WO2002008974A3 - Ameliorations portant sur la securite de systemes d'authentification - Google Patents

Ameliorations portant sur la securite de systemes d'authentification Download PDF

Info

Publication number
WO2002008974A3
WO2002008974A3 PCT/GB2001/003298 GB0103298W WO0208974A3 WO 2002008974 A3 WO2002008974 A3 WO 2002008974A3 GB 0103298 W GB0103298 W GB 0103298W WO 0208974 A3 WO0208974 A3 WO 0208974A3
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
subset
data element
challenge
user
Prior art date
Application number
PCT/GB2001/003298
Other languages
English (en)
Other versions
WO2002008974A2 (fr
Inventor
Giles Martin Wren-Hilton
Original Assignee
Nexxgen Ltd
Giles Martin Wren-Hilton
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from GB0018047A external-priority patent/GB0018047D0/en
Priority claimed from GB0111978A external-priority patent/GB0111978D0/en
Application filed by Nexxgen Ltd, Giles Martin Wren-Hilton filed Critical Nexxgen Ltd
Priority to AU2001270912A priority Critical patent/AU2001270912A1/en
Publication of WO2002008974A2 publication Critical patent/WO2002008974A2/fr
Publication of WO2002008974A3 publication Critical patent/WO2002008974A3/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/04Billing or invoicing
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/04Payment circuits
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Development Economics (AREA)
  • Marketing (AREA)
  • Economics (AREA)
  • Computer Security & Cryptography (AREA)
  • Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)
  • Telephonic Communication Services (AREA)

Abstract

L'invention concerne un procédé et un système d'authentification d'un stockage d'authentification personnelle, tel qu'une carte de paiement, destinés à être utilisés afin d'authentifier l'identité d'un utilisateur. Le procédé tient dans la réalisation d'une tâche consistant à recevoir un identificateur unique du stockage d'authentification personnelle, à identifier des premier et second sous-ensembles d'éléments de données prédéterminés en utilisant l'identificateur unique, à sélectionner un élément de données provenant du premier sous-ensemble et à émettre cet élément de données vers l'utilisateur en tant que tâche d'authentification. Chaque sous-ensemble a été auparavant choisi parmi un ensemble plus important correspondant d'éléments de données et chaque élément de données du premier sous-ensemble correspond à un élément spécifique des éléments de données du second sous-ensemble. L'authentification est déterminée par la réception d'une réponse à la tâche d'authentification provenant de l'utilisateur, déterminée par utilisation de l'information fournie par le stockage d'autorisation personnelle, et par la délivrance d'un signal d'authentification si la réponse comprend l'élément de données spécifique du second sous-ensemble qui correspond à l'élément de données du premier sous-ensemble utilisé pour la tâche.
PCT/GB2001/003298 2000-07-21 2001-07-23 Ameliorations portant sur la securite de systemes d'authentification WO2002008974A2 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
AU2001270912A AU2001270912A1 (en) 2000-07-21 2001-07-23 Improvements relating to the security of authentication systems

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
GB0018047.1 2000-07-21
GB0018047A GB0018047D0 (en) 2000-07-21 2000-07-21 Improvements in and relating to authentication cards and systems
GB0111978.3 2001-05-16
GB0111978A GB0111978D0 (en) 2001-05-16 2001-05-16 Improvements in and relating to authentication cards and systems

Publications (2)

Publication Number Publication Date
WO2002008974A2 WO2002008974A2 (fr) 2002-01-31
WO2002008974A3 true WO2002008974A3 (fr) 2003-05-01

Family

ID=26244707

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/GB2001/003298 WO2002008974A2 (fr) 2000-07-21 2001-07-23 Ameliorations portant sur la securite de systemes d'authentification

Country Status (2)

