SECURE ACCESS METHOD TO A FILE CONTAINING DATA OF AT LEAST ONE PASSENGER ON A TRIP
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Utility models
- Current Assignee / Owner
- AMADEUS SAS
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-15
AI Technical Summary
Current methods for securing passenger name record (PNR) data in the travel industry offer low security and high operational costs, with existing solutions like SMS-based verification and call center redirections impacting user experience and being costly.
A method involving adding a digital lock to PNR files, transmitting an encrypted link with an identifier, and using a rules engine to verify passenger identity and authorization for secure access, eliminating the need for call centers and SMS verification.
Enhances security and reduces costs by ensuring secure access to PNR data without impacting user experience, while maintaining optimal user interaction.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: METHOD FOR SECURE ACCESS TO A FILE CONTAINING DATA OF AT LEAST ONE PASSENGER ON A JOURNEY TECHNICAL FIELD OF THE INVENTION
[0001] The present invention relates to a method for secure access to a digital file containing data of at least one passenger on a trip. The invention finds a particularly interesting, but not exclusive, application in the field of reservations in the travel industry. TECHNOLOGICAL BACKGROUND OF THE INVENTION
[0002] In the field of reservation in the travel industry, it is known that there are digital records containing data of a passenger or a group of passengers travelling together for a given trip.
[0003] This type of digital record is better known by the acronym PNR (for "passenger name record"). Each PNR record contains personal data of the passengers as well as details of a trip.
[0004] To secure this data, a unique PNR code, also known as RLOC, is assigned to each PNR record upon its creation. The PNR code is provided to travelers once their booking is complete, allowing them to manage their trip and check-in online.
[0005] To access the online PNR file, a user simply needs to enter the PNR code and their name. The PNR code generally contains six characters, including either letters or letters and numbers, depending on the booking system used. Therefore, online access to the PNR file offers a relatively low level of security.
[0006] The number of incidents involving data breaches is increasing in all sectors, including travel. These security incidents can occur for various reasons. For example, attacks by hacker organizations can lead to the compromise of thousands, or even millions, of data points contained in PNR records. Similarly, traveler negligence, such as sharing boarding passes and / or booking information on social media, can result in the compromise of PNR data. Furthermore, it is necessary to share the PNR code with numerous stakeholders (other airlines, vendors, partners), each with a different level of security.
[0007] In order to increase the level of security required to access the online PNR file, it is known that, for each attempt to access the PNR file, security is strengthened by the use of a different code transmitted in an SMS message. The use of this secure method generates a significant cost for an airline, potentially reaching several million euros per year.
[0008] Methods are also known that, when a PNR code is generated, one or more access restrictions to the PNR file are hardcoded, such as prohibiting access to the PNR file via a public web page. These restrictions limit or prevent travelers from directly accessing the PNR files and redirect them to a call center. These methods therefore require airlines to establish a call center staffed by several hundred employees. These redirections to a call center generate significant costs and negatively impact the traveler's user experience.
[0009] Consequently, the current security methods used to secure the data contained in PNR records are not satisfactory. Summary of the invention
[0010] The invention offers a solution to the problems mentioned above, by proposing a method to strengthen the security and confidentiality of data in a file containing data of at least one passenger while improving the passenger's user experience.
[0011] In this context, the invention relates, in its broadest sense, to a secure access procedure for a file containing data of at least one passenger on a journey, the procedure comprising the steps of: • Add, via reservation methods, to a file containing data of at least one passenger, called a PNR file, a digital lock for access to said PNR file; • Transmit, via the booking methods, to at least one passenger registered in the PNR file, an encrypted link to access an application, said encrypted link containing an identifier (also called "Office ID" in English) authorized to unlock the digital lock; • Select, via a human-machine interface, the encrypted link to access the application; • Enter, via the application, a passenger name and a booking code, known as the PNR code; • Transmit, via the application, the said passenger name, the said PNR code and the said identifier authorized to unlock the digital lock to the booking means; • Allow, via a rules engine, access to the PNR record to the passenger, if and only if said passenger name and said transmitted PNR code are recorded in the PNR record and said identifier is authorized to unlock the digital lock of the PNR record.
[0012] Thus, thanks to this digital lock contained in the PNR, the passenger can only access the PNR if they connect to it via the correct application associated with the identifier authorized to unlock the digital lock. To this end, the method transmits to the passenger an encrypted link to access an application, said encrypted link containing an identifier authorized to unlock the digital lock. When the passenger attempts to connect to the PNR via the encrypted link, the method verifies that the identifier associated with the application is authorized to unlock the PNR access lock. Such an identifier can be an identifier (or Office ID) that represents a travel agency or an entity (travel agency, help desk, check-in office, etc.) of an airline.
[0013] This process thus increases the security of access to PNR files while being totally transparent to the user so that their user experience remains optimal.
[0014] Furthermore, this method does not require contacting a call center, nor even sending SMS messages each time the PNR file is accessed. Compared to prior art methods, the cost of this secure access method is therefore reduced.
[0015] In addition to the characteristics just mentioned in the preceding paragraph, the process according to this aspect of the invention may have one or more complementary characteristics from among the following, considered individually or according to all technically possible combinations.
[0016] According to a non-limiting aspect of the invention, the encrypted link for accessing the application is formed by a uniform resource locator, called a URL.
[0017] According to a non-limiting aspect of the invention, the encrypted link for accessing the application is formed by a QR code.
[0018] According to a non-limiting aspect of the invention, the encrypted link to access the application is transmitted in an email or in an SMS or MMS type message.
[0019] According to a non-limiting aspect of the invention, the application is formed by a web page.
[0020] According to a non-limiting aspect of the invention, the digital lock for access to the PNR file is added to the PNR file when the PNR file is created.
[0021] According to a non-limiting aspect of the invention, the method comprises a step, prior to the step of adding the digital lock for accessing the PNR file to the PNR file, of receive, via the booking methods, an alert of an unauthorized attempt to access the PNR file.
[0022] According to a non-limiting aspect of the invention, the method includes a step of identifying, via the booking means, a specific type of passenger, the encrypted link for accessing an application being transmitted only to at least one passenger corresponding to said specific type of passenger.
[0023] According to a non-limiting aspect of the invention, the specific passenger type is determined based on a number of kilometers travelled.
[0024] Another non-limiting aspect of the invention relates to a computer program product downloadable from a communication network and / or recorded on a computer-readable medium and / or executable by a processor, said computer program product being notable in that it includes program code instructions for implementing the method according to any one of the aforementioned aspects of the invention, when the program is executed on a computer.
[0025] The invention and its various applications will be better understood by reading the following description and examining the accompanying figures. BRIEF DESCRIPTION OF THE FIGURES
[0026] The figures are presented for illustrative purposes only and are in no way limiting of the invention.
[0027] [Fig.1] illustrates the steps of a method for secure access to a file containing data of at least one passenger of a trip according to a non-limiting aspect of the invention.
[0028] [Fig.2] illustrates a non-limiting example of computer means implemented to execute the steps of the process according to the invention illustrated in [Fig.1].
[0029] [Fig.3] illustrates the steps of a secure access procedure to a folder containing data of at least one passenger on a trip according to another non-limiting aspect of the invention.
[0030] [Fig.4] illustrates the steps of a secure access process to a folder containing data of at least one passenger on a trip according to another non-limiting aspect of the invention. DETAILED DESCRIPTION
[0031] [Fig. 1] shows a non-limiting example of a method 100 for secure access to a file containing data of at least one passenger of a trip, the steps of the method 100 being executed via computer means illustrated in [Fig. 2],
[0032] In a non-limiting example of an embodiment, when creating a file containing data of at least one passenger, called a PNR file, the method 100 includes a step of adding 102, via reservation means 1, to a PNR file, a digital lock for access to the PNR file.
[0033] Then, the method 100 includes a step of transmitting 104, via the reservation means 1, to at least one passenger registered in the PNR file, an encrypted link providing access to an application, said encrypted link containing an identifier authorized to unlock the digital lock. In a non-limiting embodiment, this application consists of a web page.
[0034] According to non-limiting embodiments, the encrypted link to access the web page is transmitted in an email or in an SMS or MMS message. This encrypted link to access the web page may be formed by: • A Uniform Resource Locator, better known by its acronym URL (for "Uniform Resource Locator" in English); or • A QR code.
[0035] Then, when a passenger who has received the encrypted link to access an application wishes to access their PNR file, they select, via a human-machine interface 2, the encrypted link to access an application. The human-machine interface 2 can be a computer screen, a digital tablet, or a mobile phone screen.
[0036] Once selected, process 100 includes a step of entering 106, via the application, the passenger's name, for example his / her last name, and a booking code, called PNR code.
[0037] The method 100 then transmits 107 to the booking means 1, via the application, the passenger name and the entered PNR code, as well as the identifier authorized to unlock the digital lock that is initially contained in the encrypted link. Finally, if and only if the passenger name and the transmitted PNR code are recorded in the PNR record and the identifier is authorized to unlock the digital lock of the PNR record, a rules engine 3 executed by the booking means 108 authorizes the passenger to access the PNR record.
[0038] [Fig.3] shows another example of a non-limiting embodiment of a method 100 for secure access to a file containing data of at least one passenger of a trip, the steps of the method 100 being executed via the computer means illustrated in [Fig.2].
[0039] In this embodiment, the method 100 includes a first step of receiving 101, via the reservation means 1, an alert of an unauthorized access attempt to the PNR record. This unauthorized access attempt can be detected following a call from a passenger informing a fraud detection service that attempts to connect to their PNR record have been made by unauthorized persons authorized. In this case, the fraud detection service can transmit, to booking means 1, an alert of attempted unauthorized access to the PNR file.
[0040] Following the receipt of this alert, the method 100 according to the invention performs the step 102 of adding, via reservation means 1, to the PNR file, a digital lock for accessing said PNR file. In other words, this digital lock for accessing the PNR file was not initially recorded in the PNR file. However, since an unauthorized access attempt was detected during step 101, the security of access to the PNR file is increased by the addition of this digital lock.
[0041] The process 100 then performs the steps of: • Transmit 104 to at least one passenger registered in the PNR file, an encrypted link to access the application, the encrypted link containing an identifier authorized to unlock the digital lock; • Select 105, the encrypted link to access the application; • Enter 106 your passenger name and a PNR code; • Transmit 107 to booking means 1 the passenger name, the entered PNR code and the authorized identifier to unlock the digital lock; • Allow the passenger 108 access to the PNR file.
[0042] Figure 4 shows another example of a non-limiting embodiment of a method 100 for secure access to a file containing data of at least one passenger of a trip, the steps of the method 100 being executed via the computer means illustrated in Figure 2.
[0043] In this non-limiting embodiment, following the step of adding a digital lock to the PNR file (102), the method (100) includes a step of identifying (103), via the reservation means (1), a specific passenger type. The specific passenger type can be determined based on the number of kilometers traveled and / or the number of flights taken and / or expenses incurred.
[0044] According to this embodiment, during the step of transmitting 104 an encrypted link to access the application, this encrypted link to access the application is transmitted only to passengers corresponding to the specific passenger type.
[0045] The process 100 then performs the steps of • Select 105, the encrypted link to access the application; • Enter 106 a passenger name and a PNR code; • Transmit to booking means 1 the passenger name as well as the PNR code entered and the identifier authorized to unlock the digital lock; • Allow the passenger 108 access to the PNR file.
[0046] Furthermore, the various computer means mentioned above, namely the reservation means 1, the human-machine interface 2 and the rules engine 3, can be integrated into one or more computers. A computer can include a processor, memory, a mass storage device, an input / output (I / O) interface and a Human-Machine Interface (HMI).
[0047] The computer can also be functionally coupled to one or more external resources via a network and / or an I / O interface.
[0048] External resources may include, but are not limited to, servers, databases, mass storage devices, peripheral devices, cloud-based network services, or any other suitable computing resource that can be used by the computer.
[0049] The processor may include one or more devices selected from microprocessors, microcontrollers, digital signal processors, microcomputers, central processing units, user-programmable networks, programmable logic devices, state machines, logic circuits, analog circuits, digital circuits, or other devices that manipulate signals (analog or digital) according to operation instructions that are stored in memory.
[0050] Memory may include a single memory device or a plurality of memory devices including, but not limited to, read-only memory (ROM), random-access memory (RAM), volatile memory, non-volatile memory, static random-access memory (SRAM), dynamic random-access memory (DRAM), flash memory, cache memory, or any other device capable of storing information.
[0051] The mass storage memory device may include data storage devices such as a hard drive, an optical disc, a cassette player, a non-volatile semiconductor device, or any other device capable of storing information. A database may reside on the mass storage memory device and may be used to collect and organize data used by the various means described herein.
[0052] The processor can operate under the control of an operating system that resides in memory. The operating system can manage text and computer resources in such a way that embedded computer program code in the form of one or more software applications, such as a memory-resident application, can have instructions executed by the processor.
Claims
Demands
1. A method (100) for secure access to a file containing data of at least one passenger of a journey, said method (100) comprising the steps of: - Adding (102), via booking means (1), to a file containing data of at least one passenger, referred to as the PNR file, a digital lock for accessing said PNR file; - Transmitting (104), via said booking means (1), to at least one passenger registered in said PNR file, an encrypted link for accessing an application, said encrypted link containing an identifier authorized to unlock said digital lock; - Selecting (105), via a human-machine interface (2), said encrypted link for accessing the application; - Entering (106), in the application, a passenger name and a booking code, referred to as the PNR code;- Transmit (107), via the application, the passenger name, the PNR code and the identifier authorized to unlock the digital lock; - Authorize (108), via a rules engine (3), access to the passenger's PNR record, if and only if the passenger name and the transmitted PNR code are recorded in the PNR record and the identifier is authorized to unlock the digital lock of the PNR record.
2. Method (100) according to the preceding claim, characterized in that the encrypted link for accessing the application is formed by a uniform resource locator or a QR code.
3. Method (100) according to any one of the preceding claims, characterized in that the encrypted link for accessing the application is transmitted in an email or in an SMS or MMS type message.
4. Method (100) according to any one of the preceding claims, characterized in that the application is formed by a web page.
5. A method (100) according to any one of the preceding claims, characterized in that the digital access lock to The PNR folder is added to the PNR folder when the PNR folder is created.
6. Method (100) according to any one of claims 1 to 5, characterized in that it comprises a step, prior to the step of adding (102) to the PNR file the digital lock for access to the PNR file, of receiving (101), via the booking means, an alert of an attempt at unauthorized access to the PNR file.
7. A method (100) according to any one of the preceding claims, characterized in that it comprises a step of identifying (103), via the booking means (1), a specific type of passenger, the encrypted link for accessing an application being transmitted only to at least one passenger corresponding to said specific type of passenger.
8. Method (100) according to the preceding claim, characterized in that the specific passenger type is determined based on a number of kilometers travelled.
9. Product computer program downloadable from a communication network and / or recorded on a computer-readable medium and / or executable by a processor, characterized in that it includes program code instructions for implementing the method (100) according to any one of the preceding claims, when the program is executed on a computer.