EP3384449A1 - Bezahlverfahren und vorrichtung mit verwendung des besagten verfahrens - Google Patents

Bezahlverfahren und vorrichtung mit verwendung des besagten verfahrens

Info

Publication number
EP3384449A1
EP3384449A1 EP16802047.7A EP16802047A EP3384449A1 EP 3384449 A1 EP3384449 A1 EP 3384449A1 EP 16802047 A EP16802047 A EP 16802047A EP 3384449 A1 EP3384449 A1 EP 3384449A1
Authority
EP
European Patent Office
Prior art keywords
payment
biometric
selection
authentication
software
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP16802047.7A
Other languages
English (en)
French (fr)
Inventor
François Lemaire
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Thales DIS France SA
Original Assignee
Gemalto SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemalto SA filed Critical Gemalto SA
Publication of EP3384449A1 publication Critical patent/EP3384449A1/de
Withdrawn legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/22Payment schemes or models
    • G06Q20/227Payment schemes or models characterised in that multiple accounts are available, e.g. to the payer
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/327Short range or proximity payments by means of M-devices
    • G06Q20/3278RFID or NFC payments by means of M-devices

Definitions

  • the invention relates to a method of payment and to a device implementing said method.
  • Payment includes any authentication and / or authorization related to a transaction including a payment, a debit unit credit (including a transport application), a simple authentication of the person who triggers a subsequent payment or valid prepayment already made.
  • a first step 1 10 is to put in contact (or type) the mobile phone and the player. Following this step, the reader transfers a selection request to the mobile phone that launches a selection application on the phone. It is then that the selection application leaves the choice to the user to validate the payment with a payment method proposed by default or to select another payment method during step 120.
  • This step 120 therefore allows to select the means of payment including a payment source such as an account or a card and a type of payment (prepaid, debit or credit).
  • the payment application associated with the selected payment means requires the user to authenticate, step 130.
  • This step 130 can be performed in different ways such as entering a PIN code, the presentation of a fingerprint, the detection of a face, or other.
  • the authentication step 130 being performed, it then becomes possible to finalize the transaction, for example using a second contact between the phone and the reader, in a step 140.
  • the phone transmits the banking information enabling the transaction to be carried out accompanied by a payment authorization signature. More generally, we speak of transaction authorization cryptogram, commonly called ARQC (Authorization Request Cryptogram) according to the EMV payment standard.
  • ARQC Authorization Request Cryptogram
  • step 1 10 it is known to delete the first step 1 10.
  • the user will directly proceed to step 120 of selecting the means of payment.
  • Step 130 will authenticate the bearer and the transaction request will be generated in step 140.
  • Such a much faster method requires some confidence in the reader because the amount is no longer displayed on the screen. the phone at the time of authentication but only on the reader.
  • the current trend is to speed up the checkout and especially the time required for payment. For this purpose, it is requested to go to the simplest possible use for the user while ensuring the most security possible.
  • biometrics is a means of strong authentication of a user while guaranteeing a great simplicity of use for the user.
  • the invention proposes a new method of payment to go even faster. More particularly, the invention is a payment method using an electronic device having at least one biometric sensor, at least one communication interface for communicating with an external or remote terminal, and at least one a processing unit having banking information, reference biometric information, at least one authentication software, one or more payment software, banking information and payment software offering at least two payment means to the user.
  • the method allows a selection of the payment means by associating with each payment means a biometric identifier of its own so that the biometric authentication allows both to select the means of payment and to generate a transaction authorization cryptogram with said means of payment.
  • the selection of the means of payment consists in making at least one of several selection possibilities.
  • the selection can be done among banking information that correspond to a bank card among at least two bank cards or that correspond to a bank account among at least two bank accounts.
  • the selection can be made among at least two types of payment (prepaid, immediate debit, deferred debit, credit).
  • the selection can be done among at least two different payment software.
  • a payment request has been received by the electronic device with an amount to be paid and in which the amount to be paid is indicated on the display device at the same time as a request for selection and authentication.
  • the biometric identifiers are fingerprints and a fingerprint can only be used for a means of payment. It may be indicated on the display device the fingerprint to present for each means of payment.
  • the invention is an electronic device which comprises at least one biometric sensor, at least one communication interface for communicating with an external or remote terminal, and at least one processing unit having banking information, biometric reference information, at least one authentication software, one or more payment software, banking information and payment software offering at least two means of payment to the user.
  • Each payment means is associated with a biometric identifier of its own, and the authentication software allows a selection of the payment means simultaneously with the biometric authentication by associating the payment means with the biometric fingerprint presented after having been authenticated. .
  • the communication interface may be a radio interface compatible with a contactless payment terminal.
  • the communication interface may be an internet interface.
  • the biometric sensor can be a sensor fingerprints where each fingerprint is associated with a means of payment.
  • the processing unit may include an attack-resistant secure processing circuit so that at least a portion of the authentication and transaction authorization cryptogram generation is performed in said secure processing circuit.
  • the electronic device may further include a display device for displaying a transaction amount and a choice of payment means.
  • FIG. 1 represents an electronic payment scheme according to the invention
  • FIGS. 2 and 3 illustrate a mobile phone that can implement the invention
  • Figure 4 illustrates a mobile phone in a payment system
  • Figures 5-7 illustrate the method of the invention.
  • FIGS. 2 and 3 show a mobile telephone 200 equipped with a touch screen 210 and a fingerprint sensor 220 connected to a processing unit 230.
  • the telephone 200 furthermore comprises a first communication interface 240 with a network mobile telecommunication radio and a second radio interface 250 for proximity communication.
  • the processing unit 230 comprises a microprocessor 231 and a memory 232 comprising a volatile part and a non-volatile part.
  • the memory 232 includes most of the programs and data that will work on the phone.
  • the processing unit 230 furthermore comprises a SIM card 233 and a secure circuit 234.
  • the SIM card 233 contains information necessary for the identification of the telephone on the radio network and also for programs and data which may require some security such as for example for a payment.
  • the secure circuit 234 is typically an attack-resistant microcontroller, this type of circuit is better known by its English name "secure element" and is intended to keep all the confidential information of the processing unit and also includes programs sensitive in relation to these data.
  • the fingerprint authentication program which makes it possible to verify that the fingerprint that is presented to the sensor 220 corresponds to a known fingerprint resides in this secure circuit 234.
  • the sensitive part of a payment software specific to the telephone can be also locate in this secure element 234.
  • the first communication interface 240 is a radio interface compatible with standards for data transfer allowing communication via the Internet.
  • the second communication interface 250 is a proximity interface which can be of different types. As a proximity interface, it is known to have interfaces related to the exchange of data type Bluetooth or Wifi that can exchange any type of data. It is also known to have a Near Field Communication (NFC) interface compatible with contactless payment terminals according to the IS014443 standard.
  • NFC Near Field Communication
  • a telephone 200 may comprise one or more payment applications that may be in parts executed either in the secure circuit 234 or in the SIM card 233 if it is desired to have a minimum of data security banking.
  • the part executed in the secure circuit 234 or the SIM card 233 is generally started by a program executed by the microprocessor 231 which sends an appropriate command to said secure circuit 234 or SIM card 233 whenever said program must perform a sensitive operation .
  • a fingerprint is taken using the fingerprint sensor 220, under the control of a program currently being executed. on the microprocessor 231.
  • the microprocessor 231 will then build a fingerprint check command to the secure circuit 234 that receives the captured fingerprint or signature of that fingerprint.
  • the secure circuit 234 compares this captured fingerprint with one or more reference fingerprints. If a reference fingerprint corresponds to the captured fingerprint, the secure circuit 234 returns a positive authentication response. In the case where several fingerprints are stored, the secure circuit can also return an identifier corresponding to the authenticated fingerprint.
  • the authentication command of the fingerprint may also contain the information relating to the transaction, thus, the return message of the authentication command may also contain the information necessary for the transaction including a signature of the transaction and / or an encrypted message corresponding to a transaction authorization cryptogram that validates the transaction with the server of a bank.
  • FIG. 4 illustrates two types of payment environment that the telephone 200 may encounter.
  • a first method of payment is the payment via internet in which the telephone 200 communicates via a marketplace 400 to which it is connected via the Internet and the radiotelephone network.
  • a second mode of payment is the payment in the shop using a bank payment terminal 450 which communicates with the telephone via a short-range radio communication.
  • Figures 5 to 7 show the operation of the invention in the context of a payment made to a payment terminal 450.
  • Figure 5 shows the steps performed by the user.
  • Figure 6 gives an example of the user interface that can be used.
  • Figure 7 illustrates what is happening at the functional level in the phone.
  • a user wishing to make a purchase will "tap" his telephone 200 against the payment terminal 450 during a start-up step 500.
  • the payment terminal 450 sends on the phone a request for authorization of payment.
  • the request received by the phone automatically initiates a selection application that requests the user to validate the payment during a step 510 authentication and payment method selection.
  • the screen 210 displays the screen shown in Figure 6 which asks the user to validate the transaction using the fingerprint sensor 220.
  • the validation screen offers different payment methods 610 to 630 while indicating a finger 640 to 660 associated with each payment method 610 to 630.
  • the user When the user will authenticate using one of the indicated fingers, he will simultaneously select the payment method associated with the fingerprint of said finger. Authentication and selection of the means of payment being simultaneous, the user only has to "type" his phone 200 again against the payment terminal 450 which will complete the transaction by providing the terminal of payment a transaction authentication cryptogram which will include, for example, the identification of the transaction, the account or card to be debit and a signature of this information to justify the debit authorization.
  • the payment methods 610 and 620 may correspond to the same credit card emulation payment software while the payment method 630 corresponds to a payment software by electronic purchase order provided by a store chain and usable only in said store chain.
  • a first step 710 starts a selection application that will display the different means of payment as shown in Figure 6, optionally the display can also indicate the amount of the transaction to perform.
  • a second step 720 then asks the user to validate the payment by authenticating with the aid of the biometric sensor 220.
  • the screen of FIG. 6 is displayed until an impression capture is received by the sensor. 220.
  • a check 730 makes it possible to check whether the imprint presented to the biometric sensor corresponds to a registered imprint and the imprint is associated with a means of payment.
  • a selection step 740 launches the application with parameters corresponding to the payment means associated with the imprint while retaining the authentication performed.
  • the payment application can go directly to the validation step 750 in order to construct a transaction authorization cryptogram corresponding to the payment means that has just been selected.
  • the user After the validation step 750, the user only has to "tap" the phone again on the reader to transmit the transaction authorization cryptogram to the payment terminal 450.
  • the payment transaction is rejected 760, a message indicates rejection to the user and terminates the selection application without triggering a payment application.
  • the validation step 750 will be done at the same time as the finalization step 520.
  • the reader sends a selection command to perform an identified transaction.
  • Step 750 can then be performed by generating the transaction authorization cryptogram based on the authentication previously performed and on the identification of the transaction received in the selection command. Once the cryptogram has been prepared, it is automatically sent back to the payment terminal.
  • steps 500 and 520 are replaced by interactions with a remote server or a script sent by a remote server.
  • the initialization of the payment is triggered by the support of the user on an icon which will trigger a payment request to a selection application on the phone 200.
  • the finalization of the payment is then naturally done at the end. of step 740 without any action of the user.
  • the payment transaction is therefore relatively simplified for the user while maintaining a certain security of the operation.
  • the security comes in particular because at least the sensitive steps are performed in a secure environment such as a secure circuit 234.
  • the SIM card is used as a secure circuit or to use a removable secure circuit which is for example integrated in an SD card.
  • the secure circuit is not essential to the realization of the invention.
  • the biometric sensor is a fingerprint sensor.
  • voice biometrics the biometric sensor becoming a microphone and the imprint can be done by voice recognition of the user on pre-recorded words such as the name of use of the means of payment each sequence corresponding to a voice print and a means of payment.
  • the payment method can also be applied to a transport network.
  • the cryptogram generated is mainly an authentication of the user. This cryptogram will then be used either to establish that the user has a valid subscription, or debit an account containing prepaid tickets.
  • the selection is certainly not necessary if only one means of transport is possible, however, the authentication and simultaneous selection of the means of transport becomes interesting when several transport application are present on the same phone.
  • the invention has been described in connection with a mobile phone but it is applicable to other electronic devices.
  • it can be tablet, laptop, smart watch or even a multi application smart card.
  • a smart card it must have a fingerprint sensor but not necessarily have a display screen, the user must in this case have in memory the fingerprint associated with payment method or the card will display the equivalent of Figure 6 on the payment terminal.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Finance (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Telephone Function (AREA)
EP16802047.7A 2015-11-30 2016-11-28 Bezahlverfahren und vorrichtung mit verwendung des besagten verfahrens Withdrawn EP3384449A1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP15306896.0A EP3173998A1 (de) 2015-11-30 2015-11-30 Zahlungsverfahren und vorrichtung unter verwendung des verfahrens
PCT/EP2016/078991 WO2017093182A1 (fr) 2015-11-30 2016-11-28 Methode de paiement et dispositif utilisant cette methode

Publications (1)

Publication Number Publication Date
EP3384449A1 true EP3384449A1 (de) 2018-10-10

Family

ID=54782644

Family Applications (2)

Application Number Title Priority Date Filing Date
EP15306896.0A Withdrawn EP3173998A1 (de) 2015-11-30 2015-11-30 Zahlungsverfahren und vorrichtung unter verwendung des verfahrens
EP16802047.7A Withdrawn EP3384449A1 (de) 2015-11-30 2016-11-28 Bezahlverfahren und vorrichtung mit verwendung des besagten verfahrens

Family Applications Before (1)

Application Number Title Priority Date Filing Date
EP15306896.0A Withdrawn EP3173998A1 (de) 2015-11-30 2015-11-30 Zahlungsverfahren und vorrichtung unter verwendung des verfahrens

Country Status (3)

Country Link
US (1) US20180349911A1 (de)
EP (2) EP3173998A1 (de)
WO (1) WO2017093182A1 (de)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11030603B1 (en) * 2017-06-26 2021-06-08 Wells Fargo Bank, N.A. Systems and methods for distinguishing between profiles in a passive authentication scheme
WO2019190639A1 (en) * 2018-03-26 2019-10-03 Mastercard International Incorporated System and method for enabling receipt of electronic payments
KR20220010242A (ko) 2020-07-17 2022-01-25 삼성전자주식회사 생체인증 기반 스마트카드

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20140046831A (ko) * 2012-10-11 2014-04-21 와이엠디(주) 결제 중개 시스템 및 방법

Also Published As

Publication number Publication date
US20180349911A1 (en) 2018-12-06
WO2017093182A1 (fr) 2017-06-08
EP3173998A1 (de) 2017-05-31

Similar Documents

Publication Publication Date Title
US20180240106A1 (en) Hand-held electronics device for aggregation of and management of personal electronic data
US9536238B2 (en) Hand-held electronics device for aggregation of and management of personal electronic data
EP2646990B1 (de) Verbessertes verfahren und system für nfc-transaktionen
FR2985344B1 (fr) Carte bancaire et procede de reponse a une demande de transaction.
US20150262052A1 (en) Omni smart card
EP2873045A1 (de) Sichere elektronische entität zur autorisierung einer transaktion
EP1709598A2 (de) Transaktionseinrichtung mit antizipierter vorbehandlung
EP1857953A1 (de) Verfahren und System zur Authentifizierung und zum sicheren Austausch von Daten zwischen einem personalisierten Chip und einem dedizierten Server
US11107081B2 (en) Systems and methods for streamlined checkout
FR2989799A1 (fr) Procede de transfert d'un dispositif a un autre de droits d'acces a un service
EP3384449A1 (de) Bezahlverfahren und vorrichtung mit verwendung des besagten verfahrens
US20190236589A1 (en) Hand-held electronics device for aggregation of and management of personal electronic data
EP3252692A1 (de) Verfahren zur lieferung der entsprechenden daten einer zahlungstransaktion, entsprechende vorrichtung und entsprechendes programm
EP3417592B1 (de) Verfahren zum authentifizieren eines gebrauchers zu einem server
FR2832829A1 (fr) Procede, systeme et dispositif permettant d'authentifier des donnees transmises et/ou recues par un utilisateur
FR2945141A1 (fr) Procede et systeme de gestion d'une application de paiement mobile sans contact mettant en oeuvre une verification de code personnel
WO2017001757A1 (fr) Serveur et procede de verification de code de securite
EP3215991A1 (de) Vereinfachte transaktion anhand einer zahlungsvorrichtung und einem kommunikationsendgerät
EP2867837B1 (de) System zum sicheren übertragen von digitalen daten
FR3068497B1 (fr) Systeme et procede de definition d'un code personnel associe a un micro­circuit
FR3038419A1 (fr) Serveur et procede de verification de code de securite
FR3038417A1 (fr) Serveur et procede de verification de code dynamique de securite
FR3045878B1 (fr) Serveur d'authentification pour le controle d'acces a un service
EP3690685A1 (de) Authentifizierungsverfahren eines benutzers und entsprechende vorrichtung
FR2980012A1 (fr) Systeme et procede d'authentification par code personnel

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20180702

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

GRAJ Information related to disapproval of communication of intention to grant by the applicant or resumption of examination proceedings by the epo deleted

Free format text: ORIGINAL CODE: EPIDOSDIGR1

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: GRANT OF PATENT IS INTENDED

RIC1 Information provided on ipc code assigned before grant

Ipc: G06Q 20/40 20120101AFI20190705BHEP

Ipc: G06Q 20/32 20120101ALI20190705BHEP

Ipc: G06Q 20/22 20120101ALI20190705BHEP

INTG Intention to grant announced

Effective date: 20190805

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: THALES DIS FRANCE SA

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20191217