Mutual authentication of devices or systems that are user-controllable and contain sensitive or confidential data
Patent Information
- Application Number
- JP2020560738
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2018-04-30
- Filing Date
- 2019-04-30
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2039-04-30
AI Technical Summary
Existing authentication methods fail to ensure mutual authentication between user-controllable functional electronic devices or systems, leading to potential security breaches when counterfeit devices or unauthorized users access sensitive or confidential data.
A method involving a pre-authentication stage for both the device and user, using secret questions and responses, ensuring that only genuine devices and users can access sensitive data by verifying authenticity before operational phases, with alerts for non-authentic entities.
Ensures secure operations and services by confirming the authenticity of both the device and user, preventing unauthorized access and maintaining data security.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the authentication of devices or systems that store important or confidential data, and more particularly to a method for mutual authentication of functional electronic devices or systems (which are also used for information processing and communication) that can be controlled by a user, an operation method for such devices or such systems, and a device or system specially arranged for implementing the authentication method or operation method.
Background Art
[0002] Within the scope of the present invention, the expression "functional electronic device" should be understood, for example, as a payment terminal, while the expression "functional electronic system" should be understood as a functional assembly including several devices that can be functionally linked to each other in a particular functional chain, such as a payment terminal and a remote server.
[0003] The term "functional" modifying such a device or such a system should be understood in a broad sense as meaning that it functions to perform a certain operation (which can also be called a task, a transaction or the like) in the operation stage, and the operation is a specific one of the nature of finally providing a prescribed service such as an order, a payment or the like to the user.
[0004] The term "controllable" associated with the user and relatively with the device or system should be understood as meaning that the device or the system is arranged in such a form that its operation is started by the user, especially in the operation stage.
[0005] The terms "device" and "system" are simplified to mean functional electronic device and functional electronic system respectively.
[0006] Within the scope of this invention, the term “authentication” must be understood to mean the process of verifying authenticity. The term “authenticity” must be understood to mean legitimacy, conformity to what is expected, truthfulness, evidentiary value, irrefutable nature, and reliability. The expression “mutual authentication” in relation to a user-controllable functional electronic device or system must be understood to involve the user verifying the authenticity of the device or system, and, in combination, the device or system verifying the authenticity of the user. Thus, the authentication as an object of this invention is, first, to verify that the device or system is indeed the correct device or system, and second, to verify that the user is indeed the correct user. Thus, mutual authentication aims to secure the operations performed, including those performed on the user, and ultimately the services provided to the user.
[0007] Within the scope of this invention, the term "data" should be understood to mean all information, code, and other elements that are specific and condition the operation of a device or system for the purpose of performing specific actions in order to provide a specified service to a user.
[0008] The terms “important” and “confidential” should be understood to describe data that, if not, could not be known, exposed, or accessed by any means other than the genuine device or system or the genuine user, and which, if not, could result in the actions performed and the services ultimately provided to the user being insecure or insecure.
[0009] The above outlines the background of the present invention and the interpretation of terms used throughout this document.
