WO2001035354A3 - Universal smart card access system - Google Patents

Universal smart card access system Download PDF

Info

Publication number
WO2001035354A3
WO2001035354A3 PCT/US2000/029293 US0029293W WO0135354A3 WO 2001035354 A3 WO2001035354 A3 WO 2001035354A3 US 0029293 W US0029293 W US 0029293W WO 0135354 A3 WO0135354 A3 WO 0135354A3
Authority
WO
WIPO (PCT)
Prior art keywords
smart card
provides
universal
debit
stored value
Prior art date
Application number
PCT/US2000/029293
Other languages
French (fr)
Other versions
WO2001035354A2 (en
Inventor
Rinaldo Digiorgio
Stephen Uhler
Moshe Levy
Original Assignee
Sun Microsystems Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sun Microsystems Inc filed Critical Sun Microsystems Inc
Priority to AU25730/01A priority Critical patent/AU2573001A/en
Publication of WO2001035354A2 publication Critical patent/WO2001035354A2/en
Publication of WO2001035354A3 publication Critical patent/WO2001035354A3/en

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/0866Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means by active credit-cards adapted therefor
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/36Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
    • G06Q20/363Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes with the personal data of a user
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3827Use of message hashing
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/409Device specific authentication in transaction processing
    • G06Q20/4097Device specific authentication in transaction processing using mutual authentication between devices and transaction partners
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1008Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system

Abstract

The present invention is a universal secure token scheme that provides two way authentication, credit, debit, and stored value operations. The invention permits the use of universally available networks to access corporate, private, and proprietary devices. The invention provides strong authentication, offers optional encryption of the established session, and operates without requiring special permission to reconfigure firewalls. One application of the invention provides a universal token scheme that can be used in debit and stored value transactions. In one embodiment, devices and services are treated as URLs and a smart card is configured to perform the necessary HTTP protocol to access the URL.
PCT/US2000/029293 1999-10-29 2000-10-23 Universal smart card access system WO2001035354A2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
AU25730/01A AU2573001A (en) 1999-10-29 2000-10-23 Universal smart card access system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US09/430,524 1999-10-29
US09/430,524 US6748532B1 (en) 1999-10-29 1999-10-29 Universal smart card access system

Publications (2)

Publication Number Publication Date
WO2001035354A2 WO2001035354A2 (en) 2001-05-17
WO2001035354A3 true WO2001035354A3 (en) 2002-01-17

Family

ID=23707904

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2000/029293 WO2001035354A2 (en) 1999-10-29 2000-10-23 Universal smart card access system

Country Status (3)

Country Link
US (1) US6748532B1 (en)
AU (1) AU2573001A (en)
WO (1) WO2001035354A2 (en)

Families Citing this family (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7111051B2 (en) * 2000-01-26 2006-09-19 Viaclix, Inc. Smart card for accessing a target internet site
US20020124058A1 (en) * 2000-10-11 2002-09-05 Jakob Ehrensvard Navigation device
US20020147907A1 (en) * 2001-04-06 2002-10-10 Bruce Ross System for authorizing transactions using specially formatted smart cards
US20020194499A1 (en) * 2001-06-15 2002-12-19 Audebert Yves Louis Gabriel Method, system and apparatus for a portable transaction device
US20040218762A1 (en) 2003-04-29 2004-11-04 Eric Le Saint Universal secure messaging for cryptographic modules
US8209753B2 (en) * 2001-06-15 2012-06-26 Activcard, Inc. Universal secure messaging for remote security tokens
JP4557969B2 (en) * 2003-03-31 2010-10-06 エヌエックスピー ビー ヴィ How to grant smart card change rights
US20040221174A1 (en) * 2003-04-29 2004-11-04 Eric Le Saint Uniform modular framework for a host computer system
JP2007525731A (en) * 2003-04-29 2007-09-06 アザイア・ネットワークス・インコーポレーテッド Method and system for providing SIM-based roaming to an existing WLAN public access infrastructure
US7204412B2 (en) * 2003-10-14 2007-04-17 Compucredit Intellectual Property Holdings Corp. Iii Family stored value card program
US7907935B2 (en) 2003-12-22 2011-03-15 Activcard Ireland, Limited Intelligent remote device
US20050138380A1 (en) * 2003-12-22 2005-06-23 Fedronic Dominique L.J. Entry control system
US20050204405A1 (en) * 2004-03-04 2005-09-15 Brian Wormington Method and system for digital rights management
US7529370B1 (en) * 2004-04-29 2009-05-05 Hewlett-Packard Development Company, L.P. Digital media-playing device and a method of playing digital media therein
US7751339B2 (en) 2006-05-19 2010-07-06 Cisco Technology, Inc. Method and apparatus for simply configuring a subscriber appliance for performing a service controlled by a separate service provider
WO2008013945A2 (en) 2006-07-27 2008-01-31 Leverage, Inc. System and method for targeted marketing and consumer resource management
US20080133419A1 (en) * 2006-12-05 2008-06-05 Brian Wormington Secure financial transaction system and method
US10783514B2 (en) * 2007-10-10 2020-09-22 Mastercard International Incorporated Method and apparatus for use in personalizing identification token
US20090204525A1 (en) * 2008-02-13 2009-08-13 Simon Phillips Payment device to issuer communication via authorization request
US8914851B2 (en) 2010-12-06 2014-12-16 Golba Llc Method and system for improved security
US8850206B2 (en) * 2011-11-15 2014-09-30 Apple Inc. Client-server system with security for untrusted server
US9594605B2 (en) 2011-11-15 2017-03-14 Apple Inc. Client-server version control system for software applications
US8924713B2 (en) 2012-03-30 2014-12-30 Golba Llc Method and system for state machine security device

