WO2011069492A1 - Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne - Google Patents
Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne Download PDFInfo
- Publication number
- WO2011069492A1 WO2011069492A1 PCT/DE2010/001435 DE2010001435W WO2011069492A1 WO 2011069492 A1 WO2011069492 A1 WO 2011069492A1 DE 2010001435 W DE2010001435 W DE 2010001435W WO 2011069492 A1 WO2011069492 A1 WO 2011069492A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- computer
- server computer
- communication device
- mobile communication
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/42—User authentication using separate channels for security data
- G06F21/43—User authentication using separate channels for security data wireless channels
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/36—User authentication by graphic or iconic representation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/168—Implementing security features at a particular protocol layer above the transport layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/77—Graphical identity
Definitions
- the present invention relates to a method for providing a secure and convenient access to a document in a computer network, in particular to online user accounts (online accounts).
- CONFIRMATION COPY Challenged passwords can be secretly sent by the Trojan through the computer network, such as at headquarters where the stolen identities are collected and then resold for misuse purposes.
- the computer network such as at headquarters where the stolen identities are collected and then resold for misuse purposes.
- the method should also be able to provide access information to multiple user accounts, e.g. Passwords, usernames, login addresses, convenient and secure to handle.
- This object is achieved by a method in which, in addition to a server computer and a client computer, which are located in the same computer network, in addition a mobile communication device with a camera, a processor with memory and means for communication with a server Calculator is needed.
- the mobile communication device may in particular be a mobile phone with Internet access and a built-in camera.
- a request (information 1) is transmitted to the server computer by the user. This can be done, for example, by calling a so-called URL for a
- This response message contains a portion of the authorization data needed to provide access to the document on the server machine.
- the response message can be cryptographically encrypted.
- Response message is displayed on the user's screen, e.g. in the form of a bar code, displayed (information 3) and may include an identification of the server computer, the accessed website, and / or an identification of the client computer at the server computer.
- the information 3 displayed on the screen of the client computer is now read by the user by means of the camera of the mobile communication device (recorded) and processed in its processor.
- the information read in may be decrypted and stored with the information stored by the user in the memory and for the assignment of identification data to certain documents (e.g.
- the newly generated authorization data preferably represents a cryptographic signature.
- the newly generated authorization data are transmitted from the mobile communication device to the server computer and checked by the latter. If the check of the authorization data is positive and the server computer has identified the client computer based on the authorization data, the server computer transmits the access data (information 5) to the client computer. After receipt of the access data by the client computer, access to the document is granted. This can e.g. can be achieved by displaying a new page with the corresponding document (e.g., user account) on the screen of the client computer. Alternatively, the server computer sends to the client computer the URL of the requested document, possibly including authorization data, so that the user subsequently receives access to the document from the server computer.
- Client computer to replace the new document is sent as a response to a request from the client computer at the server computer. Therefore, according to the invention, the transmission of the access data (information 5) from the server computer to the client computer additionally at least one transmission of
- Information 6 from the client computer to the server computer (Fig. 2).
- the information 5 in this case is a response to information 6.
- the mobile phone According to a further embodiment of the invention, the mobile phone
- the account computer generates information 8 in response and transmits it to the mobile communication device. There they are processed, generating information 4 containing authorization data for accessing a document on the account computer. After receiving the
- Information 5 transmits the client computer to the account computer information 9, which preferably also contain authorization data.
- the account calculator checks the authorization and transmits the information 10 to the
- Client computer which preferably represents the requested document.
- the method for protection against the consequences of theft of the mobile communication device can be combined with a password query at the server, either via the usual login web page with Password query, or even via trojan-safe methods, such as the photo-PIN method, as described in DE-2007029759.
- the present invention further relates to computer program product for carrying out the method according to the invention on a processor in the server computer.
- the present invention further relates to computer program product for carrying out the method according to the invention on a processor in another server computer (account computer).
- the present invention further relates to computer program product for carrying out the method according to the invention on a processor in the mobile
- the user can thus log into an online user account on the computer screen without having to type in the password and the user name.
- Another advantage of the invention is that an identity theft by Trojans on the computer of the user is practically impossible, because it will not be used multiple times usable passwords, but only once-passwords that are valid for only a few seconds.
- Fig. 1 The server computer A sends after request 1 of the client computer B, the information 2 to the client computer B, the client screen as
- Information 3 will be presented.
- the information 3 is from the mobile
- Communication device C read and processed. The result is sent as information 4 to the server computer A. After positive examination of the data, the information 5 is sent to the client computer B, which provides the access there.
- Fig. 2 If, as in the case of the World Wide Web, the server computer A can not send information 5 directly to the client computer B, the server computer A is sent by a request sent from the client computer to the server computer given the opportunity to transmit the information 5 in response to the information 6 to the client computer B ("polling").
- Fig. 3 In the case of the mobile communication device C, a communication procedure can take place with a second server computer (AccOunt computer) D, which consists at least of the transmission of two information 7 (out) and 8 (back).
- the second server computer (AccOunt computer) D which consists at least of the transmission of two information 7 (out) and 8 (back).
- Authorization data for access to this second server D arrive as part of the information 4 and 5 at client computer B, which uses this data to establish access to the second server D by sending the authorization data as information 9 to the second server D which then provides the access on the screen of the client computer by transmitting information 10 to the client computer B.
- the method according to the invention can provide access to online use in the
- the server name, account name and a secret cryptographic key are stored on the user's photo phone. If the user wants to go into the user account, they go to the login account of the user account provider. There, the account server has presented a 2D code in which the server name and a
- Session ID stand. This information is read by the user by photographing in the camera phone. The camera phone will then - completely independently - do the following: it searches for the saved username for this server name; then calculated it from the session ID with the key a codeword (signature); At the end, the mobile phone goes via mobile Internet to a website of the account server and sends the account server the user name, the session ID and the code word calculated from it. The account server checks the information: if the code word is ok, the account server activates the user account, ie the situation on the user's screen is displayed as after logging in.
- the user's camera phone stores multiple user accounts as in the example above.
- the user invokes a fixed remote redirect web page with their browser. He reads the 2D code on the page with a program on the camera phone.
- the camera phone then displays a list of user accounts on the display. The user selects a user account. Then the phone sits in the background with the
- the browser calls a login page of the account server and sends server name. Username, session ID and signature value as parameters with. After a positive check of the authorization data, the opened user account appears in the browser window of the user.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
Abstract
L'invention concerne un procédé pour fournir un accès sécurisé et confortable à un document dans un réseau informatique, notamment à des comptes d'utilisateurs en ligne, en particulier à des comptes d'utilisateurs à accès limité, requérant une autorisation. La mise en oeuvre de ce procédé nécessite, outre un ordinateur serveur et un ordinateur client, un appareil de communication mobile équipé d'une caméra. Ce procédé comprend les étapes suivantes : sur demande (1) de l'ordinateur client (B), l'ordinateur serveur (A) envoie à ce dernier les informations (2) qui sont affichées sur l'écran du client sous la forme d'informations (3); ces dernières (3) sont lues et traitées par l'appareil de communication mobile (C); le résultat est transmis sous la forme d'informations (4) à l'ordinateur serveur (A); après contrôle positif des données, les informations (5) sont envoyées à l'ordinateur client (B) qui fournit l'accès. Ce procédé permet de manipuler, de manière confortable et sécurisée, des informations d'accès à plusieurs comptes d'utilisateurs, par exemple des mots de passe, des noms d'utilisateurs, des adresses de connexion. Ce procédé n'utilise pas de mots de passe permanents, mais uniquement des mots de passe uniques, valables seulement quelque secondes.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102009057800.5 | 2009-12-10 | ||
| DE102009057800A DE102009057800A1 (de) | 2009-12-10 | 2009-12-10 | Verfahren zum Bereitstellen eines sicheren und komfortablen Zugangs zu Online-Accounts via Fern-Weiterleitung |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2011069492A1 true WO2011069492A1 (fr) | 2011-06-16 |
Family
ID=43902641
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/DE2010/001435 Ceased WO2011069492A1 (fr) | 2009-12-10 | 2010-12-09 | Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne |
Country Status (2)
| Country | Link |
|---|---|
| DE (1) | DE102009057800A1 (fr) |
| WO (1) | WO2011069492A1 (fr) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2693687A1 (fr) * | 2012-08-02 | 2014-02-05 | Banco Bilbao Vizcaya Argentaria, S.A. | Procédé de génération d'un code, procédé d'autorisation et système d'autorisation pour autoriser une opération |
| WO2014122614A3 (fr) * | 2013-02-08 | 2014-12-04 | Kochhar Anant | Procédé d'interaction d'utilisateur sécurisé réalisant des actions définies sur des ressources internet sur un canal séparé et système correspondant |
| US9729532B2 (en) | 2012-09-12 | 2017-08-08 | Zte Corporation | User identity authenticating method and device for preventing malicious harassment |
| CN107147625B (zh) * | 2017-04-25 | 2019-12-24 | 杭州禹乐网络科技有限公司 | 游戏登陆管理系统及方法 |
| TWI780047B (zh) * | 2016-08-05 | 2022-10-11 | 香港商阿里巴巴集團服務有限公司 | 身份認證方法、裝置和系統 |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR2981815A1 (fr) * | 2011-10-19 | 2013-04-26 | Bertrand Labaye | Procede securise d'authentification forte et de controle d'acces sans contact |
| FR3003671B1 (fr) * | 2013-03-25 | 2016-12-23 | Cassidian Cybersecurity Sas | Procede de generation d'un code pour la securisation d'une transaction |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2007193762A (ja) * | 2005-12-23 | 2007-08-02 | Toshiba Corp | ユーザー認証システムと、このユーザー認証システムで使用される提供用サーバ装置、携帯通信装置、利用者用携帯通信装置、承認者用携帯通信装置および認証用サーバ装置と、これらの装置のためのプログラム |
| EP2166697A1 (fr) * | 2008-09-17 | 2010-03-24 | GMV Soluciones Globales Internet S.A. | Procédé et système d'authentification d'un utilisateur au moyen d'un dispositif mobile |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10138381B4 (de) * | 2001-08-13 | 2005-04-07 | Orga Systems Enabling Services Gmbh | Computersystem und Verfahren zur Datenzugriffskontrolle |
| US7387250B2 (en) * | 2003-12-04 | 2008-06-17 | Scanbuy, Inc. | System and method for on the spot purchasing by scanning barcodes from screens with a mobile device |
-
2009
- 2009-12-10 DE DE102009057800A patent/DE102009057800A1/de not_active Withdrawn
-
2010
- 2010-12-09 WO PCT/DE2010/001435 patent/WO2011069492A1/fr not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2007193762A (ja) * | 2005-12-23 | 2007-08-02 | Toshiba Corp | ユーザー認証システムと、このユーザー認証システムで使用される提供用サーバ装置、携帯通信装置、利用者用携帯通信装置、承認者用携帯通信装置および認証用サーバ装置と、これらの装置のためのプログラム |
| EP2166697A1 (fr) * | 2008-09-17 | 2010-03-24 | GMV Soluciones Globales Internet S.A. | Procédé et système d'authentification d'un utilisateur au moyen d'un dispositif mobile |
Non-Patent Citations (1)
| Title |
|---|
| MICHIRU TANAKA ET AL: "A Method and Its Usability for User Authentication by Utilizing a Matrix Code Reader on Mobile Phones", 28 August 2006, INFORMATION SECURITY APPLICATIONS; [LECTURE NOTES IN COMPUTER SCIENCE;;LNCS], SPRINGER BERLIN HEIDELBERG, BERLIN, HEIDELBERG, PAGE(S) 225 - 236, ISBN: 978-3-540-71092-9, XP019077665 * |
Cited By (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2693687A1 (fr) * | 2012-08-02 | 2014-02-05 | Banco Bilbao Vizcaya Argentaria, S.A. | Procédé de génération d'un code, procédé d'autorisation et système d'autorisation pour autoriser une opération |
| WO2014020092A1 (fr) * | 2012-08-02 | 2014-02-06 | Banco Bilbao Vizcaya Argentaria, S.A. | Procédé permettant de générer un code, procédé d'autorisation et système d'autorisation permettant d'autoriser une opération |
| US8930694B2 (en) | 2012-08-02 | 2015-01-06 | Banco Bilbao Vizcaya Argentaria, S.A. | Method for the generation of a code, and method and system for the authorization of an operation |
| AU2013298545B2 (en) * | 2012-08-02 | 2015-08-20 | Banco Bilbao Vizcaya Argentaria, S.A. | Method for generating a code, authorization method and authorization system for authorizing an operation |
| US9729532B2 (en) | 2012-09-12 | 2017-08-08 | Zte Corporation | User identity authenticating method and device for preventing malicious harassment |
| WO2014122614A3 (fr) * | 2013-02-08 | 2014-12-04 | Kochhar Anant | Procédé d'interaction d'utilisateur sécurisé réalisant des actions définies sur des ressources internet sur un canal séparé et système correspondant |
| TWI780047B (zh) * | 2016-08-05 | 2022-10-11 | 香港商阿里巴巴集團服務有限公司 | 身份認證方法、裝置和系統 |
| CN107147625B (zh) * | 2017-04-25 | 2019-12-24 | 杭州禹乐网络科技有限公司 | 游戏登陆管理系统及方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| DE102009057800A1 (de) | 2011-06-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE60027971T2 (de) | Einmalige Anmeldung in einem Netzwerksystem, das mehrere gesondert steuerbare Ressourcen mit begrenztem Zugang enthält | |
| DE60308692T2 (de) | Verfahren und system für benutzerbestimmte authentifizierung und einmalige anmeldung in einer föderalisierten umgebung | |
| DE602004012996T2 (de) | Verfahren und vorrichtung zum authentifizieren von benutzern und websites | |
| DE60308733T2 (de) | Dienstanbieteranonymisierung in einem single sign-on system | |
| EP2454703B1 (fr) | Procédé de lecture d'attributs contenus dans un jeton d'identification | |
| DE102011089580B3 (de) | Verfahren zum Lesen von Attributen aus einem ID-Token | |
| DE102011084728B4 (de) | Verfahren zum Starten einer externen Applikation und bidirektionaler Kommunikation zwischen einem Browser und einer externen Applikation ohne Browsererweiterungen | |
| EP2289016B1 (fr) | Utilisation d'un appareil de télécommunication mobile comme carte de santé électronique | |
| WO2011069492A1 (fr) | Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne | |
| DE102010028133A1 (de) | Verfahren zum Lesen eines Attributs aus einem ID-Token | |
| DE102012213807A1 (de) | Steuerung des Lightweight-Dokumentenzugriffs mithilfe von Zugriffskontrolllisten im Cloud-Speicher oder auf dem lokalen Dateisystem | |
| DE102009001959A1 (de) | Verfahren zum Lesen von Attributen aus einem ID-Token über eine Mobilfunkverbindung | |
| EP3127293A1 (fr) | Système d'authentification réparti et procédé correspondant | |
| WO2013124145A1 (fr) | Procédé de paiement informatisé | |
| EP3528159B1 (fr) | Procédé de création d'un pseudonyme à l'aide d'un jeton d'id | |
| EP2380330B1 (fr) | Procédé et dispositif d'authentification d'utilisateurs d'un terminal hybride | |
| EP3540623B1 (fr) | Procédé de génération d'un pseudonyme à l'aide d'un jeton d'id | |
| WO2013152986A1 (fr) | Génération sécurisée d'un compte utilisateur dans un serveur de services | |
| EP2783320B1 (fr) | Procédé pour authentifier une personne se trouvant au niveau d'une instance de serveur | |
| EP3414879B1 (fr) | Utilisation d'un procédé cryptographique non-local après l'authentifcation | |
| DE10251408A1 (de) | Sicherer und vermittelter Zugriff für E-Dienste | |
| DE102021125572B3 (de) | Verfahren zur Durchführung eines Authentisierungsprozesses durch einen individuellen Systembenutzer | |
| DE102014201846A1 (de) | Verfahren zur sicheren Übertragung von Zeichen | |
| DE102011122972B3 (de) | Verfahren zum Starten einer externen Applikation und bidirektionaler Kommunikation zwischen einem Browser und einer externen Applikation ohne Browsererweiterungen | |
| EP2645670A1 (fr) | Mise à disposition d'attributs d'identité d'un utilisateur |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 10810820 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 10810820 Country of ref document: EP Kind code of ref document: A1 |