+

WO2009074994A1 - Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie - Google Patents

Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie Download PDF

Info

Publication number
WO2009074994A1
WO2009074994A1 PCT/IN2007/000588 IN2007000588W WO2009074994A1 WO 2009074994 A1 WO2009074994 A1 WO 2009074994A1 IN 2007000588 W IN2007000588 W IN 2007000588W WO 2009074994 A1 WO2009074994 A1 WO 2009074994A1
Authority
WO
WIPO (PCT)
Prior art keywords
biometric
self
software
data
atm
Prior art date
Application number
PCT/IN2007/000588
Other languages
English (en)
Inventor
Vasantlal Khinvasara Abhay
Original Assignee
Vasantlal Khinvasara Abhay
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vasantlal Khinvasara Abhay filed Critical Vasantlal Khinvasara Abhay
Priority to PCT/IN2007/000588 priority Critical patent/WO2009074994A1/fr
Publication of WO2009074994A1 publication Critical patent/WO2009074994A1/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • G07F19/206Software aspects at ATMs
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • G07F19/211Software architecture within ATMs or in relation to the ATM network

Definitions

  • the present invention relates to biometrics based device for converting regular ndc, ddc or proprietary communication protocol based automated teller machines, kiosks, self service terminals or full service terminals with pin (personal identification number) authentication to biometric based authentication.
  • TDES is short for Triple Data Encryption Standard and is an encrypting technique that uses the DES or Data Encryption Standard for encryption and is developed for the purpose of secure data transmission.
  • TDES is replacing DES, which is also an encrypting algorithm and has been in use for some time now as the security level of DES have diminished due to advancement in computing power essentially used for exhaustive attacks for finding the clear text.
  • the association between the PIN and the actual user is based on what the user knows. Many users write the PIN on the card or token so that they do not forget it. Hence essentially the loss of the card results in the loss of the PIN.
  • PINs are also prone to wireless camera attacks where the camera is mounted near the PIN pad of the ATM or self-service terminal and transmits the images of the user using the PIN pad, in effect compromising the PIN.
  • a Biometric used for authentication is secure and convenient and the responsibility of remembering something is taken away from the user.
  • Biometrics technology has stabilized and several governments of developed countries are using some form of a biometric for positive identification of people. It is now a well-accepted means of authentication. There are a huge and growing number of already deployed ATMs or self-service terminals in the world. A simple and easy to deploy solution is required that can connect a biometric authentication device to an existing ATM or self-service terminal and make it biometric enabled.
  • a SAMPLE ATM or SELF-SERVICE TERMINAL LAYOUT As shown in figure 1.
  • the proposed device as shown in figure 2; has several input output ports, for example: Ethernet, USB etc.
  • the proposed device is connected to the ATM or the self-service terminal via a data input port and the Electronics Funds Transfer (EFT) switch or other host if required to further process the data via the data output port.
  • EFT Electronics Funds Transfer
  • the proposed device's IP -if using the Ethernet port- may be configured to that of the ATM or self-service terminal host to which the proposed device is connected and in the EFT switch or host, the ATM or self-service terminal IP may be configured to be the proposed device's IP.
  • the proposed device is configured for biometric verification Operation Code Buffer.
  • the State Load must be changed to ask customer for PIN or Biometric verification.
  • Biometric verification the ATM or self-service terminal is configured to not ask for PIN entry and directly go to transaction selection.
  • ATM or self-service terminal gathers all transaction information and sends it to the proposed device.
  • the proposed device checks the Operation Code Buffer for the configured Operation Code Buffer. If the configured Operation Code Buffer and Operation Code Buffer in the transaction message match, the proposed device prompts the user for Biometric entry on the attached biometric sensor.
  • the proposed device On successful grabbing of Biometric information, the proposed device generates the required Biometric Templates and appends one field separator at the end of original transaction message followed by the Biometric Template so acquired. The Proposed device then sends this newly created transaction message to the EFT switch or host. All other messages coming from the ATM or self-service terminal to the proposed device are sent directly to the EFT switch or host without any modifications.
  • the proposed device can be configured for number of attempts for a good and matching Biometric information.
  • the EFT switch or host or any other ATM or self-service terminal routing/ controlling system handles the messages it receives from the proposed device and the role of the Biometric Security Module (BSM):
  • BSM Biometric Security Module
  • the EFT switch or host or any other system receives the message /data from the proposed device and separates the biometric information along with the card data from the transaction part of the message. It sends this authentication and card information to the BSM.
  • the BSM uses this information to compare the biometric information it has just received to the biometric information it has stored in its database associated with that card data. The result is conveyed to the EFT switch or any other controlling software. The rest of the transaction processings may not be changed.
  • Non-volatile Memory 8MB or appropriate
  • Biometric Sensor Type Optical, Capacitive, Thermal, Ultrasound
  • TDES PIN pad is required.
  • Operating System Linux, Windows, Unix, OS2
  • BIOMETRIC SECURITY MODULE ⁇ BSM1 BIOMETRIC SECURITY MODULE ⁇ BSM1:
  • the BSM is used for giving online service to the EFT switch or any other ATM or self-service terminal controlling system, the BRM or even the proposed device.
  • the BSM is always in the listening mode for the request messages from the EFT switch or any other ATM controlling system, the BRM or the proposed device.
  • Several different data channels can be used for the purpose of communication.
  • Non-volatile Memory 8MB or appropriate
  • Biometric Sensor Type Optical, Capacitive, Thermal, Ultrasound
  • TDES PIN pad is required.
  • Operating System Linux, Windows, Unix, OS2
  • BIOMETRIC REGISTRATION MODULE a.
  • BRM helps register a Customer using his/her biometric against his/her account number and card or token number.
  • This biometric data can be stored in a separate database like the BSM, on the proposed device itself, on the ATM or self-service terminal or even on a card or token.
  • the proposed device can also be used for the purpose of registration of users.
  • the registration process can include other relevant information of the user.
  • a volatile or non-volatile memory capable of temporarily saving up to a certain number of customer registrations (based on the security levels required by the service provider) can be provided in the BRM. At the end of those specific registrations, data is transmitted to the BSM and the temporary storage may be deleted.
  • the BRM can also run in live mode continuously uploading data if the connectivity bandwidth is broad enough.
  • Non-volatile Memory 8MB or appropriate
  • Biometric Sensor Type Optical, Capacitive, Thermal, Ultrasound etc.
  • the Biometric Matching engine matches the received Biometric Template either with a corresponding stored Template, with the entire stored Template database or a portion of the stored Template database
  • the ATM or self-service terminal collects all transaction information from customer and sends the information to the proposed device
  • the proposed device accepts the information from the ATM or self- service terminal and verifies that the information is for Biometric authentication by ascertaining that the PIN portion of the information received from the ATM or self-service terminal is empty.
  • the Proposed device acquires the image from the Biometric Data Scanner
  • the proposed device directly sends the information it receives from the ATM or self- service terminal to the EFT switch or host or any controlling software. • On receipt of response from Switch the Proposed device transfers the reply to the ATM or self-service terminal
  • PROPOSED DEVICE COMPRISING ATM or SELF-SERVICE TERMINAL LAYOUTS As Shown in Figure 3 and Figure 4 Sample Changes To The Transaction Request Message for the NDC protocol:
  • the regular NDC message will have a field- separator at the end following which will be the Biometric Template.
  • the PIN buffer has just space characters. If the user is using PIN for authentication, then the PIN buffer does not have any spaces.
  • the switch will extract the Template and send it to the BSM along with the information as specified in the message format as below.
  • the BSM will perform the authentication and provide the result in the format as specified below.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Finance (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

