Identification method, device, and corresponding program

ES3075544T3Undetermined Publication Date: 2026-08-05BANKS & ACQUIRERS INT HLDG SAS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
ES · ES
Patent Type
Patents
Current Assignee / Owner
BANKS & ACQUIRERS INT HLDG SAS
Filing Date
2015-05-27
Publication Date
2026-08-05

AI Technical Summary

Technical Problem

Existing identification systems for accessing goods or services are either expensive or do not provide sufficient user verification, especially when using payment cards, as they either lack robust authentication methods or require additional systems beyond existing payment infrastructure.

Method used

A method utilizing existing payment card infrastructure to execute zero-amount transactions, optionally with personal identification codes, to ensure user identification and access control, leveraging the EMV protocol for online authorization to validate access to goods or services.

Benefits of technology

Enables secure and cost-effective user identification for accessing protected sites or sensitive data using existing payment cards, ensuring the cardholder's presence and preventing unauthorized access, without the need for additional hardware or systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000008_0000
    Figure 00000008_0000
  • Figure 00000009_0000
    Figure 00000009_0000
  • Figure 00000010_0000
    Figure 00000010_0000
Patent Text Reader

Abstract

The invention relates to a method for identifying a user to access a good or service. [0002] According to the invention, said method comprises: - a step of presenting a payment card to a terminal by the user to be identified; - a step of executing a payment transaction by the terminal for a zero amount; - when said payment transaction is executed without error, a step of issuing an identification assertion that grants access to the good or service.
Need to check novelty before this filing date? Find Prior Art

Description

1. Scope of the invention

[0001] The invention relates to the field of identification.

[0002] More specifically, the invention relates to the identification of individuals by means of an identification element. Such an identification element, within the scope of the invention, is understood to be a payment card, credit card, or debit card. Such cards are widely available and used by many people around the world to carry out payment transactions. They are generally issued by banks or payment service providers. A card is typically issued to a cardholder, who is usually the bank's customer. This cardholder, the bank's or payment service provider's customer, also receives a personal identification code that they may or must use with the payment card (depending on authorization requirements and / or the country in which the card is used).These cards are issued after a relatively thorough examination of the applicant's identity (for example, the bank's customer): provision of identity document, proof of address, etc. 2. Prior Art

[0003] In this discussion, we distinguish between identification systems (used to verify identity) and authentication systems (which certify identity). Identity verification does not employ the same techniques as identity authentication: authentication is generally strong, while identification is comparatively weak.

[0004] There are many situations in which it is necessary to identify a person or individual. A common example is stating one's name when going to an appointment. Generally, stating one's name is not very strong proof of identity, and this type of identification is practically only used in cases where identification is not critical. The situation is different, for example, for access to a protected site or sensitive data. This is the case, for instance, in a company. Access to a company's premises is generally limited to a small number of people. These are, for example, company employees and, to a lesser extent, the company's clients and suppliers. Employees are often identified using a badge that serves as a key.

[0005] access to the company premises. Customers and suppliers, on the other hand, must present themselves at the company reception and provide proof of identity.

[0006] As such, verifying a person's identity document can only be done by a physical person specifically tasked with verifying identity. In situations where a physical person is not dedicated to identity verification, automated systems are implemented (access codes entered on a keypad, badge readers, etc.). Automated identification systems are numerous and often expensive.

[0007] When it comes to authentication, systems exist that are even more expensive. They often use biometric recognition (such as fingerprint scanning). Such systems are reserved for access to highly sensitive areas or to data or devices of a similar nature.

[0008] US patent application US2012 / 143768 proposes a method for authorizing a mobile device to make "card present" payments. However, this method does not allow for the identification of an intended user for access to a good or service. Another US patent application, US5614703, proposes a check-in system for hotels. With this system, a user can check into a hotel with their bank card and use that card as a "key" to open their room. The system unlocks the room door when the ID on a presented card matches the one registered in the system. Consequently, with the proposed system, an invalid or stolen bank card could still be used: this does not allow for the identification of the user for access to a good or service. 3. Summary of the invention

[0009] The invention does not present the problems of the prior art. More specifically, the invention offers a simple and inexpensive solution for enabling access to goods or services while using an existing identification architecture. The invention relates to a method for identifying a user for access to a good or service, that is, for access to a protected site or access to sensitive data. According to the invention, such a method comprises: a step of presentation to a terminal, by the user to be identified, of a payment card; a step of execution, by the terminal, of a payment transaction whose amount is zero, including an online transaction, i.e. by requesting authorization from a server, in which the fourth bit of the fourth octet of the "terminal verification results" of the EMV protocol is set to 1, in order to force an online transaction; when said payment transaction is executed without error, a step of issuing an identification assertion resulting in access to the good or service.

