WO2022225298A1 - 초광대역통신을 이용한 결제 방법 및 장치 - Google Patents
초광대역통신을 이용한 결제 방법 및 장치 Download PDFInfo
- Publication number
- WO2022225298A1 WO2022225298A1 PCT/KR2022/005586 KR2022005586W WO2022225298A1 WO 2022225298 A1 WO2022225298 A1 WO 2022225298A1 KR 2022005586 W KR2022005586 W KR 2022005586W WO 2022225298 A1 WO2022225298 A1 WO 2022225298A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- electronic device
- uwb
- payment
- identification information
- ranging
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 87
- 238000004891 communication Methods 0.000 title claims description 95
- 230000004044 response Effects 0.000 claims abstract description 39
- 230000000977 initiatory effect Effects 0.000 claims abstract description 32
- 238000012545 processing Methods 0.000 claims description 41
- 230000006870 function Effects 0.000 description 23
- 238000012913 prioritisation Methods 0.000 description 23
- 238000005516 engineering process Methods 0.000 description 18
- 230000000875 corresponding effect Effects 0.000 description 17
- 101100012910 Plasmodium falciparum (isolate FC27 / Papua New Guinea) FIRA gene Proteins 0.000 description 12
- 238000010586 diagram Methods 0.000 description 6
- XQCFHQBGMWUEMY-ZPUQHVIOSA-N Nitrovin Chemical compound C=1C=C([N+]([O-])=O)OC=1\C=C\C(=NNC(=N)N)\C=C\C1=CC=C([N+]([O-])=O)O1 XQCFHQBGMWUEMY-ZPUQHVIOSA-N 0.000 description 4
- 238000004590 computer program Methods 0.000 description 4
- 238000007726 management method Methods 0.000 description 4
- 241000287219 Serinus canaria Species 0.000 description 3
- 230000008901 benefit Effects 0.000 description 3
- 230000015556 catabolic process Effects 0.000 description 3
- 238000006731 degradation reaction Methods 0.000 description 3
- 230000003111 delayed effect Effects 0.000 description 3
- 230000008569 process Effects 0.000 description 3
- 230000003068 static effect Effects 0.000 description 3
- 230000001010 compromised effect Effects 0.000 description 2
- 239000003999 initiator Substances 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 230000001755 vocal effect Effects 0.000 description 2
- 238000003491 array Methods 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 230000001413 cellular effect Effects 0.000 description 1
- 230000002596 correlated effect Effects 0.000 description 1
- 230000001934 delay Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000036541 health Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 238000005259 measurement Methods 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/325—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices using wireless networks
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/16—Payments settled via telecommunication systems
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/326—Payment applications installed on the mobile devices
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
- G06Q20/38215—Use of certificates or encrypted proofs of transaction rights
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4015—Transaction verification using location information
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
- G06Q20/4093—Monitoring of device authentication
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/42—Confirmation, e.g. check or permission by the legal debtor of payment
- G06Q20/425—Confirmation, e.g. check or permission by the legal debtor of payment using two different networks, one for transaction and one for security confirmation
Definitions
- the present disclosure relates to UWB communication, and more particularly, to a payment method and apparatus using UWB.
- the Internet is evolving from a human-centered connection network where humans create and consume information, to an Internet of Things (IoT) network that exchanges and processes information between distributed components such as objects.
- IoT Internet of Things
- IoE Internet of Everything
- sensing technology wired/wireless communication and network infrastructure, service interface technology, and security technology
- M2M Machine to Machine
- MTC Machine Type Communication
- an intelligent IT (Internet Technology) service that collects and analyzes data generated from connected objects and creates new values in human life can be provided.
- the IoT is a smart home, smart building, smart city, smart car or connected car, smart grid, health care, smart home appliance, advanced medical service, etc. can be applied in the field of
- a method for effectively providing these services is required.
- a ranging technique for measuring a distance between electronic devices using Ultra Wide Band (UWB) may be used.
- the present disclosure provides a method for performing secure proximity payment using UWB.
- the present disclosure provides a proximity payment method and a UWB message for solving a connection delay problem that occurs when UWB secure ranging is performed using out-of-band (OOB) communication.
- OOB out-of-band
- a method of a first electronic device for processing a payment using UWB communication includes broadcasting a UWB initiation message including certificate information of the first electronic device; receiving, from at least one second electronic device, a UWB response message including identification information of a payment application included in the second electronic device and certificate information of the payment application; and determining a priority for the at least one second electronic device based on the UWB response message.
- a UWB initiation message including certificate information of the first electronic device is received from a first electronic device to do; acquiring identification information of a payment application included in the second electronic device; and transmitting, to the first electronic device, a UWB response message including identification information of the payment application and certificate information of the payment application. can do.
- a first electronic device for processing a payment using UWB communication includes a transceiver; and a control unit connected to a transceiver, wherein the control unit: broadcasts a UWB initiation message including certificate information of the first electronic device, from at least one second electronic device, to the second electronic device Receives a UWB response message including at least one of identification information of a payment application included in and certificate information of the payment application for verifying the identification information, and based on the UWB response message, the at least one second electronic device may be configured to determine priorities for
- a second electronic device for processing a payment using UWB communication includes a transceiver; and a control unit connected to a transceiver, wherein the control unit: receives, from a first electronic device, a UWB initiation message including certificate information of the first electronic device, and pays included in the second electronic device Acquire identification information of an application, and transmit, to the first electronic device, a UWB response message including identification information of the payment application and certificate information of the payment application for verifying the identification information.
- the security of the proximity payment may be increased.
- the proximity payment method and the UWB message of the present disclosure it is possible to solve a connection delay problem that occurs when UWB security ranging is performed using OOB communication.
- FIG. 1 illustrates an exemplary layer configuration of an electronic device supporting a UWB-based service.
- FIG. 2 shows an exemplary configuration of a communication system including an electronic device supporting a UWB-based service.
- FIG 3 shows an exemplary configuration of a framework included in an electronic device supporting a UWB-based service.
- FIG. 4 illustrates a proximity payment method through secure ranging using OOB communication.
- FIG. 5 illustrates a proximity payment method through secure ranging according to an embodiment of the present disclosure.
- FIG. 6 illustrates a payment scenario using a proximity payment method through secure ranging according to an embodiment of the present disclosure.
- FIG. 7 illustrates a prioritization step of the proximity payment method according to an embodiment of the present disclosure.
- FIG. 8 illustrates a security ranging step of a proximity payment method according to an embodiment of the present disclosure.
- FIG 9 illustrates a payment processing system according to an embodiment of the present disclosure.
- FIG. 10 is a flowchart illustrating a method of a first electronic device according to an embodiment of the present disclosure.
- FIG. 11 is a flowchart illustrating a method of a second electronic device according to an embodiment of the present disclosure.
- FIG. 12 is a diagram illustrating a structure of a first electronic device according to an embodiment of the present disclosure.
- FIG. 13 is a diagram illustrating a structure of a second electronic device according to an embodiment of the present disclosure.
- each block of the flowchart diagrams and combinations of the flowchart diagrams may be performed by computer program instructions.
- These computer program instructions may be embodied in a processor of a general purpose computer, special purpose computer, or other programmable data processing equipment, such that the instructions performed by the processor of the computer or other programmable data processing equipment are not described in the flowchart block(s). It creates a means to perform functions.
- These computer program instructions may also be stored in a computer-usable or computer-readable memory that may direct a computer or other programmable data processing equipment to implement a function in a particular manner, and thus the computer-usable or computer-readable memory.
