Language selection

Search

Patent 2390835 Summary

Third-party information liability

Some of the information on this Web page has been provided by external sources. The Government of Canada is not responsible for the accuracy, reliability or currency of the information supplied by external sources. Users wishing to rely upon this information should consult directly with the source of the information. Content provided by external sources is not subject to official languages, privacy and accessibility requirements.

Claims and Abstract availability

Any discrepancies in the text and image of the Claims and Abstract are due to differing posting times. Text of the Claims and Abstract are posted:

  • At the time the application is open to public inspection;
  • At the time of issue of the patent (grant).
(12) Patent Application: (11) CA 2390835
(54) English Title: SYSTEM FOR ELECTRONIC DELIVERY OF A PERSONAL IDENTIFICATION CODE
(54) French Title: SYSTEME DE DELIVRANCE ELECTRONIQUE DE CODE D'IDENTIFICATION PERSONNEL
Status: Dead
Bibliographic Data
(51) International Patent Classification (IPC):
  • H04W 4/14 (2009.01)
  • H04W 92/08 (2009.01)
(72) Inventors :
  • WARD, CHRISTIAN PAUL (France)
(73) Owners :
  • ORANGE A/S (Denmark)
(71) Applicants :
  • ORANGE A/S (Denmark)
(74) Agent: MCCARTHY TETRAULT LLP
(74) Associate agent:
(45) Issued:
(86) PCT Filing Date: 2000-11-09
(87) Open to Public Inspection: 2001-05-17
Examination requested: 2005-10-18
Availability of licence: N/A
(25) Language of filing: English

Patent Cooperation Treaty (PCT): Yes
(86) PCT Filing Number: PCT/DK2000/000620
(87) International Publication Number: WO2001/035685
(85) National Entry: 2002-05-09

(30) Application Priority Data:
Application No. Country/Territory Date
PA 1999 01608 Denmark 1999-11-09

Abstracts

English Abstract




A system is provided for electronic delivery of a PIN code in a secure, fast
and efficient manner and compromising a server (3) provided with a reference
code (2) for generating the PIN code. The server (3) is adapted to transmit a
SMS message (9) containing an electronic signature (5) based on the reference
code (2) to a SIM card (10) connected to a terminal (12). The SIM card (10)
comprises means (11) for receiving and storing the SMS message (9), and means
(17) for comparing the stored electronic signature (5) in the SMS message (9)
with an electronic signature (20) generated from a reference code (15) entered
by a user of the terminal (12). Encryption keys, generated by a triple DES
data encryption algorithm having two keys, and encryption means are provided
in the server (3) and in the SIM card (10).


French Abstract

La présente invention concerne un système de délivrance électronique de code PIN d'une manière sûre, rapide et efficace. Ce système comprend un serveur (3) pourvu d'un code de référence (2) destiné à générer le code PIN. Ce serveur (3) est adapté de façon à transmettre à une carte SIM (10) connectée à un terminal (12) un message (9) de service de message court (SMS) contenant une signature (5) électronique fondée sur le code de référence (2). Cette carte SIM (10) comprend un organe destiné à recevoir et à mémoriser ce message (9) SMS, et un organe (17) destiné à comparer la signature (5) électronique mémorisée du message (9) SMS avec une signature (20) électronique générée par un code de référence (15) entré par un utilisateur du terminal (12). Des clés de cryptage générées par un algorithme de données DES triple à deux clés et un organe de cryptage sont présents dans le serveur (3) et dans la carte SIM (10).

Claims

Note: Claims are shown in the official language in which they were submitted.


8

Claims

1. A system for electronic delivery of electronic information and comprising a
server
(3) secured by means of a number of encryption keys, said system comprising
encryption means (4) for encrypting the electronic information and via
connected
communications means (6, 8) being adapted to transmit a SMS message (9)
containing
the encrypted electronic information to a SIM card (10) connected to a
terminal (12)
with input means (13) and display means (14), said SIM card comprising means
(11)
for receiving and storing the encrypted SMS message (9), characterised in that
said server (3) is adapted for receiving unique information in the form of a
reference
code (2), said encryption means (4) is adapted for computing a first
electronic signature
(5) based on the reference code (2), and the server being adapted for
transmitting the
first electronic signature (5) as encrypted electronic information in said SMS
message
(9), and
said SIM card (10) comprises means (17) for comparing the first electronic
signature
(5) in the SMS message (9) with a second electronic signature (20) being
generated
from a reference code (15) entered by a user of the terminal (12) and by means
of a
corresponding encryption key (16) in the SIM card (10), and means (18) for
allowing
subsequent display of a PIN code associated with the signatures (5, 20) on the
display
means (14) of the terminal (12), if the first electronic signature (5) and the
second
electronic signature (20) match.
2. A system according to claim 1, wherein said SIM card (10) is adapted for
being
provided with the PIN code when supplying the SIM card (10) with a unique
identity
code.
3. A system according to claim 1, wherein said SIM card (10) is adapted to
receive the
PIN code in the form of an encrypted data signal.


9

4. A mobile phone comprising a terminal (12) with input means (13) and display
means
(14), and a SIM card (10) including means (11) adapted for receiving and
storing an
encrypted SMS message (9), characterised in that the SIM card (10) comprises
comparator means (17) adapted for comparing a first electronic signature (5)
in the
encrypted SMS message (9) with a second electronic signature (20) being
generated
from a reference code (15) entered by a user of the terminal (12) and by means
of a
corresponding encryption key (16) in the S1M card (10), and
means (18) for allowing subsequent display of a PIN code associated with the
signatures (5, 20) on the display means (14) of the terminal (12), if the
first electronic
signature (5) and the second electronic signature (2) match.

5. A mobile phone according to claim 4, wherein said SIM card (10) is adapted
for
being provided with the PIN code when supplying the SIM card (10) with a
unique
identity code.
6. A mobile phone according to claim 4, wherein said SIM card (10) is adapted
to
receive the PIN code in the form of an encrypted data signal.
7. A SIM card including storage means (11) adapted for receiving and storing
an
encrypted SMS message (9), characterised in that said SIM card (10)
comprises
encryption means (16) adapted for generating a second electronic signature (2)
from
a reference code (15) entered by a user of the terminal (12) and by means of a
corresponding encryption key (16) in the SIM card (10), and
comparator means (17) adapted for comparing a first electronic signature (5)
in the
encrypted SMS message (9) with said second electronic signature (20) and
transmitting


10

a signal to a control means (18) indicating that a PIN code (19) is to be
delivered to a
user.
8. A SIM card according to claim 7, wherein said SIM card (10) is adapted for
being
provided with the PIN code when supplying the SIM card (10) with a unique
identity
code.
9. A SIM card according to claim 8, wherein said SIM card (10) is adapted to
receive
the PIN code in the form of as encrypted data signal.

Description

Note: Descriptions are shown in the official language in which they were submitted.



CA 02390835 2002-05-09
1
T~tle~ System for electronic delivery of a ver~onal identification code
Technical Field . _
The invention relates to a system for electronic delivery of a PIN (Personal
Identification Number) evde and comprising a server 'secured by ineana of a
ncuribcr
of encryption keys and provided with a reference code for generating the-PIN
code,
said system feirther comprising means for encrypting the reference cddr arid
the PIN
code generated by means of the encryption key's atid'via coinrriected
~co~nunicadons
means being adapted to transmit a SMS (Short Mcssage'5ervice) message
'containing
an electronic signature based on the reference code to ~ a SIM (Subscriber
Identity
1U Module) card connected to a terminal with input and display means.' ~' - '
Baokgrgund,~rt_ : . w.:';'. : : _. ._.
Personal identification numbers, so-called PIN codes; are gresentlyviised
in'noany
different situations, in particular in connection with economic
'transactioiLS;~in Which
a credit card or a similar means of payment is u5ed~ together with a
terrninai~. The
information stored on the credit card is verified by °the~card user
doling-coropletion~
of the transaction by eatering a PIN code on the cerminial's keyboard, said
code being
agreed with the card issuer. It is thus ensured that the user of the card is
identical to
the owner of the card.
The PIN code is usually assigned to the credit card in connection with the
issuance
thereof and generally forwarded to the user under separate cover as ordinary
mail.
This method is neither completely secure nor very fast, as it may take several
dgys
for the letter to reach the card ovvner and thus before the owner can use his
card.
WO 99139524 relates to teiecomrnuracation systems arid discloses a procedure
arid a
system for transmission of encrypted 5M5 messages to a mobile station. The
system


