Method for managing data associated with a timepiece
Patent Information
- Application Number
- EP2024702178
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-30
- Filing Date
- 2024-01-30
- Publication Date
- 2025-12-10
AI Technical Summary
Current methods for managing data associated with timepieces, such as watches, are outdated, insecure, and do not reliably ensure communication between users and retailers for after-sales services, compromising personal data protection.
A data management system utilizing a card with an NFC chip or QR code, linked to a watch, which uses blockchain technology for authentication and access to a web page, allowing users to securely interact with retailers without needing additional applications or accounts, ensuring secure and traceable data exchange.
This solution provides secure, efficient, and user-friendly communication for managing watch-related data, enhancing customer experience while protecting personal data and ensuring secure authentication and ownership verification.
Smart Images

Figure 000029 
Figure 000031 
Figure 000030
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Method for managing data associated with a timepiece.
[0003] The invention relates to a method for managing data associated with a timepiece belonging to a user. The invention also relates to a data management system implementing such a method. The invention also relates to a computer program implementing such a method. The invention also relates to a recording medium on which such a program is recorded. The invention finally relates to a signal of a data medium, carrying the computer program product.
[0004] When a user drops off a watch at a retailer for after-sales service, it is essential that the user can communicate with the retailer, in particular to agree on quotes and / or actions to be planned on the watch. These communications are generally made through emails, faxes or telephone calls. These means of communication are now significantly outdated compared to the possibilities offered by new technologies and can only offer a relatively limited customer experience. In addition, these means of communication are not secure or are poorly secure. In particular, these means do not reliably ensure that communications are exchanged with the real user of the watch. Consequently, the protection of the user's personal data may be compromised.
[0005] Today, solutions in the watchmaking field make it possible to display specific data of a watch or a set of characteristics of a watch on a terminal by taking advantage of a single means of access using a card in an identity card format according to the ISO standard.
[0006] 7810 ID-1.
[0007] "Watch Certificate" offers a card designed to prove the authenticity of a watch. This card allows access via a web page to various specific data about a watch by scanning, using a smartphone for example, a QR code on the card. In addition, various personal data are also accessible, including data about the watch owner, by entering a code on the card. This solution benefits from blockchain technology to ensure a very high level of traceability of specific and personal data.
[0008] A similar type of solution, using blockchain technology from the Arianee consortium, is used by other watchmaking companies. This solution provides complete traceability and is designed to prove the authenticity and ownership of a watch. The solution being promoted is also a card linked to a watch and equipped with a QR code. Alternatively, it could be equipped with an NFC (Near Field Communication) chip. Once scanned with a smartphone, the card allows the user to access a web page to register their watch and obtain a certificate of authenticity. To obtain this certificate, the user is invited to log into a dedicated mobile application to generate a certificate in NFT (Non-Fungible Token) format and declare themselves as the first owner.
[0009] Omega, a watch brand, offers a solution that allows access to specific watch data using a card equipped with an NFC chip. Access to this data requires a user account and a dedicated application on an NFC-compatible smartphone. Some watch brands use solutions offered by the company "WISeKey," which leverages blockchain technology to offer warranty and / or watch authentication cards, and even payment features linked to the watch.
[0010] It should be noted that the very high level of traceability offered by blockchain technology implies unalterable storage of all data history and, depending on the strategy adopted, of the personal data of the different owner(s) of the watch.
[0011] Moreover, in known solutions, it is necessary to download a dedicated application, create a user account and use a login. These operations are inconvenient for users and are likely to generate security breaches.
[0012] The aim of the invention is to provide a method for managing data associated with a timepiece belonging to a user, remedying the drawbacks mentioned above and improving the management methods known from the prior art. In particular, the invention makes it possible to provide a method that allows easy communication between a user and a third party (database manager and / or retailer and / or organization in charge of after-sales service) without compromising the security of the user's personal data.
[0013] A management method according to the invention is defined by claim 1.
[0014] Different modes of carrying out the method are defined by claims 2 to 11.
[0015] A management system according to the invention is defined by claim 12. Embodiments of the system are defined by claims 13 and 14.
[0016] A program product according to the invention is defined by claim 15.
[0017] A recording medium according to the invention is defined by claim 16.
[0018] A data carrier signal according to the invention is defined by claim 17.
[0019] The attached drawing represents, by way of example, a mode of execution of a management method according to the invention and an embodiment of a data management system.
[0020] Figure 1 is a schematic representation of one embodiment of a data management system.
[0021] Figure 2 is a flowchart of a first procedure of an execution mode of a data management method.
[0022] Figure 3 is a flowchart of a second procedure of the data management method execution mode.
[0023] An embodiment of a data management system 100 is described below with reference to FIG. 1. The system 100 makes it possible to manage data relating to a timepiece product 10, for example a timepiece or a watch, in particular a wristwatch. The timepiece product 10 comprises, for example, a unique identifier 11 such as a serial number 11. The unique identifier is, for example, a string of alphanumeric characters comprising, for example, 8 random digits. The unique identifier may be written with a font allowing it to be automatically read by optical means. The unique identifier may be engraved on the timepiece product 10, in particular:
[0024] - on a watch movement, for example on a plate, and / or
[0025] - on a watch case, for example on a case middle or a flange, and / or
[0026] - on a bracelet, for example on a clasp.
[0027] The data managed concerns not only the watch product 10, but also preferably:
[0028] - data relating to the current user (or even previous users), including all or part of the following data: the user's name, postal address, email address, telephone number, and / or
[0029] - data relating to the organization in charge of after-sales service (for example, a retailer), including all or part of the following data: the name of the organization, its postal address, its email address, its telephone number, and / or
[0030] - data relating to the watch manufacturer or watch company marketing the watch product, in particular all or part of the following data: the name of the watch manufacturer or watch company, its postal address, its e-mail address, its telephone number.
[0031] The 100 Data Management System includes:
[0032] - a physical medium 20, for example a card 20 in a format defined by the ISO 7810 ID-1 standard, provided with an access means 21 such as an NFC chip 21,
[0033] - a device or terminal or client 30, for example a computer (portable or not), a smartphone or a tablet, having:
[0034] * a web browser application 32 capable of managing the display of web pages and more generally of ensuring communication with the Internet network, and
[0035] * a functionality or means 31 capable of communicating with the access means 21 or of reading the access means 21, such as an NFC functionality 31 or an NFC means 31,
[0036] - an authentication means 40 making it possible to verify the authenticity of the access means 21,
[0037] - a first database 50, for example a relational database, comprising in particular data of a first type 51, in particular personal data 51 of the user, possibly of several users, and
[0038] - a second database 60, for example a relational database, comprising in particular data of a second type 61, in particular data specific 61 to the watch product 10, or even to several watch products 10, such as one or more unique identifiers 11,
[0039] - a server 70, for example a web server or an application server.
[0040] Preferably, the web browser application 32 or "web browser" is a basic application integrated into the terminal 30. In other words, the web browser 32 is an application pre-installed and / or developed by the manufacturer of the terminal 30. Preferably, the means 31 capable of communicating or reading the access means 21 is a basic functionality integrated into the terminal 30, in particular a radio wave communication functionality.
[0041] The card 20, or more particularly the NFC chip 21, is intended to be associated with at least one specific data item 61 of the watch product 10 such as the serial number 11.
[0042] The NFC chip 21 is designed to be woken up by the NFC functionality 31 of the terminal 30, when the latter is brought close to the card 20. This approach and wake-up action is called a “tap” throughout this document. The NFC chip 21 is preferably provided with means making it possible, at the time of its manufacture, to guarantee the highest possible level of security. To do this, the NFC chip 21 advantageously comprises a unique number 22, cryptographic functionalities, at least one encryption key 24, such as a character string, and a means for generating URL internet addresses 25.These cryptographic functionalities advantageously make it possible to generate encrypted parameters 23 using dynamic and / or static variables which are intended to be sent to the authentication means 40, from the terminal 30, via the server 70, to carry out a verification of the encrypted parameters and an authentication of the NFC chip 21 during each tap.
