Abstract:
A method for authentication of a user towards a unit (AR1) is described that uses unique biometric data of the user but avoids spreading of the sensitive biometric data. The method overcomes the problem of the lack of trustworthiness of a client (C1) operated by a user and the lack of trustworthinessof a unit (AR1) operate d by an institution offering services or goods introducing an authentication instance (AI1) operated by a third party that is trusted by both the user operating the client (C1) and the institution operating the unit. According to the invented method the responsability for the secure handling of the sensitive biometric data is taken from the institution operating the unit (AR1) requesting authentication and given to a trusted third party organization operating an authentication instance (AI1). The authentication instance (AI1) stores the sensitive biometric data and performs the authentication based on a pattern matching of a prestored pattern of biometric data and a pattern of biometric data recorded by the user.
Abstract:
The invention relates to a method of returning change to a payer in an electronic payment system. A payer determines a change return valu, generates and blinds a change return certificate, generates a first signature by signing the blinded change return certificate, and sends a message comprising the first signature to a payee. The payee forwards the message to a payment provider. The payment provider verifies the first signaure and the change return value indicated by the message, generates a blinded second signature by signing the blinded change retun certificate, and forwards the blinded second signature to the payer. The payer unblinds and verifies the blinded second signature, and forms a second payment certificate. The invention furthermore relates to a method of performing tasks of a payer and to a method of performing tasks of a payment provider in a change return transaction, to computer programs and devices therefore.
Abstract:
The invention relates to a method of returning change to a payer in an electronic payment system. A payer determines a change return value, generates and blinds a change return certificate, generates a first signature by signing the blinded change return certificate, and sends a message comprising the first signature to a payee. The payee forwards the message to a payment provider. The payment provider verifies the first signature and the change return value indicated by the message, generates a blinded second signature by signing the blinded change return certificate, and forwards the blinded second signature to the payer. The payer unblinds and verifies the blinded second signature, and forms a second payment certificate. The invention furthermore relates to a method of performing tasks of a payer and to a method of performing tasks of a payment provider in a change return transaction, to computer programs and devices therefore.
Abstract:
THE INVENTION RELATES TO A COMMUNICATION SYSTEM, A METHOD AND DEVICES FOR AN EFFICIENT IMPLEMENTATION OF ELECTRONIC TRANSACTIONS BETWEEN A MOBILE SUBSCRIBER IN A MOBILE COMMUNICATION NETWORK AND A NETWORK FACILITY BY EXPLOITING CREDIT CARD BASED PAYMENT PROTOCOLS. THE PROTOCOL, WHICH IS USED FOR REALIZING A SECURED ELECTRONIC TRANSACTION, SUCH AS THE SETTM, IS SPLIT OVER A PLURALITY OF INVOLVED COMMUNICATION UNITS. FOR REALIZING THE INVENTION, THE FIRST PART OF THE PROTOCOL, WHICH IS USUALLY CONTAINED IN THE MOBILE STATION OF A USER, IS SPLIT INTO TWO PARTS. THE FIRST PART CONTAINING THE PRIVATE DATA OF A SUBSCRIBER, SUCH AS THE PRIVATE KEY OR THE CERTIFICATES, IS MAINTAINED IN THE MOBILE STATION. THE SECOND PART OF THE SOFTWARE IS SHIFTED TO A SERVER BEING POSITIONED BETWEEN THE MOBILE STATION AND THE MERCHANT. THUS, THE INVENTION GUARANTEES ON ONE HAND THE POSSIBILITY OF INTEGRATING COMPLEX SOFTWARE FOR AN ELECTRONIC WAY OF PAYMENT IN A NETWORK, WHICH IS CHARACTERIZED BY A SMALL TRANSMISSION CAPACITY AND TERMINALS HAVING AN INSUFFICIENT STORING CAPACITY, AND ON THE OTHER HAND THE MAINTENANCE OF SECURITY ASPECTS ON THE USER SIDE. ADDITIONALLY, THE INVENTION GUARANTEES THE COMPATIBILITY WITH THE ALREADY EXISTING SOFTWARE. (FIGURE 1)
Abstract:
La invencion se refiere a un sistema de comunicacion, un metodo y dispositivo para una implementacion eficiente de transacciones electronicas entre un suscriptor movil en una red de comunicacion movil y una instalacion de red mediante explotacion de los protocolos de pago en base a tarjeta de credito. El protocolo, el cual es utilizado para realizar una transaccion electronica asegurada, tal como el SET TM es separado sobre una pluralidad de unidades de comunicacion involucradas. Para realizar la invencion, la primera parte del protocolo, que esta contenido usualmente en la estacion movil de un usuario, es separada en dos partes. La primera parte que contiene los datos privados de un suscriptor, tal como la clave privada o el certificado, se mantiene en la estacion movil. La segunda parte del software es desviada hacia un servidor que esta colocado entre la estacion movil y el comerciante. Por tanto, la invencion garantiza por una parte la posibilidad de integrar un software complejo para una forma electronica de pago en una red, la cual esta caracterizada por una capacidad de transmision reducida y terminales que tienen una capacidad de almacenamiento insuficiente, y por otro lado el mantenimiento de los aspectos de seguridad por parte del usuario. Adicionalmente, la invencion garantiza la compatibilidad con el software ya existente.
Abstract:
The method involves receiving a payment request via a communications filter (Fl), modifying the request by adding a transaction identifier, passing it to a transaction server (WS), passing information with the identifier from the filter to a communications terminal (MS), passing a payment initialization with a further identifier from the terminal to the server, comparing the identifiers and transacting the payment if the identifiers agree. Independent claims are also included for the following: (1) a filter for a communications system (2) a transaction server (3) a computer program stored on a computer-readable medium
Abstract:
A method for the authorization of transactions is described, wherein a user equipment receives an authorization request with an identifier of a transaction and replies to the request with an authorization response. For an authorization request, an indication is determined which is output by the user equipment (UE). Preferably, the identifier is a hash value of the content which is to be authorized. After an input to approve or disapprove the authorization request, the identifier (H) is signed and the authorization response according to the input is sent, wherein an approving authorization response comprises the signed identifier (H). Devices and software programs adapted to the method are also described.