Method and system for performing secure data exchange

The dual reader system addresses network dependency and cash risks by enabling secure, efficient transactions between electronic devices through secure connections and server verification, ensuring transaction integrity.

JP7802448B2Active Publication Date: 2026-01-20MARBEUF CONSEIL ET RECHERCHE
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2019087763
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-10-26
Filing Date
2019-05-07
Publication Date
2026-01-20
Estimated Expiration
2039-05-07

AI Technical Summary

Technical Problem

Existing payment systems face issues with secure transactions when network connectivity is unavailable, and cash transactions are risky due to loss or counterfeiting, necessitating a need for improved financial and data exchange methods.

Method used

A dual reader system that facilitates secure data exchange between electronic devices without requiring a network connection, using a method involving secure connections, information registration, verification, and server communication to ensure transaction validity and security.

Benefits of technology

Enables secure and efficient transactions without network connectivity, ensuring transaction integrity and reducing risks associated with cash transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007802448000001
    Figure 0007802448000001
  • Figure 0007802448000002
    Figure 0007802448000002
  • Figure 0007802448000003
    Figure 0007802448000003
Patent Text Reader

Abstract

To provide a method and a system for performing secure data exchange.SOLUTION: A system includes first and second electronic devices 20A and 20B, a dual reader 10 including means for connection of each of the electronic devices, and a server 30 that transmits information on a human machine interface and secure exchange. A method includes a step of inputting to a dual reader, an information item relating to an exchange performed between the first and second electronic devices by using an interface of the dual reader or an external device connected to the dual reader, a step of registering an exchange related information item in the first electronic device using the dual reader, a step of registering an exchange related information item in the second electronic device using the dual reader and otherwise canceling the exchange, and a step of transmitting transaction related data to the server.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method and system for performing secure data exchange. [Background technology]

[0002] Payment cards are very widely used today to make secure payments. A reader into which the card is inserted, or in the case of contactless communication, brought close by, can be used to debit or credit the bank account associated with the card. In most cases, this reader must communicate with a remote server during the transaction, which sometimes blocks the remote server if no network is available.

[0003] Furthermore, currently, when a particular monetary amount must be debited from an account associated with a payment card for payment to another person's account, the other person must often wait for the corresponding amount to be effectively transferred before being able to use the amount received on their payment card.

[0004] Thus, although cash payments are preferred in many cases where there is no network and people want to be able to quickly reuse the money they receive, there are drawbacks associated with carrying cash, particularly the risk of it being lost or counterfeited. Summary of the Invention [Problem to be solved by the invention]

[0005] There is a need to remedy all or part of these shortcomings and, more generally, to find new means for facilitating financial transactions and, more generally, for the secure transmission of any computer file or any quantity registered in at least one register linked to or independent of such a file. [Means for solving the problem]

[0006] The present invention aims to meet this need and, according to one of its aspects, achieves this object by a method for carrying out said exchange in a system comprising a dual reader including first and second electronic devices and means for connecting with each of said devices, and preferably a human-machine interface and at least one server to which information regarding said at least one secure exchange can be communicated, said method comprising the following steps: a) Establishing a first secure connection to a first device, possibly with a reader. b) Establishing a second secure connection, possibly with the reader, to a second device. c) Entering into the reader, using an interface of the reader or an external device connected to the reader, items of information relating to the exchange carried out between the first and second devices. d) registering an item of information relating to the exchange in the first device using the reader; e) registering the item of information relating to the exchange in the second device, in particular by means of a reader, or else cancelling the exchange. f) A step of verifying the items of information about the exchange, possibly in the first device, in particular by means of a reader. g) sending data relating to said transaction to said server;

[0007] "Exchange" should be understood to mean the transfer or copying between two devices of a computer file or of one or more quantities registered in one or more registers of said devices, which transfer can be partial or total. This exchange can correspond to the exchange or transfer of documents, but also to a payment or any other financial or non-financial transaction.

[0008] Preferably there are multiple servers, and what is described below for one server also applies when there are multiple servers.

[0009] The method preferably comprises steps a) and / or b), wherein the first and / or second device is capable of transmitting information to the reader, in particular information regarding the inventory of documents stored in the device, so that the reader can incorporate the documents into a menu.

[0010] Steps a) and b) may be omitted, in particular if the list of transferable files and quantities is known to the reader independently of the electronic device, for example if the system is limited to transferring files or quantities of a particular type, or if the user can assume that said files or quantities are present on the electronic device.

[0011] If registration cannot be performed in step e), the dual reader detects this by waiting, for example, for a period of time parameterized by the system, such as one minute, without being indicated by the second electronic device. The dual reader then cancels the transaction of step e sent to the first electronic device if the second electronic device is connected to the dual reader or is brought near the dual reader again, or if the transaction is subsequently sent by another dual reader and the server, either directly or indirectly by the first dual reader, after which the cancellation information item is sent to the server when the second electronic device synchronizes with the server, or to the first electronic device when the first electronic device synchronizes with the server. The dual reader can also register cancellation information items for other electronic devices without affecting the other electronic devices other than their use as information vectors, and these cancellation information items can be passed to the server when they are later used. Thus, the validity of the registration at the first device is conditional on the registration of an item of information relating to the exchange at the second device, and the validity of the registration at the first device may be communicated to the first device by the dual reader after registration at the second device, or thereafter by the server and then another dual reader.

[0012] The method preferably comprises step f).

[0013] If step f) is omitted when the first device is the recipient of a file or a particular total representing some or all of the quantities registered in a register, the first device will be credited with the file or the total upon its next connection to the same dual reader or to the server and by the same or another dual reader. Finally, when the first device is inserted into the dual reader, steps a), d) and f) can be performed automatically without the need for manual intervention.

[0014] Step g) may occur immediately after the transaction, for example in less than 5 minutes, or may occur after a longer period of time.

[0015] If step g) is not performed immediately after the transaction, information about the exchange may be transmitted through the dual reader to the server, which then enters into communication with the second electronic device, or with the first or second electronic device if step f) has been performed, or with an electronic device to which a file or another total resulting from the quantity debited from the first device is then transferred.

[0016] "Dual reader" is understood to mean a reader capable of implementing the invention and therefore of exchanging two electronic devices simultaneously and / or successively according to the invention.

[0017] Whether the secure exchange is a financial transaction or a simple file transfer, with the dual reader and according to the present invention, there is no need to connect to a remote server at the time of the transaction, thereby making the transaction easier and at the same time allowing for a secure transaction.

[0018] transaction "Transaction" should be understood to mean the transmission of an electronic file or of one or more aggregates resulting in quantities linked to said file or registered in an independent register.

[0019] A transaction may consist of a transfer from one electronic device to another, accompanied by the deletion of a file or the settlement of a quantity transferred from the electronic device that is the source of the transferred amount, or simply the communication of a file, or a quantity linked to or independent of a file, for reference by a dual reader, by a server, or by another electronic device connected to a reader, in which case the file or quantity then remains on the electronic device where it originally resides, and its communication to the second electronic device perhaps for the sole purpose of enabling the second electronic device to obtain the corresponding information.

[0020] The file or quantity can represent a number of points, or an identification or document that is shown in a particular situation when verification occurs, such as a discount card or a transportation pass. In this case, the file may or may not be retained on the electronic device after the transaction is completed for further verification. It may also be a document with or without an expiration date, such as a discount coupon, an access pass to a ski lift or other equipment or facility, an audio or video recording, a book or other object that is, for example, borrowed, lent or purchased.

[0021] It may be an item of confidential information, such as a login and password associated with a website, a user license that may or may not require a PIN or key necessary for decryption of a single file, or a biometric file such as a fingerprint scan, where the physical measurement reading is made by a medical sensor associated with a reader and placed inside or on the body, where the physical measurement reading is made by a sensor associated with the reader of some essential use such as electricity, water or gas, where the physical measurement reading is made by a sensor associated with the reader of the vehicle's state such as its size, location, speed, etc., and securely transmitted to another vehicle, for example an electronic key or note requiring the entry of a code such as a biometric or password in order to be decrypted or transferred. The reader may include some functionality that uses files containing some cryptographic keys and can verify some electronic signatures or decrypt or encrypt documents with such cryptographic keys. Such a reader connected to the screen of a PC can decrypt or verify the signature of some files displayed by such a screen based on an encryption key placed as a document on the electronic device, and the reader can be connected to a keyboard to encrypt or sign some text typed on it before transmitting it to the screen and then over the Internet. It can be money, but the invention also covers the exchange of stocks for the bearer of a CO2 emission right, or any type of bonus or penalty, such as points awarded in a test during a game, or certain attributes of an official document, such as driver's license points.

