Mutual authentication of devices or systems that are user-controllable and contain sensitive or confidential data

By implementing a pre-authentication phase for both the device and user using respective secrets, the method ensures the authenticity of both parties, securing operations and services in functional electronic devices or systems.

JP7805708B2Active Publication Date: 2026-01-26LEDGER SAS
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2020560738
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-04-30
Filing Date
2019-04-30
Publication Date
2026-01-26
Estimated Expiration
2039-04-30

AI Technical Summary

Technical Problem

Existing authentication methods fail to ensure mutual verification of the authenticity of both the device and the user, leading to potential security breaches when using functional electronic devices or systems that handle sensitive or confidential data.

Method used

A pre-authentication phase is introduced where the user verifies the device's authenticity using a device authentication secret, and the device verifies the user's authenticity using a user authentication secret, ensuring that operations can only proceed if both are validated.

Benefits of technology

This method guarantees the security of operations and services by ensuring that both the device and the user are authentic, preventing unauthorized access and data breaches.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007805708000001
    Figure 0007805708000001
Patent Text Reader

Abstract

A method for mutual authentication of a controllable electronic device (ED) and its user (USER) who can control the device to provide the device with a service (DS), wherein the device (ED) stores sensitive or confidential data (DA) and is arranged to perform an operation (SO) for providing the service (DS) in an operation phase (OP) including a user authentication pre-step (UAP), and further includes a device authentication pre-phase (SDAP) for verifying the authenticity of the device (ED), so that if the device (ED) is found to be authentic at the end of the device authentication pre-phase (SDAP), the user (USER) can execute the operation phase (OP), whereas if the device (ED) is not found to be authentic, the user (USER) can prevent the execution of the operation phase (OP). [Selected Figure] Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the authentication of devices or systems storing important or confidential data, and more particularly to a method for mutual authentication of functional electronic devices or systems (also for information processing and communication) controllable by a user, a method for operating such devices or such systems, and a device or system specially arranged for carrying out the authentication method or the operating method. [Background technology]

[0002] Within the scope of the present invention, the expression "functional electronic device" must be understood as being, for example, a payment terminal, while the expression "functional electronic system" must be understood as meaning a functional assembly comprising several devices that may be functionally linked between each other, in particular in the form of a functional chain, such as, for example, a payment terminal and a remote server.

[0003] The term "functional" modifying such a device or such a system should be understood broadly to mean functioning to perform certain operations (which may also be called tasks, transactions or the like) at an operational level, the operations being specific in nature such as ultimately providing a defined service to a user, such as placing an order, making a payment or the like.

[0004] The term "controllable" as it relates to a device or system relative to a user should be understood to mean that this device or this system is arranged in such a way that its operation can be initiated by the user, especially in the operational phase.

[0005] The terms "device" and "system" are shorthand for functional electronic devices and functional electronic systems, respectively.

[0006] Within the scope of the present invention, the term "authentication" should be understood to mean a process of verifying authenticity. The term "authenticity" should be understood to mean correctness, conformity with what is expected, truthfulness, evidentiality, unquestionableness, and even trustworthiness. The expression "mutual authentication" in relation to a functional electronic device or system that is controllable by a user should be understood as relating to the verification of the authenticity of the device or system by the user, and in combination, the verification of the authenticity of the user by the device or system. Therefore, authentication for the purposes of the present invention is firstly the verification that the device or system is indeed the right device or the right system, and secondly the verification that the user is indeed the right user. Mutual authentication therefore aims to secure the operations performed on and with the user, and ultimately the services provided to the user.

[0007] Within the scope of the present invention, the term "data" must be understood to mean all information, code, etc. that is specific and conditions the operation of a device or system in order to perform specific operations in order to provide a defined service to the user.

[0008] The terms "sensitive" and "sensitive" should be understood as qualifying data that must not be known, exposed, or accessible, as the case may be, except by the authentic device or system or by the authentic user, otherwise operations performed and ultimately services provided to the user may be unsecured or insecure.

[0009] The above is the background of the present invention and the interpretation of terms used throughout the text.

