TWI862471B - Digital transaction apparatus, data assistance device, digital transaction card, operating method and computer-redable medium for secure transaction - Google Patents
Digital transaction apparatus, data assistance device, digital transaction card, operating method and computer-redable medium for secure transaction Download PDFInfo
- Publication number
- TWI862471B TWI862471B TW106103559A TW106103559A TWI862471B TW I862471 B TWI862471 B TW I862471B TW 106103559 A TW106103559 A TW 106103559A TW 106103559 A TW106103559 A TW 106103559A TW I862471 B TWI862471 B TW I862471B
- Authority
- TW
- Taiwan
- Prior art keywords
- digital transaction
- dtc
- digital
- dad
- card
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0853—On-card keyboard means
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/12—Payment architectures specially adapted for electronic shopping systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
- G06Q20/3552—Downloading or loading of personalisation data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/357—Cards having a plurality of specified features
- G06Q20/3572—Multiple accounts on card
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/357—Cards having a plurality of specified features
- G06Q20/3574—Multiple applications on card
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
- G06Q20/3672—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes initialising or reloading thereof
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
- G06Q20/3674—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes involving authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3823—Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0846—On-card display means
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Accounting & Taxation (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Finance (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Computer Security & Cryptography (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)
Abstract
Description
本發明大體上係關於用於實現安全數位交易(包含金融及非金融交易兩者)之裝置與方法。裝置與方法可特別用於涉及信用卡及/或金融卡之安全交易。 The present invention generally relates to apparatus and methods for implementing secure digital transactions (including both financial and non-financial transactions). The apparatus and methods may be particularly useful for secure transactions involving credit cards and/or debit cards.
信用卡、金融卡、儲值卡及禮品卡係用於全世界之金融交易之卡之實例。此外,其他類型之卡(諸如通行證、標籤及小冊子)(其可統稱為交易文件)用於各種金融及非金融交易。舉例而言,一些行政轄區需要年齡證明卡用於交易(諸如購買酒精或進入年齡受限場所)。年齡證明或身份證明文件之其他實例包含駕駛執照,其有時用於涉及交易之鑑認。在一些國家,護照及/或其他類似識別文件以一卡或一小冊子之形式發行,且可用於其中需要識別之交易,包含跨境旅行或建立一銀行帳戶。 Credit cards, debit cards, stored-value cards, and gift cards are examples of cards used for financial transactions throughout the world. In addition, other types of cards such as passes, tags, and booklets (which may be collectively referred to as transaction documents) are used for a variety of financial and non-financial transactions. For example, some jurisdictions require proof-of-age cards for transactions (such as purchasing alcohol or entering age-restricted venues). Other examples of proof-of-age or identity documents include a driver's license, which is sometimes used for identification in connection with transactions. In some countries, passports and/or other similar identification documents are issued in the form of a card or booklet and may be used for transactions where identification is required, including traveling across borders or opening a bank account.
許多交易文件具有一磁條,可使用諸如一唯一識別號碼、到期日或其他數字或字母數字資訊之資訊編碼磁條。其他類型之交易文件包含非接 觸式儲值智慧型卡,舉例而言,閉合迴路運輸卡(諸如澳大利亞墨爾本之悠遊卡(Myki)及香港之八達通卡)。 Many transaction documents have a magnetic stripe that may be encoded with information such as a unique identification number, expiration date, or other numeric or alphanumeric information. Other types of transaction documents include contactless stored-value smart cards, for example, closed-loop transit cards (such as Melbourne's EasyCard (Myki) and Hong Kong's Octopus card).
交易文件可包含一晶片、智慧型晶片或智慧型卡晶片(在本說明書中,此等晶片或器件及其他類似類型之微電路將通常稱為數位交易處理單元或DTPU)。DTPU通常包含一中央處理單元(CPU)、唯讀記憶體(ROM)、隨機存取記憶體(RAM)、電可擦除可程式化唯讀記憶體(EEPROM)、一密碼編譯協處理器及一輸入/輸出(I/O)系統之一或多者。舉例而言,信用卡常常使用一EMV器件(其中EMV係Europay、萬事達卡及Visa(Europay,MasterCard,and Visa)之一縮寫)。EMV器件(或其他類型之DTPU)含有與將使用文件之(若干)交易之類型相關之加密資料。可藉由一掃描器(舉例而言,使用根據ISO/IEC 14443之非接觸式、近距離通信,其稱為近場通信(貫穿說明書NFC))、藉由與晶片連接電極之直接接觸或藉由自晶片獲得資料之其他方法讀取EMV器件。使能憑藉一晶片、一磁條、一晶片及磁條或射頻識別(RFID)而用於數位交易中之此等交易文件貫穿本說明書稱為數位交易文件。 The transaction document may include a chip, smart chip or smart card chip (in this specification, such chips or devices and other similar types of microcircuits will generally be referred to as digital transaction processing units or DTPUs). The DTPU typically includes one or more of a central processing unit (CPU), read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), a cryptographic coprocessor and an input/output (I/O) system. For example, credit cards often use an EMV device (where EMV is an acronym for Europay, MasterCard, and Visa). The EMV device (or other type of DTPU) contains encrypted data related to the type of transaction(s) for which the document will be used. EMV devices can be read by a scanner (for example, using contactless, short-distance communication according to ISO/IEC 14443, which is called Near Field Communication (NFC)), by direct contact with the chip connection electrodes, or by other methods of obtaining data from the chip. Such transaction documents that enable use in digital transactions by means of a chip, a magnetic stripe, a chip and magnetic stripe or radio frequency identification (RFID) are referred to throughout this specification as digital transaction documents.
數位交易文件經組態以搭配包含終端機之一數位交易系統中之各種組件運作。舉例而言,信用卡及金融卡搭配用於銷售點(POS)交易之EFTPOS(銷售點電子轉帳系統)終端機及ATM(自動提款機)終端機運作。其他數位交易文件經組態以搭配其他類型之終端機運作。此等終端機可能可操作地連接至金融機構或其他第三方組織以藉由授權交易或執行關聯處理以啓用交易而使能夠發生數位交易。 Digital transaction files are configured to operate with various components in a digital transaction system that includes a terminal. For example, credit and debit cards operate with EFTPOS (Electronic Funds Transfer at Point of Sale) terminals and ATM (Automated Teller Machine) terminals used for point-of-sale (POS) transactions. Other digital transaction files are configured to operate with other types of terminals. These terminals may be operably connected to financial institutions or other third-party organizations to enable digital transactions to occur by authorizing transactions or performing associated processing to enable transactions.
在另一實例中,使用含有卡擁有者之一些或全部資訊,連同確認卡之真實性之驗證資訊之一晶片(或DTPU)來實施識別卡(諸如一年齡證明 卡)。識別卡可用於一數位交易中,藉此將其插入一終端機中、在一終端機附近滑動或擱置以確認持卡人之年齡。可以一類似方式實施其他非金融交易。 In another example, an identification card (such as an age verification card) is implemented using a chip (or DTPU) containing some or all of the card owner's information, along with verification information to confirm the card's authenticity. The identification card can be used in a digital transaction whereby it is inserted into, slid near, or held near a terminal to confirm the cardholder's age. Other non-financial transactions can be implemented in a similar manner.
用於與數位交易文件交易之終端機貫穿本說明書稱為數位交易系統器件。對於「實體卡」(Card-Present)交易,數位交易系統器件可包含(舉例而言)POS/EFTPOS終端機、ATM及用於讀取其他類型之非金融交易文件之網路連接或獨立讀取器。數位交易器件亦可適於「無卡」(Card Not-Present)交易(舉例而言,線上交易、郵件訂單/電話訂單(MOTO)交易),且可包含網際網路連接之個人電腦、智慧型電話及平板電腦。此外,數位交易系統器件包含用來與使用(舉例而言)一網路連接之終端機鍵入交易文件資料之一操作者通信之電話。 Terminals used to transact with digital transaction documents are referred to throughout this specification as digital transaction system devices. For "card-present" transactions, digital transaction system devices may include, for example, POS/EFTPOS terminals, ATMs, and network-connected or stand-alone readers for reading other types of non-financial transaction documents. Digital transaction devices may also be suitable for "card not-present" transactions (for example, online transactions, mail order/telephone order (MOTO) transactions), and may include Internet-connected personal computers, smart phones, and tablet computers. In addition, digital transaction system devices include telephones used to communicate with an operator who uses, for example, a network-connected terminal to enter transaction document data.
數位交易文件具有一唯一識別(唯一ID),通常具有一編號、一字母數字ID或一唯一名稱。唯一ID可位於數位交易文件上或中,舉例而言,印刷或壓印在文件上。唯一ID亦通常記錄在一資料庫上、(舉例而言)由數位交易文件之發行者控制,且隨附其他資訊(諸如與數位交易文件之使用者/擁有者相關之名稱、位址、年齡及/或金融資訊)。在一數位交易文件具有一晶片、一EMV器件或其他類型之DTPU之情況下,唯一ID通常分別儲存在晶片、EMV器件或DTPU上。 A digital transaction document has a unique identification (Unique ID), typically a number, an alphanumeric ID, or a unique name. The Unique ID may be located on or in the digital transaction document, for example, printed or embossed on the document. The Unique ID is also typically recorded in a database, for example, controlled by the issuer of the digital transaction document, and is accompanied by other information (such as name, address, age, and/or financial information associated with the user/owner of the digital transaction document). In the case where a digital transaction document has a chip, an EMV device, or other type of DTPU, the Unique ID is typically stored on the chip, EMV device, or DTPU, respectively.
信用卡通常壓印或印刷有一個人/主帳號(PAN)以唯一地識別帳戶卡持有人。一標準化PAN具有四個欄位,即,一系統編號、一銀行/產品編號、一使用者帳號及一檢查數字(check digit)。此類型之PAN通常具有16個數字,但可具有13與19之間個數字(舉例而言,一美國運通PAN具有17個數字)。第一數字係卡發行者類型(舉例而言,Visa、萬事達卡或美國運 通),且接下來的5至7個數字通常稱為一銀行識別號碼(BIN)且表示卡網路、銀行及此銀行之產品。最後數字保留作為PAN之先前數字之一總和檢查碼。一到期日與PAN相關聯且通常包含具有四個數字但具有有限範圍之一月份及年份碼。持卡人之PAN、名稱或業務及卡之到期日通常呈壓印或印刷在一卡之正面上。先前,一些類型之信用卡具有編碼一些或全部卡資訊之一磁條。 Credit cards are usually embossed or printed with a Personal/Primary Account Number (PAN) to uniquely identify the account card holder. A standardized PAN has four fields, namely, a system number, a bank/product number, a user account number, and a check digit. This type of PAN usually has 16 digits, but can have between 13 and 19 digits (for example, an American Express PAN has 17 digits). The first digit is the card issuer type (for example, Visa, MasterCard or American Express), and the next 5 to 7 digits are usually called a Bank Identification Number (BIN) and identify the card network, bank, and the products of this bank. The last digit is reserved as a checksum of the previous digits of the PAN. An expiration date is associated with the PAN and usually consists of a month and year code that is four digits but has a limited range. The cardholder's PAN, name or business, and the card's expiration date are usually embossed or printed on the front of a card. Previously, some types of credit cards had a magnetic strip that encoded some or all of the card information.
最近,金融交易卡已在磁條上攜載一卡驗證值(CVV)或卡驗證碼(CVC)以使得更難以複製一卡用於欺詐目的。CVC通常係一唯一密碼(cryptogram)、基於卡資料(舉例而言,包含卡PAN及到期日)及一銀行之(或一個人化製卡機構(personalization bureau)之)主金鑰予以建立、且在將個人化資料鍵入在卡上之後印刷於卡上。因此,企圖使用一卡用於欺詐目的之一人需要擁有卡達一足夠時段以製作磁條之一複本以便複製卡,或讀取卡且手動記錄卡號碼、到期日及印刷在卡上之其他細節。 More recently, financial transaction cards have been carrying a Card Verification Value (CVV) or Card Verification Code (CVC) on the magnetic stripe to make it more difficult to copy a card for fraudulent purposes. The CVC is typically a unique cryptogram, created based on the card information (including, for example, the card PAN and expiration date) and a bank's (or a personalization bureau's) master key, and printed on the card after the personalization information is keyed onto the card. Thus, a person attempting to use a card for fraudulent purposes would need to have the card in their possession for a sufficient period of time to make a copy of the magnetic stripe in order to copy the card, or to read the card and manually record the card number, expiration date, and other details printed on the card.
隨後,針對一第二CVC(有時稱為卡驗證值2(CVV2),其一般印刷在卡背面上之簽名面板中)採用相同原理。CVV2主要用來幫助保護電子商務及MOTO交易安全。此係自卡資料及銀行之主金鑰建立之一第二唯一密碼(然而此係相較於磁條CVC之一不同密碼)。CVV2不存在於磁條上。 The same principle is then used for a second CVC (sometimes called Card Verification Value 2 (CVV2), which is usually printed in the signature panel on the back of the card). CVV2 is primarily used to help secure e-commerce and MOTO transactions. This is a second unique code created from the card data and the bank's master key (however, this is a different code than the magnetic stripe CVC). CVV2 does not exist on the magnetic stripe.
一些信用卡亦具有一關聯個人識別號碼(PIN)碼,其主要用於「實體卡」交易。PIN通常必須保密,且必須鍵入在安全且經認證終端機上以確保無人可存取PIN。此外,在現代信用卡中,PIN可以一密碼區塊內之一加密形式儲存在晶片(舉例而言,一EMV器件)上。 Some credit cards also have an associated personal identification number (PIN) code, which is used primarily for "physical card" transactions. The PIN must generally be kept secret and must be entered on a secure and authenticated terminal to ensure that no one can access the PIN. Additionally, in modern credit cards, the PIN may be stored in an encrypted form within a cryptographic block on a chip (e.g., an EMV device).
存在使用信用卡之交易之兩個主要分類,其包含:「無卡」交易,當使用網際網路或MOTO時;及「實體卡」交易,諸如搭配POS/EFTPOS 及ATM終端機使用。實體卡交易涉及EMV器件讀取器(包含使用一卡上之電極接腳之實體接觸讀取器及使用(舉例而言)近場通信(NFC)之非接觸式讀取)及/或磁條讀取器。此等交易通常使用完整13至19位數PAN及4位數到期日。無卡交易通常需要使用者將PAN及到期日數字讀出至一操作者,或鍵入至一電腦中。在一些例項中,亦需要CVC/CVV2編號。 There are two main categories of transactions using credit cards, including: "card not present" transactions, when using the Internet or MOTO; and "physical card" transactions, such as used with POS/EFTPOS and ATM terminals. Physical card transactions involve EMV device readers (including physical contact readers using electrode pins on a card and contactless readers using, for example, Near Field Communication (NFC)) and/or magnetic stripe readers. These transactions typically use the full 13-19 digit PAN and 4 digit expiration date. Card not present transactions usually require the user to read the PAN and expiration date digits to an operator, or type them into a computer. In some cases, a CVC/CVV2 number is also required.
其他類型之數位交易文件可使用各種形式之安全性,諸如PIN、通行碼(password)及類似者。然而,一些其他類型之數位交易文件不使用此外部安全性,且僅依賴於文件自身之真實性,舉例而言,使用全像及難以複製之其他安全性器件。此外,一些類型之非信用卡數位交易文件可使用晶片用於安全性,包含類似於EMV器件之晶片。 Other types of digital transaction documents may use various forms of security, such as PINs, passwords, and the like. However, some other types of digital transaction documents do not use this external security and rely solely on the authenticity of the document itself, for example, using holograms and other security devices that are difficult to copy. In addition, some types of non-credit card digital transaction documents may use chips for security, including chips similar to EMV devices.
例如使用一射頻(RF)信號向卡之EMV內部微處理器及相關傳輸器供電可使卡(或其他數位交易文件)資料失竊。通常,卡資料(諸如PAN、到期日及持卡人之名稱)被傳送至一無線終端機。終端機可為一攜帶型或固定無線終端機,且一旦接近一卡,便使用RF信號供能量至卡以:第一,提取卡資料且將一些卡資料複製至一記憶體儲存器件,或複製至線上儲存器(諸如雲端);及第二,根據無需任何授權之一交易等級,使用緊靠卡之一攜帶型終端機來提取貨幣作為一非接觸式支付(舉例而言,一PayWave及/或輕觸支付(tap payment),此等交易被交易者稱為輕觸支付(tap-and-pay)或輕觸即付(tap-and-go))。隨後,竊取之卡資料可上傳至一複製「假卡」(fake card)或用於線上交易中以進行欺詐購買。用來竊取卡資料以供欺詐使用之再另一方法涉及侵入儲存卡資料之電腦資料庫中。此資料接著用於交易,且一卡擁有者可能僅在其等看見詳述用其卡或卡資料完成之交易之一清單時才意識到此。 For example, using a radio frequency (RF) signal to power the EMV internal microprocessor and associated transmitter of the card can enable the theft of card (or other digital transaction files) data. Typically, card data (such as PAN, expiration date and cardholder's name) is transmitted to a wireless terminal. The terminal may be a portable or fixed wireless terminal and, once in proximity to a card, uses RF signals to energize the card to: first, extract card data and copy some card data to a memory storage device, or to online storage (such as the cloud); and second, extract money as a contactless payment (for example, a PayWave and/or tap payment, such transactions are referred to by transactors as tap-and-pay or tap-and-go) using a portable terminal in proximity to the card, based on a transaction level that does not require any authorization. The stolen card data can then be uploaded to a duplicate "fake card" or used in online transactions to make fraudulent purchases. Yet another method used to steal card data for fraudulent use involves hacking into computer databases where card data is stored. This data is then used in transactions, and a card owner may only realize this when they see a list detailing transactions completed with their card or card data.
竊取卡資料之其他方式包含網路釣魚詐騙,其中誘騙持卡人經由一欺詐網站鍵入一安全碼連同其他卡細節。因此,網路釣魚降低作為一反欺詐手段之安全碼之有效性。然而,不使用安全碼之商家通常經受用於交易之較高卡處理成本,且無安全碼之欺詐交易更可能利於持卡者破解,此增加商家之成本。可損及交易之安全性之又其他方式係藉由忽略(skimming)及中間人(man-in-the-middle)攻擊。 Other ways to steal card information include phishing scams, where cardholders are tricked into entering a security code along with other card details through a fraudulent website. Phishing therefore reduces the effectiveness of security codes as an anti-fraud measure. However, merchants who do not use security codes typically experience higher card processing costs for transactions, and fraudulent transactions without security codes are more likely to be hacked by the cardholder, which increases costs for merchants. Still other ways that the security of transactions can be compromised are through skimming and man-in-the-middle attacks.
隨著電子商務之出現,愈來愈多交易係無卡類型交易。然而,此類型之交易經受來自欺詐者之愈來愈多攻擊,包含已導致已導致其中持卡人合法但交易被拒之一「確定失敗」結果之增加驗證之攻擊。 With the advent of e-commerce, an increasing number of transactions are card-not-present type transactions. However, this type of transaction is subject to increasing attacks from fraudsters, including attacks that increase verification that have resulted in a "definite failure" outcome where the cardholder is legitimate but the transaction is declined.
已開發數個解決方案以解決此日益成長的欺詐,包含使用虛擬帳號、與交易分開地鑑認持卡人及使用用以鑑認使用者之一硬體符記。另一提出之解決方案包括一機制,諸如將一碼發送至使用者(通常藉由SMS發送至使用者之智慧型電話)之一銀行,其可接著用來鑑認一無卡交易。此配置通常稱為帶外(OOB)訊息,其不幸地最近被攻擊。在任何情況下,許多此等解決方案需要昂貴的基礎設施變更(商家偏好避免該等變更)且可能僅提供保護達一有限時間,直至配置被攻擊。 Several solutions have been developed to address this growing fraud, including the use of virtual accounts, authenticating the cardholder separately from the transaction, and using a hardware token to authenticate the user. Another proposed solution involves a mechanism such as a bank sending a code to the user (usually via SMS to the user's smartphone) which can then be used to authenticate a card-not-present transaction. This configuration is often referred to as out-of-band (OOB) messaging, which has unfortunately recently been compromised. In any case, many of these solutions require expensive infrastructure changes (which merchants prefer to avoid) and may only provide protection for a limited time until the configuration is compromised.
隨著愈來愈多無卡交易,進行此等交易之一建議方法係電子錢包(e錢包),其亦稱為一數位錢包。一e錢包提供為來自啓用之線上商家之所購物付款之一方法給使用者。在註冊後,一使用者旋即可將其等卡、計費及運送資訊儲存在由一適合文件(諸如一銀行)主持之一網站上,且可存取該資訊以為貨物或服務付款。然而,一NFC啓用器件(諸如一智慧型電話)上之e錢包無法使用在大量實體卡交易(舉例而言,POS/EFTPOS或ATM交易)中,此係因為此等網路交易器件通常不支援非接觸式支付,而且在目前可 用非接觸式支付配置中,涉及不同後端程序及商家協議。因此,e錢包之建立及使用已經歷有限商業成功且同時其等保持對消費者可用,僅近似10%之消費者已選擇安裝一e錢包,然而消費者之開通率(take-up rate)現在開始下降。 With the increasing number of card-not-present transactions, one proposed method for conducting such transactions is an electronic wallet (e-wallet), also known as a digital wallet. An e-wallet provides users with a method to pay for purchases from enabled online merchants. After registration, a user can instantly store their card, billing and shipping information on a website hosted by a suitable entity (such as a bank) and can access that information to pay for goods or services. However, an e-wallet on an NFC-enabled device (such as a smartphone) cannot be used in a large number of physical card transactions (for example, POS/EFTPOS or ATM transactions) because these network transaction devices generally do not support contactless payments and the different backend processes and merchant protocols involved in currently available contactless payment configurations. As a result, the creation and use of e-wallets has experienced limited commercial success and while they remain available to consumers, only approximately 10% of consumers have chosen to install an e-wallet, and consumer take-up rates are now beginning to decline.
使用者可能偏好具有且隨身攜帶許多其等可用信用卡、金融卡、儲值卡、政府機構卡及會員卡(loyalty card),此係因為使用者偏好實際上持有且控制該等卡之擁有。此外,使用者可能需要身份證、駕駛執照、年齡驗證卡或護照。隨身攜帶大量個人數位交易文件可為非常不便的。此外,具有如此多實體交易文件之人可能關於一特定數位交易文件(舉例而言,一特定信用卡)在全部其他數位交易文件中之位置而變得困惑。 A user may prefer to have and carry with him many of the available credit cards, debit cards, stored value cards, government agency cards, and loyalty cards because the user prefers to actually own and control the possession of such cards. In addition, the user may need an ID card, driver's license, age verification card, or passport. Carrying a large number of personal digital transaction documents can be very inconvenient. In addition, a person with so many physical transaction documents may become confused as to the location of a particular digital transaction document (for example, a particular credit card) among all the other digital transaction documents.
已開發解決使用者攜載大量信用卡或金融卡之問題之e錢包之一替代解決方案,其中一信用卡大小器件具有一鍵盤(或配置為一簡化鍵盤之觸控板)及一小有限功能圖形使用者介面(GUI),其等用來在儲存在器件上之若干卡中選擇一個卡,且鍵入資料以供各種交易。然而,鍵盤歸因於其等在卡上可用之相對較小空間(係一平均信用卡之面積)中之有限數目個鍵而具有有限功能性。鍵盤亦由於其等小尺寸而被認為難以使用,且因此可能需要大量按鍵動作以實現任何特定功能。此外,一信用卡上之鍵盤並非用於其他類型之數位交易文件(諸如用於識別或年齡證明之文件)之一解決方案。其他嘗試解決方案包含產品,諸如Plastc、Coin、Final及Wocket。然而,Plastc解決方案具有一些操作限制,且Wocket解決方案需要一特定Wocket器件。此等解決方案皆尚未獲得廣泛商業接受。此外,已發現包含一鍵盤之卡鑑於重複、或許每天使用而在給予客戶時具有一無法接受的高故障率。認為高故障率可能至少部分歸因於在一卡上具有鍵盤之複雜 性,其已限制用於此一複雜電子器件之空間。 One alternative solution to the e-wallet that has been developed to solve the problem of users carrying a large number of credit or debit cards is a credit card sized device having a keyboard (or a touch pad configured as a simplified keyboard) and a small limited functionality graphical user interface (GUI) that is used to select a card among several cards stored on the device and to enter data for various transactions. However, keyboards have limited functionality due to their limited number of keys in the relatively small space available on the card (the area of an average credit card). Keyboards are also considered difficult to use due to their small size and therefore may require a large number of keystrokes to achieve any particular function. Furthermore, a keyboard on a credit card is not a solution for other types of digital transaction documents, such as those used for identification or proof of age. Other attempted solutions include products such as Plastc, Coin, Final, and Wocket. However, the Plastc solution has some operational limitations, and the Wocket solution requires a specific Wocket device. None of these solutions have yet gained widespread commercial acceptance. Furthermore, cards that include a keyboard have been found to have an unacceptably high failure rate when given to customers in view of repeated, perhaps daily, use. It is believed that the high failure rate may be due, at least in part, to the complexity of having a keyboard on a card, which has limited the space available for such a complex electronic device.
伴隨嘗試在一單一卡上容納多個信用卡、金融卡或其他數位交易文件之另一問題係由使用專有或標準化晶片導致之限制。此等晶片或DTPU經組態以僅安全地儲存用於一個數位交易文件之資訊。舉例而言,一信用卡晶片(諸如一EMVCo標準晶片)安全地保存通常包含信用卡PAN、到期日、一安全性碼(諸如CCV2碼)及一PIN之資訊。交易器件(諸如POS/EFTPOS終端機)與DTPU安全地通信以自DTPU獲得一些或全部資訊以授權並驗證一交易。許多DTPU亦經組態以抵制對於寫入至DTPU安全記錄記憶體(其亦可稱為一安全元件,或一安全元件之部分)之嘗試,此係因為由企圖欺詐地使用卡之人作出許多此等嘗試。將理解,一安全元件可包括安全記憶體及一執行環境,且係一動態環境,其中可安全地儲存並管理應用程式碼及應用程式資料。此外,將理解,在一安全元件中,可發生應用程式之安全執行。一安全元件可位於一高度安全加密晶片(以其他方式稱為一智慧型卡晶片)中。DTPU之安全性亦可防止將一或多個新數位交易文件(包含PAN、符記到期日、PIN及該等文件之其他資料屬性)合法地引入至DTPU之安全記錄記憶體(安全元件)中,使得DTPU無法承擔另一文件之特質(personality)(一術語,其在本文中用來描述一數位交易文件(或邏輯數位交易文件)及其屬性)。 Another problem with trying to accommodate multiple credit cards, debit cards, or other digital transaction files on a single card is the limitations caused by using proprietary or standardized chips. These chips or DTPUs are configured to securely store information for only one digital transaction file. For example, a credit card chip (such as an EMVCo standard chip) securely stores information that typically includes the credit card PAN, expiration date, a security code (such as a CCV2 code), and a PIN. The transaction device (such as a POS/EFTPOS terminal) communicates securely with the DTPU to obtain some or all of the information from the DTPU to authorize and verify a transaction. Many DTPUs are also configured to resist attempts to write to the DTPU secure log memory (which may also be referred to as a secure element, or part of a secure element) because many such attempts are made by people attempting to use the card fraudulently. It will be understood that a secure element may include secure memory and an execution environment, and is a dynamic environment in which application code and application data may be securely stored and managed. Furthermore, it will be understood that in a secure element, secure execution of applications may occur. A secure element may be located in a highly secure cryptographic chip (otherwise referred to as a smart card chip). The security of the DTPU also prevents the legal introduction of one or more new digital transaction documents (including PAN, token expiration date, PIN and other data attributes of such documents) into the secure record memory (secure element) of the DTPU, making it impossible for the DTPU to assume the personality (a term used in this article to describe a digital transaction document (or logical digital transaction document) and its attributes) of another document.
相應地,鑑於所需之基礎設施之變更(包含經修改DTPU(諸如EMVCo器件)、經修改數位交易器件(舉例而言,經修改POS/EFTPOS終端機),連同信用卡/金融卡支付基礎設施之其他部分中所需之任何其他修改),難以鼓勵使用具有多個特質之單一實體卡(一單一實體卡上表示或可表示之多個信用卡及/或金融卡)。除技術問題之外,計劃提供者(諸如Visa 及萬事達卡)具有各種額外需求,包含計劃之一全像及商標存在於實體卡上。 Accordingly, the use of a single physical card with multiple attributes (multiple credit and/or debit cards represented or representable on a single physical card) is difficult to encourage given the infrastructure changes required (including modified DTPUs (such as EMVCo devices), modified digital transaction devices (for example, modified POS/EFTPOS terminals), along with any other modifications required in other parts of the credit/debit card payment infrastructure). In addition to technical issues, program providers (such as Visa and MasterCard) have various additional requirements, including that a hologram and logo of the program be present on the physical card.