La présente invention concerne la biométrie qui est utilisée pour identifier une personne ou vérifier l'identité d'une personne en fonction de ce qu'elle est plutôt qu'en fonction de ce qu'elle connaît ou possède. Les terminaux en libre-service utilisent le cryptage des données pour vérifier l'identité d'une personne sur la base des connaissances d'une personne, c'est-à-dire du numéro d'identification personnel ou PIN, et en fonction du fait que la personne possède, par exemple une carte ou un jeton. Les PIN peuvent être violés. Ils sont difficiles à retenir et sont donc oubliés facilement. Le présent brevet concerne un dispositif comportant les éléments suivants : une entrée de données, une sortie, un processeur, des logiciels, des micrologiciels, du matériel informatique équipé d'un dispositif d'acquisition d'informations relatives aux empreintes digitales ou à la biométrie, le dispositif d'acquisition transformant un distributeur automatique de billets ou un terminal en libre-service ordinaires en un distributeur automatique de billets ou un terminal en libre-service fonctionnant suivant le principe de la biométrie. La fonction de base d'authentification par PIN du distributeur automatique de billets ou du terminal en libre-service existant demeure intacte. Le distributeur automatique de billets ou le terminal en libre-service peut donc être utilisé tel quel. Il se peut qu'il faille procéder à quelques modifications de la configuration du logiciel du distributeur automatique de billets. Le dispositif proposé offre à l'utilisateur la possibilité de choisir entre utiliser l'authentification par PIN et/ou par biométrie. Le présent brevet décrit en outre la manière dont est effectuée la communication entre le dispositif proposé et le commutateur de transfert électronique de fonds (EFTS) ou l'hôte et les modifications qu'il peut être nécessaire d'apporter au logiciel hôte ou du EFTS. En plus du dispositif proposé, l'invention concerne également un dispositif d'équipement électronique muni du logiciel requis à des fins d'enregistrement biométrique des utilisateurs du distributeur automatique de billets ou du terminal en libre-service. En outre, l'invention concerne un équipement et un logiciel pour le module de sécurité biométrique qui correspondent aux informations biométriques côté EFTS ou hôte. En variante, la mise en correspondance peut également être réalisée sur le dispositif proposé ou sur le distributeur automatique de billets ou le terminal en libre-service.
PCT/IN2007/000588 2007-12-12 2007-12-12 Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie WO2009074994A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/IN2007/000588 WO2009074994A1 (fr) 2007-12-12 2007-12-12 Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/IN2007/000588 WO2009074994A1 (fr) 2007-12-12 2007-12-12 Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie

Publications (1)

Publication Number Publication Date
WO2009074994A1 true WO2009074994A1 (fr) 2009-06-18

Family

ID=39709384

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/IN2007/000588 WO2009074994A1 (fr) 2007-12-12 2007-12-12 Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d'identification personnel), fonctionnant sur la base d'une coordonnée d'appareil normée (ndc), d'une commande numérique directe (ddc) ou d'un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie

Country Status (1)

Country Link
WO (1) WO2009074994A1 (fr)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
RU2597456C1 (ru) * 2015-08-21 2016-09-10 Кирилл Эдуардович Пищик Торговый автомат для дистанционной продажи и способ дистанционной продажи контролируемых товаров

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP0651357A1 (fr) * 1993-10-29 1995-05-03 International Business Machines Corporation Système pour le procédé de transactions commercialles
WO1998015924A2 (fr) * 1996-09-27 1998-04-16 Smarttouch Systeme biometrique sans jeton d'acces a un guichet automatique
US6308887B1 (en) * 1997-12-02 2001-10-30 Cash Technologies, Inc. Multi-transactional architecture
US20030093697A1 (en) * 2001-11-13 2003-05-15 Lin Wen Chi Method for preventing unauthorized persons from entering and using a computer facility
US20030095641A1 (en) * 2001-11-16 2003-05-22 Vishik Claire Svetlana Method and system for multimodal presence detection
US20040025029A1 (en) * 2002-08-01 2004-02-05 Yu Ki S. Biometric system for replacing password or pin terminals
US20060016884A1 (en) * 1998-04-17 2006-01-26 Diebold Self-Service Systems Division Of Diebold, Incorporated Cash dispensing automated banking machine with flexible display
WO2006022019A1 (fr) * 2004-08-27 2006-03-02 Koji Kouda Système de paiement/réception d'argent
EP1646013A2 (fr) * 2004-10-08 2006-04-12 Fujitsu Limited Procédé, dispositif et programme d'authentification individuelle

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP0651357A1 (fr) * 1993-10-29 1995-05-03 International Business Machines Corporation Système pour le procédé de transactions commercialles
WO1998015924A2 (fr) * 1996-09-27 1998-04-16 Smarttouch Systeme biometrique sans jeton d'acces a un guichet automatique
US6308887B1 (en) * 1997-12-02 2001-10-30 Cash Technologies, Inc. Multi-transactional architecture
US20060016884A1 (en) * 1998-04-17 2006-01-26 Diebold Self-Service Systems Division Of Diebold, Incorporated Cash dispensing automated banking machine with flexible display
US20030093697A1 (en) * 2001-11-13 2003-05-15 Lin Wen Chi Method for preventing unauthorized persons from entering and using a computer facility
US20030095641A1 (en) * 2001-11-16 2003-05-22 Vishik Claire Svetlana Method and system for multimodal presence detection
US20040025029A1 (en) * 2002-08-01 2004-02-05 Yu Ki S. Biometric system for replacing password or pin terminals
WO2006022019A1 (fr) * 2004-08-27 2006-03-02 Koji Kouda Système de paiement/réception d'argent
EP1646013A2 (fr) * 2004-10-08 2006-04-12 Fujitsu Limited Procédé, dispositif et programme d'authentification individuelle

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
CHIRASROTA JENA: "Biometric ATMs for rural India", INTERNET ARTICLE, 12 March 2007 (2007-03-12), www.expresscomputeronline.com, XP002493821, Retrieved from the Internet <URL:http://www.expresscomputeronline.com/20070312/technology01.shtml> [retrieved on 20080828] *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
RU2597456C1 (ru) * 2015-08-21 2016-09-10 Кирилл Эдуардович Пищик Торговый автомат для дистанционной продажи и способ дистанционной продажи контролируемых товаров

Similar Documents

Publication Publication Date Title
EP1260050B1 (fr) Interface biometrique
US20020089410A1 (en) Biometric authentication device for use with a personal digital assistant
EP2051178A1 (fr) Procédé, dispositif, serveur et système d&#39;authentification d&#39;identité avec un caractère biologique
US20080178263A1 (en) Network output system and registration method of authentication information
US20090037339A1 (en) Methods of authenticating a bank customer desiring to conduct an electronic check deposit transaction
US20100042835A1 (en) System and method for permission confirmation by transmitting a secure request through a central server to a mobile biometric device
RU2008146049A (ru) Устройство и способ для индентификации и аутентификации
EP2819107A1 (fr) Jeton de sécurité et système d&#39;autorisation de transaction
CN105933570B (zh) 图像数据处理服务器、系统以及方法
CN103238162A (zh) 安全的身份识别和记录系统和方法
EP2040228A1 (fr) Système, procédé et dispositif pour autoriser une interaction sécurisée et conviviale
US20100133342A1 (en) Secure use of externally stored data
US8161282B2 (en) System and method for requesting and issuing an authorization document
US20190349197A1 (en) Distributed token-less authentication
US20050229005A1 (en) Security badge arrangement
JP2000353216A (ja) Icカードシステム、icカード端末、icカード処理方法及び記録媒体
CN105580046B (zh) 提供与远程银行装置的银行业务交互的系统和方法
WO2009074994A1 (fr) Dispositif fonctionnant suivant le principe de la biométrie et destiné à convertir des distributeurs automatiques de billets, des kiosques, des terminaux en libre-service ou des terminaux en service complet ordinaires avec authentification par pin (numéro d&#39;identification personnel), fonctionnant sur la base d&#39;une coordonnée d&#39;appareil normée (ndc), d&#39;une commande numérique directe (ddc) ou d&#39;un protocole de communication propriétaire, en une authentification fonctionnant suivant le principe de la biométrie
KR20090001514A (ko) 순번대기표 출력장치를 이용한 신분증 처리 업무 자동화시스템 및 방법
KR20040076757A (ko) 신분증 인식 시스템 및 그 방법
CN107659750A (zh) 输出装置、系统和输出方法
GB2556625A (en) Secure enrolment of biometric data
KR20090000819A (ko) 금융거래 현장 정보 제공방법 및 시스템과 이를 위한프로그램 기록매체
US20230237136A1 (en) Processing system, information processing apparatus, non-transitory computer-readable storage medium storing control program, and image processing apparatus
US20250063024A1 (en) Portable autonomous device for securing data transfer and corresponding method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 07870547

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 07870547

Country of ref document: EP

Kind code of ref document: A1

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载