[0010] Those skilled in the art are already familiar with authentication processes for information processing and telecommunications systems. For example, a legitimate user of a mobile phone equipped with a SIM (Subscriber Identity Module) card has a personal PIN (Personal Identification Number) code that protects the SIM card from any unauthorized use. In some cases, a second code, a PUK (PIN Unlock Key) code, is envisioned whose sole role is to unblock the SIM card if it has been blocked as a result of a series of (e.g., three) incorrect entries. U.S. Patent No. 3,905,461 describes, for example, an access control device using coded tokens available to legitimate users. Alternatively, an authenticity certificate may activate a lock, for example, to ensure a secure connection typically for financial transactions, data transfers, etc. European Patent No. 2431904 describes an authentication system known as question-and-answer authentication, which is based on a challenge question and verification of the accuracy of the response to that challenge question. European Patent No. 3035640 describes a method for authenticating a first device performed by a second device through a question-and-answer authentication process. For example, a simple user identification to verify the user's identity does not constitute user authentication (see European Patent No. 2278538). Similarly, a simple user identification of a device or system does not guarantee to the user that the device or system is authentic. Therefore, for example, if an authentic device or system is replaced by a counterfeit device or system, the user's use of the device or system would mean the user is transmitting secret codes or important or confidential data or similar to the device or system, which an attacker could then recover and misuse on behalf of the authentic user. [Prior art documents] [Patent Documents]
[0011] [Patent Document 1] U.S. Patent No. 3905461 [Patent Document 2] European Patent No. 2431904 [Patent Document 3] European Patent No. 3035640 [Patent Document 4] European Patent No. 2278538 [Overview of the project] [Problems that the invention aims to solve]
[0012] Therefore, the fundamental problem of the present invention is to ensure mutual authentication in the case of a user-controllable functional electronic device or system, that is, to verify that the device or system is indeed the correct device or system and that the user is indeed the correct user, and thus to ensure the security of the operations performed by this device or system and the services ultimately provided to the user, including with respect to the user. [Means for solving the problem]
[0013] The present invention provides a solution to this problem by assuming a device or system authentication pre-stage, in which the user verifies the authenticity of the device or system, prior to an operational stage in which an operation is performed, which includes a step of the device or system authenticating a user and allowing access to important or confidential data, wherein the operational stage is conditional in that it can only be performed if the device or system authentication pre-stage is performed beforehand and the device or system is effectively authenticated by the user in this device or system authentication pre-stage. In this way, dual authentication is achieved, ensuring the security of the operation performed by the device or system and ultimately the services provided to the user.
[0014] The present invention will be described below.
[0015] According to a first aspect, the present invention relates to a method for mutual authentication of a controllable functional electronic device and its user, comprising a Device (ED) Configuration Pre-Step (SDCP) defining a method for verifying the authenticity of the device, wherein the user can then control the device to provide him with a specified service, the device being configured to store important or confidential data and to perform specific actions appropriate for providing the service—in an operational stage which includes a user authentication pre-step by the device initiated by the user, and further, prior to any operational stage, the method includes a device authentication pre-step which verifies the authenticity of the device, thus, - If the device is verified as authentic at the end of the pre-device authentication stage, the user can proceed to the operational stage. - If the device is not found to be authentic at the end of the pre-authentication stage, the user will be alerted in some way so that they can prevent the execution of the operational stage. In this way, the device is authenticated first, then the user, and the actions performed and services provided are secured. The purpose is to implement an authentication method that is designed in this way.
[0016] According to one embodiment, the device authentication pre-stage is performed by the user.
[0017] According to one embodiment, a method that includes multiple operational stages over time is one in which a device authentication pre-stage is performed before each operational stage.
[0018] According to one embodiment, the pre-device authentication step by the user is based on a question-and-answer authentication process using a pre-question for the device and a device authentication secret that is the device's pre-response to the pre-question. The pre-question and the pre-response are secret so that they are known or accessible only to the legitimate sole user, and thus the device is only legitimate. On the other hand, the user is only allowed to recognize when there is an identity between the response provided by the device to the pre-question and the pre-response.
[0019] According to a variant embodiment, at the end of the pre-device authentication step, if the device is not recognized as legitimate, the user may be prevented from executing the operation phase by the device itself.
[0020] According to one embodiment, the method also includes a preliminary configuration step in which the device is configured using the device authentication secret (SDAS).
[0021] According to one embodiment, the preliminary configuration step of the device is executed by the user.
[0022] According to one embodiment, the configuration of the device using the pre-question and the pre-response is executed from the user's question by a question-and-answer generation process.
[0023] According to one embodiment, the pre-device authentication step is executed after the preliminary configuration step has been executed and on condition that no other pre-device authentication step or operation step has been executed therebetween.
[0024] According to an embodiment, the pre-device authentication step is executed after the preliminary configuration step has been executed and on condition that one or more other pre-device authentication steps or operation steps have been executed therebetween.
