
With this end of session notice received, the othermoney module, in this example a Teller money module 5, will use 83 its Tran Log Mgr. application 36 to update its own Tran Log (Step694). Assuming, however, the second money module receiving theend of session notice is not a Teller money module 5, anadditional step of having the To Subscriber application 33 notifythe subscriber of the end of the transaction occurrence (Step696) will be necessary. Thereafter, the Session Manager 31 ofthe second money module in both cases will also make note of theend of the session (Step 698).
Directing attention back to Figure 28, the process tocommit is initiated first by the Transaction money module 4committing its transaction with the Teller money module B 5(Steps 690-698). The process steps are also applied to committhe transaction between Teller money module B 5 and the MoneyGenerator module 6 (Steps 690-698). That completes theprocessing for one complete withdrawal of electronic money froman Issuing Bank 1.
Withdrawal From A Correspondent Bank A withdrawal from a Correspondent Bank 2 will now bedescribed, aided by reference to Figure 35. To begin, thepreviously described Steps 43-48 to set up a withdrawal areundertaken by a Transaction money module A 4, in conjunction witha Teller money module B 5. Next, Steps 190-258, used toestablish a session, also described above, are initiated betweenTeller money module B 5 and Teller money module C 5. After thesessions have been established, the To Bank application B 47 willpost the accounting transaction corresponding to the withdrawalthat is going to subsequently occur (Step 900; see also Fig. 13,Step 1).
As previously noted, it is contemplated that whenever aTransaction money module 4 interacts with a bank, both Issuing 1and Correspondent 2, all electronic notes 11 that are stored - 84 within the Transaction money module 4 are removed and replacedwith electronic notes 11 containing the most recent certificate.To perform this operation, To Transaction B 49 will check to seeif there are notes 11 stored within the money module 4 (Steps902-904). If there are notes 11, To Bank B 47 will post theappropriate accounting transactions (see accounting procedureillustrated in Figure 13; Step 2) (Step 906), and perform adeposit request from the Teller money module C 5 (associated withan Issuing Bank 1) to return the notes that need to be replaced.
For a detailed description for performing a depositrequest, attention will be directed to Figure 44. Here, the ToTeller application 34 sends a deposit request message, the amountof the deposit to be sent, the account number and the accountprofile of the account to which the notes 11 will be deposited(Step 920). This information is transferred to the Teller moneymodule 5 using Steps 2-8 for sending messages, and then Steps7041-7056 (see Figure 38) are performed to validate the accountprofile and number.
In the case where the depositor is a Transaction moneymodule 4, the To Transaction application 49 of the Teller moneymodule 5 will send an acknowledgement to the Transaction moneymodule 4 that the transfer of notes 11 is ready to proceed (Step924). Alternatively, if it is another Teller money module 5 thatis making the deposit, it is the To Teller application 34 thatissues the acknowledgement to the Teller money module 5 (Step926).
In either case, the acknowledgement is encrypted andtransmitted using the procedure outlined in Steps 2-8, whereby itis received by a To Teller application 34 of the depositing moneymodule (Step 928).
Referring back to Figure 35, once the deposit requestis completed, the notes 11 are transferred from the Teller money 85 module Β 5 to the Teller money module C 5 using Steps 750-770,Figs. 39, 39A detailed above for transferring notes.
Accordingly, To Bank C 47 posts the proper accountingtransactions (see Figure 13, Step 2) to reflect this transfer ofnotes 11 (Step 908). In Teller money module C 5, the To Tellerapplication 34 acknowledges the deposit by sending a message backto the To Teller B 34 application (Steps 910-912), using Steps 2-8. Naturally, the To Bank B 47 will now post accountingtransactions to reflect the withdrawal request it has made toTeller money module C 5 (Step 914; see also Fig. 13, Step 3).
After all electronic notes 11 have been removed fromthe Transaction money module 4 and the proper accounts have beenposted, a withdrawal is requested of a total amount that includesboth the amount originally requested to be withdrawn from thesubscriber's bank account and the amount that was removed fromthe Transaction money module 4 to be replaced with updatedelectronic notes 11.
The withdrawal request is performed between Tellermoney module B 5 and Teller money module C 5 using the processSteps 700-724, Figs. 30, 30A, described above. Teller moneymodule C 5 transacts with a Money Generator module 6 to withdrawnew electronic money and in doing so it establishes a sessionbetween the two modules using the process Steps 190-258, Figs. 34, 34A-C.
