Authorization method and system in data transfer systems
22 claims: 22 independent, 0 dependent
- 1Process of authorization in data communications systems employing a transaction number (TAN) or a comparable password with the following features:- In a 1st step by means of a data inputting unit (1), the user sends his means of identification and/or an identification signal of the data inputting unit (1) via a data line to an authorization computer (2) together with a request for it to generate a TAN or a comparable password or to select the same from a file.- In a 2nd step the authorization computer (2) generates the TAN or the comparable password or selects the same from a file.- In a 3rd step the authorization computer (2) sends the TAN or the comparable password via a radio link to a receiver (3).- In a 4th step the user reads the said TAN or the comparable password from the receiver (3).- In a 5th step manual inputting is effected by the user into the data inputting unit (1).- In a 6th step the said TAN or comparable password is transmitted via the said data line to the authorization computer (2) once more.- In a 7th step the authorization computer (2) checks the validity of the TAN or comparable password.- In an 8th step a connection setup is established or released between the data inputting unit (1) and a receiver unit (4).characterized by the TAN being usable once only or being a comparable password having a predefined user time. Procédure d'autorisation dans des systèmes de transmission de données utilisant un numéro de transaction (TAN) ou mot de passe similaire et possédant les caractéristiques suivantes : - dans une 1ère étape, et au moyen d'une unité de saisie de données (1), l'utilisateur envoie à un serveur d'autorisation (2) via une ligne de transmission de données son identification et/ou une identification de l'unité de saisie de données (1) accompagnée d'une demande de génération ou de sélection à partir d'un fichier d'un TAN ou d'un mot de passe similaire,- dans une 2ème étape, le serveur d'autorisation (2) génère ou sélectionne à partir d'un fichier le TAN ou le mot de passe comparable,- dans une 3ème étape, le serveur d'autorisation (3) envoie par le biais d'un circuit radio le TAN ou le mot de passe comparable à un récepteur (3),- dans une 4ème étape, l'utilisateur déchiffre sur le récepteur (3) ce TAN ou le mot de passe comparable- et les entre dans une 5ème étape dans l'unité de saisie de données (1),- dans une 6ème étape, ce TAN ou le mot de passe comparable est retransmis au serveur d'autorisation via la ligne de transmission de données,- dans une 7ème étape, le serveur d'autorisation vérifie la validité du TAN ou du mot de passe comparable, pour ensuite- établir ou libérer dans une 8ème étape une connexion entre l'unité de saisie de données (1) et une unité de réception (4),caractérisée par le fait qu'il s'agit d'un TAN ou mot de passe similaire à utilisation unique et à durée d'utilisation prédéfinie. Verfahren zur Autorisierung in Datenübertragungssystemen unter Verwendung einer Transaktionsnummer (TAN) oder eines vergleichbaren Paßworts mit den Merkmalen - daß der Benutzer in einem 1. Schritt über ein Dateneingabegerät (1) seine Identifizierung und/oder eine Identifizierungs-Kennung des Dateneingabegeräts (1) zusammen mit der Aufforderung zur Generierung oder zur Auswahl einer TAN oder eines vergleichbaren Paßworts aus einer Datei über eine Datenleitung an einen Autorisierungsrechner (2) sendet,- daß in einem 2. Schritt der Autorisierungsrechner (2) die TAN oder das vergleichbare Paßwort generiert oder aus einer Datei auswählt,- daß in einem 3. Schritt der Autorisierungsrechner (3) die TAN oder das vergleichbare Paßwort über eine Funkverbindung an einen Empfänger (3) sendet,- daß in einem 4. Schritt der Benutzer diese TAN oder das vergleichbare Paßwort von dem Empfänger (3) abliest,- in einem 5. Schritt manuell in das Dateneingabegerät (1) eingibt,- daß in einem 6. Schritt diese TAN oder das vergleichbare Paßwort über die Datenleitung wieder an den Autorisierungsrechner (2) übermittelt wird,- daß in einem 7. Schritt der Autorisierungsrechner (2) die Gültigkeit der TAN oder des vergleichbaren Paßworts prüft, um dann- in einem 8. Schritt einen Verbindungsaufbau zwischen dem Dateneingabegerät (1) und einer Empfangseinheit (4) herzustellen oder freizuschalten,dadurch gekennzeichnet,daß es sich um eine nur einmal verwendbare TAN oder ein vergleichbares Passwort handelt, welche eine vordefinierte Benutzerzeit haben.