[0025] According to an embodiment, for the configuration preparation stage, a single pre-device authentication stage or a plurality of predefined consecutive pre-device authentication stages or an infinite number of consecutive pre-device authentication stages are linked in a necessary and sufficient manner.
[0026] According to one embodiment, the user authentication preliminary step by the device is based on a user authentication secret that is a user operation response to a device that is secret and can only be known or accessed by a genuine single user, and thus the genuineness of the user is unique. The device is only recognized when it confirms the identity between the response provided by the user and the operation response on the one hand and the operation response on the other hand.
[0027] According to one embodiment, the pre-question and the operation response are different.
[0028] According to one embodiment, the method is automatically executed at the end of a predefined number of executions of consecutive pre-device authentication stages when the device is not recognized as genuine. Specifically, when the user fails to provide a pre-question corresponding to the pre-response at the end of a predefined number of executions of consecutive pre-device or system authentication stages, and thus the device or system determines that the user is not a genuine user, this important or confidential data exclusion step also erases the pre-question and the pre-response.
[0029] According to a second aspect, the present invention provides a method for a user to operate a functional electronic device controllable by the user to provide a specified service. In this method, the device stores important or confidential data and, in an operation stage started by the user and including a user authentication preliminary step by the device, the device performs a specific operation appropriate for providing the service. Further, prior to any operation stage, the method includes a pre-device authentication stage for verifying the genuineness of the device, and thus, - At the end of the pre-device authentication stage, if the device is recognized as genuine, the user can execute the operation stage. - If the device is not found to be authentic at the end of the pre-authentication stage, the user will be alerted in some way so that they can prevent the execution of the operational stage. In this way, the device is authenticated first, then the user, and the actions performed and services provided are secured. The purpose is to implement an operational method that is designed in this way.
[0030] According to a third aspect, the present invention relates to a functional electronic device that is controllable by a user for the purpose of performing a specified service, stores important or confidential data, and is specifically configured for the implementation of the mutual authentication method described above, and in particular for the implementation of an operational method for performing a device authentication pre-stage.
[0031] According to one embodiment, the device is configured at the end of a preliminary configuration stage using the device's authentication secret, which is a user's pre-question to the device and the device's pre-response to the user to the pre-question.
[0032] Therefore, the device contains and combines a device authentication secret on the one hand and a user authentication secret on the other.
[0033] According to a fourth aspect, the present invention relates to a method for mutual authentication of a functional electronic system, which includes a plurality of electronic devices that are controllable by a user for the purpose of providing a specified service, store important or confidential data, and are functionally linked to one another, and which are arranged to perform a specific operation or set of operations appropriate for providing a service, in an operation phase which includes a step initiated by the user and in which the system authenticates the user, further comprising a pre-stage of authenticating the system prior to any operation phase, during which the authenticity of all or some of the plurality of devices included in the system is confirmed for each device under verification by performing the authentication method described above.
[0034] According to one embodiment, the method involves a plurality of electronic devices that form one or more functional chains together with one or more upstream devices and one or more downstream devices, - If a device is deemed authentic at the end of the pre-authentication stage for an upstream device in the device chain, authentication of one or more downstream devices in the same device chain is initiated. - If a device is not deemed authentic at the end of the pre-authentication stage for an upstream device in a device chain, the system is deemed not authentic, and therefore, authentication of one or more downstream devices in the same device chain will not be initiated. This is a mutual authentication method.
[0035] According to a fifth aspect, the present invention relates to a user operation of a functional electronic system controllable by a user to provide a specified service to the user, wherein the system includes a plurality of electronic devices that store important or confidential data and are functionally linked to one another, and a method for the system to perform a specific operation or set of operations appropriate for providing the service, in an operation phase initiated by the user and including a preliminary user authentication step by the system, further including a system authentication pre-stage prior to any operation phase, during which the authenticity of all or some of the plurality of devices included in the system is verified by performing the authentication method described above on each device to be verified, thus, - If the system is deemed authentic at the end of the pre-authentication phase, the user can proceed to the operational phase. - If the system is not found to be authentic at the end of the pre-authentication stage, the user will be alerted in some way so that they can prevent the execution of the operational stage. In this way, the system is authenticated first, then the user, and the actions performed and services provided are secured. The purpose is to implement an operational method that is designed in this way.