[0022] Files may be restricted or marked so that they are not displayed by the reader or copied to any device connected to the reader, or such actions are limited in time or amount, thus allowing for secure storage of user information, for example; the system stores information as required by law, but does not allow such information to be transferred externally or in large quantities.

[0023] A file can be marked as "copy-allowed," possibly with a set number of allowable copies, and the number of copies and the depth of such copies allowed. Copying refers to copying of a file that occurs within the scope of the system. Such copies may be marked as copies or potentially copies up to a certain depth, and the depth of the copies may also be recorded. This allows for official documents, such as ID cards, being copied and the copies being transferred to another secure device.

[0024] Files can be edited once they are marked this way, with the amount added to them equal to the maximum amount allowed for the file. For example, this feature allows for receipts, i.e., the automatic creation of plain storage space for files that can then benefit from the security capabilities of the system, e.g., that the file cannot be duplicated within the system or displayed outside the system.

[0025] Files can be associated together in a group, so that the transfer of one file can only be processed in conjunction with the transfer of other files to which it is associated. In such a case, a leader on another device cannot allow a transfer from a device of a file member of the group if such a transfer would allow the transfer of an amount associated with the file that is too small for the group of all files of which such file is a member. For example, this functionality allows a group of files to be prepared by a user so that the user can then quickly transfer them out to another device. The attachment of a file to a group can also be marked as "strong," so that a file that is strongly attached to a group on a particular device can only be removed from such a group if the file is marked as removable and the removal occurs on the same device where the file attached to the group. The first file attached to a group can also be prevented from leaving the group, so that any files attached to the group starting from this file will be linked to this first file, and in particular will not be linked to any other files that could later be attached to the group. For example, this functionality allows for the signing of several documents, e.g., a user adding a copy of their ID to a group of files containing documents that the user wishes to endorse without leaving open the possibility for other users to remove similar copies of their ID.

[0026] Further functionality can enable sealing of such groups of files, eliminating the ability for a group of files to be removed by removing some of its members, even on the device where they were attached to the group. This functionality can be implemented, for example, by marking the first file attached to a group as “sealable” and allowing the user of the device on which this file is marked as sealable to seal the group of files of which it is a part, thereby preventing the possibility that such a group of files could lose some of its members or eventually gain any new members. For example, this functionality allows for secure storage of endorsement signatures on documents endorsed by individuals who would potentially irreversibly consent to giving a copy of their identity to the group of files containing the document. Some files may be marked so that they can never be sealed to a group, or so that if something happens to the group, they can leave the group, preventing them from being freely exchanged, even though a file representing money, for example, may be permanently attached to the group. A file attached to a sealed group can also be used to prevent the transfer of a group of files if the original of a file derived from a template included in the sealed group or a copy of a document placed in the sealed group is not present on the device to which it is intended to be transferred, which allows, for example, to restrict the transfer or distribution of some documents to devices with, for example, a valid membership card.

[0027] Similarly, the file may have the ability to activate a repeater integrated into the reader or connected to it as a peripheral, or, if the file is grouped into an ID card copy or into a document template and an ID card original or a valid document from said template is present on a second electronic device in the proximity of said reader, to apply a voltage on a pin of the device. This functionality can be used, for example, to control appliances or door locks. In that case, the reader is preferably integrated into the appliance or lock it is supposed to control and can even be configured to work with second electronic devices in the proximity of either side of the door where the reader is located, if necessary.

[0028] Each electronic device is associated with an account managed by one or more servers external to the dual reader.

[0029] The server records all transactions linked to the account, as well as the files and quantities registered in the register of the electronic device. These transactions are reported to the server at the time of the transaction or thereafter. Actions affecting a file or quantity are confirmed by the server and registered as such on the server as soon as the server learns of all transactions linking a file or quantity transferred to the electronic device that contained an "initial" file or quantity, which itself has been previously registered and confirmed by the server following other transactions or has been modified by an external application authorized to do so, making it possible to ensure, firstly, that each transaction results in only one debit or credit of an account, and secondly, that any credit of an account by a quantity is compensated by a debit of another account by such quantity if the transaction corresponds to a transfer and not a reference. For example, if electronic device A sends a file or quantity to electronic device B, which sends it to electronic device C, the existence of the file or quantity value registered on electronic device C is not confirmed by the server before the server is informed of two transactions: from A to B and from B to C (chaining). This information process can be performed when the electronic device with the last transaction is synchronized, and intermediate transactions are registered with it during that last transaction. Files and quantities can also be updated through the intervention of a computer system external to the system, which can be authorized to perform this action. For example, the computer system of a company that issues discount cards can connect to a server and place a file corresponding to one of its discount cards on the electronic device's account. The server transmits this file to the electronic device when it connects to the electronic device through a dual reader that is itself connected to the server.

[0030] Transactions may be subject to certain constraints; for example, depending on the nature of the item being transferred, quantities may be constrained to vary within a defined range, with the possibility of varying by defined increments, if applicable. Typically, currency accounts have balances that vary by increments that are multiples of 1 / 100ths of a unit, with a minimum of 0 and a set maximum. Thus, a dual reader can transfer quantities registered in a register of a first electronic device from or to a register of another electronic device, ensuring that at the end of each transfer, the initial value of each of these registers is incremented by the quantity received or deducted by the quantity sent, following certain rules present in the dual reader at the time of the transfer; these rules may, in particular, be a remainder greater than or equal to zero and less than or equal to a maximum value. The system may be designed to associate a quantity with any file that cannot otherwise be associated with any quantity, assigning it an increment of 1, a minimum of zero, and a maximum of 1. Thus, a file can be sent by the system, while a verification procedure designed for the transfer of quantities can ensure that the file is present in only one of the system's electronic devices at any time.

[0031] The authenticity on the electronic device of the file or of the quantity forming the object of the transaction is preferably ensured by the fact that said file or quantity can be made unavailable on the electronic device as soon as it is transferred to another electronic device or as soon as the total amount transferred to the second electronic device from the quantity from the first electronic device is subtracted from the quantity of the first device, if the transaction is part of it, before or at the same time as it is added to the quantity registered in the register of the second electronic device; in addition, a verification can be installed so that this transferred total amount is not greater than the quantity originally registered in the register of the first electronic device.

[0032] For example, it is possible to ensure that the object of transfer is formed from a virtual note having a value, for which the sum of the quantities passing through the system corresponds to the balance of a bank account. The file can represent virtual currency, and the quantity can represent the value of the note. Transactions can be performed with respect to these virtual notes. The holder of the bank account issuing these virtual notes can authorize the system, through his or her external application, to increase the quantity associated with the file on the electronic device by a specific amount, but for the same amount, but actually for the credit of the bank account in real currency, and, conversely, credit the third-party bank account for debiting the quantity associated with the virtual note registered on an electronic device held by a third party. To transfer a monetary amount from a first electronic device to a second electronic device, the user can transfer all or part of the quantity associated with this virtual note present on the user's electronic device, along with the computer file associated with this virtual note (if it is not already there) to the second device. Preferably, the issuer of the virtual note credits the third-party bank account only if the amount to be debited is confirmed by the server.

[0033] The same electronic device can be configured to simultaneously and conditionally perform related transactions on different files and quantities, for example, a file and quantity on the electronic device stores the number of traffic tickets available on the device, while another file and another quantity stores the total amount available on the device.

[0034] The files and quantities (electronic files and / or associated quantities registered in a register) may originate from and be updated through the server by external third party applications belonging to the company issuing the files or registered quantities, such as, for example, a transit pass seller or a bank.

[0035] The issuer can assign to the files or quantities it issues information allowing certain fungibility with virtual notes issued by other banks, and the dual reader is then authorized to receive the entire transfer order for this currency displaying the total amount of quantities associated with the same currency, so that the user does not need to mention the issuing bank linked to the virtual note, and the dual reader takes responsibility for breaking down each entire transfer into transfers corresponding to the various virtual notes present on the electronic device to be debited.

[0036] Transactions between two electronic devices via the dual reader can be performed without connection to a remote server. However, immediate synchronization of the performed operations with the server and / or verification of the dual reader's connection to the server during the transaction can be ensured. In this case, the dual reader can be connected to a cellular data network such as 3G, 4G, or 5G, a mesh network, or a local area network (LAN) connected to the Internet, or to an external device connected to the Internet, such as a microcomputer, telephone, or dedicated terminal device. To perform transactions with external third-party applications, a user can use the external device connected to the dual reader, thereby selecting one of the two electronic devices linked to the dual reader with which they want to interact, and further selecting the files and / or available quantities they want to send or receive.

[0037] Before each transaction, an "available" quantity can be calculated that is equal to the recorded quantity plus credit transactions minus previous debit transactions, and any transaction that aims to debit the account beyond this available balance can be denied. A "final available" quantity can also be calculated that corresponds to this same quantity minus previous debit transactions. This calculated quantity can be called final unless it takes into account credit transactions that have not yet been confirmed by the server.

[0038] The dual reader can generate transactions by recording the transaction on each electronic device to be debited or credited, and, if applicable, by copying the file to be transferred to the device to be credited if it is not already there.

[0039] The dual reader performs this transfer in order to perform the quantity transfer. ● the quantity present on the electronic device; ● or credits written to an electronic device resulting from a previous transaction; can be divided into subtransfers related to Meanwhile, for each debited subelement, verify the amount or prior transactions such that the debited total does not exceed the fixed and available amount, or, for prior transactions, verify the total amount of the initial credit transaction minus the total amount of any debit transactions that may have been previously associated with it.

[0040] Functionality can be provided aimed at limiting transactions, for example by imposing maximum limits on quantities or on the amount transferred.

[0041] Transactions, files and quantities registered on the electronic device can be transmitted to the server over the Internet upon their respective sufficiently long connections.

[0042] The dual reader can act as a relay to inform the server, which enumerates transactions originating from electronic devices that are in communication with the server but have not necessarily generated said transactions.

[0043] During or after connection of the electronic device to the server, the server can verify the transaction in a one-time manner and calculate new files and quantities for the device, which involves: - A list of transactions that may be deleted during this connection or upon the next connection of the device. - A list of transactions that must be added to or removed from the balance when it is updated. - a list of transactions reported to the server by other electronic devices and readers, but which do not yet exist on the electronic device in question, especially if the transaction created a debit on the electronic device but the corresponding credit transaction has not been communicated to the device being credited, for example, if the user neglected to place their card next to the reader at the last moment between operations, or if a debit transaction with an unknown party shown on the card cannot be replaced by the same transaction but includes the party's identifier.

[0044] Upon a new connection of the device, or if this lasts long enough, during the same connection, the operations linked to each of these lists described above, and also possible update processes of files and quantities, may be performed.

[0045] If desired, the system can be configured so that updates to a particular transaction and to certain quantities and files are simultaneous. For example, if an update includes the inclusion of a transaction representing the addition of 1 to a quantity, this transaction is deleted from the device at the same time that the register containing the quantity is incremented by 1.

[0046] Electronic Devices The electronic device according to the invention is preferably compatible with existing payment terminals.

[0047] Preferably, the electronic device is in the standardized format of a credit card, as defined by the standard ISO 7810. As a variant, it may be a mobile phone or a SIM card that can be inserted into a mobile phone.

[0048] When it is in the form of a card, the device conveniently has a chip with a connector that can be inserted into and communicate with a dual reader.

[0049] The electronic device may also be equipped with a system for communicating with the dual reader via a contactless link, for example an RFID system.

[0050] The electronic device may contain a protected symmetric or private key and memory, e.g., flash memory and perhaps a processor, encrypted with the device's key. The memory containing the key is preferably physically protected so that physical access to it leads to its destruction before the information it contains can be extracted from it. The owner of the device can no longer use it and must contact the operator of the central server, who, if able to identify the electronic device and have the appropriate procedures in place to use the system, can possibly recover from the server the files and quantities present on the electronic device and place them on a new electronic device.

[0051] The electronic device may include a power source, such as a battery, an electromagnetic induction system, or a capacitor, supercapacitor, or accumulator, which is recharged upon connection to a reader or other device. The device may also include several sensors, such as temperature, pressure, position, etc., and may have the ability to create or update several documents using these sensors.

[0052] The electronic device may possibly be equipped with an interface that allows direct one-way or two-way communication with a remote server, for example by using low energy consumption wireless networks such as BLE (Bluetooth Low Energy), Sigfox, Lora, 4G LTE, etc. This communication with the server can be used when available to speed up the synchronization of data between the electronic device and the server.

[0053] The electronic device may have not only a screen but also a mini-keyboard, the screen making it possible, for example, to display documents or balances, and the mini-keyboard making it possible, for example, optionally, to select what is displayed or even to transfer certain functions of the dual-reader's keyboard to the device, such as, for example, the ability to authorize transactions.

[0054] The electronic device may be configured to perform all or some of the following operations: - Before any communication with a reader, verify that said reader is part of an authorized reader. - Only accept encrypted information for which it is the intended recipient. - Encrypt and sign any outgoing items of information intended for the reader or for the server.

[0055] The information recorded on the electronic device may be all or some of the following information: · Copies of computer files and copies of quantities. A log of the most recent transactions that have not yet been acknowledged by the server. A list of transactions with other electronic devices executed by the device that have not yet been recorded on a remote server, allowing the server to chain each transaction on the device to a quantity or file on another electronic device, even if these transactions have not yet been communicated to the server. A PIN code, possibly to authorize the transaction in which the electronic device is inserted into or otherwise communicates with the dual reader. · Electronic device identifier numbers. A private key for the electronic device that is not available outside of said device. The dual reader's and server's public keys and a list of potentially unique private keys associated with any servers or dual readers with which it can communicate and used by such servers or dual readers to identify itself.

[0056] Within the electronic device, it is possible to record for each file and quantity or type of file and type of quantity the minimum, maximum and authorized increments as well as possible rules for constraining its transfer.

[0057] Dual Reader The dual reader, which may also be called a "reader", is configured according to the present invention to establish a secure connection to electronic devices in order to carry out transactions, and therefore it comprises the means for communicating with these electronic devices.

[0058] This connection can involve physical contact between each electronic device and the dual reader. As a variant, this connection can be made contactless, in particular via a wireless link of the NFC type. The dual reader can be configured to allow secure exchanges with electronic devices in different locations through two dual readers linked by a computer connection. This type of use can then be limited to cases where one of the electronic devices has an owner, whose identity is shown to the holder of the second electronic device before the second electronic device carries out the transaction.

[0059] The dual reader can have the option to be controlled by a computer, phone, or electronic system designed for this purpose. This can be particularly useful if the computer or phone performs the functions of, for example, a cash register, ATM, or train ticket seller. The dual reader can include several sensors whose readings are used to create or update documents. The dual reader can also be connected to several peripheral devices, such as sensors whose readings can be used when creating documents or biometric devices whose readings can be used to perform biometric authentication for the reader. The dual reader can include some capabilities to automatically generate documents and place them on one of the electronic devices to which it is connected. Such automatically generated documents can be, for example, physical measurements, such as the position of molecules in a liquid or measurements of temperature or concentration. The dual reader can also incorporate one of the electronic devices, and the functionality of the incorporated electronic device can remain active when the "dual reader" functionality is turned off. The dual reader can also integrate one or more of the electronic devices, and the functionality of the integrated electronic device can potentially remain active when the "dual reader" functionality is turned off. The dual reader can also be integrated into another object, such as a phone, computer, wallet, or other, without necessarily requiring that the other object be necessarily connected to the network during a transaction with the electronic device.

[0060] In one exemplary implementation of the invention, one of the electronic devices is a card that is inserted into a card reader that supports dual readers, and the first card is held in the reader, although connections to the other electronic device and possibly to the card may be made contactless. Thus, in this example, the first connection is contact-based and the second connection is contactless.

[0061] The dual reader can be configured to allow simultaneous exchange of information with two electronic devices, either through contact or contactlessly, when the two electronic devices are connected thereto.

