Method and system to perform secured electronic transaction, and also according data carrier and terminal
Abstract
FIELD: information technologies. ^ SUBSTANCE: method is proposed to perform secured electronic transaction on terminal with application of portable data carrier. According to this method, at first the user authenticates themselves for portable data carrier. At the same time portable data carrier generates quality information on how user has been authenticated. Then portable data carrier sends confirmation of user authentication to terminal. Afterwards portable data carrier performs operation providing for information security and protection, for instance operation of digital signature creation, in process of electronic transaction. Data carrier adds quality information to result of operation providing for security and protection of information. ^ EFFECT: improved flexibility in performance of electronic transactions that are important from the security point of view. ^ 14 cl, 3 dwg
Term
Term ended
Expired 23 October 2023, 2.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
14 claims: 2 independent, 12 dependent
- 1A method for performing secure electronic transactions on a terminal using a portable data carrier, the implementation of which the user authenticates himself to the portable data carrier, the portable data carrier transmits the terminal authentication confirmation, and then during the electronic transaction generates and transmits to the terminal to guarantee the authenticity of the user message, characterized in that the portable medium (20) data generates information on an authentication indicating the authentication method used to authenticate the user (30), one type of information about the quality of the authentication indicates a biometric authentication method and another type of information as authentication It indicates the authentication method based on the knowledge of certain information referred to as authentication information is added to the user guarantees the authenticity of the message and take into account when making an electronic transaction. 1. Способ выполнения защищенной электронной транзакции на терминале с использованием портативного носителя данных, при осуществлении которого пользователь аутентифицирует себя перед портативным носителем данных, причем портативный носитель данных передает в терминал подтверждение аутентификации, а затем в ходе электронной транзакции формирует и передает в терминал гарантирующее аутентичность пользователя сообщение, отличающийся тем, что портативный носитель (20) данных формирует информацию о качестве аутентификации, указывающую метод аутентификации, использованный для аутентификации пользователя (30), причем один тип информации о качестве аутентификации указывает на биометрический метод аутентификации, а другой тип информации о качестве аутентификации указывает на метод аутентификации, основанный на знании определенной информации, указанную информацию о качестве аутентификации добавляют в гарантирующее аутентичность пользователя сообщение и учитывают при совершении электронной транзакции. 1. Способ выполнения защищенной электронной транзакции на терминале с использованием портативного носителя данных, при осуществлении которого пользователь аутентифицирует себя перед портативным носителем данных, причем портативный носитель данных передает в терминал подтверждение аутентификации, а затем в ходе электронной транзакции формирует и передает в терминал гарантирующее аутентичность пользователя сообщение, отличающийся тем, что портативный носитель (20) данных формирует информацию о качестве аутентификации, указывающую метод аутентификации, использованный для аутентификации пользователя (30), причем один тип информации о качестве аутентификации указывает на биометрический метод аутентификации, а другой тип информации о качестве аутентификации указывает на метод аутентификации, основанный на знании определенной информации, указанную информацию о качестве аутентификации добавляют в гарантирующее аутентичность пользователя сообщение и учитывают при совершении электронной транзакции.