- 2Process according to claim 1), characterized by the validity of the TAN or comparable password being dependent on a predefined number of transferred files. Procédure selon revendication 1) caractérisée par le fait que la validité du TAN ou du mot de passe comparable est fonction d'un nombre prédéfini de fichiers transmis. Verfahren nach Anspruch 1), dadurch gekennzeichnet, daß die Gültigkeit der TAN oder des vergleichbaren Paßworts von einer vordefinierten Anzahl der übertragenen Dateien abhängig ist.
- 3Process according to claim 1) or 2), characterized by the validity of the TAN or comparable password being dependent on a predefined size of the transferred files. Procédure selon revendication 1) ou 2) caractérisée par le fait que la validité du TAN ou du mot de passe comparable est fonction d'un volume prédéfini de fichiers transmis. Verfahren nach Anspruch 1) oder 2), dadurch gekennzeichnet, daß die Gültigkeit der TAN oder des vergleichbaren Paßworts von einer vordefinierten Größe der übertragenen Dateien abhängig ist.
- 4Process according to one or several claims 1) to 3), characterized by access to the data inputting unit (1) and/or receiver (3) and/or receiver unit (4) being protected by a password. Procédure selon l'une ou plusieurs des revendications 1) à 3) caractérisée par le fait que l'accès à l'unité de saisie de données (1) et/ou le récepteur (3) et/ou l'unité de réception (4) est protégé au moyen d'un mot de passe. Verfahren nach einem oder mehreren der Ansprüche 1) bis 3), dadurch gekennzeichnet, daß der Zugriff auf das Dateneingabegerät (1) und/oder der Empfänger (3) und/oder die Empfangseinheit (4) durch ein Passwort geschützt ist.
- 5Process according to one or several claims 1) to 4), characterized by the data transmitted from the data inputting unit (1) to the receiver unit (4) or vice versa being coded. Procédure selon l'une ou plusieurs des revendications 1) à 4) caractérisée par le fait que les données transmises de l'unité de saisie de données à l'unité de réception (4), ou dans le sens inverse, sont codées. Verfahren nach einem oder mehreren der Ansprüche (1) bis 4), dadurch gekennzeichnet, daß die von dem Dateneingabegerät (1) an die Empfangseinheit(4) oder umgekehrt übermittelten Daten verschlüsselt sind.
- 6Process according to one or several claims 1) to 5), characterized by the data transmitted from data inputting unit (1) to the authorization computer (2) or vice versa being coded. Procédure selon l'une ou plusieurs des revendications 1) à 5) caractérisée par le fait que les données transmises de l'unité de saisie de données au serveur d'autorisation (2), ou dans le sens inverse, sont codées. Verfahren nach einem oder mehreren der Ansprüche 1) bis 5), dadurch gekennzeichnet, daß die von dem Dateneingabegerät (1) an den Autorisierungsrechner (2) oder umgekehrt übermittelten Daten verschlüsselt sind.
- 7Device incorporating means for executing the steps of the said process according to one or several claims 1) to 6), characterized by the receiver (3) of the once-only usable TAN or a comparable password with predefined user time being a pager (31). Installation permettant d'exécuter les différentes étapes de la procédure selon l'une ou plusieurs des revendications 1) à 6) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est un pager (31). Vorrichtung mit Mitteln zur Ausführung der Schritte des Verfahrens nach einem oder mehreren der Ansprüche 1 bis 6).
- 8Device according to claim 7. Installation selon revendication 7) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est un pager (31). Vorrichtung nach Anspruch 7, dadurch gekennzeichnet, daß der Empfänger (3) der nur einmal verwendbaren TAN oder eines vergleichbaren Passwortes, welche eine vordefinierte Benutzerzeit haben, ein Pager (31) ist.