[0010] Those skilled in the art are already familiar with authentication processes for information processing and telecommunications systems. For example, a genuine user of a mobile phone equipped with a SIM (Subscriber Identity Module) card has a personal PIN (Personal Identification Number) code that protects the SIM card against any unauthorized use. In some cases, a second code, a PUK (PIN Unlock Key) code, whose sole purpose is to unlock the SIM card if it is blocked as a result of a series of incorrect entries (e.g., three times), is envisaged. U.S. Pat. No. 3,905,461, for example, describes an access control device using coded tokens available to genuine users. Alternatively, a certificate of authenticity, for example, activates a lock to ensure a secured connection, typically for financial transactions, data transfers, etc. EP 2,431,904 describes an authentication system known under the term question-and-answer authentication, based on challenge questions and verification of the accuracy of the answers to these challenge questions. EP 3035640 describes a method for authenticating a first device performed by a second device through a question-and-answer authentication process. For example, simple identification of a user to prove the user's identity does not amount to authentication of the user (see EP 2278538). Similarly, simple identification of a device or system by a user does not assure the user that the device or system is genuine. Thus, for example, if a genuine device or system is replaced by a counterfeit device or system, the user's use of the device or system may result in the user transmitting secret codes, important or confidential data, or the like, to the device or system, which an attacker may then retrieve and use fraudulently on behalf of the genuine user. [Prior art documents] [Patent documents]

[0011] [Patent Document 1] U.S. Patent No. 3,905,461 [Patent Document 2] European Patent No. 2431904 [Patent Document 3] European Patent No. 3035640 [Patent Document 4] European Patent No. 2278538 Summary of the Invention [Problem to be solved by the invention]

[0012] The problem underlying the present invention is therefore to ensure mutual authentication in the case of a functional electronic device or system controllable by a user, i.e. to verify that the device or system is indeed the correct device or the correct system and that the user is indeed the correct user, thus ensuring the security of the operations performed by this device or this system, including of the user, and ultimately of the services provided to the user. [Means for solving the problem]

[0013] The present invention provides a solution to this problem by envisaging a device or system pre-authentication phase, in which the device or system includes a step of authenticating the user, where the user verifies the authenticity of the device or system before the operational phase of performing an operation, during which critical or confidential data can be accessed, where the operational phase is conditional in that it can only be performed if the device or system has previously been authenticated and validly authenticated by the user in this device or system pre-authentication phase. In this way, a double authentication is achieved, which guarantees the security of the operations performed by the device or system and ultimately the services provided to the user.

[0014] The present invention will be described below.

[0015] According to a first aspect, the present invention provides a method for mutual authentication of a controllable functional electronic device and its user, comprising a device (ED) configuration pre-stage (SDCP) defining how the authenticity of the device can be verified, the user then being able to control the device to provide defined services to him, the device storing important or confidential data and arranged to perform specific operations appropriate to providing the service - in an operational stage initiated by the user and including a user authentication pre-step by the device, further comprising, prior to any operational stage, a device authentication pre-stage verifying the authenticity of the device, thus: - at the end of the device pre-authentication phase, if the device is found to be authentic, the user can perform the operational phase; - if at the end of the pre-device authentication phase the device is not found to be authentic, the user is alerted to this in some way so that the execution of the operational phase can be prevented; Thus, first the device and then the user are authenticated, and the actions performed and services provided are secured. The purpose of this method is to provide an authentication method that:

[0016] According to one embodiment, the device authentication pre-stage is performed by the user.

[0017] According to one embodiment, the method includes multiple operational stages over time such that before each operational stage, a device authentication pre-stage is performed.

[0018] According to one embodiment, the user's device pre-authentication stage is based on a question-and-answer authentication process using a device authentication secret, which is the user's pre-question to the device and the device's pre-response to the user to the pre-question, the pre-question and pre-response being secret so that they can only be known or accessed by the unique authentic user, such that the authenticity of the device can only be recognized when the user confirms that there is an identity between the response provided by the device to the pre-question on the one hand and the pre-response on the other hand.

[0019] According to one variant embodiment, if at the end of the pre-device authentication phase the device is not found to be authentic, the user may be prevented by the device itself from carrying out the operational phase.

[0020] According to one embodiment, the method also includes a pre-configuration step in which the device is configured with a device authentication secret (SDAS).

