Method for carrying out a secure electronic transaction using a portable data support
Abstract
A method for carrying out a secure electronic transaction on a terminal using a portable data support is disclosed. According to the invention, a user (30) first authenticates themselves to the portable data support (20). The portable data support (20) generates quality information (20) on how the authentification occurred, which is verified for the terminal (14). The portable data support (20) then carries out a security-based operation within the context of the transaction, for example, the generation of a digital signature. The result of the security-based operation is added to the quality information.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
13 claims: 13 independent, 0 dependent
- 1P a t e n t a n s p r ü c h e 1. Verfahren zum Ausführen einer gesicherten elektronischen Transaktion an einem Terminal unter Verwendung eines tragbaren Datenträgers, wobei ein Nutzer sich gegenüber dem tragbaren Datenträger authentifiziert, der tragbare Datenträger dem Terminal den Nachweis der Authentifizierung bestätigt und der tragbare Datenträger anschließend im Rahmen der elektronischen Transaktion eine sicherheitsbegründende Operation ausführt, dadurch gekennzeichnet, daß der tragbare Datenträger (20) eine Qualität- sinf ormation darüber erstellt, auf welche Weise die Authentifizierung des Nutzers (30) erfolgte und diese Qualitätsinformation dem Ergebnis der sicherheitsbegründenden Operation beigefügt wird. Patent claim 1. Method for executing a secure electronic transaction at a terminal using a portable data carrier, whereby a user authenticates himself to the portable data carrier, the portable data carrier confirms the authentication to the terminal and the portable data carrier subsequently carries out a security-based operation as part of the electronic transaction, characterized, that the portable data carrier (20) creates a quality information about it, in which way the authentication of the user (30) took place and this quality information is added to the result of the security-based operation.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die durch den tragbaren Datenträger (20) ausgeführte sicherheitsbegründende Operation in der Erstellung einer digitalen Signatur besteht. Second Method according to Claim 1, characterized in that the security-based operation carried out by the portable data carrier (20) consists in the creation of a digital signature.
- 3Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Authentifizierung des Nutzers (30) durch Präsentation eines biometrischen Merkmales vorgenommen wird. Third Method according to Claim 1, characterized in that the authentication of the user (30) is carried out by presentation of a biometric feature.
- 4Verfahren nach Anspruch 3, dadurch gekennzeichnet, daß die Authentifizierung des Nutzers (30) durch Präsentation eines für einen Nutzer (30) charakteristischen physiologischen oder verhaltensbasierten Merkmales vorge- nommen wird. 4th Method according to Claim 3, characterized in that the authentication of the user (30) is carried out by presentation of a physiological or behavior-based feature characteristic of a user (30).
- 5Verfahren nach Anspruch 1 , dadurch gekennzeichnet, daß die Authentifizierung des Nutzers (30) durch Nachweis der Kenntnis eines Geheimnisses vorgenommen wird. 5th Method according to Claim 1, characterized in that the authentication of the user (30) is carried out by proving the knowledge of a secret.
- 6Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß für die Authentifizierung des Nutzers (30) wenigstens zwei verschiedene Authentifi- zierungsmethoden von unterschiedlicher Qualität angeboten werden. 6th Method according to Claim 1, characterized in that at least two different authentication methods of different quality are offered for the authentication of the user (30).
- 7Verfahren nach Anspruch 6, dadurch gekennzeichnet, daß die jeweils nicht eingesetzten Authentifizierungsmethoden gesperrt werden. 7th Method according to Claim 6, characterized in that the respectively unused authentication methods are blocked.
- 8Verfahren nach Anspruch 6, dadurch gekennzeichnet, daß für eine Au- thentifizierungsmethode keine Qualitätsinformation erzeugt wird. 8th. Method according to Claim 6, characterized in that quality information is not generated for an authentication method.
- 9Verfaliren nach Anspruch 1 dadurch gekennzeichnet, daß ein Nutzer (30) zur Auswahl einer Authentifizierungsmethode aufgefordert wird. 9th Verfaliren according to claim 1, characterized in that a user (30) is requested to select an authentication method.
- 10Tragbarer Datenträger zur Ausführung einer sicherheitsbegründenden Operation im Rahmen einer gesicherten elektronischen Transaktion, wobei sich ein Nutzer gegenüber dem tragbaren Datenträger authentifiziert und der tragbare Datenträger einem Terminal die Authentifizierung bestätigt, dadurch gekennzeichnet, daß er dazu eingerichtet ist, eine Qualitätsinfor- mation zu erstellen, welche angibt, auf welche Weise die Authentifizierung des Nutzers (30) durchgeführt wurde. 10th A portable data carrier for carrying out a security-based operation as part of a secure electronic transaction, wherein a user authenticates himself to the portable data carrier and the portable data carrier confirms authentication to a terminal, characterized in that he is set up to produce a quality information which indicates how the authentication of the user (30) was performed.
- 11Datenträger nach Anspruch 10, dadurch gekennzeichnet daß der tragbare Datenträger (20) zur Erstellung einer digitalen Signatur eingerichtet ist. 11th A data carrier according to claim 10, characterized in that the portable data carrier (20) is set up to produce a digital signature.
- 12Datenträger nach Anspruch 10, dadurch gekennzeichnet daß er wenigstens zwei qualitativ verschiedene Authentifizierungsmethoden unterstützt. 12th A data carrier according to claim 10, characterized in that it supports at least two qualitatively different authentication methods.
- 13Terminal zur Verwendung in Verbindung mit einem tragbaren Datenträger nach Anspruch 9, dadurch gekennzeichnet, daß es Mittel aufweist (16, 18) aufweist, um einen Nutzer (30) zur Auswahl einer von wenigstens zwei möglichen Authentifizierungsmethoden zu veranlassen 14. System zur Ausführung einer gesicherten elektronischen Transaktion, in deren Rahmen die Qualität der Authentifizierung eines Nutzers gegenüber dem System festgestellt wird, umfassend einen tragbaren Datenträger nach Anspruch 10 sowie ein Terminal nach Anspruch 13. 13th Terminal for use in connection with a portable data carrier according to claim 9, characterized in that it comprises means (16, 18) for causing a user (30) to select one of at least two possible authentication methods 14. A system for executing a secure electronic transaction determining the quality of authentication of a user to the system, comprising a portable data carrier according to claim 10 and a terminal according to claim 13.
Independent claims13
43 paragraphs, as filed
A method for performing a secure electronic transaction using a portable data carrier
The invention relates to a method according to the preamble of the main claim. Such is for example of the "Handbook of
Smart card ", W. Rankl, W. Effing, 3rd edition, 1999, p 692 bis703 titled" Digital Signature "known. When dealing with a legally binding electronic signature after a digital signature card to be used, on which a secret signing key. The imposition of a signature is at a suitable terminal from which the device obtains a document to be signed electronically. To make a signature, the user of the card through the terminal must prove his identity. Regularly this detection is done by entering a PIN (personal identification number), which is compared with a reference PIN stored in the card. In the future, provided that Nutzerauthentif ication by testing a biometric feature, such as a fingerprint make. If an electronic document signed after successful authentication of the user by means of a signature card, it can then in any manner passed on ben be. With the help of the electronic signature, it is possible, particularly safety-critical transactions, such as the issue of cost-prone service contracts to carry out electronically.
The intended implementation of biometrics for user zerauthentif ication is to further improve the reliability of an electronic signature opposite of the usual PIN authentication achieved because this ensures that use of the signature card can be carried out only in the presence of a defined, authorized person , The realized herein difference in quality in terms of Nutzerauthen- fication found in the usability of each electronic signature generated far but no precipitate.
The object of the invention to provide a method for performing a secure electronic transaction using a portable data carrier, the tion takes into account the quality of the underlying Nützerauthentifizie-.
This object is achieved by a method having the features of
Main claim. The object is further achieved by a portable data carrier, a terminal and a system for performing a secure electronic transaction according to independent claims 20, 25 and 30th
According to quality information on the used authentication method is generated when executing a user authentication by the exporting media. This document is attached to the result of a subsequently executed by the portable data carrier safety establishing operation. so is clearly visible for the recipient of a message thus formed, in which way a user has authenticated before performing sichheitsbegründenden operation. Thus, the recipient opens the possibility of the execution of a secured transaction on the quality of authenti- make tion dependent. So it can be provided for example in a wallet application, that the removal of a lying below a threshold amount of money can be made from an account after PIN authentication, the removal of exceeding the limit amounts of money on the other hand only after authentication by means of a biometric. Particularly advantageously, the inventive method is used in the context of electronic signatures.
In a preferred embodiment, the implementation of the various possible user authentication methods is such that the intermediate execution results of the high-low order method can not be converted in a simple manner in the execution intermediate results of a qualitatively higher standing method. This ensures that a manipulation of an authentication document itself is not possible if an unauthorized user both a portable data carrier as it is an associated low-authentication information is available, that is, if an unauthorized user has, for example, a portable data carrier together with an associated PIN.
the financing in the implementation of a Nutzerauthentifi- not used each authentication methods for the duration of the authentication are also advantageous blocked.
Referring to the drawing, an embodiment will now be explained in more detail example of the invention.
drawing
It 1 shows the structure of a system for making a digital
Signature,
Figures 2, 3 the course of the implementation of a digital signature as a flow chart. Figure 1 illustrates the basic structure of a transaction system for executing a secure electronic transaction. Key elements of the structure in terms of the invention are a background system 10, which is connected via a data network 12 to a terminal 14, a portable data carrier 20, which is carried by a user 30 and adapted to perform a security-establishing operation within a transaction is , and a record 40 which is to be handled safely in a transaction executed.
To ensure the secure electronic transaction will hereinafter from a
assumed transaction which requires the generation of a digital signature of the user on 30 pages. Such a transaction may be about the implementation of a banking business, in which the user's account is debited 30. The solution described is, however, not limited to transactions described that require a digital signature, but gundsätzlich used in any application in which a portable data carrier 20 machined from a terminal 14 supplied records 40 and returns to the terminal 14th
The background system 10 is representative of a device which carries out the actual transaction, about the movement of money between two accounts or the initiation of a goods delivery based on an order. The background system 10 can accordingly a complex, its existing system of many individual components or even entirely eliminated, in an extreme case. If the transaction is an account movement application, which is typically formed back- ground system 10 by a central bank office. The data network 12 is used for exchanging data between a terminal 14 and the background system 10. It may have any physical form and expression for example be realized through the Internet or a cellular network.
The terminal 14 forms the user-side interface of the transaction system and has this on display means 16, typically in the form of<sup>'</sup> an image display, and input means 18, for example in the form of a keyboard. The terminal 14 may be a public terminal such as a situated at a bank machine or a work in a user's private area 30 device, such as a PC or a mobile phone. The data network 12 so that a background system 10, one or more terminals can be connected to 14, which can be of different design. The terminal 14 has an interface 19 for communicating with a portable data carrier 20. The interface 19 may be of any physical type, in particular of a contact-type or of a non-contact type be.
The terminal 14 further has a designated in the following as a sensor, sensor means 15 for sensing a biometric feature of a user 30. The sensor 15 can be detected physiological characteristics, such as facial features, characteristics of the eye or Fingerabdrük- ke, or behavioral characteristics such as by voice or by writing operations expressed speech or writing sequences. In Fig.l a sensor as a fingerprint sensor 15 is indicated. The sensor 15 may be configured to receive a plurality of different biometric features. Part of the sensor 15 are further means for preliminary evaluation of a captured biometric feature. The recorded information can be reduced and certain, characteristic primary features recycled. The various types and the implementation of biometric authentication methods are described for example in the aforementioned "Smart Card Handbook", chapter 8.1.2.
The portable data carrier 20 is, for example, a smart card, as described in detail in also the "Smart Card Handbook". Figure 1 indicates for the portable media device 20, in particular a contact smart card with a contact pad 22 on which a to the terminal side interface 19 corresponding interface forms. via the interfaces 22, 19, communication between smart card 20 and the terminal 14. in addition to the form of a chip card, the portable data carrier having 20 any other shapes and for example, in a raised from users 30 garment, or from the user 30 entrained utensil be realized.
The portable data carrier 20 has an integrated circuit 24, which has all the elements of a conventional computer, in particular a microprocessor 25 and memory means 26. The microprocessor 25 is adapted to perform a security-establishing operation. For example, it is adapted to subject a supplied data record 40, which is hereinafter referred to as an electronic document 40, a cryptographic algorithm, whereby it uses at least one secret key, which is stored in the memory means 26th The microprocessor 25 is further adapted to, to realize additional functions in accordance with in the storage means 26 stored programs.
The portable data carrier 20 is further adapted to perform at least one, but advantageously several different methods Nutzerauthentifizierungsme-. Preferably, it supports at least two way view verschiedenwertige on the quality of authentication authentication methods. Suitably, it supports at least a knowledge-based authentication method, such as a PIN verification, and at least one biometric method, under which a check is made at the terminal 14 senting rendes biometric feature of the user 30th The biometric method constitutes here the higher quality, since it requires the physical presence of the user (30); in the knowledge-based method, this is not assured, the knowledge may have been acquired by an unauthorized user. According to at least one user-vorzulegendes 30 secret, or about a 30 to a user assigned reference PIN and at least one a user 30 associated biometric reference data are stored in the memory means 26th Suitably it may be provided that the portable data carrier 20 supports more than two authentication methods, in particular more<sup>'</sup> biometric methods. According to 26 more secrets and / or reference data records are stored in this case in the memory means and the integrated circuit 24 to set up, perform the further authentication methods.
Subsequently, the execution of a secure electronic transaction will be described using the structure shown in Figure 1 with reference to FIGS. 2 and 3 As sicherheitsbegründende operation is intended to be 40 signed an electronic document.
Introduced the use is by creating an electronic document 40 in the background system 10 or terminal 14, step 100. In general, the preparation is preceded by a triggering dialogue between a user 30 and the background system 10 via the terminal 14th By the time an electronic document 40 is present in the terminal 14, causes this the start of signature application, step 102. The Start initiative can be carried out automatically by the terminal 14 or the background system 10 or is initiated by the user 30, after the terminal 14 processing these to means of a suitable representation on the Anzeigevorrich- has 16 prompted ,
After the signature application is launched, presenting the user 30 to the terminal 40 a suitable portable data 2o, step 104. For the portable media device 20 in following the shape of a contactless smart card was used. Next is subsequently assumed that the smart card supports 20 different authentication methods, namely a PIN check as a knowledge-based, high niederwerti- ge method, and a fingerprint verification as biometric, higher quality method.
the terminal 14 has detected the presence of a smart card 20, it carries out a mutual authentication with this through, step 106, first, the IC card 20 to the terminal 14, their, then the terminal 14 of the IC card 20 proves its authenticity.
Running is authentication successful, act terminal 14 and chip card 20 dynamic session key to secure all further communication to perform the so-called "Secure Messaging" mode, step 108. For details on the concept of Secure messaging and dynamic session keys will turn on the " smart card Handbook "referenced.
Subsequently, the authentication of the user 30 relative to the smart card 20. This takes place initially checks the terminal 14, the manner in which - knowledge-based, so by entering a PIN or biometric, ie by presentation of a fingerprint - want to authenticate, step 110. The determination of an authentication method can be based on information provided to the electronic document 40 information automatically through the terminal 14, but they can also the display device 16 to the user submitted 30 as a decision request. In the latter case, the user shall, 30 by means of the input means 18 a decision.
If the authentication of the user 30 knowledge-based, ie done by entering a PIN, locks the smart card 20, the further possible authentication methods, ie the fingerprint check, step 112, and prompts the user 30 on the display device 16 to his PIN via the input means 18 enter.
The user 30 then enters via the input means 18, the PIN and the terminal 14 directs, directly or modified via the interface 19, 22 to the smart card 20 further step 114. The transmission of the PIN or the derived information such as the following communication with Cliipkarte is additionally secured using the negotiated session key. Suitably all communication between terminal 14 and chip card 20 in secure messaging mode.
This checks the transmitted PIN and confirms the positive case the terminal 14, the correctness, or aborts the process, if the PIN was checked as false, step 116th
Is the good case given, causes the terminal 14, the smart card 20 by corresponding instructions for performing the security-establishing opera- ration, ie the digital signature, and transmits the IC card 20 to be signed electronic document 40, step 118th
The smart card 20 signs the supplied electronic document 40 with the data stored in the storage means 22 secret key 120 and sends the electronic signature 40 back to the terminal 14, step 122, which thus continues the initiated electronic transaction.
If the check in step 110 that the authentication of the user 30 should not take place based on knowledge but biometrically, manages the terminal 14, authentication against presentation of a biometric feature and makes the smart card 20 an appropriate message, step 130. The Cliipkarte 20 then locks the now not used further outer thentifizierungsmethoden, ie the knowledge PIN verification, step 132nd
Below presents the user 30 of the terminal 14 according to the authentication method used a biometrisch.es feature ie a fingerprint, step 134. The Invitation to presentation of the fingerprint is preferably carried out by a corresponding display on the display device 16 of the terminal 14. The fingerprint is the at the terminal 14 provided for the sensor 15 detects.
The detected biometric feature, ie the fingerprint of the user 30 subjects the terminal 14 of preprocessing, in which it is extracted from the signal obtained at the sensor 15 certain characteristic features, step 136. When using a fingerprint, for example, primary characteristics of "classification method by Henry" are determined as it is described in "smart card Handbook". The extracted features received the terminal 14 via the interface 19, 22 to the portable data carrier 20, step 138th
Upon receipt of this there performs a verification of the transmitted extracted features by, step 140. Here, the integrated circuit 24 compares the resulting extracted features with the reference features stored in the storage means, and checks whether a sufficient match exists. If this is the case, confirmed the portable data carrier 20 to the terminal 14 the successful verification of the transmitting biometric feature, step 142. Next, the portable data carrier 20 switches to perform the intended security-establishing operation, ie ready to carry out a digital signature.
After receiving confirmation of a successful verification of the authentication, the terminal causes 14 the disk 20 through appropriate commands to perform the digital signature, step 144. Along with the commands of the portable data carrier 20 transmits the terminal 14 thereby to be signed electronic document 40, or at least Parts of it.
The integrated circuit 24 of the portable data carrier 20 then performs the steps necessary to create a digital signature operations, step as 146. Typically it forms here a hash value on the receive requested part of the electronic document 40 and encrypts it with a value stored in the storage means 26 secret key of an asymmetric, consisting of a secret key and a public key pair. Furthermore, the integrated circuit 24 forms a quality information, step 148, which confirms that the authentication of the user 30 using a biometric feature occurred. This quality information is then determined cherheitsbotschaft linked to the created digital signature to a safety, functional under the "Secure Messaging" mechanism using the previously negotiated session key.
The thus formed, consisting of a digital signature and quality information security Embassy sends the portable data carrier 20 back to the terminal 14, step 150. From here the transmitted security message during the running secure electronic transaction to the recipient involved in the transaction, such as a back- ground system 10, passed.
In addition to the modification by the portable data carrier 20 security-establishing operation while the recipient of the safety message obtained by the quality of information it contains an indication of the quality of the performed authentication of the user 30th
In above example, quality information was created only when using a biometric authentication method, not using a knowledge-based method. Thus the lack of quality information already indicated the use of a low- qualtitativ wertigeren method. Of course, it can be provided that the formation of a quality information is in principle, ie regardless of whether a knowledge-based or biometric method was used for authentication. While retaining the basic idea, the result of an executed by a portable data security-establishing operation accompanied by a quality information on the quality of the previously conducted Nutzerauthentif ication, allows the above-described concept Further refinements and modifications. This applies to the design of the system used in the execution of a transaction, which may include more components and other type. The procedure described may further include additional steps, such as intermediate steps.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2007113734A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO2007113734A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US8037522B2 | Cited by | United States of America | – | Applicant | – |
| WO0182190A1 | Cites | World Intellectual Property Organization (WIPO) | A | International search | – |
| WO02067091A2 | Cites | World Intellectual Property Organization (WIPO) | A | International search | – |
| EP1045346A2 | Cites | European Patent Office (EPO) | YA | International search | 1,3,4,6,10,12,14 |
| US4993068A | Cites | United States of America | YA | International search | 1,3,4,6,10,12,14 |
| US6263447B1 | Cites | United States of America | A | International search | 1,3-6,10,12,14 |
| US6408388B1 | Cites | United States of America | A | International search | 1,2,5,10,11,14 |
14 members in 9 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 10249801 | Germany | A | |
| 10249801 | Germany | A | |
| 102498016 | – | – | – |
| DE2002149801 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| DE10249801B3 | Germany | B3 | |
| WO2004038665A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003276154A1 | Australia | A1 | |
| BR0315675A | Brazil | A | |
| EP1573689A1 | European Patent Office (EPO) | A1 | |
| CN1708773A | China | A | |
| JP2006504167A | Japan | A | |
| RU2005115843A | Russian Federation | A | |
| US2006242691A1 | United States of America | A1 | |
| CN100365666C | China | C | |
| RU2397540C2 | Russian Federation | C2 | |
| JP4578244B2 | Japan | B2 | |
| US8205249B2 | United States of America | B2 | |
| EP1573689B1 | European Patent Office (EPO) | B1 |
11 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Entry into the national phaseENP | ENP | RU | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 2004/038665
- Publication, DOCDB
- 2004038665
- Publication, EPODOC
- WO2004038665
- Application
- 11761
- Application, DOCDB
- 0311761
- Application, EPODOC
- WO2003EP11761
Titles3
- English
- METHOD FOR CARRYING OUT A SECURE ELECTRONIC TRANSACTION USING A PORTABLE DATA SUPPORT
- German
- VERFAHREN ZUM AUSFÜHREN EINER GESICHERTEN ELEKTRONISCHEN TRANSAKTION UNTER VERWENDUNG EINES TRAGBAREN DATENTRÄGERS
- French
- PROCEDE PERMETTANT D'EXECUTER UNE TRANSACTION ELECTRONIQUE SECURISEE A L'AIDE D'UN SUPPORT DE DONNEES PORTABLE
Classification
- CPC, 8
- G07F7/1008
- G06Q20/341
- G06Q20/4014
- H04L9/3218
- H04L9/3231
- H04L9/3247
- H04L2209/56
- H04L2209/805
- IPC, 5
- G06F21 32
- G06F21 34
- G06F21 35
- G06F21 44
- G07F7 10
Designated states124
- Regional, 68
- African Regional Intellectual Property Organization (ARIPO)
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Mozambique
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Eurasian Patent Organization (EAPO)
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
- Tajikistan
- Turkmenistan
and 44 moreShow fewer
- European Patent Office (EPO)
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- African Intellectual Property Organization (OAPI)
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 56
- United Arab Emirates
- Antigua and Barbuda
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Brazil
- Belize
- Canada
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Croatia
- Indonesia
- Israel
- India
- Iceland
and 32 moreShow fewer
- Japan
- Democratic People’s Republic of Korea
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Lithuania
- Latvia
- Morocco
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Nicaragua
- Norway
- New Zealand
- Oman
- Papua New Guinea
- Philippines
- Poland
- Seychelles
- Singapore
- Syrian Arab Republic
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)
- South Africa