[0010] Thus, the proposed technique allows access to a good or service using an existing payment card belonging to the user. This technique avoids the need to produce new cards to manage this access.

[0011] Depending on a particular characteristic, the execution step of a zero amount payment transaction is adapted, in types of controls carried out jointly between the payment card and the terminal, according to a degree of access sensitivity.

[0012] Thus, the application which is implemented within the terminal, which is essentially identical to a payment application, is adapted to the sensitivity of the information or goods or services which need to be accessed, without the need for any physical modification of the terminal.

[0013] According to a particular embodiment, the step of executing a zero amount payment transaction includes a step of entry, by said user, of a personal identification code on a terminal keypad.

[0014] Thus, the user cannot repudiate their access to the good or service: indeed, entering the personal identification code provides near certainty of the user's identification.

[0015] According to a particular characteristic, the execution step of a zero-amount payment transaction includes a step of transmitting an authorization request to a server connected to said terminal via a communication network.

[0016] Thus, although of a zero amount, this transaction is subject to online acceptance via a server in charge, thereby ensuring that the card has not been reported as stolen.

[0017] The invention also relates, in at least one embodiment, to a user identification device for accessing a good or service, i.e., for accessing a protected site or sensitive data. According to a particular feature, such a device comprises: means of presentation, by the user to be identified, of a payment card; means of execution, of a payment transaction whose amount is zero, including an online transaction, i.e. by requesting authorization from a server, in which the fourth bit of the fourth octet of the "terminal verification results" of the EMV protocol is set to 1, in order to force an online transaction; means of issuing an identification assertion resulting in access to the good or service.

[0018] Such a device, in its most common form, is of course a terminal. This terminal leverages an existing infrastructure, namely the infrastructure of the interbank card payment system. The terminal can advantageously be connected to this system to implement at least some of the steps in the process described elsewhere.

[0019] According to a preferred implementation, the various steps of the processes according to the invention are implemented by one or more software programs or computer programs, comprising software instructions intended to be executed by a data processor of a relay module according to the invention and designed to control the execution of the various steps of the processes.

[0020] Consequently, the invention also relates to a program, capable of being executed by a computer or by a data processor, this program comprising instructions to control the execution of the steps of a process as mentioned above.

[0021] This program can use any programming language, and be in the form of source code, object code, or code somewhere between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0022] The invention also relates to an information carrier readable by a data processor, and comprising instructions of a program as mentioned above.

[0023] The information medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a floppy disk or a hard disk drive.

[0024] On the other hand, the information medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The program according to the invention can, in particular, be uploaded to a network such as the Internet.

[0025] Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.

[0026] According to one embodiment, the invention is implemented using software and / or hardware components. In this context, the term "module" in this document may refer to a software component, a hardware component, or a set of hardware and software components.

[0027] A software component corresponds to one or more computer programs, one or more subroutines of a program, or more generally to any element of a program or software capable of implementing a function or set of functions, as described below for the module in question. Such a software component is executed by a data processor of a physical entity (terminal, server, gateway, router, etc.) and is capable of accessing the hardware resources of that physical entity (memory, storage media, communication buses, input / output cards, user interfaces, etc.).

[0028] Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or set of functions, as described below for the module in question. This could be a programmable hardware component or one with an integrated processor for software execution, for example, an integrated circuit, a smart card, a memory card, an electronic board for running firmware, etc.

[0029] Each component of the system described above naturally implements its own software modules.

[0030] The different embodiments mentioned above can be combined with each other for the implementation of the invention. 4. Drawings

[0031] Other features and advantages of the invention will become clearer upon reading the following description of a preferred embodiment, given by way of simple illustrative and non-limiting example, and the accompanying drawings, among which: there figure 1 presents an architecture on which the proposed technique is based; the figure 2 presents a synoptic overview of the proposed technique; the figure 3 describes a device for implementing the proposed technique. 5. Description 5.1. Reminders

[0032] The general principle of the proposed technique is based on the use of a payment terminal for identification purposes. More specifically, the proposed technique involves using the general architecture of the payment card system for identification purposes.

[0033] We describe, in relation to the figure 1An architecture of a payment system as currently implemented. Such a system (S1) includes at least one payment terminal (POS) (a single terminal shown in the figure), a bank server (BS) (or a payment service provider server). This payment terminal (POS) and this bank server (BS) are connected via a communication network (NTWK) (either a 3G wireless network or a wired network) and possibly via a first intermediate server (IS1).

[0034] Depending on the system, the payment terminal is not directly connected to the bank server. For example, it may be connected to an intermediary server, which acts as a proxy / buffer / accreditor (this intermediary server may be the merchant's bank's server). The intermediary server (IS1) may itself be connected to at least one other intermediary server (IS2), which is, for example, the server of the payment card issuer (Visa, Mastercard, American Express, etc.). These second-tier intermediary servers are then connected to the bank servers. The intermediary server (IS1) may also be directly connected to other bank servers (of other banks and / or payment service providers).

[0035] When a transaction needs to be processed from the point-of-sale (POS) terminal, the POS terminal connects, for example, to the first intermediary server (IS1), particularly when payment authorization is required. Depending on the transaction amount, the intermediary server (IS1) can either provide the necessary authorization itself or request it from another server. The intermediary server (IS1) selects, from among all the servers it has access to (IS2, BS, etc.), the appropriate server based on the payment card presented in the POS terminal and requests authorization from that server. Naturally, these transmissions are encrypted using cryptographic hardware distributed among the various parties to guarantee the absence of fraud and the authenticity of the exchanged information.

[0036] Furthermore, a set of protocols, called "EMV," is implemented to obtain the data necessary for the transaction from the payment card. The proposed technique is based on this architecture.

[0037] The proposed technique, described in relation to the figure 2 includes the following steps: a presentation step (10) to a terminal (Term), by the user to be identified (Usr), of a payment card (CB); an execution step (20), by the terminal (Term), of a payment transaction (TrP) whose amount is zero; when said payment transaction is executed without error, a delivery step (30) of an identification assertion (AssertID) resulting in access to the good or service.

[0038] The presentation of the payment card can consist of inserting it into a payment card reader or using contactless communication with the payment card (NFC) or another method of presenting a payment card. More specifically, at least two embodiments of the proposed technique can be implemented. The first embodiment consists of identifying a user by generating a dummy transaction with a zero amount (€0). Implementing such a simple transaction ensures that the payment card user, whose name is inscribed on the card, possesses the personal identification code information necessary to validate the transaction (when the personal identification code is used).A priori, therefore, when the personal identification code is correct, the payment card user is assumed to be the person they claim to be.

[0039] When it is not necessary to enter a personal identification code, only the card's validity is ensured. This variant is particularly well-suited, for example, to replace the use of magnetic stripe cards, RFID cards, or temporary codes. Indeed, for instance, to access a hotel room, it is common practice for the hotel to provide the guest with a magnetic stripe card. This card is inserted into a reader on the room door and allows the door to be opened. Using the technique of the invention, it is not necessary to use an additional card: the user's payment card is used instead of the magnetic stripe card to grant access to the room. When the card is inserted, a bank transaction with an amount equal to zero euros is created by the card reader (for example, integrated into the hotel room door).This transaction is transmitted to either the first or second intermediate server. The latter validates the transaction and sends back a validation confirmation to the terminal. When the terminal receives the validation, it authorizes the requested action (for example, opening the door). Alternatively, the terminal requires no validation: a transaction with a zero amount is created. When it is possible to create this transaction (that is, when the terminal is presented with a valid payment or credit card), then simply being able to create the transaction allows access to the desired product or service. Of course, in addition to creating this transaction, the terminal verifies that the payment card identifier matches an expected identifier (the identifier being, for example, the payment card number).If we consider access to a hotel room, for example, this identifier is necessarily known; indeed, to pay for the hotel room, the user must present a valid payment card or credit card at reception: the payment card number is therefore already known. Thus, in this embodiment, the hotel's room management system is greatly simplified since it is not necessary to have a supplementary system for issuing magnetic access cards. This embodiment can, of course, be adapted to other types of access to goods or services.

[0040] When it is necessary to enter a personal identification code, an additional layer of security is provided compared to existing systems: it is verified that access to the good or service is only possible for the cardholder who also possesses the card's personal identification code. This is particularly useful when access to the good or service requires strict control. For example, this type of operation can be adapted to a registered mail collection system, which can be implemented in post offices. A user who receives a notification indicating the availability of registered mail can then go to the post office and use an automated system that recognizes the payment cardholder, identifies the registered mail awaiting collection, requests the personal identification code via the terminal, and completes a zero-value transaction.When the terminal receives authorization from the server, it instructs the automated system to deliver the registered mail to the user. From then on, it becomes possible to obtain goods and services much more securely and quickly than before. Specifically, this technique can be implemented in situations involving unattended access to goods and / or services. This includes any type of distribution system where user (or customer) identification or authentication is required, but without a financial transaction: access to a parking space, opening a door, access to a workplace, etc.

[0041] In another embodiment, complementary to the previously presented embodiments, a transaction is performed each time the payment card is used to carry out an identification operation. As explained previously, in a basic embodiment, the transaction has a fixed amount of 0. Furthermore, in this basic embodiment, the transaction also includes the identity of the "merchant," that is, the provider of access to the good or service. In the hotel example, this is the name of the hotel. The transaction also includes a description, constructed according to the action performed. In the hotel example, this is, for instance, the time of use.

[0042] In this embodiment, although it is presented as a basic embodiment, a subtlety is introduced at the level of the application that manages identification / authentication transactions (the application installed on the terminal). It should be recalled that the principle of the invention consists of using a general payment system architecture to perform identification / authentication. Depending on the situation, and more specifically depending on what access is to be granted using the payment card, the application installed on the terminal will not necessarily function in the same way. Thus, in the case of "simple" access, the transaction can be conducted without requiring authorization from a server (offline transaction): this is, for example, the case of accessing a hotel room. In this case, the risk management phase on the terminal side is not implemented.The appropriate bit for the "terminal check results" of the EMV protocol is set to 0.

[0043] In the case of "sensitive" access (that is, when the goods or services being accessed are considered sensitive, such as registered mail), the transaction is always conducted "online," meaning by requesting authorization from a server (for example, a banking server). In this case, bit 4 of byte 4 of the "terminal verification results" of the EMV protocol is set to 1, in order to force an online transaction.

[0044] Consequently, generating a transaction allows the user to see, on their account statement, all uses of their payment card, whether for making a payment or for accessing a good or service. Therefore, the account statement becomes a record of transactions.

[0045] In a more complex embodiment, the payment terminal is used not to grant access to a good or service, but to authenticate an action by the payment cardholder. In such an embodiment, the transaction processed by the payment terminal represents an identified thing. This is, for example, a piece of data. 5.2. Other features and advantages

[0046] We describe, in relation to the figure 3 , a device implemented to identify a user, according to the process described previously.

[0047] For example, the device includes a memory 31 consisting of a buffer memory, a processing unit 32, equipped for example with a microprocessor, and controlled by the computer program 33, implementing an identification process.

[0048] At initialization, the code instructions of computer program 33 are, for example, loaded into memory before being executed by the processor of processing unit 32. Processing unit 32 receives activation data as input (for example, a button press or a digital activation command). The microprocessor of processing unit 32 implements the steps of the identification process, according to the instructions of computer program 33, to request the presentation of a payment card (either by insertion into a card reader or by contactless transmission), to perform a financial transaction of zero amount, and to issue an identification assertion when this transaction is executed correctly.

[0049] For this purpose, the device includes, in addition to the buffer memory 31, means of communication, such as network communication modules, means of data transmission and an encryption processor.

[0050] These means can take the form of a specific processor implemented within the device, said processor being a secure processor. In a particular embodiment, this device implements a specific application responsible for executing transactions, this application being, for example, provided by the processor manufacturer to enable its use. To this end, the processor includes unique identification means. These unique identification means ensure the processor's authenticity.

[0051] Furthermore, the system also includes means of authorizing access to a good or service, such as means of triggering openings (doors, for example). These various means also function as communication interfaces enabling the exchange of data over communication networks, means of querying and updating databases, etc.

Claims

1. Identification method of a user for access to a good or service, i.e. for access to a protected site or access to sensitive data, the method comprising: - a step of presenting, to a terminal, by the user to be identified, a payment card; - a step of verifying that an identifier of said payment card corresponds to an expected identifier known by said terminal; the method being characterized in that it comprises, when said identifier of said payment card is recognized: - a step of executing, by the terminal, a payment transaction whose amount is zero, comprising an online transaction, that is to say by requesting authorization from a server, in which the fourth bit of the fourth byte of the "Terminal Verification Results" of the EMV protocol is set to 1, in order to force an online transaction; and - when said payment transaction is executed without error, a step of issuing an identification assertion resulting in access to the good or the service.

2. Identification method according to claim 1, characterized in that the step of executing a payment transaction of zero amount is adapted, in terms of the types of checks carried out jointly between the payment card and the terminal, according to a level of access sensitivity.

3. Identification method according to claim 1, characterized in that the step of executing a payment transaction of zero amount comprises a step of entering, by said user, a personal identification code on a keypad of the terminal.

4. Identification method according to claim 1, characterized in that the step of executing a payment transaction of zero amount comprises a step of transmitting an authorization request to a server connected to said terminal via a communication network.

5. Device for identifying a user for access to a good or a service, that is to say for access to a protected site or access to sensitive data, the device being characterized in that it comprises: • means for presenting, by the user to be identified, a payment card; • means for verifying that an identifier of said payment card corresponds to an expected identifier known by said terminal; • means for executing a payment transaction whose amount is zero, comprising means for executing an online transaction, that is to say by requesting authorization from a server, in which the fourth bit of the fourth byte of the "Terminal Verification Results" of the EMV protocol is set to 1, in order to force an online transaction; • means for issuing an identification assertion resulting in access to the good or the service.

6. Computer program product downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a microprocessor, characterized in that it comprises program code instructions for implementing a method for identification according to claim 1, when it is executed on a computer.