METHOD FOR PERFORMING A TRANSACTION BETWEEN A DEVICE AND A MOBILE PHONE
Patent Information
- Application Number
- DE602016094347
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2015-05-19
- Filing Date
- 2016-05-19
- Publication Date
- 2025-12-17
- Estimated Expiration
- 2036-05-19
AI Technical Summary
Existing mobile phone transactions with point-of-sale devices lack security, allowing for the possibility of counterfeit or duplicated proof of purchase, necessitating a more secure method for product purchase.
A method involving a mobile phone and a point-of-sale device that utilizes radio frequency communication, unique identifiers, and cryptographic signatures to authenticate and verify proof of purchase, ensuring secure transactions.
The method provides secure and reliable transactions by preventing counterfeiting and duplication of proof of purchase, functioning even in the absence of a wireless network connection.
Description
[0001] The present invention relates to a method for conducting a transaction between a mobile phone and a point-of-sale device. The invention also relates to a method for verifying proof of purchase generated during such a sale. Furthermore, the invention relates to a method for purchasing a product from a point-of-sale device using a mobile phone. The invention also relates to computer software products associated with the above methods. The invention also relates to a point-of-sale device.
[0002] A mobile phone is frequently equipped with an information processing unit capable of performing functions other than just telephone communication. For example, the information processing unit is designed to run electronic games or to store video files.
[0003] It is known, in particular, to use the information processing unit of a mobile phone to store proof of purchase for a travel ticket. For example, the ticket is purchased from a centralized server via the internet and then transmitted to the mobile phone through the mobile network to which the phone belongs. To allow for authentication of the ticket, proof of purchase is displayed on the phone's screen, for example, as a matrix code.
[0004] Each of the documents WO 2010 / 065896 A1, WO2015 / 059389 A1 describes a sales or purchase process implemented by two devices.
[0005] A mobile phone often also includes a telephone communication module and at least one module enabling short-range communication with other electronic devices. Such short-range communication modules are used, for example, to transfer data from one phone to another in electronic games, or to enable the use of wireless headsets.
[0006] Short-range wireless communication modules are generally based on the use of radio frequency electromagnetic waves. Radio frequency electromagnetic waves, also called radio waves, are electromagnetic waves with a frequency between 3 kilohertz (kHz) and 3 gigahertz (GHz).
[0007] The distance over which a radio frequency electromagnetic wave propagates depends on the wave's frequency. For example, the frequency band from 2400 to 2483 MegaHertz (MHz) is used by communication modules based on the Bluetooth protocol, whose range is generally a few tens of meters.
[0008] Short-range communication modules of the type described above are sometimes integrated into fixed installations such as product display shelves, allowing, for example, a user to receive information about a product for sale on their phone. Sales kiosks equipped with short-range communication modules also allow customers to purchase products using a mobile phone.
[0009] However, the transactions offered are not secure, as it is possible to counterfeit or duplicate the proof of purchase received by the mobile phone.
[0010] There is therefore a need for a more secure method of carrying out a transaction, in particular a method allowing the purchase of a product, using a mobile phone, from a sales device.
[0011] To this end, a method is proposed according to claim 1.
[0012] According to a particular embodiment, the process is according to any one of claims 2 to 5.
[0013] Also proposed is a computer program product according to claim 6, the computer program product comprising software instructions which, when executed by a controller, implement a process as described above.
[0014] The features and advantages of the invention will become apparent from the following description, given solely by way of non-limiting example, and made with reference to the accompanying drawings, in which: therefigure 1 is a schematic representation of a sales installation, a mobile phone and a control device, the figure 2 is a flowchart of an example of the implementation of a process for carrying out a transaction, and the figure 3 is a flowchart of an example of the implementation of a control process.
[0015] A phone 6, a first computer program product 8 and an installation 10 are represented on the figure 1 .
[0016] Phone 6 is designed to allow a user U of phone 6 to purchase a product P at installation 10.
[0017] Product P is, for example, a right to use a means of transport.
[0018] In another example, product P is an object such as a piece of furniture that user U is invited to pick up from a store or warehouse.
[0019] Phone 6 is a mobile phone. This means that phone 6 is suitable for being carried by user U and for exchanging telephony data Dt with another phone 6 through a wireless telephony network R.
[0020] Preferably, telephone 6 is suitable for exchanging telephony data Dt across the network R by radio frequency communication.
[0021] The term "radio frequency communication" refers to the exchange of data via a signal containing at least one radio frequency electromagnetic wave (EMW).
[0022] Dt telephony data is suitable for enabling the reproduction of human speech by a telephone.
[0023] The telephone 6 includes a transmit / receive module 15, a first controller 20 and a human / machine interface 25.
[0024] The transmit / receive module 15 is a radio frequency communication module. This means that the transmit / receive module 15 is capable of transmitting or receiving data transmitted via a signal containing at least one radio frequency electromagnetic wave (OEM).
[0025] Preferably, the transmitting / receiving module 15 is suitable for transmitting and receiving data transmitted via a signal comprising at least one radio frequency electromagnetic wave OEM.
[0026] Radio frequency electromagnetic waves (RFE) are electromagnetic waves with a frequency between 3 Kilohertz (KHz) and 3 Gigahertz (GHz).
[0027] The transmitting / receiving module 15 includes a first antenna 30.
[0028] The transmitting / receiving module 15 is, for example, suitable for transmitting or receiving an OEM electromagnetic wave with a frequency greater than or equal to 2400 MegaHertz (MHz) and less than or equal to 2483.5 MHz.
[0029] Preferably, the transmitting / receiving module 15 is suitable for transmitting and receiving an OEM electromagnetic wave having a frequency greater than or equal to 2400 MegaHertz (MHz) and less than or equal to 2483.5 MHz.
[0030] Advantageously, the 15 transmit / receive module uses a Bluetooth communication protocol. Bluetooth is a communication standard that enables bidirectional data exchange over very short distances. The standards defining Bluetooth protocols are defined by the Bluetooth Special Interest Group.
[0031] Alternatively, the transmitting / receiving module 15 is suitable for transmitting or receiving an electromagnetic wave with a frequency greater than or equal to 13.553 MHz, and less than or equal to 13.567 MHz.
[0032] Preferably, the transmitting / receiving module 15 is suitable for transmitting and receiving an electromagnetic wave with a frequency greater than or equal to 13.553 MHz, and less than or equal to 13.567 MHz.
[0033] Advantageously, the 15 transmit / receive module uses a Near-Field Communication (NFC) protocol. Near-field communication is a short-range, high-frequency wireless communication technology that allows information exchange between devices up to a distance of approximately 10 centimeters (cm). NFC technology is an extension of the ISO / IEC 14443 standard.
[0034] The first controller 20 is suitable for manipulating and / or transforming data represented as electronic or physical quantities in registers of the first controller 20 and / or in memories into other similar data corresponding to physical data in memories, registers or other types of display, transmission or storage devices.
[0035] The first controller 20 is also capable of exchanging data with the first communication module 15 and the human / machine interface 25.
[0036] The first controller 20 is also configured to transmit data to a server (not shown) via the R wireless telephony network.
[0037] The first controller 20 includes a first memory 40.
[0038] The first memory 40 is specifically designed to store an identifier I of the phone 6.
[0039] The identifier I is unique to identifying phone 6. This means that the identifier I is associated with a unique phone 6.
[0040] For example, identifier I includes a serial number of phone 6.
[0041] Advantageously, identifier I includes an IMEI number (from the English "International Mobile Equipment Identity") of the phone 6. The IMEI number is a unique number assigned to a unique phone 6, and used by telephone operators to identify and to authorize or not the phone 6 to connect.
[0042] The IMEI number is directly associated with the phone 6 and not with the user U. The IMEI number is used in particular to block a stolen phone with all operators who have subscribed to the IMEI database.
[0043] Preferably, the identifier I is an identifier provided to the telephone 6 by an operator of the facility 10 following payment of a predefined sum, named amount to pay Mp, by the user U.
[0044] The first computer program product 8 includes program instructions.
[0045] The first computer program 8 is loadable on the first controller 20 and is adapted to drive the implementation of a purchase process for product P when the first computer program 8 is executed on the first controller 20.
[0046] Installation 10 is a sales installation. Installation 10 is designed to ensure the sale of product P to user U and to verify the purchase of product P by user U.
[0047] Installation 10 includes a sales device 45, a second computer program product 50, a centralizing device 55, a third computer program product, a control device 65 and a fourth computer program product 67.
[0048] The sales device 45 is configured to sell product P to user U of phone 6.
[0049] The sales unit 45 is fixed. This means that the sales unit 45 cannot be moved by the user U.
[0050] For example, the sales device 45 is fixed inside a public transport vehicle such as a bus or tram. For example, the sales device is fixed to the floor of the vehicle.
[0051] Alternatively, the sales unit 45 is fixed to a wall. For example, the sales unit 45 is sealed into the wall.
[0052] The sales device 45 is an automated machine.
[0053] The term "automated system" refers to a multi-service electromechanical device, such as a multi-service electromechanical ticketing system for public transportation. For example, ticket vending machine 45 is designed to validate a transportation ticket.
[0054] According to the invention, the sales device 45 is a parking management device.
[0055] This means that the sales device 45 is also configured to sell a parking ticket to user U. For example, the parking ticket is a printed ticket. Alternatively, the parking ticket is a computer file that can be stored in the memory 40 of the phone 6.
[0056] A time clock is a specific example of an automaton.
[0057] The sales device 45 includes a first transmission module 70, a second human / machine interface 72, a second controller 75 and a body 77.
[0058] The first transmission module 70 includes an antenna 80.
[0059] The first transmission module 70 is designed to exchange information with the transmitting / receiving module 15. Preferably, the first transmission module 70 is a radio frequency communication module.
[0060] The second human / machine interface 72 is configured to allow a user U of the sales device 45 to exchange information with the second controller 75.
[0061] The second human-machine interface 72 includes, for example, a touch screen.
[0062] The second controller 75 is designed to exchange information with the centralization device 55.
[0063] For example, the second controller 75 is connected to the centralizing device 55 via a wired connection such as an Ethernet link. Ethernet is a family of network protocols defined by the IEEE 802.3 standard.
[0064] Alternatively, the second controller 75 is connected to the centralizing device 55 by a wireless link such as a radio frequency link.
[0065] The second controller 75 includes a second memory 85.
[0066] The second memory 85 includes a first list L1 of identifiers I.
[0067] Advantageously, each identifier I in the first list L1 is associated with a user U who has registered with the operator of the installation 10.
[0068] The second computer program product 50 includes program instructions.
[0069] The second computer program 50 is loadable on the second controller 75 and is adapted to drive the implementation of a transaction execution process when the second computer program 50 is implemented on the second processor 82.
[0070] The second controller 75 and the first transmission module 70 are arranged inside the body 77. The body 77 is then suitable for isolating the second controller 75 and the first transmission module 70 from the outside of the sales device 45.
[0071] The centralization device 55 is designed to exchange data with the sales device 45.
[0072] The centralizing device 55 is an electronic device. This means that the centralizing device 55 includes at least one module capable of receiving, modifying, or transmitting information in the form of electrical signals. For example, the centralizing device 55 is a computer server.
[0073] The centralizing device 55 is remote from the sales device 45. This means that the centralizing device 55 is not included in the body 77 of the sales device 45.
[0074] The centralization device 55 includes a third controller 90.
[0075] The third controller 90 is designed to exchange information with the second controller 75. Preferably, the third controller 90 is configured to exchange information with each second controller 75 of a plurality of sales devices 45.
[0076] The third controller 90 includes a third memory 95.
[0077] The third memory 95 includes a first table T1 comprising at least one identifier I and information IU about the user U.
[0078] Preferably, the first table T1 includes a plurality of identifiers I.
[0079] Each identifier I in the first table T1 is associated with a unique user U. The identifier I of phone 6 is associated with user U.
[0080] User UI information includes, for example, the user's name, a billing address and / or a bank account number.
[0081] The third controller 90 is, for example, suitable for recording the payment of a predefined sum by the user U and for providing in response the identifier I to the mobile phone 6. For example, the third controller 90 is suitable for transmitting, by radio frequency communication, a payment certificate including at least the identifier I to the mobile phone 6. The third computer program product includes program instructions.
[0082] The third computer program can be loaded onto the third controller 90 and is adapted to trigger the implementation of a transaction execution process when the second computer program is implemented on the third controller 90.
[0083] The control device 65 is configured to control the purchase by user U of the mobile phone 6 of product P, and to communicate the results of the control to a user U.
[0084] The control device 65 is preferably a mobile electronic device. For example, the control device 65 is a mobile phone. Alternatively, the control device 65 is a dedicated electronic device.
[0085] The control unit 65 includes a fourth controller 100, a second transmission module 105 and a third human / machine interface 110.
[0086] The fourth controller 100 is designed to exchange information with the second transmission module 105 and the third human / machine interface 110.
[0087] The fourth controller 100 has a fourth memory 112.
[0088] The second transmission module 105 includes an antenna 115.
[0089] The second transmission module 105 is designed to exchange information with the transmitting / receiving module 15. Preferably, the second transmission module 105 is a radio frequency communication module.
[0090] The third human / machine interface 110 is configured to allow a user U of the control device 65 to exchange information with the fourth controller 100.
[0091] The third human / machine interface 110 includes, for example, a touch screen and a speaker.
[0092] The fourth computer program product 67 includes program instructions.
[0093] The fourth computer program 67 is loadable on the fourth controller 100 and is adapted to drive the implementation of a process for controlling the purchase of a product P by the user U when the fourth computer program 67 is implemented on the fourth controller 100.
[0094] The operation of installation 8 will now be described.
[0095] There figure 2 presents the steps in a process for carrying out a transaction between the sales device 45 and the telephone 6.
[0096] The term "transaction" refers to the sale of product P, that is, the provision of product P to user U in exchange for the payment of an amount payable Mp.
[0097] The process of carrying out a transaction includes a step 200 of transmitting an identifier I, a step 210 of identification, a step 220 of calculation, a step 230 of generating a proof of purchase PA, a step 240 of transmitting a proof of purchase PA, a step 250 of memorization, a step 260 of generating a witness T, a step 270 of communicating the witness T, and a step 280 of generating an invoice F.
[0098] Steps 210 identification, 220 calculation, 230 generation of proof of purchase PA, 260 generation of witness T and 270 transmission of witness T are implemented by the sales device 45.
[0099] Step 200 of transmitting identifier I and step 240 of transmitting proof of purchase PA are implemented jointly by sales device 45 and telephone 6.
[0100] Step 250 of memorization is implemented by phone 6.
[0101] When step 200 of transmitting identifier I, step 240 of transmitting proof of purchase PA and step 250 of memorization are implemented by the telephone 6, step 200 of transmitting identifier I, step 240 of transmitting proof of purchase PA and step 250 of memorization form a purchase process, by the telephone 6, of product P to the sales device 45.
[0102] Proof of purchase PA is suitable for demonstrating, during a control operation, the purchase of product P by user U of phone 6.
[0103] The PA proof of purchase is a computer file, that is to say a set of information designed to be stored by a memory 40.
[0104] The proof of purchase PA includes data D describing the product P purchased and a signature S.
[0105] The description data D is specific to identifying the product P purchased by the user U of phone 6.
[0106] For example, the description data D is associated with a single product P. Alternatively, the description data D is associated with a set of products P that are indistinguishable from each other.
[0107] The descriptive data D includes, for example, a set of product characteristics P.
[0108] When product P is a piece of furniture, the description data D includes the name, dimension, and color of product P.
[0109] When product P is a right to use a transport network, proof of purchase PA is a transport ticket.
[0110] This means that, during a ticket inspection, user U is considered authorized to use the transport network if they possess proof of purchase (PA). If user U does not possess proof of purchase (PA), they are considered not authorized to use the transport network.
[0111] For a ticket to have contractual value, it must have been paid for and validated (or stamped) by a device that finalizes the sale of the ticket. Validation is carried out, for example, by inserting the signature "S" into the proof of purchase (PA).
[0112] Description data D includes, for example, a start time of validity of the transport ticket, an end time of validity of the transport ticket, the name of a departure station and / or the name of an arrival station.
[0113] Optionally, the description data D includes a product identifier P such as a serial number.
[0114] According to another example, the memory 112 of the control device 65 has a hash table Tab comprising features of a plurality of products P, and the description data D are suitable for indicating the position of the features of product P in the hash table Tab.
[0115] For example, the description data D is suitable for enabling the control device 65 to calculate, according to a hash function H, an index i identifying the position of the characteristics of the product P in the hash table Tab.
[0116] The signature S is a specific data set used to authenticate the PA proof of purchase. This means that the signature S allows the control device 65 to verify that the PA proof of purchase was generated by the sales device 45.
[0117] For example, the signature S is a decimal number randomly generated each day and stored in the second memory 85.
[0118] Preferably, the S signature is also unique to identifying the phone 6. This means that the S signature is associated with a unique phone 6.
[0119] For example, when the identifier I is a number, the signature S includes a number calculated from the identifier I according to a first mathematical function F1.
[0120] The first function F1 preferably has a reciprocal function F2 associating the identifier I with the signature S.
[0121] Alternatively, the signature S is the result of encrypting at least the identifier I according to an encryption algorithm A.
[0122] Encryption algorithm A has an encryption key K.
[0123] The encryption algorithm is, for example, the "Advanced Encryption Standard" (also known as "Rijndael" or "AES"). The AES algorithm is defined in the ISO / IEC 18033-3 standard.
[0124] According to another variant, a second L2 list of identifiers is stored in memory 112 of the control device and the signature S includes information identifying the position of the identifier I of the phone 6 in the second L2 list.
[0125] For example, the signature S is specific to enabling the control device 65 to calculate, according to the hash function H, an index j identifying the position of the identifier I of the phone 6 in the second list L2.
[0126] During step 200 of the transmission of identifier I, a first message M1 is generated by the telephone 6 and sent by the transmit / receive module 15 to the first transmission module 70.
[0127] The first message M1 is transmitted to the first transmission module 70 by radio frequency communication.
[0128] The first message M1 includes the identifier I of phone 6. In a case where a payment certificate has been transmitted to phone 6, the first message M1 includes, for example, the payment certificate.
[0129] At the end of step 200 of transmission of identifier I, the sales device 45 received identifier I.
[0130] At identification step 210, phone 6 is identified. This means that at the end of identification step 210, the sales device 45 has determined whether or not the user U of phone 6 is registered with the operator of the facility 10.
[0131] The identifier I received by the sales device 45 is compared to each of the identifiers I from the first list L1.
[0132] If the received identifier I is not included in the first list L1, an error message ME is displayed on the screen of the second human / machine interface 72 and the process of carrying out a transaction is interrupted.
[0133] If the received identifier I is included in the first list L1, the identification step 210 is followed by the calculation step 220.
[0134] During step 220 of the calculation, the signature S is calculated.
[0135] At generation step 230, the PA proof of purchase is generated.
[0136] For example, the payment certificate includes all or part of the description data D, and the PA proof of purchase is generated from the certificate. Specifically, generating the PA proof of purchase involves inserting the signature S into the payment certificate to form the PA proof of purchase.
[0137] At step 240 of transmission, the first transmission module 70 sends a second message M2 to the transmitting / receiving module 15.
[0138] The second message M2 contains the PA purchase proof.
[0139] The second message M2 is transmitted to the transmit / receive module 15 by radio frequency communication.
[0140] The PA proof of purchase is stored in the first memory 40 during the memorization step 250.
[0141] Steps 200 of transmission of an identifier I, 210 of identification, 220 of calculation, 230 of generation of a proof of purchase PA, 240 of transmission of a proof of purchase PA and 250 of memorization therefore allow the sale of a right of use of a transport network to be finalized, since the payment certificate is validated by the sales device 45 by insertion of the signature S to then form a valid transport ticket.
[0142] At generation step 260, a witness T of the sale is generated.
[0143] Witness T is a data set comprising information relating to the sale, by the sales device 45, of the product P to the user U. Witness T is specific to enabling the centralization device 55 to generate an invoice F.
[0144] Witness T includes, for example, an amount to be paid Mp and the identifier I. Alternatively, witness T includes, in addition, the description data D and / or the signature S.
