WO2001027779A1 - Appareil et procede pour transactions en ligne utilisant une carte a puce - Google Patents
Appareil et procede pour transactions en ligne utilisant une carte a puce Download PDFInfo
- Publication number
- WO2001027779A1 WO2001027779A1 PCT/KR2000/001107 KR0001107W WO0127779A1 WO 2001027779 A1 WO2001027779 A1 WO 2001027779A1 KR 0001107 W KR0001107 W KR 0001107W WO 0127779 A1 WO0127779 A1 WO 0127779A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- smart card
- encryption algorithm
- client
- transmitted
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/22—Payment schemes or models
- G06Q20/229—Hierarchy of users of accounts
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
- G06Q20/3552—Downloading or loading of personalisation data
Definitions
- the present invention relates to an apparatus and a method for online transaction using a smart card, and more particularly, to an apparatus and a method for online transaction using a smart card that stores a predetermined encryption algorithm, in which transmission and reception of information or payment between a bank to a client or another bank is achieved using the smart card.
- the non-contact type IC card includes an RF-ID card for just reading serial numbers, an RF-IC card capable of reading and writing data with basic operations, and a combination card which has the advantages of both the RF-ID card and the RF-IC card.
- the contact type IC card which receives power and a predetermined signal from a terminal by physical contact with the terminal, is classified as a smart card if it has a microprocessor, and a memory card if it does not have a microprocessor.
- a plastic contact type smart card a predetermined information is stored by a signal from a terminal, and information stored in the smart card is read as the smart card is passed through a card reader.
- a bunch of plastic cards with MSRW are encrypted with the same algorithm, and banking facilities periodically distribute a bunch of the plastic cards through their branches, so the distribution cost is high.
- the encryption algorithm of only one of the distributed plastic cards is exposed to a third party, all the plastic cards must be collected and replaced by new plastic cards.
- a security problem may occur because the predetermined encryption algorithm for a particular banking facility is exposed to the other banking facilities.
- an online transaction apparatus using a pair of smart cards storing a predetermined encryption algorithm comprising: a communications unit connected to a predetermined network established between a client and a bank or a banking facility, in a wired or wireless manner, the communications unit for exchanging information between the client and the bank or the banking facility; a controlling unit for encrypting information to be transmitted from the communications unit through the network using the predetermined encryption algorithm stored in one of the smart cards, or decrypting the encrypted information received through the network from the communications unit using the predetermined encryption algorithm stored in the other smart card; and an input and output unit for outputting information received by or to be transmitted from the communications unit, or inputting characters or numerals to edit the information.
- an online transaction method using a pair of smart cards in which information is exchanged between a bank or a banking facility, and a client or another banking facility, each of the bank or banking facility and the client or another banking facility serving as a transmitter or a receiver, through a predetermined network, the method comprising the steps of: (a) providing the pair of smart cards storing the same encryption algorithm and smart card readers for reading the encryption algorithm stored in the smart cards to the transmitter and the receiver; and (b) encrypting information to be transmitted according to the encryption algorithm stored in the transmitter's smart card, and decrypting the encrypted information according to the encryption algorithm stored in the receiver's smart card.
- the present invention provides an online transaction method using smart cards, in which information is exchanged between at least two clients including first and second clients, via at least two banking facilities including first and second banking facilities, each of the clients and banking facilities serving as a transmitter or a receiver, the first client, the first banking facility, the second client and the second banking facility being connected in succession through predetermined networks, the method comprising: providing a pair of smart cards storing the same encryption algorithm and smart card readers to a corresponding transmitter and receiver pair; once information to be transmitted to the second client is prepared by the first client, encrypting the information to be transmitted according to the encryption algorithm stored in the first client's smart card; at least one of the banking facilities editing information being transmitted by decrypting and encrypting the transmitted information according to a predetermined encryption algorithm stored in its smart card; and once the edited information is received by the second client, decrypting the received information according to the encryption algorithm stored in the second client's smart card to read the received information.
- FIG. 1 is a block diagram of an embodiment of an online transaction apparatus using a smart card according to the present invention
- FIG. 2 is a flowchart illustrating an embodiment of an online transaction method using a smart card according to the present invention. Best mode for carrying out the Invention
- an embodiment of an online transaction apparatus using a smart card includes a communications unit 12, a controlling unit 14, a smart card read unit 16 and an input and output unit 18.
- the communications unit 12 is connected to a predetermined network 10 to communicate with banking facilities, such as a bank.
- the communications unit 12 may include a modem, and an antenna for wireless communications.
- the controlling unit 14 When information is transmitted from the communications unit 12 through the network 10, the controlling unit 14 encrypts information to be transmitted according to a predetermined encryption algorithm stored in the smart card. When information is received by the communications unit 12 through the network 10, the controlling unit 14 decrypts the received information using the predetermined encryption algorithm stored in the smart card.
- the controlling unit 14 may be implemented as a microprocessor or an electronic circuit having a microprocessor.
- the input and output unit 18 includes a liquid crystal display (LCD) or a monitor for displaying information received or to be transmitted by the communications unit 12, and a keyboard for inputting or editing information.
- the keyboard may have keys for characters or numerals.
- the smart card read unit 16 may include a smart card reader.
- the smart card reader can read a predetermined encryption algorithm stored in an integrated circuit (IC) or a memory embedded in a smart card (not shown) as the smart card is passed through the slit of the smart card reader.
- IC integrated circuit
- a memory embedded in a smart card not shown
- FIG. 2 An embodiment of an online transaction method by the online transaction apparatus, which has the configuration as described above with reference to FIG. 1 , will be described with reference to FIG. 2.
- each of the bank or banking facility and the client or another banking facility serve as a transmitter or a receiver.
- an exporter and an importer who desire to exchange information via an export bank and an import bank.
- For communications and transactions among them there are established a first network between the export and the export bank which has opened an account to the exporter, a second network between the importer and the import bank which has opened an account to the importer, and a third network between the export and import banks.
- a pair of smart cards in which the same encryption algorithm is stored, and a smart card read unit 16 are provided to each of the transmitter and the receiver who are connected each other through the first, second or third network (step 20).
- the encryption algorithm stored in the transmitter's smart card is read (step 21 ), and information to be transmitted is encrypted according to the read encryption algorithm and transmitted by the transmitter (step 22).
- the transmitted information is received by the receiver (step 23).
- the encryption algorithm stored in the receiver's smart card is read, and the information from the transmitter is decrypted according to the read encryption algorithm (step 25). Following this, transactions between the transmitter and the receiver are achieved according to the decrypted information.
- a pair of smart cards storing a predetermined encryption algorithm are provided to the importer and the exporter.
- the predetermined encryption algorithm stored in the smart cards is the key that ensures secured transmission and reception of information for transactions.
- the exporter when an exporter desires to transmit information for a contrast with an importer, the exporter as a transmitter passes the smart card that he or she has through the smart card read unit 16 to read the encryption algorithm stored in the smart card so as to send a predetermined information to the export bank concerned, which acts as a receiver in this communications (step 21 ). Then, the information to be transmitted to the export bank is encrypted by the controlling unit 14 shown in FIG. 1 according to the encryption algorithm read by the smart card read unit 16 (step 22).
- the encrypted information is transmitted through the communications unit 12 and the network 10 to the export bank, and the transmitted information is received by a communication unit of an online transaction apparatus installed at the receiver's site, i.e., at the export bank (step 23).
- the encryption algorithm stored in the receiver's smart card which is paired with the transmitter's smart card, is read by a smart card read unit of the receiver's online transaction apparatus (step 24).
- the encrypted information from the exporter is decrypted by a controlling unit 14 of the receiver's online transaction apparatus according to the encryption algorithm read by the smart card read unit 16 of the receiver's online transaction apparatus (step 25).
- the inventive online transaction can be achieved between an export bank as a transmitter and an import bank as a receiver, or between an import bank as a transmitter and an importer as a receiver.
- information from the exporter is transmitted to the export bank concerned, the import bank, and the importer in succession.
- both the export bank and the import bank are involved in the transactions between the exporter and the importer.
- Information on the credit status or accounts of the exporter and the importer can be transmitted or received.
- a predetermined encryption algorithm can be stored in a smart card by at least one of the banking facilities concerned that need encryption and decryption of information for transmission and reception, or by a smart card manufacturer associated with the banking facilities.
- a pair of smart cards for a corresponding transmitter and receiver pair for example, for the exporter and the export bank connected through the first network, for the importer and the import bank connected through the second network, and for the export bank and the import bank connected through the third network, store the same encryption algorithm therein to allow the transmitter and receiver pair to do convenient encryption or decryption of information.
- each of the pairs of smart cards for the first network, the second network and the third network must have different encryption algorithms. It will be appreciate that although information transmitted and received through the first, second and third networks are the same, the information can be encrypted in different ways.
- information to be transmitted is encrypted at a transmitter's site and then decrypted at a receiver's site to read the transmitted information using smart cards storing a predetermined encryption algorithm, so that there is no concern about illegal alteration of communications telegraphs.
- Banking facilities can conveniently one-to-one communicate with their clients or other banking facilities concerned using smart cards each storing a proper encryption algorithm.
- the encryption algorithm varies for different networks, and thus information can be exchanged with many clients or other banking facilities through a plurality of networks with increased security.
- the encryption algorithm of a smart cart is exposed to a third party, it is enough to replace a pair of smart cards storing the encryption algorithm, without need for replacing all the smart cards distributed. Thus, the restoration costs for security becomes low.
- each banking facility can independently produce smart cards for transactions with its clients, and set a predetermined encryption algorithm for the smart cards. No conflict of interest between the competitive banking facilities in manufacturing smart cards occurs.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
AU76908/00A AU7690800A (en) | 1999-10-08 | 2000-10-04 | Apparatus and method for online transaction using smart card |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR10-1999-0043512A KR100457994B1 (ko) | 1999-10-08 | 1999-10-08 | 스마트 카드에 의한 온라인 결제 장치 및 방법 |
KR1999/43512 | 1999-10-08 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2001027779A1 true WO2001027779A1 (fr) | 2001-04-19 |
Family
ID=19614547
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/KR2000/001107 WO2001027779A1 (fr) | 1999-10-08 | 2000-10-04 | Appareil et procede pour transactions en ligne utilisant une carte a puce |
Country Status (4)
Country | Link |
---|---|
KR (1) | KR100457994B1 (fr) |
CN (1) | CN1387647A (fr) |
AU (1) | AU7690800A (fr) |
WO (1) | WO2001027779A1 (fr) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN100438409C (zh) * | 2006-06-22 | 2008-11-26 | 北京飞天诚信科技有限公司 | 具有金融交易报文处理能力的智能卡及其工作方法 |
Families Citing this family (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR100408890B1 (ko) * | 2000-06-20 | 2003-12-11 | 케이비 테크놀러지 (주) | 다중 인증경로를 이용한 신용거래 인증방법 및 이를이용한 시스템 |
KR20020026505A (ko) * | 2002-03-04 | 2002-04-10 | 이성훈 | 휴대형 보안장치를 이용한 전자상거래 인증 및isp 결제서비스 방법 |
KR20040006651A (ko) * | 2002-07-13 | 2004-01-24 | 한국아이씨카드연구조합 | 스마트 카드기반의 구매장치에서의 보안시스템 및 그 방법 |
KR100719798B1 (ko) * | 2004-10-27 | 2007-05-18 | 이니텍(주) | 금융 집적 회로 카드와 컴퓨터를 이용한 금융 거래 방법및 온라인 결제 방법 |
CN101009555B (zh) * | 2006-12-29 | 2010-12-29 | 北京飞天诚信科技有限公司 | 一种智能密钥装置与主机信息交互的方法 |
KR100893125B1 (ko) * | 2007-07-27 | 2009-04-10 | (주)세나라플러스 | 자체 암호화 과정을 수행하는 개인용 atm을 이용한 금융서비스 제공 방법 및 시스템 |
CN101127954B (zh) * | 2007-09-21 | 2010-08-18 | 冯卫东 | 一种基于手机拨号通讯或gprs分组通讯技术实现数据传送的方法 |
CN102315940B (zh) * | 2011-09-08 | 2013-09-18 | 飞天诚信科技股份有限公司 | 一种数据的传输与处理系统及方法 |
CN104715545A (zh) * | 2015-03-17 | 2015-06-17 | 萧东 | 安全自动交易机及其方法 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US4736094A (en) * | 1984-04-03 | 1988-04-05 | Omron Tateisi Electronics Co. | Financial transaction processing system using an integrated circuit card device |
US5461217A (en) * | 1994-02-08 | 1995-10-24 | At&T Ipm Corp. | Secure money transfer techniques using smart cards |
US5793027A (en) * | 1994-12-19 | 1998-08-11 | Samsung Electronics Co., Ltd. | IC card for credit transactions and credit transaction apparatus and method using the same |
