发明名称 Transaction security system using time variant parameter
摘要 An electronic funds transfer system (EFT) is described in which retail terminals located in stores are connected through a public switched telecommunication system to card issuing agencies data processing centers. Users of the system are issued with intelligent secure bank cards, which include a microprocessor, ROS and RAM stores. The ROS includes a personal key (KP) and an account number (PAN) stored on the card when the issuer issues it to the user. Users also have a personal identity numbe (PIN) which is stored or remembered separately. A transaction is initiated at a retail terminal when a card is inserted in an EPT module connected to the terminal. A request message including the PAN and a session key (KS) is transmitted to the issuers data processing center. The issuer generates an authentication parameter (TAP) based upon its stored version of KP and PIN and a time variant parameter received from the terminal. The TAP is then returned to the terminal in a response message, and based upon an inputed PIN, partial processing of the input PIN and KP on the card a derived TAP is compared with the received TAP in the terminal. A correct comparison indicating that the entered PIN is valid. The request message includes the PAN encoded under the KS and KS encoded under a cross-domain key. Message authentication codes (MAC) are attached to each message and the correct reception and regeneration of a MAC on a message including a term encoded under KS indicates that the received KS is valid and that the message originated at a valid terminal or card.
申请公布号 US4747050(A) 申请公布日期 1988.05.24
申请号 US19870091310 申请日期 1987.08.28
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BRACHTL, BRUNO;HOLLOWAY, CHRISTOPHER J.;LENNON, RICHARD E.;MATYAS, STEPHEN M.;MEYER, CARL H.;OSEAS, JONATHAN
分类号 G07F7/12;G06Q40/00;G07D9/00;G07F7/10;G07F19/00;(IPC1-7):H04L9/02 主分类号 G07F7/12
代理机构 代理人
主权项
地址