WO2015039739A1 - Authentifizierung 2fa mit qr auf hmd - Google Patents
Authentifizierung 2fa mit qr auf hmd Download PDFInfo
- Publication number
- WO2015039739A1 WO2015039739A1 PCT/EP2014/002476 EP2014002476W WO2015039739A1 WO 2015039739 A1 WO2015039739 A1 WO 2015039739A1 EP 2014002476 W EP2014002476 W EP 2014002476W WO 2015039739 A1 WO2015039739 A1 WO 2015039739A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- display device
- information
- authentication information
- user
- head
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/42—User authentication using separate channels for security data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/22—Payment schemes or models
- G06Q20/26—Debit schemes, e.g. "pay now"
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/42—Confirmation, e.g. check or permission by the legal debtor of payment
- G06Q20/425—Confirmation, e.g. check or permission by the legal debtor of payment using two different networks, one for transaction and one for security confirmation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
-
- G—PHYSICS
- G02—OPTICS
- G02B—OPTICAL ELEMENTS, SYSTEMS OR APPARATUS
- G02B27/00—Optical systems or apparatus not provided for by any of the groups G02B1/00 - G02B26/00, G02B30/00
- G02B27/01—Head-up displays
- G02B27/0101—Head-up displays characterised by optical features
- G02B2027/0138—Head-up displays characterised by optical features comprising image capture systems, e.g. camera
-
- G—PHYSICS
- G02—OPTICS
- G02B—OPTICAL ELEMENTS, SYSTEMS OR APPARATUS
- G02B27/00—Optical systems or apparatus not provided for by any of the groups G02B1/00 - G02B26/00, G02B30/00
- G02B27/01—Head-up displays
- G02B27/0101—Head-up displays characterised by optical features
- G02B2027/014—Head-up displays characterised by optical features comprising information/image processing systems
-
- G—PHYSICS
- G02—OPTICS
- G02B—OPTICAL ELEMENTS, SYSTEMS OR APPARATUS
- G02B27/00—Optical systems or apparatus not provided for by any of the groups G02B1/00 - G02B26/00, G02B30/00
- G02B27/01—Head-up displays
- G02B27/017—Head mounted
- G02B2027/0178—Eyeglass type
-
- G—PHYSICS
- G02—OPTICS
- G02B—OPTICAL ELEMENTS, SYSTEMS OR APPARATUS
- G02B27/00—Optical systems or apparatus not provided for by any of the groups G02B1/00 - G02B26/00, G02B30/00
- G02B27/01—Head-up displays
- G02B27/017—Head mounted
Definitions
- the present invention relates to a method for displaying confidential information having one arranged on a head
- a head-mounted display device is also known by the term Head Mounted Display.
- Display device is worn in front of the eye of a user either integrated in a conventional glasses or mounted on a rack and can represent any type of information.
- the object is achieved by a method for displaying a confidential information according to the independent claim 1 and by the use of a arranged on a head of a user display device according to the independent claim 10.
- the invention is based on the idea of using a service device, a specific display device assigned to it and arranged on a user's head, in order to display confidential information on this display device.
- Authentication information to a service facility via a Air interface wherein the identification information of the service device is known prior to providing the authentication information, and displaying the confidential information on an arranged at the head of the user display device.
- Authentication information is transmitted to the service facility.
- the security is greatly increased because, on the one hand, the user must be in possession of the authentication information and, on the other hand, the confidential information is only transmitted to the display device when the authentication information and the identification information are transmitted with a specific display device or from a specific mobile radio device become. In other words, it requires a certain one of the display device or the mobile device
- the confidential information is confidential
- the authentication information may be a multi-digit number and / or an opto-electronically readable code, such as a barcode and / or a 2D barcode. Both the multi-digit number and the
- Opto-electronically readable code can be read and recognized reliably and error-free with the recording unit of the display device arranged on the head or with the recording unit of the mobile radio device.
- the recording unit can be designed as a camera device or as a video camera device.
- the receiving unit can be arranged on a frame of the head
- the identification information associated with the display device or the mobile device can be information negotiated with the service device, that is to say it can be information which is specified, for example, when ordering the cash card.
- the order of the cash card can be made for example in the financial institution or on the website of the financial institution. This information may describe an object, such as a chair, or an animal, such as a duck. Alternatively, it may be at the
- the mobile telephone number may be directly associated with the display device, that is, the display device is a mobile radio unit, so that the display device arranged on the head by providing suitable means, such as at least one
- Microphone and a speaker / headphone can also be used as a mobile phone.
- the mobile number of the display device can be assigned indirectly by the head
- arranged display device is coupled to a mobile device.
- the coupling of the display device and dgs mobile device can be done for example via Bluetooth, infrared, WLAN and / or any other wireless standard.
- MNO mobile network operator
- the security in the display of the confidential information on the display device arranged at the head of the user can be further improved by the display device, before displaying the confidential information, determining whether it is arranged on the head of a user so that the user sees the display device can.
- the inventive method is particularly advantageous for use with a arranged on a head of the user Display means. In this way it is possible to represent sensitive data particularly safe only for the wearer of the display device.
- Fig. 1 shows a letter containing a new cash card and a
- FIG. 2 shows a simplified representation of a display device arranged on a head of the user
- FIG. 3 shows a sequence of a method according to the invention.
- the confidential information is, for example, an access password (PIN) and / or a secret number, in particular a bank card secret number and / or a credit card secret number.
- PIN access password
- secret number in particular a bank card secret number and / or a credit card secret number.
- Fig. 1 shows a letter 22 with which a financial institution sends a debit card, a debit card and / or a credit card 20 to a user who has ordered a new card 20.
- the letter On the letter is next to the actual letter 18, which describes, for example, the handling of the cash card 20, also the cash card 20 releasably adhered.
- an authentication information 10 is printed on the letter 22 yet. In the shown
- the authentication information 10 is executed as a 2D barcode.
- the authentication information 10 can also be listed as a multi-digit number and / or as an opto-electronically readable code. The only condition is that the authentication information 10 by means of a recording unit 12, such as a camera device (see Fig. 2), can be read and processed.
- the user reads after receiving the cash card 20, in particular the credit card, the
- the head-mounted display device 16 is, for example, a frame 14, which is worn like a pair of glasses on the head and a
- Display device 16 has. Such devices 14, 16 are also referred to as head mounted display (HMD). They have a substantially transparent display device 16, through which the user can see through when carrying the frame 14 and the display device 16. On the display device 16 it is possible to display information in such a way that it is perceived against the background that the wearer of the display device 16 would perceive with his eyes if he would not wear the pointing device 16. For spectacle wearers, the display device 16 can be mounted in front of or behind the actual spectacle lens in such a way that the spectacle wearer is able to recognize the display device 16 as a function of his or her visual impairment. For users without ametropia, a frame 14 can be used, which manages without lenses 17.
- HMD head mounted display
- Such head-mounted display devices 16 may additionally be provided with a receiving device 12, by means of which the user may, for example, take photos and / or videos and is able to provide the display device 16 with information about the environment.
- a computing unit (not shown) may be provided on the frame 14. More information can be found for example in the requirements catalog of Google Glass ® .
- a user uses the pickup unit 12 of the head-mounted display 16.
- the display 16 is not provided with a pickup unit 12, the user can also use the pickup unit 12 of the head-mounted display 16.
- Recording unit 12 of a mobile device (not shown), in particular a smartphone and / or tablet PC use.
- one of the display device 16 or the mobile device (not shown) associated identification information is transmitted together with the read authentication information 10.
- Identification information may be, for example, one of
- Mobile phone number in particular a MSISDN act. This is the user when applying for the cash card 20. Is the MSISDN act.
- Mobile device (not shown) associated identification information to designate an item, such as a chair, or an animal, such as a duck.
- Subject is agreed when applying for the cash card 20 between the user and the financial institution.
- the user indicates this item when transmitting the display device 16 or the mobile device associated identification information.
- Identification information and read authentication information 10 are transmitted to the service facility. If both agree with the information stored in the service device - in a secure environment - then the confidential information is also transmitted via the air interface to the display device 16. If display device 16 is arranged at the head of a user, the confidential information is further displayed on the display device.
- the service facility may be a mobile network operator
- MNO financial institution
- / or a credit card company a financial institution and / or a credit card company.
- Display device and the service device can be done by means of an integrated into the display device mobile device (not shown) or via a mobile phone coupled to the display device.
- the coupling between display device 14, 16 and mobile phone can be done for example via Bluetooth, infrared and / or WLAN. Other radio standards can also be used.
- Fig. 3 shows the essential steps S1-S4 of an inventive
- a user is provided with authentication information 10 in a first step S1. This can be done for example by on the money card 20 containing letter 22 the Authentication information 10 is printed.
- Authentication information 10 may be in the form of a barcode.
- the user reads the authentication information 10 in a next step S2 with a recording unit 12 arranged at the head
- Display device 16 or a recording unit of a mobile device (not shown).
- the content of the barcode which may be a number, for example, read.
- step S3 one of the display device 14, 16 or the mobile device (not shown) associated
- Authentication information 10 transmitted to a service facility.
- the transmission takes place via an air interface of the display device or the mobile device.
- the identification information is the
- Authentication information 10 agree with the stored at the service device information / data, so in a next step S4 the confidential information is transmitted to the display device 16 and displayed there when the display device 16 is arranged at the head of the user.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Software Systems (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephone Function (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
Die vorliegende Erfindung betrifft ein Verfahren zum Anzeigen einer vertraulichen Information, wie beispielsweise einer Geldkarten- und/ oder einer Kreditkartengeheimzahl. Die vertrauliche Information wird, wenn die an eine Serviceeinrichtung übermittelten Informationen mit den dort hinterlegten Informationen übereinstimmen, auf einer an einem Kopf eines Nutzers angeordneten Anzeigeeinrichtung (16) angezeigt.
Description
AUTHENTIFIZIERUNG 2FA MIT QR AUF HMD
Technisches Gebiet
Die vorliegende Erfindung betrifft ein Verfahren zum Anzeigen einer vertraulichen Information mit einer an einem Kopf angeordneten
Anzeigevorrichtung. Eine am Kopf angeordnete Anzeigevorrichtung ist auch unter dem Begriff Head Mounted Display bekannt. Die
Anzeigevorrichtung wird vor dem Auge eines Nutzers wahlweise integriert in eine herkömmliche Brille oder lediglich auf einem Gestell montiert getragen und kann jegliche Art von Informationen darstellen.
Stand der Technik
Es ist bekannt, bei Beantragung einer neuen Kreditkarte oder einer neuen Geldkarte die zugehörige Geheimzahle/ PIN in einem separaten Brief zu übermitteln. Dieses Verfahren weist den Nachteil auf, dass zusätzlich zu der Kreditkarte ein weiterer Brief verschickt werden muss. Dadurch entstehen zusätzlich Kosten und es besteht das Risiko, dass der Brief mit der PIN von einem unbefugten Dritten abgefangen wird.
Ferner ist das sogenannte ePIN- Verfahren bekannt, bei welchem einem Kartenbesitzer die PIN per Kurznachricht (SMS) mitgeteilt wird. Dieses Verfahren weist den Nachteil auf, dass auch der Versand von
Kurznachrichten Kosten verursacht und zusätzlich die Gefahr besteht, dass eine auf der Anzeigevorrichtung eines Mobilfunkgerätes dargestellte PIN von einem in der Nähe stehenden Dritten mitgelesen wird, um die PIN anschließend missbräuchlich einzusetzen.
Darstellung der Erfindung
Es ist eine Aufgabe der vorliegenden Erfindung, die oben genannten
Nachteile bei der Übertragung von PINs zu lösen und ferner ein Verfahren zum Anzeigen einer vertraulichen Information zur Verfügung zu stellen, das es ermöglicht, vertrauliche Informationen sicher und geschützt vor dem Zugriff durch Dritte zu übertragen und darzustellen.
Die Lösung der Aufgabe erfolgt durch ein Verfahren zum Anzeigen einer vertraulichen Information gemäß dem unabhängigen Anspruch 1 sowie durch die Verwendung einer an einem Kopf eines Nutzers angeordneten Anzeigevorrichtung gemäß dem unabhängigen Anspruch 10. Vorteilhafte Ausgestaltungen des erfindungsgemäßen Verfahrens sowie der
erfindungsgemäßen Verwendung ergeben sich aus den Unteransprüchen.
Der Erfindung liegt der Gedanke zugrunde eine einer Serviceeinrichtung, zugeordnete und an einem Kopf eines Nutzers angeordnete bestimmte Anzeigeeinrichtung dazu zu verwenden, um eine vertrauliche Information auf dieser Anzeigevorrichtung darzustellen.
Gemäß der Erfindung umf asst das Verfahren zum Anzeigen der
vertraulichen Information das Bereitstellen einer Serviceeinrichtung, das Bereitstellen einer Authentisierungsinf ormation an einen Nutzer, das
Einlesen der Authentisierungsinf ormation mit einer Aufnahmeeinheit einer am Kopf eines Nutzers angeordneten Anzeigeeinrichtung oder einer
Aufnahmeeinheit eines Mobilfunkgerätes, das Übermitteln einer der
Anzeigeeinrichtung oder dem Mobilfunkgerät zugeordneten
Identifizierungsinformation sowie der eingelesenen
Authentisierungsinformation an eine Serviceeinrichtung über eine
Luftschnittstelle, wobei die Identifizierungsinformation der Serviceeinrichtung vor dem Bereitstellen der Authentisierungsinformation bekannt ist, und das Anzeigen der vertraulichen Information auf einer an dem Kopf des Nutzers angeordneten Anzeigeeinrichtung.
Mit dem erfindungsgemäßen Verfahren ist es besonders vorteilhaft möglich sicherzustellen, dass eine Serviceeinrichtung Informationen an eine
Anzeigeeinrichtung nur dann übermittelt, wenn die Serviceeinrichtung einerseits in Kenntnis der der Anzeigeeinrichtung oder dem Mobilfunkgerät zugeordneten Identifizierungsinformation ist und andererseits die
Identifizierungsinformation sowie eine dem Nutzer bereitgestellte
Authentisierungsinformation an die Serviceeinrichtung übermittelt werden. Auf diese Weise wird die Sicherheit stark erhöht, da zum einen der Nutzer im Besitz der Authentisierungsinformation sein muss und zum anderen die vertrauliche Information nur an die Anzeigeeinrichtung übermittelt wird, wenn die Authentisierungsinformation und die Identifizierungsinformation mit einer bestimmten Anzeigeeinrichtung bzw. von einem bestimmten Mobilfunkgerät übermittelt werden. In anderen Worten ist es erforderlich eine bestimmte der Anzeigeeinrichtung oder dem Mobilfunkgerät
zugeordnete Identifizierungsinformation über die Luftschnittstelle an die Serviceeinrichtung zu senden. Unbefugten Dritten wird es so wesentlich erschwert, einen unberechtigten Zugang zu der vertraulichen Information zu erhalten. Gemäß einer Ausführungsform handelt es sich bei der vertraulichen
Information um ein Zugangspasswort und/ oder eine Geheimzahl, insbesondere eine Geldkartengeheimzahl und/ oder eine
Kreditkartengeheimzahl. Somit wird mit dem erfindungsgemäßen Verfahren
eine besonders sichere und einfache Möglichkeit geschaffen, um diese vertraulichen Informationen zu übertragen.
Gemäß einer weiteren bevorzugten Ausführungsform wird die
Authentisierungsinf ormation elektronisch, beispielsweise per E-Mail, und/ oder per Post bereitgestellt. Bei der Authentisierungsinf ormation kann es sich um eine mehrstellige Zahl und/ oder um einen optoelektronisch lesbaren Code, wie beispielsweise einen Barcode und/ oder einen 2D- Barcode handeln. Sowohl die mehrstellige Zahl als auch der
optoelektronisch lesbare Code können zuverlässig und fehlerfrei mit der Aufnahmeeinheit der am Kopf angeordneten Anzeigeeinrichtung bzw. mit der Aufnahmeeinheit des Mobilfunkgerätes eingelesen und erkannt werden.
Gemäß einer weiteren Ausführungsform kann die Aufnahmeeinheit als Kameraeinrichtung bzw. als Videokameraeinrichtung ausgebildet sein. Die Aufnahmeeinheit kann an einem Gestell der am Kopf angeordneten
Anzeigeeinrichtung ausgebildet sein.
Bei der der Anzeigeeinrichtung oder dem Mobilfunkgerät zugeordneten Identifizierungsinformation kann es sich um eine mit der Serviceeinrichtung ausgehandelte Information handeln, d.h., es kann sich um eine Information handeln, die beispielsweise bei Bestellung der Geldkarte angegeben wird. Die Bestellung der Geldkarte kann beispielsweise in dem Geldinstitut oder auf der Webseite des Geldinstituts erfolgen. Diese Information kann einen Gegenstand, wie beispielsweise einen Stuhl, oder ein Tier, wie beispielsweise eine Ente, beschreiben. Alternativ kann es sich bei der der
Anzeigeeinrichtung oder dem Mobilfunkgerät zugeordneten
Identifizierungsinformation um eine der Anzeigeeinrichtung oder dem Mobilfunkgerät zugeordnete Mobiltelefonnummer, insbesondere eine
MSISDN handeln. Die Mobiltelefonnummer kann der Anzeigeeinrichtung direkt zugeordnet sein, d.h., in der Anzeigeeinrichtung befindet sich eine Mobilfunkeinheit, so dass die an dem Kopf angeordnete Anzeigeeinrichtung durch Vorsehen von geeigneten Einrichtungen, wie zumindest einem
Mikrophon und einem Lautsprecher/ Kopfhörer auch als Mobilfunktelefon eingesetzt werden kann. Alternativ kann die Mobiltelefonnummer der Anzeigeeinrichtung indirekt zugeordnet sein, indem die am Kopf
angeordnete Anzeigeeinrichtung mit einem Mobilfunkgerät gekoppelt wird. Die Kopplung der Anzeigeeinrichtung und dgs Mobilfunkgeräts kann beispielsweise über Bluetooth, Infrarot, WLAN und/ oder irgendeinen anderen Funkstandard erfolgen.
Gemäß einer weiteren Ausführungsform kann es sich bei der
Serviceeinrichtung um einen Mobilfunknetzbetreiber (MNO), ein
Geldinstitut und/ oder ein Kreditkartenunternehmen handeln. Für den Fall, dass es sich um ein Geldinstitut und/ oder ein Kreditkartenunternehmen handelt, sind diesem die übermittelte Identifizierungsinformation sowie die übermittelte und eingelesene Authentisierungsinf ormation von dem
Mobilfunknetzbetreiber mittels geeigneter Datenübertragungsverfahren bereitzustellen.
Die Sicherheit bei der Anzeige der vertraulichen Informationen auf der an dem Kopf des Nutzers angeordneten Anzeigevorrichtung kann weiter verbessert werden, indem die Anzeigevorrichtung vor dem Anzeigen der vertraulichen Informationen feststellt, ob sie an dem Kopf eines Nutzers angeordnet ist, so dass der Nutzer die Anzeigeeinrichtung sehen kann.
Das erfindungsgemäße Verfahren eignet sich besonders vorteilhaft zur Verwendung mit einer an einem Kopf des Nutzers angeordneten
Anzeigeeinrichtung. Auf diese Weise wird es ermöglicht, sensible Daten besonders sicher nur für den Träger der Anzeigeeinrichtung darzustellen.
Kurze Beschreibung der Zeichnungen
Nachfolgend wird die Erfindung anhand einer in den Zeichnungen dargestellten Ausführungsform näher erläutert. Es zeigen:
Fig. 1 ein Schreiben enthaltend eine neue Geldkarte und eine
Authentisierungsinformation,
Fig. 2 eine vereinfachte Darstellung einer an einem Kopf des Nutzers angeordneten Anzeigeeinrichtung, und Fig. 3 einen Ablauf eines erfindungsgemäßen Verfahrens.
Ausführliche Beschreibung bevorzugter Ausführungsformen der Erfindung
Im Folgenden wird das erfindungsgemäße Verfahren zum Anzeigen einer vertraulichen Information anhand einer beispielhaften Ausführungsform unter Bezugnahme auf die Fig. 1 bis 3 beschrieben.
Bei der vertraulichen Information handelt es sich beispielsweise um ein Zugangspasswort (PIN) und/ oder eine Geheimzahl, insbesondere eine Geldkartengeheimzahl und/ oder eine Kreditkartengeheimzahl.