- the instructions stored in the flowchart block(s) may also be possible for the instructions stored in the flowchart block(s) to produce an article of manufacture containing instruction means for performing the function described in the flowchart block(s).
- the computer program instructions may also be mounted on a computer or other programmable data processing equipment, such that a series of operational steps are performed on the computer or other programmable data processing equipment to create a computer-executed process to create a computer or other programmable data processing equipment. It may also be possible for instructions to perform the processing equipment to provide steps for performing the functions described in the flowchart block(s).
- each block may represent a module, segment, or portion of code that includes one or more executable instructions for executing specified logical function(s). It should also be noted that in some alternative implementations it is also possible for the functions recited in the blocks to occur out of order. For example, two blocks shown one after another may in fact be performed substantially simultaneously, or it may be possible that the blocks are sometimes performed in a reverse order according to a corresponding function.
- ' ⁇ unit' used in this embodiment means software or hardware components such as FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit), and ' ⁇ unit' performs certain roles. do.
- '-part' is not limited to software or hardware.
- ' ⁇ unit' may be configured to reside on an addressable storage medium or may be configured to refresh one or more processors.
- ' ⁇ part' refers to components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, and programs. Includes procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, and variables.
- components and ' ⁇ units' may be combined into a smaller number of components and ' ⁇ units' or further separated into additional components and ' ⁇ units'.
- components and ' ⁇ units' may be implemented to play one or more CPUs in a device or secure multimedia card.
- ' ⁇ unit' may include one or more processors.
- the term 'terminal' or 'device' refers to a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit. may be referred to as a (Subscriber Unit), Subscriber Station (SS), wireless device, wireless communication device, Wireless Transmit/Receive Unit (WTRU), mobile node, mobile or other terms.
- Various embodiments of the terminal include a cellular phone, a smart phone having a wireless communication function, a personal digital assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, and a digital camera having a wireless communication function.
- PDA personal digital assistant
- the terminal may include a machine to machine (M2M) terminal and a machine type communication (MTC) terminal/device, but is not limited thereto.
- M2M machine to machine
- MTC machine type communication
- the terminal may be referred to as an electronic device or simply a device.
- wireless sensor network technology is largely divided into a wireless local area network (WLAN) technology and a wireless personal area network (WPAN) technology according to a recognition distance.
- the wireless LAN is a technology based on IEEE 802.11, and it is a technology that can connect to a backbone network within a radius of about 100 m.
- the wireless private network is a technology based on IEEE 802.15, and includes Bluetooth, ZigBee, and ultra wide band (UWB).
- a wireless network in which such a wireless network technology is implemented may include a plurality of electronic devices.
- UWB may refer to a wireless communication technology that uses a bandwidth of 500 MHz or more, or a bandwidth corresponding to a center frequency of 20% or more.
- UWB may mean a band itself to which UWB communication is applied.
- UWB enables secure and accurate ranging between devices.
- the operation of the UWB-based service includes a service initiation step for initiating a UWB-based service, a key provisioning step for providing a key for security, and a discovery step for discovering a device. ), a connection step including secure channel creation and parameter exchange, and/or a UWB ranging step for measuring a distance/direction (angle) between devices.
- the service initiation phase and the UWB ranging phase may be a mandetory phase, but the key provisioning phase, discovery phase, and connection phase may be optional phases.
- the service initiation phase, the key provisioning phase, and the UWB ranging phase may be a mandetory phase, but the discovery phase and the connection phase may be optional phases.
- ADF Application Dedicated File
- SE Secure Element
- application specific data application specific data
- An “Application Protocol Data Unit (APDU)” may be a command and a response used when communicating with a Secure Element (SE) (eg, an embedded SE).
- SE Secure Element
- application specific data may be, for example, data used by a specific service and application regardless of a location (eg, applet, device, etc.).
- Controller may be a Ranging Device that defines and controls Ranging Control Messages (RCM).
- the ranging device may be, for example, an Enhanced Ranging Device (ERDEV) defined in the IEEE Std 802.15.4z specification.
- ELDEV Enhanced Ranging Device
- Controllee may be a ranging device using a ranging parameter in the RCM received from the controller.
- “Dynamic STS” may be an operation mode in which STS is not repeated during a ranging session.
- the STS may be managed by the Ranging device, and the Ranging Session Key generating the STS may be managed by the Secure Component.
- Applet may be an Applet that implements an APDU interface executed on a Secure Component and is identified by an Application (Applet) ID (AID). This applet can host the data needed for secure ranging.
- the Applet may be, for example, a FiRa Applet defined in the FIRA CONSORTIUM COMMON SERVICE & MANAGEMENT LAYER (CSML) specification.
- Ranging Device is a Ranging Device capable of communicating with another Ranging Device using predefined profiles (eg, UWB-enabled door lock), or a predefined UWB for performing a ranging session with another Ranging Device. It may be a ranging device capable of supporting a ranging service.
- the Ranging Device may be referred to as a UWB Device or a UWB Ranging Device.
- the Ranging Device may be, for example, a FiRa Device defined in the FIRA CONSORTIUM CSML specification.
- UWB-enabled Application may be an application using Framework API for configuring OOB Connector, Secure Service, and/or UWB service for UWB session.
- UWB-enabled Application may be abbreviated as an application or a UWB application.
- the UWB-enabled Application may be, for example, a FiRa-enabled Application defined in the FIRA CONSORTIUM CSML specification.
- a “Framework” may be a collection of logical software components including an OOB Connector, a Secure Service, and/or a UWB service.
- the Framework may be, for example, the FiRa Framework defined in the FIRA CONSORTIUM CSML specification.
- OOB Connector may be a software component for establishing out-of-band (OOB) communication (eg, Bluetooth Low Energy (BLE) communication) between Ranging Devices.
- OOB out-of-band
- BLE Bluetooth Low Energy
- the OOB Connector may be, for example, a FiRa OOB Connector defined in the FIRA CONSORTIUM CSML specification.
- Profile may be a predefined set of UWB and OOB configuration parameters.
- the Profile may be, for example, a FiRa Profile defined in the FIRA CONSORTIUM CSML specification.
- Profile Manager can implement profiles available in Ranging Device.
- the Profile Manager may be, for example, a FiRa Profile Manager defined in the FIRA CONSORTIUM CSML specification.
- Smart Ranging Device may host one or more UWB-enabled Applications, and may be a Ranging Device that can implement Framework, or a Ranging device that implements a specific service application provided by a manufacturer (eg, a physical access reader). ).
- the Smart Ranging Device may be a Ranging Device capable of installing multiple UWB-enabled Applications in order to support a UWB ranging-based service to perform a ranging session with another ranging device or a Smart Ranging Device.
- the Smart Ranging Device may be, for example, a FiRa Smart Device defined in the FIRA CONSORTIUM CSML specification.
- GDF Global Dedicated File
- Framework API may be an API used by a UWB-enabled Application to communicate with the Framework.
- “Initiator” may be a Ranging Device that initiates a ranging exchange.
- OID Object Identifier
- SP service provider
- Out-Of-Band (OOB)” may be data communication that does not use UWB as an underlying wireless technology.
- Responder may be a Ranging Device that responds to the Initiator in a ranging exchange.
- “Scrambled Timestamp Sequence (STS)” may be a ciphered sequence for increasing the integrity and accuracy of ranging measurement timestamps.
- the STS may be generated from a ranging session key.
- a “Secure Channel” may be a data channel that prevents overhearing and tampering.
- “Secure Component” may be a component that interfaces with UWBS for the purpose of providing RDS to UWBS, for example, when dynamic STS is used. It can also host UWB-enabled Application data.
- Secure Element may be a tamper-resistant secure hardware component that can be used as a Secure Component in the Ranging Device.
- “Secure Service” may be a component for interfacing with a Secure Component of a system, such as a Secure Element or a Trusted Execution Environment (TEE).
- a Secure Component of a system such as a Secure Element or a Trusted Execution Environment (TEE).
- TEE Trusted Execution Environment
- Static STS is an operation mode in which the STS is repeated during a session, and does not need to be managed by the Secure Component.
- SUS Applet may be an Applet on a Secure Component that operates as an end point for a Secure Channel between UWBS and a Secure Component such as SE.
- UWB Service may be an implementation-specific software component that provides access to UWBS.
- UWB Session may be considered to be established when the Controller and Controllee(s) can start UWB ranging.
- the UWB Session may be a period from when the Controller and the Controlee start communication through UWB until the communication stops (stop).
- a UWB Session may include ranging, data transfer, and both.
- UWB Session ID may be an ID (eg, integer) identifying a UWB Session.
- UWB Session Key may be a key used to protect the UWB Session.
- the UWB Session Key may be used to generate the STS.
- the UWB Session Key may be a UWB Ranging Session Key (URSK), and may be abbreviated as a session key.
- URSK UWB Ranging Session Key
- UWB Subsystem may be a hardware component implementing the UWB PHY and MAC specifications.
- UWBS may have an interface to FiRa Framework in which UCI logical interface layer is implemented and an interface to Secure Component to search for RDS.
- the UWB PHY and MAC specifications may be, for example, FiRa CONSORTIUM PHY and MAC specifications.
- FIG. 1 illustrates an exemplary layer configuration of an electronic device supporting a UWB-based service.
- the electronic device (UWB device) of FIG. 1 may be, for example, a Smart Ranging Device.
- the electronic device 100 includes a UWB-enabled Application Layer 110 , a Common Service & Management Layer 120 , and/or a UWB subsystem (UWBS) including a UWB MAC Layer and a UWB Physical Layer ( 130) may be included.
- UWBS UWB subsystem
- UWB MAC Layer UWB Physical Layer
- the UWB-enabled Application Layer 100 may be, for example, a layer of an application (eg, FiRa-enabled Application) that uses a Framework API to configure an OOB Connector, Secure Service, and UWB service for a UWB session.
- an application eg, FiRa-enabled Application
- a Framework API to configure an OOB Connector, Secure Service, and UWB service for a UWB session.
- the Common Service & Management Layer 110 may define, for example, common components and procedures necessary to implement UWB secure ranging.
- UWB MAC Layer and the UWB Physical Layer may be collectively referred to as a UWB subsystem (UWBS) 130 .
- UWBS may be based on the FiRa PHY and MAC specifications referencing the IEEE 802.15.4z specification (spec).
- FIG. 2 shows an exemplary configuration of a communication system including an electronic device supporting a UWB-based service.
- the communication system 200 includes a first electronic device 210 and a second electronic device 220 .
- the first electronic device (first UWB device) 210 may be, for example, a Smart Ranging Device
- the second electronic device (second UWB device) 220 may be, for example, a ranging device.
- the first electronic device 210 may host, for example, one or more UWB-enabled Applications 211 that may be installed by a user (eg, a mobile phone). It can be based on the Framework API.
- the second electronic device 220 does not provide the Framework API, and for example, may use a proprietary interface to implement the specific UWB-enabled Application 221 provided only by the manufacturer.
- the first electronic device 210 and the second electronic device 220 are UWB-enabled Application Layer (211,221), Framework (212,222), OOB Component/Connector (213,223), Secure Component (214,224) and/or UWBS (215,225). may include Depending on the embodiment, some components may be omitted or additional components may be further included.
- the first electronic device 210 and the second electronic device 220 may create an OOB connection (channel) through the OOB connectors 213 and 223 and create a UWB connection (channel) through the UWBS 215 and 225 to each other. can communicate.
- FIG 3 shows an exemplary configuration of a framework included in an electronic device supporting a UWB-based service.
- the framework of FIG. 3 may be, for example, FiRa Framework defined in the FIRA CONSORTIUM CSML specification.
- the framework 300 may be a set of logical software components.
- the UWB-enabled Application may interface with the framework through the framework API provided by the framework 300 .
- the framework 300 may include a Profile Manager 310 , an OOB Connector 320 , a Secure Service 330 , and/or a UWB Service 340 .
- a Profile Manager 310 may include a Profile Manager 310 , an OOB Connector 320 , a Secure Service 330 , and/or a UWB Service 340 .
- some components may be omitted or additional components may be further included.
- the Profile Manager component 310 may manage the Profile(s) available on the Ranging Device.
- the Profile may be a set of UWB and OOB configuration parameters required to establish a successful UWB session between Ranging Devices.
- Profile Manager 310 may abstract UWB and OOB configuration parameters from UWB-enabled applications.
- the OOB Connector component 320 may be a component for establishing an OOB connection between Ranging Devices.
- the OOB Connector 320 may handle a Discovery Phase and a Connection Phase for providing a UWB-based service.
- the Secure Service component 330 may play a role of interfacing with a security component such as a Secure Element (SE), an eSE, or a Trusted Execution Environment (TEE).
- SE Secure Element
- eSE eSE
- TEE Trusted Execution Environment
- the security component may be a component that interfaces with UWBS to deliver UWB ranging data to UWBS.
- SE is a secure security module based on the tamper resistant characteristic, but if the contractual relationship between various entities is not established, there are restrictions in installing and running the application.
- the eSE refers to a fixed SE that is fixed and used in an electronic device.
- the eSE is typically manufactured exclusively for the manufacturer at the request of the terminal manufacturer, and may be manufactured including an operating system and a framework.
- the eSE remotely downloads and installs an applet-type service control module, and can be used for various security services such as, for example, electronic wallet, ticketing, e-passport, and digital key.
- the TEE may be, for example, a S/W-centered security environment that creates a virtual separated environment based on codes supported by a specific chipset (eg, ARM-based). TEE does not have tamper resistant characteristics, but has advantages of large available memory, high speed, and low cost compared to SE. In addition, since various service providers can be used immediately within the range allowed by the mobile manufacturer, it has the advantage of lower complexity between entities compared to SE.
- a specific chipset eg, ARM-based
- the UWB Service component 340 may be a component that provides access to UWBS.
- the distance is manipulated by an attacker
- the distance is manipulated by an attacker
- an intentional payment eg, a payment between a user (or user device) and a payment terminal in an actual payment zone
- an intentional payment eg, a compromised payment
- the payment terminal recognizes that a user who is not in the actual payment zone is in the payment zone, and performs payment processing with the user.
- UWB security ranging This problem of distance manipulation can be solved through UWB security ranging.
- the current UWB security ranging is due to problems such as power consumption and concerns about degradation of ranging performance during data communication.
- OOB communication such as BLE
- security components such as eSE and TEE are used in UWB It is carried out by using it in conjunction with communication.
- FIG. 4 illustrates a proximity payment method through secure ranging using OOB communication.
- OOB communication is BLE communication.
- OOB communication is not limited thereto, and other communication methods (eg, ZigBee, NFC, etc.) having the same or similar function may be applied.
- a user in the case of performing security ranging using BLE communication, a user (a payment subject) and a payment terminal 410 who are the target of actual payment processing among a plurality of users capable of communicating with the payment terminal/device 410 . ), a BLE connection (communication channel) between them needs to be established.
- a user may be used to refer to a user's electronic device. That is, in the present disclosure, a user and a user device may be used interchangeably.
- a payment target may be used to refer to an electronic device of a user that is an actual payment processing target. That is, in the present disclosure, the payment subject and the payment subject's electronic device may be used interchangeably.
- a plurality of users for example, a user (User in checkout), a user in a BLE connection state (Users in connection), and/or a user waiting for a connection (User in checkout) through a barcode scan, etc. Users in waiting).
- the user who has performed the checkout may be located in the payment zone (Pay zone) 420 .
- the payment subject is a user of the intended payment, for example, the user closest to the payment terminal or at the front of the specified payment line, the user who performed the checkout, the user within the specified area (eg, the payment zone) , or a user who satisfies at least two of the conditions (eg, a user who is closest to the payment terminal or at the forefront of a predetermined payment line and performs checkout, a user within a payment zone that performs checkout, etc.).
- the BLE connection to the payment target may be delayed due to various factors. For example, when the number of BLE sessions that the payment terminal 410 can support at the same time is smaller than the number of users capable of BLE communication with the payment device 410, the BLE connection to the payment target may be delayed. Alternatively, due to a scan duty cycle or other factors, when the payment subject enters the connection mode the latest, the BLE connection to the payment subject may be delayed. This BLE connection delay causes an increase in the payment time required.
- FIG. 5 illustrates a proximity payment method through secure ranging according to an embodiment of the present disclosure.
- the secure ranging may be secure ranging using OOB communication.
- OOB communication is BLE communication.
- OOB communication is not limited thereto, and other communication methods having the same or similar function may be applied.
- the proximity payment method may be performed between a payment application and a payment device (terminal).
- the payment application may be an application included (or installed) in the user's electronic device (user device). Accordingly, the operation of the payment application in the present disclosure may be understood as the operation of the user device including the payment application.
- the user device corresponds to the first UWB device (or the second UWB device) of FIG. 2 , or includes a part or all of the configuration of the first UWB device (or the second UWB device).
- the payment terminal corresponds to the second UWB device (or the first UWB device) of FIG. 2 , or a UWB device including a part or all of the configuration of the second UWB device (or the first UWB device) can be
- the payment application and the payment terminal may be a UWB enabled application and a UWB enabled terminal including a payment processing function, respectively.
- the proximity payment method includes a prioritization phase 510 , a secure ranging phase 520 and/or a payment transaction phase 530 .
- a prioritization phase 510 may include
- a secure ranging phase 520 may include
- a payment transaction phase 530 may include
- the prioritization step 510 may be a step for determining priorities for users (or user devices) for proximity payment.
- the prioritization step 510 is an operation (launch) of the payment application of the user device (launch) operation (511), transmission and reception operation of the UWB start / response message between the payment application and the payment terminal (ranging operation) (512) and/or a prioritization operation 513 according to the performance of the payment terminal.
- launch an operation of the payment application of the user device
- ranging operation ranging operation
- 512 transmission and reception operation of the UWB start / response message between the payment application and the payment terminal
- a prioritization operation 513 according to the performance of the payment terminal.
- the ranging operation 512 may be an operation for measuring a distance/direction (angle) between electronic devices using a UWB communication method.
- the ranging operation 512 may be performed in advance based on an operation of transmitting and receiving a ranging start message and a response message through the ranging frame RFRAME, and information (eg, time stamp information) included in the ranging frame. It may include an operation of acquiring distance information according to a set ranging method or mode.
- IEEE Std 802.15.4z-2020 and FIRA CONSORTIUM UWB MAC TECHNICAL REQUIREMENTS for a detailed description of the above-described ranging operation 512, reference may be made to the description of IEEE Std 802.15.4z-2020 and FIRA CONSORTIUM UWB MAC TECHNICAL REQUIREMENTS.
- the initiation message (UWB initiation message) may be a Ranging Initiation Message defined in "IEEE 802.15.4z Specification” and "UWB MAC Specification of FiRa Consortium".
- the response message may be a ranging response message defined in "IEEE 802.15.4z standard” and "UWB MAC standard of FiRa consortium”.
- the security ranging step 520 may be a step of performing security ranging for proximity payment.
- the secure ranging step 520 includes a user authentication operation 521, a BLE advertising/scanning operation (discovery operation) 522, secure channel establishment and UWB parameter exchange (or negotiation) through BLE. ) operation (connection operation) 523 , UWB security ranging operation 524 using Scrambled Timestamp Sequence (STS), and/or operation 525 of checking whether the user is in the payment zone.
- the user authentication operation 521 may be performed using, for example, a personal identification number (PIN) number and/or a fingerprint.
- PIN personal identification number
- the discovery operation 522 is a procedure for discovering a UWB device (service), and may be performed through OOB communication (eg, BLE communication) or in-band communication (eg, UWB communication).
- OOB communication eg, BLE communication
- in-band communication eg, UWB communication
- connection operation 523 may be a procedure for establishing a UWB channel or session by exchanging parameters for establishing a channel or session for UWB communication.
- the exchanged UWB parameters may include a ranging session key (UWB Ranging Session Key (URSK)).
- URSK UWB Ranging Session Key
- the UWB secure ranging operation 524 may perform a secured ranging operation using the STS generated from the session key (URSK) exchanged through the UWB parameter exchange operation 523 .
- the session key is a key for protecting the UWB session (eg, ranging session), and may be used to derive the STS.
- IEEE Std 802.15.4z-2020, FIRA CONSORTIUM UWB MAC TECHNICAL REQUIREMENTS, and FIRA CONSORTIUM COMMON SERVICE & MANAGEMENT LAYER TECHNICAL SPECIFICATION may be referred to.
- the operation 525 of checking whether the user is in the payment zone may be performed using angle of arrival (AOA) and/or distance information.
- AOA angle of arrival
- the AOA and/or distance information may be obtained via a UWB secure ranging operation 524 .
- the payment processing step 530 may be a step of processing a proximity payment.
- the payment processing step 530 may include a payment processing operation 531 using OOB (eg, BLE) communication or UWB communication.
- OOB eg, BLE
- UWB UWB
- the payment processing step 530 may include an operation of transmitting and receiving a message (payment message) for payment processing through an already created BLE secure channel.
- communication of the payment message may follow, for example, an application protocol data unit (APDU)-based electromagnetic wave (EMW) protocol of ISO/IEC 7816-4.
- APDU application protocol data unit
- EMW electromagnetic wave
- the payment processing step 530 may include transmitting and receiving a payment message including data encrypted using a data encryption key (data payload encryption key) derived from the UWB session key.
- a data encryption key data payload encryption key
- the communication of the payment message may follow the APDU-based EMW protocol of ISO/IEC 7816-4.
- FIG. 6 illustrates a payment scenario using a proximity payment method through secure ranging according to an embodiment of the present disclosure.
- the proximity payment method of the embodiment of FIG. 6 may be an example of the proximity payment method of FIG. 5 .
- a plurality of users eg, Tiger, Lion, and Canary
- one user eg, Canary
- executes a payment application and pays It is assumed to be located in the pay zone.
- the payment terminal may transmit an initiation message (UWB initiation message).
- UWB initiation message For example, the payment terminal may broadcast a UWB initiation message.
- At least one user among the plurality of users may transmit a response message (UWB response message) to the payment terminal in response to the initiation message.
- a payment subject within the pay zone and at least one user outside the pay zone may transmit a UWB response message to the payment terminal.
- the payment terminal may acquire location information (distance and/or angle information) of each user who has transmitted the response message based on a preset ranging method.
- the payment terminal may order the at least one user according to a preset criterion.
