MX361793B - Método y sistema para la autentificación segura del usuario y el dispositivo móvil sin elementos de seguridad. - Google Patents

Método y sistema para la autentificación segura del usuario y el dispositivo móvil sin elementos de seguridad.

Info

Publication number
MX361793B
MX361793B MX2016007217A MX2016007217A MX361793B MX 361793 B MX361793 B MX 361793B MX 2016007217 A MX2016007217 A MX 2016007217A MX 2016007217 A MX2016007217 A MX 2016007217A MX 361793 B MX361793 B MX 361793B
Authority
MX
Mexico
Prior art keywords
secure
generating
processing device
session key
application cryptogram
Prior art date
Application number
MX2016007217A
Other languages
English (en)
Other versions
MX2016007217A (es
Inventor
Collinge Mehdi
Smets Patrik
Emile Jean Charles Cateland Axel
Original Assignee
Mastercard International Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mastercard International Inc filed Critical Mastercard International Inc
Publication of MX2016007217A publication Critical patent/MX2016007217A/es
Publication of MX361793B publication Critical patent/MX361793B/es

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3274Short range or proximity payments by means of M-devices using a pictured code, e.g. barcode or QR-code, being displayed on the M-device
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/204Point-of-sale [POS] network systems comprising interface for record bearing medium or carrier for electronic funds transfer or payment credit
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3823Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Computer And Data Communications (AREA)

Abstract

Un método para generar credenciales de pago en una transacción de pago incluye: almacenar, en una memoria, por lo menos una llave de un solo uso asociada con una cuenta de transacciones; recibir, mediante un dispositivo de recepción, un número de identificación personal; identificar, mediante un dispositivo de procesamiento, una primera llave de sesión; generar, mediante el dispositivo de procesamiento, una segunda llave de sesión basándose en por lo menos la llave de un solo uso almacenada y el número de identificación personal recibido; generar, mediante el dispositivo de procesamiento, un primer criptograma de la aplicación basándose en por lo menos la primera llave de sesión; generar, mediante el dispositivo de procesamiento, un segundo criptograma de la aplicación basándose en por lo menos la segunda llave de sesión; y transmitir, mediante un dispositivo de transmisión, por lo menos el primer criptograma de la aplicación y el segundo criptograma de la aplicación para utilizarse en una transacción de pago.
MX2016007217A 2013-12-02 2014-12-02 Método y sistema para la autentificación segura del usuario y el dispositivo móvil sin elementos de seguridad. MX361793B (es)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
US201361910819P 2013-12-02 2013-12-02
US201461951842P 2014-03-12 2014-03-12
US201461955716P 2014-03-19 2014-03-19
US201461979132P 2014-04-14 2014-04-14
US201461980784P 2014-04-17 2014-04-17
PCT/US2014/067992 WO2015084755A1 (en) 2013-12-02 2014-12-02 Method and system for secure authentication of user and mobile device without secure elements

Publications (2)

Publication Number Publication Date
MX2016007217A MX2016007217A (es) 2016-12-09
MX361793B true MX361793B (es) 2018-12-17

Family

ID=53274011

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2016007217A MX361793B (es) 2013-12-02 2014-12-02 Método y sistema para la autentificación segura del usuario y el dispositivo móvil sin elementos de seguridad.

Country Status (16)

Country Link
EP (1) EP3077972A4 (es)
JP (2) JP6353537B2 (es)
KR (2) KR101809221B1 (es)
CN (1) CN106062799B (es)
AU (1) AU2014357381B2 (es)
BR (1) BR112016012527A2 (es)
CA (1) CA2932346C (es)
CL (1) CL2016001353A1 (es)
HK (1) HK1227146A1 (es)
IL (1) IL245965B (es)
MX (1) MX361793B (es)
NZ (1) NZ720688A (es)
RU (1) RU2663319C2 (es)
SG (1) SG10201800179UA (es)
UA (1) UA115500C2 (es)
WO (1) WO2015084755A1 (es)