Fig. 1 zeigt ein Schreiben 22, mit welchem ein Geldinstitut eine Geldkarte, eine Debitkarte und/ oder eine Kreditkarten 20 an einen Nutzer schickt, der eine neue Karte 20 bestellt hat. Auf dem Schreiben ist neben dem
eigentlichen Anschreiben 18, das beispielsweise den Umgang mit der Geldkarte 20 beschreibt, auch die Geldkarte 20 lösbar aufgeklebt. Zusätzlich zu dem Anschreiben 18 und der Geldkarte 20 ist auf dem Schreiben 22 noch eine Authentisierungsinformation 10 aufgedruckt. In dem gezeigten
Ausführungsbeispiel ist die Authentisierungsinformation 10 als 2D-Barcode ausgeführt. Alternativ kann die Authentisierungsinformation 10 auch als mehrstellige Zahl und/ oder als optoelektronisch lesbarer Code aufgeführt sein. Bedingung ist nur, dass die Authentisierungsinformation 10 mittels einer Aufnahmeeinheit 12, wie beispielsweise einer Kameraeinrichtung (siehe Fig. 2), eingelesen und verarbeitet werden kann.
Bei dem erfindungsgemäßen Verfahren liest der Nutzer nach dem Erhalt der Geldkarte 20, insbesondere der Kreditkarte, die
Authentisierungsinformation 10 mit der Aufnahmeeinheit 12 einer am Kopf angeordneten Anzeigeeinrichtung 6 ein. Bei der am Kopf angeordneten Anzeigeeinrichtung 16 handelt es sich beispielsweise um ein Gestell 14, welches wie eine Brille am Kopf getragen wird und über eine
Anzeigeeinrichtung 16 verfügt. Derartige Einrichtungen 14, 16 werden auch als Head Mounted Display (HMD) bezeichnet. Sie verfügen über eine im Wesentlichen transparente Anzeigeeinrichtung 16, durch welche der Nutzer beim Tragen des Gestells 14 und der Anzeigeeinrichtung 16 hindurchsehen kann. Auf der Anzeigeeinrichtung 16 ist es möglich Informationen so darzustellen, dass diese vor dem Hintergrund wahrgenommen werden, den der Träger der Anzeigeeinrichtung 16 mit den Augen wahrnehmen würde, wenn er die Allzeigeeinrichtung 16 nicht tragen würde. Bei Brillenträgern kann die Anzeigeeinrichtung 16 derart vor oder hinter dem eigentlichen Brillenglas angebracht werden, dass der Brillenträger in Abhängigkeit von seiner Sehschwäche in der Lage ist, die Anzeigeeinrichtung 16 zu erkennen. Bei Nutzern ohne Fehlsichtigkeit kann ein Gestell 14 verwendet werden,
welches ohne Brillengläser 17 auskommt. Derartige am Kopf angeordnete Anzeigeeinrichtungen 16 können zusätzlich mit einer Aufnahmeeinrichtung 12 versehen sein, mittels welcher der Nutzer beispielsweise Fotos und/ oder Videos aufnehmen kann und die im Stande ist, die Anzeigeeinrichtung 16 mit Informationen über die Umgebung zu versorgen. Zur Ansteuerung, Auswertung und Verarbeitung der Informationen der Aufnahmeeinheit 12 bzw. um die Anzeigeeinrichtung 16 anzusteuern, kann eine Recheneinheit (nicht gezeigt) an dem Gestell 14 vorgesehen sein. Weitere Informationen dazu finden sich beispielsweise im Anforderungskatalog von Google Glass®.
Um die bereitgestellte Authentisierungsinformation 10 einzulesen,
verwendet ein Nutzer die Aufnahmeeinheit 12 der am Kopf angeordneten Anzeigeeinrichtung 16. Für den Fall, dass die Anzeigeeinrichtung 16 nicht mit einer Aufnahmeeinheit 12 versehen ist, kann der Nutzer auch die
Aufnahmeeinheit 12 eines Mobilfunkgerätes (nicht gezeigt), insbesondere eines Smartphones und/ oder Tablet-PCs, verwenden.
Ferner wird eine der Anzeigeeinrichtung 16 oder dem Mobilfunkgerät (nicht gezeigt) zugeordnete Identifizierungsinformation gemeinsam mit der eingelesenen Authentisierungsinformation 10 übermittelt. Bei der
Identifizierungsinformation kann es sich beispielsweise um eine der
ArLzeigeeinrichrung und/ oder dem Mobilfunkgerät zugeordnete
Mobiltelefonnummer, insbesondere eine MSISDN, handeln. Diese gibt der Nutzer bei Beantragung der Geldkarte 20 an. Ist die
Identifizierungsinformation eine MSISDN, gibt der Nutzer diese dem
Bereitstellen der Authentisierungsinformation 10 an.
Alternativ kann es sich bei der der Anzeigeeinrichtung 16 oder dem
Mobilfunkgerät (nicht gezeigt) zugeordneten Identifizierungsinformation
um die Bezeichnung eines Gegenstands, wie beispielsweise von einem Stuhl, oder eines Tieres, wie beispielsweise von einer Ente, handeln. Dieser
Gegenstand wird beim Beantragen der Geldkarte 20 zwischen dem Nutzer und dem Geldinstitut vereinbart. Der Nutzer gibt diesen Gegenstand beim Übermitteln der der Anzeigeeinrichtung 16 oder dem Mobilfunkgerät zugeordneten Identifizierungsinformation an.