- the payment terminal may determine the order of at least one user who transmitted the response message, based on the distance information. For example, the payment terminal may determine the user order in the order of distance (eg, from the nearest user to the farthest user from the payment terminal).
- an operation for verbal communication/checkout may be performed.
- Such verbal communication/checkout may be performed to directly confirm whether the corresponding user is a payment target.
- a security ranging procedure (step) between the user (or payment application) located in the payment zone and the payment terminal may be performed.
- the secure ranging procedure may include a service discovery operation, a BLE connection and UWB parameter exchange operation, and/or a secure ranging operation.
- the payment terminal may determine whether a specific user (eg, a payment target) is in a specific area (eg, a payment zone) based on the result of the security ranging procedure of operation 5 . For example, the payment terminal may check whether the payment target (eg, canary) is actually in the payment zone, based on the result of the security ranging procedure. In an embodiment, the payment terminal may determine whether the payment target is actually in the payment zone using distance information and/or direction information (AoA). Through the verification procedure using such secure ranging, the problem of distance manipulation is solved, so that the intended payment between the user who needs to actually make the payment and the payment terminal can be accurately performed.
- a specific user eg, a payment target
- a specific area eg, a payment zone
- the payment terminal may check whether the payment target (eg, canary) is actually in the payment zone, based on the result of the security ranging procedure.
- the payment terminal may determine whether the payment target is actually in the payment zone using distance information and/or direction information (A
- a payment processing procedure may be performed between the payment terminal and the user (or payment application) located in the payment zone.
- FIG. 7 illustrates a prioritization step of the proximity payment method according to an embodiment of the present disclosure.
- the prioritization step of the embodiment of FIG. 7 may be an example of the prioritization step of the embodiment of FIG. 5 .
- the prioritization step may be performed between the payment terminal and at least one payment application.
- the payment terminal may be a UWB capable terminal (device)
- the payment application may be a UWB capable application (payment application).
- the payment application may be included in the user device. Accordingly, the operation of the payment application in the present disclosure may be understood as the operation of the user device including the payment application.
- the user device including the payment application may execute the payment application before or within the prioritization step (operation 7001).
- the payment application and the payment terminal recognize each other as an authenticated (or verified) object (a trusted object) and start communicating with each other.
- the payment terminal may transmit a terminal certificate associated with a terminal ID identifying the payment terminal.
- the payment terminal includes a terminal certificate (Cert Terminal (Terminal ID)) including a terminal ID (eg, object ID) (or data (authentication data (information)) of the terminal certificate) in the UWB initiation message and , may transmit this UWB initiation message.
- the payment terminal may broadcast a UWB initiation message.
- the UWB initiation message may be included in the RFRAME and transmitted.
- the terminal certificate may be issued and/or signed by an upper entity (eg, an issuer or a payment authority).
- an issuer's certificate may be stored (or installed) in advance in the payment application.
- the payment application may obtain (or load) authentication data.
- the payment application may acquire authentication data when receiving a UWB initiation message including a terminal certificate or a terminal certificate.
- the authentication data may include identification information for identifying a payment application.
- the identification information may be a universally unique identifier (UUID) or a signed UUID.
- UUID universally unique identifier
- the UUID may be allocated to the payment application by an upper entity (eg, an issuer or an authority) and stored (or installed) in the payment application.
- the signed UUID may be signed by an upper entity (eg, issuer or payment authority) or a user (or payment application).
- the payment application may transmit the signed UUID and/or the certificate of the payment application to the UWB-capable terminal.
- the payment application is processed based on the UUID (Sign(UUID)) signed by the user and the payment application certificate (Cert Payapp ) that can verify the signature (or the signed UUID and the payment application certificate) data) may be included in the UWB response message, and the UWB response message may be transmitted.
- the payment application may include the UUID (Sign(UUID)) signed by the upper entity in the UWB response message and transmit the UWB response message. As such, when the UUID is signed by a higher-level subject, a certificate for verifying this signature may not be transmitted together.
- the UWB response message may be a message corresponding to the received UWB initiation message.
- the payment terminal may establish a BLE connection based on the received UUID. In this way, the prioritization step and the security ranging step can be correlated with each other through the UUID.
- operation 7030 may be performed by all or some of the payment applications that have received the terminal certificate or the UWB initiation message including the terminal certificate.
- each UWB capable payment application may perform a corresponding operation based on its UUID associated with the corresponding payment application.
- the payment terminal may determine a priority for the user (user device). In an embodiment, the payment terminal may determine a priority according to a predetermined criterion (eg, a distance criterion) based on the received UWB response message. In an embodiment, the payment terminal may determine the priority according to the performance of the corresponding terminal. For example, the payment terminal identifies users (eg, the number of users corresponding to the number of simultaneously supportable BLE sessions) corresponding to the BLE capability of the terminal (eg, the number of BLE sessions that can be supported simultaneously), Priority may be determined for the identified number of users. For example, when the number of supportable BLE sessions of the corresponding payment terminal is 3, the payment terminal identifies only three user devices among the user devices that have transmitted the UWB response message, and determines the priority for the identified three user devices. have.
- a predetermined criterion eg, a distance criterion
- the identification and/or prioritization of the user device may be based on distance information between the payment terminal and the user device. For example, the payment terminal identifies only three user devices having the closest distance from the payment terminal to the prioritization target, and prioritizes the corresponding user devices in order of distance (eg, the closest distance to the farthest distance). order) can be determined.
- the distance information may be obtained through a UWB ranging method based on timestamp information included in the UWB initiation/response message.
- the prioritization method based on the performance and/or distance information of the terminal described above in operation 7040 is only an example of a prioritization method of the proximity payment method, and is not limited thereto, and priorities may be determined according to various methods. .
- FIG. 8 illustrates a security ranging step of a proximity payment method according to an embodiment of the present disclosure.
- the secure ranging step of the embodiment of FIG. 8 may be an example of the secure ranging step of the embodiment of FIG. 5 .
- the security ranging step of FIG. 8 may be a step performed after the prioritization step of FIG. 7 .
- the security ranging step of FIG. 8 may be a step performed between the payment application and the payment terminal that have shared the UUID through the prioritization step of FIG. 7 .
- the payment terminal may be a UWB capable terminal (device)
- the payment application may be a UWB capable application (payment application).
- the payment application may be included in the user device. Accordingly, the operation of the payment application in the present disclosure may be understood as the operation of the user device including the payment application.
- the secure ranging step may be a secure ranging step using an OOB such as BLE.
- the payment application may boost up the duty cycle to a high value (operation 8001) to quickly establish a BLE connection within the secure ranging step or before the secure ranging step, and user authentication ( operation 8002) may be performed.
- the payment terminal may select the UUID of the highest priority. For example, the payment terminal may select the UUID for the user device (or payment application) having the highest priority. In an embodiment, the priority may be determined through the prioritization step of FIG. 7 .
- the payment terminal may generate a BLE advertising packet including the selected UUID.
- the payment terminal may transmit (or broadcast) the generated BLE advertising packet.
- the payment application may request a BLE connection to the payment terminal.
- the payment application may identify the UUID included in the BLE advertising packet and check whether the UUID is its own UUID. When the UUID is its own UUID, the payment application may request a BLE connection to the UWB capable terminal. Alternatively, when the UUID is not its own UUID, the payment application may not request a BLE connection to the payment terminal. Through this, the BLE connection may be established only between the user device having the highest priority and the UWB capable terminal. A fast BLE connection to these payment recipients makes it possible to eliminate delays in payment time.
- a BLE secure channel establishment procedure and a UWB parameter exchange procedure may be performed between the payment application and the payment terminal.
- a session key (URSK) for protecting a UWB session can be shared.
- a procedure for obtaining the STS and/or data encryption key may be performed between the payment application/payment terminal.
- the STS and/or data encryption key may be derived using the UWB session key obtained through the UWB parameter exchange procedure of operation 8050 .
- UWB security ranging may be performed between the payment application/payment terminal.
- secure ranging may be performed based on the STS generated from the session key.
- the payment terminal may identify whether the user (user device) is in the payment zone based on the information obtained through the security ranging in operation 8070 .
- the payment terminal identifies whether the user device including the UWB-enabled payment application is located on a predefined distance and/or angle based on the distance information and/or AoA information obtained through secure ranging. , it is possible to identify whether the user device is within the payment zone.
- the payment terminal may confirm that the user with the highest priority corresponds to a user within the actual payment zone, and may perform a payment processing procedure with the corresponding user. As such, by accurately identifying the actual payment target through security ranging, a distance expansion attack from a street attacker can be defended, and the problem of lowering payment reliability due to distance manipulation can be solved.
- FIG 9 illustrates a payment processing system according to an embodiment of the present disclosure.
- the payment processing system 900 may include a user device 910 and a payment terminal (device) 920 .
- the user device 910 corresponds to the first UWB device (or the second UWB device) of FIG. 2 , or includes a part or all of the configuration of the first UWB device (or the second UWB device) It may be a UWB device that does
- the payment terminal 920 corresponds to the second UWB device (or the first UWB device) of FIG. 2 , or includes a part or all of the configuration of the second UWB device (or the first UWB device) It may be a UWB device that does
- the payment application 911 and the payment terminal 920 may be a UWB enabled application and a UWB enabled terminal including a payment processing function, respectively.
- the user device 910 may include a UWB communication module 912 for UWB communication and/or at least one OOB communication module 913 and 914 for OOB communication.
- the OOB communication module may include a BLE communication module 913 for BLE communication and/or an NFC communication module 914 for NFC communication.
- the UWB communication module 912 may correspond to the above-described UWB subsystem (UWBS) or may be a module including a part or all of the UWB subsystem (UWBS).
- the OOB communication module may correspond to the above-described OOB component or may be a module including a part or all of the OOB component.
- the user device 910 may perform a prioritization step (step 1) with the payment terminal 920 through the UWB communication module 912 .
- the user equipment 910 may perform the prioritization step through a contention mode (contention-based ranging mode/method) using a static STS.
- the prioritization step may follow the procedure described above with reference to FIGS. 5 and 7 .
- the user device 910 may perform the security ranging step (step 2) with the payment terminal 920 through the UWB communication module 912 and the BLE communication module 913 .
- a BLE discovery (service discovery) operation and a UWB parameter exchange operation may be performed through the BLE communication module 913
- a ranging operation may be performed through the UWB communication module 912 .
- the security ranging step may follow the procedure described above with reference to FIGS. 5 and 8 .
- the user device 910 may perform a payment processing step (step 3) with the payment terminal 920 through the BLE communication module 913 and/or the UWB communication module 912 .
- the user device 910 may perform payment processing based on the EMV application protocol.
- the user device 910 may include a payment application 911 connected to a communication module.
- the payment application 911 may be a UWB capable application.
- the payment application 911 and the communication module may communicate through a predefined interface (eg, UWB Command Interface (UCI), etc.).
- a predefined interface eg, UWB Command Interface (UCI), etc.
- the user device 910 may include at least one security component 915 , 916 connected to the payment application 911 .
- the user device 910 may include at least one of a trusted application (TA) 915 and an embedded secure element (eSE) 916 as a security component.
- TA trusted application
- eSE embedded secure element
- the TA 915 may be included with an application conforming to the EMV protocol (EMV application protocol).
- the secure components 915 and 916 may be used for secure payment processing and/or secure channel establishment via the payment application 911 .
- the payment application 911 and the security components 915 and 916 may communicate through a predefined interface (eg, CA API (TEE Client Application API), etc.).
- a predefined interface eg, CA API (TEE Client Application API), etc.
- FIG. 10 is a flowchart illustrating a method of a first electronic device according to an embodiment of the present disclosure.
- the first electronic device may be a payment terminal
- the second electronic device may be a user device including a payment application
- the payment application may be a UWB capable application
- the payment terminal may be a UWB capable terminal.
- an operation of the second electronic device may be understood as an operation of a payment application of the second electronic device. The operation of FIG. 10 may follow the corresponding operation of FIGS. 1-9 .
- the first electronic device may broadcast a UWB initiation message including certificate information of the first electronic device ( 1010 ).
- the UWB initiation message may be transmitted through a ranging frame (RFRAME). This may be performed, for example, according to operation 7010 of FIG. 7 .
- the first electronic device may receive, from the at least one second electronic device, a UWB response message including identification information of a payment application included in the second electronic device and/or certificate information of a payment application for verifying the identification information.
- a UWB response message may be transmitted through a ranging frame (RFRAME). This may be performed, for example, according to operation 7030 of FIG. 7 .
- the first electronic device may determine a priority for at least one second electronic device based on the UWB response message ( 1030 ). This may be performed, for example, according to operation 7040 of FIG. 7 .
- the first electronic device may perform security ranging with the second electronic device using first identification information of the payment application of the second electronic device having the highest priority.
- performing the secure ranging includes broadcasting a BLE advertising packet including the first identification information, and/or for a BLE connection from a second electronic device having the first identification information. receiving the request.
- the performing of the secure ranging includes, based on the request for the BLE connection, establishing a secure channel with the second electronic device, and the UWB ranging session key with the second electronic device through the secure channel. exchanging UWB parameters comprising: obtaining an STS from a UWB ranging session key; performing secure ranging with a second electronic device by using the STS; and/or based on a result of the security ranging
- the method may further include identifying whether the user of the second electronic device having the first identification information is located in the payment zone.
- the first electronic device may perform payment processing with the second electronic device.
- the identification information may be a UUID assigned to the payment application or a signed UUID.
- the signed UUID may be signed by a payment application or an upper entity.
- FIG. 11 is a flowchart illustrating a method of a second electronic device according to an embodiment of the present disclosure.
- the first electronic device may be a payment terminal
- the second electronic device may be a user device including a payment application.
- the payment application may be a UWB capable application
- the payment terminal may be a UWB capable terminal.
- an operation of the second electronic device may be understood as an operation of a payment application of the second electronic device. The operation of FIG. 11 may follow the corresponding operation of FIGS. 1-9 .
- the second electronic device may receive, from the first electronic device, a UWB initiation message including certificate information of the first electronic device ( 1110 ).
- the UWB initiation message may be transmitted through a ranging frame (RFRAME). This may be performed, for example, according to operation 7010 of FIG. 7 .
- the second electronic device may obtain identification information of a payment application included in the second electronic device ( 1120 ). This may be performed, for example, according to operation 7020 of FIG. 7 .
- the second electronic device may transmit, to the first electronic device, the UWB response message including identification information of the payment application and/or certificate information of the payment application for verifying the identification information ( 1130 ).
- the UWB response message may be transmitted through a ranging frame (RFRAME). This may be performed, for example, according to operation 7030 of FIG. 7 .
- the second electronic device may receive a BLE advertising packet including the first identification information from the first electronic device, and transmit a request for BLE connection to the first electronic device.
- the identification information may be a UUID assigned to the payment application or a signed UUID.
- the signed UUID may be signed by a payment application or an upper entity.
- FIG. 12 is a diagram illustrating a structure of a first electronic device according to an embodiment of the present disclosure.
- the first electronic device may be a payment terminal.
