Method for managing data associated with timepiece

By using ISO 7810 ID-1 standard NFC chip cards and blockchain technology, combined with a strong authentication mechanism, the problems of outdated communication methods and poor security in existing technologies are solved, enabling safe and reliable communication between users and retailers and protecting users' personal data.

CN120604177APending Publication Date: 2025-09-05ROLEX SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480009514.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-30
Filing Date
2024-01-30
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing technology has problems when users communicate with retailers, especially during the valuation and operation of watches, such as outdated communication methods, poor security, and inability to reliably ensure the authenticity of the identities of both parties in the communication, resulting in the damage of user personal data protection.

Method used

Using the ISO 7810 ID-1 standard NFC chip card, combined with blockchain technology, users can access table-related data by scanning QR codes or NFC chips with smartphones. It utilizes distributed computing architecture and strong authentication mechanisms to achieve secure communication between users and third parties, provide anonymity and service mode switching, and ensure the non-traceability and security of data.

Benefits of technology

It enables convenient communication between users and third parties without compromising the security of users' personal data, improves the security and reliability of communication, simplifies the interaction process between users and retailers, and protects users' privacy data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005519510170000011
    Figure HDA0005519510170000011
  • Figure HDA0005519510170000021
    Figure HDA0005519510170000021
  • Figure HDA0005519510170000031
    Figure HDA0005519510170000031
Patent Text Reader

Abstract

Disclosed is a method for managing data associated with a timepiece (10) belonging to a user, said data comprising: a first type of data (51) comprising or consisting of personal data of the user, and a second type of data (61) comprising or consisting of timepiece-specific data, the method comprises exclusive modes: a first mode (S10) in which the user is able to consult the first type of data (51), and a second mode (S20) in which the user is not able to consult the first type of data (51), said data being able to be consulted via the web page (71).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for managing data associated with a timepiece belonging to a user. The invention also relates to a data management system for implementing this method. The invention further relates to a computer program for implementing this method. The invention also relates to a recording medium on which such a program is recorded. Finally, the invention relates to a signal from a data carrier carrying a computer program product. Background Art

[0002] When a user brings a watch to a retailer for repair (after-sales service), it's crucial that the user be able to communicate with the retailer, particularly to agree on the price and / or operation of the watch. This communication typically takes place via email, fax, or phone. These communication methods are now largely outdated compared to the possibilities offered by new technologies and offer only a relatively limited customer experience. Furthermore, these communication methods are either insecure or have poor security. In particular, these methods cannot reliably ensure that communications are actually being exchanged with the actual user of the watch. Consequently, the protection of the user's personal data may be compromised.

[0003] Today, solutions in the watchmaking industry make it possible to display specific data on a watch or a set of characteristics of a watch on a terminal by means of a unique access method using a card in the identity card format conforming to the ISO 7810 ID-1 standard.

[0004] "Watch Certificate" proposes a card designed to certify the authenticity of a watch. This card can be used to access various specific data about the watch via a website by scanning a QR code on the card (e.g., with a smartphone). Furthermore, various personal data, particularly those related to the watch's owner, can be accessed by entering a code written on the card. This solution uses blockchain technology to ensure a high degree of traceability of specific and personal data.

[0005] Other watchmakers are using a similar scheme, the "Arianee" consortium, that utilizes blockchain technology. This scheme provides complete traceability and is designed to prove the authenticity and ownership of a watch. The proposed scheme also involves a card associated with the watch and bearing a QR code. Alternatively, it could include an NFC (Near Field Communication) chip. Once scanned with a smartphone, the card allows the user to access a webpage to register their watch and obtain a certificate of authenticity. To obtain this certificate, the user is invited to connect to a dedicated mobile app to generate a certificate in NFT (non-fungible token) format, declaring themselves the original owner.

[0006] The OMEGA watch brand has proposed a solution that can be used to access specific data of the watch using a card with an NFC chip. Accessing this data requires a user account and a dedicated application on a smartphone compatible with NFC technology.