Families Citing this family (26)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
MX361684B (es) 2013-12-02 2018-12-13 Mastercard International Inc Método y sistema para la transmisión segura de mensajes del servicio de notificación a distancia a dispositivos móviles sin elementos de seguridad.
RU2653290C1 (ru) * 2014-04-14 2018-05-07 Мастеркард Интернэшнл Инкорпорейтед Способ и система для генерации усовершенствованного ключа хранения в мобильном устройстве без защитных элементов
US10614442B2 (en) 2014-12-03 2020-04-07 Mastercard International Incorporated System and method of facilitating cash transactions at an ATM system without an ATM card using mobile
US10185949B2 (en) * 2015-03-05 2019-01-22 American Express Travel Related Services Company, Inc. System and method for authentication of a mobile device configured with payment capabilities
US10248947B2 (en) * 2015-06-29 2019-04-02 Oberthur Technologies of America Corp. Method of generating a bank transaction request for a mobile terminal having a secure module
US11120436B2 (en) * 2015-07-17 2021-09-14 Mastercard International Incorporated Authentication system and method for server-based payments
SG10201508945YA (en) 2015-10-29 2017-05-30 Mastercard International Inc Method and system for cardless use of an automated teller machine (atm)
US10496982B2 (en) 2016-02-03 2019-12-03 Accenture Global Solutions Limited Secure contactless card emulation
EP4177810A1 (en) * 2016-04-18 2023-05-10 Bancontact Payconiq Company Method and device for authorizing mobile transactions
WO2017184840A1 (en) 2016-04-21 2017-10-26 Mastercard International Incorporated Method and system for contactless transactions without user credentials
SG11201900748QA (en) * 2016-09-04 2019-03-28 Mastercard International Inc Method and system for cardless atm transaction via mobile device
EP3340094B1 (en) * 2016-12-22 2021-04-28 Mastercard International Incorporated Method for renewal of cryptographic whiteboxes under binding of new public key and old identifier
EP3571652B1 (en) * 2017-01-23 2024-04-17 Mastercard International Incorporated Method and system for authentication via a trusted execution environment
EP3364352A1 (en) 2017-02-21 2018-08-22 Mastercard International Incorporated Determining legitimate conditions at a computing device
EP3364329B1 (en) 2017-02-21 2023-07-26 Mastercard International Incorporated Security architecture for device applications
EP3364363A1 (en) 2017-02-21 2018-08-22 Mastercard International Incorporated Transaction cryptogram
CN107274183B (zh) * 2017-03-21 2020-05-22 中国银联股份有限公司 交易验证方法及系统
US11468444B2 (en) * 2017-12-18 2022-10-11 Mastercard International Incorporated Method and system for bypassing merchant systems to increase data security in conveyance of credentials
KR101972599B1 (ko) * 2018-06-19 2019-04-25 김승훈 세션키 처리장치, 처리 방법 및 이를 위한 프로그램을 기록한 컴퓨터 판독 가능한 기록매체
US10581611B1 (en) * 2018-10-02 2020-03-03 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
EP3640878B1 (fr) * 2018-10-17 2023-06-21 Swatch Ag Procede et systeme d'activation d'un objet portable de paiement sans contact
US10984416B2 (en) * 2019-03-20 2021-04-20 Capital One Services, Llc NFC mobile currency transfer
US11803827B2 (en) 2019-11-01 2023-10-31 Mastercard International Incorporated Method and system for enabling cardless transactions at an ATM for any institutional entity
CN111901109B (zh) * 2020-08-04 2022-10-04 华人运通(上海)云计算科技有限公司 基于白盒的通信方法、装置、设备和存储介质
CN113421084B (zh) * 2021-05-26 2023-03-24 歌尔股份有限公司 公交卡处理方法、装置、设备及可读存储介质
US12562905B2 (en) 2024-01-22 2026-02-24 Bank Of America Corporation System and method for encrypting user device resource transactions

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH07297819A (ja) * 1994-04-12 1995-11-10 Tandem Comput Inc ネットワーク伝送のために個人の照合とメッセージ認証の暗号化とを組み合わせ処理する方法および手段
JP4030027B2 (ja) * 1997-08-22 2008-01-09 沖電気工業株式会社 取引情報通知システム
JP4183823B2 (ja) * 1999-02-10 2008-11-19 富士通株式会社 データ照合装置、データ照合システムおよびデータ照合プログラム記憶媒体
US7249093B1 (en) * 1999-09-07 2007-07-24 Rysix Holdings, Llc Method of and system for making purchases over a computer network
JP2002169959A (ja) * 2000-11-30 2002-06-14 Laurel Intelligent Systems Co Ltd 金融システム
JP2003006449A (ja) * 2001-06-18 2003-01-10 Mist Wireless Technology Kk 取引処理システム、取引処理方法、暗証番号入力装置、取引端末、ホスト装置
JP2004086599A (ja) * 2002-08-27 2004-03-18 Toppan Printing Co Ltd クレジットカード情報管理装置および管理方法並びにそのプログラム
JP4052158B2 (ja) * 2003-03-25 2008-02-27 株式会社日立製作所 Icカードシステムおよびicカード発行方法
US7873572B2 (en) * 2004-02-26 2011-01-18 Reardon David C Financial transaction system with integrated electronic messaging, control of marketing data, and user defined charges for receiving messages
SI2011301T1 (sl) * 2006-04-10 2011-10-28 Trust Integration Services B V Sklop in postopek za varen prenos podatkov
JP2008236449A (ja) * 2007-03-22 2008-10-02 Oki Electric Ind Co Ltd 金融システムとマスタキー登録確認方法
JP2009043196A (ja) * 2007-08-10 2009-02-26 Icon:Kk 手続き代行サーバ装置、停止処理代行サーバ装置、停止処理代行方法及びプログラム
US8713655B2 (en) * 2008-04-21 2014-04-29 Indian Institute Of Technology Method and system for using personal devices for authentication and service access at service outlets
US20120143752A1 (en) * 2010-08-12 2012-06-07 Mastercard International, Inc. Multi-commerce channel wallet for authenticated transactions
US8746553B2 (en) * 2010-09-27 2014-06-10 Mastercard International Incorporated Purchase Payment device updates using an authentication process
KR20120110926A (ko) * 2011-03-30 2012-10-10 주식회사 비즈모델라인 프로그램 식별을 통한 카드 결제 방법 및 시스템과 이를 위한 스마트폰
GB201105765D0 (en) * 2011-04-05 2011-05-18 Visa Europe Ltd Payment system
US20120317628A1 (en) * 2011-06-09 2012-12-13 Yeager C Douglas Systems and methods for authorizing a transaction
CN103858141B (zh) * 2011-08-08 2018-03-30 维萨国际服务协会 带有集成芯片的支付设备
US10515359B2 (en) * 2012-04-02 2019-12-24 Mastercard International Incorporated Systems and methods for processing mobile payments by provisioning credentials to mobile devices without secure elements
WO2013158419A1 (en) * 2012-04-18 2013-10-24 Google Inc. Processing payment transactions without a secure element

Also Published As

Publication number Publication date
JP2018164281A (ja) 2018-10-18
CN106062799A (zh) 2016-10-26
KR102025816B1 (ko) 2019-09-26
EP3077972A4 (en) 2017-08-09
CA2932346A1 (en) 2015-06-11
KR20160091418A (ko) 2016-08-02
MX2016007217A (es) 2016-12-09
KR101809221B1 (ko) 2017-12-14
JP6353537B2 (ja) 2018-07-04
IL245965B (en) 2022-05-01
KR20170139689A (ko) 2017-12-19
CN106062799B (zh) 2022-04-29
AU2014357381A1 (en) 2016-06-16
CL2016001353A1 (es) 2017-05-12
JP2017504871A (ja) 2017-02-09
SG10201800179UA (en) 2018-02-27
HK1227146A1 (zh) 2017-10-13
UA115500C2 (uk) 2017-11-10
RU2663319C2 (ru) 2018-08-03
AU2014357381B2 (en) 2017-03-23
BR112016012527A2 (pt) 2017-08-08
WO2015084755A1 (en) 2015-06-11
NZ720688A (en) 2017-09-29
EP3077972A1 (en) 2016-10-12
IL245965A0 (en) 2016-07-31
CA2932346C (en) 2018-09-04

Similar Documents

Publication Publication Date Title
MX361793B (es) Método y sistema para la autentificación segura del usuario y el dispositivo móvil sin elementos de seguridad.
HK1206900A1 (en) Systems and methods for processing mobile payments by provisioning credentials to mobile devices without secure elements
NZ629125A (en) Credential management system
MX2020014235A (es) Sistemas y metodos para autenticacion segura de solo lectura.
NZ628971A (en) Transaction processing system and method
PH12018502545A1 (en) Increased security through ephemeral keys for software virtual contactless card in mobile phone
PH12019501081A1 (en) Scan and pay method and device utilized in mobile apparatus
MX2015009491A (es) Procedimiento y aparato de autenticacion de usuarios basados en datos de audio y video.
MX2015012794A (es) Metodos y sistemas para autenticar una transaccion con el uso de un dispositivo electronico portatil.
WO2015025282A3 (en) Methods and systems for transferring electronic money
EP4271016A3 (en) Enhanced authentication based on secondary device interactions
EP4325806A3 (en) Geo-fence authorization provisioning
PH12012502573A1 (en) Method and devices for creating and using an identification document that can be displayed on a mobile device
MY190913A (en) Device and method for secure connection
WO2016190918A3 (en) Multiple protocol transaction encryption
MX2017012298A (es) Sistema de procesamiento de pagos utilizando informacion de pago codificada y metodo para el procesamiento de los mismos.
SG2013042429A (en) Method for receiving an electronic receipt of an electronic payment transaction into a mobile device
MX392027B (es) Sistemas y metodos de pago de modos multiples.
IN2014KN02931A (es)
MX2014002399A (es) Metodo y sistema para autorizar una accion en un sitio.
WO2013192564A3 (en) Aggregating online activities
TW201612812A (en) Apparatus and method for self-service payment
MX2019003187A (es) Sistema y metodos para encriptacion punto a punto y tokenizacion mediante un dispositivo movil.
MX2018003170A (es) Verificacion de transacciones de pago.
MY170316A (en) Portable communication device and system and method therefor

Legal Events

Date Code Title Description
FG Grant or registration