PAYMENT DEVICE ADAPTED TO ESTABLISH A SECURE MESSAGING CHANNEL WITH A REMOTE SERVER FOR A PAYMENT TRANSACTION AND ASSOCIATED REMOTE SERVER
    2.
    发明申请
    PAYMENT DEVICE ADAPTED TO ESTABLISH A SECURE MESSAGING CHANNEL WITH A REMOTE SERVER FOR A PAYMENT TRANSACTION AND ASSOCIATED REMOTE SERVER 审中-公开
    支付设备适用于建立一个安全的远程服务器进行付款交易和相关的远程服务器的通道

    公开(公告)号:WO2018011202A1

    公开(公告)日:2018-01-18

    申请号:PCT/EP2017/067395

    申请日:2017-07-11

    Applicant: GEMALTO SA

    Abstract: The present invention relates to a payment device (D) adapted to establish a secure messaging channel (SM) with a remote server (RS) for a payment transaction (T), wherein said payment device (D) is adapted to: - receive from said remote server (RS) a remote server certificate chain (RSca); - verify said remote server certificate chain (RSca); - receive from said remote server (RS) a remote server challenge (RSch); - send to said remote server (RS) a first parameter (SKA), a payment device signature (Slcc), and a payment device challenge (ICCch), said payment device signature (Slcc) being based on said remote server challenge (RSch) and on said first parameter (SKA); - receive a second parameter (SKB) and a remote server signature (Srs) from said remote server (RS), said remote server signature (Srs) being based on said second parameter (SKB) and on said payment device challenge (ICCch); - verify said remote server signature (Srs) for authenticating said remote server (RS); - generate session keys (KiccEnc, KiccMac, KRsMac) from a first random number (RD1 ) and from said second parameter (SKB) using a cryptographic algorithm (ALG), for establishing a secure messaging channel (SM).

    Abstract translation: 支付设备(D)适于与远程服务器(RS)建立用于支付交易(T)的安全消息信道(SM),其中所述支付设备(D) )适用于: - 从所述远程服务器(RS)接收远程服务器证书链(RSca); - 验证所述远程服务器证书链(RSca); - 从所述远程服务器(RS)接收远程服务器质询(RSch); - 向所述远程服务器(RS)发送第一参数(SKA),支付设备签名(Slcc)和支付设备询问(ICCch),所述支付设备签名(Slcc)基于所述远程服务器询问(RSch) 并在所述第一参数(SKA)上; - 从所述远程服务器(RS)接收第二参数(SKB)和远程服务器签名(Srs),所述远程服务器签名(Srs)基于所述第二参数(SKB)并且基于所述支付设备质询(ICCch); - 验证所述远程服务器签名(Srs)以认证所述远程服务器(RS); - 使用密码算法(ALG)从第一随机数(RD1)和来自所述第二参数(SKB)生成会话密钥(KiccEnc,KiccMac,KRsMac),用于建立安全消息信道(SM)。

    METHOD FOR SECURING OVER-THE-AIR COMMUNICATION BETWEEN A MOBILE APPLICATION AND A GATEWAY
    3.
    发明申请
    METHOD FOR SECURING OVER-THE-AIR COMMUNICATION BETWEEN A MOBILE APPLICATION AND A GATEWAY 审中-公开
    保护移动应用与网关之间的空中通信的方法

    公开(公告)号:WO2015044162A1

    公开(公告)日:2015-04-02

    申请号:PCT/EP2014/070300

    申请日:2014-09-24

    Applicant: GEMALTO SA

    Abstract: The present invention generally relates to systems and methods for performing issuer updates of data stored in a mobile device, a remote authentication, a remote payment transaction or enable the configuration of mobile application functions or operations. More specifically, the present invention relates to a method and system for securing an issuer updates processing for mobile payment application. When an update transaction is initiated, the payment application increments an Application Transaction Counter ATC and derives from this ATC a session keys. Sensitive user credential data are encrypted with the computed session keys before transmission to a gateway which is configured to compute the session keys for decryption. The decrypted user credential data are forwarded to a payment application issuer for updates.

    Abstract translation: 本发明一般涉及用于执行存储在移动设备中的数据的发行者更新,远程认证,远程支付交易或启用移动应用功能或操作的配置的系统和方法。 更具体地,本发明涉及一种用于确保用于移动支付应用的发行者更新处理的方法和系统。 当启动更新事务时,支付应用程序会增加一个应用程序事务计数器ATC,并从该ATC派生一个会话密钥。 敏感的用户凭证数据在传输到网关之前用所计算的会话密钥加密,网关被配置为计算用于解密的会话密钥。 解密的用户凭证数据被转发到支付应用发行者以进行更新。

    METHOD, DEVICE, SERVER AND SYSTEM FOR AUTHENTICATING A USER
    4.
    发明申请
    METHOD, DEVICE, SERVER AND SYSTEM FOR AUTHENTICATING A USER 审中-公开
    用于认证用户的方法,设备,服务器和系统

