IP Library Granted Patent US 8,205,249
Granted Patent B2
US 8,205,249 · App. 10/531,259 · Granted Jun 19, 2012

Method for carrying out a secure electronic transaction using a portable data support

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,205,249
App. No.
10/531,259
Granted
Jun 19, 2012
Kind
B2
Abstract

A method for effecting a secure electronic transaction on a terminal using a portable data carrier is proposed. According to the method a user ( 30 ) first authenticates himself vis-à-vis the portable data carrier ( 20 ). The portable data carrier ( 20 ) at the same time produces quality information about how authentication was done. The authentication is confirmed to the terminal ( 14 ). Then the portable data carrier ( 20 ) performs a security-establishing operation within the transaction, for example the creation of a digital signature. It attaches the quality information to the result of the security-establishing operation.

Claims (13)

1. A method for effecting a secure electronic transaction on a terminal using a portable data carrier arranged to perform different quality user authentication methods, wherein the portable data carrier performs a user authentication using one of said different user authentication methods, the portable data carrier confirms the proof of authentication to the terminal, and the portable data carrier then performs a security-establishing operation within the electronic transaction, comprising the steps of creating authentication quality information by the portable data carrier about said user authentication method used and attaching said authentication quality information to the result of the security-establishing operation, wherein the difference in quality of said user authentication methods varies between an inherently relatively lower quality and an inherently relatively higher quality from a security perspective.

2. The method according to claim 1 , wherein the security-establishing operation performed by the portable data carrier comprises creating a digital signature.

3. The method according to claim 1 , wherein the authentication of the user is performed by presentation of a biometric feature.

4. The method according to claim 3 , wherein the authentication of the user is performed by presentation of a physiological or behavior-based feature characteristic of a user.

5. The method according to claim 1 , wherein the authentication of the user is performed by proof of knowledge of a secret.

6. The method according to claim 1 , wherein at least two different authentication methods of different quality are offered for authentication of the user.

7. The method according to claim 6 , wherein the particular authentication methods not used are disabled.

8. The method according to claim 6 , wherein no quality information is produced for an authentication method.

9. The method according to claim 1 , wherein a user is asked to select an authentication method.

10. A portable data carrier for performing a security-establishing operation within a secure electronic transaction and arranged to perform different quality user authentication methods, wherein the difference in quality of said user authentication methods varies between an inherently relatively lower quality and an inherently relatively higher quality from a security perspective, comprising: the portable data carrier is arranged to perform a user authentication using one of said implemented user authentication methods and the portable data carrier is arranged to confirm the authentication to a terminal, and wherein the data carrier is arranged to create quality information about said user authentication method used and to attach such quality information to the result of the security establishing operation.

11. The data carrier according to claim 10 , wherein the portable data carrier is set up to create a digital signature.

12. The data carrier according to claim 10 , wherein the data carrier supports at least two qualitatively different authentication methods.

13. A terminal for use in connection with a portable data carrier, said terminal including a device arranged to cause a user to select one of at least two possible different quality authentication methods, wherein the portable data carrier is arranged to perform a user authentication using one of the at least two possible different quality authentication methods and to confirm the authentication to the terminal, and the data carrier is arranged to create quality information about the authentication method used and to attach such quality information to the result of a security establishing operation, the difference in quality of said authentication methods varies between an inherently relatively lower quality and an inherently relatively higher quality from a security perspective.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2024
From: AIRE TECHNOLOGY LIMITED
To: NERA INNOVATIONS LIMITED
Reel/Frame 066709/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2021
From: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
To: AIRE TECHNOLOGY LIMITED
Reel/Frame 057471/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2021
From: JAGER, BARBARA; BRANZKA, THOMAS
To: AIRE TECHNOLOGY LIMITED
Reel/Frame 057317/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2017
From: GIESECKE & DEVRIENT GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 044559/0969 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2006
From: MEISTER, GISELA; MARTIN, NIGOL
To: GIESECKE & DEVRIENT GMBH
Reel/Frame 017528/0682 →