Country Link
AU (1) AU2001270912A1 (fr)
WO (1) WO2002008974A2 (fr)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8224887B2 (en) 2003-03-26 2012-07-17 Authenticatid, Llc System, method and computer program product for authenticating a client
US9191215B2 (en) 2003-12-30 2015-11-17 Entrust, Inc. Method and apparatus for providing authentication using policy-controlled authentication articles and techniques
US8060915B2 (en) 2003-12-30 2011-11-15 Entrust, Inc. Method and apparatus for providing electronic message authentication
US8230486B2 (en) 2003-12-30 2012-07-24 Entrust, Inc. Method and apparatus for providing mutual authentication between a sending unit and a recipient
US9281945B2 (en) 2003-12-30 2016-03-08 Entrust, Inc. Offline methods for authentication in a client/server authentication system
US8966579B2 (en) 2003-12-30 2015-02-24 Entrust, Inc. Method and apparatus for providing authentication between a sending unit and a recipient based on challenge usage data
US8612757B2 (en) 2003-12-30 2013-12-17 Entrust, Inc. Method and apparatus for securely providing identification information using translucent identification member
US7347366B2 (en) * 2006-03-14 2008-03-25 Verisign, Inc. Method and apparatus to provide authentication using an authentication card
US7739169B2 (en) 2007-06-25 2010-06-15 Visa U.S.A. Inc. Restricting access to compromised account information
US9742761B2 (en) 2015-11-10 2017-08-22 International Business Machines Corporation Dynamic authentication for a computing system
CN113469694A (zh) * 2021-07-27 2021-10-01 中国银行股份有限公司 一种低视力人群手机软件登录和支付的方法和装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2058417A (en) * 1979-06-25 1981-04-08 Gao Ges Automation Org Input of a Personal Code Word
US4958066A (en) * 1988-08-19 1990-09-18 Secured Transactions Financial instrument verification and method of production
FR2654238A1 (fr) * 1989-11-07 1991-05-10 Lefevre Jean Pierre Procede d'authentification de l'identite d'une personne physique et dispositif authentificateur de mise en óoeuvre du procede.
US5177789A (en) * 1991-10-09 1993-01-05 Digital Equipment Corporation Pocket-sized computer access security device
US5712627A (en) * 1995-04-19 1998-01-27 Eastman Chemical Company Security system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2058417A (en) * 1979-06-25 1981-04-08 Gao Ges Automation Org Input of a Personal Code Word
US4958066A (en) * 1988-08-19 1990-09-18 Secured Transactions Financial instrument verification and method of production
FR2654238A1 (fr) * 1989-11-07 1991-05-10 Lefevre Jean Pierre Procede d'authentification de l'identite d'une personne physique et dispositif authentificateur de mise en óoeuvre du procede.
US5177789A (en) * 1991-10-09 1993-01-05 Digital Equipment Corporation Pocket-sized computer access security device
US5712627A (en) * 1995-04-19 1998-01-27 Eastman Chemical Company Security system

Also Published As

Publication number Publication date
WO2002008974A2 (fr) 2002-01-31
AU2001270912A1 (en) 2002-02-05

Similar Documents

Publication Publication Date Title
US6398115B2 (en) System for authenticating use of transaction cards having a magnetic stripe
CN105379409B (zh) Ehf安全通信设备
CN100570631C (zh) 存取控制方法、安全模块保持器以及安全模块
CA2208055A1 (fr) Systeme de verification de l'utilisation d'une carte de credit/d'identite, a enregistrement des attributs physiques des utilisateurs non autorises
WO2001057750A8 (fr) Systeme d'authentification
BR9807372A (pt) Método de verificar autorização
CN101233476A (zh) 带有近场通信的大容量存储设备
MY122139A (en) Personal identification authenticating with fingerprint identification
NZ232106A (en) Secure data interchange system: verification of card, terminal and user validity
CA2140803A1 (fr) Methode d'authentification de terminaux pour systeme d'execution de transactions
AU1470795A (en) Method and apparatus for authenticating a data carrier intended to enable a transaction or access to a service or a location, and corresponding carrier
EP0391261A3 (fr) Méthode et dispositif pour réaliser de la monnaie électronique
AU8427498A (en) Method and system for payment by electronic cheque
WO2006100171A1 (fr) Carte de credit securisee a communications en champ proche
US7543337B2 (en) System and method for automatic verification of the holder of an authorization document and automatic establishment of the authenticity and validity of the authorization document
GB2050021A (en) Method and means for securing the distribution of encoding keys
CA2026739A1 (fr) Methode et dispositif de securite pour systeme transactionnel
EP0440800A4 (en) Ic card for security attestation and ic card service system using said ic card
WO2002065253A3 (fr) Procede, systeme et moyen de securite pour authentifier un utilisateur
WO2001075864A8 (fr) Identificateur electronique
WO2002008974A3 (fr) Ameliorations portant sur la securite de systemes d'authentification
ES2185217T3 (es) Procedimiento para la verificacion de la autenticidad de un soporte de datos.
CA2094026C (fr) Methode et appareil d'identification de personnes
EP1046976A3 (fr) Méthode et appareil pour permettre à un utilisateur d'authentifier un système avant la présentation d'informations privilégiées
WO2002003285A8 (fr) Procede et systeme ainsi que porteuse de donnees permettant l'authentification d'un client souhaitant obtenir un service ou un produit d'un fournisseur

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG US UZ VN YU ZA ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
REG Reference to national code

Ref country code: DE

Ref legal event code: 8642

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 69(1) EPC (EPO FORM 1205A DATED 06.06.03)

122 Ep: pct application non-entry in european phase
NENP Non-entry into the national phase

Ref country code: JP