- the payment terminal may be a UWB capable terminal.
- the first electronic device may include a transceiver 1210 , a controller 1220 , and a storage 1230 .
- the controller may be defined as a circuit or an application-specific integrated circuit or at least one processor.
- the transceiver 1210 may transmit/receive signals to and from other network entities.
- the transceiver 1210 may transmit/receive data for payment with the second electronic device using, for example, UWB communication.
- the controller 1220 may control the overall operation of the first electronic device according to the embodiment proposed in the present disclosure.
- the controller 1220 may control a signal flow between blocks to perform an operation according to the above-described flowchart.
- the controller 1220 may control, for example, the operation of the first electronic device described with reference to FIGS. 1 to 11 .
- the storage unit 1230 may store at least one of information transmitted and received through the transceiver 1210 and information generated through the control unit 1220 .
- the storage unit 1230 may store information and data for payment processing using UWB described with reference to FIGS. 1 to 11 .
- FIG. 13 is a diagram illustrating a structure of a second electronic device according to an embodiment of the present disclosure.
- the second electronic device may be a user device including a payment application.
- the payment application may be a UWB capable application.
- an operation of the second electronic device may be understood as an operation of a payment application of the second electronic device.
- the second electronic device may include a transceiver 1310 , a controller 1320 , and a storage 1330 .
- the controller may be defined as a circuit or an application-specific integrated circuit or at least one processor.
- the transceiver 1310 may transmit/receive signals to and from other network entities.
- the transceiver 1310 may transmit/receive data for payment with the first electronic device using, for example, UWB communication.
- the controller 1320 may control the overall operation of the second electronic device according to the embodiment proposed in the present disclosure.
- the controller 1320 may control a signal flow between blocks to perform an operation according to the above-described flowchart.
- the controller 1320 may control, for example, the operation of the second electronic device described with reference to FIGS. 1 to 11 .
- the storage unit 1330 may store at least one of information transmitted/received through the transceiver 1310 and information generated through the control unit 1320 .
- the storage unit 1330 may store information and data for payment processing using UWB described with reference to FIGS. 1 to 11 .
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (15)
- UWB 통신을 이용하여 결제를 처리하는 제1 전자 장치의 방법에 있어서,상기 제1 전자 장치의 인증서(certificate) 정보를 포함하는 UWB 개시 메시지를 브로드캐스팅하는 단계;적어도 하나의 제2 전자 장치로부터, 상기 제2 전자 장치에 포함된 결제 어플리케이션의 식별 정보 및 상기 식별 정보를 검증하기 위한 상기 결제 어플리케이션의 인증서 정보 중 적어도 하나를 포함하는 UWB 응답 메시지를 수신하는 단계; 및상기 UWB 응답 메시지에 기초하여 상기 적어도 하나의 제2 전자 장치에 대한 우선순위를 결정하는 단계를 포함하는, 방법.
- 제1항에 있어서,가장 높은 우선순위를 갖는 제2 전자 장치의 결제 어플리케이션의 제1 식별 정보를 이용하여 상기 제2 전자 장치와의 보안 레인징을 수행하는 단계를 더 포함하는, 방법.
- 제1항에 있어서,상기 보안 레인징을 수행하는 단계는:상기 제1 식별 정보를 포함하는 BLE 어드버타이징 패킷을 브로드캐스팅하는 단계; 및상기 제1 식별 정보를 갖는 제2 전자 장치로부터 BLE 연결을 위한 요청을 수신하는 단계를 포함하는, 방법.
- 제3항에 있어서,상기 보안 레인징을 수행하는 단계는:상기 BLE 연결을 위한 요청에 기초하여, 상기 제2 전자 장치와 보안 채널을 설정하는 단계;상기 보안 채널을 통해, 상기 제2 전자 장치와 UWB 레인징 세션 키를 포함하는 UWB 파라미터를 교환하는 단계;상기 UWB 레인징 세션 키로부터 STS를 획득하는 단계;상기 STS를 이용하여, 상기 제2 전자 장치와 보안 레인징을 수행하는 단계를 포함하는, 방법.
- 제4항에 있어서, 상기 방법은:상기 보안 레인징의 결과에 기초하여 상기 제1 식별 정보를 갖는 제2 전자 장치의 사용자가 결제 존 내에 위치하는지를 식별하는 단계를 더 포함하는, 방법.
- 제5항에 있어서,상기 제1 식별 정보를 갖는 제2 전자 장치의 사용자가 결제 존 내에 위치함이 식별된 경우, 상기 제2 전자 장치와 결제 처리를 수행하는 단계를 더 포함하는, 방법.
- 제1항에 있어서,상기 식별 정보는 상기 결제 어플리케이션에 할당된 UUID 또는 상기 결제 어플리케이션에 할당되어 서명된 UUID인, 방법.
- UWB 통신을 이용하여 결제를 처리하는 제2 전자 장치의 방법에 있어서,제1 전자 장치로부터, 상기 제1 전자 장치의 인증서(certificate) 정보를 포함하는 UWB 개시 메시지를 수신하는 단계;상기 제2 전자 장치에 포함된 결제 어플리케이션의 식별 정보를 획득하는 단계; 및상기 제1 전자 장치로, 상기 결제 어플리케이션의 식별 정보 및 상기 식별 정보를 검증하기 위한 상기 결제 어플리케이션의 인증서 정보를 포함하는 UWB 응답 메시지를 전송하는 단계를 포함하는, 방법.
- 제7항에 있어서,상기 제1 전자 장치로부터, 상기 제1 식별 정보를 포함하는 BLE 어드버타이징 패킷을 수신하는 단계; 및상기 제1 전자 장치로, BLE 연결을 위한 요청을 전송하는 단계를 포함하는, 방법.
- 제8항에 있어서,상기 식별 정보는 상기 결제 어플리케이션에 할당된 UUID 또는 상기 결제 어플리케이션에 할당되어 서명된 UUID인, 방법.
- 제1항에 있어서,상기 서명된 UUID는 상기 결제 어플리케이션 또는 상기 결제 어플리케이션의 상위 주체에 의해 서명된 것인, 방법.
- UWB 통신을 이용하여 결제를 처리하는 제1 전자 장치에 있어서,송수신부; 및송수신부와 연결된 제어부를 포함하며, 상기 제어부는:상기 제1 전자 장치의 인증서(certificate) 정보를 포함하는 UWB 개시 메시지를 브로드캐스팅하고,적어도 하나의 제2 전자 장치로부터, 상기 제2 전자 장치에 포함된 결제 어플리케이션의 식별 정보 및 상기 식별 정보를 검증하기 위한 상기 결제 어플리케이션의 인증서 정보 중 적어도 하나를 포함하는 UWB 응답 메시지를 수신하고,상기 UWB 응답 메시지에 기초하여 상기 적어도 하나의 제2 전자 장치에 대한 우선순위를 결정하도록 구성되는, 제1 전자 장치.
- 제12항에 있어서, 상기 제어부는:가장 높은 우선순위를 갖는 제2 전자 장치의 결제 어플리케이션의 제1 식별 정보를 이용하여 상기 제2 전자 장치와의 보안 레인징을 수행하도록 더 구성되는, 제1 전자 장치.
- 제13항에 있어서, 상기 제어부는:상기 제1 식별 정보를 포함하는 BLE 어드버타이징 패킷을 브로드캐스팅하고,상기 제1 식별 정보를 갖는 제2 전자 장치로부터 BLE 연결을 위한 요청을 수신하도록 더 구성되는, 제1 전자 장치.