[0021] In one embodiment, the preliminary steps of configuring the device are performed by the user.

[0022] According to one embodiment, the configuration of the device with pre-questions and pre-answers is performed from the user's questions by a question and answer generation process.

[0023] According to one embodiment, the device authentication pre-phase is performed after the configuration pre-phase is performed and provided that no other device authentication pre-phase or operation phase has been performed in between.

[0024] According to an embodiment, the device authentication pre-phase is performed after the configuration pre-phase has been performed and provided that one or more other device authentication pre-phases or operation phases have been performed in the meantime.

[0025] According to an embodiment, a configuration pre-stage is necessarily and sufficiently linked to either a single device authentication pre-stage, a predetermined number of consecutive device authentication pre-stages, or an infinite number of consecutive device authentication pre-stages.

[0026] According to one embodiment, the preliminary step of user authentication by the device is based on a user authentication secret, which is the user's action response to the device that is secret so that it can only be known or accessed by the unique authentic user, so that the authenticity of the user can only be recognized when the device confirms that there is an identity between the response provided by the user on the one hand and the action response on the other hand.

[0027] According to one embodiment, the preliminary question and the action response are different.

[0028] According to one embodiment, the method is automatically performed at the end of a predetermined number of consecutive device pre-authentication phases during which the device is not recognized as authentic. In particular, this sensitive or confidential data purging step also erases the pre-questions and pre-responses if, at the end of a predetermined number of consecutive device or system pre-authentication phases, the user fails to provide a pre-question corresponding to a pre-response, thereby causing the device or system to determine that the user is not a genuine user.

[0029] According to a second aspect, the present invention provides a method for the operation by a user of a functional electronic device controllable by the user to provide a defined service to the user, the device storing important or confidential data and performing specific operations appropriate for the device to provide the service during an operational phase initiated by the user and including a preliminary step of user authentication by the device, further including a device authentication pre-phase verifying the authenticity of the device prior to any operational phase, thus: - at the end of the device pre-authentication phase, if the device is found to be authentic, the user can perform the operational phase; - if, at the end of the pre-device authentication phase, the device is not found to be authentic, the user is alerted to this by some means so that the execution of the operational phase can be prevented; Thus, first the device and then the user are authenticated, and the actions performed and services provided are secured. The purpose of this method of operation is to

[0030] According to a third aspect, the invention is directed to a functional electronic device controllable by a user for defined services, storing important or confidential data and specially arranged for the implementation of the above-described mutual authentication method and in particular for the implementation of an operational method for carrying out a device authentication pre-phase.

[0031] According to one embodiment, the device is configured at the end of a pre-configuration phase with an authentication secret for the device that is a user's preliminary questions for the device and the device's preliminary responses to the user's questions.

[0032] The device therefore contains and combines, on the one hand, a device authentication secret and, on the other hand, a user authentication secret.

[0033] According to a fourth aspect, the present invention is directed to a method for mutual authentication of a functional electronic system comprising a plurality of electronic devices controllable by a user for the purpose of a defined service, storing important or confidential data and functionally linked amongst themselves, arranged in such a way that they perform a specific operation or series of operations appropriate to providing the service - in an operational phase initiated by the user and including a step in which the system authenticates the user - and further comprising, prior to any operational phase, a preliminary phase of authenticating the system, during which the authenticity of all or part of the plurality of devices comprised by the system is verified by implementing the authentication method described above for each of the devices to be verified.

[0034] According to one embodiment involving multiple electronic devices forming one or more functional chains with one or more upstream devices and one or more downstream devices, the method comprises: - if, at the end of the pre-authentication phase of an upstream device in the device chain, this device is found to be authentic, authentication of one or more downstream devices in the same device chain is initiated; - if at the end of the pre-authentication phase of a device upstream in the device chain, this device is not found to be authentic, the authentication of one or more downstream devices in the same device chain will not be initiated because the system has been found to be inauthentic; This is a mutual authentication method.