[0036] According to a sixth aspect, the present invention relates to a functional electronic system that includes a plurality of electronic devices that are controllable by a user for the purpose of providing a specified service, store important or confidential data, and are functionally linked to one another as described above, and is specifically arranged for the implementation of the mutual authentication method described above, and in particular for the implementation of the operational method described above for performing the authentication pre-stage of all or some of the plurality of devices that the system includes. [Brief explanation of the drawing]
[0037] [Figure 1] This is a theoretical overall diagram of an embodiment of the present invention. [Modes for carrying out the invention]
[0038] Here, we will briefly explain the sole Figure 1. This figure is a purely academic and indicative theoretical overview of possible embodiments of how a user may operate a functional electronic device containing important or confidential data, which is controllable by the user to provide a specified service to the user, illustrating the following: - First, a preliminary configuration step based on the device authentication secret is performed by the user. - Next, a device authentication pre-stage that verifies the authenticity of the device based on the device authentication secret. - Next, an operational phase in which the device is found to be authentic at the end of the pre-device authentication phase, including a user authentication preliminary step by the device initiated by the user and based on the user authentication secret, wherein the device performs specific actions appropriate for providing the service.
[0039] The following is a detailed description of the methods of carrying out the present invention and various embodiments, including references to examples and figures. This description should be understood in the context of the present invention, along with the interpretations of terms presented previously, and therefore, repetition is unnecessary here.
[0040] The present invention relates to and implements controllable functional (also for information processing and communication) electronic devices ED that store important or confidential data DA, and more generally, functional (also for information processing and communication) electronic systems ES that include one or more upstream devices and one or more downstream devices and one or more functional chains of multiple devices ED. As with the devices ED, the system ES stores important or confidential data DA. The description of the present invention will be more specifically detailed with respect to devices ED. This is applicable to the system ES, that is, to all or some of the devices ED that the system includes, in particular all or some of the devices that store important or confidential data DA or whose authenticity must be recognized.
[0041] The present invention involves a user USER who controls a device ED or system ES using a command CO to provide a specified service DS to the user and performs different stages or steps required for the operation of the device ED or system ES.
[0042] The present invention aims to guarantee mutual authentication with respect to the user USER as well as the device ED or system ES, that is, to ensure that the user USER can first verify that the device ED or system ES is indeed genuine, and then that the device ED or system ES can verify that the user USER is indeed genuine. In this way, the security of specific operations SO performed by the device ED or system ES and ultimately prescribed services DS provided to the user USER is guaranteed, including with respect to the user USER. From this, it should be understood that control of the device ED or system ES by the user USER is only possible if the device ED or system ES is genuine and not a forged or fraudulent device or system, and the user USER is genuine and not a fake or fraudulent user. If the device ED or system ES is suspected of being ungenuine, the user will be unable to perform certain operations SO in the sense that their execution will be blocked. Similarly, if the user is found to be ungenuine, the user will be even more unable to perform certain operations SO in the sense that their execution will be blocked.
[0043] In the following, it is assumed that device ED or system ES is authentic and user USER is authentic. The description of the present invention will detail what happens when device ED or system ES is not authentic and when user USER is not authentic.
[0044] In one embodiment, the user USER is the real person themselves.
[0045] In another embodiment, User USER is an avatar of a real person. This avatar is legal for the execution under consideration and has legally obtained code, secrets, etc., owned by the real person so that it can act legally on behalf of the real person.
[0046] "Operational phase" (OP) refers to a phase initiated by user CO, in which device ED or system ES performs appropriate specific operation SO, which is specifically designed to provide service DS to user USER.
[0047] The "User Authentication Preliminary Step" (UAP) refers to a preliminary step included within the Operational Phase (OP) in which the device authenticates the user (USER) using the User Authentication Secret (UAS).
[0048] The "Device or System Authentication Pre-stage" (SDAP) refers to the stage in which a user verifies the authenticity of a device ED or system ES using, for example, the authentication secret SDAS of the device or system.
[0049] The "device or system configuration preliminary stage" (SDCP) refers to the stage in which device ED or system ES is configured using the authentication secret SDAS of the device or system. In one embodiment, this configuration is performed by user USER.
[0050] The operation of device ED or system ES includes a pre-authentication stage SDAP for the device or system, which precedes and is performed before any operational stage OP, and is attached to and conditions the possibility of performing the operational stage OP itself. In fact, if device ED or system ES is deemed authentic at the end of the pre-authentication stage SDAP, user USER can perform the operational stage OP. On the other hand, if device ED or system ES is not deemed authentic at the end of the pre-authentication stage SDAP, user USER can prevent the performance of the operational stage OP.
[0051] Thus, the operation method of device ED or system ES integrates a mutual authentication method between device ED or system ES and its user USER. In this way, device ED or system ES is authenticated first, and then user USER. In this manner, specific operations SO performed by device ED or system ES and services DS provided to user USER are secured. The present invention can be viewed from the perspective of the operation method of device ED or system ES that integrates this mutual authentication method, and at the same time from the perspective of this mutual authentication method that is integrated into and within such an operation method.
[0052] In one embodiment where several operational stages are envisioned over time, a pre-authentication stage SDAP for the device or system is performed before each operational stage OP.
[0053] In one possible embodiment, the user's pre-authentication stage SDAP for a device or system is based on a question-and-answer authentication process using the authentication secret SDAS, which is the user's pre-question PQ to the device ED or system ES and the device or system's pre-response PA to the user. The pre-question PQ and pre-response PA are different and secret because only the one genuine user knows or can access them. Therefore, the authenticity of the device ED or system ES is recognized only when the user confirms that there is identity between the response ADS and the pre-response PA provided by the device ED or system ES to the pre-question PQ.
[0054] It is understood that the pre-authentication SDAP for devices or systems based on the question-and-answer authentication process described above is not exclusive or limiting. Other processes that provide a higher level of authentication can be conceived. Accordingly, the present invention also includes embodiments based on authentication processes equivalent to the question-and-answer process. Similarly, it is understood that the pre-authentication SDAP for devices or systems may include a combination of question-and-answer or several equivalent authentication processes for the purpose of having a higher level of authentication. Accordingly, the expression "pre-authentication SDAP for devices or systems" should be understood to mean that it is based on a question-and-answer authentication process.
[0055] According to one possible embodiment, the configuration of a device ED or system ES using the authentication secret SDAS (pre-question PQ and pre-answer PA) is performed from a user's question by a question-answer generation process such as a function, program, or algorithm.
[0056] With regard to the relationships between the device or system configuration pre-stage SDCP, the device or system authentication pre-stage SDAP, and the operation stage OP, several embodiments can be considered. Thus, according to one embodiment, the device or system authentication pre-stage SDAP is executed after the device or system configuration pre-stage SDCP has been executed, via the absence of execution of any other device or system authentication pre-stage SDAP or operation stage OP in between. According to another embodiment, the device or system authentication pre-stage SDAP is executed after the device or system configuration pre-stage SDCP has been executed, with one or more other device or system authentication pre-stage SDAP or operation stage OP being executed in between. On the other hand, according to several embodiments, the device or system configuration pre-stage SDCP is associated with a necessary and sufficient number of consecutive predetermined authentication pre-stage SDAPs or an infinite number of consecutive authentication pre-stage SDAPs.
[0057] The user authentication secret UAS used in the user authentication preliminary step UAP is the user USER's action response OA to device ED or system ES, which is secret so that only the one true user can know and access it. Thus, the user's authenticity is recognized only when device ED or system ES confirms that there is identity between the response AU provided by the user and the action response OA.
