Untitled record
18 claims: 1 independent, 17 dependent
- 1; ....... ........ A method of a direct-controlled system, comprising a * central computer and at least one remote terminal with a code reader (14) and a keyboard (16), for verifying that the holder> of an identification card (12) with a machine readable data is an authorized holder, which method is characterized in that it comprises:converting (14) said machine-readable data into a first electrical signal;inserting (16) on the terminal keyboard a set of indicia known only to the authorized holder;converting (42, 44) said set of indicia into first and second signal portions;comparing (48) at the remote terminal of said first signal portion with a first reference signal;generating (48) a first validation signal in response to a favorable comparison of said first signal with the first reference signal *, transmitting (30) said second signal portion to the central computer in response to generating said first validation signal;comparing (54) at the central computer of said second signal portion with, a second reference signal;and generating (54) a second validity signal indicating that the holder of the card (12) is an authorized holder in response tos a favorable comparison of said andi-a signal part with said second reference signal. ;....... ........ Patentkrav ‘ 1., Förfarande vid ett direktstyrt system, som innefattar en * central dator och åtminstone en avlägsen terminal med en kodläsare (14) och ett tangentbord (16), för verifiering av att innehavare > av ett identifieringskort (12) med maskin-läsbara data är en auktoriserad innehavare, vilket förfarande kännetecknas av att det innefattar: omvandling (14) av nämnda maskin-läsbara data till en första elektrisk signal;införande (16) på terminalens tangentbord av en sats av indicia som är kända endast av den auktoriserade innehavaren;omvandling (42, 44) av nämnda sats av indicia till första och andra signaldelar;jämförelse (48) vid den avlägsna terminalen av nämnda första signaldel med en första referenssignal;alstring (48) av en första giltighetssignal som svar på en gynnsam jämförelse av nämnda första signal med den första referens signa len*, överföring (30) av nämnda andra signaldel till den centrala datorn som svar på alstringen av nämnda första giltighetssignal;jämförelse (54) vid den centrala datorn av nämnda andra signaldel med, en andra referenssignal;och alstring (54) av en andra giltighetssignal som indikerar att j innehavaren av kortet (12) är en auktoriserad innehavare som svar på s en gynnsam jämförelse av nämnda andi-a signaldel med nämnda andra reI ferenssignal. ;;
71 paragraphs, as filed
The present invention relates to a method and an apparatus according to claim 1 and 2, respectively. 13 preamble for verification that the holder of an identification card is an authorized holder thereof, and the invention is defined by the features stated in the claims. In particular, the invention relates to a method and apparatus for verifying that a holder of the card is an authorized holder at a remote terminal in an on-line system, where secret data entered on the keyboard by the holder is compared with invisible machine machines. readable data present on the card, and where said secret data can not be determined by monitoring the connection line between the terminal and the central computer.
Machine-readable identification cards have become commonplace in such applications as gaining access to a restricted area and executing credit sales transactions. In commercial banking, unattended online banking terminals, ie. directly controlled terminals, execution of certain transactions. These transactions include the receipt of deposits, the payment of cash, the transfer of amounts from one account to another, and payments by credit card, accounts relating to public works and establishments or other accounts, or to mortgages or
7701611-1 installment loans and the like. The customer is then presented with an identification card, often consisting of plastic, which contains machine-readable information. The information includes, but is not limited to, the customer's account number, the identification number of the bank or institution, an expiration date, credit limit, account balance, and types of authorized transactions. Although the information is preferably found on the card in the form of invisible magnetically registered indicia, the information could also be found in high-relief indicia, openings, or electrically.<sup>-</sup>leading segment.
The remote bank terminal is equipped with a keyboard, as well as a card reader. The customer places his identification card in the card reader, and his account number and other data are read from the card and converted into digital signals. While using the keyboard, the customer enters a secret number that is known only to the authorized holder of the identification card. The account number, read from the card, is converted to another number that has no logical relation to the account number, and the converted number is compared with the secret number entered on the keyboard. A positive comparison shows that the customer is the authorized holder of the identification card.
The secret number is given to the authorized holder of the identification card when the card is issued. The secret number is determined according to the particular algorithm or conversion used to convert or transform the account number.
The secret number entered on the keyboard can optionally be combined with an offset number, ie. disguised number, before comparison with the converted account number. The disguised number causes the secret number entered on the keyboard to correspond to the translated account number. This allows the customer to choose his own secret number, when his card is issued.
A system for converting a machine-read account number for comparison with a secret number entered on the keyboard, and optionally combining a disguised number with the secret number before comparison is disclosed in U.S. Patent 4,016,405, over35 the song to the assignee of the present application.
When the customer at the remote terminal is found to be the authorized holder of the identification card presented at the terminal, the secret data together with the account number and other data are transferred to the host or central computer over a pre-binding line. By monitoring the connection line it is possible3
7701611-1 for an unauthorized person to intercept a customer's secret data and, in possession of the identification card, perform unauthorized transactions at the terminal.
An object of the invention is therefore to provide a secure method and a things apparatus for gaining access to a remote terminal in an on-line system.
Another object of the invention is to provide a new method and apparatus for determining at a remote terminal in an on-line system whether a holder of an identification card is an authorized holder.
Another object of the invention is to enable secure completion of transactions, such as depositing or withdrawing money, or transferring amounts from an account to a
In another, at a remote terminal of an on-line banking system.
Yet another object of the invention is to provide a method and apparatus which enables secure access to a terminal in an on-line system, where a part of secret data entered at the terminal is verified at the terminal, and another part is verified at the central computer.
Yet another object of the invention is to enable operation of a central computer-from a remote on-line terminal, where secret data is used to gain access to the terminal, but where this secret data is not ascertainable by monitoring the connection line between the central the computer and the terminal.
According to a feature of the invention, in a method and apparatus for verifying a customer at a remote terminal of an online banking system is authorized to complete a requested transaction, invisible account number data pre-registered on the card may be machine readable. at the terminal, and converted into a digital signal. A portion of the digital signal is applied to a signal translator, as described in said U.S. Patent 4,016,405, to develop a translated signal which has no logical relation to the account number data signal.
Secret data is entered by the customer on a keyboard at the terminal, and the data is converted into a digital signal. The digital signal is then divided into first and second signal parts. The first signal part of said secret data is compared with the translated part of the account data signal. If the result of this comparison is positive, the other signal part is transmitted, together with on
7701611-1 ··,.
keyboard entered transaction data and account number data, to the central computer via connection lines.
At the central computer, the second signal part is compared with the reference signal, stored in the authorized cardholder's file under his account number. The file is addressed through the account number data that is transferred to the computer. If the result of this comparison is positive, the customer is considered authorized to perform the requested transaction, and the central computer transmits a signal back to the remote terminal, which enables completion of the requested transaction.
According to another feature of the invention, the secret data entered on the keyboard by the customer may consist of alphabetic characters, numerals, or a combination thereof. Furthermore, the secret data may consist of any number of characters or numerals, within a predetermined range or limits, and the secret number may be selected by the customer when the identification card is issued. The keyboard is an alphanumeric keyboard, or optionally a decoder can be arranged to convert alphabetic characters, entered on the keyboard, into corresponding numerals.
Another choice may be that a disguised number can be combined with the secret data entered on the keyboard, before comparison with the translated account number data. The preset number is registered on the card when the card is issued. This allows the customer to choose their own secret data.
Thus, another object of the invention is to provide a method and apparatus for completing a transaction at a remote terminal of an online banking system, where alphabetic characters, as well as numerals, can be used as secret data entered on keyboards by customer for verification.
Another object of the invention is to provide a method and apparatus for completing a transaction at a remote terminal of an on-line banking system, where any number of alphabetic characters and / or numbers can be used as secret data entered on keyboards. verification, and the secret data can be selected by the customer when his identification card is issued.
The above and other objects and advantages of the invention will become apparent from the following detailed description of a preferred embodiment of the invention, particularly taken in conjunction with the drawing.
Fig. 1 shows a simplified block diagram of the system according to the invention.
Fig. 2 shows a general flow chart illustrating the method according to the invention.
Fig. 1 shows an apparatus 10 for verifying whether a customer presenting an identification card 12 at a remote terminal of an online banking system is authorized to carry out a transaction at the terminal, which apparatus comprises a card reader 14 for reading of data pre-recorded on the card, and a keyboard 16 for receiving data sonij manually entered by the customer.
The data entered on the keyboard includes a secret alphanumeric code, known only to the authorized holder of the identification card, and transaction information, i.e. information related, to the type of transaction requested, as well as the amount in question. The transaction types include depositing or withdrawing money from an account, transferring amounts between accounts, paying bills, and the like.
According to an important feature of the invention, two-step verification is provided that the customer is authorized to complete a requested transaction. A first part of the secret data entered on the keyboard is compared with it. pre-registered data, which is machine-read at the terminal. If then the result of this comparison is positive, the remaining part of the secret data is transferred to the central computer for comparison with reference data registered in the authorized cardholder's file. If the result of this comparison is positive, the customer is considered to be the authorized holder of the identification card. If the particular requested transaction ^ is an authorized one, the central computer instructs the terminal to complete the transaction. Since only a portion of the secret data is transferred to the central computer, the entire secret data can<sub>ä</sub>not determined by monitoring the connection line.
The identification card 12 is a conventional information-bearing medium, such as plastic, and contains data stored in field A, field B and field C. This data is machine-readable, but not readable by the customer. Although the data are preferably recorded on magnetizable material, they could alternatively be recorded via high-relief coded indicia, apertures, or electrically conductive strips.
Field A on the identification card 12 contains data related to the use of the card, such as expiration date data, amounts, and types of authorized transactions. Field B contains the account number of the authorized holder, together with a bank or
7701611-1 institution identification number. Account number, read<sup>:</sup>From field B, it is subjected to distortion and then compared with a portion of the secret data entered on the keyboard to determine whether the customer is the authorized holder of the identification card. Field C contains a disguised number, which is determined by the bank or institution when the identification card is issued. The disguised number is determined in such a way that the secret data is brought to correspond to the authorized account holder's distorted account number, and is combined with the secret data before comparison. This allows the authorized holder of the identification card to choose his own secret data.
The reader 14 is a conventional magnetic card reader which converts the data recorded on the card 12 in fields A, B and C into digital signals. The reader 14 also stores the signals derived from these respective fields in registers 18, 20 and 22. The A-field signal stored in the register 18, as mentioned above, is related to authorized use of the card. This signal, transmitted to the host or central computer 24, is used as a preliminary check of the validity of the card, e.g. whether the card has expired. If the central computer 24 determines that the identification card 12 is invalid, e.g. has expired, the B and C field data signals, which are stored in registers 20 and 22, not to be processed to determine whether the holder of the card 12 is an authorized holder, or whether he is authorized to complete a requested transaction. Preferably, the keyboard 16 is arranged so that it can receive secret data and transaction data from the customer only if the preliminary check shows that the card 12 is valid.
Assuming that the result of the preliminary check of the identification card 12 is positive, the account number (the account number includes a bank or institution identification number) is added in the register 20. to a number translator 26 along the line 28. The number translator 26 converts (distorts) this data to translated data that has no logical relation to the data stored in the register 20. This is a security feature and ensures that an unauthorized cardholder cannot use the card to complete a transaction, even if he determines the account number registered in field B on the card 12. The number translator 26 is a pseudo- random number generator, which distorts the account number, which is stored in a digital signal in the register 20, in a manner which is dependent on the bank or institution identification number. Nummor translator
26 is of a type described in U.S. Patent 4,016,405.
7701611-1
In addition to being supplied to the translator 26, the account and institution number signals are also supplied, on line 32, to an input of a buffer / switch 30. As further described in the said U.S. patent specification, when the holder of the card 12 is determined to be an authorized holder, bank or the institution identification number and the account number, together with the transaction data and other data, to be transmitted to the central computer 24 over the connection line 34. If the requested transaction is an authorized one, the transaction is performed with respect to the Authorized Holder's account, identified by the account number, and debited with respect to the bank or institution identified by the identification number.
The keyboard 16, located on the remote terminal, is preferably an alphanumeric "push-button keyboard", where the push-button keys represent alphabetic characters as well as numbers. For example, the upper left pushbutton on the keyboard 16 represents the alphabetic characters A, B and C, as well as the numeral 1, as shown. The keyboard 16 converts the data entered on it by the holder of the identification card 12 into digital signals, and stores these signals in registers 36 and 38. In accordance with an important feature of the invention, which is described in more detail below, the secret data entered in the keyboard 16 by the customer, a word, a numeral, or a combination-- ·, nation thereof. Furthermore, the data comprises an arbitrary number of characters and numerals within a predetermined total number of such, e.g. 4-12. This data is converted into digital signals through the keyboard 16. Signals representing the secret data are stored in register 36, and signals representing transaction data are stored in register 38. Storage of the signals, in registers 36 resp. 38, is controlled by the central computer 24, or by a conventional sequencer or assignor (not shown) located at the terminal. The sequencing or counting sequence is preferably checked at the terminal to minimize the island-line time.
Preferably, the secret data stored in the register 36 comprises a word, such as CUSTOMER, together with a numeral, such as 8, as shown in Fig. 1. The use of a word together with a numeral such as secret data helps the authorized holder of the card 12 to remember his secret data. For example, the authorized holder can
7701611-1 δ
use his own name as the said word, and his year of birth as the number.
In the preferred embodiment, the secret data comprises from four to twelve alphanumeric characters. When less than twelve characters are used as the secret data, the numeric zero is stored in the register 36 for each unused character, but in the case of secret data it is treated as a twelve-character block. This is an important feature, as it allows the secret data to have variable length, which is determined by the authorized cardholder, or by the bank or by the institution.
Output from the register 36, containing the alphanumeric data, is supplied to an optional decoder 40 (shown in dashed lines) for converting the alphabetic characters of the secret data into numerals. The decoder 40 required when the keyboard 16 is of a type with alphabetic character keys as well as separate numeric keys, and where each key corresponds to a single digital code to be generated, is conventional. For example, the decoder 40 may be a read only memory addressed by signals representing alphabetical characters and generating signals representing corresponding numerals. However
2Q, the decoder 40 is omitted when the keyboard 16 is an alphanumeric keyboard of the type shown in Fig. 1, where each key represents alphabetic characters as well as corresponding numerals. For example, in the keyboard 16 (Fig. 1), the pushbutton key, which represents the letters A, B and C, also represents the numeral 1. Thus, when the cardholder 12 inserts the letter A, B or C on the keyboard 16, the digital word representing the numeral is stored. 1, in the register 36.
In accordance with another important feature of the invention, the data stored in the decoder 40 is divided into two data parts or segments stored in the A-register 42 and 42, respectively. The B register 44. In the example shown in Fig. 1, the data in the decoder 40 is divided between the numbers 6 and 8. The numbers 1, 7, 3 and 6 are stored in the register 42, while the numbers 8, 7, 9, 1, 2 and 8 stored in the register 44. Optionally, other numerals could be stored in the register 42 while the remaining numerals of the secret data were stored in the register 44. For example, alternating numerals, i.e. 1,3,8 and 9 from the example in Fig. 1 could be stored in register 42, and the remaining numbers 7, 6,7, 1, 2 and 8 could be stored in register 44. As another variation, more or less than four numbers can be stored in register 42 and the remaining numerals are stored in register 44. Only the numbers
7701611-1 in the register 42 is used on the remote terminal for comparison with the translated account number signal generated by the number translator 26. The output signal from the register 42 is applied to an input of the adder 46. The preset number, stored in the register 11 ',' 5 is applied to the second input of the adder 46. These two numbers are added together without a memory digit, and the result is applied to an input of the comparator 48. The output of the number translator 26 is applied to the second input of the comparator 48.
As mentioned above, the purpose of the disguised number stored in the register 22 and read from field C on the identification card 12 is to allow the authorized holder of the identification card to select his own secret data when the card is issued. The disguised number, registered in field C on the card 12 at the time of issue, ensures that the part of the secret data stored in the register
42 compares positively with the output of the number translator 26, and is a function of the particular secret data selected by the authorized holder of the card. This is described in detail in the aforementioned U.S. Patent 4,016,405 ... The holder of the identification card 12 also enters transaction data on the keyboard 16,
for example the type of transaction requested, and the amount therein. This data is converted into digital signals stored in the register 38 under the control of the sequencer (not shown). The output of register 38 is connected to an input of buffer / switch 30.
Output data from the B register 44, which contains the remaining part of the secret data separated from the register 40, is supplied to another input of the buffer / switch 30. The buffer / switch 30 is controlled by the output of the comparator 48. A positive comparison between the output of the adder 46 and the output of the number translator 26 enables the buffer / switch 30 to transmit the data stored in the register 20, the register 44 and the register 38 to the central computer 24 overconnection line 34. The buffer / switch 30 amplifies the output signal from these registers for transmission on the relatively long connection line 34. Only the second part of the secret data, stored in the register 44, is transmitted to the central computer
24; the first part of the secret code, stored in the register 42, is retained on the remote terminal.
A central computer 24, a signal conditioner 50, receives the data signals transmitted by the buffer / switch 30 at the remote terminal and amplifies and conditions these signals for processing in the computer.
7701611-1
A signal splitter 52, located at the central computer 24, is connected to the output of the signal conditioner 50. The signal splitter 52 is a conventional signal demultiplexer circuit which detects the B signal data signal, the account number data signal, and the transaction data signal transmitted on line 34. . Account number data is transmitted to the computer 24 together with B-register data, but transaction data is preferably not transmitted until after the holder of the card 12 has been established to be the authorized holder.
The account number data signal is applied to the input of a file memory 53 in the computer 24 as a file address. A reference data signal associated with each authorized cardholder. account, stored in the memory 53. The reference data signal, addressed in the memory 52 by the account number signal, is supplied to one input of a comparator 54. B-register data generated by the signal divider 52 is supplied to the other input of the comparator 54. If there is a positive comparison between the reference data stored in the memory 53 (addressed by the account number data signal) and the B register data, the comparator 54 generates a signal on the line 56 indicating that the holder of the card 12 is an authorized holder. The output of the comparator 5 = 4, together with the transaction data signal generated by the signal divider 52, is connected to a switch 58. Switch 58 in turn sends a signal back to the remote terminal, instructing it to complete the transaction requested by the cardholder.
Of particular importance is that only the part of the secret data stored in the B-register 44 is transferred to the central computer 24 along the connection line 34. The remaining part of the secret data is retained in the remote terminal in the A-register 42. It is thus, it is impossible to determine the entire secret data by monitoring the connection line 34, since only a part of the secret data is transmitted on the line.
Also of particular importance is that when secret data with less than the maximum default number of characters, e.g. twelve, is selected, the numeric zero is used for the unselected characters. The zeros, together with the selected characters, are stored in the file memory 55 as reference data when the file is created. The zeros stored in the file memory 53 are compared with the zeros sent to the central computer 24, as a second verification of the card. This provides flexibility in the selection of secret data made by the authorized cardholder.
For example, in Fig. 1, assuming that the secret data was selected as 123400000000, the data 123400000000 would be stored in the register
7701611-1
36. Since there are no alphabetical characters in the selected secret data, this data would be stored in the decoder 40 without any pre-. change. The data 1234 would then be stored in the A-register 42 for comparison with the output of the number translator 26, and the numbers 00000000 would be stored in the B-register 44. If the result of the comparison is positive, the zeros in the register 44 would be transmitted, together with other data. to the computer 24. The numbers 00000000 would then be compared with the data stored in the cardholder's file under his account number for the second verification.
With reference to Fig. 2, the method according to the invention will be described. At the remote terminal, the identification card 12 provided by a customer shall be machine-read in step 60. By examining the data in field A on the card 12 (Fig. 1), a preliminary check of the validity of the card is made in step 62. If in accordance with a preliminary control card 12 is determined to be invalid, e.g. output, a card control message is sent to the host or central computer in step 64. The transmitted message is analyzed in the central computer, together with the card-read data (step 66), and a decision is made whether the card should be returned to the holder or retained (step 68).
If it is decided to return the card, a notice of return of the card is sent to the holder, back to the terminal, in step 70. If, on the other hand, it is decided to keep the card, a message to that effect is sent back to the terminal in step 72.
If the preliminary check (step 62) shows that the card 12 is valid, the keyboard (step 74) can determine whether the holder of the card is an authorized holder. The holder then enters the secret data via the keyboard, in step 76. The customer's account number and bank or institution number, read from the card in step 60, translatcras (distorted), and part of the distorted number is compared with the secret data in step 78. If the result of this comparison is negative, found during step 80, the holder is allowed to re-enter the secret data, as in step 74. Re-entry is allowed a default number of times. After a final re-entry, determined during step 82, a message is sent to the central computer to determine whether the card should be returned to the user or retained.
If the result of the comparison in step 80 is positive, the magnetic table has the possibility (step 84) to receive data from the cardholder. The holder selects the requested transaction, e.g. depositing or withdrawing money, etc., (step 86). Transaction data, to 40 together with the account number data (including the bank or institution 7701611-1 number) and only the remaining part of the secret data, is sent to the central computer (step 88).
The data transmitted during step 88 is analyzed in the central computer in step 90. The analysis includes determining whether the secret data entered by the holder during step 76 is correct. This is done, as described in more detail in connection with Fig. 1 above, by comparing only the transmitted part of the secret data with reference data recorded in the memory of the computer. Reference data is registered in the authorized holder's account register and addressed with the account number data sent during step: 88. If the reference data and the transmitted secret data are compared with a positive result in step 92, a message is sent back to the terminal (step 94) instructing the terminal shall allow the holder of the identification card to complete the requested transaction. On the other hand, if the result of the comparison in step 92 is negative, optional, the holder may be allowed to re-enter the secret data a preselected number of times (step 96). After the preselected number of re-entries has been reached, a decision is made (step 68) as to whether or not to retain the identification card. If the preselected number of re-entries has not been reached, as determined in step 96, a message (step 98) is sent back to the terminal to allow the holder to re-enter the secret data.
In summary, a method and system for determining whether the holder of an identification card at a remote terminal in an online banking system is an authorized holder of the card, and is authorized to complete a requested transaction at the terminal, has been described above. Of particular importance is that only a part of secret data, which is entered at the terminal by the holder, was transmitted to the central computer over the connection lines. The transmitted part is verified at the central computer, and the remaining part is verified at the terminal. No secret data is sent to the central computer, unless there is a positive verification of the part of the secret data retained at the terminal. Then only the remaining part of the secret data was transmitted over the connection lines.
Thus, it is impossible to determine the entire secret data by monitoring the connection lines.
It is also of particular importance that flexibility is obtained regarding the customer's choice of secret data when the identification card is issued. The customer is allowed to select secret data with any number of characters within a predetermined range of characters. Any combination of
7701611-1 alphabetic characters and numbers can be selected. This acts as a memory aid for the customer, as he can choose a combination of alphabetical characters and numbers that matter to him.
While a particular embodiment of the invention has been described and shown, it is to be understood that variations of the construction details and of the method which are particularly shown and described are possible without departing from the scope of the invention. It is clear, for example, that the principles of the invention can be used in connection with any security system using an identification card and secret data that the authorized cardholder keeps in mind, e.g. obtain access to a restricted area, point-of-sale credit transactions, and the like.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US4882779A | Cited by | United States of America | Search report |
3 priority claims, no other members on record
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 7701611 | Sweden | A | |
| 7701611 | – | – | – |
| SE19770001611 | – | – | – |
Numbers
- Publication, DOCDB
- 410129
- Publication, EPODOC
- SE410129
- Application
- 7701611
- Application, DOCDB
- 7701611
- Application, EPODOC
- SE19770001611
Titles2
- Swedish
- FORFARANDE FOR VERIFIERING AV ATT INNEHAVARE AV ETT IDENTIFIERINGSKORT ER EN AUKTORISERAD INNEHAVARE SAMT APPARAT FOR UTFORANDE AV FORFARANDET
- English
- PROCEDURE FOR VERIFYING THAT THE HOLDER OF AN IDENTIFICATION CARD IS AN AUTHORIZED HOLDER AND APPARATUS FOR CARRYING OUT THE PROCEDURE
Classification
- CPC, 2
- G07C11/00
- G07F7/10
- IPC, 2
- G07C11 00
- G07F7 10