[0043] To be able to decrypt said encrypted parameters 23, the authentication means 40 notably comprises at least one decryption key 41 compatible with the encryption key 24 of the NFC chip 21.
[0044] Preferably, the NFC chip 21 does not require a battery. It is powered by electromagnetic induction generated by the terminal 30 during tapping.
[0045] Each tap of the card 20 is intended to initiate a connection procedure on a web page 71 dedicated to the associated watch product 10. On this web page, data contained in the first database 50 and in the second database 60 can be displayed. The data associated with the watch product 10 belonging to a user include:
[0046] - data of a first type 51, for example stored in the first database 50, and
[0047] - data of a second type 61, for example stored in the second database 60. The system 100 comprises all the hardware and / or software means making it possible to implement the management method which is the subject of the invention. These means may comprise software means. Preferably, the means form a distributed computer architecture, the means being located in different computers, machines or physical entities.
[0048] A mode of execution of a method for managing data associated with a timepiece belonging to a user is described below with reference to Figures 2 and 3. The mode of execution is advantageously implemented by the management system described previously. The management method can therefore also be seen as a method of operation of a management system described previously.
[0049] The method includes the following exclusive modes:
[0050] - a first mode S10 in which the data of the first type 51 can be consulted, for example on a smartphone, a tablet or a computer and / or via a website or an application, by the user in a step S50, and
[0051] - a second mode S20 in which the data of the first type 51 cannot be consulted by the user in a step S60.
[0052] The two modes are exclusive, that is to say that the method and the system 100 which implements it are:
[0053] - either in the first S10 mode,
[0054] - either in the second S20 mode.
[0055] In the first mode S10, the data of the first type 51 can advantageously be consulted by the user via the use of the terminal 30 and via the server 70.
[0056] The two modes make it possible to offer a different experience to the user: - Advantageously, in the first mode S10 (also called “Service” mode), the physical medium 20 allows the user to consult, on a web page 71, the specific data 61 of the watch product 10 associated with the physical medium 20. In other words, it allows access to the identity card or to the individual data of said watch product. In this first mode, the physical medium 20 allows the user to access personal data 51 such as a quote for maintenance of the watch product 10 or to notifications issued by an organization maintaining the watch product 10. In addition, in this first mode, the user advantageously has the possibility of interacting with the organization thanks to a dedicated interface on said web page 71. This interaction is advantageously secure.
[0057] - In the second mode S20 (also called “Anonymous” mode), no data of the first type 51, in particular no personal data of the user, is accessible. Indeed, the physical medium 20 only allows the user to consult specific data 61 of the watch product 10 associated with the physical medium 20, such as the identity card or the individual data of the watch product, on a dedicated web page 71.
[0058] The mode of the management method or operating mode of the management system (first mode S10 or second mode S20) is defined as a function of an association or dissociation of the watch product 10 with the user, in particular an association or dissociation:
[0059] - data of the first type 51, for example stored in the first database 50, and
[0060] - data of the second type 61, for example stored in the second database 60.
[0061] For example, data is associated / dissociated by an action (such as an entry) carried out by a data manager (organisation in charge of an after-sales service operation or retailer for example) through a computer program or a computer application made available to it.
[0062] For example, the association of data or databases is only provided if the watch product 10 is deposited with an organization for, for example, maintenance. In this case, the management system is configured in the first mode "Service". Otherwise, the management system is configured in the second mode "Anonymous".
[0063] Advantageously, it is possible to modify the mode indefinitely depending on whether or not the user owns the watch product 10.
[0064] More generally:
[0065] - in the first “Service” mode, the terminal 30 allows the display of data contained in the first database 50, even if the first and second databases are not associated, and
[0066] - in the second “Anonymous” mode, the terminal 30 does not allow the display or consultation of data contained in the first database 50, even if the first and second databases are associated.