The electronic notes 11 are requested by the Tellermoney module C 5 from the Money Generator module 6 using processSteps 780-792, Fig. 40, and the notes 11 are transferred from theMoney Generator module 6 to the Teller money module C 5 using theSteps 750-770, Figs. 39, 39A.
The To Bank application C 47 performs the accountingpostings (Step 916; see also Fig. 13, Step 4). After this, theelectronic notes 11 are transferred from Teller money module C 5 86 to Teller money module B 5 using the Steps 750-770; the notes 11are than transferred to Transaction money module A 4 also usingSteps 750-770.
To finalize the withdrawal from the Correspondent Bank2, each money module must commit to the transaction it has justhad with the corresponding money module. Thus, Transaction moneymodule A 4 commits to Teller money module B 5 using Steps 690-698, Fig. 41, and thereafter Teller money module B 5 commits toTeller money module C 5. Finally, Teller money module C 5commits to the Money Generator module 6, using the same processSteps 690-698.
Deposit Τθ An Issuing Bank
Referring to Figure 42 in combination with Figure 43,an example of a deposit to an Issuing Bank 1 will now bedescribed in detail. To start the transaction, a deposit set upmust be done which uses the process steps shown in Figure 43.
In Step 398 at the top of Figure 43, the subscriberdecides to deposit some money to a bank. After performing thesign on routine for a Transaction money module 4 (following Steps10-42, Figs. 31-31A), the To Subscriber A 33 prompts thesubscriber for the transaction desired (Step 400).
In this example, the subscriber chooses the deposittransaction, the amount to be deposited, and the bank and accountnumber in which to deposit the electronic money (Step 402).
Before any other procedures, Note Directory A 39 checks to see ifthe money module contains funds sufficient to support the depositrequest (Step 404).
Assuming there are insufficient funds for the deposit,To Subscriber A 33 prompts the subscriber for a new amount (Step410) and if no new amount is selected, the Session Manager A 31informs the subscriber that the transaction must be terminated - 87 (Step 414). If the subscriber enters a new amount. Step 412, theprocess flow returns to Step 404, wherein the Note Directory 39application again checks for sufficient funds for the transaction.
Assuming there are adequate funds within the moneymodule, the process flow advances to the Network 25 sign onprocedures outline in Steps 50-168, Figs. 33-33A. A successfulNetwork 25 sign on then advances the process flow to Steps 190-258, for establishing a session between the Transaction moneymodule A 4 and Teller money module B 5.
Once the session is established between the two moneymodules, the deposit request steps outlined in procedures 920-928are followed conveying the request from Transaction money moduleA 4 to the Teller money module B 5. The To Teller A 34 transfersall of the electronic notes 11 stored within the money module tothe Teller money module B 5 (Step 408) using the Steps 750-770described above for transferring electronic notes 11 between twomoney modules.
Continuing with Figure 42, the To Bank B 47 posts theaccounting transactions for the notes deposited (Step 418, seeFig. 12 Step 1). In Teller money module B 5, the To Transactionapplication 49 checks to see if the amount deposited is less thanthe total notes 11 that were stored in module A and thentransferred to the Teller money module 5 (Step 420). If thedeposit is less than the total amount of transferred notes 11,updated notes 11 must be generated and sent back to theTransaction money module 4.
When all the notes that are contained in theTransaction money module 4 are deposited, i.e., the amount to bedeposited is not less than the total amount of electronic notes11, the To Transaction B 49 will send an acknowledgement to theTransaction money module 4 (Step 428) using the Steps 2-8 for 88 sending messages between money modules. The To Teller A 34receives the acknowledgement (Step 430) and initiates the Steps690-698 to commit the deposit transaction between the two money modules.
When the electronic notes 11 removed exceed the desireddeposit amount, new updated notes 11 must be returned to theTransaction money module 4. To perform this, the To Bankapplication B 47 of the Teller money module B 5 posts the properaccounting transactions (Step 424; Fig. 12, Step 2). Thereafter,Teller money module B 5 establishes a session with the MoneyGenerator module 6 using process Steps 190-258, and requestselectronic notes 11 from the Money Generator module 6 in theamount that should be returned to the Transaction money module 4,by performing Steps 780-792.
