Smart card with optoelectronic transducer.
The smart card with an optoelectronic transducer addresses the challenges of contactless PIN entry by generating a digital code from light blockages, ensuring secure transactions without terminal modifications or databases, enhancing user experience and security.
Patent Information
- Application Number
- FR2023001204
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-02-09
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-02-09
AI Technical Summary
Existing contactless payment transactions with PIN code entry on payment terminals are cumbersome, require software updates, and pose health risks due to shared use, while online PIN solutions complicate user experience and necessitate secure database implementation.
A smart card with an optoelectronic transducer, such as a photodiode or phototransistor, generates a digital code based on the sequence of light blockages, allowing secure contactless transactions without modifying payment terminals or databases, using the optoelectronic transducer to convert light intensity into a digital code for authentication.
Enables secure contactless transactions without PIN code entry on terminals, eliminating payment limits and health risks, and avoids the need for terminal updates or secure databases, enhancing user experience and security.
Smart Images

Figure 00000013_0000 
Figure 00000013_0001 
Figure 00000013_0002
Abstract
Description
Title of the invention: Chip card with optoelectronic transducer.
[0001] The invention relates to the field of contactless payment transactions.
[0002] For the purposes of the present invention, the chip card is a bank card.
[0003] In the world of payment cards, transactions are classified into two main groups: the “card present” or CP group, and the “card not present” or CNP group.
[0004] A CNP transaction is carried out for example when the buyer and the seller are distant from each other, for example during an online transaction.
[0005] A CP transaction is carried out for example when the buyer, who holds a means of payment, for example a bank card or a payment application on a smartphone, and the seller are present at the same location. For example, a payment on a payment terminal by a smartphone on which a payment application is installed is a CP payment while the chip card is not present.
[0006] In fact, a CP transaction captures transaction details automatically, unlike a CNP transaction.
[0007] The transaction can be carried out in two main ways: - With contact, by inserting the bank card into a terminal, generally with entry and verification of the PIN code, - Contactless, thanks to a contactless reader.
[0008] The present invention particularly relates to CP type payment transactions in contactless mode with a card.
[0009] In this area, certain transactions are possible without entering and verifying the PIN code, but in this case there is generally a payment limit, in order to limit the risks in the event of loss or theft of the bank card.
[0010] In other cases, the PIN code may be requested from the cardholder. These are contactless CP transactions with a card, known as "online PIN". The PIN code must then be entered on a terminal. Typically, the terminal is a payment terminal, known as a POS, an acronym for "Point Of Sale" or TPE for Electronic Payment Terminal.
[0011] The PIN code is then stored temporarily and verified not on the card but remotely in a secure database, by comparison with a reference PIN stored in it.
[0012] The online PIN solution makes it possible to increase, or even eliminate, the payment limit implemented for transactions without entering and verifying the PIN code.
[0013] However, the online PIN solution has a number of constraints, including the need to update payment terminal software and to organize the securing of online PIN code verification as well as the secure storage of reference PIN codes.
[0014] Furthermore, in terms of user experience, entering the PIN code on a payment terminal is contradictory to the contactless function.
[0015] Finally, the use of the same payment terminal by a number of individuals can also raise health issues.
[0016] The present invention aims to improve this state of affairs.
[0017] In this context, the present invention relates, according to a first of its objects, to a smart card configured to be able to carry out contactless banking transactions, comprising:
[0018] • a support comprising a front side often comprising personal data relating to the cardholder and a reverse side,
[0019] • a module comprising a secure element in which a secret code is recorded (PINE),
[0020] • an antenna.
[0021] It is essentially characterized in that it further comprises:
[0022] • an optoelectronic transducer, electrically connected to the secure element.
[0023] The optoelectronic transducer may be electrically powered by an electrical energy source, for example by the antenna, by a Vcc output of the secure element or of another microcontroller, etc.
[0024] It can be provided that the optoelectronic transducer emits an analog output signal, the card further comprising an analog-to-digital converter, configured to convert the analog output signal of the optoelectronic transducer into a digital signal sent to the secure element.
[0025] It is also possible to provide a resistor connected in series with the optoelectronic transducer, configured to saturate the latter.
[0026] It can be provided that the optoelectronic transducer is accessible via the front face or the back face of the card, the surface dimensions of the optoelectronic transducer being less than 1 cm2, so that it can be blocked by an adult finger.
[0027] It can be provided that the optoelectronic transducer is a photodiode or a phototransistor.
[0028] The optoelectronic transducer generates an output signal whose current is proportional to the number of photons received.
[0029] Thus, when the optoelectronic transducer is temporarily closed and electrically powered, the output signal of said optoelectronic transducer has the shape of a respective peak at each closure,
[0030] It can be provided that the secure element is configured to detect a set of peaks of said output signal whose current value is beyond a threshold whose value is predetermined, in a predetermined time window, the threshold being constant or adaptive.
[0031] It may be provided that the secure element is configured to determine the sequence of peaks included in the predetermined time window, the sequence of peaks being defined by at least one of the following characteristics of the peaks:
[0032] • the number of consecutive peaks;
[0033] • the duration of each peak;
[0034] • the time interval between two consecutive peaks.
[0035] It can be provided that the secure element is configured to:
[0036] • Generate a candidate digital code, said candidate digital code being a function of the determined peak sequence;
[0037] • compare the candidate code to the secret code (PIN); and
[0038] • emit a signal representative of the result of the comparison.
[0039] Preferably said signal is binary and sent to a payment terminal.
[0040] According to another of its objects, the invention relates to a method for securing a contactless banking transaction with a chip card according to the invention, comprising steps consisting of:
[0041] • Position the card in the magnetic field of a payment terminal,
[0042] • Supply power to the card via the payment terminal,
[0043] • Optionally emit a signal inviting entry of the secret code on a device sphere in electrical contact with the payment terminal,
[0044] • Sequentially close the optoelectronic transducer,
[0045] • Generate a candidate digital code, said candidate digital code being a function of the sequence of shutters,
[0046] • compare the generated candidate code to the secret code (PIN) recorded in the element secure chip card, and
[0047] • emit a binary signal representative of the result of the comparison.
[0048] A step can be provided consisting of authorizing the transaction only if the generated candidate code is equal to the secret code (PIN).
[0049] Thanks to the present invention, there is no need to modify current payment terminals or update their firmware. There is also no need to implement a secure database to store reference PIN codes.
[0050] Other characteristics and advantages of the present invention will appear more clearly on reading the following description given by way of illustrative and non-limiting example and made with reference to the appended figures.
[0051] The figures are not to scale. Some details have been omitted and others enlarged, to make it easier to understand.
[0052] DESCRIPTION OF THE DRAWINGS
[0053] [Fig. 1] illustrates a smart card according to the prior art,
[0054] [Fig.2] illustrates an embodiment of a smart card according to the invention,
[0055] [Fig.3] illustrates an embodiment of the electrical connection of a transducer optoelectronics according to the invention with a secure element,
[0056] [Fig.4] illustrates another embodiment of the electrical connection of a optoelectronic transducer according to the invention with a secure element,
[0057] [Fig.5] illustrates an output signal, in light intensity, after blocking of an optoelectronic transducer according to the invention,
[0058] [Fig.6] illustrates an optoelectronic transducer according to the invention. Detailed description
[0059] [Fig.l] a smart card according to the prior art. Conventionally, a smart card 100 comprises a support and meets standards.
[0060] The support comprises a front face and a back face, the front face often comprising data, in particular personal data relating to the card holder, in this case individual data 140 of the card holder, at least the name 142 and first name 141 of the holder of the smart card 100.
[0061] The front side of the smart card 100 also generally includes a card number 120. In general, the number 120 is a 16-digit, unique, generally standardized number.
[0062] The smart card 100 also comprises a module 110, allowing secure transactions to be established. The module 110 notably comprises a secure element. A secret code (PIN code) is stored in a memory of the secure element, and sometimes online, and in a manner known per se, the completion of a transaction can be dependent on the entry of the PIN code.
[0063] For security reasons, the smart card 100 also includes an expiration date 130.
[0064] In a manner not illustrated, the smart card 100 also comprises an antenna 160 which makes it possible to electrically power the module using the antenna when the smart card 100 is powered by a terminal. The smart card 100 is positioned in the magnetic field of a payment terminal, generally on a specific surface thereof. However, this power supply mode is called “contactless” as opposed to the “contact” mode in which metal tips come into contact with the module of the smart card 100. The smart card 100 may comprise a concentrator in electrical connection with the antenna.
[0065] According to the invention, illustrated [Fig.2], the smart card 100 further comprises a optoelectronic transducer, the operation of which is described later.
[0066] The optoelectronic transducer is electrically connected to the secure element and indirectly supplied with electrical energy by the antenna.
[0067] For example, the optoelectronic transducer is provided to be a photodiode or a phototransistor.
[0068] The optoelectronic transducer emits an output signal, which can be analog or digital, and which is sent to the secure element.
[0069] When the output signal is analog, an analog-to-digital converter is preferably provided, configured to convert the output signal of the optoelectronic transducer into a digital signal.
[0070] A first variant of the electrical connection of an optoelectronic transducer with a secure element is illustrated in [Fig.3].
[0071] The secure element is supplied with electrical energy by an antenna using specific ports La and Lb, known per se.
[0072] The optoelectronic transducer is supplied with electrical energy by a Vcc_Out port of the secure element.
[0073] The output signal of the optoelectronic transducer is transmitted to the secure element on a standard GPIO (general purpose input-output) communication port.
[0074] A resistor 170 may be provided, mounted in series with the optoelectronic transducer, configured to saturate the latter.
[0075] A second variant of the electrical connection of an optoelectronic transducer with a secure element is illustrated in [Fig.4].
[0076] The secure element is always supplied with electrical energy by an antenna using specific ports La and Lb, known per se.
[0077] The optoelectronic transducer is also supplied with electrical energy by a Vcc_Out port of the secure element.
[0078] But in this variant, the output signal of the optoelectronic transducer is transmitted to the secure element on at least one standard GPIO (general purpose input-output) communication port, in this case on two communication ports according to the I2C protocol. Other protocols can be provided, in particular SPI, UART or CAN.
[0079] As illustrated in [Fig.2], the optoelectronic transducer is accessible from the front side of the card. It can obviously be provided that it is accessible from the back side.
[0080] In this case the dimensions of the accessible surface of the optoelectronic transducer are less than 1 cm2, so that when an adult finger is placed on the optoelectronic transducer, the latter is blocked by the finger. Of course, the optoelectronic transducer can be blocked by means other than a finger.
[0081] Preferably, the accessible surface of the optoelectronic transducer has a polygonal or oval shape or even disc-shaped.
[0082] When closed, the optoelectronic transducer generates an output signal whose current is proportional to the number of photons received. It is also possible to provide, or process the signal so that the optoelectronic transducer generates an output signal whose current is inversely proportional to the number of photons received.
[0083] Overall, the output signal has the shape of a peak at each shutter of the optoelectronic transducer, as illustrated in [Fig. 5]. By "peak" is meant a shape with steep slopes, i.e. pointed or square, depending on the duration of the shutter.
[0084] [Fig. 5] illustrates an output signal 180 of the optoelectronic transducer. In this case, the output signal 180 is the temporal evolution of the light intensity at the input of the optoelectronic transducer. When the optoelectronic transducer is exposed to ambient light, the output signal 180 is saturated. When the optoelectronic transducer is blocked, for example by a finger, the light intensity decreases, then increases again when the blocking ceases. Thus, a temporary blocking of the optoelectronic transducer leads to a variation in light intensity at its input which results in a peak-shaped output signal. A sequence of blockings therefore generates a sequence of peaks, each blocking generating a respective peak.
[0085] As stated previously, to avoid artifacts, only peaks whose value crosses a threshold value 190 are selected.
[0086] Other responses of the optoelectronic transducer can be provided, i.e. other output signals, for example in current or voltage.
[0087] To avoid artifacts, provision is preferably made to select only the peaks whose (absolute) value crosses a threshold. To this end, provision is made for the secure element to be configured to detect a set of peaks of the output signal whose current value is beyond a threshold whose value is predetermined, within a predetermined time window.
[0088] It can be expected that the threshold is constant.
[0089] It is also possible to provide that the threshold is adaptive. For example, the threshold is calculated by an algorithm, for example as a function of the exposure time to the measured brightness, which makes it possible in particular to detect a bright environment (for example in summer) or a dark environment (for example in winter, or inside a poorly lit building).
[0090] It is advantageously provided that the algorithm implemented by the secure element makes it possible not only to detect the peaks, but also their sequence and their characteristics.
[0091] For this purpose, it can be provided that the secure element is configured to determine the sequence of peaks included in a predetermined time window, the sequence of peaks being defined by at least one of the following characteristics:
[0092] • the number of consecutive peaks;
[0093] • the duration of each peak;
[0094] • the time interval between two consecutive peaks.
[0095] For example, [Fig.5] illustrates an example of an output signal from the optoelectronic transducer in a predetermined time window.
[0096] In this case [Fig.5] illustrates a total number of 4 consecutive peaks.
[0097] But the number of consecutive peaks may not be enough to determine a code, it is better to take into account a time component.
[0098] Thus, it is preferably planned to also take into account the duration of each peak.
[0099] The first peak has a first time value, typically the half-height interval or the time interval between the rising edge and the falling edge, corresponding to the duration during which the optoelectronic transducer was first blocked.
[0100] The second peak has a second time value, corresponding to the duration during which the optoelectronic transducer was blocked a second time.
[0101] The third peak shows a second time value, corresponding to the duration during which the optoelectronic transducer was blocked a third time.
[0102] The fourth peak has a second time value, corresponding to the duration during which the optoelectronic transducer was blocked a fourth time.
[0103] Advantageously, the algorithm can also take into consideration the time interval between two consecutive peaks.
[0104] We thus have a sequence, a rhythm, which can correspond to a code, for example like Morse code.
[0105] The algorithm can thus transform the output signal of the optoelectronic transducer into a digital code, in this case a candidate digital code, depending on the determined sequence of peaks.
[0106] It is then possible to compare the candidate code with a secret code recorded in a memory of the secure element (or online), for example the PIN code of the smart card. The recorded secret code may be different from the PIN code. In this case, this comparison step is implemented by the secure element of the smart card.
[0107] Then it is advantageous to provide for the emission of a signal representative of the result of the comparison. Preferably, this signal representative of the result of the comparison is a binary signal, such that the candidate digital code is considered to be equal to the secret code, or not.
[0108] Thus, the optoelectronic transducer is used as a one-touch keyboard that allows for the implementation of a “what I know” authentication factor, which is entered thanks to the sequential shuttering of the latter, the sequence of shutterings of the optoelectronic transducer corresponding to a secret code.
[0109] Preferably, the secret code comprises several digits.
[0110] As explained previously, the entry of a digit corresponds to a sequence of peaks. To distinguish the entry of a digit of the secret code from the entry of the previous digit, a minimum delay, i.e. greater than a predetermined value between two peaks, can be provided. For example, in [Fig. 5], the first peak corresponds to the first digit of the secret code, and the second, third and fourth peaks correspond to the second digit of the secret code, the time interval between the first peak and the second peak being greater than a predetermined value.
[0111] It can be provided that the detection of the secret code by the sequence of shutters of the optoelectronic transducer is controlled by a trigger.
[0112] For example, it can be provided that the trigger activates the optoelectronic transducer or activates the detection of the shutter sequence.
[0113] For example, it can be provided that the trigger is the activation of one of the standard commands when a chip card is placed on a payment terminal, for example the PIN code query command.
[0114] Thus, the present invention can be implemented on a standard payment terminal, with a standard command.
[0115] Provision may be made to emit a signal inviting entry of the candidate secret code on a peripheral in electrical contact with the payment terminal, for example by a visual device such as a set of at least one LED or a display screen, or by an audible device such as a loudspeaker or a buzzer.
[0116] If the candidate secret code is equal to the recorded secret code, for example the PIN code, then the secure element returns a corresponding signal, in this case the “PIN OK” command to the payment terminal.
[0117] Preferably, the transaction is dependent on the result of the comparison of the candidate secret code and the recorded secret code. Nomenclature
[0118] 100 smart card
[0119] 110 module
[0120] 111 secure element
[0121] 120 smart card number
[0122] 130 smart card expiry date
[0123] 140 individual data of the smart card
[0124] 141 first name of the smart card holder
[0125] 142 name of the smart card holder
[0126] 150 optoelectronic transducer
[0127]
[0128]
[0129]
[0130] 160 antenna 170 resistance 180 optoelectronic transducer output signal 190 threshold value
Claims
Claims
1. Smart card (100) configured to be able to carry out contactless banking transactions, comprising: • a support comprising a front face comprising personal data relating to the cardholder and a back face, • a module (110) comprising a secure element (111) in which a secret code (PIN) is recorded, • an antenna (160), and • an optoelectronic transducer (150), electrically connected to the secure element (111), characterized in that: • when it is closed, the optoelectronic transducer (150) generates an output signal (180) whose current is proportional to the number of photons received, said signal having the shape of a respective peak at each closing of said transducer, • And in which the secure element (111) is configured to detect a set of peaks of said output signal (180) whose value crosses a threshold whose value is predetermined,within a predetermined time window, the threshold being constant or adaptive.,
2. Card according to claim 1, wherein the optoelectronic transducer (150) emits an analog output signal (180), the card further comprising an analog-to-digital converter, configured to convert the analog output signal of the optoelectronic transducer (150) into a digital signal sent to the secure element (111).
3. A card according to any preceding claim, further comprising a resistor (170) connected in series with the optoelectronic transducer (150), configured to saturate the latter.
4. A card according to any preceding claim, wherein the optoelectronic transducer (150) is accessible from the front or back of the card, the surface dimensions of the optoelectronic transducer (150) being less than 1 cm2, so that that it can be closed by an adult finger.
5. A card according to any preceding claim, wherein the optoelectronic transducer (150) is a photodiode or a phototransistor.
6. Card according to any one of the preceding claims, in which the threshold is adaptive and calculated by an algorithm, as a function of the exposure time to the measured brightness.
7. A card according to any one of the preceding claims, wherein the secure element (111) is configured to determine the sequence of peaks included in the predetermined time window, the sequence of peaks being defined by at least one of the following peak characteristics: • the number of consecutive peaks; • the duration of each peak; • the time interval between two consecutive peaks.
8. Card according to claim 7, in which the secure element (111) is configured to: • Generate a candidate digital code, said candidate digital code being a function of the determined sequence of peaks; • compare the candidate code to the secret code (PIN); and • emit a signal, preferably binary, representative of the result of the comparison.
9. Method for securing a contactless banking transaction with a chip card (100) according to any one of the preceding claims, comprising steps consisting of: • Positioning the card in the magnetic field of a payment terminal, • Supplying power to the card via the payment terminal, • Optionally emitting a signal inviting entry of the secret code on a peripheral in electrical contact with the payment terminal, • Sequentially closing the optoelectronic transducer (150), Generate a candidate digital code, said candidate digital code being a function of the sequence of occlusions, • the optoelectronic transducer (150) generating, when it is occluded, an output signal (180) whose current is proportional to the number of photons received, said signal having the shape of a respective peak at each occlusion of said transducer, • the secure element (111) being configured to detect a set of peaks of said output signal (180) whose value crosses a threshold whose value is predetermined, in a predetermined time window, the threshold being constant or adaptive, compare the generated candidate code with the secret code (PIN) recorded in the secure element (111) of the smart card (100), and emit a binary signal representative of the result of the comparison.
10. The method of claim 9, comprising a step of authorizing the transaction only if the generated candidate code is equal to the secret code (PIN).