Authentication and authorization system using smart card
Abstract
Authentication and authorization system through intelligent card and only key, consisting of a system having intelligent card readers, located at different peripheral units, all them connected with an authentication and authorization server, which, on one side, identifies the person who is the owner of the card by means of a key made available in the card, which is only accesible to the system, not even to the own user, and on the other side, starting from the profile arrogated to the user, which is also recorded in the own card, the server authorizes it and gains access to certain computerized applications, with no need for the user to know the method of access to them, without entering new access keys, although so required by the applications, the own system doing it instead of the user.

Term
Term ended
Projected expiry passed 25 April 2021, 5.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
10 claims: 4 independent, 6 dependent
- 1An authentication and authorization system, thru intelligent card and only key, of those constituted by an architecture based on a unit acting as an identification, authentication and authorization server, connected, through a communication network, on one side, to peripheral units used by multiusers, such as, for example, the access to buildings, and to others units used by only one user, each of which has a corresponding reading element and the corresponding method for performing said read for an intelligent card, such as a chip card, and on the other side, the identification and authorization server is connected with public key infrastructures and different computerized application servers to which a user wishes to accede, characterized in that it combines, on a same intelligent card support, keys of physical access to installations, and logic access to computerized systems of the organization, using for this purpose two applications recorded in said support managing the use of these keys, also recorded in protected portions of the support.
- 8An authentication and authorization system thru intelligent card and only key, according to any of the preceding claims, characterized in that by configuring in an adequate way the modifiable computerized applications, said applications can be entered without intervening the user, by means of the automatic write of the entry keys to said applications.
- 9An authentication and authorization system thru intelligent card and only key, according to any of the preceding claims, characterized in that the identification made of the user is configured so that it is accepted as certification and electronic signature in systems with applications in a native mode of challenge/answer.
Independent claims4
21 paragraphs in 5 sections, as filed
BACKGROUND OF THE INVENTION
The present specification relates to an application for a Patent of Invention referring to an authentication and authorization system through intelligent card and only key, the purpose of which is that, upon being configured as a system having intelligent card readers, located at different peripheral units, such as, for example, access to buildings, hours of work controllers, users' PCs, etc., all them being connected with an authentication and authorization server, it gets, on one side, to identify the person possessing the card thanks to a key made available in the card, which is only accessible to the system, and not even to the own user, while, on the other side, starting from the profile adjudged to the user, said profile being also recorded in the own card, the server authorizes it and gets access to certain computerized applications, with no need for the user to know the method of access to them, not entering appropriate access keys, although so required by the applications, the own system doing and performing these functions instead of the user.
FIELD OF THE INVENTION
This invention will find application in the industry dedicated to the manufacture of apparatus, devices and ancillary elements for the computer science and telecommunications.
RELATED ART
The applicant is not aware of the existence, at present, of an invention disclosing the characteristics incorporating that described in this specification.
SUMMARY OF THE INVENTION
The authentication and authorization system through intelligent card and only key as proposed by the invention, configures itself as an evident novelty in its application field, offering the appropiate tools to establish necessary links among the elements of the system, and, at the same time, it configures as a unique central authentication service for all users and applications, including a physical access control.
In a most definite way, the authentication and authorization system through intelligent card and only key of the invention, is configured starting from an architecture based on a unit acting as an identification, authentication and authorization server, connected by means of a communication network, on one side, to peripheral units used by many users (such as the access to buildings), and to other units used by an only user, each of which has the corresponding reading element and reading method for intelligent card, i.e, a chip card; and on the other side, the identification and authorization server is connected to public key infrastructures and different computerized application servers to which a user wants to accede.
The invention covers the needs of a physical access control to offices, as well as the logic access control to computerized applications, including, on one side, the person identification, i.e, the authentication, and on the other side, a control of access permits to each application, i.e, the authorization.
The system involves management of users and authorizations in a coordinated way in all applications, and, at the same time, acts as an auditing, i.e, it is capable of obtaining traces or evidences allowing the behaviour carried out by a user within an application to be determined.
The invention is based on the use of cryptographic techniques of public key, and it is also based on intelligent cards as an item identifying the person possessing it.
The authentication and authorization system acts also as an agglutinator of the elements composing the system, erecting a punctual client who takes charge of establishing links among the different parts, which are: <ul id="ul0001" list-style="dash"><li>Intelligent card, and</li><li>Reader thereof.</li></ul>
In collaboration with the mentioned elements, the invention also contemplates the use of the following. to wit: <ul id="ul0002" list-style="dash"><li>Physical access control elements,</li><li>Authentication and authorization server,</li><li>Public key infrastructure (PKI), and</li><li>Computerized applications.</li></ul>
The invention combines, on a same support of intelligent card, the keys of physical access to installations, and of logic access to computerization systems of the organization, using for this purpose, two recorded applications in said support managing the use of these keys, also recorded in protected portions of the support, managing the use of these keys, also recorded in protected portions of the support.
The invention relies on units of only user, for example: PC of client, with facilities for managing, on one side, the communication with the reader of intelligent card, and, on the other side, managing the communication with the Directory X.500, authorization and identification server, where the user's credentials or passewords reside in.
It is also easily configured so that the card requests or not the PIN, as well as to block the PC or not when the card is extracted, to have the safescreen jumped to a determined time after extracting the card, etc.
In short, the invention allows to act on the PC according to the configuration had, depending on the events coinciding with the card reader, and on the other side, it stores in a volatile RAM, already encoded in order to avoid their interception, the credentials of that user in particular.
Also, this module performs the function of single sign-on (SS0) or unique password, together with the Directory X.500, on the applications.
The novelty lies on the fact that up to now there are not any commercial implementations of SSO making basically use of standards, without having recourse to any proprietary technology, excepting, of course, the functinal elements performed in the place of the user.
DESCRIPTION OF THE DRAWINGS
In order to complement this description and aid to a better understanding of the characteristics of the invention, the appending sheet of drawings, which is a part of this specification, shows, by way of illustrative and non-limiting example, the following: Figure 1 corresponds to a schematic representation of several elements configuring the invention, related to a authentication and authorization system through intelligent card and only key.
DESCRIPTION OF THE PREFERRED EMBODIMENT OF THE INVEN+ TION
From figure 1, it can be seen that the authentication and authorization system through intelligent card and only key is constituted starting from a user' computer (1), fitted with its corresponding card, as well as a control of physical access (2), the elements (1) and (2) being connected to a communication network (3), and this, in turn, is connected with computerized applications servers (3), and also with an authentication and authorization server (4), which, in turn, is connected to a certification authority (6) and record authority (5), both configured as two computers having their corresponding keyboard.
The user (1) offers the relative tools in order to establish the necessary links among the elements configuring the system, producing a unique central authentication service for all users and applications, including a physical access control (2)
The invention uses cryptographic techniques with authentication on the level of application.
Contents5
2 sheets
Sheet 1 Sheet 2
Every citation, both waysCites: the store holds 1 of 2
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN112070940A | Cited by | China | Search report |
| GB2367937B | Cited by | United Kingdom | Search report |
| CN104408810A | Cited by | China | Search report |
| WO2009025431A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| GB2367937A | Cited by | United Kingdom | Search report |
| US8543530B2 | Cited by | United States of America | Applicant |
| WO2008054101A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US6802007B1 | Cited by | United States of America | Applicant |
| EP0717339A2 | Cites | European Patent Office (EPO) | Search report |
8 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 200001080 | Spain | A | |
| 200001080 | Spain | A | |
| 200001080 | Spain | – | |
| 200001080 | – | – | – |
| ES20000001080 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP1150197A2This record | European Patent Office (EPO) | A2 | |
| BR0101903A | Brazil | A | |
| MA25295A1 | Morocco | A1 | |
| SV2002000431A | El Salvador | A | |
| AR029249A1 | Argentina | A1 | |
| ES2191507A1 | Spain | A1 | |
| EP1150197A3 | European Patent Office (EPO) | A3 | |
| ES2191507B1 | Spain | B1 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application withdrawnWithdrawn18W | 18W | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1150197
- Publication, DOCDB
- 1150197
- Publication, EPODOC
- EP1150197
- Application
- 1500110
- Application, DOCDB
- 01500110
- Application, EPODOC
- EP20010500110
Titles3
- German
- Authentifizierungs- und Berechtigungssystem mit Chipkarte
- English
- Authentication and authorization system using smart card
- French
- Système d'authentification et d'autorisation utilisant une carte à puce
Classification
- CPC, 5
- G07C9/00103
- G06F21/34
- G07C9/27
- H04L9/3263
- H04L9/3297
- IPC, 3
- G06F1 00
- G06F21 34
- G07C9 00
Designated states26
- Contracting states, 20
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia