Authentication of a vehicle occupant for a financial transaction
The method uses an identity card with PIN or biometrics to authenticate vehicle occupants for secure payment authorization, eliminating complex authentication and minimizing data exposure, ensuring secure and convenient transactions.
Patent Information
- Application Number
- DE102024001374
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-04-27
- Publication Date
- 2025-11-20
- Estimated Expiration
- 2044-04-27
AI Technical Summary
Existing methods for vehicle-based electronic financial transactions require inconvenient and privacy-intrusive user authentication, such as video identification and multiple-factor authentication, which expose personal data and are cumbersome.
A method using a physical or virtual electronically readable identity card, authenticated with a PIN or biometrics, communicates with a vehicle reader to initiate a transaction, obtaining a security token from a central computer for secure payment authorization without additional user authentication steps.
Ensures secure and convenient payment authorization by minimizing data transmission and eliminating the need for complex authentication methods, ensuring the user's identity and legitimacy.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for executing an electronic financial transaction by a user as an occupant of a vehicle.
[0002] In electronic payment transactions, it is typically necessary for a user to identify themselves as an authenticated person in order to authorize the payment process. Methods for securely performing this verification using the features of a modern vehicle are known in the prior art.
[0003] DE 10 2022 002 474 B3 relates to a method for paying for goods and / or services by an authorized user of a mobile communication unit with a SIM or eSIM, wherein a user-related parameter set is transmitted to a mobile communication provider assigned to the SIM or eSIM and linked to the SIM or eSIM by the latter, after which the mobile communication provider sends a request to a payment service provider, which creates a virtual payment card or virtual payment token and transmits it to the mobile communication provider, after which the mobile communication provider links the virtual payment card or virtual payment token to the SIM or eSIM, wherein the mobile communication unit is integrated into a vehicle, and wherein the user-related parameter set is determined by a vehicle-external server of the vehicle manufacturer linked to the vehicle and transmitted to the mobile communication provider.Furthermore, a user-specific, vehicle-related parameter set is determined by the vehicle manufacturer's external server and transmitted to the mobile network operator, which also links this to the SIM or eSIM, whereby, when paying for goods and / or services, the parameter sets linked to the SIM or eSIM are compared with the corresponding parameter sets stored at the mobile network operator and / or on the vehicle manufacturer's external server in order to authenticate the user.
[0004] The mobile communication unit of DE 10 2022 002 474 B3 is considered an integral part of the vehicle and is therefore permanently connected to the vehicle's operating system and sensors. According to DE 10 2022 002 474 B3, this permanently installed SIM card / eSIM in the vehicle thus acts as the second factor in a two-factor authentication process to confirm the user's authenticity. For this process, participating payment service providers typically require mandatory personal authentication of the user during service registration in order to, for example, register a direct debit as a payment method. This mandatory authentication is problematic because it requires the user to access / install a web application or app of the payment service provider on their mobile device and to present an identification document (e.g., national identity card) containing all their personal data (eye color, height, ID number, etc.).The process involves recording / photographing one's own face using the camera on a mobile device. This procedure is often called "video identification." However, this raises data privacy concerns: personal data irrelevant to the process is disclosed, the secure storage of the data by the service provider is beyond the user's control, and the data stored there can be misused intentionally. Furthermore, the procedure can be inconvenient for the user, especially since care must be taken to cover the ID card with fingers, and specific lighting conditions are required for hologram recognition.
[0005] Other payment methods are known in the prior art, some of which use up to three factors for authentication. An example is US 2015 / 0058224A1, which concerns a method comprising: receiving a request for transaction account information from an external device at a vehicle interface; determining, by means of the vehicle interface device, that the vehicle interface device is located in a predetermined vehicle; determining, by means of the vehicle interface device, that a mobile communication device is located in the predetermined vehicle; and transmitting the transaction account information to the external device upon determining that the vehicle interface device and the mobile communication device are located in the predetermined vehicle.
[0006] US 2020 / 0 258 074 A1 further concerns a method for vehicle-based payments, wherein a vehicle-based payment system comprising a payment integration unit connected to a mobile electronic device includes: the payment integration unit that receives a confirmation request for a vehicle-based transaction from a third party; the payment integration unit that receives confirmation of the vehicle-based transaction from a vehicle user; the payment integration unit that transmits a payment token request from a financial institution backend to the mobile electronic device, wherein the mobile electronic device transmits the payment token request to the financial institution and receives a payment token from the financial institution; the payment integration unit that receives the payment token from the mobile electronic device;and the payment integration unit that communicates the payment token to the third party, the third party executing the transaction using the payment token.