在此點上,期望在一數位交易卡(DTC)(舉例而言,一信用卡大小卡)上提供一單一EMV(或EMV類型器件)或其他類型之DTPU,其能夠選擇性地採用若干不同數位交易文件(或邏輯數位交易文件)之特質。舉例而言,一使用者可企圖使用萬事達卡帳戶進行一個交易,但使用Visa帳戶進行一不同交易。替代地,一使用者可企圖使用DTC作為一信用卡,但隨後使用其作為一年齡身份證。 In this regard, it is desirable to provide a single EMV (or EMV-type device) or other type of DTPU on a digital transaction card (DTC) (e.g., a credit card-sized card) that can selectively employ the characteristics of several different digital transaction documents (or logical digital transaction documents). For example, a user may attempt to use a MasterCard account for one transaction, but use a Visa account for a different transaction. Alternatively, a user may attempt to use a DTC as a credit card, but then use it as an age identification card.
然而,迄今為止,尚不存在用於調適一DTPU(諸如一EMVCo指定器件)以體現相較於最初安裝之DTPU之特質之不同特質之一足夠有效、高效率及/或安全手段及/或方法。 However, to date, there does not exist a sufficiently effective, efficient and/or secure means and/or method for adapting a DTPU (such as an EMVCo specified device) to embody different characteristics than those of the originally installed DTPU.
伴隨目前數位交易文件之另一問題係自一信用卡或其他交易文件獲得資料之能力。儘管已引入諸如EMV器件之器件以嘗試限制資料盜用,然而此等配置尚未證實在防止此類型之犯罪方面完全成功。愈來愈多信用卡欺詐可能招致一銀行、一商家、一使用者或全部三方之成本。此外,身份盜用係使用者日益關注之一問題,此係因為一竊取身份可用來進行欺詐金融交易及其他類型之犯罪。 Another problem with current digital transaction documents is the ability to obtain data from a credit card or other transaction document. Although devices such as EMV devices have been introduced to attempt to limit data theft, these arrangements have not proven completely successful in preventing this type of crime. Increasingly, credit card fraud may incur costs to a bank, a merchant, a user, or all three. Additionally, identity theft is a growing concern for users because a stolen identity can be used to conduct fraudulent financial transactions and other types of crime.
對於一些數位交易文件(諸如信用卡),有時使用符記提高交易之安全性。對於信用卡,符記通常係與信用卡之PAN長度相同且在一交易中替代PAN之編號。符記不應被可行地解密以由企圖欺詐地使用信用卡之一人獲得原始PAN,且因此該人無法模仿信用卡,且無法使用信用卡PAN及一持卡人之其他個人細節用於線上交易。相應地,若在一高風險、低安全性環境中使用一信用卡,則符記係保護敏感資料之一手段。符記之安全性主 要基於在僅知道代理符記值時判定原始PAN(或其他資料)之不可行性。符記化可代替或結合其他加密技術用於與數位交易文件之交易。 For some digital transaction documents (such as credit cards), tokens are sometimes used to increase the security of the transaction. For credit cards, the token is usually a number that is the same length as the credit card's PAN and that replaces the PAN in a transaction. The token should not be able to be decrypted to obtain the original PAN by a person attempting to use the credit card fraudulently, and therefore that person cannot impersonate the credit card and use the credit card PAN and other personal details of a cardholder for online transactions. Accordingly, if a credit card is used in a high-risk, low-security environment, tokens are a means of protecting sensitive data. The security of tokens is primarily based on the impracticability of determining the original PAN (or other data) when only the proxy token value is known. Tokenization can be used instead of or in conjunction with other encryption techniques for transactions with digital transaction documents.
可由諸如一信用卡發行者、一金融機構或信用卡之一安全性提供者之一第三方產生一符記(或數位符記)。符記亦用於保護諸如涉及駕駛執照之其他非金融交易的安全。可使用來自(舉例而言)信用卡之PAN(或一數位交易文件之一些其他唯一ID)及/或卡之到期日之一選擇之輸入產生符記作為一密碼。可基於其中正發生交易之商家或終端機之ID、交易之日期、交易之時間或各種其他準則而自一集區中之若干符記選擇用於一交易之符記。擷取原始PAN之解除符記化通常發生在一交易之處理期間,且通常由信用卡發行者、金融機構或發行符記之安全性提供者執行。 A token (or digital token) may be generated by a third party such as a credit card issuer, a financial institution, or a security provider for a credit card. Tokens are also used to secure other non-financial transactions such as those involving driver's licenses. The token may be generated as a password using a selected input from, for example, the credit card's PAN (or some other unique ID from a digital transaction file) and/or the card's expiration date. The token used for a transaction may be selected from a pool of tokens based on the ID of the merchant or terminal where the transaction is occurring, the date of the transaction, the time of the transaction, or various other criteria. De-tokenization to extract the original PAN typically occurs during the processing of a transaction and is typically performed by the credit card issuer, financial institution, or security provider that issued the token.
通常,在建立並向其擁有者/使用者發行一信用卡之程序期間產生符記。各卡可具有一或多個關聯符記。在一卡具有多個符記之情況下,各符記可選擇性地用於不同交易或不同交易類型。 Typically, tokens are generated during the process of creating and issuing a credit card to its owner/user. Each card may have one or more tokens associated with it. Where a card has multiple tokens, each token may be selectively used for different transactions or different types of transactions.
符記具有若干問題,包含不可由使用者選擇以允許使用者控制安全性及如何使用符記。舉例而言,一使用者可企圖能夠針對某些交易或交易類型選擇符記。另一問題係相同符記可能需要用於若干不同交易,因此限制由符記提供之安全性。此係特別地針對諸如一信用卡之一數位交易文件之情況。即使一數位交易文件具有若干關聯符記,仍將需要在若干交易之後重複使用或重新發行該等符記。難以(舉例而言)向一信用卡發行新符記,此係因為已開發用於發行新符記之基礎設施以在建立並發行一新信用卡時發行該等新符記。 Tokens have several problems, including not being user selectable to allow the user to control security and how the token is used. For example, a user may attempt to be able to select tokens for certain transactions or transaction types. Another problem is that the same token may need to be used for several different transactions, thus limiting the security provided by the token. This is particularly the case with a digital transaction file such as a credit card. Even if a digital transaction file has several tokens associated with it, the tokens will still need to be reused or reissued after several transactions. It is difficult to issue new tokens to a credit card, for example, because the infrastructure for issuing new tokens has been developed to issue new tokens when a new credit card is created and issued.
防止一遭竊取或遭盜用信用卡或其他類型之交易文件之欺詐使用之一方式係簡單地取消文件,包含取消該文件之唯一識別符(舉例而言,取 消一信用卡之帳號),且發行具有一新到期日之一新文件。文件之提供者可具有一機制以使舊文件無效(舉例而言,使舊帳號無效),且向現有使用者發行新編號。然而,有時可花費大量時間來遞送一新文件(舉例而言,透過郵件遞送一信用卡),且延遲對使用者造成極大不便。在一信用卡之例項中,一新卡之發行導致使用者藉由自信用帳戶自動轉帳而維持支付之能力之一暫時中止。 One way to prevent fraudulent use of a stolen or compromised credit card or other type of transaction document is to simply cancel the document, including canceling the document's unique identifier (e.g., canceling a credit card account number), and issue a new document with a new expiration date. The provider of the document may have a mechanism to invalidate the old document (e.g., invalidate the old account number) and issue new numbers to existing users. However, it can sometimes take a significant amount of time to deliver a new document (e.g., delivering a credit card by mail), and the delay can be a significant inconvenience to the user. In the example of a credit card, the issuance of a new card results in a temporary suspension of the user's ability to maintain payments by automatic transfer from the credit account.
此外,文件擁有者通常偏好立即或接近立即(「即時」)回饋關於其等卡用於金融交易或其他類型之交易(諸如一卡或其他此等文件用於識別、旅行及其他目的)之資訊。卡擁有者亦可能偏好即時回饋關於帳戶餘額及與其等卡或其他數位交易文件相關之其他資訊。此外,卡及其他數位交易文件之擁有者可能偏好即時或有最小延遲地阻止使用一文件之能力。若擁有者意識到或懷疑使用其等(若干)數位交易文件之一或多者之(若干)欺詐交易,則此可為有用的。 In addition, file owners often prefer immediate or near immediate ("instant") feedback regarding the use of their cards for financial transactions or other types of transactions (e.g., a card or other such file is used for identification, travel, and other purposes). Card owners may also prefer immediate feedback regarding account balances and other information associated with their cards or other digital transaction files. In addition, owners of cards and other digital transaction files may prefer the ability to block the use of a file immediately or with minimal delay. This may be useful if the owner is aware of or suspects fraudulent transaction(s) using one or more of their digital transaction file(s).
本發明之一目標係克服或至少改善先前技術中之上述問題之至少一者,及/或提供先前技術器件、系統及/或方法之至少一有用替代。 One of the objectives of the present invention is to overcome or at least improve at least one of the above-mentioned problems in the prior art, and/or to provide at least one useful alternative to the prior art devices, systems and/or methods.
在一項態樣中,本發明提供一種可搭配複數個數位符記操作之數位交易裝置,各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該數位交易裝置包含:一資料輔助器件(DAD),其包含一使用者介面及一DAD傳輸器;及一數位交易卡(DTC),其包含一DTC接收器及一數位交易處理單元(DTPU),其中該裝置經組態用於儲存該複數個數位符記之至少一者,其中該DAD 經組態以允許藉由該使用者介面對該經儲存至少一個數位符記之一者之選擇且將該選擇傳輸至該DTC,且其中該DTC經組態以實施該所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In one aspect, the present invention provides a digital transaction device operable with a plurality of digital tokens, each digital token being associated with a digital transaction document, and each digital transaction document being associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction document for a digital transaction with at least one digital transaction device, the digital transaction device comprising: a data-assisted device (DAD) comprising a user interface and a DAD transmitter; and a digital transaction card (DTC) , comprising a DTC receiver and a digital transaction processing unit (DTPU), wherein the device is configured to store at least one of the plurality of digital tokens, wherein the DAD is configured to allow selection of one of the stored at least one digital token by the user interface and transmit the selection to the DTC, and wherein the DTC is configured to implement the selected digital token so that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token.
在另一態樣中,本發明提供一種可搭配具有一數位交易卡(DTC)接收器及一數位交易處理單元(DTPU)之一DTC操作,且可搭配複數個數位符記操作之資料輔助器件(DAD),各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該DAD包含一使用者介面及一DAD傳輸器,其中該DAD經組態用於與該DTC協作地儲存該複數個數位符記之至少一者,使得將該至少一個符記儲存在該DTC、該DAD或該DTC及該DAD兩者中,且其中該DAD經組態以允許藉由該使用者介面對該經儲存至少一個數位符記之一者之選擇且將該選擇傳輸至該DTC,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In another aspect, the present invention provides a data-assisted device (DAD) that can be used in conjunction with a digital transaction card (DTC) receiver and a digital transaction processing unit (DTPU) having a DTC, and can be used in conjunction with a plurality of digital tokens, each digital token being associated with a digital transaction file, and each digital transaction file being associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, and the DAD includes a user interface and a DAD transmitter, wherein the DAD is configured to store at least one of the plurality of digital tokens in cooperation with the DTC, such that the at least one token is stored in the DTC, the DAD, or both the DTC and the DAD, and wherein the DAD is configured to allow selection of one of the stored at least one digital tokens by the user interface and transmit the selection to the DTC, such that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token.
在再另一態樣中,本發明提供一種可搭配具有一使用者介面及一資料輔助器件(DAD)傳輸器之一DAD操作,且可搭配複數個數位符記操作之數位交易卡(DTC),各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該DTC包含一DTC接收器及一數位交易處理單元(DTPU),其中該DTC經組態用於與該DAD協作地儲存該複數個數位符記之至少一者,使得該至少一個符記經儲存在該DTC、該DAD或該DTC及該DAD兩者中,其中該DTC經組態 以接受自該DAD傳輸之表示該經儲存至少一個數位符記之一所選擇者之資料,且其中該DTC經組態以實施該所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In yet another aspect, the present invention provides a digital transaction card (DTC) operable with a data-assisted device (DAD) having a user interface and a DAD transmitter, and operable with a plurality of digital tokens, each digital token being associated with a digital transaction document, and each digital transaction document being associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction document for a digital transaction with at least one digital transaction device, the DTC comprising a DTC receiver and a digital transaction processing unit (DTC). TPU), wherein the DTC is configured to store at least one of the plurality of digital tokens in cooperation with the DAD, such that the at least one token is stored in the DTC, the DAD, or both the DTC and the DAD, wherein the DTC is configured to receive data transmitted from the DAD representing a selected one of the stored at least one digital token, and wherein the DTC is configured to implement the selected digital token such that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token.
在一進一步態樣中,本發明提供一種使用包含具有一使用者介面及一DAD傳輸器之一資料輔助器件(DAD)之一數位交易裝置交易之方法,該數位交易裝置亦包含具有一DTC接收器及一數位交易處理單元(DTPU)之一數位交易卡(DTC),其中該數位交易裝置可搭配複數個數位符記操作,各數位符記與一數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該方法包含實施一所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In a further aspect, the present invention provides a method for transacting using a digital transaction device including a data-assisted device (DAD) having a user interface and a DAD transmitter, the digital transaction device also including a digital transaction card (DTC) having a DTC receiver and a digital transaction processing unit (DTPU), wherein the digital transaction device can operate with a plurality of digital tokens, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, the method comprising implementing a selected digital token so that the DTC is enabled to operate as the tokenized associated digital transaction file represented by the selected digital token.
在又一進一步態樣中,本發明提供一種使用包含具有一使用者介面及一資料輔助器件(DAD)收發器之一DAD之數位交易裝置交易之方法,該數位交易裝置亦包含具有一數位交易卡(DTC)接收器及一數位交易處理單元(DTPU)之一DTC,其中該數位交易裝置可搭配複數個數位符記操作,各數位符記與一數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該方法包含操作該使用者介面以選擇已儲存在該裝置中之該複數個數位符記之至少一者之一者。 In yet a further aspect, the present invention provides a method for conducting a transaction using a digital transaction device including a DAD having a user interface and a data-assisted device (DAD) transceiver, the digital transaction device also including a digital transaction card (DTC) receiver and a digital transaction processing unit (DTPU) having a DTC, wherein the digital transaction device can be operated with a plurality of digital tokens, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, the method comprising operating the user interface to select one of at least one of the plurality of digital tokens stored in the device.
在再另一態樣中,本發明提供一種方法,其中一使用者自一發行機構接收一數位交易卡(DTC)用於根據上文之陳述之任何一或多者之使用。 In yet another aspect, the present invention provides a method in which a user receives a digital transaction card (DTC) from an issuing institution for use according to any one or more of the above statements.
在再另一態樣中,本發明提供一種方法,其中一發行機構發行根據 上文之陳述之任何一或多者之一數位交易卡(DTC)。 In yet another aspect, the present invention provides a method in which an issuing institution issues a digital transaction card (DTC) according to any one or more of the above statements.
在再另一態樣中,本發明提供一種方法,其中一發行機構發行一數位交易卡(DTC)用於根據上文之陳述之任何一或多者之使用。 In yet another aspect, the present invention provides a method in which an issuing institution issues a digital transaction card (DTC) for use according to any one or more of the above statements.
在一進一步態樣中,本發明提供一種方法,其中一發行機構向一資料輔助器件(DAD)及/或向一數位交易卡(DTC)發行包含軟體及/或韌體之操作碼用於根據上文之陳述之任何一或多者之使用。 In a further aspect, the present invention provides a method in which an issuing organization issues an operation code containing software and/or firmware to a data assisted device (DAD) and/or to a digital transaction card (DTC) for use according to any one or more of the above statements.
在實施例中,本發明提供一種可搭配複數個數位符記操作之數位交易裝置,各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該數位交易裝置包含:一資料輔助器件(DAD),其包含一處理器、一使用者介面、一DAD收發器及DAD記憶體;及一數位交易卡(DTC),其包含一DTC收發器、一數位交易處理單元(DTPU)及DTC記憶體,其中該DTC可僅與該DAD連結而排除全部其他DAD以實現資料在該DAD與該DTC之間藉由各自收發器之安全傳輸,其中該裝置經組態用於儲存該複數個數位符記之至少一者,其中該DAD經組態以允許藉由該使用者介面對該經儲存至少一個數位符記之一者之選擇且將該選擇傳輸至該DTC,其中該DTC經組態以實施該所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件,且其中該DTC經組態以與該至少一個數位交易器件介接,因此在該DTC可操作為該符記化關聯數位交易文件時實現該數位交易。 In an embodiment, the present invention provides a digital transaction device that can be operated with multiple digital tokens, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, and the digital transaction device includes: a data-assisted device (DAD), which includes a processor, a user interface, a DAD transceiver and a DAD memory; and a digital transaction card (DTC), which includes a DTC transceiver, a digital transaction processing unit (DTPU) and a DTC memory, wherein the DTC can be connected only to the DAD and exclude all other DADs to enable secure transmission of data between the DAD and the DTC via respective transceivers, wherein the device is configured to store at least one of the plurality of digital tokens, wherein the DAD is configured to allow selection of one of the stored at least one digital token via the user interface and transmit the selection to the DTC, wherein the DTC is configured to implement the selected digital token so that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token, and wherein the DTC is configured to interface with the at least one digital transaction device, thereby implementing the digital transaction when the DTC is operable as the tokenized associated digital transaction document.
在實施例中,本發明提供一種可搭配具有一DTC收發器、一DTPU及 DTC記憶體之一DTC操作,且可搭配複數個數位符記操作之DAD,各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該DAD包含一處理器、一使用者介面、一DAD收發器及DAD記憶體,其中僅該DAD可與該DTC連結而排除全部其他DAD以實現資料在該DAD與該DTC之間藉由各自收發器之安全傳輸,其中該DAD記憶體經組態用於與該DTC記憶體協作地儲存該複數個數位符記之至少一者,使得將該至少一個符記儲存在該DTC記憶體、該DAD記憶體或該DTC記憶體及該DAD記憶體兩者中,且其中該DAD經組態以允許藉由該使用者介面對該經儲存至少一個數位符記之一者之選擇且將該選擇傳輸至該DTC,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In an embodiment, the present invention provides a DAD that can be used with a DTC having a DTC transceiver, a DTPU and a DTC memory, and can be used with a plurality of digital tokens, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, and the DAD includes a processor, a user interface, a DAD transceiver and a DAD memory, wherein only the DAD can be connected to the DTC to exclude all other DADs to achieve Data is securely transmitted between the DAD and the DTC via respective transceivers, wherein the DAD memory is configured to store at least one of the plurality of digital tokens in cooperation with the DTC memory such that the at least one token is stored in the DTC memory, the DAD memory, or both the DTC memory and the DAD memory, and wherein the DAD is configured to allow selection of one of the stored at least one digital tokens via the user interface and transmit the selection to the DTC such that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token.
在實施例中,本發明提供一種可搭配具有一處理器、一使用者介面、一DAD收發器及DAD記憶體之一DAD操作,且可搭配複數個數位符記操作之DTC,各數位符記與一個數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中各數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該DTC包含一DTC收發器、一DTPU及DTC記憶體,其中該DTC可僅與該DAD連結而排除全部其他DAD以實現資料在該DAD與該DTC之間藉由各自收發器之安全傳輸,其中該DTC記憶體經組態用於與該DAD記憶體協作地儲存該複數個數位符記之至少一者,使得該至少一個符記經儲存在該DTC記憶體、該DAD記憶體或該DTC記憶體及該DAD記憶體兩者中,其中該DTC經組態以接受自該DAD傳輸之表示該經儲存至少一個數位符記之一所選擇者 之資料,其中該DTC經組態以實施該所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件,且其中該DTC經組態以與該至少一個數位交易器件介接用於在該DTC可操作為該符記化關聯數位交易文件時實現該數位交易。 In an embodiment, the present invention provides a DTC that can be used with a DAD operation having a processor, a user interface, a DAD transceiver and a DAD memory, and can be used with a plurality of digital token operations, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein each digital token represents a tokenized associated digital transaction file for a digital transaction with at least one digital transaction device, the DTC includes a DTC transceiver, a DTPU and a DTC memory, wherein the DTC can be connected only to the DAD and exclude all other DADs to achieve secure transmission of data between the DAD and the DTC through their respective transceivers, wherein the DTC memory The DTC is configured to store at least one of the plurality of digital tokens in cooperation with the DAD memory, such that the at least one token is stored in the DTC memory, the DAD memory, or both the DTC memory and the DAD memory, wherein the DTC is configured to receive data transmitted from the DAD representing a selected one of the stored at least one digital token, wherein the DTC is configured to implement the selected digital token, such that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token, and wherein the DTC is configured to interface with the at least one digital transaction device for implementing the digital transaction when the DTC is operable as the tokenized associated digital transaction document.
在實施例中,本發明提供一種使用包含具有一處理器、一使用者介面、一DAD收發器及DAD記憶體之一DAD之一數位交易裝置交易之方法,該數位交易裝置亦包含具有一DTC收發器、一DTPU及DTC記憶體之一DTC,其中該DTC可僅與一個DAD連結而排除全部其他DAD,該數位交易裝置可搭配複數個數位符記操作,各數位符記與一數位交易文件相關聯,且各數位交易文件與一或多個數位符記相關聯,其中數位符記表示用於與至少一個數位交易器件之一數位交易之一符記化關聯數位交易文件,該方法包含:操作該使用者介面以選擇已儲存在該裝置中之該複數個數位符記之至少一者之一者;使該DAD與該DTC連結以實現藉由各自收發器將表示該所選擇數位符記之資料自該DAD傳輸至該DTC,其中該DTC經組態以實施該所選擇數位符記,使得該DTC經啟用以操作為由該所選擇數位符記表示之該符記化關聯數位交易文件。 In an embodiment, the present invention provides a method for trading using a digital transaction device including a DAD having a processor, a user interface, a DAD transceiver and a DAD memory, wherein the digital transaction device also includes a DTC having a DTC transceiver, a DTPU and a DTC memory, wherein the DTC can be connected to only one DAD and exclude all other DADs, and the digital transaction device can be operated with a plurality of digital tokens, each digital token is associated with a digital transaction file, and each digital transaction file is associated with one or more digital tokens, wherein the digital A digital token represents a tokenized associated digital transaction document for a digital transaction with at least one digital transaction device, the method comprising: operating the user interface to select one of at least one of the plurality of digital tokens stored in the device; connecting the DAD and the DTC to enable data representing the selected digital token to be transmitted from the DAD to the DTC through respective transceivers, wherein the DTC is configured to implement the selected digital token, so that the DTC is enabled to operate as the tokenized associated digital transaction document represented by the selected digital token.
在又其他實施例中,DTC可使用一實體連接件(諸如一資料纜線)來與DAD連結。在此等實施例中,資料纜線可經調適以在一端部處插入於DAD上之一USB埠中,其中另一端部經調適以夾箝或夾持在DTC之一部分上。DTC可具有處於或朝向其一邊緣之電極或金屬板以允許資料纜線之另一端部之夾箝或夾持。 In still other embodiments, the DTC may be connected to the DAD using a physical connector, such as a data cable. In such embodiments, the data cable may be adapted to plug into a USB port on the DAD at one end, with the other end adapted to clamp or clip onto a portion of the DTC. The DTC may have electrodes or metal plates at or toward one of its edges to allow for clamping or clipping of the other end of the data cable.
在一些實施例中,將複數個數位符記之至少一者儲存在DAD上。在其他實施例中,將複數個數位符記之至少一者儲存在DTC上,其中透過 DAD藉由與一數位符記相關聯之一指示符或名稱而選擇數位符記,但數位符記自身未儲存在DAD上,使得經由指示已選擇哪一符記之資料將符記之選擇傳遞至DTC,且DTC基於指示資料實施來自其記憶體之所選擇符記。在又其他實施例中,將複數個數位符記之至少一者之各者之一部分儲存在DAD上。將複數個數位符記之各對應至少一者之另一部分儲存在DTC上,其中選擇係基於儲存在DAD上之部分。將所選擇數位符記之部分傳輸至DTC,且以此方式在DTC上判定匹配所選擇部分之數位符記之部分,可組合數位符記之兩個部分以形成整個數位符記,其可接著由DTC實施。 In some embodiments, at least one of the plurality of digital symbols is stored on the DAD. In other embodiments, at least one of the plurality of digital symbols is stored on the DTC, wherein the digital symbol is selected by the DAD by an indicator or name associated with a digital symbol, but the digital symbol itself is not stored on the DAD, so that the selection of the symbol is communicated to the DTC via data indicating which symbol has been selected, and the DTC implements the selected symbol from its memory based on the indicating data. In still other embodiments, a portion of each of the at least one of the plurality of digital symbols is stored on the DAD. Another portion of each corresponding at least one of the plurality of digital symbols is stored on the DTC, wherein the selection is based on the portion stored on the DAD. The selected portion of the digital token is transmitted to the DTC, and in this way the portion of the digital token that matches the selected portion is determined at the DTC, and the two portions of the digital token can be combined to form the entire digital token, which can then be implemented by the DTC.
在一實施例中,DAD經啟用以儲存及/或提供在DTC上實施為一數位交易文件之一邏輯數位交易文件之選擇。各邏輯數位交易文件具有一唯一識別,(例如)一信用卡之一個人/主帳號(PAN)。文件之選擇可在與文件相關聯之一符記之選擇之前發生。在一文件僅具有一個符記之情況下,可將文件之選擇視為關聯符記之選擇,此係因為不需要一進一步選擇程序。在一些實施例中,一符記之選擇自動指示待選擇之邏輯數位交易文件,此係因為符記僅與一個文件相關聯。 In one embodiment, the DAD is enabled to store and/or provide selection of a logical digital transaction file implemented as a digital transaction file on the DTC. Each logical digital transaction file has a unique identification, such as a personal/primary account number (PAN) of a credit card. Selection of the file may occur before selection of a token associated with the file. In the case where a file has only one token, selection of the file may be considered selection of the associated token because a further selection process is not required. In some embodiments, selection of a token automatically indicates the logical digital transaction file to be selected because tokens are associated with only one file.
如同數位符記之情況,邏輯數位交易文件可儲存在DAD記憶體、DTC記憶體中,或各邏輯數位交易文件之一部分可儲存在DAD記憶體及DTC記憶體兩者中。邏輯數位交易文件之選擇可係藉由一代表性圖式或一類似螢幕顯示器。在實施例中,使用者選擇所要數位交易文件且接著選擇與所選擇交易文件相關聯之所要數位符記。在另一實施例中,使用者可選擇一數位交易文件且基於由DAD判定之內容脈絡而選擇一預定符記。舉例而言,若DAD感測不同位置,則可基於經感測位置自動選擇一符記。 As with digital tokens, logical digital transaction files may be stored in DAD memory, DTC memory, or a portion of each logical digital transaction file may be stored in both DAD memory and DTC memory. Selection of a logical digital transaction file may be by a representative diagram or a similar screen display. In an embodiment, a user selects a desired digital transaction file and then selects a desired digital token associated with the selected transaction file. In another embodiment, a user may select a digital transaction file and select a predetermined token based on the content context determined by the DAD. For example, if the DAD senses different locations, a token may be automatically selected based on the sensed location.
在邏輯數位交易文件及符記完全或部分儲存在DTC上之情況中,DAD可具有可選擇文件及符記之表示,但非文件及符記之唯一識別(唯一ID)資訊之全部或某一部分。在此一實施例中,可將所選擇文件及符記傳遞至DTC作為代表性資料,其僅指示已選擇之文件及符記而不含有文件及符記之整個唯一ID資訊。舉例而言,DAD可僅含有一信用卡之PAN之部分,及與該信用卡相關聯之一符記之部分。在另一實例中,DAD可僅具有經指派至信用卡及符記之一名稱或暱稱而無儲存在其上之PAN或符記號碼之任何部分。 In the case where logical digital transaction files and tokens are stored in whole or in part on the DTC, the DAD may have representations of selectable files and tokens, but not all or a portion of the unique identification (unique ID) information of the files and tokens. In such an embodiment, the selected files and tokens may be delivered to the DTC as representative data indicating only the files and tokens that have been selected without containing the entire unique ID information of the files and tokens. For example, the DAD may contain only a portion of the PAN of a credit card and a portion of a token associated with the credit card. In another example, the DAD may have only a name or nickname assigned to the credit card and token without any portion of the PAN or token number stored thereon.
在各項實施例中,一些數位交易文件將僅具有一個關聯符記且其他數位交易文件將具有多個關聯符記。應理解,在本說明書中論述之實施例包含兩個選項,除非另外陳述或除非包含兩個選項導致不可能實施之一實施例。 In various embodiments, some digital transaction documents will have only one associated token and other digital transaction documents will have multiple associated tokens. It should be understood that the embodiments discussed in this specification include both options unless otherwise stated or unless the inclusion of both options renders one embodiment impossible to implement.
在各項實施例中,一數位交易文件將不需要儲存在裝置中(DAD記憶體或DTC記憶體中),此係因為儲存在裝置中之(若干)符記將足以識別其(等)(若干)關聯數位交易文件。舉例而言,在數位交易文件係一信用卡之情況中,卡號碼(PAN)不儲存在裝置上且代替性地,與信用卡相關聯之符記足以識別特定信用卡。在此一實例中,信用卡PAN可包含將卡識別為具有一特定類型或品牌(萬事達卡、Visa等)之4個典型前導數字。特定信用卡之一符記可具有相同的四個前導數字,但具有不同剩餘數字,使得符記識別與其相關聯之卡。應瞭解,(例如)裝置中(DAD記憶體或DTC記憶體中)不儲存一PAN應增加數位交易文件之安全性。在此等實例中,僅數位符記由DAD選擇,其中關聯數位交易文件經自動識別及選擇。 In various embodiments, a digital transaction file will not need to be stored in the device (in DAD memory or DTC memory) because the token(s) stored in the device will be sufficient to identify its(the) associated digital transaction file(s). For example, in the case where the digital transaction file is a credit card, the card number (PAN) is not stored on the device and instead, the token associated with the credit card is sufficient to identify the specific credit card. In this example, the credit card PAN may include the 4 typical leading digits that identify the card as being of a specific type or brand (MasterCard, Visa, etc.). A token for a specific credit card may have the same four leading digits, but with different remaining digits so that the token identifies the card with which it is associated. It will be appreciated that not storing a PAN in the device (in DAD memory or DTC memory, for example) should increase the security of the digital transaction document. In such instances, only the digital token is selected by the DAD, with the associated digital transaction document automatically identified and selected.
在各項實施例中,數位交易文件可係一信用卡、金融卡、銀行帳 戶、儲值卡、護照、身份證、年齡驗證卡、會員卡、政府機構卡、駕駛執照及/或將通常實施為卡、文件或小冊子或經電子實施之各種其他種類及類型之數位交易文件。應理解,在本說明書中,術語「邏輯」係指針對各數位交易文件之一特性集合。特性可包含資料,諸如數位交易文件之唯一ID、擁有權資訊及到期日。識別資訊可係一唯一ID號碼。自表達一個數位交易文件至表達另一數位交易文件之DTC之一變更亦可稱為DTC「特質」之一變更。 In various embodiments, the digital transaction document may be a credit card, debit card, bank account, stored-value card, passport, identity card, age verification card, membership card, government agency card, driver's license, and/or various other types and categories of digital transaction documents that are typically implemented as cards, documents or booklets or implemented electronically. It should be understood that in this specification, the term "logical" refers to a set of characteristics for each digital transaction document. Characteristics may include data such as a unique ID, ownership information, and expiration date of the digital transaction document. The identification information may be a unique ID number. A change in a DTC from expressing one digital transaction document to expressing another digital transaction document may also be referred to as a change in a DTC "characteristic".
在各項實施例中,數位交易器件可包含銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機、自動提款機(ATM)、網際網路連接電腦或個人電腦(PC)及其他此等電子器件。數位交易器件亦可包含基礎設施,其包含經啟用用於郵件訂單/電話訂單(MOTO)類型交易之一電話及呼叫中心。 In various embodiments, the digital transaction device may include a point of sale/electronic fund transfer system (POS/EFTPOS) terminal, an automated teller machine (ATM), an Internet-connected computer or personal computer (PC), and other such electronic devices. The digital transaction device may also include an infrastructure including a telephone and call center enabled for mail order/telephone order (MOTO) type transactions.
在實施例中,數位交易文件之唯一ID可係一PAN,或類似種類之唯一ID,諸如唯一字母數字ID或唯一名稱。 In an embodiment, the unique ID of the digital transaction document may be a PAN, or a similar type of unique ID, such as a unique alphanumeric ID or a unique name.
在其他各項實施例中,DAD可係一智慧型電話、電腦平板、膝上型電腦、PC、鎖環器件或用於儲存數位符記且能夠操作以允許一使用者選擇一數位符記且傳輸表示該所選擇數位符記之資料之其他適合設備。DAD亦可包含適合於該目的之一客製DAD。在其他實施例中,DAD可係一可佩帶器件(諸如一智慧型手錶),或可經啟用以搭配此一可佩帶器件操作。 In other embodiments, the DAD may be a smart phone, computer tablet, laptop, PC, lock device, or other suitable device for storing digital tokens and operable to allow a user to select a digital token and transmit data representing the selected digital token. The DAD may also include a customized DAD suitable for that purpose. In other embodiments, the DAD may be a wearable device (such as a smart watch), or may be enabled to operate in conjunction with such a wearable device.
在一實施例中,經由一使用者介面之選擇可包含自(例如)一智慧型電話上之一觸控啟動螢幕選擇。觸控啟動螢幕可藉由顯示清單、下拉式清單或其他螢幕設計操作,或可採用螢幕上之圖式。使用者介面亦可係具有(舉例而言)一鎖環上之按鈕之一簡單顯示器。在DAD係一PC或膝上型電 腦之情況下,其可採用一螢幕及鍵盤以提供一使用者介面。然而,使用者通常偏好DAD為一攜帶型DAD。 In one embodiment, selection via a user interface may include a touch screen selection from, for example, a smart phone. The touch screen may operate by displaying a list, a drop-down list, or other screen design, or may employ graphics on the screen. The user interface may also be a simple display with, for example, buttons on a lock ring. In the case where the DAD is a PC or laptop, it may employ a screen and keyboard to provide a user interface. However, users generally prefer that the DAD be a portable DAD.
在各項其他實施例中,DTC可包含其他特徵,舉例而言,用於顯示所選擇數位符記、所選擇邏輯數位交易文件及/或關於其之資訊之一圖形使用者介面(GUI)。舉例而言,若邏輯數位交易文件係一信用卡,則DTC上之GUI可顯示PAN、與所選擇邏輯數位交易文件相關聯之所選擇符記、卡品牌標誌、信用卡之到期日,且亦可顯示信用卡品牌之一虛擬或模仿全像。在另一實施例中,DTC可僅顯示所選擇符記且不顯示關聯PAN。DTC亦可包含顯示於其表面上之某處之一真實全像。 In various other embodiments, the DTC may include other features, such as a graphical user interface (GUI) for displaying the selected digital token, the selected logical digital transaction document, and/or information about the same. For example, if the logical digital transaction document is a credit card, the GUI on the DTC may display the PAN, the selected token associated with the selected logical digital transaction document, the card brand logo, the expiration date of the credit card, and may also display a virtual or simulated hologram of the credit card brand. In another embodiment, the DTC may only display the selected token and not the associated PAN. The DTC may also include a real hologram displayed somewhere on its surface.
在其他實施例中,DTC可包含用於處理要求(例如,安全性要求、儲存要求)之一處理器。處理器亦可控制GUI顯示器。 In other embodiments, the DTC may include a processor for processing requests (e.g., security requests, storage requests). The processor may also control the GUI display.
在各項實施例中,DTC亦可包含一按鈕或一類似器件以啟動與DAD之連結。在一些實施例中,用於DAD及DTC之各自收發器可適合於BluetoothTM、Low Energy BluetoothTM、Wi-Fi、近場通信(NFC)、ANT+或其他類型之非接觸式或無線通信收發器。在其他實施例中,收發器可需要DAD與DTC之間之接觸以便傳輸資料,或以便建立兩者之間之一連結。 In various embodiments, the DTC may also include a button or a similar device to activate the connection with the DAD. In some embodiments, the respective transceivers for the DAD and the DTC may be adapted for Bluetooth ™ , Low Energy Bluetooth ™ , Wi-Fi, Near Field Communication (NFC), ANT+, or other types of contactless or wireless communication transceivers. In other embodiments, the transceiver may require contact between the DAD and the DTC in order to transfer data, or in order to establish a connection between the two.
在選用實施例中,DTC上之記憶體可在一EMV晶片(其係Europay、萬事達卡及Visa(Europay,MasterCard,and Visa)之一縮寫)或另一類型之類似或相容晶片上。 In an alternative embodiment, the memory on the DTC may be on an EMV chip (which is an acronym for Europay, MasterCard, and Visa) or another type of similar or compatible chip.
在又其他實施例中,DTC經組態以插入至一POS/EFTPOS終端機或一ATM中。 In yet other embodiments, the DTC is configured to be inserted into a POS/EFTPOS terminal or an ATM.
在又其他實施例中,舉例而言,若DTC包含非靜態型記憶體儲存器 或某一形式之供電收發器(諸如BluetoothTM),則DTC包含用於記憶體儲存之一電池。一電池亦可用於對DTC供電以處理加密,且用於藉由實施儲存在DTC上之邏輯數位交易文件及/或關聯數位符記之變更而變更由DTC表達之數位交易文件及/或數位符記。 In still other embodiments, for example, if the DTC includes non-static memory storage or some form of powered transceiver (such as Bluetooth ™ ), the DTC includes a battery for memory storage. A battery may also be used to power the DTC to process encryption and to change the digital transaction files and/or digital tokens represented by the DTC by implementing changes to the logical digital transaction files and/or associated digital tokens stored on the DTC.
在一實施例中,DTC可經調適以表達一預設「歸零」特質,其中代替需要唯一ID之一邏輯數位交易文件之資料可係一系列預定數字(例如,全零)。在一個實例中,在邏輯數位交易文件係一信用卡之情況中,唯一ID可係信用卡PAN或一關聯數位符記,且藉由使用全零複寫或替換PAN或關聯數位符記而執行將DTC設定返回至表達一歸零特質。 In one embodiment, the DTC may be adapted to express a default "return to zero" characteristic, where the data in place of a logical digital transaction document requiring a unique ID may be a series of predetermined numbers (e.g., all zeros). In one example, where the logical digital transaction document is a credit card, the unique ID may be the credit card PAN or a related digital token, and the DTC setting is returned to express a return to zero characteristic by overwriting or replacing the PAN or related digital token with all zeros.
在一選用實施例中,DTC亦可經組態以儲存一邏輯數位交易文件及/或關聯數位符記達一選擇時期。時期可由DTC之發行者及/或數位符記之發行者(其可係與DTC之發行者不同之一發行者)預定。替代地,儲存期可由使用者選擇。在其他變動中,時期可為可動態選擇的,且可由使用者針對各交易或針對DTC上之一單一邏輯數位交易文件及/或(若干)關聯數位符記選擇。在其他實施例中,可基於所選擇邏輯數位交易文件及/或(若干)數位符記或基於交易類型或兩者而判定DTC上之邏輯數位交易文件及/或(若干)關聯數位符記之儲存期。 In an optional embodiment, the DTC may also be configured to store a logical digital transaction file and/or associated digital token for a selected period. The period may be predetermined by the issuer of the DTC and/or the issuer of the digital token (which may be an issuer different from the issuer of the DTC). Alternatively, the storage period may be selected by the user. In other variations, the period may be dynamically selectable and may be selected by the user for each transaction or for a single logical digital transaction file and/or (several) associated digital tokens on the DTC. In other embodiments, the storage period of the logical digital transaction file and/or (several) associated digital tokens on the DTC may be determined based on the selected logical digital transaction file and/or (several) digital tokens or based on the transaction type or both.
在實施例中,DTC及數位交易器件可藉由各種方法彼此介接。在一些實施例中,可藉由將DTC插入至數位交易器件中而實現介接。在其他實施例中,DTC及交易器件之介接可係藉由NFC,其中DTC及/或器件各具有用於通信之一收發器及天線。在又其他實施例中,DTC可包含一磁條,其中數位交易器件包含一磁條讀取器。在又其他實施例中,DAD可包含一收發器,其經組態用於與數位交易器件之通信,使得可視情況直接透過 DAD進行交易。 In embodiments, the DTC and the digital transaction device may interface with each other by various methods. In some embodiments, the interface may be achieved by inserting the DTC into the digital transaction device. In other embodiments, the interface between the DTC and the transaction device may be via NFC, wherein the DTC and/or the device each has a transceiver and antenna for communication. In still other embodiments, the DTC may include a magnetic stripe, wherein the digital transaction device includes a magnetic stripe reader. In still other embodiments, the DAD may include a transceiver configured for communication with the digital transaction device, allowing transactions to be conducted directly through the DAD as appropriate.
在實施例中,一DTC包含一可佩帶支付器件,其包含併入至若干珠寶件(諸如一戒指、手鐲及墜子)中之支付器件。DTC亦包含任何可植入支付器件,其包含亦可經適當組態用於皮下植入之晶片(DTPU)及收發器配置。 In an embodiment, a DTC includes a wearable payment device, which includes a payment device incorporated into a number of jewelry pieces (such as a ring, bracelet, and pendant). DTC also includes any implantable payment device, which includes a chip (DTPU) and transceiver configuration that can also be appropriately configured for subcutaneous implantation.
在其他實施例中,DAD可係一智慧型電話或其他適合器件,諸如經組態以操作為DAD之一鎖環或鑰鍊。在一些實施例中,DAD可係或可包含一可佩帶器件,諸如一手錶或其他珠寶件。在此點上,一些智慧型電話目前使用可佩帶手腕(或手錶式)器件進行操作。設想未來智慧型電話可完全併入至一可佩帶器件中,且DAD可係此一器件。在DAD包含搭配一可佩帶手腕(或手錶式)器件進行操作之一智慧型電話之境況下,應瞭解,可佩帶組件可具有其自身唯一ID,其可用於分別與針對一智慧型電話及DTC之唯一ID合作保護DAD與DTC之間之連結及資料傳送的安全。 In other embodiments, the DAD may be a smartphone or other suitable device, such as a lock or keychain configured to operate as a DAD. In some embodiments, the DAD may be or may include a wearable device, such as a watch or other piece of jewelry. In this regard, some smartphones currently operate using a wearable wrist (or watch-like) device. It is envisioned that in the future smartphones may be fully incorporated into a wearable device, and the DAD may be such a device. In the case where the DAD includes a smartphone that operates with a wearable wrist (or watch-like) device, it should be understood that the wearable component may have its own unique ID, which may be used to cooperate with the unique IDs for a smartphone and DTC, respectively, to secure the connection and data transmission between the DAD and the DTC.
在實施例中,各DAD可與多個DTC連結。然而,各DTC可僅連結至一個DAD而排除全部其他DAD。 In an embodiment, each DAD may be linked to multiple DTCs. However, each DTC may be linked to only one DAD to the exclusion of all other DADs.
在實施例中,可藉由使用DTC之一唯一ID及DAD之另一唯一ID而實施DTC與DAD之間之連結。在一些實施例中,DTC與DAD之連結可(至少部分)在將DTC發送至一使用者之前發生,舉例而言,連結可由一DTC發行者實施,包含一銀行、一卡(或DTC)發行設施、一卡(或DTC)「個人化」設施或能夠實施一「部分」連結之其他類型之第三方機構。在一個實例中,可藉由使DTC發行者設置DTC且提供準備好由一使用者下載至使用者之DAD(例如,一智慧型電話)之一應用程式而實施一部分連結,其中啟動應用程式將導致智慧型電話尋找且連結至發行至使用者之DTC。在 其他實施例中,連結可由使用者實施,且可在使用者接收DTC時發生。 In embodiments, the linking between the DTC and the DAD may be implemented by using a unique ID for the DTC and another unique ID for the DAD. In some embodiments, the linking of the DTC and the DAD may occur (at least partially) before the DTC is sent to a user, for example, the linking may be implemented by a DTC issuer, including a bank, a card (or DTC) issuing facility, a card (or DTC) "personalization" facility, or other types of third-party institutions that can implement a "partial" linking. In one example, a partial linking may be implemented by having the DTC issuer set up the DTC and provide an application ready to be downloaded by a user to the user's DAD (e.g., a smartphone), where activating the application will cause the smartphone to find and link to the DTC issued to the user. In other embodiments, linking may be implemented by the user and may occur when the user receives a DTC.
在一些實施例中,DTC與DAD之間之連結係永久的或半永久的,且無法在無來自(例如)前述第三方之一者之允許及所需動作之情況下解除連結或重新連結。舉例而言,為解除連結一DTC及唯一連結至該DTC之DAD,可在DAD上鍵入一唯一碼且將該唯一碼上傳至DTC。此將DTC重設至一預設狀態。在預設狀態中,DTC可「尋找」一不同DAD之一新指定唯一ID(例如,一智慧型電話之一IMEI號碼或另一適合唯一ID)。當使用者替換其DAD(諸如一智慧型電話)時,此解除連結/重新連結可係有用的。在又其他實施例中,連結可係暫時的且可由使用者執行。舉例而言,一使用者可在發生一預期交易之前之一短時間內形成一連結,且可在交易完成之後在交易之後之一預設短持續時間解除連結。 In some embodiments, the link between the DTC and the DAD is permanent or semi-permanent and cannot be unlinked or relinked without permission and required action from, for example, one of the aforementioned third parties. For example, to unlink a DTC and a DAD that is uniquely linked to the DTC, a unique code may be entered on the DAD and uploaded to the DTC. This resets the DTC to a default state. In the default state, the DTC may "find" a newly assigned unique ID for a different DAD (e.g., an IMEI number for a smartphone or another suitable unique ID). This unlinking/relinking may be useful when a user replaces their DAD (e.g., a smartphone). In yet other embodiments, the link may be temporary and may be performed by the user. For example, a user may form a link a short time before an expected transaction occurs, and may unlink after the transaction is completed, a preset short duration after the transaction.
在進一步實施例中,DTC可具有一磁條,且DAD可具有一磁條讀取器及/或寫入器。 In further embodiments, the DTC may have a magnetic stripe and the DAD may have a magnetic stripe reader and/or writer.
在再另一實施例中,DTC經組態以在任何特定時間僅儲存一個邏輯數位交易文件及(若干)關聯數位符記。在此點上,為了變更儲存在DTC上之邏輯數位交易文件,若當時存在體現於DTC中之一個邏輯數位交易文件,則一使用者必須複寫或刪除一先前儲存之邏輯數位交易文件及(若干)其關聯符記。 In yet another embodiment, the DTC is configured to store only one logical digital transaction file and associated digital token(s) at any given time. In this regard, in order to change a logical digital transaction file stored on the DTC, a user must overwrite or delete a previously stored logical digital transaction file and its associated token(s) if there is a logical digital transaction file embodied in the DTC at the time.
在另一實施例中,DTC可經組態以針對各文件同時儲存一個以上邏輯數位交易文件及(若干)關聯符記。 In another embodiment, the DTC may be configured to simultaneously store more than one logical digital transaction file and associated token(s) for each file.
在另一實施例中,DTC可經組態以儲存一主要邏輯數位交易文件及(若干)其關聯符記,以及一個副邏輯數位交易文件及(若干)其關聯符記。在再另一實施例中,DTC可經組態以儲存一個主要邏輯數位交易文件及 (若干)其關聯符記,以及一或多個副邏輯數位交易文件及各副邏輯數位交易文件之(若干)關聯符記。在一些實施例中,可將主要邏輯數位交易文件及(若干)其關聯符記永久儲存在DTC上,其中將一個或一或多個副邏輯數位交易文件及各副邏輯數位交易文件之(若干)關聯符記暫時儲存在DTC上。在又其他實施例中,可將一個或一或多個副邏輯數位交易文件及各副邏輯數位交易文件之(若干)關聯符記永久儲存在DTC上且由儲存在DAD上之一碼參照。 In another embodiment, the DTC may be configured to store a primary logical digital transaction file and (several) of its associated tokens, and a secondary logical digital transaction file and (several) of its associated tokens. In yet another embodiment, the DTC may be configured to store a primary logical digital transaction file and (several) of its associated tokens, and one or more secondary logical digital transaction files and (several) of the associated tokens of each secondary logical digital transaction file. In some embodiments, the primary logical digital transaction file and (several) of its associated tokens may be permanently stored on the DTC, wherein one or more secondary logical digital transaction files and (several) of the associated tokens of each secondary logical digital transaction file are temporarily stored on the DTC. In yet other embodiments, one or more sub-logical digital transaction files and (several) associated tokens of each sub-logical digital transaction file may be permanently stored on the DTC and referenced by a code stored on the DAD.
在其中DTC及DAD經動態連結(即,由使用者在一選擇時間連結)之一實施例中,來自DAD之所要邏輯數位交易文件之連結及選擇可按任何順序發生。 In an embodiment where the DTC and DAD are dynamically linked (i.e., linked by the user at a time of selection), the linking and selection of the desired logical digital transaction document from the DAD may occur in any order.
在實施例中,為了具有DTC與DAD之間之安全通信,可藉由連結DTC及DAD而實施安全性,或可針對DTC與DAD之間之資料傳輸實施安全性。在其他實施例中,可針對連結及資料傳輸兩者實施安全性。 In an embodiment, in order to have secure communication between the DTC and the DAD, security may be implemented by linking the DTC and the DAD, or security may be implemented for data transmission between the DTC and the DAD. In other embodiments, security may be implemented for both the link and the data transmission.
在又其他實施例中,DAD可包含一e錢包,其可經組態以搭配儲存在DAD上之邏輯數位交易文件及(若干)關聯符記之一或多者操作。在邏輯數位交易文件係一金融卡或一信用卡之情況下,此配置可用於補足資金。此外,DAD可包含允許一使用者即時觀察使用DTC(或藉由其他手段,諸如線上交易)完成之交易之功能性。此可允許使用者在一單一螢幕中或使用一單一智慧型電話應用程式監測由裝置(其可包含與DAD連結或可與DAD連結之複數個DTC)中之全部邏輯數位交易文件完成之全部交易。此外,可對使用者展示用於一交易之關聯數位符記。若使用者偵測或感知一或多個邏輯數位交易文件已被濫用或欺詐地使用,則此可進一步允許使用者取消、停止、暫停或以其他方式適當處置一或多個邏輯數位交易文件。系統 亦可經調適以允許使用者在一逐符記基礎上取消、停止、暫停或以其他方式適當處置一或多個邏輯數位交易文件,使得僅停用與一文件相關聯之特定符記,而仍可搭配其他關聯符記使用文件。若使用者企圖限制(例如)使用一或多個邏輯數位交易文件發生之花費或其他金融或非金融交易,則使用者亦可取消、停止、暫停或以其他方式適當處置一或多個邏輯數位交易文件。此亦可在一逐符記基礎上完成。 In yet other embodiments, the DAD may include an e-wallet that may be configured to operate with one or more of the logical digital transaction files and (several) associated tokens stored on the DAD. In the case where the logical digital transaction file is a debit card or a credit card, this configuration may be used to replenish funds. In addition, the DAD may include functionality that allows a user to observe transactions completed using DTCs (or by other means, such as online transactions) in real time. This may allow a user to monitor all transactions completed by all logical digital transaction files in a device (which may include multiple DTCs linked to the DAD or linkable to the DAD) in a single screen or using a single smartphone application. In addition, the associated digital tokens used for a transaction may be displayed to the user. This may further allow the user to cancel, stop, suspend or otherwise appropriately dispose of one or more logical digital transaction files if the user detects or perceives that one or more logical digital transaction files have been abused or used fraudulently. The system may also be adapted to allow the user to cancel, stop, suspend or otherwise appropriately dispose of one or more logical digital transaction files on a token-by-token basis, such that only a particular token associated with a file is disabled, while the file may still be used with other associated tokens. The user may also cancel, stop, suspend or otherwise appropriately dispose of one or more logical digital transaction files if the user seeks to limit, for example, spending or other financial or non-financial transactions that occur using one or more logical digital transaction files. This may also be done on a token-by-token basis.
在另一實施例中,當使用DTC進行一交易或一選擇類別或類型之交易時,DAD可經啓用以將警報發送至使用者。舉例而言,DAD可警告使用者一邏輯數位交易文件(諸如一護照)已在一機場用於識別。此外,可在一逐符記基礎上實施警報。在另一實例中,DAD可警告使用者一信用卡已用來購買不包含在由使用者選擇之一授權交易類別清單(諸如購買燃料及雜貨)中之貨物或服務(諸如乘坐出租車)。 In another embodiment, the DAD may be enabled to send alerts to the user when a transaction or a selected category or type of transaction is conducted using the DTC. For example, the DAD may alert the user that a logical digital transaction document (such as a passport) has been used for identification at an airport. Additionally, alerts may be implemented on a token-by-token basis. In another example, the DAD may alert the user that a credit card has been used to purchase goods or services (such as a taxi ride) that are not included in a list of authorized transaction categories selected by the user (such as fuel and groceries).
在其他實施例中,DAD及/或DTC可經組態以允許一使用者將交易分類。可由使用者預定義及/或定義類別。分類可經組態以便允許使用者監測及/或限制交易,諸如在該類別內之信用花費。一類別可能與僅一個(邏輯)數位交易文件相關,或可能與若干邏輯數位交易文件相關。符記亦可用於使用一個數位交易文件之交易之分類。 In other embodiments, the DAD and/or DTC may be configured to allow a user to categorize transactions. Categories may be predefined and/or defined by the user. Categories may be configured to allow the user to monitor and/or limit transactions, such as credit spending within the category. A category may be associated with only one (logical) digital transaction file, or may be associated with several logical digital transaction files. Tokens may also be used to categorize transactions using one digital transaction file.
在再另一實施例中,DAD可經組態以允許使用者將資金轉帳至具有一DAD之另一使用者。轉帳可限於相同或類似(邏輯)數位交易文件類型,且可在數量上受限。在一進一步實施例中,DTC可經組態以將資金轉帳至另一DTC(其由使用者擁有或另一使用者擁有),或至另一DAD(由使用者或另一使用者擁有)。 In yet another embodiment, a DAD may be configured to allow a user to transfer funds to another user with a DAD. Transfers may be limited to the same or similar (logical) digital transaction document type, and may be limited in quantity. In a further embodiment, a DTC may be configured to transfer funds to another DTC (owned by the user or another user), or to another DAD (owned by the user or another user).
此外,在另一實施例中,第三方(諸如金融機構、警察、海關、政 府、僱主、配偶、父母及其他有關方)可經授權且能夠取消、停止、暫停或以其他方式適當處置系統中之一或多個邏輯數位交易文件或與文件相關聯之(若干)所選擇符記。舉例而言,若一使用者具有一博弈成癮,且偏好具有一第三方監測且防止對信用卡、金融卡、銀行帳戶或其他種類之金融邏輯數位交易文件之存取以便防止使用者過度博弈,則此可係有用的。 Furthermore, in another embodiment, third parties (such as financial institutions, police, customs, government, employers, spouses, parents, and other interested parties) may be authorized and able to cancel, stop, suspend, or otherwise appropriately dispose of one or more logical digital transaction files or selected token(s) associated with the files in the system. This may be useful, for example, if a user has a gambling addiction and prefers to have a third party monitor and prevent access to credit cards, debit cards, bank accounts, or other types of financial logical digital transaction files in order to prevent the user from excessive gambling.
在其他實施例中,DAD可經組態以儲存表示附屬於一(邏輯)數位交易文件或複數個(邏輯)數位交易文件之忠誠點數(loyalty point)、飛行常客點數(frequent flyer point)或其他關聯交易相關文件之資料。DAD亦可經啓用以在一交易期間或之後或在其他時間更新忠誠點數、飛行常客點數及其他關聯交易相關文件。舉例而言,可在一交易期間使用忠誠點數以減少使用DTC及DAD購買之一物項之成本。若一使用者造訪一特定購物商店或在商店之一預定距離內,則DAD亦可經啓用以增加忠誠點數、飛行常客點數及其他關聯交易相關文件。 In other embodiments, the DAD may be configured to store data representing loyalty points, frequent flyer points, or other associated transaction-related documents attached to a (logical) digital transaction document or multiple (logical) digital transaction documents. The DAD may also be enabled to update loyalty points, frequent flyer points, and other associated transaction-related documents during or after a transaction or at other times. For example, loyalty points may be used during a transaction to reduce the cost of an item purchased using DTC and DAD. The DAD may also be enabled to increase loyalty points, frequent flyer points, and other associated transaction-related documents if a user visits a specific shopping store or is within a predetermined distance of a store.
在再另一實施例中,若DTC包含(例如)永久儲存在DTC上之一主要邏輯數位交易文件,則主要邏輯數位交易文件可係一錯誤或偽造邏輯數位交易文件,使得自DTC(其中僅初級邏輯數位交易文件儲存在DTC上)複製之資料將對於任何數位交易無用。替代地,可由不完整、到期或全零之一唯一ID(諸如一歸零身份)表示主要邏輯數位交易文件。舉例而言,在主要數位交易文件係一信用卡之情況下,卡之PAN可為不完整、到期或全零。在此實施例中,僅儲存在DTC上之副邏輯數位交易文件將係真實的且當在DTC上體現為一數位交易文件時可用於一數位交易。此外,一副邏輯數位交易文件及(若干)其關聯數位符記可儲存或體現為DTC上之一符記化數位交易文件僅達一短時期(例如,五分鐘),以便減少表示邏輯數位交易文件 及符記之資料之盜用之風險。此配置減少一未經授權使用者可仿真關聯數位交易文件及符記之風險。替代地,儲存在DTC上之主要邏輯數位交易文件可包括不完整資料,致使DTC不可用於數位交易直至一使用者下載副資料且將副資料保存至DTC(以及關聯符記資料),以致使主要邏輯數位交易文件完整且可用於數位交易。 In yet another embodiment, if the DTC includes a primary logical digital transaction file that is, for example, permanently stored on the DTC, the primary logical digital transaction file may be a faulty or forged logical digital transaction file such that data copied from the DTC (where only the primary logical digital transaction file is stored on the DTC) will be useless for any digital transaction. Alternatively, the primary logical digital transaction file may be represented by a unique ID (such as a zeroed identity) that is incomplete, expired, or all zeros. For example, where the primary digital transaction file is a credit card, the card's PAN may be incomplete, expired, or all zeros. In this embodiment, only the secondary logical digital transaction file stored on the DTC will be authentic and can be used in a digital transaction when embodied as a digital transaction file on the DTC. In addition, a secondary logical digital transaction file and (some) of its associated digital tokens may be stored or embodied as a tokenized digital transaction file on the DTC for only a short period of time (e.g., five minutes) in order to reduce the risk of theft of the data representing the logical digital transaction file and the token. This configuration reduces the risk that an unauthorized user can simulate the associated digital transaction file and token. Alternatively, the primary logical digital transaction file stored on the DTC may include incomplete data, rendering the DTC unusable for digital transactions until a user downloads the secondary data and saves the secondary data to the DTC (and associated token data) to render the primary logical digital transaction file complete and usable for digital transactions.
在再另一實施例中,儲存在DAD上之各邏輯數位交易文件或邏輯數位交易文件之各子集可具有與其相關聯之一個人識別號碼(PIN)。PIN可為一靜態PIN,或可為一動態產生之PIN。在其他實施例中,PIN可顯示於DAD之使用者介面上。可藉由安全方法存取PIN以使其顯示於DAD之螢幕上,諸如手指滑動或諸如通常在智慧型電話上實施之其他此等安全性方法。在另一實施例中,DAD可經組態以允許使用者更新用於一特定邏輯數位交易文件或若干邏輯數位交易文件之一PIN。在實施例中,PIN亦可與一文件之特定符記相關聯,使得文件之各符記具有一不同PIN。 In yet another embodiment, each logical digital transaction file or each subset of logical digital transaction files stored on the DAD may have a personal identification number (PIN) associated therewith. The PIN may be a static PIN, or may be a dynamically generated PIN. In other embodiments, the PIN may be displayed on the user interface of the DAD. The PIN may be accessed by a secure method for display on the screen of the DAD, such as a finger swipe or other such security methods as are commonly implemented on smartphones. In another embodiment, the DAD may be configured to allow a user to update a PIN for a particular logical digital transaction file or several logical digital transaction files. In embodiments, the PIN may also be associated with a particular token of a file, such that each token of the file has a different PIN.
在實施例中,方法包含使經啟動之DTC搭配數位交易器件操作以執行數位交易。 In an embodiment, the method includes causing the activated DTC to operate in conjunction with a digital transaction device to perform digital transactions.
在一些實施例中,在將DTC發行至一使用者之前提供用於一主要邏輯數位交易文件之符記。可透過一安全網路將符記發送至DAD使得可在一交易時針對使用關聯邏輯數位交易文件(已在發行時儲存在DTC上)進行之一交易選擇一符記。替代地,與主要文件關聯之符記可在發行時載入至DTC上,其中在一交易時由DAD實現選擇。副邏輯數位交易文件可在發行DTC之後透過至DAD的一安全網路構件發行至使用者,且可連同關聯副文件發行各副文件之關聯數位符記。 In some embodiments, tokens for a primary logical digital transaction document are provided prior to issuing a DTC to a user. Tokens may be sent to the DAD via a secure network so that a token may be selected at a transaction for a transaction conducted using an associated logical digital transaction document (already stored on the DTC at the time of issuance). Alternatively, tokens associated with the primary document may be loaded onto the DTC at the time of issuance, with selection being effected by the DAD at the time of a transaction. Secondary logical digital transaction documents may be issued to users after the DTC is issued via a secure network component to the DAD, and the associated digital tokens of each secondary document may be issued along with the associated secondary documents.
在其他實施例中,可將符記發行至DTC以儲存在其上,其中在交易 時經由DAD選擇用於交易之一符記。 In other embodiments, tokens may be issued to a DTC for storage thereon, wherein at the time of a transaction one of the tokens is selected via the DAD for use in the transaction.
在再另一實施例中,符記可為一固定或可擴展集區,以一循環方式使用符記,其中按順序選擇下一符記。替代地,可自集區隨機地(或偽隨機地)選擇符記。在一進一步實施例中,符記可能只使用一次,其中在集區中之每一符記已經使用或到期時替換經使用或到期符記之一集區。亦可在每一符記經使用或到期之前補充符記集區,舉例而言,當集區中剩餘十個未使用或未到期之符記時,可警告使用者需要符記補充。將理解,單次使用之符記可改良一關聯數位交易文件及交易之安全性。 In yet another embodiment, tokens may be a fixed or expandable pool, with tokens used in a round-robin fashion, where the next token is selected in sequence. Alternatively, tokens may be randomly (or pseudo-randomly) selected from the pool. In a further embodiment, tokens may be used only once, where a pool of used or expired tokens is replaced as each token in the pool is used or expired. The pool of tokens may also be replenished before each token is used or expires, for example, when ten unused or unexpired tokens remain in the pool, the user may be alerted that a token replenishment is required. It will be appreciated that single-use tokens may improve the security of an associated digital transaction document and transaction.
在另一實施例中,使用者可選擇何時替換符記集區中之符記。在此實施例中,使用者可向一符記提供者請求一新集區或其等現有符記集區之一擴展。 In another embodiment, the user can choose when to replace tokens in a token pool. In this embodiment, the user can request a new pool or an extension of one of their existing token pools from a token provider.
在一進一步實施例中,一給定數位交易文件之一主要使用者可將符記指派至該文件之一副使用者。舉例而言,一主要信用卡持有人可將(若干)符記自一符記集區指派至該信用卡之一附屬持有人。此可用作將附屬信用卡使用者之花費控制為花費之限制、數量或類別之一方式。 In a further embodiment, a primary user of a given digital transaction file can assign tokens to a secondary user of the file. For example, a primary credit card holder can assign token(s) from a pool of tokens to a secondary holder of the credit card. This can be used as a way to control the spending of the secondary credit card user to limits, amounts, or categories of spending.
在又其他實施例中,在符記經指派僅用於某些交易類型之情況下,一第三方(諸如一符記發行者、政府機構或符記使用之其他控制者)有權允許僅針對所選擇交易類型發行符記。在一個實例中,控制符記之發行之權力可僅允許針對用於非博弈支出之一信用卡發行符記。 In still other embodiments, where tokens are designated for use only in certain transaction types, a third party (such as a token issuer, government agency, or other controller of token use) has the authority to allow tokens to be issued only for selected transaction types. In one example, the authority to control the issuance of tokens may only allow tokens to be issued for a credit card used for non-gaming expenditures.
在一些實施例中,符記僅由將符記發行至使用者之一第三方提供者產生。在其他實施例中,符記亦可由另一第三方提供者發行。替代地,在一實施例中,符記可由使用者(例如)藉由DAD在本端產生。本端產生之符記可安全地複製至一第三方以在一交易期間匹配以藉此授權交易。可使用 以下之一或多者產生符記作為一密碼:關聯文件之唯一ID、到期日、DAD之唯一ID、時間、日期、位置及各種其他隨機、偽隨機或非隨機輸入。 In some embodiments, the token is generated only by a third party provider who issues the token to the user. In other embodiments, the token may also be issued by another third party provider. Alternatively, in one embodiment, the token may be generated locally by the user (for example, via DAD). The locally generated token may be securely copied to a third party for matching during a transaction to thereby authorize the transaction. The token may be generated as a password using one or more of the following: unique ID of the associated document, expiration date, unique ID of DAD, time, date, location, and various other random, pseudo-random, or non-random inputs.
熟習相關技術的讀者將理解,在本發明之實施例中,包含且需要用於一數位交易之一資料輔助器件(DAD)及一數位交易卡(DTC)兩者之數位交易裝置為數位交易提供一多因素驗證(包含授權、鑑認及授權與鑑認兩者),因素係使用者(例如,企圖使用一金融數位交易為貨物及/或服務付款的人)需要兩個物項(即,DAD及DTC及亦關於如何使用該兩個物項實現一交易之知識)。因此,若一人在企圖進行一數位交易時具有一DAD及一DTC兩者,則顯著減小此人藉由欺詐、盜用或騙術獲得兩個物項之可能性。舉例而言,若DAD係一智慧型電話,則在與單獨盜竊如目前用來進行數位交易之一合法信用卡相比時,企圖進行一欺詐交易之一人將能夠盜用一合法DTC及擁有者之智慧型電話係不可能的。此外,若企圖進行一欺詐交易之人設法竊取一合法DTC,則該人將極難以仿真或欺騙DTC擁有者之智慧型電話,包含搭配DTC操作以進行一數位交易之任何必要額外硬體及軟體。 Readers familiar with the relevant technology will understand that in embodiments of the present invention, a digital transaction device that includes and requires both a data-assisted device (DAD) and a digital transaction card (DTC) for a digital transaction provides a multi-factor authentication (including authorization, authentication, and both authorization and authentication) for digital transactions, the factor being that a user (e.g., a person attempting to use a financial digital transaction to pay for goods and/or services) requires two items (i.e., DAD and DTC and also knowledge of how to use the two items to effect a transaction). Therefore, if a person has both a DAD and a DTC when attempting to conduct a digital transaction, the possibility of the person obtaining the two items by fraud, theft, or deception is significantly reduced. For example, if the DAD is a smart phone, then a person attempting to conduct a fraudulent transaction would be able to steal a legitimate DTC and the owner's smart phone would be impossible compared to the sole theft of a legitimate credit card such as one currently used to conduct digital transactions. Additionally, if someone attempting to conduct a fraudulent transaction manages to steal a legitimate DTC, it would be extremely difficult for that person to emulate or spoof the DTC owner's smartphone, including any additional hardware and software necessary to operate the DTC to conduct a digital transaction.
在實施例中,DAD及DTC可操作以在其間傳送資料,其可進一步輔助減小欺詐數位交易之發生率。舉例而言,可使用DAD在各及每一交易之前將一一次性PIN(OTP)傳輸至DTC,OTP在一數位交易期間由一數位交易系統器件請求且需要由使用者鍵入PIN以完成交易。在任何情況下,預期在DAD與DTC之間傳送資料將輔助使用者管理並監測其等數位交易。 In an embodiment, the DAD and DTC are operable to transmit data therebetween, which may further assist in reducing the incidence of fraudulent digital transactions. For example, the DAD may be used to transmit a one-time PIN (OTP) to the DTC prior to each and every transaction, the OTP being requested by a digital transaction system device during a digital transaction and requiring the user to enter the PIN to complete the transaction. In any case, it is expected that transmitting data between the DAD and the DTC will assist users in managing and monitoring their digital transactions.
在一些實施例中,DTPU係一EMV器件,或符合一或多個EMVCo規 範之一器件。在其他實施例中,DTPU係一EMV器件(以其他方式符合一或多個EMVCo規範),其經建構以為了建立其中安裝DTPU之卡之特質之目的而讀取一安全儲存區域(暫存記憶體/暫存區域)。安全儲存區域或暫存記憶體可在經建構EMV器件內、在經建構EMV器件儲存區域(記憶體)內,或在某一其他安全記憶體內。 In some embodiments, the DTPU is an EMV device, or a device that complies with one or more EMVCo specifications. In other embodiments, the DTPU is an EMV device (otherwise compliant with one or more EMVCo specifications) that is constructed to read a secure storage area (scratch memory/scratch memory area) for the purpose of establishing the characteristics of the card in which the DTPU is installed. The secure storage area or scratch memory may be within the constructed EMV device, within the constructed EMV device storage area (memory), or within some other secure memory.
在實施例中,DTPU之CPU及/或在DTPU外部但駐存在DTC內之一CPU(稱為一外部DTC處理器)僅在CPU或外部CPU對一經連結DAD(諸如一智慧型電話)安全地識別其自身之後啟動。在一些實施例中,DAD(例如,一智慧型電話)與DTC之間之連結針對ID及資料之傳送使用強加密。連結可能對於各集合(智慧型電話及DTC)唯一。 In embodiments, the CPU of the DTPU and/or a CPU external to the DTPU but residing within the DTC (referred to as an external DTC processor) is activated only after the CPU or external CPU securely identifies itself to a connected DAD (such as a smartphone). In some embodiments, the link between the DAD (e.g., a smartphone) and the DTC uses strong encryption for the transmission of IDs and data. The link may be unique to each set (smartphone and DTC).
在實施例中,DAD與DTC之間之連結係無線的,且可使用DAD及DTC之各自收發器形成。在又其他實施例中,DTC可使用一實體連接件(諸如一資料纜線)與DAD連結(即,可操作以建立通信)。在此等實施例中,資料纜線可經調適以在一端部處插入於DAD上之一通信埠(諸如一USB埠)中,其中另一端部經調適以夾箝或夾持在DTC之一部分上。DTC可具有處於或朝向其一邊緣之電極或金屬板以在將資料纜線之另一端部夾箝或夾持至DTC時與電纜連接。在一些實施例中,用於DAD及DTC之各自收發器可適於BluetoothTM、Low Energy BluetoothTM、Wi-Fi、NFC、ANT+或其他類型之非接觸式或無線通信收發器。在實施例中,DTC可包含一按鈕或一類似器件以啟動與DAD之連結。 In embodiments, the connection between the DAD and the DTC is wireless and may be formed using respective transceivers of the DAD and the DTC. In still other embodiments, the DTC may be connected (i.e., operable to establish communication) with the DAD using a physical connector, such as a data cable. In such embodiments, the data cable may be adapted to be plugged into a communication port (such as a USB port) on the DAD at one end, with the other end adapted to be clamped or clipped onto a portion of the DTC. The DTC may have an electrode or metal plate at or toward one of its edges to connect with the cable when the other end of the data cable is clamped or clipped to the DTC. In some embodiments, the respective transceivers for the DAD and DTC may be adapted for Bluetooth ™ , Low Energy Bluetooth ™ , Wi-Fi, NFC, ANT+ or other types of contactless or wireless communication transceivers. In embodiments, the DTC may include a button or similar device to activate the connection with the DAD.
在各項實施例中,DAD可操作以在未形成DAD與DTC之間之一直接連結之情況下將資料傳送至DTC。在此等實施例中,DAD用於(例如)經由網際網路將資料傳送至一(雲端)連接之第三方器件。用於資料傳送之DAD 與第三方器件之間之一連結可為暫時的,且一旦已完全傳送資料,便可終止該連結。第三方器件連接(例如)至一網路(或許經由另一第三方,諸如一支付處理器),網路使第三方器件能夠繼與網路形成一連結之後,與一數位交易系統器件(諸如一銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機或自動提款機(ATM))形成一連結並通信,且因此連接至數位交易系統器件。啓用第三方器件以將先前自DAD接收之資料傳送至數位交易系統器件。一DTC之一持有人(其可為不同於DAD之擁有者及/或操作者之一人)可將DTC帶至數位交易器件,且藉由插入或將DTC放置在器件附近,DTC持有人可自數位交易系統器件獲得資料。以此方式,來自DAD之資料可間接且非同步地傳送至DTC。亦可顛倒DAD與DTC之間之此間接資料傳遞,使得DTC或許使用數位交易系統器件之相同基礎設施以將資料間接且非同步地傳送至DAD,網路包含支付處理器、第三方器件及網際網路。將理解,間接且非同步資料傳送在一第一人具有一DAD且希望將資料發送至受地理上遠離第一人之一第二人之控制的一DTC之情況下可係有用的。舉例而言,操作其DAD之母親可偏好增加由正在一外國旅行之其兒子操作之一DTC之花費限制。 In various embodiments, the DAD is operable to transfer data to the DTC without forming a direct link between the DAD and the DTC. In these embodiments, the DAD is used to transfer data to a (cloud) connected third party device via the Internet, for example. A link between the DAD and the third party device used for data transfer may be temporary and may be terminated once the data has been fully transferred. The third party device is connected, for example, to a network (perhaps via another third party, such as a payment processor), which enables the third party device, subsequent to forming a link with the network, to form a link and communicate with a digital transaction system device (such as a point of sale/electronic fund transfer system (POS/EFTPOS) terminal or automated teller machine (ATM)), and thereby connect to the digital transaction system device. The third party device is enabled to transmit data previously received from the DAD to the digital transaction system device. A holder of a DTC (who may be a person different from the owner and/or operator of the DAD) may bring the DTC to the digital transaction device, and by inserting or placing the DTC near the device, the DTC holder may obtain data from the digital transaction system device. In this way, data from the DAD may be transmitted to the DTC indirectly and asynchronously. This indirect data transfer between the DAD and the DTC may also be reversed, such that the DTC may use the same infrastructure of digital transaction system devices to indirectly and asynchronously transfer data to the DAD, the network including payment processors, third-party devices and the Internet. It will be appreciated that indirect and asynchronous data transfer may be useful in situations where a first person has a DAD and wishes to send data to a DTC controlled by a second person who is geographically remote from the first person. For example, a mother operating her DAD may prefer to increase the spending limit of a DTC operated by her son who is traveling in a foreign country.
在實施例中,外部DTC CPU控制DTPU(例如,一EMV器件)之讀取及重新讀取,及更新DTPU之記憶體內容。 In an embodiment, an external DTC CPU controls the reading and re-reading of a DTPU (e.g., an EMV device), and updates the memory contents of the DTPU.
在實施例中,可藉由使用DTC之一唯一ID及DAD之另一唯一ID而實施DTC與DAD之間之連結。在一些實施例中,DTC與DAD之連結可(至少部分)在將DTC發送至一使用者之前發生。舉例而言,連結可由一DTC發行者實施,包含一銀行、一卡發行設施、一卡「個人化」設施或能夠實施一「部分」連結之其他類型之第三方機構。在一個實例中,可藉由DTC發 行者建立DTC且提供準備好由一使用者下載至使用者之DAD(例如,一智慧型電話)之一應用程式而實施一部分連結,其中啟動應用程式導致智慧型電話搜尋且連結至發行至使用者之DTC。在其他實施例中,連結可由使用者實施,且可在使用者接收DTC時發生。 In embodiments, the link between the DTC and the DAD may be implemented by using a unique ID for the DTC and another unique ID for the DAD. In some embodiments, the linking of the DTC and the DAD may occur (at least in part) before the DTC is sent to a user. For example, the linking may be implemented by a DTC issuer, including a bank, a card issuing facility, a card "personalization" facility, or other types of third-party institutions capable of implementing a "partial" link. In one example, a partial linking may be implemented by the DTC issuer creating the DTC and providing an application ready to be downloaded by a user to the user's DAD (e.g., a smartphone), where activating the application causes the smartphone to search for and link to the DTC issued to the user. In other embodiments, the linking may be implemented by the user and may occur when the user receives the DTC.
在一些實施例中,DTC與DAD之間之連結係永久的或半永久的,且無法在無來自(例如)前述第三方之一者之允許及所需動作之情況下解除連結或重新連結。舉例而言,為解除連結一DTC及唯一連結至該DTC之DAD,可在DAD上鍵入一唯一碼且將該唯一碼上傳至DTC。此將DTC重設至一預設狀態。在預設狀態中,DTC可「尋找」一不同DAD之一新指定唯一識別符(例如,一智慧型電話之一IMEI號碼或另一適合唯一ID)。當使用者替換其DAD(諸如一智慧型電話)時,此解除連結/重新連結可係有用的。在又其他實施例中,連結可係暫時的,且由使用者執行。舉例而言,一使用者可在一預期交易發生之前之一短時間內形成一連結,且可在交易完成之後且在交易之後之一預定義短持續時間解除連結。 In some embodiments, the link between the DTC and the DAD is permanent or semi-permanent and cannot be unlinked or relinked without permission and required action from, for example, one of the aforementioned third parties. For example, to unlink a DTC and a DAD that is uniquely linked to the DTC, a unique code may be entered on the DAD and uploaded to the DTC. This resets the DTC to a default state. In the default state, the DTC may "look for" a newly assigned unique identifier for a different DAD (e.g., an IMEI number for a smartphone or another suitable unique ID). This unlinking/relinking may be useful when a user replaces their DAD (e.g., a smartphone). In yet other embodiments, the link may be temporary and performed by the user. For example, a user may form a link a short time before an expected transaction occurs, and may unlink after the transaction is completed and a predefined short duration after the transaction.
在其中DTC及DAD經動態連結(即,由使用者在一選擇時間連結)之一實施例中,來自DAD之所要LDTDP之連結及選擇可按任何順序發生。 In an embodiment where the DTC and DAD are dynamically linked (i.e., linked by the user at a time of choice), the linking and selection of the desired LDTDP from the DAD may occur in any order.
在實施例中,為了具有DTC與DAD之間之安全通信,可藉由連結交易卡及DAD而實施安全性,或可針對交易卡與DAD之間之資料傳輸實施安全性。在其他實施例中,可針對連結及資料傳輸兩者實施安全性。 In embodiments, in order to have secure communication between the DTC and the DAD, security may be implemented by linking the transaction card and the DAD, or security may be implemented for data transmission between the transaction card and the DAD. In other embodiments, security may be implemented for both the link and the data transmission.
在各項實施例中,數位交易器件可包含POS/EFTPOS終端機、ATM、網際網路連接電腦或個人電腦,及其他此等電子器件。數位交易器件亦可包含基礎設施,諸如經啟用用於郵件訂單/電話訂單(MOTO)類型交易之一電話及呼叫中心。 In various embodiments, the digital transaction device may include a POS/EFTPOS terminal, an ATM, an Internet-connected computer or personal computer, and other such electronic devices. The digital transaction device may also include infrastructure such as a telephone and call center enabled for mail order/telephone order (MOTO) type transactions.
在實施例中,DTC及數位交易器件可藉由各種方法彼此介接。在一些實施例中,可藉由將DTC插入至數位交易器件中而實現介接。在其他實施例中,可藉由近場通信(NFC)實現交易卡與交易器件之間之介接,其中卡及/或器件各具有一收發器及天線用於通信。在又其他實施例中,DTC可包含一磁條,其中數位交易器件包含一磁條讀取器。在又其他實施例中,DAD可包含一收發器,其經組態用於與數位交易器件之通信,使得可視情況直接透過DAD進行交易。在又其他實施例中,DTC經組態以插入至一POS/EFTPOS終端機或一ATM中,且近似與一信用卡/金融卡大小相同。 In embodiments, the DTC and the digital transaction device may interface with each other by various methods. In some embodiments, the interface may be achieved by inserting the DTC into the digital transaction device. In other embodiments, the interface between the transaction card and the transaction device may be achieved by near field communication (NFC), wherein the card and/or the device each has a transceiver and antenna for communication. In still other embodiments, the DTC may include a magnetic stripe, wherein the digital transaction device includes a magnetic stripe reader. In still other embodiments, the DAD may include a transceiver configured for communication with the digital transaction device, so that transactions can be conducted directly through the DAD as appropriate. In still other embodiments, the DTC is configured to be inserted into a POS/EFTPOS terminal or an ATM and is approximately the same size as a credit/debit card.
在進一步實施例中,DTC可具有一磁條,且DAD可具有一磁條讀取器及/或寫入器。 In further embodiments, the DTC may have a magnetic stripe and the DAD may have a magnetic stripe reader and/or writer.
在再另一實施例中,DAD可經組態以允許使用者將資金轉帳至具有一DAD之另一使用者。轉帳可限於相同或類似LDTDP及關聯(邏輯)數位交易文件類型,且可在數量上受限。在一進一步實施例中,DTC可經組態以將資金轉帳至另一DTC(由使用者擁有或由另一使用者擁有),或至另一DAD(由使用者或另一使用者擁有)。 In yet another embodiment, a DAD may be configured to allow a user to transfer funds to another user with a DAD. Transfers may be limited to the same or similar LDTDP and associated (logical) digital transaction document types, and may be limited in quantity. In a further embodiment, a DTC may be configured to transfer funds to another DTC (owned by the user or owned by another user), or to another DAD (owned by the user or another user).
此外,在另一實施例中,第三方(諸如金融機構、警察、海關、政府、僱主、配偶、父母及其他有關方)可經授權且能夠取消、停止、暫停或以其他方式適當地處置(包含暫時停權)含有裝置中之邏輯數位交易文件或與文件相關聯之(若干)所選擇符記之一或多個LDTDP。舉例而言,若一使用者具有一博弈成癮,且偏好具有一第三方監測且防止對信用卡、金融卡、銀行帳戶或其他種類之金融邏輯數位交易文件之存取以便防止使用者過度博弈,則此可係有用的。在一邏輯數位交易文件之一嘗試欺詐交易及 取消/重新發行之例項中,可向使用者提供警報,用以建議取消一文件及一替換文件之可用性以供針對收集/下載至一使用者之DAD及後續使用以使用採用最新發行(替換)文件之特質之一DTC實現一交易。 Furthermore, in another embodiment, a third party (such as a financial institution, police, customs, government, employer, spouse, parent, and other interested parties) may be authorized and able to cancel, stop, suspend, or otherwise appropriately dispose of (including temporarily suspending) one or more LDTDPs containing a logical digital transaction file in a device or selected token(s) associated with the file. This may be useful, for example, if a user has a gambling addiction and prefers to have a third party monitor and prevent access to credit cards, debit cards, bank accounts, or other types of financial logical digital transaction files in order to prevent the user from excessive gambling. In the instance of an attempted fraudulent transaction and cancellation/reissue of a logical digital transaction file, an alert may be provided to the user advising the cancellation of a file and the availability of a replacement file for collection/download to a user's DAD and subsequent use to effectuate a transaction using a DTC employing the characteristics of the most recently issued (replacement) file.
在一實施例中,方法包含使經啟動之DTC搭配數位交易器件操作以執行數位交易。 In one embodiment, the method includes causing an activated DTC to operate in conjunction with a digital transaction device to perform digital transactions.
儘管熟習相關技術者在閱讀說明書後旋即明白各種安全性及便利性益處,然而使用根據本發明之實施例之一或多個配置,迄今為止尚不存在用於調適一DTPU(諸如一EMVCo指定器件)以體現相較於最初安裝之DTPU之特質之不同特質之一足夠有效、高效率及/或安全手段及/或方法。 Although the various security and convenience benefits are immediately apparent to those skilled in the relevant art upon reading the specification, there has heretofore not been a sufficiently effective, efficient and/or secure means and/or method for adapting a DTPU (such as an EMVCo specified device) to exhibit different characteristics than those of the originally installed DTPU using one or more configurations according to the embodiments of the present invention.
儘管對一認證EMV器件之基本操作韌體之一修改導致器件丟失其認證憑證,然仍可使用對一現有認證EMV器件之一韌體修改實施本發明之一實施例。當然,一旦已修改韌體,便在可使用器件之前需要具有經修改韌體之器件之重新認證。 Although a modification to the basic operating firmware of a certified EMV device causes the device to lose its certification credentials, an embodiment of the present invention may still be implemented using a firmware modification to an existing certified EMV device. Of course, once the firmware has been modified, re-certification of the device with the modified firmware is required before the device can be used.
在此實施例中,一現有EMV器件之韌體經修改以使EMV器件能夠接收且執行來自一外部網路交易器件(諸如一ATM或EFTPOS器件(或起始一網路交易器件之一器件))之一增加命令集合,其使EMV器件之安全記憶體能夠被修改。 In this embodiment, the firmware of an existing EMV device is modified to enable the EMV device to receive and execute an added command set from an external network transaction device (such as an ATM or EFTPOS device (or a device that initiates a network transaction device)) that enables the secure memory of the EMV device to be modified.
16A:銷售點電子轉帳系統(POS/EFTPOS)終端機 16A: Point of Sale Electronic Funds Transfer System (POS/EFTPOS) terminal
16B:線上交易終端機 16B: Online transaction terminal
18:邏輯數位交易文件/額外信用卡/額外卡 18: Logical digital transaction documents/additional credit cards/additional cards
30:智慧型電話介面 30: Smart phone interface
100:裝置 100:Device
102:數位交易器件/銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機/商家終端機 102: Digital transaction device/point of sale/electronic fund transfer system (POS/EFTPOS) terminal/merchant terminal
104:數位交易處理單元(DTPU) 104: Digital Transaction Processing Unit (DTPU)
106:智慧型電話/資料輔助器件(DAD) 106: Smartphone/Data Assisted Device (DAD)
108:數位交易卡(DTC) 108: Digital Transaction Card (DTC)
110:使用者介面 110: User Interface
112:電極/外部接觸板 112: Electrode/external contact plate
114:數位交易卡(DTC)收發器 114: Digital Transaction Card (DTC) transceiver
116:智慧型電話收發器 116: Smart phone transceiver
200:實體卡/數位交易卡(DTC) 200: Physical card/digital transaction card (DTC)
202:使用者介面 202: User Interface
204:智慧型電話 204: Smartphone
206:VISA卡/數位交易卡(DTC) 206: VISA card/digital transaction card (DTC)
208:萬事達卡/數位交易卡(DTC) 208: MasterCard/Digital Transaction Card (DTC)
210:歸零特質數位交易卡(DTC) 210: Zero Characteristic Digital Trading Card (DTC)
300:可佩帶器件 300: Wearable devices
302:智慧型電話 302: Smartphone
304:商家終端機 304: Merchant terminal
306:戒指 306: Ring
308:智慧型電話外殼 308: Smartphone case
310:EMV器件 310:EMV devices
312:選用印刷識別 312: Select Printing Identification
314:最上部數位交易卡(DTC) 314: Top Digital Transaction Card (DTC)
316:第二數位交易卡(DTC) 316: Second Digital Transaction Card (DTC)
318:第三數位交易卡(DTC) 318: Digital Transaction Card (DTC)
320:顯示器 320: Display
322:第四數位交易卡(DTC) 322: Fourth Digital Transaction Card (DTC)
324:顯示器 324: Display
326:捲動鍵/歸位鍵 326: Scroll key/return key
402:個人化公司 402: Personalized company
404:數位交易卡(DTC)積分器 404: Digital Transaction Card (DTC) Integrator
406:數位交易卡(DTC)製造商 406: Digital Transaction Card (DTC) Manufacturer
408:安全性供應者 408: Security Provider
412:數位交易卡(DTC) 412: Digital Transaction Card (DTC)
414:資料輔助器件(DAD)/智慧型電話 414: Data Assisted Device (DAD)/Smart Phone
415:連結/連結程序 415: Link/Link Process
419:主要數位交易文件 419: Main digital transaction documents
420:使用者 420: User
422:EMV晶片/數位交易處理單元(DTPU) 422: EMV chip/digital transaction processing unit (DTPU)
423:按鈕 423:Button
424:數位交易卡(DTC)顯示器 424: Digital Transaction Card (DTC) Display
428:顯示器/數位交易卡(DTC)名稱空間 428: Display/Digital Transaction Card (DTC) Namespace
430:智慧型電話介面/螢幕 430: Smartphone interface/screen
440:發行金融機構 440: Issuing financial institution
442:安全性請求者/符記請求者 442: Security Requester/Token Requester
444:種子 444:Seeds
446:客戶服務 446:Customer Service
502:金融機構 502: Financial institutions
503:IMEI號碼/唯一ID 503:IMEI number/unique ID
504:安全性請求者/符記請求者 504: Security Requester/Token Requester
505:提供 505: Provided
508:客戶服務 508:Customer Service
510:金鑰 510:Key
512:數位交易卡(DTC) 512: Digital Transaction Card (DTC)
514:資料輔助器件(DAD)/智慧型電話 514: Data Assisted Device (DAD)/Smart Phone
520:使用者 520: User
524:數位交易卡(DTC)顯示器 524: Digital Transaction Card (DTC) Display
526:唯一ID 526: Unique ID
534:金融機構查找區段 534:Financial institution search section
536:計數器 536:Counter
538:種子/秘密金鑰 538: Seed/Secret Key
540:應用程式連結 540: Application link
544:帶外(OOB)通知 544: Out-of-band (OOB) notification
554:網際網路下載 554: Internet download
556:雲端 556: Cloud
602:個人化公司 602: Personalized company
604:數位交易卡(DTC)積分器 604: Digital Transaction Card (DTC) Integrator
606:非接觸式數位交易卡(DTC)製造商 606:Contactless Digital Transaction Card (DTC) Manufacturer
608:安全性供應者 608: Security Provider
610:發行金融機構 610: Issuing financial institutions
611:安全性請求者/符記請求者 611: Security Requester/Token Requester
612:數位交易卡(DTC) 612: Digital Transaction Card (DTC)
614:智慧型電話 614: Smartphone
616:種子 616:Seeds
618:客戶服務 618:Customer Service
620:使用者 620: User
640:應用程式 640: Application
702:主要卡發行金融機構 702:Major card issuing financial institutions
708:客戶服務區段 708: Customer Service Section
710:清單 710: List
712:數位交易卡(DTC) 712: Digital Transaction Card (DTC)
714:智慧型電話 714: Smartphone
716:副卡發行金融機構 716: Financial institution issuing supplementary card
720:使用者 720: User
806:符記供應者 806:Symbol Supplier
808:客戶服務區段 808: Customer Service Section
810:OOB(帶外) 810:OOB (out of band)
812:數位交易卡(DTC) 812: Digital Transaction Card (DTC)
814:智慧型電話 814: Smartphone
818:額外信用卡 818: Additional credit card
822:晶片 822: Chip
912:數位交易卡(DTC) 912: Digital Transaction Card (DTC)
950:舊智慧型電話 950: Old smartphone
952:新智慧型電話 952: New Smartphone
1002:第一螢幕 1002: First Screen
1004:「設置」標題 1004: "Settings" title
1006:「設置」按鈕 1006: "Settings" button
1012:數位交易卡(DTC) 1012: Digital Transaction Card (DTC)
1014:智慧型電話 1014: Smartphone
1020:使用者 1020: User
1023:連結按鈕 1023: Link button
1032:下一螢幕 1032: Next screen
1034:「狀態」標題 1034: "Status" title
1036:「申請碼」按鈕 1036: "Application code" button
1038:「金鑰」鍵入欄位 1038: "Key" key-in field
1040:「與卡配對」按鈕 1040: "Pair with card" button
1042:最後螢幕 1042: Final Screen
1044:「恭喜」訊息 1044: "Congratulations" message
1046:保持 1046:Keep
1104:主要卡標誌 1104: Main card logo
1106:全像 1106: Hologram
1108:主要卡到期日 1108: Primary card expiration date
1110:簽名 1110:Signature
1112:數位交易卡(DTC) 1112: Digital Transaction Card (DTC)
1112f:前側 1112f:Front side
1112r:背側 1112r: Dorsal side
1114:卡驗證值(CVV) 1114: Card Verification Value (CVV)
1119:主要卡 1119: Main card
1202:第一智慧型電話螢幕 1202: The first smart phone screen
1204:「PIN(個人識別號碼)」按鈕 1204: "PIN (Personal Identification Number)" button
1206:「滑動」按鈕 1206: "Slide" button
1208:「生物特徵」按鈕 1208: "Biological Characteristics" button
1210:下一螢幕/智慧型電話螢幕 1210: Next screen/smart phone screen
1211:「當前」標題 1211: "Current" title
1212:數位交易卡(DTC) 1212: Digital Transaction Card (DTC)
1213:「VISA」卡 1213:「VISA」card
1214:智慧型電話 1214: Smartphone
1215:「變更為」標題 1215: "Change to" title
1217:「萬事達卡」按鈕 1217: "MasterCard" button
1218:「銀行轉帳」按鈕 1218: "Bank transfer" button
1219:「美國運通」按鈕 1219: "American Express" button
1220:使用者 1220:User
1221:「大來卡」按鈕 1221: "Diners Club Card" button
1224:數位交易卡(DTC)圖形使用者介面(GUI)顯示器 1224: Digital Transaction Card (DTC) Graphical User Interface (GUI) Display
1234:「將萬事達卡設定為較佳支付方法」訊息 1234: "Set MasterCard as preferred payment method" message
1236:「是」按鈕 1236: "Yes" button
1238:「否」按鈕 1238: "No" button
1242:智慧型電話螢幕 1242: Smart phone screen
1244:「安全性」標題 1244: "Security" title
1246:「是」按鈕 1246: "Yes" button
1248:「否」按鈕 1248: "No" button
1252:智慧型電話螢幕 1252: Smart phone screen
1254:「狀態」標題 1254: "Status" title
1256:「生物特徵設定/不設定」指示符/「觸控卡」指令 1256: "Biometrics set/not set" indicator/"touch card" command
1258:「卡連結」指示符 1258: "Card Link" indicator
1260:新所選擇文件號碼/符記號碼 1260: New selected document number/symbol number
1262:螢幕 1262: Screen
1263:面板 1263: Panel
1264:「建立OTP」按鈕 1264: "Create OTP" button
1267:4個前導數字/標題「到期日」/到期日 1267: 4 leading digits/title "Expiration Date"/Expiration Date
1268:面板 1268: Panel
1269:卡驗證值(CW) 1269: Card verification value (CW)
1270:商家 1270: Merchants
1272:處理 1272: Processing
1274:有效信用卡發行金融機構 1274: Valid credit card issuing financial institution
1280:螢幕 1280: Screen
1282:「超出限制交易」訊息 1282: "Transaction limit exceeded" message
1284:「是」按鈕 1284: "Yes" button
1286:訊息 1286: Message
1288:「否」按鈕 1288: "No" button
1312:數位交易卡(DTC) 1312: Digital Transaction Card (DTC)
1316:商家銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機 1316: Merchant Point of Sale/EFTPOS Terminal
1318:商家收單機構 1318: Merchant acquiring institution
1320:使用者 1320:User
1321:信用卡號碼 1321: Credit card number
1324:數位交易卡(DTC)圖形使用者介面(GUI)顯示器 1324: Digital Transaction Card (DTC) Graphical User Interface (GUI) Display
1330:智慧型電話螢幕 1330: Smart phone screen
1332:卡軌 1332: Stuck track
1334:安全性供應者 1334: Security Provider
1336:主要卡發行金融機構 1336:Major card issuing financial institutions
1338:生物特徵技術 1338: Bio-characterization technology
1340:安全性保證資料 1340: Security assurance information
1342:網際網路 1342: Internet
1344:其他邏輯數位交易文件符記化唯一ID 1344:Other logical digital transaction files to mark unique ID
為了更好地理解本發明,且為展示可如何執行本發明,現在將僅藉由非限制實例且參考隨附圖式描述本發明之選用實施例,其中:圖1係根據本發明之一實施例之一裝置之一圖形表示,其包含一數位交易卡(DTC)之一實施例及呈一智慧型電話之形式之一資料輔助器件 (DAD)之一實施例,其中裝置用於與一數位交易器件(在此實例中,一銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機)之一交易;圖2A係根據一實施例之與圖1之DAD通信之一DTC之一圖形表示,其操作以藉由使用DAD、及源自選擇DAD上之所需特質的DTC之特質之選擇、及傳遞所選擇之特質至DTC而選擇一數位交易文件;圖2B係圖解說明藉由使用一DTC使用者介面選擇數位交易文件之一DTC之一圖形表示,在圖2B之實施例中,DTC使用者介面包含各種觸控啟動開關及一顯示器;圖3A、圖3B、圖3C及圖3D係分別呈一手錶、戒指、智慧型電話保護外殼及一信用卡本體之形式之一DTC之各項實施例之圖形表示,根據一最小可行產品實施例分別在無介面實施例及具有介面實施例之情況下描繪圖3D之信用卡本體;圖4係展示根據本發明之一實施例之一方法中之一系統及步驟之各種部分之一功能流程圖;圖5係展示根據本發明之一實施例之用於設置一數位交易卡(DTC)之方法中之系統及步驟之一功能流程圖;圖6係展示具有安全性之初始設置之一功能流程圖;圖7係展示將副邏輯數位交易文件增加至DTC之步驟之一功能流程圖;圖8係展示增加副邏輯數位交易文件之安全性之步驟之一功能流程圖;圖9係展示根據本發明之實施例之使一資料輔助器件(DAD)與一DTC連結之步驟之一功能流程圖; 圖10係根據本發明之一實施例中之一方法之一DAD中之一系列螢幕;圖11展示根據本發明之一實施例之一DTC;圖12A展示用於一實體卡交易之根據本發明之一實施例之一方法中之一DAD之螢幕;圖12B係用於一無卡交易之類似於圖12A之一視圖;圖13係展示根據本發明之一實施例之使用一DTC DAD支付之一實例之一功能流程圖。 In order to better understand the present invention and to show how it may be performed, selected embodiments of the present invention will now be described by way of non-limiting example only and with reference to the accompanying drawings, wherein: FIG. 1 is a graphical representation of a device according to an embodiment of the present invention, comprising an embodiment of a digital transaction card (DTC) and an embodiment of a data-assisted device (DAD) in the form of a smart phone, wherein the device is used for a transaction with a digital transaction device (in this example, a point of sale/electronic fund transfer system (POS/EFTPOS) terminal); FIG. 2A is a graphical representation of a device according to an embodiment communicating with the DAD of FIG. FIG. 2B is a graphical representation of a DTC for selecting a digital transaction document using a DAD, and selecting characteristics of the DTC derived from selecting the desired characteristics on the DAD, and transmitting the selected characteristics to the DTC; FIG. 2B is a graphical representation of a DTC for selecting a digital transaction document using a DTC user interface, in the embodiment of FIG. 2B, the DTC user interface includes various touch-activated switches and a display; FIGS. 3A, 3B, 3C and 3D are diagrams of various embodiments of a DTC in the form of a watch, a ring, a smartphone protective case and a credit card body, respectively. The graphic representation shows the credit card body of FIG. 3D according to a minimum viable product embodiment in the case of a non-interface embodiment and an interface embodiment; FIG. 4 is a functional flow chart showing various parts of a system and steps in a method according to an embodiment of the present invention; FIG. 5 is a functional flow chart showing a system and steps in a method for setting up a digital transaction card (DTC) according to an embodiment of the present invention; FIG. 6 is a functional flow chart showing an initial setting with security; FIG. 7 is a functional flow chart showing the step of adding a secondary logic digital transaction file to the DTC; FIG. 8 is a functional flow chart showing the step of adding a secondary logic digital transaction file to the DTC; FIG. 9 is a functional flow chart showing the steps of linking a data-assisted device (DAD) to a DTC according to an embodiment of the present invention; FIG. 10 is a series of screens in a DAD according to a method in an embodiment of the present invention; FIG. 11 shows a DTC according to an embodiment of the present invention; FIG. 12A shows a screen of a DAD in a method according to an embodiment of the present invention for a physical card transaction; FIG. 12B is a view similar to FIG. 12A for a card-not-present transaction; FIG. 13 is a functional flow chart showing an example of payment using a DTC DAD according to an embodiment of the present invention.
圖1詳述根據本發明之一實施例之一裝置(100)之主要組件,包含一數位交易卡(DTC)(108)、呈一智慧型電話(106)之形式之一資料輔助器件(DAD)及一數位交易器件(102),在此實例中,數位交易器件(102)係一銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機(102)。此等終端機(102)在本文中可稱為商家終端機,且可在一終端機收發器(未展示)與一DTC收發器(114)之間根據按照ISO/IEC 14443之一非接觸式近距離通信能力而與DTC(108)接合。終端機(102)亦可與一智慧型電話收發器(116)接合且根據ISO/IEC 14443通信協定而與其通信。終端機(102)亦可藉由實體接觸件而與DTC(108)接合或與DTC(108)上之一磁條接合。在展示之實施例中,終端機(102)需要將DTC(108)插入至該終端機(102)中以藉由實體接觸件接合。在圖1之實施例中,智慧型電話(106)藉由NFC而與DTC(108)無線地接合,而DTC(108)藉由根據ISO/IEC 14443(其係NFC通信格式之一子集)之通信而與終端機(102)無線地接合。 FIG1 details the major components of a device (100) according to an embodiment of the present invention, including a digital transaction card (DTC) (108), a data-assisted device (DAD) in the form of a smart phone (106), and a digital transaction device (102), which in this example is a point-of-sale/electronic fund transfer system (POS/EFTPOS) terminal (102). These terminals (102) may be referred to herein as merchant terminals, and may interface with the DTC (108) based on a contactless near-field communication capability in accordance with ISO/IEC 14443 between a terminal transceiver (not shown) and a DTC transceiver (114). The terminal (102) may also interface with a smartphone transceiver (116) and communicate therewith in accordance with the ISO/IEC 14443 communication protocol. The terminal (102) may also interface with the DTC (108) via physical contacts or with a magnetic strip on the DTC (108). In the embodiment shown, the terminal (102) requires the DTC (108) to be inserted into the terminal (102) for interface via physical contacts. In the embodiment of FIG. 1 , the smartphone (106) wirelessly interfaces with the DTC (108) via NFC, and the DTC (108) wirelessly interfaces with the terminal (102) by communicating in accordance with ISO/IEC 14443, which is a subset of the NFC communication format.
將理解,許多類型之智慧型器件或運算器件(諸如智慧型電話(106)) 無法與許多類型之POS/EFTPOS終端機(102)及自動提款機(ATM)互動。為完成與此等終端機之一交易,有必要使用一金融卡或信用卡。然而,金融卡或信用卡將各自具有一單一「特質」,或包括僅一單一數位交易文件之實體實施例。舉例而言,目前,一實體交易卡可僅具有一萬事達卡或一Visa卡之特質,而無法在不同時間選擇性地且連續地採用一萬事達卡及一Visa卡兩者之特質。 It will be appreciated that many types of intelligent devices or computing devices, such as smart phones (106), are not able to interact with many types of POS/EFTPOS terminals (102) and automated teller machines (ATMs). To complete a transaction with one of these terminals, it is necessary to use a debit or credit card. However, a debit or credit card will each have a single "identity," or physical embodiment that includes only a single digital transaction document. For example, currently, a physical transaction card may only have the identity of a MasterCard or a Visa card, and cannot selectively and continuously adopt the identity of both a MasterCard and a Visa card at different times.
在圖1中展示之實施例中,DTC(108)上之DTPU(104)係一EMV器件(其中EMV係Europay、萬事達卡及Visa(Europay,MasterCard,and Visa)之一縮寫),或遵守一或多個EMVCo規範之一器件,其已經調適以允許表達若干不同特質。此等當前DTPU或EMV器件可包含唯讀記憶體(ROM)、隨機存取記憶體(RAM)及/或電可擦除可程式化唯讀記憶體(EEPROM)。DTPU(104)可含有其他種類之記憶體,且DTPU(104)可包含用於控制DTPU(104)之操作之一中央處理單元(CPU)(104)。DTPU CPU可與處置加密及解密資料之任務之一密碼編譯協處理器合作工作,因此釋放DTPU CPU以執行其他處理任務。由DTPU(104)之一系統輸入/輸出(系統I/O)(108)實現DTPU(104)與DTC(108)之表面上之電極(112)之間之通信。 In the embodiment shown in FIG. 1 , the DTPU (104) on the DTC (108) is an EMV device (where EMV is an acronym for Europay, MasterCard, and Visa), or a device that complies with one or more EMVCo specifications that has been adapted to allow for the expression of several different features. These current DTPU or EMV devices may include read-only memory (ROM), random access memory (RAM), and/or electrically erasable programmable read-only memory (EEPROM). The DTPU (104) may contain other types of memory, and the DTPU (104) may include a central processing unit (CPU) (104) for controlling the operation of the DTPU (104). The DTPU CPU can work in conjunction with a cryptographic coprocessor that handles the task of encrypting and decrypting data, thereby freeing the DTPU CPU to perform other processing tasks. Communication between the DTPU (104) and the electrodes (112) on the surface of the DTC (108) is achieved by a system input/output (system I/O) (108) of the DTPU (104).
類似於一標準EMV器件,圖1中展示之實施例之DTPU(104)位於使用電極(112)用於外部通信之一塑膠信用卡本體中。然而,DTPU(104)亦可使用一無線收發器來與終端機(102)外部通信。 Similar to a standard EMV device, the DTPU (104) of the embodiment shown in FIG. 1 is located in a plastic credit card body using electrodes (112) for external communication. However, the DTPU (104) may also use a wireless transceiver to communicate externally with the terminal (102).
在其中修改一EMV器件之操作韌體之一實施例中,DTPU(104)EEPROM可被劃分成兩個記憶體區域。在一些實施例中,劃分可能藉由分割區(或虛擬分割區)、藉由使用一適合檔案結構,或藉由使用一適合目 錄結構。在此例示性實施例中,使用EEPROM之部分作為暫存記憶體(暫存區域)。在操作期間,暫存記憶體具有自LDTDP儲存記憶體寫入至其暫存記憶體中的至少一個邏輯數位交易文件封包(LDTDP)。使用EEPROM之另一部分作為安全記錄記憶體(安全元件)。在操作期間,至少一個LDTDP取自暫存記憶體,且寫入至安全元件中,在DTPU經啟動以讀取安全元件時由DTPU CPU存取該至少一個LDTDP。當DTPU CPU存取LDTDP時,DTPU(104)能夠採用由LDTDP表示之特質,使得DTC(108)可用於與該特質之交易。 In one embodiment in which the operating firmware of an EMV device is modified, the DTPU (104) EEPROM may be divided into two memory areas. In some embodiments, the division may be by partition (or virtual partition), by using a suitable file structure, or by using a suitable directory structure. In this exemplary embodiment, a portion of the EEPROM is used as a temporary memory (temporary area). During operation, the temporary memory has at least one logical digital transaction file package (LDTDP) written to its temporary memory from the LDTDP storage memory. Another portion of the EEPROM is used as a secure recording memory (secure element). During operation, at least one LDTDP is retrieved from the temporary memory and written to the secure element, and the at least one LDTDP is accessed by the DTPU CPU when the DTPU is activated to read the secure element. When the DTPU CPU accesses the LDTDP, the DTPU (104) is able to adopt the characteristic represented by the LDTDP so that the DTC (108) can be used for transactions with the characteristic.
在其他實施例中,代替使用劃分成兩個記憶體區域(暫存記憶體區域及安全記錄記憶體區域)之一單一EEPROM,可能具備各自含有一暫存記憶體及一安全記錄記憶體之一者之兩個分開之記憶體晶片。此等記憶體器件(或晶片)可在DTPU(104)中經組態以不具有直接連結,以便增加安全性,特別針對安全記錄記憶體,其應僅可由DTPU(104)中之某些指定元件(諸如DTPU CPU)直接存取。 In other embodiments, instead of using a single EEPROM divided into two memory areas (a temporary memory area and a secure recording memory area), there may be two separate memory chips each containing one of a temporary memory and a secure recording memory. These memory devices (or chips) can be configured in the DTPU (104) to have no direct connection in order to increase security, especially for the secure recording memory, which should only be directly accessible by certain designated components in the DTPU (104) (such as the DTPU CPU).
在DTC(108)中,根據本發明之一實施例,可能定位有與DTPU CPU不同且額外之一外部DTC CPU。可藉由控制DTPU CPU來控制DTPU(104)。外部DTC CPU及與其相關聯之韌體可允許資料(包含LDTDP)透過系統I/O傳遞至DTPU(104)。外部DTC CPU及韌體可經操作以指示DTPU CPU將資料(舉例而言,一或多個LDTDP)複製至暫存記憶體中。DTC CPU亦可經操作以指示DTPU CPU將暫存記憶體中之資料傳送至安全記錄記憶體。 In DTC (108), according to one embodiment of the present invention, an external DTC CPU different from and additional to the DTPU CPU may be located. The DTPU (104) may be controlled by controlling the DTPU CPU. The external DTC CPU and firmware associated therewith may allow data (including LDTDP) to be transferred to the DTPU (104) via system I/O. The external DTC CPU and firmware may be operated to instruct the DTPU CPU to copy data (for example, one or more LDTDPs) to a temporary memory. The DTC CPU may also be operated to instruct the DTPU CPU to transfer data in the temporary memory to a secure log memory.
含有LDTDP之資料可儲存在智慧型電話(106)中或本身在與DTPU(104)中之記憶體分離之一記憶體中之DTC(108)上之LDTDP儲存記憶體 中。圖1中描繪之配置允許LDTDP儲存在LDTDP儲存記憶體中,且自LDTDP儲存記憶體複製至暫存記憶體。自LDTDP儲存記憶體複製至暫存記憶體可受控於外部DTC CPU,外部DTC CPU繼而控制DTPU CPU之操作。外部DTC CPU之操作可受控於DAD(106),由一使用者經由使用者DAD使用者介面110操作DAD(106)。 Data containing the LDTDP may be stored in the smart phone (106) or in an LDTDP storage memory on the DTC (108) itself in a memory separate from the memory in the DTPU (104). The configuration depicted in FIG. 1 allows the LDTDP to be stored in the LDTDP storage memory and copied from the LDTDP storage memory to the temporary memory. The copying from the LDTDP storage memory to the temporary memory may be controlled by the external DTC CPU, which in turn controls the operation of the DTPU CPU. The operation of the external DTC CPU may be controlled by the DAD (106), which is operated by a user via the user DAD user interface 110.
在一實例操作之另一步驟中,含有一或多個LDTDP之資料自暫存記憶體載入至DTPU(104)之安全記錄記憶體中。 In another step of an example operation, data containing one or more LDTDPs is loaded from the temporary memory into the secure log memory of the DTPU (104).
在實施例中,建立在一智慧型電話(一DAD)(106)與一DTC(108)之間之一連結,使用強加密用於其間之資料之識別及傳送。連結對於各對之一智慧型電話(106)與一DTC(108)可為唯一的。 In an embodiment, a link is established between a smart phone (a DAD) (106) and a DTC (108), using strong encryption for identification and transmission of data therebetween. The link may be unique for each pair of a smart phone (106) and a DTC (108).
外部DTC處理器(或DTC CPU)通常僅在向經連結智慧型電話安全地識別其自身之後啟動。DTC(108)上之DTC處理器控制DTPU(104)之讀取及重新讀取及DTPU(104)之更新以表達新特質。在一些實施例中,可藉由按壓DTC(108)上之一接通/關斷開關來啟動外部DTC CPU。在其他實施例中,由DAD(106)啟動(且供電給)DTC CPU。 The external DTC processor (or DTC CPU) is typically activated only after securely identifying itself to the connected smartphone. The DTC processor on the DTC (108) controls the reading and re-reading of the DTPU (104) and the updating of the DTPU (104) to express new characteristics. In some embodiments, the external DTC CPU can be activated by pressing an on/off switch on the DTC (108). In other embodiments, the DTC CPU is activated (and powered) by the DAD (106).
在實施例中,在安全地連結智慧型電話(106)及DTC(108)之後,智慧型電話(106)在符合特定標準且通過各種合規性檢查之後藉由外部DTC CPU將正確格式化資料(舉例而言,一LDTDP)上傳至指定安全儲存區域(舉例而言,暫存記憶體),且接著將一指令傳輸至DTPU處理器以進行以下各者:‧檢查指定儲存區域(暫存記憶體)是否含有呈一指定格式之資料(一LDTDP);‧若資料符合一指定標準且通過各種檢查,則DTPU處理器將資料複 製或移動至DTPU內之一指定區域(安全記錄記憶體);‧接著,處理器將一指令發送至DTPU(104)以讀取指定區域(安全記錄記憶體)內之資料且根據該區域內含有之資料採取動作,其可陳述為表達安全記錄記憶體中之LDTDP中表示之特定文件之特質之DTPU(104);‧接著,DTPU處理器可經指示以在對該資料起作用之前搜尋一系列參數內之特定標頭及其他資料識別符。 In an embodiment, after securely connecting the smart phone (106) and the DTC (108), the smart phone (106) uploads the correctly formatted data (for example, an LDTDP) to a designated secure storage area (for example, a temporary memory) through the external DTC CPU after meeting certain standards and passing various compliance checks, and then transmits an instruction to the DTPU processor to do the following: ‧ Check whether the designated storage area (temporary memory) contains data in a designated format (an LDTDP); ‧ If the data meets a designated standard and passes various checks, the DTPU processor copies or moves the data to a designated area ( Secure Log Memory); ‧The processor then sends an instruction to the DTPU (104) to read the data in the specified area (Secure Log Memory) and take action based on the data contained in the area, which can be described as a DTPU (104) expressing the characteristics of a specific file represented in the LDTDP in the Secure Log Memory; ‧The DTPU processor can then be instructed to search for specific headers and other data identifiers within a series of parameters before acting on the data.
熟習相關技術的讀者將理解,DTPU(104)可為使用一增大儲存區域建構之一EMV器件,其經明確指示以檢查及/或監測一安全儲存區域(此可稱為安全記錄記憶體或安全元件)。EMV器件亦可自(舉例而言)駐存在DTC(108)內之一外部處理器接受命令。 Readers familiar with the relevant technology will understand that the DTPU (104) can be an EMV device constructed using an enlarged storage area, which is explicitly instructed to check and/or monitor a secure storage area (which may be referred to as a secure recording memory or secure element). The EMV device can also receive commands from an external processor (for example) residing in the DTC (108).
在實施例中,外部DTC處理器僅將資料傳送至DTPU(104)之(若干)記憶體區域中,且一旦進入此記憶體區域,DTPU處理器便負責資料之進一步複製、讀取、寫入及/或處理。然而,在其他實施例中,資料可保持受控於外部DTC處理器,其中外部DTC處理器(CPU)可發佈指令至DTPU處理器(CPU)以操作以複製、讀取、寫入及/或處理資料。 In an embodiment, the external DTC processor simply transfers the data to the memory area(s) of the DTPU (104), and once in this memory area, the DTPU processor is responsible for further copying, reading, writing and/or processing of the data. However, in other embodiments, the data may remain under the control of the external DTC processor, where the external DTC processor (CPU) may issue instructions to the DTPU processor (CPU) to operate to copy, read, write and/or process the data.
在另一實施例中,DTPU處理器在將資料傳送至安全位置(安全記錄記憶體)之前驗證資料。此外,DTPU處理器在完成資料之檢查及驗證之後指示EMV器件載入資料或更新其自身。 In another embodiment, the DTPU processor verifies the data before transmitting it to a secure location (secure recording memory). In addition, the DTPU processor instructs the EMV device to load the data or update itself after completing the check and verification of the data.
在各項實施例中,全部記憶體儲存器(LDTDP儲存記憶體、暫存記憶體及安全記錄記憶體)可能位於EMV器件上。替代地,一些記憶體儲存器可能位於在DTPU外部但連結至EMV器件之一晶片上。記憶體儲存器可以檔案為基礎、使用位於具有一根目錄或主檔案(MF)之一目錄檔案(DF)中之資料檔案(電子檔案)。 In various embodiments, all memory storage (LDTDP storage memory, temporary memory, and secure log memory) may be located on the EMV device. Alternatively, some memory storage may be located on a chip external to the DTPU but connected to the EMV device. The memory storage may be file-based, using data files (electronic files) located in a directory file (DF) having a root directory or master file (MF).
外部DTC處理器上之韌體可為原生韌體(使用機器語言),但可為根據一以解譯器為基礎之作業系統(包含Java卡、MultOS或BasicCard)執行之解譯碼。由於外部DTC CPU及DTPU CPU兩者提供指令,因此外部DTC CPU將受益於具有與DTPU CPU相同之韌體,因此允許使用相同格式提供指令。在此點上,若且當更新用於外部DTC CPU之韌體時,亦更新用於DTPU CPU之韌體可為有益的。在一些實施例中,用於外部DTC CPU及DTPU CPU兩者之韌體可儲存在相同位置、可由兩個CPU存取,因此僅需要對一個韌體儲存庫之更新。然而,一單一韌體來源可能具有安全隱患。 The firmware on the external DTC processor may be native firmware (using machine language), but may be interpreted code executed according to an interpreter-based operating system (including Java Card, MultOS, or BasicCard). Since both the external DTC CPU and the DTPU CPU provide instructions, the external DTC CPU will benefit from having the same firmware as the DTPU CPU, thus allowing instructions to be provided in the same format. In this regard, if and when the firmware for the external DTC CPU is updated, it may be beneficial to also update the firmware for the DTPU CPU. In some embodiments, the firmware for both the external DTC CPU and the DTPU CPU may be stored in the same location, accessible by both CPUs, so only an update to one firmware repository is required. However, a single source of firmware may have security implications.
圖1詳述一DTC(108),其可經由一DTC收發器(114)而與智慧型電話(106)之一智慧型電話收發器(116)形成一通信連結以使能夠在其間進行資料傳送。在其中數位交易文件與一使用者企圖進行一交易相關之本發明之實施例中,使用者可操作智慧型電話(106)之使用者介面(110)以選擇一特定數位文件且在DTC(108)中啟動該數位文件。一旦DTC(108)採用所需特質且採用由使用者操作其智慧型電話(106)所選擇之數位交易文件之特性,便可接著使用DTC(108)來與DTC(108)進行交易。在此點上,DTC(108)使用所選擇數位交易文件之全部特性操作,所選擇數位交易文件一旦啟動為待安裝為DTC所屬之文件之文件,文件便成為DTC之特質。換言之,一旦一DTC成為一文件之實體實施例,文件便轉變為DTC之一「特質」。 FIG. 1 details a DTC (108) that can form a communication link with a smartphone transceiver (116) of a smartphone (106) via a DTC transceiver (114) to enable data transfer therebetween. In an embodiment of the present invention where a digital transaction file is associated with a user attempting to conduct a transaction, the user can operate the user interface (110) of the smartphone (106) to select a particular digital file and activate the digital file in the DTC (108). Once the DTC (108) adopts the desired characteristics and adopts the characteristics of the digital transaction file selected by the user operating his smartphone (106), the DTC (108) can then be used to conduct transactions with the DTC (108). At this point, the DTC (108) operates using all of the properties of the selected digital transaction file, which once activated as a file to be installed as a file owned by the DTC, becomes a property of the DTC. In other words, once a DTC becomes a physical embodiment of a file, the file becomes a "property" of the DTC.
特定言之,具有針對一數位交易文件之選擇的所選擇特質之DTC(108)可接著用來根據包含自動提款機(未展示)及/或如圖1中展示之一商家終端機(102)之一數位支付交易網路之現有基礎設施進行交易以實現一系列交易。 Specifically, the DTC (108) having the selected characteristics for selection of a digital transaction document may then be used to conduct transactions based on an existing infrastructure of a digital payment transaction network including an ATM (not shown) and/or a merchant terminal (102) as shown in FIG. 1 to implement a series of transactions.
在使用具有一所選擇數位交易文件作為其特質之DTC(108)之情況中,可藉由使用DTC與商家終端機之間之任何現有通信構件且在圖1中實現與DTC(108)通信之商家終端機(102)。所圖解說明之實例包含在DTC(108)與一商家終端機(102)之間藉由DTC(108)與商家終端機(102)之間之實體接觸件實現之一交易,實體接觸件通常包含介於在併入DTC(108)中之一支付器件之一外部接觸板(112)與駐存在商家終端機(102)內之電極(未展示)之間之實體接觸件。 In the case of using a DTC (108) having a selected digital transaction file as its feature, a merchant terminal (102) communicating with the DTC (108) can be implemented in FIG1 by using any existing communication means between the DTC and the merchant terminal. The illustrated example includes a transaction between the DTC (108) and a merchant terminal (102) implemented by physical contacts between the DTC (108) and the merchant terminal (102), the physical contacts typically including physical contacts between an external contact plate (112) of a payment device incorporated in the DTC (108) and electrodes (not shown) residing in the merchant terminal (102).
在一DTC(108)與一商家終端機(102)之間進行一交易之進一步實例包含DTC(108)及商家終端機(102)之非接觸式近距離通信能力之使用且在其中DTC(108)包含一磁條之例項中,使用終端機(102)及DTC(108)之一磁條讀取器來實現交易。 A further example of conducting a transaction between a DTC (108) and a merchant terminal (102) includes the use of contactless near field communication capabilities of the DTC (108) and the merchant terminal (102) and in the example where the DTC (108) includes a magnetic stripe, a magnetic stripe reader of the terminal (102) and the DTC (108) is used to effectuate the transaction.
上文中已按照包含一經韌體修改之EMV器件之一實施例描述圖1中之實施例。 The embodiment in FIG. 1 has been described above according to an embodiment including a firmware-modified EMV device.
類似地,可使用涉及一經韌體修改之EMV器件之一配置實施圖2A、圖2B及圖3A至圖3D中描述之實施例。 Similarly, the embodiments described in FIGS. 2A , 2B , and 3A to 3D may be implemented using a configuration involving a firmware-modified EMV device.
參考圖2A,用圖形圖解說明呈具有關聯DAD使用者介面(202)之一實體卡(200)之形式之一DTC,其逐步執行針對DTC(200)選擇一不同特質之一程序。 Referring to FIG. 2A , a DTC in the form of a physical card ( 200 ) with an associated DAD user interface ( 202 ) is graphically illustrated, which steps through a process of selecting a different characteristic for the DTC ( 200 ).
在圖2A之實施例中,在選擇一特質之程序開始時,DTC(200)不具有一特定特質。一使用者可操作一智慧型電話(204)且根據一非接觸式近距離通信協定而與DTC(200)通信以便選擇DTC(200)所需之特質。在圖2A之特定實例中,智慧型電話(204)已執行軟體以呈現可用卡特質給已選擇一VISA卡作為DTC(200)之較佳特質之一使用者。在一實施例中,使用 者可能有必要提供生物特徵鑑認(諸如一指紋)以便操作智慧型電話(204)來選擇DTC(200)的一特質。 In the embodiment of FIG. 2A , at the beginning of the process of selecting a characteristic, the DTC ( 200 ) does not have a particular characteristic. A user may operate a smart phone ( 204 ) and communicate with the DTC ( 200 ) according to a contactless near-field communication protocol to select a desired characteristic of the DTC ( 200 ). In the specific example of FIG. 2A , the smart phone ( 204 ) has executed software to present available card characteristics to a user who has selected a VISA card as a preferred characteristic of the DTC ( 200 ). In one embodiment, the user may need to provide biometric identification (such as a fingerprint) in order to operate the smart phone ( 204 ) to select a characteristic of the DTC ( 200 ).
一旦智慧型電話(204)傳遞使用者對一VISA卡之選擇作為應由DTC(200)採用之特質,相關選擇及/或資料便自智慧型電話(204)傳送至DTC(200)且在接受表示一VISA卡之LDTDP之選擇及/或資料後,DTC旋即採用VISA卡之特質(206)。在一後續時間點,使用者可能偏好將DTC之特質變更為一萬事達卡且可操作其等智慧型電話上之軟體以選擇一萬事達卡特質用於實現DTC中之一特質變更之目的。參考圖2A,智慧型電話(204)已經操作以選擇一萬事達卡特質且在將相關選擇及/或LDTDP資料傳遞至DTC(200)後,DTC旋即採用一萬事達卡特質且繼此之後,DTC(200)將作為消費者萬事達卡(208)操作。 Once the smartphone (204) communicates the user's selection of a VISA card as the characteristic to be adopted by the DTC (200), the relevant selection and/or data is transmitted from the smartphone (204) to the DTC (200) and upon receiving the selection and/or data of the LDTDP representing a VISA card, the DTC immediately adopts the VISA card's characteristic (206). At a subsequent point in time, the user may prefer to change the DTC's characteristic to a MasterCard and may operate the software on their smartphone to select a MasterCard characteristic for the purpose of achieving a characteristic change in the DTC. Referring to FIG. 2A , the smartphone ( 204 ) has been operated to select a MasterCard quality and after transmitting the relevant selection and/or LDTDP data to the DTC ( 200 ), the DTC immediately adopts a MasterCard quality and thereafter, the DTC ( 200 ) will operate as a consumer MasterCard ( 208 ).
最後,一旦一消費者已完成使用其等DTC進行交易,其等便可能偏好致使DTC具有一歸零特質,且參考圖2A,智慧型電話(204)經操作以識別消費者偏好藉由將一歸零特質賦予DTC而鎖定其等DTC。在傳遞使用者之請求後,智慧型電話(204)旋即導致DTC(200)採用一歸零特質(200)。 Finally, once a consumer has completed a transaction using their DTC, they may prefer to cause the DTC to have a zeroing feature, and referring to FIG. 2A , the smart phone (204) is operated to recognize the consumer's preference to lock their DTC by assigning the zeroing feature to the DTC. Upon transmitting the user's request, the smart phone (204) immediately causes the DTC (200) to adopt the zeroing feature (200).
在圖2A之實施例中,DTC(200、206、208)係執行軟體之一經修改DTPU,其已經修改以允許/使DTC能夠根據由DAD(204)傳送至DTC之資料指令而採用包含一歸零特質之不同特質。 In the embodiment of FIG. 2A , the DTC ( 200 , 206 , 208 ) is a modified DTPU executing software that has been modified to allow/enable the DTC to employ different characteristics including a return-to-zero characteristic based on the data command sent to the DTC by the DAD ( 204 ).
可藉由DAD處理器經由各自收發器(在圖1中分別展示為智慧型電話收發器(116)及DTC收發器(114))與一DTC外部處理器通信而實現DAD與DTC之間之通信,且其中已自DAD接收指令及/或資料之DTC外部處理器與EMV器件協作地通信,以導致EMV器件根據由DTC自DAD接收之指令 及/或資料採用一所需特質。 Communication between the DAD and the DTC can be achieved by the DAD processor communicating with a DTC external processor via respective transceivers (shown as a smartphone transceiver (116) and a DTC transceiver (114) respectively in FIG. 1), and wherein the DTC external processor having received instructions and/or data from the DAD communicates cooperatively with the EMV device to cause the EMV device to adopt a desired characteristic according to the instructions and/or data received by the DTC from the DAD.
參考圖2B,在圖2B中關於一數位交易卡之特質之變更圖解說明圖2A中描繪之相同步驟。讀者將注意,圖2B中之DTC係包含一使用者介面之具有一歸零特質之一DTC(210),其在下文中更詳細地描述,尤其參考圖3D。在圖2B中描繪之實施例之例項中,由相較於DAD使用者介面(參考圖2A)之DTC使用者介面實現變更DTC(210)之特質之請求。關於圖2A中之DTC(200),圖2B中之歸零特質DTC(210)藉由使用者操作歸零特質DTC(210)(其包含捲動鍵及歸位鍵及DTC上之一顯示器)上之使用者介面而轉變為一VISA卡(206)。 Referring to FIG. 2B , the same steps depicted in FIG. 2A are illustrated with respect to the change of a characteristic of a digital transaction card. The reader will note that the DTC in FIG. 2B is a DTC (210) having a zeroed characteristic that includes a user interface, which is described in more detail below, particularly with reference to FIG. 3D . In the example of the embodiment depicted in FIG. 2B , the request to change the characteristic of the DTC (210) is implemented by a DTC user interface that is comparable to the DAD user interface (see FIG. 2A ). With respect to the DTC (200) in FIG. 2A, the zeroing characteristic DTC (210) in FIG. 2B is transformed into a VISA card (206) by the user operating the user interface on the zeroing characteristic DTC (210) (which includes a scroll key and a return key and a display on the DTC).
當企圖將特質自一VISA卡(206)變更為一萬事達卡(208)時,使用者操作DTC捲動鍵,觀察在重複按下捲動鍵時循序顯示可用特質之顯示器。一旦顯示一萬事達卡特質,使用者便可按下歸位鍵且相應地更改DTC特質。DTC(208)可藉由使用者操作DTC使用者介面以顯示且選擇一歸零特質並實現歸零特質而再次變更為一歸零特質。 When attempting to change the characteristic from a VISA card (206) to a MasterCard card (208), the user operates the DTC scroll key and observes the display showing available characteristics in sequence as the scroll key is repeatedly pressed. Once a MasterCard characteristic is displayed, the user may press the reset key and change the DTC characteristic accordingly. The DTC (208) may be changed again to a reset characteristic by the user operating the DTC user interface to display and select a reset characteristic and implement the reset characteristic.
參考圖3A,連同呈一智慧型電話(302)及一商家終端機(304)之形式之一DAD圖解說明呈一可佩戴器件(300)之形式之一DTC。在此特定實施例中,可佩戴器件(300)係亦提供顯示當前時間之功能及根據可佩戴器件(300)可用之任何其他功能之一手錶。日益地,可佩戴器件由消費者採用以組合許多個別物項之功能,藉此減少進行交易之複雜性,此係因為一旦一DTC之功能性併入至一可佩戴器件(300)中,便不再有必要攜帶一分開之DTC。佩戴可佩戴器件(300)讓使用者能夠用其等平常將佩戴之器件進行交易。在圖3A之例項中,可佩戴器件(300)圖解說明為經由非接觸式近距離通信而與智慧型電話(302)及一商家終端機(304)通信。當然,儘管全 部三個器件圖解說明為很靠近,然而熟習相關技術的讀者將理解,可佩戴器件(300)不必同時與一智慧型電話(302)及一商家終端機(304)兩者進行非接觸式近距離通信且可在不同時間單獨發生各自器件之間之通信。 Referring to FIG. 3A , a DTC in the form of a wearable device ( 300 ) is illustrated along with a DAD in the form of a smart phone ( 302 ) and a merchant terminal ( 304 ). In this particular embodiment, the wearable device ( 300 ) is a watch that also provides the functionality of displaying the current time and any other functionality available from the wearable device ( 300 ). Increasingly, wearable devices are being adopted by consumers to combine the functionality of many separate items, thereby reducing the complexity of conducting transactions because once the functionality of a DTC is incorporated into a wearable device ( 300 ), it is no longer necessary to carry a separate DTC. Wearing the wearable device ( 300 ) enables the user to conduct transactions using the device they would normally wear. In the example of FIG. 3A , the wearable device (300) is illustrated as communicating with a smart phone (302) and a merchant terminal (304) via contactless near-field communication. Of course, although all three devices are illustrated as being in close proximity, readers skilled in the art will understand that the wearable device (300) need not be in contactless near-field communication with both a smart phone (302) and a merchant terminal (304) at the same time and that communication between the respective devices may occur separately at different times.
參考圖3B,呈一戒指(306)之形式之一替代可佩戴器件詳述為與呈一智慧型電話(302)及一商家終端機(304)之形式之一DAD進行非接觸式近距離通信。再一次,在圖3B中之圖解說明中,皆使用非接觸式近距離通信發生智慧型電話(302)、呈一戒指(306)之形式之可佩戴器件與一商家終端機(304)之間之通信。 Referring to FIG. 3B , an alternative wearable device in the form of a ring ( 306 ) is illustrated as being in contactless near field communication with a DAD in the form of a smartphone ( 302 ) and a merchant terminal ( 304 ). Again, in the illustration in FIG. 3B , the communication between the smartphone ( 302 ), the wearable device in the form of a ring ( 306 ) and a merchant terminal ( 304 ) occurs using contactless near field communication.
參考圖3C,圖解說明再另一實施例,其中DTC提供為呈一智慧型電話外殼(308)之形式。在此特定實施例中,呈一智慧型電話(302)之形式之一DAD與呈智慧型電話外殼(308)之形式之一DTC通信,DTC繼而與一商家終端機(304)通信。根據按照ISO/IEC 14443之非接觸式近距離通信發生圖3C中圖解說明之全部通信且在此特定實施例中,並非一可佩戴器件,DTC採取另一便利器件之形式,即,一智慧型電話外殼(308),此係因為使用者定期為其等智慧型電話購買外殼以便保護其等智慧型電話免受損壞。當然,在圖3C之實施例中,若一消費者將使用呈一智慧型電話外殼(308)之形式之一DTC,且將外殼(308)附接至智慧型電話(302),則呈智慧型電話(302)之形式之DAD及呈一智慧型電話外殼(308)之形式之DTC同時被消費者擁有。 Referring to FIG. 3C , yet another embodiment is illustrated in which the DTC is provided in the form of a smartphone case (308). In this particular embodiment, a DAD in the form of a smartphone (302) communicates with a DTC in the form of a smartphone case (308), which in turn communicates with a merchant terminal (304). All communications illustrated in FIG. 3C occur according to contactless near field communications in accordance with ISO/IEC 14443 and in this particular embodiment, rather than being a wearable device, the DTC takes the form of another convenient device, namely, a smartphone case (308), because users regularly purchase cases for their smartphones in order to protect their smartphones from damage. Of course, in the embodiment of FIG. 3C , if a consumer is to use a DTC in the form of a smart phone case (308) and attach the case (308) to the smart phone (302), the DAD in the form of the smart phone (302) and the DTC in the form of a smart phone case (308) are simultaneously owned by the consumer.
讀者將瞭解,可以若干不同方式組態DTC,且存在自具有最小(或有限)功能性/連接能力但將生產較不昂貴且較不易於故障之一DTC、至具有最大功能性且包含輔助使用者互動之特徵且因此將被視為更加「使用者易用」但將生產更昂貴且將更可能易於故障之一DTC之一系列可行DTC實 施例。圖3D提供具有一信用卡輪廓的四個DTC之圖形表示,藉此各包含一EMV器件(310)及一選用印刷識別(312)(在展示之實施例中,係卡擁有者之名稱),且該四個DTC之功能性/連接能力之特徵表示關於數位交易之使用者體驗之明顯差異。 The reader will appreciate that a DTC can be configured in a number of different ways, and that there is a range of possible DTC implementations from one with minimal (or limited) functionality/connectivity but which will be less expensive to produce and less prone to failure, to one with maximum functionality and including features to assist user interaction and thus will be considered more "user friendly" but which will be more expensive to produce and will be more likely to be prone to failure. Figure 3D provides a graphical representation of four DTCs having a credit card outline, whereby each includes an EMV device (310) and an optional printed identification (312) (in the embodiment shown, the name of the card owner), and the features of the functionality/connectivity of the four DTCs represent significant differences in the user experience with respect to digital transactions.
舉例而言,圖3D中描繪之最上部DTC(314)表示具有最小功能性/連接能力之一卡且包含一EMV器件(310),其經韌體修改且啓用EMV器件與一DAD(302)之間之NFC無線連接能力且變更DTC(314)之特質,但排除一外部DTC處理器(稱為一MCU)、藍芽連接能力及任何形式之顯示器或捲動鍵/歸位鍵。在一項特定實施例中,可向一使用者發行組態成具有最小功能性/連接能力之DTC(314)使得EMV器件(310)具有預載入多個特質。更普遍地,在將DTC(314)遞送至使用者之後,可使用DAD(302)將多個特質之一者傳送至EMV器件(310)上或傳送若干特質以供由EMV器件(310)同時儲存。 For example, the topmost DTC (314) depicted in FIG. 3D represents a card with minimal functionality/connectivity and includes an EMV device (310) that has been firmware modified to enable NFC wireless connectivity between the EMV device and a DAD (302) and change the characteristics of the DTC (314), but excludes an external DTC processor (referred to as an MCU), Bluetooth connectivity, and any form of display or scroll/home keys. In a specific embodiment, a DTC (314) configured with minimal functionality/connectivity may be issued to a user such that the EMV device (310) has multiple characteristics pre-loaded. More generally, after the DTC (314) is delivered to the user, the DAD (302) may be used to transmit one of a plurality of characteristics to the EMV device (310) or to transmit several characteristics for simultaneous storage by the EMV device (310).
描繪之第二DTC(316)亦表示包含一EMV器件(310)之具有最小功能性/連接能力之一卡,EMV器件(310)經韌體修改且啓用EMV器件與一DAD(302)之間之無線連接能力(諸如藍芽及/或NFC)以變更DTC(316)之特質。DTC(316)亦包含一MCU(圖3D中未展示)。可向一使用者發行組態成具有相對最小功能性/連接能力但包含一MCU之一DTC(316),其中EMV器件(310)對執行至多個特質之資料進行存取。替代地,在將DTC(316)遞送至使用者之後,可使用DAD(302)將多個特質之一者傳送至EMV器件(310)上或傳送若干特質以供由EMV器件(310)同時儲存。 The second DTC (316) depicted also represents a card with minimal functionality/connectivity that includes an EMV device (310) that is firmware modified and enables wireless connectivity (such as Bluetooth and/or NFC) between the EMV device and a DAD (302) to change the characteristics of the DTC (316). The DTC (316) also includes an MCU (not shown in FIG. 3D). A DTC (316) configured with relatively minimal functionality/connectivity but including an MCU can be issued to a user, wherein the EMV device (310) accesses data that implements multiple characteristics. Alternatively, after the DTC (316) is delivered to the user, the DAD (302) may be used to transmit one of the multiple characteristics to the EMV device (310) or to transmit several characteristics for simultaneous storage by the EMV device (310).
圖3D中描繪之第三DTC(318)表示包含一EMV器件(310)之一中等功能性/連接能力卡,EMV器件(310)經韌體修改且啓用EMV器件(310)與一 DAD(302)之間之無線連接能力(諸如藍芽及/或NFC)且變更DTC(318)之特質。DTC(318)亦包含一顯示器(320),其可呈用於顯示資訊之一簡化4數位字母數字介面之形式,資訊包含(但不限於)經載入(或先前儲存)卡上之所選擇特質、所選擇特質之一唯一ID或縮寫、針對文件之一到期日、一臨時PIN號碼、一PAN號碼或其部分及/或卡擁有者之一名稱。可向一使用者發行組態成具有中等功能性/連接能力之一DTC(318)使得EMV器件(310)可存取關於多個特質之資料。替代地,在將DTC(318)遞送至使用者之後,可使用DAD(302)將多個特質之一者傳送至EMV器件(310)上或傳送若干特質以供由EMV器件(310)同時儲存。 The third DTC (318) depicted in FIG3D represents a medium functionality/connectivity card including an EMV device (310) that is firmware modified and enables wireless connectivity (such as Bluetooth and/or NFC) between the EMV device (310) and a DAD (302) and changes the characteristics of the DTC (318). The DTC (318) also includes a display (320) that may be in the form of a simplified 4-digit alphanumeric interface for displaying information including (but not limited to) selected characteristics loaded (or previously stored) on the card, a unique ID or abbreviation of the selected characteristics, an expiration date for the document, a temporary PIN number, a PAN number or portion thereof, and/or a name of the card owner. A DTC (318) configured with medium functionality/connectivity may be issued to a user so that the EMV device (310) may access data regarding multiple characteristics. Alternatively, after the DTC (318) is delivered to the user, the DAD (302) may be used to transmit one of the multiple characteristics to the EMV device (310) or to transmit several characteristics for simultaneous storage by the EMV device (310).
圖3D中描繪之第四DTC(322)表示具有一高等級之功能性/連接能力之一卡且包含一EMV器件(310),其經韌體修改且啓用EMV器件(310)與一DAD(302)之間之NFC或藍芽無線連接能力且在遞送卡之後將多個特質傳送至EMV器件(310)上。DTC(322)亦包含一更全面顯示器(324)及使能包含實現一所儲存特質之選擇之輸入之使用者輸入之捲動鍵/歸位鍵(326)。熟習相關技術的技術人士將瞭解,即使在諸如一使用者之智慧型電話之一DAD(302)不存在時(舉例而言,若DAD未由使用者攜帶或具有一放電電池),在卡上包含一使用者介面使能夠使用DTC(322)。 The fourth DTC (322) depicted in Figure 3D represents a card with a high level of functionality/connectivity and includes an EMV device (310) that is firmware modified and enables NFC or Bluetooth wireless connectivity between the EMV device (310) and a DAD (302) and transmits multiple properties to the EMV device (310) after delivery of the card. The DTC (322) also includes a more comprehensive display (324) and scroll/home keys (326) to enable user input including input to enable selection of a stored property. Those skilled in the art will appreciate that including a user interface on the card enables the use of the DTC (322) even when a DAD (302) such as a user's smartphone is not present (for example, if the DAD is not carried by the user or has a discharged battery).
表1係在與DTC相關聯之EMV器件經韌體修改時圖3D中描繪之DTC實施例(314、316、318及322)之一圖表,其詳述各實施例中存在之特徵之組合。符號表示一特徵存在,且符號表示一特徵不存在,且應理解,實施例之此列出僅表示可經組態具有特徵之不同組合之可能實施例之一選擇且非旨在表示一詳盡列出。 Table 1 is a graph of the DTC embodiments (314, 316, 318, and 322) depicted in FIG. 3D when the EMV device associated with the DTC is firmware modified, detailing the combination of features present in each embodiment. The symbol indicates that a feature exists, and The symbol denotes the absence of a feature, and it is understood that this listing of embodiments represents only one selection of possible embodiments that can be configured with different combinations of features and is not intended to represent an exhaustive listing.
在表1中之第一實施例中,DTC(314)需要使用具有一經修改NFC能力之一資料輔助器件(DAD)(諸如一智慧型電話)以將資料傳遞至經韌體修改之一EMV器件。如先前描述,一經韌體修改之EMV器件具有包含韌體之一外部DTC CPU,韌體可操作以將資料(舉例而言,LDTDP資料)寫入至暫存記憶體,使得當啟動DTPU時,DTPU以導致DTC採用一特定卡特質或以某一其他方式輔助進行一數位交易之一方式將資料複製至DTPU中 之安全記錄記憶體(安全元件)。可將關於各特質之資料儲存在與DAD相關聯之記憶體中,其中DAD與DTC之間之通信可能呈將資料下載並複製至安全元件中用於更新DTC之特質之目的之指令之形式。經韌體修改之DTC(314)限於搭配一NFC啓用之DAD使用及使用具有經修改非接觸式通信能力之一EMV器件,以便安全地接收自NFC啓用之DAD接收之資料,但具有能夠針對一單一計劃採用多個特質及低成本及低故障傾向之優點,此係因為DTC(314)不包含一MCU、顯示器或捲動鍵/歸位鍵。 In the first embodiment of Table 1, the DTC (314) requires the use of a data-assisted device (DAD) (such as a smart phone) with a modified NFC capability to pass data to a firmware-modified EMV device. As previously described, a firmware-modified EMV device has an external DTC CPU that includes firmware that is operable to write data (e.g., LDTDP data) to a temporary memory so that when the DTPU is activated, the DTPU copies the data to a secure log memory (secure element) in the DTPU in a manner that causes the DTC to employ a specific card quality or assist in conducting a digital transaction in some other manner. Data about each characteristic may be stored in memory associated with the DAD, wherein communication between the DAD and the DTC may be in the form of instructions to download and copy data to the secure element for the purpose of updating the characteristics of the DTC. The firmware modified DTC (314) is limited to use with an NFC enabled DAD and use of an EMV device with modified contactless communication capabilities to securely receive data received from the NFC enabled DAD, but has the advantages of being able to employ multiple characteristics for a single project and low cost and low fault proneness, because the DTC (314) does not include an MCU, display or scroll/home keys.
經韌體修改之DTC(316)亦需要使用諸如一智慧型電話之一資料輔助器件(DAD)以將資料傳遞至經韌體修改之一EMV器件,如上文中描述。DTC(314)與DTC(316)之間之差異在於DTC(316)包含一MCU,其可儲存關於多個特質之資料(及/或可能與變更一些其他數位交易參數相關之資料),而非將資料儲存在DAD記憶體中,且可接受具有無線連接能力(NFC或藍芽)之一DAD與含有亦具有無線連接能力(NFC或藍芽)之MCU之DTC之間之一安全工作階段。使用經韌體修改之DTC(316)之優點包含低成本及低故障傾向,不存在針對一NFC啓用之DAD(其中MCU可接受與單獨藍芽啓用(舉例而言)之一電話之通信)之需求、針對一單一計劃採用多個特質之能力,及可輔助自DAD之安全資料傳送且不需要使用具有經修改非接觸式通信能力之一EMV器件之一MCU之存在。 The firmware modified DTC (316) also requires the use of a data assist device (DAD) such as a smart phone to pass data to a firmware modified EMV device, as described above. The difference between DTC (314) and DTC (316) is that DTC (316) includes an MCU that can store data about multiple characteristics (and/or data that may be related to changing some other digital transaction parameters) instead of storing data in DAD memory, and can accept a secure working session between a DAD with wireless connectivity (NFC or Bluetooth) and a DTC containing an MCU that also has wireless connectivity (NFC or Bluetooth). Advantages of using a firmware modified DTC (316) include low cost and low fault proneness, the absence of a requirement for an NFC enabled DAD where the MCU can accept communications with a separate Bluetooth enabled (for example) phone, the ability to employ multiple features for a single scheme, and the presence of an MCU that can facilitate secure data transfer from the DAD and does not require the use of an EMV device with modified contactless communication capabilities.
表1中之DTC(318)亦需要使用諸如一智慧型電話之一資料輔助器件(DAD)以將資料傳遞至可經由一非接觸式介面建立具有無線連接能力(NFC及/或藍芽)之一DAD與DTC之間之一安全工作階段之一經韌體修改之EMV器件。DTC(318)包含一MCU,其可自NFC啓用且藍芽啓用之DAD接受無線通信,且可藉此建立大多數電話與含有MCU之DTC之間之 一安全工作階段。使用DTC(318)之優點包含低至中等成本、低至中等故障傾向,且不存在單獨使用一NFC啓用之DAD之需求,但鑑於DTC(318)包含一MCU及顯示器(320),相較於DTC(314)及DTC(316),存在與DTC(318)之生產相關聯之一更高成本。 The DTC (318) in Table 1 also requires the use of a data-assisted device (DAD) such as a smart phone to pass data to a firmware modified EMV device that can establish a secure session between a DAD with wireless connectivity (NFC and/or Bluetooth) and the DTC via a contactless interface. The DTC (318) includes an MCU that can accept wireless communications from an NFC-enabled and Bluetooth-enabled DAD and thereby establish a secure session between most phones and the DTC containing the MCU. Advantages of using DTC (318) include low to moderate cost, low to moderate failure tendency, and no need to use a separate NFC-enabled DAD, but given that DTC (318) includes an MCU and display (320), there is a higher cost associated with the production of DTC (318) compared to DTC (314) and DTC (316).
當使用表1中描述之DTC(322)時,熟習相關技術的技術人士將理解,不一定必需使用一DAD(諸如一智慧型電話),但可使用DAD來變更卡之特質或以某一其他方式輔助進行一數位交易。在任何情況中,DAD必需初始設置卡且將多個特質下載/儲存在MCU中,但繼初始設置之後,卡自身可用來使用捲動鍵/歸位鍵(326)變更一卡之特質之操作參數或以某一其他方式輔助數位交易。一MCU用來在一初始設置期間自DAD接受無線通信(藍芽及NFC兩者),且進一步經程式化以自可(舉例而言)包含捲動鍵/歸位鍵(326)之一本端介面接受命令,且將按鍵動作轉換成命令。當使用捲動鍵/歸位鍵(326)變更DTC(322)之特質或執行輔助數位交易之某一其他任務時,由本端介面授權傳輸,本端介面授權MCU選擇所儲存資料且將所儲存資料複製至安全元件。 When using the DTC (322) described in Table 1, those skilled in the art will appreciate that it is not necessary to use a DAD (such as a smart phone), but the DAD can be used to change the characteristics of the card or assist in a digital transaction in some other way. In any case, the DAD is required to initially set up the card and download/store the characteristics in the MCU, but after the initial setup, the card itself can be used to change the operating parameters of a card's characteristics or assist in a digital transaction in some other way using the scroll key/home key (326). An MCU is used to accept wireless communications (both Bluetooth and NFC) from the DAD during an initial setup, and is further programmed to accept commands from a local interface that may include, for example, a scroll key/home key (326), and convert key presses into commands. When the scroll key/home key (326) is used to change the characteristics of the DTC (322) or perform some other task that assists in digital transactions, the transmission is authorized by the local interface, which authorizes the MCU to select stored data and copy the stored data to the secure element.
DTC(322)具有在本端自儲存在卡上之許多多個並行特質選擇一個特質而不具有在更新或變更(即,狀態/更新之變更)期間發現卡細節之風險之優點,此係因為卡細節未被傳輸。進一步優點包含減少實現更新或變更(即,狀態/更新之變更)之時間、需要傳送最小量資料以實現特質之一變更,及在不使用一DAD之情況下變更DTC特質之能力。然而,DTC(322)具有一較高生產成本且歸因於其複雜性而可具有一較高故障傾向。 The DTC (322) has the advantage of selecting a characteristic locally from a number of concurrent characteristics stored on the card without the risk of discovering card details during an update or change (i.e., a change of state/update) because the card details are not transmitted. Further advantages include reduced time to implement an update or change (i.e., a change of state/update), the minimum amount of data required to implement a change of characteristics, and the ability to change DTC characteristics without using a DAD. However, the DTC (322) has a higher production cost and may have a higher fault tendency due to its complexity.
在下文中,例示本發明之裝置及方法之實施例,其等討論一個可能邏輯數位交易文件或數位交易文件類型及用於一金融交易之其關聯符記。 所例示之邏輯數位交易文件/數位交易文件及其關聯符記涉及作為一主要數位交易文件(主要信用卡)之一信用卡,以及其他副數位交易文件(副信用卡)及其等關聯符記。然而,應理解,本發明可更廣泛應用至其他類型之數位交易文件及其等關聯符記,諸如儲值卡、會員卡、運輸卡、駕駛執照、護照、年齡證明卡、身份證及其他金融及非金融交易文件。 In the following, embodiments of the apparatus and method of the present invention are illustrated, which discuss a possible logical digital transaction file or digital transaction file type and its associated token for a financial transaction. The illustrated logical digital transaction file/digital transaction file and its associated token involve a credit card as a primary digital transaction file (primary credit card), and other secondary digital transaction files (secondary credit cards) and their associated tokens. However, it should be understood that the present invention can be more widely applied to other types of digital transaction files and their associated tokens, such as stored value cards, membership cards, transportation cards, driver's licenses, passports, age verification cards, identity cards and other financial and non-financial transaction files.
將一數位交易文件視為意謂卡、文件或其他實體物件或(例如)在一銀行帳戶之情況中,意謂該銀行帳戶在一運算系統中之實體存在。一「邏輯」數位交易文件係數位交易文件之一表示,其包含與特定數位交易文件相關之資料。資料可包含文件之一唯一識別(唯一ID)、到期日或唯一識別該數位交易文件之任何其他此資訊以及關於數位交易之其他資訊。 A digital transaction document is considered to mean a card, document or other physical object or, in the case of a bank account, for example, the physical presence of the bank account in a computing system. A "logical" digital transaction document is a representation of a digital transaction document that contains data related to a particular digital transaction document. The data may include a unique identification of the document (unique ID), an expiration date or any other such information that uniquely identifies the digital transaction document and other information about the digital transaction.
舉例而言,針對一信用卡,唯一ID係一個人/主帳號(PAN),且(若干)關聯符記係PAN之一替代號碼,其係與經替代PAD相同之數位號碼,但係已經安全產生之一不同號碼。 For example, for a credit card, the unique ID is a personal/primary account number (PAN), and the associated token(s) is a replacement number for the PAN, which is the same digits as the replaced PAD, but a different number that has been securely generated.
圖4展示根據本發明之一實施例之一系統中之例示性元件。一個元件係一數位交易卡(DTC)(412)且另一元件係一資料輔助器件(DAD)(414)。在此實例中,DAD係一智慧型電話,但其可係一電腦平板、某一其他形式之攜帶型計算DAD或為了本發明之目的製造之一特定DAD。 FIG. 4 shows exemplary components in a system according to an embodiment of the present invention. One component is a digital transaction card (DTC) (412) and another component is a data-assisted device (DAD) (414). In this example, the DAD is a smart phone, but it could be a computer tablet, some other form of portable computing DAD, or a specific DAD manufactured for the purposes of the present invention.
系統用於在兩個例示性數位交易器件之一者處之支付,數位交易器件包含一銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機(16A)及線上交易終端機(16B)。線上交易終端機可包含一個人電腦(PC)或經啟用用於此等線上(無卡/無DTC)交易之任何其他器件。 The system is used for payment at one of two exemplary digital transaction devices, including a point of sale/electronic fund transfer system (POS/EFTPOS) terminal (16A) and an online transaction terminal (16B). The online transaction terminal may include a personal computer (PC) or any other device enabled for such online (card-not-present/DTC-not-present) transactions.
DTC(412)具有一主要數位交易文件(419),其係一主要信用卡。作為一邏輯數位交易文件,主要信用卡經載入至DTC(412)上且可在供應至 使用者(420)之前完成此。此外,與主要信用卡相關聯之(若干)符記可在供應至使用者之前經載入至DTC上。使用者可將智慧型電話(414)連結(415)至DTC(412),此係因為DTC(412)經供應有預載入之主要數位交易文件(主要信用卡)(419)及(若干)關聯符記。在展示一DTC(412)之初始設置之圖2、圖3及圖7中進一步詳述連結程序(415)。 The DTC (412) has a primary digital transaction file (419) which is a primary credit card. As a logical digital transaction file, the primary credit card is loaded onto the DTC (412) and this can be done before being supplied to the user (420). In addition, the token(s) associated with the primary credit card can be loaded onto the DTC before being supplied to the user. The user can link (415) the smart phone (414) to the DTC (412) because the DTC (412) is supplied with the pre-loaded primary digital transaction file (primary credit card) (419) and the associated token(s). The linking process (415) is further detailed in Figures 2, 3 and 7 showing the initial setup of a DTC (412).
圖4展示建立一DTC(412)且將DTC(412)發行至一使用者(420)之例示性步驟。可存在提供一DTC(412)之若干行動者,包含一個入化公司402、一DTC(卡)積分器(404)、一DTC(卡)製造商(406)及一安全性供應者(408)。安全性供應者(408)提供與一給定數位交易文件相關聯之(若干)符記。發行一DTC(412)之其他行動者可包含一發行金融機構(440),諸如一銀行或其他類似方。發行金融機構(440)可充當一安全性請求者(符記請求者)(442),其經供應有(例如)一種子(444)。發行金融機構(440)之客戶服務(446)可與使用者(420)互動,使用者(420)請求DTC(412)且將所需資訊供應至金融機構,諸如名稱、出生日期、其DAD之細節(在一智慧型電話之實例中,可為IMEI號碼或智慧型電話之另一適合唯一ID)。 FIG. 4 shows exemplary steps for establishing a DTC (412) and issuing the DTC (412) to a user (420). There may be several actors providing a DTC (412), including an entry company 402, a DTC (card) integrator (404), a DTC (card) manufacturer (406), and a security provider (408). The security provider (408) provides token(s) associated with a given digital transaction document. Other actors issuing a DTC (412) may include an issuing financial institution (440), such as a bank or other similar party. The issuing financial institution (440) may act as a security requester (token requester) (442), which is provided with, for example, a seed (444). The issuing financial institution's (440) customer service (446) may interact with the user (420), who requests a DTC (412) and supplies the financial institution with the required information, such as name, date of birth, details of their DAD (which in the case of a smartphone may be the IMEI number or another suitable unique ID for the smartphone).
金融機構(440)可接著產生一安全性密碼編譯金鑰,其經提供至個人化公司(402)用於建立DTC(412)。 The financial institution (440) may then generate a secure cryptographic key which is provided to the personalization company (402) for use in establishing the DTC (412).
在此實施例中,DTC(412)係一信用卡式交易卡。DTC(412)具有一EMV晶片(其中EMV係Europay、萬事達卡及Visa(Europay,MasterCard,and Visa)之一縮寫)(數位交易處理單元(DTPU))(422)、一按鈕(423),其可用於(例如)藉由使用用於完成連結之BluetoothTM而使DTC與智慧型電話(414)連結。DTC(412)亦具有一DTC顯示器(424),其可係用於展示一所選擇邏輯數位交易文件之一唯一ID之一簡化圖形使用者介面,該唯一ID 經載入至DTC上,且實施於DTC(412)上,使得其充當該數位交易文件。在DTC實施為一符記化數位交易文件之情況中,DTC顯示器(424)展示符記號碼。在圖4中展示之實例中,數位交易文件係一主要信用卡或複數個副信用卡之一者。 In this embodiment, the DTC (412) is a credit card type transaction card. The DTC (412) has an EMV chip (where EMV is an acronym for Europay, MasterCard, and Visa) (Digital Transaction Processing Unit (DTPU)) (422), a button (423) that can be used to connect the DTC to a smartphone (414), for example, by using Bluetooth ™ for completing the connection. The DTC (412) also has a DTC display (424) that can be used to display a simplified graphical user interface of a unique ID of a selected logical digital transaction file that is loaded onto the DTC and implemented on the DTC (412) so that it acts as the digital transaction file. In the case where the DTC is implemented as a tokenized digital transaction document, the DTC display (424) displays the token number. In the example shown in Figure 4, the digital transaction document is a primary credit card or one of a plurality of secondary credit cards.
DTC(412)亦具有顯示正在操作為其之特定數位交易文件之一到期日之構件。DTC亦具有用於擁有DTC之人(420)之名稱之一顯示器(428)之一空間。在一些實施例中,各及每一邏輯數位交易文件之名稱將相同,即,使用者(420)之名稱。然而,在其他實施例中,(例如)若一人使用DTC(412)用於個人使用及公司使用兩者,則與一特定邏輯數位交易文件相關聯之名稱可係不同的。在此點上,DTC名稱空間(428)可僅係一印刷名稱,或可係經啟用用於顯示不同名稱之一簡化圖形使用者介面(GUI)。可取決於針對一交易選擇之符記而顯示不同名稱。 The DTC (412) also has a component that displays an expiration date for the particular digital transaction document for which it is operating. The DTC also has a space for a display (428) for the name of the person (420) who owns the DTC. In some embodiments, the name of each and every logical digital transaction document will be the same, i.e., the name of the user (420). However, in other embodiments, the name associated with a particular logical digital transaction document may be different, for example, if a person uses the DTC (412) for both personal use and corporate use. In this regard, the DTC name space (428) may be just a printed name, or may be a simplified graphical user interface (GUI) enabled to display different names. The different names may be displayed depending on the token selected for a transaction.
為一智慧型電話之DAD(414)包含一智慧型電話介面(430),在圖4中,其為一螢幕(430)及鍵盤。替代地,智慧型電話可包含一觸控螢幕,使得不需要鍵盤。 The DAD (414) for a smart phone includes a smart phone interface (430), which in FIG4 is a screen (430) and a keyboard. Alternatively, the smart phone may include a touch screen so that a keyboard is not required.
圖4亦描繪一DTC(412)及一智慧型電話(414)之初始設置、建立及發行一DTC涉及之行動者及在交易中使用DTC。圖4亦展示DTC(412)至一智慧型電話(414)之連結(415)。亦圖解說明發行DTC之金融機構(440)(包含行動者)及DTC發行(在一些實施例中,包含主要信用卡之發行)之步驟之細節。 FIG. 4 also depicts the initial setup of a DTC (412) and a smart phone (414), the actors involved in establishing and issuing a DTC, and the use of the DTC in a transaction. FIG. 4 also shows the connection (415) of the DTC (412) to a smart phone (414). The details of the steps of issuing a DTC (440) (including actors) and DTC issuance (including the issuance of a major credit card in some embodiments) are also illustrated.
為一智慧型電話之DAD(414)具有一IMEI號碼或另一適合唯一ID以便唯一地識別智慧型電話。智慧型電話可使用Android及/或iOS作業系統或任何其他適合作業系統。在實施例中,智慧型電話(414)包含無線連接 技術,(例如)近場通信(NFC)及/或BluetoothTM或BluetoothTM LE。 The DAD (414) being a smart phone has an IMEI number or another suitable unique ID to uniquely identify the smart phone. The smart phone may use Android and/or iOS operating systems or any other suitable operating system. In an embodiment, the smart phone (414) includes wireless connection technology, such as near field communication (NFC) and/or Bluetooth TM or Bluetooth TM LE.
DTC(412)具有一DTC晶片(422),其可係認證智慧卡晶片(DTPU)(422)以便可通常操作以僅與一外部讀取/寫入器件傳遞資料。認證智慧卡晶片之實例可遵守以下認證標準ISO/IEC 7816或ISO/IEC 14443之一者或兩者。此外,認證智慧卡晶片可遵守其他標準,諸如通用準則EAL4+/EAL5+(ISO/IEC 15408資訊技術-安全性技術-針對IT安全性部分1至3之評估準則)、FIPS 140-2 3及4級、ISO/IEC 7816識別卡、積體電路卡部分1至5、ISO/IEC 14443識別卡-非接觸式積體電路卡-感應卡部分1至4及EMVCo。 The DTC (412) has a DTC chip (422) which may be a certified smart card chip (DTPU) (422) so as to be normally operable to communicate data only with an external read/write device. Examples of certified smart card chips may comply with one or both of the following certification standards ISO/IEC 7816 or ISO/IEC 14443. In addition, the certified smart card chip may comply with other standards such as Common Criteria EAL4+/EAL5+ (ISO/IEC 15408 Information Technology - Security Technology - Evaluation Criteria for IT Security Parts 1 to 3), FIPS 140-2 Level 3 and 4, ISO/IEC 7816 Identification Card, Integrated Circuit Card Parts 1 to 5, ISO/IEC 14443 Identification Card - Contactless Integrated Circuit Card - Proximity Card Parts 1 to 4, and EMVCo.
圖5展示在具有一DAD(514)(其係具有一智慧型電話介面(30)之一智慧型電話)之一系統中操作之一DTC(512)之一例示性設置。在此實例中,設置開始於使用者(520)自智慧型電話(514)提取IMEI號碼或另一適合唯一ID(503)。將為智慧型電話(514)之一唯一ID之IMEI號碼提供(505)至相關金融機構(502)(其亦稱為發行金融機構)。金融機構(502)記錄且處理經提交IMEI號碼及使用者細節,且在記錄此等細節之後,金融機構查找區段(534)查找記錄且使用種子/秘密金鑰(538)資訊填入一應用程式且經由一帶外(OOB)通知(544)將一應用程式連結(540)發送至智慧型電話(514)。經由(例如)自雲端(556)之一網際網路下載(554)而使智慧型電話(514)之一軟體應用程式(應用軟體(app))中之應用程式連結(540)可用,應用軟體可由使用者(520)在智慧型電話(514)上在其上點選而操作。當將種子/秘密金鑰(538)下載至智慧型電話(514)時,設置之此部分完成且使用者(520)可繼續連結智慧型電話與DTC(512)。 FIG5 shows an exemplary setup of a DTC (512) operating in a system having a DAD (514) which is a smart phone having a smart phone interface (30). In this example, the setup begins with a user (520) extracting the IMEI number or another suitable unique ID (503) from the smart phone (514). The IMEI number, which is a unique ID of the smart phone (514), is provided (505) to the relevant financial institution (502), also referred to as the issuing financial institution. The financial institution (502) records and processes the submitted IMEI number and user details, and after recording these details, the financial institution looks up the record in a lookup section (534) and uses the seed/secret key (538) information to populate an application and sends an application link (540) to the smartphone (514) via an out-of-band (OOB) notification (544). The application link (540) in a software application (app) in the smartphone (514) is made available via an internet download (554) such as from the cloud (556), and the app can be operated by the user (520) by clicking on it on the smartphone (514). When the seed/secret key (538) is downloaded to the smartphone (514), this portion of the setup is complete and the user (520) can continue to connect the smartphone to the DTC (512).
圖5亦展示具有展示一唯一ID(526)之DTC顯示器(524)之DTC (512),在此情況中,唯一ID(526)係主要信用卡之符記化號碼(有時稱為一動態符記號碼),即,主要邏輯數位交易文件導致DTC(512)表現為符記化數位交易文件(即,符記化主要信用卡)。 FIG. 5 also shows a DTC (512) having a DTC display (524) showing a unique ID (526), in which case the unique ID (526) is the tokenized number of the primary credit card (sometimes referred to as a dynamic tokenized number), i.e., the primary logical digital transaction document causes the DTC (512) to appear as a tokenized digital transaction document (i.e., a tokenized primary credit card).
圖5亦展示發行金融機構(502)充當安全性請求者(符記請求者)(504)且獲得金鑰(510)之角色,將金鑰(510)傳遞至客戶服務(508)且接著傳遞至查找(534),使用一計數器(536)開發種子/秘密金鑰(538)且接著經由應用軟體連結(540)將其傳遞至智慧型電話(514)。 Figure 5 also shows the issuing financial institution (502) acting as a security requester (token requester) (504) and obtaining a key (510), passing the key (510) to customer service (508) and then to lookup (534), using a counter (536) to develop a seed/secret key (538) and then passing it to the smartphone (514) via an application link (540).
圖6展示設置如由一個人化公司(602)提供之一DTC(612)之例示性步驟,其涉及一DTC積分器(604)及一非接觸式DTC製造商(606)兩者。個人化公司(602)亦搭配一安全性供應者(608)(其係產生各信用卡之一或多個符記之一符記供應者)工作,安全性供應者(608)繼而搭配發行金融機構(610)(其係一安全性請求者(符記請求者)(611))工作。金融機構(610)建立一種子(616),經由客戶服務(618)將種子(616)供應為載入有智慧型電話之IMEI或智慧型電話之另一適合唯一ID及安全性細節之一應用程式(640)。 FIG6 shows exemplary steps for setting up a DTC (612) such as provided by a personalization company (602), involving both a DTC integrator (604) and a contactless DTC manufacturer (606). The personalization company (602) also works with a security provider (608), which is a token provider that generates one or more tokens for each credit card, which in turn works with the issuing financial institution (610), which is a security requester (token requester) (611). The financial institution (610) creates a seed (616), which is provisioned via customer service (618) as an application (640) loaded with the IMEI of the smartphone or another suitable unique ID and security details for the smartphone.
以此方式,圖6證實一個例示性方法,其中DTC(612)可經供應經預載入有一主要邏輯數位交易文件(在此實例中為一主要信用卡)及其關聯符記。DTC(612)及智慧型電話(614)各具有主要邏輯數位交易文件及關聯符記之細節,使得使用者(620)可操作智慧型電話(614)以選擇DTC(612)上之主要邏輯數位交易文件,且接著選擇主要邏輯數位交易文件之關聯數位符記之一者,且以便導致DTC(612)充當符記化主要數位交易文件。 In this manner, FIG. 6 demonstrates an exemplary method in which a DTC (612) may be provided preloaded with a primary logical digital transaction document (in this example, a primary credit card) and its associated token. The DTC (612) and the smart phone (614) each have details of the primary logical digital transaction document and the associated token, so that a user (620) may operate the smart phone (614) to select the primary logical digital transaction document on the DTC (612), and then select one of the primary logical digital transaction document's associated digital tokens, and so as to cause the DTC (612) to act as the tokenized primary digital transaction document.
在此點上,應意識到,在一些實施例中,邏輯數位交易文件可部分儲存在DTC(612)上,且該等邏輯數位交易文件之其他部分可儲存在智慧型電話(614)上,使得智慧型電話可經操作以選擇一特定邏輯數位交易文 件且選擇與用於一交易所要之邏輯數位交易文件相關聯之一符記,且使得智慧型電話可導致DTC(612)充當與所選擇邏輯數位交易文件及所選擇關聯符記相關聯之符記化數位交易文件。 At this point, it should be appreciated that in some embodiments, logical digital transaction files may be partially stored on the DTC (612) and other portions of the logical digital transaction files may be stored on the smart phone (614), such that the smart phone may be operated to select a particular logical digital transaction file and select a token associated with the logical digital transaction file for a transaction, and such that the smart phone may cause the DTC (612) to act as a tokenized digital transaction file associated with the selected logical digital transaction file and the selected associated token.
圖7展示一例示性實施例,其中已具有載入至其上之一主要邏輯數位交易文件(主要信用卡)及關聯符記之一DTC(712)可具有經由智慧型電話(714)載入至其上之額外副邏輯數位交易文件(18)及其等(若干)關聯符記。在此實例中,第二邏輯數位交易文件(18)係其他信用卡。 FIG. 7 shows an exemplary embodiment in which a DTC (712) that already has a primary logical digital transaction file (primary credit card) and associated tokens loaded thereon may have additional secondary logical digital transaction files (18) and their associated tokens loaded thereon via a smart phone (714). In this example, the second logical digital transaction file (18) is another credit card.
在此實例中,使用者(720)經由主要卡發行金融機構(702)之客戶服務區段(708)將額外卡(18)細節供應或鍵入至主要卡發行金融機構(702)。在一項實施例中,主要卡(或DTC)發行金融機構可藉由進行具有一參考號碼之一轉帳或具有兩個唯一貨幣量之一轉帳及一貸款(其可在增加至主要卡之額外信用卡(18)之各者上進行)而進行驗證。當使用者(720)具有由特定副卡(或DTC)發行金融機構(716)發行之一清單(710)時,清單將展示具有一參考號碼之一轉帳或具有兩個唯一量之一轉帳及一貸款。使用者(720)閱讀清單(710)且鍵入或提交來自清單之行細節以驗證使用者(720)係增加至主要卡(例如,如在圖4中表示)之各額外副信用卡之實際擁有者。當主要卡(或DTC)發行金融機構(702)對於使用者(720)係額外信用卡之正確擁有者滿意時,主要卡發行金融機構可請求使用者將額外卡加入該金融機構(702)且讀取卡以提取用於使用(例如)一POS/EFTPOS終端機之密碼之公開加密密鑰。替代地,主要金融機構(702)可將一請求發送至金融機構(716),金融機構(716)已針對用於一POS/EFTPOS終端機處之一密碼中之公開加密密鑰發行額外卡。當主要卡發行金融機構(702)對於使用者(720)係額外卡(18)之正確擁有者滿意時,機構(702)可經由一OOB訊息將碼發 送至使用者註冊智慧型電話(714)。接著,使用者(720)具有碼,當選擇碼時,其可用於將選自智慧型電話(714)之副邏輯數位交易文件(副信用卡)之一者載入DTC(712)。 In this example, the user (720) supplies or enters the additional card (18) details to the primary card issuing financial institution (702) through the customer service section (708) of the primary card issuing financial institution (702). In one embodiment, the primary card (or DTC) issuing financial institution can verify by making a transfer with a reference number or a transfer with two unique monetary amounts and a loan (which can be made on each of the additional credit cards (18) added to the primary card). When the user (720) has a list (710) issued by a specific secondary card (or DTC) issuing financial institution (716), the list will show a transfer with a reference number or a transfer with two unique amounts and a loan. The user (720) reads the list (710) and enters or submits row details from the list to verify that the user (720) is the actual owner of each additional secondary credit card added to the primary card (e.g., as shown in FIG. 4). When the primary card (or DTC) issuing financial institution (702) is satisfied that the user (720) is the correct owner of the additional credit card, the primary card issuing financial institution may request the user to add the additional card to the financial institution (702) and read the card to extract the public encryption key for a password used to use, for example, a POS/EFTPOS terminal. Alternatively, the primary financial institution (702) may send a request to a financial institution (716) that has issued additional cards for a public encryption key in a password for use at a POS/EFTPOS terminal. When the primary card issuing financial institution (702) is satisfied that the user (720) is the correct owner of the additional card (18), the institution (702) may send the code to the user's registered smartphone (714) via an OOB message. The user (720) then has the code, which when selected, can be used to load one of the secondary logical digital transaction files (secondary credit cards) selected from the smartphone (714) into the DTC (712).
在實施例中,可使用圖7中展示之方法論與(若干)副卡同時發行與(若干)副卡18相關聯之數位符記。替代地,可在(若干)副卡之發行之後但仍使用類似於圖7中展示之一方法論發行符記,其中使用上文論述之轉帳/貸款方法驗證若干符記或各符記。 In an embodiment, a digital token associated with a secondary card(s) 18 may be issued simultaneously with the secondary card(s) using the methodology shown in FIG. 7. Alternatively, the token may be issued after the secondary card(s) are issued but still using a methodology similar to that shown in FIG. 7, wherein the token(s) or tokens are verified using the transfer/loan method discussed above.
圖8展示用於藉由針對額外信用卡(818)之各者增加額外支付符記而增加額外安全性之程序步驟,經由客戶服務區段(808)經由OOB(810)而將額外安全性符記提供至智慧型電話(814)。針對一交易,選擇一個符記以作為一符記化數位交易文件實施於DTC(812)上,其中DTC(812)在顯示器中顯示符記號碼。符記供應者(806)亦可係用於DTC(812)之晶片(822)之一供應者。符記供應者產生用作信用卡之PAN之一替代之符記。使用者可僅增加符記一次,或(例如)若符記經設定在一特定日期之後到期或若符記係一次性使用符記,則在一定期基礎上增加符記。若符記經指定用於特定交易類型且使用者希望進行該等種類之交易,則使用者亦可尋找進一步符記。 FIG. 8 shows the process steps for adding additional security by adding additional payment tokens for each of the additional credit cards (818), the additional security tokens being provided to the smart phone (814) via the customer service section (808) via OOB (810). For a transaction, a token is selected to be implemented on the DTC (812) as a tokenized digital transaction document, wherein the DTC (812) displays the token number in a display. The token provider (806) may also be a provider of a chip (822) for the DTC (812). The token provider generates a token that is used as a substitute for the PAN of the credit card. The user may add a token only once, or add tokens on a regular basis, for example, if the token is set to expire after a specific date or if the token is a one-time use token. The User may also search for further tokens if the tokens are designated for specific transaction types and the User wishes to conduct those types of transactions.
圖9展示一DTC(912)可使用不同類型之智慧型電話進行操作。然而,DTC僅可與一個DAD(智慧型電話)連結而排除全部其他DAD。 FIG. 9 shows that a DTC (912) can be operated using different types of smart phones. However, the DTC can only be linked to one DAD (smart phone) to the exclusion of all other DADs.
如圖9中展示,一使用者可決定購買一新智慧型電話(952),在該情況中,DTC(912)將需要被更新以便能夠與新智慧型電話連結。在此實例中,一舊智慧型電話(950)與DTC(912)連結,但使用者希望將新智慧型電話(952)與DTC(912)連結。連結係(例如)一雙向加密傳輸。DTC(912)可 在製造時經載入匹配種子及動態金鑰以便能夠僅與一個智慧型電話(950)連結。為了使DTC(912)與新智慧型電話(952)連結,自(例如)一動態金鑰建構一動態碼或可使一種子可供經驗證擁有者使用。使用動態金鑰或種子以使舊智慧型電話(950)與DTC(912)斷開或解除連結。DTC可接著經載入有一匹配種子及/或動態金鑰以便與新智慧型電話(952)連結。種子及動態金鑰係基於智慧型電話之IMEI或智慧型電話之另一適合唯一ID。應理解,使DTC連結至智慧型電話之碼必須對於各DTC係唯一的,且對於各DTC之序號可係唯一的。在此點上,一智慧型電話與一DTC之間之連結可僅基於匹配IMEI或智慧型電話之另一適合唯一ID及DTC序號在智慧型電話與DTC之間發生。 As shown in FIG. 9 , a user may decide to purchase a new smartphone (952), in which case the DTC (912) will need to be updated in order to be able to link with the new smartphone. In this example, an old smartphone (950) is linked with the DTC (912), but the user wishes to link the new smartphone (952) with the DTC (912). The link is, for example, a two-way encrypted transmission. The DTC (912) may be loaded with matching seeds and dynamic keys at the time of manufacture so that it can only be linked with one smartphone (950). In order for the DTC (912) to link with the new smartphone (952), a dynamic code may be constructed from, for example, a dynamic key or a seed may be made available to the authenticated owner. A dynamic key or seed is used to disconnect or unlink the old smartphone (950) from the DTC (912). The DTC may then be loaded with a matching seed and/or dynamic key in order to link with the new smartphone (952). The seed and dynamic key are based on the IMEI of the smartphone or another suitable unique ID of the smartphone. It should be understood that the code linking the DTC to the smartphone must be unique for each DTC, and the serial number for each DTC may be unique. In this regard, the link between a smartphone and a DTC may occur only between the smartphone and the DTC based on the matching IMEI or another suitable unique ID of the smartphone and the DTC serial number.
圖10展示在用於一智慧型電話(1014)與一DTC(1012)之初始配對(連結)之一實施例程序中之一智慧型電話(1014)上之螢幕。 FIG. 10 shows a screen on a smart phone (1014) during an example process for initial pairing (linking) of a smart phone (1014) with a DTC (1012).
在第一螢幕(1002)中,智慧型電話顯示一標題「設置」(1004),且在標題(1004)下係一「設置」按鈕(1006),且在按鈕(1006)下係展示「網際網路連接」之一指示符。 In the first screen (1002), the smart phone displays a title "Settings" (1004), and under the title (1004) is a "Settings" button (1006), and under the button (1006) is an indicator showing "Internet Connection".
下一螢幕(1032)展示一標題「狀態」(1034),其包含一「申請碼」按鈕(1036)及一「金鑰」鍵入欄位(1038),以及一「與卡配對」(替代地,「與DTC配對」)按鈕(1040)。在最後螢幕(1042)中,顯示一「恭喜」訊息(1044),其對使用者(1020)指示智慧型電話(1014)經連結至DTC(1012)。 The next screen (1032) displays a title "Status" (1034) that includes an "Apply Code" button (1036) and a "Key" input field (1038), as well as a "Pair with Card" (alternatively, "Pair with DTC") button (1040). In the final screen (1042), a "Congratulations" message (1044) is displayed indicating to the user (1020) that the smartphone (1014) is linked to the DTC (1012).
在一實施例中,亦藉由連結按鈕(1023)而使智慧型電話(1014)與DTC(1012)連結,連結按鈕(1023)經按壓且保持(1046)使得其可連結至智慧型電話(1014)。 In one embodiment, the smart phone (1014) is also connected to the DTC (1012) by a connection button (1023), which is pressed and held (1046) so that it can be connected to the smart phone (1014).
圖11展示具有具備若干指示符之一前側(1112f)及一背側(1112r)之一DTC(1112)之一實施例,該等指示符展示(例如)與儲存在DTC(1112)上之主要邏輯數位交易文件相關之個人化細節。在DTC之前側(1112f)上印刷有主要卡(1119)之標誌(1104),以及附接至DTC(1112)之一全像(1106)。DTC(1112)亦可顯示主要卡到期日(1108)。在DTC(1112)之背側上,可存在用於主要卡擁有者之簽名(1110)之一面板。亦可印刷有卡驗證值(CVV)(1114),以及其他識別細節。在一些實施例中,在細節經印刷或以其他方式永久標記於DTC(1112)上之情況中,細節將僅關於儲存在DTC(1112)上之主要邏輯數位交易文件,諸如一使用者之名稱、CVV、到期日。在一DTC(1112)在可變更GUI中顯示細節之情況中,該等細節可關於目前表達為DTC之數位交易文件之邏輯數位交易文件(包含主要邏輯數位交易文件及副邏輯數位交易文件)。 FIG. 11 shows an embodiment of a DTC (1112) having a front side (1112f) and a back side (1112r) with several indicators showing, for example, personalized details associated with the primary logical digital transaction file stored on the DTC (1112). Printed on the front side (1112f) of the DTC is the logo (1104) of the primary card (1119), as well as a hologram (1106) attached to the DTC (1112). The DTC (1112) may also display the primary card expiration date (1108). On the back side of the DTC (1112), there may be a panel for the signature (1110) of the primary card owner. The card verification value (CVV) (1114) may also be printed, as well as other identifying details. In some embodiments, where the details are printed or otherwise permanently marked on the DTC (1112), the details will only be about the primary logical digital transaction document stored on the DTC (1112), such as a user's name, CVV, expiration date. Where a DTC (1112) displays details in a changeable GUI, the details may be about the logical digital transaction document (including the primary logical digital transaction document and the secondary logical digital transaction document) currently represented as the digital transaction document of the DTC.
在一例示性交易中,商家檢查一有效DTC可包含以下:1.DTC(1112)包含一全色DTC發行者商標,2.DTC號碼(或替代地,主要卡號碼)係12至19個數字之一有效長度,3.顯示於DTC顯示器上之DTC號碼之前四個數字與直接印刷在下方之數字相同,4.到期日在未來且按正確格式「MM/YY」,5.全像或全像(Holomag)帶可位於DTC之前側或背側。若位於DTC之前側,則其可位於商標上方,若位於DTC之背側,則其可位於簽名面板之上方或下方,6.一磁條存在於DTC上且位於簽名面板之上方,且應看上去平滑且 筆直而無篡改之標記。在一些DTC上,可代替磁條而使用全像帶,及7.印刷於簽名面板上之四個數字必須匹配帳號之後四個數字,接著為三數位卡驗證碼(CVC)號碼。 In an exemplary transaction, the merchant checks for a valid DTC may include the following: 1. The DTC (1112) contains a full color DTC issuer logo, 2. The DTC number (or alternatively, the primary card number) is a valid length of 12 to 19 digits, 3. The first four digits of the DTC number displayed on the DTC display are the same as the digits printed directly below, 4. The expiration date is in the future and in the correct format "MM/YY", 5. The hologram or hologram strip may be located on the front or back of the DTC. If located on the front of the DTC, it may be located above the logo, if located on the back of the DTC, it may be located above or below the signature panel, 6. A magnetic strip is present on the DTC and is located above the signature panel and should appear smooth and straight with no signs of tampering. On some DTCs, a full video tape may be used instead of a magnetic stripe, and 7. The four digits printed on the signature panel must match the last four digits of the account number, followed by the three-digit Card Verification Code (CVC) number.
圖12A展示使用智慧型電話(1214)選擇一不同邏輯數位交易文件(不同信用卡)用於針對使用所選擇邏輯數位交易文件之一交易更新DTC(1212)之一例示性實施例。第一智慧型電話螢幕(1202)具有一「登入」標題,接著為選擇安全性類型之三個按鈕,包含一「PIN(個人識別號碼)」按鈕(1204)、一「滑動」按鈕1206及一「生物特徵」按鈕(1208)。使用者(1220)選擇選項(1204)、(1206)或(1208)之一者,接著智慧型電話(1214)顯示下一螢幕(1210),其展示一「支付選項」標題,在該標題下方展示一「當前」標題(1211),其指示當前在DTC(1212)上操作之文件。在此實例中,智慧型電話螢幕(1210)展示當前操作文件係一「VISA」卡(1213)。 12A shows an exemplary embodiment of using a smart phone (1214) to select a different logical digital transaction file (different credit card) for updating a DTC (1212) for a transaction using the selected logical digital transaction file. The first smart phone screen (1202) has a "Login" title followed by three buttons for selecting the security type, including a "PIN (Personal Identification Number)" button (1204), a "Slide" button 1206, and a "Biometrics" button (1208). The user (1220) selects one of the options (1204), (1206) or (1208), and then the smart phone (1214) displays the next screen (1210), which displays a "Payment Options" title, and below the title displays a "Current" title (1211), which indicates the file currently operating on the DTC (1212). In this example, the smart phone screen (1210) shows that the current operating file is a "VISA" card (1213).
使用者可操作一螢幕(1210)以選擇可在DTC(1212)上操作且在「變更為」標題(1215)下方列出之四個其他文件(信用卡)之一者。用於金融交易之額外文件包含「VISA」按鈕(1217)、「萬事達」按鈕(1218)、「銀行轉帳」按鈕(1219)及「美國運通」按鈕(1221)。使用者(1220)選擇「變更為」標題下方之文件之一者,此接著導致智慧型電話(1214)顯示下一螢幕(1252),其顯示訊息「支付方法」(1234),在該訊息下方顯示兩個按鈕,「是」按鈕(1236)及「否」按鈕(1238)。使用者(1220)可按壓該等按鈕之一者以判定萬事達卡是否將係較佳支付方法。 The user can operate a screen (1210) to select one of four other files (credit cards) that are available on the DTC (1212) and listed under the "Change To" heading (1215). The additional files used for financial transactions include a "VISA" button (1217), a "MasterCard" button (1218), a "Bank Transfer" button (1219), and an "American Express" button (1221). The user (1220) selects one of the files under the "Change To" heading, which then causes the smart phone (1214) to display the next screen (1252), which displays the message "Payment Method" (1234), and below the message are two buttons, a "Yes" button (1236) and a "No" button (1238). The user (1220) may press one of the buttons to determine whether MasterCard would be the preferred payment method.
下一智慧型電話螢幕(1242)展示針對使用者之安全性選項,其具有「變更符記」標題(1244)及一「是」按鈕(1246)以及「否」按鈕(1248)。在螢幕(1242)處,使用者可選擇(例如)是否變更針對目前交易文件操作之 目前符記。若選擇「是」(1246),則使用者可接著經呈現一關聯符記清單以便能夠選擇該等所列出符記之一者。如先前提及,在各項實施例中,符記可在清單中僅呈現為符記號碼。在其他實施例中,符記可以符號呈現為(例如)圖式。 The next smart phone screen (1242) displays security options for the user, with a "Change Token" title (1244) and a "Yes" button (1246) and a "No" button (1248). At screen (1242), the user can select, for example, whether to change the current token for the current transaction file operation. If "Yes" (1246) is selected, the user may then be presented with a list of associated tokens so that one of the listed tokens can be selected. As previously mentioned, in various embodiments, the token may be presented in the list simply as a token number. In other embodiments, the token may be presented as a symbol, for example, as a diagram.
下一智慧型電話螢幕(1242)展示狀態且包含「狀態」標題(1254),在其下方係展示「生物特徵設定/不設定」(1256)之一指示符,螢幕(1242)亦展示指令「觸控卡」(替代地,「觸控DTC」)(1256),以及展示智慧型電話(1214)及DTC已連結之一指示符「卡連結」(替代地,「DTC連結」)(1258)。 The next smart phone screen (1242) displays the status and includes a "Status" heading (1254), below which is an indicator that reads "Biometrics Set/Not Set" (1256). The screen (1242) also displays the command "Touch Card" (alternatively, "Touch DTC") (1256), and an indicator that reads "Card Linked" (alternatively, "DTC Linked") (1258) indicating that the smart phone (1214) and the DTC are linked.
智慧型電話(1214)接著將資料傳輸至DTC(1212)以便使用新選擇文件及符記細節更新DTC,且使得DTC GUI顯示器(1224)展示新選擇文件(信用卡)號碼(1260)作為符記化號碼。在其中DTC(1212)僅實施一個文件(信用卡)之一實施例中,作為一額外安全性預防,DTC(1212)亦可印刷單一信用卡之4個前導數字(1267),使得與該信用卡相關聯之經顯示之全部符記號碼(1260)必須具有相同的4個前導數字。 The smartphone (1214) then transmits the data to the DTC (1212) to update the DTC with the new selection document and token details and causes the DTC GUI display (1224) to display the new selection document (credit card) number (1260) as the tokenized number. In one embodiment where the DTC (1212) implements only one document (credit card), as an additional security precaution, the DTC (1212) may also print the 4 leading digits (1267) of a single credit card so that all displayed token numbers (1260) associated with that credit card must have the same 4 leading digits.
智慧型電話接著顯示具有進一步安全性之螢幕(1262),其包含當由使用者(1220)按壓時在一面板(1268)中展示一次性PIN(OTP)之一「建立OTP」按鈕(1264)。 The smartphone then displays a screen (1262) with further security, including a "Create OTP" button (1264) which, when pressed by the user (1220), displays a one-time PIN (OTP) in a panel (1268).
使用者可接著將DTC(1212)呈現至一商家(1270),接著經由與有效信用卡(數位交易文件)發行金融機構(1274)之通信而處理(1272)DTC。 The user may then present the DTC (1212) to a merchant (1270), which then processes (1272) the DTC via communication with the issuing financial institution (1274) of the valid credit card (digital transaction document).
在一些例項中,一交易可超出標準限制且智慧型電話(1214)可在一螢幕(1280)上顯示一訊息「超出限制交易」(1282)。使用者(1220)可接著藉由按壓在邀請使用者授權交易之一訊息(1286)下方之「是」按鈕(1284) 而授權超出限制交易。替代地,使用者(1220)可按壓「否」按鈕(1288),使得交易不被授權且不繼續。 In some examples, a transaction may exceed standard limits and the smart phone (1214) may display a message "Exceeding Limit Transaction" (1282) on a screen (1280). The user (1220) may then authorize the exceeding limit transaction by pressing a "yes" button (1284) beneath a message (1286) inviting the user to authorize the transaction. Alternatively, the user (1220) may press a "no" button (1288) such that the transaction is not authorized and does not proceed.
圖12B(其描繪一無卡交易)係與圖12A類似之一視圖,其中智慧型電話亦顯示具有用於顯示與所選擇邏輯數位交易文件之所選擇符記相關聯之一唯一識別符(在此實例中,所選擇信用卡(數位交易文件)之符記化號碼(1260))之一面板(1263)之螢幕(1262)。智慧型電話螢幕(1261)亦在一標題「到期」(1267)下方顯示到期日(1267)。智慧型電話螢幕(1262)亦可在CVV顯示面板中顯示所選擇文件之CVV(1269)。 FIG. 12B (which depicts a card-not-present transaction) is a view similar to FIG. 12A , wherein the smart phone also displays a screen (1262) having a panel (1263) for displaying a unique identifier associated with a selected token of a selected logical digital transaction document (in this example, the tokenized number (1260) of the selected credit card (digital transaction document)). The smart phone screen (1261) also displays the expiration date (1267) below a heading "Expiration" (1267). The smart phone screen (1262) may also display the CVV (1269) of the selected document in the CVV display panel.
圖13展示使用本發明之一實施例中之系統之一例示性店內或實體卡(實體DTC)交易。在此實例中,使用者(1320)決定使用主要卡以進行一購買,且針對該卡選擇一符記。在DTC GUI顯示器(1324)上顯示符記化主要卡號碼。使用者(1320)將DTC(1312)呈現至商家POS/EFTPOS終端機(1316)(其係具有一EMV讀取器之數位交易器件)。EMV讀取器獲得細節,包含密碼、符記、符記到期日及符記請求者ID。POS/EFTPOS終端機經由一商家收單機構(1318)可能藉由使用卡軌(1332)而獲取主要信用卡之細節。接著經由一支付處理器且經由一安全性供應者(符記供應者)(1334)使用安全性程序傳遞安全符記化主要卡細節以解除符記化號碼以便判定PAN(或若非一信用卡文件,則一文件之其他類型之唯一ID),接著將PAN提供至主要卡發行金融機構(1336)以處理支付(或若非一信用卡文件,則其他類型之交易)。 FIG. 13 shows an exemplary in-store or physical card (physical DTC) transaction using the system in an embodiment of the present invention. In this example, the user (1320) decides to use a primary card to make a purchase and selects a token for the card. The tokenized primary card number is displayed on the DTC GUI display (1324). The user (1320) presents the DTC (1312) to the merchant POS/EFTPOS terminal (1316), which is a digital transaction device with an EMV reader. The EMV reader obtains details including the password, token, token expiration date, and token requester ID. The POS/EFTPOS terminal obtains the primary credit card details, possibly by using card track (1332), via a merchant acquirer (1318). The secure tokenized primary card details are then passed through a payment processor and through a security provider (token provider) (1334) using security procedures to de-tokenize the tokenized number in order to determine the PAN (or other type of unique ID on file if not a credit card on file), which is then provided to the primary card issuing financial institution (1336) to process the payment (or other type of transaction if not a credit card on file).
在一個例示性實施例中,在自DTC(1312)讀取主要卡細節之後,POS/EFTPOS終端機(1316)建立自細節(包含(例如)生物特徵(1338)及其他安全性(符記)保證資料(1340))產生之一密碼,其中將一號碼給定至來自自 DTC(1312)中之晶片(DTPU)獲取之細節之授權之類型及位準。密碼亦可包含商家POS/EFTPOS終端機識別號碼、購買價格及用於轉送至商家收單機構(1318)之其他相關細節。 In an exemplary embodiment, after reading the primary card details from the DTC (1312), the POS/EFTPOS terminal (1316) creates a password generated from the details (including (for example) biometrics (1338) and other security (token) assurance data (1340)), where a number is given to the type and level of authorization from the details obtained from the chip (DTPU) in the DTC (1312). The password may also include the merchant POS/EFTPOS terminal identification number, the purchase price and other relevant details for transmission to the merchant acquirer (1318).
圖13亦展示使用DTC(1312)上之主要信用卡使用一智慧型電話或經由網際網路(1342)之一選用線上或無卡交易。使用者自DTC(1312)或智慧型電話螢幕(1330)讀取信用卡號碼(1321)、到期日及CVV號碼,且線上鍵入該等細節或經由智慧型電話將該等細節讀出至一商家。商家擷取資訊且可使用經提供之正確授權碼發生交易。 Figure 13 also shows an online or card-not-present transaction using a major credit card on a DTC (1312) using one of the options of a smartphone or via the internet (1342). The user reads the credit card number (1321), expiration date and CVV number from the DTC (1312) or smartphone screen (1330) and types in the details online or reads them out to a merchant via a smartphone. The merchant captures the information and can proceed with the transaction using the correct authorization code provided.
圖13亦展示交易DTC(1312)可與一所選擇其他邏輯數位交易文件及關聯所選擇符記一起使用,其等之細節顯示於DTC GUI(1324)上,亦即其他邏輯數位交易文件符記化唯一ID(1344)。 FIG. 13 also shows that the transaction DTC (1312) can be used with a selected other logical digital transaction document and associated selected token, the details of which are displayed on the DTC GUI (1324), namely the other logical digital transaction document tokenized unique ID (1344).
以此方式,系統可用於實體卡(實體DTC)交易及無卡(無DTC)交易。 In this way, the system can be used for both physical card (physical DTC) transactions and card-not-present (no-DTC) transactions.
應理解,在本說明書中,術語「邏輯」係指針對各數位交易文件之一特性集合。特性可包含資料,諸如數位交易文件之唯一ID、擁有權資訊、到期日及類似者。識別資訊可係一唯一ID號碼。自表達一個數位交易文件至表達另一數位交易文件之DTC之一變更亦可稱為DTC「特質」之一變更。 It should be understood that in this specification, the term "logical" refers to a set of characteristics for each digital transaction document. Characteristics may include data such as a unique ID of the digital transaction document, ownership information, expiration date, and the like. The identification information may be a unique ID number. A change from a DTC expressing one digital transaction document to a DTC expressing another digital transaction document may also be referred to as a change in the "characteristics" of the DTC.
貫穿本說明書及隨後之發明申請專利範圍,除非內容脈絡另有要求,否則字組「包括(comprise)」及諸如「包括(comprises)」及「包括(comprising)」之變動將理解為意謂包含一陳述整數或步驟,或整數或步驟群組,而非排除任何其他整數或步驟或整數或步驟群組。 Throughout this specification and subsequent claims, unless the context otherwise requires, the word "comprise" and variations such as "comprises" and "comprising" will be understood to mean the inclusion of a recited number or step, or group of numbers or steps, but not the exclusion of any other number or step or group of numbers or steps.
熟習相關技術領域者將瞭解,可如實施例中詳述般對本發明作出許多變動及/或修改而不脫離如廣泛描述之本發明之精神或範疇。因此,本 實施例應被視為在全部態樣中係闡釋性而非限制性的。 Those skilled in the relevant art will appreciate that many variations and/or modifications may be made to the present invention as detailed in the embodiments without departing from the spirit or scope of the invention as broadly described. Therefore, the embodiments should be considered in all respects to be illustrative and not restrictive.
100:裝置 100:Device
102:數位交易器件/銷售點/銷售點電子轉帳系統(POS/EFTPOS)終端機/商家終端機 102: Digital transaction device/point of sale/electronic fund transfer system (POS/EFTPOS) terminal/merchant terminal
104:數位交易處理單元(DTPU) 104: Digital Transaction Processing Unit (DTPU)
106:智慧型電話/資料輔助器件(DAD) 106: Smartphone/Data Assisted Device (DAD)
108:數位交易卡(DTC) 108: Digital Transaction Card (DTC)
110:使用者介面 110: User Interface
112:電極/外部接觸板 112: Electrode/external contact plate
114:數位交易卡(DTC)收發器 114: Digital Transaction Card (DTC) transceiver
116:智慧型電話收發器 116: Smart phone transceiver
Claims (43)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| AU2016900264A AU2016900264A0 (en) | 2016-01-29 | System and method for secure transacting | |
| ??2016900264 | 2016-01-29 | ||
| AU2016900264 | 2016-01-29 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TW201801018A TW201801018A (en) | 2018-01-01 |
| TWI862471B true TWI862471B (en) | 2024-11-21 |
Family
ID=59396843
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW106103559A TWI862471B (en) | 2016-01-29 | 2017-02-02 | Digital transaction apparatus, data assistance device, digital transaction card, operating method and computer-redable medium for secure transaction |
Country Status (3)
| Country | Link |
|---|---|
| AU (3) | AU2017210754A1 (en) |
| TW (1) | TWI862471B (en) |
| WO (1) | WO2017127883A1 (en) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10915899B2 (en) * | 2017-03-17 | 2021-02-09 | Visa International Service Association | Replacing token on a multi-token user device |
| US11044244B2 (en) | 2018-09-18 | 2021-06-22 | Allstate Insurance Company | Authenticating devices via one or more pseudorandom sequences and one or more tokens |
| TWI770279B (en) * | 2018-09-19 | 2022-07-11 | 財團法人工業技術研究院 | Voucher verification auxiliary device, system and method thereof |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040215964A1 (en) * | 1996-03-11 | 2004-10-28 | Doug Barlow | Configuring and managing resources on a multi-purpose integrated circuit card using a personal computer |
| US20110244920A1 (en) * | 2009-10-23 | 2011-10-06 | Apriva, Llc | System and device for consolidating sim, personal token, and associated applications for electronic wallet transactions |
| US20120074232A1 (en) * | 2010-03-02 | 2012-03-29 | Douglas Spodak | Portable e-wallet and universal card |
| TW201333848A (en) * | 2012-02-07 | 2013-08-16 | Silicon Motion Inc | Secure digital card |
| US20140032419A1 (en) * | 2012-07-26 | 2014-01-30 | Lisa Anderson | Configurable payment tokens |
| US20150356551A1 (en) * | 2014-06-04 | 2015-12-10 | Mastercard International Incorporated | Multi-account payment card |
-
2017
- 2017-01-28 WO PCT/AU2017/000029 patent/WO2017127883A1/en not_active Ceased
- 2017-01-28 AU AU2017210754A patent/AU2017210754A1/en not_active Abandoned
- 2017-02-02 TW TW106103559A patent/TWI862471B/en active
-
2022
- 2022-12-07 AU AU2022283711A patent/AU2022283711A1/en not_active Abandoned
-
2024
- 2024-12-13 AU AU2024278427A patent/AU2024278427A1/en not_active Abandoned
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040215964A1 (en) * | 1996-03-11 | 2004-10-28 | Doug Barlow | Configuring and managing resources on a multi-purpose integrated circuit card using a personal computer |
| US20110244920A1 (en) * | 2009-10-23 | 2011-10-06 | Apriva, Llc | System and device for consolidating sim, personal token, and associated applications for electronic wallet transactions |
| US20120074232A1 (en) * | 2010-03-02 | 2012-03-29 | Douglas Spodak | Portable e-wallet and universal card |
| TW201333848A (en) * | 2012-02-07 | 2013-08-16 | Silicon Motion Inc | Secure digital card |
| US20140032419A1 (en) * | 2012-07-26 | 2014-01-30 | Lisa Anderson | Configurable payment tokens |
| US20150356551A1 (en) * | 2014-06-04 | 2015-12-10 | Mastercard International Incorporated | Multi-account payment card |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201801018A (en) | 2018-01-01 |
| WO2017127883A1 (en) | 2017-08-03 |
| AU2024278427A1 (en) | 2025-01-09 |
| AU2022283711A1 (en) | 2023-02-02 |
| AU2017210754A1 (en) | 2018-09-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11657384B2 (en) | Apparatus and method for emulating transactional infrastructure with a digital transaction processing unit (DTPU) | |
| US10776774B2 (en) | Biometric reader in card | |
| AU2023266392A1 (en) | Digital transaction system and method with a virtual companion card | |
| US12051058B2 (en) | Validating transactions | |
| US20200356984A1 (en) | Transaction recording | |
| AU2022279388B2 (en) | Apparatus and method for externally controlling a digital transaction processing unit (dtpu) | |
| AU2024278427A1 (en) | System and method for secure transacting | |
| AU2022291488A1 (en) | Apparatus and method for communicating with a digital transaction processing unit (dtpu) | |
| AU2024259771A1 (en) | Digital transaction apparatus and method | |
| AU2024259770A1 (en) | System and method for transacting | |
| TWI819998B (en) | Apparatus and method for directly communicating with a digital transaction processing unit (dtpu) |