Method for certifying a mobile terminal for the implementation of a payment application on the mobile terminal
Patent Information
- Application Number
- EP2023837709
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-22
- Filing Date
- 2023-12-22
- Publication Date
- 2025-10-29
AI Technical Summary
Current methods for attesting mobile terminals to ensure they meet security criteria for payment applications are resource-intensive and time-consuming, consuming significant processing power and vulnerable to 'man in the middle' attacks due to the transfer of bulk information.
A method where a server randomly selects a restricted number of attestation requests from a large set, using encryption keys to establish a trusted communication channel, reducing the amount of data transferred and making it difficult for attackers to fraudulently determine responses, by breaking down the attestation process into smaller, less computationally demanding steps.
This approach reduces processing power requirements, limits data transfer time, and enhances security by establishing a trusted communication channel that protects against attacks, making the attestation process more efficient and secure.
Smart Images

Figure 1.1
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Method of attesting a mobile terminal for the implementation of a payment application on the mobile terminal.
[0003] The present invention relates to the field of payment applications, and in particular to software applications configured to transform a commercial mobile terminal intended for the general public into a payment terminal.
[0004] It is known to use a software application to transform a commercial mobile terminal intended for non-professional customers, for example a smartphone, in particular, into a payment terminal. Said software application implements a method configured to guarantee the confidentiality of payment transactions carried out by the mobile terminal.
[0005] This can only be permitted if the commercial mobile terminal meets security criteria. However, the mobile terminal cannot determine by itself that it meets the security criteria. A specific process implemented by a server is required to certify that the mobile terminal meets the criteria.
[0006] Payment card industry specifications do not describe how to develop and implement such an attestation process.
[0007] It is known to obtain the desired certificate from a set of information concerning the mobile terminal, the set of information being transferred "in bulk" to the server.
[0008] However, this certification process consumes a lot of processing power in the mobile terminal and requires a lot of time to collect and transfer data to the server.
[0009] The invention therefore aims to propose a solution to all or part of these problems. To this end, the present invention relates to a method for attesting a mobile terminal for the implementation of a payment application on the mobile terminal, the mobile terminal being configured to communicate with a server, the method comprising the following steps implemented by the mobile terminal:
[0010] - receiving an attestation request from the server, the attestation request being randomly selected by the server from a predetermined subset of a plurality of attestation requests, the attestation request defining a list of characteristics of the mobile terminal,
[0011] - collecting a list of values for the mobile terminal, a value from the list of values corresponding to a characteristic from the list of characteristics of the mobile terminal transmitted by the server;
[0012] - transmission to the server of the list of values, the trusted communication channel being established by the server based on the list of values.
[0013] According to these provisions, the server randomly selects a limited number of attestation requests from a large number of possible attestation requests, making it very difficult for an attacker to design a fraudulent mechanism for determining the responses expected by the server. The random nature of the selection, from all possible lists of technical characteristics, of one list or another list of technical characteristics of the mobile terminal, thus makes it possible to protect against a “man-in-the-middle” attack.
[0014] According to these provisions, the method allows the establishment of a trusted communication channel which is implemented for a transaction phase which uses the trusted communication channel thus established, for example for said transaction, for example a payment procedure.
[0015] According to one embodiment, the invention comprises one or more of the following features, alone or in a technically acceptable combination. According to one embodiment, the attestation request is encrypted by the server using a variable encryption key, selected from a set of encryption keys of the server, each encryption key of the set of encryption keys corresponding to a decryption key of the mobile terminal, the decryption key being recorded in a white box of the mobile terminal, and the method further comprises a step of decrypting the encrypted attestation request with the decryption key of the mobile terminal recorded in the white box of the mobile terminal.
[0016] According to one embodiment, the method further comprises a step of encrypting the list of values with another variable encryption key of the mobile terminal recorded in a white box of the mobile terminal, the encryption step producing a list of encrypted values, the list of values transmitted to the server during the transmission step being the list of encrypted values.
[0017] According to one implementation mode, the established trusted communication channel is secured.
[0018] According to one embodiment, the list of characteristics of the mobile terminal comprises at least one of at least one of the characteristics of the mobile terminal among a brand, a model number, and a version number of an operating system of the mobile terminal.
[0019] According to one method of implementation, the mobile terminal is commercial equipment intended for the general public, for example of the smart phone type, in particular a smartphone, or a tablet.
[0020] According to one embodiment, the method further comprises the following steps, implemented after the establishment of the trusted communication channel: - receiving another attestation request from the server, the other attestation request being randomly selected by the server from among the plurality of attestation requests, the other attestation request defining another list of characteristics of the mobile terminal;
[0021] - collecting another list of values for the mobile terminal, a value from the other list of values corresponding to a characteristic of the other list of characteristics of the mobile terminal;
[0022] - further transmission to the server of the other list of values; the communication channel being maintained or interrupted by the server depending on the other list of values.
[0023] According to these provisions, the number of attestation requests included in the plurality of attestation requests being large, each individual request may concern a small amount of information; the collection and transmission of this information by the mobile terminal will thus require limited computing power and load. It will be noted that another attestation request of the predetermined subset of the plurality of attestation requests defines another list of characteristics of the mobile terminal.
[0024] According to one mode of implementation, the step of receiving another attestation request takes place at a time depending on a time randomly determined by the server.
[0025] Under these provisions, the server randomly choosing a small number of attestation requests from a large number of possible attestation requests, and the server issuing these requests at randomly determined times, makes it even more difficult for an attacker to design a fraudulent mechanism for determining the responses expected by the server.
[0026] According to one embodiment, the other attestation request is encrypted by the server using an encryption key of the server corresponding to a decryption key of the mobile terminal, the decryption key being recorded in a white box of the mobile terminal and the method further comprises a step of decrypting the other attestation request encrypted with the decryption key of the mobile terminal recorded in the white box of the mobile terminal.
[0027] According to one embodiment, the method further comprises a step of encrypting the other list of values with another variable encryption key of the mobile terminal recorded in a white box of the mobile terminal, the encryption step producing another list of encrypted values, the other list of values transmitted to the server during the other transmission being the other list of encrypted values.
[0028] According to one mode of implementation, the list of characteristics of the mobile terminal includes at least one of the following characteristics: presence or absence of a specific software module among the applications installed on the mobile terminal, brand of the mobile terminal, identifying number of the mobile terminal, version of the operating system installed on the mobile terminal, presence or absence of a specific file in the file system installed on the mobile terminal.
[0029] According to one aspect, the invention also relates to a method of attesting a mobile terminal for the implementation of a payment application on the mobile terminal, the mobile terminal being configured to communicate with a server, the method comprising the following steps implemented by the server:
[0030] - transmission to the mobile terminal of an attestation request, the attestation request being randomly selected by the server from a predetermined subset of a plurality of attestation requests, the attestation request defining a list of characteristics of the mobile terminal;
[0031] - receiving a list of values, a value from the list of values corresponding to a characteristic from the list of characteristics of the mobile terminal transmitted by the server;
[0032] - determination, on the basis of the list of values, of a security level of the mobile terminal;
[0033] - establishment of a trusted communication channel based on the security level of the mobile terminal.
[0034] According to these provisions, the server randomly chooses a small number of attestation requests from a large number of possible attestation requests, making it very difficult for an attacker to design a fraudulent mechanism for determining the responses expected by the server.
[0035] According to one embodiment, the invention comprises one or more of the following characteristics, alone or in a technically acceptable combination.
[0036] According to one embodiment, the method comprises a transaction phase which can use the trusted communication channel established by the method, for example to implement a payment procedure.
[0037] According to one embodiment, the method further comprises a step of encryption by the server, using a variable encryption key, selected from a set of encryption keys of the server, each encryption key of the set of encryption keys corresponding to a decryption key of the mobile terminal, the decryption key being recorded in a white box of the mobile terminal, the encrypted attestation request being decrypted with the decryption key of the mobile terminal recorded in the white box of the mobile terminal.
[0038] According to one embodiment, the method further comprises a step of decryption by the server of the list of encrypted values, with another server decryption key corresponding to a variable encryption key of the mobile terminal stored in a white box of the mobile terminal, the decryption step producing the list of values.
[0039] According to one implementation mode, the trusted communication channel is established according to the security level of the mobile terminal and according to a delay between the reception of the list of values and the transmission of the attestation request.
[0040] According to one implementation mode, if the reception delay is greater than a determined delay, or if the security level is lower than a determined threshold, the communication channel is not established by the server.
[0041] According to one embodiment, the method further comprises the following steps, implemented by the server after the establishment of the communication channel:
[0042] - transmission of at least one other attestation request, the at least one other attestation request being randomly selected by the server from among the plurality of attestation requests;
[0043] - receiving another list of values, a value from the other list of values corresponding to a characteristic of the other list of characteristics of the mobile terminal,
[0044] - another step of determining, on the basis of the other list of values, another security level of the mobile terminal;
[0045] - maintaining or interrupting the trusted communication channel depending on the other security level.
[0046] According to these provisions, the number of attestation requests included in the plurality of attestation requests being large, each individual request may concern a small quantity of information; the collection and transmission of this information by the mobile terminal will thus require limited computing power and load. According to one embodiment, the step of transmitting at least one other attestation request takes place at a time determined randomly by the server.
[0047] Under these provisions, the server randomly choosing a small number of attestation requests from a large number of possible attestation requests, and the server issuing these requests at randomly determined times, makes it even more difficult for an attacker to design a fraudulent mechanism for determining the responses expected by the server.
[0048] According to one embodiment, the other attestation request is encrypted by the server using an encryption key of the server corresponding to a decryption key of the mobile terminal, the decryption key being recorded in a white box of the mobile terminal.
[0049] According to one embodiment, the method further comprises a step of decryption by the server of the other list of encrypted values, with another server decryption key corresponding to a variable encryption key of the mobile terminal stored in a white box of the mobile terminal, the decryption step producing the other list of values.
[0050] According to one implementation mode, the communication channel is established according to the other security level of the mobile terminal and according to another delay between the reception of the other list of values and the transmission of the other attestation request.
[0051] According to another aspect, the invention relates to a computer program comprising a set of instructions configured to implement the method according to one of the embodiments described above, when the instructions are executed on a processor of a mobile terminal, or the method according to one of the other embodiments described above, when the instructions are executed on a processor of a server.
[0052] According to another aspect, the invention relates to a mobile terminal comprising a processor and a memory and a set of instructions stored in the memory, the set of instructions being configured to implement the method according to embodiments described above when the instructions are executed on the processor of the mobile terminal.
[0053] For a better understanding, an embodiment and / or implementation of the invention is described with reference to the attached drawings representing, by way of non-limiting example, an embodiment or implementation respectively of a device and / or a method according to the invention. The same references in the drawings designate similar elements or elements whose functions are similar.
[0054] [Fig. 1] is a schematic representation of the sequence of steps of the method according to one embodiment of the invention.
[0055] [Fig. 2] is a schematic representation of a mobile terminal configured for an implementation of the invention.
[0056] The invention relates to a method 100, 200 for attesting a commercial mobile terminal TM, intended for non-professional clients, for example a smart phone, of the smartphone type in particular, the attestation of the mobile terminal TM being carried out by a server S, with a view to establishing a trusted communication channel between the mobile terminal TM and the server S, for the execution of a payment, when certain attestation conditions relating to the mobile terminal TM are satisfied.
[0057] The trusted communication channel established when the attestation conditions are satisfied may be, for example, a trusted and secure communication channel, in other words a communication channel between two mutually authenticated points whose communication is protected in confidentiality. A secure communication channel makes it possible in particular to guarantee the authenticity and provenance of the key, and thus to protect against an attack known as a "man-in-the-middle" attack.
[0058] The steps of the attestation method 100, 200 according to the invention are described below, with reference to FIG. 1, considering successively the steps of the method 100 implemented by the mobile terminal TM, presented from top to bottom along a vertical line TM in FIG. 1, and the steps of the method 200 implemented by the server S, presented from top to bottom along a vertical line S in FIG. 1; the steps of the method 100, and of the method 200 contribute together to the attestation of the mobile terminal TM for the execution of a payment.
[0059] The method comprises in particular a phase 110, 210 of establishing a trusted communication channel between the mobile terminal TM and the server S, intended to be used during a phase 120, 220 of transaction TR which uses the trusted communication channel CC, CC' established and / or maintained by the server, to execute the transaction TR associated with the execution of the payment. The communication channel will be designated by the reference CC when it is the established trusted communication channel, and will be designated by the reference CC' when it is the same established and maintained trusted communication channel.
[0060] The establishment phase 110, 210 begins more particularly with a request step 111 for establishing a communication channel sent by the mobile terminal TM to the server; upon receipt 211 by the server S of the request 111, the server S transmits 212 to the mobile terminal TM an attestation request RA, the attestation request being randomly selected by the server S from a predetermined subset of a plurality of attestation requests, the attestation request defining a list of characteristics LC of the mobile terminal TM. Thus a relatively small number of attestation requests RA is randomly chosen from a large number of possible attestation requests, so that it will be difficult for a fraudster to design the responses required for the chosen attestation requests RA, by listening to the responses made to previous attestation requests.
