FR3104760B1 - Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication - Google Patents

Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication Download PDF

Info

Publication number
FR3104760B1
FR3104760B1 FR1914346A FR1914346A FR3104760B1 FR 3104760 B1 FR3104760 B1 FR 3104760B1 FR 1914346 A FR1914346 A FR 1914346A FR 1914346 A FR1914346 A FR 1914346A FR 3104760 B1 FR3104760 B1 FR 3104760B1
Authority
FR
France
Prior art keywords
server
terminal
transaction
sends
communication channels
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
FR1914346A
Other languages
English (en)
Other versions
FR3104760A1 (fr
Inventor
Marc Beunardeau
Aisling Connolly
Rémi Geraud
Hiba Koudoussi
David Naccache
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Banks and Acquirers International Holding SAS
Original Assignee
Ingenico Group SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ingenico Group SA filed Critical Ingenico Group SA
Priority to FR1914346A priority Critical patent/FR3104760B1/fr
Priority to PCT/FR2020/052398 priority patent/WO2021116627A1/fr
Priority to US17/784,861 priority patent/US20230009385A1/en
Priority to EP20845185.6A priority patent/EP4074005A1/fr
Priority to CA3161325A priority patent/CA3161325A1/fr
Publication of FR3104760A1 publication Critical patent/FR3104760A1/fr
Application granted granted Critical
Publication of FR3104760B1 publication Critical patent/FR3104760B1/fr
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication
    • G06F21/46Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/386Payment protocols; Details thereof using messaging services or messaging apps
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q40/00Finance; Insurance; Tax strategies; Processing of corporate or income taxes
    • G06Q40/02Banking, e.g. interest calculation or account maintenance
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/067Network architectures or network communication protocols for network security for supporting key management in a packet data network using one-time keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/082Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying multi-factor authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/102Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measure for e-commerce

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Development Economics (AREA)
  • Technology Law (AREA)
  • Marketing (AREA)
  • Economics (AREA)
  • Software Systems (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Communication Control (AREA)
  • Computer And Data Communications (AREA)

Abstract

L’invention concerne un procédé de transaction pour un utilisateur 1 utilisant un premier et un deuxième terminal 2 et relié à un serveur 4 via respectivement un premier et un deuxième canal de communication. Le premier terminal 2 envoie 304 au serveur 4 un montant de transaction TA. Le serveur 4 établit 502 à 504 un code de vérification AC dont une longueur L est fonction du montant de la transaction TA puis envoie 505 et 506 une requête Req au premier terminal 2 et le code de vérification AC au deuxième terminal 5. L’utilisateur renvoie 310 ladite requête remplie avec un code recopié AC’ au serveur 4 à l’aide du premier terminal 2. Le serveur 4 compare 508 le code de vérification AC avec le code recopié AC’ et envoie 510, 512 au premier terminal 2 un message de validation ou d’invalidation de transaction en fonction de la comparaison. Figure pour l’abrégé : Fig.3
FR1914346A 2019-12-13 2019-12-13 Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication Active FR3104760B1 (fr)

Priority Applications (5)

Application Number Priority Date Filing Date Title
FR1914346A FR3104760B1 (fr) 2019-12-13 2019-12-13 Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication
PCT/FR2020/052398 WO2021116627A1 (fr) 2019-12-13 2020-12-11 Procede, serveur et systeme d'authentification de transaction utilisant deux canaux de communication
US17/784,861 US20230009385A1 (en) 2019-12-13 2020-12-11 Transaction authentication method, server and system using two communication channels
EP20845185.6A EP4074005A1 (fr) 2019-12-13 2020-12-11 Procede, serveur et systeme d'authentification de transaction utilisant deux canaux de communication
CA3161325A CA3161325A1 (fr) 2019-12-13 2020-12-11 Procede, serveur et systeme d'authentification de transaction utilisant deux canaux de communication

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR1914346 2019-12-13
FR1914346A FR3104760B1 (fr) 2019-12-13 2019-12-13 Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication

Publications (2)

Publication Number Publication Date
FR3104760A1 FR3104760A1 (fr) 2021-06-18
FR3104760B1 true FR3104760B1 (fr) 2023-05-26

Family

ID=70228146

Family Applications (1)

Application Number Title Priority Date Filing Date
FR1914346A Active FR3104760B1 (fr) 2019-12-13 2019-12-13 Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication

Country Status (5)

Country Link
US (1) US20230009385A1 (fr)
EP (1) EP4074005A1 (fr)
CA (1) CA3161325A1 (fr)
FR (1) FR3104760B1 (fr)
WO (1) WO2021116627A1 (fr)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12021861B2 (en) * 2021-01-04 2024-06-25 Bank Of America Corporation Identity verification through multisystem cooperation