[0007] The object of the invention is to improve the execution or initiation of an electronic financial transaction by a user in a vehicle.
[0008] The invention is defined by the features of the independent claims. Advantageous further developments and embodiments are the subject of the dependent claims.
[0009] A first aspect of the invention relates to a method for executing an electronic financial transaction by a user as an occupant of a vehicle, wherein the user uses a physical electronically readable identity card or a virtual electronically readable identity card displayed in a mobile device to identify and authenticate themselves to a reader in the vehicle, wherein identification of the vehicle preferably does not take place, wherein the reader connects to a central computer via the Internet and receives a security token from it after successful identification and authentication, which is transmitted together with payment data to a payment service provider, which then authorizes a financial transaction relating to the payment data and / or forwards data about it and / or initiates the payment.
[0010] Preferably, vehicle identification does not take place.
[0011] A prerequisite for successful implementation of the procedure is that the user has a physical identity card in the vehicle or a corresponding image of it on their mobile device, such as a smartphone. The image on the mobile device is created, for example, by reading a physical identity card into a so-called "Secure Element" of the mobile device. The function of the electronic identity card can then be used there via a so-called "wallet."
[0012] Furthermore, a reader must be provided in the vehicle which is capable of wirelessly communicating with the physical identity card or the mobile device with the identity card implemented therein, for example via RFID or NFC, or at least of reading this data.
[0013] The identity card, which transmits data to the reader, is used to identify the user. This identification means linking the card to an individual. However, the identity card could have been stolen by an unauthorized person, such as a car thief.
[0014] To ensure that the user is correctly identified, i.e., that the identity card was issued to them, authentication is necessary. This is done, for example, by entering a PIN at the reader or using biometric data such as a fingerprint scan or an iris scan.
[0015] The biometric data can be collected, for example, using an indoor camera or a camera on the mobile device.
[0016] This ensures, even while the vehicle is in operation, that the user is an authorized user and that any payment authorization is legitimate. To complete the transaction, the user also provides payment information, such as their credit card number and the security code stored on the card.
[0017] After successful user identification and authentication, the reader in the vehicle sends a request to a central computer for a security token, also known as an eID token. Once the security token is issued by the central computer, it is transmitted back to the vehicle. A processing unit in the vehicle, connected to the reader, can then transmit the payment data (in particular, the amount, recipient, and originating account or credit card to be charged) to a payment service provider and present the security token to demonstrate successful identification and authentication.For example, the payment service provider can use the security token to verify that the name and, if applicable, other data such as the date of birth and / or address of the user matches the personal data stored in relation to the user's account or credit card, and the payment can only be authorized if this data matches.
[0018] Instead of the payment service provider, another category of entity or organization may be involved. For example, the intended payment by the user may be transmitted to a government agency for monitoring private payment flows.
[0019] Advantageous features of the invention are that no video identification is required to confirm the user's identity. Nevertheless, a secure and reliable method for identifying and authenticating a user in a vehicle is provided to authorize a financial transaction. The amount of data to be transmitted is minimal.
[0020] Another significant advantage over current technologies is that the payment service provider can securely authorize the payment simply by receiving the payment data and the vehicle presenting the security token, without requiring further user authentication. The more complex two-factor or three-factor authentication methods used in current technologies are therefore unnecessary.
[0021] According to an advantageous embodiment, the payment data is entered by the user at an input interface of the vehicle.
[0022] According to a further advantageous embodiment, the payment data is entered by the user at an input interface of a mobile device, the mobile device communicating with a computing unit of the vehicle.
[0023] According to another advantageous embodiment, the authorization of the financial transaction takes place without any further authentication step for the user.
[0024] In particular, when the final transfer of data is carried out using the payment token as defined in DE 10 2022 002 474 B3, no explicit second factor for authentication is necessary; the use of the user's electronically readable identity card in conjunction with a first authentication step such as entering a PIN or biometric verification is sufficient to complete the procedure, in particular to authorize the financial transaction.
[0025] According to a further advantageous embodiment, the electronically readable identity card is read using RFID or NFC on the vehicle's reader.
[0026] According to another advantageous embodiment, the user identifies himself at the reader using the physical or virtual identity card and authenticates himself by entering a PIN.
[0027] According to a further advantageous embodiment, the user identifies himself at the reader using the physical or virtual identity card and authenticates himself using sensor-acquired biometric data.
[0028] According to another advantageous embodiment, the payment service provider transmits a confirmation data set to the vehicle after receiving the payment data and the security token.
