Method of authenticating a personal code of a user of an...

Registers – Records – Conductive

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C235S380000, C235S379000

Reexamination Certificate

active

06435416

ABSTRACT:

FIELD OF THE INVENTION
The present invention relates to a method of authenticating the personal code of a user of an integrated circuit card such as a bank card, e.g. during payment operations performed using a computer connected to a network.
BACKGROUND OF THE INVENTION
To perform such operations, it is common practice to use an integrated circuit card reader connected to the serial port of the computer so as to form a simple interface between the computer and the integrated circuit of the card.
Methods presently in use for authenticating a personal code (also known as a personal identification number, or PIN) include the steps of inputting the code via the computer keyboard, converting the inputted personal code into a format that is intelligible for the integrated circuit of the card, then transmitting the formatted personal code together with a command that the code be authenticated to the reader which forwards them, in turn, to the integrated circuit of the card which then authenticates the received personal code using the user's personal code as pre-stored in the integrated circuit. When the user inputs the personal code, a person with fraudulent intentions, referred to herein as an attacker, might be capable of obtaining the personal code by accessing the computer memory in which the inputted personal code is stored prior to being forwarded to the reader, where such access could be direct or over a network. The attacker could also obtain the personal code by causing an instruction to be sent to the integrated circuit of the card instead of the authentication command to store the personal code in a memory of the integrated circuit to which the attacker can subsequently gain access. The risk of fraud is thus significant with existing authentication methods. This risk is associated with using the keyboard of the computer for inputting the personal code to be authenticated.
OBJECTS AND SUMMARY OF THE INVENTION
An object of the invention is to authenticate the personal code of an integrated circuit card user in a manner that maximizes protection of the personal code and that can be implemented using an integrated circuit card reader having electronic means that are relatively simple.
To achieve this and other objects of the invention, the integrated circuit card is received in a reader that is fitted with a keypad, connected to a computer, and capable of accepting at least one type of card. The type of card inserted in the reader is recognized. Formatting instructions are transmitted from the computer to the reader, with such instructions corresponding to the type of the card, and a command is sent for authenticating the personal code. The authentication command is verified in the reader and, for a qualified authentication command, the reader is put into a secure mode. The personal code is inputted via the keypad of the reader and formatted in accordance with the formatting instructions. The formatted code and the command for authenticating it are transmitted from the reader to the integrated circuit of the card.
Thus, the personal code can be inputted to the reader only after the authentication command for transmission to the integrated circuit of the card has been verified as being qualified and the reader has been put into a secure mode. It is then no longer possible to use the computer or a network to which it is connected to intervene in inputting the personal code.
Preferably, prior to inputting a personal code, the method of the present invention includes a step of informing the user that the reader is in a secure mode.
Preferably, subsequent to putting the reader in the secure mode, the method of the present invention includes a step of authorizing inputting of the personal code.
Advantageously, the secure mode prevents the execution of instructions that enable the computer to access the inputted personal code.
Preferably, simultaneously with the step of inputting and formatting the personal code, the method of the present invention includes a step of ensuring that any instruction coming from the computer during this step is compatible with keeping the reader in the secure mode.
Preferably, subsequent to transmitting the formatted personal code to the integrated circuit, the method of the present invention includes a step performed in the integrated circuit of the card, in which the received personal code is compared with the personal code of the user as pre-stored in the integrated circuit.
Preferably, the method of the present invention includes the step of transmitting the result of the comparison from the integrated circuit to the computer via the reader.


REFERENCES:
patent: 4630201 (1986-12-01), White
patent: 5521362 (1996-05-01), Powers
patent: 5721781 (1998-02-01), Deo et al.
patent: 5796832 (1998-08-01), Kawan
patent: 195 27 715 (1997-02-01), None
patent: 0 587 375 (1994-03-01), None
patent: 0 596 276 (1994-05-01), None
patent: 0 763 791 (1997-03-01), None
patent: 960 815 (1997-11-01), None

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Method of authenticating a personal code of a user of an... does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Method of authenticating a personal code of a user of an..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Method of authenticating a personal code of a user of an... will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-2965069

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.