- UWB 통신을 이용하여 결제를 처리하는 제2 전자 장치에 있어서,송수신부; 및송수신부와 연결된 제어부를 포함하며, 상기 제어부는:제1 전자 장치로부터, 상기 제1 전자 장치의 인증서(certificate) 정보를 포함하는 UWB 개시 메시지를 수신하고,상기 제2 전자 장치에 포함된 결제 어플리케이션의 식별 정보를 획득하고,상기 제1 전자 장치로, 상기 결제 어플리케이션의 식별 정보 및 상기 식별 정보를 검증하기 위한 상기 결제 어플리케이션의 인증서 정보를 포함하는 UWB 응답 메시지를 전송하도록 구성되는, 제2 전자 장치.
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
EP22791998.2A EP4318351A1 (en) | 2021-04-19 | 2022-04-19 | Payment method and device using ultra-wideband communication |
US18/287,364 US20240202700A1 (en) | 2021-04-19 | 2022-04-19 | Payment method and device using ultra-wideband communication |
CN202280029538.8A CN117296071A (zh) | 2021-04-19 | 2022-04-19 | 使用超宽带通信的支付方法和设备 |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020210050456A KR20220144150A (ko) | 2021-04-19 | 2021-04-19 | Uwb를 이용한 결제 방법 및 장치 |
KR10-2021-0050456 | 2021-04-19 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2022225298A1 true WO2022225298A1 (ko) | 2022-10-27 |
Family
ID=83722544
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/KR2022/005586 WO2022225298A1 (ko) | 2021-04-19 | 2022-04-19 | 초광대역통신을 이용한 결제 방법 및 장치 |
Country Status (5)
Country | Link |
---|---|
US (1) | US20240202700A1 (ko) |
EP (1) | EP4318351A1 (ko) |
KR (1) | KR20220144150A (ko) |
CN (1) | CN117296071A (ko) |
WO (1) | WO2022225298A1 (ko) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2024196198A1 (ko) * | 2023-03-23 | 2024-09-26 | 삼성전자 주식회사 | 초광대역 통신을 이용하여 복수의 전자 장치들 간 결제 서비스를 제공하는 방법 및 장치 |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR20110050609A (ko) * | 2011-04-27 | 2011-05-16 | 주식회사 비즈모델라인 | 초광대역 통신을 이용한 결제 방법 |
KR20200005477A (ko) * | 2018-07-05 | 2020-01-15 | 애플 인크. | 초광대역 보안 레인징 |
KR20200070054A (ko) * | 2018-12-07 | 2020-06-17 | 삼성전자주식회사 | 무선 통신 시스템에서 레인징을 수행하기 위한 방법 및 장치 |
JP2020201837A (ja) * | 2019-06-12 | 2020-12-17 | 株式会社Nttドコモ | 決済装置、無線端末及びプログラム |
KR20210033311A (ko) * | 2019-09-18 | 2021-03-26 | 현대자동차주식회사 | 차량 결제 시스템 및 방법 |
-
2021
- 2021-04-19 KR KR1020210050456A patent/KR20220144150A/ko active Search and Examination
-
2022
- 2022-04-19 EP EP22791998.2A patent/EP4318351A1/en active Pending
- 2022-04-19 US US18/287,364 patent/US20240202700A1/en active Pending
- 2022-04-19 WO PCT/KR2022/005586 patent/WO2022225298A1/ko active Application Filing
- 2022-04-19 CN CN202280029538.8A patent/CN117296071A/zh active Pending
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR20110050609A (ko) * | 2011-04-27 | 2011-05-16 | 주식회사 비즈모델라인 | 초광대역 통신을 이용한 결제 방법 |
KR20200005477A (ko) * | 2018-07-05 | 2020-01-15 | 애플 인크. | 초광대역 보안 레인징 |
KR20200070054A (ko) * | 2018-12-07 | 2020-06-17 | 삼성전자주식회사 | 무선 통신 시스템에서 레인징을 수행하기 위한 방법 및 장치 |
JP2020201837A (ja) * | 2019-06-12 | 2020-12-17 | 株式会社Nttドコモ | 決済装置、無線端末及びプログラム |
KR20210033311A (ko) * | 2019-09-18 | 2021-03-26 | 현대자동차주식회사 | 차량 결제 시스템 및 방법 |
Also Published As
Publication number | Publication date |
---|---|
KR20220144150A (ko) | 2022-10-26 |
US20240202700A1 (en) | 2024-06-20 |
EP4318351A1 (en) | 2024-02-07 |
CN117296071A (zh) | 2023-12-26 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2017052136A1 (ko) | 이동 통신 시스템에서 프로파일 다운로드 방법 및 장치 | |
WO2016153281A1 (ko) | 무선 통신 시스템에서 프로파일을 다운로드 하는 방법 및 장치 | |
WO2020231044A1 (en) | Method for performing distance measurement and authentication concurrently and electronic device thereof | |
WO2021112539A1 (en) | Electronic device for performing ranging by using ultra-wide band and operation method thereof | |
WO2018101775A1 (en) | Apparatus and method for installing and managing esim profiles | |
WO2021112380A1 (ko) | Uwb (ultra wideband)를 통해 데이터를 송수신하는 디바이스의 동작 방법 및 장치 | |
WO2020204505A1 (ko) | 엣지 컴퓨팅 서비스를 위한 방법 및 그의 전자 장치 | |
WO2011087210A2 (ko) | 전자기기 및 전자기기의 동작 방법 | |
WO2018147711A1 (en) | APPARATUS AND METHOD FOR ACCESS CONTROL ON eSIM | |
WO2022139514A1 (en) | Method and device for device discovery using uwb | |
WO2018155832A1 (ko) | 차량용 스마트키 인증 방법 및 장치 | |
WO2021112603A1 (en) | Method and electronic device for managing digital keys | |
WO2016039576A2 (ko) | 무선 통신 시스템에서 다중 망 접속을 위한 장치 및 방법 | |
WO2020105969A1 (ko) | 무선 통신 시스템에서 업링크 동작을 결정하는 전자 장치 및 그 방법 | |
WO2022245109A1 (en) | Method and device for performing uwb secure ranging | |
WO2021235893A1 (ko) | 전자 디바이스 및 전자 디바이스가 레인징 기반 서비스를 제공하는 방법 | |
WO2022014924A1 (ko) | 전자 디바이스가 보안 레인징을 수행하는 방법 및 장치 | |
EP3874713A1 (en) | Method and apparatus for managing bundles of smart secure platform | |
WO2022250500A1 (en) | Method and apparatus for configuring medium access control (mac) address for ultra-wideband (uwb) communication | |
WO2022260495A1 (en) | Method and device for performing uwb ranging | |
EP3530016A1 (en) | Apparatus and method for installing and managing esim profiles | |
WO2022225298A1 (ko) | 초광대역통신을 이용한 결제 방법 및 장치 | |
WO2022092918A1 (ko) | 초광대역 통신을 이용한 결제 방법 및 장치 | |
WO2020122402A1 (ko) | 세컨더리 노드 추가를 지원하는 전자 장치 및 그 방법 | |
WO2016072781A1 (en) | Bootstrapping wi-fi direct communication by a trusted network entity |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22791998 Country of ref document: EP Kind code of ref document: A1 |
|
WWE | Wipo information: entry into national phase |
Ref document number: 18287364 Country of ref document: US |
|
WWE | Wipo information: entry into national phase |
Ref document number: 202280029538.8 Country of ref document: CN |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2022791998 Country of ref document: EP |
|
ENP | Entry into the national phase |
Ref document number: 2022791998 Country of ref document: EP Effective date: 20231102 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |