Abstract:
The invention relates to a device for adapting a conventional smart card so that it can communicate for example with a subscriber identification module card of a terminal with a proximity contactless communication interface in accordance with the earlier art so as to be able to implement an electronic transaction through a telecommunications network.
Abstract:
The present invention relates to a payment device (D) adapted to establish a secure messaging channel (SM) with a remote server (RS) for a payment transaction (T), wherein said payment device (D) is adapted to: - receive from said remote server (RS) a remote server certificate chain (RSca); - verify said remote server certificate chain (RSca); - receive from said remote server (RS) a remote server challenge (RSch); - send to said remote server (RS) a first parameter (SKA), a payment device signature (Slcc), and a payment device challenge (ICCch), said payment device signature (Slcc) being based on said remote server challenge (RSch) and on said first parameter (SKA); - receive a second parameter (SKB) and a remote server signature (Srs) from said remote server (RS), said remote server signature (Srs) being based on said second parameter (SKB) and on said payment device challenge (ICCch); - verify said remote server signature (Srs) for authenticating said remote server (RS); - generate session keys (KiccEnc, KiccMac, KRsMac) from a first random number (RD1 ) and from said second parameter (SKB) using a cryptographic algorithm (ALG), for establishing a secure messaging channel (SM).
Abstract:
The present invention generally relates to systems and methods for performing issuer updates of data stored in a mobile device, a remote authentication, a remote payment transaction or enable the configuration of mobile application functions or operations. More specifically, the present invention relates to a method and system for securing an issuer updates processing for mobile payment application. When an update transaction is initiated, the payment application increments an Application Transaction Counter ATC and derives from this ATC a session keys. Sensitive user credential data are encrypted with the computed session keys before transmission to a gateway which is configured to compute the session keys for decryption. The decrypted user credential data are forwarded to a payment application issuer for updates.
Abstract:
The invention relates to a method 40 for authenticating a user. According to the invention,the method comprises the following steps. A device 12 accesses 41 a key and at least one initial vector. The at least one initial vector is previously generated by using a first algorithm, at least one reference vector and reference user authentication data. The at least one reference vector is previously generated without using the reference user authentication data. The device accesses data 42 and provided user authentication data 46. The device generates 48 at least one intermediary vector by using a second algorithm, the at least one initial vector and the provided user authentication data. The device generates 410 a cryptogram by using a third algorithm22, the key, the at least one intermediary vector and the data. A server 18 receives a request 414 for authenticating a user accompanied with the cryptogram and the data. The server accesses 416 the key and the at least one reference vector. The server generates 418 a reference cryptogram by using the third algorithm, the key, the at least one reference vector and the data. The server verifies 420 whether the reference cryptogram does or does not match the cryptogram. If the reference cryptogram does or does not match the cryptogram, then the server does 422 or does not 424 authenticate the user respectively. The invention also relates to corresponding device, server and system.
Abstract:
The present invention relates to a method and system for securing a validation process of an online payment transaction. During an online transaction on a mobile device, it is requested a contactless tap from a contactless display card (thanks to NFC reader mode in the mobile device) to establish a contactless exchange session. During this contactless exchange session, the display card receives the amount requested for the transaction and the identification of merchant. The user is invited to check amount and merchant identification on the screen of the display card. When the user validates the transaction by for example pressing on a corresponding button then the display card creates an authorization message comprising enciphered financial user information and data on the transaction. With a second tap from the display card, the mobile device receives the authorization message which is transmitted to the display card issuer through the merchant for validation.
Abstract:
L' invention concerne tout dispositif électronique tel une carte à puce, un passeport, un dongle ou tout autre objet nécessitant une personnalisation du contenu d'une mémoire. Plus précisément, l'invention prévoit un procédé pour traiter une donnée d'un conteneur stocké dans une mémoire, ledit procédé étant mis en œuvre par le dispositif électronique en exploitant notamment une table des identificateurs. L'invention prévoit en outre une étape préalable pour associer un identificateur de donnée à une donnée d'un conteneur et créer ladite table des identificateurs.