[0062] In a variant, the exchange of information is asynchronous and the dual reader is configured to exchange information with only a single electronic device at a time, in which case subsequent connections are made to the electronic device to carry out the transaction.

[0063] The dual reader can be configured to connect to an external server while a transaction is being carried out between the two electronic devices, or outside of such a transaction.

[0064] The dual reader can take the form of a payment terminal, for example one that is used today in shops to make payments with a bank card, or else a reader with a keypad similar to a personal card reader, used to authorise connection to a banking interface but allowing the entry of information relating to the exchange. The dual reader can comprise both a contact card reader and a contactless card reader, in particular of the NFC type.

[0065] Dual readers can be grouped into one device to form a "multiple dual reader," which allows transfers between multiple pairs of electronic devices connected directly to the "multiple dual readers" or through connections to remote dual readers, as described further below. For example, a multiple dual reader can have slots for many internal devices, allowing transactions for other devices to be connected to other remote dual readers that are themselves connected to the multiple dual readers via the Internet or computer network. This can be useful, for example, for online shopping websites that can manage their payments using a single "multiple dual reader."

[0066] Multiple electronic devices can also be grouped into one single device, allowing multiple dual readers to process transactions using such multiple electronic devices and manage multiple electronic devices without the need for operators of the multiple dual readers.

[0067] The dual reader may be equipped with an interface that allows it to connect to a computer network, for example the Internet, via a 3G, 4G, 5G or Wi-Fi network, a mesh network or a LAN that connects to the Internet via a computer or phone, if applicable. The human-machine interface of the dual reader may include a keypad, preferably with buttons, and at least one screen, from which the system can display two messages intended for the bearers of the first and second devices, respectively.

[0068] As a variant, the human-machine interface of the dual reader comprises a voice interface. The interface of the dual reader may also comprise means for identifying the holder of the electronic device, for example the option to enter a PIN code or a biometric system, which, after identifying said holder and taking into account the documents carried by said electronic device, is able to verify the credentials of the electronic device and of its holder.

[0069] The dual reader human machine interface can enable: - Verify the connection to the electronic device inserted into the reader or otherwise connected to it. - Perhaps select the files or quantity to be transferred. - Possibly enter a quantity for the transaction, for example the amount to be transferred, and indicate whether this involves sending or receiving for the corresponding electronic device. - Displaying possibly consecutive messages to each user of the two electronic devices. - Allow users to view balances and / or one or more quantities associated or not associated with a file on their electronic device. - Allows you to change the PIN code. - Perhaps allow the contents of the file to be changed if this is allowed for this file. - Possibly allowing the creation of files and associated quantities.

[0070] The human-machine interface may allow one or more quantities associated with the transfer to be displayed before confirmation of the transaction, and a file relating to the transaction may also be displayed or read, particularly if it is an audio or video file, and instructions to the user may also be displayed or read.

[0071] Where applicable, the human machine interface is transferred to another device with which the dual reader communicates via a wired or wireless link, such as a computer, cash register, electronic lock or mobile phone.

[0072] The dual reader preferably comprises the means necessary to carry out the above-mentioned transactions and therefore to sign messages with a computer key identifying it, i.e. the available quantities, in particular the ability to calculate the available quantities definitively, for example to create messages representing transactions or commands to be registered in the electronic device, as well as means enabling the server to freely write, read and delete the quantities, transactions and list of authorized readers registered in the register to and from the electronic device.

[0073] The dual reader preferably comprises all or some of the following elements: a connection, e.g. of the USB type, for a wired link to a microcomputer or other terminal, a wireless connection, for example of the Bluetooth type, to a microcomputer or a telephone, a wireless connection, for example of Bluetooth or RFID type, to establish a link to the electronic device according to the invention, a contact-type connector for communicating with the electronic device according to the invention when the electronic device is inserted into the reader; an internal clock that is synchronized on every connection to the server and on which transactions and balances are time-stamped, this clock preferably being accurate to within + / - 5 seconds per month; a physically protected memory containing the dual reader's private key, physical access to which preferably leads to its destruction before the information it contains can be copied from it; At least one memory, the contents of which may be encrypted with its own private key and in which all or part of the following information may be stored: A code that identifies the dual reader, A list of the most recent transactions executed through the dual reader and the corresponding files, a buffer list of transactions performed by other readers, including fraudulent transactions or balances or any other items of data that the server wishes to transmit to the electronic device or that the electronic device wishes to transmit to the server; A list of common or public keys, and possibly private keys, of a server and electronic device that are associated with the server or electronic device and used to communicate with and identify itself to such server or electronic device.

[0074] The dual reader can be configured to perform all or some of the following operations: reading the PIN code and the identifier of the connected electronic device; Calculate the available quantity, Delete, write, or keep transactions, Allowing connected electronic devices to sign messages; On the electronic device, the list of authorized readers and servers is updated according to the security system employed.

[0075] Another subject of the invention is a dual reader considered as such.

[0076] server These are remote computer systems that include an account associated with each electronic device and a dual reader based on transactions performed by the associated electronic device or based on commands originating from authorized external applications that can add or remove files and modify quantities.

[0077] The server includes at least one memory in which all or part of the following information may be stored: 1. For each electronic device: On this device, copies of transactions that have not yet caused changes in the quantity or files to which the transaction relates, and those related files for which another copy has been recorded on the corresponding electronic device, and each transaction that is subsequently confirmed by the server, is marked as follows: · Quantities and files recorded on electronic devices. Information identifying the list of keys present on the electronic device. 2. For each dual reader: Information identifying the list of keys present in the dual reader. 3. A preferably physically protected server private key, or a preferably physically protected list of private keys, each of which is used by several individual devices or individual dual readers, or groups of such, to identify itself, together with their associated public keys. 4. A list of the dual reader's public keys. 5. A list of public keys for electronic devices. 6. A list of other servers' public keys.

[0078] The servers can communicate with each other, for example by the electronic device and by the dual reader, to distribute information between the servers, which can allow information relating to a particular electronic device to be kept in a particular dual reader or in a particular server, and which can also be read and changed or modified as needed by the server to which any dual reader is connected. The system may include only one server, thus reducing the complexity of the system.

[0079] The server may be configured to reject any transaction that purports to debit a quantity by an amount greater than the said quantity and to mark such a transaction as fraudulent, and this item of information may be communicated to the electronic device upon its next connection. A transaction that is marked as fraudulent is thereafter no longer considered. Transactions that depend on the fraudulent transaction may also be canceled or marked as fraudulent.

[0080] In particular, the server can mark a transaction as valid as soon as the following verifications are made: - They are associated with an electronic device and dual reader that is valid for the duration of said transaction. - Either they debit quantities resulting from transactions that have themselves been confirmed by the server before this verification, or they debit quantities or files that are pre-registered by the server on the electronic device, or they debit files that have been created from scratch using the dual reader and have not yet been sent. ● That they comply with the rules imposed on such transactions at the time of this transaction, such as: o It is not possible to debit a quantity registered in a register by an amount greater than the above quantity, if this rule is applicable to this quantity. o It is not possible to debit a total amount greater than the amount registered in the register of the electronic device adjusted by the total amount of other transactions before the verified transaction and from which this total is to be debited, if this rule is applicable to this amount. o It is not possible to make a transaction if other linked transactions are not executed at the same time, and not all of these transactions have been executed, and one of these linked transactions may require, for example, biometric verification.

[0081] Information about the transaction may include information about the quantity present on the electronic device being credited, which may be required by the server to verify the transaction.

[0082] The server can be configured to calculate and update quantities only if it has knowledge of all transactions marked as confirmed for each device and linking each credit to a debit of an already confirmed quantity. In this way, transactions originating from a reader or from an electronic device not registered with the server cannot cause a change in the quantity. This also allows the server to credit a quantity to an electronic device based on the same transaction linked to a debit on another electronic device, ensuring consistency across all electronic devices in the total value of the quantity adjusted by all transactions that have been confirmed but not yet taken into account by the quantity registered on the electronic device. The server can also be configured to simultaneously calculate and update quantities debited and credited by the same transaction. The server then keeps in memory, first, the quantity registered on the electronic device, and second, the quantity updated by the server but not yet registered on the electronic device. Linked to that quantity is the transaction used for the update and must be deleted from the electronic device when the newly calculated quantity is copied to the device.

[0083] To facilitate this chaining, the electronic device may contain copies of other transactions carried out prior to the debit of the quantity or file, which transactions allow linking this debit to an initial file or quantity already confirmed by the server, unless these transactions have been reported to the server in another way.

[0084] During a transaction with an external entity, the server can begin by calculating the relevant quantity, taking into account all of the transactions that apply to said quantity present on the device.

[0085] To modify a document represented by a file or quantity registered in a register of the electronic device, if the electronic device involves a transaction relating to this document that has not yet been confirmed by the server, a dual reader may follow the procedure provided for transactions with external entities, thus requiring synchronization with the server, and then allowing and implementing the modification of said file or quantity in the electronic device. The device may also restrict file changes to files with only one register that can register a quantity, where this quantity is limited to 0 or 1.

[0086] The servers may be accessible by connection to a data network, so that they may enable data synchronization of at least one of the electronic devices with the servers via a computer or telephone. An exemplary synchronization process is further described with reference to FIG.

[0087] A system embodying the present invention can include several electronic keys per server, which can be used indiscriminately when necessary, so that each server can respond to dual readers and electronic devices in a short time.

[0088] In one exemplary implementation of the present invention, an electronic device includes a SIM chip card and an RFID connection, and the system is configured to allow transactions to involve two dual readers that are remote from each other. The system can then note the respective identifiers of the two readers in the transaction record. A mechanism for pairing the two readers can be configured. This mechanism can include means for displaying the identity of the holder of the remote electronic device and can also limit transactions to transactions in which at least one of the electronic devices involved has an identifiable holder. The pairing mechanism can also include means for one or each of the two paired readers to indicate the location where the other reader is located.

[0089] File and quantity security "Secure" is intended to mean that information cannot flow into or be modified in a system outside of the procedures specific to that system, and cannot be left there or entered without authorization from the user in accordance with the system's procedures, which may depend on each document type.

[0090] The data present in the electronic device and reader or server according to the invention is preferably secure: these data registered in memory can only be interpreted in the presence of the electronic device or the dual reader carrying them, for example through encryption using a key present on this electronic device or dual reader.

[0091] Mechanisms for protecting the software carried by the electronic device and dual reader preferably exist to prevent unauthorized software from being introduced therein. This software may be signed, and the signature verified when it is loaded. These signatures may also be verified before every transaction. The software may also be made different for each specific element of a system, for example, by adding a reference to the identity of the element of the system on which it is intended to run to its code, so that hacking or compromising one piece of software only compromises the element on which it is intended to run, rather than many or all elements of the system. By hacking or compromising software, we mean the ability to replace such software with a different one without the element of the system on which it is intended to run being able to detect such a replacement. For example, techniques used to secure files have used methods known as "hashing," and such methods, such as MD5, have been reported to be completely insecure at some point.

[0092] Preferably, all communications between the various elements of the system are carried out in such a way that they are understandable only to the elements of the system and cannot originate from third party elements outside the system authorized for this purpose and linked to a server or controlling the dual reader on behalf of the user.

[0093] Each element of the system, i.e. each server, dual reader or electronic device, can have a private key that it knows only, but whose public key is related to its identifier. Each element of the system can also have a private key that is dedicated to each other element of the system, and hacking of any such private key will only compromise the security of communications with the device with which it was associated, and not with all devices of the same category.

[0094] Advantageously, none of these private keys of the server, of each dual reader, or of each electronic device ever leaves its carrier and are advantageously physically protected by appropriate electronic techniques.

[0095] A mechanism can be provided that allows the server's keys and each dual reader's keys to be updated.

[0096] Fraud Detection Because the dual reader contains a clock, information registered in the first and second devices can be time-stamped with the time of the exchange.

[0097] The server may cancel a transaction recorded on the electronic device if the chaining of the transaction to any transaction results in the transaction not complying with any of the rules associated with the transaction and parameterized at the server.

[0098] Preferably, transactions are deleted from the dual readers only after they have been reported to the server. Dual readers are conveniently equipped with a light or other indicator that shows when their entire memory is in use, they cannot operate for new transactions.

[0099] Any anomalies, such as chaining, signature or date anomalies, are preferably marked as fraudulent.

[0100] Any balance, any transaction, any list that is detected as fraudulent, for example with an invalid signature, will be reported to the server and marked as invalid.

[0101] Handling fraud The server can be configured to detect fraud and mark any transaction, list, balance or electronic device as fraudulent.

[0102] These overrides and possible modifications are transmitted to the electronic device.

[0103] An electronic device or reader can be marked as unauthorized, rendered inoperable, and removed from the list of authorized electronic devices or dual readers and marked as such. The list of unauthorized electronic devices can be communicated to the dual reader so that the reader will stop unauthorized electronic devices from connecting to it.

[0104] Transactions made using a known fraudulent reader that have not yet been confirmed cannot be confirmed by the server until a reasonable time set by the server has passed from the moment the transaction was made, and such transactions may be marked as suspicious by the device and prevented from being subordinated to other transactions themselves until the reasonable time has passed, or until they have been validly confirmed by the server.

[0105] Data Integrity Certain operations that register quantities and transactions or other operations must be consistent with respect to each other. Transforming a transaction by modifying a quantity or file cannot be accomplished unless the two elements, i.e., the transaction and the quantity or file, are updated or deleted together. A process can be used that ensures that update blocks in the electronic device are confirmed only if these information blocks are registered completely and correctly. For example, a reference can be assigned to the information in these write blocks, and this reference is marked as valid only if all of the elements of the block are written correctly. To delete redundant information, a referenced deletion instruction can be registered as well, i.e., a procedure that later actually deletes this redundant information.

[0106] Communications Security Various techniques can ensure the security of communications between various servers, electronic devices, and dual readers. The following description is not intended to be exhaustive but merely illustrative of techniques that take such security into account.

[0107] List-based security Each element of the system, i.e., each server, each dual reader, and each electronic device, can have one or more private keys that are not duplicated anywhere, but whose corresponding public keys are known to the system and compiled in a list. If a server, dual reader, or electronic device has multiple private keys, some or all of these private keys can be associated with a particular or group of other servers, readers, or devices, and their corresponding public keys are made public by such other servers, readers, or devices with which they are associated. This key, which may be the same or different from the private key associated with any element of the system (servers, electronic devices, and dual readers) in any event, is used to update its software, update itself, and encrypt data in its memory.

[0108] These lists are therefore lists of public keys associated with each element: there is thus a list of server public keys, a list of reader public keys and a list of electronic device public keys, and such lists have, in the case of multiple private keys, information of other particular or groups of servers, readers or devices to which they are associated.

[0109] The server maintains each of these lists, as does the dual reader, and all electronic devices have a list of the server's public keys and of the dual reader's public keys.

[0110] When an element of the system is connected for a long enough time (dual reader to server, electronic device to reader, or electronic device to server), the list is updated.

[0111] Any transmission of data will be sent only to elements listed in one of these lists, encrypted so that only the intended recipient element can read it, and signed so that the intended recipient can verify the authenticity of the sender of the message.

[0112] The system allows private keys and their associated public keys to be updated at the request of the server.

[0113] This system can ensure that each electronic device communicates with only one reader or one server of the same system, and likewise, that each reader communicates with only one server or one electronic device of the system, and does so in an encrypted manner.

[0114] While list-based security has the drawback of requiring significant storage and updating of lists in each electronic device and reader, it has the advantage, first, of making it possible to defend against theft of private keys, since these keys are physically located on and designed not to leave each hardware carrier, thereby requiring fewer securing techniques, and second, of ensuring redundancy, so that theft of a key affecting a reader or electronic device compromises only that reader or electronic device. The use of multiple private keys can mitigate the impact of hacking such keys, since compromising a key affects fewer servers, readers, and devices, and a compromised server key, for example, in a multiple private key system, only renders other elements of the system with which such a compromised private key is associated insecure. Private keys can also be updated from time to time or when they are suspected of being hacked, so that an element of the system that knows the latest corresponding public key cannot communicate with an element that appears to be part of the system but in fact does not process the new private key but only one of the previous keys.

[0115] Shared Key Security The list of keys of an electronic device, the list of keys of a dual reader, or the list of keys of a server can be replaced with a smaller list of shared keys of the dual reader, the electronic device, or the server, respectively. These keys are said to be shared as long as they are found on some elements of the system, even if they are secret and should not leave the system. This exchange can be partial, for example, only affecting the list of electronic devices or the list of readers, or the list of electronic devices and the list of readers, or the list of some readers, electronic devices, and servers. In these cases, the list of electronic devices, for example, no longer exists and is replaced with the shared keys of the electronic devices; then, the elements of the system must use this shared key to communicate, thereby avoiding communication with elements outside the system. These keys can be asymmetric, a private / public key system in which the private key of the elements of the list, found on each element registered on the list, and the public key on each element of the system, can enter into communication with the elements of the list, or symmetric, in which this same key, found on both the elements registered on the list and on the elements of the system, can communicate with the elements registered on the list. These keys can be updated periodically to prevent two recently updated elements from communicating with a potentially stolen key. This update is performed by a server, which secretly transmits new shared keys to it with knowledge of the public keys of each electronic device and each dual reader. With list-based or shared-key security, two elements of the system can be authorized to communicate with each other if they each have a public key that corresponds to a private key located in the other element, and if this private key is unique and located only in that element, or is shared by various elements of the system and then located in several elements of the system. Elements of the system can also communicate with each other if they each know the same private key shared between them or between them and other elements of the system.

[0116] In one exemplary implementation, the electronic devices and readers no longer contain a list of public keys of the electronic devices and their IDs and of the dual readers; only one key is shared by the dual readers and another key is shared by the electronic devices. Each electronic device and each dual reader also has a private key, but only the server has a list of their associated public keys. The server can then change and update the shared keys.

[0117] In another exemplary implementation, the existence of a shared key for dual readers makes it possible to avoid the requirement for a list of the public keys of readers and their IDs in each electronic device.

[0118] In another exemplary implementation, the existence of a shared key of the electronic device allows for avoiding the requirement for a list of the public key of the electronic device in each dual reader.

[0119] Peripheral Security Peripherals connected and used by a reader are preferably secured so that information provided to the peripherals can be trusted or so that information provided by the reader to the peripherals can remain secure. Thus, peripherals can be registered, preferably collectively or individually, with a server that can verify to the reader that such connected devices are trustworthy. The authentication procedure can include verification that the peripheral contains a private key and that the associated public key is known to the server, so that creation of a shared key can be used for subsequent communication between the reader and peripherals.

[0120] Additional Security Other security measures may be implemented, including: Associating an electronic device with a user, where such association is reported to the electronic device or to a server. - A requirement that the holder of the electronic device identify themselves and confirm the transaction, for example by entering a PIN code or by using a biometric device before placing the electronic device next to the dual reader. These means of identification may be located randomly on the dual reader or on the electronic device, or may even be accessible to the dual reader by the device to which it is connectable. Thus, the dual reader or the electronic device may include means for identifying the user, and these means may be biometric. · Adding a button or biometric device to an electronic device to confirm a transaction or enter a PIN. · Adding a screen to an electronic device to display messages, files or quantities. Adding attributes to files, such as expiration dates.

[0121] The present invention will be better understood upon reading the following detailed description of exemplary, non-limiting modes of implementation thereof and upon examining the accompanying drawings, in which: [Brief explanation of the drawings]

[0122] [Figure 1] 1 illustrates a schematic diagram of an exemplary system for implementing the present invention. [Figure 2] 1 is a block diagram illustrating various steps of an exemplary data exchange method according to the present invention; [Figure 3] 3 is a view similar to FIG. 2 of a variant implementation of the invention; [Figure 4] FIG. 2 is a diagram of an example of the timing of data flow between an electronic device and third-party software connecting to a server in accordance with the present invention. [Figure 5] FIG. 2 illustrates various steps that can be performed to synchronize data between an electronic device and a server according to the present invention. [Figure 6] FIG. 1 illustrates various steps that can be performed to update the list and keys of an electronic device or of a reader. [Figure 7] FIG. 1 illustrates various steps that can be performed to update the software of an electronic device or of a reader. [Figure 8] FIG. 1 illustrates various steps that can be taken to synchronize a reader with a server. [Figure 9] FIG. 2 illustrates various steps that can be performed by a user to create or modify a file in a secure device. DETAILED DESCRIPTION OF THE INVENTION

[0123] FIG. 1 shows an exemplary system for implementing the method according to the present invention.

[0124] The system includes a dual reader 10 according to the invention, configured to exchange information with two electronic devices 20A and 20B according to the invention, in the format of a credit card in the example shown.

[0125] The dual reader 10 and electronic devices 20A and 20B can exchange information with at least one remote server 30, for example via the Internet or wireless link, and, if applicable, by means of an auxiliary device such as a microcomputer 40 or a mobile phone 41.

[0126] 2 of the steps of an exemplary method according to the present invention for performing a transaction between two electronic devices 20A and 20B. The transaction is said to be synchronous in this example because electronic devices 20A and 20B must be connected to the dual reader 10 at the same time so that the transaction can take place, and the first secure connection and the second secure connection overlap in time, with the first connection being contact-based and the second connection being contactless.

[0127] Thus, a transaction takes place between a first user A having a first electronic device 20A according to the present invention and a second user B having a second electronic device 20B according to the present invention.

[0128] User A begins by inserting his electronic device 20A into the dual reader in step 201. User B may place his electronic device next to the reader in step 201 part 2, perhaps to inform the reader of the nature and quantity of files contained therein.

[0129] In step 202, user A selects the action he wishes to perform, for example, transaction / balance or balance-create balance, the latter selection corresponding to showing the balances of the two devices 20A and 20B.

[0130] Next, in step 203, the user selects the direction (send or receive), file, or quantity of the transaction, and, if applicable, provides a quantity, ie, an amount in the case of a financial transaction.

[0131] Step 203 may be repeated if several transactions are linked, i.e., if an exchange must consist of several files or quantities sent or received simultaneously.

[0132] In step 204, some transactions may also be generated automatically if the originally selected transaction so requests; for example, the transferred document may be associated with a price and a payment corresponding to those values ​​may need to occur in response to their transfer, or conversely, a payment for a quantity may be set on the receiving device to generate a receipt; such automatically generated transactions are shown to the user, who may perhaps enter their PIN (Personal Identification Number) code to confirm the action or just confirm the automatically generated transaction, if any.

[0133] User B can load items of information onto the screen of the dual reader 10 in step 205 to provide him with a transaction or to find out his balance.

[0134] The user can enter a PIN code in step 206 if the operation requires this, and then place their electronic device 20B in the dual reader 10 to perform the transaction in step 207. If some transactions are reported on device B as requiring some automatically generated transactions that are not already on the list of transactions to be performed and confirmed, such automatic transactions are generated and the process resumes at step 204.

[0135] In step 208, the reader indicates that the transaction is complete.

[0136] User B can then remove his card in step 209 and User A can do the same in step 210 .

[0137] In step 211, the reader sends information about the exchange to the server.

[0138] In the case of grouped transactions, the same code may be assigned to each transaction. The transaction is first registered on a first electronic device, but is identified as "conditional" and associated with a code. The conditional allows the system to consider debits written to the electronic device but not credits, which are only considered if the conditional is removed. The transaction is then also conditionally registered on a second device and associated with the same code, but in this case, no transactions or only debit transactions can be considered unless the conditional is removed. The conditional may be removed at the end of the write, within a reasonable time period parameterized by the system, by writing a new line, called the conditional removal line, to the second device. Once this last line is sent to the reader, it is sent to the first device, removing the conditional status of this single line registered on the first electronic device for transactions associated with the same code on this device. The command is then transmitted to the server. If the conditional removal is not registered on the second electronic device within a reasonable time, the reader generates a write operation canceling the grouped transactions during this read of the second card, or during or after a re-read of the first card. This write operation is communicated to the first device if it has not yet received it, or to the second device if it has not yet received it, and then to the server. All debit or credit transactions associated with this code are then canceled. The server can then be responsible for preparing instructions to delete these transactions that are written to the two electronic devices.

[0139] The transfer of files or quantities present in the system can also be constrained by other rules attached to said files and quantities, for example making their transfer conditional on the transfer of a copy of an identity document, which is itself possibly conditional on biometric authentication of the holder of the electronic device. A transfer constraint may, for example, be the reciprocal transfer of money corresponding to the invoice amount for a trader-issued invoice, or else the transfer of carbon dioxide emission credits required by law when purchasing an object.

