Virtual keyboard
Abstract
A virtual keyboard for typing the safety password, comprising the steps of displaying a multiple key keyboard; generating and assigning a predetermined number of characters to each one of the keys, such that the user selects a key which is associated with one of the predetermined number of characters; and displaying the predetermined number of characters in relative proximity to each one of the keys.

Term
Term ended
Projected expiry passed 20 February 2024, 2.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 8 independent, 1 dependent
- 1CLAIMS REIVINDICAÇÕES 1. A method for providing access to electronic services through a secure access code, comprising the following steps:(i) providing a keyboard (100, 200, 1. Método para providenciar acesso a serviços electrónicos através de um código de acesso seguro, compreendendo os seguintes passos: (i) providenciar um teclado (100, 200, 300, 400, 500) compreendendo um predeterminado número de teclas, as quais são utilizadas para introduzir um código de acesso seguro, sendo o método caracterizado por compreender adicionalmente os seguintes passos: 300, 400, 500) comprising a predetermined number of keys which are used to enter a secure access code, the method further comprising the following steps: (ii) assigning at least two variables to each individual key, wherein the value of one or more of said variables may vary from one access to the other;(ii) associar, pelo menos, duas variáveis a cada tecla individual, em que o valor de uma ou mais das referidas variáveis pode variar de um acesso para o outro;(iii) mostrar as variáveis ao utilizador;(iii) show the variables to the user;(iv) seleccionar, pelo utilizador, cada tecla, que corresponde a cada variável do seu código de acesso;(iv) selecting by the user each key corresponding to each variable of his access code;(v) comparar os valores associados a cada tecla seleccionada com um código armazenado numa base de dados;e (vi) permitir ao utilizador aceder aos serviços electrónicos, se os valores associados às teclas, seleccionadas pelo utilizador de um modo sequencial, coincidirem com o código de acesso armazenado. (v) comparing the values associated with each selected key with a code stored in a database;and (vi) permitting the user to access electronic services if the key-associated values selected by the user in a sequential manner match the stored access code.
- 57 The method of any of claims 5 or 6, characterized in that the virtual keyboard is comprised of five keys (105, 110, 115, 120, 125;205, 210, 215, 220, 225;305, 310, 315, 320, 325;405, 410, 415, 420, 425). 7. Método de qualquer das reivindicações 5 ou 6, caracterizado por o teclado virtual ser composto por cinco teclas (105, 110, 115, 120, 125;205, 210, 215, 220, 225;305, 310, 315, 320, 325;405, 410, 415, 420, 425).
- 68 Method of any one of claims 1 to 7, characterized in that the user is notified when the selected keys and the access code do not match. 8. Método de qualquer das reivindicações de 1 a 7, caracterizado por o utilizador ser notificado quando as teclas seleccionadas e o código de acesso não coincidirem.
- 79. 9. Method of any characterized by the bankers. Método de qualquer caracterizado por os bancárias. claims 1 to 8, are functions das reivindicações serviços electrónicos de 1 a 8, serem funções Method of any characterized by alphanumeric. Método de qualquer caracterizado por alfanuméricos. das as reivindicações de variáveis serem since the variable claims are 1 to 9 characters 1 a 9, caracteres Method of characterized in any of the claims that the variables are numbers of Método de caracterizado qualquer das reivindicações por as variáveis serem números de 1 at 9, 1 a 9, Método de qualquer das reivindicações de 1 caracterizado por as variáveis serem letras. The method of any of claims 1, characterized in that the variables are letters. a 9, at 9, Method of any characterized by the letters and numbers. Método de qualquer caracterizado por as letras e números. das reivindicações variáveis serem uma de 1 a 9, combinação de of the variable claims being one from 1 to 9, combination of
- 814 Method of any of the claims, characterized in that the variables are symbols of 14. Método de qualquer das reivindicações caracterizado por as variáveis serem símbolos de 9, 9,
- 915 Method of any one of claims 1 to 14, characterized in that a group of variables is selected and shown to each user. 15. Método de qualquer das reivindicações de 1 a 14, caracterizado por um grupo de variáveis ser seleccionado e mostrado para cada utilizador. Method of claim variables be generated by Método da reivindicação variáveis ser gerado por 15, caracterizado por o grupo uma sequência predeterminada. 15, characterized in that the group is a predetermined sequence. de in Method of the variable sequence claim 15, characterized in that it is associated with the random value combination keys by the group agreement with a Método da variáveis sequência reivindicação 15, caracterizado ser associado com as teclas de aleatória de combinação de valores por o acordo grupo de com uma caracterizado por compreender ainda o passo de introdução de um cartão disponibilizado por um banco num terminal para executar uma transacção (605). characterized in that it further comprises the step of introducing a card provided by a bank into a terminal for executing a transaction (605). 21 The method of any one of claims 1 to 20, further comprising the step of requesting the user's access code (620). 21. Método de qualquer das reivindicações de 1 a 20, caracterizado por compreender ainda o passo de solicitar o código (620) de acesso do utilizador. 22 The method of claim 20, further comprising the following steps:22. Método da reivindicação 20, caracterizado por compreender ainda os seguintes passos: transmitir a informação do cartão para um servidor (610) ;transmitting the card information to a server (610);verificar a autenticidade do cartão emitido pelo banco;verify the authenticity of the card issued by the bank;and determining which keyboard to display to the user (615). e determinar qual o teclado a mostrar ao utilizador (615). 23 The method of any of claims 1 to 22, further comprising the following steps: 23. Método de qualquer das reivindicações de 1 a 22, caracterizado por compreender ainda os seguintes passos: iv.a) encriptar os dados do código de acesso do utilizador;e iv.b) transmitir os dados para um servidor (630) . iv.a) encrypting the data of the user's access code;and iv.b) transmitting the data to a server (630). 24 Keypad (100, 200, 300, 400, 500) for providing access to electronic services via a secure access code, comprising: 24. Teclado (100, 200, 300, 400, 500) para providenciar acesso aos serviços electrónicos através de um código de acesso seguro, compreendendo: a predetermined number of keys for entering a um número de teclas predeterminado para introdução de um At least two variables are associated with each key and are shown to the user, where the user selects sequentially the keys corresponding to all the variables of his access code, the variables being able to switch from one access to another. where the values associated with each selected key are compared to a code stored in a database and the user's access to electronic services is allowed if the values associated with those keys, sequentially selected by the user match the stored access code. menos, duas variáveis estarem associadas a cada tecla e serem mostradas ao utilizador, em que o utilizador selecciona, de um modo sequencial, as teclas correspondentes a todas as variáveis do seu código de acesso, sendo as variáveis capazes de mudar de um acesso para outro, em que os valores associados com cada tecla seleccionada são comparados com um código armazenado numa base de dados e é permitido o acesso do utilizador aos serviços electrónicos se os valores associados àsas teclas, seleccionadas pelo utilizador de um modo sequencial, coincidirem com o código de acesso armazenado. 25 Keypad of claim 24, characterized in that the variables may change over a predetermined period of time. 25. Teclado da reivindicação 24, caracterizado por as variáveis poderem mudar ao fim de um período de tempo predeterminado. 26 Keyboard of any one of claims 24 to 25, characterized in that the keyboard is a virtual keyboard. 26. Teclado de qualquer das reivindicações de 24 a 25, caracterizado por o teclado ser um teclado virtual. 27 Keyboard of claim 26, characterized in that the virtual keyboard is viewed through a graphical user interface. 27. Teclado da reivindicação 26, caracterizado por o teclado virtual ser visualizado através de um interface gráfico de utilizador. 28 Keyboard of any one of claims 24 to 25, characterized in that the keys are physical. 28. Teclado de qualquer das reivindicações de 24 a 25, caracterizado por as teclas serem físicas. 29 Keyboard of claim 28, characterized in that the keys are placed off the screen. 29. Teclado da reivindicação 28, caracterizado por as teclas serem colocadas fora do ecrã. 30 Keyboard of claim 29, characterized in that the variables are displayed within the screen. 30. Teclado da reivindicação 29, caracterizado por as variáveis serem apresentadas dentro do ecrã. 31 Keyboard of any of claims 24 to 30, characterized in that it comprises five keys. 31. Teclado de qualquer das reivindicações de 24 a 30, caracterizado por compreender cinco teclas. 32 Keyboard of any one of claims 24 to 31, characterized in that the variables are alphanumeric characters. 32. Teclado de qualquer das reivindicações de 24 a 31, caracterizado por as variáveis serem caracteres alfanuméricos. 33 Keyboard of any one of claims 24 to 31, characterized in that the variables are numbers. 33. Teclado de qualquer das reivindicações de 24 a 31, caracterizado por as variáveis serem números. 34 Keyboard of any one of claims 24 to 31, characterized in that the variables are letters. 34. Teclado de qualquer das reivindicações de 24 a 31, caracterizado por as variáveis serem letras. 35 Keyboard of any one of claims 24 to 31, characterized in that the variables are a combination of letters and numbers. 35. Teclado de qualquer das reivindicações de 24 a 31, caracterizado por as variáveis serem uma combinação de letras e números. 36 Keyboard of any of claims 24 to 31, characterized in that the variables are symbols 36. Teclado de qualquer das reivindicações de 24 a 31, caracterizado por as variáveis serem símbolos 37 Keyboard of any of claims 24 to 36, characterized in that a group of variables is selected and presented to each user. 37. Teclado de qualquer das reivindicações 24 a 36, caracterizado por um grupo de variáveis ser seleccionado e apresentado a cada utilizador. 38 Keypad of claim 37, characterized in that the group of variables is generated by a predetermined sequence. 38. Teclado da reivindicação 37, caracterizado por o grupo de variáveis ser gerado por uma sequência predeterminada. 39 Keyboard of claim 37, characterized in that the group of variables is associated with the keys according to a random sequence of combination of values. 39. Teclado da reivindicação 37, caracterizado por o grupo de variáveis estar associado com as teclas de acordo com uma sequência aleatória de combinação de valores. 40 Keyboard of any one of claims 24 to 39, characterized in that a predetermined keyboard is presented to a user. 40. Teclado de qualquer das reivindicações de 24 a 39, caracterizado por um teclado predeterminado ser apresentado a um utilizador. 41 Keyboard of any one of claims 24 to 40, characterized in that the keyboard is implemented in a secure access terminal. 41. Teclado de qualquer das reivindicações de 24 a 40, caracterizado por o teclado ser implementado num terminal de acesso seguro. Secure access terminal services for providing electronic access via a secure code, the terminal comprising a graphical user interface, which allows access to secure electronic information to a user, and a keyboard as defined in any of claims 24 to 41. Terminal serviços de acesso seguro para providenciar acesso electrónicos através de um código seguro, compreendendo o terminal uma interface gráfica de utilizador, a qual permite o acesso a informação electrónica segura a um utilizador, e um teclado como definido em qualquer das reivindicações 24 a 41.
Independent claims8
66 paragraphs in 2 sections, as filed
DESCRIPTION
VIRTUAL KEYBOARD
Field of the Invention
The invention in particular use the same keyboards.
belongs to terminal machines. Another invention relates to terminal machines, which on the screen and a method of using the
Background of the Invention
Due to the increasing predominance of computers in everyday life, it is evident that in the near future the business will be traded mostly on the electronic superhighway or on the Internet. The convenience of shopping on the Internet and the use of e-commerce has begun to penetrate our lives. Credit card transactions and product orders on the Internet are now commonplace. However, associated with this newfound convenience, system security, user ID, and user ID validation remain the primary and legitimate concerns for users of current systems.
Automatic teller machines (ATMs) and Internet banking enable a bank's customers to conduct bank transactions with financial institutions from remote locations anywhere in the world. A bank's customers access their accounts through various technologies (including ATM and Online Banking terminals) for the purpose of doing business and obtaining exclusive information about their accounts. As a security measure, the financial institution assigns each bank customer a personal identification number or PIN. The bank customer enters the PIN on a numeric keypad operably connected to a card reader or other device that reads magnetically encoded user identification information on the ATM check or card, credit card or the like. Then, the PIN and user information are communicated to the financial institution's network, which then verifies the accuracy of the information. After verifying bank customer PIN information and user information, the bank customer is allowed to conduct business with the financial institution.
In the current market, four requirements are paramount in granting access to a protected resource to an authorized user: (1) authorized user identification, (2) verification of authorized user identification, (3) rejection of unauthorized user access, and (4) an appropriate level of security to protect the resource from unauthorized use. For example, when a user (authorized or unauthorized) wishes to withdraw money from an ATM, a card issued by the bank is inserted into the ATM identified by the magnetically transferred data or an electronic integrated circuit within the card to a database system. To verify that the user is the authorized user of the card issued by the bank inserted in the ATM, ATM asks the user to enter a Personal Identification Number (PIN), which is only available to the card and is from a user band authorized by the bank. bank card managing authority. If the PIN entered by the user is identical to the PIN made available to the authorized user and also stored in the database system memory, the user is considered as the authorized user and allowed to continue the transaction. The security provided by this transaction involves the user's possession of the bank issued card, knowledge of the PIN code, an upper withdrawal limit and card deactivation if a consecutive series of incorrect PINs are entered into the ATM system. Theoretically, this security system is adequate to prevent an unauthorized user from being able to access an account, but unfortunately protecting resources from unauthorized access has become a $ 1 billion problem. The solution to this problem lies in understanding the weaknesses of current systems and how to effectively eliminate these weaknesses while maintaining simplicity, safety and efficiency.
As the PIN security system becomes the norm for an authorized user to verify either the card-based system or the non-card-based system, authorized users are required to memorize a plurality of PIN codes in order to gain access. to protected resources and services. This problem of excessive memorization has been solved at user level by writing down PIN codes and carrying a copy in your wallet or suitcase for easy reference. However, this is a direct compromise with the security perspective provided by the PIN system, and can result in easy, unauthorized access to related accounts if your wallet or bag is stolen. 0 The memorization issue has been resolved at the managing authority level by allowing the use of custom PINs, for example various PINs, fully dynamic PINs, and other overlapping security measures. In this way an authorized user can eliminate the memorization of a multitude of PIN codes by making all PIN codes identical. In other words, custom PINs allow an authorized user to use a single PIN code for all their protected features, and additionally one PIN of their choice. However, if the personalized PIN is easy to guess, such as the authorized user's date of birth or telephone number, an informed unauthorized user can gain access to all protected resources with a single smart guess. Today, the biggest disadvantage of custom PINs is the requirement for identical code sizes with constant and invariant characters, usually digits. If, by observing an authorized user's PIN, unauthorized use of a feature is obtained, that unauthorized user instantly obtains access to all features protected by said custom PINs. In this way, custom PINs diminish the authorized user's personal security due to the possible occurrence associated with unlawfully obtaining possession of the user's wallet or bag and subsequent access to all resources protected by custom PINs. Gaining access to the Internet and e-commerce environments with an enhanced level of security has changed the passcode requirements for code size and the alphanumeric mix of code characters. Since many websites now require access codes of eight or more characters with a minimum of two digits, or.
instead, it offers a code of your choice of varying sizes, custom PINs only solve the problem of PIN over-memory for a short time.
There are numerous well-known methods for protecting the privacy of a bank customer's PIN. For example, in addition to fixed numeric keypads, advances in graphical user interface (GUI) technology allow a bank customer to enter their PIN on a numeric keypad or touchscreen. A bank customer is able to shield a potential scammer from appropriating the PIN. Typically, terminal keyboards, which are known in the art, are always displayed on terminals in the same position and with keys in the same arrangement. As a result, a scammer can see a customer's movements made by a bank while writing the PIN and thus recognizes dialed numbers as the keys and numbers are always displayed in the same position on the ATM terminal screen.
In addition, some con artists use the trick of cleaning up the ATM terminal touch screen before a bank customer uses it. Such a device allows the identification of a user's PIN through their fingerprints, which, once written, remain printed on the touchscreen. After the user leaves the ATM, the scammer checks the fingerprints, discovering the numbers pressed by the user, as the keys and numbers are always displayed in the same position on the ATM terminal.
The virtual keyboard of the present invention solves this and other limitations of the prior art by using a virtual keyboard that provides an image of a compact keyboard on an ATM terminal screen for the purpose of preventing fraud after writing the security password as described. in the previous paragraphs.
The available prior art reference documents do not describe, or even suggest, the solution to a fraud-proof keyboard such as the present invention.
WO 98/27518 A describes a fraud-proof keyboard for an appropriate automated banking terminal to prevent keys pressed on the keyboard by the person using the terminal during banking from being detected and used to discover personal identification code or other confidential user data. 0 The keypad comprises means that automatically and randomly vary between two successive banking operations, the number and / or symbol associated with each key.
DE 4129202 A1 describes a protection circuit for a personally identifiable numeric keypad which uses a number of keys for entering the PIN value, wherein the indicated values vary in a pseudorandom manner.
The keyboards of both WO 98/27518 and DE 4129202 A1 teach that in any new user access to the electronic terminal, the location of each number relative to each key will be different. Such a solution does not prevent an observer from identifying the digits of the user's access code when observing the keypad from a sufficiently close position to be able to see the characters displayed on it.
WO 02/101531 A describes a keypad for a pocket electronic device comprising a row of keys, each of said keys representing at least two alphanumeric characters and the characters of each key being positioned relative to the characters on adjacent keys. , to form a QWERTY or DVORAK configuration.
In WO 02/101531 A, more than one value is assigned to each keyboard key. The objectives of such an assignment are to minimize production costs and facilitate typing. According to this document, the configuration and the characters associated with each key remain constant. Thus, an observer only needs to identify the sequence of keys pressed by the user to know the user's access code to electronic services.
With this keypad setup, it is not necessary to know the numbers that make up the user's access code, but only the keystroke pressed by the user to gain access to the user's electronic services.
EP 0844778 A describes a radiotelephone comprising a user interface and a controller unit connected to the user interface, the user interface comprising a screen and a keyboard having at least one operation key whose function is controlled by the user. controller button and is displayed in a predetermined area of the screen. The radiotelephone is capable of assuming a plurality of states in which a predetermined group of actions associated with the state in question may be performed by said at least one operation key. The controller unit displays an action of said action group as a default function in the predetermined screen area.
EP 0844778 A describes a smart key whose functionality varies according to the state of the radiotelephone. Consequently, the result from pressing the key while the phone is in a call is different from the result from, for example, pressing the key while the phone is idle.
However, for a given phone state, the functionality associated with the keypad key remains unchanged. Since there is only one feature associated with each key, an observer watching the keyboard at a sufficiently close position is able to identify the value associated with the key pressed by the user.
Summary of the Invention
According to one embodiment of the invention, a method has been provided for providing access to electronic services via a secure access code. The method comprises the step of providing a keypad comprising a predetermined number of keys which are used to enter a secure access code, the method further comprising the following steps: associating at least two variables with each key where the value of one or more of said variables may change from one access to another; present the variables to the user; select by the user each key corresponding to each variable of his access code; compare the values associated with each selected key with a code stored in a database; and allowing the user to access electronic services if the values associated with the keys as selected by the user in a sequential manner match the stored access code. 0 The keyboard of the present invention can be either virtual, viewed through a graphical user interface, or physical.
According to another embodiment of the invention there is provided a keypad comprising a predetermined number of keys for entering an access code; characterized in that at least two variables are associated with each key, wherein the user selects keys based on the variables corresponding to some part of the user's access code, the variables being capable of switching from one access to another. 0 The keyboard can be either virtual, viewed through a graphical user interface, or physical.
According to another embodiment of the invention, there is provided a secure access terminal for providing access to electronic services via a secure access code, the terminal comprising a graphical user interface which allows a user to access information. secure electronics, and a keyboard, characterized in that each keyboard key has at least two variables associated with it; and because the variables are assigned from a group of possible combinations of variables and these variables are associated with each key, so that the user gets the right to perform certain transactions by selecting keys, which have assigned variables that match to a secret code.
Brief Description of Drawings
In the accompanying drawings which form part of the document and are to be read in conjunction therewith, the present invention is illustrated by way of example and is not limited thereto, with like reference numerals referring to like elements, wherein:
Figure 1 illustrates an example of a virtual keyboard, according to an embodiment of the invention;
Figure 2 illustrates another example of a virtual keyboard according to an embodiment of the invention;
Figure 3 illustrates yet another example of a virtual keyboard according to one embodiment of the invention;
Figure 4 is another illustration of a virtual keyboard in accordance with an embodiment of the invention;
Figure 5 is another embodiment of a virtual keyboard according to an embodiment of the invention;
<td>Figure 6</td><td>illustrates a</td><td>flow chart</td><td colspan="2">of a method</td>
<td>exemplary</td><td>according</td><td>a form</td><td>of achievement</td><td>gives</td>
<td>invention; and</td><td></td><td></td><td></td><td></td>
<td>Figure 6 (a) is</td><td>an illustration</td><td>from the list</td><td>of characters,</td><td>in</td>
according to one embodiment of the invention.
Detailed Description of the Invention
In the following detailed description, numerous specific details are given in order to provide a complete understanding of the invention. However, it will be apparent to one skilled in the art that these specific details need not be used to practice the invention. In other examples, well-known structures, interfaces, and processes have not been shown in detail so as not to unnecessarily minimize the invention.
The method of the present invention, which may be implemented by software, is to create a virtual keyboard, as illustrated preferably in Figures 1 to 6, at an ATM terminal or any other computer terminal, for example a computer. person or a laptop.
Fig. 1 illustrates a virtual keyboard 100 according to an embodiment of the invention. The virtual keyboard 100 provides five keys 105-125, however, one skilled in the art can easily understand that the figure is not intended to limit the scope of the invention and that any number of keys may be used. Associated with each key 105-125 on the virtual keyboard 100 is a number of alphanumeric characters which are displayed in relative proximity between each key 105-125. These characters are preferably numbers as illustrated in the figure, but one skilled in the art may understand that these may also be combinations of letters, numbers or symbols. Also, one skilled in the art can understand that while the figure illustrates two characters associated with each key, this is not intended to limit the invention but is for illustrative purposes only.
As shown in Figure 1, alphanumeric characters 7 and 4 are assigned to the first key 105, alphanumeric characters 2 and 9 are assigned to the second key 110, alphanumeric characters 1 and 3 are assigned to the third key 115, alphanumeric characters 6 and 5 are assigned to the fourth key 120 and alphanumeric characters 8 and 0 are assigned to the fifth key 125. Accordingly, in order to enter the password (e.g. 723604), the user presses the first key 105 through the fifth key 125, and presses the first key 105. The skilled artisan may appreciate that there may be various value permutations. based on the keys pressed.
As illustrated in the figure, there is more than one number assigned to each key. Thus, when a user presses the keys, which are associated with password elements, there is a process for determining which of the possible values entered is the correct password. For example, if the user presses the keys to enter 723604, numerous possible password combinations appear (eg, 491587). The system determines the possible password either by using the stored password or by an encrypted password. For example, consider that a user's secret password is 723604, and the keyboard is configured as shown in Fig. 1. If the password is stored on a central computer, then a comparison is made between the password stored password and the values entered by the user. The system knows that the user has pressed the first key indicating that either 7 or 4 is the first value of the password. The value 7 and then the value 4 are compared to the stored password and the value corresponding to the password is retained. A decision is made for each digit of the password, thereby resolving the distinction between possible different passwords. If there is no match, then an incorrect password has been entered and the user is notified. Another technique involves the possibility of a central computer not having access to the password. When you open an account with a financial institution, they choose a password that is encrypted and the encrypted password value is stored by the financial institution. When you press the keys, which are associated with the password, the system tests all possible character combinations using the same encryption method (for example, Triple DES) and compares the results of the encrypted value stored with the combinations. of encrypted values.
These alphanumeric characters can be displayed around each key to make it easier to see them, however, the skilled artisan can select other key positions, for example, being represented within each key 105-. 125 virtual ones.
According to the invention, the system includes multiple keys and various characters assigned to the keys. These features allow a user to have multiple layers of protection against observers or other types of fraud. For example, with several characters assigned to each key, the number of combinations, which must be observed, is considerable.
If a user types each key during the process of entering his PIN number, then the observer must determine which number the customer wants to enter, but also the correct sequence of buttons, since the combination of numbers by The key will be changed when the scammer accesses the terminal twice. Thus, the invention provides protection against fraudulent activity.
When a user uses the electronic terminal, the virtual keyboard 100 is displayed on a touch screen (not shown). One skilled in the art will recognize that there are numerous methods of displaying information to a user and that the type of screen is not intended to limit the invention.
The user identifies the generated characters, which are assigned to each of the five keys, and presses the keys that correspond to the PIN values to gain access to electronic transactions.
Together, keys 105-125 and associated characters are referred to as a screen. The screen may vary from user to user or after a predetermined period of time. A screen may be assigned to a user for certain periods of time. The skilled artisan can appreciate the various types of scenarios that may be proposed. The only variable on each screen is the character values assigned to each key. As shown in Figs. 1 and 2, the only difference between the figures is the values assigned to each key. Each screen has a total of ten characters assigned to the keys. A central computer in a financial institution can store all possible ten-character combinations that do not have repeated characters (for example, not having two 3's, as this would cause a lot of confusion between users and password decryption). An example of value combinations is illustrated in Fig. 6th (The) . After a card assigned by a bank to a user has been authenticated, a screen appears.
<td colspan="2">assigned to that user predetermined.</td><td>for one</td><td>period</td><td>of time</td>
<td>Typically,</td><td>when a new</td><td>user</td><td>uses</td><td>the terminal</td>
<td>a new screen</td><td>with a new</td><td>combination</td><td colspan="2">of characters is</td>
<td>displayed, the</td><td>virtual keys</td><td colspan="2">always remain</td><td>in the same</td>
position. Fig. 2 illustrates a new virtual keyboard 200 with a new character combination according to an embodiment of the invention. Virtual keyboard 200 provides five keys 205 - 225, however, the skilled artisan can readily appreciate that the figure is not intended to limit the scope of the invention and that any number of keys may be used.
As will be shown in Figures 3 and 4, the arrangement of the virtual keyboard keys 200 on a touchscreen may not be rigid. The keyboard 200 can be customized to the preferences of most users. As illustrated, the only difference between figure 1 and figure 2 is the character combination assigned to each of the five keys. For example, in figure 1, the virtual keys 105-125, which show a one-hand figure following the text you press here, are displayed in the same position, however, the numbers displayed around each of the virtual keys vary from one to another. user to user as illustrated in Figure 2, where the key layout is the same but the number combination is different. Accordingly, Figures 1 and 2 show examples of virtual keyboards that can be viewed by two distinct users.
Figure 3 illustrates a virtual keyboard 300, according to an embodiment of the invention. Virtual keyboard 300 provides five keys 305-325, however, one skilled in the art may readily appreciate that the figure is not intended to limit the scope of the invention and that any number of keys may be used. Associated with each key 305-325 on keyboard 300 are pairs of characters, which are displayed around or within each key 305-325. These characters are preferably numbers, as illustrated in the figure, the skilled artisan may appreciate that they may also be combinations of letters or letters and numbers. As shown in the figure, keys 305-325 are displayed in a horizontal configuration across the screen.
Figure 4 also illustrates a horizontal configuration of the keyboard 400. However, figure 4 illustrates a keyboard 400 in which the characters assigned to each key 405-425 have been configured to be displayed to a new user.
Figure 5 illustrates an alternative embodiment of the invention. The figure illustrates a keyboard 500 which has the keys off the screen. The screen illustrates several characters, which represent elements of a personal identification number (PIN) and a box, which shows the selected characters. The keys are arranged in a line such that they are associated with multiple characters. For example the first key (at the top left) is associated with the characters A, C and D. The characters A, C and D are shown on the screen. The screen illustrates the characters and a box that should indicate the number of characters that have been pressed. A user must select the button that corresponds to the PIN element and either the number or character should appear in the box.
Figure 6 illustrates a flowchart of a secure terminal access method 600 according to an embodiment of the invention. At step 605, a user approaches the terminal, decides to perform at least one bank transaction through the terminal and inserts a bank-assigned card into the terminal machine.
At step 610, the terminal reads the card information assigned by the bank and transmits it to the bank computer (not shown). Typically, information is encrypted according to a well known encryption method. The bank computer determines that the user who is associated with the bank card is using a terminal machine
At step 615, the system determines which numeric keypad will be displayed to the user. Because the user selects a key, which is at least two characters long, there are a number of values that can be associated with each key. For example, there are two characters associated with each key (as shown in Fig. 1). The computer stores predetermined character lists so that no individual number is assigned twice to the same key. Each screen contains two columns of numbers between 0-9. There are 945 possible screen combinations.
In step 620, the bank computer selects a random screen and displays the screen to the user, similar to Figs. 1 and 2 .
In step 625, the user enters the secret password. The user presses the keys, which have numbers associated with the secret passwords.
At step 630, the terminal machine encrypts the data associated with the secret password and transmits it to the bank computer. The data is encrypted in a manner known to the person skilled in the art.
At step 635, the bank computer verifies the secret password information and allows the user to perform predetermined bank transactions with the bank.
Contents2
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
19 members in 13 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 0300474 | Brazil | A | |
| 0300474 | Brazil | A | |
| 0300474 | – | – | – |
| BR20030300474 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| WO2004077194A2 | World Intellectual Property Organization (WIPO) | A2 | |
| UY28206A1 | Uruguay | A1 | |
| BR0300474A | Brazil | A | |
| US2004257238A1 | United States of America | A1 | |
| PE20041035A1 | Peru | A1 | |
| WO2004077194A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CL2004000360A1 | Chile | A1 | |
| AR043390A1 | Argentina | A1 | |
| EP1599786A2 | European Patent Office (EPO) | A2 | |
| BRPI0407796A | Brazil | A | |
| EP1599786B1 | European Patent Office (EPO) | B1 | |
| AT347132T | Austria | T | |
| ATE347132T1 | Austria | T1 | |
| DE602004003478D1 | Germany | D1 | |
| PT1599786EThis record | Portugal | E | |
| DK1599786T3 | Denmark | T3 | |
| ES2276279T3 | Spain | T3 | |
| DE602004003478T2 | Germany | T2 | |
| BRPI0407796B1 | Brazil | B1 |
Numbers
- Publication, DOCDB
- 1599786
- Publication, EPODOC
- PT1599786E
- Application
- 4712975
- Application, DOCDB
- 04712975
- Application, EPODOC
- PT20040712975T
Titles2
- English
- VIRTUAL KEYBOARD
- Portuguese
- TECLADO VIRTUAL
Classification
- CPC, 7
- G06F21/83
- G06F3/04886
- G06F21/36
- G06F21/31
- G07F7/10
- G07F7/1041
- G07F19/20
- IPC, 5
- G06F21 00
- G06F3 023
- G07F7 10
- G07F7 12
- G07F19 00