Method and system for generating a file of auditable logs relating to games using onsite and remote electronic means
Abstract
The invention relates to a method for the reliable auditing of a series of pre-established confidence requirements for a game using either onsite or remote electronic means. The invention involves the use of a game module with which the players interact, a security module and an auditing module which can have different degrees of dispersion and/or aggregation. The method is characterised in that: the game module supplies the security module with digital information containing significant events that occurred in the game; the security module generates a protected log for each of the aforementioned significant events; the security module stores each of the protected logs, thereby generating the file of protected logs; and, finally, the auditing module accesses the protected log file in order to check that the game progressed correctly. The method generates a protected log file which is independent of the game operator and which enables a third party to reproduce the game that occurred in a secure manner and to check that the game progressed correctly using pre-established criteria. Owing to the structure of the system thus defined, the reliability of the audit is based on the correct operation of the security module and the auditing module, without the game module being able to alter or disturb the result of the audits once the game has taken place.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
68 claims: 2 independent, 66 dependent
- 1REIVINDICACIONES 1. Método para permitir auditorías fiables de una serie de requisitos de confianza preestablecidos para unos juegos por medios electrónicos que incluyen una sucesión de eventos significativos de juego, en cual método se utilizan un módulo de juego, destinado a interactuar con al menos un jugador, un módulo de seguridad destinado a Ia generación de un archivo digital de registros protegidos que toma en consideración al menos un subconjunto de dichos eventos significativos de juego, y un módulo de auditoría destinado a Ia generación de una información de auditoría del juego acontecido, susceptibles de diversos grados de dispersión y/o agrupación, y unos protocolos criptográficos destinados a Ia protección de dichos registros, comprendiendo dicho método, para cada uno de dichos eventos significativos tomados en consideración para Ia generación de dicho archivo digital de registros protegidos, las siguientes etapas:a) aportación, por parte de dicho módulo de juego a dicho módulo de seguridad, de una información digital que contiene al menos parte de dicho evento significativo tomado en consideración;b) generación en dicho módulo de seguridad de un registro protegido a partir de dicha información digital de dicha etapa a);y c) almacenamiento de dicho registro protegido, dando lugar a un archivo digital de registros protegidos, y realizándose, en dicho módulo de auditoría, una verificación del correcto desarrollo del juego acontecido, a partir de al menos una parte de dicho archivo digital de registros protegidos que incluye un determinado número de dichos registros protegidos seleccionados en función de un criterio de auditoría.
- 2Método según Ia reivindicación 1 , caracterizado porque dicho subconjunto de dichos eventos significativos de juego es el total de los eventos significativos acontecidos durante el juego.
- 3Método según Ia reivindicación 1 caracterizado porque dicha información digital aportada en dicha etapa a) está marcada digitalmente por dicho módulo de juego para impedir Ia manipulación fraudulenta de dicha información digital.
- 4Método según Ia reivindicación 3 caracterizado porque dicha marca digital es una firma digital asimétrica.
- 5Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a Ia autenticación de un jugador que accede a dicho módulo de juego.
- 6Método según Ia reivindicación 5 caracterizado porque dicha autenticación se realiza mediante al menos una de las técnicas del grupo que comprende al menos Ia validación de un nombre de acceso y una palabra clave asociados previamente a dicho jugador, Ia utilización de una infraestructura de clave pública, o el uso de unos patrones biométricos asociados unívocamente a dicho jugador.
- 7Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a Ia localización geográfica de un jugador que accede a dicho módulo de juego.
- 8Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a una elección o decisión relativa al juego por parte de un jugador.
- 9Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a un proceso de generación de un evento azaroso del juego.
- 10Método según Ia reivindicación 9 caracterizado porque dicho evento azaroso es generado individualmente por dicho módulo de juego.
- 11Método según Ia reivindicación 9 caracterizado porque dicho evento azaroso es generado individualmente por dicho módulo de seguridad.
- 12Método según Ia reivindicación 11 caracterizado porque dicho evento azaroso es generado en base a un generador de números aleatorios contenido en dicho módulo de seguridad.
- 13Método según Ia reivindicación 11 caracterizado porque dicho evento azaroso es notificado a dicho módulo de juego y dicha información digital enviada en dicha etapa a) por dicho módulo de juego corresponde a una solicitud de evento azaroso o a una confirmación de recepción del mismo.
- 14Método según Ia reivindicación 13 caracterizado porque dicha notificación a dicho módulo de juego está marcada digitalmente para garantizar que dicho evento azaroso ha sido generado por dicho módulo de seguridad y que no ha sido manipulado.
- 15Método según Ia reivindicación 14 caracterizado porque dicha marca digital es una firma digital asimétrica.
- 16Método según Ia reivindicación 9 caracterizado porque dicho evento azaroso es generado de manera compartida entre dicho módulo de juego y dicho módulo de seguridad.
- 17Método según Ia reivindicación 16 caracterizado porque dicha información digital enviada en dicha etapa a) por dicho módulo de juego corresponde a una información digital del grupo que comprende al menos una solicitud de generación compartida de evento azaroso, una confirmación de generación de evento azaroso, o unos datos necesarios para dicha generación compartida.
- 18Método según Ia reivindicación 17 caracterizado porque el resultado de dicha generación compartida está marcado digitalmente para garantizar que dicho resultado ha sido generado de manera compartida por dicho módulo de juego y dicho módulo de seguridad, y que no ha sido manipulado.
- 19Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a un establecimiento o a una actualización de unos parámetros relativos a una cuenta de un jugador.
- 20Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a un pago de un premio.
- 21Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde a una notificación por parte de dicho módulo de juego a un jugador.
- 22Método según Ia reivindicación 1 caracterizado porque dicho evento significativo de dichas etapas a), b) y c) corresponde al abandono del juego o de Ia partida por parte de un jugador.
- 23Método según Ia reivindicación 1 caracterizado porque dicho archivo digital de registros protegidos de dicha etapa c) se almacena en una base de datos.
- 24Método según Ia reivindicación 1 caracterizado porque dicho archivo digital de registros protegidos de dicha etapa c) se almacena en un dispositivo de almacenamiento de escritura de una sola vez.
- 25Método según Ia reivindicación 1 caracterizado porque dicho archivo digital de registros protegidos de dicha etapa c) se almacena independientemente de dicho módulo de juego.
- 26Método según Ia reivindicación 1 caracterizado porque dicho registro protegido generado en dicha etapa b) se protege mediante el uso de protocolos criptográficos y al menos una clave.
- 27Método según Ia reivindicación 26, caracterizado porque dicha clave está guardada en dicho módulo de seguridad con medidas de protección física.
- 28Método según Ia reivindicación 27 caracterizado porque dichas medidas de protección física incluyen al menos Ia utilización de un dispositivo del grupo que comprende al menos un sistema hardware sellado o una tarjeta inteligente.
- 29Método según Ia reivindicación 1 caracterizado porque Ia protección de dicho registro protegido generado en dicha etapa b) se realiza mediante al menos una marca digital para garantizar Ia autenticidad e integridad de dicho registro protegido.
- 30Método según Ia reivindicación 29 caracterizado porque dicha marca digital es una firma digital asimétrica.
- 31Método según Ia reivindicación 1 caracterizado porque Ia protección de dicho registro protegido generado en dicha etapa b) se realiza mediante al menos una marca digital para garantizar Ia ordenación de dicho registro protegido dentro de Ia secuencia de registros protegidos generados durante el juego.
- 32Método según Ia reivindicación 31 caracterizado porque dicha marca digital contiene al menos un número de secuencia.
- 33Método según Ia reivindicación 31 caracterizado porque dicha marca digital contiene al menos un valor resumen encadenado.
- 34Método según Ia reivindicación 29 ó 31 caracterizado porque dicha marca digital se almacena en dicha etapa c) conjuntamente con dicho registro en dicho archivo de registros protegidos.
- 35Método según Ia reivindicación 29 ó 31 caracterizado porque dicha marca digital se mantiene en dicho módulo de seguridad asociada a un cierto número de dichos registros, almacenándose en dicha etapa c) en dicho archivo de registros protegidos después de dicho cierto número de dichos registros.
- 36Método según Ia reivindicación 1 caracterizado porque dicha verificación realizada en dicho módulo de auditoría comprende Ia comprobación de Ia autenticidad e integridad de dichos registros protegidos de dicha parte de dicho archivo de registros protegidos.
- 37Método según Ia reivindicación 1 caracterizado porque dicha verificación realizada en dicho módulo de auditoría comprende Ia reconstrucción, a partir de dicha parte de dicho archivo de registros protegidos, de dichos eventos significativos acontecidos en el juego.
- 38Método según Ia reivindicación 37 caracterizado porque dicha verificación realizada en dicho módulo de auditoría comprende el análisis de dichos eventos significativos de juego reconstruidos, para verificar un conjunto de requisitos preestablecidos esenciales para Ia confianza y el desarrollo honesto de dichos juegos por medios electrónicos.
- 39Método según Ia reivindicación 38 caracterizado porque dicho análisis se realiza en base a unas reglas de dichos juegos y/o unas condiciones preestablecidas, que incorpora dicho módulo de auditoría y/o que Ie son suministradas.
- 40Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación de Ia condición de jugadores autorizados respecto de los jugadores que han participado en el juego por medios electrónicos.
- 41Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación de Ia honestidad del juego, comprobando el correcto comportamiento de dicho módulo de juego en base a las reglas de cada juego.
- 42Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación de Ia imparcialidad del juego, comprobando Ia correcta generación de los eventos azarosos.
- 43Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación de Ia inexistencia de movimientos y decisiones de juego sospechosas de fraude.
- 44Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación del ajuste del desarrollo del juego a unos parámetros preestablecidos y/o determinados por las cuentas de cada jugador.
- 45Método según Ia reivindicación 44 caracterizado porque dichos parámetros son algunos del conjunto que contiene entre otros los importes máximos a jugar por partida o los importes máximos a jugar mensualmente.
- 46Método según Ia reivindicación 38 caracterizado porque dichos requisitos incluyen al menos Ia validación del correcto pago de premios.
- 47Método según Ia reivindicación 1 caracterizado porque tras dicha verificación, dicho módulo de auditoría realiza una etapa adicional de generación de al menos un informe de auditoría.
- 48Método según Ia reivindicación 47 caracterizado por el envío de al menos parte de dicho/s informe/s de auditoría a dicho jugador.
- 49Método según Ia reivindicación 48 caracterizado porque dicho envío se realiza mediante al menos uno de los medios del grupo que comprende al menos un mensaje al teléfono móvil de dicho jugador, Ia publicación en un sitio Web accesible a dicho jugador, o un correo electrónico a dicho jugador.
- 50Sistema de juego por medios electrónicos que genera un archivo de registros protegidos que permite verificar Ia confianza de unos juegos por medios electrónicos que incluyen una sucesión de eventos significativos, para implementar el método descrito en las reivindicaciones 1 a 49, comprendiendo:a) un módulo de juego con el que interactúa al menos un jugador, configurado para llevar a cabo el desarrollo del juego y que integra: i. unos medios de entrada y salida de datos para transmitir al menos una información digital que contiene al menos parte de unos eventos significativos de juego;ii. unos medios de procesamiento;iii. unos medios de presentación o envío de al menos algunos de dichos eventos significativos a dicho jugador;iv. unos medios de introducción de datos que permitan a dicho jugador seleccionar unas acciones y/o tomar unas decisiones de juego;caracterizado porque comprende los siguientes módulos adicionales: b) al menos un módulo de seguridad adaptado para su interconexión o integración con dicho módulo de juego, que genera, a partir de al menos un subconjunto de dichos eventos significativos del juego, unos registros protegidos, almacenando todos ellos en un archivo de registros protegidos, integrando dicho módulo de seguridad: i. unos medios de procesamiento;ii. unos medios de entrada y salida de datos para obtener al menos dicha información digital aportada por dicho módulo de juego que contiene al menos parte de dichos eventos significativos;iii. unos medios de almacenamiento para almacenar dichos registros protegidos una vez generados;y c) un módulo de auditoría adaptado para tener acceso a dicho archivo de registros protegidos, que comprende: i. unos medios de entrada y salida de datos para al menos acceder a parte de dicho archivo de registros protegidos almacenado por dicho módulo de seguridad;y ii. unos medios de procesamiento para procesar información relativa a dichos registros protegidos de dicho archivo.
- 51Sistema según Ia reivindicación 50 caracterizado porque dispone de medios para proporcionar una interacción presencial, a través de un sistema tal como un terminal de video lotería, de dicho jugador con dicho módulo de juego.
- 52Sistema según Ia reivindicación 50 caracterizado porque dispone de medios que facilitan una interacción remota, a través de una red de comunicación tal como Internet, de dicho jugador con dicho módulo de juego.
- 53Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de seguridad comprende un submódulo criptográfico y un submódulo de almacenamiento.
- 54Sistema según Ia reivindicación 53 caracterizado porque dicho submódulo criptográfico integra un hardware sellado que proporciona medidas de protección física a al menos parte de dichos medios de procesamiento de dicho módulo de seguridad y/o al menos parte de dichos medios de almacenamiento de dicho módulo de seguridad.
- 55Sistema según Ia reivindicación 54 caracterizado porque dicho hardware sellado es escogido del grupo que comprende al menos un módulo hardware de seguridad, una placa criptográfica, o un dispositivo extraíble tal como una tarjeta inteligente.
- 56Sistema según Ia reivindicación 53 caracterizado porque dicho submódulo de almacenamiento es un servidor de bases de datos.
- 57Sistema según Ia reivindicación 53 caracterizado porque dicho submódulo de almacenamiento se encuentra físicamente separado de dicho submódulo criptográfico y ambos disponen de unos medios de entrada y salida de datos para interconectarse a través de una red de comunicación tal como Internet.
- 58Sistema según Ia reivindicación 53 caracterizado porque dicho módulo de auditoría tiene acceso a dicho submódulo de almacenamiento para obtener al menos parte de dicho archivo de registros protegidos.
