WO2006036363A2 - Systeme de numero d'identification personnel (pin) dynamique dialogique a securite elevee et bon marche destine a des cartes de credit et a des demandes de connexion - Google Patents

Systeme de numero d'identification personnel (pin) dynamique dialogique a securite elevee et bon marche destine a des cartes de credit et a des demandes de connexion Download PDF

Info

Publication number
WO2006036363A2
WO2006036363A2 PCT/US2005/029425 US2005029425W WO2006036363A2 WO 2006036363 A2 WO2006036363 A2 WO 2006036363A2 US 2005029425 W US2005029425 W US 2005029425W WO 2006036363 A2 WO2006036363 A2 WO 2006036363A2
Authority
WO
WIPO (PCT)
Prior art keywords
card
pin number
account
transaction
addend
Prior art date
Application number
PCT/US2005/029425
Other languages
English (en)
Other versions
WO2006036363A3 (fr
Inventor
Peng Qin
Original Assignee
Peng Qin
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Peng Qin filed Critical Peng Qin
Publication of WO2006036363A2 publication Critical patent/WO2006036363A2/fr
Publication of WO2006036363A3 publication Critical patent/WO2006036363A3/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions

Definitions

  • Card Verification Number fails when the card is stolen or this number is exposed or intercepted; Address Verification Services becomes void when the cardholder's address is filched and no physical products need to be shipped; Manual Review involves tremendous efforts and resources of the staff which significantly increases the cost for both the merchant and card issuer, and there are many cases that direct contact with the cardholder fails or delays.
  • Password Protection like in the means of Verified by Visa and MasterCard SecureCode also fail when skillful hackers sneak some insidious virus into the users computer to monitor and filter the keystrokes and information browsed or entered, various of such detrimental virus have existence for years and are still evolving to being more perdue by hiding within the processes or threads of other legitimate applications, the encryp ⁇ ion of transmitted data provides " no protection since the iHtbrrnatf ⁇ ; ri u is : "rnferteptetl before being encrypted, the trend of this omnipotent hacker method will become stronger and stronger while other means become more difficult, and the threat of this method is not only to the credit cards but also to all the online accounts requesting login name and password for access, further when the virus is able to scan all local files the whole computer will be compromised; Dynamic Account Number like in American Express Private Payment system is also defeated easily with the login name and password filched by the virus, and unauthorized users can login and get new dynamic card numbers anytime; Smart Card technology has its limitation of the locations of usage
  • the primary object of the present invention is to prevent credit card and debit card fraud with generic highly secure and low cost scheme.
  • Another object of the present invention is to prevent identity fraud of online account administration and usage.
  • An optional object of the present invention is to enhance the security of any system which uses static login name, password or PIN number to grant authentication and authorization to the users.
  • This invention is a highly secure Dialogic Enciphered Dynamic PIN System which is used to prevent fraud of credit card, debit card and any account access on-line and POS transactions effectively with low-cost and convenience.
  • the card or account issuer randomly assigns and securely stores operation addend, short secure PIN number and long secret formula with encryption in the backend database for each account, three numbers are sent to the cardholder or account owner via separate mails.
  • the cardholder or account owner can use touch-tone phones to call the card or account issuer's automated telephone account administration system to update operation addend and secure PIN number or get new secret formula based on sufficient authentication anytime.
  • Each cardholder or account owner has a small special passcode protected calculator to encipher dynamic answer PIN numbers for all transactions of the carcTS and accounts.
  • a request of authentication of the cardholder and authorization of the transaction is sent to the card issuer with the transaction amount and other details by the merchant based on the card number provided by the cardholder, the card issuer assigns a random inquiry PIN number to the transaction and sends it back to the cardholder via merchant, the card holder selects the card from the list in the calculator, enters the transaction amount as the base, then types in the inquiry PIN number and the secure PIN number separately, the calculator does special calculation to the transaction amount by the sequence of secret formula + inquiry PIN number + secure PIN number.
  • This low-cost offline Dialogic Enciphered Dynamic PIN System ensures extremely high security of the online transactions against even the most skillful hackers who can completely monitor all the activities including keystrokes and browsed information on the client's computer while the computer is online or offline, and are capable of decrypting all the encrypted information transmitted through the network.
  • Card Issuer a financial institute like a bank which issues credit cards or debit cards to cardholders.
  • Account Issuer a corporation or institute which generates and holds on-line accounts for the account owners.
  • Card Service Center a corporation which maintains and updates the card issuer directory and other software and information for clients to access and download.
  • Cardholder the legitimate owner and holder of the card.
  • Account owner the legitimate owner of the account.
  • the card or account issuer system has a software component using some aigoritnrrvi ⁇ generare-pseudo random numbers, or a hardware using electronic noise to generate real random numbers, for the 4 or more digit secure PIN numbers, fractional operation addends, and 30 or more digit secret formulas for the accounts, as well as 4 or more digit inquiry PIN numbers for the transactions;
  • the card or account issuer system has a backend database which stores the secure PIN number, operation addend and secret formula in encrypted format for the accounts, as well as caching the transaction information and inquiry PIN number for the transactions;
  • the card or account issuer system has another software component which does special calculation to the transaction amount or base by the sequence of secret formula + inquiry PIN number + secure PIN number, as well as comparing the results with the dynamic answer PIN numbers from the users;
  • the card or account issuer system also has an automated telephone account administration system which allows the cardholder or account owner to call to update secure PIN number, operation addend and secret formula
  • the card service center maintains and updates the card issuer directory containing the name, number, status of enrollment of dynamic PIN program and network address of each card issuer, presents this directory on ⁇ line for merchants to download;
  • the card service center also presents the information related to the Dialogic Enciphered Dynamic PIN System, as well as the card processor and merchant side software component.
  • the card processor and merchant download the software components from the card service center and install them into their websites or terminals, to provide the means for passing additional data between card issuers and users.
  • the cardholder and account owner will get a generic small special passcode protected calculator which stores the card or account type, partial card number or account login name, operation addend, secret formula and secure PIN number for each card or account, does special calculations based on the transaction amount or base by the sequence of secret formula + inquiry PIN number + secure PIN number, displays the card or account type, partial card number or accourrriogin name, inquiry PIN numbered dynamic answer PIN rtumDer ⁇ as well as "pmorm the functions of a regular calculator and phone address notebook.
  • (1 ) addend is a fractional number with 3 significant digits after decimal point, bigger than 0.100, and smaller than 0.999
  • shift(x) means shift xxxx.xxx to x.xxxxxx
  • trim(x) means trim x.xxxxxx to x.xxx

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Finance (AREA)
  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Marketing (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

L'invention concerne un système de numéro d'identification personnel (PIN) dynamique dialogique et à sécurité élevée utilisé pour empêcher, de manière efficace, commode et bon marché, la fraude par carte de crédit et carte de débit, l'accès à un compte quelconque en ligne et la réalisation de transactions POS. Chaque détenteur de carte ou de compte possède une petite calculatrice protégée par un mot de passe spécial permettant de stocker un cumulateur d'opérations et une formule de sécurité longue pour chaque compte. Un émetteur de carte renvoie un code PIN d'interrogation après réception d'une demande de transaction. Le détenteur de carte ou de compte sélectionne la carte ou le compte à partir de la calculatrice, entre la quantité de transactions, le code PIN d'interrogation et un code PIN sécurisé mémorisé. Puis, la calculatrice effectue un calcul spécial relatif à la quantité de transactions ou en fonction d'une séquence renfermant la formule secrète, le code PIN d'interrogation et le code PIN sécurisé, et génère un code PIN de réponse qui est renvoyé à l'émetteur de la carte. On effectue le même calcul du côté émetteur de la carte afin d'authentifier l'utilisateur et de l'autoriser à effectuer simultanément une transaction à sécurité élevée.
PCT/US2005/029425 2004-09-20 2005-08-18 Systeme de numero d'identification personnel (pin) dynamique dialogique a securite elevee et bon marche destine a des cartes de credit et a des demandes de connexion WO2006036363A2 (fr)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US52235404P 2004-09-20 2004-09-20
US60/522,354 2004-09-20
US17874805A 2005-07-12 2005-07-12
US11/178,748 2005-07-12

Publications (2)

Publication Number Publication Date
WO2006036363A2 true WO2006036363A2 (fr) 2006-04-06
WO2006036363A3 WO2006036363A3 (fr) 2009-04-16