The electronic notes 11 are created by the MoneyGenerator module 6 and transferred to the Teller money module B 5using Steps 750-770. With the electronic notes 11 in thepossession of the Teller money module B 5, they are transferredto the Transaction money module A 4 using Steps 750-770.
After Transaction money module A 4 receives theelectronic notes 11, it must finalize the transaction bycommitting Teller money module B 5 to Transaction money module A4 using Steps 690-698. Likewise, Teller money module B 5 mustcommit to the Money Generator module 6 using the same Steps 690- 698.
Deposit To A Correspondent Bank
Figure 45 illustrates the process flow for a deposit ata Correspondent Bank. In depositing to a Correspondent Bank 2,the deposit set up described in Steps 398 through 414 arerepeated in the first stage of the transaction. From there theTo Transaction B 49 tests to see if the deposit is less than the 89 -total amount of electronic notes 11 that have been withdrawn inthe deposit set up procedures that were just processed (Step440).
In the case where all the electronic notes 11 stored inthe Transaction money module 4 are equal to the amount of notes11 to be deposited, then To Transaction B 49 sends a depositacknowledgement back to the Transaction money module 4 (Step444), using steps 2-8 to send the message from the Teller moneymodule B 5 to Transaction money module A 4.
On the Transaction money module 4 side, the To Teller34 application receives the acknowledgement (Step 446) and usesSteps 690-698 to commit the transaction with Teller money moduleB 5. The Transaction money module 4 is now finished and removedfrom the process. The finalization of the deposit provides forthe account posting transactions to be made by the To Bankapplication 47 (Step 448). See Figure 11, step 1 for theaccounting transactions. A session is now established between Teller moneymodule B 5 and Teller money module C 5 using Steps 190-258.
Teller money module B 5 issues a request to make adeposit, to the Teller money module C 5 by using process Steps780-792. The To Bank B 47 then posts the accounting transactions(Step 450; see also Fig. 11, Step 2).
Notes 11 are now transferred from the CorrespondentBank B 2 to the Issuing Bank C 1 using Steps 750-770; the IssuingBank C 1 posts the corresponding accounting transactions (Step452; see also Fig. 11, Step 2). The To Teller C 34 responds bysending the deposit acknowledgement (Step 454) using Steps 2-8,to To Teller application 34 of Teller money module B 5 (Fig. 45A,Step 456).
Here again, the deposit is checked to see if it is lessthan the amount of electronic notes 11 that have been removed - 90
I earlier, and when it is not, the withdrawal is completed with theprocess Steps 690-698, Fig. 41, to commit Teller money module B 5to Teller money module C 5. A deposit request that is less than the amount of notes11 that are withdrawn requires account updating (Step 460; seealso Fig. 11, Step 3), and new notes 11 to replace the additionalnotes 11 that were taken. Accordingly, a withdrawal requestfollowing the process Steps of 920-928 from Teller money module B5 to Teller money module C 5 is made to provide these newelectronic notes 11.
Teller money module C 5 must first establish a sessionwith the Money Generator module 6, using the process Steps 190-258. The new electronic notes 11 are requested by the Tellermoney module C 5 from the Money Generator module 6 followingprocess Steps 780-792, which are then transferred to the Tellermoney module C 5 using Steps 750-770 to transfer notes 11 betweenmoney modules.
This transfer of electronic notes 11 to the Tellermoney module C 5 requires that accounting transactions be postedby the To Bank application C 47 (Step 462, Fig. 45B; see alsoFig. 11, Step 3).
From there, the notes 11 are transferred from theIssuing Bank's 1 Teller money module C 5 to the CorrespondentBank's 2 Teller money module B 5 and to the Transaction moneymodule 4 by using Steps 750-770 for transferring notes 11.Thereafter, each money module must commit to the money modulewith which it has established a session. Thus, Transaction moneymodule A 4 commits to Teller money module B 5, Teller moneymodule B 5 subsequently commits to Teller money module C 5, whichthen commits to the Money Generator module 6. All three of thesecommitment transactions use process Steps 690-698, describedabove. 91
Subscriber To Subscriber Payment
Figure 36 illustrates the process flow for a paymenttransaction from one Transaction money module 4 to another and inthis example of a preferred embodiment, Alice (or a hypotheticalpayor corporation, is denoted "A" in Figure 36) will agree to payBob (or a hypothetical payee corporation, is denoted "B" inFigure 36) a specific amount of electronic money (Step 800).