[0035] According to a fifth aspect, the present invention provides a method for the operation by a user of a functional electronic system controllable by the user to provide the user with a defined service, the system comprising a plurality of electronic devices storing important or confidential data and functionally linked amongst themselves, in which - in an operational phase initiated by the user and including a preliminary step of user authentication by the system - the system performs a specific operation or series of operations appropriate for providing the service, further including, prior to any operational phase, a system pre-authentication phase, during which the authenticity of all or some of the devices comprised by the system is verified by implementing the authentication method described above for each of the devices to be verified, thus: - at the end of the system pre-authentication phase, if the system is found to be authentic, the user can carry out the operational phase; - if at the end of the pre-authentication phase of the system the system is not found to be authentic, the user is alerted to this by some means so that the execution of the operational phase can be prevented; Thus, first the system and then the user are authenticated, and the actions performed and the services provided are secured. The purpose of this method of operation is to

[0036] According to a sixth aspect, the present invention is directed to a functional electronic system, controllable by a user for defined services, comprising a plurality of electronic devices storing important or confidential data and functionally linked among each other as described above, specially arranged for the implementation of a mutual authentication method as described above and for the implementation of an operating method as described above, in particular for carrying out a pre-authentication phase of all or part of the plurality of devices that the system comprises. [Brief explanation of the drawings]

[0037] [Figure 1] 1 is a theoretical overview of an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0038] We now briefly describe the only Figure 1, which is a purely academic and indicative theoretical overview of the steps of a possible embodiment of how a user operates a functional electronic device that can be controlled by the user to provide the user with defined services and that contains important or confidential data, illustrating: - first, a preliminary configuration phase based on the device authentication secret, carried out by the user; - a pre-device authentication phase that verifies the authenticity of the device based on the device authentication secret; - then, insofar as the device is found to be authentic at the end of the device authentication pre-phase, an operational phase including a preliminary user authentication step initiated by the user and based on the user authentication secret by the device, in which the device performs specific operations appropriate for providing the service.

[0039] The following is a detailed description of various embodiments and methods of carrying out the invention, including examples and reference to figures. This description should be understood in the context of the invention and with the interpretation of terms as provided above, and therefore no repetition is necessary here.

[0040] The present invention relates to and embodies a controllable functional (also information processing and communication) electronic device ED storing sensitive or confidential data DA, and more generally a functional (also information processing and communication) electronic system ES comprising a plurality of devices ED forming one or more functional chains with one or more upstream devices and one or more downstream devices. As in the case of the device ED, the system ES stores sensitive or confidential data DA. The description of the present invention is more particularly detailed with respect to the device ED. It can be applied to the system ES, i.e. to all or part of the devices ED it contains, in particular to all or part of the devices that store sensitive or confidential data DA or whose authenticity must be recognized.

[0041] The invention involves a user USER who controls a device ED or a system ES by means of commands CO to provide a defined service DS to the user and who carries out the different phases or steps required for the operation of the device ED or the system ES.

[0042] The present invention aims to ensure mutual authentication of the user USER as well as the device ED or system ES, i.e., to ensure that the user USER can first verify that the device ED or system ES is indeed authentic, and then that the device ED or system ES can verify that the user USER is indeed authentic. In this way, the security of specific operations SO performed by the device ED or system ES, including with respect to the user USER, and ultimately of the defined services DS provided to the user USER, is guaranteed. From this, it should be understood that control of the device ED or system ES by the user USER is only possible if the device ED or system ES is authentic and not a fake or fraudulent device or system, and if the user USER is authentic and not a fake or fraudulent user. If the device ED or system ES appears to be inauthentic, the user will be prevented from performing specific operations SO, in the sense that they will be prevented from being executed. Similarly, if the user is found to be inauthentic, the user will be prevented from performing specific operations SO even more, in the sense that they will be prevented from being executed.

[0043] In the following, it is assumed that the device ED or system ES is authentic and that the user USER is authentic. The description of the present invention details what happens if the device ED or system ES is not authentic and if the user USER is not authentic.

[0044] In one embodiment, the user USER is a genuine person.

[0045] In another embodiment, the user USER is an avatar of a bona fide person who is legal to perform the task under consideration and who has lawfully obtained the code, secrets, etc. that the bona fide person possesses so that he or she can lawfully act on behalf of the bona fide person.

[0046] "Operation phase" OP means a phase initiated by a user USER by a command CO, in which a device ED or a system ES performs appropriate specific operations SO specifically designed to provide a service DS to the user USER.