[0061] The following steps, implemented by the mobile terminal TM are a step 112 of receiving the attestation request RA from the server S, followed by a step 113 of collecting the information required by the attestation request RA; this collection leads to the creation of a list of values LV for the mobile terminal TM, a value of the list of values LV corresponding to a characteristic of the list of characteristics LC of the mobile terminal TM transmitted by the server S; in other words, each characteristic of the list of characteristics LC can take a certain number of particular values for the mobile terminal TM considered, so that the latter collects, during the collection step, the particular value corresponding to a given characteristic of the list of characteristics LC.
[0062] For example, the list of characteristics LC will include at least one of the following characteristics: presence or absence of a specific software module among the applications installed on the mobile terminal, brand of the mobile terminal, identification number of the mobile terminal, for example a serial number of the mobile terminal, version of the operating system installed on the mobile terminal, presence or absence of a specific file in the file system installed on the mobile terminal. For each of these characteristics, the mobile terminal TM will collect a particular value specific to it, so as to constitute a list of values LV.
[0063] The next step, implemented by the mobile terminal TM, is a step 114 of transmitting the list of values LV to the server S. The following steps, implemented by the server S, are respectively the steps of:
[0064] - reception 214 of the LV list of values;
[0065] - determination 215, on the basis of the list of values LV, of a security level NS of the mobile terminal TM;
[0066] - establishment 216 of the trusted communication channel CC according to the security level NS of the mobile terminal TM.
[0067] Thus, the security level is determined 215 based, for example, on one or more of the values of the following characteristics:
[0068] - presence or absence of a specific software module among the applications installed on the mobile terminal,
[0069] - brand of the mobile terminal,
[0070] - mobile terminal identification number,
[0071] - version of the operating system installed on the mobile terminal,
[0072] - presence or absence of a specific file in the file system installed on the mobile terminal.
[0073] For example, the determined security level is compared to a predetermined level: if the determined security level is higher than the predetermined level then the trusted communication channel CC is established 216 between the server S and the mobile terminal TM. Otherwise, it is not established by the server S.
[0074] The trusted communication channel CC, as established at the end of step 216 of establishing the trusted communication channel CC, may in particular also be secured, within the meaning of the definition recalled above.
[0075] Thus, the method 100, 200 can in particular, during a phase 120, 220 of transaction TR, use the trusted communication channel CC established 216 by the server S, in particular to implement a payment procedure.According to an exemplary implementation, the exchanges during the establishment phase 110, 210 can be encrypted to obtain enhanced security; thus, according to this exemplary implementation, the attestation request RA is encrypted 212bis by the server S using a variable encryption key, selected from a set of encryption keys of the server S, each encryption key of the set of encryption keys corresponding to a decryption key of the mobile terminal TM, the decryption key being recorded in a white box of the mobile terminal TM, and the method 100 further comprises a step of decrypting 112bis the encrypted attestation request RAC with the decryption key of the mobile terminal TM recorded in the white box of the mobile terminal TM.
[0076] According to a complementary example of implementation, the method 100 further comprises a step 114bis of encryption of the list of values LV with another variable encryption key of the mobile terminal TM stored in a white box of the mobile terminal TM, the encryption step 114bis producing a list of encrypted values LVC, the list of values transmitted to the server S during the transmission step 114 being the list of encrypted values LVC. Conversely, according to this example of implementation, the method 200 further comprises a step 214bis of decryption by the server S of the list of encrypted values LVC, with another server decryption key S corresponding to a variable encryption key of the mobile terminal TM stored in a white box of the mobile terminal TM, the decryption step 214bis producing the list of values LV
[0077] Optionally, the method 100 may further comprise, after the establishment 216 by the server S of the trusted communication channel CC, and in particular during the phase 120, 220 of transaction TR which uses the trusted communication channel, the following steps:
[0078] - reception 112' of one or more other ARA attestation requests from the server S, each other ARA attestation request being randomly selected by the server S from among the plurality of attestation requests, each other attestation request defining another list of ALC characteristics of the mobile terminal TM;
[0079] - collection 113' of another list of values ALV for the mobile terminal TM, a value of the other list of values ALV corresponding to a characteristic of the other list of characteristics ALC of the mobile terminal TM;
[0080] - transmission 114' to the server S of the other list of values ALV; the communication channel CC' being maintained or interrupted 216' by the server S depending on the other list of values ALV.