    公开(公告)号:WO2017102142A1

    公开(公告)日:2017-06-22

    申请号:PCT/EP2016/075258

    申请日:2016-10-20

    Applicant: GEMALTO SA

    Abstract: The invention relates to a method 40 for authenticating a user. According to the invention,the method comprises the following steps. A device 12 accesses 41 a key and at least one initial vector. The at least one initial vector is previously generated by using a first algorithm, at least one reference vector and reference user authentication data. The at least one reference vector is previously generated without using the reference user authentication data. The device accesses data 42 and provided user authentication data 46. The device generates 48 at least one intermediary vector by using a second algorithm, the at least one initial vector and the provided user authentication data. The device generates 410 a cryptogram by using a third algorithm22, the key, the at least one intermediary vector and the data. A server 18 receives a request 414 for authenticating a user accompanied with the cryptogram and the data. The server accesses 416 the key and the at least one reference vector. The server generates 418 a reference cryptogram by using the third algorithm, the key, the at least one reference vector and the data. The server verifies 420 whether the reference cryptogram does or does not match the cryptogram. If the reference cryptogram does or does not match the cryptogram, then the server does 422 or does not 424 authenticate the user respectively. The invention also relates to corresponding device, server and system.

    Abstract translation: 本发明涉及用于认证用户的方法40。 根据本发明,该方法包括以下步骤。 设备12访问41密钥和至少一个初始向量。 该至少一个初始向量先前通过使用第一算法,至少一个参考向量和参考用户认证数据来生成。 预先生成至少一个参考矢量而不使用参考用户认证数据。 设备访问数据42并提供用户认证数据46.设备通过使用第二算法,至少一个初始向量和提供的用户认证数据来生成48至少一个中间矢量。 该设备通过使用第三算法22,密钥,至少一个中间矢量和数据来生成410密码。 服务器18接收用于认证伴随密码和数据的用户的请求414。 服务器访问416密钥和至少一个参考矢量。 服务器通过使用第三算法,密钥,至少一个参考矢量和数据来生成418参考密码。 服务器验证420参考密码是否与密码匹配。 如果参考密码与密码匹配或不匹配,则服务器分别对422或424进行认证。 本发明还涉及相应的设备,服务器和系统。

    METHOD FOR SECURING A VALIDATION STEP OF AN ONLINE TRANSACTION
    5.
    发明申请
    METHOD FOR SECURING A VALIDATION STEP OF AN ONLINE TRANSACTION 审中-公开
    用于保护在线交易的验证步骤的方法

    公开(公告)号:WO2015007637A1

    公开(公告)日:2015-01-22

    申请号:PCT/EP2014/064909

    申请日:2014-07-11

    Applicant: GEMALTO SA

    Abstract: The present invention relates to a method and system for securing a validation process of an online payment transaction. During an online transaction on a mobile device, it is requested a contactless tap from a contactless display card (thanks to NFC reader mode in the mobile device) to establish a contactless exchange session. During this contactless exchange session, the display card receives the amount requested for the transaction and the identification of merchant. The user is invited to check amount and merchant identification on the screen of the display card. When the user validates the transaction by for example pressing on a corresponding button then the display card creates an authorization message comprising enciphered financial user information and data on the transaction. With a second tap from the display card, the mobile device receives the authorization message which is transmitted to the display card issuer through the merchant for validation.

    Abstract translation: 本发明涉及一种用于确保在线支付交易的验证过程的方法和系统。 在移动设备的在线交易期间,请求来自非接触式显示卡的非接触式抽头(由于移动设备中的NFC读取器模式)来建立非接触式交换会话。 在非接触式交换会话期间,显示卡接收交易请求的金额和商家的识别。 请用户检查显示卡屏幕上的金额和商家标识。 当用户通过例如按下相应的按钮来验证交易时,显示卡创建包括加密的金融用户信息和交易数据的授权消息。 通过显示卡的第二次轻敲,移动设备接收授权消息,该授权消息通过商家传送到显示卡发行者进行验证。

    PROCEDE POUR PERSONNALISER UN DISPOSITIF ELECTRONIQUE, PROCEDE DE TRAITEMENT DE DONNEES ET DISPOSITIF ASSOCIES
    6.
    发明申请
    PROCEDE POUR PERSONNALISER UN DISPOSITIF ELECTRONIQUE, PROCEDE DE TRAITEMENT DE DONNEES ET DISPOSITIF ASSOCIES 审中-公开
    用于个人化电子设备的方法,相关数据处理方法和设备

    公开(公告)号:WO2010115840A1

    公开(公告)日:2010-10-14

    申请号:PCT/EP2010/054411

    申请日:2010-04-01

    CPC classification number: G07F7/10 G06Q20/3574 G06Q20/3576

    Abstract: L' invention concerne tout dispositif électronique tel une carte à puce, un passeport, un dongle ou tout autre objet nécessitant une personnalisation du contenu d'une mémoire. Plus précisément, l'invention prévoit un procédé pour traiter une donnée d'un conteneur stocké dans une mémoire, ledit procédé étant mis en œuvre par le dispositif électronique en exploitant notamment une table des identificateurs. L'invention prévoit en outre une étape préalable pour associer un identificateur de donnée à une donnée d'un conteneur et créer ladite table des identificateurs.

    Abstract translation: 本发明涉及任何电子设备,例如芯片卡,护照,加密狗或需要个性化存储器内容的任何其它对象。 更准确地说,本发明提供了一种用于处理存储在存储器中的容器的数据项的方法,所述方法由电子设备通过特别使用标识符表来实现。 本发明还提供了用于将数据标识符与容器的数据项相关联并创建所述标识符表的先前步骤。

Patent Agency Ranking