[0047] By "user authentication preliminary step" UAP is meant a preliminary step included within the operational phase OP in which the device authenticates the user USER using the user authentication secret UAS.

[0048] "Device or system pre-authentication phase" SDAP means a phase in which the user USER verifies the authenticity of the device ED or system ES, for example by means of the device or system authentication secret SDAS.

[0049] "Device or system pre-configuration phase" SDCP refers to the phase in which the device ED or system ES is configured with the device or system authentication secret SDAS. In one embodiment, this configuration is achieved by the user USER.

[0050] The operation method of the device ED or system ES is such that, before every operation phase OP, it includes a device or system pre-authentication phase SDAP, which is added to the operation phase OP, is executed before this operation phase OP, and conditions the possibility of executing this operation phase OP itself. Indeed, if at the end of the device or system pre-authentication phase SDAP, the device ED or system ES is recognized as authentic, the user USER can execute the operation phase OP, but if at the end of the device or system pre-authentication phase SDAP, the device ED or system ES is not recognized as authentic, the user USER can prevent the execution of the operation phase OP.

[0051] Thus, the operating method of the device ED or system ES integrates a mutual authentication method between the device ED or system ES and its user USER. In this way, first the device ED or system ES and then the user USER are authenticated. And in this way, certain operations SO performed by the device ED or system ES and services DS provided to the user USER are secured. The invention can be seen both from the point of view of the operating method of the device ED or system ES integrating this mutual authentication method, and also from the point of view of this mutual authentication method for and being integrated within such an operating method.

[0052] According to an embodiment in which several operational phases are envisaged over time, a device or system authentication pre-phase SDAP is carried out before each operational phase OP.

[0053] In one possible embodiment, the pre-authentication phase SDAP of the device or system by the user USER is based on a question-and-answer authentication process using a device or system authentication secret SDAS, which is a pre-question PQ of the user USER to the device ED or system ES and a pre-response PA of the device ED or system ES to the user USER to the pre-question PQ. The pre-question PQ and the pre-response PA are different and secret because they are known or accessible only to the unique authentic user USER. Therefore, the authenticity of the device ED or system ES can only be recognized if the user USER confirms that there is an identity between the response ADS provided by the device ED or system ES to the pre-question PQ and the pre-response PA.

[0054] It is understood that the above-described device or system authentication pre-stage SDAP using a question-and-answer authentication process is not exclusive or limiting. Other processes that provide a higher level of authentication can be contemplated. Therefore, the present invention also encompasses embodiments based on authentication processes equivalent to a question-and-answer process. Likewise, it is understood that a device or system authentication pre-stage SDAP can include a combination of several question-and-answer or equivalent authentication processes to achieve a higher level of authentication. Therefore, it should be understood that the expression device or system authentication pre-stage SDAP is based on a question-and-answer authentication process.

[0055] According to one possible embodiment, the configuration of the device ED or the system ES with the authentication secret SDAS (pre-question PQ and pre-answer PA) of the device or system is carried out by: Using questions from user USER, Functions, programs, or algorithms question The response generation process Really It will be carried out.

[0056] Several embodiments can be envisioned regarding the correlation between the device or system configuration pre-phase SDCP, the device or system authentication pre-phase SDAP, and the operation phase OP. Thus, according to one embodiment, the device or system authentication pre-phase SDAP is executed after the device or system configuration pre-phase SDCP has been executed, without any other device or system authentication pre-phase SDAPs or operation phase OPs being executed therebetween. According to another embodiment, the device or system authentication pre-phase SDAP is executed after the device or system configuration pre-phase SDCP has been executed, with one or more other device or system authentication pre-phase SDAPs or operation phase OPs being executed therebetween. Meanwhile, according to several embodiments, a device or system configuration pre-phase SDCP is necessarily and sufficiently associated with a predetermined number of consecutive authentication pre-phase SDAPs or an infinite number of consecutive authentication pre-phase SDAPs.

[0057] The user authentication secret UAS used in the user authentication preliminary step UAP is the user USER's action response OA to the device ED or system ES which is secret since only the authentic user knows and has access to it, and thus the authenticity of the user is recognized only when the device ED or system ES has verified that there is an identity between the response AU provided by the user on the one hand and the action response OA on the other hand.