[0067] In the first “Service” mode, when the user brings his or her watch product 10 to an organization, such as a retailer for, for example, maintenance, personal data 51 of the user are recorded or modified in the first database 50. Personal data 51 such as the name, postal address, email address and telephone number of the user may for example be recorded in the database 50. This personal data 51 is particularly necessary for the preparation of quotes and invoices and for communicating with the user. This personal data may be recorded or modified at the time the user drops off his or her watch product. Alternatively, the personal data 51 may already be contained in the first database 50 at the time the user drops off his or her watch product 10.Of course, this first database 50 is not accessible by third parties and uses security methods to optimally protect users' personal data 51. The security methods may include access management and / or authorization management and / or encryption and / or network segmentation and / or filtering. In addition, the processing of this data is done in such a way as to comply with the General Data Protection Regulation, for example, GDPR in Europe.
[0068] A physical medium 20, such as a card 20, associated with the watch product 10 is made available to the user to allow him to connect to the web page 71 dedicated to the watch product 10 via a terminal 30 of his choice allowing access to the server 70 via an internet protocol. However, preferably, for the user to be able to connect to the web page 71, according to the first “Service” mode, it is necessary that at least one of the personal data 51 of the user is associated with a specific data 61 of the watch product 10. For example, the telephone number of the user can be associated with the serial number 11 of the watch product 10. Preferably, the association is carried out automatically by a computer system interfacing between the personal data 51 of users and the specific data 61 of the watch products, that is to say between:
[0069] - data from the first database 50, and
[0070] - data from the second database 60.
[0071] However, the transition (from the second mode S20 “Anonymous”) to the first mode S10 “Service” is triggered or carried out by a first event caused by a data manager (organization or retailer for example). This first event may for example be a validation or an action on a computer system in service in the organization with which the user deposits his watch product. Preferably, the first “Service” mode is only active or activatable when the user’s watch product 10 has been deposited with the organization.
[0072] In the second “Anonymous” mode, when the user has the watch product 10 in his possession, preferably, no association between the personal data 51 of the user and the specific data 61 of the watch product 10 is established. The user can however still have the physical medium 20 associated with the watch product 10, allowing him to access the specific data 61 of the watch product 10, on a dedicated web page 71.
[0073] The transition (from the first mode S10 “Service”) to the second mode S20 “Anonymous” is triggered or carried out by a second event. This second event can for example be:
[0074] - an action by the data manager, such as a validation or an action on a computer system operating in the organization with which the user deposits their watch product,
[0075] - a user action, such as a particular action on a human-machine interface of the terminal 30 while the latter is connected to the server 70 in a secure mode allowing the consultation of data of the first type 51. This action may for example also consist of a communication or an interaction with the organization, for example consisting of a refusal of a quote.
[0076] - a time-out period. For example, it may be defined by default that the first S10 “Service” mode remains activated for a defined number of days, for example 30 days. At the end of this time-out period, the device automatically switches, without any specific action from the user or a third party, to the second S20 “Anonymous” mode.
[0077] Thus, as shown in Figure 2, in a test step T05, we test whether the last event is a first event or a second event. If the last event is a first event, we move to the first mode S10. Otherwise, the last event is a second event and we move to the second mode S20.
[0078] Once the physical medium 20 is in the user's hands, the user can connect to the server via a web page 71 dedicated to the watch product 10. To do this, it is possible to proceed as follows:
[0079] 1. The user has a terminal 30, such as a smartphone 30, equipped with an NFC functionality 31, and he performs a tap of the NFC chip 21 of the physical medium 20.
[0080] 2. At the time of the tap, the NFC chip 21 wakes up and provides the terminal 30 with encrypted parameters 23 by the at least one encryption key 24, and generates a URL 25 which points to a server 70. Preferably, the URL is a new, different URL and cannot be reused each time the NFC chip is used or each tap.
[0081] 3. The server 70 then relays in particular the encrypted parameters 23 by means of authentication 40.
[0082] 4. Using the at least one decryption key 41, the authentication means 40 authenticates the NFC chip 21 by decrypting the encrypted parameters 23 and also decoding the unique number 22 of the NFC chip. Furthermore, the authentication of the NFC chip 21 can still be controlled by any other means making it possible to further strengthen security.
[0083] 5. If the authentication of the NFC chip 21 is proven, the authentication means 40 returns in particular the unique number 22 of the NFC chip 21 to the server 70. Otherwise, the connection procedure is interrupted.
[0084] 6. Using the unique number 22, the server 70 consults the second database 60 so as to find the serial number 11 of the watch product 10 associated with the NFC chip 21. Therefore, if the serial number 11 is also associated with a personal data item 51 of a user, the server 70 generates a session on the web browser 32 of the smartphone 30 with a web page 71 in the first “Service” mode allowing access to data from the first and second databases. Otherwise, a session with a web page 71 in the second “Anonymous” mode is generated.
[0085] In other words, as illustrated in FIG. 3, in a step T30, in the event of an attempt to consult data using the physical medium 20, an authentication procedure is launched for the physical medium, in particular for the access means 21, and, if the authentication procedure for the physical medium is successful, a test is carried out to see whether the system is in first mode S10 or in second mode S20. If the system is in first mode S10, a strong authentication procedure T40 is launched, i.e. a procedure in which the user holding the physical medium is authenticated. If the user authentication procedure is successful, step S50 is accessed in which the data of the first type 51 can be consulted. Otherwise (i.e. if the strong authentication procedure fails or if the system is in second mode S20), step S60 is accessed in which the data of the first type 51 cannot be consulted.
[0086] Preferably, it is only possible to open one session at a time with the physical medium 20, in particular it is only possible to open one session at a time with the physical medium 20 in the first “Service” mode. On the other hand, as long as the physical medium 20 is associated with the watch product 10, it is for example possible to open indefinitely and successively as many sessions as desired.
[0087] Regardless of the mode (“Service” or “Anonymous”), the session is opened on the user’s terminal 30 with the user’s web browser 32. No additional or dedicated application, as well as no user account or account identifier, is advantageously necessary to consult and display the web page 71. In the first “Service” mode, it is advantageous to carry out strong authentication of the user, such as multi-factor authentication using at least two factors of a distinct nature. The authentication may implement biometric data and / or a temporary code and / or a smart card and / or a mobile application.
[0088] Factors may include:
[0089] - knowledge factor type, such as a password, PIN code or answer to a security question,
[0090] - of the possession factor type, such as a security token (hardware or software), a smart card, a security key, a mobile authenticator, an SMS or a notification received on a mobile device,
[0091] - biological factor type, such as a fingerprint, facial recognition, retina scan, iris scan or voiceprint,
[0092] - location factor type, such as network connection or geographic position.
[0093] Indeed, in this first “Service” mode, it is possible to access personal data 51 of the user via the web page 71 displayed on the terminal 30 and via the server 70. For example, to do this, the user is invited to enter a code previously sent by the server 70 to an e-mail address or to a telephone number entered or contained in the first database 50. This code makes it possible to verify that the user who is trying to connect is indeed the one who transmitted his personal data 51 and who deposited the watch product 10 with the organization. Advantageously, a new code is generated for each new session.
[0094] The concept of strong authentication is defined as consisting of an access verification mixing different strategies and comprising several levels. One of the strategies may consist of a test in various forms (smart card, telephone, email, etc.). If the physical medium 20 were to be held by another user while the management system is in “Service” mode, this other user advantageously cannot access the personal data 51 of the user of the watch product 10, thanks to this strong authentication. In particular, this other user will not receive the code sent by the server 70 to the email address or telephone number of the user of the watch product 10. The strong authentication of the user will therefore fail.
[0095] In the second “Anonymous” mode, the session is opened on the user’s terminal 30 with the web browser 32 to display the web page 71. The session is opened without strong authentication, but following authentication of the access means 21 by the authentication means 40, because no personal information or data of the user is associated or accessible. In this mode, any person possessing the physical medium 20 or carrying the physical medium 20 can open such a session. Indeed, in such a session, the user can only access the specific data 61 of the associated watch product 10 and access to the personal data 51 is excluded.
[0096] Thus, preferably, whatever the mode (“Service” or “Anonymous”), the session is only opened after the access means 21 is authenticated by the authentication means 40.
[0097] Preferably, whatever the mode, if the connection and session opening procedures have been successful, the web page 71 generated on the user's terminal 30 makes it possible to display, in steps S50 and S60, the data of the second type 61, i.e. specific data 61 of the watch product such as:
[0098] - the model of the watch product,
[0099] - photos of the watch product,
[0100] - the serial number of the watch product, - the end date of the warranty,
[0101] - performance measures,
[0102] - a user manual etc.
[0103] All of this data is advantageously anonymous. It is stored in particular in the second database 60. Thus, in the first mode S10 or in the second mode S20, the data of the second type 61 can preferably be consulted by the user. This data of the second type 61 can in particular be consulted without a password and without a user account.
[0104] In the second “Anonymous” mode, it is sufficient to have the physical medium 20 to open a session on the browser 32 and consult data located in the second database 60. This mode can be seen as a mode without user authentication since the bearer of the physical medium 20 is not necessarily known, this medium having been transmitted by the user or stolen from the user. The consultation is therefore anonymous.
[0105] Furthermore, in the first “Service” mode, the web page 71 can display, after strong authentication of the user, personal data 51 such as information on the current maintenance, a maintenance history, quotes or invoices. Furthermore, still after strong authentication, a communication interface can be generated on the web page 71 between the user and the organization owning the watch product 10. Thanks to this communication interface, the organization can for example submit quotes to the user. Advantageously, the user can interact with these quotes by accepting them totally or partially, or even by refusing them. He can even leave comments or communicate directly with the organization by exchanging messages. Preferably, only the personal data 51 of the user that are strictly necessary are potentially accessible or consultable on the web page 71.
[0106] It should be noted that, in the first “Service” mode, the user may possibly receive a message from the organization, for example an SMS or an e-mail, inviting him to connect to consult new notifications on the web page 71. Of course, strong authentication will be necessary to open a new session on the browser 32 and access these notifications via the terminal 30.
[0107] To disconnect from the web page 71, or close the session, it is sufficient to exit the web browser 32, regardless of the operating mode of the management system. Preferably, the session of the web page 71 remains accessible to the user without a new connection or login procedure for a short defined timeout period that may last a few minutes or a few tens of minutes, for example. This allows for smooth navigation on the website 71 and avoids any inconvenience to the user linked to an untimely disconnection or any temporary malfunction of the connection between the terminal and the server.
[0108] Advantageously, the same physical medium 20 can alternatively be configured so as to allow the display of a web page 71 in the first “Service” mode and in the second “Anonymous” mode.
[0109] Being associated with a serial number 11 of a watch product 10 and thanks to the authentication of the access means 21 during a tap, the physical medium 20 can also be used, in the second “Anonymous” mode, as a certificate making it possible to prove the authenticity of the watch product 10, in particular at the time of sale or maintenance of the latter by an organization. As a reminder, in “Anonymous” mode, no personal or historical data is accessible. The physical medium 20 can therefore be transmitted without special attention and without risking compromising the protection of the personal data of previous users of the watch product 10.
[0110] It should be noted that, in the first mode S10 “Service”, the watch product 10 is normally not in the hands of the user, but in the hands of the organization. Therefore, the watch product cannot be sold under these conditions. To be sold, the watch product must be recovered by the user, which inevitably causes the card to switch to mode S20 “Anonymous”.
[0111] Alternatively to the connection to a terminal having a means 31 allowing communication or reading of the access means 21, the physical medium 20 can also allow connection to another terminal not having a means 31 allowing communication or reading of the access means 21.
[0112] The procedure can then proceed as follows:
[0113] 1. First, a dedicated web page is opened in the web browser of the other terminal and specific data 61 of the watch product 10 is entered, such as the serial number 11. The session is then put on hold.
[0114] 2. To unlock the session, the user must tap the physical medium 20 at the terminal 30, which is associated with or corresponds to the serial number 11 previously entered on the other terminal. The terminal 30 then indicates to the user that a session on another terminal is pending, and requests confirmation of the opening of said session.
[0115] 3. Once unlocked, the web page on said session includes the same functionalities and interfaces or substantially the same functionalities and interfaces as a web page 71 generated on the web browser of the terminal 30. As previously described, if the management system is in the first mode S10 “Service”, strong or multi-factor authentication is necessary to access the personal data 51.
[0116] Alternatively, instead of the session being put on hold at the end of the first step of the above procedure, an association request can be generated. Therefore, to validate the association request, the user must perform a tap on the physical medium 20 at the terminal 30. On the terminal 30, the user must then enter the information in the association request displayed on the other terminal. Once the association request has been validated, a session is created and the web page 71 is then generated.
[0117] Preferably, regardless of the embodiment, an NFC chip can only be associated with a single watch product serial number. However, it is preferably possible to associate several NFC chips with the same serial number.
[0118] Regardless of the embodiment, the physical medium may include, for example, a print or engraving allowing the user to identify which watch product the medium is associated with.
[0119] Whatever the method of production, the watch product may in particular be:
[0120] - a watch, in particular a wristwatch,
[0121] - a watch strap,
[0122] - a watch movement.
[0123] Whatever the embodiment, the physical medium 20 may include an access means 21 other than an NFC chip. The access means may in particular be:
[0124] - a QR code, for example printed on the physical medium 20, or - a bar code, for example printed on the physical medium 20, or
[0125] - an RFID tag, for example stuck on the physical support or embedded in the physical support.
[0126] In the case of a QR code or a barcode, the user simply has to scan the QR code or the barcode with a terminal, during the connection procedure, instead of tapping the NFC chip 21. However, the QR code or the barcode cannot be authenticated because it cannot benefit from cryptographic functionality such as the generation of dynamic variables allowing optimal security of the connection to the web page dedicated to the watch product. In addition, unlike an NFC chip, or more particularly unlike the NFC chip 21 according to the invention, a QR code or a barcode can be very easily duplicated by, for example, simply taking a photo of it. Alternatively, other types of access means can be used. Furthermore, the physical medium may comprise an access means 21 including any combination of the following elements and / or other suitable elements, without limitation:
[0127] - an NFC chip,
[0128] - a QR code, or
[0129] - a barcode, or
[0130] - an RFID tag.
[0131] The physical medium 20 could also be a completely different medium than a card, such as a sheet of paper, any object or a watch product.
[0132] Alternatively, the system may also use means, such as applications and / or technologies not integrated as standard with the terminal 30. These means must be added specifically to the terminal 30 so that it takes part in the data management system according to the invention. The first and second databases may be hosted on separate machines or on the same machine. Of course, even if the databases are hosted on the same machine, the association procedure remains as previously described: the association between user data and product data is preferably only established temporarily when the user hands over his watch product to the organization.
[0133] Thanks to the solution according to the invention, the method can be implemented using a smartphone, tablet or computer type terminal on which no specific application installation that could risk compromising the security of personal data is necessary. Indeed:
[0134] - viewing web page 71 only requires a basic integrated application on terminal 30,
[0135] - reading or communication with the NFC means 31 requires only basic integrated functionality on the terminal 30,
[0136] - more generally, the process exclusively requires basic applications and functionalities integrated into the terminal 30.
[0137] Furthermore, consulting web page 71 does not require the creation of a user account or an account identifier which could also compromise the security of personal data.
[0138] Finally, the solution according to the invention does not allow tracking of personal data, or more particularly tracking of the different owner(s) of the watch.
[0139] The proposed solutions optimize the customer experience by benefiting from advanced features offered by certain mobile devices, such as smartphones. In this case, these solutions allow a user to securely access, on their mobile device, a web page dedicated to their watch product using a unique, authenticatable access method associated with the watch product. This access method is embodied by an object provided by a retailer or an organization in charge of an after-sales service operation. These solutions provide simplified and improved exchange and communication capabilities while strengthening the protection of users' personal data.
Claims
CLAIMS 1. Method for managing data associated with a timepiece (10) belonging to a user, the data comprising: - data of a first type (51) including personal data of the user or consisting of personal data of the user, and - data of a second type (61) including data specific to the timepiece or consisting of data specific to the timepiece, the method comprising the following exclusive modes: - a first mode (S10) in which the data of the first type (51) can be consulted by the user, and - a second mode (S20) in which the data of the first type (51) cannot be consulted by the user, the data being consultable via a web page (71).
2. Management method according to the preceding claim, characterized in that, in the first mode (S10) or in the second mode (S20), the data of the second type (61) can be consulted by the user.
3. Management method according to one of the preceding claims, characterized in that the transition from the first mode (S10) to the second mode (S20) is carried out by one of the following events: - an action by a data manager, - a user action, - a deadline for a time delay.
4. Management method according to one of the preceding claims, characterized in that the transition from the second mode (S20) to first mode (S10) is achieved by an action of a data manager.
5. Management method according to one of the preceding claims, characterized in that the data of the first type (51) can be consulted by the user subject to strong authentication of the user or multi-factor authentication of the user, in particular authentication using a code sent to the user and allowing connection to the web page (71).
6. Management method according to one of the preceding claims, characterized in that the data of the first type or of the second type can be consulted by the user subject to authentication of an access means (21), in particular an NFC access means (21), by an authentication means (40).
7. Management method according to the preceding claim, characterized in that the access means is associated with at least one specific data item of the timepiece and / or in that the access means is equipped with cryptographic functionalities making it possible to generate, with each use, a new URL to a new web page (71).
8. Management method according to one of the preceding claims, characterized in that, in the first and second modes (S10, S20), the data of the second type (61) can be consulted by the user anonymously, without authentication of the user.
9. Management method according to one of the preceding claims, characterized in that the first mode (S10) allows a secure communication between the user and another authenticated person, in particular the manager.
10. Management method according to one of the preceding claims, characterized in that the method is implemented using a terminal (30) of the smartphone or tablet or computer type on which only the basic applications integrated in the terminal (30) are necessary and / or no specific application installation is necessary and / or no use of a user account is necessary and / or no use of a user account identifier is necessary.
11. Management method according to one of the preceding claims, characterized in that at least one piece of data of the first type (51) is associated with at least one piece of data of the second type (61) when switching from the second mode (S20) to the first mode (S10) and in that the data of the first type (51) and the data of the second type (61) are dissociated when switching from the first mode (S10) to the second mode (S20).
12. System (100) for managing data associated with a timepiece (10) belonging to a user, the system comprising means (20, 30, 40, 50, 60, 70) for implementing the method according to one of the preceding claims.
13. System according to the preceding claim, characterized in that the system comprises an NFC type access means (21).
14. System according to the preceding claim, characterized in that the system comprises means (31) capable of communicating with the access means (21) or of reading the access means (21).
15. Computer program product downloadable from a communications network and / or recorded on a data medium readable by a computer and / or executable by a computer, characterized in that it comprises instructions which, when the program is executed by the computer, lead the latter to implement the method according to any one of claims 1 to 11.
16. A computer-readable recording medium comprising instructions which, when executed by a computer, cause the computer to implement the method according to any one of claims 1 to 11.
17. Signal of a data carrier, carrying the computer program product according to claim 15.