WO2002028030A2 - Liaison entre un terminal et une partie mobile - Google Patents

Liaison entre un terminal et une partie mobile Download PDF

Info

Publication number
WO2002028030A2
WO2002028030A2 PCT/DE2001/003459 DE0103459W WO0228030A2 WO 2002028030 A2 WO2002028030 A2 WO 2002028030A2 DE 0103459 W DE0103459 W DE 0103459W WO 0228030 A2 WO0228030 A2 WO 0228030A2
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
connection
control unit
identification signal
search query
Prior art date
Application number
PCT/DE2001/003459
Other languages
German (de)
English (en)
Other versions
WO2002028030A3 (fr
Inventor
Albert Honecker
Roland MÄSING
Gerhard Siemens
Original Assignee
Siemens Aktiengesellschaft
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens Aktiengesellschaft filed Critical Siemens Aktiengesellschaft
Publication of WO2002028030A2 publication Critical patent/WO2002028030A2/fr
Publication of WO2002028030A3 publication Critical patent/WO2002028030A3/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • G07F19/201Accessories of ATMs
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0492Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload by using a location-limited connection, e.g. near-field communication or limited proximity of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/04Protocols specially adapted for terminals or networks with limited capabilities; specially adapted for terminal portability
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/51Discovery or management thereof, e.g. service location protocol [SLP] or web services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/50Secure pairing of devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/329Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M1/00Substation equipment, e.g. for use by subscribers
    • H04M1/72Mobile telephones; Cordless telephones, i.e. devices for establishing wireless links to base stations without route selection
    • H04M1/724User interfaces specially adapted for cordless or mobile telephones
    • H04M1/72403User interfaces specially adapted for cordless or mobile telephones with means for local support of applications that increase the functionality
    • H04M1/72409User interfaces specially adapted for cordless or mobile telephones with means for local support of applications that increase the functionality by interfacing with external accessories
    • H04M1/72412User interfaces specially adapted for cordless or mobile telephones with means for local support of applications that increase the functionality by interfacing with external accessories using two-way short-range wireless interfaces
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks

Definitions

  • the invention relates to the establishment of a near field connection between a control unit and a terminal, in particular a self-service terminal of a bank, savings bank or the like according to the preamble of claim 1 and claim 8.
  • a final identification signal called the link key in the Bluetooth standard, is calculated for the closed connection and the data transmission encrypted therein.
  • Such a method is complex and requires the user to enter a read PIN, what takes a lot of time and the risk of incorrect entries.
  • the user To establish the connection, the user must also first make a selection from all devices that can be reached in the near field, called BT devices in the Bluetooth standard. If, for example, a counter hall is full of people, the respective operating parts, such as cell phones, of these people as well as the terminals are displayed to the respective user. This is the
  • the invention is based on the problem of making the connection establishment safer, simpler and faster for the user.
  • the user no longer has to display all devices in his vicinity that are ready to receive, but instead selects, for example, only the class of networked devices (WEB class or WAP class), which would display the networked terminals, but not the cell phones of the bystanders.
  • WEB class or WAP class the class of networked devices
  • the customer would then only be shown three ATMs, for example, between which he could then choose.
  • each device has a fixed identification (similar to a car identification).
  • This identification includes a unique device address and a classification in a device class.
  • Bluetooth differentiates between different device classes, such as B. audio devices, telephony devices, information (WEB, WAP) devices etc.
  • the selection is only possible within the machine if desired, without networked computers of any other type being displayed, as in the WEB class, for example. This reduces the number of devices displayed under the desired selection, thus further accelerating the selection.
  • an identification signal for the establishment of a closed connection is permanently assigned when the first connection is established, the user does not need to enter a PIN or the like again to establish a connection later, but instead is authorized via its identification signal, called the link key in the Bluetooth standard.
  • the link key that was assigned for the first connection establishment must be available both in the control panel and in the machine.
  • the control panel it is usually stored and made available in the machine via a network.
  • connection establishment it is advantageously possible to classify a later connection establishment as the first connection establishment, in order to be able to use an automated teller machine even after a defect in the cell phone or other telecommunication device.
  • FIG. 2 shows a flow chart of the method according to the invention for establishing a connection.
  • the arrangement 1 shows a network of three terminals 2, 3, 4 and a server 5.
  • a user (not shown) carries a telecommunication device 6 with him, for example a cell phone, via radio contact 7, 8, 9, 10 in optionally connect to one of the terminals 2, 3, 4 and the server 5.
  • the terminals 2, 3, 4 are designed, for example, as ATMs or also as vending machines or other service terminals and can be arranged, for example, in bank premises. In many cases, there will only be one terminal 2, 3, 4 in the close range (radius around 10 m to 20 m), but often several terminals 2, 3, 4 are also available for establishing a radio connection 7, 8, 9, 10 stand.
  • a near-field standard whose range does not exceed the above-mentioned radius is preferably used as the radio standard.
  • the Bluetooth standard is recommended here, which provides for a numbering of each device participating in the standard and an identification made possible via it.
  • Other standards are also possible.
  • connection 7, 8, 9 between the control unit 6 and one of the terminals 2, 3, 4 or the server 5 as a secure, closed connection.
  • no third party can intervene in this connection 7, 8, 9, 10. This avoids the so-called "man in the middle” problem.
  • a prerequisite for such a connection is “unity” between the respective terminal 2, 3, 4 or the server 5 as a distributor between the terminals 2, 3, 4 on the one hand and the telecommunication device 6 on the other.
  • a device class with which a connection is desired for example the “WEB” class or the class
  • WAP the search for devices of this class started.
  • all devices 2, 3, 4, 5 of this device class that are within range - here the networked devices, i.e. not the cell phones of other customers - are transmitted to the control unit 6 and the display 11 shows the Users displayed.
  • the name, symbol, color or similar identification (“user-friendly na e ') is transmitted to the display 11 of the control unit 6, which facilitates the assignment to the device to be selected in each case.
  • the user makes the selection from the devices displayed (machine interface: MMI) or that the server 5 automatically assigns a free terminal 2, 3, 4 to the user.
  • the fourth step is automated, namely the request of the control unit 6 (Service discovery protocol: SDP) for the WAP capability of the assigned or selected terminals 2, 3, 4 and for the selection of a channel for the data transmission.
  • SDP Service discovery protocol
  • a query is then carried out automatically in the fifth step as to whether this is the first connection establishment with the operating part 6 present here on the one hand and the specified terminal 2 or the network from the server 5 and the terminals 2, 3, 4 or the network of all machines that are networked with this server 5 are, for example devices from other branches.
  • a number signal is developed between the terminal and the control unit in such a way that the terminal 2 or the network generates a random number and then sends it to the control unit 6.
  • This then prompts the user to enter a PIN.
  • This PIN appears on the display 12 of the terminal 2 and is then to be entered by the user via the keyboard of the control unit, which then sends the PIN to the terminal 2.
  • the terminal 2 and the control unit 6 are then both assigned a so-called key, with the aid of which an intermediate result is calculated independently of the terminal and control unit and compared with one another. If the intermediate result matches, a final identification signal, called the link key in the Bluetooth standard, is calculated for the closed connection and the data transmission encrypted therein. This link key does not need to be registered by the user because it is saved automatically in the control panel.
  • the secure connection is established and the actual data transfer, such as the request for cash payment by entering the EC PIN number, can begin.
  • the link key is stored in the control unit 6, for example on the SIM card, when the first connection is established with the terminal 2 or with the network in which it is integrated, so that the cumbersome procedure after the assignment of a link key for each subsequent connection establishment can be omitted and the secure connection can start directly with the individually encrypted data transmission. If the answer to the first connection is answered in the negative, you can proceed automatically to a security query in which the user is given the opportunity to determine a new identifier despite the link key having been received and stored in the device, for example if the control panel is in Is repair or for other reasons.
  • Transmitters and receivers installed in motor vehicles, for example to enable a drive in banking.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Finance (AREA)
  • Strategic Management (AREA)
  • Theoretical Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)

Abstract

L'invention concerne un procédé permettant d'établir une liaison en champ proche entre une partie de commande et un terminal, en particulier entre un terminal de service automatique d'une banque, d'une caisse d'épargne ou d'une institution analogue, la partie de commande réalisant, pour l'acceptation d'une liaison, une interrogation de recherche de partenaires de communication appropriée. Ce procédé est développé de telle sorte que l'interrogation de recherche peut être limitée à une classe d'appareil. Selon une variante ou en complément, lors de la sécurisation de la liaison empêchant l'intrusion d'un tiers, par l'intermédiaire d'un signal d'identification échangé entre le terminal et la partie de commande, ledit signal est transmis à celle-ci lors d'une première liaison en champ proche entre un terminal et la partie de service, et il reste de façon durable à disposition pour d'autres liaisons en champ proche sécurisées.
PCT/DE2001/003459 2000-09-29 2001-09-07 Liaison entre un terminal et une partie mobile WO2002028030A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE10048481A DE10048481A1 (de) 2000-09-29 2000-09-29 Verbindung zwischen einem Terminal und einem Mobilteil
DE10048481.6 2000-09-29

Publications (2)

Publication Number Publication Date
WO2002028030A2 true WO2002028030A2 (fr) 2002-04-04
WO2002028030A3 WO2002028030A3 (fr) 2003-08-14

Family

ID=7658216

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/DE2001/003459 WO2002028030A2 (fr) 2000-09-29 2001-09-07 Liaison entre un terminal et une partie mobile

Country Status (2)

Country Link
DE (1) DE10048481A1 (fr)
WO (1) WO2002028030A2 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1367797A1 (fr) * 2002-05-30 2003-12-03 Nokia Corporation Système et méthode pour accéder aux services
GB2389996A (en) * 2002-05-27 2003-12-24 Nec Corp Portable data terminal with short-range communication function
WO2008039234A1 (fr) * 2006-09-29 2008-04-03 Sony Ericsson Mobile Communications Ab Dispositif et procédé pour une recherche de contenu entre des dispositifs homologues

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102008016986A1 (de) * 2008-04-03 2009-10-08 Giesecke & Devrient Gmbh Anzeigen von Anzeigedaten

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19732574A1 (de) * 1997-07-29 1999-02-04 Inge Hahnel Einzustellendes Funkgerät zur Suche eines Kommunikations- bzw. Geschäftspartners

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19732574A1 (de) * 1997-07-29 1999-02-04 Inge Hahnel Einzustellendes Funkgerät zur Suche eines Kommunikations- bzw. Geschäftspartners

Non-Patent Citations (5)

* Cited by examiner, † Cited by third party
Title
"Specification of the Bluetooth System, Specification Volume 1, Wireless Connections made easy, Core, v1.0 B" , 1. Dezember 1999 (1999-12-01), Seite 108, 1039-1041 XP002215199 *
"Specification of the Bluetooth System, Specification Volume 1, Wireless Connections made easy, Core, V1.0 B, pages 149-178, Chapter 14 Bluetooth Security" SPECIFICATION OF THE BLUETOOTH SYSTEM, 1. Dezember 1999 (1999-12-01), XP002227118 *
"Specification of the Bluetooth System, Specification Volume 2, Wireless connections made easy, Profiles v1.0B" , 1. Dezember 1999 (1999-12-01), Seite 40-42, 89-90 XP002215200 *
CAMP MICHAEL T: "WAP and Bluetooth technologies - Beyond cable replacement" SIGNAL NEWSLETTER, Nr. 3, November 1999 (1999-11), Seite 3 XP002171357 *
VAINIO JUHA: "Bluetooth Security" , [Online] 25. Mai 2000 (2000-05-25), XP002211441 Helsinki, FI Gefunden im Internet: <URL:http://www.niksula.cs.hut.fi/~jiitv/b luesec.html> [gefunden am 2002-08-28] *

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2389996A (en) * 2002-05-27 2003-12-24 Nec Corp Portable data terminal with short-range communication function
GB2389996B (en) * 2002-05-27 2006-06-07 Nec Corp Portable data terminal
US7158755B2 (en) 2002-05-27 2007-01-02 Nec Corporation Portable data terminal
EP1367797A1 (fr) * 2002-05-30 2003-12-03 Nokia Corporation Système et méthode pour accéder aux services
WO2008039234A1 (fr) * 2006-09-29 2008-04-03 Sony Ericsson Mobile Communications Ab Dispositif et procédé pour une recherche de contenu entre des dispositifs homologues
US7965981B2 (en) 2006-09-29 2011-06-21 Sony Ericsson Mobile Communications Ab Device and method for content searching between peer devices
US8583038B2 (en) 2006-09-29 2013-11-12 Sony Corporation Device and method for content searching between peer devices

Also Published As

Publication number Publication date
DE10048481A1 (de) 2002-05-02
WO2002028030A3 (fr) 2003-08-14

Similar Documents

Publication Publication Date Title
DE60209881T2 (de) Verfahren zum transferieren eines einrichtungskennungsblocks auf einer von der bluetooth-strecke getrennten zweiten kommunikationsstrecke
EP1240631B1 (fr) Procede et systeme de transaction de paiement
DE69429379T2 (de) Betrugsschutz für Kartentransaktionen
DE69521156T2 (de) Verfahren zum Authentisieren eines Schalterterminals in einem System zur Durchführung von Überweisungen
DE69727519T2 (de) Datennetzwerk mit Stimmkontrollmitteln
EP1240632B1 (fr) Procede et systeme de transaction de paiement
EP1145200B1 (fr) Systeme et procede de transaction de paiement
DE19722424C5 (de) Verfahren zum Sichern eines Zugreifens auf ein fernab gelegenes System
DE102012109629A1 (de) Mobiles Mehrfach-Modus-Kundenbetreuungssystem
WO2009003605A2 (fr) Carte prépayée ou de crédit virtuelle et procédé ainsi que système de fourniture de celle-ci et de gestion de paiement électronique
DE19731293A1 (de) Chip Service Point
EP2417550A1 (fr) Procédé d&#39;exécution d&#39;une application au moyen d&#39;un support de données portable
EP1792248A1 (fr) Appareil portatif pour liberer un acces
DE102007024496A1 (de) Waschküchenverwaltungsverfahren und -System
DE69906206T2 (de) Chipkarte mit Zugriff auf eine entfernte Anwendung, Endgerät und zugehöriges Übertragungssystem und Verfahren zum Zugriff auf die entfernte Anwendung mittels dieser Chipkarte
EP1009181A1 (fr) Procédé pour activer une card SIM
DE60001661T2 (de) Tragbares endgerät
WO2002028030A2 (fr) Liaison entre un terminal et une partie mobile
DE10054633C2 (de) Verfahren und System zum Kontrollieren des Zugangs zu Waren und Dienstleistungen
DE19809043A1 (de) Verfahren und Vorrichtung zum universellen und gesicherten Zugang zu Telefonnetzen
WO1998009256A1 (fr) Procede de preparation d&#39;une application de carte a puce et dispositif correspondant
EP1163807B1 (fr) Procede permettant de verifier l&#39;authentification d&#39;une application de gestion d&#39;un systeme de commande de reseau de gestion des telecommunications par un element reseau et element reseau adapte
DE102006037167A1 (de) Verfahren und System zur Durchführung eines Zahlungsvorgangs mit einem Zahlungsmittel
DE10136414A1 (de) Verfahren zum Bezug einer über ein Datennetz angebotenen Leistung
EP3097505B1 (fr) Authentification via un clavier randomisé qui est capté par le dispositif de l&#39;utilisateur sur un canal visuel secondaire

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): CN JP US

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
122 Ep: pct application non-entry in european phase
NENP Non-entry into the national phase

Ref country code: JP