[0007] Some watch brands use a solution proposed by the company "WISeKey", which specifically uses blockchain technology to provide warranty and / or authentication cards for watches, and even provide payment functions related to watches.

[0008] It is important to note that the high degree of traceability provided by blockchain technology involves the unalterable storage of all historical data and, depending on the adopted policy, the unalterable storage of the personal data of the different owners of the table.

[0009] Furthermore, in known solutions, it is necessary to download an application dedicated to the solution, create a user account, and use an identifier, which is inconvenient for the user and is susceptible to security vulnerabilities. Summary of the Invention

[0010] The object of the present invention is to provide a method for managing data associated with a timepiece belonging to a user, which overcomes the aforementioned drawbacks and improves upon the management methods known from the prior art. In particular, the present invention makes it possible to implement a method that facilitates communication between the user and a third party (database manager and / or retailer and / or organization responsible for after-sales service) without compromising the security of the user's personal data.

[0011] The management method according to the invention is defined by claim 1 .

[0012] Different embodiments of the method are defined in claims 2 to 11 .

[0013] The management system according to the invention is defined by claim 12 .

[0014] Embodiments of the system are defined by claims 13 and 14 .

[0015] The program product according to the invention is defined by claim 15 .

[0016] The recording medium according to the present invention is defined by claim 16 .

[0017] A data carrier signal according to the invention is defined by claim 17 . BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings show, by way of example, embodiments of a management method and an embodiment of a data management system according to the present invention.

[0019] Figure 1 is a schematic diagram of an implementation of a data management system.

[0020] Figure 2 It is a flowchart of a first procedure of an embodiment of a data management method.

[0021] Figure 3 It is a flowchart of the second procedure of the embodiment of the data management method. DETAILED DESCRIPTION

[0022] Refer to the following Figure 1 An embodiment of a data management system 100 is described. System 100 can be used to manage data associated with a timepiece product 10 (e.g., a clock or watch, particularly a wristwatch). Timepiece product 10 includes, for example, a unique identifier 11, such as a serial number 11. The unique identifier is, for example, a string of alphanumeric characters, including, for example, eight random digits. The unique identifier can be printed in a font that allows for automatic optical reading. The unique identifier can be engraved on timepiece product 10, particularly:

[0023] - on a watch movement, for example on a main plate, and / or

[0024] - on the case, for example on the middle piece or flange, and / or

[0025] - For example, on a wrist strap, on a buckle.

[0026] The data being managed not only relates to the table product 10, but also preferably relates to:

[0027] - data relating to the current user (or indeed to previous users), in particular all or part of the following: the user's name, postal address, e-mail address, telephone number, and / or

[0028] - data relating to the organization responsible for after-sales service (e.g. a retailer), in particular all or part of the following: the organization's name, postal address, e-mail address, telephone number, and / or

[0029] - Data relating to the watch manufacturer or the watch company marketing watch products, in particular all or part of the following data: name, postal address, e-mail address, telephone number of the watch manufacturer or watch company.

[0030] The data management system 100 includes:

[0031] - a physical medium 20, for example a card 20 in the format defined by the ISO 7810 ID-1 standard, having access means 21 such as an NFC chip 21,

[0032] - a device or terminal or client 30, such as a computer (which may or may not be portable), a smartphone or a tablet, having:

[0033] * a web browser application 32 adapted to manage the display of web pages and more generally to ensure communication with the Internet, and

[0034] * a function or device 31 capable of communicating with or reading the access device 21, such as an NFC function 31 or an NFC device 31,

[0035] - authentication means 40 for verifying the authenticity of the access means 21,

[0036] a first database 50, for example a relational database, comprising in particular data 51 of a first type, in particular personal data 51 of a user, and possibly personal data 51 of a plurality of users, and

[0037] a second database 60, for example a relational database, comprising in particular data 61 of a second type, in particular data 61 specific to the table product 10 or indeed specific to a plurality of table products 10, for example one or more unique identifiers 11,

[0038] - A server 70, for example a web server or an application server.

[0039] The web browser application 32 or "web browser" is preferably an application that is integrated as standard in the terminal 30. In other words, the web browser 32 is an application that is pre-installed and / or developed by the manufacturer of the terminal 30. The device 31 capable of communicating with or reading the access device 21 is preferably a function that is integrated as standard in the terminal 30, in particular a radio wave communication function.

[0040] The card 20 , or more specifically the NFC chip 21 , is intended to be associated with at least one specific item of data 61 of the product 10 , such as the serial number 11 .

[0041] The NFC chip 21 is designed to be activated by the NFC function 31 of the terminal 30 when the card 20 is brought close to the terminal 30. This action of bringing the card close to the terminal and activating is referred to as "tapping" in this document.

[0042] The NFC chip 21 preferably has means for ensuring the highest possible security level during manufacture. To this end, the NFC chip 21 advantageously comprises a unique number 22, a cryptographic function, at least one encryption key 24 (e.g., a string of characters), and means 25 for generating a URL internet address. These cryptographic functions advantageously enable the generation of encryption parameters 23 using dynamic and / or static variables intended to be sent from the terminal 30 via the server 70 to the authentication device 40 in order to verify the encryption parameters and authenticate the NFC chip 21 during each tap.

[0043] In order to be able to decrypt said encrypted parameters 23 , the authentication device 40 notably comprises at least one decryption key 41 compatible with the encryption key 24 of the NFC chip 21 .

[0044] The NFC chip 21 preferably does not require a power cell or battery pack. It is powered by the electromagnetic induction generated by the terminal 30 during tapping.

[0045] Each tap of the card 20 is designed to start a program for connecting to a web page 71 dedicated to the relevant watch product 10. On this web page, the data contained in the first database 50 and the second database 60 can be displayed. The data associated with the watch product 10 belonging to the user include:

[0046] - data of a first type 51, for example stored in a first database 50, and

[0047] Data of a second type 61 , for example stored in a second database 60 .

[0048] System 100 includes all hardware and / or software devices for implementing the management method that is the object of the present invention. These devices may include software devices. Preferably, these devices form a distributed computing architecture, and these devices are located in different computers, machines or physical entities.

[0049] Refer to the following Figure 2 and Figure 3 An embodiment of a method for managing data associated with a timepiece belonging to a user is described. This embodiment is advantageously implemented by the management system described above. Therefore, the management method can also be considered as a method for operating the management system described above.

[0050] This method includes the following exclusive modes:

[0051] - a first mode S10, in which in step S50 the user is able to consult data 51 of a first type, for example on a smartphone, tablet or computer and / or via a website or application, and

[0052] A second mode S20 in which the user cannot consult the data 51 of the first type in step S60 .

[0053] These two modes are exclusive, i.e., the method and system 100 for implementing the same:

[0054] - either in the first mode S10,

[0055] - or in the second mode S20.

[0056] In the first mode S10 , data 51 of the first type can advantageously be consulted by the user using the terminal 30 and by the server 70 .

[0057] These two modes help provide different experiences for users:

[0058] Advantageously, in a first mode S10 (hereinafter also referred to as "service" mode), the physical medium 20 allows the user to consult data 61 specific to the watch product 10 associated with the physical medium 20 on a web page 71. In other words, it can be used to access the identity document or personal data of the watch product. In this first mode, the physical medium 20 allows the user to access personal data 51, such as an estimate for repairing the watch product 10 or notices issued by the organization that repairs the watch product 10. Furthermore, in this first mode, the user advantageously has the possibility of interacting with the organization via a dedicated interface on the web page 71. This interaction is advantageously secure.

[0059] In the second mode S20 (hereinafter also referred to as "anonymous" mode), the first type of data 51 is not accessible, in particular the user's personal data. In fact, the physical medium 20 only allows the user to consult, on a dedicated web page 71, certain data 61 representing the product 10 associated with the physical medium 20, such as the product's identity document or personal data.