[0140] A description will now be given with reference to FIG. 3 of one variant implementation of the invention in the case of asynchronous transactions.

[0141] User A begins by bringing his electronic device 20A near the dual reader 10 in step 301, and user B does the same in step 301 part 2. These actions are used to send the reader a list of files and quantities contained on each electronic device placed next to the reader; these actions can be omitted if the reader, depending on its configuration, is able to dispense with knowing the files and quantities available for transfer on the electronic devices.

[0142] In step 302, user A selects the action he or she wishes to perform, for example, create transaction / balance or balance-balance, the latter selection corresponding to displaying the quantities available on the two devices 20A and 20B.

[0143] Next, in step 303, the user selects the direction (send or receive), file, or transaction amount.

[0144] If several transactions are linked, step 303 may be repeated.

[0145] In step 304, User A can enter his PIN code and confirm the action.

[0146] A transaction is then prepared by the dual reader 10 with an "unknown" partner.

[0147] In step 305, the dual reader displays the proposed transaction and prompts User A to bring his / her card nearby.

[0148] In step 306, user A brings his device, for example in the form of a card, nearby. All debit transactions are verified so that each available quantity debited on this electronic device is at least equal to the total amount to be debited, and no credited quantity exceeds its maximum value. The reader creates a copy of the previous transaction, linking the files and quantities to be debited from this electronic device to the files and quantities already registered on the electronic device by the server. If one or more available quantities are insufficient, the operation is canceled; in the opposite case, in step 307, user B is prompted to bring his device nearby, possibly by entering his PIN code.

[0149] In step 308, User B enters his PIN code.

[0150] In step 309, user B brings his device 20B, for example in the form of a card, nearby. All debit transactions are verified so that each available quantity to be debited on this device is at least equal to the total amount to be debited. If one or more available quantities are insufficient, a write operation canceling the transaction is generated and registered on this device. In the opposite case, the transaction is registered there. Previous transactions collected in step 306 on device 20A are copied to electronic device 20B. Thus, the items of information about exchanges contain information about previous exchanges related to the same register or file. The reader creates a copy of the previous transactions, linking the files and quantities to be debited from this electronic device 20B to the files and quantities already registered on the electronic device by the server. The registration and copying are authorized by writing an instruction to confirm the transaction, which makes these transactions valid on device 20B.

[0151] In step 310, User B is prompted to remove his device and User A is prompted to bring his device closer.

[0152] In step 311, user A brings his device nearby. A confirmation or invalidation command is sent to electronic device 20A. The transaction written to this device 20A is simultaneously updated with the final known identity of device 20B. The previous transactions collected in step 309 are copied to electronic device 20A. If this step 311 is omitted, these operations are then performed during another synchronization with the servers after they have received a confirmation command conveyed to them by the same reader or by another reader with which device 20B has subsequently communicated.

[0153] In step 312, the reader indicates that the transaction is complete and prompts User A to remove his device.

[0154] In step 313, the transactions and verification instructions generated during this exchange are sent to the server along with the transactions copied from devices 20A and 20B in steps 306 and 309.

[0155] FIG. 4 shows an example of data exchange between a user, an associated electronic device, and an external website controlling the insertion (credit) or removal (debit) of a file or change in the quantity allocated to the electronic device in the system.

[0156] The electronic device 20A or 20B may be in the form of a credit card, for example. It may communicate with a server by means of the dual reader 10 or by means of a computer or telephone. A user may communicate with a website which itself communicates with the server 30.

[0157] In step 401, a user opens a session with a third-party site.

[0158] In step 402, a user places the electronic device 20A, possibly next to a reader. The reader is connected to a server and synchronizes the device 20A with the server 30. Quantities are updated according to the latest transaction, as illustrated in Figure 5. This step may not be required if the transfer does not require the transfer of files or quantities from the device to a third-party site.

[0159] In step 403, the user selects the file or quantity and direction of the transaction at the third party site to be transferred to or from the site, and instructions to update the balance on the electronic device are prepared.

[0160] In step 404, the third-party site verifies that it is able to perform the transaction: it can, for example, temporarily debit the user's bank account, then send a possible file to the server, and finally display the transaction and offer the user to confirm it by bringing the user's electronic device 20A near a reader or by clicking an icon if the electronic device 20A is already in communication with the server.

[0161] In step 405, the user brings their electronic device 20A close to the reader 10 or presses an icon. An instruction to update the quantity is then written to the device 20A. The file sent from the possibly third-party site in step 404 is copied to the device 20A and possibly to the system's server. If this step is not performed within a reasonable time, the transaction is canceled, the third-party site is notified of this, and the possible file sent in step 404 is deleted from the server and from the device 20A. In the opposite case, the third-party site is notified that the operation was successful. The file sent from the device 20A to the third-party site is effectively sent from the server to the third-party site and possibly deleted from the server, and then an instruction to delete said file from the device is generated.

[0162] In step 406, the reader indicates that the transaction is complete and prompts the user to remove their device 20A.

[0163] In step 407, the user removes his device 20A.

[0164] 5 shows an example of a synchronous exchange that can take place between an electronic device, for example in the form of a credit card, and a server. This exchange takes place when the electronic device communicates with the reader and the reader communicates with the server. Therefore, it only requires inserting the card 20A into the reader or placing the card 20A next to the reader for the required time. The following steps describe an exchange between the electronic device 20A and the server 30 through the reader 10.

[0165] In step 501, a user brings their electronic device 20A close to a reader.

[0166] In step 502, server 30 sends to device 20A a transaction deletion instruction that it has likely already prepared.

[0167] In step 503, all transaction deletion instructions present on electronic device 20A are executed.

[0168] In step 504, all commands, transactions and files that are present on device 20A but not on the server are copied to the server through server 10.

[0169] In step 505, the server calculates, or has calculated by one of the servers in the system, the new quantity and prepares a list of transactions to be copied to or deleted from device 20A.

[0170] In step 506, all deletion commands, transactions, files and new quantities that exist on the server 30 but do not exist on the electronic device 20A, but that should or will be calculated in step 505, are copied to the electronic device 20A.

[0171] In step 507, all transaction deletion instructions present on electronic device 20A are executed.

[0172] In step 508, the user is prompted to remove their electronic device.

[0173] FIG. 6 shows an exemplary organization of the process of updating keys and of the list of keys present in a reader or electronic device.

[0174] This diagram assumes that an electronic device (DE) and a reader are present, however the following steps also apply to reader-only synchronization.

[0175] In step 601, the electronic device or reader sends its identification information to the server.

[0176] The server a. Key update process; b. Key list update process; Prepare, encrypt, and sign the As a result, only the electronic device or reader can read them. It signs the encrypted files with one of its keys, the private key of which it knows resides on the electronic device or reader. These update files contain information about elements to be removed, replaced, and added. They can be split into several files to allow a gradual update process.

[0177] In step 602, the encrypted and signed file is sent to an electronic device or reader.

[0178] In step 603, the electronic device or reader verifies the signature of the file and decrypts it.

[0179] In step 604, the electronic device or reader installs the keys and the list of keys in its internal memory provided for this purpose and causes this update to be taken into account.

[0180] In step 605, the device or reader notifies the server that it will take the updated file into consideration.

[0181] In step 606, the electronic device or reader deletes from its memory information that is no longer in use.

[0182] FIG. 7 shows an exemplary implementation of a reader or electronic device software update process.

[0183] This diagram assumes that an electronic device (DE) and a reader are present, however the following steps also apply to reader-only synchronization.

[0184] In step 701, the electronic device or reader sends its identification information to the server.

[0185] In step 702, the server encrypts the software to be installed so that only the electronic device or reader can read it. It also signs the file thus encrypted with one of its keys, the public key of which it knows resides on the electronic device or reader.

[0186] In step 703, the encrypted and signed file is sent to an electronic device or reader.

[0187] In step 704, the electronic device or reader verifies the signature of the file and decrypts it.

[0188] In step 705, the electronic device or reader installs the software in its internal memory provided for this purpose, without yet removing the software already installed.