Identifizierungsinformation und eingelesene Authentif izierungsinf ormation 10 werden an die Serviceeinrichtung übermittelt. Stimmen beide mit den bei der Serviceeinrichtung - in einer gesicherten Umgebung - gespeicherten Informationen überein, dann wird die vertrauliche Information ebenfalls über die Luftschnittstelle an die Anzeigeeinrichtung 16 übermittelt. Ist Anzeigeeinrichtung 16 am Kopf eines Nutzers angeordnet, wird die vertrauliche Information ferner auf der Anzeigeeinrichtung angezeigt. Bei der Serviceeinrichtung kann es sich um einen Mobilfunknetzbetreiber
(MNO), ein Geldinstitut und/ oder ein Kreditkartenunternehmen handeln.
Die Übermittlung über die Luftschnittstelle zwischen der
Anzeigeeinrichtung und der Serviceeinrichtung kann mittels einer in die Anzeigeeinrichtung integrierten Mobilfunkeinrichtung (nicht gezeigt) oder über ein mit der Anzeigeeinrichtung gekoppeltes Mobil telefon erfolgen. Die Kopplung zwischen Anzeigeeinrichtung 14, 16 und Mobiltelefon kann beispielsweise über Bluetooth, Infrarot und/ oder WLAN erfolgen. Andere Funkstandards können ebenfalls verwendet werden.
Fig. 3 zeigt die wesentlichen Schritte S1-S4 eines erfindungsgemäßen
Verfahrens. Danach wird einem Nutzer in einem ersten Schritt Sl eine Authentisierungsinformation 10 bereitgestellt. Dies kann beispielsweise erfolgen, indem auf dem die Geldkarte 20 enthaltenden Brief 22 die
Authentisierungsinformation 10 aufgedruckt ist. Die
Authentisierungsinformation 10 kann in Form eines Barcodes vorliegen.
Der Nutzer liest die Authentisierungsinformation 10 in einem nächsten Schritt S2 mit einer Aufnahmeeinheit 12 einer am Kopf angeordneten
Anzeigeeinrichtung 16 oder einer Aufnahmeeinheit eines Mobilfunkgeräts (nicht gezeigt) ein. Beim Einlesen wird, wenn es sich um einen Barcode handelt, der Inhalt des Barcodes, der beispielsweise eine Zahl sein kann, ausgelesen.
Anschließend werden (Schritt S3) eine der Anzeigeeinrichtung 14, 16 oder dem Mobilfunkgerät (nicht gezeigt) zugeordnete
Identifizierungsinformation und die eingelesene
Authentisierungsinformation 10 an eine Serviceeinrichtung übermittelt. Die Übermittlung erfolgt über eine Luftschnittstelle der Anzeigeeinrichtung oder des Mobilfunkgerätes. Die Identifizierungsinformation ist der
Serviceeinrichtung bereits vor dem Bereitstellen der
Authentisierungsinformation 10, also bereits bevor der Brief 22 mit der Geldkarte 20 an den Nutzer geschickt wird, bekannt.
Wenn die Identifizierungsinformation und die eingelesene
Authentifizierungsinformation 10 mit den bei der Serviceeinrichtung hinterlegten Informationen/ Daten überemstimmen, so wird in einem nächsten Schritt S4 die vertrauliche Information an die Anzeigeeinrichtung 16 übermittelt und dort angezeigt, wenn die Anzeigeeinrichtung 16 an dem Kopf des Nutzers angeordnet ist.
Bezugszeichenliste
10 Authentisierungsinformation 12 Aumahrneeinheit
14 Gestell
16 Anzeigeeinrichtung
18 Anschreiben
20 Geldkarte
22 Brief
Sl bis S4 Verfahrensschritte
Claims
P a t e n t a n s p r ü c h e 1. Verfahren zum Anzeigen einer vertraulichen Information, aufweisend die folgenden Schritte:
- postalisches Bereitstellen einer Authentisierungsinformation (10) an einen Nutzer;
- Einlesen der Authentisierungsinformation (10) mit einer Aufnahme- einheit (12) einer am Kopf angeordneten Anzeigeeinrichtung (14, 16) oder einer Aufnahmeeinheit (12) eines Mobilfunkgerätes;
- Übermitteln einer der Anzeigeeinrichtung (14, 16) oder dem Mobilfunkgerät zugeordneten Identifizierungsinformation und der eingelesenen Authentisierungsinformation (10) an eine Serviceeinrichtung über eine Luft- Schnittstelle, wobei die Identifizierungsinformation der Serviceeinrichtung vor dem Bereitstellen der Authentisierungsinformation (10) bekannt ist;
- Übermitteln der vertraulichen Information an die an den Kopf des Nutzers angeordnete Anzeigeeinrichtung (16) über die Luftschnittstelle, wenn die Identifizierungsinformation und die Authentisierungsinformation mit der bei der Serviceeinrichtung gespeicherten Identifizierungsinformation und der Authentisierungsinformation übereinstimmen und
- Anzeigen der vertraulichen Information auf der an dem Kopf des Nutzers angeordneten Anzeigeeinrichtung (16).
2. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass es sich bei der vertraulichen Information um ein Zugangspasswort und / oder eine Geheimzahl, insbesondere eine Geldkartengeheimzahl, eine Debitkartenge- heimzahl und/ oder eine Kreditkartengeheimzahl handelt.
3. Verfahren nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass die Authentisierungsinformation (10) elektronisch, insbesondere per Email, und/ oder per Post bereitgestellt wird.
4. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass es sich bei der Authentisierungsinformation (10) um eine mehrstellige Zahl, und/ oder einen optoelektronisch lesbaren Code, insbesondere einen Barcode und/ oder einen 2D-Barcode handelt.
5. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Aumahmeernheit als Kameraeinrichtung (12) ausgebildet ist.
6. Verfahren nach einem der vorhergehenden Ansprüche, dadurch ge- kennzeichnet, dass die Identifizierungsinformation eine mit der Serviceeinrichtung ausgehandelte Information und/ oder eine der Anzeigeeinrichtung (14, 16) zugeordnete Mobiltelefonnummer, insbesondere eine MSISDN, ist.
7. Verfahren nach Anspruch 6, dadurch gekennzeichnet, dass die Mobil- telefonnummer der Anzeigeeinrichtung (14, 16) über ein mit der Anzeigeeinrichtung (14, 16) gekoppeltes Mobiltelefon zugeordnet ist.
8. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass es sich bei der Serviceeinrichtung um einen Mobilfunk- netzbetreiber, ein Geldinstitut und/ oder ein Kreditkartenunternehmen handelt.
9. Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die Anzeigeeinrichtung (14, 16) vor dem Anzeigen der
vertraulichen Information feststellt, ob die Anzeigeeinrichtung (14, 16) an dem Kopf eines Nutzers angeordnet ist.
10. Verwendung einer an einem Kopf eines Nutzers angeordneten Anzei- geeinrichtung (14, 16) in einem Verfahren nach einem der vorhergehenden Ansprüche.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US15/022,648 US10341330B2 (en) | 2013-09-17 | 2014-09-12 | 2FA authentication with QR on HMD |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102013015382.4 | 2013-09-17 | ||
| DE102013015382.4A DE102013015382A1 (de) | 2013-09-17 | 2013-09-17 | Verfahren zum Anzeigen einer Information |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015039739A1 true WO2015039739A1 (de) | 2015-03-26 |
Family
ID=51585067
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2014/002476 Ceased WO2015039739A1 (de) | 2013-09-17 | 2014-09-12 | Authentifizierung 2fa mit qr auf hmd |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US10341330B2 (de) |
| DE (1) | DE102013015382A1 (de) |
| WO (1) | WO2015039739A1 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10825563B2 (en) | 2018-05-14 | 2020-11-03 | Novarad Corporation | Aligning image data of a patient with actual views of the patient using an optical code affixed to the patient |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070278291A1 (en) * | 2005-12-22 | 2007-12-06 | Rans Jean-Paul E | Methods and Systems for Two-Factor Authentication Using Contactless Chip Cards or Devices and Mobile Devices or Dedicated Personal Readers |
| US20140108260A1 (en) * | 2011-10-17 | 2014-04-17 | Capital One Financial Corporation | System and method for token-based payments |
| US20140244464A1 (en) * | 2013-02-27 | 2014-08-28 | Capital One Financial Corporation | System and method for providing a user-loadable stored value card |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060115130A1 (en) * | 2004-11-29 | 2006-06-01 | Douglas Kozlay | Eyewear with biometrics to protect displayed data |
| GB0910897D0 (en) * | 2009-06-24 | 2009-08-05 | Vierfire Software Ltd | Authentication method and system |
| US20110153503A1 (en) * | 2009-12-23 | 2011-06-23 | Charles Blewett | Device and Method for Identity Theft Resistant Transcations |
| US8613065B2 (en) * | 2010-02-15 | 2013-12-17 | Ca, Inc. | Method and system for multiple passcode generation |
| US9105023B2 (en) * | 2010-02-26 | 2015-08-11 | Blackberry Limited | Methods and devices for transmitting and receiving data used to activate a device to operate with a server |
| JP2012174208A (ja) * | 2011-02-24 | 2012-09-10 | Sony Corp | 情報処理装置、情報処理方法、プログラム及び端末装置 |
| EP2509275A1 (de) * | 2011-04-04 | 2012-10-10 | Buntinx | Verfahren und System zur Authentifizierung von Einheiten mittels mobiler Endgeräte |
| FR2985149A1 (fr) * | 2011-12-23 | 2013-06-28 | France Telecom | Procede d'acces par un terminal de telecommunication a une base de donnees hebergee par une plateforme de services accessible via un reseau de telecommunications |
| US8677116B1 (en) * | 2012-11-21 | 2014-03-18 | Jack Bicer | Systems and methods for authentication and verification |
| US9979547B2 (en) * | 2013-05-08 | 2018-05-22 | Google Llc | Password management |
