WO2011069492A1 - Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne - Google Patents

Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne Download PDF

Info

Publication number
WO2011069492A1
WO2011069492A1 PCT/DE2010/001435 DE2010001435W WO2011069492A1 WO 2011069492 A1 WO2011069492 A1 WO 2011069492A1 DE 2010001435 W DE2010001435 W DE 2010001435W WO 2011069492 A1 WO2011069492 A1 WO 2011069492A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
computer
server computer
communication device
mobile communication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/DE2010/001435
Other languages
German (de)
English (en)
Inventor
Bernd Borchert
Klaus Reinhardt
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Eberhard Karls Universitaet Tuebingen
Original Assignee
Eberhard Karls Universitaet Tuebingen
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Eberhard Karls Universitaet Tuebingen filed Critical Eberhard Karls Universitaet Tuebingen
Publication of WO2011069492A1 publication Critical patent/WO2011069492A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/42User authentication using separate channels for security data
    • G06F21/43User authentication using separate channels for security data wireless channels
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/36User authentication by graphic or iconic representation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/77Graphical identity

Definitions

  • the present invention relates to a method for providing a secure and convenient access to a document in a computer network, in particular to online user accounts (online accounts).
  • CONFIRMATION COPY Challenged passwords can be secretly sent by the Trojan through the computer network, such as at headquarters where the stolen identities are collected and then resold for misuse purposes.
  • the computer network such as at headquarters where the stolen identities are collected and then resold for misuse purposes.
  • the method should also be able to provide access information to multiple user accounts, e.g. Passwords, usernames, login addresses, convenient and secure to handle.
  • This object is achieved by a method in which, in addition to a server computer and a client computer, which are located in the same computer network, in addition a mobile communication device with a camera, a processor with memory and means for communication with a server Calculator is needed.
  • the mobile communication device may in particular be a mobile phone with Internet access and a built-in camera.
  • a request (information 1) is transmitted to the server computer by the user. This can be done, for example, by calling a so-called URL for a
  • This response message contains a portion of the authorization data needed to provide access to the document on the server machine.
  • the response message can be cryptographically encrypted.
  • Response message is displayed on the user's screen, e.g. in the form of a bar code, displayed (information 3) and may include an identification of the server computer, the accessed website, and / or an identification of the client computer at the server computer.
  • the information 3 displayed on the screen of the client computer is now read by the user by means of the camera of the mobile communication device (recorded) and processed in its processor.
  • the information read in may be decrypted and stored with the information stored by the user in the memory and for the assignment of identification data to certain documents (e.g.
  • the newly generated authorization data preferably represents a cryptographic signature.
  • the newly generated authorization data are transmitted from the mobile communication device to the server computer and checked by the latter. If the check of the authorization data is positive and the server computer has identified the client computer based on the authorization data, the server computer transmits the access data (information 5) to the client computer. After receipt of the access data by the client computer, access to the document is granted. This can e.g. can be achieved by displaying a new page with the corresponding document (e.g., user account) on the screen of the client computer. Alternatively, the server computer sends to the client computer the URL of the requested document, possibly including authorization data, so that the user subsequently receives access to the document from the server computer.
  • Client computer to replace the new document is sent as a response to a request from the client computer at the server computer. Therefore, according to the invention, the transmission of the access data (information 5) from the server computer to the client computer additionally at least one transmission of
  • Information 6 from the client computer to the server computer (Fig. 2).
  • the information 5 in this case is a response to information 6.
  • the mobile phone According to a further embodiment of the invention, the mobile phone
  • the account computer generates information 8 in response and transmits it to the mobile communication device. There they are processed, generating information 4 containing authorization data for accessing a document on the account computer. After receiving the
  • Information 5 transmits the client computer to the account computer information 9, which preferably also contain authorization data.
  • the account calculator checks the authorization and transmits the information 10 to the
  • Client computer which preferably represents the requested document.
  • the method for protection against the consequences of theft of the mobile communication device can be combined with a password query at the server, either via the usual login web page with Password query, or even via trojan-safe methods, such as the photo-PIN method, as described in DE-2007029759.
  • the present invention further relates to computer program product for carrying out the method according to the invention on a processor in the server computer.
  • the present invention further relates to computer program product for carrying out the method according to the invention on a processor in another server computer (account computer).
  • the present invention further relates to computer program product for carrying out the method according to the invention on a processor in the mobile
  • the user can thus log into an online user account on the computer screen without having to type in the password and the user name.
  • Another advantage of the invention is that an identity theft by Trojans on the computer of the user is practically impossible, because it will not be used multiple times usable passwords, but only once-passwords that are valid for only a few seconds.
  • Fig. 1 The server computer A sends after request 1 of the client computer B, the information 2 to the client computer B, the client screen as
  • Information 3 will be presented.
  • the information 3 is from the mobile
  • Communication device C read and processed. The result is sent as information 4 to the server computer A. After positive examination of the data, the information 5 is sent to the client computer B, which provides the access there.
  • Fig. 2 If, as in the case of the World Wide Web, the server computer A can not send information 5 directly to the client computer B, the server computer A is sent by a request sent from the client computer to the server computer given the opportunity to transmit the information 5 in response to the information 6 to the client computer B ("polling").
  • Fig. 3 In the case of the mobile communication device C, a communication procedure can take place with a second server computer (AccOunt computer) D, which consists at least of the transmission of two information 7 (out) and 8 (back).
  • the second server computer (AccOunt computer) D which consists at least of the transmission of two information 7 (out) and 8 (back).
  • Authorization data for access to this second server D arrive as part of the information 4 and 5 at client computer B, which uses this data to establish access to the second server D by sending the authorization data as information 9 to the second server D which then provides the access on the screen of the client computer by transmitting information 10 to the client computer B.
  • the method according to the invention can provide access to online use in the
  • the server name, account name and a secret cryptographic key are stored on the user's photo phone. If the user wants to go into the user account, they go to the login account of the user account provider. There, the account server has presented a 2D code in which the server name and a
  • Session ID stand. This information is read by the user by photographing in the camera phone. The camera phone will then - completely independently - do the following: it searches for the saved username for this server name; then calculated it from the session ID with the key a codeword (signature); At the end, the mobile phone goes via mobile Internet to a website of the account server and sends the account server the user name, the session ID and the code word calculated from it. The account server checks the information: if the code word is ok, the account server activates the user account, ie the situation on the user's screen is displayed as after logging in.
  • the user's camera phone stores multiple user accounts as in the example above.
  • the user invokes a fixed remote redirect web page with their browser. He reads the 2D code on the page with a program on the camera phone.
  • the camera phone then displays a list of user accounts on the display. The user selects a user account. Then the phone sits in the background with the
  • the browser calls a login page of the account server and sends server name. Username, session ID and signature value as parameters with. After a positive check of the authorization data, the opened user account appears in the browser window of the user.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

L'invention concerne un procédé pour fournir un accès sécurisé et confortable à un document dans un réseau informatique, notamment à des comptes d'utilisateurs en ligne, en particulier à des comptes d'utilisateurs à accès limité, requérant une autorisation. La mise en oeuvre de ce procédé nécessite, outre un ordinateur serveur et un ordinateur client, un appareil de communication mobile équipé d'une caméra. Ce procédé comprend les étapes suivantes : sur demande (1) de l'ordinateur client (B), l'ordinateur serveur (A) envoie à ce dernier les informations (2) qui sont affichées sur l'écran du client sous la forme d'informations (3); ces dernières (3) sont lues et traitées par l'appareil de communication mobile (C); le résultat est transmis sous la forme d'informations (4) à l'ordinateur serveur (A); après contrôle positif des données, les informations (5) sont envoyées à l'ordinateur client (B) qui fournit l'accès. Ce procédé permet de manipuler, de manière confortable et sécurisée, des informations d'accès à plusieurs comptes d'utilisateurs, par exemple des mots de passe, des noms d'utilisateurs, des adresses de connexion. Ce procédé n'utilise pas de mots de passe permanents, mais uniquement des mots de passe uniques, valables seulement quelque secondes.
PCT/DE2010/001435 2009-12-10 2010-12-09 Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne Ceased WO2011069492A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE102009057800.5 2009-12-10
DE102009057800A DE102009057800A1 (de) 2009-12-10 2009-12-10 Verfahren zum Bereitstellen eines sicheren und komfortablen Zugangs zu Online-Accounts via Fern-Weiterleitung

Publications (1)

Publication Number Publication Date
WO2011069492A1 true WO2011069492A1 (fr) 2011-06-16

Family

ID=43902641

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/DE2010/001435 Ceased WO2011069492A1 (fr) 2009-12-10 2010-12-09 Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne

Country Status (2)

Country Link
DE (1) DE102009057800A1 (fr)
WO (1) WO2011069492A1 (fr)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2693687A1 (fr) * 2012-08-02 2014-02-05 Banco Bilbao Vizcaya Argentaria, S.A. Procédé de génération d'un code, procédé d'autorisation et système d'autorisation pour autoriser une opération
WO2014122614A3 (fr) * 2013-02-08 2014-12-04 Kochhar Anant Procédé d'interaction d'utilisateur sécurisé réalisant des actions définies sur des ressources internet sur un canal séparé et système correspondant
US9729532B2 (en) 2012-09-12 2017-08-08 Zte Corporation User identity authenticating method and device for preventing malicious harassment
CN107147625B (zh) * 2017-04-25 2019-12-24 杭州禹乐网络科技有限公司 游戏登陆管理系统及方法
TWI780047B (zh) * 2016-08-05 2022-10-11 香港商阿里巴巴集團服務有限公司 身份認證方法、裝置和系統

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR2981815A1 (fr) * 2011-10-19 2013-04-26 Bertrand Labaye Procede securise d'authentification forte et de controle d'acces sans contact
FR3003671B1 (fr) * 2013-03-25 2016-12-23 Cassidian Cybersecurity Sas Procede de generation d'un code pour la securisation d'une transaction

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007193762A (ja) * 2005-12-23 2007-08-02 Toshiba Corp ユーザー認証システムと、このユーザー認証システムで使用される提供用サーバ装置、携帯通信装置、利用者用携帯通信装置、承認者用携帯通信装置および認証用サーバ装置と、これらの装置のためのプログラム
EP2166697A1 (fr) * 2008-09-17 2010-03-24 GMV Soluciones Globales Internet S.A. Procédé et système d'authentification d'un utilisateur au moyen d'un dispositif mobile

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE10138381B4 (de) * 2001-08-13 2005-04-07 Orga Systems Enabling Services Gmbh Computersystem und Verfahren zur Datenzugriffskontrolle
US7387250B2 (en) * 2003-12-04 2008-06-17 Scanbuy, Inc. System and method for on the spot purchasing by scanning barcodes from screens with a mobile device

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007193762A (ja) * 2005-12-23 2007-08-02 Toshiba Corp ユーザー認証システムと、このユーザー認証システムで使用される提供用サーバ装置、携帯通信装置、利用者用携帯通信装置、承認者用携帯通信装置および認証用サーバ装置と、これらの装置のためのプログラム
EP2166697A1 (fr) * 2008-09-17 2010-03-24 GMV Soluciones Globales Internet S.A. Procédé et système d'authentification d'un utilisateur au moyen d'un dispositif mobile

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
MICHIRU TANAKA ET AL: "A Method and Its Usability for User Authentication by Utilizing a Matrix Code Reader on Mobile Phones", 28 August 2006, INFORMATION SECURITY APPLICATIONS; [LECTURE NOTES IN COMPUTER SCIENCE;;LNCS], SPRINGER BERLIN HEIDELBERG, BERLIN, HEIDELBERG, PAGE(S) 225 - 236, ISBN: 978-3-540-71092-9, XP019077665 *

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2693687A1 (fr) * 2012-08-02 2014-02-05 Banco Bilbao Vizcaya Argentaria, S.A. Procédé de génération d'un code, procédé d'autorisation et système d'autorisation pour autoriser une opération
WO2014020092A1 (fr) * 2012-08-02 2014-02-06 Banco Bilbao Vizcaya Argentaria, S.A. Procédé permettant de générer un code, procédé d'autorisation et système d'autorisation permettant d'autoriser une opération
US8930694B2 (en) 2012-08-02 2015-01-06 Banco Bilbao Vizcaya Argentaria, S.A. Method for the generation of a code, and method and system for the authorization of an operation
AU2013298545B2 (en) * 2012-08-02 2015-08-20 Banco Bilbao Vizcaya Argentaria, S.A. Method for generating a code, authorization method and authorization system for authorizing an operation
US9729532B2 (en) 2012-09-12 2017-08-08 Zte Corporation User identity authenticating method and device for preventing malicious harassment
WO2014122614A3 (fr) * 2013-02-08 2014-12-04 Kochhar Anant Procédé d'interaction d'utilisateur sécurisé réalisant des actions définies sur des ressources internet sur un canal séparé et système correspondant
TWI780047B (zh) * 2016-08-05 2022-10-11 香港商阿里巴巴集團服務有限公司 身份認證方法、裝置和系統
CN107147625B (zh) * 2017-04-25 2019-12-24 杭州禹乐网络科技有限公司 游戏登陆管理系统及方法

Also Published As

Publication number Publication date
DE102009057800A1 (de) 2011-06-16

Similar Documents

Publication Publication Date Title
DE60027971T2 (de) Einmalige Anmeldung in einem Netzwerksystem, das mehrere gesondert steuerbare Ressourcen mit begrenztem Zugang enthält
DE60308692T2 (de) Verfahren und system für benutzerbestimmte authentifizierung und einmalige anmeldung in einer föderalisierten umgebung
DE602004012996T2 (de) Verfahren und vorrichtung zum authentifizieren von benutzern und websites
DE60308733T2 (de) Dienstanbieteranonymisierung in einem single sign-on system
EP2454703B1 (fr) Procédé de lecture d'attributs contenus dans un jeton d'identification
DE102011089580B3 (de) Verfahren zum Lesen von Attributen aus einem ID-Token
DE102011084728B4 (de) Verfahren zum Starten einer externen Applikation und bidirektionaler Kommunikation zwischen einem Browser und einer externen Applikation ohne Browsererweiterungen
EP2289016B1 (fr) Utilisation d'un appareil de télécommunication mobile comme carte de santé électronique
WO2011069492A1 (fr) Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne
DE102010028133A1 (de) Verfahren zum Lesen eines Attributs aus einem ID-Token
DE102012213807A1 (de) Steuerung des Lightweight-Dokumentenzugriffs mithilfe von Zugriffskontrolllisten im Cloud-Speicher oder auf dem lokalen Dateisystem
DE102009001959A1 (de) Verfahren zum Lesen von Attributen aus einem ID-Token über eine Mobilfunkverbindung
EP3127293A1 (fr) Système d'authentification réparti et procédé correspondant
WO2013124145A1 (fr) Procédé de paiement informatisé
EP3528159B1 (fr) Procédé de création d'un pseudonyme à l'aide d'un jeton d'id
EP2380330B1 (fr) Procédé et dispositif d'authentification d'utilisateurs d'un terminal hybride
EP3540623B1 (fr) Procédé de génération d'un pseudonyme à l'aide d'un jeton d'id
WO2013152986A1 (fr) Génération sécurisée d'un compte utilisateur dans un serveur de services
EP2783320B1 (fr) Procédé pour authentifier une personne se trouvant au niveau d'une instance de serveur
EP3414879B1 (fr) Utilisation d'un procédé cryptographique non-local après l'authentifcation
DE10251408A1 (de) Sicherer und vermittelter Zugriff für E-Dienste
DE102021125572B3 (de) Verfahren zur Durchführung eines Authentisierungsprozesses durch einen individuellen Systembenutzer
DE102014201846A1 (de) Verfahren zur sicheren Übertragung von Zeichen
DE102011122972B3 (de) Verfahren zum Starten einer externen Applikation und bidirektionaler Kommunikation zwischen einem Browser und einer externen Applikation ohne Browsererweiterungen
EP2645670A1 (fr) Mise à disposition d'attributs d'identité d'un utilisateur

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10810820

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 10810820

Country of ref document: EP

Kind code of ref document: A1