- 10The portable data carrier to perform secure and protect information during transactions secure electronic transactions carried out by the method according to one of claims 1-9, in which the user authenticates himself to the portable data carrier, the portable data carrier sends a confirmation to the terminal user authentication and then in the course of an electronic transaction generates and transmits to the terminal to guarantee the authenticity of the user message, characterized in that it is configured to generate information about the quality of authentication indicating the authentication method used to authenticate the user (30), and adding this information to guarantee the authenticity User message, one type of information about the quality of the biometric authentication refers to the authentication method, and the other type of information about the quality of the authentication indicates the authentication method is based on the knowledge of certain information. 10. Портативный носитель данных для выполнения обеспечивающей безопасность и защиту информации операции в ходе защищенной электронной транзакции, осуществляемой способом по одному из пп.1-9, при которой пользователь аутентифицирует себя перед портативным носителем данных, причем портативный носитель данных передает в терминал подтверждение аутентификации пользователя, а затем в ходе электронной транзакции формирует и передает в терминал гарантирующее аутентичность пользователя сообщение, отличающийся тем, что он выполнен с возможностью формирования информации о качестве аутентификации, указывающей метод аутентификации, использованный для аутентификации пользователя (30), и добавления этой информации в гарантирующее аутентичность пользователя сообщение, причем один тип информации о качестве аутентификации указывает на биометрический метод аутентификации, а другой тип информации о качестве аутентификации указывает на метод аутентификации, основанный на знании определенной информации. 10. Портативный носитель данных для выполнения обеспечивающей безопасность и защиту информации операции в ходе защищенной электронной транзакции, осуществляемой способом по одному из пп.1-9, при которой пользователь аутентифицирует себя перед портативным носителем данных, причем портативный носитель данных передает в терминал подтверждение аутентификации пользователя, а затем в ходе электронной транзакции формирует и передает в терминал гарантирующее аутентичность пользователя сообщение, отличающийся тем, что он выполнен с возможностью формирования информации о качестве аутентификации, указывающей метод аутентификации, использованный для аутентификации пользователя (30), и добавления этой информации в гарантирующее аутентичность пользователя сообщение, причем один тип информации о качестве аутентификации указывает на биометрический метод аутентификации, а другой тип информации о качестве аутентификации указывает на метод аутентификации, основанный на знании определенной информации.
Independent claims2
44 paragraphs, as filed
The present invention relates to a method according to the preamble of the main claim. Such a method is known, for example, under the name of "Digitale Signatur" from the directory "Handbuch der Chipkarten", W.Ranki, W.Effing, 3rd ed., 1999, s.692-703. In accordance with this method to create a legally binding signature should be used so-called digital signature card containing a secret crypto key signature. The procedure for the formation of a digital signature is executed on a suitable for this purpose, the terminal from which the card is received in electronic form document that is required to provide a digital signature. To be able to create a digital signature card user needs through the same terminal to authenticate, ie It must identify and authenticate itself important. Typically, such a customer confirmation of its authenticity based on their so-called entering a PIN (personal identification number) that is compared to those stored in the memory card control or master PIN. In the future, the user authentication to be used by any user biometric feature such as a fingerprint. An electronic document signed with a digital signature using the card after a successful user authentication may subsequently be transmitted to the addressee in any way. Using the digital signature enables electronic transactions are primarily those that require compliance with special security measures, and as an example of which can be called the issuance of orders for the provision of paid services.
Targeted involvement of biometric features for user authentication allows for comparison with the standard currently authenticated based on the verification PIN, further enhance the credibility of the digital signature as verification of biometric features ensures that the use of the card signature is possible only with the personal presence of certain authorized to the face.
However, arising from this difference in the quality or reliability of user authentication to date are not reflected in any of the procedures for creating a digital signature.
The present invention is to provide a method for performing a secure electronic transaction using the portable data carrier, allowing to take into consideration the quality or reliability of the results of user authentication.
This problem is solved by a method whose features are given in the main claim. The stated object is achieved according to the invention further by the portable data carrier and a terminal system for performing a secure electronic transaction, features which are presented in independent claims 10, 13 and 14.
According to the invention during the procedure it carries out the user authentication data carrier is formed as the authentication information indicating the authentication method used. This quality information is added to the result of authentication performance providing security and data protection operations carried out in the subsequent data carrier. Thus, formed in this way the recipient of the message can uniquely determine which method the user has authenticated himself before executing providing security and data protection operations. In this way the recipient of the communication, the opportunity to take into account when making a transaction quality or reliability of user authentication. For example, when performing transactions with the so-called e-wallet can be provided withdrawals sum of money not exceeding a set limit, after the user authentication method based on the verification of the PIN, and withdrawals of cash amounts in excess of this limit, Only after the user authentication method based on the verification of the biometric feature.