Both Alice and Bob sign on to their respective Transaction moneymodules 4 using the process Steps 10-42 described above. Throughthe To Subscriber A 33 application, Alice directs her Transactionmoney module 4 to make a payment (Steps 806 &amp; 810), while Boboperates his Transaction money module 4 such that the To ' Subscriber B 33 application will issue an entitlement to receivepayment (Steps 808 &amp; 812).
In Steps 814 &amp; 816, the Session Managers 31 of bothAlice's Transaction money module 4 and Bob's Transaction moneymodule 4 establish communications. From there, a session is
I established, as described in Steps 190-258 above for transactingbetween any two money modules.
With a session established, To Subscriber A 33 promptsthe subscriber to enter the amount of payment that she desires to ; transfer (Step 818), which is displayed to the subscriber.
Alice enters the amount that she wishes to transfer toBob. Pay/Exchange application A 35 receives the amount entered(Fig. 36, Step 820). The amount entered by type (currency orcredit) is now compared by Note Directory A 39 to the balance ofthe value of the electronic money stored in the Transaction moneymodule 4, to see if there are sufficient funds available topermit the transaction to proceed (Step 822).
If there are insufficient funds, To Subscriber A 33sends the subscriber a notice that there are not sufficient fundsto cover the transaction desired (Steps 824-826), and prompts the - 92 subscriber again for a new amount of payment (Step 827). If thesubscriber prefers not to enter a new amount, the aborttransaction process Steps 500-524 are activated to terminate thecommunications link between the two Transaction money modules 4.On the other hand, a newly entered amount will return the processto Step 820, to check for sufficient funds again.
When there are sufficient funds stored in Transactionmoney module λ 4 to process the transfer, Pay/Exchange A 35 sendsa message disclosing the amount of the transfer to Bob'sTransaction money module 4 (Step 828), using the processdisclosed in Steps 2-8. See Fig. 36A. From there, To SubscriberB 33 prompts the owner to verify that the amount to be transferred will be accepted by him (Step 830). Bob can thendecide whether to accept or reject the amount to be transferred(Step 832).
I
I j If Bob responds in the negative, then Pay/Exchange B 35 J will send a message back to Transaction money module A 4 using
Steps 2-8, that the amount to be transferred is incorrect (Step834); the process again returns to Step 826, Fig. 36, to promptAlice for a new amount to be entered.
When Bob responds in the affirmative in Step 832, Pay/ I Exchange B 35 will send an acknowledgement to Transaction money ί module A 4 using Steps 2-8 (Step 835). Back in Transaction money i module A 4, the message will be conveyed to Pay/Exchange A 35 toreceive the acknowledgment sent by Transaction money module B 4(Step 836).
With this acknowledgement received, Pay/Exchange A 35will send the amount desired to be transferred to the MoneyHolder 38 (Step 838) so that the electronic notes 11 may betransferred using Steps 750-770. With the transfer completed,the two Transaction money modules 4 must commit to the transferusing Step 690-698 described above. The communication link 93 between the two transaction modules may now be terminated.
Subscriber to Subscriber Foreign Exchange
Referring to Figure 46, the process flow for anexchange of foreign currencies between two Transaction moneymodules 4 will now be illustrated. In this example Alice (or ahypothetical corporation, denoted "A" in Figures 46-46A) agreesto exchange dollars for pounds with Bob (or a hypotheticalcorporation, denoted "B" in Figures 46-46A). The exchange ratethat they have agreed to will be a ratio of dollars to pounds(Step 300).
Alice begins by signing on to her Transaction moneymodule 4 (using Steps 10-42 described above) while Bob signs onto his Transaction money module 4 (using Steps 10-42).
Thereafter, the To Subscriber 33 applications of both Transactionmoney modules 4 prompt the respective users to select a type oftransaction (Steps 302-303). In this example, Alice and Bobagree to exchange her dollars for his pounds.
By requesting the foreign exchange transaction, SessionManager A 31 will establish a communications link with SessionManager B 31 (Steps 306, 307) so that a session may beestablished between the two money modules using Steps 190-258.Alice is then prompted by To Subscriber A 33 for the amount ofdollars she will sell, and the exchange rate that she will use inthe transaction (Step 308).
Pay/Exchange A 35 receives the input (Step 310) andNote Directory A 39 checks for sufficient funds by comparing theamount requested to the amount of value contained in theTransaction money module 4 (Step 312). An insufficient fundscondition will cause the To Subscriber A 33 to send an insufficient funds message to Alice and prompt the subscriber toselect another amount of dollars and exchange rate (Steps 318- - 94 - 320). When new selections are entered, the process flow returnsto Step 312 and continues from there. If Alice does not select anew amount, the session is dissolved using abort transactionSteps 500-524.
When the funds are sufficient to meet the amountrequested, the Pay/Exchange A 35 sends the amount of the dollarsand the proposed dollar/pound exchange rate (Step 316) to the ToSubscriber application 33 of Transaction money module B 4 usingthe Steps 2-8 (se^e Figure 46A). At this point, To Subscriber B33 prompts Bob with the amount and rate proposed by Alice, todetermine if the values are what Bob will agree to exchange (Step322).
The Pay/Exchange B 35 receives the dollar amount andthe rate that is proposed by Alice and if the amount and rate are: not agreed to by Bob, Pay/Exchange B 35 will send a messageindicating that the value or exchange rate is incorrect (Step326), through the Steps of 2-8 for sending messages. To jSubscriber A 33 prompts Alice for the dollar amount and exchange | rate over again (Step 327). Entry of new values returns the i process to Step 310 for continuation, see Fig. 46, while the lackof new values entered causes the abort transaction process ofSteps 500-524 to be initiated.
If the amount and rate are agreed to by Bob,Pay/Exchange B 35 will calculate the equivalent amount in pounds,based on the rate provided (not shown), and then initiate thestep of having Note Directory B 39 check to see that Transactionmoney module B 4 contains sufficient funds to fulfill theexchange (Step 323). When the funds in Transaction money moduleB 4 are insufficient to meet the exchange, Pay/Exchange B 35sends a message to Alice of insufficient funds (Step 325) usingSteps 2-8. The process flow returns to Step 327.
Proceeding with the case in which sufficient funds do 95 exist in Transaction money module B 4, Pay/Exchange B 35 willsend an acknowledgement using Steps 2-8 to Transaction moneymodule λ 4 (Step 329). After receiving this acknowledgement,Pay/Exchange A 35 sends the amount of dollars requested to itscorresponding Money Holder 38 application in Step 330. Thedollars are transferred from Alice to Bob via the Steps 750-770described above for transferring notes 11.
Pay/Exchange B 35 receives the notes 11 and thentransfers the amount of pounds to its Money Holder 38 application(Step 331). From there, the electronic pounds are transferred toAlice using the transfer notes process described in Steps 750-770. To record this exchange, Transaction money module A 4commits with Transaction money nodule B 4 by using process Steps690-698 described above. With a satisfactory exchange, thecommunications link between the two transaction money modules maynow be terminated.
Foreign Exchange
At An Issuing Bank
Turning attention now to Figure 48, if a subscriberwere to exchange his/her dollars for pounds with an Issuing Bank1 instead of with a subscriber, the following process isfollowed.
Subscriber A sets up the foreign exchange transactionby signing on to his/her Transaction money module 4 (referringnow to Fig. 47) using Steps 10-42 described above. To SubscriberA 33 prompts the subscriber for the transaction desired (Step334), and in this example, the subscriber chooses thedollar/pound exchange, and the amount of dollars the subscriberwill exchange. It is anticipated that the choice of the bank totransact with may be an option offered to the subscriber (Step336).
The Note Directory A 39 checks for a sufficient balance 96 to complete the request (Step 338). An Insufficient balancepermits the subscriber to again enter the amount he/she willexchange (Steps 340-342), whereby Session Manager A 31 willterminate the transaction (Step 345) if no new amount is entered.Entry of a new amount returns the process to Step 338 to checkfor sufficient funds to meet the new request. When the funds aresufficient for the exchange request, a Network 25 sign-on usingSteps 50-168 is commenced.
After the Network 25 sign-on, the Network 25 checks ifa bank or financial institution has been selected (Step 346). Ifa bank or financial institution was not chosen earlier, To TellerA 34 must prompt the Network Server 26, through Session Manager A31, for a list of banks or financial institutions that willprovide the exchange (Steps 348-350). The Network Server 26sends the list (along with rates) to the subscriber through theTo Teller A 34 and the To Subscriber A 33 applications (Steps352-356).
After the prompting (Steps 357, Fig. 47A), thesubscriber chooses a bank or financial institution, or ends thetransaction (Step 359). When a bank or financial institution ischosen, a session is established with the Teller money module 5 : chosen using Steps 190-258 described above. After a session isestablished, To Teller A 34 sends the amount of dollars to beexchanged for pounds (Step 360) using Steps 2-8 for encryptingand transmitting a message.
To ensure that the subscriber still wants to proceedwith the exchange, To Transaction B 49 sends the current exchangerate to the subscriber using process Steps 2-8 (Step 362). Atthis point, To Subscriber A 33 prompts the subscriber with thebank's exchange rate and if the subscriber does not wish toproceed, the transaction is aborted by following Steps 500-524(Steps 364-366). If the transaction is to proceed, the dollars 97 are transferred from Transaction money module A 4 to Teller moneymodule B 5 using Steps 750-770 described herein.
Returning to Figure 48, once the set up of the foreignexchange transaction is accomplished, the proper accountingtransactions are posted (Step 368; also illustrated in Figure 15,Step 1) to reflect the dollars that have just been transferred. A session is established between Teller money module B 5 and aMoney Generator module 6 via Steps 190-258. Teller money moduleB 5 requests the proper pound notes 11 through process Steps 780-792. The notes 11 are returned from the Money Generator module 6to the Teller money module B 5 using Steps 750-770.
This latter transfer of notes 11 requires acorresponding updating of the accounts involved (Step 370; seealso Fig. 15, Step 2). The notes 11 are transferred to theTransaction money module A 4 through process Steps 750-770. Tocomplete the exchange, Transaction money module A 4 commits toTeller money module B 5 who subsequently commits to the MoneyGenerator module 6 using process Steps 690-698.
Foreign Exchange At A Correspondent Bank
The foreign exchange with a Correspondent Bank 2 isdescribed with the aid of Figure 49. Initially, the foreignexchange transaction is set up by repeating process Steps 334-366, (Figs. 47-47A) and updating the proper accounts (see Figure16, Steps 1-2) to reflect the notes 11 that have just beentransferred from the subscriber's money module 4 to Teller moneymodule B 5 (Step 372). Thereafter, Teller money module B 5 willestablish a session with Teller money module C 5 at an IssuingBank 1, by performing process Steps 190-258. A withdrawal is requested by Teller money module B 5 toTeller money module C 5 using process Steps 920-928 describedabove. To obtain the notes 11 for the request, Teller money 98 module C 5 must get them from a Money Generator module ¢.Accordingly, a session is established between the two moneymodules via Steps 190-258, and the notes 11 are requestedfollowing process Steps 780-792 outlined above.
The Money Generator module C will create the notes 11requested and transfer them to Teller money module C 5 usingprocess Steps 750-770. This is followed by a posting to theproper accounts in the bank C's systems (Step 374, see Figure 16,Step 3 for accounting transactions). The notes 11 are nowtransferred from Teller money module C to Transaction moneymodule A 4 via Teller money module B 5 using for each transferthe process Steps 750-770. Finally, all the sessions must becommitted, and Transaction money module A 4 commits to Tellermoney module B 5 who in turn commits to Teller money module C 5using Steps( 690-698. Teller money module C 5 commits to theMoney Generator module 6 to complete the exchange of dollars forpounds.
Updating Notes, Certificate
As mentioned above, it is anticipated that the date ofexpiration of a note, used as a security measure, may expirewhile it is stored in a Transaction money module 4. If thisoccurs, the holder of expired notes 11 will not be able totransfer them to another Transaction money module 4, but theholder may deposit them or exchange them for new notes 11 bytransacting with a participating bank or financial institution.
Additionally, if the certificate associated with aparticular Transaction money module 4 expires, the subscribermust sign on the Network 25 to update the certificate in order totransact with another money module 4. The following is adescription of the process flow for updating an expiredcertificate or expired notes 11. 99
Beginning at the top of Figure 50, a subscriber signson to the Transaction money module 4 using the Steps 10-42described above, and is prompted by To Subscriber λ 33 to selecta transaction (Step 570). After selecting the transaction for"updating" (Step 572), a sign-on to the Network 25 is performedusing Steps 50-168. The sign-on to the Network 25 will performthe updating of the certificate, as described above withreference to Figure 33-33A.
For updating the notes 11, the Session Manager A 31sends the update notes request to the Network 25 (Step 574); TheNetwork Server 26 responds by sending the selected bankidentifier back to the Transaction money module 4 (Step 576).
Now, a session may be established between the Transaction moneymodule A 4 and a Teller money module B 5 of the bank selected,using Steps 190-258.
Once the session is established, To Teller A 34 sendsthe request to update notes 11 (Step 578) using the messagesending routine in Steps 2-8. To Transactor B 32 responds, Fig.50A, with an acknowledgement (Step 580) sent using Steps 2-8.Transaction money module A 4 can now transfer the expired notes11 to Teller money module B 5 using Steps 750-770. Thereafter,the corresponding accounting (see Figure 24, Step 1) is performedin the bank's records (Step 582), and a session is establishedbetween Teller money module B 5 and the Money Generator module 6through Steps 190-258.
The request notes routine of Steps 780-792 is thenperformed. The Money Generator module 6 sends the requestednotes 11 via Steps 750-770, and updates the accounts at the bank(Step 584; see also Fig. 24, Step 2). Teller money module B 5takes the updated notes 11 and passes them to Transaction moneymodule A 4 using the same Steps 750-770.
Now that the notes 11 have been updated in the - 100 -
Transaction money module 4, the sessions are completed by havingTransaction money module A 4 commit to Teller money module B 5,and having Teller money module B 5 then commit the transactionwith the Money Generator module. Finally, both committingroutines are performed using Steps 690-698 described above.
The above described process flows illustrate thecapability of the invention to provide an improved system forexchanging electronic representations of economic value, whileavoiding the inherent limitations of paper based monetarysystems.
• I
Operation of the invention has been described primarilywith currency notes and credit notes that can be used bysubscribers in the same processes. It will be understood thatthe described system can also be adapted to other monetaryinstruments. For example, personal and corporate checks and bank 1 drafts could be provided by enhancing several of the Transactorapplications. More complicated multiparty payment processes suchas letters of credit and banker's acceptances could also beprovided with appropriate changes to the system. It may also bepossible to adapt the system of the invention to providecorporate financial obligations such as commercial paper.
Moreover, although the invention has been described indetail with particular reference to a preferred embodimentthereof, it should be understood that the invention is capable ofother and different embodiments, and its details are capable ofmodifications in various obvious respects. As is readilyapparent to those skilled in the art, variations andmodifications can be affected while remaining within the spiritand scope of the invention. Accordingly, the foregoingdisclosure, description, and figures are for illustrativepurposes only, and do not in any way limit the invention, whichis defined only by the claims. 101
Contents8
201 members in 31 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 79411291 | United States of America | A | |
| 10339795 | Israel | A |
Members201
| Document | Office | Kind | |
|---|---|---|---|
| UY23501A1 | Uruguay | A1 | |
| IL103397A0 | Israel | A0 | |
| IL103397D0 | Israel | D0 | |
| ZA928773B | South Africa | B | |
| CA2080452A1 | Canada | A1 | |
| BR9204413A | Brazil | A | |
| EP0542298A2 | European Patent Office (EPO) | A2 | |
| WO9310503A1 | World Intellectual Property Organization (WIPO) | A1 | |
| MX9205890A | Mexico | A | |
| AU2739292A | Australia | A | |
| CN1073789A | China | A | |
| FI933208A | Finland | A | |
| FI933208A0 | Finland | A0 | |
| FI933208A7 | Finland | A7 | |
| NO932577D0 | Norway | D0 | |
| NO932577L | Norway | L | |
| HU9302008D0 | Hungary | D0 | |
| GR930300107T1 | Greece | T1 | |
| DE542298T1 | Germany | T1 | |
| ES2046156T1 | Spain | T1 | |
| PL300041A1 | Poland | A1 | |
| HUT65212A | Hungary | A | |
| TW224172B | Taiwan Province of China | B | |
| JPH06162059A | Japan | A | |
| EP0542298A3 | European Patent Office (EPO) | A3 | |
| AU658233B2 | Australia | B2 | |
| AU2013695A | Australia | A | |
| AU2013795A | Australia | A | |
| AU2013895A | Australia | A | |
| AU2013995A | Australia | A | |
| US5453601A | United States of America | A | |
| US5455407A | United States of America | A | |
| CA2184380A1 | Canada | A1 | |
| CA2287130A1 | Canada | A1 | |
| CA2287133A1 | Canada | A1 | |
| CA2287136A1 | Canada | A1 | |
| WO9530211A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2105895A | Australia | A | |
| JPH07111723B2 | Japan | B2 | |
| IL116370A0 | Israel | A0 | |
| IL116370D0 | Israel | D0 | |
| IL116371A0 | Israel | A0 | |
| IL116371D0 | Israel | D0 | |
| IL103397A | Israel | A | |
| US5557518A | United States of America | A | |
| FI964032A | Finland | A | |
| FI964032A0 | Finland | A0 | |
| FI964032A7 | Finland | A7 | |
| CA2218612A1 | Canada | A1 | |
| WO9633476A2 | World Intellectual Property Organization (WIPO) | A2 | |
| NO964538D0 | Norway | D0 | |
| NZ244903A | New Zealand | A | |
| NZ286668A | New Zealand | A | |
| NZ286669A | New Zealand | A | |
| NZ286670A | New Zealand | A | |
| NZ286671A | New Zealand | A | |
| AU673304B2 | Australia | B2 | |
| AU673305B2 | Australia | B2 | |
| AU5561596A | Australia | A | |
| HU9602478D0 | Hungary | D0 | |
| NO964538L | Norway | L | |
| WO9633476A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0758474A1 | European Patent Office (EPO) | A1 | |
| PL317026A1 | Poland | A1 | |
| SK68593A3 | Slovakia | A3 | |
| US5621797A | United States of America | A | |
| CN1147875A | China | A | |
| KR970702540A | Republic of Korea | A | |
| US5642419A | United States of America | A | |
| AU679359B2 | Australia | B2 | |
| AU679360B2 | Australia | B2 | |
| SI9520039A | Slovenia | A | |
| EP0784282A2 | European Patent Office (EPO) | A2 | |
| EP0785515A2 | European Patent Office (EPO) | A2 | |
| EP0785516A2 | European Patent Office (EPO) | A2 | |
| EP0785517A2 | European Patent Office (EPO) | A2 | |
| EP0785518A2 | European Patent Office (EPO) | A2 | |
| PL172072B1 | Poland | B1 | |
| EP0788066A2 | European Patent Office (EPO) | A2 | |
| BR9507107A | Brazil | A | |
| JPH09245108A | Japan | A | |
| HUT76463A | Hungary | A | |
| SK117696A3 | Slovakia | A3 | |
| CZ251396A3 | Czechia | A3 | |
| NO974835D0 | Norway | D0 | |
| HU213819B | Hungary | B | |
| EP0803827A2 | European Patent Office (EPO) | A2 | |
| MY109965A | Malaysia | A | |
| JPH09511350A | Japan | A | |
| CA2080452C | Canada | C | |
| NO974835L | Norway | L | |
| US5703949A | United States of America | A | |
| MX9605174A | Mexico | A | |
| IL116371AThis record | Israel | A | |
| EP0823105A2 | European Patent Office (EPO) | A2 | |
| NZ283103A | New Zealand | A | |
| PL323007A1 | Poland | A1 | |
| NZ329065A | New Zealand | A | |
| NZ329066A | New Zealand | A | |
| NZ329067A | New Zealand | A |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent expiredExpiredEXP | EXP | |
| Patent renewedKB | KB | |
| Patent grantedGrantedFF | FF |
Numbers
- Application
- 11637192
Titles
- English
- ELECTRONIC MONETARY SYSTEM
Classification
- CPC, 20
- G07F7/1008
- G06Q20/02
- G06Q20/04
- G06Q20/06
- G06Q20/10
- G06Q20/108
- G06Q20/1085
- G06Q20/26
- G06Q20/29
- G06Q20/341
- G06Q20/367
- G06Q20/3674
- G06Q20/3676
- G06Q20/3678
- G06Q20/381
- G06Q20/40
- G06Q40/00
- G06Q40/02
- G07F7/082
- G07F19/211
- IPC, 14
- G06F19 00
- G06F21 00
- G07F19 00
- G06G7 52
- G06K19 07
- G06Q20 36
- G06Q20 40
- G06Q40 02
- G06Q40 04
- G07F
- G07F7 08
- G07F7 10
- G07G1 12
- H04L9 32