[0058] The operational stage OP (Operational Process) preliminarily includes a user authentication preliminary step UAP (User Authentication Preliminary Step), which conditions the possibility of executing the operational stage OP itself. In fact, if user USER is found to be authentic at the end of the user authentication preliminary step UAP, user USER can execute the operational stage OP; on the other hand, if user USER is not found to be authentic at the end of the user authentication preliminary step UAP, user USER can be prevented from executing the operational stage OP.
[0059] Several embodiments can be conceived. In one embodiment, an operational question OQ is assumed to be issued to a user USER by a device ED or system ES, to which the user USER must respond with an operational response OA. Alternatively, the commencement of the operational phase OP itself compels the user USER to provide the operational response OA to the device ED or system ES. In any case, if the response AU provided by the user and the operational response OA are not identical, the device ED or system ES considers the user to be not a genuine user, and as a result, operation SO is not performed and service DS is not provided.
[0060] Following the conventions of device or system authentication, user authentication through the question-and-answer authentication process described above is not exclusive or limiting. Other processes that provide a higher level of authentication can be conceived. Accordingly, the present invention also includes embodiments based on authentication processes equivalent to the question-and-answer process. Similarly, it is understood that, for the purpose of having a higher level of authentication, the user authentication preliminary step UAP may include a combination of question-and-answer or several equivalent authentication processes.
[0061] According to one embodiment, the pre-question PQ and the operational response OA are different.
[0062] According to one embodiment, the method includes a step of eliminating important or sensitive data DA of a device ED or system ES. This elimination step is performed automatically at the end of the execution of a predetermined number of consecutive authentication pre-stage SDAPs for devices or systems in which the device ED or system ES is not deemed authentic.
[0063] According to one supplementary embodiment, the step of excluding important or sensitive data DA from device ED or system ES also excludes the pre-question PQ and pre-response PA if, at the end of the execution of a predetermined number of consecutive authentication pre-stages SDAP of a device or system, the user USER fails to provide a pre-question PQ corresponding to a pre-response PA, and therefore device ED or system ES considers the user to be not a genuine user.
[0064] If the method concerns the system ES, a pre-system authentication stage SDAP is assumed before every operational stage OP, and the authenticity of all or some of the multiple devices ED included in the system ES is verified by performing the authentication method described above on each device ED identified during this stage.
[0065] In such a system ES, multiple device EDs may form one or more functional chains together with one or more upstream device EDs and one or more downstream device EDs. In this case, on the one hand, if the upstream device ED in the device ED chain is deemed authentic at the end of its pre-authentication SDAP stage, the pre-authentication SDAP stage for one or more downstream device EDs in the same device ED chain will be initiated. On the other hand, if the upstream device ED in the device ED chain is not deemed authentic at the end of its pre-authentication SDAP stage, the system ES will be deemed not authentic, and therefore the pre-authentication SDAP stage for one or more downstream device EDs in the same device ED chain will not be initiated.
[0066] The device ED or system ES according to the present invention is specifically configured for the implementation of the mutual authentication method described above, and in particular for the implementation of an operational method for performing the pre-authentication stage SDAP of the device or system. The device ED or system ES is configured, and thus includes, a combination of the authentication secret SDAS of the device or system on the one hand and the user authentication secret UAS on the other hand.
[0067] Here, we refer to the only figure, Figure 1. This figure represents the user USER and the device ED or system ES in the form of two columns, one on the left and one on the right. It presents the operation stage OP, which itself is broken down into three blocks from top to bottom on the timeline: the configuration pre-stage SDCP, the device or system pre-authentication stage SDAP, and finally, the operation stage OP, which is itself broken down into two blocks: the first block corresponding to the user authentication pre-step UAP and the second block corresponding to the so-called operation stage. As explained earlier, these two blocks overlap to some extent.
[0068] This diagram illustrates how a device ED or system ES stores important or confidential data DA, and combines the device or system authentication secret SDAS on the one hand and the user authentication secret UAS (symbolically represented by a closed lock) on the other.
[0069] The diagram illustrates how these two secrets are unlocked sequentially, first the device or system authentication secret (SDAS), and then the user authentication secret (UAS), which is symbolically represented by an open lock.
[0070] Once a device ED or system ES is authenticated, it is represented by horizontal stripes, and once a user is authenticated, they are represented by horizontal stripes.
[0071] This diagram illustrates that a user command CO, intended for the execution of a specific operation SO by a device ED or system ES to provide a prescribed service DS to a user, only intervenes once the device ED or system ES has been authenticated (by the user) and the user has been authenticated, in combination. [Explanation of Symbols]
[0072] AU response ADS Response CO command DA Data DS Service ED Electronic Devices ES Electronic Systems SO operation OA operation response OP operation phase OQ Operation Question PA Pre-response PQ Pre-questions SDAS Authentication Secret SDAP Certification Pre-stage SDCP Configuration Preliminary Stage UAP User Authentication Preliminary Steps UAS User Authentication Secret USER
Claims
1. In a method for executing a transaction on an electronic device, the electronic device starts the operation phase of the transaction when receiving a command from a user, and is configured to perform specific operations to provide a specified service corresponding to the target transaction to the user during the operation phase. Before the operation phase is executed, the method includes a preliminary configuration phase of the electronic device and a pre-authentication phase of the electronic device. The preliminary configuration phase of the electronic device includes setting, in the electronic device, a pre-question and a pre-answer generated by a question-and-answer generation process using questions from the user. The pre-authentication phase of the electronic device is for the user to send a pre-question to the electronic device, for the user to receive a response to the pre-question from the electronic device, and for the user to confirm that the response provided by the electronic device corresponds to the expected pre-answer. Based on the result of the confirmation in the pre-authentication phase of the electronic device by the user, if the electronic device is confirmed to be genuine, the execution of the operation phase is permitted, and if it is not confirmed to be genuine, the execution of the operation phase is blocked. Here, the pre-question and the pre-answer are secret and accessible only by the user. The operation phase includes a preliminary user authentication step by the electronic device. The preliminary user authentication step is for the electronic device to provide an operation question to the user, for the electronic device to receive a response to the operation question from the user and compare the user's response with the expected operation response stored in the electronic device. The method further includes, when the user fails to provide a pre-question to the electronic device during a predetermined number of executions of the pre-authentication phase of the electronic device by the user, the electronic device to eliminate confidential data stored in the electronic device.
2. The method according to claim 1, including a plurality of operation phases over time, and before each operation phase, a pre-authentication phase of the electronic device is executed.
3. The method according to claim 1, wherein the elimination of confidential data stored in the electronic device includes the deletion of the pre-question and the pre-answer.
4. To provide a plurality of electronic devices that form a single functional chain for executing a transaction, the functional chain including at least a single upstream electronic device and a single downstream electronic device, Performing an authentication pre-step of the upstream electronic device, and When the upstream electronic device is authenticated, performing an authentication pre-step of the downstream electronic device; otherwise, not performing the authentication pre-step of the downstream electronic device, the method according to claim 1.
5. In an electronic device for executing a transaction, when the electronic device receives a command from a user, it starts an operation phase of the transaction and is configured to execute specific operations to provide a specified service corresponding to the target transaction to the user during the operation phase. The electronic device stores confidential data including pre-questions and pre-answers generated by a question-and-answer generation process using questions from the user, and During the authentication pre-step of the electronic device by the user, Receiving a pre-question from the user, In response to the pre-question received from the user, providing the corresponding pre-answer stored in the memory to the user, The electronic device is configured to permit the execution of the operation phase if it is confirmed that the electronic device is genuine as a result of the confirmation in the authentication pre-step of the electronic device by the user, and to prevent the execution of the operation phase if it is not confirmed to be genuine. During the operation phase, as a preliminary user authentication step by the electronic device, Providing an operation question to the user, Receiving a response to the operation question from the user and being configured to compare the user's response with the expected operation response stored in the electronic device, and The electronic device is configured to eliminate the confidential data stored in the electronic device if no pre-question is received from the user during a predetermined number of executions of the authentication pre-step of the electronic device by the user.