- 59Sistema según Ia reivindicación 50 caracterizado porque dichos medios de procesamiento de dicho módulo de seguridad comprenden un generador de números escogido del grupo que comprende al menos un generador hardware de números aleatorios o un algoritmo de generación de números pseudoaleatorios.
- 60Sistema según Ia reivindicación 50 caracterizado porque dichos medios de almacenamiento de dicho módulo de seguridad que almacenan dicho archivo de registros protegidos emplean un dispositivo de una sola escritura tal como un WORM ("write once, read many").
- 61Sistema según Ia reivindicación 50 caracterizado porque dichos medios de almacenamiento de dicho módulo de seguridad están adaptados para almacenar al menos una clave para su uso en operaciones criptográficas a partir de al menos parte de dicha información digital recibida por dichos medios de entrada y salida y que contiene al menos dichos eventos significativos.
- 62Sistema según Ia reivindicación 61 caracterizado porque dichos medios de almacenamiento de dicho módulo de seguridad están adaptados además para registrar al menos parte del resultado de dichas operaciones criptográficas.
- 63Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de juego comprende también unos medios de almacenamiento de al menos una clave para su uso en operaciones criptográficas a partir de al menos parte de una información introducida mediante dichos medios de introducción de datos y/o al menos parte de dicha información digital recibida por dichos medios de entrada y salida.
- 64Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de juego no tiene interconexión con dicho módulo de auditoría.
- 65Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de juego y dicho módulo de seguridad se encuentran interconectados lógicamente.
- 66Sistema según Ia reivindicación 65 caracterizado porque dicha interconexión lógica es una API ("Application Programming Interface").
- 67Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de seguridad está conectado a un solo módulo de juego o a un número de módulos de juego mayor que uno.
- 68Sistema según Ia reivindicación 50 caracterizado porque dicho módulo de auditoría está conectado a un solo módulo de seguridad o a un número de módulos de seguridad mayor que uno.
Independent claims68
80 paragraphs in 1 section, as filed
<sup>0 O</sup>F<sup>)</sup> S / n not 4no
1
METHOD AND SYSTEM FOR GENERATING A RECORD auditable GAMES BY ELECTRONIC MEDIA AND REMOTE CLASSROOM
Field of the Invention
The present invention describes a method and a system for ensuring Ia features regarding trust (such as honesty and fairness Ia) in the implementation of electronic games. This is achieved by recording the activity developed in these games and the safe storage, using cryptographic operations. a file of protected records that allows reliable periodic audits game actions occurred, thus providing more confidence on it is thus generated. The present invention is applicable to electronic games offered both in person and remotely (via a communication network).
The system applies to games by electronic means of the present invention introduces two modules or different functional parts. The first security module is essentially intended to protect digital information using cryptographic tools. The second audit module allows verifying the honesty and fairness of the game when playing part of Io happened in the game, using in case of the game logic is necessary. All this without interfering too much in Ia usual dynamic game by players.
Background of the Invention
In the electronic game players participate in game play by means of using electronic systems, computer systems and / or communications networks. Sometimes it is traditional gaming electronically. In these cases, the player interacts directly with an electronic gaming machine located in a game center or in a given facility to which the player must move to play. At other times it is remote electronic game where the player interacts remotely with the electronic game system, usually by means of using your computer with a connection to the Internet or an equivalent network. The variety of games offered in both modes is extensive: Game Center games like roulette or blackjack Ia, sports betting, poker games, bingo machines, rollers, and so on.
The game electronically, in all its forms, leads to a lack of transparency that can give rise to problems of mistrust regarding critical aspects of honesty and fairness. In fact, at times lack of transparency Ia electronically game has managed to successfully use fraudulent purposes. That is why Ia gaming industry has been using two mechanisms to try to ensure the smooth running of the games. On the one hand, the certification of the source code of computer programs that determine the functioning of electronic gaming. On the other hand, the audit statistics distribution of awards.
However, both mechanisms have serious deficiencies. Indeed, Ia certification program source code is actually playing a system inspection carried out in a determined by an independent laboratory time. You can therefore get to ensure that at that moment the system had a correct design that would result for both honest behavior. However, Ia certification of the source code has no ability to demonstrate that the system will maintain at all times the same design and correct behavior. You can be certified programs module electronic game today, but maybe tomorrow will have been manipulated or replaced, either accidentally or intentionally. Although there are procedures to verify the existence of changes or manipulations in a computer program, Ia real possibility of replacing with great ease and speed critical modules correct by manipulated and vice versa relegates in Ia practice, these procedures all probability of success as security measures. Io regard to subsequent audits of the percentage distribution of prizes, they seek to assure the correct operation of electronic gaming systems to contrast the publicly known statistics of each game in particular with the actual data of awards given. Unfortunately, these audits can only ensure that prizes have been distributed in a correct percentage in relation to the total volume played. However, they are completely unable to demonstrate fairness or honesty Ia game offered. In fact, a certain fraction of the awards may have been deliberately given to certain players with the aim of carrying out money laundering or simply for economic gain at the expense of cheating players.
Given the aforementioned limitations of the main control mechanisms used in Ia electronic game industry, there are still problems at the present time primarily distrust of the game, electronically or electronic game. Include the following:
1. In the case of remote electronic game, there is the problem of the identification of the players. A remote identification of low quality allows fraudulent actions, such as money laundering, and also allows access to the game by players who should be banned, as is the case of minors.
2. In the case of electronic game based on randomly generated electronically (virtually Ia all variants of electronic game with Ia except for some as in the case of sports betting), there may be reasonable doubt about Ia fraudulent manipulation of the generation of the chance to predict or influence in some way future random events.
3. Possible subsequent audits game development are based on records generated by the electronic game system itself. However, these records are inadequately protected against internal attacks (eg by staff technician privileged access to electronic gaming system), by Io that Ia veracity of the records is compromised.
Then discussed in more detail each of these three problems and the solutions proposed to date to mitigate Ia. The identification of electronic game players in the remote has been supported to date basically Ia Ia Ia ownership of credit card used for the flow of gambling money and awards. However, this identification mechanism is clearly insufficient since anyone can impersonate another with only access to the card credit of the second (relatively easy in the case of members of the same family or in cases of theft, for example). Moreover, this mechanism is not satisfactory for management Ia self-excluded lists or lists of problem gamblers. Identifying players based on Ia ownership of credit cards it has also been combined with the mechanism of "login / password". It is these cases, the identity of the user is verified by checking the "password" introduced corresponds to the generated in a previous user registration process. However, the mechanism of "login / password" presents a set of weaknesses well known that Io make it unsuitable for use in networks of communication open. Not only passwords can be intercepted (Ia facilitating unauthorized impersonation), but also are also susceptible to attacks such as "phishing", Trojans, or brute force attacks, among others. A complete study of the weaknesses of the mechanism of "login / password" can be found in [A. Shimizu, T. Horioka and H. Inagaki, A password authentication methods for communication on the Internet contents, IEICE Transactions on Communications, vol. E81-B, no. 8 pp. 1666-1673, Aug. 1998] or [F. Bao, Security Analysis of a Password Authenticated Key Exchange Protocol, Proceedings of 6th Information Security Conference - ISC 2003, LNCS 2851, pp. 208-217, Springer-Verlag Heidelberg, 2003, ISSN: 0302-9743, Information Security: 6th International Conference, ISC 2003, Bristol, UK, October 1-3, 2003. Proceedings, ISBN: 3-540-20176-9] .
Recent proposals suggest means of using biometric mechanisms to assure the correct identification of the players, either in environments electronic game face and remote electronic gaming environments. To cite some proposals, the inventions described in US6612928, US2004192438 and US2004192442 are examples remote electronic gaming environments. The patent US2002160834 proposes a solution where the biometric reader is located in different kiosks, therefore they are suited to environments face electronic game. However, biometric identification Ia presents its own disadvantages. On the one hand, it is too intrusive for the player. On the other hand, in environments electronic gaming remote, it remains unresolved Ia need to ensure that the reading of the biometric pattern is performed at the precise moment of the game and is not appropriate, however, a previous reading.
With respect to the reliability of the generation electronically chance, Ia root of the problem is introducing a vulnerability Ia overly centralized generation. Indeed, electronic modules set current onic all control of the generation of randomly placed in one central point (always in the hands of the gaming operator and / or its employees). There are previous proposals in order to overcome problems of fraudulent derivatives random generation of this vulnerability. These proposals are based on the generation of random shared between several parties, without any of them (especially the gaming operator) represents a central point of control. Using these methods allows generation shared assure the impartiality of the resulting random numbers, provided that the various parties do not cooperate fully. Not just any party can manipulate the result of the co - generation of electronically generated random event, but also neither party has privileged information regarding future random events. Representative examples of shared or collaborative generation of random numbers are on the one proposed in 1982 Manuel Blum [Blum M., Coin Flipping by telephone: a protocol for solving impossible problems, Proc. IEEE Computer Conference, pp. 133-137, IEEE, 1982] or Ia proposal Joe Kilian 1990 [Kilian, J., Uses of randomness in algorithms and protocols, ACM Distinguished Dissertation, MIT, 1990, ISBN: 0-262-11153-5] . Previous inventions described in US 6,099,408, US 6,030,288, WO2004035159 or WO2005021118, take advantage of this type of shared or collaborative mechanisms for generating random numbers to try to assure the fairness of the game. However, the main problem is that these proposals suffer Ia little practical realization, requiring the active participation of the players in Ia shared random generation. This creates, in Ia practice, a dependence on the behavior of unknown systems and a high degree of heterogeneity, such as client systems used by players. A possible variant, which consists of the shared generation Ia delegation to a third party not directly controlled by players, would exceed this technical limitation. However, in this case the players might not be able to verify themselves Ia impartiality of the generation of random.
There are additionally other proposals that turn out to be, at best, partial solutions to potential security problems in game development but in no case develop solutions to the problem of impartiality chance. For example, some prior inventions describe methods and / or related Ia game operation by electronic means, such as those disclosed in US 4,926,327, US 5,038,022, GB 2,307,184 systems. Other inventions Ia focus on security at the network level, using cryptosystems between the different participants in the game to ensure such communications security Ia, but without proposing solutions to the problems of fairness and honesty Ia above. Some representative examples of these inventions are described in US 6,106,396, 6,117,011, WO9811686 and references US6.264.560.
Finally, the third issue of trust not properly resolved electronic game refers to the capacity of inspection and audit of these systems. It is obviously necessary to maintain a reliable and independent control extemal, about the essential characteristics of honesty of a game module electronically. These essential features include controlling the identity of the players, Ia honesty of the development of the games, and play adjusting to the limitations imposed by the regulation or by scores of each player (for example, referring to maximum you can bet monthly). Currently, however, the external control of these features is based on audits that rely on excessive measure data provided by the operator of game data that otherwise are not sufficiently protected and can be manipulated too easily. There are to date proposals efficient enough to propose methods to perform safely happened these audits game. In classroom environments gaming electronically, some inventions considered various contributions to guarantee a certain level of security. For example, in the detection of fraud US200424321 proposes running Io happened in the game on two different machines and monitoring the second to detect fraud. The proposal of the invention US2004198494 is to use a cryptographic device to assure the security module play, by preventing access to unauthorized persons and / or tampering. However, the audit method proposed inventions is both inefficient and does not provide Ia security needed to be applied in real environments games electronically. Indeed, it comes solutions involving the use of a large volume of digital information as they use the entirety of the information Io happened during the game. In addition, these proposals do not provide mechanisms to ensure that the digital information to be audited has not been manipulated during the game or even once it is complete.
In summary, it can be noted that in all previous proposals known to the inventors an operation of the game covering a complete cycle in which the player himself, not directly involved in the generation of chance is not specified, you can verify that the game was made honestly and impartially. In addition, the audit process, which generally has not been considered in previous inventions, resulting in the known proposals Io deal, expensive (given the large volume of data processed in real time during the development of the game itself) and unreliable (by relying on data without adequate protection). In addition, the audit process does not yield any reliable conclusions regarding the identities of the players who participated in the games. SUMMARY OF THE INVENTION
In the present invention a method and a system which allow to provide an electronic game system, either face (in kiosks game) or remote (via a communication network such as the Internet), of the capacity to generate confidence proposed . By faith we understand Ia assurance or guarantee on criteria such as Ia honesty and fairness in the development of the games. This objective is achieved by means of creating a file of protected records that allows third parties (such as auditors or regulators), or the players themselves, verify that the different events happening during the game respond to an honest development thereof (based on the rules of each game), to a fair random generation (in those games where required), and restrictions imposed of various kinds (eg age of the players or play maximum amounts).
The present invention introduces two additional means of using modules in conjunction with a game module. The first of them, the security module is primarily responsible for generating secure Ia protected records that allow play Io happened later in the game. Additionally, this security module is responsible for Ia honest generation of random events (where required). The second additional module introduced in the present invention, named audit module, takes as input the protected records generated by the security module for reliable reproduction occurred Ia game. Thus, the module generates audit reports on the various relevant factors Ia trust and honesty electronic gaming module. The provision of reports of these players allows them to verify the correct development of the game even when Ia use of the method proposed in the present invention has been transparent to the players during the execution of the game.
Thus, the present invention discloses in a first aspect a method for the generation of secure and auditable records containing information to reconstruct Io happened during the game to see if there have been fraudulent or not operations. The invention also relates in a second aspect the characteristics of said security module and the said audit module associated module game and which allow the implementation of this method.
A long Io of Ia present invention means significant event of that game action or event that reflects an important game event that determines the development of a game play in its main aspects. An object of the present invention is to generate records of such significant events that characterize the development of the game, and provide these records protection against manipulation. To that end, the security module interacts with the module records and generates game based on the data provided by the game module. The security module incorporates cryptographic protocols that enable to provide protection to records once generated. All this results in a file of protected records. The security module protects each record individually with cryptographic measures and also protects Ia entire sequence of records to avoid alterations in the order of records or deletions of the sequence. In addition, cryptographic protections developed in the present invention are particularly efficient, although based in part on a digital signature (operation generally is considered costly in computational point of view).