[0060] The modes of the management method or the operating modes of the management system (first mode S10 or second mode S20) are defined as functions of associating or disassociating the watch product 10 with the user, in particular, functions of associating or disassociating the following data:

[0061] - data of the first type 51, for example stored in the first database 50, and

[0062] Data of a second type 61 , for example stored in a second database 60 .

[0063] For example, data are linked / separated via actions (such as registration) performed by data administrators (such as the organization responsible for after-sales service operations or the retailer) through a computer program or application provided to them.

[0064] For example, the association of data or databases is only envisaged when the table product 10 is handed over to the organization for maintenance. In this case, the management system is configured in the first "service" mode. Otherwise, the management system is configured in the second "anonymous" mode.

[0065] Advantageously, the schema can be modified infinitely depending on whether the user owns the watch product 10 .

[0066] More generally:

[0067] - in a first "service" mode, the terminal 30 allows the display of data contained in the first database 50 even if the first and second databases are not linked, and

[0068] In a second “anonymous” mode, the terminal 30 does not allow the display or consultation of the data contained in the first database 50 , even if the first and second databases are linked.

[0069] In a first "service" mode, when a user takes his or her watch product 10 to an organization, such as a retailer, for repair, the user's personal data 51 is recorded or modified in a first database 50. For example, personal data 51 such as the user's name, postal address, email address, and telephone number can be recorded in database 50. This personal data 51 is particularly necessary for drawing up estimates and invoices, as well as for communicating with the user. This personal data can be recorded or modified when the user hands over his or her watch product. Alternatively, the personal data 51 may already be contained in the first database 50 when the user hands over his or her watch product 10. Naturally, this first database 50 is not accessible to third parties and uses security methods to optimally protect the user's personal data 51. The security methods may include access management and / or authorization management and / or encryption and / or network segmentation and / or filtering. Furthermore, the data is processed in a manner that complies with the European General Data Protection Regulation, or GDPR.

[0070] The user is provided with a physical medium 20 (e.g. a card 20) associated with the watch product 10 in order to enable him or her to connect to a web page 71 dedicated to the watch product 10 via a terminal 30 of the user's choice, which terminal 30 allows access to the server 70 via the Internet protocol. Preferably, however, in order for the user to be able to connect to the web page 71, according to a first "service" mode, at least one item of the user's personal data 51 must be associated with a specific item of the data 61 of the watch product 10. For example, the user's telephone number can be associated with the serial number 11 of the watch product 10. Preferably, the association between the user's personal data 51 and the specific data 61 of the watch product is made automatically by the computer system providing the interface, that is, the association between the following data:

[0071] - data from the first database 50, and

[0072] - Data from the second database 60 .

[0073] However, the transition (from the second "anonymous" mode S20) to the first "service" mode S10 is triggered or executed by a first event caused by the data manager (e.g., an organization or retailer). For example, this first event can be a verification or action performed on a computer system used by the organization to which the user has delivered their watch product. Preferably, the first "service" mode only works or can be activated after the user's watch product 10 has been delivered to the organization.

[0074] In the second, “anonymous” mode, when the user is in possession of the watch product 10, preferably no association is established between the user's personal data 51 and the specific data 61 of the watch product 10. However, the user can still use the physical medium 20 associated with the watch product 10, enabling him or her to access the specific data 61 of the watch product 10 on the dedicated web page 71.

[0075] The transition (from the first “service” mode S10) to the second “anonymous” mode S20 is triggered or executed by a second event. For example, the second event may be:

[0076] - actions by data managers, such as verification or actions on computer systems running in the organization to which users submit their table products,

[0077] - an action of the user, for example a specific action on the human-machine interface of the terminal 30 when the terminal 30 is connected to the server 70 in a secure mode allowing access to the first type of data 51. Such an action may also include, for example, a communication or interaction with the organization, such as the rejection of an estimate.

[0078] - Expiration of a timeout. For example, it may be defined by default that the first "service" mode S10 remains active for a defined number of days, for example 30 days. At the end of this timeout, it automatically switches to the second "anonymous" mode S20 without any specific action by the user or a third party.