-
2013
- 2013-09-17 DE DE102013015382.4A patent/DE102013015382A1/de not_active Ceased
-
2014
- 2014-09-12 US US15/022,648 patent/US10341330B2/en active Active
- 2014-09-12 WO PCT/EP2014/002476 patent/WO2015039739A1/de not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070278291A1 (en) * | 2005-12-22 | 2007-12-06 | Rans Jean-Paul E | Methods and Systems for Two-Factor Authentication Using Contactless Chip Cards or Devices and Mobile Devices or Dedicated Personal Readers |
| US20140108260A1 (en) * | 2011-10-17 | 2014-04-17 | Capital One Financial Corporation | System and method for token-based payments |
| US20140244464A1 (en) * | 2013-02-27 | 2014-08-28 | Capital One Financial Corporation | System and method for providing a user-loadable stored value card |
Non-Patent Citations (3)
| Title |
|---|
| ABHAS TANDON ET AL: "QR Code based secure OTP distribution scheme for Authentication in Net-Banking", INTERNATIONAL JOURNAL OF ENGINEERING AND TECHNOLOGY, 1 June 2013 (2013-06-01), pages 2502 - 2505, XP055151840, Retrieved from the Internet <URL:http://doaj.org/search?source=%7B%22query%22%3A%7B%22bool%22%3A%7B%22must%22%3A%5B%7B%22term%22%3A%7B%22id%22%3A%2242bffb162bcd496aa4efb60e7d091bdc%22%7D%7D%5D%7D%7D%7D> * |
| ANONYMOUS: "Glassauth Google Glass APP - 2step authentication for Google Accounts | Google Glass APPs", 9 May 2013 (2013-05-09), XP055151832, Retrieved from the Internet <URL:https://web.archive.org/web/20130509042225/http://glass-apps.org/glassauth-google-glass-app-2step-authentication-for-google-accounts> [retrieved on 20141110] * |
| ANONYMOUS: "Local Backup Codes - OTP Google Authenticator", 5 July 2013 (2013-07-05), XP055151835, Retrieved from the Internet <URL:https://web.archive.org/web/20130705075656/https://support.google.com/accounts/answer/1187538> [retrieved on 20141110] * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20160234194A1 (en) | 2016-08-11 |
| US10341330B2 (en) | 2019-07-02 |
| DE102013015382A1 (de) | 2015-03-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102013104499A1 (de) | Sichere Zahlungen mit nicht vertrauenswürdigen Vorrichtungen | |
| DE102015006907A1 (de) | Endgerät und Verfahren für mobiles Bezahlen | |
| DE112014001975T5 (de) | Verfahren und System zur sicheren Dateneingabe in eine Einheit | |
| DE112012001536T5 (de) | System und Verfahren zur Ermöglichung sicherer SMS-Übertragung | |
| DE102011116489A1 (de) | Mobiles Endgerät, Transaktionsterminal und Verfahren zur Durchführung einer Transaktion an einem Transaktionsterminal mittels eines mobilen Endgeräts | |
| DE102014000644A1 (de) | Verfahren zum Autorisieren einer Transaktion | |
| DE112015000746T5 (de) | Sichere Transaktionsverarbeitung in einem Kommunikationssystem | |
| DE102013015382A1 (de) | Verfahren zum Anzeigen einer Information | |
| EP2883182B1 (de) | Vorrichtungsanordnung zur durchführung oder freigabe eines elektronischen diensts und verfahren zum sicheren eingeben von autorisierungsdaten | |
| DE102014002602B4 (de) | Verfahren zum Autorisieren einer Transaktion sowie Verwendung einer Uhr und eines Kassensystems in diesem Verfahren | |
| WO2016096110A1 (de) | Verfahren zur echtheitsprüfung eines sicherheitsmerkmals, das auf einem dokument angeordnet ist | |
| DE102017101159A1 (de) | Kommunikationssystem zur entfernten Unterstützung von Senioren | |
| DE102013015861A1 (de) | Verfahren zum Zugänglichmachen einer Information | |
| DE102017123113A1 (de) | Vorrichtung zum Speichern von Kennwörtern | |
| DE102014018860A1 (de) | Verifikation mit Webcam | |
| DE102019104025A1 (de) | Verfahren und System zur Durchfühung einer Versicherungstransaktion | |
| DE102014011853A1 (de) | Verfahren zum Durchführen einer Finanztransaktion | |
| DE10043554C2 (de) | Datennetzbasiertes Identifizierungsverfahren | |
| DE102017128807A1 (de) | Verfahren und Anordnung zum Auslösen einer elektronischen Zahlung | |
| DE102013009600B4 (de) | Verfahren zum Authentisieren einer Transaktion | |
| DE102013223082B4 (de) | Identitätsverifikationsverfahren und Identitätsverifikationssystem | |
| DE102024125786A1 (de) | Datenträger, Lesegerät, System und Verfahren zum Erzeugen digitaler Transaktionsbelege | |
| DE202021103299U1 (de) | System zum Sammeln von Bonuspunkten | |
| DE102017119803A1 (de) | Verfahren und System zum Erfassen von Nutzeridentitätsdaten für ein Identitätskonto an einem Point-of-Sale | |
| DE102018106660A1 (de) | Schutzvorrichtung und Verfahren |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14771510 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 15022648 Country of ref document: US |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14771510 Country of ref document: EP Kind code of ref document: A1 |