EP1649665A2 - Verfahren und system für doppeltgesicherte authentifikation eines benutzers während des zugriffs auf einen dienst mittels eines datenübertragungsnetzwerks - Google Patents

Verfahren und system für doppeltgesicherte authentifikation eines benutzers während des zugriffs auf einen dienst mittels eines datenübertragungsnetzwerks

Info

Publication number
EP1649665A2
EP1649665A2 EP04767677A EP04767677A EP1649665A2 EP 1649665 A2 EP1649665 A2 EP 1649665A2 EP 04767677 A EP04767677 A EP 04767677A EP 04767677 A EP04767677 A EP 04767677A EP 1649665 A2 EP1649665 A2 EP 1649665A2
Authority
EP
European Patent Office
Prior art keywords
authentication
user
network
access
actors
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP04767677A
Other languages
English (en)
French (fr)
Inventor
Estelle Transy
Fréderic DELMOND
Sébastien NGUYEN NGOC
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
France Telecom SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by France Telecom SA filed Critical France Telecom SA
Publication of EP1649665A2 publication Critical patent/EP1649665A2/de
Withdrawn legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/40User authentication by quorum, i.e. whereby two or more security principals are required
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0884Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/329Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload

Definitions

  • the present invention relates to the provision of services accessible via a data transmission network, such as services based on an IP (Internet Protocol) transport accessible in particular by the Internet, or conversational services over IP.
  • a data transmission network such as services based on an IP (Internet Protocol) transport accessible in particular by the Internet, or conversational services over IP.
  • IP Internet Protocol
  • a user when a user wishes to access such a service, he must connect to the IP network via an access network and a service provider (FS) such as a provider. Internet access. For this purpose, it must first be authenticated by an authentication server of the service provider. For this, he must send him an identifier of the form identifianfFS @ domaineFS and a password. Such authentication allows the service provider to personalize its services, for example by transmitting to the user a home page in which the name of the user appears.
  • FS service provider
  • an online banking service on the Internet requires an access network operator, an Internet service provider and the bank concerned.
  • Access to a corporate intranet requires at least one access network operator and the company concerned.
  • IP / PPP Point-to-Point Protocol
  • PSTN Switchched Telephone Network
  • ISDN Digital Integrated Services Network
  • ADSL Asymmetric Digital Subscriber Line
  • the present invention aims to eliminate these drawbacks by proposing a method for performing authentication for several actors independent of the network. This objective is achieved by providing a method for authenticating a user when attempting to access an actor in a data transmission network, this method comprising steps during which:
  • a user terminal sends an actor of the network an access request containing identification and authentication data of the user to the actor, the access request being transmitted via the network to an actor authentication server,
  • the authentication server performs a user authentication procedure on the basis of the identification and authentication data contained in the access request, and
  • the authentication server transmits to the user terminal a response message containing the result of the authentication of the user by the authentication server.
  • this method also comprises stages during which:
  • user authentication data with at least two actors in the network are calculated using at least one predefined cryptographic algorithm and at least one secret key specific to the user,
  • the terminal inserts the user identification data from said network actors and the calculated authentication data into the access request, and
  • the terminal transmits the access request to an access controller which transmits to each of the two actors a respective authentication request containing respectively the identification and authentication data of the user with said network actors, contained in the access request,
  • authentication servers of each of the actors execute a user authentication procedure, based on the identification and authentication data of the user, contained in the authentication requests, and
  • At least one of the authentication data is calculated by a module connected to the terminal.
  • this method comprises a prior step during which the terminal establishes a connection with a specialized server via the network, the random number being generated and transmitted to the terminal by the specialized server at following the establishment of the connection.
  • the access request sent by the terminal is transmitted to the specialized server which inserts therein the random number used to calculate the authentication data, the access request being then transmitted to the access controller which inserts the random number into the authentication requests transmitted to the two actors.
  • the authentication procedures executed by the actors' authentication servers include a step of searching for the user's secret key on the basis of the identification data contained in the authentication request, a step of calculating authentication data by executing the cryptographic algorithm with the user's secret key and the random number contained in the authentication request, and a step of comparing the authentication data contained in the authentication request, with the calculated authentication data, the user being correctly authenticated if the authentication data contained in the authentication request corresponds to the calculated authentication data.
  • the actors of the network include several actors among access providers offering the user access to the Internet network, IP service providers, and an access network operator. and IP transport.
  • the identification data inserted in the access request are in the form:
  • IdA represents the user identifier with the network operator
  • DomainA represents the identifier of the network actor in the network
  • the access controller determining the actors to which to transmit the authentication requests on the basis of the identifiers "DomainA" of the network actor contained in the access request.
  • the steps of authenticating the user by the authentication servers of the actors are carried out one after the other.
  • the user authentication steps by the actors' authentication servers are triggered substantially simultaneously.
  • the random number from which the data The authentication credentials are calculated is a random number modified with each connection attempt.
  • the user authentication procedures are carried out in accordance with the CHAP protocol.
  • the invention also relates to a system for authenticating a user when trying to access an actor of a data transmission network to which actors of the network are connected, and to which user terminals can access. via access networks, this system comprising:
  • each user terminal for transmitting requests for access to a network actor, these requests containing identification and authentication data of the user with the network actor, and
  • At least one authentication server for each of the actors in the network, designed to identify and authenticate users according to the identification and authentication data contained in the access requests received.
  • each user terminal comprises means for receiving a random number when establishing a connection with the network, cryptographic calculation means for applying at least one predefined cryptographic algorithm to the random number received in order to '' obtain user authentication data from at least two network players, and means for inserting user identification data from the two network players into each access request sent and calculated authentication data
  • the system further comprising an access controller comprising means for receiving the access requests from user terminals and transmitted by the network, means for extracting from each of the access requests the user identification and authentication data from at least two actors in the network, means for transmitting to each of the two actors a respective authentication request containing respectively the identification and authentication data of the user with the two actors, contained in the access request.
  • this system comprises an external module designed to connect to each of the user terminals and comprising means for receiving the random number from the terminal to which it is connected, means of cryptographic calculation to execute the cryptographic algorithm predefined on the basis of the random number, and for transmitting to the terminal at least one user authentication data item to a network actor obtained by cryptographic calculations.
  • the predefined algorithm is a cryptographic algorithm using a secret key specific to the user and stored by the module.
  • the module is a microprocessor card, each terminal comprising means for connecting to a microprocessor card.
  • the access controller further comprises means for receiving authentication reports from the user, issued by the actors in response to authentication requests, and means for transmit to the user terminal an authentication report on the basis of the reports received from the actors.
  • this system further comprises a specialized server connected to the network so as to be connected to the user terminals following the establishment of a connection of the terminal to the network, the specialized server comprising means for generating and transmitting a random number to each of the terminals with which a connection is established, and means for inserting the random number in each of the access requests sent by the terminals.
  • the specialized server is an HTTP server comprising an interface with the RADIUS protocol.
  • the access controller is a RADIUS Proxy.
  • each actor of the network comprises means for storing secret keys of users, means for determining the authentication data of the user from the actor by applying the predefined algorithm to the random number received in an authentication request and to the secret key of a user, and for comparing the result obtained with the user authentication data received in the authentication request, the user being correctly authenticated by the actor only if the result of the cryptographic calculation obtained is equal to the authentication data contained in the authentication request .
  • FIG. 1 schematically represents the architecture of a service supply system, according to the invention
  • FIG. 2 represents a sequencing diagram of steps which are executed in the system represented in FIG. 1, according to the method according to the invention.
  • the system shown in FIG. 1 comprises access networks 1, 2 to which teixnals 11 of users are connected. These access networks 1, 2 provide the terminals 11 with access to an IP transport network 5 via respective IP gateways 3, 4 adapted to the access network. All access networks, gateways and the IP transport network are implemented by an ORA / OTI operator of IP access and transport networks.
  • the IP transport network 5 allows users to access an Internet service provider 6, 7 or an IP service provider 8.
  • this system comprises, according to the invention, a specialized server 12 which delivers to users wishing to connect to the IP network, random numbers intended to be used during identification procedures, and an access controller 10 connected to the IP transport network 5 and to which the specialized server 12 transmits the access requests sent by the terminals 11.
  • the access controller 10 is designed to receive all requests for access to a provider 6, 7, 8 of access or of service, sent by the users on the networks 1, 2, via the gateway 3 , 4 corresponding to the network access 1, 2 employee, and the specialized server 12, and to direct these requests through the IP transport network to the provider 6, 7, 8 of access or service indicated in the request by the terminal of the 'user.
  • gateways 3, 4 can alternately provide the functions executed by the specialized server 12.
  • the user's terminal To access the IP network 5 via an access provider 6, 7 and to a particular service offered by a service provider 8 connected to the network, the user's terminal first performs a procedure d establishment of connection with the specialized server 12 to obtain a random RAND number. Next, the user's terminal sends an access request to the desired service provider via the access provider, which is transmitted successively by the IP gateway 3, 4 and by the specialized server 12 to the access controller 10. Upon receipt of such a request, the access controller 10 requests the access provider 6, 7 and the service provider 8 requested to authenticate the user. When the access provider and the service provider have sent their response concerning user authentication, the access controller sends an access authorization response to the user's terminal 11, depending authentication responses received.
  • the user's terminal 11 To access an IP service, the user's terminal 11 first of all executes a procedure 21 for establishing a connection with the specialized server 12 via an IP gateway 3, 4 accessible to the terminal, the address of the server specialist being for example known from the connection software installed in the terminal.
  • This procedure consists first of all in establishing a connection with the IP gateway 3, 4, for example in accordance with the LCP protocol (Link Control Protocol).
  • LCP protocol Link Control Protocol
  • a random RAND number is sent by the specialized server 12 to the terminal 11 (step 22), for example in the form of a challenge message 41 conforming to the CHAP protocol.
  • This random number is intended to serve as a basis for password calculations that can only be used for the current connection and access attempt.
  • password calculations are advantageously based on algorithms cryptography involving one or more secret keys and the random RAND number provided by the specialized server for the current connection.
  • the cryptographic algorithms can be implemented by the user's terminal, and / or preferably by a module 15 physically independent of the latter, for example of the microprocessor card type.
  • connection software installed in the terminal is also designed to interrogate the module 15.
  • the cryptography algorithm chosen is, for example, that which is implemented in the SIM (Subscriber Identification Module) cards of mobile terminals of the GSM (Global System for Mobile communications) type.
  • SIM Subscriber Identification Module
  • GSM Global System for Mobile communications
  • the terminal On receipt of the challenge message 41, the terminal extracts the random number RAND 42 therefrom and transmits it to the module 15 connected to the terminal (step 23).
  • the module 15 applies a cryptography algorithm to the random number received using a secret key from the user, which makes it possible to obtain a number 43 to be used as the authentication password for the user.
  • a cryptography algorithm to be used as the authentication password for the user.
  • the passwords AUTH1, AUTH2 possibly calculated by the module 15 are then transmitted in response to the terminal 11.
  • step 24 is at least partially executed by the terminal.
  • This request message 44 includes the identifiers ID1 and ID2 of the user respectively from the access provider and the chosen service, and the passwords AUTH1 and AUTH2 obtained by the cryptographic calculations.
  • the specialized server 12 On receipt of the request message 44, the specialized server 12 encapsulates this message in an access authorization request 45 (step 26).
  • This request is for example of the "Access-Request” type conforming to the RADIUS protocol (Remote Authentication Dial In User Service) comprising a username attribute "User-Name” equal to the two concatenated identifiers ID1
  • the request 45 is transmitted by the specialized server 12 to the access controller 10.
  • the access controller receives the request 45 and extracts the identification and authentication parameters therefrom. These parameters are transmitted in steps 28, 29 in authentication messages 46, 47 respectively to the authentication servers 16 of the access provider and of the chosen service provider.
  • the identification information ID1 and ID2 are for example of the form "IdA @ domainA", "IdA” allowing the user to be identified in a unique way with the access or service provider, and "domainA” allowing determine the domain name in the IP network of the server to which the corresponding authentication message must be sent.
  • These authentication messages 46, 47 each contain the identifier and the password corresponding to the recipient of the message, as well as the random number RAND.
  • the authentication server 16 Upon receipt of such an authentication message 46, 47, the authentication server 16 executes an authentication procedure 28, respectively 29.
  • This authentication procedure consists in identifying the user by means of the information of identification ID1, respectively ID 2, then determining the user's secret key by accessing a secret key database of authorized users, then calculating the user's password using this key secret and of the RAND number received, and finally to compare the password thus calculated with that which was received.
  • the authentication server has the same cryptographic algorithm as that used by the terminal 11 or the module 15.
  • the user is correctly authenticated only if the password calculated by the authentication server is identical to that which was received.
  • the result of this authentication in the form of success / failure, is transmitted to the access controller 10 in the form of an authentication report message 48, respectively 49.
  • the access controller 10 On receipt of the two authentication report messages 48, 49, coming respectively from the access provider 6, 7 and from the chosen IP service provider 8, the access controller 10 has the information necessary to manage the access rights of the user according to the policy of the operator ORA / OTI and executes a step 30 of generation of a message 50 of response to the access request sent by the user and transmits this message response to the specialized server 12.
  • This response message 50 contains the authentication reports sent by the access provider 6, 7, and by the chosen service provider 8.
  • authentication procedures 28 and 29 executed by the access provider 6, 7 and the service provider 8 can be executed simultaneously or else sequentially in any order.
  • the specialized server 12 executes a procedure 31 consisting in extracting from this response message the information to be returned to the user, then transmitting to the user terminal in a message 51, for example from type "CHAP-success” or "Chap-failure" for the CHAP protocol, the extracted information intended for it.
  • a user can be authenticated simultaneously by different actors of the network, for example benefit from an Internet access in which he has been authenticated by a secure online payment service, for example offered by a banking organization. It can also be authenticated by the operator ORA / OTI.
  • the invention which has just been described can be achieved by implementing a specialized server 12 of the HTTP server type, and an access controller 10 of the RADIUS proxy type, the specialized server comprising a RADIUS interface in order to be able to communicate with the controller access, the authentication servers are also RADIUS servers.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Lock And Its Accessories (AREA)
EP04767677A 2003-07-24 2004-07-13 Verfahren und system für doppeltgesicherte authentifikation eines benutzers während des zugriffs auf einen dienst mittels eines datenübertragungsnetzwerks Withdrawn EP1649665A2 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0309086A FR2858145A1 (fr) 2003-07-24 2003-07-24 Procede et systeme de double authentification securise d'un utilisateur lors de l'acces a un service par l'intermediaire d'un reseau ip
PCT/FR2004/001849 WO2005020538A2 (fr) 2003-07-24 2004-07-13 Procede et systeme de double authentification d'un utilisateur lors de l'acces a un service

Publications (1)

Publication Number Publication Date
EP1649665A2 true EP1649665A2 (de) 2006-04-26

Family

ID=33561077

Family Applications (1)

Application Number Title Priority Date Filing Date
EP04767677A Withdrawn EP1649665A2 (de) 2003-07-24 2004-07-13 Verfahren und system für doppeltgesicherte authentifikation eines benutzers während des zugriffs auf einen dienst mittels eines datenübertragungsnetzwerks

Country Status (4)

Country Link
US (1) US20060265586A1 (de)
EP (1) EP1649665A2 (de)
FR (1) FR2858145A1 (de)
WO (1) WO2005020538A2 (de)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110107410A1 (en) * 2009-11-02 2011-05-05 At&T Intellectual Property I,L.P. Methods, systems, and computer program products for controlling server access using an authentication server
US8590031B2 (en) * 2009-12-17 2013-11-19 At&T Intellectual Property I, L.P. Methods, systems, and computer program products for access control services using a transparent firewall in conjunction with an authentication server
US20110154469A1 (en) * 2009-12-17 2011-06-23 At&T Intellectual Property Llp Methods, systems, and computer program products for access control services using source port filtering
US10498734B2 (en) * 2012-05-31 2019-12-03 Netsweeper (Barbados) Inc. Policy service authorization and authentication
CN103778535B (zh) * 2012-10-25 2017-08-25 中国银联股份有限公司 处理来自移动终端的数据访问请求的设备和方法
CN107566476B (zh) * 2017-08-25 2020-03-03 中国联合网络通信集团有限公司 一种接入方法、sdn控制器、转发设备及用户接入系统
CN116389032B (zh) * 2022-12-29 2023-12-08 国网甘肃省电力公司庆阳供电公司 一种基于sdn架构的电力信息传输链路身份验证方法

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4268690B2 (ja) * 1997-03-26 2009-05-27 ソニー株式会社 認証システムおよび方法、並びに認証方法
JP3595109B2 (ja) * 1997-05-28 2004-12-02 日本ユニシス株式会社 認証装置、端末装置、および、それら装置における認証方法、並びに、記憶媒体
FI19991733A7 (fi) * 1999-08-16 2001-02-17 Nokia Networks Oy Autentikointi matkaviestinjärjestelmässä
US6850983B2 (en) * 2001-09-18 2005-02-01 Qualcomm Incorporated Method and apparatus for service authorization in a communication system
US7155526B2 (en) * 2002-06-19 2006-12-26 Azaire Networks, Inc. Method and system for transparently and securely interconnecting a WLAN radio access network into a GPRS/GSM core network

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO2005020538A3 *

Also Published As

Publication number Publication date
US20060265586A1 (en) 2006-11-23
WO2005020538A2 (fr) 2005-03-03
WO2005020538A3 (fr) 2006-05-18
FR2858145A1 (fr) 2005-01-28

Similar Documents

Publication Publication Date Title
EP1733533B1 (de) System und verfahren zur benutzerautorisations-zugangsverwaltung in der lokalen administrativen domäne während der verbindung eines benutzers mit einem ip-netzwerk
FR2851104A1 (fr) Procede et systeme d'authentification d'un utilisateur au niveau d'un reseau d'acces lors d'une connexion de l'utilisateur au reseau internet
FR2877521A1 (fr) Dispositif, procede, programme et support de distribution d'informations, d'initialisation, dispositif, procede, programme et support de transfert d'initialisation d'authentification et programme de reception ...
WO2011073560A1 (fr) Acces a un reseau de distribution de contenu numerique
EP1909462A2 (de) Verfahren zur unterteilten Bereitstellung eines elektronischen Dienstes
EP2001196A1 (de) Verwaltung von Benutzeridentitäten zum Dienstzugriff
EP1649665A2 (de) Verfahren und system für doppeltgesicherte authentifikation eines benutzers während des zugriffs auf einen dienst mittels eines datenübertragungsnetzwerks
EP1891771A1 (de) Verfahren zum übersetzen eines authentifizierungsprotokolls
WO2005034468A1 (fr) Systeme d'acces a un reseau adapte pour la mise en oeuvre d'un procede a signature simplifiee, et serveur pour sa realisation
EP4241416A1 (de) Verfahren zur delegierung des zugriffs auf eine blockchain
EP3219077B1 (de) Verfahren und system zur verwaltung von benutzeridentitäten, die während der kommunikation zwischen zwei webbrowsern implementiert werden sollen
EP1227640B1 (de) Verfahren und System zur Übertragung eines Zertifikats zwischen einem Sicherheitsmodul und einem Server
EP3808060B1 (de) Nachrichtenverarbeitung in einem voice-over-ip-netz
EP1762037A2 (de) Verfahren und system zur bestätigung einer benutzeridentität
EP1964359B1 (de) Verfahren und system zum aktualisieren der telekommunikationsnetz-dienstzugangsbedingungen einer telekommunikationseinrichtung
EP1413158B1 (de) Zugangsverfahren zu einem von einem virtuellen operator vorgeschlagenen spezifischen dienst und chipkarte für eine entsprechende vorrichtung
WO2020128239A1 (fr) Procédé de détermination d'une chaîne de délégation associée à une résolution d'un nom de domaine dans un réseau de communication
EP2146534B1 (de) Authentifizierung eines endgeräts
WO2007012786A2 (fr) Procede de mise en oeuvre d'une sequence d'authentifications
WO2007054657A2 (fr) Procede et dispositif de fourniture d'un identifiant de federation reseau a un fournisseur de service
EP4362391A1 (de) Verfahren zur verwaltung des zugriffs eines benutzers auf mindestens eine anwendung, computerprogramm und system dafür
EP3360293A1 (de) Mittel zur verwaltung des zugriffs auf daten
EP1649657A1 (de) Verfahren und gerät für die beglaubigung eines nutzers zu einem diensteanbieter
WO2002089447A2 (fr) Systeme et procede de communication entre stations traitant des dossiers communs
FR2885464A1 (fr) Procede et dispositif de controle d'acces

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20060119

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR

AX Request for extension of the european patent

Extension state: AL HR LT LV MK

PUAK Availability of information related to the publication of the international search report

Free format text: ORIGINAL CODE: 0009015

DAX Request for extension of the european patent (deleted)
RIN1 Information on inventor provided before grant (corrected)

Inventor name: NGUYEN NGOC, SEBASTIEN

Inventor name: TRANSY, ESTELLE

Inventor name: DELMOND, FREDERIC

RIN1 Information on inventor provided before grant (corrected)

Inventor name: TRANSY, ESTELLE

Inventor name: DELMOND, FREDERIC

Inventor name: NGUYEN NGOC, SEBASTIEN

17Q First examination report despatched

Effective date: 20081022

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: ORANGE

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20180201