CA 02390835 2002-05-09
2
comprises a teleconununication network, a mobile station connected to it surd
a
subscriber identity module (SIM) connected to the mobile stab on, amessage
svvitehing
centre, and transmission software connected to the message switching cenlrc.
1be
transmission sotlware comprises applications attd parameters of the encryption
algorithm to be used. Hereby, SMS messages ruay be generated~tmd sent to the
mobile
station via the message switching centre. The S 1M card in the mobile station
is adapted
for receiving acrd storing an encrypted SMS message.
Brief Descripsion of ,~,nvernion
The object of the invention is to provide a secure, fast aiid efficient system
which is
able to deliver PIN codes to the customers in a~ more advantageous manner.
A system of the above type is according to the invcrytion characterised in
that
said server is adapted for receiving unique information in the ftirm'of a
reference code,
said encryption means is adapted for computing a furst-electronic signature
based on
the reference code, and the server being adapted for transmitting~the first
electronic
signature as encrypted electronic informaxion in said SMS message, and' ~ ' '
said SIM card comprises means For comparingthe ttrstelectfivnic signature in
the~SMS
message with a second electronic signature being generated' from a reference
code
entered by a user of the terminal arid by means of a corresponding encryption
key in
the SIM card, and means for allowing subsequent display of a PIN code
associated
with the signatures onthe display means afthe terminal, ifthe first electxvtuc
signature
and the second electronic signature march.
It is thus only possible to be advised of a PIN code, if the user ~f a
specific terminal
enters the associatod reference code. ?he exchange of the PIN code and the
reference
code is made exclusively in form of encrypted data signals which can only be


CA 02390835 2002-05-09
decrypted by using the two unique encryption keys. A high decree of security
delivery of PIN codes is thus obtained.
Furthermore according to the invention said S1M card is adapted for being
provided
with the PIN code when supplying the S!M card with a unique identity code.
Hereby, .
the PIN code never needs to be transmitted and therefore unauthorised
decr3.~tion of
the PIN coda can be prevented.
Moreover, according to a preferred embodiment of the inventioir, said SIM card
is
adapted to receive the PIhT code in the form of an encrypted data signal,
'The invention also relates to a mobile telephone comprising a terminal with
input
meaz~.s and display means, and a STM card including means adapted for
ieceiving and
storing an encrypted SMS message, characterised in that the
SIM~card~comprisas:
comparator means adapted For comparing a first electronic signature in the
encrypted
SMS message with a second electronic signature being geaei~ted.frorr~ a
reference code
entered by a user of t(ze tcrmiaal and by means of a corresponding encryption
key in
the SIM card, and
means for allowing subsequent display of a P1N code e~sssociated with the
signatures on
the display rne~ns of the terminal, if the fu-st electronic signature and the
second
electronic si (nature snatch.
Preferred embodiment of the mobil a phone according to the invention is
claimed in the
dependent claims 5 and 6.
Finally, the invention relates to a SIM card including storage means adapted
for
receiving and storing an encrypted 5MS message, characterised in that said
SI'M card
comprises:


CA 02390835 2002-05-09
encryption means adapted for generatinget second electronic signature from a
reference
cede entered by a usEr of the terminal and by means of a corresponding encz-
yption key
in the SIM card, and
camparator means adapted for comparing a frst electronic signature in~the
encrypted
SNlS message urith said second electrotuc signature and aanstnitting a signal
to a
control means indicating that a PIN code is to be delivered to a user.
(referred embodiment of a 5IM card according to the invention are claimed in
the
dependent claims 8 and 9.
Brief Description of the Drawing ~ ... .. .. . _ ._ . . . .
1 o The invention is explained in greater devil below with reference to the
accompanying
drawing illustrating a flow chart of a preferred embodiment of the invention.
Best Mode fir ,Carrvir~a hut the tnventivn --~ -
The system for electronic delivery of a P1N code shown in the drawing
comprises a
secured server 3 adapted to receive unique information 1 (illustrated as ~a
chart for
I5 filiing-in personal data) in form of reference codas 2, and encryption
means 4
subsequently catnputing the electronic signature 5 based on the reference code
2 in
the server 3. The server 3 communicates with a so-called ever-the-air platform
6
(OTA) communicating with a SMS service centre 8 adapted to receive encrypted
information 7 from the platform 6. The SMS ser~~ice centre 8 is connected to a
SIM
20 card 10 which communicates~with a mobile handset 12 of the GSM cope
comprising
a keyboard 13 and a display means in form of a display 14, said sen~ice centre
being
able to transmit completed SM5 messages to the SIM card 10. The SIM card 10
comprises a su~ragc 11. for storing encrypted SMS messages 9, encryption means
I6
for encrypting data 15 catered by a user of the terminal !2 v is the keyboard
13 and