The inventive method is most preferably used in the procedures of creating a digital signature.
In one embodiment, the process for performing the various possible methods of user authentication is organized so that the intermediate results of the less efficient in terms of quality, the method of authentication is not possible in a simple way to transform the intermediate results in better performance, in terms of quality, the method of authentication. This eliminates the possibility of unauthorized manipulation of the results of authentication, even in the case where an unauthorized person in possession has not only a portable storage medium, but also the corresponding information necessary for successful authentication, the less efficient in terms of quality, the method, i.e. when available unauthorized person has, for example, a portable data carrier, together with its corresponding PIN.
It is further preferable to prohibit the execution of user authentication is not used to its current authentication methods.
The invention is discussed in more detail an example of one embodiment thereof with reference to the accompanying drawings, in which:
Figure 1 - Structure of the system to create a digital signature and
2, 3 - a block diagram illustrating a process of creating a digital signature.
1 shows a basic structure of a system for performing a secure electronic transaction. Essential to the invention, the components of this structure are the background system 10, which is a network of 12 data is connected to the terminal 14, the portable storage medium 20, the data that the user 30 is in possession of, and which is designed for providing security and data protection operations in the course of committing the transaction, and a set of 40 data which is to be protected from unauthorized access while operating with it during the transaction.
In the following description performing a secure electronic transaction is considered as an example transaction, which requires the creation of a digital signature by the user 30. Such a transaction may involve, for instance, in the banking business for debiting a bank account user 30. It should be noted, however, that in the proposed invention is not limited to the solution transaction for fulfillment of which a digital signature, and can in principle be used in all cases where the portable medium 20 processes the data received from the terminal 14, 40 sets of data and transmits it back to the terminal 14.
Under the background system 10 refers to a device that performs the actual transaction, such as cash transfers between accounts or initiates the delivery of ordered goods. Accordingly, the background system 10 may be a complex consisting of many separate components or in the extreme case, may be completely absent. If the transaction is an operation related to the movement of funds between accounts, the background system 10 is typically a bank cash processing center.
Data network 12 is used for communication between the terminal 14 and the background system 10. The data network may take any physical realization of such a network may be the Internet or a mobile radio network.
The terminal 14 forms a transaction fulfillment system interface for interfacing with the user and has the necessary funds 16 visual display of information, usually in the form of display and input means 18, such as a keyboard. Terminal 14 may be a public terminal such as a device installed in a bank, or belonging to the user device 30 such as a personal computer (PC) or a mobile phone. Data transmission network 12 may thus be combined with the background system 10, one or more terminals 14 which can thus be totally heterogeneous. The terminal 14 has an interface 19 for exchanging data with the portable data carrier 20. This interface 19 may have any physical performance, especially interface may be a contact or contactless type.
The terminal 14 is hereinafter referred to as the sensor below the sensor device 15 for registering biometric feature user 30. This sensor 15 can detect physiological signs, such as facial features, the iris or retina of the eye, or fingerprints or behavioral symptoms such as expressed by voice or speech writing, respectively written sequences. In the example shown in Figure 1 sensor 15 is a sensor for registering fingerprints. The sensor 15 may be calculated and the registration number of different biometric features. Part of the sensor means 15 are also pre-processing of data obtained during the registration biometric feature. Such data preprocessing is to reduce the volume of information collected and its attention to certain characteristic primary features. Various types of biometric authentication and its features are described for example in the aforementioned reference "Handbuch der Chipkarten", chapter 8.1.2.
Portable data carrier 20 can be, for example, a chip card (smart cards), which is also described in detail in a handbook "Handbuch der Chipkarten". Shown in particular in Figure 1 portable data storage medium 20 is a contact smart card with a pad 22 which forms a suitable interface 19 to the terminal interface. Via interfaces 22, 19, data is exchanged between the chip card 20 and the terminal 14. In addition the smart card portable data carrier 20 may have any other performance, for example, may be implemented as a wearable garment 30 a person or object related that the user has a 30 myself.