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE19710249A1 (en) * 1997-03-12 1998-09-17 Siemens Nixdorf Inf Syst Network-supported chip card transaction process
US5905908A (en) * 1995-06-22 1999-05-18 Datascape, Inc. Open network system for I/O operations with non-standard I/O devices utilizing extended protocol including device identifier and identifier for operation to be performed with device
US5909492A (en) * 1994-10-24 1999-06-01 Open Market, Incorporated Network sales system
WO2000025221A2 (en) * 1998-10-23 2000-05-04 Sun Microsystems, Inc. Method and apparatus for accessing devices on a network
WO2000079411A2 (en) * 1999-06-21 2000-12-28 Sun Microsystems, Inc. Method and apparatus for commercial transactions via the internet

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5844218A (en) * 1996-07-16 1998-12-01 Transaction Technology, Inc. Method and system for using an application programmable smart card for financial transactions in multiple countries
US6564995B1 (en) * 1997-09-19 2003-05-20 Schlumberger Malco, Inc. Smart card application-selection
CA2265032A1 (en) * 1998-04-24 1999-10-24 J.J. Mackay Canada Limited Multiple electronic purse parking meter

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5909492A (en) * 1994-10-24 1999-06-01 Open Market, Incorporated Network sales system
US5905908A (en) * 1995-06-22 1999-05-18 Datascape, Inc. Open network system for I/O operations with non-standard I/O devices utilizing extended protocol including device identifier and identifier for operation to be performed with device
DE19710249A1 (en) * 1997-03-12 1998-09-17 Siemens Nixdorf Inf Syst Network-supported chip card transaction process
WO2000025221A2 (en) * 1998-10-23 2000-05-04 Sun Microsystems, Inc. Method and apparatus for accessing devices on a network
WO2000079411A2 (en) * 1999-06-21 2000-12-28 Sun Microsystems, Inc. Method and apparatus for commercial transactions via the internet

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
VERSCHUREN T: "Smart access: strong authentication on the Web", COMPUTER NETWORKS AND ISDN SYSTEMS,NORTH HOLLAND PUBLISHING. AMSTERDAM,NL, vol. 30, no. 16-18, 30 September 1998 (1998-09-30), pages 1511 - 1519, XP004138682, ISSN: 0169-7552 *

Also Published As

Publication number Publication date
WO2001035354A2 (en) 2001-05-17
US6748532B1 (en) 2004-06-08
AU2573001A (en) 2001-06-06

Similar Documents

Publication Publication Date Title
WO2001035354A3 (en) Universal smart card access system
EP1602194B1 (en) Methods and software program product for mutual authentication in a communications network
CA2241052A1 (en) Application level security system and method
WO1999062210A3 (en) Secure token device access to services provided by an internet service provider (isp)
ES2305203T3 (en) PORTABLE DEVICE FOR SECURING PACKAGE TRAFFIC IN A GUEST PLATFORM.
NZ504186A (en) Communication system for selectively permitting access by a mobile terminal to a packet data network with password generator coupled to mobile terminal and authenticator coupled to packet data network
WO2004046849A3 (en) Cryptographic methods and apparatus for secure authentication
WO2002033879A3 (en) Security system
WO2002044858A3 (en) System and method for securing a non-secure communication channel
WO1999027678A3 (en) Security of data connections
AU2001251411A1 (en) Biometric authentication card, system and method
AU6491800A (en) Internet payment, authentication and loading system using virtual smart card
AU2001243319A1 (en) System, and method for prepaid anonymous and pseudonymous credit card type transactions
AU4575900A (en) Method for pre-controlling a programme contained in a terminal additional chip card
IL159295A0 (en) Authentication of a user across communication sessions
HK1042182A1 (en) Safe terminal provided with a smart card reader designed to communicate with a server via an internet-type network
WO2001011845A3 (en) Security architecture with environment sensitive credentials
WO2007072318A3 (en) Secure identity management
CA2391246A1 (en) Terminal communication system
IL144902A0 (en) Mutual authentication in a data network using automatic incremental credential disclosure
WO2002082769A3 (en) Facilitating legal interception of ip connections
WO2002033887A3 (en) Multiple authentication sessions for content protection
WO2003003689A3 (en) Dynamic configuration of ipsec tunnels
WO2002093337A3 (en) Method and apparatus for multiple token access to thin client architecture session
NO20012463L (en) Procedure and apparatus for securely distributing authentication credentials to roaming users

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DE DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG UZ VN YU ZA ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
AK Designated states

Kind code of ref document: A3

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DE DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG UZ VN YU ZA ZW

AL Designated countries for regional patents

Kind code of ref document: A3

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG

REG Reference to national code

Ref country code: DE

Ref legal event code: 8642

122 Ep: pct application non-entry in european phase
NENP Non-entry into the national phase

Ref country code: JP