EP1829280A2 - Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz - Google Patents
Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetzInfo
- Publication number
- EP1829280A2 EP1829280A2 EP05796271A EP05796271A EP1829280A2 EP 1829280 A2 EP1829280 A2 EP 1829280A2 EP 05796271 A EP05796271 A EP 05796271A EP 05796271 A EP05796271 A EP 05796271A EP 1829280 A2 EP1829280 A2 EP 1829280A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- service
- container
- data
- server
- access
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F17/00—Coin-freed apparatus for hiring articles; Coin-freed facilities or services
- G07F17/0014—Coin-freed apparatus for hiring articles; Coin-freed facilities or services for vending, access and use of specific services not covered anywhere else in G07F17/00
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/12—Payment architectures specially adapted for electronic shopping systems
- G06Q20/123—Shopping for digital content
- G06Q20/1235—Shopping for digital content with control of digital rights management [DRM]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/346—Cards serving only as information carrier of service
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/351—Virtual cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/385—Payment protocols; Details thereof using an alias or single-use codes
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/56—Financial cryptography, e.g. electronic payment or e-cash
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/76—Proxy, i.e. using intermediary entity to perform cryptographic operations
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present invention generally relates to the authentication domain on a data transmission network and relates, in particular, to a method of accessing a service on a data transmission network, via a connected user terminal. to the network.
- a service may designate any exchange of information, via a digital data transmission network or telecommunication network between two or more users, or between a user and a service provider.
- the present invention aims to provide a robust authentication system, very flexible to implement, and can be implemented on inexpensive user terminals with limited computing resources, for access to services, including services voice over IP, on a data transmission network.
- the subject of the invention is a method of accessing a service on a data transmission network, via a user terminal connected to said network, characterized in that it comprises a phase for subscribing to said service where: an information container associated with the user is generated, comprising a first set of authentication data of the access to the service and a second set of useful data relating to said user and access rights to said service, said first and second sets of data being encrypted, and wherein said container is transmitted securely on said user terminal, and access to said service where: said container is transmitted securely from said user terminal to at least one management server connected to the network during a request for access to said service, and where the server verifies, after decryption of the constituent data of said container, the validity of said first set of authentication data and, if successful verification, authorizes access to the service for its execution according to said access rights of the second set of data.
- the subscription phase to the service includes the payment of said service by the user to a payment server.
- the subscription phase further comprises the provision of a one-time password by the payment server to the user, the transmission of the password of the user terminal to the management server, triggering securely transmitting the container from said server to said terminal.
- a step of updating the useful data of the container relating to the access rights to the service is implemented. server-side, said updated data being saved on the management server side.
- the first and second sets of data of the container are encrypted on the server side, then the said updated container is transmitted securely from the management server to the user terminal for an access phase. at the later service.
- the secure transmission of the container consists in transmitting in encrypted form the constituent data of said container by applying a symmetric encryption algorithm using a secret key shared by the user terminal and by the server.
- the secret key implemented is renewed by configurable period.
- the renewal of the secret key consists in transmitting a new key at the same time as the container during its secure transmission from the server to the user terminal for a subsequent service access phase.
- the symmetric encryption algorithm implemented at the terminal and server side is of the RC4 type.
- the encryption of the first and second sets of constituent data of the container before their secure transmission is obtained by applying to said data of a public key encryption algorithm, the corresponding private key being stored only on the server side.
- the first set of authentication data is represented by hashing function collisions.
- the server-side verification step consists in checking that the authentication data actually form hashing function collisions.
- the verification step consists in checking the correspondence of the authentication data from the container with authentication data referenced in a user database for this user.
- a service cost billing element is generated at the server after execution of said service, from the payload data of the container relating to the service access rights for the user, the authentication data being associated with said service. billing item generated as evidence that access to that service has been authorized.
- the billing element is stored for use for subsequent financial compensation.
- the service accessed is a voice over IP service.
- the transmission of the container from the user terminal to the server or from the server to the user terminal for access to the service is integrated into a protocol allowing voice over IP transmissions, for example the SIP protocol.
- the transmission of the container from the user terminal to the management server during a phase of access to a service is performed via an intermediate gateway of the network, said gateway implementing a preliminary verification step of the validity of the container before routing it to said server.
- the preliminary verification step of the validity of the container consists in checking the validity of a third set of authentication data of said container.
- the invention also relates to a server connected to a data transmission network, for accessing a service via a user terminal connected to said network, characterized in that it comprises means for implementing process steps as just described.
- FIG. 1 schematically illustrates an exemplary network architecture in which the invention can be described
- FIG. 2 illustrates, according to a preferred exemplary embodiment, the steps implemented when registering a user with a service on a data transmission network
- FIG. 3 illustrates a possible model for the structure of a secure container bearing the information necessary for accessing and performing the service on the network
- FIG 4 illustrates steps of obtaining the secure container by the terminal following the subscription to the service for access to it;
- FIG. 5 is a block diagram illustrating a sequence of steps implemented on the server side during access to the service.
- the invention therefore relates to a method of accessing a service on a data transmission network.
- Access to the service is preferably performed via a user terminal 30 connected to an access network RA coupled by a PA gateway to the data transmission network, typically the Internet network and generally with its couplings to other autonomous networks, such as the PSTN public switched telephone network.
- the access network can be either a wireless local area network, for example a Wifi network, a public or private network operating with the IP protocol or with a protocol other than IP, a public or private switched telephone network.
- the service subscribed by the user may be an IP telephony service, video telephony or a download service for digital files, for example music files type MP3.
- IP telephony service for example IP telephony service
- video telephony for example video files type MP3.
- download service for digital files
- music files type MP3 for example music files type MP3.
- FIG 2 illustrates precisely this phase of subscription of the user to the service, which is more particularly materialized by a deed of payment
- the user obtains (b) an activation number of the subscribed service.
- This activation number includes a OTP one-time password and a secret key Ko, the use of which will be explained later.
- the transaction between the user and the payment server is preferably implemented according to a protocol allowing the secure transmission of information, such as the SSL protocol for example.
- the activation number could be transmitted to the user by any other suitable means, for example by mail, a call to an interactive voice response system or via a card to scratch.
- a secure container is an encrypted numerical value representative of various information associated with a user subscribed to a service and, in particular, access rights to this service. It allows this information to pass between different nodes of the network in a secure manner without the need to provide for the implementation of a channel figure.
- the container also allows its owner, in this case a user terminal, to be authorized to access a service on the network according to the access rights to this service as they were defined at the time of subscription in the service and stored in digital form in the secure container.
- FIG. 3 illustrates an exemplary structure of a TOKEN secure container, which is generated on a network management server during the subscription phase to the service by the user. It comprises a first set of CBF data forming the core of the container, essentially comprising authentication data of access to the XO service, Xl, X2 and X3, which form the proof that the access to the service can be authorized for its execution.
- the value and the origin of this first set of authentication data must be easily authenticated and verifiable by the entity authorizing the access and this, of course.
- a TPID field can thus be inserted in this first set of data, representative of the producer entity of the container.
- the authentication data of the access to the service denoted X0, X1, X2 and X3 in the example of FIG. 3, are manufactured according to a method described in FIG. article entitled "PayWord and Micromint - Two Simple Micropayment Schemes" by RL RIVEST and A. SHAMIR and presented on January 26, 1996 at the 1996 RSA conference. manufacturing electronic coins, represented by bit strings whose validity can be verified by anyone, but which are very difficult to produce. In this system, parts are represented by hashing function collisions.
- the container also comprises a second set of useful data PBF, including data relating to the user of the service and rights of access to this service that were defined at the time of subscription to the service by the user.
- PBF useful data
- an RBF field of the container includes data defining the conditions of access to the services, for example indicating whether the user can make local calls and / or national and / or international.
- a UBF field includes value data associated with the service for establishing a billing, for example a number of units representative of the amount of the payment paid by the user when subscribing to the service.
- a TCBF field comprises time data, for example data representative of a communication time. Other critical information could still be inserted in the second set of useful data PBF, such as for example an expiry date of the validity of the container.
- the second payload data set may also include a SID / PN field including user data, such as a subscriber ID number and / or its telephone number.
- the first set of authentication data thus provides the security and integrity functions of the second set of useful data and can be likened to a unique non-forgeable key for authenticating access to a given service.
- the container can thus guarantee, by means of a verification of the first set of authentication data, that access to a given service can be authorized, depending on the access rights defined in the container, and that the latter has already been paid or the user can be charged for this service.
- a public key encryption algorithm E PK for example an RSA type algorithm.
- E PK public key encryption algorithm
- This container thus secured is intended to be stored on the user terminal side, in order to allow the implementation, from this terminal, of a service access phase, which will be implemented at a PA gateway of data transmission network, typically the management server.
- the private key corresponding to the public key implemented as part of the RSA algorithm for the encryption of the constituent data of the container is stored only on the server side.
- the data transmission network must comprise, at the level of each management server involved in a phase of access to the service by the user terminal, a data processing system programmed so as to perform the various steps of the method of the invention.
- This data processing system can be individualized as a separate system from the computer system managing the server, or integrated into the computer system by the addition of integrated software.
- the secure container must first be stored on the user terminal side. This step is described with reference to FIG.
- the server 40 is a server placed in the network in front of a voice over IP VoIP infrastructure and which will transmit all the signaling packets of the call to the next VoIP device of this infrastructure, once the information of a TOKEN container received from a terminal or, alternatively, from another node of the network, as part of an access request VoIP service will have been recovered and verified as explained below.
- the server 40 is for example a SIP proxy server ("Session Initiation Protocol").
- the container and its use in a data transmission network as described in the present description to authenticate access to a given service can also be implemented in the context of a communication protocol between two nodes of the network involved in the access to the service, for example between two servers of the SIP proxy type.
- step c of transmitting the password OPT of the user terminal 30 to the management server 40 is implemented, triggering the secure transmission to step d, of the container TOKEN, itself already secured by heavy RSA type encryption, from the server 40 to the terminal 30.
- the secure transmission of the TOKEN container over the network is ensured by the application of a symmetric encryption algorithm C K 0 / for example of type RC4, with the secret key Ko, provided beforehand to the user and shared by the user. management server.
- Two types of encryption are applied to the container.
- the first set of data of the CBF container is securely linked to the second set of PBF data by heavy RSA type encryption, managed server side.
- the container has a second level of encryption, lighter, type RC4 for its secure transmission through the network.
- this last type of encryption is intended to be implemented on both the server and the terminal side, so as to provide anti-replay properties to the secure container.
- the secret keys used in the secure transmission of the container on the network are changed very often so as to further enhance the security given the light encryption algorithm used.
- the secret keys implemented are thus renewed by configurable period.
- the renewal of the secret key K 0 is carried out by transmitting a new key K1 at the same time as the TOKEN container during its secure transmission of the the
- the server 40 to the user terminal 30.
- the server 40 therefore sends C ⁇ o (TOKEN, K1) to the terminal 30.
- the terminal 30 decrypts the received value using the secret key K 0 which it already has, and thus retrieves the TOKEN container value, always encrypted RSA, and the secret key K1.
- a service access request sent by the terminal 30 consists of transmitting the (C) securely to the container C RI (TOKEN). to the server 40, by application on the terminal side of the algorithm RC4 with the secret key K1 on the container.
- the process steps can advantageously be implemented on user terminals with few available CPU resources.
- the heavy security operations of the container being managed mainly on the management server side, including RSA encryption of the data constituting the container, client-side implementation on the user terminal requires only a simple application that can ensure secure storage of the container on the terminal and the implementation of RC4 encryption, used for the secure transmission of the container.
- step f the server performs a decryption operation of the data received from the terminal. It first decrypts C K i (TOKEN) with the secret key K1 in order to retrieve the TOKEN container whose data is encrypted with RSA. Then, in a second step, it retrieves the first set of authentication data CBF and the second set of user data UBF from the container by the decryption operation RSA with the corresponding private key of which it is the only one to dispose.
- a step of checking the validity of the first set of authentication data XO, X1, X2, X3 is implemented. This step can simply consist in checking that the authentication data X0, X1, X2, X3 actually form hashing function collisions.
- the server 40 authorizes access to the service for its execution according to the access rights to this service referenced in the second set of useful data of the container.
- the service accessed may be a SIP call to an international number, authorized under the RBF / UBF / TCBF values, the signaling packets of this call being then transmitted by the server to the VoIP infrastructure.
- the properties of the container implemented thus provides a great deal of flexibility in managing access to the IP telephony service.
- the container we do not have to go back to a centralized database to identify the user.
- the access rights of the user to access the service can indeed be verified directly from the container without having to go back to a user account defining these rights.
- the server 40 may, however, use a user database.
- the verification can thus consist in verifying the correspondence of the authentication data of the transaction coming from the container with authentication data referenced in a user database for this user.
- Authentication data access to the service may indeed be formed in one variant by a digital fingerprint of the user, having the same security guarantees that the use of hashing function collisions.
- the server can also check in the user database that the useful data RBF, UBF and TCBF from the container actually correspond to the current useful data for access to the service stored for this user in the database.
- a step i of updating the payload data of the container relating to the access rights to the service is implemented, in particular, a step of updating the data RBF, UBF and TCBF. For example, if a prepaid period of 500 minutes had been subscribed by the user, at the end of a 7 minute call session, the initial value 500 of the TCBF field of the payload data of the container is decreased by 7. The updated payloads are then saved to the management server side in the user database.
- a service cost billing element may optionally be generated and stored at the server 40, the content of which is determined from the payload data of the container relating to the service access rights for the user. .
- the variations of the TCBF data, giving the communication time, and UBF for the cost of a communication unit can be memorized to form the billing element.
- the authentication data is also associated with the generated billing item as evidence that access to the service has been authorized.
- the billing element thus stored on the server side 40 can then be used subsequently with a third party organization to obtain financial compensation on the basis of the accumulated data.
- an RSA encryption step of the first set of authentication data CBF and the second set of payload data PBF with the updated data is implemented. In this way, the updated secure container is obtained.
- the updated secure container is transmitted in step k securely to the user terminal 30 for a subsequent service access phase, the secure transmission being provided as previously explained by the application of the RC4 algorithm with Kl.
- the renewal of the secret key Kl is performed during this step, by transmitting a new key K2 which will be used during the subsequent service access phase.
- the new secret key K2 is transmitted together with the updated container TOKEN during the secure transmission of the server 40 to the user terminal 30.
- the server 40 sends thus C ⁇ i (TOKEN, K2) to the terminal 30 .
- the secure transmission of the TOKEN container, whose data are already encrypted, from the user terminal 30 to the management server 40, or from the server to the user terminal, or between two servers of the network, for the implementation of the access the service and its execution, is intended to be integrated in a protocol for voice transmissions over IP, for example the SIP protocol, according to the embodiment described with reference to a subscribed VoIP service.
- a protocol for voice transmissions over IP for example the SIP protocol
- IP for example the SIP protocol
- a header in order to allow the appropriate processing according to the invention of container-carrying packets. This header could for example consist of several fields such as the size of the data, a control number, a session identifier or other control information.
- the TOKEN information container may comprise a third set of authentication data, the role of which will be described below.
- an intermediate gateway of the network is implemented to carry out the transmission of the container of the user terminal to the management server during a phase of access to a service on the network.
- the intermediate gateway is then provided to perform a preliminary verification of the validity of the container before routing it to the management server, consisting of checking the validity of the third set of authentication data of the container.
- the third set of authentication data can be represented by bit strings obtained by hashing function collisions, in the same way as for the first set of data of the container.