[0189] In step 706, the electronic device or reader verifies that the new software has indeed been copied and modifies the boot instructions of the electronic device (or reader) so that when it boots up again, the device boots up again with the new software.

[0190] In step 707, the electronic device or reader is powered up again.

[0191] Upon startup, in step 708, old software on the electronic device or reader is removed if it is still present there.

[0192] FIG. 8 illustrates an exemplary synchronization of a reader with a server.

[0193] In step 801, the certificates and lists are updated.

[0194] In step 802, transactions performed on and stored on the reader are sent to the server and deleted therefrom.

[0195] In step 803, there may be receipt of a list of electronic devices that are to be marked as unauthorized or suspended.

[0196] FIG. 9 represents various steps that may be performed by a user to create or modify a file on a secure device.

[0197] In step 901, a user brings their secure device next to a reader.

[0198] In step 902, the user selects the file they wish to modify or chooses "Create a new file" from the reader's menu.

[0199] In step 903, if the amount associated with the file is equal to the maximum amount that can be associated with the file and the file is marked as "modifiable", the file is displayed in the reader and a function allowing its editing is invoked. If the user selects "Create new file", a blank file is displayed in the reader and a function allowing its editing is invoked.

[0200] In step 904, the user edits the file.

[0201] In step 905, the user can edit some of the file's characteristics, such as its minimum amount, maximum amount, increment, or other characteristics that affect what can be done with the file in the system, such as "can be transferred" or "require biometric device to view." The amount added to the file is then set to its maximum allowed amount.

[0202] In step 906, the user again approaches the device next to the reader.

[0203] In step 907, the file is copied to the device.

[0204] In step 908, if the situation occurs where the reader is connected to the server, or if the reader is later connected to the server, the file is copied to the server.

[0205] In step 909, the card may also place a copy of the file on a server through a connection to the server with another reader. [Explanation of symbols]

[0206] 10 Dual Reader 20A Electronic Device 20B Electronic Devices 30 Remote Servers 40 Microcomputer 41 Mobile Phone

Claims

1. 1. A method for performing at least one secure exchange in a system, said system comprising first and second electronic devices (20A, 20B) and a dual reader (10) comprising means for connection with each of said devices, and at least one server (30) to which information about said exchange can be communicated, said method comprising: a) inputting into the reader (10) items of information relating to a transaction to be carried out between the first and second devices (20A, 20B) using an interface of the reader (10) or an external device connected to the reader (10); b) registering an item of information about the transaction in the first device (20A) using the reader (10); c) registering an item of information about the transaction in the second device (20B) or otherwise cancelling the transaction; d) transmitting data relating to the transaction to said server (30); Including, the dual reader is configured to connect to the server (30) while a transaction is being carried out between two electronic devices or outside of such a transaction; a list of transactions carried out by said device with other electronic devices, which transactions have not yet been recorded on said remote server but have been recorded on at least one of said electronic devices, said items of information about said transactions allowing said server to link each transaction on said device to a quantity or file on another electronic device, even if these transactions have not been communicated to said server, and including information about previous transactions relating to the same register or the same file on an electronic device; at least one of said electronic devices contains copies of other transactions carried out prior to the debit of the quantity or file, allowing these transactions to link this debit to an initial file or quantity already confirmed by said server, unless these transactions were reported to said server in another way; method.

2. 2. The method of claim 1, wherein the validity of the registration at the first device (20A) is conditional on the registration of the item of information regarding the transaction at the second device (20B), and the validity of the registration at the first device (20A) is communicated to the first device (20A) by the dual reader after the registration at the second device (20B) or subsequently by the server and another dual reader.

3. 3. The method of claim 1 or 2, wherein two elements of the system selected from the electronic device, the server and the dual reader are authorized to communicate with each other if they each have a public key that corresponds to a private key located on the other element, and this private key is unique and located only on the element or shared by other elements of the system, or if the two elements each know the same private key shared between them or between them and other elements of the system.

4. 4. The method of any one of claims 1 to 3, wherein the dual reader (10) includes a clock and the information registered in the first and second devices is time-stamped with the time of the exchange.

5. 5. The method of claim 1, wherein the dual reader performs transfers of quantities registered in registers of a first electronic device from or to registers of other electronic devices, ensuring that at the end of each transfer, each initial value of the register is incremented by the quantity received or subtracted from its value by the quantity sent, in accordance with specific rules present in the dual reader at the time of transfer.

6. A method described in any one of claims 1 to 5, wherein a first secure connection to the first device using the reader and a second secure connection to the second device using the reader overlap in time.

7. 7. The method according to claim 1, wherein step a) is after a step in which the first device and / or the second device communicate information to the reader.

8. 8. The method of claim 7, wherein the information relates to a list of documents stored at the device so that the reader can incorporate the documents into a menu of the interface of the dual reader.

9. A method described in any one of claims 1 to 8, wherein a first secure connection to the first device using the reader is contact-based and a second secure connection to the second device using the reader is contactless.

10. 10. The method of claim 1, wherein the human-machine interface of the dual reader includes a keypad for entering the items of information about the transaction.

11. 11. The method of claim 1, wherein the human-machine interface of the dual reader includes a screen, and the system is configured to display two messages intended for the bearers of the first and second devices, respectively.

12. 12. The method of any one of claims 1 to 11, wherein the electronic device is in the form of a credit card or a SIM card.

13. 13. The method according to any one of claims 1 to 12, wherein the secure exchange with the electronic device is carried out at different locations through two dual readers linked by a computer connection.

14. 14. The method of claim 13, wherein one of the electronic devices has an owner, and an identification of the owner is revealed to the holder of the second electronic device before the second electronic device conducts the transaction.

15. 15. The method of any one of claims 1 to 14, wherein the dual reader acts as a relay to inform the server, which lists transactions originating from electronic devices that are in communication with the server but do not necessarily generate the transactions.

16. 16. The method of claim 1, wherein step d) occurs after the transaction.

17. A system for implementing the method according to any one of claims 1 to 16, comprising: - at least one dual reader (10); - at least two electronic devices (20A, 20B); - At least one server (30) Including, the dual reader is configured to establish a first secure connection to the first device (20A) and a second secure connection to the second device (20B), to allow items of information relating to an exchange to be carried out between the first and second electronic devices (20A, 20B) to be entered into the reader using an interface of the reader or an external device connected to the reader, to register the items of information relating to the exchange in the first device (20A) and to register items of information related to the exchange in the second device (20B), and to communicate the information relating to the exchange to the server (30) if the exchange is not cancelled, the dual reader (10) is configured to connect to the server (30) while a transaction is being carried out between the two electronic devices or outside of such a transaction; at least one of said electronic devices is configured to record a list of said transactions carried out by said device with other electronic devices, said items of information about said transactions allowing said server to link each transaction in said device to a quantity or file of another electronic device, even if the transactions have not yet been recorded in said remote server and said items of information about said transactions have not been communicated to said server, and which include information about previous transactions relating to the same register or the same file of said electronic device, at least one of said electronic devices is configured to contain copies of other transactions carried out prior to the debit of the quantity or file, allowing these transactions to link this debit to an initial file or quantity already confirmed by said server, insofar as these transactions have not been reported to said server in other ways; system.

18. 20. The system of claim 17, wherein the server is accessible by connection to a data network and enables data synchronization of at least one of the electronic devices via a computer or telephone.

19. 19. The system of claim 17 or 18, wherein the dual reader is configured to simultaneously enable contact-based communication with one of the electronic devices and contactless communication with another electronic device.

20. 20. The system of any one of claims 17 to 19, wherein the dual reader or the electronic device includes biometric means for identifying a user.

21. 21. A system according to any one of claims 17 to 20, wherein the server records all transactions linked to an account, and these transactions are reported to the server at the time of the transaction or thereafter.

22. 22. The system of claim 17, wherein the dual reader includes a physically protected memory containing the dual reader's private key.

23. 23. The system of claim 22, wherein physical access of the memory leads to its destruction before the information it contains can be copied therefrom.

Citation Information

Patent Citations

  • Parental card system

    JP1988037468A

  • Transaction processing system and pretransmitted card issuing machine

    JP1991164891A

  • Integral skiing ground managing system

    JP1997016727A

  • Ticket issuing system

    JP2006201997A

  • Service-providing terminal device and security system

    JP2007310575A