[0029] According to a further advantageous embodiment, the confirmation data set is linked to a SIM card integrated into the vehicle, or to an eSIM module integrated into the vehicle, or to secure storage integrated into the vehicle, and is stored at least temporarily.
[0030] According to a further advantageous embodiment, in addition to the security token, a user-related parameter set is transmitted to the payment service provider, wherein the parameter set is linked to a SIM card integrated into the vehicle, or to an eSIM module integrated into the vehicle, or to a secure memory integrated into the vehicle.
[0031] Further advantages, features, and details will become apparent from the following description, in which – possibly with reference to the drawing – at least one embodiment is described in detail. Identical, similar, and / or functionally equivalent parts are identified by the same reference numerals.
[0032] They show: Fig. 1: A method for executing an electronic financial transaction according to an embodiment of the invention based on a physical identity card. Fig. 2: A method for executing an electronic financial transaction according to a further embodiment of the invention based on an electronically represented identity card.
[0033] Fig. Figure 1 shows a method for executing an electronic financial transaction by a user as an occupant of a vehicle 1, wherein the user uses a physical electronically readable identity card 3 or a virtual electronically readable identity card 3 displayed on a mobile device to identify and authenticate themselves at a reader 5 of the vehicle 1. In this exemplary situation, the user is sitting in the vehicle 1 and provides their electronically readable identity card 3, which they are carrying with them. They also recall their PIN associated with the electronic identity card 3. The user then starts the registration process in the vehicle 1 or on their mobile device, which has at least one application linked to the individual vehicle 1. For the recipient of a money transaction, they provide their payment data, such as...The user enters their current account data for a direct debit or their credit card data in vehicle 1 or on their mobile device at a designated interface. Vehicle 1 is equipped with a reader 5 for the electronically readable identity card 3 (e.g., via RFID or NFC). The user places their identity card 3 on the reader 5 or brings it close to it. The approach of the identity card 3 and the establishment of a communication interface in the so-called "physical layer" of the reader 5 (where no data exchange is yet possible) trigger the launch of a program signed by the issuing government agency of the identity card 3, which establishes communication with the identity card 3. A security chip verifies whether the program possesses the required signature and will only permit data access if such a signature is present.This program can run on a backend computer 7 and communicate with the card reader 5 in the vehicle 1 using end-to-end encryption. Alternatively, it can run directly within the telematics system in the vehicle 1 and communicate with the card reader from there using encryption. This program prompts the user to enter the PIN of their identity card 3 on the display in the vehicle 1. After entering this PIN, the user confirms, thereby granting the program access to the data stored in the electronic identity card 3. The program then establishes a data connection to a payment service provider 9, transmits the entered payment data, and retrieves the data fields from the payment service provider 9 that the provider requires for secure user authentication. The program then displays to the user on the vehicle 1 display which data is to be read from the identity card 3 and requests their consent.If the user agrees, the data is read, cryptographically encrypted end-to-end, and transmitted to payment service provider 9 for user authentication. After verifying the user's identity and comparing it with the entered payment data, payment service provider 9, if successful, issues a token as a confirmation record. This token attests to the user's authenticity and the (possibly time-limited) validity of the payment method. This token is then cryptographically encrypted end-to-end and transmitted via backend 7 to the SIM card or another so-called "secure element" in vehicle 1, where it is securely stored. This token can then be used for payment as described in DE 10 2022 002 474 B3, without requiring a second factor.