[0058] The operation phase OP preliminarily includes a user authentication preliminary step UAP, which conditions the possibility of the execution of this operation phase OP itself. Indeed, if the user USER is recognized as authentic at the end of the user authentication preliminary step UAP, this user USER can execute the operation phase OP, whereas if the user is not recognized as authentic at the end of the user authentication preliminary step UAP, this user can prevent the execution of the operation phase OP.

[0059] Several embodiments can be envisaged. In one embodiment, an action question OQ of the device ED or system ES to the user USER is envisaged, to which the user USER must respond with an action response OA. Alternatively, it is the initiation of the action phase OP itself that forces the user USER to provide an action response OA to the device ED or system ES. In any case, if the response AU provided by the user and the action response OA are not identical, the device ED or system ES will consider that the user is not a genuine user, with the result that the action SO is not executed and the service DS is not provided.

[0060] The authentication of a user by the above-described question-and-answer authentication process, similar to device or system authentication, is not exclusive or limiting. Other processes that provide a higher level of authentication can be contemplated. Therefore, the present invention also encompasses embodiments based on authentication processes equivalent to the question-and-answer process. It is also understood that the user authentication preliminary step UAP can include a combination of several authentication processes, such as question-and-answer, in order to have a higher level of authentication.

[0061] According to one embodiment, the pre-questions PQ and the action responses OA are different.

[0062] According to one embodiment, the method comprises a step of excluding sensitive or confidential data DA of the device ED or system ES, which step is carried out automatically at the end of a predetermined number of consecutive executions of the device or system pre-authentication phase SDAP during which the device ED or system ES is not recognized as authentic.

[0063] According to a complementary embodiment, the step of excluding important or confidential data DA of the device ED or system ES also excludes the pre-question PQ and pre-response PA if, at the end of a predetermined number of consecutive executions of the device or system pre-authentication phase SDAP, the user USER fails to provide a pre-question PQ corresponding to a pre-response PA, and therefore the device ED or system ES considers the user to be not a genuine user.

[0064] If the method relates to a system ES, a system authentication pre-phase SDAP is assumed before any operational phase OP, during which the authenticity of all or some of the devices ED contained in the system ES is confirmed by carrying out the authentication method described above for each device ED confirmed.

[0065] In such a system ES, multiple device EDs may form one or more functional chains together with one or more upstream device EDs and one or more downstream device EDs. In this case, it can be assumed that, on the one hand, if an upstream device ED in the device ED chain is found to be authentic at the end of the pre-authentication phase SDAP, the authentication pre-phase SDAP of one or more downstream device EDs in the same device ED chain is initiated, and, on the other hand, if an upstream device ED in the device ED chain is found not to be authentic at the end of the pre-authentication phase SDAP, the system ES is found to be inauthentic, and therefore the authentication pre-phase SDAP of one or more downstream device EDs in the same device ED chain is not initiated.

[0066] The device ED or system ES according to the invention is specially arranged for the implementation of the above-described mutual authentication method and in particular for the implementation of an operational method for performing a device or system pre-authentication phase SDAP, said device ED or said system ES being configured with, and thus comprising and combining, a device or system authentication secret SDAS on the one hand and a user authentication secret UAS on the other hand.

[0067] We now refer to the single diagram in Figure 1, which represents a user USER and a device ED or system ES in the form of two columns, one on the left and one on the right. It presents three blocks, which follow each other on the time axis from top to bottom: a configuration preparatory step SDCP, a device or system authentication preparatory step SDAP, and finally an operation phase OP, which is itself decomposed into two blocks, the first corresponding to a user authentication preparatory step UAP and the second corresponding to the so-called operation phase. As explained above, these two blocks overlap to a greater or lesser extent.

[0068] The diagram illustrates that a device ED or a system ES stores important or confidential data DA, which contains and combines, on the one hand, a device or system authentication secret SDAS and, on the other hand, a user authentication secret UAS (symbolically represented by a closed lock).

[0069] The diagram illustrates that these two secrets are successively opened (symbolized by an open lock) firstly the device or system authentication secret SDAS and then on the other hand the user authentication secret UAS.