[0079] Therefore, if Figure 2 As shown, the test step T05 tests whether the most recent event is the first event or the second event. If the most recent event is the first event, the mode is switched to the first mode S10. If not the first event, the most recent event is the second event, and the mode is switched to the second mode S20.

[0080] Once the physical medium 20 is in the hands of the user, the user can connect to the server via the web page 71 dedicated to the watch product 10. To do this, it can be done in the following way:

[0081] 1. The user has a terminal 30 (eg, a smartphone 30 ) with NFC functionality 31 and taps the NFC chip 21 of the physical medium 20 against it.

[0082] 2. Upon tapping, the NFC chip 21 is activated and provides the terminal 30 with parameters 23 encrypted by at least one encryption key 24, and generates a URL 25 pointing to the server 70. This URL is preferably a new, different and non-reusable URL each time the NFC chip is used or during each tap.

[0083] 3. The server 70 then relays, in particular, the encrypted parameters 23 to the authentication device 40 .

[0084] 4. Using at least one decryption key 41, the authentication device 40 continues to authenticate the NFC chip 21 by decrypting the encryption parameter 23 and decoding the NFC chip's unique number 22. In addition, to further enhance security, the authentication of the NFC chip 21 may also be controlled by any other means.

[0085] 5. If the authentication of the NFC chip 21 is confirmed, the authentication device 40 sends in particular the unique number 22 of the NFC chip back to the server 70. Otherwise, the connection procedure is interrupted.

[0086] 6. Using unique number 22, server 70 consults second database 60 to find serial number 11 of watch product 10 associated with NFC chip 21. If serial number 11 is further associated with an item in the user's personal data 51, server 70 then generates a session on smartphone 30's web browser 32 with web page 71 in a first "service" mode, which allows access to data from both the first and second databases. If not, a session is generated with web page 71 in a second "anonymous" mode.

[0087] In other words, if Figure 3 As shown, in step T30, if an attempt is made to access data by using the physical medium 20, a procedure for authenticating the physical medium, particularly the access device 21, is started. If the procedure for authenticating the physical medium is successful, a test is performed to determine whether the system is in the first mode S10 or the second mode S20. If the system is in the first mode S10, a strong authentication procedure T40 is started, i.e., a procedure for authenticating the user holding the physical medium. If the user authentication procedure is successful, the process proceeds to step S50, where the first type of data 51 can be accessed. If unsuccessful (i.e., if the strong authentication procedure fails or if the system is in the second mode S20), the process proceeds to step S60, where the first type of data 51 cannot be accessed.

[0088] Preferably, only one session can be opened at a time via the physical medium 20, and in particular, in the first "service" mode, only one session can be opened at a time via the physical medium 20. However, as long as the physical medium 20 is associated with the watch product 10, for example, as many sessions as desired can be opened indefinitely and continuously.

[0089] Regardless of the mode ("service" or "anonymous"), a session is opened on the user's terminal 30 using the terminal's 30 web browser 32. Advantageously, no additional or dedicated applications are required, and no user account or account identifier is required to consult and display the web page 71.

[0090] In the first "service" mode, it is advantageous to perform strong authentication of the user (e.g., multi-factor authentication using at least two different factors). Authentication may involve biometric data and / or a temporary code and / or a smart card and / or a mobile application. These factors may be:

[0091] - knowledge-based factors, such as passwords, PINs, or answers to security questions,

[0092] - Possession-based factors such as a security token (hardware or software), smart card, security key, mobile authenticator, SMS or notification received on a mobile device,

[0093] - a biometric factor, such as a fingerprint, facial recognition, retinal scan, iris scan, or voiceprint,

[0094] - Location-based factors, such as network connectivity or geographic location.

[0095] In fact, in this first "service" mode, the user's personal data 51 can be accessed via a web page 71 displayed on the terminal 30 and via the server 70. For this purpose, the user is invited to enter a code previously sent by the server 70 to an email address or telephone number entered or contained in the first database 50. This code makes it possible to verify that the user attempting to connect is indeed the user who has sent his or her personal data 51 and has handed over the watch product 10 to the organization. Advantageously, a new code is generated for each new session.

[0096] The concept of strong authentication is defined as consisting of access verification combined with different strategies and including multiple levels. One strategy can consist of various forms of testing (smart card, phone, email, etc.).

[0097] If the physical medium 20 is in the possession of another user while the management system is in "service" mode, then, due to this strong authentication, the other user will advantageously not be able to access the personal data 51 of the user of the watch product 10. In particular, the other user will not receive the code sent by the server 70 to the email address or phone number of the user of the watch product 10. Thus, the strong authentication of the user will fail.

[0098] In the second, "anonymous" mode, a session is opened on the user's terminal 30 using a web browser 32 to display a web page 71. The session is opened without strong authentication, but only after authentication of the access device 21 by the authentication device 40, since no information or personal data of the user is associated or accessible. In this mode, anyone in possession of the physical medium 20 or carrying it can open such a session. Indeed, in such a session, the user can only access the specific data 61 of the associated watch product 10, and access to personal data 51 is excluded.

[0099] Therefore, preferably, whatever the mode (“service” or “anonymous”), a session is only opened after the access device 21 has been authenticated by the authentication device 40 .

[0100] Preferably, regardless of the mode, if the procedure of connecting and opening a session has been successful, the web page 71 generated on the user terminal 30 can be used in steps S50 and S60 to display the second type of data 61, i.e., specific data 61 of the table product, for example:

[0101] - Table product model,

[0102] -Table product photos,

[0103] - Table product serial number,

[0104] - Warranty expiration date,

[0105] - performance measurement results,

[0106] -User manual, etc.

[0107] All of this data is advantageously anonymous. In particular, it is stored in the second database 60. Therefore, in the first mode S10 or the second mode S20, the user can preferably consult the second type of data 61. In particular, the second type of data 61 can be consulted without a password or a user account.

[0108] In the second "anonymous" mode, the physical medium 20 is sufficient to open a session on the browser 32 and consult the data located in the second database 60. This mode can be considered a mode without user authentication, because the owner of the physical medium 20 is not necessarily known and the medium may have been transferred or stolen from the user. Therefore, the consultation is anonymous.

[0109] Furthermore, in the first "Service" mode, after strong authentication of the user, web page 71 can display personal data 51, such as information about current services, service history, estimates, or invoices. Furthermore, also after strong authentication, a communication interface between the user and the organization that owns the watch product 10 can be generated on web page 71. For example, using this communication interface, the organization can submit estimates to the user. Advantageously, the user can interact with these estimates by accepting or rejecting them in full or in part. He or she can even leave comments or communicate directly with the organization by exchanging messages.

[0110] Preferably, only strictly necessary personal data 51 of the user may be accessed or viewed on the web page 71 .

[0111] It should be noted that in the first "service" mode, the user may receive a message from the organization (e.g. SMS or email) inviting him or her to connect in order to consult new notifications on the web page 71. Naturally, in order to open a new session on the browser 32 and access these notifications via the terminal 30, strong authentication is required.

[0112] To disconnect from the web page 71, i.e., to close the session, it is sufficient to close the web browser 32, regardless of the operating mode of the management system. Preferably, the session of the web page 71 is accessible to the user during a short, defined timeout period, which may last for several minutes or tens of minutes, without the need to execute a new program to connect or open the session. This ensures smooth browsing on the website 71 and avoids any inconvenience to the user due to untimely disconnection or temporary failure of the connection between the terminal and the server.

[0113] Advantageously, the same physical medium 20 may alternatively be configured to allow display of the web page 71 in a first "service" mode and in a second "anonymous" mode.

[0114] Because physical medium 20 is associated with serial number 11 of watch product 10 and because access device 21 is authenticated during the tapping process, physical medium 20 can further be used in a second, "anonymous" mode as a certificate proving the authenticity of watch product 10, particularly when it is sold or repaired by an organization. As previously mentioned, in "anonymous" mode, no personal data or history is accessible. Therefore, physical medium 20 can be transferred without any specific precautions and without risking compromising the protection of the personal data of previous users of watch product 10.

[0115] It should be noted that in the first "Service" mode S10, the watch product 10 is typically not in the hands of the user, but rather in the hands of the organization. Therefore, the watch product cannot be sold under these conditions. In order to be sold, the watch product must be acquired by the user, which inevitably results in the card being transferred to the "Anonymous" mode S20.

[0116] As an alternative to connection to a terminal provided with means 31 for communicating with or reading access device 21 , physical medium 20 may also be used for connection to another terminal not having means 31 for communicating with or reading access device 21 .

[0117] The procedure can then proceed as follows:

[0118] 1. First, open a dedicated web page in a web browser of another terminal and enter a specific item in the data 61 of the table product 10, such as the serial number 11. Then put the session into a standby state.

[0119] 2. To unlock the session, the user needs to tap the terminal 30 with the physical medium 20 associated with or corresponding to the serial number 11 previously entered on the other terminal. The terminal 30 then indicates to the user that the session is on standby on the other terminal and requests confirmation to open the session.

[0120] 3. Once unlocked, the web page on the session includes the same functions and interface as the web page 71 generated on the web browser of the terminal 30 or substantially the same functions and interface.

[0121] As previously mentioned, if the management system is in the first “service” mode S10 , strong authentication or multi-factor authentication is required to access personal data 51 .

[0122] Alternatively, instead of placing the session in a standby state at the end of the first step of the above procedure, an association request can be generated. To verify the association request, the user is required to tap the terminal 30 with the physical medium 20. The user must then enter the information of the association request displayed on the other terminal on the terminal 30. Once the association request is verified, the session is created and the web page 71 is generated.

[0123] Preferably, in any embodiment, the NFC chip can only be associated with a single watch product serial number. However, preferably, multiple NFC chips can be associated with the same serial number.

[0124] In any embodiment, the physical media may include, for example, printing or engraving that enables a user to identify the product associated with the media.

[0125] In any embodiment, the table product may in particular be:

[0126] - watches, especially wristwatches,

[0127] - watch strap,

[0128] -Watch movement.

[0129] In any embodiment, the physical medium 20 may include an access device 21 in addition to the NFC chip. The access device may in particular be:

[0130] - a QR code, for example printed on the physical medium 20, or

[0131] - a barcode, for example printed on the physical medium 20, or

[0132] - RFID tag, e.g. adhered to or embedded in a physical medium.

[0133] In the case of a QR code or barcode, the user only needs to scan the QR code or barcode with the terminal during the connection procedure, rather than performing a tap on the NFC chip 21. However, a QR code or barcode cannot be authenticated because it cannot benefit from cryptographic functions, such as the generation of dynamic variables, thereby achieving optimal security in connection with the web page dedicated to the watch product. In addition, unlike an NFC chip, or more specifically, unlike the NFC chip 21 according to the present invention, a QR code or barcode can be copied very easily, for example simply by taking a photo of it. As an alternative, other types of access devices can be used. In addition, the physical medium can include an access device 21, which includes, without limitation, any combination of the following elements and / or other suitable elements:

[0134] -NFC chip,

[0135] -QR code, or

[0136] - a barcode, or

[0137] -RFID tags.

[0138] The physical medium 20 may also be a medium other than a card, such as paper, any object, or a printed product.

[0139] As a variant, the system may also use means such as applications and / or technologies that are not integrated as standard in the terminal 30. These means need to be specifically added to the terminal 30 in order to be part of the data management system according to the invention.

[0140] The first database and the second database can be hosted on separate machines or in the same machine. Of course, even if the databases are hosted on the same machine, the association procedure remains as described above: the association between the user's data and the product's data is preferably only established temporarily when the user delivers his table product to the organization.