[0145] As a result of step 260 of generating the witness T, a third message M3 is issued by the second controller 75 to the third controller 90, during step 270 of transmission.
[0146] The third message M3 includes the witness T.
[0147] Witness T is stored in a third witness list L3. The third list L3 is stored in the third memory 95.
[0148] At the end of communication step 270, witness T was therefore communicated by the sales device 45 to the centralization device 55.
[0149] Finally, at billing step 280, the centralization device 55 generates an invoice F from the witness T. Preferably, the centralization device 55 generates the invoice F from all the witnesses T including the same identifier I.
[0150] Invoice F is a set of data transmitted to user U and intended to order payment, by user U, of the amount to be paid Mp, if this payment has not already taken place.
[0151] For example, invoice F includes the amount to pay Mp and the description data D.
[0152] Invoice F is generated at a fixed frequency, for example, monthly. This means that only one invoice F is generated each month, and that invoice F includes the amounts payable Mp for each purchase made by user U since the issuance of the previous invoice F.
[0153] Alternatively, invoice F is generated during each implementation of the transaction execution process.
[0154] Invoice F is transmitted to user U via the Internet network.
[0155] At the end of steps 200 to 280 above, the telephone 10 received a proof of purchase PA from the sales device 45, and the centralization device 20 generated an invoice F in return. Steps 200 to 280 above therefore constitute a process for carrying out a transaction.
[0156] There figure 3 presents the steps of an example process for verifying PA proof of purchase.
[0157] The control process includes a step 300 of carrying out a transaction, a step 310 of transfer and a step 320 of authentication of the PA proof of purchase.
[0158] At step 300 of transaction execution, the transaction execution process as described above is implemented.
[0159] At the end of step 300 of completing a transaction, the proof of purchase PA was generated by the sales device 45 and stored in the memory 40 of the phone 6.
[0160] At transfer step 310, the transmit / receive module 15 sends a fourth message M4 to the second transmit module 105.
[0161] The fourth M4 message includes the PA proof of purchase and the I identifier.
[0162] At the end of transfer step 310, the PA proof of purchase and the identifier I were transmitted from phone 6 to control device 65.
[0163] At authentication step 320, the signature S is authenticated by the control device 65.
[0164] This means that the fourth controller 100 checks that the signature S has a characteristic expected by the fourth controller 100 and generates an authenticity signal Sa depending on the presence or absence of the expected characteristic.
[0165] For example, when the signature S is a number associated with a particular day, the signature S is compared to a reference signature Sr stored in the fourth memory 112. The reference signature Sr is equal to the signature S stored in the second memory 85.
[0166] Alternatively, the fourth controller 100 performs at least one operation from the signature S, and compares the result of the operation to an expected result.
[0167] For example, the signature S is a number and the expected characteristic is the value of the sum of the digits of the signature S. The fourth controller 100 calculates the sum of the digits of the signature S and compares it to a reference value Vr stored in the fourth memory 112.
[0168] Preferably, authentication step 320 includes a substep 325 for calculating an identifier Ic and a substep 330 for comparison.
[0169] In substep 325 of calculation, an identifier Ic is calculated from the signature S.
[0170] When the signature S is a number calculated according to the first function F1 from the identifier I of the phone 6, the calculated identifier Ic is calculated from the second function F2.
[0171] When the signature S is the result of the encryption of the identifier I, the encryption key K is stored in memory 112 of the control device 65, and the identifier Ic is calculated according to the encryption algorithm A.
[0172] According to a second variant, the control device 65 calculates an index i according to the hash function H, and the calculated identifier Ic is set equal to the identifier I located in the second list L2 by the calculated index i.
[0173] Then, during a comparison step 330, the identifier Ic calculated from the signature S is compared to the identifier I included in the fourth message M4.
[0174] The definition data D are, in addition, compared to reference data Dr stored in the fourth memory 112.
[0175] In the case where the proof of purchase PA is a transport ticket, the reference data Dr are, for example, identical to the definition data D corresponding to a journey in progress on a train on which the control device 25 is on board.
[0176] If the calculated identifier Ic is identical to the received identifier I, and the definition data D is identical to the reference data Dr, a conformity signal Sc is emitted by the third human / machine interface 110.