It is also an object of the present invention provide third parties the audit process electronic game. For this purpose the invention incorporates the audit module that enables reliable audits and time efficient Ia, from the file of protected records. Cryptographic protections made by the security module for the generation of records allow the audit module to verify that the records have been generated by a correct security module and have not been subsequently altered. They also allow to verify that the sequence of records is complete and in the original order.
The proposed division in two modules, security and audit system is a novel feature that enables a game control bit Ia intrusive dynamics of development of games electronic gaming module. The displacement of all Ia intelligence (for example, the various sets of logic or control the various game variants) to audit module makes the security module in a single module secure registration. This entails great advantages of performance and flexibility. On the one hand, the overall system performance benefits, since the security module performs real-time critical tasks that affect the development of the games. On the other hand, the evolution of games (introduction of new methods or alteration of established rules) only affects the audit module, less sensitive for the development of games in real time. Indeed, the security module is integrated or interfaced with the game module, and in constant communication with it. By contrast, the audit module can act in complete disconnection with the game module. Thus, although underperforming security module could adversely affect the overall performance of game module perceived by players not happen Io same with insufficient performance audit module. In the latter case, the development of the game and the interaction between players and game module would not be affected at all. Another object of the present invention is to allow the security module actively involved (in gambling) in the determination of electronically generated random events. This is achieved either by Ia full generation of such events or by generation Ia shared game module itself. In this respect, the present invention aims to ensure fair game development and Ia auditability of such impartiality. This is higher than other previous inventions objective, which is limited to guaranteeing the impartiality of the generation of random numbers base.
An important improvement of the present invention over prior inventions is Ia guarantee players about fairness and honesty Ia electronic game without involving them directly in the control process or the process of generating random. This substantially improves the efficiency of the resulting protocol. It is an objective of the present invention allow players to delegate to a third party controlling the honesty of the game, providing mechanisms to verify that the delegation has resulted in an effective and rigorous control. The present invention provides a suitable combination of physical protection measures (through sealed systems hardware) cryptographic protocols. This combination keeps a file of protected records in a data base maintained in conventional own game operator premises without the records stored therein may be affected by manipulations.
Last but not least, the present invention has as an additional objective to support the control of the identity of the players, with the possibility of an audit by third parties. Thus, the invention integrated into a single system controlling the fairness and honesty in developing games with controlling the identity of the players.
The proposed in the present invention method is characterized by comprising the following basic steps, performed for a subset or all of the significant events that occurred game: contribution by the game module to the security module of digital information containing an event significant game; generating in said security module protected for each significant event has been received content in the digital information provided by the game module registration; storing said protected record, resulting in a file of protected records. The method also comprises a step of verifying the correct development of the game, made in the audit module from the information contained in the file of protected records. This verification step can be performed during the game or, for example, after completion, depending on the different audit criteria considered.
Should fraudulent transactions have occurred in the module of play during the game, the method ensures the detection of such shares through reliable audits. The method also contemplates the possibility that the player instantly receives information for various channels, Ie possible to verify the correct development of the game, possibly in real time.
For those cases where it is required the electronic generation of chance, the method includes three possibilities: generation individually by the game module generation individually by the security module, or shared generation between the game module and the module of security. In all cases the generation process is properly recorded to enable a subsequent audit of the same.
The security module used in the system for the implementation of the proposed method comprises, in its most basic version, the following: processing means, means of input and output data for a digital information related to significant events game, and storage means for storing the generated protected records. The security module is divided, in a variant preferred embodiment, in a cryptographic submodule providing physical security measures and storage submodule. The cryptographic submodule could be implemented as a Hardware Security Module (or HSM). Storage sub-module may be implemented as a database server. The audit module used in the system for the implementation of the proposed method comprises, in its most basic version, the following elements: input means and output data Ie allow access to the file of protected records stored by the security module, and processing means which allow Ie process information concerning protected records contained in the file of protected records.
Other features of the present invention, specifically, the particular characteristics of the method steps and the constituent elements of the security modules and audit will be described in greater detail below further illustrated with sheets of drawings. BRIEF DESCRIPTION OF THE DRAWINGS
a player or a plurality of them interact with a game module: Figure 1 shows a simplified manner the main elements on which the method and system of the present invention is implemented. This game module is connected to a security module which, together with the audit module is responsible for guaranteeing the honesty and impartiality of Ia electronic games that develop. Figure 2 illustrates schematically the main steps characterizing the proposed method in the present invention. The game module security module provides the digital information related to a significant gaming event. Then the security module generates a protected record associated with this significant event and stores each of these protected, giving rise to a log file records protected. Finally, the audit module to access sometime protected log file to verify the correct development of the game occurred from significant events.
As shown in Figure 3, the authorized parties (such as the case of auditors) have access to the information generated audit the audit module. These authorized parties can conveniently send some players report indicating information regarding Io happened in the game. Such reports allow the player to verify the correction of Io happened in the game (eg concerning Ia Io impartial generation of chance).
The present invention concerns both remote electronic games and face, as the sample Figure 4.
Figure 5 shows some of the basic elements that relate to the game or module that can be integrated. A registrar who is primarily responsible for controlling the identity of the players entering the game, a gaming operator who represents the owner or manager game module, a bank that provides a payment gateway for economic transactions relating to games, and finally, an auditing entity is responsible for verifying that the game develops or is successfully developed.
Figure 6 shows the two sub-modules in which you can divide the security module. On the one hand, the cryptographic submodule, which in a preferred implementation contains a random number generator (PRNG), which provides protection for records generated based on the significant events occurred game. Furthermore, the storage submodule, wherein the protected file is stored records. As shown in Figure 7, said file of protected records is formed by the succession or sequence of different protected records previously generated by the security module.
DETAILED DESCRIPTION OF THE INVENTION
The present invention proposes the use, in conjunction with a gaming module electronically, either in person or remotely, an independent unit that allows guaranteeing the honesty and trust operations developed game. The independent unit introduced in the present invention is connected or integrated with the game module and its main missions as follows:
- Participate in the generation of random whenever Ia Io game logic requires; - Maintain a file of protected records; and finally,
- Enable the embodiment of reliable audits on the development of the game.
More specifically, the present invention introduces for that purpose two distinct modules (although susceptible to varying degrees of aggregation and / or dispersion): a security module and an audit module (see Figs 1 and 3.). Both make the mentioned independent unit. The security module is intended for the generation and the protection of records relating to the main events happening during the game. The security module preferably incorporates a cryptographic hardware that performs this task safely against potential attacks and / or manipulation. The security module stores the generated records in a file (called file protected records). This file can optionally be stored in a device that prevents writing one further manipulation.
For its part, the audit module is designed to ensure the correct development of the games from the information contained in the file of protected records (for this, the audit module has access to protected log file). The present invention contemplates the possibility that this verification is carried out in real time as the game develops, and also the possibility that this verification is carried out in moments diferidamente preset for reasons related to audit Ia. In any case, the present invention allows the player always has the possibility of verifying the honesty and fairness of the game. To this end, part of the information generated is sent by the audit module to each of the players with a message such as mobile phone or email. Thus, the present invention partitioned between the two modules cited
Ia computational load reliable method to allow audits, it proposes. Most computational burden (because it requires analysis, sometimes exhaustive of the various protected records) lies with the audit module. Thus it does not interfere with gameplay Ia setting out the players with the game module. The security module, in constant interaction with the game module, is limited to aspects of copying and / or encryption of digital information. Ia all intelligence concerning the different logics of play is shifted audit module. This facilitates the management of Ia update logic game and the addition of new games, again without interfering with the behavior of the security module and consequently without altering in any dynamic Ia gameplay between the module game Players. The following describes in more detail the system that is introduced in the present invention, and the various parties with whom it relates or module integrates an electronic game.