[0141] The solution according to the invention allows the method to be implemented using a smartphone, tablet or computer-type terminal, without having to install any specific application that could compromise the security of personal data. In fact:

[0142] - access to the web page 71 only requires an application that is integrated as standard in the terminal 30,

[0143] - reading the NFC device 31 or communicating with the NFC device 31 only requires functions integrated as standard in the terminal 30,

[0144] - More generally, the method only requires applications and functions that are integrated as standard in the terminal 30 .

[0145] Furthermore, viewing the web page 71 does not require the creation of a user account or account identifier which could also compromise the security of personal data.

[0146] Finally, the solution according to the invention does not allow tracking of personal data, or more specifically of the different owners of a table.

[0147] The proposed solutions leverage the advanced capabilities offered by mobile devices, such as smartphones, to help optimize the customer experience. Specifically, these solutions enable users to securely access a webpage dedicated to their watch on their mobile device through a unique access method that can be authenticated and associated with the watch product. This access method takes the form of an object provided by the retailer or the organization responsible for after-sales service operations. These solutions offer simplified and improved exchange and communication capabilities while strengthening the protection of users' personal data.

Claims

1. A method for managing data associated with a timepiece (10) belonging to a user, the data comprising: - data of a first type (51) comprising or consisting of personal data of the user, and - data of a second type (61) comprising or consisting of data specific to said timepiece, The method includes the following exclusive modes: - a first mode (S10) in which the user is able to consult data of the first type (51), and - a second mode (S20) in which the user cannot access data of the first type (51), The data can be accessed via a web page (71).

2. Management method according to the preceding claim, wherein: In the first mode (S10) or the second mode (S20), the user can view the second type of data (61).

3. A management method according to any preceding claim, wherein: The transition from the first mode (S10) to the second mode (S20) is performed by one of the following events: - actions of the data controller, - actions of the user, - Timed expiration.

4. A management method according to any preceding claim, wherein: The transition from the second mode (S20) to the first mode (S10) is performed by an action of a data manager.

5. A management method according to any preceding claim, wherein: The data of the first type (51) can be consulted by the user under strong authentication of the user or multi-factor authentication of the user, in particular using a code sent to the user and enabling connection to the web page (71).

6. A management method according to any preceding claim, wherein: The first type of data or the second type of data can be viewed by the user when the access device (21), in particular the NFC access device (22), is authenticated by the authentication device (40).

7. Management method according to the preceding claim, wherein: The access means are associated with at least one specific data item of the timepiece and / or the access means have a cryptographic function capable of generating a new URL to a new web page (71) each time it is used.

8. A management method according to any preceding claim, wherein: In both the first mode (S10) and the second mode (S20), the second type of data (61) can be viewed anonymously by the user without user authentication.

9. A management method according to any preceding claim, wherein: The first mode (S10) allows secure communication between the user and another authenticated person, in particular an administrator.

10. A management method according to any preceding claim, wherein: The method is implemented using a terminal (30) of the smartphone or tablet or computer type, on which only an application integrated as standard in the terminal (30) is required and / or no specific application needs to be installed and / or no user account and / or no user account identifier needs to be used.

11. A management method according to any preceding claim, wherein: When switching from the second mode (S20) to the first mode (S10), at least one item of the first type of data (51) is associated with at least one item of the second type of data (61), and when switching from the first mode (S10) to the second mode (S20), the first type of data (51) is not associated with the second type of data (61).

12. A system (100) for managing data associated with a timepiece (10) belonging to a user, the system comprising means (20, 30, 40, 50, 60, 70) for implementing the method according to any one of the preceding claims.

13. System according to the preceding claim, wherein The system comprises an NFC access device (21).

14. System according to the preceding claim, wherein The system comprises a device (31) capable of communicating with or reading the access device (21).

15. A computer program product which can be downloaded from a communication network and / or recorded on a computer-readable and / or computer-executable data carrier, wherein: The computer program product comprises instructions which, when the program is executed by the computer, cause the computer to carry out the method according to any one of claims 1 to 11. 16 . A computer-readable recording medium comprising instructions which, when executed by a computer, cause the computer to implement the method according to claim 1 .

17. A signal from a data carrier carrying a computer program product according to claim 15.