[0177] The Sc conformity signal is designed to assure a user of the control device 65 of the authenticity of the PA proof of purchase. The Sc conformity signal includes, for example, an audible signal.
[0178] Otherwise, a non-conformity signal Sn is emitted by the third human / machine interface 110. The non-conformity signal Sn takes, for example, the form of a sound signal different from the conformity signal Sc.
[0179] The generation of the signature S by the sales device 45 allows for easy verification of the authenticity of the proof of purchase PA. Counterfeiting the proof of purchase PA therefore requires knowledge of the method used to calculate the signature S.
[0180] In particular, since the signature S is generated from the identifier I, the control device 65 can compare the identifier I of the phone 6 and the identifier Ic calculated from the proof of purchase PA.
[0181] The duplication of the proof of purchase PA and its transfer to another phone 6 are therefore easily detectable by the control device 65. The process of carrying out a transaction is therefore secure.
[0182] Furthermore, the transaction execution process does not involve data transfer over the wireless telephone network. Therefore, the process can be implemented by a phone 6 that is not connected to the mobile telephone network R. In particular, the transaction execution process can be implemented even in the event of a failure or saturation of the wireless telephone network R.
[0183] The process of carrying out a transaction is therefore reliable.
[0184] A second example of installation 10 will now be described. The elements are identical to the first example of the figure 1 are not described again. Only the differences are highlighted.
[0185] The second message M2 includes the witness T.
[0186] The third controller 90 is also capable of receiving the third message M3 via the wireless telephony network R.
[0187] The third message M3 is generated by the first controller 20.
[0188] During communication step 270, the telephone 6 transmits the third message M3 to the centralizing device 55 via the wireless telephone network R.
[0189] In particular, the third message M3 is transmitted via the wireless telephone network R if the wired link between the sales device 45 and the centralizing device 55 is damaged.
[0190] The process of carrying out a transaction is then more robust.
Claims
1. A verification method for verifying the purchase of a product (P) by a mobile phone (6), the method comprising a step of: i) carrying out a method for performing a transaction between a mobile phone (6) and a parking management apparatus, the parking management apparatus being configured to sell the product, the product being a parking ticket, the phone (6) comprising a first memory (40) for storing an identifier (I), the identifier (I) being unique to the mobile phone (6), the method for performing a transaction comprising the steps of: a) reception of the identifier (I) by radiofrequency communication via the parking management apparatus, b) identification of the mobile telephone (6) by the parking management apparatus from the identifier (I) received during the reception step, and c) generation by the parking management apparatus of a proof of purchase (PA) comprising a signature (S) computed by the parking management apparatus and able to authenticate the proof of purchase (PA), and d) sending of the proof of purchase (PA) from the parking management apparatus to the mobile phone (6) by radiofrequency communication, the verification method comprising the steps of: ii) transfer of the proof of purchase (PA) from the mobile phone (6) to a verification apparatus (65) by radiofrequency communication; and iii) authentication, by the verification apparatus (65), of the signature (8) of the proof of purchase (PA).
2. The verification method according to claim 1, wherein the signature (S) is computed by the parking management apparatus from at least the received identifier (I).
3. The verification method according to claim 1 or 2, wherein the radiofrequency communications have at least one frequency greater than or equal to 2400 MegaHertz (MHz) and less than or equal to 2483.5 MHz.
4. The verification method according to any one of claims 1 to 3, wherein the method further comprises following steps: e) generation, by the parking management apparatus, of a cookie (T) for the sale, f) communication, by the parking management apparatus, of the cookie (T) to a remote electronic device (55), and h) generation, by the remote device (55), of a bill (F) from at least the received cookie (T).
5. The verification method according to claim 1, taken with claim 2, the method further comprising the steps of: iv) transfer of the identifier (I) from the mobile telephone (6) to the verification apparatus (65), and v) computation, by the verification apparatus (65), of an identifier (Ic) computed from the signature (S), the authentication step iii) comprising a comparison of the computed identifier (Ic) and the received identifier (I).
6. A computer program product (8, 50, 67) comprising software instructions which, when implemented by a controller (20, 75, 90, 100), carry out a method according to any one of claims 1 to 5.