[0070] Once authenticated, the device ED or system ES is represented by a horizontal stripe, and once authenticated, the user is represented by a horizontal stripe.

[0071] This diagram illustrates that a user's command CO, aimed at the execution by the device ED or the system ES of a particular action SO for providing the user with a defined service DS, only intervenes once the device ED or the system ES has been authenticated (by the user) in a combined manner and once the user has been authenticated. [Explanation of symbols]

[0072] AU Response ADS Response CO Command DA data DS Services ED Electronic Device ES Electronic Systems SO operation OA Operation Response OP Operational Stage OQ Operational Questions PA Advance Response PQ Advance Questions SDAS authentication secret SDAP Pre-Authentication Stage SDCP configuration preliminary stage UAP User Authentication Preliminary Steps UAS User Authentication Secret USER User

Claims

1. A method of executing a transaction with an authentic electronic device, the electronic device being configured to initiate an operational phase of the transaction upon receiving a command from a user, and to perform specific operations during the operational phase to provide the user with a predetermined service corresponding to the intended transaction; The method includes, before the operating stage begins: a pre-configuration step of the electronic device; and a pre-authentication step of the electronic device; The preliminary step of configuring the electronic device includes setting, in the electronic device, preliminary questions and preliminary answers generated by a question-and-answer generation process using questions from the user; The pre-authentication stage of the electronic device comprises: sending, by the user, the advance query to the electronic device; receiving a response to the preliminary question from the electronic device by the user; confirming by the user that the response provided by the electronic device corresponds to the expected prior response; the electronic device permits execution of the operation step when the electronic device is confirmed to be authentic as a result of the user's verification of the electronic device in the pre-authentication step, and prevents execution of the operation step when the electronic device is not confirmed to be authentic; the operating stage includes a preliminary step of user authentication by the electronic device; The preliminary user authentication step includes: providing, by the electronic device, an operational query to the user; receiving, by the electronic device, a response from the user to the operational question and comparing the user's response with an expected operational response stored in the electronic device; The method further includes, by the electronic device, purging confidential data stored on the electronic device if the user fails to provide the pre-question to the electronic device within a predetermined number of repetitions of the pre-authentication stage by the electronic device.

2. The method of claim 1 , comprising a plurality of said operational steps over time, each step preceded by said pre-authentication step of said electronic device.

3. The method of claim 1, wherein eliminating the confidential data stored by the electronic device includes erasing the pre-questions and pre-responses.

4. Providing a plurality of electronic devices forming a single functional chain for performing the transaction, the functional chain including at least a single upstream electronic device and a single downstream electronic device; performing the pre-authentication step of the upstream electronic device; and 2. The method of claim 1, further comprising: if the upstream electronic device is authenticated, performing the pre-authentication step of the downstream electronic device; and otherwise not performing the pre-authentication step of the downstream electronic device.

5. a genuine electronic device for performing a transaction, the electronic device being configured to initiate an operational phase of the transaction upon receiving a command from a user, and to perform specific operations during the operational phase in order to provide the user with a defined service corresponding to the intended transaction; The electronic device stores confidential data including pre-questions and pre-answers generated by a question-answer generation process using questions from the user; and During a pre-authentication phase of the electronic device by the user, receiving the advance question from the user; providing the user with the stored corresponding preliminary response in response to the preliminary question received from the user; the electronic device is configured to permit execution of the operation step when the electronic device is confirmed to be authentic as a result of the user's verification of the electronic device in the pre-authentication step, and to prevent execution of the operation step when the electronic device is not confirmed to be authentic; The electronic device, during the operating phase, as a preliminary step of user authentication by the electronic device, providing the user with an operational question; configured to receive a response from the user to the operational question and compare the user's response with an expected operational response stored in the electronic device; and The electronic device is configured to remove the confidential data stored on the electronic device if the user does not receive the pre-question within a predetermined number of executions of the pre-authentication stage of the electronic device by the user.

Citation Information

Patent Citations

  • Online payer authentication service

    EP2278538A1

  • Circumstantial authentication

    EP2431904A1

  • Method for authenticating a device

    EP3035640A1

  • Access-control equipment

    US3905461A