Authenticating a vehicle occupant for a financial transaction

EP4670099A1Pending Publication Date: 2025-12-31MERCEDES BENZ GROUP AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2025714476
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-27
Filing Date
2025-03-19
Publication Date
2025-12-31

AI Technical Summary

Technical Problem

Existing electronic payment methods in vehicles require complex and privacy-invasive user authentication processes, often necessitating video identification and multiple authentication factors, which are inconvenient and raise data privacy concerns.

Method used

A method utilizing a physical or virtual electronically readable identity card, authenticated with a PIN or biometrics, to securely identify and authorize a vehicle occupant for financial transactions without requiring vehicle identification, using a reader and a central computer to issue a security token for payment authorization.

Benefits of technology

Provides a secure and convenient authentication method that minimizes data transmission and eliminates the need for multiple authentication factors, ensuring legitimate payment authorization while protecting user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025057553_30102025_PF_FP_ABST
    Figure EP2025057553_30102025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for carrying out an electronic financial transaction by a user as an occupant of a vehicle (1), wherein a physical electronically readable identity card (3) or a virtual electronically readable identity card (3) displayed on a mobile terminal is used by the user in order to identify and authenticate themselves at a reading device (5) of the vehicle (1), wherein an identification of the vehicle does not take place, wherein the reading device (5) connects to a central computer (7) via the Internet and, after successful identification and authentication, a security token is obtained from said central computer (9), which is transmitted along with payment details to a payment service provider (9), which in turn authorises a financial transaction in relation to the payment details and / or shares data relating to same.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Authentication of a vehicle occupant for a financial transaction

[0002] The invention relates to a method for executing an electronic financial transaction by a user as an occupant of a vehicle.

[0003] In electronic payment transactions, it is typically necessary for a user to identify themselves as an authenticated person in order to authorize the payment process. Methods for securely performing this authentication using the features of a modern vehicle are known in the prior art.

[0004] DE 10 2022 002 474 B3 relates to a method for paying for goods and / or services by an authorized user of a mobile communication unit with a SIM or eSIM, wherein a user-related parameter set is transmitted to a mobile communication provider assigned to the SIM or eSIM and linked to the SIM or eSIM by the latter, after which the mobile communication provider sends a request to a payment service provider, which creates a virtual payment card or virtual payment token and transmits it to the mobile communication provider, after which the mobile communication provider links the virtual payment card or virtual payment token to the SIM or eSIM, wherein the mobile communication unit is integrated into a vehicle, and wherein the user-related parameter set is determined by a vehicle-external server of the vehicle manufacturer linked to the vehicle and transmitted to the mobile communication provider.furthermore, a user-specific, vehicle-related parameter set is determined by the vehicle manufacturer's external server and transmitted to the mobile network operator, which also links this to the SIM or eSIM, whereby, when paying for goods and / or services, the parameter sets linked to the SIM or eSIM are compared with the corresponding parameter sets stored at the mobile network operator and / or on the vehicle manufacturer's external server.to authenticate the user. The mobile communication unit of DE 102022 002 474 B3 is considered an integral part of the vehicle and is therefore permanently connected to the vehicle's operating system and sensors. According to DE 102022 002 474 B3, this permanently installed SIM card / eSIM in the vehicle thus assumes the role of the second factor in a two-factor authentication process to confirm the user's authenticity. For this procedure, participating payment service providers typically require mandatory personal authentication of the user during service registration in order to, for example, register a direct debit as a payment method. This mandatory authentication is problematic insofar as it requires the user to access / install a web application or app of the payment service provider on their mobile device and to present an identification document (e.g., identity card) containing all their personal data (eye color, height, etc.).The process involves recording / photographing the ID number, etc., using the camera on a mobile device, and also capturing one's own face. This procedure is often called "video identification." However, this raises data privacy concerns: personal data irrelevant to this process is disclosed, the secure storage of the data by the service provider is beyond the user's control, and the data stored there can be misused intentionally. Furthermore, the procedure can be inconvenient for the user, especially since care must be taken to cover the ID card with fingers, and specific lighting conditions are required for hologram recognition.

[0005] Other payment methods are known in the prior art, some of which use up to three factors for authentication. An example is US 2015 / 058224 A1, which concerns a method comprising: receiving a request for transaction account information from an external device at a vehicle interface; determining, by means of the vehicle interface device, that the vehicle interface device is located in a predetermined vehicle; determining, by means of the vehicle interface device, that a mobile communication device is located in the predetermined vehicle; and transmitting the transaction account information to the external device upon determining that the vehicle interface device and the mobile communication device are located in the predetermined vehicle.

[0006] US 2020 / 258074 A1 further concerns a method for vehicle-based payments, wherein a vehicle-based payment system comprising a payment integration unit connected to a mobile electronic device includes: the payment integration unit that receives a confirmation request for a vehicle-based transaction from a third party; the payment integration unit that receives confirmation of the vehicle-based transaction from a vehicle user; the payment integration unit that transmits a payment token request from a financial institution backend to the mobile electronic device, wherein the mobile electronic device transmits the payment token request to the financial institution and receives a payment token from the financial institution; the payment integration unit that receives the payment token from the mobile electronic device;and the payment integration unit that communicates the payment token to the third party, the third party executing the transaction using the payment token.

[0007] The object of the invention is to improve the execution or initiation of an electronic financial transaction by a user in a vehicle.

[0008] The invention is defined by the features of the independent claims. Advantageous further developments and embodiments are the subject of the dependent claims.

[0009] A first aspect of the invention relates to a method for executing an electronic financial transaction by a user as an occupant of a vehicle, wherein the user uses a physical electronically readable identity card or a virtual electronically readable identity card displayed in a mobile device to identify and authenticate themselves to a reader in the vehicle, wherein identification of the vehicle preferably does not take place, wherein the reader connects to a central computer via the Internet and receives a security token from it after successful identification and authentication, which is transmitted together with payment data to a payment service provider, which then authorizes a financial transaction relating to the payment data and / or forwards data about it and / or initiates the payment.

[0010] Preferably, vehicle identification does not take place.

[0011] For the procedure to be successful, the user must have a physical identity card in the vehicle or a corresponding image of it on their mobile device, such as a smartphone. The image on the mobile device is created, for example, by reading a physical identity card into a so-called "Secure Element" of the mobile device. The electronic identity card function can then be used there via a so-called "wallet."

[0012] Furthermore, a reader must be provided in the vehicle which is capable of wirelessly communicating with the physical identity card or the mobile device with the identity card implemented therein, for example via RFID or NFC, or at least of reading this data.

[0013] The identity card, which transmits data to the reader, is used to identify the user. This identification means linking the card to an individual. However, the identity card could have been stolen by an unauthorized person, such as a car thief.

[0014] To ensure that the user is correctly identified, i.e., that the identity card was issued to them, authentication is necessary. This is done, for example, by entering a PIN at the reader or using biometric data such as a fingerprint scan or an iris scan.

[0015] The biometric data can be collected, for example, using an indoor camera or a camera on the mobile device.

[0016] This ensures, even while the vehicle is in operation, that the user is an authorized user and that any payment authorization is legitimate. To complete the transaction, the user also provides payment information, such as their credit card number and the security code stored on the card.

[0017] After successful user identification and authentication, the reader in the vehicle sends a request to a central computer for a security token, also known as an eID token. Once the security token is issued by the central computer, it is transmitted back to the vehicle. A processing unit in the vehicle, connected to the reader, can then transmit the payment data (specifically the amount, recipient, and originating account or credit card to be charged) to a payment service provider and present the security token to confirm successful identification and authentication.For example, the payment service provider can use the security token to verify that the name and, if applicable, other data such as the date of birth and / or address of the user matches the personal data stored in relation to the user's account or credit card, and the payment can only be authorized if this data matches.

[0018] Instead of the payment service provider, another category of entity or organization may be involved. For example, the intended payment by the user may be transmitted to a government agency for monitoring private payment flows.

[0019] Advantageous features of the invention are that no video identification is required to confirm the user's identity. Nevertheless, a secure and reliable method for identifying and authenticating a user in a vehicle is provided to authorize a financial transaction. The amount of data to be transmitted is minimal.

[0020] Another significant advantage over current technologies is that the payment service provider can securely authorize the payment simply by receiving the payment data and the vehicle presenting the security token, without requiring further user authentication. The more complex two-factor or three-factor authentication methods used in current technologies are therefore unnecessary.

[0021] According to an advantageous embodiment, the payment data is entered by the user at an input interface of the vehicle.

[0022] According to a further advantageous embodiment, the payment data is entered by the user at an input interface of a mobile device, the mobile device communicating with a computing unit of the vehicle. According to a further advantageous embodiment, the financial transaction is authorized without any further authentication step for the user.

[0023] In particular, when the final transfer of data is carried out using the payment token as defined in DE 10 2022 002 474 B3, no explicit second factor for authentication is necessary; the use of the user's electronically readable identity card in conjunction with a first authentication step such as entering a PIN or biometric verification is sufficient to complete the procedure, in particular to authorize the financial transaction.

[0024] According to a further advantageous embodiment, the electronically readable identity card is read using RFID or NFC on the vehicle's reader.

[0025] According to a further advantageous embodiment, the user identifies himself at the reader using the physical or virtual identity card and authenticates himself by entering a PIN.

[0026] According to a further advantageous embodiment, the user identifies himself at the reader using the physical or virtual identity card and authenticates himself using sensor-acquired biometric data.

[0027] According to another advantageous embodiment, the payment service provider transmits a confirmation data set to the vehicle after receiving the payment data and the security token.

[0028] According to a further advantageous embodiment, the confirmation data set is linked to a SIM card integrated into the vehicle, or to an eSIM module integrated into the vehicle, or to a secure storage device integrated into the vehicle, and is stored at least temporarily.

[0029] According to a further advantageous embodiment, in addition to the security token, a user-related parameter set is transmitted to the payment service provider, wherein the parameter set is linked to a SIM card integrated into the vehicle, or to an eSIM module integrated into the vehicle, or to a secure memory integrated into the vehicle.

[0030] Further advantages, features, and details will become apparent from the following description, in which – possibly with reference to the drawing – at least one embodiment is described in detail. Identical, similar, and / or functionally equivalent parts are identified by the same reference numerals.

[0031] They show:

[0032] Fig. 1 : A method for executing an electronic financial transaction according to an embodiment of the invention based on a physical identity card.

[0033] Fig. 2: A method for executing an electronic financial transaction according to a further embodiment of the invention based on an electronically represented identity card.

[0034] Fig. 1 shows a method for executing an electronic financial transaction by a user as an occupant of a vehicle 1, wherein the user uses a physical electronically readable identity card 3 or a virtual electronically readable identity card 3 displayed on a mobile device to identify and authenticate themselves at a reader 5 of the vehicle 1. In this exemplary situation, the user is sitting in the vehicle 1 and provides their electronically readable identity card 3, which they are carrying with them. They also recall their PIN associated with the electronic identity card 3. The user then starts the registration process in the vehicle 1 or on their mobile device, which has at least one application linked to the individual vehicle 1. For the recipient of a money transaction, they provide their payment data, such as...The user enters their current account data for a direct debit or their credit card data in vehicle 1 or on their mobile device at a designated interface. Vehicle 1 is equipped with a reader 5 for the electronically readable identity card 3 (e.g., via RFID or NFC). The user places their identity card 3 on the reader 5 or brings it close to it. The approach of the identity card 3 and the establishment of a communication interface in the so-called "physical layer" of the reader 5 (where no data exchange is yet possible) trigger the launch of a program signed by the issuing government agency of the identity card 3, which establishes communication with the identity card 3. A security chip verifies whether the program possesses the required signature and will only permit data access if such a signature is present.This program can run on a backend computer 7 and communicate with the card reader 5 in the vehicle 1 using end-to-end encryption. Alternatively, it can run directly within the telematics system in the vehicle 1 and communicate with the card reader from there using encryption. This program prompts the user to enter the PIN of their identity card 3 on the display in the vehicle 1. After entering this PIN, the user confirms, thereby granting the program access to the data stored in the electronic identity card 3. The program then establishes a data connection to a payment service provider 9, transmits the entered payment data, and retrieves the data fields from the payment service provider 9 that the provider requires for secure user authentication. The program then displays to the user on the vehicle 1 display which data is to be read from the identity card 3 and requests their consent.If the user agrees, the data is read, cryptographically encrypted end-to-end, and transmitted to payment service provider 9 for user authentication. After verifying the user's identity and comparing it with the entered payment data, payment service provider 9, if successful, issues a token as a confirmation record. This token attests to the user's authenticity and the (possibly time-limited) validity of the payment method. This token is then cryptographically encrypted end-to-end and transmitted via backend 7 to the SIM card or another so-called "secure element" in vehicle 1, where it is securely stored. This token can then be used for payment as described in DE 102022 002 474 B3, without requiring a second factor.

[0035] Fig. 2 shows another method for executing an electronic financial transaction by a user as an occupant of a vehicle 1. In contrast to the embodiment shown in Fig. 1, the user in the vehicle 1 does not use their physical, electronically readable identity card 3; rather, it is digitized and implemented as an electronically readable identity card 3 in software. Again, the user either memorizes the corresponding PIN or uses another method. The digital, electronically readable identity card 3 is thus stored on their mobile device and is specifically linked to a so-called "wallet" implemented on the mobile device. The user can then start the registration process in the vehicle 1 or on their mobile device, which has a software-related connection to their individual vehicle 1, and subsequently enter their payment data (e.g.,The user enters account reference data (for a direct debit or their credit card details) in vehicle 1 or on their mobile device. Vehicle 1 is connected to the mobile device via an end-to-end encrypted connection (e.g., via Wi-Fi / UWB / RFID / NFC). The user then initiates the data release of their ID card data on their mobile device, for example, by releasing it to their digital wallet as described above. This triggers the launch of a program signed by the issuing (government) authority of the ID card 3, which establishes communication with the mobile device. A security chip verifies whether the program possesses the required signature and will only permit data access if such a signature is present.This program can run on a backend computer 7 and communicate with the card reader 5 in the vehicle 1 using end-to-end encryption. Alternatively, it can run directly within the telematics system in the vehicle 1 and communicate with the card reader 5 from there using encryption. The program prompts the user to enter their ID card data access PIN on the display in the vehicle 1 or on their mobile device. The user confirms this PIN, thereby granting the program access to the data in the mobile device's wallet. The program then establishes a data connection to the payment service provider 9, transmits the entered payment data, and retrieves the data fields from the payment service provider 9 that the provider requires for secure customer authentication. A display on the vehicle screen informs the user which data is to be read from the ID card 3 and requests their consent.If the user agrees, the data from the wallet on the mobile device is read and transmitted to the payment service provider 9 using end-to-end cryptographic encryption for customer authentication. After verifying the identity and comparing it with the entered payment data, the payment service provider 9, if successful, issues a token as a confirmation record, which attests to the customer's authenticity and the (possibly time-limited) validity of the payment method. This token is then transmitted via backend 7 to the vehicle 1, to the SIM card or another secure element, using end-to-end cryptographic encryption, and stored securely there. This token can then be used for payment as described in DE 102022 002 474 B3, without requiring a second factor.

[0036] Although the invention has been further illustrated and explained in detail by means of preferred embodiments, the invention is not limited by the disclosed examples, and other variations can be derived from them by a person skilled in the art without departing from the scope of protection of the invention. It is therefore clear that a multitude of possible variations exist. It is also clear that the embodiments mentioned as examples are truly only examples and are not to be understood in any way as limiting, for example, the scope of protection, the possible applications, or the configuration of the invention.Rather, the preceding description and the description of the figures enable the person skilled in the art to implement the exemplary embodiments in concrete terms, whereby the person skilled in the art, with knowledge of the disclosed inventive concept, can make various changes, for example with regard to the function or the arrangement of individual elements mentioned in an exemplary embodiment, without leaving the scope of protection defined by the claims and their legal equivalents, such as further explanations in the description.

Claims

Patent claims 1. Method for carrying out an electronic financial transaction by a user as an occupant of a vehicle (1), wherein the user uses a physical electronically readable identity card (3) or a virtual electronically readable identity card (3) displayed in a mobile device to identify and authenticate himself / herself to a reader (5) of the vehicle (1), wherein the reader (5) connects to a central computer (7) via the Internet and receives a security token from it after successful identification and authentication, which is transmitted together with payment data to a payment service provider (9), which authorizes a financial transaction relating to the payment data and / or transmits data about it and / or initiates the payment.

2. Method according to claim 1, wherein the payment data is entered by the user at an input interface of the vehicle (1).

3. Method according to claim 1, wherein the payment data is entered by the user at an input interface of a mobile device, the mobile device communicating with a computing unit of the vehicle (1).

4. Method according to any of the preceding claims, wherein the authorization of the financial transaction takes place without any further authentication step for the user.

5. Method according to one of the preceding claims, wherein the reading of the electronically readable identity card (3) by means of RFID or NFC at the reader (5) of the vehicle (1) is performed.

6. Method according to one of the preceding claims, wherein the user identifies himself at the reader (5) by means of the physical or virtual identity card (3) and authenticates himself by means of a PIN entry.

7. Method according to one of the preceding claims, wherein the user identifies himself at the reading device (5) by means of the physical or virtual identity card (3) and is authenticated by means of sensorially acquired biometric data.

8. Method according to one of the preceding claims, wherein the payment service provider (9) transmits a confirmation data set to the vehicle (1) after receiving the payment data and the security token.

9. Method according to claim 8, wherein the confirmation data set is coupled to a SIM card integrated into the vehicle (1) or to an eSIM module integrated into the vehicle (1) or to a secure storage device integrated into the vehicle (1) and is stored at least temporarily.

10. Method according to one of the preceding claims, wherein, in addition to the security token, a user-related parameter set is transmitted to the payment service provider (9), wherein the parameter set is coupled to a SIM card integrated into the vehicle (1) or to an eSIM module integrated into the vehicle (1) or to a secure memory integrated into the vehicle (1).