[0034] Fig. Figure 2 shows another method for executing an electronic financial transaction by a user as an occupant of a vehicle 1. In contrast to the embodiment of the Fig.In vehicle 1, the user does not use their physical, electronically readable identity card 3; rather, it is digitized and implemented as an electronically readable identity card 3 in software. They then recall the corresponding PIN or use another authentication method. The digital, electronically readable identity card 3 is thus stored on their mobile device and is specifically linked to a so-called "wallet" implemented on the mobile device. The user can then start the registration process in vehicle 1 or on their mobile device, which has a software-related connection to their individual vehicle 1, and subsequently enter their payment details (e.g., account reference data for direct debit or their credit card details) in vehicle 1 or on the mobile device. Vehicle 1 is connected to the mobile device via an end-to-end encrypted connection (e.g.,(via WLAN / UWB / RFID / NFC). The user then initiates the data release of the ID card data on their mobile device, for example, by releasing it to their wallet as described above. This triggers the launch of a program signed by the issuing (government) authority of the ID card 3, which establishes communication with the mobile device. A security chip verifies whether the program possesses the required signature and will only permit data access if such a signature is present. This program can run on a backend computer 7 and communicate with the card reader 5 in the vehicle 1 using end-to-end encryption, or it can run directly within the telematics system in the vehicle 1 itself and communicate with the card reader 5 from there using encryption.The program prompts the user to enter their ID card data access PIN on the display in vehicle 1 or on their mobile device. The user confirms this PIN, thereby granting the program access to the data in the mobile device's wallet. The program then establishes a data connection to payment service provider 9, transmits the entered payment data, and retrieves the data fields required by payment service provider 9 for secure customer authentication. A display on the vehicle screen shows the user which data from the ID card 3 is to be read and requests their consent. If the user agrees, the data is read from the wallet on the mobile device and transmitted to payment service provider 9 for customer authentication using secure end-to-end encryption.After verifying the customer's identity and comparing it with the entered payment data, the payment service provider 9 issues a token as a confirmation record, if successful. This token attests to the customer's authenticity and the (possibly time-limited) validity of the payment method. This token is then securely encrypted end-to-end and transmitted via backend 7 to the SIM card or another secure element in vehicle 1, where it is stored securely. This token can then be used for payment as described in DE 10 2022 002 474 B3, without requiring a second factor.
[0035] Although the invention has been further illustrated and explained in detail by means of preferred embodiments, the invention is not limited by the disclosed examples, and other variations can be derived from them by a person skilled in the art without departing from the scope of protection of the invention. It is therefore clear that a multitude of possible variations exist. It is also clear that the embodiments mentioned as examples are truly only examples and are not to be understood in any way as limiting, for example, the scope of protection, the possible applications, or the configuration of the invention.Rather, the preceding description and the description of the figures enable the person skilled in the art to implement the exemplary embodiments in concrete terms, whereby the person skilled in the art, with knowledge of the disclosed inventive concept, can make various changes, for example with regard to the function or the arrangement of individual elements mentioned in an exemplary embodiment, without leaving the scope of protection defined by the claims and their legal equivalents, such as further explanations in the description. Reference symbol list 1 vehicle 3. Identity card 5 Reader 7 Central computers 9 Payment service providers
Claims
[1] Method for carrying out an electronic financial transaction by a user as an occupant of a vehicle (1), wherein the user uses a physical electronically readable identity card (3) or a virtual electronically readable identity card (3) displayed in a mobile device to identify and authenticate himself to a reader (5) of the vehicle (1), wherein the reader (5) connects to a central computer (7) via the Internet and receives a security token from it after successful identification and authentication, which is transmitted together with payment data to a payment service provider (9), which authorizes a financial transaction relating to the payment data and / or transmits data about it and / or initiates the payment. [2] Method according to claim 1, wherein the payment data is entered by the user at an input interface of the vehicle (1). [3] Method according to claim 1, wherein the payment data is entered by the user at an input interface of a mobile device, the mobile device communicating with a computing unit of the vehicle (1). [4] Method according to any of the preceding claims, wherein the authorization of the financial transaction takes place without any further authentication step for the user. [5] Method according to one of the preceding claims, wherein the electronically readable identity card (3) is read by means of RFID or NFC on the reader (5) of the vehicle (1). [6] Method according to one of the preceding claims, wherein the user identifies himself at the reading device (5) by means of the physical or virtual identity card (3) and authenticates himself by means of a PIN entry. [7] Method according to one of the preceding claims, wherein the user identifies himself at the reading device (5) by means of the physical or virtual identity card (3) and is authenticated by means of sensorially acquired biometric data. [8] Method according to any of the preceding claims, wherein the payment service provider (9) transmits a confirmation data set to the vehicle (1) after receiving the payment data and the security token. [9] Method according to claim 8, wherein the confirmation data set is coupled to a SIM card integrated into the vehicle (1) or to an eSIM module integrated into the vehicle (1) or to a secure storage device integrated into the vehicle (1) and is stored at least temporarily. [10] Method according to one of the preceding claims, wherein in addition to the security token a user-related parameter set is transmitted to the payment service provider (9), wherein the parameter set is coupled to a SIM card integrated into the vehicle (1) or to an eSIM module integrated into the vehicle (1) or to a secure memory integrated into the vehicle (1).
Citation Information
Patent Citations
Methods for paying for goods and / or services
DE102022002474B3
Mechanism For Secure In-Vehicle Payment Transaction
US20150058224A1
Electronic device including electronic payment system and operating method thereof
US20160253651A1
System and method for implementing vehicle-based payment tokenization
US20200258074A1
System for value loading onto in-vehicle device
US20210019731A1