Method for processing an operation involving secret data, terminal, system and corresponding computer program

The method securely processes PIN entries on touchscreens by transforming touch events into random characters using a function with random server-provided numbers, addressing vulnerabilities in existing secure PIN entry methods and enhancing data protection.

FR3116920B1Active Publication Date: 2025-06-27BANKS & ACQUIRERS INT HLDG SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2020012428
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-11-30
Publication Date
2025-06-27
Estimated Expiration
2040-11-30

AI Technical Summary

Technical Problem

Existing methods for securely entering PIN codes on touchscreens in communication terminals, such as smartphones, are vulnerable due to the insecure nature of the open terminals on which these applications run, allowing potential fraud and data interception.

Method used

A method that involves transforming touch events into random characters using a transformation function that incorporates random numbers received from an intermediate transactional server, ensuring that the touchscreen terminal does not have access to the confidential data entered by the user.

Benefits of technology

This approach enhances the security of PIN entry by preventing malicious programs on the touchscreen terminal from intercepting or understanding the actual digits entered, thus ensuring the confidentiality and integrity of the payment data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000025_0000
    Figure 00000025_0000
  • Figure 00000026_0000
    Figure 00000026_0000
  • Figure 00000026_0001
    Figure 00000026_0001
Patent Text Reader

Abstract

A method is disclosed for processing data resulting from an entry on a touch screen of an electronic terminal (TermEt) comprising means for connecting to an intermediate transactional server (Sti), a method which comprises: receiving (A01) a random number (Dra, ParT), from the intermediate transactional server (Sti) via a secure connection; receiving (A02), from a touch screen controller (CtrlDT), coordinates (x,y) of support on the touch screen; transforming (A03), via a transformation function f Ts, the coordinates (x,y) of support on the touch screen, using said at least one data item representative of a random number (Dra, ParT), delivering a data item of random character (DrCa); transmitting (A04) the data item representative of a random character (DrCa) to a verification terminal. Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: DESCRIPTION

[0001] TITLE: Method for processing an operation involving secret data, terminal, system and corresponding computer program 1. Technical domain

[0002] The disclosure relates to the field of computer security. More particularly, the disclosure relates to the security and confidentiality of data processing within a communication terminal, such as a smartphone or a terminal processing sensitive data equipped with a touch screen. 1. Prior art

[0003] Since the massive adoption of intelligent communication terminals (smartphones) by a large part of the population, the idea has arisen of being able to make a payment via such a terminal. The more recent appearance on these terminals of contactless means of communication (NFC type communication interface) has made it possible to seriously consider the implementation of payment transactions directly on these terminals. The general principle that was initially envisaged consisted of using a contactless payment card that the user places on his communication terminal. A specific application, installed on the communication terminal and secured, is supposed to obtain the necessary data from the user's bank card and use this data to carry out the payment transaction.The need to secure such a transaction quickly emerged, in particular to ensure that the generated transaction is considered a "card present" transaction, a guarantee of greater security for the payment transaction. However, to deliver a "card present" transaction, it is necessary for the user's bank card to play an "active" role in the transaction, this role not being limited to a simple, contactless provision of payment data (number, name, date, validation code). Thus, the need to enter a PIN ("Personal Id-netificaiton Number") on the touch screen of the communication terminal emerged. The use of this PIN entered by the user to implement the transaction is similar to the use of this same PIN on a "classic" payment terminal (i.e. with a chip card).Manufacturers therefore began work to implement such PIN code entries on touch screens. At the same time, it quickly became clear that it was not necessarily necessary to use a payment card physically affixed to the terminal to carry out transactions. The principle of "Card On File" thus emerged, particularly for high-end communications terminals, which had more advanced security functions (including the presence of a secure execution environment - TEE - ". Trusted Execution Environment") to be able to transmit payment data. It should also be noted that this payment data can theoretically be transmitted online (i.e. via the use of a merchant application on the user's communication terminal) and contactless (by placing the user's communication terminal on a merchant's physical payment terminal). In any case, and despite advances in terms of security for the processing of this banking data by the communication terminal (with touch screen), the need to be able to enter a PIN code relating to banking data persists, as it is an additional guarantee of security.This need for PIN entry has also evolved over time, moving from a need more related to entry on a user's communication terminal, to a need related to entering a PIN on a touch screen on many types of terminals, which it would be practical to be able to use securely to be able to enter the PIN. In the context of this document, we are interested, for example, in the entry of secret information on a touchscreen terminal (of the communication terminal type), as part of a payment transaction carried out with a payment terminal (whether it is a physical terminal, at a merchant's, or a remote terminal, for example installed on a processing server implementing a payment terminal). In this configuration, the user of the communication terminal therefore uses this terminal to enter the secret information, which is then transmitted to the payment terminal (physical or remote), which validates the conformity of the secret information. In other words, we split, into two different devices (including a touchscreen terminal, not necessarily secure and a "secure" verification terminal), an operation (the entry of secret information) which until then was carried out on a single device: only a secure terminal. With these contextual considerations explained, in concrete terms, the entry of the PIN keys is carried out on a virtual keyboard on the touch screen. The virtual keyboard is presented in the form of a keyboard displayed by a (secure) application running on the touch screen terminal. A first method considered by the inventors consisted of transforming the keypress events ("touch event") of the virtual keyboard into (numeric) characters directly on the application of the touchscreen terminal, using an obfuscation principle. Despite these protective measures, this method did not withstand inspection by the laboratory in charge of the security evaluation of the application. One of the characteristics of the problem that the inventors must face is that the application responsible for managing the entry of the PIN code runs on an "open" terminal. The "open" terminal is so-called because it is managed by a user, who can install software applications of their choice on it. This possibility is offered by the publisher of the operating system of the open terminal (such as Android™ or iOS™). To the extent that it is accepted that these freely installable applications are not secure (i.e. they may include all or part of the fraudulent modules) or that the user himself may endanger the security of the open terminal by engaging in inappropriate behavior, the open terminal is by nature considered to be insecure, and therefore to potentially present risks for the operation of an application that manages confidential data, such as payment data. Thus, when assessing the security of such an application, the assessor has control over the entire touchscreen terminal on which the application that manages PIN entry is installed. A first method of solving the control problem posed by the evaluator would consist of having, within the "secure" verification terminal, a table for transforming touch events into characters. The disadvantage of this method is that it relies on a secret that is embedded in the verification terminal application, and therefore also attackable by a fraudster (or an evaluator), although such an operation is more complex. Thus, despite the theoretical possibility of using a touchscreen terminal to implement the secure entry of secret information, this possibility turns out to be, in practice, not implementable. 1. Summary of the invention

[0004] The disclosure makes it possible to respond at least in part to the problems posed by the prior art. More particularly, the disclosure relates to a method for processing data resulting from an entry on a touch screen, a method implemented within an electronic terminal comprising a touch screen on which the data is entered, said electronic terminal comprising means for connection to an intermediate transactional server. Such a method includes: • a step of receiving, from the intermediate transactional server to which the touchscreen terminal is connected via a secure link, at least one piece of data representative of a random event; • a step of receiving, from a touch screen controller, data representing coordinates (x,y) of support on the touch screen of the terminal; • a transformation step, by means of a transformation function / rs, of said data representative of coordinates (x,y) of support on the touch screen of the terminal, using said at least one data representative of a random number, delivering data representative of a character random ; • a transmission step of the data representing a random character to a verification terminal.

[0005] Thus, the disclosure offers the possibility of securely managing the entry of confidential data on an entry terminal which may be compromised, because the character conversion data is not available to the electronic terminal, which only has one or more random numbers. The touch screen terminal therefore does not have information available to it that would allow it to find the confidential code that the user wished to enter. According to a particular characteristic, the transformation step comprises the application of the following transformation function: • It is a random character obtained, which is transmitted in the form of data representing a random character; • R is a screen resolution; • x is the abscissa of the data representing coordinates (x,y); • y is the ordinate of the data representing coordinates (x,y); • a is a random number inserted in the calculation, random number obtained from said minus one data representative of a hazard;

[0006] Thus, it is not possible, even with knowledge of the function, to determine its result, since this result depends on a random variable transmitted, online, or even in real time, by the intermediate transactional server. According to a particular characteristic, the transformation function implements a random permutation, generated by the intermediate transactional server and received at least in part by the electronic terminal. According to a particular characteristic, the transformation function implements a module function, the parameters of which have been randomly determined by the intermediate transactional server and received at least in part by the electronic terminal. According to a particular characteristic, the processing method further comprises, prior to the step of receiving said at least one data item representative of a random number, an optional step of transmitting, to the intermediate transactional server, data representative of a screen resolution of the touch screen of the electronic terminal. According to a particular characteristic, the processing method is implemented during the execution of an electronic payment transaction involving the entry, by a user, of a personal identification code on the touch screen of the electronic terminal. According to another aspect, the invention also relates to an electronic terminal comprising a touch screen on which data is entered, said electronic terminal comprising means for connection to an intermediate transactional server. Such a terminal comprises: • means of receiving, from the intermediate transactional server to which the touchscreen terminal is connected via a secure link, at least one item of data representative of a random event; • means for receiving, from a touch screen controller, data representing coordinates (x,y) of support on the touch screen of the terminal; • means of transformation, by means of a transformation function / rs, of said data representative of coordinates (x,y) of support on the touch screen of the terminal, using said at least one data representative of a random number, delivering data representative of a random character; • means of transmission of data representing a random character to the intermediary transactional server.

[0007] According to another aspect, the disclosure also relates to an intermediate transactional server, a server of the type comprising a central unit, a memory and means for receiving and transmitting data from a communication network. Such a server comprises: • means of determining data representative of a resolution of a touch screen of an electronic terminal on which data must be entered; • means for generating at least one piece of data representative of a random event, optionally as a function of the data representative of a screen resolution of the touch screen of the electronic terminal; • means of transmitting said at least one piece of data representative of a random event to the electronic terminal, and • means for transmitting, to a verification terminal, a decoding table of characters entered on said touch screen of the electronic terminal.

[0008] According to another aspect, the disclosure also relates to a terminal for verifying the validity of data entered on a touch screen of a touch screen terminal, terminal of the type comprising a central unit, a memory and means for receiving and transmitting data from a communication network. Such a terminal includes: • means of receiving, from an intermediate transactional server, a decoding table of characters entered on said touch screen of the electronic terminal; • means of receiving means, from the electronic terminal comprising a touch screen, data representative of a random character obtained by the execution of a transformation function fTs, data representative of coordinates (x,y) of support on the touch screen of the terminal, to at least one data representative of a random number; • means of converting data representative of random characters into characters actually entered; • means of validating the characters actually entered for validation of a transaction.

[0009] According to another aspect, the disclosure also relates to a system for processing data resulting from an entry on a touch screen, a system comprising an electronic terminal, an intermediate transactional server and a verification terminal according to the claim as described previously. According to a preferred implementation, the different steps of the methods according to the present disclosure are implemented by one or more software or computer programs, comprising software instructions intended to be executed by a data processor of an execution terminal according to the present technique and being designed to control the execution of the different steps of the methods, implemented at the level of the communication terminal, the electronic execution terminal and / or the remote server, within the framework of a distribution of the processing operations to be carried out and determined by a scripted source code or a compiled code. Accordingly, the present technique also relates to programs, capable of being executed by a computer or by a data processor, these programs comprising instructions for controlling the execution of the steps of the methods as mentioned above. A program may use any programming language, and may be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form. The present technique also aims at an information medium readable by a data processor, and comprising instructions of a program as mentioned above. The information carrier may be any entity or terminal capable of storing the program. For example, the carrier may include a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium, for example a mobile medium (memory card) or a hard disk or an SSD. On the other hand, the information medium may be a transmissible medium such as a electrical or optical signal, which can be conveyed via an electrical or optical cable, by radio or by other means. The program according to the present technique can in particular be downloaded over a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to perform or to be used in performing the method in question. According to one embodiment, the present technique is implemented by means of software and / or hardware components. In this regard, the term "module" may correspond in this document to a software component, a hardware component or a set of hardware and software components. A software component corresponds to one or more computer programs, one or more sub-programs of a program, or more generally to any element of a program or software capable of implementing a function or a set of functions, as described below for the module concerned. Such a software component is executed by a data processor of a physical entity (terminal, server, gateway, set-top-box, router, etc.) and is likely to access the hardware resources of this physical entity (memories, recording media, communication buses, electronic input / output cards, user interfaces, etc.) Similarly, a hardware component is any element of a hardware assembly capable of implementing a function or set of functions, as described below for the module in question. It may be a programmable hardware component or one with an integrated processor for running software, for example an integrated circuit, a smart card, a memory card, an electronic card for running firmware, etc. Each component of the system described above of course implements its own software modules. The various embodiments mentioned above can be combined with each other for the implementation of the present technique. 1. Brief description of the drawings

[0010] Other characteristics and advantages will appear more clearly on reading the following description of a preferred embodiment, given as a simple illustrative and non-limiting example, and the appended drawings, among which: • [Fig.l] sets out the general principle of the method of processing data entered on a touch screen according to the present technique; • [Fig.2] shows a method of processing payment transactions in which the method of [Fig.l] is implemented; • [Fig.3] is a schematic representation of a touch screen terminal for the implementation of the data processing method previously presented; • [Fig.4] is a schematic representation of an inter-transactional server mediator for the implementation of the data processing method previously presented. 1. Detailed description

[0011] The general principle of the present technique is based on the implementation of a secret function, this function not being in the possession of the communication terminal which is used to enter the personal identification code. More particularly, the virtual keyboard is displayed on the communication terminal. This virtual keyboard displays the numbers and / or characters to be used to enter the secret information held by the user (personal identification code, password, etc.). The virtual keyboard displayed may be a standard keyboard, adapted according to the language and country of the user (the keyboard is then immediately recognized by the user). However, according to the present technique, the virtual keyboard is a keyboard specifically dedicated to entering the data required by the secure processing to be implemented. In which case, the keyboard is generated by the application requiring the secure entry.The keyboard can be displayed randomly. In other words, the keyboard keys are not necessarily displayed in the standard order. The keys can be shuffled so that they appear randomly on the touchscreen input. This makes typing more difficult for the user, but prevents fraudulent or malicious programs from inferring keystrokes based on events other than input events. Regardless of the display, the computer program in charge requires the user to enter information. According to the present technique, to prevent the entered information from being intercepted by a malicious program, a secret function is implemented within the legitimate program, to deliver a random character resulting from the user's input. In an unsecured version, as presented previously, the touchscreen data entry program transforms a touchscreen tap into {x;y} coordinates, the screen reference point traditionally being the upper left corner (which represents the {0;0} coordinates). A transformation function fTns is then used, within the program, to transform these {x;y} coordinates into an entered character. In particular, the transformation function / r„s takes into account the terminal's touchscreen resolution and transforms the input made: [Math 2] (1) In which • C s is the character entered (recognized); • R is the screen resolution; • x is the abscissa; • y is the ordinate.

[0012] In this basic version, currently widely implemented on input terminals, the / r„s function performs a transformation {x;y] into an index to determine the location of the keystroke on the virtual keyboard. Such a function is implemented, for example, by the keyboards of Google™ Gboard™ or Apple™. As explained previously, this type of unsecured function is not really usable for entering sensitive information. The inventors therefore had the idea of ​​proposing a new function so that it integrates a new parameter: this is a random parameter (a). This random parameter (a) is introduced each time a key is pressed and allows the result of the function calculation to be modified. The new function / rs is therefore: [Math 3] (2) • C sa is the random character obtained; • R is the screen resolution; • x is the abscissa; • y is the ordinate; • a is the random number inserted into the calculation.

[0013] According to the present technique, the random number is not determined by the touchscreen terminal. Indeed, an attempt is made to protect against a fraudulent program that might be installed on this terminal. It is therefore assumed that this touchscreen terminal is corrupted and therefore that its resources are potentially under the control of this fraudulent program (resources of which the random or pseudo-random generator of the terminal may be part). This random number is also not determined by the “secure” verification terminal to which the entered information is transmitted for compliance validation, because this terminal could potentially itself be under the control of a fraudulent application. Consequently, in order to protect against this type of threat, the random number (a) is received from a server to which the touchscreen terminal is connected.More specifically, the random number is received from a server that may be responsible for jointly implementing the transaction with the touchscreen terminal and / or the verification terminal. This server is called an intermediate transaction server. Thus, the technique described is partially part of the implementation of a system comprising an intermediate transactional server, a “secure” verification terminal (which can take the form of a physical terminal or a remote (i.e. virtual) terminal) and the touchscreen terminal in the possession of the user, terminal which is responsible for obtaining personal and confidential data held by the user (i.e. personal identification code, password). It should be noted that this data is not "saved" on the touchscreen terminal. In essence, this data is intended to implement a transaction requiring identification or authentication: it is therefore not in the possession of the user's touchscreen terminal and it is not envisaged that this data will be recorded by the terminal to facilitate its use (it is not, for example, a question of letting the touchscreen terminal take over to save this data securely within the terminal). It should be noted that the terminal is considered to be corrupted, so it is preferable to avoid recording this type of data there. The operation of the present technique consists of inserting a random number into the calculation function of the characters that are entered on the keyboard displayed on the touch screen terminal. To do this, the random number is determined by an intermediate transaction server, and a different random number is potentially used for each key press on the touch screen. The intermediate transaction server can transmit the random numbers in the form of a random number list [ai, a 2, a 3, a 4, a 5,... an ], when initializing the transaction with the touch screen terminal.The intermediate server may also transmit a random number after each key press, according to a method in which the first random number is transmitted by the intermediate server; then the user presses the touch screen; the terminal determines a character using the / rs function; the terminal transmits the result obtained by the fTs function to the verification terminal; upon receipt of this result, of which it is informed by the verification terminal or directly by the touch screen terminal, the intermediate server generates a new random number and transmits it to the touch screen terminal, etc. Regardless of the manner in which the random numbers are transmitted to the touch screen terminal, according to the present technique, the validation character, which is used to signify the end of the user's input (this is generally the "enter" character ("return") or an "OK" key), is not treated differently from other characters on the keyboard.A random number is also used for this validation character or function. This feature is important because it ensures that a malicious application installed on the touchscreen terminal cannot guess or infer when password entry is complete, even if this malicious application succeeds in intercepting the characters generated by the / rs function. Thus, the malicious application cannot guess, for example, the length of the password. According to the present technique, the display of the keyboard on the touchscreen terminal is managed at least partially by the intermediary server. It is the intermediary server (or the verification terminal) that instructs the password entry computer program on the touchscreen terminal to close the password or PIN entry keyboard. To do this, . the data entry computer program receives, from the intermediate server (or the verification terminal), a closing instruction encapsulated in a message. This makes it possible to limit or even eliminate the risks of takeover of the data entry computer program by a malicious application. Concretely, the transaction management application, when it starts, transmits to the intermediate server the resolution of the screen on which it is running (or any other information allowing the server to determine this resolution, such as for example an identifier of the touch screen terminal, identifier which allows the intermediate server to find the resolution of the terminal's touch screen). Depending on this resolution, the server determines a random correspondence between the key events (x,y) and the corresponding character. 1 explains the different stages of the treatment process according to the present technique. Such a treatment process comprises: • an optional step of transmitting (A00), to a transactional server, data (DRT) representative of a screen resolution of the touch screen of the touch screen terminal; this representative data can actually be a screen resolution, a terminal identifier making it possible to obtain such a resolution, from data available from the transactional server, or even an application identifier making it possible to obtain such data; this step is not obligatory, because depending on the embodiments, it is not necessary to have such a resolution to implement the technique described; • a reception step (A01), from the intermediate transactional server (Sti) to which the touchscreen terminal (TermEt) is connected via a secure link, of at least one piece of data representative of a random event (Dra, ParT), optionally as a function of the data (DRT) representative of a screen resolution of the touchscreen of the touchscreen terminal; • a reception step (A02), from a touch screen controller (CtrlDT), of data representing coordinates (x,y) of pressure on the touch screen of the terminal; this is for example a pressure made with a finger from a user entering a password or a personal identification code; • a transformation step (A03), via the transformation function fTs, of said data representing coordinates (x,y) of support on the touch screen of the terminal, using said at least one data representative of a random number (Dra, ParT), delivering data representative of a random character (DrCa); • a transmission step (A04) of the data representative of a random character (DrCa) to the verification terminal.

[0014] In an exemplary embodiment, the implementation of the randomness is implemented by a random permutation. A random permutation is drawn by the intermediate server, and each character is chosen as an element of this chosen permutation. The intermediate server transforms this function into a table and transmits it to the verification terminal, for example at the initialization of the transaction (i.e. after the establishment of the secure connection with the intermediate server). The intermediate server then transmits to the application the "randomness" (a) which makes it possible to select the permutation in the permutation table. A different permutation table can be transmitted for each character entered.Two distinct variants can be implemented in the case of this random permutation: the first variant consists of performing a random permutation of characters, directly from the keyboard characters, for example a "qwerty" keyboard will have a permutation "rteywq" (voluntarily limited example) or a "1234567890" keyboard will have a permutation "8463917205"; the second variant consists of performing a random permutation of the key presses (x,y coordinates); which is more efficient in terms of security, but also more voluminous in terms of data to be transmitted. In another exemplary embodiment, the implementation of the randomness is implemented by a technique of drawing randomness and applying a modulus (i.e. applying a modulus to the number obtained), the modulus also being random. More particularly, the modulus (modulo) is randomly obtained by the intermediate server (for example "34") and a randomness (for example "29) is also randomly determined within the interval between 1 and the random modulus (here "34"). In such a case, there are two randomnesses: the modulus M t and the randomness in the modulus a M. They are transmitted to the application responsible for input on the touch screen terminal. Taking the previous example: the user presses the key for the character "c" with value "9": the obfuscated function / rs calculates (c+ a M ) modulo M;, i.e. (9+29). mod(34)=4 and transmits 4 to the verification terminal. For the next character, a new modulo and a new random number are used.The moduli, as in the previous case of random permutation, can be transmitted in advance (like the permutation table) or a modulus can be transmitted for each character. The advantage of this second implementation example, compared to the first, is that it can transmit two short random values ​​for each character, which is not necessarily possible with random permutation, particularly when the keyboard is extended (case of a full keyboard of the "azerty" or "qwerty" type for entering a password for example). In another example of implementation, both the technique of per random mutation and the modulus technique. This can for example be the case for a keyboard of numeric characters (ten characters from [0] to [9]) and two function keys ("Cancel", Validate"), i.e. twelve keys in total. In this situation The obfuscated fTs function allows from a keypress event {x;y} to generate a random index. This involves a first step which transforms the keypress into an index between zero and twelve. With these twelve characters, we can calculate modulo 13 (prime number), so we can generate permutations of this number quite easily. A permutation is generated: the function / rs is a random permutation that is composed of an affine transformation based on two random numbers that are taken from randomness, and they are used "modulo 13". With this modulo 13, any random function creates a permutation. We therefore manage to permute with only two numbers all the characters on the keyboard and we simply obtain a random permutation. As previously stated, the randomness comes from the intermediate transactional server. The server knows the fTs function, so it is able to calculate the correspondence and provide a reverse conversion table to the verification terminal. As a result, the verification terminal does not have the logic since it does not implement an affine modulo 13 function. It only implements access to one or more tables, which come from the server and which are modified each time a PIN is entered, or even each time a character is entered. Thus, even if an attacker masters the verification terminal software, the only information that will be obtained is access to a table, not recorded in this software. The communication terminal implements the logic for key entry and transmission of entered random characters to the verification terminal. It implements this using randomness from the intermediate transaction server and optionally, for increased security, using obfuscation methods (thus, this function fTs function that transforms a key press into a character is completely obfuscated). Obfuscation makes reverse and understanding very difficult. The fTs function is embedded in or accessible to the mobile application in an obfuscated form (very difficult to understand). Either this function is available, in the form of an API, from the application, or this function is directly integrated into the application itself. Ideally, this function is implemented within a secure execution element of the touchscreen terminal ("secure element") or a trusted execution environment ("TEE"), in order to further protect against fraud attempts. Such an implementation is described below, although it is not mandatory to guarantee the primary security effect obtained by the obfuscated function / Ts. Regardless of the randomness implementation mode, each time the application's virtual keyboard is pressed, the random character is generated by the obfuscated fTs function embedded or accessible for the mobile application. Each time a password or character is entered, a new correspondence table can be calculated, thus effectively protecting the entered password. For example, at the first character entry, the user wishes to enter the key '1'. This key corresponds, after transformation by the obfuscated fTs function, to the random character '6'. The mobile application transmits, via the secure transmission channel, the number '6' to the verification terminal, which by applying the inverse function fTs 7 transforms the entry back into '1' (i.e. by using the table received from the intermediate server). At the next press, if the user wishes to press the key '1' again, a new corresponding key '9' is obtained by the obfuscated fTs function. The verification terminal, by applying the inverse transformation fTs 7 again, obtains a '1' (by simply accessing an inverse permutation table transmitted by the intermediate transactional server).In relation to 2, a method is described for implementing a financial transaction, using a touchscreen terminal, requiring, for the implementation of this transaction, in particular the obtaining of payment data from a means of payment presented by a user (the example of a contactless payment card is used). In the method presented in 2, the function fTs is implemented for entering a PIN code in conjunction with obtaining data from the contactless card. It is noted that the method can also be implemented with a contact card (conventional payment terminal having a touchscreen for entering the PIN code) or for a payment made via a user's communication terminal (with or without the use of a payment card, the payment data possibly already being recorded within the mobile terminal, i.e. in the form of a "card on file").Such a method includes: . • a step (10) to start the transaction • an establishment step (20), with the intermediate transactional server, of a secure communications link; • a reception step (30), from the intermediate transactional server, of the transaction configuration data (ParT), including the random event(s) and its parameters; • a step of obtaining (40) payment data (PyD), comprising for example: • a display step (40-1), on the screen of the screen terminal, of a request to place a payment card on the screen terminal tactile; • a step of reading (40-2) the data coming from the payment card affixed to the touch screen terminal; • a step of displaying (50) a virtual keyboard (Vk) requiring the entry of a personal identification code; • a step (60) of entry, by the user, of a plurality of digits of the personal identification code, on the virtual keyboard (Vk), comprising the use of the function fTs and the data of the configuration (ParT) of the transaction delivering a series (SCa) of random digits; • a transmission step (70), to the verification terminal, via the secure channel (or another channel), of the series of random numbers (SCa); the transmission step is either implemented once, for the entire series, or implemented as soon as a number is entered by the user; • a decoding step (80), by the verification terminal, of the series of random digits (SCa), delivering the series of original digits (SCo); • a validation step (90) of the transaction by the verification terminal; • a step of transmitting (100) the result of validation of the transaction to the touch screen terminal and step of displaying, by the touch screen terminal, this result.

[0015] Thus, even if the touchscreen terminal is infected or compromised, it is not possible to intercept and correctly understand what the actual digits entered by the user for the PIN code are, because these digits are randomly generated by the transformation function at the time of entry. In relation to 3, a simplified architecture of a touch screen terminal (TermEt) capable of processing a transaction as presented previously is presented. A touch screen terminal comprises a memory 31, a processing unit 32 equipped for example with a microprocessor, and controlled by a computer program 33. The touch screen terminal optionally comprises: a secure memory 34, which can be merged with the memory 31 (as indicated by dotted lines, in this case the memory 31 is a secure memory), a secure processing unit 35 equipped for example with a secure microprocessor and physical protection measures (physical protection around the chip, by lattice, vias, etc.and protection on the data transmission interfaces), and driven by a computer program 36 specifically dedicated to this secure processing unit 35, this computer program 36 implementing all or part of the method for processing a transaction as previously described. The group composed of the secure processing unit 35, the secure memory 34 and the dedicated computer program 36 constitutes the secure portion (PS) of the touch screen terminal. In at least . In one embodiment, the present technique is implemented in the form of a set of programs installed in part or in full on this secure portion of the transaction processing terminal. In at least one other embodiment, the present technique is implemented in the form of a dedicated component (CpX) capable of processing data from the processing units and installed in part or in full on the secure portion of the transaction processing terminal. Furthermore, the terminal also comprises communication means (CIE) presented for example in the form of network components (WiFi, 3G / 4G / 5G, wired) which allow the terminal to receive data (I) from entities connected to one or more communication networks and to transmit processed data (T) to such entities. Such a terminal comprises, depending on the embodiments: • means of obtaining data from transactional devices presented by users (access card, transaction card, etc.; these means may be presented, for example, in the form of a smart card reader, or even contactless card readers of the NFC or RFID type); • means of obtaining randomness and setting randomness parameters from an intermediate transactional server; • input means, allowing the user to enter one or more data for the implementation of the transaction, when necessary (in particular means of generating a keyboard on a touch screen) • means of processing data obtained by means of obtaining data from transactional devices and means of processing data entered by users; • means of implementing an obfuscated secret transformation function / Ts,; • means of providing data to one or more verification terminals;

[0016] As explained previously, these means are for example implemented via modules and / or components, for example secure ones. They thus make it possible to ensure the security of the transactions carried out while guaranteeing greater maintainability of the terminal. In relation to 4, a simplified architecture of an intermediate transactional server (STi) capable of processing a transaction as presented previously is presented. An intermediate transactional server (STi) comprises a memory 41, a processing unit 42 equipped for example with a microprocessor, and controlled by a computer program 43. Furthermore, the intermediate transactional server mediator (STi) also includes means of communication (CIE) presented for example in the form of network components (WiFi, 3G / 4G / 5G, wired) which allow the intermediate transactional server (STi) to receive data (I) from entities (transactional terminal, decision-making server) connected to one or more communication networks and to transmit processed data (T) to such entities. Such an intermediate transactional server (STi) comprises, depending on the embodiments: • means for determining a resolution of a touch screen of a terminal on which data must be entered; • means for generating at least one data item representative of a random event (Dra, ParT), optionally as a function of data (DRT) representative of a screen resolution of the touch screen of the electronic terminal (TermEt); • means of transmitting said at least one piece of data representative of a random event (Dra, ParT) to the electronic terminal (TermEt), and • means of transmitting, to a verification terminal, a decoding table of characters entered on said touch screen of the Electronic Terminal (TermEt).

[0017] A verification terminal capable of processing a transaction as presented above, comprises a memory, a processing unit equipped for example with a microprocessor, and controlled by a computer program. The touch screen terminal also comprises: a secure memory, which can optionally be merged with the memory, a secure processing unit equipped for example with a secure microprocessor and physical protection measures (physical protection around the chip, by lattice, vias, etc. and protection on the data transmission interfaces), and controlled by a computer program specifically dedicated to this secure processing unit, this computer program implementing all or part of the method for processing a transaction as previously described.The group consisting of the secure processing unit of the secure memory and the dedicated computer program constitutes the secure portion of the touchscreen terminal. In at least one embodiment, the present technique is implemented in the form of a set of programs installed in part or in full on this secure portion of the transaction processing terminal. In at least one other embodiment, the present technique is implemented in the form of a dedicated component capable of processing data from the processing units and installed in part or in full on the secure portion of the transaction processing terminal. Furthermore, the terminal also comprises communication means presented for example in the form of network components (WiFi, 3G / 4G / 5G, wired). which allow the terminal to receive data from entities connected to one or more communication networks and to transmit processed data to such entities. Such a verification terminal comprises, depending on the embodiments: • means for receiving, from the electronic terminal (TermEt) comprising a touch screen, data representative of a random character (DrCa) obtained by the execution of a transformation function / rs, data representative of coordinates (x,y) of support on the touch screen of the terminal, using said at least one data representative of a random character (Dra, ParT); • means of converting data representing random characters (DrCa) into characters actually entered, this means being presented in particular in the form of a reverse conversion table transmitted by the intermediate transactional server; • means of validating the characters actually entered for validation of a transaction, such as a payment transaction.

Claims

Claims

1. Method for processing data from an entry on a touch screen, method implemented within an electronic terminal (TermEt) comprising a touch screen on which the data is entered, said touch screen being capable of displaying a virtual keyboard comprising a plurality of keys corresponding to numeric characters and a key corresponding to a validation character, said electronic terminal (TermEt) comprising a module for connection to an intermediate transactional server (Sti) which is capable of generating and transmitting to the electronic terminal (TermEt) data representative of a succession of random events distinct from one another, method characterized in that it comprises: • a first reception step (A01), from the intermediate transactional server (Sti) to which the electronic terminal (TermEt) is connected via a secure link, of data representative of a random event (Dra, ParT); • a step of receiving (A02), from a controller (CtrIDT) of the touch screen of the electronic terminal (TermEt), data representing coordinates (x,y) of a press of a first type on the touch screen of the electronic terminal (TermEt), said press of the first type being carried out on a key corresponding to a numeric character of the virtual keyboard displayed on the touch screen of the electronic terminal (TermEt); • a transformation step (A03), by means of a transformation function fTs, of said data representative of coordinates (x,y) of the support of the first type on the touch screen of the electronic terminal (TermEt), using the data representative of a random number (Dra, ParT) received in the first reception step (A01), delivering data representative of a random character (DrCa) corresponding to a digital character; • a transmission step (A04) of the data representative of the random character (DrCa) corresponding to a digital character to a verification terminal; • at least a second reception stage, coming from the intermediate transactional server (Sti) to which the electronic terminal (TermEt) is connected via a secure link, of data representing a random event (Dra, ParT) distinct from the data representing a random event (Dra, ParT) received at the first reception step (A01); • a step of receiving, from the controller (CtrlDT) of the touch screen of the electronic terminal (TermEt), data representing coordinates (x,y) of a press of a second type on the touch screen of the electronic terminal (TermEt), said press of the second type being carried out on the key corresponding to the validation character of the virtual keyboard displayed on the touch screen of the electronic terminal (TermEt); • a transformation step, via the transformation function fTs, of the data representing coordinates (x,y) of the support of the second type on the touch screen of the electronic terminal (TermEt), using the data representing a random element (Dra, ParT) received at T at least a second reception step, delivering data representing a random character (DrCa) corresponding to the end of an entry; • A transmission step of the data representative of the random character (DrCa) corresponding to the end of entry at the verification terminal.

2. Processing method according to claim 1 characterized in that the transformation step (A03) comprises the application of the following transformation function: Csa= fTs (R, x,y, a) Csa is a random character obtained, which is transmitted in the form of data representing a random character (DrCa); R is a screen resolution; x is the abscissa of the data representing coordinates (x,y); y is the ordinate of the data representing coordinates (x,y); a is a random value inserted in the calculation, random value obtained from said data representing a random value (Dra, ParT).

3. Treatment method according to claim 2 characterized in that the transformation function implements a random permutation, generated by the intermediate transactional server (Sti) and received at least in part by the electronic terminal (TermEt).

4. Processing method according to claim 2 characterized in that the transformation function implements a module function, the parameters of which have been randomly determined by the intermediate transactional server (Sti) and received at least in part by the electronic terminal (TermEt).

5. Processing method according to claim 1 characterized in that it further comprises, prior to the step of receiving (A01), said at least one data item representative of a random number (Dra, ParT), an optional step of transmitting (A00), to the intermediate transactional server (STi), data (DRT) representative of a screen resolution of the touch screen of the electronic terminal (TermEt).

6. Processing method according to claim 1 characterized in that it is implemented during the execution of an electronic payment transaction involving the entry, by a user, of a personal identification code (PIN) on the touch screen of the electronic terminal (TermEt).

7. Electronic terminal (TermEt) comprising a touch screen capable of displaying a virtual keyboard comprising a plurality of keys corresponding to numeric characters and a key corresponding to a validation character, said electronic terminal (TermEt) comprising a module for connection to an intermediate transactional server (Sti), terminal characterized in that it comprises: • a module for receiving, from the intermediate transactional server (Sti) to which the touch screen terminal (TermEt) is connected via a secure link, data representative of a succession of random events distinct from one another (Dra, ParT);• a module for receiving, from a touch screen controller (CtrIDT) of the touch terminal (TermEt), data representing coordinates (x,y) of presses on the touch screen of the terminal, at least one of said presses, of a first type, being made on a key corresponding to a numeric character of the virtual keyboard displayed on the touch screen of the electronic terminal (TermEt) and another of said; presses, of a second type, being made on the key corresponding to the validation character of the virtual keyboard displayed on the touch screen of the electronic terminal (TermEt); • a transformation module, implementing a transformation function fTs, of said data representative of coordinates (x,y) of presses on the touch screen of the electronic terminal (TermEt), using data representative of a succession of random events distinct from each other (Dra, ParT), the transformation module delivering data representative of random characters (DrCa); • a transmission module, data representative of random characters (DrCa) to a verification terminal.

8. Intermediate transactional server, server of the type comprising a central unit, a memory and a module for receiving and transmitting data from a communication network, server comprising: a module for determining data (DRT) representative of a resolution of a touch screen of an electronic terminal (TermEt) on which data must be entered; a module for generating data representative of a succession of random events distinct from one another (Dra, ParT), optionally as a function of the data (DRT) representative of a screen resolution of the touch screen of the electronic terminal (TermEt); a module for transmitting data representative of the succession of random events distinct from one another (Dra, ParT) to the electronic terminal (TermEt), and a module for transmitting, to a verification terminal, a decoding table of characters entered on said touch screen of the electronic terminal (TermEt).

9. Terminal for verifying the validity of data entered on a touch screen of a touch screen terminal, terminal of the type comprising a central unit, a memory and a module for receiving and transmitting data from a communication network, verification terminal comprising: • a reception module, from an intermediate transactional server, of a decoding table of characters entered on said touch screen of the Electronic Terminal (TermEt) • a module for receiving, from the electronic terminal (TermEt) comprising a touch screen, data representing a random character (DrCa) corresponding to a numeric character, obtained by executing a transformation function fTs, data representing coordinates (x,y) of a press of a first type on the touch screen of the electronic terminal (TermEt), using data representing a first random number (Dra, ParT) received in a first reception step (A01), said press of the first type being carried out on a key corresponding to a numeric character of a virtual keyboard displayed on the touch screen of the electronic terminal (TermEt), and data representing a random character (DrCa) corresponding to the end of input, obtained by executing a transformation function fTs, data representing coordinates (x,y) of a press of a second type on the touch screen of the electronic terminal (TermEt),using at least one piece of data representative of a random number (Dra, ParT) received at at least one second reception step and distinct from the data representative of a random number received at the first reception step (A01), said press of the second type being carried out on the key corresponding to the validation character of the virtual keyboard displayed on the touch screen of the electronic terminal (TermEt).; • a module for converting the data representative of the random characters (DrCa) into characters actually entered; • a module for validating the characters actually entered for validation of a transaction.,

10. System for processing data resulting from an entry on a touch screen, system characterized in that it comprises an electronic terminal (TermEt) according to claim 7, an intermediate transactional server according to claim 8 and a verification terminal according to claim 9.

11. Computer program product downloadable from a communications network and / or stored on a computer-readable medium and / or executable by a microprocessor, characterized in that it comprises program code instructions for executing a method of treatment according to one of claims 1 to 6, when executed on a computer.