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
SK5232001A3 (en) * 2001-04-18 2002-03-05 Blue Orange S R O Method of safety transactions by means of public networks
WO2005114886A2 (fr) * 2004-05-21 2005-12-01 Rsa Security Inc. Systeme et procede permettant de reduire la fraude
US7657489B2 (en) * 2006-01-18 2010-02-02 Mocapay, Inc. Systems and method for secure wireless payment transactions
US20090307140A1 (en) * 2008-06-06 2009-12-10 Upendra Mardikar Mobile device over-the-air (ota) registration and point-of-sale (pos) payment
US8661258B2 (en) * 2009-10-23 2014-02-25 Vasco Data Security, Inc. Compact security device with transaction risk level approval capability
US9800574B2 (en) * 2013-12-31 2017-10-24 Vasco Data Security, Inc. Method and apparatus for providing client-side score-based authentication
US11151568B2 (en) * 2018-05-09 2021-10-19 Capital One Services, Llc Real-time selection of authentication procedures based on risk assessment

Also Published As

Publication number Publication date
EP4074005A1 (fr) 2022-10-19
CA3161325A1 (fr) 2021-06-17
WO2021116627A1 (fr) 2021-06-17
FR3104760A1 (fr) 2021-06-18
US20230009385A1 (en) 2023-01-12

Similar Documents

Publication Publication Date Title
KR101455891B1 (ko) 네트워크와 통신하는 이동 장비에 의해 수행되는 방법 및 이동 장비와 통신하는 네트워크에 의해 수행되는 방법
KR102424055B1 (ko) 두 개의 api 토큰을 이용한 api 인증 장치 및 방법
FI981132A (fi) Palvelun luvattoman käytön estäminen
BR112013000358A2 (pt) método em um sistema que compreende um primeiro dispositivo de comunicação,um segundo dispositivo de comunicação, e um servidor,método em um primeiro dispositivo de comunicação,método em um segundo dispositivo de comunicação, método em um servidor,primeiro dispositivo de comunicação,segundo aparelho de comunicação,servidor,e produto de programa de computador.
KR20060123345A (ko) 무선 랜에서의 인증을 위한 시스템, 방법, 및 장치들
US20050154909A1 (en) Certificate based authentication authorization accounting scheme for loose coupling interworking
SG10201808534SA (en) Method and system for processing blockchain-based transactions on existing payment networks
US20160078095A1 (en) Location-based updating of profile data
DE60137233D1 (de) Anordnung zur benutzerauthentifizierung und autorisierung der benutzung eines gesicherten systems
CA2357792A1 (fr) Methode et dispositif pour executer des transactions protegees
HUP0303213A2 (hu) Eljárás és rendszer vezeték nélküli tranzakció elősegítésére
KR20040107888A (ko) 동기화 프로토콜에서의 사용자 인증 방법
FR2821225B1 (fr) Systeme de paiement electronique a distance
CN110995751B (zh) 一种基于区块链的大数据智慧医疗养老服务方法及其系统
FR3104760B1 (fr) Procede, serveur et systeme d’authentification de transaction utilisant deux canaux de communication
WO2016173146A1 (fr) Procédé de transmission de données de service, terminal et système de facturation, et support d'informations informatique
TW200703025A (en) Method and apparatus for improving data transfers in peer-to-peer networks
CN106936600A (zh) 流量计费方法和系统以及相关设备
ATE260010T1 (de) Sim basierte authentifizierung als zahlungsverfahren in öffentlichen isp zugangsnetzen
CN105208042A (zh) 一种资源安全访问方法及系统
FR3060785B1 (fr) Procede et systeme d’impression securisee a distance depuis un terminal mobile
KR20190005044A (ko) 상호 인증 방법 및 그 시스템
ATE393555T1 (de) Verfahren, vorrichtung und system zur behandlung von einem authentifizierungsfehler von einem zwischen einem gsm-netz und einem wlan-netz umherstreifenden teilnehmer
SG10201705259VA (en) Transaction terminal and system for obtaining third-party location based services and method thereof
KR20060122746A (ko) 장치관리에서의 부트스트랩 메시지 보안 전송 방법 및 장치

Legal Events

Date Code Title Description
PLFP Fee payment

Year of fee payment: 2

PLSC Publication of the preliminary search report

Effective date: 20210618

PLFP Fee payment

Year of fee payment: 3

TP Transmission of property

Owner name: BANKS AND ACQUIRERS INTERNATIONAL HOLDING, FR

Effective date: 20211202

PLFP Fee payment

Year of fee payment: 4

PLFP Fee payment

Year of fee payment: 5