Family

ID=36119340

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2005/029425 WO2006036363A2 (fr) 2004-09-20 2005-08-18 Systeme de numero d'identification personnel (pin) dynamique dialogique a securite elevee et bon marche destine a des cartes de credit et a des demandes de connexion

Country Status (1)

Country Link
WO (1) WO2006036363A2 (fr)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2009037335A2 (fr) * 2007-09-20 2009-03-26 Tds Todos Data System Ab Système, procédé et dispositif permettant des interactions avec sécurité dynamique
US8494959B2 (en) 2007-08-17 2013-07-23 Emc Corporation Payment card with dynamic account number
US9626725B2 (en) 2010-12-23 2017-04-18 Facebook, Inc. Using social graph for account recovery
US9727886B2 (en) 2010-12-23 2017-08-08 Facebook, Inc. Predicting real-world connections based on interactions in social networking system

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030163427A1 (en) * 2002-02-27 2003-08-28 Nicholas Ho Chung Fung Activity management method
US20040067750A1 (en) * 2002-10-03 2004-04-08 Engstrom G. Eric Identification based operational modification of a portable electronic device

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030163427A1 (en) * 2002-02-27 2003-08-28 Nicholas Ho Chung Fung Activity management method
US20040067750A1 (en) * 2002-10-03 2004-04-08 Engstrom G. Eric Identification based operational modification of a portable electronic device

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8494959B2 (en) 2007-08-17 2013-07-23 Emc Corporation Payment card with dynamic account number
WO2009037335A2 (fr) * 2007-09-20 2009-03-26 Tds Todos Data System Ab Système, procédé et dispositif permettant des interactions avec sécurité dynamique
EP2043036A1 (fr) * 2007-09-20 2009-04-01 Tds Todos Data System Ab Système, procédé et dispositif pour autoriser une interaction avec une sécurité dynamique
WO2009037335A3 (fr) * 2007-09-20 2009-06-04 Tds Todos Data System Ab Système, procédé et dispositif permettant des interactions avec sécurité dynamique
NO341998B1 (no) * 2007-09-20 2018-03-12 Tds Todos Data System Ab System, fremgangsmåte og anordning for muliggjøring av vekselvirkning med dynamisk sikkerhet
US9626725B2 (en) 2010-12-23 2017-04-18 Facebook, Inc. Using social graph for account recovery
US9727886B2 (en) 2010-12-23 2017-08-08 Facebook, Inc. Predicting real-world connections based on interactions in social networking system
US11848927B1 (en) 2010-12-23 2023-12-19 Meta Platforms, Inc. Using social graph for account recovery

Also Published As

Publication number Publication date
WO2006036363A3 (fr) 2009-04-16

Similar Documents

Publication Publication Date Title
US12052252B2 (en) Systems and methods for third-party interoperability in secure network transactions using tokenized data
US10083285B2 (en) Direct authentication system and method via trusted authenticators
US8567670B2 (en) Dynamic card verification values and credit transactions
US8555079B2 (en) Token management
US8656180B2 (en) Token activation
US20170308896A1 (en) Methods and apparatus for brokering a transaction
US7505941B2 (en) Methods and apparatus for conducting electronic transactions using biometrics
US8972719B2 (en) Passcode restoration
US9053471B2 (en) Apparatus and method for conducting securing financial transactions
CN110084602B (zh) 一种隐私信息受保护的借贷方法和系统、设备及存储介质
US20130226813A1 (en) Cyberspace Identification Trust Authority (CITA) System and Method
US8620824B2 (en) Pin protection for portable payment devices
JP2010170561A (ja) 携帯型電子的課金/認証デバイスとその方法
US11836696B2 (en) Systems and methods for linking high-value tokens using a low-value token
US20090119184A1 (en) Apparatus and method for conducting secure financial transactions
WO2006036363A2 (fr) Systeme de numero d'identification personnel (pin) dynamique dialogique a securite elevee et bon marche destine a des cartes de credit et a des demandes de connexion
US20040015688A1 (en) Interactive authentication process
US11663597B2 (en) Secure e-commerce protocol
EP1172776A2 (fr) Procédé d'authentification certifiée
CA2883873A1 (fr) Systeme de transaction securise
WO2002021469A2 (fr) Procede d'authentification interactive

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KM KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NG NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SM SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LT LU LV MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
NENP Non-entry into the national phase in:

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 05785187

Country of ref document: EP

Kind code of ref document: A2