- the third data set of the container can also be encrypted using a symmetric key encryption algorithm, type RC4.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Security & Cryptography (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Signal Processing (AREA)
- Finance (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Telephonic Communication Services (AREA)
- Storage Device Security (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0408797A FR2874295B1 (fr) | 2004-08-10 | 2004-08-10 | Procede d'authentification securisee pour la mise en oeuvre de services sur un reseau de transmission de donnees |
| PCT/FR2005/002034 WO2006021661A2 (fr) | 2004-08-10 | 2005-08-05 | Procede d'authentification securisee pour la mise en œuvre de services sur un reseau de transmission de donnees |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1829280A2 true EP1829280A2 (de) | 2007-09-05 |
Family
ID=34950840
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP05796271A Withdrawn EP1829280A2 (de) | 2004-08-10 | 2005-08-05 | Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US8359273B2 (de) |
| EP (1) | EP1829280A2 (de) |
| FR (1) | FR2874295B1 (de) |
| WO (1) | WO2006021661A2 (de) |
Families Citing this family (24)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6735288B1 (en) * | 2000-01-07 | 2004-05-11 | Cisco Technology, Inc. | Voice over IP voice mail system configured for placing an outgoing call and returning subscriber to mailbox after call completion |
| GB0319918D0 (en) * | 2003-08-23 | 2003-09-24 | Ibm | Method system and device for mobile subscription content access |
| US8874477B2 (en) | 2005-10-04 | 2014-10-28 | Steven Mark Hoffberg | Multifactorial optimization system and method |
| US7596092B2 (en) * | 2006-02-02 | 2009-09-29 | Cisco Technology, Inc. | VoIP verifier |
| ES2517865T3 (es) * | 2006-03-08 | 2014-11-04 | Monitise Limited | Métodos, aparatos y software para usar un testigo para calcular contraseña limitada en tiempo en teléfono celular |
| US9807096B2 (en) * | 2014-12-18 | 2017-10-31 | Live Nation Entertainment, Inc. | Controlled token distribution to protect against malicious data and resource access |
| JP5034821B2 (ja) * | 2007-09-21 | 2012-09-26 | ソニー株式会社 | 生体情報記憶装置 |
| US8819838B2 (en) * | 2008-01-25 | 2014-08-26 | Google Technology Holdings LLC | Piracy prevention in digital rights management systems |
| GB2464553B (en) * | 2008-10-22 | 2012-11-21 | Skype | Controlling a connection between a user terminal and an access node connected to a communication network |
| EP2502192A2 (de) * | 2009-11-18 | 2012-09-26 | Magid Joseph Mina | Zahlungssysteme und -verfahren bei anonymen transaktionen |
| US20110162054A1 (en) * | 2009-12-30 | 2011-06-30 | Infosys Technologies Limited | FIRMWARE AND METHOD FOR GENERATING ONE TIME PASSWORDS (OTPs) FOR APPLICATIONS |
| JP5573489B2 (ja) * | 2010-08-23 | 2014-08-20 | ソニー株式会社 | 情報処理装置、および情報処理方法、並びにプログラム |
| CN102572815B (zh) * | 2010-12-29 | 2014-11-05 | 中国移动通信集团公司 | 一种对终端应用请求的处理方法、系统及装置 |
| JP5935883B2 (ja) * | 2012-05-21 | 2016-06-15 | ソニー株式会社 | 情報処理装置、情報処理システム、および情報処理方法、並びにプログラム |
| US9106411B2 (en) | 2012-09-30 | 2015-08-11 | Apple Inc. | Secure escrow service |
| US9332008B2 (en) | 2014-03-28 | 2016-05-03 | Netiq Corporation | Time-based one time password (TOTP) for network authentication |
| US9842062B2 (en) | 2015-05-31 | 2017-12-12 | Apple Inc. | Backup accessible by subset of related devices |
| US10063557B2 (en) | 2015-06-07 | 2018-08-28 | Apple Inc. | Account access recovery system, method and apparatus |
| JP5951094B1 (ja) * | 2015-09-07 | 2016-07-13 | ヤフー株式会社 | 生成装置、端末装置、生成方法、生成プログラム及び認証処理システム |
| US10630648B1 (en) | 2017-02-08 | 2020-04-21 | United Services Automobile Association (Usaa) | Systems and methods for facilitating digital document communication |
| US11146398B2 (en) * | 2019-08-30 | 2021-10-12 | Comcast Cable Communications, Llc | Method and apparatus for secure token generation |
| US11870899B2 (en) * | 2021-08-30 | 2024-01-09 | Whitestar Communications, Inc. | Secure device access recovery based on validating encrypted target password from secure recovery container in trusted recovery device |
| US12361408B2 (en) * | 2021-09-24 | 2025-07-15 | Artema Labs, Inc | Systems and methods for transaction management in NFT-directed environments |
| CN115600177B (zh) * | 2022-10-09 | 2024-04-16 | 北京金和网络股份有限公司 | 一种身份认证的方法、装置、存储介质及电子设备 |
Family Cites Families (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5153919A (en) * | 1991-09-13 | 1992-10-06 | At&T Bell Laboratories | Service provision authentication protocol |
| US5970144A (en) * | 1997-01-31 | 1999-10-19 | Synacom Technology, Inc. | Secure authentication-key management system and method for mobile communications |
| CA2255285C (en) * | 1998-12-04 | 2009-10-13 | Certicom Corp. | Enhanced subscriber authentication protocol |
| US7035410B1 (en) * | 1999-03-01 | 2006-04-25 | At&T Corp. | Method and apparatus for enhanced security in a broadband telephony network |
| AU2374401A (en) * | 1999-12-03 | 2001-06-12 | First Hop Oy | A method and a system for obtaining services using a cellular telecommunication system |
| US6760841B1 (en) * | 2000-05-01 | 2004-07-06 | Xtec, Incorporated | Methods and apparatus for securely conducting and authenticating transactions over unsecured communication channels |
| US7721109B1 (en) * | 2000-07-28 | 2010-05-18 | Verizon Business Global Llc | Secure transaction card using biometrical validation |
| US6938019B1 (en) * | 2000-08-29 | 2005-08-30 | Uzo Chijioke Chukwuemeka | Method and apparatus for making secure electronic payments |
| PL345054A1 (en) * | 2001-01-11 | 2002-07-15 | Igor Hansen | Personal database system and method of managing the access to such database |
| US7181017B1 (en) * | 2001-03-23 | 2007-02-20 | David Felsher | System and method for secure three-party communications |
| US20030037261A1 (en) * | 2001-03-26 | 2003-02-20 | Ilumin Corporation | Secured content delivery system and method |
| US7302571B2 (en) * | 2001-04-12 | 2007-11-27 | The Regents Of The University Of Michigan | Method and system to maintain portable computer data secure and authentication token for use therein |
| EP1257106B1 (de) * | 2001-05-08 | 2005-03-23 | Telefonaktiebolaget LM Ericsson (publ) | Sicherer Zugang zu einem entfernten Teilnehmermodul |
| US20040029562A1 (en) * | 2001-08-21 | 2004-02-12 | Msafe Ltd. | System and method for securing communications over cellular networks |
| DE10164131A1 (de) * | 2001-12-30 | 2003-07-17 | Juergen K Lang | Kryptographisches Modul zur Speicherung und Wiedergabe kopier-und nutzungsgeschützter elektronischer Ton- und Bildmedien |
| GB2405566B (en) * | 2002-10-14 | 2005-05-18 | Toshiba Res Europ Ltd | Methods and systems for flexible delegation |
| US20050004873A1 (en) * | 2003-02-03 | 2005-01-06 | Robin Pou | Distribution and rights management of digital content |
| JP2006526204A (ja) * | 2003-03-13 | 2006-11-16 | ディーアールエム テクノロジーズ、エルエルシー | セキュアストリーミングコンテナ |
| US7421732B2 (en) * | 2003-05-05 | 2008-09-02 | Nokia Corporation | System, apparatus, and method for providing generic internet protocol authentication |
| US20050050330A1 (en) * | 2003-08-27 | 2005-03-03 | Leedor Agam | Security token |
| US7430606B1 (en) * | 2003-10-17 | 2008-09-30 | Arraycomm, Llc | Reducing certificate revocation lists at access points in a wireless access network |
-
2004
- 2004-08-10 FR FR0408797A patent/FR2874295B1/fr not_active Expired - Fee Related
-
2005
- 2005-08-05 WO PCT/FR2005/002034 patent/WO2006021661A2/fr not_active Ceased
- 2005-08-05 EP EP05796271A patent/EP1829280A2/de not_active Withdrawn
- 2005-08-05 US US11/659,836 patent/US8359273B2/en not_active Expired - Fee Related
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2006021661A2 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20080176533A1 (en) | 2008-07-24 |
| WO2006021661A2 (fr) | 2006-03-02 |
| FR2874295A1 (fr) | 2006-02-17 |
| FR2874295B1 (fr) | 2006-11-24 |
| WO2006021661A3 (fr) | 2006-10-26 |
| US8359273B2 (en) | 2013-01-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1829280A2 (de) | Verfahren zur gesicherten authentifikation zur bereitstellung von diensten in einem datenübertragungsnetz | |
| EP1683388B1 (de) | Verfahren zur Verwaltung der Sicherheit von Anwendungen in einem Sicherheitsmodul | |
| EP1442557B1 (de) | System und verfahren zur erzeugung eines gesicherten netzes unter verwendung von beglaubigungen von verfahrensgruppen | |
| EP1427231B1 (de) | Verfahren zur Herstellung und Verwaltung eines Vertrauensmodells zwischen einer SIM-Karte und einem mobilen Terminal | |
| EP1909462B1 (de) | Verfahren zur unterteilten Bereitstellung eines elektronischen Dienstes | |
| EP0973318A1 (de) | Verfahren zum Fernbezahlen mittels eines mobilen Funktelefons, die Erwerbung eines Gutes und/oder eines Dienstes und entsprechendes System und mobiles Funktelefon | |
| EP2279581A1 (de) | Verfahren zum sicheren senden digitaler daten an eine autorisierte drittpartei | |
| FR3058243A1 (fr) | Procede de controle d'identite d'un utilisateur au moyen d'une base de donnees publique | |
| FR2930391A1 (fr) | Terminal d'authentification d'un utilisateur. | |
| EP3758322A1 (de) | Verfahren und system zur erzeugung von chiffrierschlüsseln für transaktions- oder verbindungsdaten | |
| WO2015059389A1 (fr) | Procede d'execution d'une transaction entre un premier terminal et un deuxieme terminal | |
| EP3375133A1 (de) | Verfahren zur sicherung und authentifizierung einer telekommunikation | |
| EP3965361B1 (de) | Datenaustausch zwischen einem client und einem fernen gerät, z.b. ein geschützten modul | |
| EP1514377A1 (de) | Schnittstellenverfahren- und einrichtung zum online-austausch von inhaltsdaten auf sichere weise | |
| EP4241416B1 (de) | Verfahren zur delegierung des zugriffs auf eine blockchain | |
| EP1400090B1 (de) | Vorrichtung und verfahren zur bereitstellung gesicherter kommunikation in einem computernetzwerk | |
| EP4359986B1 (de) | Blockchain-zahlungsverfahren und -vorrichtung | |
| EP1949590A1 (de) | Verfahren zum sicheren deponieren digitaler daten, diesbezügliches verfahren zum wiederherstellen digitaler daten, diesbezügliche einrichtungen zum implementieren von verfahren und system mit den einrichtungen | |
| EP1413158B1 (de) | Zugangsverfahren zu einem von einem virtuellen operator vorgeschlagenen spezifischen dienst und chipkarte für eine entsprechende vorrichtung | |
| EP2911365B1 (de) | Verfahren und System zur Sicherung von Transaktionen, die von einer Vielzahl von Diensten zwischen einem Mobilgerät eines Benutzers und einer Akzeptanzstelle angeboten werden | |
| EP2317691B1 (de) | Vorrichtung und Verfahren zur kontextueller und dynamischer Sicherung der Datenaustausch durch ein Netzwerk | |
| WO2024153437A1 (fr) | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés | |
| FR3128089A1 (fr) | Procédé et dispositif de sélection d’une station de base | |
| FR2763192A1 (fr) | Procede de recuperation de cles mis en oeuvre pour un chiffrement fort de message | |
| FR3066346A1 (fr) | Procede de securisation en vue d'un appairage hors bande dans la bande |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20070615 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20100421 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20130701 |