It is assumed, first, that a player or a plurality of them (see Fig. 1) participate in the game by electronic means. The game, of a certain modalities, is offered to the player or players using a game module, either in face to face or remotely (see Fig. 4). Action games electronically provide direct, face interaction with the players, through systems such as video lottery terminals (VLT) installed in gambling halls or bingo halls. By contrast, in the remote electronic games, player interaction Ia is remotely via a communication network such as the Internet. In both cases, the game module, aware of Ia logic games, interact with the players, getting information from them regarding their decisions during the game and showing the evolution of the game. Often the game module records the operations carried out during the game. If necessary (especially in remote games), players often have an execution platform (for example, a kiosk game, a personal computer, a personal digital assistant or mobile terminal) and / or a set of programs or applications that allows the interaction with the game module. Henceforth, unless otherwise specified Io necessary, reference will be made as players, either both players and their related programs. The main elements or parts that are integrated or related to the module game that players interact (see Fig. 5) are:
- Registration entity primarily responsible for providing credentials to allow authentication players before the game module, either in person or remotely. In the case of remote gaming electronically, such credentials may, for example, a user name ( "login") and a word key ( "password") or a pair of asymmetric keys duly certified;
- A gaming operator, owner or manager game module and responsible for the operation thereof; - An accounting entity that is responsible for verifying that gaming operations carried out by the game module have met the criteria of honesty and impartiality preset, for example Ia relevant regulations regarding electronic game;
- A bank that manages the flow of money driven by gambling and payment of prizes during the game development.
The security module introduced in the present invention also has an important relationship with the game module. The security module is adapted for connection or integration with a module game. The security module consists of a set of programs and / or execution platforms for implementing Ia operations that require the method described in the present invention. This security module generates, by means of processing, records protected from information Ie module provides game and obtained by means of input and output data. The module stores these in a file protected by storage means records.
. In a preferred implementation 8VER Fig 6), the security module is formed by two different sub-modules: a cryptographic submodule and storage submodule. Cryptographic sub-module integrates a sealed hardware that provides physical security measures to part of the processing means security module protection and can even store information in the event that required (thereby providing physical protection also to the media storage security module). To cite an actual example, sealing hardware that integrates the cryptographic submodule could be of Hardware Security Module (HSM). On the market these types of components, such as might be a manufacturer nCipher nShield [http://www.ncipher.com/nshield/ 19/05/2005]). This is a secure hardware, tamper-proof, with delivery capacity applications within, code execution, execution of cryptographic primitives and storage and management of cryptographic keys. It could also be a crypto plate or a removable device such as a smart card. Regarding the storage sub-module (see Fig. 7), in a preferred implementation of the invention it would be a database server. the case is also contemplated that the storage sub-module device employing a write-once as a WORM (English, "write once, read many"). The storage submodule can be directly interconnected or integrated with the cryptographic submodule or, conversely, can be physically separated from said cryptographic submodule. In the latter case, both submodules have input means and output data to interface via a communication network such as the Internet. The processing means security module included in a
MPLEMENTATION preferred a random number generator. It may be a hardware device random number generation. It can also be a software algorithm that generates pseudorandom numbers. It could also be the case a combination of both, where a random seed is used to generate a pseudorandom sequence of values. Examples of pseudorandom number generators are collected in [FIPS PUB 140-2: Security Requirements for Cryptographic Modules, http://csrc.nist.gov/cryptval/140-2.htm, April 2005] or [Appendix 3 of FIPS PUB 186: Digital Signature Standard, http://csrc.nist.gov/publications/fips/fips186-2/fips186-2-change1.pdf, May 2005] and [RFC 1750: Randomness Recommendations for Security, http: / /www.ietf.org/rfc/rfc1750.txt, May 2005].
The security module is also adapted to store at least one key for performing cryptographic operations from that obtained digital information module game. The security module is also adapted to record at least part of the result of these cryptographic operations. Also, the game module would also be, in a preferred implementation, adapted for storing cryptographic keys.
With respect to the logical interconnection between the game module and the security module, the present invention contemplates the possibility that they are logically interconnected, preferably using an API (Application Programming Interface) that allows dialogue between the module software game software security module. Essentially, Ia API provides the module game (face or remote) of a well-defined interface through which it can be easily and standardized access the functionalities of the modules that are claimed in the present invention, without knowing internal thereof and allowing a high level of independence to future evolutions details. Furthermore, the API also performs the tasks of dynamic load balancing in the case where, for performance requirements, the same game module has more than one security module integrated. In this regard, the software comprising API Ia is responsible for distributing requests game module between different security modules as these are more or less available.
The audit module is adapted for connection or integration with the security module. The audit module has access by means of input and output data to the file of protected records stored by the security module. In the case where the security module be divided into two distinct sub-modules mentioned above, the present invention contemplates the possibility that the audit module to access the storage submodule for information protected log file. As the security module, the audit module consists of a set of programs and / or execution platforms for operations claimed the method of the present invention. The audit module can verify the correct operation of the game thanks to the processing means available.
Although all the modules that are introduced in the present invention are capable of being grouped individually or jointly, in a preferred implementation the security module and the audit module They will find themselves physically separated. In any case, the audit module has access to protected log file I materialized for example by a physical medium such as a CD-ROM or via remote access through a communication network. In a preferred implementation, the audit module would find completely disconnected from the game module. However it could maintain connections with one or more security modules simultaneously. The same module game could maintain simultaneous connections to one or more security modules. Similarly, the same security module may maintain simultaneous connections to one or more game modules.
In the present invention a method that allows, to be implemented by the system described above, ensuring a number of requirements for trust (such as Ia honesty and fairness) of the shares took place during a game electronically face either likewise called or remote. The basic structure Ia which the method is based consists of the safe preservation of information concerning significant events of any game at all times to enable analysis and audit reliably. As noted above, significant gaming event is any action or event that reflects an important game event that determines the development of a game play in its main aspects. Examples of significant events would play decisions by players such as entering or leaving a table, or the action of performing a certain bet. It would also be an example of significant gaming event, in the case of the roulette, the stopping of Ia ball in a certain box. In an electronic game system, playing significant events can be represented internally by digital information, which can be transferred Ia during the game between the different elements of the game system.
For example, the authentication of a player who accesses said gaming module corresponds to a significant event in a game electronically. This authentication can be done in different ways, depending on the level of security desired guarantee. For example, you can allow access to the game to a player that validates a login name and a keyword previously associated with that player, or use a public key infrastructure to provide digital certificates to players allowing for a more robust authentication process. At the present biometric patterns they are also used to authenticate players entering the game. With recent advances in cryptographic authentication techniques ID-Based (also known as Identity- Based), this alternative is also configured as a possible way to use. Whatever the authentication method used in the game, when the significant event corresponds to the authentication of a player who enters the game module, the latter can contribute to the security module digital information to reproduce the authentication process. The game module could also provide other information on geographical location Ia player who enters the game. In the case of remote electronic game, said location Ia correspond to location of the terminal from which the player access remotely the game module through a communication network. This could be another significant gaming event. In reality, however, the localization of a player and authentication when accessing the game could be joined to form a single significant game event which would include both issues. Another significant event was the beginning play a game of a particular game, or the incorporation of a player that heading. The description of this event Ia conform the essential features of the game such as game type, game variant Ia and limits for gambling, for example. Another significant event of importance corresponds to a decision or action game by a player, as could be for example Ia decision to perform a certain bet or the action of driving the rollers of a game machine, or also Ia decision example of taking an additional card. In case that the game logic Io required, it may be necessary to generate random during the game. Random generation used to determine eg which box should stop Ia ball of a roulette wheel, or are the cards once have been considered. Random generation is also an significant event of vital importance. Electronic random generation requires first obtaining or generating a random number or pseudo-random. Secondly, this number is transferred to the appropriate range depending on the type of random event is expected (the launch of a given for example requires a number from 1 to 6, whereas the location of Ia ball in Ia roulette requires a number 0 to 36). Third, the number thus obtained is transferred to the end chance result through a specific function preset mapping.
The present invention contemplates three different methods for the generation of random events. First, the generation by the game module individually without any intervention by the security module. Second, the generation by the security module individually without intervention game module using, for example, a random number generator that is in the crypto submodule. Thirdly, the present invention also contemplates Ia option that randomly generate a shared basis between the gaming module and security module.
In any case, the game module is always leading the development of the games and the interaction with the players. That is why in the second above assumptions and third (generation of random by the security module and generation of shared random), the module game should start the process of the generation of random via a request to the security module. The game module must always be finally notified the final result of the generation of random event, to allow the continued development of the game. If it deemed appropriate, such notification may be marked digitally (eg via a symmetric or asymmetric digital signature) to provide it with authenticity and integrity. The protocol end, in a preferred implementation, a final confirmation module game security module. In the case of a shared random generation, in a preferred implementation are used mainly two cryptographic tools. On the one hand, a scheme for sharing secrets that can generate random numbers distributed manner without any of the parts involved (in this case the game module and the security module) have any information about what will be the resulting value nor can predict at least Io. On the other hand, a commitment protocol, which prevents Ia tampering by any of the parties involved in shared Ia generation. In addition, with the main objective to provide more security to this generation process, it is considered in the present invention the use of additional cryptographic tools, such as digital, simple or distributed signatures that ensure the integrity, Ia authenticity and non-repudiation. The protected record associated with this significant event shared generating random saved, in a preferred implementation, the digital information to enable later convincingly reproducing process shared generation of random and can verify that the safety features mentioned above are met . There are other significant events important game to take into account in the normal operation of a gaming module and the interactions of the players. For example, the establishment or Ia update parameters for Ia player account (such as the maximum amounts to play by starting or details of payment methods that will be used for payment and collection of bets and prizes ). Also prize payment itself can be considered a significant event game. Also the embodiment of notifications or communications module by playing a player (eg notifications concerning the total time that a player has been playing). Finally, a significant event last example would be the abandonment of the game or a game by a player.
The method of the present invention is characterized in that during the game, for each significant event game (or at least for each of the significant events of a set of them deemed appropriate), the security module generates a log that will allow faithfully reproduce the related significant event. In addition such registration is protected to prevent any further manipulation once it has been generated. The set of protected records stored in what is known as a file of protected records. This file of protected records enable the audit module check the correct operation of the game as will be specified later.
More detail under the proposed method, for each of at least a subset of said significant events of play are performed (see Fig. 2) the following stages: a) input to a security module, by a game module intended to interact with at least one player, a digital information containing at least one of a significant event; b) generation in the security module of a protected record of at least some of the significant event from the digital information received in step a) above; c) storing the protected record, resulting in a digital file of protected records. At certain times, an audit module intended for the generation of an audit information, performs a check, from at least part of said digital file of protected records, the proper development of the game happened. Such verification is not necessarily performed on a permanent basis for each of the significant events that occur in the game, but can be performed after the occurrence of a number of significant events. Thus, for such verification, the audit module takes into account a number of these significant events, selecting them based on audit criteria. This criterion may be subject to audit Ia own game logic or also be determined by example by Ia specific regulation on electronic gaming. For example, they could take into account all significant events that occurred during Ia game last week.
Such game module, security module, and audit module, are susceptible to varying degrees of dispersion and / or group, and a cryptographic protocols for the protection of these registers are used. The subset of significant events for each of which the above steps a) to c) depends on different implementations are performed. In a preferred embodiment, this subset is the total of the significant events that occurred during the game development. In a preferred implementation, the module stores the digital play file protected records in a database. Additionally, the protected records can be stored in a storage device writing once, to increase the overall physical protection is conferred to records. In any case, the present invention contemplates the possibility of maintaining the digital file of protected records outside the game module to increase their independence from it.
Before performing Ia contribution of digital information described in the previous step a), the module can optionally digitally game mark this digital information (for example by a symmetric or asymmetric) digital signature to assure the authenticity and integrity of said digital information.
After the game module has contributed to the security module the digital information regarding a significant event, the security module generates a protected record for this significant event. The protection of such registration may be different. In a preferred implementation cryptographic protocols are used. The keys required for such cryptographic protocols can be saved in the security module itself. In a preferred implementation would be stored in the cryptographic submodule, to provide them with physical protection (a smart card or a sealed system hardware offers a very restricted to certain areas of internal memory access).
Protecting records mainly aims to address the following threats:
- Changing the order in which significant events occur during the game. An alteration of this order could lead to fraudulent practices, varying for example, the winner or winners of the game. - Elimination of significant events. Again, this action may lead to alterations in the logical outcome of the game.
- Handling of significant events.
- Adding further significant events that actually did not happen.
The protection given to records of significant events must guarantee immunity from the threats described, but simultaneously should represent an efficient process that does not degrade the performance of the security module in excess. In the present invention different proposals for the protection of these records are suggested.
As first option, it is considering the use of a digital signature
(Like a HMAC symmetric or asymmetric-like a RSA) associated with each of the protected records that are generated. However, this approach is too costly from a computational view and also does not protect against such threat Ia Ia rearrangement of the records.
As a second alternative proposes the addition of some additional redundant registration information (relating essentially Ia management thereof), and the digital signature of the total result (again, using a symmetrical or asymmetrical signature). The redundant information can be for example a simple sequence number or a chained hash value (obtained through a one-way function summary from the current record and Ia succession of several previous records). With this procedure all threats previously made impossible. However, the generation of a digital signature for each of the protected records is still inefficient.
Finally, in a preferred implementation of the present invention, it is considered a proposal that would not only guarantee protection against all threats Ia exposed, but also represents an efficient alternative to be implemented. This is an internal record keeping in the security module that stores the result of a hash function Chained protected records that are generated. The security module proceeds to digitally sign (using a symmetrical or asymmetrical signature) registration internal according to a specified criterion, as it could be every few records or periodically. The internal register, once signed, is stored together with the file of protected records.
The process of verification of the correct development of the game happened, by the audit module is carried out in a preferred implementation the following steps:
1. Verification of Ia authenticity and integrity of protected records to be analyzed. It is found that the records that have been fed to the module are authentic and complete (ie, that have been produced by the security module and have not been altered in any way or have been altered in their management).
2. Reconstruction of game play from the significant events contained in records protected. Each game play can be reconstructed in all its critical steps, because Ia intelligence on the various games that incorporates the audit module and the description of type Ia and starting mode including records.
3. Testing a set of essential characteristics confidence game. This task is performed by contrasting the one hand, significant game events that occurred, and on the other, the rules of the games and / or predefined conditions (such as procedures or parameters specified by Ia relevant regulations for electronic game). The audit module can incorporate source, the rules of the games and any prescribed conditions. Alternatively, they can be supplied Ie or updated by Ia competent authority (an auditor or a regulator, for example). The verification carried out by the audit module in this step includes essential features of confidence game such as: a. Validation of the identities of the players, checking that it is older and is not excluded players. b. Validation Ia fairness of the game based on chance, and the correct and honest behavior module game based on the rules of each game. c. Validation Ia absence of suspicious movements and decisions game. In some cases, a particular movement game can be perfectly valid from the point of view of the rules but nevertheless can be highly suspicious (eg, abandonment in a poker game when you have a very good hand letters). d. Validation play adjusting the parameters determined by scores of each player (eg maximum playing for starting or monthly amounts). and. Validation of the payment of prizes, for example Ia by checking the information generated by the payment gateways Ia bank in relation to each prize awarded.
4. Generation of audit reports on the results of step 3) above. For example, this report may contain, among others, the information of the player's credit status and the results obtained in the different runs or bets. For example, some existing regulations require that such reports include gains and losses of the player and the time that lasted the games.
Reports generated by the audit module enable auditing entity Ia see how far the game has been developed in accordance with predetermined criteria. In addition, if there have been big gains (or losses), it may require additional information, as is a thorough review of each and every one of the currency movements of each of the players who have participated in the development of the game Ia or revision of the identities of the different players who have interacted with the game module. The present invention also contemplates the possibility of a permanent audit module access to the file of protected records, with the purpose of issuing instant alarms in real time to fraudulent actions. These alarms may be directed to auditors or regulators, for example.
In the case where the audit reports, perhaps partly refer to players, it allows players to check effectively on their game play by the security module was involved and ensuring safe recording of all Io happened . This information sending players can be performed in real time through the game system with which players interact, to enable instant verification of the correct development of the games. Alternatively, you can send audit information to players delayed by various external communication channels such as email, sending short messages to mobile phone (SMS) or Ia publication of the information audit on a particular Web page accessible to players.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both waysCites: the store holds 20 of 21
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| US2023024852A1 | Cited by | United States of America | – | Search report |
| US2002160834A1 | Cites | United States of America | – | Applicant |
| WO2004034223A2 | Cites | World Intellectual Property Organization (WIPO) | A | International search |
| WO2004035159A1 | Cites | World Intellectual Property Organization (WIPO) | – | Applicant |
| US2004192438A1 | Cites | United States of America | – | Applicant |
| US2004192442A1 | Cites | United States of America | – | Applicant |
| US2004198494A1 | Cites | United States of America | – | Applicant |
| US2004242321A1 | Cites | United States of America | – | Applicant |
| WO2005021118A1 | Cites | World Intellectual Property Organization (WIPO) | A | International search |
| WO2005021118A1 | Cites | World Intellectual Property Organization (WIPO) | A | Applicant |
| GB2307184A | Cites | United Kingdom | – | Applicant |
| US4926327A | Cites | United States of America | – | Applicant |
| US5038022A | Cites | United States of America | – | Applicant |
| US6030288A | Cites | United States of America | – | Applicant |
| US6099408A | Cites | United States of America | – | Applicant |
| US6106396A | Cites | United States of America | – | Applicant |
| US6117011A | Cites | United States of America | – | Applicant |
| US6165072A | Cites | United States of America | A | International search |
| US6264560B1 | Cites | United States of America | – | Applicant |
| US6612928B1 | Cites | United States of America | – | Applicant |
| WO9811686A2 | Cites | World Intellectual Property Organization (WIPO) | – | Applicant |
| A. SHIMIZU; T. HORIOKA; H. INAGAKI: "A Password Authentication Method for Contents Communication on the Internet", IEICE TRANSACTIONS ON COMMUNICATIONS, vol. E81-B, no. 8, August 1998 (1998-08-01), pages 1666 - 1673, XP000788473 | Non-patent | – | – | Applicant |
| BLUM M.: "Coin Flipping by Telephone: a Protocol for Solving Impossible Problems", PROC. IEEE COMPUTER CONFERENCE, 1982, pages 133 - 137, XP000892068 | Non-patent | – | – | Applicant |
| KILIAN, J.: "Uses of Randomness in Algorithms and Protocols", ACM DISTINGUISHED DISSERTATION, MIT, 1990 | Non-patent | – | – | Applicant |
| See also references of EP 1908503A4 | Non-patent | – | – | Applicant |
8 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005000400 | Spain | W | |
| WO2005ES00400 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| GB0521102D0 | United Kingdom | D0 | |
| GB2418153A | United Kingdom | A | |
| GB2418153B | United Kingdom | B | |
| WO2007010055A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| EP1908503A1 | European Patent Office (EPO) | A1 | |
| US2008287188A1 | United States of America | A1 | |
| EP1908503A4 | European Patent Office (EPO) | A4 | |
| US9155959B2 | United States of America | B2 |
6 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2007/010055
- Publication, DOCDB
- 2007010055
- Publication, EPODOC
- WO2007010055
- Application
- 400
- Application, DOCDB
- 2005000400
- Application, EPODOC
- WO2005ES00400
Titles3
- English
- METHOD AND SYSTEM FOR GENERATING A FILE OF AUDITABLE LOGS RELATING TO GAMES USING ONSITE AND REMOTE ELECTRONIC MEANS
- Spanish
- MÉTODO Y SISTEMA PARA LA GENERACIÓN DE UN ARCHIVO DE REGISTROS AUDITABLES EN LOS JUEGOS POR MEDIOS ELECTRÓNICOS PRESENCIALES Y REMOTOS
- French
- PROCEDE ET SYSTEME DE GENERATION D'UN FICHIER D'ENREGISTREMENTS VERIFIABLES DANS LES JEUX PAR DES MOYENS ELECTRONIQUES PRESENTS ET A DISTANCE
Classification
- CPC, 11
- G06F21/645
- A63F9/24
- G07F17/32
- A63F1/00
- A63F2009/2489
- A63F2300/532
- A63F2300/5586
- G06F2221/2101
- G06F2221/2109
- G06F2221/2111
- A63F13/75
- IPC, 5
- A63F13 12
- A63F1 00
- A63F9 24
- G06F21 64
- G07F17 32
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo