EP1829280A2 - Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz - Google Patents

Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz

Info

Publication number
EP1829280A2
EP1829280A2 EP05796271A EP05796271A EP1829280A2 EP 1829280 A2 EP1829280 A2 EP 1829280A2 EP 05796271 A EP05796271 A EP 05796271A EP 05796271 A EP05796271 A EP 05796271A EP 1829280 A2 EP1829280 A2 EP 1829280A2
Authority
EP
European Patent Office
Prior art keywords
service
container
data
server
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP05796271A
Other languages
English (en)
French (fr)
Inventor
Jean-Luc Leleu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Publication of EP1829280A2 publication Critical patent/EP1829280A2/de
Withdrawn legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F17/00Coin-freed apparatus for hiring articles; Coin-freed facilities or services
    • G07F17/0014Coin-freed apparatus for hiring articles; Coin-freed facilities or services for vending, access and use of specific services not covered anywhere else in G07F17/00
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/12Payment architectures specially adapted for electronic shopping systems
    • G06Q20/123Shopping for digital content
    • G06Q20/1235Shopping for digital content with control of digital rights management [DRM]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/346Cards serving only as information carrier of service
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/351Virtual cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/355Personalisation of cards for use
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1008Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3234Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/76Proxy, i.e. using intermediary entity to perform cryptographic operations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless

Definitions

  • the present invention generally relates to the authentication domain on a data transmission network and relates, in particular, to a method of accessing a service on a data transmission network, via a connected user terminal. to the network.
  • a service may designate any exchange of information, via a digital data transmission network or telecommunication network between two or more users, or between a user and a service provider.
  • the present invention aims to provide a robust authentication system, very flexible to implement, and can be implemented on inexpensive user terminals with limited computing resources, for access to services, including services voice over IP, on a data transmission network.
  • the subject of the invention is a method of accessing a service on a data transmission network, via a user terminal connected to said network, characterized in that it comprises a phase for subscribing to said service where: an information container associated with the user is generated, comprising a first set of authentication data of the access to the service and a second set of useful data relating to said user and access rights to said service, said first and second sets of data being encrypted, and wherein said container is transmitted securely on said user terminal, and access to said service where: said container is transmitted securely from said user terminal to at least one management server connected to the network during a request for access to said service, and where the server verifies, after decryption of the constituent data of said container, the validity of said first set of authentication data and, if successful verification, authorizes access to the service for its execution according to said access rights of the second set of data.
  • the subscription phase to the service includes the payment of said service by the user to a payment server.
  • the subscription phase further comprises the provision of a one-time password by the payment server to the user, the transmission of the password of the user terminal to the management server, triggering securely transmitting the container from said server to said terminal.
  • a step of updating the useful data of the container relating to the access rights to the service is implemented. server-side, said updated data being saved on the management server side.
  • the first and second sets of data of the container are encrypted on the server side, then the said updated container is transmitted securely from the management server to the user terminal for an access phase. at the later service.
  • the secure transmission of the container consists in transmitting in encrypted form the constituent data of said container by applying a symmetric encryption algorithm using a secret key shared by the user terminal and by the server.
  • the secret key implemented is renewed by configurable period.
  • the renewal of the secret key consists in transmitting a new key at the same time as the container during its secure transmission from the server to the user terminal for a subsequent service access phase.
  • the symmetric encryption algorithm implemented at the terminal and server side is of the RC4 type.
  • the encryption of the first and second sets of constituent data of the container before their secure transmission is obtained by applying to said data of a public key encryption algorithm, the corresponding private key being stored only on the server side.
  • the first set of authentication data is represented by hashing function collisions.
  • the server-side verification step consists in checking that the authentication data actually form hashing function collisions.
  • the verification step consists in checking the correspondence of the authentication data from the container with authentication data referenced in a user database for this user.
  • a service cost billing element is generated at the server after execution of said service, from the payload data of the container relating to the service access rights for the user, the authentication data being associated with said service. billing item generated as evidence that access to that service has been authorized.
  • the billing element is stored for use for subsequent financial compensation.
  • the service accessed is a voice over IP service.
  • the transmission of the container from the user terminal to the server or from the server to the user terminal for access to the service is integrated into a protocol allowing voice over IP transmissions, for example the SIP protocol.
  • the transmission of the container from the user terminal to the management server during a phase of access to a service is performed via an intermediate gateway of the network, said gateway implementing a preliminary verification step of the validity of the container before routing it to said server.
  • the preliminary verification step of the validity of the container consists in checking the validity of a third set of authentication data of said container.
  • the invention also relates to a server connected to a data transmission network, for accessing a service via a user terminal connected to said network, characterized in that it comprises means for implementing process steps as just described.
  • FIG. 1 schematically illustrates an exemplary network architecture in which the invention can be described
  • FIG. 2 illustrates, according to a preferred exemplary embodiment, the steps implemented when registering a user with a service on a data transmission network
  • FIG. 3 illustrates a possible model for the structure of a secure container bearing the information necessary for accessing and performing the service on the network
  • FIG 4 illustrates steps of obtaining the secure container by the terminal following the subscription to the service for access to it;
  • FIG. 5 is a block diagram illustrating a sequence of steps implemented on the server side during access to the service.
  • the invention therefore relates to a method of accessing a service on a data transmission network.
  • Access to the service is preferably performed via a user terminal 30 connected to an access network RA coupled by a PA gateway to the data transmission network, typically the Internet network and generally with its couplings to other autonomous networks, such as the PSTN public switched telephone network.
  • the access network can be either a wireless local area network, for example a Wifi network, a public or private network operating with the IP protocol or with a protocol other than IP, a public or private switched telephone network.
  • the service subscribed by the user may be an IP telephony service, video telephony or a download service for digital files, for example music files type MP3.
  • IP telephony service for example IP telephony service
  • video telephony for example video files type MP3.
  • download service for digital files
  • music files type MP3 for example music files type MP3.
  • FIG 2 illustrates precisely this phase of subscription of the user to the service, which is more particularly materialized by a deed of payment
  • the user obtains (b) an activation number of the subscribed service.
  • This activation number includes a OTP one-time password and a secret key Ko, the use of which will be explained later.
  • the transaction between the user and the payment server is preferably implemented according to a protocol allowing the secure transmission of information, such as the SSL protocol for example.
  • the activation number could be transmitted to the user by any other suitable means, for example by mail, a call to an interactive voice response system or via a card to scratch.
  • a secure container is an encrypted numerical value representative of various information associated with a user subscribed to a service and, in particular, access rights to this service. It allows this information to pass between different nodes of the network in a secure manner without the need to provide for the implementation of a channel figure.
  • the container also allows its owner, in this case a user terminal, to be authorized to access a service on the network according to the access rights to this service as they were defined at the time of subscription in the service and stored in digital form in the secure container.
  • FIG. 3 illustrates an exemplary structure of a TOKEN secure container, which is generated on a network management server during the subscription phase to the service by the user. It comprises a first set of CBF data forming the core of the container, essentially comprising authentication data of access to the XO service, Xl, X2 and X3, which form the proof that the access to the service can be authorized for its execution.
  • the value and the origin of this first set of authentication data must be easily authenticated and verifiable by the entity authorizing the access and this, of course.
  • a TPID field can thus be inserted in this first set of data, representative of the producer entity of the container.
  • the authentication data of the access to the service denoted X0, X1, X2 and X3 in the example of FIG. 3, are manufactured according to a method described in FIG. article entitled "PayWord and Micromint - Two Simple Micropayment Schemes" by RL RIVEST and A. SHAMIR and presented on January 26, 1996 at the 1996 RSA conference. manufacturing electronic coins, represented by bit strings whose validity can be verified by anyone, but which are very difficult to produce. In this system, parts are represented by hashing function collisions.
  • the container also comprises a second set of useful data PBF, including data relating to the user of the service and rights of access to this service that were defined at the time of subscription to the service by the user.
  • PBF useful data
  • an RBF field of the container includes data defining the conditions of access to the services, for example indicating whether the user can make local calls and / or national and / or international.
  • a UBF field includes value data associated with the service for establishing a billing, for example a number of units representative of the amount of the payment paid by the user when subscribing to the service.
  • a TCBF field comprises time data, for example data representative of a communication time. Other critical information could still be inserted in the second set of useful data PBF, such as for example an expiry date of the validity of the container.
  • the second payload data set may also include a SID / PN field including user data, such as a subscriber ID number and / or its telephone number.
  • the first set of authentication data thus provides the security and integrity functions of the second set of useful data and can be likened to a unique non-forgeable key for authenticating access to a given service.
  • the container can thus guarantee, by means of a verification of the first set of authentication data, that access to a given service can be authorized, depending on the access rights defined in the container, and that the latter has already been paid or the user can be charged for this service.
  • a public key encryption algorithm E PK for example an RSA type algorithm.
  • E PK public key encryption algorithm
  • This container thus secured is intended to be stored on the user terminal side, in order to allow the implementation, from this terminal, of a service access phase, which will be implemented at a PA gateway of data transmission network, typically the management server.
  • the private key corresponding to the public key implemented as part of the RSA algorithm for the encryption of the constituent data of the container is stored only on the server side.
  • the data transmission network must comprise, at the level of each management server involved in a phase of access to the service by the user terminal, a data processing system programmed so as to perform the various steps of the method of the invention.
  • This data processing system can be individualized as a separate system from the computer system managing the server, or integrated into the computer system by the addition of integrated software.
  • the secure container must first be stored on the user terminal side. This step is described with reference to FIG.
  • the server 40 is a server placed in the network in front of a voice over IP VoIP infrastructure and which will transmit all the signaling packets of the call to the next VoIP device of this infrastructure, once the information of a TOKEN container received from a terminal or, alternatively, from another node of the network, as part of an access request VoIP service will have been recovered and verified as explained below.
  • the server 40 is for example a SIP proxy server ("Session Initiation Protocol").
  • the container and its use in a data transmission network as described in the present description to authenticate access to a given service can also be implemented in the context of a communication protocol between two nodes of the network involved in the access to the service, for example between two servers of the SIP proxy type.
  • step c of transmitting the password OPT of the user terminal 30 to the management server 40 is implemented, triggering the secure transmission to step d, of the container TOKEN, itself already secured by heavy RSA type encryption, from the server 40 to the terminal 30.
  • the secure transmission of the TOKEN container over the network is ensured by the application of a symmetric encryption algorithm C K 0 / for example of type RC4, with the secret key Ko, provided beforehand to the user and shared by the user. management server.
  • Two types of encryption are applied to the container.
  • the first set of data of the CBF container is securely linked to the second set of PBF data by heavy RSA type encryption, managed server side.
  • the container has a second level of encryption, lighter, type RC4 for its secure transmission through the network.
  • this last type of encryption is intended to be implemented on both the server and the terminal side, so as to provide anti-replay properties to the secure container.
  • the secret keys used in the secure transmission of the container on the network are changed very often so as to further enhance the security given the light encryption algorithm used.
  • the secret keys implemented are thus renewed by configurable period.
  • the renewal of the secret key K 0 is carried out by transmitting a new key K1 at the same time as the TOKEN container during its secure transmission of the the
  • the server 40 to the user terminal 30.
  • the server 40 therefore sends C ⁇ o (TOKEN, K1) to the terminal 30.
  • the terminal 30 decrypts the received value using the secret key K 0 which it already has, and thus retrieves the TOKEN container value, always encrypted RSA, and the secret key K1.
  • a service access request sent by the terminal 30 consists of transmitting the (C) securely to the container C RI (TOKEN). to the server 40, by application on the terminal side of the algorithm RC4 with the secret key K1 on the container.
  • the process steps can advantageously be implemented on user terminals with few available CPU resources.
  • the heavy security operations of the container being managed mainly on the management server side, including RSA encryption of the data constituting the container, client-side implementation on the user terminal requires only a simple application that can ensure secure storage of the container on the terminal and the implementation of RC4 encryption, used for the secure transmission of the container.
  • step f the server performs a decryption operation of the data received from the terminal. It first decrypts C K i (TOKEN) with the secret key K1 in order to retrieve the TOKEN container whose data is encrypted with RSA. Then, in a second step, it retrieves the first set of authentication data CBF and the second set of user data UBF from the container by the decryption operation RSA with the corresponding private key of which it is the only one to dispose.
  • a step of checking the validity of the first set of authentication data XO, X1, X2, X3 is implemented. This step can simply consist in checking that the authentication data X0, X1, X2, X3 actually form hashing function collisions.
  • the server 40 authorizes access to the service for its execution according to the access rights to this service referenced in the second set of useful data of the container.
  • the service accessed may be a SIP call to an international number, authorized under the RBF / UBF / TCBF values, the signaling packets of this call being then transmitted by the server to the VoIP infrastructure.
  • the properties of the container implemented thus provides a great deal of flexibility in managing access to the IP telephony service.
  • the container we do not have to go back to a centralized database to identify the user.
  • the access rights of the user to access the service can indeed be verified directly from the container without having to go back to a user account defining these rights.
  • the server 40 may, however, use a user database.
  • the verification can thus consist in verifying the correspondence of the authentication data of the transaction coming from the container with authentication data referenced in a user database for this user.
  • Authentication data access to the service may indeed be formed in one variant by a digital fingerprint of the user, having the same security guarantees that the use of hashing function collisions.
  • the server can also check in the user database that the useful data RBF, UBF and TCBF from the container actually correspond to the current useful data for access to the service stored for this user in the database.
  • a step i of updating the payload data of the container relating to the access rights to the service is implemented, in particular, a step of updating the data RBF, UBF and TCBF. For example, if a prepaid period of 500 minutes had been subscribed by the user, at the end of a 7 minute call session, the initial value 500 of the TCBF field of the payload data of the container is decreased by 7. The updated payloads are then saved to the management server side in the user database.
  • a service cost billing element may optionally be generated and stored at the server 40, the content of which is determined from the payload data of the container relating to the service access rights for the user. .
  • the variations of the TCBF data, giving the communication time, and UBF for the cost of a communication unit can be memorized to form the billing element.
  • the authentication data is also associated with the generated billing item as evidence that access to the service has been authorized.
  • the billing element thus stored on the server side 40 can then be used subsequently with a third party organization to obtain financial compensation on the basis of the accumulated data.
  • an RSA encryption step of the first set of authentication data CBF and the second set of payload data PBF with the updated data is implemented. In this way, the updated secure container is obtained.
  • the updated secure container is transmitted in step k securely to the user terminal 30 for a subsequent service access phase, the secure transmission being provided as previously explained by the application of the RC4 algorithm with Kl.
  • the renewal of the secret key Kl is performed during this step, by transmitting a new key K2 which will be used during the subsequent service access phase.
  • the new secret key K2 is transmitted together with the updated container TOKEN during the secure transmission of the server 40 to the user terminal 30.
  • the server 40 sends thus C ⁇ i (TOKEN, K2) to the terminal 30 .
  • the secure transmission of the TOKEN container, whose data are already encrypted, from the user terminal 30 to the management server 40, or from the server to the user terminal, or between two servers of the network, for the implementation of the access the service and its execution, is intended to be integrated in a protocol for voice transmissions over IP, for example the SIP protocol, according to the embodiment described with reference to a subscribed VoIP service.
  • a protocol for voice transmissions over IP for example the SIP protocol
  • IP for example the SIP protocol
  • a header in order to allow the appropriate processing according to the invention of container-carrying packets. This header could for example consist of several fields such as the size of the data, a control number, a session identifier or other control information.
  • the TOKEN information container may comprise a third set of authentication data, the role of which will be described below.
  • an intermediate gateway of the network is implemented to carry out the transmission of the container of the user terminal to the management server during a phase of access to a service on the network.
  • the intermediate gateway is then provided to perform a preliminary verification of the validity of the container before routing it to the management server, consisting of checking the validity of the third set of authentication data of the container.
  • the third set of authentication data can be represented by bit strings obtained by hashing function collisions, in the same way as for the first set of data of the container.
  • the third data set of the container can also be encrypted using a symmetric key encryption algorithm, type RC4.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Theoretical Computer Science (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Computer Security & Cryptography (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Signal Processing (AREA)
  • Finance (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Telephonic Communication Services (AREA)
  • Storage Device Security (AREA)
EP05796271A 2004-08-10 2005-08-05 Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz Withdrawn EP1829280A2 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0408797A FR2874295B1 (fr) 2004-08-10 2004-08-10 Procede d'authentification securisee pour la mise en oeuvre de services sur un reseau de transmission de donnees
PCT/FR2005/002034 WO2006021661A2 (fr) 2004-08-10 2005-08-05 Procede d'authentification securisee pour la mise en œuvre de services sur un reseau de transmission de donnees

Publications (1)

Publication Number Publication Date
EP1829280A2 true EP1829280A2 (de) 2007-09-05

Family

ID=34950840

Family Applications (1)

Application Number Title Priority Date Filing Date
EP05796271A Withdrawn EP1829280A2 (de) 2004-08-10 2005-08-05 Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz

Country Status (4)

Country Link
US (1) US8359273B2 (de)
EP (1) EP1829280A2 (de)
FR (1) FR2874295B1 (de)
WO (1) WO2006021661A2 (de)

Families Citing this family (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6735288B1 (en) * 2000-01-07 2004-05-11 Cisco Technology, Inc. Voice over IP voice mail system configured for placing an outgoing call and returning subscriber to mailbox after call completion
GB0319918D0 (en) * 2003-08-23 2003-09-24 Ibm Method system and device for mobile subscription content access
US8874477B2 (en) 2005-10-04 2014-10-28 Steven Mark Hoffberg Multifactorial optimization system and method
US7596092B2 (en) * 2006-02-02 2009-09-29 Cisco Technology, Inc. VoIP verifier
ES2517865T3 (es) * 2006-03-08 2014-11-04 Monitise Limited Métodos, aparatos y software para usar un testigo para calcular contraseña limitada en tiempo en teléfono celular
US9807096B2 (en) * 2014-12-18 2017-10-31 Live Nation Entertainment, Inc. Controlled token distribution to protect against malicious data and resource access
JP5034821B2 (ja) * 2007-09-21 2012-09-26 ソニー株式会社 生体情報記憶装置
US8819838B2 (en) * 2008-01-25 2014-08-26 Google Technology Holdings LLC Piracy prevention in digital rights management systems
GB2464553B (en) * 2008-10-22 2012-11-21 Skype Controlling a connection between a user terminal and an access node connected to a communication network
EP2502192A2 (de) * 2009-11-18 2012-09-26 Magid Joseph Mina Zahlungssysteme und -verfahren bei anonymen transaktionen
US20110162054A1 (en) * 2009-12-30 2011-06-30 Infosys Technologies Limited FIRMWARE AND METHOD FOR GENERATING ONE TIME PASSWORDS (OTPs) FOR APPLICATIONS
JP5573489B2 (ja) * 2010-08-23 2014-08-20 ソニー株式会社 情報処理装置、および情報処理方法、並びにプログラム
CN102572815B (zh) * 2010-12-29 2014-11-05 中国移动通信集团公司 一种对终端应用请求的处理方法、系统及装置
JP5935883B2 (ja) * 2012-05-21 2016-06-15 ソニー株式会社 情報処理装置、情報処理システム、および情報処理方法、並びにプログラム
US9106411B2 (en) 2012-09-30 2015-08-11 Apple Inc. Secure escrow service
US9332008B2 (en) 2014-03-28 2016-05-03 Netiq Corporation Time-based one time password (TOTP) for network authentication
US9842062B2 (en) 2015-05-31 2017-12-12 Apple Inc. Backup accessible by subset of related devices
US10063557B2 (en) 2015-06-07 2018-08-28 Apple Inc. Account access recovery system, method and apparatus
JP5951094B1 (ja) * 2015-09-07 2016-07-13 ヤフー株式会社 生成装置、端末装置、生成方法、生成プログラム及び認証処理システム
US10630648B1 (en) 2017-02-08 2020-04-21 United Services Automobile Association (Usaa) Systems and methods for facilitating digital document communication
US11146398B2 (en) * 2019-08-30 2021-10-12 Comcast Cable Communications, Llc Method and apparatus for secure token generation
US11870899B2 (en) * 2021-08-30 2024-01-09 Whitestar Communications, Inc. Secure device access recovery based on validating encrypted target password from secure recovery container in trusted recovery device
US12361408B2 (en) * 2021-09-24 2025-07-15 Artema Labs, Inc Systems and methods for transaction management in NFT-directed environments
CN115600177B (zh) * 2022-10-09 2024-04-16 北京金和网络股份有限公司 一种身份认证的方法、装置、存储介质及电子设备

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5153919A (en) * 1991-09-13 1992-10-06 At&T Bell Laboratories Service provision authentication protocol
US5970144A (en) * 1997-01-31 1999-10-19 Synacom Technology, Inc. Secure authentication-key management system and method for mobile communications
CA2255285C (en) * 1998-12-04 2009-10-13 Certicom Corp. Enhanced subscriber authentication protocol
US7035410B1 (en) * 1999-03-01 2006-04-25 At&T Corp. Method and apparatus for enhanced security in a broadband telephony network
AU2374401A (en) * 1999-12-03 2001-06-12 First Hop Oy A method and a system for obtaining services using a cellular telecommunication system
US6760841B1 (en) * 2000-05-01 2004-07-06 Xtec, Incorporated Methods and apparatus for securely conducting and authenticating transactions over unsecured communication channels
US7721109B1 (en) * 2000-07-28 2010-05-18 Verizon Business Global Llc Secure transaction card using biometrical validation
US6938019B1 (en) * 2000-08-29 2005-08-30 Uzo Chijioke Chukwuemeka Method and apparatus for making secure electronic payments
PL345054A1 (en) * 2001-01-11 2002-07-15 Igor Hansen Personal database system and method of managing the access to such database
US7181017B1 (en) * 2001-03-23 2007-02-20 David Felsher System and method for secure three-party communications
US20030037261A1 (en) * 2001-03-26 2003-02-20 Ilumin Corporation Secured content delivery system and method
US7302571B2 (en) * 2001-04-12 2007-11-27 The Regents Of The University Of Michigan Method and system to maintain portable computer data secure and authentication token for use therein
EP1257106B1 (de) * 2001-05-08 2005-03-23 Telefonaktiebolaget LM Ericsson (publ) Sicherer Zugang zu einem entfernten Teilnehmermodul
US20040029562A1 (en) * 2001-08-21 2004-02-12 Msafe Ltd. System and method for securing communications over cellular networks
DE10164131A1 (de) * 2001-12-30 2003-07-17 Juergen K Lang Kryptographisches Modul zur Speicherung und Wiedergabe kopier-und nutzungsgeschützter elektronischer Ton- und Bildmedien
GB2405566B (en) * 2002-10-14 2005-05-18 Toshiba Res Europ Ltd Methods and systems for flexible delegation
US20050004873A1 (en) * 2003-02-03 2005-01-06 Robin Pou Distribution and rights management of digital content
JP2006526204A (ja) * 2003-03-13 2006-11-16 ディーアールエム テクノロジーズ、エルエルシー セキュアストリーミングコンテナ
US7421732B2 (en) * 2003-05-05 2008-09-02 Nokia Corporation System, apparatus, and method for providing generic internet protocol authentication
US20050050330A1 (en) * 2003-08-27 2005-03-03 Leedor Agam Security token
US7430606B1 (en) * 2003-10-17 2008-09-30 Arraycomm, Llc Reducing certificate revocation lists at access points in a wireless access network

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO2006021661A2 *

Also Published As

Publication number Publication date
US20080176533A1 (en) 2008-07-24
WO2006021661A2 (fr) 2006-03-02
FR2874295A1 (fr) 2006-02-17
FR2874295B1 (fr) 2006-11-24
WO2006021661A3 (fr) 2006-10-26
US8359273B2 (en) 2013-01-22

Similar Documents

Publication Publication Date Title
EP1829280A2 (de) Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz
EP1683388B1 (de) Verfahren zur Verwaltung der Sicherheit von Anwendungen in einem Sicherheitsmodul
EP1442557B1 (de) System und verfahren zur erzeugung eines gesicherten netzes unter verwendung von beglaubigungen von verfahrensgruppen
EP1427231B1 (de) Verfahren zur Herstellung und Verwaltung eines Vertrauensmodells zwischen einer SIM-Karte und einem mobilen Terminal
EP1909462B1 (de) Verfahren zur unterteilten Bereitstellung eines elektronischen Dienstes
EP0973318A1 (de) Verfahren zum Fernbezahlen mittels eines mobilen Funktelefons, die Erwerbung eines Gutes und/oder eines Dienstes und entsprechendes System und mobiles Funktelefon
EP2279581A1 (de) Verfahren zum sicheren senden digitaler daten an eine autorisierte drittpartei
FR3058243A1 (fr) Procede de controle d'identite d'un utilisateur au moyen d'une base de donnees publique
FR2930391A1 (fr) Terminal d'authentification d'un utilisateur.
EP3758322A1 (de) Verfahren und system zur erzeugung von chiffrierschlüsseln für transaktions- oder verbindungsdaten
WO2015059389A1 (fr) Procede d'execution d'une transaction entre un premier terminal et un deuxieme terminal
EP3375133A1 (de) Verfahren zur sicherung und authentifizierung einer telekommunikation
EP3965361B1 (de) Datenaustausch zwischen einem client und einem fernen gerät, z.b. ein geschützten modul
EP1514377A1 (de) Schnittstellenverfahren- und einrichtung zum online-austausch von inhaltsdaten auf sichere weise
EP4241416B1 (de) Verfahren zur delegierung des zugriffs auf eine blockchain
EP1400090B1 (de) Vorrichtung und verfahren zur bereitstellung gesicherter kommunikation in einem computernetzwerk
EP4359986B1 (de) Blockchain-zahlungsverfahren und -vorrichtung
EP1949590A1 (de) Verfahren zum sicheren deponieren digitaler daten, diesbezügliches verfahren zum wiederherstellen digitaler daten, diesbezügliche einrichtungen zum implementieren von verfahren und system mit den einrichtungen
EP1413158B1 (de) Zugangsverfahren zu einem von einem virtuellen operator vorgeschlagenen spezifischen dienst und chipkarte für eine entsprechende vorrichtung
EP2911365B1 (de) Verfahren und System zur Sicherung von Transaktionen, die von einer Vielzahl von Diensten zwischen einem Mobilgerät eines Benutzers und einer Akzeptanzstelle angeboten werden
EP2317691B1 (de) Vorrichtung und Verfahren zur kontextueller und dynamischer Sicherung der Datenaustausch durch ein Netzwerk
WO2024153437A1 (fr) Procédés de signature de données, de fourniture de données signées, terminal et serveur associés
FR3128089A1 (fr) Procédé et dispositif de sélection d’une station de base
FR2763192A1 (fr) Procede de recuperation de cles mis en oeuvre pour un chiffrement fort de message
FR3066346A1 (fr) Procede de securisation en vue d'un appairage hors bande dans la bande

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20070615

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR

DAX Request for extension of the european patent (deleted)
17Q First examination report despatched

Effective date: 20100421

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20130701