Portable data carrier 20 has an integrated circuit 24 with all components of a conventional computer, especially a microprocessor 25 and memory 26. The microprocessor 25 is designed for providing security and data protection operations. For example, it can be used to encrypt the enrolled data set 40, below called an electronic document 40, in accordance with the determined cryptographic algorithm, which requires at least one secret key stored in memory 26. Additionally, microprocessor 25 is designed to implement other functions in accordance with the stored 26 programs.
Portable data carrier 20 also serves to authenticate a user at least one and preferably a number of different methods. In a preferred embodiment, it must support at least two authentication methods, dissimilar in terms of its quality. In this respect, it is advisable that he maintained at least one based on knowledge of certain information authentication method, such as a method based on the verification of the PIN, as well as at least one biometric method based on the verification of the registered terminal 14 biometric feature by 30. Biometric method is thus more effective in terms of quality, the method of user authentication 30, as it involves private his presence, unlike the method based on the knowledge of certain information that may become known to an unauthorized person. Accordingly, in the memory 26 stores at least one secret that a user 30 must submit to their authentication, ie, for example, the control messages to users 30 PIN, as well as at least one set of reference biometric data corresponding to some biometric user 30. Preferably provide the ability to support a portable data carrier 20, more than two different authentication methods, first of all the other biometric authentication techniques. Accordingly, in this case, the memory 26 should be kept other secrets and / or sets of control data, and integrated circuit 24 must be designed to perform such other authentication methods.
With reference to Figures 2 and 3 discloses a process for performing a secure electronic transaction using the system, the structure of which is shown in Figure 1. By providing security and data protection operation at the same time meant signing an electronic document 40 digital signature.
The process begins with the creation of an electronic document 40 in the system 10 or the background in the terminal 14 (step 100). Typically, such an electronic document creation precedes derived interactively communicate between the user 30 and the background system 10 through the terminal 14. Then, the terminal 14 at the latest when it already has the electronic document 40 initiates a digital signature (step 102). Such a procedure for creating a digital signature can be initiated automatically by the terminal 14 or the background system 10 or 30 may be initiated by the user in response to a request issued by his terminal 14 and output them to the display 16.
After the initiation of the formation of the digital signature the user terminal 30 is a portable storage medium 40 corresponding to the data 20 (step 104). In the following description of a portable data carrier 20 is received a contact chip card. In addition, the following description assumes that such a chip card 20 is able to maintain two user authentication method, and in particular, based on the verification PIN method as based on the knowledge of specific information, qualitatively less effective authentication method, and based on checking Fingerprint biometric method as more effective in terms of quality authentication method.
Recognizes the presence of the chip card 20, the terminal 14 first executes a subroutine to the mutual authentication (step 106) at which the first chip card 20 confirms the authenticity of its terminal 14, then terminal 14 verifies its authenticity chip card 20.
Upon successful completion of the mutual authentication procedure of the terminal 14 and chip card 20 mutually agree upon dynamic session keys to allow subsequent communication in the so-called operation "Secure Messaging" (secure messaging mode) (step 108). In more detail the concept of a secure messaging ("Secure Messaging"), as well as the concept of using a dynamic session keys are also discussed in the aforementioned reference "Handbuch der Chipkarte".
Thereafter, the user authentication procedure 30, before the chip card 20. This terminal 14 first checks which method - based on the knowledge of specific information, i.e. on entering the PIN code or biometric, i.e. based on the verification of the fingerprint is used for authentication (step 110). As used in the following authentication method can be selected automatically based on the terminal 14 is transmitted together with the electronic document information 40 or 30 by the user, making the decision in response to a request for output to the display 16. In the latter case, the user 30 announces its decision by means of 18 input data.