US5943423A (en) * | 1995-12-15 | 1999-08-24 | Entegrity Solutions Corporation | Smart token system for secure electronic transactions and identification |
-
1999
- 1999-10-08 KR KR10-1999-0043512A patent/KR100457994B1/ko active IP Right Grant
-
2000
- 2000-10-04 WO PCT/KR2000/001107 patent/WO2001027779A1/fr active Application Filing
- 2000-10-04 AU AU76908/00A patent/AU7690800A/en not_active Abandoned
- 2000-10-04 CN CN00815276A patent/CN1387647A/zh active Pending
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US4736094A (en) * | 1984-04-03 | 1988-04-05 | Omron Tateisi Electronics Co. | Financial transaction processing system using an integrated circuit card device |
US5461217A (en) * | 1994-02-08 | 1995-10-24 | At&T Ipm Corp. | Secure money transfer techniques using smart cards |
US5793027A (en) * | 1994-12-19 | 1998-08-11 | Samsung Electronics Co., Ltd. | IC card for credit transactions and credit transaction apparatus and method using the same |
US5943423A (en) * | 1995-12-15 | 1999-08-24 | Entegrity Solutions Corporation | Smart token system for secure electronic transactions and identification |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN100438409C (zh) * | 2006-06-22 | 2008-11-26 | 北京飞天诚信科技有限公司 | 具有金融交易报文处理能力的智能卡及其工作方法 |
Also Published As
Publication number | Publication date |
---|---|
KR20010036485A (ko) | 2001-05-07 |
CN1387647A (zh) | 2002-12-25 |
KR100457994B1 (ko) | 2004-11-18 |
AU7690800A (en) | 2001-04-23 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP3802074B2 (ja) | 携帯可能な身分証明要素でのトランザクション方法 | |
US6442532B1 (en) | Wireless transaction and information system | |
US4536647A (en) | Pocket banking terminal, method and system | |
US6185307B1 (en) | Cryptography security for remote dispenser transactions | |
AU2008268326B2 (en) | System and method for account identifier obfuscation | |
US6539364B2 (en) | Electronic cash implementing method and equipment using user signature and recording medium recorded thereon a program for the method | |
US5832090A (en) | Radio frequency transponder stored value system employing a secure encryption protocol | |
AU663739B2 (en) | Value transfer system | |
EP3171540B1 (fr) | Système et procédé de remise de clé | |
WO2010135154A2 (fr) | Dispositif contenant des données cryptées de date d'expiration et de création de valeur de vérification | |
US7222108B2 (en) | Electronic cash implementing method and equipment using user signature and recording medium recorded thereon a program for the method | |
CN101138242A (zh) | 交互式电视系统 | |
US6321213B1 (en) | Electronic money processing method having a transaction fee collecting function and an electronic money storage apparatus for the same | |
CN101329786A (zh) | 移动终端获取银行卡磁道信息或支付应用的方法及系统 | |
CN101330675B (zh) | 一种移动支付终端设备 | |
WO2001027779A1 (fr) | Appareil et procede pour transactions en ligne utilisant une carte a puce | |
CN101223729A (zh) | 对移动支付设备进行更新 | |
JPH1020778A (ja) | 暗号化装置および復号化装置、並びにicカード | |
JPH05504643A (ja) | 金銭移転システム | |
KR20030074853A (ko) | 휴대단말기를 이용한 상거래에서의 금융/id카드본인인증방법 및 그 장치 | |
JP3113063B2 (ja) | 情報処理システム | |
JP2000507380A (ja) | 安全モジュール | |
AU8349998A (en) | Secure transactions | |
KR100696077B1 (ko) | Sam 서버를 이용한 ic 카드 발급 시스템 및 그 방법 | |
JPH0447862B2 (fr) |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DE DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG US UZ VN YU ZA ZW |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
DFPE | Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101) | ||
WWE | Wipo information: entry into national phase |
Ref document number: 008152764 Country of ref document: CN |
|
WWE | Wipo information: entry into national phase |
Ref document number: 10110063 Country of ref document: US |
|
122 | Ep: pct application non-entry in european phase | ||
NENP | Non-entry into the national phase |
Ref country code: JP |