US 11,954,196 B2
Mutual authentication of a user-controllable device or system containing sensitive or confidential
Nicolas Bacca, Paris (FR); and Olivier Tomaz, Orsay (FR)
Assigned to LEDGER, SAS, Paris (FR)
Appl. No. 17/051,519
Filed by LEDGER, SAS, Paris (FR)
PCT Filed Apr. 30, 2019, PCT No. PCT/FR2019/000064
§ 371(c)(1), (2) Date Oct. 29, 2020,
PCT Pub. No. WO2019/211533, PCT Pub. Date Nov. 7, 2019.
Claims priority of application No. 1870507 (FR), filed on Apr. 30, 2018.
Prior Publication US 2021/0240813 A1, Aug. 5, 2021
Int. Cl. H04L 29/06 (2006.01); G06F 21/31 (2013.01); G06F 21/44 (2013.01); G06F 21/62 (2013.01)
CPC G06F 21/44 (2013.01) [G06F 21/31 (2013.01); G06F 21/6245 (2013.01); G06F 2221/2103 (2013.01)] 5 Claims
OG exemplary drawing
 
1. A method for performing a transaction with an electronic device, the electronic device being configured to initiate an operational phase of the transaction upon receipt of a command from a user, and to perform, during the operational phase, a specific operation in order to provide the user with a determined service corresponding to the intended transaction, the method comprising, before the operational phase is performed:
a configuration phase of the electronic device, comprising configuring the electronic device with one preliminary question and one preliminary answer;
a preliminary authentication phase of the electronic device by the user, comprising:
sending, by the user, a preliminary question to the electronic device;
receiving, by the user, from the electronic device, an answer to the preliminary question; and
verifying, by the user, that the answer provided by the electronic device corresponds to an expected preliminary answer,
wherein the configuration phase is performed before preliminary authentication phase and the preliminary question and the preliminary answer are secret and supposedly known by the user, and wherein the electronic device is configured to enable the user to prevent execution of the operational phase if the user so wishes after receiving the answer from the electronic device;
an authentication phase of the user by the electronic device, comprising:
providing, by the electronic device, an operational question to the user;
receiving, by the electronic device, an answer from the user; and
comparing the user's answer with an expected operational answer;
the method further comprising deleting, by the electronic device, confidential data, if the user has failed to provide the preliminary question during a predetermined number of executions of the preliminary authentication phase of the electronic device by the user.