If user authentication 30 should be used based on the knowledge of a particular method of information, for example based on entering the PIN method, the chip card 20 prohibits the user authentication by other possible methods, ie in this case, the fingerprint authentication (step 112), and displays 16 30 addressed to the user prompted to enter a PIN code using the input means 18.
In response to such a request with a user 30 via the input means 18 inputs a PIN code, which is directly or after conversion of the corresponding terminal 14 is transmitted through the interface 19, 22 further into the chip-card 20 (step 114). Transfer PIN respectively obtained on the basis of its information, as well as the subsequent communication with the chip card is further protected with the previously agreed session key. All communication between the terminal 14 and the chip-card 20 is suitable for a mode "Secure Messaging".
Chip card checks received PIN and the results of such inspection or terminal 14 confirms the correct PIN code or if you enter the wrong PIN, the process terminates (step 116).
If a positive test result PIN terminal 14 by issuing the appropriate commands triggers the chip card 20 providing security and data protection operations, ie creating a digital signature, and transmits to the smart card 20 the electronic document 40 which is required to provide a digital signature (step 118).
The chip card 20 signs the resulting electronic document 40 stored in its memory 22, a secret key (step 120) and then transmits the signed electronic document 40 back to the terminal 14 (step 122), which continues to perform with him started an electronic transaction.
If step 110 decides that the user authentication is to be used is not based on knowledge of specific information, and a biometric method, the terminal 14 initiates authentication by biometric features, and sends a smart card 20 a message (step 130). In response to this message smart card authentication 20 prohibits not used in this case, other methods, ie In this particular example, knowledge-based authentication and PIN verification method (step 132).
Thereafter, the user 30 according to the used for its authentication by the terminal 14 is a biometric feature, i.e. in this case, a fingerprint (step 134). Request a proposal to introduce a fingerprint preferably issued by displaying relevant information on the display 16 of the terminal 14. The fingerprint is read by the existing sensor in the terminal 14 15.
Data on the registered biometric features, ie Fingerprint user 30, terminal 14 exposed in pre-processing in which the output signal of the sensor indicates information about certain characteristic features (step 136). When used as a fingerprint biometric feature are determined, e.g., the primary features that are classified according to the method of Henry ("Klassifikationsverfahren nach Henry"), as described in the handbook "Handbuch der Chipkarten".
Thus isolated by the feature information is then transmitted to the terminal 14 through the interface 19, 22 to the portable data carrier 20 (step 138).
After receiving this information, the feature of the data carrier performs verification (step 140). To this end, the integrated circuit 24 compares the resulting extract information about the characteristic features with a stored reference biometric information about the signs and check whether there is a sufficient degree between the two matches. With a positive result of this test portable medium 20 transmits data to the terminal 14 a message confirming the successful verification of the biometric feature on the basis of the transmitted data in this media information (step 142). After that, the portable data carrier 20 goes into a state of readiness for the implementation of the proposed providing security and data protection operations, ie the creation of a digital signature.
After receiving confirmation of the successful verification of the authenticity of the biometric feature user terminal 14 by issuing the appropriate commands triggers the carrier 20 of these procedures to create a digital signature (step 144). This, along with the command terminal 14 transmits to the portable medium 20, electronic document data 40 which is required to provide a digital signature, or at least part thereof.
Thereafter, the integrated circuit 24 of the portable data carrier 20 starts execution needed to create a digital signature operations (step 146). To this end, the integrated circuit generally computes a hash value of the received part of the electronic document 40 and encrypts the value stored in the memory 26 by the private key of an asymmetric key pair, one of which is a secret key, and the other - the public key.
Along with this, the integrated circuit 24 generates information (step 148) of an authentication, which confirms that the 30 user authentication is performed by checking his biometric feature. This information about the quality of authentication then intimately combined with the generated digital signature to guarantee the authenticity of the user message, which is preferable to use the mechanism of "Secure Messaging" with the previously agreed session key.
