US2019260748A1PendingUtilityA1

Securing a transaction performed from a non-secure terminal

Assignee: SKEYECODEPriority: Nov 2, 2016Filed: Apr 29, 2019Published: Aug 22, 2019
Est. expiryNov 2, 2036(~10.3 yrs left)· nominal 20-yr term from priority
H04L 63/083H04L 2209/56H04L 63/0876G06Q 20/40145G06F 21/36H04L 9/3271H04L 63/0853G06F 2221/2103H04L 9/085G06F 21/32H04L 63/0861H04L 63/0884H04L 2209/16G06F 21/14H04L 2209/12G06F 2221/2133H04L 9/3231H04L 63/0428G06V 40/1318G06V 40/18G06V 40/168G06V 40/172G06V 40/1365G10L 17/24H04W 12/068H04W 12/069G09C 5/00
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a general aspect, a method for authenticating a user including: receiving, from a secure processor, a software component configured to generate an image frame including encrypted information; executing the software component, the execution of the software component generating the image frame; displaying the image frame; superimposing on the image frame a semi-transparent image including transparent and opaque pixels configured to make the encrypted information intelligible to the user; acquiring from the user a response depending on the information; and transmitting the acquired response to the secure processor, the user being authenticated by the secure processor as a function of the acquired response.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for authenticating a user, the method comprising:
 receiving a software component configured to generate an image frame including encrypted information;   executing the software component, the execution of the software component generating the image frame;   displaying the image frame;   superimposing, on the image frame, a semi-transparent image including transparent and opaque pixels configured to make the encrypted information intelligible to the user;   acquiring, from the user, a response depending on the encrypted information; and   transmitting the acquired response to a secure processor, the user being authenticated by the secure processor as a function of the acquired response.   
     
     
         2 . The method of  claim 1 , wherein the user is authenticated when the acquired response corresponds to the encrypted information and to a secret information known to the user and included in the secure processor. 
     
     
         3 . The method of  claim 1 , wherein the software component is executed once to generate the image frame that is displayed for authenticating the user, and then set to invalid. 
     
     
         4 . The method of  claim 1 , wherein the semi-transparent image is printed on a transparent tag, or displayed on a transparent display. 
     
     
         5 . The method of  claim 1 , wherein the information:
 includes a plurality of labels of a keypad having a key layout specific to the software component, the response from the user including key positions of keys of the keypad selected by the user,   includes a plurality of labels of a keypad and a validation code, the plurality of labels and the validation code being specific to the software component, the response from the user including key positions of keys of the keypad selected by the user, or   specifies a biometric challenge, the response from the user including biometric data inputted by the user using a biometric sensor.   
     
     
         6 . The method of  claim 1 , further comprising:
 generating the software component using the secure processor;   setting the software component to valid, by the secure processor, when transmitting the software component to the user terminal; and   setting the software component to invalid, by the secure processor, after a first period has elapsed or subsequent to receiving, by the secure processor, an execution report of the software component from the user terminal, an execution report corresponding with a software component set to invalid being rejected by the secure processor.   
     
     
         7 . The method of  claim 1 , wherein the software component is configured to generate encrypted parts of the encrypted image frame, the method further comprising:
 receiving a decryption mask from the secure processor;   applying a partial decryption operation to each generated encrypted image frame parts using a decryption mask to obtain partially decrypted image frame parts; and   inserting each partially decrypted image frame part in an image frame background to generate the image frame.   
     
     
         8 . The method of  claim 7 , wherein the partial decryption operation combines each pixel value provided by the software component with a corresponding pixel value of the decryption mask by an Exclusive OR operation. 
     
     
         9 . The method of  claim 1 , wherein the software component is encoded as a garbled circuit including circuit inputs, circuit outputs, logic gates and wires, each logic gate having two inputs and one output, each wire having a first end connected to one of the circuit inputs or to one of the logic gate outputs and a second end connected to one of the logic gate inputs or to one of the circuit outputs, the garbled circuit being generated by selecting a valid data for each binary state of each of the wires, and by computing, for one logic gate of the garbled circuit, truth table values as a function of each valid data of each input of the logic gate, each valid data of the output of the logic gate and a logic operation performed by the logic gate. 
     
     
         10 . A user terminal configured to:
 receive a software component configured to generate an image frame including encrypted information;   execute the software component, the execution of the software component generating the encrypted image frame;   display the encrypted image frame, the encrypted information being decrypted by superimposing, on the image frame, a semi-transparent image comprising transparent and opaque pixels configured to make the encrypted information intelligible to the user;   acquire from the user a response depending on the encrypted information in the displayed image frame; and   transmit the acquired response to a secure processor, the user being authenticated by the secure processor as a function of the acquired response.   
     
     
         11 . The terminal of  claim 10 , wherein the user is authenticated when the acquired response corresponds to the encrypted information and to a secret information known to the user and included in the secure processor. 
     
     
         12 . The terminal of  claim 10 , configured to execute the software component once to generate the image frame that is displayed for authenticating the user, and then set the software component to invalid. 
     
     
         13 . The terminal of  claim 10 , wherein the semi-transparent image is printed on a transparent tag, or displayed on a transparent display. 
     
     
         14 . The terminal of  claim 10 , wherein the information:
 includes a plurality of labels of a keypad having a key layout specific to the software component, the response from the user including key positions of keys of the keypad selected by the user,   includes a plurality of labels of a keypad and a validation code, the plurality of labels and the validation code being specific to the software component, the response from the user including key positions of keys of the keypad selected by the user, or   specifies a biometric challenge, the response from the user including biometric data inputted by the user using a biometric sensor.   
     
     
         15 . The terminal of  claim 10 , wherein the software component is configured to generate encrypted parts of the encrypted image frame, the terminal being further configured to:
 receive a decryption mask from the secure processor;   apply a partial decryption operation to each generated encrypted image frame part using the decryption mask to obtain partially decrypted image frame parts; and   insert each partially decrypted image frame part in an image frame background to generate the image frame.   
     
     
         17 . The terminal of claim  16 , wherein the partial decryption operation combines each pixel value provided by the software component with a corresponding pixel value of the decryption mask by an Exclusive OR operation. 
     
     
         18 . The terminal of  claim 10 , wherein the software component is encoded as a garbled circuit including circuit inputs, circuit outputs, logic gates and wires, each logic gate having two inputs and one output, each wire having a first end connected to one of the circuit inputs or to one of the logic gate outputs and a second end connected to one of the logic gate inputs or to one of the circuit outputs, the garbled circuit being generated by selecting a valid data for each binary state of each of the wires, and by computing, for one logic gate of the garbled circuit, truth table values as a function of each valid data of each input of the logic gate, each valid data of the output of the logic gate and a logic operation performed by the logic gate. 
     
     
         19 . The terminal of  claim 10 , wherein the secure processor is a secure element connected to a main processor of the terminal. 
     
     
         20 . The terminal of  claim 10 , wherein the secure processor belongs to a remote server linked to the terminal through a data transmission network. 
     
     
         21 . A secure element connected to a processor of a terminal and configured to:
 transmit, to a user terminal, a software component configured to generate an image frame including encrypted information, the encrypted information becoming intelligible to the user when a semi-transparent image including transparent and opaque pixels is superimposed on the image frame;   receive, from the user terminal, a response acquired from a user and depending on the encrypted information; and   authenticate the user when the acquired response corresponds with the encrypted information.   
     
     
         22 . A server linked to a user terminal through a data transmission network and configured to:
 transmit, to a user terminal, a software component configured to generate an image frame including encrypted information, the encrypted information becoming intelligible to the user when a semi-transparent image including transparent and opaque pixels is superimposed on the image frame;   receive, from the user terminal, a response acquired from a user and depending on the encrypted information; and   authenticate the user when the acquired response corresponds with the encrypted information.   
     
     
         23 . The server of  claim 22 , further configured to:
 generate the software component;   set the software component to valid, when transmitting the software component to the user terminal; and   set the software component to invalid after a first period has elapsed or subsequent to receiving an execution report of the software component from the user terminal, an execution report corresponding with a software component set to invalid being rejected.   
     
     
         24 . A computer program product loadable into a computer memory and comprising code portions which, when carried out by a computer, configure the computer to:
 receive a software component configured to generate an image frame including encrypted information;   execute the software component, the execution of the software component generating the encrypted image frame;   display the encrypted image frame, the encrypted information being decrypted by superimposing, on the image frame, a semi-transparent image comprising transparent and opaque pixels configured to make the encrypted information intelligible to the user;   acquire, from the user, a response depending on the encrypted information in the displayed image frame; and   transmit the acquired response to a secure processor, the user being authenticated by the secure processor as a function of the acquired response.

Join the waitlist — get patent alerts

Track US2019260748A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.