- 9Device according to claim 7, characterized by the receiver (3) of the once-only usable TAN or a comparable password with predefined user time being a mobile phone (32). Installation selon revendication 7) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est un téléphone mobile (32). Vorrichtung nach Anspruch 7, dadurch gekennzeichnet, daß der Empfänger (3) der nur einmal verwendbaren TAN oder eines vergleichbaren Passwortes, welche eine vordefinierte Benutzerzeit haben, ein Handy (32) ist.
- 10Device according to claim 7, characterized by the receiver (3) of the once-only usable TAN or a comparable password with predefined user time being a fax machine (33). Installation selon revendication 7) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est un télécopieur (33). Vorrichtung nach Anspruch 7), dadurch gekennzeichnet, daß der Empfänger (3) der nur einmal verwendbaren TAN oder eines vergleichbares Passwortes, welche eine vordefinierte Benutzerzeit haben, ein Telefax (33) ist.
- 11Device according to claim 7, characterized by the receiver (3) of the once-only usable TAN or a comparable password with predefined user time being an email address or network address. Installation selon revendication 7) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est une adresse email ou réseau. Vorrichtung nach Anspruch 7) dadurch gekennzeichnet, daß der Empfänger (3) der nur einmal verwendbaren TAN oder eines vergleichbaren Passwortes, welche eine vordefinierte Benutzerzeit haben, eine E-Mailoder Netzwerkadresse ist.
- 12Device according to claim 7, characterized by the receiver (3) of the once-only usable TAN or a comparable password with predefined user time being a voice output device. Installation selon revendication 7) caractérisée par le fait que le récepteur (3) du TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie est un appareil muni d'une sortie vocale. Vorrichtung nach Anspruch 7), dadurch gekennzeichnet, daß der Empfänger (3) der nur einmal verwendbaren TAN oder eines vergleichbaren Passwortes, welche eine vordefinierte Benutzerzeit haben, ein Sprachausgabegerät ist.
- 13Device according to claim 12, characterized by the voice output device being a loudspeaker (34). Installation selon revendication 12) caractérisée par le fait que l'appareil muni d'une sortie vocale est un haut-parleur (34). Vorrichtung nach Anspruch 12), dadurch gekennzeichnet, daß das Sprachausgabegerät ein Lautsprecher (34) ist.
- 14Device according to claim 12, characterized by the voice output device being a telephone (35). Installation selon revendication 12) caractérisée par le fait que l'appareil muni d'une sortie vocale est un téléphone (35). Vorrichtung nach Anspruch 12), dadurch gekennzeichnet, daß das Sprachausgabegerät ein Telefon (35) ist.
- 15Device according to claim 7, characterized by the receiver (3) being a radio receiving unit incorporated in the data inputting unit (1) outputting the once-only usable TAN or a comparable password with predefined user time on the display or monitor of the said data inputting unit (1). Installation selon revendication 7) caractérisée par le fait que le récepteur (3) est un récepteur radio intégré dans l'unité de saisie de données (1) qui sort le TAN ou mot de passe comparable à utilisation unique et à durée d'utilisation prédéfinie sur l'affichage ou l'écran de l'unité de saisie de données (1). Vorrichtung nach Anspruch 7), dadurch gekennzeichnet, daß der Empfänger (3) ein im Dateneingabegerät (1) eingebauter Funkempfänger ist, welcher die nur einmal verwendbare TAN oder ein vergleichbares Passwort, welche eine vordefinierte Benutzerzeit haben, auf dem Display oder Monitor des Dateneingabegeräts (1) ausgibt.
- 16Device according to claim 15, characterized by the said radio receiving unit incorporating a user identification element. Installation selon revendication 15) caractérisée par le fait que le récepteur radio est équipé d'un élément d'identification de l'utilisateur. Vorrichtung nach Anspruch 15), dadurch gekennzeichnet, daß der Funkempfänger ein Benutzer-Identifizierungelement besitzt.
- 17Device according to claim 16, characterized by the said user identification element being a magnetic card or chip card. Installation selon revendication 16) caractérisée par le fait que l'élément d'identification de l'utilisateur est une carte à puce ou magnétique. Vorrichtung nach Anspruch 16), dadurch gekennzeichnet, daß das Benutzer-Identifizierungelement eine Magnet- oder Chipkarte ist.