Formed in this manner, consisting of a digital signature, and authentication information as guaranteeing the authenticity of a message transmitted by user portable data carrier 20 back to the terminal 14 (Step. 150). The terminal in turn performed in secure electronic transaction sends it had received guaranteeing the authenticity of the user involved in the transaction message to the recipient, such as a background system 10.
The recipient user guarantees the authenticity of the message in addition to the result of providing security and data protection operation carried portable data carrier 20 receives at the same time thanks to the contained in this report information on the quality of authentication information as the authentication of the user 30.
In the above example of an authentication information formed only using biometric authentication method, but the application is based on knowledge of some information authentication method. Accordingly, one has only to a lack of information about the quality authentication guarantees the authenticity of the message indicates the user to authenticate the user using the less efficient in terms of quality of the method. It is obvious, however, that it is possible in principle to provide the possibility of forming as authentication information, i.e. possibility of its formation, regardless of whether user authentication is selected based on knowledge of some information method or biometric techniques.
The above concept implies the possibility of its implementation in other ways and to make it different modifications while maintaining the underlying invention, the principle of which consists in adding to the result of providing security and data protection operation performed by a portable data carrier, information about the quality of authentication, which characterizes the quality of the performed earlier user authentication. This applies to the configuration used to perform the transaction system, which may differ from that discussed above the number and type of its constituent components. In addition, in the above method may provide for additional steps, such as some intermediate stage.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO0074001A1 | Cites | World Intellectual Property Organization (WIPO) |
| WO02073341A2 | Cites | World Intellectual Property Organization (WIPO) |
| US4993068A | Cites | United States of America |
| US6263447B1 | Cites | United States of America |
| US6408388B1 | Cites | United States of America |
| RU2071114C1 | Cites | Russian Federation |
14 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10249801 | Germany | A | |
| 10249801 | Germany | A | |
| 102498016 | Germany | – | |
| 102498016 | – | – | – |
| DE2002149801 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| DE10249801B3 | Germany | B3 | |
| WO2004038665A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003276154A1 | Australia | A1 | |
| BR0315675A | Brazil | A | |
| EP1573689A1 | European Patent Office (EPO) | A1 | |
| CN1708773A | China | A | |
| JP2006504167A | Japan | A | |
| RU2005115843A | Russian Federation | A | |
| US2006242691A1 | United States of America | A1 | |
| CN100365666C | China | C | |
| RU2397540C2This record | Russian Federation | C2 | |
| JP4578244B2 | Japan | B2 | |
| US8205249B2 | United States of America | B2 | |
| EP1573689B1 | European Patent Office (EPO) | B1 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A | |
| Official registration of the transfer of exclusive rightPC41 | PC41 |
Numbers
- Publication
- 2397540
- Publication, DOCDB
- 2397540
- Publication, EPODOC
- RU2397540
- Application
- 200511584309
- Application, DOCDB
- 2005115843
- Application, EPODOC
- RU20050115843
Titles3
- Russian
- СПОСОБ И СИСТЕМА ДЛЯ ВЫПОЛНЕНИЯ ЗАЩИЩЕННОЙ ЭЛЕКТРОННОЙ ТРАНЗАКЦИИ, А ТАКЖЕ СООТВЕТСТВУЮЩИЕ НОСИТЕЛЬ ДАННЫХ И ТЕРМИНАЛ
- English
- METHOD AND SYSTEM TO PERFORM SECURED ELECTRONIC TRANSACTION, AND ALSO ACCORDING DATA CARRIER AND TERMINAL
- Russian
- ?????? ? ??????? ??? ?????????? ?????????? ??????????? ??????????, ? ????? ??????????????? ???????? ?????? ? ????????
Classification
- CPC, 8
- G07F7/1008
- G06Q20/341
- G06Q20/4014
- H04L9/3218
- H04L9/3231
- H04L9/3247
- H04L2209/56
- H04L2209/805
- IPC, 6
- G06F21 20
- G07F7 10
- G06F21 32
- G06F21 34
- G06F21 35
- G06F21 44