[0081] Similarly, from the point of view of the server S, the corresponding steps of the method 200 are implemented by the server:
[0082] - transmission 212' of one or more other ARA certification requests;
[0083] - receipt 214' of one or more other ALV value lists, each other value list corresponding to one of the other ARA attestation requests;
[0084] - determination 215', on the basis of each other list of ALV values, of another ANS security level of the mobile terminal TM;
[0085] - maintenance or interruption 216' of the communication channel CC' depending on the other security level ANS.
[0086] Thus, since the number of attestation requests included in the plurality of attestation requests is large, each individual request may concern a small amount of information; the collection and transmission of this information by the mobile terminal will thus require limited computing power and load.
[0087] In particular, the step 212' of transmission by the server of the other attestation request ARA takes place at a time randomly determined by the server S, during an exchange of messages between the mobile terminal TM and the server S which uses the trusted communication channel CC, so that the step 112' of reception by the mobile terminal TM of the other attestation request ARA takes place at a time depending on the time randomly determined by the server S (the time of reception 112' of the other attestation request by the mobile terminal TM is in fact a function of the time of transmission 212' of said other request by the server S, the time of transmission 212' by the server S being randomly determined by the server S).The mechanism for issuing one (or more) other ARA attestation request(s) is thus “intertwined” with the functional dialogue between the mobile terminal TM and the server S which uses the trusted communication channel CC, in particular for a phase 120, 220 of implementing a transaction TR.
[0088] Under these provisions, the server randomly choosing a small number of attestation requests from a large number of possible attestation requests, and the server issuing these requests at randomly determined times, makes it even more difficult for an attacker to design a fraudulent mechanism for determining the responses expected by the server.
[0089] According to a complementary example of implementation of the method 100, 200, the trusted communication channel CC is established as a function of the security level NS of the mobile terminal TM and as a function of a delay between the reception 214 of the list of values LV and the transmission 212 of the attestation request; Thus, by way of example, if the reception delay is greater than a determined delay, or if the security level NS is less than a determined threshold, the trusted communication channel CC is not established by the server S; similarly, the trusted communication channel is maintained or interrupted 216' by the server S as a function of the other security level ANS of the mobile terminal TM and as a function of another delay between the reception 214' of the other list of values ALV and the transmission 212' of the other attestation request ARA,among the plurality of other attestation requests that the server S is likely to issue after the establishment of the trusted channel CC, in particular during the phase 120, 220 of implementing a transaction TR. In the same way that the information exchanges can be encrypted during the establishment phase 110, 220, before the establishment 216 of the trusted communication channel CC by the server S, the information exchanges after the establishment 216 of the trusted communication channel CC by the server S, with a view to maintaining or interrupting 216' the communication channel CC' by the server S, can also be encrypted. Thus, according to an example of implementation, the other ARA attestation request is encrypted 212'bis by the server S using an encryption key of the server S corresponding to a decryption key of the mobile terminal TM, the decryption key being recorded in a white box of the mobile terminal TM,and the other ARAC encrypted attestation request is decrypted 112'bis with the decryption key of the TM mobile terminal recorded in the white box of the TM mobile terminal.,
[0090] Similarly, the method 100 may further comprise a step 114'bis of encryption of the other list of values ALV with another variable encryption key of the mobile terminal TM recorded in a white box of the mobile terminal TM, the encryption step 114'bis producing another list of encrypted values ALVC, transmitted to the server S during the other transmission 114'; reciprocally, the method 200 further comprises a step 214'bis of decryption by the server S of the other list of encrypted values ALVC, with another server decryption key S corresponding to the variable encryption key of the mobile terminal TM, the decryption step 214bis producing the other list of values ALV.
[0091] According to one aspect, the invention relates to a computer program comprising a set of instructions configured to implement the method 100, according to one of the embodiments described above, when the instructions are executed on a processor of a mobile terminal TM, or the method 200 according to one of the embodiments described above, when the instructions are executed on a processor of a server S. According to another aspect, the invention relates to a mobile terminal TM comprising a processor PC and a memory M and a set of instructions recorded in the memory M, the set of instructions being configured to implement the method 100 according to one of the embodiments described above when the instructions are executed on the processor of the mobile terminal TM.
Claims
CLAIMS 1. Method (100) for attesting a mobile terminal (TM) for implementing a payment application on the mobile terminal, the mobile terminal (TM) being configured to communicate with a server (S), the method (100) comprising the following steps implemented by the mobile terminal (TM): - reception (112) of an attestation request (RA) from the server (S), the attestation request being randomly selected by the server (S) from a predetermined subset of a plurality of attestation requests, the attestation request defining a list of characteristics (LC) of the mobile terminal (TM), - collection (113) of a list of values (LV) for the mobile terminal (TM), a value of the list of values corresponding to a characteristic of the list of characteristics (LC) of the mobile terminal (TM) transmitted by the server (S); - transmission (114) to the server (S) of the list of values (LV), a trusted communication channel (CC) being established (216) by the server (S) according to the list of values (LV) and a security level of the mobile terminal (TM) determined on the basis of the list of values (LV).
2. Method (100) according to one of claims 1, in which the established trusted communication channel (CC) is secure.
3. A method (100) of attestation according to one of claims 1 or 2, further comprising the following steps, implemented after the establishment of the trusted communication channel (CC): - reception (112') of another attestation request (ARA) from the server (S), the other attestation request (ARA) being randomly selected by the server (S) from among the plurality of attestation requests, the other attestation request defining another list of characteristics (ALC) of the mobile terminal (TM); - collection (113') of another list of values (ALV) for the mobile terminal (TM), a value from the other list of values (ALV) corresponding to a characteristic from the other list of characteristics (ALC) of the mobile terminal (TM); - further transmission (114') to the server (S) of the other list of values (ALV); the communication channel (CC) being maintained or interrupted (CC') by the server (S) depending on the other list of values (ALV).
4. Method (100) according to the preceding claim, in which the step of receiving (112') another attestation request (ARA) takes place at a time depending on a time determined randomly by the server (S).
5. Method (200) for attesting a mobile terminal (TM) for the implementation of a payment application on the mobile terminal, the mobile terminal (TM) being configured to communicate with a server (S), the method (200) comprising the following steps implemented by the server (S): - transmission (212) to the mobile terminal (TM) of an attestation request (RA), the attestation request being randomly selected by the server (S) from a predetermined subset of a plurality of attestation requests, the attestation request defining a list of characteristics (LC) of the mobile terminal (TM); - reception (214) of a list of values (LV), a value of the list of values corresponding to a characteristic of the list of characteristics (LC) of the mobile terminal (TM) transmitted by the server (S); - determination (215), on the basis of the list of values (LV), of a security level (NS) of the mobile terminal (TM); - establishment (216) of a trusted communication channel (CC) according to the security level (NS) of the mobile terminal (TM).
6. Method (200) according to claim 5, in which the trusted communication channel is established according to the security level (NS) of the mobile terminal (TM) and according to a delay between the reception (214) of the list of values (LV) and the transmission (212) of the attestation request.
7. A method (200) of attestation according to claim 6, further comprising the following steps, implemented by the server (S) after the establishment of the communication channel: - transmission (212') of at least one other attestation request (ARA), the at least one other attestation request being randomly selected by the server (S) from among the plurality of attestation requests; - reception (214') of another list of values (ALV), a value of the other list of values (ALV) corresponding to a characteristic of the other list of characteristics (ALC) of the mobile terminal (TM), - another step of determining (215'), on the basis of the other list of values (ALV), another security level (ANS) of the mobile terminal (TM); - maintenance or interruption (216') of the trusted communication channel (CC') depending on the other security level (ANS).
8. The method (200) of claim 7, wherein the transmitting step (212') of at least one other attestation request (ARA) takes place at a time randomly determined by the server (S).
9. Method (200) according to claim 7 or 8, in which the communication channel is established according to the other security level (ANS) of the mobile terminal (TM) and according to another delay between the reception (214') of the other list of values (ALV) and the transmission (212') of the other attestation request (ARA).
10. Computer program comprising a set of instructions configured to implement the method (100) according to one of claims 1 to 4 when the instructions are executed on a processor of a mobile terminal (TM), or the method (200) according to one of claims 5 to 9 when the instructions are executed on a processor of a server (S).
11. Mobile terminal (TM) comprising a processor (PC) and a memory (M) and a set of instructions stored in the memory (M), the set of instructions being configured to implement the method (100) according to one of claims 1 to 4 when the instructions are executed on the processor of the mobile terminal (TM).