- 18Device according to claim 16, characterized by the said user identification element operating with graphic facilities for checking a fingerprint or image identification of the user. Installation selon revendication 16) caractérisée par le fait que l'élément d'identification de l'utilisateur fonctionne avec du matériel graphique de vérification d'empreinte digitale ou d'identification graphique de l'utilisateur. Vorrichtung nach Anspruch 16), dadurch gekennzeichnet, daß das Benutzer-Identifizierungelement mit grafischen Einrichtungen zur Überprüfung eines Fingerabdruckes oder zu einer Bildidentifizierung des Benutzers arbeitet.
- 19Device according to one or several claims 7) to 8), characterized by the presence of coding modules in the authorization computer (2) and receiver (3). Installation selon l'une ou plusieurs des revendications 7) à 18) caractérisée par le fait que le serveur d'autorisation (2) et le récepteur (3) sont équipés de modules de codages concordants. Vorrichtung nach einem oder mehreren der Ansprüche 7) bis 18), dadurch gekennzeichnet, daß im Autorisierungsrechner (2) und im Empfänger (3) übereinstimmende Verschlüsselungs-Module vorhanden sind.
- 20Device according to one or several claims 7) to 9), characterized by the receiver unit (4) assuming the form of door-locking mechanism. Installation selon l'une ou plusieurs des revendications 7) à 19) caractérisée par le fait que l'unité de réception (4) consiste dans un mécanisme de fermeture de porte. Vorrichtung nach einem oder mehreren der Ansprüche 7) bis 19), dadurch gekennzeichnet, daß die Empfangseinheit (4) ein Türschließ-Mechanismus ist.
- 21Device according to one or several claims 7) to 20), characterized by the authorization computer (2) and receiver unit (4) being incorporated in a unit of equipment. Installation selon l'une ou plusieurs des revendications 7) à 20) caractérisée par le fait que e serveur d'autorisation (2) et l'unité de réception (4) sont intégrés dans un même appareil. Vorrichtung nach einem oder mehreren der Ansprüche 7) bis 20), dadurch gekennzeichnet, daß der Autorisierungsrechner (2) und die Empfangseinheit (4) in einem Gerät integriert sind.
- 22Device according to one or several claims 7) to 20), characterized by the data inputting unit, the authorization computer (2) and receiver unit (4) being incorporated in a unit of equipment. Installation selon l'une ou plusieurs des revendications 7) à 20) caractérisée par le fait que l'unité de saisie de données, le serveur d'autorisation (2) et l'unité de réception (4) sont intégrés dans un même appareil. Vorrichtung nach einem oder mehreren der Ansprüche 7) bis 20), dadurch gekennzeichnet, daß das Dateneingabegerät, der Autorisierungsrechner (2) und die Empfangseinheit (4) in einem Gerät integriert sind.
Independent claims22
40 paragraphs in 1 section, as filed
The invention relates to a method for authorization in data transmission systems, and a device for its execution.
It is known that when telebanking the user permanent addition to his Password (? IN) for each transaction additionally a transaction number (TAN) is required. Such TAN's are received in the mail in larger blocks to the user. There is therefore the risk that third parties of such TANs become aware and in conjunction with the password abuse can make. The risk is increased by the fact that Such TAN's virtually an unlimited validity have.
Also known are call-back systems in which the called System is stored by a callback when a rule Number verifies that the calling system is authorized and not a foreign system impersonates a legitimate system. The disadvantage of the call-back systems is that a unauthorized user, which is any one of a source a functional access to the legitimate calling system has given, among these unlawfully obtained permission problems can work, as the call-back system only checks whether called by a legitimate principle system has been.
D1 (WO 96 00485 A) discloses a method and apparatus for authorizing a User in terms of too relevant in every service. A modified therefor Pager calculated based on a request code, a password and an internal Encryption methods, a response code, which the service users in a further Terminal is inputted. After a positive review is the desired service for the Users enabled.
The invention has for its object a method and apparatus for authorization to create in the data transfer, the security is increased. This task is accomplished by the method and apparatus according to the independent claims.
Wireless telecommunications devices such as mobile phones or Pagers often have the ability to short (alpha-) numeric messages (Z. B. the Short Message Service = SMS service) to receive and display on their display. The present invention uses this possibility, a TAN or a comparable password to transfer.
According to the present invention, the user transmitted via a Data input device his identification (user ID, password o. Ä.) and / or an identification ID of the data input device together with a request to generate a TAN (or a comparable password) to a computer, which the Authorization process takes over and then briefly authorization computer is called. This is authorization computer by a random alphanumeric or numeric only TAN (or a comparable password) or calculated taken from a file. Then, by the authorization computer parallel to the existing connection with the data input device, via another transmission TAN (or an equivalent Password) is transmitted to a receiver. This receiver For example,<sl><li>a) a radio receiver with a display or monitor such. B. a cell phone, a pager (z. B. a pager receiver)</li><li>b) a specially crafted reception card within the Data input device which via radio or a fixed Wiring is addressed,</li><li>c) a mailbox,</li><li>d) a fax or</li><li>d) a voice output device such as a fixed instalierter speakers or a (voice) telephone</li></sl>be. For this purpose, the authorization computer the requisite (s) Telephone, paging or fax numbers, e-mail or network address (es). The relevant data are usually in the authorization computer stored. However, it is possible that the authorization computer in turn, these data from a database obsolete, which is located on another computer. in this respect can the authorization computer using the inventive Process is by itself an access to these make another computer.
The authorized user can then forwarded him TAN (or Enter the comparable password) into his data input device manually and send back to the authorization computer. at automated process takes place according to the invention an automatic Transmission of the TAN (or the comparable password). The authorization computer now verified the correspondence between all (awarded by him) valid TAN's (or comparable Passwords) and allows for this authorization check a Release of the data flow between the data input device and a Receiving unit.
When TAN (or the comparable password) may be a act only once usable TAN. However, there are other limitations as the user time and / or the number or size of the transferred files for the validity of the TAN (or comparable Password) possible.
After authorized in the aforementioned way connecting, now data from the data input device to the receiving unit (Or vice versa; full duplex) are received.
It is obvious that, for additional security, these data can also be encrypted.
Both the data entry device, and the authorization computer and the receiving unit may be computer normal (human). The invention works platform independent, ie it is independent of processor types, operating systems and / or control electronics (Z. B. the receiver unit) and / or input / output units (Z. B. the data input device and the receiving unit).
The security of this system is that only an authorization the devices have a data transfer from the data input device to the receiving unit by the authorization computer will be shown. This is through the use of separate transmission paths between the file player and the authorization computer einseits and the authorization computer and the TAN transfer On the other hand, is achieved. To that extent, the different Invention of call-back systems in which only one review the data input device and the authorization computer takes place.
The inventive method allows to perform various security levels.
At the lowest level of security according to the invention is in the data input device as a receiver, a radio receiver, for example, incorporated in the form of a plug-in card, so that only with this specific device a data transmission to the receiving unit possible is. To increase this reliability can be provided, that this radio receiver with a user identification element, operated, for example, a magnetic or chip card can be. The user identification element can also graphical methods such as checking a fingerprint or Image identifying the user work.
The additional security level according to the invention is that the authorization computer which TAN (or the comparable password) sent to a pager or a similar device. In this Case, one of authorization only if the data input device and the pager in accessing the same person. Only then is it is possible that the image displayed on the display of the pager TAN (or a comparable password) entered in the data input device and is sent back to the authorization computer from there.
At a pager transmitted data are known to be, however, be intercepted. Another security level according to the invention can be obtained in such a way that the authorization computer and in the pager matching encryption modules in use are.
Instead of pagers or mobile phones can also in inventive Way be another receiver provided. This can be a Mailbox, be a fax or a voice output device. As voice output device are inventively fixed speaker or the transfer of the language to a defined telephone extension possible. In the speech output devices is a language Issue of TAN (or the comparable password).
It is obvious that also the transmission to such Receivers can be encrypted.
If instead of a pager, a mobile phone, in particular a GSM mobile phone, is in use, then it is possible as a result of encryption of the relevant Transmission technology according to the invention to other encryption mechanisms without. In this case, the display is TAN (or the comparable password) on the display the phone.
Another security level of the invention can achieved by be that of the data input device and the authorization computer a connection is only established if the data input device transmits a corresponding password. This password can present invention have a much longer time Validity own as the TAN.
Another security level of the invention can achieved by be that even the use of the data input device also requires a password.
It is obvious that a combination of the aforementioned is safety levels.
The invention is universal in the field of data transmission systems usable. This applies for example also for the Internet and intra-networks, Local Area Networks (LAN), Wide Area Networks (WAN) etc ..
The system in question is outside the classical computer, for example, used in physical access control. The user gives this example on a mounted near the door Keyboard (= data input device) his personal password. Of the Authorization computer checks the password, if necessary. Also in connection with access on the concrete - for concrete Period. If the relevant password is valid (still), transmitted the authorization computer to a mobile phone or the Special door locking system konzepierte, functional with a Pager similar device, the TAN (or the comparable password). Then this is TAN (or the comparable password) manually by the user via the keyboard attached to doors entered and automatically forwarded to the authorization computer. After successful verification is done by the authorization computer a signal for the release of the door locking mechanism. This release may possibly. Be temporary. The receiving unit in this case, simple in technical terms its nature, since it only the signal for the release of the door locking mechanism so has to process that question electrical mechanics the door opening releases.
Thus it is possible to construct a system in which different People different permission to different apprehended have spaces.
The specific application fields include, for example:<ul><li>data center</li><li>airports</li><li>ministries</li><li>inch</li><li>Border crossings</li><li>Security areas</li><li>banks</li><li>safes</li><li>garages</li><li>Park homes</li><li>cars</li></ul>
The whole system gets its security from the combination several different basic principles and factors:<sl><li>(1) "what-you-have" (which does not want to duplicate (GSM) smart card) So a physical unique, not Verlus dictating that they can be passed.</li><li>(2) "what-you-know" (the PIN of GSM smart card and the own user name in the data input device and / or authentication server), So know-how that is not inadvertently can be passed or accidentally</li><li>(3) DES encryption and cryptographic authentication in the GSM network itself, characterized resistance to eavesdropping and spoofing attacks</li></sl>
This is to system compromise combining at least three - each very unlikely for themselves - Events from emergencies:<sl><li>a) physical loss of (mobile) chip card, the pager or a stranger access to the mailbox, the fax or Voice output device,</li><li>b) publication of the PIN of the recipient (eg. B. from the smart card or the phone) and</li><li>c) knowledge of the transmitted TAN or comparable Password.</li></sl>
An accidental coincidence of these factors is virtually ruled out especially as in this case, the successful attack on the system, the intimate knowledge of the access method and Userid presupposes that not in an attack in the normal case given is. In addition, the user has the option, his user id at losing his chip card into the authentication server immediately block or be blocked.
Another advantage of the support on GSM is that the user during the authorization process at all times is, eg in access problems or doubts as to its Identity from the system administrator can be called directly.
This solution has the advantage of being very safe, cost-effective and with conventional, widespread and secure hardware can be realized.
Another inventive solution is that the authorization computer and receiving unit, a device is.
Further advantages and possible applications of the invention from the hereinafter mentioned embodiment in connection with the drawing.
An authorized user operates a data input device 1). here About it sends the request to generate or select and Returning a TAN (or a comparable password) to an authorization computer 2). The authorization computer 2) generates the TAN (or a comparable password). The authorization computer 2) is the number or data address, z. B. the E-mail or the recipient (3) network address of the user's Data input device 1) is known. He sends to a receiver 3) (Not shown in detail) TAN (or an equivalent Password). The receiver 3), a pager 31) or a mobile phone 32) be. However, the receiver 3) can also be the E-mail address of a Mailbox (not shown), a facsimile machine 33) or a voice output device be. The voice output device may be a permanently installed be speaker 34) or a telephone 35). The user reads this TAN (or a comparable password) from the receiver 3) from, or she hears the voice and gives them manually in the data input device 1). transmitted the data input device 1) now the TAN (or a comparable password) to the Authorization computer 2). The authorization computer 2) is checked, whether these TAN (or the comparable password) is still valid. To this purpose, the authorization computer be programmed to that the validity of the TAN (or the comparable password) between they were sent to the receiver 3) and transmission via the data input device 1) is limited in time. The temporal Limiting example, can take two minutes. If the TAN (or the comparable password) is valid, then provides the Authorization computer 2) a compound to a receiving unit 4) forth. Now the user for the duration of the maintenance this compound capable of data from the data input device 1) to be transmitted to the receiving unit 4) and / or receive.
It is obvious that this data for further securing can be encrypted.
It is also conceivable that not only the TAN (or comparable Password) for its validity for a time limit has, but also that the duration of the maintenance of the connection between the data input device 1) and the receiving unit 4) is limited. In this way it can be avoided that a "Leased line" between the data input unit 1) and the receiving unit 4) is produced, which in turn a vulnerability could represent.
The authorization computer 2) and the receiving unit 4) can have a his only computer. In this case, a first access is made to a data processing program which the authorization process (Generation and transmission of the TAN) in the manner described above performs. In a second step, the data is transmitted.
It can even the data input device (1), the authorization computer 2) and the receiving unit 4) can be a single computer. In this case is carried out a first access to a data processing program, which the authorization process (generation and transmission TAN performs to the recipient) in the manner described above. It was only after the authorization of the user receives a full or limited to certain areas of computer access.
LIST OF REFERENCE NUMBERS
<dl tsize="21" compact="compact"><dt>The data input device</dt><dd>1)</dd><dt>authorization computer</dt><dd>2)</dd><dt>receiver</dt><dd>3)</dd><dt>pager</dt><dd>31)</dd><dt>mobile</dt><dd>32)</dd><dt>Fax machine</dt><dd>33)</dd><dt>speaker</dt><dd>34)</dd><dt>phone</dt><dd>35)</dd><dt>receiving unit</dt><dd>4)</dd></dl>
1 sheet
Sheet 1
18 members in 11 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19718103 | Germany | A | |
| 19718103 | Germany | A | |
| 19718103 | Germany | – | |
| 19718103 | – | – | – |
| DE1997118103 | – | – | – |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| DE19718103A1 | Germany | A1 | |
| EP0875871A2 | European Patent Office (EPO) | A2 | |
| AU6354598A | Australia | A | |
| JPH10341224A | Japan | A | |
| CN1207533A | China | A | |
| EP0875871A3 | European Patent Office (EPO) | A3 | |
| AR009872A1 | Argentina | A1 | |
| US6078908A | United States of America | A | |
| TW425804B | Taiwan Province of China | B | |
| BR9801177A | Brazil | A | |
| EP0875871B1This record | European Patent Office (EPO) | B1 | |
| AT226346T | Austria | T | |
| ATE226346T1 | Austria | T1 | |
| DE59805939D1 | Germany | D1 | |
| ES2186019T3 | Spain | T3 | |
| CN1149504C | China | C | |
| JP4204093B2 | Japan | B2 | |
| BR9801177B1 | Brazil | B1 |
98 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Ep patent has been removed from the registerECNC | ECNC | SE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Ep patent has been removed from the registerECNC | ECNC | SE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent revokedRevoked27W | 27W | EP | |
| Gb: patent revoked under art. 102 of the ep convention designating the uk as contracting stateRevokedGBPR | GBPR | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Patent revokedRevokedORIGINAL CODE: 0009271RDAG | RDAG | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: PATENT REVOKEDSTAA | STAA | EP | |
| Appeal procedure closedAppealORIGINAL CODE: EPIDOSNNOA9OAPBU | APBU | EP | |
| Opposition withdrawnWithdrawnORIGINAL CODE: 0009264PLBP | PLBP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Date of receipt of statement of grounds of appeal recordedAppealORIGINAL CODE: EPIDOSNNOA3OAPBQ | APBQ | EP | |
| Appeal reference modifiedAppealORIGINAL CODE: EPIDOSCREFNOAPAH | APAH | EP | |
| Appeal reference recordedAppealORIGINAL CODE: EPIDOSNREFNOAPBM | APBM | EP | |
| Date of receipt of notice of appeal recordedAppealORIGINAL CODE: EPIDOSNNOA2OAPBP | APBP | EP | |
| Information modified related to despatch of communication that patent is revokedRevokedORIGINAL CODE: EPIDOSCREV1RDAD | RDAD | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition data, opponent's data or that of the opponent's representative modifiedOppositionORIGINAL CODE: 0009299OPPOPLAB | PLAB | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Appeal procedure closedAppealORIGINAL CODE: EPIDOSNNOA9OAPBU | APBU | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Opposition data, opponent's data or that of the opponent's representative modifiedOppositionORIGINAL CODE: 0009299OPPOPLAB | PLAB | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition filed (corrected)OppositionR26 | R26 | EP | |
| Opposition data, opponent's data or that of the opponent's representative modifiedOppositionORIGINAL CODE: 0009299OPPOPLAB | PLAB | EP | |
| Date of receipt of statement of grounds of appeal recordedAppealORIGINAL CODE: EPIDOSNNOA3OAPBQ | APBQ | EP | |
| Appeal reference modifiedAppealORIGINAL CODE: EPIDOSCREFNOAPAH | APAH | EP | |
| Date of receipt of notice of appeal recordedAppealORIGINAL CODE: EPIDOSNNOA2OAPBP | APBP | EP | |
| Communication despatched that patent is revokedRevokedORIGINAL CODE: EPIDOSNREV1RDAF | RDAF | EP | |
| Application for restoration allowed (sect. 28/1977)728Y | 728Y | GB | |
| Notification of lapseLapsedST | ST | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application for restoration filed (sect. 28/1977)728V | 728V | GB | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Reply of patent proprietor to notice(s) of opposition receivedOppositionORIGINAL CODE: EPIDOSNOBS3PLBB | PLBB | EP | |
| Information related to reply of patent proprietor to notice(s) of opposition deletedOppositionORIGINAL CODE: EPIDOSDOBS3PLAS | PLAS | EP | |
| Reply of patent proprietor to notice(s) of opposition receivedOppositionORIGINAL CODE: EPIDOSNOBS3PLBB | PLBB | EP | |
| Notice of opposition and request to file observation + time limit sentOppositionORIGINAL CODE: EPIDOSNOBS2PLAX | PLAX | EP | |
| Nl: lapsed or anulled due to non-payment of the annual feeLapsedNLV4 | NLV4 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Notice of opposition and request to file observation + time limit sentOppositionORIGINAL CODE: EPIDOSNOBS2PLAX | PLAX | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Unpublished change to opponent dataORIGINAL CODE: EPIDOS OPPOPLBQ | PLBQ | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Unpublished change to opponent dataORIGINAL CODE: EPIDOS OPPOPLBQ | PLBQ | EP | |
| Fr: translation filedET | ET | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| New agentNV | NV | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedGERMANFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information provided on other rights and legal means of execution20020129 AT BE CH DE DK ES FI FR GB GR IE IT LI LU NL PT SE111Z | 111Z | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Title (correction)AUTHORIZATION METHOD AND SYSTEM IN DATA TRANSFER SYSTEMSRTI1 | RTI1 | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Designation fees paidAT BE CH DE DK ES FI FR GB GR IE IT LI LU MC NL PTAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0875871
- Publication, DOCDB
- 0875871
- Publication, EPODOC
- EP0875871
- Application
- 98100688
- Application, DOCDB
- 98100688
- Application, EPODOC
- EP19980100688
Titles3
- German
- Verfahren und Vorrichtung zur Autorisierung in Datenübertragungssystemen
- English
- Authorization method and system in data transfer systems
- French
- Méthode et système d'authorisation dans des systèmes de transfert de données
Classification
- CPC, 14
- G06F21/335
- G06Q20/401
- G06F21/42
- G06F21/43
- G06F2221/2103
- G06F2221/2153
- G06Q20/04
- G06Q20/385
- G06Q20/425
- H04L63/083
- H04L63/18
- H04L2463/102
- H04W12/06
- H04W12/08
- IPC, 15
- E05B49 00
- G06F12 00
- G06F21 33
- G06F21 42
- G06F21 43
- G06Q20 00
- G07C9 00
- G07F7 10
- G07F19 00
- G09C1 00
- H04L9 32
- H04L29 06
- H04M11 00
- H04N1 44
- H04W12 06
Designated states17
- Contracting states, 17
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Netherlands (Kingdom of the)
- Portugal
- Sweden