CA 02390835 2002-05-09
comparison means 17 connected to the storage I 1 and the keyboard 13 for
comparing
the stored data with entered data. The comparison means l 7 are further
connected
to means 18 fir displaying the PIN code on the display 14 of the terminal 12.
When using the system the user delivers unique information 1 in form of a
reference
code 2 to the secured server 3. The reference code 2 is used as an input
signal for
generating an electronic signature 5 in the server 3 by means of the
encryption means
4. The electronic signature 5 is transmitted via the over-the=air platfvrtn 6
to the SMS
service centre 8 for administration of the SIM card, said serYice centre 8
converting
the electronic signature 5 to a 5MS message 9 suitable for transmission
thereof to the
SIM card 10 in question connected to the mobile handset 12. The SIM card 10
comprises a storage 11 adapted to receive and store the encrypted SMS message
9.
The comparison means 17 are used for comparing the electronic signature 5 in
the
cnczyptcd SMS message 9 with the. electronic signature 20 ' generated by the
encryption mesas 16, said signature 20 being generated on the basis of data
entered
on the keyboard in the teirninal 12. If the electronic signature 5 and the
electronic
signature 20 entered by the user match, the comparison means 17 transmits a
signal
to the guide means 18 that the PIN code 19 is to be displayed on the display
14 of
the mobile handset 12, whereby the PIN cede is delivered to the user.
In a preferred embodiment of the iavention the cermitsal 12 is a mobile
handset such
as a cellular telephone. A S1M card (subscriber Identity Module) is required
for
operating mobile handsets adapted for communication via an existing GSM
network.
The SIM card, which in use forms an integrated part of the elec4ronics of the
mobile
handset, contains inrer ells codes identifying the mobile handset in relation
to the
GSM network. This identification is necessary to enable the network to
determine far
instance the position of the mobile terminal for transmission of mobile
telephony via
the most advantageous transmission tower(s) in the network at the specific
time.
The sem~er 3 comprises software (not shown) for generating PIN codes, a triple
DES


CA 02390835 2002-05-09
b
(Data Encryption Standard) encryption algorithm (reference numeral 4), an
encrypted
datrabase (not shown) containing encryption b;eys tv all of the SIM cards
registered
in the system and information .about the connection between the numbers ~ of
the
mobile handsets and the numbers of the associated ~ SIM cards. A triple DES
algorithm is an encryption process ~ in three levels which is considered
particular 1y
secure against unauthorised decryption. ' - ~ ' v
When the secured server 3 has received the reference-~code from ~a~ new user
and
verified that the user's SIM card number is valid in the system, the server 3
generates
an electronic sigslauue 5 preferably by means of the triple -AE5 algorithm 4
combined with the two keys of at least 55 bit belonging ~io the user's SIM
card
number. ThE electronic signature 5 is transmitted to the user's SIM card ~ 10
~as as
uniquely formatted G5M S bit SM5 (Short Messager~'Sysiem) message The coiling
'
of the SMS messages is adapted such that the electronic signat<ire ~5 ~of the
rice
code 2 is stored in the storage 11 of the SIM card !0 sad die-usei is notiFied
that the
generated PIN cede is ready for use when a SMS message 9 is received by the
user's
SIM card 10. '
When the user subsequently runs the program in the SIM card 10 enabling
delivery
of the PIN code, the user is requested by the program wia the displajr -14' of
the
terminal to enter the referents code 15 on the keyboard 1~3 cif the terminal
12. For
gcneraeing another electronic signature 20, the reference node 15 is i;odcd by
the
encryption means 16 in the SIM card a0 bytncans of the same encryption
algorithm
used by the encryption means 4 in the secured server 3 when the reference node
2
was supplied to the secured server 3. The comparison means 17 in the SIM card
10
then compares the electronic signature 5 stored in the storage 11 and based on
the
~referra~ce code Z with the electronic signature 20 generated by the
encryption means
16. If the two signatures match, the comparison means 17 transmits a signal to
the
,guide means 18 indicating that the PIN code 19 is to be displayed on the
display 14
of the terminal 12. If the two electronic signatures arc not identical, the
user is


