SECURE ACCESS METHOD TO A FILE CONTAINING DATA OF PASSENGERS FROM THE SAME JOURNEY

The method addresses the security and confidentiality issues in accessing PNR data by using risk scoring and multi-factor authentication to control data access, ensuring only appropriate information is displayed, thus safeguarding personal data.

FR3166722A3Pending Publication Date: 2026-03-27AMADEUS SAS
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing methods for accessing passenger name records (PNR) in the travel industry lack sufficient security and confidentiality, allowing unauthorized access and potential misuse of personal data, including incorrect awarding of loyalty points and exposure of sensitive information.

Method used

A method involving a risk score determination based on user input, multi-factor authentication for high-risk scenarios, and adaptive display of passenger data based on the calculated risk score, using parameters like user ID, geolocation, and query history to enhance security and confidentiality.

Benefits of technology

Enhances data security and confidentiality by limiting information access based on risk assessment, ensuring only relevant data is displayed to authorized users, thereby protecting personal information.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

One aspect of the invention relates to a method 100 for secure access to a file containing passenger data for the same trip, said method 100 comprising the steps of: Entering 101, in a human-machine interface, a request to access a file of passenger data for the same trip, the request being entered by a user; Transmitting 102 the request to computing means; Determining 103, via the computing means, a risk score for the request based on the user; Displaying 105, via a screen, a predetermined number, based on the determined risk score, of data from the passenger data file for the same trip. Figure to be published with the abbreviation: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: METHOD FOR SECURE ACCESS TO A FILE CONTAINING DATA OF PASSENGERS FROM THE SAME JOURNEY TECHNICAL FIELD OF THE INVENTION

[0001] The present invention relates to a method of secure access to a file containing data of passengers from the same trip.

[0002] The invention finds a particularly interesting, but not exclusive, application in the field of reservation in the travel industry. TECHNOLOGICAL BACKGROUND OF THE INVENTION

[0003] In the field of reservations within the travel industry, it is common to find records containing passenger data for the same trip. This type of record is more commonly known by the acronym PNR (for "passenger name record"). Each PNR record contains personal data concerning all the details of a trip for passengers traveling together.

[0004] When a traveler wishes to access a PNR file associated with their trip, they enter a code and their name and receive in return all the information contained in the PNR file, in other words, the information relating to all travelers traveling together, including personal data. However, the information of other passengers is not relevant to the traveler accessing the PNR file.

[0005] The security and confidentiality of user data is therefore low, and it sometimes happens that loyalty points are awarded to a traveler other than the original owner. Furthermore, if a malicious person gains access to a PNR record, they then have access to all the personal information of the travelers on the same trip. Summary of the invention

[0006] The invention offers a solution to the problem mentioned above, by proposing a method to strengthen the security and confidentiality of data in a file containing data of passengers from the same trip.

[0007] In this context, the invention thus relates, in its broadest sense, to a method of secure access to a file containing passenger data from the same trip, the method comprising the steps of: • Enter, in a human-machine interface, a request to access a data file of passengers from the same trip, said request being entered by a user; • Transmit said request to computing resources; • Determine, using the aforementioned calculation methods, a risk score for the said request based on the said user; • Display via a screen, a determined number, based on said determined risk score, of data from said passenger data file of the same trip.

[0008] Thanks to the invention, and more specifically to the determined risk score, the amount of information displayed to the user can be more or less significant. For example, if the risk score is high, very little information can be displayed. Conversely, if the risk score is low, a large amount of information can be displayed. The security and confidentiality of the data contained in the file are therefore preserved.

[0009] In addition to the characteristics just mentioned in the preceding paragraph, the process according to this aspect of the invention may have one or more complementary characteristics from among the following, considered individually or according to all technically possible combinations.

[0010] According to a non-limiting aspect of the invention, when the determined risk score is greater than a threshold score, the method includes a step, prior to the display step, of transmitting a multi-factor authentication request to the user. This multi-factor authentication request is more often referred to by the acronym MFA (for "Multi-factor authentication").

[0011] According to a non-limiting aspect of the invention, the lower the determined risk score, the higher the number of passenger data records for the same trip that are displayed.

[0012] According to a non-limiting aspect of the invention, the determined risk score is a function of at least one of the following parameters: • User ID; • Date a request was issued; • Departure date of the trip; • Geolocation of a user; • Reason to access a passenger data file for the same trip, for example to change a traveler's meal choice or add baggage; • Internet Protocol address of a user; • A user's virtual private network address, better known by the acronym VPN (for "Virtual Private Network").

[0013] According to a non-limiting aspect of the invention, the method comprises the steps of: • Record in a database, for each user, a user profile based on the aforementioned past queries performed by the user; • Record in the database, for each reference of a file containing passenger data from the same trip, data related to said trip; • The risk score determined is a function of a user profile of the user registered in the database and the data linked to the file reference registered in the database and entered in the query.

[0014] According to a non-limiting aspect of the invention, each user profile includes at least a user identifier, a reference to a file containing passenger data from the same trip which the said user has previously accessed, and a date of access to said file.

[0015] According to a non-limiting aspect of the invention, the data linked to the reference of a file containing passenger data from the same trip includes the name of the departure and destination cities of the trip, a time window associated with a departure date of the trip and a user ID of a user who previously accessed said file.

[0016] According to a non-limiting aspect of the invention, the time window is three days before the departure date.

[0017] According to a non-limiting aspect of the invention, the trip includes an airplane flight.

[0018] Another non-limiting aspect of the invention relates to a program product computer downloadable from a communication network and / or recorded on a computer-readable medium and / or executable by a processor, said computer program product being notable in that it includes program code instructions for implementing the method according to any of the aforementioned aspects of the invention, when the program is executed on a computer.

[0019] The invention and its various applications will be better understood by reading the following description and examining the accompanying figures. BRIEF DESCRIPTION OF THE FIGURES

[0020] The figures are presented for illustrative purposes only and are in no way limiting of the invention.

[0021] [Fig.1] illustrates the steps of a method for secure access to a file containing data of passengers from the same trip according to a non-limiting aspect of the invention.

[0022] [Fig.2] illustrates a non-limiting example of computer means implemented for execute the steps of the process according to the invention illustrated in [Fig.1].

[0023] [Fig.3] illustrates a non-limiting example of computer means implemented to execute the steps of the process according to the invention illustrated in [Fig.1]. DETAILED DESCRIPTION

[0024] Figure 1 shows a non-limiting example of a method 100 for secure access to a file containing data of passengers from the same trip, the steps of the method 100 being executed via computer means illustrated in Figures 2 and 3.

[0025] The method 100 includes a step of entering 101, in a human-machine interface 1, a request to access a data file of passengers of the same trip, also called a PNR file (for "passenger name record" in English).

[0026] In this embodiment, • The request was completed on August 28th, and • The query is entered by a first user U1.

[0027] Without limitation, the first user U1 may be a traveler participating in the trip, an employee of a travel agency or even of an airline.

[0028] By way of non-limitation, when establishing the request, the first user U1 may enter a user identifier II, his surname NI and a reference to a file DI containing passenger data from the same trip which he wishes to access.

[0029] Once the query is entered, the process 100 includes a step of transmitting 102 the query to computing means 2.

[0030] It should be noted that, in a database 3, user profiles of users who have already accessed the DI file containing passenger data from the same trip have been previously recorded.

[0031] In the illustrated example, in database 3, • A user ID 12 of a second user, a DI file reference and the access dates of 8 / 08 and 9 / 08 to the DI file were previously recorded when the second user accessed the DI file on August 8 and 9; • A third user's user ID 13, a DI file reference and the 6 / 07 access date to the DI file were previously recorded when the third user accessed the DI file on July 6.

[0032] In addition, travel-related data is also recorded for reference in file Dl.

[0033] In the illustrated example, the following is already recorded in database 3: • The file number Dl; • The city of departure and the city of arrival, Paris-Nice; • The DCS time window of three days before the departure date of September 10; • The second and third user IDs 12,13 of the second and third users who have already accessed the Dl folder.

[0034] The process 100 also includes a step of determining 103, via the computing means 2, a risk score of the query as a function of the first user. Ul.

[0035] According to this non-limiting embodiment example, the determined risk score is a function of a user profile of the first user U1 registered in database 3 and of the data related to the file reference Dl which is registered in database 3 and is entered in the query.

[0036] Since the first user U1 was unknown to database 3 before this new query, no user profile for the first user is present. Because the first user is unknown to database 3, the risk score determined by the calculation means 2 is therefore higher than a threshold score. In this case, process 100 performs a step of transmitting 104 to the first user U1 a multi-factor authentication request, more commonly referred to by the acronym MFA (for "Multi-factor authentication").

[0037] Once the first user U1 has identified himself, the process 100 includes a step of displaying 105, via a screen 4, a determined number of data from the file Dl, the determined number of data displayed being a function of the determined risk score.

[0038] For example, since the risk score is high, only non-personal data of travelers are displayed.

[0039] The process 100 also includes a step of recording 106 in the database 3, for the first user Ul, a user profile based on the query performed by the first user U1.

[0040] In the example illustrated in [Fig. 3], a user profile of the first user Ul, consisting of a user identifier II, a reference to the file Dl containing passenger data for the same trip, and the access date of 28 / 08 to the file DL, is recorded in database 3.

[0041] The method 100 further includes a step of recording 107 in database 3, for reference to file D1, data related to the trip. In this embodiment, the first user identifier II is added during this step.

[0042] Since the first user U1 is now known to database 3, and more specifically it is recorded that the first user U1 accessed the Dl folder on 28 / 08, when this first user U1 subsequently wishes to access the Dl folder, the determined risk score will be lower. Therefore, they will be able to access a larger amount of data.

[0043] Furthermore, the various computer means mentioned above, namely the human-machine interface 1, the computing means 2, the database 3 and the screen 4, can be integrated into one or more computers. A computer can include a processor, memory, a mass storage device, an input / output (I / O) interface and a Human-Machine Interface (HMI).

[0044] The computer can also be functionally coupled to one or more external resources via a network and / or an I / O interface.

[0045] External resources may include, but are not limited to, servers, databases, mass storage devices, peripheral devices, cloud-based network services, or any other suitable computing resource that can be used by the computer.

[0046] The processor may include one or more devices selected from microprocessors, microcontrollers, digital signal processors, microcomputers, central processing units, user-programmable networks, programmable logic devices, state machines, logic circuits, analog circuits, digital circuits, or other devices that manipulate signals (analog or digital) according to operation instructions that are stored in memory.

[0047] Memory may include a single memory device or a plurality of memory devices including, but not limited to, read-only memory (ROM), random-access memory (RAM), volatile memory, non-volatile memory, static random access memory (SRAM), dynamic random access memory (DRAM), flash memory, cache memory, or any other device capable of storing information.

[0048] The mass storage memory device may include data storage devices such as a hard drive, an optical disc, a cassette player, a non-volatile semiconductor device, or any other device capable of storing information. A database may reside on the mass storage memory device and may be used to collect and organize data used by the various means described herein.

[0049] The processor can operate under the control of an operating system that resides in memory. The operating system can manage text and computer resources in such a way that embedded computer program code in the form of one or more software applications, such as a memory-resident application, can have instructions executed by the processor.

[0050] The various aspects of the aforementioned invention offer numerous advantages. Among these, we can mention: • Strengthen the security and confidentiality of data in a file containing passenger data from the same trip; Adapting the displayed data of a file containing passenger data from the same trip according to the user, a traveler will for example not have access to the same information as an employee of a travel agency or an airline.

Claims

Demands

1. Method (100) for secure access to a file containing data of passengers of the same trip, said method (100) comprising the steps of: - Entering (101), in a human-machine interface (1), a request to access a file of data of passengers of the same trip, said request being entered by a user (Ul); - Transmitting (102) said request to computing means (2); - Determining (103), via said computing means (2), a risk score of said request as a function of said user (Ul); - Displaying (105) via a screen (4), a determined number, as a function of said determined risk score, of data of said file of data of passengers of the same trip.

2. Method (100) according to the preceding claim, characterized in that when the determined risk score is greater than a threshold score, the method (100) includes a step, prior to the display step (105), of transmitting (104) a multi-factor authentication request to the user (Ul).

3. Method (100) according to any one of the preceding claims, characterized in that the lower the determined risk score, the higher the number of passenger data records for the same trip displayed.

4. A method (100) according to any one of the preceding claims, characterized in that the determined risk score is a function of at least one of the following parameters: - User ID; - Date of issue of a request; - Date of departure of the trip; - Geolocation of a user; - Reason for accessing a passenger data file for the same trip; - Internet protocol address of a user; - Virtual private network address of a user.

5. A method (100) according to any one of the preceding claims, characterized in that it comprises the steps of: - Recording (106) in a database (3), for each user (Ul), a user profile based on said past queries made by said user (Ul); - Recording (107) in said database (3), for each reference of a file (Dl) containing passenger data for the same trip, data related to said trip; • The risk score determined being based on a user profile of the user (Ul) recorded in the database (3) and the data related to the file reference (Dl) recorded in said database (3) and entered in the query.

6. Method (100) according to the preceding claim, characterized in that each user profile includes at least one user identifier of a user (II), a reference to a file (Dl) containing passenger data from the same trip which was previously accessed by said user (Ul) and a date of access to said file (Dl).

7. Method (100) according to any one of claims 5 or 6, characterized in that the data linked to the reference of a file (Dl) containing passenger data from the same trip include the names of the departure and destination cities of the trip, a time window associated with a departure date of the trip and a user identifier of a user (Ul) who previously accessed said file (Dl).

8. Method (100) according to the preceding claim, characterized in that the time window is three days before the departure date.

9. Method (100) according to any one of the preceding claims, characterized in that the journey includes an airplane flight.

10. Product: a computer program downloadable from a communication network and / or stored on a computer-readable medium and / or executable by a processor, characterized in that it includes program code instructions for the implementation of operation of the process (100) according to any one of the preceding claims, when the program is executed on a computer.