CA 02390835 2002-05-09
7
advised on the display 14 that the reference code 15 has not baen accepted
arid is
asked to enter the reference code 15 once more. If the reference code 1S after
tvvo
additional attempts still is incorrect, the program is interrupted and the PIN
code 19
is not delivered until the user has fetched a new reference code 2 from the
secured
server 3, said code being eithez~ identical to or different from the initial
reference
code 2.
In order to ensure that the delivered PIN code is read correctly, the user may
be
offered validation of the delivered PIN code, The validation process is
pcrforrned by
the user entering the PIN code shown on the display 14 by means of the
keyboard,
whereafter the user is advised whether the PIN code has been entered
correctly. If
not, the PIN code is shown once mere on the display 14 and the validation
process
can be repeated. =
In an alternative embodiment the PIN code nay be provided in the SIM card,
when
the card is supplied with a unique identity code, vV$ereby the PIN code never
need
be transmitted. This is considered a more secure embodiment, unauchvrised
decryption of the PIN code duri~c~g transmission therieof thus being
prevented.
The invention is not restricted to the above preferred embodiment, but may be
altered
in many ways without thereby deviating from the scope of the invention.

Representative Drawing
A single figure which represents the drawing illustrating the invention.
Administrative Status

For a clearer understanding of the status of the application/patent presented on this page, the site Disclaimer , as well as the definitions for Patent , Administrative Status , Maintenance Fee  and Payment History  should be consulted.

Administrative Status

Title Date
Forecasted Issue Date Unavailable
(86) PCT Filing Date 2000-11-09
(87) PCT Publication Date 2001-05-17
(85) National Entry 2002-05-09
Examination Requested 2005-10-18
Dead Application 2008-11-10

Abandonment History

Abandonment Date Reason Reinstatement Date
2007-11-09 FAILURE TO PAY APPLICATION MAINTENANCE FEE

Payment History

Fee Type Anniversary Year Due Date Amount Paid Paid Date
Registration of a document - section 124 $100.00 2002-05-09
Application Fee $300.00 2002-05-09
Maintenance Fee - Application - New Act 2 2002-11-12 $100.00 2002-10-31
Maintenance Fee - Application - New Act 3 2003-11-10 $100.00 2003-10-15
Maintenance Fee - Application - New Act 4 2004-11-09 $100.00 2004-10-12
Request for Examination $800.00 2005-10-18
Maintenance Fee - Application - New Act 5 2005-11-09 $200.00 2005-10-18
Maintenance Fee - Application - New Act 6 2006-11-09 $200.00 2006-11-07
Owners on Record

Note: Records showing the ownership history in alphabetical order.

Current Owners on Record
ORANGE A/S
Past Owners on Record
WARD, CHRISTIAN PAUL
Past Owners that do not appear in the "Owners on Record" listing will appear in other documentation within the application.
Documents

To view selected files, please enter reCAPTCHA code :



To view images, click a link in the Document Description column. To download the documents, select one or more checkboxes in the first column and then click the "Download Selected in PDF format (Zip Archive)" or the "Download Selected as Single PDF" button.

List of published and non-published patent-specific documents on the CPD .

If you have any difficulty accessing content, you can call the Client Service Centre at 1-866-997-1936 or send them an e-mail at CIPO Client Service Centre.


Document
Description 
Date
(yyyy-mm-dd) 
Number of pages   Size of Image (KB) 
Description 2002-05-09 7 322
Representative Drawing 2002-10-18 1 8
Abstract 2002-05-09 1 65
Cover Page 2002-10-21 1 43
Claims 2002-05-09 3 97
Drawings 2002-05-09 1 12
PCT 2002-05-09 18 733
Assignment 2002-05-09 3 104
Correspondence 2002-10-16 1 25
Fees 2003-10-15 1 26
Assignment 2002-11-04 2 55
Fees 2005-10-18 1 25
Correspondence 2005-10-18 1 25
Prosecution-Amendment 2005-10-18 1 32
Fees 2002-10-31 1 32
Fees 2004-10-12 1 27
Prosecution-Amendment 2006-07-24 1 30
Fees 2006-11-07 1 24